NSX CLI Guide

Associated Commands:

CLI Description Command

Clear IDS Engine Event stats


clear IDS Engine Event stats.
clear edgeids events stats

Delete all TLS inspection cached certificates


Delete all TLS inspection cached certificates.
clear tls-inspection cached-certificates

Delete TLS inspection cached certificates


Delete TLS inspection cached certificates.
clear tls-inspection cached-certificates <certificate-id-string-arg>

Clear all TLS inspection error stats


Clear all TLS inspection error stats.
clear tls-inspection errors

Clear all TLS inspection traffic stats


Clear all TLS inspection traffic stats.
clear tls-inspection traffic-stats

Writes IDPS filter specific statistics to /var/log/nsx-idps/filter_stats.txt


Writes IDPS filter specific statistics to /var/log/nsx-idps/filter_stats.txt
dump ids filter stats

Display NSX DPI Lib Log Level


Display NSX DPI Lib Log Level.
get dpi lib-dfw logging-level all

Display NSX DPI Log Level


Display NSX DPI Log Level.
get dpi logging-level

Display NSX DPI Statistics


Display NSX DPI Statistics.
get dpi stats

Get IDS Event Engine config stats


Get IDS Event Engine config stats.
get edgeids event-config stats

Get IDS Engine Event stats


Get IDS Engine Event stats.
get edgeids events stats

Display the specified firewall address set


Display the specified firewall address set for the logical router interface.
get firewall <dpd-uuid-firewall-port-arg> addrset name <string-arg>

Display all the firewall address sets


Display all the firewall address sets for the logical router interface.
get firewall <dpd-uuid-firewall-port-arg> addrset sets

Display the specified firewall attribute set


Display the specified firewall attribute set for the logical router interface.
get firewall <dpd-uuid-firewall-port-arg> attrset name <string-arg>

Display all the firewall attribute sets


Display all the firewall attribute sets for the logical router interface.
get firewall <dpd-uuid-firewall-port-arg> attrset sets

Display firewall connection information


Display the firewall connections on the specified logical router interface.
get firewall <dpd-uuid-firewall-port-arg> connection

Display firewall connection count


Display the firewall connection count.
get firewall <dpd-uuid-firewall-port-arg> connection count

Display firewall connection information


Display the firewall connections on the specified logical router interface.
get firewall <dpd-uuid-firewall-port-arg> connection raw

Display firewall connection state


Display the state of the firewall connections.
get firewall <dpd-uuid-firewall-port-arg> connection state

Display firewall interface statistics


Display firewall interface statistics for the specified logical router interface.
get firewall <dpd-uuid-firewall-port-arg> interface stats

Display firewall active/standby configuration


Display the active/standby configuration for the firewall on the specified logical router interface.
get firewall <dpd-uuid-firewall-port-arg> sync config

Display firewall synchronization statistics


Display the firewall synchronization statistics.
get firewall <dpd-uuid-firewall-port-arg> sync stats

Display the fixed timeouts for connection events


Display the fixed timeouts for connection events.
get firewall <dpd-uuid-firewall-port-arg> timeouts

Display specific firewall L7 profile info on given Logical Router UUID


Display specific firewall L7 profile information on given Logical Router UUID.
get firewall <dpd-uuid-lrouter-port-arg> l7-profile <uuid-string-arg>

Display specific firewall L7 profile entry stats info on given Logical Router UUID


Display specific firewall L7 profile entry stats information on given Logical Router UUID.
get firewall <dpd-uuid-lrouter-port-arg> l7-profile <uuid-string-arg> stats

Display all firewall L7 profiles info on given Logical Router UUID


Display all firewall L7 profiles information on given Logical Router UUID.
get firewall <dpd-uuid-lrouter-port-arg> l7-profiles

Display all firewall L7 profile entry stats info on given Logical Router UUID


Display all firewall L7 profile entry stats information on given Logical Router UUID.
get firewall <dpd-uuid-lrouter-port-arg> l7-profiles stats

