The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

CLI Commands

Prev Next

This section consists of the CLI commands used for configuring a 100G Active Fail-Open module in three mode levels.

  1. Default mode

  2. Enable mode

  3. Configure mode

To access all the commands for a 100G Active Fail-Open kit, except the commands available only to the administrator, enter enable mode.

  1. Login to the CLI console of the 100G Active Fail-Open.

  2. Enter enable.

To access all commands for a 100G Active Fail-Open kit, enter configure mode.

  1. Login to the CLI console of the 100G Active Fail-Open.

  2. Enter enable.

  3. Enter configure.

    Note

    After each CLI configuration change made, enter the command write memory to keep the changes across system reboot.

    Note

    • For any help regarding the CLI commands, enter ?.

    • Use UP or Down arrow keys to get past commands already executed.

This command enables or disables the FEC (Forward Error Correction) state for the monitor ports and network ports of the Active Fail-Open modules and segments.

Syntax

afo port-link <1.1.mon0|1.1.mon1|1.1.net0|1.1.net1|2.1.mon0|2.1.mon1|2.1.net0|2.1.net1|> fec <disable|enable>

Parameter

Description

port <1.1.mon0|1.1.mon1|1.1.net0|1.1.net1|2.1.mon0|2.1.mon1|2.1.net0|2.1.net1|>

The following are the monitor and network ports of an Active Fail-Open kit:

  • 1.1.mon0: Module 1 segment 1 monitor port 0

  • 1.1.mon1: Module 1 segment 1 monitor port 1

  • 1.1.net0: Module 1 segment 1 network port 0

  • 1.1.net1: Module 1 segment 1 network port 1

  • 2.1.mon0: Module 1 segment 1 monitor port 0

  • 2.1.mon1: Module 1 segment 1 monitor port 1

  • 2.1.net0: Module 1 segment 1 network port 0

  • 2.1.net1: Module 1 segment 1 network port 1

disable

Disables the FEC state

enable

Enables the FEC state

afo segment 1.1 active-op-mode

This command configures the active operation mode of an Active Fail-Open kit.

Syntax

afo segment <1.1/2.1> active-op-mode <bypass|inline|tap>

Parameter

Description

1.1

Module 1 segment 1

2.1

Module 2 segment 1

bypass

bypass mode

inline

inline mode

tap

tap mode

afo segment heartbeat

This command configures the heartbeat for an Active Fail-Open segment.

Syntax

afo segment <1.1/2.1> hb <active-mode|active-restore|recover-time|hold-time|interval>

Parameter

Description

1.1

Module 1 segment 1

2.1

Module 2 segment 1

active-mode <enable|disable>

Enables or disables the heartbeat checking for an Active Fail-Open segment

active-restore <enable|disable>

Enables or disables the heartbeat active restore for an Active Fail-Open segment

recover-time <0-50000>

Set the time between 0 (milliseconds) and 50000 (milliseconds) to recover from a heartbeat lost event.

hold-time <10-50000>

Set the time between 10 (milliseconds) and 50000 (milliseconds) to hold the received heartbeats.

interval <3-10000>

Set the heartbeat interval time between 3 (milliseconds) and 10000 (milliseconds).

This command enables or disables the state of two-ports-link for an Active Fail-Open segment.

Syntax:

afo segment <1.1|2.1> port two-ports-link <disable|enable>

Parameter

Description

1.1

Module 1 segment 1

2.1

Module 2 segment 1

disable

Disables the status of two-ports-link

enable

Enables the status of two-ports-link

afo segment port two-ports-link-threshold

This command sets the two-ports-link-threshold value for an Active Fail-Open segment.

Syntax:

afo segment <1.1|2.1> port two-ports-link-threshold <4-25 sec>

Parameter

Description

1.1

Module 1 segment 1

2.1

Module 2 segment 1

<4-25 sec>

An integer between 4 (seconds) and 25 (seconds)

Note

By default, the threshold value is 4 seconds.

clear afo error rxtx

This command clears the received and transmitted errors of an Active Fail-Open module and segment.

Syntax

clear afo error rxtx <all|module|segment>

Parameter

Description

all

All received and transmitted errors of an Active Fail-Open kit

module <1|2>

All received and transmitted errors of an Active Fail-Open module 1 and 2

segment <1.1|2.1>

All received and transmitted errors of an Active Fail-Open segment

  • 1.1: Module 1 segment 1

  • 2.1: Module 2 segment 1

clear afo stats

This command clears the statistics of an Active Fail-Open kit.

Syntax

clear afo stats <all|module<1|2>|port <1.1.mon0|1.1.mon1|1.1.net0|1.1.net1|2.1.mon0|2.1.mon1|2.1.net0|2.1.net1|>|segment<1.1|2.1>>

Parameter

Description

all

All statistics of the Active Fail-Open kit

module <1|2>

All statistics of the Active Fail-Open module 1 and 2

port <1.1.mon0|1.1.mon1|1.1.net0|1.1.net1|2.1.mon0|2.1.mon1|2.1.net0|2.1.net1|>

Statistics of the following Active Fail-Open monitor and network ports:

  • 1.1.mon0: Module 1 segment 1 monitor port 0

  • 1.1.mon1: Module 1 segment 1 monitor port 1

  • 1.1.net0: Module 1 segment 1 network port 0

  • 1.1.net1: Module 1 segment 1 network port 1

  • 2.1.mon0: Module 1 segment 1 monitor port 0

  • 2.1.mon1: Module 1 segment 1 monitor port 1

  • 2.1.net0: Module 1 segment 1 network port 0

  • 2.1.net1: Module 1 segment 1 network port 1

segment <1.1|2.1>

Statistics of the Active Fail-Open segment

  • 1.1: Module 1 segment 1

  • 2.1: Module 2 segment 1

cli clear-history

This command clears the CLI command history for the current user.

Syntax

cli clear-history

clock set date

This command sets the system date.

Syntax

clock set date <yyyy-mm-dd>

Parameter

Description

<yyyy-mm-dd>

Set the year, month, and date for the system date.

clock set time

This command sets the system time.

Syntax

clock set time <hh:mm:ss>

Parameter

Description

<hh:mm:ss>

Set the exact hour, minute, and seconds for the system time.

clock timezone

This command sets the system time zone area.

Syntax

clock timezone <region> area <place>

Parameter

Description

<region>

Select the region for the timezone from the list available.

<place>

For the region selected, select the place from the list available.

com speed

This command sets the serial console speed.

Syntax:

com speed <speed>

Parameter

Description

<speed>

Speed setting of 9600, 34800, or 115200

Note

115200 is the default speed value for a 100G Active Fail-Open Chassis.

configurations reset

This command resets the system to default configurations.

Syntax:

configurations reset

configurations restore

This command restores the system configuration from a saved configuration file.

Syntax:

configurations restore <temp_afo_100G| is_config_yyyymmddHHMMSS>

Parameter

Description

temp_afo_100G

File name when the configuration file is saved without using the default file name

is_config_yyyymmddHHMMSS

Each time the current configurations are saved, the default file name is used with the current date and time.

configurations save

This command saves the current configuration to a file with a default file name is_config_yyyymmddHHMMSS.

Syntax:

configurations save

configurations upload

This command uploads a configuration file with a default file name is_config_yyyymmddHHMMSS from SCP or FTP server.

Syntax:

configurations upload <url>

Parameter

Description

url

Uses url, such as http://xxx/file or scp://xxx@x.x.x.x: /path/file

dump create log

This command creates a system log dump file.

Syntax:

dump create log

dump delete

This command deletes the selected dump file from the system.

Syntax:

dump delete is_log_<yyyymmddHHMMSS>.tar.gz

enable/disable

This command enables or disables administrator privileges. By default, it is disabled.

Syntax:

IS100G_AFO>enable

IS100G_AFO#disable

exit

This command is used to exit the CLI.

Syntax:

exit

log level

This command sets the system log level.

Syntax:

log level <debug|info|notice|warn|err|crit|alert|emerg>

Parameter

Description

debug

System log level is set to debug level.

info

System log level is set to information level.

notice

System log level is set to notice level.

warn

System log level is set to warning level.

err

System log level is set to error level.

crit

System log level is set to critical level.

alert

System log level is set to alert level.

emerg

System log level is set to emergency level.

log max-size

This command sets the maximum size of the log file.

Syntax:

log max-size <1-10>

Parameter

Description

1–10 MB

An integer value between 1 MB and 10 MB

log remote

This command enables or disables the remote log.

Syntax:

log remote <disable|enable>

Parameter

Description

disable

Disables the remote log

enable

Enables the remote log

log remote server

This command sets the IP address of the remote log server.

