Below are few of the show commands that you need to know in order to manage or troubleshoot the firewall related issues.
- Show version: To check the version of the code that you are running on firewall.
- show int ip brief: To check all the firewall interfaces , their IP address and the status (up/down). Please note the command is different in Cisco switches and routers which is “show ip int brief”.
- show nameif: To check the interfaces and their associated names
- show arp: To check the arp table. The command in Cisco switches and routers is “show ip arp”.
- show route: To check the routing table. The command in Cisco switches and routers is “show ip route”.
- show logging: To check the logs in firewall.
- show run access-list : To check all the access-lists configured in Firewall
- show run access-group: To check interfaces where the ACLs are applied and in direction (inbound/outbound)
- show acceess-list: To check all the access-lists with the hits for each access-list entries
- show run nat: To check the NAT configuration of firewall
- show xlate: To check the live NAT translation table
- show run object-group: To check all the object-groups configured on Firewall.
- show run object: To check all the objects configured on the firewall.
- show connection: To check the stateful-connection table
- Show failover: To check the failover ststus of the HA pair.
VPN Related:
- Show crypto ipsec sa:
- show crypto isakmp sa:
- show vpn session-db