Pelican Parts
Parts Catalog Accessories Catalog How To Articles Tech Forums
Call Pelican Parts at 888-280-7799
Shopping Cart Cart | Project List | Order Status | Help



Go Back   Pelican Parts Forums > Miscellaneous and Off Topic Forums > Off Topic Discussions


Reply
 
LinkBack Thread Tools Rate Thread
Author
Thread Post New Thread    Reply
It'll be legen-waitforit
 
stealthn's Avatar
 
Join Date: Jan 2002
Location: Calgary, Canada
Posts: 7,006
SO what was the outcome? Did you have a backup of the configuration, and a copy of the changes you made last?

A couple things in your statement confuse me; you said refusing LAN connections then you said you SSH'd into the Public IP? Can you ssh to the private IP from the LAN?

As well why would you only use a password on the public interface? (I know this doesn't help but I had to ask).

If you had HTTPs enabled on the inside interface can you get to it that way? As well, as stated, did you try the default username pass? What was the aaa method set to in the past?

Good luck, let us know

<-- CCSP working on CCIE now

__________________
Bob James
06 Cayman S - Money Penny
18 Macan GTS
Gone: 79 911SC, 83 944, 05 Cayenne Turbo, 10 Panamera Turbo
Old 01-21-2009, 07:35 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #21 (permalink)
Registered
 
Join Date: Jul 2003
Location: Glorious Pac NW
Posts: 4,184
Quote:
Originally Posted by masraum View Post
The hardest part of a console cable (assuming you don't have the blue cisco premade) is the DB9 snap adapter.
My local Rat Shack sells unmade-up DB9-RJ45 adapters, for like, $4. Pin them up anyway you want - e.g. so you can run an oddball console cable with off-the-shelf patch cables.

Just need a pin insert/extraction tool (although you can get by without one if you don't mess up assembling it)...
__________________
'77 S with '78 930 power and a few other things.
Old 01-21-2009, 08:50 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #22 (permalink)
Registered
 
mikester's Avatar
 
Join Date: Mar 2002
Location: My House
Posts: 5,345
Send a message via AIM to mikester
Quote:
Originally Posted by stealthn View Post
SO what was the outcome? Did you have a backup of the configuration, and a copy of the changes you made last?

A couple things in your statement confuse me; you said refusing LAN connections then you said you SSH'd into the Public IP? Can you ssh to the private IP from the LAN?

As well why would you only use a password on the public interface? (I know this doesn't help but I had to ask).

If you had HTTPs enabled on the inside interface can you get to it that way? As well, as stated, did you try the default username pass? What was the aaa method set to in the past?

Good luck, let us know

<-- CCSP working on CCIE now
It sounds like he's hosting some old Cisco VPN clients with this very old PIX 501. I don't believe they support many clients but I don't recall all the licensing options from them. The 501s have been end of life and end of support for at least 3 years now (since the 7.0 code was released). If he's hosting VPN and maybe a website or two - he should only be allowing those protocols inbound on the outside interface.

This would not affect any outbound traffic like web browsing and so forth as that comes from the inside interface to the outside. The inside interface has a higher security level than the outside so traffic (unless otherwise denied by an inbound ACL) is by default permitted in that direction.

SSH access to the outside - ideally - should not be allowed from the public internet (also I believe that the old 6.x code may not support more than SSHv1 which is not bad but not great. In less than ideal circumstances SSH access from the outside should be protected by more than just the enable password. At the very least a local user should be configured. Better would be a tacacs server but we're talking less than ideal situations here.

I'm not criticizing so please don't take it that way, I know that ultimately it comes down to money. I have worked for companies that you would not believe were unwilling to spend a dime on the network yet had expectations that were sky high. Unreal - seriously. If management won't spend the money then you end up with less than ideal circumstances and it is so easy to get there.

Feel free to pick my brain on the PIX configuration or routing or switching or wireless for that matter.

A few years back I tried to get the CCSP, I passed all the tests except the IDS test. This was when the 4 code was still in use and being tested on (if memory serves). After 3 attempts (at the time something like $125 a pop) at that one test I gave up.

I will never take another CCxP level exam again. I will only take CCIE level exams which keep my current certs online and hopefully advance my career potential. I'm hoping to take the R&S lab around april when I will be going to one of those 5 day boot camps (for free).
__________________
-The Mikester

I heart Boobies

Last edited by mikester; 01-21-2009 at 09:11 PM..
Old 01-21-2009, 09:08 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #23 (permalink)
Registered
 
mikester's Avatar
 
Join Date: Mar 2002
Location: My House
Posts: 5,345
Send a message via AIM to mikester
no update?

__________________
-The Mikester

I heart Boobies
Old 01-22-2009, 10:18 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #24 (permalink)
Reply


 


All times are GMT -8. The time now is 06:29 AM.


 
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website -    DMCA Registered Agent Contact Page
 

DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.