Protecting Access to Privileged EXEC Commands
•
•
Protecting Access to Privileged EXEC Commands
A simple way of providing terminal access control in your network is to use passwords and assign
privilege levels. Password protection restricts access to a network or network device. Privilege levels
define what commands users can enter after they have logged into a network device.
For complete syntax and usage information for the commands used in this section, refer to the Cisco IOS
Note
Security Command Reference for Release 12.1.
This section describes how to control access to the configuration file and privileged EXEC commands.
It contains this configuration information:
•
•
•
•
•
•
•
Default Password and Privilege Level Configuration
Table 7-1
Table 7-1
Default Password and Privilege Levels
Feature
Enable password and privilege level
Enable secret password and privilege level
Line password
Catalyst 2950 Desktop Switch Software Configuration Guide
7-2
For an additional layer of security, you can also configure username and password pairs, which are
locally stored on the switch. These pairs are assigned to lines or interfaces and authenticate each
user before that user can access the switch. If you have defined privilege levels, you can also assign
a specific privilege level (with associated rights and privileges) to each username and password pair.
For more information, see the
If you want to use username and password pairs, but you want to store them centrally on a server
instead of locally, you can store them in a database on a security server. Multiple networking devices
can then use the same database to obtain user authentication (and, if necessary, authorization)
information. For more information, see the
page
7-10.
Default Password and Privilege Level Configuration, page 7-2
Setting or Changing a Static Enable Password, page 7-3
Protecting Enable and Enable Secret Passwords with Encryption, page 7-4
Disabling Password Recovery, page 7-5
Setting a Telnet Password for a Terminal Line, page 7-6
Configuring Username and Password Pairs, page 7-7
Configuring Multiple Privilege Levels, page 7-8
shows the default password and privilege level configuration.
Default Setting
No password is defined. The default is level 15 (privileged EXEC level).
The password is not encrypted in the configuration file.
No password is defined. The default is level 15 (privileged EXEC level).
The password is encrypted before it is written to the configuration file.
No password is defined.
"Configuring Username and Password Pairs" section on page
"Controlling Switch Access with TACACS+" section on
Chapter 7
Administering the Switch
7-7.
78-14982-01