How to Recover the Root Password for Junos OS
If you forget the root password for the router, you can use the password recovery procedure to reset the root password.
Before you begin, note the following:
-
You need console access to recover the root password.
To recover the root password:
- Power off the router by pressing the power button on the front panel.
- Turn off the power to the management device (usually a computer) that you use to access the CLI.
- Plug one end of the Ethernet rollover cable (supplied with the router) into the RJ-45 to DB-9 serial port adapter supplied with the router.
- Plug the RJ-45 to DB-9 serial port adapter into the serial port on the management device.
- Connect the other end of the Ethernet rollover cable to the console port on the router.
- Turn on the power to the management device.
- From the management device, start your asynchronous terminal emulation application (such as Microsoft Windows Hyperterminal), and select the appropriate COM port to use (for example, COM1).
- Configure the port settings as follows:
-
Bits per second: 9600
-
Data bits: 8
-
Parity: None
-
Stop bits: 1
-
Flow control: None
-
- Power on the router by pressing the power button on the front panel.
Verify that the POWER LED on the front panel turns green.
The terminal emulation screen on your management device displays the router’s boot sequence.
-
When the following prompt appears, press the Spacebar to access the router’s
bootstrap loader command prompt.
Hit [Enter] to boot immediately, or space bar for command prompt. Booting [kernel] in 9 seconds...
Note:Depending on your device hardware, the bootstrap loader might proceed quickly at this step without pausing for input. Pay close attention to the prompts that appear and press the Spacebar immediately after seeing the above prompt flash on the screen.
- At the following prompt, type
boot -sto start the system in single-user mode.boot -s
- At the following prompt, type
recoveryto start the root password recovery procedure.Enter full pathname of shell or 'recovery' for root password recovery or RETURN for /bin/sh: recovery
- Enter configuration mode in the CLI.
- Set the root password.
[edit] user@host# set system root-authentication plain-text-password
When you configure a plain-text password, the system encrypts the password for you.
CAUTION:Avoid using the
encrypted-passwordoption unless the password is already encrypted and you are entering the encrypted version of the password. If you commit theencrypted-passwordoption with a plain-text password or with blank quotation marks (" "), you will not be able to log in to the device as root, and you will need to repeat this password recovery process. - At the following prompt, enter the new root password. For example:
New password: password
- At the second prompt, reenter the new root password.
Retype new password:
- After you have finished configuring the password, commit the
configuration.
root@host# commit commit complete
- Exit configuration mode in the CLI.
- Exit operational mode in the CLI.
- At the prompt, type
yto reboot the router.Reboot the system? [y/n] y