Feedback
|
Table Of Contents
Cisco PIX Security Appliance Release Notes Version 8.0(2)
Maximum Recommended Configuration File Size
Cisco VPN Software Interoperability
Cisco VPN Client Interoperability
Cisco Easy VPN Remote Interoperability
Determining the Software Version
Upgrading to a New Software Version
Readme Document for the Conduits and Outbound List Conversion Tool 1.2
Features not Supported in Version 8.0(2)
Obtaining Documentation and Submitting a Service Request
Cisco PIX Security Appliance Release Notes Version 8.0(2)
June 2007Contents
This document includes the following sections:
•
Obtaining Documentation and Submitting a Service Request
Introduction
Note
The PIX 501, PIX 506/506E, and PIX 520 security appliances are not supported in software Version 8.0(2).
The Cisco PIX 500 series security appliance delivers unprecedented levels of defense against threats to the network with deeper web inspection and flow-specific analysis, improved secure connectivity through end-point security posture validation and voice and video over VPN support. It also provides enhanced support for intelligent information networks through improved network integration, resiliency, and scalability.
For more information on all the new features, see New Features.
Additionally, the adaptive security appliance software supports Cisco Adaptive Security Device Manager (ASDM). ASDM delivers world-class security management and monitoring through an intuitive, easy-to-use web-based management interface. Bundled with the security appliance, ASDM accelerates adaptive security appliance deployment with intelligent wizards, robust administration tools, and versatile monitoring services that complement the advanced integrated security and networking features offered by the market-leading suite of the security appliance. Its secure, web-based design enables anytime, anywhere access to security appliances.
System Requirements
The sections that follow list the system requirements for operating a security appliance.
Note
The PIX 501, PIX 506/506E, and PIX 520 security appliances are not supported in software Version 8.0(2).
Memory Requirements
If you are using a PIX 515/515E running PIX Version 6.2/6.3, you must increase your memory before upgrading to PIX Version 8.0(2). This version requires at least 64 MB of RAM for Restricted (R) licenses and 128 MB of RAM for Unrestricted (UR) and Failover (FO) licenses. Table 1 lists the default value for the memory that ships with each security appliance and flash memory requirements for Version 8.0(2).
Table 1 Default Memory Shipped and Flash Memory Requirements
PIX Security Appliance Model Default Memory (MB) Flash Memory Required (MB)515/515E
64
16
525
128
535
512
For more information about minimum memory requirements, see the "Minimum Memory Requirements" section in the Guide for Cisco PIX 6.2 and 6.3 Users Upgrading in Cisco PIX Software Version 7.0.
Software Requirements
Version 8.0(2) requires the following:
•
The minimum software version required before upgrading to PIX Version 8.0(2) is PIX Version 7.2. If you are running a PIX version earlier than Version 6.2, you must first upgrade to PIX Version 6.2 or PIX Version 6.3 before you can upgrade to PIX Version 7.2.
•
To upgrade your PIX software image, go to the following website:
http://www.cisco.com/public/sw-center/index.shtml
•
For information on specific licenses supported on each model of the security appliance, go to the following website: http://www.cisco.com/en/US/docs/security/asa/asa80/license/license80.html
•
If you are upgrading from a previous PIX version, save your configuration and record your activation key and serial number. For new installation requirements, go to the following website: http://www.cisco.com/public/sw-center/index.shtml
Maximum Recommended Configuration File Size
For the PIX 525 and PIX 535, the maximum supported configuration file size is 2 MB for Version 8.0(2). For the PIX 515/515E, the maximum supported configuration file size is 1 MB for Version 8.0(2). If you are using ASDM, we recommend no more than a 500 KB configuration file, because larger configuration files can interfere with the performance of ASDM on your workstation.
While configuration files up to 2 MB are supported on the PIX 525 and PIX 535, be aware that such large configuration files can reduce system performance. For example, a large configuration file is likely to noticeably slow execution times in the following situations:
•
While executing commands such as the write terminal and show running-config commands
•
Failover (the configuration synchronization time)
•
During a system reload
Cisco VPN Software Interoperability
Cisco VPN Client Interoperability
Cisco Easy VPN Remote Interoperability
Determining the Software Version
Use the show version command to verify the software version installed on your security appliance. Alternatively, you can view the software version on the Cisco ASDM home page.
Upgrading to a New Software Version
If you have a Cisco.com (CDC) login, you can obtain software from the following website:
http://www.cisco.com/public/sw-center/index.shtml
If you want to upgrade from Version 7.1.(x) to 7.2(x) or downgrade from Version 7.2(x) to Version 7.1(x), you must follow the subsequent procedure, because older versions of the security appliance images do not recognize new ASDM images, and new security appliance images does not recognize old ASDM images.
You can also use the CLI to download the image. For more information, see the "Downloading Software or Configuration Files to Flash Memory" section in the Cisco Security Appliance Command Line Configuration Guide.
To upgrade from Version 7.2.(x) to Version 8.0(2), perform the following steps:
Step 1
Load the new Version 8.0(2) image from the following website:
http://www.cisco.com/public/sw-center/index.shtml
Step 2
Reload the device to upgrade to the Version 8.0(2) image.
Step 3
Copy the new ASDM Version 6.0 image from the following website:
http://www.cisco.com/public/sw-center/index.shtml
Step 4
Enter the following command to tell the security appliance where to find the ASDM image:
hostname(config)# asdm image flash:/asdmfile
To downgrade from Version 8.0(2) to 7.2.(x), perform the following steps:
Step 1
Load the earlier Version 7.2(x) image from the following website:
http://www.cisco.com/public/sw-center/index.shtml
Step 2
Reload the device to downgrade to the Version 7.2(x) image.
Step 3
Copy the earlier ASDM Version 5.2(x) image from the following website:
http://www.cisco.com/public/sw-center/index.shtml
Step 4
Enter the following command to tell the security appliance where to find the ASDM image:
hostname(config)# asdm image flash:/asdmfile
New Features
This section lists the new feature for Version 8.0(2). All new features are supported in ASDM 6.0(2).
Important Notes
This section lists important notes related to Version 8.0(2).
virtual http Command
The virtual http command has been restored. This command is needed with basic authentication when you have cascading authentication requests.
FIPS 140-2
Version 8.0(2) has been submitted for FIPS 140-2 Level 2 validation.
AnyConnect Client Sessions
A reestablished AnyConnect Client session fails to displace an AnyConnect Client session that is terminated abnormally (CSCsi40917).
Open Source Software Usage
For a list of the open source software used in th ASA 8.0 release, see the Open Source Software Licenses for ASA and PIX Security Appliances document on Cisco.com.
User Upgrade Guide
Before upgrading to Version 8.0(2), read the Guide for Cisco PIX 6.2 and 6.3 Users Upgrading in Cisco PIX Software Version 7.0. This guide includes information about deprecated features and other changes in the Cisco PIX software Version 7.0. For a list of deprecated features and user upgrade information, go to the following URL:
http://www.cisco.com/en/US/docs/security/asa/asa70/pix_upgrade/upgrade/guide/pixupgrd.html
CautionIf you share the Stateful Failover update link with a link for regular traffic such as your inside interface, you must change your configuration before upgrading. Do not upgrade until you have corrected your configuration, because this is not a supported configuration and Version 8.0(2) treats the LAN failover and Stateful Failover update interfaces as special interfaces. If you upgrade to Version 8.0(2) with a configuration that shares an interface for both regular traffic and the Stateful Failover updates, configuration related to the regular traffic interface will be lost after the upgrade. The lost configuration may prevent you from connecting to the adaptive security appliance over the network.
Readme Document for the Conduits and Outbound List Conversion Tool 1.2
The security appliance Outbound and Conduit Conversion tool assists in converting configurations with the outbound or conduit command to similar configurations using ACLs. ACL-based configurations provide uniformity, optimize the ACL feature set, and provide the following benefits:
•
ACE insertion capability— Provides simplified system configuration and management, which allows you to add, delete, or modify individual ACEs.
•
Outbound ACLs and time-based ACLs—Provides administrators with improved flexibility for defining access control policies by adding support for outbound ACLs and time-based ACLs.
•
Enabling and Disabling of ACL entries—Provides a convenient troubleshooting tool that allows administrators to test and fine-tune ACLs without the need to remove and replace ACL entries.
Features not Supported in Version 8.0(2)
The PPTP feature is not supported in Version 8.0(2).
The TLS proxy feature is not supported on the PIX security appliance.
Downgrade to Previous Version
To downgrade to a previous version of the operating system software (software image), use the downgrade command in privileged EXEC mode. Use the downgrade command only if you want to downgrade to a version other than 7.x.
For more information and a complete description of the command syntax, see the Cisco Security Appliance Command Reference.
CautionDo not load a previous version of software if your PIX security appliance is currently running PIX Version 7.0 or later. If you load a software image from monitor mode onto a PIX security appliance that has a PIX Version 7.0 file system, unpredictable behavior may occur and is not supported. We strongly recommend that you use the downgrade command from a running PIX Version 7.0 image that facilitates the downgrade process.
Certificates
•
Symptom: SSL connections from browsers and AnyConnect fail if the certificate being used contains the following enhanced key usage "IP security IKE intermediate (1.3.6.1.5.5.8.2.2)". This is the default way of issuing certificates via SCEP enrollment to a Microsoft 2003 Enterprise CA with the newer certificate templates.
Workaround:
–
Use terminal enrollment instead of SCEP to get an ASA certificate.
–
Changing the SCEP policy module on the 2003 CA may alleviate this issue.
•
Symptom: If the validity date on the a certificate is issued beyond the year 2099, it will fail to authenticate and an error will be generated when attempting to authenticate it.
Workaround:
–
Limit the validity period of the certificate to less than the recommended end date of 03:14:08 UTC, January 19, 2038.
•
Symptom: User prompted for credentials when permstore and auto-signon are both enabled.
Conditions:
Both auto-signon and permanent-storage are enabled for the server requiring authentication.
Workaround:
–
Disable auto-signon for this server. Enable auto-signon only for servers having the same login credentials as WebVPN.
Note
Because credentials used by auto-signon take precedence over permanent-storage of user credentials, do not enable auto signon for servers that do not require authentication or that use credentials different from the adaptive security appliance. When auto signon is enabled, the adaptive security appliance passes on the login credentials that the user entered to log into the adaptive security appliance regardless of what credentials are in user storage.
Caveats
This section lists the open and resolved caveats for Version 8.0(2).
For your convenience in locating caveats in Cisco's Bug Toolkit, the caveat titles listed in this section are drawn directly from the Bug Toolkit database. These caveat titles are not intended to be read as complete sentences because the title field length is limited. In the caveat titles, some truncation of wording or punctuation may be necessary to provide the most complete and concise description. The only modifications made to these titles are as follows:
•
Commands are in boldface type.
•
Product names and acronyms may be standardized.
•
Spelling errors and typos may be corrected.
Note
If you are a registered cisco.com user, view Bug Toolkit on cisco.com at the following website:
http://www.cisco.com/pcgi-bin/Support/Bugtool/launch_bugtool.pl
To become a registered cisco.com user, go to the following website:
http://tools.cisco.com/RPF/register/register.do
Open Caveats - Version 8.0(2)
Related Documentation
Use this document in conjunction with the PIX firewall and Cisco VPN client Version 3.x documentation at the following website:
http://www.cisco.com/en/US/products/sw/secursw/ps2120/tsd_products_support_series_home.html
http://www.cisco.com/en/US/products/sw/secursw/ps2308/tsd_products_support_series_home.html
Obtaining Documentation and Submitting a Service Request
For information on obtaining documentation, submitting a service request, and gathering additional information, see the monthly What's New in Cisco Product Documentation, which also lists all new and revised Cisco technical documentation, at:
http://www.cisco.com/en/US/docs/general/whatsnew/whatsnew.html
Subscribe to the What's New in Cisco Product Documentation as a Really Simple Syndication (RSS) feed and set content to be delivered directly to your desktop using a reader application. The RSS feeds are a free service and Cisco currently supports RSS version 2.0.
This document is to be used in conjunction with the documents listed in the "Related Documentation" section.
CCVP, the Cisco logo, and the Cisco Square Bridge logo are trademarks of Cisco Systems, Inc.; Changing the Way We Work, Live, Play, and Learn is a service mark of Cisco Systems, Inc.; and Access Registrar, Aironet, BPX, Catalyst, CCDA, CCDP, CCIE, CCIP, CCNA, CCNP, CCSP, Cisco, the Cisco Certified Internetwork Expert logo, Cisco IOS, Cisco Press, Cisco Systems, Cisco Systems Capital, the Cisco Systems logo, Cisco Unity, Enterprise/Solver, EtherChannel, EtherFast, EtherSwitch, Fast Step, Follow Me Browsing, FormShare, GigaDrive, HomeLink, Internet Quotient, IOS, iPhone, IP/TV, iQ Expertise, the iQ logo, iQ Net Readiness Scorecard, iQuick Study, LightStream, Linksys, MeetingPlace, MGX, Networking Academy, Network Registrar, Packet, PIX, ProConnect, ScriptShare, SMARTnet, StackWise, The Fastest Way to Increase Your Internet Quotient, and TransPath are registered trademarks of Cisco Systems, Inc. and/or its affiliates in the United States and certain other countries.
All other trademarks mentioned in this document or Website are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (0705R)
© 2007 Cisco Systems, Inc.
All rights reserved.
Feedback
