You can set the following passwords:
Different groups of commands are associated with privilege levels (Table 51). You can set enable passwords to allow users to access commands at different privilege levels.
Table 51: Commands Available at Different Privilege Levels
To maximize security and usability, set different passwords for levels 1, 5, 10, and 15. By default, no enable passwords exist.
If users have access to the console, they automatically have access to privilege level 0. To access higher levels of privilege, they must enter the enable privilege-level command. When users specify a privilege level, the system determines whether there is a password at that level. If there is not, the system prompts the user for the password for the lower level closest to the requested level.
To set up enable passwords, use the commands described in Setting Basic Password Parameters .
If you forget an enable password or secret, you can erase all enable passwords and secrets.
Two commands allow you to erase passwords and secrets: erase secrets and service unattended-password-recovery. It is important to fully understand the purpose of these commands and how they work with each other.
The erase secrets command can be used to delete all existing passwords. To use this command, you must be physically present at the router to complete the operation. After the command has been executed, you have a finite number of seconds to press the software reset button on the SRP module. You can execute this command from the console or any vty.
The service unattended-password-recovery command provides you with a way to delete existing passwords and secrets without physically being present at the router. You must have the proper privilege level to execute the command, and you can execute it from either the console or any vty.
When you execute service unattended-password-recovery, you change the behavior of erase secrets. You can now delete passwords and secrets from the console by executing erase secrets without a time restraint or having to be physically present at the router. When you use the no version of service unattended-password-recovery, you revert the functionality of erase secrets to the factory default setting.
To erase all enable passwords or secrets:
- host1>erase secrets 60
Figure 28: Location of the Software Reset Button

![]() |
Note: If you do not press the software reset button within the time limit, the system will not erase the password, and you will need to repeat the process. |
erase secrets
- host1>erase secrets 60
service unattended-password-recovery
- host1(config)#service unattended-password-recovery
By default, there is no console password. To set a console password:
If you need to reset the enable password, see Privilege Levels .
- host1(config)#line console 0
- host1(config-line)#login
- host1(config-line)#password 7 dq]XG`,%N"SS7d}o)_?Y
line
- host1(config)#line vty 1 4
login
- host1(config)#line vty 1 4
- host1(config-line)#login
password
![]() |
Note: To use an encrypted password or a secret, you must follow the procedure in Setting Basic Password Parameters to obtain the encrypted password or secret. You cannot create your own encrypted password or secret; you must use a system-generated password or secret. |
- host1(config-line)#password 0 mypassword
- host1(config-line)#password 5 bcA";+1aeJD8)/[1ZDP6
- host1(config-line)#password 7 dq]XG`,%N"SS7d}o)_?Y
If you forget the console password, you can erase the existing value and configure a new one. This action deletes all authentication for the console line. To erase existing passwords:
- :boot##disable console authentication
If you remember the password at this point, you can override this action by entering:
- :boot##no disable console authentication
- :boot##reload
When the operating system reloads, you can access the console without a password.
![]() |
Note: You will be able to log in to the console without a password until you set a new password. |
You can use the show secrets command to view all current passwords and secrets.
show secrets
host1#show secrets
Current Password Settings
-------------------------
encryption encrypted
level type password/secret mode
----- ------------ -------------------- ----------
0
1
2
3
4
5 7 (password) zRFj_6>^]1OkZR@e!|S$ configured
6 7 (password) zRFj_6>^]1OkZR@e!|S$ inherited
7 7 (password) zRFj_6>^]1OkZR@e!|S$ inherited
8 7 (password) zRFj_6>^]1OkZR@e!|S$ inherited
9 7 (password) zRFj_6>^]1OkZR@e!|S$ inherited
10 7 (password) zRFj_6>^]1OkZR@e!|S$ inherited
11 7 (password) zRFj_6>^]1OkZR@e!|S$ inherited
12 7 (password) zRFj_6>^]1OkZR@e!|S$ inherited
13 7 (password) zRFj_6>^]1OkZR@e!|S$ inherited
14 7 (password) zRFj_6>^]1OkZR@e!|S$ inherited