Configuring Local User Account Features
The features providing more control and
security are available when configuring user accounts and their passwords.
The following features are configured in this task. All these features are disabled by default:
- Password Masking
- Password Combination Rules
- Password Aging
- Password History
- User Login Attempts
- Password Expiration
After entering global configuration mode, all subsequent steps are optional and can be entered in any order.
- Enter global configuration mode.
- Enable password aging to force
the user to provide a new password every three months. After 90 days the CLI automatically prompts the user for a new password.
- Configure a user password to
expire in 30 days. Password expiration can be used for temporary user accounts.
- Enable a minimum number of
characters and a required combination of characters to ensure secure passwords. Note: Strict password enforcement is configured globally. Only accounts and passwords configured after the feature is enabled are subject to the minimum password length requirement.
- Enable password masking to hide
the password characters from the console display as they are entered using the
CLI. When password masking is enabled, press the Enter key before entering the password, and enter the password when prompted.
- Configure the device to require
a password be input when a user enters the
enablecommand to access Privileged EXEC mode. - Configure the device to store up to 15 previous passwords to prevent previous passwords from being reused as a security measure.
- Configure the maximum number of invalid login attempts a user can make before being locked out to 8 with a 15-minute time period before the user account is automatically unlocked.
- Display user account information
using the
show userscommand.