The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared default! confi"uration. #f $our networ% is live& ma%e sure that $ou understand the potential impact of an$ command.
The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared default! confi"uration. #f $our networ% is live& ma%e sure that $ou understand the potential impact of an$ command.
The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared default! confi"uration. #f $our networ% is live& ma%e sure that $ou understand the potential impact of an$ command.
The information in this document is based on these hardware versions:
Cisco 2600 Series Router
Cisco 2800 Series Router The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared default! confi"uration. #f $our networ% is live& ma%e sure that $ou understand the potential impact of an$ command. Related Products Refer to 'assword Recover$ 'rocedures for information on how to recover passwords for related products. Conventions Refer to Cisco Technical Tips Conventions for information on document conventions. Step-by-Step Procedures This section describes two procedures to recover $our passwords. Procedure 1 Complete these steps in order to recover $our password: 1. Attach a terminal or 'C with terminal emulation to the console port of the router. (se these terminal settin"s: o )600 baud rate o *o parit$ o 8 data bits o + stop bit o *o flow control Refer to these documents for information on how to cable and connect a terminal to the console port or the A(, port: o Cablin" -uide for Console and A(, 'orts o Connectin" a Terminal to the Console 'ort on Catal$st Switches o Connect a Terminal to Catal$st 2).8-/01& .)08-/01& and .8.0- Series Switches 2. #f $ou can access the router& t$pe show version at the prompt& and record the confi"uration re"ister settin". See 23ample of 'assword Recover$ 'rocedure in order to view the output of a show version command. Note: The confi"uration re"ister is usuall$ set to 032+02 or 03+02. #f $ou can no lon"er access the router because of a lost lo"in or TACACS password!& $ou can safel$ assume that $our confi"uration re"ister is set to 0x2102. 3. (se the power switch in order to turn off the router& and then turn the router bac% on. Iportant Notes: o #n order to simulate this step on a Cisco 6.00& pull out and then plu" in the *ode Route 'rocessor *R'! or *ode Switch 'rocessor *S'! card. o #n order to simulate this step on a Cisco 6300 with *#/2& pull out and then plu" in the *#/2 card. !. 'ress "rea# on the terminal %e$board within 60 seconds of power up in order to put the router into R45mon. #f the brea% se6uence does not wor%& refer to Standard 7rea% 8e$ Se6uence Combinations 9urin" 'assword Recover$ for other %e$ combinations. $. T$pe con%re& '(21!2 at the rommon 1> prompt in order to boot from :lash. This step b$passes the startup confi"uration where the passwords are stored. ). T$pe reset at the rommon 2> prompt. The router reboots& but i"nores the saved confi"uration. *. T$pe no after each setup 6uestion& or press Ctrl-C in order to s%ip the initial setup procedure. +. T$pe enable at the Router> prompt. ;ou are in enable mode and should see the Router# prompt. ,. T$pe con%i&ure eory or copy startup-con%i& runnin&-con%i& in order to cop$ the nonvolatile RA5 *<RA5! into memor$. -arnin&: 9o not t$pe copy runnin&-con%i& startup-con%i& or write. These commands erase $our startup confi"uration. 1'. T$pe show runnin&-con%i&. The show runnin&-con%i& command shows the confi"uration of the router. #n this confi"uration& the shutdown command appears under all interfaces& which indicates all interfaces are currentl$ shut down. #n addition& the passwords enable password& enable secret& vt$& console passwords! are in either an encr$pted or unencr$pted format. ;ou can reuse unencr$pted passwords. ;ou must chan"e encr$pted passwords to a new password. 