The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Creating a Network Security HA pair using the CLI

Prev Next

Use the commands in this section to create a Network Security HA pair.

To create a Network Security HA pair:

  1. Make sure all requirements listed in System requirements have been met.

  2. Log in to the Central Management System CLI.

  3. Enable the CLI configuration mode:

    hostname > enable
    hostname # configure terminal
    hostname (config) #
  4. Create the pair:

    hostname (config) # cmc ha nx <pair> appliances <member1> <member2> enable-nx-ipv6

    where:

    <pair> is a unique name that identifies the Network Security HA pair.

    <member1> and <member2> are the names of the two Network Security appliances that will form the pair. (The appliance names are displayed in the show cmc appliances command output).

    enable-nx-ipv6 allows the Central Management System appliance to enable IPv6 on the two appliances.

  5. (Optional) Add a comment that describes the pair. (See Working with comments for details.)

  6. Synchronize the configuration so the detection settings are identical. (See Synchronizing configuration settings using the CLI.)

  7. Verify your changes:

    hostname (config) # show cmc ha nx
  8. Save your changes

    hostname (config) # write memory
Example

The following example creates a Network Security HA pair named "Acme_NXHA" that includes the "nx-1 and "nx-2" appliances.

hostname (config) # cmc ha nx Acme_NXHA appliances acme-nx1 acme-nx2 enable-nx-ipv6
hostname (config) # cmc ha nx Acme_NXHA comment "Western region NX pair"
hostname (config) # show cmc ha nx
NX-HA Acme_NXHA nx-1 nx-2        Status: OK    
    Comment:                            Western region NX pair
    Connected:                          yes
    Software version match:             yes
    Configuration match:                yes
    GI image version match:             yes
    Security content version match:     yes
    NX health status OK:                yes
    System time in sync:                yes
    Peer id verified:                   yes
    Hardware model match:               yes

Note

See Viewing the Network Security HA status for a description of the output fields.