Solved

Cannot connect to Cisco Pix due to a Certificate error.

Posted on 2009-05-19
9
670 Views
Last Modified: 2012-06-27
When attempting to connect to our Cisco Pix device vie IE I get a "Certificate Error". I have had to obtain new certificates for our ADP software from Bank Of America so I am familiar with installing new certs but I am new to this position that I now hold and there is no one here to guide me threw this one.

I was wondering where I would get a new cert from. Would it be Cisco or am I just lost? Can someone please help me? If you need any additional information I will be more than happy to provide it.

Thank you in advanced
Michael
0
Comment
Question by:bvrmnky46
  • 5
  • 4
9 Comments
 
LVL 13

Expert Comment

by:3nerds
ID: 24422097
bvrmnky46,

Are you just attempting to administer this device? If so then the expired certificate will have no bearing for you. As you will be the only one connecting to it. I will warn you though the PVDM is a bad/flaky way to administer this device imho.

It doesn't need a certificate to function and it doesn't support SSL VPN so would you  be able to explain what you were doing when you ran into this error.

Regards,

3nerds
0
 

Author Comment

by:bvrmnky46
ID: 24423527
Actually I was attempting to connect so that I can reroute my incoming SMTP to another IP on our network. I have installed a new spam/virus filter.

I attempted to connect to it like so https://ip address

I get a "please wait" while connecting and nothing but that cert error is present.
0
 
LVL 13

Accepted Solution

by:
3nerds earned 500 total points
ID: 24423676
Pix used an early gui called a PVDM it was unstable. It may not be loading simply because in your device it is not working.

I tried to stay away from the PVDM. The new ASDM is much nicer.

If you would like assistance with these changes via command line I would be glad to help.

You will need to get a tool like putty to connect to the device via ssh, you could even try to connect to the device via telnet as that may be open to it as well it depends on the config.

try this.

open a command prompt and type the following:
telnet <device IP>
and hit enter.

If it doesn't connect download putty and try to connect via that.

Once you are in the device do a show run and copy the output and paste it here. If you don't want to paste your whole config just past your lines in regard to STATIC.

MAKE SURE YOU XX OUT any USERNAMES, PASSWORDS OR IP ADDRESSES. I don't want you opening yourself up to any one messing with you and that info would let them right in.

Good Luck,

3nerds
0
 

Author Comment

by:bvrmnky46
ID: 24423820
I did a telnet and got in but then I'm a bit confused by the "show run" what exactly do I do?

I'm sorry but obviously I am not familiars at all whit this unit or Cisco for that matter.

Thank you!
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 
LVL 13

Expert Comment

by:3nerds
ID: 24423951
are you at a

>

or a

#

for a prompt?

If your at the >
type
>en
hit enter
it should prompt you for a password

if your at the #
type
#sh ru
hit enter

lots of code will show up on your screen.

Good Luck,

3nerds
0
 

Author Comment

by:bvrmnky46
ID: 24424061
I did the #sh ru and seen all the configurations. I need to make some changes and maybe this is far to much to ask. Let me know and I will continue.

Thank you so far by the way. You are way cool!!
0
 
LVL 13

Expert Comment

by:3nerds
ID: 24424109
I need to see the code you are seeing, to help further.

I don't know what the rules are for "going to far" per say are but if you want to post the code I will see what I can do.

If you want to start a new post let me know I can help you there as well.

Your call on that one.

In your config you should see some lines that start with the word "Static" to start out I specifically need those lines but the whole config may be necessary.

Good Luck,

3nerds

0
 
LVL 13

Expert Comment

by:3nerds
ID: 24435125
Just checking to see if you still need assistance?
0
 

Author Closing Comment

by:bvrmnky46
ID: 31582996
Thanks for your help. I have to stop here because I found our support information from Cisco.. lol, better for me!!
0

Featured Post

Free camera licenses with purchase of My Cloud NAS

Milestone Arcus software is compatible with thousands of industry-leading cameras for added flexibility. Upon installation on your My Cloud NAS, you will receive two (2) camera licenses already enabled in the software. And for a limited time, get additional camera licenses FREE.

Join & Write a Comment

Article by: IanTh
Hi Guys After a whole weekend getting wake on lan over the internet working, I thought I would share the experience. Your firewall has to have a port forward for port 9 udp to your local broadcast x.x.x.255 but if that doesnt work, do it to a …
Join Greg Farro and Ethan Banks from Packet Pushers (http://packetpushers.net/podcast/podcasts/pq-show-93-smart-network-monitoring-paessler-sponsored/) and Greg Ross from Paessler (https://www.paessler.com/prtg) for a discussion about smart network …
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now