The D6686 or D6100IPv6 may be vulnerable to becoming inoperative if a telnet session is left open by any means not intended by its owner. Enabling a password for Telnet sessions will prevent an internet attacker from attempting to utilize the second available tunnel.
-
Prerequisites: The PC used to make configuration changes must reside on the same subnet as the D6686 or D6100IPv6.
How to add a password to protect the telnet session:
-
This article applies to both the D6100IPv6 and D6686. Substitute D6100IPv6 in place of D6686 in all below examples when working with a D6100IPv6 .
-
Prompt display: When Telnet authentication is disabled the unit short name (default: D6686) will display, if a short name has not been programmed, the symbol [ > ] will display.
-
If
‘login’:
displays, this indicates the Telnet password has been enabled and will be required to access telnet.
-
Open a command prompt and enter [telnet xxx.xxx.xxx.xxx] (where xxx.xxx.xxx.xxx is IP Address of the device) and press Enter.
-
D6686> displays, type [en] and press Enter.
-
D6686(enable)# displays, type [conf] and press Enter.
-
D6686(config)# displays, type [cli] and press Enter.
-
D6686(config-cli)# displays, type [login password] followed by [your new telnet password] and press Enter. Note: the password entered in step 5 will be required for all future telnet sessions in the D6686.
-
D6686(config-cli)# displays, type [telnet] and press Enter.
-
D6686(config-cli-telnet)# displays, type [authentication enable] and press Enter.
-
D6686(config-cli-telnet)# displays, type [write] and press Enter to save the above changes.
-
D6686(config-cli-telnet)# displays, type [ex] and press Enter.
-
D6686(config-cli)# displays, type [ex] and press Enter.
-
D6686(config)# displays, type [ex] and press Enter.
-
D6686(enable)# displays, type [reload] and press Enter.
-
Are you sure (yes/no)? displays, type the word [yes] and press Enter and the D6686 will reboot. The next time the Telnet command is entered as in step 6, a login prompt will appear and the newly added Telnet password will be required.
How to remove the password from the telnet session:
-
Open a command prompt and enter [telnet xxx.xxx.xxx.xxx] (Where xxx.xxx.xxx.xxx is IP Address of the device) and press Enter.
-
D6686 login: displays, enter the default user name [admin].
-
Password: displays, enter the Telnet password and press Enter.
-
D6686> displays, enter [en] and press Enter.
-
D6686(enable)# displays, enter [conf] and press Enter.
-
D6686(config)# displays, enter [cli] and press Enter.
-
D6686(config-cli)# displays, enter [telnet] and press Enter.
-
D6686(config-cli-telnet)# displays, enter [authentication disable] and press Enter.
-
D6686(config-cli-telnet)# displays, enter [write] and press Enter to save the above changes.
-
D6686(config-cli-telnet)# displays, type [ex] and press Enter.
-
D6686(config-cli)# displays, type [ex] and press Enter.
-
D6686(config)# displays, type [ex] and press Enter.
-
D6686(enable)# displays, type [reload] and press Enter.
-
Are you sure (yes/no)? displays, type the word [yes] and press Enter and the D6686 will reboot. The next time the Telnet command is entered as in step 1 the login will no longer display and the unit short name (default: D6686) displays.
How to return the D6686 to factory settings.
-
Open a command prompt and enter [telnet xxx.xxx.xxx.xxx] (Where xxx.xxx.xxx.xxx is IP Address of the device) and press Enter. If the display reads: D6686 login:, enter the default user name [admin]. Password: displays, enter the Telnet password and press Enter.
-
D6686> displays, type [en] and press Enter.
-
D6686(enable)# displays, type [reload factory defaults] and press enter.
-
A warning displays indicating all configurable parameters will be destroyed and that the unit will reboot.
-
At the Are you sure you want to do this (yes/no)? prompt, type the word [yes] and press enter.
-
Do you want to back out (yes/no)? type the word [no] and press enter.
-
Changes will take effect on next reboot.
-
Rebooting ...
-
After the reboot cycle finishes, the unit will now again be at the factory default settings.
-