IntermediatePublished 2026-07-24
CCNA Foundations: SSH & Device Hardening — Secure the Management Plane
Archive lab
CCNA exam domain: Security Fundamentals
Harden a single-site management LAN by replacing insecure Telnet with SSH-only access on the router. You will generate RSA keys, define a domain name, create a local admin user with a secret, force SSHv2, and restrict VTY lines to SSH with local login. Validate success from an admin workstation and confirm Telnet is refused. The topology is intentionally simple: one router, one access switch, and two hosts on a dedicated management VLAN.
Learning objectives
- Build a complete SSHv2 management plane on a Cisco IOS router
- Create and secure local credentials with an encrypted secret
- Generate RSA keys and set a device domain name for SSH
- Lock VTY lines to SSH only with local authentication
- Validate SSH connectivity from a management host and confirm Telnet is refused
Troubleshooting focus
- If SSH fails immediately, verify that RSA keys exist and that an ip domain name is configured before key generation.
- If prompted for a password on Telnet, VTY may still allow Telnet. Restrict transport to SSH only on lines 0–4.
- If SSH prompts never appear, confirm reachability: host IP, VLAN membership on the switch ports, and the router interface state.
- If login fails on SSH, ensure a local username with a secret exists and VTY uses 'login local'.
- If SSH connects but shows protocol warnings, confirm 'ip ssh version 2' is set to enforce v2.
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the
running-config— a change that only exists in a terminal session never reaches the grader. - You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.