11-13-2005 07:10 AM
Hi
I want to block password recovery procedure ,what confreg do i use ?
Best Regards
farshid
11-13-2005 07:34 PM
You can't. If a knowledgable person has physical access to your network device, they can recover the passwords and 'own' it. The best you can do is log accesses and events remotely so you will know if the system has been compromised.
11-13-2005 11:03 PM
Hi
You mite want to check this link for disabling the same..
you can do it with no service password-recovery command in the global config mode..
but i dont suggest to do something inline with that..
regds
11-14-2005 01:05 AM
Hi
thank u for your recommendations ,
no knowlgable person is gonna hae access to router,
and i think they only know basic key combinations for entering rommon , the only thing i need to do is to disbla break and Ctrl+break key combination .
and by the way the link you offered requires a previledged cco account and unfortunatly i don't have one .
Best Wishes
Farshid
11-14-2005 02:22 AM
Hi
sorry about the link ...
do check this one...
regds
11-14-2005 03:12 AM
Hi
i have just been checking the link u offered
when i tried to test the command (no service password-encryption) i foun out that the router does not support it .
the router that i am testing the command on , is a 3620 router , but the router that i want to disable password recovery is a 3745 router with its default ios , i wanna know if the 3745 router supports the command or not .
Thank you
11-14-2005 03:38 AM
Hi
Its well mentioned in the link sent by me...
Cisco 2691, 3631, 3725, and 3745 Routersno minimum ROMMON or Cisco IOS® software requirements
Cisco 3600 Series Routersminimum ROMMON version 11.1(17)AA (orderable as BOOT-3600=) Minimum Cisco IOS Software Release 11.2(12)P or 11.3(3)T
Cisco 2600 Series Routersall ROMMON and Cisco IOS software versions
Cisco 1700 Series Routersrequires minimum ROMMON 12.1(5r)T1. This is not orderable as a spare, so you cannot upgrade an existing 1720 or 1750. All 1710, and 1751 routers have this ROMMON.
Again its no service password-recovery not password-encryption...
regd
11-14-2005 04:05 AM
Thank u very much
i realy do appreciate your help
i have got one more question ,is it possible to disable the console port so it does not respond to any connection even during startup ?
11-14-2005 04:59 AM
Hi
Console access is very much reqd to troubleshoot or diagnoise booting issues or issues during startup.
AFAIK i dont think its possible to disable during the startup and its not a wise decision to do so.
Better i would suggest to configure with non guessable passwds to secure the access..
regds
11-14-2005 05:10 AM
Hi
the reason that makes me do such a thing is, not to let anybody have access to router rommon ,
if there is any other solution preventing users from accessing rommon and changing config register, i would prefer that way .
Thanks
11-14-2005 05:22 AM
Hi
Do check this link for more info in securing your router..
http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080120f48.shtml
regds
11-14-2005 05:39 AM
Thank u for your time kumar i hope your greatful in your life.
BestWishes
farshid.sh
11-14-2005 05:45 AM
Hi
Good to hear that my post helped ur process out...
regds
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide