Amer Networks E5 CLI User Manual

Page 1
Clavister cOS Core
CLI Reference Guide
Version: 10.20.02
Clavister AB
SE-89160 Örnsköldsvik
Phone: +46-660-299200
Published 2014-03-31
Copyright © 2014 Clavister AB
Sjögatan 6J
SWEDEN
Page 2

Clavister cOS Core

CLI Reference Guide Version: 10.20.02
Published 2014-03-31 Copyright © 2014 Clavister AB
Copyright Notice
This publication, including all photographs, illustrations and software, is protected under international copyright laws, with all rights reserved. Neither this manual, nor any of the material contained herein, may be reproduced without the written consent of Clavister.
Disclaimer
The information in this document is subject to change without notice. Clavister makes no representations or warranties with respect to the contents hereof and specifically disclaims any implied warranties of merchantability or fitness for a particular purpose. Clavister reserves the right to revise this publication and to make changes from time to time in the content hereof without any obligation to notify any person or parties of such revision or changes.
Limitations of Liability
UNDER NO CIRCUMSTANCES SHALL CLAVISTER OR ITS SUPPLIERS BE LIABLE FOR DAMAGES OF ANY CHARACTER (E.G. DAMAGES FOR LOSS OF PROFIT, SOFTWARE RESTORATION, WORK STOPPAGE, LOSS OF SAVED DATA OR ANY OTHER COMMERCIAL DAMAGES OR LOSSES) RESULTING FROM THE APPLICATION OR IMPROPER USE OF THE CLAVISTER PRODUCT OR FAILURE OF THE PRODUCT, EVEN IF CLAVISTER IS INFORMED OF THE POSSIBILITY OF SUCH DAMAGES. FURTHERMORE, CLAVISTER WILL NOT BE LIABLE FOR THIRD-PARTY CLAIMS AGAINST CUSTOMER FOR LOSSES OR DAMAGES. CLAVISTER WILL IN NO EVENT BE LIABLE FOR ANY DAMAGES IN EXCESS OF THE AMOUNT CLAVISTER RECEIVED FROM THE END-USER FOR THE PRODUCT.
2
Page 3

Table of Contents

Preface ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... . 9
1. Introduction . ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... 11
1.1. Running a command .. ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .11
1.2. Help ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ..... 12
1.2.1. Help for commands ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ....... 12
1.2.2. Help for object types .......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ....12
1.3. Function keys ...... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .13
1.4. Command line history .... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... .14
1.5. Tab completion ........ ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... .. 15
1.5.1. Inline help ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ....15
1.5.2. Autocompleting Current and Default value ..... ... ... ... ... ... ... ......... ... ... 16
1.5.3. Configuration object type categories .. ... ... ... ... ......... ... ... ... ... ... ... ... .. 16
1.6. User roles .. ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... .. 18
2. Command Reference ........ ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .. 20
2.1. Configuration . ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... 20
2.1.1. activate . ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... .20
2.1.2. add ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... .. 20
2.1.3. cancel .. ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... .. 22
2.1.4. cc .. ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ........22
2.1.5. commit ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... .. 23
2.1.6. delete ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .23
2.1.7. pskgen ..... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ....... 24
2.1.8. reject ..... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... 25
2.1.9. reset .... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... .. 26
2.1.10. set ..... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... .. 27
2.1.11. show ..... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ........28
2.1.12. undelete . ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ....29
2.2. Runtime .. ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... 31
2.2.1. about .. ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... 31
2.2.2. alarm ...... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .. 31
2.2.3. appcontrol ..... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... .. 31
2.2.4. arp . ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... .32
2.2.5. arpsnoop .... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ..... 33
2.2.6. ats .. ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... .34
2.2.7. authagent ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... .34
2.2.8. authagentsnoop ....... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... .35
2.2.9. blacklist ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... .. 35
2.2.10. buffers .... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ...... 37
2.2.11. cam . ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... .37
2.2.12. certcache ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... .38
2.2.13. cfglog ..... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ...... 38
2.2.14. connections ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... 39
2.2.15. cpuid . ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... .. 40
2.2.16. crashdump ... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... .40
2.2.17. cryptostat .... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ........40
2.2.18. dconsole ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... .. 41
2.2.19. dhcp .... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... 41
2.2.20. dhcprelay ..... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ....42
2.2.21. dhcpserver . ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ....... 42
2.2.22. dhcpv6server ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ....43
2.2.23. dns ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... 44
2.2.24. dnsbl ........ ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .45
2.2.25. dynroute ..... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... .. 45
2.2.26. frags . ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... 46
2.2.27. ha . ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ....... 46
2.2.28. hostmon .. ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... 47
3
Page 4
Clavister cOS Core
2.2.29. httpalg . ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... 47
2.2.30. httpposter . ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ....48
2.2.31. hwm ..... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... .. 48
2.2.32. idppipes .... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ....49
2.2.33. ifstat ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... .49
2.2.34. igmp .. ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... .. 50
2.2.35. ihs .. ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ........51
2.2.36. ikesnoop .... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... 51
2.2.37. ippool .... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... .52
2.2.38. ipsecdefines .. ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... .52
2.2.39. ipsecglobalstats ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... .53
2.2.40. ipsechastat .... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... 53
2.2.41. ipsecstats ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .54
2.2.42. ipsectunnels ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... 54
2.2.43. killsa ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... .55
2.2.44. languagefiles .... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... .55
2.2.45. ldap .. ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... 56
2.2.46. license .. ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... 56
2.2.47. linkmon ..... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .57
2.2.48. logout . ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... .58
2.2.49. memory .. ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... 58
2.2.50. natpool ... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... 58
2.2.51. nd .. ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .. 59
2.2.52. ndsnoop . ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .60
2.2.53. netcon ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... .60
2.2.54. netobjects .. ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... 61
2.2.55. ospf .... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... .61
2.2.56. pcapdump ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... .. 63
2.2.57. pciscan ..... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .. 65
2.2.58. pipes .. ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... .. 66
2.2.59. pptpalg ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... 66
2.2.60. reconfigure .... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... 67
2.2.61. rekeysa . ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... 67
2.2.62. route ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... .68
2.2.63. routemon ........ ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... .68
2.2.64. routes .... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .68
2.2.65. rtmonitor ... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... .69
2.2.66. rules .. ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... .. 70
2.2.67. selftest ....... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... 71
2.2.68. services . ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .. 73
2.2.69. sessionmanager .. ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... .. 73
2.2.70. settings .... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... .. 75
2.2.71. shutdown .... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... .. 75
2.2.72. sipalg . ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... .. 76
2.2.73. sshserver .... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... 78
2.2.74. sslvpn ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... .. 78
2.2.75. stats . ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... .79
2.2.76. sysmsgs . ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... .. 79
2.2.77. techsupport .... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... .. 79
2.2.78. time .. ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... 80
2.2.79. uarules .... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... 80
2.2.80. updatecenter . ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... 81
2.2.81. userauth .. ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... 82
2.2.82. vlan .... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .83
2.2.83. vpnstats ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... .. 83
2.3. Utility ...... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ...... 84
2.3.1. ping ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... 84
2.4. Misc .... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... .85
2.4.1. echo .... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... .. 85
2.4.2. help . ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... 85
2.4.3. history ..... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ....86
4
Page 5
Clavister cOS Core
2.4.4. ls ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... .. 86
2.4.5. script .. ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... 87
3. Configuration Reference ..... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... .90
3.1. Access ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... .. 94
3.2. Address ..... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... .95
3.2.1. AddressFolder .... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .95
3.2.2. EthernetAddress . ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... .98
3.2.3. EthernetAddressGroup ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... .. 98
3.2.4. IP4Address ... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... 98
3.2.5. IP4Group ... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... 98
3.2.6. IP4HAAddress .. ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... 98
3.2.7. IP6Address ... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... 98
3.2.8. IP6Group ... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... 98
3.3. AdvancedScheduleProfile ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... 99
3.3.1. AdvancedScheduleOccurrence .... ... ......... ... ... ... ... ... ... ... ......... ... ... .. 99
3.4. ALG ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... .... 100
3.4.1. ALG_FTP ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... . 100
3.4.2. ALG_H323 ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... .. 101
3.4.3. ALG_HTTP .... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... . 101
3.4.4. ALG_POP3 ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... .. 103
3.4.5. ALG_PPTP .. ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... 104
3.4.6. ALG_SIP ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ........ 104
3.4.7. ALG_SMTP ... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... .. 105
3.4.8. ALG_TFTP ..... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... . 107
3.4.9. ALG_TLS .... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... . 107
3.5. AntiVirusPolicy ..... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... . 109
3.6. ApplicationRuleSet . ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... 110
3.6.1. ApplicationRule ..... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... .. 110
3.7. ARPND ....... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ....... 111
3.8. ARPNDSettings . ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... .. 112
3.9. AuthAgent .. ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... . 115
3.10. AuthenticationSettings . ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... . 116
3.11. BlacklistWhiteHost . ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... .. 117
3.12. BNE2EthernetPCIDriver . ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... . 118
3.13. BroadcomEthernetPCIDriver .... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ... 119
3.14. Certificate ........ ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... 120
3.15. COMPortDevice ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... 121
3.16. ConfigModePool .... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... . 122
3.17. ConnTimeoutSettings .. ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ..... 123
3.18. DateTime ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... 124
3.19. DefaultInterface .. ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... . 125
3.20. Device ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... . 126
3.21. DHCPRelay .... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... 127
3.22. DHCPRelaySettings . ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... . 129
3.23. DHCPServer ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... 130
3.23.1. DHCPServerPoolStaticHost .. ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ...... 131
3.23.2. DHCPServerCustomOption ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... .. 131
3.24. DHCPServerSettings .. ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... .... 133
3.25. DHCPv6Server ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ........ 134
3.25.1. DHCPv6ServerPoolStaticHost . ... ... ... ......... ... ... ... ... ... ... ... ......... ... . 135
3.26. DHCPv6ServerSettings .... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... .. 136
3.27. DNS ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... .. 137
3.28. DynamicRoutingRule ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .. 138
3.28.1. DynamicRoutingRuleExportOSPF ... ... ......... ... ... ... ... ... ... ... ......... .. 139
3.28.2. DynamicRoutingRuleAddRoute . ... ... ... ... ......... ... ... ... ... ... ... ... ....... 139
3.29. DynDnsClientCjbNet .... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... .. 141
3.30. DynDnsClientDyndnsOrg .. ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... 142
3.31. DynDnsClientDynsCx .. ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... 143
3.32. DynDnsClientPeanutHull .. ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... . 144
3.33. E1000EthernetPCIDriver .... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... 145
3.34. E100EthernetPCIDriver .. ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... . 146
5
Page 6
Clavister cOS Core
3.35. Ethernet ........ ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... 147
3.36. EthernetDevice ... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... . 149
3.37. EthernetSettings ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... .. 150
3.38. EventReceiverSNMP2c .... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... .. 152
3.38.1. LogReceiverMessageException ... ... ... ... ... ... ... ... ... ......... ... ... ... ... .. 152
3.39. FileControlPolicy .. ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... 153
3.40. FragSettings .... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... . 154
3.41. GRETunnel ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... . 156
3.42. HighAvailability ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... . 157
3.43. HTTPALGBanners .. ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... .. 158
3.44. HTTPAuthBanners ..... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... . 159
3.45. HTTPPoster ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... .... 160
3.46. HWM ... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... 161
3.47. HWMSettings .... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... 162
3.48. ICMPSettings .... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... 163
3.49. IDList ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... 164
3.49.1. ID .... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... .. 164
3.50. IDPRule . ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... .. 165
3.50.1. IDPRuleAction .. ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... .. 165
3.51. IGMPRule ..... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ....... 167
3.52. IGMPSetting .... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... . 169
3.53. IKEAlgorithms ... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... 170
3.54. InterfaceGroup .. ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... 171
3.55. IPPolicy ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... 172
3.56. IPPool ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... .. 175
3.57. IPRule . ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... . 176
3.58. IPRuleFolder .... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... . 179
3.58.1. IPPolicy ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... . 179
3.58.2. IPRule ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... . 179
3.59. IPRuleSet ..... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... .. 180
3.59.1. IPPolicy ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... . 180
3.59.2. IPRule ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... . 180
3.59.3. IPRuleFolder .. ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... .. 180
3.60. IPsecAlgorithms ...... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... 181
3.61. IPsecTunnel . ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... .. 183
3.62. IPsecTunnelSettings .... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... 186
3.63. IPSettings ....... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .. 188
3.64. ixgbeEthernetPCIDriver ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... .. 191
3.65. IXP4NPEEthernetDriver ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... .. 192
3.66. L2TPClient ..... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... 193
3.67. L2TPServer .... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... 195
3.68. L2TPServerSettings .. ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... 197
3.69. L2TPv3Server .. ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .. 198
3.70. LDAPDatabase .. ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... 199
3.71. LDAPServer ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... 200
3.72. LengthLimSettings .. ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... 201
3.73. LinkAggregation .. ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... 202
3.74. LinkMonitor ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... 204
3.75. LocalReassSettings ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .. 205
3.76. LocalUserDatabase .. ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... 206
3.76.1. User . ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... .. 206
3.77. LogReceiverFWLog ........ ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... 207
3.77.1. LogReceiverMessageException ... ... ... ... ... ... ... ... ... ......... ... ... ... ... .. 207
3.78. LogReceiverMemory . ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... .. 208
3.78.1. LogReceiverMessageException ... ... ... ... ... ... ... ... ... ......... ... ... ... ... .. 208
3.79. LogReceiverSMTP ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... . 209
3.80. LogReceiverSyslog ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ...... 210
3.80.1. LogReceiverMessageException ... ... ... ... ... ... ... ... ... ......... ... ... ... ... .. 210
3.81. LogSettings .. ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... . 211
3.82. LoopbackInterface ..... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... . 212
3.83. MarvellEthernetPCIDriver . ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ....... 213
6
Page 7
Clavister cOS Core
3.84. MiscSettings ...... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .. 214
3.85. MulticastSettings ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .. 216
3.86. NATPool ... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... .... 217
3.87. OSPFProcess ..... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... 218
3.87.1. OSPFArea .. ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .. 219
3.88. Pipe ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... . 223
3.89. PipeRule . ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ...... 226
3.90. PPPoETunnel .... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... 227
3.91. PPPSettings . ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... .. 229
3.92. PSK ..... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... 230
3.93. R8139EthernetPCIDriver ...... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... . 231
3.94. R8169EthernetPCIDriver ...... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... . 232
3.95. RadiusAccounting .. ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... . 233
3.96. RadiusRelay .. ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... . 234
3.97. RadiusServer . ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... . 236
3.98. RealTimeMonitorAlert ....... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... 237
3.99. RemoteIDList . ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... 238
3.100. RemoteMgmtHTTP .. ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... .... 239
3.101. RemoteMgmtNetcon .... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... .. 240
3.102. RemoteMgmtSettings ... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... .. 241
3.103. RemoteMgmtSNMP . ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... . 243
3.104. RemoteMgmtSSH ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... .. 244
3.105. RouteBalancingInstance . ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... . 246
3.106. RouteBalancingSpilloverSettings .... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ..... 247
3.107. RouterAdvertisement .... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... .. 248
3.107.1. RA_PrefixInformation ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... .. 249
3.108. RoutingRule ..... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ..... 250
3.109. RoutingSettings .. ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .. 251
3.110. RoutingTable .... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... . 253
3.110.1. Route .. ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... 253
3.110.2. Route6 ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... . 255
3.110.3. SwitchRoute ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... .. 256
3.111. ScheduleProfile ... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... .. 257
3.112. ServiceGroup .. ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... 258
3.113. ServiceICMP .... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... 259
3.114. ServiceICMPv6 ... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... 261
3.115. ServiceIPProto .... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ...... 263
3.116. ServiceTCPUDP . ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... . 264
3.117. SSHClientKey .. ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... 265
3.118. SSLSettings ....... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... . 266
3.119. SSLVPNInterface ........ ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... .. 267
3.120. SSLVPNInterfaceSettings ..... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... 268
3.121. ST201EthernetPCIDriver ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... 269
3.122. StateSettings ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... .. 270
3.123. TCPSettings ..... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ..... 271
3.124. ThresholdRule .. ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... .. 273
3.124.1. ThresholdAction ........ ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... 273
3.125. TulipEthernetPCIDriver ........ ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... .. 275
3.126. UpdateCenter .. ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... .. 276
3.127. URLFilterPolicy .. ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... . 277
3.127.1. URLFilterPolicy_URL ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... 277
3.128. UserAuthRule ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... .. 278
3.129. VLAN .. ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... .. 281
3.130. VLANSettings .. ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... 283
3.131. WebContentFilteringPolicy . ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... 284
3.132. X3C905EthernetPCIDriver ... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... 285
Alphabetical Index .... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ........ 287
7
Page 8
List of Examples
1. Command option notation ..... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... . 9
1.1. Help for commands ....... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... 12
1.2. Help for object types .... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... .12
1.3. Command line history .... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... 14
1.4. Tab completion ........ ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ....15
1.5. Inline help ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... .. 15
1.6. Edit an existing property value ..... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... .. 16
1.7. Using categories with tab completion .. ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... .16
2.1. Create a new object ..... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .. 21
2.2. Change context ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... 22
2.3. Delete an object . ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... .24
2.4. Reject changes .... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... 25
2.5. Set property values . ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... 27
2.6. Show objects ..... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... .. 28
2.7. Undelete an object .. ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ...... 30
2.8. Block hosts . ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... 36
2.9. frags .... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .. 46
2.10. List network objects which have names containing "net". .. ... ... ... ... ... ... ... ... ......... 61
2.11. Show all monitored objects in the alg/http category . ......... ... ... ... ... ... ... ... ... ........70
2.12. Show a range of rules ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... 70
2.13. Interface ping test between all interfaces ..... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... .71
2.14. Interface ping test between interfaces 'if1' and 'if2' ..... ... ... ... ... ... ... ... ......... ... ... ... 71
2.15. Start 30 min burn-in, testing RAM, storage media and crypto accelerator ....... ... ... .71
2.16. List all services which names begin with "http" . ......... ... ... ... ... ... ... ... ......... ... ... ... .73
2.17. Show a range of rules ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... 81
2.18. Hello World .. ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... .. 85
2.19. Transfer script files to and from the device ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... .86
2.20. Upload license data .. ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ... 86
2.21. Upload certificate data ..... ... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... .. 87
2.22. Upload ssh public key data ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... .87
2.23. Execute script ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... ... ... ... ... ... ......... ... ... .87
8
Page 9

Preface

Audience
The target audience for this reference guide is:
• Administrators that are responsible for configuring and managing the Clavister Security Gateway.
• Administrators that are responsible for troubleshooting the Clavister Security Gateway.
This guide assumes that the reader is familiar with the Clavister Security Gateway, and has the necessary basic knowledge in network security.
Notation
The following notation is used throughout this reference guide when specifying the options of a command:
Angle brackets <name> or
-option=<description>
Square brackets [option] or
-option[=value]
Curly brackets {value1 | value2 | value3}
Ellipsis ... Used for specifying that more than one value can be
Example 1. Command option notation
One of the usages for the help command looks like this:
help -category={COMMANDS | TYPES} [<Topic>]
This means that help has an option called category which has two possible values which are
COMMANDS and TYPES. There is also an optional option called Topic which in this case is a search string used to specify what help topic to display. Since the topic is optional, it is possible to exclude it when running the command.
Both of the following examples are valid for the usage described above:
Used for specifying the name of an option or a description of a value.
Used for specifying that an option or a value for an option is optional and can be omitted.
Used for specifying the available values for an option.
specified for the option.
Device:/> help -category=COMMANDS Device:/> help -category=COMMANDS activate
The usage for the routes command is:
routes [-all] [-switched] [-flushl3cache[=<percent>]] [-num=<n>]
None of the options of this command are mandatory. The flushl3cache option also has an
[-nonhost] [-tables] [-lookup=<ip address>] [-verbose] [-setmtu=<mtu>] [-cacheinfo] [<table name>]...
9
Page 10
Notation Preface
optional value. This is because that option has a default value, 100, which will be used if no value is specified.
The following two examples will yield the same result:
Device:/> routes -flushl3cache=100 Device:/> routes -flushl3cache
Because the table name option is followed by ellipses it is possible to specify more than one routing table. Since table name is optional as well, the user can specify zero or more policy-based routing tables.
Device:/> routes Virroute Virroute2
10
Page 11

Chapter 1: Introduction

• Running a command, page 11
• Help, page 12
• Function keys, page 13
• Command line history, page 14
• Tab completion, page 15
• User roles, page 18
This guide is a reference for all commands and configuration object types that are available in the command line interface for Clavister cOS Core.

1.1. Running a command

The commands described in this guide can be run by typing the command name and then pressing the return key. Many commands require options to be set to run. If a required option is missing a brief syntax help will be displayed.
11
Page 12

1.2. Help

1.2.1. Help for commands

There are two ways of getting help about a command. A brief help is displayed if the command name is typed followed by -? or -h. This applies to all commands and is therefore not listed in the option list for each command in this guide. Using the help command gives a more detailed help corresponding to the information found in this guide. In most cases it is possible to simply type help followed by the command name to get the full help. See Section 2.4.2, “help” for a more detailed description. To list the available commands, just type help and press return.
Example 1.1. Help for commands
Brief help for the activate command:
Device:/> activate -? Device:/> activate -h
Full help for activate:
Chapter 1: Introduction
Device:/> help activate
Help for the arp command. Arp is also the name of a configuration object type, so it is necessary to specify that the help text for the command should be displayed:
Device:/> help -category=COMMANDS arp
List all available commands:
Device:/> help

1.2.2. Help for object types

To get help about configuration object types, use the help command. It is also possible to get information about each property in an object type, such as data type, default value, etc. by entering the ? character when entering the value of a property and pressing tab. More on this in Section 1.5.1, “Inline help”.
Example 1.2. Help for object types
Full help for IP4Address:
Device:/> help IP4Address
Help for the ARP configuration object type, which collides with the arp command:
Device:/> help -category=TYPES ARP
12
Page 13

1.3. Function keys

In addition to the return key there are a number of function keys that are used in the CLI.
Backspace Delete the character to the left of the cursor.
Tab Complete current word.
Ctrl-A or Home Move the cursor to the beginning of the line.
Ctrl-B or Left Arrow Move the cursor one character to the left.
Ctrl-C Clear line or cancel page view if more than one page of
Ctrl-D or Delete Delete the character to the right of the cursor.
Ctrl-E or End Move the cursor to the end of the line.
Ctrl-F or Right Arrow Move the cursor one character to the right.
Ctrl-K Delete from the cursor to the end of the line.
Chapter 1: Introduction
information is shown.
Ctrl-N or Down Arrow Show the next entry in the command history.
Ctrl-P or Up Arrow Show the previous entry in the command history.
Ctrl-T Transpose the current and the previous character.
Ctrl-U Delete from the cursor to the beginning of line.
Ctrl-W Delete word backwards.
13
Page 14

1.4. Command line history

Every time a command is run, the command line is added to a history list. The up and down arrow keys are used to access previous command lines (up arrow for older command lines and down arrow to move back to a newer command line). See also Section 2.4.3, “history”.
Example 1.3. Command line history
Using the command line history via the arrow keys:
Device:/> show Address Device:/> (up arrow) Device:/> show Address (the previous commandline is displayed)
Chapter 1: Introduction
14
Page 15

1.5. Tab completion

By using the tab function key in the CLI the names of commands, options, objects and object properties can be automatically completed. If the text entered before pressing tab only matches one possible item, e.g. "activate" is the only match for "acti", and a command is expected, the name will be autocompleted. Should there be more than one match the part common to all matches will be completed. At this point the user can either enter more characters or press tab again, which will display a list of the possible completions. This can also be done without entering any characters, but the resulting list might be long if there are many possible completions, e.g. all commands.
Example 1.4. Tab completion
An example of tab completion when using the add command:
Device:/> add Add (tab) Device:/> add Address ("ress" was autocompleted) Device:/> add Address i (tab) Device:/> add Address IP4 ("IP4" was autocompleted) Device:/> add Address IP4
(tab, or double tab if IP4 were entered manually) A list of all types starting with IP4 is listed. Device:/> add Address IP4a (tab) Device:/> add Address IP4Address ("Address" was autocompleted) Device:/> add Address IP4Address example_ip a (tab) Device:/> add Address IP4Address example_ip Address=
("Address=" was autocompleted) Device:/> add Address IP4Address example_ip Address=1.2.3.4
Chapter 1: Introduction
Tab completion of references:
Device:/> set Address IP4Group examplegroup Members= (tab, tab) A list of valid objects is displayed. Device:/> set Address IP4Group examplegroup Members=e (tab) Device:/> set Address IP4Group examplegroup Members=example_ip ("example_ip" was autocompleted)

1.5.1. Inline help

It is possible to get help about available properties of configuration objects while a command line is being typed by using the ? character. Write ? instead of a property name and press tab and a help text for the available properties is shown. If ? is typed in stead of a property value and tab is pressed a help text for that property which contains more information such as data type, default value, etc. is displayed.
Example 1.5. Inline help
Get inline help for all properties of an IP4Address:
Device:/> set IP4Address example_ip ? (tab) A help text describing all available properties is displayed.
Getting inline help for the Address property:
Device:/> set IP4Address example_ip Address=? (tab)
15
Page 16
A more detailed help text about Address is displayed.

1.5.2. Autocompleting Current and Default value

Another special character that can be used together with tab completion is the period "." character. If "." is entered instead of a property value and tab is pressed it will be replaced by the current value of that property. This is useful when editing an existing list of items or a long text value.
The "<" character before a tab can be used to automatically fill in the default value for a parameter if no value has yet been set. If the "." character is used, all possible values will be shown and these can then be edited with the back arrrow and backspace keys.
Example 1.6. Edit an existing property value
Edit the current value:
Device:/> add IP4Address example_ip Address=1.2.3.4 Device:/> set IP4Address example_ip Address=. (tab) Device:/> set IP4Address example_ip Address=1.2.3.4
(the value was inserted) The value can now be edited by using the arrow keys or backspace.
Chapter 1: Introduction
Device:/> set IP4Group examplegroup Members=ip1,ip2,ip3,ip5 Device:/> set IP4Group examplegroup Members=. (tab) Device:/> set IP4Group examplegroup Members=ip1,ip2,ip3,ip5 (the value was inserted) It is now possible to add or remove a member to the list without having to enter all the other members again.
Edit the default value:
Device:/> add LogReceiverSyslog example Address=example_ip Device:/> add LogReceiverSyslog example Address=example_ip
LogSeverity=Emergency,Alert,Critical,Error,Warning,Notice,Info
LogSeverity=. (tab)
Now it is easy to remove a log severity.

