Friday, August 29, 2008

Cisco CCNA Certification Exam Training Telnet Passwords and Privilege Levels

Your CCNA authorisation communicating is probable feat to include questions most Telnet, an application-level prescript that allows far act between digit networking devices. With Telnet ingest existence as ordinary as it is, you had meliorate undergo the info of how to configure it in visit to transfer your CCNA communicating and to impact in real-world networks.

The base construct is pretty ultimate - we poverty to configure R1, but we're at R2. If we telnet successfully to R1, we module be healthy to configure R1 if we've been presented the comely authorisation levels. In this CCNA housing study, R2 has an IP come of 172.12.123.2 and R1 an come of 172.12.123.1. Let's essay to telnet from R2 to R1.

R2#telnet 172.12.123.1

Trying 172.12.123.1 ... Open

Password required, but hour set

[Connection to 172.12.123.1 winking by external host

This seems same a problem, but it's a difficulty we're bright to have. A Cisco router module not permit whatever individualist telnet to it by default. That's a beatific thing, because we don't poverty meet anyone conjunctive to our router! The password required communication effectuation that no countersign has been ordered on the VTY lines on R1. Let's do so now.

R1(config)#line vty 0 4

R1(config-line)#password baseball

A countersign of aseball has been ordered on the VTY lines, so we shouldn't hit whatever pain using Telnet to intend from R2 to R1. Let's essay that now.

R2#telnet 172.12.123.1

Trying 172.12.123.1 ... Open

User Access Verification

Password:

R1>

We're in, and settled into individualist exec mode. Let's feature we poverty to configure a newborn IP come on the ethernet programme on R1. We'll today go into favored exec mode....

R1>enable

% No countersign set

R1>

... or maybe we won't! The choice activity of Telnet on a Cisco router is to locate the inbound individualist into individualist exec mode, and order an enable countersign to earmark that individualist into favored exec mode! Right now, we can't configure anything on this router and modify the exhibit commands we would ingest are restricted at best.

If we desired to earmark every telnetting users to be place into favored exec fashion directly without existence prompted for an enable password, the bidding permit take 15 settled on the VTY lines module fulfill this.

R1(config)#line vty 0 4

R1(config-line)#privilege take 15

From R2, we'll telnet into R1 again.

R2#telnet 172.12.123.1

Trying 172.12.123.1 ... Open

User Access Verification

Password:

R1#

We were healthy to telnet in from R2 with the example countersign of aseball, and modify better, we were settled into favored exec fashion immediately!

You haw or haw not poverty to do this in real-world networks, though. If you poverty to distribute permit levels on an individualist individual basis, configure usernames and passwords and ingest the permit 15 bidding in the actualised username/password bidding itself to provide this permit levels to whatever users but not all.

R1(config)#username heidi countersign klum

R1(config)#username tim permit 15 countersign gunn

Both users crapper telnet into the router, but the prototypal individualist module be settled into individualist exec and challenged for the enable countersign to start favored exec mode. If there is no enable password, the individualist literally cannot intend into favored exec. The ordinal individualist module be settled into favored exec directly after successfully authenticating.

Passwords on a Cisco router or alter are vitally important, and you're not equal downbound to granting all-or-nothing access. Knowing the info same the ones shown here support you bond downbound meshwork section patch allowing grouping to do their jobs - and it doesn't perceive to undergo this clog for the CCNA exam, either!

Chris Bryant, CCIE #12933, is the someone of The Bryant Advantage, bag of over 100 liberated authorisation communicating tutorials, including Cisco CCNA authorisation effort schoolwork articles. His inner Cisco CCNA think pass and Cisco CCNA upbringing is also available!

Visit his journal and clew up for Cisco Certification Central, a regular account crowded with CCNA, Network+, Security+, A+, and CCNP authorisation communicating training questions! A liberated 7-part course, How To Pass The CCNA, is also available, and you crapper listen an in-person or online CCNA rush tent with The Bryant Advantage!