cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
641
Views
0
Helpful
8
Replies

ASDM vulnerability concern

jkrawczyk
Level 1
Level 1

Hello;

I'm contimplating on using ASDM as a tool to monitor my PIX 525 in terms of VPN trhoughput, interface stats and perform the security check, all of which the asdm program offers.

Currently I prefer to use the CLI to implement change, and I will continue this practive.

My question is "Should I be concerned if I enable http inside 192.168.1.0 255.255.255.0 so that I can access the installed asdm application?" Are there any security concerns? I'm thinking as long as I specify the host that will be used to access the PIX, I should be okay.

Your feedback is apreciated.

Regards

Jeff

1 Accepted Solution
8 Replies 8

abinjola
Cisco Employee
Cisco Employee

rather than making it for the entire subnet why dont you make it specific to few hosts..till the time you have your enable credentials safe..you are safe as well..:-)

Hi, yes good idea.

Now I'm thinking will asdm use my tacacs service. If not, I need to find out how to configure.

Regards

Jeff

you mean you have a TACACS Server configured ?..if yes then you can get ASDM authenticated via TACACS as well

Hi,

Yes I currently use tacacs server. Changed config is below:

I need to fond out if this config will use tacacs without any additional commands. I would think I would need to specify the authentication such as https. still digging on this issue. Thanks for the feedback,

aaa-server RADIUS protocol radius

aaa-server ABCACS protocol tacacs+

aaa-server ABCACS host 192.168.100.1

key guessme

aaa authentication ssh console ABCACS

aaa authentication enable console ABCACS

add one more command for ASDM auth

aaa authentication http console ABACS

In this case you are not using the fall back mechanism that means if TACACS server is down ..then you would be completely locked

Hi;

Currently if tacacs is down, my local account can be accessed via ssh or console by using the default ?pix? local account.

Are you saying if I include ?aaa authentication http console ABCACS?, I will not be able ssh into my PIX not even bby using the local ?pix? account? I?m a little confused. All configuration changes will be made from either my console or ssh session. ASDM will be used only for monitoring, but I want to authenticate with my tacacs server when I access my PIX via http as well as ssh and console.

Best Regards

Jeff

yes you dont have a fallback configured that means that if your TACACS server is unreachable then you would not be able to access the firewall using ssh or console

to configure fallback to the local database try this :-

aaa authentication ssh console ABACS local

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: