Preventing Unauthorized Access 19
CHAPTER 4
Controlling Switch Access with Passwords and Privilege Levels 21
Finding Feature Information 21
Restrictions for Controlling Switch Access with Passwords and Privileges 21
Information About Passwords and Privilege Levels 22
Default Password and Privilege Level Configuration 22
Additional Password Security 22
Password Recovery 23
Terminal Line Telnet Configuration 23
Username and Password Pairs 23
Privilege Levels 24
How to Control Switch Access with Passwords and Privilege Levels 24
Setting or Changing a Static Enable Password 24
Protecting Enable and Enable Secret Passwords with Encryption 25
Disabling Password Recovery 27
Setting a Telnet Password for a Terminal Line 28
Configuring Username and Password Pairs 30
Setting the Privilege Level for a Command 31
Changing the Default Privilege Level for Lines 32
Logging into and Exiting a Privilege Level 33
Monitoring Switch Access 34
Configuration Examples for Setting Passwords and Privilege Levels 35
Example: Setting or Changing a Static Enable Password 35
Example: Protecting Enable and Enable Secret Passwords with Encryption 35
Example: Setting a Telnet Password for a Terminal Line 35
Example: Setting the Privilege Level for a Command 35
CHAPTER 5
Configuring TACACS+ 37
Finding Feature Information 37
Prerequisites for Controlling Switch Access with Terminal Access Controller Access Control
System Plus (TACACS+) 37
Information About TACACS+ 39
TACACS+ and Switch Access 39
TACACS+ Overview 39
Catalyst 2960-XR Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX1
iv OL-29434-01
Contents