How to use XTAM to provide Privileged Account and Session Management for your Cisco device including Password Rotation
This FAQ article covers how to create an XTAM record to manage your SSH enabled Cisco device, optionally with Enable mode, including secure, password-less connections with recording and automated polices for password reset and rotation.
Creating an XTAM record to Manage your Cisco device
Login to XTAM as a System Administrator.
Navigate to Administration > Records Types.
Locate the Cisco record type in the list and click the Edit button to its right.
On the Cisco type edit page, locate the Hidden parameter and disable/remove the checked option. Click the Save button.
Navigate to Records > All Records.
From the Add Record dropdown menu, select Cisco.
Enter a Name (required) and a Description (optional)
Populate your Cisco device values into the Host, Port, User and Password fields.
(Optional) If you want to automatically switch to Cisco’s Enable mode when a secure connection is established, enter a value for Enable Password and Enable Level.
Click Save and Return to continue.
Your Cisco device is now under management in XTAM. You may use the Connect button to test connectivity and if you wish to implement a Password Reset policy, continue to the next section of this article.
Creating a policy to reset or rotate the Password for your Cisco device
Open your Cisco record in XTAM with a System Administrator or an account that has the Manage permission for Task Control.
Within this record, open the Manage menu and select the Tasks option.
By default, both the Check Status and Password Reset scripts will applied.
Next to the Password Reset script, click the Actions menu and select Edit Policy.
Choose your required Policy by selecting from the list of available events.
Click the Save button when finished.
Your password reset policy is now applied to the XTAM record managing your Cisco device. The password being reset will be the User password, not the Enable password.