Cisco AS5300-96VOIP-A Software Configuration Manual page 111

Universal access server
Table of Contents

Advertisement

If you use the enable secret command and specify an encryption type, you must enter the
Caution
encrypted version of a specific password. Do not enter the cleartext version of the password after specifying
an encryption type. You must comply with the following procedure when you specify an encryption type or
you will be locked irretrievably out of privileged EXEC (enable) mode. The only way to regain access to
privileged EXEC mode will be to erase the contents of NVRAM, erase your entire configuration, and
reconfigure the access server.
To enter an encryption type with the enable secret command, follow the steps listed in Table 4-2.
Table 4-2
Entering an Encryption Type
Step
Command
1
5300> enable
Password: <password>
5300#
2
5300# configure terminal
Enter configuration commands, one per line. End
with CNTL/Z.
5300(config)#
3
5300(config)# enable secret guessme
4
5300(config-if)# Ctrl-Z
5300#
%SYS-5-CONFIG_I: Configured from console by
console
5300#
5
5300# show running-config
Building configuration...
Current configuration:
!
version XX.X
.
.
.
enable secret 5 $1$h7dd$VTNs4.BAfQMUU0Lrvw6570
6
5300# configure terminal
Enter configuration commands, one per line. End
with CNTL/Z.
5300(config)#
7
5300(config)# enable secret 5
$1$h7dd$VTNs4.BAfQMUU0Lrvw6570
Securing Access to Privileged EXEC and Configuration Mode
Description
Enter enable mode.
Enter the password.
You have entered enable mode when the
prompt changes to
.
5300#
Enter global configuration mode. You
have entered global configuration mode
when the prompt changes to
5300(config)#.
Enter a secret enable password. This
password provides access to privileged
EXEC mode. Substitute your own enable
secret password instead of using
guessme.
Return to enable mode.
This message is normal and does not
indicate an error.
View the encrypted password. In this
example, the encrypted password
follows "enable secret 5" and is shown as
"$1$h7dd$VTNs4.BAfQMUU0Lrvw
6570."
Re-enter global configuration mode. You
have entered global configuration mode
when the prompt changes to
5300(config)#.
Enter the encryption type (5 is the only
valid encryption type for the
enable secret password). Then copy and
paste in the encrypted version of the
password that was displayed in the
output of the show running-config
command in Step 5.
Access Service Security 4-5

Advertisement

Table of Contents
loading

This manual is also suitable for:

As5300

Table of Contents