• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Catalyst 3560 Question

Cmustang87

Supreme [H]ardness
Joined
Oct 4, 2007
Messages
4,498
Hello,

I'm currently studying for ICND1 to be on course to CCNA. I'm following CBT Nuggets by Jeremy Cioara, please forgive my lack of knowledge in this, I'm just starting to get the hang of navigating around IOS and being comfortable with it.

I'm trying to find out why in my running config after setting a password for VTY 0-15 why "no login" is set. In the videos he says "login" is supposed to be default for Telnet, so that way it requires you to set a password. Can anyone shine some light on why mine is doing this? I went through a factory reset of the device by deleting the config files and initiating a boot. Pasted below is my running-config:

% Invalid input detected at '^' marker.

SW01-C3560#!
SW01-C3560#interface GigabitEthernet0/1
^
% Invalid input detected at '^' marker.

SW01-C3560#!
SW01-C3560#interface GigabitEthernet0/2
^
% Invalid input detected at '^' marker.

SW01-C3560#!
SW01-C3560#interface GigabitEthernet0/3
^
% Invalid input detected at '^' marker.

SW01-C3560#!
SW01-C3560#interface GigabitEthernet0/4
^
% Invalid input detected at '^' marker.

SW01-C3560#!
SW01-C3560#interface Vlan1
^
% Invalid input detected at '^' marker.

SW01-C3560# no ip address
^
% Invalid input detected at '^' marker.

SW01-C3560#!
SW01-C3560#ip classless
^
SW01-C3560#show running-config
Building configuration...

Current configuration : 2046 bytes
!
version 12.2
no service pad
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname SW01-C3560
!
!
no aaa new-model
ip subnet-zero
!
!
!
!
!
!
no file verify auto
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
interface FastEthernet0/1
!
interface FastEthernet0/2
!
interface FastEthernet0/3
!
interface FastEthernet0/4
!
interface FastEthernet0/5
!
interface FastEthernet0/6
!
interface FastEthernet0/7
!
interface FastEthernet0/8
!
interface FastEthernet0/9
!
interface FastEthernet0/10
!
interface FastEthernet0/11
!
interface FastEthernet0/12
!
interface FastEthernet0/13
!
interface FastEthernet0/14
!
interface FastEthernet0/15
!
interface FastEthernet0/16
!
interface FastEthernet0/17
!
interface FastEthernet0/18
!
interface FastEthernet0/19
!
interface FastEthernet0/20
!
interface FastEthernet0/21
!
interface FastEthernet0/22
!
interface FastEthernet0/23
!
interface FastEthernet0/24
!
interface FastEthernet0/25
!
interface FastEthernet0/26
!
interface FastEthernet0/27
!
interface FastEthernet0/28
!
interface FastEthernet0/29
!
interface FastEthernet0/30
!
interface FastEthernet0/31
!
interface FastEthernet0/32
!
interface FastEthernet0/33
!
interface FastEthernet0/34
!
interface FastEthernet0/35
!
interface FastEthernet0/36
!
interface FastEthernet0/37
!
interface FastEthernet0/38
!
interface FastEthernet0/39
!
interface FastEthernet0/40
!
interface FastEthernet0/41
!
interface FastEthernet0/42
!
interface FastEthernet0/43
!
interface FastEthernet0/44
!
interface FastEthernet0/45
!
interface FastEthernet0/46
!
interface FastEthernet0/47
!
interface FastEthernet0/48
!
interface GigabitEthernet0/1
!
interface GigabitEthernet0/2
!
interface GigabitEthernet0/3
!
interface GigabitEthernet0/4
!
interface Vlan1
no ip address
!
ip classless
ip http server
ip http secure-server
!
!
control-plane
!
!
line con 0
password cisco
login
line vty 0 4
password cisco
no login
line vty 5 15
password cisco
no login
!
end

SW01-C3560#

Here is my bootup:

Base ethernet MAC Address: XX:XX:XX:XX:XX:XX
Xmodem file system is available.
The password-recovery mechanism is enabled.
Initializing Flash...
flashfs[0]: 365 files, 5 directories
flashfs[0]: 0 orphaned files, 0 orphaned directories
flashfs[0]: Total bytes: 32514048
flashfs[0]: Bytes used: 8529408
flashfs[0]: Bytes available: 23984640
flashfs[0]: flashfs fsck took 12 seconds.
...done Initializing Flash.
Boot Sector Filesystem (bs) installed, fsid: 3
done.
Loading "flash:c3560-ipbasek9-mz.122-25.SEE/c3560-ipbasek9-mz.122-25.SEE.bin"...
@
File "flash:c3560-ipbasek9-mz.122-25.SEE/c3560-ipbasek9-mz.122-25.SEE.bin" uncompressed and installed, entry point: 0x3000
executing...


