Network Access // Lesson 08

Device Management Access.

Compare console, SSH, Telnet, web, AAA and cloud-managed access so you can choose and verify a safe management path.

ConsoleSSHHTTPSAAACloud-managed
01 // Mental model

Start with the big picture.

Console access works without IP connectivity and is invaluable for initial setup or recovery.

CCNA focus: Prefer encrypted protocols, restrict who can reach the management plane, use central AAA where appropriate and retain a tested recovery path.
02 // Building blocks

Know what each part does.

01

Out-of-band

Console access works without IP connectivity and is invaluable for initial setup or recovery.

02

In-band

SSH and HTTPS depend on reachable IP addressing, routing and permitted management traffic.

03

AAA

TACACS+ or RADIUS can centralise authentication, authorisation and accounting.

04

Cloud managed

A device forms a secure outbound relationship to a vendor platform for central policy and visibility.

03 // Compare and recognise

Read the clues.

ItemWhat to remember
ConsoleLocal, out-of-band and unencrypted; physical access is required.
TelnetRemote CLI with plaintext credentials and payload; avoid when SSH is available.
SSH / HTTPSEncrypted remote CLI or browser management.
TACACS+ / RADIUSCentral AAA services; TACACS+ is commonly used for device administration.
04 // Secure management baseline

Secure management baseline.

SW1(config)# hostname SW1
SW1(config)# ip domain-name baznetic.local
SW1(config)# username netadmin privilege 15 secret StrongSecret
SW1(config)# crypto key generate rsa modulus 2048
SW1(config)# line vty 0 4
SW1(config-line)# login local
SW1(config-line)# transport input ssh
SW1# show ip ssh

Read the example from top to bottom, then verify the resulting state. Configuration is only complete when the output matches the intended design.

05 // Exam and troubleshooting

Turn facts into a method.

  • Local, out-of-band and unencrypted; physical access is required.
  • Remote CLI with plaintext credentials and payload; avoid when SSH is available.
  • Encrypted remote CLI or browser management.
  • Central AAA services; TACACS+ is commonly used for device administration.
Exam checkpoint: Prefer encrypted protocols, restrict who can reach the management plane, use central AAA where appropriate and retain a tested recovery path.
06 // Check yourself

Device Management Access quiz.

1. Which method works before the device has IP connectivity?

2. Why is Telnet unsafe on an untrusted path?

3. Which protocol provides an encrypted remote CLI?

4. What does the first A in AAA represent?

5. What must exist for in-band management to work?

Score: 0 / 5