PIX 506 Certificate install from am Windows server CA

I want to install a certificate on a PIX 506e from our windows 2003 server CA.
In the Cisco manual it is written: "You have to contact the CA administrator to authenticate your PIX manually"

I don't know how to do that.

I am using PDM, and tried also command interface.

I need to use this certificate for VPN client setup.
LVL 14
Ehab SalemIT ManagerAsked:
Who is Participating?
javajwsConnect With a Mentor Commented:
Ehab SalemIT ManagerAuthor Commented:
Thanks a lot, but I got stuck.

I downloaded the MSCEP add-on, installed it, and followed all the instructions given, and all went ok.
But after the certificate enrollment was successfull, I tried to logon to the PIX PDM to configure VPN I couldn't. It is always giving "Cannot find server".

I restored original conf and it worked back again. I restarted the procedure and I always get stuck at this point.

What could be wrong?
I think you are doing everything correctly.  I think you need to use my solution above with this additional piece of information:
Managing Security Policy in a Changing Environment

The enterprise network environment is evolving rapidly as companies extend their physical data centers to embrace cloud computing and software-defined networking. This new reality means that the challenge of managing the security policy is much more dynamic and complex.

Ehab SalemIT ManagerAuthor Commented:
I just wanted to make things more clear:
Before doing the enrollment I was able to use the PDM.
After enroll, PDM is not working
I restarted the PIX (conf changes lost), then PDM is working again.

I habe one question:

I read in another Cisco doc that I have to enter
ca save all

In the end.
I did not. Can this be the cause of the problem?
It very well could be.  Give it a try.
Ehab SalemIT ManagerAuthor Commented:
ca save all did not solve the proble, neither did: aaa authentication http console LOCAL

I do not have a problem in username and password, the PIX PDM page is not opening at all.
Ehab SalemIT ManagerAuthor Commented:
Now even after restart I cannot use PDM.

PDM is now again working after I wrote:

ca zeroize rsa

But the enrollment is cancelled.
Ehab SalemIT ManagerAuthor Commented:
I am still facing the problem that everytime I restart the PIX I cannot access thru PDM http interface, till I zeroize rsa.

I really appreciate the help by javajws, and would like to complete the task.
Ehab SalemIT ManagerAuthor Commented:
I don't know what happened but it is working. Thanks
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.