IntermediatePublished 2026-07-04
Blocking Brute-Force Logins and Adding a Banner on R1
Bundle lab
Harden the management plane of a single IOS router by throttling brute-force login attempts and presenting a legal-warning banner. You will enable SSH-based management, configure login block-for and delay to resist password-guessing, and verify behavior from an ADMIN Linux workstation.
Learning objectives
- Enable SSH-only management with a local user on a single IOS router
- Throttle brute-force attempts using global login controls
- Display a legal-warning banner before authentication
- Verify quiet-mode behavior and failed-attempt tracking with show commands
- Validate end-to-end access from an ADMIN Linux workstation
Troubleshooting focus
- SSH key generation prerequisites missing (hostname/domain-name)
- VTY lines not using local login or still allow Telnet
- Incorrect login block-for or delay syntax not taking effect
- Banner delimiter errors preventing banner from being saved
- Quiet-mode blocks all logins longer than expected due to fresh failures
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.