cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
682
Views
0
Helpful
2
Replies

Cisco 2960 Get back access Access Deny

denis.pasternak
Level 1
Level 1

Hi, 

I have no experience in Cisco routes configuration, but there is a need.

2 routes Cisco 2960/1 and Cisco 2960/2. I try change password of administrator, I change it and enable Web Service (HTTP) for CNA. Save config and reboot.

WS-C2960-24TC-L-1 and WS-C2960-24TC-L-2

.............

Now, at 2960/1 - I can access over CNA and Web Service with old admin login new password. If i try connect over SSH or Telnet - get erros "Connection refused" or "Access Deny" after three attempts.

At CNA I can change passwors and save configuration, but nothing changes :)

............

At 2960/2 - I Can not access over CNA or Web Service or SSH (use new or old password), "Access Deny" after three attempts.

I ask administrator to connect over COM port, and than I try connect over Putty or Tera Term and it was a success (old password not new).

WS-C2960-24TC-L-2#show ip http server status
HTTP server status: Enabled
HTTP server port: 80
HTTP server authentication method: enable
HTTP server access class: 0
HTTP server base path: flash:html
HTTP server help root:
Maximum number of concurrent server connections allowed: 16
Server idle time-out: 180 seconds
Server life time-out: 180 seconds
Maximum number of requests allowed on a connection: 25
HTTP server active session modules: ALL
HTTP secure server capability: Present
HTTP secure server status: Disabled
HTTP secure server port: 443
HTTP secure server ciphersuite: 3des-ede-cbc-sha des-cbc-sha rc4-128-md5 rc4-128-sha
HTTP secure server client authentication: Disabled
HTTP secure server trustpoint:
HTTP secure server active session modules: ALL

How can I get back access? I just want to:

1. Change passwords

2. Get access over CNA and SSH

3. Change default route for users VLANs to new ISP router

Thank you! :)

2 Replies 2

denis.pasternak
Level 1
Level 1

over com port I can see 

000044: Dec 29 14:02:16: %SEC-6-IPACCESSLOGP: list acl_vty denied tcp 192.168.65.32 49487) -> 0.0.0.0(22), 1 packet

when try to connect over Putty

I do this

WS-C2960-24TC-L-2(config)#ip http server
WS-C2960-24TC-L-2(config)#username cisco pr 15 pass P@ssw0rd

WS-C2960-24TC-L-2(config)#ip http authentication local

and now can access over CNA by new cisco user and password.

Review Cisco Networking for a $25 gift card