Skip to main content
AD Academy
CCNA — Cisco Networking Fundamentals
Beginner12 minLast updated: Topic 12 of 12

Port Security, SSH and Device Hardening

Closing the entrance door: MAC restriction, encrypted management, and disabling unnecessary services.

Not read

What you will learn here

  • How to restrict MAC addresses on a port
  • Why SSH instead of Telnet
  • Which unneeded services to turn off

Worth reading first:ACL: Standard vs. Extended and Rule Order

Analogy: Telnet is shouting the password in the hallway, SSH is whispering it in a closed room. is a lock on the wall socket — only the recognized device can connect.

Port Security — Three Responses to a Violation

  • protect — Silently drops violating traffic, without an alert.
  • restrict — Drops traffic and generates a Log and a violation counter.
  • shutdown (default) — Puts the port into err-disabled until manual intervention.
  • sticky — The switch learns the first MAC and saves it in the configuration.
  • aging — Deletes a learned MAC after X minutes, convenient for meeting rooms.
! Port Security on user port
Switch(config-if)# switchport mode access
Switch(config-if)# switchport port-security
Switch(config-if)# switchport port-security maximum 2
Switch(config-if)# switchport port-security mac-address sticky
Switch(config-if)# switchport port-security violation restrict

! SSH instead of Telnet
Switch(config)# hostname SW1
Switch(config)# ip domain-name lab.local
Switch(config)# crypto key generate rsa modulus 2048
Switch(config)# username admin privilege 15 secret StrongPass!23
Switch(config)# ip ssh version 2
Switch(config)# line vty 0 15
Switch(config-line)# transport input ssh
Switch(config-line)# login local
Switch(config-line)# exec-timeout 5 0

! Basic Hardening
Switch(config)# service password-encryption
Switch(config)# enable secret StrongEnable!23
Switch(config)# no ip http server
Switch(config)# banner motd #Authorized access only#
Switch(config)# line console 0
Switch(config-line)# password ConsolePass!23
Switch(config-line)# login

! Checks and Port Recovery
Switch# show port-security interface gi0/1
Switch# show ip ssh
Switch(config-if)# shutdown
Switch(config-if)# no shutdown
bash
Architecture and Theory — Under the Hood

Hardening = Reduce the attack surface of the equipment itself: management encryption, strong passwords, disabling unnecessary services, logs and documentation.

  • Telnet sends passwords in clear text — SSHv2 only; requires hostname, domain-name and RSA 2048 key.
  • enable secret stores a hash (Type 8/9) while enable password is saved almost in clear text.
  • service password-encryption is weak encryption (Type 7) — do not rely on it.
  • Disable: CDP towards untrusted networks, HTTP server, random DNS lookup, unused ports (shutdown).
  • + /TACACS: authentication against instead of shared local passwords.
Practical Configuration (CLI)
R(config)# hostname CORE-SW1
R(config)# ip domain-name lab.local
R(config)# crypto key generate rsa modulus 2048
R(config)# ip ssh version 2
R(config)# username admin privilege 15 secret Str0ng!Pass
R(config)# enable secret Str0ng!Enable
R(config)# line vty 0 15
R(config-line)# transport input ssh
R(config-line)# login local
R(config-line)# exec-timeout 5 0
R(config)# no ip http server
R(config)# no ip http secure-server
R(config)# banner motd #Authorized access only#
R(config)# logging host 192.168.10.50
R(config)# ntp server 192.168.10.10
R(config)# interface range gi0/21-23
R(config-if-range)# shutdown
R# copy running-config startup-config
bash
Real-world Scenarios in the Organization
  • All network equipment sends syslog to a central server / — without it, there is no incident investigation.
  • Management access only from a dedicated management VLAN and via a Jump Server.
  • Administrator logins with personal account via / — tracks who did what.
  • Automated configuration backup before every change.
Troubleshooting
R# show ip ssh
R# show users
R# show running-config | include username|enable|transport
R# show logging
R# show version              ! uptime, IOS version
R# show inventory
bash
  • SSH fails to start → missing domain-name or RSA key; modulus must be 768 or higher (2048 recommended).
  • Login rejected → line vty without 'login local' or without a local username.
  • 'Lost configuration after reboot' → 'copy running-config startup-config' was not performed.
  • No logs on the server → check logging host, UDP 514 connectivity, and NTP clock.
Glossary and quick command line
  • SSH: hostname + ip domain-name + crypto key generate rsa + ip ssh version 2
  • enable secret (strong) instead of enable password
  • transport input ssh — disables Telnet
  • copy run start / write memory — to save!

Check yourself

What does the violation restrict mode do?

What must be configured before creating an RSA key for SSH?

Was this page helpful?