Protecting Enable And Enable Secret Passwords With Encryption - Allen-Bradley Stratix 5100 User Manual

Wireless access point/workgroup bridge
Hide thumbs Also See for Stratix 5100:
Table of Contents

Advertisement

Chapter 6
Administering the WAP Access
Protecting Enable and
Enable Secret Passwords
with Encryption
204
To provide an additional layer of security, particularly for passwords that cross the
network or that are stored on a Trivial File Transfer Protocol (TFTP) server, you
can use either the
enable password
configuration commands. Both commands accomplish the same thing; that is,
you can establish an encrypted password that users must enter to access privileged
EXEC mode (the default) or any privilege level you specify.
We recommend that you use the
improved encryption algorithm.
If you configure the
enable secret
command; the two commands cannot be in effect
enable password
simultaneously.
Beginning in privileged EXEC mode, follow these steps to configure encryption
for enable and enable secret passwords:
1. Enter global configuration mode.
configure terminal
2. Define a new password or change an existing password for access to
privileged EXEC mode.
enable password [level level] {password |
encryption-type encrypted-password}
or
enable secret [level level] {password | encryption-
type encrypted-password}
Define a secret password, that is saved by using a nonreversible encryption
method.
• (Optional) For
EXEC mode privileges. The default level is 15 (privileged EXEC mode
privileges).
• For
password
The string cannot start with a number, is case sensitive, and allows
spaces but ignores leading spaces. By default, no password is defined.
• (Optional) For
proprietary encryption algorithm, is available. If you specify an
encryption type, you must provide an encrypted password—an
encrypted password you copy from another access point configuration.
TIP
3. (Optional) Encrypt the password when the password is defined or when
the configuration is written.
service password-encryption
Rockwell Automation Publication 1783-UM006A-EN-P - May 2014
or
enable secret
enable secret
command, it takes precedence over the
, the range is from 0 to 15. Level 1 is normal user
level
, specify a string from 1...25 alphanumeric characters.
, type only a 5, a Cisco
encryption-type
If you specify an encryption type and then enter a clear text password,
you can not re-enter privileged EXEC mode. You cannot recover a lost
encrypted password by any method.
global
command because it uses an

Advertisement

Table of Contents
loading

This manual is also suitable for:

1783-wapak91783-wapek91783-wapck91783-wapzk9

Table of Contents