Cisco Systems 6500 manual 112

Page 138

Chapter 2 Commands for the Catalyst 6500 Series SSL Services Module

standby timers

The standby timers command configures the time between standby hello packets and the time before other routers declare the active or standby router to be down. Routers or access servers on which timer values are not configured can learn timer values from the active or standby router. The timers configured on the active router always override any other timer settings. All routers in a Hot Standby group should use the same timer values. Normally, holdtime is greater than or equal to three times the value of hellotime. The range of values for holdtime force the holdtime to be greater than the hellotime. If the timer values are specified in milliseconds, the holdtime is required to be at least three times the hellotime value and not less than 50 milliseconds.

Some HSRP state flapping can occasionally occur if the holdtime is set to less than 250 milliseconds, and the processor is busy. It is recommended that holdtime values less than 250 milliseconds be used. Setting the process-max-timecommand to a suitable value may also help with flapping.

The value of the standby timer will not be learned through HSRP hellos if it is less than 1 second.

When group number 0 is used, no group number is written to NVRAM, providing backward compatibility.

Examples

This example sets, for group number 1 on Ethernet interface 0, the time between hello packets to 5

 

seconds, and the time after which a router is considered to be down to 15 seconds:

 

interface ethernet 0

 

standby

1

ip

 

standby

1

timers 5 15

This example sets, for the hot router interface that is located at 172.19.10.1 on Ethernet interface 0, the time between hello packets to 300 milliseconds, and the time after which a router is considered to be down to 900 milliseconds:

interface ethernet 0 standby ip 172.19.10.1

standby timers msec 300 msec 900

This example sets, for the hot router interface that is located at 172.18.10.1 on Ethernet interface 0, the time between hello packets to 15 milliseconds, and the time after which a router is considered to be down to 50 milliseconds. Note that the holdtime is three times larger than the hellotime because the minimum holdtime value in milliseconds is 50.

interface ethernet 0 standby ip 172.18.10.1 standby timers msec 15 msec 50

 

