Following new Sensor CLI commands are available:
Normal Mode
| CLI Command
|
Description
|
|
clear ssl outbound urlcache
|
Clears the URL cache generated for outbound SSL traffic where exceptions are set for specific URLs.
|
| set hypervisor server ip
|
Sets the IPv4 or IPv6 address for the hypervisor server.
|
|
show snort config
|
Displays the Snort engine configuration as selected through the Manager.
|
|
show ssl config
|
Shows the configuration details for SSL on the Sensor.
|
| show ssl stats inbound agents
|
Displays the number of Agents connected to the Sensor.
|
| show sslagentaccesscontrol status
|
Displays the SSL Agent status and the number of connections from the Agents to the Sensor.
|
| show suricata enginestats
|
Displays the statistics of the Suricata Snort engine.
|
| show suricata sbstats
|
Displays the rule, packet, and alert statistics of the Suricata Snort engine.
|
| sslagentaccesscontrol resetlist
|
Deletes the entire access list of SSL agents that are configured for accessing the Sensor.
|
Debug Mode
| CLI Command
|
Description
|
|
packetcapture
|
Starts or stops packet capture in VMware NSX, AWS, and Azure Platforms, or uploads captured packet files.
|
| set gzip decode limit
|
Sets maximum size for http response to be decompressed upon gzip encoding.
|
| show ssl stats sensor
|
Displays the Inbound SSL Task connection, packet, and session statistics.
|
| suricata
|
Enables or disables packet forwarding to the Suricata engine.
|
Following Sensor CLI commands are updated:
Normal Mode
| CLI Command
|
Description
|
|
clear gti server
|
This command works only for the Public GTI cloud and only when the Private GTI cloud is disabled in the Manager.
|
| resolve gti server
|
This command works only for the Public GTI cloud and only when the Private GTI cloud is disabled in the Manager.
|
| set gtiserver ip
|
This command works only for the Public GTI cloud and only when the Private GTI cloud is disabled in the Manager.
|
| show gti config
|
Output displays both Public and Private GTI could configuation information.
|
| show ssl stats
|
Earlier it displayed information only for the inbound SSL traffic with RSA ciphers. This command now displays infromation related to the outbound SSL traffic and the inbound SSL traffic with the DHE/ECDHE ciphers.
|
Following Sensor CLI commands are removed:
Normal Mode
| CLI Command
|
|
clear tcp-proxy statistics
|
| increasemgmtprocessing
|
| show powersupply
|
Debug Mode
| CLI Command
|
|
clearactiveflows
|
| flashcheck
|
| reset ratelimitstats
|
| show fe stat
|
| show feswitch port
|
| show gmac
|
| show ratelimit drops
|
| show ratelimit markstats
|
For more information, see the
CLI commands section in the
Trellix Intrusion Prevention System Product Guide.