- 论坛徽章:
- 0
|
Password Recovery Procedure\r\nfor PIX\r\n\r\n--------------------------------------------------------------------------------\r\n\r\nContents \r\nDescription\r\nRequired Files\r\nStep-by-Step Procedure\r\nRelated Information \r\n\r\n\r\n--------------------------------------------------------------------------------\r\n\r\nDescription\r\nThis document describes how to recover a PIX password for PIX software releases through 5.1. \r\n\r\nThe PIX Password Lockout Utility is based on the PIX software release you are running. \r\n\r\n \r\n\r\nIn addition to the required files listed in the next section, you will need the following items to follow the password recovery procedure: \r\n\r\nA PC \r\nA working serial terminal or terminal emulator \r\nApproximately 10 minutes of PIX and network downtime \r\nRequired Files\r\nNote: If you are a registered user and have logged in, you can download the files here. If you are not a registered user, please open a case with the Technical Assistance Center (TAC) to obtain the files. \r\n\r\nThe PIX Password Lockout Utility, which includes the following files: \r\nrawrite.exe>\r\n\r\nOne of the following files:\r\n\r\nnppix.bin (4.3 and earlier releases) \r\nnp44.bin (4.4 release) \r\nnp50.bin (5.0 release) \r\nnp51.bin (5.1 release) \r\nStep-by-Step Procedure\r\nPIX with a Floppy Drive\r\nExecute the rawrite.exe file on your PC and answer the questions on the screen. \r\n \r\nInstall a serial terminal or a PC with terminal emulation software on the PIX console port. \r\n \r\nVerify that you have a connection with the PIX, and that characters are going from the terminal to the PIX, and from the PIX to the terminal. \r\n\r\nNote: Because you are locked out, you will see only a password prompt.\r\n \r\n\r\nInsert the PIX Password Lockout Utility disk into the floppy drive of the PIX. \r\n \r\nPush the Reset button on the front of the PIX. The PIX will reboot from the floppy and print the message below: \r\n\r\nErasing Flash Password. Please eject diskette and reboot.\r\nEject the disk and press the Reset button. You will now be able to log in without a password. When you are prompted for a password, press Return. \r\n \r\nCreate a password with the passwd command, and save your configuration. \r\n \r\n\r\nPIX without a Floppy Drive\r\nInstall a serial terminal or a PC with terminal emulation software on the PIX console port. \r\n \r\nVerify that you have a connection with the PIX, and that characters are going from the terminal to the PIX, and from the PIX to the terminal. \r\n\r\nNote: Because you are locked out, you will see only a password prompt. \r\n\r\nImmediately after you power on the PIX Firewall and the startup messages appear, send a BREAK character or press the Esc (Escape) key. The monitor> prompt is displayed. If needed, enter a question mark (?) to list the available commands. \r\nUse the interface command to specify which interface the ping traffic should use. If the PIX 515 has only two interfaces, the monitor command defaults to the inside interface. \r\nUse the address command to specify the IP address of the PIX Firewall\'s interface. \r\nUse the server command to specify the IP address of the remote server. \r\nUse the file command to specify the filename of the PIX password recovery file. For example, np51.bin. \r\nIf needed, enter the gateway command to specify the IP address of a router gateway through which the server is accessible. \r\nIf needed, use the ping command to verify accessibility. If this command fails, fix access to the server before continuing. \r\nUse the tftp command to start the download. \r\nAs the password recovery file loads, the following message is displayed: \r\nDo you wish to erase the passwords? [yn] y\r\nPasswords have been erased. \r\n\r\nCreate a password with the passwd command, and save your configuration. |
|