Incomplete Packet Tracer - Implement Access Control

Addressing Table

Device

Interface

IP Address

Subnet Mask

Default Gateway

Enterprise_Router

G0/0/0

192.168.10.254

255.255.255.0

N/A

G0/0/1

209.165.200.226

255.255.255.240

N/A

Enterprise_SW2

VLAN 1

192.168.10.252

255.255.255.0

192.168.10.254

ISP

G0/0/1

209.165.200.225

255.255.255.240

N/A

IT_Workstation1

NIC

DHCP

IT_Workstation2

NIC

DHCP

ISA3000

G1/1

192.168.10.1

255.255.255.0

192.168.10.254

G1/2

172.16.1.254

255.255.254.0

172.16.1.254

Switch0

VLAN 1

172.16.1.240

255.255.254.0

172.16.1.254

Enterprise_SW1

VLAN 1

192.168.10.251

255.255.255.0

192.168.10.254

Engineering_Workstation

NIC

DHCP

Enterprise_Server

NIC

192.168.10.250

255.255.255.0

192.168.10.254

SCADA

NIC

192.168.10.240

255.255.255.0

192.168.10.254

Objectives

In this activity, you will complete the following objectives:

  • Part 1: Configure Local AAA Authentication for Enterprise_Router
  • Part 2: Configure Local AAA Authentication for ISA3000 for SSH Access
  • Part 3: Configure 802.1X authentication for SSH access on Enterprise_Router

Background / Scenario

In this activity, you will configure account-based access control on networking devices in an industrial network. You will create a local user account, configure local AAA on Enterprise_Router, and a RADIUS server on Enterprise_Server. You will use these AAA credentials to remotely access Enterprise_Router via SSH. You will also configure SSH access to a Cisco Industrial Security Appliance (ISA) firewall using local authentication.

The Enterprise_Router and ISA3000 are pre-configured with the following:

  • Enable secret password: class

Note: The passwords used in this activity do not meet the password complexity recommended by industrial security best practices. These simple passwords are used in this activity for convenience only.

Instructions

Part 1: Configure Local AAA Authentication for Enterprise_Router

In this part, you will configure a local AAA user for console and SSH access on Enterprise_Router.

Step 1: Configure the local user database.

  1. The Enterprise_Router is located in the IT network. Click the Enterprise network cloud to access the IT network.
  2. Local users must be manually configured on each networking device that will use local AAA authentication.
  3. Enterprise_Router(config)# username admin privilege 15 secret cisco

    Use of the secret argument in the command configures an encrypted password.

Step 2: Configure local AAA authentication for console access.

  1. Enable aaa new-model.
  2. Enterprise_Router(config)# aaa new-model
  3. Configure the local login method for console access.
  4. Enterprise_Router(config)# aaa authentication login default local
    Enterprise_Router(config)# line con 0
    Enterprise_Router(config-line)# login authentication default
  5. Verify the AAA authentication method by logging in.
  6. Enterprise_Router(config-line)# end
    Enterprise_Router# exit
    %SYS-5-CONFIG_I: Configured from console by console
    
    
    Enterprise_Router con0 is now available
    
    Press RETURN to get started.
    
    ************ AUTHORIZED ACCESS ONLY *************
    UNAUTHORIZED ACCESS TO THIS DEVICE IS PROHIBITED.
    
    User Access Verification
    
    Username: admin
    Password: cisco
    Enterprise_Router>
  7. Configure another user using a username and password of your choice. Log out and log back in using the new user account.

Step 3: Configure local AAA authentication for SSH access.

  1. Configure ITOT.com as the domain name. A domain name is required for SSH configuration.
  2. Enterprise_Router(config)# ip domain-name ITOT.com
  3. Configure an RSA crypto key using a 2048-bit modulus. This command enables the SSH server on the router for local and remote authentication and generates an RSA-encrypted key pair. Generating an RSA key pair for the device automatically enables SSH. The modulus value defines the encrypted key length. The higher the value the greater the security, however higher values take more time and resources to compute.
  4. Enterprise_Router(config)# crypto key generate rsa general-keys modulus 2048
    The name for the keys will be: Enterprise_Router.ITOT.com
    % The key modulus size is 2048 bits
    % Generating 2048 bit RSA keys, keys will be non-exportable...[OK]
    *Mar 5 9:59:12.739: %SSH-5-ENABLED: SSH 1.99 has been enabled
  5. Configure a named list called SSH-LOGIN to authenticate logins using local AAA for SSH access.
  6. Enterprise_Router(config)# aaa authentication login SSH-LOGIN local
    Enterprise_Router(config)# line vty 0 4
    Enterprise_Router(config-line)# transport input ssh
    Enterprise_Router(config-line)# login authentication SSH-LOGIN
    Enterprise_Router(config-line)# end
  7. Navigate to IT_Workstation2 in the Enterprise network. Open a command prompt from the desktop. Verify the AAA authentication method from the command prompt on IT_Workstation2 by opening an SSH connection with Enterprise_Router using the admin account in its local user database. If successful, this will open an encrypted remote management session with the router.
  8. C:/> ssh -l admin 192.168.10.254
    Password: cisco
    Enterprise_Router>
  9. Execute the show running-config command to view the router configuration from the workstation over the network.
  10. Enterprise_Router> enable
    Password: class
    Enterprise_Router# show running-config
  11. Press Spacebar or Enter to advance or q to exit.
  12. Type exit to close the connection and try again with the user that you configured previously.

