You can view health and status information in the Central Management System and Network Security Web UI and CLI.
Critical messages are displayed under the following conditions:
The Network Security HA pair has fewer than two appliances configured.
Host key authentication failed.
A connection between one or more members and the Central Management System appliance cannot be established.
There is a configuration mismatch between the two members.
Any status other than "Good" in the "HA Status" row in Network Security status fields is present.
Warning messages are displayed under the following conditions:
The system time is not synchronized.
The appliance software versions do not match.
The guest images and versions do not match.
The security content versions do not match.
The Network Security editions do not match.
Important
Failover functionality is disabled and the Network Security appliances function as standalone appliances if the pair has less than two members, if the peer IDs are not verified, or if the hardware models do not match.
Central Management System status fields
The following table describes the output fields displayed in the Central Management System CLI. Some of the values are also displayed in the Network Security Web UI.
Field | Description |
|---|---|
Status | The status of the Network Security HA pair:
|
Comment | Descriptive information about the HA pair, if available. |
Connected | Whether both appliances in the HA pair are connected to the Central Management System appliance. |
Software version match | Whether the following are running on both appliances:
|
Configuration match | Whether all required configuration settings match. |
GI image version match | Whether the same version of guest images is installed on both appliances. |
Security content version match | Whether the same version of security content is installed on both appliances. |
NX health status OK | Whether both appliances are healthy. |
System time in sync | Whether the system time is synchronized. |
Peer id verified | Whether the two appliances exchanged their IDs. |
Hardware model match | Whether both appliances have the same hardware model. |
Network Security status fields
The following table describes the output fields displayed in the Network Security CLI. Some of the values are also displayed in the Central Management System Web UI.
Field | Description |
|---|---|
High Availability | Enabled if the Network Security appliance is in the pair. Disabled if the appliance has never been added to the pair or has been removed from it. |
HA Cluster Name | The name of the HA pair. |
HA Peer Name | The hostname of the other Network Security appliance in the pair. |
HA Peer ID | The unique ID of the other appliance in the HA pair. |
HA Status | The status of the HA pair:
|
HA Status Description | A brief description of the status. |
HA License | Full or Restricted. A full license must be installed on one of the appliances in the pair. A restricted or a full license can be installed on the other appliance. |
HA Grace Period Status | Disabled if the appliance with the restricted license has already been added to the pair. Enabled if the restricted appliance has not been added to the pair. The grace period is 90 days. If the restricted appliance is not added to the pair before the grace period ends, that appliance will lose its detection capabilities. |
HA Grace Period Days Left | The number of days remaining before the grace period ends. This value is reduced by one for each day the appliance is not added to the pair. (If the HA Grace Period Status value is Disabled, the value of this field is always 90.) |
Prerequisites
Monitor, Operator, or Admin access