
1-26
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 1 Getting Started
Using the Command-Line Interface
• Configuration mode—Displays the prompt <pix_name>(config)#, where pixname is the host name
assigned to the PIX
Firewall. You use configuration mode to change system configuration. All
privileged, unprivileged, and configuration commands work in this mode. Use the configure
terminal command to start configuration mode and the exit or quit commands to exit.
• Subcommand mode—Displays the prompt <pix_name>(config-<main_cmd_name>)#,where
pixname is the host name assigned to the PIX
Firewall and main_cmd_name is the object grouping
command used to enter subcommand mode. Object grouping is a way to simplify access control by
letting you apply access control statements to groups of network objects, such as protocols or hosts.
For further information about enabling and using this mode, refer to the “
Simplifying Access
Control with Object Grouping” section in Chapter 3, “Controlling Network Access and Use.”
• Monitor mode—This is a special mode that enables you to update the image over the network. While
in the monitor mode, you can enter commands specifying the location of the TFTP server and the
binary image to download. For information about using monitor mode to upgrade your PIX
Firewall
software, refer to
Chapter 11, “Changing Feature Licenses and System Software.”
Accessing Configuration Mode
Perform the following steps to access the PIX Firewall configuration mode:
Step 1 Start your terminal emulation program.
Step 2 Power on the PIX Firewall. On newer models, the switch is at the back, on older models, at the front.
Step 3 If you are configuring a PIX 506/506E, PIX 515/515E, PIX 525, or PIX 535 and your site downloads
configuration images from a central source with TFTP, look for the following prompt in the startup
messages:
Use BREAK or ESC to interrupt flash boot.
PIX Firewall displays this prompt for 10 seconds. To download an image, press the Escape key to start
boot mode. If you are not downloading an image, ignore the prompt or press the Space bar to start
immediately and PIX
Firewall starts normally.
Step 4 After the startup messages appear, you are prompted with the following unprivileged mode prompt:
pixfirewall>
Enter the following command:
enable privilegelevel
Replace privilegelevel with a number from 0 to 15, indicating the privilege level to which you require
access. If you omit this parameter, the system assumes you are seeking access to privilege Level 15.
With PIX Firewall Version 6.2 or higher, you can configure up to fifteen different enable passwords for
different privilege levels. By default, all commands are assigned to Level 0 or Level 15, and only Level
15 is preconfigured with a password.
Comentários a estes Manuais