12-07-2006 08:00 AM - edited 03-11-2019 02:05 AM
Suppose that I have royally messed up my running and start-up configs:
Since configure net merges a tftp backup with the running config, I think this would make things worse.
From a console connection, I can
1. execute write erase, reload.
2. configure inside interface and route to tftp server.
3. execute configure net <tftp>:<cfg.file>
4. write mem
This appears to work, but I will need console access or potentially talk an onsite person through this.
Can anyone tell me of a more direct way to restore the start-up config?
Thanks.
12-07-2006 11:36 AM
No answer, but I'm eager to see if someone has a solution that will work for me as well. I'm running into a similar problem where I can edit the firewall context config files on my 6509's FWSM by tftp'ing them over to a server, editing them there, and tftp'ing them back. Problem is, once I get them there, there's no way to merge them with the running config.
"copy start run" generates the error message "Command not valid in current execution space". The reload command doesn't appear in the individual contexts, and I can't afford to restart the entire FWSM and shut down the hundreds of Mbps of client traffic that flows through it any time any single client needs a config update that requires this form of editing.
I suppose I should start my own thread so I can hand out rating points if anyone has the answer.
12-07-2006 06:10 PM
Try this method, for ASA 7.2:
- To copy from a TFTP server:
hostname# copy tftp://server[/path]/filename {startup-config | running-config}
i.e:
hostname# copy tftp://10.1.1.10/startup-config.cfg startup-config
- To copy from an FTP server:
hostname# copy ftp://[user[:password]@]server[/path]/filename {startup-config | running-config}
i.e:
hostname# copy ftp://admin password @10.1.1.10/startup-config.cfg startup-config
Check the status using "sh start".
You can also copy them to running config, verify, then saved as startup config:
viaTFTP -> hostname# copy tftp://10.1.1.10/startup-config.cfg running-config
via FTP -> hostname# copy ftp://admin password @10.1.1.10/startup-config.cfg running-config
I believed you can use the same method for multiple security context, or load (from tftp/ftp server) individual context configuration from the context itself
HTH
AK
12-07-2006 06:25 PM
Specific for PIX6.3, try:
tftp-server 10.1.1.10 startup-config
configure net :
Then view the loaded config file. Copy it to running config as well.
- configure net
The configure net command merges the current running configuration with a TFTP configuration stored at the IP address you specify and from the file you name. If you specify both the IP address and path name in the tftp-server command, you can specify server_ip :filename as simply a colon ( : ).
HTH
AK
12-08-2006 12:18 PM
AK,
I do not understand:
"The configure net command
Suppose either inadvertently or maliciously someone has inserted "network-object 0.0.0.0 0.0.0.0" into object-group network Trusted.
Does this not remain in the running config after merging in good back up from the tftp server?
If so, has does one efficiently restore to the last known good config?
Thanks, Steve
12-26-2006 03:35 PM
I'm having the same challenge copying my old running-config to the startup config of the nex 515e.
I read some of the options people have mentioned and theory is great, but those options simply do not exist.
The best I have been able to do is merge my old configuration to the new configuration.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide