Nortel 3050, 3070, NVG 3050, NVG 3070, 1000 Command Reference Manual

...
Page 1
Nortel VPN Gateway
Command Reference
Release: 7.0 Document Revision: 01.01
www.nortel.com
NN46120-103
216369-E
Page 2
Nortel VPN Gateway Release: 7.0 Publication: NN46120-103 Document status: Standard Document release date: 10 September 2007
Copyright © 2007 Nortel Networks All Rights Reserved.
The information in this document is subject to change without notice. The statements, configurations, technical data, and recommendations in this document are believed to be accurate and reliable, but are presented without express or implied warranty. Users must take full responsibility for their applications of any products specified in this document. The information in this document is proprietary to Nortel Networks.
*Nortel, Nortel Networks, the Nortel logo and the Globemark are trademarks of Nortel Networks.
Export
This product, software and related technology is subject to U.S. export control and may be subject to export or import regulations in other countries. Purchaser must strictly comply with all such laws and regulations. A license to export or reexport may be required by the U.S. Department of Commerce.
Licensing
This product includes software developed by the OpenSSL Project for use in the OpenSSL Toolkit (
h
ttp://www.openssl.org/)
This product includes cryptographic software written by Eric Young ([email protected]).
This product includes software written by Tim Hudson ([email protected]).
This product includes software developed by the Apache Software Foundation (h
ttp://www.apache.org/).
This product includes a TAP-Win32 driver derived from the CIPE-Win32 kernel driver, Copyright © Damion K. Wilson, and is licensed under the GPL.
See Appendix D, "License Information", in the User’s Guide for more information.
Page 3
3
Contents
Preface 5
Who Should Use This Book 6 Related Documentation 7 Product Names 8 Typographic Conventions 9 How to Get Help 10 Getting help from Nortel Web site 10 Getting help over the phone from a Nortel Solutions Center 10 Getting help from a specialist by using an Express Routing Code 10 Getting help through a Nortel distributor or reseller 10
Command Reference 11
Menu Basics 12 Global Commands 13 CommandLine History and Editing 16 Command Line Interface Shortcuts 18 Variables 22 The Main Menu 25
/info Information Menu 26 /stats Statistics Menu 42 /cfg Configuration Menu 81 /cfg/ vpn #/syslog Syslog VPN configuration 419 /boot Boot Menu 468 /maint Maintenance Menu 472 /maint/logLogging system configuration 477 /maint/log/ in-memoryInternal memory configuration 477
CLI Dumps 479 Index 495
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 4
4
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 5
5
Preface
This Command Reference lists all the CLI commands available in the Nortel VPN Gateway (NVG) software. The software supports both SSL Acceleration and VPN.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 6
6 Preface
Who Should Use This Book
This Command Reference is intended for network installers and system administrators engaged in configuring and maintaining a network. It assumes that you are familiar with Ethernet concepts and IP addressing.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 7
Licensing 7
Related Documentation
For full documentation on installing, configuring and using the many features of the SSL VPN, see the following manuals:
• VPN Gateway 7.0 User’s Guide
(part number 216368-F September 2007) Describes the initial setup procedure, upgrades, operator user management, certificate management, troubleshooting and other general operations that apply to both SSL Acceleration and VPN.
• VPN Gateway 7.0 Command Reference Guide
(part number 216369-E September 2007) Describes each command line in detail. The commands are listed per menu according to the order listed in the Command Line Interface (CLI).
•
VPN Gateway 7.0 Application Guide for SSL Acceleration
(part number 216370-D April 2006) Provides examples on how to configure SSL Acceleration through the CLI.
•
VPN Gateway 7.0 CLI Application Guide for VPN
(part number 216371-E September 2007) Provides examples on how to configure VPN deployment through the CLI.
•
VPN Gateway 7.0 BBI Application Guide for VPN
(part number 217239-D, September 2007) Provides examples on how to configure VPN deployment through the BBI (Browser-Based Management Interface).
• VPN Gateway 7.0 VPN Administrator’s Guide
(part number 217238-D, September 2007) VPN management guide intended for end-customers in a Secure Service Partitioning configuration.
• VPN Gateway 3050/3070 Hardware Installation Guide
(part number 216213-B, March 2005) Describes installation of the VPN Gateway 3050 and 3070 hardware models.
• VPN Gateway 7.0 Release Notes
(part number 216372-P, September 2007) Lists new features available in version 7.0 and provides up-to-date product information.
The preceding manuals are available for download (see “How to Get
Help” (page 10)).
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 8
8 Preface
Product Names
The software described in this manual runs on several different hardware models. Whenever the terms Nortel VPN Gateway, VPN Gateway or NVG are used in the documentation, the following hardware models are implied:
• Nortel VPN Gateway 3050 (NVG 3050)
• Nortel VPN Gateway 3070 (NVG 3070)
• Nortel SSL VPN Module 1000 (SVM 1000)
The integrated SSL Accelerator (SSL processor) on the Nortel 2424-SSL switch Similarly, all references to the old product name iSD-SSL or iSD in commands or screen outputs should be interpreted as applying to the preceding hardware models.
Note:
Manufacturing of the Nortel SSL Accelerator (formerly Alteon
SSL Accelerator) has been discontinued.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 9
Licensing 9
Typographic Conventions
The following table describes the typographic styles used in this book.
Table 1 Typographic Conventions
Typeface or Symbol
Meaning Example
AaBbCc123
This type is used for names of commands, files, and directories used within the text.
View the readme.txt file.
It also depicts on-screen computer output and prompts.
Main#
AaBbCc123
This bold type appears in command examples. It shows text that must be typed in exactly as shown.
Main# sys
<AaBbCc123> This italicized type appears
in command examples as a parameter placeholder. Replace the indicated text with the appropriate real name or value when using the command. Do not type the brackets.
To establish a Telnet session, enter: host#
telnet <IP address>
This also shows book titles, special terms, or words to be emphasized.
Read your User’s Guide thoroughly.
[ ] Command items shown
inside brackets are optional and can be used or excluded as the situation demands. Do not type the brackets.
host# ls[-a]
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 10
10 Preface
How to Get Help
This section explains how to get help for Nortel products and services.
Getting help from Nortel Web site
The best way to get technical support for Nortel products is from the Nortel Technical Support Web site: w
ww.nortel.com/support
This site provides quick access to software, documentation, bulletins, and tools to address issues with Nortel products. From this site, you can:
• download software, documentation, and product bulletins for answers
to technical issues
• sign up for automatic notification of new software and documentation
for Nortel equipment
•
open and manage technical support cases
Getting help over the phone from a Nortel Solutions Center
If you do not find the information you require on the Nortel Technical Support web site, and have a Nortel support contract, you can also get help over the phone from a Nortel Solutions Center.
In North America, call 1-800-4NORTEL (1-800-466-7835). Outside North America, go to the following web site to obtain the phone number for your region: w
ww.nortel.com/callus
Getting help from a specialist by using an Express Routing Code
An Express Routing Code (ERC) is available for many Nortel products and services. When you use an ERC, your call is routed to a technical support person who specializes in supporting that product or service. To locate the ERC for your product or service, go to:w
ww.nortel.com/erc
Getting help through a Nortel distributor or reseller
If you purchased a service contract for your Nortel product from a distributor or authorized reseller, contact the technical support staff for that distributor or reseller.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 11
11
Command Reference
This chapter describes how to use the command line interface on the Nortel VPN Gateway (NVG). The chapter also provides explanations of all available commands.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 12
12 Command Reference
Menu Basics
The Command Line Interface (CLI) is used for viewing information and statistics. In addition, the administrator can use the CLI for configuring all levels of the VPN Gateway.
The various CLI commands are grouped into a series of menus and submenus. Each menu displays a list of commands and/or submenus that are available, along with a summary of what each command will do. Below each menu is a prompt where you can enter any command appropriate to the current menu.
When creating new CLI objects, for example a new interface or a new group, you will enter a wizard providing the relevant questions for that object. The regular menu for the object will be displayed after the wizard is completed.
This section describes the Main menu commands, and provides a list of commands and shortcuts that are commonly available from all the menus within the CLI.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 13
Getting help through a Nortel distributor or reseller 13
Global Commands
Some basic commands are recognized throughout the menu hierarchy. These commands are useful for obtaining online help, navigating through menus, and for applying and saving configuration changes:
Table 2 Global Commands
Command
Action
help
Display a summary of the global commands.
help <command>
Displays help on a specific command in the command line interface. Example: Typing the "/cfg/sys" command at any prompt in the CLI will display the System menu. The same result is achieved by only typing /cfg/sys (no quotation marks) at any menu prompt.
.
Display the current menu.
print
Display the current menu.
..
Go up one level in the menu structure.
up
Go up one level in the menu structure.
/
If placed at the beginning of a command, go to the Main menu. Otherwise, this is used to separate multiple commands placed on the same line.
cd " <menu/path> "
Display the menu indicated within quotation marks. Example: Typing cd "/cfg/sys" at any prompt in the CLI will display the System menu. The same result is achieved by only typing /cfg/sys (no quotation marks) at any menu prompt.
pwd
Display the command path used to reach the current menu.
apply
Apply pending configuration changes.
diff
Show any pending configuration changes. Passwords and secrets (if any) are displayed as (SECRET).
revert
Remove pending configuration changes between "apply" commands. Use this command to restore configuration parameters set since last "apply" command.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 14
14 Command Reference
Table 2 Global Commands (cont’d.)
Command
Action
paste
Lets you restore a previously dumped configuration. Before pasting the configuration, you need to provide the password phrase you specified when executing the dump command. For more information, see the dump command.
exit
Terminate the current session and log out. If you have unapplied (pending) configuration changes when using the exit command, you will be notified. If you choose to log out anyhow without using the apply command, your pending configuration changes will be lost.
quit
Same as Exit. If you have unapplied (pending) configuration changes when using the quit command, you will be notified. If you choose to log out anyhow without using the apply command, your pending configuration changes will be lost.
CTRL+^
Exit from the command line interface in case the VPN Gateway has stopped responding. This command should only be used when connected to a specific VPN Gateway through a console connection, not when connected to the Management IP of the cluster through a Telnet or SSH connection.
netstat
Use this command to show the current network status of the VPN Gateway. The netstat command provides information about active TCP connections, as well as the state of all TCP/IP servers and the sockets used by them.
nslookup
Use this command to find the IP address or host name of a machine. To use this command, you must have configured the VPN Gateway to use a DNS server. Example: >> Configuration# nslookup Enter Hostname | IpAddress: 47.80.21.24; Server: zsc4s011.us.nortel.com ; Address: 47.81.2.10
ping
Use this command to verify station-to-station connectivity across the network. The format is as follows:
ping <IP address or host name>
The DNS parameters must be configured if specifying host names (see /cfg/vpn <id> /adv/dns/servers DNS Servers Configuration).
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 15
Getting help through a Nortel distributor or reseller 15
Table 2 Global Commands (cont’d.)
Command
Action
traceroute
Use this command to identify the route used for station-to-station connectivity across the network. The format is as follows:
traceroute <IP address or host name of target station>
As with ping, the DNS parameters must be configured if specifying host names.
cur
Use this command to view all the current settings for the active menu. Passwords and secrets (if any) are displayed as (SECRET).
curb
Use this command for a brief version of the current settings for the active menu.
dump
Use this command to dump the current configuration for the active menu. The dumped information can be cut and pasted in to another operator’s CLI at the same menu level. The dump command is also available in all statistics menus to display statistics information for the active menu. When the dump command is used, no secret value will be dumped unless a dump password has been given, and in this case the secret value is encrypted. To paste a dump, the paste command should be used. The password given at the dumpcommand should then be supplied.
lines n
Set the number of lines (n) that is displayed on the screen at one time. The default value is 24 lines. When used without a value, the current setting is displayed.
verbose
n
Sets the level of information displayed on the screen: 0 = Quiet: Nothing appears except errors—not even prompts. 1 = Normal: Prompts and requested output are shown, but no menus. 2 = Verbose: Everything is shown. The default level is 2. When used without a value, the current setting is displayed.
slist
Use this command to display a list of all Admin user sessions currently running in the cluster.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 16
16 Command Reference
CommandLine History and Editing
Using the command line interface, you can retrieve and modify previously entered commands with just a few keystrokes. The following options are available globally at the command line:
Table 3 Command Line History and Editing Options
Option
Description
history
Display a numbered list of the last 10 previously entered commands.
!!
Repeat the last entered command.
! n
Repeat the n
th
command shown on the history list.
pushd
"Bookmarks" your current position in the menu structure. After moving to another level or command in the menu structure, you can easily return to the bookmarked position by typing the popd command. The
pushd command can be combined with command
stacking, as in this example:
>> Information# pushd "/cfg/ssl/server 1/ssl"
>> SSL Settings# When you issue the popd command,
you are immediately taken back to the prompt from where you issued the pushd command, the Information prompt in this example.
popd
Takes you back to a position in the menu structure that has been "bookmarked" by using the pushd command.
<Ctrl-p> (Also the up arrow key.) Recall the previous command from the
history list. This can be used multiple times to work backward through the last 10 commands. The recalled command can be entered as is, or edited using the following options.
<Ctrl-n> (Also the down arrow key.) Recall the next command from the
history list. This can be used multiple times to work forward through the last 10 commands. The recalled command can be
entered as is, or edited using the following options. <Ctrl-a> Move the cursor to the beginning of command line. <Ctrl-e> Move cursor to the end of the command line. <Ctrl-b> (Also the left arrow key.) Move the cursor back one position to
the left. <Ctrl-f> (Also the right arrow key.) Move the cursor forward one
position to the right. <Backspace> (Also the Delete key.) Erase one character to the left of the
cursor position. <Ctrl-d> Delete one character at the cursor position.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 17
Getting help through a Nortel distributor or reseller 17
Table 3 Command Line History and Editing Options (cont’d.)
Option
Description
<Ctrl-k> Kill (erase) all characters from the cursor position to the end of
the command line. <Ctrl-l> Rewrites the most recent command. <Ctrl-c>
Abort an on-going transaction. If pressed when there is no
on-going transaction, the current menu is displayed.
Note: Using <Ctrl-c> will not abort screen output generated from
using the cur command. To abort the heavy screen output that
may result from using the cur command, press <q>. <Ctrl-u> Clear the entire line. Other keys Insert new characters at the cursor position.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 18
18 Command Reference
Command Line Interface Shortcuts
Command Stacking
You can type multiple commands separated by forward slashes (/) on a single line to access a submenu and one of the related menu options. Type as many commands as required to access the desired submenu and menu option. For example, the keyboard shortcut to access the
list
command in the NTP Servers menu from the Main menu prompt is as follows:
>> Main# cfg/sys/time/ntp/list
You can also use command stacking to go up one or more levels in the menu system, and then go directly to another submenu and one of the related menu options in that submenu. For example, to go up two levels from the NTP Servers menu to the System menu, and from there to the DNS settings menu to access the DNS servers menu, you would type:
>> NTP Servers# ../../dns/servers
Command Abbreviation
Most commands can be abbreviated by entering the first characters which distinguish the command from the others in the same menu or submenu. For example, the command shown in the first preceding example could also be entered as follows:
>> Main# c/sy/t/n/l
TAB Command Completion
By typing the first letter of a command at any menu prompt and pressing TAB, all commands in that menu beginning with the letter you typed are displayed. By typing additional letters, you can further refine the list of commands or options displayed. If only one command matches the letter(s) you typed, that command is supplied on the command line when pressing TAB. You can then execute the command by pressing ENTER. If the TAB key is pressed without any input on the command line, the currently active menu is displayed.
TAB Value Presentation
Pressing the TAB key also displays available options, for example if you want to view previously configured values.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 19
UsingSubmenu Name as Command Argument 19
>> Main# cfg/vpn #/linkset #/link Enter Link number (1-256): <press TAB> Windows file share link(1) Net Direct link(2) Enter Link number (1-256):
In the preceding example, with the object name followed by the object ID within parenthesis, both the name and the integer (for example 2) can be used to select the object.
Example: To select Net Direct link, enter N and press TAB. This will complete the object name so that the full name is printed. Then press ENTER to select this value.
In the example below, with the object ID followed by the object name within parenthesis, only the integer (for example 2) can be used to select the object.
>> AAA# defippool <press TAB> Usage: defippool <integer>
2(RADIUS) 1(Local)
UsingSubmenu Name as Command Argument
To display the properties related to a specific submenu, you can provide the submenu name as an argument to the cur command (at a menu prompt one level up from the desired submenu information).
For example, to display system information at the Configuration menu prompt (/cfg), type the following command:
>> Configuration# cur sys System:
Management IP (MIP) address = 192.168.128.211
Cluster Host 1: Type of the host = master IP address = 192.168.128.213 SysName = SysLocation = License = IPsec user sessions: 250 Secure Service Partitioning PortalGuard TPS: unlimited SSL user sessions: 250 Default gateway address = 192.168.128.3 Ports = 1 : 2 Hardware platform = 3070 Host Routes: No items configured
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 20
20 Command Reference
Host Interface 1: IP address = 10.1.82.145 Network mask = 255.255.255.0 Default gateway address = 0.0.0.0 VLAN tag id = 0 Mode = failover Primary port = 0 Host Interface Routes: No items configured
Without having to descend into the System menu (/cfg/sys), system-specific information only is displayed directly at the Configuration menu prompt. If the cur command had been used without the sys submenu argument in the preceding example, information related to both the Configuration menu and all submenus would have been displayed.
