The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Viewing the Network Security HA status using the CLI

Prev Next

Use the commands in this section to view the status of the Network Security HA pair and its members.

To view the status of all pairs:
  1. Log in to the Central Management System CLI.

  2. Enable the CLI enable mode:

    hostname > enable
    hostname #
  3. View the status:

    hostname # show cmc ha nx
To view the status of a specific pair:
  1. Enable the CLI enable mode:

    hostname > enable
    hostname #
  2. View the status:

    hostname # show cmc ha nx <pair>

    where <pair> is the name of the HA pair.

To view the connection status of a member of the pair:
  1. Log in to the Central Management System CLI.

  2. Enable the CLI enable mode:

    hostname > enable
    hostname #
  3. View the status:

    hostname # show cmc appliance <member>

    where <member> is the name of the appliance. (The appliance name is displayed in the show cmc appliances command output).

To view the HA-related status of a member of a pair:
  1. Log in to the Network Security CLI.

  2. Enable the CLI enable mode:

    hostname > enable
    hostname # 
  3. View the status:

    hostname # show ha status
Examples

The following example shows the status of the Acme_NXHA pair:

cm-hostname # show cmc ha nx Acme_NXHA
NX-HA Acme_NXHA: nx-1 nx-2      Status: Degraded
    Comment:                          Western region NX pair
    Connected:                        yes
    Software version match:           yes
    Configuration match:              no
    GI image version match:           yes
    Security content version match:   yes
    NX health status OK:              yes
    System time in sync:              yes
    Peer id verified:                 yes
    Hardware model match:             yes 

The following example shows the status of the nx-1 appliance from the Central Management System CLI:

cm-hostname # show cmc appliance nx-1

Appliance nx-1: (Acme_NXHA)

   Connection status:
      Connected:                   yes (server-initiated)
      Connected failure reason:    None
      Connection broken reason:    None
      Connection last formed:      2015/12/18 21:12:28
      Connection last broken:      2015/12/18 21:12:27
      Last connection attempt:     2015/12/18 21:12:27
      Next connection attempt: 
      Current time:                2015/12/18 23:50:03
      Status check OK:             yes   
      Server username on client:   admin
      Client username on server:   cmcclient
 
  Appliance Status:
      Client software version:     wMPS (wMPS) 7.7.0.432165
      Client software match:       no
      Client software compatible:  yes

      Appliance ID:                0XXXXXXXXXXXXXX
      Product model:               FireEye9450
      Content version:             432.198
      ...

The following example shows the status of the nx-1 appliance from its own CLI. This appliance is the member with the full Network Security product license.

nx-1 # show ha status
        High Availability          :Enabled
        HA Cluster Name            :Acme_NXHA
        HA Peer Name               :nx-2
        HA Peer ID                 :1XXXXXXXXXXX
        HA Status                  :Good
        HA Status Description      :OK
        HA License                 :Full  

The following example shows the status of the nx-2 appliance from its own CLI. This appliance is the member with the restricted Network Security product license.

nx-2 # show ha status
        High Availability          :Enabled
        HA Cluster Name            :Acme_NXHA
        HA Peer Name               :nx-1
        HA Peer ID                 :2XXXXXXXXXXX
        HA Status                  :Good
        HA Status Description      :OK
        HA License                 :Restricted
        HA Grace Period Status     :Disabled
        HA Grace Period Days Left  :90

The following example shows the status of the nx-2 appliance from its own CLI after it was removed from the Network Security HA pair. Removing it from the pair causes the restricted license grace period to be enabled as described in Licensing requirements.

nx-2 # show ha status
High Availability: Disabled

The following example shows the status of the nx-1 appliance from its own CLI while its peer is rebooting. While nx-2 is rebooting, the status of nx-1 is Init Check failed.

nx-1 # show ha status
       High Availability           :Enabled
       HA Cluster Name             :Acme_NXHA
       HA Peer Name                :nx-2
       HA Peer ID                  :1XXXXXXXXXXX
       HA Status                   :Degraded
       HA Status Description       :Init Check failed
       HA License                  :Full