brocade mlx-8 enable password - 夜莺博客

brocade mlx-8 enable password

The default password for the enable (privileged EXEC) mode on a Brocade MLX-8 is password, while the default username/password for initial login is admin / password. [1, 2, 3]

If those credentials do not work, the password has been customized and must be recovered via the serial console.

How to Bypass/Recover the Enable Password

To reset the password, you need physical access to the device and a serial console cable.

  1. Connect and Reboot: Attach a console cable to the switch, open your terminal emulator, and reboot the router.
  2. Access Boot Monitor: During the initial boot sequence, press b to enter the Boot Monitor mode (sometimes called the Monitor or U-Boot prompt).
  3. Bypass Password Check: At the boot prompt, type:
    no password
  4. Boot the System: After receiving confirmation, type:
    boot system flash primary
  5. Set a New Password: Once the switch boots into the OS, press Return, enter Privileged EXEC mode (using the command enable), and access the configuration mode to set a new password:
Brocade> enable
Brocade# configure terminal
Brocade(config)# enable password [your_new_password]
Brocade(config)# write memory

What the MLX-8 actually runs

The MLX-8 is a chassis switch from the Brocade MLX series (the same family as the MLX-4, MLX-16 and MLXe) running Multi-Service IronWare, which Brocade later shipped under the NetIron name. That matters for password recovery, because the CLI, the boot monitor and the recovery procedure are completely different from Brocade’s Fibre Channel switches, which run Fabric OS (FOS). Instructions for a Brocade SAN switch will not work here, and vice versa.

Two prompts matter in day-to-day use:

  • Brocade> — user EXEC. You can look at a limited set of things and nothing else.
  • Brocade# — privileged EXEC, reached with the enable command and the enable password. This is where show running-config, write memory and reload live.

Configuration commands are executed from Brocade(config)#, which you enter with configure terminal.

Console and first login

The MLX management module has an RJ-45 console port (a DB-9 adapter is usually in the accessory kit). Terminal settings are the standard IronWare ones:

  • 9600 baud, 8 data bits, no parity, 1 stop bit
  • No flow control, no hardware handshaking
  • A null-modem style connection — if your adapter is a straight-through cable, you will see nothing at all

Once the chassis finishes booting (give it several minutes — a full MLX boot including line cards is not fast), press Return and you should be presented with the login prompt. Log in as admin with the password password, then type enable and supply the enable password, which on a factory-fresh unit is password as well.

A nuance worth knowing before you conclude the device has been customized: on some factory builds and after certain firmware loads, the enable password is left unset, in which case enable simply promotes you to privileged EXEC when you press Return at the password prompt. So if password is rejected, try an empty password once before you reach for a console cable and a maintenance window.

Confirming the password has been changed

If you have any level of access — including read-only — you can see how the passwords are stored without knowing them:

show running-config | include enable
show running-config | include username

IronWare prints password lines in encrypted form, for example enable password 8 $1$.... Seeing an encrypted string where you expected nothing means someone set a password and did not leave a record of it. Seeing nothing at all means the login is using the defaults or an AAA server. Neither tells you the plaintext, which is the whole point of the recovery procedure.

Other useful sanity checks once you are in privileged mode:

show version
show running-config
show users
show redundancy

show redundancy is meaningful on chassis with two management modules — both share the same running configuration, so clearing the password on the active module is enough; the standby picks it up when it synchronises.

Recovery walkthrough, with the failure modes

Reboot the chassis with reload (or the power switch if you must), and watch the console. IronWare prints a countdown during which it accepts a keystroke to interrupt the boot; press b during that window. You should land at the boot monitor prompt.

At that prompt:

no password
boot system flash primary
  • If no password is not accepted, your IronWare version does not expose that command in the boot monitor. Use the secondary image instead — boot system flash secondary — which is often on an older firmware release with a known, or empty, password. Several recovery guides use exactly that trick on MLX and MLXe hardware.
  • If the device boots straight through without giving you the interrupt window, your terminal is too slow to react or the window is genuinely short. Start the terminal emulator before powering the chassis on, and use a wired serial connection rather than a USB-to-serial adapter of unknown quality.
  • If the console shows garbage, you are on the wrong baud rate or the wrong cable. Both are extremely common. 9600 8N1 with no flow control is the starting point.

After the chassis finishes booting, press Return, then run the sequence from the original post to set a password you actually know:

Brocade> enable
Brocade# configure terminal
Brocade(config)# enable password Str0ng-Enable-Pw
Brocade(config)# write memory

write memory is the important line. Without it the new password lives only in the running configuration and disappears at the next reload — which means you get to do the whole recovery again.

