Transcription of Downloading and Installing Cisco Security Device Manager ...
1 Corporate Headquarters:Copyright 2003 Cisco Systems, Inc. All rights Systems, Inc., 170 West Tasman Drive, San Jose, CA 95134-1706 USAD ownloading and Installing Cisco SecurityDevice Manager (SDM) Version document contains instructions on Downloading Cisco Security Device Manager (SDM) version the web site and Installing it onto your router. This document is updated as document contains the following sections: About SDM Installing SDM Upgrading SDM on a Router With an Earlier Version of SDM Launching SDM Related DocumentationAbout SDMSDM is an easy-to-use, java-based Device management tool, designed for configuring LAN, WAN, andsecurity features on a router. SDM is designed for resellers and network administrators of small- tomedium-sized businesses who are proficient in basic network fast and efficient configuration of Ethernet networks, WAN connectivity, firewalls and VirtualPrivate Networks (VPNs), Cisco SDM prompts you through the setup process with wizards.
2 Cisco SDMrequires no previous experience with Cisco devices or the Cisco command-line interface (CLI).SDM resides in your router s Flash memory, but when invoked, it is downloaded and run from a your PCusing a web browser. To determine whether or not your router hardware, Cisco IOS version, PChardware, and web browser are supported by SDM, refer to the following sections: Cisco Routers and Cisco IOS Versions Supported PC System Requirements Browser Requirements2 Downloading and Installing Cisco Security Device Manager (SDM) Version SDMC isco Routers and Cisco IOS Versions SupportedTable 1 lists the routers and Cisco IOS versions supported by SDM version information about supported network modules and WAN interface cards (WICs), refer to the Security Device Manager Version Release Notes. PC System RequirementsSDM is designed to run on a personal computer that has a Pentium III or higher processor and that isrunning any of the following operating systems: Windows NT workstation with Service Pack 4 Windows 98 (second edition) Windows 2000 Windows ME Windows XPTable 1 SDM-Supported Routers and Cisco IOS VersionsSDM-Supported RoutersSDM-Supported Cisco IOS VersionsCisco 831, 836, and (13)ZH or 1701, 1710, 1721, 1751, 1751-v ,1760, and1760-v (13)ZH, or later (13)T3 or later (1)M or later (11)T6 not supportedCisco 1711 and 1712 (15)ZLCisco 2610XM, 2611XM, 2620XM, 2621XM,2650XM, 2651XM, and 2691 (11)T6 or later (1)M or later (13)T3 not supported1 (13)ZJ1.
3 (13)T3 will be supported in the next release of SDM, which will be available in July 3620, 3640, 3640A, 3661, and 3662 (11)T6 or later (1)M or later (13)T3 not supported1 Cisco 3725 and 3745 (11)T6 or later (1)M or later (13)T3 not supported13 Downloading and Installing Cisco Security Device Manager (SDM) Version SDMB rowser RequirementsSDM supports the following browsers: Netscape version with Java support or with Java plug-in JRE version or later Internet Explorer version or later with Java support or with Java plug-in JRE version orlaterInstalling SDMSDM comes preinstalled on all supported routers manufactured in June 2003 or later that were purchasedwith the VPN bundle. SDM is also available as a separate option on all supported routers manufacturedin June 2003 or later. If you have a router that does not have SDM installed, and would like to use SDM,you must download it from the website and install SDM on your you purchased a router on which SDM came pre-installed, you do not need to download and installSDM.
4 For instructions on starting SDM, see the Launching SDM information on how to determine whether or not SDM is installed on your router, refer to the FAQdocument, available section contains instructions for the following: Configuring Your Router to Support SDM Downloading the SDM Files and a Cisco IOS Image to a TFTP Server Downloading the Cisco IOS Image to Your Router Downloading the SDM Files to a Cisco 1700, 2600, 3600, or 3700 Series RouterConfiguring Your Router to Support SDMB efore SDM can run on your router, a few configuration options must be present in the routerconfiguration file. There are several default router configuration files included in the SDM download can either use one of these default configuration files, or modify your existing configuration fileusing the router CLI to ensure that your router configuration supports and Installing Cisco Security Device Manager (SDM) Version SDMM odifying Your Existing Configuration FileBefore Installing SDM onto your router, access the CLI using Telnet or the console connection to modifythe existing configuration file on your router.
