More IOS help please!

GobBluth

Senior member
Sep 18, 2012
703
45
91
Took a new job as a NA/SA only to find out that they want me to do most of the core networking. Short story long, it has been years (since the 3650s were the big thing) since I've done IOS anything. The previous infrastructure guy was fired and I have 20 switches I have to change passwords on. So far I've done this.

>enable
#conf term
#enable password ******
#line console 0 (also did line vty 0 4 here)
#login
#password *******

Am I forgetting anything? I need to make sure the ex-employee can't access this switch via telnet or ssh.

Thanks,

GB
 

drebo

Diamond Member
Feb 24, 2006
7,034
1
81
Better to use local database auth and secrets:

username admin priv 15 secret *****
crypto key generate rsa general-keys mod 2048
enable secret *****
line con 0
login local
line vty 0 15
transport input ssh
login local

Then, when you connected via console or ssh, you'd be prompted for both username and password.
 

GobBluth

Senior member
Sep 18, 2012
703
45
91
Better to use local database auth and secrets:

username admin priv 15 secret *****
crypto key generate rsa general-keys mod 2048
enable secret *****
line con 0
login local
line vty 0 15
transport input ssh
login local

Then, when you connected via console or ssh, you'd be prompted for both username and password.

TY. Exactly what I was looking for. cheers!
 

GobBluth

Senior member
Sep 18, 2012
703
45
91
Hey guys,

So, here is today's situation. Google is failing me this morning.

I'm looking for the physical location of a wireless AP in my hospital. I'm con'd into the switch and ping'd the AP. I ran trace route and just get empty hops.

Rather then consoling into every switch and using sh cdp neighbor is there any other method I can use to locate what switch/port this AP is on?:hmm:


Cheers!

GB
 

GobBluth

Senior member
Sep 18, 2012
703
45
91
Wrong forum, I know, but I need a quick response.


I'm looking for the physical location of a wireless AP in my hospital. I'm con'd into the switch and ping'd the AP. I ran trace route and just got empty hops.

Rather then consoling into every switch and using sh cdp neighbor is there any other method I can use to locate what switch/port this AP is on?


Cheers!

GB

FYI: I'm a IOS noob so try and keep the flames to a minimum folks, thanks.
 
Last edited by a moderator:

HN

Diamond Member
Jan 19, 2001
8,186
4
0
Classic bash.org

#5273 +(30077)- [X]
<erno> hm. I've lost a machine.. literally _lost_. it responds to ping, it works completely, I just can't figure out where in my apartment it is.
 

jlazzaro

Golden Member
May 6, 2004
1,743
0
0
not really...instead of looking at random switches for CDP neighborships, searching based on the MAC address should be more methodical and narrow. from your core switch, ping the AP then find the MAC address of the AP in your arp table. then look in the MAC address table for the outgoing interface and trace it down to the access switch.

core-switch# sho arp | i <ip address of AP>
core-switch# show mac address-table address abcd.efgh.ijkl

use CDP neighborship to find the switch connected to that trunk and run the same command until you find the access layer port.

there are tools out there that will do this "scouring" for you, but I can't recommend any free solutions.
 
Last edited:

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
Solar winds or what's UP gold should be able to do it. If they are controller based the CDP neighbor information is on the controller.

Also, you should be able to telnet into the AP and find CDP neighbor
 

gsaldivar

Diamond Member
Apr 30, 2001
8,691
1
81
Take your phone into the switching room and just make note of which spots are empty or occupied (whichever is the smaller number is faster). For this purpose, in large server rooms I will just take a few seconds of video of the activity lights with my smartphone. Then go unplug the mystery device from the LAN and go back into the server room and look for the single activity light that has changed. Even with hundreds of ports, this shouldn't take more than a few minutes. Good luck!
 
Last edited:

GobBluth

Senior member
Sep 18, 2012
703
45
91
not really...instead of looking at random switches for CDP neighborships, searching based on the MAC address should be more methodical and narrow. from your core switch, ping the AP then find the MAC address of the AP in your arp table. then look in the MAC address table for the outgoing interface and trace it down to the access switch.

core-switch# sho arp | i <ip address of AP>
core-switch# show mac address-table address abcd.efgh.ijkl

use CDP neighborship to find the switch connected to that trunk and run the same command until you find the access layer port.

there are tools out there that will do this "scouring" for you, but I can't recommend any free solutions.

Thanks, this is the method I wound up using. I was doing it from a border switch at first rather then the core. I'm trying to bring Solarwinds/OpenView/Cisco Works solution online here so we don't have to deal with this kind of anything.

It was a tedious process but I found all of the APs I was looking for. Thanks again!!
 

amdTJL0

Member
Dec 17, 2006
40
0
0
Thanks, this is the method I wound up using. I was doing it from a border switch at first rather then the core. I'm trying to bring Solarwinds/OpenView/Cisco Works solution online here so we don't have to deal with this kind of anything.

It was a tedious process but I found all of the APs I was looking for. Thanks again!!

I just brought up our LMS server and while it was kind of a pain it has helped us so much. Glad you found it
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |