IntermediatePublished 2026-07-04
AAA Authentication with a Local User Database
Bundle lab
Lab 7 of 9 in Device Hardening: SSH, AAA & Secure Access · ← Previous · Next →
CCNA exam domain: Security Fundamentals
Harden R1’s management plane by moving SSH login authentication and exec authorization under the IOS AAA framework using the local user database. You will start from a secure SSH-only baseline that still uses login local, enable aaa new-model, define default AAA methods that point at local, and bind VTY lines to AAA. Success is proven by authenticating from the ADMIN host over SSH and landing at the user’s privilege level.
Learning objectives
- Enable AAA on IOS and migrate VTY login from login local to a default AAA method list that uses the local database
- Assign user privilege via the user account and enforce it with AAA exec authorization
- Harden remote access with SSH-only transport and safe local admin retention to prevent lockout
- Verify AAA operation from the router and via SSH from a Linux host
Troubleshooting focus
- AAA not enabled (no aaa new-model) so AAA method lists never take effect
- VTY lines still use login local, which means aaa new-model was never applied — once AAA is on, IOS removes login local from the line by itself
- Missing local username or wrong privilege assignment
- SSH service not ready (no RSA key pair, missing hostname or ip domain name)
- Transport not restricted to SSH (Telnet allowed) or SSHv2 not enforced
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the
running-config— a change that only exists in a terminal session never reaches the grader. - You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.