


 



<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="http://docwiki.cisco.com/w/skins/common/feed.css?270"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://docwiki.cisco.com/w/index.php?title=Configuration_Command_Differences&amp;feed=atom&amp;action=history</id>
		<title>Configuration Command Differences - Revision history</title>
		<link rel="self" type="application/atom+xml" href="http://docwiki.cisco.com/w/index.php?title=Configuration_Command_Differences&amp;feed=atom&amp;action=history"/>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=Configuration_Command_Differences&amp;action=history"/>
		<updated>2013-06-18T21:58:36Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.16.0</generator>

	<entry>
		<id>http://docwiki.cisco.com/w/index.php?title=Configuration_Command_Differences&amp;diff=29815&amp;oldid=prev</id>
		<title>Mikecrowe4ics: Small spelling and formatting corrections</title>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=Configuration_Command_Differences&amp;diff=29815&amp;oldid=prev"/>
				<updated>2010-05-07T01:04:59Z</updated>
		
		<summary type="html">&lt;p&gt;Small spelling and formatting corrections&lt;/p&gt;
&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
		&lt;tr valign='top'&gt;
		&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
		&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 01:04, 7 May 2010&lt;/td&gt;
		&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 8:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 8:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;'''set connection timeout idle'''&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;'''set connection timeout idle'''&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|The '''idle''' keyword was introduced in FWSM release 3.2(1). This command closes idle connections of all protocols after the specified period of time.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|The '''idle''' keyword was introduced in FWSM release 3.2(1). This command closes idle connections of all protocols after the specified period of time.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|The '''idle''' keyword is not supported in ASA software. The ASA software has the '''tcp''' keyword, which is used to close TCP &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;comnections &lt;/del&gt;after a specified time.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|The '''idle''' keyword is not supported in ASA software. The ASA software has the '''tcp''' keyword, which is used to close TCP &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;connections &lt;/ins&gt;after a specified time.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|Connection rate limit&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|Connection rate limit&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 33:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 33:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;'''auth-prompt reject''' ['''invalid-credentials''' | '''expired-pwd''']&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;'''auth-prompt reject''' ['''invalid-credentials''' | '''expired-pwd''']&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|This command was introduced in FWSM release 1.1. The '''invalid-credentials''' and '''expired-pwd''' options were added in FWSM release 3.2(1). This command, with the new options, allows users to specify the strings during authentication&amp;nbsp; rejection sdue to invalid credentials or expired passwords.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|This command was introduced in FWSM release 1.1. The '''invalid-credentials''' and '''expired-pwd''' options were added in FWSM release 3.2(1). This command, with the new options, allows users to specify the strings during authentication&amp;nbsp; rejection sdue to invalid credentials or expired passwords.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|This command is &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;suppored &lt;/del&gt;in ASA software, but the '''invalid-credentials''' and '''expired-pwd''' options are not supported.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|This command is &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;supported &lt;/ins&gt;in ASA software, but the '''invalid-credentials''' and '''expired-pwd''' options are not supported.