17-4
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter17 Administrative Tasks for the Sensor
Recovering the Password

Using ROMMON

For the IPS 4345, IPS 4360, IPS 4510, and IPS 4520, you c an use the ROMMON to recover the
password. To access the ROMMON CLI, reboot the sensor from a terminal server or direct connection
and interrupt the boot process.
To recover the password using the ROMMON CLI, follow these steps:
Step 1
Reboot the appliance.
Step 2
To interrupt the boot process, press ESC or Control-R (terminal server) or send a BREAK command
(direct connection). The boot code either pauses for 10 seconds or displays some thing similar to one of
the following:
Evaluating boot options
Use BREAK or ESC to interrupt boot
Step 3
Enter the following commands to reset the password:
confreg 0x7
boot
Sample ROMMON session:
Booting system, please wait...
CISCO SYSTEMS
Embedded BIOS Version 1.0(11)2 01/25/06 13:21:26.17
...
Evaluating BIOS Options...
Launch BIOS Extension to setup ROMMON
Cisco Systems ROMMON Version (1.0(11)2) #0: Thu Jan 26 10:43:08 PST 2006
Platform IPS-4360-K9
Use BREAK or ESC to interrupt boot.
Use SPACE to begin boot immediately.
Boot interrupted.
Management0/0
Link is UP
MAC Address:000b.fcfa.d155
Use ? for help.
rommon #0> confreg 0x7
Update Config Register (0x7) in NVRAM...
rommon #1> boot
Recovering the Password for the ASA 5500-X IPS SSP
You can reset the password to the default (cisco) for the ASA5500-X IPS SSP using the CLI or the
ASDM. Resetting the password causes it to reboot. IPS services are not available during a reboot.
Note
To reset the password, you must have ASA 8.6.1 or later.
Use the sw-module module ips password-reset command to reset the password to the default cisco. If
the module in the specified slot has an IPS version that does not support password recovery, the
following error message is displayed:
ERROR: the module in slot <n> does not support password recovery.