I have been doing more and more with Cisco ISE and it warranted a 2 node cluster at home. Everything was working great until the password on my local admin expired. To make matters worse, I forgot the CLI admin password… Thankfully there is a way to reset both!
To start, you will need to download or grab the ISO Installer for your version of Cisco ISE and upload it to your Datastore and mount it in the CD/DVD drive of your VM. Check designer download free.
Once the ISO is mounted, you can boot to the ISO. You will be presented with four options, 2 for Installing ISE and 2 for System Utilities. Select Option 3.
Cisco ise cli restart services. Cisco ise cli restart services. How to Reset ISE GUI Password from CLI July 18, 2017 Sean 0 Command: ISE-Server# application reset-passwd ise admin Notes: The ISE GUI admin password expires after 45 days by default. Application reset-passwd ise In my case, the username equals admin. In addition, the password for ISE GUI admin expires in 45 days by default. For lab environments, this becomes a pain in the neck. Go to Administration System Admin Access Password Policy to change the default password expiration configuration. I have disabled. To change the GUI Admin password, the command is 'application reset-passwd ise admin newpassword' Posted by srikanth at 9:17 PM. Email This BlogThis!
Select Option 1 at the next prompt to Recover Administrator Password.
Once you have selected the name of your local administrator account, you will be prompted to enter a new password for the account.
Enter your new password and select Y to save your changes and exit. From there you can Quit and Reload by using Q.
After ISE has restarted, you should be able to log into the console or SSH (if enabled). If you also need to change the application user password you can use the following command:
If you’re familiar with Cisco ISE deployments, then no doubt you’ve encountered a time where an Administrator password has expired and needs to be reset. This can happen for a number of reasons however the most common would be because of the admin password expiry setting that hasn’t been disabled in ISE.
When setting up a new Cisco ISE deployment, you will set the admin password. It is important to note that the CLI and GUI admin password can be different.
Although you can reset the admin GUI password via the CLI when it has expired, if the CLI password expires or you forget it, you will be required to boot from the .ISO in order to reset the password.
Booting from the .ISO can be a pain if ISE nodes are in a production environment and you may find that you need a change window to do this. Whatever the case may be, this article focuses on how to reset the admin passwords while ISE is in production.
These steps were taken when I encountered a similar issue with a distributed ISE deployment. If you’ve encountered similar or done a password reset a similar way, share your experience below.
Steps Summary
Request a change window (Optional)
Acquire the relevant .ISO file
Decide on the order of relevance for nodes in the deployment
Reset the Admin CLI password node by node
Unmount .ISO file
Verify successful password change
Change the GUI admin password (Optional)
Disable Admin password expiry (Optional)
Request a change window if required
As your ISE nodes may be in a production environment, it might not be as simple as taking ISE nodes offline while resetting the Admin password. Distributed deployment a slightly easier because you’d normally have secondary/multiple nodes to manage tasks while others are offline. On the other hand, if your deployment is a standalone deployment, more planning may be needed before taking the node offline.
Whatever the case may be, it’s best to check whether a change window is required before proceeding with the change.
Application Reset Passwd Ise Administrator
Acquire the relevant .ISO file
Navigate to software.cisco.com and download the relevant .ISO. The .ISO needs to match the same version software of your current deployment.
Decide which nodes will be shutdown first & reset passwords one by one on each node
This is a rather important step within a live environment because each ISE node will be taken offline while the .ISO is mounted and the passwords are changed.
Each deployment will differ so this article won’t mandate which of your nodes should be shutdown first however, when I’ve performed this task in the past, I would normally start with shutting down PSN nodes. So here is what I would do with a typical distributed deployment:
Shut one node down at a time
Start with a PSN, ensuring NAD’s will use another PSN in the event that one of the configure PSN’s is not available. If load balancing is used then this should be taken care of
Shutdown the first node and mount the .ISO as per Cisco documentation and dependant on whether it is a physical or virtual deployment.
Power on the node, ensuring it will boot into the .ISO
Reset the password for the necessary admin accounts as per Cisco documentation:
Application Reset Passwd Ise Admin Reset
Unmount the the .ISO
Reboot the node
Verify access to the device now using the CLI now that the password has been changed
Verify all services are online before following the same steps again on other nodes
Change the GUI password (Optional)
The admin CLI and GUI password can be different. Some administrators are not aware of this and when one password is changed, they often think it will change for the other too but that is not the case. I think the assumption that this is the case stems from the initial install of ISE because you only configure the admin password once for the CLI and that is also used for the GUI. T3r elemento underground zip code.
If you would like to change the GUI password then either log into the ISE GUI and change the ISE password or if that password also needs resetting then access the CLI and enter the following command below or watch the video demonstration:
Disable admin password expiry (Optional)
By default, ISE admin accounts will expire after a specific period (45 days by default). The following screenshot shows you how to disable admin password expiry.
In the ISE GUI navigate to Administration > System > Admin Access > Authentication > Password Policy and uncheck ‘Administrator passwords expire # days after creation or last change’.
Cisco Ise Application Reset-passwd Ise Admin
I hope this post has been useful in helping you plan a password reset within your ISE deployment.