EasyManua.ls Logo

Cisco ASR 1000 Series User Manual

Cisco ASR 1000 Series
72 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #28 background imageLoading...
Page #28 background image
Page 28 of 72
Note: Details for the security passwords min-length command can be found in the: [10]
Under Reference Guides Command References Security and VPN See manual
Cisco IOS Security Command Reference: Commands S to Z.
2. Composed of any combination of characters that includes characters for at least 3 of these
four character sets: upper case letters, lower case letters, numerals, and the following
special characters: “!”, “@”, “#”, “$”, “%”, “^”, “&”, “*”, “(“, “)”. Configure the router
to enforce that complexity requirement by using enabling “aaa password restriction”.
Example: router(config)# security passwords min-length 15
Enabling aaa password restriction will also enforce the following restrictions:
1. The new password cannot have any character repeated more than three times
consecutively.
2. The new password cannot be the same as the associated username.
3. The password obtained by capitalization of the username or username reversed is not
accepted.
4. The new password cannot be “cisco”, “ocsic”, or any variant obtained by changing the
capitalization of letters therein, or by substituting “1”, “|”, or “!” for i, or by substituting
“0” for “o”, or substituting “$” for “s”.
Note: The aaa password restriction command can only be used after the aaa new-model
command is configured. [10] Under Reference Guides Command References Security and
VPN See manual Cisco IOS Security Command Reference: Commands A to C.
The following configuration steps are optional, but recommended for good password complexity.
The below items are recommended but are not enforced by the TOE:
1. Does not contain more than three sequential characters, such as abcd
2. Does not contain dictionary words
3. Does not contain common proper names
Administrative passwords, including any “enable” password that may be set for any privilege
level, must be stored in non-plaintext form. To have passwords stored as a SHA-256 hash, use
the “service password-encryption” command in config mode.
router(config)#service password-encryption
Once that service has been enabled, passwords can be entered in plaintext, or has SHA-256 hash
values, and will be stored as SHA-256 hash values in the configuration file when using the
“username” command.
router(config)#username name {password password | password encryption-type encrypted-
password}

Table of Contents

Other manuals for Cisco ASR 1000 Series

Questions and Answers:

Cisco ASR 1000 Series Specifications

General IconGeneral
SeriesASR 1000
CategoryNetwork Router
Operating SystemCisco IOS XE
MemoryUp to 64 GB
Interfaces10 Gigabit Ethernet
Power SupplyAC or DC options
DimensionsVaries by model
EncryptionIPsec, SSL
StorageVaries by model
Operating Temperature32°F to 104°F (0°C to 40°C)
Humidity5% to 95% non-condensing
MTBFVaries by model

Summary

Document Introduction

Introduction to Cisco ASR 1000 Series Common Criteria Guidance

Supported Hardware and Software

Details the specific hardware and software versions compliant with CC evaluation.

Operational Environment

Lists supported external hardware, software, and firmware components for TOE operation.

Excluded Functionality

Identifies functionality not covered or excluded from the TOE's CC evaluation.

Secure Acceptance of the Target of Evaluation (TOE)

Secure Installation and Configuration Procedures

Physical Installation

Guides hardware installation using Cisco ASR 1000 Series Router Hardware Installation Guide.

Initial Setup via Direct Console Connection

Details initial configuration steps via console before network connection.

Network Protocols and Cryptographic Settings

Covers secure network protocols and cryptographic configurations.

Secure Management of the Cisco ASR

User Roles

Explains the different administrator roles and privilege levels on the ASR.

Passwords

Details password complexity requirements and configuration for secure authentication.

Virtual Private Networks (VPN)

Covers the configuration and use of IPsec VPNs for secure communication.

Security Relevant Events and Audit Records

Deleting Audit Records

Explains how privileged administrators can delete audit records using the clear logging command.

Network Services and Protocols Overview

Modes of Operation for the Cisco ASR

Operational Environment Security Measures

Related Documentation and Resources

World Wide Web Documentation

Provides URLs for accessing current Cisco documentation online.

Ordering Documentation

Explains methods for ordering Cisco product documentation.

Obtaining Technical Assistance

Related product manuals