NoteUse of the four-port Ethernet circuit board changes the position of the outside and inside interfaces
Chapter 5 PIX 520
Figure 5-2 shows the rear view of the PIX 520.
Figure 5-2PIX 520 Rear Panel
Auto-Range Selection
L:90-135V H:180-270V
R
ESET
PIX Firewall
SERIES
67853
depending on the slot in which the circuit board is installed. Four-port Ethernet connectors are numbered
from the top connector down sequentially. On horizontally mounted cards, the slots are numbered left to
right.
The PIX 520 can be used with Ethernet circuit boards.
The four-port Ethernet circuit board provides four 10/100 Ethernet connections and has autosense
capability. Connectors on the four-port Ethernet circuit board are numbered top to bottom sequentially;
however, the actual device number depends on the slot in which the four-port Ethernet circuit board is
installed.
Table 5-1 describes how the top connector is numbered.
Table 5-1Numbering Devices with a Four-Port Connector
Four-Port Top
Slot 0 Contains Slot 1 Contains Slot 2 Contains
Connector
4-port AnyAnyethernet0
Ethernet4-portAnyethernet1
EthernetEthernet4-port ethernet2
Token Ring4-portAnyethernet0
Token RingToken Ring4-portethernet0
Token RingEthernet4-portethernet1
EthernetToken Ring4-portethernet1
With the four-port Ethernet circuit board, having a circuit board in slot 3 makes the number of interfaces
greater than six; while the circuit board in slot 3 cannot be accessed, its presence does not cause
problems with the PIX security appliance.
Always check the release notes first before configuring the PIX security appliance for the latest release
details. You can find the latest versions of release notes online at:
To install a failover connection, perform the following steps:
NoteThis section only applies to PIX security appliance units with a “UR” (unrestricted) license.
Step 1Power off both the primary and secondary units.
NoteBoth PIX security appliances must be the same model number, have at least as much RAM, have
the same Flash memory size, and be running the same software version.
Step 2Locate the Failover cable (shown in Figure 5-9). This cable is shipped separately from the PIX security
appliance. The cable is labeled Primary on one end and Secondary on the other. Install the cable for the
PIX 520 as shown in Figure 5-9.
Figure 5-9PIX 520 Failover Cable Connection
Installing Failover
F
A
I
L
O
V
E
R
Y
R
A
M
I
R
P
Primary end
F
A
I
L
O
V
E
R
Y
R
A
D
N
O
C
E
S
12395
Secondary end
Step 3
Connect the Primary end of the Failover cable to the first PIX security appliance unit, that is, the one
you have already configured.
Step 4Connect the Secondary end of the Failover cable to the standby unit.
Step 5Connect a power cord to the power connector on the rear panel of each unit, and the other end of each
power cord to (preferably separate) power outlets.
Step 6If you are using Stateful Failover, use one of the following types of connections, that is appropriate for
your system, between the dedicated interfaces on the PIX security appliance units:
• 100BaseTX half-duplex hub using straight Category 5 cables.
• 100BaseTX full duplex on a dedicated switch or dedicated VLAN of a switch.
• All enabled interfaces must be connected between the active and standby units. Only configure the
active unit. On the PIX 520, you can access the console and determine which unit is active with the
show failover command in the command reference online at:
CautionDo not turn the power on until the units are connected and the primary unit is configured completely.
Step 7Use the power switch at the back of the units to power the primary unit on and then power on the standby
unit.
Within a few seconds, the active unit automatically downloads its configuration to the standby unit.
If the primary unit fails, the secondary unit automatically becomes active.
Installing LAN-Based Failover
LAN-based failover supports failover between two units connected over a dedicated Ethernet interface.
LAN-based failover eliminates the need for a special Failover cable and overcomes the distance
limitations imposed by the Failover cable.
For information on configuring a LAN-based failover, refer to the configuration guide online at:
If you are using Stateful Failover, use one of the following types of connections, that is appropriate for
your system, between the dedicated interfaces on the PIX security appliances:
• 100BaseTX full duplex on a dedicated switch or dedicated VLAN of a switch.
• 1000BaseSX full duplex on a dedicated switch or dedicated VLAN of a switch.
NoteFor Stateful Failover on the PIX 520, if you have Gigabit Ethernet (GE) interfaces,
then the failover link must be GE.
CautionDo not turn the power on until the units are connected and the primary unit is configured completely.
Step 6Power the primary unit on first, then power on the secondary unit. Within a few seconds, the active unit
automatically downloads its configuration to the standby unit.
If the primary unit fails, the secondary unit automatically becomes active.
The PIX security appliance has a lithium battery on its main circuit board. This battery has an operating
life of about ten years. When the battery loses its charge, the PIX security appliance cannot function.
The lithium battery is not a field-replacable unit (FRU). Contact Cisco TAC to replace the battery.
