Add NGFW Engine tests

Add NGFW Engine tests and configure the settings for each test.

Before you begin

Enable the NGFW Engine tester and specify global settings.

The following tests are available:

  • Engine Properties Test External — Runs a command or custom script stored on the NGFW Engine. If the command or script returns the code zero (0), the test is considered successful, otherwise the test is considered failed.
  • Engine Properties Test File Space — Checks the free disk space on a hard disk partition.
  • Engine Properties Test Swap Space — Checks the available swap space on the hard disk.
  • Engine Properties Test Link Status — Checks whether a network port reports the link as up or down.
  • Engine Properties Test Multiping — Sends out a series of ping requests to determine whether there is connectivity through a network link.
Note: Engine Properties Test Inline Link is only available for inline interfaces. Inline interfaces are not yet supported on the NGFW Manager.

For more details about the product and how to configure features, click Help or press F1.

Steps

  1. Browse to NGFW > Properties > General.
  2. In the Test cell of the Tests table, click , then select the type of test to add.
  3. Configure the settings, then click Save.
  4. Click Save.
  5. Publish the changes.

Example

Table 1. NGFW Engine Properties - General - Tests
Option Definition
Tests Shows the configured NGFW Engine tests. To add a row to the list, click .
Active When selected, the NGFW Engine test is active.
Test Shows the name of the NGFW Engine test. Add a test in one of the following ways:
  • Click , then select the type of test to add.
  • Type part of the name of an element or browse through the drop-down list to select an element.
Table 2. Engine Properties Test External
Option Definition
Is Run Online When selected, the test is run when the NGFW Engine node is online.
Is Run Offline When selected, the test is run when the NGFW Engine node is offline.
Is Run Standby This option is only available for clusters. Clusters are not yet supported on the NGFW Manager.
Test Interval Specify in seconds how frequently the test is run.
Action in Failure

Select the action taken if a test fails.

  • None — No action is taken.
  • OfflineThis option is only available for clusters. Clusters are not yet supported on the NGFW Manager.
  • Force OfflineThe NGFW Engine node goes offline, even if the node is in the Locked Online state. Use in cases in which a complete cut in traffic is a better option than a partially working NGFW Engine.
Is Alert When selected, sends an alert to notify administrators that a test has failed.
Retry Count Enter the number of times the tester tries to execute the test.
Timeout Enter the timeout in seconds. If the test being run does not return a response in the specified time, the test has failed. Avoid overly short timeout values. We recommend a timeout of 500–1000 ms, depending on the test.
Command Line Enter the command or script path. The result must return an exit code of 0 (zero) if it succeeds. Any non-zero return value is a failure.
CAUTION:
This test allows administrators who have permissions to edit the properties of NGFW Engines to run arbitrary commands in the NGFW Engine operating system.
Clear All Reverts your changes.
Table 3. Engine Properties Test File Space
Option Definition
Is Run Online When selected, the test is run when the NGFW Engine node is online.
Is Run Offline When selected, the test is run when the NGFW Engine node is offline.
Is Run Standby This option is only available for clusters. Clusters are not yet supported on the NGFW Manager.
Test Interval Specify in seconds how frequently the test is run.
Action in Failure

Select the action taken if a test fails.

  • None — No action is taken.
  • OfflineThis option is only available for clusters. Clusters are not yet supported on the NGFW Manager.
  • Force OfflineThe NGFW Engine node goes offline, even if the node is in the Locked Online state. Use in cases in which a complete cut in traffic is a better option than a partially working NGFW Engine.
Is Alert When selected, sends an alert to notify administrators that a test has failed.
Retry Count Enter the number of times the tester tries to execute the test.
Partition Specify the partition to test.
Free Space Enter the minimum amount of free space in kilobytes. When the amount of free space drops below this amount, the NGFW Engine executes the chosen action.
Table 4. Engine Properties Test Swap Space
Option Definition
Is Run Online When selected, the test is run when the NGFW Engine node is online.
Is Run Offline When selected, the test is run when the NGFW Engine node is offline.
Is Run Standby This option is only available for clusters. Clusters are not yet supported on the NGFW Manager.
Test Interval Specify in seconds how frequently the test is run.
Action in Failure

Select the action taken if a test fails.

  • None — No action is taken.
  • OfflineThis option is only available for clusters. Clusters are not yet supported on the NGFW Manager.
  • Force OfflineThe NGFW Engine node goes offline, even if the node is in the Locked Online state. Use in cases in which a complete cut in traffic is a better option than a partially working NGFW Engine.
Is Alert When selected, sends an alert to notify administrators that a test has failed.
Retry Count Enter the number of times the tester tries to execute the test.
Free Swap Space Enter the minimum amount of free space in kilobytes. When the amount of free space drops below this amount, the NGFW Engine executes the chosen action.
Table 5. Engine Properties Test Link Status
Option Definition
Is Run Online When selected, the test is run when the NGFW Engine node is online.
Is Run Offline When selected, the test is run when the NGFW Engine node is offline.
Is Run Standby This option is only available for clusters. Clusters are not yet supported on the NGFW Manager.
Test Interval Specify in seconds how frequently the test is run.
Action in Failure

Select the action taken if a test fails.

  • None — No action is taken.
  • OfflineThis option is only available for clusters. Clusters are not yet supported on the NGFW Manager.
  • Force OfflineThe NGFW Engine node goes offline, even if the node is in the Locked Online state. Use in cases in which a complete cut in traffic is a better option than a partially working NGFW Engine.
Is Alert When selected, sends an alert to notify administrators that a test has failed.
Retry Count Enter the number of times the tester tries to execute the test.
Link Scope Select the interface on which the test is run.
  • All — All interfaces.
  • All with CVIThis option is only available for clusters. Clusters are not yet supported on the NGFW Manager.
  • Specific — A specific physical interface only.
Physical Interface

(When Link Scope is Specific)

Select the physical interface to run the test on.

Table 6. Engine Properties Test Multiping
Option Definition
Is Run Online When selected, the test is run when the NGFW Engine node is online.
Is Run Offline When selected, the test is run when the NGFW Engine node is offline.
Is Run Standby This option is only available for clusters. Clusters are not yet supported on the NGFW Manager.
Test Interval Specify in seconds how frequently the test is run.
Action in Failure

Select the action taken if a test fails.

  • None — No action is taken.
  • OfflineThis option is only available for clusters. Clusters are not yet supported on the NGFW Manager.
  • Force OfflineThe NGFW Engine node goes offline, even if the node is in the Locked Online state. Use in cases in which a complete cut in traffic is a better option than a partially working NGFW Engine.
Is Alert When selected, sends an alert to notify administrators that a test has failed.
Retry Count Enter the number of times the tester tries to execute the test.
Clear All Reverts your changes.
Target Addresses Enter the IP addresses that you want to ping.

Enter one IP address per row. If you have a list of IP addresses where each IP address is on a separate row, you can copy and paste the list.

To remove a row, click Remove next to the row. To remove all rows, click Clear All.
Source Address Select the IP address to use as the source of the ping.