Professional Documents
Culture Documents
FW Check Point 1500 Appliance Series CLI Guide
FW Check Point 1500 Appliance Series CLI Guide
2019
R80.20
All rights reserved. This product and related documentation are protected by copyright and distributed
under licensing restricting their use, copying, distribution, and decompilation. No part of this product or
related documentation may be reproduced in any form or by any means without prior written authorization
of Check Point. While every precaution has been taken in the preparation of this book, Check Point
assumes no responsibility for errors or omissions. This publication and features described herein are
subject to change without notice.
TRADEMARKS:
Refer to the Copyright page for a list of our trademarks.
Refer to the Third Party copyright notices for a list of relevant copyrights and third-party licenses.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 2
Important Information
Important Information
Latest Software
We recommend that you install the most recent software release to stay up-to-date with the
latest functional improvements, stability fixes, security enhancements and protection
against new and evolving attacks.
Certifications
For third party independent certification of Check Point products, see the Check Point
Certifications page.
Feedback
Check Point is engaged in a continuous effort to improve its documentation.
Please help us by sending your comments.
Revision History
Date Description
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 3
Table of Contents
Table of Contents
Introduction 41
Using Command Line Reference 42
CLI Syntax 43
Running Gaia Clish Commands from Expert Mode 44
Supported Linux Commands 45
access-rule type outgoing 46
add access-rule type outgoing 47
delete access-rule type outgoing 50
set access-rule type outgoing 51
show access-rule type outgoing 54
access-rule type incoming-internal-and-vpn 55
add access-rule type incoming-internal-and-vpn 56
delete access-rule type incoming-internal-and-vpn 58
set access-rule type incoming-internal-and-vpn 59
show access-rule type incoming-internal-and-vpn 62
additional-hw-settings 63
set additional-hw-settings 64
show additional-hw-settings 65
additional-management-settings 66
set additional-management-settings 67
show additional-management-settings 68
ad-server 69
add ad-server 70
delete ad-server 71
set ad-server 72
show ad-server 73
show ad-servers 74
address-range 75
add address-range 76
delete address-range 77
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 4
Table of Contents
set address-range 78
show address-range 79
show address-ranges 80
admin-access 81
add admin access 82
set admin-access 83
show admin-access 84
admin-access-ip-addresses 85
show admin-access-ip-addresses 86
delete admin-access-ip-address-all 87
admin-access-ipv4-address 88
add admin-access-ipv4-address 89
add admin-access-ipv4-address 90
add admin-access-ipv4-address 91
delete admin-access-ipv4-address 92
show admin-access-ipv4-addresses 93
delete admin-access-ipv4-address-all 94
administrator 95
add administrator 96
delete administrator 97
set administrator 98
set administrator 99
set administrator 100
set administrators 101
set administrators 102
show administrator 103
show administrators 104
show administrators 105
show administrators 106
administrators radius-auth 107
set administrators radius-auth 108
set administrators radius-auth (legacy mode) 109
show administrators radius-auth 110
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 5
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 6
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 7
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 8
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 9
Table of Contents
cloud-deployment 249
set cloud-deployment 250
show cloud-deployment 251
cloud-notifications 252
set cloud-notification 253
show cloud-notifications 254
send cloud-report 255
cloud-services 256
reconnect cloud-services 257
set cloud-services 258
set cloud-services 259
set cloud-services 260
show cloud-services 261
show cloud-services connection-details 262
cloud-services-firmware-upgrade 263
set cloud-services-firmware-upgrade 264
set cloud-services-firmware-upgrade 265
set cloud-services-firmware-upgrade 266
set cloud-services-firmware-upgrade 267
show cloud-services-firmware-upgrade 268
show cloud-services-firmware-upgrade 269
show cloud-services-firmware-upgrade 270
show cloud-service managed-blades 271
show cloud-services managed-services 272
fetch cloud-services policy 273
show cloud-services status 274
show commands 275
cphaprob 276
cphastop 279
cpinfo 280
cpstart 281
cpstat 282
cpstop 285
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 10
Table of Contents
cpwd_admin 286
date 287
set date 288
set date 289
set date 290
set date 291
set date 292
show date 293
show date 294
show date 295
show date 296
show date 297
restore default-settings 298
dhcp-relay 299
set dhcp-relay 300
show dhcp-relay 301
show dhcp servers 302
dhcp server interface 303
delete dhcp server interface 304
set dhcp server interface 305
set dhcp server interface 306
set dhcp server interface 307
set dhcp server interface 308
set dhcp server interface 309
set dhcp server interface 310
set dhcp server interface 311
set dhcp server interface 312
set dhcp server interface 313
set dhcp server interface 314
set dhcp server interface 315
set dhcp server interface 316
set dhcp server interface 317
set dhcp server interface 318
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 11
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 12
Table of Contents
dynamic-dns 355
set dynamic-dns 356
set dynamic-dns 357
set dynamic-dns 358
show dynamic-dns 359
show dynamic-dns 360
show dynamic-dns 361
dynamic objects 362
exit 364
set expert password 365
fetch certificate 366
fetch policy 367
fw commands 368
fw policy 370
set fw policy 371
set fw policy 372
set fw policy 373
set fw policy 374
show fw policy 375
show fw policy 376
show fw policy 377
show fw policy 378
set fw policy user-check accept 379
set fw policy user-check ask 380
set fw policy user-check block 382
set fw policy user-check block-device 383
set fw policy user-check block-infected-device 384
global-radius-conf 385
set global-radius-conf 386
show global-radius-conf 387
group 388
add group 389
delete group 390
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 13
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 14
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 15
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 16
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 17
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 18
Table of Contents
monitor-mode-network 581
add monitor-mode-network 582
delete monitor-mode-network 583
set monitor-mode-network 584
show monitor-mode-networks 585
monitor-mode-configuration 586
set monitor-mode-configuration 587
show monitor-mode-configuration 588
message 589
set message 590
show message 591
show message 592
show memory usage 593
nat 594
set nat 595
set nat 596
set nat 597
set nat 598
set nat 599
set nat 600
set nat 601
set nat 602
set nat 603
set nat 604
set nat 605
set nat 606
set nat 607
set nat 608
show nat 609
show nat 610
show nat 611
nat-rule 612
add nat-rule 613
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 19
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 20
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 21
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 22
Table of Contents
reboot 723
restore settings 724
show restore settings log 725
show revert log 726
revert to factory defaults 727
revert to saved image 728
report-settings 729
set report-settings 730
set report-settings 731
set report-settings 732
show report-settings 733
show rule hits 734
show saved image 735
update security-blades 736
security-management 737
connect security-management 738
set security-management 739
set security-management 740
set security-management 741
show security-management 742
serial-port 743
set serial-port 744
set serial-port 745
set serial-port 746
set serial-port 747
show serial-port 748
server 749
add server 750
delete server 752
show server 753
show servers 754
service-details 755
set device-details 756
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 23
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 24
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 25
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 26
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 27
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 28
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 29
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 30
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 31
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 32
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 33
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 34
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 35
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 36
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 37
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 38
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 39
Table of Contents
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 40
Introduction
Introduction
This guide contains all relevant CLI commands for the Small and Medium Business (SMB) 1500 appliance
models:
n 1550
n 1590
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 41
Using Command Line Reference
CLISH Auto-completion
All CLISH commands support auto-completion. Standard Check Point and native Linux commands can be
used from the CLISH shell but do not support auto-completion. These are examples of the different
commands:
n CLISH - fetch,set, show
n Standard Check Point - cphaprob,..., fw, vpn
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 42
CLI Syntax
CLI Syntax
The CLI commands are formatted according to these syntax rules.
Notation Description
<Text inside angle brackets> Placeholder for which you must supply a value
Vertical pipe (|) Separator for mutually exclusive items; choose one
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 43
Running Gaia Clish Commands from Expert Mode
Syntax
Parameters
Parameter Description
-v Verbose
-A Run as admin
Note - If the default shell, in which you logged in, was Gaia Clish, and then you logged
in to the Expert mode from it, you cannot run the clish command from the Expert
mode (running clish -> expert -> clish commands does not work, but running
expert-> clish commands works).
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 44
Supported Linux Commands
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 45
access-rule type outgoing
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 46
add access-rule type outgoing
Syntax
Parameters
Parameter Description
application- If true, the rule accepts or blocks all applications but the selected application
negate
Type: Boolean (true/false)
destination- If true, the destination is all traffic except what is defined in the destination field
negate
Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 47
add access-rule type outgoing
Parameter Description
log Defines which logging method to use: None - do not log, Log - Create log, Alert -
log with alert, Account - account rule
Options: none, log, alert, account
name name
Type: A string of alphanumeric characters without space between them
service The network service object that the rule should match to
service-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
source-negate If true, the source is all traffic except what is defined in the source field
Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 48
add access-rule type outgoing
Example
add access-rule type outgoing action block log none source TEXT source-
negate true destination TEXT destination-negate true service TEXT
service-negate true disabled true comment "This is a comment." hours-
range-enabled true hours-range-from 23:20 hours-range-to 23:20 position
2 name word application-name hasOne application-negate true limit-
application-download true limit 200 limit-application-upload true limit
5
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 49
delete access-rule type outgoing
Syntax
Parameters
Parameter Description
name name
Type: A string of alphanumeric characters without space between them
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 50
set access-rule type outgoing
Syntax
Parameters
Parameter Description
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 51
set access-rule type outgoing
Parameter Description
application- If true, the rule accepts or blocks all applications but the selected application
negate
Type: Boolean (true/false)
destination- If true, the destination is all traffic except what is defined in the destination field
negate
Type: Boolean (true/false)
log Defines which logging method to use: None - do not log, Log - Create log, Alert -
log with alert, Account - account rule
Options: none, log, alert, account
name name
Type: A string of alphanumeric characters without space between them
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 52
set access-rule type outgoing
Parameter Description
service The network service object that the rule should match to
service-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
source-negate If true, the source is all traffic except what is defined in the source field
Type: Boolean (true/false)
Example
set access-rule type outgoing position 2 action block log none source
TEXT source-negate true destination TEXT destination-negate true
service TEXT service-negate true disabled true comment "This is a
comment." hours-range-enabled true hours-range-from 23:20 hours-range-
to 23:20 position 2 name word application-name hasOne application-
negate true limit-application-download true limit 100 limit-
application-upload true limit 5
set access-rule type outgoing name word action block log none source
TEXT source-negate true destination TEXT destination-negate true
service TEXT service-negate true disabled true comment "This is a
comment." hours-range-enabled true hours-range-from 23:20 hours-range-
to 23:20 position 2 name word application-name hasOne application-
negate true limit-application-download true limit 100 limit-
application-upload true limit 5
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 53
show access-rule type outgoing
Syntax
Parameters
Parameter Description
name name
Type: A string of alphanumeric characters without space between them
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 54
access-rule type incoming-internal-and-vpn
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 55
add access-rule type incoming-internal-and-vpn
Syntax
Parameters
Parameter Description
destination- If true, the destination is all traffic except what is defined in the destination field
negate
Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 56
add access-rule type incoming-internal-and-vpn
Parameter Description
log Defines which logging method to use: None - do not log, Log - Create log, Alert - log
with alert, Account - account rule
Options: none, log, alert, account
name name
Type: A string of alphanumeric characters without space between them
service The network service object that the rule should match to
service-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
source-negate If true, the source is all traffic except what is defined in the source field
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 57
delete access-rule type incoming-internal-and-vpn
Syntax
Parameters
Parameter Description
name Name
Type: A string of alphanumeric characters without space between them
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 58
set access-rule type incoming-internal-and-vpn
Syntax
Parameters
Parameter Description
destination- If true, the destination is all traffic except what is defined in the destination field
negate
Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 59
set access-rule type incoming-internal-and-vpn
Parameter Description
log Defines which logging method to use: None - do not log, Log - Create log, Alert - log
with alert, Account - account rule
Options: none, log, alert, account
name name
Type: A string of alphanumeric characters without space between them
service The network service object that the rule should match to
service-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
source-negate If true, the source is all traffic except what is defined in the source field
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 60
set access-rule type incoming-internal-and-vpn
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 61
show access-rule type incoming-internal-and-vpn
Syntax
Parameters
Parameter Description
name name
Type: A string of alphanumeric characters without space between them
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 62
additional-hw-settings
additional-hw-settings
Relevant commands for additional hardware settings.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 63
set additional-hw-settings
set additional-hw-settings
Description
Configures various hardware settings.
Syntax
Parameters
Parameter Description
reset- Indicates the amount of time (in seconds) that you need to press and hold the factory
timeout defaults button on the back panel to restore to the factory defaults image
Type: A number with no fractional part (integer)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 64
show additional-hw-settings
show additional-hw-settings
Description
Shows advanced hardware related setings.
Syntax
show additional-hw-settings
Parameters
Parameter Description
n/a
Example
show additional-hw-settings
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 65
additional-management-settings
additional-management-settings
Commands relevant for additional management settings.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 66
set additional-management-settings
set additional-management-settings
Description
Configure additional management settings.
Syntax
Parameters
Parameter Description
advanced-settings Indicates whether the temporary policy installation files will be saved to the
storage partition
install-temporary-
policy- Type: Boolean (true/false)
to-storage
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 67
show additional-management-settings
show additional-management-settings
Description
Show the additional management settings that were configured.
Syntax
show additional-management-settings
Parameters
Parameter Description
n/a
Example
show additional-management-settings
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 68
ad-server
ad-server
Relevant commands for ad server
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 69
add ad-server
add ad-server
Description
Adds a new Active Directory server object.
Syntax
When you fill the branch-path field, you can add multiple branches by chaining them into a single string with
a semi-colon separator between them: branch1path;branch2path;branch3path
Parameters
Parameter Description
use-branch- Select only if you want to use only part of the user database defined in the Active
path Directory
Type: Boolean (true/false)
username A user name with administrator privileges to communicate with the AD server
Type: A string that contains (0-9, a-z, - . @) up to 64 characters without spaces
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 70
delete ad-server
delete ad-server
Description
Deletes an existing Active Directory server object.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 71
set ad-server
set ad-server
Description
Configures an existing Active Directory server object.
Syntax
Parameters
Parameter Description
use-branch- Select only if you want to use only part of the user database defined in the Active
path Directory
Type: Boolean (true/false)
username A user name with administrator privileges to communicate with the AD server
Type: A string that contains (0-9, a-z, - . @) up to 64 characters without spaces
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 72
show ad-server
show ad-server
Description
Shows settings of a configured Active Directory server object.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 73
show ad-servers
show ad-servers
Description
Shows settings of all configured AD server objects.
Syntax
show ad-servers
Parameters
Parameter Description
n/a
Example
show ad-servers
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 74
address-range
address-range
Relevant commands for address range.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 75
add address-range
add address-range
Description
Adds a new IP address range object.
Syntax
Parameters
Parameter Description
dhcp-exclude-ip-addr Indicates if the object's IP address(es) is excluded from internal DHCP daemon
Options: on, off
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 76
delete address-range
delete address-range
Description
Deletes an existing address range object.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 77
set address-range
set address-range
Description
Configures an existing IP address range object.
Syntax
Parameters
Parameter Description
dhcp-exclude-ip-addr Indicates if the object's IP address(es) is excluded from internal DHCP daemon
Options: on, off
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 78
show address-range
show address-range
Description
Shows settings of a configured IP address range object.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 79
show address-ranges
show address-ranges
Description
Shows settings of all configured IP address range objects.
Syntax
show address-ranges
Parameters
Parameter Description
n/a
Example
show address-ranges
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 80
admin-access
admin-access
Relevant commands for admin access.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 81
add admin access
Syntax
add admin-access-ipv4-address
{single-ipv4-address|network-ipv4-address} <ip_addr> {subnet-mask
<netmask>|mask-length <mask_length>}
Parameters
Parameter Description
Return Value
0 on success, 1 on failure
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 82
set admin-access
set admin-access
Description
Configures various parameters for administrator access to the device via web/SSH.
Syntax
Parameters
Parameter Description
access Enable administrator access from the Internet (clear traffic from external interfaces)
Type: Boolean (true/false)
support- For security reasons, it is highly recommended never to change this parameter's value.
weak-tls- Support of TLSv1.0 will be added back to the administration portal to allow connectivity
version with old browsers (usually ones released prior to 2014). Changing the default of this
parameter exposes the administration portal to at- tacks that use vulnerabilities like
Heartbleed (CVE-2014-0160).
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 83
show admin-access
show admin-access
Description
Shows settings of administrator access configuration.
Syntax
show admin-access
Parameters
Parameter Description
n/a
Example
show admin-access
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 84
admin-access-ip-addresses
admin-access-ip-addresses
Relevant commands for admin access IP addresses.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 85
show admin-access-ip-addresses
show admin-access-ip-addresses
Description
Show all the configured IP addresses that are permitted for administrator access to the appliance.
Syntax
show admin-access-ip-addresses
Parameters
Parameter Description
n/a
Example
show admin-access-ip-addresses
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 86
delete admin-access-ip-address-all
delete admin-access-ip-address-all
Description
Delete all the reserved IP addresses for administrator access.
Syntax
delete admin-access-ip-address-all
Parameters
Parameter Description
n/a
Example
delete admin-access-ip-address-all
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 87
admin-access-ipv4-address
admin-access-ipv4-address
Relevant commands for admin access IPv4 addresses.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 88
add admin-access-ipv4-address
add admin-access-ipv4-address
Adds a specific IPv4 address or an IPv4 address network and mask from which the administrator can
remotely access the appliance according to configuration.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 89
add admin-access-ipv4-address
add admin-access-ipv4-address
Description
Adds a specific IPv4 address from which the administrator can remotely access the appliance according to
configuration.
Syntax
Parameters
Parameter Description
single-ipv4-address IP address
Type: IP address
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 90
add admin-access-ipv4-address
add admin-access-ipv4-address
Description
Adds an IPv4 address network and mask from which the administrator can remotely access the appliance
according to configuration.
Syntax
Parameters
Parameter Description
network-ipv4-address IP address
Type: IP address
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 91
delete admin-access-ipv4-address
delete admin-access-ipv4-address
Description
Deletes a specific IPv4 address or an IPv4 network and subnet from which the administrator can remotely
access the appliance according to configuration.
Syntax
Parameters
Parameter Description
ipv4-address IP address
Type: IP address
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 92
show admin-access-ipv4-addresses
show admin-access-ipv4-addresses
Description
Shows allowed IP addresses for admin access.
Syntax
show admin-access-ipv4-addresses
Parameters
Parameter Description
n/a
Example
show admin-access-ipv4-addresses
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 93
delete admin-access-ipv4-address-all
delete admin-access-ipv4-address-all
Description
Deletes all configured IPv4 addresses from which the administrator can remotely access the appliance
according to configuration.
Syntax
delete admin-access-ipv4-address-all
Parameters
Parameter Description
n/a
Example
delete admin-access-ipv4-address-all
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 94
administrator
administrator
Relevant commands for admininstrators.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 95
add administrator
add administrator
Description
Adds a new user who can access the administration web portal and SSH.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 96
delete administrator
delete administrator
Description
Deletes an existing defined administrator. The system will not allow deletion of the last administrator.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 97
set administrator
set administrator
Configures an existing user with administrator privileges.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 98
set administrator
set administrator
Description
Configures a new password for an existing administrator. You will be prompted to add a new password
following this command (this command cannot be used in a script).
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 99
set administrator
set administrator
Description
Configures an existing administrator's permission level and password (by hash).
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 100
set administrators
set administrators
Configure users with administrator privileges through a RADIUS server.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 101
set administrators
set administrators
Description
Configures users with administrator privileges through a RADIUS server.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 102
show administrator
show administrator
Description
Shows settings of an existing user with administrator privileges.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 103
show administrators
show administrators
Shows settings of all users with administrator privileges.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 104
show administrators
show administrators
Description
Shows settings of all users with administrator privileges.
Syntax
show administrators
Parameters
Parameter Description
n/a
Example
show administrators
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 105
show administrators
show administrators
Description
Shows advanced settings of all users with administrator privileges.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 106
administrators radius-auth
administrators radius-auth
Relevant commands for administrator radius authentication.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 107
set administrators radius-auth
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 108
set administrators radius-auth (legacy mode)
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 109
show administrators radius-auth
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 110
show administrators radius-auth
administrators roles-settings
Commands relevant for configuring administrator roles
Syntax
Parameters
Parameter Description
roles-conf The configuration of administrator roles in base64 format. To get the right configuration,
contact Check Point Support.
Type: base64
Example
Syntax
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 111
show administrators radius-auth
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 112
administrator session-settings
administrator session-settings
Relevant commands for administrator session settings.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 113
set administrator session-settings
Syntax
Parameters
Parameter Description
inactivity-timeout Allowed web interface session idle time before automatic logout is executed (in
minutes)
Type: A number with no fractional part (integer)
lock-period Once locked out, the administrator will be unable to login for this long
Type: A number with no fractional part (integer)
max-lockout- The maximum number of consecutive login failure attempts before the
attempts administrator is locked out
Type: A number with no fractional part (integer)
password- Number of days before administrator is required to change his password. Takes
expiration- effect only if password complexity level is set to 'high'
timeout
Type: A number with no fractional part (integer)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 114
show administrator session-settings
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 115
show adsl statistics
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 116
aggressive-aging
aggressive-aging
Relevant commands for aggressive aging.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 117
set aggressive-aging
set aggressive-aging
Configures aggressive aging feature's behavior. Aggressive Aging is designed to optimize how the device
is dealing with a large connection number by aggressively reducing the timeout of existing connections
when necessary.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 118
set aggressive-aging
set aggressive-aging
Description
Configures aggressive aging default reduced timeouts.
Syntax
Parameters
Parameter Description
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 119
set aggressive-aging
Parameter Description
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 120
set aggressive-aging
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 121
set aggressive-aging
set aggressive-aging
Description
Configures aggressive aging advanced settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 122
show aggressive-aging
show aggressive-aging
Shows aggressive aging settings.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 123
show aggressive-aging
show aggressive-aging
Description
Shows aggressive aging settings.
Syntax
show aggressive-aging
Parameters
Parameter Description
n/a
Example
show aggressive-aging
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 124
show aggressive-aging
show aggressive-aging
Description
Shows aggressive aging advanced settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 125
antispam
antispam
Relevant commands for Anti-Spam Software Blade and settings.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 126
set antispam
set antispam
Configures policy for Anti-Spam blade.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 127
set antispam
set antispam
Description
Configures the policy for Anti-Spam blade.
