SSH and secure management
Telnet sends credentials in plain text and has no place on a modern network. SSH replaces it with strong encryption. This chapter walks through generating RSA keys, enabling SSH version 2, and locking down VTY lines.
Telnet sends credentials in plain text and has no place on a modern network. SSH replaces it with strong encryption. This chapter walks through generating RSA keys, enabling SSH version 2, and locking down VTY lines.
Telnet (port 23) sends every keystroke and password in cleartext. Anyone on the path can capture credentials with a basic packet capture. SSH (port 22) encrypts the entire session, including the username/password exchange. There is no scenario in 2026 where Telnet is acceptable on a production device.
R1(config)# hostname R1
R1(config)# ip domain-name lab.local
R1(config)# crypto key generate rsa modulus 2048
R1(config)# username admin privilege 15 secret S3cretP@ss
R1(config)# ip ssh version 2
R1(config)# line vty 0 4
R1(config-line)# transport input ssh
R1(config-line)# login local
R1(config-line)# exec-timeout 5 0You can see the title, summary, learning objectives and the opening sections. The rest of this chapter, like all of modules 2–8, comes with the Course & Lab Pass and All-Access Max. A free account opens Module 1: Network Foundations end-to-end and saves your labs — start there, no card required.
NetForge-AI is an independent educational platform and is not affiliated with, endorsed by, or sponsored by any networking vendor or certification body. All product names, protocols, and standards referenced are the property of their respective owners and are used for descriptive, educational purposes only.
Free account · no card required · compare plans any time