version 12.4 service timestamps debug datetime msec service timestamps log datetime msec no service password-encryption version 12.4 service timestamps debug datetime msec service timestamps log datetime msec no service password-encryption version 12.4 service timestamps debug datetime msec service timestamps log datetime msec no service password-encryption version 12.4 service timestamps debug datetime msec service timestamps log datetime msec no service password-encryption
0/ 25)#exi Ruijie(config)#enable password ruijie // 配置交换机超级用户密码,请配置为 ruijie Ruijie(config)#service password-encryption
config-line)#pass cisco3 设置vty密码 ccna1(config-line)#exit ccna1(config)#service password-encryption password' is set ccna2(config-line)#password cisco3 ccna2(config-line)#exit ccna2(config)#service password-encryption until 'password' is set ccna3(config-line)#pass cisco3 ccna3(config-line)#exit ccna3(config)#service password-encryption
XWRJ(config-line)#password0 PASSWORD-txt XWRJ(config-line)#login 口令加密(推荐配置): Router (config)#service password-encryption
10.0.1.133 #用主机ip代替即可 password test log file /var/log/quagga/ospfd.log log stdout log syslog service password-encryption 10.0.1.133 # 主机ip代替 password test enable password test log file /var/log/quagga/zebra.log service password-encryption 10.0.1.136 #主机ip地址 password test log file /var/log/quagga/ospfd.log log stdout log syslog service password-encryption HOSTNAME改为IP也可以 password test enable password test log file /var/log/quagga/zebra.log #log syslog service password-encryption
./0U enable password 8 g9UPXyneQv2n. log file /var/log/quagga/zebra.log service password-encryption # password 8 cQGHF4e9QbcA enable password 8 RBUKMtvgMhU3M log file /var/log/quagga/ospfd.log service password-encryption
version 12.0 no service pad service timestamps debug uptime service timestamps log uptime service password-encryption version 11.3 service timestamps debug uptime service timestamps log uptime service password-encryption version 12.0 service timestamps debug uptime service timestamps log uptime no service password-encryption version 11.3 service timestamps debug uptime service timestamps log uptime service password-encryption
conf t enable secret Cisco1service password-encryption 接下来我们将实现基于标准VTY线路(0-5)的SSH连接,同时禁掉telnet功能。 我们将建立静态路由和一些小的安全功能: conf t enable secret Cisco1service password-encryption username admin password administrator 255.255.255.0ip route 0.0.0.0 0.0.0.0 192.168.0.1 250 0×07:Router_ISP conf t enable secret Cisco1service password-encryption
version 12.2 no service pad service timestamps debug uptime service timestamps log uptime no service password-encryption version 12.2 no service pad service timestamps debug uptime service timestamps log uptime no service password-encryption version 12.2 no service pad service timestamps debug uptime service timestamps log uptime no service password-encryption
//设置明文密码 R1(config)#enable secret 123456 //设置特权模式密码(优先级大于上面这个) R1(config)#service password-encryption
并且要启用Service password-encryption,这条命令用于对存储在配置文件中的所有口令和类似数据进行加密。避免当配置文件被不怀好意者看见,从而获得这些数据的明文。 操作方式: Router(Config)#enable secret xxxxxxxx Router(Config)#Service password-encryption 对比enable password
version 12.1 no service timestamps log datetime msec no service timestamps debug datetime msec no service password-encryption
命令输错时,系统会认为你输入的是一个域名,会进行解析,没有DNS时会卡住很久 加密所有口令:service password-encryption (所有密码都会变成密文) 2、常见命令使用 描述:description
远程密码: line vty 0 4 password 密码 login 把明文加密成密文: service password-encryption
还需要设置进入特权模式的密码) (config)#line vty 0 4 (config-line)#password 789 (config-lline)#login 说明:在全局配置模式下使用service password-encryption 设置访问用户及密码: username username password password 设置特权密码密文: enable secret password 设置将明文密码加密: service password-encryption
version 12.2 no service timestamps log datetime msec no service timestamps debug datetime msec no service password-encryption
不过可以使用service password-encryption对password密码、VTY密码等进行简单加密。 hostname SW2950 SW2950(config)#enable password cjj SW2950(config)#enable secret cjj SW2950(config)#service password-encryption
version 12.4service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption version 12.4service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption
信息加密网络设备配置文件中有敏感口令信息,一旦泄露,将导致网络设备失去控制为保护配置文件的敏感信息,网络设备提供安全加密功能,保存敏感口令数据未启用加密保护的时候,配置文件中的口令信息是明文,任何人都可以读懂启用service password-encryption
相关命令 aaa group server 1.1.10 service password-encryption 要对系统中相关的密码进行加密,可使用这条命令,使用该命令的no形式可以取消对新配置密码的加密 service password-encryption no service password-encryption 参数 无 缺省 不对系统中相关的密码进行加密显示。 no service password-encryption命令仅对使用此命令后配置的密码有效,对使用此命令前配置的已被加密的密码无效。 示例 router_config#service password-encryption 使用此命令对已经配置的明文密码进行加密,且对使用此命令后的明文密码也进行加密。 相关命令 aaa authentication enable default service password-encryption 1.1.13 debug aaa authentication