Dameon Welch Abernathy wrote:
.def files need to be edited on the management.
If you’re using Multi-Domain, they need to be edited in the domain context.
Which means using the following command before editing: msdenv domain_name
Also after you edit .def files, you need to do a policy install to the relevant gateways.
fw tab commands are run on the VSX Gateway.
Thanks for replying,
No, we dont have multi domains here, and I am feeling kind of "locked" because I cant use any commands in any machine besides management. any command returns nothing even on expert mode
I presume that any Virtual System Cluster that we have IS a firewall as their ACLs are managed via smartconsole. I try to enter via ssh on each of then and dont have a prompt for any SSH or telnet session. So i enter on the cluster machines (via VIP ou via their IPs) and use the "set virtual-system" command to change context to one of the Firewall virtual machines. After that, nothing, I cant do nothing.
for example:
ssh user@10.14.x.y ( one of the two cluster members)
[Expert@fwcml1:0]#
[Expert@fwcml1:0]# clish
fwcml1:0> ########################## after clish command I am still on expert mode??)
fwcml1:0> show virtual-system all
Virtual systems list
VS ID VS NAME
0 0
1 fwcml1_fwvscml01 fw
2 fwcml1_fwvscml02 <---- fw and vpn IPSEC machine
3 fwcml1_fwvswcml fw
4 fwcml1_fwvscml03 fw
5 fwcml1_fwvscml04 fw
fwcml1:0> set virtual-system 2
Context is set to vsid 2
fwcml1:2>
fwcml1:2> cpview
fwcml1:2> ################################# nothing?
fwcml1:2> cpstat fw
fwcml1:2> ################################## nothing??
|fwcml1:2> expert
Enter expert password:
Wrong password. ########################## I made on purpose just for testing
fwcml1:2> expert
Enter expert password:
Warning! All configuration should be done through clish
You are in expert mode now.
fwcml1:2> ############### Am I on expert mode? why theres no "expert" prompt?
fwcml1:2> cpstat
fwcml1:2> cpview
fwcml1:2>
So, is this normal? Why no return from commands? What I am missing here? I cannot do anything relating my original VPN problem this way, I am really on "expert" mode?
sorry for such basic questions but I am locked here and cant progress to useful stuff, because of my bad knowledge on this