Display IKE policy


Display IKE policy for the specified logical router interface.
get firewall <uuid> ike policy [<rule-id>]

Display firewall rules


Display firewall rules with expanded address sets for the specified logical router interface.
get firewall <uuid> ruleset [type <rule-type>] rules [<ruleset-detail>]

Display firewall rule statistics


Display firewall rule statistics for the specified logical router interface.
get firewall <uuid> ruleset [type <rule-type>] stats

Display firewall address sets


Display firewall address sets
get firewall <vif-uuid-arg> addrsets

Display firewall fqdn attribute of profiles


Display firewall fqdn attribute of profiles.
get firewall <vif-uuid-arg> fqdn

Display firewall attribute profiles


Display firewall attribute profiles.
get firewall <vif-uuid-arg> profile

Display firewall rules


Display firewall rules
get firewall <vif-uuid-arg> ruleset rules

Display firewall interfaces


Display the logical router or switch interfaces which have firewall rules.
get firewall [logical-switch <uuid>] interfaces

Display firewall addresses for the specified address set


Display firewall addresses for the specified address set.
get firewall addrset name <uuid-arg>

Display firewall address sets for the available virtual interface


Display firewall address sets for the available virtual interface.
get firewall addrset sets

Display firewall connection state


Display the state of the firewall connections in the VRF context.
get firewall connection state

Display firewall fqdn attribute of profiles


Display firewall fqdn attribute of profiles.
get firewall context-profile <context-profile-id-arg> fqdn

Display firewall fqdn attribute of profiles


Display firewall fqdn attribute of profiles.
get firewall context-profiles

Display firewall exclude interfaces


Display firewall exclude interfaces.
get firewall exclude

Get the firewall exclusion list


Display the firewall exclusion list.
get firewall exclude-list

Display firewall exclusion


Display firewall exclusions.
get firewall exclusion

Display firewall interface statistics


Display firewall interface statistics for the specified logical router interface in the VRF context.
get firewall interface stats

Display firewall interfaces


Display the logical router or switch interfaces which have firewall rules.
get firewall interfaces

Display firewall sync interfaces


Display sync configuration for logical router interfaces with firewall rules.
get firewall interfaces sync

Display firewall ipfix containers


Display firewall ipfix containers.
get firewall ipfix-containers

Display firewall ipfix filters


Display firewall ipfix filters.
get firewall ipfix-filters

Display firewall ipfix profile configuration


Display firewall ipfix profile configration.
get firewall ipfix-profiles

Display firewall ipfix statistics


Display firewall ipfix statistics.
get firewall ipfix-stats

Display specific firewall L7 profile info based on UUID


Display specific firewall L7 profile information based on UUID.
get firewall l7-profile <uuid-string-arg>

Display specific firewall L7 profile entry stats based on UUID


Display specific firewall L7 profile entry stats information based on UUID.
get firewall l7-profile <uuid-string-arg> stats

Display all firewall L7 profiles info


Display all firewall L7 profiles information.
get firewall l7-profiles

Display all firewall L7 profile entry stats


Display all firewall L7 profile entry stats information.
get firewall l7-profiles stats

Show DFW packet log file contents


Display the contents of the DFW packet log file.
get firewall packetlog

Show last lines of DFW packet log file contents


Display last lines of the DFW packet log file.
get firewall packetlog last <line-count-arg>

Display firewall rule statistics


Display firewall rule statistics.
get firewall rule-stats

Display total firewall rule statistics


Display total firewall rule statistics.
get firewall rule-stats total

Display the summary of firewall rules


Display the summary of firewall rules.
get firewall rules

Display the firewall status


Display the firewall status.
get firewall status

Get the firewall summary


Display the firewall summary.
get firewall summary

Display firewall active/standby configuration


Display the active/standby configuration for the firewall on the specified logical router interface.
get firewall sync config

Display firewall synchronization statistics


Display the firewall synchronization statistics in the VRF context.
get firewall sync stats

