Cisco WS-C2960S-24PD-L Software Guide - Page 139

Assigning Passwords and Privilege Levels

Page 139 highlights

Chapter 6 Configuring the System Assigning Passwords and Privilege Levels Assigning Passwords and Privilege Levels You can assign the password of your switch in these ways: • Using the setup program, as described in the release notes (http://www.cisco.com/univercd/cc/td/doc/product/lan/c2900xl/index.htm) • Manually assigning a password, as described in this section Note You can change a password only by using the CLI. Your connection with the switch ends when you change the enable secret password. You will then need to reopen the session with the new password. Because many privileged EXEC commands are used to set operating parameters, you should password-protect these commands to prevent unauthorized use. Catalyst 2900 XL and Catalyst 3500 XL switches have two commands for setting passwords: • enable secret password (a very secure, encrypted password) • enable password password (a less secure, unencrypted password) You must enter one of these passwords to gain access to privileged EXEC mode. We recommend that you use the enable secret password. Note • When set, the enable secret password takes precedence, and the enable password serves no purpose. • You need an enable secret password with a privilege level 15 to access CMS. You must also use this password if you configure the Terminal Access Controller Access Control System Plus (TACACS+) protocol from the CLI so that all your HTTP connections are authenticated through the TACACS+ server. The Telnet password must be an enable secret password. • CMS provides two levels of access to the configuration options: read-write access and read-only access. Privilege levels 0 to 15 are supported. - Privilege level 15 provides you with read-write access to CMS. - Privilege levels 1 to 14 provide you with read-only access to CMS. Any options in the CMS windows, menu bar, toolbar, and popup menus that change the switch or cluster configuration are not shown in read-only mode. - Privilege level 0 denies access to CMS. For information about passwords and CMS, see the "Access Modes in CMS" section on page 2-33. • The password of a command switch is inherited by the switches that join the switch cluster. For information about managing passwords in switch clusters, see the "Passwords" section on page 5-16. Both types of passwords can contain from 1 to 25 uppercase and lowercase alphanumeric characters, and both can start with a number. Spaces are also valid password characters; for example, two words is a valid password. Leading spaces are ignored; trailing spaces are recognized. The password is case sensitive. If you enter the enable secret command, the text is encrypted before it is written to the config.text file, and it is unreadable. If you enter the enable password command, the text is written as entered to the config.text file where you can read it. To remove a password, use the no version of the commands: no enable secret or no enable password. For CLI procedures, refer to the Cisco IOS Release 12.0 documentation on Cisco.com for additional information and CLI procedures. 78-6511-08 Catalyst 2900 Series XL and Catalyst 3500 Series XL Software Configuration Guide 6-11

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368

6-11
Catalyst 2900 Series XL and Catalyst 3500 Series XL Software Configuration Guide
78-6511-08
Chapter 6
Configuring the System
Assigning Passwords and Privilege Levels
Assigning Passwords and Privilege Levels
You can assign the password of your switch in these ways:
Using the setup program, as described in the release notes
(
)
Manually assigning a password, as described in this section
Note
You can change a password only by using the CLI. Your connection with the switch ends when you
change the enable secret password. You will then need to reopen the session with the new password.
Because many privileged EXEC commands are used to set operating parameters, you should
password-protect these commands to prevent unauthorized use. Catalyst
2900
XL and Catalyst
3500 XL
switches have two commands for setting passwords:
enable secret
password
(a very secure, encrypted password)
enable password
password
(a less secure, unencrypted password)
You must enter one of these passwords to gain access to privileged EXEC mode. We recommend that
you use the enable secret
password.
Note
When set, the enable secret password takes precedence, and the enable password serves no purpose.
You need an enable secret password with a privilege level 15 to access CMS. You must also use this
password if you configure the Terminal Access Controller Access Control System Plus (TACACS+)
protocol from the CLI so that all your HTTP connections are authenticated through the TACACS+
server. The Telnet password must be an enable secret password.
CMS provides two levels of access to the configuration options: read-write access and read-only
access. Privilege levels 0 to 15 are supported.
Privilege level 15 provides you with read-write access to CMS.
Privilege levels 1 to 14 provide you with read-only access to CMS. Any options in the CMS
windows, menu bar, toolbar, and popup menus that change the switch or cluster configuration
are not shown in read-only mode.
Privilege level 0 denies access to CMS.
For information about passwords and CMS, see the
“Access Modes in CMS” section on page 2-33
.
The password of a command switch is inherited by the switches that join the switch cluster. For
information about managing passwords in switch clusters, see the
“Passwords” section on
page 5-16
.
Both types of passwords can contain from 1
to
25 uppercase and lowercase alphanumeric characters, and
both can start with a number. Spaces are also valid password characters; for example, two words is a
valid password. Leading spaces are ignored; trailing spaces are recognized. The password is case
sensitive.
If you enter the
enable secret
command, the text is encrypted before it is written to the config.text file,
and it is unreadable. If you enter the
enable password
command, the text is written as entered to the
config.text file where you can read it. To remove a password, use the
no
version of the commands:
no
enable secret
or
no enable password
. For CLI procedures, refer to the Cisco IOS Release 12.0
documentation on Cisco.com for additional information and CLI procedures.