Cisco PIX 525 Specifikace Strana 518

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 604
  • Tabulka s obsahem
  • ŘEŠENÍ PROBLÉMŮ
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 517
32-10
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 32 Monitoring and Troubleshooting
Troubleshooting the Security Appliance
Password Recovery for the PIX 500 Series Security Appliance
Performing password recovery on the security appliance erases the login password, enable password,
and aaa authentication console commands. To erase these commands so you can log in with the default
passwords, perform the following steps:
Step 1 Download the PIX password tool from Cisco.com to a TFTP server accessible from the security
appliance. See the link in the “Password Recovery Procedure for the PIX” document at the following
URL:
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_password_recovery09186a0080
09478b.shtml
Step 2 Connect to the security appliance console port according to the Accessing the Command-Line
Interface” section on page 2-1.
Step 3 Power off the security appliance, and then power it on.
Step 4 Immediately after the startup messages appear, press the Escape key to enter monitor mode.
Step 5 Configure the network settings for the interface that accesses the TFTP server by entering the following
commands:
monitor> interface
interface_id
monitor> address
interface_ip
monitor> server
tftp_ip
monitor> file
pw_tool_name
monitor> gateway
gateway_ip
Step 6 Download the PIX password tool from the TFTP server by entering the following command:
monitor> tftp
If you have trouble reaching the server, you can enter the ping address command to test the connection.
Step 7 At the “Do you wish to erase the passwords?” prompt, enter Y.
You can now log in with the default login password of “cisco” and the blank enable password.
The following example shows the PIX password recovery with the TFTP server on the outside interface:
monitor> interface 0
0: i8255X @ PCI(bus:0 dev:13 irq:10)
1: i8255X @ PCI(bus:0 dev:14 irq:7 )
Using 0: i82559 @ PCI(bus:0 dev:13 irq:10), MAC: 0050.54ff.82b9
monitor> address 10.21.1.99
address 10.21.1.99
monitor> server 172.18.125.3
server 172.18.125.3
monitor> file np70.bin
file np52.bin
monitor> gateway 10.21.1.1
gateway 10.21.1.1
monitor> ping 172.18.125.3
Sending 5, 100-byte 0xf8d3 ICMP Echoes to 172.18.125.3, timeout is 4 seconds:
!!!!!
Success rate is 100 percent (5/5)
monitor> tftp
tftp [email protected] via 10.21.1.1...................................
Received 73728 bytes
Zobrazit stránku 517
1 2 ... 513 514 515 516 517 518 519 520 521 522 523 ... 603 604

Komentáře k této Příručce

Žádné komentáře