We've moved from Blogger to WordPress!

You should be automatically redirected in 5 seconds. If not, visit
http://blog.michaelfmcnamara.com
and update your bookmarks.

Sunday, November 25, 2007

Factory Reset Nortel Ethernet Switch

There can be times when you need to factory reset a switch. This process can be accomplished through the CLI but if you've lost the switch password you'll need to follow a special process. This process should work for any of the Ethernet Switches (450, 460, 470) and the Ethernet Routing Switches 2500 Series, 4500 Series, 5500 (5510, 5520, 5530) Series. There is a different process to recover lost passwords on the Ethernet Routing Switch 1600 and 8600.

Follow these steps:

  1. Connect to the console port of the switch (9600,8,N,1)
  2. Reboot the switch.
  3. When the first line of the diagnostics tests is displayed, press CTRL-C. The system then displays a menu.
  4. Select option "i" to factory default the switch.
  5. Select option "a" to run the agent code.
Upon boot up, the switch will be in a factory default configuration.

Cheers!

20 comments:

Unknown said...

Hi Michael,

There is a clever way to reset the password without losing configuration nor reboot.

Though only possible when
1) you still have SNMP-access
2) the software agent allows downloading the ASCII config of the switch to TFTP

So this is how to do it:
- With JDM instruct the switch to put the ASCII config on your TFTP
- Edit the line for the telnet/console password en set it to 'none'
- Save the config file
- Upload it to the switch

Result will be that you can login without password en be able to set a new password.

Compliments on the informational site!

Michael McNamara said...

Hi Thomas,

Thanks for the comment. I can see that you've been around the block a few times with the Nortel switches.

While we're on the topic there's also another problem folks can run into when they set both the RO and RW passwords the same. Whenever you log into the switch it will assume the READ-ONLY user, leaving you unable to make any changes. A quick workaround is to use the Web GUI (if it's enabled) to log into the switch as the RW user (provide the username of RW along with the RW password). When your inside the Web GUI you can change the passwords.

Thanks again for the feedback Thomas!

Anonymous said...

I have a Baystack 310-24T Reset Password and I've tried using the method Michael suggested and it's not working. No matter what command I give it, it runs POST and ask for password when it's done. Here is the output:
Bay Networks 310-24T Ethernet Switch
Copyright (C) 1999, Bay Networks, Inc.

**********************************************************************
Power On Self Test


UART Local Loopback Test PASSED
CPU Test PASSED
STACK DRAM Test PASSED
DRAM Test PASSED
Watch Dog Timer Test PASSED
Timer Module Test PASSED
FLASH Image Checksum Test PASSED
Software Version [1.6.5 ]
~


Enter '.RETURN to go to Boot Options Menu
Booting Switch software
Decompressing ...

Eventually, it ask for a password. I hit the CRTL-C command just when I see:
Enter '.RETURN' to go to Boot Options Menu

I really would appreciate any help to get into this switch and reset the password. I really would. I've opened it to see if there is a battery there I could take out, but found none. Please help.
Michael-not the owner of this blog

Michael McNamara said...

The BayStack 310 was one of the original Ethernet switches in the BayStack product line so it looks like it doesn't conform to the procedure I've outlined above.

What are the options if you follow the prompt, "Enter '.RETURN to go to Boot Options Menu"?

One of those options might be to reset the flash NVRAM, which is the configuration.

Anonymous said...

That's not one of the options it gives me; to reset NVRAM.

You seem to know about these things-a lot. Is there any other way you could help me, please. I mean please.

Thanks,
Michael

Michael McNamara said...

Hi Michael,

What are the options it gives you? Can you post a copy of the options from HyperTerminal (or whatever application your using to access the serial port).

I don't personally have access to a BayStack 310 switch so I can't really add anything. I would be very surprised though if there wasn't some option that allowed you to reset the switch configuration since I believe the BayStack 310 was released after the BayStack 450 switch, and that supports "initialize NVRAM" the option that clears the configuration.

Sorry,
Mike

Anonymous said...

