! Cisco Layer 3 Switch Hardened Configuration
! Routed upstream; inspected access switches on downstream trunk.
! Ensure DHCP service/relay and upstream return routes already exist.
configure terminal
vlan 10
 name USERS
exit
vlan <MGMT-VLAN>
 name MANAGEMENT
exit
vlan 998
 name UNUSED-NATIVE
exit
vlan 999
 name UNUSED-PORTS
exit
hostname <HOSTNAME>
no ip domain-lookup
ip domain-name <DOMAIN.LOCAL>
username <ADMIN> privilege 15 algorithm-type scrypt secret <STRONG-PASSWORD>
aaa new-model
aaa authentication login default local
aaa authorization exec default local
no ip http server
no ip http secure-server
no service pad
no ip source-route
login block-for 120 attempts 5 within 60
crypto key generate rsa modulus 2048
ip ssh version 2
ip ssh time-out 60
ip ssh authentication-retries 3
ip access-list standard MGMT-SSH
 permit <ADMIN-SUBNET> <WILDCARD>
 deny any log
exit
line vty 0 15
 login authentication default
 transport input ssh
 exec-timeout 10 0
 access-class MGMT-SSH in
exit
line console 0
 login authentication default
 exec-timeout 10 0
 logging synchronous
exit
clock timezone <TZ-NAME> <OFFSET>
ntp source Vlan<MGMT-VLAN>
ntp server <NTP-IP> prefer
service timestamps log datetime msec localtime show-timezone
logging host <SYSLOG-IP>
logging source-interface Vlan<MGMT-VLAN>
logging trap warnings
logging buffered 16384 informational
ip access-list standard SNMP-ACL
 permit host <MONITORING-IP>
 deny any log
exit
snmp-server view NMS-READ iso included
snmp-server group NMS-GROUP v3 priv read NMS-READ access SNMP-ACL
snmp-server user <SNMP-USER> NMS-GROUP v3 auth sha <SNMP-AUTH-PASSWORD> priv aes 128 <SNMP-PRIV-PASSWORD>
ip routing
interface Vlan<MGMT-VLAN>
 description MANAGEMENT
 ip address <MGMT-IP> <MASK>
 no ip redirects
 no ip proxy-arp
 no shutdown
exit
interface Vlan10
 description USERS-GATEWAY
 ip address 10.10.10.1 255.255.255.0
 no ip redirects
 no ip proxy-arp
 no shutdown
exit
interface <UPLINK>
 description ROUTED-UPSTREAM
 no switchport
 ip address <TRANSIT-IP> <TRANSIT-MASK>
 no ip redirects
 no ip proxy-arp
 no shutdown
exit
ip route 0.0.0.0 0.0.0.0 <UPSTREAM-NEXT-HOP>
ip access-list extended USERS-TO-MGMT
 remark Approved shared infrastructure exceptions
 permit udp 10.10.10.0 0.0.0.255 host 10.99.99.10 eq domain
 permit tcp 10.10.10.0 0.0.0.255 host 10.99.99.10 eq domain
 permit udp 10.10.10.0 0.0.0.255 host 10.99.99.20 eq ntp
 deny ip 10.10.10.0 0.0.0.255 10.99.99.0 0.0.0.255
 permit ip any any
exit
interface Vlan10
 ip access-group USERS-TO-MGMT in
exit
spanning-tree mode rapid-pvst
spanning-tree portfast bpduguard default
ip dhcp snooping
ip dhcp snooping vlan <USER-VLANS>
no ip dhcp snooping information option
ip arp inspection vlan <USER-VLANS>
interface <DOWNLINK-TRUNK>
 description TO-INSPECTED-ACCESS-SWITCH
 switchport mode trunk
 switchport trunk native vlan 998
 switchport trunk allowed vlan <VLAN-LIST>
 switchport nonegotiate
 ! DHCP replies originate locally/upstream: this downstream ingress is untrusted.
 ! ARP trust only because downstream Catalyst enforces DAI on every endpoint port.
 ip arp inspection trust
 no shutdown
exit
interface range <ACCESS-PORTS>
 description REVIEWED-DHCP-ENDPOINTS
 switchport mode access
 switchport access vlan 10
 switchport nonegotiate
 spanning-tree portfast
 spanning-tree bpduguard enable
 ip dhcp snooping limit rate <RATE>
 ip arp inspection limit rate <ARP-RATE>
 ip verify source
 switchport port-security
 switchport port-security maximum 3
 switchport port-security violation restrict
 switchport port-security mac-address sticky
 storm-control broadcast level <BCAST-RISE> <BCAST-FALL>
 storm-control multicast level <MCAST-RISE> <MCAST-FALL>
 storm-control action trap
 no shutdown
exit
interface range <UNUSED-PORTS>
 switchport mode access
 switchport access vlan 999
 shutdown
exit
end
! Validate, then separately run: copy running-config startup-config
