Automating PIX Configuration

Unanswered Question
Jan 7th, 2008
User Badges:

I am trying to automate the configuration of PIX501 (currently running 6.3). My goal is to have a tech pull a PIX out of the box and enter the Serial Number and MAC address into a database. At that point a DHCP reservation is made for the MAC address and the firewall is put on a shelf until needed.

When needed, the PIX is installed and powered up. The tech can then trigger an event to automatically push a configuration down (from outside) into the PIX eliminating as much operator error as possible.

The problem: The PIX does not come out of the box with SSH configured from the outside. Is there anyway to work around this? Presently, I am down to configuring SSH for outside, setting the domain-name and generating the RSA keys. I really need to eliminate even this amount of manual intervention.




  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Collin Clark Tue, 01/08/2008 - 06:31
User Badges:
  • Purple, 4500 points or more

I used to use VB scripts in SecureCRT to eliminate user error. I know of no way to have a FW pre-configured from Cisco. I can provide the script if you like.



This Discussion