! Cisco Layer 2 Access Switch Hardened Configuration
! Replace placeholders; apply in reviewed stages, not as a blind paste.
configure terminal
vlan 10
 name USERS
exit
vlan <MGMT-VLAN>
 name MANAGEMENT
exit
vlan 998
 name UNUSED-NATIVE
exit
vlan 999
 name UNUSED-PORTS
exit
hostname <HOSTNAME>
no ip domain-lookup
ip domain-name <DOMAIN.LOCAL>
username <ADMIN> privilege 15 algorithm-type scrypt secret <STRONG-PASSWORD>
aaa new-model
aaa authentication login default local
aaa authorization exec default local
no ip http server
no ip http secure-server
no service pad
no ip source-route
login block-for 120 attempts 5 within 60
crypto key generate rsa modulus 2048
ip ssh version 2
ip ssh time-out 60
ip ssh authentication-retries 3
ip access-list standard MGMT-SSH
 permit <ADMIN-SUBNET> <WILDCARD>
 deny any log
exit
line vty 0 15
 login authentication default
 transport input ssh
 exec-timeout 10 0
 access-class MGMT-SSH in
exit
line console 0
 login authentication default
 exec-timeout 10 0
 logging synchronous
exit
clock timezone <TZ-NAME> <OFFSET>
ntp source Vlan<MGMT-VLAN>
ntp server <NTP-IP> prefer
service timestamps log datetime msec localtime show-timezone
logging host <SYSLOG-IP>
logging source-interface Vlan<MGMT-VLAN>
logging trap warnings
logging buffered 16384 informational
ip access-list standard SNMP-ACL
 permit host <MONITORING-IP>
 deny any log
exit
snmp-server view NMS-READ iso included
snmp-server group NMS-GROUP v3 priv read NMS-READ access SNMP-ACL
snmp-server user <SNMP-USER> NMS-GROUP v3 auth sha <SNMP-AUTH-PASSWORD> priv aes 128 <SNMP-PRIV-PASSWORD>
no ip routing
ip default-gateway <GATEWAY>
interface Vlan<MGMT-VLAN>
 description MANAGEMENT
 ip address <MGMT-IP> <MASK>
 no shutdown
exit
spanning-tree mode rapid-pvst
spanning-tree portfast bpduguard default
ip dhcp snooping
ip dhcp snooping vlan <USER-VLANS>
no ip dhcp snooping information option
ip arp inspection vlan <USER-VLANS>
interface <UPLINK>
 description TRUSTED-UPSTREAM-TO-CORE
 switchport mode trunk
 switchport trunk native vlan 998
 switchport trunk allowed vlan <VLAN-LIST>
 switchport nonegotiate
 ip dhcp snooping trust
 ip arp inspection trust
 no shutdown
exit
interface range <ACCESS-PORTS>
 description REVIEWED-DHCP-ENDPOINTS
 switchport mode access
 switchport access vlan 10
 switchport nonegotiate
 spanning-tree portfast
 spanning-tree bpduguard enable
 ip dhcp snooping limit rate <RATE>
 ip arp inspection limit rate <ARP-RATE>
 ip verify source
 switchport port-security
 switchport port-security maximum 3
 switchport port-security violation restrict
 switchport port-security mac-address sticky
 storm-control broadcast level <BCAST-RISE> <BCAST-FALL>
 storm-control multicast level <MCAST-RISE> <MCAST-FALL>
 storm-control action trap
 no shutdown
exit
interface range <UNUSED-PORTS>
 switchport mode access
 switchport access vlan 999
 shutdown
exit
end
! Validate, then separately run: copy running-config startup-config
