Routelearn.net
Course menu

Course 1: Cisco IOSLesson 1.2 (2 of 5 in this course)2 of 91 in the CCNA series

Initial switch and router setup

Hostname, passwords, banners, management IP and default gateway, interface descriptions and basic interface settings.

Beginner · 12 min read

Baseline configuration is the minimum set of settings applied to every network device regardless of its role: a hostname, an enable secret, console and VTY line protection, a banner, a management IP address with a default gateway, and basic interface settings. It makes the device identifiable, protected and remotely manageable.

In simple terms: It's the first set of commands you give any new router or switch. You name it, lock it with passwords and give it an address so you can manage it from your desk.

A real-life situation

Your branch office has a new router, R1, and a new switch, SW1. Out of the box both are called Router and Switch, anyone with a console cable gets full access, and you can only manage them by standing next to them. Before they carry any traffic you give each one a baseline configuration: a name, passwords, a warning banner, a management address and tidy interfaces.

Gi0/0198.51.100.2/30Gi0/1Gi1/0/24Gi1/0/1Gi0/2ISP198.51.100.1R1Gi0/1 192.168.10.1SW1Vlan1 192.168.10.2Admin PC192.168.10.10Admin, other LAN192.168.20.10
  1. 1. Same subnet: the admin PC reaches SW1's management address directly. No gateway needed.
  2. 2. From another subnet: a session from 192.168.20.0/24 reaches SW1 through R1.
  3. 3. The reply needs ip default-gateway: SW1 must know to send off-subnet replies to 192.168.10.1, or the session never completes.

What a baseline configuration is

A baseline is the small set of settings every device in a network should have, whatever its job. It makes the device identifiable, protects access to it, and lets you manage it remotely. On the CCNA you are expected to type it from memory.

Identify
hostname, banner
Protect
enable secret, line passwords
Reach
management IP, gateway
Interfaces
description, speed, shutdown
Save
copy run start
The order that makes sense on a new device: identify it, lock it, then make it reachable.

Why it works that way

  • Hostname: the prompt changes to the name, so you always know which device you are typing on. It also appears in CDP, logs and SSH keys.
  • Separate passwords per entry point: the console, the remote VTY (virtual terminal) lines and privileged EXEC are three different doors. Each needs its own lock.
  • A switch's IP lives on an SVI: a Layer 2 switch port has no IP address. Instead you give an address to a switched virtual interface (SVI), a virtual interface for one VLAN, such as interface vlan 1. The switch answers management traffic on that VLAN.
  • Router interfaces start shut down: on most Cisco routers every interface is administratively down until you type no shutdown, so a new router never leaks traffic by accident. Switch ports are the opposite: they are enabled by default, so a switch works the moment you plug it in.

How it works step by step

  1. You connect to the console and enter global configuration (see CLI modes and navigation).
  2. hostname renames the device. The prompt changes right away.
  3. enable secret protects the move from > to #. It is stored as a hash.
  4. Under line console 0 and line vty, password sets a password and login tells the line to ask for it. Without login the password is never checked.
  5. An IP address on a routed interface (router) or an SVI (switch) makes the device reachable. A switch also needs ip default-gateway to reply to other subnets.
  6. You save with copy running-config startup-config, or everything is lost at the next reload.

How to configure it on Cisco IOS

⚠️ Based on Cisco IOS / IOS XE documentation, not run on a lab device. Line passwords are shown for learning; in production use local usernames and SSH, covered in Passwords, local users and SSH.

Settings shared by the router and the switch

hostname R1 enable secret Str0ng-Enable! service password-encryption no ip domain-lookup banner motd # Authorised access only. Activity is logged. #

Global configuration. The banner text goes between two copies of a delimiter character (# here) that doesn't appear in the message.

line console 0 password C0nsole-Pass login logging synchronous exec-timeout 10 0 line vty 0 4 password Vty-Pass login transport input ssh exec-timeout 10 0

Console and remote lines. Routers usually have VTY 0 4 (five sessions); Catalyst switches have VTY 0 15 as well. transport input ssh refuses Telnet, but SSH also needs a domain name, RSA keys and a local user.

Router interfaces (R1)

interface GigabitEthernet0/0 description WAN to ISP ip address 198.51.100.2 255.255.255.252 no shutdown interface GigabitEthernet0/1 description LAN to SW1 Gi1/0/24 ip address 192.168.10.1 255.255.255.0 no shutdown interface GigabitEthernet0/2 description LAN 192.168.20.0/24 ip address 192.168.20.1 255.255.255.0 no shutdown interface GigabitEthernet0/3 description Unused shutdown

Each interface needs an address in its own subnet and no shutdown. The description is free text that shows up in show interfaces description.

Switch management and ports (SW1)

hostname SW1 interface vlan 1 description Management SVI ip address 192.168.10.2 255.255.255.0 no shutdown exit ip default-gateway 192.168.10.1 interface GigabitEthernet1/0/1 description Admin PC speed auto duplex auto interface GigabitEthernet1/0/24 description Uplink to R1 Gi0/1 interface range GigabitEthernet1/0/2 - 23 description Unused shutdown

The SVI is the switch's management address. ip default-gateway is for a Layer 2 switch (one without ip routing enabled). Shutting unused ports is a basic security step.

Leave speed and duplex on auto unless you have a reason not to. If you hard-code them on one end, hard-code the same values on the other end, or you risk a duplex mismatch (see Speed and duplex). In real networks, management usually goes on its own VLAN rather than VLAN 1; the VLANs and trunks lesson shows how.

How to verify it

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ip interface brief
Interface              IP-Address      OK? Method Status                Protocol
GigabitEthernet0/0     198.51.100.2    YES manual up                    up
GigabitEthernet0/1     192.168.10.1    YES manual up                    up
GigabitEthernet0/2     192.168.20.1    YES manual up                    up
GigabitEthernet0/3     unassigned      YES unset  administratively down down
manual means the address was typed in this session (after a reload it shows NVRAM). Gi0/3 is down on purpose.
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show interfaces description
Interface                      Status         Protocol Description
Gi0/0                          up             up       WAN to ISP
Gi0/1                          up             up       LAN to SW1 Gi1/0/24
Gi0/2                          up             up       LAN 192.168.20.0/24
Gi0/3                          admin down     down     Unused
A quick map of what each port is for, straight from your descriptions.
Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show ip interface brief | include Vlan|1/0/1 |1/0/24
Vlan1                  192.168.10.2    YES manual up                    up
GigabitEthernet1/0/1   unassigned      YES unset  up                    up
GigabitEthernet1/0/24  unassigned      YES unset  up                    up
The SVI is up/up. An SVI only comes up when at least one port in that VLAN is up (and the VLAN exists).
Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show running-config | include default-gateway|hostname
hostname SW1
ip default-gateway 192.168.10.1
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show running-config | section line
line con 0
 exec-timeout 10 0
 password 7 0822455D0A16544541
 logging synchronous
 login
line vty 0 4
 exec-timeout 10 0
 password 7 01100F175804575D72
 login
 transport input ssh
With service password-encryption on, line passwords show as type 7, a weak reversible encoding. The enable secret appears as a hash (type 5, or type 8/9 on newer releases) and can't be reversed.
Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#ping 192.168.10.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.10.1, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/2 ms
The first dot is normal: the switch was busy resolving R1's MAC address with ARP and the first echo timed out.

What goes wrong and how to troubleshoot it

SymptomLikely causeFix
Router interface is administratively downNever enabledno shutdown on the interface
SVI Vlan1 is down/downNo port in VLAN 1 is up, or the SVI is shut downConnect a port in the VLAN; no shutdown on the SVI
Switch reachable from its own subnet onlyNo default gatewayip default-gateway 192.168.10.1
Telnet/SSH says Password required, but none setlogin with no password on the VTY linesSet a password, or use login local with a username
Console never asks for a passwordpassword set but login missingAdd login under line console 0
Interface up/down or many errorsSpeed or duplex mismatchSet both ends to auto, or both to the same fixed values

Common mistakes

  • Using enable password instead of enable secret. If both exist, the secret wins.
  • Configuring VTY 0 4 on a switch and leaving VTY 5 15 open with different settings.
  • Putting ip address on a switch's physical access port. Layer 2 ports don't take addresses; use the SVI.
  • Using ip default-gateway on a router or a Layer 3 switch with ip routing enabled. It is ignored there; those devices use a default route.
  • Choosing a banner delimiter that appears in the message, which ends the banner early.
  • Forgetting to save, then losing the whole baseline at the next reload.

💡 Exam tip: the exam likes small differences. Know that enable secret beats enable password, that service password-encryption only gives weak type 7 encoding, that login is what makes a line ask for its password, and that a Layer 2 switch is managed through an SVI plus ip default-gateway. Be ready to spot a missing no shutdown in a configuration exhibit.

Key takeaways

  • Every device gets a hostname, enable secret, console and VTY protection, a banner and a management address.
  • password + login on a line; enable secret for privileged EXEC.
  • A Layer 2 switch is managed through an SVI and needs ip default-gateway for remote access.
  • Router interfaces need no shutdown; switch ports are on by default, so shut unused ones.
  • Describe interfaces and save the configuration when you are done.

Check yourself

Predict · scenario 1

A router has both 'enable password cisco' and 'enable secret class'. Which password does enable accept?

Predict · scenario 2

SW1's SVI is 192.168.10.2/24 and up/up. Hosts in 192.168.10.0/24 can SSH to it, but an admin at 192.168.20.10 can't. What is most likely missing?

Predict · scenario 3

Under line console 0 you typed 'password C0nsole-Pass' but the console still lets anyone in without a prompt. What is missing?

Predict · scenario 4

show ip interface brief on a new router shows Gi0/1 with an IP address but 'administratively down'. What do you do?

Predict · scenario 5

After 'service password-encryption', the VTY password shows as 'password 7 0110...'. How secure is it?

FAQ

What is the difference between enable password and enable secret?
Both protect privileged EXEC mode. enable password is stored in clear text (or with the weak type 7 encoding if service password-encryption is on). enable secret is stored as a one-way hash. If both are set, IOS uses enable secret and ignores enable password. Always use enable secret.
Why does a Layer 2 switch need an IP address at all?
It doesn't need one to forward frames. The IP address, set on a VLAN interface (SVI), is only for managing the switch: SSH, SNMP, syslog, NTP and so on. Without it, the only way in is the console port.
Why can I reach my switch from the same subnet but not from another network?
The switch is missing ip default-gateway. It can answer hosts on its own subnet directly, but it has no idea where to send replies to anything else. Point the default gateway at the router on the management subnet.
Does service password-encryption make passwords secure?
No. It applies type 7 encoding, which can be reversed in seconds. It only stops someone reading a password over your shoulder or in a printout. Use enable secret and hashed local user secrets for real protection.