Este documento descreve como recuperar uma senha nos Catalyst 6500/6000 Series Switches e nos Cisco 7600 Series Routers que executam o Cisco IOS® System Software.
Não existem requisitos específicos para este documento.
Este documento se aplica aos sistemas baseados no Supervisor 1, Supervisor 2, Supervisor 720 e Sistema de Comutação Virtual (VSS - Virtual Switching System) 1440. Para sistemas baseados no Supervisor 720, este documento se aplica quando executa o Cisco IOS Software Release 12.2(17)SX ou posterior. Se o Supervisor 720 executar uma versão anterior a esta, consulte o Procedimento de Recuperação de Senha para o Catalyst 6500 com Supervisor 720 Executando o Software do Sistema Cisco IOS anteriores a 12.2(17)SX.
Observação: o software suportado para sistemas baseados no Virtual Switching System (VSS) 1440 é o Cisco IOS® Software Release 12.2(33)SXH1 ou posterior.
A sequência de inicialização é diferente no Catalyst 6500/6000 e no Cisco 7600 que executam o Cisco IOS System Software do que no Cisco 7200 Series Router porque o hardware é diferente. Depois de desligar e desligar a caixa, o processador do switch (SP) é inicializado primeiro. Após um curto período de tempo (aproximadamente 25 a 60 segundos), ele transfere a propriedade do console para o processador de rota (RP (MSFC)). O RP continua carregando a imagem do software em pacote. É crucial que você pressione Ctrl-brk logo após a controladora de armazenamento entregar o controle do console ao RP. Se você enviar a sequência de interrupção muito cedo, acabará no ROMMON da controladora de armazenamento, que não é onde deveria estar. Envie a sequência de interrupção depois de ver esta mensagem no console:
00:00:03: %OIR-6-CONSOLE: Changing console ownership to route processor
Após este ponto, a recuperação da senha é feita da mesma maneira que em um roteador normal.
Observação: desse ponto em diante, o Switch Catalyst 6000 Series que executa o Cisco IOS System Software é conhecido como roteador.
For more information on document conventions, refer to the Cisco Technical Tips Conventions.
O switch é configurado como um roteador devido ao sistema operacional que é executado no switch. O procedimento de recuperação de senha segue as mesmas etapas de um Cisco 7200 Series Router, exceto que você precisa esperar aproximadamente 25 a 60 segundos mais antes de iniciar a sequência de interrupção.
Conecte um terminal ou PC com emulação de terminal à porta de console do roteador. Utilize estas configurações de terminal:
9600 baud rate No parity 8 data bits 1 stop bit No flow control
As especificações do cabo do console necessário estão descritas no documento Especificações do cabo. As instruções sobre como se conectar à porta do console estão no Guia de Instalação do Módulo. A seção Conexão à porta de console—Somente Supervisor Engine fornece informações úteis.
Se você ainda tem acesso ao roteador, emita o comando show version e registre a definição do registro de configuração. Geralmente é 0x2102 ou 0x102. Clique aqui para ver a saída de um comando show version.
Se você não tiver acesso ao roteador (devido a um login perdido ou a uma senha TACACS), seu registro de configuração será definido como 0x2102.
Desligue o roteador e ligue-o novamente com a ajuda do botão liga/desliga.
Cuidado: a sequência de interrupção deve ser iniciada somente após o RP ganhar o controle da porta de console.
Pressione Break no teclado do terminal logo após o RP ganhar o controle da porta do console. No Catalyst 6000 que executa o Cisco IOS Software, o SP é inicializado primeiro. Depois de inicializar, ele transfere o controle para o RP. Depois que o RP ganhar controle, inicie a sequência de interrupção. O RP ganha controle da porta de console quando você vê esta mensagem. (Não inicie a seqüência de break até ver esta mensagem):
00:00:03: %OIR-6-CONSOLE: Changing console ownership to route processor
A partir desse ponto, o procedimento de recuperação de senha é o mesmo que para qualquer outro roteador. Se a sequência de interrupção não funcionar, consulte as Combinações de Sequência de Teclas de Interrupção Padrão Durante a Recuperação de Senha para obter outras combinações de teclas.
Digite confreg 0x2142 no prompt ROMMON 1> para inicializar a partir da flash sem carregar a configuração.
Digite reset no prompt rommon 2>.
O roteador é reinicializado. No entanto, ele ignora a configuração salva.
Digite no depois de cada pergunta da configuração ou pressione Ctrl-C para pular o procedimento inicial de configuração.
Digite enable no prompt Router>.
Você está no modo enable e vê o prompt Router#.
Importante: Emita os comandos configure memory ou copy start running para copiar a RAM não volátil (NVRAM) na memória. Não emita o comando configure terminal.
Emita o comando write terminal ou show running.
Os comandos show running e write terminal apresentam a configuração do roteador. Nessa configuração, você vê em todas as interfaces o comando shutdown. Isso significa que todas as interfaces estão desligadas no momento.Você vê as senhas no formato criptografado ou não criptografado.
Emita o comando configure terminal para entrar no modo de configuração global e fazer as alterações.
O prompt agora é hostname(config)#.
Emita o comando enable secret < senha > no modo de configuração global para alterar a senha enable.
Emita o comando config-register 0x2102 ou o valor registrado na Etapa 2 em modo de configuração global (Router(config)#) para redefinir o valor da configuração para seu valor original.
Altere as senhas do terminal virtual, se presentes:
Router(config)#line vty 0 4 Router(config-line)#password cisco Router(config-line)#^Z Router#
Emita o comando no shutdown em todas as interfaces que estão normalmente em uso. Emita um comando show ip interface brief para ver uma lista de interfaces e seu status atual. Você deve estar em modo de habilitação (Roteador#) para executar o comando show ip interface brief. Aqui está um exemplo de uma interface:
Router#show ip interface brief Interface IP-Address OK? Method Status Prol Vlan1 172.17.10.10 YES TFTP administratively down dow Vlan10 10.1.1.1 YES TFTP administratively down dow GigabitEthernet1/1 unassigned YES unset administratively down dow GigabitEthernet1/2 unassigned YES TFTP administratively down dow GigabitEthernet2/1 unassigned YES TFTP administratively down dow GigabitEthernet2/2 unassigned YES TFTP administratively down dow FastEthernet3/1 172.16.84.110 YES TFTP administratively down dow <snip>... Router#configure terminal Enter configuration commands, one per line. End with CNTL/Z. Router(config)#interface fastEthernet 3/1 Router(config-if)#no shutdown Router(config-if)#exit Router(config)# <do other interfaces as necessary...>
Pressione Ctrl-Z para sair do modo de configuração.
O prompt agora é hostname#.
Emita os comandos write memory ou copy running startup para confirmar as alterações.
O exemplo aqui mostra um procedimento real de recuperação de senha. Este exemplo é criado com a ajuda de um switch Catalyst 6000 Series. Comece com os comandos show version e show module para ver quais componentes são usados neste exemplo.
Press RETURN to get started. Router>enable Password: Router#show version Cisco Internetwork Operating System Software IOS (tm) c6sup1_rp Software (c6sup1_rp-JSV-M), Version 12.1(6)E, EARLY DEPLOYME) TAC Support: http://www.cisco.com/cgi-bin/ibld/view.pl?i=support Copyright (c) 1986-2001 by cisco Systems, Inc. Compiled Sat 17-Mar-01 00:14 by eaarmas Image text-base: 0x60020950, data-base: 0x6165E000 ROM: System Bootstrap, Version 12.0(3)XE, RELEASE SOFTWARE BOOTFLASH: MSFC Software (C6MSFC-BOOT-M), Version 12.1(6)E, EARLY DEPLOYMENT RE) Router uptime is 14 minutes System returned to ROM by power-on (SP by reload) System image file is "sup-bootflash:c6sup11-jsv-mz.121-6.E" Cisco Catalyst 6000 (R5000) processor with 114688K/16384K bytes of memory. Processor board ID SAD04281AF6 R5000 CPU at 200Mhz, Implementation 35, Rev 2.1, 512KB L2 Cache Last reset from power-on Bridging software. X.25 software, Version 3.0.0. SuperLAT software (copyright 1990 by Meridian Technology Corp). TN3270 Emulation software. 24 Ethernet/IEEE 802.3 interface(s) 2 Virtual Ethernet/IEEE 802.3 interface(s) 48 FastEthernet/IEEE 802.3 interface(s) 4 Gigabit Ethernet/IEEE 802.3 interface(s) 381K bytes of non-volatile configuration memory. 4096K bytes of packet SRAM memory. 16384K bytes of Flash internal SIMM (Sector size 256K). Configuration register is 0x2102 Router# Router#show module Slot Ports Card Type Model Serial Number ---- ----- ----------------------------------------- --------------------- ----------- 1 2 Cat 6000 sup 1 Enhanced QoS (active) WS-X6K-SUP1A-2GE SAD043301JS 2 2 Cat 6000 sup 1 Enhanced QoS (standby) WS-X6K-SUP1A-2GE SAD03510114 3 48 48 port 10/100 mb RJ45 WS-X6348-RJ-45 SAD04230FB6 6 24 24 port 10baseFL WS-X6024-10FL-MT SAD03413322 Slot MAC addresses Hw Fw Sw ---- ---------------------------------- ----- ------------ ---------- 1 00d0.c0d2.5540 to 00d0.c0d2.5541 3.2 unknown 6.1(0.105)OR 2 00d0.bcf1.9bb8 to 00d0.bcf1.9bb9 3.2 unknown 6.1(0.105)OR 3 0002.7ef1.36e0 to 0002.7ef1.370f 1.1 5.3(1) 1999- 6.1(0.105)OR 6 00d0.9738.5338 to 00d0.9738.534f 0.206 5.3(1) 1999- 6.1(0.105)OR Router# Router#reload Proceed with reload? [confirm] !--- Here you turn off the power and then turn it back on. !--- Here it is done with a reload instead of a hard power-cycle. 00:15:28: %SYS-SP-3-LOGGER_FLUSHING: System pausing to ensure console debugging. 00:15:27: %C6KPWR-SP-4-DISABLED: power to module in slot 2 set off (admin reque) 00:15:28: %C6KPWR-SP-4-DISABLED: power to module in slot 3 set off (admin reque) 00:15:28: %C6KPWR-SP-4-DISABLED: power to module in slot 6 set off (admin reque) 00:15:28: %OIR-SP-6-CONSOLE: Changing console ownership to switch processor 00:15:28: %SYS-SP-3-LOGGER_FLUSHED: System was paused for 00:00:00 to ensure co. 00:15:30: %SYS-SP-3-LOGGER_FLUSHING: System pausing to ensure console debugging. *** *** --- SHUTDOWN NOW --- *** 00:15:30: %SYS-SP-5-RELOAD: Reload requested 00:15:30: %OIR-SP-6-CONSOLE: Changing console ownership to switch processor 00:15:30: %SYS-SP-3-LOGGER_FLUSHED: System was paused for 00:00:00 to ensure co. 00:15:31: %OIR-SP-6-REMCARD: Card removed from slot 1, interfaces disabled !