Cisco Press books by returning this survey! Cisco is dedicated to customer
satisfaction and would like to hear your thoughts on these printed manuals. Please visit the Cisco Product Comments on-line
survey at
www.cisco.com/go/crc
to submit your comments about accessing Cisco technical manuals. Thank you for your time.
General Information
1 Years of networking experience:Years of experience with Cisco products:
2 I have these network types:LANBackboneWAN
Other:
3 I have these Cisco products:SwitchesRouters
Other (specify models):
4 I perform these types of tasks:H/W installation and/or maintenanceS/W configuration
Network managementOther:
5 I use these types of documentation:H/W installationH/W configurationS/W configuration
Command referenceQuick referenceRelease notesOnline help
Other:
6 I access this information through:% Cisco.com% CD-ROM% Printed manuals
% Other:
7 I prefer this access method:Cisco.comCD-ROMPrinted manuals
Other:
8 I use the following three product features the most:
Part Number:78-15170-03S/W Release (if applicable):
On a scale of 1–5 (5 being the best), please let us know how we rate in the following areas:
The document is complete.The information is accurate.
The information is well organized.The information I wanted was easy to find.
The document is written at my
technical level of understanding.
Please comment on our lowest scores:
The information I found was useful to my job.
Mailing Information
OrganizationDate
Contact Name
Mailing Address
CityState/ProvinceZip/Postal Code
CountryPhone ()Extension
E-mailFax()
May we contact you further concerning our documentation?YesNo
You can also send us your comments by e-mail to bug-doc@cisco.com, or by fax to 408-527-8089.
When mailing this card from outside of the United States, please enclose in an envelope addressed to the location on the back of this card with
the required postage or fax to 1-408-527-8089.
Cisco Systems, Inc.
170 West Tasman Drive
San Jose, CA 95134-1706
USA
http://www.cisco.com
Tel: 408 526-4000
800 553-NETS (6387)
Fax: 408 526-4100
Customer Order Number: DOC-7815170=
Text Part Number: 78-15170-03
Page 4
THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL
STATEMENTS, INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL ARE BELIEVED TO BE ACCURATE BUT ARE PRESENTED WITHOUT
WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. USERS MUST TAKE FULL RESPONSIBILITY FOR THEIR APPLICATION OF ANY PRODUCTS.
THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH IN THE INFORMATION PACKET THAT
SHIPPED WITH THE PRODUCT AND ARE INCORPORATED HEREIN BY THIS REFERENCE. IF YOU ARE UNABLE TO LOCATE THE SOFTWARE LICENSE
OR LIMITED WARRANTY, CONTACT YOUR CISCO REPRESENTATIVE FOR A COPY.
The following inform ation is for FCC compliance of Class A devices: This equipment has been tested and found to comply with the limits for a Class A digital device, pursuant
to part 15 of the FCC rules. These limits are designed to provide reasonable protection against harmful interference when the equipment is operated in a commercial
environment. This equipment generates, uses, and can radiate radio-frequency energy and, if not installed and used in accordance with the instruction manual, may cause
harmful interference to radio communications. Operation of this equipment in a residential area is likely to cause harmful interference, in which case users will be required
to correct the interference at their own expense.
The following information is for FCC compliance of Class B devices: The equipment described in this manual generates and may radiate radio-frequency energy. If it is not
installed in accordance with Cisco’s installation instructions, it may cause interference with radio and television reception. This equipment has been tested and found to
comply with the limits for a Class B digital device in accordance with the specifications in part 15 of the FCC rules. These specifications are designed to provide reasonable
protection against such interference in a residential installation. However, there is no guarantee that interference will not occur in a particular installation.
Modifying the equipment without Cisco’s written authorization may result in the equipment no longer complying with FCC requirements for Class A or Class B digital
devices. In that event, your right to use the equipment may be limited by FCC regulations, and you may be required to correct any interference to radio or television
communications at your own expense.
You can determine whether your equipment is causing interference by turning it off. If the interference stops, it was probably caused by the Cisco equipment or one of its
peripheral devices. If the equipment causes interference to radio or television reception, try to correct the interference by using one or more of the following measures:
• Turn the television or radio antenna until the interference stops.
• Move the equipment to one side or the other of the television or radio.
• Move the equipment farther away from the television or radio.
• Plug the equipment into an outlet that is on a different circuit from the television or radio. (That is, make certain the equipment and the television or radio are on circuits
controlled by different circuit breakers or fuses.)
Modifications to this product not authorized by Cisco Systems, Inc. could void the FCC approval and negate your authority to operate the product.
NOTWITHSTANDING ANY OTHER WARRANTY HEREIN, ALL DOCUMENT FILES AND SOFTWARE OF THESE SUPPLIERS ARE PROVIDED “AS IS” WITH
ALL FAULTS. CISCO AND THE ABOVE-NAMED SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESSED OR IMPLIED, INCLUDING, WITHOUT
LIMITATION, THOSE OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OR ARISING FROM A COURSE OF
DEALING, USAGE, OR TRADE PRACTICE.
IN NO EVENT SHALL CISCO OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT, SPECIAL, CONSEQUENTIAL, OR INCIDENTAL DAMAGES, INCLUDING,
WITHOUT LIMITATION, LOST PROFITS OR LOSS OR DAMAGE TO DATA ARISING OUT OF THE USE OR INABILITY TO USE THIS MANUAL, EVEN IF CISCO
OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
CCSP, CCVP, the Cisco Square Bridge logo, Follow Me Browsing, and StackWise are trademarks of Cisco Systems, Inc.; Changing the Way We Work, Live, Play, and Learn, and
iQuick Study are service marks of Cisco Systems, Inc.; and Access Registrar, Aironet, ASIST, BPX, Catalyst, CCDA, CCDP, CCIE, CCIP, CCNA, CCNP, Cisco, the Cisco
Certified Internetwork Expert logo, Cisco IOS, Cisco Press, Cisco Systems, Cisco Systems Capital, the Cisco Systems logo, Cisco Unity, Empowering the Internet Generation,
Enterprise/Solver, EtherChannel, EtherFast, EtherSwitch, Fast Step, FormShare, GigaDrive, GigaStack, HomeLink, Internet Quotient, IOS, IP/TV, iQ Expertise, the iQ logo, iQ
Net Readiness Scorecard, LightStream, Linksys, MeetingPlace, MGX, the Networkers logo, Networking Academy, Network Registrar, Pac k e t, PIX, Post-Routing, Pre-Routing,
ProConnect, RateMUX, ScriptShare, SlideCast, SMARTnet, StrataView Plus, TeleRouter, The Fastest Way to Increase Your Internet Quotient, and TransPath are registered
trademarks of Cisco Systems, Inc. and/or its affiliates in the United States and certain other countries.
All other trademarks mentioned in this document or Website are the property of their respective owners. The use of the word partner does not imply a partnership relationship
between Cisco and any other company. (0502R)
• Chapter 1, “Preparing for Installation,” describes the installation overview, safety
recommendations, and general site requirements.
• Chapter 2, “PIX 501,” provides a product overview, installation instructions, and lithium battery
replacement instructions.
• Chapter 3, “PIX 506/506E,” provides a product overview, installation instructions, and lithium
battery replacement instructions.
• Chapter 4, “PIX 515/515E,” provides a product overview, installation instructions, as well as the
procedure to remove and replace the chassis cover. This chapter also includes installation procedures
for the circuit board and installation of the DC model.
• Chapter 5, “PIX 520,” provides a product overview, installation instructions, as well as the
procedure to remove and replace the chassis cover. This chapter also includes the procedure for
installation of the DC model.
• Chapter 6, “PIX 525,” provides a product overview, installation instructions, as well as the
procedure to remove and replace the chassis cover. This chapter also includes installation procedures
for the circuit board and installation of the DC model.
About This Guide
• Chapter 7, “PIX 535,” provides a product overview, installation instructions, as well as the
installation procedure for the circuit board and installation of the DC model.
• Appendix A, “Cable Pinouts,” provides cable pinouts.
Graphic user interface access uses these conventions:
• Boldface indicates buttons and menu items.
• Selecting a menu item (or screen) is indicated by the following convention:
Click Start > Settings > Control Panel.
NoteMeans reader take note. Notes contain helpful suggestions or references to material not covered in the
manual.
Warning Definition
Document Conventions
Warning
Waarschuwing
Varoitus
IMPORTANT SAFETY INSTRUCTIONS
This warning symbol means danger. You are in a situation that could cause bodily injury. Before you
work on any equipment, be aware of the hazards involved with electrical circuitry and be familiar
with standard practices for preventing accidents. Use the statement number provided at the end of
each warning to locate its translation in the translated safety warnings that accompanied this
device.
SAVE THESE INSTRUCTIONS
BELANGRIJKE VEILIGHEIDSINSTRUCTIES
Dit waarschuwingssymbool betekent gevaar. U verkeert in een situatie die lichamelijk letsel kan
veroorzaken. Voordat u aan enige apparatuur gaat werken, dient u zich bewust te zijn van de bij
elektrische schakelingen betrokken risico's en dient u op de hoogte te zijn van de standaard
praktijken om ongelukken te voorkomen. Gebruik het nummer van de verklaring onderaan de
waarschuwing als u een vertaling van de waarschuwing die bij het apparaat wordt geleverd, wilt
raadplegen.
BEWAAR DEZE INSTRUCTIES
TÄRKEITÄ TURVALLISUUSOHJEITA
Tämä varoitusmerkki merkitsee vaaraa. Tilanne voi aiheuttaa ruumiillisia vammoja. Ennen kuin
käsittelet laitteistoa, huomioi sähköpiirien käsittelemiseen liittyvät riskit ja tutustu
onnettomuuksien yleisiin ehkäisytapoihin. Turvallisuusvaroitusten käännökset löytyvät laitteen
mukana toimitettujen käännettyjen turvallisuusvaroitusten joukosta varoitusten lopussa näkyvien
lausuntonumeroiden avulla.
Ce symbole d'avertissement indique un danger. Vous vous trouvez dans une situation pouvant
entraîner des blessures ou des dommages corporels. Avant de travailler sur un équipement, soyez
conscient des dangers liés aux circuits électriques et familiarisez-vous avec les procédures
couramment utilisées pour éviter les accidents. Pour prendre connaissance des traductions des
avertissements figurant dans les consignes de sécurité traduites qui accompagnent cet appareil,
référez-vous au numéro de l'instruction situé à la fin de chaque avertissement.
CONSERVEZ CES INFORMATIONS
WICHTIGE SICHERHEITSHINWEISE
Dieses Warnsymbol bedeutet Gefahr. Sie befinden sich in einer Situation, die zu Verletzungen
führen kann. Machen Sie sich vor der Arbeit mit Geräten mit den Gefahren elektrischer Schaltungen
und den üblichen Verfahren zur Vorbeugung vor Unfällen vertraut. Suchen Sie mit der am Ende jeder
Warnung angegebenen Anweisungsnummer nach der jeweiligen Übersetzung in den übersetzten
Sicherheitshinweisen, die zusammen mit diesem Gerät ausgeliefert wurden.
BEWAHREN SIE DIESE HINWEISE GUT AUF.