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|DHCP &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;relaty &lt;/del&gt;trusted interface (option 82)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|DHCP &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;relay &lt;/ins&gt;trusted interface (option 82)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;'''dhcprelay information trusted'''&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;'''dhcprelay information trusted'''&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;'''dhcprelay information &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;trustedall&lt;/del&gt;'''&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;'''dhcprelay information &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;trust-all&lt;/ins&gt;'''&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|This command was introduced in FWSM command 4.0. This command allows users to preserve option 82 and forward a packet by identifying an interface as a trusted interface, ensuring that DHCP snooping and IP source guard features on the switch work along with the FWSM. The '''&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;trustall&lt;/del&gt;''' keyword enables the command for interfaces, as opposed to the '''trusted''' keyword, which enables the command for a single interface.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|This command was introduced in FWSM command 4.0. This command allows users to preserve option 82 and forward a packet by identifying an interface as a trusted interface, ensuring that DHCP snooping and IP source guard features on the switch work along with the FWSM. The '''&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;trust-all&lt;/ins&gt;''' keyword enables the command for interfaces, as opposed to the '''trusted''' keyword, which enables the command for a single interface.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|This command is not supported in ASA software.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|This command is not supported in ASA software.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-|&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-|&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 47:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 47:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|'''logging deny conn-queue-full'''&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|'''logging deny conn-queue-full'''&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|This command was introduced in FWSM release 3.1(1). When traffic is so heavy that the &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;loggin gqueue &lt;/del&gt;fills up, the FWSM might discard messages. This command prevents the creation of new transit connections through the FWSM to avoid discarding messages.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|This command was introduced in FWSM release 3.1(1). When traffic is so heavy that the &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;logging queue &lt;/ins&gt;fills up, the FWSM might discard messages. This command prevents the creation of new transit connections through the FWSM to avoid discarding messages.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|This command is not supported in ASA software.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|This command is not supported in ASA software.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 62:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 62:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;'''virtual http ip_address''' ['''host''' ''hostname'']&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;'''virtual http ip_address''' ['''host''' ''hostname'']&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|Direct authentication including login and logout are supported using the '''virtual http''' command.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|Direct authentication including login and logout are supported using the '''virtual http''' command.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|ASA software supports the login aspect of direct authentication but not logout. Because logout is not &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;support&lt;/del&gt;, direct authentication is not supported. ASA software does support cascading authentication with the '''virtual http''' command.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|ASA software supports the login aspect of direct authentication but not logout. Because logout is not &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;supported&lt;/ins&gt;, direct authentication is not supported. ASA software does support cascading authentication with the '''virtual http''' command.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|Route Monitoring&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|Route Monitoring&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 89:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 89:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|RIP&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|RIP&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;'''rip'''&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;'''rip'''&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|FWSM software still &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;suppports &lt;/del&gt;the old style single line '''rip''' configuration command.