![]() |
CSS 11000 SCA Versions 3.2.0 and 3.1.0
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Command Summary
![]() |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Table of ContentsCommand SummaryInput Data Format Specification
Text Conventions Editing and Completion Features Command Hierarchy Configuration Security Methods to Manage the Device Initiating a Management Session Using the Remote Configuration Manager Top Level Command Set Non-Privileged Command Set
Group Configuration Command Setattach
Privileged Command Setattach ip clear screen cls discover enable exit group help monitor paws ping quit set monitor-interval set on-prefix show arp show copyrights show cpu show date show device show device list show dns show flow show group show history show interface show interface errors show interface statistics show ip domain-name show ip name-server show ip routes show ip statistics show keepalive-monitor show memory show messages show netstat show processes show profile show rdate-server show remote-management show rip show route show sessions show sntp-server show ssl show ssl cert show ssl certgroup show ssl errors show ssl key show ssl secpolicy show ssl server show ssl session-stats show ssl statistics show syslog show system-resources show telnet show terminal show version show web-management terminal baud terminal history terminal length terminal pager terminal reset terminal width traceroute clear interface statistics
clear ip routes clear ip statistics clear line clear messages clear ssl session-stats clear ssl statistics configure copy running-configuration copy running-configuration startup-configuration copy startup-configuration copy startup-configuration running-configuration copy to flash copy to running-configuration copy to startup-configuration disable erase running-configuration erase startup-configuration quick-start refresh reload show access-list show running-configuration show snmp show startup-configuration write file write flash write memory write messages write network write terminal Configuration Command Set access-list
end exit finished help hostname interface ip address ip domain-name ip name-server ip route ip route default keepalive-monitor mode one-port mode pass-thru password rdate-server registration-code remote-management access-list remote-management enable remote-management encryption remote-management port remote-management shared-secret rip no snmp snmp access-list snmp contact snmp default community snmp enable snmp location snmp trap-host snmp trap-type enterprise snmp trap-type generic sntp-server ssl syslog telnet access-list telnet enable telnet port timezone web-mgmt access-list web-mgmt enable web-mgmt port Interface Configuration Command Set SSL Configuration Command Set backend-server
Backend Server Configuration Command Setcert certgroup end finished gencsr help import pkcs12 import pkcs7 key reverse-proxy-server secpolicy server activate
Certificate Configuration Command Setcertgroup serverauth end exit finished help info ip address localport log-url remoteport secpolicy serverauth enable serverauth ignore session-cache enable session-cache size session-cache timeout suspend transparent Certificate Group Configuration Command Set Key Configuration Command Set Reverse-Proxy Server Configuration Command Set activate
Security Policy Configuration Command Setcertgroup serverauth end exit finished help info localport log-url secpolicy serverauth enable serverauth ignore session-cache enable session-cache size session-cache timeout suspend Server Configuration Command Set activate
cert certgroup chain certgroup clientauth clientauth enable clientauth error clientauth verifydepth end ephrsa exit finished help httpheader info ip address key localport log-url redirect remoteport secpolicy session-cache enable session-cache size session-cache timeout sslport suspend transparent Command SummaryThis appendix contains a categorized complete listing of CLI configuration manager commands for the Secure Content Accelerator. Each command is described and, where appropriate, an example of usage is included. Some commands are available only with specific configuration connection methods. Availability of each command is indicated. Configuration using the GUI is described in Chapter 6. This appendix contains the following sections:
Input Data Format SpecificationTable C-1 describes the data formats acceptable for most commands. Table C-1: Input Data Formats
"H" is one or more hexadecimal digit [0-F] and "D" is one or more decimal digit. Text ConventionsBold text indicates a command in a paragraph.
Courier bold text indicates commands and text you enter in a command line. Italic text indicates the first occurrence of a new term, book title, and emphasized text. In this command summary, items presented in italics represent user-specified information. Items within angle brackets ("<>") are required information. Items within square brackets ("[]") are optional information. Items separated by a vertical bar ("|") are options. You can choose any of them.
Editing and Completion FeaturesYou can use individual keys and control-key combinations to help you work with the Command Line Interface (CLI). Table C-2 describes the key and key combination functions. Table C-2: Key Reference
Most configuration commands require completing all fields in the command. For commands that have several possible completers, the TAB or ? keys display all options. SCA> show [TAB] access-list ip route arp keep-alive monitor running-configuration copyrights memory snmp cpu messages ssl device netstat syslog dns processes system-resources group profile terminal history remote-management version interface rip The TAB key can also be used to finish a command if the command is uniquely identified by user input. SCA> show cop[TAB] results in SCA> show copyrights Additionally, commands may be abbreviated as long as the partial commands are unique. The following text: SCA> sho dev lis is an acceptable abbreviation for SCA> show device list
Command HierarchyThe CLI configuration manager allows you to control hardware and SSL portions of the appliance through a discreet mode and submode system. The commands for the Secure Content Accelerator device fit into the logical hierarchy show in Figure C-1. Figure C-1: Command Hierarchy
To configure items in a submode, activate the submode by entering a command in the mode above it. For example, to set the network interface speed or duplex you must first enter enable, configure, then interface network. To return to the higher Configuration mode, simply enter end or exit or press CTRL+D. The finished command returns to the Top Level from any mode. Appendix C lists all commands for SSL devices. Configuration SecurityCisco Secure Content Accelerator devices allow easy, flexible configuration without compromising the security of your network or their own configuration. PasswordsSSL devices are shipped without passwords. Setting passwords is important because the device can be administered over a network. For more information about passwords, see the commands password access and password enable in Appendix C. Access ListsAccess lists control which computers can attach to a specific device. No access lists exist when you first install the Secure Content Accelerator. You can restrict the computers allowed to manage the appliance by adding their IP addresses to one or more access lists for each device. For more information about configuring access lists, see the commands show access-list, access-list, snmp access-list, remote-management access-list, telnet access-list, and web-mgmt access-list in Appendix C. Encrypted Management SessionsTo further protect the configuration security, you can specify that remote (non-serial and non-telnet) configuration sessions be encrypted using AES, DES, or ARC4. See remote-management encryption in Appendix C. Factory Default Reset Password
Methods to Manage the DeviceYou can configure the Cisco Secure Content Accelerator using one of four methods, three of which use the CLI configuration manager.
Additionally, the behaviors of some commands vary depending upon the management method. The configuration information for the commands ip name-server, rdate-server, and ip domain-name can be set remotely, but the configuration information is used only through a serial or telnet connection. The results of the ping and traceroute commands also are dependent upon the management method. When used with the remote management application, these commands are executed and results returned based upon the configuring computer's hardware information. When used with serial or telnet management, the results are based upon the SSL appliance's hardware information. File name formats differ depending on the management method. When using remote management, you can specify the file name as it appears in the configuring computer's file system. A path must be included, if necessary. When using serial or telnet management, the file name must be entered in any of the following formats: [<http:// | ftp:// | https:// | tftp:// >] URL In situations where a file is written, anonymous write access must be configured on the system with these caveats:
Additionally, we provide a guided QuickStart wizard configuration method, available from both the configuration manager and GUI. To use this method for configuration, see Chapter 4. Brief instructions are also included for initiating a management session using the configuration manager. For instructions on using any of the CLI configuration managers, see Chapter 5 for instructions on using the GUI, see Chapter 6. Initiating a Management SessionSerial Management and IP Address Assignment1. Attach the included null modem cable to the appliance port marked "CONSOLE". Attach the other end of the null modem cable to a serial port on the configuring computer. 2. Launch any terminal emulation application that communicates with the serial port connected to the appliance. Use these settings: 9,600 baud, 8 data bits, no parity, 1 stop bit, no flow control. 3. Press Return. Initial information is displayed followed by an 4. Enter Privileged and Configuration modes and set the IP address using the following commands. Replace the IP address in the example with the appropriate one. SCA> enable SCA# configure (config[SCA])# ip address 10.1.2.5 (config[SCA])#
Telnet1. Initiate a telnet session with the IP address previously assigned to the appliance. 2. An SCA> prompt is displayed.
Running the Remote Configuration ManagerUse the appropriate instructions below to run the CLI configuration manager. LinuxEnter csacfg at a Linux shell prompt. SolarisEnter csacfg at a Unix shell prompt. Windows NT and Windows 2000 SoftwareTo start the configuration manager, use the Start menu and point to Programs>Cisco Systems and click Cisco Secure Content Acc. Manager, or double-click the shortcut on the desktop. Using the Remote Configuration ManagerType Key Name Version MacAddr IPaddr Cisco Secure Content Accelerator devices are listed with the "CSS-SCA" device type. Note the MAC address of the device you wish to configure. It is used with the "CS-" prefix to identify a specific device when giving commands in the format CS-macaddress, where macaddress is the MAC address of the device.
