All language subtitles for 11 - Switching - Base Configuration-eng

af Afrikaans
ak Akan
sq Albanian
am Amharic
ar Arabic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranรฎ)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal)
pa Punjabi
qu Quechua
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

[Inaudible Remark]

>> You run to the door 'cause you know that that sound means a delivery truck

and they're bringing the Cisco switches that you ordered.

And sure enough, there's the delivery guy unloading them from the truck,

bring them in on a little push cart and you got them in your organization.

You pull them out of the box and you look at them,

they smell great, they look good, now what?

That's going to be where we pick up here.

Two things I want to discuss,

one is understanding the physical connections then we'll get into the base IOS configurations

to optimize how these switches operate.

So the first thing that you want to do with that switch is get it physically connected.

Okay, now this is a piece that is actually not much of the CCNA certification at all.

And I still I'm not completely sure as to why.

I have some ideas but for the most part,

Cisco assume somebody else does all the physical connections which sometimes is true,

sometimes you have a cabling company that comes in and does all this.

But if you're new into the network world and you haven't seen,

at least seen how old this stuff physically connects together,

this is a hugely valuable piece to understand.

A lot of you may have started here.

This is where you first got your feet wet in the network world is doing cabling.

So, the computers in your organizations, and servers, and printers,

and fill in the device here that connects to the network,

everything all eventually terminates to an Ethernet wire.

Even if you have a wireless device, you know, here's you're iPad where you're scribbling

on the screen, it's going Wi-Fi, well, that Wi-Fi eventually terminates

to a wireless access point which is physically plugged into the network.

So it's essentially converting your wireless communication down to some form of wire.

Now, if you look in an organization, you'll see, you know, physically and walk around,

you will see Cat5, Cat6 cabling wall jacks that are everywhere.

Now, inside of-- if you were to, you know, I don't want to get down to this level

but you could actually take those jacks out and physically look at them.

Actually, let me just bring up a picture from MonoPrice.

This is what a wall jack looks like.

You have the play tray here where this little widget,

the little connector just snaps right into it.

This is what it looks like.

So, really, this is kind of a small little punch down block and what that means is if you look

at the back of this right here are all the little punch down connection.

So, you take a cable which an Ethernet cable,

if you strip back the shielding is eight individual wires

with specific color code, and you line them up.

You put wire 1, I can't draw.

You put wire 1 right there, wire 2 right there, wire 3,

and you actually use something called a punch down tool.

Actually, let me just-- make sure I get all the pieces in place.

So let's see.

We've got-- there's-- there we are.

So, a punch down tool which this little guy has a blade on-- man, I need my arrows.

This little guy has a blade on it where he will actually take that little wire

and punch it down, thus the name, kind of push it down into this slot and kind

of move that where all the way down.

Now, inside of the there, if you were to somehow see the view inside,

you would see that there's very sharp metal connectors in there that when the cable that--

or I shouldn't say the cable, the wire, the individual wire from the cable gets pushed

down in there, it's strips off the shielding of the wire and makes a physical metal

to metal connection allowing the communication to flow.

So you do that with each one of the eight wires.

And you can see down at the bottom, depending on the wall jack,

it will actually give you a little color code of what that is and then this is just showing,

when you're done putting all the wires in there's, you usually, I actually don't,

I'm kind of lazy, but you will usually put these little protectors on there

that will peel off your fingernails if you try and get them off,

to keep the wires from popping back out

and then you take this little widget and push it on the wall jack.

So you physically have cabling that are all running through the walls

that terminate those wall jacks and those wall jacks are what plugged

in to your actual computer or whatever device you want to do.

Now, if you were to follow it up the wall, it would go up the dry wall through the ceiling

or whatever kind of environment you have, however you're running that wire,

and eventually come down and terminate into your IT room.

Now, not shown here and I got to give these guys props, this is a beautiful looking network.

I always love seeing just a nice clean cabling, you now, the spaghetti string, I loathe just so,

you know, I'm like I just want to clean it up.

I want to fix it.

You know, it's like, you know, some people like the scenery, you know, you're like, "Oh,

the beautiful sunset," you know, shed a tear, for me, I'm like, "Oh, look at that cabling."

You know, I'm going to cry, tear, it's beautiful.

