Addressing Table
Objectives
In this activity, you will complete the following objectives:
- Part 1: Configure Local AAA Authentication for Enterprise_Router
- Part 2: Configure Local AAA Authentication for ISA3000 for SSH Access
- Part 3: Configure 802.1X authentication for SSH access on Enterprise_Router
Background / Scenario
In this activity, you will configure account-based access control on networking devices in an industrial network. You will create a local user account, configure local AAA on Enterprise_Router, and a RADIUS server on Enterprise_Server. You will use these AAA credentials to remotely access Enterprise_Router via SSH. You will also configure SSH access to a Cisco Industrial Security Appliance (ISA) firewall using local authentication.
The Enterprise_Router and ISA3000 are pre-configured with the following:
- Enable secret password: class
Note: The passwords used in this activity do not meet the password complexity recommended by industrial security best practices. These simple passwords are used in this activity for convenience only.
Instructions
Part 1: Configure Local AAA Authentication for Enterprise_Router
In this part, you will configure a local AAA user for console and SSH access on Enterprise_Router.
Step 1: Configure the local user database.
- The Enterprise_Router is located in the IT network. Click the Enterprise network cloud to access the IT network.
- Local users must be manually configured on each networking device that will use local AAA authentication.
Enterprise_Router(config)# username admin privilege 15 secret cisco
Use of the secret argument in the command configures an encrypted password.
Step 2: Configure local AAA authentication for console access.
- Enable aaa new-model.
- Configure the local login method for console access.
- Verify the AAA authentication method by logging in.
- Configure another user using a username and password of your choice. Log out and log back in using the new user account.
Enterprise_Router(config)# aaa new-model
Enterprise_Router(config)# aaa authentication login default local Enterprise_Router(config)# line con 0 Enterprise_Router(config-line)# login authentication default
Enterprise_Router(config-line)# end Enterprise_Router# exit %SYS-5-CONFIG_I: Configured from console by console Enterprise_Router con0 is now available Press RETURN to get started. ************ AUTHORIZED ACCESS ONLY ************* UNAUTHORIZED ACCESS TO THIS DEVICE IS PROHIBITED. User Access Verification Username: admin Password: cisco Enterprise_Router>
Step 3: Configure local AAA authentication for SSH access.
- Configure ITOT.com as the domain name. A domain name is required for SSH configuration.
- Configure an RSA crypto key using a 2048-bit modulus. This command enables the SSH server on the router for local and remote authentication and generates an RSA-encrypted key pair. Generating an RSA key pair for the device automatically enables SSH. The modulus value defines the encrypted key length. The higher the value the greater the security, however higher values take more time and resources to compute.
- Configure a named list called SSH-LOGIN to authenticate logins using local AAA for SSH access.
- Navigate to IT_Workstation2 in the Enterprise network. Open a command prompt from the desktop. Verify the AAA authentication method from the command prompt on IT_Workstation2 by opening an SSH connection with Enterprise_Router using the admin account in its local user database. If successful, this will open an encrypted remote management session with the router.
- Execute the show running-config command to view the router configuration from the workstation over the network.
- Press Spacebar or Enter to advance or q to exit.
- Type exit to close the connection and try again with the user that you configured previously.
Enterprise_Router(config)# ip domain-name ITOT.com
Enterprise_Router(config)# crypto key generate rsa general-keys modulus 2048 The name for the keys will be: Enterprise_Router.ITOT.com % The key modulus size is 2048 bits
% Generating 2048 bit RSA keys, keys will be non-exportable...[OK] *Mar 5 9:59:12.739: %SSH-5-ENABLED: SSH 1.99 has been enabled
Enterprise_Router(config)# aaa authentication login SSH-LOGIN local Enterprise_Router(config)# line vty 0 4 Enterprise_Router(config-line)# transport input ssh Enterprise_Router(config-line)# login authentication SSH-LOGIN Enterprise_Router(config-line)# end
C:/> ssh -l admin 192.168.10.254 Password: cisco Enterprise_Router>
Enterprise_Router> enable Password: class Enterprise_Router# show running-config
Part 2: Configure Local AAA Authentication for ISA3000 for SSH Access
- Exit the Enterprise cluster by clicking the return arrow at right in the dark blue bar that is above the topology. This will return you to the root view of the network. Click ISA3000 firewall.
- Navigate to the global configuration mode. The enable secret password is class.
- Create a local username on ISA3000.
- Configure a local login method for console access.
- Save your configuration with the copy running-config startup-config command.
- Navigate to IT_Workstation1. Verify the AAA authentication method from the command prompt on IT_Workstation1. From the Desktop Command Prompt enter the following:
ISA3000(config)# username admin password cisco
ISA3000(config)# aaa authentication ssh console local
C:/> ssh -l admin 192.168.10.1 Password: cisco ISA3000>
You can now manage the ISA from the host.
Part 3: Configure 802.1X authentication for SSH access on Enterprise_Router
In this part, you will set up a RADIUS server to authenticate SSH access to Enterprise_Router. The RADIUS server provides a centralized way to manage user accounts that can be accessed by networking devices over the network using the IEEE 802.1X protocol.
Step 1: Configure a RADIUS server.
- Navigate to Enterprise_Server. Select the Services tab. Click AAA on the left side bar.
- Click On to enable the AAA services.
- Enter the following information for the Network Configuration:
- Click Add to save the new client in the server configuration.
- Under User Setup, enter SSHuser as the username and SSHpassword as the password. Click Add to save the new user information.
Client Name: Enterprise_Router Client IP: 192.168.10.254 Secret: ciscosecret ServerType: Radius
Step 2: Configure Enterprise_Router to use the RADIUS server for authentication.
To access the Enterprise_Router, use the user credentials (admin / cisco) created in a previous step and the enable password class.
- Enter the Enterprise cluster and access Enterprise_Router. Configure the following:
- In global configuration mode, configure the RADIUS client (this router) to use the named list SSH-LOGIN to authenticate SSH logins with the RADIUS server.
Enterprise_Router(config)# radius server Enterprise_RADIUS Enterprise_Router(config-radius-server)# address ip 192.168.10.250 Enterprise_Router(config-radius-server)# key ciscosecret
Enterprise_Router(config-radius-server)# exit
Note: Currently, the only type of password available for the RADIUS configuration in Cisco Packet Tracer is unencrypted. An encrypted password should always be used.
Enterprise_Router(config)# aaa authentication login SSH-LOGIN group radius local
Step 3: Verify connectivity.
- From a command prompt on any Workstation PC, ping Enterprise_Router at 192.168.10.254 to verify connectivity. If the ping fails, try another host.
- SSH into 192.168.10.254 with the user information configured on the authentication server. (Username SSHuser and password SSHpassword)
- Enter exit to terminate the SSH session.
- SSH into 192.168.10.254 again. This time, use the username admin and password cisco from the local database configured on the Enterprise_Router.
C:/> ssh -l SSHuser 192.168.10.254
Password: Enterprise_Router>
C:/> ssh -l admin 192.168.10.254
- Navigate to the Enterprise_Server, Disable the AAA Service (Services tab> AAA). SSH into 192.168.10.254 using the admin / cisco credentials.
Answer Scripts
Router Enterprise_Router
configure terminal aaa new-model username admin privilege 15 secret cisco aaa authentication login SSH-LOGIN group radius local aaa authentication login default local ip domain-name ITOT.com radius server Enterprise_RADIUS address ip 192.168.10.250 key ciscosecret line con 0 login authentication default line vty 0 4 transport input ssh login authentication SSH-LOGIN crypto key generate rsa general-keys modulus 2048
Firewall ISA3000
configure terminal username admin password cisco aaa authentication ssh console local copy running-config startup-config