Specifying DevicesFor example, entering show device list returns the following list of unattached devices: CSS-SCA Ru sslDev1 ... CSS-SCA Ru sslDev2 ... CSS-SCA Ru sslDev3 ... CSS-SCA Ru sslDev4 ... To attach the configuration manager to the device sslDev3, enter this command: on sslDev3 attach The auto completer function can assist data entry. See "Editing and Completion Features" in Appendix C for details for using editing and auto completer features. Working with Device Groupscsacfg> group myGroup create (group[myGroup])> device sslDev1 (group[myGroup])> device sslDev2 (group[myGroup])> device sslDev4 (group[myGroup])> info group name: myGroup number of devices: 3 device: sslDev1 device: sslDev2 device: sslDev4 (group[myGroup])> To remove a device from the group, use the no form of the command: (group[myGroup])> no device sslDev2 Enter end to leave Group configuration mode. To send commands to every device in the group, use the on prefix. on myGroup attach set on-prefix myGroup After entering this command, you do not need to use the on prefix when addressing the default target. For example, the on myGroup attach command becomes attach. You can still address another group instead of the default; simply specify its name following the on prefix. Change the on prefix target by re-entering the command, identifying the new group. View the on prefix target by entering show profile.
For more information about Group Configuration commands, see "Group Configuration Command Set" in Appendix C. Remote Configuration CachingTop Level Command SetNon-Privileged Command SetattachAttaches or detaches the configuration manager from one or more devices. attachno attach on <devname|groupname|all> attach on <devname|groupname|all> no attach Syntax Description
Usage Guidelines Availability: Remote Use the simple attach form of the command to attach to a single found device. Use the no form of the command to detach the configuration manager from a single attached device. If an access-level password has been defined, you must enter it when prompted before the configuration manager will attach to the device(s). If a shared secret passphrase has been assigned as part of remote management encryption, you are prompted for it. When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate.
Related Commands attach ip (Non-Privileged Command Set) attach ipAttaches or detaches the configuration manager from one or more devices using an alternate remote management port. attach ip <ipaddr> [port <portid>]no attach ip <ipaddr> Syntax Description
Usage Guidelines Availability: Remote Use the port option to specify a TCP/UDP service port to use for attaching to the device. The remote-management port command must have been used on the device to change the management port from the default. If a shared secret passphrase has been assigned as part of remote management encryption, you are prompted for it. Use the no form of the command to detach the configuration manager from the specified device. If an access-level password has been defined, you must enter it when prompted before the configuration manager can attach to the device.
Related Commands attach (Non-Privileged Command Set) clear screenClears the display, leaving only one prompt line. clear screenUsage Guidelines Availability: Remote, Serial, Telnet clsClears the display, leaving only one prompt line. clsUsage Guidelines Availability: Remote, Serial, Telnet discoverChecks the network for new remote devices on the default or, optionally, on the specified TCP service port when using an alternate remote management port. discover [port <portid>]Syntax Description
Usage Guidelines Availability: Remote Use the port option to specify a TCP service port to search for devices when using an alternate remote management port. Related Commands remote-management port (Configuration Command Set) enableEnters or leaves Privileged Mode for one or more attached device. enableno enable on <devname|groupname|all> enable on <devname|groupname|all> no enable Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If an enable-level password has been defined, you must enter it when prompted. When using remote management, enters Privileged mode for a single, attached device. Using the no form of this command leaves Privileged mode. When using remote configuration, use the on form of the command to specify the target(s) of the command when more than one device is appropriate.
Related Commands attach (Non-Privileged Command Set) exitQuits the configuration manager. exitUsage Guidelines Availability: Remote, Serial, Telnet When executed from the remote configuration manager, closes the configuration manager. When executed from a serial connection, the connection is not closed. If an access password has been configured, you are prompted for it. When executed from telnet, the telnet connection is closed. Related Commands quit (Non-Privileged Command Set) groupCreates or configures the specified user-defined device group. group <groupname> [create]no group <groupname> Syntax Description
Usage Guidelines Availability: Remote Use the create flag to create the specified group and enter Group Configuration mode for it. Use the no form of the command to remove the specified group. Related Commands See also "Group Configuration Command Set". helpDisplays help information for the specified command. help [command]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If no command is specified, help information is displayed for all Non-Privileged commands. When using remote configuration, help information is displayed for all Top Level commands. monitorDisplays the results of the specified show command at one second intervals. monitor <command>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet The interval between refreshes is set using the set monitor-interval command. Related Commands set monitor-interval (Non-Privileged Command Set) pawsPauses the configuration manager for a specified time or until a key is pressed. pawsUsage Guidelines Availability: Remote, Serial, Telnet pingSends ICMP packets to the specified IP address. ping <ipaddr|name>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet The host name can be used remotely if a domain name has been assigned for the device. When issued from a serial or telnet connection, the command returns information based upon the hardware of the Secure Content Accelerator. When issued from a remote management connection, the command returns information based upon the configuring computer. Related Commands ip name-server (Configuration Command Set) quitQuits the configuration manager. quitUsage Guidelines Availability: Remote, Serial, Telnet When executed from the remote configuration manager, closes the configuration manager. When executed from a serial connection, the connection is not closed. If an access password has been configured, you are prompted for it. When executed from telnet, the telnet connection is closed. Related Commands exit (Non-Privileged Command Set) set monitor-intervalSets the number of seconds between monitor-prefixed command refreshes. set monitor-interval <value>no set monitor-interval Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Use the no form of the command to return the monitor interval to default value. Related Commands monitor (Non-Privileged Command Set) set on-prefixSets the entity to address as default when using the on prefix. set on-prefix <devname|groupname|all>no set on-prefix Syntax Description
Usage Guidelines Availability: Remote Use the no form of the command to clear the default entity. Related Commands group (Non-Privileged Command Set) show arpDisplays the ARP cache on the specified device. show arpon <devname|groupname|all> show arp Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. show copyrightsDisplays copyright information for software and hardware products. show copyrightsUsage Guidelines Availability: Remote, Serial, Telnet Related Commands show version (Non-Privileged Command Set) show cpuDisplays CPU utilization information for one or more devices. show cpu [continuous] [interval <value>]on <devname|groupname|all> show cpu [continuous] [interval <value>] Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Use the continuous option to have statistics displayed continuously, updated at one-second intervals. Use the interval option to specify an interval for display updates. Press any key to stop displaying statistics. When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. show dateDisplays current date and time settings on the device. show dateUsage Guidelines Availability: Serial, Telnet Related Commands rdate-server (Configuration Command Set) show deviceDisplays information about the specified device(s). show deviceon <devname|groupname|all> show device Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. show device listDisplays summary information for all Secure Content Accelerators in the same broadcast domain as the configuring computer or found by the configuration manager after launching the configuration manager and using the discover command. show device listUsage Guidelines Availability: Remote Devices are listed in the following format: Type Key Name Version MacAddr IPaddr Note the MAC address of the device you wish to configure. It is used with the "CS-" prefix to identify a specific device when giving commands. Related Commands discover (Non-Privileged Command Set) show dnsDisplays DNS configuration information for one or more devices. show dnson <devname|groupname|all> show dns Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands ip domain-name (Configuration Command Set) show flowDisplays IP connection information for one or more devices. show flowon <devname|groupname|all> show flow Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. show groupDisplays group summary information for the specified group. show group [groupname]Syntax Description
Usage Guidelines Availability: Remote If a group is not specified, information is displayed for all groups. Related Commands group (Non-Privileged Command Set) show historyDisplays the last commands executed. show historyUsage Guidelines Availability: Remote, Serial, Telnet Related Commands show terminal (Top Level Command Set) show interfaceDisplays information for the specified Ethernet interface on one or more devices. show interface [network | server]on <devname|groupname|all> show interface [network | server] Syntax Description
Usage Guidelines The information includes connection, duplex, speed, and autonegotiation settings. If a single interface is not specified, information is displayed for all interfaces on the device(s). When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands show interface errors (Non-Privileged Command Set) show interface errorsDisplays error information for the specified Ethernet interface on one or more devices. show interface errors [network | server] [continuous] [interval <value>]on <devname|groupname|all> show interface errors [network | server] [continuous] [interval <value>] Syntax Description