--- First, the switch processor comes up. System Bootstrap, Version 5.3(1) Copyright (c) 1994-1999 by cisco Systems, Inc. c6k_sup1 processor with 65536 Kbytes of main memory Autoboot executing command: "boot bootflash:c6sup11-jsv-mz.121-6.E" Self decompressing the image : ################################################] Restricted Rights Legend Use, duplication, or disclosure by the Government is subject to restrictions as set forth in subparagraph (c) of the Commercial Computer Software - Restricted Rights clause at FAR sec. 52.227-19 and subparagraph (c) (1) (ii) of the Rights in Technical Data and Computer Software clause at DFARS sec. 252.227-7013. Cisco Systems, Inc. 170 West Tasman Drive San Jose, California 95134-1706 Cisco Internetwork Operating System Software IOS (TM) c6sup1_sp Software (c6sup1_sp-SPV-M), Version 12.1(6)E, EARLY DEPLOYME) TAC Support: http://www.cisco.com/cgi-bin/ibld/view.pl?i=support Copyright (c) 1986-2001 by cisco Systems, Inc. Compiled Sat 17-Mar-01 00:52 by eaarmas Image text-base: 0x60020950, database: 0x605FC000 Start as Primary processor 00:00:03: %SYS-3-LOGGER_FLUSHING: System pausing to ensure console debugging ou. 00:00:03: %OIR-6-CONSOLE: Changing console ownership to route processor !--- The RP now has control of the console. !--- This is when you send the break sequence. System Bootstrap, Version 12.0(3)XE, RELEASE SOFTWARE Copyright (c) 1998 by cisco Systems, Inc. *** Address Error (Load/Fetch) Exception *** Access address = 0x5e PC = 0x5e, Cause = 0x10, Status Reg = 0x3040d003 ROM Monitor Can Not Recover From Exception A Board Reset Is Issued *** Software NMI *** PC = 0xbfc0b6b0, SP = 0x00002a90 Cat6k-MSFC platform with 131072 Kbytes of main memory Self decompressing the image : ################################################] *** System received an abort due to Break Key *** signal= 0x3, code= 0x0, context= 0x6049ed68 PC = 0x601011ac, Cause = 0x20, Status Reg = 0x34008002 !--- You are now in ROMMON mode on the RP. Continue the password !--- recovery procedure just as on any router. Changing the configuration !--- register from 0x2102 to 0x2142 causes the router to ignore the existing !--- configuration. You want it to be ignored because it has passwords that you do not !--- know. rommon 1 > confreg 0x2142 You must reset or power cycle for new config to take effect rommon 2 > reset System Bootstrap, Version 12.0(3)XE, RELEASE SOFTWARE Copyright (c) 1998 by cisco Systems, Inc. Cat6k-MSFC platform with 131072 Kbytes of main memory Self decompressing the image : ################################################] Attempt to download 'sup-bootflash:c6sup11-jsv-mz.121-6.E' ... okay Starting download of 'sup-bootflash:c6sup11-jsv-mz.121-6.E': 8722810 bytes!!!!!! Chksum: Verified! Self decompressing the image : ################################################] Restricted Rights Legend Use, duplication, or disclosure by the Government is subject to restrictions as set forth in subparagraph (c) of the Commercial Computer Software - Restricted Rights clause at FAR sec. 52.227-19 and subparagraph (c) (1) (ii) of the Rights in Technical Data and Computer Software clause at DFARS sec. 252.227-7013. Cisco Systems, Inc. 170 West Tasman Drive San Jose, California 95134-1706 Cisco Internetwork Operating System Software IOS (TM) c6sup1_RP Software (c6sup1_rp-JSV-M), Version 12.1(6)E, EARLY DEPLOYME) TAC Support: http://www.cisco.com/cgi-bin/ibld/view.pl?i=support Copyright (c) 1986-2001 by Cisco Systems, Inc. Compiled Sat 17-Mar-01 00:14 by eaarmas Image text-base: 0x60020950, database: 0x6165E000 Cisco Catalyst 6000 (R5000) processor with 114688K/16384K bytes of memory. Processor board ID SAD04281AF6 R5000 CPU at 200Mhz, Implementation 35, Rev 2.1, 512KB L2 Cache Last reset from power-on Bridging software. X.25 software, Version 3.0.0. SuperLAT software (copyright 1990 by Meridian Technology Corp). TN3270 Emulation software. 24 Ethernet/IEEE 802.3 interface(s) 1 Virtual Ethernet/IEEE 802.3 interface(s) 48 FastEthernet/IEEE 802.3 interface(s) 4 Gigabit Ethernet/IEEE 802.3 interface(s) 381K bytes of nonvolatile configuration memory. 