206
helo-holddown
<holddown_integer>
The hello state hold-down time, which is the number of seconds
that a cluster unit waits before changing from hello state to work
state. A cluster unit changes from hello state to work statewhen
it starts up.
The hello state hold-down time range is 5 to 300 seconds.
20
load-balance-all
{disable | enable}
Configure active-active HA to load balance all sessions or to
load balance virus scanning sessions only. Enter enable to load
balance all communication sessions. Enter disable to load
balance only virus scanning sessions.
disable
mode {a-a | a-p |
standalone}
Set the HA mode.
Enter a-p to create an Active-Passive HA cluster, in which the
primary cluster unit isactively processing all connections and
the others are passively monitoring the status and remaining
synchronized with the primary cluster unit.
Enter a-a to create an Active-Active HA cluster, in which each
cluster unit is actively processingconnections and monitoring
the status of the other freeGuard 100s.
All members of an HA cluster must be set to the same HA
mode.
Enter standalone to remove the freeGuard 100 from an HA
cluster.
standalone
monitor {<interface-
1_str> <priority-
1_integer><interface_
2_str> <priority-
2_integer>}
Enable or disable monitoring freeGuard 100 interfacesand
setting monitor priorities. You can enter one or more interface
names followed by a space and a monitor priority. Use a space
to separate each interface name and priority pair. If you want to
remove an interface from the list, add an interface to the list, or
change the monitor priority of an interface you must retype the
list with theoptions changed as required.
You can monitor physical interfaces but not VLAN
subinterfaces. Increase the priority of interfaces connected to
higher priority networks or networks with moretraffic. The
monitor priority range is 0 to 255. If a high priority interface on
the primary cluster unit fails, one of the other units in the cluster
becomes the new primary unit to provide better service to the
high priority network.
If a low priority interface fails on one cluster unit and a high
priority interface fails on another cluster unit, a unit in the cluster
with a working connection to the high priority interface would, if
itbecomes necessary to negotiate a new primary unit, be
selected instead of a unit with a working connection to the low
priority interface.
No default
override {disable |
enable}
Configure the freeGuard 100 to always overridethe current
primary cluster unit and become the primary cluster unit in its
place. Enable OverrideMaster for the cluster unit that you have
given thehighest unit priority. Enabling Override Master means
disable
Summary of Contents for freeGuard 100
Page 1: ...freeGuard 100 UTM Firewall CLI USER S MANUAL P N F0025000 Rev 1 1...
Page 3: ......
Page 7: ......
Page 87: ...80 The config ips anomaly command has 1 subcommand config limit...
Page 183: ...176...