
32-9
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 32 Monitoring and Troubleshooting
Troubleshooting the Security Appliance
Disabling the Test Configuration
After you complete your testing, disable the test configuration that allows ICMP to and through the
security appliance and that prints debug messages. If you leave this configuration in place, it can pose a
serious security risk. Debug messages also slow the security appliance performance.
To disable the test configuration, perform the following steps:
Step 1 To disable ICMP debug messages, enter the following command:
hostname(config)# no debug icmp trace
Step 2 To disable logging, if desired, enter the following command:
hostname(config)# no logging on
Step 3 To remove the ICMPACL access list, and also delete the related access-group commands, enter the
following command:
hostname(config)# no access-list ICMPACL
Step 4 (Optional) To disable the ICMP inspection engine, enter the following command:
hostname(config)# no service-map ICMP-POLICY
Reloading the Security Appliance
In multiple mode, you can only reload from the system execution space. To reload the security appliance,
enter the following command:
hostname# reload
Performing Password Recovery
This section describes how to recover if you forget passwords, or you create a lockout situation because
of AAA settings. You can also disable password recovery for extra security. This section includes the
following topics:
• Password Recovery for the PIX 500 Series Security Appliance, page 32-10
• Disabling Password Recovery, page 32-11
Komentarze do niniejszej Instrukcji