Download this guide: IKE and ESP ALG


Add to my manuals
76 Pages

advertisement

Download this guide: IKE and ESP ALG | Manualzz

PART 3

Administration

Operational Commands on page 51

Copyright © 2016, Juniper Networks, Inc.

49

IKE and ESP ALG Feature Guide for Security Devices

50 Copyright © 2016, Juniper Networks, Inc.

CHAPTER 4

Operational Commands

clear security alg ike-esp-nat

show security alg ike-esp-nat summary

show security zones

show security zones type

Copyright © 2016, Juniper Networks, Inc.

51

IKE and ESP ALG Feature Guide for Security Devices

clear security alg ike-esp-nat

Supported Platforms J Series , SRX Series

Syntax clear security alg ike-esp-nat

Release Information Command introduced in Junos OS Release 10.2.

Description Clear state information about Application Layer Gateway (ALG) for IKE and ESP.

Required Privilege

Level clear

Related

Documentation

show security alg ike-esp-nat summary on page 53

List of Sample Output

clear security alg ike-esp-nat on page 52

Output Fields This command produces no output.

Sample Output clear security alg ike-esp-nat user@host> clear security alg ike-esp-nat

10 active IKE-ESP alg state cleared

52 Copyright © 2016, Juniper Networks, Inc.

Chapter 4: Operational Commands

show security alg ike-esp-nat summary

Supported Platforms J Series , SRX Series

Syntax show security alg ike-esp-nat summary

Release Information Command introduced in Junos OS Release 10.2.

Description Display Application Layer Gateway (ALG) for IKE and ESP information summary.

Required Privilege

Level view

Related

Documentation

clear security alg ike-esp-nat on page 52

List of Sample Output

show security alg ike-esp-nat summary on page 53

Sample Output show security alg ike-esp-nat summary user@host> security alg ike-esp-nat summary

Initiator cookie: d5732d9b4114de1a

Responder cookie: 4776fe31164ef

Session-ID: 13

ALG state : 1

Timeout: 6292

Used IKE cookies: 0

Maximum IKE cookies: 2400

Copyright © 2016, Juniper Networks, Inc.

53

IKE and ESP ALG Feature Guide for Security Devices

show security zones

Supported Platforms J Series , LN Series , SRX Series

Syntax show security zones

<detail | terse>

< zone-name >

Release Information Command introduced in Junos OS Release 8.5. The Description output field added in

Junos OS Release 12.1.

Description Display information about security zones.

Options

• none—Display information about all zones.

• detail

| terse—(Optional) Display the specified level of output.

zone-name

—(Optional) Display information about the specified zone.

Required Privilege

Level view

Related

Documentation

Ethernet Port Switching Feature Guide for Security Devices

Layer 2 Bridging and Transparent Mode Feature Guide for Security Devices

security-zone

Security Zones and Interfaces Feature Guide for Security Devices

Junos OS Logical Systems Library for Security Devices

List of Sample Output

show security zones on page 55 show security zones abc on page 55 show security zones abc detail on page 55

show security zones terse on page 56

Output Fields

Table 3 on page 54

lists the output fields for the show security zones command. Output fields are listed in the approximate order in which they appear.

Table 3: show security zones Output Fields

Field Name Field Description

Security zone

Name of the security zone.

Description

Policy configurable

Interfaces bound

Description of the security zone.

Whether the policy can be configured or not.

Interfaces

Number of interfaces in the zone.

List of the interfaces in the zone.

54 Copyright © 2016, Juniper Networks, Inc.

Table 3: show security zones Output Fields (continued)

Field Name Field Description

Zone

Type

Name of the zone.

Type of the zone.

Sample Output show security zones user@host> show security zones

Functional zone: management

Description: This is the management zone.

Policy configurable: No

Interfaces bound: 1

Interfaces:

ge-0/0/0.0

Security zone: Host

Description: This is the host zone.

Send reset for non-SYN session TCP packets: Off

Policy configurable: Yes

Interfaces bound: 1

Interfaces:

fxp0.0

Security zone: abc

Description: This is the abc zone.

Send reset for non-SYN session TCP packets: Off

Policy configurable: Yes

Interfaces bound: 1

Interfaces:

ge-0/0/1.0

Security zone: def

Description: This is the def zone.

