Configuring Advanced Local User Account Features
Advanced features providing more control and security are available when configuring
user accounts and their passwords.
The following features are configured in this task. All these features are disabled by default:
- Password Length
- Password Combination Rules
- Password Aging
- Password History
- User Login Attempts
- Password Expiration
All the steps are optional and can be entered in any order.
- Enter global configuration mode.
- Enable password aging to force
the user to provide a new password every three months. After 90 days the CLI automatically prompts the user for a new password.
- Enable a minimum number of
characters and a required combination of characters to ensure secure passwords.
When strict password enforcement is enabled, the password must be a minimum of 15 characters and must contain the following combinations:The strict password enforcement feature displays an error message when the password entered does not meet the criteria.Note: Strict password enforcement is configured globally. Only accounts and passwords configured after the feature is enabled are subject to the minimum password length requirement.
- Configure the device to store up to 15 previous passwords to prevent previous passwords
from being used as a security measure.
An error message will display if a user attempts to use a previous password that is still stored.
- Configure the maximum number of invalid login attempts a user can make before being locked out to 8 with a 15 minute time period before the user account is automatically unlocked.
- Configure a user password to expire in 30 days.
Password expiration can be used for temporary user accounts.
- (Optional) Display user account
information using the
show userscommand.
The following example shows how to
configure advanced local user account features to provide more secure user accounts
and passwords, including password requirements imposed by the enable
strict-password-enforcement command.
device# configure terminal device(config)# enable strict-password-enforcement device(config)# enable user password-aging device(config)# enable user password-history 15 device(config)# enable user disable-on-login-failure 8 login-recovery-time 15 device(config)# username sandy expires 30