Telnet, Console and AUX Port Passwords on Cisco Routers Configuration Example

Similar documents
Console Port, Telnet, and SSH Handling

Console Port, Telnet, SSH Handling, and Reset

Configuring a Modem on the AUX Port for EXEC Dialin Connectivity

Configuring a Terminal/Comm Server

Cisco - Connecting Routers Back-to-Back Through the AUX Ports using a Rollover Cable

Access Service Security

Policy Based Routing with the Multiple Tracking Options Feature Configuration Example

Lab 7 Configuring Basic Router Settings with IOS CLI

PT Activity: Configure AAA Authentication on Cisco Routers

This document is exclusive property of Cisco Systems, Inc. Permission is granted to print and copy this document for non-commercial distribution and

Configuring Basic AAA on an Access Server

Password Recovery Procedure for the Cisco 801, 802, 803, 804, 805, 811, and 813 Series Routers

Use NAT to Hide the Real IP Address of CTC to Establish a Session with ONS 15454

Chapter 12. AAA. Upon completion of this chapter, you will be able to perform the following tasks:

4(b): Assign the IP address on the Serial interface of Router. Console Cable

Lab AAA Authorization and Accounting

Configuring Secure Shell

How to Configure a Cisco Router Behind a Non-Cisco Cable Modem

Lab Configuring Basic RIPv2 (Solution)

Practice Dynagen. Winpcap 4.0. RPMs for are now available in the download section. Thanks to Sean Walberg for performing the packaging.

Access Server Dial In IP/PPP Configuration With Dedicated V.120 PPP

Implementing Authentication Proxy

Configuring PPP Dialin with External Modems

Examples of Cisco APE Scenarios

Lab Using the CLI to Gather Network Device Information Topology

Configuring Local Authentication

Lab - Examining Telnet and SSH in Wireshark

Configure IOS-XE to display full show running-config for users with low Privilege Levels

Secure Shell Configuration Guide, Cisco IOS Release 15M&T

Configure a Cisco Router with TACACS+ Authentication

ord Recovery Procedure for the Cisco Catalyst 8510 Multiserv

Password Recovery Procedure for the Cisco 3600 and 3800 Series Routers

Configuring Transparent and Proxy Media Redirection Using ACNS Software 4.x

Lab Advanced Telnet Operations Instructor Version 2500

Packet Tracer - Configuring Initial Switch Settings

TELECOMMUNICATION MANAGEMENT AND NETWORKS

Configuring TACACS+ Finding Feature Information. Prerequisites for TACACS+

KIM DONNERBORG / RTS. Cisco Lab Øvelse Af Kim Donnerborg / RTS. Side 0 af 8

cable modem dhcp proxy nat on Cisco Cable Modems

What is EXEC timeout

TELECOMMUNICATION MANAGEMENT AND NETWORKS

Configuring Switch-Based Authentication

Console Port, Telnet, and SSH Handling

ITdumpsFree. Get free valid exam dumps and pass your exam test with confidence

Lab Catalyst 2950T and 3550 Series Basic Setup

Lab Designing and Implementing a VLSM Addressing Scheme. Topology. Objectives. Background / Scenario

Configuring IDS TCP Reset Using VMS IDS MC

First-Time Configuration

Cisco IOS Firewall Authentication Proxy

Lock and Key: Dynamic Access Lists

Configuring Authorization

SLIP and PPP Configuration Commands

Context Based Access Control (CBAC): Introduction and Configuration

Lab 1. CLI Navigation. Scenario. Initial Configuration for R1

TACACS+ on an Aironet Access Point for Login Authentication Configuration Example

Configuring Secure Shell on Routers and Switches Running Cisco IOS

Lab Establishing and Verifying a Telnet Connection Instructor Version 2500

Lab Configuring and Verifying Standard IPv4 ACLs (Instructor Version Optional Lab)

VPN Connection through Zone based Firewall Router Configuration Example

Password Recovery Procedure for the Cisco 1900 Series Integrated Services Routers

Lab - Configuring IPv6 Addresses on Network Devices

Lab Configuring Per-Interface Inter-VLAN Routing (Solution)

Configuration Guide Cisco UCS Express Local Management Platform

Lab Configuring Per-Interface Inter-VLAN Routing (Instructor Version)

Configuration Professional: Site to Site IPsec VPN Between Two IOS Routers Configuration Example

Lab Configuring Basic Router Settings with IOS CLI (Instructor Version Optional Lab)

