Scenario
You've just unboxed a 2911 router. Before connecting it to the network it has to be identified and secured.
Name it R1, protect privileged mode with the encrypted password "class", and the console and remote access (vty lines 0 to 4) with "cisco". Encrypt the passwords stored in clear text, add a banner warning that only authorized staff may log in, and stop the router from trying to resolve mistyped commands through DNS.
When you're done, save the configuration so it survives a restart. You can check it with reload.
Topology
Devices and cabling
Starting configuration
This lab starts with the devices straight out of the box.
Tasks
What must end up working. In the app, each one ticks itself off as soon as you get it.
- The router is named R1
- Privileged mode protected with enable secret "class"
- Console with password "cisco" and login
- vty lines 0 to 4 with password "cisco" and login
- Clear-text passwords encrypted
- Warning MOTD banner
- No DNS lookups for mistyped commands
- Configuration saved to NVRAM
In Packet Tracer- When you open the CLI of a new router, Packet Tracer asks "Would you like to enter the initial configuration dialog? [yes/no]". Answer no and press Enter until you see Router>.
- No cabling needed: this whole lab is done from the router's CLI tab.
Hints
- The router is named R1: In global configuration mode: hostname R1
- Privileged mode protected with enable secret "class": enable secret class (secret is stored encrypted; password is not)
- Console with password "cisco" and login: line console 0, then password cisco and login
- vty lines 0 to 4 with password "cisco" and login: line vty 0 4, then password cisco and login
- Clear-text passwords encrypted: service password-encryption encrypts existing and future ones
- Warning MOTD banner: banner motd #Authorized staff only# (the first character is the delimiter)
- No DNS lookups for mistyped commands: no ip domain-lookup
- Configuration saved to NVRAM: In privileged mode: copy running-config startup-config and press Enter. If you change anything afterwards, save again.
Step-by-step solution
Try it on your own first: you learn much more by typing the commands yourself.
Show the solution
1Enter configuration mode and name the router R1
enable takes you to privileged mode (#) and configure terminal to global configuration. no ip domain-lookup stops the router from spending seconds trying to resolve a mistyped command as a hostname.
R1enable
configure terminal
hostname R1
no ip domain-lookup
2Protect privileged mode R1
enable secret is stored as a hash (type 5); enable password is stored in clear text. If both exist, secret wins.
R1enable secret class
3Protect the console R1
The password alone isn't enough: without login, the line never asks for it.
R1line console 0
password cisco
login
exit
4Protect remote access R1
vty lines 0 to 4 are the simultaneous Telnet/SSH sessions. They are configured together.
R1line vty 0 4
password cisco
login
exit
5Encrypt passwords and add the banner R1
service password-encryption applies type 7 to clear-text passwords (it's reversible: it protects from prying eyes, not from an attacker). In the banner, the first character is the delimiter.
R1service password-encryption
banner motd #Authorized staff only#
end
6Save the configuration R1
What you configure lives in the running-config (RAM). copy running-config startup-config copies it to NVRAM; IOS asks for the destination name and pressing Enter is enough.
R1copy running-config startup-config
⏎
Verification
Console and vty passwords show up as "password 7 …" and the enable one as "secret 5 …". If any appears in clear text, service password-encryption is missing.
R1R1#show running-config
Building configuration...
Current configuration : 706 bytes
!
version 15.1
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname R1
!
boot-start-marker
boot-end-marker
!
enable secret 5 $1$uINU$aT/G1LuCbNEGfagIKjl0Hb
!
no aaa new-model
!
no ip domain-lookup
ip cef
!
interface GigabitEthernet0/0
no ip address
shutdown
duplex auto
speed auto
!
interface GigabitEthernet0/1
no ip address
shutdown
duplex auto
speed auto
!
interface GigabitEthernet0/2
no ip address
shutdown
duplex auto
speed auto
!
ip forward-protocol nd
!
no ip http server
!
!
banner motd ^CSolo personal autorizado^C
!
line con 0
password 7 01100F175804
login
line aux 0
line vty 0 4
password 7 01100F175804
login
!
end
Common mistakes
- Using enable password instead of enable secret: it works, but it's stored in clear text (or as type 7, which can be cracked in seconds).
- Forgetting login on the lines: the password is set, but nobody is asked for it.
- Not saving: after a reload, the router goes back to the previous configuration. Check it yourself with reload.
Practice this lab on your phone
RoutingLab has this lab with a simulated IOS terminal: abbreviations, ? help, the same error messages and objectives that check themselves. The first two labs are free.
Get RoutingLab