Cisco Switching/Routing :: Password Recovery For 6509 Switch?
May 16, 2010
I have one CISCO 6509 Switch in my store. I tired to login in that switch but couldnt.. Once it's booted it's asking me: rd: . Find the attachment. I recover the password by changing confreg value but that also failed.
I am trying to use the password recovery for an NME-16 and am having trouble. I am unable to look at my files in dir to so I can rename them. I can get the switch to bypass the config and come with the switch: prompt, but can not do anything more. I am trying the password recovery guide, but cant get to the text file to rename. I am using a 2811 router.
I can see the console on the router. (Using the USB console connected to a Macintosh.) I was configuring the router though this console connection, and I created a new user (priv level 15) and removed the default 'cisco' user. So I'm stuck at the username/password login prompt now.
I decided to do the password recovery procedure (via the cisco doc I found etc), but I cannot break into ROMMON during the boot process. I'm not sure if that's because my Mac isn't sending the break, or what.
The pw recovery doc says you can "remove flash" if you can't break into the boot sequence. However, I cannot find any instructions on how to remove the flash. I've opened the router, and I see one very small daughter card on the main board that I think is the flash, but I'm not about to start arbitrarly prying parts off.
i just wanna know if it's possible to perform a router password recovery using the reload command and then issue the break sequence instead of doing an off/on on the power switch. i often find in the docs to use the latter.also, is there a way to retain the startup-config on a router when we re-enable the password recovery functionality (no service password-recovery). i've just tried this on one of our 877 and when i hit the break sequence, it went back to factory default setting.
I understand that the password has to be changed the first time we login to Cisco 3945 router but i failed to do that and its not allowing me to connect using default username/password.
I need to break into a 2901 router to recover the passwords. Cisco's methodology for password recovery on 2900 seriews routerssays to remove the compact flash card and reboot into RMON. There is no external compact flash card on a 2901. Is there acompact flash card inside the box? Or can you use the older method of rebooting and then hitting ctl+break to boot into RMON?
I have a major problem with our core 2801 router. In summary it appears that a staff member disabled password recovery, deleted the IOS and rebooted. Net result is no Rommon and no IOS on the flash. I've read that the Conf-Reg will be reset if I remove the NVRAM but I cannot identify it on the board. If I can get to Rommon I can recover. Currently I don't have Flash reader to restore to flash.
i read alot about password recovery , but when i apply it to cisco 7604 it fails ?i went to rommon mode and typed# confreg 0x2142 then i typed reset when the router startup it request a password form me ,i can enter the user mode , and when i type sh ver command i note that the config resgitser is 0x2102 , not 0x2142 !!!!
i could enter the privilage mode !!!! and seems no thing changed ! does this router has a specific password recovery procedure ? which differes than the classic procedure?
I have catalys 4507 with TWO supervisor V.I flowed this procedure : url...
after the reset normaly i can change the password and i check the confreg is 0X2142 but it still ask to enter the possword should i remove 1 supervisor and do the procedure or i must let the two spuervisor?
I have 2 x 6513 each with dual supervisor 720, and need to recover the enable password, is there a better method than removing one supervisor, disabling redundancy and performing password recovery on the single active supervisor module , before re-inserting the second supervisor and re-enabling SSO/RPR on the still active module.
Im trying to access the switch to reset the password to factory defaults (please see switch output Astrix has removed customer identifying information for security purposes.) Each time I reboot the switch and try and access the password recover mode this same output below starts and im still not able to access the recovery area of the switch
cisco WS-C3560G-48PS (PowerPC405) processor (revision F0) with 122880K/8184K bytes of memory. Processor board ID FOC1133Y28Q
I enabled the "no service password-recovery" command on my C2960 switch. All seems to work as discribed. Only issue I have is --- which show command is used to reveal if the password-recovery feature is enabled of disabled as the command doesn't show up in the running config after you enable it ?
NOTE: The command does show up in the C2960 switch in config t mode (unlike the IOS router 2800 series), but doesn't show up in the running-config after you enable or disable it.
On the 2800 series routers (latest IOS) in config t mode the command does not show up but if you type "no service passowrd-recovery" the command function correctly and it does list it in the running configuration.
