Cisco не работает rommon

Восстановление Cisco ASA из режима ROMMON

Read the article CISCO ASA RECOVERY USING ROMMON MODE in English

К сожалению, иногда случается так, что оборудование выходит из строя. Конечно же, это происходит в самый неподходящий момент. В большинстве случаев, встречавшихся в моей практике, происходит следующее: по какой-либо причине (работы с электрооборудованием, гроза, плановое или аварийное отключение электричества) Cisco ASA выключается или перезагружается, а при запуске каналы связи, VPN и другие сервисы не восстанавливаются. Вариант, когда перестают моргать даже лампочки индикаторов на корпусе, я не рассматриваю –почти точно устройство направляется в утиль или на замену по гарантии. Рассмотрю вариант, когда Cisco ASA все еще работает, но не загружается до конца, а именно: не может загрузить образ операционной системы Cisco IOS. Есть шанс реанимировать устройство, как минимум на время, до замены на полностью исправное.

Первым делом подключаемся к межсетевому экрану с помощью консольного кабеля . Если устройство не отзывается ни на какие действия, то дело плохо – поблагодарите его за долгий и плодотворный труд и положите в шкаф на полку. Если же увидите некую активность, то попытайтесь понять, что происходит. Межсетевой экран может сразу находиться в технологическом режиме ROMMON (в обычных условиях режим вызывается нажатием клавиши ESC во время загрузки) с ограниченным функционалом или же в процессе загрузки образа системы постоянно перезагружаться.

Выглядит этот режим примерно так:
Use ? for help.
ROMMON #0>
Попав в ROMMON, стоит попробовать запустить процесс загрузки системы командой boot.
ROMMON #0> boot
Cisco ASA попытается загрузить тот образ своей операционной системы, который находится во встроенной Flash памяти. Сразу скажу, что за несколько лет практики был только один раз, когда мне повезло и устройство загрузилось. В большинстве же своем попытки оказывались неудачными.

В этом случае стоит вспомнить принцип работы устройств Cisco:
Операционная система находится на неком носителе и загружается с него в оперативную память единожды при включении устройства. После этого система работает до следующей перезагрузки. В качестве носителя почти всегда используется внутренняя Flash память (Вероятнее всего вы читаете эту статью как раз потому, что этот модуль и вышел из строя), однако также возможно указать в качестве источника внешний ресурс, например — TFTP сервер.
Задача по восстановлению межсетевого экрана сводится к:

  • установке TFTP сервера на какой-либо рабочей станции. Подойдет обычный ноутбук.
  • размещения на нем образа операционной системы Cisco IOS
  • подключения этой рабочей станции с TFTP сервером напрямую в один из интерфейсов Cisco ASA
  • указания этого хоста в качестве источника образа на самом межсетевом экране и загрузка образа

Для установки TFTP сервера достаточно скачать дистрибутив, запустить программу и выложить образ операционной системы в папку, указанную в окне приложения. Посоветую простой и бесплатный TFTPD. Скачать можно здесь.
Интерфейс программы прост и понятен и не должен вызвать какие-либо дополнительные трудности.

В папку C:\Program Files\Tftpd64, указанную в поле Current Directory, выкладываем образ IOS для межсетевого экрана. Советую при восстановлении использовать тот же, что был на момент выхода устройства из строя. Устанавливать более новую версию стоит не раньше, чем будет уверенность в надежной работе межсетевого экрана.

Важно!
Обратите внимание на интерфейс сервера. Если ip адрес сетевой карты ноутбука будет изменен, то в поле Server interfaces останутся старые настройки. Проверьте корректность этого поля и, если там указан старый адрес, перезагрузите TFTP сервер. Для примера будем использовать 192.168.1.2
Далее нужно соединить прямым патч кордом интерфейс ноутбука с TFTP сервером и интерфейс Ethernet 0/0 межсетевого экрана.
В консоли устройства (в режиме ROMMON) задается ip адрес (ADDRESS), порт (PORT), TFTP сервер (SERVER) с файлом образа (IMAGE).

