Routelearn.net
Course menu

Course 13: Security FundamentalsLesson 2.1 (4 of 8 in this course)82 of 91 in the CCNA series

Passwords, local users and SSH

Securing console, VTY and enable access, local usernames, password encryption and configuring SSH.

Intermediate · 10 min read

Device access security means protecting the management access to a router or switch: securing the console and VTY lines with individual local user accounts and hashed secrets, using SSH instead of Telnet for encrypted remote sessions, and limiting which addresses may connect.

In simple terms: It is about locking the doors you use to manage a network device, so only the right people can log in and nobody can read their passwords on the way.

A real-life situation

A security audit of the branch finds that SW1 can be reached with Telnet, every engineer shares the same VTY password, and that password is cisco. Worse, the auditor ran a packet capture on a desk port and read the password as it crossed the network. Nothing in the logs says who changed what last week, because everyone logs in the same way. This lesson fixes all of it: strong hashed secrets, a personal account for each admin, and SSH instead of Telnet.

Gi1/0/2Gi1/0/5Gi1/0/24Gi0/1Admin PC192.168.10.10SW1Vlan10 192.168.10.2R1Gi0/1 192.168.10.1listeningEavesdroppersame VLAN
  1. 1. Telnet sends everything in clear text. Username, password and every command can be read by anyone who captures the traffic, for example from a mirrored port.
  2. 2. SSH encrypts the whole session. The same login over SSH is unreadable to the eavesdropper. Only SW1 and the admin PC hold the session keys.
  3. 3. Telnet is refused. With transport input ssh on the VTY lines, SW1 rejects Telnet connections outright.

What you are protecting

A Cisco device has several ways in. Each one needs its own protection. If one is left open, the others don't matter.

Entry pointWhat it isProtected by
Console (line console 0)The physical console port, for someone standing next to the devicelogin local (or a line password)
VTY lines (line vty 0 15)Virtual terminal lines: remote sessions over the network (SSH or Telnet)login local, transport input ssh, optionally an ACL
Privileged EXECThe move from > to #, where everything can be changedenable secret, or a user with privilege 15

The basics of line passwords and the login command are in Initial switch and router setup. This lesson goes further: how passwords are stored, personal accounts, and SSH.

Why it works that way

How IOS stores passwords

A hash is a one-way calculation: easy to compute from a password, practically impossible to reverse. When you log in, IOS hashes what you type and compares it with the stored hash. The number IOS shows in front of a stored password is its type:

TypeWhat it isStrength
0Clear textNone
7Cisco's reversible encoding, from service password-encryptionVery weak: hides a password from a glance only
5MD5 hash, the classic enable secret defaultOld, but not reversible
8PBKDF2 with SHA-256Strong
9scryptStrong; the recommended choice

Newer IOS XE releases use type 9 for secret by default; on older ones you ask for it with algorithm-type scrypt.

Why personal accounts

A shared line password tells you only that someone logged in. With a local user database (usernames stored on the device) each admin has their own name, logs and show users show who is connected, and you can remove one person's access without changing everyone's password. In larger networks the user list moves to a central server; see AAA: RADIUS and TACACS+.

Why SSH

Telnet (TCP port 23) sends every keystroke as plain text. SSH (Secure Shell, TCP port 22) encrypts the whole session and lets the client check it is talking to the real device. More background is in SSH and Telnet. SSH needs an RSA key pair on the device: a public key it can share and a private key it keeps. The keys are what let the two ends agree on secret session keys safely.

How it works step by step

What happens when the admin PC opens an SSH session to SW1:

Step 1 of 5 · TCP handshake
Admin PC
192.168.10.10
VLAN 10
TCP port 22
SW1
192.168.10.2

How to configure it on Cisco IOS

⚠️ Based on Cisco IOS / IOS XE documentation, not run on a lab device. Create the local user before setting login local on the lines, or you can lock yourself out.

