On Wed, 5 Dec 2007, Eric Van Tol wrote:

>> From: [EMAIL PROTECTED]
>> [mailto:[EMAIL PROTECTED] On Behalf Of Marc Haber
>>
>> Actually, I do not care about seeing the keys, I care about pulling
>> the configuration from the box in an automated, secure way with least
>> possible privileges.
>
> I could be wrong, but I believe that the PIX/ASA configuration can be
> seen via the internal web server.  It's encrypted via SSL, so a wget
> should work, if it's compiled with SSL support.

The last time I had to do this I ended up writing an expect script to log 
into the device and pull the config down that way.  At the time there 
wasn't a way to initiate the download using SNMP and SCP.

It was ugly, but it worked once I wrote in some better error-handling :)

jms
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to