TMS zl Management and Configuration Guide ST.1.1.100430
1-60
Overview
Firewall
Firewall Troubleshooting
You can troubleshoot the firewall from the CLI interface. Information that you
can collect includes:
■ A capture of packets received on each TMS VLAN
■ All connections currently processed by the firewall
■ NAT translation currently processed by firewall
■ Route table
■ ARP caches
■ Crash dump
You can also perform these tasks from the CLI interface:
■ Ping from the module to any other IP address
Note that the ping will only be successful if the firewall access policies
permit ICMP echo traffic from the Self zone to the correct destination
zone (and vice versa).
■ Close a specific connection established through the firewall
■ Trace a route to a particular destination IP address
Again, ICMP echo traffic must be permitted between the Self zone and the
destination’s zone.
■ Clear the ARP cache
Firewall Logging
The TMS zl Module can log firewall events both locally and remotely.
Firewall Events
Events logged by the TMS zl Module firewall include:
■ Sessions initiated using any access policy (policy must have logging
enabled)
■ Packets denied by any access policy (policy must have logging enabled)
■ Successful and failed login attempts to the TMS zl Module Web browser
interface
■ Status of components at startup