Security Fundamentals // Lesson 03

Local Device Access.

Configure and verify console and VTY access using local secrets, privileged mode protection and encrypted SSH.

enable secretLocal userConsoleVTYSSH
01 // Mental model

Start with the big picture.

The enable secret protects access to privileged EXEC functions.

CCNA focus: Verify which database each line uses, whether SSH is the only remote transport, and whether inactivity, retry and source restrictions match policy.
02 // Building blocks

Know what each part does.

01

Privileged mode

The enable secret protects access to privileged EXEC functions.

02

Named accounts

Local usernames create individual identities and support privilege assignment.

03

Line access

Console and VTY lines each need an explicit authentication method.

04

Secret handling

Use secret-based commands and strong unique credentials; avoid reversible or plaintext storage where possible.

03 // Compare and recognise

Read the clues.

ItemWhat to remember
enable secretProtects privileged EXEC with a hashed secret.
username ... secretCreates a local account with protected credential storage.
login localUses the local username database on the line.
service password-encryptionObscures some plaintext passwords but is not a substitute for strong secret hashing.
04 // Harden local access

Harden local access.

R1(config)# enable secret PrivilegedSecret
R1(config)# username admin privilege 15 secret UserSecret
R1(config)# login block-for 120 attempts 3 within 60
R1(config)# line console 0
R1(config-line)# login local
R1(config)# line vty 0 4
R1(config-line)# login local
R1(config-line)# transport input ssh
R1# show login

Read the example from top to bottom, then verify the resulting state. Configuration is only complete when the output matches the intended design.

05 // Exam and troubleshooting

Turn facts into a method.

  • Protects privileged EXEC with a hashed secret.
  • Creates a local account with protected credential storage.
  • Uses the local username database on the line.
  • Obscures some plaintext passwords but is not a substitute for strong secret hashing.
Exam checkpoint: Verify which database each line uses, whether SSH is the only remote transport, and whether inactivity, retry and source restrictions match policy.
06 // Check yourself

Local Device Access quiz.

1. Which command protects privileged EXEC mode?

2. What does login local use?

3. Why prefer username ... secret over username ... password?

4. Which remote transport should be permitted instead of Telnet?

5. What can login block-for reduce?

Score: 0 / 5