ASA 5510 IOS的恢复方法:
1、flash卡拷贝
2.通过usb拷贝
3.通过线缆tftp拷贝
具体实施方法:
1.对于没有ios的系统,会不断重启,直到中断系统,进入rommon模式。
Use BREAK or ESC to interrupt boot.
Use SPACE to begin boot immediately.
Boot interrupted.
2.进入rommon模式以后,给这个微系统配置ip地址,网关、tftp服务器,接口等。为和服务器的同步做准备:
ADDRESS=192.168.8.40
SERVER=192.168.8.44
GATEWAY=192.168.8.44
PORT=Management0/0 【pc要和m0/0相连】
IMAGE=asa803-k8.bin
3。测试和pc的互通性
ping 192.168.8.44 !!!!!!!!!!!!!!!!
4.保存并下载
rommon #4> sync
rommon #4> tftpdnld
rommon #5> tftpdnld
ROMMON Variable Settings:
ADDRESS=192.168.8.40
SERVER=192.168.8.44
GATEWAY=192.168.8.44
PORT=Management0/0
VLAN=untagged
IMAGE=asa803-k8.bin
CONFIG=
LINKTIMEOUT=200
PKTTIMEOUT=4
RETRY=20
tftp [email protected] via 192.168.8.44
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
5.这个过程并不是下载tftp服务器上的ios,而是从服务上引导asa启动,在asa硬盘中没有ios。
ciscoasa# dir
Directory of disk0:/
2 drwx 4096 00:04:38 Jan 01 2003 log
6 drwx 4096 00:04:51 Jan 01 2003 crypto_archive
6.我们最现有引导的系统进行配置,copy tftp到disk0中。
现在asa上配置地址,其中asa上的e0/0上的地址是192.168.8.40.pc是192.168.8.44.
ciscoasa(config)# int e0/0
ciscoasa(config-if)# nameif outside
INFO: Security level for "outside" set to 0 by default.
ciscoasa(config-if)# ip address 192.168.8.40 255.255.255.0
ciscoasa(config-if)# no sh
注意,把pc对端从m0/0换到e0/0口上去,并且检查一下,asa和pc的连通性。
ciscoasa# ping 192.168.8.44
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.8.44, timeout is 2 seconds:
!!!!!
7。开始copy tftp到disk0上
ciscoasa# copy tftp: disk0:/
完毕!!!!!!!!!!!