5 SDM requires that the following commands are present inyour router configuration file: The router HTTP/HTTPS server must be enabled, using the following Cisco IOS commands:ip http serverip http secure-serverip http authentication local SDM requires a user account defined with privilege level 15 (enable privileges):username sdm privilege 15 password 0 sdmNoteFor Security purposes, the user account defined should be different than the default one usedin the example above. SSH/Telnet must be configured for local login and privilege level 15:line vty 0 4 privilege level 15 login local transport input telnet transport input telnet ssh Local logging should (optionally) be enabled to support the log monitoring function:logging buffered 51200 warningIf you use your existing configuration file, SDM will not display the Startup Wizard the first time yourun SDM.
6 It is assumed that you have already done basic network a Default Configuration FileIncluded in the SDM download file are several default configuration files. See the table below todetermine which configuration file should be used for your router:When following the instructions to download the SDM files to your router, use the default configurationfile that is listed for your 2 Supplied Default Configuration FilesRouterUse This Configuration FileCisco 831, 836, or 1701, 1710, or 1711 or 1751 or 2610XM, 2611XM, 2620XM, 2621XM, 2650XM, 2651XM,or 3620, 3640, 3640A, 3661, 3662, 3725, or and Installing Cisco Security Device Manager (SDM) Version SDMIf you use a default configuration file, SDM will display the Startup Wizard, letting you enter basicnetwork configuration information, the first time you run the SDM Files and a Cisco IOS Image to a TFTP ServerIf you have a router manufactured before June 2003, you may need to upgrade your Cisco IOS softwareto a version that supports SDM.
7 To determine whether or not your version of Cisco IOS supports SDM,see the Cisco Routers and Cisco IOS Versions Supported section on page section contains instructions for Downloading both SDM and an upgraded version of Cisco IOSfrom the web site. If you do not need to upgrade your Cisco IOS software, follow only theinstructions for Downloading files are contained in a .zip file that is available on In order to open this type of file andextract the SDM files, you must have the WinZip utility installed on your PC. You can obtain Winzip byfollowing the link 1On your PC, open a web the following URL into your web browser: 2 Log in using your login user identification and password, and follow the instructions on theSDM Software page to download the SDM .zip file ( ).NoteIt is recommended that you also download and read the SDM version Release Notes.
8 Thatdocument is also available at the following URL: 3 Double-click the file and extract the files , , and files to the root directory of a TFTP server. The TFTP server can be a PC with aTFTP server utility. If you need assistance extracting the files to the directory you want to place themin, refer to the WinZip online you do not need to upgrade your Cisco IOS version, you are now ready to download the SDM files toyour router. Skip to the Downloading the SDM Files to a Cisco 1700, 2600, 3600, or 3700 SeriesRouter section on page 6, or to the Downloading the SDM Files to a Cisco 831, 836, or 837 Router section on page 7, depending on the type of router that you 4If you need to upgrade your Cisco IOS version, enter the following URL into your web browser to accessthe Cisco IOS software center: 5 Follow the links on the page to download an upgraded version of Cisco IOS software.
9 See the CiscoRouters and Cisco IOS Versions Supported section on page 2 to ensure that you are Downloading anSDM-supported Cisco IOS 6 Save the Cisco IOS image file to a TFTP and Installing Cisco Security Device Manager (SDM) Version SDMSDM and the upgraded Cisco IOS image are now downloaded to the TFTP server. To download the CiscoIOS image to your router, proceed to the Downloading the Cisco IOS Image to Your Router the Cisco IOS Image to Your RouterTo download the Cisco IOS image to your section describes one way to upgrade your Cisco IOS software. You may also want to view thedocument Software Installation and Upgrade Procedure to view alternative procedures, particularly ifyou have a router using PCMCIA Flash you did not download an upgraded version of the Cisco IOS software, do not follow the instructionsin this section.
10 Skip to the Downloading the SDM Files to a Cisco 1700, 2600, 3600, or 3700 SeriesRouter section on page 6 to continue the installation 1 Access the router CLI using a Telnet connection or the console 2 Delete your old Cisco IOS image from Flash memory, using the following CLI commands, andresponding to the prompts as shown:Router#delete<old IOS image name>Delete filename [<old IOS image name>]?yDelete flash:y? [confirm]nDelete flash:y aborted!Router#squeeze flash:Step 3 Copy the Cisco IOS image to the router Flash memory, using the following CLI command:Router#copy tftp://<tftp server IP address>/<new IOS image name> flash:When prompted do NOT erase the Flash 4 Reboot the router to use the new Cisco IOS image using the following CLI command:Router#reloadThe new Cisco IOS image is now installed on your router.