cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
365
Views
0
Helpful
1
Replies

PIX Patch for PMTUD Vulnerability

slug420
Level 1
Level 1

This is in reference to the DoS vulnerability for PIXs accepting ipsec connections detailed here:

http://www.cisco.com/en/US/products/products_security_advisories_listing.html

Do you simply copy this image from tftp to run in order to upgrade? What is the command syntax? copy tftp://10.1.1.1/path/pix624-101.bin flash ?

Do you then have to reboot at your convenience or does it force a reboot?

Has anyone deployed these patches and if so have you had any trouble in doing so?

tia

1 Reply 1

gfullage
Cisco Employee
Cisco Employee

This code is just a standard PIX code interim release with bug fixes. You upgrade your existing PIX to it just like any other upgrade, in that you TFTP the code onto your PIX and then reboot it at your convenience.

There are detailed upgrade instructions here:

http://www.cisco.com/warp/public/110/upgrade.shtml

You mention the 6.2(4.101) image in your post, but if you're currently running 6.3(x) software on your PIX then I would recommend you use the 6.3(4.120) code release available from the same URL.

Review Cisco Networking for a $25 gift card