Send reset for non-SYN session TCP packets: Off

Policy configurable: Yes

Interfaces bound: 1

Interfaces:

ge-0/0/2.0

Sample Output show security zones abc user@host> show security zones abc

Security zone: abc

Description: This is the abc zone.

Send reset for non-SYN session TCP packets: Off

Policy configurable: Yes

Interfaces bound: 1

Interfaces:

ge-0/0/1.0

Sample Output show security zones abc detail user@host> show security zones abc detail

Copyright © 2016, Juniper Networks, Inc.

Chapter 4: Operational Commands

55

IKE and ESP ALG Feature Guide for Security Devices

Security zone: abc

Description: This is the abc zone.

Send reset for non-SYN session TCP packets: Off

Policy configurable: Yes

Interfaces bound: 1

Interfaces:

ge-0/0/1.0

Sample Output show security zones terse user@host> show security zones terse

Zone Type my-internal Security my-external Security dmz Security

56 Copyright © 2016, Juniper Networks, Inc.

Chapter 4: Operational Commands

show security zones type

Supported Platforms J Series , LN Series , SRX Series

Syntax show security zones type

(functional | security)

<detail | terse>

Release Information Command introduced in Junos OS Release 8.5. The Description output field added in

Junos OS Release 12.1.

Description Display information about security zones of the specified type.

Options

• functional —Display functional zones.

• security —Display security zones.

• detail | terse—(Optional) Display the specified level of output.

Required Privilege

Level view

Related

Documentation

security-zone

Security Zones and Interfaces Feature Guide for Security Devices

List of Sample Output

show security zones type functional on page 58 show security zones type security on page 58 show security zones type security terse on page 58 show security zones type security detail on page 58

Output Fields

Table 4 on page 57

lists the output fields for the show security zones type command.

Output fields are listed in the approximate order in which they appear.

Table 4: show security zones type Output Fields

Field Name Field Description

Security zone

Zone name.

Description Description of the security zone.

Whether the policy can be configured or not.

Policy configurable

Interfaces bound Number of interfaces in the zone.

List of the interfaces in the zone.

Interfaces

Zone

Type

Name of the zone.

Type of the zone.

Copyright © 2016, Juniper Networks, Inc.

57

IKE and ESP ALG Feature Guide for Security Devices

Sample Output show security zones type functional user@host> show security zones type functional

Functional zone: management

Description: management zone

Policy configurable: No

Interfaces bound: 0

Interfaces:

Sample Output show security zones type security user@host> show security zones type security

Security zone: trust

Description: trust zone

Send reset for non-SYN session TCP packets: Off

Policy configurable: Yes

Interfaces bound: 1

Interfaces:

ge-0/0/0.0

Security zone: untrust

Description: untrust zone

Send reset for non-SYN session TCP packets: Off

Policy configurable: Yes

Interfaces bound: 1

Interfaces:

ge-0/0/1.0

Security zone: junos-host

Description: junos-host zone

Send reset for non-SYN session TCP packets: Off

Policy configurable: Yes

Interfaces bound: 0

Interfaces:

Sample Output show security zones type security terse user@host> show security zones type security terse

Zone Type trust Security untrust Security junos-host Security

Sample Output show security zones type security detail user@host> show security zones type security detail

Security zone: trust

Description: trust zone

Send reset for non-SYN session TCP packets: Off

Policy configurable: Yes

Interfaces bound: 1

Interfaces:

ge-0/0/0.0

58 Copyright © 2016, Juniper Networks, Inc.

Security zone: untrust

Description: untrust zone

Send reset for non-SYN session TCP packets: Off

Policy configurable: Yes

Interfaces bound: 1

Interfaces:

ge-0/0/1.0

Security zone: junos-host

Description: junos-host zone

Send reset for non-SYN session TCP packets: Off

Policy configurable: Yes

Interfaces bound: 0

Interfaces:

Chapter 4: Operational Commands

Copyright © 2016, Juniper Networks, Inc.

59

IKE and ESP ALG Feature Guide for Security Devices

60 Copyright © 2016, Juniper Networks, Inc.

advertisement

Was this manual useful for you? Yes No
Thank you for your participation!

* Your assessment is very important for improving the workof artificial intelligence, which forms the content of this project

Related manuals

advertisement

Table of contents