The Dropped counter in the software section states the number of packets discarded as the result of
structural integrity tests or rule set drops. The IP Input Errs counter in the software section specifies
the number of packets discarded due to checksum errors or IP headers broken beyond recognition.
The latter is most likely the result of local network problems rather than remote attacks.
Ikesnoop
Ikesnoop is used to diagnose problems with IPsec tunnels.
Syntax: ikesnoop
Display current ikesnoop status.
Syntax: ikesnoop -off
Turn IKE snooping off.
Syntax: ikesnoop -on [ipaddr]
Turn IKE snooping on, if an IP is specified then only IKE traffic from that IP will be shown.
Syntax: ikesnoop -verbose [ipaddr]
Enable verbose output, if an IP is specified then only IKE traffic from that IP will be shown.
IPsecstats
Display connected IPsec VPN gateways and remote clients.
Syntax: ipsecstats <options>
Options:
-u - Append SA usage.
-num <connection-number> - Show this connection number.
Example:
DFL-160:/> ipsecstats
--- IPsec SAs:
Displaying one line per SA-bundle
VPN Tunnel Local net
Remote net
Remote GW
---------- ---------------
-------------
--------------
vpn-home
192.168.123.0/24 192.168.1.2/32 192.168.1.2/32
IPsectunnels
Display configured IPsec VPN connections.
Syntax: ipsectunnels
Example:
DFL-160:/> ipsectunnel
No Name
Local Net
Remote Net
Remote GW
-- ---------
----------------
------------
-----------
1
vpn-home
192.168.123.0/24
0.0.0.0
0.0.0.0/0
Ikesnoop
Appendix A. CLI Reference
113
Содержание NetDefend SOHO DFL-160
Страница 11: ...1 3 The LED Indicators Chapter 1 Product Overview 11...
Страница 22: ...2 4 Console Port Connection Chapter 2 Initial Setup 22...
Страница 39: ...3 7 Dynamic DNS Settings Chapter 3 The System Menu 39...
Страница 76: ...4 10 Schedules Chapter 4 The Firewall Menu 76...
Страница 78: ...5 1 Ping Chapter 5 The Tools Menu 78...
Страница 93: ...6 11 DHCP Server Status Chapter 6 The Status Menu 93...
Страница 102: ...7 6 Technical Support Chapter 7 The Maintenance Menu 102...