cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1761
Views
5
Helpful
5
Replies

Unable to Save Config after Nexus Password Recovery

shah_vatsal239
Level 1
Level 1

After Password Recover of Nexus 5672UP, I was able to login to Nexus switch via console cable, However I am seeing below error. I am unable to save config or go to terminal mode or do show command. Any idea ?
NEX01# config terminal
Error: AAA authorization failed AAA_AUTHOR_STATUS_METHOD=17(0x11)

 

NEX01# copy running-config startup-config
Error: AAA authorization failed AAA_AUTHOR_STATUS_METHOD=17(0x11)

 

Is there any way to completely factory reset and erase nvram ?

1 Accepted Solution

Accepted Solutions

As per Cisco TAC, due to this issue we cannot recover password, which defeats the purpose of password recovery.

The only option is to factory reset by below procedure.

https://community.cisco.com/t5/data-center-and-cloud-videos/how-to-restore-a-cisco-nexus-switch-from-loader-prompt/bc-p/3101971

 

View solution in original post

5 Replies 5

balaji.bandi
Hall of Fame
Hall of Fame

looks like this is TACACS Authorise issue

 

can you post show version and show run | in tac

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

I think show run | in tac  also shows same output of authorization.

Any command I enter shows same authorization issue. No command works. 

show running-config, show inventory or any command doesn't work.

This switch is not connected to anywhere currently.  Why would Password Reset won't bypass this authorization ? Is there a way to completely factory reset ? I don't need any config on this switch. I just need to get into this switch to be utilized for project. 

Arne Bier
VIP
VIP

You might get the assistance you need by asking this question in the Nexus Community - it's not really a NAC question.

 

Cisco Community > Technology and Support > Data Center and Cloud > Nexus Dashboard

thomas
Cisco Employee
Cisco Employee

This switch appears to be configured to use TACACS for command-based authorization of each and every command on the CLI and you do not appear to be authorized to run these commands from the console.

Try logging in via SSH as you normally would and hopefully this will work properly.

Talk to your peers or manager or security team in your organization about your privilege level and whether or not you should be allowed to run these commands.

If you should be able to do this, they may need to change your authorized privilege level or add commands to your privilege level so you may run them.

As per Cisco TAC, due to this issue we cannot recover password, which defeats the purpose of password recovery.

The only option is to factory reset by below procedure.

https://community.cisco.com/t5/data-center-and-cloud-videos/how-to-restore-a-cisco-nexus-switch-from-loader-prompt/bc-p/3101971