Configuring Username and Password Security

 

Front-Panel Security

 

 

C a u t i o n

Disabling password-recoveryrequires that factory-resetbe enabled, and locks

 

out the ability to recover a lost manager username (if configured) and pass­

 

word on the switch. In this event, there is no way to recover from a lost

 

manager username/password situation without resetting the switch to its

 

factory-default configuration. This can disrupt network operation and make

 

it necessary to temporarily disconnect the switch from the network to prevent

 

unauthorized access and other problems while it is being reconfigured. Also,

 

with factory-resetenabled, unauthorized users can use the Reset+Clear button

 

combination to reset the switch to factory-default configuration and gain

 

management access to the switch.

 

 

Syntax: [no] front-panel-security password-recovery

Enables or (using the “no” form of the command) disables the ability to recover a lost password.

When this feature is enabled, the switch allows management access through the password recovery process described below. This provides a method for recovering from a lost manager username (if configured) and password. When this feature is disabled, the password recovery process is disabled and the only way to regain management access to the switch is to use the Reset+Clear button combination (page 2-25)to restore the switch to its factory default configuration.

Note: To disable password-recovery:

–You must have physical access to the front panel of the switch.

The factory-resetparameter must be enabled (the default).

(Default: Enabled.)

Steps for Disabling Password-Recovery.

1.Set the CLI to the global interface context.

2.Use show front-panel-securityto determine whether the factory-reset parameter is enabled. If it is disabled, use the front-panel-security factory- reset command to enable it.

3.Press and release the Clear button on the front panel of the switch.

4.Within 60-seconds of pressing the Clear button, enter the following com­ mand:

no front-panel-security password-recovery

5.Do one of the following after the “CAUTION” message appears:

• If you want to complete the command, press [Y] (for “Yes”).

2-33