So, the cable comes out of the wall and you're actually going to--

it's not shown here 'cause it's probably not as pretty but you got a big old bundle

of cable coming out of the ceiling or whatever usually wire-tied or whatever.

Bring it back down to behind of these guys.

Now these, these are not switches.

These are patch panels.

What the patch panels do is act as a little termination point

where I can bring all the cable out of the ceiling, you know, so it's running from the wall

through the ceiling, it comes out right here and I actually,

if you were to flip these guys around, here, I'll show you.

Okay, so here is a example of a little 12 port patch panel, you know.

The ones that are on there are 24 port, but if you flip that guy around actually,

let's do them in here, if you flip that guy around, this is actually a whole bunch

of those little like, you know, if we go back here or a whole bunch of these things.

It's not as zoomed in so we can't see it quite as well but really, that's all these are.

It's a bunch of a little punch down.

So, all of that cabling, all that cabling comes out of the ceiling

and gets punched into the magnets.

Does it take a long time?

Yeah. Does it hurt your fingers?

Yeah. So using that little punch down tool effectively, what that tool does

that I showed you will actually punch that wire in there and then if as long

as the blade is sharp enough, we'll actually cut it off.

Like this one actually comes with a small little punch

down tool right here that's probably not going to work as well

but hey, it's free, might as well.

So this will push those wires into the--

each one of those little openings and now you have all the wires connected a patch panel.

Now, patch panels are optional kind of.

You might say, "Well, can I just bring all of these wires out of the ceiling and instead

of punching them into here, just put little Cat5 or Cat6 ends on them to where you got the wire

and now you clip a little end on them with-- that's actually backwards but put the little tip

on them that plugs in the computer.

Yes, you could.

You could actually bring those and then plug those directly into the switch.

However, now you're stuck, if you ever want to move your switches

around like let's say you put your switches right here, that's where you mounted them

and that's where you cut the wires too.

And then you go, "Oh man, because of, you know, something,

we have to move our switches over to this one."

Now you're stuck because you've got all these wires with tips on them that are terminated

at that point and you can't, you know, make them longer easily anyway.

So, you're stuck.

You have to leave your switches there where if you've got patch panels,

patch panels are just dummy devices.

There's no power to them.

They're just kind of a coupler that take the wire from the wall and move to a jack.

And then you can buy however long cables you want to connect from the patch panel.

Now, these cables actually go up, you know, through the nicely wire-tied conduit

that they have here and then run down into the individual switches.

So down here are the switches.

The ones that came from the delivery truck and you mounted into your rack so you take the cable

from the patch panel and plug it into here and now you have full communication.

So that's a view of the physical connections of the switch infrastructure.

Again, it's not typically covered too much in the CCNA.

You probably won't to see it on the exam.

There-- Cisco of course, since they don't really manufacture patch panels,

they're more interested in do you know the switch itself.

So, here's what the Cisco switch looks like.

Now this one I can tell just because I've owned a number of those,

that's a Cisco 3550 switch which is a great switch.

It's a 10/100, it's not gigabit, but it's a 10/100 switch great for a lab environment

because it actually does layer three switching.

It does all kinds of stuff.

So, this switch a lot of times, I put a little arrow here 'cause many

of them will have a mode button.

And the mode button depending on the switch will do different things.

So, not all switches have mode buttons but it can switch between status

like is there something connected to utilization to where you'll--

it's kind of like a radio equalizer where you kind of get levels based

on how much the switch is being utilized to duplex where you see different colors.

If one is full duplex, one is half duplex into speed.

That's the bottom line.

Or you can see 10 megabit or a hundred megabit or nowadays in more recent switches,

you get the gigabit connections or even 10 or 40 gigabit per second connection.

I mean, the speed just continues to increase more and more and more and more.

So you can click that button and go through those.

Also, something to be aware of is if a Cisco switch has a button,

it may support a feature that can erase the entire thing.

If you hold down that button for somewhere around 10 seconds, just hold it down,

you'll actually see a blink a number of times and the switch will reboot itself.

That will flush all configurations that you have on the switch and reset it to factory default.

Wow! What does that tell you about physical location of these switches?

Can we say locked door?

Yes, absolutely.

This room is behind a locked door because if somebody can get to that, they can really mess

up your entire network just by holding down a button for 10 seconds or so.

So this is the physical world.

Now, I want to reinforce that Cisco doesn't usually focus on the physical connections

because normally, other companies come in there and do that all for you.

They can do it faster, cheaper than a Cisco engineer could 'cause they've got all the right

tools and all the right expertise to run the cables to the wall and solve the patch panels

and essentially leave you at that point.

They'll say, "Okay, there you go, install your switches right there and you're good.

Thanks. Bye-bye."

So, we pick up in the Cisco world from an initial switch configuration.

Now, I've got behind the scenes, my Cisco switch loading up so it's actually booting right now,

going through all its power and self-test.

So we'll let it do that.

In the meanwhile, I want to first off re-emphasize,

I said this in the previous nugget, switches will work out of the box.

So you pull those switches out of box, you connect the cables to them

and they will do what a switch does which is learn MAC addresses

and allow devices to communicate.

However, if you're going to leave it at that, you might as well go by any switch.

I mean, there's no real advantage other than getting the support in good,

really solid hardware from Cisco, there's no real advantage to having Cisco

and the advantage comes in when you start configuring it and enabling features.

So what you see on the screen right now is a base configuration, meaning,

this will get you started to where you can enable a lot more features on the Cisco switch.

So we'll work through this one by one.

Let's see if the switches booted.

Okay, good, it is.

Now, by the way, when the switch boots, initially it might be--

a lot of times you will just sit there staring at this going, okay, is it done,

you know, expecting this screen to clear.

There is no fear in pressing the Enter key, right?

The Enter key is pretty much going to always call up a new line in the Cisco device.

I guess there's fear of you type the Enter key after the wrong command

but just enter on a blank line is harmless.

So, it's asking us, do you want to enter the initial config dialog, you might remember

from the IOS basics nugget, the answer to that is always no because it's going

to have you configure all kinds of legacy old stuff

and we don't want to waste our time with that.

We just want to get into what we need to do.

The first thing is to name the switch.

So I'm sitting in privilege mode.

You remember, again, just some fly by review from IOS basics, question mark gives me a list

of commands and the first thing I need to do is to get into enable mode.

Now, if I want to finish the partially typed command, you guys remember, tab key, right?

Enable now takes me straight over to enable mode.

I know I'm there because of the pound symbol.

There was no password because the switch has no configuration.

That's can be one of the things that we do here.

So I'm sitting at the switch with a pound symbol and from here I can view all the configuration.

You remember the modes?

We start off in the user mode that was the little right angle bracket.

We type in Enable and that will take us to privilege mode where we have the pound symbol.

Now, from there we can view all the configurations of the Cisco device

but we still can't configure anything unless we move into global configuration mode.

So I'll put GC, global config, and we do that by typing in configure terminal

or the shortcut is CONF T. So I'll type in C-O-N-F--

I drop my pen, C-O-N-F T using the tab key to finish that and hit the Enter key.

I'm now in global configuration mode.

Okay, great starting point because anything that I type here globally affects the whole switch

and that does mean things like the name of the device

which is the first thing that I have, host name.

Host name is the command that will name the device.

So I'm sitting here, I can just type in host name and I'll hit the question mark,

it says, "What is the system's name?"

And you might remember, I said anytime you see something at all capitals where it says word,

it's saying there's no syntax for this other than just type a word.

We don't know what you want to name your device.

So fill it in right here.

So we can type in the host name.

Now, different companies will do different things.

You'll see some companies that are like host name, Neo, you know,

and they start picking a theme for their devices.

Then the next switch will be Trinity and Morpheus and all that,

and then that's fine for smaller company.

But before long, it becomes paginal because there's only one guy meaning you,

the network admin, who knows what's going on, you know, a consulting coming in.

They're like, "I am on Morpheus right now."

What does that mean?

And they need the other guy to come in and go, "Well, I'm Morpheus,

that's actually that switch over there."

So as you move into larger companies, you'll find they start coming up with schemes.

It starts out simple to where some of them will say, you know, third floor,

switch one, you know, something like that.

You can't use spaces in the name but, you know, that way, you know, as the company grows,

they're like, "Okay, oh, so that's the switch one on the third floor."

That makes sense.

And as you start getting into the enormous companies, you know,

start talking about companies, the size of Intel, Motorola, American Express, you know,

all these giant enterprise companies, they'll have names, you'll see host names like,

you know, XJ500-L or X-LL1-, you know, BB9 or, you know, I'm just making that up

but there's literally, you know a--

and so there's going to be a white paper that they've produced where literally every character

of that host name means something like the first letter might represent what region

of the world it's in.

X stands for an exciting place, you know, whatever.

So, they'll actually have different definitions so the technicians are trained

when they see these names, they're able to quickly identify exactly

where the switch fits into the scheme.

So, just for this series, let's just call this the CVT switch, right?

This will be our first switch.

So that's the host name of the switch.

You can see it's just a prompt.

It's just an identifier of what it is.

Now, before we go anywhere, I want to also show you how to negate commands because a lot

of times, I mean, you saw me, I type in host name Neo

and then I type in this and it overwrites that.

And then I type in this and it overwrites that, it kind of replaces my old host name.

Well, not all commands are that way.

Sometimes when you type a command, it'll stay there until you remove that command.

So, there's always the ability to negate a command.

Cisco makes it really easy.

You just type in no and whatever command you want to negate, and negate meaning remove.

So for instance, if I were to type in No Host name, I don't even have to type in CVT switch,

I just hit Enter and notice the switch goes back to its normal configuration of switch

because I've said, "Oh, nope, there's no more host name anymore."

Hit the up arrow a few times in the key board,

recall that host name CVT switch and I put that back in.

So the no command can be use for a lot of stuff, a lot of stuff on the Cisco device.

You'll see it all over the place.

So, now let's start getting into the pass-- I should be checking this, right?

Let's get in to the passwords.

There are three different passwords that I want to show you on the device.

The first one is the console password.

Now, when we get into this device, when we physically come up

and that's how I'm connected right now.

I've gone in.

If I were to go into-- let's see, set up do the-- what would it be?

General, is that where it's-- yeah, so there we are.

I've got my general set up.

I'm using COM4 which is my serial port right now attached to a USB to a serial adapter to connect

to the console port of the device.

So I'm configuring it through the console board, and you saw when I got in here,

I booted the switch and poof, there I am.

Now if I-- let me exit out, and I said, "Okay, you're logged out."

I hit Enter and I'm in, I'm in to at least user mode and then I can get into privilege mode,

the global config mode, you know, it's very easy for me to navigate 'cause there is no passwords.

So to set a console password, what I need to do is go into the console configuration mode.

That's where we're going to start seeing the different modes.

So we've gone in from user to privilege, right?

So here we have limited show commands, all show commands.

We've gone from privilege to global config where we can now configure global options,

but now we can start going to some of the individual configuration modes.

The first one I want to show you is called line console, a line con or line console.

Essentially, Cisco has created a console mode of configuration.

Let me show you.

I can go in here and type in line, let me just do a space question mark, it says, "Okay,

do you wan to configure VTY lines," which we're going to talk about in just a second,

"or do you want to configure the console line."

So I'm going to say, "Console line" and I hit the question mark.

And it says, "Well, which console port are you talking about?"

Now, Cisco is just being kind of trivial here because they know as well

as we know all Cisco devices only have one console port.

You're never going to find one that has multiple console ports

for redundancy or anything like that.

But nonetheless, they make you type it.

They say, "Okay, well, the first line number is zero."

And by the way, you might-- 'cause numbering in Cisco often starts from zero.

So the very first line, instead of being one will be the number zero.

So the very first or essentially the only console port is blank console zero.

So, now notice what happened here.

My mode changed.

I'm now-- I've gone from config to config dash line.

Every command that I type right now, right now I'm in this mode,

every single one of these commands deal specifically with the console port.

If I were to exit out of this mode, those commands would disappear.

They're no longer valid.

So inside of here is where I want to use the command password and I type

in whatever I want my password to be.

So in this case, let's just-- I'm going to make not a good practice but for a lab, hey, why not.

I want to make all of the passwords Cisco, so all lower case password Cisco.

Now you notice, when I hit question mark, initially it's going,

wow, this looks kind of confusing.

It says, I can put a zero here to specify an unencrypted password will follow

or I can type a seven here to specify that a hidden password will follow or I can type

in line, notice all capitals, where it says the unencrypted clear text pass-- line password.

Now, what does all that mean?

Well, I typed in password Cisco but notice, I could have typed in password space

and type the number zero space and then typed in the unencrypted clear text line password.

So, huh? What?

Huh? What?

What's going on?

So, can I type in password zero Cisco and enter?

Yes I can.

Now, wait a sec, can I type in password Cisco and hit enter?

Yes, you can.

There's actually two ways of doing the same thing here.

You might be going, what's the difference?

Well, this just explicitly tells the device, this will be in unencrypted password.

I'm going to paste it in.

A lot of times, if somebody copies and pastes the config from a different Cisco device

and says here, it just kind of copy these commands and paste them into your device.

It'll do it for you.

A lot of times, they'll specify zero here because they know it's unencrypted, whereas,

they can also copy and paste a configuration

where they have an encrypted flavor of the password.

Do you notice if I type in password space seven like it's telling me to, it says, "Okay,

now you can type in word where the word represents a hidden line password string?"

Meaning, if maybe-- maybe somebody didn't feel really good about giving you configuration

with all their passwords and clear text.

So they said here, "I'm going to give you an encrypted version of this password

that you can copy and paste in the config and it'll still understand it."

So, that's where that comes in.

I'm getting a little deep a little early but I just wanted to comfort you

if you are wondering what that all meant when I hit question mark.

But Cisco realized this.

You know what?

People don't really want to type a number.

Let's just give them a shortcut.

You know what, if you just want to type in password

and what your password is, you can do that.

It's the same thing as typing password zero in your password but,

you know, we'll let you do it either way.

So I can type in password Cisco and that.

So what I've done at this point is assign a password to the console port.

Let me type an end which will drop me back out and then I'll type in exit to log out.

Watch this.

I'll hit the enter key and [laughter] never mind.

Scratch that.

I forgot to do something.

Oh, yes. We did set of console password but I want to show you something.

I want to do a show-- I'm actually going to do a show command

where I'm going to do a show running config.

At first I was like, "Wow, that was one of the most basic commands I could've done."

I'm going to scroll down and you can just see there's all kinds

of stuff in this configuration.

This is its running configuration.

What's actually running and you can see that underline console zero,

I have the password Cisco but it's actually missing a command.

It's missing a command that is underneath a few of these other ports which actually is log in.

Now, look at this.

I'll show it to you and then I'll explain it.

I'll do line console zero and I'm going to type in log in and hit enter.

So, what did that do?

Let me exit back out here and I'll do a show running config.

Now, what did that do?

Hang on, scroll down, show me that command.

Is it there now?

I hit the wrong button, stop the output.

Is it there now?

Yes it is.

It's underneath the counts for-- what's it do?

Let's find out.

Hit the enter key and now it's asking me for a password, Cisco.

Okay, okay.

And then I get in and I'm in.

Okay, so now I have this password prompt which was not previously there.

And what I did was type in log in.

Let me do a short run.

Let me just-- I'm going to do a begin with line con, of course,

line con so I don't have to scroll through all that.

So it's showing line console 0, password Cisco log in, that command is there.

So wait a sec.

If I were to go in into the console port and type in line console 0 and type in no log in,

to remove that command, now what happens?

Let's go back.

Let's look at the config and verify.

Let me do that again.

Verify, we've got password Cisco is under the console port, exit back out,

enter the enter key, no log in required.

Is that-- is this starting to put the pieces together?

So what-- let me ask you, if you were to give a definition, what does the log in command do?

The log in command requires log-ins to that port, meaning, I can type in passwords all day.

Let me do a show run begin line console.

I can type in passwords all day long under that console port but they won't take affect

until I'm requiring somebody to log in.

So I'm going to go into global config, line console 0, and let's just hit the question mark.

You can see that log in if we look at the definition L log in, enable password checking.

That's the definition that they give it

and essentially enable this console port to check the password.

So, let me type in log in, hit enter, and now we are requiring console password, good.

Now, what about the telnet password?

Setting a telnet password is what allows you to manage the switch remotely.

Meaning right now, I am connected if you were to look at me right now, I have a cable plugged

in to that switch and, you know, I got my laptop or whatever device I'm using.

I've got this console connected.

I'm looking down, I'm literally three feet away from the switch standing here and that's great

for an initial configuration, that's how we have to configure it.

But eventually, I want to get out of this cold IT room and I walk back

to my desk or fly back to my office.

It could be thousands of miles away and manage this switch remotely.

That is where the telnet password or you should-- could also look at more modern,

more secure is an SSH password comes into play.

Now, these are also configured under the line but the line is actually called VTY.

Let me get back to the problem.

So we're under the console part right now.

We don't want to do anything else from here.

For now, we'll come back here.

I'm going to exit out of the console port.

I'm going to type in line VTY space, well, let me just question mark through the whole thing.

So line VTY that sends for a virtual terminal.

It's virtually as if I was standing there next to the switch, right?

So virtual term, a VTY space and then it says, okay, what is the first line number.

What's that mean?

Well, depending on your iOS version,

you will see different Cisco devices supporting multiple telnet connections at a time.

So that means I can be remotely telnetted in managing the switch, so can Bob, so can Sue,

so can Mary, so can Neil, you know, everybody can actually be on that switch at the same time.

Whoa, wait a second, does that mean we could make conflicting changes?

It does and you have to be careful about that.

But usually, you know, technicians communicate.

[laughter] Did I just say "technicians communicate"?

Scratch that.

Policies dictate that technicians are supposed to communicate

so that they don't make those kind of conflicting changes.

But nonetheless, the Cisco device supports everybody getting

on that device at the same time.

Now when I say everybody, I mean, however many line numbers you configure.

Now this iOS version, this Cisco device supports--

you can just by hitting the question mark, it says, what is the first line number?

So I type in zero, that's going to be the first one we commit on and I hit the question mark,

it says, "Well, what is the last line number?"

And I can go up to 15.

So what this allows me to do is configure a whole bunch of VTY ports at the same time?

So if I were to type in 15, that now puts me into the configuration mode for 16 total,

'cause I started counting from zero, right, so that adds one more, so 16 total VTY ports

that I'm configuring all at the same time.

And then I can come under here and say password and whatever I want my password to be.

We'll say password Cisco and hit the enter key.

And now I've created a password that says whenever somebody accesses device remotely,

they're going to have to type in the password Cisco before they are able to get to user mode.

Now, let me show you a couple quick things.

I'm going to bail out of this mode and just do a show run.

And by the way, I've been typing this in a couple of times just to get us straight there.

You can actually do a show running config, this is how we verify.

It's saying, show me what configuration is on this device that's running right now

and you can type in the pipe, it's the character right above the enter key,

and then you can do some filtering commands.

You can say, I want to begin with the line, I want to include the lines,

I want to exclude the line, so what I have been typing all along,

I've been putting B there which are like, what is that?

That's actually begin with the line where I type in line and I just hit enter.

Begin with a line that says line because that will move me down to the bottom so I don't have

to hit the spacebar through all that config and I can just look directly at these ports.

So, I see my console port configuration, right, everybody good with that,

and then below, I see my VTY configuration.

Now, a couple of things worth mentioning, first off,

what's up with the 0 through 4 and then 515?

You know, and I also want to talk about the syntax.

When you see 0 space 4, mentally put a little dash in there.

They give it like 0 through 4 'cause that's really what it means.

So why did it break it into two?

Well, to understand it, you have to go back into long, long history of Cisco.

Cisco has always had five telnet ports, 0 through 4 on their devices.

Only recently and I say "recent" within the last decade, it's been a long time.

But, you know, for as long as Cisco has been around, I'd say recently, have they expanded

that to allow more to where you can go up to 15 or I guess 16 total VTY ports.

But a lot of times people would take configurations from one device and send it

over to another device and, you know, kind of-- it's very common.

When you get a good base configuration with Cisco to say, "Okay, I've got it," you know,

that's what we're doing right now is a base configuration.

'Cause I've got it, let me now copy and paste that into all my devices

so I don't have to do them all individually.

Well, if you have some older devices, they might only support five telnet ports at the same time.

Whereas some newer devices might also expand and support up to, you know, 16 telnet ports,

you know, for essentially 0 through 15.

So Cisco said, "Well, why don't we do this?"

We'll break it into two sections so that way if you copy and paste a config from a new device

into an older device, so the new device supporting all these telnet ports

and the older device supporting this, at least it will take the commands for this piece of it.

You know, when it gets to this, the older device would be like "I don't know what that means.

I don't have 16 telnet ports" and it'll ignore those commands

but at least it will take this whereas if we would have put them all as one big chunk,

if we were to put 0 space 15, then the older device would say, "Well, I can't support that,"

and it would forget the commands completely.

At least by doing this, it gets most of the configuration in there

and ignores the stuff that doesn't support.

So, I know a little longer explanation but you we're to believe, how many times I have people

when I explain that to them and they've been in Cisco for a while,

they're like, "Oh, that always confuse me."

So, I wanted to take the time right there.

So, second thing worth mentioning, notice when I got under the VTY ports right here,

I typed in password Cisco, I never typed the word log in and yet it's there.

Why? Well, if we back up, if we look at the configuration before

when I was doing the console port, we saw that the console port didn't have the log in command

and the VTY lines did before I even got in there.

Well, that's Cisco's form of security.

They don't want you to be setting up your switch and then you give it an IP address

and all of a sudden someone behind the scene is like [laughs], you know, dives in there

and telnet is in before you have the chance to set a password.

No. So what they do is they say, "Require log-ins to this port."

But notice there's no password set underneath the port, right?

So if somebody does happen to try and sneak in there before you have the chance

to set a password, they'll actually get the message

from the Cisco device and here's the exact message.

I don't know why I remember this verbatim.

It will say, "Password required but none set," click and it will disconnect them.

"Password acquired but none set."

What that's saying is "Hey, this log in command is telling me, me being a Cisco device,

I need to require log-ins for this port."

So when somebody connects, it's like I need to log you in but then it looks and it goes,

wait a second, I don't have a password, thus the message.

Sorry, password required but there's none set so you can't log in case I'm requiring.

Now, let me show you, let me show you a bad thing to do.

If I were to go underline VTY 0 space 15 and type in the command, no log in,

hit the enter key, what do you think that does?

Careful, sometimes you're like, "Oh, okay," so I'm not letting anyone log in, right, right?

That's a lot of times the initial feeling is like, well, it says no log in so that--

well, careful, careful, remember the language.

No is the negating command.

So we're not saying no log in like we're speaking English to each other,

like oh no, no, you can't log in.

What we're saying is no, the log in is not required.

So before I was requiring log ins and now I'm not, oh my goodness,

what this means is somebody can type in telnet and the IP address of the switch

which thankfully we haven't given it one yet.

But they could type that in and bam, they're immediately sitting in user mode

and then they type in enable and now they're into the privilege mode.

It's creepy.

There is a few, there is minor security mechanisms

like if you don't have an enabled password, it might restrict you from doing that.

But oh my goodness, that's not something you want to do.

So no log in does not say you can't log in.

It means no log in is required so that's why you absolutely want to keep that one on there.

See how dangerous those commands can be.

Okay. So, are you feeling good so far?

I'm looking at the amount of time.

I'm like, good grief.

I'm spending a lot of time on this.

I thought I'd be able to just blaze through this.

But then as I started talking, I'm like, you know what,

this is really our first real config of a Cisco device.

I want to spend the time with you.

I want to spend some time just to talk and brainstorm and just think through a lot

of the questions that I know I've been asked when I have explained this previously.

So, I'm probably-- here's what-- I'm going to kind of divide this in half.

This will be part 1, this will be part 2.

We'll do all that in another nugget.

But let's-- that's the last one I want to do is to set a password.

I want to set the enable password.

So, so far, we've now set it up to where when I plug

in with the console port, it's asking me for a password.

That's good to get into user mode.

If telnet or SSH which we'll talk about SSH later, if I get into the switch that way,

it's going to ask me for a password which is good.

So I'm kind of protecting it but now there's this transition from virtually no access

or very limited access into full access which is not protected at all.

And that's where the enable password comes into play.

Now, the way that we do this is very similar to the way that we've done everything.

I'm going to exit back out.

Now, there's no line for this, I don't have to go under a line config

because the enable password is something that applies to the whole switch.

It doesn't matter how you get on that switch whether you've console in, telnet in, SSH in,

doesn't matter how you get there,

it has one global enable password to protect that transition.

So it's something that we do from global config.

And the way that we do that is typing in enable, there's actually two ways.

You can type in enable password or enable secret.

Okay. So these two commands do exactly the same thing.

They protect the privilege mode with a password.

So let me show you the first one first.

Let's do enable password and similar to the console port, it says, you know,

what mode or anything and I would just say, hey, at this point type it in, type in the line.

So I type in, the enable password is Cisco, right?

So now when I exit out, what happens?

I hit the enter key, it's prompting me for a console password which I type that in, Cisco.

I'm now in user mode, I'm like okay, great, I've got limited access here so I type in enable,

hit the enter key, and now look at that.

Now we're prompted for a second password which normally best practice,

you should make that a different password than what your telnet password is.

Not everybody does but it is much better security if you do.

And I'm in the privilege mode.

So okay, that's great.

You're probably thinking, well, what could be different about the enable secret.

Well, let me show you.

I'm going to go back and verify my commands that I've typed in the switch and I'm like, "Okay,

well, I'll just do a show run and whoa, hey, stop looking over my shoulder.

Hey, no, no, yeah.

Look at that.

It's clear text."

Enable password means if somebody is looking over your shoulder when you're doing a show run

or you happened to send your running config to somebody,

right there is essentially the key to your Cisco device.

The password is Cisco, that's scary.

So let's go back in here and type in enable, hit the question mark, secret.

And let's-- I'm going to use a different password and I'll explain why in a second.

So let's just do enable secrets CBT nuggets, enter.

So I'm going to exit back out.

Let's do a show running config.

That's got to make you feel better.

Enable secret is [inaudible].

And it's just garbling moosh moosh.

And then underneath right there is enable password Cisco,

okay, okay, that can't be good, right?

Okay, so what happens?

I type in exit and I'm here.

I type in Cisco and I'm in 'cause that's the console password, right?

So now when I type in enable and I'm going to say, okay, I'm going to try the password

of Cisco, wait, wait, maybe I mistyped in Cisco.

No, Cisco, no.

Enable is no longer allowing me to use the password of Cisco anymore.

I actually have to use the password of CBT nuggets and that will get me right in.

See, using the enable secret, the Cisco device realizes, whoa, that's way better,

that's way more secure than the enable password.

I'm going to prefer that.

As a matter of fact, I'm going to disable the enable password

because you have a more secure password typed in that's enable secret and that's completely hash.

It's totally, think of it as encrypted.

They're like people can't get to that password just by looking over your shoulder.

So, I know, if you're like me, the questions are rattling your mind.

Okay, number 1, why does that enable password exist, why is it there?

And then why do you have-- why does it even let you type two of them in?

It seems like it would, you know, it would just remove the other or something, right?

That's like our brainstorming [inaudible].

Well, let's go back.

Go back to the old devices.

Old devices, again, old being, again, more than a decade old since they've come

out with enable secret, but long, long ago, devices had only the enable password.

There was no enable secret command on some of the original Cisco devices.

So Cisco said, "Let's keep it around.

Let's keep this in here."

Again, that way if somebody copy and paste their configuration from a new device and they put it

in the old device, well, the old device when it sees this command if you're copying and pasting,

it's going to be like, I don't know what that command is.

I don't support that command but it will support this.

And so you'll see this theme, you get that feel, right?

So there are legacy commands that still work on newer devices

but really Cisco has long since developed better ways.

The only reason they keep those command around is if you were to apply that configuration

to an older device or for example, maybe I downgrade this iOS version, you know,

right now I'm running, you know, whatever version, 12.2 on the Cisco switch,

what if I downgraded this iOS version 2, really old version.

Well, when it boots up, it's going to start seeing all these commands and it's like,

I don't get that, I don't understand this 'cause my iOS version doesn't support that command.

So these commands will automatically disappear from the config

because the switch doesn't support it and all the old commands, the legacy commands will stay.

So, that will at least give you some level of protection by doing that.

With all that being said, let me just say this, Cisco nowadays recommends,

don't even worry about the enable password.

Enable secret has been out for a long time and that's the way that you should probably go.

As a matter of fact, how would we get rid of that enable password?

There's your pop quiz, no enable password.

It's gone, right?

Show running config, that negating command removes everything

and now all I see that's left is the enable secret.

Wow! What a good start.

So we can check this off thinking of this as like core security if you will

on the left hand side to get our device configured.

And I would say just getting really familiar with kind of the feel of this Cisco switch.

So I'm going to put that dividing line right there, line in the sand for now.

I'll start off the next nugget right off-- right where we finished this one.

I'll kind of do a fly by review of where we're at and then we'll dive into part 2

which will be setting up the rest of the management of this device.

For now, I hope this has been informative for you and I'd like to thank you for viewing.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.