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|FWSM software still &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;supports &lt;/ins&gt;the old style single line '''rip''' configuration command.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|ASA software converted to the new style multiline '''rip''' configuration command in release 7.2&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|ASA software converted to the new style multiline '''rip''' configuration command in release 7.2&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 95:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 95:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;[no] '''control-point tcp-normalizer'''&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;[no] '''control-point tcp-normalizer'''&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|FWSM software supports a limited TCP normalizer. This feature can be turned on or off using a knob.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|FWSM software supports a limited TCP normalizer. This feature can be turned on or off using a knob.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|ASA software does not have a &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;nob &lt;/del&gt;to turn off the TCP normalizer.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|ASA software does not have a &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;knob &lt;/ins&gt;to turn off the TCP normalizer.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|Rate limits&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|Rate limits&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 125:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 125:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|This command is not supported in ASA software.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|This command is not supported in ASA software.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|'''&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;syspot &lt;/del&gt;uauth allow-http-cache'''&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|'''&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;sysopt &lt;/ins&gt;uauth allow-http-cache'''&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|This command is related to the direct authentication part of the '''virtual http''' command. When an authentication &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;sessions &lt;/del&gt;times out and when a user connects again without this command, the username and password &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;are prompted again&lt;/del&gt;. If this command is used, then the web browser is allowed to supply the username and password from its cache.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|This command is related to the direct authentication part of the '''virtual http''' command. When an authentication &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;session &lt;/ins&gt;times out and when a user connects again without this command, the &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;user is prompted again for a &lt;/ins&gt;username and password. If this command is used, then the web browser is allowed to supply the username and password from its cache.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|This command is not present in ASA software.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|This command is not present in ASA software.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 175:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 175:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|[no] '''aaa schedule round-robin'''&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|[no] '''aaa schedule round-robin'''&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|This command has no documentation, although it appears to have been introduced in FWSM release 3.1 to resolve an AAA bug, which states the following: &amp;quot;The problem is, we see a lot of stale https connections on &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;tehe &lt;/del&gt;groupq, which is not allowing the other connections like telnet and ftp to pass though. This will result in a latency in echoing back the characters typed on the telnet client. To get away from this problem, we are &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;crating &lt;/del&gt;a &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;cli &lt;/del&gt;'''aaa schedule round-robin''' which will schedule the groupq and allow other connections to be processed smoothly, if there are any stale https connections. Use the no form of this command to make the groupq to be processed in &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;fifo &lt;/del&gt;format (which is the default).