R1 has to be managed securely from PC1. Telnet sends everything in clear text, so only SSH version 2 will be allowed.
Configure the domain ccna.local, generate 1024-bit RSA keys, create user admin with secret password cisco123 and protect privileged mode with enable secret class. On vty lines 0 to 4, authenticate against local users and allow SSH only.
Finally, connect from PC1: ssh -l admin 192.168.1.1
Topology
Devices and cabling
R1·2911
SW1·2960-24TT
PC1·PC-PT
From
To
Cable
R1Gi0/0
SW1Gi0/1
Straight-through
PC1Fa0
SW1Fa0/1
Straight-through
If in doubt, the automatic connection cable (the lightning bolt) picks the right one. Rule: straight-through between different devices (PC or router to switch) and crossover between alike ones.
Addressing
Device
Interface
Address
Mask
Default gateway
R1
G0/0
192.168.1.1
255.255.255.0
—
PC1
NIC
192.168.1.10
255.255.255.0
192.168.1.1
Starting configuration
In the app this is already done. In Packet Tracer, before you start, enter each device with enable and configure terminal and type (or paste) these lines.
R1hostname R1
no ip domain-lookup
interface g0/0
ip address 192.168.1.1 255.255.255.0
no shutdown
SW1hostname SW1
no ip domain-lookup
PCs and servers (Desktop › IP Configuration)
PC1: IP 192.168.1.10, mask 255.255.255.0, gateway 192.168.1.1
Tasks
What must end up working. In the app, each one ticks itself off as soon as you get it.
Domain ccna.local
RSA keys of 1024 bits or more
User admin with a secret password
Privileged mode with enable secret
SSH version 2
vty 0 to 4: local users and SSH only
PC1 logs in over SSH
In Packet Tracer
To connect, on PC1 go to Desktop › Command Prompt and type ssh -l admin 192.168.1.1.
Hints
Domain ccna.local: ip domain-name ccna.local. Without a domain you can't generate the keys.
RSA keys of 1024 bits or more: crypto key generate rsa and answer 1024 (or add general-keys modulus 1024)
User admin with a secret password: username admin secret cisco123
Privileged mode with enable secret: enable secret class. Over vty, without an enable password IOS replies "% No password set".
SSH version 2: ip ssh version 2 (needs keys of 768 bits or more)
vty 0 to 4: local users and SSH only: line vty 0 4 → login local → transport input ssh
PC1 logs in over SSH: On PC1's console: ssh -l admin 192.168.1.1 and the password cisco123
Step-by-step solution
Try it on your own first: you learn much more by typing the commands yourself.
Show the solution
1Domain and RSA keys R1
Keys are named hostname.domain: without a hostname other than Router and a domain, IOS won't generate them.
Over SSH you log in with a username and password. Without enable secret, IOS replies "% No password set" when you try enable from a remote session.
R1username admin secret cisco123
enable secret class
3SSH version 2 R1
Version 2 needs keys of 768 bits or more.
R1ip ssh version 2
4vty lines for SSH only R1
login local uses the router's users and transport input ssh rejects Telnet.
R1line vty 0 4
login local
transport input ssh
end
5Connect from PC1 PC1
The password isn't shown as you type it. Then enter privileged mode with the enable password.
PC1ssh -l admin 192.168.1.1
cisco123
enable
class
exit
Verification
SSH Enabled - version 2.0: keys generated and version 2 active.
R1R1#show ip ssh
SSH Enabled - version 2.0
Authentication timeout: 120 secs; Authentication retries: 3
The vty lines use login local and only accept SSH.
R1R1#show running-config | section line vty
line vty 0 4
login local
transport input ssh
Common mistakes
Generating the keys without ip domain-name: "% Please define a domain-name first".
Using login instead of login local: SSH needs a username.
Practice this lab on your phone
RoutingLab has this lab with a simulated IOS terminal: abbreviations, ? help, the same error messages and objectives that check themselves. The first two labs are free.