Layer 2 mode on drops at Switch/NIC ports
Starting with this release of 10.1, layer 2 mode on drops feature provides the capability for Sensor to enter layer 2 mode upon detecting heavy drops at the Switch/NIC ports and prevent network outage. The Sensor monitors the drops periodically. If number of drops exceeds the drop count threshold value in consecutive occurrences and the configured sensitivity level is met, then the Sensor is put in to layer 2 mode.
You can configure the settings for layer 2 mode on drops with set l2OnDrops from Sensor CLI. After configuring the required settings, show l2OnDropsConfig can be used to view the status of Layer2 mode.
For more information, refer IPS CLI enhancements section.
IPS CLI enhancements
The following Sensor CLI commands are added:
| Command | Description |
|---|---|
| show castoreinfo | Displays information like CA store issuer, expiry date, serial number, and fingerprint for the global CA store and Private GTI. |
| show pluggable-module | Displays the status of the pluggable module(s) inserted into the specified slot(s) located within the chassis front panel.
|
| show powersupply | Displays the Sensor power supply information. |
| show transceiver serial-number | Displays the status of the pluggable module(s) inserted into the specified slot(s) of transceiver.
|
| set l2OnDrops | Configures the settings for Layer2 mode on packet drops at Switch/NIC ports. |
| set l2OnDrops sensitivity-level | Configures the sensitivity level for Layer2 mode on drops at Switch/NIC ports. |
| show l2OnDropsConfig | Displays the status configurations of Layer2 mode on drops at Switch/NIC ports. |
| Command | Description |
|---|---|
| importcacertfile | Imports CA cert file from the configured SCP server to the Sensor. The CA cert stores must be in .pem, .cer, or .crt format. |
| set gti filerep cert-check | Enables or disables server certificate validation for private GTI. |
| set gti filerep curl-verbose | Enables or disables curl-verbose log. |
| set gti filerep ro-flag | Enable or disable ro-flag in file reputation query. |
| show gti filerep status | Displays run-time information on the server certificate validation status. |
| show pluggable-module | Displays the status of the pluggable module(s) inserted into the specified slot(s) located within the chassis front panel.
|
| show powersupply | Displays the Sensor power supply information. |
| show transceiver serial-number | Displays the status of the pluggable module(s) inserted into the specified slot(s) of transceiver.
|
The following Sensor CLI commands are updated:
| Command | Description |
|---|---|
| downloadstatus | Displays the status of various download and upload operations from the Manager to Sensor and from the Sensor to Manager. With this release, the CA store status is included. |
| Show gti config | Updated the CLI command to display the GTI REST server URL and proxy settings. |
| layer2 mode | Updated the configuration settings for layer 2 mode. With this release, the syntax and sample output are updated. |
| Command | Description |
|---|---|
| layer2 mode | Updated the configuration settings for layer 2 mode. With this release, the syntax and sample output are updated.
|