Setting passwords for management privilege levels

You can set one password for each of the following management privilege levels:

  • Super User level - Allows complete read-and-write access to the system. This is generally for system administrators and is the only management privilege level that allows you to configure passwords.
  • Port Configuration level - Allows read-and-write access for specific ports but not for global (system-wide) parameters.
  • Read Only level - Allows access to the Privileged EXEC mode and User EXEC mode of the CLI but only with read access.

You can assign a password to each management privilege level. You also can configure up to 16 user accounts consisting of a user name and password, and assign each user account to one of the three privilege levels. Refer to Local user accounts.

NOTE
You must use the CLI to assign a password for management privilege levels. You cannot assign a password using the Web Management Interface.

If you configure user accounts in addition to privilege level passwords, the device will validate a user access attempt using one or both methods (local user account or privilege level password), depending on the order you specify in the authentication-method lists. Refer to Authentication-method lists.

Follow the steps given below to set passwords for management privilege levels.

  1. At the opening CLI prompt, enter the following command to change to the Privileged level of the EXEC mode.
    device> enable
    device#
  2. Access the CONFIG level of the CLI by entering the following command.
    device#configure terminal
    device(config)#
    
  3. Enter the following command to set the Super User level password.
    device(config)#enable super-user-password text
    
    NOTE
    You must set the Super User level password before you can set other types of passwords. The Super User level password can be an alphanumeric string, but cannot begin with a number.
  4. Enter the following commands to set the Port Configuration level and Read Only level passwords.
    device(config)#enable port-config-password text
    device(config)#enable read-only-password text
    

    Syntax: enable super-user-password text

    Syntax: enable port-config-password text

    Syntax: enable read-only-password text

    NOTE
    If you forget your Super User level password, refer to Recovering from a lost password.