Topic

Device Security practice labs

2 hands-on Device Security scenarios you build in your own Cisco Modeling Labs instance and grade against the answer key. Device Security configuration and troubleshooting practice for CCNA and CCNP.

Management reached over SSH, edge ports hardened — the reference wiring for Device Security & SSH, not a specific lab.

Included with a subscription

IntermediateDailyLocked

CCNA Foundations: SSH & Device Hardening — Secure the Management Plane

Harden a single-site management LAN by replacing insecure Telnet with SSH-only access on the router. You will generate RSA keys, define a domain name, create a local admin user with a secret, force SSHv2, and restrict VTY lines to SSH with local login. Validate success from an admin workstation and confirm Telnet is refused. The topology is intentionally simple: one router, one access switch, and two hosts on a dedicated management VLAN.

CCNA45 min5 objectives

IntermediateDailyLocked

CCNA Foundations: Secure Remote Access — Restrict VTY with access-class

Harden SSH access to a production router by allowing only a designated management workstation to connect. You will apply a standard ACL to the router's VTY lines with access-class, verify that the permitted host can SSH in, and confirm that a second host on the same LAN is refused. End-to-end IP forwarding is pre-built with static routes so the focus stays on management-plane control.

CCNA40 min4 objectives

Learn Device Security

Study the theory behind these labs — the concept explainer and step-by-step guides.

Looking for something else? Browse the full lab archive, narrow it to self-standing labs, or see today's daily lab.