PIX -- Forgot "route inside" to new TACACS servers

Unanswered Question
Apr 23rd, 2009

Tacacs servers moved to a new subnet. Changed the AAA and telnet statements on the PIX to point towards and allow the new servers.

Egg on my face, when I couldn't log into the PIX. Checked syslog and saw that there was no route configured to the new subnet. Doh!!

I realized that a 'route inside' statement was missing. I attached console cable to the PIX. Console access requested Tacacs credentials.

Need assistance on how to add the "route inside" statement without bringing down my firewall. Firewall is also in failover configuration.

Doh!!!

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Collin Clark Fri, 04/24/2009 - 05:12

I assume you don't have LOCAL as a backup? You can either move the AAA server back to the IP for a minute so you can login. Otherwise you'll have to perform a password recovery on it.

Hope that helps.

Actions

This Discussion