1.5.3. Configuration object type categories

Some object types are grouped together in a category in the CLI. This only matters when using tab completion as they are used to limit the number of possible completions when tab completing object types. The category can always be omitted when running commands if the type name is entered manually.
Example 1.7. Using categories with tab completion
Accessing an IP4Address object with the use of categories:
Device:/> show ad (tab) Device:/> show Adress (the category is autocompleted) Device:/> show Adress ip4a (tab) Device:/> show Adress IP4Address (the type is autocompleted) Device:/> show Adress IP4Address example_ip
16
Page 17
Accessing an IP4Address object without the use of categories:
Device:/> show IP4Address example_ip
Chapter 1: Introduction
17
Page 18

1.6. User roles

Some commands and options cannot be used unless the logged-in user has administrator privileges. This is indicated in this guide by a note following the command or Admin only written next to an option.
Chapter 1: Introduction
18
Page 19
Chapter 1: Introduction
19
Page 20

Chapter 2: Command Reference

• Configuration, page 20
• Runtime, page 31
• Utility, page 84
• Misc, page 85

2.1. Configuration

2.1.1. activate

Activate changes.
Description
Activate the latest changes.
This will issue a reconfiguration, using the new configuration. If the reconfiguration is successful a commit command must be issued within the configured timeout interval in order to save the changes to media. If not, the system will revert to using the previous version of the configuration.
Usage
activate

2.1.2. add

Create a new object.
Note
Requires Administrator privilege.
20
Page 21
Chapter 2: Command Reference
Description
Create a new object and add it to the configuration.
Specify the type of object you want to create and the identifier, if the type has one, unless the object is identified by an index. Set the properties of the object by writing the propertyname equals (=) and then the value. An optional category can be specified for some object types when using tab completion.
If a mandatory property isn't specified a list of errors will be shown after the object is created. If an invalid property or value type is specified or if the identifier is missing the command will fail and not create an object.
Adjustments can be made after the object is created by using the set command.
Example 2.1. Create a new object
Add objects with an identifier property (not index):
gw-world:/> add Address IP4Address example_ip Address=1.2.3.4 Comments="This is an example" gw-world:/> add IP4Address example_ip2 Address=2.3.4.5
Add an object with an index:
gw-world:/main> add Route Interface=lan
Add an object without identifier:
gw-world:/> add DynDnsClientDyndnsOrg DNSName=example Username=example
Usage
add [<Category>] <Type> [<Identifier>] [-force] [-silent]
[<key-value pair>]...
Options
-force Add object, even if it has errors.
-silent Do not show any errors.
<Category> Category that groups object types.
<Identifier> The property that identifies the configuration
object. May not be applicable depending on the specified <Type>.
<key-value pair> One or more property-value pairs, i.e. <property
name>=<value> or <property name>="<value>".
<Type> Type of configuration object to perform operation
on.
Note
Requires Administrator privilege.
21
Page 22

2.1.3. cancel

Cancel ongoing commit.
Description
Cancel commit operation immediately, without waiting for the timeout.
Usage
cancel
Chapter 2: Command Reference
Note
Requires Administrator privilege.

2.1.4. cc

Change the current context.
Description
Change the current configuration context.
A context is a group of objects that are dependent on and grouped by a parent object. Many objects lie in the "root" context and do not have a specific parent. Other objects, e.g. User objects lie in a sub-context (or child context) of the root - in this case in a LocalUserDatabase. In order to add or modify users you have to be in the correct context, e.g. a LocalUserDatabase called "exampledb". Only objects in the current context can be accessed.
Example 2.2. Change context
Change to a sub/child context:
Go back to the parent context:
Go back to the root context:
or
gw-world:/> cc LocalUserDatabase exampledb gw-world:/exampledb>
gw-world:/ospf1/area1> cc .. gw-world:/ospf1> cc .. gw-world:/>
gw-world:/ospf1/area1> cc gw-world:/>
gw-world:/ospf1/area1> cc / gw-world:/>
Usage
cc [<Category>] <Type> <Identifier>
22
Page 23
Chapter 2: Command Reference
Change the current context.
cc -print
Print the current context.
cc
Change to root context (same as "cc /").
Options
-print Print the current context.
<Category> Category that groups object types.
<Identifier> The property that identifies the configuration
object. May not be applicable depending on the specified <Type>.
<Type> Type of configuration object to perform operation
on.

2.1.5. commit

Save new configuration to media.
Description
Save the new configuration to media. This command can only be issued after a successful activate command.
Usage
commit

2.1.6. delete

Delete specified objects.
Note
Requires Administrator privilege.
Description
Delete the specified object, removing it from the configuration.
Add the force flag to delete the object even if it is referenced by other objects or if it is a context that has child objects that aren't deleted. This may cause objects referring to the specified object or one of its children to get errors that must be corrected before the configuration can be
23
Page 24
Chapter 2: Command Reference
activated.
See also: undelete
Example 2.3. Delete an object
Delete an unreferenced object:
gw-world:/> delete Address IP4Address example_ip Delete a referenced object: (will cause error in examplerule)
gw-world:/> set IPRule examplerule SourceNetwork=examplenet
gw-world:/> delete Address IP4Address examplenet -force
Usage
delete [<Category>] <Type> [<Identifier>] [-force]
Options
-force Force object to be deleted even if it's used by other
<Category> Category that groups object types.
<Identifier> The property that identifies the configuration
<Type> Type of configuration object to perform operation

2.1.7. pskgen

Generate random pre-shared key.
objects or has children.
object. May not be applicable depending on the specified <Type>.
on.
Note
Requires Administrator privilege.
Description
Generate a pre-shared key of specified size, containing randomized key data. If a key with the specified name exists, the existing key is modified. Otherwise a new key object is created.
Usage
pskgen <Name> [-comments=<String>] [-size={64 | 128 | 256 | 512 |
1024 | 2048 | 4096}]
24
Page 25
Chapter 2: Command Reference
Options
-comments=<String> Comments for this key.
-size={64 | 128 | 256 | 512 | 1024 | 2048 | 4096}
<Name> Name of key.

2.1.8. reject

Reject changes.
Description
Reject the changes made to the specified object by reverting to the values of the last committed configuration.
All changes made to the object will be lost. If the object is added after the last commit, it will be removed.
To reject the changes in more than one object, use either the -recursive flag to delete a context and all its children recursively or the -all flag to reject the changes in all objects in the configuration.
Number of bits of data in the generated key. (Default: 64)
Note
Requires Administrator privilege.
See also: activate, commit
Example 2.4. Reject changes
Reject changes in individual objects:
gw-world:/> set Address IP4Address example_ip
Comments="This comment will be rejected"
gw-world:/> reject Address IP4Address example_ip
gw-world:/> add Address IP4Address example_ip2 Address=1.2.3.4
Comments="This whole object will be removed"
gw-world:/> reject Address IP4Address example_ip2 Reject changes recursively: (will reject changes in the user database and all users)
gw-world:/exampledb> set User user1 Comments="Something"
gw-world:/exampledb> set User user2 Comments="that will be"
gw-world:/exampledb> set User user3 Comments="rejected"
gw-world:/exampledb> cc ..
gw-world:/> reject LocalUserDatabase exampledb -recursive Reject all changes:
gw-world:/anycontext> reject -all All changes since the last commit will be rejected: (example_ip will be removed since it is newly added)
gw-world:/> add IP4Address example_ip Address=1.2.3.4
gw-world:/> delete IP4Address example_ip
gw-world:/> reject IP4Address example_ip
25
Page 26
Chapter 2: Command Reference
Usage
reject [<Category>] <Type> [<Identifier>] [-recursive]
Reject changes made to the specified object.
reject -all
Reject all changes in the configuration.
Options
-all Reject all changes in the configuration.
-recursive Recursively reject changes.
<Category> Category that groups object types.
<Identifier> The property that identifies the configuration
object. May not be applicable depending on the specified <Type>.
<Type> Type of configuration object to perform operation

2.1.9. reset

Reset unit configuration and/or binaries.
Description
Reset configuration to the base configuration as generated by the current core or reset binaries to factory defaults.
Usage
reset -configuration
on.
Note
Requires Administrator privilege.
Reset the configuration to factory defaults.
reset -unit
Reset the unit to factory defaults.
Options
-configuration Reset configuration to current core default.
26
Page 27
-unit Reset unit to factory defaults.

2.1.10. set

Set property values.
Description
Set property values of configuration objects.
Specify the type of object you want to modify and the identifier, if the type has one. Set the properties of the object by writing the propertyname equals (=) and then the value. An optional category can be specified for some object types when using tab completion.
Chapter 2: Command Reference
Note
Requires Administrator privilege.
If a mandatory property hasn't been specified or if a property has an error a list of errors will be shown after the specified properties have been set. If an invalid property or value type is specified the command will fail and not modify the object.
See also: add
Example 2.5. Set property values
Set properties for objects that have an identifier property:
gw-world:/> set Address IP4Address example_ip Address=1.2.3.4
Comments="This is an example"
gw-world:/> set IP4Address example_ip2 Address=2.3.4.5
Comments=comment_without_whitespace
gw-world:/main> set Route 1 Comment="A route"
gw-world:/> set IPRule 12 Index=1 Set properties for an object without identifier:
gw-world:/> set DynDnsClientDyndnsOrg Username=example
Usage
set [<Category>] <Type> [<Identifier>] [-disable] [-enable]
[-force] [<key-value pair>]...
Options
-disable Disable object. This option is not available if the
object is already disabled.
-enable Enable object. This option is not available if the
object is already enabled.
-force Set values, even if they contain errors.
27
Page 28
<Category> Category that groups object types.
<Identifier> The property that identifies the configuration
<key-value pair> One or more property-value pairs, i.e. <property
<Type> Type of configuration object to perform operation

2.1.11. show

Show objects.
Chapter 2: Command Reference
object. May not be applicable depending on the specified <Type>.
name>=<value> or <property name>="<value>".
on.
Note
Requires Administrator privilege.
Description
Show objects.
Show the properties of a specified object. There are a number of flags that can be specified to show otherwise hidden properties. To show a list of object types and categories available in the current context, just type show. Show a table of all objects of a type by specifying a type or a category. Use the -errors or -changes flags to show what objects have been changed or have errors in the configuration.
When showing a table of all objects of a certain type, the status of each object since the last time the configuration was committed is indicated by a flag. The flags used are:
- The object is deleted.
o The object is disabled.
! The object has errors.
+ The object is newly created.
* The object is modified.
Additional flags:
D The object has dynamic properties which are updated by the system.
When listing categories and object types, categories are indicated by [] and types where objects may be contexts by /.
Example 2.6. Show objects
Show the properties of an individual object:
28
Page 29
Chapter 2: Command Reference
gw-world:/> show Address IP4Address example_ip
gw-world:/main> show Route 1
gw-world:/> show Client DynDnsClientDyndnsOrg Show a table of all objects of a type and a selection of their properties as well as their status:
gw-world:/> show Address IP4Address
gw-world:/> show IP4Address Show a table of all objects for each type in a category:
gw-world:/> show Address Show objects with changes and errors:
gw-world:/> show -changes
gw-world:/> show -errors Show what objects use (refer to) a certain object:
gw-world:/> show Address IP4Address example_ip -references
Usage
show
Show the types and categories available in the current context.
show [<Category>] [<Type> [<Identifier>]] [-disabled] [-references]
Show an object or list a type or category.
show -errors [-verbose]
Show all errors.
show -changes
Show all changes.
Options
-changes Show all changes in the current configuration.
-disabled Show disabled properties.
-errors Show all errors in the current configuration.
-references Show all references to this object from other
objects.
-verbose Show error details.
<Category> Category that groups object types.
<Identifier> The property that identifies the configuration
<Type> Type of configuration object to perform operation

2.1.12. undelete

object. May not be applicable depending on the specified <Type>.
on.
29
Page 30
Chapter 2: Command Reference
Restore previously deleted objects.
Description
Restore a previously deleted object.
This is possible as long as the activate command has not been called.
See also: delete
Example 2.7. Undelete an object
Undelete an unreferenced object:
gw-world:/> delete Address IP4Address example_ip
gw-world:/> undelete Address IP4Address example_ip Undelete a referenced object: (will remove the error in examplerule)
gw-world:/> set IPRule examplerule SourceNetwork=examplenet
gw-world:/> delete Address IP4Address examplenet -force
gw-world:/> undelete Address IP4Address examplenet
Usage
undelete [<Category>] <Type> [<Identifier>]
Options
<Category> Category that groups object types.
<Identifier> The property that identifies the configuration
object. May not be applicable depending on the specified <Type>.
<Type> Type of configuration object to perform operation
on.
Note
Requires Administrator privilege.
30
Page 31

2.2. Runtime

2.2.1. about

Show copyright/build information.
Description
Show copyright and build information.
Usage
about

2.2.2. alarm

Chapter 2: Command Reference
Show alarm information.
Description
Show list of currently active alarms.
Usage
alarm [-history] [-active]
Options
-active Show the currently active alarms.
-history Show the 20 latest alarms.

2.2.3. appcontrol

Show application control status.
Description
Browse the applications defined in the Application Control functionality. Saved browsing results as filters that can be later used to define IPPolicies.
Usage
31
Page 32
appcontrol
Show general information about application control system.
appcontrol -show_lists
List information about specified application.
appcontrol -delete_lists={ALL | <Integer>}
List information about specified application.
appcontrol <Name>
List information about specified application.
appcontrol -application=<String> [-save_list]
Define a filter selecting individual applications.
Chapter 2: Command Reference
appcontrol -filter [-name=<String>] [-family=<String>]
[-risk={VERY_LOW | LOW | MEDIUM | HIGH | VERY_HIGH}] [-tag=<String>] [-save_list]
Define a filter selecting families, tags, risks and a matching expression for the applications names.
Options
-application=<String> Exact application name.
-delete_lists={ALL | <Integer>} Free saved Strings.
-family=<String> Application family.
-filter Shows applications matching certain criteria.
-name=<String> Application name (wildcards allowed).
-risk={VERY_LOW | LOW | MEDIUM |
Application risk level.
HIGH | VERY_HIGH}
-save_list Saved filter result.
-show_lists List saved strings.
-tag=<String> Application tag.
<Name> Application name.

2.2.4. arp

Show ARP entries for given interface.
Description
List the ARP cache entries of specified interfaces.
If no interface is given the ARP cache entries of all interfaces will be presented.
32
Page 33
Chapter 2: Command Reference
The presented list can be filtered using the ip and hw options.
Usage
arp
Show all ARP entries.
arp -show [<Interface>] [-ip=<pattern>] [-hw=<pattern>] [-num=<n>]
Show ARP entries.
arp -hashinfo [<Interface>]
Show information on hash table health.
arp -flush [<Interface>]
Flush ARP cache of specified interface.
arp -notify=<ip> [<Interface>] [-hwsender=<Ethernet Address>]
Send gratuitous ARP for IP.
Options
-flush Flush ARP cache of all specified interfaces.
-hashinfo Show information on hash table health.
-hw=<pattern> Show only hardware addresses matching pattern.
-hwsender=<Ethernet Address> Sender ethernet address.
-ip=<pattern> Show only IP addresses matching pattern.
-notify=<ip> Send gratuitous ARP for <ip>.
-num=<n> Show only the first <n> entries per interface.
-show Show ARP entries for given interface(s).
<Interface> Interface name.

2.2.5. arpsnoop

(Default: 20)
Toggle snooping and displaying of ARP requests.
Description
Toggle snooping and displaying of ARP queries and responses on-screen.
The snooped messages are displayed before the access section validates the sender IP addresses in the ARP data.
33
Page 34
Usage
arpsnoop
Show snooped interfaces.
arpsnoop {ALL | NONE | <interface>} [-verbose]
Snoop specified interface.
Options
-verbose Verbose.
{ALL | NONE | <interface>} Interface name.

2.2.6. ats

Chapter 2: Command Reference
Show active ARP Transaction States.
Description
Show active ARP Transaction States.
Usage
ats [-num=<n>]
Options
-num=<n> Limit list to <n> entries. (Default: 20)

2.2.7. authagent

Shows the state of the Authentication Agents.
Description
Shows the state of the Authentication Agents.
Usage
authagent
Shows the state of the configured Authentication Agents.
34
Page 35
authagent {ALL | <AuthAgent>}
Shows the state of the configured Authentication Agents.
authagent -reconnect {ALL | <AuthAgent>}
Closes the connection with the Agent and attempst to reconnect.
Options
-reconnect Closes the connection with the Agent and
{ALL | <AuthAgent>} Authentication Agent name.

2.2.8. authagentsnoop

Toggle snooping and displaying of Authentication Agents traffic.
Chapter 2: Command Reference
attempst to reconnect. (Admin only)
Description
Toggle snooping and displaying of Authentication Agents queries and responses on-screen.
Usage
authagentsnoop
Show snooped Authentication Agents.
authagentsnoop {ALL | NONE | <AuthAgent>} [-verbose]
Snoop specified Authentication Agent.
Options
-verbose Verbose.
{ALL | NONE | <AuthAgent>} Authentication Agent name.
Note
Requires Administrator privilege.

2.2.9. blacklist

Blacklist.
Description
Block and unblock hosts on the black and white list.
35
Page 36
Chapter 2: Command Reference
Note: Static blacklist hosts cannot be unblocked.
If -force is not specified, only the exact host with the service, protocol/port and destiny specified is unblocked.
Example 2.8. Block hosts
blacklist -show -black -listtime -info blacklist -block 100.100.100.0/24 -serv=FTP -dest=50.50.50.1 -time=6000
Usage
blacklist -show [-creationtime] [-dynamic] [-listtime] [-info]
[-black] [-white] [-all]
Show information about the blacklisted hosts.
blacklist -block <host> [-serv=<service>] [-prot={TCP | UDP | ICMP
| OTHER | TCPUDP | ALL}] [-port=<port number>] [-dest=<ip address>] [-time=<seconds>]
Block specified netobject.
blacklist -unblock <host> [-serv=<service>] [-prot={TCP | UDP |
ICMP | OTHER | TCPUDP | ALL}] [-port=<port number>] [-dest=<ip address>] [-time=<seconds>] [-force]
Unblock specified netobject.
Options
-all Show all the information.
-black Show blacklist hosts only.
-block Block specified netobject. (Admin only)
-creationtime Show creation time.
-dest=<ip address> Destination address to block/unblock
(ExceptExtablished flag is set on).
-dynamic Show dynamic hosts only.
-force Unblock all services for the host that matches to
options.
-info Show detailed information.
-listtime Show time in list (for dynamic hosts).
-port=<port number> Number of the port to block/unblock.
-prot={TCP | UDP | ICMP | OTHER |
Protocol to block/unblock.
TCPUDP | ALL}
-serv=<service> Service to block/unblock.
36
Page 37
-show Show information about the blacklisted hosts.
-time=<seconds> The time that the host will remain blocked.
-unblock Unblock specified netobject. (Admin only)
-white Show whitelist hosts only.
<host> IP address range.

2.2.10. buffers

List packet buffers or the contents of a buffer.
Description
Lists the 20 most recently freed packet buffers, or in-depth information about a specific buffer.
Chapter 2: Command Reference
Usage
buffers
List the 20 most recently freed buffers.
buffers -recent
Decode the most recently freed buffer.
buffers <Num>
Decode buffer number <Num>.
Options
-recent Decode most recently freed buffer.
<Num> Decode given buffer number.

2.2.11. cam

CAM table information.
Description
Show information about the CAM table(s) and their entries.
Usage
cam -num=<n>
37
Page 38
Chapter 2: Command Reference
Show CAM table information.
cam <Interface> [-num=<n>]
Show interface-specified CAM table information.
cam <Interface> [-flush]
Flush CAM table information of specified interface.
cam -flush
Flush CAM table information.
Options
-flush Flush CAM table. If interface is specified, only
entries using this interface are flushed. (Admin only)
-num=<n> Limit list to <n> entries per CAM table. (Default: 20)
<Interface> Interface.

2.2.12. certcache

Show the contents of the certificate cache.
Description
Show all certificates in the certificate cache.
Usage
certcache [-verbose]
Options
-verbose Show verbose information.

2.2.13. cfglog

Display configuration log.
Description
Display the log of the last configuration read attempt.
Usage
38
Page 39
cfglog

2.2.14. connections

List current state-tracked connections.
Description
List current state-tracked connections.
Usage
Chapter 2: Command Reference
connections -show [-num=<n>] [-verbose] [-srciface=<interface>]
[-destiface=<interface>] [-protocol=<name/num>] [-srcport=<port>] [-destport=<port>] [-srcip=<ip addr>] [-destip=<ip addr>] [-ipver={IPV6 | IPV4}]
List connections.
connections
Same as "connections -show".
connections -close [-all] [-ipver={IPV6 | IPV4}]
[-srciface=<interface>] [-destiface=<interface>] [-protocol=<name/num>] [-srcport=<port>] [-destport=<port>] [-srcip=<ip addr>] [-destip=<ip addr>]
Close connections.
Options
-all Mark all connections.
-close Close all connections that match the filter
expression. (Admin only)
-destiface=<interface> Filter on destination interface.
-destip=<ip addr> Filter on destination IP address.
-destport=<port> Show only given destination TCP/UDP port.
-ipver={IPV6 | IPV4} List only connections of the specified IP version.
-num=<n> Limit list to <n> connections. (Default: 20)
-protocol=<name/num> Show only given IP protocol.
-show Show connections.
-srciface=<interface> Filter on source interface.
-srcip=<ip addr> Filter on source IP address.
-srcport=<port> Show only given source TCP/UDP port.
39
Page 40
-verbose Verbose (more information).

2.2.15. cpuid

Display info about the cpu.
Description
Display the make and model of the machine's CPU.
Usage
cpuid
Chapter 2: Command Reference

2.2.16. crashdump

Show the contents of the crash.dmp file.
Description
Show the contents of the crash.dmp file, if it exists.
Usage
crashdump

2.2.17. cryptostat

Show information about crypto accelerators.
Description
Show information about installed crypto accelerators.
Usage
cryptostat [-hashinfo]
Options
-hashinfo Show information about the hardware fastpath
hash.
40
Page 41

2.2.18. dconsole

Displays the content of the diagnose console.
Description
The diagnose console is used to help troubleshooting internal problems within the security gateway
Usage
dconsole [-clean] [-flush] [-date=<date>] [-onlyhigh]
Options
-clean Remove all diagnose entries. (Admin only)
Chapter 2: Command Reference
-date=<date> YYYY-MM-DD. Only show entries from this date
-flush Flush all diagnose entries to disk. (Admin only)
-onlyhigh Only show entries with severity high. (Admin only)

2.2.19. dhcp

Display information about DHCP-enabled interfaces or modify/update their leases.
Description
Display information about a DHCP-enabled interface.
Usage
dhcp
List DHCP enabled interfaces.
and forward.
dhcp -list
List DHCP enabled interfaces.
dhcp -show [<interface>]
Show information about DHCP enabled interface.
dhcp -lease={RENEW | RELEASE} <interface>
Modify interface lease.
41
Page 42
Options
-lease={RENEW | RELEASE} Modify interface lease.
-list List all DHCP enabled interfaces.
-show Show information about DHCP enabled interface.
<interface> DHCP Interface.

2.2.20. dhcprelay

Show DHCP/BOOTP relayer ruleset.
Description
Display the content of the DHCP/BOOTP relayer ruleset and the current routed DHCP relays.
Display filter filters relays based on interface/ip (example: if1 192.168.*)
Chapter 2: Command Reference
Usage
dhcprelay
Show the currently relayed DHCP sessions.
dhcprelay -show [-rules] [-routes] [<display filter>]...
Show DHCP/BOOTP relayer ruleset.
dhcprelay -release <ip address> [-interface=<Interface>]
Terminate relayed session.
Options
-interface=<Interface> Interface.
-release Terminate relayed session <[interface:]ip>. (Admin
only)
-routes Show the currently relayed DHCP sessions.
-rules Show the DHCP/BOOTP relayer ruleset.
-show Show ruleset.
<display filter> Display filter, filters relays based on interface/ip.
<ip address> IP address.

2.2.21. dhcpserver

42
Page 43
Chapter 2: Command Reference
Show content of the DHCP server ruleset.
Description
Show the content of the DHCP server ruleset and various information about active/inactive leases.
Display filter filters entries based on Interface/MAC/IP (example: If1 192.168.*)
Usage
dhcpserver
Show DHCP server leases.
dhcpserver -show [-rules] [-leases] [-num=<Integer>]
Show DHCP server ruleset.
dhcpserver -release={BLACKLIST}
Release a specific types of IPs.
dhcpserver -releaseip <Interface> <IP address>
Release an active IP.
Options
-fromentry=<Integer> Show entry list from offset <n>.
-leases Show DHCP server leases.
-mappings Show DHCP server IP mappings.
-num=<Integer> Limit list to <n> entries.
-release={BLACKLIST} Release specific type of IPs. (Admin only)
-releaseip Release an active IP. (Admin only)
[-fromentry=<Integer>] [-mappings] [-utilization] [<Display filter>]...
-rules Show DHCP server rules.
-show Show ruleset.
-utilization Show IP pool utilization.
<Display filter> Display filter based on Interface/MAC/IP (eg. If1
<Interface> Interface.
<IP address> IP address.

2.2.22. dhcpv6server

192.168.*).
43
Page 44
Chapter 2: Command Reference
Show content of the DHCPv6 server ruleset.
Description
Show the content of the DHCPv6 server ruleset and various information about active/inactive leases.
Display filter filters leases based on interface/mac/ip (example: if1 2001:DB8::*)
Usage
dhcpv6server
Show DHCPv6 server leases.
dhcpv6server -releaseip <interface> <IPv6 address>
Release an active IP6.
dhcpv6server -show [-rules] [-leases] [-num=<Integer>]
Show DHCP server ruleset.
Options
-fromentry=<Integer> Shows dhcp server lease list from offset <n>.
-leases Show DHCPv6 server leases.
-num=<Integer> Limit list to <n> leases.
-releaseip Release an active IP. (Admin only)
-rules Show DHCPv6 server rules.
-show Show ruleset.
<display filter> Display filters for leases based on interface/mac/ip
<interface> Interface.
<IPv6 address> IPv6 address.
[-fromentry=<Integer>] [<display filter>]...
(eg. if1 2001:DB8::*).

2.2.23. dns

DNS client and queries.
Description
Show status of the DNS client and manage pending DNS queries.
Usage
44
Page 45
dns [-query=<domain name>] [-list] [-remove]
Options
-list List pending DNS queries.
-query=<domain name> Resolve domain name.
-remove Remove all pending DNS queries.

2.2.24. dnsbl

DNSBL.
Description
Show status of DNSBL.
Chapter 2: Command Reference
Usage
dnsbl [-show] [<SMTP ALG>] [-clean]
Options
-clean Clear DNSBL statistics for ALG.
-show Show DNSBL statistics for ALG.
<SMTP ALG> Name of SMTP ALG.

2.2.25. dynroute

Show dynamic routing policy.
Description
Show the dynamic routing policy filter ruleset and current exports.
In the "Flags" field of the dynrouting exports, the following letters are used:
o Route describe the optimal path to the network
u Route is unexported
Usage
dynroute [-rules] [-exports]
45
Page 46
Options
-exports Show current exports.
-rules Show dynamic routing, filter ruleset.

