<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 515E: Can't Get Inside Interface Working During Setup in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515e-can-t-get-inside-interface-working-during-setup/m-p/1478465#M641017</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No route to host normally means that you don't have route towards the TFTP server.&lt;/P&gt;&lt;P&gt;What is the ip address of the interface that you configured? Also, please make sure that you configure "nameif" and security level for the interfaces, otherwise, it will not work.&lt;/P&gt;&lt;P&gt;Please post the current config and also what is the TFTP server ip address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 24 Jun 2010 04:42:50 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2010-06-24T04:42:50Z</dc:date>
    <item>
      <title>PIX 515E: Can't Get Inside Interface Working During Setup</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-can-t-get-inside-interface-working-during-setup/m-p/1478464#M641008</link>
      <description>&lt;P&gt;Hi folks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got a freshly formatted Cisco PIX 515E firewall that I am trying to configure with the proper boot image. When it boots, I can escape into the monitor mode, set the IP address, and download the boot image (pix804.bin) from the TFTP server. I can then boot into the firewall. However, that's as far as I can get.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My next step has been to try to configure the IP address of the appropriate interface and download the image from the TFTP server again in regular console mode so that it can be saved to flash. However, when I attempt to configure the exact same interface with the exact same IP as I used in the monitor mode, I get no network connectivity. I cannot reach the TFTP server, and any ping attempts return "No route to host."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts on what I might be doing wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Tom&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:02:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-can-t-get-inside-interface-working-during-setup/m-p/1478464#M641008</guid>
      <dc:creator>easyadstom</dc:creator>
      <dc:date>2019-03-11T18:02:59Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515E: Can't Get Inside Interface Working During Setup</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-can-t-get-inside-interface-working-during-setup/m-p/1478465#M641017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No route to host normally means that you don't have route towards the TFTP server.&lt;/P&gt;&lt;P&gt;What is the ip address of the interface that you configured? Also, please make sure that you configure "nameif" and security level for the interfaces, otherwise, it will not work.&lt;/P&gt;&lt;P&gt;Please post the current config and also what is the TFTP server ip address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jun 2010 04:42:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-can-t-get-inside-interface-working-during-setup/m-p/1478465#M641017</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-24T04:42:50Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515E: Can't Get Inside Interface Working During Setup</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-can-t-get-inside-interface-working-during-setup/m-p/1478466#M641028</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, this is interesting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I use "nameif" to give the interface a name and security level, and then do a "show interface" command, it says "IP address unassigned." If I try to do an "ip address" command at the prompt to assign an IP address, it accepts it, but still says "IP address unassigned" in the "show interface" output. No IP address I try to enter will "take."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I undo the nameif command by doing a "no nameif," then all of a sudden the IP address re-appears in the configuration, and I'm back to the "no route to host" error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The address I'm trying to configure on the inside interface is 192.168.0.3, which works when I use that address from the "monitor&amp;gt;" prompt.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the current "show config" output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: Written by enable_15 at 00:48:30.190 UTC Thu Jun 24 2010&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX Version 8.0(4)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname ez2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;domain-name prestige.local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;enable password xxx encrypted&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;passwd xxx encrypted&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; ip address 192.168.0.3 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; domain-name prestige.local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime seconds 28800&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jun 2010 05:00:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-can-t-get-inside-interface-working-during-setup/m-p/1478466#M641028</guid>
      <dc:creator>easyadstom</dc:creator>
      <dc:date>2010-06-24T05:00:19Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515E: Can't Get Inside Interface Working During Setup</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-can-t-get-inside-interface-working-during-setup/m-p/1478467#M641032</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Interface configuration looks ok.&lt;/P&gt;&lt;P&gt;Can you please reconfigure the interface with ip address, nameif and security level, and see if you can ping the TFTP server? Assuming the TFTP server is in the same subnet as the inside interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jun 2010 05:10:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-can-t-get-inside-interface-working-during-setup/m-p/1478467#M641032</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-24T05:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515E: Can't Get Inside Interface Working During Setup</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-can-t-get-inside-interface-working-during-setup/m-p/1478468#M641037</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For anyone else googling to find an answer for this problem: I was trying to configure a failover only unit and had the same problem.&amp;nbsp; I had to finish configuring all the failover settings, then force a failover so the interfaces would go active.&amp;nbsp; Once this was finished I was able to do TFTP on the interface that was previously having a problem with the IP address:&amp;nbsp; Do a SH VER and see if you are working with a failover unit.&amp;nbsp; Can't tell from the outside of the case.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Feb 2011 15:58:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-can-t-get-inside-interface-working-during-setup/m-p/1478468#M641037</guid>
      <dc:creator>dbutts</dc:creator>
      <dc:date>2011-02-08T15:58:24Z</dc:date>
    </item>
  </channel>
</rss>