Display firewall threshold alarms


Display firewall threshold alarms.
get firewall threshold-alarms

Display firewall thresholds


Display firewall thresholds.
get firewall thresholds

Display firewall VIFs


Display firewall VIFs
get firewall vifs

Display firewall vsipioctl fqdn entries with no debug


Display firewall vsipioctl fqdn entries with no debug.
get firewall vsipioctl <vsip_commands> [<vsip_param>]

Display NSX IDS Engine Fast Log setting


Display NSX IDS Engine Fast Log setting.
get ids engine alertlog

Display IDS Engine Fast Log setting


Display IDS Engine Fast Log setting.
get ids engine fastlog

Displays all IDS global stats


Displays all IDS global stats.
get ids engine global stats

Display IDS logging level


Displays the IDS logging level.
get ids engine logging-level

Display NSX IDS Engine Log Level


Display NSX IDS Engine Log Level.
get ids engine logging-level

Display IDS profiles


Displays the IDS profiles.
get ids engine profiles

Display NSX IDS Engine Profiles


Display NSX IDS Engine Profiles.
get ids engine profiles

Lists IDS profiles for a specified signature


Displays the IDS profiles for the specified signature.
get ids engine profiles signature <ids-sig-id-arg>

Display NSX IDS Engine Profile statistics


Display NSX IDS Engine Profile statistics.
get ids engine profilestats <profile-id>

Display NSX IDS Enginet Profile status


Display NSX IDS Engine Profile status
get ids engine profilestatus <profile-id>

Display NSX IDS Engine Rules


Display NSX IDS Engine Rules.
get ids engine rules

Get Signature Action for a particular RuleID, ProfileID, SignID


Get Signature Action for a particular RuleID, ProfileID, SignID
get ids engine signaction <rule-id> <profile-id> <sign-id>

Checks for membership and action for a signature-profile pair


Checks for membership and action for a signature-profile pair.
get ids engine signature <ids-sig-id-arg> profile <context-profile-id-arg> membership

Display NSX IDS Engine global statistics


Display NSX IDS Engine global statistics.
get ids engine stats

Display IDS Enable/Disable


Displays the IDS Enable/Disable Status.
get ids engine status

Display NSX IDS Engine Status


Display NSX IDS Engine Status.
get ids engine status

Get IDS Event Engine queue stats


Get IDS Event Engine queue stats.
get ids events queue stats

Get IDS Event Engine stats


Get IDS Event Engine stats.
get ids events stats

Display NSX IDPS filter specific statistics


Display NSX IDPS filter specific statistics.
get ids filter stats <filtername-arg>

Display NSX IDS Log Level


Display NSX IDS Log Level.
get ids logging-level

Display NSX IDS Profiles


Display NSX IDS Profiles.
get ids profiles

Display NSX IDS Rules


Display NSX IDS Rules.
get ids rules

Display NSX IDS Status


Display NSX IDS Status.
get ids status

Display info about Service Insertion


Display information about Service Insertion.
get service-insertion

Display info about Service Insertion


Display information about Service Insertion.
get service-insertion <dpd-uuid-service-insertion-arg>

Display info about NS Service Insertion BFD control status.


Display information about NS Service Insertion BFD control status.
get service-insertion bfd-ctrl

Display info about Service Insertion flow programming table.


Display information about Service Insertion flow programming table.
get service-insertion flow-prog-table

Display info about Service Insertion failed SPI.


Display information about Service Insertion failed SPI.
get service-insertion spi-fail-table

Display info about EW Service Insertion VRF to interface mapping.


