IntermediatePublished 2026-07-04
CCNA: Console and VTY Line Hardening
Bundle lab
Harden the console and VTY lines on a single Cisco IOS router so idle sessions close automatically and every access path requires authentication. You will configure login local on both console and VTY, set 5-minute exec timeouts, enable logging synchronous on the console, and restrict VTY to SSH. Verification uses show outputs; grading evaluates the deterministic running-config.
Learning objectives
- Require authentication on the console with login local tied to a local user database
- Enforce exec-timeout 5 0 on both console and VTY lines to close idle sessions
- Prevent log messages from interrupting console input with logging synchronous
- Restrict remote access to SSH only with transport input ssh on VTY
- Explain how these controls reduce risk of unattended or unauthenticated access
Troubleshooting focus
- If exec-timeout is not exactly 5 0, the grader will not pass; confirm minutes and seconds.
- login local must be under both line console 0 and line vty 0 4; setting it only in one place is insufficient.
- transport input ssh must appear on VTY; leaving Telnet enabled (or transport input all) does not meet requirements.
- logging synchronous must be configured under line console 0 (not globally).
- Ensure a local username with secret exists so login local works; otherwise you can lock yourself out.
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.