&amp;quot;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|This command has no documentation, although it appears to have been introduced in FWSM release 3.1 to resolve an AAA bug, which states the following: &amp;quot;The problem is, we see a lot of stale https connections on &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;the &lt;/ins&gt;groupq, which is not allowing the other connections like telnet and ftp to pass though. This will result in a latency in echoing back the characters typed on the telnet client. To get away from this problem, we are &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;creating &lt;/ins&gt;a &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;CLI &lt;/ins&gt;'''aaa schedule round-robin''' which will schedule the groupq and allow other connections to be processed smoothly, if there are any stale https connections. Use the no form of this command to make the groupq to be processed in &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;FIFO &lt;/ins&gt;format (which is the default).&amp;quot;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|This command is not present in ASA software.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|This command is not present in ASA software.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 183:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 183:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;'''limit-resource mac-addresses''' ''value / value%''&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;'''limit-resource mac-addresses''' ''value / value%''&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;'''limit-resource rate &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;fixips&lt;/del&gt;''' ''value''&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;'''limit-resource rate &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;fixups&lt;/ins&gt;''' ''value''&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;'''limit-resource rate''' ''resource value%''&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;'''limit-resource rate''' ''resource value%''&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 196:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 196:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;'''url-server''' / ''ifc name'' '''vendor websense host local_ip protocol udp context-name'''&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;'''url-server''' / ''ifc name'' '''vendor websense host local_ip protocol udp context-name'''&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|In FWSM release 4.0 in &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;multipmode &lt;/del&gt;context &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;name&lt;/del&gt;, this command can be sent to the websense server using the '''context-name''' keyword. Also, the '''connections''' keyword can be used to specify the number of simultaneous TCP connections without the '''protocol''' keyword.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|In FWSM release 4.0 in &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;multiple &lt;/ins&gt;context &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;mode&lt;/ins&gt;, this command can be sent to the websense server using the '''context-name''' keyword. Also, the '''connections''' keyword can be used to specify the number of simultaneous TCP connections without the '''protocol''' keyword.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|ASA software does not support the '''context-name''' keyword. Also, it requires the '''protocol''' keyword, followed by TCP for configuring the number of simultaneous connections.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|ASA software does not support the '''context-name''' keyword. Also, it requires the '''protocol''' keyword, followed by TCP for configuring the number of simultaneous connections.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|}&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|}&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Mikecrowe4ics</name></author>	</entry>

	<entry>
		<id>http://docwiki.cisco.com/w/index.php?title=Configuration_Command_Differences&amp;diff=20311&amp;oldid=prev</id>
		<title>Lorlando: New page: The following table lists the differences among FWSM and ASA software configuration commands. {| border=&quot;1&quot; cellpadding=&quot;2&quot; !width=&quot;250&quot; align=&quot;left&quot; style=&quot;background:#99CCFF;&quot; |'''Featur...</title>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=Configuration_Command_Differences&amp;diff=20311&amp;oldid=prev"/>
				<updated>2009-08-28T21:05:04Z</updated>
		