Syntax
Parameters
Parameter Description
action-spam-email- Action to be used upon spam detection in email content: block, flag-
content header, flag-subject
Options: block, flag-header, flag-subject
action-suspected- spam- Action to be used upon suspected spam detection in email content: block,
email-content flag-header, flag-subject
Options: block, flag-header, flag-subject
flag-subject-stamp Text to add to spam emails' subject (depends on action chosen for
detected spam)
Type: A string of alphanumeric characters with space between them
flag-suspected-spam- Text to add to suspected spam emails subject (depends on action chosen
subject-stamp for detected spam)
Type: A string of alphanumeric characters with space between them
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 128
set antispam
Parameter Description
specify-suspected- spam- Handle suspected spam emails differently from spam emails
settings
Type: Boolean (true/false)
suspected-spam-log Tracking options for suspected spam emails: log, alert or none
Options: none, log, alert
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 129
set antispam
set antispam
Description
Configures advanced setting for the Anti-Spam blade.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 130
set antispam
set antispam
Description
Configures advanced setting for the Anti-Spam blade.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 131
set antispam
set antispam
Description
Configures advanced setting for the Anti-Spam blade.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 132
set antispam
set antispam
Description
Configures advanced setting for the Anti-Spam blade.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 133
set antispam
set antispam
Description
Configures advanced setting for the Anti-Spam blade.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 134
set antispam
set antispam
Description
Configures advanced setting for the Anti-Spam blade.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 135
set antispam
set antispam
Description
Configures advanced setting for the Anti-Spam blade.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 136
set antispam
set antispam
Description
Configures advanced setting for the Anti-Spam blade.
Syntax
<spam-engine-all-mail-track>
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 137
show antispam
show antispam
Shows the configured policy for the Anti-Spam blade.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 138
show antispam
show antispam
Description
Shows the configured policy for the Anti-Spam blade.
Syntax
show antispam
Parameters
Parameter Description
n/a
Example
show antispam
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 139
show antispam
show antispam
Description
Shows the advanced settings in the configured policy for the Anti-Spam blade.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 140
antispam allowed-sender
antispam allowed-sender
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 141
add antispam allowed-sender
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 142
add antispam allowed-sender
Description
Adds a new Anti-Spam "allow" exception for a specific IP address.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 143
add antispam allowed-sender
Description
Adds a new Anti-Spam "allow" exception for a sender email or domain.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 144
delete antispam allowed-sender
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 145
delete antispam allowed-sender
Description
Deletes all existing Anti-Spam "allow" exceptions.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 146
delete antispam allowed-sender
Description
Deletes an existing Anti-Spam "allow" exception for sender's email or domain.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 147
delete antispam allowed-sender
Description
Deletes an existing Anti-Spam "allow" exception for a specific IPv4 address.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 148
show antispam allowed-senders
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 149
antispam blocked-sender
antispam blocked-sender
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 150
add antispam blocked-sender
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 151
add antispam blocked-sender
Description
Adds a new Anti-Spam "block" exception for a specific IP address.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 152
add antispam blocked-sender
Description
Adds a new Anti-Spam "block" exception for a sender email or domain.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 153
delete antispam blocked-sender
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 154
delete antispam blocked-sender
Description
Deletes all existing Anti-Spam "block" exceptions.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 155
delete antispam blocked-sender
Description
Deletes an existing Anti-Spam "block" exception for sender's email or domain.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 156
delete antispam blocked-sender
Description
Deletes an existing Anti-Spam "block" exception for a specific IPv4 address.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 157
show antispam blocked-senders
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 158
application
application
Relevant commands for application.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 159
add application
add application
Adds a new custom application object (string or regular expression signature over URL).
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 160
add application
add application
Description
Adds a new custom application object (string or regular expression signature over URL).
Syntax
Parameters
Parameter Description
category The primary category for the application (the category which is the most relevant)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 161
add application
add application
Description
Simplified method for adding a new custom application object (string over URL)
Syntax
add application-url <application-url>
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 162
delete application
delete application
Deletes an existing custom application object (string or regular expression signature over URL).
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 163
delete application
delete application
Description
Deletes an existing custom application object by application ID.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 164
delete application
delete application
Description
Deletes an existing custom application object by application name.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 165
find application
find application
Description
Find an application by name (or partial string) to view further details regarding it.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 166
set application
set application
Configures an existing custom application object.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 167
set application
set application
Description
Adds a URL to an existing custom application object by name.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 168
set application
set application
Description
Removes a URL from an existing custom application object by name.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 169
set application
set application
Description
Adds a URL to an existing custom application object by ID.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 170
set application
set application
Description
Removes a URL from an existing custom application object by ID.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 171
set application
set application
Description
Adds a category to an existing custom application object by name.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 172
set application
set application
Description
Removes a category from an existing custom application object by name.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 173
set application
set application
Description
Adds a category to an existing custom application object by ID.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 174
set application
set application
Description
Removes a category from an existing custom application object by ID.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 175
set application
set application
Description
Configures an existing custom application by ID.
Syntax
Parameters
Parameter Description
category The primary category for the application (the category which is the most relevant)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 176
set application
set application
Description
Configures an existing custom application by name.
Syntax
Parameters
Parameter Description
category The primary category for the application (the category which is the most relevant)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 177
show application
show application
Shows details for a specific application in the Application Control database.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 178
show application
show application
Description
Shows details for a specific application in the Application Control database by application name.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 179
show application
show application
Description
Shows details for a specific application in the Application Control database by application ID.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 180
show applications
show applications
Description
Shows details of all applications.
Syntax
show applications
Parameters
Parameter Description
n/a
Example
show applications
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 181
application-control
application-control
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 182
set application-control
set application-control
Description
Configures the default policy for the Application Control and URL filtering blades.
Syntax
Parameters
Parameter Description
block-security- Block applications and URLs that can be a security risk and are categorized as
categories spyware, phishing, botnet, spam, anonymizer, or hacking
Type: Boolean (true/false)
limit-bandwidth Indicates if applications that use a lot of bandwidth are limited (also used for
QoS)
Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 183
set application-control
Parameter Description
mode Applications & URLs mode - true for on, false for off
Type: Boolean (true/false)
url-flitering-only Indicates if enable URL Filtering and detection only mode is enabled
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 184
show application-control
show application-control
Description
Shows the configured policy for the Application Control blade
Syntax
show application-control
Parameters
Parameter Description
n/a
Example
show application-control
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 185
show application-control other-undesired-applications
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 186
application-control-engine-settings
application-control-engine-settings
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 187
set application-control-engine-settings
set application-control-engine-settings
Configures Application Control blade's advanced engine settings.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 188
set application-control-engine-settings
set application-control-engine-settings
Description
Configures Application Control blade's advanced engine settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 189
set application-control-engine-settings
set application-control-engine-settings
Description
Configures Application Control blade's advanced engine settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 190
set application-control-engine-settings
set application-control-engine-settings
Description
Configures Application Control blade's advanced engine settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 191
set application-control-engine-settings
set application-control-engine-settings
Description
Configures Application Control blade's advanced engine settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 192
set application-control-engine-settings
set application-control-engine-settings
Description
Configures Application Control blade's advanced engine settings.
Syntax
<track-browse-time>
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 193
set application-control-engine-settings
set application-control-engine-settings
Description
Configures Application Control blade's advanced engine settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 194
set application-control-engine-settings
set application-control-engine-settings
Description
Configures Application Control blade's advanced engine settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 195
show application-control-engine-settings
show application-control-engine-settings
Description
Shows advanced settings of the Application Control blade.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 196
application-group
application-group
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 197
add application-group
add application-group
Description
Adds a new group object for applications.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 198
delete application-group
delete application-group
Deletes an existing group object of applications.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 199
delete application-group
delete application-group
Description
Deletes an existing group object of applications by group object name.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 200
delete application-group
delete application-group
Description
Deletes an existing group object of applications by group object ID.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 201
set application-group
set application-group
Configures an existing application group object.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 202
set application-group
set application-group
Description
Adds an application to an existing application group object by application's name.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 203
set application-group
set application-group
Description
Removes an application from an existing application group object by application's name.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 204
set application-group
set application-group
Description
Adds an application to an existing application group object by application's ID.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 205
set application-group
set application-group
Description
Removes an application from an existing application group object by application's ID.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 206
set application-group
set application-group
Description
Adds an application to an existing application group object by application's name using group object's ID.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 207
set application-group
set application-group
Description
Removes an application from an existing application group object by application's name using group
object's ID.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 208
set application-group
set application-group
Description
Adds an application to an existing application group object by application's ID using group object's ID.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 209
set application-group
set application-group
Description
Removes an application from an existing application group object by application's ID using group object's
ID.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 210
show application-group
show application-group
shows the configuration of the Application group objects.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 211
show application-group
show application-group
Description
Shows the configuration of a specific application group object by ID.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 212
show application-group
show application-group
Description
Shows the configuration of a specific application group object by name.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 213
show application-groups
show application-groups
Description
Shows the configuration of all specific application group objects.
Syntax
show application-groups
Parameters
Parameter Description
n/a
Example
show application-groups
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 214
antispoofing
antispoofing
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 215
set antispoofing
set antispoofing
Description
Configures the activation of the IP address Anti-Spoofing feature.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 216
show antispoofing
show antispoofing
Description
Shows the configuration for IP addresses Anti-Spoofing functionality.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 217
backup settings
backup settings
Description
Creates a backup file that contains the current settings for the appliance and saves them to a file. The file is
saved to either a USB device or TFTP server. You can use these options when the backup file is created:
n Specific file name (The default file name contains the current image and a date and time stamp)
n Password encryption
n Backup policies
n Add a comment to the file
Syntax
Parameters
Parameter Description
pass Password for the file. Alphanumeric and special characters are allowed.
Return Value
0 on success, 1 on failure
Example
Output
Success prints OK. Failure shows an appropriate error message.
Comments
When saving the backup file to a USB device, the backup settings command fails if there are two USB
devices connected to the appliance.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 218
show backup settings
Syntax
Parameters
Parameter Description
Example
show backup-settings-log
Output
Success shows backup settings information. Failure shows an appropriate error message.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 219
blade-update-schedule
blade-update-schedule
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 220
set blade-update-schedule
set blade-update-schedule
Configures schedule for Software Blade updates.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 221
set blade-update-schedule
set blade-update-schedule
Description
Configures schedule forSoftware Blades updates.
Syntax
Parameters
Parameter Description
day-of-month If the update occurs monthly, this is the day in which it occurs
Type: A number with no fractional part (integer)
day-of-week If the update occurs weekly, this is the weekday in which it occurs
Options: sunday, monday, tuesday, wednesday, thursday, friday, saturday
hour-interval If the update occurs hourly, this indicates the hour interval between each update
Type: A number with no fractional part (integer)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 222
set blade-update-schedule
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 223
set blade-update-schedule
set blade-update-schedule
Description
Configures advanced settings for Software Blade updates.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 224
set blade-update-schedule
set blade-update-schedule
Description
Configures advanced settings for Software Blade updates.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 225
show blade-update-schedule
show blade-update-schedule
Shows the configuration of Software Blade updates schedule.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 226
show blade-update-schedule
show blade-update-schedule
Description
Shows the configuration of Software Blade updates schedule
Syntax
show blade-update-schedule
Parameters
Parameter Description
n/a
Example
show blade-update-schedule
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 227
show blade-update-schedule
show blade-update-schedule
Description
Shows advanced settings of Software Blade updates schedule.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 228
bookmark
bookmark
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 229
add bookmark
add bookmark
Description
Adds a new bookmark link that will appear for VPN remote access users in the SNX VPN remote access
landing page.
Syntax
Parameters
Parameter Description
is-global Indicates if the bookmark will be displayed for all remote access users
Type: Boolean (true/false)
label Text for the bookmark in the SSL Network Extender portal
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
screen-height The height of the screen when the bookmark is remote desktop
Type: A number with no fractional part (integer)
screen-width The width of the screen when the bookmark is remote desktop
Type: A number with no fractional part (integer)
tooltip Tooltip for the bookmark in the SSL Network Extender portal
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
url Bookmark URL - should start with http:// or https:// for a bookmark of type link
Type: URL
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 230
add bookmark
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 231
delete bookmark
delete bookmark
Deletes an existing bookmark link that appears in the SNX VPN remote access landing page.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 232
delete bookmark
delete bookmark
Description
Deletes an existing bookmark link by label.
Syntax
Parameters
Parameter Description
label Text for the bookmark in the SSL Network Extender portal
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 233
delete bookmark
delete bookmark
Description
Deletes all existing bookmark links.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 234
set bookmark
set bookmark
Description
Configures an existing bookmark shown to users in the SNX landing page.
Syntax
Parameters
Parameter Description
is-global Indicates if the bookmark will be displayed for all remote access users
Type: Boolean (true/false)
label Text for the bookmark in the SSL Network Extender portal
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
new-label Text for the bookmark in the SSL Network Extender portal
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
screen-height The height of the screen when the bookmark is remote desktop
Type: A number with no fractional part (integer)
screen-width The width of the screen when the bookmark is remote desktop
Type: A number with no fractional part (integer)
tooltip Tooltip for the bookmark in the SSL Network Extender portal
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
url Bookmark URL - should start with http:// or https:// for a bookmark of type link
Type: URL
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 235
set bookmark
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 236
show bookmark
show bookmark
Description
Shows the configuration of a bookmark defined to be shown to users when connecting to the SNX portal
using remote access VPN.
Syntax
Parameters
Parameter Description
label Text for the bookmark in the SSL Network Extender portal
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 237
show bookmarks
show bookmarks
Description
Shows all bookmarks defined to be shown to users when connecting to the SNX portal using remote
access VPN.
Syntax
show bookmarks
Parameters
Parameter Description
n/a
Example
show bookmarks
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 238
bridge
bridge
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 239
add bridge
add bridge
Description
Adds a new bridge.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 240
delete bridge
delete bridge
Description
Deletes an existing bridge.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 241
set bridge
set bridge
Configures an existing bridge interface.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 242
set bridge
set bridge
Description
Configures an existing bridge interface.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 243
set bridge
set bridge
Description
Adds an existing network/interface to an existing bridge.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 244
set bridge
set bridge
Description
Removes an existing network/interface from an existing bridge.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 245
show bridge
show bridge
Description
Shows configuration and statistics of a defined bridge.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 246
show bridges
show bridges
Description
Shows details of all defined bridges.
Syntax
show bridges
Parameters
Parameter Description
n/a
Example
show bridges
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 247
show clock
show clock
Description
Shows current system date and time.
Syntax
show clock
Parameters
Parameter Description
n/a
Example
show clock
Output
Success shows date and time. Failure shows an appropriate error message.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 248
cloud-deployment
cloud-deployment
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 249
set cloud-deployment
set cloud-deployment
Description
Configures different settings for zero-touch deployment. Command is relevant to preset files.
Syntax
Parameters
Parameter Description
cloud-url The DNS or IP address through which the device will connect to the cloud service
Type: URL
container Container
Type: String
template Template
Type: String
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 250
show cloud-deployment
show cloud-deployment
Description
Shows the configuration of cloud management connection.
Syntax
show cloud-deployment
Parameters
Parameter Description
n/a
Example
show cloud-deployment
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 251
cloud-notifications
cloud-notifications
These commands are relevant for Cloud notifications
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 252
set cloud-notification
set cloud-notification
Description
Turn on/off a specific notification type.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 253
show cloud-notifications
show cloud-notifications
Description
Show mode for all types of notifications
Syntax
show cloud-notifications
Parameters
Parameter Description
n/a
Example
show cloud-notifications
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 254
send cloud-report
send cloud-report
Description
Force sending a report to Cloud Services.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 255
cloud-services
cloud-services
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 256
reconnect cloud-services
reconnect cloud-services
Description
Force a manual reconnection to Cloud Services.
Syntax
reconnect cloud-services
Parameters
Parameter Description
n/a
Example
reconnect cloud-services
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 257
set cloud-services
set cloud-services
Configures settings for cloud/SMP management connection.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 258
set cloud-services
set cloud-services
Description
Configures settings for cloud/SMP management connection.
Syntax
Parameters
Parameter Description
activation-key A key received from the Cloud Services provider which is used to initialize the
connection to the Cloud Services
Type: String
gateway-id Gateway id (in the format <gateway name>.<portal name>). This is not needed if an
activation-key was configured.
Type: cloudGwName
registration- Registration key that acts as a password when connecting to the cloud service for the
key first time. This is not needed if an activation-key was configured.
Type: A registration key
service-center The DNS or IP address through which the device will connect to the cloud service for
the first time. This is not needed if an activation-key was configured.
Type: URL
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 259
set cloud-services
set cloud-services
Description
Configures advanced settings for cloud/SMP management connection.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 260
show cloud-services
show cloud-services
Description
Shows advanced settings of cloud management connection.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 261
show cloud-services connection-details
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 262
cloud-services-firmware-upgrade
cloud-services-firmware-upgrade
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 263
set cloud-services-firmware-upgrade
set cloud-services-firmware-upgrade
Configure settings for the "firmware upgrade" Cloud Services.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 264
set cloud-services-firmware-upgrade
set cloud-services-firmware-upgrade
Description
Configures settings for the "firmware upgrade" Cloud Services.
Syntax
Parameters
Parameter Description
activate Enable auto firmware upgrades. Upgrades may occur immediately or be scheduled
according to a predefined frequency
Type: Boolean (true/false)
frequency Indicates the preferred time to perform upgrade once a new firmware is detected
Type: Press TAB to see available options
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 265
set cloud-services-firmware-upgrade
set cloud-services-firmware-upgrade
Description
Configures advanced settings for the "firmware upgrade" Cloud Services.
Syntax
<max-num-of-retries>
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 266
set cloud-services-firmware-upgrade
set cloud-services-firmware-upgrade
Description
Configures advanced settings for the "firmware upgrade" Cloud Services.
Syntax
<timeout-until-retry>
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 267
show cloud-services-firmware-upgrade
show cloud-services-firmware-upgrade
Shows configuration of the "Firmware Upgrade" Cloud Services.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 268
show cloud-services-firmware-upgrade
show cloud-services-firmware-upgrade
Description
Shows configuration of the "Firmware Upgrade" Cloud Services.
Syntax
show cloud-services-firmware-upgrade
Parameters
Parameter Description
n/a
Example
show cloud-services-firmware-upgrade
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 269
show cloud-services-firmware-upgrade
show cloud-services-firmware-upgrade
Description
Shows advanced settings of the "Firmware Upgrade" Cloud Services.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 270
show cloud-service managed-blades
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 271
show cloud-services managed-services
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 272
fetch cloud-services policy
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 273
show cloud-services status
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 274
show commands
show commands
Description
Shows all available CLI commands.
Syntax
show commands
Parameters
Parameter Description
n/a
Example
show commands
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 275
cphaprob
cphaprob
Description
Defines and manages the critical cluster member properties of the appliance. When a critical process fails,
the appliance is considered to have failed.
Syntax
Parameters
Parameter Description
-d The name of the device as it appears in the output of the cphaprob list.
<device>
-p The configuration change is permanent and applies after the appliance reboots.
-s Status to be reported.
ok - <appliance> is alive
init - <appliance> is initializing
problem - <appliance> has failed
-f <file> Option to automatically register several appliances. The file defined in the <file> field
register should contain the list of appliances with these parameters:
n <device>
n <timeout>
n Status
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 276
cphaprob
Parameter Description
state Displays the state of all the gateways in the High Availability configuration.
Example
Output
Success prints OK. Failure shows an appropriate error message.
These are some typical scenarios for the cphaprob command.
Argument Description
cphaprob -f <file> register Register all the user defined critical devices listed in
<file>.
cphaprob [-i[a]] [-e] list View the list of critical devices on a cluster member, and
of all the other machines in the cluster.
cphaprob state View the status of a cluster member, and of all the other
members of the cluster.
cphaprob [-a] if View the state of the cluster member interfaces and the
virtual cluster interfaces.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 277
cphaprob
Examples
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 278
cphastop
cphastop
Description
Disables High Availability on the appliance. Running cphastopon an appliance that is a cluster member
stops the appliance from passing traffic. State synchronization also stops.
Syntax
cphastop
Parameters
Parameter Description
n/a
Return Value
0 on success, 1 on failure
Example
cphastop
Output
Success prints OK. Failure shows an appropriate error message.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 279
cpinfo
cpinfo
Description
Creates a Check Point Support Information (CPinfo) file on a machine at the time of execution.
The files is saved to a USB drive or TFTP server.
The CPinfo output file enables Check Point's support engineers to analyze setups from a remote location.
Syntax
Parameters
Parameter Description
Return Value
0 on success, 1 on failure
Example
cpinfo to-usb
Output
Success prints Creating cpinfo.txt file. Failure shows an appropriate error message.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 280
cpstart
cpstart
Start all Check Point processes and applications running on a machine.
Description
Starts firewall services.
Syntax
cpstart
Parameters
Parameter Description
n/a
Return Value
0 on success, 1 on failure
Example
cpstart
Output
Success shows Starting CP products.... Failure shows an appropriate error message.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 281
cpstat
cpstat
Description
Shows Check Point statistics for applications.
Syntax
cpstat [-p <port>] [-s <SICname>] [-f <flavor>] [-o <polling>] [-c
<count>] [-e <period>] [-x] [-j] [-d] application_flag <flag>
Parameters
Parameter Description
-p <port> Port number of the server. The default is the standard server port (18192).
-f The flavor of the output (as it appears in the configuration file). The default is the first
<flavor> flavor found in the configuration file.
-c Specifies how many times the results are shown. The default is 0, meaning the results
<count> are repeatedly shown.
-e Specifies the interval (seconds) over which 'statistical' olds are computed. Ignored for
<period> regular olds.
-d Debug mode.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 282
cpstat
Parameter Description
Return Value
0 on success, 1 on failure
Example
cpstat -c 3 -o 3 fw
Output
Success shows OK. Failure shows an appropriate error message.
The following flavors can be added to the application flags:
n fw- "default", "interfaces", "all", "policy", "perf", "hmem", "kmem", "inspect", "cookies", "chains",
"fragments", "totals", "ufp", "http", "ftp", "telnet", "rlogin", "smtp", "pop3", "sync"
n vpn- "default", "product", "IKE", "ipsec", "traffic", "compression", "accelerator", "nic", "statistics",
"watermarks", "all"
n fg- "all"
n ha- "default", "all"
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 283
cpstat
n os- "default", "ifconfig", "routing", "memory", "old_memory", "cpu", "disk", "perf", "multi_cpu", "multi_
disk", "all", "average_cpu", "average_memory", "statistics"
n mg- "default"
n persistency- "product", "Tableconfig", "SourceConfig"
n polsrv- "default", "all"
n uas- "default"
n svr- "default"
n cpsemd- "default"
n cpsead- "default"
n asm- "default", "WS"
n ls- "default"
n ca- "default", "crl", "cert", user", "all"
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 284
cpstop
cpstop
Description
Stops firewall services and terminates all Check Point processes and applications running on the
appliance.
Syntax
cpstop
Parameters
Parameter Description
n/a
Return Value
0 on success, 1 on failure
Example
cpstop
Output
Success shows Uninstalling Security Policy.... Failure shows an appropriate error
message.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 285
cpwd_admin
cpwd_admin
Description
The cpwd_admin utility can be used to verify if a process is running and to stop and start a process if
necessary.
