Quantum Spark 1500, 1600 AND 1800 Appliance Series: CLI Reference Guide
Quantum Spark 1500, 1600 AND 1800 Appliance Series: CLI Reference Guide
Quantum Spark 1500, 1600 AND 1800 Appliance Series: CLI Reference Guide
R80.20.20
Check Point Copyright Notice
© 2021 Check Point Software Technologies Ltd.
All rights reserved. This product and related documentation are protected by copyright and distributed under
licensing restricting their use, copying, distribution, and decompilation. No part of this product or related
documentation may be reproduced in any form or by any means without prior written authorization of Check
Point. While every precaution has been taken in the preparation of this book, Check Point assumes no
responsibility for errors or omissions. This publication and features described herein are subject to change
without notice.
RESTRICTED RIGHTS LEGEND:
Use, duplication, or disclosure by the government is subject to restrictions as set forth in subparagraph (c)
(1)(ii) of the Rights in Technical Data and Computer Software clause at DFARS 252.227-7013 and FAR
52.227-19.
TRADEMARKS:
Refer to the Copyright page for a list of our trademarks.
Refer to the Third Party copyright notices for a list of relevant copyrights and third-party licenses.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 2
Important Information
Important Information
Latest Software
We recommend that you install the most recent software release to stay up-to-date with the
latest functional improvements, stability fixes, security enhancements and protection against
new and evolving attacks.
Certifications
For third party independent certification of Check Point products, see the Check Point
Certifications page.
Check Point R80.20.20
For more about this release, see the R80.20.20 home page.
Latest Version of this Document in English
Open the latest version of this document in a Web browser.
Download the latest version of this document in PDF format.
Feedback
Check Point is engaged in a continuous effort to improve its documentation.
Please help us by sending your comments.
Revision History
Date Description
03 August 2021 Updated "Configuring NetFlow" on page 651
02 May 2021 Updated "add internet-connection (physical interface)" on page 464
28 January 2021 First release of this document
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 3
Table of Contents
Table of Contents
Introduction 42
Using Command Line Reference 43
CLI Syntax 44
Running Gaia Clish Commands from Expert Mode 45
Supported Linux Commands 46
access-rule type outgoing 47
add access-rule type outgoing 47
delete access-rule type outgoing 50
set access-rule type outgoing 51
show access-rule type outgoing 54
access-rule type incoming-internal-and-vpn 55
add access-rule type incoming-internal-and-vpn 55
delete access-rule type incoming-internal-and-vpn 57
set access-rule type incoming-internal-and-vpn 58
show access-rule type incoming-internal-and-vpn 60
additional-hw-settings 61
set additional-hw-settings 61
show additional-hw-settings 62
additional-management-settings 63
set additional-management-settings 63
show additional-management-settings 64
ad-server 65
add ad-server 65
delete ad-server 66
set ad-server 67
show ad-server 68
show ad-servers 69
address-range 70
add address-range 70
delete address-range 71
set address-range 72
show address-range 73
show address-ranges 74
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 4
Table of Contents
admin-access 75
add admin access 75
set admin-access 76
show admin-access 77
admin-access-ip-addresses 78
show admin-access-ip-addresses 78
delete admin-access-ip-address-all 79
admin-access-ipv4-address 80
add admin-access-ipv4-address 80
add admin-access-ipv4-address 81
add admin-access-ipv4-address 82
delete admin-access-ipv4-address 83
show admin-access-ipv4-addresses 84
delete admin-access-ipv4-address-all 85
administrator 86
add administrator 86
delete administrator 87
set administrator 88
set administrator 88
set administrator 89
set administrators 90
set administrators 91
show administrator 92
show administrators 93
show administrators 94
show administrators 95
autogmt 96
set-autogmt 96
show-autogmt 96
administrators radius-auth 98
set administrators radius-auth 99
set administrators radius-auth (legacy mode) 100
show administrators radius-auth 101
administrators roles-settings 102
set administrators roles-settings 102
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 5
Table of Contents
show administrators roles-settings 102
administrator session-settings 104
set administrator session-settings 105
show administrator session-settings 106
show adsl statistics 107
aggressive-aging 108
set aggressive-aging 109
set aggressive-aging 110
set aggressive-aging 112
show aggressive-aging 113
show aggressive-aging 114
show aggressive-aging 115
antispam 116
set antispam 117
set antispam 118
set antispam 120
set antispam 121
set antispam 122
set antispam 123
set antispam 124
set antispam 125
set antispam 126
set antispam 127
show antispam 128
show antispam 129
show antispam 130
antispam allowed-sender 131
add antispam allowed-sender 132
add antispam allowed-sender 133
add antispam allowed-sender 134
delete antispam allowed-sender 135
delete antispam allowed-sender 136
delete antispam allowed-sender 137
delete antispam allowed-sender 138
show antispam allowed-senders 139
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 6
Table of Contents
antispam blocked-sender 140
add antispam blocked-sender 141
add antispam blocked-sender 142
add antispam blocked-sender 143
delete antispam blocked-sender 144
delete antispam blocked-sender 145
delete antispam blocked-sender 146
delete antispam blocked-sender 147
show antispam blocked-senders 148
application 149
add application 150
add application 151
add application 152
delete application 153
delete application 154
delete application 155
find application 156
set application 157
set application 158
set application 159
set application 160
set application 161
set application 162
set application 163
set application 164
set application 165
set application 166
set application 167
show application 168
show application 169
show application 170
show applications 171
application-control 172
set application-control 173
show application-control 175
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 7
Table of Contents
show application-control other-undesired-applications 176
application-control-engine-settings 177
set application-control-engine-settings 178
set application-control-engine-settings 179
set application-control-engine-settings 180
set application-control-engine-settings 181
set application-control-engine-settings 182
set application-control-engine-settings 183
set application-control-engine-settings 184
set application-control-engine-settings 185
show application-control-engine-settings 186
application-group 187
add application-group 188
delete application-group 189
delete application-group 190
delete application-group 191
set application-group 192
set application-group 193
set application-group 194
set application-group 195
set application-group 196
set application-group 197
set application-group 198
set application-group 199
set application-group 200
show application-group 201
show application-group 202
show application-group 203
show application-groups 204
antispoofing 205
set antispoofing 206
show antispoofing 207
backup settings 208
show backup settings 209
blade-update-schedule 210
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 8
Table of Contents
set blade-update-schedule 211
set blade-update-schedule 212
set blade-update-schedule 214
set blade-update-schedule 215
show blade-update-schedule 216
show blade-update-schedule 217
show blade-update-schedule 218
bookmark 219
add bookmark 220
delete bookmark 221
delete bookmark 222
delete bookmark 223
set bookmark 224
show bookmark 226
show bookmarks 227
bridge 228
add bridge 229
delete bridge 230
set bridge 231
set bridge 232
set bridge 233
set bridge 234
show bridge 235
show bridges 236
show cellular-modem-status 237
show clock 238
cloud-deployment 239
set cloud-deployment 240
show cloud-deployment 241
cloud-notifications 242
set cloud-notification 243
show cloud-notifications 244
send cloud-report 245
cloud-services 246
reconnect cloud-services 247
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 9
Table of Contents
set cloud-services 248
set cloud-services 249
set cloud-services 250
show cloud-services 251
show cloud-services connection-details 252
cloud-services-firmware-upgrade 253
set cloud-services-firmware-upgrade 254
set cloud-services-firmware-upgrade 255
set cloud-services-firmware-upgrade 256
set cloud-services-firmware-upgrade 257
show cloud-services-firmware-upgrade 258
show cloud-services-firmware-upgrade 259
show cloud-services-firmware-upgrade 260
show cloud-service managed-blades 261
show cloud-services managed-services 262
fetch cloud-services policy 263
show cloud-services status 264
show commands 265
cphaprob 266
cphastop 269
cpinfo 270
cpstart 271
cpstat 272
cpstop 275
cpwd_admin 276
date 277
set date 278
set date 279
set date 280
set date 281
set date 282
show date 283
show date 284
show date 285
show date 286
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 10
Table of Contents
show date 287
restore default-settings 288
dhcp-bridge-settings 289
show dhcp-bridge-settings 289
set dhcp-bridge-settings 289
dhcp-relay 291
set dhcp-relay 292
show dhcp-relay 293
show dhcp servers 294
dhcp server interface 295
delete dhcp server interface 296
set dhcp server interface 297
set dhcp server interface 298
set dhcp server interface 299
set dhcp server interface 300
set dhcp server interface 301
set dhcp server interface 302
set dhcp server interface 303
set dhcp server interface 304
set dhcp server interface 305
set dhcp server interface 306
set dhcp server interface 307
set dhcp server interface 308
set dhcp server interface 309
set dhcp server interface 310
set dhcp server interface 311
set dhcp server interface 312
set dhcp server interface 313
set dhcp server interface 314
set dhcp server interface 315
set dhcp server interface 316
set dhcp server interface 317
set dhcp server interface 318
set dhcp server interface 319
show dhcp server interface 320
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 11
Table of Contents
show dhcp server interface 321
show dhcp server interface 322
show diag 323
show disk usage 324
dns 325
delete dns 326
delete dns 327
delete dns 328
delete dns 329
delete dns 330
set dns 331
set dns 332
set dns 333
set dns 334
set dns 335
show dns 336
show dns 337
show dns 338
dsl 339
set dsl advanced-settings global-settings 340
set dsl advanced-settings standards 341
show dsl advanced-setting 343
show dsl statistics 344
dynamic-dns 347
set dynamic-dns 348
set dynamic-dns 349
set dynamic-dns 350
show dynamic-dns 351
show dynamic-dns 352
show dynamic-dns 353
dynamic objects 354
exit 356
set expert password 357
fetch certificate 358
fetch policy 359
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 12
Table of Contents
fw commands 360
fw policy 361
set fw policy 362
set fw policy 363
set fw policy 364
set fw policy 365
show fw policy 366
show fw policy 367
show fw policy 368
show fw policy 369
set fw policy user-check accept 370
set fw policy user-check ask 371
set fw policy user-check block 372
set fw policy user-check block-device 373
set fw policy user-check block-infected-device 374
global-radius-conf 375
set global-radius-conf 376
show global-radius-conf 377
group 378
add group 379
delete group 380
set group 381
set group 382
set group 383
set group 384
set group 385
show group 386
show groups 387
host 388
add host 389
delete host 390
set host 391
show host 393
show hosts 394
hotspot 395
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 13
Table of Contents
set hotspot 396
set hotspot 397
set hotspot 399
set hotspot 400
set hotspot 401
set hotspot 402
show hotspot 403
show hotspot 404
show hotspot 405
https-categorization 406
set https-categorization 407
set https-categorization 408
set https-categorization 409
set https-categorization 410
show https-categorization 411
interface 412
add interface 413
add interface 414
add interface 415
add interface-alias 416
delete interface 417
set interface 418
set interface 419
set interface 420
set interface 421
set interface 422
set interface 423
set interface 424
set interface 425
set interface 426
set interface 427
set interface 428
show interface 429
show interfaces 430
show interfaces all 431
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 14
Table of Contents
interface-alias 432
add interface-alias 432
delete interface-alias 433
set interface-alias 434
interface-bond 435
add interface-bond 435
delete interface-bond 436
set interface-bond 437
set interface-bond 438
set interface-bond 439
show interface-bond 440
show interfaces-bond 441
internal-certificates-conf 442
add internal-certificate 442
delete internal-certificate 442
show internal-certificate 443
show internal-certificates 443
ips engine-settings 445
set ips engine-settings 446
set ips engine-settings 447
set ips engine-settings 448
set ips engine-settings 449
show ips engine-settings 450
show ips engine-settings 451
show ips engine-settings 452
interface-loopback 453
add interface-loopback 454
delete interface-loopback 455
internet 456
set internet 457
show internet 458
internet-advanced-settings 459
set internet-advanced-settings 459
show internet-advanced-settings 459
internet-connection 461
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 15
Table of Contents
add internet-connection 462
add internet-connection interface cellular 462
add internet-connection (physical interface) 464
WAN 464
ADSL 469
DSL 470
DMZ 473
add internet-connection (3G/4G modem) 483
delete internet-connection 485
delete internet-connection 486
deleter internet-connection 487
delete internet-connections 488
set internet-connection 489
set internet-connection 490
set internet-connection 491
set internet-connection 492
set internet-connection 493
set internet-connection 494
set internet-connection 495
set internet-connection 496
set internet-connection 497
set internet-connection 498
set internet-connection 500
set internet-connection 502
set internet-connection 504
set internet-connection 506
set internet-connection 507
set internet-connection 508
set internet-connection interface DMZ 508
set internet-connection {name} type cellular 511
set internet-connection {name} type usb-cellular 512
show internet-connection 514
show internet-connection 515
show internet-connection 516
show internet-connection {name} type cellular 516
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 16
Table of Contents
show internet-connections 522
show internet-connections table 523
set iot-stats 524
show iot-stats 525
internet-connection-bond 526
delete internet-connection-bond 526
set internet-connection-bond 527
set internet-connection-bond 528
set internet-connection-bond 529
show internet-connection-bond 530
show internet-connections-bond 531
internet mode 532
set internet mode 533
show internet mode 534
ip-fragments-params 535
set ip-fragments-params 536
set ip-fragments-params 537
set ip-fragments-params 538
show ip-fragments-params 539
ipv6-state 540
set ipv6-state 541
show ipv6-state 542
ip-resolving 543
set ip-resolving 543
show ip-resolving 543
license 545
fetch license 546
show license 547
fetch license usercenter retry 547
local-group 548
add local-group 549
delete local-group 550
delete local-group 551
delete local-group 552
set local-group 553
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 17
Table of Contents
set local-group 554
set local-group 555
set local-group 556
show local-group 557
show local-groups 558
set local-group users 559
set local-group users 560
set local-group users 561
local-user 562
add local-user 563
delete local-user 564
delete local-user 565
delete local-user 566
set local-user 567
set local-user 568
set local-user 570
set local-user 571
show local-user 572
show local-users 573
local-users expired 574
delete local-users expired 575
show local-users expired 576
show logs 577
log-servers-configuration 578
set log-servers-configuration 579
show log-servers-configuration 580
maas 581
connect maas 581
set maas 582
show maas 583
mac-filtering-list 584
add mac-filtering-list 585
delete mac-filtering-list 586
show mac-filtering-list 587
mac-filtering-settings 588
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 18
Table of Contents
set mac-filtering settings 589
set mac-filtering-settings 590
set mac-filtering settings 591
set mac-filtering settings 592
show mac-filtering-settings 593
show mac-filtering-settings 594
show mac-filtering-settings 595
set mobile-settings 596
set mobile-settings 597
show mobile-settings 598
mobile-device 599
revoke mobile-device 599
mobile-settings 600
set mobile-settings 601
set mobile-settings 602
show mobile-settings 603
mobile-invitation 604
add mobile-invitation 604
show mobile-invitation 604
mobile-push-notification 605
show mobile-push-notification 605
monitor-mode-network 606
add monitor-mode-network 607
delete monitor-mode-network 608
set monitor-mode-network 609
show monitor-mode-networks 610
monitor-mode-configuration 611
set monitor-mode-configuration 612
show monitor-mode-configuration 613
message 614
set message 615
show message 616
show message 617
show memory usage 618
set misp-refresh-route 619
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 19
Table of Contents
nat 620
set nat 621
set nat 622
set nat 623
set nat 624
set nat 625
set nat 626
set nat 627
set nat 628
set nat 629
set nat 630
set nat 631
set nat 632
set nat 633
set nat 634
show nat 635
show nat 636
show nat 637
nat-rule 638
add nat-rule 639
delete nat-rule 641
set nat-rule 642
show nat-rule 644
show nat-rules 645
show nat-manual-rules 646
nat-rule position 647
delete nat-rule position 648
set nat-rule position 649
Configuring NetFlow 651
Introduction 651
Configuration Procedure for Centrally Managed 653
add netflow collector 653
delete netflow collector 654
set netflow collector 655
show netflow collector 657
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 20
Table of Contents
show netflow collectors 657
network 659
add network 660
delete network 661
set network 662
show network 663
show networks 664
show notifications-log 665
notifications-policy 666
set notifications-policy 667
set notifications-policy 668
set notifications-policy 669
show notifications-policy 670
show notifications-policy 671
ntp 672
set ntp 673
set ntp 674
set ntp 675
set ntp 676
set ntp 677
show ntp 678
show ntp active 679
ntp server 680
set ntp server 681
set ntp server 682
set ntp server 683
show ntp servers 684
os-settings 685
set os-settings 685
set os-settings 686
show os-settings 687
periodic backup 688
set periodic-backup 689
show periodic-backup 691
set property 692
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 21
Table of Contents
privacy settings 693
set privacy-settings advanced-settings 693
show privacy-settings advanced-settings 694
proxy 695
delete proxy 696
set proxy 697
set proxy 698
set proxy 699
show proxy 700
qos 701
set qos 702
set qos 703
set qos 704
set qos 705
set qos 706
show qos 707
show qos 708
show qos 709
qos delay-sensitive-service 710
set qos delay-sensitive-service 711
set qos delay-sensitive-service 712
set qos delay-sensitive-service 713
show qos delay-sensitive-services 714
qos guarantee-bandwidth-selected-services 715
set qos guarantee-bandwidth-selected-services 716
set qos guarantee-bandwidth-selected-services 717
set qos guarantee-bandwidth-selected-services 718
show qos guarantee-bandwidth-selected-services 719
qos-rule 720
add qos-rule 721
delete qos-rule 723
delete qos-rule 724
delete qos-rule 725
set qos-rule 726
set qos-rule 727
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 22
Table of Contents
set qos-rule 729
show qos-rule 731
show qos-rule 732
show qos-rule 733
show qos-rules 734
radius-server 735
delete radius-server 736
set radius-server 737
show radius-server 738
show radius-servers 739
reach-my-device 740
set reach-my-device 741
set reach-my-device 742
set reach-my-device 743
set reach-my-device 744
show reach-my-device 745
show reach-my-device 746
show reach-my-device 747
reboot 748
set remote-access users 749
show remote-access users radius-auth 750
set rest-api 751
show rest-api 752
generate report cloud-report 753
restore settings 754
show restore settings log 755
show revert log 756
revert to factory defaults 757
revert to saved image 758
report-settings 759
set report-settings 760
set report-settings 761
set report-settings 762
show report-settings 763
show rule hits 764
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 23
Table of Contents
show saved image 765
update security-blades 766
updatable-object 767
add updatable-object 767
delete updatable-object 768
show updatable-object 769
show updatable-object 769
show updatable-object 770
show updatable-objects 771
show updatable-objects-imported 772
security-management 773
connect security-management 774
set security-management 775
set security-management 776
set security-management 777
show security-management 778
serial-port 779
set serial-port 780
set serial-port 781
set serial-port 782
set serial-port 783
set serial-port-nine-pin 784
set serial-port-nine-pin 785
set serial-port-nine-pin 786
show serial-port 787
show serial-port-nine-pin 788
server 789
add server 790
delete server 792
show server 793
show servers 794
service-details 795
set device-details 796
show device-details 797
service-group 798
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 24
Table of Contents
add service-group 799
delete service-group 800
set service-group 801
set service-group 802
set service-group 803
set service-group 804
set service-group 805
show service-group 806
show service-groups 807
service-icmp 808
add service-icmp 809
delete service-icmp 810
set service-icmp 811
show service-icmp 812
add service-protocol 813
service-protocol 814
delete service-protocol 815
set service-protocol 816
show service-protocol 818
show services-protocol 819
set server server-access 820
set server server-nat-settings 822
set server server-network-settings 824
set server server-ports 825
service-system-default 828
set service-system-default Any_TCP 829
show service-system-default Any_TCP 831
set service-system-default Any_UDP 832
show service-system-default Any_UDP 834
set service-system-default CIFS 835
show service-system-default CIFS 837
set service-system-default Citrix 838
show service-system-default Citrix 840
set service-system-default Citrix firewall-settings 841
show service-system-default Citrix firewall-settings 842
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 25
Table of Contents
set service-system-default DHCP 843
show service-system-default DHCP 844
set service-system-default DNS_TCP 845
show service-system-default DNS_TCP 847
set service-system-default DNS_UDP 848
show service-system-default DNS_UDP 849
set service-system-default FTP 850
show service-system-default FTP 852
set service-system-default FTP firewall-settings 853
show service-system-default FTP firewall-settings 854
set service-system-default GRE 855
show service-system-default GRE 857
set service-system-default H323 858
show service-system-default H323 860
set service-system-default H323_RAS 861
show service-system-default H323_RAS 862
set service-system-default HTTP 863
show service-system-default HTTP 865
set service-system-default HTTPS 866
show service-system-default HTTPS 868
set service-system-default HTTP ips-settings 869
show service-system-default HTTP ips-settings 871
set service-system-default HTTPS url-filtering-settings 872
show service-system-default HTTPS url-filtering-settings 873
set service-system-default IIOP 874
show service-system-default IIOP 876
set service-system-default IMAP 877
show service-system-default IMAP 879
set service-system-default LDAP 880
show service-system-default LDAP 882
set service-system-default MGCP 883
show service-system-default MGCP 884
set service-system-default NetBIOSDatagram 885
show service-system-default NetBIOSDatagram 886
set service-system-default NetBIOSName 887
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 26
Table of Contents
show service-system-default NetBIOSName 888
set service-system-default NetShow 889
show service-system-default NetShow 891
set service-system-default NNTP 892
show service-system-default NNTP 894
set service-system-default POP3 895
show service-system-default POP3 897
set service-system-default PPTP_TCP 898
show service-system-default PPTP_TCP 900
set service-system-default PPTP_TCP ips-settings 901
show service-system-default PPTP_TCP ips-settings 902
set service-system-default RealAudio 903
show service-system-default RealAudio 905
set service-system-default RSH 906
show service-system-default RSH 908
set service-system-default RTSP 909
show service-system-default RTSP 911
set service-system-default SCCP 912
show service-system-default SCCP 914
set service-system-default SCCPS 915
show service-system-default SCCPS 917
set service-system-default SIP_TCP 918
show service-system-default SIP_TCP 920
set service-system-default SIP_UDP 921
show service-system-default SIP_UDP 922
set service-system-default SMTP 923
show service-system-default SMTP 925
set service-system-default SNMP 926
show service-system-default SNMP 927
set service-system-default SNMP firewall-settings 928
show service-system-default SNMP firewall-settings 929
set service-system-default SQLNet 930
show service-system-default SQLNet 932
set service-system-default SSH 933
show service-system-default SSH 935
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 27
Table of Contents
set service-system-default SSH ips-settings 936
show service-system-default SSH ips-settings 937
set service-system-default TELNET 938
show service-system-default TELNET 940
set service-system-default TFTP 941
show service-system-default TFTP 943
service-tcp 944
add service-tcp 945
set service-tcp 946
delete service-tcp 948
show service-tcp 949
show services-tcp 950
service-udp 951
add service-udp 952
delete service-udp 953
set service-udp 954
show service-udp 955
show services-udp 956
show services-icmp 957
shell/expert 958
set sic_init 959
sim 960
snmp 961
add snmp 962
add snmp 963
add snmp 964
delete snmp 965
delete snmp 966
delete snmp 967
delete snmp 968
set snmp 969
set snmp 970
set snmp 971
set snmp 972
set snmp 973
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 28
Table of Contents
set snmp 974
show snmp 975
show snmp 976
show snmp 977
show snmp 978
show snmp 979
show snmp 980
show snmp-general-all 981
snmp traps 982
set snmp traps 983
set snmp traps 984
set snmp traps 985
set snmp traps 986
set snmp-traps 987
set snmp-traps 988
set-snmp-traps 989
show snmp traps 990
delete snmp traps-receivers 991
show snmp traps receivers 992
show snmp traps enabled-traps 993
snmp user 994
delete snmp user 995
set snmp user 996
show snmp user 997
show snmp users 998
delete snmp users 999
show software version 1000
ssl-inspection advanced-settings 1001
set ssl-inspection advanced-settings 1002
show ssl-inspection advanced-settings 1004
ssl-inspection exception 1005
add ssl-inspection exception 1006
delete ssl-inspection exception 1008
delete ssl-inspection exception 1009
delete ssl-inspection exception 1010
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 29
Table of Contents
set ssl-inspection exception 1011
show ssl-inspection exception 1013
show ssl-inspection exceptions 1014
ssl-inspection policy 1015
set ssl-inspection policy 1016
set ssl-inspection policy https-categorization-only-mode 1018
set ssl-inspection policy inspect-https-protocol 1019
set ssl-inspection policy inspect-imaps-protocol 1020
show ssl-inspection policy 1021
delete ssl-network-extender 1022
stateful-inspection 1023
set stateful-inspection 1023
set stateful-inspection 1023
set stateful-inspection 1023
set stateful-inspection 1024
set stateful-inspection 1024
set stateful-inspection 1025
set stateful-inspection 1025
set stateful-inspection 1026
set stateful-inspection 1026
set stateful-inspection 1027
set stateful-inspection 1027
set stateful-inspection 1028
set stateful-inspection 1028
set stateful-inspection 1029
set stateful-inspection 1029
set stateful-inspection 1030
set stateful-inspection 1030
set stateful-inspection 1031
show stateful-inspection 1031
static-route 1033
add static-route 1034
add static-route 1034
set static-route 1036
delete static-route 1037
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 30
Table of Contents
delete static-routes 1038
show static-routes 1039
streaming-engine-settings 1040
set streaming-engine-settings 1041
set streaming-engine-settings 1042
set streaming-engine-settings 1044
show streaming-engine-settings 1045
show streaming-engine-settings 1046
show streaming-engine-settings 1047
switch 1048
add switch 1049
delete switch 1050
set switch 1051
set switch 1052
set switch 1053
show switch 1054
show switch 1055
show switch 1056
show switches 1057
syslog-server 1058
add syslog-server 1059
add-syslog-server protocol tls 1060
delete syslog-server 1061
delete syslog-server 1062
delete syslog-server 1063
set syslog-server 1064
set syslog-server 1065
set syslog-server 1066
show syslog-server 1067
show syslog-server 1068
show syslog-server 1069
show syslog-server all 1070
system-settings 1071
show system-settings is-custom-branding 1072
traceroute-max-ttl 1073
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 31
Table of Contents
threat-prevention-advanced 1074
set threat-prevention-advanced 1075
show threat-prevention-advanced 1076
threat-prevention anti-bot 1077
set threat-prevention anti-bot engine 1078
show threat-prevention anti-bot engine 1079
set threat-prevention anti-bot policy 1080
set threat-prevention anti-bot policy 1081
set threat-prevention anti-bot policy 1082
show threat-prevention anti-bot policy 1083
show threat-prevention anti-bot policy 1084
show threat-prevention anti-bot policy 1085
set threat-prevention anti-bot user-check ask 1086
show threat-prevention anti-bot user-check ask 1087
set threat-prevention anti-bot user-check block 1088
show threat-prevention anti-bot user-check block 1089
threat-prevention anti-virus 1090
set threat-prevention anti-virus engine 1091
show threat-prevention anti-virus engine 1092
add threat-prevention anti-virus file-type 1093
delete threat-prevention anti-virus file-type 1094
set threat-prevention anti-virus file-type 1095
show threat-prevention anti-virus file-type 1096
show threat-prevention anti-virus file-types 1097
delete threat-prevention anti-virus file-type custom 1098
set threat-prevention anti-virus policy 1099
set threat-prevention anti-virus policy 1100
set threat-prevention anti-virus policy 1101
set threat-prevention anti-virus policy 1102
set threat-prevention anti-virus policy 1103
set threat-prevention anti-virus policy 1104
set threat-prevention anti-virus policy 1105
show threat-prevention anti-virus policy 1106
show threat-prevention anti-virus policy 1107
show threat-prevention anti-virus policy 1108
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 32
Table of Contents
set threat-prevention anti-virus user-check ask 1109
show threat-prevention anti-virus user-check ask 1110
set threat-prevention anti-virus user-check block 1111
show threat-prevention anti-virus user-check block 1112
threat-prevention exception 1113
add threat-prevention exception 1114
delete threat-prevention exception 1116
set threat-prevention exception 1117
show threat-prevention exception 1119
delete threat-prevention exceptions 1120
show threat-prevention infected-hosts 1121
threat-prevention ips 1122
set threat-prevention ips custom-default-policy 1123
show threat-prevention ips custom-default-policy 1125
add threat-prevention ips network-exception 1126
add threat-prevention ips network-exception 1127
add threat-prevention ips network-exception 1128
delete threat-prevention ips network-exception 1129
delete threat-prevention ips network-exception 1130
delete threat-prevention ips network-exception 1131
set threat-prevention ips network-exception 1132
set threat-prevention ips network-exception 1133
set threat-prevention ips network-exception 1134
show threat-prevention ips network-exception 1135
set threat-prevention ips policy 1136
show threat-prevention ips policy 1137
find threat-prevention ips protection 1138
set threat-prevention ips protection-action-override 1139
set threat-prevention ips protection-action-override 1140
set threat-prevention ips protection-action-override 1141
set threat-prevention ips protection-action-override 1142
set threat-prevention ips protection-action-override 1143
show threat-prevention ips protection-action-override 1144
show threat-prevention ips protection-action-override 1145
show threat-prevention ips protection-action-override 1146
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 33
Table of Contents
threat-prevention-profile 1147
set threat-prevention policy 1147
threat-prevention policy 1148
set threat-prevention policy 1149
show threat-prevention policy 1150
threat-prevention threat-emulation additional-remote-emulator 1151
add threat-prevention threat-emulation additional-remote-emulator 1152
delete threat-prevention threat-emulation additional-remote-emulator 1153
delete threat-prevention threat-emulation additional-remote-emulator 1154
delete threat-prevention threat-emulation additional-remote-emulator 1155
set threat-prevention threat-emulation additional-remote-emulator 1156
show threat-prevention threat-emulation additional-remote-emulator 1157
show threat-prevention threat-emulation additional-remote-emulator 1158
show threat-prevention threat-emulation additional-remote-emulator 1159
set threat-prevention threat-emulation file-types-revert-actions-to-default 1160
threat-prevention threat-emulation 1161
set threat-prevention threat-emulation file-type 1162
show threat-prevention threat-emulation file-type 1163
show threat-prevention threat-emulation file-types 1164
set threat-prevention threat-emulation policy 1165
set threat-prevention threat-emulation policy 1166
set threat-prevention threat-emulation policy 1168
show threat-prevention threat-emulation policy 1169
show threat-prevention threat-emulation policy 1170
show threat-prevention threat-emulation policy 1171
threat-prevention whitelist 1172
add threat-prevention whitelist mail 1173
show threat-prevention whitelist files 1174
delete threat-prevention whitelist mail 1175
set threat-prevention whitelist mail 1176
show threat-prevention whitelist mail 1177
delete threat-prevention whitelist mails 1178
show threat-prevention whitelist mails 1179
add threat-prevention whitelist type-file 1180
delete threat-prevention whitelist type-file 1181
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 34
Table of Contents
delete threat-prevention whitelist type-file 1182
delete threat-prevention whitelist type-file 1183
add threat-prevention whitelist type-url 1184
delete threat-prevention whitelist type-url 1185
delete threat-prevention whitelist type-url 1186
delete threat-prevention whitelist type-url 1187
show threat-prevention whitelist urls 1188
update default-image from current-image 1189
ui-settings 1190
set ui-settings 1191
set ui-settings 1192
set ui-settings 1193
show ui-settings 1194
show ui-settings 1195
show ui-settings 1196
usb-modem-advanced 1197
add usb-modem-advanced 1198
delete usb-modem-advanced 1199
delete usb-modem-advanced-all 1200
set usb-modem-advanced 1201
show usb-modem-advanced 1202
show usb-modem-advanced table 1203
usb-modem-info 1204
show usb-modem-info 1205
show usb-modem-info-table 1206
usb-modem-watchdog 1207
set usb-modem-watchdog 1208
set usb-modem-watchdog 1209
set usb-modem-watchdog 1210
show usb-modem-watchdog 1211
set used-ad-group 1212
set used-ad-group 1213
set used-ad-group 1214
user-awareness 1215
set user-awareness 1216
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 35
Table of Contents
set user-awareness 1217
set user-awareness 1218
set user-awareness 1219
set user-awareness browser-based-authentication 1220
set user-awareness browser-based-authentication 1221
set user-awareness browser-based-authentication 1223
set user-awareness browser-based-authentication 1224
set user-awareness browser-based-authentication 1225
show user-awareness 1226
show user-awareness 1227
show user-awareness 1228
show user-awareness browser-based-authentication 1229
set user-management 1230
show upgrade log 1231
show used-ad-group bookmarks 1232
upgrade from usb or tftp server 1233
vpn 1234
vpn 1235
Managing the VPN Driver 1236
Launching TunnelUtil Tool 1237
Debugging VPN 1238
delete vpn 1239
set vpn 1240
set vpn 1241
set vpn 1245
set vpn 1246
set vpn 1247
set vpn 1248
set vpn 1249
set vpn 1250
set vpn 1251
set vpn 1252
set vpn 1253
set vpn 1254
set vpn 1255
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 36
Table of Contents
set vpn 1256
set vpn 1257
set vpn 1258
set vpn 1259
set vpn 1260
set vpn 1261
set vpn 1262
set vpn 1263
set vpn 1264
set vpn 1265
set vpn 1266
show vpn 1267
show vpn 1268
show vpn 1269
vpn remote-access 1270
set vpn remote-access 1271
set vpn remote-access 1272
set vpn remote-access 1273
set vpn remote-access 1274
set vpn remote-access 1275
set vpn remote-access 1276
set vpn remote-access 1277
set vpn remote-access 1278
set vpn remote-access 1279
set vpn remote-access 1280
set vpn remote-access 1281
set vpn remote-access 1282
set vpn remote-access 1283
set vpn remote-access 1284
set vpn remote-access 1285
set vpn remote-access 1286
set vpn remote-access 1287
set vpn remote-access 1288
set vpn remote-access 1289
set vpn remote-access 1290
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 37
Table of Contents
set vpn remote-access 1291
set vpn remote-access 1292
set vpn remote-access 1293
set vpn remote-access 1294
set vpn remote-access 1295
set vpn remote-access 1296
set vpn remote-access 1297
set vpn remote-access 1298
set vpn remote-access 1299
set vpn remote-access 1300
set vpn remote-access 1301
set vpn remote-access 1302
set vpn remote-access 1303
set vpn remote-access 1304
set vpn remote-access 1305
set vpn remote-access 1306
set vpn remote-access 1306
set vpn remote-access 1307
show vpn remote-access 1308
show vpn remote-access 1309
show vpn remote-access 1310
show vpn remote-access 1310
show vpn remote-access 1312
set vpn remote-access advanced 1313
show vpn remote-access advanced 1315
set vpn remote-access advanced enc-dom-obj manual 1316
set vpn remote-access advanced enc-dom-obj manual 1317
set vpn remote-access advanced enc-dom-obj manual 1318
vpn remote-access two-factor-authentication 1319
set vpn remote-access two-factor-authentication 1319
show vpn remote-access two-factor-authentication 1320
vpn site 1322
add vpn site 1323
delete vpn site 1330
delete vpn site 1331
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 38
Table of Contents
delete vpn site 1332
show vpn sites 1333
vpn site-to-site 1334
set vpn site-to-site 1335
set vpn site-to-site 1336
set vpn site-to-site 1338
set vpn site-to-site 1339
set vpn site-to-site 1340
set vpn site-to-site 1341
set vpn site-to-site 1342
set vpn site-to-site 1343
set vpn site-to-site 1344
set vpn site-to-site 1345
set vpn site-to-site 1346
set vpn site-to-site 1347
set vpn site-to-site 1348
set vpn site-to-site 1349
set vpn site-to-site 1350
set vpn site-to-site 1351
set vpn site-to-site 1352
set vpn site-to-site 1353
set vpn site-to-site 1354
set vpn site-to-site 1355
set vpn site-to-site 1356
set vpn site-to-site 1357
set vpn site-to-site 1358
set vpn site-to-site 1359
set vpn site-to-site 1360
set vpn site-to-site 1361
set vpn site-to-site 1362
set vpn site-to-site 1363
set vpn site-to-site 1364
set vpn site-to-site 1365
set vpn site-to-site 1366
set vpn site-to-site 1367
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 39
Table of Contents
set vpn site-to-site 1368
set vpn site-to-site 1369
set vpn site-to-site 1370
set vpn site-to-site 1371
shows vpn site-to-site 1372
show vpn site-to-site 1373
shows vpn site-to-site 1374
set vpn site-to-site enc-dom manual 1375
set vpn site-to-site enc-dom manual 1376
set vpn site-to-site enc-dom manual 1377
set vpn site-to-site enc-dom manual 1378
vpn tunnel 1379
show vpn tunnel 1380
show vpn tunnels 1381
wlan 1382
delete wlan 1383
set wlan 1384
set wlan 1385
set wlan 1386
set wlan 1387
set wlan 1388
set wlan 1389
set wlan 1390
set wlan 1391
set wlan 1392
set wlan 1393
set wlan 1394
set wlan 1395
set wlan 1396
set wlan 1397
set wlan 1398
set wlan 1399
set wlan wireless advanced-settings protected-mgmt-frames 1400
show wlan 1401
show wlan 1402
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 40
Table of Contents
show wlan 1403
wlan radio 1404
set wlan radio 1405
set wlan radio 1406
set wlan radio 1407
set wlan radio 1408
set wlan radio 1409
set wlan radio 1410
set wlan radio 1411
show wlan radio 1412
show wlan statistics 1413
wlan vaps 1414
add wlan vap 1415
delete wlan vaps 1416
set wlan vap wireless advanced-settings protected-mgmt-frames 1417
set wlan vap 1418
show wlan vap wireless 1419
show wlan vaps 1420
show wlan vaps statistics 1421
zero-touch 1422
set zero-touch 1423
show zero-touch 1424
test zero-touch-request 1425
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 41
Introduction
Introduction
This guide contains all relevant CLI commands for the Quantum Spark Small and Medium Business (SMB)
appliance models:
n 1530
n 1550
n 1570
n 1590
n 1570R
n 1600
n 1800
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 42
Using Command Line Reference
Using Command Line Reference
You can make changes to your appliance with the WebUI or Command Line Interface (CLI). When using CLI
note these aspects:
n The CLI default shell (clish) covers all the operations that are supported from the WebUI. It also
supports auto-completion capabilities, similar to Gaia. For advanced operations that require direct
access to the file system (such as redirecting debug output to a file), log in to Expert mode.
n SSH to the appliance is supported and is enabled through the WebUI.
n You can enable login directly to expert mode. To do this:
l Login to Expert mode using the "Expert" password.
l Run the command bashUser on
l You will now always login directly to expert mode (this mode is not deleted during reboot)
l To turn this mode off, run the command bashUser off
n SCP to the appliance is supported but you need to enable direct login to Expert mode. Note that
SFTP that is commonly used by winSCP is not supported. For more information, see sk52763.
CLISH Auto-completion
All CLISH commands support auto-completion. Standard Check Point and native Linux commands can be
used from the CLISH shell but do not support auto-completion. These are examples of the different
commands:
n CLISH - fetch,set, show
n Standard Check Point - cphaprob,..., fw, vpn
n Native Linux - ping, tcpdump, traceroute
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 43
CLI Syntax
CLI Syntax
The CLI commands are formatted according to these syntax rules.
Notation Description
Text without brackets Items you must type as shown
<Text inside angle brackets> Placeholder for which you must supply a value
[Text inside square brackets] Optional items
Vertical pipe (|) Separator for mutually exclusive items; choose one
{Text inside curly brackets} Set of required items; choose one
Ellipsis (?) Multiple values or parameters can be entered
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 44
Running Gaia Clish Commands from Expert Mode
Running Gaia Clish Commands from Expert
Mode
You can run Gaia Clish commands from Expert mode.
Syntax
Parameters
Parameter Description
-c Cmd Single command to execute
-f File File to load commands from
-v Verbose
-i Ignore cmd failure in batch mode and continue
-A Run as admin
-C List available commands
-h Help (this message)
Note - If the default shell, in which you logged in, was Gaia Clish, and then you logged in
to the Expert mode from it, you cannot run the clish command from the Expert mode
(running clish -> expert -> clish commands does not work, but running expert->
clish commands works).
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 45
Supported Linux Commands
Supported Linux Commands
These standard Linux commands are also supported by the Check Point Small and Medium Business
Appliance CLI.
n arp
n netstat
n nslookup
n ping
n resize
n sleep
n tcpdump
n top
n traceroute
n uptime
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 46
access-rule type outgoing
access-rule type outgoing
Relevant commands for outgoing access rule
add access-rule type outgoing
Description
Adds a new firewall access rule to the outgoing (clear) traffic Rule Base.
Syntax
Parameters
Parameter Description
action The action taken when there is a match on the rule
Options: block, accept, ask, inform, block-inform
application-id Applications or web sites that are accepted or blocked
application-name Applications or web sites that are accepted or blocked
application- If true, the rule accepts or blocks all applications but the selected application
negate Type: Boolean (true/false)
comment Description of the rule
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : ()
@
destination Network object that is the target of the connection
destination- If true, the destination is all traffic except what is defined in the destination field
negate Type: Boolean (true/false)
disabled Indicates if the rule is disabled
Type: Boolean (true/false)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 47
access-rule type outgoing
Parameter Description
hours-range- If true, time is configured
enabled Type: Boolean (true/false)
hours-range-from Time in the format HH:MM
Type: A time format hh:mm
hours-range-to Time in the format HH:MM
Type: A time format hh:mm
limit Applications traffic upload limit (in kbps)
Type: A number with no fractional part (integer)
limit-application- If true, download is limited
download Type: Boolean (true/false)
limit-application- If true, upload is limited
upload Type: Boolean (true/false)
log Defines which logging method to use: None - do not log, Log - Create log, Alert - log
with alert, Account - account rule
Options: none, log, alert, account
name name
Type: A string of alphanumeric characters without space between them
position The order of the rule in comparison to other manual rules
Type: Decimal number
position-above The order of the rule in comparison to other manual rules
Type: Decimal number
position-below The order of the rule in comparison to other manual rules
Type: Decimal number
service The network service object that the rule should match to
service-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
source Network object or user group that initiates the connection
source-negate If true, the source is all traffic except what is defined in the source field
Type: Boolean (true/false)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 48
access-rule type outgoing
Example
add access-rule type outgoing action block log none source TEXT source-
negate true destination TEXT destination-negate true service TEXT service-
negate true disabled true comment "This is a comment." hours-range-enabled
true hours-range-from 23:20 hours-range-to 23:20 position 2 name word
application-name hasOne application-negate true limit-application-download
true limit 200 limit-application-upload true limit 5
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 49
delete access-rule type outgoing
delete access-rule type outgoing
Description
Deletes an existing firewall access rule to the outgoing (clear) traffic Rule Base by rule position or rule name.
Syntax
Parameters
Parameter Description
position The order of the rule in comparison to other manual rules
Type: Decimal number
name name
Type: A string of alphanumeric characters without space between them
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 50
set access-rule type outgoing
set access-rule type outgoing
Description
Configures an existing firewall access rule to the outgoing (clear) traffic Rule Base by position or name.
Syntax
set access-rule type outgoing name <name>[ action <action> ] [ log <log> ]
[ source <source> ] [ source-negate <source-negate> ] [ destination
<destination> ] [ destination-negate <destination-negate> ] [ service
<service> ] [ service-negate <service-negate> ] [ disabled <disabled> ] [
comment <comment> ] [ hours-range-enabled { true hours-range-from <hours-
range-from> hours-range-to <hours-range-to> | false } ] [ { position
<position> | position-above <position-above> | position-below <position-
below> } ] [ name <name> ] [ { [ application-name <application-name> ] | [
application-id <application-id> ] } ] [ application-negate <application-
negate> ] [ limit-application-download { true limit <limit> | false } ] [
limit-application-upload { true limit <limit> | false } ]
Parameters
Parameter Description
action The action taken when there is a match on the rule
Options: block, accept, ask, inform, block-inform
application-id Applications or web sites that are accepted or blocked
application-name Applications or web sites that are accepted or blocked
application- If true, the rule accepts or blocks all applications but the selected application
negate Type: Boolean (true/false)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 51
set access-rule type outgoing
Parameter Description
comment Description of the rule
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : ()
@
destination Network object that is the target of the connection
destination- If true, the destination is all traffic except what is defined in the destination field
negate Type: Boolean (true/false)
disabled Indicates if the rule is disabled
Type: Boolean (true/false)
hours-range- If true, time is configured
enabled Type: Boolean (true/false)
hours-range-from Time in the format HH:MM
Type: A time format hh:mm
hours-range-to Time in the format HH:MM
Type: A time format hh:mm
limit Applications traffic upload limit (in kbps)
Type: A number with no fractional part (integer)
limit-application- If true, download is limited
download Type: Boolean (true/false)
limit-application- If true, upload is limited
upload Type: Boolean (true/false)
log Defines which logging method to use: None - do not log, Log - Create log, Alert - log
with alert, Account - account rule
Options: none, log, alert, account
name name
Type: A string of alphanumeric characters without space between them
position The order of the rule in comparison to other manual rules
Type: Decimal number
position-above The order of the rule in comparison to other manual rules
Type: Decimal number
position-below The order of the rule in comparison to other manual rules
Type: Decimal number
service The network service object that the rule should match to
service-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 52
set access-rule type outgoing
Parameter Description
source Network object or user group that initiates the connection
source-negate If true, the source is all traffic except what is defined in the source field
Type: Boolean (true/false)
Example
set access-rule type outgoing position 2 action block log none source TEXT
source-negate true destination TEXT destination-negate true service TEXT
service-negate true disabled true comment "This is a comment." hours-range-
enabled true hours-range-from 23:20 hours-range-to 23:20 position 2 name
word application-name hasOne application-negate true limit-application-
download true limit 100 limit-application-upload true limit 5
set access-rule type outgoing name word action block log none source TEXT
source-negate true destination TEXT destination-negate true service TEXT
service-negate true disabled true comment "This is a comment." hours-range-
enabled true hours-range-from 23:20 hours-range-to 23:20 position 2 name
word application-name hasOne application-negate true limit-application-
download true limit 100 limit-application-upload true limit 5
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 53
show access-rule type outgoing
show access-rule type outgoing
Description
Shows a firewall access rule in the outgoing (clear) traffic Rule Base according to name or position.
Syntax
Parameters
Parameter Description
name name
Type: A string of alphanumeric characters without space between them
position The order of a manual rule in comparison to other manual rules
Type: Decimal number
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 54
access-rule type incoming-internal-and-vpn
access-rule type incoming-internal-
and-vpn
Commands relevant for firewall access rule to the incoming/internal/VPN traffic Rule Base.
add access-rule type incoming-internal-and-vpn
Description
Adds a new firewall access rule to the incoming/internal/VPN traffic Rule Base.
Syntax
Parameters
Parameter Description
action The action taken when there is a match on the rule
Options: block, accept, ask, inform, block-inform
comment Description of the rule
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
destination Network object that is the target of the connection
destination- If true, the destination is all traffic except what is defined in the destination field
negate Type: Boolean (true/false)
disabled Indicates if the rule is disabled
Type: Boolean (true/false)
hours-range- If true, time is configured
enabled Type: Boolean (true/false)
hours-range- Time in the format HH:MM
from Type: A time format hh:mm
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 55
access-rule type incoming-internal-and-vpn
Parameter Description
hours-range-to Time in the format HH:MM
Type: A time format hh:mm
log Defines which logging method to use: None - do not log, Log - Create log, Alert - log
with alert, Account - account rule
Options: none, log, alert, account
name name
Type: A string of alphanumeric characters without space between them
position The order of the rule in comparison to other manual rules
Type: Decimal number
position-above The order of the rule in comparison to other manual rules
Type: Decimal number
position-below The order of the rule in comparison to other manual rules
Type: Decimal number
service The network service object that the rule should match to
service-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
source Network object or user group that initiates the connection
source-negate If true, the source is all traffic except what is defined in the source field
Type: Boolean (true/false)
vpn Indicates if traffic is matched on encrypted traffic only or all traffic
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 56
delete access-rule type incoming-internal-and-vpn
delete access-rule type incoming-internal-and-
vpn
Description
Deletes an existing firewall access rule to the incoming/internal/VPN traffic Rule Base by rule name or rule
position.
Syntax
Parameters
Parameter Description
name Name
Type: A string of alphanumeric characters without space between them
position The order of the rule in comparison to other manual rules
Type: Decimal number
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 57
set access-rule type incoming-internal-and-vpn
set access-rule type incoming-internal-and-vpn
Description
Configures an existing firewall access rule to the incoming/internal/VPN traffic Rule Base by position or
name.
Syntax
Parameters
Parameter Description
action The action taken when there is a match on the rule
Options: block, accept, ask, inform, block-inform
comment Description of the rule
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
destination Network object that is the target of the connection
destination- If true, the destination is all traffic except what is defined in the destination field
negate Type: Boolean (true/false)
disabled Indicates if the rule is disabled
Type: Boolean (true/false)
hours-range- If true, time is configured
enabled Type: Boolean (true/false)
hours-range- Time in the format HH:MM
from Type: A time format hh:mm
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 58
set access-rule type incoming-internal-and-vpn
Parameter Description
hour-range-to Time in the format HH:MM
Type: A time format hh:mm
log Defines which logging method to use: None - do not log, Log - Create log, Alert - log
with alert, Account - account rule
Options: none, log, alert, account
name name
Type: A string of alphanumeric characters without space between them
position The order of the rule in comparison to other manual rules
Type: Decimal number
position-above The order of the rule in comparison to other manual rules
Type: Decimal number
position-below The order of the rule in comparison to other manual rules
Type: Decimal number
service The network service object that the rule should match to
service-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
source Network object or user group that initiates the connection
source-negate If true, the source is all traffic except what is defined in the source field
Type: Boolean (true/false)
vpn Indicates if traffic is matched on encrypted traffic only or all traffic
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 59
show access-rule type incoming-internal-and-vpn
show access-rule type incoming-internal-and-
vpn
Description
Shows a firewall access rule in the incoming/internal/VPN traffic Rule Base according to position or name..
