CLI Guide - WatchGuard Technologies

CLI Guide - WatchGuard Technologies CLI Guide - WatchGuard Technologies

watchguard.com
from watchguard.com More from this publisher
25.06.2013 Views

CHAPTER 3: Configuration Mode Commands icmp_error_handling command (configure system level) WG#config WG(config)#system WG(config-sys)#icmp_error_handling [all]| [[no] fragmentation_required] [[no] host_unreachable] [[no] time_exceeded] [[no] port_unreachable] [[no] network_unreachable] Effect Allows you to turn on ICMP error handling for all events, or just for the events you specify. interface command (configure system level) WG#config WG(config)#interface Effect Enters the interface configuration mode, at which point you can enter interface-specific commands and their arguments. Arguments None in this mode. See Also For more information on interface configuration mode, see “Level 2 interface configuration commands” on page 82. ldap command (configure system level) WG#config WG(config)#system WG(config-sys)#[no] ldap \ [port_number] 110 WatchGuard Vclass 5.1

Second level configuration mode commands Effect Activates (or deactivates) a network connection to an LDAP server that this security appliance would use to look up certificate revocation lists during IKE key negotiations. Arguments no This argument (when entered before the ldap command prompt) deactivates this LDAP connection. [port-number] This argument notes the pertinent IP address and LDAP server port number. You can enter either an IP address or a domain name, and, if the LDAP server port number is other than “389”, you must enter it. To enter a host name, you must first record the DNS server connection, as noted elsewhere in this Guide. Example WG(config-sys)#ldap 207.124.35.3 189 log command (configure system level) WG#config WG(config)#system WG(config-sys)#log Effect Enters the log configuration mode, at which point you can enter log file-specific commands and their arguments. Arguments None in this mode. For more information about “log” mode commands, see “Level 3 log configuration commands” on page 124. WatchGuard Command Line Interface Guide 111

Second level configuration mode commands<br />

Effect<br />

Activates (or deactivates) a network connection to<br />

an LDAP server that this security appliance would<br />

use to look up certificate revocation lists during<br />

IKE key negotiations.<br />

Arguments<br />

no<br />

This argument (when entered before the ldap<br />

command prompt) deactivates this LDAP<br />

connection.<br />

[port-number]<br />

This argument notes the pertinent IP address and<br />

LDAP server port number. You can enter either an<br />

IP address or a domain name, and, if the LDAP<br />

server port number is other than “389”, you must<br />

enter it.<br />

To enter a host name, you must first record the<br />

DNS server connection, as noted elsewhere in this<br />

<strong>Guide</strong>.<br />

Example<br />

WG(config-sys)#ldap 207.124.35.3<br />

189<br />

log command (configure system level)<br />

WG#config<br />

WG(config)#system <br />

WG(config-sys)#log<br />

Effect<br />

Enters the log configuration mode, at which point<br />

you can enter log file-specific commands and their<br />

arguments.<br />

Arguments<br />

None in this mode. For more information about<br />

“log” mode commands, see “Level 3 log<br />

configuration commands” on page 124.<br />

<strong>WatchGuard</strong> Command Line Interface <strong>Guide</strong> 111

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!