cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2461
Views
0
Helpful
5
Replies

password recovery on IDS 4215 Appliance sensor

ptaylor51
Level 1
Level 1

Does anyone know how i can recover from an admin password that has been forgotten on a Cisco IDS 4215 Appliance Sensor

As for the 4235 and the IDSM it is quit easy, however the 4215 does not have cd-rom drive. Would i have to tftp a new image to the sensor, something like you would have to do with a pix 506e firewall ?

regards

Peter

5 Replies 5

marcabal
Cisco Employee
Cisco Employee

For the 4215 we have what are called system images.

The system images do what the CDROM does for the other sensors.

It will reformat the harddrive and install new software.

The system image is tftp downloaded and installed by ROMMON.

The system image is located here:

http://www.cisco.com/cgi-bin/tablebuild.pl/ids4-app-recovr

You will need to download:

IDS-4215-K9-sys-4.1-4-S91a.img

The installation instructions are in this file:

IDS-4215-K9-sys-4.1-4-S91a.txt

NOTE: You may need to update your ROMMON prior to installing the system image.

The new ROMMON can downloaded from:

http://www.cisco.com/cgi-bin/tablebuild.pl/ids-firmware

The file is:

IDS-4215-bios-5.1.7-rom-1.4.bin

The installation instructions are in:

IDS-4215-bios-5.1.7-rom-1.4.txt

Can this not also be accomplished simply by selecting the recovery partition during the boot-up process?

All appliances, regardless of platform, have a recovery partition that is selectable during boot-up that will perform that same function as a re-image via either Recovery CD or System Image if I recall correctly.

Just another option, unless I'm missing something...

Alex Arndt

You are correct.

If all you have done is forget the password, then using the recovery partition is a viable option.

And the option is available on all of the appliance sensors.

If the system has been corrupted and you don't trust what is on the recovery partition then the system image file would be the other method to use (both the CD and system image install new application partitions and new recovery partitions).

Just to clarify what marcabal and a.arndt have said:

All appliance sensors DO have a recovery partition that is accessible using the GRUB boot menu. However, when/where this functionality is available in 4.x will depend on the platform type. Older appliances with keyboard/monitor connections (4210/4220/4230/4235/4250) will only display the GRUB boot options on a monitor connected directly to the sensor, and not on a serial connection, regardless of "display serial" setting. Newer appliances (4215 and later) do not offer keyboard/monitor connections, and will output this boot menu on the serial port (console).

I am told that this inconsistency will be resolved in the 5.0 release. I would expect the GRUB menu output to be controlled by the "display serial" command on legacy hardware. Newer appliances will always display it on the serial/console port.

Alex - thank you for your help,as you said all you have to do is run the recovery from the conole, at bootup select option 1 recovery and then hit the "ENTER" key, from there it rebuilds the kernal and the deffault password is set back to cisco cisco

regards

peter