console到命令行恢复密码,console密码也忘记的话就得重启到bootware恢复了
通过conlse线和crt软件连接并登陆设备,然后把设备断电重启。控制台上会打印如下信息,当出现“press Ctrl+B”的时候快速按住“Ctrl+B” 进入botroom菜单
System is starting...
Press Ctrl+D to access BASIC-BOOTWARE MENU
Booting Normal Extend BootWare
The Extend BootWare is self-decompressing.......................Done!
BootWare Validating...
Press Ctrl+B to enter extended boot menu...
BotWare password: Not required. Please press Enter to continue.
Password recovery capability is enabled.
Note: The current operating device is flash
Enter < Storage Device Operation > to select device.
按住“Ctrl+B”进入如下菜单。选择“<6> Skip Current System Configuration”跳过当前配置启动,不同设备可能不是数字6,
===========================<EXTEND-BOOTWARE MENU>===========================
|<1> Boot System |
|<2> Enter Serial SubMenu |
|<3> Enter Ethernet SubMenu |
|<4> File Control |
|<5> Restore to Factory Default Configuration |
|<6> Skip Current System Configuration |
|<7> BootWare Operation Menu |
|<8> Clear Super Password |
|<9> Storage Device Operation |
|<0> Reboot |
============================================================================
Ctrl+Z: Access EXTEND-ASSISTANT MENU
Ctrl+F: Format File System
Enter your choice(0-9): 6
Flag Set Success.
然后输入0重启设备
===========================<EXTEND-BOOTWARE MENU>===========================
|<1> Boot System |
|<2> Enter Serial SubMenu |
|<3> Enter Ethernet SubMenu |
|<4> File Control |
|<5> Restore to Factory Default Configuration |
|<6> Skip Current System Configuration |
|<7> BootWare Operation Menu |
|<8> Clear Super Password |
|<9> Storage Device Operation |
|<0> Reboot |
============================================================================
Ctrl+Z: Access EXTEND-ASSISTANT MENU
Ctrl+F: Format File System
Enter your choice(0-9): 0
System is starting...
Press ENTER to get started.
操作步骤:跳过启动文件后直接保存当前配置,再重启。
<H3C>save
The current configuration will be written to the device. Are you sure? [Y/N]:y
Please input the file name(*.cfg)[flash:/startup.cfg]
(To leave the existing filename unchanged, press the enter key):(输入回车)
flash:/startup.cfg exists, overwrite? [Y/N]:y
Validating file. Please wait...
Configuration is saved to device successfully.
<H3C>reboot
Start to check configuration with next startup configuration file, please wait.........DONE!
Current configuration may be lost after the reboot, save current configuration? [Y/N]:y
This command will reboot the device. Continue? [Y/N]:y
<H3C>
#Apr 26 12:02:07:166 2000 H3C SHELL/4/LOGIN:
Trap 1.3.6.1.4.1.25506.2.2.1.1.3.0.1<hh3cLogIn>: login from Console
%Apr 26 12:02:07:306 2000 H3C SHELL/5/SHELL_LOGIN: Console logged in from aux0.
<H3C>dir %查看设备配置文件
Directory of flash:/
1 drw- - Apr 26 2000 12:00:20 logfile
2 -rw- 1666 Apr 26 2000 12:05:39 startup.cfg
3 -rw- 1556 Apr 26 2000 12:05:33 _startup_bak.cfg
4 -rw- 151 Apr 26 2000 12:05:30 system.xml
29106 KB total (16876 KB free)
给设备和电脑配置成同网段IP地址(举例:WAC配置成192.168.100.x,电脑配置成192.168.100.x),在电脑上通过3CD软件搭建tftp服务器。

<H3C>sys
System View: return to User View with Ctrl+Z.
[H3C]interface Vlan-interface 1
[H3C-Vlan-interface1]ip address 192.168.100.x 24
[H3C-Vlan-interface1]quit
[H3C]ping 192.168.100.x
PING 192.168.100.x: 56 data bytes, press CTRL_C to break
Reply from 192.168.10a0.a: bytes=56 Sequence=1 ttl=128 time=7 ms
Reply from 192.168.100.a: bytes=56a Sequence=2 ttl=128 time=2 ms
<H3C>tftp 192.168.100.a put startup.cfg
File will be transferred in binary mode
Sending file to remote TFTP server. Please wait... |
TFTP: 1666 bytes sent in 0 second(s).
File uploaded successfully.
<H3C>
下载成功:

