This publication, including all photographs, illustrations and software, is protected under
international copyright laws, with all rights reserved. Neither this manual, nor any of the material
contained herein, may be reproduced without the written consent of Clavister.
Disclaimer
The information in this document is subject to change without notice. Clavister makes no
representations or warranties with respect to the contents hereof and specifically disclaims any
implied warranties of merchantability or fitness for a particular purpose. Clavister reserves the
right to revise this publication and to make changes from time to time in the content hereof
without any obligation to notify any person or parties of such revision or changes.
Limitations of Liability
UNDER NO CIRCUMSTANCES SHALL CLAVISTER OR ITS SUPPLIERS BE LIABLE FOR DAMAGES OF
ANY CHARACTER (E.G. DAMAGES FOR LOSS OF PROFIT, SOFTWARE RESTORATION, WORK
STOPPAGE, LOSS OF SAVED DATA OR ANY OTHER COMMERCIAL DAMAGES OR LOSSES)
RESULTING FROM THE APPLICATION OR IMPROPER USE OF THE CLAVISTER PRODUCT OR
FAILURE OF THE PRODUCT, EVEN IF CLAVISTER IS INFORMED OF THE POSSIBILITY OF SUCH
DAMAGES. FURTHERMORE, CLAVISTER WILL NOT BE LIABLE FOR THIRD-PARTY CLAIMS AGAINST
CUSTOMER FOR LOSSES OR DAMAGES. CLAVISTER WILL IN NO EVENT BE LIABLE FOR ANY
DAMAGES IN EXCESS OF THE AMOUNT CLAVISTER RECEIVED FROM THE END-USER FOR THE
PRODUCT.
•Administrators that are responsible for configuring and managing the Clavister Security
Gateway.
•Administrators that are responsible for troubleshooting the Clavister Security Gateway.
This guide assumes that the reader is familiar with the Clavister Security Gateway, and has the
necessary basic knowledge in network security.
Notation
The following notation is used throughout this reference guide when specifying the options of a
command:
Angle brackets <name> or
-option=<description>
Square brackets [option] or
-option[=value]
Curly brackets {value1 | value2 |
value3}
Ellipsis ...Used for specifying that more than one value can be
Example 1. Command option notation
One of the usages for the help command looks like this:
help -category={COMMANDS | TYPES} [<Topic>]
This means that help has an option called category which has two possible values which are
COMMANDS and TYPES. There is also an optional option called Topic which in this case is a
search string used to specify what help topic to display. Since the topic is optional, it is possible
to exclude it when running the command.
Both of the following examples are valid for the usage described above:
Used for specifying the name of an option or a description
of a value.
Used for specifying that an option or a value for an option is
optional and can be omitted.
Used for specifying the available values for an option.
specified for the option.
Device:/> help -category=COMMANDS
Device:/> help -category=COMMANDS activate
Because the table name option is followed by ellipses it is possible to specify more than one
routing table. Since table name is optional as well, the user can specify zero or more
policy-based routing tables.
Device:/> routes Virroute Virroute2
10
Page 11
Chapter 1: Introduction
• Running a command, page 11
• Help, page 12
• Function keys, page 13
• Command line history, page 14
• Tab completion, page 15
• User roles, page 18
This guide is a reference for all commands and configuration object types that are available in
the command line interface for Clavister cOS Core.
1.1. Running a command
The commands described in this guide can be run by typing the command name and then
pressing the return key. Many commands require options to be set to run. If a required option is
missing a brief syntax help will be displayed.
11
Page 12
1.2. Help
1.2.1. Help for commands
There are two ways of getting help about a command. A brief help is displayed if the command
name is typed followed by -? or -h. This applies to all commands and is therefore not listed in
the option list for each command in this guide. Using the help command gives a more detailed
help corresponding to the information found in this guide. In most cases it is possible to simply
type help followed by the command name to get the full help. See Section 2.4.2, “help” for a
more detailed description. To list the available commands, just type help and press return.
Example 1.1. Help for commands
Brief help for the activate command:
Device:/> activate -?
Device:/> activate -h
Full help for activate:
Chapter 1: Introduction
Device:/> help activate
Help for the arp command. Arp is also the name of a configuration object type, so it is necessary
to specify that the help text for the command should be displayed:
Device:/> help -category=COMMANDS arp
List all available commands:
Device:/> help
1.2.2. Help for object types
To get help about configuration object types, use the help command. It is also possible to get
information about each property in an object type, such as data type, default value, etc. by
entering the ? character when entering the value of a property and pressing tab. More on this in
Section 1.5.1, “Inline help”.
Example 1.2. Help for object types
Full help for IP4Address:
Device:/> help IP4Address
Help for the ARP configuration object type, which collides with the arp command:
Device:/> help -category=TYPES ARP
12
Page 13
1.3. Function keys
In addition to the return key there are a number of function keys that are used in the CLI.
BackspaceDelete the character to the left of the cursor.
TabComplete current word.
Ctrl-A or HomeMove the cursor to the beginning of the line.
Ctrl-B or Left ArrowMove the cursor one character to the left.
Ctrl-CClear line or cancel page view if more than one page of
Ctrl-D or DeleteDelete the character to the right of the cursor.
Ctrl-E or EndMove the cursor to the end of the line.
Ctrl-F or Right ArrowMove the cursor one character to the right.
