The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Viewing the Network Security HA status

Prev Next

You can view health and status information in the Central Management System and Network Security Web UI and CLI.

Critical messages are displayed under the following conditions:

  • The Network Security HA pair has fewer than two appliances configured.

  • Host key authentication failed.

  • A connection between one or more members and the Central Management System appliance cannot be established.

  • There is a configuration mismatch between the two members.

  • Any status other than "Good" in the "HA Status" row in Network Security status fields is present.

Warning messages are displayed under the following conditions:

  • The system time is not synchronized.

  • The appliance software versions do not match.

  • The guest images and versions do not match.

  • The security content versions do not match.

  • The Network Security editions do not match.

Important

Failover functionality is disabled and the Network Security appliances function as standalone appliances if the pair has less than two members, if the peer IDs are not verified, or if the hardware models do not match.

Central Management System status fields

The following table describes the output fields displayed in the Central Management System CLI. Some of the values are also displayed in the Network Security Web UI.

Field

Description

Status

The status of the Network Security HA pair:

  • OK—The pair is healthy.

  • Degraded—The pair has one or more conditions indicated by the critical or warning messages listed above.

  • Not Connected—At least one appliance is not connected to the Central Management System appliance.

Comment

Descriptive information about the HA pair, if available.

Connected

Whether both appliances in the HA pair are connected to the Central Management System appliance.

Software version match

Whether the following are running on both appliances:

  • The same major and minor version of the Network Security software image

  • The same Network Security edition (Power or Classic)

Configuration match

Whether all required configuration settings match.

GI image version match

Whether the same version of guest images is installed on both appliances.

Security content version match

Whether the same version of security content is installed on both appliances.

NX health status OK

Whether both appliances are healthy.

System time in sync

Whether the system time is synchronized.

Peer id verified

Whether the two appliances exchanged their IDs.

Hardware model match

Whether both appliances have the same hardware model.

Network Security status fields

The following table describes the output fields displayed in the Network Security CLI. Some of the values are also displayed in the Central Management System Web UI.

Field

Description

High Availability

Enabled if the Network Security appliance is in the pair. Disabled if the appliance has never been added to the pair or has been removed from it.

HA Cluster Name

The name of the HA pair.

HA Peer Name

The hostname of the other Network Security appliance in the pair.

HA Peer ID

The unique ID of the other appliance in the HA pair.

HA Status

The status of the HA pair:

  • Good—The HA pair is healthy.

  • Control port link is down—The control port link is down. If the cable is properly connected, this condition usually clears with no intervention.

  • Data port link is down—The data port link is down. If the cable is properly connected, this condition usually clears with no intervention.

  • Heartbeat not received—Heartbeat messages were not exchanged. This condition usually clears with no intervention.

  • Data port connectivity not connected properly—The data port is not healthy or is not connected to the peer appliance.

  • HA pair is not compatible—The appliances are not running the same version of the Network Security software image.

  • HA model is not compatible—The Network Security appliance hardware models do not match.

  • HA pair is not compatible due to license check—A restricted license is active on both appliances (see "HA License," below).

  • HA peer verification failed—The peer verification failed for one or more of the following reasons: the appliances do not have an established connection between them, the appliance hardware models do not match, the Network Security software images do not match, or a license check failed.

  • Init Check failed—The initial handshake failed, so the appliances cannot communicate with each other. This status usually clears with no intervention.

HA Status Description

A brief description of the status.

HA License

Full or Restricted. A full license must be installed on one of the appliances in the pair. A restricted or a full license can be installed on the other appliance.

HA Grace Period Status

Disabled if the appliance with the restricted license has already been added to the pair. Enabled if the restricted appliance has not been added to the pair. The grace period is 90 days. If the restricted appliance is not added to the pair before the grace period ends, that appliance will lose its detection capabilities.

HA Grace Period Days Left

The number of days remaining before the grace period ends. This value is reduced by one for each day the appliance is not added to the pair. (If the HA Grace Period Status value is Disabled, the value of this field is always 90.)

Prerequisites

  • Monitor, Operator, or Admin access