Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

pix 506e: PDM -> "policy NAT" error problem

Status
Not open for further replies.

dgr72371

Programmer
Jan 13, 2005
35
US
Hello,
We have at my office a Cisco PIX 506e and until recently I haven't had to do only limited telnet-access maintenance. My supervisor now wants me to go through a browser and the PDM and pull Attack reports, make configuration changes, etc. I've run into a problem when logging into the unit to get to the java applet PDM. After a few moments the Cisco PIX Device Manager 3.0 window will appear (I had to go in my browser's advanced settings and deselect the Use JRE check box so the internal IE Java would be used BTW or it would never get as far as the smaller Java window appearing), then a smaller Java window appears where it was loading the current configuration from the firewall, then after another few moments the below Error window appeared talking about a Unsupported Command Found...PDM doesn't support "policy NAT" commands in your config...etc. etc. Then the IE "encountered a problem" window appeared and the whole web browser & Java window crash shortly thereafter.
It sounds like from reading what was in the UCF error window that I have to telnet to the PIX and type in some commands to fix this "policy NAT" issue.
What commands do I type or is there some other way to fix thus Unsupported Command Found issue so I will have have full access to the PDM and be able to make configuration changes?
thanks,
binary7
 
The PDM sucks on the 506E and is almost unusable. I would upgrade to an asa 5505 and enjoy the new features.
 
brianinms,
hello,
unfortunately I'm not the one in my office that can make the purchase decision on a new firewall, and I'm pretty sure my boss wants to stick with the 506E that we have, because of some special configurations we have in in (tunnels to clients, etc.)
Is there a way to make the 506e run better than it is now?
thanks,
david
 
The issue you are actually having is a Java issue with your workstation. There are no "attack events" to monitor in the PDM, so I am slightly confused by your bosses request.
 
Hi,

Upgrade Java to the latest release on the PC (better still, do this from another PC as it looks like yours has IE issues). I can't see a reason why the PDM shouldn't work like it does on any other Pix - I've used it extensively on 501's and 515's with no problems.

Regards Colin.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top