Understand how to secure network devices using AAA, access control lists (ACLs), secure remote access, and switch-level security techniques.
-
Used to control user access and actions
-
RADIUS vs TACACS+:
-
RADIUS combines authentication & authorization
-
TACACS+ separates them (more flexible)
-
Router(config)#aaa new-model
Router(config)#aaa authentication login default local
Router(config)#username admin password cisco123
-
Filters traffic based on criteria like IP, port, protocol
-
Two types:
-
Standard ACL: Source IP only
-
Extended ACL: Source + destination + protocol/port
-
Router(config)#access-list 10 permit 192.168.1.0 0.0.0.255
Router(config)#interface g0/0
Router(config-if)#ip access-group 10 in
Router(config)#access-list 100 permit tcp any host 192.168.1.10 eq 80
Router(config)#interface g0/1
Router(config-if)#ip access-group 100 out
-
Disable unused services and interfaces
-
Strong passwords
-
Enable SSH, disable Telnet
-
Login banners
Router(config)#service password-encryption
Router(config)#banner motd ^Unauthorized Access Prohibited^
Router(config)#line vty 0 4
Router(config-line)#transport input ssh
Router(config)#username admin secret s3cr3t
Router(config)#ip domain-name ccna.local
Router(config)#crypto key generate rsa
Router(config)#ip ssh version 2
Router(config)#username admin password admin123
Router(config)#line vty 0 15
Router(config-line)#login local
Router(config-line)#transport input ssh
Switch(config)#interface fa0/1
Switch(config-if)#switchport mode access
Switch(config-if)#switchport port-security
Switch(config-if)#switchport port-security mac-address sticky
Switch(config-if)#switchport port-security maximum 1
Switch(config-if)#switchport port-security violation shutdown
Switch(config)#interface fa0/1
Switch(config-if)#spanning-tree bpduguard enable
Router(config)#access-list 101 deny tcp any any eq 23
Router(config)#access-list 101 permit ip any any
Router(config)#interface g0/0
Router(config-if)#ip access-group 101 in
Router(config)#aaa new-model
Router(config)#aaa authentication login default local
Router(config)#username netadmin password strongpass
-
Which ACL type can filter by port?
-
A) Standard
-
B) Extended ✅
-
C) Named
-
D) Time-based
-
-
Which protocol separates auth & authorization?
-
A) RADIUS
-
B) TACACS+ ✅
-
C) LDAP
-
D) FTP
-
-
What command disables Telnet access?
-
A) no transport
-
B) transport input ssh ✅
-
C) line vty disable
-
D) crypto disable
-
-
AAA controls access to devices
-
ACLs restrict or permit traffic
-
Device hardening improves overall security
-
SSH ensures secure remote management
-
Switch security prevents rogue device threats