ITNE2006 VIT - Securing Administrative Access Using AAA and RADIUS
VerifiedAdded on 2023/06/13
|11
|544
|155
Practical Assignment
AI Summary
This document provides a detailed solution to a lab assignment focused on securing administrative access using AAA and RADIUS. The solution covers configuring basic device settings, including hostnames, interface IP addresses, and access passwords, as well as static routing. It demonstrates th...

Network Topology
Paraphrase This Document
Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser

Task 1: Configure Basic Device Settings
Router R1
Router R3
Router R1
Router R3

Router R2
Router R1 – Set Clock Rate
Router R2 – Set Clock Rate
Router R1 – Set Clock Rate
Router R2 – Set Clock Rate
⊘ This is a preview!⊘
Do you want full access?
Subscribe today to unlock all pages.

Trusted by 1+ million students worldwide

Router R3 – Set Clock Rate
Show IP Interface (R1)
Show IP Route (R1)
Show IP Interface (R1)
Show IP Route (R1)
Paraphrase This Document
Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser

Show IP Interface (R2)
Show IP Route (R2)
Show IP Interface (R3)
Show IP Route (R2)
Show IP Interface (R3)

Show IP Route (R3)
Step 8e)
Before encryption,
Mode Password
Console ciscoconpass
Telnet (vty) ciscovtypass
AUX ciscoauxpass
After encryption,
Step 8e)
Before encryption,
Mode Password
Console ciscoconpass
Telnet (vty) ciscovtypass
AUX ciscoauxpass
After encryption,
⊘ This is a preview!⊘
Do you want full access?
Subscribe today to unlock all pages.

Trusted by 1+ million students worldwide

We could not able to view the con, aux and vty password in running configuration, because we
configured as service password-encryption. It is used to prevent the unauthorized user to view the
password in the running router
Part 2: Configure Local Authentication
Step 1a
The following command is used to create the local user account with type 9 hashing algorithm
username user01 privilege 9 secret user01pass
Step 1b
No, I am not able to view the user’s password. It shows as
Step 1c
What is the difference between logging in at the console now and previously?
Now, it asks the username and then password for the user
Previously, it asks the console password to enter
configured as service password-encryption. It is used to prevent the unauthorized user to view the
password in the running router
Part 2: Configure Local Authentication
Step 1a
The following command is used to create the local user account with type 9 hashing algorithm
username user01 privilege 9 secret user01pass
Step 1b
No, I am not able to view the user’s password. It shows as
Step 1c
What is the difference between logging in at the console now and previously?
Now, it asks the username and then password for the user
Previously, it asks the console password to enter
Paraphrase This Document
Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser

Step 1d
We should enter the enable secret password. So we should use enable command after login the user
Step 3e
Telnet to R1 from R2
First we should enter vty password (ciscovtypass) and then enter enable password (cisco12345)
After enable the login local in vty mode, we try to login R1 from R2
It asks the username and password
We should enter the enable secret password. So we should use enable command after login the user
Step 3e
Telnet to R1 from R2
First we should enter vty password (ciscovtypass) and then enter enable password (cisco12345)
After enable the login local in vty mode, we try to login R1 from R2
It asks the username and password

While connected to R1 via Telnet, access privileged EXEC mode with the enable command.
What password did you use?
cisco12345
Part 3: Configure Local Authentication using AAA on R3
Step 1b
We could not able to view the user’s password
Task2 – Step2
We can able to login using Admin01
Task2 – Step2d. Attempt to log in to the console as baduser with any password. Were you able to log
in? Explain.
Not able to login as baduser
If no user accounts are configured in the local database, which users are permitted to access the device?
Previous configuration command is,
aaa authentication login default local-case none
Here none means no authentication requires if no user accounts found
What password did you use?
cisco12345
Part 3: Configure Local Authentication using AAA on R3
Step 1b
We could not able to view the user’s password
Task2 – Step2
We can able to login using Admin01
Task2 – Step2d. Attempt to log in to the console as baduser with any password. Were you able to log
in? Explain.
Not able to login as baduser
If no user accounts are configured in the local database, which users are permitted to access the device?
Previous configuration command is,
aaa authentication login default local-case none
Here none means no authentication requires if no user accounts found
⊘ This is a preview!⊘
Do you want full access?
Subscribe today to unlock all pages.

Trusted by 1+ million students worldwide

Task2 – Step3c. Log in as Admin01 with a password of Admin01pass. Were you able to login? Explain
Yes, Username and password are found in the database
Task2 – Step3e. Attempt to log in as baduser with any password. Were you able to login? Explain
No, No user name (baduser) found in the database. Another one, we did not configure login-local as none
in VTY mode
If you login from R2 using valid user (Admin01), the debug message in R3
If enter baduser to login from telnet mode
Yes, Username and password are found in the database
Task2 – Step3e. Attempt to log in as baduser with any password. Were you able to login? Explain
No, No user name (baduser) found in the database. Another one, we did not configure login-local as none
in VTY mode
If you login from R2 using valid user (Admin01), the debug message in R3
If enter baduser to login from telnet mode
Paraphrase This Document
Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser

If enter baduser to login from enable mode, debug messages are,
What message was displayed on the Telnet client screen?
%Authentication failed message will be displayed
What message was displayed on the Telnet client screen?
%Authentication failed message will be displayed
1 out of 11
Related Documents

Your All-in-One AI-Powered Toolkit for Academic Success.
+13062052269
info@desklib.com
Available 24*7 on WhatsApp / Email
Unlock your academic potential
© 2024 | Zucol Services PVT LTD | All rights reserved.