Enable Privileged Mode Password
Configure a password that will be
required for transitioning from User EXEC mode to Privileged EXEC mode after logging
in to
the device through the console or SSH.
- Enter global configuration mode.
- Enable the privileged mode
password using the
enable privilege-mode passwordcommand.
The following example configures the password for the Privileged EXEC mode which requires additional authentication after logging in to the device through the console or SSH. Although optional, enabling password masking before configuring the password for privilege mode provides optimum security.
device(config)# enable user password-masking Password masking is enabled device(config)# enable privilege-mode password Password:
If you do not press Enter after password, the following error mesaage is dispalyed:
device(config)# enable privilege-mode password test Error - password masking enabled: <cr> required before entering password.
enable command to access
Privileged EXEC mode, you will be prompted to enter the Privileged EXEC mode password
(which is different from all user-specific passwords). If password-masking was also
enabled, the password will be masked on the
CLI.device(config)# exit device# SYSLOG: <14>1 2025-04-15T11:14:39+05:30 ICX7650-48F Router ICX7650_Router - General [meta sequenceId=26] BOM Security: running-config was potentially changed by cli from CONSOLE SYSLOG: <14>1 2025-04-15T11:14:40+05:30 ICX7650-48F Router ICX7650_Router - General [meta sequenceId=27] BOM Security: console logout by cli from PRIVILEGED EXEC mode ICX7650-48F Router>enable Password: Privilege mode authentication successful. SYSLOG: <14>1 2025-04-15T11:14:49+05:30 ICX7650-48F Router ICX7650_Router - General [meta sequenceId=29] BOM Security: console login by cli to PRIVILEGED EXEC modeIn global configuration mode, you can use the
show running-config
command, filtered to include all configuration entries containing the word "enable"
(as
per the previous example, the output will display password-masking and privilege-mode
password as
enabled).device(config)# show running-config | include enable fips enable common-criteria enable user disable-on-login-failure 7 login-recovery-time in-secs 30 enable privilege-mode password 1 $6$b5e6c667$wu8qq1F9jZdvjelDwvH0Afi6wQaoIfb3ewLzuO7CXmwaF6Oor57BvutO02vjkn enable user password-masking logging enable rfc5424
Note: When
aaa authentication enable
default command is used to configure the default authentication method
list, or when aaa
authentication login privilege-mode command is set up on the device to
enter the privileged EXEC mode after a successful login through SSH, these methods
will take priority over the enable privilege-mode password command .