UsingSlashes (/) and Spaces in Commands
If you need to use a forward slash (/) or a space in a command string, make sure the string containing the slash or space is within double quotation marks before you run the command. One example of a command where double quotation marks is required, is when you specify a directory path and file name on the same line as the ftp command in the CLI.
Example:
>> Software Management# download ftp 10.0.0.1 "pub/SSL-7.0.1­upgrade_complete.pkg"
IP Address and Network Mask Formats
IP Addresses
IP addresses can be specified in different ways in the CLI:
• Dotted decimal notation. Specify the IP address as is, for example
10.0.0.1.
•
According to the formats below: A.B.C.D = A.B.C.D, i.e. same as above A.B.D = A.B.0.D, i.e. 10.1.10 translates to 10.1.0.10 A.D = A.0.0.D, i.e. 10.1translates to 10.0.0.1 D = 0.0.0.D, i.e. 10translates to 0.0.0.10
Network Masks
A network mask can be entered in number of bits or in dotted decimal notation.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 21
IP Address and Network Mask Formats 21
Example: The network mask 255.0.0.0 can also be entered as 8. The network mask 255.255.0.0 can also be entered as 16. The network mask 255.255.255.0can also be entered as 24. The network mask 255.255.255.255can also be entered as 32.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 22
22 Command Reference
Variables
Some of the commands and features in the NVG software can take variables. The table below lists available variables and areas where they can be used.
Variable Usage
<var:user>
Expands to the user name specified when the user logged in to the VPN, for example on the Portal login page. The variable can for example be included in Portal link specifications (see ), in single-sign-on headers (see “
/cfg/vpn <id> /aaa/ssoheaders
Single-Sign-On Headers Configuration” (page
257)), for proxy mapping (see “/cfg/vpn <id> /server/proxymap Proxy Mapping Configuration” (page 282)), in redirect URLs and static texts
(see “/cfg/vpn <id> /portal SSL VPN Portal
Configuration” (page 323)).
<var:password> Expands to the password specified when the user
logged in to the VPN. The variable can for example be included in Portal link specifications (see ), in single-sign-on headers (see “ /cfg/vpn <id>
/aaa/ssoheaders Single-Sign-On Headers Configuration” (page 257)), for proxy mapping (see “/cfg/vpn <id> /server/proxymap Proxy Mapping Configuration” (page 282)) and in redirect URLs
(see “/cfg/vpn <id> /portal SSL VPN Portal
Configuration” (page 323)).
<var:group>
Expands to the group in which the logged on user is a member. The variable can for example be included in Portal link specifications (see ), in single-sign-on headers (see “ /cfg/vpn <id> /aaa/ssoheaders
Single-Sign-On Headers Configuration” (page 257)), in
redirect URLs and static texts (see “/cfg/vpn <id>
/portal SSL VPN Portal Configuration” (page 323)).
<var:portal> Expands to the Portal’s IP address. The variable can
for example be included in single-sign-on headers (see
“ /cfg/vpn <id> /aaa/ssoheaders Single-Sign-On Headers Configuration” (page 257)) and in redirect
URLs (see “/cfg/vpn <id> /portal SSL VPN
Portal Configuration” (page 323)).
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 23
IP Address and Network Mask Formats 23
Variable Usage
<var:domain> Expands to the domain name specified for the
authentication method by which the logged in user was authenticated. The domain name is specified with the /
cfg /vpn #/aaa/auth #/domain command. The variable can for example be included in Portal link specifications (see ) and in single-sign-on headers (see
“ /cfg/vpn <id> /aaa/ssoheaders Single-Sign-On Headers Configuration” (page 257)).
<var:method> Expands to the access protocol used, i.e. http or https. <var:sslsid> Expands to the SSL session ID in binary format. <var:clicert> Expands to a Base 64 encoded version of the
client certificate, if one was present when the user was logged in to the VPN. The variable can be used when creating dynamic HTTP headers (see
“/cfg/ssl/server <id> /http/dynheader Dynamic Header Configuration” (page 115)).
<md5:...> Expands the variable or variables (for example
<md5:<user>:<password>>) and computes an MD5 checksum which is Base 64 encoded. Can be used when creating dynamic HTTP headers (see
“/cfg/ssl/server <id> /http/dynheader Dynamic Header Configuration” (page 115)) and
single-sign-on headers (see “ /cfg/vpn <id>
/aaa/ssoheaders Single-Sign-On Headers Configuration” (page 257)).
<base64:...> Expands the variable or variables (for example
<base64:<user>:<password>>) and encodes them using Base 64. Can be used when creating dynamic HTTP headers (see “/cfg/ssl/server <id>
/http/dynheader Dynamic Header Configuration” (page 115)) and single-sign-on headers (see “ /cfg/vpn <id> /aaa/ssoheaders Single-Sign-On Headers Configuration” (page 257)).
<var:tgFailureReason>Expands to the Tunnel Guard rule expression and the
Tunnel Guard rule comment specified for the current SRS rule when a Tunnel Guard check has failed. For more information, see the "Configure Tunnel Guard" chapter in the Application Guide for VPN.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 24
24 Command Reference
Variable Usage
<var:tgFailureDetail> Expands to the software definition comment specified
for the current SRS rule, along with a detailed specification of missing/present files/processes etc generated by the Tunnel Guard applet when a Tunnel Guard check has failed. For more information, see the "Configure Tunnel Guard" chapter in the
Application
Guide for VPN.
Note that this variable is not expanded if /cfg/vpn #/aaa/tg/details is set to off.
Operator-defined variables
Custom variables can be created to retrieve the desired values from RADIUS and LDAP databases (see “/cfg/vpn <id> /aaa/auth <id>
/radius/macro RADIUS Macro Configuration” (page 188) and “/cfg/vpn <id> /aaa/auth <id> /ldap/ldapmacro LDAP Macro Configuration” (page
199)).
Note: Variables included in links are URL encoded whereas variables
included in static texts (for example on the Portal page and on the Portal login page) are not URL encoded.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 25
Menu Summary 25
The Main Menu
The Main menu appears after a successful connection and login. Table 4
"Administrator Main Menu" (page 25) shows the Main menu as it appears
when logged in as Administrator. Note that some of the commands are not available when logged in as Operator.
Table 4 Administrator Main Menu
[Main Menu] info - Information menu stats - Statistics menu cfg - Configuration menu boot - Boot menu maint - Maintenance menu diff - Show pending config changes [global command] apply - Apply pending config changes [global command] revert- Revert pending config changes [global command] paste - Restore saved config with key [global command] help - Show command help [global command] exit - Exit [global command, always available]
Menu Summary
•
Information menu
Provides submenus for displaying information about the current status of the VPN Gateway. For more information, see “/info Information
Menu” (page 26).
•
Statistics menu
Provides submenus for displaying NVG performance statistics. For more information, see “/stats Statistics Menu” (page 42).
•
Configuration menu
Provides submenus for configuring the NVG cluster, for example for SSL offload and VPN deployment. Some of the commands in the Configuration menu are available only when logged in as the Administrator user. For more information, see “ /cfg Configuration
Menu” (page 81).
• Boot menu
Is used for upgrading NVG software and for rebooting, if necessary. The Boot menu is only accessible when logged in as the Administrator user. For more information, see “/boot Boot Menu” (page 468).
• Maintenance menu
Is used for sending technical support information to an FTP/TFTP/SFTP server. For more information, see “/maint
Maintenance Menu” (page 472).
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 26
26 Command Reference
/info Information Menu
The Information menu is used for viewing information and events for VPN Gateways in a cluster.
[Information Menu]
servers - Show configured SSL servers
certs - Show configured certificates
hsm - Show local HSM information
sslvpn - Show configured VPNs
users - Show logged in SSL VPN portal users
idleusers - Show idle logged in SSL VPN portal users
ipsec - Show logged inIPsec users
botuns - Show IPsec BO tunnels
ippool - Show IP pool allocations
ip - Find information about an IP address
sys - Show system configuration
sonmp - SONMP topology
licenses - Show SSL VPN portal license usage
access - Print the access rules of an SSL VPN portal
user
kick - Kick an SSL VPN portal user
isd list - Show all hosts and their operational
status
local - Show local host information
Ethernet - Show local Ethernet status information
ports - Showlocal port(s) information
id - Show user name and groups for current user
events - Inspect Events menu
Table 5 Information Menu Options (/info)
Command Syntax and Usage
servers
Displays the current SSL server settings, including SSL specific settings for each configured virtual SSL server.
certs
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 27
Menu Summary 27
Table 5 Information Menu Options (/info) (cont’d.)
Command Syntax and Usage
Displays the certificate name, serial number, expiration date, and key size for each installed certificate. Information related to the subject part of the certificate is also displayed.
hsm
Displays status information related to the HSM cards on each NVG device in the cluster. Information about the current security mode (Extended mode or FIPS mode) is displayed, as well as current login status and login user information (HSM-SO or HSM-USER).
For a sample screen output, see “/info/hsm HSM Command” (page 33).
Note: HSM information is only displayed when you are using the ASA 310-FIPS model.
sslvpn
Displays information about the current SSL VPN settings, for example login session idle timeout value (shared by all configured VPNs), as well as information related to each specific VPN configuration. For each VPN, information about authentication methods, authentication order, user access groups and the access rules associated with each group is displayed.
users
<VPN ID> <prefix>
Displays the user name, login time, source IP address, access method (SSL or IPsec), group membership and profile of all remote users that are currently logged in to a VPN. The users are listed per VPN.
Examples of argument usage:
>> Information# users
Lists all currently logged in users for all VPNs.
>> Information# users 2
Lists all users currently logged in to VPN 2.
>> Information# users 2 j*
Lists users currently logged in to VPN 2, whose user name begins with the letter "j ".
>> Information# users 2 joe
Lists users currently logged in to VPN 2, whose user name is exactly "joe ".
For a sample screen output, see “info/users Users Command” (page
33).
idleusers <number of seconds> <VPN ID> <prefix>
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 28
28 Command Reference
Table 5 Information Menu Options (/info) (cont’d.)
Command Syntax and Usage
Lists all users that have been idle longer than the time specified in the command argument.
Examples of argument usage:
>> Information# idle 30
Lists all SSL users who have been idle more than 30 seconds.
>> Information# idle 5m 2
Lists all SSL users currently logged in to VPN 2 who have been idle more than 5 minutes.
>> Information# idle 1h 2 j*
Lists all SSL users currently logged in to VPN 2, whose user name begins with the letter "j", who have been idle more than 1 hour.
>> Information# idle 1h 2 joe
Lists all SSL users currently logged in to VPN 2, whose user name is exactly "joe", who have been idle more than 1 hour.
The information includes VPN ID, user name, login time, last time active, source IP address and access method.
For a sample screen output, see “info/idleusers Idleusers Command”
(page 34).
ipsec <VPN ID> <prefix>
Shows currently logged in IPsec users. The information includes user name, user tunnel profile name, actual source IP address, new source IP address allocated from IP pool, encrypted/decrypted data in kBytes and session length.
Examples of argument usage:
>> Information# ipsec
Lists all currently logged in users for all VPNs.
>> Information# ipsec 2
Lists all users currently logged in to VPN 2.
>> Information# ipsec 2 s*
Lists all users currently logged in to VPN 2, whose user tunnel profile name begins with the letter "s ".
>> Information# ipsec 2 staff
Lists users currently logged in to VPN 2, whose user tunnel profile name is exactly "staff ".
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 29
Menu Summary 29
Table 5 Information Menu Options (/info) (cont’d.)
Command Syntax and Usage
For a sample screen output, see “info/ipsec Ipsec Command” (page 35).
Note: This command is not available if the VPN Gateway software runs on the ASA 310 or ASA 410 hardware platforms.
botuns <VPN ID> <prefix>
Shows the number of active branch office tunnel sessions for all VPNs. The information includes branch office tunnel profile name, the NVG host from which the tunnel is set up, the tunnel state, encrypted/decrypted data in kBytes and session length.
Examples of argument usage:
>> Information# botuns
Lists all currently active branch office tunnels for all VPNs.
>> Information# botuns 2
Lists all currently active branch office tunnels for VPN 2.
>> Information# botuns 2 d*
Lists all currently active branch office tunnels for VPN 2, whose tunnel profile name begins with the letter "d ".
>> Information# botuns 2 denver
Lists all currently active branch office tunnels for VPN 2, whose tunnel profile name is exactly "denver ".
For a sample screen output, see “info/botuns Botuns Command” (page
35).
ippool <VPN ID>
Shows IP pool allocations per IP pool and VPN. The information includes configured IP address range, free IP addresses or ranges and currently allocated IP addresses. It also shows which VPN Gateway (iSD) that owns the IP address.
Examples of argument usage:
>> Information# ippool
Shows IP pool allocations for all VPNs.
>> Information# ippool 2
Shows IP pool allocations for VPN
2.
For a sample screen output, see “info/ippool Ippool Command” (page
36).
ip <IP address>
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 30
30 Command Reference
Table 5 Information Menu Options (/info) (cont’d.)
Command Syntax and Usage
Finds information about a specific IP address allocated from the IP address pool. The information includes the VPN Gateway that owns the IP address, to which VPN the remote user has connected, user name, actual source IP, login time, user groups to which the user belongs, source IP allocated from IP pool and user profile information (access method, source IP, authentication server, client certificate present, Nortel IE cache wiper running, Tunnel Guard activated, domain).
For a sample screen output, see “info/ip Ip Command” (page 37).
sys
Displays information about the current system configuration, for example network mask, default gateway address, static routes, NTP servers, DNS servers, syslog servers, networks, number of VPN Gateways included in the cluster along with IP addresses etc.
sonmp
Displays information about the current network topology, if SONMP participation is enabled (using the /cfg/sys/adm/sonmp command).
For a sample screen output, see “/info/sonmp Sonmp Command” (page
38).
licenses <VPN ID>
Shows information about the license pool and current usage per VPN and license type.
To limit the presentation to a specific VPN, enter the desired VPN ID following the command.
Example:
>> Information# licenses 2
For a sample screen output, see “/info/licenses Licenses Command”
(page 39).
access <VPN ID> <user name>
By specifying a VPN number and a user name following the access command, a detailed view of a logged in user’s access rights is displayed. The information is presented in a table showing the user’s access rights to specific networks, ports, protocols and paths.
kick <VPN ID> <user name>
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 31
Menu Summary 31
Table 5 Information Menu Options (/info) (cont’d.)
Command Syntax and Usage
By specifying the desired VPN number and a user name following the kick command, a user can be logged out from a VPN session by the operator.
To log out multiple users, for example selected users or a range of users, enter an asterisk when prompted for user name. Currently logged in users are displayed in list format with an index number. Enter the index numbers corresponding to the users you wish to log out.
Example: To log out users corresponding to index numbers 1-3 and 5, enter
1-3, 5.
isdlist
Displays the IP addresses, master/slave assignments, CPU usage, memory usage, and operational status for all the VPN Gateways in the cluster. An asterisk (*) in the MIP column indicates which VPN Gateway in the cluster is currently is control of the Management IP. An asterisk (*) in the Local column indicates the particular VPN Gateway to which you have connected.
For a sample screen output, see “/info/isdlist iSD List Command”
(page 40).
local
Displays the current software version, hardware platform, up time (since last boot), IP address, and Ethernet MAC address for the particular VPN Gateway to which you have connected. If you have connected to the MIP address, the information displayed relates to the VPN Gateway in the cluster that currently is in control of the MIP.
For a sample screen output, see “/info/local Information Local
Command” (page 40).
ethernet
Displays statistics for the Ethernet network interface card (NIC) on the particular VPN Gateway to which you have connected. If you have connected to the MIP address, the information displayed relates to the VPN Gateway in the cluster that currently is in control of the MIP. If more than one network is configured in the cluster, ethernet statistics for the respective network is displayed.
• RX packets: the total number of received packets
• TX packets: the total number of transmitted packets
• errors: packets lost due to error
• dropped: error due to lack of resources
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 32
32 Command Reference
Table 5 Information Menu Options (/info) (cont’d.)
Command Syntax and Usage
• overruns: error due to lack of resources
•
frame: error due to malformed packets
•
carrier: error due to lack of carrier
•
collisions: number of packet collisions
• RX bytes: received packets in bytes
•
TX packets: transmitted packets in bytes
For a sample screen output, see “/info/ethernet Information Ethernet
Command” (page 40).
Note: A non-zero collision value may indicate an incorrect configuration of the Ethernet autonegotiation. For more information, see the autoneg command on "autoneg on|off" (page 432) .
ports
Displays the status of the physical ports on the Ethernet network interface card (NIC) on the particular VPN Gateway to which you have connected. If you have connected to the MIP address, the information displayed relates to the VPN Gateway in the cluster that currently is in control of the MIP.
For each port, link status (up/down) and the Ethernet autonegotiation setting (on/off) is shown. If the link is up, current values for speed (10/100/1000) and duplex mode (half/full) are also shown. If the link is down and autonegotiation is set to off, the configured values for speed and duplex mode are shown instead.
