<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Resetting the EXEC passwords on an ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/resetting-the-exec-passwords-on-an-asa/m-p/1344700#M858187</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jimmy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Depending on your AAA config, you can make this happen without changing/revealing your enable password. For example, with SSH you can configure:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA(config)# username Doe password John priv 15&lt;/P&gt;&lt;P&gt;ASA(config)# aaa authentication ssh console LOCAL &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then, when you SSH to the device, you'll get a prompt to provide a username and password. Once the user logs in successfully, they can use the 'enable' command to enter privileged exec mode with their own password ('John' in this case) and it will give them a # prompt at the privilege level associated with their user (i.e. 15).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 Sep 2009 16:18:21 GMT</pubDate>
    <dc:creator>robertson.michael</dc:creator>
    <dc:date>2009-09-10T16:18:21Z</dc:date>
    <item>
      <title>Resetting the EXEC passwords on an ASA</title>
      <link>https://community.cisco.com/t5/network-security/resetting-the-exec-passwords-on-an-asa/m-p/1344697#M858182</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone got a working procedure for changing the EXEC &amp;amp; privilege EXEC passwords on an ASA?&lt;/P&gt;&lt;P&gt;I was thinking of logging on (using the old account), deleting the current details, applying the new account details - then, open a second ssh session to this device to test the new account.&lt;/P&gt;&lt;P&gt;This way I safeguard my access to the device should the new account not be configured correctly, as my first session is still up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will this work:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no enable password XXXX encrypted&lt;/P&gt;&lt;P&gt;no passwd XXXX encrypted&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;passwd ABCD&lt;/P&gt;&lt;P&gt;enable password EFGH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for helping!!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:08:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resetting-the-exec-passwords-on-an-asa/m-p/1344697#M858182</guid>
      <dc:creator>walter1972</dc:creator>
      <dc:date>2019-03-11T16:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: Resetting the EXEC passwords on an ASA</title>
      <link>https://community.cisco.com/t5/network-security/resetting-the-exec-passwords-on-an-asa/m-p/1344698#M858184</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Walter,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That will do the trick for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Aug 2009 16:55:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resetting-the-exec-passwords-on-an-asa/m-p/1344698#M858184</guid>
      <dc:creator>robertson.michael</dc:creator>
      <dc:date>2009-08-21T16:55:56Z</dc:date>
    </item>
    <item>
      <title>Re: Resetting the EXEC passwords on an ASA</title>
      <link>https://community.cisco.com/t5/network-security/resetting-the-exec-passwords-on-an-asa/m-p/1344699#M858186</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Michael,&lt;/P&gt;&lt;P&gt;On my ASA 5520, when I type in "no enable password ?"  I get a prompt asking me to choose level 0-15.  Of course it won't accept level 15, only 0-14 !!   Anyways, I'm trying to give another engineer level 15 privileges without giving him our enable password.  I enter the command "username Doe password John priv 15", but when I "ssh -l Doe" I do not get the enable prompt, only user prompt.  Thoughts?  Jimmyc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Sep 2009 13:06:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resetting-the-exec-passwords-on-an-asa/m-p/1344699#M858186</guid>
      <dc:creator>jimmyc_2</dc:creator>
      <dc:date>2009-09-10T13:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: Resetting the EXEC passwords on an ASA</title>
      <link>https://community.cisco.com/t5/network-security/resetting-the-exec-passwords-on-an-asa/m-p/1344700#M858187</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jimmy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Depending on your AAA config, you can make this happen without changing/revealing your enable password. For example, with SSH you can configure:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA(config)# username Doe password John priv 15&lt;/P&gt;&lt;P&gt;ASA(config)# aaa authentication ssh console LOCAL &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then, when you SSH to the device, you'll get a prompt to provide a username and password. Once the user logs in successfully, they can use the 'enable' command to enter privileged exec mode with their own password ('John' in this case) and it will give them a # prompt at the privilege level associated with their user (i.e. 15).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Sep 2009 16:18:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resetting-the-exec-passwords-on-an-asa/m-p/1344700#M858187</guid>
      <dc:creator>robertson.michael</dc:creator>
      <dc:date>2009-09-10T16:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: Resetting the EXEC passwords on an ASA</title>
      <link>https://community.cisco.com/t5/network-security/resetting-the-exec-passwords-on-an-asa/m-p/1344701#M858188</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;That is what I have, and it doesn't work.  Just for grins, I even created a new user via cut and paste of your reply (Doe was changed to Doee, because the username must be at least four charachters).  It still failed.  I log into the ASA via "ssh -l Doee 10.1.1.1" and it puts me at the user prompt.  "John" will not work as the password to go to enable, it still needs the private one.  Sounds like a Cisco bug to me.&lt;/P&gt;&lt;P&gt;Should I remove the private enable-password?&lt;/P&gt;&lt;P&gt;Whatya think?&lt;/P&gt;&lt;P&gt;Jimmyc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Sep 2009 12:15:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resetting-the-exec-passwords-on-an-asa/m-p/1344701#M858188</guid>
      <dc:creator>jimmyc_2</dc:creator>
      <dc:date>2009-09-11T12:15:50Z</dc:date>
    </item>
    <item>
      <title>Re: Resetting the EXEC passwords on an ASA</title>
      <link>https://community.cisco.com/t5/network-security/resetting-the-exec-passwords-on-an-asa/m-p/1344702#M858189</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jimmy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You'll also need to add:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication enable console LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My apologies for not including that before--shouldn't have assumed you had that already.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Sep 2009 13:07:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resetting-the-exec-passwords-on-an-asa/m-p/1344702#M858189</guid>
      <dc:creator>robertson.michael</dc:creator>
      <dc:date>2009-09-11T13:07:52Z</dc:date>
    </item>
    <item>
      <title>Re: Resetting the EXEC passwords on an ASA</title>
      <link>https://community.cisco.com/t5/network-security/resetting-the-exec-passwords-on-an-asa/m-p/1344703#M858190</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You da man!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did notice that pretty much makes the generic enable password obsolete, since any time you need to upgrade from user to enable it will ask you for your ID and personal password, yes?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When my daughter is ready to study game design, I'll ask her to look into RIT....&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Sep 2009 13:22:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resetting-the-exec-passwords-on-an-asa/m-p/1344703#M858190</guid>
      <dc:creator>jimmyc_2</dc:creator>
      <dc:date>2009-09-11T13:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: Resetting the EXEC passwords on an ASA</title>
      <link>https://community.cisco.com/t5/network-security/resetting-the-exec-passwords-on-an-asa/m-p/1344704#M858191</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are correct--I pretty much don't have a use for the enable password once things are configured this way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't actually work for RIT, I'm just a grad student there. It is a great school though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take care,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Sep 2009 16:34:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resetting-the-exec-passwords-on-an-asa/m-p/1344704#M858191</guid>
      <dc:creator>robertson.michael</dc:creator>
      <dc:date>2009-09-11T16:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: Resetting the EXEC passwords on an ASA</title>
      <link>https://community.cisco.com/t5/network-security/resetting-the-exec-passwords-on-an-asa/m-p/1344705#M858192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Or another method is:&lt;/P&gt;&lt;P&gt;Login via SSH with your privilege level 15 account. You will have the &amp;gt; prompt. Now just type 'login' and enter your username and password again.....you will be at the Enable prompt.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Sep 2009 15:07:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resetting-the-exec-passwords-on-an-asa/m-p/1344705#M858192</guid>
      <dc:creator>clark.d</dc:creator>
      <dc:date>2009-09-12T15:07:56Z</dc:date>
    </item>
  </channel>
</rss>

