1、模拟的方法
模拟的方法很简单,从网上下载pix的IOS(是.bin格式的文件),然后在GNS3的“编辑”–>“首选项”–>”Qemu”–>”PIX”,在binary p_w_picpath中设置相应IOS文件即可。
[PIX的设置界面]
2. PIX的激活
要完全使用PIX的功能,需要激活PIX,激活方法如下(引用自网络):
pixfirewall> en
Password:
pixfirewall# sh version
Cisco PIX Security Appliance Software Version 7.2(2)
Compiled on Wed 22-Nov-06 14:16 by builders
System p_w_picpath file is “Unknown, monitor mode tftp booted p_w_picpath”
Config file at boot was “startup-config”
pixfirewall up 3 mins 23 secs
Hardware: PIX-525, 256 MB RAM, CPU Pentium II 1 MHz
Flash E28F128J3 @ 0xfff00000, 16MB
BIOS Flash AM29F400B @ 0xfffd8000, 32KB
0: Ext: Ethernet0 : address is 0000.abcd.ef00, irq 9
1: Ext: Ethernet1 : address is 0000.abcd.ef01, irq 11
2: Ext: Ethernet2 : address is 0000.abcd.ef02, irq 11
3: Ext: Ethernet3 : address is 0000.abcd.ef03, irq 11
4: Ext: Ethernet4 : address is 0000.abcd.ef04, irq 11
The Running Activation Key is not valid, using default settings:
Licensed features for this platform:
Maximum Physical Interfaces : 6
Maximum VLANs : 25
Inside Hosts : Unlimited
Failover : Disabled //Failover 不可用
×××-DES : Disabled
×××-3DES-AES : Disabled
Cut-through Proxy : Enabled
Guards : Enabled
URL Filtering : Enabled
Security Contexts : 0
GTP/GPRS : Disabled
××× Peers : Unlimited
This platform has a Restricted (R) license.
Serial Number: 808102688 //序列号
Running Activation Key: 0×00000000 0×00000000 0×00000000 0×00000000 0×00000000 //激活码
Configuration has not been modified since last system restart.
pixfirewall# activation-key 0xd2390d2c 0×9fc4b36d 0×98442d99 0xeef7d8b1 //输入激活码
The following features available in flash activation key are NOT
available in new activation key:
Failover is different.
flash activation key: Restricted(R)
new activation key: Unrestricted(UR)
Proceed with update flash activation key? [confirm]
The following features available in running activation key are NOT
available in new activation key:
Failover is different.
running activation key: Restricted(R)
new activation key: Unrestricted(UR)
WARNING: The running activation key was not updated with the requested key.
The flash activation key was updated with the requested key, and will
become active after the next reload.
pixfirewall# write //保存配置
Building configuration…
Cryptochecksum: 70b1d47e d807251d 47f50cb7 f851d390
1226 bytes copied in 0.800 secs
[OK]
然后在GNS3中直接停掉PIX,重新启动即可,不能reload。
下面是重启后的
pixfirewall> en
Password:
pixfirewall# sh version
Cisco PIX Security Appliance Software Version 7.2(2)
Compiled on Wed 22-Nov-06 14:16 by builders
System p_w_picpath file is “Unknown, monitor mode tftp booted p_w_picpath”
Config file at boot was “startup-config”
pixfirewall up 17 secs
Hardware: PIX-525, 256 MB RAM, CPU Pentium II 1 MHz
Flash E28F128J3 @ 0xfff00000, 16MB
BIOS Flash AM29F400B @ 0xfffd8000, 32KB
0: Ext: Ethernet0 : address is 0000.abcd.ef00, irq 9
1: Ext: Ethernet1 : address is 0000.abcd.ef01, irq 11
2: Ext: Ethernet2 : address is 0000.abcd.ef02, irq 11
3: Ext: Ethernet3 : address is 0000.abcd.ef03, irq 11
4: Ext: Ethernet4 : address is 0000.abcd.ef04, irq 11
Licensed features for this platform:
Maximum Physical Interfaces : 10
Maximum VLANs : 100
Inside Hosts : Unlimited
Failover : Active/Active
×××-DES : Enabled
×××-3DES-AES : Enabled
Cut-through Proxy : Enabled
Guards : Enabled
URL Filtering : Enabled
Security Contexts : 2
GTP/GPRS : Disabled
××× Peers : Unlimited
This platform has an Unrestricted (UR) license.
Serial Number: 808102688
Running Activation Key: 0xd2390d2c 0×9fc4b36d 0×98442d99 0xeef7d8b1
Configuration has not been modified since last system restart.
附上我找到的PIX序列号&激活码
Serial Number: 0x302aab20
Running Activation Key: 0xd2390d2c 0×9fc4b36d 0×98442d99 0xeef7d8b1
Serial Number: 807211225 转成十六进制后:0x301D10D9
Running Activation Key: 0×5236f5a7 0×97def6da 0×732a91f5 0xf5deef57
Serial Number: 808181272 转成十六进制后:0x302BDE18
Running Activation Key: 0×052a1524 0×3712a12b 0xb636cc54 0xa178eeac
3、修改PIX Serial Number,套用已有激活码激活PIX
通常无法获得与上文中相同的Serial Number,那么也就没办法使用对应的激活码了。但是,我们可以通过修改GNS3中的PIX参数来修改PIX的Serial Number, 这样,我们就可以使用已有的激活码了。
具体操作:
方法一:
“编辑”–>“首选项”–>”Qemu”–>”PIX”–>”PIX Specific Settings”—>”Serial” 注意:要把上面的serial number中的十进制转成十六进制。用系统计算器就能完成:Windows键+R,输入calc,确定。
点击左上角“查看”--》“程序员”。将十进制数贴进去,点击左侧十六进制,结果出来了。
方法二:
进入设置的Qemu的工作目录,找到FW1目录,修改该目录下的pemu.ini文件中相应的内容
注:只有在GNS中创建了PIX防火墙,才会有FW1目录产生。以此类推,若创建了多个PIX,则就会产生FW2,FW3…等多个目录。
至此,大功告成。