To change the NIC port settings, see the commands under .
id
Shows user name and groups for the currently logged in administrator user. The primary purpose of the command is to verify the group assignment when using RADIUS authorization of CLI/BBI users (see the /cfg/sys/adm/auth/group command on
“/cfg/sys/adm/auth/group RADIUS Group Attribute Configuration” (page 455)).
events
Displays the Events menu. To view menu options, see “/info/events
Events Menu” (page 33).
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 33
info/users Users Command 33
/info/events Events Menu
[Events Menu] alarms - List all pending alarms download - Dump the event log file to a TFTP/FTP/SFTP server
The Events menu is used for viewing active alarms and events that have been logged.
Table 6 Events Menu Options (/info/events)
Command Syntax and Usage
alarms
Displays all alarms in the active alarm list by their main attributes: severity level, alarm ID number, date and time when triggered, alarm name, sender, and cause.
To alert the operator at system login, a notice is displayed if there are active alarms.
Alarms are also sent as syslog messages.
download <method (TFTP/FTP/SFTP)> <host name or IP address> <file name on host>
Transmits the event log file from the NVG cluster to a file on a TFTP/FTP/SFTP server. You need to specify the IP address or host name of the server, as well as a file name.
The default value is tftp.
/info/hsm HSM Command
>> Information# hsm iSD IP 192.168.128.185:
Mode: Extended HSM card 0: Logged in as HSM-USER HSM card 1: Logged in as HSM-USER
The output shows status information related to the HSM cards on each NVG device in the cluster. Information about the current security mode (Extended mode or FIPS mode) is displayed, as well as current login status and login user information (HSM-SO or HSM-USER).
info/users Users Command
>>Main #/info/users
Number of currently logged in users:1
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 34
34 Command Reference
VPN ID User Login SourceIP Access Group:Profile:Users
1 john 05:46 47.102.177.57
134.177.220.2 9
ssl trusted:nortel
trusted:<base>
domain="vmdomain"
The output shows VPN ID, name of logged in Portal user, login time, source IP per access method ( SSL, IPsec or Net Direct), host IP (of the NVG to which the user is connected), access method ( SSL, IPsec or Net Direct), group membership, profile, and current owner of the session (User currently logged into the NVG cluster). The <base> profile refers to data configured directly under the Group menu. Any other profile stated after the group name is an
extended profile. For more information about base profiles and extended profiles, see the "Groups, Access Rules and Profiles" chapter in the Application Guide for VPN.
If values are retrieved from LDAP or RADIUS authentication servers through variables, the variable name and the retrieved value is also displayed. For more information about LDAP and RADIUS variables, see
“/cfg/vpn <id> /aaa/auth <id> /ldap/ldapmacro LDAP Macro Configuration” (page 199) and “/cfg/vpn <id> /aaa/auth <id> /radius/macro RADIUS Macro Configuration” (page 188) respectively.
If Tunnel Guard is enabled, if the user failed the Tunnel Guard check and if the variables <var:tgFailureReason> and/or <var:tgFailureDetail> have values configured, these values are printed as a result of the Tunnel Guard check. Note that the
<var:tgFailureDetail> variable is not expanded if the /cfg/vpn #/aaa/tg/details command is set to off. You can read more about
these variables in the section “Variables” (page 22).
info/idleusers Idleusers Command
>> Information# idleusers Number of users idle more than 30s: 2 VPN Id User Login Active Source IP Access...
------ ---- ----- ------ --------- --------­1 lisa 13:13 13:15 192.168.128.19 ssl 2 john 13:28 13:39 192.168.128.31 ssl
The output shows VPN ID, user name, login time, last time active, source IP address and access method.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 35
info/botuns Botuns Command 35
info/ipsec Ipsec Command
>> Information#ipsec
Number of active ipsec user sessions for all VPNs: 1
------ VPN Number: ’1’ ------
User: TunProf IP Inner/OuterEnc (Kb) Dec (kB) Time
john vpn_1_1 10.1.82.148
/192.168.12
8.19
0 0 0:01:55
The output shows the user name of the IPsec user and the user tunnel profile, the inner IP address (i.e. the IP address allocated from the IP pool/RADIUS for the unencrypted connection between the VPN Gateway and the destination host), the outer IP address (i.e. the IP address from which the remote user connects to the VPN Gateway), encrypted data in kBytes and decrypted data in kBytes. The output also shows the time the tunnel has been active (hours:minutes:seconds).
info/botuns Botuns Command
>> Informatio n# botuns
Number of enabled BO tunnels for all VPNs: 3
------ VPN Number: ’1’ ------
Number of enabled BO tunnels: 1
Number of BO tunnels in state:
down:1 phase1:0 up:0
BotunProf At host State Enc (KB) Dec (KB) Time
denver(1) 1 down 0 0 07:04:36
----- VPN Number: ’2’ -----
Number of enabled BO tunnels: 2
Number of BO tunnels in state:
down:0 phase1:0 up:1
BotunProf At host State Enc (KB) Dec (KB) Time
austin(2) 1 down 0 0 00:00:05
dallas(1) 2 up 143 138 09:01:25
------ VPN Number: ’3’ ------
Number of enabled BO tunnels: 0
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 36
36 Command Reference
Number of BO tunnels in state
down:0 phase1:0 up:0
BotunProf At host State Enc (KB) Dec (KB) Time
------ VPN Number: ’4’ ------
Number of enabled BO tunnels: 0
Number of BO tunnels in state
down:0 phase1:0 up:0
The output shows the name of the branch office tunnel profile, the NVG host from which the tunnel is set up, the tunnel state (up, phase1 or down), encrypted data in kBytes and decrypted data in kBytes. The up tunnel state means that both ISAKMP and IPsec SAs are established, whereas the phase1 state indicates that only the ISAKMP SA is established).
The output also shows the time the tunnel has been active (hours:minutes:seconds).
info/ippool Ippool Command
>> information ippool
*** Pool ’1’ for ’VPN 2’
type = local
proxyarp= on
hostroute= false
range= 2.2.2.2.-2.2.2.100
free=
2.2.2.2
2.2.2.3
2.2.2.4
2.2.2.5
2.2.2.6
2.2.2.7
2.2.2.8
2.2.2.9
2.2.2.10
2.2.2.11
2.2.2.12
2.2.2.13
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 37
info/ip Ip Command 37
2.2.2.14
2.2.2.15
2.2.2.16
franges=
10.1.82.102-10.1.82.149
alloc = (2 allocated IP addresses)
’isd@a10-1-82-200’ has 10.1.82.100
’isd@a10-1-82-205’ has 10.1.82.101
The output shows IP pool information per IP pool and VPN. The information includes configured IP address range, free IP addresses or ranges and currently allocated IP addresses. It also shows which VPN Gateway (iSD) that owns the IP address.
An IP address from the IP pool is allocated as source IP address to unencrypted connections between the VPN Gateway and the requested destination when the remote user connects to the VPN Gateway through the Net Direct client or the Nortel IPsec VPN client (formerly the Contivity VPN client).
info/ip Ip Command
>> Information# ip
Enter IP to search for: 10.1.82.148 IP 10.1.82.148 allocated at ’isd@a10-1-82-145’ by ipsec at node
’isd@a10-1-82-145’ (VPNid = ’1’)
--- Node ’isd@a10-1-82-145’ --­VPN: ’1’ User: john Src IP: 192.168.128.19 Login: 10:24 Groups: trusted
staff
Src: ipsec 10.1.82.148 Groups: trusted
staff
Prof: Access: ipsec
SrcIp: 192.168.128.19
AuthSrv: local
ClientCert: false
IE Wiper: false TunnelGuard: false Domain:
The output shows information about the VPN Gateway that owns the IP address, to which VPN the remote user has connected, user name, actual source IP, login time, user groups to which the user belongs, source IP
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 38
38 Command Reference
allocated from IP pool and user profile information (access method, source IP, authentication server, client certificate present, Nortel IE cache wiper running, Tunnel Guard activated, domain).
/info/sonmp Sonmp Command
>> Information# sonmp
Slot IP address Seg MAC address Chassis Type Local State Port Id Seg
---- ----------- --- ----------------- ------------ ----- ----­0/0 10.1.82.145 0 00:07:e9:13:a6:dd NnVPNGw3070 true heartbeat 1/1 10.1.0.10 303 00:09:97:f3:b4:aa ERS5510-48T true heartbeat 1/1 10.1.82.2 275 00:80:2d:7e:ab:ea BayStack450 true new
The table lists all SONMP-aware Network Management Modules (NMMs) on the same network as the reporting NMM (the VPN Gateway). A table entry is created when a topology message is sent from a "new" NMM. An entry is removed when no topology messages are received from the NMM within a specified time interval.
Slot The slot (on the port) on which the topology message was
received. The reporting agent’s row has slot number equal to zero (see top row in the preceding example).
Port The port on which the topology message was received. The
reporting agent’s row has port number equal to zero (see top row in the preceding example).
IP address IP address of the interface on which the topology message was
received. Seg Id Identifies the network segment in the NMM
from which the topology message was sent. MAC address The MAC address of the NMM sending the topology message. Chassis Type The chassis type (product name) of the NMM sending the
topology message. Local Seg Indicates whether or not the NMM is located on the same
network segment (local) as the reporting NMM or across a
bridge. State Indicates the state of the NMM. Available values are
topChanged (topology value has recently changed),
heartbeat (topology information unchanged and new
(sending agent is in new state).
Note: Only the NMM topology table is tracked, not the bridge topology
table.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 39
/info/licenses Licenses Command 39
/info/licenses Licenses Command
>> Information# licenses
Global License Pools
VPN Used Size
------------------------------------------------------------------------------------------------------------------------------
-------------
SSL - 0 50
SSL 1 1 20
SSL 2 3 30
IPSEC - 020
Vdesk 1 3 25
SPIKE 2 1 10
License usage per VPN Used
---------------------------------------------------------------------------------------------------------------------------------
-------------
SSL 1 0
SSL 2 3
SSL 3 0
IPSEC 1 0
IPSEC 2 2
IPSEC 3 0
Vdesk 1 0
Vdesk 2 0
Vdesk 3 0
Vdesk 4 3
SPIKE 1 1
SPIKE 2 0
The output shows logged in VPN users (under Used) and allowed number of concurrent VPN users in the cluster (under Size). The number is presented for each license type (i.e. SSL and IPsec) and if the Secure Service Partitioning feature is used for each VPN.
In the preceding example, a 100 user SSL license is loaded to the cluster. The top table’s Size column shows how the administrator has set a limit of 20 concurrent users for VPN no 1 and 30 to VPN no 2. The remaining 50 are not allocated and thus available to other VPNs in the cluster. Only the VPNs with a configured license allocation are included in this table.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 40
40 Command Reference
The bottom table which includes all VPNs shows license usage per VPN and license type. The preceding example reveals that a third VPN exists in the cluster and that 22 remote users belonging to that VPN are currently logged in.
/info/isdlist iSD List Command
>> Information# isdlist IP addr type MIP Local cpu(%) mem(%) op
192.168.128.122 master * 4 14 up
192.168.128.123 master * 4 14 up
192.168.128.124 master 4 14 up
192.168.128.125 slave down
The output shows the IP addresses, master/slave assignments, CPU usage, memory usage, and operational status for all the VPN Gateways in the cluster. An asterisk (*) in the MIP column indicates which VPN Gateway in the cluster is currently is control of the Management IP. An asterisk (*) in the Local column indicates the particular VPN Gateway to which you have connected.
/info/local Information Local Command
>> Information# local Alteon iSD SSL Hardware platform: 3070 Software version 7.0.1 Up time: 5 days 21 hours 40 minutes IP address: 192.168.128.185 MAC address: 00:01:02:b1:25:c0
The output shows the current software version, hardware platform, up time (since last boot), IP address, and Ethernet MAC address for the particular VPN Gateway to which you have connected. If you have connected to the MIP address, the information displayed relates to the VPN Gateway in the cluster that currently is in control of the MIP.
/info/ethernet Information Ethernet Command
>> Information# ethernet Net 1: RX packets:2618 errors:0 dropped:0 overruns:1 frame:0 Net 1: TX packets:221 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 Net 1: RX bytes:192038 (187.5 Kb) TX bytes:13298 (12.9 Kb)
The output shows statistics for the Ethernet network interface card (NIC) on the particular VPN Gateway to which you have connected. If you have connected to the MIP address, the information displayed relates to the
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 41
/info/ethernet Information Ethernet Command 41
VPN Gateway in the cluster that currently is in control of the MIP. If more than one network is configured in the cluster, ethernet statistics for the respective network is displayed.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 42
42 Command Reference
/stats Statistics Menu
The Statistics menu is used for accessing performance statistics for the VPN Gateway software’s main features.
[Statistics Menu] sslstats - SSL stats ipsec- IPsec stats aaa - AAA specific statistics dump - Dump all information
Table 7 Statistics Menu Options (/stats)
Command Syntax and Usage
sslstats
Displays the SSL statistics menu. To view menu options, see
“/stats/sslstats SSL Statistics Menu” (page 42).
ipsec
Displays the IPsec statistics menu. To view menu options, see
“/stats/ipsec IPsec Statistics Menu” (page 63).
Note: This command is not available if the VPN Gateway software is run on the ASA 310 or ASA 410 hardware platforms.
aaa
Displays the AAA statistics menu. To view menu options, see
“/stats/aaa AAA Statistics Menu” (page 78).
dump
Displays cluster-wide SSL statistics for each virtual SSL server in the cluster, as well as the number of active request sessions, and the total number of completed request sessions. The total number of initiated SSL client connections, and the total number of established SSL client connections as accumulated values for all virtual SSL servers in the cluster are also displayed. Histograms, however, are not included in the output.
/stats/sslstats SSL Statistics Menu
[SSL Statistics Menu] vpn - Cluster SSL VPN statistics server - Cluster SSL Server statistics local- Local statistics for each isdhost clear- Clear all statistics for all IPs activesess - Number of currently active request sessions totalsess - Total completed request sessions sslaccept - Total completed SSL accept sslconnect - Total completed SSL connect
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 43
/stats/sslstats SSL Statistics Menu 43
tpshisto - Cluster-wide TPS histograms for all servers clihisto - Cluster wide client data histograms for all servers srvhisto - Cluster wide server data histograms for all servers
The SSL Statistics menu is used for viewing various statistics relating to SSL sessions.
Table 8 SSL Statistics Menu Options (/stats/sslstats)
Command Syntax and Usage
vpn
Displays the Cluster Wide SSL Statistics menu for the specified VPN (i.e. the portal server of that domain). To view menu options, see
“/stats/sslstats/vpn <number> Cluster Wide SSL Statistics for VPN Menu” (page 47).
server <virtual SSL server number>
Displays the Cluster Wide SSL Statistics menu for the specified virtual SSL server (i.e. servers configured under /cfg/ssl).
Press TAB following this command to view the numbers of configured servers.
To view menu options, see “/stats/sslstats/server <number>
Cluster Wide SSL Statistics for Server Menu” (page 50).
local
Displays the Local Statistics menu. To view menu options, see
“/stats/sslstats/local Local SSL Statistics Menu” (page 53).
clear
Resets all statistics to zero.
activesess
Displays the number of currently active request sessions in the cluster.
totalsess
Displays the total number of completed request sessions in the cluster.
sslaccept
Displays the total number of initiated SSL client connections on all virtual SSL servers in the cluster.
sslconnect
Displays the total number of established SSL client connections on all virtual SSL servers in the cluster.
tpshisto
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 44
44 Command Reference
Table 8 SSL Statistics Menu Options (/stats/sslstats) (cont’d.)
Command Syntax and Usage
Displays histograms of the number of SSL transactions per second, as performed by each virtual SSL server in the cluster. The figures presented are accumulated from all NVG devices in the cluster.
For a sample screen output, see “/stats/sslstats/tpshisto
Cluster-Wide TPS Histogram for All Servers” (page 44).
clihisto
Displays histograms of data throughput in bytes per second from clients to each virtual SSL server in the cluster. The figures presented are accumulated from all NVG devices in the cluster.
For a sample screen output, see “/stats/sslstats/clihisto
Cluster-Wide Client Data Throughput Histogram for All Servers” (page
45).
srvhisto
Displays histograms of data throughput in bytes per second from backend servers to each virtual SSL server in the cluster. The figures presented are accumulated from all NVG devices in the cluster.
For a sample screen output, see “/stats/sslstats/srvhisto
Cluster-Wide Server Data Throughput Histogram for All Servers” (page
46).
/stats/sslstats/tpshisto Cluster-Wide TPS Histogram for All Servers
Cluster wide histograms for all Servers
10.1.82.146:443 Histogram SSL tps (last 60 secs) sec(0) 0 0000000 sec(8) 0 0000000 sec(16) 00000000 sec(24) 00000000 sec(32) 00000000 sec(40) 00000000 sec(48) 00000000 sec(56) 0000
10.1.82.146:443 Histogram medium tps (last 60 mins) min(0) 0 0000000 min(8) 0 0000000 min(16) 00000000 min(24) 00000000 min(32) 00000000 min(40) 00000000
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 45
/stats/sslstats/clihisto Cluster-Wide Client Data Throughput Histogram for All Servers 45
min(48) 00000000 min(56) 0000
10.1.82.146:443 Histogram medium tps (last 24 hours) hour(0) 00000000 hour(8) 00000000 hour(16) 0 0 0 00000
10.1.82.146:443 Histogram medium tps (last 31 days) day(0) 0 0000000 day(8) 0 0000000 day(16) 00000000 day(24) 0000000
The output shows the number of SSL transactions per second, as performed by each virtual SSL server in the cluster of VPN Gateways. It is divided in the following sections per virtual SSL server:
•
SSL transactions per each of the last 60 seconds.
• Average number of transactions per second during the last 60 minutes.
•
Average number of transactions per second during the last 24 hours.
•
Average number of transactions per second during the last 31 days.
/stats/sslstats/clihisto Cluster-Wide Client Data Throughput Histogram for All Servers
Cluster wide histograms for all Servers
10.1.82.146:443 Histogram client data byte/s (last 60 secs) sec(0) 0 0 0 00000 sec(8) 0 0 0 00000 sec(16) 0 0 0 0 0 0 0 0 sec(24) 0 0 0 0 0 0 0 0 sec(32) 0 0 0 0 0 0 0 0 sec(40) 0 0 0 0 0 0 0 501 sec(48) 0 0 0 0 0 0 0 0 sec(56) 0 0 0 0
10.1.82.146:443 Histogram medium client data byte/s (last 60 mins) min(0) 8 2131 1052 0 0 0 0 0 min(8) 0 0 0 00000 min(16) 0 0 0 0 0 0 0 0 min(24) 0 0 0 0 0 0 0 0 min(32) 0 0 0 0 0 0 0 0 min(40) 0 0 0 0 0 0 0 0 min(48) 0 0 21 0 0 0 0 0 min(56) 0 0 0 0
10.1.82.146:443 Histogram medium client data byte/s (last 24 hours) hour(0) 0 0 0 0 0 0 0 0 hour(8) 0 0 0 0 0 0 0 0 hour(16) 0 0 000000
10.1.82.146:443 Histogram medium client data byte/s (last 31 days)
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 46
46 Command Reference
day(0) 0 0 2 00000 day(8) 0 0 0 00000 day(16) 0 0 0 0 0 0 0 0 day(24) 0 0 0 0 0 0 0
The output shows the data throughput in bytes per second from clients to each virtual SSL server in the cluster. It is divided in the following sections per virtual SSL server:
•
Data throughput per each of the last 60 seconds.
• Average data throughput per second during the last 60 minutes.
•
Average data throughput per second during the last 24 hours.
• Average data throughput per second during the last 31 days.
/stats/sslstats/srvhisto Cluster-Wide Server Data Throughput Histogram for All Servers
Cluster wide histograms for all Servers
10.1.82.146:443 Histogram server data byte/s (last 60 secs) sec(0) 0 0 0 00000 sec(8) 0 0 0 00000 sec(16) 0 0 0 0 0 0 0 0 sec(24) 0 0 0 0 0 0 335 0 sec(32) 0 0 0 0 0 0 0 0 sec(40) 0 0 0 0 0 0 0 0 sec(48) 0 0 0 0 0 0 0 0 sec(56) 0 0 0 0
10.1.82.146:443 Histogram medium server data byte/s (last 60 mins) min(0) 5 5 5 55554006 min(8) 7349 0000000 min(16) 0 0 0 0 0 0 0 0 min(24) 0 0 0 0 0 0 0 0 min(32) 0 0 0 0 0 0 0 0 min(40) 0 0 0 0 0 0 0 0 min(48) 0 0 0 0 0 0 0 0 min(56) 321 0 0 0
10.1.82.146:443 Histogram medium server data byte/s (last 24 hours) hour(0) 5 0 0 0 0 0 0 0 hour(8) 0 0 0 0 0 0 0 0 hour(16) 0 0 000000
10.1.82.146:443 Histogram medium server data byte/s (last 31 days) day(0) 0 0 21 0 0 0 0 0 day(8) 0 0 0 00000 day(16) 0 0 0 0 0 0 0 0 day(24) 0 0 0 0 0 0 0
The output shows the data throughput in bytes per second from backend servers to each virtual SSL server in the cluster. It is divided in the following sections per virtual SSL server:
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 47
/stats/sslstats/vpn <number> Cluster Wide SSL Statistics for VPN Menu 47
• Data throughput per each of the last 60 seconds.
• Average data throughput per second during the last 60 minutes.
• Average data throughput per second during the last 24 hours.
•
Average data throughput per second during the last 31 days.
/stats/sslstats/vpn <number> Cluster Wide SSL Statistics for VPN Menu
[Cluster wide SSL Stats for VPN 1 Menu]
accept - SSL accept
renegotiat - SSL renegotiate requests
handshakeg - SSL handshakes completed
cachemisse - SSL cache misses
cachetimeo - SSL cache timeout
cachefull - SSL cache full
cachehits - SSL cache hits
sslconnect - SSL connects
evocation - Client cert revocations
cipherrewr - HTTP weak cipher rewrites
http_redir - HTTP redirect rewrites
becnctfail - Failed back end server connects
tps - SSL transactions/sec
tpshisto - Cluster wide TPS histograms for this VPN
clihisto - Cluster wide client byte/s histos for this
VPN
srvhisto - Cluster wide server data byte/s histos for
this VPN
dump - Print all states except histograms
The Cluster Wide SSL Statistics for VPN menu is used for viewing various statistics for a specific VPN, specified by its ID. The figures presented are accumulated from all NVG devices in the cluster, but specific for the selected VPN.
Table 9 Cluster Wide SSL Statistics for VPN Menu Options (/stats/sslstats/vpn)
Command Syntax and Usage
accept
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 48
48 Command Reference
Table 9 Cluster Wide SSL Statistics for VPN Menu Options (/stats/sslstats/vpn) (cont’d.)
Command Syntax and Usage
Displays the number of initiated SSL client connections for the current virtual VPN.
renegotiat
Displays the number of times clients have requested a renegotiation of the SSL connection for the current VPN.
handshakeg
Displays the number of successfully completed SSL handshakes for the current VPN.
The number of failed SSL handshakes equals the combined values for SSL accept and SSL renegotiate requests, minus the combined values for SSL handshakes completed and Number of currently active request sessions.
You can view the values mentioned above by using the/stats/dump command.
cachemisse
Displays the number of times clients have made requests to reuse a particular session ID, and that session ID was not found in the SSL cache.
If there is a high number of cache misses in combination with a high value for cachefull, you may consider increasing the SSL cache size of the virtual SSL server. To change the current SSL cache size, use the /cfg/vpn #/server/ssl/cachesize command. The default SSL cache size is 4000 items.
If there is a high number of cache misses in combination with a low value for cachefull, you may consider increasing the cachettl value. To change the current cachettl value, use the /cfg/vpn #/server/ssl/cachettl command.
The default SSL cache timeout value is 5 minutes.
cachetimeo
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 49
/stats/sslstats/vpn <number> Cluster Wide SSL Statistics for VPN Menu 49
Table 9 Cluster Wide SSL Statistics for VPN Menu Options (/stats/sslstats/vpn) (cont’d.)
Command Syntax and Usage
Displays the number of reuse attempts on SSL sessions still in the cache, and whose timeouts were initiated.
If there is a high number of cache timeouts, you may consider increasing the cachettl value for the virtual SSL server using the /cfg/vpn #/server/ssl/cachettl command.
The default SSL cache timeout value is 5 minutes.
cachefull
Displays the number of times when a new client session could not be cached due to the cache being full. If the cachefull value is high, you may consider increasing the SSL cache size of the virtual SSL server.
cachehits
Displays the number of times clients have made requests to reuse a particular session ID, and that session ID was found in the SSL cache.
sslconnect
Displays the number of completed SSL client connections for the current VPN.
revocation
Displays the number of revoked client certificates.
cipherrewr
Displays the number of HTTP weak cipher rewrites.
http_redir
Displays the number of HTTP redirect rewrites.
becnctfail
Displays the number of failed connections to backend servers.
tps
Displays the number of SSL transactions per second for the specified VPN, as performed on all NVG devices in the cluster.
tpshisto
Displays histograms of the number of SSL transactions per second for the specified VPN on all NVG devices in the cluster.
clihisto
Displays histograms of data throughput in bytes per second from clients for the specified VPN, as performed on all NVG devices in the cluster.
srvhisto
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 50
50 Command Reference
Table 9 Cluster Wide SSL Statistics for VPN Menu Options (/stats/sslstats/vpn) (cont’d.)
Command Syntax and Usage
Displays histograms of data throughput in bytes per second from backend servers for the specified VPN, as performed on all NVG devices in the cluster.
dump
Displays all statistics for the VPN, except the histograms.
/stats/sslstats/server <number> Cluster Wide SSL Statistics for Server Menu
[Cluster Wide SSL Stats for Server 1 Menu] accept - SSL accept renegotiat - SSL renegotiate requests handshakeg - SSL handshakes completed cachemisse - SSL cache misses cachetimeo - SSL cache timeout cachefull - SSL cache full cachehits - SSL cache hits sslconnect - SSL connects revocation - Client cert revocations cipherrewr - HTTP weak cipher rewrites http_redir - HTTP redirect rewrites becnctfail - Failed backend server connects tps - SSL transactions/sec tpshisto - Cluster wide TPS histograms for this server clihisto - Cluster wide client byte/s histos for this server srvhisto - Cluster wide server data byte/s histos for this server dump - Print all stats except histograms
The Cluster Wide SSL Statistics Server menu is used for viewing various statistics for a virtual SSL server, specified by its index number. The figures presented are accumulated from all NVG devices in the cluster, but specific for the selected virtual SSL server.
Table 10 Cluster Wide SSL Statistics for Server Menu Options (/stats/sslstats/server)
Command Syntax and Usage
accept
Displays the number of initiated SSL client connections on the current virtual SSL server.
renegotiat
Displays the number of times clients have requested a renegotiation of the SSL connection on the current virtual SSL server.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 51
/stats/sslstats/server <number> Cluster Wide SSL Statistics for Server Menu 51
Table 10 Cluster Wide SSL Statistics for Server Menu Options (/stats/sslstats/server) (cont’d.)
Command Syntax and Usage
handshakeg
Displays the number of successfully completed SSL handshakes on the current virtual SSL server.
The number of failed SSL handshakes equals the combined values for SSL accept and SSL renegotiate requests, minus the combined values for SSL handshakes completed and Number of currently active request sessions.
You can view the values mentioned above by using the/stats/dump command.
cachemisse
Displays the number of times clients have made requests to reuse a particular session ID, and that session ID was not found in the SSL cache.
If there is a high number of cache misses in combination with a high value for cachefull, you may consider increasing the SSL cache size of the virtual SSL server, using the /cfg/ssl /server #/ssl/cachesize command.
The default SSL cache size is 4000 items.
If there is a high number of cache misses in combination with a low value for cachefull, you may consider increasing the cachettl value, using the /cfg/ssl/server #/ssl /cachettl command.
The default SSL cache timeout value is 5 minutes.
cachetimeo
Displays the number of reuse attempts on SSL sessions still in the cache, and whose timeouts were initiated.
If there is a high number of cache timeouts, you may consider increasing the cachettl value for the virtual SSL server, using the /cfg/ssl/server #/ssl/cachettl command.
The default SSL cache timeout value is 5 minutes.
cachefull
Displays the number of times when a new client session could not be cached due to the cache being full. If the cachefull value is high, you may consider increasing the SSL cache size of the virtual SSL server.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 52
52 Command Reference
Table 10 Cluster Wide SSL Statistics for Server Menu Options (/stats/sslstats/server) (cont’d.)
Command Syntax and Usage
cachehits
Displays the number of times clients have made requests to reuse a particular session ID, and that session ID was found in the SSL cache.
sslconnect
Displays the number of completed SSL client connections on the current virtual SSL server.
revocation
Displays the number of revoked client certificates.
cipherrewr
Displays the number of HTTP weak cipher rewrites.
http_redir
Displays the number of HTTP redirect rewrites.
becnctfail
Displays the number of failed connections to backend servers.
tps
Displays the number of SSL transactions per second for the specified virtual SSL server, as performed on all NVG devices in the cluster.
tpshisto
Displays histograms of the number of SSL transactions per second, as performed by the specified virtual SSL server on all NVG devices in the cluster.
clihisto
Displays histograms of data throughput in bytes per second from clients to the specified virtual SSL server, as performed on all NVG devices in the cluster.
srvhisto
Displays histograms of data throughput in bytes per second from backend servers to the specified virtual SSL server, as performed on all NVG devices in the cluster.
dump
Displays all SSL statistics for the current virtual SSL server, except the histograms.
For a sample screen output, see “/stats/sslstats/server
<number> /dump Cluster-Wide SSL Statistics for Server” (page 53).
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 53
/stats/sslstats/local Local SSL Statistics Menu 53
/stats/sslstats/server <number> /dump Cluster-Wide SSL
Statistics for Server
Cluster wide SSL Stats for Server 1001:
10.1.82.146:443 SSL accept = 90
10.1.82.146:443 SSL renegotiate requests = 0
10.1.82.146:443 SSL handshakes completed = 90
10.1.82.146:443 SSL cache misses = 9
10.1.82.146:443 SSL cache timeout = 1
10.1.82.146:443 SSL cache full = 0
10.1.82.146:443 SSL cache hits = 78
10.1.82.146:443 SSL connects = 0
10.1.82.146:443 Client cert revocations = 0
10.1.82.146:443 HTTP weak cipher rewrites = 0
10.1.82.146:443 HTTP redirect rewrites = 2
10.1.82.146:443 Failed backend server connects = 0
10.1.82.146:443 SSL transactions/sec = 0
The output shows all SSL statistics for the current virtual SSL server, except the histograms.
/stats/sslstats/local Local SSL Statistics Menu
[Local SSL Statistics Menu]
isdhost - ISD local SSL server statistics menu
overview - Overview of isdhost local statistics
tpshisto
- ISD local TPS histograms for all servers/ISDs
clihisto - ISD local client byte/s histos for all
servers/ISDs
srvhisto - ISD local server data byte/s histos for all
servers/ISDs
license - ISD local license statistics
dump - Dump all information
The Local Statistics menu is used for viewing histograms of SSL transactions per second, received client data and received backend server data (in bytes per second). Values are presented for each virtual SSL server, on a per NVG device basis. You can therefore easily compare the performance of a particular virtual SSL server on different NVG devices in the cluster.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 54
54 Command Reference
The Local Statistics menu is also used for accessing the Single iSD Stats menu, in which you can view the same histograms as in the Local Statistics menu, with the difference that the histograms only pertain to a single NVG device (specified by host index number).
The dump command in the Local Statistics menu displays a number of statistics, where most of them relate to various SSL properties for incoming client connections. These statistics are presented for each virtual SSL server, on a per NVG device basis. Information related to the health check status (of backend servers) and pool status may also be displayed, depending on your virtual SSL server configuration. This information is also displayed on a per NVG device basis, because each NVG performs its own health checking of configured backend servers independently from other NVGs in the cluster.
Histograms are not included in the output when running the dump command.
Table 11 Local Statistics Menu Options (/stats/sslstats/local)
Command Syntax and Usage
isdhost < NVG host by index number (1-256)>
Displays the Single ISD Stats menu, after you have specified the index number of an NVG host in the cluster. To view menu options, see “/stats/sslstats/local/isdhost <number> Single iSD
Statistics Menu” (page 56).
To view information about host index numbers for all NVG hosts in the cluster, use the /cfg/sys/cur command.
overview
Displays the total number of completed request sessions for each virtual SSL server on a per NVG device basis. An overview of the health check status of backend servers and the pool status may also be displayed, depending on your virtual SSL server configuration.
tpshisto
Displays histograms of the number of SSL transactions per second, as performed by each virtual SSL server on a per NVG device basis.
clihisto
Displays histograms of data throughput in bytes per second from clients to each virtual SSL server, on a per NVG device basis.
srvhisto
Displays histograms of data throughput in bytes per second from backend servers to each virtual SSL server, on a per NVG device basis.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 55
/stats/sslstats/local/dump Local SSL Statistics 55
Table 11 Local Statistics Menu Options (/stats/sslstats/local) (cont’d.)
Command Syntax and Usage
license
Displays information about the number of times the tps license has reached the limit.
dump
Displays various SSL statistics for incoming client connections, as well as HTTP-related statistics. The statistics are presented for each virtual SSL server, on a per NVG device basis. Histograms are not included in the output.
For a sample screen output, see “/stats/sslstats/local/dump
Local SSL Statistics” (page 55).
/stats/sslstats/local/dump Local SSL Statistics
Local SSL Statistics: Single ISD SSL Stats 1: Single ISD SSL Stats for Server 1:
10.1.82.146:80 SSL accept = 0
10.1.82.146:80 SSL renegotiate requests = 0
10.1.82.146:80 SSL handshakes completed = 0
10.1.82.146:80 SSL cache misses = 0
10.1.82.146:80 SSL cache timeout = 0
10.1.82.146:80 SSL cache full = 0
10.1.82.146:80 SSL cache hits = 0
10.1.82.146:80 SSL connects = 0
10.1.82.146:80 Client cert revocations = 0
10.1.82.146:80 HTTP weak cipher rewrites = 0
10.1.82.146:80 HTTP redirect rewrites = 0
10.1.82.146:80 Failed backend server connects = 0
10.1.82.146:80 SSL transactions/sec = 0 Single ISD SSL Stats for Server 1001:
10.1.82.146:443 SSL accept = 90
10.1.82.146:443 SSL renegotiate requests = 0
10.1.82.146:443 SSL handshakes completed = 90
10.1.82.146:443 SSL cache misses = 9
10.1.82.146:443 SSL cache timeout = 1
10.1.82.146:443 SSL cache full = 0
10.1.82.146:443 SSL cache hits = 78
10.1.82.146:443 SSL connects = 0
10.1.82.146:443 Client cert revocations = 0
10.1.82.146:443 HTTP weak cipher rewrites = 0
10.1.82.146:443 HTTP redirect rewrites = 2
10.1.82.146:443 Failed backend server connects = 0
10.1.82.146:443 SSL transactions/sec = 0
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 56
56 Command Reference
The output shows all SSL statistics per VPN Gateway, except the histograms. The statistics are presented per virtual SSL server for each VPN Gateway. Histograms are not included in the output.
