The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Replacing a member of a Network Security HA pair using the CLI

Prev Next

Use the commands in this section to replace a member of a Network Security HA pair.

To replace a member of a Network Security HA pair:
  1. Log in to the Central Management System CLI.

  2. Enable the CLI configuration mode:

    hostname > enable
    hostname # configure terminal
    hostname (config) #
  3. Create the pair again, but specify the name of the replacement member instead of the existing member:

    hostname (config) # cmc ha nx <pair> appliances <existingMember> <replacementMember> enable-nx-ipv6

    where <existingMember> is the name of the appliance you want to keep in the pair, <replacementMember> is the name of the appliance that will replace the other appliance in the pair, and enable-nx-ipv6 allows the Central Management System appliance to enable IPv6 on the two appliances. (The appliance name is displayed in theshow cmc appliances command output).

  4. Verify your change:

    hostname (config) # show cmc ha nx <pair>
  5. Save your change:

    hostname (config) # write memory
Example

The following example replaces nx-2 with nx-3 in the Acme_NXHA pair.

hostname (config) # show cmc ha nx Acme_NXHA
NX-HA Acme_NXHA nx-1 nx-2       Status: OK
...
hostname (config) #cmc ha nx Acme_NXHA appliances nx-1 nx-3 enable-nx-ipv6
hostname (config) # show cmc ha nx Acme_NXHA
NX-HA Acme_NXHA nx-1 nx-3        Status: OK
...