
To recover a lost enable or lost enable-secret password:
1.
Change the Configuration Register
2.
Reset the Router
3.
Reset the Password and Save Your Changes (for lost enable secret passwords only)
4.
Reset the Configuration Register Value
Note
Recovering a lost password is only possible when you are connected to the router through the console port. These procedures cannot be performed through a Telnet session.
Tip
See the "Hot Tips" section on Cisco.com for additional information on replacing enable secret passwords.
To change a configuration register, follow these steps:
Step 1
Connect an ASCII terminal or a PC running a terminal emulation program to the CONSOLE port on the rear panel of the router.
Step 2
Configure the terminal to operate at 9600 baud, 8 data bits, no parity, and 1 stop bit.
Step 3
If you still have access to the router, enter the show version command at the privilege EXEC prompt to display the existing configuration register value (shown in bold at the bottom of this output example). Record the setting of the configuration register.
Step 4
If you do not have access to the router (because of a lost login or tacacs password), you can safely consider that your configuration register is set to 0x2102.
Step 5
Using the power switch, turn off the router and then turn it back on.
Step 6
Enter the config-register 0x01 command from privileged EXEC mode To enable the break setting (indicated by the value of bit 8 in the configuration register).
•
Break enabled—Bit 8 is set to 0.
•
Break disabled (default setting)—Bit 8 is set to 1.
Note
Disable the 'no service password recovery' setting in the router configuration or the Break key will be ignored when attempting to get into rommon.
To reset the router, follow these steps:
Step 1
If break is enabled, go to Step 2. If break is disabled, turn the router off (O), wait 5 seconds, and turn it on (|) again. Within 60 seconds, press the Break key. The terminal displays the ROM monitor prompt. Go to Step 3.
Note
Some terminal keyboards have a key labeled Break. If your keyboard does not have a Break key, see the documentation that came with the terminal for instructions on how to send a break.
Step 2
Press break. The terminal displays the following prompt:
Step 3
Enter confreg 0x2142 to reset the configuration register:
Step 4
Initialize the router by entering the reset command:
The router cycles its power, and the configuration register is set to 0x2142. The router uses the boot ROM system image, indicated by the system configuration dialog:
Step 5
Enter no in response to the prompts until the following message is displayed:
Step 6
Press Return. The following prompt appears:
Step 7
Enter the enable command to enter enable mode. Configuration changes can be made only in enable mode:
The prompt changes to the privileged EXEC prompt:
Step 8
Enter the show startup-config command to display an enable password in the configuration file:
If you are recovering an enable password, do not perform the steps in the following "Reset the Password and Save Your Changes" section. Instead, complete the password recovery process by performing the steps in the "Reset the Configuration Register Value" section.
If you are recovering an enable secret password, it is not displayed in the show startup-config command output. Complete the cisco router password recovery process by performing the steps in the following "Reset the Password and Save Your Changes" section.
To reset your password and save the changes, follow these steps:
Step 1
Enter the configure terminal command to enter global configuration mode:
Step 2
Enter the enable secret command to reset the enable secret password in the router:
Step 3
Enter exit to exit global configuration mode:
Step 4
Save your configuration changes:
To reset the configuration register value after you have recovered or reconfigured a password, follow these steps:
Step 1
Enter the configure terminal command to enter global configuration mode:
Step 2
Enter the configure register command and the original configuration register value that you recorded.
Step 3
Enter exit to exit configuration mode:
Note
To return to the configuration being used before you recovered the lost enable password, do not save the configuration changes before rebooting the router.
Step 4
Reboot the router, and enter the recovered password.
The Cisco SDM tool is a free software configuration utility, supporting the Cisco 850 and Cisco 870 series access routers. It includes a web-based GUI that offers the following features:
•
Simplified setup
•
Advanced configuration
•
Router security
•
Router monitoring
Cisco 800 Series Router Comparison
Cisco 800 Series Router Data Sheet
Cisco 800 Series Router Software Configuration Guide