
Configuration Verifiers
Check Point Maestro R80.20SP Administration Guide | 209
Verifying VSX Gateway Configuration (asg vsx_verify)
Description
The
asg vsx_verify
command replaces the old verifier in the
smo verifiers
command and runs
on a VSX system only.
Use this command to confirm that all Security Appliances have the same VSX configuration - Interfaces,
Routes, and Virtual Systems.
n
The same MD5 of configuration files that must be identical between Security Appliances.
n
Similarity in configuration files that must be identical, but not necessarily written that way (like
/config/active
).
The command uses the
db_cleanup
report to do this.
n
The same VSX configuration on Security Appliances.
n
Similarity of VMAC and BMAC addresses.
Use output when there is an inconsistency in the configuration.
The differences are compared in two ways:
n
The return value of the command run on the Security Appliances with
gexec_inner_command
n
The output of the commands
Example of a difference in the command output:
Difference between blade: 1_01 and blade: 2_01 found.
====================================================
--- 1_01
+++ 2_01
-73b4c20e598d6b495de7515ad4ea2fdc
/opt/CPsuite-R80.20/fw1/conf/fwha_vsx_conf_id.conf
+b21dfa3feab817c3640bbb984346cdf1
/opt/CPsuite-R80.20/fw1/conf/fwha_vsx_conf_id.conf
When a command fails, the output contains:
Command "asg xxx" failed to run on blade "2_01"
Syntax
> asg vsx_verify [{-a | -c | -v}]
Parameters
Parameter
Description
-a
Includes Security Appliances in the Administrative DOWN state
-c
Compares:
n
Database configuration between Security Appliances
n
Operating system and database configuration on each Security
Appliance