Syntax
Parameters
Parameter Description
position The order of a manual rule in comparison to other manual rules
Type: Decimal number
name name
Type: A string of alphanumeric characters without space between them
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 60
additional-hw-settings
additional-hw-settings
Relevant commands for additional hardware settings.
set additional-hw-settings
Description
Configures various hardware settings.
Syntax
Parameters
Parameter Description
reset-timeout Indicates the amount of time (in seconds) that you need to press and hold the factory
defaults button on the back panel to restore to the factory defaults image
Type: A number with no fractional part (integer)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 61
show additional-hw-settings
show additional-hw-settings
Description
Shows advanced hardware related setings.
Syntax
show additional-hw-settings
Parameters
Parameter Description
n/a
Example
show additional-hw-settings
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 62
additional-management-settings
additional-management-settings
Commands relevant for additional management settings.
set additional-management-settings
Description
Configure additional management settings.
Syntax
Parameters
Parameter Description
advanced-settings Indicates whether the temporary policy installation files will be saved to the
install-temporary- storage partition
policy- Type: Boolean (true/false)
to-storage
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 63
show additional-management-settings
show additional-management-settings
Description
Show the additional management settings that were configured.
Syntax
show additional-management-settings
Parameters
Parameter Description
n/a
Example
show additional-management-settings
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 64
ad-server
ad-server
Relevant commands for ad server
add ad-server
Description
Adds a new Active Directory server object.
Syntax
When you fill the branch-path field, you can add multiple branches by chaining them into a single string with
a semi-colon separator between them: branch1path;branch2path;branch3path
Parameters
Parameter Description
branch-path The branch of the domain to be used
Type: An LDAP DN
domain Domain name
Type: Host name
ipv4-address Domain controller IP address
password The user's password
Type: A string that contains alphanumeric and special characters
use-branch- Select only if you want to use only part of the user database defined in the Active
path Directory
Type: Boolean (true/false)
user-dn FQDN of the user
Type: An LDAP DN
username A user name with administrator privileges to communicate with the AD server
Type: A string that contains (0-9, a-z, - . @) up to 64 characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 65
delete ad-server
delete ad-server
Description
Deletes an existing Active Directory server object.
Syntax
Parameters
Parameter Description
domain Domain name
Type: Host name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 66
set ad-server
set ad-server
Description
Configures an existing Active Directory server object.
Syntax
When you fill the branch-path field, you can add multiple branches by chaining them into a single string with
a semi-colon separator between them: branch1path;branch2path;branch3path
Parameters
Parameter Description
branch-path The branch of the domain to be used
Type: An LDAP DN
domain Domain name
Type: Host name
ipv4-address Domain controller IP address
password The user's password
Type: A string that contains alphanumeric and special characters
use-branch- Select only if you want to use only part of the user database defined in the Active
path Directory
Type: Boolean (true/false)
user-dn FQDN of the user
Type: An LDAP DN
username A user name with administrator privileges to communicate with the AD server
Type: A string that contains (0-9, a-z, - . @) up to 64 characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 67
show ad-server
show ad-server
Description
Shows settings of a configured Active Directory server object.
Syntax
Parameters
Parameter Description
domain Domain name
Type: Host name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 68
show ad-servers
show ad-servers
Description
Shows settings of all configured AD server objects.
Syntax
show ad-servers
Parameters
Parameter Description
n/a
Example
show ad-servers
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 69
address-range
address-range
Relevant commands for address range.
add address-range
Description
Adds a new IP address range object.
Syntax
Parameters
Parameter Description
dhcp-exclude-ip-addr Indicates if the object's IP address(es) is excluded from internal DHCP daemon
Options: on, off
end-ipv4 The end of the IP range
name Network Object name
Type: String
start-ipv4 The beginning of the IP range
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 70
delete address-range
delete address-range
Description
Deletes an existing address range object.
Syntax
Parameters
Parameter Description
name Network Object name
Type: String
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 71
set address-range
set address-range
Description
Configures an existing IP address range object.
Syntax
Parameters
Parameter Description
dhcp-exclude-ip-addr Indicates if the object's IP address(es) is excluded from internal DHCP daemon
Options: on, off
end-ipv4 The end of the IP range
name Network Object name
Type: String
start-ipv4 The beginning of the IP range
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 72
show address-range
show address-range
Description
Shows settings of a configured IP address range object.
Syntax
Parameters
Parameter Description
name Network Object name
Type: String
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 73
show address-ranges
show address-ranges
Description
Shows settings of all configured IP address range objects.
Syntax
show address-ranges
Parameters
Parameter Description
n/a
Example
show address-ranges
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 74
admin-access
admin-access
Relevant commands for admin access.
add admin access
Description
Adds a specific IPv4 address or a network IPv4 address from which the administrator can remotely access
the appliance.
Syntax
add admin-access-ipv4-address
{single-ipv4-address|network-ipv4-address} <ip_addr> {subnet-mask
<netmask>|mask-length <mask_length>}
Parameters
Parameter Description
ip_addr IPv4 address
mask_length Interface mask length, a value between 1 - 32
netmask Interface IPv4 address subnet mask
Return Value
0 on success, 1 on failure
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 75
set admin-access
set admin-access
Description
Configures various parameters for administrator access to the device via web/SSH.
Syntax
Parameters
Parameter Description
access Enable administrator access from the Internet (clear traffic from external interfaces)
Type: Boolean (true/false)
allowed-ipv4- Administrator access permissions policy for source IP addresses
addresses Options: any, from-ip-list, any-except-internet
ssh-access- SSH Port
port Type: Port number
support- For security reasons, it is highly recommended never to change this parameter's value.
weak-tls- Support of TLSv1.0 will be added back to the administration portal to allow connectivity
version with old browsers (usually ones released prior to 2014). Changing the default of this
parameter exposes the administration portal to at- tacks that use vulnerabilities like
Heartbleed (CVE-2014-0160).
Type: Boolean (true/false)
web-access- Web Port (HTTPS)
port Type: Port number
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 76
show admin-access
show admin-access
Description
Shows settings of administrator access configuration.
Syntax
show admin-access
Parameters
Parameter Description
n/a
Example
show admin-access
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 77
admin-access-ip-addresses
admin-access-ip-addresses
Relevant commands for admin access IP addresses.
show admin-access-ip-addresses
Description
Show all the configured IP addresses that are permitted for administrator access to the appliance.
Syntax
show admin-access-ip-addresses
Parameters
Parameter Description
n/a
Example
show admin-access-ip-addresses
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 78
delete admin-access-ip-address-all
delete admin-access-ip-address-all
Description
Delete all the reserved IP addresses for administrator access.
Syntax
delete admin-access-ip-address-all
Parameters
Parameter Description
n/a
Example
delete admin-access-ip-address-all
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 79
admin-access-ipv4-address
admin-access-ipv4-address
Relevant commands for admin access IPv4 addresses.
add admin-access-ipv4-address
Adds a specific IPv4 address or an IPv4 address network and mask from which the administrator can
remotely access the appliance according to configuration.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 80
add admin-access-ipv4-address
add admin-access-ipv4-address
Description
Adds a specific IPv4 address from which the administrator can remotely access the appliance according to
configuration.
Syntax
Parameters
Parameter Description
single-ipv4-address IP address
Type: IP address
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 81
add admin-access-ipv4-address
add admin-access-ipv4-address
Description
Adds an IPv4 address network and mask from which the administrator can remotely access the appliance
according to configuration.
Syntax
Parameters
Parameter Description
mask-length Subnet mask length
Type: A string that contains numbers only
network-ipv4-address IP address
Type: IP address
subnet-mask Subnet mask
Type: Subnet mask
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 82
delete admin-access-ipv4-address
delete admin-access-ipv4-address
Description
Deletes a specific IPv4 address or an IPv4 network and subnet from which the administrator can remotely
access the appliance according to configuration.
Syntax
Parameters
Parameter Description
ipv4-address IP address
Type: IP address
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 83
show admin-access-ipv4-addresses
show admin-access-ipv4-addresses
Description
Shows allowed IP addresses for admin access.
Syntax
show admin-access-ipv4-addresses
Parameters
Parameter Description
n/a
Example
show admin-access-ipv4-addresses
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 84
delete admin-access-ipv4-address-all
delete admin-access-ipv4-address-all
Description
Deletes all configured IPv4 addresses from which the administrator can remotely access the appliance
according to configuration.
Syntax
delete admin-access-ipv4-address-all
Parameters
Parameter Description
n/a
Example
delete admin-access-ipv4-address-all
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 85
administrator
administrator
Relevant commands for admininstrators.
add administrator
Description
Adds a new user who can access the administration web portal and SSH.
Syntax
Parameters
Parameter Description
password-hash Virtual field used for calculating a hashed password
Type: An encrypted password
permission The administrator role and permissions
Options: read-write, readonly, networking
username Indicates the administrator user name
Type: A string that contains [A-Z], [0-9], and '_' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 86
delete administrator
delete administrator
Description
Deletes an existing defined administrator. The system will not allow deletion of the last administrator.
Syntax
Parameters
Parameter Description
username Indicates the administrator user name
Type: A string that contains [A-Z], [0-9], and '_' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 87
set administrator
set administrator
Configures an existing user with administrator privileges.
set administrator
Description
Configures a new password for an existing administrator. You will be prompted to add a new password
following this command (this command cannot be used in a script).
Syntax
Parameters
Parameter Description
username Indicates the administrator user name
Type: A string that contains [A-Z], [0-9], and '_' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 88
set administrator
set administrator
Description
Configures an existing administrator's permission level and password (by hash).
Syntax
Parameters
Parameter Description
password-hash Virtual field used for calculating a hashed password
Type: An encrypted password
permission The administrator role and permissions
Options: read-write, readonly, networking
username Indicates the administrator user name
Type: A string that contains [A-Z], [0-9], and '_' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 89
set administrators
set administrators
Configure users with administrator privileges through a RADIUS server.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 90
set administrators
set administrators
Description
Configures users with administrator privileges through a RADIUS server.
Syntax
Parameters
Parameter Description
permission Administrators role
Options: read-write, readonly, networking
radius-auth Administrators RADIUS authentication
Type: Boolean (true/false)
radius-groups RADIUS groups for authentication. Example: RADIUS-group1, RADIUS-class2
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_', ',' and space characters
use-radius-groups Use RADIUS groups for authentication
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 91
show administrator
show administrator
Description
Shows settings of an existing user with administrator privileges.
Syntax
Parameters
Parameter Description
username Indicates the administrator user name
Type: A string that contains [A-Z], [0-9], and '_' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 92
show administrators
show administrators
Shows settings of all users with administrator privileges.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 93
show administrators
show administrators
Description
Shows settings of all users with administrator privileges.
Syntax
show administrators
Parameters
Parameter Description
n/a
Example
show administrators
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 94
show administrators
show administrators
Description
Shows advanced settings of all users with administrator privileges.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 95
show administrators
autogmt
AutoGMT allows the user to automatically determine the gateway’s location and time zone without user
input in the First Time Configuration Wizard.
set-autogmt
Description
Configure to automatically determine the gateway’s location and time zone without user input in the First
Time Configuration Wizard.
Note – In the "set privacy-settings advanced-settings" on page 693 command, the consent flags must be on
to enable this feature:
set privacy-settings advanced-settings customer-consent true location-service-
consent true
Syntax
Parameters
Parameter Description
n/a
Example
set autogmt on
show-autogmt
Description
Shows if the AutoGMT feature to automatically determine the gateway’s location and time zone is turned on
or off.
Syntax
show autogmt
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 96
show administrators
Parameters
Parameter Description
n/a
Example
show autogmt
Output
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 97
administrators radius-auth
administrators radius-auth
Relevant commands for administrator radius authentication.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 98
set administrators radius-auth
set administrators radius-auth
Description
Configure the administrator role on the RADIUS.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 99
set administrators radius-auth (legacy mode)
set administrators radius-auth (legacy mode)
Description
Use the default role for all RADIUS users.text.
Syntax
Parameters
Parameter Description
admin role n Read Only
n Read-Write
n Networking
group_name The name of the radius group
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 100
show administrators radius-auth
show administrators radius-auth
Description
Shows RADIUS related settings for users with administrator privileges.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 101
show administrators radius-auth
administrators roles-settings
Commands relevant for configuring administrator roles
set administrators roles-settings
Description
Configure settings for administrator roles.
Syntax
Parameters
Parameter Description
customize- Customize administrators roles permissions
roles Type: Boolean (true/false)
roles-conf The configuration of administrator roles in base64 format. To get the right configuration,
contact Check Point Support.
Type: base64
Example
show administrators roles-settings
Description
Show settings for administrator roles.
Syntax
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 102
show administrators radius-auth
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 103
administrator session-settings
administrator session-settings
Relevant commands for administrator session settings.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 104
set administrator session-settings
set administrator session-settings
Description
Configures session settings for administrators. The settings are global for all administrators.
Syntax
Parameters
Parameter Description
inactivity-timeout Allowed web interface session idle time before automatic logout is executed (in
minutes)
Type: A number with no fractional part (integer)
lock-period Once locked out, the administrator will be unable to login for this long
Type: A number with no fractional part (integer)
lockout-enable Limit administrators login failure attempts
Options: on, off
max-lockout- The maximum number of consecutive login failure attempts before the administrator
attempts is locked out
Type: A number with no fractional part (integer)
password- Set of additional restrictions on administrator passwords, according to the selected
complexity-level mode
Options: low, high
password- Number of days before administrator is required to change his password. Takes
expiration- effect only if password complexity level is set to 'high'
timeout Type: A number with no fractional part (integer)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 105
show administrator session-settings
show administrator session-settings
Description
Shows session settings for users with administrator privileges.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 106
show adsl statistics
show adsl statistics
Description
Shows statistics regarding the DSL internet connection (applicable on appliance models with DSL).
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 107
aggressive-aging
aggressive-aging
Relevant commands for aggressive aging.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 108
set aggressive-aging
set aggressive-aging
Configures aggressive aging feature's behavior. Aggressive Aging is designed to optimize how the device is
dealing with a large connection number by aggressively reducing the timeout of existing connections when
necessary.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 109
set aggressive-aging
set aggressive-aging
Description
Configures aggressive aging default reduced timeouts.
Syntax
Parameters
Parameter Description
connt-limit-high- watermark-pct Connection table percentage limit
Type: A number with no fractional part (integer)
connt-mem-high- watermark-pct Memory consumption percentage limit
Type: A number with no fractional part (integer)
general Enable aggressive aging of connections
Type: Boolean (true/false)
icmp-timeout ICMP connections reduced timeout
Type: A number with no fractional part (integer)
icmp-timeout-enable Enable reduced timeout for ICMP connections
Type: Boolean (true/false)
log Tracking options for aggressive aging
Options: log, none
memory-conn-status Choose when aggressive aging timeouts are enforced
Options: both, connections, memory
other-timeout Other IP protocols reduced timeout
Type: A number with no fractional part (integer)
other-timeout-enable Enable reduced timeout for non TCP/UDP/ICMP connections
Type: Boolean (true/false)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 110
set aggressive-aging
Parameter Description
pending-timeout Pending Data connections reduced timeout
Type: A number with no fractional part (integer)
pending-timeout- enable Enable reduced timeout for non TCP/UDP/ICMP connections
Type: Boolean (true/false)
tcp-end-timeout TCP termination reduced timeout
Type: A number with no fractional part (integer)
tcp-end-timeout- enable Enable reduced timeout for TCP termination
Type: Boolean (true/false)
tcp-start-timeout TCP handshake reduced timeout
Type: A number with no fractional part (integer)
tcp-start-timeout- enable Enable reduced timeout for TCP handshake
Type: Boolean (true/false)
tcp-timeout TCP session reduced timeout
Type: A number with no fractional part (integer)
tcp-timeout-enable Enable reduced timeout for TCP session
Type: Boolean (true/false)
udp-timeout UDP connections reduced timeout
Type: A number with no fractional part (integer)
udp-timeout-enable Enable reduced timeout for UDP connections
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 111
set aggressive-aging
set aggressive-aging
Description
Configures aggressive aging advanced settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 112
show aggressive-aging
show aggressive-aging
Shows aggressive aging settings.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 113
show aggressive-aging
show aggressive-aging
Description
Shows aggressive aging settings.
Syntax
show aggressive-aging
Parameters
Parameter Description
n/a
Example
show aggressive-aging
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 114
show aggressive-aging
show aggressive-aging
Description
Shows aggressive aging advanced settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 115
antispam
antispam
Relevant commands for Anti-Spam Software Blade and settings.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 116
set antispam
set antispam
Configures policy for Anti-Spam blade.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 117
set antispam
set antispam
Description
Configures the policy for Anti-Spam blade.
Syntax
Parameters
Parameter Description
action-spam-email- Action to be used upon spam detection in email content: block, flag-header,
content flag-subject
Options: block, flag-header, flag-subject
action-suspected- spam- Action to be used upon suspected spam detection in email content: block,
email-content flag-header, flag-subject
Options: block, flag-header, flag-subject
detect-mode Detect-Only mode: on, off
Type: Boolean (true/false)
detection-method Type of spam detection: Either Sender's IP address or both Sender's IP
address and content based detection
Options: email-content, sender-ipaddr-reputation-only
flag-subject-stamp Text to add to spam emails' subject (depends on action chosen for detected
spam)
Type: A string of alphanumeric characters with space between them
flag-suspected-spam- Text to add to suspected spam emails subject (depends on action chosen
subject-stamp for detected spam)
Type: A string of alphanumeric characters with space between them
log Tracking options for spam emails: log, alert or none
Options: none, log, alert
mode Anti-Spam blade mode: on, off
Options: on, off
specify-suspected- spam- Handle suspected spam emails differently from spam emails
settings Type: Boolean (true/false)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 118
set antispam
Parameter Description
suspected-spam-log Tracking options for suspected spam emails: log, alert or none
Options: none, log, alert
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 119
set antispam
set antispam
Description
Configures advanced setting for the Anti-Spam blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 120
set antispam
set antispam
Description
Configures advanced setting for the Anti-Spam blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 121
set antispam
set antispam
Description
Configures advanced setting for the Anti-Spam blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 122
set antispam
set antispam
Description
Configures advanced setting for the Anti-Spam blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 123
set antispam
set antispam
Description
Configures advanced setting for the Anti-Spam blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 124
set antispam
set antispam
Description
Configures advanced setting for the Anti-Spam blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 125
set antispam
set antispam
Description
Configures advanced setting for the Anti-Spam blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 126
set antispam
set antispam
Description
Configures advanced setting for the Anti-Spam blade.
Syntax
<spam-engine-all-mail-track>
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 127
show antispam
show antispam
Shows the configured policy for the Anti-Spam blade.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 128
show antispam
show antispam
Description
Shows the configured policy for the Anti-Spam blade.
Syntax
show antispam
Parameters
Parameter Description
n/a
Example
show antispam
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 129
show antispam
show antispam
Description
Shows the advanced settings in the configured policy for the Anti-Spam blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 130
antispam allowed-sender
antispam allowed-sender
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 131
add antispam allowed-sender
add antispam allowed-sender
Adds a new Anti-Spam "allow" exception.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 132
add antispam allowed-sender
add antispam allowed-sender
Description
Adds a new Anti-Spam "allow" exception for a specific IP address.
Syntax
Parameters
Parameter Description
ipv4-addr Anti-Spam allowed IP address
Type: IP address
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 133
add antispam allowed-sender
add antispam allowed-sender
Description
Adds a new Anti-Spam "allow" exception for a sender email or domain.
Syntax
Parameters
Parameter Description
sender-or-domain Anti-Spam allowed domain or sender
Type: A domain or email address
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 134
delete antispam allowed-sender
delete antispam allowed-sender
Deletes an existing Anti-Spam "allow" exception.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 135
delete antispam allowed-sender
delete antispam allowed-sender
Description
Deletes all existing Anti-Spam "allow" exceptions.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 136
delete antispam allowed-sender
delete antispam allowed-sender
Description
Deletes an existing Anti-Spam "allow" exception for sender's email or domain.
Syntax
Parameters
Parameter Description
sender-or-domain Anti-Spam allowed domain or sender
Type: A domain name or email address
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 137
delete antispam allowed-sender
delete antispam allowed-sender
Description
Deletes an existing Anti-Spam "allow" exception for a specific IPv4 address.
Syntax
Parameters
Parameter Description
ipv4-addr Anti-Spam allowed IP address
Type: IP address
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 138
show antispam allowed-senders
show antispam allowed-senders
Description
Shows the "allowed" exceptions for the Anti-Spam blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 139
antispam blocked-sender
antispam blocked-sender
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 140
add antispam blocked-sender
add antispam blocked-sender
Adds a new Anti-Spam "block" exception.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 141
add antispam blocked-sender
add antispam blocked-sender
Description
Adds a new Anti-Spam "block" exception for a specific IP address.
Syntax
Parameters
Parameter Description
ipv4-addr Anti-Spam blocked IP address
Type: IP address
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 142
add antispam blocked-sender
add antispam blocked-sender
Description
Adds a new Anti-Spam "block" exception for a sender email or domain.
Syntax
Parameters
Parameter Description
sender-or-domain Anti-Spam blocked domain or sender
Type: A domain name or email address
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 143
delete antispam blocked-sender
delete antispam blocked-sender
Deletes an existing Anti-Spam "block" exception.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 144
delete antispam blocked-sender
delete antispam blocked-sender
Description
Deletes all existing Anti-Spam "block" exceptions.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 145
delete antispam blocked-sender
delete antispam blocked-sender
Description
Deletes an existing Anti-Spam "block" exception for sender's email or domain.
Syntax
Parameters
Parameter Description
sender-or-domain Anti-Spam blocked domain or sender
Type: A domain name or email address
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 146
delete antispam blocked-sender
delete antispam blocked-sender
Description
Deletes an existing Anti-Spam "block" exception for a specific IPv4 address.
Syntax
Parameters
Parameter Description
ipv4-addr Anti-Spam blocked IP address
Type: IP address
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 147
show antispam blocked-senders
show antispam blocked-senders
Description
Shows the "blocked" exceptions for the Anti-Spam blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 148
application
application
Relevant commands for application.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 149
add application
add application
Adds a new custom application object (string or regular expression signature over URL).
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 150
add application
add application
Description
Adds a new custom application object (string or regular expression signature over URL).
Syntax
Parameters
Parameter Description
application-name Application name
Type: URL
application-url Contains the URLs related to this application
category The primary category for the application (the category which is the most relevant)
regex-url Indicates if regular expressions are used instead of partial strings
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 151
add application
add application
Description
Simplified method for adding a new custom application object (string over URL)
Syntax
add application-url <application-url>
Parameters
Parameter Description
application-url Application URL
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 152
delete application
delete application
Deletes an existing custom application object (string or regular expression signature over URL).
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 153
delete application
delete application
Description
Deletes an existing custom application object by application ID.
Syntax
Parameters
Parameter Description
application-id The ID of the application
Type: A number with no fractional part (integer)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 154
delete application
delete application
Description
Deletes an existing custom application object by application name.
Syntax
Parameters
Parameter Description
application-name Application name
Type: URL
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 155
find application
find application
Description
Find an application by name (or partial string) to view further details regarding it.
Syntax
Parameters
Parameter Description
application-name Application or group name
Type: String
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 156
set application
set application
Configures an existing custom application object.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 157
set application
set application
Description
Adds a URL to an existing custom application object by name.
Syntax
Parameters
Parameter Description
application-name Application name
Type: URL
url Application URL
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 158
set application
set application
Description
Removes a URL from an existing custom application object by name.
Syntax
Parameters
Parameter Description
application-name Application name
Type: URL
url Application URL
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 159
set application
set application
Description
Adds a URL to an existing custom application object by ID.
Syntax
Parameters
Parameter Description
application-id The ID of the application
Type: A number with no fractional part (integer)
url Application URL
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 160
set application
set application
Description
Removes a URL from an existing custom application object by ID.
Syntax
Parameters
Parameter Description
application-id The ID of the application
Type: A number with no fractional part (integer)
url Application URL
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 161
set application
set application
Description
Adds a category to an existing custom application object by name.
Syntax
Parameters
Parameter Description
application-name Application name
Type: URL
category Category name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 162
set application
set application
Description
Removes a category from an existing custom application object by name.
Syntax
Parameters
Parameter Description
application-name Application name
Type: URL
category Category name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 163
set application
set application
Description
Adds a category to an existing custom application object by ID.
Syntax
Parameters
Parameter Description
application-id The ID of the application
Type: A number with no fractional part (integer)
category Category name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 164
set application
set application
Description
Removes a category from an existing custom application object by ID.
Syntax
Parameters
Parameter Description
application-id The ID of the application
Type: A number with no fractional part (integer)
category Category name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 165
set application
set application
Description
Configures an existing custom application by ID.
Syntax
Parameters
Parameter Description
application-id The ID of the application
Type: A number with no fractional part (integer)
category The primary category for the application (the category which is the most relevant)
regex-url Indicates if regular expressions are used instead of partial strings
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 166
set application
set application
Description
Configures an existing custom application by name.
Syntax
Parameters
Parameter Description
application-name Application name
Type: URL
category The primary category for the application (the category which is the most relevant)
regex-url Indicates if regular expressions are used instead of partial strings
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 167
show application
show application
Shows details for a specific application in the Application Control database.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 168
show application
show application
Description
Shows details for a specific application in the Application Control database by application name.
Syntax
Parameters
Parameter Description
application-name Application or group name
Type: String
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 169
show application
show application
Description
Shows details for a specific application in the Application Control database by application ID.
Syntax
Parameters
Parameter Description
application-id The ID of the application or the group
Type: A number with no fractional part (integer)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 170
show applications
show applications
Description
Shows details of all applications.
Syntax
show applications
Parameters
Parameter Description
n/a
Example
show applications
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 171
application-control
application-control
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 172
set application-control
set application-control
Description
Configures the default policy for the Application Control and URL filtering blades.
Syntax
Parameters
Parameter Description
block-file-sharing- Block file sharing using torrents and peer-to-peer applications
applications Type: Boolean (true/false)
block- Control content by blocking Internet access to websites with inappropriate content
inappropriate- such as sex, violence, weapons, gambling, and alcohol
content Type: Boolean (true/false)
block-other- Manually add and block applications or categories of URLs to a group of
undesired- undesired applications
applications Type: Boolean (true/false)
block-security- Block applications and URLs that can be a security risk and are categorized as
categories spyware, phishing, botnet, spam, anonymizer, or hacking
Type: Boolean (true/false)
limit-bandwidth Indicates if applications that use a lot of bandwidth are limited (also used for QoS)
Type: Boolean (true/false)
limit-download If true, traffic for downloading is limited to the value in maxLimitedDownload
Type: Boolean (true/false)
limit-upload If true, traffic for uploading is limited to the value in maxLimitedDownload
Type: Boolean (true/false)
mode Applications & URLs mode - true for on, false for off
Type: Boolean (true/false)
set-limit The limit, in kbps, for downloading
Type: A number with no fractional part (integer)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 173
set application-control
Parameter Description
url-flitering-only Indicates if enable URL Filtering and detection only mode is enabled
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 174
show application-control
show application-control
Description
Shows the configured policy for the Application Control blade
Syntax
show application-control
Parameters
Parameter Description
n/a
Example
show application-control
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 175
show application-control other-undesired-applications
show application-control other-undesired-
applications
Description
Shows the content of the custom "Other Undesired Applications" group. This group can be chosen to be
blocked by default by the Application Control policy.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 176
application-control-engine-settings
application-control-engine-settings
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 177
set application-control-engine-settings
set application-control-engine-settings
Configures Application Control blade's advanced engine settings.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 178
set application-control-engine-settings
set application-control-engine-settings
Description
Configures Application Control blade's advanced engine settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 179
set application-control-engine-settings
set application-control-engine-settings
Description
Configures Application Control blade's advanced engine settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 180
set application-control-engine-settings
set application-control-engine-settings
Description
Configures Application Control blade's advanced engine settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 181
set application-control-engine-settings
set application-control-engine-settings
Description
Configures Application Control blade's advanced engine settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 182
set application-control-engine-settings
set application-control-engine-settings
Description
Configures Application Control blade's advanced engine settings.
Syntax
<track-browse-time>
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 183
set application-control-engine-settings
set application-control-engine-settings
Description
Configures Application Control blade's advanced engine settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 184
set application-control-engine-settings
set application-control-engine-settings
Description
Configures Application Control blade's advanced engine settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 185
show application-control-engine-settings
show application-control-engine-settings
Description
Shows advanced settings of the Application Control blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 186
application-group
application-group
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 187
add application-group
add application-group
Description
Adds a new group object for applications.
Syntax
Parameters
Parameter Description
name Application group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .
&) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 188
delete application-group
delete application-group
Deletes an existing group object of applications.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 189
delete application-group
delete application-group
Description
Deletes an existing group object of applications by group object name.
Syntax
Parameters
Parameter Description
name Application group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .
&) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 190
delete application-group
delete application-group
Description
Deletes an existing group object of applications by group object ID.
Syntax
Parameters
Parameter Description
application-group-id The ID of the application group
Type: A number with no fractional part (integer)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 191
set application-group
set application-group
Configures an existing application group object.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 192
set application-group
set application-group
Description
Adds an application to an existing application group object by application's name.
Syntax
Parameters
Parameter Description
application- Application or group name
name
name Application group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .
&) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 193
set application-group
set application-group
Description
Removes an application from an existing application group object by application's name.
Syntax
Parameters
Parameter Description
application- Application or group name
name
name Application group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .
&) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 194
set application-group
set application-group
Description
Adds an application to an existing application group object by application's ID.
Syntax
Parameters
Parameter Description
application-id The ID of the application or the group
name Application group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .
&) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 195
set application-group
set application-group
Description
Removes an application from an existing application group object by application's ID.
Syntax
Parameters
Parameter Description
application-id The ID of the application or the group
name Application group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .
&) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 196
set application-group
set application-group
Description
Adds an application to an existing application group object by application's name using group object's ID.
Syntax
Parameters
Parameter Description
application-group-id The ID of the application group
Type: A number with no fractional part (integer)
application-name Application or group name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 197
set application-group
set application-group
Description
Removes an application from an existing application group object by application's name using group
object's ID.
Syntax
Parameters
Parameter Description
application-group-id The ID of the application group
Type: A number with no fractional part (integer)
application-name Application or group name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 198
set application-group
set application-group
Description
Adds an application to an existing application group object by application's ID using group object's ID.
Syntax
Parameters
Parameter Description
application-group-id The ID of the application group
Type: A number with no fractional part (integer)
application-id The ID of the application or the group
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 199
set application-group
set application-group
Description
Removes an application from an existing application group object by application's ID using group object's
ID.
Syntax
Parameters
Parameter Description
application-group-id The ID of the application group
Type: A number with no fractional part (integer)
application-id The ID of the application or the group
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 200
show application-group
show application-group
shows the configuration of the Application group objects.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 201
show application-group
show application-group
Description
Shows the configuration of a specific application group object by ID.
Syntax
Parameters
Parameter Description
application-group-id The ID of the application group
Type: A number with no fractional part (integer)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 202
show application-group
show application-group
Description
Shows the configuration of a specific application group object by name.
Syntax
Parameters
Parameter Description
name Application group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .
&) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 203
show application-groups
show application-groups
Description
Shows the configuration of all specific application group objects.
Syntax
show application-groups
Parameters
Parameter Description
n/a
Example
show application-groups
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 204
antispoofing
antispoofing
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 205
set antispoofing
set antispoofing
Description
Configures the activation of the IP address Anti-Spoofing feature.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 206
show antispoofing
show antispoofing
Description
Shows the configuration for IP addresses Anti-Spoofing functionality.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 207
backup settings
backup settings
Description
Creates a backup file that contains the current settings for the appliance and saves them to a file. The file is
saved to either a USB device or TFTP server. You can use these options when the backup file is created:
n Specific file name (The default file name contains the current image and a date and time stamp)
n Password encryption
n Backup policies
n Add a comment to the file
Syntax
Parameters
Parameter Description
comment Comment that is added to the file.
filename Name of the backup file.
pass Password for the file. Alphanumeric and special characters are allowed.
serverIP IPv4 address of the TFTP server.
Return Value
0 on success, 1 on failure
Example
Output
Success prints OK. Failure shows an appropriate error message.
Comments
When saving the backup file to a USB device, the backup settings command fails if there are two USB
devices connected to the appliance.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 208
show backup settings
show backup settings
Description
Shows previous backup information of the appliance's settings.
show backup-settings-log shows the log file of previous backup settings operations.
Syntax
Parameters
Parameter Description
server IP address or host name of the TFTP server
file Name of backup file
Example
show backup-settings-log
Output
Success shows backup settings information. Failure shows an appropriate error message.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 209
blade-update-schedule
blade-update-schedule
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 210
set blade-update-schedule
set blade-update-schedule
Configures schedule for Software Blade updates.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 211
set blade-update-schedule
set blade-update-schedule
Description
Configures schedule forSoftware Blades updates.
Syntax
Parameters
Parameter Description
day-of-month If the update occurs monthly, this is the day in which it occurs
Type: A number with no fractional part (integer)
day-of-week If the update occurs weekly, this is the weekday in which it occurs
Options: sunday, monday, tuesday, wednesday, thursday, friday, saturday
hour-interval If the update occurs hourly, this indicates the hour interval between each update
Type: A number with no fractional part (integer)
recurrence The recurrence of the updates - hourly, daily, weekly or monthly
Type: Press TAB to see available options
schedule-anti- Indicates if Anti-Bot blade is automatically updated according to configured
bot schedule
Type: Boolean (true/false)
schedule-anti- Indicates if Anti-Virus blade is automatically updated according to configured
virus schedule
Type: Boolean (true/false)
schedule-appi Indicates if Application Control blade is automatically updated according to
configured schedule
Type: Boolean (true/false)
schedule-ips Indicates if IPS blade is automatically updated according to configured schedule
Type: Boolean (true/false)
time The hour of the update (Format: HH:MM in 24 hour clock)
Type: A time format hh:mm
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 212
set blade-update-schedule
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 213
set blade-update-schedule
set blade-update-schedule
Description
Configures advanced settings for Software Blade updates.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 214
set blade-update-schedule
set blade-update-schedule
Description
Configures advanced settings for Software Blade updates.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 215
show blade-update-schedule
show blade-update-schedule
Shows the configuration of Software Blade updates schedule.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 216
show blade-update-schedule
show blade-update-schedule
Description
Shows the configuration of Software Blade updates schedule
Syntax
show blade-update-schedule
Parameters
Parameter Description
n/a
Example
show blade-update-schedule
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 217
show blade-update-schedule
show blade-update-schedule
Description
Shows advanced settings of Software Blade updates schedule.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 218
bookmark
bookmark
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 219
add bookmark
add bookmark
Description
Adds a new bookmark link that will appear for VPN remote access users in the SNX VPN remote access
landing page.
Syntax
add bookmark label <label> url <url> [ tooltip <tooltip> ] [ type <type> ]
[ is-global <is-global> ] [ user-name <user-name> ] [ password <password> ]
[ screen-width <screen-width> ] [ screen-height <screen-height> ]
Parameters
Parameter Description
is-global Indicates if the bookmark will be displayed for all remote access users
Type: Boolean (true/false)
label Text for the bookmark in the SSL Network Extender portal
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
password The password for remote desktop connection
Type: A string that contains alphanumeric and special characters
screen-height The height of the screen when the bookmark is remote desktop
Type: A number with no fractional part (integer)
screen-width The width of the screen when the bookmark is remote desktop
Type: A number with no fractional part (integer)
tooltip Tooltip for the bookmark in the SSL Network Extender portal
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
type The type of the bookmark - link or remote desktop connection
Options: link, rdp
user-name The user name for remote desktop connection
Type: A string that contains (0-9, a-z, - . @) up to 64 characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 220
delete bookmark
delete bookmark
Deletes an existing bookmark link that appears in the SNX VPN remote access landing page.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 221
delete bookmark
delete bookmark
Description
Deletes an existing bookmark link by label.
Syntax
Parameters
Parameter Description
label Text for the bookmark in the SSL Network Extender portal
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 222
delete bookmark
delete bookmark
Description
Deletes all existing bookmark links.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 223
set bookmark
set bookmark
Description
Configures an existing bookmark shown to users in the SNX landing page.
Syntax
Parameters
Parameter Description
is-global Indicates if the bookmark will be displayed for all remote access users
Type: Boolean (true/false)
label Text for the bookmark in the SSL Network Extender portal
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
new-label Text for the bookmark in the SSL Network Extender portal
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
password The password for remote desktop connection
Type: A string that contains alphanumeric and special characters
screen-height The height of the screen when the bookmark is remote desktop
Type: A number with no fractional part (integer)
screen-width The width of the screen when the bookmark is remote desktop
Type: A number with no fractional part (integer)
tooltip Tooltip for the bookmark in the SSL Network Extender portal
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
type The type of the bookmark - link or remote desktop connection
Options: link, rdp
url Bookmark URL - should start with http:// or https:// for a bookmark of type link
Type: URL
user-name The user name for remote desktop connection
Type: A string that contains (0-9, a-z, - . @) up to 64 characters without spaces
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 224
set bookmark
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 225
show bookmark
show bookmark
Description
Shows the configuration of a bookmark defined to be shown to users when connecting to the SNX portal
using remote access VPN.
Syntax
Parameters
Parameter Description
label Text for the bookmark in the SSL Network Extender portal
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 226
show bookmarks
show bookmarks
Description
Shows all bookmarks defined to be shown to users when connecting to the SNX portal using remote access
VPN.
Syntax
show bookmarks
Parameters
Parameter Description
n/a
Example
show bookmarks
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 227
bridge
bridge
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 228
add bridge
add bridge
Description
Adds a new bridge.
Syntax
Parameters
Parameter Description
name Bridge name
Type: A bridge name should be br0-9
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 229
delete bridge
delete bridge
Description
Deletes an existing bridge.
Syntax
Parameters
Parameter Description
name Bridge name
Type: A bridge name should be br0-9
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 230
set bridge
set bridge
Configures an existing bridge interface.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 231
set bridge
set bridge
Description
Configures an existing bridge interface.
Syntax
Parameters
Parameter Description
name Bridge name
Type: A bridge name should be br0-9
stp Spanning Tree Protocol mode
Options: on, off
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 232
set bridge
set bridge
Description
Adds an existing network/interface to an existing bridge.
Syntax
Parameters
Parameter Description
member Network name
name Bridge name
Type: A bridge name should be br0-9
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 233
set bridge
set bridge
Description
Removes an existing network/interface from an existing bridge.
Syntax
Parameters
Parameter Description
member Network name
name Bridge name
Type: A bridge name should be br0-9
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 234
show bridge
show bridge
Description
Shows configuration and statistics of a defined bridge.
Syntax
Parameters
Parameter Description
name Bridge name
Type: A bridge name should be br0-9
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 235
show bridges
show bridges
Description
Shows details of all defined bridges.
Syntax
show bridges
Parameters
Parameter Description
n/a
Example
show bridges
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 236
show bridges
show cellular-modem-status
Description
Show the status of the cellular (LTE) modem..
Syntax
show cellular-modem-status
Parameters
Parameter Description
N/A
Example
show cellular-modem-status
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 237
show clock
show clock
Description
Shows current system date and time.
Syntax
show clock
Parameters
Parameter Description
n/a
Example
show clock
Output
Success shows date and time. Failure shows an appropriate error message.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 238
cloud-deployment
cloud-deployment
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 239
set cloud-deployment
set cloud-deployment
Description
Configures different settings for zero-touch deployment. Command is relevant to preset files.
Syntax
Parameters
Parameter Description
cloud-url The DNS or IP address through which the device will connect to the cloud service
Type: URL
container Container
Type: String
gateway-name The appliance name used to identify the gateway
Type: A string that contains [A-Z], [0-9] and '-' characters
template Template
Type: String
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 240
show cloud-deployment
show cloud-deployment
Description
Shows the configuration of cloud management connection.
Syntax
show cloud-deployment
Parameters
Parameter Description
n/a
Example
show cloud-deployment
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 241
cloud-notifications
cloud-notifications
These commands are relevant for Cloud notifications
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 242
set cloud-notification
set cloud-notification
Description
Turn on/off a specific notification type.
Syntax
Parameters
Parameter Description
notification-type Describes the notification type including:
n license-expired
n license-about-to-expire
n license-activated
n infected-device
n malicious-file-blocked
n malicious-file-downloaded
n firmware-upgrade-available
n new-device
n system-up
n unexpected-reboot
n primary-internet-up
n secondary-internet-up
n malicious-mail-blocked
n malicious-mail-received
n reconnected-device
mode Enable sending the chosen cloud notification type.
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 243
show cloud-notifications
show cloud-notifications
Description
Show mode for all types of notifications
Syntax
show cloud-notifications
Parameters
Parameter Description
n/a
Example
show cloud-notifications
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 244
send cloud-report
send cloud-report
Description
Force sending a report to Cloud Services.
Syntax
Parameters
Parameter Description
type The report type
Options: top-last-hour, top-last-day, top-last-week, top-last-month, 3d
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 245
cloud-services
cloud-services
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 246
reconnect cloud-services
reconnect cloud-services
Description
Force a manual reconnection to Cloud Services.
Syntax
reconnect cloud-services
Parameters
Parameter Description
n/a
Example
reconnect cloud-services
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 247
set cloud-services
set cloud-services
Configures settings for cloud/SMP management connection.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 248
set cloud-services
set cloud-services
Description
Configures settings for cloud/SMP management connection.
Syntax
Parameters
Parameter Description
activation-key A key received from the Cloud Services provider which is used to initialize the
connection to the Cloud Services
Type: String
confirm- Is the service center URL is a trusted certificate
untrusted- Type: Boolean (true/false)
certificate
gateway-id Gateway id (in the format <gateway name>.<portal name>). This is not needed if an
activation-key was configured.
Type: cloudGwName
mode Indicates if the device is managed by a cloud service
Options: off, on
registration- Registration key that acts as a password when connecting to the cloud service for the
key first time. This is not needed if an activation-key was configured.
Type: A registration key
service-center The DNS or IP address through which the device will connect to the cloud service for
the first time. This is not needed if an activation-key was configured.
Type: URL
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 249
set cloud-services
set cloud-services
Description
Configures advanced settings for cloud/SMP management connection.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 250
show cloud-services
show cloud-services
Description
Shows advanced settings of cloud management connection.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 251
show cloud-services connection-details
show cloud-services connection-details
Description
Shows connection details for cloud management connection.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 252
cloud-services-firmware-upgrade
cloud-services-firmware-upgrade
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 253
set cloud-services-firmware-upgrade
set cloud-services-firmware-upgrade
Configure settings for the "firmware upgrade" Cloud Services.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 254
set cloud-services-firmware-upgrade
set cloud-services-firmware-upgrade
Description
Configures settings for the "firmware upgrade" Cloud Services.
Syntax
Parameters
Parameter Description
activate Enable auto firmware upgrades. Upgrades may occur immediately or be scheduled
according to a predefined frequency
Type: Boolean (true/false)
day-of-month Choose the desired day of the month
Type: A number with no fractional part (integer)
day-of-week Choose the desired day of week
Options: sunday, monday, tuesday, wednesday, thursday, friday, saturday
frequency Indicates the preferred time to perform upgrade once a new firmware is detected
Type: Press TAB to see available options
time The hour of the upgrade (Format: HH:MM in 24 hour clock)
Type: A time format hh:mm
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 255
set cloud-services-firmware-upgrade
set cloud-services-firmware-upgrade
Description
Configures advanced settings for the "firmware upgrade" Cloud Services.
Syntax
<max-num-of-retries>
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 256
set cloud-services-firmware-upgrade
set cloud-services-firmware-upgrade
Description
Configures advanced settings for the "firmware upgrade" Cloud Services.
Syntax
<timeout-until-retry>
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 257
show cloud-services-firmware-upgrade
show cloud-services-firmware-upgrade
Shows configuration of the "Firmware Upgrade" Cloud Services.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 258
show cloud-services-firmware-upgrade
show cloud-services-firmware-upgrade
Description
Shows configuration of the "Firmware Upgrade" Cloud Services.
Syntax
show cloud-services-firmware-upgrade
Parameters
Parameter Description
n/a
Example
show cloud-services-firmware-upgrade
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 259
show cloud-services-firmware-upgrade
show cloud-services-firmware-upgrade
Description
Shows advanced settings of the "Firmware Upgrade" Cloud Services.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 260
show cloud-service managed-blades
show cloud-service managed-
blades
Description
Shows the currently managed blades by the cloud management.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 261
show cloud-services managed-services
show cloud-services managed-
services
Description
Shows the currently managed services by the cloud management.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 262
fetch cloud-services policy
fetch cloud-services policy
Description
Fetch configuration now from your Cloud Services Security Management Server.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 263
show cloud-services status
show cloud-services status
Description
Shows the current status of the cloud management connection.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 264
show commands
show commands
Description
Shows all available CLI commands.
Syntax
show commands
Parameters
Parameter Description
n/a
Example
show commands
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 265
cphaprob
cphaprob
Description
Defines and manages the critical cluster member properties of the appliance. When a critical process fails,
the appliance is considered to have failed.
Syntax
Parameters
Parameter Description
register Registers <appliance> as a critical process.
-a Lists all devices in the cluster.
-d <device> The name of the device as it appears in the output of the cphaprob list.
-p The configuration change is permanent and applies after the appliance reboots.
-t <timeout> If <device> fails to contact ClusterXL in <timeout> seconds, <device> is considered
to have failed.
To disable this parameter, enter the value 0.
-s Status to be reported.
ok - <appliance> is alive
init - <appliance> is initializing
problem - <appliance> has failed
-f <file> Option to automatically register several appliances. The file defined in the <file> field
register should contain the list of appliances with these parameters:
n <device>
n <timeout>
n Status
unregister Unregisters <device> as a critical process.
report Reports the status of the <device> to the gateway.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 266
cphaprob
Parameter Description
list Displays that state of:
-i - Internal (as well as external) devices, such as interface check and High
Availability initialization.
-e - External devices, such as devices registered by the user or outside the kernel.
For example, fwd, sync, filter.
-ia - All devices, including those used for internal purposes, such as note initialization
and load-balance configuration.
state Displays the state of all the gateways in the High Availability configuration.
if Displays the state of interfaces.
Example
Output
Success prints OK. Failure shows an appropriate error message.
These are some typical scenarios for the cphaprob command.
Argument Description
Examples
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 267
cphaprob
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 268
cphastop
cphastop
Description
Disables High Availability on the appliance. Running cphastopon an appliance that is a cluster member
stops the appliance from passing traffic. State synchronization also stops.
Syntax
cphastop
Parameters
Parameter Description
n/a
Return Value
0 on success, 1 on failure
Example
cphastop
Output
Success prints OK. Failure shows an appropriate error message.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 269
cpinfo
cpinfo
Description
Creates a Check Point Support Information (CPinfo) file on a machine at the time of execution.
The files is saved to a USB drive or TFTP server.
The CPinfo output file enables Check Point's support engineers to analyze setups from a remote location.
Syntax
Parameters
Parameter Description
ipaddr IPv4 address
Return Value
0 on success, 1 on failure
Example
cpinfo to-usb
Output
Success prints Creating cpinfo.txt file. Failure shows an appropriate error message.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 270
cpstart
cpstart
Start all Check Point processes and applications running on a machine.
Description
Starts firewall services.
Syntax
cpstart
Parameters
Parameter Description
n/a
Return Value
0 on success, 1 on failure
Example
cpstart
Output
Success shows Starting CP products.... Failure shows an appropriate error message.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 271
cpstat
cpstat
Description
Shows Check Point statistics for applications.
Syntax
cpstat [-p <port>] [-s <SICname>] [-f <flavor>] [-o <polling>] [-c <count>]
[-e <period>] [-x] [-j] [-d] application_flag <flag>
Parameters
Parameter Description
-p <port> Port number of the server. The default is the standard server port (18192).
-s Secure Internal Communication (SIC) name of the server.
<SICname>
-f <flavor> The flavor of the output (as it appears in the configuration file). The default is the first
flavor found in the configuration file.
-o Polling interval (seconds) specifies the pace of the results.
<polling> The default is 0, meaning the results are shown only once.
-c <count> Specifies how many times the results are shown. The default is 0, meaning the results
are repeatedly shown.
-e <period> Specifies the interval (seconds) over which 'statistical' olds are computed. Ignored for
regular olds.
-x XML output mode
-j Json output mode
-d Debug mode.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 272
cpstat
Parameter Description
<flag> One of these applications is displayed:
One of the following:
fw- Firewall component of the Security Gateway
vpn- VPN component of the Security Gateway
fg- QoS (formerly FloodGate-1)
ha- ClusterXL (High Availability)
os- OS Status
mg- for the Security Management Server
persistency- for historical status values
polsrv
uas
svr
cpsemd
cpsead
asm
ls
ca
Return Value
0 on success, 1 on failure
Example
cpstat -c 3 -o 3 fw
Output
Success shows OK. Failure shows an appropriate error message.
