Hardened passwords
Restrictions for passwords
Password attempts and password change
You are allowed five consecutive password attempts before your account is locked. After six failed password attempts, you are locked out for 15 minutes. If you enter an incorrect password on the seventh attempt, you are not allowed to log in, and the 15-minute lock timer starts again.
If your account is locked, wait for 15 minutes for the account to automatically be unlocked. Alternatively, reach out to an administrator to reset the password, or have an administrator unlock your account.
![]() Note |
Your account gets locked even if password is not entered multiple times. When you do not enter anything in the password field, it is considered as invalid or wrong password. |
Password change policy
When resetting your password, you must set a new password. You cannot reset a password using an old password.
In Cisco vManage Release 20.6.4, Cisco vManage Release 20.9.1 and later releases, a user that is logged out, or a user whose password has been changed locally or on the remote TACACS server cannot log in using their old password. The user can log in only using their new password.
Password requirements
The following password requirements are applicable to releases before Cisco vManage Release 20.9.1:
-
Must contain a minimum of eight characters and a maximum of 32 characters.
-
Must contain at least one uppercase character.
-
Must contain at least one lowercase character.
-
Must contain at least one numeric character.
-
Must contain at least one of the following special characters: # ? ! @ $ % ^ & * -.
-
Must not contain the full name or username of the user.
-
Must not reuse a previously used password.
-
Change at least four characters so their positions differ from those in your old password.
From Cisco IOS XE Catalyst SD-WAN Release 17.9.1a:
|
Password criteria |
Requirements |
|---|---|
|
Medium security |
|
|
High security |
|
Enable Password Policy
Enable password policy rules in Cisco SD-WAN Manager to enforce use of strong passwords.
After you enable a password policy rule, the passwords that are created for new users must meet the requirements defined by the rule. From Cisco vManage Release 20.9.1, you are prompted to change your password the next time you log in if your existing password does not meet the requirements defined by the rule.
Procedure
|
Step 1 |
From the Cisco SD-WAN Manager menu, choose . |
|
Step 2 |
Click Password Policy. |
|
Step 3 |
Perform one of these actions, based on your SD-WAN Manager release:
By default, Password Policy is set to Disabled. |
|
Step 4 |
Click Save. |
Reset a locked user using SD-WAN Manager
If a user is locked out after multiple incorrect password attempts, an administrator with the necessary rights can update the user's password. You can unlock the user account by either changing the password or by getting the user account unlocked.
![]() Note |
Only a netadmin user or a user with the User Management Write role can perform this operation. |
Use these steps to reset a locked user.
Procedure
|
Step 1 |
From the Cisco SD-WAN Manager menu, choose ). |
|
Step 2 |
Choose the user account you want to unlock. |
|
Step 3 |
Click . . . and choose Reset Locked User. |
|
Step 4 |
Click OK to confirm that you want to reset the password of the locked user. This operation cannot be undone. Alternatively, click Cancel to cancel the operation. |
Reset a locked user using CLI commands
Use this procedure to reset a locked user by changing the password using CLI commands.
Procedure
|
Step 1 |
Log in to the device as an admin user. |
|
Step 2 |
Run the following command: Example:
|
|
Step 3 |
When prompted, enter a new password for the user. |

Feedback