Solved

Cisco FireWall Backup and Restore to

Posted on 2013-11-28
8
393 Views
Last Modified: 2013-11-28
Hello,

we have a Cisco PIX 525 and we recently acquired another for backup purposes.

Now i would like to restore the Config onto the spare PiX.
i know they both have different image version.
Can i Backup the Image from  Production PiX and Restore it onto the Spare PiX
what is the simplest way of achieving identical settings on the spare, so it is simple question of replacing the production one if it fails in future.

Thanks in advance
0
Comment
Question by:icdl101
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
8 Comments
 
LVL 12

Expert Comment

by:Infamus
ID: 39683702
If you have two PIX, I would suggest configure them as primary and secondary for failover.

Here's the instruction.

http://www.cisco.com/en/US/docs/security/pix/pix63/configuration/guide/failover.html
0
 
LVL 12

Expert Comment

by:Infamus
ID: 39683719
If you still want the second PIX as spare in case the current PIX fails in the future, you will need to have BOTH devices have same software version installed.

Here is how to backup and restore using TFTP server.


1.Backing up to TFTP server (10.1.1.15)

pix#copy running-config tftp
Address or name of remote host []? 10.1.1.15
Destination filename [pix-confg]? backup_cfg_for_pix (assign file name)

2.Restore from TFTP server

pix#copy tftp running-config
Address or name of remote host []? 10.1.1.15
Source filename []? backup_cfg_for_pix (same name you assigned when you backup)
Destination filename [running-config]? <enter>

write mem
0
 

Author Comment

by:icdl101
ID: 39683749
i cannot use as a primary and secondary failover as i do not have the necessary add on cards for the Spare.

Thanks for the Config Step by Step.

How about the image version can i backup image from the Production Firewall and and copy it to the Spare ?
0
Surfing Is Meant To Be Done Outdoors

Featuring its rugged IP67 compliant exterior and delivering broad, fast, and reliable Wi-Fi coverage, the AP322 is the ideal solution for the outdoors. Manage this AP with either a Firebox as a gateway controller, or with the Wi-Fi Cloud for an expanded set of management features

 
LVL 12

Accepted Solution

by:
Infamus earned 500 total points
ID: 39683761
Yes.

First you need to configure IP on the LAN interfacce of secondary PIX.

I wouldn't plug in secondary PIX on the production network, I would just give it temp IP first. (192.168.1.1/24)

pixfirewall1#copy flash TFTP
Address or name of remote host [127.0.0.1]? 10.1.1.15
Source file name [cdisk]?pix611.bin (name of the image file)
copying tftp://10.1.1.15/pix611.bin to flash
[yes|no|again]?yes

Plug in your laptop (TFTP server) and configure NIC IP to same subnet as secondary PIX.
(192.168.1.101)

pixfirewall2#copy tftp flash
Address or name of remote host [127.0.0.1]? 192.168.1.101/24
Source file name [cdisk]?pix611.bin
copying tftp://192.168.1.101/pix611.bin to flash
[yes|no|again]?yes

reload
0
 

Author Comment

by:icdl101
ID: 39683800
thanks perfect.

Does the PiX support  copy flash to USB command ?
0
 
LVL 12

Expert Comment

by:Infamus
ID: 39683807
I believe so, does it have USB port?

Try dir and look at the result.
0
 

Author Comment

by:icdl101
ID: 39684117
The USB port on the PIX Firewall is a dummy port.
 It can not be enabled because it does not perform any function.
It is reserved for future use.
0
 

Author Closing Comment

by:icdl101
ID: 39684120
Thank you for your prompt and precise answers
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
Arrow Electronics was searching for a KVM  (Keyboard/Video/Mouse) switch that could display on one single monitor the current status of all units being tested on the rack.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question