SSH Flashcards
T/F: By default, no password is needed to access the CLI of a Cisco device via console port
T
T/F: By default, the password needed to access the Cisco CLI is ‘password’
F
By default, there is no password needed to access the CLI via console port
T/F: You can configure a password on the console line, which means that a user will have to enter a password to access the CLI via console port
T
How many console lines are there on a Cisco IOS device
1
What is the series of commands to enable a password for the CLI via console port
line console 0
password {password}
login
What is the series of commands to require users to login using a configured username on the console port
username {username} secret {password}
line console 0
login local
What is the command to log a user out after a certain amount of inactivity on a console line
exec-timeout {mins} {seconds}
T/F: You can assign an IP address to an SVI to allow remote connections to the switch CLI
T
T/F: You can only assign an IP address for remote switch management on L3 switches
F
You can assign an IP address to an SVI on L2 only switches to facilitate remote SSH management
T/F: You don’t need to configure a default gateway on a switch for remote SSH management
F
You should always configure a default gateway for this
What is the command to assign a default gateway for an L2 Cisco Switch
ip default-gateway [ip-addr]
What is the series of commands to assign an IP address to an SVI
interface [svi]
ip address [ip-addr] [subnet-mask]
no shutdown
T/F: Telnet is more secure than SSH and should be used instead
F
Telnet is unencrypted and should never be used as it is a security risk
T/F: Telnet is unencrypted and should never be used for remote management
T
T/F: Telnet is insecure and should be disabled for network management
T
What is the protocol and port which a telnet server listens for telnet traffic on
TCP 23
List the series of commands for configuring Telnet access on a switch
- enable secret password
- username username secret password
- access-list 1 permit host host-ip
- line vty 0 15
- login local
- exec-timeout minutes seconds
- transport input telnet
- access-class 1 in
What does VTY stand for
Virtual TeleType
What is the command to specify which protocols are allowed to connect to a VTY line
transport input { telnet | ssh | telnet ssh | all | none }
What is the difference between the access-class and ip access-group commands
access-class applies an ACL to VTY lines
ip access-group applies an ACL to an interface
T/F: SSH is unencrypted and should never be used for remote switch management
F
What protocol and port does SSH use
TCP 22
T/F: Not all IOS versions support SSH, you should ensure that your version does before configuring SSH
T
IOS images that support SSH will have ‘K9’ in the version name.
What is the command to view an overview of SSH information on a device
sh ip ssh
T/F: Cisco IOS automatically generates RSA public and private key pairs for SSH on boot
F
This must be done manually as part of SSH configuration
What is the series of actions required for configuring SSH RSA keys
- Configure domain name of the switch w/ FQDN
- Generate the RSA key
What is the series of commands required for configuring SSH RSA keys
- ip domain name fqdn
- crypto key generate rsa modulus length (length must be > 768 bits)
What is the series of steps for configuring SSH access on a Cisco device
- Configure hostname
- Configure DNS domain name
- Generate RSA key pair
- Configure enable PW, username/PW
- Enable SSH (v2 only)
- Configure VTY lines
What is the series of commands for configuring SSH access on a Cisco device
- ip default gateway
- line con 0
- line vty 0 15
- crypto key generate rsa
- ip ssh version 2
- login local
- transport input [protocols | all | none]
- exec-timeout minutes sec
- access-class acl in
You issue the crypto key generate rsa command on a Cisco router, but the command is rejected. Which of the following might be the cause? (select multiple)
a) A host name hasn’t been configured
b) The ip ssh version 2 command hasn’t been configured
c) The transport input ssh command hasn’t been configured
d) Only switches can generate RSA keys
e) A DNS domain name hasn’t been configured
f) SSH version 1.99 is enabled
A and E
Which of the following commands would allow both Telnet and SSH to be used to connect to the VTY lines of a device (select 2)
a) transport input default
b) transport input none
c) transport input telnet ssh
d) transport input all
C and D
You want to allow only 192.168.1.1 to connect to R1 via SSH. Which configs need to be made to accomplish this?
- Create an ACL that only allows traffic on port 22 from 192.168.1.1
- Apply the ACL to all in traffic on all VTY lines
Which of the following statements about SSH are true? (pick 2)
a) RSA keys are optional but recommended
b) K9 IOS images support SSH
c) SSH version 1.99 was released between version 1 and 2
d) SSH sends data in plain text
e) NPE IOS images support SSH
f) A key length of at least 768 bits is required for SSHv2
B and F
A network admin using PC1 is remotely configuring SW1 by connecting to the CLI of SW1 via SSH. What is the role of SW1 in this situation?
a) SSH peer
b) SSH server
c) SSH client
d) None of the above
B
You want to configure SSH for incoming VTY connections on a router with the host name Router1. Router1 is running a K9 IOS image but has not yet been configured with a domain name or RSA key pair. In addition, the VTY lines are not yet configured to accept incoming SSH connections.
You issue the crypto key generate rsa command from global configuration mode.
Which of the following messages will you most likely receive?
a) The name for the keys will be:
b) Please define a domain-name first
c) Please create RSA keys to enable SSH
d) Please define a hostname other than Router
e) Please enable SSH version 2
B
Which of the following commands automatically enables SSH on a router?
a) enable secret
b) no transport input telnet
c) crypto key zeroize rsa
d) transport input ssh
e) crypto key generate rsa
e) crypto key generate rsa
What is the command to remove RSA keys from a router?
crypto key zeroize rsa
You’ve done zero SSH setup on a new router so far. You issue the ip ssh time-out 60 command, what is the message you are likely to receive?
Please create RSA keys to enable SSH