Configure the PIX Security Appliance with PIX Device Manager
|
|
|
|
Introduction
This document describes how to configure the PIX Security Appliance
with PIX Device Manager.
Back to Top
Requirements
This section lists the items that you need, to use the PIX Device
Manager (PDM) to access and configure your PIX:
Back to Top
Connect to the PIX
The PIX 506E/515E contains the integrated utility PDM. PDM is a
browser-based tool designed to help you to set up, configure, and monitor the
PIX Security Appliance. The PDM is preinstalled on the PIX 506E/515E.
Complete these steps to access the PIX with PDM:
-
Use an Ethernet cable to connect your PC to the inside port
(Ethernet 1) on the rear panel of the PIX Security Appliance.
-
Change the PC IP address to match the PIX inside interface IP
address (for example, if the PIX has an IP address 192.168.10.1, then configure
your PC with 192.168.10.50 and with subnet mask 255.255.255.0).
Note: You may need to restart your computer after you change the IP
address.
-
Check the ACT LED on the PIX front panel to verify that your PC has
the basic connectivity to the inside port-Ethernet 1. When the connectivity
occurs, the ACT LED on the front of the PIX lights up solid green.
-
Open a browser window and type https://
<pix_interface_ip_address> in your browser address field. This
new IP address is found on line R12 of the Security Appliance Worksheet.
Note: Ensure that you add the "s" to
"https" to launch the web browser. HTTPS (HTTP over SSL)
provides a secure connection between your browser and the PIX Security
Appliance.
-
Leave both the user name and password boxes empty and press
Enter.
-
Accept the security certificates.
To avoid the certificate from appearing in Windows Internet
Explorer when the certificate dialog (titled "Security Alert")
is shown, perform these steps:
-
Click View Certificate.
-
Click Install Certificate.
-
Click Next > Next > Finish >
Yes.
-
Click OK in the certificate dialog
box.
-
In the Security Alert dialog box, click
Yes.
-
The next logon screen appears. If no password is set, click
OK to continue.
-
Answer `Always' to the Security Warning asking "Do
you want to install and run `Cisco PIX Device Manager'". PDM starts after the
certificates are accepted.
Back to Top
Configure the PIX with the Startup Wizard
The Startup Wizard starts immediately the first time you connect to the
PDM. You can access the Startup Wizard at any time through the Wizards menu.
The Wizard can be aborted at any time by clicking Cancel. This preserves your
original PIX settings. The Back button allows you to go back and change the
information on previous screens before you click Finish.
Follow these steps to go through the initial setup of the PIX
firewall:
Basic Configuration
On the Basic Configuration panel, configure the host name of your
firewall and set the Enable Password, as well as a domain name for the
firewall.
Follow these steps for the basic configuration panel:
-
Enter the Host Name from line B63 of your Internet Worksheet. The
PIX Host Name can be up to 63 alphanumeric characters of mixed
case.
-
Enter the domain name the of the PIX Firewall found on line B48 of
the Internet Worksheet. There is a 64 alphanumeric character limit on the
domain name. No special characters or spaces must be used.
-
Check the box Change Enable Password.
-
Leave the Old Enable Password field blank. Enter the New Enable
password. The password is case-sensitive and up to 16 alphanumeric characters.
This password is found on line B12 of the Internet
Worksheet.
-
Enter the password for the second time in the Confirm New Enable
Password box.
-
Click Next.
Outside Interface Configuration
On the Outside Interface Configuration panel, configure the outside
interface IP address, subnet mask, and default gateway.
Follow these steps to configure the outside interface:
-
Speed—Leave the speed set to auto.
-
To configure the outside interface IP, follow these steps:
-
If you select DHCP on the Internet Worksheet:
-
Click Use DHCP.
-
Click
Next.
-
If you select Static IP on the Internet Worksheet:
-
Click Static IP Address.
-
Enter the IP address from line B46 of the Internet
Worksheet.
-
Enter the subnet mask found on line B41 of the Internet
Worksheet.
-
Enter the gateway IP address found on line B47 of the Internet
Worksheet.
-
Click
Next.
-
If you select Static PPP on the Internet Worksheet:
-
Click Use PPPoE. The PPPoE Configuration
screen appears.
-
Enter the User Name (Remote Host Name) from line B63 of the
Internet Worksheet.
-
Enter the PPPoE password (Shared Secret) from line B64 of the
Internet Worksheet.
-
Enter the password again in the Confirm password
box.
-
Click the PPP authentication from line B62 of the Internet
Worksheet.
-
Click Next.
Easy VPN Remote Configuration
On the Easy VPN Remote Configuration screen, follow these
steps:
Ensure the box Enable Easy VPN Remote is not
checked.
Click Next.
Auto Update Configuration
On the Auto Update Configuration screen, follow these
steps:
Ensure that the check box Enable Auto Update is not
checked.
Click Next.
Other Interfaces Configuration
The Other Interfaces Configuration panel lets you to configure the IP
addresses of the inside interface on the firewall. PDM automatically lists the
interfaces available for configuration. In this panel you can set the IP
address, speed, interface name, and security level to make each inside
interface unique.
To configure the internal interfaces, follow these
steps:
Highlight the preferred inside interface and click
Edit. Another panel appears with the highlighted
information.
-
Ensure that the Enable Interface box is
checked.
-
Ensure the speed is set to Auto.
-
Set the Security Level to 100.
Click OK and click Next.
NAT and PAT Configuration
On the NAT and PAT Configuration panel, configure the Port Address
Translation (PAT) to protect your network.
Follow these steps to configure PAT Configuration:
-
Select Use Port Address
Translation.
-
Click Use the IP address on the outside
interface.
-
Click Next.
DHCP Server Configuration
The DHCP Server Configuration panel lets you to configure the firewall
as a DHCP server to clients on the inside interface. You can configure a range
of IP addresses in the address pool to be assigned to the clients upon their
request.
If line L3 on the LAN Addressing Worksheet is your PIX firewall, the
DHCP server needs to be enabled. If not skip this step and click
Next.
Follow these steps to configure the DHCP server:
-
Check Enable DHCP on inside
interface.
-
Next to the DHCP Address Pool:
-
Enter the starting range of the DHCP server pool from line L50A
on the LAN Addressing Worksheet.
-
Enter the ending range of the DHCP server pool from line L51A on
the LAN Addressing Worksheet.
-
Next to the DHCP Parameters:
-
Enter the IP address of the DNS server from line L4A on the LAN
Addressing Worksheet.
-
Enter the IP address of the alternate DNS server from line L5A on
the LAN Addressing Worksheet.
-
Enter the domain name of the DNS server from line B48 of the
Internet Worksheet.
-
Click Next.
The create an Administrative Account panel appears. Click
Finish to save the configuration to the PIX Security
Appliance.
Back to Top
Create an Administrative Account
To create an administrative account to manage the PIX, follow these
steps:
-
Click Configuration.
-
Click System Properties.
-
Click Administration.
-
Click User Accounts.
-
Click Add.
-
Type admin in the User Name field and enter the
password that you entered on the Internet Worksheet (B11) in the Password and
Confirm Password fields. Ensure that the Privilege Level is set to
15 and click OK.
-
Click OK in the Information
window.
-
Click Apply.
Back to Top
Configure Authentication/Authorization
To configure authentication or authorization, follow these
steps:
-
Click Configuration > System
properties > Administration >
Authentication/Authorization.
The Authentication/Authorization screen
appears:
-
In the Authentication/Authorization screen, make these
changes:
-
Next to the Require AAA Authentication to allow use of Privileged
mode commands, check the Enable check box.
-
Click OK in Are you sure?
window and select LOCAL from the Server
Group.
-
Next to Require AAA Authentication for the these type of
connections, check the HTTP/PDM check box and select
Local. Click OK to the Are you sure? warning
message.