Catalyst 6500 Series Switch SSL Services Module Command Reference

2-112

OL-9105-01

Image 138
Contents Corporate Headquarters Text Part Number OL-9105-01Page N T E N T S IiiNatpool Acronyms A-1 OL-9105-01 Related Documentation AudienceOrganization Chapter Title DescriptionBoldface font ConventionsConvention Description Example, interface interface typeObtaining Documentation Cisco.comDocumentation Feedback Cisco Product Security OverviewReporting Security Problems in Cisco Products Obtaining Technical AssistanceSubmitting a Service Request XiiObtaining Additional Publications and Information XiiiXiv Getting Help This chapter includes the following sectionsHow to Find Command Options Command Comment After you enter the mode keyword Must enter next on the command lineMode keyword Complete the command. If additionalConfigure terminal privileged Exec Understanding Command ModesCommand Mode Access Method Prompt Exit Method Configure terminalImage using the boot system flash filename Using the No and Default Forms of CommandsInterface command With an interfaceUsing the CLI String Search Character Special MeaningAbcdABCD \$ \ \+Aeiou DA-DBa?b Telebit 3107 v32bisCharacter This string matches any number of asterisksAbcd Za-z0-9+Codex telebit $\.121300$ 1300space space1300 1300, ,1300, 1300 ,1300 For example1300 WithOL-9105-01 A P T E R Clear ssl-proxy conn DefaultsCommand Modes Command History Release ModificationClear ssl-proxy content Defaults Command Modes Command HistoryClear ssl-proxy session Usage GuidelinesClear ssl-proxy stats Ssl-proxy#clear ssl-proxy stats Des Crypto pki export pemTerminal 3desRelated Commands Crypto pki import pemExportable Defaults Command HistoryCrypto pki import pem Usage-keysCrypto pki export pem Crypto pki export pkcs12 This example shows how to export a PKCS12 file using SCP Crypto pki import pkcs12 This example shows how to import a PKCS12 file using SCP Filename TP2? /users/admin-1/pkcs12/TP2.p12Crypto Passphrase passphrase Crypto key decrypt rsaName key-name Crypto key encrypt rsaCrypto key encrypt rsa Crypto key decrypt rsaCrypto key lock rsa Crypto key export rsa pem Keylabel Name of the keyOptional Specifies that the key can be exported Key nametest-keys UsageGeneral Purpose Key Null-Imports from the null file system Crypto key import rsa pemInstead of one general-purpose key pair System-Imports from the system file systemPEM-formatted RSA key to the SSL Services Module Name key-name Optional Name of the key Crypto key lock rsaCrypto key lock rsa name key-namepassphrase passphrase Passphrase passphraseCrypto key unlock rsa Crypto key unlock rsa name key-namepassphrase passphraseDebug ssl-proxy Command History Release Modification This example shows how to turn on App debugging Do command Command EXEC-level command to be executedConfiguration mode Syntax Description Defaults Command Modes Command History Interface ssl-proxySyntax Description Standby timers Standby authenticationStandby delay minimum reload Standby ipSsl-proxy config# interface ssl-proxy Ssl-proxyconfig-subif#ip address 208.59.100.18Natpool Context subcommand modeThis example shows how to define a pool of IP addresses Natpool nat-pool-name startipaddr endipaddr netmask netmaskInterval seconds Syntax Description Defaults Command ModesPolicy health-probe tcp Failed-interval secondsSsl-proxyconfig-context#policy health-probe tcp probe1 Open-timeout secondsSsl-proxyconfig#ssl-proxy context ssl Running on server IP addressPage Alias Policy http-headerClient-cert pem Policy that is applied to the payloadField To Insert Description Client-cert pem Inserts the custom-stringheader into the Http header Client-ip-portCustom custom-string PrefixRelated Commands show ssl-proxy policy SSL-OFFLOAD-SOFTWARE VERSION3.11Timeout session timeout absolute Close-protocol is disabledSession-caching is enabled Policy sslSSL-Policy Configuration Submode Command Descriptions Help Renegotiation volume sizeTimeout handshake timeout Renegotiation interval timeOL-9105-01 This example shows how to enable a session cache This example shows how to disable a session cacheOL-9105-01 Policy tcp No timeout fin-wait timeout-in-seconds Delayed-ack-threshold delayDelayed-ack-timeout timer No timeout inactivity timeout-in-secondsNo tos carryover No timeout reassembly timeForm of this command to return to the default setting Server to client connection, the server connection must beSsl-proxy config-ctx-tcp-policy# mss Policy url-rewrite Ssl-proxyconfig-context#ssl-proxy policy url-rewrite test1 RedirectonlyPool ca Pool ca ca-pool-nameCa-pool-name Certificate authority pool name Service Inservice Authenticate verify all signature-onlyDefault certificate inservice nat server Certificate rsa general-purpose trustpointVirtual policy ssl ssl-policy-name Virtual policy tcpVlan vlan Related Commands show ssl-proxy service Service client Policy health-probe tcp Policy http-headerVirtual policy tcp Nat server client natpool-nameVirtual policy ssl ssl-policy-name Vlan vlanSsl-proxy config-ctx-ssl-proxy# server policy tcp tcppl1 Policy tcp Show interfaces ssl-proxyShow interfaces ssl-proxy 0.subinterface Show ionterfacesShow ssl-proxy buffers This command has no default settingsShow ssl-proxy buffers Ssl-proxy#show ssl-proxy buffersSpecific proxy service Show ssl-proxy certificate-history service nameService name Show ssl-proxy certificate-historySsl-proxy# show ssl-proxy certificate-history Record 1, Timestamp000051, 163634 UTC Oct 31Related Commands service Local Show ssl-proxy conn4tuple RemoteContext name Module module Ssl-proxy#show ssl-proxy conn200.200.1438814 58796 Show ssl-proxy context name Context DefaultShow ssl-proxy context Name Optional Name of the contextBrief Show ssl-proxy crash-infoShow ssl-proxy crash-info brief details DetailsStack top Printing 1024 bytes from stack top Ssl-proxy#show ssl-proxy crash-info briefShow ssl-proxy mac address Show ssl-proxy mac addressSsl-proxy#show ssl-proxy mac address Context name Show ssl-proxy natpoolShow ssl-proxy natpool namecontext name NatpoolHttp-header Show ssl-proxy policyHealth-probe tcp Url-rewriteSsl-proxy#show ssl-proxy policy ssl ssl-policy1 Ssl-proxy#show ssl-proxy policy tcp tcp-policy1Ssl-proxy#show ssl-proxy policy health-probe tcp tcp-health Ssl-proxy#show ssl-proxy service Show ssl-proxy serviceShow ssl-proxy service namecontext name Ssl-proxy#show ssl-proxy service S6Service client Content Show ssl-proxy statsShow ssl-proxy stats type Stats This example shows how to display the TCP statistics This example shows how to display the PKI statisticsThis example shows how to display context statistics Ssl-proxy#show ssl-proxy stats context Context name DefaultSsl-proxy# show ssl-proxy stats hdr This example shows how to display content statistics Ssl-proxy#show ssl-proxy stats contentShow ssl-proxy status Show ssl-proxy status fdu ssl tcpShow ssl-proxy status TCP cpu is alive Show ssl-proxy version Show ssl-proxy versionSsl-proxy#show ssl-proxy version Debug Show ssl-proxy vlanShow ssl-proxy vlan vlan-iddebugmodule module Optional Displays debug informationSnmp-server enable Defaults Command Modes Command History ExamplesSsl-proxy context name No ssl-proxy context name Command Purpose and Guidelines DefaultsSsl-proxy context Description descriptionPolicy url-rewrite policy-name Policy ssl policy-namePolicy tcp policy-name Pool ca nameSsl-proxy crypto selftest Seconds Global configurationThis example shows how to start a cryptographic self-test Time-intervalSsl-proxy config# ssl-proxy mac address 00e0.b0ff.f232 This example shows how to configure a MAC addressRelated Commands show ssl-proxy mac address Ssl-proxy mac addressSsl-proxy pki This example shows how to specify the cache size This example shows how to enable PKI event-historyRelated Commands show ssl-proxy stats Ssl-proxy crypto key unlock rsa Key-name Name of the key Passphrase Pass phraseSsl-proxy ip-frag-ttl Time is 6 seconds Global configurationSsl-proxyconfig#ssl-proxy ip-frag-ttl Ssl-proxy ip-frag-ttl timeSsl-proxy ssl ratelimit Ssl-proxy config# ssl-proxy ssl ratelimitSsl-proxy config# no ssl-proxy ssl ratelimit Ssl-proxy ssl ratelimit No ssl-proxy ssl ratelimitStandby authentication Group-number is String is ciscoStandby delay minimum reload Min-delay is 1 second Reload-delay is 5 secondsShow standby delay Ssl-proxyconfig#interface ssl-proxySsl-proxyconfig-subif#standby delay minimum 30 reload Secondary Defaults Command Modes Command History Usage GuidelinesStandby ip Group-number isUsed by the hot standby group is learned using Hsrp 100No standby group-numbermac-address Standby mac-addressStandby group-numbermac-addressmac-address Mac-address MAC addressShow standby Ssl-proxyconfig-subif#standby 1 mac-addressThat is used in the end nodes 102Standby mac-refresh Standby mac-refresh seconds no standby mac-refresh103 Standby name group-name No standby name group-name Hsrp is disabledStandby name Group-name Name of the standby groupStandby preempt 105Clients Operation returns to the default behaviorLeaves any synchronization delay if it was configured To become the active routerNo standby group-numberpriority priority Standby priorityStandby group-numberpriority priority Group-number is Priority isThis example shows how to change the router priority 108Standby redirects 109Show standby redirect Related Commands show standbySsl-proxyconfig-subif#standby redirects timers 90 110Optional Specifies the interval in milliseconds Standby timersMsec 111112 Or comes back up Standby trackDecrement priority 113Related Commands standby preempt Router a ConfigurationRouter B Configuration 114Scope interface Standby use-biaStandby use-bia scope interface no standby use-bia On which it was entered, instead of the major interfaceStandby version 1 This example shows how to configure Hsrp versionStandby version Specifies Hsrp versionAcronym Expansion CDP CbacCCA CEFDscp DramDsap DspuIDB ICDIcmp IDPMdss MD5Mdix MFDOspf OSIOSM PAERommon RmonROM RPCSVI STPSVC TACACS+XNS Weighted round-robinWRR Xerox Network SystemOL-9105-01 Acknowledgments for Open-Source Software OL-9105-01 $ character # character privileged Exec mode promptAsterisk + plus sign Period ? command Caret IN-1IN-2 IN-3 IN-4 TCP IN-5Configuration submode User Exec mode, summary IN-6
Related manuals
Manual 20 pages 62.17 Kb Manual 112 pages 18.84 Kb Manual 262 pages 31.67 Kb