<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX PDM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-pdm/m-p/1990968#M401487</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;im sort of at my wits end, ive spent most of the after noon trying to work this out - I got hold of an old pix 501, running following: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hardware:&amp;nbsp;&amp;nbsp; PIX-501, 16 MB RAM, CPU Am5x86 133 MHz&lt;/P&gt;&lt;P&gt;Flash E28F640J3 @ 0x3000000, 8MB&lt;/P&gt;&lt;P&gt;BIOS Flash E28F640J3 @ 0xfffd8000, 128KB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;0: ethernet0: address is 001d.4521.a06f, irq 9&lt;/P&gt;&lt;P&gt;1: ethernet1: address is 001d.4521.a070, irq 10&lt;/P&gt;&lt;P&gt;Licensed Features:&lt;/P&gt;&lt;P&gt;Failover:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Disabled&lt;/P&gt;&lt;P&gt;VPN-DES:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enabled&lt;/P&gt;&lt;P&gt;VPN-3DES-AES:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enabled&lt;/P&gt;&lt;P&gt;Maximum Physical Interfaces: 2&lt;/P&gt;&lt;P&gt;Maximum Interfaces:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&lt;/P&gt;&lt;P&gt;Cut-through Proxy:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enabled&lt;/P&gt;&lt;P&gt;Guards:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enabled&lt;/P&gt;&lt;P&gt;URL-filtering:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enabled&lt;/P&gt;&lt;P&gt;Inside Hosts:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10&lt;/P&gt;&lt;P&gt;Throughput:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Unlimited&lt;/P&gt;&lt;P&gt;IKE peers:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This PIX has a Restricted (R) license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Serial Number: 907381129 (0x36158989)&lt;/P&gt;&lt;P&gt;Running Activation Key: 0x6e9eef0d 0x39fc65c5 0x12491b66 0x1be8afaf&lt;/P&gt;&lt;P&gt;Configuration has not been modified since last system restart.&lt;/P&gt;&lt;P&gt;192.168.1.1#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everytime i try and start the PDM, i get the error that there is a hostname mismatch with certificates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now i've tried the following: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) 5 differant versions of java, from 1.5 and under.&lt;/P&gt;&lt;P&gt;2) Tried delating the key on the router and re-createing it.&lt;/P&gt;&lt;P&gt;Ive been all over the internet checking out lots of other people who had this problem and it seems to relate to java or the cetificates, but i still cant get this working...has anyone got any suggestions ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im not a company so dont have a CCO login to maybe uprage the IOS and PDM...I'm more than happy to try and configure things via command line...i just cant stand it when i cant work out why its not working.....&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 23:35:53 GMT</pubDate>
    <dc:creator>andymorph</dc:creator>
    <dc:date>2019-03-11T23:35:53Z</dc:date>
    <item>
      <title>PIX PDM</title>
      <link>https://community.cisco.com/t5/network-security/pix-pdm/m-p/1990968#M401487</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;im sort of at my wits end, ive spent most of the after noon trying to work this out - I got hold of an old pix 501, running following: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hardware:&amp;nbsp;&amp;nbsp; PIX-501, 16 MB RAM, CPU Am5x86 133 MHz&lt;/P&gt;&lt;P&gt;Flash E28F640J3 @ 0x3000000, 8MB&lt;/P&gt;&lt;P&gt;BIOS Flash E28F640J3 @ 0xfffd8000, 128KB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;0: ethernet0: address is 001d.4521.a06f, irq 9&lt;/P&gt;&lt;P&gt;1: ethernet1: address is 001d.4521.a070, irq 10&lt;/P&gt;&lt;P&gt;Licensed Features:&lt;/P&gt;&lt;P&gt;Failover:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Disabled&lt;/P&gt;&lt;P&gt;VPN-DES:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enabled&lt;/P&gt;&lt;P&gt;VPN-3DES-AES:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enabled&lt;/P&gt;&lt;P&gt;Maximum Physical Interfaces: 2&lt;/P&gt;&lt;P&gt;Maximum Interfaces:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&lt;/P&gt;&lt;P&gt;Cut-through Proxy:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enabled&lt;/P&gt;&lt;P&gt;Guards:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enabled&lt;/P&gt;&lt;P&gt;URL-filtering:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enabled&lt;/P&gt;&lt;P&gt;Inside Hosts:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10&lt;/P&gt;&lt;P&gt;Throughput:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Unlimited&lt;/P&gt;&lt;P&gt;IKE peers:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This PIX has a Restricted (R) license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Serial Number: 907381129 (0x36158989)&lt;/P&gt;&lt;P&gt;Running Activation Key: 0x6e9eef0d 0x39fc65c5 0x12491b66 0x1be8afaf&lt;/P&gt;&lt;P&gt;Configuration has not been modified since last system restart.&lt;/P&gt;&lt;P&gt;192.168.1.1#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everytime i try and start the PDM, i get the error that there is a hostname mismatch with certificates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now i've tried the following: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) 5 differant versions of java, from 1.5 and under.&lt;/P&gt;&lt;P&gt;2) Tried delating the key on the router and re-createing it.&lt;/P&gt;&lt;P&gt;Ive been all over the internet checking out lots of other people who had this problem and it seems to relate to java or the cetificates, but i still cant get this working...has anyone got any suggestions ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im not a company so dont have a CCO login to maybe uprage the IOS and PDM...I'm more than happy to try and configure things via command line...i just cant stand it when i cant work out why its not working.....&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:35:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-pdm/m-p/1990968#M401487</guid>
      <dc:creator>andymorph</dc:creator>
      <dc:date>2019-03-11T23:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: PIX PDM</title>
      <link>https://community.cisco.com/t5/network-security/pix-pdm/m-p/1990969#M401488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bro&lt;/P&gt;&lt;P&gt;As long as your config looks like this, this is not a FW problem. Perhaps, it could be your PC. Have you tried with another PC, to see if this works fine? I suspect this has something to do with your browser's cookies etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asdm image flash:/asdm&lt;BR /&gt;asdm history enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;http server enable&lt;BR /&gt;http 10.0.0.0 255.0.0.0 inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;domain-name cisco.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname FW01&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Try this as well;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ca zeroize rsa&lt;/P&gt;&lt;P&gt;ca generate rsa key 768 &amp;lt;-- 1024 and above seems to have compatiblity issue with some browsers.&lt;/P&gt;&lt;P&gt;ca save all &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2012 03:56:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-pdm/m-p/1990969#M401488</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2012-07-30T03:56:10Z</dc:date>
    </item>
    <item>
      <title>Re: PIX PDM</title>
      <link>https://community.cisco.com/t5/network-security/pix-pdm/m-p/1990970#M401489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The error-message in question comes when you connect to your pix with a different hostname then what is in the certificate. If you only have the IP-address in the certificate, then you have to use &lt;A href="https://1.2.3.4" target="_blank"&gt;https://1.2.3.4&lt;/A&gt;. If you have used a hostname or FQDN, then you have to use that: &lt;A href="https://pixfirewall" target="_blank"&gt;https://pixfirewall&lt;/A&gt; or &lt;A href="https://pixfirewall.yourdomain.local" target="_blank"&gt;https://pixfirewall.yourdomain.local&lt;/A&gt;. Just change the IP or the names to what you have on your PIX. If you have a name in your certificate you also need to make sure that the name resolves to the correct IP-address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you don't know what's in the certificate, I think the command on this plattform was also "show crypto ca certificate". There you need to look at the field "subject".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2012 06:28:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-pdm/m-p/1990970#M401489</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2012-07-30T06:28:26Z</dc:date>
    </item>
  </channel>
</rss>