The following flavors can be added to the application flags:
n fw- "default", "interfaces", "all", "policy", "perf", "hmem", "kmem", "inspect", "cookies", "chains",
"fragments", "totals", "ufp", "http", "ftp", "telnet", "rlogin", "smtp", "pop3", "sync"
n vpn- "default", "product", "IKE", "ipsec", "traffic", "compression", "accelerator", "nic", "statistics",
"watermarks", "all"
n fg- "all"
n ha- "default", "all"
n os- "default", "ifconfig", "routing", "memory", "old_memory", "cpu", "disk", "perf", "multi_cpu", "multi_
disk", "all", "average_cpu", "average_memory", "statistics"
n mg- "default"
n persistency- "product", "Tableconfig", "SourceConfig"
n polsrv- "default", "all"
n uas- "default"
n svr- "default"
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 273
cpstat
n cpsemd- "default"
n cpsead- "default"
n asm- "default", "WS"
n ls- "default"
n ca- "default", "crl", "cert", user", "all"
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 274
cpstop
cpstop
Description
Stops firewall services and terminates all Check Point processes and applications running on the appliance.
Syntax
cpstop
Parameters
Parameter Description
n/a
Return Value
0 on success, 1 on failure
Example
cpstop
Output
Success shows Uninstalling Security Policy.... Failure shows an appropriate error message.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 275
cpwd_admin
cpwd_admin
Description
The cpwd_admin utility can be used to verify if a process is running and to stop and start a process if
necessary.
Syntax
cpwd_admin {del <name>|detach <name>|list|kill|exist|start_monitor|stop_
monitor|
monitor_list}
Parameters
Parameter Description
del Deletes process
detach Detaches process
list Print status of processes
kill Stops cpWatchDog
exist Checks if cpWatchDog is running
start_monitor cpwd starts monitoring this machine
stop_monitor cpwd stops monitoring this machine
monitor_list Displays list of monitoring processes
name Name of process
Return Value
0 on success, 1 on failure
Example
cpwd_admin start_monitor
Output
Success shows OK. Failure shows an appropriate error message.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 276
date
date
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 277
set date
set date
Configures the device's date and time.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 278
set date
set date
Description
Manually configure the device's date.
Syntax
Parameters
Parameter Description
date Date in the format YYYY-MM-DD
Type: A date format yyyy-mm-dd
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 279
set date
set date
Description
Manually configure the device's time.
Syntax
Parameters
Parameter Description
time Time in the format HH:MM
Type: A time format hh:mm
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 280
set date
set date
Description
Manually configure the device's time zone.
Syntax
Parameters
Parameter Description
timezone Timezone location
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 281
set date
set date
Description
Configures if the daylight savings will be changed automatically.
Syntax
Parameters
Parameter Description
timezone-dst automatic Automatic adjustment clock for daylight saving changes flag
Options: on, off
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 282
show date
show date
Shows date and time.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 283
show date
show date
Description
Shows current date of the appliance.
Syntax
show date
Parameters
Parameter Description
n/a
Example
show date
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 284
show date
show date
Description
Shows current time of the appliance.
Syntax
show time
Parameters
Parameter Description
n/a
Example
show time
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 285
show date
show date
Description
Shows current time zone of the appliance.
Syntax
show timezone
Parameters
Parameter Description
n/a
Example
show timezone
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 286
show date
show date
Description
Shows current daylight savings configuration of the appliance.
Syntax
show timezone-dst
Parameters
Parameter Description
n/a
Example
show timezone-dst
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 287
restore default-settings
restore default-settings
Description
Restores the default settings of the appliance without affecting the software image. All the custom user
settings for the appliance are deleted.
Syntax
Parameters
Parameter Description
preserve-sic Select whether to preserve your current SIC settings.
preserve-license Select whether to preserve your current license.
force Skip the confirmation question.
Return Value
0 on success, 1 on failure
Example
Comments
The appliance automatically reboots after the default settings are restored.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 288
restore default-settings
dhcp-bridge-settings
Delete this text and replace it with your own content.
show dhcp-bridge-settings
Description
Show the MAC address for the DHCP bridge.
Syntax
show dhcp-bridge-settings
Parameters
Parameter Description
n/a
Example
show dhcp-bridge-settings
set dhcp-bridge-settings
Description
Configure the MAC address for the DHCP bridge from an internal (LAN) or external port (WAN, DMZ).
Syntax
Parameters
Parameter Description
mac- Indicates whether the MAC address for the DHCP bridge is taken from an internal
assignment (LAN) or external port (WAN, DMZ).
Options: use-internal-interfaces-mac, use-external-interfaces-mac
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 289
restore default-settings
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 290
dhcp-relay
dhcp-relay
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 291
set dhcp-relay
set dhcp-relay
Description
Configures advanced settings for DHCP Relay functionality.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 292
show dhcp-relay
show dhcp-relay
Description
Shows advanced settings for DHCP relay.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 293
show dhcp servers
show dhcp servers
Description
Shows configuration for all DHCP servers.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 294
dhcp server interface
dhcp server interface
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 295
delete dhcp server interface
delete dhcp server interface
Description
Deletes the configured exclude range from the DHCP server settings of a specific network/interface.
Syntax
Parameters
Parameter Description
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 296
set dhcp server interface
set dhcp server interface
Configures DHCP server settings.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 297
set dhcp server interface
set dhcp server interface
Description
Configures a custom DHCP option.
Syntax
Parameters
Parameter Description
cliName cliName
Type: virtual
custom-option Set the name of the object
name Type: A string that contains alphanumeric characters or hyphen
data Set the desired value of the object
Type: String
tag Select a unique tag for the object
Type: A number with no fractional part (integer)
type Select the appropriate type to store your object
Options: string, int8, int16, int32, uint8, uint16, uint32, boolean, ipv4-address, ipv4-
address-array, hex-string
Example
set dhcp server interface LAN1 custom-option name MyOption type string tag
43 data TEXT
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 298
set dhcp server interface
set dhcp server interface
Description
Configures if a DHCP server is active or not on an existing network/interface.
Syntax
Parameters
Parameter Description
dhcp Use DHCP Server with a specified IP address range
Options: off, on, relay
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 299
set dhcp server interface
set dhcp server interface
Description
Configures DHCP relay functionality on an existing network/interface.
Syntax
Parameters
Parameter Description
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
relay relay-to Enter the DHCP server IP address
Type: IP address
relay-secondary This field is deprecated. Please use field 'secondary'
secondary Enter the secondary DHCP server IP address
Type: IP address
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 300
set dhcp server interface
set dhcp server interface
Description
Configures an IP address pool for a DHCP server on an existing network/interface.
Syntax
Parameters
Parameter Description
include-ip-pool DHCP range
Type: A range of IP addresses
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 301
set dhcp server interface
set dhcp server interface
Description
Configures the default gateway provided by a DHCP server on an existing network/interface.
Syntax
Parameters
Parameter Description
default-gateway A virtual field calculated by the values of the fields: dhcpGwMode & dhcpGw
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 302
set dhcp server interface
set dhcp server interface
Description
Configures the WINS mode provided by a DHCP server on an existing network/interface.
Syntax
Parameters
Parameter Description
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
wins-mode Configure the WINS Server
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 303
set dhcp server interface
set dhcp server interface
Description
Configures the WINS servers IP addresses provided by a DHCP server on an existing network/interface.
Syntax
set dhcp server interface <name> wins primary <wins primary> [ secondary
<secondary> ]
Parameters
Parameter Description
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
secondary Configure the IP address for the second WINS server
wins primary Configure the IP address for the first WINS server
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 304
set dhcp server interface
set dhcp server interface
Description
Configures the lease time used by a DHCP server on an existing network/interface.
Syntax
Parameters
Parameter Description
lease-time Configure the timeout in hours for a single device to retain a dynamically acquired IP
address
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 305
set dhcp server interface
set dhcp server interface
Description
Configures the domain used by a DHCP server on an existing network/interface.
Syntax
Parameters
Parameter Description
domain The domain name of the DHCP
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 306
set dhcp server interface
set dhcp server interface
Description
Configures the NTP servers used by a DHCP server on an existing network/interface.
Syntax
Parameters
Parameter Description
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
ntp Configure the first NTP (Network Time Protocol) server to be distributed to DHCP client
secondary Configure the second NTP (Network Time Protocol) server to be distributed to DHCP
client
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 307
set dhcp server interface
set dhcp server interface
Description
Configures the TFTP server used by a DHCP server on an existing network/interface.
Syntax
Parameters
Parameter Description
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
tftp Configure TFTP server to be distributed to DHCP client
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 308
set dhcp server interface
set dhcp server interface
Description
Configures the TFTP bootfile used by a DHCP server on an existing network/interface.
Syntax
Parameters
Parameter Description
file Configure TFTP bootfile to be distributed to DHCP client
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 309
set dhcp server interface
set dhcp server interface
Description
Configures the Call Manager servers used by a DHCP server on an existing network/interface.
Syntax
Parameters
Parameter Description
callmgr Configure the first Call manager server to be distributed to DHCP client
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
secondary Configure the second Call manager server to be distributed to DHCP client
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 310
set dhcp server interface
set dhcp server interface
Description
Configures the X-Windows display manager server used by a DHCP server on an existing
network/interface.
Syntax
Parameters
Parameter Description
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
xwin-display-mgr Configure X-Windows display manager to be distributed to DHCP client
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 311
set dhcp server interface
set dhcp server interface
Description
Configures the Avaya Manager server used by a DHCP server on an existing network/interface.
Syntax
Parameters
Parameter Description
avaya-voip Configure Avaya IP phone to be distributed to DHCP client
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 312
set dhcp server interface
set dhcp server interface
Description
Configures the Nortel Manager server used by a DHCP server on an existing network/interface.
Syntax
Parameters
Parameter Description
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
nortel-voip Configure Nortel IP phone to be distributed to DHCP client
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 313
set dhcp server interface
set dhcp server interface
Description
Configures the Thomson Manager server used by a DHCP server on an existing network/interface.
Syntax
Parameters
Parameter Description
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
thomson-voip Configure Thomson IP phone to be distributed to DHCP client
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 314
set dhcp server interface
set dhcp server interface
Description
Configures the DNS servers provided by a DHCP server on an existing network/interface. In automatic
mode the device will provide its own IP address when configured as DNS proxy, and the DNS servers it is
configured with otherwise.
Syntax
set dhcp server interface <name> dns { none | manual [ primary <primary> ]
[ secondary <secondary> ] [ tertiary <tertiary> ] | auto }
Parameters
Parameter Description
dns Configure the DNS Server
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
primary Configure the IP address for the first DNS server
secondary Configure the IP address for the second DNS server
tertiary Configure the IP address for the third DNS server
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 315
set dhcp server interface
set dhcp server interface
Description
Configures the primary DNS server provided by a DHCP server on an existing network/interface in manual
mode.
Syntax
Parameters
Parameter Description
dns primary Configure the IP address for the first DNS server
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 316
set dhcp server interface
set dhcp server interface
Description
Configures the secondary DNS server provided by a DHCP server on an existing network/interface in
manual mode.
Syntax
Parameters
Parameter Description
dns secondary Configure the IP address for the second DNS server
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 317
set dhcp server interface
set dhcp server interface
Description
Configures the tertiary DNS server provided by a DHCP server on an existing network/interface in manual
mode.
Syntax
Parameters
Parameter Description
dns tertiary Configure the IP address for the third DNS server
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 318
set dhcp server interface
set dhcp server interface
Description
Removes a custom DHCP option from a DHCP server on an existing network/interface.
Syntax
Parameters
Parameter Description
custom-option Set the name of the object
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 319
show dhcp server interface
show dhcp server interface
Shows configuration of DHCP servers.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 320
show dhcp server interface
show dhcp server interface
Description
Shows the configuration of a DHCP server configured on a specific interface/network.
Syntax
Parameters
Parameter Description
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 321
show dhcp server interface
show dhcp server interface
Description
Shows the IP address pool of a DHCP server configured on a specific interface/network.
Syntax
Parameters
Parameter Description
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 322
show diag
show diag
Description
Shows information about your appliance, such as the current firmware version and additional details.
Syntax
show diag
Parameters
Parameter Description
n/a
Example
show diag
Output
Current system information.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 323
show disk usage
show disk usage
Description
Shows the file system space used and space available.
Syntax
Parameters
Parameter Description
-h Human readable (e.g. 1K 243M 2G)
-m 1024*1024 blocks
-k 1024 blocks
Example
show disk-usage-h
Output
Current file system space used and space available.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 324
dns
dns
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 325
delete dns
delete dns
Deletes configured DNS settings.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 326
delete dns
delete dns
Description
Deletes configured primary DNS.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 327
delete dns
delete dns
Description
Deletes configured secondary DNS.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 328
delete dns
delete dns
Description
Deletes configured tertiary DNS.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 329
delete dns
delete dns
Description
Deletes configured domain name of the appliance.
Syntax
delete domainname
Parameters
Parameter Description
n/a
Example
delete domainname
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 330
set dns
set dns
Configures the DNS and domain settings for the device.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 331
set dns
set dns
Description
Configures the DNS settings for the device.
Syntax
Parameters
Parameter Description
primary ipv4-address First global DNS IP address
Type: IP address
secondary ipv4- address Second global DNS IP address
Type: IP address
tertiary ipv4-address Third global DNS IP address
Type: IP address
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 332
set dns
set dns
Description
Configures the DNS mode for the device. It can either use manually configured DNS servers or use the DNS
servers provided to him by the active internet connection from his ISP.
Syntax
Parameters
Parameter Description
mode Status of appliance using global DNS servers
Options: global, internet
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 333
set dns
set dns
Description
Configures the DNS proxy mode. DNS proxy allows treating the configured network objects as a hosts list
which the device can translate from hostname to IP address for local networks.
Syntax
Parameters
Parameter Description
proxy Relay DNS requests from internal network clients to the DNS servers defined above
Type: Press TAB to see available options
resolving Use network objects as a hosts list to translate names to their IP addresses
Options: on, off
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 334
set dns
set dns
Description
Configures the domain settings for the device.
Syntax
Parameters
Parameter Description
domainname Identification string that defines a realm of administrative autonomy, authority, or
control in the Internet
Type: A FQDN
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 335
show dns
show dns
Shows configuration for DNS and domain name.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 336
show dns
show dns
Description
Shows configuration for DNS.
Syntax
show dns
Parameters
Parameter Description
n/a
Example
show dns
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 337
show dns
show dns
Description
Shows configuration for domain name.
Syntax
show domainname
Parameters
Parameter Description
n/a
Example
show domainname
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 338
dsl
dsl
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 339
set dsl advanced-settings global-settings
set dsl advanced-settings global-settings
Description
Set DSL configuration parameters.
Syntax
Parameters
Parameter Description
ginp Enhanced Impulse Noise Protection
sra Enables Seamless Rate Adaption
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 340
set dsl advanced-settings standards
set dsl advanced-settings standards
Description
Set DSL standard related configuration parameters.
Syntax
Parameters
Parameter Description
vdsl2 Supports ITU G.993.2 VDSL2 standard.
dmt Supports ITU G.992.1 ADSL (G.dmt) standard.
adsl-lite Supports ITU G.992.2 ADSL Lite (G.lite) standard.
adsl2 Supports ITU G.992.3 ADSL2 standard.
adsl2plus Supports ITU G.992.5 Annex M ADSL2+M standard.
t1413 Supports ANSI T1.413-1998 Issue 2 ADSL.
annex-m In an Annex A appliance: Combined with supported ADSL2+ it specifies support for
Annex M ADSL2+. In an Annex B appliance: Combined with supported ADSL2 it
specifies support for Annex J ADSL2.
annex-l Combined with enabled ADSL2 (G.992.3) specifies support for Annex L.
vdsl-8a Supports VDSL Profile 8a.
vdsl-8b Supports VDSL Profile 8b.
vdsl-8c Supports VDSL Profile 8c.
vdsl-8d Supports VDSL Profile 8d.
vdsl-12a Supports VDSL Profile 12a.
vdsl-12b Supports VDSL Profile 12b.
vdsl-17a Supports VDSL Profile 17a.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 341
set dsl advanced-settings standards
Parameter Description
vdsl-us0 Enables usage of first upstream band in VDSL2.
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 342
show dsl advanced-setting
show dsl advanced-setting
Description
Show all DSL advanced settings parameters.
Syntax
Parameters
Parameter Description
n/a
Example
Sample Output
adsl2plus: true
vdsl-8d: true
vdsl-8c: true
vdsl-8b: true
annex-m: false
t1413: true
vdsl-17a: true
adsl-lite: true
vdsl2: true
annex-l: false
vdsl-12b: true
adsl2: true
dmt: true
ginp: disabled
sra: false
vdsl8a: true
vdsl-us0: true
vdsl-12a: true
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 343
show dsl statistics
show dsl statistics
Description
Show DSL statistics.
Syntax
Parameters
Parameter Description
tpstc Indicates the TPS-TC layer. Possible values: ATM, PTM.
mode Indicates the negotiated DSL mode. Example for a value: VDSL Annex B.
status Indicates the status of DSL connection synchronization. Example values: Showtime,
G.994.
bitrate-up Indicates the upstream DSL bit rate.
bitrate-down Indicates the downstream DSL bit rate.
vendor 4 hexa digits representing the vendor of the DSL chip in the peer DSLAM/MSAG (i.e.
IFTN, BDCM) + 4 hex digits representing the firmware version of the vendor.
power-up Indicates the appliance transmission power (dBm).
hec-up Indicates the number of HEC errors counted by the peer DSLAM/MSAG.
attn-up Indicates the upstream attenuation (dB).
attn-down Indicates the attenuation of the power from the peer DSLAM/MSAG to the appliance
(dB).
rs-down Indicates the number of RS words that were received by the appliance in the
downstream.
rs-corrected- Indicates the number of RS words that were corrected by the appliance in the
down downstream.
rs-up Indicates the number of RS words that were received by the peer DSLAM/MSAG in the
upstream.
rs-corrected- Indicates the number of RS words that were corrected by the peer DSLAM/MSAG in the
up upstream.
hec-up Indicates the number of HEC errors counted by the peer DSLAM/MSAG.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 344
show dsl statistics
Parameter Description
hec-down Indicates the number of HEC errors counted by the appliance.
total-cells-up Indicates the number of 53 bytes (cells in the case of ATM) that were transmitted by the
appliance.
total-cells- Indicates the number of 53 bytes (cells in the case of ATM) that were received by the
down appliance.
configured- Indicates the seamless rate adaptation (SRA) that was configured in the appliance.
sra Possible values: On, Off.
configured- Indicates whether trellis was enabled in the appliance configuration. Possible values:
trellis On, Off.
configured- Indicates the upstream/downstream on/off for the configured Enhanced Impulse
ginp response. Possible values: Off/Off, Off/On, On/Off, On/On
configured- Indicates the upstream/downstream on/off for the Bit Swap configured in the appliance.
bitswap Possible values: On, Off.
vectoring Indicates the vectoring status. Possible values:
0: Vectoring Training State.
1: Showtime vectoring state, idle, not reporting errors.
2: Initial showtime vector mode state, transition to full factoring when the peer sends a
vectoring configuration message.
3: Vectoring state where error samples are being reported upon peer request.
4: Vectoring is disabled.
5: DSLAM/MSAG doesn't support vectoring.
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 345
show dsl statistics
Sample Output
snr-down: 8.7
configured-ginp: Off/Off
power-up: 7.6
rs-corrected-down: 421298
rs-corrected-up: 208
configured-sra: Off
rs-up: 1610329207
configured-trellis: On
total-cells-down: 2609810117
snr-up: 15.4
tpstc: PTM
bitrate-up: 5024
vectoring: 5 (DSLAM is not a vectored DSLAM)
vendor: IFTN:0xb206
status: Showtime
rs-down: 2127995393
mode: VDSL2 Annex B
hec-up: 0
bitrate-down: 48470
training: Showtime
power-down: 7.7
total-cells-up: 0
hec-down: 0
attn-down: 25.9
attn-up: 0.0
configured-bitswap: Off
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 346
dynamic-dns
dynamic-dns
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 347
set dynamic-dns
set dynamic-dns
Configures a persistent domain name for the device.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 348
set dynamic-dns
set dynamic-dns
Description
Configures a persistent domain name for the device.
Syntax
<user> domain <domain>
Parameters
Parameter Description
domain The domain name (sometimes called host name) within your account that the device will
use
Type: A FQDN
is-active Is the DDNS service active
Type: Boolean (enable/disable)
password The password of the account
Type: A string that contains alphanumeric and special characters
provider Select the DDNS provider that you have already set up an account with
Options: no-ip.com, DynDns
user The user name of the account
Type: DynDns provider: begins with a letter and have 2-25 alphanumeric char acters.
no-ip.com provider: length is 6-15 characters and contains only a-z, 0-9, -, _
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 349
set dynamic-dns
set dynamic-dns
Description
Configure advanced settings for the DDNS service.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 350
show dynamic-dns
show dynamic-dns
Shows configuration for DDNS service.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 351
show dynamic-dns
show dynamic-dns
Description
Shows configuration for DDNS service.
Syntax
show dynamic-dns
Parameters
Parameter Description
n/a
Example
show dynamic-dns
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 352
show dynamic-dns
show dynamic-dns
Description
Shows advanced settings for DDNS service.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 353
dynamic objects
dynamic objects
Manages dynamic objects on the appliance. The dynamic_objects command specifies an IP address to
which the dynamic object is resolved.
First, define the dynamic object in the SmartDashboard. Then create the same object with the CLI (-n
argument). After the new object is created on the gateway with the CLI, you can use the dynamic_objects
command to specify an IP address for the object.
Any change you make to dynamic objects' ranges are applied immediately to the objects. It is not necessary
to reinstall the policy.
Description
Manages dynamic objects on the appliance.
Syntax
dynamic_objects -o <object> [-r <fromIP> <toIP> ...] [-a] [-d] [-l] [-n
<object> ] [-c] [-do <object>]
Parameters
Parameter Description
-o Name of the dynamic object that is being configured.
-r Defines the range of IP addresses that are being configured for this object.
-a Adds range of IP addresses to the dynamic object.
-d Deletes range of IP addresses from the dynamic object.
-l Lists dynamic objects that are used on the appliance.
-n Creates a new dynamic object.
-c Compare the objects in the dynamic objects file and in objects.
-do Deletes the dynamic object.
<object> Name of dynamic object.
<fromIP> Starting IPv4 address.
<toIP> Ending IPv4 address.
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 354
dynamic objects
Output
Success shows Operation completed successfully. Failure shows an appropriate error message.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 355
exit
exit
Description
Exits from the shell.
Syntax
exit
Parameters
Parameter Description
n/a
Example
exit
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 356
set expert password
set expert password
Description
Sets the initial password or password hash for the expert shell
Syntax
Parameters
Parameter Description
pass Password using alphanumeric and special characters
pass_hash Password MD5 string representation
Example
Output
Success shows OK. Failure shows an appropriate error message.
Comments
To generate a password-hash, you can use this command on any Check Point SMB Appliance gateway (as
an expert user).
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 357
fetch certificate
fetch certificate
Description
Establishes a SIC connection with the Security Management Server and fetches the certificate. You fetch
the certificate from a specific appliance with the gateway-name parameter.
Syntax
Parameters
Parameter Description
ip_addr Management IPv4 address
gw_name Appliance/Module name
Example
Output
Success shows OK. Failure shows an appropriate error message.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 358
fetch policy
fetch policy
Description
Fetches a policy from the Security Management Server with IPv4 address <ip_addr> or from the local
gateway.
Syntax
Parameters
Parameter Description
ip_addr IPv4 address of the Security Management Server.
Return Value
0 on success, 1 on failure
Example
Output
Success shows Done. Failure shows an appropriate error message.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 359
fw commands
fw commands
The fw commands are used for working with various aspects of the firewall. All fwcommands are executed
on the Check Point Security Gateway. For more about the fwcommands, see the Command Line Interface
(CLI) Reference Guide.
fw commands can be found by typing fw [TAB] at a command line. For some of the CLI commands, you
can enter the -h parameter to display all the relevant arguments and parameters. These commands are:
fw command Explanation
fw activation Activate license
[-h]
fw fetch Fetch last policy
fw fetchdefault Fetch default policy
[-h]
fw fetchlocal Fetch local policy
[-h]
fw pull_cert Pull certificate from internal CA
fw sfwd fw daemon
fw sic_init [- Initialize SIC
h]
fw sic_reset [- Reset SIC
h]
fw sic_test Test SIC with management
fw unloadlocal Unload local policy
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 360
fw policy
fw policy
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 361
set fw policy
set fw policy
Configures the default policy for the Firewall blade
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 362
set fw policy
set fw policy
Description
Configures the default policy for the Firewall blade.
Syntax
] [ track-blocked-traffic <track-blocked-traffic> ]
Parameters
Parameter Description
mode Current mode for firewall policy
track-allowed-traffic Indicates if accepted connections are logged
Options: none, log
track-blocked-traffic Indicates if blocked connections are logged
Options: none, log
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 363
set fw policy
set fw policy
Description
Configures advanced settings for the default policy of the Firewall blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 364
set fw policy
set fw policy
Description
Configures advanced settings for the default policy of the Firewall blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 365
show fw policy
show fw policy
Shows the configured policy for the Firewall blade.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 366
show fw policy
show fw policy
Description
Shows the configured policy for the Firewall blade.
Syntax
show fw policy
Parameters
Parameter Description
n/a
Example
show fw policy
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 367
show fw policy
show fw policy
Description
Shows advanced settings for the Firewall blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 368
show fw policy
show fw policy
Description
Shows the configuration for customizable messages shown to users upon actions.
Syntax
Parameters
Parameter Description
user-check Activity message type
Type: Press TAB to see available options
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 369
set fw policy user-check accept
set fw policy user-check accept
Description
Configures a customizable "accept" message shown to users upon match on browser based traffic.
Syntax
Parameters
Parameter Description
body The informative text that appears in the APPI 'Accept' user message
Type: A string that contains only printable characters
fallback- Indicates the action to take when an 'Accept' user message cannot be displayed
action Options: block, accept
frequency Indicates how often is the APPI 'Accept' user message is being presented to the same
user
Options: day, week, month
subject The subject of an APPI 'Accept' user message
Type: A string that contains only printable characters
title The title of an APPI 'Accept' user message
Type: A string that contains only printable characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 370
set fw policy user-check ask
set fw policy user-check ask
Description
Configures a customizable "ask" message shown to users upon match on browser based traffic.
Syntax
Parameters
Parameter Description
body The informative text that appears in the APPI 'Ask' user message
Type: A string that contains only printable characters
confirm-text This text appears next to the 'ignore warning' checkbox of an APPI 'Ask' user
message
Type: A string that contains only printable characters
fallback-action The action that is performed when the 'Ask' message cannot be shown
Options: block, accept
frequency Indicates how often is the APPI 'Ask' user message is being presented to the same
user
Options: day, week, month
reason- Indicates if the user must enter a reason for ignoring this message in a designated
displayed text dialog
Type: Boolean (true/false)
subject The subject of an APPI 'Ask' user message
Type: A string that contains only printable characters
title The title of an APPI 'Ask' user message
Type: A string that contains only printable characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 371
set fw policy user-check block
set fw policy user-check block
Description
Configures a customizable "block" message shown to users upon match on browser based traffic.
Syntax
Parameters
Parameter Description
body The informative text that appears in the APPI 'Block' user message
Type: A string that contains only printable characters
redirect-to-url Indicates if the user will be redirected to a custom URL in case of a 'Block' action
Type: Boolean (true/false)
redirect-url Indicates the URL to redirect the user in case of a 'Block' action if configured to do so.
The URL to redirect the user in case of a 'Block' action. Redirection happens only if this
functionality is turned on
Type: urlWithHttp
subject The subject of an APPI 'Block' user message
Type: A string that contains only printable characters
title The title of an APPI 'Block' user message
Type: A string that contains only printable characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 372
set fw policy user-check block-device
set fw policy user-check block-
device
Description
User Check is a customizable message shown to users upon match, and allows to 'ask' the user for the
desired action. In this case, to block a particular device.
Syntax
Parameters
Parameter Description
body The informative text that appears in the 'Block Device' user message.
Type: A string that contains only printable characters
subject The subject of the 'Block Device' user message
Type: A string that contains only printable characters
title The title of the 'Block Device' user message
Type: A string that contains only printable characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 373
set fw policy user-check block-infected-device
set fw policy user-check block-
infected-device
Description
User Check is a customizable message shown to users upon match, and allows to 'ask' the user for the
desired action. In this case, to block an infected device.
Syntax
Parameters
Parameter Description
body The informative text that appears in the 'Block Infected Device' user message
Type: A string that contains only printable characters
subject The subject of the 'Block Infected Device' user message
Type: A string that contains only printable characters
title The title of the 'Block Infected Device' user message
Type: A string that contains only printable characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 374
global-radius-conf
global-radius-conf
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 375
set global-radius-conf
set global-radius-conf
Description
Configure the NAS IP\IPv6 address for RADIUS server authentication.
NAS IP\IPv6 address indicates the identifying IP Address of the NAS which is requesting authentication of
the user, and should be unique to the NAS within the scope of the RADIUS server.
Syntax
Parameters
Parameter Description
nas-ip-address Nas ip address
Type: IP address
nasIPV6 nasIPV6
Type: ipv6addr
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 376
show global-radius-conf
show global-radius-conf
Description
Configure the NAS IP\IPv6 address for RADIUS server authentication.
Syntax
show global-radius-conf
Parameters
Parameter Description
n/a
Example
show global-radius-conf
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 377
group
group
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 378
add group
add group
Description
Adds a new group of network objects.
Syntax
Parameters
Parameter Description
comments Comments and explanation about the Network Object group
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
member An association field to the contained network objects
name Network Object group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 379
delete group
delete group
Description
Deletes an existing group object of network objects.
Syntax
Parameters
Parameter Description
name Network Object group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 380
set group
set group
Configures an existing network objects group.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 381
set group
set group
Description
Configures an existing network objects group.
Syntax
Parameters
Parameter Description
comments Comments and explanation about the Network Object group
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
name Network Object group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
new-name Network Object group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 382
set group
set group
Description
Removes all members from an existing network objects group.
Syntax
Parameters
Parameter Description
name Network Object group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 383
set group
set group
Description
Adds an existing network object to an existing network objects group.
Syntax
Parameters
Parameter Description
member Network Object name
name Network Object group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 384
set group
set group
Description
Removes an existing network object from an existing network objects group.
Syntax
Parameters
Parameter Description
member Network Object name
name Network Object group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 385
show group
show group
Description
Shows the contents of a network object group.
Syntax
Parameters
Parameter Description
name Network Object group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 386
show groups
show groups
Description
Shows the contents of all network object groups.
Syntax
show groups
Parameters
Parameter Description
n/a
Example
show groups
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 387
host
host
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 388
add host
add host
Description
Adds a new network host object that can be used for resolving when the device acts as a DNS proxy, and
also DHCP settings for this object (exclude/reserve IP address).
Syntax
Parameters
Parameter Description
dhcp-exclude-ip- Indicates if the object's IP address(es) is excluded from internal DHCP daemon
addr Type: Press TAB to see available options
dhcp-reserve-ip- Indicates if the IP address is reserved in internal DHCP daemon
addr- to-mac Type: Press TAB to see available options
dns-resolving Indicates if the name of the server/network object will be used as a hostname for
internal DNS service Type: Boolean (true/false)
ipv4-address The beginning of the IP range
mac-addr MAC address of the Network Object
Type: MAC address
mac-reserved-in- This field is deprecated. Please use field 'dhcp-reserve-ip-addr-to-mac'
dhcp
name Network Object name
Type: String
reserve-mac- This field is deprecated. Please use field 'mac-addr'
address
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 389
delete host
delete host
Description
Deletes an existing network host object.
Syntax
Parameters
Parameter Description
name Network Object name
Type: String
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 390
set host
set host
Description
Configures an existing network object/host.
Syntax
Parameters
Parameter Description
dhcp-exclude-ip-addr Indicates if the object's IP address(es) is excluded from internal DHCP daemon
Type: Press TAB to see available options
dhcp-reserve-ip-addr- Indicates if the IP address is reserved in internal DHCP daemon
to-mac Type: Press TAB to see available options
dns-resolving Indicates if the name of the server/network object will be used as a hostname
for internal DNS service
Type: Boolean (true/false)
exclude-from-dhcp This field is deprecated. Please use field 'dhcp-reserve-ip-addr-to-mac'
ipv4-address The beginning of the IP range
mac-addr MAC address of the Network Object
Type: MAC address
mac-reserved-in-dhcp This field is deprecated. Please use field 'dhcp-reserve-ip-addr-to-mac'
name Network Object name
Type: String
reserve-mac-address This field is deprecated. Please use field 'mac-addr'
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 391
set host
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 392
show host
show host
Description
Shows the configuration of an existing network object.
Syntax
Parameters
Parameter Description
name Network Object name
Type: String
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 393
show hosts
show hosts
Description
Shows the configuration of all existing network objects.
Syntax
show hosts
Parameters
Parameter Description
n/a
Example
show hosts
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 394
hotspot
hotspot
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 395
set hotspot
set hotspot
Configures hotspot settings.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 396
set hotspot
set hotspot
Description
Configures hotspot settings.
Syntax
Parameters
Parameter Description
allowed- Indicates the specific user group that can authenticate through the hotspot when auth-
group mode is set to allow-specific-group
Type: A string of alphanumeric characters without space between them
auth-mode Allow access to a specific user group only or all users
Options: allow-all, allow-specific-group
portal-msg The message shown in hotspot portal
Type: A string that contains only printable characters
portal-title The title of the hotspot portal
Type: A string that contains only printable characters
redirect-after- Indicates if after the user accepts terms or authenticate in the hotspot portal the user will
auth be redirected to a configured external URL instead of the originally requested URL
Options: on, off
redirect-after- Redirect the user to the following URL after the user accepts terms or authenticate in
auth-url the hotspot portal
Type: urlWithHttp
require-auth Indicates if user authentication is required
Type: Boolean (true/false)
show-terms- Indicates if a terms and conditions link will be shown in the hotspot portal
of-use Options: on, off
terms-of-use Indicates the When users will click the terms and conditions text shown in the hotspot
portal
Type: A string that contains only printable characters
timeout Time, in minutes, untill the hotspot session expires
Type: A number with no fractional part (integer)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 397
set hotspot
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 398
set hotspot
set hotspot
Description
Adds an existing network object as an exception for hotspot portal.
Syntax
Parameters
Parameter Description
exception Network object name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 399
set hotspot
set hotspot
Description
Removes an existing network object from being an exception to hotspot portal.
Syntax
Parameters
Parameter Description
exception Network object name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 400
set hotspot
set hotspot
Description
Configures advanced hotspot settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 401
set hotspot
set hotspot
Description
Configures advanced hotspot settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 402
show hotspot
show hotspot
Shows hotspot configuration.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 403
show hotspot
show hotspot
Description
Shows hotspot configuration.
Syntax
show hotspot
Parameters
Parameter Description
n/a
Example
show hotspot
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 404
show hotspot
show hotspot
Description
Shows hotspot advanced settings configuration.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 405
https-categorization
https-categorization
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 406
set https-categorization
set https-categorization
Configures HTTPS categorization settings (categorization does not require a full SSL inspection
mechanism).
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 407
set https-categorization
set https-categorization
Description
Configures advanced HTTPS categorization settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 408
set https-categorization
set https-categorization
Description
Configures advanced HTTPS categorization settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 409
set https-categorization
set https-categorization
Description
Configures advanced HTTPS categorization settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 410
show https-categorization
show https-categorization
Description
Shows configuration for HTTPS categorization feature.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 411
interface
interface
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 412
add interface
add interface
Adds a new virtual interface.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 413
add interface
add interface
Description
Adds a new 802.1q tag-based VLAN over an existing physical interface.
Syntax
Parameters
Parameter Description
assignment The switch or bridge which the object belongs to
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
vlan Enter a number that is the virtual identifier
Type: A number with no fractional part (integer)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 414
add interface
add interface
Description
Adds a new numbered/unnumbered Virtual Tunnel Interface (VTI) to be used for Route-based VPN
purposes.
Syntax
add vpn tunnel <vpn tunnel> type { unnumbered peer <peer> internet-
connection <internet-connection> | numbered local <local> remote <remote>
peer <peer> }
Parameters
Parameter Description
internet- The local interface for unnumbered VTI
connection
local Enter the IP address of the interface
Type: IP address
peer Remote peer name as defined in the VPN community. You must define the two peers in
the VPN community before you can define the VTI. The Peer ID is an alpha-numeric
character string.
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z, _ -)
characters without spaces
remote Defines the remote peer IPv4 address, used at the peer gateway's point-to-point virtual
interface (numbered VTI only)
Type: IP address
type The type of VTI: Numbered VTI that uses a specified, static IPv4 addresses for local and
remote connections, or unnumbered VTI that uses the interface and the remote peer
name to get addresses
Type: Press TAB to see available options
vpn tunnel A number identifying the Virtual Tunnel Interface (VTI)
Type: A number with no fractional part (integer)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 415
add interface
add interface-alias
Description
Associate more than one IP address to a network interface.
Syntax
Parameters
Parameter Description
alias-physical-port The physical port used by the alias network. Separate networks only
Type: A string that contains [A-Z], [0-9], ’_’, ’.’, ’-’ and ’/’ characters
ipv4-address Enter the IP address of the interface
Type: IP address
mask-length Represents the network’s mask length
Type: A string that contains numbers only
subnet-mask The subnet mask of the specified network
Type: A subnet mask, or 255.255.255.255
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 416
delete interface
delete interface
Description
Deletes an existing virtual interface.
Syntax
Parameters
Parameter Description
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 417
set interface
set interface
Configures local networks/interfaces.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 418
set interface
set interface
Description
Configures local networks/interfaces.
Syntax
Parameters
Parameter Description
default-gw Default gateway
Type: IP address
dns-primary First DNS server IP address
Type: IP address
dns-secondary Second DNS server IP address
Type: IP address
dns-tertiary Third DNS server IP address
Type: IP address
ipv4-address The IP address
Type: IP address
mask-length Subnet mask length
Type: A string that contains numbers only
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
subnet-mask Subnet mask
Type: Subnet mask
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 419
set interface
set interface
Description
Configures IP address for local networks/interfaces.
Syntax
Parameters
Parameter Description
ipv4-address Enter the IP address of the interface
Type: IP address
mask-length Represents the network's mask length
Type: A string that contains numbers only
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
subnet-mask Enter the Subnet mask of the specified network
Type: A subnet mask, or 255.255.255.255
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 420
set interface
set interface
Description
Configures a physical interface to be unassigned from existing networks.
Syntax
Parameters
Parameter Description
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 421
set interface
set interface
Description
Configures monitor mode on an existing local network/interface.
Syntax
Parameters
Parameter Description
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 422
set interface
set interface
Description
Configures advanced settings on an existing local network/interface.
Syntax
Parameters
Parameter Description
exclude-from-dns- proxy Exclude from DNS proxy
Options: on, off
mac-address-override Override default MAC address
Type: MAC address
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 423
set interface
set interface
Description
Configures networking settings on an existing local network/interface.
Syntax
Parameters
Parameter Description
auto-negotiation Enable this option in order to manually configure the link speed of the interface.
Options: on, off
link-speed Configure the link speed of the interface manually
Options: 10/full, 10/half, 100/full, 100/half
mtu Configure the Maximum Transmission Unit size for an interface
Type: A number with no fractional part (integer)
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 424
set interface
set interface
Description
Enable/disable an existing local network/interface.
Syntax
Parameters
Parameter Description
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
state The mode of the network - enabled or disabled
Options: on, off
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 425
set interface
set interface
Description
Configures a description for an existing local network/interface.
Syntax
Parameters
Parameter Description
description Description
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 426
set interface
set interface
Description
Configures automatic access policy for an existing local network/interface. This feature is relevant when the
device is locally managed.
Syntax
Parameters
Parameter Description
lan-access Local networks will be accessible from this network once this option is enabled
Options: block, accept
lan-access-track Traffic from this network to local networks will be logged once this option is enabled
Options: none, log
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 427
set interface
set interface
Description
Configure hotspot functionality for an existing local network/interface.
Syntax
Parameters
Parameter Description
hotspot Redirect users to the Hotspot portal before allowing access from this interface
Options: on, off
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 428
show interface
show interface
Description
Shows configuration and details of local networks.
Syntax
Parameters
Parameter Description
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 429
show interfaces
show interfaces
Description
Shows the list of defined local networks.
Syntax
show interfaces
Parameters
Parameter Description
n/a
Example
show interfaces
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 430
show interfaces all
show interfaces all
Description
Shows details of all defined local networks.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 431
interface-alias
interface-alias
add interface-alias
Description
Associate more than one IP address to a network interface.
Syntax
Parameters
Parameter Description
alias-physical-port The physical port used by the alias network. Separate networks only
Type: A string that contains [A-Z], [0-9], ’_’, ’.’, ’-’ and ’/’ characters
ipv4-address Enter the IP address of the interface
Type: IP address
mask-length Represents the network’s mask length
Type: A string that contains numbers only
subnet-mask The subnet mask of the specified network
Type: A subnet mask, or 255.255.255.255
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 432
delete interface-alias
delete interface-alias
Description
Delete one of multiple IP addresses associated to a network interface.
Syntax
Parameters
Parameter Description
name Network name
Type: A string that contains [A-Z], [0-9], ’_’, ’.’, ’-’ and ’/’ characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 433
set interface-alias
set interface-alias
Description
Configure the settings for an alias IP.
Syntax
Parameters
Parameter Description
ipv4 address Enter the IP address of the interface Type: IP address
mask-length Represents the network’s mask length Type: A string that contains numbers only
name Network name
Type: A string that contains [A-Z], [0-9], ’_’, ’.’, ’-’ and ’/’ characters
state The mode of the network - enabled or disabled Options: on, off
subnet-mask The subnet mask of the specified network Type: A subnet mask, or 255.255.255.255
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 434
interface-bond
interface-bond
add interface-bond
Description
Create a link aggregation (bond) between two or more interfaces (LAN).
Syntax
Parameters
Parameter Description
bond-hash policy The bond hash policy
Options: layer2, layer2_3, layer3_4
bond-master The bond Master port
Type: A string that contains [A-Z], [0-9], ’_’, ’.’, ’-’ and ’/’ characters
bond-mii-interval The bond MII interval
Type: A number with no fractional part (integer)
bond-mode The bond operation mode policy
Type: Press TAB to see available options
slave-port-1 bondPort1
Type: A string that contains [A-Z], [0-9], ’_’, ’.’, ’-’ and ’/’ characters
slave-port-2 bondPort2
Type: A string that contains [A-Z], [0-9], ’_’, ’.’, ’-’ and ’/’ characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 435
delete interface-bond
delete interface-bond
Delete this text and replace it with your own content.
Description
Delete a link aggregation (bond) between two or more interfaces.
Syntax
Parameters
Parameter Description
name Network name
Type: A string that contains [A-Z], [0-9], ’_’, ’.’, ’-’ and ’/’ characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 436
set interface-bond
set interface-bond
Description
Configure the settings for an interface bond.
Syntax
Parameters
Parameter Description
bond-hash-policy The bond hash policy
Options: layer2, layer2_3, layer3_4
bond-master The bond Master port
Type: A string that contains [A-Z], [0-9], ’_’, ’.’, ’-’ and ’/’ characters
bond-mii-interval The bond MII interval
Type: A number with no fractional part (integer)
bond-mode The bond operation mode policy
Options: 8023ad, round-robin, xor, master
name Network name
Type: A string that contains [A-Z], [0-9], ’_’, ’.’, ’-’ and ’/’ characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 437
set interface-bond
set interface-bond
Description
Configure the settings for an internet bond (LAN).
Syntax
Parameters
Parameter Description
add-member bondPort1
Type: A string that contains [A-Z], [0-9], ’_’, ’.’, ’-’ and ’/’ characters
name Network name
Type: A string that contains [A-Z], [0-9], ’_’, ’.’, ’-’ and ’/’ characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 438
set interface-bond
set interface-bond
Description
Configure the settings for an interface bond (LAN).
Syntax
Parameters
Parameter Description
name Network name
Type: A string that contains [A-Z], [0-9], ’_’, ’.’, ’-’ and ’/’ characters
remove-member bondPort1
Type: A string that contains [A-Z], [0-9], ’_’, ’.’, ’-’ and ’/’ characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 439
show interface-bond
show interface-bond
Description
Show the name of the interface in the bond (LAN).
Syntax
Parameters
Parameter Description
name Network name
Type: A string that contains [A-Z], [0-9], ’_’, ’.’, ’-’ and ’/’ characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 440
show interfaces-bond
show interfaces-bond
Description
Show the interfaces in the bond (LAN).
Syntax
show interfaces-bond
Parameters
Parameter Description
n/a
Example
show interfaces-bond
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 441
show interfaces-bond
internal-certificates-conf
Configure settings for internal certificates.
add internal-certificate
Description
Add an internal certificate.
Syntax
Parameters
Parameter Description
certificate- Informal representation for the Certificate Type: String
name
Less-secure Allow connections to SSL sites without certificates. Only applied over SFTP.
Type: Boolean (true/false)
P12- PKCS#12 Password, PKCS #12 defines an archive file format for storing many
password cryptography objects as a single file
Type: A registration key
url Download the certificate file from this URL. The URL format should be
(s)ftp://name:passwd@machine.domain:port/full_path_to_file
Type: ftpUrl
Example
delete internal-certificate
Description
Delete an internal certificate.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 442
show interfaces-bond
Syntax
Parameters
Parameter Description
name Name of the internal certificate
Type: String
Example
show internal-certificate
Description
Show an internal certificate.
Syntax
Parameters
Parameter Description
name Name of the internal certificate
Type: String
Example
show internal-certificates
Description
Show all internal certificates.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 443
show interfaces-bond
Syntax
show internal-certificates
Parameters
Parameter Description
n/a
Example
show internal-certificates
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 444
ips engine-settings
ips engine-settings
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 445
set ips engine-settings
set ips engine-settings
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 446
set ips engine-settings
set ips engine-settings
Description
Configures advanced IPS engine settings. This command configures if and when IPS will deactivate upon
high resource consumption of the device.
Syntax
Parameters
Parameter Description
bypass-track Indicates how the appliance will track events where the bypass mechanism is
activated/deactivated
Options: none, log, alert
bypass- Indicates if the IPS engine will move to bypass mode if the appliance is under heavy
under-load load
Type: Boolean (true/false)
protection- Indicates if the IPS blade will protect internal networks only or protect all networks
scope (including external networks)
Options: protect-internal-hosts-only, perform-ips-inspection-on-all-traffic
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 447
set ips engine-settings
set ips engine-settings
Description
Configures advanced IPS engine settings. This command configures a legacy error page shown in some
legacy IPS HTTP protections.
Syntax
] [ enable-logo-url <enable-logo-url> ]
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 448
set ips engine-settings
set ips engine-settings
Description
Configures advanced IPS engine settings. This command configures a legacy error page shown in some
legacy IPS HTTP protections.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 449
show ips engine-settings
show ips engine-settings
Shows engine settings for the IPS blade.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 450
show ips engine-settings
show ips engine-settings
Description
Shows engine settings for the IPS blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 451
show ips engine-settings
show ips engine-settings
Description
Shows advanced engine settings for the IPS blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 452
interface-loopback
interface-loopback
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 453
add interface-loopback
add interface-loopback
Description
Adds a new loopback interface (A fixed interface in the system that is commonly used for dynamic routing
purposes).
Syntax
Parameters
Parameter Description
ipv4-address Enter the IP address of the interface
Type: IP address
mask-length Represents the network's mask length
Type: A string that contains numbers only
subnet-mask Enter the Subnet mask of the specified network
Type: A subnet mask, or 255.255.255.255
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 454
delete interface-loopback
delete interface-loopback
Description
Deletes an existing configured loopback interface.
Syntax
Parameters
Parameter Description
name Network name
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 455
internet
internet
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 456
set internet
set internet
Description
Configures advanced settings for internet connectivity.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 457
show internet
show internet
Description
Shows advanced settings for configured internet
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 458
show internet
internet-advanced-settings
set internet-advanced-settings
Description
Configure advanced global internet settings.
Syntax
Parameters
Parameter Description
reset-sierra-usb-on-lsi- Indicates whether Sierra type USB modems will be reset when they send an
event Invalid LSI signal
Type: Boolean (true/false)
Example
show internet-advanced-settings
Description
Show internet advanced global settings.
Syntax
Parameters
Parameter Description
n/a
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 459
show internet
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 460
internet-connection
internet-connection
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 461
add internet-connection
add internet-connection
Adds a new internet connection.
add internet-connection interface cellular
Description
Add a new cellular (LTE) internet connection.
Syntax
Parameters
Parameter Description
apn APN (Access Point Name) of SIM 1(optional).
pin PIN (Personal Identification Number) of SIM 1(optional).
apn-sim1- The APN authentication method provided by your cellular network carrier for
authentication-method SIM1.
Values:
n pap
n chap
n none
apn-sim1-password The APN password provided by your cellular network carrier for SIM1.
