The following table lists the SunScreen ssadm subcommands and their descriptions. Many ssadm subcommands duplicate administration GUI functions, while others provide a context for other subcommands.
Table 10-2 SunScreen ssadm Subcommand Summary
ssadm Subcommand |
Description |
---|---|
Activate a Screen policy |
|
List information about the currently active policy |
|
List algorithms supported by SKIP |
|
Write a SunScreen backup file to standard output |
|
Allows a user to manually administer the two databases of public key certificates used by SKIP and IKE. These databases store long term certificates so that they may be accessed by the key manager. |
|
A utility for managing the two local identity databases on a Screen. ssadm certlocal is the primary tool for administering local IDs. |
|
certrldb |
A utility for managing the certificate revocations lists in the IKE certificate database. ssadm certrldb can add, delete, extract, and list IKE certificates based on the command option specified. |
Create an initial SunScreen configuration. ssadm configure, when combined with pkgadd, is equivalent to using the installation wizard graphical user interface. |
|
Set or clear the level of debugging output generated by a Screen |
|
Run the SunScreen configuration editor (see "Configuration Editor Reference" in SunScreen 3.2 Administrator's Overview) |
|
Configure the features of a high availability (HA) Screen |
|
Examine or remove the protection lock that the configuration editor places on a policy file |
|
Maintain the Screen log file |
|
Interpret Screen logs and display their contents |
|
Authenticate a user for administrative access through ssadm to a Screen from a remote Administration Station |
|
Expands SunScreen logmacro objects |
|
Terminate the session created by ssadm login. |
|
Print information about the SunScreen log |
|
Install patch, as needed |
|
Create, delete, list, rename Screen policies |
|
Print single line describing the SunScreen product in use |
|
Read a backup file from standard input |
|
Configure the client layer of the SecurID system |
|
Print a description of running SunScreen software |
|
Report summary information about the traffic flowing through the SunScreen, classified by interface |
You maintain user-controlled data by using the ssadm edit subcommand.
To look at or change a policy in some way, invoke the configuration editor and type a series of commands that end with save and quit requests.
ssadm configure is a text-based command line utility for creating an initial SunScreen configuration. ssadm configure, combined with pkgadd, is the command line equivalent of the installation wizard graphical user interface.
ssadm configure interactively queries you with various options for configuring the SunScreen, creates a configuration, stores it under the policy name Initial, and activates it. After ssadm configure finishes, you can administer the firewall.