NoteDo not attempt to replace this battery yourself.
Chapter 5 PIX 520
Warning
Danger of explosion exists if the lithium battery is incorrectly replaced. Replace only with the same
or equivalent type recommended by the manufacturer. Dispose of used batteries according to the
manufacturer's instructions.
Installing a Memory Upgrade
Observe the following warnings, cautions, and notes when installing additional PIX security appliance
system memory.
The following statement applies to DC models:
Warning
Warning
Before performing any of the following procedures, ensure that power is removed from the DC circuit.
To ensure that all power is OFF, locate the circuit breaker on the panel board that services the DC
circuit, switch the circuit breaker to the OFF position, and tape the switch handle of the circuit
breaker in the OFF position.
The following statement applies to both AC and DC models:
Before working on a system that has an On/Off switch, turn OFF the power and unplug the power cord.
CautionAlways remove old memory before installing new memory.
NoteAfter installing additional memory in the PIX 520, do not remove the memory strips and power on the
unit, or the PIX security appliance will become inoperable.
CautionIf you remove the PIX security appliance chassis chassis cover, always reinstall the chassis cover. Running
the PIX security appliance without the chassis cover causes overheating and damage to electrical components.
To install additional system memory, perform the following steps:
Step 1If the unit is rack-mounted, remove network wires and any cords connecting to the PIX security
appliance. The PIX 520 should be removed from the rack and placed on a stable working surface. Ensure
that the unit is unplugged from its power source.
Step 2Unpack the items in the memory upgrade kit.
Remove the chassis cover from the PIX security appliance. Remove all screws holding the assembly in
place. Refer to the “Removing and Replacing the PIX 520 Chassis Cover” section on page 5-10 for more
information.
Step 3Determine the location of your system memory sockets (see Figure 5-14).
Step 4Use the markings on the motherboard to determine the socket numbers. Always install the first memory
strip into the lowest socket number. Progressively add memory boards into higher numbered sockets.
Figure 5-14 PIX 520 System Memory Location
Installing a Memory Upgrade
Bank 0
Bank 1
Bank 2
17996
Front
Step 5Locate the wrist grounding strap in the accessory kit and connect one end to the unit as shown in
Figure 5-17, or to the PIX security appliance chassis, and securely attach the other to your wrist so it
contacts your bare skin.
Step 6With the wrist strap on your wrist, carefully grasp the memory strip from either end. Note that a DIMM
strip has notches.
Step 7To install a DIMM strip:
• Remove the old memory strip by opening the two plastic wing connectors, and pulling the old strip
up. Discard the old strip.
• When installing the memory strip in the PIX 520, install the new strip in Bank 0 as shown in
Figure 5-15 and Figure 5-16, by opening the two plastic wing connectors, inserting the strip, and
Figure 5-15 Inserting a DIMM Memory Strip in the PIX 520
Bank 2
Bank 1
Chapter 5 PIX 520
DIMM
17997
Bank 0
Figure 5-16 Securing a DIMM Memory Strip in the PIX 520
17998
Bank 2
Bank 1
Bank 0
• When you finish inserting new RAM memory, replace the chassis cover on the chassis. Reattach the
screws. If desired, rack mount the PIX security appliance and attach all cables and cords as
discussed in previous sections. After the PIX security appliance is installed, you can view the
amount of RAM memory in the system startup messages or with the show version command in the
The information in this section refers to the installation of a circuit board in the PIX 520.
The 4-port 64 bit/66 MHz FE card (PIX-4FE-66) is supported in software Versions 6.3, 6.2(2), 6.1(4),
and 5.2(9), and later versions. These are the minimum software versions that support the card.
NoteThe PIX-4FE card continues to be supported but is no longer manufactured.
The new card has the following characteristics:
• Includes an Intel 21154BE bridge and 4 Intel 82559 ethernet mac/phy devices.
• Supports 10/100mbps full/half-duplex operation on each port.
• Retains bus performance when installed with other 66 MHz devices.
• Does not support auto MDI/MDIX operation.
This section includes the following topics:
• 16 MB Flash Circuit Board, page 5-18
• VPN Accelerator Circuit Board, page 5-19
• Gigabit Ethernet Circuit Board, page 5-20
Installing a Circuit Board in the PIX 520
• Installing the PIX 520 DC Model, page 5-21
To install a circuit board in the PIX 520, perform the following steps:
Step 1Locate the grounding strap from the accessory kit. Fasten the grounding strap to your wrist so that it
contacts your bare skin. Attach the other end to bare metal inside the PIX security appliance chassis as
shown in Figure 5-17.
Figure 5-17 Attaching Grounding Strap to Your Wrist and to the PIX Security Appliance
Along with upgrading your Flash memory to 16 MB, the PIX security appliance 16 MB Flash circuit
board includes pre-installed PIX security appliance software and a UR (unrestricted) 56-bit DES
encryption license. The 16 MB Flash circuit board installs into the PIX security appliance ISA slot.
An illustration of the 16 MB Flash circuit board is shown in Figure 5-21.
Use the following information to install a 16 MB Flash circuit board:
• The PIX security appliance must have a minimum of 32 MB of RAM memory.
• You must obtain a new activation key if you will be using 3DES.
• The PIX security appliance should not be downgraded to a software revision lower than 5.0(3) after
the new software from the 16 MB circuit board is installed.
• If you downgrade from software Version 5.3 to 5.2 or lower, you will lose private data (keys,
certifications, and CRLs) that are stored in Flash memory. You need to use the clear flashfs
command, downgrade 5.0 | 5.1 | 5.2 options if your PIX security appliance has 16 MB Flash
memory, private data stored in the Flash memory, and you used the ca save all command to save
these items in Flash memory.
Step 1Record the present PIX security appliance unit serial number.
Step 2Record the new serial number from the 16 MB Flash circuit board.
Step 3Create a backup of your present configuration (to use later to reconfigure your system).
Step 4Obtain a new Activation key (if using 3DES).
Step 5Remove any previously installed Flash memory circuit boards from the unit.
CautionDo not remove or reposition the 16 MB Flash circuit board. The PIX security appliance will not work if
Step 6Install the 16 MB Flash circuit board into an available ISA slot in the PIX security appliance chassis.
Installing a Circuit Board in the PIX 520
To install the 16 MB Flash circuit board, perform the following steps:
NoteAfter installation, the serial number of the PIX security appliance changes to the serial number
supplied with the 16 MB Flash circuit board.
this jumper is moved.
VPN Accelerator Circuit Board
The VPN Accelerator (PIX-VPN-ACCEL) is an encryption and accelerator circuit board. The VPN
Accelerator uses a PCI interface and therefore can only be installed in PIX security appliance platforms
with PCI slots. The VPN Accelerator begins to function immediately after installation without the need
of special installation configurations.
NoteThe new VPN Accelerator cannot be used with the former PIX security appliance IPSec accelerator in
the same chassis. The PIX security appliance IPSec accelerator was also known as the Private Link card.
An illustration of the VPN Accelerator is shown in Figure 5-22.
Figure 5-22 VPN Accelerator Circuit Board
Chapter 5 PIX 520
61921
Gigabit Ethernet Circuit Board
PIX security appliance supports 1000 Mbps (Gigabit) Ethernet. The Gigabit Ethernet circuit board uses
only has one hardware speed and the following duplex options:
The Gigabit Ethernet circuit board and the fiber optic cable connection are shown in Figure 5-23.
Figure 5-23 Gigabit Ethernet Circuit Board
33010
TX
RX
LINK
The Gigabit Ethernet circuit board has three LEDs:
• TX—Transmitting data
• RX—Receiving data
• LINK—The Gigabit Ethernet circuit board has established a network connection
Installing the PIX 520 DC Model
Warning
Step 1Read the Regulatory Compliance and Safety Information document.
Step 2Terminate the DC input wiring on a DC source capable of supplying at least 15 amps. A 15-amp circuit
Step 3Be sure the PIX 520 power is off by checking the power switch at the rear of the unit.
Before performing any of the following procedures, ensure that power is removed from the DC circuit.
To ensure that all power is OFF, locate the circuit breaker on the panel board that services the DC
circuit, switch the circuit breaker to the OFF position, and tape the switch handle of the circuit
breaker in the OFF position.
To install the PIX 520 DC power model, perform the following steps:
breaker is required at the 48 VDC facility power source. An easily accessible disconnect device should
be incorporated into the facility wiring.
Step 4As shown in Figure 5-24, the PIX 520 is equipped with two grounding studs at the back of the unit,
which you can use to connect a two-hole grounding lug to the PIX 520. Use the 10-32 nuts provided with
the PIX 520 to connect a copper standard barrel grounding lug to the studs. The PIX 520 requires a lug
where the distance between the center of each hole is 0.56 inches. A lug is not supplied with the PIX 520.
Figure 5-24 Attaching a Grounding Lug to the PIX Security Appliance
PIX security appliance
Rear of
Chapter 5 PIX 520
–
+
11827
To ra c k
ground
10-32 nuts
2-hole copper
standard barrel
grounding lug
Grounding studs
on PIX DC model
Step 5Ensure that power is removed from the DC circuit. To ensure that all power is OFF, locate the circuit
breaker on the panel board that services the DC circuit, switch the circuit breaker to the OFF position,
and tape the switch handle of the circuit breaker in the OFF position.
Step 6Strip the ends of the wires for insertion into the power connect lugs on the PIX 520.
Step 7Insert the ground wire into the connector for the earth ground and tighten the screw on the connector (see
Figure 5-25). Using the same method as for the ground wire, connect the negative wire and then the