ASR9000/XR: How to reset a lost password (password recovery on IOS-XR)

Document

Mar 30, 2011 6:36 AM
Mar 30th, 2011

Introduction

This document shows you how to reset a lost password or when you have locked yourself out due to a problematic AAA configuration.

Core Issue

Because IOS-XR is substantially different in the way config files are managed, the standard trick of conf-reg 0x2142 will not work for IOS-XR.

You can lock yourself out if you are configuring aaa authentication to tacacs with no local fall back, if the tacacs server is unavailable there

is no way for you to get in.

eg:

aaa authentication login default groupt tacacs

Also this procedure is good when you have forgotten the password to your super user in IOS-XR to manage your machine.

Resolution

The following step through guide can be tried, the details of each step are listed below with more explanation:

  • •1)       Fixing AAA configuration errors  
    • •a.       On the standby RP/RSP from the CONSOLE port hit the ESC key and type ‘ksh’ without quotes and hit ENTER  
      • i.      Login with a local username and password
      • ii.      If this fails get the standby RP/RSP into ROMMON
      • iii.      Bypass KSH authentication with AUX_AUTHEN_LEVEL=0 and boot
      • iv.      Try step 1a again or use the AUX port and go to step 1b
    • •b.       View and edit the configuration from KSH  
      • i.      Save the configuration to harddisk with ‘nvgen -c -l 1 -t 1 -o 1  > harddisk:/backupconfig.txt’
      • ii.      Edit out the bad AAA statements with ‘nano –e /harddisk:/backupconfig.txt’
    • •c.        Try to roll back the configuration with ‘config_rollback –n 0x1’
    • •d.       Bypass AAA and enter exec mode with ‘/pkg/bin/exec –a’
    • •e.        Attempt to use show commands or change the configuration 
      • i.      If this fails reload all RP/RSP ROMMON
      • ii.      On the standby card set IOX_CONFIG_FILE=/harddisk:/backupconfig.txt or use ‘boot <image> -a <bogus_config>’ and boot
      • iii.      Also follows step 2g if you saw issues in 1a
      • iv.      If nothing above worked then this is the only option
  • •2)       Fixing a lost local username/password  
    • •a.       Get the standby RP/RSP into ROMMON  
      • i.      Bypass KSH authentication with AUX_AUTHEN_LEVEL=0 and boot
    • •b.       View the admin configuration with ‘nvgen –b /admin/cfg’
    • •c.        Save the admin configuration to the harddisk and edit out any and all users if you need other portions of this file
    • •d.       Bypass AAA and enter exec mode with ‘/pkg/bin/exec –a’
    • •e.        Attempt to use show commands or change the configuration
    • •f.        If this fails reload all RP/RSP to ROMMON
    • •g.        Set confreg 0x142 or IOX_ADMIN_CONFIG_FILE=/harddisk:/backupconfig.txt on the standby card or ‘boot <image> -o <bogus_config>’ and boot  
      • i.      Note that this does not ignore the exec configuration and will not help if the issue is AAA related
    • •h.       Enter a new username and password when prompted
  • •3)       Fixing both issues 
    • •a.       If you do not know a local login or cannot use the KSH method to recover the configuration then both the IOX_CONFIG_FILE and IOX_ADMIN_CONFIG_FILE will need to be pointed towards non-existent files. Both the admin and exec configurations will be cleared by this method
  • •4)       Make sure to remove any ROMMON variables which were changed

There are 2 steps to this process.

1) Override the BASE running configuration

     When you configure the problematic AAA statement sample as above.

2) Override the admin configuration that stores local usernames and passwords

     When you don't remember any of the local usernames/passwords you have defined locally.

Overriding the Base configuration in XR:

Step 1

In rommon set the following variable:

rommon> IOX_CONFIG_FILE=/harddisk:/no-config

the file no-config is just a non existent file, you can give any name here really.

Step 2

And issue 'sync', this will make the change persistent in the rommon config vars.

rommon> sync

Step 3

Issue 'i' or 'reset' and when the rsp is booting up, it should ignore  the config file, since there's no config file found on /harddisk:  called no-config

rommon> reset

or

rommon> i

Overriding the ADMIN configuration in XR:

In Admin configuration we store all the local usernames and passwords.

Step 1

Similarly you can do the same thing for admin config:

IOX_ADMIN_CONFIG_FILE=/disk0:/none

You should get prompted for root user/pass and will have a blank config on the box.

You need to load your config and do your modification.

Step 2 and 3

are the same as for the base xr config file.

Second Option

Another way of recoveryof the password is to enable the following again in rommon:

rommon> AUX_AUTHEN_LEVEL=0

Which will allow the aux port to drop to ksh upon the RSP bootup with no prompt for login.

At the prompt you can either type:

/pkg/bin/exec -a

Which will give you a router prompt: Or simply

# Config

Which drops you into EXEC config mode.

