Cisco CISCO876-SEC-I-K9 Configuration Guide - Page 161

Enable Secret Passwords and Enable Passwords, Entering Global Configuration Mode

Page 161 highlights

Appendix A Cisco IOS Software Basic Skills Enable Secret Passwords and Enable Passwords Enable Secret Passwords and Enable Passwords By default, the router ships without password protection. Because many privileged EXEC commands are used to set operating parameters, you should password-protect these commands to prevent unauthorized use. You can use two commands to do this: • enable secret password-A very secure, encrypted password • enable password-A less secure, unencrypted local password Both the enable and enable secret passwords control access to various privilege levels (0 to 15). The enable password is intended for local use and is thus unencrypted. The enable secret password is intended for network use; that is, in environments where the password crosses the network or is stored on a TFTP server. You must enter an enable secret or enable password with a privilege level of 1 to gain access to privileged EXEC mode commands. For maximum security, the passwords should be different. If you enter the same password for both during the setup process, your router accepts the passwords, but warns you that they should be different. An enable secret password can contain from 1 to 25 uppercase and lowercase alphanumeric characters. An enable password can contain any number of uppercase and lowercase alphanumeric characters. In both cases, a number cannot be the first character. Spaces are also valid password characters; for example, two words is a valid password. Leading spaces are ignored; trailing spaces are recognized. Entering Global Configuration Mode To make any configuration changes to your router, you must be in global configuration mode. This section describes how to enter global configuration mode while using a terminal or PC that is connected to your router console port. To enter global configuration mode, follow these steps: Step 1 Step 2 Step 3 After your router boots up, enter the enable or enable secret command: Router> enable If you have configured your router with an enable password, enter it when you are prompted. The enable password does not appear on the screen when you enter it. This example shows how to enter privileged EXEC mode: Password: enable_password Router# Privileged EXEC mode is indicated by the # in the prompt. You can now make changes to your router configuration. Enter the configure terminal command to enter global configuration mode: Router# configure terminal Router(config)# You can now make changes to your router configuration. OL-5332-01 Cisco 850 Series and Cisco 870 Series Access Routers Software Configuration Guide A-5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196

A-5
Cisco 850 Series and Cisco 870 Series Access Routers Software Configuration Guide
OL-5332-01
Appendix A
Cisco IOS Software Basic Skills
Enable Secret Passwords and Enable Passwords
Enable Secret Passwords and Enable Passwords
By default, the router ships without password protection. Because many privileged EXEC commands are
used to set operating parameters, you should password-protect these commands to prevent unauthorized
use.
You can use two commands to do this:
enable secret
password
—A very secure, encrypted password
enable
password
—A less secure, unencrypted local password
Both the
enable
and
enable secret
passwords control access to various privilege levels (0 to 15). The
enable
password is intended for local use and is thus unencrypted. The
enable secret
password is
intended for network use; that is, in environments where the password crosses the network or is stored
on a TFTP server. You must enter an
enable secret
or
enable
password with a privilege level of 1 to gain
access to privileged EXEC mode commands.
For maximum security, the passwords should be different. If you enter the same password for both during
the setup process, your router accepts the passwords, but warns you that they should be different.
An
enable secret
password can contain from 1 to 25 uppercase and lowercase alphanumeric characters.
An
enable
password can contain any number of uppercase and lowercase alphanumeric characters. In
both cases, a number cannot be the first character. Spaces are also valid password characters; for
example,
two words
is a valid password. Leading spaces are ignored; trailing spaces are recognized.
Entering Global Configuration Mode
To make any configuration changes to your router, you must be in global configuration mode. This
section describes how to enter global configuration mode while using a terminal or PC that is connected
to your router console port.
To enter global configuration mode, follow these steps:
Step 1
After your router boots up, enter the
enable
or
enable secret
command:
Router>
enable
Step 2
If you have configured your router with an enable password, enter it when you are prompted.
The enable password does not appear on the screen when you enter it. This example shows how to enter
privileged EXEC mode:
Password:
enable_password
Router#
Privileged EXEC mode is indicated by the # in the prompt. You can now make changes to your router
configuration.
Step 3
Enter the
configure terminal
command to enter global configuration mode:
Router#
configure terminal
Router(config)#
You can now make changes to your router configuration.