Password string. Maximum length of 15 characters. Required when apn-sim1-
authentication-method = pap or chap
apn-sim1-username The APN username provided by your cellular network carrier for SIM1.
Maximum length of 59 characters. Required when apn-sim1-authentication-
method = pap or chap
apn-sim2- The APN authentication method provided by your cellular network carrier for
authentication-method SIM2.
n pap
n chap
n none
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 462
add internet-connection
Parameter Description
apn-sim2-password The APN password provided by your cellular network carrier for SIM2.
Password string. Maximum length of 15 characters. Required when apn-sim2-
authentication-method = pap or chap
apn-sim2-username The APN username provided by your cellular network carrier for SIM2.
Maximum length of 59 characters. Required when apn-sim2-authentication-
method = pap or chap
apn-sim2 APN (Access Point Name) of SIM 2 (optional).
pin-sim2 PIN number of SIM 2 (optional).
primary-sim The preferred SIM to use for the connection.
disable-sim Allows disabling of one of the SIM cards.
name The name of the internet connection.
sim1-carrier- Predefined configuration and firmware package required for specific cellular
configuation-package network carriers for SIM1.
sim2-carrier- Predefined configuration and firmware package required for specific cellular
configuation-package network carriers for SIM2.
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 463
add internet-connection (physical interface)
add internet-connection (physical interface)
Description
Adds a new internet connection using an existing physical interface (multiple internet connection can
engage in High Availability/Load Sharing).
WAN
Syntax for DHCP
Parameters
Parameter Description
conn-test-timeout Connection test timeout
Type: A number with no fractional part (integer)
interface Interface name
Type: Press TAB to see available options
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
type Connection type
Type: Press TAB to see available options
vlan-id VLAN ID
Type: A number with no fractional part (integer)
Syntax for Static IP
Parameters
Parameter Description
conn-test-timeout Connection test timeout
Type: A number with no fractional part (integer)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 464
add internet-connection (physical interface)
Parameter Description
interface Interface name
Type: Press TAB to see available options
default-gw WAN default gateway (in the advanced section of PPTP and l2TP)
Type: IP address
dns-primary First DNS server IP address
Type: IP address
dns-secondary Second DNS server IP address
Type: IP address
dns-tertiary Third DNS server IP address
Type: IP address
ipv4-address IP address field (for static IP and bridge settings)
Type: IP address
mask-length Subnet mask length
Type: A string that contains numbers only
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
subnet-mask Subnet mask
Type: A subnet mask, or 255.255.255.255
type Connection type
Type: Press TAB to see available options
vlan-id VLAN ID
Type: A number with no fractional part (integer)
Syntax for L2TP
add internet-connection name <name> interface WAN type l2tp server <server>
password-hash <password-hash>
add internet-connection name <name> interface WAN type l2tp server <server>
password <password> username <username> { local-ipv4-address <local-ipv4-
address> wan-ipv4-address <wan-ipv4-address> wan-mask-length <wan-mask-
length>
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 465
add internet-connection (physical interface)
Parameters
Parameter Description
conn-test- Connection test timeout
timeout Type: A number with no fractional part (integer)
interface Interface name
Type: Press TAB to see available options
default-gw WAN default gateway (in the advanced section of PPTP and l2TP)
Type: IP address
is-unnumbered- Unnumbered PPPoE lets you manage a range of IP addresses and dial only once
pppoe Type: Boolean (true/false)
local-ipv4- Local tunnel IP address or Auto for automatic
address Type: An IP address, or 'auto'
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
password Password for PPP connection or cellular modem settings
Type: internetPassword
password-hash The hash of the user password
Type: passwordHash
server Server IP address
Type: IP address
type Connection type
Type: Press TAB to see available options
username User name for PPP connection or cellular modem settings
Type: A string that contains all printable characters but a single or double quote- like
characters. Usually <username>@<ISP>
vlan-id VLAN ID
Type: A number with no fractional part (integer)
wan-ipv4- Wan IP address wrapper
address Type: An IP address, or 'auto'
wan-mask- WAN subnet mask length
length Type: A string that contains numbers only
wan-subnet- WAN subnet mask (in the advanced section)
mask Type: Subnet mask
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 466
add internet-connection (physical interface)
Syntax for PPPoE
add internet-connection name < name> interface WAN type pppoe username
<username> password-hash <password-hash>
Parameters
Parameter Description
conn-test- Connection test timeout
timeout Type: A number with no fractional part (integer)
interface Interface name
Type: Press TAB to see available options
is-unnumbered- Unnumbered PPPoE lets you manage a range of IP addresses and dial only once
pppoe Type: Boolean (true/false)
local-ipv4- Local tunnel IP address or Auto for automatic
address Type: An IP address, or 'auto'
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
password Password for PPP connection or cellular modem settings
Type: internetPassword
password-hash The hash of the user password
Type: passwordHash
type Connection type
Type: Press TAB to see available options
username User name for PPP connection or cellular modem settings
Type: A string that contains all printable characters but a single or double quote- like
characters. Usually <username>@<ISP>
vlan-id VLAN ID
Type: A number with no fractional part (integer)
Syntax for PPTP
add internet-connection name <name> interface WAN type pptp server <server>
password-hash <password-hash>
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 467
add internet-connection (physical interface)
add internet-connection name <name> interface WAN type pptp server <server>
password <password> username <username> { local-ipv4-address <local-ipv4-
address> wan-ipv4-address <wan-ipv4-address> wan-subnet-mask <wan-subnet-
mask> default-gw <default-gw>} { is-unnumbered-pppoe <is-unnumbered-pppoe>
local-ipv4-address <local-ipv4-address>}
Parameters
Parameter Description
conn-test- Connection test timeout
timeout Type: A number with no fractional part (integer)
interface Interface name
Type: Press TAB to see available options
default-gw
is-unnumbered- Unnumbered PPPoE lets you manage a range of IP addresses and dial only once
pppoe Type: Boolean (true/false)
local-ipv4- Local tunnel IP address or Auto for automatic
address Type: An IP address, or 'auto'
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
password Password for PPP connection or cellular modem settings
Type: internetPassword
password-hash The hash of the user password
Type: passwordHash
server Server IP address
Type: IP address
type Connection type
Type: Press TAB to see available options
username User name for PPP connection or cellular modem settings
Type: A string that contains all printable characters but a single or double quote- like
characters. Usually <username>@<ISP>
vlan-id VLAN ID
Type: A number with no fractional part (integer)
wan-ipv4- Wan IP address wrapper
address Type: An IP address, or 'auto'
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 468
add internet-connection (physical interface)
Parameter Description
wan-mask- WAN subnet mask length
length Type: A string that contains numbers only
wan-subnet- WAN subnet mask (in the advanced section)
mask Type: Subnet mask
ADSL
Syntax for EoA
Parameters
Parameter Description
conn-test-timeout Connection test timeout
Type: A number with no fractional part (integer)
encapsulation Encapsulation type for the ADSL connection
Options: llc, vcmux
interface Interface name
Type: Press TAB to see available options
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
standard The ADSL standard to use
Options: multimode, t1413, glite, gdmt, adsl2, adsl2+
type Connection type
Type: Press TAB to see available options
vci VCI value for the ADSL connection
Type: A number between 0 and 65535
vpi VPI value for the ADSL connection
Type: A number between 0 and 255
Syntax for PPPoE
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 469
add internet-connection (physical interface)
Parameters
Parameter Description
conn-test- Connection test timeout
timeout Type: A number with no fractional part (integer)
encapsulation Encapsulation type for the ADSL connection
Options: llc, vcmux
interface Interface name
Type: Press TAB to see available options
is-unnumbered- Unnumbered PPPoE lets you manage a range of IP addresses and dial only once
pppoe Type: Boolean (true/false)
local-ipv4- Local tunnel IP address or Auto for automatic
address Type: An IP address, or 'auto'
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
password Password for PPP connection or cellular modem settings
Type: internetPassword
password-hash The hash of the user password
Type: passwordHash
type Connection type
Type: Press TAB to see available options
username User name for PPP connection or cellular modem settings
Type: A string that contains all printable characters but a single or double quote- like
characters. Usually <username>@<ISP>
vci VCI value for the ADSL connection
Type: A number between 0 and 65535
vpi VPI value for the ADSL connection
Type: A number between 0 and 255
DSL
Syntax for IPoE Dynamic
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 470
add internet-connection (physical interface)
Parameters
Parameter Description
conn-test-timeout Connection test timeout
Type: A number with no fractional part (integer)
encapsulation Encapsulation type for the ADSL connection
Options: llc, vcmux
interface Interface name
Type: Press TAB to see available options
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
type Connection type
Type: Press TAB to see available options
vci VCI value for the ADSL connection
Type: A number between 0 and 65535
vlan-id VLAN ID
Type: A number with no fractional part (integer)
vpi VPI value for the ADSL connection
Type: A number between 0 and 255
Syntax for IPoE Static
Parameters
Parameter Description
conn-test-timeout Connection test timeout
Type: A number with no fractional part (integer)
default-gw WAN default gateway (in the advanced section of PPTP and l2TP)
Type: IP address
dns-primary First DNS server IP address
Type: IP address
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 471
add internet-connection (physical interface)
Parameter Description
dns-secondary Second DNS server IP address
Type: IP address
dns-tertiary Third DNS server IP address
Type: IP address
encapsulation Encapsulation type for the ADSL connection
Options: llc, vcmux
interface Interface name
Type: Press TAB to see available options
ipv4-address IP address field (for static IP and bridge settings)
Type: IP address
mask-length Subnet mask length
Type: A string that contains numbers only
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
subnet-mask Subnet mask
Type: A subnet mask, or 255.255.255.255
type Connection type
Type: Press TAB to see available options
vci VCI value for the ADSL connection
Type: A number between 0 and 65535
vlan-id VLAN ID
Type: A number with no fractional part (integer)
vpi VPI value for the ADSL connection
Type: A number between 0 and 255
Syntax for PPPoE
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 472
add internet-connection (physical interface)
Parameters
Parameter Description
conn-test- Connection test timeout
timeout Type: A number with no fractional part (integer)
encapsulation Encapsulation type for the ADSL connection
Options: llc, vcmux
interface Interface name
Type: Press TAB to see available options
is-unnumbered- Unnumbered PPPoE lets you manage a range of IP addresses and dial only once
pppoe Type: Boolean (true/false)
local-ipv4- Local tunnel IP address or Auto for automatic
address Type: An IP address, or 'auto'
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
password Password for PPP connection or cellular modem settings
Type: internetPassword
password-hash The hash of the user password
Type: passwordHash
type Connection type
Type: Press TAB to see available options
username User name for PPP connection or cellular modem settings
Type: A string that contains all printable characters but a single or double quote- like
characters. Usually <username>@<ISP>
vci VCI value for the ADSL connection
Type: A number between 0 and 65535
vlan-id VLAN ID
Type: A number with no fractional part (integer)
vpi VPI value for the ADSL connection
Type: A number between 0 and 255
DMZ
Syntax for SFP-DSL type ppoe
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 473
add internet-connection (physical interface)
Parameters
Parameter Description
conn-test- Connection test timeout
timeout Type: A number with no fractional part (integer)
ls-unnumbered- Unnumbered PPPoE lets you manage a range of IP addresses and dial only once
ppoe Type: Boolean (true/false)
local-ipv4- Local tunnel IP address or Auto for automatic
address Type: An IP address, or 'auto'
password Password for PPP connection settings
Type: internetPassword
password-hash The hash of the user password
Type: passwordHash
username User name for PPP connection settings Type: A string that contains all printable
characters but a single or double quote- like characters. Usually
<username>@<ISP>
vci VCI value for the ADSL connection Type: A number between 0 and 65535
vpi VPI value for the ADSL connection Type: A number between 0 and 255
Example
Syntax for SFP-DSL type ipoe-dynamic
Parameters
Parameter Description
conn-test-timeout Connection test timeout
Type: A number with no fractional part (integer)
vci VCI value for the ADSL connection
Type: A number between 0 and 65535
vpi VPI value for the ADSL connection
Type: A number between 0 and 255
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 474
add internet-connection (physical interface)
Parameter Description
encapsulation Encapsulation type for the ADSL connection
Options:
n llc
n vcmux
Example
Syntax for SFP-DSL type ipoe-static
Parameters
Parameter Description
conn-test-timeout Connection test timeout
Type: A number with no fractional part (integer)
default-gw WAN default gateway (in the advanced section of PPTP and l2TP)
Type: IP address
dns-primary First DNS server IP address
Type: IP address
dns-secondary Second DNS server IP address
Type: IP address
dns-tertiary Third DNS server IP address
Type: IP address
vci VCI value for the ADSL connection
Type: A number between 0 and 65535
vpi VPI value for the ADSL connection
Type: A number between 0 and 255
ipv4-address IP address field (for static IP and bridge settings)
Type: IP address
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 475
add internet-connection (physical interface)
Parameter Description
mask-length Subnet mask length
Type: A string that contains numbers only
subnet-mask Subnet mask Type: A subnet mask, or 255.255.255.255
Example
Syntax for DHCP
Parameters
Parameter Description
conn-test-timeout Connection test timeout
Type: A number with no fractional part (integer)
interface Interface name
Type: Press TAB to see available options
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
type Connection type
Type: Press TAB to see available options
vlan-id VLAN ID
Type: A number with no fractional part (integer)
Syntax for Static IP
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 476
add internet-connection (physical interface)
Parameters
Parameter Description
conn-test-timeout Connection test timeout
Type: A number with no fractional part (integer)
interface Interface name
Type: Press TAB to see available options
default-gw WAN default gateway (in the advanced section of PPTP and l2TP)
Type: IP address
dns-primary First DNS server IP address
Type: IP address
dns-secondary Second DNS server IP address
Type: IP address
dns-tertiary Third DNS server IP address
Type: IP address
ipv4-address IP address field (for static IP and bridge settings)
Type: IP address
mask-length Subnet mask length
Type: A string that contains numbers only
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
subnet-mask Subnet mask
Type: A subnet mask, or 255.255.255.255
type Connection type
Type: Press TAB to see available options
vlan-id VLAN ID
Type: A number with no fractional part (integer)
Syntax for L2TP
add internet-connection name <name> interface DMZ type l2tp server <server>
password-hash <password-hash>
add internet-connection name <name> interface DMZ type l2tp server <server>
password <password> username <username> { local-ipv4-address <local-ipv4-
address> wan-ipv4-address <wan-ipv4-address> wan-mask-length <wan-mask-
length>
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 477
add internet-connection (physical interface)
add internet-connection name <name> interface DMZ type l2tp server <server>
password <password> username <username> { local-ipv4-address <local-ipv4-
address> wan-ipv4-address <wan-ipv4-address> wan-subnet-mask <wan-mask-
length> default-gw <default-gw>} { is-unnumbered-pppoe <is-unnumbered-
pppoe> local-ipv4-address <local-ipv4-address>}
Parameters
Parameter Description
conn-test- Connection test timeout
timeout Type: A number with no fractional part (integer)
interface Interface name
Type: Press TAB to see available options
default-gw WAN default gateway (in the advanced section of PPTP and l2TP)
Type: IP address
is-unnumbered- Unnumbered PPPoE lets you manage a range of IP addresses and dial only once
pppoe Type: Boolean (true/false)
local-ipv4- Local tunnel IP address or Auto for automatic
address Type: An IP address, or 'auto'
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
password Password for PPP connection or cellular modem settings
Type: internetPassword
password-hash The hash of the user password
Type: passwordHash
server Server IP address
Type: IP address
type Connection type
Type: Press TAB to see available options
username User name for PPP connection or cellular modem settings
Type: A string that contains all printable characters but a single or double quote- like
characters. Usually <username>@<ISP>
vlan-id VLAN ID
Type: A number with no fractional part (integer)
wan-ipv4- Wan IP address wrapper
address Type: An IP address, or 'auto'
wan-mask- WAN subnet mask length
length Type: A string that contains numbers only
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 478
add internet-connection (physical interface)
Parameter Description
wan-subnet- WAN subnet mask (in the advanced section)
mask Type: Subnet mask
Syntax for PPPoE
Parameters
Parameter Description
conn-test- Connection test timeout
timeout Type: A number with no fractional part (integer)
interface Interface name
Type: Press TAB to see available options
is-unnumbered- Unnumbered PPPoE lets you manage a range of IP addresses and dial only once
pppoe Type: Boolean (true/false)
local-ipv4- Local tunnel IP address or Auto for automatic
address Type: An IP address, or 'auto'
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
password Password for PPP connection or cellular modem settings
Type: internetPassword
password-hash The hash of the user password
Type: passwordHash
type Connection type
Type: Press TAB to see available options
username User name for PPP connection or cellular modem settings
Type: A string that contains all printable characters but a single or double quote- like
characters. Usually <username>@<ISP>
vlan-id VLAN ID
Type: A number with no fractional part (integer)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 479
add internet-connection (physical interface)
Syntax for PPTP
add internet-connection name <name> interface DMZ type pptp server <server>
password-hash <password-hash>
add internet-connection name <name> interface DMZ type pptp server <server>
password <password> username <username> { { local-ipv4-address <local-ipv4-
address> wan-ipv4-address <wan-ipv4-address> wan-mask-length <wan-mask-
length>
add internet-connection name <name> interface DMZ type pptp server <server>
password <password> username <username> { local-ipv4-address <local-ipv4-
address> wan-ipv4-address <wan-ipv4-address> wan-subnet-mask <wan-subnet-
mask> default-gw <default-gw>} { is-unnumbered-pppoe <is-unnumbered-pppoe>
local-ipv4-address <local-ipv4-address>}
Parameters
Parameter Description
conn-test- Connection test timeout
timeout Type: A number with no fractional part (integer)
interface Interface name
Type: Press TAB to see available options
default-gw WAN default gateway (in the advanced section of PPTP and l2TP)
Type: IP address
dns-primary First DNS server IP address
Type: IP address
dns-secondary Second DNS server IP address
Type: IP address
dns-tertiary Third DNS server IP address
Type: IP address
encapsulation Encapsulation type for the ADSL connection
Options: llc, vcmux
ipv4-address IP address field (for static IP and bridge settings)
Type: IP address
is-unnumbered- Unnumbered PPPoE lets you manage a range of IP addresses and dial only once
pppoe Type: Boolean (true/false)
isVlan isVlan
Type: Boolean (true/false)
local-ipv4- Local tunnel IP address or Auto for automatic
address Type: An IP address, or 'auto'
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 480
add internet-connection (physical interface)
Parameter Description
mask-length Subnet mask length
Type: A string that contains numbers only
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
password Password for PPP connection or cellular modem settings
Type: internetPassword
password-hash The hash of the user password
Type: passwordHash
server Server IP address
Type: IP address
standard The ADSL standard to use
Options: multimode, t1413, glite, gdmt, adsl2, adsl2+
subnet-mask Subnet mask
Type: A subnet mask, or 255.255.255.255
type Connection type
Type: Press TAB to see available options
username User name for PPP connection or cellular modem settings
Type: A string that contains all printable characters but a single or double quote- like
characters. Usually <username>@<ISP>
vci VCI value for the ADSL connection
Type: A number between 0 and 65535
vlan-id VLAN ID
Type: A number with no fractional part (integer)
vpi VPI value for the ADSL connection
Type: A number between 0 and 255
wan-ipv4- Wan IP address wrapper
address Type: An IP address, or 'auto'
wan-mask- WAN subnet mask length
length Type: A string that contains numbers only
wan-subnet- WAN subnet mask (in the advanced section)
mask Type: Subnet mask
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 481
add internet-connection (physical interface)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 482
add internet-connection (3G/4G modem)
add internet-connection (3G/4G modem)
Description
Adds a new internet connection using an external 3G/4G modem connected directly to the appliance
(multiple internet connection can engage in High Availability/Load Sharing).
Syntax
USB:
add internet-connection name <name> typeanalog use-serial-portfalse number
<number> { username <username> password-hash <password-hash>}
Parameters
Parameter Description
apn APN (cellular modem settings)
Type: A string that contains [a-z], [0-9], '-' and '.' characters
conn-test- Connection test timeout
timeout Type: A number with no fractional part (integer)
flow-control Flow control (serial port settings)
Options: rts-cts, xon-xoff
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
number Dialed number of the cellular modem settings
Type: A sequence of numbers and #,* characters
password Password for PPP connection settings
Type: internetPassword
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 483
add internet-connection (3G/4G modem)
Parameter Description
password- The hash of the user password
hash Type: passwordHash
port-speed Port speed (serial port settings)
Options: 9600, 19200, 38400, 57600, 115200, 230400
type Connection type
Type: Press TAB to see available options
use-serial- Use serial port
port Type: Boolean (true/false)
username User name for PPP connection settings
Type: A string that contains all printable characters but a single or double quote- like
characters. Usually <username>@<ISP>
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 484
delete internet-connection
delete internet-connection
Deletes an existing internet connection or internet connection related configuration.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 485
delete internet-connection
delete internet-connection
Description
Deletes an existing internet connection by name.
Syntax
Parameters
Parameter Description
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 486
deleter internet-connection
deleter internet-connection
Description
Deletes an existing internet connection's ping servers, configured for connection health monitoring.
Syntax
Parameters
Parameter Description
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 487
delete internet-connections
delete internet-connections
Description
Deletes all existing internet connections.
Syntax
delete internet-connections
Parameters
Parameter Description
n/a
Example
delete internet-connections
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 488
set internet-connection
set internet-connection
Configures internet connections settings.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 489
set internet-connection
set internet-connection
Description
Configures an existing internet connection.
Syntax
Parameters
Parameter Description
auto-negotiation Disable auto negotiation and manually define negotiation link speed
Options: on, off
link-speed Link speed
Options: 100/full, 100/half, 10/full, 10/half
mac-addr Default mac address wrapper
Type: A MAC address or 'default'
mtu MTU size. Select 'default' for default value.
Type: A string of alphanumeric characters without space between them
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 490
set internet-connection
set internet-connection
Description
Configures advanced settings for an existing internet connection.
Syntax
Parameters
Parameter Description
connect-on-demand Holds the status of the connect on demand feature
Type: Boolean (true/false)
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 491
set internet-connection
set internet-connection
Description
Enable/Disable an existing internet connection.
Syntax
Parameters
Parameter Description
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
state Connection enabled/disabled
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 492
set internet-connection
set internet-connection
Description
Configures advanced settings for an existing internet connection. Download bandwidth details allow QoS
blade to run on this internet connection in locally/SMP managed mode and when managed using an LSM
profile.
Syntax
Parameters
Parameter Description
bandwidth ISP download bandwidth
Type: A number with no fractional part (integer)
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
qos-download Enable QoS (quality of service) restriction on inbound traffic (download)
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 493
set internet-connection
set internet-connection
Description
Configures advanced settings for an existing internet connection. Upload bandwidth details allow QoS blade
to run on this internet connection in locally/SMP managed mode and when managed using an LSM profile.
Syntax
Parameters
Parameter Description
bandwidth ISP upload bandwidth
Type: A number with no fractional part (integer)
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
qos-upload Enable QoS (quality of service) restriction on outbound traffic (upload)
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 494
set internet-connection
set internet-connection
Description
Configure hide NAT behavior on an existing internet connection. It is possible to disable hide-NAT from a
specific internet connection.
Syntax
Parameters
Parameter Description
disable-nat Disable NAT(Network Address Translation) for traffic going through this Internet
connection
Type: Boolean (true/false)
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 495
set internet-connection
set internet-connection
Description
Configures multiple ISP settings for an existing internet connection.
Syntax
Parameters
Parameter Description
ha-priority Priority of the connection in HA
Type: A number with no fractional part (integer)
load-balancing-weight Internet connection weight for load balancing configuration
Type: A number with no fractional part (integer)
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 496
set internet-connection
set internet-connection
Description
Configures advanced settings for an existing internet connection. It is possible to remove a configured
internet connection from being used as a default route, making it available for traffic through
manual/dynamic routing rules.
Syntax
Parameters
Parameter Description
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space
characters
route-traffic-through- default- In order to route traffic through this connection you need to add specific
gateway routes through it
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 497
set internet-connection
set internet-connection
Description
Configures settings for an existing internet connection.
Syntax
Parameters
Parameter Description
default-gw Default gateway
Type: IP address
dns-primary First DNS server IP address
Type: IP address
dns-secondary Second DNS server IP address
Type: IP address
dns-tertiary Third DNS server IP address
Type: IP address
ipv4-address IP address field (for static IP and bridge settings)
Type: IP address
is-unnumbered- Unnumbered PPoE lets you manage a range of IP addresses and dial only once.
pppoe Type: Boolean (true/false)
local-ipv4- Local tunnel IP address or Auto for automatic
address Type: An IP address, or 'auto'
mask-length Subnet mask length
Type: A string that contains numbers only
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 498
set internet-connection
Parameter Description
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
password Password for PPP connection or cellular modem settings
Type: internetPassword
password-hash The hash of the user password
Type: passwordHash
server Server IP address
Type: IP address
subnet-mask Subnet mask
Type: A subnet mask, or 255.255.255.255
type Connection type
Type: Press TAB to see available options
username User name for PPP connection or cellular modem settings
Type: A string that contains all printable characters but a single or double quote- like
characters. Usually <username>@<ISP>
wan-ipv4- Wan IP address wrapper
address Type: An IP address, or 'auto'
wan-mask- WAN subnet mask length
length Type: A string that contains numbers only
wan-subnet- WAN subnet mask (in the advanced section)
mask Type: Subnet mask
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 499
set internet-connection
set internet-connection
Description
Configures advanced settings for an existing internet connection.
Syntax
Parameters
Parameter Description
encapsulation Encapsulation type for the ADSL connection
Options: llc, vcmux
is-unnumbered- Unnumbered PPPoE lets you manage a range of IP addresses and dial only once.
pppoe Type: Boolean (true/false)
local-ipv4- Local tunnel IP address or Auto for automatic
address Type: An IP address, or 'auto'
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
password Password for PPP connection or cellular modem settings
Type: internetPassword
password-hash The hash of the user password.
Type: passwordHash
type Connection type
Type: Press TAB to see available options
username User name for PPP connection or cellular modem settings
Type: A string that contains all printable characters but a single or double quotelike
characters. Usually <username>@<ISP>
vci VCI value for the ADSL connection
Type: A number between 0 and 65535
vpi VPI value for the ADSL connection
Type: A number between 0 and 255
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 500
set internet-connection
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 501
set internet-connection
set internet-connection
Description
Configures advanced settings for an existing internet connection. This command is available only for
hardware that contains a DSL port.
Syntax
Parameters
Parameter Description
default-gw WAN default gateway (in the advanced section of PPTP and l2TP)
Type: IP address
encapsulation Encapsulation for the ADSL connection
Options: llc, vcmux
idle-time Disconnect idle time
Type: A number with no fractional part (integer)
method Authentication method
Options: auto, pap, chap
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
standard The ADSL standard to use
Options: multimode, t1413, glite, gdmt, adsl2, adsl2+
type Connection type
Type: Press TAB to see available options
vci VCI value for the ADSL connection
Type: A number between 0 and 65535
vpi VPI value for the ADSL connection
Type: A number between 0 and 255
wan-ipv4-address Wan IP address wrapper
Type: An IP address, or 'auto'
wan-mask-length WAN subnet mask length
Type: A string that contains numbers only
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 502
set internet-connection
Parameter Description
wan-subnet-mask WAN subnet mask (in the advanced section)
Type: Subnet mask
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 503
set internet-connection
set internet-connection
Description
Configures advanced settings for an existing internet connection. This command is available only for
hardware that contains a DSL port.
Syntax
Parameters
Parameter Description
default-gw Default gateway
Type: IP address
dns-primary First DNS server IP address
Type: IP address
dns-secondary Second DNS server IP address
Type: IP address
dns-tertiary Third DNS server IP address
Type: IP address
encapsulation Encapsulation type for the ADSL connection
Options: llc, vcmux
idle-time Disconnect idle time
Type: A number with no fractional part (integer)
ipv4-address IP address field (for static IP and bridge settings)
Type: IP address
is-unnumbered- Unnumbered PPPoE lets you manage a range of IP addresses and dial only
pppoe once
Type: Boolean (true/false)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 504
set internet-connection
Parameter Description
isVlan isVlan
Type: Boolean (true/false)
local-ipv4-address Local tunnel IP address or Auto for automatic
Type: An IP address, or 'auto'
mask-length Subnet mask length
Type: A string that contains numbers only
method Authentication method
Options: auto, pap, chap
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
password Password for PPP connection or cellular modem settings
Type: internetPassword
password-hash The hash of the user password
Type: passwordHash
standard The ADSL standard to use
Options: multimode, t1413, glite, gdmt, adsl2, adsl2+
subnet-mask Subnet mask
Type: A subnet mask, or 255.255.255.255
type Connection type
Type: Press TAB to see available options
username User name for PPP connection or cellular modem settings
Type: A string that contains all printable characters but a single or double
quotelike
characters. Usually <username>@<ISP>
vci VCI value for the ADSL connection
Type: A number between 0 and 65535
vlan-id VLAN ID
Type: A number with no fractional part (integer)
vpi VPI value for the ADSL connection
Type: A number between 0 and 255
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 505
set internet-connection
set internet-connection
Description
Configures settings for an existing internet connection.
Syntax
Parameters
Parameter Description
apn APN (cellular modem settings)
Type: A string that contains [a-z], [0-9], '-' and '.' characters
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
number Dialed number of the cellular modem settings
Type: A sequence of numbers and #,* characters
password Password for PPP connection or cellular modem settings
Type: internetPassword
password- The hash of the user password
hash Type: passwordHash
type Connection type
Type: Press TAB to see available options
username User name for PPP connection or cellular modem settings
Type: A string that contains all printable characters but a single or double quote- like
characters. Usually <username>@<ISP>
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 506
set internet-connection
set internet-connection
Description
Configures health monitoring settings for an existing internet connection.
Syntax
Parameters
Parameter Description
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
probe-next-hop Automatically detect loss of connectivity to the default gateway
Type: Boolean (true/false)
probe-servers Monitor connection state by sending probe packets to one or more servers on the
Internet
Type: Boolean (true/false)
probing- Connection probing method
method Options: icmp, dns
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 507
set internet-connection
set internet-connection
Description
Configures health monitoring settings for an existing internet connection.
Syntax
Parameters
Parameter Description
first First IP address for the probing method (when using connection monitoring)
Type: An IP address or host name
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
probing-method Connection probing method
Options: icmp, dns
second Second IP address for the probing method (when using connection monitoring)
Type: An IP address or host name
third Third IP address for the probing method (when using connection monitoring)
Type: An IP address or host name
Example
set internet-connection interface DMZ
Description
Configure settings for an SFP DSL internet connection over the DMZ port in 1570 / 1590 appliances that do
not have an internal DSL port.
Syntax for SFP-DSL type ppoe
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 508
set internet-connection
Parameters
Parameter Description
conn-test- Connection test timeout
timeout Type: A number with no fractional part (integer)
ls-unnumbered- Unnumbered PPPoE lets you manage a range of IP addresses and dial only once
ppoe Type: Boolean (true/false)
local-ipv4- Local tunnel IP address or Auto for automatic
address Type: An IP address, or 'auto'
password Password for PPP connection settings
Type: internetPassword
password-hash The hash of the user password
Type: passwordHash
username User name for PPP connection settings Type: A string that contains all printable
characters but a single or double quote- like characters. Usually
<username>@<ISP>
vci VCI value for the ADSL connection Type: A number between 0 and 65535
vpi VPI value for the ADSL connection Type: A number between 0 and 255
Example
Syntax for SFP-DSL type ipoe-dynamic
Parameters
Parameter Description
conn-test-timeout Connection test timeout
Type: A number with no fractional part (integer)
vci VCI value for the ADSL connection
Type: A number between 0 and 65535
vpi VPI value for the ADSL connection
Type: A number between 0 and 255
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 509
set internet-connection
Parameter Description
encapsulation Encapsulation type for the ADSL connection
Options:
n llc
n vcmux
Example
Syntax for SFP-DSL type ipoe-static
Parameters
Parameter Description
conn-test-timeout Connection test timeout
Type: A number with no fractional part (integer)
default-gw WAN default gateway (in the advanced section of PPTP and l2TP)
Type: IP address
dns-primary First DNS server IP address
Type: IP address
dns-secondary Second DNS server IP address
Type: IP address
dns-tertiary Third DNS server IP address
Type: IP address
vci VCI value for the ADSL connection
Type: A number between 0 and 65535
vpi VPI value for the ADSL connection
Type: A number between 0 and 255
ipv4-address IP address field (for static IP and bridge settings)
Type: IP address
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 510
set internet-connection
Parameter Description
mask-length Subnet mask length
Type: A string that contains numbers only
subnet-mask Subnet mask Type: A subnet mask, or 255.255.255.255
Example
set internet-connection {name} type cellular
Description
Sets the LTE modem internet connection to a specific carrier.
Syntax
Parameter Description
apn APN (Access Point Name) of SIM 1(optional).
pin PIN (Personal Identification Number) of SIM 1(optional).
apn-sim1-authentication- The APN authentication method provided by your cellular network
method
carrier for SIM1. Values:
n pap
n chap
n none
apn-sim1-password The APN password provided by your cellular network carrier for SIM1.
Password String. Maximum length of 15 characters. Required when apn-sim1-
authentication-method = pap or chap
apn-sim1-username The APN username provided by your cellular network carrier for SIM1.
Maximum length of 59 characters. Required when apn-sim1-authentication-
method = pap or chap
apn-sim2-authentication- The APN authentication method provided by your cellular network carrier for
method SIM2.
n pap
n chap
n none
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 511
set internet-connection
Parameter Description
apn-sim2-password The APN password provided by your cellular network carrier for SIM2.
Password String. Maximum length of 15 characters. Required when apn-sim2-
authentication-method = pap or chap
apn-sim2-username The APN username provided by your cellular network carrier for SIM2.
Maximum length of 59 characters. Required when apn-sim2-authentication-
method = pap or chap
apn-sim2 APN (Access Point Name) of SIM 2 (optional).
pin-sim2 PIN number of SIM 2 (optional).
primary-sim The preferred SIM to use for the connection.
disable-sim Allows disabling of one of the SIM cards.
name The name of the internet connection.
sim1-carrier- Predefined configuration and firmware package required for specific cellular
configuation-package - network carriers for SIM1.
sim2-carrier- Predefined configuration and firmware package required for specific cellular
configuation-package - network carriers for SIM2.
Example
set internet-connection {name} type usb-cellular
Description
Configure the settings for a new cellular interface (USB).
Syntax
Parameters
Parameter Description
apn The Access Point Name given to you by your cellular network carrier for SIM1.
password-hash The hash of the user password.
password Password for PPP connection or cellular modem settings.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 512
set internet-connection
Parameter Description
initialization-string The initialization string for the cellular modem settings.
is-unnumbered- Unnumbered PPPoE lets you manage a range of IP addresses and dial only
pppoe once.
local-ipv4-address Local tunnel IP address or auto for automatic.
method Authentication method.
number Dialed number of the cellular modem settings.
username User name for PPP connection or cellular modem settings.
conn-test-timeout Connection test timeout.
name Connection name.
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 513
show internet-connection
show internet-connection
Shows configuration and details of defined internet connections.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 514
show internet-connection
show internet-connection
Description
Shows configuration and details of a defined internet connection.
Syntax
Parameters
Parameter Description
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 515
show internet-connection
show internet-connection
Description
Shows configured ping servers for health monitoring of defined internet connection.
Syntax
Parameters
Parameter Description
name Connection name
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_' and space characters
Example
show internet-connection {name} type cellular
Description
Shows the carrier connection name for LTE internal modem.
Syntax
Parameters
Parameter Description
sim1-carrier-configuation- Predefined configuration and firmware package required for specific
package - cellular network carriers for SIM1.
sim2-carrier-configuation- Predefined configuration and firmware package required for specific
package - cellular network carriers for SIM2.
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 516
show internet-connection
Output
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 517
show internet-connection
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 518
show internet-connection
prefix-length: 64
dns-secondary-ipv6:
type: pppoa
qos-upload: false
ipv6-address: ::
apn-sim2:
failover-after-ping-failure-percent:63
local-ipv4-address: auto
cellular-generation: 4g
bridge-name:
bridge-type: dhcp
interface-ipv6: WAN
type: usb-cellular
cluster-status: non-ha
interface: cellular
disable-sim: none
hostname-via-dhcp: false
ip-version: ipv4
inbound-bandwidth: 1000000
probing-method: icmp
mask-length: 28
ipv6-address:
state: true
type: pppoe
name: Internet1
primary-sim: sim1
wan-ip-assignment: automatic
country:
dns-primary-ipv6:
probingStatus: table: 0xf6dd0a48
username:
vci: 0
access-point-password:
status:
bond-id:
second-name: Level 3 Communications
connect-on-demand: false
access-point-signal-strength:
apn-sim1-authentication-method:none
route-traffic-through-default-gateway:true
use-serial-port: false
pin:
interface: cellular
server:
default-gw: 10.152.144.40
apn-sim1-username:
dmz-link-speed: 10/half
mtu: 1500
wan-default-mac-address: 00:1C:7F:95:E8:25
standard:
sim1-carrier-configuation-package:
bond-slaves:
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 519
show internet-connection
access-point-wpa-password:
probe-servers: true
disable-nat: false
dmz-default-mac-address: 00:1C:7F:95:E8:27
apn:
bond-hash-policy: layer2
active-sim: sim2
default-gw:
auto-negotiation: on
ipv4-address: 10.152.144.39
apn-sim2-username:
ip-address: 10.152.144.39
password:
access-point-radio-type:
number: *99#
vlan-id: 0
failover-after-ping-failures: 1
apn-sim2-authentication-method:none
lan-link-speed:
linked-connection-id:
access-point-operation-mode:
wan-mask-length:
conn-duration: 3396
cellularRadioMode: on
password:
outbound-bandwidth: 1000000
status-type:
username:
type-ipv6: auto-obtain
wan-link-speed: 10/half
bond-mode: 802.3ad
password:
access-point-user-name:
mtu: 1500
apn-sim1-password:
ha-priority: 1
port-speed: 115200
type-ipv6: pppoe-ipv6
vpi: 0
encapsulation: llc
service-rovider:
third-name: OpenDNS
service-name:
mac-addr: default
dial: tone
bond-mii-interval: 100
password:
probing-frequency: 3
flow-control: rts-cts
method: auto
sim2-carrier-configuation-package:
linked-connection:
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 520
show internet-connection
default-gw-ipv6:
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 521
show internet-connections
show internet-connections
Description
Shows details and configuration of all internet connections.
Syntax
show internet-connections
Parameters
Parameter Description
n/a
Example
show internet-connections
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 522
show internet-connections table
show internet-connections table
Description
Shows details and configuration of all internet connections in a table.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 523
show internet-connections table
set iot-stats
Description
Enable or disable IoT collecting statistics.
Syntax
Parameters
Parameter Description
mode Enable / Disable IoT collecting statistics.
Options:
n on
n off
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 524
show internet-connections table
show iot-stats
Description
Show collected IoT statistics.
Syntax
show iot-stats
Parameters
Parameter Description
n/a
Example
show iot-stats
Output
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 525
internet-connection-bond
internet-connection-bond
delete internet-connection-bond
Description
Delete a link aggregation (bond) between two or more interfaces (WAN).
Syntax
Parameters
Parameter Description
name Connection name
Type: A string that contains [A-Z], [0-9], ’-’, ’@’, ’.’, ’_’ and space characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 526
set internet-connection-bond
set internet-connection-bond
Description
Configure a link aggregation (bond) between two or more interfaces (WAN).
Syntax
Parameters
Parameter Description
bond-hash-policy The bond hash policy
Options: layer2, layer2_3,layer3_4
bond-master The bond Master port
Type: A string that contains [A-Z], [0-9], ’_’, ’.’, ’-’ and ’/’ characters
bond-mii-interval The bond MII interval
Type: A number with no fractional part (integer)
bond-mode The bond operation mode policy
Options: 802.3ad, round-robin, xor, high-availability
name Connection name
Type: A string that contains [A-Z], [0-9], ’-’, ’@’, ’.’, ’_’ and space characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 527
set internet-connection-bond
set internet-connection-bond
Description
Configure a link aggregation (bond) between two or more interfaces (WAN).
Syntax
Parameters
Parameter Description
add-member bondPort1
Type: Type: A string that contains [A-Z], [0-9], ’_’, ’.’, ’-’ and ’/’ characters
name Connection name
Type: A string that contains [A-Z], [0-9], ’-’, ’@’, ’.’, ’_’ and space characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 528
set internet-connection-bond
set internet-connection-bond
Description
Configure a link aggregation (bond) between two or more interfaces (WAN).
Syntax
Parameters
Parameter Description
name Connection name
Type: A string that contains [A-Z], [0-9], ’-’, ’@’, ’.’, ’_’ and space characters
remove-member List of interfaces that are part of the WAN link aggregation (Bond)
Type: String
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 529
show internet-connection-bond
show internet-connection-bond
Description
Show the link aggregation (bond) between two or more interfaces. (WAN).
Syntax
Parameters
Parameter Description
name Connection name
Type: A string that contains [A-Z], [0-9], ’-’, ’@’, ’.’, ’_’ and space characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 530
show internet-connections-bond
show internet-connections-bond
Description
Show the link aggregations (bond) between two or more interfaces (WAN).
Syntax
show internet-connections-bond
Parameters
Parameter Description
n/a
Example
show internet-connections-bond
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 531
internet mode
internet mode
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 532
set internet mode
set internet mode
Description
Configures multiple ISP internet connections behavior. Determines whether traffic will be distributed
automatically across the defined active Internet connections according to the configured load balancing
weights or use the default High Availability behavior based on priorities of each internet connection.
Syntax
Parameters
Parameter Description
lb-mode The load balancing mode
Options: on, off
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 533
show internet mode
show internet mode
Description
Shows multiple internet connections mode (High Availability or Load Sharing.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 534
ip-fragments-params
ip-fragments-params
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 535
set ip-fragments-params
set ip-fragments-params
Configures how the appliance handles IP fragments.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 536
set ip-fragments-params
set ip-fragments-params
Description
Configures how the appliance handles IP fragments.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 537
set ip-fragments-params
set ip-fragments-params
Description
Configures how the appliance handles IP fragments.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 538
show ip-fragments-params
show ip-fragments-params
Description
Shows configuration of IP fragments handling.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 539
ipv6-state
ipv6-state
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 540
set ipv6-state
set ipv6-state
Description
Enable the IPv6 mode of the appliance.
Syntax
set ipv6-state
Parameters
Parameter Description
n/a
Example
set ipv6-state
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 541
show ipv6-state
show ipv6-state
Description
Show if the IPv6 mode of the appliance is enabled or disabled.
Syntax
show ipv6-state
Parameters
Parameter Description
n/a
Example
show ipv6-state
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 542
show ipv6-state
ip-resolving
set ip-resolving
Description
Configure IP Resolving settings.
Syntax
Parameters
Parameter Description
mode Enable / Disable IP Resolving logs enrichment.
Options: on, off
ttl The time (in seconds) for which the hostname resolution will be used. Limited to a range
of 30-86400.
Type: A number with no fractional part (integer)
Example
show ip-resolving
Description
Show IP Resolving.
Syntax
show ip-resolving
Parameters
Parameter Description
n/a
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 543
show ipv6-state
Example
show ip-resolving
Output
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 544
license
license
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 545
fetch license
fetch license
Description
Fetches a license from one of these locations:
n Local gateway - There is an option to specify the file name with the <file_name> parameter.
n User Center at Check Point
n USB device - There is an option to specify the file name with the <file_name> parameter.
Syntax
Parameters
Parameter Description
file_name Name of the file that contains the license
Return Value
0 on success, 1 on failure
Example
fetch license usb file LicenseFile.xml
Output
Success shows OK. Failure shows an appropriate error message.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 546
show license
show license
Description
Shows current license state.
Syntax
show license
Parameters
Parameter Description
n/a
Example
show license
Output
Current license state
fetch license usercenter retry
Description
If the User Center is not available, the appliance tries to fetch the license in the background in defined
intervals (minutes).
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 547
local-group
local-group
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 548
add local-group
add local-group
Description
Adds a new group for user objects.
Syntax
Parameters
Parameter Description
comments Comments
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
name Local group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
remote- Indicates if the users group have remote access permissions
access-on Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 549
delete local-group
delete local-group
Deletes an existing group object for user objects.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 550
delete local-group
delete local-group
Description
Deletes an existing group object for user objects by group object name.
Syntax
Parameters
Parameter Description
name Local group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 551
delete local-group
delete local-group
Description
Deletes all existing group objects for user objects.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 552
set local-group
set local-group
Configures an existing user group object.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 553
set local-group
set local-group
Description
Configures an existing user group object.
Syntax
Parameters
Parameter Description
comments Comments
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
name Local group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
new-name Local group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
remote- Indicates if the users group have remote access permissions
access-on Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 554
set local-group
set local-group
Description
Adds a bookmark to be shown in the SNX landing page to an existing user group object. This is relevant only
if users in this group have VPN remote access privileges.
Syntax
Parameters
Parameter Description
bookmark Text for the bookmark in the SSL Network Extender portal
label
name Local group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 555
set local-group
set local-group
Description
Removes a bookmark from being shown in the SNX landing page to an existing user group object. This is
relevant only if users in this group have VPN remote access privileges.
Syntax
Parameters
Parameter Description
bookmark Text for the bookmark in the SSL Network Extender portal
label
name Local group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 556
show local-group
show local-group
Description
Shows the content of a user group object.
Syntax
Parameters
Parameter Description
name Local group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 557
show local-groups
show local-groups
Description
Shows the content of all user group objects.
Syntax
show local-groups
Parameters
Parameter Description
n/a
Example
show local-groups
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 558
set local-group users
set local-group users
Configures an existing user group object.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 559
set local-group users
set local-group users
Description
Adds a user to an existing user group object.
Syntax
Parameters
Parameter Description
name Local group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
user-name User's name in the local database
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 560
set local-group users
set local-group users
Description
Removes a user from an existing user group object.
Syntax
Parameters
Parameter Description
name Local group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
user-name User's name in the local database
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 561
local-user
local-user
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 562
add local-user
add local-user
Description
Adds a new locally defined user object and configure its VPN remote access permissions.
Syntax
Parameters
Parameter Description
comments Comments
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , .
- : () @
expiration-date Expiration date for a temporary user in format yyyy-mm-dd
Type: A date format yyyy-mm-dd
expiration-time Expiration time for a temporary user in format HH:MM
Type: A time format hh:mm
is-temp-user Indicates if the user entry is temporary
Type: Boolean (true/false)
name User's name in the local database
Type: A string that contains (0-9, a-z, - . @) up to 64 characters without
spaces
password User's password in the local database
Type: A string that contains alphanumeric and special characters
password-hash User's hashed password (used for importing database)
Type: An encrypted password
remote-access-always- Always enable remote access permission for user
on Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 563
delete local-user
delete local-user
Deletes an existing locally defined user object.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 564
delete local-user
delete local-user
Description
Deletes an existing locally defined user object by user name.
Syntax
Parameters
Parameter Description
name User's name in the local database
Type: A string that contains (0-9, a-z, - . @) up to 64 characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 565
delete local-user
delete local-user
Description
Deletes all existing locally defined user objects by user name.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 566
set local-user
set local-user
Configures an existing user object.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 567
set local-user
set local-user
Description
Configures an existing user object.
Syntax
Parameters
Parameter Description
comments Comments
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , .
- : () @
expiration-date Expiration date for a temporary user in format yyyy-mm-dd
Type: A date format yyyy-mm-dd
expiration-time Expiration time for a temporary user in format HH:MM
Type: A time format hh:mm
is-temp-user Indicates if the user entry is temporary
Type: Boolean (true/false)
name User's name in the local database
Type: A string that contains (0-9, a-z, - . @) up to 64 characters without
spaces
new-name User's name in the local database
Type: A string that contains (0-9, a-z, - . @) up to 64 characters without
spaces
password User's password in the local database
Type: A string that contains alphanumeric and special characters
password-hash User's hashed password (used for importing database)
Type: An encrypted password
remote-access-always- Always enable remote access permission for user
on Type: Boolean (true/false)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 568
set local-user
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 569
set local-user
set local-user
Description
Adds a bookmark to be shown in the SNX landing page to an existing user. This is relevant only if the user
has VPN remote access privileges.
Syntax
Parameters
Parameter Description
bookmark label Text for the bookmark in the SSL Network Extender portal
name User's name in the local database
Type: A string that contains (0-9, a-z, - . @) up to 64 characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 570
set local-user
set local-user
Description
Removes a bookmark from being shown in the SNX landing page to an existing user. This is relevant only if
the user has VPN remote access privileges.
Syntax
Parameters
Parameter Description
bookmark label Text for the bookmark in the SSL Network Extender portal
name User's name in the local database
Type: A string that contains (0-9, a-z, - . @) up to 64 characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 571
show local-user
show local-user
Description
Shows the configuration of a locally defined user.
Syntax
Parameters
Parameter Description
name User's name in the local database
Type: A string that contains (0-9, a-z, - . @) up to 64 characters without spaces
Example
Output
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 572
show local-users
show local-users
Description
Shows all locally defined users.
Syntax
show local-users
Parameters
Parameter Description
n/a
Example
show local-users
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 573
local-users expired
local-users expired
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 574
delete local-users expired
delete local-users expired
Description
Deletes all expired locally defined user objects from the database.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 575
show local-users expired
show local-users expired
Description
Shows all expired locally defined users.