Hostname
not the default
Domain name
ip domain name
RSA keys
2048 bits
Local user
username ... secret
VTY lines
login local, ssh only
SSH has prerequisites. Each step depends on the one before.
hostname SW1 ip domain name example.com crypto key generate rsa modulus 2048 ip ssh version 2

Older releases spell it ip domain-name; both are accepted on current IOS XE. The key is named after hostname.domain.

Example output · based on Cisco documentation; exact format varies by platform and software version
SW1(config)#crypto key generate rsa modulus 2048
The name for the keys will be: SW1.example.com

% The key modulus size is 2048 bits
% Generating 2048 bit RSA keys, keys will be non-exportable...
[OK] (elapsed time was 2 seconds)
Generating the keys turns the SSH server on. Deleting them (crypto key zeroize rsa) turns it off.
enable algorithm-type scrypt secret En4ble-S3cret! username admin privilege 15 algorithm-type scrypt secret Adm1n-S3cret! username helpdesk privilege 1 algorithm-type scrypt secret H3lp-S3cret!

A type 9 enable secret and two personal accounts. privilege 15 lands in privileged EXEC; privilege 1 lands in user EXEC and must still type enable.

line console 0 login local exec-timeout 10 0 line vty 0 15 login local transport input ssh exec-timeout 10 0

Both lines ask for a username. transport input ssh refuses Telnet on the VTY lines. exec-timeout logs out an idle session after 10 minutes.

Extra hardening

service password-encryption security passwords min-length 10 login block-for 120 attempts 3 within 60 ip ssh time-out 60 ip ssh authentication-retries 3

Type 7 for any remaining clear-text passwords; a minimum length for new passwords; after 3 failed logins within 60 seconds, refuse all logins for 120 seconds; SSH login limits.

access-list 10 permit 192.168.10.0 0.0.0.255 line vty 0 15 access-class 10 in

Only allow SSH sessions from the management subnet. access-class filters who may connect to the VTY lines; the ACL syntax is covered in Standard ACLs.

Standard ACLs explains the wildcard mask in that ACL.

Full example for SW1

hostname SW1 ip domain name example.com enable algorithm-type scrypt secret En4ble-S3cret! username admin privilege 15 algorithm-type scrypt secret Adm1n-S3cret! service password-encryption security passwords min-length 10 login block-for 120 attempts 3 within 60 ! interface Vlan10 ip address 192.168.10.2 255.255.255.0 no shutdown ip default-gateway 192.168.10.1 ! crypto key generate rsa modulus 2048 ip ssh version 2 ! access-list 10 permit 192.168.10.0 0.0.0.255 line console 0 login local exec-timeout 10 0 line vty 0 15 access-class 10 in login local transport input ssh exec-timeout 10 0 ! end copy running-config startup-config

Everything together. The RSA keys are stored separately from the configuration file but survive a reload once generated.

How to verify it

Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show ip ssh
SSH Enabled - version 2.0
Authentication methods:publickey,keyboard-interactive,password
Authentication timeout: 60 secs; Authentication retries: 3
...
SSH Enabled - version 2.0 means keys exist and only version 2 is allowed. If it says version 1.99, both 1 and 2 are accepted: add ip ssh version 2.
Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show users
    Line       User       Host(s)              Idle       Location
*  0 con 0     admin      idle                 00:00:00
   1 vty 0     admin      idle                 00:00:41 192.168.10.10
Who is logged in, on which line, and from where. The asterisk is your own session.
Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show running-config | include username|enable
enable secret 9 $9$hJ2kT0bQ4xW8nE$Xb1...
username admin privilege 15 secret 9 $9$Cq7mL5vR3pZ1aD$Kp9...
secret 9: scrypt hashes. A password 7 anywhere here means a reversible password is still in use.

