43-8
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 43 Troubleshooting the Security Appliance
Performing Password Recovery
hostname(config)#
enable password
password
hostname(config)#
username
name
password
password
Step 14
Load the default configuration by entering the following command:
hostname(config)#
no
config-register
The default configuration register value is 0x1. For more information about the configuration register,
see the
Cisco Security Appliance Command Reference
.
Step 15
Save the new passwords to the startup configuration by entering the following command:
hostname(config)#
copy running-config startup-config
Recovering Passwords for the PIX 500 Series Security Appliance
Recovering passwords on the PIX 500 Series security appliance erases the login password, enable
password, and
aaa authentication console
commands. To recover passwords for the PIX 500 Series
security appliance, perform the following steps:
Step 1
Download the PIX password tool from Cisco.com to a TFTP server accessible from the security
appliance. For instructions, go to the following URL:
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_password_recovery09186a0080
09478b.shtml
Step 2
Connect to the security appliance console port according to the instructions in
“Accessing the
Command-Line Interface” section on page 2-4
.
Step 3
Power off the security appliance, and then power it on.
Step 4
Immediately after the startup messages appear, press the
Escape
key to enter monitor mode.
Step 5
In monitor mode, configure the interface network settings to access the TFTP server by entering the
following commands:
monitor>
interface
interface_id
monitor>
address
interface_ip
monitor>
server
tftp_ip
monitor>
file
pw_tool_name
monitor>
gateway
gateway_ip
Step 6
Download the PIX password tool from the TFTP server by entering the following command:
monitor>
tftp
If you have trouble reaching the server, enter the
ping
address
command to test the connection.
Step 7
At the “Do you wish to erase the passwords?” prompt, enter
Y
.
You can log in with the default login password of “cisco” and the blank enable password.
The following example shows password recovery on a PIX 500 Series security appliance with the TFTP
server on the outside interface:
monitor>
interface 0
0: i8255X @ PCI(bus:0 dev:13 irq:10)
1: i8255X @ PCI(bus:0 dev:14 irq:7 )
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......