华三交换机Console口密码清除

张开发
2026/4/21 13:57:27 15 分钟阅读

分享文章

华三交换机Console口密码清除
在企业网络运维管理中Console 口是网络设备如华三交换机最核心的本地管理通道也是远程登录失效、系统异常时的最后运维生命线。为保障设备本地访问安全生产环境通常会为 Console 口配置严格的认证密码。但在实际运维过程中常因人员交接密码未同步、长期未登录导致密码遗忘、配置变更后密码记录丢失等情况造成无法通过 Console 口登录设备直接阻断本地管理路径。1. 故障描述当远程管理SSH/Telnet因网络故障、配置错误不可用时Console 口密码锁定将导致设备完全无法运维严重影响故障排查、配置恢复与业务恢复效率。因此掌握华三交换机Console 口密码清除与重置方法是快速解除设备登录锁定、恢复本地管理权限、保障网络运维连续性的关键技能对提升故障应急响应能力、降低运维风险具有重要意义。2. 解决办法步骤 1进入bootroom菜单清除Consle密码。通过conlse线和Secure CRT软件连接并登录设备然后断电重启设备。在配置终端的屏幕上显示如下信息当出现“press CtrlB”的时候快速按住“CtrlB”进入botroom菜单。System is starting...Press CtrlD to access BASIC-BOOTWARE MENUBooting Normal Extend BootWareThe Extend BootWare is self-decompressing.......................Done!BootWare Validating...Press CtrlBto enter extended boot menu...BotWare password: Not required. Please press Enter to continue.Password recovery capability is enabled.Note: The current operating device is flashEnter Storage Device Operation to select device.步骤 2进入bootroom主菜单查看是否使能密码恢复功能。Password recovery capability is enabled. //enabled使能密码恢复功能。Note: The current operating device is flashEnter Storage Device Operation to select device.EXTENDBOOTWARE MENU|1 Boot System ||2 Enter Serial SubMenu ||3 Enter Ethernet SubMenu|4 File Control ||5 Restore to Factory Default Configuration //恢复到出厂默认配置|6 Skip Current System Configuration //跳过当前系统配置启动|7 BootWare Operation Menu ||8 Clear Super Password ||9 Storage Device Operation ||0 Reboot //重启设备CtrlZ: Access EXTEND-ASSISTANT MENUCtrlF: Format File SystemEnter your choice(0-9):Flag Set Success.步骤 3进入bootroom主菜单然后选择“6 Skip Current System Configuration”跳过当前系统配置启动此时设备不会删除上次启动时加载的配置文件不同设备可能不是数字6。有部分系列交换机型号可以使用如下方法清除console口密码1. 重启设备进入BootWare主菜单选择6即以忽略系统当前配置的方式启动此时设备不会删除上次启动时加载的配置文件。Password recovery capability is enabled.Note: The current operating device is flashEnter Storage Device Operation to select device.EXTENDED-BOOTWARE MENU|1 Boot System ||2 Enter Serial SubMenu ||3 Enter Ethernet SubMenu ||4 File Control ||5 Restore to Factory Default Configuration ||6 Skip Current System Configuration ||7 BootWare Operation Menu ||8 Skip Authentication for Console Login ||9 Storage Device Operation ||0 Reboot |CtrlZ: Access EXTENDED ASSISTANT MENUCtrlF: Format File SystemCtrlC: Display CopyrightEnter your choice(0-9): 62. 系统出现如下提示表明已经设置成功。Flag Set Success.3. 当再次出现BootWare主菜单时选择1设备开始启动。4. 重启设备后设备的配置为空用户可以在系统视图下配置回滚恢复原有配置如下配置表示将当前配置回滚到配置文件startup.cfg中的配置状态。如果用户不想恢复原有配置请跳过此步骤。Sysname system-view[Sysname] configuration replace file flash:/startup.cfgCurrent configuration will be lost, save current configuration? [Y/N]:nNow replacing the current configuration. Please wait ...Succeeded in replacing current configuration with the file flash:/startup.cfg.5. 在系统视图下设置新的Console口的登录认证模式和密码例如设置Console口验证方式为密码验证且以明文方式设置Console口的密码为123456。Sysname system-view[Sysname] line console 0[Sysname-line-console0] authentication-mode password[Sysname-line-console0] set authentication password simple 1234566. 保存新配置。[Sysname-line-console0] savePassword recovery capability is enabled. //enabled使能密码恢复功能。