Use the enable password Global Configuration mode command to set a local password to control access to normal and privilege levels. Use the no form of this command to return to the default password.
Syntax
enable password [level
privilege-level] {[method hash-method] unencrypted-password | encrypted
encrypted-password}
enable [level
privilege-level] [method hash-method] generate-password
enable masked-secret [level
privilege-level] [method
hash-method]
no enable password [level privilege-level]
Parameters
-
level privilege-level—Level for which the password applies. If not specified, the level is 15. (Range: 1–15)
-
[method hash-method] — (optional) specifies the method used for encrypting the clear-text password. Supported values:
-
unencrypted-password—Password for this level. (Range: 0–159 chars)
-
encrypted encrypted-password—Specifies that the password is encrypted and hashed using a salt. Use this keyword to enter a password
that is already encrypted (for instance, a password that was copied from the configuration file of another device). The encrypted-password is specified in the format of $<type>$<salt>$<encrypted-password >, where:
-
<type> - is an integer value that indicates the type of hash algorithm used to generate the hash
-
<salt> - The base64 encoding of the 96 bits used for salt (length – 16 bytes)
-
<encrypted-password> - The base64 encoding of the encrypted hash output (length - 86 bytes)
Default Configuration
Default for level is 15.
Command Mode
Global Configuration mode
User Guidelines
The unencrypted-password must comply to password complexity requirements.

Note
|
The password complexity rules are as follows:
-
Minimal password length is 8 characters by default. Passwords are configurable with a range of 8-64.
-
Character Repetition: A character cannot be repeated consecutively. The maximum number of repetition allowed is 3 by default.
-
Minimum number of character classes: The number of different character classes that must be included in the password (classes
are: uppercase letter, lowercase letter, number and special character). The minimum number is 3 by default and is configurable
to 0-4 (0 and 1 are functionally identical).
-
Any password established or altered by the user (hence "Secret") is compared to a list of common passwords. SecLists/Password Common Credentials If the secret contains a word from the list, the user will receive the following error message and will need to re-enter
an alternative password: "Password rejected- Passwords must not match words in the dictionary, and must not contain commonly
used passwords".
-
Sequential characters – The password MUST NOT contain more than 2 sequential characters or numbers, or the reverse value of
these sequences. Restriction also includes letters that are replaced with other characters, as follows: "$" for "s", "@" for
"a", "0" for "o", "1" for "l", "!" for "i", "3" for "e". Examples for prohibited passwords: “efg123!$”, “abcd765%”, “kji!$378”,
qr$58!230. Sequential letters are prohibited in any case combination (e.g. AbC or aBC).
-
Context specific words (project and vendor name) – The password MUST NOT contain the username or the words “cisco” , "catalyst"
or derivatives of such. This restriction includes these words reversed or in any case. Restriction also includes letters that
are replaced with other characters, as follows: "$" for "s", "@" for "a", "0" for "o", "1" for "l", "!" for "i", "3" for "e",
is not permitted. For example, C!$c0678! is not permitted.
-
Known passwords are not allowed as passwords
|
When the administrator configures a new enable password, this password is encrypted automatically and saved to the configuration file. No matter how the password was entered,
it appears in the configuration file with the keyword encrypted and the encrypted value. The administrator is required to use the encrypted keyword only when actually entering an encrypted keyword.
If the administrator wants to manually copy a password that was configured on one switch (for instance, switch B) to another
switch (for instance, switch A), the administrator must add encrypted in front of this encrypted password when entering the enable command in switch A. In this way, the two switches will have the same password.
The administrator is required to use the encrypted keyword only when actually entering an encrypted keyword.
If the generate-password option is used, instead of entering a password the user will be presented with a randomly generated password suggestion.
This suggestion will comply with all current password strength settings
The user will be given the choice to accept or reject the proposed password. If the user elects to accept the password, then
this password will be added for the configured enable level (in encrypted format) in the configuration file.
If the user rejects the password suggestion, the command will need to be entered again to configure this enable level.
Example
Example 1 - The command sets a password that has already been encrypted. It will be copied to the configuration file just as it is
entered. To login to device using this password, the user must know its unencrypted form.
switchxxxxxx(config)# enable password encrypted $15$TqKC13RgV/QJb2Ma$4JmeD7wgRGH2iwGKMM+g4M53uQxpOMlhkUN56UMAEUuMqhw0bsRH27zakc7
2hLxt/YhEknPA6LX7fTgqwZn6Vw==
Example 2 - The command sets an unencrypted password for level 1 (it will be encrypted in the configuration file).
switchxxxxxx(config)# enable password level 1 let-me-In
Example 3 - The command in this example includes the generate-password key word. in this case the device will propose a randomly generated password to be used. in the example below the user selects
to accept the proposed password.
switchxxxxxx(config)# enable password generate-password
Generated password: aBgrT9!59Hq$
Accept generated password (y/n) [Y] y
“Configuration and password are added to device configuration. Please Note
password for future use”
Example 4 - The command in this example includes the generate-password key word. in this case the device will propose a randomly generated
password to be used. in the example below the user selects to rejects the proposed password.
switchxxxxxx(config)# enable password generate-password
Generated password: aBgrT9!59Hq$
Accept generated password (y/n) [Y] n
“Auto generated password rejected by user. Password configuration is not added to
device configuration”