It displays the communication details that happened between the Sensor and the Manager instance at the time of Sensor registration. You can use this command to check if the Sensor is successfully registered with the Manager.
Type the command in the CLI as shown in the Syntax below.
Syntax:
show cloud-cluster registration trace
Sample Output:
intruShell@Jason-611u-10.150.10.68> show cloud-cluster registration trace
validating shared secret: begin
validating shared secret key: end
validating userdata: begin
User data validation succesful, Userdata: 10.150.10.52 Jason
{"cluster_name":"Jason", "cloud_uuid":"i-074b66789xxxxx", "sensor_name":"Jason-611u-10.150.10.68", "sensor_ip":"10.150.10.68", "cloud_env":"aws", "hmac":"Osy5+mOXm9HZeTd6XiqL1xxxx="}
* Closing connection -1
curl: (3) URL using bad/illegal format or missing URL
* Trying 10.150.10.52:443...
* TCP_NODELAY set
* Connected to 10.150.10.52 (10.150.10.52) port 443 (#0)
* Cipher selection: ALL:!EXPORT:!EXPORT40:!EXPORT56:!aNULL:!LOW:!RC4:@STRENGTH
* TLSv1.2 (OUT), TLS header, Certificate Status (22):
} [5 bytes data]
* TLSv1.2 (OUT), TLS handshake, Client hello (1):
...
* SSL connection using TLSv1.2 / ECDHE-RSA-AES256-GCM-SHA384
* ALPN, server did not agree to a protocol
* Server certificate:
* subject: emailAddress=root@localhostSS; CN=localhostSS; OU=Intrusion Prevention Systems; O=Trellix; L=Santa Clara; ST=CA; C=US
* start date: Jan 10 07:07:12 2023 GMT
* expire date: Jan 7 07:07:12 2033 GMT
* issuer: emailAddress=root@localhostSS; CN=localhostSS; OU=Intrusion Prevention Systems; O=Trellix; L=Santa Clara; ST=CA; C=US
* SSL certificate verify result: self signed certificate (18), continuing anyway.
} [5 bytes data]
> POST /com/api/v1/vnsp/sensor HTTP/1.1
> Host: 10.150.10.52
> User-Agent: curl/7.68.0
> Accept: */*
> Content-Type:application/json
> Content-Length: 188
>
} [188 bytes data]
* upload completely sent off: 188 out of 188 bytes
{ [5 bytes data]
* Mark bundle as not supporting multiuse
< HTTP/1.1 200
< Strict-Transport-Security: max-age=31536000;includeSubDomains
< X-Frame-Options: SAMEORIGIN
< X-Content-Type-Options: nosniff
< X-XSS-Protection: 1; mode=block
< Content-Type: application/json
< Content-Length: 27
< Date: Mon, 23 Jan 2023 06:22:52 GMT
< Server:
<
{ [27 bytes data]
* Connection #0 to host 10.150.10.52 left intact
HTTP/1.1 200
Strict-Transport-Security: max-age=31536000;includeSubDomains
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Content-Type: application/json
Content-Length: 27
Date: Mon, 23 Jan 2023 06:22:52 GMT
Server:
{"data":null,"status":"OK"}
REGISTERED NSM: 10.150.10.52
Applicable to: Virtual IPS Sensors