Thursday, June 27, 2013

Cisco delivers "monster" Catalyst switch in major product refresh

Network World - Cisco this week will significantly update its enterprise network line-up with programmable campus and branch switches and routers designed to tightly bind applications to network hardware and services.
The new products include the Catalyst 6800 backbone switching line, a new supervisor engine for Cisco’s 4500-E chassis-based access switch, a new high-end ISR branch router and application performance extensions to the ASR 1000 edge router.
Cisco 6800
Cisco 6800
“Cisco has…delivered a monster Catalyst,” says Bill Carter, senior business communications analyst at value-added reseller Sentinel Technologies in Springfield, Ill. “This gives customers a core switch with 10G/40G/100G with the feature set required in the campus.”
The company, which this week hosts itsCisco Live event in Orlando, says its new products fit within an Enterprise Network Architecture under which applications, network services software and hardware networking functions all work together.
Much of this synergy is facilitated by Cisco’s ONE API framework for programmable networking and associated ASICs optimized for Cisco ONE programmability. Cisco ONE and its onePK API set is Cisco’s response to software-defined networking (SDN), in which many of the functions of network behavior are divorced from hardware and centrally administered by software controllers.
SDN makes network functions less reliant on specific hardware and operating systems, and more accommodating to commodity switching and open source software. It threatens Cisco’s dominance and fat profits in routers and switches.
Cisco is combatting the SDN trend by attempting to tightly link software programmability of network infrastructure to custom-developed ASIC hardware and hardware-specific operating systems, and defending its incumbency and massive installed base. These new products are instantiations of that strategy.
Cisco says it will support onePK across its entire enterprise routing and switching portfolio within the next 12 months, beginning with the ISR 4451-AX and ASR 1000-AX routers announced this week, which will support onePK in late summer/early fall.
The Catalyst 6800 is an outgrowth of the ubiquitous – and 10+ year old – Catalyst 6500. The 6800 is targeted at campus backbone 10/40/100Gbps services. In addition to network programmability, the 6800 is supervisor- and line card-compatible with the 6500, Cisco says, adding that there is still no date set for retiring the 6500.
“I see the Cat 6800 as a natural evolution of the 6500 platform,” says IDC analyst Rohit Mehra. “While scale and performance are going to be important, so will the need for providing agility and deploying programmable platforms. That's what the 6800 brings to the table with added simplicity, while maintaining operational consistency and continuity with the 6500 product suite.”
Sources say Cisco still has a vibrant roadmap for the Catalyst 6500, including a 10Tbps supervisor engine in the works. Cisco confirmed that a 10T supervisor engine is planned for both the 6500 and 6800 switches. The company would not say when it's coming.

Courtesynetworkworld

Tuesday, January 1, 2013

Check Point SPLAT Commands


This is a list of several Check Point SPLAT commands that I use frequently. Perhaps this CLI tip sheet for Secure Platform is useful to you too:

clockdisplay date and time on firewall
cpconfigchange SIC, licenses and more
cphaprob ldstatdisplay sync serialization statistics
cphaprob statlist the state of the high availability cluster members. Should show active and standby devices.
cphaprob syncstatdisplay sync transport layer statistics
cphastopstop a cluster member from passing traffic. Stops synchronization. (emergency only)
cplic printlicense information
cpstartstart all checkpoint services
cpstat fwshow policy name, policy install time and interface table
cpstat hahigh availability state
cpstat os -f allcheckpoint interface table, routing table, version, memory status, cpu load, disk space
cpstat os -f cpucheckpoint cpu status
cpstat os -f routingcheckpoint routing table
cpstopstop all checkpoint services
cpwd_admin monitor_listlist processes actively monitored. Firewall should contain cpd and vpnd.
expertchange from the initial administrator privilege to advanced privilege
find / -type f -size 10240k -exec ls -la {} \;Search for files larger than 10Mb
fw ctl iflistshow interface names
fw ctl pstatshow control kernel memory and connections
fw exportlog -oexport the current log file to ascii
fw fetch 10.0.0.42get the policy from the firewall manager (use this only if there are problems on the firewall)
fw logshow the content of the connections log
fw log -b search the current log for activity between specific times, eg
fw log -b "Jul 23, 2009 15:01:30" "Jul 23,2009 15:15:00"
fw log -c dropsearch for dropped packets in the active log; also can use accept or reject to search
fw log -ftail the current log
fwm logexport -i -o export an old log file on the firewall manager
fw logswitchrotate logs
fw lslogslist firewall logs
fw statfirewall status, should contain the name of the policy and the relevant interfaces, i.e. Standard_5_1_1_1_1 [>eth4] [eth0.900] [
fw stat -lshow which policy is associated with which interface and package drop, accept and reject
fw tabdisplays firewall tables
fw tab -s -t connectionsnumber of connections in state table
fw tab -t xlate -xclear all translated entries (emergency only)
fw unloadlocalclear local firewall policy (emergency only)
fw verfirewall version
fwm lock_admin -hunlock a user account after repeated failed log in attempts
fwm verfirewall manager version (on SmartCenter)
ifconfig -alist all interfaces
log listlist the names of the logs
log show display a specific log, ‘log show 33′ will display "Can’t find my SIC name in registry" if there are communication problems
netstat -an | morecheck what ports are in use or listening
netstat -rnrouting table
passwdchange the current user’s password
ps -eflist running processes
sysconfigconfigure date/time, network, dns, ntp
upgrade_importrun ‘/opt/CPsuite-R65/fw1/bin/upgrade_tools/upgrade_import’ after a system upgrade to import the old license and system information.
hwclockshow the hardware clock. If the hardware and operating system clocks are off by more than a minute, sync the hardware clock to the OS with "hwclock –systohc"
fw fetch 10.0.0.42Manually grab the policy from the mgmt server at 10.0.0.42
fw log -fShows you realtime logs on the firewall – will likely crash your terminal