IMPORTANTI ISTRUZIONI SULLA SICUREZZA
Questo simbolo di avvertenza indica un pericolo. La situazione potrebbe causare infortuni alle
persone. Prima di intervenire su qualsiasi apparecchiatura, occorre essere al corrente dei pericoli
relativi ai circuiti elettrici e conoscere le procedure standard per la prevenzione di incidenti.
Utilizzare il numero di istruzione presente alla fine di ciascuna avvertenza per individuare le
traduzioni delle avvertenze riportate in questo documento.
Advarsel
Aviso
CONSERVARE QUESTE ISTRUZIONI
VIKTIGE SIKKERHETSINSTRUKSJONER
Dette advarselssymbolet betyr fare. Du er i en situasjon som kan føre til skade på person. Før du
begynner å arbeide med noe av utstyret, må du være oppmerksom på farene forbundet med
elektriske kretser, og kjenne til standardprosedyrer for å forhindre ulykker. Bruk nummeret i slutten
av hver advarsel for å finne oversettelsen i de oversatte sikkerhetsadvarslene som fulgte med denne
enheten.
TA VARE PÅ DISSE INSTRUKSJONENE
INSTRUÇÕES IMPORTANTES DE SEGURANÇA
Este símbolo de aviso significa perigo. Você está em uma situação que poderá ser causadora de
lesões corporais. Antes de iniciar a utilização de qualquer equipamento, tenha conhecimento dos
perigos envolvidos no manuseio de circuitos elétricos e familiarize-se com as práticas habituais de
prevenção de acidentes. Utilize o número da instrução fornecido ao final de cada aviso para
localizar sua tradução nos avisos de segurança traduzidos que acompanham este dispositivo.
Este símbolo de aviso indica peligro. Existe riesgo para su integridad física. Antes de manipular
cualquier equipo, considere los riesgos de la corriente eléctrica y familiarícese con los
procedimientos estándar de prevención de accidentes. Al final de cada advertencia encontrará el
número que le ayudará a encontrar el texto traducido en el apartado de traducciones que acompaña
a este dispositivo.
GUARDE ESTAS INSTRUCCIONES
VIKTIGA SÄKERHETSANVISNINGAR
Denna varningssignal signalerar fara. Du befinner dig i en situation som kan leda till personskada.
Innan du utför arbete på någon utrustning måste du vara medveten om farorna med elkretsar och
känna till vanliga förfaranden för att förebygga olyckor. Använd det nummer som finns i slutet av
varje varning för att hitta dess översättning i de översatta säkerhetsvarningar som medföljer denna
anordning.
CautionLightning protection or grounding blocks are required to isolate or protect the in-building equipment
from the hazards associated with the outside plant or outside environment. Lightning protectors
and/or grounding blocks are normally installed outside the building just prior to the coaxial cable
entering the building.
Power Supply Disconnection Warning
CautionBefore working on a chassis or working near power supplies, unplug the power cord on AC units;
disconnect the power at the circuit breaker on DC units.
Jewelry Removal Warning
CautionBefore working on equipment that is connected to power lines, remove jewelry (including rings,
necklaces, and watches). Metal objects will heat up when connected to power and ground and can
cause serious burns or weld the metal object to the terminals.
Cautions
AC Power Disconnection Warning
CautionBefore working on a chassis or working near power supplies, unplug the power cord on AC units.
TN Power Warning
CautionThe device is designed to work with TN power systems.
48 VDC Power System
CautionThe customer 48 volt power system must provide reinforced insulation between the primary AC
power and the 48 VDC output.
More Than One Power Cord
CautionThis unit might have more than one power cord. To reduce the risk of electrical shock, disconnect all
CautionThis product relies on the building's installation for short-circuit (overcurrent) protection. Ensure
that a UL Listed and Certified fuse or circuit breaker no larger than 60 VDC, 15 A is used on all
current-carrying conductors.
Grounded Equipment Warning
CautionThis equipment is intended to be grounded. Ensure that the host is connected to earth ground during
normal use.
Safety Cover Requirement
CautionThe safety cover is an integral part of the product. Do not operate the unit without the safety cover
installed. Operating the unit without the cover in place will invalidate the safety approvals and pose
a risk of fire and electrical hazards.
About This Guide
Faceplates and Cover Panel Requirement
CautionBlank faceplates and cover panels serve three important functions: they prevent exposure to
hazardous voltages and currents inside the chassis; they contain electromagnetic interference (EMI)
that might disrupt other equipment; and they direct the flow of cooling air through the chassis. Do
not operate the system unless all cards, faceplates, front covers, and rear covers are in place.
Wrist Strap Warning
CautionDuring this procedure, wear grounding wrist straps to avoid ESD damage to the card. Do not directly
touch the backplane with your hand or any metal tool, or you could shock yourself.
Obtaining Documentation
Cisco documentation and additional literature are available on Cisco.com. Cisco also provides several
ways to obtain technical assistance and other technical resources. These sections explain how to obtain
technical information from Cisco Systems.
• Nonregistered Cisco.com users can order documentation through a local account representative by
calling Cisco Systems Corporate Headquarters (California, USA) at 408 526-7208 or, elsewhere in
North America, by calling 1 800 553-NETS (6387).
Documentation Feedback
You can send comments about technical documentation to bug-doc@cisco.com.
You can submit comments by using the response card (if present) behind the front cover of your
document or by writing to the following address:
Cisco Systems
Attn: Customer Document Ordering
170 West Tasman Drive
San Jose, CA 95134-9883
We appreciate your comments.
Obtaining Technical Assistance
For all customers, partners, resellers, and distributors who hold valid Cisco service contracts, Cisco
Technical Support provides 24-hour-a-day, award-winning technical assistance. The Cisco Technical
Support Website on Cisco.com features extensive online support resources. In addition, Cisco Technical
Assistance Center (TAC) engineers provide telephone support. If you do not hold a valid Cisco service
contract, contact your reseller.
The Cisco Technical Support Website provides online documents and tools for troubleshooting and
resolving technical issues with Cisco products and technologies. The website is available 24 hours a day,
365 days a year, at this URL:
http://www.cisco.com/techsupport
Access to all tools on the Cisco Technical Support Website requires a Cisco.com user ID and password.
If you have a valid service contract but do not have a user ID or password, you can register at this URL:
http://tools.cisco.com/RPF/register/register.do
NoteUse the Cisco Product Identification (CPI) tool to locate your product serial number before submitting
a web or phone request for service. You can access the CPI tool from the Cisco Technical Support
Website by clicking the Tools & Resources link under Documentation & Tools.Choose Cisco Product
Identification Tool from the Alphabetical Index drop-down list, or click the Cisco Product
Identification Tool link under Alerts & RMAs. The CPI tool offers three search options: by product ID
or model name; by tree view; or for certain products, by copying and pasting show command output.
Search results show an illustration of your product with the serial number label location highlighted.
Locate the serial number label on your product and record the information before placing a service call.
About This Guide
Submitting a Service Request
Using the online TAC Service Request Tool is the fastest way to open S3 and S4 service requests. (S3
and S4 service requests are those in which your network is minimally impaired or for which you require
product information.) After you describe your situation, the TAC Service Request Tool provides
recommended solutions. If your issue is not resolved using the recommended resources, your service
request is assigned to a Cisco TAC engineer. The TAC Service Request Tool is located at this URL:
http://www.cisco.com/techsupport/servicerequest
For S1 or S2 service requests or if you do not have Internet access, contact the Cisco TAC by telephone.
(S1 or S2 service requests are those in which your production network is down or severely degraded.)
Cisco TAC engineers are assigned immediately to S1 and S2 service requests to help keep your business
operations running smoothly.
To open a service request by telephone, use one of the following numbers:
For a complete list of Cisco TAC contacts, go to this URL:
http://www.cisco.com/techsupport/contacts
Definitions of Service Request Severity
xvi
To ensure that all service requests are reported in a standard format, Cisco has established severity
definitions.
Severity 1 (S1)—Your network is “down,” or there is a critical impact to your business operations. You
and Cisco will commit all necessary resources around the clock to resolve the situation.
Severity 2 (S2)—Operation of an existing network is severely degraded, or significant aspects of your
business operation are negatively affected by inadequate performance of Cisco products. You and Cisco
will commit full-time resources during normal business hours to resolve the situation.
Severity 3 (S3)—Operational performance of your network is impaired, but most business operations
remain functional. You and Cisco will commit resources during normal business hours to restore service
to satisfactory levels.
Severity 4 (S4)—You require information or assistance with Cisco product capabilities, installation, or
configuration. There is little or no effect on your business operations.
Obtaining Additional Publications and Information
Information about Cisco products, technologies, and network solutions is available from various online
and printed sources.
• Cisco Marketplace provides a variety of Cisco books, reference guides, and logo merchandise. Visit
Cisco Marketplace, the company store, at this URL:
http://www.cisco.com/go/marketplace/
• The Cisco Product Catalog describes the networking products offered by Cisco Systems, as well as
ordering and customer support services. Access the Cisco Product Catalog at this URL:
http://cisco.com/univercd/cc/td/doc/pcat/
• Cisco Press publishes a wide range of general networking, training and certification titles. Both new
and experienced users will benefit from these publications. For current Cisco Press titles and other
information, go to Cisco Press at this URL:
http://www.ciscopress.com
• Packet magazine is the Cisco Systems technical user magazine for maximizing Internet and
networking investments. Each quarter, Packet delivers coverage of the latest industry trends,
technology breakthroughs, and Cisco products and solutions, as well as network deployment and
troubleshooting tips, configuration examples, customer case studies, certification and training
information, and links to scores of in-depth online resources. You can access Packet magazine at
this URL:
http://www.cisco.com/packet
• iQ Magazine is the quarterly publication from Cisco Systems designed to help growing companies
learn how they can use technology to increase revenue, streamline their business, and expand
services. The publication identifies the challenges facing these companies and the technologies to
help solve them, using real-world case studies and business strategies to help readers make sound
technology investment decisions. You can access iQ Magazine at this URL:
http://www.cisco.com/go/iqmagazine
• Internet Protocol Journal is a quarterly journal published by Cisco Systems for engineering
professionals involved in designing, developing, and operating public and private internets and
intranets. You can access the Internet Protocol Journal at this URL:
78-15170-03
http://www.cisco.com/ipj
• World-class networking training is available from Cisco. You can view current offerings at
This chapter describes how to install and add hardware upgrades that accompany the unit. The
information in this guide applies to the PIX 501, PIX 506/506E, PIX 515/515E, PIX 520, PIX 525, and
PIX 535. In this guide, the term “security appliance” refers to all models unless specifically noted
otherwise.
CautionInstalling PIX software Version 6.0(1), or a later version, on an older model of PIX hardware, such as a
PIX “Classic” (PIX 10000) or PIX 510, causes the security appliance to reboot continuously until a
software version previous to 6.0(1) is reinstalled.
This chapter includes the following sections:
• Installation Overview, page 1-1
• Safety Recommendations, page 1-2
• General Site Requirements, page 1-4
Installation Overview
To prepare for the installation of the PIX security appliance, perform the following steps:
NoteIf your PIX security appliance model supports a failover configuration, perform the steps that follow
only on the primary (active) unit. (Not applicable to the PIX 501 or the PIX 506/506E.)
Step 1Review the safety precautions outlined in the Regulatory Compliance and Safety Information document.
Step 2Completely read the release notes for your respective software version.
Step 3Unpack the PIX security appliance. The PIX security appliance consists of two main components, the
PIX security appliance unit and a separate accessory kit. The accessory kit contains documentation, a
power supply or cord, rack mounting hardware (not applicable to the PIX 501 or the PIX 506/506E), and
additional software you can use with the PIX security appliance.
Step 4Place the PIX security appliance on a stable work surface.
Use the following guidelines and the information in the following sections to help ensure your safety and
protect the PIX security appliance. The list of guidelines may not address all potentially hazardous
situations in your working environment, so be alert and exercise good judgement at all times.
NoteIf you need to open the PIX security appliance case to install a hardware component, such as additional
memory or an interface card, doing so does not affect your Cisco warranty. Upgrading the PIX security
appliance does not require any special tools and does not create any radio frequency leaks.
The safety guidelines are as follows:
• Keep the chassis area clear and dust-free before, during, and after installation.
• Keep tools away from walk areas where you and others could fall over them.
• Do not wear loose clothing or jewelry, such as earrings, bracelets, or chains, that could get caught
in the chassis.
• Wear safety glasses if you are working under any conditions that might be hazardous to your eyes.
Chapter 1 Preparing for Installation
• Do not perform any action that creates a potential hazard to people or makes the equipment unsafe.
• Never attempt to lift an object that is too heavy for one person to handle.
Before working on a chassis or working near power supplies, unplug the power cord on AC units;
disconnect the power at the circuit breaker on DC units.
Follow these guidelines when working on equipment powered by electricity:
• Before beginning procedures that require access to the interior of the PIX security appliance, locate
the emergency power-off switch for the room in which you are working. Then, if an electrical
accident occurs, you can act quickly to turn off the power.
• Do not work alone if potentially hazardous conditions exist anywhere in your work space.
• Never assume that power is disconnected from a circuit; always check the circuit.
• Look carefully for possible hazards in your work area, such as moist floors, ungrounded power
extension cables, frayed power cords, and missing safety grounds.
1-2
• If an electrical accident occurs, proceed as follows:
• Use the PIX security appliance within its marked electrical ratings and product usage instructions.
• Install the PIX security appliance in compliance with local and national electrical codes as listed in
the Regulatory Compliance and Safety Information document.
• PIX security appliance models equipped with AC-input power supplies are shipped with a three-wire
electrical cord with a grounding-type plug that fits only a grounding-type power outlet. This is a
safety feature that you should not circumvent. Equipment grounding should comply with local and
national electrical codes.
• PIX security appliance models equipped with DC-input power supplies must be terminated with the
DC input wiring on a DC source capable of supplying at least 15 amps. A 15-amp circuit breaker is
required at the 48 VDC facility power source. An easily accessible disconnect device should be
incorporated into the facility wiring. Be sure to connect the grounding wire conduit to a solid earth
ground. We recommend that you use a closed loop ring to terminate the ground conductor at the
ground stud.
Safety Recommendations
If possible, send another person to get medical aid. Otherwise, assess the condition of the victim
and then call for help.
Determine if the person needs rescue breathing or external cardiac compressions; then take
appropriate action.
Other DC power guidelines are listed in the Regulatory Compliance and Safety Information document.
Preventing Electrostatic Discharge Damage
Electrostatic discharge (ESD) can damage equipment and impair electrical circuitry. ESD damage
occurs when electronic components are improperly handled and can result in complete or intermittent
failures.
• Always follow ESD-prevention procedures when removing and replacing components. Ensure that
the chassis is electrically connected to earth ground. Wear an ESD-preventive wrist strap, ensuring
that it makes good skin contact. Connect the grounding clip to an unpainted surface of the chassis
frame to safely ground ESD voltages. To properly guard against ESD damage and shocks, the wrist
strap and cord must operate effectively. If no wrist strap is available, ground yourself by touching
the metal part of the chassis.
• For safety, periodically check the resistance value of the antistatic strap, which should be between
The topics in this section describe the requirements your site must meet for safe installation and
operation of your system. Ensure that your site is properly prepared before beginning installation.
This section includes the following topics:
• Site Environment, page 1-4
• Preventive Site Configuration, page 1-4
• Power Supply Considerations, page 1-4
• Configuring Equipment Racks, page 1-5
Site Environment
The PIX security appliance can be placed on a desktop. Except for the PIX 501 and the PIX 506/506E,
all other PIX security appliance models can be mounted in a rack. The location of the PIX security
appliance and the layout of your equipment rack or wiring room are extremely important for proper
system operation. Equipment placed too close together, inadequate ventilation, and inaccessible panels
can cause system malfunctions and shutdowns, and can make PIX security appliance maintenance
difficult.
Chapter 1 Preparing for Installation
When planning your site layout and equipment locations, keep in mind the precautions described in the
next section “Preventive Site Configuration,” to help avoid equipment failures and reduce the possibility
of environmentally caused shutdowns. If you are currently experiencing shutdowns or unusually high
errors with your existing equipment, these precautions may help you isolate the cause of failures and
prevent future problems.
Preventive Site Configuration
The following precautions helps you plan an acceptable operating environment for your PIX security
appliance and helps you avoid environmentally caused equipment failures:
• Electrical equipment generates heat. Ambient air temperature might not be adequate to cool
equipment to acceptable operating temperatures without adequate circulation. Ensure that the room
in which you operate your system has adequate air circulation.
• Always follow the ESD-prevention procedures described previously to avoid damage to equipment.
Damage from static discharge can cause immediate or intermittent equipment failure.
• Ensure that the chassis cover is secure. The chassis is designed to allow cooling air to flow
effectively within it. An open chassis allows air leaks, which may interrupt and redirect the flow of
cooling air from internal components.
Power Supply Considerations
1-4
The PIX 515/515E, PIX 520, PIX 525, PIX 535, and PIX 10000, have AC power supplies. The
PIX 515/515E, PIX 520, PIX 525, and PIX 535 models can have either an AC or DC power supply. The
PIX 501 and the PIX 506/506E have an external power supply that converts AC to DC.
• Check the power at your site before installing the PIX security appliance to ensure that you are
receiving “clean” power (free of spikes and noise). Install a power conditioner if necessary, to ensure
proper voltages and power levels in the source voltage for the system.
• Install proper grounding for the site to avoid damage from lightning and power surges.
• In units equipped with AC-input power supplies, use the following guidelines:
–
–
–
–
–
General Site Requirements
The PIX 501, PIX 506/506E, and PIX 10000 models automatically select operating ranges of a
low range of 90 to 135 volts or a high range of 180 to 270 volts.
The PIX 510 and PIX 520 models operate with a source voltage ranging from 100 to 240 VAC;
the input power supply requires a 20 amp service minimum for North America and 10 amp or
16 amp for the international area.
The PIX 515/PIX 515E, PIX 525, and PIX 535 do not have a selectable operating range. Refer
to the label on each model for the correct AC-input power requirement.
Several styles of AC-input power supply cords are available; make sure you have the correct
style for your site.
Install an uninterruptible power source for your site, if possible.
–
Install proper site grounding facilities to guard against damage from lightning or power surges.
• In a unit equipped with DC-input power supplies, use the following guidelines:
–
Each DC-input power supply requires dedicated 15 amp service.
–
For DC power cables, we recommend that you use a minimum of 18 AWG wire cable.
Configuring Equipment Racks
Follow these tips to help plan for configuration of an equipment rack:
• PIX 515/515E, PIX 520, PIX 525, and PIX 535 security appliances require you to first attach rack
mounting brackets to the units before mounting them in an equipment rack.
• Enclosed racks must have adequate ventilation. Ensure that the rack is not overly congested because
each unit generates heat. An enclosed rack should have louvered sides and a fan to provide cooling
air.
• When mounting a chassis in an open rack, ensure that the rack frame does not block the intake or
exhaust ports. If the chassis is installed on slides, check the position of the chassis when it is seated
all the way into the rack.
• In an enclosed rack with a ventilation fan in the top, excessive heat generated by equipment near the
bottom of the rack can be drawn upward and into the intake ports of the equipment above it in the
rack. Ensure that you provide adequate ventilation for equipment at the bottom of the rack.
• Baffles can help to isolate exhaust air from intake air, which also helps to draw cooling air through
the chassis. The best placement of the baffles depends on the airflow patterns in the rack.
Experiment with different arrangements to position the baffles effectively.
Table 2 - 1 lists the states of the PIX 501 front panel LEDs.
Figure 2-3PIX 501 Front Panel LEDs
Table 2-1PIX 501 Front Panel LEDs
LEDColorStateDescription
POWERGreenOnThe device is powered on.
OffThe device is powered off.
LINK/ACTGreenFlashing Network activity, such as Internet access, is present.
OnThe correct cable is in use, and the connected equipment has power and
is operational.
OffNo link is established.
TipIf the LINK/ACT LED does not light up, you might be using the
wrong type of cable. Try replacing the yellow, straight-through
Ethernet cable with the orange, crossover Ethernet cable.
VPN TUNNEL GreenOnOne or more IKE/IPSec VPN tunnels are established.
OffOne or more IKE/IPSec VPN tunnels are disabled. If the standard
configuration is not modified to support VPN tunnels, the LED does not
light up because it is disabled by default. Also, the LED does not light up
when PPTP/L2TP tunnels are established.
100 MBPSGreenOnThe interface is enabled at 100 Mbps (autonegotiated).
Place the PIX 501 on a flat, stable surface. The PIX 501 is not rack mountable.
To install the PIX 501, perform the following steps:
Step 1Connect Port 0, the outside Ethernet port, to the public network.
• Use the yellow Ethernet cable (72-1482-01) to connect the device to a switch or hub.
• Use the orange Ethernet cable (72-3515-01) to connect the device to a DSL modem, cable modem,
or router.
Step 2Connect your PC or the other network devices to one of the four switched inside ports (numbered 1
through 4).
Connecting a Power Supply Module to the PIX 501
Installing the PIX 501
This section describes how to connect the power supply module to a PIX 501. Use this information in
conjunction with the Regulatory Compliance and Safety Information document.
To connect the power supply module to the PIX 501, perform the following steps:
Step 1Connect the small, round connector of the power supply cable to the power connector on the rear panel
(see Figure 2-4).
Step 2Connect the AC power connector of the power supply input cable to an electrical outlet.
NoteThe PIX 501 does not have a power switch. Completing Step 2 powers on the device.
Figure 2-4Connecting the Power Supply Module to the PIX 501
The PIX 501 includes a slot that accepts standard desktop cable locks to provide physical security for
small portable equipment, such as laptop computers (see Figure 2-5).
Chapter 2 PIX 501
POWER
43
2
1
0CONSOLE
3.3V 4.5A
Lock slot
Cable lock
(not included)
To install a security cable lock, perform the following steps:
Figure 2-5PIX 501 Security Cable Lock
Step 1Attach the cable lock to the lock slot on the back panel of the PIX 501.
Step 2Follow the directions from the manufacturer for attaching the other end of the device for securing the
PIX 501.
Removing and Replacing the PIX 501 Chassis Cover
This section describes how to remove and replace the chassis cover from the PIX 501. This section
includes the following topics:
61929
• Removing the Chassis Cover, page 2-4
• Replacing the Chassis Cover, page 2-5
Removing the Chassis Cover
To remove the chassis cover, perform the following steps:
NoteRemoving the chassis cover does not affect your Cisco warranty. Upgrading the PIX security appliance
does not require any special tools and does not create any radio frequency leaks.