Cisco IOS Software, C3560 Software (C3560-IPBASEK9-M), Version 12.2(25)SEE, RELEASE SOFTWARE (fc2)
Copyright (c) 1986-2006 by Cisco Systems, Inc.
Compiled Fri 03-Feb-06 07:38 by antonino
Image text-base: 0x00003000, data-base: 0x00FDB4CC

Initializing flashfs...

flashfs[1]: 365 files, 5 directories
flashfs[1]: 0 orphaned files, 0 orphaned directories
flashfs[1]: Total bytes: 32514048
flashfs[1]: Bytes used: 8529408
flashfs[1]: Bytes available: 23984640
flashfs[1]: flashfs fsck took 1 seconds.
flashfs[1]: Initialization complete....done Initializing flashfs.

POST: CPU MIC register Tests : Begin
POST: CPU MIC register Tests : End, Status Passed

POST: PortASIC Memory Tests : Begin
POST: PortASIC Memory Tests : End, Status Passed

POST: CPU MIC PortASIC interface Loopback Tests : Begin
POST: CPU MIC PortASIC interface Loopback Tests : End, Status Passed

POST: PortASIC RingLoopback Tests : Begin
POST: PortASIC RingLoopback Tests : End, Status Passed

POST: PortASIC CAM Subsystem Tests : Begin
POST: PortASIC CAM Subsystem Tests : End, Status Passed

POST: PortASIC Port Loopback Tests : Begin
POST: PortASIC Port Loopback Tests : End, Status Passed

Waiting for Port download...Complete

cisco WS-C3560-48TS (PowerPC405) processor (revision D0) with 118784K/12280K bytes of memory.
Processor board ID CAT0951N17J
Last reset from power-on
1 Virtual Ethernet interface
48 FastEthernet interfaces
4 Gigabit Ethernet interfaces
The password-recovery mechanism is enabled.

512K bytes of flash-simulated non-volatile configuration memory.
Base ethernet MAC Address : XX:XX:XX:XX:XX:XX
Motherboard assembly number : X
Power supply part number : 341-0097-02
Motherboard serial number : X
Power supply serial number : X
Model revision number : D0
Motherboard revision number : A0
Model number : WS-C3560-48TS-S
System serial number : X
SFP Module assembly part number : 73-7757-03
SFP Module revision Number : A0
SFP Module serial number : X
Top Assembly Part Number : 800-26162-02
Top Assembly Revision Number : C0
Version ID : V02
CLEI Code Number : COMMJ00ARB
Hardware Board Revision Number : 0x01


Switch Ports Model SW Version SW Image
------ ----- ----- ---------- ----------
* 1 52 WS-C3560-48TS 12.2(25)SEE C3560-IPBASEK9-M




Press RETURN to get started!

The only commands I have run on this device are:

line con 0
password cisco
login
conf t
line vty 0 15
password cisco

Does this device by default set VTY ports to no login? Seems like a security issue, just bothers me that it's not consistent with the video.
 
You're trying to configure interfaces and other things without being in config mode... Type 'conf t' then try again...

Example:
SW01-C3560#interface GigabitEthernet0/2

That shows that you're not in config mode...config mode would look like this
SW01-C3560(config)#

Good luck.
 
Thank you for the response.

I was in config mode, sorry. The last part of commands i was running was just letting you know I was configuring them. I can set the password and everything fine, I"m just curious why "no login" is the default, when I'm being told it's not supposed to be.

See:

Switch#show running-config | begin line
line con 0
password cisco
login
line vty 0 4
password cisco
no login
line vty 5 15
password cisco
no login
!
end
 
I see. I'm not sure. It could be IOS version specific. I wouldn't take every word Jeremy says for the absolute truth in all cases.

