Description

What Are the Unmanaged Commands in the NetScreen-Security Manager?

Symptoms

NSM-Netscreen Security Manager NSM: What are the unmanaged commands from Security Manager?

Solution

The Juniper Networks NetScreen-Security Manager is designed for system-level management, enabling multiple administrators to manage their devices from one central location using the majority of Command Line Interface (CLI) commands available in ScreenOS. However, a small number of device commands are unmanaged from the Security Manager UI.

Most unmanaged commands are useful only when performing device administration on a specific device, and do not affect management capabilities (although future versions of the Security Manager may support these commands). To use an unmanaged device command, you must connect locally to the NetScreen FW/VPN device.

The table below details each unmanaged command:

Unsupported Command Description
admin These commands configure or display administrative parameters for NetScreen FW/VPN devices, including:
  • Characteristics for each admin user, such as password and privilege level
  • How the device performs admin user authentication
  • Ways that admin users can access the device
  • Which IP address to use for administering the device from the Web
  • Which port the device uses to detect configuration changes made through the Web
  • Whether the device automatically emails generated alerts and traffic alarms
  • Whether the device is enabled for reset
common-criteria This command disables all internal commands. Only the root admin can set this command. If someone other than the root admin tries to set this command, the NetScreen FW/VPN device displays an error message.
envar These commands define environment variables. NetScreen FW/VPN devices use environment variables to make special configurations at startup.
gate This command checks the number of gates on a NetScreen FW/VPN device, how many are in use, and how many are still available. Gates are logical access points in the firewall for FTP and similar applications. NetScreen FW/VPN devices create the gates, and then convert a gate for each new session when data traffic occurs.
ike These commands define the Phase 1 and Phase 2 proposals and the gateway for an AutoKey IKE (Internet Key Exchange) VPN tunnel, and specify other IKE parameters.
intervlan-traffic These commands configure inter-VLAN traffic through a NetScreen FW/VPN device. It is possible to configure a virtual system (VSYS) with two trusted interfaces, such that traffic can enter the VSYS through one interface and exit through the other without undergoing any security services such as authentication or encryption. This is known as inter-VLAN traffic.
ssh These commands configure the Secure Shell (SSH) server task, an SSH-compatible server application that resides on a NetScreen FW/VPN device. When you enable the SSH server task, SSH client applications can manage the device through a secure connection (the look and feel of an SSH client session is identical to a Telnet session). You can run either SSH version 1 (SSHv1) or SSH version 2 (SSHv2) on a NetScreen FW/VPN device; the commands available depend on the SSH version that you activate.
set console This command defines the CLI console parameters, such as:
  • Whether the NetScreen FW/VPN device displays messages in the active console window
  • The number of lines that may appear on a console window page
  • The maximum time that can pass before automatic logout occurs due to inactivity
If console access is currently disabled, you can enable it using the unset console disable command through a Telnet connection.
set log audit-lossmitigation This command configures logging to mitigate message loss due to memory limitations on a NetScreen FW/VPN device.

Used for common criteria only.
set mac This command configures a static Media Access Control (MAC) address for a NetScreen FW/VPN device interface.
timer These commands display timer settings, or configure a NetScreen FW/VPN device to execute management or diagnosis automatically at a specified time. All timer settings remain in the configuration script after the specified time has expired.
user These commands create, remove, or display entries in the internal user authentication database.


Former Article Id

nskb6726