Telnet and SSH on packet tracer

A terminal emulation program for TCP/IP networks such as the Internet. The Telnet program runs on your computer and connects your PC to a server on the network. You can then enter commands through the Telnet program and they will be executed as if you were entering them directly on the server console. This enables you to control the server and communicate with other servers on the network. To start a Telnet session, you must log in to a server by entering a valid username and password. Telnet is a common way to remotely control Web servers. To telnet means to establish a connection with the Telnet protocol, either with command line client or with a programmatic interface.
Secure Shell (SSH) is a cryptographic network protocol for secure data communication, remote shell services or command execution and other secure network services between two networked computers that connects, via a secure channel over an insecure network, a server and a client (running SSH server and SSH client programs, respectively). It was designed as a replacement for Telnet and other insecure remote shell protocols such as the Berkeley rsh and rexec protocols, which send information, notably passwords, in plaintext, rendering them susceptible to interception and disclosure using packet analysis. The encryption used by SSH is intended to provide confidentiality and integrity of data over an unsecured network, such as the Internet.

a network protocol that ensures a high-level encryption, allowing for the data transmitted over insecure networks, such as the Internet, to be kept intact and integrate. SSH and SSH Telnet, in particular, work for establishing a secure communication between two network-connected computers as an alternative to remote shells, such as TELNET, that send sensitive information in an insecure environment. 

In contrast to other remote access protocols, such as FTP, SSH Telnet ensures higher level of connection security between distant machines but at the same time represents a potential threat to the server stability. Thus, SSH access is considered a special privilege by hosting providers and is often assigned to users only per request. 

Let us apply Telnet and SSH on packet tracer.

Take the topology as in the above diagram. Set IPs on the PCs. As, by default, all PCs are in vlan 1. We will create a virtual interface on switch with vlan 1 as follows.


Now, we can ping to switch by our hosts because hosts are in vlan 1 and switch also has a vlan 1 interface.

Now, try to telnet the switch from our PC, it refuses because we have not applied authentication on the switch yet.
So, lets apply line authentication on the switch. The system supports 20 virtual tty (vty) lines for Telnet, Secure Shell Server (SSH) and FTP services. Each Telnet, SSH, or FTP session requires one vty line. You can add security to your system by configuring the software to validate login requests. 

Now, we can easily telnet. But it does not let us go in the switch enabled mode because we have not set the password on the switch yet.


Lets apply password on the switch enabled mode.

Now, we can go inside Switch configuration mode from our pc.


So, now let us apply SSH on the switch.


Commands continued.


Now, we try to telnet it but it is refused because ssh has over ruled telnet. So, we will use SSH protocol on it. By default username is admin.


And we can apply any sort of configuration on our switch from out pc.


Now, if we want to change the username from admin to something else, we will do it as follows.


and from our pc as follows.


The SSH commands are as follows.

Switch(config)#ip domain name ?

 WORD  Default domain nameSwitch(config)#ip domain name abc.comSwitch(config)#crypto key generate rsa
% Please define a hostname other than Switch.

Switch(config)#hostname s1

s1(config)#ip domain name cs-studys1

s1(config)#crypto key generate rsa

Choose the size of the key modulus in the range of 360 to 2048 for your General Purpose Keys. Choosing a key modulus greater than 512 may take   a few minutes.

s1(config)#line vty 0 15

s1(config-line)#transport input ssh

The name for the keys will be: s1.cs-study
How many bits in the modulus [512]: 1024

% Generating 1024 bit RSA keys, keys will be non-exportable...[OK]

s1(config)#ip ssh version 2




  1. Replies
  2. I just wonder what are the configurations in telneting multiple switches...can someone give me a full grasp?

    1. yup thats possible. i have just tried that. Connect two switches with the crossover cable and attach PC to one of the switch. You can telnet both switches from that PC. Like in the image attached. PC0 is able to telnet both switches. Dont forget to provide the vlan interfaces to both switches in order to enable telnet. Hope that helps. Cheers :)

    2. oops forgot to attach the url

  3. thankx it was really helpful

  4. Nice example, I doing a lab on packet tracer if possible to use teraterm with packet tracer.

    1. Nope, this is not possible. You will have to use the default PC command line.

  5. Nice information
    Thanks for sharing

  6. Very useful information.
    Thank you.

  7. How can a vlan interface be assigned a dhcp ip address??

    1. Hi , There is no DHCP applied here . Look carefully . DHCP is mostly applied either on router or Server. We rnt using any of those devices. We just applied IP address to vlan interface of switch so that we can ping the switch.

  10. Nice explaination very usefull..

  12. how can the beginners easily memorize the flow of configurations? advance thanks for answering this:)

  13. how can the beginners easily memorize the flow of configurations? advance thanks for answering this:)

  14. hello,i don't know.why Laptop1 can't telnet to the switch0?

  15. After Configuring SSH on my switch, it cannot regonize enable feature any more, it just goes to the privillage mode straight away with out enable password, kindly help i may have done something wrong.

    please help

    1. yow tru this one

      R1#conf t
      R1(config)#enable secret
      R1(config)#password cisco
      R1(config)#line console 0
      password cisco
      R1(config)#line vty 04
      R1(config)#pasword cisco
      R1#copy running-config startup-config

  16. i'm sorry MR. what the same configuration ssh you explain with ssh version 2.

  20. good, but you have forgot in the real network scenarios default VLAN (Vlan1) it's not recommended for security reasons, instead of create one else:

    Switch(config)# vlan id_de_vlan
    Switch(config-vlan)# name name_of_vlan
    Switch(config-vlan)# exit
    Switch(config)# interface interface_id
    Switch(config-if)# ip address
    Switch(config-if)# switchport access vlan id_de_vlan

    and then the rest of settings.. as VTY security, etc..

  23. Really have good to know this information .Thanks for sharing.Keep posting...

  24. I'am glad to read the whole content of this blog and am very excited.Thank you.


