![]() |
Cisco
|
|||
| Home > SMB Support Assistant Configuration Overview > Password Security | ||||||||
IntroductionThis document describes Cisco's recommendations for how to implement a strong password policy on Cisco devices that require a password. RequirementsYou do not need to provide any additional equipment to complete this procedure. Strong PasswordsPassword-based authentication systems that do not use strong passwords are vulnerable to dictionary attacks. A policy that requires users to select strong passwords is one of the most effective means to mitigate against potential dictionary attacks. A strong password policy should expire user passwords periodically, such as every three months. Give users advanced notice to change passwords before they expire. Some characteristics of strong passwords include:
Password-Generation UtilitiesPassword generation utilities are tools that help administrators and users generate strong passwords. These tools can be used by companies to enforce a password policy. In general, it is better if users select strong passwords with guidelines such as those described in this document. When users generate their own passwords, they are less likely to write the password down or document it anywhere but in their memory. Password AuditsA strong password policy should periodically check for weak passwords. A common way to check for password weakness is to use a password-cracker utility. Password audits can be run regularly with these tools: Note: Cisco does not endorse these tools, but provides these links as examples of technology to enforce strong passwords. Username PoliciesIn addition to a strong password policy, you should ensure that usernames do not create security vulnerabilities.
Related Information |
||||||||
![]() |
![]() |