CLI Guide - WatchGuard Technologies

CLI Guide - WatchGuard Technologies CLI Guide - WatchGuard Technologies

watchguard.com
from watchguard.com More from this publisher
25.06.2013 Views

CHAPTER 1: Using the Command Line Interface To assign network addresses to appliance interfaces To assign network addresses to the data interfaces, use these commands (along with the arguments and values noted later in this user guide): Command Additional Information WG(config-if)#interface 0 WG(config-if)#interface 1 WG(config-if)#interface 2 if a DMZ interface is present WG(config-if)#ha2 if an HA2 port is present To complete system configuration To complete the initial system configuration, use these commands: Command Description WG(admin)#passwd change the default password to a new, secure password WG(config-sys)#route includes both static and dynamic routes WG(config-sys)#dns connect to a domain name server WG(config-sys)#snmp connect to any SNMP management stations WG(config-sys)#log activate needed system activity logging WG(config-sys)#ldap connect this appliance to an LDAP server WG(config)#tunnel_switch activate WatchGuard tunnelswitching features 20 WatchGuard Vclass 5.1

Command Description Installing and configuring a WatchGuard appliance WG(config)#cert request and import needed certificates from CA’s WG(config)#denial_of_service customize anti-hacker protection for this appliance WG(config)#high_availability set up and activate a high-availability system, using the High Availibility feature WG(config)#log includes event, traffic and alarm log files To create and apply security policies To create and apply security policies, use these commands: Command Description WG(config)#address create all the needed address groups for use in policies WG(config)#service add new services or groups of related services WG(config-ike)#action create IKE actions for use in IKE policies) WG(config-ike)#policy create IKE policies for use in IPSec policies WG(config-ipsec)#action create IPSec actions for use in IPSec proposals WG(config-ipsec)#proposal create IPSec proposals for use in security policies WG(config)#nat create NAT actions (DNAT, SNAT or VIP) for use in policies WG(config)#vlan create VLAN IDs for use in policies WG(config-qos)#action create QoS actions for use in policies WG(config)#schedule create schedules for application to specific policies WatchGuard Command Line Interface Guide 21

CHAPTER 1: Using the Command Line Interface<br />

To assign network addresses to appliance<br />

interfaces<br />

To assign network addresses to the data interfaces, use<br />

these commands (along with the arguments and values<br />

noted later in this user guide):<br />

Command Additional Information<br />

WG(config-if)#interface 0<br />

WG(config-if)#interface 1<br />

WG(config-if)#interface 2 if a DMZ interface is present<br />

WG(config-if)#ha2 if an HA2 port is present<br />

To complete system configuration<br />

To complete the initial system configuration, use these<br />

commands:<br />

Command Description<br />

WG(admin)#passwd change the default password to a new,<br />

secure password<br />

WG(config-sys)#route includes both static and dynamic<br />

routes<br />

WG(config-sys)#dns connect to a domain name server<br />

WG(config-sys)#snmp connect to any SNMP management<br />

stations<br />

WG(config-sys)#log activate needed system activity<br />

logging<br />

WG(config-sys)#ldap connect this appliance to an LDAP<br />

server<br />

WG(config)#tunnel_switch activate <strong>WatchGuard</strong> tunnelswitching<br />

features<br />

20 <strong>WatchGuard</strong> Vclass 5.1

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!