What can I do, if I forgot my USG FLEX/ATP/VPN password or cannot access it anymore?

This step-by-step guide explains how to recover a firewall device configuration when access to the device is no longer possible. The available recovery options depend on the specific device model and the firmware version installed. Below, we outline the different recovery methods you can use.

Note: Regardless of the method, you will require a console cable to connect to the device

Reset admin password - Firmware on 5.20 or newer

Starting from firmware version 5.20, it is possible to reset only the root admin password without resetting the entire device, unlike in firmware versions prior to 5.20 where a full device reset was required.

Note: A  console cable  is needed to proceed

1. Reboot the device

2. Enter debug mode and type 

atkz –g  

This command resets the admin password.

3. Enter the next command to start the reset

atgo

This command quits the debug mode and reboots the device again.

mceclip0.png

4. After the device reboots, all your settings will remain, excluding the "admin" password, which will now be the default 1234.

The admin password can now be changed again to secure your device, without losing any other configuration in the recovery process.
 

1. Configuration file recovery - Firmware older than 5.20 or USG/Zywall series

1. Reboot the device

2. Enter debug mode and type

atkz –b

3. Enter the next command to start the reset

atgo

4. Now the device will start with the system-default configuration and back up the old startup-config.conf to startup-config-back.conf on the USG.

5. After the USG is accessible via its default credentials and IP, download the startup-config-back.conf to replace the admin password.

a.) Find the line beginning with “username admin encrypted-password” in the startup-config-back.conf. The line should look like this:

username admin encrypted-password $4$encryptedpasswordencryptedpassword$ user-type admin

b.) Change the line to ("12345678" will be your new password) and delete "encrypted-"

username admin password 12345678 user-type admin

Original line:

username admin encrypted-password $5$qfqk.z2q$r4R63fRn$SYGgbOziSvhxTSKphFuiHcGIGX5pn5r9V2xk/SP8Dsla86PngvJJq96Xy6ZXv6GFCuDBPofY9NyTxZUtnq
GT7FzyeFWkeCnmCgS7SH4WwYSN498C+6mDUgxeSHB2W6hlgSa/lErhYCrACjtOmkXXRn9cfqK8TVgNT3wQcFjBc6o1jyMs0AR+bDqJCicrj5dAtkEEsuAi7qnGCvDS0gC89aFt2RijLB4j0tH
z8YeVp0Us6PjSQrXmayBMEBcicOhCwJ19E6VUOTmLHIx87EGIq/TazBgHrT8KElFW+NqUzV9gG7XT0JUEbvGdj2/V9zQZ2+is2aF5tiZYvpKH2VbfJzIhmavq7Jn2WAoksVaYN9A$ user-type admin

After the changes:

username admin password 12345678 user-type admin

6. Save and rename the startup-config-back.conf, upload it back to the USG, and apply it.
Now you can log in with the new password you set in step 5.

With this, access to your firewall was restored.

 

Articles in this section

Was this article helpful?
14 out of 28 found this helpful
Share

Comments

2 comments

Please sign in to leave a comment.

  • Common guys, who uses RS232 these days. There are no PC with this interface anymore.

    Get real and provide an up-to-date interface or do you sitill dwell in in the 70is?

    0
  • HI Technik!

    RS232 is on USG Site so you can use USB to your PC. There are enough RS232 to USB Converter on the market to work for this scenario.

    Regards,

    Tobias

    0