I'm trying to do password recovery on a Catalyst 3850 switch..I've read the section in this: url...where it says that I need to have physical access to the switch (I do), and that I reset the password if I issue a break command and interrupt the boot procedure. I've tried to do that... it gives me the "switch:" prompt, so I think I've interrupted the boot procedure successfully, but, what do I do next?I've successfully done recoveries on Catalyst 2950s, 3550s & 3560s, but the procedure for this one, if I'm reading the link above right, sounds like it's completely different.
i need to recover a router Cisco 2801. I lost the password and the "no service password-recovery" is configured. I have done many attempts with the procedure in this link :URL
I am trying to use a Tekradius Windows2008 server to aaa authenticate switch admin logins. The Radius server and 6509 loop0 are in a management VRF "netman". I can happily ping to and from the Server and loopback0 interface without issue. I have also tested the radius server account using RadiusNT on a workstation. I get an accept reply with the following variables..
shell:priv-lvl=15 NAS-Prompt
Here are the relevant parts of my config as far as I can see..
aaa new-model aaa group server radius SRADIUS server-private 192.168.1.101 auth-port 1812 acct-port 1813 key cisco ip vrf forwarding netman ip radius source-interface Loopback0 ! aaa authentication login default group SRADIUS local
Im having a strange problem on a 6509 switch. I am trying to use a Tekradius Windows2008 server to aaa authenticate switch admin logins. The Radius server and 6509 loop0 are in a management VRF "netman". I can happily ping to and from the Server and loopback0 interface without issue. I have also tested the radius server account using RadiusNT on a workstation. [code]
I have a 6509 running catOS that i had to do some routing changes on this weekend. I guess i forgot to set the default route so now I can't login or ping from outside the local subnet and because of acl restrictions on the vty lines can't login from a device within the local subnet. I can login to the sup module so i'm trying to figure out if there is way to get to the switch from the sup like you would access the sup from the switch by inputting the command session 15 or session 16, is there a way to do the reverse to get to the switch from the sup?
I have number of 6500 switches and we are in the process of getting support contract renewed now when i buy support for my 6500 series switches i have to inform main module serial numbers (Only this one). or do i also have to inform about sub module serial numbers to my support vendor?
Suffered a big outage on the network, the fix was to reload the module 3 on the 6509 switch, we had these errors on the log %CONST_DIAG-SW1_SP-3-HM_PORT_TEST_FAIL: Switch 1 Module 3 TestUnusedPortLoopback Port(s)[24,46] failed. System operation continues.in the end, we reloaded the card and it was all ok. is there anything I can do to check the card / or any deeper logs? would that error cause the card to crash?
I have a 6509-E chassis that was prevoius in a VSS configuration. Due to some VSL failures I had to cobvert it to a standalone chassis but would like to bring it back to a virtual system.
Whenever I try to convert it by using the command "switch convert mode virtual" I get the msg %Please configure local switch number first". After doing so by entering the CLI cmd "switch set switch_num 1 local" I still get the same message.
I have a 6509 that has dual SUP32's.Just want to make sure and give a reason(if there is one). Slot 6 always becomes the active hot on a full reboot. Meaning from no power to the whole switch to powered on. What is the election process for Supervisors?
If I dual connect my access switch to my 6509s running vss, what will happen, will spanning tree still block one of the ports if I don't set up an etherchannel?
I was trying to uplink a switch today on a 1500m run of SMF. I have a 6509 core switch with a 16 port GBIC module. On that end I have a WS-G5486-LX with a 3m SC to LC patch cable.On the other end I have a 3750G with a GLC-LH-SM SFP. I have checked my fiber path and it seems good, (by sight, did not have an OTDR avialable).I can't get the link up at all. Tried swapping Tx Rx at one end, Tried different transceivers. Tried different patch cables. Nothing worked. At about the mid-point of my fiber run the cable passes through another network closet with a core switch for a separate network. If I break my fiber path there and try to connect in either direction it works. The only differences are the length of the fiber run and that the core switch on the other network has a CLC-LX-SM SFP.Is it the distance? Or is there some issue connecting a GLC-LH-SM to a WS-G5486-LX?
i have one of my switch modules that shows PwrDown when i issue the command show mod.
Mod Ports Card Type Model Serial No. --- ----- -------------------------------------- ------------------ ----------- 1 9 Supervisor Engine 32 8GE (Active) WS-SUP32-GE-3B SAD09120263 2 48 48 port 10/100/1000mb EtherModule WS-X6148-GE-TX SAL1029VWZ5
[Code]....
i tried disabling the diagnostic monitor for the module, did a power enable module command and then reset it but it still fails. this is the third blade that i am replacing in a few weeks and i still get the same error. i am persuded that it is not a hardware since it is the third blade in a matter of weeks. after the module reset, i receive this error % module 3 is operationally off (FRU-power failed)
could an ios upgrade solve this issue? are there any ios related bugs?
We have a network of 30 VLANS and currently all the vlans have access to everything. We are using Cisco 6509 switch for Layer3 routing.I would like to prevent some VLANs accessing the server VLANs. How can I restrict access to the server VLANs?Do i need to implement access-lists on the 6500 switch? or do i need to create VLANS on the firewall so that all traffic i filtered ?