[c-nsp] Retrieving *'d secrets in PIX6.3(5)

Clue Store cluestore at gmail.com
Wed Aug 18 16:30:08 EDT 2010


If you can tftp the config, it will show the passwords in clear text. Not
sure if there's any other way to do it in 6.3.5

Clue

On Wed, Aug 18, 2010 at 3:03 PM, Jason Lixfeld <jason at lixfeld.ca> wrote:

> In current PIX/ASA OS 7+, one is able to look at things like *'d out
> ipsec/isakmp secrets using 'more system:running-configuration' which makes
> it easy to move the config over to a new box or something.  Is there a way
> to do the same thing with PIX6?  6.3(5) more specifically?  I'm looking to
> upgrade a couple of PIX firewalls to proper ASAs and would like to avoid
> having to reconfigure every IPSec client (dynamic and static) that
> terminates on this box currently.
>
> Thanks in advance.
> _______________________________________________
> cisco-nsp mailing list  cisco-nsp at puck.nether.net
> https://puck.nether.net/mailman/listinfo/cisco-nsp
> archive at http://puck.nether.net/pipermail/cisco-nsp/
>


More information about the cisco-nsp mailing list