Ctrl-KDelete from the cursor to the end of the line.
Chapter 1: Introduction
information is shown.
Ctrl-N or Down ArrowShow the next entry in the command history.
Ctrl-P or Up ArrowShow the previous entry in the command history.
Ctrl-TTranspose the current and the previous character.
Ctrl-UDelete from the cursor to the beginning of line.
Ctrl-WDelete word backwards.
13
Page 14
1.4. Command line history
Every time a command is run, the command line is added to a history list. The up and down
arrow keys are used to access previous command lines (up arrow for older command lines and
down arrow to move back to a newer command line). See also Section 2.4.3, “history”.
Example 1.3. Command line history
Using the command line history via the arrow keys:
Device:/> show Address
Device:/> (up arrow)
Device:/> show Address (the previous commandline is displayed)
Chapter 1: Introduction
14
Page 15
1.5. Tab completion
By using the tab function key in the CLI the names of commands, options, objects and object
properties can be automatically completed. If the text entered before pressing tab only matches
one possible item, e.g. "activate" is the only match for "acti", and a command is expected, the
name will be autocompleted. Should there be more than one match the part common to all
matches will be completed. At this point the user can either enter more characters or press tab
again, which will display a list of the possible completions. This can also be done without
entering any characters, but the resulting list might be long if there are many possible
completions, e.g. all commands.
Example 1.4. Tab completion
An example of tab completion when using the add command:
Device:/> add Add (tab)
Device:/> add Address ("ress" was autocompleted)
Device:/> add Address i (tab)
Device:/> add Address IP4 ("IP4" was autocompleted)
Device:/> add Address IP4
(tab, or double tab if IP4 were entered manually)
A list of all types starting with IP4 is listed.
Device:/> add Address IP4a (tab)
Device:/> add Address IP4Address ("Address" was autocompleted)
Device:/> add Address IP4Address example_ip a (tab)
Device:/> add Address IP4Address example_ip Address=
("Address=" was autocompleted)
Device:/> add Address IP4Address example_ip Address=1.2.3.4
Chapter 1: Introduction
Tab completion of references:
Device:/> set Address IP4Group examplegroup Members= (tab, tab)
A list of valid objects is displayed.
Device:/> set Address IP4Group examplegroup Members=e (tab)
Device:/> set Address IP4Group examplegroup Members=example_ip
("example_ip" was autocompleted)
1.5.1. Inline help
It is possible to get help about available properties of configuration objects while a command
line is being typed by using the ? character. Write ? instead of a property name and press tab
and a help text for the available properties is shown. If ? is typed in stead of a property value and
tab is pressed a help text for that property which contains more information such as data type,
default value, etc. is displayed.
Example 1.5. Inline help
Get inline help for all properties of an IP4Address:
Device:/> set IP4Address example_ip ? (tab)
A help text describing all available properties is displayed.
Getting inline help for the Address property:
Device:/> set IP4Address example_ip Address=? (tab)
15
Page 16
A more detailed help text about Address is displayed.
1.5.2. Autocompleting Current and Default value
Another special character that can be used together with tab completion is the period "."
character. If "." is entered instead of a property value and tab is pressed it will be replaced by the
current value of that property. This is useful when editing an existing list of items or a long text
value.
The "<" character before a tab can be used to automatically fill in the default value for a
parameter if no value has yet been set. If the "." character is used, all possible values will be
shown and these can then be edited with the back arrrow and backspace keys.
Example 1.6. Edit an existing property value
Edit the current value:
Device:/> add IP4Address example_ip Address=1.2.3.4
Device:/> set IP4Address example_ip Address=. (tab)
Device:/> set IP4Address example_ip Address=1.2.3.4
(the value was inserted)
The value can now be edited by using the arrow keys or backspace.
Chapter 1: Introduction
Device:/> set IP4Group examplegroup Members=ip1,ip2,ip3,ip5
Device:/> set IP4Group examplegroup Members=. (tab)
Device:/> set IP4Group examplegroup Members=ip1,ip2,ip3,ip5
(the value was inserted)
It is now possible to add or remove a member to the list without
having to enter all the other members again.
Edit the default value:
Device:/> add LogReceiverSyslog example Address=example_ip
Device:/> add LogReceiverSyslog example Address=example_ip
Some object types are grouped together in a category in the CLI. This only matters when using
tab completion as they are used to limit the number of possible completions when tab
completing object types. The category can always be omitted when running commands if the
type name is entered manually.
Example 1.7. Using categories with tab completion
Accessing an IP4Address object with the use of categories:
Device:/> show ad (tab)
Device:/> show Adress (the category is autocompleted)
Device:/> show Adress ip4a (tab)
Device:/> show Adress IP4Address (the type is autocompleted)
Device:/> show Adress IP4Address example_ip
16
Page 17
Accessing an IP4Address object without the use of categories:
Device:/> show IP4Address example_ip
Chapter 1: Introduction
17
Page 18
1.6. User roles
Some commands and options cannot be used unless the logged-in user has administrator
privileges. This is indicated in this guide by a note following the command or Admin only
written next to an option.
Chapter 1: Introduction
18
Page 19
Chapter 1: Introduction
19
Page 20
Chapter 2: Command Reference
• Configuration, page 20
• Runtime, page 31
• Utility, page 84
• Misc, page 85
2.1. Configuration
2.1.1. activate
Activate changes.
Description
Activate the latest changes.
This will issue a reconfiguration, using the new configuration. If the reconfiguration is successful
a commit command must be issued within the configured timeout interval in order to save the
changes to media. If not, the system will revert to using the previous version of the configuration.
Usage
activate
2.1.2. add
Create a new object.
Note
Requires Administrator privilege.
20
Page 21
Chapter 2: Command Reference
Description
Create a new object and add it to the configuration.
Specify the type of object you want to create and the identifier, if the type has one, unless the
object is identified by an index. Set the properties of the object by writing the propertyname
equals (=) and then the value. An optional category can be specified for some object types when
using tab completion.
If a mandatory property isn't specified a list of errors will be shown after the object is created. If
an invalid property or value type is specified or if the identifier is missing the command will fail
and not create an object.
Adjustments can be made after the object is created by using the set command.
Example 2.1. Create a new object
Add objects with an identifier property (not index):
gw-world:/> add Address IP4Address example_ip Address=1.2.3.4
Comments="This is an example"
gw-world:/> add IP4Address example_ip2 Address=2.3.4.5
<Identifier>The property that identifies the configuration
object. May not be applicable depending on the
specified <Type>.
<key-value pair>One or more property-value pairs, i.e. <property
name>=<value> or <property name>="<value>".
<Type>Type of configuration object to perform operation
on.
Note
Requires Administrator privilege.
21
Page 22
2.1.3. cancel
Cancel ongoing commit.
Description
Cancel commit operation immediately, without waiting for the timeout.
Usage
cancel
Chapter 2: Command Reference
Note
Requires Administrator privilege.
2.1.4. cc
Change the current context.
Description
Change the current configuration context.
A context is a group of objects that are dependent on and grouped by a parent object. Many
objects lie in the "root" context and do not have a specific parent. Other objects, e.g. User objects
lie in a sub-context (or child context) of the root - in this case in a LocalUserDatabase. In order to
add or modify users you have to be in the correct context, e.g. a LocalUserDatabase called
"exampledb". Only objects in the current context can be accessed.
Example 2.2. Change context
Change to a sub/child context:
Go back to the parent context:
Go back to the root context:
or
gw-world:/> cc LocalUserDatabase exampledb
gw-world:/exampledb>
gw-world:/ospf1/area1> cc ..
gw-world:/ospf1> cc ..
gw-world:/>
gw-world:/ospf1/area1> cc
gw-world:/>
gw-world:/ospf1/area1> cc /
gw-world:/>
Usage
cc [<Category>] <Type> <Identifier>
22
Page 23
Chapter 2: Command Reference
Change the current context.
cc -print
Print the current context.
cc
Change to root context (same as "cc /").
Options
-printPrint the current context.
<Category>Category that groups object types.
<Identifier>The property that identifies the configuration
object. May not be applicable depending on the
specified <Type>.
<Type>Type of configuration object to perform operation
on.
2.1.5. commit
Save new configuration to media.
Description
Save the new configuration to media. This command can only be issued after a successful
activate command.
Usage
commit
2.1.6. delete
Delete specified objects.
Note
Requires Administrator privilege.
Description
Delete the specified object, removing it from the configuration.
Add the force flag to delete the object even if it is referenced by other objects or if it is a context
that has child objects that aren't deleted. This may cause objects referring to the specified object
or one of its children to get errors that must be corrected before the configuration can be
23
Page 24
Chapter 2: Command Reference
activated.
See also: undelete
Example 2.3. Delete an object
Delete an unreferenced object:
gw-world:/> delete Address IP4Address example_ip
Delete a referenced object:
(will cause error in examplerule)
gw-world:/> set IPRule examplerule SourceNetwork=examplenet
-forceForce object to be deleted even if it's used by other
<Category>Category that groups object types.
<Identifier>The property that identifies the configuration
<Type>Type of configuration object to perform operation
2.1.7. pskgen
Generate random pre-shared key.
objects or has children.
object. May not be applicable depending on the
specified <Type>.
on.
Note
Requires Administrator privilege.
Description
Generate a pre-shared key of specified size, containing randomized key data. If a key with the
specified name exists, the existing key is modified. Otherwise a new key object is created.
Reject the changes made to the specified object by reverting to the values of the last committed
configuration.
All changes made to the object will be lost. If the object is added after the last commit, it will be
removed.
To reject the changes in more than one object, use either the -recursive flag to delete a
context and all its children recursively or the -all flag to reject the changes in all objects in the
configuration.
Number of bits of data in the generated key.
(Default: 64)
<Identifier>The property that identifies the configuration
object. May not be applicable depending on the
specified <Type>.
<Type>Type of configuration object to perform operation
2.1.9. reset
Reset unit configuration and/or binaries.
Description
Reset configuration to the base configuration as generated by the current core or reset binaries
to factory defaults.
Usage
reset -configuration
on.
Note
Requires Administrator privilege.
Reset the configuration to factory defaults.
reset -unit
Reset the unit to factory defaults.
Options
-configurationReset configuration to current core default.
26
Page 27
-unitReset unit to factory defaults.
2.1.10. set
Set property values.
Description
Set property values of configuration objects.
