Safari Books Online is a digital library providing on-demand subscription access to thousands of learning resources.
In addition to physical ports, devices also have virtual ports (called virtual terminal lines). Most current Cisco devices support 16 virtual terminal lines, numbered vty 0 through vty 15. Standard and extended access lists applied to physical interfaces do not prevent router-initiated Telnet sessions.
Virtual terminal access lists can block vty access to the router or block access to other routers on allowed vty sessions. Restrictions on vty access should include all virtual ports, because users can connect through any vty port. The syntax for a vty access list is as follows: