1. Basic Switch Configurations
Switch>
The “>” prompt is for user exec mode
It has very limited functions
Switch>enable
Switch#
The “#” prompt is for privileged exec mode
It is has extended rights to show commands
Switch#configure terminal
Switch(config)#
The “(config)#” prompt is for global
configuration mode
It makes configuration changes that affect the
entire device
Switch(config)#interface g0/0
Switch(config-if)#
The “(config-if)#” prompt is for the specific
configuration mode
Other examples are (config-router)# and (config-
line)#
It makes changes to only that portion of the
device
Name the device
Naming the device is important so, if you are
administering from a distance, you can
positively identify the device
Switch(config)#hostname NAME
NAME(config)#
Setting passwords
There are two categories of passwords. User-
mode and enable.
User-mode on set on where they originate.
Console port, telnet, or dial up.
Switch(config)#line console 0
/line vty 0 15 / line aux 0
Switch(config-line)#password Incorrect
Switch(config-line)#login
Enable are set on the command used to enter
them
Switch(config)#enable password LetMeIn
/enable secret SHHitsAsecret
Banner
The banner should be a warning that access will
be monitored
Switch(config)#banner motd *
Authorized Access Only*
2. Assigning IP Address
IPs can be assigned to a specific interface or a
VLAN
Switch(config)#interface vlan 25
Switch(config-if)#ip address 192.168.25.2
255.255.255.0
Switch(config-if)#no shutdown
Default Gateway
The default gateway is a layer three device on
the same subnet. Computers have default
gateways and switches do too. It is where the
device will send network traffic not in the same
network.
Switch(config)#ip default-gateway 192.168.25.1
VLANs
Virtual Local Area Networks (VLANs) split up
the ports of a switch into different networks.
Switch(config)#interface f0/1
Switch(config-if)#switchport mode access
Switch(config-if)#switchport access vlan 25
Switch(config-if)#no shutdown
Switch#vlan database
Switch(vlan)#vlan 1 name Admin
Switch(vlan)#vlan 25 name Users
Trunking
Trunking allows multiple VLANs to travel
through the same cable
Switch(config)#interface g0/0
Switch(config-if)#switchport mode trunk
Switch(config-if)#switchport trunk
encapsulation dot1q
Usernames
Usernames create logins on the device with
different passwords with different rights
Swtich(config)#username Robert secret 5 FClub
Port Security
Port security restricts people from plugging any
computer into a switch and being granted access
Shutdown all ports not in use
Switch(config)#interface range f0/13 – 48
Switch(config-if-range)#shutdown
Switch(config)#interface range f0/1 – 48
Switch(config-if-range)#switchport port-security
Switch(config-if-range)#switchport port-security
maximum 2
Switch(config-if-range)#switchport port-security
mac-address sticky
Switch(config-if-range)#swtichport port-security
violation shutdown