Recovering From A Lockout - Cisco 7604 Configuration Manual

Catalyst 6500 series switch and cisco 7600 series router firewall services module configuration guide using the cli
Hide thumbs Also See for 7604:
Table of Contents

Advertisement

Chapter 23
Configuring Management Access
Table 23-1
Table 23-1
Field
Username
Current privilege level Level from 0 to 15. Unless you configure local command authorization and
Current Mode/s

Recovering from a Lockout

In some circumstances, when you turn on command authorization or CLI authentication, you can be
locked out of the FWSM CLI. You can usually recover access by restarting the FWSM. However, if you
already saved your configuration, you might be locked out.
conditions and how you might recover from them.
Table 23-2
CLI Authentication and Command Authorization Lockout Scenarios
Feature
Lockout Condition Description
Local CLI
No users in the
authentication
local database
TACACS+
Server down or
command
unreachable and
authorization
you do not have
the fallback
TACACS+ CLI
method
authentication
configured
RADIUS CLI
authentication
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
describes the show curpriv command output.
show curpriv Display Description
Description
Username. If you are logged in as the default user, the name is enable_1 (user
EXEC) or enable_15 (privileged EXEC).
assign commands to intermediate privilege levels, levels 0 and 15 are the only
levels that are used.
Shows the access modes:
P_UNPR—User EXEC mode (levels 0 and 1)
P_PRIV—Privileged EXEC mode (levels 2 to 15)
P_CONF—Configuration mode
If you have no users in
the local database, you
cannot log in, and you
cannot add any users.
If the server is
unreachable, then you
cannot log in or enter
any commands.
Table 23-2
Workaround: Single Mode
Log in and reset the
passwords and aaa
commands.
Log in and reset the
1.
passwords and AAA
commands.
Configure the local
2.
database as a fallback
method so you do not
get locked out when the
server is down.
AAA for System Administrators
lists the common lockout
Workaround: Multiple Mode
Session in to the FWSM
from the switch. From the
system execution space, you
can change to the context
and add a user.
If the server is
1.
unreachable because the
network configuration
is incorrect on the
FWSM, session in to the
FWSM from the switch.
From the system
execution space, you
can change to the
context and reconfigure
your network settings.
Configure the local
2.
database as a fallback
method so you do not
get locked out when the
server is down.
23-23

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

7609-s76137606-sCatalyst 6500 series7600 series

Table of Contents