dump config security
Table of Contents
Expand all | Collapse all
-
-
- clear app-engine
- clear app-map dynamic
- clear app-probe prefix
- clear connection
- clear device account-login
- clear dhcplease
- clear dhcprelay stat
- clear flow and clear flows
- clear flow-arp
- clear qos-bwc queue-snapshot
- clear routing
- clear routing multicast statistics
- clear routing ospf
- clear routing peer-ip
- clear switch mac-address-entries
- clear user-id agent statistics
-
- arping interface
- curl
- ping
- ping6
- debug bounce interface
- debug bw-test src-interface
- debug cellular stats
- debug controller reachability
- debug flow
- debug ipfix
- debug log agent eal file log
- debug logging facility
- debug logs dump
- debug logs follow
- debug logs tail
- debug poe interface
- debug process
- debug reboot
- debug routing multicast log
- debug routing multicast pimd
- debug servicelink logging
- debug tcpproxy
- debug time sync
- debug performance-policy
- dig dns
- dig6
- file export
- file remove
- file space available
- file tailf log
- file view log
- ssh6 interface
- ssh interface
- tcpdump
- tcpping
- traceroute
- traceroute6
-
- dump appdef config
- dump appdef version
- dump app-engine
- dump app-l4-prefix table
- dump app-probe config
- dump app-probe flow
- dump app-probe prefix
- dump app-probe status
- dump auth config
- dump auth status
- dump banner config
- dump bfd status
- dump bypass-pair config
- dump cellular config
- dump cellular stats
- dump cellular status
- dump cgnxinfra status
- dump cgnxinfra status live
- dump cgnxinfra status store
- dump config network
- dump config security
- dump controller cipher
- dump controller status
- dump device accessconfig
- dump device conntrack count
- dump device date
- dump device info
- dump device status
- dump dhcp-relay config
- dump dhcprelay stat
- dump dhcp-server config
- dump dhcp-server status
- dump dhcpstat
- dump dnsservice config all
- dump dpdk cpu
- dump dpdk interface
- dump dpdk port status
- dump dpdk stats
- dump flow
- dump flow count-summary
- dump interface config
- dump interface status
- dump interface status interface details
- dump interface status interface module
- dump ipfix config collector-contexts
- dump ipfix config derived-exporters
- dump ipfix config filter-contexts
- dump ipfix config ipfix-overrides
- dump ipfix config prefix-filters
- dump ipfix config profiles
- dump ipfix config templates
- dump lldp
- dump lldp config
- dump lldp info
- dump lldp stats
- dump lldp status
- dump log-agent eal conn
- dump log-agent eal response-time
- dump log-agent eal stats
- dump log-agent config
- dump log-agent iot snmp config
- dump log-agent iot snmp device discovery stats
- dump log-agent ip mac bindings
- dump log-agent neighbor discovery stats
- dump log-agent status
- dump ml7 mctd counters
- dump ml7 mctd session
- dump ml7 mctd version
- dump nat counters
- dump nat summary
- dump network-policy config policy-rules
- dump network-policy config policy-sets
- dump network-policy config policy-stacks
- dump network-policy config prefix-filters
- dump overview
- dump performance-policy config policy-rules
- dump performance-policy config policy-sets
- dump performance-policy config policy-set-stacks
- dump performance-policy config threshold-profile
- dump poe system config
- dump poe system status
- dump priority-policy config policy-rules
- dump priority-policy config policy-sets
- dump priority-policy config policy-stacks
- dump priority-policy config prefix-filters
- dump probe config
- dump probe profile
- dump radius config
- dump radius statistics
- dump radius status
- dump reachability-probe config
- dump qos-bwc config
- dump reachability-probe status
- dump routing aspath-list
- dump routing cache
- dump routing communitylist
- dump routing multicast config
- dump routing multicast igmp
- dump routing multicast interface
- dump routing multicast internal vif-entries
