Setting Cisco Passwords and Password Security
|
Router(config)#enable password cisco |
Sets the enable password to cisco |
|
Router(config)#enable secret class |
Sets the enable secret password to class CAUTION: The enable secret password is encrypted by default. The enable password is not. For this reason, recommended practice is that you never use the enable password. Use the enable secret password only in a router configuration. CAUTION: You should not set both the enable password and the enable secret password to the same password. Although Cisco IOS will warn you to change your enable secret password, it will accept the same password. Doing do defeats the use of the encryption feature of the enable secret password. |
|
Router(config)#line console 0 |
Enters console line configuration mode |
|
Router(config-line)#password darktower |
Sets the console mode password to darktower |
|
Router(config-line)#login |
Enables password checking at login |
|
Router(config)#line vty 0 4 |
Enters line vty mode for all five vty lines |
|
Router(config-line)#password iscwguide |
Sets vty password to iscwguide |
|
Router(config-line)#login |
Enables password |
|
checking at login |
|
|
Router(config)#line aux 0 |
Enters auxiliary line mode |
|
Router(config-line)#password backdoor |
Sets console mode |
|
password to backdoor |
|
|
Router(config-line)#login |
Enables password |
|
checking at login |
|
|
Router(config)#service password-encryption |
Applies a weak encryption |
|
to passwords |
|
|
NOTE: The service |
|
|
password-encryption |
|
|
command uses a Cisco |
|
|
proprietary algorithm |
|
|
based on the Vigenere |
|
|
cipher (as indicated |
|
|
by the number 7 |
|
|
when viewing the |
|
|
configuration). This |
|
|
is considered to be |
|
|
a relatively weak |
|
|
algorithm, and can |
|
|
be cracked easily. |
|
|
Therefore it is |
|
|
imperative to use |
|
|
other methods to |
|
|
secure your routers |
|
|
than just password |
|
|
encryption. |
|
Router(config)#no service password-encryption |
Turns off password encryption NOTE: If you use the service password-encryption command to encrypt your passwords, and then turn password encryption off with the no service password-encryption command, your passwords will remain encrypted; new passwords will be unencrypted, except for the enable secret password, which is always encrypted with the MD5 algorithm. |
|
Router(config)#security passwords min-length 10 |
Sets a requirement for all user/enable passwords to be a minimum of ten characters in length NOTE: This command was introduced in Cisco IOS Release 12.3(1). Range is from 0 to 16 characters. Existing router passwords are not affected by this command. It is highly recommended to set a minimum password length of at least ten characters. |
|
Router(config)#username roland password darktower |
Creates a locally stored password of darktower for the username roland. The password is unencrypted but can be encrypted with the service password-encryption command. |
|
Router(config)#username roland password 7 darktower |
Creates a locally stored password of darktower for the username roland. The password is encrypted with the weak Vigenere algorithm. |
|
Router(config)#username roland secret 0 darktower |
Enables enhanced username password security that uses MD5 hashing on the plaintext password darktower |
|
Router(config)#username roland secret 5 $1$ExxV$YMPap5SrXimAKcWilh2Sp1 |
Enables enhanced username password security that uses a previously encrypted MD5 secret NOTE: MD5 encryption is considered to be a strong encryption method and is therefore not retrievable. You cannot use MD5 encryption with protocols that require plaintext passwords, such as CHAP. |
|
94 Securing ROMMON |
|
|
Securing ROMMON |
|
|
Router(config)#no service password-recovery |
Disables password- |
|
recovery capability at |
|
|
the system console |
|
|
NOTE: This feature is |
|
|
not available on all |
|
|
platforms. Use Cisco |
|
|
Feature Navigator on |
|
|
Cisco.com to ensure that |
|
|
it is available on your |
|
|
platform. |
|
CAUTION: Using the no service password-recovery command prevents all access to ROMMON. You cannot perform a password recovery with the Break sequence to enter ROMMON.
A valid Cisco IOS image should be in flash memory before this command is entered. If you do not have a valid image in flash, you will not be able to use the ROMMON> xmodem command to load a new flash image.
NOTE: To recover a device once the no service password-recovery command has been entered, press the Break key within 5 seconds after the image decompresses during the boot. You are prompted to confirm the Break key action. When you confirm the action, the startup configuration is erased, the password-recovery procedure is enabled, and the router boots with the factory default configuration.
If you do not confirm the Break key action, the router boots normally with the No Service Password-Recovery feature enabled.
Continue reading here: Setting a Login Failure Rate
Was this article helpful?
Responses
-
Dorotea9 months ago
- Reply
-
lucie1 year ago
- Reply