11. T$pe con%i&ure terinal. The hostname(config)# prompt appears. 12. T$pe enable secret .password/ in order to chan"e the enable secret password. :or e3ample: 13. hostname(config)#enable secret cisco 1!. 1$. #ssue the no shutdown command on ever$ interface that $ou use. #f $ou issue a show ip inter%ace brie% command& ever$ interface that $ou want to use should displa$ up up. 1). T$pe con%i&-re&ister .configuration_register_setting/. =here configuration_register_setting is either the value $ou recorded in step 2 or 0x2102 . :or e3ample: 1*. hostname(config)#config-register 0x2102 1+. 1,. 'ress Ctrl-0 or end in order to leave the confi"uration mode. The hostname# prompt appears. 2'. T$pe write eory or copy runnin&-con%i& startup-con%i& in order to commit the chan"es. Procedure 2 Complete these steps in order to recover $our password: 1. Shut down the router. 2. Remove the compact flash that is at the bac% of the router. 3. 'ower on the router. !. 4nce the Rommon1> prompt appears& enter this command: $. confreg 0x2142 ). #nsert the compact flash. *. T$pe reset. +. =hen $ou are prompted to enter the initial configuration& t$pe No& and press 1nter. ,. At the Router> prompt& t$pe enable. 1'. At the Router# prompt& enter the con%i&ure eory command& and press 1nter in order to cop$ the startup confi"uration to the runnin" confi"uration. 11. (se the con%i& t command in order to enter "lobal confi"uration mode. 12. (se this command in order to create a new user name and password: 13. router(config)#username cisco privilege 15 password 1!. cisco 1$. (se this command in order to chan"e the boot statement: 1). config-register 1*. 0x2102 1+. (se this command in order to save the confi"uration: 1,. write 2'. memory 21. Reload the router& and then use the new user name and password to lo" in to the router. 1(aple o% Password Recovery Procedure This section provides an e3ample of the password recover$ procedure. This e3ample was created with a Cisco 2600 Series Router. 2ven if $ou do not use a Cisco 2600 Series Router& this output provides an e3ample of what $ou should e3perience on $our product. Router>enable Password: Password: Password: % Bad secrets Router>show version Cisco Internetwork !erating "#stem "oftware I" (tm) C2$%% "oftware (C2$%%&I"&')( )ersion 12*%(+),( R-.-/"- "0,1/R- (fc2) Co!#right (c) 123$&1222 4# cisco "#stems( Inc* Com!i5ed ,ue %+&6ec&22 %2:21 4# !hangu#e Image te7t&4ase: %73%%%3%33( data&4ase: %73%C82903 R': "#stem Bootstra!( )ersion 11*:(2);/9( R-.-/"- "0,1/R- (fc1) Router u!time is : minutes "#stem returned to R' 4# a4ort at PC %73%26%B$% "#stem image fi5e is <f5ash:c2$%%&is&m=*12%&+*,< cisco 2$11 ('PC3$%) !rocessor (re>ision %72%2) with 2$$29?@$199? 4#tes of memor#* Processor 4oard I6 A/B%:12%2B? (:3+31332$:) '3$% !rocessor: !art num4er %( mask 92 Bridging software* ;*28 software( )ersion :*%*%* Basic Rate I"6B software( )ersion 1*1* 2 -thernet@I--- 3%2*: interface(s) 2 "eria5(s#nc@as#nc) network interface(s) 1 I"6B Basic Rate interface(s) :2? 4#tes of non&>o5ati5e configuration memor#* 3122? 4#tes of !rocessor 4oard "#stem f5ash !artition 1 (Read@1rite) 3122? 4#tes of !rocessor 4oard "#stem f5ash !artition 2 (Read@1rite) Configuration register is 0x2102 Router> !--- The router was just powercycled, and during bootup a !--- break sequence was sent to the router. C DDD "#stem recei>ed an a4ort due to Break ?e# DDD signa5E %7:( codeE %78%%( conte7tE %731:ac183 PC E %73%2d%4$%( )ector E %78%%( "P E %73%%%$%:% rommon 1 > confreg 0x2142 Fou must reset or !ower c#c5e for new config to take effect rommon 2 > reset "#stem Bootstra!( )ersion 11*:(2);/9( R-.-/"- "0,1/R- (fc1) Co!#right (c) 1222 4# cisco "#stems( Inc* ,/C:Gome:"1:I":"!ecia5s for info C2$%% !5atform with :2+$3 ?4#tes of main memor# !rogram 5oad com!5ete( entr# !oint: %73%%%3%%%( si=e: %7$fd49c "e5f decom!ressing the image : ############################### ############################################################## ############################################################## ############################################################## ############################### H?I Restricted Rights .egend Jse( du!5ication( or disc5osure 4# the Ko>ernment is su4Lect to restrictions as set forth in su4!aragra!h (c) of the Commercia5 Com!uter "oftware & Restricted Rights c5ause at 0/R sec* 82*22+&12 and su4!aragra!h (c) (1) (ii) of the Rights in ,echnica5 6ata and Com!uter "oftware c5ause at 60/R" sec* 282*22+&+%1:* cisco "#stems( Inc* 1+% 1est ,asman 6ri>e "an Aose( Ca5ifornia 281:9&1+%$ Cisco Internetwork !erating "#stem "oftware I" (tm) C2$%% "oftware (C2$%%&I"&')( )ersion 12*%(+),( R-.-/"- "0,1/R- (fc2) Co!#right (c) 123$&1222 4# cisco "#stems( Inc* Com!i5ed ,ue %+&6ec&22 %2:21 4# !hangu#e Image te7t&4ase: %73%%%3%33( data&4ase: %73%C82903 cisco 2$11 ('PC3$%) !rocessor (re>ision %72%2) with 2$$29?@$199? 4#tes of memor#* Processor 4oard I6 A/B%:12%2B? (:3+31332$:) '3$% !rocessor: !art num4er %( mask 92 Bridging software* ;*28 software( )ersion :*%*%* Basic Rate I"6B software( )ersion 1*1* 2 -thernet@I--- 3%2*: interface(s) 2 "eria5(s#nc@as#nc) network interface(s) 1 I"6B Basic Rate interface(s) :2? 4#tes of non&>o5ati5e configuration memor#* 3122? 4#tes of !rocessor 4oard "#stem f5ash !artition 1 (Read@1rite) 3122? 4#tes of !rocessor 4oard "#stem f5ash !artition 2 (Read@1rite) &&& "#stem Configuration 6ia5og &&& 1ou5d #ou 5ike to enter the initia5 configuration dia5ogM H#es@noI: n Press R-,JRB to get startedC %%:%%:12: %.IB?&:&JP61B: Interface BRI%@%( changed state to u! %%:%%:12: %.IB?&:&JP61B: Interface -thernet%@%( changed state to u! %%:%%:12: %.IB?&:&JP61B: Interface -thernet%@1( changed state to u! %%:%%:12: %.IB?&:&JP61B: Interface "eria5%@%( changed state to down %%:%%:12: %.IB?&:&JP61B: Interface "eria5%@1( changed state to down %%:%%:2%: %.IB-PR,&8&JP61B: .ine !rotoco5 on Interface BRI%@%( changed state to down %%:%%:2%: %.IB-PR,&8&JP61B: .ine !rotoco5 on Interface -thernet%@%( changed state to u! Router> %%:%%:2%: %.IB-PR,&8&JP61B: .ine !rotoco5 on Interface -thernet%@1( changed state to u! %%:%%:2%: %.IB-PR,&8&JP61B: .ine !rotoco5 on Interface "eria5%@%( changed state to down %%:%%:2%: %.IB-PR,&8&JP61B: .ine !rotoco5 on Interface "eria5%@1( changed state to down %%:%%:8%: %"F"&8&R-",/R,: "#stem restarted && Cisco Internetwork !erating "#stem "oftware I" (tm) C2$%% "oftware (C2$%%&I"&')( )ersion 12*%(+),( R-.-/"- "0,1/R- (fc2) Co!#right (c) 123$&1222 4# cisco "#stems( Inc* Com!i5ed ,ue %+&6ec&22 %2:21 4# !hangu#e %%:%%:8%: %.IB?&8&CG/BK-6: Interface BRI%@%( changed state to administrati>e5# down %%:%%:82: %.IB?&8&CG/BK-6: Interface -thernet%@%( changed state to administrati>e5# down %%:%%:82: %.IB?&8&CG/BK-6: Interface "eria5%@%( changed state to administrati>e5# down %%:%%:82: %.IB?&8&CG/BK-6: Interface -thernet%@1( changed state to administrati>e5# down %%:%%:82: %.IB?&8&CG/BK-6: Interface "eria5%@1( changed state to administrati>e5# down %%:%%:8:: %.IB-PR,&8&JP61B: .ine !rotoco5 on Interface -thernet%@%( changed state to down %%:%%:8:: %.IB-PR,&8&JP61B: .ine !rotoco5 on Interface -thernet%@1( changed state to down Router> Router>enable Router#copy startup-config running-config 6estination fi5ename Hrunning&configIM 1:29 4#tes co!ied in 2*:8 secs ($$2 4#tes@sec) Router# %%:%1:29: %.IB-PR,&8&JP61B: .ine !rotoco5 on Interface BRI%@%:1( changed state to down %%:%1:29: %.IB-PR,&8&JP61B: .ine !rotoco5 on Interface BRI%@%:2( changed state to down Router#configure terminal -nter configuration commands( one !er 5ine* -nd with CB,.@N* Router(config)#enable secret < password Router(config)#!" %%:%1:89: %"F"&8&CB0IKOI: Configured from conso5e 4# conso5e Router#show ip interface brief Interface IP&/ddress ?M 'ethod "tatus Protoco5 -thernet%@% 1%*2%%*9%*:+ F-" ,0,P administratively down down "eria5%@% unassigned F-" ,0,P administratively down down BRI%@% 12:*281*121*18+ F-" unset administratively down down BRI%@%:1 unassigned F-" unset administratively down down BRI%@%:2 unassigned F-" unset administratively down down -thernet%@1 unassigned F-" ,0,P administratively down down "eria5%@1 unassigned F-" ,0,P administratively down down .oo!4ack% 12:*281*121*18+ F-" ,0,P u! u! Router#configure terminal -nter configuration commands( one !er 5ine* -nd with CB,.@N* Router(config)#interface #thernet0$0 Router(config&if)#no shutdown Router(config&if)# %%:%2:19: %.IB?&:&JP61B: Interface -thernet%@%( changed state to u! %%:%2:18: %.IB-PR,&8&JP61B: .ine !rotoco5 on Interface -thernet%@%( changed state to u! Router(config&if)#interface %&'0$0 Router(config&if)#no shutdown Router(config&if)# %%:%2:2$: %.IB?&:&JP61B: Interface BRI%@%:1( changed state to down %%:%2:2$: %.IB?&:&JP61B: Interface BRI%@%:2( changed state to down %%:%2:2$: %.IB?&:&JP61B: Interface BRI%@%( changed state to u! %%:%2:1182$911$221: %I"6B&$&./F-R2JP: .a#er 2 for Interface BR%@%( ,-I $3 changed to u! Router(config&if)#!" Router# %%:%2::8: %"F"&8&CB0IKOI: Configured from conso5e 4# conso5e Router#copy running-config startup-config 6estination fi5ename Hstartu!&configIM Bui5ding configuration*** H?I Router#show version Cisco Internetwork !erating "#stem "oftware I" (tm) C2$%% "oftware (C2$%%&I"&')( )ersion 12*%(+),( R-.-/"- "0,1/R- (fc2) Co!#right (c) 123$&1222 4# cisco "#stems( Inc* Com!i5ed ,ue %+&6ec&22 %2:21 4# !hangu#e Image te7t&4ase: %73%%%3%33( data&4ase: %73%C82903 R': "#stem Bootstra!( )ersion 11*:(2);/9( R-.-/"- "0,1/R- (fc1) Router u!time is : minutes "#stem returned to R' 4# a4ort at PC %73%26%B$% "#stem image fi5e is <f5ash:c2$%%&is&m=*12%&+*,< cisco 2$11 ('PC3$%) !rocessor (re>ision %72%2) with 2$$29?@$199? 4#tes of memor#* Processor 4oard I6 A/B%:12%2B? (:3+31332$:) '3$% !rocessor: !art num4er %( mask 92 Bridging software* ;*28 software( )ersion :*%*%* Basic Rate I"6B software( )ersion 1*1* 2 -thernet@I--- 3%2*: interface(s) 2 "eria5(s#nc@as#nc) network interface(s) 1 I"6B Basic Rate interface(s) :2? 4#tes of non&>o5ati5e configuration memor#* 3122? 4#tes of !rocessor 4oard "#stem f5ash !artition 1 (Read@1rite) 3122? 4#tes of !rocessor 4oard "#stem f5ash !artition 2 (Read@1rite) Configuration register is %72192 Router#configure terminal -nter configuration commands( one !er 5ine* -nd with CB,.@N* Router(config)#config-register 0x2102 Router(config)#PN %%:%::2%: %"F"&8&CB0IKOI: Configured from conso5e 4# conso5e Router#show version Cisco Internetwork !erating "#stem "oftware I" (tm) C2$%% "oftware (C2$%%&I"&')( )ersion 12*%(+),( R-.-/"- "0,1/R- (fc2) Co!#right (c) 123$&1222 4# cisco "#stems( Inc* Com!i5ed ,ue %+&6ec&22 %2:21 4# !hangu#e Image te7t&4ase: %73%%%3%33( data&4ase: %73%C82903 R': "#stem Bootstra!( )ersion 11*:(2);/9( R-.-/"- "0,1/R- (fc1) Router u!time is : minutes "#stem returned to R' 4# a4ort at PC %73%26%B$% "#stem image fi5e is <f5ash:c2$%%&is&m=*12%&+*,< cisco 2$11 ('PC3$%) !rocessor (re>ision %72%2) with 2$$29?@$199? 4#tes of memor#* Processor 4oard I6 A/B%:12%2B? (:3+31332$:) '3$% !rocessor: !art num4er %( mask 92 Bridging software* ;*28 software( )ersion :*%*%* Basic Rate I"6B software( )ersion 1*1* 2 -thernet@I--- 3%2*: interface(s) 2 "eria5(s#nc@as#nc) network interface(s) 1 I"6B Basic Rate interface(s) :2? 4#tes of non&>o5ati5e configuration memor#* 3122? 4#tes of !rocessor 4oard "#stem f5ash !artition 1 (Read@1rite) 3122? 4#tes of !rocessor 4oard "#stem f5ash !artition 2 (Read@1rite) Configuration register is %72192 (wi55 4e 0x2102 at ne7t re5oad) Router#