Syntax
cpwd_admin {del <name>|detach <name>|list|kill|exist|start_monitor|stop_
monitor|
monitor_list}
Parameters
Parameter Description
Return Value
0 on success, 1 on failure
Example
cpwd_admin start_monitor
Output
Success shows OK. Failure shows an appropriate error message.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 286
date
date
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 287
set date
set date
Configures the device's date and time.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 288
set date
set date
Description
Manually configure the device's date.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 289
set date
set date
Description
Manually configure the device's time.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 290
set date
set date
Description
Manually configure the device's time zone.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 291
set date
set date
Description
Configures if the daylight savings will be changed automatically.
Syntax
Parameters
Parameter Description
timezone-dst automatic Automatic adjustment clock for daylight saving changes flag
Options: on, off
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 292
show date
show date
Shows date and time.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 293
show date
show date
Description
Shows current date of the appliance.
Syntax
show date
Parameters
Parameter Description
n/a
Example
show date
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 294
show date
show date
Description
Shows current time of the appliance.
Syntax
show time
Parameters
Parameter Description
n/a
Example
show time
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 295
show date
show date
Description
Shows current time zone of the appliance.
Syntax
show timezone
Parameters
Parameter Description
n/a
Example
show timezone
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 296
show date
show date
Description
Shows current daylight savings configuration of the appliance.
Syntax
show timezone-dst
Parameters
Parameter Description
n/a
Example
show timezone-dst
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 297
restore default-settings
restore default-settings
Description
Restores the default settings of the appliance without affecting the software image. All the custom user
settings for the appliance are deleted.
Syntax
Parameters
Parameter Description
Return Value
0 on success, 1 on failure
Example
Comments
The appliance automatically reboots after the default settings are restored.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 298
dhcp-relay
dhcp-relay
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 299
set dhcp-relay
set dhcp-relay
Description
Configures advanced settings for DHCP Relay functionality.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 300
show dhcp-relay
show dhcp-relay
Description
Shows advanced settings for DHCP relay.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 301
show dhcp servers
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 302
dhcp server interface
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 303
delete dhcp server interface
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 304
set dhcp server interface
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 305
set dhcp server interface
Syntax
Parameters
Parameter Description
cliName cliName
Type: virtual
Example
set dhcp server interface LAN1 custom-option name MyOption type string
tag 43 data TEXT
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 306
set dhcp server interface
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 307
set dhcp server interface
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 308
set dhcp server interface
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 309
set dhcp server interface
Syntax
Parameters
Parameter Description
default-gateway A virtual field calculated by the values of the fields: dhcpGwMode & dhcpGw
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 310
set dhcp server interface
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 311
set dhcp server interface
Syntax
Parameters
Parameter Description
wins primary Configure the IP address for the first WINS server
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 312
set dhcp server interface
Syntax
Parameters
Parameter Description
lease-time Configure the timeout in hours for a single device to retain a dynamically acquired IP
address
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 313
set dhcp server interface
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 314
set dhcp server interface
Syntax
Parameters
Parameter Description
ntp Configure the first NTP (Network Time Protocol) server to be distributed to DHCP client
secondary Configure the second NTP (Network Time Protocol) server to be distributed to DHCP
client
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 315
set dhcp server interface
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 316
set dhcp server interface
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 317
set dhcp server interface
Syntax
Parameters
Parameter Description
callmgr Configure the first Call manager server to be distributed to DHCP client
secondary Configure the second Call manager server to be distributed to DHCP client
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 318
set dhcp server interface
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 319
set dhcp server interface
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 320
set dhcp server interface
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 321
set dhcp server interface
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 322
set dhcp server interface
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 323
set dhcp server interface
Syntax
Parameters
Parameter Description
dns primary Configure the IP address for the first DNS server
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 324
set dhcp server interface
Syntax
Parameters
Parameter Description
dns secondary Configure the IP address for the second DNS server
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 325
set dhcp server interface
Syntax
Parameters
Parameter Description
dns tertiary Configure the IP address for the third DNS server
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 326
set dhcp server interface
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 327
show dhcp server interface
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 328
show dhcp server interface
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 329
show dhcp server interface
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 330
show diag
show diag
Description
Shows information about your appliance, such as the current firmware version and additional details.
Syntax
show diag
Parameters
Parameter Description
n/a
Example
show diag
Output
Current system information.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 331
show disk usage
Syntax
Parameters
Parameter Description
-m 1024*1024 blocks
-k 1024 blocks
Example
show disk-usage-h
Output
Current file system space used and space available.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 332
dns
dns
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 333
delete dns
delete dns
Deletes configured DNS settings.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 334
delete dns
delete dns
Description
Deletes configured primary DNS.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 335
delete dns
delete dns
Description
Deletes configured secondary DNS.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 336
delete dns
delete dns
Description
Deletes configured tertiary DNS.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 337
delete dns
delete dns
Description
Deletes configured domain name of the appliance.
Syntax
delete domainname
Parameters
Parameter Description
n/a
Example
delete domainname
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 338
set dns
set dns
Configures the DNS and domain settings for the device.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 339
set dns
set dns
Description
Configures the DNS settings for the device.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 340
set dns
set dns
Description
Configures the DNS mode for the device. It can either use manually configured DNS servers or use the
DNS servers provided to him by the active internet connection from his ISP.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 341
set dns
set dns
Description
Configures the DNS proxy mode. DNS proxy allows treating the configured network objects as a hosts list
which the device can translate from hostname to IP address for local networks.
Syntax
Parameters
Parameter Description
proxy Relay DNS requests from internal network clients to the DNS servers defined above
Type: Press TAB to see available options
resolving Use network objects as a hosts list to translate names to their IP addresses
Options: on, off
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 342
set dns
set dns
Description
Configures the domain settings for the device.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 343
show dns
show dns
Shows configuration for DNS and domain name.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 344
show dns
show dns
Description
Shows configuration for DNS.
Syntax
show dns
Parameters
Parameter Description
n/a
Example
show dns
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 345
show dns
show dns
Description
Shows configuration for domain name.
Syntax
show domainname
Parameters
Parameter Description
n/a
Example
show domainname
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 346
dsl
dsl
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 347
set dsl advanced-settings global-settings
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 348
set dsl advanced-settings standards
Syntax
Parameters
Parameter Description
annex-m In an Annex A appliance: Combined with supported ADSL2+ it specifies support for Annex
M ADSL2+. In an Annex B appliance: Combined with supported ADSL2 it specifies
support for Annex J ADSL2.
annex-l Combined with enabled ADSL2 (G.992.3) specifies support for Annex L.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 349
set dsl advanced-settings standards
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 350
show dsl advanced-setting
Syntax
Parameters
Parameter Description
n/a
Example
Sample Output
adsl2plus: true
vdsl-8d: true
vdsl-8c: true
vdsl-8b: true
annex-m: false
t1413: true
vdsl-17a: true
adsl-lite: true
vdsl2: true
annex-l: false
vdsl-12b: true
adsl2: true
dmt: true
ginp: disabled
sra: false
vdsl8a: true
vdsl-us0: true
vdsl-12a: true
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 351
show dsl statistics
Syntax
Parameters
Parameter Description
mode Indicates the negotiated DSL mode. Example for a value: VDSL Annex B.
status Indicates the status of DSL connection synchronization. Example values: Showtime,
G.994.
vendor 4 hexa digits representing the vendor of the DSL chip in the peer DSLAM/MSAG (i.e.
IFTN, BDCM) + 4 hex digits representing the firmware version of the vendor.
hec-up Indicates the number of HEC errors counted by the peer DSLAM/MSAG.
attn-down Indicates the attenuation of the power from the peer DSLAM/MSAG to the appliance
(dB).
rs-down Indicates the number of RS words that were received by the appliance in the
downstream.
rs- Indicates the number of RS words that were corrected by the appliance in the
corrected- downstream.
down
rs-up Indicates the number of RS words that were received by the peer DSLAM/MSAG in the
upstream.
rs- Indicates the number of RS words that were corrected by the peer DSLAM/MSAG in the
corrected- upstream.
up
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 352
show dsl statistics
Parameter Description
hec-up Indicates the number of HEC errors counted by the peer DSLAM/MSAG.
total-cells- Indicates the number of 53 bytes (cells in the case of ATM) that were transmitted by the
up appliance.
total-cells- Indicates the number of 53 bytes (cells in the case of ATM) that were received by the
down appliance.
configured- Indicates the seamless rate adaptation (SRA) that was configured in the appliance.
sra Possible values: On, Off.
configured- Indicates whether trellis was enabled in the appliance configuration. Possible values: On,
trellis Off.
configured- Indicates the upstream/downstream on/off for the configured Enhanced Impulse
ginp response. Possible values: Off/Off, Off/On, On/Off, On/On
configured- Indicates the upstream/downstream on/off for the Bit Swap configured in the appliance.
bitswap Possible values: On, Off.
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 353
show dsl statistics
Sample Output
snr-down: 8.7
configured-ginp: Off/Off
power-up: 7.6
rs-corrected-down: 421298
rs-corrected-up: 208
configured-sra: Off
rs-up: 1610329207
configured-trellis: On
total-cells-down: 2609810117
snr-up: 15.4
tpstc: PTM
bitrate-up: 5024
vectoring: 5 (DSLAM is not a vectored DSLAM)
vendor: IFTN:0xb206
status: Showtime
rs-down: 2127995393
mode: VDSL2 Annex B
hec-up: 0
bitrate-down: 48470
training: Showtime
power-down: 7.7
total-cells-up: 0
hec-down: 0
attn-down: 25.9
attn-up: 0.0
configured-bitswap: Off
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 354
dynamic-dns
dynamic-dns
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 355
set dynamic-dns
set dynamic-dns
Configures a persistent domain name for the device.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 356
set dynamic-dns
set dynamic-dns
Description
Configures a persistent domain name for the device.
Syntax
Parameters
Parameter Description
domain The domain name (sometimes called host name) within your account that the device will
use
Type: A FQDN
provider Select the DDNS provider that you have already set up an account with
Options: no-ip.com, DynDns
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 357
set dynamic-dns
set dynamic-dns
Description
Configure advanced settings for the DDNS service.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 358
show dynamic-dns
show dynamic-dns
Shows configuration for DDNS service.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 359
show dynamic-dns
show dynamic-dns
Description
Shows configuration for DDNS service.
Syntax
show dynamic-dns
Parameters
Parameter Description
n/a
Example
show dynamic-dns
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 360
show dynamic-dns
show dynamic-dns
Description
Shows advanced settings for DDNS service.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 361
dynamic objects
dynamic objects
Manages dynamic objects on the appliance. The dynamic_objects command specifies an IP address
to which the dynamic object is resolved.
First, define the dynamic object in the SmartDashboard. Then create the same object with the CLI (-n
argument). After the new object is created on the gateway with the CLI, you can use the dynamic_objects
command to specify an IP address for the object.
Any change you make to dynamic objects' ranges are applied immediately to the objects. It is not
necessary to reinstall the policy.
Description
Manages dynamic objects on the appliance.
Syntax
dynamic_objects -o <object> [-r <fromIP> <toIP> ...] [-a] [-d] [-l] [-n
<object> ] [-c] [-do <object>]
Parameters
Parameter Description
-r Defines the range of IP addresses that are being configured for this object.
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 362
dynamic objects
Output
Success shows Operation completed successfully. Failure shows an appropriate error
message.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 363
exit
exit
Description
Exits from the shell.
Syntax
exit
Parameters
Parameter Description
n/a
Example
exit
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 364
set expert password
Syntax
Parameters
Parameter Description
Example
Output
Success shows OK. Failure shows an appropriate error message.
Comments
To generate a password-hash, you can use this command on any Check Point SMB Appliance gateway
(as an expert user).
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 365
fetch certificate
fetch certificate
Description
Establishes a SIC connection with the Security Management Server and fetches the certificate. You fetch
the certificate from a specific appliance with the gateway-name parameter.
Syntax
Parameters
Parameter Description
Example
Output
Success shows OK. Failure shows an appropriate error message.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 366
fetch policy
fetch policy
Description
Fetches a policy from the Security Management Server with IPv4 address <ip_addr> or from the local
gateway.
Syntax
Parameters
Parameter Description
Return Value
0 on success, 1 on failure
Example
Output
Success shows Done. Failure shows an appropriate error message.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 367
fw commands
fw commands
The fw commands are used for working with various aspects of the firewall. All fwcommands are executed
on the Check Point Security Gateway. For more about the fwcommands, see the Command Line Interface
(CLI) Reference Guide.
fw commands can be found by typing fw [TAB] at a command line. For some of the CLI commands,
you can enter the -h parameter to display all the relevant arguments and parameters. These commands
are:
fw command Explanation
fw sfwd fw daemon
fw stat [-h] Display policy installation status of the gateway. (Command is provided for
backward compatibility.)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 368
fw commands
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 369
fw policy
fw policy
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 370
set fw policy
set fw policy
Configures the default policy for the Firewall blade
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 371
set fw policy
set fw policy
Description
Configures the default policy for the Firewall blade.
Syntax
] [ track-blocked-traffic <track-blocked-traffic> ]
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 372
set fw policy
set fw policy
Description
Configures advanced settings for the default policy of the Firewall blade.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 373
set fw policy
set fw policy
Description
Configures advanced settings for the default policy of the Firewall blade.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 374
show fw policy
show fw policy
Shows the configured policy for the Firewall blade.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 375
show fw policy
show fw policy
Description
Shows the configured policy for the Firewall blade.
Syntax
show fw policy
Parameters
Parameter Description
n/a
Example
show fw policy
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 376
show fw policy
show fw policy
Description
Shows advanced settings for the Firewall blade.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 377
show fw policy
show fw policy
Description
Shows the configuration for customizable messages shown to users upon actions.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 378
set fw policy user-check accept
Syntax
Parameters
Parameter Description
body The informative text that appears in the APPI 'Accept' user message
Type: A string that contains only printable characters
fallback- Indicates the action to take when an 'Accept' user message cannot be displayed
action
Options: block, accept
frequency Indicates how often is the APPI 'Accept' user message is being presented to the same
user
Options: day, week, month
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 379
set fw policy user-check ask
Syntax
Parameters
Parameter Description
body The informative text that appears in the APPI 'Ask' user message
Type: A string that contains only printable characters
confirm-text This text appears next to the 'ignore warning' checkbox of an APPI 'Ask' user
message
Type: A string that contains only printable characters
fallback-action The action that is performed when the 'Ask' message cannot be shown
Options: block, accept
frequency Indicates how often is the APPI 'Ask' user message is being presented to the same
user
Options: day, week, month
reason- Indicates if the user must enter a reason for ignoring this message in a designated
displayed text dialog
Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 380
set fw policy user-check ask
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 381
set fw policy user-check block
Syntax
Parameters
Parameter Description
body The informative text that appears in the APPI 'Block' user message
Type: A string that contains only printable characters
redirect- Indicates if the user will be redirected to a custom URL in case of a 'Block' action
to-url
Type: Boolean (true/false)
redirect- Indicates the URL to redirect the user in case of a 'Block' action if configured to do so. The
url URL to redirect the user in case of a 'Block' action. Redirection happens only if this
functionality is turned on
Type: urlWithHttp
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 382
set fw policy user-check block-device
Syntax
Parameters
Parameter Description
body The informative text that appears in the 'Block Device' user message.
Type: A string that contains only printable characters
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 383
set fw policy user-check block-infected-device
Syntax
Parameters
Parameter Description
body The informative text that appears in the 'Block Infected Device' user message
Type: A string that contains only printable characters
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 384
global-radius-conf
global-radius-conf
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 385
set global-radius-conf
set global-radius-conf
Description
Configure the NAS IP\IPv6 address for RADIUS server authentication.
NAS IP\IPv6 address indicates the identifying IP Address of the NAS which is requesting authentication of
the user, and should be unique to the NAS within the scope of the RADIUS server.
Syntax
Parameters
Parameter Description
nasIPV6 nasIPV6
Type: ipv6addr
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 386
show global-radius-conf
show global-radius-conf
Description
Configure the NAS IP\IPv6 address for RADIUS server authentication.
Syntax
show global-radius-conf
Parameters
Parameter Description
n/a
Example
show global-radius-conf
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 387
group
group
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 388
add group
add group
Description
Adds a new group of network objects.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 389
delete group
delete group
Description
Deletes an existing group object of network objects.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 390
set group
set group
Configures an existing network objects group.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 391
set group
set group
Description
Configures an existing network objects group.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 392
set group
set group
Description
Removes all members from an existing network objects group.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 393
set group
set group
Description
Adds an existing network object to an existing network objects group.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 394
set group
set group
Description
Removes an existing network object from an existing network objects group.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 395
show group
show group
Description
Shows the contents of a network object group.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 396
show groups
show groups
Description
Shows the contents of all network object groups.
Syntax
show groups
Parameters
Parameter Description
n/a
Example
show groups
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 397
host
host
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 398
add host
add host
Description
Adds a new network host object that can be used for resolving when the device acts as a DNS proxy, and
also DHCP settings for this object (exclude/reserve IP address).
Syntax
Parameters
Parameter Description
dhcp-exclude-ip- Indicates if the object's IP address(es) is excluded from internal DHCP daemon
addr
Type: Press TAB to see available options
dns-resolving Indicates if the name of the server/network object will be used as a hostname for
internal DNS service Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 399
add host
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 400
delete host
delete host
Description
Deletes an existing network host object.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 401
set host
set host
Description
Configures an existing network object/host.
Syntax
Parameters
Parameter Description
dns-resolving Indicates if the name of the server/network object will be used as a hostname
for internal DNS service
Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 402
set host
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 403
show host
show host
Description
Shows the configuration of an existing network object.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 404
show hosts
show hosts
Description
Shows the configuration of all existing network objects.
Syntax
show hosts
Parameters
Parameter Description
n/a
Example
show hosts
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 405
hotspot
hotspot
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 406
set hotspot
set hotspot
Configures hotspot settings.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 407
set hotspot
set hotspot
Description
Configures hotspot settings.
Syntax
Parameters
Parameter Description
allowed- Indicates the specific user group that can authenticate through the hotspot when auth-
group mode is set to allow-specific-group
Type: A string of alphanumeric characters without space between them
redirect- Indicates if after the user accepts terms or authenticate in the hotspot portal the user will
after-auth be redirected to a configured external URL instead of the originally requested URL
Options: on, off
redirect- Redirect the user to the following URL after the user accepts terms or authenticate in the
after-auth- hotspot portal
url
Type: urlWithHttp
show- Indicates if a terms and conditions link will be shown in the hotspot portal
terms-of-
use Options: on, off
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 408
set hotspot
Parameter Description
terms-of- Indicates the When users will click the terms and conditions text shown in the hotspot
use portal
Type: A string that contains only printable characters
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 409
set hotspot
set hotspot
Description
Adds an existing network object as an exception for hotspot portal.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 410
set hotspot
set hotspot
Description
Removes an existing network object from being an exception to hotspot portal.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 411
set hotspot
set hotspot
Description
Configures advanced hotspot settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 412
set hotspot
set hotspot
Description
Configures advanced hotspot settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 413
show hotspot
show hotspot
Shows hotspot configuration.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 414
show hotspot
show hotspot
Description
Shows hotspot configuration.
Syntax
show hotspot
Parameters
Parameter Description
n/a
Example
show hotspot
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 415
show hotspot
show hotspot
Description
Shows hotspot advanced settings configuration.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 416
https-categorization
https-categorization
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 417
set https-categorization
set https-categorization
Configures HTTPS categorization settings (categorization does not require a full SSL inspection
mechanism).
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 418
set https-categorization
set https-categorization
Description
Configures advanced HTTPS categorization settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 419
set https-categorization
set https-categorization
Description
Configures advanced HTTPS categorization settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 420
set https-categorization
set https-categorization
Description
Configures advanced HTTPS categorization settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 421
show https-categorization
show https-categorization
Description
Shows configuration for HTTPS categorization feature.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 422
interface
interface
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 423
add interface
add interface
Adds a new virtual interface.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 424
add interface
add interface
Description
Adds a new 802.1q tag-based VLAN over an existing physical interface.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 425
add interface
add interface
Description
Adds a new numbered/unnumbered Virtual Tunnel Interface (VTI) to be used for Route-based VPN
purposes.
Syntax
add vpn tunnel <vpn tunnel> type { unnumbered peer <peer> internet-
connection <internet-connection> | numbered local <local> remote
<remote> peer <peer> }
Parameters
Parameter Description
peer Remote peer name as defined in the VPN community. You must define the two peers in
the VPN community before you can define the VTI. The Peer ID is an alpha-numeric
character string.
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z, _ -)
characters without spaces
remote Defines the remote peer IPv4 address, used at the peer gateway's point-to-point virtual
interface (numbered VTI only)
Type: IP address
type The type of VTI: Numbered VTI that uses a specified, static IPv4 addresses for local and
remote connections, or unnumbered VTI that uses the interface and the remote peer
name to get addresses
Type: Press TAB to see available options
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 426
delete interface
delete interface
Description
Deletes an existing virtual interface.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 427
set interface
set interface
Configures local networks/interfaces.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 428
set interface
set interface
Description
Configures local networks/interfaces.
Syntax
Parameters
Parameter Description
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 429
set interface
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 430
set interface
set interface
Description
Configures IP address for local networks/interfaces.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 431
set interface
set interface
Description
Configures a physical interface to be unassigned from existing networks.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 432
set interface
set interface
Description
Configures monitor mode on an existing local network/interface.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 433
set interface
set interface
Description
Configures advanced settings on an existing local network/interface.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 434
set interface
set interface
Description
Configures networking settings on an existing local network/interface.
Syntax
Parameters
Parameter Description
auto-negotiation Enable this option in order to manually configure the link speed of the interface.
Options: on, off
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 435
set interface
set interface
Description
Enable/disable an existing local network/interface.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 436
set interface
set interface
Description
Configures a description for an existing local network/interface.
Syntax
Parameters
Parameter Description
description Description
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 437
set interface
set interface
Description
Configures automatic access policy for an existing local network/interface. This feature is relevant when
the device is locally managed.
Syntax
Parameters
Parameter Description
lan-access Local networks will be accessible from this network once this option is enabled
Options: block, accept
lan-access-track Traffic from this network to local networks will be logged once this option is enabled
Options: none, log
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 438
set interface
set interface
Description
Configure hotspot functionality for an existing local network/interface.
Syntax
Parameters
Parameter Description
hotspot Redirect users to the Hotspot portal before allowing access from this interface
Options: on, off
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 439
show interface
show interface
Description
Shows configuration and details of local networks.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 440
show interfaces
show interfaces
Description
Shows the list of defined local networks.
Syntax
show interfaces
Parameters
Parameter Description
n/a
Example
show interfaces
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 441
show interfaces all
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 442
show interfaces all
internal-certificates-conf
Configure settings for internal certificates.
add internal-certificate
Description
Add an internal certificate.
Syntax
Parameters
Parameter Description
Less- Allow connections to SSL sites without certificates. Only applied over SFTP.
secure
Type: Boolean (true/false)
P12- PKCS#12 Password, PKCS #12 defines an archive file format for storing many
password cryptography objects as a single file
Type: A registration key
url Download the certificate file from this URL. The URL format should be
(s)ftp://name:passwd@machine.domain:port/full_path_to_file
Type: ftpUrl
Example
delete internal-certificate
Description
Delete an internal certificate.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 443
show interfaces all
Syntax
Parameters
Parameter Description
Example
show internal-certificate
Description
Show an internal certificate.
Syntax
Parameters
Parameter Description
Example
show internal-certificates
Description
Show all internal certificates.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 444
show interfaces all
Syntax
show internal-certificates
Parameters
Parameter Description
n/a
Example
show internal-certificates
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 445
ips engine-settings
ips engine-settings
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 446
set ips engine-settings
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 447
set ips engine-settings
Syntax
Parameters
Parameter Description
bypass-track Indicates how the appliance will track events where the bypass mechanism is
activated/deactivated
Options: none, log, alert
bypass- Indicates if the IPS engine will move to bypass mode if the appliance is under heavy
under-load load
Type: Boolean (true/false)
protection- Indicates if the IPS blade will protect internal networks only or protect all networks
scope (including external networks)
Options: protect-internal-hosts-only, perform-ips-inspection-on-all-traffic
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 448
set ips engine-settings
Syntax
] [ enable-logo-url <enable-logo-url> ]
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 449
set ips engine-settings
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 450
show ips engine-settings
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 451
show ips engine-settings
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 452
show ips engine-settings
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 453
interface-loopback
interface-loopback
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 454
add interface-loopback
add interface-loopback
Description
Adds a new loopback interface (A fixed interface in the system that is commonly used for dynamic routing
purposes).
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 455
delete interface-loopback
delete interface-loopback
Description
Deletes an existing configured loopback interface.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 456
internet
internet
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 457
set internet
set internet
Description
Configures advanced settings for internet connectivity.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 458
show internet
show internet
Description
Shows advanced settings for configured internet
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 459
internet-connection
internet-connection
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 460
add internet-connection
add internet-connection
Adds a new internet connection.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 461
add internet-connection (physical interface)
WAN
Parameters
Parameter Description
vlan-id VLAN ID
Type: A number with no fractional part (integer)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 462
add internet-connection (physical interface)
Parameters
Parameter Description
default-gw WAN default gateway (in the advanced section of PPTP and l2TP)
Type: IP address
vlan-id VLAN ID
Type: A number with no fractional part (integer)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 463
add internet-connection (physical interface)
Parameters
Parameter Description
default-gw WAN default gateway (in the advanced section of PPTP and l2TP)
Type: IP address
is- Unnumbered PPPoE lets you manage a range of IP addresses and dial only once
unnumbered-
pppoe Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 464
add internet-connection (physical interface)
Parameter Description
vlan-id VLAN ID
Type: A number with no fractional part (integer)
add internet-connection name < name> interface WAN type pppoe username
<username> password-hash <password-hash>
Parameters
Parameter Description
is- Unnumbered PPPoE lets you manage a range of IP addresses and dial only once
unnumbered-
pppoe Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 465
add internet-connection (physical interface)
Parameter Description
vlan-id VLAN ID
Type: A number with no fractional part (integer)
Parameters
Parameter Description
default-gw
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 466
add internet-connection (physical interface)
Parameter Description
is- Unnumbered PPPoE lets you manage a range of IP addresses and dial only once
unnumbered-
pppoe Type: Boolean (true/false)
vlan-id VLAN ID
Type: A number with no fractional part (integer)
ADSL
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 467
add internet-connection (physical interface)
Parameters
Parameter Description
Parameters
Parameter Description
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 468
add internet-connection (physical interface)
Parameter Description
is- Unnumbered PPPoE lets you manage a range of IP addresses and dial only once
unnumbered-
pppoe Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 469
add internet-connection (physical interface)
Parameters
Parameter Description
is- Unnumbered PPPoE lets you manage a range of IP addresses and dial only once
unnumbered-
pppoe Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 470
add internet-connection (physical interface)
Parameter Description
DSL
Parameters
Parameter Description
vlan-id VLAN ID
Type: A number with no fractional part (integer)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 471
add internet-connection (physical interface)
Parameters
Parameter Description
default-gw WAN default gateway (in the advanced section of PPTP and l2TP)
Type: IP address
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 472
add internet-connection (physical interface)
Parameter Description
vlan-id VLAN ID
Type: A number with no fractional part (integer)
Parameters
Parameter Description
is- Unnumbered PPPoE lets you manage a range of IP addresses and dial only once
unnumbered-
pppoe Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 473
add internet-connection (physical interface)
Parameter Description
vlan-id VLAN ID
Type: A number with no fractional part (integer)
DMZ
Parameters
Parameter Description
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 474
add internet-connection (physical interface)
Parameter Description
vlan-id VLAN ID
Type: A number with no fractional part (integer)
Parameters
Parameter Description
default-gw WAN default gateway (in the advanced section of PPTP and l2TP)
Type: IP address
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 475
add internet-connection (physical interface)
Parameter Description
vlan-id VLAN ID
Type: A number with no fractional part (integer)
Parameters
Parameter Description
default-gw WAN default gateway (in the advanced section of PPTP and l2TP)
Type: IP address
is- Unnumbered PPPoE lets you manage a range of IP addresses and dial only once
unnumbered-
pppoe Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 476
add internet-connection (physical interface)
Parameter Description
vlan-id VLAN ID
Type: A number with no fractional part (integer)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 477
add internet-connection (physical interface)
Parameters
Parameter Description
is- Unnumbered PPPoE lets you manage a range of IP addresses and dial only once
unnumbered-
pppoe Type: Boolean (true/false)
vlan-id VLAN ID
Type: A number with no fractional part (integer)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 478
add internet-connection (physical interface)
Parameters
Parameter Description
default-gw WAN default gateway (in the advanced section of PPTP and l2TP)
Type: IP address
is- Unnumbered PPPoE lets you manage a range of IP addresses and dial only once
unnumbered-
pppoe Type: Boolean (true/false)
isVlan isVlan
Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 479
add internet-connection (physical interface)
Parameter Description
vlan-id VLAN ID
Type: A number with no fractional part (integer)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 480
add internet-connection (physical interface)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 481
add internet-connection (3G/4G modem)
Syntax
USB:
add internet-connection name <name> typeanalog use-serial-portfalse number
<number> { username <username> password-hash <password-hash>}
add internet-connection name <name> typeanalog use-serial-portfalse number
<number> { username <username> password <password> }
add internet-connection name <name> typeanalog use-serial-porttrue number
<number> { username <username> password-hash <password-hash> }
add internet-connection name <name> typeanalog use-serial-porttrue number
<number> username <username> password <password> { flow-control <flow-
control> port-speed <port-speed>} { conn-test-timeout <conn-test-
timeout>}
add internet-connection name <name> typecellular number <number> { conn-
test-timeout <conn-test-timeout> } name <name>} { apn <apn> username
<username> password-hash <password-hash> }
add internet-connection name <name> typecellular number <number> { conn-
test-timeout <conn-test-timeout> name <name>} { apn <apn> username
<username>password <password> }
Parameters
Parameter Description
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 482
add internet-connection (3G/4G modem)
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 483
delete internet-connection
delete internet-connection
Deletes an existing internet connection or internet connection related configuration.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 484
delete internet-connection
delete internet-connection
Description
Deletes an existing internet connection by name.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 485
deleter internet-connection
deleter internet-connection
Description
Deletes an existing internet connection's ping servers, configured for connection health monitoring.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 486
delete internet-connections
delete internet-connections
Description
Deletes all existing internet connections.
Syntax
delete internet-connections
Parameters
Parameter Description
n/a
Example
delete internet-connections
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 487
set internet-connection
set internet-connection
Configures internet connections settings.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 488
set internet-connection
set internet-connection
Description
Configures an existing internet connection.
Syntax
Parameters
Parameter Description
auto-negotiation Disable auto negotiation and manually define negotiation link speed
Options: on, off
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 489
set internet-connection
set internet-connection
Description
Configures advanced settings for an existing internet connection.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 490
set internet-connection
set internet-connection
Description
Enable/Disable an existing internet connection.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 491
set internet-connection
set internet-connection
Description
Configures advanced settings for an existing internet connection. Download bandwidth details allow QoS
blade to run on this internet connection in locally/SMP managed mode and when managed using an LSM
profile.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 492
set internet-connection
set internet-connection
Description
Configures advanced settings for an existing internet connection. Upload bandwidth details allow QoS
blade to run on this internet connection in locally/SMP managed mode and when managed using an LSM
profile.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 493
set internet-connection
set internet-connection
Description
Configure hide NAT behavior on an existing internet connection. It is possible to disable hide-NAT from a
specific internet connection.
Syntax
Parameters
Parameter Description
disable- Disable NAT(Network Address Translation) for traffic going through this Internet
nat connection
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 494
set internet-connection
set internet-connection
Description
Configures multiple ISP settings for an existing internet connection.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 495
set internet-connection
set internet-connection
Description
Configures advanced settings for an existing internet connection. It is possible to remove a configured
internet connection from being used as a default route, making it available for traffic through
manual/dynamic routing rules.
Syntax
Parameters
Parameter Description
route-traffic-through- default- In order to route traffic through this connection you need to add
gateway specific routes through it
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 496
set internet-connection
set internet-connection
Description
Configures settings for an existing internet connection.
Syntax
Parameters
Parameter Description
is- Unnumbered PPoE lets you manage a range of IP addresses and dial only once.
unnumbered-
pppoe Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 497
set internet-connection
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 498
set internet-connection
set internet-connection
Description
Configures advanced settings for an existing internet connection.
Syntax
Parameters
Parameter Description
is- Unnumbered PPPoE lets you manage a range of IP addresses and dial only once.
unnumbered-
pppoe Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 499
set internet-connection
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 500
set internet-connection
set internet-connection
Description
Configures advanced settings for an existing internet connection. This command is available only for
hardware that contains a DSL port.
Syntax
Parameters
Parameter Description
default-gw WAN default gateway (in the advanced section of PPTP and l2TP)
Type: IP address
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 501
set internet-connection
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 502
set internet-connection
set internet-connection
Description
Configures advanced settings for an existing internet connection. This command is available only for
hardware that contains a DSL port.
Syntax
Parameters
Parameter Description
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 503
set internet-connection
Parameter Description
is-unnumbered- Unnumbered PPPoE lets you manage a range of IP addresses and dial only
pppoe once
Type: Boolean (true/false)
isVlan isVlan
Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 504
set internet-connection
Parameter Description
vlan-id VLAN ID
Type: A number with no fractional part (integer)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 505
set internet-connection
set internet-connection
Description
Configures settings for an existing internet connection.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 506
set internet-connection
set internet-connection
Description
Configures health monitoring settings for an existing internet connection.
Syntax
Parameters
Parameter Description
probe-servers Monitor connection state by sending probe packets to one or more servers on the
Internet
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 507
set internet-connection
set internet-connection
Description
Configures health monitoring settings for an existing internet connection.
Syntax
Parameters
Parameter Description
first First IP address for the probing method (when using connection monitoring)
Type: An IP address or host name
second Second IP address for the probing method (when using connection monitoring)
Type: An IP address or host name
third Third IP address for the probing method (when using connection monitoring)
Type: An IP address or host name
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 508
show internet-connection
show internet-connection
Shows configuration and details of defined internet connections.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 509
show internet-connection
show internet-connection
Description
Shows configuration and details of a defined internet connection.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 510
show internet-connection
show internet-connection
Description
Shows configured ping servers for health monitoring of defined internet connection.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 511
show internet-connections
show internet-connections
Description
Shows details and configuration of all internet connections.
Syntax
show internet-connections
Parameters
Parameter Description
n/a
Example
show internet-connections
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 512
show internet-connections table
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 513
internet mode
internet mode
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 514
set internet mode
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 515
show internet mode
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 516
ip-fragments-params
ip-fragments-params
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 517
set ip-fragments-params
set ip-fragments-params
Configures how the appliance handles IP fragments.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 518
set ip-fragments-params
set ip-fragments-params
Description
Configures how the appliance handles IP fragments.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 519
set ip-fragments-params
set ip-fragments-params
Description
Configures how the appliance handles IP fragments.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 520
show ip-fragments-params
show ip-fragments-params
Description
Shows configuration of IP fragments handling.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 521
ipv6-state
ipv6-state
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 522
set ipv6-state
set ipv6-state
Description
Enable the IPv6 mode of the appliance.
Syntax
set ipv6-state
Parameters
Parameter Description
n/a
Example
set ipv6-state
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 523
show ipv6-state
show ipv6-state
Description
Show if the IPv6 mode of the appliance is enabled or disabled.
Syntax
show ipv6-state
Parameters
Parameter Description
n/a
Example
show ipv6-state
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 524
license
license
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 525
fetch license
fetch license
Description
Fetches a license from one of these locations:
n Local gateway - There is an option to specify the file name with the <file_name> parameter.
n User Center at Check Point
n USB device - There is an option to specify the file name with the <file_name> parameter.
Syntax
Parameters
Parameter Description
Return Value
0 on success, 1 on failure
Example
fetch license usb file LicenseFile.xml
Output
Success shows OK. Failure shows an appropriate error message.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 526
show license
show license
Description
Shows current license state.
Syntax
show license
Parameters
Parameter Description
n/a
Example
show license
Output
Current license state
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 527
local-group
local-group
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 528
add local-group
add local-group
Description
Adds a new group for user objects.
Syntax
Parameters
Parameter Description
comments Comments
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 529
delete local-group
delete local-group
Deletes an existing group object for user objects.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 530
delete local-group
delete local-group
Description
Deletes an existing group object for user objects by group object name.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 531
delete local-group
delete local-group
Description
Deletes all existing group objects for user objects.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 532
set local-group
set local-group
Configures an existing user group object.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 533
set local-group
set local-group
Description
Configures an existing user group object.
Syntax
Parameters
Parameter Description
comments Comments
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 534
set local-group
set local-group
Description
Adds a bookmark to be shown in the SNX landing page to an existing user group object. This is relevant
only if users in this group have VPN remote access privileges.
Syntax
Parameters
Parameter Description
bookmark Text for the bookmark in the SSL Network Extender portal
label
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 535
set local-group
set local-group
Description
Removes a bookmark from being shown in the SNX landing page to an existing user group object. This is
relevant only if users in this group have VPN remote access privileges.
Syntax
Parameters
Parameter Description
bookmark Text for the bookmark in the SSL Network Extender portal
label
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 536
show local-group
show local-group
Description
Shows the content of a user group object.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 537
show local-groups
show local-groups
Description
Shows the content of all user group objects.
Syntax
show local-groups
Parameters
Parameter Description
n/a
Example
show local-groups
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 538
set local-group users
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 539
set local-group users
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 540
set local-group users
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 541
local-user
local-user
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 542
add local-user
add local-user
Description
Adds a new locally defined user object and configure its VPN remote access permissions.
Syntax
Parameters
Parameter Description
comments Comments
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or ,
. - : () @
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 543
add local-user
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 544
delete local-user
delete local-user
Deletes an existing locally defined user object.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 545
delete local-user
delete local-user
Description
Deletes an existing locally defined user object by user name.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 546
delete local-user
delete local-user
Description
Deletes all existing locally defined user objects by user name.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 547
set local-user
set local-user
Configures an existing user object.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 548
set local-user
set local-user
Description
Configures an existing user object.
Syntax
Parameters
Parameter Description
comments Comments
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or ,
. - : () @
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 549
set local-user
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 550
set local-user
set local-user
Description
Adds a bookmark to be shown in the SNX landing page to an existing user. This is relevant only if the user
has VPN remote access privileges.
Syntax
Parameters
Parameter Description
bookmark label Text for the bookmark in the SSL Network Extender portal
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 551
set local-user
set local-user
Description
Removes a bookmark from being shown in the SNX landing page to an existing user. This is relevant only if
the user has VPN remote access privileges.
Syntax
Parameters
Parameter Description
bookmark label Text for the bookmark in the SSL Network Extender portal
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 552
show local-user
show local-user
Description
Shows the configuration of a locally defined user.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 553
show local-users
show local-users
Description
Shows all locally defined users.
Syntax
show local-users
Parameters
Parameter Description
n/a
Example
show local-users
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 554
local-users expired
local-users expired
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 555
delete local-users expired
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 556
show local-users expired
Syntax
Parameters
Parameter Description
n.a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 557
show logs
show logs
Description
Shows system and kernel logs.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 558
log-servers-configuration
log-servers-configuration
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 559
set log-servers-configuration
set log-servers-configuration
Description
Configures external log servers for a locally managed device.
Syntax
Parameters
Parameter Description
log-server-ip- This IP address is used if the log server is not located on the Security Management
addr Server.
Type: IP address
mgmt-server- This IP address is used for establishing trusted communication between the Check
ip-addr Point Appliance and the log server. Type: IP address
sic-name Enter the SIC name of the log server object that was defined in SmartDashboard
Type: A SIC name
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 560
show log-servers-configuration
show log-servers-configuration
Description
Shows external log server configuration.
Syntax
show log-servers-configuration
Parameters
Parameter Description
n/a
Example
show log-servers-configuration
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 561
mac-filtering-list
mac-filtering-list
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 562
add mac-filtering-list
add mac-filtering-list
Description
Add a MAC address to the list of addresses allowed to access LAN/DMZ networks.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 563
delete mac-filtering-list
delete mac-filtering-list
Description
Delete a MAC address from the list of addresses allowed to access LAN/DMZ networks.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 564
show mac-filtering-list
show mac-filtering-list
Description
Show the MAC addresses that are allowed to access LAN/DMZ networks.
Syntax
show mac-filtering-list
Parameters
Parameter Description
n/a
Example
show mac-filtering-list
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 565
mac-filtering-settings
mac-filtering-settings
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 566
set mac-filtering settings
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 567
set mac-filtering-settings
set mac-filtering-settings
Description
Configure the settings for MAC filtering.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 568
set mac-filtering settings
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 569
set mac-filtering settings
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 570
show mac-filtering-settings
show mac-filtering-settings
Show the settings for MAC filtering.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 571
show mac-filtering-settings
show mac-filtering-settings
Description
Show the settings for MAC filtering.
Syntax
show mac-filtering-settings
Parameters
Parameter Description
n/a
Example
show mac-filtering-settings
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 572
show mac-filtering-settings
show mac-filtering-settings
Description
Show the advanced settings for MAC filtering.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 573
set mobile-settings
set mobile-settings
Description
Configure settings for a mobile device. In this case, for when the pairing code expires.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 574
set mobile-settings
set mobile-settings
Description
Configure settings for a mobile device.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 575
show mobile-settings
show mobile-settings
Description
Show configured advanced settings for a mobile device.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 576
mobile-settings
mobile-settings
These commands are relevant for mobile settings.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 577
set mobile-settings
set mobile-settings
Description
Configure settings for a mobile device. In this case, for when the pairing code expires.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 578
set mobile-settings
set mobile-settings
Description
Configure settings for a mobile device.
Syntax
Parameters
Parameter Description
not-cloud-server Notification server URL - URL for the cloud service that pushes the notifications.
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 579
show mobile-settings
show mobile-settings
Description
Show configured advanced settings for a mobile device.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 580
monitor-mode-network
monitor-mode-network
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 581
add monitor-mode-network
add monitor-mode-network
Description
Configuring "Monitor mode" over interfaces requires a mechanism to determine which are the local
networks within the real topology. One of the options is a manual configuration of this topology using this
command.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 582
delete monitor-mode-network
delete monitor-mode-network
Description
Deletes manually configured IP addresses that determine the local networks in monitor mode when not
working in automatic detection mode.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 583
set monitor-mode-network
set monitor-mode-network
Description
Configures IP addresses of networks that are manually recognized as local in the non-automatic mode of
monitor mode interface inspection.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 584
show monitor-mode-networks
show monitor-mode-networks
Description
Shows manually defined local networks for monitor mode configuration.
Syntax
show monitor-mode-networks
Parameters
Parameter Description
n/a
Example
show monitor-mode-networks
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 585
monitor-mode-configuration
monitor-mode-configuration
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 586
set monitor-mode-configuration
set monitor-mode-configuration
Description
Configures mode of work for monitor mode interface inspection. Determines if locally managed networks
will be automatically detected or manually configured.
Syntax
Parameters
Parameter Description
use-defined-networks Indicates if user-defined internal networks are used for Monitor mode
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 587
show monitor-mode-configuration
show monitor-mode-configuration
Description
Shows monitor mode configuration for interfaces.
Syntax
show monitor-mode-configuration
Parameters
Parameter Description
n/a
Example
show monitor-mode-configuration
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 588
message
message
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 589
set message
set message
Description
Configures a banner message for the SSH administrator login
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 590
show message
show message
Shows banner message for the ssh login.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 591
show message
show message
Description
Shows banner message for the ssh login.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 592
show memory usage
Syntax
show memory-usage
Parameters
Parameter Description
n/a
Example
show memory-usage
Output
Success shows used memory. Failure shows an appropriate error message.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 593
nat
nat
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 594
set nat
set nat
Configures general NAT policy settings.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 595
set nat
set nat
Description
Configures if local networks will be hidden by default behind the external IP addresses of the gateway.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 596
set nat
set nat
Description
Configures advanced NAT policy settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 597
set nat
set nat
Description
Configures advanced NAT policy settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 598
set nat
set nat
Description
Configures advanced NAT policy settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 599
set nat
set nat
Description
Configures advanced NAT policy settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 600
set nat
set nat
Description
Configures advanced NAT policy settings.
Syntax
<nat-destination-client-side-manual>
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 601
set nat
set nat
Description
Configures advanced NAT policy settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 602
set nat
set nat
Description
Configures advanced NAT policy settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 603
set nat
set nat
Description
Configures advanced NAT policy settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 604
set nat
set nat
Description
Configures advanced NAT policy settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 605
set nat
set nat
Description
Configures advanced NAT policy settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 606
set nat
set nat
Description
Configures advanced NAT policy settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 607
set nat
set nat
Description
Configures advanced IP-Pool NAT policy settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 608
show nat
show nat
Shows NAT policy.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 609
show nat
show nat
Description
Shows NAT policy.
Syntax
show nat
Parameters
Parameter Description
n/a
Example
show nat
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 610
show nat
show nat
Description
Shows advanced settings for NAT policy.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 611
nat-rule
nat-rule
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 612
add nat-rule
add nat-rule
Description
Adds a new manual NAT (translation of source/destination/service) rule to the NAT Rule Base.
Syntax
Parameters
Parameter Description
enable-arp- The gateway will reply to ARP requests sent to the original destination's IP address
proxy (Does not apply to IP ranges/networks) Type: Boolean (true/false)
name name
Type: A string of alphanumeric characters without space between them
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 613
add nat-rule
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 614
delete nat-rule
delete nat-rule
Description
Deletes a manually configured NAT rule by name.
Syntax
Parameters
Parameter Description
name name
Type: A string of alphanumeric characters without space between them
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 615
set nat-rule
set nat-rule
Description
Configures an existing manual NAT rule by name.
Syntax
Parameters
Parameter Description
enable-arp- The gateway will reply to ARP requests sent to the original destination's IP address
proxy (Does not apply to IP ranges/networks)
Type: Boolean (true/false)
name name
Type: A string of alphanumeric characters without space between them
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 616
set nat-rule
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 617
show nat-rule
show nat-rule
Description
Shows the name or position of a specific NAT rule. Includes auto-generated rules.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 618
show nat-rules
show nat-rules
Description
Shows configuration of all manually and auto-generated NAT rules.
Syntax
show nat-rules
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 619
show nat-manual-rules
show nat-manual-rules
Description
Shows configuration of manual NAT rules by name or position.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 620
nat-rule position
nat-rule position
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 621
delete nat-rule position
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 622
set nat-rule position
Syntax
Parameters
Parameter Description
enable-arp- The gateway will reply to ARP requests sent to the original destination's IP address
proxy (Does not apply to IP ranges/networks)
Type: Boolean (true/false)
name name
Type: A string of alphanumeric characters without space between them
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 623
set nat-rule position
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 624
netflow collector
netflow collector
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 625
add netflow collector
Syntax
Parameters
Parameter Description
ip IP address
Type: IP address
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 626
delete netflow collector
Syntax
Parameters
Parameter Description
ip IP address
Type: IP address
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 627
set netflow collector
Syntax
Parameters
Parameter Description
for-ip IP address
Type: IP address
ip IP address
Type: IP address
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 628
show netflow collector
Syntax
Parameters
Parameter Description
ip IP address
Type: IP address
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 629
show netflow collectors
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 630
network
network
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 631
add network
add network
Description
Adds a new network address range object (a network and a subnet mask).
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 632
delete network
delete network
Description
Deletes an existing network address range object (a network and a subnet mask) by object name.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 633
set network
set network
Description
Configures an existing network with subnet.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 634
show network
show network
Description
Shows configuration of a specific IP address network object.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 635
show networks
show networks
Description
Shows configuration of all IP address network objects.
Syntax
show networks
Parameters
Parameter Description
n/a
Example
show networks
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 636
show notifications-log
show notifications-log
Description
Show the notification logs.
Syntax
show notifications-log
Parameters
Parameter Description
n/a
Example
show notifications-log
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 637
notifications-policy
notifications-policy
These commands are relevant for notifications policy.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 638
set notifications-policy
set notifications-policy
Description
Configure the policy for sending notifications to the user.
Syntax
Parameters
Parameter Description
send-detailed- Notification previews may contain information about your network. Turning it off
push- means that the security gateway removes this information from the push notification.
notifications
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 639
set notifications-policy
set notifications-policy
Description
Configure the policy for sending notifications to the user.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 640
set notifications-policy
set notifications-policy
Description
Configure the policy for sending notifications to the user.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 641
show notifications-policy
show notifications-policy
Description
Show the policy for sending notifications to the user.
Syntax
show notifications-policy
Parameters
Parameter Description
n/a
Example
show notifications-policy
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 642
show notifications-policy
show notifications-policy
Description
Show the policy for sending notifications to the user.
Syntax
show notifications-policy advanced-settings
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 643
ntp
ntp
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 644
set ntp
set ntp
Configures NTP settings.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 645
set ntp
set ntp
Description
Configures NTP settings.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 646
set ntp
set ntp
Description
Enables/Disables NTP functionality.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 647
set ntp
set ntp
Description
Configures NTP settings.
Syntax
Parameters
Parameter Description
interval Time interval (minutes) to update date and time settings from the NTP server
Type: A number with no fractional part (integer)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 648
set ntp
set ntp
Description
Configures NTP settings.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 649
show ntp
show ntp
Description
Shows NTP configuration.
Syntax
show ntp
Parameters
Parameter Description
n/a
Example
show ntp
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 650
show ntp active
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 651
ntp server
ntp server
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 652
set ntp server
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 653
set ntp server
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 654
set ntp server
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 655
show ntp servers
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 656
periodic backup
periodic backup
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 657
set periodic-backup
set periodic-backup
Description
Configures periodic backup to a remote FTP server.
Syntax
Parameters
Parameter Description
hour Scheduled backup hour. The backup will be performed during this hour
Type: A number with no fractional part (integer)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 658
set periodic-backup
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 659
show periodic-backup
show periodic-backup
Description
Shows periodic backup configuration.
Syntax
show periodic-backup
Parameters
Parameter Description
n/a
Example
show periodic-backup
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 660
set property
set property
Description
Disables or enables first time configuration (from the USB autoplay configuration or the WebUI).
Syntax
Parameters
Parameter Description
n/a
Example
n set property USB_auto_configuration off
n set property first-time-wizard off
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 661
privacy settings
privacy settings
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 662
set privacy-settings
set privacy-settings
Description
In Advanced Settings, select if the customer consents to sending diagnostic data to Check Point.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 663
show privacy-settings
show privacy-settings
Description
In Advanced Settings, show if the customer consents to sending diagnostic data.
Syntax
Parameters
Parameter Description
n/a
Example
Sample Output
customer-consent: true
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 664
proxy
proxy
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 665
delete proxy
delete proxy
Description
Deletes configured proxy settings for the appliance.
Syntax
delete proxy
Parameters
Parameter Description
n/a
Example
delete proxy
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 666
set proxy
set proxy
Configures proxy settings for connecting with Check Point update and license servers.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 667
set proxy
set proxy
Description
Configures proxy settings for connecting with Check Point update and license servers, when the device is
located behind a proxy server.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 668
set proxy
set proxy
Description
Enable/Disable proxy configuration for the device.
Syntax
Parameters
Parameter Description
use-proxy A proxy server between the appliance and the Internet. This proxy server will be used
when the appliance?s internal processes must reach a Check Point server.
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 669
show proxy
show proxy
Description
Shows proxy configuration.
Syntax
show proxy
Parameters
Parameter Description
n/a
Example
show proxy
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 670
qos
qos
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 671
set qos
set qos
Configures QoS policy.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 672
set qos
set qos
Description
Enables/Disables the QoS
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 673
set qos
set qos
Description
Configures the default QoS policy.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 674
set qos
set qos
Description
Configures advanced QoS settings.
Syntax
<maximum-percentage-of-bandwidth>
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 675
set qos
set qos
Description
Configures advanced QoS settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 676
show qos
show qos
Shows the policy of the QoS blade.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 677
show qos
show qos
Description
Shows the policy of the QoS blade.
Syntax
show qos
Parameters
Parameter Description
n/a
Example
show qos
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 678
show qos
show qos
Description
Shows advanced settings of the QoS blade.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 679
qos delay-sensitive-service
qos delay-sensitive-service
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 680
set qos delay-sensitive-service
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 681
set qos delay-sensitive-service
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 682
set qos delay-sensitive-service
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 683
show qos delay-sensitive-services
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 684
qos guarantee-bandwidth-selected-services
qos guarantee-bandwidth-selected-
services
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 685
set qos guarantee-bandwidth-selected-services
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 686
set qos guarantee-bandwidth-selected-services
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 687
set qos guarantee-bandwidth-selected-services
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 688
show qos guarantee-bandwidth-selected-services
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 689
qos-rule
qos-rule
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 690
add qos-rule
add qos-rule
Description
Adds a new bandwidth/latency control rule to the QoS Rule Base.
Syntax
Parameters
Parameter Description
diffserv- DiffServ Mark is a way to mark connections so a third party will handle it. To use this
mark option, your ISP or private WAN must support DiffServ
Type: Boolean (true/false)
diffserv- To mark packets that will be given priority on the public network according to their DSCP,
mark-val select DiffServ Mark (1-63) and select a value. You can get the DSCP value from your
ISP or private WAN administrator
Type: A number with no fractional part (integer)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 691
add qos-rule
Parameter Description
log Defines which logging method to use: None - do not log, Log - Create log
Options: none, log
name name
Type: A string of alphanumeric characters without space between them
service The network service object that the rule should match to
weight Traffic weight, relative to the weights defined for other rules
Type: A number with no fractional part (integer)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 692
add qos-rule
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 693
delete qos-rule
delete qos-rule
Deletes an existing bandwidth/latency control rule in the QoS Rule Base.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 694
delete qos-rule
delete qos-rule
Description
Deletes an existing bandwidth/latency control rule in the QoS Rule Base by idx.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 695
delete qos-rule
delete qos-rule
Description
Deletes an existing bandwidth/latency control rule in the QoS Rule Base by name.
Syntax
Parameters
Parameter Description
name name
Type: A string of alphanumeric characters without space between them
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 696
set qos-rule
set qos-rule
Configures an existing bandwidth/latency control rule within the QoS blade policy.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 697
set qos-rule
set qos-rule
Description
Configures an existing bandwidth/latency control rule within the QoS blade policy by idx.
Syntax
Parameters
Parameter Description
diffserv- DiffServ Mark is a way to mark connections so a third party will handle it. To use this
mark option, your ISP or private WAN must support DiffServ
Type: Boolean (true/false)
diffserv- To mark packets that will be given priority on the public network according to their DSCP,
mark-val select DiffServ Mark (1-63) and select a value. You can get the DSCP value from your
ISP or private WAN administrator
Type: A number with no fractional part (integer)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 698
set qos-rule
Parameter Description
log Defines which logging method to use: None - do not log, Log - Create log
Options: none, log
name name
Type: A string of alphanumeric characters without space between them
service The network service object that the rule should match to
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 699
set qos-rule
Parameter Description
weight Traffic weight, relative to the weights defined for other rules
Type: A number with no fractional part (integer)
Example
set qos-rule idx 3.141 source TEXT destination TEXT service TEXT low-
latency-rule normal limit-bandwidth true limit-percentage 80 guarantee-
bandwidth true guarantee-percentage 80 weight 15 log none comment "This
is a comment." vpn true hours-range-enabled true hours-range-from 23:20
hours-range-to 23:20 diffserv-mark true diffserv-mark-val 5 name word
position 2 disabled true
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 700
set qos-rule
set qos-rule
Description
Configures an existing bandwidth/latency control rule within the QoS blade policy by name.
Syntax
Parameters
Parameter Description
diffserv- DiffServ Mark is a way to mark connections so a third party will handle it. To use this
mark option, your ISP or private WAN must support DiffServ
Type: Boolean (true/false)
diffserv- To mark packets that will be given priority on the public network according to their DSCP,
mark-val select DiffServ Mark (1-63) and select a value. You can get the DSCP value from your
ISP or private WAN administrator
Type: A number with no fractional part (integer)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 701
set qos-rule
Parameter Description
log Defines which logging method to use: None - do not log, Log - Create log
Options: none, log
name name
Type: A string of alphanumeric characters without space between them
service The network service object that the rule should match to
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 702
set qos-rule
Parameter Description
weight Traffic weight, relative to the weights defined for other rules
Type: A number with no fractional part (integer)
Example
set qos-rule name word source TEXT destination TEXT service TEXT low-
latency-rule normal limit-bandwidth true limit-percentage 80 guarantee-
bandwidth true guarantee-percentage 80 weight 15 log none comment "This
is a comment." vpn true hours-range-enabled true hours-range-from 23:20
hours-range-to 23:20 diffserv-mark true diffserv-mark-val 5 name word
position 2 disabled true
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 703
show qos-rule
show qos-rule
Shows configuration of QoS (bandwidth/latency control) rules.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 704
show qos-rule
show qos-rule
Description
Shows configuration of a QoS rule by ID.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 705
show qos-rule
show qos-rule
Description
Shows configuration of a QoS rule by name.
Syntax
Parameters
Parameter Description
name name
Type: A string of alphanumeric characters without space between them
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 706
show qos-rules
show qos-rules
Description
Shows configuration of a QoS rule by position.
Syntax
Parameters
Parameter Description
position The order of the generated rules in the QoS Rule Base
Type: A number with no fractional part (integer)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 707
radius-server
radius-server
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 708
delete radius-server
delete radius-server
Description
Deletes an existing configured RADIUS server.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 709
set radius-server
set radius-server
Description
Configures RADIUS servers.
Syntax
Parameters
Parameter Description
shared- Pre-shared secret between the RADIUS server and the Appliance
secret
Type: A string that contains alphanumeric and special characters
timeout A timeout value in seconds for communication with the RADIUS server
Type: A number with no fractional part (integer)
udp-port The port number through which the RADIUS server communicates with clients. The
default is 1812
Type: A number with no fractional part (integer)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 710
show radius-server
show radius-server
Description
Shows the configuration of a RADIUS server.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 711
show radius-servers
show radius-servers
Description
Shows the configuration of all RADIUS servers.
Syntax
show radius-servers
Parameters
Parameter Description
n/a
Example
show radius-servers
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 712
reach-my-device
reach-my-device
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 713
set reach-my-device
set reach-my-device
Configures the "Reach my device" service, which enables connecting to the device's management portal
even when the device is behind NAT.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 714
set reach-my-device
set reach-my-device
Description
Configures the "Reach my device" service, which enables connecting to the device's management portal
even when the device is behind NAT.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 715
set reach-my-device
set reach-my-device
Description
Configures advanced settings of the "Reach my device" service, which enables connecting to the device's
management portal even when the device is behind NAT.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 716
set reach-my-device
set reach-my-device
Description
Configures advanced settings of the "Reach my device" service, which enables connecting to the device's
management portal even when the device is behind NAT.
Syntax
<reach-my-device-server-addr>
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 717
show reach-my-device
show reach-my-device
Shows the configuration of "Reach My Device" cloud service.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 718
show reach-my-device
show reach-my-device
Description
Shows the configuration of "Reach My Device" cloud service.
Syntax
show reach-my-device
Parameters
Parameter Description
n/a
Example
show reach-my-device
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 719
show reach-my-device
show reach-my-device
Description
Shows advanced settings of "Reach My Device" cloud service.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 720
set remote-access users
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 721
show remote-access users radius-auth
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 722
reboot
reboot
Description
Reboots the system.
Syntax
reboot
Parameters
Parameter Description
n/a
Example
reboot
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 723
restore settings
restore settings
Description
Restores the appliance settings from a backup file. The backup file can be located on a USB device or on a
TFTP server.
Syntax
Parameters
Parameter Description
Example
Comments
The appliance automatically reboots after the settings are restored.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 724
show restore settings log
Syntax
show {restore-settings-log|restore-default-settings-log}
Parameters
Parameter Description
n/a
Example
show restore-settings-log
Output
Success shows the restore settings log file. Failure shows an appropriate error message.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 725
show revert log
Syntax
show revert-log
Parameters
Parameter Description
n/a
Example
show revert-log
Output
Success shows the revert log file. Failure shows an appropriate error message.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 726
revert to factory defaults
Syntax
revert to factory-defaults
Parameters
Parameter Description
n/a
Example
revert to factory-defaults
Output
Success shows a warning message. Enter yesto continue.
Failure shows an appropriate error message.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 727
revert to saved image
Syntax
revert to previous-image
Parameters
Parameter Description
n/a
Example
revert to previous-image
Output
Success shows OK. Failure shows an appropriate error message.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 728
report-settings
report-settings
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 729
set report-settings
set report-settings
Configure local reports settings.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 730
set report-settings
set report-settings
Description
Configure advanced local reports settings.
Syntax
<centrally-max-period>
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 731
set report-settings
set report-settings
Description
Configure advanced local reports settings.
Syntax
<locally-max-period>
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 732
show report-settings
show report-settings
Description
Shows report scheduling and creation configuration.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 733
show rule hits
Syntax
Parameters
Parameter Description
Return Value
0
on success,
1
on failure
Example
Output
Success shows number of hits per rule. Failure shows an appropriate error message.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 734
show saved image
Syntax
show saved-image
Parameters
Parameter Description
n/a
Example
show saved-image
Output
Success shows information about the image. Failure shows an appropriate error message.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 735
update security-blades
update security-blades
Description
Manually update Software Blades.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 736
security-management
security-management
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 737
connect security-management
connect security-management
Description
Configure first connection to the Security Management Server.
Syntax
Parameters
Parameter Description
local- Indicates if the management address used in the next manual fetch command will be
override- saved and continuously used instead of the address downloaded in the policy
mgmt-addr
Type: Boolean (true/false)
send-logs-to Indicates from where the address of the log server is taken
Type: Press TAB to see available options
use-one- Indicates whether to connect to the Security Management Server using a one time
time- password
password
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 738
set security-management
set security-management
Configures settings to connect to a remote Security Management Server and log server.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 739
set security-management
set security-management
Description
Configures a local override to the IP addresses of the Security Management Server and log server. This is
relevant when centrally managed.
Syntax
Parameters
Parameter Description
local- Indicates if the management address used in the next manual fetch command will be
override- saved and continuously used instead of the address downloaded in the policy
mgmt- addr
Type: Boolean (true/false)
send-logs-to Indicates from where the address of the log server is taken
Type: Press TAB to see available options
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 740
set security-management
set security-management
Description
Configures if the device is managed centrally or locally. In centrally managed appliances only the
networking configurations are available and the security policy comes from the remote Security
Management Server.
Syntax
Parameters
Parameter Description
mode Indicates whether the appliance is managed locally or centrally using a Check Point
Security Management Server.
Options: locally-managed, centrally-managed
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 741
show security-management
show security-management
Description
Shows settings of the Security Management Server.
Syntax
show security-management
Parameters
Parameter Description
n/a
Example
show security-management
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 742
serial-port
serial-port
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 743
set serial-port
set serial-port
Configures the physical serial port settings.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 744
set serial-port
set serial-port
Description
Configures the physical serial port data flow settings.
Syntax
Parameters
Parameter Description
flow- Indicates the method of data flow control to and from the serial port
control
mode Indicates if the serial port is used to connect to the appliance's console, a remote telnet
server or allow a remote telnet connection to the device connected to the serial port.
port- Indicates the port speed (Baud Rate) of the serial connection
speed
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 745
set serial-port
set serial-port
Description
Configures the physical serial port as a relay to which incoming TELNET traffic on a configured port will be
redirected.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 746
set serial-port
set serial-port
Description
Configures the physical serial port as a relay to outgoing connection to a remote TELNET server.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 747
show serial-port
show serial-port
Description
Shows configuration for the serial port.
Syntax
show serial-port
Parameters
Parameter Description
n/a
Example
show serial-port
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 748
server
server
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 749
add server
add server
Description
Adds a new server object. Server object are a way to define a network host object with its access and NAT
configuration, instead of creating manual rules for it.
Syntax
Parameters
Parameter Description
comments Comments
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : ()
@
dhcp-exclude- Indicates if the internal DHCP service will not distribute the configured IP address of
ip-addr this server/network object to anyone
Type: Press TAB to see available options
dhcp-reserve- Indicates if the internal DHCP service will distribute the configured IP address only
ip-addr-to-mac to this server/network object according to its MAC address
Type: Press TAB to see available options
dns-resolving Indicates if the name of the server/network object will be used as a hostname for
internal DNS service
Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 750
add server
Parameter Description
tcpProtocol tcpProtocol
Type: Boolean (true/false)
udpProtocol udpProtocol
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 751
delete server
delete server
Description
Deletes an existing server object.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 752
show server
show server
Description
Shows configuration of an existing server object.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 753
show servers
show servers
Description
Shows the configuration of all server objects.
Syntax
show servers
Parameters
Parameter Description
n/a
Example
show servers
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 754
service-details
service-details
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 755
set device-details
set device-details
~~
Description
Configures the device's details.
Syntax
Parameters
Parameter Description
country The country where you are located. The country configured for the WLAN
Options: country
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 756
show device-details
show device-details
Description
Shows configuration of basic device details.
Syntax
show device-details
Parameters
Parameter Description
n/a
Example
show device-details
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 757
service-group
service-group
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 758
add service-group
add service-group
Description
Adds a new group for service objects.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 759
delete service-group
delete service-group
Description
Deletes an existing group object for service objects by object name.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 760
set service-group
set service-group
Configures an existing service objects group.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 761
set service-group
set service-group
Description
Configures an existing service objects group.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 762
set service-group
set service-group
Description
Removes all service objects from an existing service objects group.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 763
set service-group
set service-group
Description
Adds an existing service object to an existing service objects group.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 764
set service-group
set service-group
Description
Removes an existing service object from an existing service objects group.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 765
show service-group
show service-group
Description
Shows the content of a service object group.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 766
show service-groups
show service-groups
Description
Shows the content of all service object groups.
Syntax
show service-groups
Parameters
Parameter Description
n/a
Example
show service-groups
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 767
service-icmp
service-icmp
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 768
add service-icmp
add service-icmp
Description
Adds a new ICMP-type service object.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 769
delete service-icmp
delete service-icmp
Description
Deletes an existing ICMP-type service object by name.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 770
set service-icmp
set service-icmp
Description
Configures an existing ICMP-type service object.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 771
show service-icmp
show service-icmp
Description
Shows the configuration of a specific ICMP-type service object.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 772
add service-protocol
add service-protocol
Description
Adds a new non-TCP/UDP service object (a different IP protocol than 6 or 17).
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 773
service-protocol
service-protocol
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 774
delete service-protocol
delete service-protocol
Description
Deletes a non-TCP/UDP service object by name.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 775
set service-protocol
set service-protocol
Description
Configures an existing non-TCP/UDP service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging- firewall to increase durability and stability
enable
aggressive- Time (in seconds) before the aggressive aging times out
aging-
timeout
match INSPECT expression that searches for a pattern in a packet, only relevant for services
of type 'other'
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 776
set service-protocol
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 777
show service-protocol
show service-protocol
Description
Shows the configuration of a specific non-TCP/UDP service object.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 778
show services-protocol
show services-protocol
Description
Shows the configuration of all non-TCP/UDP service objects.
Syntax
show services-protocol
Parameters
Parameter Description
n/a
Example
show services-protocol
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 779
set server server-access
Syntax
Parameters
Parameter Description
access-zones Zones the server is accessible from by default (accept all by default, accept only
from configured zones, or define no server-specific default access policy). Manual
policy rules will override this policy.
Type: Press TAB to see available options
allow-ping-to- Indicates if default access policy will work on ICMP traffic as well as defined ports.
server This option will not work on multiple ports hidden behind the gateway.
Type: Boolean (true/false)
log-accepted- Indicates if connections that are accepted by the default access policy to the server
connections are logged
Options: none, log
log-blocked- Indicates if connections that are blocked by the default access policy to the server
connections are logged
Options: none, log
trusted-zone- Indicates if traffic from the DMZ network to the server is allowed or blocked by default
dmz
Options: blocked, allowed
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 780
set server server-access
Parameter Description
trusted-zone- Indicates if traffic from Physical internal networks (LAN ports) to the server is allowed
lan or blocked by default
Options: blocked, allowed
trusted-zone- Indicates if traffic from trusted wireless networks to the server is allowed or blocked
trusted- by default
wireless-
networks Options: blocked, allowed
trusted-zone- Indicates if encrypted traffic from remote VPN sites to the server is allowed or
vpn-sites blocked by default
Options: blocked, allowed
trusted-zone- Indicates if encrypted traffic from VPN remote access users to the server is allowed
vpn- users or blocked by default
Options: blocked, allowed
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 781
set server server-nat-settings
Syntax
Parameters
Parameter Description
force-source-hide- Allow access from internal networks to the external IP address of the server via
nat local switch
Type: Boolean (true/false)
nat-settings Indicates the general NAT settings configured (no NAT, hide behind the
gateway's external IP address or use a different external IP address)
Type: Press TAB to see available options
port-address- For servers with a single port, indicates if the external port is not the same as
translation the internal port.
Type: Boolean (true/false)
port-address- For servers with a single port, indicates the external port that is used to forward
translation-external- traffic to the server
port
Type: Port number
static-nat-for- indicates if outgoing traffic from the server using static NAT will be hidden
outgoing-traffic behind the configured external IP address without a port change
Type: Boolean (true/false)
static-nat-ipv4- For servers using static NAT, the external IP address used to forward traffic to
address the server
Type: IP address
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 782
set server server-nat-settings
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 783
set server server-network-settings
Syntax
Parameters
Parameter Description
comments Comments
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : ()
@
dhcp-exclude- Indicates if the internal DHCP service will not distribute the configured IP address of
ip-addr this server/network object to anyone
Type: Press TAB to see available options
dhcp-reserve-ip- Indicates if the internal DHCP service will distribute the configured IP address only
addr- to-mac to this server/network object according to its MAC address
Type: Press TAB to see available options
dns-resolving Indicates if the name of the server/network object will be used as a hostname for
internal DNS service
Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 784
set server server-network-settings
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 785
set server server-ports
Syntax
Parameters
Parameter Description
citrix-server Indicates a Citrix server (for each type we provide default but configurable ports)
dns-server Indicates a DNS server (for each type we provide default but configurable ports
ftp-server Indicates a FTP server (for each type we provide default but configurable ports)
mail-server Indicates a mail server (for each type we provide default but configurable ports)
pptp-server Indicates a PPTP server (for each type we provide default but configurable ports)
service-citrix Indicates if ports are defined for Citrix (for a Citrix server)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 786
set server server-ports
Parameter Description
service-dns Indicates if ports are defined for DNS (for a DNS server)
service-ftp Indicates if ports are defined for FTP (for a FTP server)
service-http Indicates if ports are defined for HTTP (for a web server)
service-https Indicates if ports are defined for HTTPS (for a web server)
service-imap Indicates if ports are defined for IMAP (for a mail server)
service-pop3 Indicates if ports are defined for POP3 (for a mail server)
service-pptp- Indicates if ports are defined for PPTP (for a PPTP server)
selected
service-smtp Indicates if ports are defined for SMTP (for a mail server)
tcpProtocol tcpProtocol
Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 787
set server server-ports
Parameter Description
udpProtocol udpProtocol
Type: Boolean (true/false)
web-server Indicates a web server (for each type we provide default but configurable ports)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 788
service-system-default
service-system-default
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 789
set service-system-default Any_TCP
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging- enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 790
set service-system-default Any_TCP
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 791
show service-system-default Any_TCP
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 792
set service-system-default Any_UDP
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging- enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 793
set service-system-default Any_UDP
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 794
show service-system-default Any_UDP
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 795
set service-system-default CIFS
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 796
set service-system-default CIFS
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 797
show service-system-default CIFS
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 798
set service-system-default Citrix
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 799
set service-system-default Citrix
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 800
show service-system-default Citrix
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 801
set service-system-default Citrix firewall-settings
Syntax
Parameters
Parameter Description
protocol- Which protocol to support on the configured ports. The default port 1494 is commonly
support used by two different protocols - Winframe or Citrix ICA
Options: PROTO_TYPE.WIN_FRAME, PROTO_TYPE.CITRIX_ICA
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 802
show service-system-default Citrix firewall-settings
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 803
set service-system-default DHCP
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 804
show service-system-default DHCP
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 805
set service-system-default DNS_TCP
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 806
set service-system-default DNS_TCP
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 807
show service-system-default DNS_TCP
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 808
set service-system-default DNS_UDP
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 809
show service-system-default DNS_UDP
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 810
set service-system-default FTP
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability.
aggressive- Time (in seconds) before the aggressive aging times out.
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections.
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy.
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 811
set service-system-default FTP
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 812
show service-system-default FTP
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 813
set service-system-default FTP firewall-settings
Syntax
Parameters
Parameter Description
mode FTP connection mode (allowed values are 'Any', 'Active' or 'Passive').
Options: any, active, passive
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 814
show service-system-default FTP firewall-settings
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 815
set service-system-default GRE
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability.
aggressive- Time (in seconds) before the aggressive aging times out.
aging-timeout
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy.
open-after-
policy-
installation
match INSPECT expression that searches for a pattern in a packet, only relevant for
services of type 'other'.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 816
set service-system-default GRE
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 817
show service-system-default GRE
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 818
set service-system-default H323
Syntax
Parameters
Parameter Description
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections.
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy.
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 819
set service-system-default H323
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 820
show service-system-default H323
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 821
set service-system-default H323_RAS
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 822
show service-system-default H323_RAS
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 823
set service-system-default HTTP
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability.
aggressive- Time (in seconds) before the aggressive aging times out.
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections.
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy.
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 824
set service-system-default HTTP
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 825
show service-system-default HTTP
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 826
set service-system-default HTTPS
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability.
aggressive- Time (in seconds) before the aggressive aging times out.
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections.
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy.
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 827
set service-system-default HTTPS
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 828
show service-system-default HTTPS
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 829
set service-system-default HTTP ips-settings
Syntax
Parameters
Parameter Description
non- Select action for connection over non standard ports (allowed values are 'Accept' and
standard- 'Block').
ports-action
Options: block, accept
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 830
set service-system-default HTTP ips-settings
Parameter Description
non- Select track option for connection over non standard ports (allowed values are 'log',
standard- 'alert' and 'don't log') .
ports-track
Options: none, log, alert
parser- Select action for when the parser fails (allowed values are 'Accept' and 'Block').
failure-action
Options: block, accept
parser- Select track option for when the parser fails (allowed values are 'log', 'alert' and 'don't
failure-track log').
Options: none, log, alert
post True to block requests with 'POST' method and without 'Content-Type' header.
Type: Boolean (true/false)
split-url True to split the URL between the query and fragment sections instructs the HTTP
protections to inspect the query and fragment sections separately.
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 831
show service-system-default HTTP ips-settings
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 832
set service-system-default HTTPS url-filtering-settings
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 833
show service-system-default HTTPS url-filtering-settings
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 834
set service-system-default IIOP
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability.
aggressive- Time (in seconds) before the aggressive aging times out.
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections.
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy.
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 835
set service-system-default IIOP
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 836
show service-system-default IIOP
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 837
set service-system-default IMAP
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability.
aggressive- Time (in seconds) before the aggressive aging times out.
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections.
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy.
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 838
set service-system-default IMAP
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 839
show service-system-default IMAP
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 840
set service-system-default LDAP
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 841
set service-system-default LDAP
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 842
show service-system-default LDAP
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 843
set service-system-default MGCP
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 844
show service-system-default MGCP
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 845
set service-system-default NetBIOSDatagram
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 846
show service-system-default NetBIOSDatagram
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 847
set service-system-default NetBIOSName
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 848
show service-system-default NetBIOSName
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 849
set service-system-default NetShow
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 850
set service-system-default NetShow
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 851
show service-system-default NetShow
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 852
set service-system-default NNTP
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 853
set service-system-default NNTP
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 854
show service-system-default NNTP
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 855
set service-system-default POP3
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 856
set service-system-default POP3
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 857
show service-system-default POP3
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 858
set service-system-default PPTP_TCP
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 859
set service-system-default PPTP_TCP
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 860
show service-system-default PPTP_TCP
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 861
set service-system-default PPTP_TCP ips-settings
Syntax
Parameters
Parameter Description
action Select action for PPTP connections (allowed values are 'Accept' and 'Block')
Options: block, accept
track Select track option for PPTP connections (allowed values are 'log', 'alert' and 'don't log')
Options: none, log, alert
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 862
show service-system-default PPTP_TCP ips-settings
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 863
set service-system-default RealAudio
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 864
set service-system-default RealAudio
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 865
show service-system-default RealAudio
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 866
set service-system-default RSH
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 867
set service-system-default RSH
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 868
show service-system-default RSH
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 869
set service-system-default RTSP
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 870
set service-system-default RTSP
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 871
show service-system-default RTSP
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 872
set service-system-default SCCP
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 873
set service-system-default SCCP
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 874
show service-system-default SCCP
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 875
set service-system-default SCCPS
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 876
set service-system-default SCCPS
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 877
show service-system-default SCCPS
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 878
set service-system-default SIP_TCP
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 879
set service-system-default SIP_TCP
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 880
show service-system-default SIP_TCP
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 881
set service-system-default SIP_UDP
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 882
show service-system-default SIP_UDP
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 883
set service-system-default SMTP
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 884
set service-system-default SMTP
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 885
show service-system-default SMTP
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 886
set service-system-default SNMP
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 887
show service-system-default SNMP
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 888
set service-system-default SNMP firewall-settings
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 889
show service-system-default SNMP firewall-settings
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 890
set service-system-default SQLNet
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 891
set service-system-default SQLNet
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 892
show service-system-default SQLNet
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 893
set service-system-default SSH
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 894
set service-system-default SSH
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 895
show service-system-default SSH
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 896
set service-system-default SSH ips-settings
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 897
show service-system-default SSH ips-settings
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 898
set service-system-default TELNET
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 899
set service-system-default TELNET
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 900
show service-system-default TELNET
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 901
set service-system-default TFTP
Syntax
Parameters
Parameter Description
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 902
set service-system-default TFTP
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 903
show service-system-default TFTP
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 904
service-tcp
service-tcp
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 905
add service-tcp
add service-tcp
Description
Adds a new TCP service object with configurable ports.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 906
set service-tcp
set service-tcp
Description
Configures an existing TCP service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging- firewall to increase durability and stability
enable
aggressive- Time (in seconds) before the aggressive aging times out
aging-
timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 907
set service-tcp
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 908
delete service-tcp
delete service-tcp
Description
Deletes a TCP service object by name.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 909
show service-tcp
show service-tcp
Description
Shows the configuration of a specific TCP service object.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 910
show services-tcp
show services-tcp
Description
Shows the configuration of all TCP service objects.
Syntax
show services-tcp
Parameters
Parameter Description
n/a
Example
show services-tcp
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 911
service-udp
service-udp
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 912
add service-udp
add service-udp
Description
Adds a new UDP service object with configurable ports.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 913
delete service-udp
delete service-udp
Description
Deletes a UDP service object by name.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 914
set service-udp
set service-udp
Description
Configures an existing UDP service object
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging- firewall to increase durability and stability
enable
aggressive- Time (in seconds) before the aggressive aging times out
aging-
timeout
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 915
set service-udp
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 916
show service-udp
show service-udp
Description
Shows the configuration of a specific UDP service object
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 917
show services-udp
show services-udp
Description
Shows the configuration of all UDP service objects.
Syntax
show services-udp
Parameters
Parameter Description
n/a
Example
show services-udp
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 918
show services-icmp
show services-icmp
Description
Shows the configuration of all ICMP-type service objects.
Syntax
show services-icmp
Parameters
Parameter Description
n/a
Example
show services-icmp
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 919
shell/expert
shell/expert
The shelland expertcommands switch between the shell and expert modes.
Description
Changes to expert mode.
Syntax
shell
expert
Parameters
Parameter Description
n/a
Example
shell
Comments
Use the cpshell command to start cpshell.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 920
set sic_init
set sic_init
Description
Sets the SIC password.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 921
sim
sim
Description
SecureXL Implementation Module commands
Parameters
Parameter Description
tab [-s] [name] print the table content (-s for summary)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 922
snmp
snmp
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 923
add snmp
add snmp
Adds SNMP trap receiver and SNMP users to the SNMP configuration.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 924
add snmp
add snmp
Description
Adds a new SNMP trap receiver IP address to be used by the SNMP agent.
Syntax
Parameters
Parameter Description
community Community name of the receivers trap, public is default for version2 users
Type: A string of alphanumeric characters without space between them
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 925
add snmp
add snmp
Description
Adds a new user to be used by SNMPv3 protocol.
Syntax
Parameters
Parameter Description
auth-pass-type Authentication protocol type for the version3 user, options are: MD5 or SHA1
Options: MD5, SHA1
privacy-pass-phrase Privacy password chosen by the version3 user in case privacy is set
Type: A string that contains alphanumeric and special characters
privacy-pass-type Privacy protocol type for the version3 user, options are: AES or DES
Options: AES, DES
security-level Does Privacy protocol for this version3 user was set in the security level
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 926
delete snmp
delete snmp
Deletes SNMP trap receivers and SNMP users.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 927
delete snmp
delete snmp
Description
Deletes an existing SNMP trap receiver by IP address.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 928
delete snmp
delete snmp
Description
Deletes a configured SNMP contact.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 929
delete snmp
delete snmp
Description
Deletes a configured SNMP location.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 930
set snmp
set snmp
Configures SNMP settings.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 931
set snmp
set snmp
escription
Configures SNMP agent settings.
Syntax
Parameters
Parameter Description
Example
set snmp agent true agent-version true community word contact myContact
location myLocation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 932
set snmp
set snmp
Description
Configures SNMP agent settings.
Syntax
Parameters
Parameter Description
Example
set snmp agent-version true agent true community word contact myContact
location myLocation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 933
set snmp
set snmp
Description
Configures SNMP community settings.
Syntax
Parameters
Parameter Description
Example
set snmp community word agent true agent-version true contact myContact
location myLocation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 934
set snmp
set snmp
Description
Configures SNMP contact settings.
Syntax
Parameters
Parameter Description
Example
set snmp contact myContact agent true agent-version true community word
location myLocation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 935
set snmp
set snmp
Description
Configures SNMP location settings.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 936
show snmp
show snmp
Shows SNMP configuration.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 937
show snmp
show snmp
Description
Shows SNMP agent configuration.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 938
show snmp
show snmp
Description
Shows SNMP agent version configuration.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 939
show snmp
show snmp
Description
Shows SNMP community configuration.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 940
show snmp
show snmp
Description
Shows SNMP contact configuration.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 941
show snmp
show snmp
Description
Shows SNMP location configuration.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 942
show snmp-general-all
show snmp-general-all
Description
Shows SNMP configuration.
Syntax
show snmp-general-all
Parameters
Parameter Description
n/a
Example
show snmp-general-all
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 943
snmp traps
snmp traps
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 944
set snmp traps
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 945
set snmp traps
Syntax
Parameters
Parameter Description
snmpTrapsEnable snmpTrapsEnable
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 946
set snmp traps
Syntax
Parameters
Parameter Description
enable Enable or disable whether a trap is sent for the specific event
Type: Boolean (true/false)
repetitions-delay Wait time (in seconds) between sending each trap, optional field
Type: A number with no fractional part (integer)
severity Trap hazardous level, optional field, severity of the trap between 1 - 4
Type: A number with no fractional part (integer)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 947
set snmp traps
Syntax
Parameters
Parameter Description
community Community name of the receivers trap, public is default for version2 users
Type: A string of alphanumeric characters without space between them
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 948
show snmp traps
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 949
delete snmp traps-receivers
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 950
show snmp traps receivers
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 951
show snmp traps enabled-traps
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 952
snmp user
snmp user
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 953
delete snmp user
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 954
set snmp user
Syntax
Parameters
Parameter Description
auth-pass-type Authentication protocol type for the version3 user, options are: MD5 or SHA1
Options: MD5, SHA1
privacy-pass-phrase Privacy password chosen by the version3 user in case privacy is set
Type: A string that contains alphanumeric and special characters
privacy-pass-type Privacy protocol type for the version3 user, options are: AES or DES
Options: AES, DES
security-level Does Privacy protocol for this version3 user was set in the security level
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 955
show snmp user
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 956
show snmp users
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 957
delete snmp users
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 958
show software version
Syntax
Parameters
Parameter Description
n/a
Example
show software-version
Output
Success shows the software version of the appliance. Failure shows an appropriate error message.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 959
ssl-inspection advanced-settings
ssl-inspection advanced-settings
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 960
set ssl-inspection advanced-settings
Syntax
Parameters
Parameter Description
additional-https-ports Additional HTTPS ports for ssl inspection (a comma separated list
ofports/ranges)
Type: Port range
bypass-well-known- Bypass HTTPS Inspection of traffic to well known software update services
update-services
Type: Boolean (true/false)
log-empty-ssl- Log connections that were terminated by the client before data was sent -
connections might indicate the client did not install CA certificate
Type: Boolean (true/false)
retrieve-intermediate- Indicates if the SSL inspection mechanism will perform it's validations on all
ca-certificate intermidate CA certificates in the certificate chain
Type: Boolean (true/false)
validate-cert- Indicates if the SSL inspection mechanism will drop connections that present
expiration an expired certificate
Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 961
set ssl-inspection advanced-settings
Parameter Description
validate-crl Indicates if the SSL inspection mechanism will drop connections that present a
revoked certificate
Type: Boolean (true/false)
validate- Indicates if the SSL inspection mechanism will drop connections that present a
unreachable-crl certificate with an unreachable CRL
Type: Boolean (true/false)
validate-untrusted- Indicates if the SSL inspection mechanism will drop connections that present
certificates an untrusted server certificate
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 962
show ssl-inspection advanced-settings
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 963
ssl-inspection exception
ssl-inspection exception
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 964
add ssl-inspection exception
Syntax
Parameters
Parameter Description
category-negate If true, the category is all traffic except what is defined in the category field
Type: Boolean (true/false)
destination- If true, the destination is all traffic except what is defined in the destination field
negate
Type: Boolean (true/false)
service The network service object that the exception should match to
service-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
source-negate If true, the source is all traffic except what is defined in the source field
Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 965
add ssl-inspection exception
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 966
delete ssl-inspection exception
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 967
delete ssl-inspection exception
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 968
delete ssl-inspection exception
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 969
set ssl-inspection exception
Syntax
Parameters
Parameter Description
category-negate If true, the category is all traffic except what is defined in the category field
Type: Boolean (true/false)
destination- If true, the destination is all traffic except what is defined in the destination field
negate
Type: Boolean (true/false)
service The network service object that the exception should match to
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 970
set ssl-inspection exception
Parameter Description
service-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
source-negate If true, the source is all traffic except what is defined in the source field
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 971
show ssl-inspection exception
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 972
show ssl-inspection exceptions
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 973
ssl-inspection policy
ssl-inspection policy
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 974
set ssl-inspection policy
Syntax
Parameters
Parameter Description
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 975
set ssl-inspection policy
Parameter Description
log-inspected-traffic Generates an SSL inspection log. You can see the logs of the security
policy that is enforced on SSL traffic without enabling this feature.
Type: Boolean (true/false)
log-policy-bypass-traffic Generate an SSL bypass log for SSL traffic that was not inspected by SSL
inspection
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 976
set ssl-inspection policy https-categorization-only-mode
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 977
set ssl-inspection policy inspect-https-protocol
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 978
set ssl-inspection policy inspect-imaps-protocol
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 979
show ssl-inspection policy
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 980
delete ssl-network-extender
delete ssl-network-extender
Description
Forces a manual deletion of the SSL network extender, thus forcing the gateway to re-download the latest
version of the extender from the cloud.
Syntax
delete ssl-network-extender
Parameters
Parameter Description
n/a
Example
delete ssl-network-extender
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 981
static-route
static-route
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 982
add static-route
add static-route
Description
Adds a new manually configured routing rule.
Syntax
Parameters
Parameter Description
destination IP address and subnet length of the destination of the packet in the format
IP/subnet. e.g. 192.168.0.0/16
Type: An IP address with a mask length
metric Metric
Type: A number with no fractional part (integer)
source IP address and subnet length of the source of the packet in the format IP/subnet. e.g.
192.168.1.0/24
Type: An IP address with a mask length
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 983
set static-route
set static-route
Description
Configures an existing manually configured route rule.
Syntax
Parameters
Parameter Description
destination IP address and subnet length of the destination of the packet in the format IP/subnet. e.g.
192.168.0.0/16
Type: An IP address with a mask length
id id
Type: A number with no fractional part (integer)
metric Metric
Type: A number with no fractional part (integer)
source IP address and subnet length of the source of the packet in the format IP/subnet. e.g.
192.168.1.0/24
Type: An IP address with a mask length
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 984
delete static-route
delete static-route
Description
Deletes a manually defined routing rule.
Syntax
Parameters
Parameter Description
Example
delete static-route 3
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 985
delete static-routes
delete static-routes
Description
Deletes all manually defined static routing rules.
Syntax
delete static-routes
Parameters
Parameter Description
n/a
Example
delete static-routes
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 986
show static-routes
show static-routes
Description
Shows all static routes.
Syntax
show static-routes
Parameters
Parameter Description
n/a
Example
show static-routes
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 987
streaming-engine-settings
streaming-engine-settings
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 988
set streaming-engine-settings
set streaming-engine-settings
Configures the streaming engine settings.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 989
set streaming-engine-settings
set streaming-engine-settings
Description
Configures the streaming engine settings.
Syntax
Parameters
Parameter Description
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 990
set streaming-engine-settings
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 991
set streaming-engine-settings
set streaming-engine-settings
Description
Configures the streaming engine settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 992
show streaming-engine-settings
show streaming-engine-settings
Shows streaming engine settings.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 993
show streaming-engine-settings
show streaming-engine-settings
Description
Shows streaming engine settings.
Syntax
show streaming-engine-settings
Parameters
Parameter Description
n/a
Example
show streaming-engine-settings
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 994
show streaming-engine-settings
show streaming-engine-settings
Description
Shows streaming engine advanced settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 995
switch
switch
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 996
add switch
add switch
Description
Adds a new Port-based VLAN switch object. The physical LAN ports can take part in a "switch" object which
passes traffic between those ports in the hardware level (traffic doesn't undergo inspection as it is not
routed between those ports). In essence the "switch" combines physical LAN ports into a single network.