Hi Mike:

Thanks a lot. I will try and post the output here soon. I really need this open, so I won't even mind sending it to you; if that what it will take.

Regards,
Michael

Michael McNamara said...

I did some research today and made some calls and found the following. The BayStack 350/450 switches do not support resetting the configuration (password). The very early versions of software (boot code/agent code) did support a backdoor password "NetICs" which needed to entered within the first 30 days of a switch booting, however, later versions did not support any method of resetting the switch locally. I'm not 100% clear on this but some believe that Nortel might be able to generate a onetime password based on the MAC address of the switch. You would, of course, need a maintenance support contract with Nortel. Someone also brought up the possibility of stacking the switch with another switch although I don't believe the BayStack 310 model supported stacking.

Here's the manual from Nortel;

http://www25.nortelnetworks.com/library/tpubs/pdf/switches/bstack/310/201875A.PDF


Sorry but it seems like you might be out of luck.

Mike

Anonymous said...

Mike:
Thanks so much for all your work on this. Since I have 3 of these, I'm ready to open, fiddle, and test. I'm thinking hard-reset. Please let me know if you can think of anything I could do while I'm in there.

Kind regards,
Michael

Anonymous said...

Hi
Was the hard reset successful?

Anonymous said...

I need some help with Baystack 350T console port. I use a straight thru null modem and nothing appears on the screen. What am I doing wrong?

Anonymous said...

When you say on-screen, what screen do you mean? You should go to hyper terminal that's in windows to be able to see anything.

You can get to it by going to run>cmd>hypertrm

Is your switch port managed. After months of working on mine, I find out the ports are 10BaseT. I need 24...anyone?

Anonymous said...

..sorry, I meant I need a port managed switch that's 100BaseT. Anyone...?

Anonymous said...

Sorry, Yes through hyperterm.
I used a straight through cable with mod adapters on each end. I am now getting
BayStack 350T Self-Test
ASIC addressing test ... Pass
ASIC buffer RAM test ... Pass
Physical layer test ... Pass
Port internal loopback test ... Pass
Self-test complete.
But right after this I get odd characters and the output completely stops...Any ideas!?

Anonymous said...

Hello all,
I ve got a 470-24T which i need to access with RW, but cannot do so through web, nor can access R. I can connect to it through telnet and get access to priviliged level (exec) on the command line. Is there a way i can reset this switch either to a RW password or default? Help please. I am very much interested in the command line to reset the whole switch or the username and passsword. I did enter same password for RW and R and i was never given a chance to accept or deny the changes. Web access .....

Michael McNamara said...

Hi Pete,

If I understand your post you're having issues because you set the RW and RO to the same password?

Unfortunately that can leave you locked out from the RW account, although there is a fix. Login to the switch from the web GUI and change the RO password. When logging into the web GUI you obviously need to use the RW account and password.

Good Luck!

Anonymous said...

I can not logon through the Web GUI. I can telnet to it and get access to the command line with privileged mode. I need some CLI that will let me change the password. Can you help.

Michael McNamara said...

Have a look at this post and let us know if that is what you're looking for.

Cheers!

Unknown said...

Hi Michael,

do you know how to clear passwords on Nortel BES120-24T PWR Business Ethernet Switch 120?

I can reset config from Boot menu config, but not passwords. On unit I have it was to clear it form Boot menu. Do you have any idea how to do it?

Regards,
P.

Michael McNamara said...

Hi Pawel,

The Nortel Business Ethernet Switch (BES) is a relatively new product as you've noted. There are some posts
on Tek-Tips that make reference to resetting the password on a BES;

http://www.tek-tips.com/viewthread.cfm?qid=1451699&page=1

Looking at the documentation is seems that the default username and password are the same as the Business
Communication Manager (BCM) and Survivalbe Remote Gateway (SRG);

Username: nnadmin
Password: PlsChgMe!

Actually on page 185 of the Using
the Nortel Business Ethernet Switch 100/200 Series
manual indicates that you can factory reset the switch using the button
on the front of the switch.

Reset button - for reset to factory default
The reset button resets the switch and sets all switch properties to the factory default values.

Cheers!