7-5
Catalyst2950 Desktop Switch Software Configuration Guide
78-11380-05
Chapter7 Administering the Swi tc h Protecting Access to Privileged EXEC Comman d s
If both the enable and enable secret passwords are defined, users must enter the enable secret password.
Use the level keyword to define a password for a specific privilege level. After you specify the level and
set a password, give the password only to users who need to have access at this level. Use the privilege
level global configuration command to specify commands accessible at various levels. For more
information, see the Configuring Multiple Privilege Levels section on page7-7.
If you enable password encryption, it applies to all passwords includi ng u ser na me p asswords,
authentication key passwords, the privileged command password, and console and virtual terminal line
passwords.
To remove a password and level, use the no enable password [level level] or no enable secret [level
level] global configuration command. To disable password encryption, use the no service
password-encryption global configuration command.
This example shows how to configure the encrypted password $1$FaD0$Xyti5Rkls3LoyxzS8 for
privilege level 2:
Switch(config)# enable secret level 2 5 $1$FaD0$Xyti5Rkls3LoyxzS8
Setting a Telnet Password for a Terminal Line
When you power-up your switch for the first time, an automatic setup p rog ram run s t o as sig n IP
information and to create a default configuration for continued use. The setup program a lso prompts you
to configure your switch for Telnet access through a password. If you neglected to co nfigure thi s
password during the setup program, you can configure it now through the command-line inte rface (CLI).
Beginning in privileged EXEC mode, follow these steps to configure your switch for Telnet access:
Command Purpose
Step1 Attach a PC or workstation with emulation software to the switch console
port.
The default data characteristics of the console port are 9600 , 8, 1, n o
parity. You might need to press the Return key several times to see the
command-line prompt.
Step2 enable password password Enter privileged EXEC mode.
Step3 configure terminal Enter global configuration mode.
Step4 line vty 0 15 Configure the number of Telnet sessions (lines), and enter line
configuration mode.
There are 16 possible sessions on a command-capable switch. The 0
and 15 mean that you are configuring all 16 possible Telnet sessions.
Step5 password password Enter a Telnet password for the line or lines.
For password, specify a string from 1 to 25 alphanumeric char acters. The
string cannot start with a number, is case sensitive, and allows spaces but
ignores leading spaces. By default, no password is defined.
Step6 end Return to privileged EXEC mode.
Step7 show running-config Verify your entries.
The password is listed under the command line vty 0 15.
Step8 copy running-config startup-config (Optional) Save your entries in the configuration file.