access to locked out

Hello

I recently installed a cat2924XL. I was setting up Ganymede when I'm distracted and the session has expired - now I can't get to the switch. The only part I had set up was aaa-new model and secure line aaa authentication login. Unfortunately, I have no authentication of secure connection configured on the vty lines cty. Is it possible around this other than breaking into the device - it's understandable that I don't want to take the unit down!

Thank you

If you have written your config, password recovery is required. If this isn't the case, you need to restart.

It's always a good idea to install a local account as a roundabout way method. This is useful if the AAA negotiation encounters an "error", then it will try the next method. Some examples of this are if you have the wrong key in the device mapped to the AAA server or network connectivity is down to the AAA server.

Personally, I like to turn off aaa on the port of the console for this particular reason. Certainly, it can bypass a security policy, but if someone has physical access to the console, they can break anyway.

Here's how:

NO_AUTHEN AAA authentication login no

Line con 0

authentication of the connection NO_AUTHEN

If you use EXEC authorization or order, they should be disabled on port console as well.

Tags: Cisco Security

Similar Questions

Maybe you are looking for