Amer-networks E5 CLI Manuel d'utilisateur

Naviguer en ligne ou télécharger Manuel d'utilisateur pour Accessoires pour ordinateurs Amer-networks E5 CLI. Amer Networks E5 CLI User Manual Manuel d'utilisatio

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 290
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs

Résumé du contenu

Page 1 - CLI Reference Guide

Clavister cOS CoreCLI Reference GuideVersion: 10.20.02Clavister ABSjögatan 6JSE-89160 ÖrnsköldsvikSWEDENPhone: +46-660-299200www.clavister.comPublishe

Page 2

optional value. This is because that option has a default value, 100, which will be used if no valueis specified.The following two examples will yield

Page 3 - Table of Contents

3.4. ALGThis is a category that groups the following object types.3.4.1. ALG_FTPDescriptionUse an FTP Application Layer Gateway to manage FTP traffic

Page 4

switches if a virus is found.FileListType Specifies if the file list contains files to allow ordeny. (Default: Block)FailModeBehavior Standard behavio

Page 5

RemoveApplets Remove Java applets. (Default: No)RemoveActiveX Remove ActiveX objects (including Flash). (Default:No)VerifyUTF8URL Verify that URLs doe

Page 6

allowed for the host that requested the override.(Default: 300)AllowFilteringReclassification Allow reclassification of sites. (Default: No)Comments T

Page 7

VerifyContentMimetype Verify that file extentions correspond to the MIMEtype. (Default: No)Antivirus Disabled, Audit or Protect. (Default: Disabled)Sc

Page 8 - List of Examples

MaxSessionsPerId Maximum number of sessions per SIP URI. (Default:5)MaxRegistrationTime The maximum allowed time in seconds betweenregistration reques

Page 9 - Notation

type. (Default: No)Antivirus Disabled, Audit or Protect. (Default: Disabled)ScanExclude List of files to exclude from antivirus scanning.(Optional)Com

Page 10

Used to whitelist or blacklist an email sender/recipient.PropertiesType Specifies if the email address is the sender or therecipient. (Default: Sender

Page 11 - Chapter 1: Introduction

Name Specifies a symbolic name for the ALG. (Identifier)HostCert Specifies the host certificate.RootCert Specifies the root certificates. (Optional)Co

Page 12 - 1.2. Help

3.5. AntiVirusPolicyDescriptionAdd a Anti-Virus Profile that can be used by one or many IP Policies. The same Profile can be usedon all protocols that

Page 13 - 1.3. Function keys

Chapter 1: Introduction• Running a command, page 11• Help, page 12• Function keys, page 13• Command line history, page 14• Tab completion, page 15• Us

Page 14 - 1.4. Command line history

3.6. ApplicationRuleSetDescriptionList of Application RulesPropertiesName Specifies a symbolic name for the Profile.(Identifier)DefaultAction Default

Page 15 - 1.5. Tab completion

3.7. ARPNDDescriptionUse an ARP/Neighbor Discovery entry to publish additional IP addresses and/or MAC addresseson a specified interface.PropertiesMod

Page 16

3.8. ARPNDSettingsDescriptionAdvanced ARP/Neighbor Discovery-table settings.PropertiesARPMatchEnetSender The Ethernet Sender address matching thehardw

Page 17

LogResolveFailure Specifies whether or not to log failed ARP Resolves.(Default: Yes)NDRateLimit Rate limit originated ND packets. (Default: 1000)MaxAn

Page 18 - 1.6. User roles

AdvReachableTime The value to be placed in the Reachable Time fieldin the Router Advertisement messages SGW. Thevalue zero means unspecified. (Default

Page 19

3.9. AuthAgentDescriptionThe Authentication Agent collect user login and logout events on a network domain controller.PropertiesName Specifies a symbo

Page 20 - Chapter 2: Command Reference

3.10. AuthenticationSettingsDescriptionSettings related to Authentication and Accounting.PropertiesLogoutAccUsersAtShutdown Logout authenticated accou

Page 21

3.11. BlacklistWhiteHostDescriptionHosts and networks added to this whitelist can never be blacklisted by IDP or Threshold Rules.PropertiesAddresses S

Page 22 - 2.1.4. cc

3.12. BNE2EthernetPCIDriverDescriptionBroadcom NE2 Gigabit Ethernet.PropertiesComments Text describing the current object. (Optional)NoteThis object t

Page 23 - 2.1.6. delete

3.13. BroadcomEthernetPCIDriverDescriptionBroadcom NE Gigabit Ethernet.PropertiesComments Text describing the current object. (Optional)NoteThis objec

Page 24 - 2.1.7. pskgen

1.2. Help1.2.1. Help for commandsThere are two ways of getting help about a command. A brief help is displayed if the commandname is typed followed by

Page 25 - 2.1.8. reject

3.14. CertificateDescriptionAn X. 509 certificate is used to authenticate a VPN client or gateway when establishing an IPsectunnel.PropertiesName Spec

Page 26 - 2.1.9. reset

3.15. COMPortDeviceDescriptionA serial communication port, that is used for accessing the CLI.PropertiesPort Port. (Identifier)BitsPerSecond Bits per

Page 27 - 2.1.10. set

3.16. ConfigModePoolDescriptionAn IKE Config Mode Pool will dynamically assign the IP address, DNS server, WINS server etc. tothe VPN client connectin

Page 28 - 2.1.11. show

3.17. ConnTimeoutSettingsDescriptionTimeout settings for various protocols.PropertiesConnLife_TCP_SYN Connection idle lifetime for TCP connections bei

Page 29 - 2.1.12. undelete

3.18. DateTimeDescriptionSet the date, time and time zone information for this system.PropertiesTimeZone Specifies the time zone. (Default: GMT)DSTEna

Page 30

3.19. DefaultInterfaceDescriptionA special interface used to represent internal mechanisms in the system as well as an abstract"any" interfa

Page 31 - 2.2. Runtime

3.20. DeviceDescriptionGlobal parameters for this device.PropertiesName Name of the device. (Default: Device)LocalCfgVersion Local version number of t

Page 32 - 2.2.4. arp

3.21. DHCPRelayDescriptionUse a DHCP Relay to dynamically alter the routing table according to relayed DHCP leases.PropertiesName Specifies a symbolic

Page 33 - 2.2.5. arpsnoop

LogSeverity Specifies with what severity log events will be sentto the specified log receivers. (Default: Default)Comments Text describing the current

Page 34 - 2.2.7. authagent

3.22. DHCPRelaySettingsDescriptionAdvanced DHCP relay settings.PropertiesMaxTransactions Maximum number of concurrent BOOTP/DHCPtransactions. (Default

Page 35 - 2.2.9. blacklist

1.3. Function keysIn addition to the return key there are a number of function keys that are used in the CLI.Backspace Delete the character to the lef

Page 36

3.23. DHCPServerDescriptionA DHCP Server determines a set of IP addresses and host configuration parameters to hand outto DHCP clients attached to a g

