Just plugged in a new Cisco switch? Out of the box, its management page is protected only by a default username and password that anyone can look up online, leaving its settings open to anyone on your network. Do these five things before you connect any other devices to it.
Fix #1: Replace the default administrator account
Some Cisco switches request an address from your router through DHCP. Others use a static address such as 192.168.1.254.
- Connect your computer directly to the switch with an Ethernet cable.
- Check your routerās DHCP client list for the switchās address.
- If the switch doesnāt appear, open Settings > Network & internet > Ethernet on your Windows PC.
- Select the connected Ethernet network, click Edit beside IP assignment, and choose Manual.
- Enable IPv4, then enter an unused address between
192.168.1.2and192.168.1.253.
- Enter
255.255.255.0as the subnet mask, save the settings, and browse tohttps://192.168.1.254.
A certificate warning is expected because a new switch normally uses a self-signed certificate. Confirm that youāre connected directly to the switch before accepting the warning.
If neither method works, connect through the console port with a USB-to-serial adapter and use the setup instructions for your exact model.
- Sign in with the credentials printed in the switch documentation or on its label. Older models commonly use
ciscofor both fields, while some useadmin.
- On an SG300, open Administration > User Accounts.
- Create a new account with a unique username, a strong password, and Read/Write Management Access (15).
Current Cisco Business and Catalyst 1300 menus vary by firmware. Look under Administration, System, or Users for the local account settings.
- Sign out, then sign in with the new administrator account.
- Remove or disable the factory account after confirming the new login works.
- Enable the switchās password-complexity and failed-login lockout options where available.
You should finish with one working administrator account that doesnāt use the factory credentials. Store the password in a password manager rather than relying on the switchās recovery service.
Fix #2: Enable encrypted management access
Telnet and HTTP send management traffic without adequate encryption. Use SSH for command-line access and HTTPS when you need the web interface.
- Open the switchās management-services page.
- On an SG300, go to Security > TCP/UDP Services and enable SSH Service.
- Enable HTTPS management.
- Disable Telnet.
- Disable HTTP after confirming that HTTPS works.
- Open an SSH client such as PuTTY and connect to the switchās management address.
- Sign in with the administrator account created in Fix #1.
The SSH session should display the switch prompt without exposing your password as plain text. If you prefer command-line administration, follow the existing instructions for enabling SSH access on an SG300 switch.
For tighter authentication, you can also enable SSH public-key authentication on an SG300 switch. Small businesses with several switches should consider RADIUS or TACACS+ so administrator access can be managed centrally.
Iād disable the web interface only after testing SSH from a second session. Closing your only working management path turns a routine setup into a console-cable recovery job.
Fix #3: Move management traffic off VLAN 1
VLAN 1 includes every port on many factory configurations. A dedicated management VLAN addresses this by separating the switch interface from regular computers, guest devices, and wireless clients.
- Choose an unused VLAN ID and management subnet. The example below uses VLAN
15and192.168.50.0/24.
- Create VLAN
15through the switchās VLAN-management page.
- Name it Management.
- Open the IPv4 interface settings. On an SG300, the path is Administration > Management Interface > IPv4 Interface.
- Select VLAN
15as the management VLAN.
- Assign the switch an unused static address such as
192.168.50.2with subnet mask255.255.255.0.
- Enter the router interface for that VLAN, such as
192.168.50.1, as the default gateway.
- Configure one switch port as an access port in VLAN
15.
- Connect your administration PC to that port.
- Give the PC an address in the same subnet, then open the switchās new management address.
- Confirm that HTTPS and SSH work at
192.168.50.2.
- Restrict access to the management subnet with an access control list if your switch and router support it.
- Block guest Wi-Fi and ordinary user VLANs from reaching the switchās management address.
You should be able to manage the switch from the designated administrator port or subnet, while devices on other VLANs receive no response.
Donāt remove the old management address until the new one works. A wrong VLAN assignment can cut off both the web interface and SSH, forcing you to recover through the console port.
Fix #4: Update the firmware
Firmware updates correct security flaws and switch bugs. Download the package for the exact model and hardware revision; firmware intended for a similar-looking switch can fail validation or prevent a clean upgrade.
- Record the full model number and current firmware version from the switchās status page.
- Find the modelās support page on Ciscoās website.
- Download the newest firmware Cisco provides for that exact model and revision.
- Read the release notes for required intermediate versions, boot-code updates, and configuration warnings.
- Back up the current configuration before uploading anything.
- Open Administration > File Management or the equivalent firmware-management page for your model.
- Upload the firmware file to the inactive image slot when the switch provides two image slots.
- Select the uploaded image as the next active image.
- Reboot the switch during a maintenance window.
- Sign back in and verify the running firmware version.
The switch should report the new version and retain its VLAN, account, and port settings. If it starts from the previous image, check which image is marked active and review the switch log for an installation error.
The SG300 is legacy hardware, and the SG350 is no longer sold. CBS350 models also reached end-of-sale, with Catalyst 1300 switches replacing many models in that range. Cisco still publishes model-specific files and lifecycle details, so check support status before putting an older managed switch on an important network.
Fix #5: Harden ports and save the configuration
Unused ports create easy entry points for unauthorized devices. Access-port protections can also stop accidental loops, rogue DHCP servers, and broadcast floods.
- Open Port Management > Port Settings, or the matching port-configuration page on your model.
- Disable every unused physical port.
- Place unused ports in an isolated VLAN if your switchās policy requires them to remain enabled.
- Enable port security on user-facing access ports.
- Set a reasonable MAC-address limit. One address fits a dedicated workstation, while a desk with an IP phone and computer may require two.
- Enable BPDU Guard on access ports that must never connect to another switch.
- Configure storm control to limit disruptive broadcast or multicast traffic.
- Enable DHCP snooping if the switch supports it, then mark only legitimate DHCP uplinks as trusted.
- Enable Dynamic ARP Inspection and IP Source Guard where supported and compatible with your network design.
Test these protections on one port first. Incorrect DHCP snooping or ARP inspection settings can block valid clients.
- Send switch events to a syslog server if you maintain one.
- Back up the configuration through SCP or SFTP instead of unencrypted FTP or TFTP when the model supports secure transfers.
- On an SG300, open Administration > File Management > Copy/Save Configuration.
- Select the running configuration as the source and startup configuration as the destination.
- Click Apply.
- Reboot the switch and confirm that your administrator account, management VLAN, secure services, and port settings remain active.
The saved startup configuration should match the running configuration. Repeat the save operation after every approved change; otherwise, the switch can discard unsaved settings during a restart or power failure.
SG300 and Current Cisco Switches
The SG300 remains usable in a home lab or low-risk network, but its age matters. If it no longer receives firmware for a security issue affecting your setup, replacement is safer than adding workarounds around unsupported code.
Catalyst 1300 is the current family to consider for a new small-business deployment. Menu labels differ across SG300, CBS350, and Catalyst firmware, but the setup goals remain consistent: replace factory credentials, use encrypted management, isolate the management interface, protect access ports, and keep recoverable configuration backups.
Cisco Business Dashboard can manage supported switches from one place. Direct switch administration is still useful for initial access and recovery, while a dashboard reduces repetitive work across several devices.
When the Switch Still Isnāt Secure or Reachable
Use the console connection if changing an address or VLAN cuts off web and SSH access. For repeated crashes, rejected firmware, corrupted configuration files, or unexplained port failures, check the modelās Cisco support status and replace unsupported hardware rather than exposing it to an active business network.
Conclusion
Fix #1, replacing the factory administrator account, removes the most immediate risk, but Fix #5 solves the common problem of losing changes after a reboot. If the switch canāt run current firmware or begins dropping links across several known-good Ethernet cables, treat that as a hardware or lifecycle problem rather than another configuration mistake.