Display information about EW Service Insertion VRF to interface mapping.
get service-insertion vrf-to-intf

Display spoof guard config for a host switch and dvport


Display spoof guard config for a host switch and dvport.
get spoof-guard config <hs-name-arg> <dvport-id-arg>

Display Spoof Guard config for a logical port


Displays Spoof Guard config for a logical port.
get spoof-guard config <logical-port>

Display spoof guard stats for a host switch and dvport


Display spoof guard stats for a host switch and dvport.
get spoof-guard stats <hs-name-arg> <dvport-id-arg>

Display Spoof Guard stats for a logical port


Displays Spoof Guard stats for a logical port.
get spoof-guard stats <logical-port>

Display spoof guard whitelist for a host switch and dvport


Display spoof guard whitelist for a host switch and dvport.
get spoof-guard whitelist <hs-name-arg> <dvport-id-arg>

Display Spoof Guard whitelist for a logical port


Displays Spoof Guard whitelist for a logical port.
get spoof-guard whitelist <logical-port>

Display TLS inspection info


Display TLS inspection information.
get tls-inspection

Display TLS inspection action profile details


Display TLS inspection action profile details.
get tls-inspection action-profile <uuid-string-arg>

Display TLS inspection action profile info


Display TLS inspection action profile information.
get tls-inspection action-profiles

Display TLS inspection bypassed sites


Display TLS inspection bypassed sites and the reason.
get tls-inspection bypassed-sites lr-uuid <uuid>

Display TLS inspection bypassed sites


Display TLS inspection bypassed sites and the reason.
get tls-inspection bypassed-sites sr-uuid <uuid>

Display TLS inspection CA bundle details


Display TLS inspection CA bundle details.
get tls-inspection ca-bundle <uuid-string-arg>

Display TLS inspection CA bundle info


Display TLS inspection CA bundle information.
get tls-inspection ca-bundles

Show TLS Inspection Cached Certificate Details


Show TLS Inspection Cached Certificate Details.
get tls-inspection cached-certificate <certificate-id-string-arg>

Display TLS inspection cached certificates


Display TLS inspection cached certificates.
get tls-inspection cached-certificates

Show TLS Inspection Certificate Details


Show TLS Inspection Certificate Details.
get tls-inspection certificate <tls-certificate-id-arg>

Display TLS inspection CRL info


Display TLS inspection CRL information.
get tls-inspection crls

Display revoked certs of a TLS inspection CRL matching a serial number


Display revoked certs of a TLS inspection CRL matching a serial number.
get tls-inspection crls <crl-uuid> certificate-serial-number <certificate-serial-number>

Display revoked certs of a TLS inspection CRL of an issuer


Display revoked certs of a TLS inspection CRL of an issuer.
get tls-inspection crls <crl-uuid> issuer <issuer-SHA256>

Display the revoked cert of a TLS inspection CRL that matches the issuer hash and serial number


Display the revoked cert of a TLS inspection CRL that matches the issuer hash and serial number.
get tls-inspection crls <crl-uuid> issuer <issuer-SHA256> certificate-serial-number <certificate-serial-number>

Display the revoked cert of a TLS inspection CRL that matches the public key hash


Display the revoked cert of a TLS inspection CRL that matches the public key hash.
get tls-inspection crls <crl-uuid> public-key-hash <public-key-hash>

Display the revoked cert of a TLS inspection CRL that matches the subject SHA256 hash


Display the revoked cert of a TLS inspection CRL that matches the subject SHA256 hash.
get tls-inspection crls <crl-uuid> subject <subject-SHA256>

Display the revoked cert of a TLS inspection CRL that matches the subject and public key hash


Display the revoked cert of a TLS inspection CRL that matches the subject and public key hash.
get tls-inspection crls <crl-uuid> subject <subject-SHA256> public-key-hash <public-key-hash>

Display revoked certs of a TLS inspection CRL


Display revoked certs of a TLS inspection CRL.
get tls-inspection crls <uuid-string-arg>

Display TLS inspection global error stats


Display TLS inspection global error stats associated with the routers.
get tls-inspection errors

Display TLS inspection error stats


Display TLS inspection error stats associated with the routers.
get tls-inspection errors lr-uuid <uuid>

Display TLS inspection error stats


Display TLS inspection error stats associated with the routers.
get tls-inspection errors sr-uuid <uuid>

Display TLS inspection logging levels


Display TLS inspection logging levels.
get tls-inspection logging-level

Display TLS inspection rule stats


Display TLS inspection rule stats associated with the routers.
get tls-inspection rule-stats <lr-uuid|sr-uuid>