		<summary type="html">&lt;p&gt;New page: The following table lists the differences among FWSM and ASA software configuration commands. {| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;2&amp;quot; !width=&amp;quot;250&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:#99CCFF;&amp;quot; |&amp;#39;&amp;#39;&amp;#39;Featur...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;The following table lists the differences among FWSM and ASA software configuration commands.&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
!width=&amp;quot;250&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:#99CCFF;&amp;quot; |'''Feature/Command'''&lt;br /&gt;
!width=&amp;quot;450&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:#99CCFF;&amp;quot; |'''FWSM Description'''&lt;br /&gt;
!width=&amp;quot;250&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:#99CCFF;&amp;quot; |'''ASA Description'''&lt;br /&gt;
|-&lt;br /&gt;
|Connection timeouts for all protocols&lt;br /&gt;
'''set connection timeout idle'''&lt;br /&gt;
|The '''idle''' keyword was introduced in FWSM release 3.2(1). This command closes idle connections of all protocols after the specified period of time.&lt;br /&gt;
|The '''idle''' keyword is not supported in ASA software. The ASA software has the '''tcp''' keyword, which is used to close TCP comnections after a specified time.&lt;br /&gt;
|-&lt;br /&gt;
|Connection rate limit&lt;br /&gt;
'''set connection conn-rate-limit'''&lt;br /&gt;
|This command was introduced in FWSM release 4.0(1). It allows users to rate limit TCP and/or UDP connections to a value specified in the CLI.&lt;br /&gt;
|This command is not present in ASA software.&lt;br /&gt;
|-&lt;br /&gt;
|AAA authentication challenge&lt;br /&gt;
'''aaa authentication challenge disable'''&lt;br /&gt;
|This command was introduced in FWSM release 3.1(1). This command disables authentication challenge for ftp, telnet, http, and https.&lt;br /&gt;
|This command is not supported in ASA software.&lt;br /&gt;
|-&lt;br /&gt;
|AAA authentication clear conn&lt;br /&gt;
'''aaa authentication clear-conn'''&lt;br /&gt;
|This command was introduced in FWSM release 3.2(1). This command forces active connections to close immediately after user authentication times out or when the authentication session is cleared with the '''clear uauth''' command.&lt;br /&gt;
|This command is not supported in ASA software.&lt;br /&gt;
|-&lt;br /&gt;
|Virtual SSH&lt;br /&gt;
[no] '''virtual ssh'''&lt;br /&gt;
|This command was introduced in FWSM release 3.2(1). This command allows direct authentication using SSH.&lt;br /&gt;
|This command is not supported in ASA software.&lt;br /&gt;
|-&lt;br /&gt;
|Interactive password prompts with RADIUS for authentication&lt;br /&gt;
'''auth-prompt reject''' ['''invalid-credentials''' | '''expired-pwd''']&lt;br /&gt;
|This command was introduced in FWSM release 1.1. The '''invalid-credentials''' and '''expired-pwd''' options were added in FWSM release 3.2(1). This command, with the new options, allows users to specify the strings during authentication  rejection sdue to invalid credentials or expired passwords.&lt;br /&gt;
|This command is suppored in ASA software, but the '''invalid-credentials''' and '''expired-pwd''' options are not supported.&lt;br /&gt;
|-&lt;br /&gt;
|DHCP relaty trusted interface (option 82)&lt;br /&gt;
'''dhcprelay information trusted'''&lt;br /&gt;
'''dhcprelay information trustedall'''&lt;br /&gt;
|This command was introduced in FWSM command 4.0. This command allows users to preserve option 82 and forward a packet by identifying an interface as a trusted interface, ensuring that DHCP snooping and IP source guard features on the switch work along with the FWSM. The '''trustall''' keyword enables the command for interfaces, as opposed to the '''trusted''' keyword, which enables the command for a single interface.&lt;br /&gt;
|This command is not supported in ASA software.&lt;br /&gt;
|-|&lt;br /&gt;
|http-map&lt;br /&gt;
'''port-misuse'''&lt;br /&gt;
|The command was introduced in FWSM release 3.1(1). This command restricts HTTP traffic by specifying a restricted application category. The '''port-misuse''' command  is used in http map configuration mode, that is accessible using the '''http-map''' command.&lt;br /&gt;
|This command is not supported in ASA software.&lt;br /&gt;
|-&lt;br /&gt;
|'''logging deny conn-queue-full'''&lt;br /&gt;
|This command was introduced in FWSM release 3.1(1). When traffic is so heavy that the loggin gqueue fills up, the FWSM might discard messages. This command prevents the creation of new transit connections through the FWSM to avoid discarding messages.&lt;br /&gt;
|This command is not supported in ASA software.&lt;br /&gt;
|-&lt;br /&gt;
|CPU Threshold&lt;br /&gt;
[no] '''cpu threshold rising&lt;br /&gt;
|This command was introduced in FWSM release 3.2(1). When SNMP is enabled, traps are sent when the CPU levels reach a certain configurable mark.&lt;br /&gt;
