Need to pw reset PIX 501. How are all the wires supposed to be connected?

JediFonger

2[H]4U
Joined
Jan 2, 2003
Messages
2,777
hey ya'll,

I'm an admin@a small network. We have a older Cisco PIX 501 that hadn't been used yet. The FW's just been sitting there. No one knows the PW. The only way to reset it is with the blue serial console cable. Yes I'm aware of all these resources:

http://www.cisco.com/en/US/products...ducts_password_recovery09186a008009478b.shtml

http://www.experts-exchange.com/Security/Firewalls/Q_21244026.html

http://www.tech-recipes.com/cisco_firewall_tips639.html

I'm using Tera Term as the terminal, com1 is enabled and I can communicate with the PIX no problem. I can boot into the monitor> CLI. I'm also using the Solarwind TFTP server. I've tried following all of the directions but I can't reset the pw cause I'm unable to ping the firewall and the tftp server from the monitor> CLI.

Settings:
-PIX's internal IP is 192.168.1.1 (same ole', same ole'), gateway's the same. external IP&config is configured to a static IP on internet.
-PC's ethernet address is 192.168.1.2, gateway 192.168.1.1. i've tried using to do it through the external connection using diff set of IPs similar to the external IP configs, but that didn't work either. i was trying to replicate what the cisco instructions said, but can't ping anything.

Here are the combos of how I've connected all of the components.

combo#1:
-PC to PIX via blue serial console cable ONLY.

combo#2:
-PC to PIX via console cable
-PC's ethernet to PIX's internal ethernet (tried crossover cables as well)

combo#3:
-PC to PIX via console cable
-PC's ethernet to PIX's external ethernet (tried crossover cables as well)

questions:
1. how am i supposed to physically connect all of the components for a pw reset.
2. looking at the solarwind tftp server's help files, it looks like the status screen is supposed to say it's getting info from the gateway:
image003.gif

i'm not getting anything. the same screen is blank. The reset bin file location is correct, i already set it to send/receive, the IP address is correct.
3. am i supposed to be able to ping the fw's IP for eth0 and the tftp server's IP from the monitor>? the instructions say i should be able to before transferring the bin file.
4. when in monitor> mode i can use window's command prompt to ping 192.168.1.2 but not 192.168.1.1. if i can't do so in windows, how can i do it via PIX console's CLI?

i'm stuck. any suggestions?
 
Do you ever get link lights on the PC or PIX when hooking up the ethernet cables?
 
yes. if i get out of monitor> CLI mode into firewall> CLI mode, i can use window's cmd to ping 192.168.1.1 and 192.168.1.2.

all lights are working, the network works... just a bit strange. how's my physical setup? i'm more worried about that because the directions above don't really specify how i should connect to the PIX physically.
 
In monitor mode, you don't get link lights? I'd say that's the problem.

You may need to assign the NIC an IP and up the interface, but I'd think the directions would cover that if needed. I'd say setup #2 sounds best (the internal NIC will have lower security settings in normal firewall mode, and will allow you access to it.. I'm not sure if that changes in monitor mode)
 
all the lights are working. i've assigned the internal NIC IPs, still no ping from monitor> CLI from either.
 
it's working now, i did the SAME EXACT thing yesterday and dunno why it didn't work!

here are the exact steps:
1. connect blue console (serial) from PC to PIX.
2. connect crossover cable from PC's ethernet to PIX's internet ethernet.
3. connect a cat5 cable from PIX's external to any network device to get a link light on the PIX. i connected it to an empty switch.
4. make sure PC's IP address is 192.168.1.2 w/255.255.255.0 sub and 192.168.1.1 gateway.
5. fired up tera term and connect to com1 serial to PIX. did the whole esc/send break.
6. typed address 192.168.1.1
7. typed server 192.168.1.2
8. typed file np63.bin
9. fired up tftp server
10. typed tftp
11. the solarwind's dialogue box gave me a ton of timeouts, but the file uploaded regardless and i was able to reset pw!!! YEE HA!
 
Back
Top