Chapter 5 Configuring Firewall Load Balancing

Displaying Firewall IP Information

Displaying Firewall IP Information

Use the show ip firewall command to display the configured values of the IP firewall keepalive timeout and the state of each firewall path configured on the CSS. For example:

(config)# show ip firewall

Table 5-3describes the fields in the show ip routes output.

Table 5-3 Field Descriptions for the show ip routes firewall Command

Field

Description

 

 

IP Firewall

The number of seconds the CSS will wait to receive a keepalive

KAL Timeout

message from the remote CSS before declaring the firewall

 

unreachable.

 

 

Firewall Index

The index number to identify the firewall.

 

 

State

The current state of the connection to the remote switch (Init,

 

Reachable, or Unreachable).

 

 

Next Hop

The IP address used for the next hop.

 

 

Remote

The IP address of the firewall on the remote subnet that

Firewall

connects to the remote CSS.

 

 

Remote Switch

The IP address of the remote CSS.

 

 

Time Since

The length of time since the last keepalive message was

Last KAL Tx

transmitted.

 

 

Time Since

The length of time since the last keepalive message was

Last KAL Rx

received.

 

 

 

 

Cisco Content Services Switch Security Configuration Guide

 

 

 

 

 

 

OL-5650-02

 

 

5-17

 

 

 

Page 115
Image 115
Cisco Systems OL-5650-02 manual Displaying Firewall IP Information, Config# show ip firewall