Specify the type of object you want to modify and the identifier, if the type has one. Set the
properties of the object by writing the propertyname equals (=) and then the value. An optional
category can be specified for some object types when using tab completion.
Chapter 2: Command Reference
Note
Requires Administrator privilege.
If a mandatory property hasn't been specified or if a property has an error a list of errors will be
shown after the specified properties have been set. If an invalid property or value type is
specified the command will fail and not modify the object.
See also: add
Example 2.5. Set property values
Set properties for objects that have an identifier property:
gw-world:/> set Address IP4Address example_ip Address=1.2.3.4
Comments="This is an example"
gw-world:/> set IP4Address example_ip2 Address=2.3.4.5
Comments=comment_without_whitespace
gw-world:/main> set Route 1 Comment="A route"
gw-world:/> set IPRule 12 Index=1
Set properties for an object without identifier:
gw-world:/> set DynDnsClientDyndnsOrg Username=example
Usage
set [<Category>] <Type> [<Identifier>] [-disable] [-enable]
[-force] [<key-value pair>]...
Options
-disableDisable object. This option is not available if the
object is already disabled.
-enableEnable object. This option is not available if the
object is already enabled.
-forceSet values, even if they contain errors.
27
Page 28
<Category>Category that groups object types.
<Identifier>The property that identifies the configuration
<key-value pair>One or more property-value pairs, i.e. <property
<Type>Type of configuration object to perform operation
2.1.11. show
Show objects.
Chapter 2: Command Reference
object. May not be applicable depending on the
specified <Type>.
name>=<value> or <property name>="<value>".
on.
Note
Requires Administrator privilege.
Description
Show objects.
Show the properties of a specified object. There are a number of flags that can be specified to
show otherwise hidden properties. To show a list of object types and categories available in the
current context, just type show. Show a table of all objects of a type by specifying a type or a
category. Use the -errors or -changes flags to show what objects have been changed or
have errors in the configuration.
When showing a table of all objects of a certain type, the status of each object since the last time
the configuration was committed is indicated by a flag. The flags used are:
-The object is deleted.
oThe object is disabled.
!The object has errors.
+The object is newly created.
*The object is modified.
Additional flags:
DThe object has dynamic properties which are updated by the system.
When listing categories and object types, categories are indicated by [] and types where objects
may be contexts by /.
Example 2.6. Show objects
Show the properties of an individual object:
28
Page 29
Chapter 2: Command Reference
gw-world:/> show Address IP4Address example_ip
gw-world:/main> show Route 1
gw-world:/> show Client DynDnsClientDyndnsOrg
Show a table of all objects of a type and a selection of their
properties as well as their status:
gw-world:/> show Address IP4Address
gw-world:/> show IP4Address
Show a table of all objects for each type in a category:
gw-world:/> show Address
Show objects with changes and errors:
gw-world:/> show -changes
gw-world:/> show -errors
Show what objects use (refer to) a certain object:
gw-world:/> show Address IP4Address example_ip -references
Usage
show
Show the types and categories available in the current context.
show [<Category>] [<Type> [<Identifier>]] [-disabled] [-references]
Show an object or list a type or category.
show -errors [-verbose]
Show all errors.
show -changes
Show all changes.
Options
-changesShow all changes in the current configuration.
-disabledShow disabled properties.
-errorsShow all errors in the current configuration.
-referencesShow all references to this object from other
objects.
-verboseShow error details.
<Category>Category that groups object types.
<Identifier>The property that identifies the configuration
<Type>Type of configuration object to perform operation
2.1.12. undelete
object. May not be applicable depending on the
specified <Type>.
on.
29
Page 30
Chapter 2: Command Reference
Restore previously deleted objects.
Description
Restore a previously deleted object.
This is possible as long as the activate command has not been called.
See also: delete
Example 2.7. Undelete an object
Undelete an unreferenced object:
gw-world:/> delete Address IP4Address example_ip
gw-world:/> undelete Address IP4Address example_ip
Undelete a referenced object:
(will remove the error in examplerule)
gw-world:/> set IPRule examplerule SourceNetwork=examplenet
<Identifier>The property that identifies the configuration
object. May not be applicable depending on the
specified <Type>.
<Type>Type of configuration object to perform operation
on.
Note
Requires Administrator privilege.
30
Page 31
2.2. Runtime
2.2.1. about
Show copyright/build information.
Description
Show copyright and build information.
Usage
about
2.2.2. alarm
Chapter 2: Command Reference
Show alarm information.
Description
Show list of currently active alarms.
Usage
alarm [-history] [-active]
Options
-activeShow the currently active alarms.
-historyShow the 20 latest alarms.
2.2.3. appcontrol
Show application control status.
Description
Browse the applications defined in the Application Control functionality. Saved browsing results
as filters that can be later used to define IPPolicies.
Usage
31
Page 32
appcontrol
Show general information about application control system.
appcontrol -show_lists
List information about specified application.
appcontrol -delete_lists={ALL | <Integer>}
List information about specified application.
appcontrol <Name>
List information about specified application.
appcontrol -application=<String> [-save_list]
Define a filter selecting individual applications.
Turn IKE on-screen snooping on/off. Useful for troubleshooting IPsec connections.
Usage
ikesnoop
Show IKE snooping status.
ikesnoop -on [<ip address>] [-verbose]
Enable IKE snooping.
ikesnoop -off
Disable IKE snooping.
