• No results found

Catalyst 6500 Series and Cisco 7600 Series Switch Firewall Services Module Command Reference, 3.1(1)

N/A
N/A
Protected

Academic year: 2020

Share "Catalyst 6500 Series and Cisco 7600 Series Switch Firewall Services Module Command Reference, 3.1(1)"

Copied!
1876
0
0

Loading.... (view fulltext now)

Full text

(1)

Corporate Headquarters

Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA

http://www.cisco.com Tel: 408 526-4000

800 553-NETS (6387) Fax: 408 526-4100

(2)

THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL STATEMENTS, INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL ARE BELIEVED TO BE ACCURATE BUT ARE PRESENTED WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. USERS MUST TAKE FULL RESPONSIBILITY FOR THEIR APPLICATION OF ANY PRODUCTS. THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH IN THE INFORMATION PACKET THAT SHIPPED WITH THE PRODUCT AND ARE INCORPORATED HEREIN BY THIS REFERENCE. IF YOU ARE UNABLE TO LOCATE THE SOFTWARE LICENSE OR LIMITED WARRANTY, CONTACT YOUR CISCO REPRESENTATIVE FOR A COPY.

The Cisco implementation of TCP header compression is an adaptation of a program developed by the University of California, Berkeley (UCB) as part of UCB’s public domain version of the UNIX operating system. All rights reserved. Copyright © 1981, Regents of the University of California.

NOTWITHSTANDING ANY OTHER WARRANTY HEREIN, ALL DOCUMENT FILES AND SOFTWARE OF THESE SUPPLIERS ARE PROVIDED “AS IS” WITH ALL FAULTS. CISCO AND THE ABOVE-NAMED SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESSED OR IMPLIED, INCLUDING, WITHOUT

LIMITATION, THOSE OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OR ARISING FROM A COURSE OF DEALING, USAGE, OR TRADE PRACTICE.

IN NO EVENT SHALL CISCO OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT, SPECIAL, CONSEQUENTIAL, OR INCIDENTAL DAMAGES, INCLUDING, WITHOUT LIMITATION, LOST PROFITS OR LOSS OR DAMAGE TO DATA ARISING OUT OF THE USE OR INABILITY TO USE THIS MANUAL, EVEN IF CISCO OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

Catalyst 6500 Series and Cisco 7600 Series Switch Firewall Services Module Command Reference, 3.1

Copyright © 2006 Cisco Systems, Inc. All rights reserved.

CCSP, CCVP, the Cisco Square Bridge logo, Follow Me Browsing, and StackWise are trademarks of Cisco Systems, Inc.; Changing the Way We Work, Live, Play, and Learn, and iQuick Study are service marks of Cisco Systems, Inc.; and Access Registrar, Aironet, BPX, Catalyst, CCDA, CCDP, CCIE, CCIP, CCNA, CCNP, Cisco, the Cisco Certified Internetwork Expert logo, Cisco IOS, Cisco Press, Cisco Systems, Cisco Systems Capital, the Cisco Systems logo, Cisco Unity, Enterprise/Solver, EtherChannel, EtherFast, EtherSwitch, Fast Step, FormShare, GigaDrive, GigaStack, HomeLink, Internet Quotient, IOS, IP/TV, iQ Expertise, the iQ logo, iQ Net Readiness Scorecard, LightStream, Linksys, MeetingPlace, MGX, the Networkers logo, Networking Academy, Network Registrar, Packet, PIX, Post-Routing, Pre-Routing, ProConnect, RateMUX, ScriptShare, SlideCast, SMARTnet, The Fastest Way to Increase Your Internet Quotient, and TransPath are registered trademarks of Cisco Systems, Inc. and/or its affiliates in the United States and certain other countries.

(3)

C O N T E N T S

About This Guide

xxxiii

Using the Command-Line Interface

1- 1

aaa accounting through accounting-server-group Commands

2 - 1

aaa accounting

2 - 2

aaa accounting command

2 - 5

aaa accounting console

2 - 7

aaa accounting match

2 - 9

aaa authentication

2 - 11

aaa authentication console

2 - 17

aaa authentication match

2 - 22

aaa authentication secure-http-client

2 - 24

aaa authorization

2 - 26

aaa authorization command

2 - 30

aaa authorization match

2 - 32

aaa local authentication attempts max-fail

2 - 34

aaa mac-exempt

2 - 36

aaa proxy-limit

2 - 37

aaa-server host

2 - 39

aaa-server protocol

2 - 42

absolute

2 - 44

accept-subordinates

2 - 46

access-group

2 - 48

access-list alert-interval

2 - 50

access-list commit

2 - 52

access-list deny-flow-max

2 - 54

access-list ethertype

2 - 56

access-list extended

2 - 58

access-list mode

2 - 63

access-list remark

2 - 67

access-list standard

2 - 69
(4)

Contents

accounting-port

2 - 73

accounting-server-group

2 - 75

activation-key through auto-update timeout Commands

3 - 1

activation-key

3 - 2

address-pool

3 - 3

admin-context

3 - 5

alias

3 - 7

allocate-acl-partition

3 - 10

allocate-interface

3 - 12

area

3 - 15

area authentication

3 - 17

area default-cost

3 - 19

area filter-list prefix

3 - 21

area nssa

3 - 23

area range

3 - 25

area stub

3 - 27

area virtual-link

3 - 29

arp

3 - 32

arp timeout

3 - 34

arp-inspection

3 - 35

asdm disconnect

3 - 37

asdm disconnect log_session

3 - 39

asdm group

3 - 41

asdm history enable

3 - 42

asdm location

3 - 43

asr-group

3 - 44

authentication-port

3 - 46

authentication-server-group

3 - 48

authorization-dn-attributes

3 - 50

authorization-required

3 - 52

authorization-server-group

3 - 54

auth-prompt

3 - 56

auto-update device-id

3 - 58
(5)

Contents

auto-update timeout

3 - 64

backup-servers through bridge-group Commands

4 - 1

backup-servers

4 - 2

banner

4 - 4

banner (group-policy)

4 - 6

blocks

4 - 7

bridge-group

4 - 9

cache-time through clear capture Commands

5 - 1

cache-time

5 - 2

call-agent

5 - 3

capture

5 - 5

cd

5 - 8

certificate

5 - 9

chain

5 - 11

changeto

5 - 13

checkheaps

5 - 15

check-retransmission

5 - 17

checksum-verification

5 - 19

class

5 - 21

class (policy-map)

5 - 23

class-map

5 - 25

clear aaa local user fail-attempts

5 - 27

clear aaa local user lockout

5 - 29

clear aaa-server statistics

5 - 31

clear access-group

5 - 33

clear access-list

5 - 34

clear arp

5 - 35

clear asp drop

5 - 36

clear blocks

5 - 38

clear capture

5 - 39

clear configure through clear configure virtual Commands

6 - 1

clear configure

6 - 2

clear configure aaa

6 - 4
(6)