Step 1Read the Regulatory Compliance and Safety Informationdocument.
Step 2Unplug the power cord from the power outlet to power off the security appliance.
Step 3Disconnect the network interface cables.
Step 4Turn the unit upside down so that the top of the chassis is resting on a flat surface, and the front of the
Step 5Unscrew the single screw located on the bottom of the chassis, centered under the front panel
Removing and Replacing the PIX 501 Chassis Cover
chassis is facing toward you.
(see Figure 2-6).
Figure 2-6Removing PIX 501 Bottom Panel Screw
Step 6
POWER
VPN TUNNEL
LINK/ACT
1234
100 MBPS
119682
C
ISC
O
®
PIX
501
FIREWALL
Return the chassis to the upright position. Note that the chassis is comprised of two sections: top and
bottom (see Figure 2-7).
Figure 2-7Sliding the Chassis Cover Off the Chassis
119683
CISCO
®
PIX
501
FIREWALL
POWER
VPN TUNNEL
LINK/ACT
1234
100 MBPS
Step 7
With the front panel facing you, slide the top section toward you, and then lift it up and off the bottom
section (see Figure 2-7).
Replacing the Chassis Cover
CautionDo not operate PIX security appliances without the chassis cover installed. The chassis cover protects
the internal components, prevents electrical shorts, and provides proper air-flow for cooling the
electronic components.
To replace the chassis cover, perform the following steps:
Step 1Place the chassis on a secure surface with the front panel facing you.
Step 2Hold the chassis cover so the tabs at the rear of the chassis cover are aligned with the chassis bottom.
Step 3Lower the front of the cover onto the chassis, making sure that the side tabs of the cover fit under the
side panels of the chassis.
Step 4Slide the chassis cover toward the front, making sure that the cover tabs fit under the back panel, and the
back panel tabs fit under the chassis cover.
Step 5Secure the chassis cover with the screw you set aside earlier.
Step 6Reconnect the network interface cables.
Step 7Place the PIX 501 on a flat, stable surface. The PIX 501 is not rack mountable.
Step 8Reconnect the power cord to the power outlet to power on the security appliance.
Replacing a Lithium Battery
The PIX 501 has a lithium battery on the main circuit board (see Figure 2-8). This battery has an
operating life of about ten years. When the battery loses its charge, the PIX security appliance cannot
function. The lithium battery is a field-replaceable unit (FRU). You can use a standard 3V lithium battery
to replace the used battery.
Danger of explosion exists if the lithium battery is incorrectly replaced. Replace only with the same
or equivalent type recommended by the manufacturer. Dispose of used batteries according to the
manufacturer's instructions.
78-15170-03
Page 33
Chapter 2 PIX 501
Step 1Remove the chassis cover as described in the “Removing the Chassis Cover” section on page 2-4.
Step 2Use a flathead screwdriver to slide the battery out of the metal clip on the circuit board (see Figure 2-8).
Step 3Place the used battery aside and replace it with a new battery. Install the new battery writing side up.
Step 4The battery snaps into place as you slide it into the battery slot.
Step 5Replace the chassis cover as described in the “Replacing the Chassis Cover” section on page 2-5.
Replacing a Lithium Battery
To replace the lithium battery, perform the following steps:
Figure 3-4 shows the PIX 506/506E rear panel LEDs.
Figure 3-4PIX 506/506E Rear Panel LEDs
ACT(ivity)
LED
ACT
E
T
H
10BaseT
(RJ-45)
E
ACT(ivity)
LED
LINK
LED
LINK
R
N
E
T
1
ACT
E
T
H
E
R
N
E
10BaseT
(RJ-45)
LINK
LED
LINK
T
0
U
S
B
USB
port
Power switch
DC
POWER
INPUT
C
O
N
S
O
L
E
38852
Console
port (RJ-45)
Table 3 - 2 lists the states of the PIX 506/506E rear panel LEDs.
Table 3-2PIX 506/506E Rear Panel LEDs
LEDColorStateDescription
ACTGreenOnShows network activity.
LINKGreenOnShows that data is passing on the network to which the
connector is attached.
The USB port at the left of the Console port is not used.
Installing the PIX 506/506E
Place the PIX 506/506E on a flat, stable surface. The PIX 506/506E is not rack mountable.
To install the PIX 506/506E, perform the following steps:
Step 1Connect the cable so that you have either a DB-9 or DB-25 connector on one end as required by the serial
port for your computer, and the other end is the RJ-45 connector.
NoteUse the RJ-45 Console port to connect a computer to enter configuration commands. Locate the
serial cable from the accessory kit. The serial cable assembly consists of a null modem cable
with RJ-45 connectors, and one DB-9 connector and one DB-25 connector.
Connecting a Power Supply Module to the PIX 506/506E
Step 2Connect the RJ-45 connector to the PIX 506/506E and connect the other end to the serial port connector
on your computer (see Figure 3-7).
Figure 3-5PIX 506/506E Serial Console Cable
ACT
LINK
ACT
E
T
H
E
R
N
E
T 1
E
Chapter 3 PIX 506/506E
DC
POWER
INPUT
LINK
T
H
E
R
N
E
T
0
U
S
B
C
O
N
S
O
L
E
Console
port (RJ-45)
Computer serial port
DB-9 or DB-25
RJ-45 to
DB-9 or DB-25
serial cable
(null-modem)
Step 3Connect the inside network cable to the interface connector marked ETHERNET 0 or ETHERNET 1.
NoteThe inside or outside network connections can be made to either interface port on the
PIX 506/506E.
Step 4Connect the outside network cable to the remaining Ethernet port.
Connecting a Power Supply Module to the PIX 506/506E
This section describes how to connect the power supply module to the PIX 506/506E. Use this
information in conjunction with the Regulatory Compliance and Safety Information document.
The PIX 506/506E uses an external AC to DC power supply. Power is supplied to the PIX 506/506E by
connecting the power supply to the back of the security appliance and connecting a separate AC power
cord to the power supply.
Connecting a Power Supply Module to the PIX 506/506E
Figure 3-6 displays the cable connection from the power supply to the PIX 506, and displays the AC
power cord connector (at the opposite end of the power supply).
Figure 3-6Connecting the Power Supply Module to the PIX 506 6-Pin Connector
DC
POWER
ACT
LINK
ACT
E
T
H
E
R
N
E
T
1
LINK
E
T
H
E
R
N
E
T
0
U
S
B
C
O
N
S
O
LE
INPUT
38854
Power supply
Figure 3-7 displays the cable connection from the power supply to the PIX 506E, and displays the AC
power cord connector (at the opposite end of the power supply).
Figure 3-7Connecting the Power Supply Module to the PIX 506E 8-Pin Connector
DC
POWER
ACT
LINK
ACT
E
T
H
E
R
N
E
T
1
LINK
E
T
H
E
R
N
E
T
0
U
S
B
C
O
N
S
O
LE
Power supply
INPUT
67847
78-15170-03
To connect the power supply module, perform the following steps:
Step 1Place the PIX 506/506E on a flat, stable surface. The PIX 506/506E is not rack mountable.
Step 2Connect the power supply to the back of the PIX 506/506E. See Figure 3-6 for the PIX 506 and
Figure 3-7 for the PIX 506E.
Step 3When you are ready to start the PIX 506/506E, power on the unit from the switch at the rear of the unit.
CautionDo not operate PIX security appliances without the chassis cover installed. The chassis cover protects
the internal components, prevents electrical shorts, and provides proper air-flow for cooling the
electronic components.
To replace the chassis cover, perform the following steps:
Step 1Place the chassis on a secure surface with the front panel facing you.
Step 2Hold the chassis cover so the tabs at the rear of the cover are aligned with the bottom of the chassis.
Step 3Lower the front of the cover onto the chassis, making sure that the side tabs of the cover fit under the
side panels of the chassis.
Step 4Slide the chassis cover toward the front, making sure that the cover tabs fit under the back panel, and the
back panel tabs fit under the chassis cover.
Step 5Secure the chassis cover with the screws you set aside earlier.
Step 6Reconnect the network interface cables.
Replacing a Lithium Battery
Step 7Place the PIX 506/506E on a flat, stable surface. The PIX 506/506E is not rack mountable..
Step 8Reconnect the power cord and power on the security appliance.
Replacing a Lithium Battery
The PIX 506/506E has a lithium battery on its main circuit board (see Figure 3-9). This battery has an
operating life of about ten years. When the battery loses its charge, the PIX security appliance cannot
function. The battery is a field-replaceable unit (FRU). You can use a standard 3V lithium battery to
replace the used battery.
Danger of explosion exists if the lithium battery is incorrectly replaced. Replace only with the same
or equivalent type recommended by the manufacturer. Dispose of used batteries according to the
manufacturer's instructions.
To replace the lithium battery, perform the following steps:
Step 1Remove the chassis cover as described in the “Removing the Chassis Cover” section on page 3-6.
Step 2Use a flathead screwdriver to slide the battery out of the metal clip on the circuit board (see Figure 3-9).
Step 3Place the used battery aside and replace it with a new battery. Install the new battery writing side up.
Step 4The battery snaps into place as you slide it into the battery slot.
Step 5Replace the chassis cover by lining up the cover tabs with the bottom panel tabs, and sliding the chassis
cover back into the side and front panel slots on the chassis.
Step 6Replace the chassis cover as described in the “Replacing the Chassis Cover” section on page 3-7.
Table 4 - 2 lists the states of the rear panel LEDs.
Table 4-2PIX 515/515E Rear Panel LEDs
LEDColorStatusDescription
100 MbpsGreenOn100 megabits per second 100BaseTX communication. If the light is
off, that port is using 10 megabits per second data exchange.
ACTGreenFlashingShows that data is passing on the network to which the connector is
attached.
LINKGreenOnShows that the connection uses full duplex data exchange where
data is transmitted and received simultaneously.
OffIf this light is off, half duplex is in effect.
The inside or outside network connections can be made to any available interface port on the
PIX 515/515E. If you are only using the ETHERNET 0 and ETHERNET 1 ports, connect the inside
network cable to the interface connector marked ETHERNET 0 or ETHERNET 1. Connect the outside
network cable to the remaining Ethernet port.
The USB port to the left of the Console port is not used. The detachable plate above the ETHERNET 1
connector is also not used.
Installing the PIX 515/515E
This section contains the following topics:
• Surface Mounting the PIX 515/515E, page 4-4
• Removing and Replacing the PIX 515/515E Chassis Cover, page 4-13
• Vertical Mounting the PIX 515/515E, page 4-5
• Installing a Circuit Board in the PIX 515/515E, page 4-19
To surface mount the chassis, perform the following steps:
Step 1Locate the rubber feet on the black adhesive strip that shipped with the chassis.
Step 2Place the chassis upside down on a smooth, flat surface.
Step 3Peel off the rubber feet from the black adhesive strip and place them adhesive-side down onto the five round,
recessed areas on the bottom of the chassis, as shown in Figure 4-5.
Step 4Place the security appliance right-side up on a flat, smooth, secure surface.
NoteThe fan is not blocked by the device below if you surface mount the chassis on top of each other, the air
is sucked in from the back and side vents and exhausted out with the help of the fan through the bottom
of the chassis and then directed out the side of the channel by the channel feature on the bottom of the
chassis.
