Cisco Cisco ASA 5580 Adaptive Security Appliance Leaflet
4-111
思科 ASA 系列命令参考,S 命令
第 4 章 show bgp 至 show cpu 命令
show cluster info
以下是
show cluster info incompatible-config 命令的输出示例:
ciscoasa(cfg-cluster)# show cluster info incompatible-config
INFO: Clustering is not compatible with following commands which given a user's
confirmation upon enabling clustering, can be removed automatically from running-config.
policy-map global_policy
class scansafe-http
inspect scansafe http-map fail-close
policy-map global_policy
class scansafe-https
inspect scansafe https-map fail-close
INFO: No manually-correctable incompatible configuration is found.
以下是
show cluster info trace 命令的输出示例:
ciscoasa# show cluster info trace
Feb 02 14:19:47.456 [DBUG]Receive CCP message: CCP_MSG_LOAD_BALANCE
Feb 02 14:19:47.456 [DBUG]Receive CCP message: CCP_MSG_LOAD_BALANCE
Feb 02 14:19:47.456 [DBUG]Send CCP message to all: CCP_MSG_KEEPALIVE from 80-1 at MASTER
以下是
show cluster info health 命令在
ASA 5500-X 上的输出示例:
ciscoasa# show cluster info health
Member ID to name mapping:
0 - A 1 - B(myself)
0 1
GigabitEthernet0/0 up up
Management0/0 up up
ips (policy off) up None
sfr (policy off) None up
Unit overall healthy healthy
Cluster overall healthy
以上输出列出
ASA IPS (ips) 和 ASA FirePOWER (sfr) 模块,且对于每个模块,ASA 都显示
“
policy on(策略开启)” 或 “policy off(策略关闭)” 来表明您是否在服务策略中配置了该
模块。例如:
class-map sfr-class
match sfr-traffic
policy-map sfr-policy
class sfr-class
sfr inline fail-close
service-policy sfr interface inside
通过上述配置,
ASA FirePOWER 模块(“sfr”)会显示为 “policy on(策略开启)”。如果一
个集群成员将模块作为 “
up”,另一个成员将该模块作为 “down” 或 “None”,则具有 down
模块的成员将被踢出集群。但是,如果未配置服务策略,则集群成员不会被踢出集群;仅当模块
正在运行时才会关联模块状态。
正在运行时才会关联模块状态。
以下是
show cluster info health 命令在
ASA 5585-X 上的输出示例:
ciscoasa# show cluster info health
spyker-13# sh clu info heal
Member ID to name mapping:
0 - A(myself) 1 - B
0 1
GigabitEthernet0/0 upup