As requested, here is how you can do a diff between rollbacks:
A) Determine which rollback you want to compare via:
root@SRX210_A> show system commit
0 2013-04-21 08:46:04 UTC by root via cli
1 2013-04-21 08:44:55 UTC by root via cli
2 2013-04-21 08:43:58 UTC by root via cli
3 2013-04-21 08:42:27 UTC by root via cli
4 2013-04-21 08:35:52 UTC by root via cli
5 2013-04-21 08:33:21 UTC by root via cli
6 2013-04-21 08:25:22 UTC by root via cli
7 2013-04-21 08:24:50 UTC by root via cli
8 2013-04-21 07:57:11 UTC by root via cli
9 2013-04-21 07:56:03 UTC by root via cli
10 2013-04-21 07:53:25 UTC by root via cli
11 2013-04-21 07:52:37 UTC by root via cli
12 2013-04-21 07:47:42 UTC by root via cli
13 2013-04-16 20:25:01 UTC by root via cli
B) Select the rollback you wish to compare based on the above list via:0 2013-04-21 08:46:04 UTC by root via cli
1 2013-04-21 08:44:55 UTC by root via cli
2 2013-04-21 08:43:58 UTC by root via cli
3 2013-04-21 08:42:27 UTC by root via cli
4 2013-04-21 08:35:52 UTC by root via cli
5 2013-04-21 08:33:21 UTC by root via cli
6 2013-04-21 08:25:22 UTC by root via cli
7 2013-04-21 08:24:50 UTC by root via cli
8 2013-04-21 07:57:11 UTC by root via cli
9 2013-04-21 07:56:03 UTC by root via cli
10 2013-04-21 07:53:25 UTC by root via cli
11 2013-04-21 07:52:37 UTC by root via cli
12 2013-04-21 07:47:42 UTC by root via cli
13 2013-04-16 20:25:01 UTC by root via cli
root@SRX210_A> show system rollback compare 5 0
[edit security policies from-zone Trust to-zone Trust policy Trust_to_Trust match]
- source-address Net_192.168.0.0/24;
- destination-address any;
- application any;
+ source-address Net_192.168.0.0/24;
+ destination-address any;
+ application junos-icmp-all;
[edit security zones security-zone Trust address-book]
address Net_192.168.0.0/24 { ... }
+ address Host_192.168.0.10 192.168.0.10/32;
The output above compares rollback '5' to the active configuration '0'[edit security policies from-zone Trust to-zone Trust policy Trust_to_Trust match]
- source-address Net_192.168.0.0/24;
- destination-address any;
- application any;
+ source-address Net_192.168.0.0/24;
+ destination-address any;
+ application junos-icmp-all;
[edit security zones security-zone Trust address-book]
address Net_192.168.0.0/24 { ... }
+ address Host_192.168.0.10 192.168.0.10/32;
No comments:
Post a Comment