Cisco - Mengatur Username dan Password Cisco Router and Switch
conf t
hostname R1
ip domain-name training.lab
hostname R1
ip domain-name training.lab
crypto key generate rsa
[isi nilai moduls]
[isi nilai moduls]
username admin pasword cisco123
enable password cisco456
exti
line con 0
exec-timeout 5 0
password 123
login local
exit
line vty 0 4
exec-timeout 5 0
password 456
login
transport input ssh
ip ssh ver 2
exit
=================
LAKUKAN VERIFIKASI (sh run):
R1#sh run
Building configuration...
Current configuration : 912 bytes
!
version 15.1
no service timestamps log datetime msec
no service timestamps debug datetime msec
no service password-encryption
!
hostname R1
!
enable password cisco456
!
!
username admin password 0 cisco123
!
!
license udi pid CISCO2911/K9 sn FTX15245B79-
!
!
ip ssh version 2
ip domain-name training.lab
2. Exit, lalu lgoin lg (console)
username : admin password cisco123
3. ketika aktifkan (enable) global mode
password: cisco456
4. Ketika remote dari PC (SSH)
username : admin password: cisco123
password enabled: cisco456
5. Verifikasi level user admin
R1#sh privilege
6.MENAMBAH USER
username admin privilege 15 secret cisco
R1#sh run
Building configuration...
Current configuration : 912 bytes
!
version 15.1
no service timestamps log datetime msec
no service timestamps debug datetime msec
no service password-encryption
!
hostname R1
!
enable password cisco456
!
!
username admin password 0 cisco123
!
!
license udi pid CISCO2911/K9 sn FTX15245B79-
!
!
ip ssh version 2
ip domain-name training.lab
2. Exit, lalu lgoin lg (console)
username : admin password cisco123
3. ketika aktifkan (enable) global mode
password: cisco456
4. Ketika remote dari PC (SSH)
username : admin password: cisco123
password enabled: cisco456
5. Verifikasi level user admin
R1#sh privilege
6.MENAMBAH USER
username admin privilege 15 secret cisco
II. Mengaktifkan (enable password dam enable screet)
hostname R1
ip domain-name training.lab
crypto key generate rsa
username admin pasword cisco123
enable password cisco123 #jk seperti ini sj, tanpa mengaktifkan service-encryption mk password akan terlihat
enable secret cisco123456 #password akn menjadi type 5 / dan ter-eknkrpsi MD5
service password-encryption #ntk meng-enkripsi semua password (no plain-text), biasanya type-7 ini password mash bs di crack
ip domain-name training.lab
crypto key generate rsa
username admin pasword cisco123
enable password cisco123 #jk seperti ini sj, tanpa mengaktifkan service-encryption mk password akan terlihat
enable secret cisco123456 #password akn menjadi type 5 / dan ter-eknkrpsi MD5
service password-encryption #ntk meng-enkripsi semua password (no plain-text), biasanya type-7 ini password mash bs di crack
line vty 0 4
exec-timeout 5 0
password cisco456
login
transport input ssh
ip ssh ver 2
exit
----------------------------------------------------------
exec-timeout 5 0
password cisco456
login
transport input ssh
ip ssh ver 2
exit
----------------------------------------------------------
Ketika dilakukan hal ini
username admin password cisco123
username admin password cisco123
mk ketika sh run, password akan namapak. Tp jika dilakukan hal ini
service password-encryption
username admin password cisco123
mk semua password akan di hidden/encryptsi.
-------------------------------------------------------
R1(config)#username admin secret cisco123
mk hasilnya
username admin secret 5 $1$mERr$5.a6P4JqbNiMX01usIfka/
------------------------------------------------------
username admin password 0 cisco123
mk hasilnya
username admin password 0 cisco123
------------------------------------
R1(config)#username admin secret cisco123
R1(config)#service password-encryption
mk hasilnya,
username admin password 7 0822455D0A16544541
dan ini masih bs dicrack, kt buktikan
-----------------------------------------------------------------------------------
mk, solusinya adalah buat user (aktifkan secret dan service-password enkripsi)
kita buat user dengan command berikut
R1(config)#username cisco secret cisco123456
R1(config)#service password-encryption
mk hasilnya, type 5 susah ntk di crack/dekripsi
username cisco secret 5 $1$mERr$9xNQotxCL6Ay1NEt8MtN51
Posting Komentar untuk "Cisco - Mengatur Username dan Password Cisco Router and Switch"