可以到本地相关路径(此例子中是E盘)查看到相关文件。
需要恢复之前配置
解决方法:删除密码恢复之前配置文件
使用记事本打开startup.cfg文件

删除aux0口下的认证方式和密码并保存文件

覆盖当前配置文件
<H3C>tftp 192.168.100.20 get startup.cfg
The file startup.cfg exists. Overwrite it? [Y/N]:y
Verifying server file...
Deleting the old file, please wait...
...
File will be transferred in binary mode
Downloading file from remote TFTP server, please wait....
TFTP: 1166 bytes received in 0 second(s)
File downloaded successfully.
<H3C>reboot
Start to check configuration with next startup configuration file, please wait.........DONE!
Current configuration may be lost after the reboot, save current configuration? [Y/N]:n 不保存配置
This command will reboot the device. Continue? [Y/N]:y 确定继续重启
在保的话400不在保的话,你需要先准备一根调试线,然后跳过,如果你知道console密码那就可以直接进去配置一下
console如果能进去就重新配置一下
<H3C> system-view
[H3C] local-user admin 账户admin
[H3C-luser-manage-admin] password simple Admin@1234 配置新密码为Admin@1234
[H3C-luser-manage-admin] authorization-attribute user-role leave-15
[H3C-luser-manage-admin] service-type telnet ssh http https 服务类型为web 和SSH
[H3C-luser-manage-admin] quit
你如果是console密码忘记了,进不去,那就先跳过进去console之后,再按上面的来配置
console密码重置或者跳过
1.重启设备进入bootware菜单
重启过程中按Ctrl+B进入bootware菜单
先按8在按0,然后就可以跳过密码进入系统,然后重新配置密码

暂无评论
暂无评论
一、设备判定
序列号 21980142U1923800003N 归属 H3C SecPath IPS 入侵防御系统(V7 防火墙 / IPS 一体化硬件)。
分为两种场景:
Console 串口无密码、可进 BootWare:自行本地重置密码,完整保留业务配置,无需工程师上门;
BootROM 被加密、Console 也设有密码:必须联系 H3C 官方工程师核验 SN,获取临时解锁验证码才能重置,也就是你所说需要工程师介入重置初始密码的场景。
二、方案 1:自主 Console 重置(能接 Console 就不用上门工程师,保留所有配置)
前置准备
Console 线、电脑串口工具(Xshell/SecureCRT),波特率 9600 8N1 无流控。
设备断电重启,开机瞬间反复按 Ctrl+B 进入 BootWare 菜单;
查看菜单是否存在选项:8. Skip Authentication for Console Login(跳过Console认证)
选中 8 → 选择 0.Reboot 重启设备;
设备重启完毕,Console 登录不需要密码,直接进入系统;
重置管理员账号密码:
plaintext
system-view
# 修改admin管理员密码
local-user admin class manage
password simple 自定义新密码
authorization-attribute user-role network-admin
quit
save force
验证 SSH/Web 均可使用新密码登录即可。
限制条件
如果进入 BootWare 时需要输入BootROM 解锁密码,代表设备开启了安全防破解机制,个人无法解锁,必须官方介入。
三、方案 2:必须 H3C 工程师介入的正规流程(Boot 加密场景,你的现状)
1、对接渠道(任选其一)
1)官方热线:400-810-0504(新华三企业售后专线,推荐)
2)联系当初采购 IPS 的 H3C 授权代理商代为开 case。
2、向工程师提供核验资料(缺一不可,用来确权防止恶意破解)
1)设备完整 SN:21980142U1923800003N
2)设备机身铭牌完整照片;
3)设备维保状态、采购合同 / 出库凭证(用于所有权核验);
4)问题描述:IPS 忘记 admin 管理密码,BootWare 加密无法本地重置,申请临时解锁口令。
3、工程师介入两种处理形式
模式 A:远程下发临时解锁码(不用上门,最快)
工程师后台绑定你的 SN 生成一次性解锁验证码,你在设备 BootROM 加密界面输入验证码,即可开启「免认证启动」,自行进系统改密码,全程保留原有安全策略、IPS 特征库、业务配置,不会清空配置。
模式 B:现场上门(极少情况)
老旧 IPS 机型、加密等级较高的硬件,工程师携带授权工具到场解锁重置。
4、重置完成后收尾
修改密码、保存配置,工程师同步关闭临时解锁权限,恢复设备安全防护机制。
四、严禁操作(避坑)
不要选择 Boot 菜单 6. Ignore configuration and startup(忽略配置启动),该选项会加载出厂配置,所有 IPS 策略、入侵规则、VPN、安全配置全部丢失,业务中断;
不要使用第三方工具破解 IPS 固件,会破坏安全证书、IPS 特征库失效,入侵防御功能直接废掉,失去防护能力;
解锁重置务必在夜间维护窗口执行,避免重启过程短暂断网。
五、补充:账号单纯锁定≠忘记密码
若只是输错密码导致 admin 账号锁定,Console 能正常登录的情况下无需工程师介入,直接解锁即可:
plaintext
display account
unlock account admin
六、整体流程总结
先现场接 Console 尝试进 Boot 跳过认证,能解开就自行改密码;
BootROM 需要密码加密锁定 → 拨打 400-810-0504 提交 SN 确权,由官方工程师下发临时口令解锁重置;
全程优先保留配置,禁止恢复出厂。
暂无评论
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论