Usage Guidelines If a single interface is not specified, errors are displayed for both interfaces. If continuous is specified, error statistics are updated every second. Use the interval option to specify an interval for display updates. Press any key to stop displaying errors. When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands show interface (Non-Privileged Command Set) show interface statisticsDisplays interface statistics for one or more devices. show interface statistics [network | server] [continuous] [interval <value>]on <devname|groupname|all> show interface statistics [network | server] [continuous] [interval <value>] Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If a single interface is not specified, statistics are displayed for both interfaces. If continuous is specified, statistics are updated every second. Use the interval option to specify an interval for display updates. Press any key to stop displaying statistics. When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands show interface (Non-Privileged Command Set) show ip domain-nameDisplays DNS configuration information for one or more devices. show ip domain-nameon <devname|groupname|all> show ip domain-name Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands ip domain-name (Configuration Command Set) show ip name-serverDisplays DNS configuration information for one or more devices. show ip name-serveron <devname|groupname|all> show ip name-server Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command when more than one device is appropriate. Related Commands ip domain-name (Configuration Command Set) show ip routesDisplays the routing table stored in one or more devices. show ip routeson <devname|groupname|all> show ip routes Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands show route (Non-Privileged Command Set) show ip statisticsDisplays diagnostic IP, ICMP, TCP, and UDP statistics for one or more devices. show ip statisticson <devname|groupname|all> show ip statistics Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. show keepalive-monitorDisplays a list of keepalive-monitor IP addresses for one or more devices. show keepalive-monitoron <devname|groupname|all> show keepalive-monitor Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet SSL errors from IP addresses specified with the keepalive-monitor command are ignored. When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands keepalive-monitor (Configuration Command Set) show memoryDisplays memory usage on one or more devices. show memory [zones]on <devname|groupname|all> show memory [zones] Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet The zones flag is used to display information for each memory zone. When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. show messagesDisplays the diagnostic message buffer for one or more devices. show messageson <devname|groupname|all> show messages Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands clear messages (Non-Privileged Command Set) show netstatDisplays the current state of the IP connection for one or more devices. show netstaton <devname|groupname|all> show netstat Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. show processesDisplays information, by thread, about processes running on one or more devices. show processeson <devname|groupname|all> show processes Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. show profileDisplays the monitor-interval and on-prefix settings of the if they have been changed from the default settings. show profile [all]Syntax Description
Usage Guidelines Availability: Remote Use the all keyword to display the current configuration of both the monitor-interval and on-prefix. Related Commands monitor (Non-Privileged Command Set) show rdate-serverDisplays the IP address of the RDATE protocol server configuration for one or more devices. show rdate-serveron <devname|groupname|all> show rdate-server Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. show remote-managementDisplays remote management information for one or more devices. show remote-managementon <devname|groupname|all> show remote-management Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands remote-management access-list (Configuration Command Set) show ripDisplays the RIP status of one or more devices. show ripon <devname|groupname|all> show rip Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands rip (Configuration Command Set) show routeDisplays the routing table stored in one or more devices. show routeon <devname|groupname|all> show route Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands show ip routes (Top Level Command Set) show sessionsDisplays current remote configuration manager, serial, and telnet management connections to the device. show sessionsUsage Guidelines Availability: Serial, Telnet Related Commands clear line (Privileged Command Set) show sntp-serverDisplays SNTP-server information for one or more devices. The SNTP server is used for date and time information. show sntp-serveron <devname|groupname|all> show sntp-server Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands sntp-server (Configuration Command Set) show sslDisplays SSL summary data for one or more devices. show sslon <devname|groupname|all> show ssl Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands show ssl cert (Non-Privileged Command Set) show ssl certDisplays summary data for the specified certificate entity loaded on one or more devices. show ssl cert [certname]on <devname|groupname|all> show ssl cert [certname] Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not specify a certificate name, all certificate entity information is displayed When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands show ssl (Non-Privileged Command Set) show ssl certgroupDisplays summary data for the specified certificate group loaded on one or more devices. show ssl certgroup [certgroupname]on <devname|groupname|all> show ssl certgroup [certgroupname] Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not specify a certificate group, all certificate group information is displayed. When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands show ssl (Non-Privileged Command Set) show ssl errorsDisplays SSL errors reported on one or more devices. show ssl errors [continuous] [interval <value>]on <devname|groupname|all> show ssl errors [continuous] [interval <value>] Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet (This command must be given on one line.) Displays SSL errors reported on a single device or module. Use the continuous keyword to update the statistics every second. Use the interval keyword to specify an interval for display updates, where value is the interval in seconds. Press any key to stop displaying errors. When using remote configuration, use the on form of the command to specify the target(s) of the command, where devname is the name of a single device or module, groupname is the name of a user-defined device group, and all represents all appropriate devices and modules. The errors displayed when using the continuous or interval keywords are:
Related Commands keepalive-monitor (Configuration Command Set) show ssl keyDisplays summary data for the specified private key loaded on one or more devices. show ssl key [keyname]on <devname|groupname|all> show ssl key [keyname] Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not specify a key name, all key information is displayed. When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands show ssl (Non-Privileged Command Set) show ssl secpolicyDisplays summary data for the specified security policy on one or more devices. show ssl secpolicy [polname]on <devname|groupname|all> show ssl secpolicy [polname] Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not specify a security policy name, all security policy information is displayed. When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands show ssl (Non-Privileged Command Set) show ssl serverDisplays information for the specified configured logical secure server of type server, reverse-proxy server, or backend server on one or more devices. show ssl server [servname]on <devname|groupname|all> show ssl server [servname] Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not specify a secure server name, all secure server information is displayed. When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands show ssl (Non-Privileged Command Set) show ssl session-statsDisplays SSL session statistics summed over all secure logical servers on one or more devices. show ssl session-stats [continuous] [interval <value>]on <devname|groupname|all> show ssl session-stats [continuous] [interval <value>] Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Use the continuous keyword to update the statistics every second. Use the interval keyword to specify an interval for display updates. Press any key to stop displaying information. When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands show ssl (Non-Privileged Command Set) show ssl statisticsDisplays SSL statistics summed over all secure logical servers on one or more devices. show ssl statistics [continuous] [interval <value>]on <devname|groupname|all> show ssl statistics [continuous] [interval <value>] Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Use the continuous keyword to update the statistics every second. Use the interval keyword to specify an interval for display updates. Press any key to stop displaying information. When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. The statistics displayed when using the continuous or interval keywords are:
Related Commands show ssl (Non-Privileged Command Set) show syslogDisplays the list of hosts to which diagnostic messages from one or more devices are sent. show syslogon <devname|groupname|all> show syslog Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands syslog (Configuration Command Set) show system-resourcesDisplays system memory and CPU usage for one or more devices. show system-resources [continuous] [interval <value>]on <devname|groupname|all> show system-resources [continuous] [interval <value>] Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Use the continuous option to update the information every second. Use the interval option to specify an interval for display updates. Press any key to stop displaying information. When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. show telnetDisplays telnet management information for one or more devices. show telneton <devname|groupname|all> show telnet Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands telnet access-list (Configuration Command Set) show terminalDisplays terminal setting information. show terminalUsage Guidelines Availability: Remote, Serial, Telnet Related Commands show history (Non-Privileged Command Set) show versionDisplays configuration manager version information. show versionUsage Guidelines Availability: Remote, Serial, Telnet show web-managementDisplays Web-based GUI management information for one or more devices. show web-managementon <devname|groupname|all> show web-management Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands web-mgmt access-list (Configuration Command Set) terminal baudSets the baud for communicating with the Secure Content Accelerator. terminal baud <1200|2400|4800|9600|19200|38400|115200>Syntax Description
Usage Guidelines Availability: Serial Related Commands show terminal (Non-Privileged Command Set) terminal historySets the number of commands saved in the history buffer. Use the no form of the command to disable the history list. terminal history <length>no terminal history Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet The default is 25. Related Commands show history (Non-Privileged Command Set) terminal lengthSets the number of lines in a terminal window. terminal lengthUsage Guidelines Availability: Remote, Serial, Telnet Related Commands show terminal (Non-Privileged Command Set) terminal pagerEnables the terminal pager. Using the no form of the command disables the pager. terminal pagerno terminal pager Usage Guidelines Availability: Remote, Serial, Telnet Related Commands show terminal (Non-Privileged Command Set) terminal resetResets the internal state of the terminal. terminal resetUsage Guidelines Availability: Remote, Serial, Telnet Related Commands show terminal (Non-Privileged Command Set) terminal widthSets the width of the terminal window. terminal width <width>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Related Commands show terminal (Non-Privileged Command Set) tracerouteDisplays the router hops to the specified destination. traceroute <ipaddr|name>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When issued from a serial or telnet connection, the command returns information based upon the device's hardware. When issued from the remote configuration manager, the command returns information based upon the configuring computer. Privileged Command Setclear interface statisticsResets all interface statistics for one or more devices. clear interface statisticson <devname|groupname|all> clear interface statistics Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands show interface (Non-Privileged Command Set) clear ip routesClears the IP routing table on one or more devices. clear ip routeson <devname|groupname|all> clear ip routes Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands show ip routes (Non-Privileged Command Set) clear ip statisticsResets all IP statistics on one or more devices. clear ip statisticson <devname|groupname|all> clear ip statistics Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands show ip statistics (Non-Privileged Command Set) clear lineCloses a specified management session. clear line <sessionId>Syntax Description
Usage Guidelines Availability: Serial When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Use the show sessions command to display the open management sessions. Related Commands show sessions (Non-Privileged Command Set) clear messagesEmpties the diagnostic message buffer on one or more devices. clear messageson <devname|groupname|all> clear messages Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands show messages (Non-Privileged Command Set) clear ssl session-statsResets all SSL session statistics for one or more devices. clear ssl session-statson <devname|groupname|all> clear ssl session-stats Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands show ssl errors (Non-Privileged Command Set) clear ssl statisticsResets all SSL statistics for one or more devices. clear ssl statisticson <devname|groupname|all> clear ssl statistics Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands show ssl errors (Non-Privileged Command Set) configureEnters Configuration mode for a device in Privileged mode. configureUsage Guidelines Availability: Remote, Serial, Telnet Related Commands See the section "Configuration Command Set". copy running-configurationWrites the running-configuration of a device to a file. copy running-configuration [filename|url]on <devname> copy running-configuration [filename] Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not specify a file name or URL, you are prompted for it. When using remote configuration, use the on form of the command to specify the target of the command if more than one device is appropriate. Related Commands copy running-configuration startup-configuration (Privileged Command Set) copy running-configuration startup-configurationWrites the running-configuration of a device to its startup-configuration. copy running-configuration startup-configurationUsage Guidelines Availability: Serial, Telnet Related Commands copy running-configuration (Privileged Command Set) copy startup-configurationWrites the startup-configuration of a device to a file. copy startup-configuration <url>Syntax Description
Usage Guidelines Availability: Serial, Telnet Related Commands copy running-configuration (Privileged Command Set) copy startup-configuration running-configurationWrites the startup-configuration of a device to its running-configuration. copy startup-configuration running-configurationUsage Guidelines Availability: Serial, Telnet Related Commands copy running-configuration (Privileged Command Set) copy to flashUploads a Cisco Secure Content Accelerator image file to the device flash. copy to flash [filename|url]on <devname> copy to flash [filename] Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not specify a file name or URL, you are prompted for it. When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands copy running-configuration (Privileged Command Set) copy to running-configurationUploads a saved configuration file and merges it to the running-configuration of a device. copy to running-configuration [filename|url]on <devname> copy to running-configuration [filename] Syntax Description
Usage Guidelines Availability: Remote If you do not specify a file name or URL, you are prompted for it. When using remote configuration, use the on form of the command to specify the target of the command if more than one device is appropriate. Related Commands copy running-configuration (Privileged Command Set) copy to startup-configurationUploads a saved configuration file and merges it to the startup-configuration of a device. copy to startup-configuration [url]Syntax Description
Usage Guidelines Availability: Serial, Telnet If you do not specify a URL, you are prompted for it. Related Commands copy running-configuration (Privileged Command Set) disableExits Privileged mode for one or more devices. disableon <devname|groupname|all> disable Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands enable (Non-Privileged Command Set) erase running-configurationErases the running-configuration on one or more devices. erase running-configurationon <devname|groupname|all> erase running-configuration Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands copy running-configuration (Privileged Command Set) erase startup-configurationErases the startup-configuration on one or more devices. erase startup-configurationon <devname|groupname|all> erase startup-configuration Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands copy running-configuration (Privileged Command Set) quick-startRuns the QuickStart wizard for a device. quick-starton <devname> quick-start Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. refreshUpdates device information in the configuration manager. refreshUsage Guidelines Availability: Remote, Serial, Telnet reloadReboots one or more devices. reloadon <devname|groupname|all> reload Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet The device resumes operation using the startup-configuration stored in the flash memory. You are prompted to confirm restarting the device. When using remote configuration, use the on form of the command to specify the target(s) of the command.
show access-listDisplays the specified access list for one or more devices. show access-list [listid]on <devname|groupname|all> show access-list [listid] Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not specify an access list id, information for all access lists is displayed. When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands access-list (Configuration Command Set) show running-configurationDisplays the running-configuration on one or more devices. show running-configurationon <devname|groupname|all> show running-configuration Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands copy running-configuration (Privileged Command Set) show snmpDisplays SNMP configuration information for one or more devices. show snmpon <devname|groupname|all> show snmp Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands no snmp (Configuration Command Set) show startup-configurationDisplays the startup-configuration on a device. show startup-configurationUsage Guidelines Availability: Serial, Telnet Related Commands copy running-configuration startup-configuration (Privileged Command Set) write fileWrites the running-configuration of a device to a file on the file system of the configuring computer. write file [filename]on <devname> write file [filename] Syntax Description
Usage Guidelines Availability: Remote If you do not supply a file name, you are prompted for it. When using remote configuration, use the on form of the command to specify the target of the command if more than one device is appropriate. Related Commands copy running-configuration (Privileged Command Set) write flashWrites the running-configuration to flash memory on one or more devices. write flashon <devname|groupname|all> write flash Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Related Commands copy running-configuration (Privileged Command Set) write memoryWrites the running-configuration to flash memory on a device. write memoryUsage Guidelines Availability: Serial, Telnet Related Commands copy running-configuration startup-configuration (Privileged Command Set) write messagesWrites the diagnostic messages for one or more devices to a file. write messages [filename]on <devname> write messages [filename] Syntax Description
Usage Guidelines Availability: Remote If you do not supply a file name, you are prompted for it. When using remote configuration, use the on form of the command to specify the target of the command if more than one device is appropriate. Related Commands show messages (Non-Privileged Command Set) write networkWrites the running-configuration to a file on a remote host. write network [url]Syntax Description
Usage Guidelines Availability: Serial, Telnet If you do not supply URL information, you are prompted for it. Related Commands copy running-configuration startup-configuration (Privileged Command Set) write terminalDisplays the running-configuration of one or more devices. write terminalon <devname|groupname|all> write terminal Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet When using remote configuration, use the on form of the command to specify the target(s) of the command if more than one device is appropriate. Group Configuration Command SetdeviceAdds the specified device to the group list. device <devname>no device <devname> Syntax Description
Usage Guidelines Availability: Remote Use the no form of the command to remove the specified device from the group list. endLeaves Group Configuration Mode. endUsage Guidelines Availability: Remote exitLeaves Group Configuration Mode. exitUsage Guidelines Availability: Remote finishedExits Group Configuration Mode and returns to Top Level mode. finishedUsage Guidelines Availability: Remote helpDisplays information for a specific command. help [command]Syntax Description
Usage Guidelines Availability: Remote If no command is specified, help information is displayed for all Group Configuration commands. infoDisplays current information about the device group being created or edited. infoUsage Guidelines Availability: Remote Configuration Command Setaccess-listAdds an access list entry to the end of the specified access list. Use the no form of the command to delete the entire specified access list. access-list <id> <permit | deny> <ipaddr> <mask>no access-list <id> Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet To activate the access list, you must also use the remote-management access-list, snmp access-list, telnet access-list, or web-mgmt access-list commands. A device can have up to 999 configured access lists.
Examples The following example specifies the host with the IP address 10.1.2.3 to be the only remote host to configure the Secure Content Accelerator. access-list 2 permit 100.1.2.3 0.0.0.0 The following example specifies only remote hosts on the identified subnet can configure the Secure Content Accelerator. access-list 1 permit 100.128.0.0 0.0.255.255 Related Commands show access-list (Privileged Command Set) endLeaves Configuration Mode and returns to Privileged Mode. endUsage Guidelines Availability: Remote, Serial, Telnet exitLeaves Configuration Mode and returns to Privileged Mode. exitUsage Guidelines Availability: Remote, Serial, Telnet finishedLeaves Configuration Mode and returns to Top Level mode. finishedUsage Guidelines Availability: Remote, Serial, Telnet helpDisplays help information for the specified command. help [command]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not specify a command, help information is displayed for all Configuration commands hostnameSets the identification name for the current Secure Content Accelerator. hostname <devname>no hostname Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Use the no form of the command to clear the hostname of the current device.
interfaceEnters Interface Configuration mode for the specified Ethernet interface of the current device. interface <network|server>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Related Commands show interface (Non-Privileged Command Set) ip addressSets the IP address for the current Secure Content Accelerator. ip address <<ipaddr> [netmask <netmask>]>|<ipaddr/netabbr>>no ip address Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If the netmask is not specified, a default value calculated from the user-provided IP address is used. Use the no form of the command to clear the IP address for the current device. Related Commands ip route default (Configuration Command Set) ip domain-nameSets the default domain name for the device. ip domain-name <name>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Related Commands show ip domain-name (Non-Privileged Command Set) ip name-serverSets the one or more name servers to use with the device. ip name-server <ipaddr>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Related Commands show ip domain-name (Non-Privileged Command Set) ip routeAdds a static route entry for the specified destination IP address to the device routing table. ip route <destip> <mask> <gatewayip> [metric <hops>]no ip route <destip> Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Use the no form of the command to delete the specified static route entry from the device's routing table. Related Commands show ip routes (Non-Privileged Command Set) ip route defaultSets the default route for the current device. ip route default <ipaddr>no ip route default Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Use the no form of the command to clear the IP address for the default router. Related Commands ip address (Configuration Command Set) keepalive-monitorIndicates that SSL errors from the specified IP address are to be ignored. keepalive-monitor <ipaddr>no keepalive-monitor <ipaddr> Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Up to two IP addresses, set individually, are allowed. Related Commands show keepalive-monitor (Non-Privileged Command Set) mode one-portEnables secure and non-secure traffic to pass through the single "Network" Ethernet port. Use the no form of the command to return the device to dual-port mode. mode one-portno mode one-port Usage Guidelines Availability: Serial Use the no form of the command to clear the IP address.
mode pass-thruEnables pass through of non-SSL traffic. This is the default configuration. mode pass-thruno mode pass-thru Usage Guidelines Availability: Remote, Serial, Telnet Use the no form of the command to block non-SSL traffic pass through. passwordSets the access- or enable-level password for the current Secure Content Accelerator. password <access|enable>no password <access|enable> Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet The access password is used when attaching to the device during a remote management session.You are prompted to enter and verify the password. Use the no form of the command to clear the access- or enable-level password for the current device. rdate-serverSpecifies and RDATE-protocol server to be used for date and time information on the device. rdate-server <ipaddr>no rdate-server Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Use the no form of the command to clear the server assignment. Related Commands show date (Non-Privileged Command Set) registration-codeStores the registration code of the device. registration-code <code>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet remote-management access-listAssigns the specified IP access list to the remote management subsystem. remote-management access-list <id>no remote-management access-list Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Use the no form of the command to clear the IP access list assignment in the remote management subsystem. The access list still exists but is no longer used by the remote management subsystem. Related Commands access-list (Configuration Command Set) remote-management enableEnables remote management for the current device. remote-management enableno remote-management enable Usage Guidelines Availability: Remote, Serial, Telnet Use the no form of the command to disable remote management of the current device.
Related Commands access-list (Configuration Command Set) remote-management encryptionSets the encryption method for remote management sessions. remote-management encryption <ARC4|AES|DES>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Use this command after setting a passphrase using the remote-management shared-secret command. Encryption begins the next time the configuration manager accesses the Secure Content Accelerator. Related Commands remote-management access-list (Configuration Command Set) remote-management portSets the TCP service port used for remote management to the current device. Use the no form of the command to clear the port specification and return to the default communication port. remote-management port <portid>no remote-management port Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet This port is used at the next attach. You must enter a reload command to activate the new remote management port. Related Commands discover (Non-Privileged Command Set) remote-management shared-secretSets the secret passphrase used for encryption. Use the no form of the command to clear the passphrase. remote-management shared-secret <passphrase>no remote-management shared-secret Syntax Description
Usage Guidelines Availability: Serial You are prompted for this passphrase the next time a management connection with the device is requested. Related Commands remote-management access-list (Configuration Command Set) ripEnables Routing Interface Protocol (RIP) for the current device. rip [v1|v2]no rip [v1|v2] Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If a single RIP version is not specified, both versions are enabled. Using the no form of the command disables RIP completely if you do not specify a version to disable. Examples The following example activates RIP version 1. The first command enables both RIP versions. The second command disables on RIP v2. This has the same result as using the command rip v1. rip Related Commands show rip (Non-Privileged Command Set) no snmpDisables SNMP and clears all SNMP data. no snmp
Usage Guidelines Availability: Remote, Serial, Telnet Related Commands show snmp (Non-Privileged Command Set) snmp access-listAssigns an existing access list to be used with the SNMP subsystem. snmp access-list <id>no snmp access-list <id> Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Use the no form of the command to remove the specified access list. The access list still exists but is no longer used by the SNMP subsystem. Related Commands access-list (Configuration Command Set) snmp contactAssigns contact information for the SNMP subsystem. Use the no form of the command to remove the contact information. snmp contact <contactInfo>no snmp contact Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Related Commands no snmp (Configuration Command Set) snmp default communityAssigns a default community for the SNMP subsystem to use when sending trapping information. snmp default community <comName>no snmp default community Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Use the no form of the command to clear the community name. Related Commands no snmp (Configuration Command Set) snmp enableEnables SNMP using the current SNMP configuration. snmp enableno snmp enable Usage Guidelines Availability: Remote, Serial, Telnet Use the no form of the command to disable SNMP without clearing SNMP data.
Related Commands show snmp (Non-Privileged Command Set) snmp locationAssigns location information for the SNMP subsystem. snmp location <locInfo>no snmp location Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Use the no form of the command to clear the location information. Related Commands no snmp (Configuration Command Set) snmp trap-hostAssigns a destination for SNMP trap messages. snmp trap-host <v1|v2c> <ipaddr> [community]no snmp trap-host <v1|v2c> <ipaddr> [community] Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Related Commands no snmp (Configuration Command Set) snmp trap-type enterpriseEnables device event trap messages to be sent for a specific trap-type event and event filter. snmp trap-type enterprise <config-changed|cpu-utilization| ssl-cert-expire|ssl-cert-invalid|ssl-certify-fail| ssl-neg-failure|ssl-total-connections|ssl-tps> [threshold <threshold>] [hysteresis <lowvalue> <highvalue>]no snmp trap-type enterprise <config-changed|cpu-utilization| ssl-cert-expire|ssl-cert-invalid|ssl-certify-fail| ssl-neg-failure|ssl-total-connections|ssl-tps> Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet (This command must be entered on one line.) Use the no form of the command to disable the specified event trap-type. The table below shows trap-type minimum, maximum, and default levels for each value argument. Except in the case of cpu-utilization, the levels indicate actual values; cpu-utilization levels indicate percentage of use.
Related Commands no snmp (Configuration Command Set) snmp trap-type genericEnables generic SNMP traps. snmp trap-type genericno snmp trap-type generic Usage Guidelines Availability: Remote, Serial, Telnet Use the no form of the command to disable generic SNMP traps. Related Commands no snmp (Configuration Command Set) sntp-serverAssigns an SNTP server. sntp-server <ipaddr>no sntp-server Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Use the no form of the command to remove the SNTP server information. Related Commands show sntp-server (Non-Privileged Command Set) sslEnters SSL Configuration mode for the current device. sslUsage Guidelines Availability: Remote, Serial, Telnet Related Commands show ssl (Non-Privileged Command Set) syslogAdds the specified IP address to the syslog list for the device. syslog <ipaddr>no syslog <ipaddr> Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Using the no form of the command removes the specified IP address from the syslog list of the current device. Up to four IP addresses can be specified. Syslog messages are sent to all hosts at the IP addresses in this list. Related Commands show syslog (Non-Privileged Command Set) telnet access-listAssigns an existing access list to be used with telnet management requests. telnet access-list <id>no telnet access-list <id> Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Use the no form of the command to remove the specified access list. The access list still exists but is no longer used by the telnet subsystem. Related Commands access-list (Configuration Command Set) telnet enableAllows telnet management sessions for the device. Use the no form of the command to disable telnet management access. telnet enableno telnet enable Usage Guidelines Availability: Remote, Serial, Telnet Related Commands show telnet (Non-Privileged Command Set) telnet portSpecifies the TCP service port to use for telnet management sessions. telnet port <portid>no telnet port <portid> Syntax Description
Usage Guidelines ; Availability: Remote, Serial, Telnet Use the no form of the command to return the telnet management port to the default setting. The port assignment is used at the next attach. Related Commands show telnet (Non-Privileged Command Set) timezoneSpecifies the time zone of the device's location. timezone <zone>Syntax Description
Usage Guidelines Availability: Serial, Telnet The zone is entered in the form of Standard Time Zone identifier|GMT offset (integer)|Daylight Savings Time Zone identifier. For example, MST7MDT is used for Mountain Standard/Daylight Savings Time. The alphabetic strings are used for display; the integer is used for date and time computation. The alphabetic strings are optional; the GMT offset integer is not. Related Commands show date (Non-Privileged Command Set) web-mgmt access-listAssigns an existing access list to be used with web browser-based management requests. web-mgmt access-list <id>no web-mgmt access-list <id> Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Use the no form of the command to remove the specified access list. The access-list still exists but is no longer used by the Web management subsystem. Related Commands access-list (Configuration Command Set) web-mgmt enableAllows web browser-based management sessions for the device. Use the no form of the command to diable web browser-based management access. web-mgmt enableno web-mgmt enable Usage Guidelines Availability: Remote, Serial, Telnet Related Commands show web-management (Non-Privileged Command Set) web-mgmt portSpecifies the TCP service port used for management with the Web-based GUI. web-mgmt port <portid>no web-mgmt port <portid> Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Use the no form of the command to return the GUI management port to the default setting. The port assignment is used at the next attach. Related Commands access-list (Configuration Command Set) Interface Configuration Command SetautoSets the current Ethernet interface to autonegotiation, canceling any existing forced duplex or speed setting. autoUsage Guidelines Availability: Remote, Serial, Telnet duplexForces the current Ethernet interface to full or half duplex. duplex <full|half>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet endExits Interface Configuration mode and returns to Configuration mode. endfinishedLeaves Interface Configuration Mode and returns to Top Level mode. finishedUsage Guidelines Availability: Remote, Serial, Telnet helpDisplays help information for the specified command. help [command]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not specify a command, help information is displayed for all Interface Commands speedForces the speed of the current Ethernet interface to 10 Mbps or 100 Mbps. speed <10|100>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet SSL Configuration Command Setbackend-serverCreates and/or configures the specified backend server and enters Backend Server Configuration mode for that server. backend-server <servname> [create]no backend-server <servname> Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet The no form of the command is used to remove the specified backend server. A device can have a total of 255 servers in any combination of backend, reverse-proxy, or standard secure servers. When a backend server has been specified for removal, all connections are allowed to finish before the backend server is actually removed. Backend server names can consist of Arabic numerals and upper- and lowercase alphabetic, underscore (_), hyphen (-), and period (.) characters. Backend server names must begin wih an alphabetic character or underscore and have a limit of 15 characters. Related Commands show ssl (Non-Privileged Command Set) certCreates and/or configures the specified certificate object and enters Certificate configuration mode for that object. cert <certname> [create]no cert <certname> Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet The no form of the command is used to remove the specified certificate object. You cannot remove a certificate referenced by a server. A device can have up to 511 certificate objects. Certificate names can consist of Arabic numerals and upper- and lowercase alphabetic, underscore (_), hyphen (-), and period (.) characters. Certificate names must begin wih an alphabetic character or underscore and have a limit of 127 characters. Examples The following example creates a certificate object named myCert and enters Certificate Configuration mode for the certificate object myCert. cert myCert create Related Commands show ssl cert (Non-Privileged Command Set) certgroupCreates and/or configures the specified certificate group and enters Certificate Group Configuration mode for the certificate group. certgroup <certgroupname> [create]no certgroup <certgroupname> Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet The no form of the command is used to remove the specified certificate group. You cannot remove a certificate group referenced by a server. A device can have up to 63 certificate groups. Certificate group names can consist of Arabic numerals and upper- and lowercase alphabetic, underscore (_), hyphen (-), and period (.) characters. Certificate group names must begin wih an alphabetic character or underscore and have a limit of 15 characters. Examples The following example creates a certificate object named myCertGroup and enters Certificate Group Configuration mode for certificate group myCertGroup. cert myCertGroup create Related Commands show ssl certgroup (Top Level Command Set) endExits SSL Configuration mode and returns to Configuration mode. endUsage Guidelines Availability: Remote, Serial, Telnet finishedLeaves SSL Configuration Mode and returns to Top Level mode. finishedUsage Guidelines Availability: Remote, Serial, Telnet gencsrGenerates a certificate signing request and/or self-signed certificate. gencsr <key <keyname>> [newhdr] [digest md5|sha1] [output <filename|url>]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet A device can up to 255 key objects. Examples The following example uses a key object named myGenKey, displays the certificate digest in MD5 format, and saves the certificate file named myCertFile. gencsr key myGenKey digest md5 output myCertFile Related Commands See the section "Key Configuration Command Set". helpDisplays help information for the specified command. help [command]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not specify a command, help information is displayed for all SSL Commands import pkcs12Imports and processes a PKCS#12 file to create certificate and key objects. import pkcs12 <name> [filename|url]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not specify a file name or URL, you are prompted for it. Related Commands import pkcs7 (SSL Command Set) import pkcs7Imports and processes a PKCS#7 file to create a certificate objects and a certificate group. import pkcs7 <name> <der|pem> [prefix <prefixText>] [filename]|url]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not specify a file name or URL, you are prompted for it. Related Commands import pkcs12 (SSL Command Set) keyCreates and/or configures the specified key object. key <keyname> [create]no key <keyname> Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet The no form of the command is used to remove a key. You cannot delete a key referenced by a server. A device can have up to 255 key objects. Key names can consist of Arabic numerals and upper- and lowercase alphabetic, underscore (_), hyphen (-), and period (.) characters. Key names must begin wih an alphabetic character or underscore and have a limit of 15 characters. Examples The following example creates a key association named mykey and enters Key Configuration mode for the key association mykey. key mykey create Related Commands show ssl key (Non-Privileged Command Set) reverse-proxy-serverCreates and/or configures the specified reverse-proxy server and enters Reverse-Proxy Server Configuration mode for that server. reverse-proxy-server <servname> [create]no reverse-proxy-server <servname> Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet The no form of the command is used to remove the specified reverse-proxy server. A device can have a total of 255 servers in any combination of backend, reverse-proxy, or standard secure servers. When a reverse-proxy server has been specified for removal, all connections are allowed to finish before the reverse-proxy server is actually removed. Reverse-proxy server names can consist of Arabic numerals and upper- and lowercase alphabetic, underscore (_), hyphen (-), and period (.) characters. Reverse-proxy server names must begin wih an alphabetic character or underscore and have a limit of 15 characters. Related Commands show ssl (Non-Privileged Command Set) secpolicyCreates and/or configures the specified security policy and enters Security Policy Configuration mode for the security policy. secpolicy <polname> [create]no secpolicy <polname> Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet The no form of the command is used to remove a security policy. You cannot delete a security policy referenced by a logical secure server. Security policy names can consist of Arabic numerals and upper- and lowercase alphabetic, underscore (_), hyphen (-), and period (.) characters. Security policy names must begin wih an alphabetic character or underscore and have a limit of 15 characters. Examples The following example creates a security policy named mypolicy and enters Security Policy Configuration mode for the security policy mypolicy. secpolicy mypolicy create Related Commands show ssl secpolicy (Non-Privileged Command Set) serverCreates and/or configures the specified standard secure server and enters Server Configuration mode for that server. server <servname> [create]no server <servname> Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet The no form of the command is used to remove a server. A device can have a total of 255 servers in any combination of backend, reverse-proxy, or standard secure servers. When a secure server has been specified for removal, all connections are finished before the server is actually removed. Server names can consist of Arabic numerals and upper- and lowercase alphabetic, underscore (_), hyphen (-), and period (.) characters. Server names must begin wih an alphabetic character or underscore and have a limit of 15 characters. Related Commands show ssl server (Non-Privileged Command Set) Backend Server Configuration Command SetactivateActivates the current suspended backend server if enough information has been configured. activateUsage Guidelines Availability: Remote, Serial, Telnet All backend servers are created as active servers by default. Related Commands suspend (Backend Server Configuration Command Set) certgroup serverauthAssigns a certificate group to be used for server certificate authentication. certgroup serverauth <certgroupname>no certgroupchain Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet The no form of the command is used to disable server authentication using the certificate group. When using the no form of the command, you need not specify any certificate group name. Only one certificate group can be used. Related Commands certgroup (SSL Configuration Command Set) endExits Backend Server Configuration mode, activates all changes, and returns to SSL Configuration mode. endUsage Guidelines Availability: Remote, Serial, Telnet exitExits Backend Server Configuration mode, activates all changes, and returns to SSL Configuration mode. exitUsage Guidelines Availability: Remote, Serial, Telnet finishedLeaves Backend Server Configuration Mode and returns to Top Level mode. finishedUsage Guidelines Availability: Remote, Serial, Telnet helpDisplays help information for the specified command. help [command]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not specify a command, help information is displayed for all Backend Server Configuration Commands. infoDisplays current information about the logical secure server being edited or created. infoUsage Guidelines Availability: Remote, Serial, Telnet ip addressSets the specified IP address for the backend server. ip address <ipaddr> [netmask <mask>]no ip address Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Using the no form of the command clears the IP address for the backend server. localportSpecifies the TCP service port through which non-secure connections are received. localport <port|default>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Related Commands remoteport (Backend Server Configuration Command Set) log-urlSpecifies a host for logging of URL requests. log-url <ipaddr>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet remoteportSpecifies the TCP service port through which redirected secure connections are sent. remoteport <port|default>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Related Commands localport (Backend Server Configuration Command Set) secpolicyCreates an association between this server and the specified security policy. secpolicy <polname|all|default|strong|weak>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Several default security policies are preloaded into the SSL device. To see a list of all loaded default and user-defined security policies, use the show ssl secpolicy command. Related Commands secpolicy (SSL Configuration Command Set) serverauth enableEnables server certificate authentication. serverauth enableno serverauth enable Usage Guidelines Availability: Remote, Serial, Telnet Using the no form of the command disables server certificate authentication. Related Commands certgroup serverauth (Backend Server Configuration Command Set) serverauth ignoreSpecifies the server authentication errors to ignore. serverauth ignore all | none|signature-failure|expired-date| cert-not-yet-valid|invalid-ca|domain-nameno serverauth ignore all | none|signature-failure|expired-date| cert-not-yet-valid|invalid-ca|domain-name Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Any combination of options can be used currently. Use the no form of the command to cease ignoring the specific server authentication error. Related Commands certgroup serverauth (Backend Server Configuration Command Set) session-cache enableEnables session caching. session-cache enableno session-cache enable Usage Guidelines Availability: Remote, Serial, Telnet Use the no form of the command to disable session caching. Related Commands session-cache size (Backend Server Configuration Mode) session-cache sizeSpecifies the size of the session cache. session-cache size <cachesize>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Related Commands session-cache enable (Backend Server Configuration Mode) session-cache timeoutSpecifies the session cache length before being timed out. session-cache timeout <seconds>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Related Commands session-cache enable (Backend Server Configuration Mode) suspendSuspends the function of the backend server. suspend [now]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet This command behaves in three ways:
Related Commands activate (Backend Server Configuration Mode) transparentEnables the backend server to function as a transparent proxy (default). transparentno transparent Usage Guidelines Availability: Remote, Serial, Telnet When transparent proxy behavior is disabled, the device accepts connections on the IP address of the Secure Content Accelerator rather than on the server address. The no form of the command is used to disable this behavior. Certificate Configuration Command SetbinhexPastes a binary hex-encoded X509 certificate into the configuration manager. binhex [value]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet After the command is entered, you are prompted to paste the certificate from the cut buffer. You can use a text editor to copy the certificate from a file. After the certificate is pasted, you must press Enter twice to complete the command. derLoads a DER-encoded X509 certificate file into the current object. der [certfilename|url]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not enter the file name or URL, you are prompted for it. endExits Certificate Configuration mode, activates all valid changes, and returns to SSL Configuration mode. endUsage Guidelines Availability: Remote, Serial, Telnet exitExits Certificate Configuration mode, activates all valid changes, and returns to SSL Configuration mode. exitUsage Guidelines Availability: Remote, Serial, Telnet finishedLeaves Certificate Configuration Mode and returns to Top Level mode. finishedUsage Guidelines Availability: Remote, Serial, Telnet helpDisplays help information for the specified command. help [command]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not specify a command, help information is displayed for all Certificate Configuration Commands Usage Guidelines Availability: Remote, Serial, Telnet infoDisplays current information about the certificate object being created or edited. infopemLoads a PEM-encoded X509 certificate into the current certificate object. pem [certfilename|url]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not enter the file name or URL, you are prompted for it. Related Commands pem-paste (Certificate Configuration Command Set) pem-pasteAllows a PEM-encoded X.509 certificate to be pasted into the configuration manager. pem-pasteUsage Guidelines Availability: Remote, Serial, Telnet After the command is entered, you are prompted to paste a certificate from the cut buffer. You can use a text editor to copy the certificate from a file. After the certificate is pasted, you must press Enter twice to complete the command. Related Commands pem (Certificate Configuration Command Set) Certificate Group Configuration Command SetcertAdds the specified, existing certificate object into the current certificate group. cert <certObject>no cert <certObject> Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Up to 64 certificate objects are allowed per certificate group. Use the no form of the command to remove the specified certificate from the certificate group. Related Commands cert (SSL Configuration Command Set) endExits Certificate Group Configuration mode, activates all changes, and returns to SSL Configuration mode. endUsage Guidelines Availability: Remote, Serial, Telnet exitExits Certificate Group Configuration mode, activates all changes, and returns to SSL Configuration mode. exitUsage Guidelines Availability: Remote, Serial, Telnet finishedLeaves Certificate Group Configuration Mode and returns to Top Level mode. finishedUsage Guidelines Availability: Remote, Serial, Telnet helpDisplays help information for the specified command. help [command]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not specify a command, help information is displayed for all Certificate Group Commands infoDisplays current information about the certificate group being created or edited. infoUsage Guidelines Availability: Remote, Serial, Telnet Key Configuration Command SetbinhexAllows a binary hex-encoded X.509 key to be pasted into the configuration manager. binhex [value]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet After the command is entered, you are prompted to paste the key from the cut buffer. You can use a text editor to copy the key from a file. After the key is pasted, you must press Enter twice to complete the command. derLoads a DER-encoded X509 key file into the current key object. der [keyfilename|url]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not enter the file name or URL, you are prompted for it. endExits Key Configuration mode, activates all changes, and returns to SSL Configuration mode. endUsage Guidelines Availability: Remote, Serial, Telnet exitExits Key Configuration mode, activates all changes, and returns to SSL Configuration mode. exitUsage Guidelines Availability: Remote, Serial, Telnet finishedLeaves Key Configuration Mode and returns to Top Level mode. finishedUsage Guidelines Availability: Remote, Serial, Telnet genrsaGenerates an RSA key. genrsa [bits <512|1024>] [encrypt <des|des3>] [seed <seedstring>] [output <filename|url>]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If the encrypt keyword is not used, the key is not be displayed. Examples The following example generates a 1024-bit key using the seed string lemon. The key is displayed once using DES encryption. The resulting key is stored on the device as well as exported to a PEM-encoded file named mykey.pem. genrsa bits 1024 encrypt des seed lemon output mykey.pem helpDisplays help information for the specified command. help [command]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not specify a command, help information is displayed for all Key Configuration Commands infoDisplays current information about the key being created or edited. infoUsage Guidelines Availability: Remote, Serial, Telnet net-iisLoads a private key exported from IIS 4 only into the key entity. net-iis [keyfilename|url]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not enter the file name and path, you are prompted for it. pemLoads a PEM-encoded X.509 private key into the key entry. pem [keyfilename|url]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not enter the file name and path, you are prompted for it. Related Commands pem-paste (Key Configuration Command Set) pem-pasteAllows a PEM-encoded X.509 key to be pasted into the configuration manager. pem-pasteUsage Guidelines Availability: Remote, Serial, Telnet After the command is entered, you are prompted to paste a key from the cut buffer. You can use a text editor to copy the key from a file. After the key is pasted, you must press Enter twice to complete the command. Reverse-Proxy Server Configuration Command SetactivateActivates the current suspended reverse-proxy server if enough information has been configured. activateUsage Guidelines Availability: Remote, Serial, Telnet All reverse-proxy servers are created as active servers by default. Related Commands suspend (Reverse-Proxy Server Configuration Command Set) certgroup serverauthAssigns a certificate group to be used for server certificate authentication. certgroup serverauth <certgroupname>no certgroupchain Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet The no form of the command is used to disable server authentication using the certificate group. When using the no flag, you need not specify any certificate group name. Only one certificate group can be used. Related Commands certgroup (SSL Configuration Command Set) endExits Reverse-Proxy Server Configuration mode, activates all changes, and returns to SSL Configuration mode. endUsage Guidelines Availability: Remote, Serial, Telnet exitExits Reverse-Proxy Server Configuration mode, activates all changes, and returns to SSL Configuration mode. exitUsage Guidelines Availability: Remote, Serial, Telnet finishedLeaves Reverse-Proxy Server Configuration Mode and returns to Top Level mode. finishedUsage Guidelines Availability: Remote, Serial, Telnet helpDisplays help information for the specified command. help [<command>]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not specify a command, help information is displayed for all Reverse-Proxy Server Configuration Commands infoDisplays current information about the reverse-proxy server being edited or created. infoUsage Guidelines Availability: Remote, Serial, Telnet localportSpecifies the TCP service port through which non-secure connections are received. localport <port|default>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet log-urlSpecifies a host for logging of URL requests. log-url <ipaddr>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet secpolicyCreates an association between this server and the specified security policy. secpolicy <polname|all|default|strong|weak>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Several default security policies are preloaded into the SSL device. To see a list of all loaded default and user-defined security policies, use the show ssl secpolicy command. Related Commands secpolicy (SSL Configuration Command Set) serverauth enableEnables server certificate authentication. serverauth enableno serverauth enable Usage Guidelines Availability: Remote, Serial, Telnet Related Commands certgroup serverauth (Reverse-Proxy Configuration Command Set) serverauth ignoreSpecifies the server authentication errors to ignore. serverauth ignore <all | none|signature-failure|expired-date| cert-not-yet-valid|invalid-ca|domain-name>no serverauth ignore< all | none|signature-failure|expired-date| cert-not-yet-valid|invalid-ca|domain-name> Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Any combination of options can be used currently. Use the no form of the command to cease ignoring the specific server authentication error. Related Commands certgroup serverauth (Reverse-Proxy Server Configuration Command Set) session-cache enableEnables session caching. session-cache enableno session-cache enable Usage Guidelines Availability: Remote, Serial, Telnet Related Commands session-cache size (Reverse-Proxy Server Configuration Mode) session-cache sizeSpecifies the size of the session cache. session-cache size <cachesize>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Related Commands session-cache enable (Reverse-Proxy Server Configuration Mode) session-cache timeoutSpecifies the session cache length before being timed out. session-cache timeout <seconds>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Related Commands session-cache enable (Reverse-Proxy Server Configuration Mode) suspendSuspends the function of the backend server. suspend [now]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet This command behaves in three ways:
Related Commands activate (Reverse-Proxy Server Configuration Mode) Security Policy Configuration Command SetcryptoCreates a customized security policy for the current SSL device. crypto <strong | weak | all | ARC4-MD5 | ARC4-SHA | DES-CBC3-MD5 | DES-CBC3-SHA | DES-CBC-MD5 | DES-CBC-SHA | EXP-ARC2-MD5 | EXP-ARC4-MD5 | EXP-ARC4-SHA | EXP-DES-CBC-SHA | EXP1024-ARC2-CBC-MD5 | EXP1024-ARC4-MD5 | EXP1024-ARC4-SHA | EXP1024-DES-CBC-SHA | NULL-MD5 | NULL-SHA >no crypto < ARC4-MD5 | ARC4-SHA | DES-CBC3-MD5 | DES-CBC3-SHA | DES-CBC-MD5 | DES-CBC-SHA | EXP-ARC2-MD5 | EXP-ARC4-MD5 | EXP-ARC4-SHA | EXP-DES-CBC-SHA | EXP1024-ARC2-CBC-MD5 | EXP1024-ARC4-MD5 | EXP1024-ARC4-SHA | EXP1024-DES-CBC-SHA | NULL-MD5 | NULL-SHA > Syntax Description The following table shows the characteristics of each crytptographic algorithm.
1ARC4 is compatible with RC4™ RSA Data Security. 2ARC2 is compatible with RC2™ RSA Data Security. Usage Guidelines Availability: Remote, Serial, Telnet (This command must be entered on one line.) You can identify either individual ciphers or use the strong, weak, default, or all keywords to specify cipher sets. The no form of this command is used to remove a cipher or set of ciphers. You must specify which algorithm(s) to remove following the no crypto command. For example, using the commands crypto ARC4-MD5 and crypto ARC4-SHA loads both schemes into the current user-defined security policy. Additionally, you can alter the preset cryptography schemes specified for the current security policy. If you enter crypto weak and no crypto NULL-MD5 commands, the NULL-MD5 cryptography scheme is removed from the current security policy.
endExits Security Policy Configuration mode, activates all changes, and returns to SSL Configuration mode. endUsage Guidelines Availability: Remote, Serial, Telnet exitExits Security Policy Configuration mode, activates all changes, and returns to SSL Configuration mode. exitUsage Guidelines Availability: Remote, Serial, Telnet finishedLeaves Security Policy Configuration Mode and returns to Top Level mode. finishedUsage Guidelines Availability: Remote, Serial, Telnet helpDisplays help information for the specified command. help [command]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not specify a command, help information is displayed for all Security Policy Configuration Commands infoDisplays current information about the security policy being edited or created. infoUsage Guidelines Availability: Remote, Serial, Telnet Server Configuration Command SetactivateActivates the current logical secure server if enough information has been configured. activateRelated Commands suspend (Server Configuration Command Set) certSets the specified certificate for use by the server. cert <certname | default | default-1024 | default 512>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Only one certificate is allowed per server. If you enter this command with a different certificate, that reference replaces the earlier one. Related Commands certificate (SSL Configuration Command Set) certgroup chainEnables the specified certificate group to be used as a certificate chain. The no form of the command is used to disable certificate chaining. certgroup chain certgroupnameno certgroupchain Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Use the no form of the command to remove a certificate group association. When using the no flag, you need not specify any certificate group name. Only one certificate chain is allowed. Related Commands certgroup (SSL Configuration Command Set) certgroup clientauthAssigns a certificate group to be used as a certificate trust list for client certificate authentication. certgroup clientauth <certgroupname>no clientauth Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet The no form of the command is used to disable client authentication using the certificate group. When using the no flag, you need not specify any certificate group name. Only one certificate chain can be used. Related Commands clientauth enable (Server Configuration Command Set) clientauth enableEnables client certificate authentication. clientauth enableno clientauth enable Usage Guidelines Availability: Remote, Serial, Telnet Use the no form of the command to disable client certificate authentication. Related Commands certgroup enable (Server Configuration Command Set) clientauth errorSpecifies the client certificate authentication errors to ignore. clientauth error <cert-not-provided|cert-not-yet-valid|cert-has-expired| cert-revoked|cert-has-invalid-ca|cert-has-signature-failure|cert-other-error|all> <fail|failhtml|ignore|redirect <url>>no clientauth error <cert-not-provided| cert-not-yet-valid|cert-has-expired|cert-revoked| cert-has-invalid-ca|cert-has-signature-failure|cert-other-error|all > Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Any combination of options can be used currently. Use the no form of the command to cease ignoring the specific client authentication error. Related Commands certgroup clientauth (Server Configuration Command Set) clientauth verifydepthSpecifies the level of certificate within the certificate group to use when verifying client certificates. clientauth verifydepth <depth>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Related Commands certgroup clientauth (Server Configuration Command Set) endExits Server Configuration mode, activates all changes, and returns to SSL Configuration mode. endUsage Guidelines Availability: Remote, Serial, Telnet ephrsaWhen an export browser version connects to a server using 1024-bit keys, this allows the RSA key exchange (the SSL handshake) to be negotiated using a dynamically created 512-bit key. Using ephemeral RSA ensures the device complies with United States commerce laws. ephrsano ephrsa Usage Guidelines Availability: Remote, Serial, Telnet The default is no ephemeral RSA. Use the no form of the command to disable ephemeral RSA. exitExits Server Configuration mode, activates all changes, and returns to SSL Configuration mode. exitUsage Guidelines Availability: Remote, Serial, Telnet finishedLeaves Server Configuration Mode and returns to Top Level mode. finishedUsage Guidelines Availability: Remote, Serial, Telnet helpDisplays help information for the specified command. help [command]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet If you do not specify a command, help information is displayed for all Server Configuration Commands httpheaderSpecifies the header information to pass to backend HTTP servers. httpheader <session|server-cert|client-cert|pre-filter|prefix <prefixString>>no httpheader <session|server-cert|client-cert|pre-filter|prefix> Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet (This command must be entered on one line.) Any combination of options can be used currently. Use the no form of the command to cease using the specific option. infoDisplays current information about the logical secure server being edited or created. infoUsage Guidelines Availability: Remote, Serial, Telnet ip addressSets the specified IP address for the logical secure server. Using the no form of the command clears the IP address for the logical secure server. ip address <ipaddr> [netmask <mask>]no ip address Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet keySets the specified key for use by the server. key <keyname | default | default-1024 | default 512>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Only one key is allowed per server. If you enter this command with a different key, that reference replaces the earlier one. Related Commands key(SSL Configuration Command Set) localportSpecifies the port on which the secure server receives SSL traffic. The SSL traffic is decrypted and sent to the real server using the TCP service port previously specified with the remoteport command. localport <port|default>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Related Commands remoteport (Server Configuration Command Set) log-urlSpecifies a host for logging of URL requests. log-url <ipaddr>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet redirectEnables server redirection. redirectno redirect Usage Guidelines Use the no form of the command to disable server redirection. remoteportSpecifies the TCP service port through which non-secure connections is sent. remoteport <port|default>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Related Commands localport (Server Configuration Command Set) secpolicyCreates an association between this server and the specified security policy. secpolicy <polname|all|default|strong|weak>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Several default security policies are preloaded into the SSL device. To see a list of all loaded default and user-defined security policies, use the show ssl secpolicy command. Related Commands secpolicy (SSL Configuration Command Set) session-cache enableEnables session caching. session-cache enableno session-cache enable Usage Guidelines Availability: Remote, Serial, Telnet Use the no form of the command to disable session caching. Related Commands session-cache size (Server Configuration Mode) session-cache sizeSpecifies the size of the session cache. session-cache size <cachesize>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Related Commands session-cache enable (Server Configuration Mode) session-cache timeoutSpecifies the session cache length before being timed out. session-cache timeout <seconds>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet Related Commands session-cache enable (Server Configuration Mode) sslportSpecifies the port on which the logical secure server receives SSL traffic. The SSL traffic is decrypted and sent to the physical server using the TCP service port previously specified with the remoteport command. sslport <port|default>Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet
Related Commands localport (Server Configuration Command Set) suspendSuspends the function of the server. suspend [now]Syntax Description
Usage Guidelines Availability: Remote, Serial, Telnet This command behaves in three ways:
Related Commands activate (Server Configuration Mode) transparentEnables to servers to function as a transparent proxy (default). The no form of the command is used to disable this behavior. transparentno transparent Usage Guidelines Availability: Remote, Serial, Telnet When transparent proxy behavior is disabled, the device accepts connections on the IP address of the Secure Content Accelerator rather than on the server address.
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|