How to deal with console login password loss and user privilege level password loss
depends on the state of password recovery capability (see Figure 9 ). Password recovery
capability controls console user access to the device configuration and NVRAM from
BootWare menus.
If password recovery capability is enabled, a console user can access the device
configuration without authentication and configure new passwords.
If password recovery capability is disabled, a console user must restore the
factory-default configuration before configuring new passwords. Restoring the
factory-default configuration deletes the main and backup next-startup configuration
files.
To enhance system security, disable password recovery capability.