The sample output above shows two virtual SSL servers. The server with number 1 is a virtual SSL server configured under /cfg/ssl. These servers are numbered from 1 and up. The server with number 1001 is a portal server, configured under /cfg/vpn. Server numbers assigned to portal servers start with 1001.
/stats/sslstats/local/isdhost <number> Single iSD Statistics Menu
[Single ISD SSL Stats 1 Menu
server - ISD local SSL server stats
tpshisto - ISD local TPS histograms for all servers
clihisto - ISD local client byte/s histograms for all servers
srvhisto - ISD local server byte/s histograms for all servers
dump - Dump all information
The Single iSD Statistics menu is used for viewing histograms of SSL transactions per second, received client data, and received backend server data (in bytes per second). Values are presented for each virtual SSL server in the cluster, as performed on a single NVG device (specified by host index number when you enter the Single iSD Statistics menu).
The Single iSD Statistics menu is also used for accessing the Single iSD Stats for Server menu, in which you can view various statistics related to one specific virtual SSL server as performed on the currently selected NVG host.
The dump command in the Single iSD Statistics menu displays a number of statistics where most of them are related to various SSL properties for incoming client connections for each virtual SSL server individually, as performed on the selected individual VPN Gateway. Histograms are not included in the output when running the dump command.
Table 12 Single iSD Statistics Menu Options (/stats/sslstats/local/isdhost)
Command Syntax and Usage
server <virtual SSL server number>
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 57
/stats/sslstats/local/isdhost <number> /server <number> Single ISD SSL Statistics for
Virtual SSL Server Menu 57
Table 12 Single iSD Statistics Menu Options (/stats/sslstats/local/isdhost) (cont’d.)
Command Syntax and Usage
Displays the Single iSD Stats for Server # menu. To view menu options, see “/stats/sslstats/local/isdhost <number>
/server <number> Single ISD SSL Statistics for Virtual SSL Server Menu” (page 57).
tpshisto
Displays histograms of the number of SSL transactions per second for each virtual SSL server, as performed on the currently specified VPN Gateway.
clihisto
Displays histograms of data throughput in bytes per second from clients to each virtual SSL server, as performed on the currently specified VPN Gateway.
srvhisto
Displays histograms of data throughput in bytes per second from backend servers to each virtual SSL server, as performed on the currently specified VPN Gateway.
dump
Displays various SSL properties for incoming client connections, as well as HTTP-related statistics. The statistics are presented for each virtual SSL server in the cluster, but where the figures relate only to the currently specified VPN Gateway. Histograms are not included in the output.
/stats/sslstats/local/isdhost <number> /server <number>
Single ISD SSL Statistics for Virtual SSL Server Menu
[Single ISD SSL Stats for Server 1 Menu] healthchec - Display health check status for all loadbalanced RIPs poolstatus - Pool status and statistics accept - SSL accept renegotiat - SSL renegotiate requests handshakeg - SSL handshakes completed cachemisse - SSL cache misses cachetimeo - SSL cache timeout cachefull - SSL cache full cachehits - SSL cache hits sslconnect - SSL connects revocation - Client cert revocations cipherrewr - HTTP weak cipher rewrites http_redir - HTTP redirect rewrites becnctfail - Failed backend server connects tps - SSL transactions/sec
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 58
58 Command Reference
tpshisto - isdhost local TPS histograms for this server clihisto - isdhost local client byte/s histos for this server srvhisto - isdhost local server data byte/s histos for this server dump - Dump all information
The Single iSD Stats for Server # menu is used for viewing the pool status for backend servers that are load balanced by the specified virtual SSL server. The health check status of backend servers can also be displayed. Remember that each NVG device (or host) performs its own health checks of configured backend servers, which makes the status information unique for the specified VPN Gateway.
Other statistics can also be displayed, such as statistics related to SSL properties for incoming client connections handled by the specified virtual SSL server on the currently selected VPN Gateway. The values are unique for the selected VPN Gateway, because the figures depend on the Nortel Application Switch load balancing configuration of the server group in which the VPN Gateway resides.
The dump command will display all statistics available through the individual commands in the menu, except the health check status, pool status, and histograms.
Table 13 Single iSD Statistics Server Menu Options (/stats/sslstats/local/isdhost/ser ver)
Command Syntax and Usage
healthchec
Displays the health check status for the backend servers that are load balanced by the current virtual SSL server. Because each NVG device (or host) performs its own health checks of configured backend servers, the displayed health check status information is specific not only for the selected virtual SSL server, but also for the selected NVG host.
The following health check properties are displayed:
• BE: Backend servers by index number.
• RIP: Load balanced backend servers listed by IP address and TCP
port.
• UP: Lists the current status of backend servers as up or down,
where backend servers that passed the health check are indicated as up.
• EXEC: Indicates whether a health check is currently being
performed on a backend server.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 59
/stats/sslstats/local/isdhost <number> /server <number> Single ISD SSL Statistics for
Virtual SSL Server Menu 59
Table 13 Single iSD Statistics Server Menu Options (/stats/sslstats/local/isdhost/server) (cont’d.)
Command Syntax and Usage
• FAILS: Indicates the number of times a health check has failed.
For more information about script-based health checks, see the "Script-Based Health Checks" chapter in the
Application Guide for
SSL Acceleration.
• REASON: States the reason, in clear text, for why a health check
failed.
Note 1: If you have enabled load balancing of configured backend servers and set the health check method to none, all backend servers will at all times be considered up. Failed connections to backend servers are still logged (as a total) and can be viewed using the /stats/sslstats/server #/becnctfail command.
Note 2: If you have not added any backend servers to the system configuration, the IP address specified as the Real Server IP (RIP) for the current virtual SSL server is listed under the RIP column. When using the NVG together with an Nortel Application Switch, the RIP typically corresponds to 0.0.0.0. By specifying 0.0.0.0 as the Real Server IP address, the SSL server is instructed to use the destination IP address (in the received packets) when initiating requests sent to the virtual server. Such a RIP configuration ensures that requests initiated by the virtual SSL server always reach the correct Virtual Server IP address (as configured on the Nortel Application Switch), because the destination IP address in the received packets corresponds to the IP address of the virtual server.For a sample screen output, see
“/stats/sslstats/local/isdhost # /server #/healthchec Single iSD Host SSL Server Healthcheck Command” (page 62).
poolstatus
Displays pool status for the backend servers that are load balanced by the current virtual SSL server (where one pool is maintained for each backend server that passed the health check). Because each NVG device (or host) performs its own health checks of configured backend servers, the displayed pool status information is specific not only for the selected virtual SSL server, but also for the selected NVG host.
The following pool status information is displayed:
• BE:Backend servers by index number.
• RIP: Backend servers (listed by IP address), for which a pool is
maintained.
• fds: File Descriptors. The number of server-side sockets that are
currently in the pool.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 60
60 Command Reference
Table 13 Single iSD Statistics Server Menu Options (/stats/sslstats/local/isdhost/server) (cont’d.)
Command Syntax and Usage
• sess: SSL sessions. The number of SSL sessions that are
currently in the pool. A pooled SSL session can be reused when setting up a new server-side socket.
• poolcnct: The number of server-side sockets in the pool that
have been reused.
• !poolcnct: The number of server-side sockets that have been set
up without taking advantage of reusing an existing socket.
Note: If you have not added any backend servers to the system configuration, the IP address specified as the Real Server IP (RIP) for the current virtual SSL server is listed under the RIP column. When using the NVG together with an Nortel Application Switch, the RIP typically corresponds to 0.0.0.0. By specifying 0.0.0.0 as the Real Server IP address, the SSL server is instructed to use the destination IP address (in the received packets) when initiating requests sent to the virtual server. Such a RIP configuration ensures that requests initiated by the virtual SSL server always reach the correct Virtual Server IP address (as configured on the Nortel Application Switch), because the destination IP address in the received packets corresponds to the IP address of the virtual server.For a sample screen output, see
“
/stats/sslstats/local/isdhost # /server #/poolstatus
Single iSD Host SSL Server Poolstatus Command” (page 63).
accept
Displays the number of initiated SSL client connections on the current virtual SSL server.
renegotiat
Displays the number of times clients have requested a renegotiation of the SSL connection on the current virtual SSL server.
handshakeg
Displays the number of successfully completed SSL handshakes on the current virtual SSL server.
To view the number of failed SSL handshakes, use the /stats/dump command. The number of failed SSL handshakes equals the combined values for SSL accept and SSL renegotiate requests, minus the combined values for SSL handshakes completed and the number of currently active request sessions.
cachemisse
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 61
/stats/sslstats/local/isdhost <number> /server <number> Single ISD SSL Statistics for
Virtual SSL Server Menu 61
Table 13 Single iSD Statistics Server Menu Options (/stats/sslstats/local/isdhost/server) (cont’d.)
Command Syntax and Usage
Displays the number of times clients have made requests to reuse a particular session ID, and that session ID was not found in the SSL cache.
If there is a high number of cache misses in combination with a high value for cachefull, you may consider increasing the SSL cache size of the virtual SSL server. To change the current SSL cache size, use the /cfg/ssl/server command, specify the appropriate virtual SSL server by index number, and then type the command ssl/cachesize. The default SSL cache size is 8000 items.
If there is a high number of cache misses in combination with a low value for cachefull, you may consider increasing the cachettl value. To change the current cachettl value, use the /cfg/ssl/server command, specify the appropriate virtual SSL server by index number, and then type the command ssl/cachettl.
The default SSL cache timeout value is 5 minutes.
cachetimeo
Displays the number of reuse attempts on SSL sessions still in the cache, and whose timeouts were initiated.
If there is a high number of cache timeouts, you may consider increasing the cachettl value for the virtual SSL server. To change the current cachettl value, use the /cfg/ssl/server command, specify the appropriate virtual SSL server by index number, and then type the command ssl/cachettl. For more information, see the cachettl command on "cachettl" (page 97) .
The default SSL cache timeout value is 5 minutes.
cachefull
Displays the number of times when a new client session could not be cached due to the cache being full. If the cachefull value is high, you may consider increasing the SSL cache size of the virtual SSL server.
cachehits
Displays the number of times clients have made requests to reuse a particular session ID, and that session ID was found in the SSL cache.
sslconnect
Displays the number of completed SSL client connections on the current virtual SSL server.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 62
62 Command Reference
Table 13 Single iSD Statistics Server Menu Options (/stats/sslstats/local/isdhost/server) (cont’d.)
Command Syntax and Usage
revocation
Displays the number of revoked client certificates.
cipherrewr
Displays the number of HTTP weak cipher rewrites.
http_redir
Displays the number of HTTP redirect rewrites.
becnctfail
Displays the number of failed connections to backend servers.
tps
Displays the number of SSL transactions per second as performed by the specified virtual SSL server on the currently selected VPN Gateway.
tpshisto
Displays histograms of the number of SSL transactions per second for the specified virtual SSL server, as performed on the currently selected VPN Gateway.
clihisto
Displays histograms of data throughput in bytes per second from clients to the specified virtual SSL server, as performed on the currently selected VPN Gateway.
srvhisto
Displays histograms of data throughput in bytes per second from backend servers to the specified virtual SSL server, as performed on the currently selected VPN Gateway.
dump
Displays all statistics for the specified virtual SSL server on the currently selected VPN Gateway, except the health check status, pool status, and histograms.
/stats/sslstats/local/isdhost # /server #/healthchec
Single iSD Host SSL Server Healthcheck Command
>> Single ISD SSL Stats for Server 1# healthchec Healthcheck status at ISD number ’1’ BE RIP UP EXEC FAILS REASON 1 192.168.128.1:80 up no
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 63
/stats/ipsec IPsec Statistics Menu 63
/stats/sslstats/local/isdhost # /server #/poolstatus
Single iSD Host SSL Server Poolstatus Command
>> Single ISD SSL Stats for Server 1# poolstatus Poolstatus at ISD number ’1’ BE RIP fds sess poolcnct !poolcnct 1 192.168.128.1:80 0 0 0 0
/stats/ipsec IPsec Statistics Menu
[IPsec stats Menu]
vpn - Cluster IPsec server statistics
local - Local statistics for each isdhost
clear - Clear allIPsec statistics for all IPs
activesess - Number of currently active IPsec user sessions
totalsess - Total completed IPsecuser sessions
failedsess - Total failed IPsec user sessions
enctot - Total encoded kBytes
dectot - Total decodedkBytes
enc - Encoded user kB/sec last minute
boenc - Encoded BO kB/sec last minute
dec - Decoded User kB/sec last minute
bodec - Decoded kB/seclast minute
sesshisto - Cluster-wide IPsec user session histograms for
all VPNs
enchisto - Cluster-wide IPsec user encrypt histograms for
all VPNs
dechisto - Cluster-wideIPsec user decrypt histograms for
all VPNs
boenchisto - Cluster-wideIPsec BO encrypt histograms for all
VPNs
bodechisto - Cluster-wideIPsec BO decrypt histograms for all
VPNs
The IPsec Statistics menu is used for viewing performance statistics relating to IPsec sessions.
Note: This menu is not available if the VPN Gateway software is run on
the ASA 310 or ASA 410 hardware platforms.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 64
64 Command Reference
Table 14 IPsec Statistics Menu Options (/stats/ipsec)
Command Syntax and Usage
vpn <VPN ID>
Displays the Cluster Wide IPsec Statistics menu for the specified VPN.
Press TAB following this command to view available VPN IDs.
To view menu options see, “/stats/ipsec/vpn <id> Cluster Wide
IPsec Statistics for VPN Menu” (page 66).
local
Displays the Local Statistics menu. To view menu options see,
“/stats/ipsec/local Local IPsec Statistics Menu” (page 69).
clear
Resets all IPsec statistics to zero.
activesess
Displays the number of currently active IPsec user sessions for all VPNs in the cluster.
totalsess
Displays the total number of completed IPsec user sessions for all VPNs in the cluster.
The information includes all sessions since the system was first started or since the statistics were last cleared using the clear command.
failedsess
Displays the number of failed IPsec user sessions for all VPNs in the cluster.
The information includes all sessions since the system was first started or since the statistics were last cleared using the clear command.
enctot
Displays the total number of encoded kBytes for all VPNs in the cluster.
The information includes all sessions since the system was first started or since the statistics were last cleared using the clear command.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 65
/stats/ipsec IPsec Statistics Menu 65
Table 14 IPsec Statistics Menu Options (/stats/ipsec) (cont’d.)
Command Syntax and Usage
dectot
Displays the total number of decoded kBytes for all VPNs in the cluster.
The information includes all sessions since the system was first started or since the statistics were last cleared using the clear command.
enc
Displays the number of encoded kBytes per second during the last minute, for user tunnels in all VPNs in the cluster.
boenc
Displays the number of encoded kBytes per second during the last minute, for branch office tunnels in all VPNs in the cluster.
dec
Displays the number of decoded kBytes per second during the last minute, for user tunnels in all VPNs in the cluster.
bodec
Displays the number of decoded kBytes per second during the last minute, for branch office tunnels in all VPNs in the cluster.
sesshisto
Displays cluster wide IPsec session histograms for all VPNs. The histograms show the average number of sessions per minute, hour and day up to 31 days.
enchisto
Displays cluster wide IPsec encryption histograms for user tunnel sessions in all VPNs. The histograms show the average encryption times in kBytes per second. The information is shown per minute, hour and day up to 31 days.
dechisto
Displays cluster wide IPsec decryption histograms for user tunnel sessions in all VPNs. The histograms show the average decryption times in kBytes per second. The information is shown per minute, hour and day up to 31 days.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 66
66 Command Reference
Table 14 IPsec Statistics Menu Options (/stats/ipsec) (cont’d.)
Command Syntax and Usage
boenchisto
Displays cluster wide IPsec encryption histograms for branch office tunnels in all VPNs. The histograms show the average encryption times in kBytes per second. The information is shown per minute, hour and day up to 31 days.
bodechisto
Displays cluster wide IPsec decryption histograms for branch office tunnels in all VPNs. The histograms show the average decryption times in kBytes per second. The information is shown per minute, hour and day up to 31 days.
/stats/ipsec/vpn <id> Cluster Wide IPsec Statistics for VPN Menu
[Cluster wide IPsec Stats for VPN 1 Menu]
activesess - Number of currently active IPsec user sessions
totalsess - Total completed IPsec user sessions
failedsess - Total failed IPsec user sessions
enctot - Total encrypted kByte
dectot - Total decrypted kBytes
enc - Encrypted user kB/sec last minute
boenc - Encrypted BO kB/sec last minute
dec - Decrypted user kB/sec last minute
bodec - Decrypted BO kB/sec last minute
sesshisto - Cluster wide IPsec user sess histograms for this VPN
enchisto - Cluster wide IPsec user encrypt histogr for this VPN
dechisto - Cluster wide IPsec user decrypt histogr for this VPN
boenchisto - Cluster wide IPsec BO encrypt histograms for this VPN
bodechisto - cluster wide ipsec BO decrypt histograms for this VPN
dump - Print all stats except histograms
The Cluster Wide IPsec Statistics for VPN menu is used for viewing IPsec session statistics for a specific VPN.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 67
/stats/ipsec/vpn <id> Cluster Wide IPsec Statistics for VPN Menu 67
Table 15 Cluster Wide IPsec Statistics for VPN Menu Options (/stats/ipsec/vpn)
Command Syntax and Usage
activesess
Displays the number of currently active IPsec sessions for the selected VPN.
totalsess
Displays the total number of completed IPsec sessions for the selected VPN.
The information includes all sessions since the system was first started or since the statistics were last cleared using the clear command.
failedsess
Displays the number of failed IPsec sessions for the selected VPN.
The information includes all sessions since the system was first started or since the statistics were last cleared using the clear command.
enctot
Displays the total number of encoded kBytes for the selected VPN.
The information includes all sessions since the system was first started or since the statistics were last cleared using the clear command.
dectot
Displays the total number of decoded kBytes for the selected VPN.
The information includes all sessions since the system was first started or since the statistics were last cleared using the clear command.
enc
Displays the number of encoded kBytes per second during the last minute, for user sessions in the selected VPN.
boenc
Displays the number of encoded kBytes per second during the last minute, for branch office tunnel sessions in the selected VPN.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 68
68 Command Reference
Table 15 Cluster Wide IPsec Statistics for VPN Menu Options (/stats/ipsec/vpn) (cont’d.)
Command Syntax and Usage
dec
Displays the number of decoded kBytes per second during the last minute, for user sessions in the selected VPN.
bodec
Displays the number of decoded kBytes per second during the last minute, for branch office tunnel sessions in the selected VPN.
sesshisto
Displays cluster wide IPsec user session histograms for the selected VPN. The histograms show the average number of sessions per minute, hour and day up to 31 days.
enchisto
Displays cluster wide IPsec encryption histograms for user sessions in the selected VPN. The histograms show the average encryption times in kBytes per second. The information is shown per minute, hour and day up to 31 days.
dechisto
Displays cluster wide IPsec decryption histograms for user sessions in the selected VPN. The histograms show the average decryption times in kBytes per second. The information is shown per minute, hour and day up to 31 days.
boenchisto
Displays cluster wide IPsec encryption histograms for branch office tunnels in the selected VPN. The histograms show the average encryption times in kBytes per second. The information is shown per minute, hour and day up to 31 days.
bodechisto
Displays cluster wide IPsec decryption histograms for branch office tunnels in the selected VPN. The histograms show the average decryption times in kBytes per second. The information is shown per minute, hour and day up to 31 days.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 69
/stats/ipsec/local Local IPsec Statistics Menu 69
Table 15 Cluster Wide IPsec Statistics for VPN Menu Options (/stats/ipsec/vpn) (cont’d.)
Command Syntax and Usage
dump
Displays all IPsec statistics for the selected VPN, except the histograms.
For a sample screen output, see “/stats/ipsec/vpn <id> /dump
Cluster-Wide IPsec Statistics for VPN” (page 69).
/stats/ipsec/vpn <id> /dump Cluster-Wide IPsec Statistics for VPN
Cluster wide IPsec Stats for VPN 1: VPN(1) Active ipsec user sessions = 0 VPN(1) Total ipsec user sessions = 0 VPN(1) Total failed user sessions = 0 VPN(1) Total encrypted kBytes = 0 VPN(1) Total decrypted kBytes = 0 VPN(1) Encrypt User kB/sec last minute = 0 VPN(1) Encrypt BO kB/sec last minute = 0 VPN(1) Decrypt User kB/sec last minute = 0 VPN(1) Decrypt BO kB/sec last minute = 0
The output shows all IPsec statistics for the selected VPN, except the histograms.
/stats/ipsec/local Local IPsec Statistics Menu
[Local IPsec Statistics Menu]
isdhost - ISD local IPsec server statistics menu
sesshisto - ISD local IPsec user sess histogr for all
VPNs/ISDs
enchisto - ISD local IPsec user encrypt histogr for
all VPNs/ISDs
dechisto - ISD local IPsec user decrypt histogr for
all VPNs/ISDs
boenchisto - ISD local IPsec BO encrypt histogr for
all VPNs/ISDs
bodechisto - ISD local IPsec BO decrypt histogr for
all VPNs/ISDs
dump - Dump all information
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 70
70 Command Reference
The Local IPsec Statistics menu is used for viewing IPsec statistics per VPN Gateway (iSD), if the cluster consists of several devices. For each VPN Gateway, the statistics are shown per VPN. Using the
isdhost
command, you can view statistics for specific VPN Gateways in the cluster.
Table 16 Local IPsec Statistics Menu Options (/stats/ipsec/local)
Command Syntax and Usage
isdhost
Displays the Single ISD Statistics menu where you can view statistic information for a specified VPN Gateway. To view menu options, see “/stats/ipsec/local/isdhost <number> Single iSD IPsec
Statistics Menu” (page 72).
sesshisto
Displays IPsec session histograms for user tunnels per VPN Gateway. The histograms show the average number of sessions per minute, hour and day up to 31 days.
enchisto
Displays IPsec encryption histograms for user tunnels per VPN Gateway. The histograms show the average encryption times in kBytes per second. The information is shown per minute, hour and day up to 31 days.
dechisto
Displays IPsec decryption histograms for user tunnels per VPN Gateway. The histograms show the average decryption times in kBytes per second. The information is shown per minute, hour and day up to 31 days.
boenchisto
Displays IPsec encryption histograms for branch office tunnels per VPN Gateway. The histograms show the average encryption times in kBytes per second. The information is shown per minute, hour and day up to 31 days.
bodechisto
Displays IPsec decryption histograms for branch office tunnels per VPN Gateway. The histograms show the average decryption times in kBytes per second. The information is shown per minute, hour and day up to 31 days.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 71
/stats/ipsec/local/dump Single VPN Gateway IPsec Statistics 71
Table 16 Local IPsec Statistics Menu Options (/stats/ipsec/local) (cont’d.)
Command Syntax and Usage
dump
Displays all IPsec statistics per VPN Gateway and VPN, except the histograms.
For a sample screen output, see “/stats/ipsec/vpn <id> /dump
Cluster-Wide IPsec Statistics for VPN” (page 69).
/stats/ipsec/local/dump Single VPN Gateway IPsec Statistics
Local IPsec Statistics: Single ISD IPSEC Stats 1: ipsec_active_sess: 0 ipsec_total_sess: 0 ipsec_failed_sess: 0 ipsec_total_enc: 0 ipsec_total_dec: 0 ipsec_enc: 0 ipsec_bo_enc: 0 ipsec_dec: 0 ipsec_bo_dec: 0 Single ISD IPSEC Stats for VPN 1: VPN(1) Ipsec active sessions = 0 VPN(1) Ipsec total sessions = 0 VPN(1) Ipsec total failed sessions = 0 VPN(1) Ipsec total encrypted kB = 0 VPN(1) Ipsec total decrypted kB = 0 VPN(1) Ipsec encode kb/sec last minute = 0 VPN(1) Ipsec decode kb/sec last minute = 0 VPN(1) Ipsec decode kb/sec last minute = 0 VPN(1) Ipsec decode kb/sec last minute = 0 Single ISD IPSEC Stats for VPN 2: VPN(2) Ipsec active sessions = 0 VPN(2) Ipsec total sessions = 0 VPN(2) Ipsec total failed sessions = 0 VPN(2) Ipsec total encrypted kB = 0 VPN(2) Ipsec total decrypted kB = 0 VPN(2) Ipsec decode kb/sec last minute = 0 VPN(1) Ipsec decode kb/sec last minute = 0 VPN(1) Ipsec decode kb/sec last minute = 0 VPN(1) Ipsec decode kb/sec last minute = 0
The output shows all IPsec statistics per VPN Gateway and VPN, except the histograms.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 72
72 Command Reference
/stats/ipsec/local/isdhost <number> Single iSD IPsec Statistics Menu
[Single iSD IPsec Stats 1 Menu]
vpn - iSD local IPsec server stats
activesess - Locally active IPsec user sessions, all VPNs
totalsess - Locally total IPsec user sessions, all VPNs
failedsess - Locally failed IPsec user sessions, all VPNs
enctot - Locally total IPsec encoded kBytes all VPNs
dectot - Locally total IPsec decoded kBytes, all VPNs
enc - Locally IPsec user encoded kB/sec last minute, all V
PNs
boenc - Locally IPsec BO encoded kB/sec last minute all VPNs
dec - Locally IPsec user decoded kB/sec last minute, all VPNs
bodec - Locally IPsec BO decoded kB/sec last minute all VPNs
sesshisto - iSD local IPsec user sess histograms for all VPNs
enchisto - iSD local IPsec user encrypt histograms for all VPNs
dechisto - iSD local IPsec user decrypt histograms for all VPNs
boenchisto - ISD local ipsec BO encrypt histograms for all VPNs
bodechisto - ISD local ipsec BO decrypt histograms for all VPNs
dump - Dump all information
The Single ISD IPsec Statistics menu is used for viewing IPsec statistics for a specific VPN Gateway (iSD), i.e. the statistics do not relate to the whole cluster of VPN Gateways. The statistics are shown per VPN.
Table 17 Single ISD IPsec Statistics Menu Options (/stats/ipsec/local/isdhost)
Command Syntax and Usage
vpn
Displays the Single ISD IPsec Statistics for VPN menu. To view menu options, see “/stats/ipsec/local/isdhost <number> /vpn
<id> Single iSD IPsec Statistics for VPN Menu” (page 75).
activesess
Displays the number of currently active IPsec user sessions for the selected VPN Gateway.
totalsess
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 73
/stats/ipsec/local/isdhost <number> Single iSD IPsec Statistics Menu 73
Table 17 Single ISD IPsec Statistics Menu Options (/stats/ipsec/local/isdhost) (cont’d.)
Command Syntax and Usage
Displays the total number of completed IPsec user sessions for the selected VPN Gateway.
The information includes all user sessions since the system was first started or since the statistics were last cleared using the clear command.
failedsess
Displays the number of failed IPsec user sessions for the selected VPN Gateway.
The information includes all user sessions since the system was first started or since the statistics were last cleared using the clear command.
enctot
Displays the total number of encoded kBytes for the selected VPN Gateway.
The information includes all sessions since the system was first started or since the statistics were last cleared using the clear command.
dectot
Displays the total number of decoded kBytes for the selected VPN Gateway.
The information includes all sessions since the system was first started or since the statistics were last cleared using the clear command.
enc
Displays the number of encoded kBytes per second during the last minute, for user tunnels on the selected VPN Gateway.
boenc
Displays the number of encoded kBytes per second during the last minute, for branch office tunnels on the selected VPN Gateway.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 74
74 Command Reference
Table 17 Single ISD IPsec Statistics Menu Options (/stats/ipsec/local/isdhost) (cont’d.)
Command Syntax and Usage
dec
Displays the number of decoded kBytes per second during the last minute, for user tunnels on the selected VPN Gateway.
bodec
Displays the number of decoded kBytes per second during the last minute, for branch office tunnels on the selected VPN Gateway.
sesshisto
Displays IPsec session histograms for the selected VPN Gateway. The histograms show the average number of sessions per minute, hour and day up to 31 days.
enchisto
Displays IPsec encryption histograms for user tunnels in the selected VPN Gateway. The histograms show the average encryption times in kBytes per second. The information is shown per minute, hour and day up to 31 days.
dechisto
Displays IPsec decryption histograms for user tunnels on the selected VPN Gateway. The histograms show the average decryption times in kBytes per second. The information is shown per minute, hour and day up to 31 days.
boenchisto
Displays IPsec encryption histograms for branch office tunnels in the selected VPN Gateway. The histograms show the average encryption times in kBytes per second. The information is shown per minute, hour and day up to 31 days.
bodechisto
Displays IPsec decryption histograms for branch office tunnels on the selected VPN Gateway. The histograms show the average decryption times in kBytes per second. The information is shown per minute, hour and day up to 31 days.
dump
Displays all IPsec statistics for the selected VPN Gateway, except the histograms.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 75
/stats/ipsec/local/isdhost <number> /vpn <id> Single iSD IPsec Statistics for VPN
Menu 75
/stats/ipsec/local/isdhost <number> /vpn <id> Single iSD IPsec Statistics for VPN Menu
[Single ISD IPsecStats for VPN 1 Menu] activesess - Active IPsec sessions totalsess - Total IPsec sessions failedsess - Total failed IPsec sessions enctot - Total IPsec encrypted kBytes dectot - Total IPsec decrypted kBytes enc - IPsec encoded user kB/s last minute boenc - IPsec encodedBO kB/s last minute dec - IPsec decoded user kB/slast minute bodec - IPsec decoded BO kB/s last minute sesshisto - isdhost local IPsec user sessions histogr for this VPN enchisto - isdhost local IPsec user encrypt histogr for this VPN dechisto - isdhost local IPsec user decrypt histogr for this VPN boenchisto - isdhost local IPsec BO encrypt histograms for this VPN bodechisto - isdhost local IPsec BO decrypt histograms for this VPN dump - Dump all information
The Single ISD IPsec Statistics for VPN menu is used for viewing IPsec statistics for a specific VPN on the selected VPN Gateway (iSD).
Table 18 Single ISD IPsec Statistics for VPN Menu Options (/stats/ipsec/local/isdh ost/vpn)
Command Syntax and Usage
activesess
Displays the number of currently active IPsec sessions for the selected VPN Gateway and VPN.
totalsess
Displays the total number of completed IPsec sessions for the selected VPN Gateway and VPN.
The information includes all sessions since the system was first started or since the statistics were last cleared using the clear command.
failedsess
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 76
76 Command Reference
Table 18 Single ISD IPsec Statistics for VPN Menu Options (/stats/ipsec/local/isdhost/vpn) (cont’d.)
Command Syntax and Usage
Displays the number of failed IPsec sessions for the selected VPN Gateway and VPN.
The information includes all sessions since the system was first started or since the statistics were last cleared using the clear command.
enctot
Displays the total number of encoded kBytes for the selected VPN Gateway and VPN.
The information includes all sessions since the system was first started or since the statistics were last cleared using the clear command.
dectot
Displays the total number of decoded kBytes for the selected VPN Gateway and VPN.
The information includes all sessions since the system was first started or since the statistics were last cleared using the clear command.
enc
Displays the number of encoded kBytes per second during the last minute, for user tunnels on the selected VPN Gateway and VPN.
boenc
Displays the number of encoded kBytes per second during the last minute, for branch office tunnels on the selected VPN Gateway and VPN.
dec
Displays the number of decoded kBytes per second during the last minute, for user tunnels on the selected VPN Gateway and VPN.
bodec
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 77
/stats/ipsec/local/isdhost <number> /vpn <id> Single iSD IPsec Statistics for VPN
Menu 77
Table 18 Single ISD IPsec Statistics for VPN Menu Options (/stats/ipsec/local/isdhost/vpn) (cont’d.)
Command Syntax and Usage
Displays the number of decoded kBytes per second during the last minute, for branch office tunnels on the selected VPN Gateway and VPN.
sesshisto
Displays IPsec session histograms for the selected VPN Gateway and VPN.
enchisto
Displays IPsec encryption histograms for user tunnels on the selected VPN Gateway and VPN. The histograms show the average number of sessions per minute, hour and day up to 31 days.
dechisto
Displays IPsec decryption histograms for user tunnels on the selected VPN Gateway and VPN. The histograms show the average decryption times in kBytes per second. The information is shown per minute, hour and day up to 31 days.
boenchisto
Displays IPsec encryption histograms for branch office tunnels on the selected VPN Gateway and VPN. The histograms show the average number of sessions per minute, hour and day up to 31 days.
bodechisto
Displays IPsec decryption histograms for branch office tunnels on the selected VPN Gateway and VPN. The histograms show the average decryption times in kBytes per second. The information is shown per minute, hour and day up to 31 days.
dump
Displays all statistics for the selected VPN Gateway and VPN, except the histograms.
For a sample screen output, see “/stats/ipsec/local/isdhost
<number> /vpn <id> /dump Single VPN Gateway IPsec Statistics for VPN” (page 78).
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 78
78 Command Reference
/stats/ipsec/local/isdhost <number> /vpn <id> /dump
Single VPN Gateway IPsec Statistics for VPN
Single ISD IPSEC Stats for VPN 1: VPN(1) Ipsec active sessions = 0 VPN(1) Ipsec total sessions = 0 VPN(1) Ipsec total failed sessions = 0 VPN(1) Ipsec total encrypted kB = 0 VPN(1) Ipsec total decrypted kB = 0 VPN(1) Ipsec encode kb/sec last minute = 0 VPN(1) Ipsec decode kb/sec last minute = 0
The output shows all IPsec statistics for the selected VPN Gateway and VPN, except the histograms.
/stats/aaa AAA Statistics Menu
[AAA Statistics Menu]
total - Cluster-wide authentication statistics (per VPN)
isdhost - ISD local authentication statistics (per VPN)
dump - Dump all information
The AAA Statistics menu is used for viewing authentication statistics related to the NVG cluster as a whole, or to one specific VPN Gateway in the cluster.
The number of accepted and rejected authentication requests of VPN users are listed for each configured authentication method and authentication server. The remote authentication servers are listed by IP address and TCP port number.
Note that authentication statistics for all servers that are configured in the NVG cluster are displayed, and not only for the servers that are included in the authentication order scheme (by using the /cfg/vpn #/aaa/authorder command). If the statistics for a certain authentication method always comes down to a row with zeroes, this might be due to the fact that the method is not included in the authentication order scheme.
Table 19 AAA Statistics Menu Options (/stats/aaa)
Command Syntax and Usage
total
Displays the total authentication statistics for all VPN Gateways in the cluster since the system was started.
isdhost <host id> <VPN ID>
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 79
/stats/aaa/dump Accept/Reject Statistics per Authentication Method and VPN 79
Table 19 AAA Statistics Menu Options (/stats/aaa) (cont’d.)
Command Syntax and Usage
Displays the authentication statistics for the specified VPN Gateway and VPN.
To view authentication statistics for all VPNs, enter 0 when prompted for VPN ID.
dump
Dumps all authentication statistics in the CLI, i.e. the total statistics and statistics sorted per VPN Gateway.
For a sample screen output, see “/stats/aaa/dump Accept/Reject
Statistics per Authentication Method and VPN” (page 79).
/stats/aaa/dump Accept/Reject Statistics per Authentication Method and VPN
>> AAA Statistics# dump
RADIUS Servers VPN Accepted Rejected Time
Out
192.168.128.1:1 812
1810
10.1.0.10:1812 2600
Local DB VPN Accepted Rejected
------------------------------------------------------------------------------------------------------------------------------------
--------------------------------------------------------------------------------------
100
200
300
473
Licenses VPN Accepted Rejected
------------------------------------------------------------------------------------------------------------------------------------
--------------------------------------------------------------------------------------
SSL 1 0 0
Vdesk 1 0 0
SPIKE 1 0 0
IPSEC 1 0 0
SSL 2 0 0
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 80
80 Command Reference
Vdesk 2 0 0
SPIKE 2 0 0
IPSEC 2 0 0
SSL 3 0 0
Vdesk 3 0 0
SPIKE 3 0 0
IPSEC 3 0 0
The first part of the output shows accepted/rejected connections to configured authentication servers. In the preceding example, VPNs 1 and 2 are both configured with RADIUS authentication, NVG local database authentication and client certificate authentication. Rejections occur for example when the user submits the wrong password. For remote authentication methods (for example RADIUS, LDAP and NTLM), the number of times an authentication request has timed out on a specific server is listed as well.
Under Licenses, the sum of accepted connections are presented per license type and VPN. Authentication server rejections are not included. In the preceding example, for VPN 1, there are 8 accepted connections to the RADIUS server and 4 to the local database. That makes a total of 12 accepted connections. Of those 12 connections, 10 are displayed under Accepted and 2 under Rejected. This means that only 10 concurrent users are allocated to VPN 1. The figure under Rejected refers to connections exceeding the allowed number of concurrent users.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 81
/stats/aaa/dump Accept/Reject Statistics per Authentication Method and VPN 81
/cfg Configuration Menu
The Configuration menu is used for performing SSL and system-wide configuration, as well as for saving and restoring NVG configurations to and from a TFTP, FTP, SCP or SFTP server.
[Configuration Menu]
ssl - SSL offload menu
cert - Certificate menu
vpn - VPN menu
test - Create test vpn,portal and certificate
quick - Quick vpn setup wizard
sys - System-wide parameter menu
lang - Language support
log - logging system menu
ptcfg - Backup configuration to TFTP/FTP/SCP/SFTP server
gtcfg - Restore configuration from TFTP/FTP/SCP/SFTP server
dump - Dump configuration on screen for copy-and-paste
Table 20 Configuration Menu Options (/cfg)
Command Syntax and Usage
ssl
Displays the SSL offload menu. To view menu options, see “/cfg/ssl
SSL Menu” (page 86).
cert <certificate index number>
Displays the Certificate menu, after you have typed the index number of an existing certificate or a new certificate. To view menu options, see
“/cfg/cert <id> Certificate Management Configuration” (page 149).
vpn
Displays the VPN menu. To view menu options, see “/cfg/vpn <id>
VPN Menu” (page 161).
test
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 82
82 Command Reference
Table 20 Configuration Menu Options (/cfg) (cont’d.)
Command Syntax and Usage
Lets you run a wizard for creating a testVPN with the next available VPN ID. You will be prompted the following information:
•
Portal IP address for test portal. Used by the remote user to connect to the VPN.
•
Certificate. If you do not select an existing certificate, the system creates a test certificate with the next available certificate number.
• User name and password for a test user.
•
IPsec. If your hardware model supports IPsec you will also have the option to enable IPsec, configure group authentication (including shared secret) and an IP address range to be used for unencrypted connections between the VPN Gateway and destination hosts. You can read more about IPsec in the "Transparent Mode" chapter in the Application Guide for VPN.
•
Net Direct. Lets you configure the VPN Gateway to allow use with the Net Direct client (SSL VPN client downloadable from Portal). If an IP address range has not yet been configured you will be prompted for this. You can read more about the Net Direct client in the "Net Direct" chapter in the Application Guide for VPN.
The system configures the VPN to use local database authentication, adds the test user to the local database and creates a group called test with access to all networks, services and paths. The test user to is mapped to the test group. An empty linkset called base-links is created and mapped to the test group.
quick
Lets you run a wizard for creating a sharp VPN with the next available VPN ID. You will be prompted the following information:
•
Portal IP address. Used by the remote user to connect to the VPN.
• Name of VPN. Lets you enter a name for the VPN, for example My
VPN.
• VPN used with Alteon switch yes/no. Choose yes if a Nortel
Application Switch (formerly Alteon Application Switch) is connected to the VPN Gateway, otherwise choose no. If set to no, the portal server will be set to standalone mode.
• Which port number the Portal should listen to. The default value is
443 (https).
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 83
/stats/aaa/dump Accept/Reject Statistics per Authentication Method and VPN 83
Table 20 Configuration Menu Options (/cfg) (cont’d.)
Command Syntax and Usage
•
Support for short DNS names. Lets the remote user access hosts in the specified domain by using short names, for example inside instead of inside.example.com.
• Certificate. Lets you use an existing certificate or paste a new
certificate.
•
Chain certificate. Asks whether or not a chain certificate is needed and lets you use an existing certificate as the chain certificate or paste a new chain certificate.
•
HTTP to HTTPS redirect service. Automatically redirects requests made with http to the proper https server configured for the VPN, e.g. http://vpn.example.com gets redirected to
https://vpn.example.com.
• Default services. Creates a number of service definitions that can
later be used to limit access to specific services (for example FTP, HTTP, SMTP etc).
•
Trusted account. User name and password for a test user.
• IPsec. If your hardware model supports IPsec you will also have
the option to enable IPsec for user tunnels, configure group authentication (including shared secret) and an IP address range to be used for unencrypted connections between the VPN Gateway and destination hosts. You can read more about IPsec in the "Transparent Mode" chapter in the
Application Guide for VPN.
• Net Direct. Lets you configure the VPN Gateway to allow use with
the Net Direct client (SSL VPN client downloadable from Portal). If an IP address range has not yet been configured you will be prompted for this. You can read more about the Net Direct client in the "Net Direct" chapter in the Application Guide for VPN.
The system configures the VPN to use local database authentication, adds the test user to the local database and creates a group called trusted with access to all networks, services and paths. The test user to is mapped to the trusted group. An empty linkset called base-links is created and mapped to the trusted group.
sys
Displays the System Configuration menu. To view menu options, see
“/cfg/sys System Configuration” (page 421).
lang
Displays the Language Support menu. To view menu options, see
“/cfg/lang Language Support Configuration” (page 465).
log
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 84
84 Command Reference
Table 20 Configuration Menu Options (/cfg) (cont’d.)
Command Syntax and Usage
A logging system is used to cache the logging information in the internal buffer. This allows network to collect and access the logging information.
ptcfg <method (TFTP/FTP/SCP/SFTP)> <server host name or IP address> <destination file name> <password phrase> <FTP user name and password (if applicable)>
Saves the current configuration, including private keys and certificates, to a TFTP/FTP/SCP/SFTP server. The configuration can later be restored by using the gtcfg command.
You are required to specify a password phrase before the information is sent to the server. If you restore the configuration by using the gtcfg command, you will be prompted for the password phrase you have specified. The password phrase is used to protect the private keys in the configuration.
Note 1: If you have fully separated the Administrator user role from the Certificate Administrator user role, the export passphrase defined by the certificate administrator is used to protect the private keys in the configuration—transparently to the user. When a configuration backup is restored by using the gtcfg command, the certificate administrator must enter the correct passphrase. For more information on separating the Administrator user role from the Certificate Administrator user role, see the "Adding a New User" section in the "Managing Users and Groups" chapter in the
User’s Guide.
Note 2: When using the ptcfg command on an ASA FIPS, private keys are encrypted using the wrap key that was generated when the first HSM card in the cluster was initialized.
gtcfg <method (TFTP/FTP/SCP/SFTP)> <server host name or IP address> <file name> <FTP user name and password (if applicable)> <password phrase>
Restores a configuration, including private keys and certificates, from a TFTP/FTP/SCP/SFTP server. You need to provide the password phrase you specified when saving the configuration to the server.
Note: If you have fully separated the Administrator user role from the Certificate Administrator user role (by removing the admin user from the certadmin group), the certificate administrator must enter the passphrase that he or she defined by using the /cfg/sys/user/caphrase command.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 85
Viewing, Applying and Removing Changes 85
Table 20 Configuration Menu Options (/cfg) (cont’d.)
Command Syntax and Usage
dump
Dumps the current configuration on screen in a format that allows you to restore the configuration without downloading the configuration to a file server. Save the configuration to a text file by performing a copy-and-paste operation to a text editor. The configuration can later be restored by pasting the contents of the saved text file at any command prompt in the command line interface using the global paste command. When pasted, the content is batch processed by the VPN Gateway. To view the pending configuration changes resulting from the batch processing, use the diff command. To apply the configuration changes, use the apply command.
If you choose to include private keys in the configuration dump, you are required to specify a password phrase. The password phrase you specify applies to all private keys. When restoring a configuration that includes private keys, use the global paste command. Before pasting the configuration, you will be prompted for the password phrase you have specified.
Note: When using this command on an ASA FIPS machine, private keys are only displayed for client certificates. For a sample screen output, see “ CLI Dumps” (page 479) ".
Viewing, Applying and Removing Changes
As you use the configuration menus to set NVG parameters, the configuration changes you make do not take effect immediately. All changes are considered "pending" until you explicitly apply them.
While configuration changes are in the pending state, you can do the following:
• View the pending changes
• Apply the pending changes
• Remove the pending changes
Viewing Pending Changes
You can view all pending configuration changes by using the diff command at the menu prompt.
>> # diff
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 86
86 Command Reference
If you have pending configuration changes when using the exit command to log out from the command line interface, you will be prompted to view the pending changes by using the diff command. You can then either apply the changes, or remove them.
Applying Pending Changes
To make your configuration changes active, you must apply them. To apply pending configuration changes, use the apply command at the menu prompt.
>> # apply
Removing Pending Changes
To remove your pending configuration changes before they have been applied, use the revert command at the menu prompt.
>> # revert
Note: The diff, apply and revert commands are global
commands. Therefore, you can enter these commands at any menu prompt in the command line interface.
/cfg/ssl SSL Menu
[SSL Menu] server - SSL server menu test - Create test server and certificate quick- Quick server setup wizard
The SSL menu is used for configuring virtual SSL servers. There are also menu options for creating a test server and a test certificate.
Table 21 SSL Configuration Menu Options (/cfg/ssl)
Command Syntax and Usage
server <virtual SSL server index number>
Displays the Server menu, after you have typed the index number of an existing virtual SSL server or a new server. To view menu options, see
“/cfg/ssl/server <id> SSL Server Configuration” (page 89).
test
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 87
/cfg/ssl SSL Menu 87
Table 21 SSL Configuration Menu Options (/cfg/ssl) (cont’d.)
Command Syntax and Usage
Creates a test SSL server using the first available virtual SSL index number. The default name of the test server is test_server. A test certificate and key are also created for the test SSL server. When executing the test command, you are asked to specify the IP address of a virtual server (defined on the Nortel Application Switch). The virtual server you specify will then make use of the services the test SSL server provides (HTTPS offload by default).
You also need to specify which type of test SSL server you want to create. Depending on the type you choose to create, you will be prompted for additional related information. Valid SSL server types include the following:
• generic: When selecting the generic SSL server type, you only
need to specify a virtual server IP address. A generic SSL server listens on port 443 (HTTPS) and runs in transparent proxy mode. Contents handled by a generic SSL server is treated as generic data and will not be parsed.
• http: When selecting the HTTP SSL server type, you only need
to specify a virtual server IP address. A HTTP server shares many of its characteristics with the generic server type, but content is parsed as HTTP requests and responses. This paves the way for using a number of HTTP configuration options on the non-encrypted contents.
For each of the preceding SSL server types, you have the option to use an existing certificate (if available), identified by the certificate index number, or create a test certificate.>
For more information on the characteristics and capabilities of the respective server type, see the type command"type generic|http|socks"
(page 92) .
quick
Lets you run a wizard for creating a sharp SSL server with he next available server ID. Before using the wizard, you must have obtained a server certificate in the PEM format that the virtual SSL server can use.
Note that even if the wizard provides an easy way to create and configure a virtual SSL server, you still must configure the Nortel Application Switch accordingly. The extent of configuration changes to filters etc. needed on the Nortel Application Switch depend on your
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 88
88 Command Reference
Table 21 SSL Configuration Menu Options (/cfg/ssl) (cont’d.)
Command Syntax and Usage
current setup and services. For detailed examples of virtual SSL server implementations in conjunction with an Nortel Application Switch, see the
Application Guide for SSL Acceleration.
The VPN Gateway can also operate in standalone mode, i.e. without being connected to an Nortel Application Switch. For configuration examples, see the "Standalone Web Server Accelerator" chapter in the Application Guide for SSL Acceleration.
You will be prompted the following information:
•
Type of server. Lets you specify the type of server, i.e. generic or http. For example, to create a server for HTTPS offload purposes, select http. When the SSL server type is set to HTTP, the virtual SSL server is automatically configured to use built-in features such as automatic SSL redirect and the adding of extra headers. For more information about these advanced HTTP-specific features, see the
/cfg/ssl/server #/http command.
• IP address of SSL server. Lets you specify the IP address of an
existing virtual server on the Nortel Application Switch to bind the HTTP virtual SSL server to that virtual server.
• Which port number the server should listen to. The default value is
443 (https) which is used for HTTPS offload purposes. To set up the virtual SSL server to handle IMAPS for example, set the listen TCP port to 993.
• Real server IP. Sets the IP address of the real server to which the
virtual SSL server should connect when initiating requests. When using the VPN Gateway with an Nortel Application Switch, the real server IP address (RIP) should be the set to 0.0.0.0 (the default setting).
• Real server port. Defines the TCP port to which the virtual SSL
server connects. When setting up a virtual SSL server for HTTPS offload purposes, the default real server port is 81. The virtual SSL server will use this port to send and receive decrypted HTTP information to and from the real web servers. The real Web servers must also be configured to listen for NVG traffic on port 81. For security reasons, it is also important to define a filter on the Nortel Application Switch that blocks all incoming client traffic destined for port 81.
• Should the site be password-protected (yes/no). If you choose yes
here, a login window will be displayed when the user connects to the HTTP server. The login feature is on top of the SSL encryption, which makes it safe to enter user name and password. For user
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 89
/cfg/ssl/server <id> SSL Server Configuration 89
Table 21 SSL Configuration Menu Options (/cfg/ssl) (cont’d.)
Command Syntax and Usage
authentication, you will be prompted to select an existing VPN (if any). The authentication scheme adhering to this VPN will then be used.
•
Is the real server an Outlook Web Access server (yes/no). Enabling this setting corresponds to enabling the addfront setting on the /cfg/ssl/server #/http menu.
•
Certificate. Lets you use an existing certificate or paste a new certificate. If you wish to use a certificate already present in the configuration, choose the desired certificate by entering the corresponding number, otherwise choose no. In this case you will be prompted to paste the certificate you want the virtual SSL server to use.
•
Chain certificate. If the server certificate you just added is a chain certificate, add your chain certificate(s) as well. You need to repeat the pasting of chain certificates until the root CA certificate has been added. This constructs the server certificate chain, which is sent to the client’s browser in addition to the server certificate. When you have added your root CA certificate, answer
no to the question if
you require (additional) chain certificates.
/cfg/ssl/server <id> SSL Server Configuration
[Server 1 Menu]
name - Set server name
vips - Set IP addr(s) of server
standalone - Set standalone mode
port - Set listen port of server
interface - Set back end interface used by server
rip - Set real server IP addrr
port - Set real server port
type - Set type (generic/http/socks)
dnsname - Set DNS name of server
trace - Traffic trace menu
ssl - SSL settings menu
tcp - TCP endpoint settings menu
http - HTTP settings menu
socks - Socks settings menu
adv - Advanced settings menu
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 90
90 Command Reference
del - Remove virtual server
ena - Enable virtual server
dis
- Disable virtual server
The SSL Server menu is used for configuring various attributes of a particular virtual SSL server. The number of items available in the menu will vary according to the virtual SSL server type (generic, http or socks). When accessing the SSL Server menu, you are requested to specify the index number of the virtual SSL server you want to work with. To view information about all configured SSL servers, use the
/info/servers
command.
Table 22 SSL Server Configuration Menu Options (/cfg/ssl/server)
Command Syntax and Usage
name <SSL server name>
Assigns a name to the virtual SSL server. The assigned name is mainly for your own reference.
"" is the default value. You cannot enter only numerals as server name.
vips <virtual server IP addresses separated by comma>
Sets the virtual server IP address (on the Nortel Application Switch), to which the virtual SSL server is mapped. For example: 10,127,232,48.
If the VPN Gateway is used without a Nortel Application Switch (standalone mode), several IP addresses can be specified to create a solution where two or more VPN Gateways in a cluster are load-balanced by the DNS server. For configuration examples in standalone mode, see the "Stand-alone Web Server Accelerator" chapter in the
Application Guide for SSL Acceleration.
standalone on|off
• on: When set to on, the VPN Gateway operates in standalone
mode, i.e. it is not connected to an Nortel Application Switch. Clients connect directly to one of the virtual SSL server’s IP addresses, configured with the vips command. For configuration examples in standalone mode, see the "Stand-alone Web Server Accelerator" chapter in the Application Guide for SSL Acceleration.
• off: When set to off, the VPN Gateway is connected to an Nortel
Application Switch for SSL offload purposes. The IP address set with the vips command corresponds to a virtual IP address on the Nortel Application Switch.
The default value is off.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 91
/cfg/ssl/server <id> SSL Server Configuration 91
Table 22 SSL Server Configuration Menu Options (/cfg/ssl/server) (cont’d.)
Command Syntax and Usage
port <TCP port number>
Sets the TCP port number to which the virtual SSL server listens. The default is port 443 for all virtual SSL servers.
When using the VPN Gateway for SSL Acceleration, the port setting on the VPN Gateway must be accompanied by a redirect filter (on the Nortel Application Switch) in which the
dport value corresponds to the
port value (on the VPN Gateway).
rip <real server IP address>
Sets the IP address of the real server to which the virtual SSL server should connect when initiating requests.
When using the VPN Gateway in conjunction with an Nortel Application Switch, the real server IP address (RIP) should be the set to 0.0.0.0 (the default setting). This setting instructs the VPN Gateway to use the destination IP address found in the received packets, when initiating requests to the virtual server on the Nortel Application Switch to which the virtual SSL server has been mapped.
When using the VPN Gateway as a stand-alone web server accelerator, without any interoperability with an Nortel Application Switch, the real server IP address (RIP) should be set to the IP address of the (single) server that the NVG offloads.
If you have enabled the built-in load balancing capabilities of the VPN Gateway, the rip command is unavailable. Instead, the IP address for each load balanced real server is specified using the
/cfg/ssl/server #/adv/loadbalanc/backend #/ip command.
rport <TCP port number>
Sets the TCP port to which the virtual SSL server connects. The default rport value for all virtual SSL servers that are created is 81. If you are setting up your VPN Gateway as a web server accelerator, the NVG will use this port to send and receive decrypted HTTP information to and from the real web servers. Note that both the virtual server (on the Nortel Application Switch) and the real servers must also be configured to listen for NVG traffic on port 81.
When using the VPN Gateway as a stand-alone web server accelerator (of a single real web server) in combination with end to end encryption, the rport value should be set to 443. The real web server must also be configured to listen to TCP port 443.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 92
92 Command Reference
Table 22 SSL Server Configuration Menu Options (/cfg/ssl/server) (cont’d.)
Command Syntax and Usage
If you have enabled the built-in load balancing capabilities of the VPN Gateway, the rport value is neglected. Instead, the TCP port for each load balanced real server is specified using the /cfg/ssl/server
#/adv/loadbalanc/backend #/port command.
type generic|http|socks
Specifies the virtual SSL server type. Valid options are:
•
generic: When the server type is set to generic, the contents is treated as generic data and will not be parsed.
•
http: When the server type is set to http, the content is parsed as HTTP requests and responses, and you can use the HTTP configuration options on the non-encrypted contents. For more information about HTTP configuration options, see .
• socks: Sets the server type to SOCKS. A SOCKS server is only
required in configurations supporting the SSL VPN client exclusively, i.e. without the need for Portal interaction. To support both the SSL VPN client and the Portal, a portal server is sufficient. A portal server is created automatically when you create a VPN (see
“/cfg/vpn <id> VPN Menu” (page 161)).
The default SSL server type is set to generic.
proxy on|off proxy on|off
Specifies whether to use Transparent proxy mode. If proxy is set to on, the client’s real IP address is used when the VPN Gateway forwards client requests to the real servers. Consequently, it is the client’s IP address that is logged on the real servers, and not the VPN Gateway ’s IP address (which is "transparent" to the real servers). To use the Transparent proxy mode, you need to make sure all client traffic is routed back to the clients through the Nortel Application Switch. The NVG real server group defined on the Nortel Application Switch must use the hash algorithm for server load balancing, and FWLB (Firewall Load Balancing) must be enabled in the appropriate redirect filter on the Nortel Application Switch.
If proxy is set to off, the IP address assigned to the VPN Gateway is used when client requests are forwarded to the real servers. If a real web server is logging the client IP address, it will log the NVG ’s IP address instead of the real client’s IP address. When proxy is set to
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 93
/cfg/ssl/server <id> SSL Server Configuration 93
Table 22 SSL Server Configuration Menu Options (/cfg/ssl/server) (cont’d.)
Command Syntax and Usage
off, the VPN Gateway works in non-transparent proxy mode, that is.
When using non-transparent proxy mode, firewall redirect hash method must not be applied to any real ports on the Nortel Application Switch.
The default proxy mode value is on.
trace
Displays the Trace menu. To view menu options, see“/cfg/ssl/serv
er <id> /trace Network Traffic Dump Commands” (page 94) .
ssl
Displays the SSL settings menu.
tcp
Displays the TCP settings menu.
http
Displays the HTTP settings menu.
Note: This menu item is only available when the SSL server type is set to http.
socks
Displays the Socks settings menu. To view menu options, see .
Note: This menu item is only available when the SSL server type is set to socks.
adv
Displays the Advanced settings menu. To view menu options, see
“/cfg/ssl/server <id> /adv AdvancedSettings Menu” (page 122).
del
Removes the current virtual SSL server.
ena
Enables the current virtual SSL server. This is the default value.
dis
Disables the current virtual SSL server.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 94
94 Command Reference
/cfg/ssl/server <id> /trace Network Traffic Dump Commands
[Trace Menu] ssldump - Create traffic dump tcpdump - Create traffic dump ping - Ping through backend interface dnslookup - Lookup a name in DNS through backend interface traceroute - Traceroute through backend interface
The Trace menu is used for capturing and analyzing SSL and TCP traffic flowing between clients and the selected virtual SSL server on the VPN Gateway. The commands can be useful for debugging purposes. The ssldump command will decrypt transmitted data traffic, provided private keys and certificates have been configured properly on the selected virtual SSL server.
The ssldump and the tcpdump commands can be permanently deactivated in the NVG cluster. For more information, see the /cfg/sys/distrace command on page "distrace" (page 422) .
Table 23 Trace Menu Options (/cfg/ssl/server/trace)
Command Syntax and Usage
ssldump interactive|tftp|ftp|sftp
Creates a dump of the SSL traffic flowing between clients and the currently selected virtual SSL server. The captured information can either be displayed decrypted on screen (the default interactive output mode), or saved as a file to a TFTP/FTP/SFTP server. The server can be specified using either the host name or the IP address.
If you choose to send the dump as a file to a TFTP server, a number of files will be sent to the server depending on the amount of captured information. A number is appended to the file name given in the CLI, starting at 1 and incremented automatically for additional files. You will be prompted for a destination file name prefix of your own choice.
If you choose to send the dump as a file to an FTP server, you will be prompted for the destination file name, as well as a user name and password valid on the specified FTP server.
For detailed information about the default flags used when issuing the ssldump command, as well as customizing the default filter expression, see the SSLDUMP (1) manual pages under UNIX.
For a sample screen output, see “ CLI Dumps” (page 479) ".
tcpdump interactive|tftp|ftp|sftp
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 95
/cfg/ssl/server <id> /trace Network Traffic Dump Commands 95
Table 23 Trace Menu Options (/cfg/ssl/server/trace) (cont’d.)
Command Syntax and Usage
Creates a dump of the TCP traffic flowing between clients and the currently selected virtual SSL server. The captured information can either be displayed on screen (the default
interactive output mode), or saved as a file to a TFTP/FTP/SFTP server. The server can be specified using either the host name or the IP address. You can read a saved TCP traffic dump file using the TCPDUMP or Ethereal application on a remote machine.
If you choose to send the dump to a TFTP server, a number of files will be saved on the server depending on the amount of captured information. A number is appended to the file name given in the CLI, starting at 1 and incremented automatically for additional files. You will be prompted for a destination file name prefix of your own choice.
If you choose to send the dump as a file to an FTP server, you will be prompted for the destination file name, as well as a user name and password valid on the specified FTP server.
For detailed information about the default flags used when issuing the tcpdump command, as well as customizing the default filter expression, see the TCPDUMP (8) manual pages under UNIX.
For a sample screen output, see “ CLI Dumps” (page 479) ".
ping <host name or IP address>
Use this command to verify station-to-station connectivity across the network. If a backend interface is mapped to the current virtual SSL server (only possible for socks servers), the check is made through that backend interface.
To map a backend interface to the virtual SSL server, use the /cfg/ssl/server #/interface command.
To be able to use a host name, the DNS parameters must be configured. To configure a DNS server for the virtual SSL server, use the /cfg/ssl/server #/dns/servers command or use the default DNS server (/cfg/sys/dns).
dnslookup <host name or IP address>
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 96
96 Command Reference
Table 23 Trace Menu Options (/cfg/ssl/server/trace) (cont’d.)
Command Syntax and Usage
Use this command to find the IP address or host name of a machine.
If a backend interface is mapped to the current virtual SSL server (only possible for socks servers), the check is made through that backend interface. If a DNS server is configured for the current virtual SSL server, the check is made against that DNS server.
To map a backend interface to the virtual SSL server, use the /cfg/ssl/server #/interface command. To configure a DNS server for the virtual SSL server, use the /cfg/ssl /server
#/dns/servers command.
traceroute <host name or IP address of target station >
Use this command to identify the route used for station-to-station connectivity across the network. If a backend interface is mapped to the current virtual SSL server (only possible for socks servers), the check is made through that backend interface.
To map a backend interface to the virtual SSL server, use the /cfg/ssl/server #/interface command.
To be able to use a host name, the DNS parameters must be configured. To configure a DNS server for the virtual SSL server, use the /cfg/ssl/server #/dns/servers command or use the default DNS server (/cfg/sys/dns).
/cfg/ssl/server <id> /ssl SSL Settings Configuration
[SSL Settings Menu]
cert - Set server certificate
cache size -Set SSL cache size
cachettl - Set SSL cache timeout
cacerts - Set list of accepted signers of client certificates
cachain - Set list of CA chain certificates
protocol - Set protocol version
verify - Set certificate verification level
ciphers - Set cipher list
ena - Enable SSL
dis - Disable SSL
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 97
/cfg/ssl/server <id> /ssl SSL Settings Configuration 97
The SSL Settings menu is used for configuring SSL-specific settings for a particular virtual SSL server.
Table 24 SSL Settings Menu Options (/cfg/ssl/server/ssl)
Command Syntax and Usage
cert <certificate index number>
Specifies which server certificate is used by the current virtual SSL server. To view basic information about available certificates, use the /info/certs command. To add a new certificate, see the "Adding Certificates to the NVG "section in the "Certificates and Client Authentication" chapter in the
User’s Guide.
Note that each virtual SSL server may only use one server certificate.
cachesize <number of SSL sessions>
Sets the size of the SSL cache. The default value is 4000 cached sessions. If you notice that there are many cache misses, the cachesize value can be increased for better performance.
To view the number of cache misses for a virtual SSL server, use the /stats/sslstats/server #/cachemisse command (where you replace " # " with the index number of the desired virtual SSL server).
cachettl <maximum Time To Live value in seconds>
Sets the maximum Time To Live (TTL) value for items in the SSL cache, before they are discarded.
The default TTL value is 5 minutes.
cacerts <certificate index number>
Specifies which of the available CA certificates to use for client authentication. CA certificates are added the same way as an SSL server certificate—either through cut-and-paste, or through TFTP/FTP/SCP/SFTP from a remote host. Both actions are performed from the Certificate menu. To get an overview over available certificates, enter the /info/certs command.
When specifying more than one certificate, use commas to separate the corresponding index numbers. Example: 1,2,5
To clear all specified CA certificates, press ENTER when asked to enter the certificate numbers, then answer yes to the question if you want to clear the list.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 98
98 Command Reference
Table 24 SSL Settings Menu Options (/cfg/ssl/server/ssl) (cont’d.)
Command Syntax and Usage
Note: If you are using one of the available certificates to generate your own client certificates, you must specify it as a CA certificate to successfully authenticate clients. For more information on client authentication, see the section "Configuring a Virtual SSL Server for Client Authentication" in the "Certificates and Client Authentication" chapter in the
User’s Guide.
cachain <certificate index number>
Specifies the CA certificate chain of the server certificate. The chain starts with the issuing CA certificate of the server certificate, and can range up to the root CA certificate. This command explicitly constructs the server certificate chain, which is sent to the browser in addition to the server certificate.
When specifying more than one certificate, use commas to separate the corresponding index numbers. Example: 1,2,5
To clear all specified chain certificates, press ENTER when asked to enter the certificate numbers, then answer yes to the question if you want to clear the list.
Note: When configuring the virtual SSL server to use chain certificates, the protocol version must be set to SSL3 or SSL23.
protocol ssl2|ssl3|ssl23|tls1
Specifies the protocol to use when establishing an SSL session with a client. Valid options are:
• ssl2: Only accept SSL 2.0.
• ssl3: Accept SSL 3.0 and TLS 1.0.
• ssl23: Accept SSL 2.0, SSL 3.0, and TLS 1.0.
•
tls1: Only accept TLS 1.0.
The default protocol value is ssl3.
verify none|optional|require
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 99
/cfg/ssl/server <id> /tcp TCP Settings Configuration 99
Table 24 SSL Settings Menu Options (/cfg/ssl/server/ssl) (cont’d.)
Command Syntax and Usage
Specifies the level of client authentication to use when establishing an SSL session. Valid options are:
•
none: No client certificate is required.
•
optional: A client certificate is requested, but the client need not present one.
•
require: The client must present a valid certificate to establish a session.
The default verify value is none.
ciphers <cipher list>
Lets you change the default cipher preference list, which corresponds to
ALL@STRENGTH.
For more information about cipher lists, see the "Cipher List Formats" section in Appendix A, Supported Ciphers, in the User’s Guide.
ena
Enables SSL on the current virtual SSL server. By default, SSL is enabled on all virtual SSL servers.
dis
Disables SSL on the current virtual SSL server.
/cfg/ssl/server <id> /tcp TCP Settings Configuration
[TCP Settings Menu]
cwrite - Set client TCP write timeout
ckeep - Set client TCP keep alive timeout
skeep - Set socks client TCP keep alive heartbeat timeout
swrite - Set server TCP write timeout
sconnect - Set server TCP connect timeout
csendbuf - Set client TCP send buffer size
crecbuf - Set client TCP receive buffer size
ssendbuf - Set server TCP send buffer size
srecbuf - Set server TCP receive buffer size
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Page 100
100 Command Reference
The TCP Settings menu is used for configuring various TCP timeout and buffer size settings on both the client and the virtual SSL server side.
Table 25 TCP Settings Menu Options (/cfg/ssl/server/tcp)
Command Syntax and Usage
cwrite <client write timeout>
Sets the timeout value for how long the virtual SSL server should wait for a write operation towards the client(s) to complete.
The default client write timeout value is 15m = 15 minutes.
ckeep <client keep alive timeout>
Sets the timeout value for how long the virtual SSL server should wait before closing an idle session.
The default client keep alive timeout value is 15m = 15 minutes.
skeep <SSL VPN client keep alive timeout>
If the SSL VPN client stops communicating with the VPN Gateway, this timeout value determines for how long the SSL VPN client should be kept alive before the remote user is logged out.
The default SSL VPN client keep alive timeout value is 2m = 2 minutes.
The skeep command is only available for virtual servers of the socks type.
swrite <server write timeout>
Sets the timeout value for how long the virtual SSL server should wait for a write operation towards the backend server(s) to complete.
The default server write timeout value is 15m = 15 minutes.
sconnect <server connect timeout>
Sets the timeout value for how long the virtual SSL server should wait for a server connection when trying to open a TCP connection.
The default server connect timeout value is 30s = 30 seconds.
csendbuf auto| <buffer size (2000-100000 bytes)>
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
Copyright © 2007 Nortel Networks
Loading...