Page 37 - 2.2.11. cam

(Optional)LogEnabled Enable logging. (Default: Yes)LogSeverity Specifies with what severity log events will be sentto the specified log receivers. (De

Page 38 - 2.2.13. cfglog

NoteIf no Index is specified when creating an instance of this type, the object will be placedlast in the list and the Index will be equal to the leng

Page 39 - 2.2.14. connections

3.24. DHCPServerSettingsDescriptionAdvanced DHCP server settings.PropertiesAutoSaveLeasePolicy Policy for saving the lease database to disk.(Default:

Page 40 - 2.2.17. cryptostat

3.25. DHCPv6ServerDescriptionA DHCPv6 Server determines a set of IPv6 addresses and host configuration parameters to handout to DHCPv6 clients attache

Page 41 - 2.2.19. dhcp

3.25.1. DHCPv6ServerPoolStaticHostDescriptionStatic DHCPv6 Server host entryPropertiesHost IPv6 Address of the host.MACAddress The hardware address of

Page 42 - 2.2.21. dhcpserver

3.26. DHCPv6ServerSettingsDescriptionAdvanced DHCPv6 server settings.PropertiesAutoSaveLeasePolicy Policy for saving the lease database to disk.(Defau

Page 43 - 2.2.22. dhcpv6server

3.27. DNSDescriptionConfigure the DNS (Domain Name System) client settings.PropertiesDNSServer1 IP of the primary DNS Server. (Optional)DNSServer2 IP

Page 44 - 2.2.23. dns

3.28. DynamicRoutingRuleDescriptionA Dynamic Routing Policy rule creates a filter to catch statically configured or OSPF learnedroutes. The matched ro

Page 45 - 2.2.25. dynroute

last in the list and the Index will be equal to the length of the list.3.28.1. DynamicRoutingRuleExportOSPFDescriptionAn OSPF action is used to manipu

Page 46 - 2.2.27. ha

1.4. Command line historyEvery time a command is run, the command line is added to a history list. The up and downarrow keys are used to access previo

Page 47 - 2.2.29. httpalg

OffsetMetric Increases the metric by this value. (Optional)OffsetMetricType2 Increases the for Type2 routers metric by this value.(Optional)LimitMetri

Page 48 - 2.2.31. hwm

3.29. DynDnsClientCjbNetDescriptionConfigure the parameters used to connect to the Cjb.net DynDNS service.PropertiesUsername Username.Password The pas

Page 49 - 2.2.33. ifstat

3.30. DynDnsClientDyndnsOrgDescriptionConfigure the parameters used to connect to the dyndns.org DynDNS service.PropertiesDNSName The DNS name excludi

Page 50 - 2.2.34. igmp

3.31. DynDnsClientDynsCxDescriptionConfigure the parameters used to connect to the dyns.cx DynDNS service.PropertiesDNSName The DNS name excluding the

Page 51 - 2.2.36. ikesnoop

3.32. DynDnsClientPeanutHullDescriptionConfigure the parameters used to connect to the Peanut Hull DynDNS service.PropertiesDNSNames Specifies the DNS

Page 52 - 2.2.38. ipsecdefines

3.33. E1000EthernetPCIDriverDescriptionIntel (E1000) Gigabit Ethernet Adaptor.PropertiesRxRingsize Rx ringsize. (Default: 64)TxRingsize Rx ringsize. (

Page 53 - 2.2.40. ipsechastat

3.34. E100EthernetPCIDriverDescriptionIntel (E100) Fast Ethernet Adaptor.PropertiesRxRingsize Rx ringsize. (Default: 32)TxRingsize Tx ringsize. (Defau

Page 54 - 2.2.42. ipsectunnels

3.35. EthernetDescriptionAn Ethernet interface represents a logical endpoint for Ethernet traffic.PropertiesName Specifies a symbolic name for the int

Page 55 - 2.2.44. languagefiles

switch route is added automatically for thisinterface. (Default: No)AutoInterfaceNetworkRoute Automatically add a route for this interface usingthe gi

Page 56 - 2.2.46. license

3.36. EthernetDeviceDescriptionHardware settings for an Ethernet interface.PropertiesName Specifies a symbolic name for the device.(Identifier)Etherne

Page 57 - 2.2.47. linkmon

1.5. Tab completionBy using the tab function key in the CLI the names of commands, options, objects and objectproperties can be automatically complete

Page 58 - 2.2.50. natpool

3.37. EthernetSettingsDescriptionSettings for Ethernet interface.PropertiesDHCP_MinimumLeaseTime Minimum lease time (seconds) accepted from theDHCP se

Page 59 - 2.2.51. nd

Ringsize_pcnet32_tx Size of pcnet32 transmit ring (per interface).(Default: 256)IfaceMon_e1000 Enable interface monitor for e1000 interfaces.(Default:

Page 60 - 2.2.53. netcon

3.38. EventReceiverSNMP2cDescriptionA SNMP2c event receiver is used to receive SNMP events from the system.PropertiesName Specifies a symbolic name fo

Page 61 - 2.2.55. ospf

3.39. FileControlPolicyDescriptionAdd a File Control Profile that can be used by one or many IP Policies. The same Profile can beused on all protocols

Page 62

3.40. FragSettingsDescriptionSettings related to fragmented packets.PropertiesPseudoReass_MaxConcurrent Maximum number of concurrent fragmentreassembl

Page 63 - 2.2.56. pcapdump

LogSuspect)IP6RejectBadFragLength Send Parameter Problem error upon reception offragments with bad data length. (Default: No)IP6IgnoreStubFrags Ignore

Page 64

3.41. GRETunnelDescriptionA GRE interface is a Generic Routing Encapsulation (no encryption, no authentication, onlyencapsulation) tunnel over an exis

Page 65 - 2.2.57. pciscan

3.42. HighAvailabilityDescriptionConfigure the High Availability cluster parameters for this system.PropertiesEnabled Enable high availability. (Defau

Page 66 - 2.2.59. pptpalg

3.43. HTTPALGBannersDescriptionHTTP banner files specifies the look and feel of HTTP ALG restriction web pages.PropertiesName Specifies a symbolic nam

Page 67 - 2.2.61. rekeysa

3.44. HTTPAuthBannersDescriptionHTTP banner files specifies the look and feel of HTML authentication web pages.PropertiesName Specifies a symbolic nam

Page 68 - 2.2.64. routes

A more detailed help text about Address is displayed.1.5.2. Autocompleting Current and Default valueAnother special character that can be used togethe

Page 69 - 2.2.65. rtmonitor

3.45. HTTPPosterDescriptionUse the HTTP poster for dynamic DNS or automatic logon to services using web-basedauthentication.PropertiesURL The URL that

Page 70 - 2.2.66. rules

3.46. HWMDescriptionHardware Monitoring allows monitoring of hardware sensors.PropertiesName Specifies a symbolic name for the object.Type Type of mon

Page 71 - 2.2.67. selftest

3.47. HWMSettingsDescriptionGeneral settings for Hardware MonitoringPropertiesEnableSensors Enable/disable all HWM functionality. (Default: No)SensorP

Page 72

3.48. ICMPSettingsDescriptionSettings related to the ICMP protocol.PropertiesICMPSendPerSecLimit Maximum number of ICMP responses that will besent eac

Page 73 - 2.2.69. sessionmanager

3.49. IDListDescriptionAn ID list contains IDs, which are used within the authentication process when establishing anIPsec tunnel.PropertiesName Speci

Page 74

3.50. IDPRuleDescriptionAn IDP Rule defines a filter for matching specific network traffic. When the filter criterion is met,the IDP Rule Actions are

Page 75 - 2.2.71. shutdown

DescriptionAn IDP Rule Action specifies what signatures to search for in the network traffic, and what actionto take if those signatures are found.Pro

Page 76 - 2.2.72. sipalg

3.51. IGMPRuleDescriptionAn IGMP rule specifies how to handle inbound IGMP reports and outbound IGMP queries.PropertiesIndex The index of the object,

Page 77

NoteIf no Index is specified when creating an instance of this type, the object will be placedlast in the list and the Index will be equal to the leng

Page 78 - 2.2.74. sslvpn

3.52. IGMPSettingDescriptionIGMP parameters can be tuned for one, or a group of interfaces in order to match thecharacteristics of a network.Propertie

Page 79 - 2.2.77. techsupport

Accessing an IP4Address object without the use of categories:Device:/> show IP4Address example_ipChapter 1: Introduction17

Page 80 - 2.2.79. uarules

3.53. IKEAlgorithmsDescriptionConfigure algorithms which are used in the IKE phase of an IPsec session.PropertiesName Specifies a symbolic name for th

Page 81 - 2.2.80. updatecenter

3.54. InterfaceGroupDescriptionUse an interface group to combine several interfaces for a simplified security policy.PropertiesName Specifies a symbol

Page 82 - 2.2.81. userauth

3.55. IPPolicyDescriptionAn IP Policy specifies what action to perform on network traffic that matches the specified filtercriteria.PropertiesIndex Th

Page 83 - 2.2.83. vpnstats

address to use.DestNewIP Specifies which destination address will be used.DestBaseIP Specifies base address for destination address.DestPortAction Spe

Page 84 - 2.3. Utility

(Default: 300)WCF_AllowReclassification Allow reclassification of sites. (Default: No)URLFilter URL Filter. (Default: No)WC_Policy Selects preconfigur

Page 85 - 2.4. Misc

3.56. IPPoolDescriptionAn IP Pool is a dynamic object which consists of IP leases that are fetched from a DHCP Server.The IP Pool is used as an addres

Page 86 - 2.4.4. ls

3.57. IPRuleDescriptionAn IP rule specifies what action to perform on network traffic that matches the specified filtercriteria.PropertiesIndex The in

Page 87 - 2.4.5. script

(Default: 30)SLBMaxSlots Specifies maximum number of slots for IP andnetwork stickiness. (Default: 2048)SLBNetSize Specifies network size for network

Page 88

SLBHTTPMaxAverageLatency Specifies the max average latency for the sampleattempts. (Default: 800)SLBHTTPURLType Defines how the request URL should bei

Page 89

3.58. IPRuleFolderDescriptionAn IP Rule Folder can be used to group IP Rules into logical groups for better overview andsimplified management.Properti

Page 90

1.6. User rolesSome commands and options cannot be used unless the logged-in user has administratorprivileges. This is indicated in this guide by a no

Page 91

3.59. IPRuleSetDescriptionAn IP Rule Set is a self-contained set of IP Rules. Default action is Drop.PropertiesName A name to uniquely identify this I

Page 92

3.60. IPsecAlgorithmsDescriptionConfigure algorithms which are used in the IPsec phase of an IPsec session.PropertiesName Specifies a symbolic name fo

Page 93

XCBCEnabled Enable XCBC-AES integrity algorithm. (Default: No)Comments Text describing the current object. (Optional)Chapter 3: Configuration Referenc

Page 94 - 3.1. Access

3.61. IPsecTunnelDescriptionAn IPsec tunnel item is used to define IPsec endpoint and will appear as a logical interface in thesystem.PropertiesIndex

Page 95 - 3.2. Address

LocalIDValue Specify the local identity of the tunnel ID.GatewayCertificate Selects the certificate the security gateway uses toauthenticate itself to

Page 96 - 3.2.1.5. IP4HAAddress

the given remote network. (Default: Yes)LocalEndpoint Specifies on which local address this tunnel shouldaccept incoming IKE/IPsec traffic. (Optional)

Page 97 - 3.2.1.7. IP4Address

3.62. IPsecTunnelSettingsDescriptionSettings for the IPsec tunnel interfaces used for establishing IPsec VPN connections to and fromthis system.Proper

Page 98

IPsecDisablePKAccel Disable hardware acceleration for public-keyoperations. (Default: No)AESNIEnable Enable AES-NI acceleration for processors thatsup

Page 99 - 3.3. AdvancedScheduleProfile

3.63. IPSettingsDescriptionSettings related to the IP protocol.PropertiesEnableIPv6 Enable processing of IPv6 traffic. (Default: No)LogDropOnForwardHo

Page 100 - 3.4. ALG

IP6OPT_RA Validate Router Alert packets. (Default: Ignore)IP6OPT_HA Validate Home Address option packets. (Default:Ignore)IP6OPT_OTH Validate unknown

Page 101 - 3.4.3. ALG_HTTP

Chapter 1: Introduction19

Page 102

IPOPT_SR How to handle IP packets with contained source orreturn routes. (Default: DropLog)IPOPT_TS How to handle IP packets with containedTimestamps.

