Reset PIX Password
From LinuxServerTech
Taken from http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_password_recovery09186a008009478b.shtml. Modified slightly by me.
The above site also has links to the .bin files necessary.
Complete these steps to recover your password:
Note: Sample output from the password recovery procedure is available in this document.
- Install a serial terminal or a PC with terminal emulation software on the PIX console port. See PIX Console Connection for examples.
- Verify that you have a connection with the PIX, and that characters are going from the terminal to the PIX, and from the PIX to the terminal. Note: Because you are locked out, you only see a password prompt.
- Immediately after you power on the PIX Firewall and the startup messages appear, send a BREAK character or press the ESC key. The monitor> prompt is displayed. If needed, type ? (question mark) to list the available commands.
- Use the interface command to specify which interface the ping traffic should use. For floppiless PIXes with only two interfaces, the monitor command defaults to the inside interface.
- Use the address command to specify the IP address of the PIX Firewall's interface.
- Use the server command to specify the IP address of the remote TFTP server containing the PIX password recovery file.
- Use the file command to specify the filename of the PIX password recovery file. For example, the 5.1 release uses a file named np51.bin.
- If needed, enter the gateway command to specify the IP address of a router gateway through which the server is accessible.
- If needed, use the ping command to verify accessibility. If this command fails, fix access to the server before continuing.
- Use the tftp command to start the download.
- As the password recovery file loads, this message is displayed: Do you wish to erase the passwords? [yn] y
- Note: If there are Telnet or console aaa authentication commands in version 6.2, the system also prompts to remove these.
- The default Telnet password after this process is "cisco." There is no default enable password. Go into configuration mode and issue the passwd your_password command to change your Telnet password and the enable password your_enable_password command to create an enable password, and then save your configuration.
