Device Access and Management

· 2 min read

done ccnanetworkingciscocommands

Hostname Config

Configures the name the device identifies itself by.

# in configuration mode
hostname <hostname>

Console Password Config

Configures a password to be able to access the device.

# in configuration mode
line console 0 # entering the line console
password <password>  # configure the password for the device
login # tells the device to ask the password at login
exec-timeout 10 0 # closes the session after idle for 10min

Privileged Exec Password Config

Configures a password for entering privileged EXEC mode.

# in configuration mode
enable secret <password>

Local User Config

Creating a user (contains a username and password).

# in config mode
username <username> secret <password>

Domain Name and Crypto Key Generation

Note: To generate the crypto key you need the domain name and the hostname configured before you are able to generate the crypto key.

# in config mode
ip domain-name <domainname> # configuring the domain name (REQUIRED before key gen)
crypto key generate rsa modulus 2048 # generate the ssh key and define the key size

Remote Access Config

Configure SSH or telnet for access through a remote terminal. Best practice: configure a domain name and a local user before SSH authentication config. This is for more precise control of users and for generating the RSA keys for SSH.

# in config mode
line vty 0 15 # vty lines are where the configs for remote connection are
transport input ssh # specifying only to use ssh (disables telnet)
login local # uses local user database (SSH requires username auth)
exec-timeout 10 0 # closes the session after idle for 10min
exit # takes you back to config mode
ip ssh version 2 # enforces using SSH V2 (v1 is broken crypto)
show ip ssh # verify ssh config

Encrypt Plaintext Passwords Config

Encrypts all future and current passwords.

# in config mode
service password-encryption

MOTD Config

Message of the Day (MOTD) displays a message to anyone connecting to the device.

banner motd #Authorized access only. All activity is monitored.#

Login Banners Config

Displays a message before the username and password prompt.

banner login #Unauthorized access is prohibited.You must authenticate.#

VLAN SVI IP Config

Configures a Switched Virtual Interface (SVI) so the switch can be managed remotely over IP.

# layer 2 and in config mode
vlan 10
name <name>
exit

interface vlan 10
ip address <ip> <mask>
no shutdown
exit

# layer 3 - same as layer 2 but add one command
ip routing

Default Gateway Config

Sets default gateway on switches.

# layer 2 switch and in config mode
ip default-gateway <gateway ip>

# layer 3 switch and in config mode
# SVI/interface IP is configured the same as above,
# but routing uses a default route instead of ip default-gateway
ip route 0.0.0.0 0.0.0.0 <gateway ip>