Contents

clear configure access-group

6 - 7

clear configure access-list

6 - 8

clear configure alias

6 - 9

clear configure arp

6 - 10

clear configure arp-inspection

6 - 11

clear configure asdm

6 - 12

clear configure auth-prompt

6 - 14

clear configure auto-update

6 - 15

clear configure banner

6 - 16

clear configure ca certificate map

6 - 17

clear configure class

6 - 18

clear configure class-map

6 - 19

clear configure command-alias

6 - 20

clear configure console

6 - 21

clear configure context

6 - 22

clear configure crypto

6 - 24

clear configure crypto ca trustpoint

6 - 25

clear configure crypto dynamic-map

6 - 26

clear configure crypto map

6 - 27

clear configure dhcpd

6 - 28

clear configure dhcprelay

6 - 29

clear configure dns

6 - 29

clear configure established

6 - 31

clear configure failover

6 - 32

clear configure filter

6 - 33

clear configure firewall

6 - 34

clear configure fixup

6 - 35

clear configure fragment

6 - 36

clear configure ftp

6 - 38

clear configure ftp-map

6 - 39

clear configure global

6 - 40

clear configure group-policy

6 - 41

clear configure gtp-map

6 - 42

clear configure hostname

6 - 43
(7)

Contents

clear configure http-map

6 - 45

clear configure icmp

6 - 46

clear configure interface

6 - 47

clear configure interface bvi

6 - 49

clear configure ip

6 - 50

clear configure ip local pool

6 - 51

clear configure ip verify reverse-path

6 - 52

clear configure ipv6

6 - 53

clear configure isakmp

6 - 54

clear configure isakmp policy

6 - 55

clear configure logging

6 - 56

clear configure mac-address-table

6 - 58

clear configure mac-learn

6 - 59

clear configure mac-list

6 - 60

clear configure management-access

6 - 61

clear configure mgcp-map

6 - 62

clear configure monitor-interface

6 - 63

clear configure mroute

6 - 64

clear configure mtu

6 - 65

clear configure multicast-routing

6 - 66

clear configure name

6 - 67

clear configure nat

6 - 68

clear configure object-group

6 - 69

clear configure passwd

6 - 70

clear configure pim

6 - 70

clear configure policy-map

6 - 72

clear configure prefix-list

6 - 73

clear configure privilege

6 - 74

clear configure rip

6 - 75

clear configure route

6 - 76

clear configure route-map

6 - 77

clear configure router

6 - 78

clear configure service-policy

6 - 79

clear configure snmp-map

6 - 80
(8)

Contents

clear configure ssh

6 - 82

clear configure static

6 - 83

clear configure sunrpc-server

6 - 84

clear configure sysopt

6 - 85

clear configure telnet

6 - 86

clear configure terminal

6 - 87

clear configure timeout

6 - 88

clear configure tunnel-group

6 - 89

clear configure url-block

6 - 90

clear configure url-cache

6 - 91

clear configure url-server

6 - 92

clear configure username

6 - 93

clear configure virtual

6 - 94

clear console-output through clear xlate Commands

7 - 1

clear console-output

7 - 2

clear counters

7 - 3

clear crashinfo

7 - 4

clear crypto accelerator statistics

7 - 5

clear crypto ca crls

7 - 6

clear crypto protocol statistics

7 - 7

clear dhcprelay statistics

7 - 9

clear dns-hosts cache

7 - 10

clear failover statistics

7 - 11

clear fragment

7 - 12

clear gc

7 - 14

clear igmp counters

7 - 15

clear igmp group

7 - 16

clear igmp traffic

7 - 17

clear interface

7 - 18

clear ip verify statistics

7 - 20

clear ipsec sa

7 - 21

clear ipv6 access-list counters

7 - 22

clear ipv6 neighbors

7 - 23
(9)

Contents

clear local-host

7 - 27

clear logging asdm

7 - 29

clear logging buffer

7 - 30

clear mac-address-table

7 - 31

clear memory profile

7 - 32

clear mfib counters

7 - 33

clear ospf

7 - 34

clear pim counters

7 - 36

clear pim reset

7 - 37

clear pim topology

7 - 38

clear prompt

7 - 39

clear resource usage

7 - 41

clear route

7 - 43

clear service-policy

7 - 44

clear service-policy inspect gtp

7 - 46

clear shun

7 - 48

clear sunrpc-server active

7 - 49

clear traffic

7 - 50

clear uauth

7 - 51

clear url-block block statistics

7 - 53

clear url-cache statistics

7 - 55

clear url-server

7 - 57

clear xlate

7 - 58

client-access-rule through crl-configure Commands

8 - 1

client-access-rule

8 - 2

client-firewall

8 - 4

client-update

8 - 6

command-alias

8 - 8

command-queue

8 - 10

compatible rfc1583

8 - 12

configure http

8 - 13

configure memory

8 - 15

configure net

8 - 17

configure terminal

8 - 19
(10)

Contents

console timeout

8 - 23

content-length

8 - 24

content-type-verification

8 - 26

context

8 - 28

copy

8 - 30

copy capture

8 - 32

crashinfo force

8 - 34

crashinfo save disable

8 - 36

crashinfo test

8 - 37

crl

8 - 38

crl configure

8 - 39

crypto ca authenticate through crypto map set trustpoint Commands

9 - 1

crypto ca authenticate

9 - 2

crypto ca certificate chain

9 - 4

crypto ca certificate map

9 - 5

crypto ca crl request

9 - 7

crypto ca enroll

9 - 8

crypto ca export

9 - 10

crypto ca import

9 - 12

crypto ca trustpoint

9 - 14

crypto dynamic-map match address

9 - 16

crypto dynamic-map set peer

9 - 17

crypto dynamic-map set pfs

9 - 18

crypto dynamic-map set reverse route

9 - 20

crypto dynamic-map set security-association lifetime

9 - 21

crypto dynamic-map set transform-set

9 - 23

crypto ipsec df-bit

9 - 25

crypto ipsec fragmentation

9 - 27

crypto ipsec security-association lifetime

9 - 29

crypto ipsec transform-set

9 - 31

crypto key generate dsa

9 - 34

crypto key generate rsa

9 - 36

crypto key zeroize

9 - 38
(11)