Syntax
Parameters
Parameter Description
n.a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 576
show logs
show logs
Description
Shows system and kernel logs.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 577
log-servers-configuration
log-servers-configuration
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 578
set log-servers-configuration
set log-servers-configuration
Description
Configures external log servers for a locally managed device.
Syntax
Parameters
Parameter Description
external-log- Determine if an external log server is active
server- enable Type: Boolean (true/false)
log-server-ip- This IP address is used if the log server is not located on the Security Management
addr Server.
Type: IP address
mgmt-server-ip- This IP address is used for establishing trusted communication between the Check
addr Point Appliance and the log server. Type: IP address
one-time- SIC one time password
password Type: A string that contains alphanumeric and special characters
sic-name Enter the SIC name of the log server object that was defined in SmartDashboard
Type: A SIC name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 579
show log-servers-configuration
show log-servers-configuration
Description
Shows external log server configuration.
Syntax
show log-servers-configuration
Parameters
Parameter Description
n/a
Example
show log-servers-configuration
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 580
maas
maas
connect maas
Description
Connect to Management as a Service (MaaS) to manage policy, log analysis, and reporting log retention.
Syntax
Parameters
Parameter Description
auth-token Authentication token is used for connecting to MAAS
Type: base64
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 581
set maas
set maas
Description
Configure the settings for Management as a Service (MaaS).
Syntax
Parameters
Parameter Description
mode Connection to MAAS mode
Options: enable, disable, stop-using
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 582
show maas
show maas
Description
Show if connected to Management as a Service (MaaS).
Syntax
show maas
Parameters
Parameter Description
n/a
Example
show maas
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 583
mac-filtering-list
mac-filtering-list
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 584
add mac-filtering-list
add mac-filtering-list
Description
Add a MAC address to the list of addresses allowed to access LAN/DMZ networks.
Syntax
Parameters
Parameter Description
mac MAC address to allow
Type: MAC address
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 585
delete mac-filtering-list
delete mac-filtering-list
Description
Delete a MAC address from the list of addresses allowed to access LAN/DMZ networks.
Syntax
Parameters
Parameter Description
mac MAC address to allow
Type: MAC address
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 586
show mac-filtering-list
show mac-filtering-list
Description
Show the MAC addresses that are allowed to access LAN/DMZ networks.
Syntax
show mac-filtering-list
Parameters
Parameter Description
n/a
Example
show mac-filtering-list
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 587
mac-filtering-settings
mac-filtering-settings
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 588
set mac-filtering settings
set mac-filtering settings
Configure the settings for MAC filtering.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 589
set mac-filtering-settings
set mac-filtering-settings
Description
Configure the settings for MAC filtering.
Syntax
Parameters
Parameter Description
state MAC filtering state
Options: on, off
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 590
set mac-filtering settings
set mac-filtering settings
Description
Configure the settings for MAC filtering.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 591
set mac-filtering settings
set mac-filtering settings
Description
Configure the settings for MAC filtering.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 592
show mac-filtering-settings
show mac-filtering-settings
Show the settings for MAC filtering.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 593
show mac-filtering-settings
show mac-filtering-settings
Description
Show the settings for MAC filtering.
Syntax
show mac-filtering-settings
Parameters
Parameter Description
n/a
Example
show mac-filtering-settings
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 594
show mac-filtering-settings
show mac-filtering-settings
Description
Show the advanced settings for MAC filtering.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 595
set mobile-settings
set mobile-settings
Description
Configure settings for a mobile device. In this case, for when the pairing code expires.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 596
set mobile-settings
set mobile-settings
Description
Configure settings for a mobile device.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 597
show mobile-settings
show mobile-settings
Description
Show configured advanced settings for a mobile device.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 598
mobile-device
mobile-device
revoke mobile-device
Description
Remove mobile device from the list of associated devices.
Syntax
Parameters
Parameter Description
id id
Type: A number with no fractional part (Integer)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 599
mobile-settings
mobile-settings
These commands are relevant for mobile settings.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 600
set mobile-settings
set mobile-settings
Description
Configure settings for a mobile device. In this case, for when the pairing code expires.
Syntax
Parameters
Parameter Description
pairing-code-expiration Number of hours until the pairing code expires.
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 601
set mobile-settings
set mobile-settings
Description
Configure settings for a mobile device.
Syntax
Parameters
Parameter Description
not-cloud-server Notification server URL - URL for the cloud service that pushes the notifications.
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 602
show mobile-settings
show mobile-settings
Description
Show configured advanced settings for a mobile device.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 603
mobile-invitation
mobile-invitation
add mobile-invitation
Description
Invitation for a new mobile device.
Syntax
Parameters
Parameter Description
administrator name Administrator Name
Type: A string that contains [A-Z], [0-9], and ’_’ characters
Example
show mobile-invitation
Description
Show which mobile devices are connected.
Syntax
Parameters
Parameter Description
id id
Type: A number with no fractional part (Integer)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 604
mobile-push-notification
mobile-push-notification
show mobile-push-notification
Description
Show mobile push notifications.
Syntax
show mobile-push-notifications
Parameters
Parameter Description
n/a
Example
show mobile-push-notifications
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 605
monitor-mode-network
monitor-mode-network
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 606
add monitor-mode-network
add monitor-mode-network
Description
Configuring "Monitor mode" over interfaces requires a mechanism to determine which are the local
networks within the real topology. One of the options is a manual configuration of this topology using this
command.
Syntax
Parameters
Parameter Description
ipv4-address Indicates a network IP address that will be recognized as Internal
Type: IP address
subnet-mask Network subnet mask
Type: A subnet mask, or 255.255.255.255
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 607
delete monitor-mode-network
delete monitor-mode-network
Description
Deletes manually configured IP addresses that determine the local networks in monitor mode when not
working in automatic detection mode.
Syntax
Parameters
Parameter Description
ipv4-address Indicates a network IP address that will be recognized as Internal
Type: IP address
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 608
set monitor-mode-network
set monitor-mode-network
Description
Configures IP addresses of networks that are manually recognized as local in the non-automatic mode of
monitor mode interface inspection.
Syntax
Parameters
Parameter Description
ipv4-address Indicates a network IP address that will be recognized as Internal
Type: IP address
subnet-mask Network subnet mask
Type: A subnet mask, or 255.255.255.255
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 609
show monitor-mode-networks
show monitor-mode-networks
Description
Shows manually defined local networks for monitor mode configuration.
Syntax
show monitor-mode-networks
Parameters
Parameter Description
n/a
Example
show monitor-mode-networks
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 610
monitor-mode-configuration
monitor-mode-configuration
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 611
set monitor-mode-configuration
set monitor-mode-configuration
Description
Configures mode of work for monitor mode interface inspection. Determines if locally managed networks will
be automatically detected or manually configured.
Syntax
Parameters
Parameter Description
use-defined-networks Indicates if user-defined internal networks are used for Monitor mode
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 612
show monitor-mode-configuration
show monitor-mode-configuration
Description
Shows monitor mode configuration for interfaces.
Syntax
show monitor-mode-configuration
Parameters
Parameter Description
n/a
Example
show monitor-mode-configuration
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 613
message
message
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 614
set message
set message
Description
Configures a banner message for the SSH administrator login
Syntax
Parameters
Parameter Description
msgvalue Indicates the banner messages text
Type: virtual
status Indicates if a banner message for SSH login will appear
Type: Boolean (true/false)
type Indicates the type of the message (only banner supported)
Options: motd, banner, caption
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 615
show message
show message
Shows banner message for the ssh login.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 616
show message
show message
Description
Shows banner message for the ssh login.
Syntax
Parameters
Parameter Description
type Indicates the type of the message (only banner supported)
Options: motd, banner, caption
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 617
show memory usage
show memory usage
Description
Shows the amount of memory that is being used.
Syntax
show memory-usage
Parameters
Parameter Description
n/a
Example
show memory-usage
Output
Success shows used memory. Failure shows an appropriate error message.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 618
show memory usage
set misp-refresh-route
Description
Refresh multiple ISP routes.
Syntax
Parameters
Parameter Description
mode Indicates whether acceleration will refresh routes in multiple ISP configurations.
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 619
nat
nat
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 620
set nat
set nat
Configures general NAT policy settings.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 621
set nat
set nat
Description
Configures if local networks will be hidden by default behind the external IP addresses of the gateway.
Syntax
Parameters
Parameter Description
hide-internal-networks Hide internal networks behind the Gateway's external IP address
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 622
set nat
set nat
Description
Configures advanced NAT policy settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 623
set nat
set nat
Description
Configures advanced NAT policy settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 624
set nat
set nat
Description
Configures advanced NAT policy settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 625
set nat
set nat
Description
Configures advanced NAT policy settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 626
set nat
set nat
Description
Configures advanced NAT policy settings.
Syntax
<nat-destination-client-side-manual>
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 627
set nat
set nat
Description
Configures advanced NAT policy settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 628
set nat
set nat
Description
Configures advanced NAT policy settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 629
set nat
set nat
Description
Configures advanced NAT policy settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 630
set nat
set nat
Description
Configures advanced NAT policy settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 631
set nat
set nat
Description
Configures advanced NAT policy settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 632
set nat
set nat
Description
Configures advanced NAT policy settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 633
set nat
set nat
Description
Configures advanced IP-Pool NAT policy settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 634
show nat
show nat
Shows NAT policy.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 635
show nat
show nat
Description
Shows NAT policy.
Syntax
show nat
Parameters
Parameter Description
n/a
Example
show nat
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 636
show nat
show nat
Description
Shows advanced settings for NAT policy.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 637
nat-rule
nat-rule
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 638
add nat-rule
add nat-rule
Description
Adds a new manual NAT (translation of source/destination/service) rule to the NAT Rule Base.
Syntax
Parameters
Parameter Description
comment Comment for manual NAT rule
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
enable-arp- The gateway will reply to ARP requests sent to the original destination's IP address
proxy (Does not apply to IP ranges/networks) Type: Boolean (true/false)
hide-sources Hide multiple sources behind the translated source addresses
Type: Boolean (true/false)
name name
Type: A string of alphanumeric characters without space between them
original- Original destination of rule
destination
original- Original service of rule
service
original- Original source of rule
source
position The order of the rule in comparison to other manual rules
Type: Decimal number
position- The order of the rule in comparison to other manual rules
above Type: Decimal number
position- The order of the rule in comparison to other manual rules
below Type: Decimal number
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 639
add nat-rule
Parameter Description
translated- Translated destination of rule
destination
translated- Translated service of rule
service
translated- Translated source of rule
source
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 640
delete nat-rule
delete nat-rule
Description
Deletes a manually configured NAT rule by name.
Syntax
Parameters
Parameter Description
name name
Type: A string of alphanumeric characters without space between them
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 641
set nat-rule
set nat-rule
Description
Configures an existing manual NAT rule by name.
Syntax
Parameters
Parameter Description
comment Comment for manual NAT rule
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
disabled Indicates if rule is disabled
Type: Boolean (true/false)
enable-arp- The gateway will reply to ARP requests sent to the original destination's IP address
proxy (Does not apply to IP ranges/networks)
Type: Boolean (true/false)
hide-sources Hide multiple sources behind the translated source addresses
Type: Boolean (true/false)
name name
Type: A string of alphanumeric characters without space between them
original- Original destination of rule
destination
original- Original service of rule
service
original- Original source of rule
source
position The order of the rule in comparison to other manual rules
Type: Decimal number
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 642
set nat-rule
Parameter Description
position-above The order of the rule in comparison to other manual rules
Type: Decimal number
position-below The order of the rule in comparison to other manual rules
Type: Decimal number
translated- Translated destination of rule
destination
translated- Translated service of rule
service
translated- Translated source of rule
source
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 643
show nat-rule
show nat-rule
Description
Shows the name or position of a specific NAT rule. Includes auto-generated rules.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 644
show nat-rules
show nat-rules
Description
Shows configuration of all manually and auto-generated NAT rules.
Syntax
show nat-rules
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 645
show nat-manual-rules
show nat-manual-rules
Description
Shows configuration of manual NAT rules by name or position.
Syntax
Parameters
Parameter Description
<name> Rule name
<position> Rule position
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 646
nat-rule position
nat-rule position
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 647
delete nat-rule position
delete nat-rule position
Description
Deletes a manually configured NAT rule by position.
Syntax
Parameters
Parameter Description
position The order of the rule in comparison to other manual rules
Type: Decimal number
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 648
set nat-rule position
set nat-rule position
Description
Configures an existing manual NAT rule by position
Syntax
Parameters
Parameter Description
comment Comment for manual NAT rule
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . -: () @
disabled Indicates if rule is disabled
Type: Boolean (true/false)
enable-arp- The gateway will reply to ARP requests sent to the original destination's IP address
proxy (Does not apply to IP ranges/networks)
Type: Boolean (true/false)
hide-sources Hide multiple sources behind the translated source addresses
Type: Boolean (true/false)
name name
Type: A string of alphanumeric characters without space between them
original- Original destination of rule
destination
original- Original service of rule
service
original- Original source of rule
source
position The order of the rule in comparison to other manual rules
Type: Decimal number
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 649
set nat-rule position
Parameter Description
position-above The order of the rule in comparison to other manual rules
Type: Decimal number
position-below The order of the rule in comparison to other manual rules
Type: Decimal number
translated- Translated destination of rule
destination
translated- Translated service of rule
service
translated- Translated source of rule
source
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 650
set nat-rule position
Configuring NetFlow
Introduction
NetFlow is an industry standard for traffic monitoring. Cisco developed this network protocol to collect
network traffic patterns and volume.
One host (the NetFlow Exporter) sends information about its network flows to a different host (the NetFlow
Collector).
A network flow is a unidirectional stream of packets that contain the same set of characteristics.
You can configure a Quantum Spark Appliance as an Exporter of NetFlow records for all the traffic that
passes through it.
The NetFlow Collector is a different external server, and you configure it separately.
NetFlow Export configuration is a list of collectors, to which the service sends records:
n To enable NetFlow, configure at minimum one NetFlow Collector.
n To disable NetFlow, remove all NetFlow Collectors from the Gaia Embedded configuration.
You can configure a maxumum of three NetFlow Collectors. Gaia Embedded sends the NetFlow records go
to all configured NetFlowCollectors. If you configure three NetFlow Collectors, Gaia Embedded sends each
NetFlow record three times.
Regardless of which NetFlow export format you configure, Gaia Embedded exports values as set of fields.
The fields
n Source IP address.
n Destination IP address.
n Source port.
n Destination port.
n Ingress physical interface index (defined by SNMP).
n Egress physical interface index (defined by SNMP).
n Packet count for this flow.
n Byte count for this flow.
n Start of flow timestamp (FIRST_SWITCHED).
n End of flow timestamp (LAST_SWITCHED).
n IP protocol number.
n TCP flags from the flow (TCP only).
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 651
set nat-rule position
Notes:
n The IP addresses and TCP/UDP ports the NetFlow reports are the ones, on
which the NetFlow expects to receive traffic.
Therefore, for NAT connections, the NetFlow reports one of the two directions of
the flow with the NATed address.
n NetFlow sends the connection records after the connections terminated.
If the connections are open for a long time, it can take time for the NetFlow to
sends the records.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 652
set nat-rule position
Configuration Procedure for Centrally Managed
1. Configure the NetFlow Export settings in Gaia
a. Add the NetFlow Collector.
See "add netflow collector" below.
b. If needed, change the NetFlow Collector configuration.
See "set netflow collector" on page 655.
2. In ,SmartConsole configure the explicit Access Control rule
a. From the left navigation panel, click Security Policies.
b. Open the applicable policy.
c. In the top left corner, click Access Control > Policy.
d. Add an explicit rule for the traffic that you wish to export with NetFlow:
Services &
Destinatio
Source VPN Application Content Action Track
n
s
e. Publish the SmartConsole session.
f. Install the Access Control policy on the Quantum Spark Appliance object.
add netflow collector
Description
Adds a new NetFlow Collector object (you can configure up to three). The NetFlow records are exported to
each defined collector.
In addition, see "Configuring NetFlow" on page 651.
Syntax
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 653
set nat-rule position
Parameters
Parameter Description
ip <IPv4 Address of Specifies the destination IPv4 address of the NetFlow Collector, to which
Collector> Gaia Embedded sends the NetFlow packets.
Type: IP address
port <Destination Port on Specifies the destination UDP port number on the NetFlow Collector, on
Collector> which the collector listens.
Type: Port number
srcaddr <Source IPv4 Optional: Specifies the source IPv4 address of the NetFlow packets.
Address> This must be an IPv4 address of the local host.
The default is an IPv4 address of the network interface, from which Gaia
Embedded sends the NetFlow packets.
We recommend the default.
Type: IP address
export-format {Netflow_ The NetFlow protocol version to use:
V5 | Netflow_V9}
n Netflow_V5 - Protocol NetFlow v5
n Netflow_V9 - Protocol NetFlow v9 (default)
Each NetFlow protocol version has a different packet format.
is-enabled {true | false} Enables (true) and disables (false) the NetFlow Collector.
Type: Boolean (true/false)
Example
delete netflow collector
Description
Deletes an existing NetFlow Collector.
In addition, see "Configuring NetFlow" on page 651.
Syntax
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 654
set nat-rule position
Parameters
Parameter Description
ip <IPv4 Address of Collector> Selects the configured NetFlow Collector by its destination IPv4
address.
Type: IP address
port <Destination Port on Selects the configured NetFlow Collector by its destination UDP port
Collector> number.
Type: Port number
Example
set netflow collector
Description
Configures an existing NetFlow Collector that you added with the "add netflow collector" on page 653
command.
In addition, see "Configuring NetFlow" on page 651.
Syntax
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 655
set nat-rule position
Parameters
Parameter Description
for-ip <IPv4 Address of Selects the configured NetFlow Collector by its destination IPv4 address.
Collector> Notes:
n If you configured only one NetFlow Collector, it is not
necessary to use the "for-ip" and the "for-port"
parameters.
n If you configured two or three NetFlow Collectors with
different IP addresses, use the "for-ip" parameter.
n If you configured two or three collectors with the same IPv4
address and different UDP ports, you must use the "for-
ip" and the "for-port" parameters to identify the
collectors.
Type: IP address
for-port <Destination Port Selects the configured NetFlow Collector by its destination UDP port
on Collector> number.
Type: Port number
ip <IPv4 Address of Specifies the destination IPv4 address of the NetFlow Collector, to which
Collector> Gaia Embedded sends the NetFlow packets.
Type: IP address
port <Destination Port on Specifies the destination UDP port number on the NetFlow Collector, on
Collector> which the collector listens.
Type: Port number
export-format {Netflow_ The NetFlow protocol version to use:
V5 | Netflow_V9}
n Netflow_V5 - Protocol NetFlow v5
n Netflow_V9 - Protocol NetFlow v9 (default)
Each NetFlow protocol version has a different packet format.
srcaddr <Source IPv4 Optional: Specifies the source IPv4 address of the NetFlow packets.
Address> This must be an IPv4 address of the local host.
The default is an IPv4 address of the network interface, from which Gaia
Embedded sends the NetFlow packets.
We recommend the default.
Type: IP address
is-enabled {true | false} Enables (true) and disables (false) the NetFlow Collector.
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 656
set nat-rule position
show netflow collector
Description
Shows configuration of a specific NetFlow collector.
In addition, see:
n "show netflow collectors" below
n "Configuring NetFlow" on page 651
Syntax
show netflow collector ip [Press TAB to select the configured IPv4 Address
of Collector] port [Press TAB to select the configured Destination Port on
Collector]
Parameters
Parameter Description
ip <IPv4 Address of Collector> Selects the configured NetFlow Collector by its destination IPv4
address.
Type: IP address
port <Destination Port on Selects the configured NetFlow Collector by its destination UDP port
Collector> number.
Type: Port number
Example
show netflow collectors
Description
Shows configuration of all NetFlow collectors.
In addition, see:
n "show netflow collector" above
n "Configuring NetFlow" on page 651
Syntax
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 657
set nat-rule position
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 658
network
network
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 659
add network
add network
Description
Adds a new network address range object (a network and a subnet mask).
Syntax
Parameters
Parameter Description
mask-length Mask length
name Network Object name
Type: String
network-ipv4-address Network address
subnet-mask IP mask used in the related network
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 660
delete network
delete network
Description
Deletes an existing network address range object (a network and a subnet mask) by object name.
Syntax
Parameters
Parameter Description
name Network Object name
Type: String
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 661
set network
set network
Description
Configures an existing network with subnet.
Syntax
Parameters
Parameter Description
mask-length Mask length
name Network Object name
Type: String
network-ipv4-address Network address
subnet-mask IP mask used in the related network
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 662
show network
show network
Description
Shows configuration of a specific IP address network object.
Syntax
Parameters
Parameter Description
name Network Object name
Type: String
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 663
show networks
show networks
Description
Shows configuration of all IP address network objects.
Syntax
show networks
Parameters
Parameter Description
n/a
Example
show networks
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 664
show notifications-log
show notifications-log
Description
Show the notification logs.
Syntax
show notifications-log
Parameters
Parameter Description
n/a
Example
show notifications-log
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 665
notifications-policy
notifications-policy
These commands are relevant for notifications policy.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 666
set notifications-policy
set notifications-policy
Description
Configure the policy for sending notifications to the user.
Syntax
Parameters
Parameter Description
send-detailed- Notification previews may contain information about your network. Turning it off
push- means that the security gateway removes this information from the push notification.
notifications Type: Boolean (true/false)
send-push- Indicates whether notifications are sent to mobile application
notifications Type: Boolean (true/false)
send-cloud- Enable sending cloud notifications.
notifications Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 667
set notifications-policy
set notifications-policy
Description
Configure the policy for sending notifications to the user.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 668
set notifications-policy
set notifications-policy
Description
Configure the policy for sending notifications to the user.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 669
show notifications-policy
show notifications-policy
Description
Show the policy for sending notifications to the user.
Syntax
show notifications-policy
Parameters
Parameter Description
n/a
Example
show notifications-policy
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 670
show notifications-policy
show notifications-policy
Description
Show the policy for sending notifications to the user.
Syntax
show notifications-policy advanced-settings
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 671
ntp
ntp
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 672
set ntp
set ntp
Configures NTP settings.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 673
set ntp
set ntp
Description
Configures NTP settings.
Syntax
Parameters
Parameter Description
auto-adjust-daylight- saving Auto daylight
Options: on, off
local-time-zone Region on earth that has a uniform standard time
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 674
set ntp
set ntp
Description
Enables/Disables NTP functionality.
Syntax
Parameters
Parameter Description
active Region on earth that has a uniform standard time
Options: on, off
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 675
set ntp
set ntp
Description
Configures NTP settings.
Syntax
Parameters
Parameter Description
interval Time interval (minutes) to update date and time settings from the NTP server
Type: A number with no fractional part (integer)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 676
set ntp
set ntp
Description
Configures NTP settings.
Syntax
Parameters
Parameter Description
auth Authentication with NTP servers flag
Type: Press TAB to see available options
secret Key string for authentication with the NTP servers
Type: A string that contains alphanumeric and special characters
secret-id Authentication key identifier
Type: A number with no fractional part. Values are between 4,503,599,627,370,495 to
4,503,599,627,370,495
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 677
show ntp
show ntp
Description
Shows NTP configuration.
Syntax
show ntp
Parameters
Parameter Description
n/a
Example
show ntp
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 678
show ntp active
show ntp active
Description
Shows NTP activation status.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 679
ntp server
ntp server
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 680
set ntp server
set ntp server
Configures NTP server settings.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 681
set ntp server
set ntp server
Description
Configures primary NTP server's IP address.
Syntax
Parameters
Parameter Description
primary Primary NTP server
Type: An IP address or host name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 682
set ntp server
set ntp server
Description
Configures secondary NTP server's IP address.
Syntax
Parameters
Parameter Description
secondary Secondary NTP server
Type: An IP address or host name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 683
show ntp servers
show ntp servers
Description
Shows all defined NTP servers.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 684
os-settings
os-settings
set os-settings
Description
Enable net switch flow control.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 685
set os-settings
set os-settings
Description
Disable automatic transfer of received Internet DHCP client options to internal LAN network DHCP servers.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 686
show os-settings
show os-settings
Description
Show the advanced OS settings for disable DHCP transfer options, enable net switch flow control, and
enable automatic WiFi channel change.
Syntax
Parameters
Parameter Description
n/a
Example
Output
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 687
periodic backup
periodic backup
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 688
set periodic-backup
set periodic-backup
Description
Configures periodic backup to a remote FTP server.
Syntax
Parameters
Parameter Description
day-of-month Day of the month to backup
Type: A number with no fractional part (integer)
day-of-week Day of the week to backup
Options: sunday, monday, tuesday, wednesday, thursday, friday, saturday
encryption-password Encryption password
Type: A string that contains alphanumeric and special characters
file-encryption Choose whether to encrypt the backup data
Type: Boolean (true/false)
hour Scheduled backup hour. The backup will be performed during this hour
Type: A number with no fractional part (integer)
mode Is periodic backup enabled
Type: Boolean (true/false)
schedule Schedule the frequency of the periodic backup
Type: Press TAB to see available options
server-address Backup server name or IPv4 address (FTP)
Type: backupUrl
server-password Backup server password
Type: A string that contains alphanumeric and special characters
server-username Backup server username
Type: A string that contains (0-9, a-z, - . @) up to 64 characters without spaces
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 689
set periodic-backup
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 690
show periodic-backup
show periodic-backup
Description
Shows periodic backup configuration.
Syntax
show periodic-backup
Parameters
Parameter Description
n/a
Example
show periodic-backup
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 691
set property
set property
Description
Disables or enables first time configuration (from the USB autoplay configuration or the WebUI).
Syntax
Parameters
Parameter Description
n/a
Example
n set property USB_auto_configuration off
n set property first-time-wizard off
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 692
privacy settings
privacy settings
set privacy-settings advanced-settings
Description
In Advanced Settings, select if the customer consents to sending diagnostic data to Check Point.
Syntax
Parameters
Parameter Description
customer-consent Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 693
show privacy-settings advanced-settings
show privacy-settings advanced-settings
Description
In Advanced Settings, show if the customer consents to sending diagnostic data.
Syntax
Parameters
Parameter Description
n/a
Example
Sample Output
customer-consent: true
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 694
proxy
proxy
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 695
delete proxy
delete proxy
Description
Deletes configured proxy settings for the appliance.
Syntax
delete proxy
Parameters
Parameter Description
n/a
Example
delete proxy
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 696
set proxy
set proxy
Configures proxy settings for connecting with Check Point update and license servers.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 697
set proxy
set proxy
Description
Configures proxy settings for connecting with Check Point update and license servers, when the device is
located behind a proxy server.
Syntax
Parameters
Parameter Description
port The proxy port
Type: Port number
server The proxy Host name or IP address
Type: An IP address or host name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 698
set proxy
set proxy
Description
Enable/Disable proxy configuration for the device.
Syntax
Parameters
Parameter Description
use-proxy A proxy server between the appliance and the Internet. This proxy server will be used
when the appliance?s internal processes must reach a Check Point server.
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 699
show proxy
show proxy
Description
Shows proxy configuration.
Syntax
show proxy
Parameters
Parameter Description
n/a
Example
show proxy
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 700
qos
qos
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 701
set qos
set qos
Configures QoS policy.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 702
set qos
set qos
Description
Enables/Disables the QoS
Syntax
Parameters
Parameter Description
mode Indicates if QoS blade is enabled
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 703
set qos
set qos
Description
Configures the default QoS policy.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 704
set qos
set qos
Description
Configures advanced QoS settings.
Syntax
<maximum-percentage-of-bandwidth>
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 705
set qos
set qos
Description
Configures advanced QoS settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 706
show qos
show qos
Shows the policy of the QoS blade.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 707
show qos
show qos
Description
Shows the policy of the QoS blade.
Syntax
show qos
Parameters
Parameter Description
n/a
Example
show qos
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 708
show qos
show qos
Description
Shows advanced settings of the QoS blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 709
qos delay-sensitive-service
qos delay-sensitive-service
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 710
set qos delay-sensitive-service
set qos delay-sensitive-service
Configures a default used group of services that are delay sensitive.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 711
set qos delay-sensitive-service
set qos delay-sensitive-service
Description
Adds an existing service object to the default group of services that are delay sensitive.
Syntax
Parameters
Parameter Description
service Service name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 712
set qos delay-sensitive-service
set qos delay-sensitive-service
Description
Removes an existing service object from the default group of services that are delay sensitive.
Syntax
Parameters
Parameter Description
service Service name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 713
show qos delay-sensitive-services
show qos delay-sensitive-services
Description
Shows the group of services that are considered delay sensitive.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 714
qos guarantee-bandwidth-selected-services
qos guarantee-bandwidth-selected-
services
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 715
set qos guarantee-bandwidth-selected-services
set qos guarantee-bandwidth-selected-services
Configures a default used group of services that will be guaranteed bandwidth according to QoS default
policy.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 716
set qos guarantee-bandwidth-selected-services
set qos guarantee-bandwidth-selected-services
Description
Adds an existing service object to the default used group of services that will be guaranteed bandwidth
according to QoS default policy.
Syntax
Parameters
Parameter Description
service Service name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 717
set qos guarantee-bandwidth-selected-services
set qos guarantee-bandwidth-selected-services
Description
Removes an existing service object from the default used group of services that will be guaranteed
bandwidth according to QoS default policy.
Syntax
Parameters
Parameter Description
service Service name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 718
show qos guarantee-bandwidth-selected-services
show qos guarantee-bandwidth-selected-
services
Description
Shows the group of services that can be guaranteed bandwidth in the QoS default policy.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 719
qos-rule
qos-rule
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 720
add qos-rule
add qos-rule
Description
Adds a new bandwidth/latency control rule to the QoS Rule Base.
Syntax
Parameters
Parameter Description
comment Description of the rule
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
destination Network object that is the target of the connection
diffserv-mark DiffServ Mark is a way to mark connections so a third party will handle it. To use this
option, your ISP or private WAN must support DiffServ
Type: Boolean (true/false)
diffserv-mark- To mark packets that will be given priority on the public network according to their
val DSCP, select DiffServ Mark (1-63) and select a value. You can get the DSCP value
from your ISP or private WAN administrator
Type: A number with no fractional part (integer)
guarantee- If true, traffic guarantee is defined
bandwidth Type: Boolean (true/false)
guarantee- Traffic guarantee percentage
percentage Type: A number with no fractional part (integer)
hours-range- If true, time is configured
enabled Type: Boolean (true/false)
hours-range- Time in the format HH:MM
from Type: A time format hh:mm
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 721
add qos-rule
Parameter Description
hours-range- Time in the format HH:MM
to Type: A time format hh:mm
limit- If true, traffic limit is defined
bandwidth Type: Boolean (true/false)
limit- Traffic limit percentage
percentage Type: A number with no fractional part (integer)
log Defines which logging method to use: None - do not log, Log - Create log
Options: none, log
low-latency- The latency of the rule (low or normal)
rule Type: Press TAB to see available options
name name
Type: A string of alphanumeric characters without space between them
position The order of the rule in comparison to other manual rules
Type: Decimal number
position- The order of the rule in comparison to other manual rules
above Type: Decimal number
position- The order of the rule in comparison to other manual rules
below Type: Decimal number
service The network service object that the rule should match to
source Network object or user group that initiates the connection
vpn Indicates if traffic is matched on encrypted traffic only or all traffic
Type: Boolean (true/false)
weight Traffic weight, relative to the weights defined for other rules
Type: A number with no fractional part (integer)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 722
delete qos-rule
delete qos-rule
Deletes an existing bandwidth/latency control rule in the QoS Rule Base.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 723
delete qos-rule
delete qos-rule
Description
Deletes an existing bandwidth/latency control rule in the QoS Rule Base by idx.
Syntax
Parameters
Parameter Description
idx The order of the rule in comparison to other manual rules
Type: Decimal number
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 724
delete qos-rule
delete qos-rule
Description
Deletes an existing bandwidth/latency control rule in the QoS Rule Base by name.
Syntax
Parameters
Parameter Description
name name
Type: A string of alphanumeric characters without space between them
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 725
set qos-rule
set qos-rule
Configures an existing bandwidth/latency control rule within the QoS blade policy.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 726
set qos-rule
set qos-rule
Description
Configures an existing bandwidth/latency control rule within the QoS blade policy by idx.
Syntax
Parameters
Parameter Description
comment Description of the rule
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
destination Network object that is the target of the connection
diffserv-mark DiffServ Mark is a way to mark connections so a third party will handle it. To use this
option, your ISP or private WAN must support DiffServ
Type: Boolean (true/false)
diffserv-mark- To mark packets that will be given priority on the public network according to their
val DSCP, select DiffServ Mark (1-63) and select a value. You can get the DSCP value
from your ISP or private WAN administrator
Type: A number with no fractional part (integer)
disabled Indicates if rule is disabled
Type: Boolean (true/false)
guarantee- If true, traffic guarantee is defined
bandwidth Type: Boolean (true/false)
guarantee- Traffic guarantee percentage
percentage Type: A number with no fractional part (integer)
hours-range- If true, time is configured
enabled Type: Boolean (true/false)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 727
set qos-rule
Parameter Description
hours-range- Time in the format HH:MM
from Type: A time format hh:mm
hours-range- Time in the format HH:MM
to Type: A time format hh:mm
idx The order of the rule in comparison to other manual rules
Type: Decimal number
limit- If true, traffic limit is defined
bandwidth Type: Boolean (true/false)
limit- Traffic limit percentage
percentage Type: A number with no fractional part (integer)
log Defines which logging method to use: None - do not log, Log - Create log
Options: none, log
low-latency- The latency of the rule (low or normal)
rule Type: Press TAB to see available options
name name
Type: A string of alphanumeric characters without space between them
position The order of the rule in comparison to other manual rules
Type: Decimal number
position- The order of the rule in comparison to other manual rules
above Type: Decimal number
position- The order of the rule in comparison to other manual rules
below Type: Decimal number
service The network service object that the rule should match to
source Network object or user group that initiates the connection
vpn Indicates if traffic is matched on encrypted traffic only or all traffic
Type: Boolean (true/false)
weight Traffic weight, relative to the weights defined for other rules
Type: A number with no fractional part (integer)
Example
set qos-rule idx 3.141 source TEXT destination TEXT service TEXT low-
latency-rule normal limit-bandwidth true limit-percentage 80 guarantee-
bandwidth true guarantee-percentage 80 weight 15 log none comment "This is
a comment." vpn true hours-range-enabled true hours-range-from 23:20 hours-
range-to 23:20 diffserv-mark true diffserv-mark-val 5 name word position 2
disabled true
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 728
set qos-rule
set qos-rule
Description
Configures an existing bandwidth/latency control rule within the QoS blade policy by name.
Syntax
Parameters
Parameter Description
comment Description of the rule
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
destination Network object that is the target of the connection
diffserv-mark DiffServ Mark is a way to mark connections so a third party will handle it. To use this
option, your ISP or private WAN must support DiffServ
Type: Boolean (true/false)
diffserv-mark- To mark packets that will be given priority on the public network according to their
val DSCP, select DiffServ Mark (1-63) and select a value. You can get the DSCP value
from your ISP or private WAN administrator
Type: A number with no fractional part (integer)
disabled Indicates if rule is disabled
Type: Boolean (true/false)
guarantee- If true, traffic guarantee is defined
bandwidth Type: Boolean (true/false)
guarantee- Traffic guarantee percentage
percentage Type: A number with no fractional part (integer)
hours-range- If true, time is configured
enabled Type: Boolean (true/false)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 729
set qos-rule
Parameter Description
hours-range- Time in the format HH:MM
from Type: A time format hh:mm
hours-range- Time in the format HH:MM
to Type: A time format hh:mm
limit- If true, traffic limit is defined
bandwidth Type: Boolean (true/false)
limit- Traffic limit percentage
percentage Type: A number with no fractional part (integer)
log Defines which logging method to use: None - do not log, Log - Create log
Options: none, log
low-latency- The latency of the rule (low or normal)
rule Type: Press TAB to see available options
name name
Type: A string of alphanumeric characters without space between them
position The order of the rule in comparison to other manual rules
Type: Decimal number
position- The order of the rule in comparison to other manual rules
above Type: Decimal number
position- The order of the rule in comparison to other manual rules
below Type: Decimal number
service The network service object that the rule should match to
source Network object or user group that initiates the connection
vpn Indicates if traffic is matched on encrypted traffic only or all traffic
Type: Boolean (true/false)
weight Traffic weight, relative to the weights defined for other rules
Type: A number with no fractional part (integer)
Example
set qos-rule name word source TEXT destination TEXT service TEXT low-
latency-rule normal limit-bandwidth true limit-percentage 80 guarantee-
bandwidth true guarantee-percentage 80 weight 15 log none comment "This is
a comment." vpn true hours-range-enabled true hours-range-from 23:20 hours-
range-to 23:20 diffserv-mark true diffserv-mark-val 5 name word position 2
disabled true
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 730
show qos-rule
show qos-rule
Shows configuration of QoS (bandwidth/latency control) rules.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 731
show qos-rule
show qos-rule
Description
Shows configuration of a QoS rule by ID.
Syntax
Parameters
Parameter Description
idx The order of the rule in comparison to other manual rules
Type: Decimal number
position The order of the rule in comparison to other manual rules
Type: Decimal number
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 732
show qos-rule
show qos-rule
Description
Shows configuration of a QoS rule by name.
Syntax
Parameters
Parameter Description
name name
Type: A string of alphanumeric characters without space between them
position The order of the rule in comparison to other manual rules
Type: Decimal number
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 733
show qos-rules
show qos-rules
Description
Shows configuration of a QoS rule by position.
Syntax
Parameters
Parameter Description
position The order of the generated rules in the QoS Rule Base
Type: A number with no fractional part (integer)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 734
radius-server
radius-server
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 735
delete radius-server
delete radius-server
Description
Deletes an existing configured RADIUS server.
Syntax
Parameters
Parameter Description
priority Priority of the choose tab, can be primary or secondary
Type: A number with no fractional part (integer)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 736
set radius-server
set radius-server
Description
Configures RADIUS servers.
Syntax
Parameters
Parameter Description
ipv4-address The IP address of the RADIUS server
Type: IP address
priority Priority of the choose tab, can be primary or secondary
Type: A number with no fractional part (integer)
shared-secret Pre-shared secret between the RADIUS server and the Appliance
Type: A string that contains alphanumeric and special characters
timeout A timeout value in seconds for communication with the RADIUS server
Type: A number with no fractional part (integer)
udp-port The port number through which the RADIUS server communicates with clients. The
default is 1812
Type: A number with no fractional part (integer)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 737
show radius-server
show radius-server
Description
Shows the configuration of a RADIUS server.
Syntax
Parameters
Parameter Description
priority Priority of the choose tab, can be primary or secondary
Type: A number with no fractional part (integer)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 738
show radius-servers
show radius-servers
Description
Shows the configuration of all RADIUS servers.
Syntax
show radius-servers
Parameters
Parameter Description
n/a
Example
show radius-servers
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 739
reach-my-device
reach-my-device
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 740
set reach-my-device
set reach-my-device
Configures the "Reach my device" service, which enables connecting to the device's management portal
even when the device is behind NAT.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 741
set reach-my-device
set reach-my-device
Description
Configures the "Reach my device" service, which enables connecting to the device's management portal
even when the device is behind NAT.
Syntax
Parameters
Parameter Description
existing-host-name Register with an existing host name
Type: Boolean (true/false)
host-name Gateway Host name (DNS Prefix)
Type: A string of alphanumeric characters without space between them
mode Reach my device mode (on/off)
Type: Boolean (true/false)
validation-token Gateway validation token
Type: A string of alphanumeric characters without space between them
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 742
set reach-my-device
set reach-my-device
Description
Configures advanced settings of the "Reach my device" service, which enables connecting to the device's
management portal even when the device is behind NAT.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 743
set reach-my-device
set reach-my-device
Description
Configures advanced settings of the "Reach my device" service, which enables connecting to the device's
management portal even when the device is behind NAT.
Syntax
<reach-my-device-server-addr>
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 744
show reach-my-device
show reach-my-device
Shows the configuration of "Reach My Device" cloud service.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 745
show reach-my-device
show reach-my-device
Description
Shows the configuration of "Reach My Device" cloud service.
Syntax
show reach-my-device
Parameters
Parameter Description
n/a
Example
show reach-my-device
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 746
show reach-my-device
show reach-my-device
Description
Shows advanced settings of "Reach My Device" cloud service.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 747
reboot
reboot
Description
Reboots the system.
Syntax
reboot
Parameters
Parameter Description
n/a
Example
reboot
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 748
set remote-access users
set remote-access users
Description
Configures VPN remote access privileges to users defined in configured RADIUS servers.
Syntax
Parameters
Parameter Description
radius-auth Remote users RADIUS authentication
Type: Boolean (true/false)
radius-groups RADIUS groups for authentication. Example: RADIUS-group1, RADIUS-class2
Type: A string that contains [A-Z], [0-9], '-', '@', '.', '_', ',' and space characters
use-radius-groups Use RADIUS groups for authentication
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 749
show remote-access users radius-auth
show remote-access users radius-
auth
Description
Shows RADIUS-based users VPN remote access configuration.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 750
show remote-access users radius-auth
set rest-api
Description
Enable or disable REST API.
Syntax
Parameters
Parameter Description
mode Indicates if REST API is enabled or not.
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 751
show remote-access users radius-auth
show rest-api
Description
Show enabled REST API.
Syntax
show rest-api
Parameters
Parameter Description
n/a
Example
show rest-api
Output
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 752
show remote-access users radius-auth
generate report cloud-report
Description
Generate a cloud report.
Syntax
Parameters
Parameter Description
type The report type
Options:
n monthly
n daily
n weekly
n hourly
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 753
restore settings
restore settings
Description
Restores the appliance settings from a backup file. The backup file can be located on a USB device or on a
TFTP server.
Syntax
Parameters
Parameter Description
file_name Name of the backup file.
serverIP IPv4 address of the TFTP server.
Example
Comments
The appliance automatically reboots after the settings are restored.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 754
show restore settings log
show restore settings log
Description
Shows the log file of previous restore settings to default operations. You can display these restore settings
log files:
n restore-settings-log- Log file for restoring saved settings.
n restore-default-settings-log - Log file for restoring the default settings.
Syntax
show {restore-settings-log|restore-default-settings-log}
Parameters
Parameter Description
n/a
Example
show restore-settings-log
Output
Success shows the restore settings log file. Failure shows an appropriate error message.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 755
show revert log
show revert log
Description
Shows the log file of previous revert operations.
Syntax
show revert-log
Parameters
Parameter Description
n/a
Example
show revert-log
Output
Success shows the revert log file. Failure shows an appropriate error message.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 756
revert to factory defaults
revert to factory defaults
Description
Revert the appliance to the original factory defaults. This command deletes all data and software images
from the appliance.
Syntax
revert to factory-defaults
Parameters
Parameter Description
n/a
Example
revert to factory-defaults
Output
Success shows a warning message. Enter yesto continue.
Failure shows an appropriate error message.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 757
revert to saved image
revert to saved image
Description
Reverts the appliance to the previous software image.
Syntax
revert to previous-image
Parameters
Parameter Description
n/a
Example
revert to previous-image
Output
Success shows OK. Failure shows an appropriate error message.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 758
report-settings
report-settings
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 759
set report-settings
set report-settings
Configure local reports settings.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 760
set report-settings
set report-settings
Description
Configure advanced local reports settings.
Syntax
<centrally-max-period>
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 761
set report-settings
set report-settings
Description
Configure advanced local reports settings.
Syntax
<locally-max-period>
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 762
show report-settings
show report-settings
Description
Shows report scheduling and creation configuration.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 763
show rule hits
show rule hits
Description
Shows the top firewall policy rule hits.
Syntax
Parameters
Parameter Description
rule Number of rules in the security policy that are displayed.
Minimum value i
1
.
Return Value
0
on success,
1
on failure
Example
Output
Success shows number of hits per rule. Failure shows an appropriate error message.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 764
show saved image
show saved image
Description
Shows information about the saved backup image.
Syntax
show saved-image
Parameters
Parameter Description
n/a
Example
show saved-image
Output
Success shows information about the image. Failure shows an appropriate error message.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 765
update security-blades
update security-blades
Description
Manually update Software Blades.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 766
update security-blades
updatable-object
add updatable-object
Description
Add an object to the list of updatable objects.
Syntax
Parameters
Parameter Description
name The name of the updatable object.
Type: String
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 767
delete updatable-object
delete updatable-object
Description
Delete an object from the list of updatable objects.
Syntax
Parameters
Parameter Description
name The name of the updatable object.
Type: String
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 768
show updatable-object
show updatable-object
Show the list of updatable objects.
show updatable-object
Description
Show details of the updatable object by UI.
Syntax
Parameters
Parameter Description
uid The code name of the updatable object, as used in the Management Server.
Type: A string of alphanumeric characters without space between them.
Example
Output
uid: CP_GEO_IL
name: Israel
parent-uid: CP_GEO_ASIA
is-imported: true
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 769
show updatable-object
show updatable-object
Description
Show details of the updatable object by name.
Syntax
Parameters
Parameter Description
name The name of the updatable object.
Type: String.
Example
Output
uid: CP_GEO_IL
name: Israel
parent-uid: CP_GEO_ASIA
is-imported: true
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 770
show updatable-objects
show updatable-objects
Description
Shows the list of all available updatable objects.
Syntax
show updatable-objects
Parameters
Parameter Description
n/a
Example
show updatable-objects
Output
name: Africa
uuid: d00802e8-0570-4851-8900-0a7c2ca80a9a
is-imported: false
uid: CP_GEO_AFRICA
parent-uid:
name: Burkina Faso
uuid: 91dac46d-1d35-4f8c-b4a4-ac588325c9b7
is-imported: false
uid: CP_GEO_BF
parent-uid: CP_GEO_AFRICA
name: Burundi
uuid: e80e48ad-022b-4fec-88df-91164346513e
is-imported: false
uid: CP_GEO_BI
parent-uid: CP_GEO_AFRICA
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 771
show updatable-objects-imported
show updatable-objects-imported
Description
Shows a list of all the imported updatable objects.
Syntax
show updateable-objects-imported
Parameters
Parameter Description
n/a
Example
show updatable-objects-imported
Output
name: Benin
uuid: 96d9b816-3216-45c8-9446-c73380244bbd
is-imported: true
uid: CP_GEO_BJ
parent-uid: CP_GEO_AFRICA
name: Chad
uuid: 11be095e-9343-47dc-aaed-2e2cb4ad2862
is-imported: true
uid: CP_GEO_TD
parent-uid: CP_GEO_AFRICA
name: Japan
uuid: 3f615c4d-3d99-4b08-b4e1-cf6b3b2e73e1
is-imported: true
uid: CP_GEO_JP
parent-uid: CP_GEO_ASIA
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 772
security-management
security-management
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 773
connect security-management
connect security-management
Description
Configure first connection to the Security Management Server.
Syntax
Parameters
Parameter Description
addr The logs are sent to this address
Type: An IP address or host name
local- Indicates if the management address used in the next manual fetch command will be
override- saved and continuously used instead of the address downloaded in the policy
mgmt-addr Type: Boolean (true/false)
mgmt-addr The IP address or hostname of the Security Management Server
Type: An IP address or host name
send-logs-to Indicates from where the address of the log server is taken
Type: Press TAB to see available options
use-one- Indicates whether to connect to the Security Management Server using a one time
time- password
password Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 774
set security-management
set security-management
Configures settings to connect to a remote Security Management Server and log server.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 775
set security-management
set security-management
Description
Configures a local override to the IP addresses of the Security Management Server and log server. This is
relevant when centrally managed.
Syntax
Parameters
Parameter Description
addr The logs are sent to this address
Type: An IP address or host name
local- Indicates if the management address used in the next manual fetch command will be
override- saved and continuously used instead of the address downloaded in the policy
mgmt- addr Type: Boolean (true/false)
mgmt- IP address or hostname of the Security Management Server
address Type: An IP address or host name
send-logs-to Indicates from where the address of the log server is taken
Type: Press TAB to see available options
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 776
set security-management
set security-management
Description
Configures if the device is managed centrally or locally. In centrally managed appliances only the
networking configurations are available and the security policy comes from the remote Security
Management Server.
Syntax
Parameters
Parameter Description
mode Indicates whether the appliance is managed locally or centrally using a Check Point
Security Management Server.
Options: locally-managed, centrally-managed
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 777
show security-management
show security-management
Description
Shows settings of the Security Management Server.
Syntax
show security-management
Parameters
Parameter Description
n/a
Example
show security-management
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 778
serial-port
serial-port
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 779
set serial-port
set serial-port
Configures the physical serial port settings.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 780
set serial-port
set serial-port
Description
Configures the physical serial port data flow settings.
Syntax
Parameters
Parameter Description
disabled Indicates if the serial port is disabled
flow-control Indicates the method of data flow control to and from the serial port
mode Indicates if the serial port is used to connect to the appliance's console, a remote telnet
server or allow a remote telnet connection to the device connected to the serial port.
port-speed Indicates the port speed (Baud Rate) of the serial connection
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 781
set serial-port
set serial-port
Description
Configures the physical serial port as a relay to which incoming TELNET traffic on a configured port will be
redirected.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 782
set serial-port
set serial-port
Description
Configures the physical serial port as a relay to outgoing connection to a remote TELNET server.