Lab Configuring IPv4 Static and Default Routes (Solution)

Cisco Configuring Hub and Spoke Frame Relay

Configuring a Cisco 827 Router to Support PPPoE Clients, Terminating on a Cisco 6400 UAC

Lab - Securing Administrative Access Using AAA and RADIUS

Lab Configuring and Verifying Standard IPv4 ACLs Topology

Lab - Configuring a Switch Management Address

Table of Contents. Cisco Password Recovery Procedure for the Cisco 2000, 2500, 3000, 4000, AccessPro, 7000 (RP), AGS, IGS, STS

Prerequisites for Controlling Switch Access with Terminal Access Controller Access Control System Plus (TACACS+)

Configuring Secure Shell (SSH)

Configuring Authentication Proxy

No Service Password-Recovery

Using the Management Interfaces

Cisco Network Academy CCNA 1 Introduction to Networks

Using NAT in Overlapping Networks

IOS Router : Easy VPN (EzVPN) in Network Extension Mode (NEM) with Split tunnelling Configuration Example

Take Assessment - CCNA 607 Certification Practice Exam - CCNA 4 WAN Technologies Version 3.1

Lab Troubleshooting Basic PPP with Authentication Topology

Lab Introductory Lab 1 Getting Started and Building Start.txt

Antonio Cianfrani. Packet Tracer

Module 9, Assignment 7

Lab Configuring Dynamic and Static NAT (Solution)

AAA Authorization and Authentication Cache

Hochschule Bremen Networking Lab

Configuring Authorization

Three interface Router without NAT Cisco IOS Firewall Configuration

Lab Troubleshooting IPv4 and IPv6 Static Routes (Instructor Version Optional Lab)

Understanding and Troubleshooting Idle Timeouts

Secure ACS Database Replication Configuration Example

Lab Securing Network Devices

Lab Configuring Dynamic and Static NAT (Instructor Version Optional Lab)

Cisco Router Security: Principles and Practise. The foundation of network security is router security.

Configuring Modem Transport Support for VoIP

Configuring Layer 2 Tunneling Protocol (L2TP) over IPSec

Configuring Authentication Proxy

Transcription:

Telnet, Console and AUX Port Passwords on Cisco Routers Configuration Example Document ID: 45843 Contents Introduction Prerequisites Requirements Components Used Conventions Background Information Configure Passwords on the Line Troubleshoot Login Failure Configure Local User Specific Passwords Troubleshoot User specific Password Failure Configure AUX Line Password Verify Configuration Configure AAA Authentication for Login Troubleshoot AAA Login Failure Related Information Introduction This document provides sample configurations for configuring password protection for inbound EXEC connections to the router. Prerequisites Requirements In order to perform the tasks described in this document, you must have privileged EXEC access to the router's command line interface (CLI). For information on using the command line and for understanding command modes, see Using Cisco IOS Software. For instructions on connecting a console to your router, refer to the documentation that accompanied your router, or refer to the online documentation for your equipment. Components Used The information in this document is based on these software and hardware versions: Cisco 2509 router

Cisco IOS Software Version 12.2(19) The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared (default) configuration. If your network is live, make sure that you understand the potential impact of any command. Conventions For more information on document conventions, refer to the Cisco Technical Tips Conventions. Background Information The use of password protection to control or restrict access to the command line interface (CLI) of your router is one of the fundamental elements of an overall security plan. Protecting the router from unauthorized remote access, typically Telnet, is the most common security that needs configuring, but protecting the router from unauthorized local access cannot be overlooked. Note: Password protection is just one of the many steps you should use in an effective in depth network security regimen. Firewalls, access lists, and control of physical access to the equipment are other elements that must be considered when implementing your security plan. Command line, or EXEC, access to a router can be made in a number of ways, but in all cases the inbound connection to the router is made on a TTY line. There are four main types of TTY lines, as seen in this sample show line output: 2509#show line Tty Typ Tx/Rx A Modem Roty AccO AccI Uses Noise Overruns Int * 0 CTY 0 0 0/0 1 TTY 9600/9600 0 0 0/0 2 TTY 9600/9600 0 0 0/0 3 TTY 9600/9600 0 0 0/0 4 TTY 9600/9600 0 0 0/0 5 TTY 9600/9600 0 0 0/0 6 TTY 9600/9600 0 0 0/0 7 TTY 9600/9600 0 0 0/0 8 TTY 9600/9600 0 0 0/0 9 AUX 9600/9600 0 0 0/0 10 VTY 0 0 0/0 11 VTY 0 0 0/0 12 VTY 0 0 0/0 13 VTY 0 0 0/0 14 VTY 0 0 0/0 2509# The CTY line type is the Console Port. On any router, it appears in the router configuration as line con 0 and in the output of the show line command as cty. The console port is mainly used for local system access using a console terminal. The TTY lines are asynchronous lines used for inbound or outbound modem and terminal connections and can be seen in a router or access server configuration as line x. The specific line numbers are a function of the hardware built into or installed on the router or access server. The AUX line is the Auxiliary port, seen in the configuration as.

