Recovering A Lost Password - Cisco WS-C2948G-GE-TX Configuration Manual

Catalyst 4500 series switch
Table of Contents

Advertisement

Configuring Authentication
Disabling Local Authentication
Make sure that RADIUS or TACACS+ authentication is configured and operating correctly before
Caution
disabling local login or enabling authentication. If you disable local authentication when RADIUS or
TACACS+ is not correctly configured, or if the RADIUS or TACACS+ server is not online, you may be
unable to log in to the switch.
To disable local authentication on the switch, perform this task in privileged mode:
Task
Step 1
Disable local login authentication on the switch.
Enter the console or telnet keywords to disable local
authentication only for the console port or for the
Telnet connection attempts.
Step 2
Disable local enable authentication on the switch.
Enter the console or telnet keywords to disable local
authentication only for the console port or for the
Telnet connection attempts.
Step 3
Verify the local authentication configuration.
This example shows how to disable local login and enable authentication for both console and Telnet
connections, and how to verify the configuration (you must have RADIUS or TACACS+ authentication
enabled before you disable local authentication):
Console> (enable) set authentication login local disable
local login authentication set to disable for console and telnet session.
Console> (enable) set authentication enable local disable
local enable authentication set to disable for console and telnet session.
Console> (enable) show authentication
Login Authentication:
---------------------
tacacs
radius
kerberos
local
Enable Authentication: Console Session
---------------------- ----------------- ----------------
tacacs
radius
kerberos
local
Console> (enable)

Recovering a Lost Password

To recover a lost local authentication password, follow these steps. You must complete Steps 3 through
Step 7 within 30 seconds of a power cycle or the recovery will fail. If you have lost both the login and
enable passwords, repeat the process for each password.
Catalyst 4500 Series, Catalyst 2948G, Catalyst 2948G-GE-TX, and Catalyst 2980G Switches Software Configuration Guide—Release 8.2GLX
30-14
Console Session
Telnet Session
----------------
----------------
disabled
disabled
enabled(primary)
enabled(primary)
disabled
disabled
disabled
disabled
Telnet Session
disabled
disabled
enabled(primary)
enabled(primary)
disabled
disabled
disabled
disabled
Chapter 30
Configuring Switch Access Using AAA
Command
set authentication login local disable [all |
console | http | telnet]
set authentication enable local disable [all |
console | http | telnet]
show authentication
78-15908-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents