A real-life situation
A security audit of the branch finds that SW1 can be reached with Telnet, every engineer shares the same VTY password, and that password is cisco. Worse, the auditor ran a packet capture on a desk port and read the password as it crossed the network. Nothing in the logs says who changed what last week, because everyone logs in the same way. This lesson fixes all of it: strong hashed secrets, a personal account for each admin, and SSH instead of Telnet.
- 1. Telnet sends everything in clear text. Username, password and every command can be read by anyone who captures the traffic, for example from a mirrored port.
- 2. SSH encrypts the whole session. The same login over SSH is unreadable to the eavesdropper. Only SW1 and the admin PC hold the session keys.
- 3. Telnet is refused. With transport input ssh on the VTY lines, SW1 rejects Telnet connections outright.
What you are protecting
A Cisco device has several ways in. Each one needs its own protection. If one is left open, the others don't matter.
| Entry point | What it is | Protected by |
|---|---|---|
Console (line console 0) | The physical console port, for someone standing next to the device | login local (or a line password) |
VTY lines (line vty 0 15) | Virtual terminal lines: remote sessions over the network (SSH or Telnet) | login local, transport input ssh, optionally an ACL |
| Privileged EXEC | The move from > to #, where everything can be changed | enable secret, or a user with privilege 15 |
The basics of line passwords and the login command are in Initial switch and router setup. This lesson goes further: how passwords are stored, personal accounts, and SSH.
Why it works that way
How IOS stores passwords
A hash is a one-way calculation: easy to compute from a password, practically impossible to reverse. When you log in, IOS hashes what you type and compares it with the stored hash. The number IOS shows in front of a stored password is its type:
| Type | What it is | Strength |
|---|---|---|
| 0 | Clear text | None |
| 7 | Cisco's reversible encoding, from service password-encryption | Very weak: hides a password from a glance only |
| 5 | MD5 hash, the classic enable secret default | Old, but not reversible |
| 8 | PBKDF2 with SHA-256 | Strong |
| 9 | scrypt | Strong; the recommended choice |
Newer IOS XE releases use type 9 for secret by default; on older ones you ask for it with algorithm-type scrypt.
Why personal accounts
A shared line password tells you only that someone logged in. With a local user database (usernames stored on the device) each admin has their own name, logs and show users show who is connected, and you can remove one person's access without changing everyone's password. In larger networks the user list moves to a central server; see AAA: RADIUS and TACACS+.
Why SSH
Telnet (TCP port 23) sends every keystroke as plain text. SSH (Secure Shell, TCP port 22) encrypts the whole session and lets the client check it is talking to the real device. More background is in SSH and Telnet. SSH needs an RSA key pair on the device: a public key it can share and a private key it keeps. The keys are what let the two ends agree on secret session keys safely.
How it works step by step
What happens when the admin PC opens an SSH session to SW1:
How to configure it on Cisco IOS
⚠️ Based on Cisco IOS / IOS XE documentation, not run on a lab device. Create the local user before setting login local on the lines, or you can lock yourself out.
hostname SW1
ip domain name example.com
crypto key generate rsa modulus 2048
ip ssh version 2Older releases spell it ip domain-name; both are accepted on current IOS XE. The key is named after hostname.domain.
SW1(config)#crypto key generate rsa modulus 2048 The name for the keys will be: SW1.example.com % The key modulus size is 2048 bits % Generating 2048 bit RSA keys, keys will be non-exportable... [OK] (elapsed time was 2 seconds)
crypto key zeroize rsa) turns it off.enable algorithm-type scrypt secret En4ble-S3cret!
username admin privilege 15 algorithm-type scrypt secret Adm1n-S3cret!
username helpdesk privilege 1 algorithm-type scrypt secret H3lp-S3cret!A type 9 enable secret and two personal accounts. privilege 15 lands in privileged EXEC; privilege 1 lands in user EXEC and must still type enable.
line console 0
login local
exec-timeout 10 0
line vty 0 15
login local
transport input ssh
exec-timeout 10 0Both lines ask for a username. transport input ssh refuses Telnet on the VTY lines. exec-timeout logs out an idle session after 10 minutes.
Extra hardening
service password-encryption
security passwords min-length 10
login block-for 120 attempts 3 within 60
ip ssh time-out 60
ip ssh authentication-retries 3Type 7 for any remaining clear-text passwords; a minimum length for new passwords; after 3 failed logins within 60 seconds, refuse all logins for 120 seconds; SSH login limits.
access-list 10 permit 192.168.10.0 0.0.0.255
line vty 0 15
access-class 10 inOnly allow SSH sessions from the management subnet. access-class filters who may connect to the VTY lines; the ACL syntax is covered in Standard ACLs.
