BeginnerPublished 2026-07-04
SSH-Only Management: Disabling Telnet on R1
Bundle lab
Harden a Cisco IOS router so remote management is allowed only via SSH. You will remove Telnet from the VTY lines, keep local authentication, and add an idle-session timeout. Verify success from a Linux ADMIN host by confirming SSH works and Telnet is refused.
Learning objectives
- Explain why Telnet is insecure and must be disabled on managed devices
- Restrict VTY access to SSH only using transport input ssh
- Retain local authentication on VTY lines using login local
- Configure an SSH administrator idle timeout on VTY lines
- Verify SSH success and Telnet refusal from a Linux host
- Show and interpret IOS running-config sections related to VTY/SSH
Troubleshooting focus
- If SSH fails to connect, generate RSA keys (crypto key generate rsa) and confirm hostname and ip domain name are set
- If the login prompt never appears, ensure line vty 0 4 has login local and at least one username secret
- If Telnet is still accepted, check that transport input is set to ssh only (not all or telnet ssh)
- If the ADMIN host cannot reach R1, verify IP addressing and the host default route to 10.0.0.1
- If SSH connects but closes unexpectedly, verify exec-timeout settings and network stability
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.