Example

# uname -a

QNX node0_RSP0_CPU0 6.4.0 2009/12/10-13:43:22PST asr9k ppcbe

# config

RP/0/RSP0/CPU0:RO-A(config)#exit

#

# /pkg/bin/exec -a

RP/0/RSP0/CPU0:RO-A#

RP/0/RSP0/CPU0:RO-A#

RP/0/RSP0/CPU0:RO-A#exit

#

Clean up

Make sure that after you're done with your changes, in case you made the rommon vars persistent, you may want to unset

the variables to get back to the normal files that are used.

rommon> unset IOX_ADMIN_CONFIG_FILE

rommon> unset IOX_CONFIG_FILE

rommon> sync

All set!


If you forget the cleanup, you might see these lines:

RP/0/RSP1/CPU0:Oct 28 07:18:37.141 : locald_DSC[301]: %SECURITY-LOCALD-3-LWA_ADD_FAIL : Failed to add the username admin to lightweight authentication password database: No such file or directory

Related Information

It has been seen that sometimes a system autonomously enters password recovery mode. This is identified with:

“enter root-system username”

This is due to a ddts known as CSCth03923

You end up providing what you think is a known username and password combination and it failes to get you in.

The solution is simple, just enter a fake username/password that you know for sure has not been configured yet and you're in!

Xander Thuijs - CCIE #6775

Sr Tech Lead ASR9000

Average Rating: 5 (2 ratings)

Comments

mdebraba Wed, 11/28/2012 - 06:43 (reply to billzha)

Unlike IOS, 0x142 will not ignore the configuration, but only ask you for a new root password at bootup.

So this will work for local authentication, but will not address a TACACS configuration/reachability issue (which is actually more frequent than just 'forgetting' the password).  In those cases you need to use the method described above.

xthuijs Fri, 01/11/2013 - 06:01 (reply to rakeshsekhar)

Not inside XR, you would need a tacacs/radius server for that that can do profile management for failed auth attempts and pw expiry.

xander

rakeshsekhar Fri, 01/11/2013 - 06:10 (reply to xthuijs)

Hi Xander, Thank you for your reply.

              But, how about the passwords of local users?

rakeshsekhar Wed, 01/16/2013 - 07:07

Hi Xander,

                  Thanks for your infomation. I couldn't find "login local" command in line console of ASR9k. Is n't available in XR ? Where can we apply user user-name and password password in ASR ?

xthuijs Wed, 01/16/2013 - 08:04 (reply to rakeshsekhar)

this is the precise command:

RP/0/RSP0/CPU0:A9K-BNG(config)#line console login authentication ?

  WORD     Use an authentication list with this name

  default  Use the default authentication list

xthuijs Wed, 01/16/2013 - 08:31 (reply to rakeshsekhar)

if you combine it with aaa authentication login default local, it  will use the local username and password dbase.

which is also nicely documented here btw: https://supportforums.cisco.com/docs/DOC-22848

It references another article in case you want to go hardcore  with "priv levels" and what have you.

cheers

xander

--------

Xander Thuijs CCIE #6775

Principal Engineer ASR9000

rakeshsekhar Fri, 01/11/2013 - 05:57

Hi,

     As a part of this discussion, please let me know if any one knows how to configure aging/expiry of passwords, the number of atttenpts of a password to logon in  ASR 9000 ??

rakeshsekhar Wed, 01/16/2013 - 08:26

Hi Xander,

If we follow the below stepsm, will the router ask username and password? please suggest the right way if it's wrong.

(config)#aaa authentication login default group local

(config)#line console login authentication default

thushar362 Wed, 01/23/2013 - 09:56

Hi Xander,

                    May I know how to configure a telnet connection in ASR 9k. Can we use template name for representing a number of vty lines ?

xthuijs Wed, 01/23/2013 - 10:09 (reply to thushar362)

Tushar: you need to define a telnet server in the vrf that you want to accept sessions on:

eg:

telnet vrf default ipv4 server max-servers 4

the number "4" here identifies the number of vty's or simultenous telnet sessions you allow to accept.

these vty's are used for both telnet and ssh btw.

line template main purpose is for the console.

xander

xthuijs Wed, 01/23/2013 - 12:25 (reply to thushar362)

the telnet ipv<x> server enables the telnet deamon and provides the number of vty's specified.

the vty-pool command applies a template of configuration to the vty's.

since you can't really control on which vty a telnet lands (first session uses vty 0, second number 1 etc),

there is little use of making different vty pools with different line template configuration if you ask me.

So base configuration would be:

aaa authorization exec default local

aaa authentication login default local

vty-pool default 0 4 line-template default

telnet vrf default ipv4 server max-servers 4

then you have room for 5 telnet sessions locally authetnicated.

xander

xthuijs Thu, 01/24/2013 - 08:42 (reply to thushar362)

you are missing the telnet ipv4 server, that is far more important then the line template (which is optional).

this is the minimum configuration to enable telnet:

telnet vrf default ipv4 server max-servers 4

vty-pool default 0 4 line-template default

xander

thushar362 Thu, 01/24/2013 - 11:30

Hi Xander,

                I have added the  above steps into my router. But I am not getting the expected result. Is there any mistakes in my above configuration ? This is my first experience on ASR. Please help me, I am waiting for your response.

xthuijs Thu, 01/24/2013 - 11:41 (reply to thushar362)

Tushar, I don't have a crystal bowl so I can't really tell why it is not working for your case.

