<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 515E: Configuration Errors at Boot Up in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515e-configuration-errors-at-boot-up/m-p/1449375#M766091</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE class="notpretty" id="codeSnippet732464"&gt;*** Output from config line 493, "nat (inside) 1 192.168.4..."&lt;BR /&gt;WARNING: Binding inside nat statement to outermost interface.&lt;BR /&gt;WARNING: Keyword "outside" is probably missing.&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe your inside interface is configured with security level 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can configure it with security level 100, but then, if you say it is working for now, you have to understand the impact to traffic flow when you change the security level of an interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Depending on what version of&amp;nbsp; code you are running :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for version 6.x , you will have to do something like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"nameif e1 inside sec 100"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;documentation here :&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/mr.html#wp1026054"&gt;http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/mr.html#wp1026054&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for 7.x and later&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface e1&lt;/P&gt;&lt;P&gt;nameif inside&lt;/P&gt;&lt;P&gt;sec 100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;documentation here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa70/configuration/guide/intparam.html#wp1051819"&gt;http://www.cisco.com/en/US/docs/security/asa/asa70/configuration/guide/intparam.html#wp1051819&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE class="notpretty" id="codeSnippet732464"&gt;*** Output from config line 498, "nat (inside) 1 192.168.9..."&lt;BR /&gt;........WARNING: crypto map has incomplete entries&lt;BR /&gt;&lt;BR /&gt;This suggest you have incomplete ipsec vpn configuration.&lt;BR /&gt;If you do not use ipsec vpn, you can look for the command that binds &lt;BR /&gt;the crypto map to the outide interface, and issue a no in front of that command.&lt;BR /&gt;&lt;BR /&gt;example :&lt;BR /&gt;no crypto map nameofmap interface outside&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;If you include the complete configuration and all the errors, we can possible clean it up more.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 19 Jun 2010 02:48:02 GMT</pubDate>
    <dc:creator>edadios</dc:creator>
    <dc:date>2010-06-19T02:48:02Z</dc:date>
    <item>
      <title>PIX 515E: Configuration Errors at Boot Up</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-configuration-errors-at-boot-up/m-p/1449374#M766074</link>
      <description>&lt;P&gt;&lt;SPAN class="value"&gt;&lt;SPAN class="pBody postableBody"&gt;Hello!&lt;BR /&gt;&lt;BR /&gt;We've&amp;nbsp; purchased a used Cisco PIX 515E firewall that we are using to replace a&amp;nbsp; previous firewall of the same model. I have successfully copied the&amp;nbsp; configuration from the old unit to the new via TFTP. Everything appears&amp;nbsp; to be working normally, except that on boot-up, there are several errors&amp;nbsp; displayed. There are about a dozen of them, but all fall into one of&amp;nbsp; two categories. Either they reference keyword "outside" as "probably&amp;nbsp; missing" or they say "crypto map" has "incomplete entries". Samples of&amp;nbsp; each type are posted below.&lt;BR /&gt;&lt;BR /&gt;Can someone point me in the right&amp;nbsp; direction as to what these errors mean and how to correct them?&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;BR /&gt;&lt;BR /&gt;-&amp;nbsp; Tom&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE class="notpretty" id="codeSnippet732464"&gt;EXAMPLE 1:&lt;BR /&gt;&lt;BR /&gt;*** Output from config line 493, "nat (inside) 1 192.168.4..."&lt;BR /&gt;WARNING: Binding inside nat statement to outermost interface.&lt;BR /&gt;WARNING: Keyword "outside" is probably missing.&lt;BR /&gt;&lt;BR /&gt;EXAMPLE 2:&lt;BR /&gt;&lt;BR /&gt;*** Output from config line 498, "nat (inside) 1 192.168.9..."&lt;BR /&gt;........WARNING: crypto map has incomplete entries&lt;BR /&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:01:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-configuration-errors-at-boot-up/m-p/1449374#M766074</guid>
      <dc:creator>easyadstom</dc:creator>
      <dc:date>2019-03-11T18:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515E: Configuration Errors at Boot Up</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-configuration-errors-at-boot-up/m-p/1449375#M766091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE class="notpretty" id="codeSnippet732464"&gt;*** Output from config line 493, "nat (inside) 1 192.168.4..."&lt;BR /&gt;WARNING: Binding inside nat statement to outermost interface.&lt;BR /&gt;WARNING: Keyword "outside" is probably missing.&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe your inside interface is configured with security level 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can configure it with security level 100, but then, if you say it is working for now, you have to understand the impact to traffic flow when you change the security level of an interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Depending on what version of&amp;nbsp; code you are running :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for version 6.x , you will have to do something like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"nameif e1 inside sec 100"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;documentation here :&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/mr.html#wp1026054"&gt;http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/mr.html#wp1026054&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for 7.x and later&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface e1&lt;/P&gt;&lt;P&gt;nameif inside&lt;/P&gt;&lt;P&gt;sec 100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;documentation here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa70/configuration/guide/intparam.html#wp1051819"&gt;http://www.cisco.com/en/US/docs/security/asa/asa70/configuration/guide/intparam.html#wp1051819&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE class="notpretty" id="codeSnippet732464"&gt;*** Output from config line 498, "nat (inside) 1 192.168.9..."&lt;BR /&gt;........WARNING: crypto map has incomplete entries&lt;BR /&gt;&lt;BR /&gt;This suggest you have incomplete ipsec vpn configuration.&lt;BR /&gt;If you do not use ipsec vpn, you can look for the command that binds &lt;BR /&gt;the crypto map to the outide interface, and issue a no in front of that command.&lt;BR /&gt;&lt;BR /&gt;example :&lt;BR /&gt;no crypto map nameofmap interface outside&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;If you include the complete configuration and all the errors, we can possible clean it up more.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jun 2010 02:48:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-configuration-errors-at-boot-up/m-p/1449375#M766091</guid>
      <dc:creator>edadios</dc:creator>
      <dc:date>2010-06-19T02:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515E: Configuration Errors at Boot Up</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-configuration-errors-at-boot-up/m-p/1449376#M766099</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks! I checked and the "inside" interface is indeed set to a security of 100. Here's the output of "show nameif" at the "configure terminal" prompt:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __default_attr="plain" __jive_macro_name="code" class="jive_text_macro jive_macro_code"&gt;&lt;P&gt;Ethernet0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;Ethernet1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 100&lt;BR /&gt;Ethernet2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; intf2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding the VPN, a VPN has been used on our network in the past, but is not presently used, so disabling that command would be fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm happy to post the complete configuration, though it is rather massive in size. Not sure what the proper protocol is here for posting large amounts of text, so I'm attaching it as a text file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lastly, here is the complete set of error messages:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __default_attr="plain" __jive_macro_name="code" class="jive_text_macro jive_macro_code"&gt;...........WARNING: Enabling the logging ftp-bufferwrap feature could cause a&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; depletion of all available memory under high syslog&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; rates. Please adjust your buffered logging level&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; appropriately&lt;BR /&gt;*** Output from config line 390, "logging ftp-bufferwrap"&lt;BR /&gt;..WARNING: Binding inside nat statement to outermost interface.&lt;BR /&gt;WARNING: Keyword "outside" is probably missing.&lt;BR /&gt;*** Output from config line 490, "nat (outside) 1 192.168...."&lt;BR /&gt;WARNING: Binding inside nat statement to outermost interface.&lt;BR /&gt;WARNING: Keyword "outside" is probably missing.&lt;BR /&gt;*** Output from config line 491, "nat (outside) 1 192.168...."&lt;BR /&gt;WARNING: Binding inside nat statement to outermost interface.&lt;BR /&gt;WARNING: Keyword "outside" is probably missing.&lt;BR /&gt;*** Output from config line 492, "nat (outside) 1 192.168...."&lt;BR /&gt;WARNING: Binding inside nat statement to outermost interface.&lt;BR /&gt;WARNING: Keyword "outside" is probably missing.&lt;BR /&gt;*** Output from config line 493, "nat (outside) 1 192.168...."&lt;BR /&gt;WARNING: Binding inside nat statement to outermost interface.&lt;BR /&gt;WARNING: Keyword "outside" is probably missing.&lt;BR /&gt;*** Output from config line 494, "nat (outside) 1 192.168...."&lt;BR /&gt;WARNING: Binding inside nat statement to outermost interface.&lt;BR /&gt;WARNING: Keyword "outside" is probably missing.&lt;BR /&gt;*** Output from config line 495, "nat (outside) 1 192.168...."&lt;BR /&gt;WARNING: Binding inside nat statement to outermost interface.&lt;BR /&gt;WARNING: Keyword "outside" is probably missing.&lt;BR /&gt;*** Output from config line 496, "nat (outside) 1 192.168...."&lt;BR /&gt;WARNING: Binding inside nat statement to outermost interface.&lt;BR /&gt;WARNING: Keyword "outside" is probably missing.&lt;BR /&gt;*** Output from config line 497, "nat (outside) 1 192.168...."&lt;BR /&gt;.WARNING: Binding inside nat statement to outermost interface.&lt;BR /&gt;WARNING: Keyword "outside" is probably missing.&lt;BR /&gt;*** Output from config line 498, "nat (outside) 1 192.168...."&lt;BR /&gt;.......WARNING: crypto map has incomplete entries&lt;BR /&gt;*** Output from config line 684, "crypto map outside_map i..."&lt;BR /&gt;WARNING: crypto map has incomplete entries&lt;BR /&gt;*** Output from config line 686, "crypto map inside_map in..."&lt;BR /&gt;.&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jun 2010 03:12:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-configuration-errors-at-boot-up/m-p/1449376#M766099</guid>
      <dc:creator>easyadstom</dc:creator>
      <dc:date>2010-06-19T03:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515E: Configuration Errors at Boot Up</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-configuration-errors-at-boot-up/m-p/1449377#M766120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All your NAT and static commands are wrong. I am not sure how you say things work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All your "nat (outside)" should instead be "nat (inside)"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All your "static (outside,inside)" should have been "static (inside,outside)"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will have copy them all to notepad. put "no" in front of each to remove them, then correct each one of them and paste the corrected lines.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no nat (outside) 1 192.168.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (inside) 1 192.168.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the statics, do the same&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no static (outside,inside) tcp x.x.xxx.xxx https XXXX https netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp x.x.xxx.xxx https XXXX https netmask&amp;nbsp; 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To remove the crypto config you can do :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clear config crypto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clear config isakmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jun 2010 04:19:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-configuration-errors-at-boot-up/m-p/1449377#M766120</guid>
      <dc:creator>edadios</dc:creator>
      <dc:date>2010-06-19T04:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515E: Configuration Errors at Boot Up</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-configuration-errors-at-boot-up/m-p/1449378#M766130</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much for your help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once I realized that the "inside" and "outside" designations had somehow become transposed, I re-transferred the configuration from the old unit. It correctly transferred with the interfaces set correctly. I must have messed something up the first time around. The firewall is now working normally.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks again!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jun 2010 16:41:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-configuration-errors-at-boot-up/m-p/1449378#M766130</guid>
      <dc:creator>easyadstom</dc:creator>
      <dc:date>2010-06-23T16:41:15Z</dc:date>
    </item>
  </channel>
</rss>

