According to Nortel tech-support, this can only be done by them. They have a backdoor password generator that is based on the MAC address. My experience with this was troubling. first level support said that this only works with later 350's and not the earlier ones. They tried the password generator, said it was not responding, and generated an RMA. A standard 'REPAIR' on one of these is $1499.00 and 'a repair is a repair', 15 minutes work or a swapout is the same. I canceled the RMA, and the first level tech responded by closed the call (no phone call or permission). I then called in to the case manager, reopened and escalated the call. My 'older' switch was suddenly able to have a password generated for it. I think there are two morals, one for us and one for Nortel. For us: get the switch defaulted before you buy it or escalate immediately past first level support. For Nortel: PLEASE put a firmware BREAK in the boot prcess (like Cisco for instance!), so that we can tell a device to IGNORE a configuration on boot-up!!!