Syntax:

log remote server <IP address>

Parameter

Description

IP address

Host name or IP address of the remote log server

log reset

This command resets all system logs.

Syntax:

log reset

management eth-if

This command sets the IP address, network mask, default gateway, etc. for the management interface.

Syntax:

management eth-if <default-gateway|enable|ip|ip-mask>

Parameter

Description

default-gateway

IP address of the default gateway for the management interface

enable

Enable management interface.

ip

IP address for the management interface

ip-mask

IP address of the network mask for the management interface

management whoami

This command turns on/off the Sys Ok LED in the chassis.

Syntax:

management whoami <on|off>

Parameter

Description

on

Turns on the Sys Ok LED: Blinking green

off

Turns off the Sys Ok LED

name

This command sets the device name.

Syntax:

name <hostname>

Parameter

Description

hostname

Use the following parameters for the hostname:

  • 26 alpha: Upper and lowercase (a,b,c,...z and A, B, C,...Z)

  • 10 digits: 0 1 2 3 4 5 6 7 8 9

  • 2 symbols: _ .

reload

This command reboots the Active Fail-Open Chassis.

Note

To reboot the chassis, you must have administrator privileges which are available in the enable mode.

Syntax:

reload

reset

This command resets the system to default factory settings.

Syntax:

reset

session expired-time

This command sets the CLI session's expiry time.

Syntax:

session expired-time <0|1-2147483647>

Parameter

Description

0

Disables the session expired-time

1–2147483647

The session expired-time ranges from 1 second to 21474483647 seconds

show afo state

This command displays the AFO kit's Module and Segment status, followed by the Port transceiver information.

Syntax:

show afo state

Sample Output:

               IS100G_AFO> enable
               IS100G_AFO# show afo state
               Module 1 Status:
               Type                  : IAC-2P100FOSR-KIT
               SerialNumber          : N/A
               TrackingNumber        : N/A
               Firmware              : IS100G_AFO_MOD_1.0
               Speed                 : 100G
               Media                 : 100GBase-SR4
               Transceiver           : QSFP28 SR4
               Segment 1.1 Status:
               HbChecking            : on
               HbCheckingOffReason   : none
               ApplicationState      : active
               ActiveState           : inline
               PassiveState          : inline
               TwoPortLinkTriggered  : no
               RX/TX Error Occurred  : yes
               PortNet0Link          : up
               PortNet1Link          : up
               PortMon0Link          : up
               PortMon1Link          : up
               PortNet0Health        : normal
               PortNet1Health        : normal
               PortMon0Health        : normal
               PortMon1Health        : normal
               SegmentSpeed          : 100G
               Port transceiver information:
               Name        TransceiverPN           TransceiverSN
               net0        FTLC9551REPM            XXF0G86
               net1        FTLC9551REPM            XXF0CM1
               mon0        AFBR-89CDDZ-CS1         AVF2111G1JE
               mon1        FTLC9551REPM            X0SAGXM
               Module 2 Status:
               Type                  : IAC-2P100FOSR-KIT
               SerialNumber          : T0B7932005
               TrackingNumber        : E135361100011
               Firmware              : IS100G_AFO_MOD_1.0
               Speed                 : 100G
               Media                 : 100GBase-SR4
               Transceiver           : QSFP28 SR4
               Segment 2.1 Status:
               HbChecking            : on
               HbCheckingOffReason   : none
               ApplicationState      : active
               ActiveState           : inline
               PassiveState          : inline
               TwoPortLinkTriggered  : no
               RX/TX Error Occurred  : no
               PortNet0Link          : up
               PortNet1Link          : up
               PortMon0Link          : up
               PortMon1Link          : up
               PortNet0Health        : normal
               PortNet1Health        : normal
               PortMon0Health        : normal
               PortMon1Health        : normal
               SegmentSpeed          : 100G
               Port transceiver information:
               Name        TransceiverPN           TransceiverSN
               net0        FTLC9551REPM            X0MAN8R
               net1        FTLC9551REPM            X0MAP03
               mon0        AFBR-89CDDZ-CS1         X0SAGYG
               mon1        FTLC9551REPM            XVD0B3R
            

show afo state module

This command displays the current status of an Active Fail-Open module.

Syntax:

show afo state module <1/2>

Parameter

Description

1

The current status of the Active Fail-Open module 1

2

The current status of the Active Fail-Open module 2

Sample Output:

IS100G_AFO(config)# show afo state module 1

Module 1 Status:

Type : IAC-2P100FOSR-KIT

SerialNumber : N/A

TrackingNumber : N/A

Firmware : IS100G_AFO_MOD_1.0

Speed : 100G

Media : 100GBase-SR4

Transceiver : QSFP28 SR4

show afo state segment

This command displays the status of an Active Fail-Open segment.

Syntax:

show afo state segment <1.1|2.1>

Parameter

Description

1.1

Module 1 segment 1

2.1

Module 2 segment 1

Sample Output:

IS100G_AFO(config)# show afo state segment 1.1

Segment 1.1 Status:

HbChecking : on

HbCheckingOffReason : none

ApplicationState : active

ActiveState : inline

PassiveState : inline

TwoPortLinkTriggered : no

RX/TX Error Occurred : yes

PortNet0Link : up

PortNet1Link : up

PortMon0Link : up

PortMon1Link : up

PortNet0Health : normal

PortNet1Health : normal

PortMon0Health : normal

PortMon1Health : normal

SegmentSpeed : 100G

show afo stats segment

This command displays the statistics of an Active Fail-Open segment.

Syntax:

show afo stats segment <1.1|2.1>

Parameter

Description

1.1

Module 1 segment 1

2.1

Module 2 segment 1

Sample Output:

IS100G_AFO(config)# show afo stats segment 1.1

Port 1.1.net0 Accumulate Statistics:

RxPkts : 1080974939617

RxOctets : 2979243138312184

RxPktGood : 1080974939617

RxUnicastPkts : 1080974939617

RxMulticastPkts : 0

RxBroadcastPkts : 0

RxErrors : 0

RxDiscards : 0

TxPkts : 1766597576376

TxOctets : 2965528500585946

TxPktGood : 1766597576376

TxUnicastPkts : 1766597576376

TxMulticastPkts : 0

TxBroadcastPkts : 0

TxErrors : 0

TxDiscards : 0

Port 1.1.net0 Realtime Statistics:

RxPkts : 536472

RxOctets : 1864061376

RxPktGood : 536472

RxUnicastPkts : 536472

RxMulticastPkts : 0

RxBroadcastPkts : 0

RxErrors : 0

RxDiscards : 0

TxPkts : 1103687

TxOctets : 1852722738

TxPktGood : 1103687

TxUnicastPkts : 1103687

TxMulticastPkts : 0

TxBroadcastPkts : 0

TxErrors : 0

TxDiscards : 0

RxUsage : 14.99%

TxUsage : 14.99%

show cli

This command displays the current auto logout time in seconds.

Syntax:

show cli

Sample Output:

IS100G_AFO> show cli

CLI Current auto logout time(s): 10000

show clock

This command displays the system date and time.

Syntax:

show clock

Sample Output:

IS100G_AFO> show clock

Current Clock:

Tue Sep 17 08:31:09 UTC 2022

show com configured

This command displays the RS232 port configuration.

Syntax:

show com configured

Sample Output:

IS100G_AFO> show com configured

Com Console Configuration:

Speed : 115200

Terminal Type : vt100

show configurations detail

This command displays the system configuration in detail.

Syntax:

show configurations detail <select from list>

Parameter

Description

<select from list>

Lists all the saved system configuration files

Sample Output:

IS100G_AFO(config)# show configurations detail is_config_20220801204702

#Device type: IS100G_AFO

management eth-if ip 10.1.8.12

management eth-if default-gateway 10.1.8.252

tacacs enable

tacacs server 1 ip 10.1.99.94 port 49 secret 12345678

user name Trellix00 full-name normal encrypt-password JDYkMkhtZ3BBZjJYRU5pWVBiUSRCWWJsLmwxS1RjQUM0ajFFaFZJY1VJTDJxMmNjMmMmM25wQUlyTzB4a2QuQzNBSi5sV0Y1TUk4cS9od0ZwSEZSQ2= privilege admin

user name admin full-name admin encrypt-password JDYkeWRFa1V2RFJwRkV3T2ZSSCQyNVFpQkc2VjRaTzE4NFowTFh2Ukcx0a05PZE14RTFKM1NnZHY0d1Vmci83b= privilege admin

snmp user Trellix00 password Trellix00 sha

snmp user Trellix00 enable

snmp user Trellix00 read-only

snmp host 10.1.8.20 v2c community Trellix00

snmp host 10.1.2.11 v3 user Trellix00 password Trellix00 sha

snmp host 10.1.8.21 v1 community Trellix00

bypass port-link 1.1.3 fec enable

bypass port-link 1.1.4 fec enable

afo segment 1.1 hb hold-time 30

bypass port-link 2.1.3 fec enable

bypass port-link 2.1.4 fec enable

afo segment 2.1 hb hold-time 30

snmp apply

#Fingerprint NThkOTBiOGM1NzM2NDMwNDljZjQ5YzgwZDFhMGIzYjEK

pl

show configurations list

This command displays the system configuration file list.

Syntax:

show configurations list

Sample Output:

IS100G_AFO(config)# show configurations list

2022-08-01 20:47:02 is_config_20220801204702

2022-08-01 20:43:50 Temp_afo_100G

2022-08-01 20:31:50 is_config_20220801203150

show device

This command displays the device information.

Syntax:

show device

Sample Output:

IS100G_AFO> show device

Device Information:

DeviceType : IAC-AFOCH100-KT2

DeviceSerialNumber : T0B7932002

DeviceTrackingNumber : E134211200003

HardwareVersion : 0120

FirmwareVersion : IS100G_AFO_FW_18.0

SwitchVersion : IS100G_AFO_2.1.0.0_BUILD_b77b3c90

UbootVersion : IS100G_AFO_UBOOT_1.0_2015_09_29

PowerSupply1 : up

PowerSupply2 : up

AlarmLED : off

WhoAmI : off

show dump

This command displays the system dump file list.

Syntax:

show dump

Sample Output:

IS100G_AFO(config)# show dump

is_core_20220805055957.tar.gz

is_core_20220805055655.tar.gz

show health

This command displays the fan status of an Active Fail-Open module.

Syntax:

show health

Sample Output:

IS100G_AFO> show health

Fan State:

ID Name Speed(RPM) Status RunTime(H) Fault Warning

1 FN11 17045 green 1620 no no

2 FN12 17201 green 1620 no no

3 FN13 15690 green 1619 no no

4 FN14 17123 green 1620 no no

show log

This command displays the latest Active Fail-Open logs.

Syntax:

show log

Sample Output:

IS100G_AFO(config)# show log

2022-08-12T08:57:09.125350+00:00 IS100G_AFO sshd[24085]:[authpriv.notice] pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=10.37.111.20 user=root

2022-08-12T08:57:18.673165+00:00 IS100G_AFO sshd[24085]:[auth.err] error: PAM: Authentication failure for illegal user root from 10.37.111.20

2022-08-12T21:22:34.342216+00:00 IS100G_AFO lua:[user.notice] Web login as user Trellix00

2022-08-12T02:58:56.931966+00:00 IS100G_AFO lua:[user.notice] Web login as user Trellix00

2022-08-12T07:13:32.575128+00:00 IS100G_AFO sshd[24644]:[authpriv.notice] pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=10.37.111.20 user=root

2022-08-121T07:13:34.247587+00:00 IS100G_AFO sshd[24642]:[auth.err] error: PAM: Authentication failure for illegal user root from 10.37.111.20

2022-08-12T07:13:34.363007+00:00 IS100G_AFO sshd[24642]:[authpriv.notice] pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=10.37.111.20 user=root

2022-08-12T07:13:38.015370+00:00 IS100G_AFO sshd[24642]:[auth.err] error: PAM: Authentication failure for illegal user root from 10.37.111.20

2022-08-12T00:46:24.361085+00:00 IS100G_AFO is_switchd:[user.notice] Segment 1.1 Appliance failed

2022-08-12T00:46:24.361124+00:00 IS100G_AFO is_switchd:[user.notice] Segment 1.1 OP Mode < INLINE> => < BYPASS>

2022-08-12T00:46:24.404319+00:00 IS100G_AFO is_switchd:[user.notice] Segment 1.1 MON0: link down

2022-08-12T00:46:24.404344+00:00 IS100G_AFO is_switchd:[user.notice] Segment 1.1 set mode, mode is already BYPASS

2022-08-12T00:46:24.624304+00:00 IS100G_AFO is_switchd:[user.notice] Segment 1.1 MON1: link down

2022-08-12T00:46:24.624345+00:00 IS100G_AFO is_switchd:[user.notice] Segment 1.1 set mode, mode is already BYPASS

2022-08-12T06:32:26.103054+00:00 IS100G_AFO sshd[9870]:[authpriv.notice] pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=10.37.111.20 user=root