4096K bytes of packet SRAM memory. 16384K bytes of Flash internal SIMM (Sector size 256K). --- System Configuration Dialog --- Would you like to enter the initial configuration dialog? [yes/no]: n !--- The router ignores the saved configuration and enters !--- the initial configuration mode. Press RETURN to get started! 00:00:03: %SYS-3-LOGGER_FLUSHED: System was paused for 00:00:00 to ensure conso. 00:00:04: %C6KPWR-4-PSINSERTED: power supply inserted in slot 1. 00:00:04: %C6KPWR-4-PSOK: power supply 1 turned on. 00:02:08: %SYS-SP-5-RESTART: System restarted -- Cisco Internetwork Operating System Software IOS (TM) c6sup1_SP Software (c6sup1_sp-SPV-M), Version 12.1(6)E, EARLY DEPLOYME) TAC Support: http://www.cisco.com/cgi-bin/ibld/view.pl?i=support Copyright (c) 1986-2001 by cisco Systems, Inc. Compiled Sat 17-Mar-01 00:52 by eaarmas 00:02:13: L3-MGR: l2 flush entry installed 00:02:13: L3-MGR: l3 flush entry installed 00:02:14: %SYS-5-RESTART: System restarted -- Cisco Internetwork Operating System Software IOS (TM) c6sup1_RP Software (c6sup1_rp-JSV-M), Version 12.1(6)E, EARLY DEPLOYME) TAC Support: http://www.cisco.com/cgi-bin/ibld/view.pl?i=support Copyright (c) 1986-2001 by Cisco Systems, Inc. Compiled Sat 17-Mar-01 00:14 by eaarmas 00:02:17: %C6KPWR-SP-4-DISABLED: power to module in slot 1 set off (admin reque) 00:02:18: %C6KPWR-SP-4-ENABLED: power to module in slot 3 set on 00:02:18: %C6KPWR-SP-4-ENABLED: power to module in slot 6 set on 00:02:28: sm_set_moduleFwVersion: nonexistent module (1) 00:02:38: %SNMP-5-MODULETRAP: Module 1 [Up] Trap 00:02:38: %OIR-SP-6-INSCARD: Card inserted in slot 1, interfaces are now online 00:02:56: %SNMP-5-MODULETRAP: Module 6 [Up] Trap 00:02:56: %OIR-SP-6-INSCARD: Card inserted in slot 6, interfaces are now online 00:02:59: SP: SENDING INLINE_POWER_DAUGHTERCARD_MSG SCP MSG 00:02:59: %SNMP-5-MODULETRAP: Module 3 [Up] Trap 00:02:59: %OIR-SP-6-INSCARD: Card inserted in slot 3, interfaces are now online Router>enable Router# !--- You go right into privilege mode without needing a password. !--- At this point, the configuration running-config is a default configuration !--- with all the ports administratively down (shutdown). Router#copy startup-config running-config Destination filename [running-config]? <press enter> !--- This pulls in the original configuration. Since you are already in privilege !--- mode, the passwords in this configuration do not affect you. 4864 bytes copied in 2.48 secs (2432 bytes/sec) Router#configure terminal Enter configuration commands, one per line. End with CNTL/Z. Router(config)#enable secret < password > [Choose a strong password with at least one capital letter, one number, and one special character.] !--- Overwrite the password that you do not know. This is your new enable password. Router(config)#^Z Router# Router#show ip interface brief Interface IP-Address OK? Method Status Prol Vlan1 172.17.10.10 YES TFTP administratively down dow Vlan10 10.1.1.1 YES TFTP administratively down dow GigabitEthernet1/1 unassigned YES unset administratively down dow GigabitEthernet1/2 unassigned YES TFTP administratively down dow GigabitEthernet2/1 unassigned YES TFTP administratively down dow GigabitEthernet2/2 unassigned YES TFTP administratively down dow FastEthernet3/1 172.16.84.110 YES TFTP administratively down dow <snip>... !--- Issue the no shut command on all interfaces that you want to bring up. Router#configure terminal Enter configuration commands, one per line. End with CNTL/Z. Router(config)#interface fastEthernet 3/1 Router(config-if)#no shutdown Router(config-if)#exit !