Recovering From A Lockout - Cisco Catalyst 6500 Series Configuration Manual

Catalyst 6500 series switch and cisco 7600 series router firewall services
Hide thumbs Also See for Catalyst 6500 Series:
Table of Contents

Advertisement

Chapter 12
Configuring AAA

Recovering from a Lockout

In some circumstances, when you turn on command authorization or CLI authentication, you can be
locked out of the FWSM CLI. You can usually recover access by restarting the FWSM. However, if you
already saved your configuration, you might be locked out.
conditions and how you might recover from them.
Table 12-3 CLI Authentication and Command Authorization Lockout Scenarios
Feature
Lockout Condition Description
Local CLI
No users in the
authentication
local database
TACACS+
Server down or
command
unreachable and
authorization
you do not have
the fallback
TACACS+ CLI
method
authentication
configured
RADIUS CLI
authentication
OL-6392-01
If you have no users in
the local database, you
cannot log in, and you
cannot add any users.
If the server is
unreachable, then you
cannot log in or enter
any commands.
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide
Table 12-3
Workaround: Single Mode
Log into the maintenance
partition and reset the
passwords and aaa
commands. See the
"Clearing the Application
Partition Passwords and
AAA Settings" section on
page
17-9.
Log into the
1.
maintenance partition
and reset the passwords
and AAA commands.
See the
"Clearing the
Application Partition
Passwords and AAA
Settings" section on
page
17-9.
Configure the local
2.
database as a fallback
method so you do not
get locked out when the
server is down.
Recovering from a Lockout
lists the common lockout
Workaround: Multiple Mode
Session into the FWSM
from the switch. From the
system execution space, you
can change to the context
and add a user.
If the server is
1.
unreachable because the
network configuration
is incorrect on the
FWSM, session into the
FWSM from the switch.
From the system
execution space, you
can change to the
context and reconfigure
your network settings.
2.
Configure the local
database as a fallback
method so you do not
get locked out when the
server is down.
12-19

Advertisement

Table of Contents
loading

This manual is also suitable for:

7600 series

Table of Contents