2.2.26. frags

Show active fragment reassemblies.
Description
List active fragment reassemblies.
More detailed information can optionally be obtained for specific reassemblies:
NEW Newest reassembly
Chapter 2: Command Reference
ALL All reassemblies
0..1023 Assembly 'N'
Example 2.9. frags
frags NEW frags 254
Usage
frags [{NEW | ALL | <reassembly id>}] [-free] [-done] [-num=<n>]
Options
-done List done (lingering) reassemblies.
-free List free instead of active.
-num=<n> List <n> entries. (Default: 20)
{NEW | ALL | <reassembly id>} Show in-depth info about reassembly <n>.

2.2.27. ha

Show current HA status.
(Default: all)
46
Page 47
Description
Show current HA status.
Usage
ha [-activate] [-deactivate]
Options
-activate Go active.
-deactivate Go inactive.

2.2.28. hostmon

Chapter 2: Command Reference
Show Host Monitor statistics.
Description
Show active Host Monitor sessions.
Usage
hostmon [-verbose] [-num=<n>]
Options
-num=<n> Limit list to <n> entries. (Default: 20)
-verbose Verbose output.

2.2.29. httpalg

Commands related to the HTTP Application Layer Gateway.
Description
Show information about the WCF cache or list the overridden WCF hosts.
Usage
httpalg -override [-flush]
47
Page 48
List or flush hosts that have overridden the wcf filter.
Chapter 2: Command Reference
httpalg -wcfcache [-show] [-url=<String>] [-flush] [-verbose]
Display URL cache information.
Options
-count Only display cache count.
-flush Removes all entries.
-num=<n> Limit list to <n> entries. (Default: 20)
-override List hosts that have overridden the wcf filter.
-server[={STATUS | CONNECT | DISCONNECT}]
-show Show Web Content Filtering cache data.
-url=<String> Limits the output from the show command to only
-verbose Verbose.
-wcfcache Show statistics of WCF functionality.
[-count] [-server[={STATUS | CONNECT | DISCONNECT}]] [-num=<n>]
Web Content Filtering Server options. (Default: status)
match the specified characters.

2.2.30. httpposter

Display HTTP Poster status.
Description
Display configuration and status of configured HTTPPoster_URLx targets.
Usage
httpposter [-repost=<Integer>]
Options
-repost=<Integer> Re-post URL now. (Admin only)

2.2.31. hwm

Show hardware monitor sensor status.
Description
48
Page 49
Show hardware monitor sensor status.
Usage
hwm [-all] [-verbose]
Options
-all Show ALL sensors, WARNING: use at own risk, may
-verbose Show sensor number, type and limits.

2.2.32. idppipes

Show and remove hosts that are piped by IDP.
Chapter 2: Command Reference
take long time for highspeed ifaces to cope.
Description
Show list of currently piped hosts.
Usage
idppipes
List all idppipes.
idppipes -show [-host=<ip addr>]
Lists hosts for which new connections are piped by IDP.
idppipes -unpipe [-all] [-host=<ip addr>]
Remove piping for the specified host.
Options
-all mark all hosts.
-host=<ip addr> Filter on source IP address.
-show Lists hosts for which new connections are piped by
-unpipe Remove piping for the specified host. (Admin only)

2.2.33. ifstat

Show interface statistics.
IDP.
49
Page 50
Chapter 2: Command Reference
Description
Show list of attached interfaces, or in-depth information about a specific interface.
Usage
ifstat [<Interface>] [-filter=<expr>] [-pbr=<table name>]
Options
-allindepth Show in-depth information about all interfaces.
-filter=<expr> Filter list of interfaces.
-maclist Show MAC addresses for all interfaces.
-num=<n> Limit list to <n> lines. (Default: 20)
-pbr=<table name> Only list members of given PBR table(s).
-restart Stop and restart the interface. (Admin only)
<Interface> Name of interface.

2.2.34. igmp

IGMP Interfaces.
[-num=<n>] [-restart] [-allindepth] [-maclist]
Description
Show information about the current state of the IGMP interfaces.
Send simulated messages to test configuration of the interface.
Usage
igmp
Prints the current IGMP state.
igmp -state [<Interface>]
Prints the current IGMP state. If an interface is specified, more details are provided.
igmp -query <Interface> [<MC address> [<router address>]]
Simulate an incoming IGMP query message.
igmp -join <Interface> <MC address> [<host address>]
Simulate an incoming IGMP join message.
50
Page 51
Chapter 2: Command Reference
igmp -leave <Interface> <MC address> [<host address>]
Simulate an incoming IGMP leave message.
Options
-join Simulate an incoming IGMP join message.
-leave Simulate an incoming IGMP leave message.
-query Simulate an incoming IGMP query message.
-state Show the current IGMP state.
<host address> Host IP address.
<Interface> Interface.
<MC address> Multicast Address.
<router address> Router IP address.

2.2.35. ihs

Alias for ipsechastat.

2.2.36. ikesnoop

Enable or disable IKE-snooping.
Description
Turn IKE on-screen snooping on/off. Useful for troubleshooting IPsec connections.
Usage
ikesnoop
Show IKE snooping status.
ikesnoop -on [<ip address>] [-verbose]
Enable IKE snooping.
ikesnoop -off
Disable IKE snooping.
Options
-off Turn IKE snooping off.
-on Turn IKE snooping on.
51
Page 52
-verbose Enable IKE snooping with verbose output.
<ip address> IP address to snoop.

2.2.37. ippool

Show IP pool information.
Description
Show information about the current state of the configured IP pools.
Usage
ippool
Show IP pool information.
Chapter 2: Command Reference
ippool -release [<ip address>] [-all]
Forcibly free IP assigned to subsystem.
ippool -show [-verbose] [-num=<n>]
Show IP pool information.
Options
-all Free all IP addresses.
-num=<n> Limit list to <n> entries. (Default: 10)
-release Forcibly free IP assigned to subsystem. (Admin
-show Show IP pool information.
-verbose Verbose output.
<ip address> IP address to free.

2.2.38. ipsecdefines

only)
Display various DEFINES that specify the system performance.
Description
Display various DEFINES that specify the system performance.
Usage
52
Page 53
ipsecdefines

2.2.39. ipsecglobalstats

Show global ipsec statistics.
Description
List global IPsec statistics.
Usage
ipsecglobalstats -mem [-verbose]
Start IKE test.
ipsecglobalstats -verbose
Chapter 2: Command Reference
Start IKE test.
ipsecglobalstats
Show interfaces.
Options
-mem Show memory statistics.
-verbose Show all statistics.

2.2.40. ipsechastat

Show statistics about HA synchronization for IPsec.
Description
Shows statistics about IKE/IPsec SAs synchronized and how many that failed to import. Sent statistics shows how many packets that has been sent to the other cluster member when this node was active and receive statistics show how many packets/failures it got as inactive.
Usage
ipsechastat [-clear]
Options
-clear Reset all statistics.
53
Page 54

2.2.41. ipsecstats

Show the SAs in use.
Description
List the currently active IKE and IPsec SAs, optionally only showing SAs matching the pattern given for the argument "tunnel".
Usage
Chapter 2: Command Reference
ipsecstats [-ike] [<tunnel>] [-ipsec] [-usage] [-verbose]
[-num={ALL | <Integer>}] [-force]
Options
-force Bypass confirmation question.
-ike Show IKE SAs.
-ipsec Show IPsec SAs.
-num={ALL | <Integer>} Maximum number of entries to show (default:
-usage Show detailed SA statistics information.
-verbose Show verbose information.
<tunnel> Only show SAs matching pattern.

2.2.42. ipsectunnels

Lists the current IPsec configuration.
40/8).
Description
Lists the current IPsec configuration,
Usage
ipsectunnels -iface=<recv iface>
Show specific interface.
ipsectunnels -num={ALL | <Integer>} [-force]
Show specific number if interface.
ipsectunnels
54
Page 55
Show interfaces.
Options
-force Bypass confirmation question.
-iface=<recv iface> IPsec interface to show information about.
-num={ALL | <Integer>} Maximum number of entries to show (default: 40).

2.2.43. killsa

Kill all SAs belonging to the given remote SG/peer.
Description
Kill all (IPsec and IKE) SAs associated with a given remote IKE peer IP or optional all SA:s in the system. IKE delete messages are sent.
Chapter 2: Command Reference
Usage
killsa <ip address> [-iface=<interface>]
Delete SAs belonging to provided remote SG/peer.
killsa -all [-iface=<interface>]
Delete all SAs.
Options
-all Kill all SAs.
-iface=<interface> Remote interface for SG/peer.
<ip address> IP address of remote SG/peer.
Note
Requires Administrator privilege.

2.2.44. languagefiles

Manage language files on disk.
Description
Manage language files on disk
Usage
55
Page 56
languagefiles
Show all language files on disk.
languagefiles -remove=<String>
Remove a language file from disk.
Options
-remove=<String> Specify language file to delete.

2.2.45. ldap

LDAP information.
Description
Chapter 2: Command Reference
Status and statistics for the configured LDAP databases.
Usage
ldap
List all LDAP databases.
ldap -list
List all LDAP databases.
ldap -show [<LDAP Server>]
Show LDAP database status and statistics.
ldap -reset [<LDAP Server>]
Reset LDAP database.
Options
-list List all LDAP databases.
-reset Reset status for LDAP database.
-show Show status and statistics.
<LDAP Server> LDAP database.

2.2.46. license

Show contents of the license file.
56
Page 57
Description
Show contents of the license file.
Usage
license -show [-remove]
Manages license.
Chapter 2: Command Reference
license -activate [-request] [-username=<String>]
Activates a license.
license
Show license's content.
license -remove
CLI.license.*U.LicenseUsage.
license -update
Initiate a license update.
Options
-activate Manages license activation. (Admin only)
-password=<String> Sets password to be used. (Admin only)
-remove Remove license file from the Security Gateway.
-request Send request to Clavister server to activate license.
[-password=<String>] [-show]
(Admin only)
(Admin only)
-show Show current status and credentials. (Admin only)
-update Initiate a license update.
-username=<String> Sets username to be used. (Admin only)

2.2.47. linkmon

Display link montitoring statistics.
Description
. If link monitor hosts have been configured, linkmon will monitor host reachability to detect link/NIC problems.
57
Page 58
Usage
linkmon

2.2.48. logout

Logout user.
Description
Logout current user.
Usage
logout
Chapter 2: Command Reference

2.2.49. memory

Show memory information.
Description
Show core memory consumption. Also show detailed memory use of some components and lists.
Usage
memory

2.2.50. natpool

Show current NAT Pools.
Description
Show current NAT Pools and in-depth information.
Usage
natpool [-verbose] [<pool name> [<IP4 Address>]] [-num=<Integer>]
58
Page 59
Options
-num=<Integer> Maximum number of items to list (default: 20).
-verbose Verbose (more information).
<IP4 Address> Translated IP.
<pool name> NAT Pool name.

2.2.51. nd

Show Neighbor Discovery entries for given interface.
Description
List the Neighbor Discovery cache entries of specified interfaces.
If no interface is given the Neighbor Discovery cache entries of all interfaces will be presented.
Chapter 2: Command Reference
The presented list can be filtered using the ip and hw options.
Usage
nd
Show all Neighbor Discovery entries.
nd -show [<Interface>] [-ip=<pattern>] [-hw=<pattern>] [-num=<n>]
Show Neighbor Discovery entries.
nd -hashinfo [<Interface>]
Show information on hash table health.
nd -flush [<Interface>]
Flush Neighbor Discovery cache of specified interface.
nd -query=<ip> <Interface>
Send Neighbor Solicitation for IP.
nd -del=<ip> <Interface>
Delete ND cache entry.
Options
-del=<ip> Delete ND cache entry <ip>.
-flush Flush Neighbor Discovery cache of all specified
interfaces.
59
Page 60
-hashinfo Show information on hash table health.
-hw=<pattern> Show only hardware addresses matching pattern.
-ip=<pattern> Show only IP addresses matching pattern.
-num=<n> Show only the first <n> entries per interface.
-query=<ip> Send Neighbor Solicitation for <ip>.
-show Show Neighbor Discovery entries for given
<Interface> Interface name.

2.2.52. ndsnoop

Toggle snooping and displaying of ARP requests.
Chapter 2: Command Reference
(Default: 20)
interface(s).
Description
Toggle snooping and displaying of Neighbor Discovery queries and responses on-screen.
The snooped messages are displayed before the access section validates the sender IP addresses in the ARP data.
Usage
ndsnoop
Show snooped interfaces.
ndsnoop {ALL | NONE | <interface>} [-verbose]
Snoop specified interface.
Options
-verbose Verbose.
{ALL | NONE | <interface>} Interface name.

2.2.53. netcon

List all NetCon users.
Description
Show a list of connected NetCon users.
60
Page 61
Usage
netcon

2.2.54. netobjects

Show runtime values of network objects.
Description
Displays named network objects and their contents.
Example 2.10. List network objects which have names containing "net".
netobjects *net*
Chapter 2: Command Reference
Usage
netobjects [<String>] [-num=<num>]
Options
-num=<num> Number of entries to show. (Default: 20)
<String> Name or pattern.

2.2.55. ospf

Show runtime OSPF information.
Description
Show runtime information about the OSPF router process(es).
Note: -process is only required if there are >1 OSPF router processes.
Usage
ospf
Show runtime information.
ospf -iface [<interface>] [-process=<OSPF Router Process>]
61
Page 62
Chapter 2: Command Reference
Show interface information.
ospf -area [<OSPF Area>] [-process=<OSPF Router Process>]
Show area information.
ospf -neighbor [<OSPF Neighbor>] [-process=<OSPF Router Process>]
Show neighbor information.
ospf -route [{HA | ALT}] [-process=<OSPF Router Process>]
Show the internal OSPF process routingtable.
ospf -database [-verbose] [-process=<OSPF Router Process>]
Show the LSA database.
ospf -lsa <lsaID> [-process=<OSPF Router Process>]
Show details for a specified LSA.
ospf -snoop={ON | OFF} [-process=<OSPF Router Process>]
Show troubleshooting messages on the console.
ospf -ifacedown <interface> [-process=<OSPF Router Process>]
Take specified interface offline.
ospf -ifaceup <interface> [-process=<OSPF Router Process>]
Take specified interface online.
ospf -execute={STOP | START | RESTART}
[-process=<OSPF Router Process>]
Start/stop/restart OSPF process.
Options
-area Show area information.
-database Show the LSA database.
-execute={STOP | START | RESTART} Start/stop/restart OSPF process. (Admin only)
-iface Show interface information.
-ifacedown Take specified interface offline. (Admin only)
-ifaceup Take specified interface online. (Admin only)
-lsa Show details for a specified LSA <lsaID>.
-neighbor Show neighbor information.
-process=<OSPF Router Process> Required if there are >1 OSPF router processes.
-route Show the internal OSPF process routingtable.
-snoop={ON | OFF} Show troubleshooting messages on the console.
62
Page 63
-verbose Increase amount of information to display.
<interface> OSPF enabled interface.
<interface> OSPF enabled interface.
<lsaID> LSA ID.
<OSPF Area> OSPF Area.
<OSPF Neighbor> Neighbor.
{HA | ALT} Show HA routingtable.

2.2.56. pcapdump

Packet capturing.
Description
Chapter 2: Command Reference
Packet capture engine
Usage
pcapdump
Show capture status.
pcapdump -start [<interface(s)>] [-size=<value>] [-snaplen=<value>]
Start capture.
pcapdump -stop [<interface(s)>]
Stop capture.
pcapdump -status
Show capture status.
[-count=<value>] [-out] [-out-nocap] [-eth=<Ethernet Address>] [-ethsrc=<Ethernet Address>] [-ethdest=<Ethernet Address>] [-ip=<IP4 Address>] [-ipsrc=<IP4 Address>] [-ipdest=<IP4 Address>] [-port=<0...65535>] [-srcport=<0...65535>] [-destport=<0...65535>] [-proto=<0...255>] [-icmp] [-tcp] [-udp] [-promisc] [-ipversion=<1...15>]
pcapdump -show [<interface(s)>]
Show a captured packets brief.
pcapdump -write [<interface(s)>] [-filename=<String>]
Write the captured packets to disk.
pcapdump -wipe
Remove all captured packets from memory.
63
Page 64
Chapter 2: Command Reference
pcapdump -cleanup
Remove all captured packets, release capture mode and delete all written capture files from disk.
Options
-cleanup Remove all captured packets, release capture
mode and delete all written capture files from disk.
-count=<value> Number of packets to capture.
-destport=<0...65535> Destination TCP/UDP port filter.
-eth=<Ethernet Address> Ethernet address filter.
-ethdest=<Ethernet Address> Ethernet destination address filter.
-ethsrc=<Ethernet Address> Ethernet source address filter.
-filename=<String> Filename for capture file.
-icmp ICMP filter.
-ip=<IP4 Address> IP address filter.
-ipdest=<IP4 Address> Destination IP address filter.
-ipsrc=<IP4 Address> Source IP address filter.
-ipversion=<1...15> IP version filter.
-out Realtime packet brief dumped to console.
-out-nocap Unbuffered (not stored in memory) realtime packet
brief dumped to console.
-port=<0...65535> TCP/UDP port filter.
-promisc Set iface in promiscuous mode.
-proto=<0...255> IP protocol filter.
-show Show a captured packets brief.
-size=<value> Size (kb) of buffer to store captured packets in
memory (default 512kb).
-snaplen=<value> Maximum length of each packet to capture.
-srcport=<0...65535> Source TCP/UDP port filter.
-start Start capture.
-status Show capture status.
-stop Stop capture.
-tcp TCP filter.
-udp UDP filter.
-wipe Remove all captured packets from memory.
64
Page 65
-write Write the captured packets to disk.
<interface(s)> Name of interface(s).

2.2.57. pciscan

Show detected PCI devices.
Description
Usage
Chapter 2: Command Reference
Note
Requires Administrator privilege.
pciscan
Show identified ethernet devices.
pciscan -all
Show all detected devices.
pciscan -ethernet
Show all detected ethernet devices.
pciscan -cfgupdate
Updates the config with detected devices.
pciscan -force_driver <Integer> {BROADCOM | BNE2 | E100 | E1000 |
Force a certain driver to a device.
Options
-all Show all detected devices.
-cfgupdate Updates the config with detected devices. (Admin
R8139 | R8169 | MARVELL | NITROXII | ST201 | TULIP | X3C905}
only)
-ethernet Show all detected ethernet devices.
-force_driver Force a certain device to a specific driver. (Admin
only)
<Integer> Index of device to update.
65
Page 66
ST201 | TULIP | X3C905} Interface driver to use.

2.2.58. pipes

Show pipes information.
Description
Show list of configured pipes / pipe details / pipe users.
Note: The "pipes" command is not executed right away; it is queued until the end of the second, when pipe values are calculated.
Usage
pipes
Chapter 2: Command Reference
List all pipes.
pipes -users [<Pipe>] [-expr=<String>]
List users of a given pipe.
pipes -show [<Pipe>] [-expr=<String>]
Show pipe details.
Options
-expr=<String> Pipe wildcard(*) expression.
-show Show pipe details.
-users List users of a given pipe.
<Pipe> Show pipe details.

2.2.59. pptpalg

Show PPTP ALG information.
Description
Shows information and statistics of the PPTP ALGs.
Usage
pptpalg
Show all configured PPTP ALGs.
66
Page 67
Chapter 2: Command Reference
pptpalg -sessions <PPTP ALG> [-verbose] [-num=<Integer>]
List all PPTP sessions.
pptpalg -services <PPTP ALG>
List all services attached to PPTP ALG.
Options
-num=<Integer> Number of entries to list.
-services List all services attached to PPTP ALG.
-sessions List all session using a PPTP tunnel.
-verbose Verbose output.
<PPTP ALG> PPTP ALG.

2.2.60. reconfigure

Initiates a configuration re-read.
Description
Restart the Security Gateway using the currently active configuration.
Usage
Note
Requires Administrator privilege.

2.2.61. rekeysa

Rekey IPsec or IKE SAs established with given remote peer.
Description
Rekey IPsec or IKE SAs associated with a given remote IKE peer, or optionally all IPsec or IKE SAs in the system.
Usage
rekeysa -ike <ip address>
Rekey IKE SAs.
67
Page 68
Chapter 2: Command Reference
rekeysa -ipsec <ip address>
Rekey IPsec SAs.
rekeysa <ip address>
Rekey IPsec SAs.
Options
-ike Rekey IKE SAs.
-ipsec Rekey IPsec SAs.
<ip address> IP address of remote peer.
Note
Requires Administrator privilege.

2.2.62. route

Alias for routes.

2.2.63. routemon

List the currently monitored interfaces and gateways.
Description
List the currently monitored interfaces and/or gateways.
Usage
routemon

2.2.64. routes

Display routing lists.
Description
Display information about the routing table(s):
- Contents of a (named) routing table.
- The list of routing tables, along with a total count of route entries in each table, as well as
how many of the entries are single-host routes.
68
Page 69
Chapter 2: Command Reference
Note that "core" routes for interface IP addresses are not normally shown. Use the -all switch to show core routes also.
Use the -switched switch to show only switched routes.
Explanation of Flags field of the routing tables:
O Learned via OSPF
X Route is Disabled
M Route is Monitored
A Published via Proxy ARP
D Dynamic (from e.g. DHCP relay, IPsec, L2TP/PPP servers, etc.)
H HA synced from cluster peer
Usage
routes [-all] [<table name>] [-switched] [-flushl3cache] [-num=<n>]
Options
-all Also show routes for interface addresses.
-flushl3cache Flush Layer 3 Cache.
-lookup=<ip address> Lookup the route for the given IP address.
-nonhost Do not show single-host routes.
-num=<n> Limit display to <n> entries. (Default: 20)
-switched Only show switched routes and L3C entries.
-tables Display list of named (PBR) routing tables.
-verbose Verbose.
<table name> Name of routing table.
[-nonhost] [-tables] [-lookup=<ip address>] [-verbose]

2.2.65. rtmonitor

Real-time monitor information.
Description
Show information about real-time monitor objects, and real-time monitor alerts.
All objects matching the specified filter are displayed. The filter can be the name of an object, or the beginning of a name. If no filter is specified, all objects are displayed.
69
Page 70
Chapter 2: Command Reference
If the option "monitored" is specified, only objects that have an associated real-time monitor alert are displayed.
Example 2.11. Show all monitored objects in the alg/http category
gw-world:/> rtmonitor alg/http -m
Usage
rtmonitor [<filter>] [-terse] [-monitored]
Options
-monitored Only show monitored objects.
-terse Only show object name.
<filter> Object filter.

2.2.66. rules

Show rules lists.
Description
Shows the content of the various types of rules, i.e. main ruleset, pipe ruleset, etc.
Example 2.12. Show a range of rules
rules -verbose 1-5 7-9
Usage
rules -type=IP [-ruleset={* | MAIN | <IP Rule Set>}] [-verbose]
[-schedule] [<rules>]...
Show IP rules.
rules -type={ROUTING | PIPE | IDP | THRESHOLD | IGMP} [-verbose]
Show a specific type of rules.
Options
[-schedule] [<rules>]...
70
Page 71
Chapter 2: Command Reference
-ruleset={* | MAIN | <IP Rule Set>} Show a specified IP ruleset.
-schedule Filter out rules that are not currently allowed by
selected schedules.
-type={IP | ROUTING | PIPE | IDP | THRESHOLD | IGMP}
-verbose Verbose: show all parameters of the rules.
<rules> Range of rules to display. (default: all rules).

2.2.67. selftest

Run appliance self tests.
Description
The appliance self tests are used to verify the correct function of hardware components.
IMPORTANT: In order for a selftest result to be reliable the test must be run using a default configuration and having the SGW disconnected from any networks.
IMPORTANT: Normal SGW operations might be disrupted during the test(s).
The outcome of the throughput crypto accelerator tests are dependent on configuration values. If the number of large buffers (LocalReassSettings->LocalReass_NumLarge) too low, it might lower throughput result. In the field 'Drop/Fail', the 'Drop' column contains the number of packets that were dropped before ever reaching the crypto accelerator and the 'Fail' column contains the number of packets that for some reason failed encryption. The 'Pkt In/Out' field shows the total number of packets sent to, and returned from the accelerator.
Type of rules to display. (Default: IP)
The interface tests 'traffic' and 'throughput' are dependent on the settings for the NIC ring sizes and possibly also license limitations. The 'traffic' test uses a uniform random distribution of six packet sizes between 60 and 1518 bytes. The content of each received packet is validated. The 'throughput' test uses only the largest packet size, and does not validate the contents of the received packets.
Example 2.13. Interface ping test between all interfaces
selftest -ping
Example 2.14. Interface ping test between interfaces 'if1' and 'if2'
selftest -ping -interfaces=if1,if2
Example 2.15. Start 30 min burn-in, testing RAM, storage media and crypto accelerator
selftest -burnin -minutes 30 -media -memory -cryptoaccel
71
Page 72
Usage
selftest -memory [-num=<Integer>]
Check the sanity of the RAM.
selftest -media [-size=<Integer>]
Check the sanity of the disk drive.
selftest -mac
Check if there are MAC address collisions on the interfaces.
selftest -ping [-interfaces=<Interface>]
Run a ping test over the interfaces.
selftest -throughput [-interfaces=<Interface>]
Run a throughput test over the interfaces.
Chapter 2: Command Reference
selftest -traffic [-interfaces=<Interface>]
Run a traffic test over the interfaces.
selftest -cryptoaccel
Verify the correct functioning of the accelerator cards.
selftest -burnin [-hours[=<Integer>]] [-minutes[=<Integer>]]
[-memory] [-media] [-ping] [-throughput] [-traffic] [-cryptoaccel]
Run burn-in tests for a set of sub tests. If no sub tests are specified the following are included:
-memory, -ping, -traffic, -cryptoaccel.
selftest -abort
Abort a running self test.
selftest
Show the status of a running test.
Options
-abort Abort a running self test.
-burnin Run burn-in tests for a selected set of sub tests.
-cryptoaccel Verify the correct functioning of available crypto
accelerator cards.
-hours[=<Integer>] Test duration in hours. (Default: 48)
-interfaces=<Interface> Ethernet interface(s).
-mac Check if there are MAC address collisions on the
interfaces.
72
Page 73
Chapter 2: Command Reference
-media Check the sanity of the disk drive.
-memory Check the sanity of the RAM.
-minutes[=<Integer>] Test duration in minutes. (Default: 0)
-num=<Integer> Number of times to execute the test. (Default: 1)
-ping Run a ping test over the interfaces.
-size=<Integer> Size of media space to utilize in the test. Set in MB.
(Default: 1)
-throughput Run a throughput test over the interfaces. This will
show the maximal achievable interface throughput.
-traffic Run a traffic test over the interfaces. The traffic test
uses mixed frame sizes and verifies the content of each received frame.