Syntax
Parameters
Parameter Description
name Name
Type: A switch name should be LAN[1-8]_Switch
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 997
delete switch
delete switch
Description
Deletes a defined port-based VLAN switch object by name.
Syntax
Parameters
Parameter Description
name Name
Type: A switch name should be LAN[1-8]_Switch
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 998
set switch
set switch
Configures an existing port-based VLAN (switch).
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 999
set switch
set switch
Description
Add a physical port to an existing port-based VLAN (switch).
Syntax
Parameters
Parameter Description
name Name
Type: A switch name should be LAN[1-8]_Switch
port Name
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1000
set switch
set switch
Description
Removes a physical port from an existing port-based VLAN (switch).
Syntax
Parameters
Parameter Description
name Name
Type: A switch name should be LAN[1-8]_Switch
port Name
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1001
show switch
show switch
Shows port-based VLAN (switch) configuration.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1002
show switch
show switch
Description
Shows port-based VLAN (switch) configuration.
Syntax
Parameters
Parameter Description
name Name
Type: A switch name should be LAN[1-8]_Switch
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1003
show switch
show switch
Description
Shows ports within a configured port-based VLAN (switch) configuration.
Syntax
Parameters
Parameter Description
name Name
Type: A switch name should be LAN[1-8]_Switch
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1004
show switches
show switches
Description
Shows all port-based VLANs (switches).
Syntax
show switches
Parameters
Parameter Description
n/a
Example
show switches
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1005
syslog-server
syslog-server
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1006
add syslog-server
add syslog-server
Description
Adds a new external syslog server. The appliance can send its syslog information to multiple syslog
servers and can also be configured to relay its security logs to external syslog servers.
Syntax
Parameters
Parameter Description
port Port in the external System Log Server that receives the logs (default is 514)
Type: Port number
sent-logs Determine which logs types will be sent to the System Log Server
Options: system-logs, security-logs, system-and-security-logs
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1007
delete syslog-server
delete syslog-server
Deletes a configured external syslog server.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1008
delete syslog-server
delete syslog-server
Description
Deletes a configured external syslog server by IP address.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1009
delete syslog-server
delete syslog-server
Description
Deletes a configured external syslog server by name.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1010
set syslog-server
set syslog-server
Configure an existing syslog server's settings.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1011
set syslog-server
set syslog-server
Description
Configure an existing syslog server's settings by IP address.
Syntax
Parameters
Parameter Description
port Port in the external System Log Server that receives the logs (default is 514)
Type: Port number
sent-logs Determine which logs types will be sent to the System Log Server
Options: system-logs, security-logs, system-and-security-logs
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1012
set syslog-server
set syslog-server
Description
Configure an existing syslog server's settings by name.
Syntax
Parameters
Parameter Description
port Port in the external System Log Server that receives the logs (default is 514)
Type: Port number
sent-logs Determine which logs types will be sent to the System Log Server
Options: system-logs, security-logs, system-and-security-logs
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1013
show syslog-server
show syslog-server
Shows configuration of external syslog servers.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1014
show syslog-server
show syslog-server
Description
Shows configuration of an external syslog server by IP address.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1015
show syslog-server
show syslog-server
Description
Shows configuration of an external syslog server by name.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1016
show syslog-server all
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1017
show syslog-server all
system-settings
Relevant commands for system settings.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1018
show system-settings is-custom-branding
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1019
traceroute-max-ttl
traceroute-max-ttl
Description
The maximal value for TTL field for a packet to be considered as a traceroute
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1020
threat-prevention-advanced
threat-prevention-advanced
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1021
set threat-prevention-advanced
set threat-prevention-advanced
Description
Configures advanced settings for Threat Prevention blades.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1022
show threat-prevention-advanced
show threat-prevention-advanced
Description
Shows advanced settings for the Threat Prevention blades.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1023
threat-prevention anti-bot
threat-prevention anti-bot
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1024
set threat-prevention anti-bot engine
Syntax
Parameters
Parameter Description
malicious- Indicates if the action upon detecting malicious activity will be according to the policy
activity settings or a manually configured specific action
Options: ask, prevent, detect, inactive, policy-action
reputation- Indicates if the action upon detecting attempted access to domains with a bad reputation
domains will be according to the policy or a manually configured specific action
Options: ask, prevent, detect, inactive, policy-action
reputation- Indicates if the action upon detecting attempted access to IP addresses with a bad
ips reputation will be according to the policy or a manually configured specific action
Options: ask, prevent, detect, inactive, policy-action
reputation- Indicates if the action upon detecting attempted access to URLs with a bad reputation will
urls be according to the policy or a manually configured specific action
Options: ask, prevent, detect, inactive, policy-action
unusual- Indicates if the action upon detecting unusual activity will be according to the policy or a
activity manually configured specific action
Options: ask, prevent, detect, inactive, policy-action
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1025
show threat-prevention anti-bot engine
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1026
set threat-prevention anti-bot policy
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1027
set threat-prevention anti-bot policy
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1028
set threat-prevention anti-bot policy
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1029
show threat-prevention anti-bot policy
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1030
show threat-prevention anti-bot policy
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1031
show threat-prevention anti-bot policy
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1032
set threat-prevention anti-bot user-check ask
Syntax
Parameters
Parameter Description
activity-text This text appears next to the 'ignore warning' checkbox of an Anti-Bot 'Ask' user
message
Type: A string that contains only printable characters
body The informative text that appears in the Anti-Bot 'Ask' user message
Type: A string that contains only printable characters
fallback-action Indicates the action to take when an 'Ask' user message cannot be displayed
Options: block, accept
frequency Indicates how often is the Anti-Bot 'Ask' user message is being presented to the
same user
Options: day, week, month
reason- Indicates if the user must enter a reason for ignoring this message in a designated
displayed text dialog
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1033
show threat-prevention anti-bot user-check ask
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1034
set threat-prevention anti-bot user-check block
Syntax
Parameters
Parameter Description
body The informative text that appears in the Anti-Bot 'Block' user message
Type: A string that contains only printable characters
redirect- Indicates if the user will be redirected to a custom URL in case of a 'Block' action
to-url
Type: Boolean (true/false)
redirect- Indicates the URL to redirect the user in case of a 'Block' action if configured to do so. The
url URL to redirect the user in case of a 'Block' action. Redirection happens only if this
functionality is turned on
Type: urlWithHttp
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1035
show threat-prevention anti-bot user-check block
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1036
threat-prevention anti-virus
threat-prevention anti-virus
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1037
set threat-prevention anti-virus engine
Syntax
Parameters
Parameter Description
urls-with- Indicates if the action upon detecting access to and from URLs with a bad reputation will
malware be according to the policy or a manually configured specific action
Options: ask, prevent, detect, inactive, policy-action
viruses Indicates if the action upon detecting viruses will be according to the policy or a manually
configured specific action
Options: ask, prevent, detect, inactive, policy-action
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1038
show threat-prevention anti-virus engine
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1039
add threat-prevention anti-virus file-type
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1040
delete threat-prevention anti-virus file-type
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1041
set threat-prevention anti-virus file-type
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1042
show threat-prevention anti-virus file-type
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1043
show threat-prevention anti-virus file-types
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1044
delete threat-prevention anti-virus file-type custom
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1045
set threat-prevention anti-virus policy
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1046
set threat-prevention anti-virus policy
Syntax
Parameters
Parameter Description
file-types- Indicates the file types that are inspected by the Anti-Virus blade: malware (known to
policy contain malware), all (all file types), specific (configured file families)
Options: malware, all-types, specific-families
interfaces Indicates the source zones for inspected incoming files: External, External and DMZ or all
interfaces
Options: all, external, external-dmz
protocol- Indicates if Anti-Virus inspection will be performed on all configured ports of HTTP traffic
http
Type: Boolean (true/false)
protocol- Indicates if Anti-Virus inspection will be performed on mail traffic (SMTP and POP3)
mail
Type: Boolean (true/false)
scope Indicates the source of scanned filed: Scan incoming files, or scan both incoming and
outgoing files
Options: incoming, incoming-and-outgoing
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1047
set threat-prevention anti-virus policy
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1048
set threat-prevention anti-virus policy
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1049
set threat-prevention anti-virus policy
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1050
set threat-prevention anti-virus policy
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1051
set threat-prevention anti-virus policy
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1052
set threat-prevention anti-virus policy
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1053
show threat-prevention anti-virus policy
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1054
show threat-prevention anti-virus policy
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1055
show threat-prevention anti-virus policy
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1056
set threat-prevention anti-virus user-check ask
Syntax
Parameters
Parameter Description
activity-text This text appears next to the 'ignore warning' checkbox of an Anti-Virus 'Ask' user
message
Type: A string that contains only printable characters
body The informative text that appears in the Anti-Virus 'Ask' user message
Type: A string that contains only printable characters
fallback-action Indicates the action to take when an 'Ask' user message cannot be displayed
Options: block, accept
frequency Indicates how often is the Anti-Virus 'Ask' user message is being presented to the
same user
Options: day, week, month
reason- Indicates if the user must enter a reason for ignoring this message in a designated
displayed text dialog
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1057
show threat-prevention anti-virus user-check ask
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1058
set threat-prevention anti-virus user-check block
Syntax
Parameters
Parameter Description
body The informative text that appears in the Anti-Virus 'Block' user message
Type: A string that contains only printable characters
redirect- Indicates if the user will be redirected to a custom URL in case of a 'Block' action
to-url
Type: Boolean (true/false)
redirect- Indicates the URL to redirect the user in case of a 'Block' action if configured to do so. The
url URL to redirect the user in case of a 'Block' action. Redirection happens only if this
functionality is turned on
Type: urlWithHttp
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1059
show threat-prevention anti-virus user-check block
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1060
threat-prevention exception
threat-prevention exception
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1061
add threat-prevention exception
Syntax
Parameters
Parameter Description
blade The blade to which the exception applies: Anti-Virus, Anti-Bot or both
Options: any, any-av, any-ab, any-ips
destination- If true, the destination is all traffic except what is defined in the destination field
negate
Type: Boolean (true/false)
log The logging method used when there is a match on the rule: None - do not log, Log -
Create log, Alert - log with alert
Options: none, log, alert
protection- Indicates if the exception rule will be matched a specific IPS protection
code
protection- Indicates if the exception rule will be matched a specific IPS protection
name
service- If true, the service is everything except what is defined in the service field
negate
Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1062
add threat-prevention exception
Parameter Description
source IP address, network object or user group that the exception applies to
source If true, the source is all traffic except what is defined in the source field
negate
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1063
delete threat-prevention exception
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1064
set threat-prevention exception
Syntax
Parameters
Parameter Description
blade The blade to which the exception applies: Anti-Virus, Anti-Bot or both
Options: any, any-av, any-ab, any-ips
destination- If true, the destination is all traffic except what is defined in the destination field
negate
Type: Boolean (true/false)
log The logging method used when there is a match on the rule: None - do not log, Log -
Create log, Alert - log with alert
Options: none, log, alert
protection- Indicates if the exception rule will be matched a specific IPS protection
code
protection- Indicates if the exception rule will be matched a specific IPS protection
name
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1065
set threat-prevention exception
Parameter Description
service- If true, the service is everything except what is defined in the service field
negate
Type: Boolean (true/false)
source IP address, network object or user group that the exception applies to
source- If true, the source is all traffic except what is defined in the source field
negate
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1066
show threat-prevention exception
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1067
delete threat-prevention exceptions
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1068
show threat-prevention infected-hosts
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1069
threat-prevention ips
threat-prevention ips
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1070
set threat-prevention ips custom-default-policy
Syntax
Parameters
Parameter Description
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1071
set threat-prevention ips custom-default-policy
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1072
show threat-prevention ips custom-default-policy
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1073
add threat-prevention ips network-exception
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1074
add threat-prevention ips network-exception
Syntax
Parameters
Parameter Description
destination- If true, the destination is all traffic except what is defined in the destination field
negate
Type: Boolean (true/false)
protection-name Indicates if the exception rule will be matched on all IPS protections or a specific
one
service-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
source-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1075
add threat-prevention ips network-exception
Syntax
Parameters
Parameter Description
destination- If true, the destination is all traffic except what is defined in the destination field
negate
Type: Boolean (true/false)
protection-code Indicates if the exception rule will be matched on all IPS protections or a specific
one
service-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
source-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1076
delete threat-prevention ips network-exception
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1077
delete threat-prevention ips network-exception
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1078
delete threat-prevention ips network-exception
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1079
set threat-prevention ips network-exception
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1080
set threat-prevention ips network-exception
Syntax
Parameters
Parameter Description
destination- If true, the destination is all traffic except what is defined in the destination field
negate
Type: Boolean (true/false)
protection-code Indicates if the exception rule will be matched on all IPS protections or a specific
one
service-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
source-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1081
set threat-prevention ips network-exception
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1082
set threat-prevention ips network-exception
Syntax
Parameters
Parameter Description
destination- If true, the destination is all traffic except what is defined in the destination field
negate
Type: Boolean (true/false)
protection-name Indicates if the exception rule will be matched on all IPS protections or a specific
one
service-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
source-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1083
set threat-prevention ips network-exception
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1084
show threat-prevention ips network-exception
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1085
set threat-prevention ips policy
Syntax
Parameters
Parameter Description
default-policy The type of policy used for IPS - strict, typical or custom
detect-mode Indicates if the default policy of IPS is to only logs events and not block them
Type: Boolean (true/false)
log Indicates the tracking level for IPS - none, block or alert
Options: none, log, alert
Example
set threat-prevention ips policy mode true log none default-policy word
detect-mode true
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1086
show threat-prevention ips policy
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1087
find threat-prevention ips protection
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1088
set threat-prevention ips protection-action-override
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1089
set threat-prevention ips protection-action-override
Syntax
Parameters
Parameter Description
protection- The IPS topic the override belongs to. Every override belongs to a single topic
code
Type: A number with no fractional part. Values are between 4,503,599,627,370,495 to
4,503,599,627,370,495
track Indicates the manually configured tracking option for this protection
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1090
set threat-prevention ips protection-action-override
Syntax
Parameters
Parameter Description
track Indicates the manually configured tracking option for this protection
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1091
set threat-prevention ips protection-action-override
Syntax
Parameters
Parameter Description
override- Indicates if the action upon detection will be according to the general IPS policy or
policy-action manually configured for this protection
Type: Boolean (true/false)
protection- The IPS topic the override belongs to. Every override belongs to a single topic
code
Type: A number with no fractional part. Values are between 4,503,599,627,370,495
to 4,503,599,627,370,495
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1092
set threat-prevention ips protection-action-override
Syntax
Parameters
Parameter Description
override- Indicates if the action upon detection will be according to the general IPS policy or
policy-action manually configured for this protection
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1093
show threat-prevention ips protection-action-override
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1094
show threat-prevention ips protection-action-override
Syntax
Parameters
Parameter Description
protection- The IPS topic the override belongs to. Every override belongs to a single topic
code
Type: A number with no fractional part. Values are between 4,503,599,627,370,495 to
4,503,599,627,370,495
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1095
show threat-prevention ips protection-action-override
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1096
show threat-prevention ips protection-action-override
threat-prevention-profile
Commands relevant for the Unified Threat Prevention profile.
Syntax
Parameters
Parameter Description
track Tracking options for Threat Prevention protections: None - do not log, Log -Create log,
Alert - log with alert
Options: none, log, alert
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1097
threat-prevention policy
threat-prevention policy
Shows commands relevant to Threat Prevention policy.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1098
set threat-prevention policy
Syntax
Parameters
Parameter Description
track Tracking options for Threat Prevention protections: None - do not log, Log -Create log,
Alert - log with alert
Options: none, log, alert
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1099
show threat-prevention policy
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1100
threat-prevention threat-emulation additional-remote-emulator
threat-prevention threat-emulation
additional-remote-emulator
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1101
add threat-prevention threat-emulation additional-remote-emulator
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1102
delete threat-prevention threat-emulation additional-remote-emulator
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1103
delete threat-prevention threat-emulation additional-remote-emulator
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1104
delete threat-prevention threat-emulation additional-remote-emulator
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1105
set threat-prevention threat-emulation additional-remote-emulator
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1106
show threat-prevention threat-emulation additional-remote-emulator
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1107
show threat-prevention threat-emulation additional-remote-emulator
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1108
show threat-prevention threat-emulation additional-remote-emulator
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1109
set threat-prevention threat-emulation file-types-revert-actions-to-default
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1110
threat-prevention threat-emulation
threat-prevention threat-emulation
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1111
set threat-prevention threat-emulation file-type
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1112
show threat-prevention threat-emulation file-type
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1113
show threat-prevention threat-emulation file-types
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1114
set threat-prevention threat-emulation policy
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1115
set threat-prevention threat-emulation policy
Syntax
Parameters
Parameter Description
connection- Indicates the strictness mode of the Threat Emulation engine over HTTP: Back-ground -
handling- connections are allowed while the file emulation runs (if needed), Hold - connections are
mode-http blocked until the file emulation is completed
Options: background, hold
connection- Indicates the strictness mode of the Threat Emulation engine over SMTP: Back-ground -
handling- connections are allowed while the file emulation runs (if needed), Hold - connections are
mode-smtp blocked until the file emulation is completed
Options: background, hold
detect- Indicates if the Threat Emulation blade is set to 'Detect Only' mode
mode
Type: Boolean (true/false)
interfaces Indicates the source zones for inspected incoming files: External, External and DMZ or
all interfaces
Options: all, external, external-dmz
protocol- Indicates if file emulation will be performed on all configured ports of HTTP traffic
http
Type: Boolean (true/false)
scope Indicates the source of scanned file: scan incoming files, or scan both incoming and
outgoing files
Options: incoming, incoming-and-outgoing
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1116
set threat-prevention threat-emulation policy
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1117
set threat-prevention threat-emulation policy
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1118
show threat-prevention threat-emulation policy
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1119
show threat-prevention threat-emulation policy
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1120
show threat-prevention threat-emulation policy
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1121
threat-prevention whitelist
threat-prevention whitelist
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1122
add threat-prevention whitelist mail
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1123
show threat-prevention whitelist files
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1124
delete threat-prevention whitelist mail
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1125
set threat-prevention whitelist mail
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1126
show threat-prevention whitelist mail
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1127
delete threat-prevention whitelist mails
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1128
show threat-prevention whitelist mails
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1129
add threat-prevention whitelist type-file
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1130
delete threat-prevention whitelist type-file
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1131
delete threat-prevention whitelist type-file
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1132
delete threat-prevention whitelist type-file
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1133
add threat-prevention whitelist type-url
Syntax
Parameters
Parameter Description
url URL
Type: URL
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1134
delete threat-prevention whitelist type-url
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1135
delete threat-prevention whitelist type-url
Syntax
Parameters
Parameter Description
url URL
Type: URL
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1136
delete threat-prevention whitelist type-url
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1137
show threat-prevention whitelist urls
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1138
ui-settings
ui-settings
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1139
set ui-settings
set ui-settings
Configures customizations that can be done for the administration portal.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1140
set ui-settings
set ui-settings
Description
Configure a custom logo that will appear in the administration portal. The logo can be reached through a
URL.
Syntax
Parameters
Parameter Description
custom- Clicking the company logo in the web interface opens this URL
webui-
logo-url Type: urlWithHttp
use- The company logo is displayed on the appliance's web interface and on its login page.
custom- The customized logo should follow the size restrictions in order to be displayed properly.
webui-
logo Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1141
set ui-settings
set ui-settings
Description
Configures customizations that can be done for the administration portal.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1142
show ui-settings
show ui-settings
Shows web interface settings and customizations.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1143
show ui-settings
show ui-settings
Description
Shows web interface settings and customizations.
Syntax
show ui-settings
Parameters
Parameter Description
n/a
Example
show ui-settings
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1144
show ui-settings
show ui-settings
Description
Shows web Interface advanced settings.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1145
usb-modem-advanced
usb-modem-advanced
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1146
add usb-modem-advanced
add usb-modem-advanced
Description
Add a USB modem advanced entry.
Syntax
Parameters
Parameter Description
field-name Name
Type: A string that contains [a-z], [A-Z], [0-9], '_'
field-value Value
Type: A string that contains [a-z], [A-Z], [0-9], '_', '.', ',', '-', '/', '@', '+', ',', ':', '='
product-id Product ID
Type: A hexadecimal string
vendor-id Vendor ID
Type: A hexadecimal string
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1147
delete usb-modem-advanced
delete usb-modem-advanced
Description
Delete an existing USB modem advanced entry.
Syntax
Parameters
Parameter Description
id id
Type: A number with no fractional part (integer)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1148
delete usb-modem-advanced-all
delete usb-modem-advanced-all
Description
Delete all existing USB modem advanced entries.
Syntax
delete usb-modem-advanced-all
Parameters
Parameter Description
n/a
Example
delete usb-modem-advanced-all
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1149
set usb-modem-advanced
set usb-modem-advanced
Description
Configure a USB modem advanced entry.
Syntax
Parameters
Parameter Description
field-name Name
Type: A string that contains [a-z], [A-Z], [0-9], '_'
field-value Value
Type: A string that contains [a-z], [A-Z], [0-9], '_', '.', ',', '-', '/', '@', '+', ',', ':', '='
id id
Type: A number with no fractional part (integer)
product-id Product ID
Type: A hexadecimal string
vendor-id Vendor ID
Type: A hexa decimal string
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1150
show usb-modem-advanced
show usb-modem-advanced
Description
Show existing USB modem advanced entries.
Syntax
show usb-modem-advanced
Parameters
Parameter Description
n/a
Example
show usb-modem-advanced
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1151
show usb-modem-advanced table
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1152
usb-modem-info
usb-modem-info
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1153
show usb-modem-info
show usb-modem-info
Description
Show existing USB modem information.
Syntax
show usb-modem-info
Parameters
Parameter Description
n/a
Example
show usb-modem-info
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1154
show usb-modem-info-table
show usb-modem-info-table
Description
Show existing USB modem information in a table.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1155
usb-modem-watchdog
usb-modem-watchdog
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1156
set usb-modem-watchdog
set usb-modem-watchdog
Configures the internet probing (if probing is enabled) to automatically detect and fix 3G/4G internet
connectivity problems.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1157
set usb-modem-watchdog
set usb-modem-watchdog
Description
Configures the internet probing (if probing is enabled) to automatically detect and fix 3G/4G internet
connectivity problems.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1158
set usb-modem-watchdog
set usb-modem-watchdog
Description
Configures the internet probing (if probing is enabled) to automatically detect and fix 3G/4G internet
connectivity problems.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1159
show usb-modem-watchdog
show usb-modem-watchdog
Description
Shows configuration for additional health monitoring functionality to USB modems.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1160
set used-ad-group
set used-ad-group
Configures settings of a user group defined in the AD server.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1161
set used-ad-group
set used-ad-group
Description
Adds a bookmark to be shown in the SNX landing page to user group defined in the AD server. This is
relevant only if the user group is defined with VPN remote access privileges.
Syntax
Parameters
Parameter Description
bookmark label Text for the bookmark in the SSL Network Extender portal
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1162
set used-ad-group
set used-ad-group
Description
Removes a bookmark from being shown in the SNX landing page to user group defined in the AD server.
This is relevant only if the user group is defined with VPN remote access privileges.
Syntax
Parameters
Parameter Description
bookmark label Text for the bookmark in the SSL Network Extender portal
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1163
user-awareness
user-awareness
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1164
set user-awareness
set user-awareness
Configures settings for the User Awareness blade.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1165
set user-awareness
set user-awareness
Description
Configures the activation mode and user identification methods for the User Awareness blade.
Syntax
Parameters
Parameter Description
browser-based- Indicates if User Awareness uses a portal to identify locally defined users or
authentication- mode as a backup to other identification methods
Type: Boolean (true/false)
mode User Awareness mode - true for on, false for off
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1166
set user-awareness
set user-awareness
Description
Configures advanced settings for the User Awareness blade.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1167
set user-awareness
set user-awareness
Description
Configures advanced settings for the User Awareness blade.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1168
set user-awareness browser-based-authentication
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1169
set user-awareness browser-based-authentication
Syntax
Parameters
Parameter Description
block- When true, users using non-HTTP traffic are forced to login first through
unauthenticated- non- Browser-Based Authentication
web-traffic
Type: Boolean (true/false)
log-out-on-portal- When true, the user is forced to keep the portal window open to remain
close logged in
Type: Boolean (true/false)
portal-address Use the auto option unless you want to redirect to a manually configured URL
Type: String
Enter "<auto>" for default
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1170
set user-awareness browser-based-authentication
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1171
set user-awareness browser-based-authentication
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1172
set user-awareness browser-based-authentication
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1173
set user-awareness browser-based-authentication
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1174
show user-awareness
show user-awareness
Shows the configuration of the User Awareness blade.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1175
show user-awareness
show user-awareness
Description
Shows the configuration of the User Awareness blade.
Syntax
show user-awareness
Parameters
Parameter Description
n/a
Example
show user-awareness
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1176
show user-awareness
show user-awareness
Description
Shows advanced settings of the User Awareness blade.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1177
show user-awareness browser-based-authentication
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1178
set user-management
set user-management
Description
Configures advanced settings for the User Awareness blade.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1179
show upgrade log
Syntax
show upgrade-log
Parameters
Parameter Description
n/a
Example
show upgrade-log
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1180
show used-ad-group bookmarks
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1181
upgrade from usb or tftp server
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1182
vpn
vpn
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1183
vpn
vpn
The vpncommand manages the VPN driver and helps to debug the VPN.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1184
Managing the VPN Driver
Syntax
Parameters
Parameter Description
Return Value
0 on success, 1 on failure
Example
vpn drv on
Output
Success shows OK. Failure shows an appropriate error message.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1185
Launching TunnelUtil Tool
Syntax
vpn tunnelutil
Parameters
Parameter Description
n/a
Return Value
0 on success, 1 on failure
Example
vpn tunnelutil
Output
Success launches VPN TunnelUtil tool. Failure shows an appropriate error message.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1186
Debugging VPN
Debugging VPN
Description
Contains multiple utilities for troubleshooting VPN issues.
Syntax
Parameters
Parameter Description
Return Value
0
on success,
1
on failure
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1187
Debugging VPN
Example
vpn debug on
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1188
delete vpn
delete vpn
Description
Delete a configured Virtual Tunnel Interface (VTI) by tunnel ID.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1189
set vpn
set vpn
Configures existing remote VPN sites.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1190
set vpn
set vpn
Description
Configures existing remote VPN sites.
Syntax
Parameters
Parameter Description
aggressive- Determine the strength of the key when aggressive mode is enabled
mode-DH-group
aggressive- Indicates if gateway ID matching will be used. This adds a layer of security to
mode- enable- aggressive mode
gateway-id
Type: Boolean (true/false)
aggressive- Indicates if peer ID matching will be used. This adds a layer of security to
mode- enable- aggressive mode
peer-id
Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1191
set vpn
Parameter Description
aggressive- Indicates if Aggressive mode, a less secure negotiation protocol compared to main
mode-enabled mode, is used. It is less recommended if the remote site supports IPSec main
mode
Type: Boolean (true/false)
aggressive- The gateway ID that will be used for matching when configured to
mode-gateway-id
Type: vpnAggressiveModePeerId
aggressive- Indicates the type of gateway ID that will be used for matching when configured
mode- gateway-
id-type Options: domain-name, user-name
aggressive- The peer ID that will be used for matching when configured to
mode-peer-id
Type: vpnAggressiveModePeerId
aggressive- Indicates the type of peer ID that will be used for matching when configured
mode-peer-id-
type Options: domain-name, user-name
auth-method Indicates the type of authentication used when connecting to the remote site
Type: Press TAB to see available options
disable-nat Disable NAT for traffic to/from the remote site. Useful when one of the internal
networks contains a server Type: Boolean (true/false)
enable-perfect- Ensures that a session key will not be compromised if one of the (long-term)
forward-secrecy
private keys is compromised in the future. Type: Boolean (true/false)
enable- VPN Tunnels are constantly kept active and as a result, make it easier to recognize
permanent-vpn- malfunctions and connectivity problems
tunnel
Type: Boolean (true/false)
is-check-point- Enable if the remote site is connected through a Check Point Security Gateway
site
Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1192
set vpn
Parameter Description
is-site-behind- When connection type is IP address, this indicates if it is behind static NAT
static-nat
link-selection- The type of probing used for link selection when multiple IP addresses are
probing-method configured for the remote site
Options: ongoing, one-time
match-cert-dn Indicates if certificate matching should match the DN string in the certificate to the
configured DN string Type: Boolean (true/false)
match-cert-e- Indicates if certificate matching should match the E-mail string in the certificate to
mail the configured E-mail string
Type: Boolean (true/false)
match-cert-ip Indicates if certificate matching should match IP address in the certificate to the
site's IP address
Type: Boolean (true/false)
phase2-dh Determine the strength of the key used for the IPsec (Phase 2) key exchange
process. The higher the group number, the stronger and more secure the key is.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1193
set vpn
Parameter Description
remote-site-host- Indicates the remote site's host name when the link selection method is configured
name as such
remote-site-ip- Indicates the remote site's single IP address when the link selection method is
address configured as such
remote-site-link- Indicates the method of determining the destination IP address/s of the remote site
selection
Options: ip-address, host-name, high-availability, load-sharing, connection-
initiated-only-from-remote-site
static-nat-ip Indicates an external routable IP address via static NAT used by the remote site,
when configured as such
use-trusted-ca Indicates if a specific trusted CA is used for matching the remote site's certificate or
all configured trusted CAs
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1194
set vpn
set vpn
Description
Adds network objects to the encryption domain of existing remote VPN sites.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1195
set vpn
set vpn
Description
Removes all network objects from the encyryption domain of existing remote VPN sites.
Syntax
<remote-site-enc-dom-network-obj>
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1196
set vpn
set vpn
Description
Removes network objects from the encryption domain of existing remote VPN sites.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1197
set vpn
set vpn
Description
Adds IP addresses to an existing remote VPN site. This allows High Availability or Load Sharing between
the remote links using the link selection functionality.
Syntax
Parameters
Parameter Description
link-selection- IP address
multiple-
addrs addr
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1198
set vpn
set vpn
Description
Removes all IP addresses from an existing remote VPN site configured with multiple links.
Syntax
Parameters
Parameter Description
link-selection- IP address
multiple-
addrs addr
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1199
set vpn
set vpn
Description
Removes IP addresses from an existing remote VPN site. This allows High Availability or Load Sharing
between the remote links using the link selection functionality.
Syntax
Parameters
Parameter Description
link-selection- IP address
multiple-
addrs addr
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1200
set vpn
set vpn
Description
Adds a phase 1 encryption algorithm to an existing remote VPN site configured with a custom encryption
suite.
Syntax
Parameters
Parameter Description
custom-enc- Encryption algorithm preferences for phase1 in the VPN encryption algorithm,
phase1-enc which sets the base for phase2
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1201
set vpn
set vpn
Description
Removes all phase 1 encryption algorithm from an existing remote VPN site configured with a custom
encryption suite.
Syntax
Parameters
Parameter Description
custom-enc- Encryption algorithm preferences for phase1 in the VPN encryption algorithm,
phase1-enc which sets the base for phase2
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1202
set vpn
set vpn
Description
Removes a phase 1 encryption algorithm from an existing remote VPN site configured with a custom
encryption suite
Syntax
Parameters
Parameter Description
custom-enc- Encryption algorithm preferences for phase1 in the VPN encryption algorithm,
phase1-enc which sets the base for phase2
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1203
set vpn
set vpn
Description
Adds a phase 1 authentication algorithm to an existing remote VPN site configured with a custom
encryption suite.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1204
set vpn
set vpn
Description
Removes all phase 1 authentication algorithms from an existing remote VPN site configured with a custom
encryption suite.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1205
set vpn
set vpn
Description
Removes a phase 1 authentication algorithm from an existing remote VPN site configured with a custom
encryption suite.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1206
set vpn
set vpn
Description
Adds a Diffie-Hellman group to an existing remote VPN site configured with a custom encryption suite.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1207
set vpn
set vpn
Description
Removes all Diffie-Hellman groups from an existing remote VPN site configured with a custom encryption
suite.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1208
set vpn
set vpn
Description
Removes an Diffie-Hellman group from an existing remote VPN site configured with a custom encryption
suite.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1209
set vpn
set vpn
Description
Adds a phase 2 encryption algorithm to an existing remote VPN site configured with a custom encryption
suite.
Syntax
Parameters
Parameter Description
custom-enc- Encryption algorithm preferences for phase2 in the VPN encryption algorithm
phase2-enc
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1210
set vpn
set vpn
Description
Removes all phase 2 encryption algorithms from an existing remote VPN site configured with a custom
encryption suite.
Syntax
Parameters
Parameter Description
custom-enc- Encryption algorithm preferences for phase2 in the VPN encryption algorithm
phase2-enc
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1211
set vpn
set vpn
Description
Removes a phase 2 encryption algorithm from an existing remote VPN site configured with a custom
encryption suite.
Syntax
Parameters
Parameter Description
custom-enc- Encryption algorithm preferences for phase2 in the VPN encryption algorithm
phase2-enc
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1212
set vpn
set vpn
Description
Adds a phase 2 authentication algorithm to an existing remote VPN site configured with a custom
encryption suite.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1213
set vpn
set vpn
Description
Removes all phase 2 authentication algorithms from an existing remote VPN site configured with a custom
encryption suite.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1214
set vpn
set vpn
Description
Removes a phase 2 authentication algorithm from an existing remote VPN site configured with a custom
encryption suite.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1215
set vpn
set vpn
Description
Configures an existing Virtual Tunnel Interface (VTI) for route based VPN.
Syntax
Parameters
Parameter Description
peer Remote peer name as defined in the VPN community. You must define the two peers in
the VPN community before you can define the VTI. The Peer ID is an alpha-numeric
character string.
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z, _ -)
characters without spaces
remote Defines the remote peer IPv4 address, used at the peer gateway's point-to-point virtual
interface (numbered VTI only)
Type: IP address
type The type of VTI: Numbered VTI that uses a specified, static IPv4 addresses for local and
remote connections, or unnumbered VTI that uses the interface and the remote peer
name to get addresses
Type: Press TAB to see available options
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1216
show vpn
show vpn
Shows VPN site to site configuration.
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1217
show vpn
show vpn
Description
Shows the configuration of a remote VPN site.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1218
show vpn
show vpn
Description
Shows the configuration of a Virtual Tunnel Interface (VTI) used for route-based VPN.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1219
vpn remote-access
vpn remote-access
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1220
set vpn remote-access
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1221
set vpn remote-access
Syntax
Parameters
Parameter Description
l2tp-vpn-client Enable VPN remote access clients to connect via native VPN client (L2TP)
Type: Boolean (true/false)
mobile-client Enable VPN remote access mobile clients to connect via Check Point Mobile
VPN client
Type: Boolean (true/false)
sslvpn-client Enable VPN remote access clients to connect via SSL VPN
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1222
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1223
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1224
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1225
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1226
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1227
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1228
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1229
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1230
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1231
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1232
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1233
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1234
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1235
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1236
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1237
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1238
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1239
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1240
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1241
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1242
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1243
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1244
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1245
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1246
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1247
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1248
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1249
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1250
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1251
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1252
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1253
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1254
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1255
set vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1256
show vpn remote-access
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1257
show vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1258
show vpn remote-access
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1259
set vpn remote-access advanced
Syntax
Parameters
Parameter Description
default-route- Indicates if Internet traffic from connected clients will be routed first through this
through- this- gateway
gateway
Type: Boolean (true/false)
dns-domain-mode Indicates if remote access clients use the domain name configured under DNS
network settings of the device, or a manually configured domain name
Type: Boolean (true/false)
enc-dom Indicates if the encryption domain for remote access clients is calculated
automatically or manually configured
Options: manual, auto
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1260
set vpn remote-access advanced
Parameter Description
om-subnet-mask Subnet for allocating IP addresses of incoming remote access connections (Office
Mode)
Type: Subnet mask
use-this-gateway- Indicates if the remote access clients will use this gateway as a DNS server.
as- dns-server Applicable only when encryption domain is calculated automatically
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1261
show vpn remote-access advanced
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1262
set vpn remote-access advanced enc-dom-obj manual
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1263
set vpn remote-access advanced enc-dom-obj manual
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1264
set vpn remote-access advanced enc-dom-obj manual
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1265
vpn site
vpn site
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1266
add vpn site
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1267
add vpn site
Syntax
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1268
add vpn site
Parameters
Parameter Description
aggressive-mode- determine the strength of the key when aggressive mode is enabled
DH-group
aggressive-mode- Indicates if gateway ID matching will be used. This adds a layer of security to
enable-gateway- aggressive mode
id
Type: Boolean (true/false)
aggressive-mode- Indicates if peer ID matching will be used. This adds a layer of security to
enable-peer-id
aggressive mode
Type: Boolean (true/false)
aggressive-mode- main mode, is used. It is less recommended if the remote site supports IPSec
enabled main mode
Type: Boolean (true/false)
aggressive-mode- The gateway ID that will be used for matching when configured to
gateway-id
Type: vpnAggressiveModePeerId
aggressive-mode- Indicates the type of gateway ID that will be used for matching when configured
gateway-id-type
Options: domain-name, user-name
aggressive-mode- The peer ID that will be used for matching when configured to
peer-id
Type: vpnAggressiveModePeerId
aggressive-mode- Indicates the type of peer ID that will be used for matching when configured
peer-id-type
Options: domain-name, user-name
auth-method Indicates the type of authentication used when connecting to the remote site
Type: Press TAB to see available options
disable-nat Disable NAT for traffic to/from the remote site. Useful when one of the internal
networks contains a server
Type: Boolean (true/false)
enable-perfect- Ensures that a session key will not be compromised if one of the (long-term)
forward-secrecy
private keys is compromised in the future.
Type: Boolean (true/false)
enable- VPN Tunnels are constantly kept active and as a result, make it easier to
permanent- vpn- recognize malfunctions and connectivity problems Type: Boolean (true/false)
tunnel
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1270
add vpn site
Parameter Description
is-check-point-site Enable if the remote site is connected through a Check Point Security Gateway
Type: Boolean (true/false)
link-selection- IP address
multiple-addrs
addr
link-selection- The type of probing used for link selection when multiple IP addresses are
probing- method configured for the remote site
Options: ongoing, one-time
match-cert-dn Indicates if certificate matching should match the DN string in the certificate to the
configured DN string
Type: Boolean (true/false)
match-cert-e-mail Indicates if certificate matching should match the E-mail string in the certificate to
the configured E-mail string
Type: Boolean (true/false)
match-cert-ip Indicates if certificate matching should match IP address in the certificate to the
site's IP address
Type: Boolean (true/false)
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1271
add vpn site
Parameter Description
phase2-dh Determine the strength of the key used for the IPsec (Phase 2) key exchange
process. The higher the group number, the stronger and more secure the key is.
remote-site-link- Indicates the method of determining the destination IP address/s of the remote
selection site
Type: Press TAB to see available options
static-nat-ip Indicates an external routable IP address via static NAT used by the remote site
Type: IP address
use-trusted-ca Indicates if a specific trusted CA is used for matching the remote site's certificate
or all configured trusted CAs
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1272
add vpn site
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1273
delete vpn site
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1274
delete vpn site
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1275
delete vpn site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1276
show vpn sites
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1277
vpn site-to-site
vpn site-to-site
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1278
set vpn site-to-site
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1279
set vpn site-to-site
Syntax
Parameters
Parameter Description
manual-source- A manually configured source IP address to be used (if configured to) for VPN
ip-address tunnels
Type: IP address
outgoing- Indicates the method according to which the outgoing interface selection for VPN
interface- traffic is chosen
selection
Options: routing-table, route-based-probing
source-ip- Select whether the source IP address is chosen automatically according to the
address-selection outgoing interface or manually configured
Options: automatically, manually
track The default Logging setting for traffic from remote sites
Options: none, log
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1280
set vpn site-to-site
Parameter Description
tunnel-health- VPN tunnel monitor mechanism, can work with permanent tunnel or with DPD
monitor-mode mode
Options: tunnel-test, dpd
use-dpd- Once checked DPD responder mode will be enabled, otherwise permanent tunnel
responder-mode based on DPD mode will be enabled
Type: Boolean (true/false)
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1281
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1282
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1283
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1284
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1285
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1286
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1287
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1288
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1289
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1290
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1291
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1292
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1293
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1294
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1295
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1296
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1297
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1298
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1299
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1300
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1301
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1302
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1303
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1304
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1305
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1306
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1307
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1308
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1309
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1310
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1311
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1312
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1313
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1314
set vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1315
shows vpn site-to-site
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1316
show vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1317
shows vpn site-to-site
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1318
set vpn site-to-site enc-dom manual
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1319
set vpn site-to-site enc-dom manual
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1320
set vpn site-to-site enc-dom manual
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1321
set vpn site-to-site enc-dom manual
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1322
vpn tunnel
vpn tunnel
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1323
show vpn tunnel
Syntax
show vpn-tunnel-info
Parameters
Parameter Description
n/a
Example
show vpn-tunnel-info
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1324
show vpn tunnels
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1325
wlan
wlan
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1326
delete wlan
delete wlan
Description
Delete an existing wireless Virtual Access Point (VAP) by SSID.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1327
set wlan
set wlan
Configures a virtual access point (VAP) wireless network in appliance models that contain wireless
options).
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1328
set wlan
set wlan
Description
Turn on/off the first wireless network (VAP) that was created.
Syntax
Parameters
Parameter Description
Example
set wlan on
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1329
set wlan
set wlan
Description
Configures the SSID of the first wireless network that was created.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1330
set wlan
set wlan
Description
Configures the first wireless network that was created.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1331
set wlan
set wlan
Description
Configures the first wireless network that was created.
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1332
set wlan
set wlan
Description
Configures the first wireless network that was created.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1333
set wlan
set wlan
Description
Configures the first wireless network that was created.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1334
set wlan
set wlan
Description
Configures the first wireless network that was created.
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1335
set wlan
set wlan
Description
Enable/Disable an existing wireless network (VAP).
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1336
set wlan
set wlan
Description
Configures the SSID of an existing wireless network (VAP).
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1337
set wlan
set wlan
Description
Configures an existing wireless network (VAP).
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1338
set wlan
set wlan
Description
Configures an existing wireless network (VAP).
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1339
set wlan
set wlan
Description
Configures an existing wireless network (VAP).
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1340
set wlan
set wlan
Description
Configures an existing wireless network (VAP).
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1341
set wlan
set wlan
Description
Configures an existing wireless network (VAP).
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1342
set wlan
set wlan
Description
Configures an existing wireless network (VAP).
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1343
set wlan wireless advanced-settings protected-mgmt-frames
Syntax
Parameters
Parameter Description
on/off on - Enabled
off - Disabled
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1344
show wlan
show wlan
Shows configuration for wireless networks (relevant to hardware models with wireless).
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1345
show wlan
show wlan
Description
Shows configuration for a virtual access point (VAP or wireless network).
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1346
show wlan
show wlan
Description
Shows configuration of the wireless radio.
Syntax
text
show wlan
Parameters
Parameter Description
n/a
Example
show wlan
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1347
wlan radio
wlan radio
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1348
set wlan radio
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1349
set wlan radio
Syntax
Parameters
Parameter Description
channel Channel
Options: channel
country Country
Options: country
Example
set wlan radio country albania operation-mode 11b channel auto channel-
width auto
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1350
set wlan radio
Syntax
Parameters
Parameter Description
band type
Options: 5GHz, 2.4GHz
channel Channel
Options: channel
country Country
Options: country
Example
set wlan radio band 5GHz country albania operation-mode 11b channel
auto channel-width auto
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1351
set wlan radio
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1352
set wlan radio
Syntax
Parameters
Parameter Description
band type
Options: 5GHz, 2.4GHz
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1353
set wlan radio
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1354
set wlan radio
Syntax
Parameters
Parameter Description
band type
Options: 5GHz, 2.4GHz
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1355
show wlan radio
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1356
show wlan statistics
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1357
wlan vaps
wlan vaps
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1358
add wlan vap
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1359
delete wlan vaps
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1360
set wlan vap wireless advanced-settings protected-mgmt-frames
Syntax
Parameters
Parameter Description
on/off on - Enabled
off - Disabled
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1361
set wlan vap
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1362
show wlan vap wireless
Syntax
Parameters
Parameter Description
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1363
show wlan vaps
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1364
show wlan vaps statistics
Syntax
Parameters
Parameter Description
n/a
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1365
zero-touch
zero-touch
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1366
set zero-touch
set zero-touch
Description
Configure parameters for the ZeroTouch service.
Syntax
Parameters
Parameter Description
mode When the mode is set to on, the appliance will constantly try to fetch configuration from
the Zero Touch server if the First Time Configuration Wizard is not started.
Options: on, off
Default: on
verify- When verify-certificate is set to on, the appliance will verify the SSL certificate of the Zero
certificate Touch server. You are advised NOT to change this value.
Options: on, off
Default: on
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1367
show zero-touch
show zero-touch
Description
Show the parameters configured for the Zero Touch service.
Syntax
show zero-touch
Parameters
Parameter Description
n/a
Example
show zero-touch
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1368
test zero-touch-request
test zero-touch-request
Description
Test the procedure of receiving configuration from the Zero Touch server. If the command is executed
without parameters, the gateway will connect to the Zero Touch server and display the received
configuration without enforcing it. There is an option to store the configuration in the /storage/zt_
cfg.clish file.
Syntax
Parameters
Example
SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide | 1369