Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

ASDM vulnerability concern

Hello;

I'm contimplating on using ASDM as a tool to monitor my PIX 525 in terms of VPN trhoughput, interface stats and perform the security check, all of which the asdm program offers.

Currently I prefer to use the CLI to implement change, and I will continue this practive.

My question is "Should I be concerned if I enable http inside 192.168.1.0 255.255.255.0 so that I can access the installed asdm application?" Are there any security concerns? I'm thinking as long as I specify the host that will be used to access the PIX, I should be okay.

Your feedback is apreciated.

Regards

Jeff

1 ACCEPTED SOLUTION

Accepted Solutions
Cisco Employee

Re: ASDM vulnerability concern

8 REPLIES
Cisco Employee

Re: ASDM vulnerability concern

rather than making it for the entire subnet why dont you make it specific to few hosts..till the time you have your enable credentials safe..you are safe as well..:-)

Community Member

Re: ASDM vulnerability concern

Hi, yes good idea.

Now I'm thinking will asdm use my tacacs service. If not, I need to find out how to configure.

Regards

Jeff

Cisco Employee

Re: ASDM vulnerability concern

you mean you have a TACACS Server configured ?..if yes then you can get ASDM authenticated via TACACS as well

Community Member

Re: ASDM vulnerability concern

Hi,

Yes I currently use tacacs server. Changed config is below:

I need to fond out if this config will use tacacs without any additional commands. I would think I would need to specify the authentication such as https. still digging on this issue. Thanks for the feedback,

aaa-server RADIUS protocol radius

aaa-server ABCACS protocol tacacs+

aaa-server ABCACS host 192.168.100.1

key guessme

aaa authentication ssh console ABCACS

aaa authentication enable console ABCACS

Cisco Employee

Re: ASDM vulnerability concern

add one more command for ASDM auth

aaa authentication http console ABACS

In this case you are not using the fall back mechanism that means if TACACS server is down ..then you would be completely locked

Community Member

Re: ASDM vulnerability concern

Hi;

Currently if tacacs is down, my local account can be accessed via ssh or console by using the default ?pix? local account.

Are you saying if I include ?aaa authentication http console ABCACS?, I will not be able ssh into my PIX not even bby using the local ?pix? account? I?m a little confused. All configuration changes will be made from either my console or ssh session. ASDM will be used only for monitoring, but I want to authenticate with my tacacs server when I access my PIX via http as well as ssh and console.

Best Regards

Jeff

Cisco Employee

Re: ASDM vulnerability concern

yes you dont have a fallback configured that means that if your TACACS server is unreachable then you would not be able to access the firewall using ssh or console

to configure fallback to the local database try this :-

aaa authentication ssh console ABACS local

Cisco Employee

Re: ASDM vulnerability concern

220
Views
0
Helpful
8
Replies
CreatePlease to create content