通過(guò)console端口,AUX端口,或Telnet進(jìn)入路由器時(shí),通常遇到兩個(gè)口令
1.進(jìn)入路由器的口令
2.從一般用戶模式進(jìn)入超級(jí)權(quán)限模式的口令
進(jìn)入路由器的口令設(shè)置步驟:在console,AUX,vty端口設(shè)置
login
password 字符串
多級(jí)權(quán)限配置
缺省條件下,Cisco IOS只有一個(gè)超級(jí)權(quán)限的口令,可以配置Cisco IOS有多達(dá)16個(gè)級(jí)別的權(quán)限及其口令。可以設(shè)置通過(guò)某個(gè)級(jí)別的口令登錄的用戶只允許使用某些命令。
設(shè)置步驟:
1.設(shè)置某條命令屬于某個(gè)級(jí)別,在全局設(shè)置模式下
privilege 模式 level級(jí)別 命令關(guān)鍵字
注意:Cisco IOS 可以定制0-15個(gè)級(jí)別權(quán)限。0-15級(jí)別中,數(shù)字越大,權(quán)限越高,權(quán)限高的級(jí)別繼承低權(quán) 限的所有命令。
2.設(shè)置某個(gè)級(jí)別的口令
enable secret level 級(jí)別 口令
通過(guò)多級(jí)權(quán)限,可以根據(jù)管理要求,授予相應(yīng)的工作以相應(yīng)的權(quán)限。
實(shí)例:
Current configuration:
!
version 11.2
service password-encryption
no service udp-small-servers
no service tcp-small-servers
!
hostname kim
!
enable secret level 1 5 $1$i263$yOdAuqsvie8CyULIgGeRM/
enable secret level 2 5 $1$XvWZ$1rd0j5SjVd3172mBzd16e1
enable secret 5 $1$m3hv$ahrsOKrkeAXElm.yapgcA/
!
interface Ethernet0
no ip address
shutdown
!
interface Serial0
no ip address
shutdown
!
interface Serial1
no ip address
shutdown
!
interface Async1
no ip address
!
no ip classless
privilege configure level 2 line
privilege configure level 2 ip route
privilege configure level 2 interface
privilege configure level 2 ip routing
privilege configure level 15 ip
privilege exec level 2 start-chat
privilege exec level 2 copy running-config startup-config
privilege exec level 2 copy running-config
privilege exec level 2 copy
privilege exec level 2 configure terminal
privilege exec level 2 configure
privilege exec level 1 show ip route
privilege exec level 1 show ip protocols
privilege exec level 1 show ip
privilege exec level 1 show startup-config
privilege exec level 1 show running-config
privilege exec level 1 show
privilege exec level 1 debug dialer
privilege exec level 1 debug ppp authentication
privilege exec level 1 debug ppp error
privilege exec level 1 debug ppp negotiation
privilege exec level 1 debug ppp packet
privilege exec level 1 debug ppp
privilege exec level 1 debug ip routing
privilege exec level 1 debug ip
privilege exec level 1 debug modem
privilege exec level 1 debug
!
line con 0
line 1 8
line aux 0
line vty 0 4
login
!
end