3-16
Software Configuration Guide—Release 12.2(25)SG
OL-7659-03
Chapter3 Configuring the Switch for the First Time
Controlling Access to Privileged EXEC Commands
Encryption occurs when the current configuration is written or when a pa ssword is configured. Password
encryption is applied to all passwords, including authentication key passwords, the privileged command
password, console and virtual terminal line access passwords, and Border Gateway Protocol (BGP)
neighbor passwords. The service password-encryption command keeps unauthorized individuals from
viewing your password in your configuration file.
Caution The service password-encryption command does not provide a high level of network security. If you
use this command, you should also take additional network secu rity measures.
Although you cannot recover a lost encrypted password (that is, you c annot get the original password
back), you can regain control of the switch after having lost or forgotten the encrypted password. See
the “Recovering a Lost Enable Password” section on page3-18 for more informa tion.
For information on how to display the password or access level configuration, see the “Displaying the
Password, Access Level, and Privilege Level Configuration” section on page 3-17.
Configuring Multiple Privilege Levels
By default, Cisco IOS software has two modes of password security: user EX EC mode and privileged
EXEC mode. You can configure up to 16 hierarchical levels of commands for each mode. By configuring
multiple passwords, you can allow different sets of users to have access to spec ified commands.
For example, if you want many users to have access to the clear line command, you can assign it level 2
security and distribute the level 2 password fairly widely. If you want more restricted access to the
configure command, you can assign it level 3 security and distribute that password to fewer users.
The procedures in the following sections describe how to configure additional levels of security:
Setting the Privilege Level for a Command, page 3-16
Changing the Default Privilege Level for Lines, page 3-17
Logging In to a Privilege Level, page 3-17
Exiting a Privilege Level, page 3-17
Displaying the Password, Access Level, and Privilege Level Configuration, page 3-17

Setting the Privilege Level for a Command

To set the privilege level for a command, perform this task:
For information on how to display the password or access level configuration, see the “Displaying the
Password, Access Level, and Privilege Level Configuration” section on page 3-17.
Command Purpose
Step1 Switch(config)# privilege
mode
level
level
command
Sets the privilege level for a command.
Step2 Switch(config)# enable password level
level
[
encryption-type
]
password
Specifies the enable password for a privilege level.