26.2.4 Packet Tracer - Configure Secure Passwords and SSH (Answers)
Topology

26.2.4 Packet Tracer - Configure Secure Passwords and SSH
Addressing Table
| Device | Interface | IP Address | Subnet Mask | Default Gateway |
|---|---|---|---|---|
| RTA | G0/0 | 172.16.1.1 | 255.255.255.0 | N/A |
| PCA | NIC | 172.16.1.10 | 255.255.255.0 | 172.16.1.1 |
| SW1 | VLAN 1 | 172.16.1.2 | 255.255.255.0 | 172.16.1.1 |
Scenario
The network administrator has asked you to prepare RTA and SW1 for deployment. Before they can be connected to the network, security measures must be enabled.
Intructions
Step 1: Configure Basic Security on the Router
a. Configure IP addressing on PCA according to the Addressing Table.
b. Console into RTA from the Terminal on PCA.
c. Configure the hostname as RTA.
d. Configure IP addressing on RTA and enable the interface.
e. Encrypt all plaintext passwords.
RTA(config)# service password-encryption
f. Set the minimum password length to 10.
RTA(config)# security password min-length 10
g. Set a strong secret password of your choosing. Note: Choose a password that you will remember, or you will need to reset the activity if you are locked out of the device.
h. Disable DNS lookup.
RTA(config)# no ip domain-lookup
i. Set the domain name to CCNA.com (case-sensitive for scoring in PT).
RTA(config)# ip domain-name CCNA.com
j. Create a user of your choosing with a strong encrypted password.
RTA(config)# username any_user secret any_password
k. Generate 1024-bit RSA keys.
Note: In Packet Tracer, enter the crypto key generate rsa command and press Enter to continue.
RTA(config)# crypto key generate rsa The name for the keys will be: RTA.CCNA.com Choose the size of the key modulus in the range of 360 to 2048 for your General Purpose Keys. Choosing a key modulus greater than 512 may take a few minutes. How many bits in the modulus [512]: 1024
l. Block anyone for three minutes who fails to log in after four attempts within a two-minute period.
RTA(config)# login block-for 180 attempts 4 within 120
m. Configure all VTY lines for SSH access and use the local user profiles for authentication.
RTA(config)# line vty 0 4 RTA(config-line)# transport input ssh RTA(config-line)# login local
n. Set the EXEC mode timeout to 6 minutes on the VTY lines.
RTA(config-line)# exec-timeout 6
o. Save the configuration to NVRAM.
p. Access the command prompt on the desktop of PCA to establish an SSH connection to RTA.
C:\> ssh /? Packet Tracer PC SSH Usage: SSH -l username target C:\>
Step 2: Configure Basic Security on the Switch
Configure switch SW1 with corresponding security measures. Refer to the configuration steps on the router if you need additional assistance.
a. Click on SW1 and select the CLI
b. Configure the hostname as SW1.
c. Configure IP addressing on SW1 VLAN1 and enable the interface.
d. Configure the default gateway address.
e. Disable all unused switch ports.
Note: On a switch it is a good security practice to disable unused ports. One method of doing this is to simply shut down each port with the ‘shutdown’ command. This would require accessing each port individually. There is a shortcut method for making modifications to several ports at once by using the interface range command. On SW1 all ports except FastEthernet0/1 and GigabitEthernet0/1 can be shutdown with the following command:
SW1(config)# interface range F0/2-24, G0/2 SW1(config-if-range)# shutdown %LINK-5-CHANGED: Interface FastEthernet0/2, changed state to administratively down %LINK-5-CHANGED: Interface FastEthernet0/3, changed state to administratively down <Output omitted> %LINK-5-CHANGED: Interface FastEthernet0/24, changed state to administratively down %LINK-5-CHANGED: Interface GigabitEthernet0/2, changed state to administratively down
The command used the port range of 2-24 for the FastEthernet ports and then a single port range of GigabitEthernet0/2.
f. Encrypt all plaintext passwords.
g. Set a strong secret password of your choosing.
h. Disable DNS lookup.
i. Set the domain name to CCNA.com (case-sensitive for scoring in PT).
j. Create a user of your choosing with a strong encrypted password.
k. Generate 1024-bit RSA keys.
l. Configure all VTY lines for SSH access and use the local user profiles for authentication.
m. Set the EXEC mode timeout to 6 minutes on all VTY lines.
n. Save the configuration to NVRAM.
