cc/td/doc/product/iaabu/pix/pix_v52
hometocprevnextglossaryfeedbacksearchhelp
PDF

Table of Contents

Introduction

Introduction

The Cisco Secure PIX Firewall ships ready to power on and configure. The configuration in the Flash memory lets the PIX Firewall start up, but it does not permit traffic to pass through the network until you configure it to do so. Installing the PIX Firewall consists of unpacking the unit, placing it in a safe place, installing any optional hardware, optionally mounting it in an equipment rack, connecting the network cables, and powering on the unit.

This guide describes how to add hardware upgrades and install optional PIX Firewall software that accompanies the unit. The information in this guide applies to all current and previous models of the PIX Firewall including the PIX 506, PIX 510, PIX 515, PIX 520, PIX 525, PIX10000, and the PIX Firewall. In this guide, the term "PIX Firewall" refers to all models unless specifically noted.

This chapter includes the following sections:

Hardware and Software Requirements

This section includes the following topics, which describe the PIX Firewall requirements by version:

Version 5.2

The following requirements and restrictions apply:

  http://www.cisco.com/kobayashi/sw-center/internet/pix-56bit.shtml

Before installing this version, save your configuration and write down your activation key and serial number. Refer to "Installation Enhancement" for new installation requirements.

This section includes the following topics:

Failover Serial Connection

The failover serial connection has been increased from 9600 baud to 117,760 baud (115K). The maximum supported length for the failover serial cable is 6 feet.


Note   Use the failover cable that is shipped with the PIX Firewall unit. If you use a replacement cable, it must have the same specifications as the supplied cable (length, type, and pinouts).

Inside and Outside Port Restriction Change

With the 5.2 software release, there are no longer restrictions on having to use specific Ethernet ports as the inside and outside network ports. Any port, whether fixed or a PCI expansion port, and any interface type, FDDI, Token Ring, Fast Ethernet, or Gigabit Ethernet, can be assigned to be the inside or outside network port.

This revision does not change the rules for port numbering. Refer to "Installing a PIX Firewall" for a description of how ports are numbered for the different PIX Firewall models.

For more information about configuring the inside and outside networks, see the Release Notes for the Cisco Secure PIX Firewall Version 5.2(1), and the Configuration Guide for the Cisco Secure PIX Firewall Version 5.2.

Installation Enhancement

PIX Firewall version 5.1 or higher now provides a software image larger than the size of a diskette. For PIX Firewall units that use a diskette to load the software, you now need to create a Boothelper diskette to start the installation, and then obtain the full image from a TFTP server. You will need your PIX Firewall activation key to complete the installation procedure. If you are upgrading from version 4, you must have obtained a new activation key to enable the VPN features in version 5.1 or higher. For details on how to use the Boothelper diskette and how to download and use a TFTP server, see "Before You Begin the Installation" in "Installing a PIX Firewall."

Version 5.1

The following requirements and restrictions apply:

  The PIX 506 does not support failover or user upgradeable boards or memory; therefore, the PIX 506 chassis should not be opened. The PIX 506 is designed to be used on a flat surface and not rack mounted.
  http://www.cisco.com/kobayashi/sw-center/internet/pix-56bit.shtml

Installation Enhancement

PIX Firewall version 5.1 or higher now provides a software image larger than the size of a diskette. For PIX Firewall units that use a diskette to load the software, you now need to create a Boothelper diskette to start the installation, and then obtain the full image from a TFTP server. You will need your PIX Firewall activation key to complete the installation procedure. If you are upgrading from version 4, you must have obtained a new activation key to enable the VPN features in version 5.1 or higher. For details on how to use the Boothelper diskette and how to download and use a TFTP server, see "Before You Begin the Installation" in "Installing a PIX Firewall."

Version 5.0

The following requirements and restrictions apply:

  The PIX 515 does not have a diskette drive and requires you to have a TFTP server to provide the image to the PIX 515 via TFTP (Trivial File Transfer Protocol). In addition, you need to store the PIX Firewall binary image on the computer on which you will run the TFTP server.
  You can download a free TFTP server from Cisco at the following site:
  http://www.cisco.com/pcgi-bin/tablebuild.pl/tftp
  You can get the most current PIX Firewall image from the following site:
  http://www.cisco.com/pcgi-bin/tablebuild.pl/pix
  When the PIX 515 starts, you can access boot mode by pressing the Esc key. You can then use TFTP to download the binary image to your PIX 515.

In version 5.0, the maximum configuration size is 350 KB regardless of the size of Flash memory.

Version 4.4

The following requirements and restrictions apply:

Version 4.3

The following requirements and restrictions apply:

Version 4.2

The following requirements and restrictions apply:

Safety Recommendations


Note   If you need to open the PIX Firewall case to install a hardware component such as additional memory or an interface card, doing so does not affect your Cisco warranty. Upgrading the PIX Firewall does not require any special tools and does not create any radio frequency leaks.

Use the following guidelines and the information in the following sections to help ensure your safety and protect the PIX Firewall equipment. The list of guidelines may not address all potentially hazardous situations in your working environment, so be alert and exercise good judgement at all times.

The safety guidelines are as follows:

This section includes the following topics:

Maintaining Safety with Electricity


Warning Before working on a chassis or working near power supplies, unplug the power cord on AC units; disconnect the power at the circuit breaker on DC units.

Follow these guidelines when working on equipment powered by electricity:

  Other DC power guidelines are listed in the Regulatory Compliance and Safety Information for the Cisco Secure PIX Firewall Version 5.2 document.

Preventing Electrostatic Discharge Damage

Electrostatic discharge (ESD) can damage equipment and impair electrical circuitry. ESD damage occurs when electronic components are improperly handled and can result in complete or intermittent failures.

General Site Requirements

The topics in this section describe the requirements your site must meet for safe installation and operation of your system. Ensure that your site is properly prepared before beginning installation.

This section includes the following topics:

Site Environment

The PIX Firewall can be placed on a desktop. Except for the PIX 506, all other PIX Firewall models can be mounted in a rack. The location of the PIX Firewall and the layout of your equipment rack or wiring room are extremely important for proper system operation. Equipment placed too close together, inadequate ventilation, and inaccessible panels can cause system malfunctions and shutdowns, and can make PIX Firewall maintenance difficult.

When planning your site layout and equipment locations, keep in mind the precautions described in the next section "Preventive Site Configuration," to help avoid equipment failures and reduce the possibility of environmentally caused shutdowns. If you are currently experiencing shutdowns or unusually high errors with your existing equipment, these precautions may help you isolate the cause of failures and prevent future problems.

Preventive Site Configuration

The following precautions will help you plan an acceptable operating environment for your PIX Firewall and will help you avoid environmentally caused equipment failures:

Power Supply Considerations

The PIX 510, PIX 515, PIX 520, PIX 525, PIX10000, and PIX Firewall have AC power supplies. The PIX 515 and PIX 520 models can have either an AC or DC power supply. The PIX 506 has an external power supply that converts AC to DC.

Observe the following considerations:

Configuring Equipment Racks

The following tips will help you plan an acceptable equipment rack configuration:


hometocprevnextglossaryfeedbacksearchhelp
Posted: Tue Aug 29 22:44:58 PDT 2000
Copyright 1989-2000©Cisco Systems Inc.