Information
Device administrators can specify password complexity policies that can be used to ensure that managementuser passwords cannot be easily guessed or brute-forced to gain access to devices.Configurable complexity requirements include:
  -  Minimum password length
  -  Password composition (lowercase, uppercase, numbers, symbols)
  -  Checking for repeat characters, repeating password, or username as part of password
  -  Password aging and history
Solution
The following example defines a password complexity policy that prohibits more than three repeated characters in a password, repeating password strings, or entering the username (forward or reverse) as part of the password:
  switch(config)# password complexity all