- dump routing multicast mroute
- dump routing multicast pim
- dump routing multicast sources
- dump routing multicast statistics
- dump routing multicast status
- dump routing ospf
- dump routing peer advertised routes
- dump routing peer config
- dump routing peer neighbor
- dump routing peer received-routes
- dump routing peer routes
- dump routing peer route-via
- dump routing peer status
- dump routing peer route-json
- dump routing prefixlist
- dump routing prefix-reachability
- dump routing route
- dump routing routemap
- dump routing running-config
- dump routing summary
- dump routing static-route reachability-status
- dump routing static-route config
- dump security-policy config policy-rules
- dump security-policy config policy-set
- dump security-policy config policy-set-stack
- dump security-policy config prefix-filters
- dump security-policy config zones
- dump sensor type
- dump sensor type summary
- dump serviceendpoints
- dump servicelink summary
- dump servicelink stats
- dump servicelink status
- dump site config
- dump snmpagent config
- dump snmpagent status
- dump software status
- dump spoke-ha config
- dump spoke-ha status
- dump standingalarms
- dump static-arp config
- dump static host config
- dump static routes
- dump support details
- dump-support
- dump switch fdb vlan-id
- dump switch port status
- dump switch vlan-db
- dump syslog config
- dump syslog-rtr stats
- dump syslog status
- dump time config
- dump time log
- dump time status
- dump troubleshoot message
- dump user-id agent config
- dump user-id agent statistics
- dump user-id agent status
- dump user-id agent summary
- dump user-id groupidx
- dump user-id group-mapping
- dump user-id ip-user-mapping
- dump user-id statistics
- dump user-id status
- dump user-id summary
- dump user-id useridx
- dump vlan member
- dump vpn count
- dump vpn ka all
- dump vpn ka summary
- dump vpn ka VpnID
- dump vpn status
- dump vpn summary
- dump vrf
- dump waninterface config
- dump waninterface summary
-
- inspect app-flow-table
- inspect app-l4-prefix lookup
- inspect app-map
- inspect certificate
- inspect certificate device
- inspect cgnxinfra role
- inspect connection
- inspect dhcplease
- inspect dhcp6lease
- inspect dpdk ip-rules
- inspect dpdk vrf
- inspect fib
- inspect fib-leak
- inspect flow-arp
- inspect flow brief
- inspect flow-detail
- inspect flow internal
- inspect interface stats
- inspect ipfix exporter-stats
- inspect ipfix collector-stats
- inspect ipfix app-table
- inspect ipfix wan-path-info
- inspect ipfix interface-info
- inspect ip-rules
- inspect ipv6-rules
- inspect lqm stats
- inspect memory summary
- inspect network-policy conflicts
- inspect network-policy dropped
- inspect network-policy hits policy-rules
- inspect network-policy lookup
- inspect performance-policy fec status
- inspect policy-manager status
- inspect policy-mix lookup-flow
- inspect priority-policy conflicts
- inspect priority-policy dropped
- inspect priority-policy hits default-rule-dscp
- inspect priority-policy hits policy-rules
- inspect priority-policy lookup
- inspect performance-policy incidents
- inspect performance-policy lookup
- inspect performance-policy hits analytics
- inspect process status
- inspect qos-bwc debug-state
- inspect qos-bwc queue-history
- inspect qos-bwc queue-snapshot
- inspect routing multicast fc site-iface
- inspect routing multicast interface
- inspect routing multicast mroute
- inspect security-policy lookup
- inspect security-policy size
- inspect switch mac-address-table
- inspect system arp
- inspect system ipv6-neighbor
- inspect system vrf
- inspect vrf
- inspect wanpaths
-
dump config security
Use the dump config security command
to display the security configuration available on a device. Information
displayed includes configuration for security policy stack, security
policy sets, security policy zones, prefix filters, and security
policy rules.
