cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1104
Views
0
Helpful
2
Replies

password recovery on ace4710 (without service outage)

Martin Kyrc
Level 3
Level 3

Hello,

password recovery procedure is during booting ACE device (both - module or 4710). I'm interested about password recovery for devices configured in redundancy.

- I have two devices, configs are sync

- I will restart one of them (it doesn't matter which one)

- I will do password reset

- but after booting, this device becomes configuration (including usernames and passwords) from active member. then is not possible to login with default password. is it right?

if previous steps are right, I have only one possibility. turn off both devices, do password recovery on one of them (this will be active member) and next boot secondary (which will sync config from active member).

my question is: is it possible do password recovery for redundant connected ACE devices without service outage?

--

martin

2 Replies 2

pablo.nxh
Level 3
Level 3

Hi Martin,

If you're running your ACE pair in active-standby fashion the outage doing this procedure should be less than 5 secs.

You can simply reboot your standby ACE, do the password recovery and by the time it comes up it will remain as the standby, once you confirm

you can login to the standby you can reboot the primary this will trigger the failover (minimal/none outage) and do the password recovery to the primary, by the time the primary comes online depending on your configuration it will claim for mastership or it will remain as the backup until a failover is triggered.

Again the outage on a well-designed HA scenario will be barely noticeable and all depends on how your setup is configured.

Is your HA configured with preempt?

Is it a active-passive or active-active config?

HTH

__ __

Pablo

Hi Pablo,

are you sure, that after password recovery and starting ACE will be configurations not synced (including passwords for admin user)? Is it possible login to Admin context on standby ACE (ACE which will be recovered) with default password earlier than configuration will be synced from active peer? By default standby box after boot is trying sync it's startup and running configuration from active peer.

But I have no other possibility - only try password recovery and quick login to recovered ACE :). Any other ideas (or answer to my first two questions)?

--

martin

Review Cisco Networking for a $25 gift card