Figure 4-5Attaching the Rubber Feet to the PIX 515/515E
Observe the following before installing the chassis into an equipment rack:
• To install optional circuit boards or memory, install the brackets on the unit for rack mounting, but
do not put the chassis in the equipment rack before installing the new boards. You must remove the
chassis cover to install or remove a circuit board. Refer to the “Removing and Replacing the
PIX 515/515E Chassis Cover” section on page 4-13 for information.
–
For more information on installing a circuit board, refer to the “Installing a Circuit Board in the
PIX 515/515E” section on page 4-19.
–
For more information on installing additional memory, refer to the “Installing a Memory
Upgrade” section on page 4-16.
NoteThe fan is not blocked by the device below if you mount the chassis on top of each other, the air is sucked
in from the back and side vents and exhausted out with the help of the fan through the bottom of the
chassis and then directed out the side of the channel by the channel feature on the bottom of the chassis.
To install the chassis in a rack, perform the following steps:
Installing the PIX 515/515E
Step 1Attach the bracket to the chassis using the supplied screws. You can attach the brackets to the holes near
the front of the chassis.
Step 2Attach the chassis to the equipment rack.
Vertical Mounting the PIX 515/515E
To mount the chassis vertically, attach the brackets to the side of the unit and mount the unit vertically
as shown in Figure 4-6.
To install the PIX 515/515E, perform the following steps:
Step 1Connect the cable as shown in Figure 4-7 so that you have either a DB-9 or DB-25 connector on one end
as required by the serial port for your computer, and the other end is the RJ-45 connector.
NoteUse the Console port to connect to a computer to enter configuration commands. Locate the
serial cable from the accessory kit. The serial cable assembly consists of a null modem cable
with RJ-45 connectors, and one DB-9 connector and a DB-25 connector.
Step 2Connect the RJ-45 connector to the PIX 515/515E Console port and connect the other end to the serial
port connector on your computer.
Figure 4-7PIX 515/515E Serial Console Cable
Chapter 4 PIX 515/515E
Console
port (RJ-45)
RJ-45 to
DB-9 or DB-25
serial cable
(null-modem)
PC terminal adapter DB-9
104944
NoteIf your unit has a four-port Ethernet circuit board already installed, refer to Figure 4-8. (The
four-port Ethernet circuit board requires the PIX-515/515E-UR license to be accessed.) If it has
one or two single-port Ethernet circuit boards, refer to Figure 4-9. If you need to install an
optional circuit board, refer to the “Removing and Replacing the PIX 515/515E Chassis Cover”
Figure 4-8Four-Port Ethernet Connectors in the PIX 515/515E
Ethernet 5
Ethernet 3
D
O
N
O
T
I
N
S
T
A
L
L
I
N
T
E
R
F
A
C
E
C
A
R
D
S
W
I
T
H
P
O
W
E
R
A
P
P
L
I
E
D
1
0
0
M
L
b
in
p
s
k
F
D
X
1
0
0
M
b
p
s
L
in
k
1
0
/
1
0
0
E
T
H
E
R
N
E
T
1
1
0
/1
0
0
E
T
H
E
R
N
E
T
PIX-515
F
A
IL
O
V
E
R
F
D
X
0
C
O
N
S
O
L
E
Ethernet 2
Ethernet 4
Ethernet 1
Ethernet 0
Installing the PIX 515/515E
25733
Step 3
Connect the inside, outside, or perimeter network cables to the interface ports. Starting from the top left
the connectors are Ethernet 2, Ethernet 3, Ethernet 4, and Ethernet 5. The maximum number of allowed
interfaces is 6.
NoteDo not add a single-port circuit board in the extra slot below the four-port circuit board.
Figure 4-9Two Single-Port Ethernet Connectors in the PIX 515/515E
Ethernet 2
D
O
N
O
T
I
N
S
T
A
L
L
I
N
T
E
R
F
A
C
E
C
A
R
D
S
W
I
T
H
P
O
W
E
R
A
P
P
L
I
E
Ethernet 3
D
1
0
0
M
L
b
in
p
s
k
F
D
X
1
0
1
0
/
1
0
0
E
T
H
E
R
N
E
T
1
Ethernet 1
PIX-515
F
A
IL
O
0
M
b
p
s
L
in
k
1
0
/
1
0
0
E
T
H
E
V
E
R
F
D
X
R
N
E
T
0
C
O
N
S
O
L
E
25734
Ethernet 0
NoteAs shown in Figure 4-9, if your unit has one or two single-port Ethernet circuit boards installed
in the auxiliary assembly on the left of the unit at the rear, the circuit boards are numbered top
to bottom so that the top circuit board is Ethernet 2 and the bottom circuit board is Ethernet 3.
(Additional Ethernet circuit boards require the PIX-515/PIX 515E-UR license to be accessed.)
78-15170-03
If you have a second PIX security appliance to use as a failover unit, install the failover feature and cable
as described in the “Installing Failover” section on page 4-9.
NoteDo not power on the failover units until the active unit has been configured.
Step 4Power on the unit from the switch at the rear to start the PIX 515/515E.
The VPN Accelerator Card (VAC) for the Cisco PIX security appliance series is a card that provides
high-performance, tunneling and encryption services suitable for site-to-site and remote access applications.
The VAC is integrated with PIX 515 unrestricted (UR) and failover (FO) bundles. You can also purchase the
VAC as a spare for use with PIX 515s that have a restricted (R) license.
VPN Accelerator Card+
The VAC+ is a 64-bit/66 MHz PCI card that provides faster tunneling and encryption services for Virtual
Private Network (VPN) remote access, and site-to-site intranet and extranet applications, than the VAC.
Each VAC+ occupies a single PCI slot in the system. The VAC+ is supported on any chassis that runs
Version 6.3 software or later, has an appropriate license to run VPN software, and at least one PCI slot
available. While the VAC continues to be supported in Version 6.3, if both types of cards, the VAC and
the VAC+, are installed in a system running Version 6.3, the VAC card is ignored. The VAC+ runs at both
32-bit/33 MHz and 64-bit/66 MHz, and does not slow down the bus when other 66 MHz cards are
installed. We strongly recommend that you install the VAC+ in a 64bit/66 MHz slot. Performance is degraded
if this recommendation is not followed.
Installing Failover
The VAC+ driver supports the following:
• 3DES, DES, AES, SHA1, MD5 for (IPSec) ESP protocol (For AES, only the CBC mode and key
sizes of 128, 192, and 256 bits are supported).
• SHA1, MD5 for the (IPSec) AH protocol.
• Load sharing ESP and AH activity between up to three VAC+.
• Diffie-Hellman public key and shared secret generation.
• Any other crypto-related activity uses a software implementation.
Installing Failover
To install a failover connection, perform the following steps:
Step 1Power off both the primary and secondary units.
NoteBoth PIX security appliances must have the same model number, have at least as much RAM,
have the same Flash memory size, and be running the same software version. Note that the
PIX-4FE and PIX-4FE-66 cards are considered equivalent and interchangeable. You can install
a PIX-4FE in the primary unit and a PIX-4FE-66 in the secondary unit, as long as you install
them in the same slot number of each chassis. For example, if you install a PIX-4FE in Slot 1 of
the primary unit, you must also install the PIX-4FE-66 in Slot 1 of the secondary unit.
78-15170-03
Step 2Locate the failover cable (shown in Figure 4-10). The cable is labeled “Primary” on one end and
“Secondary” on the other.
Install the cable for the PIX 515/515E as shown in Figure 4-10.
NoteYou can connect the PIX 515 to the PIX 515, but you cannot connect the PIX 515 to the
PIX 515E or vice versa. Both units must be identical.
Step 3Connect the Primary end of the failover cable to the first PIX security appliance; that is, the one you have
already configured.
Step 4Connect the Secondary end of the failover cable to the standby unit.
Step 5Connect a power cord to the power connector on the rear panel of each unit, and the other end of each
power cord to (preferably separate) power outlets.
Step 6If you are using Stateful Failover, use one of the following types of connections, that is appropriate for
your system, between the dedicated interfaces on the PIX security appliance:
• Category 5 crossover cable directly connecting the primary unit to the secondary unit
• 100BaseTX half-duplex hub using Straight-through Category 5 cables
• 100BaseTX full duplex on a dedicated switch or dedicated VLAN of a switch
LAN-based failover supports failover between two units connected over a dedicated Ethernet interface.
LAN-based failover eliminates the need for a special failover cable and overcomes the distance
limitations imposed by the failover cable.
NoteBoth chassis must be the same model number, have the same amount of RAM, Flash memory, number
and type of interfaces, and be running the same software version.
To set up a LAN-based failover connection, perform the following steps:
Step 1Disconnect both PIX security appliances, so that there is no traffic flow between them. If the failover
cable is connected to the PIX security appliance, disconnect it.
Step 2Configure the PIX security appliances for LAN-based failover. Refer to the chapter on configuring
LAN-based failover in the configuration guide online at:
Removing and Replacing the PIX 515/515E Chassis Cover
Step 5If you are using Stateful Failover, use one of the following types of connections, that is appropriate for
your system, between the dedicated interfaces on the PIX security appliance:
• 100BaseTX full duplex on a dedicated switch or dedicated VLAN of a switch
• 1000BaseTX full duplex on a dedicated switch or dedicated VLAN of a switch
CautionDo not turn the power on until the units are connected and the primary unit is configured completely.
Step 6Power the primary unit on first, then power on the secondary unit. Within a few seconds, the active unit
automatically downloads its configuration to the standby unit.
If the primary unit fails, the secondary unit automatically becomes active.
Removing and Replacing the PIX 515/515E Chassis Cover
This section describes how to remove and replace the chassis cover from the PIX 515/515E. This section
includes the following topics:
• Removing the Chassis Cover, page 4-13
• Replacing the Chassis Cover, page 4-15
Removing the Chassis Cover
To remove the chassis cover, perform the following steps:
NoteRemoving the chassis cover does not affect your Cisco warranty. Upgrading the PIX security appliance
does not require any special tools and does not create any radio frequency leaks.
Step 1Read the Regulatory Compliance and Safety Informationdocument.
Step 2Unplug the power cord from the power outlet. Ensure that the PIX 515/515E is powered off. Once the
upgrade is complete, you can safely reconnect the power cord.
Warning
Before working on a system that has an On/Off switch, turn OFF the power and unplug the power cord.
CautionDo not operate the PIX security appliance without the chassis cover installed. The chassis cover protects
the internal components, prevents electrical shorts, and provides proper air-flow for cooling the
electronic components.
To replace the chassis cover, perform the following steps:
Step 1Place the chassis on a secure surface with the front panel facing you.
Step 2Hold the chassis cover so the tabs at the rear of the chassis cover are aligned with the chassis bottom.
Step 3Lower the front of the chassis cover onto the chassis, making sure that the chassis cover side tabs fit
under the chassis side panels.
Step 4Slide the chassis cover toward the front, making sure that the chassis cover tabs fit under the chassis back
panel, and the back panel tabs fit under the chassis cover.
Step 5Fasten the chassis cover with the screws you set aside earlier.
Step 6Reinstall the chassis on a rack, wall, desktop, or table.
