Analogy: Telnet is shouting the password in the hallway, SSH is whispering it in a closed room. is a lock on the wall socket — only the recognized device can connect.
Port Security — Three Responses to a Violation
- protect — Silently drops violating traffic, without an alert.
- restrict — Drops traffic and generates a Log and a violation counter.
- shutdown (default) — Puts the port into err-disabled until manual intervention.
- sticky — The switch learns the first MAC and saves it in the configuration.
- aging — Deletes a learned MAC after X minutes, convenient for meeting rooms.
! Port Security on user port
Switch(config-if)# switchport mode access
Switch(config-if)# switchport port-security
Switch(config-if)# switchport port-security maximum 2
Switch(config-if)# switchport port-security mac-address sticky
Switch(config-if)# switchport port-security violation restrict
! SSH instead of Telnet
Switch(config)# hostname SW1
Switch(config)# ip domain-name lab.local
Switch(config)# crypto key generate rsa modulus 2048
Switch(config)# username admin privilege 15 secret StrongPass!23
Switch(config)# ip ssh version 2
Switch(config)# line vty 0 15
Switch(config-line)# transport input ssh
Switch(config-line)# login local
Switch(config-line)# exec-timeout 5 0
! Basic Hardening
Switch(config)# service password-encryption
Switch(config)# enable secret StrongEnable!23
Switch(config)# no ip http server
Switch(config)# banner motd #Authorized access only#
Switch(config)# line console 0
Switch(config-line)# password ConsolePass!23
Switch(config-line)# login
! Checks and Port Recovery
Switch# show port-security interface gi0/1
Switch# show ip ssh
Switch(config-if)# shutdown
Switch(config-if)# no shutdownbashArchitecture and Theory — Under the Hood
Hardening = Reduce the attack surface of the equipment itself: management encryption, strong passwords, disabling unnecessary services, logs and documentation.
- Telnet sends passwords in clear text — SSHv2 only; requires hostname, domain-name and RSA 2048 key.
- enable secret stores a hash (Type 8/9) while enable password is saved almost in clear text.
- service password-encryption is weak encryption (Type 7) — do not rely on it.
- Disable: CDP towards untrusted networks, HTTP server, random DNS lookup, unused ports (shutdown).
- + /TACACS: authentication against instead of shared local passwords.
Practical Configuration (CLI)
R(config)# hostname CORE-SW1
R(config)# ip domain-name lab.local
R(config)# crypto key generate rsa modulus 2048
R(config)# ip ssh version 2
R(config)# username admin privilege 15 secret Str0ng!Pass
R(config)# enable secret Str0ng!Enable
R(config)# line vty 0 15
R(config-line)# transport input ssh
R(config-line)# login local
R(config-line)# exec-timeout 5 0
R(config)# no ip http server
R(config)# no ip http secure-server
R(config)# banner motd #Authorized access only#
R(config)# logging host 192.168.10.50
R(config)# ntp server 192.168.10.10
R(config)# interface range gi0/21-23
R(config-if-range)# shutdown
R# copy running-config startup-configbashReal-world Scenarios in the Organization
- All network equipment sends syslog to a central server / — without it, there is no incident investigation.
- Management access only from a dedicated management VLAN and via a Jump Server.
- Administrator logins with personal account via / — tracks who did what.
- Automated configuration backup before every change.
Troubleshooting
R# show ip ssh
R# show users
R# show running-config | include username|enable|transport
R# show logging
R# show version ! uptime, IOS version
R# show inventorybash- SSH fails to start → missing domain-name or RSA key; modulus must be 768 or higher (2048 recommended).
- Login rejected → line vty without 'login local' or without a local username.
- 'Lost configuration after reboot' → 'copy running-config startup-config' was not performed.
- No logs on the server → check logging host, UDP 514 connectivity, and NTP clock.
Glossary and quick command line
- SSH: hostname + ip domain-name + crypto key generate rsa + ip ssh version 2
- enable secret (strong) instead of enable password
- transport input ssh — disables Telnet
- copy run start / write memory — to save!