background image

8

4

Optional Maintenance and Upgrade Procedures

Upgrade to DES or 3DES

Note

The following instructions are applicable to PIX Firewall Version 6.2 and higher releases. If 
you are not running PIX Firewall Version 6.2, refer to the Quick Start Guide for the version 
of software installed on your PIX Firewall.

To upgrade features you did not specify at the time of purchase, you need to use an activation key. The 
activation key lets you add software features to the PIX 506E, such as DES or 3DES. 

To obtain a free DES (56-bit) license key for the PIX Firewall, use the IPSec 56-bit Customer 
Registration form. Accessing this form requires prior registration on Cisco.com at 
http://www.cisco.com/register. However, access to this form does not require a purchase or service 
contract. You can register as a guest and then proceed to fill out the form. The form is available at the 
following website:

http://www.cisco.com/cgi-bin/Software/FormManager/formgenerator.pl?pid=221&fid=324

Note

If you are unable to access this form because you do not have a CCO login, send an e-mail to 
[email protected]. In the e-mail include the PIX Firewall serial number as it appears in the 
show version command output and request a free 56-bit DES key.

You must purchase a 3DES (168-bit) license key, or have a service contract, to obtain a 3DES license 
key. If you have already purchased a 3DES upgrade, and you have your Cisco PIX Firewall 3DES 
upgrade document with the entitlement number printed on it, you can register your license key for use 
on your PIX Firewall with the License Registration form. Accessing this form also requires prior 
registration on Cisco.com at http://www.cisco.com/register. 

The License Registration form is available at the following website:

http://www.cisco.com/cgi-bin/Software/FormManager/formgenerator.pl?pid=221&fid=301

You must also purchase or have a service contract to download PIX Firewall software. Enter the 
activation key only after you have downloaded an image—not from the command line or without 
rebooting first.

Note

You can verify if you have the DES or 3DES feature by entering the show activation-key command.

Summary of Contents for PIX 506E

Page 1: ...Quick Start Guide Cisco PIX 506E Firewall Quick Start Guide 1 Check Items Included 2 Installing the PIX 506E 3 Configuring the PIX 506E 4 Optional Maintenance and Upgrade Procedures ...

Page 2: ...ing third party URL filtering products 67931 POWER ACT NETWORK CISCOPIX506E F I R E W A L L Hardware Features External power supply 300 MHz processor 32 MB RAM 8 MB Flash memory 1 autosensing 10BaseT Ethernet port for an outside connection to the Internet port 0 1 autosensing 10BaseT Ethernet port for a connection to your internal network Serial console port for administrative access Front panel L...

Page 3: ...ter 29 0810 01 PC terminal adapter 74 0495 01 Documentation Power supply and cable US shown 506E power supply 341 0007 01 Blue console cable 72 1259 01 Yellow Ethernet cable 72 1482 01 Yellow Ethernet cable 72 1482 01 Cisco PIX Firewall Product CD ETHERNET 0 ETHERNET 1 CONSOLE LINK USB ACT LINK ACT DC POWER INPUT ...

Page 4: ...de Ethernet interface Ethernet 0 to a DSL modem cable modem or router Step 3 Use the other Ethernet cable 72 1482 01 provided to connect the inside Ethernet interface Ethernet 1 to a switch or hub ETH ERN ET 0 ETH ERN ET 1 CON SOL E LINK DC POW ER INP UT USB ACT LINK ACT Computer or other network device Power adapter Router Laptop computer Printer Switch Yellow Ethernet cables Yellow Ethernet cabl...

Page 5: ...ower LED if it is green then the device is powered on For more information refer to the Check the LEDs section on page 11 Step 3 Connect the AC power connector of the power supply input cable to an electrical outlet Step 4 Set the power switch to the on position ETHERNET 0 ETHERNET 1 CONSOLE LINK DC POWER INPUT USB ACT LINK ACT Cisco PIX 506E DC POWER INPUT 67932 Power supply ...

Page 6: ...nge the administrative and Telnet passwords from their default settings to secure the administration of the PIX Firewall To configure Point to Point Protocol over Ethernet PPPoE or a static IP address for an outside interface To configure VPN and Auto Update features The PIX 506E contains an integrated configuration utility called Cisco PIX Device Manager PDM PDM is a web browser based configurati...

Page 7: ...ck the ACT LED on the rear panel of the PIX Firewall see Table 2 on page 11 to verify that your PC has basic connectivity to the inside port Ethernet 1 When connectivity occurs the ACT LED next to the port lights up solid green Step 4 To access the Startup Wizard use a PC connected to the inside port and enter the URL https 192 168 1 1 startup html into your browser Note Remember to add the s to h...

Page 8: ...fid 324 Note If you are unable to access this form because you do not have a CCO login send an e mail to licensing cisco com In the e mail include the PIX Firewall serial number as it appears in the show version command output and request a free 56 bit DES key You must purchase a 3DES 168 bit license key or have a service contract to obtain a 3DES license key If you have already purchased a 3DES u...

Page 9: ... at https 192 168 1 1 startup html Enter the following CLI commands Refer to the following website for detailed command information and configuration examples http www cisco com univercd cc td doc product iaabu pix pix_sw v_62 cmdref index htm The Cisco TAC website is available to all customers who need technical assistance To access the TAC Website go to http www cisco com tac Command Description...

Page 10: ...port Step 4 Configure the PC terminal emulation software or terminal for 9600 baud 8 data bits no parity and 1 stop bit You can also access the CLI using SSH Telnet to the PIX Firewall By default SSH Telnet access is not permitted Use PDM or the console to configure SSH Telnet access to the PIX Firewall To Telnet to the PIX Firewall from the outside perimeter of the firewall configure an outside I...

Page 11: ...is powered off Network Flashing green One or more network interfaces are passing traffic Off No network interfaces are passing traffic Table 2 PIX 506E Rear Panel LEDs LED State Description ACT On Network activity is present on the port Off No network activity is present on the port LINK On Data is passing on the port Off No data is passing on the port CISCO PIX 506E F I R E W A L L 67933 POWER AC...

Page 12: ...ntation CD ROM through the online Subscription Store http www cisco com go subscription Nonregistered Cisco com users can order documentation through a local account representative by calling Cisco corporate headquarters California USA at 408 526 7208 or elsewhere in North America by calling 800 553 NETS 6387 Documentation Feedback If you are reading Cisco product documentation on Cisco com you ca...

Page 13: ...se Register for online skill assessment training and certification programs You can self register on Cisco com to obtain customized information and service To access Cisco com go to the following URL http www cisco com Technical Assistance Center The Cisco TAC is available to all customers who need technical assistance with a Cisco product technology or solution Two types of support are available ...

Page 14: ...o com registered user you can open a case online by using the TAC Case Open tool at the following URL http www cisco com tac caseopen If you have Internet access it is recommended that you open P3 and P4 cases through the Cisco TAC Web Site Cisco TAC Escalation Center The Cisco TAC Escalation Center addresses issues that are classified as priority level 1 or priority level 2 these classifications ...

Page 15: ...15 ...

Page 16: ...d Kingdom United States Venezuela Vietnam Zimbabwe Copyright 2002 Cisco Systems Inc All rights reserved CCIP the Cisco Arrow logo the Cisco Powered Network mark the Cisco Systems Verified logo Cisco Unity Follow Me Browsing FormShare iQ Breakthrough iQ Expertise iQ FastTrack the iQ logo iQ Net Readiness Scorecard Networking Academy ScriptShare SMARTnet TransPath and Voice LAN are trademarks of Cis...

Reviews: