Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Can someone correct me if i am wrong?

Status
Not open for further replies.

Fireman

Technical User
Dec 5, 2000
32
CA
Hi all,

Problem: must change password for user JOHN
Current 3640 router’s IOS version is 12.0.

Portion of existing running-config file:
..
aaa authentication password-prompt Password>
aaa authentication username-prompt Username>
aaa authentication login default local
aaa authorization exec default local
enable password 7 AAAAAA
!
username JOHN privilege 15 password 7 AAAAAA

Note: Passwords in lines enable password 7 AAAAAA and username JOHN privilege 15 password 7 AAAAAA ARE THE SAME (AAAAAA)

Steps I am thinking to perform:
1. Copy running-config to TFTP (is there any other way to backup configuration?)
2. Enter to config
3. Add no username JOHN privilege 15 password 7 AAAAAA
4. Add no enable password 7 AAAAAA
5. Add username JOHN privilege 15 password BBBBBB
6. Add enable password 7 BBBBBB
7. Write to running-config
8. Copy running-config startup-config

Would it work?

Thanks.
 
fireman did you try the procedure I gave you on the other Thread ? To make sure you do know that the codes behind the passwords are there because of service password-encryption , located near the top of the sh run . If your not sure of your self
remove the enable password and then do a no username john privilege 15 passsword . create your new username john privilege 15 password . After that then do a
enable password ???? . simple task, save your config .
 
Thanks Jeter,
Basically, both passwords - entered with username john privilege 15 "password" and enable password "password" must be the same? Corect?

I checked the running-config more carefully and realized that service password-encryption command is listed near the top. Since cutomer does not have configuration backed up i have to be REALY carefull.


Regards.
 
No the passwords can be differnet , Thats why you set up users to access a particular levels .
 
Hi Jeter,
i tried to add another user (without changing anything) by typing:
username peter privilege 15 password 7 ssss
and got the answer that i have to type encrypted password.

Which encrypted password i should enter?
 
I figured it out.
Typed:
no service password-encryption
no username john ....
username john privilege 15 password service password-encryption
write mem.

Worked like a charm.....

Regards.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top