welcome to pack of tracer two point two
point three point four configuring
initial switch settings objectives part
1 verify the default switch
configuration part to configure a basic
switch configuration part 3 configure a
MOTD banner message of the day part 4
save configuration files to NVRAM part 5
configure s2 background in this activity
you will perform basic switch
configurations you will secure access to
the command-line interface and console
ports using encrypted and plaintext
passwords you also learn how to
configure messages for users logging
into the switch these banners are also
used to warn unauthorized users that
access is prohibited
part-1 verify the default switch
configuration step 1 enter privileged
exec mode click s1 in the CLI cap press
enter
[Music]
type in and maple
[Music]
we are now in privileged exec mode
[Music]
step to examine the current switch
configuration
[Music]
show running config answer the following
questions
[Music]
how many fast ethernet faces does a
switch have how many gigabit ethernet
faces does a switch have
[Music]
what is the range of value shown for the
vty lines 0 through 15 which command
will display the current contents of
non-volatile random access memory that
will be show startup configuration
why does a switch respond with startup
config is not present it displays this
message because the configuration of
file was not saved nvram currently is
only located in RAM
[Music]
part to create a basic switch
configuration assign and aim to a switch
[Music]
hostname s1
[Music]
exit
[Music]
step2 secure access to the console line
to secure access to the console line
access the big line mode and set the
console password to let me in
[Music]
[Music]
why is the logging in command required
in order for the password checking
process to work it requires both the
login and password commands
step 3 verify that console access is
secured switch con 0 is now available
press return to get started
password
if the Swiss should not prompt you for a
password then you did not configure the
login parameter in step 2 right there
[Music]
step 4
secure privilege mode access set the
enable password to see one dollar sign
see oh the password protects access to
privileged mode let me in
enable config terminal enable password
[Music]
Step five verify that privilege mode
access is secure
[Music]
enter the exit command again to logout
switch press enter enter the password
let me in enter the command access
privilege exemption and we need the
password for that and we are in verify
the configurations by examining the
contents of the running configuration
file show running config notice how the
console and enabled passwords are both
in plaintext this could pose a security
risk if someone is looking over your
shoulder shoulder surfing
step six configure an encrypted password
to secure access to privileged mode
[Music]
[Music]
the enable secret password overrides the
enable password if both are configured
on the switch you must enter the enable
secret password to enter privileged exec
mode step 7 verify the den navels secret
password is added to the configuration
file enter the show running config
command again to verify the new enable
secret password is configured
[Music]
what is display for the naval secret
password sprite here why is the enable
secret password displayed differently
than what we configured the enable
secret is shown in encrypted form
whereas the enable password is in plain
text step 8
encrypt the enable and console passwords
as you noticed in step seven the enable
secret password was encrypted but the
enable of console passwords were still
in plain text
we will now encrypt these plaintext
passwords using the service password
encryption command
[Music]
[Music]
if you configure any more passwords on
the switch will they be displayed in the
configuration file as plaintext or
encrypted form explain the service
password encryption command encrypts all
current and future passwords part 3
configure and MOTD banner message of the
day
step 1 configure a message of the day
banner
[Music]
[Music]
when will this banners be displayed
the message will be displayed when
someone enters a switch through the
console port why should every switch
have a message of the day banner every
switch should have a banner to warn
unauthorized users that access is
prohibited but can also be used for
sending messages to network personnel
technicians such as impending system
shutdowns or who to contact for access
part 4 save configuration files to NVRAM
copy running-config startup config
what is the shortest abbreviated version
of the copy running-config start config
command copy run start actually I think
it might be cop are in this but I go
copy run start
[Music]
step 3 examine the startup configuration
file which command will display the
contents of NVRAM show startup config
are all the changes that were entered to
recorded in this file yes
is the same as the running configuration
[Music]
part five configure s2
[Music]
name device s2
[Music]
protect access to the console using the
led median password
[Music]
[Music]
configure an enable password of Cisco
and enable secret password it's a secret
[Music]
[Music]
configure and message to those to to
those logging into the switch with a
following message
[Music]
[Music]
encrypt all plaintext passwords
[Music]
[Music]
ensure the configuration is correct
save the configuration file to weight
loss
the switch is powered down
[Music]
[Music]
and do we are all done 72 out of 72
thank you for watching my video and have
a nice day