2. You must enable SSH. A new switch just purchased from Cisco contains no default configuration. Configure TELNET access with the following settings : - Login enabled - Password : ciscotelnet - History size : 15 commands - Timeout : 8'20'' - Synchronous logging 7. Our lab setup for this article is very simple as shown below: … Click here to download the packet tracer files for this lab, http://www.ifm.net.nz/cookbooks/passwordcracker.html, http://resources.intenseschool.com/video-basic-cisco-router-configuration/, CCDA Lab #10: Best Practices for Networks (SSH, AAA, NTP). basic_rtr_config_init.pkt: This Packet Tracer file contains the lab setup with only the devices and the necessary interface connections. To test the exec-timeout, login to R2 via SSH and just wait (don’t type anything) for 20 seconds; it should close the session. Track your progress towards a certification exam, By Tolulope Ogunsina on February 27, 2015, By Tolulope Ogunsina on February 26, 2015, By Tolulope Ogunsina on February 25, 2015, By Tolulope Ogunsina on February 24, 2015, Skillset library of over 100,000 practice test questions, Troubleshooting Routers, Switches and Wireless Networks. The articles will give you the background on the topic and walk-through the packet tracer lab. Packet Tracer - Lab 1 : Basic switch setup 1 1 1 1 1 Rating 2.95 (330 Votes) Details Last Updated: Tuesday, 19 November 2019 20:46 Published: Tuesday, 07 September 2010 19:25 Written by PacketTracerNetwork. Configure the IP address of the switch as and it's default gateway IP ( When SSH is enabled, a user will be authenticated with a username and a password (unlike Telnet that can use only a password). 2. Along your journey to exam readiness, we will: 1. The configuration to achieve this task on R2 is as follows: To verify that only SSH is allowed, let’s try to open a Telnet connection to R2: Note: On a real device, it will not say “Open” and then close. Etherchannel is the port link aggregation technology invented by a company named Kalpana. R1’s IP address should be while R2’s should be Stay up to date with InfoSec Institute and Intense School by connecting with us on Social Media! He has multiple years of experience in the design, implementation and support of network and security technologies. Configure Switch hostname as LOCAL-SWITCH, Configure the message of the day as "Unauthorized access is forbidden", Configure the password for privileged mode access as "cisco". This user should be placed at privilege level 2 when he connects via SSH. We analyze your responses and can determine when you are ready to sit for the test. Fa0/0, Gi0/0) are in the shutdown state so we need to bring them up using the no shutdown command. Open’up’the’program.’ 2. Packet’Tracer’For’BeginnersTutorial’ Part1’ 1. Configure the IP address of the switch as and it's default gateway IP ( *shivers*. It support most routing, switching, wireless, and basic firewall devices with latest IOS. There are a couple of things to note if you want to use SSH to manage a Cisco device remotely: This task also requires that different users be placed at different privilege levels.

This brings us to the end of this lab where we have looked at the basics of configuring a Cisco router including setting hostnames, configuring IP addresses and enabling various remote access management features. Cisco Packet Tracer for Beginners: Chapter 7 – Configuring etherchannel on a Cisco Switch.

Test telnet connectivity from the Remote Laptop using the telnet client. Configure the link between R1 and R2 to be on the network As a Cisco certified professional (CCENT or CCNA), it is very important to know the basic Cisco switch configuration commands to improve the performances and the security of the enterprise network. Track your progress towards a certification exam.

Configure an enable password of "cisco123" on R1 and also a password of "cisco123" on the VTY lines. Configure another user "cisco2" on R2 with a password of "cisco2123".

Even if we use the service password-encryption command, the encryption algorithm offered by this command is so weak. The configuration to meet this task on the devices is as follows: One of the easiest ways to verify your interface settings is to use the show ip interface brief command because it gives a nice summary of the interfaces, their IP addresses and their link/protocol status: From a security standpoint, configuring an enable password is not recommended because it is stored in clear text in the router's configuration. When users open a remote management session (via Telnet) to R1, the following warning should be displayed at login: "AUTHORIZED PERSONNEL ONLY!". However, since that is what the task asks for, let's go ahead with the configuration: To confirm that the passwords are not stored in clear text (due to the service password-encryption command), we can view the running configuration: Hint: To see how easy it is to crack this type of password, paste "0822455D0A16544541" in the 'Type 7 Password' field on this web page: http://www.ifm.net.nz/cookbooks/passwordcracker.html. While going through the Packet Tracer labs on the Intense School site, I noticed that there was none that covered the basic router configurations using the CLI (Section 4.2 of the exam objectives) and so, we will be doing that in this lab. Trademark notice : This web site and/or material is not affiliated with, endorsed by, or sponsored by Cisco Systems, Inc. Cisco, Cisco Systems, Cisco IOS, CCNA, CCNP, Networking Academy, Linksys are registered trademarks of Cisco Systems, Inc. or its affiliates in the U.S. or certain other countries. Since we are using the local DB for authentication, we must configure the privilege levels for each username, so configuring the privilege level on the line will not work.

Our lab setup for this article is very simple as shown below: Note: Do not enable AAA for any of the tasks. You need to configure the switch with setup mode or from scratch using the command line interface (CLI) before connecting it in your network environment.

By using our site, you agree to our use of cookies. Therefore, you need to choose a character that will not appear in the body of your banner; good options include %, ^ and $. You also need to generate an RSA key pair of at least 768 bits for SSHv2 to be enabled. Configure the password for privileged mode access as "cisco". 5.0 01 Configuring etherchannel on a Cisco switch. To view this banner, we can open a telnet connection to R1: One of the most important things you should remember to do is save the configuration you have made on your devices (and back them up). Configure a username of "cisco" with a password of "cisco123" on R2. Learn network troubleshooting skills on a large range of Cisco simulated network devices. When you turn on a new Cisco IOS device and connect to it via the console, you may see the System Configuration Dialog shown below which can help you configure basic settings on the device: I have not used this System Configuration Dialog in the real world and I'm not sure I know anyone who has so we just answer "no" and are presented with the router prompt (User EXEC mode). He's a CCIE (Security) with a new found love in writing. This simulation software will help you quickly create a lab and start configuring like a real Cisco devices. Subnetting Practice .