Важно!
При вводе команд придется печатать их полностью — будьте аккуратны и внимательны.
rommon #1> ADDRESS= 192.168.1.1
rommon #2> PORT= Ethernet0/0
rommon #3> SERVER= 192.168.1.2
rommon #4> IMAGE= asa803-k8.bin

Важно!
В примере Cisco ASA и TFTP сервер с образом IOS подключены напрямую друг к другу и шлюз по умолчанию не требуется. Однако, если доступна внутренняя корпоративная сеть, то TFTP сервер можно поднять на любой доступной рабочей станции сети. В этом случае на Cisco ASA дополнительно потребуется указать шлюз по умолчанию(GATEWAY) и/или номер Vlan (VLAN).
rommon #5> GATEWAY= Х.Х.Х.Х
rommon #6> VLAN= Y
Вместо Х.Х.Х.Х введите значения ip адреса шлюза для сети, в которой находится межсетевой экран. Вместо Y – номер Vlan этой сети.
Проверить введенные данные можно проверить командой set
rommon #6> set
Доступность TFTP сервера проверяется командой ping server
rommon #7> ping server
Убедившись, что рабочая станция и Cisco ASA подключены и настроены корректно, введите команду tftp для загрузки IOS.
rommon #8> tftp

Важно!
При удачной загрузке советую тут же озаботиться заменой проблемного оборудования, так как его надежность остается под вопросом.
Напомню еще раз, что рассматривается случай аварийного восстановления Cisco ASA, успешность которого зависит от конкретного случая и степени повреждения компонентов устройства. Все вышеописанное будет работать в 100% случаев, если аппаратная часть исправна.

Источник

Восстановление ROMmon для Cisco 2600 Series Router и для VG200

Параметры загрузки

Содержание

Введение

На этой странице объясняется, как восстановить маршрутизатор Cisco серии 2600 и VG200, не способного выйти из режима ROMmon (командная строка rommon# >).

Перед началом работы

Условные обозначения

Дополнительные сведения об условных обозначениях см. в документе Cisco Technical Tips Conventions.

Предварительные условия

Для данного документа отсутствуют предварительные условия.

Используемые компоненты

Настоящий документ не имеет жесткой привязки к каким-либо конкретным версиям программного обеспечения и оборудования.

Сведения, представленные в этом документе, получены для устройств в специфической лабораторной среде. Все устройства, описываемые в этом документе, запускались с чистой конфигурацией (конфигурацией по умолчанию). При работе с реально функционирующей сетью необходимо полностью осознавать возможные результаты использования всех команд.

Проверка параметров реестра конфигурации

Если маршрутизатор не может выйти из режима ROMmon, первым делом следует проверить значение реестра конфигурации.

Первые четыре бита конфигурационного реестра образуют поле начальной загрузки. Значение в поле загрузки определяет образ ПО Cisco IOS® по умолчанию, который будет использован для запуска маршрутизатора. Если значение этого поля равно 0 (значение реестра конфигурации XXX0), при загрузке система переходит в режим монитора ROM (rommon>), ожидая пользовательской команды для загрузки системы вручную. Дополнительные сведения о значениях битов реестра конфигурации см. в документе Настройка реестра конфигурации ПО.

Если маршрутизатор продолжает переходить в режим ROMmon каждый раз при перезапуске системы, возможной причиной может быть параметр реестра конфигурации. Чтобы убедиться в настроенном значении реестра конфигурации, воспользуйтесь командой confreg, как показано ниже:

Как показано в приведенных выше выходных данных команды confreg, реестр конфигурации имеет значение, которое заставляет маршрутизатор переходить в режим ROMmon каждый раз при перезагрузке или включении устройства. Чтобы задать автоматическую загрузку маршрутизатора с использованием стандартного образа ПО Cisco IOS, измените значение реестра конфигурации, как показано ниже:

Читайте также:  Сколько можно не работать чтобы пересчитать пенсию

Таким образом для реестра конфигурации было установлено значение, которое заставит устройство искать допустимый образ ПО Cisco IOS во время запуска и загрузиться с этого образа. Теперь следует перезагрузить маршрутизатор.

Маршрутизатор теперь должен перезагрузиться с допустимым образом программного обеспечения Cisco IOS.

