01-02-2004 01:43 PM - edited 03-02-2019 12:39 PM
Just set up new install. Having issue importing config from my PIX.
I get "failed to contact host" if I try to import from device. I can telnet and connect from my server, so my IP and enable password should be good.
If I try to import a copy/pasted config file, it says 6.3.3 is not a supported version and fails.
Is there something I need to configure on the PIX end? PIX is 6.3.3 (in failover cfg). I updated VMS 2.2 to Update 1 and I just found and downloaded Firewall update to 1.2.2.
Any ideas appreciated?
Steve
01-06-2004 04:46 PM
I am having the same problem. Reading the docs it appears that we may need to enable http on the PIX. I believe it's disabled on both of ours. I'll enable it and try it.
Quote from docs:
Enter the Contact IP address, which is the address Firewall MC uses to contact a firewall device using HTTPS. This is generally a firewall's interface address, but it might be different due to address translation between the Firewall MC server and the firewall.
Note: You should have specified this IP address for the inside interface during bootstrapping. The inside interface is the one for which you automatically enabled HTTP access using the setup command.
01-06-2004 04:50 PM
Also, I see that Firewall MC only imports configs of PIXs that are using ACLs and will not import configs that are using conduits.
01-07-2004 03:49 AM
Hi,
I've enabled HTTP... but not on the inside interface and not work!
the interface is reacheble and the https seems to work fine but, capturing the traffic from the pix I've seen that VMS try to connect but the PIX send a TCP RST...
any ideas?
Do you know if is possible manage PIX from a interface different from inside?
thanks,
Graziano
01-07-2004 07:37 AM
Good news,
I've found this information, in the PIX-MC 1.2.2 release-notes:
Troubleshooting
The following topics supplement the troubleshooting information found in Using Management Center for Firewalls 1.2.
Why does the error message "Failed to contact the device" appear when I try to import from a device?
Solaris patch 112438-01 is required for Firewall MC 1.2.2 to communicate with the device. After installing this patch, you must reboot the Solaris server.
I'll try it as soon as possible !
Bye,
Graziano
01-14-2004 07:05 AM
OK! with this patch works well!
Hope this helps all!
bye,
Graz.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide