ASDM vulnerability concern

Answered Question
Mar 20th, 2007
User Badges:


I'm contimplating on using ASDM as a tool to monitor my PIX 525 in terms of VPN trhoughput, interface stats and perform the security check, all of which the asdm program offers.

Currently I prefer to use the CLI to implement change, and I will continue this practive.

My question is "Should I be concerned if I enable http inside so that I can access the installed asdm application?" Are there any security concerns? I'm thinking as long as I specify the host that will be used to access the PIX, I should be okay.

Your feedback is apreciated.



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
abinjola Tue, 03/20/2007 - 10:35
User Badges:
  • Cisco Employee,

rather than making it for the entire subnet why dont you make it specific to few hosts..till the time you have your enable credentials are safe as well..:-)

jkrawczyk Tue, 03/20/2007 - 10:43
User Badges:

Hi, yes good idea.

Now I'm thinking will asdm use my tacacs service. If not, I need to find out how to configure.



abinjola Tue, 03/20/2007 - 10:48
User Badges:
  • Cisco Employee,

you mean you have a TACACS Server configured ?..if yes then you can get ASDM authenticated via TACACS as well

jkrawczyk Tue, 03/20/2007 - 10:52
User Badges:


Yes I currently use tacacs server. Changed config is below:

I need to fond out if this config will use tacacs without any additional commands. I would think I would need to specify the authentication such as https. still digging on this issue. Thanks for the feedback,

aaa-server RADIUS protocol radius

aaa-server ABCACS protocol tacacs+

aaa-server ABCACS host

key guessme

aaa authentication ssh console ABCACS

aaa authentication enable console ABCACS

abinjola Tue, 03/20/2007 - 11:16
User Badges:
  • Cisco Employee,

add one more command for ASDM auth

aaa authentication http console ABACS

In this case you are not using the fall back mechanism that means if TACACS server is down ..then you would be completely locked

jkrawczyk Tue, 03/20/2007 - 12:13
User Badges:


Currently if tacacs is down, my local account can be accessed via ssh or console by using the default ?pix? local account.

Are you saying if I include ?aaa authentication http console ABCACS?, I will not be able ssh into my PIX not even bby using the local ?pix? account? I?m a little confused. All configuration changes will be made from either my console or ssh session. ASDM will be used only for monitoring, but I want to authenticate with my tacacs server when I access my PIX via http as well as ssh and console.

Best Regards


abinjola Tue, 03/20/2007 - 15:39
User Badges:
  • Cisco Employee,

yes you dont have a fallback configured that means that if your TACACS server is unreachable then you would not be able to access the firewall using ssh or console

to configure fallback to the local database try this :-

aaa authentication ssh console ABACS local


This Discussion