Replacing a Lithium Battery
Step 7Reinstall network interface cables.
Replacing a Lithium Battery
The PIX security appliance has a lithium battery on its main circuit board. This battery has an operating
life of about ten years. When the battery loses its charge, the PIX security appliance cannot function.
The lithium battery is not a field-replacable unit (FRU) for the PIX 515/515E. Contact Cisco TAC to
replace the battery.
NoteDo not attempt to replace this battery yourself.
Warning
Danger of explosion exists if the lithium battery is incorrectly replaced. Replace only with the same
or equivalent type recommended by the manufacturer. Dispose of used batteries according to the
manufacturer's instructions.
Observe the following warnings, cautions, and notes when installing additional system memory.
The following statement applies to DC models:
Chapter 4 PIX 515/515E
Warning
Warning
CautionIf you remove the chassis cover, always reinstall the cover. Running the PIX security appliance without the
Before performing any of the following procedures, ensure that power is removed from the DC circuit.
To ensure that all power is OFF, locate the circuit breaker on the panel board that services the DC
circuit, switch the circuit breaker to the OFF position, and tape the switch handle of the circuit
breaker in the OFF position.
The following statements apply to both AC and DC models:
Before working on a system that has an On/Off switch, turn OFF the power and unplug the power cord.
chassis cover causes the system to overheat and and might damage the electrical components.
Memory Installation Steps
Depending on the software version and feature license installed on the PIX 515/515E security appliance,
you might need to upgrade the system memory to run newer software versions or more robust software
features.
PIX software Version 6.3 and previous software releases require a minimum of 32 MB of memory with
the Restricted license, and 64 MB of memory with the Unrestricted and Failover licenses.
PIX software Version 7.0 requires a minimum of 64 MB of memory with the Restricted license, and
128 MB of memory with the Unrestricted and Failover licenses.
4-16
If you want to upgrade the feature license from Restricted to Unrestricted or Failover, or upgrade the
software from Version 6.3 to Version 7.0, you need to upgrade the memory.
NoteSoftware Version 7.0 is supported only on the PIX 515/515E security appliance. New PIX 515E security
appliances shipped after the general availability of PIX software Version 7.0 have enough memory to run
version 7.0 and the software license ordered.
Table 4 - 4 lists the minimum memory requirements for the various software versions and licenses.
Step 1If the PIX 515/515E security appliance is rack mounted, remove it from the rack and place it on a stable
Step 2Disconnect the network interface cables and power cord from the PIX 515/515E security appliance.
Step 3Unpack the items in the memory upgrade kit.
Step 4Remove the chassis cover. Remove all screws holding the assembly in place. Refer to the “Removing
Step 5Determine the location of the memory sockets (see Figure 4-16).
Installing a Memory Upgrade
To install memory, perform the following steps:
work surface.
and Replacing the PIX 515/515E Chassis Cover” section on page 4-13 for information on how to remove
Step 6Locate the wrist grounding strap in the accessory kit and connect one end to the unit as shown in
Figure 4-17, or to the PIX security appliance chassis, and securely attach the other to your wrist so it
contacts your bare skin.
Figure 4-17 Attaching the Wrist Strap to the PIX 515/515E
Chapter 4 PIX 515/515E
Copper foil
D
O
N
O
T
IN
S
T
A
L
L
I
N
T
E
R
F
A
C
E
C
A
R
D
S
W
I
T
H
P
O
W
E
R
A
P
P
L
IE
D
1
0
0
M
L
b
in
p
s
k
FD
X
1
0
0 M
b
p
s
L
in
k
F
D
1
0
/1
0
0
E
T
H
E
R
N
E
T
0
X
/0
1
0
/1
0
0
E
T
H
E
R
N
E
T
0
/0
PIX-515
F
AILO
V
E
R
C
O
N
S
O
L
E
24304
Step 7
If you are upgrading from:
• 32 MB to 64 MB of memory, install an additional 32 MB memory module into the empty socket for
a new total of 64 MB of memory.
• 32 MB to 128 MB of memory, remove the existing 32 MB memory module. Open the two plastic
wing connectors on the sides of the memory socket, and pull the old memory module up and out of
the socket. Discard the old 32 MB memory module. Then install the two new 64 MB memory
modules for a new total of 128 MB of memory.
• 64 MB to 128 MB of memory:
–
If two 32 MB memory modules are installed, remove them. Open the two plastic wing
connectors on the sides of the memory socket, and pull the old memory module up and out of
the socket. Repeat for the second memory module. Discard the old 32 MB memory modules.
Then install the two new 64 MB memory modules for a new total of 128 MB of memory.
–
If one 64 MB memory module is installed, add an additional 64 MB memory module into the
empty socket for a new total of 128 MB of memory.
Step 8To install a new memory module, slide it into the memory socket and secure the plastic wing connectors
on the sides of the socket. Use the markings on the motherboard to determine the socket numbers.
Always install the first memory module into the lowest socket number. Then populate the second
memory socket. See Figure 4-18 and Figure 4-19.
Figure 4-18 Inserting a Memory Module in the PIX 515/515E
DIMM
24299
Figure 4-19 Securing a Memory Module in the PIX 515/515E
24300
When you finish installing new memory, replace the chassis cover. Reattach the screws. If desired, rack
mount the chassis and attach all cables and cords as discussed in previous sections. After the chassis is
installed, you can view the amount of memory in the system startup messages or with the show version
command.
The information in this section refers to both the AC and DC models of the PIX 515/515E.
The 4-port 64 bit/66 MHz FE card (PIX-4FE-66) is supported in software Versions 6.3, 6.2(2), 6.1(4),
and 5.2(9), and later versions. These are the minimum software versions that support the card.
NoteThe PIX-4FE card continues to be supported but is no longer manufactured. The PIX-4FE and
PIX-4FE-66 cards are considered equivalent and interchangeable. You can install a PIX-4FE in the
primary unit and a PIX-4FE-66 in the secondary unit, as long as you install them in the same slot number
of each chassis. For example, if you install a PIX-4FE in Slot 1 of the primary unit, you must also install
the PIX-4FE-66 in Slot 1 of the secondary unit.
The new card has the following characteristics:
• Includes an Intel 21154BE bridge and 4 Intel 82559 Ethernet MAC/PHY devices.
• Supports 10/100mbps full/half-duplex operation on each port.
• Retains bus performance when installed with other 66 MHz devices.
Chapter 4 PIX 515/515E
• Does not support auto MDI/MDIX operation.
To install a circuit board in the PIX 515/515E, perform the following steps:
Step 1Locate the grounding strap from the accessory kit. Fasten the grounding strap to your wrist so that it
contacts your bare skin. Attach the other end to bare metal inside the PIX 515/515E chassis as shown in
Figure 4-20.
Figure 4-20 Attaching the PIX 515/515E Grounding Strap
Copper foil
D
O
N
O
T
I
N
S
T
A
L
L
I
N
T
E
R
F
A
C
E
C
A
R
D
S
W
I
T
H
P
O
W
E
R
A
P
P
L
I
E
D
1
0
0
M
Lin
b
p
s
k
F
D
X
1
0
0
M
b
ps
L
in
k
F
D
1
0
/1
0
0
E
T
H
E
R
N
E
T
0
X
/0
1
0
/1
0
0
E
T
H
E
R
N
E
T
0
/0
PIX-515
F
A
IL
O
V
E
R
C
O
N
S
O
L
E
24304
4-20
Step 2
Remove the screws from the rear assembly on the left and put the assembly aside.
NoteIf you are installing a 4-port circuit board, note that the circuit board overlaps the slot connector
on the motherboard. This does not affect the use or operation of the circuit board. See
Figure 4-23.
VPN Accelerator Circuit Board
The VPN Accelerator (PIX-VPN-ACCEL) is an encryption and accelerator circuit board. The VPN
Accelerator uses a PCI interface and therefore can only be installed in PIX security appliance platforms
with PCI slots. The VPN Accelerator begins to function immediately after installation without the need
of special installation configurations.
NoteThe new VPN Accelerator cannot be used with the former PIX security appliance IPSec accelerator in
the same chassis. The PIX security appliance IPSec accelerator was also known as the Private Link card.
Before performing any of the following procedures, ensure that power is removed from the DC circuit.
To ensure that all power is OFF, locate the circuit breaker on the panel board that services the DC
circuit, switch the circuit breaker to the OFF position, and tape the switch handle of the circuit
breaker in the OFF position.
To install the PIX 515/515E DC power model, perform the following steps:
Step 1Read the Regulatory Compliance and Safety Informationdocument.
Step 2Terminate the DC input wiring on a DC source capable of supplying at least 15 amps. A 15-amp circuit
breaker is required at the 48 VDC facility power source. An easily accessible disconnect device should
be incorporated into the facility wiring.
Step 3Power off the PIX 515/515E. Ensure that power is removed from the DC circuit. To ensure that all power
is OFF, locate the circuit breaker on the panel board that services the DC circuit, switch the circuit
breaker to the OFF position, and tape the switch handle of the circuit breaker in the OFF position.
Step 4As shown in Figure 4-24, the PIX 515/515E is equipped with two grounding holes at the back of the unit,
which you can use to connect a two-hole grounding lug to the PIX 515/515E. Use 8-32 screws to connect
a copper standard barrel grounding lug to the holes. The ground lug must be NRTL listed or recognized.
In addition, the copper conductor (wires) must be used and the copper conductor must comply with the
NEC code for ampacity. The PIX 515/515E requires a lug where the distance between the center of each
hole is 0.56 inches. A lug is not supplied with the PIX 515/515E.
Figure 4-24 Attaching a Grounding Lug to the PIX Security Appliance
Ground wirewire
To r a ck
ground
8-32 screws
Grounding holes on
PIX DC model
2-hole copper standard
barrel grounding lug
must be NRTL
listed or recognized
100 Mbps
Link
10/100 ETHERNET 1
FDX
Step 5Strip the ends of the wires for insertion into the power connect lugs on the PIX 515/515E.
NoteUse of the four-port Ethernet circuit board changes the position of the outside and inside interfaces
Chapter 5 PIX 520
Figure 5-2 shows the rear view of the PIX 520.
Figure 5-2PIX 520 Rear Panel
Auto-Range Selection
L:90-135V H:180-270V
RESET
PIX Firewall
S
E
R
IE
S
67853
depending on the slot in which the circuit board is installed. Four-port Ethernet connectors are numbered
from the top connector down sequentially. On horizontally mounted cards, the slots are numbered left to
right.
The PIX 520 can be used with Ethernet circuit boards.
The four-port Ethernet circuit board provides four 10/100 Ethernet connections and has autosense
capability. Connectors on the four-port Ethernet circuit board are numbered top to bottom sequentially;
however, the actual device number depends on the slot in which the four-port Ethernet circuit board is
installed.
Table 5 - 1 describes how the top connector is numbered.
Table 5-1Numbering Devices with a Four-Port Connector
Four-Port Top
Slot 0 Contains Slot 1 Contains Slot 2 Contains
Connector
4-port AnyAnyethernet0
Ethernet4-portAnyethernet1
EthernetEthernet4-port ethernet2
Token Ring4-portAnyethernet0
Token RingToken Ring4-portethernet0
Token RingEthernet4-portethernet1
EthernetToken Ring4-portethernet1
With the four-port Ethernet circuit board, having a circuit board in slot 3 makes the number of interfaces
greater than six; while the circuit board in slot 3 cannot be accessed, its presence does not cause
problems with the PIX security appliance.
