Cisco

Cisco Firepower and Secure Firewall Password Recovery

Recover an administrator password on Cisco Firepower and Secure Firewall appliances. On managed appliances the password is set in the management centre.

Overview

This guide provides step-by-step instructions for resetting lost or forgotten administrative passwords on enterprise networking hardware. Follow the procedure below carefully to regain access while preserving your device configuration.

Prerequisites

Before proceeding with password recovery, ensure you have a console cable, terminal emulation software configured to 9600 baud, and physical access to the device.

Step 1: Establish Console Connection

Connect your terminal cable to the console port of the device and open your serial terminal session.

Step 2: Interrupt the Boot Sequence

Power cycle the hardware and issue a Break key sequence during initial system startup to enter ROMMON mode.

Step 3: Reset Password & Configuration

Bypass startup configuration loading, boot into system software, set your new credentials, and save changes back to non-volatile memory.

Overview

Firepower and Secure Firewall appliances are usually managed by a Firepower Management Center (FMC) or the CDO/SecureX. If the device is FMC-managed, the password is reset from the management centre rather than locally.

Prerequisites

Recovery Steps — locally managed (FDM / FXOS)

  1. Connect the console, terminal at 9600 8-N-1 (Firepower 1000/2100) or via the management interface.
  2. At the login prompt, use the documented password-reset procedure for your release; on FXOS platforms you can also reach the rommon equivalent from the chassis manager.
  3. For FDM-managed devices, the recovery passphrase can be set at the console prompt, which then allows a password reset without wiping the configuration.
  4. Set the new administrator password, then save.

Recovery Steps — FMC-managed

  1. Log into the Firepower Management Center.
  2. Navigate to Devices > Device Management, select the device and use Change Password / re-registration to reset credentials.

Consult the Cisco documentation for your specific Firepower release before performing a console reset — the exact prompts differ between FXOS and FTD.