Test from R1, which has an SSH client built in:

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#ssh -l admin 192.168.10.2
Password:

SW1#

What goes wrong and how to troubleshoot it

Symptom or messageCauseFix
% Please define a hostname other than Switch.Generating keys with the default hostnameSet hostname first
% Please define a domain-name first.No domain nameip domain name example.com
SSH client: connection refusedNo RSA keys, or transport input excludes SSHshow ip ssh; generate keys; check the VTY lines
Login prompt rejects a correct username and passwordUser created with a typo, or login instead of login localshow running-config | section line
Password required, but none setlogin on a line with no passwordUse login local with a user, or set a password
SSH works from one subnet but not anotheraccess-class ACL doesn't permit that subnet, or no ip default-gatewayCheck the ACL counters and the gateway
All logins refused for two minuteslogin block-for quiet period after failed attemptsWait, or check show login

Password policies beyond the device

The CCNA also expects you to know the ideas behind good access control, not just the commands:

  • Password policy: minimum length, a mix of character types, no reuse, and changing passwords when someone leaves.
  • Multi-factor authentication (MFA): proving who you are with two or more different kinds of factor: something you know (a password), something you have (a phone app or token) and something you are (a fingerprint).
  • Certificates: a digital document, signed by a trusted authority, that proves a device or user owns a key. SSH public-key logins and 802.1X can use them instead of passwords.
  • Biometrics: fingerprints, faces or voices used as the "something you are" factor.

Common mistakes

  • Using enable password or username ... password instead of secret.
  • Thinking service password-encryption makes passwords safe. Type 7 is trivial to reverse.
  • Securing line vty 0 4 on a switch and forgetting VTY 5 to 15.
  • Setting login local before any username exists, then being locked out after the session ends.
  • Leaving SSH version 1 allowed (version 1.99 in show ip ssh).
  • Forgetting that generating RSA keys needs a hostname and a domain name first.

💡 Exam tip: be able to list the SSH steps in order (hostname, domain name, RSA keys, local user, login local, transport input ssh) and spot the missing one in a configuration. Know that enable secret overrides enable password, that type 7 is reversible while 5, 8 and 9 are hashes, that Telnet is TCP 23 and SSH is TCP 22, and that access-class (not access-group) applies an ACL to VTY lines. Questions on MFA, certificates and biometrics test the concepts, not commands.

Key takeaways

  • Protect every entry point: console, VTY lines and privileged EXEC.
  • Use secret, never password; type 9 (scrypt) is the strongest.
  • Personal usernames plus login local give accountability.
  • SSH needs a hostname, domain name, RSA keys and a user; then transport input ssh.
  • Limit VTY access with access-class, idle timeouts and login blocking.

Check yourself

Predict · scenario 1

You type crypto key generate rsa on a new switch and get: % Please define a hostname other than Switch. What do you do?

Predict · scenario 2

A configuration has both enable password Cisco123 and enable secret Str0ng!. Which one unlocks privileged EXEC?

Predict · scenario 3

show running-config shows: username admin password 7 0822455D0A16. How safe is this password?

Predict · scenario 4

VTY lines have login local and transport input ssh, and SSH keys exist. An admin can SSH in from 192.168.10.10 but not from 192.168.20.10. What is a likely cause?

Predict · scenario 5

Which pair is an example of multi-factor authentication?

FAQ

What is the difference between password and secret?
A password (enable password, or username ... password) is stored in clear text, or as type 7 if service password-encryption is on, and type 7 can be reversed in seconds. A secret (enable secret, or username ... secret) is stored as a one-way hash that cannot be turned back into the password. Always use secret.
Why does SSH need a domain name?
The router names its RSA key pair after its hostname and domain name, for example SW1.example.com. Without a hostname other than the default and an ip domain name, crypto key generate rsa refuses to run, and without keys SSH can't start.
What does login local do?
It tells a line (console or VTY) to ask for a username and password and check them against the usernames configured on the device, instead of using a single shared line password. Each person gets their own account, and logs show who did what.
Should I still use SSH version 1?
No. Version 1 has known weaknesses. Use ip ssh version 2 so the device refuses version 1 clients. Version 2 needs an RSA key of at least 768 bits; use 2048 bits or more.