The VTY lines are the Virtual Terminal lines of the router, used solely to control inbound Telnet connections. They are virtual, in the sense that they are a function of software there is no hardware associated with them. They appear in the configuration as line vty 0 4. Each of these types of lines can be configured with password protection. Lines can be configured to use one password for all users, or for user specific passwords. User specific passwords can be configured locally on the router, or you can use an authentication server to provide authentication. There is no prohibition against configuring different lines with different types of password protection. It is, in fact, common to see routers with a single password for the console and user specific passwords for other inbound connections. Below is an example of router output from the show running config command: 2509#show running config Current configuration : 655 bytes version 12.2... Configuration edited for brevity line con 0 line 1 8 line vty 0 4 Configure Passwords on the Line To specify a password on a line, use the password command in line configuration mode. To enable password checking at login, use the login command in line configuration mode. Note: To find additional information on the commands used in this document, use the Command Lookup Tool (registered customers only). In this example, a password is configured for all users attempting to use the console. 1. From the privileged EXEC (or "enable") prompt, enter configuration mode and then switch to line configuration mode using the following commands. Notice that the prompt changes to reflect the current mode. router#configure terminal Enter configuration commands, one per line. End with CNTL/Z. router(config)#line con 0 router(config line)# 2. Configure the password, and enable password checking at login. router(config line)#password letmein router(config line)#login

3. Exit configuration mode. router(config line)# router# %SYS 5 CONFIG_I: Configured from console by console Note: Do not save configuration changes to line con 0 until your ability to log in has been verified. Note: Under the line console configuration, login is a required configuration command to enable password checking at login. Console authentication requires both the password and the login commands to work. Examine the configuration of the router to verify that the commands have been properly entered: Certain show commands are supported by the Output Interpreter Tool (registered customers only), which allows you to view an analysis of show command output. show running config displays the current configuration of the router. router#show running config... Lines omitted for brevity line con 0 password letmein login line 1 8 line vty 0 4 To test the configuration, log off the console and log in again, using the configured password to access the router: router#exit router con0 is now available Press RETURN to get started. User Access Verification Password: Password entered here is not displayed by the router router> Note: Before performing this test, ensure that you have an alternate connection into the router, such as Telnet or dial in, in case there is a problem logging back into the router.

Troubleshoot Login Failure If you cannot log back into the router and you have not saved the configuration, reloading the router will eliminate any configuration changes you have made. If the configuration changes were saved and you cannot login to the router, you will have to perform a password recovery. See Password Recovery Procedures to find instructions for your particular platform. Configure Local User Specific Passwords To establish a username based authentication system, use the username command in global configuration mode. To enable password checking at login, use the login local command in line configuration mode. In this example, passwords are configured for users attempting to connect to the router on the VTY lines using Telnet. 1. From the privileged EXEC (or "enable") prompt, enter configuration mode and enter username/password combinations, one for each user for whom you want to allow access to the router: router#configure terminal Enter configuration commands, one per line. End with CNTL/Z. router(config)# username russ password montecito router(config)# username cindy password belgium router(config)# username mike password rottweiler 2. Switch to line configuration mode, using the following commands. Notice that the prompt changes to reflect the current mode. 3. router(config)#line vty 0 4 router(config line)# Configure password checking at login. router(config line)#login local 4. Exit configuration mode. router(config line)# router# %SYS 5 CONFIG_I: Configured from console by console Note: In order to disable auto Telnet when you type a name on the CLI, configure no logging preferred on the line that is used. While transport preferred none provides the same output, it also disables auto Telnet for the defined host that are configured with the ip host command. This is unlike the no logging preferred command, which stops it for undefined hosts and lets it work for the defined ones. Examine the configuration of the router to verify that the commands have been properly entered: show running config displays the current configuration of the router. router#show running config

