In short
Cisco switch configuration means bringing a Catalyst or Cisco Business switch into the network with VLANs, trunks, spanning tree, port security, SSH management, SNMP monitoring and configuration backups properly set up. It is for companies that run their own network. CybUP installs new switches, audits the configuration of existing Cisco switches, and handles IOS upgrades and password recovery.
How do you install and configure a Cisco switch?
A Cisco switch setup starts with first access over the console cable, moves on to management settings, VLANs, port roles and security, and ends with a backup and documentation. The order matters: secure management access comes first, and user ports are enabled after that.
The first pass sets the hostname, domain name, management VLAN and IP address, NTP and the log server. Then the VLANs are created, uplinks are configured as trunk ports and user ports as access ports. Where IP phones are in use, a voice VLAN is added to the same port, so the phone and the PC plugged in behind it sit on separate networks.
Say a 40-person accounting firm is putting in two 48-port Catalyst switches. Users, IP phones, printers and cameras go into separate VLANs; the link between the two switches is built as a two-cable port-channel; unused ports are shut down and assigned to an unused VLAN. All of this is prepared on the bench, so at the office the only job left is plugging in cables.
Cisco Catalyst or Cisco Business: which do you need?
Catalyst is Cisco’s enterprise switch family, running IOS or IOS XE and managed in detail from the command line; the Cisco Business range is aimed at small businesses and is mostly managed through a web interface. Both handle the basics such as VLANs, trunks, port security and SSH. The differences are scale, how they are managed and the advanced features.
Plenty of older Catalyst 2960-family switches are still running in the field. Software support and spare parts for them are more limited than for current models. During the review we check the model and software version and report whether your switch is still supported; if it needs replacing, we plan that together with the core switch design.
What matters when configuring VLANs, trunks and spanning tree?
Trunk ports should carry only the VLANs they need, and the native VLAN should be moved to an unused VLAN. “All VLANs everywhere” makes day one easy, but it lets a broadcast storm spread across the whole building and leaves the door open to VLAN hopping attacks.
For spanning tree, the root bridge is deliberately placed on the core switch. Otherwise an old switch with the lowest MAC address can end up as root and traffic takes strange paths. User ports get PortFast together with BPDU Guard: if someone brings a small switch to their desk and plugs it in, the port shuts itself down and no loop forms.
Which settings make a Cisco switch secure?
Management access should be SSH only, with Telnet disabled. Cisco’s SSH configuration guide recommends SSH version 2, a strong RSA key supported by the platform, and allowing only SSH on the VTY lines. We also use an access list to restrict management access to addresses on the IT network.
On user ports, port security, DHCP snooping and Dynamic ARP Inspection protect against local network attacks such as rogue DHCP servers and ARP spoofing. Local user passwords are stored with a strong hashing algorithm; where possible, authentication goes to a central RADIUS/TACACS+ server and every command is logged.
- SSH v2, Telnet off, management access restricted by ACL
- Unused ports shut down and parked in a separate VLAN
- PortFast, BPDU Guard and port security on user ports
- DHCP snooping and Dynamic ARP Inspection
- SNMPv3, central logging and NTP
“If you want to prevent Non-SSH connections, add the transport input ssh command under the lines to limit the router to SSH connections only. Straight (non-ssh) Telnets are refused.”
SNMP monitoring, configuration backups and IOS upgrades
Running a switch without monitoring means you only find out that a port is logging errors or a fan has stopped when users start complaining. We connect the switch to a monitoring system such as Zabbix over SNMPv3, so port status, error counters, temperature and power supply alerts are visible.
Configuration backups should be taken automatically after every change, using either the switch’s own archive feature or a server that pulls backups on a schedule. When a switch fails, the latest backup goes onto the replacement and it is running with the same settings within minutes.
Before an IOS upgrade, the release notes and hardware compatibility are checked, the current image and configuration are backed up, and the upgrade is done in a maintenance window. Every member of a stack has to run the same version, so the plan always covers the whole stack.
Cisco switch password recovery: what if nobody knows the password?
On most Catalyst switches the password can be recovered without losing the configuration, but it needs physical access to the device. Cisco’s password recovery procedure involves connecting to the console port, holding down the Mode button while power is applied, temporarily renaming the configuration file so the switch boots without it, then restoring the existing configuration and changing the password.
The switch reboots during the process, so there is a short outage. If password recovery has been disabled beforehand, the configuration may not survive and the switch can fall back to factory defaults. That is why we first check whether a current backup exists. When a company is left with several switches whose passwords nobody knows after an IT manager leaves, we do them all in one visit, one switch at a time, with an outage plan.
“Hold down the mode button located on the left side of the front panel, while you reconnect the power cable to the switch.”
What you receive
- Cisco switch configurations prepared and tested before deployment
- VLAN list, port mapping table and topology diagram
- Security hardening: SSH, ACLs, port security, DHCP snooping, BPDU Guard
- SNMPv3 monitoring and central logging
- Automatic configuration backups and a restore note
- IOS / IOS XE upgrade and version report, where needed
How we work
- 1
Review
We review your existing switch models, software versions and configurations and report what is missing.
- 2
Plan
We agree the VLANs, port roles, security settings and any upgrade plan with you.
- 3
Configuration
We prepare new switches on the bench and apply changes to existing ones in a maintenance window.
- 4
Testing
We check user, phone, printer and uplink connections one by one and run loop and redundancy tests.
- 5
Handover
We hand over the configuration backups, the port table and the management credentials securely.
Frequently asked questions
How long does it take to configure a single Cisco switch?
With the plan ready, a standard office switch is configured and tested in a few hours. What really drives the time is the VLAN plan and compatibility with the other devices on the network. When there are many switches, we build templates in advance to cut the time on site.
Can you audit the configuration of our existing Cisco switches?
Yes. We read the configurations, check the security, spanning tree, VLAN and management settings, and report the findings in order of priority. If you like, we apply the fixes ourselves in a maintenance window.
Can a Cisco switch password be reset remotely?
No. If the password is unknown, someone has to be at the switch for console access and the Mode button. In Istanbul we come on site. If an admin account still works, the password can be changed remotely.
Do we need a licence or support contract for an IOS upgrade?
The right to download software is usually tied to the device’s Cisco support contract. We check the contract status with you, and we only upgrade with software obtained through official channels.
How much does Cisco switch configuration cost?
We give a written quote once we have reviewed the scope; the review is free. The number of switches, whether the work is on site or remote, and any upgrade needs determine the quote.
Do you work on mixed-vendor networks?
Yes. VLAN tagging, LACP and spanning tree are standard protocols, so different brands can work together. At the design stage we identify where vendor-proprietary protocols could cause trouble in a mixed network and use the standard equivalents instead.
Who monitors the switches, and what happens when one fails?
With SNMP and logging configured, we connect the switches to your own monitoring system or to one we set up for you. Post-installation support and fault response are defined separately in the quote.