Contents

crypto map match address

9 - 43

crypto map set connection-type

9 - 45

crypto map set peer

9 - 47

crypto map set pfs

9 - 49

crypto map set phase1 mode

9 - 51

crypto map set reverse-route

9 - 53

crypto map set security-association lifetime

9 - 54

crypto map set transform-set

9 - 56

crypto map set trustpoint

9 - 58

debug aaa through debug sip Commands

10 - 1

debug aaa

10 - 2

debug appfw

10 - 4

debug arp

10 - 5

debug arp-inspection

10 - 6

debug asdm history

10 - 7

debug context

10 - 8

debug control-plane

10 - 10

debug crypto ca

10 - 12

debug crypto ipsec

10 - 14

debug crypto isakmp

10 - 15

debug crypto isakmp

10 - 17

debug ctiqbe

10 - 19

debug ctm

10 - 21

debug dhcpc

10 - 23

debug dhcpd

10 - 25

debug dhcprelay

10 - 27

debug disk

10 - 29

debug dns

10 - 31

debug entity

10 - 32

debug fixup

10 - 34

debug fover

10 - 36

debug fsm

10 - 38

debug ftp client

10 - 40

debug generic

10 - 42
(12)

Contents

debug h323

10 - 46

debug http

10 - 48

debug http-map

10 - 49

debug icmp

10 - 50

debug igmp

10 - 52

debug ils

10 - 54

debug imagemgr

10 - 56

debug ipsec-over-tcp

10 - 58

debug ipv6

10 - 60

debug iua-proxy

10 - 62

debug kerberos

10 - 64

debug ldap

10 - 66

debug mac-address-table

10 - 68

debug menu

10 - 70

debug mfib

10 - 71

debug mgcp

10 - 73

debug mrib

10 - 74

debug ntdomain

10 - 76

debug ospf

10 - 78

debug parser cache

10 - 80

debug pim

10 - 82

debug pix acl

10 - 84

debug pix cls

10 - 85

debug pix pkt2pc

10 - 86

debug pix process

10 - 87

debug pix uauth

10 - 88

debug pptp

10 - 89

debug radius

10 - 91

debug rip

10 - 94

debug rtsp

10 - 96

debug sdi

10 - 98

debug sequence

10 - 100

debug skinny

10 - 102

debug smtp

10 - 104
(13)

Contents

debug ssh

10 - 108

debug sunrpc

10 - 110

debug tacacs

10 - 112

debug tcp-map

10 - 114

debug timestamps

10 - 116

debug vpn-sessiondb

10 - 118

debug xdmcp

10 - 120

debug sip

10 - 122

default through drop Commands

11 - 1

default (crl configure)

11 - 2

default (crl configure)

11 - 3

default (time-range)

11 - 4

default-domain

11 - 6

default enrollment

11 - 8

default-group-policy

11 - 9

default-information originate

11 - 11

delete

11 - 13

deny-request-cmd

11 - 14

dhcpd dns

11 - 16

dhcpd domain

11 - 18

dhcpd enable

11 - 20

dhcpd lease

11 - 22

dhcpd option

11 - 24

dhcpd ping-timeout

11 - 27

dhcpd wins

11 - 29

dhcp-network-scope

11 - 31

dhcprelay enable

11 - 32

dhcprelay server

11 - 34

dhcprelay setroute

11 - 36

dhcprelay enable

11 - 38

dhcp-server

11 - 40

dir

11 - 42

disable

11 - 44

distance ospf

11 - 45
(14)

Contents

dns name-server

11 - 49

dns retries

11 - 51

description

11 - 52

dns-server

11 - 54

dns timeout

11 - 55

domain-name

11 - 56

drop

11 - 58

email through ftp-map Commands

12 - 1

email

12 - 2

enable

12 - 3

enable password

12 - 5

endpoint

12 - 7

enforcenextupdate

12 - 9

enrollment retry count

12 - 10

enrollment retry period

12 - 12

enrollment terminal

12 - 13

enrollment url

12 - 14

erase

12 - 15

established

12 - 16

exit

12 - 19

failover

12 - 21

failover active

12 - 23

failover group

12 - 24

failover interface ip

12 - 26

failover interface-policy

12 - 28

failover key

12 - 30

failover lan interface

12 - 32

failover lan unit

12 - 34

failover link

12 - 36

failover polltime

12 - 38

failover reload-standby

12 - 40

failover replication http

12 - 41

failover reset

12 - 43
(15)

Contents

filter ftp

12 - 48

filter https

12 - 50

filter java

12 - 52

filter url

12 - 54

firewall transparent

12 - 58

format

12 - 60

fqdn

12 - 61

fragment

12 - 62

ftp mode passive

12 - 64

ftp-map

12 - 66

gateway through http-map Commands

13 - 1

gateway

13 - 2

global

13 - 4

group-delimiter

13 - 7

group-lock

13 - 8

group-object

13 - 9

group-policy

13 - 11

group-policy attributes

13 - 14

h225-map

13 - 16

help

13 - 18

hostname

13 - 20

hsi

13 - 22

hsi-group

13 - 24

hsi-group

13 - 26

http

13 - 28

http authentication-certificate

13 - 30

http redirect

13 - 32

http server enable

13 - 34

http-map

13 - 35

icmp through ignore lsa mospf Commands

14 - 1

icmp

14 - 2

icmp-object

14 - 5

id-cert-issuer

14 - 7

igmp

14 - 9
(16)

Contents

igmp forward interface

14 - 11

igmp join-group

14 - 12

igmp limit

14 - 13

igmp query-interval

14 - 14

igmp query-max-response-time

14 - 16

igmp query-timeout

14 - 17

igmp static-group

14 - 18

igmp version

14 - 19

ignore lsa mospf

14 - 20

inspect ctiqbe through inspect xdmcp Commands

15 - 1

inspect ctiqbe

15 - 2

inspect dns

15 - 4

inspect esmtp

15 - 7

inspect ftp

15 - 10

inspect gtp

15 - 13

inspect h323

15 - 15

inspect http

15 - 19

inspect icmp

15 - 22

inspect icmp error

15 - 24

inspect ils

15 - 26

inspect mgcp

15 - 28

inspect netbios

15 - 31

inspect pptp

15 - 33

inspect rsh

15 - 35

inspect rtsp

15 - 37

inspect sip

15 - 40

inspect skinny

15 - 43

inspect smtp

15 - 46

inspect snmp

15 - 48

inspect sqlnet

15 - 50

inspect sunrpc

15 - 52

inspect tftp

15 - 54

inspect xdmcp

15 - 56
(17)

Contents

interface bvi

16 - 4

interface-policy

16 - 6

‘ip address

16 - 8

ip-address

16 - 10

ip-address-privacy

16 - 11

ip local pool

16 - 13

ip verify reverse-path

16 - 15

ip-comp

16 - 17

ip-phone-bypass

16 - 18

ipsec-udp

16 - 19

ipsec-udp-port

16 - 21

ipv6 access-list

16 - 22

ipv6 access-list remark

16 - 26

ipv6 address

16 - 28

ipv6 enable

16 - 30

ipv6 icmp

16 - 31

ipv6 nd dad attempts

16 - 34

ipv6 nd ns-interval

16 - 36

ipv6 nd prefix

16 - 37

ipv6 nd ra-interval

16 - 39

ipv6 nd ra-lifetime

16 - 41

ipv6 nd reachable-time

16 - 43

ipv6 nd suppress-ra

16 - 44

ipv6 neighbor

16 - 45

ipv6 route

16 - 47

isakmp am-disable

16 - 49

isakmp disconnect-notify

16 - 50

isakmp enable

16 - 51

isakmp identity

16 - 52

isakmp keepalive

16 - 53

isakmp policy authentication

16 - 55

isakmp policy encryption

16 - 57

isakmp policy group

16 - 59

isakmp policy hash

16 - 61
(18)

Contents

isakmp reload-wait

16 - 65

issuer-name

16 - 66

join-failover-group through kill Commands

17 - 1

join-failover-group

17 - 2

kerberos-realm

17 - 4

key

17 - 6

keypair

17 - 8

kill

17 - 9

ldap-base-dn through log-adj-changes Commands

18 - 1

ldap-base-dn

18 - 2

ldap-defaults

18 - 4

ldap-dn

18 - 5

ldap-login-dn

18 - 7

ldap-login-password

18 - 9

ldap-naming-attribute

18 - 11

ldap-scope

18 - 13

leap-bypass

18 - 15

limit-resource

18 - 17

log-adj-changes

18 - 20

logging asdm through logout Commands

19 - 1

logging asdm

19 - 2

logging asdm-buffer-size

19 - 4

logging buffered

19 - 6

logging buffer-size

19 - 8

logging class

19 - 10

logging console

19 - 13

logging debug-trace

19 - 15

logging device-id

19 - 17

logging emblem

19 - 19

logging enable

19 - 21

logging facility

19 - 23

logging flash-bufferwrap

19 - 25

logging flash-maximum-allocation

19 - 27
(19)

Contents

logging from-address

19 - 31

logging ftp-bufferwrap

19 - 33

logging ftp-server

19 - 35

logging history

19 - 37

logging host

19 - 39

logging list

19 - 41

logging mail

19 - 44

logging message

19 - 46

logging monitor

19 - 48

logging permit-hostdown

19 - 50

logging queue

19 - 52

logging recipient-address

19 - 54

logging savelog

19 - 56

logging standby

19 - 58

logging timestamp

19 - 60

logging trap

19 - 61

login

19 - 63

logout

19 - 65

mac-address-table aging-time through multicast-routing Commands

20 - 1

mac-address-table aging-time

20 - 2

mac-address-table static

20 - 3

mac-learn

20 - 5

mac-list

20 - 7

management-access

20 - 9

mask-syst-reply

20 - 11

match access-list

20 - 12

match any

20 - 14

match default-inspection-traffic

20 - 16

match dscp

20 - 18

match interface

20 - 20

match ip address

20 - 22

match ip next-hop

20 - 24

match ip route-source

20 - 26

match metric

20 - 28
(20)

Contents

match precedence

20 - 32

match route-type

20 - 34

match rtp

20 - 36

max-failed-attempts

20 - 38

max-header-length

20 - 40

max-uri-length

20 - 42

mcc

20 - 44

member

20 - 46

memory caller-address

20 - 48

memory profile enable

20 - 50

memory profile text

20 - 51

message-length

20 - 53

mgcp-map

20 - 55

mkdir

20 - 57

mode

20 - 58

monitor-interface

20 - 61

more

20 - 63

mroute

20 - 65

mtu

20 - 67

multicast-routing

20 - 69

name through ospf transmit-delay Commands

21 - 1

name

21 - 2

nameif

21 - 4

names

21 - 6

nat

21 - 7

nat-control

21 - 13

neighbor

21 - 15

nem

21 - 17

network area

21 - 18

network-object

21 - 20

nt-auth-domain-controller

21 - 22

object-group

21 - 24

ospf authentication

21 - 29
(21)

Contents

ospf database-filter all out

21 - 34

ospf dead-interval

21 - 35

ospf hello-interval

21 - 36

ospf message-digest-key

21 - 37

ospf mtu-ignore

21 - 39

ospf network point-to-point non-broadcast

21 - 40

ospf priority

21 - 42

ospf retransmit-interval

21 - 43

ospf transmit-delay

21 - 44

pager through pwd Commands

22 - 1

pager

22 - 2

passwd

22 - 4

password (crypto ca trustpoint)

22 - 6

password-storage

22 - 8

peer-id-validate

22 - 9

perfmon

22 - 11

perfmon interval

22 - 13

perfmon settings

22 - 14

periodic

22 - 15

permit errors

22 - 17

pfs

22 - 19

pim

22 - 20

pim accept-register

22 - 21

pim dr-priority

22 - 22

pim hello-interval

22 - 23

pim join-prune-interval

22 - 24

pim old-register-checksum

22 - 25

pim rp-address

22 - 26

pim spt-threshold infinity

22 - 28

ping

22 - 29

policy

22 - 31

policy-map

22 - 33

polltime interface

22 - 35

port-misuse

22 - 37
(22)

Contents

preempt

22 - 42

prefix-list

22 - 44

prefix-list description

22 - 47

prefix-list sequence-number

22 - 49

pre-shared-key

22 - 50

primary

22 - 51

privilege

22 - 53

prompt

22 - 55

protocol http

22 - 57

protocol ldap

22 - 59

protocol-object

22 - 60

protocol scep

22 - 62

pwd

22 - 63

queue-limit through router-id Commands

23 - 1

queue-limit

23 - 2

quit

23 - 4

radius-common-pw

23 - 6

radius-with-expiry

23 - 8

reactivation-mode

23 - 9

redistribute

23 - 11

reload

23 - 13

remote-access threshold session-threshold-exceeded

23 - 16

rename

23 - 17

replication http

23 - 19

request-command deny

23 - 21

request-method

23 - 23

request-queue

23 - 26

resource acl-partition

23 - 28

retry-interval

23 - 30

re-xauth

23 - 32

rip

23 - 34

rmdir

23 - 37

route

23 - 38
(23)

Contents

router-id

23 - 44

same-security-traffic through show asdmsessions Commands

24 - 1

same-security-traffic

24 - 2

sdi-pre-5-slave

24 - 4

sdi-version

24 - 6

secure-unit-authentication

24 - 8

security-level

24 - 10

serial-number

24 - 12

server-port

24 - 13

service resetinbound

24 - 15

service-policy

24 - 17

set connection

24 - 19

set connection timeout

24 - 21

set metric

24 - 23

set metric

24 - 25

setup

24 - 27

show aaa local user

24 - 29

show access-list

24 - 31

show activation-key

24 - 33

show admin-context

24 - 35

show arp

24 - 36

show arp-inspection

24 - 37

show arp statistics

24 - 38

show asdm history

24 - 40

show asdm sessions

24 - 47

show asp drop through show curpriv Commands

25 - 1

show asp drop

25 - 2

show asp table arp

25 - 5

show asp table classify

25 - 7

show asp table interfaces

25 - 10

show asp table mac-address-table

25 - 12

show asp table routing

25 - 14

show asp table vpn-context

25 - 16

show asr

25 - 18
(24)

Contents

show blocks

25 - 21

show capture

25 - 27

show checkheaps

25 - 29

show checksum

25 - 30

show chunkstat

25 - 31

show class

25 - 32

show conn

25 - 33

show console-output

25 - 38

show context

25 - 39

show counters

25 - 43

show counters description

25 - 45

show cpu

25 - 46

show crashinfo

25 - 48

show crypto accelerator statistics

25 - 56

show crypto ca certificates

25 - 59

show crypto ca crls

25 - 61

show crypto ipsec df-bit

25 - 62

show crypto ipsec fragmentation

25 - 63

show crypto key mypubkey

25 - 64

show crypto protocol statistics

25 - 65

show ctiqbe

25 - 68

show curpriv

25 - 70

show debug through show ipv6 traffic Commands

26 - 1

show debug

26 - 2

show dhcprelay state

26 - 5

show dhcprelay statistics

26 - 7

show disk

26 - 9

show dns-hosts

26 - 11

show failover

26 - 13

show file

26 - 17

show firewall

26 - 18

show fragment

26 - 19

show gc

26 - 21
(25)

Contents

show h323-ras

26 - 26

show history

26 - 28

show idb

26 - 30

show igmp groups

26 - 32

show igmp traffic

26 - 33

show interface

26 - 34

show interface ip brief

26 - 40

show ip address

26 - 42

show ip verify statistics

26 - 44

show ipsec sa

26 - 45

show ipsec sa summary

26 - 52

show ipsec stats

26 - 54

show ipv6 access-list

26 - 56

show ipv6 interface

26 - 58

show ipv6 neighbor

26 - 60

show ipv6 route

26 - 62

show ipv6 routers

26 - 64

show ipv6 traffic

26 - 65

show isakmp sa through show route Commands

27 - 1

show isakmp sa

27 - 2

show isakmp stats

27 - 4

show local-host

27 - 7

show logging

27 - 9

show mac-address-table

27 - 11

show management-access

27 - 13

show memory

27 - 14

show memory binsize

27 - 17

show memory profile

27 - 18

show memory-caller address

27 - 21

show mfib

27 - 23

show mfib active

27 - 24

show mfib count

27 - 26

show mfib interface

27 - 27

show mfib reserved

27 - 28
(26)

Contents

show mfib summary

27 - 31

show mfib verbose

27 - 32

show mgcp

27 - 33

show mode

27 - 35

show mrib client

27 - 36

show mrib route

27 - 38

show mrib route summary

27 - 40

show mroute

27 - 41

show nameif

27 - 44

show ospf

27 - 46

show ospf border-routers

27 - 48

show ospf database

27 - 49

show ospf flood-list

27 - 53

show ospf interface

27 - 55

show ospf neighbor

27 - 57

show ospf request-list

27 - 59

show ospf retransmission-list

27 - 60

show ospf summary-address

27 - 62

show ospf virtual-links

27 - 63

show perfmon

27 - 64

show pim df

27 - 66

show pim group-map

27 - 67

show pim interface

27 - 69

show pim join-prune statistic

27 - 70

show pim neighbor

27 - 72

show pim range-list

27 - 74

show pim topology

27 - 76

show pim topology reserved

27 - 78

show pim topology route-count

27 - 79

show pim traffic

27 - 80

show pim tunnel

27 - 82

show processes

27 - 83

show prompt

27 - 86

show reload

27 - 88
(27)

Contents

show resource allocation

27 - 90

show resource types

27 - 94

show resource usage

27 - 96

show route

27 - 99

show running-config through show running-config isakmp Commands

28 - 1

show running-config

28 - 2

show running-config aaa

28 - 5

show running-config aaa-server

28 - 7

show running-config aaa-server host

28 - 9

show running-config access-group

28 - 11

show running-config access-list

28 - 12

show running-config alias

28 - 14

show running-config arp

28 - 15

show running-config arp timeout

28 - 16

show running-config arp-inspection

28 - 17

show running-config asdm

28 - 18

show running-config auth-prompt

28 - 20

show running-config auto-update

28 - 21

show running-config banner

28 - 22

show running-config class-map

28 - 23

show running-config command-alias

28 - 24

show running-config console timeout

28 - 26

show running-config context

28 - 27

show running-config crypto

28 - 29

show running-config crypto isakmp

28 - 31

show running-config crypto ipsec

28 - 32

show running-config crypto map

28 - 33

show running-config crypto dynamic-map

28 - 34

show running-config dhcpd

28 - 36

show running-config dhcprelay

28 - 37

show running-config dns

28 - 38

show running-config domain-name

28 - 39

show running-config enable

28 - 40

show running-config established

28 - 41
(28)

Contents

show running-config filter

28 - 43

show running-config fragment

28 - 44

show running-config ftp mode

28 - 46

show running-config ftp-map

28 - 47

show running-config global

28 - 48

show running-config group-delimiter

28 - 49

show running-config group-policy

28 - 50

show running-config gtp-map

28 - 51

show running-config http

28 - 53

show running-config http-map

28 - 54

show running-config icmp

28 - 56

show running-config interface

28 - 57

show running-config interface bvi

28 - 59

show running-config ip address

28 - 60

show running-config ip local pool

28 - 62

show running-config ip verify reverse-path

28 - 64

show running-config ipv6

28 - 65

show running-config isakmp

28 - 66

show running-config logging through show running-config vpn-sessiondb Commands

29 - 1

show running-config logging

29 - 2

show running-config logging rate-limit

29 - 3

show running-config mac-address-table

29 - 4

show running-config mac-learn

29 - 5

show running-config mac-list

29 - 6

show running-config management-access

29 - 8

show running-config mgcp-map

29 - 9

show running-config monitor-interface

29 - 11

show running-config mroute

29 - 13

show running-config mtu

29 - 14

show running-config multicast-routing

29 - 15

show running-config name

29 - 16

show running-config nameif

29 - 17

show running-config names

29 - 19
(29)

Contents

show running-config object-group

29 - 23

show running-config passwd

29 - 25

show running-config pim

29 - 26

show running-config policy-map

29 - 27

show running-config prefix-list

29 - 29

show running-config privilege

29 - 30

show running-config rip

29 - 32

show running-config route

29 - 33

show running-config route-map

29 - 34

show running-config router

29 - 36

show running-config same-security-traffic

29 - 37

show running-config service

29 - 38

show running-config service-policy

29 - 39

show running-config snmp-map

29 - 40

show running-config snmp-server

29 - 41

show running-config ssh

29 - 42

show running-config static

29 - 44

show running-config sunrpc-server

29 - 45

show running-config sysopt

29 - 46

show running-config telnet

29 - 48

show running-config terminal

29 - 49

show running-config tftp-server

29 - 50

show running-config timeout

29 - 51

show running-config tunnel-group

29 - 52

show running-config url-block

29 - 54

show running-config url-cache

29 - 56

show running-config url-server

29 - 57

show running-config username

29 - 58

show running-config virtual

29 - 60

show running-configuration vpn-sessiondb

29 - 61

show service-policy through show xlate Commands

30 - 1

show service-policy

30 - 2

show service-policy inspect gtp

30 - 5

show shun

30 - 8
(30)

Contents

show skinny

30 - 11

show snmp-server statistics

30 - 13

show ssh sessions

30 - 15

show startup-config

30 - 17

show sunrpc-server active

30 - 19

show tcpstat

30 - 20

show tech-support

30 - 23

show traffic

30 - 28

show uauth

30 - 32

show url-block

30 - 34

show url-cache statistics

30 - 36

show url-server

30 - 38

show version

30 - 40

show vlan

30 - 42

show vpn-sessiondb

30 - 43

show vpn-sessiondb ratio

30 - 47

show vpn-sessiondb summary

30 - 49

show xlate

30 - 50

shun through sysopt uauth allow-http-cache Commands

31 - 1

shun

31 - 1

shutdown

31 - 3

sip-map

31 - 5

smtp-server

31 - 7

snmp-map

31 - 8

snmp-server community

31 - 10

snmp-server contact

31 - 11

snmp-server enable

31 - 12

snmp-server enable traps

31 - 14

snmp-server host

31 - 16

snmp-server listen-port

31 - 18

snmp-server location

31 - 19

split-dns

31 - 20

split-tunnel-network-list

31 - 22
(31)

Contents

ssh disconnect

31 - 28

ssh scopy enable

31 - 30

ssh timeout

31 - 32

ssh version

31 - 34

static

31 - 36

strict-http

31 - 41

strip-group

31 - 43

strip-realm

31 - 45

subject-name (crypto ca certificate map)

31 - 47

subject-name (crypto ca trustpoint)

31 - 49

summary-address

31 - 50

sunrpc-server

31 - 52

support-user-cert-validation

31 - 54

sysopt connection tcpmss

31 - 56

sysopt connection timewait

31 - 58

sysopt nodnsalias

31 - 60

sysopt noproxyarp

31 - 62

sysopt radius ignore-secret

31 - 64

sysopt uauth allow-http-cache

31 - 65

tcp-map through tunnel-limit Commands

32 - 1

telnet

32 - 2

terminal

32 - 5

terminal pager

32 - 6

terminal width

32 - 8

tftp-server

32 - 9

timeout

32 - 11

timeout (aaa-server host)

32 - 14

timeout (gtp-map)

32 - 16

time-range

32 - 18

timers lsa-group-pacing

32 - 20

timers spf

32 - 21

transfer-encoding

32 - 23

trust-point

32 - 26

tunnel-group

32 - 28
(32)

Contents

tunnel-group ipsec-attributes

32 - 32

tunnel-group-map default-group

32 - 34

tunnel-group-map enable

32 - 36

tunnel-limit

32 - 38

upgrade-mp through write terminal Commands

33 - 1

upgrade-mp

33 - 1

url

33 - 3

url-block

33 - 5

url-cache

33 - 7

url-server

33 - 9

user-authentication

33 - 12

user-authentication-idle-timeout

33 - 14

username

33 - 16

username attributes

33 - 18

virtual http

33 - 20

virtual telnet

33 - 22

vpn-access-hours

33 - 24

vpn-addr-assign

33 - 25

vpn-filter

33 - 27

vpn-framed-ip-address

33 - 28

vpn-framed-ip-netmask

33 - 29

vpn-group-policy

33 - 30

vpn-idle-timeout

33 - 32

vpn-sessiondb logoff

33 - 34

vpn-sessiondb max-session-limit

33 - 36

vpn-session-timeout

33 - 37

vpn-simultaneous-logins

33 - 39

vpn-tunnel-protocol

33 - 40

who

33 - 41

wins-server

33 - 42

write erase

33 - 43

write memory

33 - 44

write net

33 - 46
(33)

About This Guide

This preface describes who should read the Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Command Reference, how it is organized, and its document conventions. This preface includes the following sections:

Document Objectives, page xxxiii

Audience, page xxxiii

Document Organization, page xxxiv

Document Conventions, page xxxv

Related Documentation, page xxxvi

Obtaining Documentation, page xxxvi

Documentation Feedback, page xxxvii

Cisco Product Security Overview, page xxxvii

Obtaining Technical Assistance, page xxxviii

Obtaining Additional Publications and Information, page xl

Document Objectives

This guide contains the commands available for use with the FWSM to protect your network from unauthorized use.

You can also configure and monitor the FWSM by using ASDM, a web-based GUI application. ASDM includes configuration wizards to guide you through some common configuration scenarios, and online Help for less common scenarios. For more information, see:

http://www.cisco.com/univercd/cc/td/doc/product/netsec/secmgmt/asdm/index.htm.

Audience

(34)

About This Guide Document Organization

Document Organization

This guide includes the following chapters:

Chapter 1, “Using the Command-Line Interface,” introduces you to the FWSM commands and access modes.

Chapter 2, “aaa accounting through accounting-server-group Commands,” provides detailed descriptions of the aaa accounting through accounting-server-group commands.

Chapter 3, “activation-key through auto-update timeout Commands,” provides detailed descriptions of the activation-key through auto-update timeout commands.

Chapter 4, “backup-servers through bridge-group Commands,” provides detailed descriptions of the

backup-servers through bridge-group commands.

Chapter 5, “cache-time through clear capture Commands,” provides detailed descriptions of the

cache-time through clear capture commands

Chapter 6, “clear configure through clear configure virtual Commands,” provides detailed descriptons of the clear configure through clear configure virtual commands.

Chapter 7, “clear console-output through clear xlate Commands,” provides detailed descriptons of the clear console-output through clear xlate commands.

Chapter 8, “client-access-rule through crl-configure Commands,” provides detailed descriptons of the client-access-rule through crl-configure commands.

Chapter 9, “crypto ca authenticate through crypto map set trustpoint Commands,” provides detailed descriptons of the crypto ca authenticate through crypto map set trustpoint commands.

Chapter 10, “debug aaa through debug sip Commands,” provides detailed descriptons of the debug aaa through debug sip commands.

• Chapter 11, “default through drop Commands,” provides detailed descriptons of the default

through drop commands.

Chapter 12, “email through ftp-map Commands,” provides detailed descriptons of the email

through ftp-map commands.