Device Configs - Final
ROUTER RTA
! ============================================================== !--- 26.2.4 Packet Tracer - Configure Secure Passwords and SSH !--- ANSWER SCRIPT FOR ROUTER RTA !--- Usage: copy this whole file and paste it into the RTA terminal (start at the RTA> prompt, connected via the console cable from PCA). Every line beginning with "!" is a comment; IOS ignores it, so pasting a comment by accident is harmless. !--- Note: this lab has no fixed answer key - several steps say "a strong !--- secret password/username of your choosing". The values below are !--- working examples that satisfy the lab's own requirements (>= 10 !--- characters, once "security password min-length 10" is set) - replace !--- them with your own before pasting if you'd rather use different ones. ! ============================================================== enable configure terminal ! -------------------------------------------------------------- !--- Step 1 (c-d): Hostname and IP addressing on the LAN interface. ! -------------------------------------------------------------- hostname RTA !--- Bring up the interface - it starts administratively down (red link !--- in the topology) until enabled here. interface gigabitethernet 0/0 ip address 172.16.1.1 255.255.255.0 no shutdown exit ! -------------------------------------------------------------- !--- Step 1 (e-g): Password policy, then the passwords it applies to. !--- Order matters - the minimum length is set BEFORE the secret !--- passwords below, so it is enforced on them. ! -------------------------------------------------------------- !--- Encrypts any remaining plaintext passwords in the running-config. service password-encryption !--- Enforces a 10-character minimum on every password/secret set from now on. security password min-length 10 !--- Example strong enable secret (16 characters) - choose your own if you prefer. enable secret C1sco-Secure-2024! ! -------------------------------------------------------------- !--- Step 1 (h-k): Prerequisites for SSH - DNS lookup off, domain name, !--- a local user account, and the RSA key pair. ! -------------------------------------------------------------- !--- Prevents RTA from hanging on a DNS lookup after a command typo. no ip domain-lookup !--- Case-sensitive for Packet Tracer's auto-grading - must be exactly this. ip domain-name CCNA.com !--- Example local account (16-character secret) - choose your own if you prefer. username net_admin secret NetAdm1n-Secure24! !--- 1024-bit RSA key pair, required before SSH will run. crypto key generate rsa 1024 ! -------------------------------------------------------------- !--- Step 1 (l-n): Login blocking, VTY hardening, and the EXEC timeout. ! -------------------------------------------------------------- !--- After 4 failed logins within 2 minutes, block further attempts for 3 minutes. login block-for 180 attempts 4 within 120 !--- VTY lines accept SSH only and authenticate against the local user database. line vty 0 4 transport input ssh login local exec-timeout 6 0 exit end ! -------------------------------------------------------------- !--- Step 1 (o): Save the configuration to NVRAM. (Press Enter when prompted for the destination filename.) ! -------------------------------------------------------------- copy running-config startup-config ! ============================================================== !--- Verification: !--- show ip interface brief -> G0/0 172.16.1.1, status/protocol up/up !--- show running-config | include password-encryption|min-length|domain !--- show crypto key mypubkey rsa -> 1024-bit key pair named RTA.CCNA.com !--- ssh -l net_admin 172.16.1.1 (from PCA's command prompt) -> prompts for the !--- username's secret, then grants the RTA> prompt (Step 1p) !--- Note: this lab has no "Device Configs - Final" answer-key section to !--- cross-check against - the Instructions themselves are the only source, !--- and several values (secret passwords, username) are explicitly left to !--- the student's choice, so there is nothing to flag as a discrepancy; !--- this script is built directly from the lettered steps in Step 1. ! ==============================================================
SWITCH SW1
