<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco FPR-4100 Password Recovery in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-fpr-4100-password-recovery/m-p/4696616#M1093812</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/287680"&gt;@Sheraz.Salim&lt;/a&gt;&amp;nbsp;CSM was used to manage both boxes. According to the Cisco documentation, we can update the password from CSM.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/security_management/cisco_security_manager/security_manager/417/user/guide/CSMUserGuide/pxhostresourc.html#114477" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/security_management/cisco_security_manager/security_manager/417/user/guide/CSMUserGuide/pxhostresourc.html#114477&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;If we truly need to do password recovery, can we just do it or do we need to disconnect the HA first and then do the procedure? Will restoring the HA then sync the policies?&amp;nbsp;Any policies deployed on CSM for user authorization and password recovery will not solve the login problem, correct?&lt;/P&gt;</description>
    <pubDate>Fri, 30 Sep 2022 08:36:49 GMT</pubDate>
    <dc:creator>ezzhar891202</dc:creator>
    <dc:date>2022-09-30T08:36:49Z</dc:date>
    <item>
      <title>Cisco FPR-4100 Password Recovery</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fpr-4100-password-recovery/m-p/4695333#M1093737</link>
      <description>&lt;P&gt;Dear guys, we have two devices that are in a HA environment. The problem is that secondary FP can connect using AD credentials, but when you run the command, you get an "error retrieving user privileges" and your admin credentials are gone. Both AD and admin have also been gone from the primary unit. So we decided to proceed with password recovery using the document below.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-9300-security-appliance/200491-Password-Recovery-Procedure-For-FirePOWE.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/security/firepower-9300-security-appliance/200491-Password-Recovery-Procedure-For-FirePOWE.html&lt;/A&gt;&lt;/P&gt;
&lt;PRE&gt;switch(boot)# &lt;STRONG&gt;config terminal&lt;/STRONG&gt;
Enter configuration commands, one per line.  End with CNTL/Z.
switch(boot)(config)# &lt;STRONG&gt;admin-password erase&lt;/STRONG&gt;
&lt;STRONG&gt;Your password and configuration will be erased!&lt;/STRONG&gt;
Do you want to continue? (y/n)  [n] &lt;STRONG&gt;y&lt;/STRONG&gt;&lt;/PRE&gt;
&lt;P&gt;Is it completely accurate that it will reset all configurations to factory defaults, including policies?&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Cisco FPR-4100&amp;nbsp;&amp;nbsp;&lt;/EM&gt;&lt;/STRONG&gt;Appliances&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 11:47:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fpr-4100-password-recovery/m-p/4695333#M1093737</guid>
      <dc:creator>ezzhar891202</dc:creator>
      <dc:date>2022-09-28T11:47:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FPR-4100 Password Recovery</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fpr-4100-password-recovery/m-p/4695368#M1093751</link>
      <description>&lt;P&gt;Correct it will wipe the config on your Box. as per the document mentioned and showed the configuration.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 12:40:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fpr-4100-password-recovery/m-p/4695368#M1093751</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2022-09-28T12:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FPR-4100 Password Recovery</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fpr-4100-password-recovery/m-p/4695674#M1093760</link>
      <description>&lt;P&gt;Thank you for your response&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/287680"&gt;@Sheraz.Salim&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;how can I recover the policies into secondary because we don't have a backup? Since the primary worked properly, only cant log in to the device and will sync and obtain the current policies after HA is restored?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 01:05:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fpr-4100-password-recovery/m-p/4695674#M1093760</guid>
      <dc:creator>ezzhar891202</dc:creator>
      <dc:date>2022-09-29T01:05:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FPR-4100 Password Recovery</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fpr-4100-password-recovery/m-p/4695817#M1093763</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/906413"&gt;@ezzhar891202&lt;/a&gt; Are you managed these FTD from FMC? as this appliances is secondary once you re-image/reset/factory-rest and you make the HA pair the configuration will syn from the Primary FTD (This include all the policies and configuration) to the secondary appliance and make the HA pair.&lt;/P&gt;
&lt;P&gt;This procedure as&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/2120/cli-guide/b_CLI_ConfigGuide_FXOS_2120/troubleshooting.html#id_110405" target="_self"&gt;mentioned&lt;/A&gt;&amp;nbsp; above returns your Firepower 4100/9300 chassis system to its default configuration settings, including the admin password. Use this procedure to reset the configurations on your device when the admin password is not known. This procedure erases any installed logical devices as well.&lt;/P&gt;
&lt;P&gt;also bear in find if you going that route make sure this procedure requires console access to the Firepower 4100/9300 chassis.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 08:29:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fpr-4100-password-recovery/m-p/4695817#M1093763</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2022-09-29T08:29:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FPR-4100 Password Recovery</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fpr-4100-password-recovery/m-p/4696616#M1093812</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/287680"&gt;@Sheraz.Salim&lt;/a&gt;&amp;nbsp;CSM was used to manage both boxes. According to the Cisco documentation, we can update the password from CSM.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/security_management/cisco_security_manager/security_manager/417/user/guide/CSMUserGuide/pxhostresourc.html#114477" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/security_management/cisco_security_manager/security_manager/417/user/guide/CSMUserGuide/pxhostresourc.html#114477&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;If we truly need to do password recovery, can we just do it or do we need to disconnect the HA first and then do the procedure? Will restoring the HA then sync the policies?&amp;nbsp;Any policies deployed on CSM for user authorization and password recovery will not solve the login problem, correct?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 08:36:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fpr-4100-password-recovery/m-p/4696616#M1093812</guid>
      <dc:creator>ezzhar891202</dc:creator>
      <dc:date>2022-09-30T08:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FPR-4100 Password Recovery</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fpr-4100-password-recovery/m-p/4696628#M1093815</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/906413"&gt;@ezzhar891202&lt;/a&gt; The cisco documentation is very clear for FTD4100 if you going to password recovery you requires console access to the Firepower 4100/9300 chassis. Remember This procedure erases any installed logical devices as well.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The best approach would be discount your secondary standby firewall (Break -HA) and follow the password recovery document. once the box is factory reset and when box will come up clean when you have the HA pair the policies from the primary ftd will push to secondary standby firewall. just make sure your recovery password FTD configured as secondary standby. &lt;/P&gt;
&lt;P&gt;Also have a look on &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/212699-configure-ftd-high-availability-on-firep.html" target="_self"&gt;this document&lt;/A&gt; you will find it very useful.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 08:53:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fpr-4100-password-recovery/m-p/4696628#M1093815</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2022-09-30T08:53:00Z</dc:date>
    </item>
  </channel>
</rss>

