Solved

Cisco 2960x network switch password policy

Posted on 2014-10-08
3
837 Views
Last Modified: 2014-10-08
Our company has a pair of Cisco 2960x switch. It has been enabled SSH remote admin and create a few admin user. We will need to conduct a security audit soon. Is there a way to implement password policy (e.g. Password length, complexity, history, min/max password time etc.) ? Do we need to rely on external authentication bodies / servers ?

Thank you so much

Patrick
0
Comment
Question by:patricktam
3 Comments
 
LVL 6

Accepted Solution

by:
Matt earned 500 total points
ID: 40368018
For password length and other policy it is better to use RADIUS or TACACS+ authentication systems, who are linked to for example Active Directory. In Active Directory you can then define password policy, define groups of users who are allowed to Access switch, enable log for logon events etc...

If you have RADIUS or TACACS+ servers, then you can login only through them, you can NOT login to switch with locally defined users if you have RADIUS server alive and running. If RADIUS or TACACS+ is not available, then you Will be able to login with locally defined users on switch.
0
 
LVL 50

Expert Comment

by:Don Johnston
ID: 40368132
Is there a way to implement password policy (e.g. Password length, complexity, history, min/max password time etc.) ? Do we need to rely on external authentication bodies / servers ?
Using local authentication, no.  There is no way to define and enforce a password policy.  You would need to use external authentication.
0
 

Author Closing Comment

by:patricktam
ID: 40369799
Thanks for the information.
0

Featured Post

Migrating Your Company's PCs

To keep pace with competitors, businesses must keep employees productive, and that means providing them with the latest technology. This document provides the tips and tricks you need to help you migrate an outdated PC fleet to new desktops, laptops, and tablets.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

In this increasingly digital world, security hacks are no longer just a threat, but a reality. As we've witnessed with Target's big identity hack 2013, Heartbleed in 2015, and now Cloudbleed, companies and their leaders need to prepare for the unthi…
It’s the first day of March, the weather is starting to warm up and the excitement of the upcoming St. Patrick’s Day holiday can be felt throughout the world.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

860 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question