Chapter 7
Passwords and Security
Passwords and security are of utmost importance for the security of your router.
This chapter provides the information you need to configure your E Series router to
be secure for all levels of users.
This chapter contains the following sections:
â– Overview on page 417
â– Platform Considerations on page 417
â– Setting Basic Password Parameters on page 418
â– Setting and Erasing Passwords on page 421
â– Vty Line Authentication and Authorization on page 427
â– Virtual Terminal Access Lists on page 434
â– Secure System Administration with SSH on page 435
â– Restricting User Access on page 446
â– Denial of Service (DoS) Protection on page 450
Overview
One of your major management responsibilities is to secure your router. To do this,
assign passwords or secrets to the router. In Global Configuration mode, you can set
passwords or secrets to prevent unauthorized users from accessing the router in
Privileged Exec mode.
Passwords and secrets have the same degree of security on your router, and they
are used interchangeably. You can define either a password or a secret for your
router, but not both.
Platform Considerations
Passwords and security are supported on all E Series routers.
For information about the modules supported on E Series routers:
â– See the ERX Module Guide for modules supported on ERX7xx models, ERX14xx
models, and the ERX310 Broadband Services Router.
â– See the E120 and E320 Module Guide for modules supported on the E120 and
E320 Broadband Services Routers.
Overview â– 417