--- Overwrite the virtual terminal passwords. Router(config)#line vty 0 4 Router(config-line)#password cisco Router(config-line)#^Z Router# !--- Restore the configuration register to its normal state so that it !--- no longer ignores the stored configuration file. Router#show version Cisco Internetwork Operating System Software IOS (tm) c6sup1_rp Software (c6sup1_rp-JSV-M), Version 12.1(6)E, EARLY DEPLOYME) TAC Support: http://www.cisco.com/cgi-bin/ibld/view.pl?i=support Copyright (c) 1986-2001 by cisco Systems, Inc. Compiled Sat 17-Mar-01 00:14 by eaarmas Image text-base: 0x60020950, data-base: 0x6165E000 ROM: System Bootstrap, Version 12.0(3)XE, RELEASE SOFTWARE BOOTFLASH: MSFC Software (C6MSFC-BOOT-M), Version 12.1(6)E, EARLY DEPLOYMENT RE) Router uptime is 7 minutes System returned to ROM by power-on (SP by reload) System image file is "sup-bootflash:c6sup11-jsv-mz.121-6.E" Cisco Catalyst 6000 (R5000) processor with 114688K/16384K bytes of memory. Processor board ID SAD04281AF6 R5000 CPU at 200Mhz, Implementation 35, Rev 2.1, 512KB L2 Cache Last reset from power-on Bridging software. X.25 software, Version 3.0.0. SuperLAT software (copyright 1990 by Meridian Technology Corp). TN3270 Emulation software. 24 Ethernet/IEEE 802.3 interface(s) 2 Virtual Ethernet/IEEE 802.3 interface(s) 48 FastEthernet/IEEE 802.3 interface(s) 4 Gigabit Ethernet/IEEE 802.3 interface(s) 381K bytes of non-volatile configuration memory. 4096K bytes of packet SRAM memory. 16384K bytes of Flash internal SIMM (Sector size 256K). Configuration register is 0x2142 Router#configure terminal Enter configuration commands, one per line. End with CNTL/Z. Router(config)#config-register 0x2102 Router(config)#^Z Router# !--- Verify that the configuration register is changed for the next reload. Router#show version Cisco Internetwork Operating System Software IOS (tm) c6sup1_rp Software (c6sup1_rp-JSV-M), Version 12.1(6)E, EARLY DEPLOYME) TAC Support: http://www.cisco.com/cgi-bin/ibld/view.pl?i=support Copyright (c) 1986-2001 by cisco Systems, Inc. Compiled Sat 17-Mar-01 00:14 by eaarmas Image text-base: 0x60020950, data-base: 0x6165E000 ROM: System Bootstrap, Version 12.0(3)XE, RELEASE SOFTWARE BOOTFLASH: MSFC Software (C6MSFC-BOOT-M), Version 12.1(6)E, EARLY DEPLOYMENT RE) Router uptime is 8 minutes System returned to ROM by power-on (SP by reload) System image file is "sup-bootflash:c6sup11-jsv-mz.121-6.E" Cisco Catalyst 6000 (R5000) processor with 114688K/16384K bytes of memory. Processor board ID SAD04281AF6 R5000 CPU at 200Mhz, Implementation 35, Rev 2.1, 512KB L2 Cache Last reset from power-on Bridging software. X.25 software, Version 3.0.0. SuperLAT software (copyright 1990 by Meridian Technology Corp). TN3270 Emulation software. 24 Ethernet/IEEE 802.3 interface(s) 2 Virtual Ethernet/IEEE 802.3 interface(s) 48 FastEthernet/IEEE 802.3 interface(s) 4 Gigabit Ethernet/IEEE 802.3 interface(s) 381K bytes of non-volatile configuration memory. 4096K bytes of packet SRAM memory. 16384K bytes of Flash internal SIMM (Sector size 256K). Configuration register is 0x2142 (will be 0x2102 at next reload) Router# Router#copy running-config startup-config Destination filename [startup-config]? <press enter> Building configuration... [OK] Router# !--- Optional: If you want to test that the router !--- operates properly and that you have changed !--- the passwords, then reload and test. Router#reload Proceed with reload? [confirm] <press enter>
Revisão | Data de publicação | Comentários |
---|---|---|
1.0 |
24-Apr-2009 |
Versão inicial |