Aaa authentication
foreverlearning
Member Posts: 42 ■■■□□□□□□□
I configured aaa new model on the cisco switch but the aaa server is not yet ready.
I am now locked out of the switch as i dont have a username or password.
What should i do?
I am now locked out of the switch as i dont have a username or password.
What should i do?
Comments
-
DCD Member Posts: 475 ■■■■□□□□□□You have to do the password recovery or wipe the startup configuration.
-
TechGromit Member Posts: 2,156 ■■■■■■■■■□So you didn't configure a username and enable password? When i set up a switch, first I set a username/password and enable password.add the commandaaa authentication login default local group tacacs+aaa authentication enable default group tacacs+ enableThis way if the tacacs server is server is down or unreachable, the switch will attempt to reach the server 3 or 4 times than after failing will allow the local account to logon. If the tacac server is reachable, the local accounts are locked out.If you have physical access to the switch, a recovery is pretty simple. If not you could try to set up a local tacac server on your computer. After all if you set up tacac on the switch you should know the server address and shared key. Should work if you on the same subnet, but not if it's set for a different one.Still searching for the corner in a round room.
-
foreverlearning Member Posts: 42 ■■■□□□□□□□TechGromit said:So you didn't configure a username and enable password? When i set up a switch, first I set a username/password and enable password.add the commandaaa authentication login default local group tacacs+aaa authentication enable default group tacacs+ enableThis way if the tacacs server is server is down or unreachable, the switch will attempt to reach the server 3 or 4 times than after failing will allow the local account to logon. If the tacac server is reachable, the local accounts are locked out.If you have physical access to the switch, a recovery is pretty simple. If not you could try to set up a local tacac server on your computer. After all if you set up tacac on the switch you should know the server address and shared key. Should work if you on the same subnet, but not if it's set for a different one.
What recovery can you do when the prompt is
Username:
Password:
And then you cannot go in because there is no AAA server?
Even console is not an option.
-
TechGromit Member Posts: 2,156 ■■■■■■■■■□recovery is pretty simple?
What recovery can you do when the prompt is
Username:
Password:
And then you cannot go in because there is no AAA server?
Even console is not an option.
Once Corporate provided an ISO version for our 9300 switches, but wasn't compatible my 9300 Fiber switches, this was a fun recovery. Worse one I ever had to do. It involved reloading the ISO from a USB flash drive and 3 reloads to get it back to reloading standalone without locking up. Now when I'm directed to update the ISO version, i verify the code is compatible with all my switch model favors with the Cisco website ISO download. If you type in your exact switch model, it will tell you what versions are compatible for your specific switch.Still searching for the corner in a round room. -
foreverlearning Member Posts: 42 ■■■□□□□□□□TechGromit said:recovery is pretty simple?
What recovery can you do when the prompt is
Username:
Password:
And then you cannot go in because there is no AAA server?
Even console is not an option.
Once Corporate provided an ISO version for our 9300 switches, but wasn't compatible my 9300 Fiber switches, this was a fun recovery. Worse one I ever had to do. It involved reloading the ISO from a USB flash drive and 3 reloads to get it back to reloading standalone without locking up. Now when I'm directed to update the ISO version, i verify the code is compatible with all my switch model favors with the Cisco website ISO download. If you type in your exact switch model, it will tell you what versions are compatible for your specific switch. -
TechGromit Member Posts: 2,156 ■■■■■■■■■□foreverlearning said:So even if I go into ROMMON mode, there is no guarantee that I can recover my configuration?
Still searching for the corner in a round room.