Cisco 800 Integrated Services Router Password Recovery Procedure

Recovering a Lost Password

To recover a lost enable or lost enable-secret password:

1. Change the Configuration Register

2. Reset the Router

3. Reset the Password and Save Your Changes (for lost enable secret passwords only)

4. Reset the Configuration Register Value


Note Recovering a lost password is only possible when you are connected to the router through the console port. These procedures cannot be performed through a Telnet session.

Tip See the "Hot Tips" section on Cisco.com for additional information on replacing enable secret passwords.

Change the Configuration Register

To change a configuration register, follow these steps:

Step 1 Connect an ASCII terminal or a PC running a terminal emulation program to the CONSOLE port on the rear panel of the router.

Step 2 Configure the terminal to operate at 9600 baud, 8 data bits, no parity, and 1 stop bit.

Step 3 If you still have access to the router, enter the show version command at the privilege EXEC prompt to display the existing configuration register value (shown in bold at the bottom of this output example). Record the setting of the configuration register.

Router# show version
Cisco IOS Software, C870 Software (C870-ADVENTERPRISEK9-M), Version 12.3(nightly
.PCBU_WIRELESS041110) NIGHTLY BUILD, synced to haw_t_pi1_pcbu HAW_T_PI1_PCBU_200
Copyright (c) 1986-2004 by Cisco Systems, Inc.
Compiled Thu 11-Nov-04 03:37 by jsomebody
ROM: System Bootstrap, Version [jsomebody],
Router uptime is 2467 minutes
System returned to ROM by power-on
System image file is "flash:c870-adventerprisek9-mz.pcbu_wireless.041110"
This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.
A summary of U.S. laws governing Cisco cryptographic products may be found at:
If you require further assistance please contact us by sending email to

Cisco 877 (MPC8272) processor (revision 0x00) with 59392K/6144K bytes of memory.

Processor board ID
MPC8272 CPU Rev: Part Number 0xC, Mask Number 0x10
4 FastEthernet interfaces
1 ATM interface
1 802.11 Radio
128K bytes of non-volatile configuration memory.
20480K bytes of processor board System flash (Intel Strataflash)

Configuration register is 0x2102

Step 4 If you do not have access to the router (because of a lost login or tacacs password), you can safely consider that your configuration register is set to 0x2102.

Step 5 Using the power switch, turn off the router and then turn it back on.

Step 6 Enter the config-register 0x01 command from privileged EXEC mode To enable the break setting (indicated by the value of bit 8 in the configuration register).

Break enabled—Bit 8 is set to 0.

Break disabled (default setting)—Bit 8 is set to 1.

Reset Cisco Router

Note Disable the 'no service password recovery' setting in the router configuration or the Break key will be ignored when attempting to get into rommon.

To reset the router, follow these steps:

Step 1 If break is enabled, go to Step 2. If break is disabled, turn the router off (O), wait 5 seconds, and turn it on (|) again. Within 60 seconds, press the Break key. The terminal displays the ROM monitor prompt. Go to Step 3.

Note Some terminal keyboards have a key labeled Break. If your keyboard does not have a Break key, see the documentation that came with the terminal for instructions on how to send a break.

Step 2 Press break. The terminal displays the following prompt:

rommon 2>

Step 3 Enter confreg 0x2142 to reset the configuration register:

rommon 2> confreg 0x2142

Step 4 Initialize the router by entering the reset command:

rommon 2> reset

The router cycles its power, and the configuration register is set to 0x2142. The router uses the boot ROM system image, indicated by the system configuration dialog:

--- System Configuration Dialog ---

Step 5 Enter no in response to the prompts until the following message is displayed:

Press RETURN to get started!

Step 6 Press Return. The following prompt appears:


Step 7 Enter the enable command to enter enable mode. Configuration changes can be made only in enable mode:

Router> enable

The prompt changes to the privileged EXEC prompt:


Step 8 Enter the show startup-config command to display an enable password in the configuration file:

Router# show startup-config

If you are recovering an enable password, do not perform the steps in the following "Reset the Password and Save Your Changes" section. Instead, complete the password recovery process by performing the steps in the "Reset the Configuration Register Value" section.

If you are recovering an enable secret password, it is not displayed in the show startup-config command output. Complete the cisco router password recovery process by performing the steps in the following "Reset the Password and Save Your Changes" section.

Reset the Password and Save Your Changes

To reset your password and save the changes, follow these steps:

Step 1 Enter the configure terminal command to enter global configuration mode:

Router# configure terminal

Step 2 Enter the enable secret command to reset the enable secret password in the router:

Router(config)# enable secret password

Step 3 Enter exit to exit global configuration mode:

Router(config)# exit

Step 4 Save your configuration changes:

Router# copy running-config startup-config

Reset the Configuration Register Value

To reset the configuration register value after you have recovered or reconfigured a password, follow these steps:

Step 1 Enter the configure terminal command to enter global configuration mode:

Router# configure terminal

Step 2 Enter the configure register command and the original configuration register value that you recorded.

Router(config)# config-reg value

Step 3 Enter exit to exit configuration mode:

Router(config)# exit

Note To return to the configuration being used before you recovered the lost enable password, do not save the configuration changes before rebooting the router.

Step 4 Reboot the router, and enter the recovered password.

Managing Your Router with SDM

The Cisco SDM tool is a free software configuration utility, supporting the Cisco 850 and Cisco 870 series access routers. It includes a web-based GUI that offers the following features:

Simplified setup

Advanced configuration

Router security

Router monitoring