Standard ACLs explains the wildcard mask in that ACL.
Full example for SW1
hostname SW1
ip domain name example.com
enable algorithm-type scrypt secret En4ble-S3cret!
username admin privilege 15 algorithm-type scrypt secret Adm1n-S3cret!
service password-encryption
security passwords min-length 10
login block-for 120 attempts 3 within 60
!
interface Vlan10
ip address 192.168.10.2 255.255.255.0
no shutdown
ip default-gateway 192.168.10.1
!
crypto key generate rsa modulus 2048
ip ssh version 2
!
access-list 10 permit 192.168.10.0 0.0.0.255
line console 0
login local
exec-timeout 10 0
line vty 0 15
access-class 10 in
login local
transport input ssh
exec-timeout 10 0
!
end
copy running-config startup-configEverything together. The RSA keys are stored separately from the configuration file but survive a reload once generated.
How to verify it
SW1#show ip ssh SSH Enabled - version 2.0 Authentication methods:publickey,keyboard-interactive,password Authentication timeout: 60 secs; Authentication retries: 3 ...
ip ssh version 2.SW1#show users Line User Host(s) Idle Location * 0 con 0 admin idle 00:00:00 1 vty 0 admin idle 00:00:41 192.168.10.10
SW1#show running-config | include username|enable enable secret 9 $9$hJ2kT0bQ4xW8nE$Xb1... username admin privilege 15 secret 9 $9$Cq7mL5vR3pZ1aD$Kp9...
password 7 anywhere here means a reversible password is still in use.Test from R1, which has an SSH client built in:
R1#ssh -l admin 192.168.10.2 Password: SW1#
What goes wrong and how to troubleshoot it
| Symptom or message | Cause | Fix |
|---|---|---|
| % Please define a hostname other than Switch. | Generating keys with the default hostname | Set hostname first |
| % Please define a domain-name first. | No domain name | ip domain name example.com |
| SSH client: connection refused | No RSA keys, or transport input excludes SSH | show ip ssh; generate keys; check the VTY lines |
| Login prompt rejects a correct username and password | User created with a typo, or login instead of login local | show running-config | section line |
| Password required, but none set | login on a line with no password | Use login local with a user, or set a password |
| SSH works from one subnet but not another | access-class ACL doesn't permit that subnet, or no ip default-gateway | Check the ACL counters and the gateway |
| All logins refused for two minutes | login block-for quiet period after failed attempts | Wait, or check show login |
Password policies beyond the device
The CCNA also expects you to know the ideas behind good access control, not just the commands:
- Password policy: minimum length, a mix of character types, no reuse, and changing passwords when someone leaves.
- Multi-factor authentication (MFA): proving who you are with two or more different kinds of factor: something you know (a password), something you have (a phone app or token) and something you are (a fingerprint).
- Certificates: a digital document, signed by a trusted authority, that proves a device or user owns a key. SSH public-key logins and 802.1X can use them instead of passwords.
- Biometrics: fingerprints, faces or voices used as the "something you are" factor.
Common mistakes
- Using
enable passwordorusername ... passwordinstead ofsecret. - Thinking
service password-encryptionmakes passwords safe. Type 7 is trivial to reverse. - Securing
line vty 0 4on a switch and forgetting VTY 5 to 15. - Setting
login localbefore any username exists, then being locked out after the session ends. - Leaving SSH version 1 allowed (version 1.99 in
show ip ssh). - Forgetting that generating RSA keys needs a hostname and a domain name first.
💡 Exam tip: be able to list the SSH steps in order (hostname, domain name, RSA keys, local user, login local, transport input ssh) and spot the missing one in a configuration. Know that enable secret overrides enable password, that type 7 is reversible while 5, 8 and 9 are hashes, that Telnet is TCP 23 and SSH is TCP 22, and that access-class (not access-group) applies an ACL to VTY lines. Questions on MFA, certificates and biometrics test the concepts, not commands.
Key takeaways
- Protect every entry point: console, VTY lines and privileged EXEC.
- Use
secret, neverpassword; type 9 (scrypt) is the strongest. - Personal usernames plus
login localgive accountability. - SSH needs a hostname, domain name, RSA keys and a user; then
transport input ssh. - Limit VTY access with
access-class, idle timeouts and login blocking.
Check yourself
You type crypto key generate rsa on a new switch and get: % Please define a hostname other than Switch. What do you do?
A configuration has both enable password Cisco123 and enable secret Str0ng!. Which one unlocks privileged EXEC?
show running-config shows: username admin password 7 0822455D0A16. How safe is this password?
VTY lines have login local and transport input ssh, and SSH keys exist. An admin can SSH in from 192.168.10.10 but not from 192.168.20.10. What is a likely cause?
Which pair is an example of multi-factor authentication?