There are 2 steps very important here. that is the config register for pw recovery and the deviation of the admin and iox config files to boot an empty config and bypass any potential AAA and local user directives.

If that doesn't work, then it would be best to capture the logging, and document the steps you took and open a TAC case for additional support.

xander

thushar362 Wed, 01/23/2013 - 11:14

Hi Xander,

                Thanks Xander, Yeah, but when I searched , I got these steps. Here don't  they discribe about telnet configuration ?

thushar362 Thu, 01/24/2013 - 08:39

Hi Xander,

              Thanks for your precious response. If I copy the steps and paste into my ASR router, will the telnet be activated ? Let me know if missed any mandatory steps because I didn't yet configure the same in XR .

thushar362 Thu, 01/24/2013 - 09:59

Xander, thanks a lot. I want to create a vty for around 50 numbers and want to limit the maximum number of inbound connections as around 7 and maximum outbound connections as 25. Let me know if any more corrections required.

thushar362 Fri, 01/25/2013 - 13:24

Xander,

                  Thanks for your reply. We have solved the problem. Still we want to redirect the traffic coming from some particular ip address(sources)  into some other destination. I planned to use class map along with policy map. But in policy map, there is no "next hop" option. Which method is the best to redirect the traffic ?. Along with that we want to apply the policy or condition on some interfaces only.

xthuijs Fri, 01/25/2013 - 15:18 (reply to thushar362)

That functionality you're after is ABF (access list based forwarding). It is a "regular" ACL with a next hop option in any vrf you like.

Just one comment, this question has nothing to do with the article above. Moving forward, would want to recommend to raise "new" questions via the right forum so everyone can chime in in case I can't respond.

regards

xander

---

Xander Thuijs CCIE #6775

Principal Engineer ASR9000

manuv1984 Wed, 01/30/2013 - 09:23

Hi Xander,

                    You have mentioned in the above comments as "main purpose of line template is for console". But in most of the configurations I have seen this with telnet configuration. Above you have mentioned the step

"telnet vrf default ipv4 server max-servers 4" , here 4 means number of inbound connections(maximum number of  incomming connections to the router). If so  where can we configure maximum number of outbound connections? Along with that for simply enabling telnet, can't we use "telnet server" instead of the above step ?

gpeirce Wed, 02/27/2013 - 10:47

re: the clean up stage, is the resetting of these variables possible from the IOS-XR CLI or only through rommon?

Ex. If I've made them persistant via 'sync' and then booted into image, do I have to return to rommon to unset the config file variable?

xthuijs Wed, 02/27/2013 - 10:56 (reply to gpeirce)

you can do it out of admin config also:

RP/0/RSP0/CPU0:A9K-BNG#admin config-register ?

  <0x0-0xffff>       a value for the config register

  boot-mode          set the boot mode characteristics

  console-baud       set the console baud rate

  console-break-key  set the console break key

  password-recovery  set the password recovery mode

gpeirce Wed, 02/27/2013 - 11:46

ah - I was looking for something in more IOS-XR speak rather than the IOS method ;-)

I currently show a config-reg of 0x2102 which I would think should boot the current config.

However, I'm also seeing this on reload.

%MGBL-CONFIG-6-STARTUP_ALTERNATE : Configuration Manager can not find any configuration to apply from the alternate source '/harddisk:/no-config' . Default configuration will be applied.

booting to rommon I see that IOX_CONFIG_FILE remains set to something that does not exist.

I can clear this from within rommon, but I thought there may be a way from CLI - not sure config-reg can modify this variable (?).


xthuijs Wed, 02/27/2013 - 11:52 (reply to gpeirce)

there is no XR command to unset rommon variables other then the config register,

so you'd need to go back to rommon and "UNSET" the IOX_CONFIG_FILE variable to have the system use the default

which is sysdb that is the actual "start up" configuration.

xander

alexander88 Tue, 12/31/2013 - 12:13

Hi Xander, 

   I believe step 3.a in the resolution should read:

     •a.       If you do not know a  local login or cannot use the KSH method to recover the configuration  then both the IOX_CONFIG_FILE and IOX_ADMIN_CONFIG_FILE 

   Instead of the current, where it states to change the ADMIN_CONFIG file twice:

  If you do not know a  local login or cannot use the KSH method to recover the configuration  then both the IOX_ADMIN_CONFIG_FILE and IOX_ADMIN_CONFIG_FILE

Other than that thank you for the detailed instructions.

Thanks,

Alex

Actions

Login or Register to take actions

This Document

Posted March 30, 2011 at 6:36 AM
Stats:
Comments:29 Avg. Rating:5
Views:7703 Contributors:8
Shares:2
Tags: No tags.