Options
-offTurn IKE snooping off.
-onTurn IKE snooping on.
51
Page 52
-verboseEnable IKE snooping with verbose output.
<ip address>IP address to snoop.
2.2.37. ippool
Show IP pool information.
Description
Show information about the current state of the configured IP pools.
Usage
ippool
Show IP pool information.
Chapter 2: Command Reference
ippool -release [<ip address>] [-all]
Forcibly free IP assigned to subsystem.
ippool -show [-verbose] [-num=<n>]
Show IP pool information.
Options
-allFree all IP addresses.
-num=<n>Limit list to <n> entries. (Default: 10)
-releaseForcibly free IP assigned to subsystem. (Admin
-showShow IP pool information.
-verboseVerbose output.
<ip address>IP address to free.
2.2.38. ipsecdefines
only)
Display various DEFINES that specify the system performance.
Description
Display various DEFINES that specify the system performance.
Usage
52
Page 53
ipsecdefines
2.2.39. ipsecglobalstats
Show global ipsec statistics.
Description
List global IPsec statistics.
Usage
ipsecglobalstats -mem [-verbose]
Start IKE test.
ipsecglobalstats -verbose
Chapter 2: Command Reference
Start IKE test.
ipsecglobalstats
Show interfaces.
Options
-memShow memory statistics.
-verboseShow all statistics.
2.2.40. ipsechastat
Show statistics about HA synchronization for IPsec.
Description
Shows statistics about IKE/IPsec SAs synchronized and how many that failed to import. Sent
statistics shows how many packets that has been sent to the other cluster member when this
node was active and receive statistics show how many packets/failures it got as inactive.
Usage
ipsechastat [-clear]
Options
-clearReset all statistics.
53
Page 54
2.2.41. ipsecstats
Show the SAs in use.
Description
List the currently active IKE and IPsec SAs, optionally only showing SAs matching the pattern
given for the argument "tunnel".
Show information about real-time monitor objects, and real-time monitor alerts.
All objects matching the specified filter are displayed. The filter can be the name of an object, or
the beginning of a name. If no filter is specified, all objects are displayed.
69
Page 70
Chapter 2: Command Reference
If the option "monitored" is specified, only objects that have an associated real-time monitor
alert are displayed.
Example 2.11. Show all monitored objects in the alg/http category
gw-world:/> rtmonitor alg/http -m
Usage
rtmonitor [<filter>] [-terse] [-monitored]
Options
-monitoredOnly show monitored objects.
-terseOnly show object name.
<filter>Object filter.
2.2.66. rules
Show rules lists.
Description
Shows the content of the various types of rules, i.e. main ruleset, pipe ruleset, etc.
Example 2.12. Show a range of rules
rules -verbose 1-5 7-9
Usage
rules -type=IP [-ruleset={* | MAIN | <IP Rule Set>}] [-verbose]
-verboseVerbose: show all parameters of the rules.
<rules>Range of rules to display. (default: all rules).
2.2.67. selftest
Run appliance self tests.
Description
The appliance self tests are used to verify the correct function of hardware components.
IMPORTANT: In order for a selftest result to be reliable the test must be run using a default
configuration and having the SGW disconnected from any networks.
IMPORTANT: Normal SGW operations might be disrupted during the test(s).
The outcome of the throughput crypto accelerator tests are dependent on configuration values.
If the number of large buffers (LocalReassSettings->LocalReass_NumLarge) too low, it might
lower throughput result. In the field 'Drop/Fail', the 'Drop' column contains the number of
packets that were dropped before ever reaching the crypto accelerator and the 'Fail' column
contains the number of packets that for some reason failed encryption. The 'Pkt In/Out' field
shows the total number of packets sent to, and returned from the accelerator.
Type of rules to display. (Default: IP)
The interface tests 'traffic' and 'throughput' are dependent on the settings for the NIC ring sizes
and possibly also license limitations. The 'traffic' test uses a uniform random distribution of six
packet sizes between 60 and 1518 bytes. The content of each received packet is validated. The
'throughput' test uses only the largest packet size, and does not validate the contents of the
received packets.
Example 2.13. Interface ping test between all interfaces
selftest -ping
Example 2.14. Interface ping test between interfaces 'if1' and 'if2'
selftest -ping -interfaces=if1,if2
Example 2.15. Start 30 min burn-in, testing RAM, storage media and crypto accelerator
Show the contents of the settings section, category by category.
Usage
settings
Chapter 2: Command Reference
Show list of categories.
settings <category>
Show settings in category.
Options
<category>Show settings in category.
2.2.71. shutdown
Initiate core or system shutdown.
Description
Initiate restart of the core/system.
Usage
shutdown [<seconds>] [-normal] [-reboot]
Options
-normalInitiate core shutdown.
-rebootInitiate system reboot.
<seconds>Seconds until shutdown. (Default: 5)
75
Page 76
2.2.72. sipalg
SIP ALG.
Description
List running SIP-ALG configurations, SIP registration and call information.
The -flags option with -snoop allows any combination of the following values:
-0x00000001 GENERAL
-0x00000002 ERRORS
-0x00000004 OPTIONS
Chapter 2: Command Reference
Note
Requires Administrator privilege.
-0x00000008 PARSE
-0x00000010 VALIDATE
-0x00000020 SDP
-0x00000040 ALLOW_CHANGES
-0x00000080 SUPPORTED_CHANGES
-0x00000100 2543COMPLIANCE
-0x00000200 RECEPTION
-0x00000400 SESSION
-0x00000800 REQUEST
-0x00001000 RESPONSE
-0x00002000 TOPO_CHANGES
-0x00004000 MEDIA
-0x00008000 CONTACT
-0x00010000 CONN
-0x00020000 PING
-0x00040000 TRANSACTION
-0x00080000 CALLLEG
-0x00100000 REGISTRY
Flags can be added in the usual way. The default value is 0x00000003 (GENERAL and ERRORS).
76
Page 77
Chapter 2: Command Reference
NOTE: 'verbose' option outputs a lot of information on the console which may lead to system
instability. Use with caution.
Usage
sipalg -definition <alg>
Show running ALG configuration parameters.
sipalg -registration[={SHOW | FLUSH}] <alg>
Show or flush current registration table.
sipalg -calls <alg>
Show active calls table.
sipalg -session <alg>
Show active SIP sessions.
sipalg -connection <alg>
Show SIP connections.
sipalg -statistics[={SHOW | FLUSH}] <alg>
Show or flush SIP counters.
sipalg -snoop={ON | OFF | VERBOSE} [<ipaddr>] [-flags=<String>]
Control SIP snooping. Useful for troubleshooting SIP transactions. NOTE: 'verbose' option
outputs a lot of information on the console which may lead to system instability. Use with
caution.
-count=<1...10>Number of packets to send. (Default: 1)
-length=<2...8192>Packet size. (Default: 4)
-pbr=<table>Route using PBR Table.
-port=<0...65535>Destination port of UDP or TCP ping.
-srcif=<interface>Pass packet through the rule set, simulating that
the packet was received by <srcif>.
-srcip=<ip address>Use this source IP.
-tcpSend TCP ping.
-tos=<0...255>Type of service.
-udpSend UDP ping.
-verboseVerbose (more information).
<host>IP address of host to ping.
84
Page 85
2.4. Misc
2.4.1. echo
Print text.
Description
Print text to the console.
Example 2.18. Hello World
echo Hello World
Usage
Chapter 2: Command Reference
echo [<String>]...
Options
<String>Text to print.
2.4.2. help
Show help for selected topic.
Description
The help system contains information about commands and configuration object types.
The fastest way to get help is to simply type help followed by the topic that you want help with.
A topic can be for example a command name (e.g. set) or the name of a configuration object
type (e.g. User).
When you don't know the name of what you are looking for you can specify the category of the
wanted topic with the -category option and use tab-completion to display a list of matching
topics.
Usage
help
List commands alphabetically.
help <Topic>
85
Page 86
Display help about selected topic from any category.
help -category={COMMANDS | TYPES} [<Topic>]
Display help from a specific topic category.
Options
-category={COMMANDS | TYPES}Topic category.
<Topic>Help topic.
2.4.3. history
Dump history to screen.
Description
List recently typed commands that have been stored in the command history.
Chapter 2: Command Reference
2.4.4. ls
Usage
history
Lists device data accessible by SCP.
Description
Lists device data which are available through SCP.
Example 2.19. Transfer script files to and from the device
-createCreate configuration script from specified object,
class or category.
-executeExecute script.
-forceForce script execution.
-name=<Name>Name of script.
-quietQuiet script execution.
-removeRemove script.
-showShow script in console window.
-storeStore a script to persistent storage.
-verboseVerbose mode.
<Category>Category that groups object types.
<Identifier>The property that identifies the configuration
object. May not be applicable depending on the
specified <Type>.
<Parameters>List of input arguments.
<Type>Type of configuration object to perform operation
on.
Note
Requires Administrator privilege.
88
Page 89
Chapter 2: Command Reference
89
Page 90
Chapter 3: Configuration Reference
• Access, page 94
• Address, page 95
• AdvancedScheduleProfile, page 99
• ALG, page 100
• AntiVirusPolicy, page 109
• ApplicationRuleSet, page 110
• ARPND, page 111
• ARPNDSettings, page 112
• AuthAgent, page 115
• AuthenticationSettings, page 116
• BlacklistWhiteHost, page 117
• BNE2EthernetPCIDriver, page 118
• BroadcomEthernetPCIDriver, page 119
• Certificate, page 120
• COMPortDevice, page 121
• ConfigModePool, page 122
• ConnTimeoutSettings, page 123
• DateTime, page 124
• DefaultInterface, page 125
• Device, page 126
• DHCPRelay, page 127
• DHCPRelaySettings, page 129
• DHCPServer, page 130
90
Page 91
• DHCPServerSettings, page 133
• DHCPv6Server, page 134
• DHCPv6ServerSettings, page 136
• DNS, page 137
• DynamicRoutingRule, page 138
• DynDnsClientCjbNet, page 141
• DynDnsClientDyndnsOrg, page 142
• DynDnsClientDynsCx, page 143
• DynDnsClientPeanutHull, page 144
• E1000EthernetPCIDriver, page 145
• E100EthernetPCIDriver, page 146
• Ethernet, page 147
Chapter 3: Configuration Reference
• EthernetDevice, page 149
• EthernetSettings, page 150
• EventReceiverSNMP2c, page 152
• FileControlPolicy, page 153
• FragSettings, page 154
• GRETunnel, page 156
• HighAvailability, page 157
• HTTPALGBanners, page 158
• HTTPAuthBanners, page 159
• HTTPPoster, page 160
• HWM, page 161
• HWMSettings, page 162
• ICMPSettings, page 163
• IDList, page 164
• IDPRule, page 165
• IGMPRule, page 167
• IGMPSetting, page 169
• IKEAlgorithms, page 170
• InterfaceGroup, page 171
• IPPolicy, page 172
91
Page 92
• IPPool, page 175
• IPRule, page 176
• IPRuleFolder, page 179
• IPRuleSet, page 180
• IPsecAlgorithms, page 181
• IPsecTunnel, page 183
• IPsecTunnelSettings, page 186
• IPSettings, page 188
• ixgbeEthernetPCIDriver, page 191
• IXP4NPEEthernetDriver, page 192
• L2TPClient, page 193
• L2TPServer, page 195
Chapter 3: Configuration Reference
• L2TPServerSettings, page 197
• L2TPv3Server, page 198
• LDAPDatabase, page 199
• LDAPServer, page 200
• LengthLimSettings, page 201
• LinkAggregation, page 202
• LinkMonitor, page 204
• LocalReassSettings, page 205
• LocalUserDatabase, page 206
• LogReceiverFWLog, page 207
• LogReceiverMemory, page 208
• LogReceiverSMTP, page 209
• LogReceiverSyslog, page 210
• LogSettings, page 211
• LoopbackInterface, page 212
• MarvellEthernetPCIDriver, page 213
• MiscSettings, page 214
• MulticastSettings, page 216
• NATPool, page 217
• OSPFProcess, page 218
92
Page 93
• Pipe, page 223
• PipeRule, page 226
• PPPoETunnel, page 227
• PPPSettings, page 229
• PSK, page 230
• R8139EthernetPCIDriver, page 231
• R8169EthernetPCIDriver, page 232
• RadiusAccounting, page 233
• RadiusRelay, page 234
• RadiusServer, page 236
• RealTimeMonitorAlert, page 237
• RemoteIDList, page 238
Chapter 3: Configuration Reference
• RemoteMgmtHTTP, page 239
• RemoteMgmtNetcon, page 240
• RemoteMgmtSettings, page 241
• RemoteMgmtSNMP, page 243
• RemoteMgmtSSH, page 244
• RouteBalancingInstance, page 246
• RouteBalancingSpilloverSettings, page 247
• RouterAdvertisement, page 248
• RoutingRule, page 250
• RoutingSettings, page 251
• RoutingTable, page 253
• ScheduleProfile, page 257
• ServiceGroup, page 258
• ServiceICMP, page 259
• ServiceICMPv6, page 261
• ServiceIPProto, page 263
• ServiceTCPUDP, page 264
• SSHClientKey, page 265
• SSLSettings, page 266
• SSLVPNInterface, page 267
93
Page 94
• SSLVPNInterfaceSettings, page 268
• ST201EthernetPCIDriver, page 269
• StateSettings, page 270
• TCPSettings, page 271
• ThresholdRule, page 273
• TulipEthernetPCIDriver, page 275
• UpdateCenter, page 276
• URLFilterPolicy, page 277
• UserAuthRule, page 278
• VLAN, page 281
• VLANSettings, page 283
• WebContentFilteringPolicy, page 284
Chapter 3: Configuration Reference
• X3C905EthernetPCIDriver, page 285
3.1. Access
Description
Use an access rule to allow or block specific source IP addresses on a specific interface.
Properties
IndexThe index of the object, starting at 1. (Identifier)
NameSpecifies a symbolic name for the object.
ActionAccept, Expect or Drop. (Default: Drop)
InterfaceThe interface the packet must arrive on for this rule
NetworkThe IP span that the sender must belong to for this
LogEnabledEnable logging. (Default: Yes)
to be carried out. Exception: the Expect rule.
rule to be carried out.
LogSeveritySpecifies with what severity log events will be sent
to the specified log receivers. (Default: Default)
CommentsText describing the current object. (Optional)
Note
If no Index is specified when creating an instance of this type, the object will be placed
last in the list and the Index will be equal to the length of the list.
94
Page 95
3.2. Address
This is a category that groups the following object types.
3.2.1. AddressFolder
Description
An address folder can be used to group related address objects for better overview.
Properties
NameSpecifies a symbolic name for the network object.
CommentsText describing the current object. (Optional)
3.2.1.1. IP6Address
Chapter 3: Configuration Reference
(Identifier)
Description
Use an IP6 Address item to define a name for a specific IP6 host, network or range.
Properties
NameSpecifies a symbolic name for the network object.
AddressIPv6 address, e.g. "2001:DB8::/32".
ActiveAddressThe dynamically set address used by e.g. DHCPv6
CommentsText describing the current object. (Optional)
3.2.1.2. IP6Group
Description
An IP6 Address Group is used for combining several IP6 Address objects for simplified
management.
Properties
(Identifier)
enabled Ethernet interfaces. (Optional)
NameSpecifies a symbolic name for the network object.
(Identifier)
MembersGroup members.
CommentsText describing the current object. (Optional)
95
Page 96
3.2.1.3. EthernetAddress
Description
Use an Ethernet Address item to define a symbolic name for an Ethernet MAC address.