2022-08-12T06:32:28.748828+00:00 IS100G_AFO sshd[9730]:[auth.err] error: PAM: Authentication failure for illegal user root from 10.37.111.20

2022-08-12T06:32:28.922444+00:00 IS100G_AFO sshd[9730]:[authpriv.notice] pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=10.37.111.20 user=root

2022-08-12T06:32:33.932554+00:00 IS100G_AFO sshd[9730]:[auth.err] error: PAM: Authentication failure for illegal user root from 10.37.111.20

2022-08-12T01:07:28.444372+00:00 IS100G_AFO is_switchd:[user.notice] Segment 1.1 port MON0 link up

2022-08-12T01:07:29.164278+00:00 IS100G_AFO is_switchd:[user.notice] Segment 1.1 port MON1 link up

2022-08-12T01:08:00.344320+00:00 IS100G_AFO is_switchd:[user.notice] Segment 1.1 MON1: link down

2022-08-12T01:08:00.344348+00:00 IS100G_AFO is_switchd:[user.notice] Segment 1.1 set mode, mode is already BYPASS

is_tmplogFANefPfn

show log configured

This command displays the system configurations of log level, maximum log file size, remote log, and log remote server.

Syntax:

show log configured

Sample Output:

IS100G_AFO(config)# show log configured

Log Configuration:

Level : notice

Max Size : 5

Remote Log : disable

Log Remote Server: None

show log realtime

This command displays the current log status for an Active Fail-Open module.

Syntax:

show log realtime

Sample Output:

IS100G_AFO(config)# show log realtime

2022-08-30T23:50:23.975115-07:00 IS100G_AFO_SCQA_88 lua:[user.notice] Web login as user Trellix00

2022-08-31T00:25:01.035161-07:00 IS100G_AFO_SCQA_88 lua:[user.notice] Web login as user Trellix00

2022-08-31T02:25:41.680490-07:00 IS100G_AFO_SCQA_88 sshd[26015]:[authpriv.warning] pam_unix(sshd:auth): check pass; user unknown

2022-08-31T02:25:41.680634-07:00 IS100G_AFO_SCQA_88 sshd[26015]:[authpriv.notice] pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=10.207.146.202

2022-08-31T02:25:41.680765-07:00 IS100G_AFO_SCQA_88 sshd[26015]:[authpriv.warning] pam_unix(sshd:auth): check pass; user unknown

2022-08-31T02:25:48.908468-07:00 IS100G_AFO_SCQA_88 sshd[26015]:[auth.err] error: Received disconnect from 10.207.146.202 port 49677:13: User request [preauth]

2022-08-31T02:25:48.908616-07:00 IS100G_AFO_SCQA_88 sshd[26015]:[authpriv.notice] PAM 1 more authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=10.207.146.202

2022-08-31T02:26:02.270118-07:00 IS100G_AFO_SCQA_88 sshd[27502]:[authpriv.info] pam_unix(sshd:session): session opened for user Trellix00 by (uid=0)

2022-08-31T03:13:05.581467-07:00 IS100G_AFO_SCQA_88 sshd[20310]:[authpriv.notice] pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=10.207.149.135 user=Trellix00

2022-08-31T03:13:43.233471-07:00 IS100G_AFO_SCQA_88 sshd[20310]:[authpriv.info] pam_unix(sshd:session): session opened for user Trellix00 by (uid=0)

show management configured

This command displays the network configuration of the Active Fail-Open module.

Syntax:

show management configured

Sample Output:

IS100G_AFO> show management configured

Interface Configurations:

MacAddr : 00:e0:ef:9a:ef:90

Port : up

IPOrigin : static

IPAddress : 10.1.8.12

IPMask : 255.255.255.0

Default-Gateway : 10.1.8.252

DHCPSendName : on

show ntp configured

This command displays the current NTP configuration.

Syntax:

show ntp configured

Sample Output:

IS100G_AFO(config)# show ntp configured

NTP Configuration:

Enabled : disable

NTP Server: None

show running-config

This command displays the configuration running on the Active Fail-Open chassis.

Syntax:

show running-config

Sample Output:

IS100G_AFO(config)# show running-config

session expired-time 10000

management eth-if ip 10.11.08.12

management eth-if default-gateway 10.11.08.252

user name Trellix00 full-name user encrypt-password JDYkZk1sb0ZJTkdSckwwNDNxSiRjYVZIM21UOFk3VlguwbFRKT0pSRElFb1lTY1BsSk1QdG5nQnB4VkkyVXhLa1Fmei9kclU5NF c4Qzd5YlB3c0lncFFZQ0lBNUh3OXlBcU54Lgo= privilege admin

bypass port-link 1.1.1 fec enable

bypass port-link 1.1.2 fec enable

bypass port-link 1.1.3 fec enable

bypass port-link 1.1.4 fec enable

show session

This command displays the current users logged in through the SSH and web interface.

Syntax:

show session

Sample Output:

IS100G_AFO> show session

Connected Sessions:

ID Username Type LoginTime LoginIP LoginPort

1 Trellix00 SSH 2022-08-31 03:14:10 10.207.149.135 52626

2 Trellix00 SSH 2022-08-31 02:26:03 10.207.146.202 51246

3 Trellix00 WEB 2022-08-30 23:50:23 10.207.159.130

show session configured

This command displays the session expired time of the system.

Syntax:

show session configured

Sample Output:

IS100G_AFO(config)# show session configured

Session Expired Time(s): 6000

show snmp configured

This command displays the SNMP server state, SNMP v3 user, SNMP trap host, and SNMP trap control configuration.

Syntax:

show snmp configured

Sample Output:

IS100G_AFO# show snmp configured

SNMP Server Configured State: enable

SNMP v3 User Configuration: None

SNMP Trap Host Configuration: None

SNMP Trap Control Configuration:

AppFail : off

Bypass : off

MON-Link : off

NET-Link : off

Error : off

show snmp engineID

This command displays the SNMP server engine ID of the local system.

Syntax:

show snmp engineID

Sample Output:

IS100G_AFO# show snmp engineID

SNMP Server Engine ID: 0x80001e88802c57e3605c6729b0

show ssh configured

This command displays the current SSH configuration.

Syntax:

show ssh configured

Sample Output:

IS100G_AFO# show ssh configured

SSH Configuration:

State : enable

Port : 22

show tacacs configured

This command displays the basic configuration and server configuration of the TACACS+ user.

Syntax:

show tacacs configured

Sample Output:

IS100G_AFO# show tacacs configured

TACACS+ Basic Configuration:

State : disable

LocalLogin : enable

Timeout : 5

ServiceTag : trellix-system

TACACS+ Server Configuration: None

show uptime

This command displays the number of days the system was last rebooted.

Syntax:

show uptime

Sample Output:

IS100G_AFO(config)# show uptime

System Uptime:

up 19 days, 9:42, load average: 1.39, 1.40, 1.51

show users

This command displays a list of user accounts with their full name and privilege.

Syntax:

show users

Sample Output:

IS100G_AFO(config)# show users

User Privilege FullName

Trellix00 admin Default administrator

show version

This command displays the current and backup software versions in the system.

Syntax:

show version

Sample Output:

IS100G_AFO> show version

Current booting bank: 1

Software current version: IS100G_AFO_2.1.0.0_BUILD_b77b3c90

Software backup version: IS100G_AFO_1.0.5.0_BUILD_8363

uboot version: IS100G_AFO_UBOOT_1.0_2015_09_29

fman version: IS100G_AFO_FMAN_1.0_2015_09_09

rcw version: IS100G_AFO_RCW_1.0_2005_09_09

Vendor: Trellix

show web configured

This command displays the current expire time of the web interface.

Syntax:

show web configured

Sample Output:

IS100G_AFO# show web configured

Session Configuration:

Expired Time : 7200

upgrade file-url

This command upgrades the system from an HTTP or SCP url.

Syntax:

upgrade file-url <url>

Parameter

Description

url

Uses url, such as http://xxx/file or scp://xxx@x.x.x.x: /path/file

User

This command creates a local user.

Syntax:

user name <user name> full-name < full-name> password <Password> privilege <readonly|normal|admin>

Parameter

Description

user name

Provide a name for the local user.

Note

A maximum of 31 characters can be used which should be in lowercase only.

full-name

Provide the user description.

password

Provide the user password in plain text.

Note

A maximum of 40 characters can be used.

readonly

User with just read only privilege - Access to all show commands.

normal

User with normal privileges - Access to all commands, except the commands available only to the administrator.

admin

User with administrator privileges - Access to all commands.

write memory

This command saves each configuration made in the system to the memory.

Syntax:

write memory