Locking it down afterwards

Recovering access is only half the job. A chassis that has been running with default passwords for years usually needs the rest of the management plane fixed at the same time:

Brocade(config)# enable password Str0ng-Enable-Pw
Brocade(config)# enable super-user-password Str0ng-SuperPw
Brocade(config)# username netadmin password An0ther-Str0ng-Pw
Brocade(config)# aaa authentication login default local
Brocade(config)# write memory
  • enable password protects privileged EXEC. If several engineers share the unit, named accounts plus aaa authentication login default local are better than one shared enable password, because the logs then show who did what.
  • enable super-user-password is a second gate used by IronWare for a subset of privileged operations on builds that support it. Set it, and store it in your password manager — losing it is a console-trip offence.
  • Restrict the management interface with an ACL so only your jump hosts can reach SSH, Telnet and SNMP, and turn off any management protocol nobody uses. On the MLX the management port is addressed under interface management 1.
  • If the unit is Layer 3 for a campus or data centre, check that no temporary changes were left behind by whoever had access before you: look for open ACL entries, an unexpected ip route 0.0.0.0/0, or a password recovery path such as an unauthenticated console that nobody owns.

Boot monitor commands worth knowing

The MLX boot monitor is intentionally tiny. Depending on the IronWare release you will find some or all of the following; type ? or help at the Monitor> prompt to see what your build supports:

  • no password — suppresses the password check for the next boot. This is the command that makes the whole recovery possible.
  • boot system flash primary / boot system flash secondary — boots the image in that flash partition. Booting the secondary image is the fallback when the primary image is corrupt, and it is also the trick used when no password is unavailable on your firmware.
  • printenv — prints the boot environment variables, including the default boot source and any autoboot settings. Useful when the chassis keeps booting the wrong image.
  • reload — restarts the chassis from the boot monitor without entering the OS.

Nothing at this prompt requires credentials, which is precisely why the recovery works — and precisely why physical access to the console port is a security boundary you should treat as such. Anyone with a serial cable and five minutes of downtime owns the device.

What each command in the recovery sequence does

It helps to know which line does what, so you can adapt the procedure when a step behaves differently on your firmware:

  • no password at the boot monitor clears the enable-password check for the boot that is about to happen. It does not modify the startup configuration, and it does not persist.
  • boot system flash primary tells the chassis which image to load. If the unit has been upgraded and the primary image is newer than what you expected, booting secondary gives you the previous release.
  • enable puts you in privileged EXEC. With the check suppressed, you are promoted without being prompted.
  • configure terminal moves you into global configuration mode.
  • enable password <text> writes a new encrypted password hash into the running configuration; the old hash is overwritten and unrecoverable.
  • write memory copies the running configuration to startup configuration so the change survives a reload. Skip it and the whole exercise is lost on the next power cycle.

Frequently asked questions

Do the same credentials apply to every Brocade device? No. Ethernet MLX, MLXe, FastIron and ICX run IronWare/NetIron and share this CLI family. Brocade Fibre Channel switches run Fabric OS and have their own default accounts and their own password recovery path. If you are working on a SAN switch instead of a chassis router, start with the essential CLI reference linked below rather than with no password.

Can I recover the password without a reboot? No. If you cannot log in, the plaintext is not retrievable from the configuration — IronWare only stores an encrypted hash, and the boot-monitor bypass requires a restart. Plan the change window accordingly.

Will the config survive the recovery? Yes. no password at the boot monitor only suppresses the password check for that boot; the startup configuration and all interfaces come up exactly as before. The only thing you should be careful about is that you do set a new password before the next reload, otherwise the device comes back with the same problem.

What if the boot monitor route fails and nothing works? As a last resort you can erase the startup configuration at the boot monitor or from privileged EXEC with erase startup-config, then reload. That returns the unit to a factory-default configuration — which means every VLAN, route and ACL on the box is gone, so only do this if you have a current configuration backup or the device is genuinely bare.

Related reading

If you work with Brocade hardware regularly, Brocade SAN switch commands for storage admins covers the Fabric OS side of the house, and 戴尔博科交换机重要命令 collects the commands that come up most often on Brocade-based Dell switches. For the equivalent recovery exercise on another platform — and a useful comparison of how much easier it is to bypass a password check when the vendor gives you a boot flag — see Cisco IOS password recovery with config-register 0x2142.