|
|
The Consistency Check command enables you to monitor your security system for inconsistencies, such as routing discrepancies, invalid port numbers, and invalid IP addresses. You can configure Consistency Check to monitor your security system automatically. You can perform on-demand Consistency Checks. You also have the option of disabling Consistency Check.
In this chapter you will find the following topics:
Consistency Check ensures that configuration discrepancies do not alter or impede security system functionality and thus lead to network security risks. You can enable Consistency Check to monitor your entire system, looking for inconsistencies and discrepancies in network traffic routing as well as in IP addresses and port numbers. It also searches for invalid network hosts and IP address ranges. Consistency Check also verifies that there is at least one valid administrative account and provides assurance that Policy Distribution Points and their associated Policy Enforcement Points are functioning appropriately.
After a Consistency Check has occurred, the system items involved and brief descriptions of the related inconsistencies appear in the System Inconsistencies panel in the View pane. You can refine the display of these error message by including messages generated by external agents, such as the Cisco Secure VPN Client and the control agent elements running on the Policy Distribution Points within your system. For external agents, you can specify that you want to refresh every five seconds the messages that they generate. In addition, you can specify whether to organize all messages for a single item entry under a single instance of that item and how often to refresh the messages for external agents.
You can configure Consistency Check to occur automatically whenever you select a node in the Navigator pane or to occur automatically with each Save or Save and Update operation that you perform. You can also disable Consistency Check altogether. You can also initiate an on-demand Consistency Check.
Example: If you have a network with the IP address 192.168.10.x and try to create a host under it with an address 192.168.12.x, the system informs you of the inconsistency in a dialog box (if Always is selected under Automatic Checking in the System Inconsistencies panel) and with an entry in the System Inconsistencies panel in the View pane.
![]() |
Note Consistency Check will not allow you to save any work in progress if it contains errors in consistency. To save any work in progress that may contain such errors, you will need to disable Consistency Check. |
You can use Consistency Check to perform the tasks listed below.
You can configure Consistency Check to occur every time you make a change or save changes in the GUI client. You can also disable Consistency Check altogether.
To configure Consistency Check, perform the following task:
Result: The System Inconsistencies panel appears in the View pane.

You can also click Consistency Check on the main toolbar to access the System Inconsistencies panel.
Step 2 To refresh the System Inconsistencies list, click Refresh.
Result: Another Consistency Check is performed on the system, and the new results appear in this list.
Step 3 To refine the display of the messages within Consistency Check, select one or more of the following options in the System Inconsistencies panel.
You can select one of three options.
Step 4 To configure Consistency Check to perform automatic checks on the system, select an option under Automatic Checking in the System Inconsistencies panel.
You can select one of three options.
Step 5 To accept your changes and close the panel, click OK. To reject your changes and close the panel, click Cancel.
Step 6 To save all changes to the Primary Policy Database, click Save on the File menu.
To perform an on-demand Consistency Check, perform the following task:
Result: The System Inconsistencies panel appears in the View pane.

You can also click Consistency Check on the main toolbar to access the System Inconsistencies panel.
Step 2 To refresh the System Inconsistencies list, click Refresh.
Result: Another Consistency Check is performed on the system, and the new results appear in the System Inconsistencies list.
Step 3 To access the panel for the system item involved in any inconsistency, double-click that item in the System Inconsistencies list.
Result: The panel for the system item appears in the View pane.
Step 4 To close the System Inconsistencies panel, click OK.
![]()
![]()
![]()
![]()
![]()
![]()
![]()
Posted: Tue May 30 08:25:00 PDT 2000
Copyright 1989 - 2000©Cisco Systems Inc.