Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Cisco FireWall Backup and Restore to

Posted on 2013-11-28
8
Medium Priority
?
400 Views
Last Modified: 2013-11-28
Hello,

we have a Cisco PIX 525 and we recently acquired another for backup purposes.

Now i would like to restore the Config onto the spare PiX.
i know they both have different image version.
Can i Backup the Image from  Production PiX and Restore it onto the Spare PiX
what is the simplest way of achieving identical settings on the spare, so it is simple question of replacing the production one if it fails in future.

Thanks in advance
0
Comment
Question by:icdl101
  • 4
  • 4
8 Comments
 
LVL 12

Expert Comment

by:Infamus
ID: 39683702
If you have two PIX, I would suggest configure them as primary and secondary for failover.

Here's the instruction.

http://www.cisco.com/en/US/docs/security/pix/pix63/configuration/guide/failover.html
0
 
LVL 12

Expert Comment

by:Infamus
ID: 39683719
If you still want the second PIX as spare in case the current PIX fails in the future, you will need to have BOTH devices have same software version installed.

Here is how to backup and restore using TFTP server.


1.Backing up to TFTP server (10.1.1.15)

pix#copy running-config tftp
Address or name of remote host []? 10.1.1.15
Destination filename [pix-confg]? backup_cfg_for_pix (assign file name)

2.Restore from TFTP server

pix#copy tftp running-config
Address or name of remote host []? 10.1.1.15
Source filename []? backup_cfg_for_pix (same name you assigned when you backup)
Destination filename [running-config]? <enter>

write mem
0
 

Author Comment

by:icdl101
ID: 39683749
i cannot use as a primary and secondary failover as i do not have the necessary add on cards for the Spare.

Thanks for the Config Step by Step.

How about the image version can i backup image from the Production Firewall and and copy it to the Spare ?
0
Nothing ever in the clear!

This technical paper will help you implement VMware’s VM encryption as well as implement Veeam encryption which together will achieve the nothing ever in the clear goal. If a bad guy steals VMs, backups or traffic they get nothing.

 
LVL 12

Accepted Solution

by:
Infamus earned 2000 total points
ID: 39683761
Yes.

First you need to configure IP on the LAN interfacce of secondary PIX.

I wouldn't plug in secondary PIX on the production network, I would just give it temp IP first. (192.168.1.1/24)

pixfirewall1#copy flash TFTP
Address or name of remote host [127.0.0.1]? 10.1.1.15
Source file name [cdisk]?pix611.bin (name of the image file)
copying tftp://10.1.1.15/pix611.bin to flash
[yes|no|again]?yes

Plug in your laptop (TFTP server) and configure NIC IP to same subnet as secondary PIX.
(192.168.1.101)

pixfirewall2#copy tftp flash
Address or name of remote host [127.0.0.1]? 192.168.1.101/24
Source file name [cdisk]?pix611.bin
copying tftp://192.168.1.101/pix611.bin to flash
[yes|no|again]?yes

reload
0
 

Author Comment

by:icdl101
ID: 39683800
thanks perfect.

Does the PiX support  copy flash to USB command ?
0
 
LVL 12

Expert Comment

by:Infamus
ID: 39683807
I believe so, does it have USB port?

Try dir and look at the result.
0
 

Author Comment

by:icdl101
ID: 39684117
The USB port on the PIX Firewall is a dummy port.
 It can not be enabled because it does not perform any function.
It is reserved for future use.
0
 

Author Closing Comment

by:icdl101
ID: 39684120
Thank you for your prompt and precise answers
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
This article will show how Aten was able to supply easy management and control for Artear's video walls and wide range display configurations of their newsroom.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
When cloud platforms entered the scene, users and companies jumped on board to take advantage of the many benefits, like the ability to work and connect with company information from various locations. What many didn't foresee was the increased risk…

824 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question