! ============================================================== !--- 26.2.4 Packet Tracer - Configure Secure Passwords and SSH !--- ANSWER SCRIPT FOR SWITCH SW1 !--- Usage: copy this whole file and paste it into the SW1 terminal (start at the SW1> prompt). Every line beginning with "!" is a comment; IOS ignores it, so pasting a comment by accident is harmless. !--- Note: this lab has no fixed answer key - Step 2 says to mirror RTA's !--- steps "of your choosing". The values below are working examples that !--- satisfy the lab's own requirements - replace them with your own !--- before pasting if you'd rather use different ones. Step 2's own list !--- (a-n) does NOT include "security password min-length" or !--- "login block-for" - those are Step 1 (RTA) items only, so they are !--- intentionally left out here. ! ============================================================== enable configure terminal ! -------------------------------------------------------------- !--- Step 2 (b-d): Hostname, management IP on VLAN 1, and the default !--- gateway - a Layer 2 switch has no "ip route", only one gateway of !--- last resort for its own management traffic. ! -------------------------------------------------------------- hostname SW1 interface vlan 1 ip address 172.16.1.2 255.255.255.0 no shutdown exit ip default-gateway 172.16.1.1 ! -------------------------------------------------------------- !--- Step 2 (e): Disable every unused port. F0/1 stays up for PCA's data !--- link and G0/1 stays up for the (currently down) uplink to RTA - every !--- other port is shut down as a security best practice. ! -------------------------------------------------------------- interface range fastethernet 0/2 - 24, gigabitethernet 0/2 shutdown exit ! -------------------------------------------------------------- !--- Step 2 (f-g): Password policy passwords. ! -------------------------------------------------------------- !--- Encrypts any remaining plaintext passwords in the running-config. service password-encryption !--- Example strong enable secret (16 characters) - choose your own if you prefer. enable secret C1sco-Secure-2024! ! -------------------------------------------------------------- !--- Step 2 (h-k): Prerequisites for SSH - DNS lookup off, domain name, !--- a local user account, and the RSA key pair. ! -------------------------------------------------------------- !--- Prevents SW1 from hanging on a DNS lookup after a command typo. no ip domain-lookup !--- Case-sensitive for Packet Tracer's auto-grading - must be exactly this !--- (same domain used on RTA, so both devices' RSA keys share the domain). ip domain-name CCNA.com !--- Example local account (16-character secret) - choose your own if you prefer. username net_admin secret NetAdm1n-Secure24! !--- 1024-bit RSA key pair, required before SSH will run. crypto key generate rsa 1024 ! -------------------------------------------------------------- !--- Step 2 (l-m): VTY hardening and the EXEC timeout. ! -------------------------------------------------------------- !--- VTY lines accept SSH only and authenticate against the local user database. line vty 0 4 transport input ssh login local exec-timeout 6 0 exit end ! -------------------------------------------------------------- !--- Step 2 (n): Save the configuration to NVRAM. (Press Enter when prompted for the destination filename.) ! -------------------------------------------------------------- copy running-config startup-config ! ============================================================== !--- Verification: !--- show ip interface brief -> VLAN1 172.16.1.2, F0/1 and G0/1 up, all other ports admin down !--- show running-config | include gateway|password-encryption|domain !--- show crypto key mypubkey rsa -> 1024-bit key pair named SW1.CCNA.com !--- ssh -l net_admin 172.16.1.2 (from PCA's command prompt) -> prompts for the !--- username's secret, then grants the SW1> prompt !--- Note: this lab has no "Device Configs - Final" answer-key section to !--- cross-check against; this script is built directly from Step 2's !--- lettered instructions, mirrored from RTA's Step 1 where the lab says !--- to do so - "security password min-length" and "login block-for" are !--- omitted here since Step 2's own list never asks for them on the switch. ! ==============================================================