Many defaults have changed over the years. I have some 3560s at home that I could boot up when I get home later and look at what their default is but I wouldn't exactly worry about it either lol

You could go download a very old version of the IOS and boot it up in default config and see if it's different.
 
I see, well thank you for your time. I mean admittedly, it's pedantic of me to worry about something so frivolous but it's more of a curiosity thing. I learn by understanding why things are a certain way. I would be interested to know if your switch is the same story. Thank you Mystic, and I appreciate the good luck, I'm having a great time so far.
 
no login is usually the default from what I have seen.

You need to issue the "login" command to allow logins.
 
I can't say i've ever seen "no login" as a default.

As mystic said, might just be a default for that version of code.

BTW, if possible, it might be worth looking into upgrading that to something a little newer. The latest iteration of the CCNA exams are based on IOS 15.x.
 
If anyone can show me any part of the ICND1 or ICND2 that can only be done on 15.x IOS I'll be shocked...ICND1 and ICND2 are just not that deep.
 
If anyone can show me any part of the ICND1 or ICND2 that can only be done on 15.x IOS I'll be shocked...ICND1 and ICND2 are just not that deep.

A quick google search states there are licensing related questions on the exam(s) which are specific to IOS 15.x.

Do you need equipment running 15.x to pass the exam, no. Worth mentioning, yes.
 
If anyone can show me any part of the ICND1 or ICND2 that can only be done on 15.x IOS I'll be shocked...ICND1 and ICND2 are just not that deep.

Not sure if you knew, but they have redone the ICND1 and ICND2. I see your sig lists several certs so it may have been a while. How would one go about updating the IOS on this switch? Does it cost money?

I also noticed that when it boots it always says "password recovery mode enabled".

EDIT: NVM Looks like you need to order Cisco IOS similar to putting new versions of Windows on a computer. I imagine I wouldn't need to update this switch as Jeremy is using 12.2 on his videos for CBT and everyone recommends 3550s or 3560s for switches. These probably came stock with 12.x versions.
 
Last edited:
12.2 (55) should serve you just fine. IOS 15 does change licensing models with a universal image, etc but it's nothing groundbreaking.

if you can memorize a few of the basic licensing commands (they're really not that difficult to understand what you're doing) the rest should all match up to what everyone is used to in the "old school" 12.2 base.
 
The OP's switch listed above does not support IOS 15.x. IOS12.2(55) SE8 is the latest release.

Cmustang, in order to upgrade the IOS you need an active service contract (smartnet).
 
Also in his video he does say by default the no login is on the vty and if you try and telnet with no login it will say something like telnet password net set and disconnect you. The problem is I am not sure which chapter he says it in (i have been watching them also).
 
From my CCNA Academy courses working with similar switches and routers, we were always taught and told that initially you had to configure the devices via console cable (security reasons I believe) first and manually turn on interfaces you wanted, including SSH/Telnet.

If they were used devices it might be because of the previous owner not clearing the device properly.

no login sounds correct to me. I've always throughout 4 quarters had to manually type the login command for it to work after the device was properly cleared the day before.
 
Also in his video he does say by default the no login is on the vty and if you try and telnet with no login it will say something like telnet password net set and disconnect you. The problem is I am not sure which chapter he says it in (i have been watching them also).

It is in nugget #9, or the video directly after getting familiar with IOS.
 
I also noticed that when it boots it always says "password recovery mode enabled".

This is totally normal. You can actually disable the ability to perform passwords resets on a Cisco switch. It's an advanced security feature you would learn in the CCNA Security track.

I would never recommend doing that with your own equipment as there would be no way to recover it save for sending it back to Cisco (at least as far as I know, I've never really had to look into it).

You can of course find IOS images online, no surprise there, but in general you need a contract with Cisco to get new images.
 
Thanks again, Mystic and thank you everyone. I think this thread is finished.
 
Regarding password recovery: There's one possibility in case of a forgotten password if disabled. Ctrl-Break on the console when booting, this gives the option of resetting the entire configuration.

However, if the IOS image is missing or corrupted and password recovery is disabled, there's no way to access ROMMON for loading a working image through TFTP or Xmodem.
 
Back
Top