Page 103 - 3.4.4. ALG_POP3

3.64. ixgbeEthernetPCIDriverDescriptionIntel (IXGBE) 10 Gigabit Ethernet Adaptor.PropertiesComments Text describing the current object. (Optional)Note

Page 104 - 3.4.6. ALG_SIP

3.65. IXP4NPEEthernetDriverDescriptionIntel (IXP4xxNPE) Fast Ethernet Adaptor.PropertiesComments Text describing the current object. (Optional)NoteThi

Page 105 - 3.4.7. ALG_SMTP

3.66. L2TPClientDescriptionA PPTP/L2TP client interface is a PPP (Point-to-Point Protocol) tunnel over an existing IP network.Its IP address and DNS s

Page 106 - 3.4.7.1. ALG_SMTP_Email

MPPERC440 Use an RC4 40 bit MPPE session key with MS-CHAPor MS-CHAP v2 authentication protocol. (Default:Yes)MPPERC456 Use an RC4 56 bit MPPE session

Page 107 - 3.4.9. ALG_TLS

3.67. L2TPServerDescriptionA PPTP/L2TP server interface terminates PPP (Point to Point Protocol) tunnels set up over existingIP networks.PropertiesNam

Page 108

Servers (NBNS) to assign IP addresses to NetBIOSnames. (Optional)AllowedRoutes Restricts networks for which routes mayautomatically be added. (Default

Page 109 - 3.5. AntiVirusPolicy

3.68. L2TPServerSettingsDescriptionPPTP/L2TP server settings.PropertiesL2TPBeforeRules Pass L2TP connections sent to the security gatewaydirectly to t

Page 110 - 3.6. ApplicationRuleSet

3.69. L2TPv3ServerDescriptionA L2TPv3 server interface terminates L2 (Ethernet and VLAN) tunnels set up over existing IPnetworks.PropertiesName Specif

Page 111 - 3.7. ARPND

3.70. LDAPDatabaseDescriptionExternal LDAP server used to verify user names and passwords.PropertiesName Specifies a symbolic name for the server.(Ide

Page 112 - 3.8. ARPNDSettings

Clavister cOS CoreCLI Reference GuideVersion: 10.20.02Published 2014-03-31Copyright © 2014 Clavister ABCopyright NoticeThis publication, including all

Page 113

Chapter 2: Command Reference• Configuration, page 20• Runtime, page 31• Utility, page 84• Misc, page 852.1. Configuration2.1.1. activateActivate chang

Page 114

3.71. LDAPServerDescriptionAn LDAP server is used as a central repository of certificates and CRLs that the security gatewaycan download when necessar

Page 115 - 3.9. AuthAgent

3.72. LengthLimSettingsDescriptionLength limitations for various protocols.PropertiesMaxTCPLen TCP; Sometimes has to be increased if tunnelingprotocol

Page 116 - 3.10. AuthenticationSettings

3.73. LinkAggregationDescriptionA Link Aggregation interface combines multiple Ethernet interfaces into a single logicalendpoint.PropertiesName Specif

Page 117 - 3.11. BlacklistWhiteHost

when IPv6 is enabled. (Default: 1500)Metric Specifies the metric for the auto-created route.(Default: 100)DHCPEnabled Enable DHCP client on this inter

Page 118 - 3.12. BNE2EthernetPCIDriver

3.74. LinkMonitorDescriptionThe Link Monitor allows the system to monitor one or more hosts and take action if they areunreachable.PropertiesAction Sp

Page 119 - Description

3.75. LocalReassSettingsDescriptionParameters use for local fragment reassembly.PropertiesLocalReass_MaxConcurrent Maximum number of concurrent localr

Page 120 - 3.14. Certificate

3.76. LocalUserDatabaseDescriptionA local user database contains user accounts used for authentication purposes.PropertiesName Specifies a symbolic na

Page 121 - 3.15. COMPortDevice

3.77. LogReceiverFWLogDescriptionA FWLog receiver is used to receive log events from the system in the FWlog format.PropertiesName Specifies a symboli

Page 122 - 3.16. ConfigModePool

3.78. LogReceiverMemoryDescriptionA memory log receiver is used to receive and keep log events in system RAM.PropertiesName Specifies a symbolic name

Page 123 - 3.17. ConnTimeoutSettings

3.79. LogReceiverSMTPDescriptionAn SMTP event receiver is used for receiving emails for IDP events.PropertiesName Specifies a symbolic name for the lo

Page 124 - 3.18. DateTime

DescriptionCreate a new object and add it to the configuration.Specify the type of object you want to create and the identifier, if the type has one,

Page 125 - 3.19. DefaultInterface

3.80. LogReceiverSyslogDescriptionA Syslog receiver is used to receive log events from the system in the standard Syslog format.PropertiesName Specifi

Page 126 - 3.20. Device

3.81. LogSettingsDescriptionAdvanced log settings.PropertiesLogSendPerSecLimit Limits how many log packets the security gatewaymay send out per second

Page 127 - 3.21. DHCPRelay

3.82. LoopbackInterfaceDescriptionLoopback interfaces will take all packets sent through them and pass them back up a differentinterface as newly rece

Page 128

3.83. MarvellEthernetPCIDriverDescriptionMarvell (88E8001,88E8053,88E8062) Fast and Gigabit Ethernet Adaptor.PropertiesComments Text describing the cu

Page 129 - 3.22. DHCPRelaySettings

3.84. MiscSettingsDescriptionMiscellaneous SettingsPropertiesUDPSrcPort0 How to treat UDP packets with source port 0.(Default: DropLog)Port0 How to tr

Page 130 - 3.23. DHCPServer

NoteThis object type does not have an identifier and is identified by the name of the typeonly. There can only be one instance of this type.Chapter 3:

Page 131

3.85. MulticastSettingsDescriptionAdvanced Multicast Settings.PropertiesAutoAddMulticastCoreRoute Auto generate core route for"224.0.0.1-239.255.

Page 132

3.86. NATPoolDescriptionA NAT Pool is used for NATing multiple concurrent connections to using different source IPaddresses.PropertiesName Specifies a

Page 133 - 3.24. DHCPServerSettings

3.87. OSPFProcessDescriptionAn OSPF Router Process defines a group of routers exchanging routing information via the OpenShortest Path First routing p

Page 134 - 3.25. DHCPv6Server

DebugDDesc Enables or disabled logging of databasedescription packets and also specifies the details ofthe log. (Default: Off)DebugExchange Enables or

Page 135

2.1.3. cancelCancel ongoing commit.DescriptionCancel commit operation immediately, without waiting for the timeout.UsagecancelNoteRequires Administrat

Page 136 - 3.26. DHCPv6ServerSettings

StubMetric Route metric for stub area. (Optional)FilterExternal Specifies the network addresses allowed to beimported into this area from external rou

Page 137 - 3.27. DNS

router will be declared to be down. (Default: 40)RxmtInterval Specifies the number of seconds betweenretransmissions of LSAs to neighbors on thisinter

Page 138 - 3.28. DynamicRoutingRule

DescriptionAn aggregate is used to replace any number of smaller networks belonging to the local (intra)area with one contiguous network which may the

Page 139

3.88. PipeDescriptionA pipe defines basic traffic shaping parameters. The pipe rules then determines which trafficgoes through which pipes.PropertiesN

Page 140

precedence 7 (the highest precedence). (Optional)LimitPPS7 Specifies the packet per second limit forprecedence 7 (the highest precedence). (Optional)U

Page 141 - 3.29. DynDnsClientCjbNet

GroupingNetworkSize If users are grouped according to source ordestination network, the size of the network has tobe specified by this setting. (Defau

Page 142 - 3.30. DynDnsClientDyndnsOrg

3.89. PipeRuleDescriptionA Pipe Rule determines traffic shaping policy - which Pipes to use - for one or more types oftraffic with the same granularit

Page 143 - 3.31. DynDnsClientDynsCx

3.90. PPPoETunnelDescriptionA PPPoE interface is a PPP (point-to-point protocol) tunnel over an existing physical Ethernetinterface. Its IP address is

Page 144 - 3.32. DynDnsClientPeanutHull

Metric Specifies the metric for the auto-created route.(Default: 90)AutoInterfaceNetworkRoute Automatically add a route for this interface usingthe gi

Page 145 - 3.33. E1000EthernetPCIDriver

3.91. PPPSettingsDescriptionSettings related to the PPP protocol.PropertiesInitialResendTime Initial time in milliseconds to wait before sending anew

Page 146 - 3.34. E100EthernetPCIDriver

Change the current context.cc -printPrint the current context.ccChange to root context (same as "cc /").Options-print Print the current cont

Page 147 - 3.35. Ethernet

3.92. PSKDescriptionPSK (Pre-Shared Key) authentication is based on a shared secret that is known only by the partiesinvolved.PropertiesName Specifies

Page 148

3.93. R8139EthernetPCIDriverDescriptionRealTek (8139) Fast Ethernet Adaptor.PropertiesComments Text describing the current object. (Optional)NoteThis

Page 149 - 3.36. EthernetDevice

3.94. R8169EthernetPCIDriverDescriptionRealTek (8169,8110) Gigabit Ethernet Adaptor.PropertiesComments Text describing the current object. (Optional)N

Page 150 - 3.37. EthernetSettings

3.95. RadiusAccountingDescriptionExternal RADIUS server used to collect user statistics.PropertiesName Specifies a symbolic name for the server.(Ident

Page 151

3.96. RadiusRelayDescriptionRADIUS relay for intercepting packets from a user endpoint and sending packets to a remoteRADIUS server.PropertiesName Spe

Page 152 - 3.38. EventReceiverSNMP2c

RoutingTable Specifies the routing table the clients host routeshould be added to. (Default: main)Comments Text describing the current object. (Option

Page 153 - 3.39. FileControlPolicy

3.97. RadiusServerDescriptionExternal RADIUS server used to verify user names and passwords.PropertiesName Specifies a symbolic name for the server.(I

Page 154 - 3.40. FragSettings

3.98. RealTimeMonitorAlertDescriptionMonitors a statistical value. Log messages are generated if the value goes below the lowerthreshold or above the

Page 155

3.99. RemoteIDListDescriptionList of Remote IDs that are allowed access when using Pre Shared Keys as authenticationmethod.PropertiesType Specifies th

Page 156 - 3.41. GRETunnel

3.100. RemoteMgmtHTTPDescriptionConfigure HTTP/HTTPS management to enable remote management to the system.PropertiesName Specifies a symbolic name for

Page 157 - 3.42. HighAvailability

activated.See also: undeleteExample 2.3. Delete an objectDelete an unreferenced object:gw-world:/> delete Address IP4Address example_ipDelete a ref

Page 158 - 3.43. HTTPALGBanners

3.101. RemoteMgmtNetconDescriptionConfigure Netcon management to enable remote management to the system.PropertiesName Specifies a symbolic name for t

Page 159 - 3.44. HTTPAuthBanners

3.102. RemoteMgmtSettingsDescriptionSetup and configure methods and permissions for remote management of this system.PropertiesNetconBiDirTimeout Spec

Page 160 - 3.45. HTTPPoster

LocalConsoleIdleTimeout Number of seconds of inactivity until the localconsole user is automatically logged out. (Default:900)WebUIIdleTimeout Number

Page 161 - 3.46. HWM

3.103. RemoteMgmtSNMPDescriptionConfigure SNMP management to enable SNMP polling.PropertiesName Specifies a symbolic name for the object.(Identifier)I

Page 162 - 3.47. HWMSettings

3.104. RemoteMgmtSSHDescriptionConfigure a Secure Shell (SSH) Server to enable remote management access to the system.PropertiesName Specifies a symbo

Page 163 - 3.48. ICMPSettings

password has to be provided within this number ofseconds or the session will be closed. (Default: 30)AuthenticationRetries The number of retires allow

Page 164 - 3.49. IDList

3.105. RouteBalancingInstanceDescriptionA route balancing instance is assoicated with a routingtable and defines how to make use ofmultiple routes to

Page 165 - 3.50. IDPRule

3.106. RouteBalancingSpilloverSettingsDescriptionSettings associated with the spillover algorithm.PropertiesInterface Interface to threshold limit. (I

Page 166

3.107. RouterAdvertisementDescriptionEnabling Router Advertisement will answer Solicitations and periodically send outAdvertisements. Stateless addres

Page 167 - 3.51. IGMPRule

sent. (Default: 0). (Default: 0)Comments Text describing the current object. (Optional)NoteIf no Index is specified when creating an instance of this

Page 168

Options-comments=<String> Comments for this key.-size={64 | 128 | 256 | 512 | 1024 | 2048 |4096}Number of bits of data in the generated key.(Def

Page 169 - 3.52. IGMPSetting

3.108. RoutingRuleDescriptionA Routing Rule forces the use of a routing table in the forward and/or return direction of trafficon a connection. The or

Page 170 - 3.53. IKEAlgorithms

3.109. RoutingSettingsDescriptionConfigure the routing capabilities of the system.PropertiesRouteFailOver_IfacePollInterval Time (ms) between polling

Page 171 - 3.54. InterfaceGroup

Transparency_ATSExpire Lifetime of an unanswered ATS entry in seconds.(Default: 3)Transparency_ATSSize Number of ATS entries, total. (Default: 4096)Nu

Page 172 - 3.55. IPPolicy

3.110. RoutingTableDescriptionThe system has a predefined main routing table. Alternate routing tables can be defined by theuser.PropertiesName Specif

Page 173

MonitorGateway Mark the route as down if the next hop does notanswer on ARP lookups during a specified time.(Default: No)MonitorGatewayManualARP Enabl

Page 174

monitoring to be successful. (Default: No)Samples Specifies the number of attempts to use forstatistical calculations. (Default: 10)MaxPollFails Speci

Page 175 - 3.56. IPPool

(Default: No)ProxyNDInterfaces Specifies the interfaces on which the securitygateway should publish routes via Proxy ARP.(Optional)Comments Text descr

Page 176 - 3.57. IPRule

3.111. ScheduleProfileDescriptionA Schedule Profile defines days and dates and are then used by the various policies in thesystem.PropertiesName Speci

Page 177

3.112. ServiceGroupDescriptionA Service Group is a collection of service objects, which can then be used by different policies inthe system.Properties

Page 178

3.113. ServiceICMPDescriptionAn ICMP Service is an object definition representing ICMP traffic with specific parameters.PropertiesName Specifies a sym

Page 179 - 3.58. IPRuleFolder

Usagereject [<Category>] <Type> [<Identifier>] [-recursive]Reject changes made to the specified object.reject -allReject all changes

Page 180 - 3.59. IPRuleSet

Protocol Protocol settings are only used by IP Policies.(Optional)MaxSessionsProtocol Specifies how many concurrent sessions that arepermitted using t

Page 181 - 3.60. IPsecAlgorithms

3.114. ServiceICMPv6DescriptionAn IPv6-ICMP Service is an object definition representing IPv6-ICMP traffic with specificparameters.PropertiesName Spec

Page 182

ALG An Application Layer Gateway (ALG), capable ofmanaging advanced protocols, can be specified forthis service. (Optional)MaxSessions Specifies how m

Page 183 - 3.61. IPsecTunnel

3.115. ServiceIPProtoDescriptionAn IP Protocol Service is a definition of an IP protocol with specific parameters.PropertiesName Specifies a symbolic

Page 184

3.116. ServiceTCPUDPDescriptionA TCP/UDP Service is a definition of an TCP or UDP protocol with specific parameters.PropertiesName Specifies a symboli

Page 185

3.117. SSHClientKeyDescriptionThe public key of the client connecting to the SSH server.PropertiesName Specifies a symbolic name for the key. (Identif

Page 186 - 3.62. IPsecTunnelSettings

3.118. SSLSettingsDescriptionSettings related to SSL (Secure Sockets Layer).PropertiesSSL_ProcessingPriority The amount of of CPU time that SSL proces

Page 187

3.119. SSLVPNInterfaceDescriptionAn SSL VPN interface, together with the bundled client, creates an easy to use tunnel solution forroaming users.Prope

Page 188 - 3.63. IPSettings

3.120. SSLVPNInterfaceSettingsDescriptionSSL VPN interface settings.PropertiesSSLVPNBeforeRules Pass SSL VPN connections sent to the securitygateway d

Page 189

3.121. ST201EthernetPCIDriverDescriptionD-Link (ST201) Fast Ethernet Adaptor.PropertiesComments Text describing the current object. (Optional)NoteThis

Page 190

-unit Reset unit to factory defaults.NoteRequires Administrator privilege.2.1.10. setSet property values.DescriptionSet property values of configurati

Page 191 - 3.64. ixgbeEthernetPCIDriver

3.122. StateSettingsDescriptionParameters for the state engine in the system.PropertiesConnReplace What to do when the connection table is full.(Defau

Page 192 - 3.65. IXP4NPEEthernetDriver

3.123. TCPSettingsDescriptionSettings related to the TCP protocol.PropertiesTCPOptionSizes Validity of TCP header option sizes. (Default:ValidateLogBa

Page 193 - 3.66. L2TPClient

TCPSynUrg The TCP URG flag together with SYN; normallyinvalid (strip=strip URG). (Default: DropLog)TCPSynPsh The TCP PSH flag together with SYN; norma

Page 194

3.124. ThresholdRuleDescriptionA Threshold Rule defines a filter for matching specific network traffic. When the filter criterion ismet, the Threshold

Page 195 - 3.67. L2TPServer

ThresholdUnit Specifies the threshold unit. (Default: ConnsSec)BlackList Activate BlackList. (Default: No)BlackListTimeToBlock The number of seconds t

Page 196

3.125. TulipEthernetPCIDriverDescriptionTulip Fast Ethernet Adaptor.PropertiesComments Text describing the current object. (Optional)NoteThis object t

Page 197 - 3.68. L2TPServerSettings

3.126. UpdateCenterDescriptionConfigure automatical updates.PropertiesAVEnabled Automatic updates of antivirus definitions andengine. (Default: No)IDP

Page 198 - 3.69. L2TPv3Server

3.127. URLFilterPolicyDescriptionAdd a URL Filtering Profile that can be used by one or many IP Policies. Only the HTTP Protocolhave support for URL F

Page 199 - 3.70. LDAPDatabase

3.128. UserAuthRuleDescriptionThe User Authentication Ruleset specifies from where users are allowed to authenticate to thesystem, and how.PropertiesI

Page 200 - 3.71. LDAPServer

HTTPBanners HTTP Authentication HTML Banners. (Default:Default)RealmString The string that is presented as a part of the 401 -Authentication Required

Page 201 - 3.72. LengthLimSettings

<Category> Category that groups object types.<Identifier> The property that identifies the configurationobject. May not be applicable depe

Page 202 - 3.73. LinkAggregation

PacketsReceived Enable reporting of the number of packetsreceived by the user. (Default: Yes)SessionTime Enable reporting of the number of seconds the

Page 203

3.129. VLANDescriptionUse a VLAN to define a virtual interface compatible with the IEEE 802.1Q Virtual LAN standard.PropertiesName Specifies a symboli

Page 204 - 3.74. LinkMonitor

EnableRouterAdvertisement Enable Router Advertisement for this interface.(Default: No)MemberOfRoutingTable All or Specific. (Default: All)RoutingTable

Page 205 - 3.75. LocalReassSettings

3.130. VLANSettingsDescriptionSettings for IEEE 802.1Q based Virtual LAN interfaces.PropertiesUnknownVLANTags VLAN packets tagged with an unknown ID.(

Page 206 - 3.76. LocalUserDatabase

3.131. WebContentFilteringPolicyDescriptionAdd a Web Content Filtering Profile that can be used by one or many IP Policies. Only the HTTPProtocol have

Page 207 - 3.77. LogReceiverFWLog

3.132. X3C905EthernetPCIDriverDescription3com Fast Ethernet Adaptor.PropertiesComments Text describing the current object. (Optional)NoteThis object t

Page 208 - 3.78. LogReceiverMemory

Chapter 3: Configuration Reference286

Page 209 - 3.79. LogReceiverSMTP

Alphabetical IndexCommandsAabout, 31activate, 20add, 20alarm, 31appcontrol, 31arp, 32arpsnoop, 33ats, 34authagent, 34authagentsnoop, 35Bblacklist, 35b

Page 210 - 3.80. LogReceiverSyslog

selftest, 71services, 73sessionmanager, 73set, 27settings, 75show, 28shutdown, 75sipalg, 76sshserver, 78sslvpn, 78stats, 79sysmsgs, 79Ttechsupport, 79

Page 211 - 3.81. LogSettings

IP6Address, 95, 98IP6Group, 95, 98IPPolicy, 172, 179, 180IPPool, 175IPRule, 176, 179, 180IPRuleFolder, 179, 180IPRuleSet, 180IPsecAlgorithms, 181IPsec

Page 212 - 3.82. LoopbackInterface

gw-world:/> show Address IP4Address example_ipgw-world:/main> show Route 1gw-world:/> show Client DynDnsClientDyndnsOrgShow a table of all ob

Page 213

Clavister ABSjögatan 6JSE-89160 ÖrnsköldsvikSWEDENPhone: +46-660-299200www.clavister.com

Page 214 - 3.84. MiscSettings

Table of ContentsPreface ... 91. Introduc

Page 215

Restore previously deleted objects.DescriptionRestore a previously deleted object.This is possible as long as the activate command has not been called

Page 216 - 3.85. MulticastSettings

2.2. Runtime2.2.1. aboutShow copyright/build information.DescriptionShow copyright and build information.Usageabout2.2.2. alarmShow alarm information.

Page 217 - 3.86. NATPool

appcontrolShow general information about application control system.appcontrol -show_listsList information about specified application.appcontrol -del

Page 218 - 3.87. OSPFProcess

The presented list can be filtered using the ip and hw options.UsagearpShow all ARP entries.arp -show [<Interface>] [-ip=<pattern>] [-hw=&

Page 219 - 3.87.1. OSPFArea

UsagearpsnoopShow snooped interfaces.arpsnoop {ALL | NONE | <interface>} [-verbose]Snoop specified interface.Options-verbose Verbose.{ALL | NONE

Page 220 - 3.87.1.1. OSPFInterface

authagent {ALL | <AuthAgent>}Shows the state of the configured Authentication Agents.authagent -reconnect {ALL | <AuthAgent>}Closes the co

Page 221 - 3.87.1.3. OSPFAggregate

Note: Static blacklist hosts cannot be unblocked.If -force is not specified, only the exact host with the service, protocol/port and destinyspecified

Page 222 - 3.87.1.4. OSPFVLink

-show Show information about the blacklisted hosts.-time=<seconds> The time that the host will remain blocked.-unblock Unblock specified netobje

Page 223 - 3.88. Pipe

Show CAM table information.cam <Interface> [-num=<n>]Show interface-specified CAM table information.cam <Interface> [-flush]Flush CA

Page 224

cfglog2.2.14. connectionsList current state-tracked connections.DescriptionList current state-tracked connections.Usageconnections -show [-num=<n&g

Page 225

2.2.29. httpalg ... 472.2.30. httpposter ...

Page 226 - 3.89. PipeRule

-verbose Verbose (more information).2.2.15. cpuidDisplay info about the cpu.DescriptionDisplay the make and model of the machine's CPU.Usagecpuid

Page 227 - 3.90. PPPoETunnel

2.2.18. dconsoleDisplays the content of the diagnose console.DescriptionThe diagnose console is used to help troubleshooting internal problems within

Page 228

Options-lease={RENEW | RELEASE} Modify interface lease.-list List all DHCP enabled interfaces.-show Show information about DHCP enabled interface.<

Page 229 - 3.91. PPPSettings

Show content of the DHCP server ruleset.DescriptionShow the content of the DHCP server ruleset and various information about active/inactiveleases.Dis

Page 230 - 3.92. PSK

Show content of the DHCPv6 server ruleset.DescriptionShow the content of the DHCPv6 server ruleset and various information about active/inactiveleases

Page 231 - 3.93. R8139EthernetPCIDriver

dns [-query=<domain name>] [-list] [-remove]Options-list List pending DNS queries.-query=<domain name> Resolve domain name.-remove Remove

Page 232 - 3.94. R8169EthernetPCIDriver

Options-exports Show current exports.-rules Show dynamic routing, filter ruleset.2.2.26. fragsShow active fragment reassemblies.DescriptionList active

Page 233 - 3.95. RadiusAccounting

DescriptionShow current HA status.Usageha [-activate] [-deactivate]Options-activate Go active.-deactivate Go inactive.2.2.28. hostmonShow Host Monitor

Page 234 - 3.96. RadiusRelay

List or flush hosts that have overridden the wcf filter.httpalg -wcfcache [-show] [-url=<String>] [-flush] [-verbose][-count] [-server[={STATUS

Page 235

Show hardware monitor sensor status.Usagehwm [-all] [-verbose]Options-all Show ALL sensors, WARNING: use at own risk, maytake long time for highspeed

Page 236 - 3.97. RadiusServer

2.4.4. ls ... 862.4.5. script ...

Page 237 - 3.98. RealTimeMonitorAlert

DescriptionShow list of attached interfaces, or in-depth information about a specific interface.Usageifstat [<Interface>] [-filter=<expr>]

Page 238 - 3.99. RemoteIDList

igmp -leave <Interface> <MC address> [<host address>]Simulate an incoming IGMP leave message.Options-join Simulate an incoming IGMP

Page 239 - 3.100. RemoteMgmtHTTP

-verbose Enable IKE snooping with verbose output.<ip address> IP address to snoop.2.2.37. ippoolShow IP pool information.DescriptionShow informa

Page 240 - 3.101. RemoteMgmtNetcon

ipsecdefines2.2.39. ipsecglobalstatsShow global ipsec statistics.DescriptionList global IPsec statistics.Usageipsecglobalstats -mem [-verbose]Start IK

Page 241 - 3.102. RemoteMgmtSettings

2.2.41. ipsecstatsShow the SAs in use.DescriptionList the currently active IKE and IPsec SAs, optionally only showing SAs matching the patterngiven fo

Page 242

Show interfaces.Options-force Bypass confirmation question.-iface=<recv iface> IPsec interface to show information about.-num={ALL | <Integer

Page 243 - 3.103. RemoteMgmtSNMP

languagefilesShow all language files on disk.languagefiles -remove=<String>Remove a language file from disk.Options-remove=<String> Specif

Page 244 - 3.104. RemoteMgmtSSH

DescriptionShow contents of the license file.Usagelicense -show [-remove]Manages license.license -activate [-request] [-username=<String>][-pass

Page 245

Usagelinkmon2.2.48. logoutLogout user.DescriptionLogout current user.Usagelogout2.2.49. memoryShow memory information.DescriptionShow core memory cons

Page 246 - 3.105. RouteBalancingInstance

Options-num=<Integer> Maximum number of items to list (default: 20).-verbose Verbose (more information).<IP4 Address> Translated IP.<po

Page 247

3.35. Ethernet ... 1473.36. EthernetDevice ...

Page 248 - 3.107. RouterAdvertisement

-hashinfo Show information on hash table health.-hw=<pattern> Show only hardware addresses matching pattern.-ip=<pattern> Show only IP add

Page 249 - 3.107.1. RA_PrefixInformation

Usagenetcon2.2.54. netobjectsShow runtime values of network objects.DescriptionDisplays named network objects and their contents.Example 2.10. List ne

Page 250 - 3.108. RoutingRule

Show interface information.ospf -area [<OSPF Area>] [-process=<OSPF Router Process>]Show area information.ospf -neighbor [<OSPF Neighbo

Page 251 - 3.109. RoutingSettings

-verbose Increase amount of information to display.<interface> OSPF enabled interface.<interface> OSPF enabled interface.<lsaID> LSA

Page 252

pcapdump -cleanupRemove all captured packets, release capture mode and delete all written capture files from disk.Options-cleanup Remove all captured

Page 253 - 3.110. RoutingTable

-write Write the captured packets to disk.<interface(s)> Name of interface(s).NoteRequires Administrator privilege.2.2.57. pciscanShow detected