Поиск допустимого образа во флэш-памяти

Если значение реестра конфигурации задано для загрузки системы автоматически с использованием образа ПО Cisco IOS по умолчанию и если во время запуска не была дана команда прерывания, маршрутизатор выполнит загрузку. Однако если маршрутизатор все также переходит в режим ROMmon, вполне возможно, что он не может найти допустимый образ ПО Cisco IOS.

Первым делом нужно найти допустимый образ ПО Cisco IOS. Для этого выполните команду dir устройство > для каждого доступного устройства и подыщите допустимый образ программного обеспечения Cisco IOS. Например, чтобы найти образ IOS во флэш-памяти, выполните приведенную ниже команду.

Обратите внимание, что если маршрутизатор возвращает сообщение «bad device name», скорее всего, указанного устройства не существует. Приведенные выше выходные данные указывают, что допустимый образ расположен во флэш-памяти. Попробуйте выполнить загрузку с использованием данного образа с помощью команды boot.

Маршрутизатор должен загрузиться с использованием образа ПО Cisco IOS, указанного в команде boot. Однако иногда допустимый образ не существует на каком-либо устройстве или образ во флэш-памяти может быть поврежден. В этих случаях допустимый образ должен быть загружен с использованием TFTP-сервера или процедуры Xmodem. Обе процедуры можно выполнить в режиме ROMmon.

Примечание. В некоторых случаях может возникнуть системная ошибка «Device does not contain a valid magic number». В этом случае помимо загрузки допустимого образа ПО Cisco IOS может понадобиться проверить крепление флэш-памяти или даже заменить ее, если она повреждена.

Загрузка с TFTP-сервера в режиме ROMmon

Это самый быстрый способ переустановки нового образа ПО Cisco IOS на маршутизаторе. См. документ Использование команды tftpdnld.

Загрузка с помощью Xmodem в режиме ROMmon

Можно загрузить новую версию ПО Cisco IOS через порт консоли с помощью модема Xmodem. См. документ Процедура загрузки через порт консоли с помощью Xmodem в режиме ROMmon.

Источник

Troubleshoot Cisco 4000 Series ISR Stuck in ROMMON

Available Languages

Download Options

Contents

Introduction

This document describe step-by-step process on how to troubleshoot and recover Cisco 4000 series ISR (Integrated Services Router) from ROMMON or infinite boot loop if configured with IOS-XE release of incorrect platform. At times Cisco 4000 series ISR may stuck in ROMMON or continuous boot loop.

Problem

Cisco 4400 and Cisco 4300 series routers have IOS-XE images looks very similar hence in case you configured Cisco 4400 with IOS-XE release for Cisco 4300 or vice-versa, router will not bootup completely, instead will get stuck in ROMMON.

Here you have Cisco 4400 configured with an IOS-XE release of Cisco 4300 —

Cisco ISR4431/K9 (1RU) processor with 1665895K/6147K bytes of memory.
Processor board ID XXXXXXXXXX
4 Gigabit Ethernet interfaces
32768K bytes of non-volatile configuration memory.
4194304K bytes of physical memory.
7057407K bytes of flash memory at bootflash:.
4013055K bytes of USB flash at usb1

If you reload this router, router will get stuck in ROMMON mode with this message on boot-up —

These methods to bring router up using correct IOS-XE image will not work.

1. Try to bring router up using USB Flash —

Please reset before booting

2. Try to ignore startup-config and bring router up without startup configuration

You must reset or power cycle for new config to take effect

Please reset before booting

3. Try to bring router up from traditional bootflash file system —

Please reset before continuing

4. In some cases, internal bootflash file system will not recognized by router.

Please reset before continuing

Solution

The correct process to recover this infinite boot loop issue is

1. Break router into ROMMON mode using break sequence during boot-up —

2. Change the config-register vlaue to 0x0 to ignore the boot variable configured in startup config —

You must reset or power cycle for new config to take effect

3. This will bring router into ROMMON mode once again. Now change the config-register value to 0x2102

4. Now we need to configure correct boot variable from ROMMON —

Once router is up and running, you can delete the incorrect boot variable and confgure the correct IOS-XE release —

5. Save the changes

Password Recovery guide for the Cisco 4000 Series Integrated Services Router —

Источник

Recover a Cisco IOS Catalyst 4500/4000 Series Switch from a Corrupt or Missing Image or in Rommon Mode

Available Languages

Download Options

Contents

Introduction

This document explains how to recover a Catalyst 4500/4000 Series Supervisor II-Plus (WS-X4013+), Supervisor III (WS-X4014), Supervisor IV (WS-X4515), or Supervisor V (WS-X4516) from a missing or corrupted system image, or an incorrect boot variable. The Supervisor II-Plus, III, IV or V module image can sometimes be corrupted during a Trivial File Transfer Protocol (TFTP) download, or when manually deleted by the user. The switch provides a number of ways to recover should any of these events occur on these Supervisor Engines.

The Catalyst 4500/4000 Series Supervisor II-Plus, III, IV and V runs Cisco IOS® software only, and does not run Catalyst OS software. If you wish to try to recover a Catalyst 4500/4000 Series Supervisor (I and II) that runs Catalyst OS, refer to this document:

When the Supervisor II-Plus, III, IV or V-equipped switch boots up or resets, there are these two possibilities:

The switch starts up normally and displays the Hostname> prompt or the default Switch> prompt.

The switch cannot find the image, the image is corrupt, no image is present in the bootflash device, or the boot variable is set incorrectly and therefore winds up in ROM monitor (ROMmon) mode. It displays the rommon> prompt. In ROMmon mode, the switch must be able to locate a valid system image from either the bootflash device or the slot0 Compact Flash card. These Supervisor Engines also provide an Ethernet Management port (10/100 Base T), which is available only from ROMmon mode and can be configured to download a new valid image through TFTP from a TFTP process. There is no option for Xmodem or Ymodem which allows you to copy an image through the console port.

In addition to the 64 MB internal Flash Single In-Line Memory Module (SIMM), these Supervisor Engines have one Type 1 Compact Flash card slot which has a capacity of up to 128 MB. If the system or the boot image should fail, theses devices provide a backup. These mentioned Flash devices are recognized in ROMmon, and the images stored there can be used to recover. The Flash device is optional, which can be obtained from Cisco or a third-party supplier. Refer to this document for more information related to using Compact Flash with Supervisor II-Plus, III, IV or V:

Читайте также:  После замены дисплея не работает динамик айфон 7 плюс

Prerequisites

Requirements

There are no specific prerequisites for this document.

Components Used

. The information in this document is applicable only for Catalyst 4500/4000 Series switches using Supervisor Engine II-Plus, III, IV or V.

The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared (default) configuration. If your network is live, make sure that you understand the potential impact of any command.

Conventions

Refer to Cisco Technical Tips Conventions for more information on document conventions.

Normal Operation

When the switch operates normally, it is at the hostname> prompt or the default Switch> prompt. You can issue the dir bootflash: or dir slot0: commands to view the contents of the Supervisor Flash devices, as this example shows. Issue the verify command to determine if the image has a valid checksum, as this example shows:

Since the switch recognizes all Flash devices in ROMmon mode, you can issue the dir device-name > commands to show the Flash contents, as is demonstrated in the remaining sections of this document.

Notice in the previous example, there is only a single boot image in bootflash. You can have as many system images as you can fit in either the bootflash: or slot0:. Bootflash size is fixed at 64 MB, whereas slot0: Compact Flash is available in 64 MB or 128 MB options. How to manage the bootflash and Flash cards is up to you, but consider distributing the images between these devices for more redundancy in case of a failure.

Recover from ROMmon Mode

The switch could wind up in ROMmon mode due to these reasons:

A switch reload or crash after the image was corrupted or deleted. See the Recover from a Corrupt or Missing Image section of this document for more information.

The Compact Flash which holds the system image has been removed. See the Recover from a Continuous Reboot section of this document to determine if a valid system image is present in the bootflash:. If there is no file present, see the Recover from a Corrupt or Missing Image section of this document

The configuration register has been changed incorrectly. The configuration register value of 0x0 always brings the switch to ROMmon mode. The typical configuration register is 0x2102, with the boot system flash command pointing to the system image to load. Refer to this document for more information about the configuration register:

The boot variable is incorrect, but a valid image is still present. See the Recover from a Continuous Reboot section of this document for more information.

These primary symptoms occur in your network if the switch is in ROMmon mode:

Routing failures occur because ROMmon mode cannot route between VLAN interfaces, and is only designed to recover the switch.

If you try to Telnet to any of the interfaces it fails, and if you are connected to the console port of the Supervisor, you see this prompt:

Recover from a Continuous Reboot

The switch might end up in a continuous reboot sequence if the boot variable is not set to the correct system image file and proper destination device. For example, the configuration register value of 0x2102 requires that a boot variable is specified by issuing the boot system flash configuration command.

This output is an example of a situation in which an incorrect boot image is specified when setting up the boot variable, which prevents the booting of the system image. This output is only seen on the console of the switch, as the switch is not yet functional.

This reboot is continuous.

Step-by-Step Instructions

These steps show how you can recover the switch.

You should already have a console connection to the Supervisor to see the previous output and perform the recovery. On a standard Windows operating system platform, configure a HyperTerminal connection directly to COM1 with these settings:

Eight data bits

Flow control = none

Use a rolled male RJ-45 cable to connect from COM1 on the PC to the console port on the Supervisor module. Use a DB-9 connector on the PC.

The reboot continues until autoboot is prevented when you press Control-C and go into ROMmon mode.

This is shown in this example:

Issue the dir bootflash: command to list the files present in the bootflash, or issue the dir slot0: command to list the files present in the Compact Flash device.

In the example, the files are in the bootflash: device:

Note: The reason the switch reboots continuously is because the system image file name specified does not exist, but there is a valid file in the bootflash and slot0:. Also, the system image file name specified is case sensitive. If it is not specified correctly, it causes a continuous reboot.

Since you have the required system image file present in the bootflash:, you can issue the boot bootflash: filename > command to boot the switch. Issue the boot slot0: filename > command if you want to load the system from the file present in slot0:. The system is booted with that specified image. If the switch fails to load due to the specified system image being corrupt, or the valid system file is not present, see the Recover from a Corrupt or Missing Image section of this document.

This is shown in this example:

Issue the enable command to enter into EXEC mode, as this example shows:

The system is back up. Issue the dir bootflash: command to note the file in the bootflash:. Issue the dir slot0: command if you loaded the system file present in the slot0:.

Issue the show bootvar command to check the current boot variable.

Remove the existing incorrect boot variable and add the correct one. Issue the configure terminal command in order to do this.

Save the configuration from running to startup, by issuing the write memory command.

Check the boot variable again to make sure it is set properly so that the switch boots up the correct system file on the next reboot. Issue the show bootvar command in order to do this.

Recover from a Corrupt or Missing Image

The Supervisor boots into ROMmon mode if the image specified is corrupt or no image file exists. Typically, you should have more than one image in the bootflash: or slot0: devices so that the switch can be recovered.

Step-by-Step Instructions

Complete these steps, in the order given, to facilitate a successful image recovery from ROMmon mode without any valid image.

Make a console connection to the Supervisor. Typically on a standard Windows operating system platform, configure a HyperTerminal connection directly to COM1 with these settings:

Eight data bits

Use a rolled male RJ-45 cable to connect from COM1 on the PC to the console port on the Supervisor module. Use a DB-9 connector on the PC, and a HyperTerminal connect window to connect to the Supervisor.

Читайте также:  Может ли сломаться телевизор от микроволновки

Press Enter. If you get the rommon > prompt, skip to Step 3. If the switch continuously reboots, press Control-C to prevent autoboot and to get into ROMmon mode.

Verify that there is a valid file present in the bootflash: by issuing the dir bootflash: command, and the dir slot0: command to check the slot0:, as this example shows. If you do have any valid file, see the Recovering from a Continuous Reboot section of this document for the recovery. Otherwise, continue to the next step.

Issue the set command to display the current environmental variables.

Issue the unset boot command to clear the current invalid boot variable, which defines the file to load.

Connect the management port on the Supervisor to the network to access a TFTP server. The Fast Ethernet port (10/100 MGT) on the Supervisor Engine is inoperative in normal operation in current software releases. An Ethernet cable plugged into the 10/100 MGT is active only in ROMmon mode. Refer to this example of a Catalyst 4500/4000 Series Supervisor Engine II-Plus, III, IV or V for the location of the MGT port:

As this example shows, if you plan to connect the 10/100 MGT port to the PC/Router directly, use a straight cable. If you connect to another switch, use a crossover cable.

