This step-by-step guide explains how to recover a firewall device configuration when access to the device is no longer possible. The available recovery options depend on the specific device model and the firmware version installed. Below, we outline the different recovery methods you can use.
Note: Regardless of the method, you will require a console cable to connect to the device
Reset admin password - Firmware on 5.20 or newer
Starting from firmware version 5.20, it is possible to reset only the root admin password without resetting the entire device, unlike in firmware versions prior to 5.20 where a full device reset was required.
Note: A console cable is needed to proceed
1. Reboot the device
2. Enter debug mode and type
atkz –g This command resets the admin password.
3. Enter the next command to start the reset
atgoThis command quits the debug mode and reboots the device again.
4. After the device reboots, all your settings will remain, excluding the "admin" password, which will now be the default 1234.
The admin password can now be changed again to secure your device, without losing any other configuration in the recovery process.
1. Configuration file recovery - Firmware older than 5.20 or USG/Zywall series
1. Reboot the device
2. Enter debug mode and type
atkz –b3. Enter the next command to start the reset
atgo4. Now the device will start with the system-default configuration and back up the old startup-config.conf to startup-config-back.conf on the USG.
5. After the USG is accessible via its default credentials and IP, download the startup-config-back.conf to replace the admin password.
a.) Find the line beginning with “username admin encrypted-password” in the startup-config-back.conf. The line should look like this:
username admin encrypted-password $4$encryptedpasswordencryptedpassword$ user-type adminb.) Change the line to ("12345678" will be your new password) and delete "encrypted-"
username admin password 12345678 user-type adminOriginal line:
username admin encrypted-password $5$qfqk.z2q$r4R63fRn$SYGgbOziSvhxTSKphFuiHcGIGX5pn5r9V2xk/SP8Dsla86PngvJJq96Xy6ZXv6GFCuDBPofY9NyTxZUtnq
GT7FzyeFWkeCnmCgS7SH4WwYSN498C+6mDUgxeSHB2W6hlgSa/lErhYCrACjtOmkXXRn9cfqK8TVgNT3wQcFjBc6o1jyMs0AR+bDqJCicrj5dAtkEEsuAi7qnGCvDS0gC89aFt2RijLB4j0tH
z8YeVp0Us6PjSQrXmayBMEBcicOhCwJ19E6VUOTmLHIx87EGIq/TazBgHrT8KElFW+NqUzV9gG7XT0JUEbvGdj2/V9zQZ2+is2aF5tiZYvpKH2VbfJzIhmavq7Jn2WAoksVaYN9A$ user-type adminAfter the changes:
username admin password 12345678 user-type admin6. Save and rename the startup-config-back.conf, upload it back to the USG, and apply it.
Now you can log in with the new password you set in step 5.
With this, access to your firewall was restored.

Comments
2 commentsPlease sign in to leave a comment.
Common guys, who uses RS232 these days. There are no PC with this interface anymore.
Get real and provide an up-to-date interface or do you sitill dwell in in the 70is?
HI Technik!
RS232 is on USG Site so you can use USB to your PC. There are enough RS232 to USB Converter on the market to work for this scenario.
Regards,
Tobias