Posted on 3 Comments

How to encrypt passwords on Cisco routers and switches.

We have seen how to set passwords on cisco switches or routers here. Of course setting passwords does add to the security of the device but there is small problem. The password is stored in plain text.  Anyone who gets access to the switch can easily see all the passwords by typing command “show running-config or show startup-config”. Today we will see how to encrypt passwords on Cisco routers and switches.

encisco1

Encrypting passwords can further enhance the security of the device. Privileged password can be encrypted by using the command “enable secret” instead of “enable password”. This command should be set from privileged global configuration mode.

encisco2

Lets see what can we see  when we use the command “show running-config”.

encisco3

We can see that the password we set has been encrypted. but what about other passwords. The  console, auxiliary and vty lines passwords cannot be encrypted even if we use “enable secret” command. To encrypt those passwords, we have to use another command “service password-encryption” as shown below.

encisco4

This command will encrypt all the passwords stored in plain text on the device.

3 thoughts on “How to encrypt passwords on Cisco routers and switches.

  1. If you want your password not to be seen in the configuration of a router than enable secret password is the best option, because when someone views the running configuration they will see and know your enable password, but in the case of enable secret password they will only see the encrypted string.

  2. THanky Yuo this was Wery helpful UwU

  3. Thank You. That was really helpful.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.