2.2.68. services

Show runtime values of configured services.
Description
Shows the runtime values of all configured services.
Example 2.16. List all services which names begin with "http"
services http*
Usage
services [<String>]
Note
Requires Administrator privilege.
Options
<String> Name or pattern.

2.2.69. sessionmanager

73
Page 74
Chapter 2: Command Reference
Session Manager.
Description
Show information about the Session Manager, and list currently active users.
Explanation of Timeout flags for sessions:
D Session is disabled
S Session uses a timeout in its subsystem
- Session does not use timeout
Usage
sessionmanager
Show Session Manager status.
sessionmanager -status
Show Session Manager status.
sessionmanager -list [-num=<n>]
List active sessions.
sessionmanager -info <session name> <database>
Show in-depth information about session(s).
sessionmanager -message <session name> <database> <message text>
Send message to session with console.
sessionmanager -disconnect <session name> <database> [<IP Address>
[{LOCAL | SSH | NETCON | HTTP | HTTPS}]]
Forcibly terminate session(s).
Options
-disconnect Forcibly terminate session(s). (Admin only)
-info Show in-depth information about session.
-list List active sessions.
-message Send message to session.
-num=<n> List <n> number of session.
-status Show Session Manager status.
<database> Name of user database.
<IP Address> IP address.
74
Page 75
<message text> Message to send.
<session name> Name of session.
{LOCAL | SSH | NETCON | HTTP | HTTPS} Session type.

2.2.70. settings

Show settings.
Description
Show the contents of the settings section, category by category.
Usage
settings
Chapter 2: Command Reference
Show list of categories.
settings <category>
Show settings in category.
Options
<category> Show settings in category.

2.2.71. shutdown

Initiate core or system shutdown.
Description
Initiate restart of the core/system.
Usage
shutdown [<seconds>] [-normal] [-reboot]
Options
-normal Initiate core shutdown.
-reboot Initiate system reboot.
<seconds> Seconds until shutdown. (Default: 5)
75
Page 76

2.2.72. sipalg

SIP ALG.
Description
List running SIP-ALG configurations, SIP registration and call information.
The -flags option with -snoop allows any combination of the following values:
- 0x00000001 GENERAL
- 0x00000002 ERRORS
- 0x00000004 OPTIONS
Chapter 2: Command Reference
Note
Requires Administrator privilege.
- 0x00000008 PARSE
- 0x00000010 VALIDATE
- 0x00000020 SDP
- 0x00000040 ALLOW_CHANGES
- 0x00000080 SUPPORTED_CHANGES
- 0x00000100 2543COMPLIANCE
- 0x00000200 RECEPTION
- 0x00000400 SESSION
- 0x00000800 REQUEST
- 0x00001000 RESPONSE
- 0x00002000 TOPO_CHANGES
- 0x00004000 MEDIA
- 0x00008000 CONTACT
- 0x00010000 CONN
- 0x00020000 PING
- 0x00040000 TRANSACTION
- 0x00080000 CALLLEG
- 0x00100000 REGISTRY
Flags can be added in the usual way. The default value is 0x00000003 (GENERAL and ERRORS).
76
Page 77
Chapter 2: Command Reference
NOTE: 'verbose' option outputs a lot of information on the console which may lead to system instability. Use with caution.
Usage
sipalg -definition <alg>
Show running ALG configuration parameters.
sipalg -registration[={SHOW | FLUSH}] <alg>
Show or flush current registration table.
sipalg -calls <alg>
Show active calls table.
sipalg -session <alg>
Show active SIP sessions.
sipalg -connection <alg>
Show SIP connections.
sipalg -statistics[={SHOW | FLUSH}] <alg>
Show or flush SIP counters.
sipalg -snoop={ON | OFF | VERBOSE} [<ipaddr>] [-flags=<String>]
Control SIP snooping. Useful for troubleshooting SIP transactions. NOTE: 'verbose' option outputs a lot of information on the console which may lead to system instability. Use with caution.
Options
-calls Show active calls table.
-connection Show SIP connections.
-definition Show running ALG configuration parameters.
-flags=<String> SIP snooping for certain levels. Expected number in
hexadecimal notation.
-registration[={SHOW | FLUSH}] Show or flush registration table. (Default: show)
-session Show active SIP sessions.
-snoop={ON | OFF | VERBOSE} Enable or disable SIP snooping. NOTE: 'verbose'
option outputs a lot of information on the console which may lead to system instability. Use with caution.
-statistics[={SHOW | FLUSH}] Show or flush SIP counters. (Default: show)
<alg> SIP-ALG name.
77
Page 78
<ipaddr> IP Address to snoop.

2.2.73. sshserver

SSH Server.
Description
Show SSH Server status, or start/stop/restart SSH Server.
Usage
sshserver
Show server status and list all connected clients.
sshserver -status [-verbose]
Chapter 2: Command Reference
Show server status and list all connected clients.
sshserver -keygen [-b=<bits>] [-t={RSA | DSA}]
Generate SSH Server private keys.
sshserver -restart <ssh server>
Restart SSH Server.
Options
-b=<bits> Bitsize. (Default: 1024)
-keygen Generate SSH Server private keys. This operation
may take a long time to finish, up to several minutes!
-restart Stop and start the SSH Server.
-status Show server status and list all connected clients.
-t={RSA | DSA} Type, (default: both RSA and DSA keys will be
created).
-verbose Verbose output.
<ssh server> SSH Server.

2.2.74. sslvpn

Note
Requires Administrator privilege.
78
Page 79
SSLVPN tunnels.
Description
List running SSLVPN configurations, SSLVPN active tunnels and call information.
Usage
sslvpn [-num=<n>]
Options
-num=<n> Limit display to <n> entries. (Default: 20)

2.2.75. stats

Chapter 2: Command Reference
Display various general firewall statistics.
Description
Display general information about the firewall, such as uptime, CPU load, resource consumption and other performance data.
Usage
stats

2.2.76. sysmsgs

System messages.
Description
Show contents of the FWLoader sysmsg buffer.
Usage
sysmsgs

2.2.77. techsupport

Technical Support information.
79
Page 80
Description
Generate information useful for technical support.
Due to the large amount of output, this command might show a truncated result when execute from the local console.
Usage
techsupport

2.2.78. time

Display current system time.
Description
Chapter 2: Command Reference
Display/set the system date and time.
Usage
time
Display current system time.
time -set <date> <time>
Set system local time: <YYYY-MM-DD> <HH:MM:SS>.
time -sync [-force]
Synchronize time with timeserver(s) (specified in settings).
Options
-force Force synchronization regardless of the MaxAdjust
setting.
-set Set system local time: <YYYY-MM-DD>
<HH:MM:SS>.
-sync Synchronize time with timeserver(s) (specified in
<date> Date YYYY-MM-DD.
<time> Time HH:MM:SS.

2.2.79. uarules

settings).
80
Page 81
Show user authentication rules.
Description
Displays the contents of the user authentication ruleset.
Example 2.17. Show a range of rules
uarules -v 1-2,4-5
Usage
uarules [-verbose] [<Integer Range>]
Options
Chapter 2: Command Reference
-verbose Verbose output.
<Integer Range> Range of rules to list.

2.2.80. updatecenter

Show status and manage autoupdate information.
Description
Show autoupdate mechanism status or force an update.
Usage
updatecenter
Show update status and database information.
updatecenter -status[={ANTIVIRUS | IDP | ALL}] [-verbose]
Show update status and database information.
updatecenter -update[={ANTIVIRUS | IDP | ALL}]
Initiate an update check of the specified database.
updatecenter -removedb={ANTIVIRUS | IDP}
Remove the specified signature database.
updatecenter -servers
81
Page 82
Show status of update servers.
Options
-removedb={ANTIVIRUS | IDP} Remove the database for the specified service.
-servers Show autoupdate server information.
-status[={ANTIVIRUS | IDP | ALL}] Show update status and service information.
-update[={ANTIVIRUS | IDP | ALL}] Force an update now for the specified service.
-verbose Show verbose status information. (Admin only)

2.2.81. userauth

Show logged-on users.
Chapter 2: Command Reference
(Admin only; Default: all)
(Admin only; Default: all)
Description
Show currently logged-on users and other information. Also allows logged-on users to be forcibly logged out.
Note: In the user listing -list, only privileges actually used by the policy are displayed.
Usage
userauth
List all authenticated users.
userauth -list [-num=<n>]
List all authenticated users.
userauth -privilege
List all known privileges (usernames and groups).
userauth -user <user ip>
Show all information for user(s) with this IP address.
userauth -remove <user ip> <Interface>
Forcibly log out an authenticated user.
Options
-list List all authenticated users.
-num=<n> Limit list of authenticated users. (Default: 20)
-privilege List all known privileges (usernames and groups).
82
Page 83
-remove Forcibly log out an authenticated user. (Admin
-user Show all information for user(s) with this IP
<Interface> Interface.
<user ip> IP address for user(s).

2.2.82. vlan

Show information about VLAN.
Description
Show list of attached Virtual LAN Interfaces, or in-depth information about a specified VLAN.
Chapter 2: Command Reference
only)
address.
Usage
vlan
List attached VLANs.
vlan -num=<n> [-page[=<n>]]
Set number of display lines per page and display page.
vlan <Interface>
Display VLANs connected to physical iface <iface>.
Options
-num=<n> Limit display lines to <n> entries in page. (Default:
20)
-page[=<n>] Set page <n> for lines to display. (Default: 1)
<Interface> Display VLAN information about this interface.

2.2.83. vpnstats

Alias for ipsecstats.
83
Page 84

2.3. Utility

2.3.1. ping

Ping host.
Description
Sends one or more ICMP ECHO, TCP SYN or UDP datagrams to the specified IP address of a host. All datagrams are sent preloaded-style (all at once).
The data size -length given is the ICMP or UDP data size. 1472 bytes of ICMP data results in a 1500-byte IP datagram (1514 bytes ethernet).
Usage
ping <host> [-srcif=<interface>] [-srcip=<ip address>]
Chapter 2: Command Reference
[-pbr=<table>] [-count=<1...10>] [-length=<2...8192>] [-port=<0...65535>] [-udp] [-tcp] [-tos=<0...255>] [-verbose]
Options
-count=<1...10> Number of packets to send. (Default: 1)
-length=<2...8192> Packet size. (Default: 4)
-pbr=<table> Route using PBR Table.
-port=<0...65535> Destination port of UDP or TCP ping.
-srcif=<interface> Pass packet through the rule set, simulating that
the packet was received by <srcif>.
-srcip=<ip address> Use this source IP.
-tcp Send TCP ping.
-tos=<0...255> Type of service.
-udp Send UDP ping.
-verbose Verbose (more information).
<host> IP address of host to ping.
84
Page 85

2.4. Misc

2.4.1. echo

Print text.
Description
Print text to the console.
Example 2.18. Hello World
echo Hello World
Usage
Chapter 2: Command Reference
echo [<String>]...
Options
<String> Text to print.

2.4.2. help

Show help for selected topic.
Description
The help system contains information about commands and configuration object types.
The fastest way to get help is to simply type help followed by the topic that you want help with. A topic can be for example a command name (e.g. set) or the name of a configuration object type (e.g. User).
When you don't know the name of what you are looking for you can specify the category of the wanted topic with the -category option and use tab-completion to display a list of matching topics.
Usage
help
List commands alphabetically.
help <Topic>
85
Page 86
Display help about selected topic from any category.
help -category={COMMANDS | TYPES} [<Topic>]
Display help from a specific topic category.
Options
-category={COMMANDS | TYPES} Topic category.
<Topic> Help topic.

2.4.3. history

Dump history to screen.
Description
List recently typed commands that have been stored in the command history.
Chapter 2: Command Reference

2.4.4. ls

Usage
history
Lists device data accessible by SCP.
Description
Lists device data which are available through SCP.
Example 2.19. Transfer script files to and from the device
Upload: scp myscript user@sgw-ip:script/myscript Download: scp user@sgw-ip:script/myscript ./myscript
In addition to the files listed it is possible to upload license, certificates and ssh public key files.
Example 2.20. Upload license data
scp licence.lic user@sgw-ip:license.lic
Certificates and ssh client key objects are created if they do not exist.
86
Page 87
Chapter 2: Command Reference
Example 2.21. Upload certificate data
scp certificate.cer user@sgw-ip:certificate/certificate_name scp certificate.key user@sgw-ip:certificate/certificate_name
Example 2.22. Upload ssh public key data
scp sshkey.pub user@sgw-ip:sshclientkey/sshclientkey_name
Usage
Options
-long Enable long listing format.
<File> File to list.

2.4.5. script

Handle CLI scripts.
Description
Run, create, show, store of delete script files.
Script files are transfered to and from the device by the SCP protocol. On the device they are stored in the "/script" folder.
Example 2.23. Execute script
"script.sgs": add IP4Address Name=$1 Address=$2 Comment="$0: \$100". :/> script -execute -name=script.sgs ip_test 127.0.0.1 is executed as line: add IP4Address Name=ip_test Address=127.0.0.1 Comment="script.sgs: $100"
Usage
script -create [[<Category>] <Type> [<Identifier>]] [-name=<Name>]
Create configuration script from specified object, class or category.
script -execute [-verbose] [-force] [-quiet] -name=<Name>
[<Parameters>]...
87
Page 88
Chapter 2: Command Reference
Execute script.
script -show [-all] [-name=<Name>]
Show script in console window.
script -store [-all] [-name=<Name>]
Store a script to persistent storage.
script -remove [-all] [-name=<Name>]
Remove script.
script
List script files.
Options
-all Apply to all scripts.
-create Create configuration script from specified object,
class or category.
-execute Execute script.
-force Force script execution.
-name=<Name> Name of script.
-quiet Quiet script execution.
-remove Remove script.
-show Show script in console window.
-store Store a script to persistent storage.
-verbose Verbose mode.
<Category> Category that groups object types.
<Identifier> The property that identifies the configuration
object. May not be applicable depending on the specified <Type>.
<Parameters> List of input arguments.
<Type> Type of configuration object to perform operation
on.
Note
Requires Administrator privilege.
88
Page 89
Chapter 2: Command Reference
89
Page 90

Chapter 3: Configuration Reference

• Access, page 94
• Address, page 95
• AdvancedScheduleProfile, page 99
• ALG, page 100
• AntiVirusPolicy, page 109
• ApplicationRuleSet, page 110
• ARPND, page 111
• ARPNDSettings, page 112
• AuthAgent, page 115
• AuthenticationSettings, page 116
• BlacklistWhiteHost, page 117
• BNE2EthernetPCIDriver, page 118
• BroadcomEthernetPCIDriver, page 119
• Certificate, page 120
• COMPortDevice, page 121
• ConfigModePool, page 122
• ConnTimeoutSettings, page 123
• DateTime, page 124
• DefaultInterface, page 125
• Device, page 126
• DHCPRelay, page 127
• DHCPRelaySettings, page 129
• DHCPServer, page 130
90
Page 91
• DHCPServerSettings, page 133
• DHCPv6Server, page 134
• DHCPv6ServerSettings, page 136
• DNS, page 137
• DynamicRoutingRule, page 138
• DynDnsClientCjbNet, page 141
• DynDnsClientDyndnsOrg, page 142
• DynDnsClientDynsCx, page 143
• DynDnsClientPeanutHull, page 144
• E1000EthernetPCIDriver, page 145
• E100EthernetPCIDriver, page 146
• Ethernet, page 147
Chapter 3: Configuration Reference
• EthernetDevice, page 149
• EthernetSettings, page 150
• EventReceiverSNMP2c, page 152
• FileControlPolicy, page 153
• FragSettings, page 154
• GRETunnel, page 156
• HighAvailability, page 157
• HTTPALGBanners, page 158
• HTTPAuthBanners, page 159
• HTTPPoster, page 160
• HWM, page 161
• HWMSettings, page 162
• ICMPSettings, page 163
• IDList, page 164
• IDPRule, page 165
• IGMPRule, page 167
• IGMPSetting, page 169
• IKEAlgorithms, page 170
• InterfaceGroup, page 171
• IPPolicy, page 172
91
Page 92
• IPPool, page 175
• IPRule, page 176
• IPRuleFolder, page 179
• IPRuleSet, page 180
• IPsecAlgorithms, page 181
• IPsecTunnel, page 183
• IPsecTunnelSettings, page 186
• IPSettings, page 188
• ixgbeEthernetPCIDriver, page 191
• IXP4NPEEthernetDriver, page 192
• L2TPClient, page 193
• L2TPServer, page 195
Chapter 3: Configuration Reference
• L2TPServerSettings, page 197
• L2TPv3Server, page 198
• LDAPDatabase, page 199
• LDAPServer, page 200
• LengthLimSettings, page 201
• LinkAggregation, page 202
• LinkMonitor, page 204
• LocalReassSettings, page 205
• LocalUserDatabase, page 206
• LogReceiverFWLog, page 207
• LogReceiverMemory, page 208
• LogReceiverSMTP, page 209
• LogReceiverSyslog, page 210
• LogSettings, page 211
• LoopbackInterface, page 212
• MarvellEthernetPCIDriver, page 213
• MiscSettings, page 214
• MulticastSettings, page 216
• NATPool, page 217
• OSPFProcess, page 218
92
Page 93
• Pipe, page 223
• PipeRule, page 226
• PPPoETunnel, page 227
• PPPSettings, page 229
• PSK, page 230
• R8139EthernetPCIDriver, page 231
• R8169EthernetPCIDriver, page 232
• RadiusAccounting, page 233
• RadiusRelay, page 234
• RadiusServer, page 236
• RealTimeMonitorAlert, page 237
• RemoteIDList, page 238
Chapter 3: Configuration Reference
• RemoteMgmtHTTP, page 239
• RemoteMgmtNetcon, page 240
• RemoteMgmtSettings, page 241
• RemoteMgmtSNMP, page 243
• RemoteMgmtSSH, page 244
• RouteBalancingInstance, page 246
• RouteBalancingSpilloverSettings, page 247
• RouterAdvertisement, page 248
• RoutingRule, page 250
• RoutingSettings, page 251
• RoutingTable, page 253
• ScheduleProfile, page 257
• ServiceGroup, page 258
• ServiceICMP, page 259
• ServiceICMPv6, page 261
• ServiceIPProto, page 263
• ServiceTCPUDP, page 264
• SSHClientKey, page 265
• SSLSettings, page 266
• SSLVPNInterface, page 267
93
Page 94
• SSLVPNInterfaceSettings, page 268
• ST201EthernetPCIDriver, page 269
• StateSettings, page 270
• TCPSettings, page 271
• ThresholdRule, page 273
• TulipEthernetPCIDriver, page 275
• UpdateCenter, page 276
• URLFilterPolicy, page 277
• UserAuthRule, page 278
• VLAN, page 281
• VLANSettings, page 283
• WebContentFilteringPolicy, page 284
Chapter 3: Configuration Reference
• X3C905EthernetPCIDriver, page 285

3.1. Access

Description
Use an access rule to allow or block specific source IP addresses on a specific interface.
Properties
Index The index of the object, starting at 1. (Identifier)
Name Specifies a symbolic name for the object.
Action Accept, Expect or Drop. (Default: Drop)
Interface The interface the packet must arrive on for this rule
Network The IP span that the sender must belong to for this
LogEnabled Enable logging. (Default: Yes)
to be carried out. Exception: the Expect rule.
rule to be carried out.
LogSeverity Specifies with what severity log events will be sent
to the specified log receivers. (Default: Default)
Comments Text describing the current object. (Optional)
Note
If no Index is specified when creating an instance of this type, the object will be placed last in the list and the Index will be equal to the length of the list.
94
Page 95

3.2. Address

This is a category that groups the following object types.

3.2.1. AddressFolder

Description
An address folder can be used to group related address objects for better overview.
Properties
Name Specifies a symbolic name for the network object.
Comments Text describing the current object. (Optional)
3.2.1.1. IP6Address
Chapter 3: Configuration Reference
(Identifier)
Description
Use an IP6 Address item to define a name for a specific IP6 host, network or range.
Properties
Name Specifies a symbolic name for the network object.
Address IPv6 address, e.g. "2001:DB8::/32".
ActiveAddress The dynamically set address used by e.g. DHCPv6
Comments Text describing the current object. (Optional)
3.2.1.2. IP6Group
Description
An IP6 Address Group is used for combining several IP6 Address objects for simplified management.
Properties
(Identifier)
enabled Ethernet interfaces. (Optional)
Name Specifies a symbolic name for the network object.
(Identifier)
Members Group members.
Comments Text describing the current object. (Optional)
95
Page 96
3.2.1.3. EthernetAddress
Description
Use an Ethernet Address item to define a symbolic name for an Ethernet MAC address.
Properties
Name Specifies a symbolic name for the network object.
Address Ethernet MAC address, e.g. "12-34-56-78-ab-cd".
Comments Text describing the current object. (Optional)
3.2.1.4. EthernetAddressGroup
Description
Chapter 3: Configuration Reference
(Identifier)
An Ethernet Address Group is used for combining several Ethernet Address objects for simplified management.
Properties
Name Specifies a symbolic name for the network object.
Members Group members.
Comments Text describing the current object. (Optional)
3.2.1.5. IP4HAAddress
Description
Use an IP4 HA Address item to define a name for a specific IP4 host, network or range for each node in a high availability cluster.
Properties
Name Specifies a symbolic name for the network object.
(Identifier)
(Identifier)
Address An IP address with one instance for each node in
the high availability cluster.
UserAuthGroups Groups and user names that belong to this object.
Objects that filter on credentials can only be used as source networks and destinations networks in rules. (Optional)
NoDefinedCredentials If this property is enabled the object requires user
96
Page 97
Comments Text describing the current object. (Optional)
3.2.1.6. IP4Group
Description
An IP4 Address Group is used for combining several IP4 Address objects for simplified management.
Properties
Name Specifies a symbolic name for the network object.
Chapter 3: Configuration Reference
authentication, but has no credentials (user names or groups) defined. This means that the object only requires that a user is authenticated, but ignores any kind of group membership. (Default: No)
(Identifier)
Members Group members.
UserAuthGroups Groups and user names that belong to this object.
NoDefinedCredentials If this property is enabled the object requires user
Comments Text describing the current object. (Optional)
3.2.1.7. IP4Address
Description
Use an IP4 Address item to define a name for a specific IP4 host, network or range.
Properties
Name Specifies a symbolic name for the network object.
Objects that filter on credentials can only be used as source networks and destinations networks in rules. (Optional)
authentication, but has no credentials (user names or groups) defined. This means that the object only requires that a user is authenticated, but ignores any kind of group membership. (Default: No)
(Identifier)
Address IP address, e.g. "172.16.50.8", "192.168.7.0/24" or
"172.16.25.10-172.16.25.50".
ActiveAddress The dynamically set address used by e.g. DHCP
enabled Ethernet interfaces. (Optional)
UserAuthGroups Groups and user names that belong to this object.
Objects that filter on credentials can only be used as source networks and destinations networks in rules. (Optional)
97
Page 98
NoDefinedCredentials If this property is enabled the object requires user
Comments Text describing the current object. (Optional)

3.2.2. EthernetAddress

The definitions here are the same as in Section 3.2.1.3, “EthernetAddress” .

3.2.3. EthernetAddressGroup

The definitions here are the same as in Section 3.2.1.4, “EthernetAddressGroup” .

3.2.4. IP4Address

The definitions here are the same as in Section 3.2.1.7, “IP4Address” .
Chapter 3: Configuration Reference
authentication, but has no credentials (user names or groups) defined. This means that the object only requires that a user is authenticated, but ignores any kind of group membership. (Default: No)

3.2.5. IP4Group

The definitions here are the same as in Section 3.2.1.6, “IP4Group” .

3.2.6. IP4HAAddress

The definitions here are the same as in Section 3.2.1.5, “IP4HAAddress” .

3.2.7. IP6Address

The definitions here are the same as in Section 3.2.1.1, “IP6Address” .

3.2.8. IP6Group

The definitions here are the same as in Section 3.2.1.2, “IP6Group” .
98
Page 99

3.3. AdvancedScheduleProfile

Description
An advanced schedule profile contains definitions of occurrences used by various policies in the system.
Properties
Name Specifies a symbolic name for the service.
(Identifier)
Comments Text describing the current object. (Optional)

3.3.1. AdvancedScheduleOccurrence

Description
Chapter 3: Configuration Reference
An advanced schedule occurrence specifies an occurrence that should happen between certain times for days in month/week
Properties
StartTime Start Time of occurence in the format HH:MM. For
example 13:30.
EndTime End Time of occurence in the format HH:MM. For
example 14:15.
Occurrence Specify type of occurrence. (Default: Weekly)
Weekly Specifies days in week the schedule occurrence
should be activated. Monday corresponds to 1 and Sunday 7. (Default: 1-7)
Monthly Specifies days in month the schedule occurrence
should be activated. The schedule only occurs at days that exists in the month. (Default: 1-31)
Comments Text describing the current object. (Optional)
Note
If no Index is specified when creating an instance of this type, the object will be placed last in the list and the Index will be equal to the length of the list.
99
Page 100

3.4. ALG

This is a category that groups the following object types.

3.4.1. ALG_FTP

Description
Use an FTP Application Layer Gateway to manage FTP traffic through the system.
Properties
Name Specifies a symbolic name for the ALG. (Identifier)
AllowServerPassive Allow server to use passive mode (unsafe for
ServerPorts Server data ports. (Default: 1024-65535)
Chapter 3: Configuration Reference
server). (Default: No)
AllowClientActive Allow client to use active mode (unsafe for client).
(Default: No)
ClientPorts Client data ports. (Default: 1024-65535)
AllowUnknownCommands Allow unknown commands. (Default: No)
AllowSITEEXEC Allow SITE EXEC. (Default: No)
MaxLineLength Maximum line length in control channel. (Default:
256)
MaxCommandRate Maximum number of commands per second.
(Default: 20)
Allow8BitStrings Allow 8-bit strings in control channel. (Default: Yes)
AllowResumeTransfer Allow RESUME even in case of content scanning.
(Default: No)
Antivirus Disabled, Audit or Protect. (Default: Disabled)
ScanExclude List of files to exclude from antivirus scanning.
(Optional)
CompressionRatio A compression ratio higher than this value will
trigger the action in Compression Ratio Action, a value of zero will disable all compression checks. (Default: 20)
CompressionRatioAction The action to take when high compression
threshold is violated, all actions are logged. (Default: Drop)
AllowEncryptedZip Allow encrypted zip files, even though the
contents can not be scanned. (Default: No)
ZDEnabled Enable ZoneDefense Block. (Default: No)
ZDNetwork Hosts within this network will be blocked at
100
Loading...