If you are not installing a four-port Ethernet circuit board, add the cables as shown in Figure 5-7.
Figure 5-7Up to Four Single-Port Interfaces in the PIX Security Appliance
44305
Interface 3
Interface 2
Interface 1
Interface 0
Installing Interface Cables to the PIX 520
To install interface cables to the PIX 520, perform the following steps:
Step 1Locate the serial cable. The serial cable assembly consists of a null modem cable with RJ-45 connectors,
two separate DB-9 connectors, and a separate DB-25 connector as shown in Figure 5-8.
Step 2Install the serial cable between the PIX security appliance and your console computer.
Figure 5-8PIX Security Appliance Serial Cable Assembly
PIX security appliance
console connector
DB-9-to-DB-25
serial cable
(null-modem)
C
O
N
S
O
L
E
Console
port (DB-9)
Computer serial port
DB-25 or DB-9
12275
78-15170-03
Step 3
Connect one of the DB-9 serial connectors to the console connector on the front panel of the PIX security
appliance.
Step 4Connect one end of the RJ-45 null modem cable to the DB-9 connector.
Step 5If you are installing an AC voltage PIX security appliance, connect the power cord to the power
connector on the rear panel of the PIX security appliance, and to a power outlet.
Always check the release notes first before configuring the PIX security appliance for the latest release
details. You can find the latest versions of release notes online at:
To install a failover connection, perform the following steps:
NoteThis section only applies to PIX security appliance units with a “UR” (unrestricted) license.
Step 1Power off both the primary and secondary units.
NoteBoth PIX security appliances must be the same model number, have at least as much RAM, have
the same Flash memory size, and be running the same software version.
Step 2Locate the Failover cable (shown in Figure 5-9). This cable is shipped separately from the PIX security
appliance. The cable is labeled Primary on one end and Secondary on the other. Install the cable for the
PIX 520 as shown in Figure 5-9.
Figure 5-9PIX 520 Failover Cable Connection
Installing Failover
F
A
I
L
O
V
E
R
Y
R
A
M
I
R
P
Primary end
F
A
I
L
O
V
E
R
Y
R
A
D
N
O
C
E
S
12395
Secondary end
Step 3
Connect the Primary end of the Failover cable to the first PIX security appliance unit, that is, the one
you have already configured.
Step 4Connect the Secondary end of the Failover cable to the standby unit.
Step 5Connect a power cord to the power connector on the rear panel of each unit, and the other end of each
power cord to (preferably separate) power outlets.
Step 6If you are using Stateful Failover, use one of the following types of connections, that is appropriate for
your system, between the dedicated interfaces on the PIX security appliance units:
• Category 5 crossover cable directly connecting the primary unit to the secondary unit.
• 100BaseTX half-duplex hub using straight Category 5 cables.
78-15170-03
• 100BaseTX full duplex on a dedicated switch or dedicated VLAN of a switch.
• All enabled interfaces must be connected between the active and standby units. Only configure the
active unit. On the PIX 520, you can access the console and determine which unit is active with the
show failover command in the command reference online at:
CautionDo not turn the power on until the units are connected and the primary unit is configured completely.
Step 7Use the power switch at the back of the units to power the primary unit on and then power on the standby
unit.
Within a few seconds, the active unit automatically downloads its configuration to the standby unit.
If the primary unit fails, the secondary unit automatically becomes active.
Installing LAN-Based Failover
LAN-based failover supports failover between two units connected over a dedicated Ethernet interface.
LAN-based failover eliminates the need for a special Failover cable and overcomes the distance
limitations imposed by the Failover cable.
Chapter 5 PIX 520
For information on configuring a LAN-based failover, refer to the configuration guide online at:
If you are using Stateful Failover, use one of the following types of connections, that is appropriate for
your system, between the dedicated interfaces on the PIX security appliances:
• Category 5 crossover cable directly connecting the primary unit to the secondary unit.
• 100BaseTX full duplex on a dedicated switch or dedicated VLAN of a switch.
• 1000BaseTX full duplex on a dedicated switch or dedicated VLAN of a switch.
NoteFor Stateful Failover on the PIX 520, if you have Gigabit Ethernet (GE) interfaces,
then the failover link must be GE.
CautionDo not turn the power on until the units are connected and the primary unit is configured completely.
Step 6Power the primary unit on first, then power on the secondary unit. Within a few seconds, the active unit
automatically downloads its configuration to the standby unit.
If the primary unit fails, the secondary unit automatically becomes active.
The PIX security appliance has a lithium battery on its main circuit board. This battery has an operating
life of about ten years. When the battery loses its charge, the PIX security appliance cannot function.
The lithium battery is not a field-replacable unit (FRU). Contact Cisco TAC to replace the battery.
NoteDo not attempt to replace this battery yourself.
Chapter 5 PIX 520
Warning
Danger of explosion exists if the lithium battery is incorrectly replaced. Replace only with the same
or equivalent type recommended by the manufacturer. Dispose of used batteries according to the
manufacturer's instructions.
Installing a Memory Upgrade
Observe the following warnings, cautions, and notes when installing additional PIX security appliance
system memory.
The following statement applies to DC models:
Warning
Warning
Before performing any of the following procedures, ensure that power is removed from the DC circuit.
To ensure that all power is OFF, locate the circuit breaker on the panel board that services the DC
circuit, switch the circuit breaker to the OFF position, and tape the switch handle of the circuit
breaker in the OFF position.
The following statement applies to both AC and DC models:
Before working on a system that has an On/Off switch, turn OFF the power and unplug the power cord.
5-12
CautionAlways remove old memory before installing new memory.
NoteAfter installing additional memory in the PIX 520, do not remove the memory strips and power on the
unit, or the PIX security appliance will become inoperable.
CautionIf you remove the PIX security appliance chassis chassis cover, always reinstall the chassis cover. Running
the PIX security appliance without the chassis cover causes overheating and damage to electrical components.
To install additional system memory, perform the following steps:
Step 1If the unit is rack-mounted, remove network wires and any cords connecting to the PIX security
appliance. The PIX 520 should be removed from the rack and placed on a stable working surface. Ensure
that the unit is unplugged from its power source.
Step 2Unpack the items in the memory upgrade kit.
Remove the chassis cover from the PIX security appliance. Remove all screws holding the assembly in
place. Refer to the “Removing and Replacing the PIX 520 Chassis Cover” section on page 5-10 for more
information.
Step 3Determine the location of your system memory sockets (see Figure 5-14).
Step 4Use the markings on the motherboard to determine the socket numbers. Always install the first memory
strip into the lowest socket number. Progressively add memory boards into higher numbered sockets.
Figure 5-14 PIX 520 System Memory Location
Installing a Memory Upgrade
Bank 0
Bank 1
Bank 2
17996
Front
Step 5
Step 6With the wrist strap on your wrist, carefully grasp the memory strip from either end. Note that a DIMM
Step 7To install a DIMM strip:
Locate the wrist grounding strap in the accessory kit and connect one end to the unit as shown in
Figure 5-17, or to the PIX security appliance chassis, and securely attach the other to your wrist so it
contacts your bare skin.
strip has notches.
• Remove the old memory strip by opening the two plastic wing connectors, and pulling the old strip
up. Discard the old strip.
• When installing the memory strip in the PIX 520, install the new strip in Bank 0 as shown in
Figure 5-15 and Figure 5-16, by opening the two plastic wing connectors, inserting the strip, and
Figure 5-15 Inserting a DIMM Memory Strip in the PIX 520
Bank 2
Bank 1
Chapter 5 PIX 520
DIMM
17997
Bank 0
Figure 5-16 Securing a DIMM Memory Strip in the PIX 520
17998
Bank 2
Bank 1
Bank 0
When you finish inserting new RAM memory, replace the chassis cover on the chassis. Reattach the
•
screws. If desired, rack mount the PIX security appliance and attach all cables and cords as
discussed in previous sections. After the PIX security appliance is installed, you can view the
amount of RAM memory in the system startup messages or with the show version command in the
The information in this section refers to the installation of a circuit board in the PIX 520.
The 4-port 64 bit/66 MHz FE card (PIX-4FE-66) is supported in software Versions 6.3, 6.2(2), 6.1(4),
and 5.2(9), and later versions. These are the minimum software versions that support the card.
NoteThe PIX-4FE card continues to be supported but is no longer manufactured.
The new card has the following characteristics:
• Includes an Intel 21154BE bridge and 4 Intel 82559 Ethernet MAC/PHY devices.
• Supports 10/100mbps full/half-duplex operation on each port.
• Retains bus performance when installed with other 66 MHz devices.
• Does not support auto MDI/MDIX operation.
This section includes the following topics:
• 16 MB Flash Circuit Board, page 5-18
Installing a Circuit Board in the PIX 520
• VPN Accelerator Circuit Board, page 5-19
• Gigabit Ethernet Circuit Board, page 5-20
• Installing the PIX 520 DC Model, page 5-21
To install a circuit board in the PIX 520, perform the following steps:
Step 1Locate the grounding strap from the accessory kit. Fasten the grounding strap to your wrist so that it
contacts your bare skin. Attach the other end to bare metal inside the PIX security appliance chassis as
shown in Figure 5-17.
Figure 5-17 Attaching Grounding Strap to Your Wrist and to the PIX Security Appliance
Copper foil
18352
LNK
LNK
LNK
ACT
100
TX
DATA
ER
PIX Firewall
S
E
R
IE
S
RESET
POW
LNK
ACT
ACT
ACT
100
100
100
TX
TX
TX
E
E
E
T
H
E
R
N
E
T
0
E
T
T
T
H
H
DATA
H
E
DATA
E
DATA
E
R
R
R
N
N
N
E
E
E
T
T
T
0
0
0
78-15170-03
Step 2
Insert the new circuit board, as shown in Figure 5-18, and secure it using the screw provided with the
circuit board.
Along with upgrading your Flash memory to 16 MB, the PIX security appliance 16 MB Flash circuit
board includes pre-installed PIX security appliance software and a UR (unrestricted) 56-bit DES
encryption license. The 16 MB Flash circuit board installs into the PIX security appliance ISA slot.
An illustration of the 16 MB Flash circuit board is shown in Figure 5-21.
Use the following information to install a 16 MB Flash circuit board:
• The PIX security appliance must have a minimum of 32 MB of RAM memory.
• You must obtain a new activation key if you will be using 3DES.
• The PIX security appliance should not be downgraded to a software revision lower than 5.0(3) after
the new software from the 16 MB circuit board is installed.
• If you downgrade from software Version 5.3 to 5.2 or lower, you will lose private data (keys,
certifications, and CRLs) that are stored in Flash memory. You need to use the clear flashfs
command, downgrade 5.0 | 5.1 | 5.2 options if your PIX security appliance has 16 MB Flash
memory, private data stored in the Flash memory, and you used the ca save all command to save
these items in Flash memory.
Step 1Record the present PIX security appliance unit serial number.
Step 2Record the new serial number from the 16 MB Flash circuit board.
Step 3Create a backup of your present configuration (to use later to reconfigure your system).
Step 4Obtain a new Activation key (if using 3DES).
Step 5Remove any previously installed Flash memory circuit boards from the unit.
