Setting Cisco Passwords and Password Security

Router(config)#enable password cisco

Sets the enable password to cisco

Router(config)#enable secret class

Sets the enable secret password to class

CAUTION: The enable secret password is encrypted by default. The enable password is not. For this reason, recommended practice is that you never use the enable password. Use the enable secret password only in a router configuration.

CAUTION: You should not set both the enable password and the enable secret password to the same password. Although Cisco IOS will warn you to change your enable secret password, it will accept the same password. Doing do defeats the use of the encryption feature of the enable secret password.

Router(config)#line console 0

Enters console line configuration mode

Router(config-line)#password darktower

Sets the console mode password to darktower

Router(config-line)#login

Enables password checking at login

Router(config)#line vty 0 4

Enters line vty mode for all five vty lines

Router(config-line)#password iscwguide

Sets vty password to iscwguide

Router(config-line)#login

Enables password

checking at login

Router(config)#line aux 0

Enters auxiliary line mode

Router(config-line)#password backdoor

Sets console mode

password to backdoor

Router(config-line)#login

Enables password

checking at login

Router(config)#service password-encryption

Applies a weak encryption

to passwords

NOTE: The service

password-encryption

command uses a Cisco

proprietary algorithm

based on the Vigenere

cipher (as indicated

by the number 7

when viewing the

configuration). This

is considered to be

a relatively weak

algorithm, and can

be cracked easily.

Therefore it is

imperative to use

other methods to

secure your routers

than just password

encryption.

Router(config)#no service password-encryption

Turns off password encryption

NOTE: If you use the service password-encryption command to encrypt your passwords, and then turn password encryption off with the no service password-encryption command, your passwords will remain encrypted; new passwords will be unencrypted, except for the enable secret password, which is always encrypted with the MD5 algorithm.

Router(config)#security passwords min-length 10

Sets a requirement for all user/enable passwords to be a minimum of ten characters in length

NOTE: This command was introduced in Cisco IOS Release 12.3(1). Range is from 0 to 16 characters. Existing router passwords are not affected by this command. It is highly recommended to set a minimum password length of at least ten characters.

Router(config)#username roland password darktower

Creates a locally stored password of darktower for the username roland. The password is unencrypted but can be encrypted with the service password-encryption command.

Router(config)#username roland password 7 darktower

Creates a locally stored password of darktower for the username roland. The password is encrypted with the weak Vigenere algorithm.

Router(config)#username roland secret 0 darktower

Enables enhanced username password security that uses MD5 hashing on the plaintext password darktower

Router(config)#username roland secret 5 $1$ExxV$YMPap5SrXimAKcWilh2Sp1

Enables enhanced username password security that uses a previously encrypted MD5 secret

NOTE: MD5 encryption is considered to be a strong encryption method and is therefore not retrievable. You cannot use MD5 encryption with protocols that require plaintext passwords, such as CHAP.

94 Securing ROMMON

Securing ROMMON

Router(config)#no service password-recovery

Disables password-

recovery capability at

the system console

NOTE: This feature is

not available on all

platforms. Use Cisco

Feature Navigator on

Cisco.com to ensure that

it is available on your

platform.

CAUTION: Using the no service password-recovery command prevents all access to ROMMON. You cannot perform a password recovery with the Break sequence to enter ROMMON.

A valid Cisco IOS image should be in flash memory before this command is entered. If you do not have a valid image in flash, you will not be able to use the ROMMON> xmodem command to load a new flash image.

NOTE: To recover a device once the no service password-recovery command has been entered, press the Break key within 5 seconds after the image decompresses during the boot. You are prompted to confirm the Break key action. When you confirm the action, the startup configuration is erased, the password-recovery procedure is enabled, and the router boots with the factory default configuration.

If you do not confirm the Break key action, the router boots normally with the No Service Password-Recovery feature enabled.

Continue reading here: Setting a Login Failure Rate

Was this article helpful?

0 -1

Responses

  • Dorotea
    Which password is encrypted with the enable secret command?
    9 months ago
  • lucie
    Are previous password affected by password restrictions cisco?
    1 year ago