SSH, SFTP/SCP, Device Hardening & AAA

CCNA 200-301 v2.0 · Live Feb 3, 2027 (v1.1 valid through Feb 2, 2027) Cisco Packet Tracer

مقصدObjectiveObjective

اس لیب میں آپ SSH کانفیگر کرنا، SFTP/SCP enable کرنا اور AAA کا concept سمجھیں گے۔ v2.0 میں SFTP/SCP نیا ٹاپک ہے۔Is lab mein aap SSH configure karna, SFTP/SCP enable karna aur AAA ka concept samjhenge. v2.0 mein SFTP/SCP naya topic hai.In this lab you'll configure SSH, enable SFTP/SCP, and understand the AAA concept. SFTP/SCP is a new topic in v2.0.

آسان مثالSimple AnalogySimple Analogy

Telnet کا مطلب دروازے پر کھڑے ہو کر زور زور سے پاس ورڈ چلانا — سب سن لیتے ہیں۔ SSH کا مطلب کان میں سرگوشی — سب کچھ encrypted۔ SFTP/SCP اسی محفوظ راستے سے فائلز بھیجتے ہیں۔ AAA کا مطلب: پہلے پوچھو 'تم کون ہو' (Authentication)، پھر 'تمہیں کیا اجازت ہے' (Authorization)، پھر 'تم نے کیا کیا' لکھ لو (Accounting)۔Telnet ka matlab darwaze par khare ho kar zor zor se password chilana — sab sun lete hain. SSH ka matlab kaan mein sargoshi — sab kuch encrypted. SFTP/SCP isi mehfooz raste se files bhejte hain. AAA ka matlab: pehle poocho 'tum kaun ho' (Authentication), phir 'tumhe kya ijazat hai' (Authorization), phir 'tumne kya kya kiya' likh lo (Accounting).Telnet is like shouting your password at the door — everyone hears it. SSH is a whisper in the ear — everything encrypted. SFTP/SCP send files over that same secure path. AAA means: first ask 'who are you' (Authentication), then 'what are you allowed to do' (Authorization), then write down 'what you did' (Accounting).

سیٹ اپLab SetupLab Setup

R1 کا G0/0 PC1 سے connected (192.168.10.0/24)۔ Devices: 1x Router 2911 (R1), 1x PC۔ PC1: 192.168.10.10/24، گیٹ وے 192.168.10.1۔ Packet Tracer میں PC کا SSH client استعمال کرو۔R1 ka G0/0 PC1 se connected (192.168.10.0/24). Devices: 1x Router 2911 (R1), 1x PC PC1: 192.168.10.10/24, gateway 192.168.10.1. Packet Tracer mein PC ka SSH client istemal karo.R1's G0/0 is connected to PC1 (192.168.10.0/24). Devices: 1x Router 2911 (R1), 1x PC. PC1: 192.168.10.10/24, gateway 192.168.10.1. Use the PC's SSH client in Packet Tracer.

اقداماتStepsSteps

Step 1

R1 پر SSH setup۔ SSH کے لیے domain-name اور RSA keys ضروری ہیں۔R1 par SSH setup. SSH ke liye domain-name aur RSA keys zaroori hain.SSH setup on R1. SSH needs a domain-name and RSA keys.

enable
configure terminal
ip domain-name mylab.local
crypto key generate rsa modulus 1024

Step 2

پھر local user بناؤ اور VTY lines پر صرف SSH کی اجازت دو (telnet بند)۔Phir local user banao aur VTY lines par sirf SSH ki ijazat do (telnet band)Then create a local user and allow only SSH on the VTY lines (telnet off).

username admin privilege 15 secret admin123
line vty 0 4
transport input ssh
login local
exit

Step 3

SFTP/SCP اور AAA۔ SCP server آن کرنے سے محفوظ file transfer ہوگا۔SFTP/SCP aur AAA. SCP server on karne se mehfooz file transfer hoga.SFTP/SCP and AAA. Enabling the SCP server gives secure file transfer.

ip scp server enable

Step 4

AAA آن کر کے بتاتے ہیں کہ login local users سے verify ہو۔AAA on kar ke batate hain ke login local users se verify hoTurning on AAA means logins are verified against local users.

aaa new-model
aaa authentication login default local
aaa authorization exec default local

Step 5

Testing: PC سے SSH کرو (R1 کا IP) — connect ہونا چاہیے۔Testing: PC se SSH karo (R1 ka IP) — connect hona chahiye.Testing: SSH from the PC (R1's IP) — it should connect.

Step 6

Telnet try کرو — refuse ہونا چاہیے۔ یہی فرق ہے محفوظ اور غیر محفوظ کا۔Telnet try karo — refuse hona chahiye. Yehi farq hai mehfooz aur ghair-mehfooz ka.Try telnet — it should be refused. That's the difference between secure and insecure.

تصدیقVerifyVerify

show ssh سے active sessions دیکھو۔ show crypto key mypubkey rsa سے keys کنفرم کرو۔show ssh se active sessions dekho. show crypto key mypubkey rsa se keys confirm karo.Check active sessions with show ssh. Confirm keys with show crypto key mypubkey rsa.

show ssh
show crypto key mypubkey rsa

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ SSH connect نہیں ہو رہا، 'connection refused'۔SSH connect nahi ho raha, 'connection refused'.SSH won't connect — 'connection refused'.

✅ crypto key generate rsa سے پہلے ip domain-name سیٹ کرنا ضروری ہے۔ پھر دوبارہ keys بناؤ۔crypto key generate rsa se pehle ip domain-name set karna zaroori hai. Phir dobara keys banao.You must set ip domain-name before crypto key generate rsa. Then regenerate the keys.

⚠️ Telnet اب بھی کام کر رہا ہے۔Telnet ab bhi kaam kar raha hai.Telnet still works.

✅ line vty پر transport input ssh ہونا چاہیے۔ 'all' ہو تو telnet بھی کھلا رہتا ہے — exam میں 'ssh' ہی جواب ہے۔line vty par transport input ssh hona chahiye. 'all' ho to telnet bhi khula rehta hai — exam mein 'ssh' hi jawab hai.The VTY lines must have transport input ssh. If it's 'all', telnet stays open too — for the exam, the answer is 'ssh'.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ SSH کانفیگر کرنے کے لیے کیا کیا چاہیے؟SSH configure karne ke liye kya kya chahiye?What do you need to configure SSH?

SSH کے لیے hostname/domain-name، RSA crypto keys، local user یا AAA، اور VTY پر transport input ssh چاہیے۔SSH ke liye hostname/domain-name, RSA crypto keys, local user ya AAA, aur VTY par transport input ssh chahiye.SSH needs a hostname/domain-name, RSA crypto keys, a local user or AAA, and transport input ssh on VTY.