Network objects -> Right click on cluster -> details -> Topology
Click details on the IP addresses
Right click on the cluster IP -> Edit interface
Go to Topology tab
Look for the radio button
IP addresses behind this interface
Specific
The interface group should be selected there
The interface groups can be found under
Network objects -> groups ->
Tuesday, 14 February 2017
Thursday, 2 February 2017
investigating NAT issues on checkpoint firewalls
In Network Objects (bottom left)
Right click Nodes -> More -> Query Objects
Refine by: Search by IP
Double click on the object and check the NAT section for auto NAT
Also you can do Actions -> Where used -> Active policy
Look for any manual NAT's here
Try the traffic while watching the logs in the tracker
You can add the columns xlatesrc and NAT rule into the tracker
Also you can double click the log entry and get more details on the NAT rule and xlated source
Auto NAT's are processed first
Manual NAT's second
In some cases you may need to add and arp
Right click Nodes -> More -> Query Objects
Refine by: Search by IP
Double click on the object and check the NAT section for auto NAT
Also you can do Actions -> Where used -> Active policy
Look for any manual NAT's here
Try the traffic while watching the logs in the tracker
You can add the columns xlatesrc and NAT rule into the tracker
Also you can double click the log entry and get more details on the NAT rule and xlated source
Auto NAT's are processed first
Manual NAT's second
In some cases you may need to add and arp
SSH to CLI of CP firewall
clish
show configuration
Looks for arp
add arp proxy ipv4-address x.x.x.x. interface eth1-02 real-ipv4-address y.y.y.1
x.x.x.x is the IP of your server
y.y.y.y is the IP of your gateway
Tuesday, 17 January 2017
Tuesday, 10 January 2017
3com / hp switch commands
Find what port a mac address is learned on
display mac-address 0860-6EE5-DFBD
Show all mac addresses learned on a port
display mac-address interface GigabitEthernet 1/0/9
Show connected switches like show cdp on cisco
display ndp
display ndp interface GigabitEthernet 1/0/9
Disable paging (5500)
user-interface vty 0 4
screen-length 0
Display what interfaces are up/down
display brief interfaces
Show the IP address on the VLAN interfaces
display ip interface brief
Create SVI interface
Show running config
display current-configuration
Enable mode
system-view (sometimes you need to type super first)
Show stp status
display stp brief
Show saved config (in case of switch reboot with blank cfg)
display saved-config
display startup
List files on disk
dir (not in expert mode)
display mac-address 0860-6EE5-DFBD
Show all mac addresses learned on a port
display mac-address interface GigabitEthernet 1/0/9
Show connected switches like show cdp on cisco
display ndp
display ndp interface GigabitEthernet 1/0/9
Disable paging (5500)
user-interface vty 0 4
screen-length 0
Display what interfaces are up/down
display brief interfaces
Show the IP address on the VLAN interfaces
display ip interface brief
Create SVI interface
interface vlan-interface 10
ip address etc
Create loopback interface
interface loopback 1
ip address etc
Show running config
display current-configuration
Enable mode
system-view (sometimes you need to type super first)
Show stp status
display stp brief
Show saved config (in case of switch reboot with blank cfg)
display saved-config
display startup
List files on disk
dir (not in expert mode)
Friday, 6 January 2017
setting up packet captures on the cisco ASA
cap capin interface inside match ip host 192.168.1.50 host 200.100.100.100 circular-buffer
This will capture data in both directions
circular buffer means it will overwrite when buffer is full
Otherwise it will fill up and stop capturing
You can use clear cap capin to clear out the data
Will capture all the drops of any type
capture asp-drop type asp-drop all
sh cap asp-drop
You can also look in sh asp drop to see if they are increasing
The capture file can be saved and copied off the ASA:
https://100.100.100.200/capture/my-cap-name/pcap
To save the capture file
copy /pcap capture: disk0:
Copy the file off with CLI or ASDM file transfer.
There is also a way to connect ASDM directly to wireshark.
This will capture data in both directions
circular buffer means it will overwrite when buffer is full
Otherwise it will fill up and stop capturing
You can use clear cap capin to clear out the data
Will capture all the drops of any type
capture asp-drop type asp-drop all
sh cap asp-drop
You can also look in sh asp drop to see if they are increasing
The capture file can be saved and copied off the ASA:
https://100.100.100.200/capture/my-cap-name/pcap
To save the capture file
copy /pcap capture: disk0:
Copy the file off with CLI or ASDM file transfer.
There is also a way to connect ASDM directly to wireshark.
time based ACL on ASA
It can be easier to setup in the ASDM
Set up the time range to end on a certain date
time-range TR_expire_acl
absolute end 14:00 07 January 2017
Create your ACL as normal and add the time range on the end.
access-list INSIDE-OUT extended permit ip host 192.168.10.50 any time-range TR_expire_acl
Set up the time range to end on a certain date
time-range TR_expire_acl
absolute end 14:00 07 January 2017
Create your ACL as normal and add the time range on the end.
access-list INSIDE-OUT extended permit ip host 192.168.10.50 any time-range TR_expire_acl
Subscribe to:
Posts (Atom)