Command
dump config security
Options
None |
Command Notes
Role | Super, Read Only, Monitor |
Related Commands |
|
Introduced in | Release 4.7.1 |
Example
dump config security SECURITY POLICY STACKS --------------------------------------------------- Security Policy Stack ID : 16242998621490011 Security Policy Stack Name : Stack1 Default Policy Set ID : 16228336609730048 Default Policy Set Name : default Policy Set Order: 16245957623450255 : Set2-Port-Range 16245009722000198 : Set3-Specific 16245013500920058 : Set4-Generic SECURITY POLICY SETS --------------------------------------------------- Security Policy Set ID : 16245957623450255 Security Policy Set Name: Set2-Port-Range Policy Rule Order: 16246315738930189: Rule1-Set2-20 16246317241460212: Rule2-Set2-21 16246318197250246: Rule3-Set2-22 Security Policy Set ID : 16245009722000198 Security Policy Set Name: Set3-Specific Policy Rule Order: 16245010650670003: Rule1-Set3-20 16245011984140128: Rule2-Set3-21 16245012757060237: Rule3-Set3-22 Security Policy Set ID : 16245013500920058 Security Policy Set Name: Set4-Generic Policy Rule Order: 16245013906270078: Rule1-Set4 Security Policy Set ID : 16228336609730048 Security Policy Set Name: default Policy Rule Order: 16228336610060052: self-zone 16228336610050051: intra-zone 16228336609900050: default SECURITY POLICY ZONES --------------------------------------------------- Security Policy Zone ID : 16204672468290016 Security Policy Zone Name : Zone-Internet-VPN Zone Association ID : 16245135536470064 Interfaces : VPN-overlay LAN Networks : Security Policy Zone ID : 16200471388560063 Security Policy Zone Name : Zone-Internet Zone Association ID : 16285714095880087 Interfaces : 16150115632720220 : 2 LAN Networks : Security Policy Zone ID : 16200471619100074 Security Policy Zone Name : Zone-LAN Zone Association ID : 16245779281070041 Interfaces : LAN Networks : Name : default_san-jose_114105279 ID : 16200275524390210 LAN Prefixes : 192.168.7.1/24 Name : default_san-jose_450021252 ID : 16261268429250112 LAN Prefixes : 192.168.102.1/24 Name : default_san-jose_270864556 ID : 16261251535530088 LAN Prefixes : 192.168.101.1/24 SECURITY POLICY PREFIX FILTERS --------------------------------------------------- Prefix Filter ID : 16242993943320129 Prefix Filter Name : DC-192-168-20-0 Prefix : 192.168.20.0/24 Prefix Filter ID : 16242994662000182 Prefix Filter Name : DC-192-168-22-0 Prefix : 192.168.22.0/24 Prefix Filter ID : 16242994310450145 Prefix Filter Name : DC-192-168-21-0 Prefix : 192.168.21.0/24 Prefix Filter ID : 16242993172060125 Prefix Filter Name : LAN-192-168-7-100 Prefix : 192.168.7.100/32 SECURITY POLICY RULES --------------------------------------------------- Security Policy Rule ID : 16246315738930189 Security Policy Rule Name : Rule1-Set2-20 Action : allow Rule-Type : custom Enabled : true Source Zones : 16200471619100074: Zone-LAN Destination Zones : 16204672468290016: Zone-Internet-VPN Applications : ANY Source Prefix Filters : 16242993172060125: LAN-192-168-7-100 Destination Prefix Filters : 16242993943320129: DC-192-168-20-0 Services : Protocol : 6 Source Port Range : ANY Destination Port Range : from : 5005 to : 5015 from : 5020 to : 5025 Protocol : 17 Source Port Range : ANY Destination Port Range : from : 5005 to : 5015 Protocol : 1 Source Port Range : ANY Destination Port Range : ANY Security Policy Rule ID : 16246317241460212 Security Policy Rule Name : Rule2-Set2-21 Action : deny Rule-Type : custom Enabled : true Source Zones : 16200471619100074: Zone-LAN Destination Zones : 16204672468290016: Zone-Internet-VPN Applications : ANY Source Prefix Filters : 16242993172060125: LAN-192-168-7-100 Destination Prefix Filters : 16242994310450145: DC-192-168-21-0 Services : Protocol : 6 Source Port Range : ANY Destination Port Range : from : 6000 to : 6010 Protocol : 17 Source Port Range : ANY Destination Port Range : from : 6005 to : 6015 Security Policy Rule ID : 16246318197250246 Security Policy Rule Name : Rule3-Set2-22 Action : reject Rule-Type : custom Enabled : true Source Zones : 16200471619100074: Zone-LAN Destination Zones : 16204672468290016: Zone-Internet-VPN Applications : ANY Source Prefix Filters : 16242993172060125: LAN-192-168-7-100 Destination Prefix Filters : 16242994662000182: DC-192-168-22-0 Services : Protocol : 6 Source Port Range : ANY Destination Port Range : from : 7000 to : 7010 Protocol : 17 Source Port Range : ANY Destination Port Range : from : 7000 to : 7010 Security Policy Rule ID : 16245010650670003 Security Policy Rule Name : Rule1-Set3-20 Action : allow Rule-Type : custom Enabled : true Source Zones : 16200471619100074: Zone-LAN Destination Zones : 16204672468290016: Zone-Internet-VPN Applications : ANY Source Prefix Filters : 16242993172060125: LAN-192-168-7-100 Destination Prefix Filters : 16242993943320129: DC-192-168-20-0 Services : Protocol : 6 Source Port Range : ANY Destination Port Range : from : 5005 to : 5005 Protocol : 17 Source Port Range : ANY Destination Port Range : from : 5005 to : 5005 Security Policy Rule ID : 16245011984140128 Security Policy Rule Name : Rule2-Set3-21 Action : deny Rule-Type : custom Enabled : true Source Zones : 16200471619100074: Zone-LAN Destination Zones : 16204672468290016: Zone-Internet-VPN Applications : ANY Source Prefix Filters : 16242993172060125: LAN-192-168-7-100 Destination Prefix Filters : 16242994310450145: DC-192-168-21-0 Services : Protocol : 6 Source Port Range : ANY Destination Port Range : from : 6000 to : 6000 Protocol : 17 Source Port Range : ANY Destination Port Range : from : 6005 to : 6005 Security Policy Rule ID : 16245012757060237 Security Policy Rule Name : Rule3-Set3-22 Action : reject Rule-Type : custom Enabled : true Source Zones : 16200471619100074: Zone-LAN Destination Zones : 16204672468290016: Zone-Internet-VPN Applications : ANY Source Prefix Filters : 16242993172060125: LAN-192-168-7-100 Destination Prefix Filters : 16242994662000182: DC-192-168-22-0 Services : Protocol : 6 Source Port Range : ANY Destination Port Range : from : 7000 to : 7000 Protocol : 17 Source Port Range : ANY Destination Port Range : from : 7000 to : 7000 Security Policy Rule ID : 16245013906270078 Security Policy Rule Name : Rule1-Set4 Action : allow Rule-Type : custom Enabled : true Source Zones : 16200471619100074: Zone-LAN Destination Zones : 16204672468290016: Zone-Internet-VPN Applications : ANY Source Prefix Filters : ANY Destination Prefix Filters : ANY Services : ANY Security Policy Rule ID : 16228336610060052 Security Policy Rule Name : self-zone Action : allow Rule-Type : self-zone Enabled : true Source Zones : ANY Destination Zones : ANY Applications : ANY Source Prefix Filters : ANY Destination Prefix Filters : ANY Services : ANY Security Policy Rule ID : 16228336610050051 Security Policy Rule Name : intra-zone Action : allow Rule-Type : intra-zone Enabled : true Source Zones : ANY Destination Zones : ANY Applications : ANY Source Prefix Filters : ANY Destination Prefix Filters : ANYServices : ANY Security Policy Rule ID : 16228336609900050 Security Policy Rule Name : default Action : deny Rule-Type : default Enabled : true Source Zones : ANY Destination Zones : ANY Applications : ANY Source Prefix Filters : ANY Destination Prefix Filters : ANY Services : ANY