Re: PIX and Cryptochecksum [7:59650]

2002-12-21 Thread Brad
Sounds like the nvram or flash took a dump to me.  Did you load a new config
on there?  What happened when you did?

thanks,
-Brad Ellis
CCIE#5796 (RS / Security)
Network Learning Inc
[EMAIL PROTECTED]
www.ccbootcamp.com

David Cooper  wrote in message
[EMAIL PROTECTED]">news:[EMAIL PROTECTED]...
 Hey folks, I just saw a strange incident with a pix 501 in china. To be
 breif,
 this pix was doing ipsec to a site in america, PAT and smtp port
 redirection.

 One day out of the blue, all the access-list entries and crypto match
rules
 were gone.. poof! all the access-groups were too. The static commands were
 still there and everything else.

 I think this is possibly a security violation. The one thing I noticed was
 the
 Cryptochecksum was _ALL_ zeros in the sh config.

 A little birdie at tac told me that it is possible that the cryptochecksum
 could be zeros but that strongly goes against my tuition.

 Does anyone have any idea on this? Afaik that should never be 0.

 Thanks in advance,
 eo




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=59676t=59650
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



PIX and Cryptochecksum [7:59650]

2002-12-20 Thread David Cooper
Hey folks, I just saw a strange incident with a pix 501 in china. To be
breif,
this pix was doing ipsec to a site in america, PAT and smtp port
redirection.

One day out of the blue, all the access-list entries and crypto match rules 
were gone.. poof! all the access-groups were too. The static commands were 
still there and everything else. 

I think this is possibly a security violation. The one thing I noticed was
the
Cryptochecksum was _ALL_ zeros in the sh config. 

A little birdie at tac told me that it is possible that the cryptochecksum 
could be zeros but that strongly goes against my tuition. 

Does anyone have any idea on this? Afaik that should never be 0.

Thanks in advance,
eo




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=59650t=59650
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]