*Note: The article presented here is written by authors not affiliated with hashemian.com.
This site is not responsible for any errors, omissions, or objectionable content.
Exercise care before engaging in business with any companies mentioned in this article.

Go to: /articles/2007/11/16/ for other articles.

Cisco PIX/ASA Security Appliance: How to Configure Banners

Cisco PIX/ASA Security Appliance: How to Configure Banners Banners can be configured to display when a user first connects (MOTD), when a user logs in (login), or when a user accesses privileged mode (exec). Banners are used for legal warnings such as when a user is cautioned not to access a restricted system or that their access of a system is subject to monitoring and logging. Banners are also used on locked systems placed at customer locations by service providers to provide contact information for device access or technical support. The Cisco security appliance supports the use of login banners in console sessions and Telnet sessions, but not in SSH sessions. Exec and MOTD banners are supported in console, Telnet, and SSH sessions. Banners can be up to 510 characters in length. You can create multiple line banners either by creating multiple banner statements or by using the keystroke sequence of "\n" which inserts a carriage return.

Here's how banners are displayed:

MOTD Banners--When usernames are not configured, MOTD displays at login in a serial console session and before login in Telnet sessions. When usernames are configured, MOTD displays before login in a Telnet session and after login in a serial console session.

Login Banners--The login banner displays before login in Telnet and serial console sessions.

Exec Banners--The exec banner displays upon login in all sessions.

How to Configure a Banner

Note: The following procedures were tested on an ASA 5505 Security Appliance running software version 7.22. Other hardware or software platforms may require modification of these procedures in order to function properly.

To configure a banner, use the following configuration mode commands:

asa(config)#banner motd This is a restricted system. asa(config)#banner motd Do not attempt unauthorized access.

Notice the use of two banner motd statements to create a multi-line banner. As mentioned previously, you can also use the "\n" key sequence to insert a carriage return.

You can view the banners you created with the following privileged mode command:

asa#show running-config banner

Hands-On Exercise: Creating Banners on the Security Appliance

The following procedures are for training purposes only and should only be performed on devices in a laboratory environment. Under no circumstances should these procedures be performed on equipment in a live, production environment without first verifying their suitability in a laboratory environment.

In the following hands-on exercise, you will create MOTD, login, and EXEC banners.

Step 1: In configuration mode, enter the following commands:

asa(config)#banner motd This is the MOTD banner asa(config)#banner login This is the login banner asa(config)#banner exec This is the EXEC banner

Step 2: Display the banners you just created with the following command:

asa(config)#show running-config banner

Step 3: Type exit repeatedly until you are logged out of your laboratory security appliance.

Notice which banners are displayed.

Step 4: Enter privileged mode with the command "enable" and notice which banners are displayed.

Step 5: From your laboratory computer, start a Telnet session and again observe which banners are displayed. When you are finished, exit the Telnet session.

Step 6: Also from your laboratory computer, start an SSH session and again observe which banners are displayed. When you are finished, exit the SSH session.

Note: The above procedures are similar to the procedures used to configure banners on other Cisco devices including routers.

About the Author:

Visit www.soundtraining.net to learn more about soundtraining.net's business skills training programs for IT professionals, plus accelerated technical training programs for IT professionals in the areas of Cisco, Microsoft, and Linux products. To learn more about soundtraining.net's Two-Day Cisco PIX/ASA Firewall hands-on seminar, visit www.soundtraining.net/onlinestore/categories/category 34.html


Article Topics
Adsense Advertising Bankruptcy Blog Credit Card
Debt Google Ira Marketing Mortgage
Real Estate Rental Retirement Rss Search Engine
Seo Stocks Tax
Recent Articles

Read Financial Markets  |   Home  |   Blog  |   Web Tools  |   News  |   Articles  |   FAQ  |   About  |   Contact

© 2001-2009 Robert Vahid Hashemian
Support the effort
Liked this page?
Please consider creating a link to it
from your Web site.

hashemian.com
هاشمیان.com

 Home

 Blog

 Web Tools Add Free Web Tools custom Google Toolbar button (Requires Toolbar >V4)
Usage

 News

 Articles

 FAQ

 About

 Contact

 Financial Markets Book
Read Complete Book



BOOK
Hot, Flat, and Crowded: Why We Need a Green Revolution--and How It Can Renew America
Thomas L. Friedman
$27.95


BOOK
The Motley Fool Million Dollar Portfolio: How to Build and Grow a Panic-Proof Investment Portfolio
Tom Gardner
$26.99


BOOK
Cisco ASA, PIX, and FWSM Firewall Handbook (2nd Edition) (Networking Technology: Security)
Dave Hucaby
$65.00


BOOK
Tricky Pix: Do It Yourself Trick Photography With Camera [colors may vary] (Klutz)
Carla Jimison
$19.95


BOOK
The Forever War
Dexter Filkins
$25.00

|cisco-pix-asa-security-appliance-how-configure-banners|

more…




Get Kindle

aStore - Hashemian.com on Amazon

Visits: Powered by hashemian.com

 

 

 

 

 

Search Hashemian.com





IBM T40 14" Intel MotherBoard 91P7993 w/Security TESTED
$54.00
Ends: Mon Jan 12, 2009 12:40:29 EST


IBM T40 14" Intel MotherBoard 91P7709 w Security TESTED
$79.00
Ends: Mon Jan 12, 2009 12:40:35 EST


Cisco 2500 Series Router Model 2524
$24.99
Ends: Mon Jan 12, 2009 12:40:44 EST


IBM T40 14" Intel MotherBoard 91P7709 w Security TESTED
$79.00
Ends: Mon Jan 12, 2009 12:40:44 EST


IBM T42/41/40 14" MotherBoard 27K9980 w/Security TESTED
$109.00
Ends: Mon Jan 12, 2009 12:41:08 EST

more…