The no service passwordrecovery command prevents console from accessing ROMMON

Boston(config)#no service password-recovery WARNING:

Executing this command will disable password recovery mechanism. Do not execute this command without another plan for password recovery. Are you sure you want to continue? [yes/no]: yes Boston(config)#

You can mitigate this potential security breach by using the no service password-recovery global configuration command. The no service password-recovery command has no arguments or keywords.

Caution If a router is configured with the no service password-recovery command, all access to the ROMMON is disabled. If the router flash memory does not contain a valid Cisco IOS image, you will not be able to use the rommon xmodem command to load a new flash image. In order to repair the router, you must obtain a new Cisco IOS image on a flash SIMM, or on a PCMCIA card (3600 only). See Cisco.com for more information regarding backup flash images.

Once the no service password-recovery command is executed, the router boot sequence will look similar to this:

System Bootstrap, Version 11.3(2)XA4, RELEASE SOFTWARE (fc1)

Copyright (c) 1999 by cisco Systems, Inc.

C2600 platform with 65536 Kbytes of main memory

PASSWORD RECOVERY FUNCTIONALITY IS DISABLED

program load complete, entry point: 0x80008000, size: 0xed9ee4

© 2006 Cisco Systems, Inc. Cisco Device Hardening 5-97

Also, after the no service password-recovery command is executed, a show running configuration command listing will contain the no service password-recovery statement as shown here:

version 12.0

service tcp-keepalives-in service timestamps debug datetime localtime show-timezone service timestamps log datetime localtime show-timezone service password-encryption no service password-recovery !

hostname Boston

5-98 Implementing Secure Converged Wide Area Networks (ISCW) v1.0

Setting a Login Failure Rate

This topic describes how to secure administrative access to Cisco routers by setting a login failure rate.

Starting with Cisco IOS software Release 12.3(1), you can configure the number of allowable unsuccessful login attempts by using the security authentication failure rate global configuration command.

security authentication failure rate threshold-rate log security authentication failure rate Parameters

Parameter

Description

threshold-rate

This is the number of allowable unsuccessful login attempts. The default is 10 (the range is 2 to 1024).

log

The log keyword is required. Results in a generated syslog event.

When the number of failed login attempts reaches the configured rate, two events occur:

■ A TOOMANY_AUTHFAILS event message is sent by the router to the configured syslog server.

■ A 15-second delay timer starts.

After the 15-second delay has passed, the user may continue to attempt to log in to the router.

© 2006 Cisco Systems, Inc. Cisco Device Hardening 5-99

Continue reading here: Setting a Login Failure Blocking Period

Was this article helpful?

0 0