Does RANCID handle Cisco PIX devices?

Hopper, Faron W. faron.hopper at
Tue Dec 28 17:19:19 UTC 2004

Hello all,  I am still exploring RANCID's capabilities.  Does it have
the ablility
to back up Cisco PIX configs?  I have added the one of our PIX's names
the router.db file and set the type to


thinking that it would be closer to
the catOS command line.  This is not successful.  I am using TACACS+ on
the PIX, and here is an example of what I get if I manually ssh into it.

    $ ssh -l net\-cfg\-bak
    net-cfg-bak at's password:
    Type help or '?' for a list of available commands.
    PIXHQ> en
    Password: ********

in my dead.letter file this is the message I get for the 2 PIXes

    From: Network Config Backup <net-cfg-bak>
    Message-Id: <200412282250.iBSMoOnX027862 at>
    To: rancid-fi
    Subject: config fetcher problems - fi
    Precedence: bulk

    The following routers have not been successfully contacted for
    more than 4 hours.
    -rw-r-----  1 net-cfg-bak  wheel  0 Dec 13 16:23 pixhq
    -rw-r-----  1 net-cfg-bak  wheel  0 Dec 13 16:23 pixhq2

If I use the clogin program, I can get the level 1 login prompt, but it
is not executing my show version.
This makes me think that it is waiting on some type of prompt character
that is not defined (just guessing).

    $ /usr/local/libexec/rancid/clogin -c "show version" -f
    spawn telnet
    telnet: connect to address Connection refused
    telnet: Unable to connect to remote host
    spawn ssh -c 3des -x -l net-cfg-bak
    net-cfg-bak at's password:
    Type help or '?' for a list of available commands.
    Error: TIMEOUT reached

my .cloginrc file is as follows

    add method              *
{telnet} {ssh}
    add autoenable          *                                       {1}
    add enauser             *
    add user                *
    add password            *

    # set ssh encryption type, dflt: 3des
    add cyphertype *                {3des}

My goal is to back up my PIX configs, does anyone have any ideas?  Can
RANCID do it?

Faron Hopper
Network Engineering
3315 North Oak Trafficway
Kansas City, MO 64116
00005BA5D30000/cid:image002.jpg at 01C4D90E.F40D7A30>

More information about the Rancid-discuss mailing list