← All labs Lab 13 · Packet Tracer

Remote access over SSH

Domain, RSA keys, local user and SSH-only vty

Level: Intermediate Time: 25 min Domain 5.0 Security Fundamentals

Scenario

R1 has to be managed securely from PC1. Telnet sends everything in clear text, so only SSH version 2 will be allowed.

Configure the domain ccna.local, generate 1024-bit RSA keys, create user admin with secret password cisco123 and protect privileged mode with enable secret class. On vty lines 0 to 4, authenticate against local users and allow SSH only.

Finally, connect from PC1: ssh -l admin 192.168.1.1

Topology

R1SW1PC1Gi0/0Gi0/1Fa0Fa0/1

Devices and cabling

FromToCable
R1 Gi0/0SW1 Gi0/1Straight-through
PC1 Fa0SW1 Fa0/1Straight-through

If in doubt, the automatic connection cable (the lightning bolt) picks the right one. Rule: straight-through between different devices (PC or router to switch) and crossover between alike ones.

Addressing

DeviceInterfaceAddressMaskDefault gateway
R1G0/0192.168.1.1255.255.255.0—
PC1NIC192.168.1.10255.255.255.0192.168.1.1

Starting configuration

In the app this is already done. In Packet Tracer, before you start, enter each device with enable and configure terminal and type (or paste) these lines.

R1hostname R1 no ip domain-lookup interface g0/0 ip address 192.168.1.1 255.255.255.0 no shutdown
SW1hostname SW1 no ip domain-lookup

PCs and servers (Desktop › IP Configuration)

Tasks

What must end up working. In the app, each one ticks itself off as soon as you get it.

  1. Domain ccna.local
  2. RSA keys of 1024 bits or more
  3. User admin with a secret password
  4. Privileged mode with enable secret
  5. SSH version 2
  6. vty 0 to 4: local users and SSH only
  7. PC1 logs in over SSH
In Packet Tracer
  • To connect, on PC1 go to Desktop › Command Prompt and type ssh -l admin 192.168.1.1.
Hints
  • Domain ccna.local: ip domain-name ccna.local. Without a domain you can't generate the keys.
  • RSA keys of 1024 bits or more: crypto key generate rsa and answer 1024 (or add general-keys modulus 1024)
  • User admin with a secret password: username admin secret cisco123
  • Privileged mode with enable secret: enable secret class. Over vty, without an enable password IOS replies "% No password set".
  • SSH version 2: ip ssh version 2 (needs keys of 768 bits or more)
  • vty 0 to 4: local users and SSH only: line vty 0 4 → login local → transport input ssh
  • PC1 logs in over SSH: On PC1's console: ssh -l admin 192.168.1.1 and the password cisco123

Step-by-step solution

Try it on your own first: you learn much more by typing the commands yourself.

Show the solution

1Domain and RSA keys R1

Keys are named hostname.domain: without a hostname other than Router and a domain, IOS won't generate them.

R1enable configure terminal ip domain-name ccna.local crypto key generate rsa general-keys modulus 1024

2Local user and enable secret R1

Over SSH you log in with a username and password. Without enable secret, IOS replies "% No password set" when you try enable from a remote session.

R1username admin secret cisco123 enable secret class

3SSH version 2 R1

Version 2 needs keys of 768 bits or more.

R1ip ssh version 2

4vty lines for SSH only R1

login local uses the router's users and transport input ssh rejects Telnet.

R1line vty 0 4 login local transport input ssh end

5Connect from PC1 PC1

The password isn't shown as you type it. Then enter privileged mode with the enable password.

PC1ssh -l admin 192.168.1.1 cisco123 enable class exit

Verification

SSH Enabled - version 2.0: keys generated and version 2 active.

R1R1#show ip ssh SSH Enabled - version 2.0 Authentication timeout: 120 secs; Authentication retries: 3

The vty lines use login local and only accept SSH.

R1R1#show running-config | section line vty line vty 0 4 login local transport input ssh

Common mistakes

Practice this lab on your phone

RoutingLab has this lab with a simulated IOS terminal: abbreviations, ? help, the same error messages and objectives that check themselves. The first two labs are free.

Get RoutingLab