Page 254 - 3.110.1.1. MonitoredHost

ST201 | TULIP | X3C905} Interface driver to use.2.2.58. pipesShow pipes information.DescriptionShow list of configured pipes / pipe details / pipe use

Page 255 - 3.110.2. Route6

pptpalg -sessions <PPTP ALG> [-verbose] [-num=<Integer>]List all PPTP sessions.pptpalg -services <PPTP ALG>List all services attache

Page 256 - 3.110.3. SwitchRoute

rekeysa -ipsec <ip address>Rekey IPsec SAs.rekeysa <ip address>Rekey IPsec SAs.Options-ike Rekey IKE SAs.-ipsec Rekey IPsec SAs.<ip add

Page 257 - 3.111. ScheduleProfile

Note that "core" routes for interface IP addresses are not normally shown. Use the -all switchto show core routes also.Use the -switched swi

Page 258 - 3.112. ServiceGroup

3.84. MiscSettings ... 2143.85. MulticastSettings ...

Page 259 - 3.113. ServiceICMP

If the option "monitored" is specified, only objects that have an associated real-time monitoralert are displayed.Example 2.11. Show all mon

Page 260

-ruleset={* | MAIN | <IP Rule Set>} Show a specified IP ruleset.-schedule Filter out rules that are not currently allowed byselected schedules.-

Page 261 - 3.114. ServiceICMPv6

Usageselftest -memory [-num=<Integer>]Check the sanity of the RAM.selftest -media [-size=<Integer>]Check the sanity of the disk drive.self

Page 262

-media Check the sanity of the disk drive.-memory Check the sanity of the RAM.-minutes[=<Integer>] Test duration in minutes. (Default: 0)-num=&l

Page 263 - 3.115. ServiceIPProto

Session Manager.DescriptionShow information about the Session Manager, and list currently active users.Explanation of Timeout flags for sessions:D Ses

Page 264 - 3.116. ServiceTCPUDP

<message text> Message to send.<session name> Name of session.{LOCAL | SSH | NETCON | HTTP | HTTPS} Session type.2.2.70. settingsShow sett

Page 265 - 3.117. SSHClientKey

NoteRequires Administrator privilege.2.2.72. sipalgSIP ALG.DescriptionList running SIP-ALG configurations, SIP registration and call information.The -

Page 266 - 3.118. SSLSettings

NOTE: 'verbose' option outputs a lot of information on the console which may lead to systeminstability. Use with caution.Usagesipalg -defini

Page 267 - 3.119. SSLVPNInterface

<ipaddr> IP Address to snoop.2.2.73. sshserverSSH Server.DescriptionShow SSH Server status, or start/stop/restart SSH Server.UsagesshserverShow

Page 268

SSLVPN tunnels.DescriptionList running SSLVPN configurations, SSLVPN active tunnels and call information.Usagesslvpn [-num=<n>]Options-num=<n

Page 269 - 3.121. ST201EthernetPCIDriver

List of Examples1. Command option notation ... 91.1. Help for commands .

Page 270 - 3.122. StateSettings

DescriptionGenerate information useful for technical support.Due to the large amount of output, this command might show a truncated result when execut

Page 271 - 3.123. TCPSettings

Show user authentication rules.DescriptionDisplays the contents of the user authentication ruleset.Example 2.17. Show a range of rulesuarules -v 1-2,4

Page 272

Show status of update servers.Options-removedb={ANTIVIRUS | IDP} Remove the database for the specified service.-servers Show autoupdate server informa

Page 273 - 3.124. ThresholdRule

-remove Forcibly log out an authenticated user. (Adminonly)-user Show all information for user(s) with this IPaddress.<Interface> Interface.<

Page 274

2.3. Utility2.3.1. pingPing host.DescriptionSends one or more ICMP ECHO, TCP SYN or UDP datagrams to the specified IP address of a host.All datagrams

Page 275 - 3.125. TulipEthernetPCIDriver

2.4. Misc2.4.1. echoPrint text.DescriptionPrint text to the console.Example 2.18. Hello Worldecho Hello WorldUsageecho [<String>]...Options<S

Page 276 - 3.126. UpdateCenter

Display help about selected topic from any category.help -category={COMMANDS | TYPES} [<Topic>]Display help from a specific topic category.Optio

Page 277 - 3.127. URLFilterPolicy

Example 2.21. Upload certificate datascp certificate.cer user@sgw-ip:certificate/certificate_namescp certificate.key user@sgw-ip:certificate/certifica

Page 278 - 3.128. UserAuthRule

Execute script.script -show [-all] [-name=<Name>]Show script in console window.script -store [-all] [-name=<Name>]Store a script to persis

Page 279

Chapter 2: Command Reference89

Page 280

PrefaceAudienceThe target audience for this reference guide is:• Administrators that are responsible for configuring and managing the Clavister Securi

Page 281 - 3.129. VLAN

Chapter 3: Configuration Reference• Access, page 94• Address, page 95• AdvancedScheduleProfile, page 99• ALG, page 100• AntiVirusPolicy, page 109• App

Page 282

• DHCPServerSettings, page 133• DHCPv6Server, page 134• DHCPv6ServerSettings, page 136• DNS, page 137• DynamicRoutingRule, page 138• DynDnsClientCjbNe

Page 283 - 3.130. VLANSettings

• IPPool, page 175• IPRule, page 176• IPRuleFolder, page 179• IPRuleSet, page 180• IPsecAlgorithms, page 181• IPsecTunnel, page 183• IPsecTunnelSettin

Page 284

• Pipe, page 223• PipeRule, page 226• PPPoETunnel, page 227• PPPSettings, page 229• PSK, page 230• R8139EthernetPCIDriver, page 231• R8169EthernetPCID

Page 285

• SSLVPNInterfaceSettings, page 268• ST201EthernetPCIDriver, page 269• StateSettings, page 270• TCPSettings, page 271• ThresholdRule, page 273• TulipE

Page 286

3.2. AddressThis is a category that groups the following object types.3.2.1. AddressFolderDescriptionAn address folder can be used to group related ad

Page 287 - Commands

3.2.1.3. EthernetAddressDescriptionUse an Ethernet Address item to define a symbolic name for an Ethernet MAC address.PropertiesName Specifies a symbo

Page 288 - Object types

authentication, but has no credentials (user namesor groups) defined. This means that the object onlyrequires that a user is authenticated, but ignore

Page 289

NoDefinedCredentials If this property is enabled the object requires userauthentication, but has no credentials (user namesor groups) defined. This me

Page 290

3.3. AdvancedScheduleProfileDescriptionAn advanced schedule profile contains definitions of occurrences used by various policies in thesystem.Properti

Modèles reliés E7 CLI | W3 CLI | W5 CLI | X8 CLI |

Commentaires sur ces manuels

Pas de commentaire