2 hands-on Device Security scenarios you build in your own Cisco Modeling Labs instance and grade against the answer key. Device Security configuration and troubleshooting practice for CCNA and CCNP.
Management reached over SSH, edge ports hardened — the reference wiring for Device Security & SSH, not a specific lab.
Harden a single-site management LAN by replacing insecure Telnet with SSH-only access on the router. You will generate RSA keys, define a domain name, create a local admin user with a secret, force SSHv2, and restrict VTY lines to SSH with local login. Validate success from an admin workstation and confirm Telnet is refused. The topology is intentionally simple: one router, one access switch, and two hosts on a dedicated management VLAN.
Harden SSH access to a production router by allowing only a designated management workstation to connect. You will apply a standard ACL to the router's VTY lines with access-class, verify that the permitted host can SSH in, and confirm that a second host on the same LAN is refused. End-to-end IP forwarding is pre-built with static routes so the focus stays on management-plane control.
CCNA40 min4 objectives
View details
Learn Device Security
Study the theory behind these labs — the concept explainer and step-by-step guides.