show policymgr drop configuration

Prev Next

Displays the information about the policy manager drop-filter configuration.

Syntax

show policymgr drop configuration

Parameters

None

Output fields

The following table describes the output fields for the show policymgr drop configuration command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Drop Out Interface

Gateway for an out-of-band block interface is enabled on either the ether1 management interface or the ether2 management interface.

HTTP comfort page

Enabled

HTTP comfort page posting to the HTTP requester is enabled.

Type

Type of comfort page message.

Message

Text of the message.

TCP reset

Enabled

A TCP connection reset is enabled.

to Server

A TCP server-side connection can be reset.

to Client

A TCP client-side connection can be reset.

UDP ICMP port-unreachable

Enabled

The “icmp port unreachable” message is posted when infected UDP packets have been blocked.

Example

The following example displays the information about the drop-filter configuration:

hostname # show policymgr drop configuration 

Policy drop filter configuration:

Drop Out Interface: ether2
    Gateway: 
Drop Out Interface    :   ether1
    Gateway: 

  Interface A:
  Out Interface       :   ether2
  HTTP Comfort Page:
     Enabled          :   no
     Type             :   access-denied
     Message          : The page you are trying to access, http://%U, has a potential threat detected.  
  UDP ICMP Port-Unreachable:
    Enabled           :   no
  Interface B:
  Out Interface       :   ether2
  HTTP Comfort Page:
     Enabled          :   no
     Type             :   access-denied
     Message          :   The page you are trying to access, http://%U, has a potential threat detected.
     TCP Reset        :
     Enabled          :   no
     to Server        :   yes
     to Client        :   yes
     UDP ICMP Port-Unreachable:
     Enabled          :   no

User role

Admin, Operator, Monitor, or Analyst

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Before Release 7.5