Solved

Need to Backup Cisco Pix 506E but the IOS has no dir command

Posted on 2010-11-19
10
1,242 Views
Last Modified: 2012-05-10
I have a Cisco PIX 506e running firewall version 6.3(3) and I am trying to take a backup to tftp server, but the IOS has no dir command.  Can someone point me in the right direction here?  I need to take a good backup of this 506E as it is in service and I want to connect a second, remote 506E to it and establish an IPSEC VPN tunnel between the two.  Of courese, I have to know I have a good backup of the in-service 506E before I begin testing.  Many thanks in advance.
0
Comment
Question by:NJJimInHI
  • 5
  • 4
10 Comments
 
LVL 17

Expert Comment

by:Kvistofta
ID: 34176127
The easiest way to get a backup of the current configuration is to issue the "show running-config"-command in enable-mode and copy all output to a textfile. Like this:

password: ****
firewall> enable
password: *****
firewall# show running-config
<A lot of outout>
<A lot of outout>
<A lot of outout>
firewall#

The way to send your config to a tftp server is this command:
firewall#copy running-config tftp:
This command will prompt you of the ip-address to the tftp-server and the file name to write before sending the file.

Best regards
Kvistofta
0
 

Author Comment

by:NJJimInHI
ID: 34176164
Thanksk Kvistofta,

Backing up thios way, how would I restore from this text file, if need be?
0
 
LVL 17

Expert Comment

by:Kvistofta
ID: 34176263
The easiest way is to "copy tftp startup-config" and then reboot the router.

Another way is to wipe the config ("write erase" and reload the router) and paste all config from the text file into the router(config)#-prompt of the console terminal. What you might miss then is to do "no shutdown" of default-shutdown interfaces.

/Kvistofta
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 

Author Comment

by:NJJimInHI
ID: 34176279
I tried:
The way to send your config to a tftp server is this command:
firewall#copy running-config tftp:
This command will prompt you of the ip-address to the tftp-server and the file name to write before sending the file.

But the IOS keeps coming back with usage suggestion for "copy".

Unable to save a copy of running-config to my tftp server with these instructions.  Different commands possibly?

Thanks
0
 
LVL 17

Expert Comment

by:Kvistofta
ID: 34176330
Can you do it again and paste all output here?

/Kvistofta
0
 

Author Comment

by:NJJimInHI
ID: 34177758
After successfully running "show running-config", I then tried the following, with the "Usage: results being returned fy the IOS.
:
firewall# copy running-config tftp:
Usage:  copy capture:<capture-name> tftp://<location>/<pathname> [pcap]
        copy http[s]://[<user>:<password>@]<location>[:<port>]/<pathname>
                flash[:[image | pdm]]
        copy tftp[:[[//location][/pathname]]] flash[:[image | pdm]]
0
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 125 total points
ID: 34178059
With PIX 6.3, use the following to backup the configuration:

write net 10.10.10.100:pix

Where 10.10.10.100 is the IP of the TFTP server and "pix" is the filename.

Use the "configure net" command to restore the configuration to the PIX.

configure net 10.10.10.100:pix
0
 

Author Comment

by:NJJimInHI
ID: 34193232
JFrederick29 - Thanks, but as there is no "Dir" command in this IOS, how can I determine the file names I need to back up.?
0
 
LVL 17

Assisted Solution

by:Kvistofta
Kvistofta earned 125 total points
ID: 34194373
There is no "file name" to back up. "writ net 10.10.10.100:pix" will send the current configuration to the tftp-server 10.10.10.100 and write it to file name "pix" on the server. You dont have to specify a file name on the firewall, "write net" will just take the current running-config which is in memory.

Best regards
Kvistofta
0
 

Author Comment

by:NJJimInHI
ID: 34201429
Just tested "write net" and "configure net" on a spare 506E and that works just fine.  I'm going to "accept multiple solutions" in the hopes that you both share the points.  Thanks for your help guys!
0

Featured Post

Connect further...control easier

With the ATEN CE624, you can now enjoy a high-quality visual experience powered by HDBaseT technology and the convenience of a single Cat6 cable to transmit uncompressed video with zero latency and multi-streaming for dual-view applications where remote access is required.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question