The MGT port auto-negotiates speed and duplex with the connected device. Currently, you can not hardcode speed and duplex settings. Since this port is available only in ROMmon mode and for TFTP only, it is not a major concern if the speed and duplex are mismatched due to any potential auto-negotiating problem. The TFTP application has an internal packet loss mechanism to prevent any corruption of the system image being downloaded.

Issue the set interface fa1 command to configure an IP address for the 10/100 MGT port, as this example shows. If the subnet mask is not specified, the IP address would take the default classful mask.

Issue the set ip route default command to configure the default gateway for the switch to use to get to the TFTP server, as this example shows. The default gateway should be a routing device in the same subnet as the IP address configured in Step 7.

In ROMmon versions earlier than 12.1(12r)EW, even if the TFTP server is in the same subnet as the 10/100 MGT port, you still need to configure the default gateway by issuing the set ip route default command. If you are directly connecting your PC, which has the TFTP server application installed, use the IP address of the PC for the default gateway IP address. If the default gateway is not configured, the TFTP can not be performed. This restriction is resolved starting in ROMmon version 12.1(12r)EW or later. You do not need to specify the default gateway IP address if the TFTP server is in the same subnet as the management IP address.

Issue the set command to verify the configurations which have been made.

Ping the TFTP server to ensure that there is connectivity to the server from the MGT port on the Supervisor Engine. Enter the ping command, as this example shows:

If the ping is not successful, troubleshoot the IP connectivity issue from the default gateway to the TFTP server. If the TFTP server is the same subnet, make sure it is configured with the IP address you are pinging.

Once the ping to the TFTP server is successful, you can issue the boot tftp :// / command to specify the system image which is available in the TFTP server to boot the Supervisor III.

The switch has booted with the image it got from the TFTP server by copying it to the DRAM. The image is not yet copied onto the bootflash:, and therefore it has to be copied again into the bootflash: or slot0:. Issue the enable command, and provide the password if one is needed to enter into EXEC mode, as this example shows:

Note: If you have accidentally deleted the system image, you can issue the dir /all command to check the deleted file, and issue the undelete command to undelete the file. This prevents you from having to TFTP the new file. If this is the case, skip to Step 17.

Ping the TFTP server by issuing the ping command to make sure the TFTP server is reachable, as this example shows:

If the ping is successful, skip to Step 15. If not, make sure you have a connection to the TFTP server from the switch. Typically you have to connect one of the regular 10/100 ports or Gigabit ports to another switch, or connect the TFTP server installed PC directly to one of the switch interfaces.

Refer to the Software Configuration Guide for more information.

Copy the file in the TFTP server onto the bootflash: file system. You can also save the file to the slot0: Compact Flash device. Issue the copy tftp flash command and follow the prompt.

If you want to copy the system image to slot0:, issue the copy tftp slot0: command, as this example shows. Otherwise, skip this step.

Note: The IP address of the TFTP server and the file has already been preselected since you used the information for the transfer of the image to the bootflash:. If you would like to change it, type the new IP address or image name. Otherwise, press Enter and the preselected information is used.

The system image has been copied. Issue the dir bootflash: command to note the file in the bootflash:. Issue the dir slot0: command if you loaded the system file into the slot0.

Issue the verify command to verify the integrity of the downloaded file. If the verification fails, you have to download the file again.

Issue the show bootvar command to check the current boot variable and the configuration register variable.

You might have to remove any existing incorrect boot variables and add the correct one, as this example shows. In this example, the configuration register is already at the desired 0x2102 value. If this is not the case, issue the global config-register 0x2102 command.

Note: If you have no boot variable, directly issue the boot system flash bootflash: command. Or if you are booting from slot0:, issue the boot system flash slot0: command.

Issue the write memory command to save the configuration from running to startup.

Check the boot variable again to make sure it is set correctly, so that the switch boots up the correct system file on the next reboot. Issue the show bootvar command in order to do this.

Verify

There is currently no verification procedure available for this configuration.

Troubleshoot

There is currently no specific troubleshooting information available for this configuration.

Источник

Оцените статью