Part 2: Configure Local AAA Authentication for ISA3000 for SSH Access

  1. Exit the Enterprise cluster by clicking the return arrow at right in the dark blue bar that is above the topology. This will return you to the root view of the network. Click ISA3000 firewall.
  2. Navigate to the global configuration mode. The enable secret password is class.
  3. Create a local username on ISA3000.
  4. ISA3000(config)# username admin password cisco
  5. Configure a local login method for console access.
  6. ISA3000(config)# aaa authentication ssh console local
  7. Save your configuration with the copy running-config startup-config command.
  8. Navigate to IT_Workstation1. Verify the AAA authentication method from the command prompt on IT_Workstation1. From the Desktop Command Prompt enter the following:
  9. C:/> ssh -l admin 192.168.10.1
    Password: cisco
    ISA3000>

    You can now manage the ISA from the host.

Part 3: Configure 802.1X authentication for SSH access on Enterprise_Router

In this part, you will set up a RADIUS server to authenticate SSH access to Enterprise_Router. The RADIUS server provides a centralized way to manage user accounts that can be accessed by networking devices over the network using the IEEE 802.1X protocol.

Step 1: Configure a RADIUS server.

  1. Navigate to Enterprise_Server. Select the Services tab. Click AAA on the left side bar.
  2. Click On to enable the AAA services.
  3. Enter the following information for the Network Configuration:
  4. Client Name:    Enterprise_Router
    Client IP:      192.168.10.254
    Secret:         ciscosecret
    ServerType:     Radius
  5. Click Add to save the new client in the server configuration.
  6. Under User Setup, enter SSHuser as the username and SSHpassword as the password. Click Add to save the new user information.

Step 2: Configure Enterprise_Router to use the RADIUS server for authentication.

To access the Enterprise_Router, use the user credentials (admin / cisco) created in a previous step and the enable password class.

  1. Enter the Enterprise cluster and access Enterprise_Router. Configure the following:
  2. Enterprise_Router(config)# radius server Enterprise_RADIUS
    Enterprise_Router(config-radius-server)# address ip 192.168.10.250
    Enterprise_Router(config-radius-server)# key ciscosecret
    Enterprise_Router(config-radius-server)# exit

    Note: Currently, the only type of password available for the RADIUS configuration in Cisco Packet Tracer is unencrypted. An encrypted password should always be used.

  3. In global configuration mode, configure the RADIUS client (this router) to use the named list SSH-LOGIN to authenticate SSH logins with the RADIUS server.
  4. Enterprise_Router(config)# aaa authentication login SSH-LOGIN group radius local

Step 3: Verify connectivity.

  1. From a command prompt on any Workstation PC, ping Enterprise_Router at 192.168.10.254 to verify connectivity. If the ping fails, try another host.
  2. SSH into 192.168.10.254 with the user information configured on the authentication server. (Username SSHuser and password SSHpassword)
  3. C:/> ssh -l SSHuser 192.168.10.254
    Password: 
    Enterprise_Router>
  4. Enter exit to terminate the SSH session.
  5. SSH into 192.168.10.254 again. This time, use the username admin and password cisco from the local database configured on the Enterprise_Router.
  6. C:/> ssh -l admin 192.168.10.254
What was the result?
Answer Area
The login attempt failed.
  1. Navigate to the Enterprise_Server, Disable the AAA Service (Services tab> AAA). SSH into 192.168.10.254 using the admin / cisco credentials.
What did you observe?
Answer Area
The login succeeds. AAA authentication uses the authentication methods in the order that they appear in the device configuration. In this example, while the authentication server is operational, the router uses the credentials (SSHuser / SSHpassword) configured on the RADIUS server for authentication. If the server is powered down, or no longer accessible, the second listed method is used for authentication. In this example, it is admin / cisco from the local database as the backup.

Answer Scripts

Router Enterprise_Router

configure terminal
aaa new-model
username admin privilege 15 secret cisco
aaa authentication login SSH-LOGIN group radius local
aaa authentication login default local
ip domain-name ITOT.com
radius server Enterprise_RADIUS
 address ip 192.168.10.250
 key ciscosecret
line con 0
 login authentication default
line vty 0 4
 transport input ssh
 login authentication SSH-LOGIN
crypto key generate rsa general-keys modulus 2048

Firewall ISA3000

configure terminal
username admin password cisco
aaa authentication ssh console local
copy running-config startup-config

© 2024 - 2025 Cisco and/or its affiliates. All rights reserved. Cisco Public