How to restrict telnet access to Cisco Router?

To specify devices to be permitted or denied, configure an Access Control List (ACL) in global configuration mode. A standard ACL is usually used for this purpose. Issue the access-list access-list-number {deny | permit} source [source-wildcard] command.

e.g. access-list 10 permit tcp host 192.168.1.10

To restrict inbound Telnet access for vty sessions, issue the access-class in command in line configuration mode. Set identical restrictions on all virtual terminal lines because a user can connect to any of them.To restrict outbound Telnet access for vty sessions, issue the access-class ‘access-list  <acl_number>  out’ command in line configuration mode.