Chapter 13, “gateway through http-map Commands,” provides detailed descriptons of the gateway

through http-map commands.

• Chapter 14, “icmp through ignore lsa mospf Commands,” provides detailed descriptons of the icmp

through ignore lsamospf commands.

Chapter 15, “inspect ctiqbe through inspect xdmcp Commands,” provides detailed descriptons of the inspect ctiqbe through inspect xdmcp commands.

Chapter 16, “interface through issuer-name Commands,” provides detailed descriptons of the

interface through issuer-name commands.

Chapter 17, “join-failover-group through kill Commands,”provides detailed descriptons of the

join-failover-group through kill commands.

Chapter 18, “ldap-base-dn through log-adj-changes Commands,” provides detailed descriptons of the ldap-base-dn through log-adj-changes commands.

Chapter 19, “logging asdm through logout Commands,” provides detailed descriptons of the inspect ctiqbe through inspect xdmcp commands.

(35)

About This Guide

Document Conventions

Chapter 21, “name through ospf transmit-delay Commands,” provides detailed descriptons of the

name through ospf transmit-delaycommands.

Chapter 22, “pager through pwd Commands,” provides detailed descriptons of the passwd through

pwd commands.

Chapter 23, “queue-limit through router-id Commands,” provides detailed descriptons of the

queue-limit through router-id commands.

Chapter 24, “same-security-traffic through show asdmsessions Commands,” provides detailed descriptons of the same-security-traffic through show asdm sessions commands.

Chapter 25, “show asp drop through show curpriv Commands,” provides detailed descriptons of the

show asp drop through show curpriv commands.

Chapter 26, “show debug through show ipv6 traffic Commands,” provides detailed descriptons of the show debug through show ipv6 traffic commands.

Chapter 27, “show isakmp sa through show route Commands,” provides detailed descriptons of the

show isakmp sa through show route commands.

Chapter 28, “show running-config through show running-config isakmp Commands,” provides detailed descriptons of the show running-config through show running-config isakmp

commands.

Chapter 29, “show running-config logging through show running-config vpn-sessiondb Commands,” provides detailed descriptons of the show running-config logging through show running-config vpn-sessionb commands.

Chapter 30, “show service-policy through show xlate Commands,” provides detailed descriptons of the show service-policy through show xlate commands.

Chapter 31, “shun through sysopt uauth allow-http-cache Commands,” provides detailed descriptons of the shun through sysopt unauth allow-http-cache commands.

Chapter 32, “tcp-map through tunnel-limit Commands,” provides detailed descriptons of the

tcp-map through tunnel-limit commands.

Chapter 33, “upgrade-mp through write terminal Commands,” provides detailed descriptons of the

upgrade-mp through write terminal commands.

Document Conventions

The FWSM command syntax descriptions use the following conventions: Command descriptions use these conventions:

Braces ({ }) indicate a required choice.

Square brackets ([ ]) indicate optional elements.

Vertical bars ( | ) separate alternative, mutually exclusive elements.

Boldface indicates commands and keywords that are entered literally as shown.

Italics indicate arguments for which you supply values. Examples use these conventions:

Examples depict screen displays and the command line in screen font.

Information you need to enter in examples is shown in boldfacescreen font.

(36)

About This Guide Related Documentation

Examples might include output from different platforms; for example, you might not recognize an interface type in an example because it is not available on your platform. Differences should be minor.

Note Means reader take note. Notes contain helpful suggestions or references to material not covered in the manual.

For information on modes, prompts, and syntax, see Chapter 1, “Using the Command-Line Interface.”

Related Documentation

For more information, refer to the following documentation:

Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide

Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Logging Configuration and System Log Messages

Upgrading the Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module to Release 3.1

Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Release Notes

Cisco ASDM Release Notes

Obtaining Documentation

Cisco documentation and additional literature are available on Cisco.com. Cisco also provides several ways to obtain technical assistance and other technical resources. These sections explain how to obtain technical information from Cisco Systems.

Cisco.com

You can access the most current Cisco documentation at this URL:

http://www.cisco.com/techsupport

You can access the Cisco website at this URL:

http://www.cisco.com

You can access international Cisco websites at this URL:

http://www.cisco.com/public/countries_languages.shtml

Product Documentation DVD

(37)

About This Guide

Documentation Feedback

The Product Documentation DVD is a comprehensive library of technical product documentation on portable media. The DVD enables you to access multiple versions of hardware and software installation, configuration, and command guides for Cisco products and to view technical documentation in HTML. With the DVD, you have access to the same documentation that is found on the Cisco website without being connected to the Internet. Certain products also have .pdf versions of the documentation available. The Product Documentation DVD is available as a single unit or as a subscription. Registered Cisco.com users (Cisco direct customers) can order a Product Documentation DVD (product number

DOC-DOCDVD=) from Cisco Marketplace at this URL:

http://www.cisco.com/go/marketplace/

Ordering Documentation

Beginning June 30, 2005, registered Cisco.com users may order Cisco documentation at the Product Documentation Store in the Cisco Marketplace at this URL:

http://www.cisco.com/go/marketplace/

Nonregistered Cisco.com users can order technical documentation from 8:00 a.m. to 5:00 p.m. (0800 to 1700) PDT by calling 1 866 463-3487 in the United States and Canada, or elsewhere by calling 011 408 519-5055. You can also order documentation by e-mail at

[email protected] or by fax at 1 408 519-5001 in the United States and Canada, or elsewhere at 011 408 519-5001.

Documentation Feedback

You can rate and provide feedback about Cisco technical documents by completing the online feedback form that appears with the technical documents on Cisco.com.

You can send comments about Cisco documentation to [email protected].

You can submit comments by using the response card (if present) behind the front cover of your document or by writing to the following address:

Cisco Systems

Attn: Customer Document Ordering 170 West Tasman Drive

San Jose, CA 95134-9883 We appreciate your comments.

Cisco Product Security Overview

Cisco provides a free online Security Vulnerability Policy portal at this URL:

http://www.cisco.com/en/US/products/products_security_vulnerability_policy.html

From this site, you can perform these tasks:

Report security vulnerabilities in Cisco products.

Obtain assistance with security incidents that involve Cisco products.

Register to receive security information from Cisco.

(38)

About This Guide Obtaining Technical Assistance

http://www.cisco.com/go/psirt

If you prefer to see advisories and notices as they are updated in real time, you can access a Product Security Incident Response Team Really Simple Syndication (PSIRT RSS) feed from this URL:

http://www.cisco.com/en/US/products/products_psirt_rss_feed.html

Reporting Security Problems in Cisco Products

Cisco is committed to delivering secure products. We test our products internally before we release them, and we strive to correct all vulnerabilities quickly. If you think that you might have identified a vulnerability in a Cisco product, contact PSIRT:

Emergencies —[email protected]

An emergency is either a condition in which a system is under active attack or a condition for which a severe and urgent security vulnerability should be reported. All other conditions are considered nonemergencies.

Nonemergencies —[email protected]

In an emergency, you can also reach PSIRT by telephone:

1 877 228-7302

1 408 525-6532

Tip We encourage you to use Pretty Good Privacy (PGP) or a compatible product to encrypt any sensitive information that you send to Cisco. PSIRT can work from encrypted information that is compatible with PGP versions 2.x through 8.x.

Never use a revoked or an expired encryption key. The correct public key to use in your correspondence with PSIRT is the one linked in the Contact Summary section of the Security Vulnerability Policy page at this URL:

http://www.cisco.com/en/US/products/products_security_vulnerability_policy.html

The link on this page has the current PGP key ID in use.

Obtaining Technical Assistance

(39)

About This Guide

Obtaining Technical Assistance

Cisco Technical Support & Documentation Website

The Cisco Technical Support & Documentation website provides online documents and tools for troubleshooting and resolving technical issues with Cisco products and technologies. The website is available 24 hours a day, at this URL:

http://www.cisco.com/techsupport

Access to all tools on the Cisco Technical Support & Documentation website requires a Cisco.com user ID and password. If you have a valid service contract but do not have a user ID or password, you can register at this URL:

http://tools.cisco.com/RPF/register/register.do

Note Use the Cisco Product Identification (CPI) tool to locate your product serial number before submitting a web or phone request for service. You can access the CPI tool from the Cisco Technical Support & Documentation website by clicking the Tools & Resources link under Documentation & Tools.Choose

Cisco Product Identification Tool from the Alphabetical Index drop-down list, or click the Cisco Product Identification Tool link under Alerts & RMAs. The CPI tool offers three search options: by product ID or model name; by tree view; or for certain products, by copying and pasting show command output. Search results show an illustration of your product with the serial number label location highlighted. Locate the serial number label on your product and record the information before placing a service call.

Submitting a Service Request

Using the online TAC Service Request Tool is the fastest way to open S3 and S4 service requests. (S3 and S4 service requests are those in which your network is minimally impaired or for which you require product information.) After you describe your situation, the TAC Service Request Tool provides recommended solutions. If your issue is not resolved using the recommended resources, your service request is assigned to a Cisco engineer. The TAC Service Request Tool is located at this URL:

http://www.cisco.com/techsupport/servicerequest

For S1 or S2 service requests or if you do not have Internet access, contact the Cisco TAC by telephone. (S1 or S2 service requests are those in which your production network is down or severely degraded.) Cisco engineers are assigned immediately to S1 and S2 service requests to help keep your business operations running smoothly.

To open a service request by telephone, use one of the following numbers: Asia-Pacific: +61 2 8446 7411 (Australia: 1 800 805 227)

EMEA: +32 2 704 55 55 USA: 1 800 553-2447

For a complete list of Cisco TAC contacts, go to this URL:

http://www.cisco.com/techsupport/contacts

Definitions of Service Request Severity

(40)

About This Guide Obtaining Additional Publications and Information

Severity 1 (S1)—Your network is “down,” or there is a critical impact to your business operations. You and Cisco will commit all necessary resources around the clock to resolve the situation.

Severity 2 (S2)—Operation of an existing network is severely degraded, or significant aspects of your business operation are negatively affected by inadequate performance of Cisco products. You and Cisco will commit full-time resources during normal business hours to resolve the situation.

Severity 3 (S3)—Operational performance of your network is impaired, but most business operations remain functional. You and Cisco will commit resources during normal business hours to restore service to satisfactory levels.

Severity 4 (S4)—You require information or assistance with Cisco product capabilities, installation, or configuration. There is little or no effect on your business operations.

Obtaining Additional Publications and Information

Information about Cisco products, technologies, and network solutions is available from various online and printed sources.

Cisco Marketplace provides a variety of Cisco books, reference guides, documentation, and logo merchandise. Visit Cisco Marketplace, the company store, at this URL:

http://www.cisco.com/go/marketplace/

Cisco Press publishes a wide range of general networking, training and certification titles. Both new and experienced users will benefit from these publications. For current Cisco Press titles and other information, go to Cisco Press at this URL:

http://www.ciscopress.com

Packet magazine is the Cisco Systems technical user magazine for maximizing Internet and networking investments. Each quarter, Packet delivers coverage of the latest industry trends, technology breakthroughs, and Cisco products and solutions, as well as network deployment and troubleshooting tips, configuration examples, customer case studies, certification and training information, and links to scores of in-depth online resources. You can access Packet magazine at this URL:

http://www.cisco.com/packet

iQ Magazine is the quarterly publication from Cisco Systems designed to help growing companies learn how they can use technology to increase revenue, streamline their business, and expand services. The publication identifies the challenges facing these companies and the technologies to help solve them, using real-world case studies and business strategies to help readers make sound technology investment decisions. You can access iQ Magazine at this URL:

http://www.cisco.com/go/iqmagazine

or view the digital edition at this URL:

http://ciscoiq.texterity.com/ciscoiq/sample/

Internet Protocol Journal is a quarterly journal published by Cisco Systems for engineering professionals involved in designing, developing, and operating public and private internets and intranets. You can access the Internet Protocol Journal at this URL:

http://www.cisco.com/ipj

Networking products offered by Cisco Systems, as well as customer support services, can be obtained at this URL:

(41)

About This Guide

Obtaining Additional Publications and Information

Networking Professionals Connection is an interactive website for networking professionals to share questions, suggestions, and information about networking products and technologies with Cisco experts and other networking professionals. Join a discussion at this URL:

http://www.cisco.com/discuss/networking

World-class networking training is available from Cisco. You can view current offerings at this URL:

(42)
(43)

C H A P T E R

1

Using the Command-Line Interface

This describes how to use the CLI on the FWSM, and includes the following topics:

Firewall Mode and Security Context Mode, page 1-1

Command Modes and Prompts, page 1-2

Syntax Formatting, page 1-3

Abbreviating Commands, page 1-3

Command-Line Editing, page 1-3

Command Completion, page 1-3

Command Help, page 1-4

Filtering show Command Output, page 1-4

Command Output Paging, page 1-5

Adding Comments, page 1-5

Text Configuration Files, page 1-6

Note The CLI uses similar syntax and other conventions to the Cisco IOS CLI, but the FWSM operating system is not a version of Cisco IOS software. Do not assume that a Cisco IOS CLI command works with or has the same function on the FWSM.

Firewall Mode and Security Context Mode

The FWSM runs i

Figure

Table 1-1Syntax Conventions
Table 1-2Using Special Characters in Regular Expressions
Table 2-1ICMP Type Literals
table is used with ARP inspection (see the arp-inspection command).
+7

References

Related documents