Properties
NameSpecifies a symbolic name for the network object.
AddressEthernet MAC address, e.g. "12-34-56-78-ab-cd".
CommentsText describing the current object. (Optional)
3.2.1.4. EthernetAddressGroup
Description
Chapter 3: Configuration Reference
(Identifier)
An Ethernet Address Group is used for combining several Ethernet Address objects for simplified
management.
Properties
NameSpecifies a symbolic name for the network object.
MembersGroup members.
CommentsText describing the current object. (Optional)
3.2.1.5. IP4HAAddress
Description
Use an IP4 HA Address item to define a name for a specific IP4 host, network or range for each
node in a high availability cluster.
Properties
NameSpecifies a symbolic name for the network object.
(Identifier)
(Identifier)
AddressAn IP address with one instance for each node in
the high availability cluster.
UserAuthGroupsGroups and user names that belong to this object.
Objects that filter on credentials can only be used
as source networks and destinations networks in
rules. (Optional)
NoDefinedCredentialsIf this property is enabled the object requires user
96
Page 97
CommentsText describing the current object. (Optional)
3.2.1.6. IP4Group
Description
An IP4 Address Group is used for combining several IP4 Address objects for simplified
management.
Properties
NameSpecifies a symbolic name for the network object.
Chapter 3: Configuration Reference
authentication, but has no credentials (user names
or groups) defined. This means that the object only
requires that a user is authenticated, but ignores
any kind of group membership. (Default: No)
(Identifier)
MembersGroup members.
UserAuthGroupsGroups and user names that belong to this object.
NoDefinedCredentialsIf this property is enabled the object requires user
CommentsText describing the current object. (Optional)
3.2.1.7. IP4Address
Description
Use an IP4 Address item to define a name for a specific IP4 host, network or range.
Properties
NameSpecifies a symbolic name for the network object.
Objects that filter on credentials can only be used
as source networks and destinations networks in
rules. (Optional)
authentication, but has no credentials (user names
or groups) defined. This means that the object only
requires that a user is authenticated, but ignores
any kind of group membership. (Default: No)
(Identifier)
AddressIP address, e.g. "172.16.50.8", "192.168.7.0/24" or
"172.16.25.10-172.16.25.50".
ActiveAddressThe dynamically set address used by e.g. DHCP
enabled Ethernet interfaces. (Optional)
UserAuthGroupsGroups and user names that belong to this object.
Objects that filter on credentials can only be used
as source networks and destinations networks in
rules. (Optional)
97
Page 98
NoDefinedCredentialsIf this property is enabled the object requires user
CommentsText describing the current object. (Optional)
3.2.2. EthernetAddress
The definitions here are the same as in Section 3.2.1.3, “EthernetAddress” .
3.2.3. EthernetAddressGroup
The definitions here are the same as in Section 3.2.1.4, “EthernetAddressGroup” .
3.2.4. IP4Address
The definitions here are the same as in Section 3.2.1.7, “IP4Address” .
Chapter 3: Configuration Reference
authentication, but has no credentials (user names
or groups) defined. This means that the object only
requires that a user is authenticated, but ignores
any kind of group membership. (Default: No)
3.2.5. IP4Group
The definitions here are the same as in Section 3.2.1.6, “IP4Group” .
3.2.6. IP4HAAddress
The definitions here are the same as in Section 3.2.1.5, “IP4HAAddress” .
3.2.7. IP6Address
The definitions here are the same as in Section 3.2.1.1, “IP6Address” .
3.2.8. IP6Group
The definitions here are the same as in Section 3.2.1.2, “IP6Group” .
98
Page 99
3.3. AdvancedScheduleProfile
Description
An advanced schedule profile contains definitions of occurrences used by various policies in the
system.
Properties
NameSpecifies a symbolic name for the service.
(Identifier)
CommentsText describing the current object. (Optional)
3.3.1. AdvancedScheduleOccurrence
Description
Chapter 3: Configuration Reference
An advanced schedule occurrence specifies an occurrence that should happen between certain
times for days in month/week
Properties
StartTimeStart Time of occurence in the format HH:MM. For
example 13:30.
EndTimeEnd Time of occurence in the format HH:MM. For
example 14:15.
OccurrenceSpecify type of occurrence. (Default: Weekly)
WeeklySpecifies days in week the schedule occurrence
should be activated. Monday corresponds to 1 and
Sunday 7. (Default: 1-7)
MonthlySpecifies days in month the schedule occurrence
should be activated. The schedule only occurs at
days that exists in the month. (Default: 1-31)
CommentsText describing the current object. (Optional)
Note
If no Index is specified when creating an instance of this type, the object will be placed
last in the list and the Index will be equal to the length of the list.
99
Page 100
3.4. ALG
This is a category that groups the following object types.
3.4.1. ALG_FTP
Description
Use an FTP Application Layer Gateway to manage FTP traffic through the system.
Properties
NameSpecifies a symbolic name for the ALG. (Identifier)
AllowServerPassiveAllow server to use passive mode (unsafe for
ServerPortsServer data ports. (Default: 1024-65535)
Chapter 3: Configuration Reference
server). (Default: No)
AllowClientActiveAllow client to use active mode (unsafe for client).
(Default: No)
ClientPortsClient data ports. (Default: 1024-65535)