Home Bundles First-Hop Redundancy (HSRP & VRRP) Securing HSRP with MD5 Intermediate Published 2026-07-02
Securing HSRP with MD5 Bundle lab · $29.99
Harden an HSRP virtual default gateway with MD5 authentication so only trusted routers can participate. You’ll secure an existing HSRP group on two IOS routers that share a user VLAN via a single L2 switch. Validate the authentication state on both routers and confirm the endpoint still reaches the virtual IP.
Learning objectives Explain why unauthenticated HSRP can be hijacked by a rogue router Configure HSRP MD5 authentication on both peers with a matching key-string Verify HSRP authentication state and active/standby roles with show standby Confirm end-host reachability to the virtual default gateway Troubleshooting focus HSRP peers remain in Init or Speak due to mismatched authentication key-string Incorrect HSRP group number or virtual IP prevents the pair from forming End host default gateway set to a physical router IP instead of the virtual IP What's included in the package Work / baseline CML import — lab-work.yaml Topology diagram — topology.svg Print-ready topology diagram (PDF) — topology.pdf Step-by-step learner guide (Markdown — for Obsidian/VS Code) — lab-guide.md Branded PDF lab guide — open in any viewer (Adobe/Preview) — lab-guide.pdf Getting-started README — README.md Verification checklist — verification-checklist.md How this lab is graded Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with access-class, are stated in the guide and do have to match.Addresses, modes and protocol keywords are exact. An IP address, a subnet mask, switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide.Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found. Download access New here? See how the download → build in CML → grade loop works.
This lab is part of the First-Hop Redundancy (HSRP & VRRP) bundle — own every lab in it permanently for a one-time $29.99.
Create a free account, then own the First-Hop Redundancy (HSRP & VRRP) bundle for a one-time $29.99 — buy once, keep every lab forever.
Found a problem with this lab? Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.