-
Next to the Require Authorization for PIX commands access, check
the Enable check box and then click OK in the
warning message. Select LOCAL from the Server
Group.
Click Apply.
The Predefined User Account Privileges screen appears.
Click No.
Note: If PDM displays a login window, log in with the new username
and password.
Back to Top
Configure a Time Server
Follow these steps to configure a time server on the security
appliance:
-
Click Configuration > System
properties > Administration >
NTP.
-
On the NTP screen, click Add.
-
In the NTP Server Detail window, enter these
values:
-
IP Address: Enter the IP address of the router than you entered
in field L6A of the LAN Addressing Worksheet.
-
Interface: Inside
-
Check the check box Preferred.
-
Leave the remaining fields blank.
-
Click OK.
-
Click Apply.
-
Click the Save button to save the
configuration.
Back to Top
Next Step
You have completed the initial setup of the PIX Security Appliance.
Refer to
Set Up
Internet Security on the PIX Security Appliance to secure your
PIX.
Back to Top
Troubleshoot the Procedure
This section provides information about common problems that you may
encounter.
Problem
|
Condition
|
Suggested Solution(s)
|
If the Browser asks for acceptance of the security certificate
again.
|
When the hostname or domain name is changed.
|
This is normal. Accept the security certificates again. (If you
change the hostname or domain of the firewall unit, the browser asks you to
accept the new security certificate.)
|
Browser asks for the password again.
|
If you change the password on the firewall unit, the browser
asks you to reenter the password for authentication.
If you use the Java Plug-in, the browser prompts you for your
username and password twice.
|
Keep track of new and changed passwords on your
worksheets.
|
Browser is unable to access PDM.
|
When you attempt to access PDM, the message "the page cannot be
displayed" appears in Internet Explorer or the message "network connection was
refused by the server" appears in Netscape Communicator.
|
Check that you are use "https" in your
connection to "https://inside_interface_ip_address " and
not "http". The connection is not possible by "http," it must be
"https."
|
Help files appear corrupted (on Internet Explorer
only).
|
This can occur because PDM compresses the online Help files and
Internet Explorer requires HTTP 1.1 to be enabled to handle compressed files
properly.
|
If you use a proxy server, select the Use HTTP 1.1
through proxy connections check box.
|
Some graphics or icons do not display properly.
|
PDM is made to run with a Java Plug-in that is not supported
(PDM supports Java Plug-in 1.4.2).
|
If you have the Java Plug-in installed, confirm that it is your
default Java Virtual Machine (JVM). Follow these steps to ensure that the Java
Plug-in is your default JVM:
-
In Internet Explorer, click Tools > Internet
Options.
-
Click the Advanced tab. Scroll down. Look for a Java (Sun)
section. If there is one, confirm that Use Java 2 is
selected.
In Netscape, click Edit > Preferences.
Click Advanced. Make sure that the Enable Java Plug-in check
box is selected.
For more detailed instructions see
Enable Java
and JavaScript on Your PC.
|
PDM launches slowly.
|
The startup speed of PDM depends on the amount of available RAM
in your computer and whether virus scanning software runs on your
computer.
|
You can increase your available RAM by closing other
applications.
The time required to download the PDM applet can be greatly
affected by the speed of the link between your workstation and the firewall
unit. A minimum of 56 Kbps link speed is required. However, 3.84 Mbps or higher
is recommended. Once the PDM applet is loaded on your workstation, the link
speed impact on PDM operation is negligible.
|
There is access only to the Monitoring tab in
PDM.
|
The use of certain firewall CLI commands, and certain command
combinations, limits the access in PDM to the Monitoring tab.
|
For more information on these commands and command
combinations, see the Catalyst 6500 Series Switch and Cisco 7600
Series Router Firewall Services Module Configuration Guide Release
2.3.
|
PDM prompts for the username/password and certificate
information twice.
|
This is normal when you use Java Plug-in.
|
You can choose to accept the certificate permanently so that
this dialog box does not appear again.
|
Back to Top
Related Information