Controlling ISP Redundancy from CLI

You can control the ISP Redundancy behavior from CLI.

Force ISP Link State

Use the "fw isp_link" command to force the ISP link state to Up or Down.

Use this to test installation and deployment, or to force the Security GroupClosed A logical group of Security Gateway Modules that provides Active/Active cluster functionality. A Security Group can contain one or more Security Gateway Modules. Security Groups work separately and independently from each other. To the production networks, a Security Group appears a single Security Gateway. to recognize the true link state if it cannot (the ISP link is down, but the Security Group detects it as up).

For more information, see the R80.20 CLI Reference Guide > Chapter Security Gateway Commands > Section fw > Section fw isp_link.

The ISP Redundancy Script

When the Security Group starts, or an ISP link state changes, the $FWDIR/bin/cpisp_update script runs on the Security Group.

This script changes the default route of the Security Group.

For example, you can force the Security Group to change the state of an interface to match that state of its ISP link.