CautionDo not remove or reposition the 16 MB Flash circuit board. The PIX security appliance will not work if
Step 6Install the 16 MB Flash circuit board into an available ISA slot in the PIX security appliance chassis.
Installing a Circuit Board in the PIX 520
To install the 16 MB Flash circuit board, perform the following steps:
NoteAfter installation, the serial number of the PIX security appliance changes to the serial number
supplied with the 16 MB Flash circuit board.
this jumper is moved.
VPN Accelerator Circuit Board
The VPN Accelerator (PIX-VPN-ACCEL) is an encryption and accelerator circuit board. The VPN
Accelerator uses a PCI interface and therefore can only be installed in PIX security appliance platforms
with PCI slots. The VPN Accelerator begins to function immediately after installation without the need
of special installation configurations.
NoteThe new VPN Accelerator cannot be used with the former PIX security appliance IPSec accelerator in
the same chassis. The PIX security appliance IPSec accelerator was also known as the Private Link card.
An illustration of the VPN Accelerator is shown in Figure 5-22.
Figure 5-22 VPN Accelerator Circuit Board
Chapter 5 PIX 520
61921
Gigabit Ethernet Circuit Board
PIX security appliance supports 1000 Mbps (Gigabit) Ethernet. The Gigabit Ethernet circuit board uses
only has one hardware speed and the following duplex options:
The Gigabit Ethernet circuit board and the fiber optic cable connection are shown in Figure 5-23.
Figure 5-23 Gigabit Ethernet Circuit Board
33010
T
X
R
X
LIN
K
The Gigabit Ethernet circuit board has three LEDs:
• TX—Transmitting data
• RX—Receiving data
• LINK—The Gigabit Ethernet circuit board has established a network connection
Installing the PIX 520 DC Model
Warning
Step 1Read the Regulatory Compliance and Safety Informationdocument.
Step 2Terminate the DC input wiring on a DC source capable of supplying at least 15 amps. A 15-amp circuit
Step 3Be sure the PIX 520 power is off by checking the power switch at the rear of the unit.
Before performing any of the following procedures, ensure that power is removed from the DC circuit.
To ensure that all power is OFF, locate the circuit breaker on the panel board that services the DC
circuit, switch the circuit breaker to the OFF position, and tape the switch handle of the circuit
breaker in the OFF position.
To install the PIX 520 DC power model, perform the following steps:
breaker is required at the 48 VDC facility power source. An easily accessible disconnect device should
be incorporated into the facility wiring.
Step 4As shown in Figure 5-24, the PIX 520 is equipped with two grounding studs at the back of the unit,
which you can use to connect a two-hole grounding lug to the PIX 520. Use the 10-32 nuts provided with
the PIX 520 to connect a copper standard barrel grounding lug to the studs. The PIX 520 requires a lug
where the distance between the center of each hole is 0.56 inches. A lug is not supplied with the PIX 520.
Figure 5-24 Attaching a Grounding Lug to the PIX Security Appliance
PIX security appliance
Rear of
Chapter 5 PIX 520
–
+
11827
Grounding studs
on PIX DC model
Step 5
To r a ck
ground
10-32 nuts
2-hole copper
standard barrel
grounding lug
Ensure that power is removed from the DC circuit. To ensure that all power is OFF, locate the circuit
breaker on the panel board that services the DC circuit, switch the circuit breaker to the OFF position,
and tape the switch handle of the circuit breaker in the OFF position.
Step 6Strip the ends of the wires for insertion into the power connect lugs on the PIX 520.
Step 7Insert the ground wire into the connector for the earth ground and tighten the screw on the connector (see
Figure 5-25). Using the same method as for the ground wire, connect the negative wire and then the
Step 8Reconnect power to the PIX 520. After wiring the DC power supply, remove the tape from the circuit
Step 9Insert the PIX 520 system diskette in the drive at the front of the unit.
Step 10If needed, install the interface boards as described in the “Installing a Circuit Board in the PIX 520”
Step 11Power on the unit from the switch at the rear of the unit.
NoteIf you need to power cycle the DC PIX security appliance, wait at least five seconds between powering
Installing the PIX 520 DC Model
breaker switch handle and reinstate power by moving the handle of the circuit breaker to the ON position.
Step 2Connect the cable so that you have either a DB-9 or DB-25 connector on one end as required by the serial
Step 3Connect the RJ-45 serial cable connector to the PIX 525 console connector and connect the other end to
Chapter 6 PIX 525
port for your computer, and the other end is the RJ-45 connector as shown in Figure 6-5.
NoteUse the Console port to connect a computer to enter configuration commands. Locate the serial
cable from the accessory kit. The serial cable assembly consists of a null modem cable with
RJ-45 connectors, and one DB-9 connector and a DB-25 connector.
the serial port connector on your computer.
Figure 6-5PIX 525 Rear Panel
Console
port (RJ-45)
RJ-45 to
DB-9 or DB-25
PC terminal adapter DB-9
serial cable
(null-modem)
104944
Step 4Connect the outside network cable to the remaining Ethernet port. Refer to the “PIX 525 Feature
Licenses” section on page 6-5 for information on how to configure the ports.
NoteThe inside or outside network connections can be made to any available interface port on the
PIX 525. If you are only using the ETHERNET 0 and ETHERNET 1 ports, connect the inside
network cable to the interface connector marked ETHERNET 0 or ETHERNET 1.
Step 5If you need to install an optional circuit board, refer to the “Installing a Circuit Board in the PIX 525”
section on page 6-15. If you need to install memory, refer to the “Installing a Memory Upgrade” section
on page 6-12 for more information.
NoteIt is not necessary to remove the chassis cover of the PIX 525 to access the circuit boards or
Step 6Connect the network cables to the expansion interface ports. (The inside, outside, or perimeter network
connections can be made to any available interface port on the PIX 525.) The first expansion port
number, at the top left, is interface 2. Starting from that port and going from left to right and top to
bottom, the next port is interface 3, the next is interface 4, and so on. Refer to the “PIX 525 Feature
Licenses” section on page 6-5 for information on how to configure the ports.
Step 7If you have a second PIX security appliance to use as a failover unit, install the failover feature and cable
as described in the “Installing Failover” section on page 6-6.
NoteDo not power on the standby failover unit until the primary unit is configured.
Step 8When you are ready to start the PIX 525, power on the unit from the switch at the rear of the unit.
PIX 525 Feature Licenses
If you have the PIX-525-UR unrestricted feature license, the following options are available:
PIX 525 Feature Licenses
• If you have a second PIX 525 to use as a failover unit, install the failover feature and cable as
described in the “Installing Failover” section on page 6-6.
• If needed, install the PIX security appliance syslog server as described on the logging command
The VPN Accelerator Card (VAC) for the Cisco PIX security appliance series is a card that provides
high-performance, tunneling and encryption services suitable for site-to-site and remote access applications.
The VAC is integrated with PIX 525 unrestricted (UR) and failover (FO) bundles. You can also purchase the
VAC as a spare for use with PIX 525 units that have a restricted (R) license.
VPN Accelerator Card+
The VAC+ is a 64-bit/66 MHz PCI card that provides faster tunneling and encryption services for Virtual
Private Network (VPN) remote access, and site-to-site intranet and extranet applications, than the VAC.
Each VAC+ occupies a single PCI slot in the system. The VAC+ is supported on any chassis that runs
software Version 6.3 or later, has an appropriate license to run VPN software, and at least one PCI slot
available. While the VAC continues to be supported in Version 6.3, if both types of cards, the VAC and
the VAC+, are installed in a system running Version 6.3, the VAC card is ignored. The VAC+ runs at both
32-bit/33 MHz and 64-bit/66 MHz, and does not slow down the bus when other 66 MHz cards are
installed. We strongly recommend that you install the VAC+ in a 64bit/66 MHz slot. Performance will be
degraded if this recommendation is not followed.
Chapter 6 PIX 525
The VAC+ driver supports the following:
• 3DES, DES, AES, SHA1, MD5 for (IPSec) ESP protocol (For AES, only the CBC mode and key
sizes of 128, 192, and 256 bits are supported).
• SHA1, MD5 for the (IPSec) AH protocol.
• Load sharing ESP and AH activity between up to three VAC+.
• Diffie-Hellman public key and shared secret generation.
• Any other crypto-related activity uses a software implementation.
Installing Failover
To install a failover connection, perform the following steps:
Step 1Power off both the primary and secondary units.
NoteBoth PIX security appliances must have the same model number, have at least as much RAM,
have the same Flash memory size, and be running the same software version. Note that the
PIX-4FE and PIX-4FE-66 cards are considered equivalent and interchangeable. You can install
a PIX-4FE in the primary unit and a PIX-4FE-66 in the secondary unit, as long as you install
them in the same slot number of each chassis. For example, if you install a PIX-4FE in Slot 1 of
the primary unit, you must also install the PIX-4FE-66 in Slot 1 of the secondary unit.
6-6
Step 2Locate the failover cable (shown in Figure 6-6). This cable is shipped separately from the PIX security
appliance. The cable is labeled “Primary” on one end and “Secondary” on the other.
Install the cable for the PIX 525 as shown in Figure 6-6.
Figure 6-6PIX 525 Failover Cable Connection
F
A
I
L
O
V
E
R
Y
R
A
M
I
R
P
Primary end
Y
R
A
D
N
O
C
E
S
Secondary end
F
A
I
L
O
V
E
R
Installing Failover
12395
Step 3
Connect the Primary end of the failover cable to the first PIX security appliance; that is, the one you have
already configured.
NoteWe highly recommend that you use a GE failover link when connecting the PIX 525 with GE
interfaces.
Step 4Connect the Secondary end of the failover cable to the standby unit.
Step 5Connect a power cord to the power connector on the rear panel of each unit, and the other end of each
power cord to (preferably separate) power outlets.
Step 6If you are using Stateful Failover, use one of the following types of connections, that is appropriate for
your system, between the dedicated interfaces on the PIX security appliance:
• Category 5 crossover cable directly connecting the primary unit to the secondary unit
• 100BaseTX half-duplex hub using Straight-through Category 5 cables
• 100BaseTX full duplex on a dedicated switch or dedicated VLAN of a switch
NoteAll enabled interfaces must be connected between the active and standby units. Only configure
the active unit. On the PIX 525, the active unit is indicated by the ACT LED on the front panel
(see Figure 6-3).
78-15170-03
CautionDo not turn the power on until the units are connected and the primary unit is configured completely.
Step 7Power on the primary unit first, then power on the secondary unit. Within a few seconds, the active unit
automatically downloads its configuration to the standby unit.
If the primary unit fails, the secondary unit automatically becomes active.
LAN-based failover supports failover between two units connected over a dedicated Ethernet interface.
LAN-based failover eliminates the need for a special failover cable and overcomes the distance
limitations imposed by the failover cable.
NoteBoth PIX security appliances must be the same model number, have the same amount of RAM, Flash
memory, number and type of interfaces, and be running the same software version.
To set up a LAN-based failover connection, perform the following steps:
Step 1Disconnect both PIX security appliance, so that there is no traffic flow between them. If the failover
cable is connected to the PIX security appliance, disconnect it.
Step 2Configure the PIX security appliance for LAN-based failover. Refer to the chapter on configuring
LAN-based failover in the configuration guide online at: