A real-life situation
Your branch office has a new router, R1, and a new switch, SW1. Out of the box both are called Router and Switch, anyone with a console cable gets full access, and you can only manage them by standing next to them. Before they carry any traffic you give each one a baseline configuration: a name, passwords, a warning banner, a management address and tidy interfaces.
- 1. Same subnet: the admin PC reaches SW1's management address directly. No gateway needed.
- 2. From another subnet: a session from 192.168.20.0/24 reaches SW1 through R1.
- 3. The reply needs ip default-gateway: SW1 must know to send off-subnet replies to 192.168.10.1, or the session never completes.
What a baseline configuration is
A baseline is the small set of settings every device in a network should have, whatever its job. It makes the device identifiable, protects access to it, and lets you manage it remotely. On the CCNA you are expected to type it from memory.
Why it works that way
- Hostname: the prompt changes to the name, so you always know which device you are typing on. It also appears in CDP, logs and SSH keys.
- Separate passwords per entry point: the console, the remote VTY (virtual terminal) lines and privileged EXEC are three different doors. Each needs its own lock.
- A switch's IP lives on an SVI: a Layer 2 switch port has no IP address. Instead you give an address to a switched virtual interface (SVI), a virtual interface for one VLAN, such as
interface vlan 1. The switch answers management traffic on that VLAN. - Router interfaces start shut down: on most Cisco routers every interface is administratively down until you type
no shutdown, so a new router never leaks traffic by accident. Switch ports are the opposite: they are enabled by default, so a switch works the moment you plug it in.
How it works step by step
- You connect to the console and enter global configuration (see CLI modes and navigation).
hostnamerenames the device. The prompt changes right away.enable secretprotects the move from>to#. It is stored as a hash.- Under
line console 0andline vty,passwordsets a password andlogintells the line to ask for it. Withoutloginthe password is never checked. - An IP address on a routed interface (router) or an SVI (switch) makes the device reachable. A switch also needs
ip default-gatewayto reply to other subnets. - You save with
copy running-config startup-config, or everything is lost at the next reload.
How to configure it on Cisco IOS
⚠️ Based on Cisco IOS / IOS XE documentation, not run on a lab device. Line passwords are shown for learning; in production use local usernames and SSH, covered in Passwords, local users and SSH.
Settings shared by the router and the switch
hostname R1
enable secret Str0ng-Enable!
service password-encryption
no ip domain-lookup
banner motd # Authorised access only. Activity is logged. #Global configuration. The banner text goes between two copies of a delimiter character (# here) that doesn't appear in the message.
line console 0
password C0nsole-Pass
login
logging synchronous
exec-timeout 10 0
line vty 0 4
password Vty-Pass
login
transport input ssh
exec-timeout 10 0Console and remote lines. Routers usually have VTY 0 4 (five sessions); Catalyst switches have VTY 0 15 as well. transport input ssh refuses Telnet, but SSH also needs a domain name, RSA keys and a local user.
Router interfaces (R1)
interface GigabitEthernet0/0
description WAN to ISP
ip address 198.51.100.2 255.255.255.252
no shutdown
interface GigabitEthernet0/1
description LAN to SW1 Gi1/0/24
ip address 192.168.10.1 255.255.255.0
no shutdown
interface GigabitEthernet0/2
description LAN 192.168.20.0/24
ip address 192.168.20.1 255.255.255.0
no shutdown
interface GigabitEthernet0/3
description Unused
shutdownEach interface needs an address in its own subnet and no shutdown. The description is free text that shows up in show interfaces description.
Switch management and ports (SW1)
hostname SW1
interface vlan 1
description Management SVI
ip address 192.168.10.2 255.255.255.0
no shutdown
exit
ip default-gateway 192.168.10.1
interface GigabitEthernet1/0/1
description Admin PC
speed auto
duplex auto
interface GigabitEthernet1/0/24
description Uplink to R1 Gi0/1
interface range GigabitEthernet1/0/2 - 23
description Unused
shutdownThe SVI is the switch's management address. ip default-gateway is for a Layer 2 switch (one without ip routing enabled). Shutting unused ports is a basic security step.
Leave speed and duplex on auto unless you have a reason not to. If you hard-code them on one end, hard-code the same values on the other end, or you risk a duplex mismatch (see Speed and duplex). In real networks, management usually goes on its own VLAN rather than VLAN 1; the VLANs and trunks lesson shows how.
How to verify it
R1#show ip interface brief Interface IP-Address OK? Method Status Protocol GigabitEthernet0/0 198.51.100.2 YES manual up up GigabitEthernet0/1 192.168.10.1 YES manual up up GigabitEthernet0/2 192.168.20.1 YES manual up up GigabitEthernet0/3 unassigned YES unset administratively down down
R1#show interfaces description Interface Status Protocol Description Gi0/0 up up WAN to ISP Gi0/1 up up LAN to SW1 Gi1/0/24 Gi0/2 up up LAN 192.168.20.0/24 Gi0/3 admin down down Unused
SW1#show ip interface brief | include Vlan|1/0/1 |1/0/24 Vlan1 192.168.10.2 YES manual up up GigabitEthernet1/0/1 unassigned YES unset up up GigabitEthernet1/0/24 unassigned YES unset up up
SW1#show running-config | include default-gateway|hostname hostname SW1 ip default-gateway 192.168.10.1
R1#show running-config | section line line con 0 exec-timeout 10 0 password 7 0822455D0A16544541 logging synchronous login line vty 0 4 exec-timeout 10 0 password 7 01100F175804575D72 login transport input ssh
service password-encryption on, line passwords show as type 7, a weak reversible encoding. The enable secret appears as a hash (type 5, or type 8/9 on newer releases) and can't be reversed.SW1#ping 192.168.10.1 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 192.168.10.1, timeout is 2 seconds: .!!!! Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/2 ms
What goes wrong and how to troubleshoot it
| Symptom | Likely cause | Fix |
|---|---|---|
| Router interface is administratively down | Never enabled | no shutdown on the interface |
SVI Vlan1 is down/down | No port in VLAN 1 is up, or the SVI is shut down | Connect a port in the VLAN; no shutdown on the SVI |
| Switch reachable from its own subnet only | No default gateway | ip default-gateway 192.168.10.1 |
| Telnet/SSH says Password required, but none set | login with no password on the VTY lines | Set a password, or use login local with a username |
| Console never asks for a password | password set but login missing | Add login under line console 0 |
| Interface up/down or many errors | Speed or duplex mismatch | Set both ends to auto, or both to the same fixed values |
Common mistakes
- Using
enable passwordinstead ofenable secret. If both exist, the secret wins. - Configuring VTY 0 4 on a switch and leaving VTY 5 15 open with different settings.
- Putting
ip addresson a switch's physical access port. Layer 2 ports don't take addresses; use the SVI. - Using
ip default-gatewayon a router or a Layer 3 switch withip routingenabled. It is ignored there; those devices use a default route. - Choosing a banner delimiter that appears in the message, which ends the banner early.
- Forgetting to save, then losing the whole baseline at the next reload.
💡 Exam tip: the exam likes small differences. Know that enable secret beats enable password, that service password-encryption only gives weak type 7 encoding, that login is what makes a line ask for its password, and that a Layer 2 switch is managed through an SVI plus ip default-gateway. Be ready to spot a missing no shutdown in a configuration exhibit.
Key takeaways
- Every device gets a hostname, enable secret, console and VTY protection, a banner and a management address.
password+loginon a line;enable secretfor privileged EXEC.- A Layer 2 switch is managed through an SVI and needs
ip default-gatewayfor remote access. - Router interfaces need
no shutdown; switch ports are on by default, so shut unused ones. - Describe interfaces and save the configuration when you are done.
Check yourself
A router has both 'enable password cisco' and 'enable secret class'. Which password does enable accept?
SW1's SVI is 192.168.10.2/24 and up/up. Hosts in 192.168.10.0/24 can SSH to it, but an admin at 192.168.20.10 can't. What is most likely missing?
Under line console 0 you typed 'password C0nsole-Pass' but the console still lets anyone in without a prompt. What is missing?
show ip interface brief on a new router shows Gi0/1 with an IP address but 'administratively down'. What do you do?
After 'service password-encryption', the VTY password shows as 'password 7 0110...'. How secure is it?