Securing the Enable Mode of a Router
The first thing you should do when configuring a router is set a password that protects the enable mode (the administrator level) of the router. You can think of the enable mode, also called the privileged EXEC mode, as the superuser level that is allowed to monitor and modify everything in the router. For basic information on navigating to and from enable mode, see Appendix E.
By default, no password is assigned to the enable mode, so you can get to it with a connection to the console port and the enable command:
RTA>enable RTA#
You are not allowed into enable mode, however, when there is no enable password and you are connected to the router with Telnet. The following output is an attempt to initiate enable mode from a Telnet session on a router without an enable password. Notice that the message No password set is displayed and the prompt returns to user liXEC mode as indicated by the > character:
MyRouter>enable % No password set MyRouter>
To set the enable password, use the enable secret global command:
RTAtfconf t
Enter configuration commands, one per line. End with CNTL/Z. RTA(config)tenable secret foolenable where enable secret foo!enabIe sets the enable password in this example to foolenable (the exclamation point was used to make the password harder to guess). Attempts to change from user mode to enable mode now require the enable password:
RTA>en
Password: <Type the password here. Text is not displayed.> RTA0
TIP The enable secret command uses a one-way cryptographic hashing function to store the password securely. Another command, enable password, also sets the enable password but is not recommended because it is less secure.
Cisco IOS supports a total of 16 configurable modes called privilege levels. The idea is that you can configure privilege levels with different allowable commands and with different passwords. Then, based on the passwords people type, they are put into the corresponding level with IOS commands you allow for that level. For more information on privilege levels, consult the Security Configuration Guide IOS manual. By default, a router has two modes: the user FXEC mode (upon login) and the enable mode.
Securing Telnet Access
By default, Cisco routers support five simultaneous Telnet sessions, allowing up to five people to log into the router at the same time. The router treats these sessions as logical interfaces called virtual terminal (or vty) lines.
The router doesn't have any passwords configured on its vty ports by default. Trying to Telnet to the router without vty passwords will be unsuccessful. The router will respond with a message Password required, but none set and immediately terminate the attempt:
myserver#telnet 192.168.1.2 Trying...
Connected to 192.168.1.2. Escape character is ,A]'.
Password required, but none set
Connection closed by remote host.
To enable Telnet sessions to the router, you must at a minimum configure a password on the vty lines—or you can configure vty lines with the no login command and disable password checking entirely (not recommended). The following is an example:
RTA#conf t
Enter configuration commands, one per line. End with CNTL/Z.
RTA(config)#service password encryption
RTA(config)#line vty 0 4
RTA(config-line)#login
RTA(config-line)«password foo! pass
In this configuration:
• The command service password-encryption enables a feature that encrypts passwords in the router so you cannot see them in plaintext when viewing the configuration with the show running-config command.
• The command line vty 0 4 tells the router that you want to simultaneously configure all five of the vty lines numbered 0-4. This changes the prompt to line configuration mode, as indicated by the text config-line.
• The command login enables password checking for vty (Telnet) connections. This should already be enabled by default, but it doesn't hurt to enter the command and ensure password checking is on.
• The last command, password foo!pass, sets the password for the vty lines to foolpass.
NOTE Cisco IOS passwords are case sensitive.
With passwords on the vty lines, you can now Telnet to the router and use the password:
myservertftelnet 192.168.1.2 Trying...
Connected to 192.168.1.2. Escape character is
User Access Verification
Password: <Type the password here. Text is not displayed.> RTA>
TIP If you worry that five active Telnet sessions by other people will prevent you from accessing the router, you can create more vty lines, or you can configure a common password for vty lines 0 through 3- and a different password for vty 4 for "emergency purposes only." Use the line vty 4 command to configure line 4 only. To create more vty lines, simply issue the line vty command with numbers greater than 4. The command line vty 5 9, for example, creates five more vty lines, numbered 5 through 9. Telnet sessions consume vty lines in the order they are numbered, starting with 0.
Additional login options allow the router to check uscrnames and leverage RADIUS and TACACS+ servers. See "Deploying Authentication. Authorization, and Accounting (AAA)," later in this chapter.
Controlling vty Access with Access Lists
If you want to restrict who can Telnet to a router, apply access lists to the logical vty lines that permit only authorized addresses. Here's a partial configuration listing:
access-list 10 permit 192.168.1.0 0.0.0.255 !
line vty 0 4 access-class 10 in
The command access-class 10 in applies access list number 10 to all five vty lines (vty lines 0-4). Only users matching the source criteria 192.168.1.0 0.0.0.255 are allowed to Telnet to the router. See "Controlling Traffic with Access Control Lists" earlier in this chapter for more information on access lists.
Continue reading here: Authentication Authorization and Accounting
Was this article helpful?