Firewall Show Commands
16-136 Configuring Security
Sample Output
TheoutputbelowdisplaysnetworkobjectsforthePrivate‐networkandPartner‐networksgroups.
Notethatonlymemberobjectsnamesareshown.
Youcanenterthe
show ip firewall networkcommandtogetaddressrangesofeachnetwork
object.
Name Network (group) objects
Private-network internet
Remote-access 10.1.0.0/16
Partner-networks dmz
ext192 ext253
ext254
int int40
show ip firewall service
Thisstaticcounterdisplaysallconfiguredserviceobjects.Itincludesthreeversions:
•
Show ip firewall service‐Displaysallservices,pre‐definedanduser‐defined.
•
Show ip firewall user-defined‐Displaysuser‐definedservicesonly.
•
Show ip firewall service name‐Displaysaspecificserviceobjectidentifiedbyname.
Syntax
show ip firewall service [user-defined | name]
Mode
EXEC or Privileged EXEC Mode: XSR> or XSR#
Sample Output
Thefollowingoutputdisplaysfirewallserviceobjects:
Name Source port range Destination port range Protocol
ftp 1024-65535 21-21 tcp
netbios 137-137 137-137 udp
show ip firewall service-group
Thisstaticcounterdisplaysallservicegroupobjects.Iftheoptionalservicegroupnameis
specifiedthenonlythatservicegroupobjectisdisplayed.
Syntax
show ip firewall service-group [name]
user-defined
Listsuser‐definedservicesonly.
name
Nameofaserviceobject.