|This command is not supported in ASA software.&lt;br /&gt;
|-&lt;br /&gt;
|EtherType Access Lists and denying IPv4 and ARPs&lt;br /&gt;
|In TFW mode with an ethertype access list configured to &amp;quot;deny all,&amp;quot; both IPv4 and ARP cannot be denied on a FWSM device.&lt;br /&gt;
|In TFW mode with an ethertype access list configured to &amp;quot;deny all,&amp;quot; all ethertypes are denied, including IPv4 and ARP.&lt;br /&gt;
|-&lt;br /&gt;
|Direct Login or Logout using Virtual HTTP for User Authentication&lt;br /&gt;
'''virtual http ip_address''' ['''host''' ''hostname'']&lt;br /&gt;
|Direct authentication including login and logout are supported using the '''virtual http''' command.&lt;br /&gt;
|ASA software supports the login aspect of direct authentication but not logout. Because logout is not support, direct authentication is not supported. ASA software does support cascading authentication with the '''virtual http''' command.&lt;br /&gt;
|-&lt;br /&gt;
|Route Monitoring&lt;br /&gt;
'''route-monitor'''&lt;br /&gt;
|The route-monitoring feature is supported. If multiple static routes are configured, the feature can detect if a network goes down and the next best route is used.&lt;br /&gt;
|This feature is supported in ASA software using the '''sla monitor''' command. In this feature the ASA software supports more commmand options than FWSM software.&lt;br /&gt;
|-&lt;br /&gt;
|Old maps for inspections&lt;br /&gt;
[no] '''ftp-map'''&lt;br /&gt;
&lt;br /&gt;
[no] '''gtppmap'''&lt;br /&gt;
&lt;br /&gt;
[no] '''h225-map'''&lt;br /&gt;
&lt;br /&gt;
[no] '''http-map'''&lt;br /&gt;
&lt;br /&gt;
[no] '''mgcp-map'''&lt;br /&gt;
&lt;br /&gt;
[no] '''sip-map'''&lt;br /&gt;
&lt;br /&gt;
[no] '''snmp-map'''&lt;br /&gt;
&lt;br /&gt;
|FWSM software still supports the old style xxx-map commands.&lt;br /&gt;
|ASA software converted to the new style '''policy-map''' and ''policy-match''' commands in release 7.2.&lt;br /&gt;
|-&lt;br /&gt;
|RIP&lt;br /&gt;
'''rip'''&lt;br /&gt;
|FWSM software still suppports the old style single line '''rip''' configuration command.&lt;br /&gt;
|ASA software converted to the new style multiline '''rip''' configuration command in release 7.2&lt;br /&gt;
|-&lt;br /&gt;
|TCP normalizer knob&lt;br /&gt;
[no] '''control-point tcp-normalizer'''&lt;br /&gt;
|FWSM software supports a limited TCP normalizer. This feature can be turned on or off using a knob.&lt;br /&gt;
|ASA software does not have a nob to turn off the TCP normalizer.&lt;br /&gt;
|-&lt;br /&gt;
|Rate limits&lt;br /&gt;
'''access-list-commit'''&lt;br /&gt;
&lt;br /&gt;
'''allocate-acl-partition'''&lt;br /&gt;
&lt;br /&gt;
'''size'''&lt;br /&gt;
&lt;br /&gt;
[no] '''resource acl-partition'''&lt;br /&gt;
&lt;br /&gt;
[no] '''resource partition'''&lt;br /&gt;
&lt;br /&gt;
[no] '''resource rule'''&lt;br /&gt;
&lt;br /&gt;
'''rule'''&lt;br /&gt;
&lt;br /&gt;
|Due to Hard NPs, FWSM has fixed rule limits and many commands to handle the limits.&lt;br /&gt;
|ASA software does not have fixed rate limits, so it does not have these commands.&lt;br /&gt;
|-&lt;br /&gt;
|Xlates for all traffic&lt;br /&gt;
[no] '''xlate-bypass'''&lt;br /&gt;
|FWSM software always creates xlates for all traffic, including to-the-box traffic. This command was introduced to work around the xlate creation.&lt;br /&gt;
|ASA software does not create xlates for all traffic, so it does not have these commands.&lt;br /&gt;
|-&lt;br /&gt;
|ACL optimization&lt;br /&gt;
[no] '''access-list optimization enable'''&lt;br /&gt;
|This command enables the access list optimization rules, which are optimized and downloaded to the Hard NPs. The command also reduces the number of ACEs for for each group.&lt;br /&gt;
|This command is not supported in ASA software.&lt;br /&gt;
|-&lt;br /&gt;
|'''syspot uauth allow-http-cache'''&lt;br /&gt;
|This command is related to the direct authentication part of the '''virtual http''' command. When an authentication sessions times out and when a user connects again without this command, the username and password are prompted again. If this command is used, then the web browser is allowed to supply the username and password from its cache.&lt;br /&gt;
|This command is not present in ASA software.&lt;br /&gt;
|-&lt;br /&gt;
|'''sysopt np completion-unit'''&lt;br /&gt;
|This command was introduced in FWSM release 3.2(5). This command allows users to enable the hardware completion unit in the accelerated path network processors (NPs), which ensures that packets are forwarded out in the same order in which they were received in the ingress queues of the NPs.&lt;br /&gt;
|This command is not present in ASA software.&lt;br /&gt;
|-&lt;br /&gt;
|'''sysopt connection tcp sack-permitted'''&lt;br /&gt;
|This command was introduced in FWSM release 3.1(12). The '''no''' form of the command allows users to clear the '''sack permitted''' option exchanged during the TCP three-way handshake. The '''sack''' option is enabled by default.&lt;br /&gt;
|This command is implemented using the '''tcp-options selective-ack clear''' / '''allow''' command under tcp-map. The default is to allow the '''sack''' option, as done in FWSM.&lt;br /&gt;
|-&lt;br /&gt;
|'''sysopt connection tcp window-scale'''&lt;br /&gt;
|This command was introduced in FWSM release 3.1. Thi '''no''' form  of the command allows users to clear the window-scale TCP option. The option is allowed by default.&lt;br /&gt;
|This command is implemented using the '''tcp-options window-scale''' {'''clear''' / '''allow'''} command under tcp-map. The default is to allow the window-scale option, as done in FWSM.&lt;br /&gt;
|-&lt;br /&gt;
|Disaster Recovery&lt;br /&gt;
'''boot device module''' ''slot string''&lt;br /&gt;
|This is a SUP command that allows for disaster recovery of FWSM software by specifying different compact flash partitions.&lt;br /&gt;
|In ASA software disaster recovery is performed using ROMMOM and a console connection.&lt;br /&gt;
|-&lt;br /&gt;
|SNMP trap commands&lt;br /&gt;
'''snmp-server enable traps cpu threshold'''&lt;br /&gt;
&lt;br /&gt;
'''snmp-server enable traps cpu threshold rising'''&lt;br /&gt;
&lt;br /&gt;
'''snmp-server enable traps entity redun-switchover'''&lt;br /&gt;
&lt;br /&gt;
'''snmp-server enable traps entity alarm-asserted'''&lt;br /&gt;
&lt;br /&gt;
'''snmp-server enable traps entity alarm-cleared'''&lt;br /&gt;
&lt;br /&gt;
'''snmp-server enable traps nat'''&lt;br /&gt;
&lt;br /&gt;
'''snmp-server enable traps nat packet-discard'''&lt;br /&gt;
&lt;br /&gt;
'''snmp-server enable traps rate-limit-reached'''&lt;br /&gt;
&lt;br /&gt;
'''snmp-server enable traps resource'''&lt;br /&gt;
&lt;br /&gt;
'''snmp-server enable traps resource limit-reached'''&lt;br /&gt;
|These commands and the related traps were introduced in FWSM release 3.2(1).&lt;br /&gt;
|These commands and the related traps are not supported in ASA software.&lt;br /&gt;
|-&lt;br /&gt;
|Service Reset&lt;br /&gt;
[no] '''service reset no-connection'''&lt;br /&gt;
|This command was introduced in FWSM release 4.0. This command configures the FWSM to send a RST for a TCP packet, for which the FWSM does not have any connection history.&lt;br /&gt;
|ASA software achieves the same behavior using the '''service resetinbound''' command.&lt;br /&gt;
|-&lt;br /&gt;
|[no] '''aaa schedule round-robin'''&lt;br /&gt;
|This command has no documentation, although it appears to have been introduced in FWSM release 3.1 to resolve an AAA bug, which states the following: &amp;quot;The problem is, we see a lot of stale https connections on tehe groupq, which is not allowing the other connections like telnet and ftp to pass though. This will result in a latency in echoing back the characters typed on the telnet client. To get away from this problem, we are crating a cli '''aaa schedule round-robin''' which will schedule the groupq and allow other connections to be processed smoothly, if there are any stale https connections. Use the no form of this command to make the groupq to be processed in fifo format (which is the default).&amp;quot;&lt;br /&gt;
|This command is not present in ASA software.&lt;br /&gt;
|-&lt;br /&gt;
|Resource limits&lt;br /&gt;
'''limit-resource ipsec''' ''value / value%''&lt;br /&gt;
&lt;br /&gt;
'''limit-resource mac-addresses''' ''value / value%''&lt;br /&gt;
&lt;br /&gt;
'''limit-resource rate fixips''' ''value''&lt;br /&gt;
&lt;br /&gt;
'''limit-resource rate''' ''resource value%''&lt;br /&gt;
&lt;br /&gt;
|The '''limit resource''' command supports rate limit % as the resources have upper limits. It also supports limiting MAC addresses and IPSec management tunnels.&lt;br /&gt;
| ASA software does not have upper limits on resources, so it does not support % rate limits for resources. ASA software also does not support limiting MAC addresses and IPSec tunnels.&lt;br /&gt;
|-&lt;br /&gt;
|URL-Server&lt;br /&gt;
'''url-server''' ''ifc name'' ''' vendor websense host local_ip protocol tcp connections num_conns'''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''url-server''' / ''ifc name'' '''vendor websense host local_ip protocol udp context-name'''&lt;br /&gt;
&lt;br /&gt;
|In FWSM release 4.0 in multipmode context name, this command can be sent to the websense server using the '''context-name''' keyword. Also, the '''connections''' keyword can be used to specify the number of simultaneous TCP connections without the '''protocol''' keyword.&lt;br /&gt;
|ASA software does not support the '''context-name''' keyword. Also, it requires the '''protocol''' keyword, followed by TCP for configuring the number of simultaneous connections.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Lorlando</name></author>	</entry>

	</feed>