Compare console, SSH, Telnet, web, AAA and cloud-managed access so you can choose and verify a safe management path.
ConsoleSSHHTTPSAAACloud-managed
01 // Mental model
Start with the big picture.
Console access works without IP connectivity and is invaluable for initial setup or recovery.
CCNA focus: Prefer encrypted protocols, restrict who can reach the management plane, use central AAA where appropriate and retain a tested recovery path.
02 // Building blocks
Know what each part does.
01
Out-of-band
Console access works without IP connectivity and is invaluable for initial setup or recovery.
02
In-band
SSH and HTTPS depend on reachable IP addressing, routing and permitted management traffic.
03
AAA
TACACS+ or RADIUS can centralise authentication, authorisation and accounting.
04
Cloud managed
A device forms a secure outbound relationship to a vendor platform for central policy and visibility.
03 // Compare and recognise
Read the clues.
Item
What to remember
Console
Local, out-of-band and unencrypted; physical access is required.
Telnet
Remote CLI with plaintext credentials and payload; avoid when SSH is available.
SSH / HTTPS
Encrypted remote CLI or browser management.
TACACS+ / RADIUS
Central AAA services; TACACS+ is commonly used for device administration.
04 // Secure management baseline
Secure management baseline.
SW1(config)# hostname SW1SW1(config)# ip domain-name baznetic.localSW1(config)# username netadmin privilege 15 secret StrongSecretSW1(config)# crypto key generate rsa modulus 2048SW1(config)# line vty 0 4SW1(config-line)# login localSW1(config-line)# transport input sshSW1# show ip ssh
Read the example from top to bottom, then verify the resulting state. Configuration is only complete when the output matches the intended design.
05 // Exam and troubleshooting
Turn facts into a method.
Local, out-of-band and unencrypted; physical access is required.
Remote CLI with plaintext credentials and payload; avoid when SSH is available.
Encrypted remote CLI or browser management.
Central AAA services; TACACS+ is commonly used for device administration.
Exam checkpoint: Prefer encrypted protocols, restrict who can reach the management plane, use central AAA where appropriate and retain a tested recovery path.
06 // Check yourself
Device Management Access quiz.
1. Which method works before the device has IP connectivity?
2. Why is Telnet unsafe on an untrusted path?
3. Which protocol provides an encrypted remote CLI?
4. What does the first A in AAA represent?
5. What must exist for in-band management to work?