SonicWall

SonicWall NSA 2650 Password Recovery

Step-by-step password recovery for the SonicWall NSA 2650 (NSA Series (SonicOS)). Console access required.

Overview

This guide provides step-by-step instructions for resetting lost or forgotten administrative passwords on enterprise networking hardware. Follow the procedure below carefully to regain access while preserving your device configuration.

Prerequisites

Before proceeding with password recovery, ensure you have a console cable, terminal emulation software configured to 9600 baud, and physical access to the device.

Step 1: Establish Console Connection

Connect your terminal cable to the console port of the device and open your serial terminal session.

Step 2: Interrupt the Boot Sequence

Power cycle the hardware and issue a Break key sequence during initial system startup to enter ROMMON mode.

Step 3: Reset Password & Configuration

Bypass startup configuration loading, boot into system software, set your new credentials, and save changes back to non-volatile memory.

Overview

This procedure recovers administrator access to the SonicWall NSA-2650 running SonicOS (SonicWall TZ/NSa series) when the admin password is lost. SonicOS provides a safe mode at boot with a password-reset option that clears the admin password while preserving the configuration.

Prerequisites

Console cable (RJ-45 serial on TZ series via the included console cable; DB-9 on some NSa models) with a terminal session at 115200 baud, 8N1 (TZ series) or 9600 baud (older NSa models — verify). Physical or remote power access to reboot the firewall.

Recovery Procedure — Safe Mode

  1. Connect the console cable with the correct baud rate and open a terminal session.
  2. Power-cycle the firewall.
  3. During boot, when the boot menu appears (SonicWall shows a boot menu with options like "Safe Mode" / "TFTP Upload" / "Boot"), select Safe Mode (or press the key for Safe Mode).
  4. The firewall boots into Safe Mode with the admin password cleared.
  5. Log in via console or the web UI as admin with no password.
  6. Set a new admin password immediately: in the web UI (Device → Administrators → Admin) or via the CLI.
  7. Reboot the firewall to exit Safe Mode: reboot (or power-cycle). Confirm normal boot with the restored configuration and new password.

Recovery Procedure — Reset Button (last resort)

  1. Power off the firewall.
  2. Press and hold the Reset button (pinhole on the front or bottom).
  3. Power on while holding Reset; hold for 10 seconds (or until the test LED pattern changes), then release.
  4. The firewall boots to factory defaults (all configuration is erased).
  5. Restore your config from a SonicWall settings backup (upload via the web UI during initial setup or Management → Settings → Restore).

Important Notes

Protecting Your Configuration

Before recovery, export the settings: in the web UI (Management → Settings → Export Settings) or via CLI. After recovery, restore the exported settings and verify.