Syntax
<primary-server-address> ] [ secondary-server-address <secondary-server-address>
]
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 783
set serial-port-nine-pin
set serial-port-nine-pin
Description
Configure the settings for the 9 PIN serial port.
Syntax
Parameters
Parameter Description
disabled Indicates if the 9-PIN serial port is disabled
flow-control Indicates the method of data flow control to and from the 9 PIN serial port
mode Indicates if the 9 PIN serial port can be used by a remote telnet server or allow a remote
telnet connection to the device connected to the serial port.
port-speed Indicates the 9 PIN port speed (Baud Rate) of the serial connection
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 784
set serial-port-nine-pin
set serial-port-nine-pin
Description
Configure the settings for the 9 PIN serial port.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 785
set serial-port-nine-pin
set serial-port-nine-pin
Description
Configure the settings for the 9 PIN serial port.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 786
show serial-port
show serial-port
Description
Shows configuration for the serial port.
Syntax
show serial-port
Parameters
Parameter Description
n/a
Example
show serial-port
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 787
show serial-port-nine-pin
show serial-port-nine-pin
Description
Show the settings for the 9 PIN serial port.
Syntax
show serial-port-nine-pin
Parameters
Parameter Description
n/a
Example
show serial-port-nine-pin
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 788
server
server
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 789
add server
add server
Description
Adds a new server object. Server object are a way to define a network host object with its access and NAT
configuration, instead of creating manual rules for it.
Syntax
Parameters
Parameter Description
comments Comments
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
dhcp-exclude- Indicates if the internal DHCP service will not distribute the configured IP address of
ip-addr this server/network object to anyone
Type: Press TAB to see available options
dhcp-reserve-ip- Indicates if the internal DHCP service will distribute the configured IP address only to
addr-to-mac this server/network object according to its MAC address
Type: Press TAB to see available options
dns-resolving Indicates if the name of the server/network object will be used as a hostname for
internal DNS service
Type: Boolean (true/false)
ipv4-address The beginning of the IP range
mac-addr MAC address of the server
Type: MAC address
name Server object name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _
- .) characters without spaces
tcp-ports TCP ports for server of type 'other'
Type: Port range
tcpProtocol tcpProtocol
Type: Boolean (true/false)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 790
add server
Parameter Description
udp-ports UDP ports for server of type 'other'
Type: Port range
udpProtocol udpProtocol
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 791
delete server
delete server
Description
Deletes an existing server object.
Syntax
Parameters
Parameter Description
name Server object name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 792
show server
show server
Description
Shows configuration of an existing server object.
Syntax
Parameters
Parameter Description
name Server object name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 793
show servers
show servers
Description
Shows the configuration of all server objects.
Syntax
show servers
Parameters
Parameter Description
n/a
Example
show servers
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 794
service-details
service-details
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 795
set device-details
set device-details
~~
Description
Configures the device's details.
Syntax
Parameters
Parameter Description
country The country where you are located. The country configured for the WLAN
Options: country
hostname The appliance name used to identify the gateway.
Type: A string that contains [A-Z], [0-9] and '-' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 796
show device-details
show device-details
Description
Shows configuration of basic device details.
Syntax
show device-details
Parameters
Parameter Description
n/a
Example
show device-details
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 797
service-group
service-group
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 798
add service-group
add service-group
Description
Adds a new group for service objects.
Syntax
Parameters
Parameter Description
comments Comments and explanation about the Service Group
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
member An association field for the contained services
name Service Group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 799
delete service-group
delete service-group
Description
Deletes an existing group object for service objects by object name.
Syntax
Parameters
Parameter Description
name Service Group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 800
set service-group
set service-group
Configures an existing service objects group.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 801
set service-group
set service-group
Description
Configures an existing service objects group.
Syntax
Parameters
Parameter Description
comments Comments and explanation about the Service Group
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
name Service Group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
new-name Service Group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 802
set service-group
set service-group
Description
Removes all service objects from an existing service objects group.
Syntax
Parameters
Parameter Description
name Service Group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 803
set service-group
set service-group
Description
Adds an existing service object to an existing service objects group.
Syntax
Parameters
Parameter Description
member Service name
name Service Group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 804
set service-group
set service-group
Description
Removes an existing service object from an existing service objects group.
Syntax
Parameters
Parameter Description
member Service name
name Service Group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 805
show service-group
show service-group
Description
Shows the content of a service object group.
Syntax
Parameters
Parameter Description
name Service Group name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ - .)
characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 806
show service-groups
show service-groups
Description
Shows the content of all service object groups.
Syntax
show service-groups
Parameters
Parameter Description
n/a
Example
show service-groups
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 807
service-icmp
service-icmp
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 808
add service-icmp
add service-icmp
Description
Adds a new ICMP-type service object.
Syntax
Parameters
Parameter Description
comments Comments and explanation about the service
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
icmp-code ICMP code
Type: A number with no fractional part (integer)
icmp-type ICMP message type
Type: A number with no fractional part (integer)
name Service name
Type: String
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 809
delete service-icmp
delete service-icmp
Description
Deletes an existing ICMP-type service object by name.
Syntax
Parameters
Parameter Description
name Service name
Type: String
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 810
set service-icmp
set service-icmp
Description
Configures an existing ICMP-type service object.
Syntax
Parameters
Parameter Description
comments Comments and explanation about the service
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
icmp-code ICMP code
Type: A number with no fractional part (integer)
icmp-type ICMP message type
Type: A number with no fractional part (integer)
name Service name
Type: String
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 811
show service-icmp
show service-icmp
Description
Shows the configuration of a specific ICMP-type service object.
Syntax
Parameters
Parameter Description
name Service name
Type: String
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 812
add service-protocol
add service-protocol
Description
Adds a new non-TCP/UDP service object (a different IP protocol than 6 or 17).
Syntax
Parameters
Parameter Description
comments Comments and explanation about the service
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
ip-protocol IP Protocol number
Type: A number with no fractional part (integer)
name Service name
Type: String
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 813
service-protocol
service-protocol
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 814
delete service-protocol
delete service-protocol
Description
Deletes a non-TCP/UDP service object by name.
Syntax
Parameters
Parameter Description
name Service name
Type: String
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 815
set service-protocol
set service-protocol
Description
Configures an existing non-TCP/UDP service object.
Syntax
<accept-replies> ] [ sync-connections-on-cluster <sync-connections-on-cluster>
] [ match <match> ] [ aggressive-aging-enable <aggressive-aging-enable> ] [
aggressive-aging-timeout <aggressive-aging-timeout> ]
Parameters
Parameter Description
accept-replies Specifies if service replies are to be accepted
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging- enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
comments Comments and explanation about the service
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
ip-protocol IP Protocol number
Type: A number with no fractional part (integer)
match INSPECT expression that searches for a pattern in a packet, only relevant for services
of type 'other'
name Service name
Type: String
session- Time (in seconds) before the session times out
timeout
sync- Enables state-synchronized High Availability or Load Sharingon a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on- cluster synchronize connections on cluster will be synchronized as they pass through the
cluster
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 816
set service-protocol
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 817
show service-protocol
show service-protocol
Description
Shows the configuration of a specific non-TCP/UDP service object.
Syntax
Parameters
Parameter Description
name Service name
Type: String
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 818
show services-protocol
show services-protocol
Description
Shows the configuration of all non-TCP/UDP service objects.
Syntax
show services-protocol
Parameters
Parameter Description
n/a
Example
show services-protocol
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 819
set server server-access
set server server-access
Description
Configures an existing server object. A server object is a network object with predefined access and NAT
configurations.
Syntax
Parameters
Parameter Description
access-zones Zones the server is accessible from by default (accept all by default, accept only from
configured zones, or define no server-specific default access policy). Manual policy
rules will override this policy.
Type: Press TAB to see available options
allow-ping-to- Indicates if default access policy will work on ICMP traffic as well as defined ports.
server This option will not work on multiple ports hidden behind the gateway.
Type: Boolean (true/false)
log-accepted- Indicates if connections that are accepted by the default access policy to the server
connections are logged
Options: none, log
log-blocked- Indicates if connections that are blocked by the default access policy to the server are
connections logged
Options: none, log
name Server object name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ -
.) characters without spaces
trusted-zone- Indicates if traffic from the DMZ network to the server is allowed or blocked by default
dmz Options: blocked, allowed
trusted-zone- Indicates if traffic from Physical internal networks (LAN ports) to the server is allowed
lan or blocked by default
Options: blocked, allowed
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 820
set server server-access
Parameter Description
trusted-zone- Indicates if traffic from trusted wireless networks to the server is allowed or blocked by
trusted- default
wireless- Options: blocked, allowed
networks
trusted-zone- Indicates if encrypted traffic from remote VPN sites to the server is allowed or blocked
vpn-sites by default
Options: blocked, allowed
trusted-zone- Indicates if encrypted traffic from VPN remote access users to the server is allowed or
vpn- users blocked by default
Options: blocked, allowed
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 821
set server server-nat-settings
set server server-nat-settings
Description
Configures NAT settings on an existing server object.
Syntax
Parameters
Parameter Description
force-source-hide- Allow access from internal networks to the external IP address of the server via
nat local switch
Type: Boolean (true/false)
name Server object name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-
z, _ - .) characters without spaces
nat-settings Indicates the general NAT settings configured (no NAT, hide behind the
gateway's external IP address or use a different external IP address)
Type: Press TAB to see available options
port-address- For servers with a single port, indicates if the external port is not the same as the
translation internal port.
Type: Boolean (true/false)
port-address- For servers with a single port, indicates the external port that is used to forward
translation-external- traffic to the server
port Type: Port number
static-nat-for- indicates if outgoing traffic from the server using static NAT will be hidden behind
outgoing-traffic the configured external IP address without a port change
Type: Boolean (true/false)
static-nat-ipv4- For servers using static NAT, the external IP address used to forward traffic to
address the server
Type: IP address
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 822
set server server-nat-settings
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 823
set server server-network-settings
set server server-network-settings
Description
Configures network settings on an existing server object.
Syntax
Parameters
Parameter Description
comments Comments
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
dhcp-exclude- Indicates if the internal DHCP service will not distribute the configured IP address of
ip-addr this server/network object to anyone
Type: Press TAB to see available options
dhcp-reserve-ip- Indicates if the internal DHCP service will distribute the configured IP address only to
addr- to-mac this server/network object according to its MAC address
Type: Press TAB to see available options
dns-resolving Indicates if the name of the server/network object will be used as a hostname for
internal DNS service
Type: Boolean (true/false)
ipv4-address The beginning of the IP range
mac-addr MAC address of the server
Type: MAC address
name Server object name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _
- .) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 824
set server server-ports
set server server-ports
Description
Configures an existing server object.
Syntax
Parameters
Parameter Description
citrix-server Indicates a Citrix server (for each type we provide default but configurable ports)
custom-server Server type custom
dns-server Indicates a DNS server (for each type we provide default but configurable ports
ftp-server Indicates a FTP server (for each type we provide default but configurable ports)
mail-server Indicates a mail server (for each type we provide default but configurable ports)
name Server object name
Type: A string that begins with a letter and contain up to 32 alphanumeric (0-9, a-z, _ -
.) characters without spaces
pptp-server Indicates a PPTP server (for each type we provide default but configurable ports)
service-citrix Indicates if ports are defined for Citrix (for a Citrix server)
service-citrix- Configured ports for Citrix (for a Citrix server)
ports
service-dns Indicates if ports are defined for DNS (for a DNS server)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 825
set server server-ports
Parameter Description
service-dns- Configured ports for DNS (for a DNS server)
ports
service-ftp Indicates if ports are defined for FTP (for a FTP server)
service-ftp- Configured ports for FTP (for a FTP server)
ports
service-http Indicates if ports are defined for HTTP (for a web server)
service-http- Configured ports for HTTP (for a web server)
ports
service-https Indicates if ports are defined for HTTPS (for a web server)
service-https- Configured ports for HTTPS (for a web server)
ports
service-imap Indicates if ports are defined for IMAP (for a mail server)
service-imap- Configured ports for IMAP (for a web server)
ports
service-pop3 Indicates if ports are defined for POP3 (for a mail server)
service-pop3- Configured ports for POP3 (for a web server)
ports
service-pptp- Configured ports for PPTP (for a PPTP server)
ports
service-pptp- Indicates if ports are defined for PPTP (for a PPTP server)
selected
service-smtp Indicates if ports are defined for SMTP (for a mail server)
service-smtp- Configured ports for SMTP (for a web server)
ports
tcp-ports TCP ports for server of type 'other'
Type: Port range
tcpProtocol tcpProtocol
Type: Boolean (true/false)
udp-ports UDP ports for server of type 'other'
Type: Port range
udpProtocol udpProtocol
Type: Boolean (true/false)
web-server Indicates a web server (for each type we provide default but configurable ports)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 826
set server server-ports
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 827
service-system-default
service-system-default
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 828
set service-system-default Any_TCP
set service-system-default Any_TCP
Description
Configures settings of the built-in Any_TCP service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging- enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session- Time (in seconds) before the session times out
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule BaseRule Base, only
on- cluster those with synchronize connections on cluster will be synchronized as they pass
through the cluster.
sync-delay- True to delay connections synchronization.
enable
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 829
set service-system-default Any_TCP
Parameter Description
use-source- Use source port
port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 830
show service-system-default Any_TCP
show service-system-default Any_TCP
Description
Shows the settings of the built-in Any_TCP service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 831
set service-system-default Any_UDP
set service-system-default Any_UDP
Description
Configures settings of the built-in Any_UDP service object.
Syntax
Parameters
Parameter Description
accept-replies Specifies if service replies are to be accepted
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging- enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session- Time (in seconds) before the session times out
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on- cluster synchronize connections on cluster will be synchronized as they pass through the
cluster.
use-source- Use source port.
port
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 832
set service-system-default Any_UDP
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 833
show service-system-default Any_UDP
show service-system-default Any_UDP
Description
Shows the settings of the built-in Any_UDP service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 834
set service-system-default CIFS
set service-system-default CIFS
Description
Configures settings of the built-in CIFS service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
disable- Disable deep inspection of traffic matching this service
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session- Time (in seconds) before the session times out
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 835
set service-system-default CIFS
Parameter Description
sync-delay- True to delay connections synchronization.
enable
use-source- Use source port.
port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 836
show service-system-default CIFS
show service-system-default CIFS
Description
Shows the settings of the built-in CIFS service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 837
set service-system-default Citrix
set service-system-default Citrix
Description
Configures settings of the built-in Citrix service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
disable- Disable deep inspection of traffic matching this service
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session- Time (in seconds) before the session times out
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 838
set service-system-default Citrix
Parameter Description
sync-delay- True to delay connections synchronization.
enable
use-source- Use source port.
port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 839
show service-system-default Citrix
show service-system-default Citrix
Description
Shows the settings of the built-in Citrix service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 840
set service-system-default Citrix firewall-settings
set service-system-default Citrix firewall-
settings
Description
Configures firewall inspection settings of the built-in Citrix service object.
Syntax
Parameters
Parameter Description
protocol- Which protocol to support on the configured ports. The default port 1494 is commonly
support used by two different protocols - Winframe or Citrix ICA
Options: PROTO_TYPE.WIN_FRAME, PROTO_TYPE.CITRIX_ICA
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 841
show service-system-default Citrix firewall-settings
show service-system-default Citrix firewall-
settings
Description
Shows the inspection settings of the built-in Citrix service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 842
set service-system-default DHCP
set service-system-default DHCP
Description
Configures settings of the built-in DHCP service object.
Syntax
Parameters
Parameter Description
accept-replies Specifies if service replies are to be accepted
disable-inspection Disable deep inspection of traffic matching this service
Type: Boolean (true/false)
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session-timeout Time (in seconds) before the session times out
source-port Source port
use-source-port Use source port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 843
show service-system-default DHCP
show service-system-default DHCP
Description
Shows the settings of the built-in DHCP service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 844
set service-system-default DNS_TCP
set service-system-default DNS_TCP
Description
Configures settings of the built-in DNS_TCP service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
disable- Disable deep inspection of traffic matching this service
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session- Time (in seconds) before the session times out
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 845
set service-system-default DNS_TCP
Parameter Description
sync-delay- True to delay connections synchronization.
enable
use-source- Use source port.
port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 846
show service-system-default DNS_TCP
show service-system-default DNS_TCP
Description
Shows the settings of the built-in DNS_TCP service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 847
set service-system-default DNS_UDP
set service-system-default DNS_UDP
Description
Configures settings of the built-in DNS_UDP service object.
Syntax
Parameters
Parameter Description
accept-replies Specifies if service replies are to be accepted.
disable-inspection Disable deep inspection of traffic matching this service.
Type: Boolean (true/false)
port Destination ports (a comma separated list of ports/ranges).
Type: Port range
session-timeout Time (in seconds) before the session times out.
source-port Source port.
use-source-port Use source port.
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 848
show service-system-default DNS_UDP
show service-system-default DNS_UDP
Description
Shows the settings of the built-in DNS_UDP service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 849
set service-system-default FTP
set service-system-default FTP
Description
Configures settings of the built-in FTP service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability.
aggressive- Time (in seconds) before the aggressive aging times out.
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections.
interval
disable- Disable deep inspection of traffic matching this service.
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy.
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges).
Type: Port range
session- Time (in seconds) before the session times out.
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 850
set service-system-default FTP
Parameter Description
sync-delay- True to delay connections synchronization.
enable
use-source- Use source port.
port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 851
show service-system-default FTP
show service-system-default FTP
Description
Shows the settings of the built-in FTP service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 852
set service-system-default FTP firewall-settings
set service-system-default FTP firewall-settings
Description
Configures firewall inspection settings of the built-in FTP service object.
Syntax
Parameters
Parameter Description
mode FTP connection mode (allowed values are 'Any', 'Active' or 'Passive').
Options: any, active, passive
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 853
show service-system-default FTP firewall-settings
show service-system-default FTP firewall-
settings
Description
Shows the inspection settings of the built-in FTP service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 854
set service-system-default GRE
set service-system-default GRE
Description
Configures settings of the built-in GRE service object.
Syntax
Parameters
Parameter Description
accept-replies Specifies if service replies are to be accepted.
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability.
aggressive- Time (in seconds) before the aggressive aging times out.
aging-timeout
disable- Disable deep inspection of traffic matching this service.
inspection Type: Boolean (true/false)
ip-protocol IP Protocol number.
Type: A number with no fractional part (integer)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy.
open-after-
policy-
installation
match INSPECT expression that searches for a pattern in a packet, only relevant for services
of type 'other'.
session- Time (in seconds) before the session times out
timeout
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 855
set service-system-default GRE
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 856
show service-system-default GRE
show service-system-default GRE
Description
Shows the settings of the built-in GRE service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 857
set service-system-default H323
set service-system-default H323
Description
Configures settings of the built-in H323 service object.
Syntax
Parameters
Parameter Description
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections.
interval
disable- Disable deep inspection of traffic matching this service.
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy.
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges).
Type: Port range
session- Time (in seconds) before the session times out.
timeout
source-port Source port.
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster.
sync-delay- True to delay connections synchronization.
enable
use-source- Use source port.
port
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 858
set service-system-default H323
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 859
show service-system-default H323
show service-system-default H323
Description
Shows the settings of the built-in H323 service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 860
set service-system-default H323_RAS
set service-system-default H323_RAS
Description
Configures settings of the built-in H323_RAS service object.
Syntax
Parameters
Parameter Description
accept-replies Specifies if service replies are to be accepted.
disable-inspection Disable deep inspection of traffic matching this service.
Type: Boolean (true/false)
port Destination ports (a comma separated list of ports/ranges).
Type: Port range
session-timeout Time (in seconds) before the session times out.
source-port Source port.
use-source-port Use source port.
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 861
show service-system-default H323_RAS
show service-system-default H323_RAS
Description
Shows the settings of the built-in H323_RAS service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 862
set service-system-default HTTP
set service-system-default HTTP
Description
Configures settings of the built-in HTTP service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability.
aggressive- Time (in seconds) before the aggressive aging times out.
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections.
interval
disable- Disable deep inspection of traffic matching this service.
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy.
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges).
Type: Port range
session- Time (in seconds) before the session times out.
timeout
source-port Source port.
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 863
set service-system-default HTTP
Parameter Description
sync-delay- True to delay connections synchronization.
enable
use-source- Use source port.
port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 864
show service-system-default HTTP
show service-system-default HTTP
Description
Shows the settings of the built-in HTTP service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 865
set service-system-default HTTPS
set service-system-default HTTPS
Description
Configures settings of the built-in HTTPS service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability.
aggressive- Time (in seconds) before the aggressive aging times out.
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections.
interval
disable- Disable deep inspection of traffic matching this service.
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy.
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges).
Type: Port range
session- Time (in seconds) before the session times out.
timeout
source-port Source port.
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 866
set service-system-default HTTPS
Parameter Description
sync-delay- True to delay connections synchronization.
enable
use-source- Use source port.
port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 867
show service-system-default HTTPS
show service-system-default HTTPS
Description
Shows the settings of the built-in HTTPS service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 868
set service-system-default HTTP ips-settings
set service-system-default HTTP ips-settings
Description
Configures IPS settings of the built-in HTTP service object.
Syntax
Parameters
Parameter Description
duplicate- True to block duplicate Content-Length' header with same value.
content-length Type: Boolean (true/false)
duplicate-host True to block duplicate 'Host' header with same value.
Type: Boolean (true/false)
empty-value True to block HTTP header with empty value.
Type: Boolean (true/false)
invalid-chunk True if invalid chunk.
Type: Boolean (true/false)
no-colon True to block HTTP header with no colon.
Type: Boolean (true/false)
non-standard- Select action for connection over non standard ports (allowed values are 'Accept' and
ports-action 'Block').
Options: block, accept
non-standard- Select track option for connection over non standard ports (allowed values are 'log',
ports-track 'alert' and 'don't log') .
Options: none, log, alert
parser-failure- Select action for when the parser fails (allowed values are 'Accept' and 'Block').
action Options: block, accept
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 869
set service-system-default HTTP ips-settings
Parameter Description
parser-failure- Select track option for when the parser fails (allowed values are 'log', 'alert' and 'don't
track log').
Options: none, log, alert
post True to block requests with 'POST' method and without 'Content-Type' header.
Type: Boolean (true/false)
recursive-url True to block HTTP requests with recursive URL encoding.
Type: Boolean (true/false)
responses True to block responses with both 'Content-Length' and 'Transfer-Encoding'headers.
Type: Boolean (true/false)
split-url True to split the URL between the query and fragment sections instructs the HTTP
protections to inspect the query and fragment sections separately.
Type: Boolean (true/false)
strict-request True to enforce strict HTTP request parsing.
Type: Boolean (true/false)
strict-response True to enforce strict HTTP response parsing.
Type: Boolean (true/false)
tab-as- True to block HTTP traffic with 'tab' character as a separator.
seperator Type: Boolean (true/false)
trailing- True to block request header names with trailing whitespaces.
whitespaces Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 870
show service-system-default HTTP ips-settings
show service-system-default HTTP ips-settings
Description
Shows the inspection settings of the built-in HTTP service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 871
set service-system-default HTTPS url-filtering-settings
set service-system-default HTTPS url-filtering-
settings
Description
Configures URL filtering over HTTPS. Enables categorization over HTTPS even without full SSL inspection.
Syntax
Parameters
Parameter Description
categorize-https-sites Categorize HTTPS sites by their certificate CN.
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 872
show service-system-default HTTPS url-filtering-settings
show service-system-default HTTPS url-
filtering-settings
Description
Shows the configuration of URL filtering categorization option over HTTPS.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 873
set service-system-default IIOP
set service-system-default IIOP
Description
Configures settings of the built-in IIOP service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability.
aggressive- Time (in seconds) before the aggressive aging times out.
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections.
interval
disable- Disable deep inspection of traffic matching this service.
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy.
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges).
Type: Port range
session- Time (in seconds) before the session times out.
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 874
set service-system-default IIOP
Parameter Description
sync-delay- True to delay connections synchronization.
enable
use-source- Use source port.
port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 875
show service-system-default IIOP
show service-system-default IIOP
Description
Shows the settings of the built-in IIOP service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 876
set service-system-default IMAP
set service-system-default IMAP
Description
Configures settings of the built-in IMAP service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability.
aggressive- Time (in seconds) before the aggressive aging times out.
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections.
interval
disable- Disable deep inspection of traffic matching this service.
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy.
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges).
Type: Port range
session- Time (in seconds) before the session times out
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 877
set service-system-default IMAP
Parameter Description
sync-delay- True to delay connections synchronization
enable
use-source- Use source port
port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 878
show service-system-default IMAP
show service-system-default IMAP
Description
Shows the settings of the built-in IMAP service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 879
set service-system-default LDAP
set service-system-default LDAP
Description
Configures settings of the built-in LDAP service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
disable- Disable deep inspection of traffic matching this service
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session- Time (in seconds) before the session times out
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 880
set service-system-default LDAP
Parameter Description
sync-delay- True to delay connections synchronization
enable
use-source- Use source port
port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 881
show service-system-default LDAP
show service-system-default LDAP
Description
Shows the settings of the built-in LDAP service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 882
set service-system-default MGCP
set service-system-default MGCP
Description
Configures settings of the built-in MGCP service object.
Syntax
Parameters
Parameter Description
accept-replies Specifies if service replies are to be accepted
disable-inspection Disable deep inspection of traffic matching this service
Type: Boolean (true/false)
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session-timeout Time (in seconds) before the session times out
source-port Source port
use-source-port Use source port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 883
show service-system-default MGCP
show service-system-default MGCP
Description
Shows the settings of the built-in MGCP service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 884
set service-system-default NetBIOSDatagram
set service-system-default NetBIOSDatagram
Description
Configures settings of the built-in NetBiosDatagram service object.
Syntax
Parameters
Parameter Description
accept-replies Specifies if service replies are to be accepted
disable-inspection Disable deep inspection of traffic matching this service
Type: Boolean (true/false)
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session-timeout Time (in seconds) before the session times out
source-port Source port
use-source-port Use source port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 885
show service-system-default NetBIOSDatagram
show service-system-default NetBIOSDatagram
Description
Shows the settings of the built-in NetBiosDatagram service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 886
set service-system-default NetBIOSName
set service-system-default NetBIOSName
Description
Configures settings of the built-in NetBiosName service object.
Syntax
Parameters
Parameter Description
accept-replies Specifies if service replies are to be accepted
disable-inspection Disable deep inspection of traffic matching this service
Type: Boolean (true/false)
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session-timeout Time (in seconds) before the session times out
source-port Source port
use-source-port Use source port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 887
show service-system-default NetBIOSName
show service-system-default NetBIOSName
Description
Shows the settings of the built-in NetBiosName service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 888
set service-system-default NetShow
set service-system-default NetShow
Description
Configures settings of the built-in NetShow service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
disable- Disable deep inspection of traffic matching this service
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session- Time (in seconds) before the session times out
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 889
set service-system-default NetShow
Parameter Description
sync-delay- True to delay connections synchronization
enable
use-source- Use source port
port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 890
show service-system-default NetShow
show service-system-default NetShow
Description
Shows the settings of the built-in NetShow service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 891
set service-system-default NNTP
set service-system-default NNTP
Description
Configures settings of the built-in NNTP service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
disable- Disable deep inspection of traffic matching this service
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session- Time (in seconds) before the session times out
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 892
set service-system-default NNTP
Parameter Description
sync-delay- True to delay connections synchronization
enable
use-source- Use source port
port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 893
show service-system-default NNTP
show service-system-default NNTP
Description
Shows the settings of the built-in NNTP service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 894
set service-system-default POP3
set service-system-default POP3
Description
Configures settings of the built-in POP3 service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
disable- Disable deep inspection of traffic matching this service
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session- Time (in seconds) before the session times out
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 895
set service-system-default POP3
Parameter Description
sync-delay- True to delay connections synchronization
enable
use-source- Use source port
port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 896
show service-system-default POP3
show service-system-default POP3
Description
Shows the settings of the built-in POP3 service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 897
set service-system-default PPTP_TCP
set service-system-default PPTP_TCP
Description
Configures settings of the built-in PPTP_TCP service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
disable- Disable deep inspection of traffic matching this service
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session- Time (in seconds) before the session times out
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 898
set service-system-default PPTP_TCP
Parameter Description
sync-delay- True to delay connections synchronization
enable
use-source- Use source port
port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 899
show service-system-default PPTP_TCP
show service-system-default PPTP_TCP
Description
Shows the settings of the built-in PPTP_TCP service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 900
set service-system-default PPTP_TCP ips-settings
set service-system-default PPTP_TCP ips-
settings
Description
Configures additional inspection settings of the built-in PPTP_TCP service object.
Syntax
Parameters
Parameter Description
action Select action for PPTP connections (allowed values are 'Accept' and 'Block')
Options: block, accept
strict True to enforce strict PPTP parsing
Type: Boolean (true/false)
track Select track option for PPTP connections (allowed values are 'log', 'alert' and 'don't log')
Options: none, log, alert
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 901
show service-system-default PPTP_TCP ips-settings
show service-system-default PPTP_TCP ips-
settings
Description
Shows the inspection settings of the built-in Any_TCP service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 902
set service-system-default RealAudio
set service-system-default RealAudio
Description
Configures settings of the built-in RealAudio service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
disable- Disable deep inspection of traffic matching this service
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session- Time (in seconds) before the session times out
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 903
set service-system-default RealAudio
Parameter Description
sync-delay- True to delay connections synchronization
enable
use-source- Use source port
port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 904
show service-system-default RealAudio
show service-system-default RealAudio
Description
Shows the settings of the built-in RealAudio service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 905
set service-system-default RSH
set service-system-default RSH
Description
Configures settings of the built-in RSH service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
disable- Disable deep inspection of traffic matching this service
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session- Time (in seconds) before the session times out
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 906
set service-system-default RSH
Parameter Description
sync-delay- True to delay connections synchronization
enable
use-source- Use source port
port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 907
show service-system-default RSH
show service-system-default RSH
Description
Shows the settings of the built-in RSH service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 908
set service-system-default RTSP
set service-system-default RTSP
Description
Configures settings of the built-in RTSP service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
disable- Disable deep inspection of traffic matching this service
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session- Time (in seconds) before the session times out
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 909
set service-system-default RTSP
Parameter Description
sync-delay- True to delay connections synchronization
enable
use-source- Use source port
port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 910
show service-system-default RTSP
show service-system-default RTSP
Description
Shows the settings of the built-in RTSP service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 911
set service-system-default SCCP
set service-system-default SCCP
Description
Configures settings of the built-in SCCP service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
disable- Disable deep inspection of traffic matching this service
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session- Time (in seconds) before the session times out
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 912
set service-system-default SCCP
Parameter Description
sync-delay- True to delay connections synchronization
enable
use-source- Use source port
port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 913
show service-system-default SCCP
show service-system-default SCCP
Description
Shows the settings of the built-in SCCP service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 914
set service-system-default SCCPS
set service-system-default SCCPS
Description
Configures settings of the built-in SCCPS service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
disable- Disable deep inspection of traffic matching this service
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session- Time (in seconds) before the session times out
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 915
set service-system-default SCCPS
Parameter Description
sync-delay- True to delay connections synchronization
enable
use-source- Use source port
port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 916
show service-system-default SCCPS
show service-system-default SCCPS
Description
Shows the settings of the built-in SCCPS service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 917
set service-system-default SIP_TCP
set service-system-default SIP_TCP
Description
Configures settings of the built-in SIP_TCP service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
disable- Disable deep inspection of traffic matching this service
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session- Time (in seconds) before the session times out
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 918
set service-system-default SIP_TCP
Parameter Description
sync-delay- True to delay connections synchronization
enable
use-source- Use source port
port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 919
show service-system-default SIP_TCP
show service-system-default SIP_TCP
Description
Shows the settings of the built-in SIP_TCP service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 920
set service-system-default SIP_UDP
set service-system-default SIP_UDP
Description
Configures settings of the built-in SIP_UDP service object.
Syntax
Parameters
Parameter Description
accept-replies Specifies if service replies are to be accepted
disable-inspection Disable deep inspection of traffic matching this service
Type: Boolean (true/false)
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session-timeout Time (in seconds) before the session times out
source-port Source port
use-source-port Use source port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 921
show service-system-default SIP_UDP
show service-system-default SIP_UDP
Description
Shows the settings of the built-in SIP_UDP service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 922
set service-system-default SMTP
set service-system-default SMTP
Description
Configures settings of the built-in SMTP service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
disable- Disable deep inspection of traffic matching this service
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session- Time (in seconds) before the session times out
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 923
set service-system-default SMTP
Parameter Description
sync-delay- True to delay connections synchronization
enable
use-source- Use source port
port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 924
show service-system-default SMTP
show service-system-default SMTP
Description
Shows the settings of the built-in SMTP service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 925
set service-system-default SNMP
set service-system-default SNMP
Description
Configures settings of the built-in SNMP service object.
Syntax
Parameters
Parameter Description
accept-replies Specifies if service replies are to be accepted
disable-inspection Disable deep inspection of traffic matching this service
Type: Boolean (true/false)
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session-timeout Time (in seconds) before the session times out
source-port Source port
use-source-port Use source port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 926
show service-system-default SNMP
show service-system-default SNMP
Description
Shows the settings of the built-in SNMP service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 927
set service-system-default SNMP firewall-settings
set service-system-default SNMP firewall-
settings
Description
Additional configuration for SNMP service
Syntax
Parameters
Parameter Description
read-only True to enforce read-only mode
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 928
show service-system-default SNMP firewall-settings
show service-system-default SNMP firewall-
settings
Description
Shows the inspection settings of the built-in SNMP service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 929
set service-system-default SQLNet
set service-system-default SQLNet
Description
Configures settings of the built-in SQLNet service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
disable- Disable deep inspection of traffic matching this service
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session- Time (in seconds) before the session times out
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 930
set service-system-default SQLNet
Parameter Description
sync-delay- True to delay connections synchronization
enable
use-source- Use source port
port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 931
show service-system-default SQLNet
show service-system-default SQLNet
Description
Shows the settings of the built-in SQLNet service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 932
set service-system-default SSH
set service-system-default SSH
Description
Configures settings of the built-in SSH service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
disable- Disable deep inspection of traffic matching this service
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session- Time (in seconds) before the session times out
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 933
set service-system-default SSH
Parameter Description
sync-delay- True to delay connections synchronization
enable
use-source- Use source port
port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 934
show service-system-default SSH
show service-system-default SSH
Description
Shows the settings of the built-in SSH service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 935
set service-system-default SSH ips-settings
set service-system-default SSH ips-settings
Description
Configures additional inspection settings of the built-in SSH service object.
Syntax
Parameters
Parameter Description
block-version True to enforce blocking of version 1.x
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 936
show service-system-default SSH ips-settings
show service-system-default SSH ips-settings
Description
Shows the inspection settings of the built-in SSH service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 937
set service-system-default TELNET
set service-system-default TELNET
Description
Configures settings of the built-in TELNET service object.
Syntax
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
disable- Disable deep inspection of traffic matching this service
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session- Time (in seconds) before the session times out
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 938
set service-system-default TELNET
Parameter Description
sync-delay- True to delay connections synchronization
enable
use-source- Use source port
port
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 939
show service-system-default TELNET
show service-system-default TELNET
Description
Shows the settings of the built-in TELNET service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 940
set service-system-default TFTP
set service-system-default TFTP
Description
Configures settings of the built-in TFTP service object.
Syntax
Parameters
Parameter Description
accept-replies Specifies if service replies are to be accepted
disable- Disable deep inspection of traffic matching this service
inspection Type: Boolean (true/false)
keep- True to keep connections open after policy has been installed, even if they are not
connections- allowed under the new policy
open-after-
policy-
installation
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session- Time (in seconds) before the session times out
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster
use-source- Use source port
port
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 941
set service-system-default TFTP
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 942
show service-system-default TFTP
show service-system-default TFTP
Description
Shows the settings of the built-in TFTP service object.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 943
service-tcp
service-tcp
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 944
add service-tcp
add service-tcp
Description
Adds a new TCP service object with configurable ports.
Syntax
Parameters
Parameter Description
comments Comments and explanation about the service
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
name Service name
Type: String
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 945
set service-tcp
set service-tcp
Description
Configures an existing TCP service object.
Syntax
<delay-sync-interval> ] [ aggressive-aging-enable <aggressive-aging-enable>
] [ aggressive-aging-timeout <aggressive-aging-timeout> ] [ use-source-port {
false | true source-port <source-port>} ]
Parameters
Parameter Description
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
comments Comments and explanation about the service
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
delay-sync- Time (in seconds) after connection initiation to start synchronizing connections
interval
name Service name
Type: String
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session- Time (in seconds) before the session times out
timeout
source-port Source port
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 946
set service-tcp
Parameter Description
sync-delay- True to delay connections synchronization
enable
use-source- Use source port
port
Example
set service-tcp TEXT name TEXT port 8080-8090 comments "This is a comment."
session-timeout 15 sync-connections-on-cluster true sync-delay-enable true
delay-sync-interval 15 aggressive-aging-enable true aggressive-aging-
timeout 15 use-source-port false source-port 8080
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 947
delete service-tcp
delete service-tcp
Description
Deletes a TCP service object by name.
Syntax
Parameters
Parameter Description
name Service name
Type: String
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 948
show service-tcp
show service-tcp
Description
Shows the configuration of a specific TCP service object.
Syntax
Parameters
Parameter Description
name Service name
Type: String
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 949
show services-tcp
show services-tcp
Description
Shows the configuration of all TCP service objects.
Syntax
show services-tcp
Parameters
Parameter Description
n/a
Example
show services-tcp
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 950
service-udp
service-udp
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 951
add service-udp
add service-udp
Description
Adds a new UDP service object with configurable ports.
Syntax
Parameters
Parameter Description
comments Comments and explanation about the service
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
name Service name
Type: String
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 952
delete service-udp
delete service-udp
Description
Deletes a UDP service object by name.
Syntax
Parameters
Parameter Description
name Service name
Type: String
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 953
set service-udp
set service-udp
Description
Configures an existing UDP service object
Syntax
Parameters
Parameter Description
accept-replies Specifies if service replies are to be accepted
aggressive- Enable to manage the connections table capacity and memory consumption of the
aging-enable firewall to increase durability and stability
aggressive- Time (in seconds) before the aggressive aging times out
aging-timeout
comments Comments and explanation about the service
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
name Service name
Type: String
port Destination ports (a comma separated list of ports/ranges)
Type: Port range
session- Time (in seconds) before the session times out
timeout
sync- Enables state-synchronized High Availability or Load Sharing on a ClusterXL or
connections- OPSEC-certified cluster. Of the services allowed by the Rule Base, only those with
on-cluster synchronize connections on cluster will be synchronized as they pass through the
cluster
Example
set service-udp TEXT name TEXT port 8080-8090 comments "This is a comment."
session-timeout 15 accept-replies true sync-connections-on-cluster true
aggressive-aging-enable true aggressive-aging-timeout 15
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 954
show service-udp
show service-udp
Description
Shows the configuration of a specific UDP service object
Syntax
Parameters
Parameter Description
name Service name
Type: String
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 955
show services-udp
show services-udp
Description
Shows the configuration of all UDP service objects.
Syntax
show services-udp
Parameters
Parameter Description
n/a
Example
show services-udp
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 956
show services-icmp
show services-icmp
Description
Shows the configuration of all ICMP-type service objects.
Syntax
show services-icmp
Parameters
Parameter Description
n/a
Example
show services-icmp
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 957
shell/expert
shell/expert
The shelland expertcommands switch between the shell and expert modes.
Description
Changes to expert mode.
Syntax
shell
expert
Parameters
Parameter Description
n/a
Example
shell
Comments
Use the cpshell command to start cpshell.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 958
set sic_init
set sic_init
Description
Sets the SIC password.
Syntax
Parameters
Parameter Description
pass One-time password, as specified by the Security Management Server administrator.
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 959
sim
sim
Description
SecureXL Implementation Module commands
Parameters
Parameter Description
ver get the version
if get the interface list
ranges print the range content
affinity get/set affinity options
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 960
snmp
snmp
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 961
add snmp
add snmp
Adds SNMP trap receiver and SNMP users to the SNMP configuration.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 962
add snmp
add snmp
Description
Adds a new SNMP trap receiver IP address to be used by the SNMP agent.
Syntax
Parameters
Parameter Description
community Community name of the receivers trap, public is default for version2 users
Type: A string of alphanumeric characters without space between them
traps-receiver Receivers IP address that the trap associated with
Type: IP address
user SNMP version3 Defined user
version SNMP Version, options are: v2 or v3
Type: Press TAB to see available options
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 963
add snmp
add snmp
Description
Adds a new user to be used by SNMPv3 protocol.
Syntax
Parameters
Parameter Description
auth-pass-phrase Authentication password for the SNMP version3 user
Type: A string that contains alphanumeric and special characters
auth-pass-type Authentication protocol type for the version3 user, options are: MD5 or SHA1
Options: MD5, SHA1
privacy-pass-phrase Privacy password chosen by the version3 user in case privacy is set
Type: A string that contains alphanumeric and special characters
privacy-pass-type Privacy protocol type for the version3 user, options are: AES or DES
Options: AES, DES
security-level Does Privacy protocol for this version3 user was set in the security level
Type: Boolean (true/false)
user version3 user name
Type: A string that contains (0-9, a-z, - . @) up to 64 characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 964
delete snmp
delete snmp
Deletes SNMP trap receivers and SNMP users.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 965
delete snmp
delete snmp
Description
Deletes an existing SNMP trap receiver by IP address.
Syntax
Parameters
Parameter Description
traps-receiver Receivers IP address that the trap associated with
Type: IP address
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 966
delete snmp
delete snmp
Description
Deletes a configured SNMP contact.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 967
delete snmp
delete snmp
Description
Deletes a configured SNMP location.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 968
set snmp
set snmp
Configures SNMP settings.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 969
set snmp
set snmp
escription
Configures SNMP agent settings.
Syntax
Parameters
Parameter Description
agent Is SNMP option enabled or disabled, disabled is the default
Type: Boolean (true/false)
agent-version Is the defined SNMP version is version3 only
Type: Boolean (true/false)
community Community name of the SNMP, public is the default
Type: A string of alphanumeric characters without space between them
contact System contact name, maximum length is 128
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
location System location name
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
Example
set snmp agent true agent-version true community word contact myContact
location myLocation
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 970
set snmp
set snmp
Description
Configures SNMP agent settings.
Syntax
Parameters
Parameter Description
agent Is SNMP option enabled or disabled, disabled is the default
Type: Boolean (true/false)
agent-version Is the defined SNMP version is version3 only
Type: Boolean (true/false)
community Community name of the SNMP, public is the default
Type: A string of alphanumeric characters without space between them
contact System contact name, maximum length is 128
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
location System location name
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
Example
set snmp agent-version true agent true community word contact myContact
location myLocation
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 971
set snmp
set snmp
Description
Configures SNMP community settings.
Syntax
Parameters
Parameter Description
agent Is SNMP option enabled or disabled, disabled is the default
Type: Boolean (true/false)
agent-version Is the defined SNMP version is version3 only
Type: Boolean (true/false)
community Community name of the SNMP, public is the default
Type: A string of alphanumeric characters without space between them
contact System contact name, maximum length is 128
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
location System location name
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
Example
set snmp community word agent true agent-version true contact myContact
location myLocation
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 972
set snmp
set snmp
Description
Configures SNMP contact settings.
Syntax
Parameters
Parameter Description
agent Is SNMP option enabled or disabled, disabled is the default
Type: Boolean (true/false)
agent-version Is the defined SNMP version is version3 only
Type: Boolean (true/false)
community Community name of the SNMP, public is the default
Type: A string of alphanumeric characters without space between them
contact System contact name, maximum length is 128
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
location System location name
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
Example
set snmp contact myContact agent true agent-version true community word
location myLocation
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 973
set snmp
set snmp
Description
Configures SNMP location settings.
Syntax
Parameters
Parameter Description
agent Is SNMP option enabled or disabled, disabled is the default
Type: Boolean (true/false)
agent-version Is the defined SNMP version is version3 only
Type: Boolean (true/false)
community Community name of the SNMP, public is the default
Type: A string of alphanumeric characters without space between them
contact System contact name, maximum length is 128
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
location System location name
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
Example
set snmp location myLocation agent true agent-version true community word
contact myContact
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 974
show snmp
show snmp
Shows SNMP configuration.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 975
show snmp
show snmp
Description
Shows SNMP agent configuration.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 976
show snmp
show snmp
Description
Shows SNMP agent version configuration.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 977
show snmp
show snmp
Description
Shows SNMP community configuration.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 978
show snmp
show snmp
Description
Shows SNMP contact configuration.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 979
show snmp
show snmp
Description
Shows SNMP location configuration.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 980
show snmp-general-all
show snmp-general-all
Description
Shows SNMP configuration.
Syntax
show snmp-general-all
Parameters
Parameter Description
n/a
Example
show snmp-general-all
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 981
snmp traps
snmp traps
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 982
set snmp traps
set snmp traps
Configures, enables or disables traps from the list, the enabled traps are sent to the trap receivers.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 983
set snmp traps
set snmp traps
Description
Enable/Disable SNMP traps functionality.
Syntax
Parameters
Parameter Description
snmpTrapsEnable snmpTrapsEnable
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 984
set snmp traps
set snmp traps
Description
Configures an existing SNMP trap.
Syntax
Parameters
Parameter Description
enable Enable or disable whether a trap is sent for the specific event
Type: Boolean (true/false)
repetitions Repetitions on trap sending times between 0 - 10, optional field
Type: A number with no fractional part (integer)
repetitions-delay Wait time (in seconds) between sending each trap, optional field
Type: A number with no fractional part (integer)
severity Trap hazardous level, optional field, severity of the trap between 1 - 4
Type: A number with no fractional part (integer)
threshold The mathematical value associated with the thresholds
Type: A number with no fractional part (integer)
trap-name Trap event name
Options: trap-name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 985
set snmp traps
set snmp traps
Description
Configures an existing SNMP trap receiver.
Syntax
Parameters
Parameter Description
community Community name of the receivers trap, public is default for version2 users
Type: A string of alphanumeric characters without space between them
receiver Receivers IP address that the trap associated with
Type: IP address
user SNMP version3 Defined user
version SNMP Version, options are: v2 or v3
Type: Press TAB to see available options
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 986
set snmp-traps
set snmp-traps
Description
Configure, enable or disable traps from the list, the enabled traps are sent to the trap receivers.
Syntax
Parameters
Parameter Description
snmpTrapsEnable snmpTrapsEnable
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 987
set snmp-traps
set snmp-traps
Description
Configure, enable or disable traps from the list, the enabled traps are sent to the trap receivers.
Syntax
Parameters
Parameter Description
enable Enable or disable whether a trap is sent for the specific event.
Type: Boolean (true/false)
repetitions Repetitions on trap sending times between 0 - 10, optional field.
Type: A number with no fractional part (integer).
repetitions-delay Wait time (in seconds) between sending each trap, optional field.
Type: A number with no fractional part (integer).
severity Trap hazardous level, optional field, severity of the trap between 1 - 4.
Type: A number with no fractional part (integer).
threshold The mathematical value associated with the thresholds.
Type: A number with no fractional part (integer).
trap-name Trap event name.
Options: trap-name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 988
set-snmp-traps
set-snmp-traps
Description
Configured destinations to receive traps sent by the SNMP agent. A trap is how the SNMP agent notifies the
administrator that something is wrong.
Syntax
Parameters
Parameter Description
community Community name of the receivers trap, public is default for version2 users.
Type: A string of alphanumeric characters without space between them.
receiver Receivers IP address that the trap is associated with.
Type: IP address
user SNMP version3 Defined user.
version SNMP Version, options are: v2 or v3.
Type: Press TAB to see available options
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 989
show snmp traps
show snmp traps
Description
Shows SNMP traps status.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 990
delete snmp traps-receivers
delete snmp traps-receivers
Description
Deletes all configured SNMP trap receivers.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 991
show snmp traps receivers
show snmp traps receivers
Description
Shows all SNMP trap receivers.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 992
show snmp traps enabled-traps
show snmp traps enabled-traps
Description
Shows all SNMP traps.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 993
snmp user
snmp user
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 994
delete snmp user
delete snmp user
Description
Deletes a configured SNMP user by name.
Syntax
Parameters
Parameter Description
user-name version3 user name
Type: A string that contains (0-9, a-z, - . @) up to 64 characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 995
set snmp user
set snmp user
Description
Configures an existing SNMP user.
Syntax
Parameters
Parameter Description
auth-pass-phrase Authentication password for the SNMP version3 user
Type: A string that contains alphanumeric and special characters
auth-pass-type Authentication protocol type for the version3 user, options are: MD5 or SHA1
Options: MD5, SHA1
privacy-pass-phrase Privacy password chosen by the version3 user in case privacy is set
Type: A string that contains alphanumeric and special characters
privacy-pass-type Privacy protocol type for the version3 user, options are: AES or DES
Options: AES, DES
security-level Does Privacy protocol for this version3 user was set in the security level
Type: Boolean (true/false)
user-name version3 user name
Type: A string that contains (0-9, a-z, - . @) up to 64 characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 996
show snmp user
show snmp user
Description
Shows the configuration of SNMP user.
Syntax
Parameters
Parameter Description
user-name version3 user name
Type: A string that contains (0-9, a-z, - . @) up to 64 characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 997
show snmp users
show snmp users
Description
Shows the configuration of all SNMP users.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 998
delete snmp users
delete snmp users
Description
Deletes all configured SNMP users.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 999
show software version
show software version
Description
Shows the version of the current software.
Syntax
Parameters
Parameter Description
n/a
Example
show software-version
Output
Success shows the software version of the appliance. Failure shows an appropriate error message.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1000
ssl-inspection advanced-settings
ssl-inspection advanced-settings
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1001
set ssl-inspection advanced-settings
set ssl-inspection advanced-settings
Description
Configure advanced settings for SSL Inspection.
Syntax
Parameters
Parameter Description
additional-https-ports Additional HTTPS ports for ssl inspection (a comma separated list
ofports/ranges)
Type: Port range
bypass-well-known- Bypass HTTPS Inspection of traffic to well known software update services
update-services Type: Boolean (true/false)
log-empty-ssl- Log connections that were terminated by the client before data was sent - might
connections indicate the client did not install CA certificate
Type: Boolean (true/false)
retrieve-intermediate- Indicates if the SSL inspection mechanism will perform it's validations on all
ca-certificate intermidate CA certificates in the certificate chain
Type: Boolean (true/false)
track-validation-errors Choose if the SSL Inspection validations are tracked
Options: none, log, alert
validate-cert- Indicates if the SSL inspection mechanism will drop connections that present an
expiration expired certificate
Type: Boolean (true/false)
validate-crl Indicates if the SSL inspection mechanism will drop connections that present a
revoked certificate
Type: Boolean (true/false)
validate-unreachable- Indicates if the SSL inspection mechanism will drop connections that present a
crl certificate with an unreachable CRL
Type: Boolean (true/false)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1002
set ssl-inspection advanced-settings
Parameter Description
validate-untrusted- Indicates if the SSL inspection mechanism will drop connections that present an
certificates untrusted server certificate
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1003
show ssl-inspection advanced-settings
show ssl-inspection advanced-settings
Description
Show advanced settings for SSL Inspection.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1004
ssl-inspection exception
ssl-inspection exception
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1005
add ssl-inspection exception
add ssl-inspection exception
Description
Add a new exception to bypass SSL Inspection policy for specific traffic.
Syntax
Parameters
Parameter Description
category-id Application or custom application name
category-name Application or custom application name
category-negate If true, the category is all traffic except what is defined in the category field
Type: Boolean (true/false)
comment Description of the rule
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : ()
@
destination Network object that is the target of the connection
destination- If true, the destination is all traffic except what is defined in the destination field
negate Type: Boolean (true/false)
disabled Indicates if the exception is disabled
Type: Boolean (true/false)
service The network service object that the exception should match to
service-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
source Network object or user group that initiates the connection
source-negate If true, the source is all traffic except what is defined in the source field
Type: Boolean (true/false)
track The action taken when there is a match on the rule
Options: none, log, alert
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1006
add ssl-inspection exception
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1007
delete ssl-inspection exception
delete ssl-inspection exception
Delete an existing SSL Inspection policy exception.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1008
delete ssl-inspection exception
delete ssl-inspection exception
Description
Delete an existing SSL Inspection policy exception.
Syntax
Parameters
Parameter Description
position The index of exception
Type: Decimal number
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1009
delete ssl-inspection exception
delete ssl-inspection exception
Description
Delete an existing SSL Inspection policy exception.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1010
set ssl-inspection exception
set ssl-inspection exception
Description
Configure an existing SSL Inspection policy exception.
Syntax
Parameters
Parameter Description
category-id Application or custom application name
category-name Application or custom application name
category-negate If true, the category is all traffic except what is defined in the category field
Type: Boolean (true/false)
comment Description of the rule
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : ()
@
destination Network object that is the target of the connection
destination- If true, the destination is all traffic except what is defined in the destination field
negate Type: Boolean (true/false)
disabled Indicates if the exception is disabled
Type: Boolean (true/false)
position The index of exception
Type: Decimal number
service The network service object that the exception should match to
service-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
source Network object or user group that initiates the connection
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1011
set ssl-inspection exception
Parameter Description
source-negate If true, the source is all traffic except what is defined in the source field
Type: Boolean (true/false)
track The action taken when there is a match on the rule
Options: none, log, alert
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1012
show ssl-inspection exception
show ssl-inspection exception
Description
Show the configuration of a specific SSL Inspection policy exception.
Syntax
Parameters
Parameter Description
position The index of exception
Type: Decimal number
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1013
show ssl-inspection exceptions
show ssl-inspection exceptions
Description
Show all configured SSL Inspection policy exceptions.
Syntax
Parameters
Parameter Description
position The index of exception
Type: Decimal number
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1014
ssl-inspection policy
ssl-inspection policy
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1015
set ssl-inspection policy
set ssl-inspection policy
Description
Configure SSL Inspection policy.
Syntax
Parameters
Parameter Description
bypass-banking-category- Bypass banking category traffic
traffic Type: Boolean (true/false)
bypass-government-and- Bypass government category traffic
military-category-traffic Type: Boolean (true/false)
bypass-health-category- Bypass health category traffic
traffic Type: Boolean (true/false)
bypass-other-categories- Bypass other categories traffic
traffic Type: Boolean (true/false)
bypass-streaming- Bypass streaming category traffic
category-traffic Type: Boolean (true/false)
bypass-trusted-wireless- Bypass SSL inspection on trusted wireless networks
ssl-inspection Type: Boolean (true/false)
bypass-untrusted- Bypass SSL inspection on untrusted wireless networks
wireless-ssl-inspection Type: Boolean (true/false)
bypass-well-known- Bypass HTTPS Inspection of traffic to well known software update services
update-services Type: Boolean (true/false)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1016
set ssl-inspection policy
Parameter Description
log-inspected-traffic Generates an SSL inspection log. You can see the logs of the security
policy that is enforced on SSL traffic without enabling this feature.
Type: Boolean (true/false)
log-policy-bypass-traffic Generate an SSL bypass log for SSL traffic that was not inspected by SSL
inspection
Type: Boolean (true/false)
mode Indicates if SSL inspection feature is active
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1017
set ssl-inspection policy https-categorization-only-mode
set ssl-inspection policy https-categorization-
only-mode
Description
Allow URL filtering for HTTPS sites and applications based on server's certificate without activating SSL
traffic inspection.
Syntax
Parameters
Parameter Description
https-categorization-only-mode HTTPS categorization only cane be enabled via HTTPS service
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1018
set ssl-inspection policy inspect-https-protocol
set ssl-inspection policy inspect-https-protocol
Description
Enable SSL Inspection policy to inspect HTTPS protocol. Note- SSL Inspection must be enabled first.
Syntax
Parameters
Parameter Description
true/false true - Enabled
false - Disabled
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1019
set ssl-inspection policy inspect-imaps-protocol
set ssl-inspection policy inspect-imaps-protocol
Description
Enable SSL Inspection policy to inspect IMAPS protocol. Note- SSL Inspection must be enabled first.
Syntax
Parameters
Parameter Description
true/false true - Enabled
false - Disabled
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1020
show ssl-inspection policy
show ssl-inspection policy
Description
Show SSL Inspection policy.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1021
delete ssl-network-extender
delete ssl-network-extender
Description
Forces a manual deletion of the SSL network extender, thus forcing the gateway to re-download the latest
version of the extender from the cloud.
Syntax
delete ssl-network-extender
Parameters
Parameter Description
n/a
Example
delete ssl-network-extender
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1022
delete ssl-network-extender
stateful-inspection
Set and show results of stateful inspection.
set stateful-inspection
Description
Configure stateful inspection advanced settings.
set stateful-inspection
Description
Configure stateful inspection advanced settings.
Syntax
Parameters
Parameter Description
n/a
Example
set stateful-inspection
Description
Configure stateful inspection advanced settings.
Syntax
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1023
delete ssl-network-extender
Parameters
Parameter Description
n/a
Example
set stateful-inspection
Description
Configure stateful inspection advanced settings.
Syntax
Parameters
Parameter Description
n/a
Example
set stateful-inspection
Description
Configure stateful inspection advanced settings.
Syntax
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1024
delete ssl-network-extender
Parameters
Parameter Description
n/a
Example
set stateful-inspection
Description
Configure stateful inspection advanced settings.
Syntax
Parameters
Parameter Description
n/a
Example
set stateful-inspection
Description
Configure stateful inspection advanced settings.
Syntax
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1025
delete ssl-network-extender
Parameters
Parameter Description
n/a
Example
set stateful-inspection
Description
Configure stateful inspection advanced settings.
Syntax
Parameters
Parameter Description
n/a
Example
set stateful-inspection
Description
Configure stateful inspection advanced settings.
Syntax
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1026
delete ssl-network-extender
Parameters
Parameter Description
n/a
Example
set stateful-inspection
Description
Configure stateful inspection advanced settings.
Syntax
Parameters
Parameter Description
n/a
Example
set stateful-inspection
Description
Configure stateful inspection advanced settings.
Syntax
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1027
delete ssl-network-extender
Parameters
Parameter Description
n/a
Example
set stateful-inspection
Description
Configure stateful inspection advanced settings.
Syntax
Parameters
Parameter Description
n/a
Example
set stateful-inspection
Description
Configure stateful inspection advanced settings.
Syntax
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1028
delete ssl-network-extender
Parameters
Parameter Description
n/a
Example
set stateful-inspection
Description
Configure stateful inspection advanced settings.
Syntax
Parameters
Parameter Description
n/a
Example
set stateful-inspection
Description
Configure stateful inspection advanced settings.
Syntax
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1029
delete ssl-network-extender
Parameters
Parameter Description
n/a
Example
set stateful-inspection
Description
Configure stateful inspection advanced settings.
Syntax
Parameters
Parameter Description
n/a
Example
set stateful-inspection
Description
Configure stateful inspections advanced settings.
Syntax
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1030
delete ssl-network-extender
Parameters
Parameter Description
n/a
Example
set stateful-inspection
Description
Configure stateful inspection advanced settings.
Syntax
Parameters
Parameter Description
n/a
Example
show stateful-inspection
Description
Show stateful inspection advanced settings.
Syntax
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1031
delete ssl-network-extender
Parameters
Parameter Description
n/a
Example
Output
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1032
static-route
static-route
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1033
add static-route
add static-route
Description
Adds a new manually configured routing rule.
Syntax
Parameters
Parameter Description
destination IP address and subnet length of the destination of the packet in the format
IP/subnet. e.g. 192.168.0.0/16
Type: An IP address with a mask length
metric Metric
Type: A number with no fractional part (integer)
service Route service name
Type: String
source IP address and subnet length of the source of the packet in the format IP/subnet. e.g.
192.168.1.0/24
Type: An IP address with a mask length
Example
add static-route
Description
Add static route monitoring.
Syntax
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1034
add static-route
Parameters
Parameter Description
destination IP address and subnet length of the destination of the packet in the format IP/subnet
e.g. 192.168.0.0/16.
Type: An IP address with a mask length
metric Metric Type: A number with no fractional part (integer)
service Route service name
Type: String
source IP address and subnet length of the source of the packet in the format IP/subnet. e.g.
192.168.1.0/24
Type: An IP address with a mask length
monitored-ip Remote IPv4 address to monitor for the next hop gateway.
Up to three unique addresses can be added here (in separate commands). The address
is followed by "on" or "off": "on" means this address is being added, while "off" removes
it.
monitored-ip- The failure condition and flavor for the configured monitored IP address(es).
option Options:
n fail-all - - Fails the next hop gateway when all monitored IP addresses become
unreachable. Restores the next hop.
n fail_any- Fails the next hop gateway when one of the monitored IP addresses
becomes unreachable.
n off
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1035
set static-route
set static-route
Description
Configures an existing manually configured route rule.
Syntax
Parameters
Parameter Description
destination IP address and subnet length of the destination of the packet in the format IP/subnet.
e.g. 192.168.0.0/16
Type: An IP address with a mask length
disabled Is rule disabled
Type: Boolean (true/false)
id id
Type: A number with no fractional part (integer)
metric Metric
Type: A number with no fractional part (integer)
service Route service name
Type: String
source IP address and subnet length of the source of the packet in the format IP/subnet. e.g.
192.168.1.0/24
Type: An IP address with a mask length
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1036
delete static-route
delete static-route
Description
Deletes a manually defined routing rule.
Syntax
Parameters
Parameter Description
id The rule order as shown in "show static-routes"
Type: A number with no fractional part (integer)
Example
delete static-route 3
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1037
delete static-routes
delete static-routes
Description
Deletes all manually defined static routing rules.
Syntax
delete static-routes
Parameters
Parameter Description
n/a
Example
delete static-routes
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1038
show static-routes
show static-routes
Description
Shows all static routes.
Syntax
show static-routes
Parameters
Parameter Description
n/a
Example
show static-routes
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1039
streaming-engine-settings
streaming-engine-settings
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1040
set streaming-engine-settings
set streaming-engine-settings
Configures the streaming engine settings.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1041
set streaming-engine-settings
set streaming-engine-settings
Description
Configures the streaming engine settings.
Syntax
Parameters
Parameter Description
tcp-block-out-of-win-mon-only TCP Out of Sequence activation mode
Options: prevent, detect
tcp-block-out-of-win-track TCP Out of Sequence tracking
Options: none, log, alert
tcp-block-retrans-err-mon-only TCP Invalid Retransmission activation mode
Options: prevent, detect
tcp-block-retrans-err-track TCP Invalid Retransmission tracking
Options: none, log, alert
tcp-block-syn-retrans-mon- only TCP SYN Modified Retransmission activation mode
Options: prevent, detect
tcp-block-syn-retrans-track TCP SYN Modified Retransmission tracking
Options: none, log, alert
tcp-block-urg-bit-mon-only TCP Urgent Data Enforcement activation mode
Options: prevent, detect
tcp-block-urg-bit-track TCP Urgent Data Enforcement tracking
Options: none, log, alert
tcp-hold-timeout-mon-only Stream Inspection Timeout activation mode
Options: prevent, detect
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1042
set streaming-engine-settings
Parameter Description
tcp-hold-timeout-track Stream Inspection Timeout tracking
Options: none, log, alert
tcp-invalid-checksum- mon-only TCP Invalid Checksum activation mode
Options: prevent, detect
tcp-invalid-checksum-track TCP Invalid Checksum tracking
Options: none, log, alert
tcp-segment-limit-mon-only TCP Segment Limit Enforcement activation mode
Options: prevent, detect
tcp-segment-limit-track TCP Segment Limit Enforcement tracking
Options: none, log, alert
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1043
set streaming-engine-settings
set streaming-engine-settings
Description
Configures the streaming engine settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1044
show streaming-engine-settings
show streaming-engine-settings
Shows streaming engine settings.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1045
show streaming-engine-settings
show streaming-engine-settings
Description
Shows streaming engine settings.
Syntax
show streaming-engine-settings
Parameters
Parameter Description
n/a
Example
show streaming-engine-settings
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1046
show streaming-engine-settings
show streaming-engine-settings
Description
Shows streaming engine advanced settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1047
switch
switch
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1048
add switch
add switch
Description
Adds a new Port-based VLAN switch object. The physical LAN ports can take part in a "switch" object which
passes traffic between those ports in the hardware level (traffic doesn't undergo inspection as it is not routed
between those ports). In essence the "switch" combines physical LAN ports into a single network.
Syntax
Parameters
Parameter Description
name Name
Type: A switch name should be LAN[1-8]_Switch
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1049
delete switch
delete switch
Description
Deletes a defined port-based VLAN switch object by name.
Syntax
Parameters
Parameter Description
name Name
Type: A switch name should be LAN[1-8]_Switch
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1050
set switch
set switch
Configures an existing port-based VLAN (switch).
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1051
set switch
set switch
Description
Add a physical port to an existing port-based VLAN (switch).
Syntax
Parameters
Parameter Description
name Name
Type: A switch name should be LAN[1-8]_Switch
port Name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1052
set switch
set switch
Description
Removes a physical port from an existing port-based VLAN (switch).
Syntax
Parameters
Parameter Description
name Name
Type: A switch name should be LAN[1-8]_Switch
port Name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1053
show switch
show switch
Shows port-based VLAN (switch) configuration.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1054
show switch
show switch
Description
Shows port-based VLAN (switch) configuration.
Syntax
Parameters
Parameter Description
name Name
Type: A switch name should be LAN[1-8]_Switch
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1055
show switch
show switch
Description
Shows ports within a configured port-based VLAN (switch) configuration.
Syntax
Parameters
Parameter Description
name Name
Type: A switch name should be LAN[1-8]_Switch
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1056
show switches
show switches
Description
Shows all port-based VLANs (switches).
Syntax
show switches
Parameters
Parameter Description
n/a
Example
show switches
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1057
syslog-server
syslog-server
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1058
add syslog-server
add syslog-server
Description
Adds a new external syslog server. The appliance can send its syslog information to multiple syslog servers
and can also be configured to relay its security logs to external syslog servers.
Syntax
Parameters
Parameter Description
enabled Determine if an external System Log Server is active
Type: Boolean (true/false)
ipv4-address The desired external System Log Server IP address
Type: IP address
name System Log Server name
Type: A string of alphanumeric characters with space between them
port Port in the external System Log Server that receives the logs (default is 514)
Type: Port number
sent-logs Determine which logs types will be sent to the System Log Server
Options: system-logs, security-logs, system-and-security-logs
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1059
add-syslog-server protocol tls
add-syslog-server protocol tls
Description
Adds a new external syslog server for the TLS protocol.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1060
delete syslog-server
delete syslog-server
Deletes a configured external syslog server.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1061
delete syslog-server
delete syslog-server
Description
Deletes a configured external syslog server by IP address.
Syntax
Parameters
Parameter Description
ipv4-address The desired external System Log Server IP address
Type: IP address
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1062
delete syslog-server
delete syslog-server
Description
Deletes a configured external syslog server by name.
Syntax
Parameters
Parameter Description
name System Log Server name
Type: A string of alphanumeric characters with space between them
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1063
set syslog-server
set syslog-server
Configure an existing syslog server's settings.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1064
set syslog-server
set syslog-server
Description
Configure an existing syslog server's settings by IP address.
Syntax
Parameters
Parameter Description
enabled Determine if an external System Log Server is active
Type: Boolean (true/false)
ipv4-address The desired external System Log Server IP address
Type: IP address
name System Log Server name
Type: A string of alphanumeric characters with space between them
port Port in the external System Log Server that receives the logs (default is 514)
Type: Port number
sent-logs Determine which logs types will be sent to the System Log Server
Options: system-logs, security-logs, system-and-security-logs
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1065
set syslog-server
set syslog-server
Description
Configure an existing syslog server's settings by name.
Syntax
Parameters
Parameter Description
enabled Determine if an external System Log Server is active
Type: Boolean (true/false)
ipv4-address The desired external System Log Server IP address
Type: IP address
name System Log Server name
Type: A string of alphanumeric characters with space between them
port Port in the external System Log Server that receives the logs (default is 514)
Type: Port number
sent-logs Determine which logs types will be sent to the System Log Server
Options: system-logs, security-logs, system-and-security-logs
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1066
show syslog-server
show syslog-server
Shows configuration of external syslog servers.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1067
show syslog-server
show syslog-server
Description
Shows configuration of an external syslog server by IP address.
Syntax
Parameters
Parameter Description
ipv4-address The desired external System Log Server IP address
Type: IP address
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1068
show syslog-server
show syslog-server
Description
Shows configuration of an external syslog server by name.
Syntax
Parameters
Parameter Description
name System Log Server name
Type: A string of alphanumeric characters with space between them
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1069
show syslog-server all
show syslog-server all
Description
Shows configuration of all external syslog servers.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1070
show syslog-server all
system-settings
Relevant commands for system settings.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1071
show system-settings is-custom-branding
show system-settings is-custom-branding
Description
Shows whether white labeling has been enabled and the appliance has been customized with a particular
brand.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1072
traceroute-max-ttl
traceroute-max-ttl
Description
The maximal value for TTL field for a packet to be considered as a traceroute
Syntax
Parameters
Parameter Description
value Integer between 0 and 64.
Default: 29
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1073
threat-prevention-advanced
threat-prevention-advanced
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1074
set threat-prevention-advanced
set threat-prevention-advanced
Description
Configures advanced settings for Threat Prevention blades.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1075
show threat-prevention-advanced
show threat-prevention-advanced
Description
Shows advanced settings for the Threat Prevention blades.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1076
threat-prevention anti-bot
threat-prevention anti-bot
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1077
set threat-prevention anti-bot engine
set threat-prevention anti-bot engine
Description
Configures the engine settings of the <tp_bot> blade.
Syntax
Parameters
Parameter Description
malicious- Indicates if the action upon detecting malicious activity will be according to the policy
activity settings or a manually configured specific action
Options: ask, prevent, detect, inactive, policy-action
reputation- Indicates if the action upon detecting attempted access to domains with a bad
domains reputation will be according to the policy or a manually configured specific action
Options: ask, prevent, detect, inactive, policy-action
reputation-ips Indicates if the action upon detecting attempted access to IP addresses with a bad
reputation will be according to the policy or a manually configured specific action
Options: ask, prevent, detect, inactive, policy-action
reputation- Indicates if the action upon detecting attempted access to URLs with a bad reputation
urls will be according to the policy or a manually configured specific action
Options: ask, prevent, detect, inactive, policy-action
unusual- Indicates if the action upon detecting unusual activity will be according to the policy or a
activity manually configured specific action
Options: ask, prevent, detect, inactive, policy-action
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1078
show threat-prevention anti-bot engine
show threat-prevention anti-bot engine
Description
Shows the engine settings of the Anti-Bot blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1079
set threat-prevention anti-bot policy
set threat-prevention anti-bot policy
Configures the policy of the Anti-Bot blade.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1080
set threat-prevention anti-bot policy
set threat-prevention anti-bot policy
Description
Configures the policy of the Anti-Bot blade.
Syntax
Parameters
Parameter Description
detect-mode Indicates if the Anti-Bot blade is set to 'Detect Only' mode
Type: Boolean (true/false)
mode Indicates if the Anti-Bot blade is active
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1081
set threat-prevention anti-bot policy
set threat-prevention anti-bot policy
Description
Configures advanced settings of the Anti-Bot blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1082
show threat-prevention anti-bot policy
show threat-prevention anti-bot policy
Shows the policy of the Anti-Bot blade.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1083
show threat-prevention anti-bot policy
show threat-prevention anti-bot policy
Description
Shows the policy of the Anti-Bot blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1084
show threat-prevention anti-bot policy
show threat-prevention anti-bot policy
Description
Shows the advanced settings of the Anti-Bot blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1085
set threat-prevention anti-bot user-check ask
set threat-prevention anti-bot user-check ask
Description
Configures a customizable "ask" message shown to users upon match on browser based traffic.
Syntax
Parameters
Parameter Description
activity-text This text appears next to the 'ignore warning' checkbox of an Anti-Bot 'Ask' user
message
Type: A string that contains only printable characters
body The informative text that appears in the Anti-Bot 'Ask' user message
Type: A string that contains only printable characters
fallback-action Indicates the action to take when an 'Ask' user message cannot be displayed
Options: block, accept
frequency Indicates how often is the Anti-Bot 'Ask' user message is being presented to the same
user
Options: day, week, month
reason- Indicates if the user must enter a reason for ignoring this message in a designated
displayed text dialog
Type: Boolean (true/false)
subject The subject of an Anti-Bot 'Ask' user message
Type: A string that contains only printable characters
title The title of an Anti-Bot 'Ask' user message
Type: A string that contains only printable characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1086
show threat-prevention anti-bot user-check ask
show threat-prevention anti-bot user-check ask
Description
Shows the settings of the customizable "ask" message shown to users upon match on browser based traffic.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1087
set threat-prevention anti-bot user-check block
set threat-prevention anti-bot user-check block
Description
Configures a customizable "block" message shown to users upon match on browser based traffic.
Syntax
Parameters
Parameter Description
body The informative text that appears in the Anti-Bot 'Block' user message
Type: A string that contains only printable characters
redirect-to-url Indicates if the user will be redirected to a custom URL in case of a 'Block' action
Type: Boolean (true/false)
redirect-url Indicates the URL to redirect the user in case of a 'Block' action if configured to do so.
The URL to redirect the user in case of a 'Block' action. Redirection happens only if this
functionality is turned on
Type: urlWithHttp
subject The subject of an Anti-Bot 'Block' user message
Type: A string that contains only printable characters
title The title of an Anti-Bot 'Block' user message
Type: A string that contains only printable characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1088
show threat-prevention anti-bot user-check block
show threat-prevention anti-bot user-check
block
Description
Shows the settings of the customizable "block" message shown to users upon Anti-Bot match on browser
based traffic.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1089
threat-prevention anti-virus
threat-prevention anti-virus
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1090
set threat-prevention anti-virus engine
set threat-prevention anti-virus engine
Description
Configures the engine settings of the Anti-Virus blade
Syntax
Parameters
Parameter Description
urls-with- Indicates if the action upon detecting access to and from URLs with a bad reputation will
malware be according to the policy or a manually configured specific action
Options: ask, prevent, detect, inactive, policy-action
viruses Indicates if the action upon detecting viruses will be according to the policy or a
manually configured specific action
Options: ask, prevent, detect, inactive, policy-action
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1091
show threat-prevention anti-virus engine
show threat-prevention anti-virus engine
Description
Shows the engine settings of the Anti-Virus blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1092
add threat-prevention anti-virus file-type
add threat-prevention anti-virus file-type
Description
Adds a new custom file type according to extension, to be handled by the Anti-Virus file type handling
mechanism. An action for the Anti-Virus blade is also configured for this new custom file type.
Syntax
Parameters
Parameter Description
action Indicates the action when the file type is detected
Options: block, pass, scan
description The file description
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
extension File extension that represents this file type
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1093
delete threat-prevention anti-virus file-type
delete threat-prevention anti-virus file-type
Description
Deletes a manually configured custom file type according to extension.
Syntax
Parameters
Parameter Description
extension File extension that represents this file type
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1094
set threat-prevention anti-virus file-type
set threat-prevention anti-virus file-type
Description
Configure a specific action of the Anti-Virus blade for a specific file extension.
Syntax
Parameters
Parameter Description
action Indicates the action when the file type is detected
Options: block, pass, scan
description The file description
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
extension File extension that represents this file type
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1095
show threat-prevention anti-virus file-type
show threat-prevention anti-virus file-type
Description
Shows the Anti-Virus blade configuration for a specific file type.
Syntax
Parameters
Parameter Description
extension File extension that represents this file type
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1096
show threat-prevention anti-virus file-types
show threat-prevention anti-virus file-types
Description
Shows the Anti-Virus blade configuration for all defined file types.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1097
delete threat-prevention anti-virus file-type custom
delete threat-prevention anti-virus file-type
custom
Description
Deletes all manually configured custom file types.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1098
set threat-prevention anti-virus policy
set threat-prevention anti-virus policy
Configures the policy of the Anti-Virus blade.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1099
set threat-prevention anti-virus policy
set threat-prevention anti-virus policy
Description
Configures the policy of the Anti-Virus blade.
Syntax
Parameters
Parameter Description
detect-mode Indicates if the Anti-Virus blade is set to 'Detect Only' mode
Type: Boolean (true/false)
file-types- Indicates the file types that are inspected by the Anti-Virus blade: malware (known to
policy contain malware), all (all file types), specific (configured file families)
Options: malware, all-types, specific-families
interfaces Indicates the source zones for inspected incoming files: External, External and DMZ or
all interfaces
Options: all, external, external-dmz
mode Indicates if the Anti-Virus blade is active
Type: Boolean (true/false)
protocol-ftp Indicates if Anti-Virus inspection will be performed on FTP traffic
Type: Boolean (true/false)
protocol-http Indicates if Anti-Virus inspection will be performed on all configured ports of HTTP traffic
Type: Boolean (true/false)
protocol-mail Indicates if Anti-Virus inspection will be performed on mail traffic (SMTP and POP3)
Type: Boolean (true/false)
scope Indicates the source of scanned filed: Scan incoming files, or scan both incoming and
outgoing files
Options: incoming, incoming-and-outgoing
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1100
set threat-prevention anti-virus policy
set threat-prevention anti-virus policy
Description
Configures advanced settings of the Anti-Virus blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1101
set threat-prevention anti-virus policy
set threat-prevention anti-virus policy
Description
Configures advanced settings of the Anti-Virus blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1102
set threat-prevention anti-virus policy
set threat-prevention anti-virus policy
Description
Configures advanced settings of the Anti-Virus blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1103
set threat-prevention anti-virus policy
set threat-prevention anti-virus policy
Description
Configures advanced settings of the Anti-Virus blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1104
set threat-prevention anti-virus policy
set threat-prevention anti-virus policy
Description
Configures advanced settings of the Anti-Virus blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1105
show threat-prevention anti-virus policy
show threat-prevention anti-virus policy
Shows the policy for the Anti-Virus blade.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1106
show threat-prevention anti-virus policy
show threat-prevention anti-virus policy
Description
Shows the policy for the Anti-Virus blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1107
show threat-prevention anti-virus policy
show threat-prevention anti-virus policy
Description
Shows advanced settings for the Anti-Virus blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1108
set threat-prevention anti-virus user-check ask
set threat-prevention anti-virus user-check ask
Description
Configures a customizable "ask" message shown to users upon match on browser based traffic.
Syntax
Parameters
Parameter Description
activity-text This text appears next to the 'ignore warning' checkbox of an Anti-Virus 'Ask' user
message
Type: A string that contains only printable characters
body The informative text that appears in the Anti-Virus 'Ask' user message
Type: A string that contains only printable characters
fallback-action Indicates the action to take when an 'Ask' user message cannot be displayed
Options: block, accept
frequency Indicates how often is the Anti-Virus 'Ask' user message is being presented to the
same user
Options: day, week, month
reason- Indicates if the user must enter a reason for ignoring this message in a designated
displayed text dialog
Type: Boolean (true/false)
subject The subject of an Anti-Virus 'Ask' user message
Type: A string that contains only printable characters
title The title of an Anti-Virus 'Ask' user message
Type: A string that contains only printable characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1109
show threat-prevention anti-virus user-check ask
show threat-prevention anti-virus user-check
ask
Description
Shows the settings of the customizable "ask" message shown to users upon Anti-Virus match on browser
based traffic.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1110
set threat-prevention anti-virus user-check block
set threat-prevention anti-virus user-check
block
Description
Configures a customizable "block" message shown to users upon match on browser based traffic.
Syntax
Parameters
Parameter Description
body The informative text that appears in the Anti-Virus 'Block' user message
Type: A string that contains only printable characters
redirect-to-url Indicates if the user will be redirected to a custom URL in case of a 'Block' action
Type: Boolean (true/false)
redirect-url Indicates the URL to redirect the user in case of a 'Block' action if configured to do so.
The URL to redirect the user in case of a 'Block' action. Redirection happens only if this
functionality is turned on
Type: urlWithHttp
subject The subject of an Anti-Virus 'Block' user message
Type: A string that contains only printable characters
title The title of an Anti-Virus 'Block' user message
Type: A string that contains only printable characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1111
show threat-prevention anti-virus user-check block
show threat-prevention anti-virus user-check
block
Description
Shows the settings of the customizable "block" message shown to users upon Anti-Virus match on browser
based traffic.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1112
threat-prevention exception
threat-prevention exception
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1113
add threat-prevention exception
add threat-prevention exception
Description
Adds a new exception rule for Threat Preventionmalware protection.
Syntax
Parameters
Parameter Description
action The action taken when there is a match on the rule
Options: ask, prevent, detect, inactive
blade The blade to which the exception applies: Anti-Virus, Anti-Bot or both
Options: any, any-av, any-ab, any-ips
comment Additional description for the exception
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
destination Network object that is the target of the connection
destination- If true, the destination is all traffic except what is defined in the destination field
negate Type: Boolean (true/false)
log The logging method used when there is a match on the rule: None - do not log, Log -
Create log, Alert - log with alert
Options: none, log, alert
protection- Indicates if the exception rule will be matched a specific IPS protection
code
protection- Indicates if the exception rule will be matched a specific IPS protection
name
service Type of network service that is under exception
service- If true, the service is everything except what is defined in the service field
negate Type: Boolean (true/false)
source IP address, network object or user group that the exception applies to
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1114
add threat-prevention exception
Parameter Description
source negate If true, the source is all traffic except what is defined in the source field
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1115
delete threat-prevention exception
delete threat-prevention exception
Description
Deletes an existing malware exception rule by name.
Syntax
Parameters
Parameter Description
name The name of the exception
Type: A string of alphanumeric characters without space between them
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1116
set threat-prevention exception
set threat-prevention exception
Description
Configures an existing exception rule for the Threat Prevention malware exceptions.
Syntax
Parameters
Parameter Description
action The action taken when there is a match on the rule
Options: ask, prevent, detect, inactive
blade The blade to which the exception applies: Anti-Virus, Anti-Bot or both
Options: any, any-av, any-ab, any-ips
comment Additional description for the exception
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . -: () @
destination Network object that is the target of the connection
destination- If true, the destination is all traffic except what is defined in the destination field
negate Type: Boolean (true/false)
log The logging method used when there is a match on the rule: None - do not log, Log -
Create log, Alert - log with alert
Options: none, log, alert
position The order of the rule in comparison to other rules
Type: Decimal number
protection- Indicates if the exception rule will be matched a specific IPS protection
code
protection- Indicates if the exception rule will be matched a specific IPS protection
name
service Type of network service that is under exception
service- If true, the service is everything except what is defined in the service field
negate Type: Boolean (true/false)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1117
set threat-prevention exception
Parameter Description
source IP address, network object or user group that the exception applies to
source-negate If true, the source is all traffic except what is defined in the source field
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1118
show threat-prevention exception
show threat-prevention exception
Description
Shows the configuration of a specific malware exception rule by name.
Syntax
Parameters
Parameter Description
name The name of the exception
Type: A string of alphanumeric characters without space between them
position The order of the rule in comparison to other rules
Type: Decimal number
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1119
delete threat-prevention exceptions
delete threat-prevention exceptions
Description
Deletes all existing malware exception rules for Anti-Virus, Anti-Bot and Threat Emulation (where
applicable).
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1120
show threat-prevention infected-hosts
show threat-prevention infected-
hosts
Description
Shows a list of infected hosts detected by Threat Prevention blades.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1121
threat-prevention ips
threat-prevention ips
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1122
set threat-prevention ips custom-default-policy
set threat-prevention ips custom-default-policy
Description
Configures the default policy of the IPS blade.
Syntax
Parameters
Parameter Description
client-protections Indicates if Client protections are active by default
Type: Boolean (true/false)
disable-by-confidence- Indicates if protections will be deactivated if their confidence level is below
level or equal configured level Type: Boolean (true/false)
disable-by-performance- Indicates if protections will be deactivated if their performance impact is
impact above or equal configured level Type: Boolean (true/false)
disable-by-severity Indicates if protections will be deactivated if their severity is below or equal
configured level
Type: Boolean (true/false)
disable-confidence-level- If configured, protections will be deactivated according to this confidence
below -or-equal level
Options: Low, Medium-low, Medium, Medium-high, High
disable-performance- If configured, protections will be deactivated according to this performance
impact -above-or-equal impact level
Options: Very-low, Low, Medium, High
disable-protocol- Do not activate protocol anomaly detection signatures
anomalies Type: Boolean (true/false)
disable-severity-below-or If configured, protections will be deactivated according to this severity level
-equal Options: Low, Medium, High, Critical
server-protections Indicates if Server protections are active by default
Type: Boolean (true/false)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1123
set threat-prevention ips custom-default-policy
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1124
show threat-prevention ips custom-default-policy
show threat-prevention ips custom-default-
policy
Description
Shows the configuration of a custom IPS policy.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1125
add threat-prevention ips network-exception
add threat-prevention ips network-exception
Adds a new exception rule for the IPS blade.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1126
add threat-prevention ips network-exception
add threat-prevention ips network-exception
Description
Adds a new exception rule for the IPS blade. To create exceptions for specific protections use protection
name.
Syntax
Parameters
Parameter Description
comment Comment on the IPS Network exception
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : ()
@
destination Network object that is the target of the connection
destination- If true, the destination is all traffic except what is defined in the destination field
negate Type: Boolean (true/false)
protection-name Indicates if the exception rule will be matched on all IPS protections or a specific
one
service Type of network service that is under exception
service-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
source Network object or user group that initiates the connection
source-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1127
add threat-prevention ips network-exception
add threat-prevention ips network-exception
Description
Adds a new exception rule for the IPS blade. To create exceptions for specific protections use protection
code.
Syntax
Parameters
Parameter Description
comment Comment on the IPS Network exception
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : ()
@
destination Network object that is the target of the connection
destination- If true, the destination is all traffic except what is defined in the destination field
negate Type: Boolean (true/false)
protection-code Indicates if the exception rule will be matched on all IPS protections or a specific
one
service Type of network service that is under exception
service-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
source Network object or user group that initiates the connection
source-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1128
delete threat-prevention ips network-exception
delete threat-prevention ips network-exception
Deletes exception rules to bypass IPS protections for specific traffic.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1129
delete threat-prevention ips network-exception
delete threat-prevention ips network-exception
Description
Deletes an existing exception rule for the IPS blade by position.
Syntax
Parameters
Parameter Description
position The order of the rule in the Rule Base
Type: Decimal number
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1130
delete threat-prevention ips network-exception
delete threat-prevention ips network-exception
Description
Deletes all existing exception rules for the IPS blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1131
set threat-prevention ips network-exception
set threat-prevention ips network-exception
Configure exception rules to bypass IPS protections for specific traffic.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1132
set threat-prevention ips network-exception
set threat-prevention ips network-exception
Description
Configure an existing exception rule to the IPS blade by position for a specific protection by protection ID
(Code).
Syntax
Parameters
Parameter Description
comment Comment on the IPS Network exception
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . -: ()
@
destination Network object that is the target of the connection
destination- If true, the destination is all traffic except what is defined in the destination field
negate Type: Boolean (true/false)
position The order of the rule in the Rule Base
Type: Decimal number
protection-code Indicates if the exception rule will be matched on all IPS protections or a specific
one
service Type of network service that is under exception
service-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
source Network object or user group that initiates the connection
source-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1133
set threat-prevention ips network-exception
set threat-prevention ips network-exception
Description
Configure an existing exception rule to the IPS blade by position for a specific protection by protection
name.
Syntax
Parameters
Parameter Description
comment Comment on the IPS Network exception
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : ()
@
destination Network object that is the target of the connection
destination- If true, the destination is all traffic except what is defined in the destination field
negate Type: Boolean (true/false)
position The order of the rule in the Rule Base
Type: Decimal number
protection-name Indicates if the exception rule will be matched on all IPS protections or a specific
one
service Type of network service that is under exception
service-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
source Network object or user group that initiates the connection
source-negate If true, the service is everything except what is defined in the service field
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1134
show threat-prevention ips network-exception
show threat-prevention ips network-exception
Description
Shows the configuration of an IPS exception rule by position
Syntax
Parameters
Parameter Description
position The order of the rule in the Rule Base
Type: Decimal number
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1135
set threat-prevention ips policy
set threat-prevention ips policy
Description
Configures general settings in the policy of the IPS blade.
Syntax
Parameters
Parameter Description
default-policy The type of policy used for IPS - strict, typical or custom
detect-mode Indicates if the default policy of IPS is to only logs events and not block them
Type: Boolean (true/false)
log Indicates the tracking level for IPS - none, block or alert
Options: none, log, alert
mode Indicates if IPS blade is active
Type: Boolean (true/false)
Example
set threat-prevention ips policy mode true log none default-policy word
detect-mode true
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1136
show threat-prevention ips policy
show threat-prevention ips policy
Description
Shows the policy of the IPS blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1137
find threat-prevention ips protection
find threat-prevention ips protection
Description
Find an IPS protection by name (or partial string) to view further details regarding it.
Syntax
Parameters
Parameter Description
name The name of the IPS topic
Type: A string of alphanumeric characters without space between them
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1138
set threat-prevention ips protection-action-override
set threat-prevention ips protection-action-
override
Configures actions to override the IPS policy for a specific IPS protection.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1139
set threat-prevention ips protection-action-override
set threat-prevention ips protection-action-override
Description
Enable/Disable an action override for a specific IPS protection by protection ID (code).
Syntax
Parameters
Parameter Description
action Indicates the manually configured action for this protection
protection- The IPS topic the override belongs to. Every override belongs to a single topic
code Type: A number with no fractional part. Values are between 4,503,599,627,370,495 to
4,503,599,627,370,495
track Indicates the manually configured tracking option for this protection
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1140
set threat-prevention ips protection-action-override
set threat-prevention ips protection-action-override
Description
Configures an action override for a specific IPS protection by name.
Syntax
Parameters
Parameter Description
action Indicates the manually configured action for this protection
protection-name The name of the IPS topic
Type: A string of alphanumeric characters without space between them
track Indicates the manually configured tracking option for this protection
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1141
set threat-prevention ips protection-action-override
set threat-prevention ips protection-action-override
Description
Configures an action override for a specific IPS protection by protection ID (code).
Syntax
Parameters
Parameter Description
override- Indicates if the action upon detection will be according to the general IPS policy or
policy-action manually configured for this protection
Type: Boolean (true/false)
protection- The IPS topic the override belongs to. Every override belongs to a single topic
code Type: A number with no fractional part. Values are between 4,503,599,627,370,495 to
4,503,599,627,370,495
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1142
set threat-prevention ips protection-action-override
set threat-prevention ips protection-action-override
Description
Enable/Disable an action override for a specific IPS protection by name.
Syntax
Parameters
Parameter Description
override- Indicates if the action upon detection will be according to the general IPS policy or
policy-action manually configured for this protection
Type: Boolean (true/false)
protection- The name of the IPS topic
name Type: A string of alphanumeric characters without space between them
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1143
show threat-prevention ips protection-action-override
show threat-prevention ips protection-action-
override
Shows action overrides for specific IPS protections.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1144
show threat-prevention ips protection-action-override
show threat-prevention ips protection-action-override
Description
Shows action overrides for a specific IPS protection by protection ID (code).
Syntax
Parameters
Parameter Description
protection- The IPS topic the override belongs to. Every override belongs to a single topic
code Type: A number with no fractional part. Values are between 4,503,599,627,370,495 to
4,503,599,627,370,495
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1145
show threat-prevention ips protection-action-override
show threat-prevention ips protection-action-override
Description
Shows action overrides for a specific IPS protection by protection name.
Syntax
Parameters
Parameter Description
protection-name The name of the IPS topic
Type: A string of alphanumeric characters without space between them
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1146
show threat-prevention ips protection-action-override
threat-prevention-profile
Commands relevant for the Unified Threat Prevention profile.
set threat-prevention policy
Description
Configures the policy for the Threat Prevention blades Anti-Virus, Anti-Bot and Threat Emulation (where
applicable).
Syntax
Parameters
Parameter Description
profile Unified policy profile
track Tracking options for Threat Prevention protections: None - do not log, Log -Create log,
Alert - log with alert
Options: none, log, alert
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1147
threat-prevention policy
threat-prevention policy
Shows commands relevant to Threat Prevention policy.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1148
set threat-prevention policy
set threat-prevention policy
Description
Configures the policy for the Threat Prevention blades Anti-Virus, Anti-Bot and Threat Emulation (where
applicable).
Syntax
Parameters
Parameter Description
profile Unified policy profile
track Tracking options for Threat Prevention protections: None - do not log, Log -Create log,
Alert - log with alert
Options: none, log, alert
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1149
show threat-prevention policy
show threat-prevention policy
Description
Shows the configuration for the Threat Prevention policy shared by the Anti-Bot, Anti-Virus and Threat
Emulation (where applicable) blades.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1150
threat-prevention threat-emulation additional-remote-emulator
threat-prevention threat-emulation
additional-remote-emulator
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1151
add threat-prevention threat-emulation additional-remote-emulator
add threat-prevention threat-emulation
additional-remote-emulator
Description
Add a gateway to the threat emulation list of additional (private) emulation gateways.
Syntax
Parameters
Parameter Description
ip-address Remote emulation gateway IP address
Type: IP address
name Remote emulation gateway name
Type: A string of alphanumeric characters with space between them
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1152
delete threat-prevention threat-emulation additional-remote-emulator
delete threat-prevention threat-emulation
additional-remote-emulator
Delete a gateway from the threat emulation list of additional (private) emulation gateways.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1153
delete threat-prevention threat-emulation additional-remote-emulator
delete threat-prevention threat-emulation additional-remote-
emulator
Description
Delete a gateway from the threat emulation list of additional (private) emulation gateways.
Syntax
Parameters
Parameter Description
ip-address Remote emulation gateway IP address
Type: IP address
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1154
delete threat-prevention threat-emulation additional-remote-emulator
delete threat-prevention threat-emulation additional-remote-
emulator
Description
Delete a gateway from the threat emulation list of additional (private) emulation gateways.
Syntax
Parameters
Parameter Description
name Remote emulation gateway name
Type: A string of alphanumeric characters with space between them
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1155
set threat-prevention threat-emulation additional-remote-emulator
set threat-prevention threat-emulation
additional-remote-emulator
Description
Configure a gateway as an additional (private) emulation gateway.
Syntax
Parameters
Parameter Description
ip-address Remote emulation gateway IP address
Type: IP address
name Remote emulation gateway name
Type: A string of alphanumeric characters with space between them
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1156
show threat-prevention threat-emulation additional-remote-emulator
show threat-prevention threat-emulation
additional-remote-emulator
Show all gateways that are configured as additional (private) emulation gateways.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1157
show threat-prevention threat-emulation additional-remote-emulator
show threat-prevention threat-emulation additional-remote-
emulator
Description
Show all gateways that are configured as additional (private) emulation gateways.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1158
show threat-prevention threat-emulation additional-remote-emulator
show threat-prevention threat-emulation additional-remote-
emulator
Description
Show all gateways that are configured as additional (private) emulation gateways.
Syntax
show threat-prevention threat-emulation additional-remote-emulator name <name>
Parameters
Parameter Description
name Remote emulation gateway name
Type: A string of alphanumeric characters with space between them
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1159
set threat-prevention threat-emulation file-types-revert-actions-to-default
set threat-prevention threat-
emulation file-types-revert-actions-
to-default
Description
Reverts all actions on specific file types to their default value in the factory settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1160
threat-prevention threat-emulation
threat-prevention threat-emulation
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1161
set threat-prevention threat-emulation file-type
set threat-prevention threat-emulation file-type
Description
Configures an override action for a specific file type by the Threat Emulation blade (where applicable).
Syntax
Parameters
Parameter Description
action Indicates the action when the file type is detected
Options: bypass, inspect
description The file description
Type: A string that contains less than 257 characters, of this set: 0-9, a-z or , . - : () @
extension File extension that represents this file type
Type: A string of alphanumeric characters without space between them
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1162
show threat-prevention threat-emulation file-type
show threat-prevention threat-emulation file-
type
Description
Shows the Threat Emulation (where applicable) configuration for a specific file type.
Syntax
Parameters
Parameter Description
extension File extension that represents this file type
Type: A string of alphanumeric characters without space between them
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1163
show threat-prevention threat-emulation file-types
show threat-prevention threat-emulation file-
types
Description
Shows the Threat Emulation (where applicable) configuration for all specific file types.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1164
set threat-prevention threat-emulation policy
set threat-prevention threat-emulation policy
Configures a policy specific to the Threat Emulation blade (where applicable).
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1165
set threat-prevention threat-emulation policy
set threat-prevention threat-emulation policy
Description
Configures policy settings for the Threat Emulation blade (where applicable).
Syntax
Parameters
Parameter Description
connection- Indicates the strictness mode of the Threat Emulation engine over HTTP: Back-ground
handling- - connections are allowed while the file emulation runs (if needed), Hold - connections
mode-http are blocked until the file emulation is completed
Options: background, hold
connection- Indicates the strictness mode of the Threat Emulation engine over SMTP: Back-ground
handling- - connections are allowed while the file emulation runs (if needed), Hold - connections
mode-smtp are blocked until the file emulation is completed
Options: background, hold
detect-mode Indicates if the Threat Emulation blade is set to 'Detect Only' mode
Type: Boolean (true/false)
interfaces Indicates the source zones for inspected incoming files: External, External and DMZ or
all interfaces
Options: all, external, external-dmz
mode Indicates if the Threat Emulation blade is active
Type: Boolean (true/false)
protocol-http Indicates if file emulation will be performed on all configured ports of HTTP traffic
Type: Boolean (true/false)
protocol-mail Indicates if file emulation will be performed on mail traffic (SMTP)
Type: Boolean (true/false)
scope Indicates the source of scanned file: scan incoming files, or scan both incoming and
outgoing files
Options: incoming, incoming-and-outgoing
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1166
set threat-prevention threat-emulation policy
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1167
set threat-prevention threat-emulation policy
set threat-prevention threat-emulation policy
Description
Configures advanced settings for the Threat Emulation blade (where applicable).
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1168
show threat-prevention threat-emulation policy
show threat-prevention threat-emulation policy
Shows the policy of the Threat Emulation policy.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1169
show threat-prevention threat-emulation policy
show threat-prevention threat-emulation policy
Description
Shows the policy of the Threat Emulation policy.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1170
show threat-prevention threat-emulation policy
show threat-prevention threat-emulation policy
Description
Shows advanced settings of the Threat Emulation policy.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1171
threat-prevention whitelist
threat-prevention whitelist
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1172
add threat-prevention whitelist mail
add threat-prevention whitelist mail
Description
Adds a new excluded mail addresses for the Threat Emulation blade (where applicable).
Syntax
Parameters
Parameter Description
email-address The email address of the recipient or sender
Type: Email address
type The type of the email address - recipient, sender or both
Options: recipient, sender, both
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1173
show threat-prevention whitelist files
show threat-prevention whitelist files
Description
Shows the list of whitelist files (md5sum) for the Threat Prevention blades.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1174
delete threat-prevention whitelist mail
delete threat-prevention whitelist mail
Description
Deletes an excluded mail address for the Threat Emulation blade (where applicable).
Syntax
Parameters
Parameter Description
email-address The email address of the recipient or sender
Type: Email address
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1175
set threat-prevention whitelist mail
set threat-prevention whitelist mail
Description
Configures excluded mail addresses for the Threat Emulation blade (where applicable).
Syntax
Parameters
Parameter Description
email-address The email address of the recipient or sender
Type: Email address
type The type of the email address - recipient, sender or both
Options: recipient, sender, both
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1176
show threat-prevention whitelist mail
show threat-prevention whitelist mail
Description
Shows the setting for a whitelist email address set for the Threat Prevention blades.
Syntax
Parameters
Parameter Description
email-address The email address of the recipient or sender
Type: Email address
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1177
delete threat-prevention whitelist mails
delete threat-prevention whitelist mails
Description
Deletes all excluded mail addresses for the Threat Emulation blade (where applicable).
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1178
show threat-prevention whitelist mails
show threat-prevention whitelist mails
Description
Shows the whitelist email addresses set for the Threat Prevention blades.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1179
add threat-prevention whitelist type-file
add threat-prevention whitelist type-file
Description
Adds a new excluded file for Threat Prevention blades according to md5.
Syntax
Parameters
Parameter Description
md5 MD5 encryption for the file in the whitelist
Type: MD5 checksum of a file. Contains only [a-f] and [0-9] characters and of exact
length of 32
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1180
delete threat-prevention whitelist type-file
delete threat-prevention whitelist type-file
Deletes excluded files for Threat Prevention blades.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1181
delete threat-prevention whitelist type-file
delete threat-prevention whitelist type-file
Description
Removes an excluded file for Threat Prevention blades by md5.
Syntax
Parameters
Parameter Description
md5 MD5 encryption for the file in the whitelist
Type: MD5 checksum of a file. Contains only [a-f] and [0-9] characters and of exact
length of 32
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1182
delete threat-prevention whitelist type-file
delete threat-prevention whitelist type-file
Description
Removes all excluded files for Threat Prevention blades.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1183
add threat-prevention whitelist type-url
add threat-prevention whitelist type-url
Description
Adds a new excluded URL for Threat Prevention blades.
Syntax
Parameters
Parameter Description
url URL
Type: URL
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1184
delete threat-prevention whitelist type-url
delete threat-prevention whitelist type-url
Deletes excluded URLs for Threat Prevention blades.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1185
delete threat-prevention whitelist type-url
delete threat-prevention whitelist type-url
Description
Removes an excluded URL for Threat Prevention blades.
Syntax
Parameters
Parameter Description
url URL
Type: URL
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1186
delete threat-prevention whitelist type-url
delete threat-prevention whitelist type-url
Description
Removes all excluded URLs for Threat Prevention blades.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1187
show threat-prevention whitelist urls
show threat-prevention whitelist urls
Description
Shows the whitelist URLs set for the Threat Prevention blades.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1188
show threat-prevention whitelist urls
update default-image from current-
image
Description
Update default image from currently running image.
Syntax
Parameters
Parameter Description
preserve-settings Yes - Preserve your current settings
No – Do not preserve your current settings
force Yes- Confirm before rebooting
No – Execute immediately
Example
Output
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1189
ui-settings
ui-settings
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1190
set ui-settings
set ui-settings
Configures customizations that can be done for the administration portal.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1191
set ui-settings
set ui-settings
Description
Configure a custom logo that will appear in the administration portal. The logo can be reached through a
URL.
Syntax
Parameters
Parameter Description
custom- Clicking the company logo in the web interface opens this URL
webui-logo- Type: urlWithHttp
url
use-custom- The company logo is displayed on the appliance's web interface and on its login page.
webui- logo The customized logo should follow the size restrictions in order to be displayed properly.
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1192
set ui-settings
set ui-settings
Description
Configures customizations that can be done for the administration portal.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1193
show ui-settings
show ui-settings
Shows web interface settings and customizations.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1194
show ui-settings
show ui-settings
Description
Shows web interface settings and customizations.
Syntax
show ui-settings
Parameters
Parameter Description
n/a
Example
show ui-settings
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1195
show ui-settings
show ui-settings
Description
Shows web Interface advanced settings.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1196
usb-modem-advanced
usb-modem-advanced
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1197
add usb-modem-advanced
add usb-modem-advanced
Description
Add a USB modem advanced entry.
Syntax
Parameters
Parameter Description
field-name Name
Type: A string that contains [a-z], [A-Z], [0-9], '_'
field-value Value
Type: A string that contains [a-z], [A-Z], [0-9], '_', '.', ',', '-', '/', '@', '+', ',', ':', '='
is-any-device Does paramter apply to all devices
Type: Boolean (true/false)
product-id Product ID
Type: A hexadecimal string
vendor-id Vendor ID
Type: A hexadecimal string
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1198
delete usb-modem-advanced
delete usb-modem-advanced
Description
Delete an existing USB modem advanced entry.
Syntax
Parameters
Parameter Description
id id
Type: A number with no fractional part (integer)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1199
delete usb-modem-advanced-all
delete usb-modem-advanced-all
Description
Delete all existing USB modem advanced entries.
Syntax
delete usb-modem-advanced-all
Parameters
Parameter Description
n/a
Example
delete usb-modem-advanced-all
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1200
set usb-modem-advanced
set usb-modem-advanced
Description
Configure a USB modem advanced entry.
Syntax
Parameters
Parameter Description
field-name Name
Type: A string that contains [a-z], [A-Z], [0-9], '_'
field-value Value
Type: A string that contains [a-z], [A-Z], [0-9], '_', '.', ',', '-', '/', '@', '+', ',', ':', '='
id id
Type: A number with no fractional part (integer)
is-any-device Does parameter apply to all devices
Type: Boolean (true/false)
product-id Product ID
Type: A hexadecimal string
vendor-id Vendor ID
Type: A hexa decimal string
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1201
show usb-modem-advanced
show usb-modem-advanced
Description
Show existing USB modem advanced entries.
Syntax
show usb-modem-advanced
Parameters
Parameter Description
n/a
Example
show usb-modem-advanced
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1202
show usb-modem-advanced table
show usb-modem-advanced table
Description
Show the existing USB modem advanced entries in a table.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1203
usb-modem-info
usb-modem-info
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1204
show usb-modem-info
show usb-modem-info
Description
Show existing USB modem information.
Syntax
show usb-modem-info
Parameters
Parameter Description
n/a
Example
show usb-modem-info
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1205
show usb-modem-info-table
show usb-modem-info-table
Description
Show existing USB modem information in a table.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1206
usb-modem-watchdog
usb-modem-watchdog
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1207
set usb-modem-watchdog
set usb-modem-watchdog
Configures the internet probing (if probing is enabled) to automatically detect and fix 3G/4G internet
connectivity problems.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1208
set usb-modem-watchdog
set usb-modem-watchdog
Description
Configures the internet probing (if probing is enabled) to automatically detect and fix 3G/4G internet
connectivity problems.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1209
set usb-modem-watchdog
set usb-modem-watchdog
Description
Configures the internet probing (if probing is enabled) to automatically detect and fix 3G/4G internet
connectivity problems.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1210
show usb-modem-watchdog
show usb-modem-watchdog
Description
Shows configuration for additional health monitoring functionality to USB modems.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1211
set used-ad-group
set used-ad-group
Configures settings of a user group defined in the AD server.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1212
set used-ad-group
set used-ad-group
Description
Adds a bookmark to be shown in the SNX landing page to user group defined in the AD server. This is
relevant only if the user group is defined with VPN remote access privileges.
Syntax
Parameters
Parameter Description
bookmark label Text for the bookmark in the SSL Network Extender portal
name Group name
Type: Active Directory group name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1213
set used-ad-group
set used-ad-group
Description
Removes a bookmark from being shown in the SNX landing page to user group defined in the AD server.
This is relevant only if the user group is defined with VPN remote access privileges.
Syntax
Parameters
Parameter Description
bookmark label Text for the bookmark in the SSL Network Extender portal
name Group name
Type: Active Directory group name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1214
user-awareness
user-awareness
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1215
set user-awareness
set user-awareness
Configures settings for the User Awareness blade.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1216
set user-awareness
set user-awareness
Description
Configures the activation mode and user identification methods for the User Awareness blade.
Syntax
Parameters
Parameter Description
ad-queries-mode Indicates if User Awareness seamlessly queries the AD (Active Directory)
servers to get user information
Type: Boolean (true/false)
browser-based- Indicates if User Awareness uses a portal to identify locally defined users or
authentication- mode as a backup to other identification methods
Type: Boolean (true/false)
mode User Awareness mode - true for on, false for off
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1217
set user-awareness
set user-awareness
Description
Configures advanced settings for the User Awareness blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1218
set user-awareness
set user-awareness
Description
Configures advanced settings for the User Awareness blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1219
set user-awareness browser-based-authentication
set user-awareness browser-based-
authentication
Configures settings for browser-based authentication (captive portal) by the User Awareness blade.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1220
set user-awareness browser-based-authentication
set user-awareness browser-based-authentication
Description
Configures settings for browser-based authentication (captive portal) by the User Awareness blade.
Syntax
Parameters
Parameter Description
agreement-text The conditions shown to the users to agree to
Type: A string that contains only printable characters
block-unauthenticated- When true, users using non-HTTP traffic are forced to login first through
non-web-traffic Browser-Based Authentication
Type: Boolean (true/false)
log-out-on-portal-close When true, the user is forced to keep the portal window open to remain logged
in
Type: Boolean (true/false)
portal-address Use the auto option unless you want to redirect to a manually configured URL
Type: String
Enter "<auto>" for default
redirect-upon- When choosing redirect to manually defined destinations - indicates if the
destination-internet destinations include the internet (external interfaces)
Type: Boolean (true/false)
redirect-upon- Browser based authentication will only be shown to unidentified users on traffic
destinations to these configured destinations
Type: Press TAB to see available options
redirect-upon- When choosing redirect to manually defined destinations - indicates if the
destinations-net-objs destinations include a manual list of network objects
Type: Boolean (true/false)
require-user- Indicates if users must agree to the legal conditions
agreement Type: Boolean (true/false)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1221
set user-awareness browser-based-authentication
Parameter Description
session-timeout Session timeout duration, in minutes, for browser-based authentication
Type: A number with no fractional part (integer) Units should be entered in
minutes
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1222
set user-awareness browser-based-authentication
set user-awareness browser-based-authentication
Description
Configures network objects to be used in the User Awareness blade.
Syntax
Parameters
Parameter Description
net-obj Network object name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1223
set user-awareness browser-based-authentication
set user-awareness browser-based-authentication
Description
Configures network objects to be used in the User Awareness blade.
Syntax
Parameters
Parameter Description
net-obj Network object name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1224
set user-awareness browser-based-authentication
set user-awareness browser-based-authentication
Description
Configures network objects to be used in the User Awareness blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1225
show user-awareness
show user-awareness
Shows the configuration of the User Awareness blade.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1226
show user-awareness
show user-awareness
Description
Shows the configuration of the User Awareness blade.
Syntax
show user-awareness
Parameters
Parameter Description
n/a
Example
show user-awareness
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1227
show user-awareness
show user-awareness
Description
Shows advanced settings of the User Awareness blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1228
show user-awareness browser-based-authentication
show user-awareness browser-based-authentication
Description
Shows the browser-based authentication configuration of the User Awareness blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1229
set user-management
set user-management
Description
Configures advanced settings for the User Awareness blade.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1230
show upgrade log
show upgrade log
Description
Shows upgrade log files.
Syntax
show upgrade-log
Parameters
Parameter Description
n/a
Example
show upgrade-log
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1231
show used-ad-group bookmarks
show used-ad-group bookmarks
Description
Show bookmarks configured to a user group defined in AD.
Syntax
Parameters
Parameter Description
name Group name
Type: Active Directory group name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1232
upgrade from usb or tftp server
upgrade from usb or tftp server
Description
Upgrades the software image from a file on a USB drive or TFTP server.
Syntax
Parameters
Parameter Description
usb_file Name of software image file on USB drive.
server Host name or IP address of TFTP server.
tftp_file Name of software image file on TFTP server.
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1233
vpn
vpn
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1234
vpn
vpn
The vpncommand manages the VPN driver and helps to debug the VPN.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1235
Managing the VPN Driver
Managing the VPN Driver
Description
Installs the VPN kernel (vpnk) and connects to the firewall kernel (fwk), attaching the VPN driver to the
Firewall driver.
Syntax
Parameters
Parameter Description
on|off Starts or stops the VPN kernel
Return Value
0 on success, 1 on failure
Example
vpn drv on
Output
Success shows OK. Failure shows an appropriate error message.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1236
Launching TunnelUtil Tool
Launching TunnelUtil Tool
Description
Launches the VPN TunnelUtil tool to:
n List IKE and IPSec SAs
n Delete IKE and IPSec SAs
Syntax
vpn tunnelutil
Parameters
Parameter Description
n/a
Return Value
0 on success, 1 on failure
Example
vpn tunnelutil
Output
Success launches VPN TunnelUtil tool. Failure shows an appropriate error message.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1237
Debugging VPN
Debugging VPN
Description
Contains multiple utilities for troubleshooting VPN issues.
Syntax
Parameters
Parameter Description
on|off Writes debugging information t
$FWDIR/log/sfwd.elg
[TOPIC=level] Sets level of debugging for a particular topic.
This argument can only be used afte
on
o
trunc
.
ikeon|ikeoff Writes IKE packet information int
$FWDIR/log/ike.elg
trunc Writes bot
sfwd.elg
an
ike.elg
, but first clears the files
mon|moff Writes raw IKE packets t
$FWDIR/log/ikemonitor.snoop
Return Value
0
on success,
1
on failure
Example
vpn debug on
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1238
delete vpn
delete vpn
Description
Delete a configured Virtual Tunnel Interface (VTI) by tunnel ID.
Syntax
Parameters
Parameter Description
tunnel A number identifying the Virtual Tunnel Interface (VTI)
Type: A number with no fractional part (integer)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1239
set vpn
set vpn
Configures existing remote VPN sites.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1240
set vpn
set vpn
Description
Configures existing remote VPN sites.
Syntax
Parameters
Parameter Description
aggressive- Determine the strength of the key when aggressive mode is enabled
mode-DH-group
aggressive- Indicates if gateway ID matching will be used. This adds a layer of security to
mode- enable- aggressive mode
gateway-id Type: Boolean (true/false)
aggressive- Indicates if peer ID matching will be used. This adds a layer of security to aggressive
mode- enable- mode
peer-id Type: Boolean (true/false)
aggressive- Indicates if Aggressive mode, a less secure negotiation protocol compared to main
mode-enabled mode, is used. It is less recommended if the remote site supports IPSec main mode
Type: Boolean (true/false)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1241
set vpn
Parameter Description
aggressive- The gateway ID that will be used for matching when configured to
mode-gateway-id Type: vpnAggressiveModePeerId
aggressive- Indicates the type of gateway ID that will be used for matching when configured
mode- gateway- Options: domain-name, user-name
id-type
aggressive- The peer ID that will be used for matching when configured to
mode-peer-id Type: vpnAggressiveModePeerId
aggressive- Indicates the type of peer ID that will be used for matching when configured
mode-peer-id- Options: domain-name, user-name
type
auth-method Indicates the type of authentication used when connecting to the remote site
Type: Press TAB to see available options
disable-nat Disable NAT for traffic to/from the remote site. Useful when one of the internal
networks contains a server Type: Boolean (true/false)
enable-perfect- Ensures that a session key will not be compromised if one of the (long-term)
forward-secrecy private keys is compromised in the future. Type: Boolean (true/false)
enable- VPN Tunnels are constantly kept active and as a result, make it easier to recognize
permanent-vpn- malfunctions and connectivity problems
tunnel Type: Boolean (true/false)
enabled Indicates whether or not the remote site is enabled
Type: Boolean (true/false)
enc-method Indicates which encryption method is used
Options: ike-v1, ike-v2, prefer-ike-v2
enc-profile Encryption profile (one of predefined profiles or custom)
Type: virtual
is-check-point- Enable if the remote site is connected through a Check Point Security Gateway
site Type: Boolean (true/false)
is-site-behind- When connection type is IP address, this indicates if it is behind static NAT
static-nat
link-selection- Specifies The primary IP address for the link selection
primary-addr Type: A string of alphanumeric characters without space between them
link-selection- The type of probing used for link selection when multiple IP addresses are
probing-method configured for the remote site
Options: ongoing, one-time
match-cert-dn Indicates if certificate matching should match the DN string in the certificate to the
configured DN string Type: Boolean (true/false)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1242
set vpn
Parameter Description
match-cert-dn- Indicates the configured DN string for certificate matching
string Type: String
match-cert-e-mail Indicates if certificate matching should match the E-mail string in the certificate to
the configured E-mail string
Type: Boolean (true/false)
match-cert-e- Indicates the configured E-mail string for certificate matching
mail-string Type: Email address
match-cert-ip Indicates if certificate matching should match IP address in the certificate to the
site's IP address
Type: Boolean (true/false)
name Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z,
_ -) characters without spaces
password Preshared secret (minimum 6 characters) to be used when authentication method is
configured as such
Type: vpnPassword
phase1-reneg- The period, in minutes, between each IKE SA renegotiation
interval Type: A number with no fractional part (integer)
phase2-dh Determine the strength of the key used for the IPsec (Phase 2) key exchange
process. The higher the group number, the stronger and more secure the key is.
phase2-reneg- The period, in seconds, between each IPSec SA renegotiation
interval Type: A number with no fractional part (integer)
remote-site-enc- The method of defining the remote site's encryption domain
dom-type Options: manually-defined-enc-dom, route-all-traffic-to-site, route-based-vpn, enc-
dom-hidden-behind-remote-site
remote-site-host- Indicates the remote site's host name when the link selection method is configured
name as such
remote-site-ip- Indicates the remote site's single IP address when the link selection method is
address configured as such
remote-site-link- Indicates the method of determining the destination IP address/s of the remote site
selection Options: ip-address, host-name, high-availability, load-sharing, connection-
initiated-only-from-remote-site
site Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z,
_ -) characters without spaces
static-nat-ip Indicates an external routable IP address via static NAT used by the remote site,
when configured as such
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1243
set vpn
Parameter Description
use-trusted-ca Indicates if a specific trusted CA is used for matching the remote site's certificate or
all configured trusted CAs
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1244
set vpn
set vpn
Description
Adds network objects to the encryption domain of existing remote VPN sites.
Syntax
Parameters
Parameter Description
remote-site- Network Object name
enc-dom-
network-obj
site Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z, _
-) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1245
set vpn
set vpn
Description
Removes all network objects from the encyryption domain of existing remote VPN sites.
Syntax
<remote-site-enc-dom-network-obj>
Parameters
Parameter Description
remote-site- Network Object name
enc-dom-
network-obj
site Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z, _
-) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1246
set vpn
set vpn
Description
Removes network objects from the encryption domain of existing remote VPN sites.
Syntax
Parameters
Parameter Description
remote-site- Network Object name
enc-dom-
network-obj
site Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z, _
-) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1247
set vpn
set vpn
Description
Adds IP addresses to an existing remote VPN site. This allows High Availability or Load Sharing between
the remote links using the link selection functionality.
Syntax
Parameters
Parameter Description
link-selection- IP address
multiple-
addrs addr
site Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z, _
-) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1248
set vpn
set vpn
Description
Removes all IP addresses from an existing remote VPN site configured with multiple links.
Syntax
Parameters
Parameter Description
link-selection- IP address
multiple-
addrs addr
site Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z, _
-) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1249
set vpn
set vpn
Description
Removes IP addresses from an existing remote VPN site. This allows High Availability or Load Sharing
between the remote links using the link selection functionality.
Syntax
Parameters
Parameter Description
link-selection- IP address
multiple-
addrs addr
site Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z, _
-) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1250
set vpn
set vpn
Description
Adds a phase 1 encryption algorithm to an existing remote VPN site configured with a custom encryption
suite.
Syntax
Parameters
Parameter Description
custom-enc- Encryption algorithm preferences for phase1 in the VPN encryption algorithm, which
phase1-enc sets the base for phase2
site Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z,
_ -) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1251
set vpn
set vpn
Description
Removes all phase 1 encryption algorithm from an existing remote VPN site configured with a custom
encryption suite.
Syntax
Parameters
Parameter Description
custom-enc- Encryption algorithm preferences for phase1 in the VPN encryption algorithm, which
phase1-enc sets the base for phase2
site Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z,
_ -) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1252
set vpn
set vpn
Description
Removes a phase 1 encryption algorithm from an existing remote VPN site configured with a custom
encryption suite
Syntax
Parameters
Parameter Description
custom-enc- Encryption algorithm preferences for phase1 in the VPN encryption algorithm, which
phase1-enc sets the base for phase2
site Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z,
_ -) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1253
set vpn
set vpn
Description
Adds a phase 1 authentication algorithm to an existing remote VPN site configured with a custom encryption
suite.
Syntax
Parameters
Parameter Description
custom-enc- Authentication algorithm used for encryption validation
phase1-auth
site Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z,
_ -) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1254
set vpn
set vpn
Description
Removes all phase 1 authentication algorithms from an existing remote VPN site configured with a custom
encryption suite.
Syntax
Parameters
Parameter Description
custom-enc- Authentication algorithm used for encryption validation
phase1-auth
site Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z,
_ -) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1255
set vpn
set vpn
Description
Removes a phase 1 authentication algorithm from an existing remote VPN site configured with a custom
encryption suite.
Syntax
Parameters
Parameter Description
custom-enc- Authentication algorithm used for encryption validation
phase1-auth
site Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z,
_ -) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1256
set vpn
set vpn
Description
Adds a Diffie-Hellman group to an existing remote VPN site configured with a custom encryption suite.
Syntax
Parameters
Parameter Description
custom-enc- VPN Diffie-Hellman key exchange encryption level
phase1-dh-group
site Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9,
a-z, _ -) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1257
set vpn
set vpn
Description
Removes all Diffie-Hellman groups from an existing remote VPN site configured with a custom encryption
suite.
Syntax
Parameters
Parameter Description
custom-enc- VPN Diffie-Hellman key exchange encryption level
phase1-dh-group
site Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9,
a-z, _ -) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1258
set vpn
set vpn
Description
Removes an Diffie-Hellman group from an existing remote VPN site configured with a custom encryption
suite.
Syntax
Parameters
Parameter Description
custom-enc- VPN Diffie-Hellman key exchange encryption level
phase1-dh-group
site Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9,
a-z, _ -) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1259
set vpn
set vpn
Description
Adds a phase 2 encryption algorithm to an existing remote VPN site configured with a custom encryption
suite.
Syntax
Parameters
Parameter Description
custom-enc- Encryption algorithm preferences for phase2 in the VPN encryption algorithm
phase2-enc
site Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z,
_ -) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1260
set vpn
set vpn
Description
Removes all phase 2 encryption algorithms from an existing remote VPN site configured with a custom
encryption suite.
Syntax
Parameters
Parameter Description
custom-enc- Encryption algorithm preferences for phase2 in the VPN encryption algorithm
phase2-enc
site Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z,
_ -) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1261
set vpn
set vpn
Description
Removes a phase 2 encryption algorithm from an existing remote VPN site configured with a custom
encryption suite.
Syntax
Parameters
Parameter Description
custom-enc- Encryption algorithm preferences for phase2 in the VPN encryption algorithm
phase2-enc
site Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z,
_ -) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1262
set vpn
set vpn
Description
Adds a phase 2 authentication algorithm to an existing remote VPN site configured with a custom encryption
suite.
Syntax
Parameters
Parameter Description
custom-enc- Authentication algorithm used for encryption validation
phase2-auth
site Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z,
_ -) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1263
set vpn
set vpn
Description
Removes all phase 2 authentication algorithms from an existing remote VPN site configured with a custom
encryption suite.
Syntax
Parameters
Parameter Description
custom-enc- Authentication algorithm used for encryption validation
phase2-auth
site Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z,
_ -) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1264
set vpn
set vpn
Description
Removes a phase 2 authentication algorithm from an existing remote VPN site configured with a custom
encryption suite.
Syntax
Parameters
Parameter Description
custom-enc- Authentication algorithm used for encryption validation
phase2-auth
site Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z,
_ -) characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1265
set vpn
set vpn
Description
Configures an existing Virtual Tunnel Interface (VTI) for route based VPN.
Syntax
Parameters
Parameter Description
internet- The local interface for unnumbered VTI
connection
local Enter the IP address of the interface
Type: IP address
peer Remote peer name as defined in the VPN community. You must define the two peers in
the VPN community before you can define the VTI. The Peer ID is an alpha-numeric
character string.
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z, _ -)
characters without spaces
remote Defines the remote peer IPv4 address, used at the peer gateway's point-to-point virtual
interface (numbered VTI only)
Type: IP address
tunnel A number identifying the Virtual Tunnel Interface (VTI)
Type: A number with no fractional part (integer)
type The type of VTI: Numbered VTI that uses a specified, static IPv4 addresses for local and
remote connections, or unnumbered VTI that uses the interface and the remote peer
name to get addresses
Type: Press TAB to see available options
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1266
show vpn
show vpn
Shows VPN site to site configuration.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1267
show vpn
show vpn
Description
Shows the configuration of a remote VPN site.
Syntax
Parameters
Parameter Description
site Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z, _ -)
characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1268
show vpn
show vpn
Description
Shows the configuration of a Virtual Tunnel Interface (VTI) used for route-based VPN.
Syntax
Parameters
Parameter Description
tunnel A number identifying the Virtual Tunnel Interface (VTI)
Type: A number with no fractional part (integer)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1269
vpn remote-access
vpn remote-access
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1270
set vpn remote-access
set vpn remote-access
Configures settings for VPN remote access (Client to server VPN).
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1271
set vpn remote-access
set vpn remote-access
Description
Configures settings for VPN remote access.
Syntax
Parameters
Parameter Description
default-access-to- Allow traffic from Remote Access clients (by default)
lan Options: block, accept
l2tp-pre-shared-key L2TP Pre-Shared Key
Type: A string of alphanumeric characters without space between them
l2tp-vpn-client Enable VPN remote access clients to connect via native VPN client (L2TP)
Type: Boolean (true/false)
mobile-client Enable VPN remote access mobile clients to connect via Check Point Mobile VPN
client
Type: Boolean (true/false)
mode Enable VPN Remote Access
Type: Boolean (true/false)
sslvpn-client Enable VPN remote access clients to connect via SSL VPN
Type: Boolean (true/false)
track Log traffic from Remote Access clients (by default)
Options: none, log
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1272
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1273
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1274
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1275
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1276
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1277
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1278
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1279
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1280
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1281
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1282
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1283
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1284
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1285
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1286
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1287
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1288
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1289
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1290
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1291
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1292
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1293
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1294
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1295
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1296
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1297
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1298
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1299
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1300
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1301
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1302
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1303
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1304
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1305
set vpn remote-access
set vpn remote-access
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
set vpn remote-access
Description
Enable/Disable two-factor authentication for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1306
set vpn remote-access
set vpn remote-access
Description
Enable/Disable two-factor authentication for VPN remote access.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1307
show vpn remote-access
show vpn remote-access
Shows configuration of remote access VPN.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1308
show vpn remote-access
show vpn remote-access
Description
Shows configuration of remote access VPN.
Syntax
Parameters
Parameter Description
n/a
Example
Output
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1309
show vpn remote-access
show vpn remote-access
Description
Shows advanced settings of remote access VPN.
Syntax
Parameters
Parameter Description
n/a
Example
show vpn remote-access
Description
Shows configuration of remote access VPN.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1310
show vpn remote-access
Output
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1311
show vpn remote-access
show vpn remote-access
Description
Shows configuration of remote access VPN.
Syntax
Parameters
Parameter Description
n/a
Example
Output
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1312
set vpn remote-access advanced
set vpn remote-access advanced
Description
Configures advanced settings for VPN remote access.
Syntax
Parameters
Parameter Description
default-route- Indicates if Internet traffic from connected clients will be routed first through this
through- this- gateway
gateway Type: Boolean (true/false)
dns-domain-mode Indicates if remote access clients use the domain name configured under DNS
network settings of the device, or a manually configured domain name
Type: Boolean (true/false)
dns-primary Configure manually office mode first DNS
Type: IP address
dns-secondary Configure manually office mode second DNS
Type: IP address
dns-tertiary Configure manually office mode third DNS
Type: IP address
domain-name Manual configuration of the domain used by remote access clients
Type: A FQDN
enc-dom Indicates if the encryption domain for remote access clients is calculated
automatically or manually configured
Options: manual, auto
om-network-ip Office Mode - Allocate IP addresses from the following network
Type: Network address
om-subnet-mask Subnet for allocating IP addresses of incoming remote access connections (Office
Mode)
Type: Subnet mask
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1313
set vpn remote-access advanced
Parameter Description
use-this-gateway- Indicates if the remote access clients will use this gateway as a DNS server.
as- dns-server Applicable only when encryption domain is calculated automatically
Type: Boolean (true/false)
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1314
show vpn remote-access advanced
show vpn remote-access advanced
Description
Shows advanced settings of remote access VPN.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1315
set vpn remote-access advanced enc-dom-obj manual
set vpn remote-access advanced enc-dom-obj
manual
Configures manual encryption domain for VPN remote access users.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1316
set vpn remote-access advanced enc-dom-obj manual
set vpn remote-access advanced enc-dom-obj manual
Description
Adds a network object to the manual encryption domain of VPN remote access.
Syntax
Parameters
Parameter Description
name Network Object name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1317
set vpn remote-access advanced enc-dom-obj manual
set vpn remote-access advanced enc-dom-obj manual
Description
Removes a network object from the manual encryption domain of VPN remote access.
Syntax
Parameters
Parameter Description
name Network Object name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1318
set vpn remote-access advanced enc-dom-obj manual
vpn remote-access two-factor-
authentication
set vpn remote-access two-factor-
authentication
Description
Configure two-factor authentication for VPN Remote Access.
Syntax
Parameters
Parameter Description
default-country- The default country code for phone numbers that do not include a country code.
code Type: A number with no fractional part (integer).
one-time- The amount of time users have to enter the one time password before it expires
password- (in minutes).
expiration Type: A number with no fractional part (integer)
one-time- Number of characters used in the one time password.
password-length Type: A number with no fractional part (integer).
one-time- The number of times users can attempt to enter the one time password before the
password-retries entire authentication process restarts.
Type: A number with no fractional part (integer)
sms-api-id The API ID required by the SMS provider.
Type: A string of alphanumeric characters without space between them.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1319
set vpn remote-access advanced enc-dom-obj manual
Parameter Description
sms-dynamicid-url The DynamicID URL when sending SMS message using a user defined SMS
provider.
Type: urlDynamicId
sms-message The SMS message that will be sent to the user.
Type: String
sms-provider Indicates which provider will send the SMS messages.
Options: check-point, external
sms-provider- The password required by the SMS provider.
password Type: extendedPassword
sms-provider- The username required by the SMS provider
username Type: A string that contains (0-9, a-z, - . @) up to 64 characters without spaces.
use-email Indicates whether sending email messages is enabled Type: Boolean (true/false)
use-sms Indicates whether sending SMS messages is enabled.
Type: Boolean (true/false)
Example
show vpn remote-access two-factor-
authentication
Description
Show two-factor authentication for VPN Remote Access settings.
Syntax
Parameters
Parameter Description
n/a
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1320
set vpn remote-access advanced enc-dom-obj manual
Example
Output
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1321
vpn site
vpn site
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1322
add vpn site
add vpn site
Description
Adds a new remote VPN site for VPN site-to-site.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1323
add vpn site
Syntax
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1324
add vpn site
Parameters
Parameter Description
aggressive-mode- determine the strength of the key when aggressive mode is enabled
DH-group
aggressive-mode- Indicates if gateway ID matching will be used. This adds a layer of security to
enable-gateway-id aggressive mode
Type: Boolean (true/false)
aggressive-mode- Indicates if peer ID matching will be used. This adds a layer of security to
enable-peer-id aggressive mode
Type: Boolean (true/false)
aggressive-mode- main mode, is used. It is less recommended if the remote site supports IPSec main
enabled mode
Type: Boolean (true/false)
aggressive-mode- The gateway ID that will be used for matching when configured to
gateway-id Type: vpnAggressiveModePeerId
aggressive-mode- Indicates the type of gateway ID that will be used for matching when configured
gateway-id-type Options: domain-name, user-name
aggressive-mode- The peer ID that will be used for matching when configured to
peer-id Type: vpnAggressiveModePeerId
aggressive-mode- Indicates the type of peer ID that will be used for matching when configured
peer-id-type Options: domain-name, user-name
auth-method Indicates the type of authentication used when connecting to the remote site
Type: Press TAB to see available options
disable-nat Disable NAT for traffic to/from the remote site. Useful when one of the internal
networks contains a server
Type: Boolean (true/false)
enable-perfect- Ensures that a session key will not be compromised if one of the (long-term)
forward-secrecy private keys is compromised in the future.
Type: Boolean (true/false)
enable- VPN Tunnels are constantly kept active and as a result, make it easier to recognize
permanent- vpn- malfunctions and connectivity problems Type: Boolean (true/false)
tunnel
enabled Indicates whether or not the remote site is enabled
Type: Boolean (true/false)
enc-method Indicates which encryption method is used
Options: ike-v1, ike-v2, prefer-ike-v2
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1326
add vpn site
Parameter Description
enc-profile Encryption profile (one of predefined profiles or custom)
Type: virtual
is-check-point-site Enable if the remote site is connected through a Check Point Security Gateway
Type: Boolean (true/false)
is-site-behind- Indicates if the remote site is behind static NAT
static- nat Type: Boolean (true/false)
link-selection- IP address
multiple-addrs
addr
link-selection- The type of probing used for link selection when multiple IP addresses are
probing- method configured for the remote site
Options: ongoing, one-time
match-cert-dn Indicates if certificate matching should match the DN string in the certificate to the
configured DN string
Type: Boolean (true/false)
match-cert-dn- Indicates the configured DN string for certificate matching
string Type: String
match-cert-e-mail Indicates if certificate matching should match the E-mail string in the certificate to
the configured E-mail string
Type: Boolean (true/false)
match-cert-e-mail- Indicates the configured E-mail string for certificate matching
string Type: Email address
match-cert-ip Indicates if certificate matching should match IP address in the certificate to the
site's IP address
Type: Boolean (true/false)
name Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-
z, _ -) characters without spaces
password Preshared secret (minimum 6 characters) to be used when authentication method
is configured as such
Type: vpnPassword
phase1-reneg- The period, in minutes, between each IKE SA renegotiation
interval Type: A number with no fractional part (integer)
phase2-dh Determine the strength of the key used for the IPsec (Phase 2) key exchange
process. The higher the group number, the stronger and more secure the key is.
phase2-reneg- The period, in seconds, between each IPSec SA renegotiation
interval Type: A number with no fractional part (integer)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1327
add vpn site
Parameter Description
remote-site-enc- The method of defining the remote site's encryption domain
dom- type Options: manually-defined-enc-dom, route-all-traffic-to-site, route-based-vpn, enc-
dom-hidden-behind-remote-site
remote-site-host- Indicates the host name of the remote site
name Type: An IP address or host name
remote-site-ip- Indicates the IP address of the remote site
address Type: IP address
remote-site-link- Indicates the method of determining the destination IP address/s of the remote site
selection Type: Press TAB to see available options
static-nat-ip Indicates an external routable IP address via static NAT used by the remote site
Type: IP address
use-trusted-ca Indicates if a specific trusted CA is used for matching the remote site's certificate or
all configured trusted CAs
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1328
add vpn site
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1329
delete vpn site
delete vpn site
Delete VPN sites.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1330
delete vpn site
delete vpn site
Description
Delete an existing VPN site by name.
Syntax
Parameters
Parameter Description
name Site name
Type: A string that begins with a letter and contains up to 32 alphanumeric (0-9, a-z, _ -)
characters without spaces
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1331
delete vpn site
delete vpn site
Description
Delete all existing VPN sites.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1332
show vpn sites
show vpn sites
Description
Show all configured remote VPN sites.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1333
vpn site-to-site
vpn site-to-site
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1334
set vpn site-to-site
set vpn site-to-site
Configure global settings for VPN site to site.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1335
set vpn site-to-site
set vpn site-to-site
Description
Configure global settings for VPN site to site.
Syntax
Parameters
Parameter Description
default-access-to- Allow traffic from remote sites (by default)?A? ?I
lan Options: block, accept
local-encryption- Indicates if the local encryption domain is configured manually or determined
domain automatically using the local networks
Options: auto, manual
manual-source-ip- A manually configured source IP address to be used (if configured to) for VPN
address tunnels
Type: IP address
mode Indicates whether or not VPN site to site is active
Type: Boolean (true/false)
outgoing- Indicates the method according to which the outgoing interface selection for VPN
interface-selection traffic is chosen
Options: routing-table, route-based-probing
source-ip- Select whether the source IP address is chosen automatically according to the
address-selection outgoing interface or manually configured
Options: automatically, manually
track The default Logging setting for traffic from remote sites
Options: none, log
tunnel-health- VPN tunnel monitor mechanism, can work with permanent tunnel or with DPD
monitor-mode mode
Options: tunnel-test, dpd
use-dpd- Once checked DPD responder mode will be enabled, otherwise permanent tunnel
responder-mode based on DPD mode will be enabled
Type: Boolean (true/false)
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1336
set vpn site-to-site
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1337
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1338
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1339
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1340
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1341
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1342
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1343
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1344
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1345
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1346
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1347
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1348
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1349
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1350
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1351
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1352
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1353
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1354
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1355
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1356
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1357
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1358
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1359
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1360
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1361
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1362
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1363
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1364
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1365
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1366
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1367
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1368
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1369
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1370
set vpn site-to-site
set vpn site-to-site
Description
Configure advanced settings for VPN site to site.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1371
shows vpn site-to-site
shows vpn site-to-site
Shows configuration of site-to-site VPN.
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1372
show vpn site-to-site
show vpn site-to-site
Description
Shows configuration of site-to-site VPN.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1373
shows vpn site-to-site
shows vpn site-to-site
Description
Shows advanced settings of site-to-site VPN.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1374
set vpn site-to-site enc-dom manual
set vpn site-to-site enc-dom manual
Configures manually the local encryption domain for site-to-site VPN
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1375
set vpn site-to-site enc-dom manual
set vpn site-to-site enc-dom manual
Description
Adds a network object to the local encryption domain for site-to-site VPN.
Syntax
Parameters
Parameter Description
name Network Object name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1376
set vpn site-to-site enc-dom manual
set vpn site-to-site enc-dom manual
Description
Removes all network objects from the local encryption domain for site-to-site VPN.
Syntax
Parameters
Parameter Description
name Network Object name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1377
set vpn site-to-site enc-dom manual
set vpn site-to-site enc-dom manual
Description
Removes a network object from the local encryption domain for site-to-site VPN.
Syntax
Parameters
Parameter Description
name Network Object name
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1378
vpn tunnel
vpn tunnel
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1379
show vpn tunnel
show vpn tunnel
Description
Shows all IKE (Internet Key Exchange) and IPSec (Internet Protocol Security) SAs (Security Associations)
for the VPN tunnel.
Syntax
show vpn-tunnel-info
Parameters
Parameter Description
n/a
Example
show vpn-tunnel-info
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1380
show vpn tunnels
show vpn tunnels
Description
Shows all Virtual Tunnel Interfaces (VTIs).
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1381
wlan
wlan
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1382
delete wlan
delete wlan
Description
Delete an existing wireless Virtual Access Point (VAP) by SSID.
Syntax
Parameters
Parameter Description
vap The name of the Virtual Access Point
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1383
set wlan
set wlan
Configures a virtual access point (VAP) wireless network in appliance models that contain wireless options).
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1384
set wlan
set wlan
Description
Turn on/off the first wireless network (VAP) that was created.
Syntax
Parameters
Parameter Description
mode The mode of the Virtual Access Point
Options: on, off
Example
set wlan on
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1385
set wlan
set wlan
Description
Configures the SSID of the first wireless network that was created.
Syntax
Parameters
Parameter Description
ssid Wireless network name (SSID)
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and space characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1386
set wlan
set wlan
Description
Configures the first wireless network that was created.
Syntax
Parameters
Parameter Description
security-type Security Type
Options: none, WEP, WPA2, WPA/WPA2
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1387
set wlan
set wlan
Description
Configures the first wireless network that was created.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1388
set wlan
set wlan
Description
Configures the first wireless network that was created.
Syntax
Parameters
Parameter Description
hotspot The Hotspot of the Virtual Access Point
Options: on, off
wpa-auth-type Wireless protected access authentication
Type: Press TAB to see available options
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1389
set wlan
set wlan
Description
Configures the first wireless network that was created.
Syntax
Parameters
Parameter Description
wpa-encryption-type Wireless protected access encryption type
Options: Auto, CCMP-AES, TKIP
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1390
set wlan
set wlan
Description
Configures the first wireless network that was created.
Syntax
Parameters
Parameter Description
assignment The network assigned to the virtual access point
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1391
set wlan
set wlan
Description
Enable/Disable an existing wireless network (VAP).
Syntax
Parameters
Parameter Description
mode The mode of the Virtual Access Point
Options: on, off
vap The name of the Virtual Access Point
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1392
set wlan
set wlan
Description
Configures the SSID of an existing wireless network (VAP).
Syntax
Parameters
Parameter Description
ssid Wireless network name (SSID)
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and space characters
vap The name of the Virtual Access Point
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1393
set wlan
set wlan
Description
Configures an existing wireless network (VAP).
Syntax
Parameters
Parameter Description
security-type Security Type
Options: none, WEP, WPA2, WPA/WPA2
vap The name of the Virtual Access Point
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1394
set wlan
set wlan
Description
Configures an existing wireless network (VAP).
Syntax
set wlan vap <vap> wpa-auth-type password <password> [ hotspot <hotspot > ]
Parameters
Parameter Description
vap The name of the Virtual Access Point
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1395
set wlan
set wlan
Description
Configures an existing wireless network (VAP).
Syntax
Parameters
Parameter Description
hotspot The Hotspot of the Virtual Access Point
Options: on, off
vap The name of the Virtual Access Point
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
wpa-auth-type Wireless protected access authentication
Type: Press TAB to see available options
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1396
set wlan
set wlan
Description
Configures an existing wireless network (VAP).
Syntax
Parameters
Parameter Description
vap The name of the Virtual Access Point
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
wpa-encryption-type Wireless protected access encryption type
Options: Auto, CCMP-AES, TKIP
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1397
set wlan
set wlan
Description
Configures an existing wireless network (VAP).
Syntax
Parameters
Parameter Description
assignment The network assigned to the virtual access point
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
vap The name of the Virtual Access Point
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1398
set wlan
set wlan
Description
Configures an existing wireless network (VAP).
Syntax
Parameters
Parameter Description
vap The name of the Virtual Access Point
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1399
set wlan wireless advanced-settings protected-mgmt-frames
set wlan wireless advanced-settings protected-
mgmt-frames
Description
Enable or disable protection of 802.11 management frames (refers to the main wireless access point).
Syntax
Parameters
Parameter Description
main-wireless-name Name of the main wireless access point
Type Press TAB to see available options
on/off on - Enabled
off - Disabled
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1400
show wlan
show wlan
Shows configuration for wireless networks (relevant to hardware models with wireless).
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1401
show wlan
show wlan
Description
Shows configuration for a virtual access point (VAP or wireless network).
Syntax
Parameters
Parameter Description
vap The name of the Virtual Access Point
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and '/' characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1402
show wlan
show wlan
Description
Shows configuration of the wireless radio.
Syntax
text
show wlan
Parameters
Parameter Description
n/a
Example
show wlan
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1403
wlan radio
wlan radio
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1404
set wlan radio
set wlan radio
Configures the radio settings of wireless antennas (in appliance models that contain wireless options).
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1405
set wlan radio
set wlan radio
Description
Configures the radio settings of wireless antennas.
Syntax
Parameters
Parameter Description
channel Channel
Options: channel
channel-width Channel width
Options: auto, 20, 40, 80
country Country
Options: country
operation-mode Operation mode
Options: 11b, 11g, 11bg, 11n, 11ng, 11ac, 11nac
Example
set wlan radio country albania operation-mode 11b channel auto channel-
width auto
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1406
set wlan radio
set wlan radio
Description
Configures the radio settings of wireless antennas per band (in wireless models that contain a concurrent
dual band option using two radio antennas).
Syntax
Parameters
Parameter Description
band type
Options: 5GHz, 2.4GHz
channel Channel
Options: channel
channel-width Channel width
Options: auto, 20, 40, 80
country Country
Options: country
operation-mode Operation mode
Options: 11b, 11g, 11bg, 11n, 11ng, 11ac, 11nac
Example
set wlan radio band 5GHz country albania operation-mode 11b channel auto
channel-width auto
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1407
set wlan radio
set wlan radio
Description
Enable/Disable the wireless radio.
Syntax
Parameters
Parameter Description
mode Wireless radio mode
Options: off, on
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1408
set wlan radio
set wlan radio
Description
Enable/Disable the wireless radio per band (in wireless models that contain a concurrent dual band option
using two radio antennas).
Syntax
Parameters
Parameter Description
band type
Options: 5GHz, 2.4GHz
mode Wireless radio mode
Options: off, on
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1409
set wlan radio
set wlan radio
Description
Configures advanced radio settings for the wireless radio.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1410
set wlan radio
set wlan radio
Description
Configures advanced radio settings for the wireless radio per band (in wireless models that contain a
concurrent dual band option using two radio antennas).
Syntax
Parameters
Parameter Description
band type
Options: 5GHz, 2.4GHz
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1411
show wlan radio
show wlan radio
Description
Shows configuration of the wireless radio.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1412
show wlan statistics
show wlan statistics
Description
Shows statistics of the wireless radio.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1413
wlan vaps
wlan vaps
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1414
add wlan vap
add wlan vap
Description
Adds a new wireless network (Virtual Access Point or VAP) to an available wireless radio. In hardware
models were dual antennas are available, during configuration of a wireless network the specific band for
the network must be selected (2.4Ghz/5Ghz).
Syntax
Parameters
Parameter Description
band Wireless radio transmitter
Options: 5GHz, 2.4GHz
ssid Wireless network name (SSID)
Type: A string that contains [A-Z], [0-9], '_', '.', '-' and space characters
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1415
delete wlan vaps
delete wlan vaps
Description
Delete all existing wireless Virtual Access Points (VAP).
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1416
set wlan vap wireless advanced-settings protected-mgmt-frames
set wlan vap wireless advanced-settings
protected-mgmt-frames
Description
Enable or disable protection of 802.11 management frames
Syntax
Parameters
Parameter Description
wireless-name Name of the wireless network
Type Press TAB to see available options
on/off on - Enabled
off - Disabled
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1417
set wlan vap
set wlan vap
Description
Use MAC address as wireless password.
Syntax
Parameters
Parameter Description
vap Name of the VAP that is being edited.
prefix The authentication type is password-set-as-mac-with-prefix.
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1418
show wlan vap wireless
show wlan vap wireless
Description
Show wlan vap wireless networks for which 802.11w is enabled
Syntax
Parameters
Parameter Description
<wireless-name> Name of the wireless network
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1419
show wlan vaps
show wlan vaps
Description
Shows all Virtual Access points (VAPs or wireless network).
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1420
show wlan vaps statistics
show wlan vaps statistics
Description
Shows statistics per Virtual Access Point.
Syntax
Parameters
Parameter Description
n/a
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1421
zero-touch
zero-touch
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1422
set zero-touch
set zero-touch
Description
Configure parameters for the ZeroTouch service.
Syntax
Parameters
Parameter Description
cloud-url The DNS or IP address of the cloud service.
Default: zerotouch.checkpoint.com
Type: URL or IP address
mode When the mode is set to on, the appliance will constantly try to fetch configuration from
the Zero Touch server if the First Time Configuration Wizard is not started.
Options: on, off
Default: on
verify- When verify-certificate is set to on, the appliance will verify the SSL certificate of the
certificate Zero Touch server. You are advised NOT to change this value.
Options: on, off
Default: on
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1423
show zero-touch
show zero-touch
Description
Show the parameters configured for the Zero Touch service.
Syntax
show zero-touch
Parameters
Parameter Description
n/a
Example
show zero-touch
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1424
test zero-touch-request
test zero-touch-request
Description
Test the procedure of receiving configuration from the Zero Touch server. If the command is executed
without parameters, the gateway will connect to the Zero Touch server and display the received
configuration without enforcing it. There is an option to store the configuration in the /storage/zt_
cfg.clish file.
Syntax
Parameters
Optional Parameter Description
save-configuration-as file Save received configuration to the /storage/zt_cfg.clish file.
Example
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.20 CLI Reference Guide | 1425