01-30-2019 05:17 AM - edited 01-30-2019 05:21 AM
hi,
was asked to use this command and it's my first time using it.
my question, can i still issue a 'write erase' remotely and the 'no service password-recovery' will remain intact?
the router is in a remote area so there's a possibility we might not get it back. so was asked to wipe it out and at the same time ensure other people (who's not very cisco savvy) won't be able to re-use them.
R1(config)#no service password-recovery
Password recovery disable mode is not supported by the current ROMMON.
Please upgrade the ROMMON if you want to use this feature.
i tested this on GNS3 and got an error to upgrade ROMMON. will i get the same error on 'real' cisco router (it's a 3945) and require to upgrade ROMMON software?
01-30-2019 05:50 AM
01-30-2019 06:12 AM - edited 01-30-2019 06:13 AM
hi,
like i said it's a very remote site and getting or sending anything back is just a small probability.
my question wasn't answered, can i still remotely issue a 'write erase' and the 'no service password-recover' would still be there?
i got this from the 'show version' does this mean i wouldn't be able to use the said command (minimum would be 15.1(1)SY)?
ROM: System Bootstrap, Version 15.0(1r)M16, RELEASE SOFTWARE (fc1)
01-30-2019 06:25 AM
01-30-2019 07:22 AM
Hello,
on a side note, 'no service password-recovery' is NOT the default, so when you disable this service and do a 'wr erase', the startup configuration will be erased, and upon reboot, the defaults will apply, which in this case means 'service password-recovery' will be enabed...
01-30-2019 07:55 AM
first a warning,
the 'no service password-recovery' does not render the device useless
the password recovery enabled setting allows you to restart the device and load the config , while bypassing the knowledge of the login and enable password
with 'no service password-recovery', during the recovery process the config will be erased, but the normal ios will still be loaded.
you'll need to erase the flash too, so the device cannot boot into ios
of course the ios can be loaded again to flash, but that needs a little more cisco knowledge.
01-30-2019 09:52 PM
@johnlloyd_13 wrote:
will i get the same error on 'real' cisco router (it's a 3945) and require to upgrade ROMMON software?
People like to use this command BEFORE they dispose of equipment. I don't understand the reason nor the logic behind it.
I have helped other people remove this config or perform factory reset even with this command is used.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide