User Tools

Site Tools


dardan:ccna_security:labs:securing_the_router_for_administrative_access
Configure a minimum password length for all router passwords
R1(config)# security passwords min-length 10

Configure the enable secret password
R1(config)# enable algorithm-type scrypt secret cisco12345

Configure basic console, auxiliary port, and virtual access lines
R1(config)# line console 0 
R1(config-line)# password ciscocon 
R1(config-line)# exec-timeout 5 0 
R1(config-line)# login 
R1(config-line)# logging synchronous 
R1(config-line)# login local 

R1(config)# line aux 0 
R1(config-line)# password ciscoauxpass 
R1(config-line)# exec-timeout 5 0 
R1(config-line)# login 
R1(config-line)# login local


R1(config)# line vty 0 4 
R1(config-line)# password ciscovtypass 
R1(config-line)# exec-timeout 5 0 
R1(config-line)# transport input telnet 
R1(config-line)# login
R1(config-line)# login local

Encrypt clear text passwords
R1(config)# service password-encryption 

Create a new user account with a secret password. 
R1(config)# username user01 algorithm-type scrypt secret user01pas


Erase existing key pairs on the router
R1(config)# crypto key zeroize rsa
dardan/ccna_security/labs/securing_the_router_for_administrative_access.txt · Last modified: 2019/02/04 13:10 by dardan

Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki