
Patch 86261-07 For Rapier and AT-8800 Series Switches 7
Patch 86261-07 for Software Release 2.6.1
C613-10388-00 REV G
To enable the display of debugging information relating to ARP requests
that are processed by the firewall, use the command:
ENABLE FIREWALL POLICY=policy-name DEBUG=ARP
To disable the display of debugging information relating to ARP requests
that are processed by the firewall, use the command:
DISABLE FIREWALL POLICY=policy-name DEBUG=ARP
To display the addresses for which the firewall may ARP respond, use the
command:
SHOW FIREWALL ARP [POLICY=policy-name]
Example output for the SHOW FIREWALL ARP command is shown in
Figure 1:
Figure 1: Example output from the SHOW FIREWALL ARP command
IP ARP Interfaces NAT Type Int Gbl Int Rule
(range) Policy
--------------------------------------------------------------------------------
172.20.8.50 Public Int based eth0-0 eth1-0 -
Office
172.20.8.57 All Public Rule eth0-1 - 1
-172.20.8.62 LAN
--------------------------------------------------------------------------------
Table 2: Parameters displayed in the output of the SHOW FIREWALL ARP command
Parameter Meaning
IP (range) An IP address (or range of addresses) for which the device
may need to make an ARP response.
Policy The name of the policy whose NAT configuration the IP
address (range) belongs to.
ARP interfaces The interfaces within the policy that ARP requests for the IP
address (range) are permitted on; one of “Public”, “All
Public”, “Private”, or “All Private”. “Public” means that
ARP requests are permitted on the public interface listed in
the “Gbl Int” field. “Private” means ARP requests are
permitted on the private interface specified by the “Int”
field. “All Public” means ARP requests are permitted on all
of the policy’s public interfaces. “All Private” means ARP
requests are permitted on all of the policy’s private intrfaces.
NAT Type The type of NAT that the IP address (range) is associated
with; one of “Int based” or “Rule”. “Int based” means that
the address (range) was specified by an interface-based NAT
configuration with the ADD FIREWALL POLICY NAT
command. “Rule” means the address (range) was specified
by a NAT rule configured with the ADD FIREWALL POLICY
RULE command with ACTION=NAT specified.
Comentários a estes Manuais