
9-26
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 9 Accessing and Monitoring PIX Firewall
Enabling Auto Update Support
Managing Auto Update Support
To enable the PIX Firewall for polling an AUS, use the following command:
[no] auto-update device-id hardware-serial | hostname | ipaddress [if-name] | mac-address
[if-name] | string text
The auto-update device-id command is used to identify the device ID to send when communicating
with the AUS. The identifier used is determined by using one of the following parameters:
• hardware-serial—Use the PIX Firewall serial number.
• hostname option—Use the PIX Firewall host name.
• ipaddress option—Use the IP address of the interface with the name if-name. If the interface name
is not specified, it will use the IP address of the interface used to communicate with the AUS.
• mac-address option—Use the MAC address of the interface with the name if-name. If the interface
name is not specified, it will use the MAC address of the interface used to communicate with the
AUS.
• string—Use the specified text identifier, which cannot contain white space or the characters ‘, “, ,
>, & and ?.
Use the no auto-update device-id command to reset the device ID to the default of host name.
To specify how often to poll the AUS for configuration or image updates, enter the following command:
[no] auto-update poll-period poll-period [retry-count [retry-period]]
The poll-period parameter specifies how often (in minutes) to check for an update. The default is 720
minutes (12 hours). The retry-count option specifies how many times to try re-connecting to the server
if the first attempt fails. The default is 0. The retry-period option specifies how long to wait (in minutes)
between retries. The default is 5.
Use the no auto-update poll-period command to reset the poll period to the default.
If the Auto Update Server has not been contacted for a certain period of time, the following command
will cause it to cease sending packets:
[no] auto-update timeout period
Use this command to ensure that the PIX Firewall has the most recent image and configuration. This
condition will be reported with the existing message%PIX-3-201008.
To remove the entire Auto Update configuration, enter the following command:
clear auto-update
Viewing the Auto Update Configuration
To display the AUS, poll time, timeout period, device ID, poll statistics and update statistics, enter the
following command:
show auto-update
The following is sample output from the show auto-update command:
pix(config)# show auto-update
Server: https://********@172.23.58.115:1742/management.cgi?1276
Certificate will be verified
Poll period: 720 minutes, retry count: 2, retry period: 5 minutes
Comentários a estes Manuais