Device Access and Management
· 2 min read
done ccnanetworkingciscocommands
Hostname Config
Configures the name the device identifies itself by.
# in configuration mode
hostname <hostname>
Console Password Config
Configures a password to be able to access the device.
# in configuration mode
line console 0 # entering the line console
password <password> # configure the password for the device
login # tells the device to ask the password at login
exec-timeout 10 0 # closes the session after idle for 10min
Privileged Exec Password Config
Configures a password for entering privileged EXEC mode.
# in configuration mode
enable secret <password>
Local User Config
Creating a user (contains a username and password).
# in config mode
username <username> secret <password>
Domain Name and Crypto Key Generation
Note: To generate the crypto key you need the domain name and the hostname configured before you are able to generate the crypto key.
# in config mode
ip domain-name <domainname> # configuring the domain name (REQUIRED before key gen)
crypto key generate rsa modulus 2048 # generate the ssh key and define the key size
Remote Access Config
Configure SSH or telnet for access through a remote terminal. Best practice: configure a domain name and a local user before SSH authentication config. This is for more precise control of users and for generating the RSA keys for SSH.
# in config mode
line vty 0 15 # vty lines are where the configs for remote connection are
transport input ssh # specifying only to use ssh (disables telnet)
login local # uses local user database (SSH requires username auth)
exec-timeout 10 0 # closes the session after idle for 10min
exit # takes you back to config mode
ip ssh version 2 # enforces using SSH V2 (v1 is broken crypto)
show ip ssh # verify ssh config
Encrypt Plaintext Passwords Config
Encrypts all future and current passwords.
# in config mode
service password-encryption
MOTD Config
Message of the Day (MOTD) displays a message to anyone connecting to the device.
banner motd #Authorized access only. All activity is monitored.#
Login Banners Config
Displays a message before the username and password prompt.
banner login #Unauthorized access is prohibited.You must authenticate.#
VLAN SVI IP Config
Configures a Switched Virtual Interface (SVI) so the switch can be managed remotely over IP.
# layer 2 and in config mode
vlan 10
name <name>
exit
interface vlan 10
ip address <ip> <mask>
no shutdown
exit
# layer 3 - same as layer 2 but add one command
ip routing
Default Gateway Config
Sets default gateway on switches.
# layer 2 switch and in config mode
ip default-gateway <gateway ip>
# layer 3 switch and in config mode
# SVI/interface IP is configured the same as above,
# but routing uses a default route instead of ip default-gateway
ip route 0.0.0.0 0.0.0.0 <gateway ip>