AdvancedPublished 2026-07-04
Secure-Access Troubleshooting Capstone: SSH VTY Fix
Bundle lab
Advanced secure-access capstone, run as a fault hunt. A hardening change was rolled back badly overnight: the edge router is reachable but the management plane is wide open in several different ways at once, and an SSH key cannot even be generated. You get symptoms and the required end state — no fault list. Everything is on one device, so the work is knowing which pieces of a management-plane build depend on each other rather than hunting across a topology.
Learning objectives
- Audit a router's management plane from its running configuration, with no list of what was changed
- Know why SSH cannot be enabled without a hostname and a domain name
- Distinguish line-password authentication from local-user authentication, and why the difference matters
- Spot a disabled session timeout as a security fault rather than a convenience
- Restore secure access without falling back to Telnet or weakening the crypto
Troubleshooting focus
- SSH negotiation fails or is refused despite IP reachability
- Login method does not reference the intended authentication source
- Service readiness gaps: RSA keys not present or SSH service not enabled
- Line authentication behavior differs from expectations due to VTY configuration
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.