Contents
xxix
Cisco Security Appliance Command Line Configuration Guide
OL-10088-01
CHAPTER
43 Troubleshooting the Security Appliance 43-1
Testing Your Configuration 43-1
Enabling ICMP Debug Messages and System Messages 43-1
Pinging Security Appliance Interfaces 43-2
Pinging Through the Security Appliance 43-4
Disabling the Test Configuration 43-5
Traceroute 43-6
Packet Tracer 43-6
Reloading the Security Appliance 43-6
Performing Password Recovery 43-6
Performing Password Recovery for the ASA 5500 Series Adaptive Security Appliance 43-7
Password Recovery for the PIX 500 Series Security Appliance 43-8
Disabling Password Recovery 43-9
Other Troubleshooting Tools 43-10
Viewing Debug Messages 43-10
Capturing Packets 43-10
Viewing the Crash Dump 43-10
Common Problems 43-10
APPENDIX
A Feature Licenses and Specifications A-1
Supported Platforms and Feature Licenses A-1
Security Services Module Support A-9
VPN Specifications A-10
Cisco VPN Client Support A-11
Cisco Secure Desktop Support A-11
Site-to-Site VPN Compatibility A-11
Cryptographic Standards A-12
APPENDIX
B Sample Configurations B-1
Example 1: Multiple Mode Firewall With Outside Access B-1
Example 1: System Configuration B-2
Example 1: Admin Context Configuration B-4
Example 1: Customer A Context Configuration B-4
Example 1: Customer B Context Configuration B-4
Example 1: Customer C Context Configuration B-5
Example 2: Single Mode Firewall Using Same Security Level B-6
Example 3: Shared Resources for Multiple Contexts B-8
Example 3: System Configuration B-9