CLI Guide - WatchGuard Technologies

CLI Guide - WatchGuard Technologies CLI Guide - WatchGuard Technologies

watchguard.com
from watchguard.com More from this publisher
25.06.2013 Views

CHAPTER 3: Configuration Mode Commands password contains the pound (#) character, it needs to be placed in double quotes. [ This allows you to set PPPoE to Dial-on-Demand or Always On mode. The function of following this option differs in each mode. For Dial-on- Demand mode, this number indicates the inactivity timeout interval in minutes (default is 20 minutes). For Always On mode, this number indicates the auto-reconnect interval in seconds (default is 60 seconds). [-unnumbered_pppoe |disable]] This option allows you to use unnumbered PPPoE. For more information on unnumbered links, see RFC 1812 section 2.2.7. [backup [ip mask gateway ] | [dhcp [host_id] ] | [pppoe -user "name" -password "password"] [unnumbered_pppoe |disable] [disable] [switch_to_backup] This allows you to enable a Backup WAN connection for Interface 1, for systems that have unreliable ISPs or network providers. You can configure the failover connection as static, by typing the IP address, netmask, and gateway. You can configure the failover connection as DHCP using the [dhcp ["host_id"]] syntax. You can configure the interface as PPPoE (always on) using the [pppoe -user "name" -password "password"] syntax. You can configure the backup WAN connection as unnumbered PPPoE using the syntax [unnumbered_pppoe |disable]. You can disable the backup connection by using the option [disable]. 88 WatchGuard Vclass 5.1

Second level configuration mode commands You can switch to the backup connection using the command switch_to_backup. [tracking -remove|-add -interval -timeout -pause_before_failback ] ] For systems that configure a Backup WAN connection using the failover command, these settings must be specified. You can add up to three IP addresses that are used to determine WAN failure. These addresses are used with the -interval and -timeout values to determine when the WAN connection has failed. -interval determines the amount of time that elapses between attempts to ping all three specified tracking addresses. -timeout determines the amount of time that can elapse before a ping attempt is considered failed. All three specified IP addresses must fail to respond to the ping attempt within the specified time to consider the WAN connection failed. In the event of failure, the WAN is switched over to the backup connection. This causes a brief interruption in processing while the system restarts. In order to prevent frequent restarts, the final parameter, -pause_before_failback, is provided. This allows you to specify the amount of time that must elapse between failovers. WatchGuard Command Line Interface Guide 89

Second level configuration mode commands<br />

You can switch to the backup connection using the<br />

command switch_to_backup.<br />

[tracking -remove|-add <br />

-interval <br />

-timeout <br />

-pause_before_failback<br />

] ]<br />

For systems that configure a Backup WAN<br />

connection using the failover command, these<br />

settings must be specified. You can add up to three<br />

IP addresses that are used to determine WAN<br />

failure. These addresses are used with the<br />

-interval and -timeout values to determine<br />

when the WAN connection has failed.<br />

-interval determines the amount of time that<br />

elapses between attempts to ping all three specified<br />

tracking addresses. -timeout determines the<br />

amount of time that can elapse before a ping<br />

attempt is considered failed. All three specified IP<br />

addresses must fail to respond to the ping attempt<br />

within the specified time to consider the WAN<br />

connection failed.<br />

In the event of failure, the WAN is switched over to<br />

the backup connection. This causes a brief<br />

interruption in processing while the system<br />

restarts. In order to prevent frequent restarts, the<br />

final parameter, -pause_before_failback, is<br />

provided. This allows you to specify the amount of<br />

time that must elapse between failovers.<br />

<strong>WatchGuard</strong> Command Line Interface <strong>Guide</strong> 89

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!