C-9
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Appendix C Troubleshooting
Password Recovery
-------------------------------------------
Use the ^ and v keys to select which entry is highlighted.
Press enter to boot the selected OS, 'e' to edit the
Commands before booting, or 'c' for a command-line.
Highlighted entry is 0:
Step 2
Press any key to pause the boot process.
Step 3
Choose
2: Cisco IPS Clear Password (cisco)
. The password is reset to cisco. Log in to the CLI with
username cisco and password cisco. You can then change the password.
Using ROMMON
For the IPS 4345 IPS 4360, IPS 4510, and IPS 4520, you can use the ROMMON to recover the
password. To access the ROMMON CLI, reboot the sensor from a terminal server or direct connection
and interrupt the boot process.
To recover the password using the ROMMON CLI, follow these steps:
Step 1
Reboot the appliance.
Step 2
To interrupt the boot process, press ESC or Control-R (terminal server) or send a BREAK command
(direct connection). The boot code either pauses for 10 seconds or displays some thing similar to one of
the following:
Evaluating boot options
Use BREAK or ESC to interrupt boot
Step 3
Enter the following commands to reset the password:
confreg 0x7
boot
Sample ROMMON session:
Booting system, please wait...
CISCO SYSTEMS
Embedded BIOS Version 1.0(11)2 01/25/06 13:21:26.17
...
Evaluating BIOS Options...
Launch BIOS Extension to setup ROMMON
Cisco Systems ROMMON Version (1.0(11)2) #0: Thu Jan 26 10:43:08 PST 2006
Platform IPS-4360-K9
Use BREAK or ESC to interrupt boot.
Use SPACE to begin boot immediately.
Boot interrupted.
Management0/0
Link is UP
MAC Address:000b.fcfa.d155
Use ? for help.
rommon #0> confreg 0x7
Update Config Register (0x7) in NVRAM...
rommon #1> boot