Corporate Headquarters
Catalyst 6500 Series Switch SSL Services Module Command Reference
Release
Cisco Systems, Inc 170 West Tasman Drive San Jose, CA
THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL STATEMENTS, INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL ARE BELIEVED TO BE ACCURATE BUT ARE PRESENTED WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. USERS MUST TAKE FULL RESPONSIBILITY FOR THEIR APPLICATION OF ANY PRODUCTS
How to Find Command Options
Definitions of Service Request Severity
Command-Line Interface
C O N T E N T S
Commands for the Catalyst 6500 Series Switch SSL Services Module
service
service client
natpool
snmp-server enable
ssl-proxy pki
Acronyms A-1
show ssl-proxy vlan
OL-9105-01
Contents
Catalyst 6500 Series Switch SSL Services Module Command Reference
Command-Line Interface
Commands for the Catalyst
Series Switch SSL Services
Preface
Conventions
Convention
boldface font
example, interface interface type
Product Documentation DVD
Obtaining Documentation
Cisco.com
Ordering Documentation
Documentation Feedback
Cisco Product Security Overview
Reporting Security Problems in Cisco Products
Obtaining Technical Assistance
Cisco Technical Support & Documentation Website
Emergencies - security-alert@cisco.com
Submitting a Service Request
Definitions of Service Request Severity
Obtaining Additional Publications and Information
xiii
OL-9105-01
Catalyst 6500 Series Switch SSL Services Module Command Reference
Preface Obtaining Additional Publications and Information
Command-Line Interface
Getting Help, page How to Find Command Options, page
Understanding Command Modes, page
Using the No and Default Forms of Commands, page
Purpose
How to Find Command Options
Command
Table 1-2 How to Find Command Options
Command
Comment
Command
Table 1-2 How to Find Command Options continued
ssl-proxyconfig-if# channel-group 1 mode auto ?
ssl-proxyconfig-if# channel-group 1 mode auto
Understanding Command Modes
Access Method
configure terminal privileged EXEC
configure terminal
Using the No and Default Forms of Commands
interface command
image using the boot system flash filename
with an interface
Using the CLI String Search
Regular Expressions
Single-Character Patterns
Character
\$ \ \+
aeiou
abcdABCD
a-dA-D
Multiple-Character Patterns
Multipliers
telebit 3107 v32bis
ba?b
Alternation
Anchoring
A-Za-z0-9+
codex telebit
Parentheses for Recall
1300
1300$ 1300space space1300 1300, ,1300, 1300 ,1300
a.bc.\1\2
1-12
Chapter 1 Command-Line Interface Using the CLI String Search
Catalyst 6500 Series Switch SSL Services Module Command Reference
OL-9105-01
Commands for the Catalyst 6500 Series Switch SSL Services Module
C H A P T E R
service name
Defaults
Command Modes Command History
clear ssl-proxy conn
clear ssl-proxy content
clear ssl-proxy content all rewrite scanning module module
Defaults Command Modes Command History
This example shows how to clear all of the content statistics
clear ssl-proxy session
Usage Guidelines
service name
Defaults
service name
Command Modes
clear ssl-proxy stats
ssl tcp url
Command History Usage Guidelines Examples
Release
Modification
context name
Defaults
crypto pki export pem
Command Modes Command History
Release
Examples
crypto pki import pem
Defaults Command History Command History
crypto pki import pem
Syntax Description
Release
2-10
151129.901 %SYS-5-CONFIGI Configured from console by console
Examples
crypto pki export pem
crypto pki export pkcs12
2-11
Defaults Command Modes Command History
Release
2-12
Chapter 2 Commands for the Catalyst 6500 Series SSL Services Module
Catalyst 6500 Series Switch SSL Services Module Command Reference
ssl-proxyconfig# crypto pki export TP1 pkcs12 scp sky is blue
crypto pki import pkcs12
2-13
Defaults
Command Modes Command History
2-14
Chapter 2 Commands for the Catalyst 6500 Series SSL Services Module
filename TP2? /users/admin-1/pkcs12/TP2.p12
Catalyst 6500 Series Switch SSL Services Module Command Reference
crypto key decrypt rsa
crypto key decrypt write rsa name key-name passphrase passphrase
passphrase passphrase
2-15
crypto key encrypt rsa
crypto key encrypt write rsa name key-name passphrase passphrase
2-16
Defaults
crypto key export rsa pem
2-17
Defaults Command Modes Command History
Syntax Description
This example shows how to export a key from the SSL Services Module
2-18
Chapter 2 Commands for the Catalyst 6500 Series SSL Services Module
Catalyst 6500 Series Switch SSL Services Module Command Reference
crypto key import rsa pem
2-19
Defaults Command Modes Command History
Syntax Description
2-20
Chapter 2 Commands for the Catalyst 6500 Series SSL Services Module
ssl-proxyconfig# crypto key import rsa newkeys pem url scp password
Catalyst 6500 Series Switch SSL Services Module Command Reference
crypto key lock rsa
crypto key lock rsa name key-name passphrase passphrase
2-21
Defaults Command Modes Command History
crypto key unlock rsa
crypto key unlock rsa name key-name passphrase passphrase
2-22
Defaults Command Modes Command History
content type
debug ssl-proxy
pki type ssl type tcp type vlan
fdu type
Command History
2-24
content type
Release
Examples
This example shows how to turn on App debugging
2-25
Command Modes
Release
Modification
Usage Guidelines
Syntax Description Defaults Command Modes Command History
default
interface ssl-proxy
Syntax
standby group-number authentication
text string delay minimum min-delay
group-name preempt delayminimum
priority priority redirects enable
Examples
2-29
Related Commands show interfaces ssl-proxy show ssl-proxy vlan
natpool
show ssl-proxy natpool
2-30
Defaults
Syntax Description Defaults Command Modes
policy health-probe tcp
policy health-probe tcp policy-name
failed-interval is 60 seconds
2-32
open-timeout seconds
Syntax
Description
2-33
Related Commands show ssl-proxy policy show ssl-proxy service
policy http-header
client-cert pem
alias
Field To Insert
2-35
Field To Insert
Description
ClientCert-Subject-CN
Field to insert
2-36
Description
Syntax
client-ip-port
prefix
session
2-37
2-38
Related Commands show ssl-proxy policy
timeout session timeout absolute
policy ssl
2-39
Defaults
SSL Services Module
This command was changed to add the following subcommands
The policy ssl command entered in context subcommand mode replaces
the ssl-proxy policy ssl command entered in global subcommand mode
renegotiation volume size
timeout handshake timeout
help
renegotiation interval time
2-42
all-export-All export ciphers all-strong-All strong ciphers default
Examples
2-43
This example shows how to enter the SSL-policy configuration submode
2-44
Chapter 2 Commands for the Catalyst 6500 Series SSL Services Module
Catalyst 6500 Series Switch SSL Services Module Command Reference
policy ssl
policy tcp
2-45
Defaults
Command Modes
delayed-ack-threshold delay
delayed-ack-timeout timer
no timeout fin-wait timeout-in-seconds
no timeout inactivity timeout-in-seconds
no timeout reassembly time
no tos carryover
2-47
Syntax
2-48
This example shows how to define the maximum size for the TCP segment
policy url-rewrite
2-49
Defaults
Command Modes
Examples
2-50
Enter the no form of the command to remove the policy
pool ca
2-51
Defaults Command Modes Command History
default
service
service client command
2-52
Defaults
authenticate verify all signature-only
default certificate inservice nat server
inservice
certificate rsa general-purpose trustpoint
2-54
Syntax
Description
virtual policy ssl ssl-policy-name
2-55
Related Commands show ssl-proxy service
service client
policy health-probe tcp policy http-header
2-56
Syntax Description Defaults Command Modes
nat server client natpool-name
virtual policy ssl ssl-policy-name
virtual policy tcp
vlan vlan
Examples
2-58
Related Commands show ssl-proxy service
show interfaces ssl-proxy
show interfaces ssl-proxy 0.subinterface
2-59
Defaults
This command has no default settings
show ssl-proxy buffers
show ssl-proxy buffers
2-60
show ssl-proxy certificate-history service name
show ssl-proxy certificate-history
2-61
Defaults Command Modes Command History
2-62
Chapter 2 Commands for the Catalyst 6500 Series SSL Services Module
Catalyst 6500 Series Switch SSL Services Module Command Reference
Examples
Related Commands service
2-63
Chapter 2 Commands for the Catalyst 6500 Series SSL Services Module
Catalyst 6500 Series Switch SSL Services Module Command Reference
show ssl-proxy conn service name context name module module
show ssl-proxy conn
show ssl-proxy conn module module
4tuple
2-65
Release
Modification
context name
2-66
Chapter 2 Commands for the Catalyst 6500 Series SSL Services Module
Catalyst 6500 Series Switch SSL Services Module Command Reference
ssl-proxy# show ssl-proxy conn service iis1
show ssl-proxy context
show ssl-proxy context name
2-67
Defaults
show ssl-proxy crash-info
show ssl-proxy crash-info brief details
brief
details
2-69
Chapter 2 Commands for the Catalyst 6500 Series SSL Services Module
Catalyst 6500 Series Switch SSL Services Module Command Reference
show ssl-proxy crash-info
show ssl-proxy mac address
show ssl-proxy mac address
2-70
Syntax Description Defaults Command Modes Command History
show ssl-proxy natpool
show ssl-proxy natpool namecontext name
2-71
Defaults Command Modes Command History
show ssl-proxy policy
url-rewrite name
health-probe tcp
http-header
2-73
Reassembly timeout
Disabled
Delayed ACK timer
ssl-proxy# show ssl-proxy policy health-probe tcp tcp-health
2-74
policy tcp policy url-rewrite
show ssl-proxy service
show ssl-proxy service namecontext name
2-75
Defaults Command Modes Command History
2-76
Related Commands service
Chapter 2 Commands for the Catalyst 6500 Series SSL Services Module
show ssl-proxy service
content
show ssl-proxy stats
show ssl-proxy stats type
2-77
2-78
Chapter 2 Commands for the Catalyst 6500 Series SSL Services Module
Catalyst 6500 Series Switch SSL Services Module Command Reference
Examples
2-79
Chapter 2 Commands for the Catalyst 6500 Series SSL Services Module
show ssl-proxy stats
ssl-proxy# show ssl-proxy stats pki PKI Memory Usage Counters
2-80
Chapter 2 Commands for the Catalyst 6500 Series SSL Services Module
ssl-proxy# show ssl-proxy stats context Context name Default
Catalyst 6500 Series Switch SSL Services Module Command Reference
2-81
Chapter 2 Commands for the Catalyst 6500 Series SSL Services Module
ssl-proxy# show ssl-proxy stats content
Catalyst 6500 Series Switch SSL Services Module Command Reference
show ssl-proxy status
show ssl-proxy status fdu ssl tcp
Syntax Description
Optional Displays the FDU status
2-83
Chapter 2 Commands for the Catalyst 6500 Series SSL Services Module
Catalyst 6500 Series Switch SSL Services Module Command Reference
show ssl-proxy status
show ssl-proxy version
show ssl-proxy version
2-84
Syntax Description Defaults Command Modes Command History
Related Commands
show ssl-proxy vlan
show ssl-proxy vlan vlan-iddebugmodule module
2-85
snmp-server enable
Defaults Command Modes Command History Examples
informs
traps
ssl-proxy context
ssl-proxy context name no ssl-proxy context name
Purpose and Guidelines
description description
Purpose and Guidelines
2-88
Command
Defaults
ssl-proxy crypto selftest
ssl-proxy crypto selftest time-interval seconds
no ssl-proxy crypto selftest
time-interval
This example shows how to configure a MAC address
ssl-proxy mac address
ssl-proxy mac address mac-addr
2-90
no ssl-proxy pki authenticate cache certificate history
authenticate
timeout seconds
timeout minutes
Examples
2-92
Related Commands show ssl-proxy stats
ssl-proxy crypto key unlock rsa
ssl-proxy crypto key unlock rsa key-name passphrase passphrase
2-93
Defaults Command Modes Command History
ssl-proxy ip-frag-ttl
ssl-proxy ip-frag-ttl time
2-94
Syntax Description Defaults Command Modes
ssl-proxy ssl ratelimit
ssl-proxy ssl ratelimit no ssl-proxy ssl ratelimit
2-95
Defaults
standby authentication
standby group-number authentication text string
no standby group-number authentication text string
2-96
standby delay minimum reload
standby delay minimum min-delay reload reload-delay
no standby delay minimum min-delay reload reload-delay
2-97
show standby delay
2-98
Related Commands
Chapter 2 Commands for the Catalyst 6500 Series SSL Services Module
Defaults Command Modes Command History Usage Guidelines
standby ip
2-99
Syntax Description
Examples
2-100
used by the hot standby group is learned using HSRP
standby mac-address
no standby group-number mac-address
APPN
2-101
Examples
show standby
2-102
standby mac-refresh
standby mac-refresh seconds no standby mac-refresh
2-103
Defaults Command Modes Command History
This example shows how to specifiy the standby name as SanJoseHA
standby name
standby name group-name no standby name group-name
2-104
standby preempt
2-105
Defaults
Command Modes Command History
Examples
2-106
ssl-proxy config-subif# standby preempt delay minimum
standby priority
no standby group-number priority priority
2-107
Defaults Command Modes Command History
2-108
Related Commands
Chapter 2 Commands for the Catalyst 6500 Series SSL Services Module
Catalyst 6500 Series Switch SSL Services Module Command Reference
enable
disable
timers
standby redirects
This example shows how to allow HSRP to filter ICMP redirect messages
Related Commands show standby
show standby redirect
2-110
standby timers
2-111
Defaults
Command Modes Command History
2-112
timers 5
standby timers msec 300 msec
Examples
standby track
2-113
Defaults Command Modes Command History
Syntax Description
Router A Configuration
Router B Configuration
Related Commands standby preempt
2-114
standby use-bia
standby use-bia scope interface no standby use-bia
scope interface
2-115
This example shows how to configure HSRP version
standby version
standby version 1
Specifies HSRP version
Acronyms
A P P E N D I X A
Acronym
Expansion
Table A-1 List of Acronyms continued
Acronym
Expansion
Acronym
Expansion
Acronym
Expansion
Acronym
Expansion
Acronym
Expansion
Acronym
Expansion
Acronym
Expansion
Catalyst 6500 Series Switch SSL Services Module Command Reference
Acronym
Expansion
Table A-1 List of Acronyms continued
A-10
Catalyst 6500 Series Switch SSL Services Module Command Reference
Appendix A Acronyms
OL-9105-01
Acknowledgments for Open-Source Software
A P P E N D I X B
OL-9105-01
Catalyst 6500 Series Switch SSL Services Module Command Reference
Appendix B Acronyms
Symbols
Numerics
I N D E
IN-1
IN-2
secondary interface
IN-3
configuring
IN-4
IN-5
IN-6
Catalyst 6500 Series Switch SSL Services Module Command Reference
Index
OL-9105-01