Note: The current operating device is flashEnter Storage Device Operation to select device.EXTENDBOOTWARE MENU|1 Boot System ||2 Enter Serial SubMenu ||3 Enter Ethernet SubMenu|4 File Control ||5 Restore to Factory Default Configuration //恢复到出厂默认配置|6 Skip Current System Configuration //跳过当前系统配置启动|7 BootWare Operation Menu ||8 Clear Super Password ||9 Storage Device Operation ||0 Reboot //重启设备CtrlZ: Access EXTEND-ASSISTANT MENUCtrlF: Format File SystemEnter your choice(0-9):6 //跳过当前系统启动的配置文件Flag Set Success.步骤 4输入0然后自动重启设备。EXTEND-BOOTWARE MENU|1 Boot System ||2 Enter Serial SubMenu ||3 Enter Ethernet SubMenu ||4 File Control ||5 Restore to Factory Default Configuration ||6 Skip Current System Configuration ||7 BootWare Operation Menu ||8 Clear Super Password ||9 Storage Device Operation ||0 Reboot |CtrlZ: Access EXTEND-ASSISTANT MENUCtrlF: Format File SystemEnter your choice(0-9):0 //输入0重启设备System is starting...Press ENTER to get started.步骤 5如不需要配置直接跳过启动文件后直接保存当前空配置再重启设备。H3C saveThe current configuration will be written to the device. Are you sure? [Y/N]:yPlease input the file name(*.cfg)[flash:/startup.cfg](To leave the existing filename unchanged, press the enter key):输入回车flash:/startup.cfg exists, overwrite? [Y/N]:yValidating file. Please wait...Configuration is saved to device successfully.H3CrebootStart to check configuration with next startup configuration file, please wait.........DONE!Current configuration may be lost after the reboot, save current configuration? [Y/N]:yThis command will reboot the device. Continue? [Y/N]:y步骤 6如需要之前的配置导出当前配置文件备份再清除密码然后再导入配置文件覆盖。1. 备份配置文件H3C#Apr 26 12:02:07:166 2000 H3C SHELL/4/LOGIN:Trap 1.3.6.1.4.1.25506.2.2.1.1.3.0.1hh3cLogIn: login from Console%Apr 26 12:02:07:306 2000 H3C SHELL/5/SHELL_LOGIN: Console logged in from aux0.H3C copy startup.cfg startup_bak.cfg //复制一份配置文件进行备份H3Cdir //查看设备配置文件Directory of flash:/1 drw- - Apr 26 2000 12:00:20 logfile2 -rw- 1666 Apr 26 2000 12:05:39 startup.cfg3 -rw- 1556 Apr 26 2000 12:05:33 startup_bak.cfg4 -rw- 151 Apr 26 2000 12:05:30 system.xml29106 KB total (16876 KB free)2. 给设备和电脑配置成同网段IP地址在电脑上通过3CD、MobaXterm软件搭建tftp服务器。H3C system-viewSystem View: return to User View with CtrlZ.[H3C]interface Vlan-interface 1[H3C-Vlan-interface1] ip address 192.168.100.1 24[H3C-Vlan-interface1]quit[H3C] ping 192.168.100.2PING 192.168.100.2: 56 data bytes, press CTRL_C to breakReply from 192.168.100.2: bytes56 Sequence1 ttl128 time7 msReply from 192.168.100.2: bytes56 Sequence2 ttl128 time2 ms3. 设备上传配置文件至tftp服务器。H3Ctftp 192.168.100.2 put startup.cfgFile will be transferred in binary modeSending file to remote TFTP server. Please wait... |TFTP: 1666 bytes sent in 0 second(s).File uploaded successfully.H3C设备文件上传成功tftp服务器下载成功。4. 清除console密码。可以到本地相关路径查看到相关文件需要恢复之前配置解决方法删除密码恢复之前配置文件1使用记事本打开startup.cfg文件 。2删除aux0口下的认证方式和密码并保存文件。5. 覆盖当前配置文件。H3C tftp 192.168.100.20 get startup.cfgThe file startup.cfg exists. Overwrite it? [Y/N]:y //选择y确认覆盖文件。Verifying server file...Deleting the old file, please wait......File will be transferred in binary modeDownloading file from remote TFTP server, please wait....TFTP: 1166 bytes received in 0 second(s)File downloaded successfully.H3C rebootStart to check configuration with next startup configuration file, please wait.........DONE!Current configuration may be lost after the reboot, save current configuration? [Y/N]:n 不保存配置This command will reboot the device. Continue? [Y/N]:y 确定继续重启步骤 7重启设备后Console口密码清除成功原始配置依然存在不影响现有网络。

更多文章