Saturday 6 February 2010

How to stop local password recovery

If you have core devices, of significant importance, that you want to ensure that nobody can recover the password localy, inject config and restore the device or change the confreg, the below command will help you.

Please bear in mind this totally removes the ROMMON mode so you will not be able to recover devices, you will not be able to recover password and you will not be able to replace IOS if it corrupts.

It's a hidden command :

no service password-recovery


If your router barfs for any reason, its a complete wipe to factory default or a trip back to Cisco for restoration so use this command sparingly.

If for any reason you wish to turn this feature off, it can be done during normal usage.

No comments:

Post a Comment