C-8
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
AppendixC Troubleshooting
Password Recovery
Verifying the State of Password Recovery, pageC-14
Troubleshooting Password Recovery, page C-14
Understanding Password Recovery
Note
Administrators may need to disable the password recovery feature for security reasons.
Password recovery implementations vary according to IPS platform requirem ents. Password recovery is
implemented only for the cisco administrative account and is enabled by default. The IPS administrator
can then recover user passwords for other accounts using the CLI. The cisco user password reverts to
cisco and must be changed after the next login.
Tabl e C-1 lists the password recovery methods according to platf orm.
Recovering the Password for the Appliance
This section describes the two ways to recover the password for appliances. It contains the following
topics:
Using the GRUB Menu, page C-8
Using ROMMON, pageC-9

Using the GRUB Menu

Note
You must have a terminal server or direct serial connection to the appliance to use the GRUB menu to
recover the password.
For the IPS 4355, IPS 4360, IPS 4510, and IPS 4520 applian ces, the password recovery is found in the
GRUB menu, which appears during bootup. When the GRUB menu appears, press any key to pause the
boot process.
To recover the password on appliances, follow these steps:
Step 1
Reboot the appliance to see the GRUB menu.
GNU GRUB version 0.94 (632K lower / 523264K upper memory)
-------------------------------------------
0: Cisco IPS
1: Cisco IPS Recovery
2: Cisco IPS Clear Password (cisco)
TableC-1 Password Recovery Methods According to Platform
Platform Description Recovery Method
4300 series sensors
4500 series sensors
Standalone IPS appliances GRUB prompt or ROMMON
ASA 5500-X IPS SSP
ASA 5585-X IPS SSP
ASA 5500 series adaptive
security appliance IPS modules
Adaptive security appliance CLI
command