Network and Telecom

Cisco Switch Installation and Configuration

A Cisco switch straight out of the box will run on factory defaults. But a switch with no VLAN separation, Telnet open for management and no backup will cost you hours at the first fault.

CybUP TeamLast updated: 6 min read

In short

Cisco switch configuration means bringing a Catalyst or Cisco Business switch into the network with VLANs, trunks, spanning tree, port security, SSH management, SNMP monitoring and configuration backups properly set up. It is for companies that run their own network. CybUP installs new switches, audits the configuration of existing Cisco switches, and handles IOS upgrades and password recovery.

How do you install and configure a Cisco switch?

A Cisco switch setup starts with first access over the console cable, moves on to management settings, VLANs, port roles and security, and ends with a backup and documentation. The order matters: secure management access comes first, and user ports are enabled after that.

The first pass sets the hostname, domain name, management VLAN and IP address, NTP and the log server. Then the VLANs are created, uplinks are configured as trunk ports and user ports as access ports. Where IP phones are in use, a voice VLAN is added to the same port, so the phone and the PC plugged in behind it sit on separate networks.

Say a 40-person accounting firm is putting in two 48-port Catalyst switches. Users, IP phones, printers and cameras go into separate VLANs; the link between the two switches is built as a two-cable port-channel; unused ports are shut down and assigned to an unused VLAN. All of this is prepared on the bench, so at the office the only job left is plugging in cables.

Cisco Catalyst or Cisco Business: which do you need?

Catalyst is Cisco’s enterprise switch family, running IOS or IOS XE and managed in detail from the command line; the Cisco Business range is aimed at small businesses and is mostly managed through a web interface. Both handle the basics such as VLANs, trunks, port security and SSH. The differences are scale, how they are managed and the advanced features.

Plenty of older Catalyst 2960-family switches are still running in the field. Software support and spare parts for them are more limited than for current models. During the review we check the model and software version and report whether your switch is still supported; if it needs replacing, we plan that together with the core switch design.

What matters when configuring VLANs, trunks and spanning tree?

Trunk ports should carry only the VLANs they need, and the native VLAN should be moved to an unused VLAN. “All VLANs everywhere” makes day one easy, but it lets a broadcast storm spread across the whole building and leaves the door open to VLAN hopping attacks.

For spanning tree, the root bridge is deliberately placed on the core switch. Otherwise an old switch with the lowest MAC address can end up as root and traffic takes strange paths. User ports get PortFast together with BPDU Guard: if someone brings a small switch to their desk and plugs it in, the port shuts itself down and no loop forms.

Which settings make a Cisco switch secure?

Management access should be SSH only, with Telnet disabled. Cisco’s SSH configuration guide recommends SSH version 2, a strong RSA key supported by the platform, and allowing only SSH on the VTY lines. We also use an access list to restrict management access to addresses on the IT network.

On user ports, port security, DHCP snooping and Dynamic ARP Inspection protect against local network attacks such as rogue DHCP servers and ARP spoofing. Local user passwords are stored with a strong hashing algorithm; where possible, authentication goes to a central RADIUS/TACACS+ server and every command is logged.

  • SSH v2, Telnet off, management access restricted by ACL
  • Unused ports shut down and parked in a separate VLAN
  • PortFast, BPDU Guard and port security on user ports
  • DHCP snooping and Dynamic ARP Inspection
  • SNMPv3, central logging and NTP

“If you want to prevent Non-SSH connections, add the transport input ssh command under the lines to limit the router to SSH connections only. Straight (non-ssh) Telnets are refused.”

— Cisco — Configure SSH on Routers and Switches

SNMP monitoring, configuration backups and IOS upgrades

Running a switch without monitoring means you only find out that a port is logging errors or a fan has stopped when users start complaining. We connect the switch to a monitoring system such as Zabbix over SNMPv3, so port status, error counters, temperature and power supply alerts are visible.

Configuration backups should be taken automatically after every change, using either the switch’s own archive feature or a server that pulls backups on a schedule. When a switch fails, the latest backup goes onto the replacement and it is running with the same settings within minutes.

Before an IOS upgrade, the release notes and hardware compatibility are checked, the current image and configuration are backed up, and the upgrade is done in a maintenance window. Every member of a stack has to run the same version, so the plan always covers the whole stack.

Cisco switch password recovery: what if nobody knows the password?

On most Catalyst switches the password can be recovered without losing the configuration, but it needs physical access to the device. Cisco’s password recovery procedure involves connecting to the console port, holding down the Mode button while power is applied, temporarily renaming the configuration file so the switch boots without it, then restoring the existing configuration and changing the password.

The switch reboots during the process, so there is a short outage. If password recovery has been disabled beforehand, the configuration may not survive and the switch can fall back to factory defaults. That is why we first check whether a current backup exists. When a company is left with several switches whose passwords nobody knows after an IT manager leaves, we do them all in one visit, one switch at a time, with an outage plan.

“Hold down the mode button located on the left side of the front panel, while you reconnect the power cable to the switch.”

— Cisco — Recover Password for Catalyst Fixed Configuration Switches

What you receive

  • Cisco switch configurations prepared and tested before deployment
  • VLAN list, port mapping table and topology diagram
  • Security hardening: SSH, ACLs, port security, DHCP snooping, BPDU Guard
  • SNMPv3 monitoring and central logging
  • Automatic configuration backups and a restore note
  • IOS / IOS XE upgrade and version report, where needed

How we work

  1. 1

    Review

    We review your existing switch models, software versions and configurations and report what is missing.

  2. 2

    Plan

    We agree the VLANs, port roles, security settings and any upgrade plan with you.

  3. 3

    Configuration

    We prepare new switches on the bench and apply changes to existing ones in a maintenance window.

  4. 4

    Testing

    We check user, phone, printer and uplink connections one by one and run loop and redundancy tests.

  5. 5

    Handover

    We hand over the configuration backups, the port table and the management credentials securely.

Frequently asked questions

How long does it take to configure a single Cisco switch?

With the plan ready, a standard office switch is configured and tested in a few hours. What really drives the time is the VLAN plan and compatibility with the other devices on the network. When there are many switches, we build templates in advance to cut the time on site.

Can you audit the configuration of our existing Cisco switches?

Yes. We read the configurations, check the security, spanning tree, VLAN and management settings, and report the findings in order of priority. If you like, we apply the fixes ourselves in a maintenance window.

Can a Cisco switch password be reset remotely?

No. If the password is unknown, someone has to be at the switch for console access and the Mode button. In Istanbul we come on site. If an admin account still works, the password can be changed remotely.

Do we need a licence or support contract for an IOS upgrade?

The right to download software is usually tied to the device’s Cisco support contract. We check the contract status with you, and we only upgrade with software obtained through official channels.

How much does Cisco switch configuration cost?

We give a written quote once we have reviewed the scope; the review is free. The number of switches, whether the work is on site or remote, and any upgrade needs determine the quote.

Do you work on mixed-vendor networks?

Yes. VLAN tagging, LACP and spanning tree are standard protocols, so different brands can work together. At the design stage we identify where vendor-proprietary protocols could cause trouble in a mixed network and use the standard equivalents instead.

Who monitors the switches, and what happens when one fails?

With SNMP and logging configured, we connect the switches to your own monitoring system or to one we set up for you. Post-installation support and fault response are defined separately in the quote.

Sources and official documentation

CybUP Team

Written and reviewed by the CybUP technical team in Istanbul. Last updated: 10 October 2026.

Request a free review for this service

Fill in the form and we will get back to you as soon as possible. For urgent matters, WhatsApp or phone is faster.

Message on WhatsApp

Cookie preferences

Strictly necessary

Required for the core functions of the site and to remember your choices. Cannot be turned off.

Analytics

Lets us measure which pages are visited, anonymously (Google Analytics via Google Tag Manager).

Marketing

Used for advertising measurement and personalisation.