Display TLS inspection rule stats


Display TLS inspection rule stats associated with the routers.
get tls-inspection rule-stats <lr-uuid|sr-uuid> [<rule-id>]

Display TLS inspection rules brief


Display TLS inspection rules brief associated with the routers.
get tls-inspection rules brief <lr-uuid|sr-uuid>

Display TLS inspection rules brief


Display TLS inspection rules brief associated with the routers.
get tls-inspection rules brief <lr-uuid|sr-uuid> [<rule-id>]

Display TLS inspection status info


Display TLS inspection status information.
get tls-inspection status

Display TLS inspection traffic stats


Display TLS inspection traffic stats associated with the routers.
get tls-inspection traffic-stats lr-uuid <uuid>

Display TLS inspection traffic stats


Display TLS inspection traffic stats associated with the routers.
get tls-inspection traffic-stats sr-uuid <uuid>

Display reputation and category info about URL


Display reputation and category info about URL
get url-classification <url-string-arg>

Configure NSX DPI Lib Log Level


Configure NSX DPI Lib Log Level.
set dpi lib-dfw logging-level <dpi-lib-log-level-arg>

Configure NSX DPI Log Level


Configure NSX DPI Log Level.
set dpi logging-level <dpi-log-level-arg>

Set peer configuration for firewall active/standby


Set the peer configuration for active/standby configuration. This configuration happens automatically when firewall rules are added to an active/standby logical router via the NSX Manager web interface or API.

This command should be used for advanced configuration or troubleshooting only.

If you manually configure the active/standby peer on an edge node, you must also configure its peer.

set firewall <dpd-uuid-firewall-port-arg> local-ip <ip-address> sync-peer <nsxa-uuid-lrouter-port-arg> sync-peer-ip <ip-address>

Set mode for firewall synchronization


Set the firewall synchronization mode for active/standby configuration. This configuration happens automatically when firewall rules are added to an active/standby logical router via the NSX Manager web interface or API.

This command should be used for advanced configuration or troubleshooting only.

If you manually configure the active/standby sync, you must correctly configure both edge nodes in the active/standby configuration. One node must be configured as primary and one as secondary. One node must be configured as active, and one as passive.

set firewall <dpd-uuid-firewall-port-arg> sync-rank <fw-primary-arg> sync-mode <fw-active-arg>

Configure NSX IDS Engine Fast Log.


Configure NSX IDS Engine Fast Log.
set ids engine alertlog <ids-eng-alertlog-arg>

Configure IDS Engine Fast Log.


Configure IDS Engine Fast Log.
set ids engine fastlog <ids-eng-fastlog-arg>

Configure NSX IDS Engine Log Level


Configure NSX IDS Engine Log Level.
set ids engine logging-level <ids-eng-log-level-arg>

Set IDS logging level


Sets the IDS logging level.
set ids engine logging-level <ids-logging-level-arg>

Clear IDS Event Engine stats


clear IDS Event Engine stats.
set ids events stats clear

Configure NSX IDS Log Level


Configure NSX IDS Log Level.
set ids logging-level <ids-log-level-arg>

Set TLS inspection logging level for all destinations


Set TLS inspection logging level for all destinations.
set tls-inspection logging-level <edge-service-logging-level-arg>

Set TLS inspection logging level for a destination


Set TLS inspection logging level for a destination.
set tls-inspection logging-level <edge-service-logging-level-arg> destination <dest-arg>

Start firewall synchronization for the logical router interface


Start firewall synchronization for the logical router interface. Synchronization happens automatically, but you can optionally start a bulk sync to more quickly synchronize a new or restarted standby router. The sync must be started from the primary router.
start firewall <dpd-uuid-firewall-port-arg> bulk-sync

Stop firewall bulk synchronization for the logical router interface


Stop firewall bulk synchronization for the logical router interface.
stop firewall <dpd-uuid-firewall-port-arg> bulk-sync

Total commands: 146