5 Things to Do After Plugging In a New Cisco Switch

Ā·
8 min read

Help Desk Geek is reader-supported. We may earn a commission when you buy through links on our site. Learn more.

Just plugged in a new Cisco switch? Out of the box, its management page is protected only by a default username and password that anyone can look up online, leaving its settings open to anyone on your network. Do these five things before you connect any other devices to it.

Fix #1: Replace the default administrator account

Some Cisco switches request an address from your router through DHCP. Others use a static address such as 192.168.1.254.

  1. Connect your computer directly to the switch with an Ethernet cable.
  1. Check your router’s DHCP client list for the switch’s address.
  1. If the switch doesn’t appear, open Settings > Network & internet > Ethernet on your Windows PC.
  1. Select the connected Ethernet network, click Edit beside IP assignment, and choose Manual.
  1. Enable IPv4, then enter an unused address between 192.168.1.2 and 192.168.1.253.
  1. Enter 255.255.255.0 as the subnet mask, save the settings, and browse to https://192.168.1.254.

A certificate warning is expected because a new switch normally uses a self-signed certificate. Confirm that you’re connected directly to the switch before accepting the warning.

If neither method works, connect through the console port with a USB-to-serial adapter and use the setup instructions for your exact model.

  1. Sign in with the credentials printed in the switch documentation or on its label. Older models commonly use cisco for both fields, while some use admin.
  1. On an SG300, open Administration > User Accounts.
  1. Create a new account with a unique username, a strong password, and Read/Write Management Access (15).
Cisco SG300 Administration > User Accounts page with the option to add a user and Read/Write Management Access (15) visible

Current Cisco Business and Catalyst 1300 menus vary by firmware. Look under Administration, System, or Users for the local account settings.

  1. Sign out, then sign in with the new administrator account.
  1. Remove or disable the factory account after confirming the new login works.
  1. Enable the switch’s password-complexity and failed-login lockout options where available.

You should finish with one working administrator account that doesn’t use the factory credentials. Store the password in a password manager rather than relying on the switch’s recovery service.

Fix #2: Enable encrypted management access

Telnet and HTTP send management traffic without adequate encryption. Use SSH for command-line access and HTTPS when you need the web interface.

  1. Open the switch’s management-services page.
  1. On an SG300, go to Security > TCP/UDP Services and enable SSH Service.
  1. Enable HTTPS management.
  1. Disable Telnet.
  1. Disable HTTP after confirming that HTTPS works.
Cisco switch TCP/UDP Services page with SSH and HTTPS enabled and Telnet and HTTP disabled
  1. Open an SSH client such as PuTTY and connect to the switch’s management address.
  1. Sign in with the administrator account created in Fix #1.

The SSH session should display the switch prompt without exposing your password as plain text. If you prefer command-line administration, follow the existing instructions for enabling SSH access on an SG300 switch.

For tighter authentication, you can also enable SSH public-key authentication on an SG300 switch. Small businesses with several switches should consider RADIUS or TACACS+ so administrator access can be managed centrally.

I’d disable the web interface only after testing SSH from a second session. Closing your only working management path turns a routine setup into a console-cable recovery job.

Fix #3: Move management traffic off VLAN 1

VLAN 1 includes every port on many factory configurations. A dedicated management VLAN addresses this by separating the switch interface from regular computers, guest devices, and wireless clients.

  1. Choose an unused VLAN ID and management subnet. The example below uses VLAN 15 and 192.168.50.0/24.
  1. Create VLAN 15 through the switch’s VLAN-management page.
  1. Name it Management.
  1. Open the IPv4 interface settings. On an SG300, the path is Administration > Management Interface > IPv4 Interface.
  1. Select VLAN 15 as the management VLAN.
  1. Assign the switch an unused static address such as 192.168.50.2 with subnet mask 255.255.255.0.
  1. Enter the router interface for that VLAN, such as 192.168.50.1, as the default gateway.
Cisco SG300 Administration > Management Interface > IPv4 Interface page with a static address assigned to management VLAN 15
  1. Configure one switch port as an access port in VLAN 15.
  1. Connect your administration PC to that port.
  1. Give the PC an address in the same subnet, then open the switch’s new management address.
  1. Confirm that HTTPS and SSH work at 192.168.50.2.
  1. Restrict access to the management subnet with an access control list if your switch and router support it.
  1. Block guest Wi-Fi and ordinary user VLANs from reaching the switch’s management address.

You should be able to manage the switch from the designated administrator port or subnet, while devices on other VLANs receive no response.

Don’t remove the old management address until the new one works. A wrong VLAN assignment can cut off both the web interface and SSH, forcing you to recover through the console port.

Fix #4: Update the firmware

Firmware updates correct security flaws and switch bugs. Download the package for the exact model and hardware revision; firmware intended for a similar-looking switch can fail validation or prevent a clean upgrade.

  1. Record the full model number and current firmware version from the switch’s status page.
  1. Find the model’s support page on Cisco’s website.
  1. Download the newest firmware Cisco provides for that exact model and revision.
Cisco support download page showing the selected switch model, firmware release version, publication date, and download button
  1. Read the release notes for required intermediate versions, boot-code updates, and configuration warnings.
  1. Back up the current configuration before uploading anything.
  1. Open Administration > File Management or the equivalent firmware-management page for your model.
  1. Upload the firmware file to the inactive image slot when the switch provides two image slots.
  1. Select the uploaded image as the next active image.
  1. Reboot the switch during a maintenance window.
  1. Sign back in and verify the running firmware version.

The switch should report the new version and retain its VLAN, account, and port settings. If it starts from the previous image, check which image is marked active and review the switch log for an installation error.

The SG300 is legacy hardware, and the SG350 is no longer sold. CBS350 models also reached end-of-sale, with Catalyst 1300 switches replacing many models in that range. Cisco still publishes model-specific files and lifecycle details, so check support status before putting an older managed switch on an important network.

Fix #5: Harden ports and save the configuration

Unused ports create easy entry points for unauthorized devices. Access-port protections can also stop accidental loops, rogue DHCP servers, and broadcast floods.

  1. Open Port Management > Port Settings, or the matching port-configuration page on your model.
  1. Disable every unused physical port.
  1. Place unused ports in an isolated VLAN if your switch’s policy requires them to remain enabled.
  1. Enable port security on user-facing access ports.
  1. Set a reasonable MAC-address limit. One address fits a dedicated workstation, while a desk with an IP phone and computer may require two.
  1. Enable BPDU Guard on access ports that must never connect to another switch.
  1. Configure storm control to limit disruptive broadcast or multicast traffic.
  1. Enable DHCP snooping if the switch supports it, then mark only legitimate DHCP uplinks as trusted.
  1. Enable Dynamic ARP Inspection and IP Source Guard where supported and compatible with your network design.

Test these protections on one port first. Incorrect DHCP snooping or ARP inspection settings can block valid clients.

  1. Send switch events to a syslog server if you maintain one.
  1. Back up the configuration through SCP or SFTP instead of unencrypted FTP or TFTP when the model supports secure transfers.
  1. On an SG300, open Administration > File Management > Copy/Save Configuration.
  1. Select the running configuration as the source and startup configuration as the destination.
  1. Click Apply.
Cisco SG300 Administration > File Management > Copy/Save Configuration page with Running Configuration selected as the source and Startup Configuration selected as the destination
  1. Reboot the switch and confirm that your administrator account, management VLAN, secure services, and port settings remain active.

The saved startup configuration should match the running configuration. Repeat the save operation after every approved change; otherwise, the switch can discard unsaved settings during a restart or power failure.

SG300 and Current Cisco Switches

The SG300 remains usable in a home lab or low-risk network, but its age matters. If it no longer receives firmware for a security issue affecting your setup, replacement is safer than adding workarounds around unsupported code.

Catalyst 1300 is the current family to consider for a new small-business deployment. Menu labels differ across SG300, CBS350, and Catalyst firmware, but the setup goals remain consistent: replace factory credentials, use encrypted management, isolate the management interface, protect access ports, and keep recoverable configuration backups.

Cisco Business Dashboard can manage supported switches from one place. Direct switch administration is still useful for initial access and recovery, while a dashboard reduces repetitive work across several devices.

When the Switch Still Isn’t Secure or Reachable

Use the console connection if changing an address or VLAN cuts off web and SSH access. For repeated crashes, rejected firmware, corrupted configuration files, or unexplained port failures, check the model’s Cisco support status and replace unsupported hardware rather than exposing it to an active business network.

Conclusion

Fix #1, replacing the factory administrator account, removes the most immediate risk, but Fix #5 solves the common problem of losing changes after a reboot. If the switch can’t run current firmware or begins dropping links across several known-good Ethernet cables, treat that as a hardware or lifecycle problem rather than another configuration mistake.