Lines omitted for brevity username russ password 0 montecito username cindy password 0 belgium username mike password 0 rottweiler Lines omitted for brevity line con 0 line 1 8 line vty 0 4 login local To test this configuration, a Telnet connection must be made to the router. This can be done by connecting from a different host on the network, but you can also test from the router itself by telnetting to the IP address of any interface on the router that is in an up/up state as seen in the output of the show interfaces command. Here is a sample output if the address of interface ethernet 0 were 10.1.1.1: router#telnet 10.1.1.1 Trying 10.1.1.1... Open User Access Verification Username: mike Password: Password entered here is not displayed by the router router Troubleshoot User specific Password Failure Usernames and passwords are case sensitive. Users attempting to log in with an incorrectly cased username or password will be rejected. If users are unable to log into the router with their specific passwords, reconfigure the username and password on the router. Configure AUX Line Password In order to specify a password on the AUX line, issue the password command in line configuration mode. In order to enable password checking at login, issue the login command in line configuration mode.

In this example, a password is configured for all users attempting to use the AUX port. 1. Issue the show line command in order to verify the line used by the AUX port. R1#show line Tty Typ Tx/Rx A Modem Roty AccO AccI Uses Noise Overruns Int * 0 CTY 0 0 0/0 65 AUX 9600/9600 0 1 0/0 66 VTY 0 0 0/0 67 VTY 0 0 0/0 2. In this example, the AUX port is on line 65. Issue these commands in order to configure the router AUX line: Verify Configuration R1# conf t R1(config)# line 65 R1(config line)#modem inout R1(config line)#speed 115200 R1(config line)#transport input all R1(config line)#flowcontrol hardware R1(config line)#login R1(config line)#password cisco R1(config line)# R1# Examine the configuration of the router in order to verify that the commands have been properly entered: The show running config command displays the current configuration of the router: R1#show running config Lines omitted for brevity. password cisco login modem InOut transport input all speed 115200 flowcontrol hardware Lines omitted for brevity. Configure AAA Authentication for Login To enable authentication, authorization, and accounting (AAA) authentication for logins, use the login authentication command in line configuration mode. AAA services must also be configured.

In this example, the router is configured to retrieve users' passwords from a TACACS+ server when users attempt to connect to the router. Note: Configuring the router to use other types of AAA servers (RADIUS, for example) is similar. See Configuring Authentication for additional information. Note: This document does not address configuration of the AAA server itself. Refer to Security Server Protocols for information on configuring the AAA server. 1. From the privileged EXEC (or "enable") prompt, enter configuration mode and enter the commands to configure the router to use AAA services for authentication: configure router# terminal Enter configuration commands, one per line. End with CNTL/Z. router(config)#aaa new model router(config)#aaa authentication login my auth list tacacs+ router(config)#tacacs server host 192.168.1.101 router(config)#tacacs server key letmein 2. Switch to line configuration mode using the following commands. Notice that the prompt changes to reflect the current mode. 3. router(config)#line 1 8 router(config line)# Configure password checking at login. router(config line)#login authentication my auth list 4. Exit configuration mode. router(config line)# router# %SYS 5 CONFIG_I: Configured from console by console Examine the configuration of the router to verify that the commands have been properly entered: show running config displays the current configuration of the router. router#write terminal Current configuration: version 12.0 service timestamps debug uptime service timestamps log uptime no service password encryption hostname router aaa new model aaa authentication login my auth list tacacs+ Lines omitted for brevity

... tacacs server host 192.168.1.101 tacacs server key letmein line con 0 line 1 8 login authentication my auth list line vty 0 4 To test this particular configuration, an inbound or outbound connection must be made to the line. See the Modem Router Connection Guide for specific information on configuring async lines for modem connections. Alternately, you can configure one or more VTY lines to perform AAA authentication and perform your testing thereupon. Troubleshoot AAA Login Failure Before issuing debug commands, see Important Information on Debug Commands. To troubleshoot a failed login attempt, use the debug command appropriate to your configuration: debug aaa authentication debug radius debug kerberos Related Information Configuring Authentication Cisco IOS Debug Command Reference Technical Support Cisco Systems Contacts & Feedback Help Site Map 2014 2015 Cisco Systems, Inc. All rights reserved. Terms & Conditions Privacy Statement Cookie Policy Trademarks of Cisco Systems, Inc. Updated: Jul 13, 2012 Document ID: 45843