NSX CLI Guide

Associated Commands:

CLI Description Command

Display the specified firewall address set


Display the specified firewall address set for the logical router interface.
get firewall <dpd-uuid-firewall-port-arg> addrset name <string-arg>

Display all the firewall address sets


Display all the firewall address sets for the logical router interface.
get firewall <dpd-uuid-firewall-port-arg> addrset sets

Display the specified firewall attribute set


Display the specified firewall attribute set for the logical router interface.
get firewall <dpd-uuid-firewall-port-arg> attrset name <string-arg>

Display all the firewall attribute sets


Display all the firewall attribute sets for the logical router interface.
get firewall <dpd-uuid-firewall-port-arg> attrset sets

Display firewall connection information


Display the firewall connections on the specified logical router interface.
get firewall <dpd-uuid-firewall-port-arg> connection

Display firewall connection count


Display the firewall connection count.
get firewall <dpd-uuid-firewall-port-arg> connection count

Display firewall connection information


Display the firewall connections on the specified logical router interface.
get firewall <dpd-uuid-firewall-port-arg> connection raw

Display firewall connection state


Display the state of the firewall connections.
get firewall <dpd-uuid-firewall-port-arg> connection state

Display firewall interface statistics


Display firewall interface statistics for the specified logical router interface.
get firewall <dpd-uuid-firewall-port-arg> interface stats

Display firewall active/standby configuration


Display the active/standby configuration for the firewall on the specified logical router interface.
get firewall <dpd-uuid-firewall-port-arg> sync config

Display firewall synchronization statistics


Display the firewall synchronization statistics.
get firewall <dpd-uuid-firewall-port-arg> sync stats

Display the fixed timeouts for connection events


Display the fixed timeouts for connection events.
get firewall <dpd-uuid-firewall-port-arg> timeouts

Display specific firewall L7 profile info on given Logical Router UUID


Display specific firewall L7 profile information on given Logical Router UUID.
get firewall <dpd-uuid-lrouter-port-arg> l7-profile <uuid-string-arg>

Display specific firewall L7 profile entry stats info on given Logical Router UUID


Display specific firewall L7 profile entry stats information on given Logical Router UUID.
get firewall <dpd-uuid-lrouter-port-arg> l7-profile <uuid-string-arg> stats

Display all firewall L7 profiles info on given Logical Router UUID


Display all firewall L7 profiles information on given Logical Router UUID.
get firewall <dpd-uuid-lrouter-port-arg> l7-profiles

Display all firewall L7 profile entry stats info on given Logical Router UUID


Display all firewall L7 profile entry stats information on given Logical Router UUID.
get firewall <dpd-uuid-lrouter-port-arg> l7-profiles stats

Display IKE policy


Display IKE policy for the specified logical router interface.
get firewall <uuid> ike policy [<rule-id>]

Display firewall rules


Display firewall rules with expanded address sets for the specified logical router interface.
get firewall <uuid> ruleset [type <rule-type>] rules [<ruleset-detail>]

Display firewall rule statistics


Display firewall rule statistics for the specified logical router interface.
get firewall <uuid> ruleset [type <rule-type>] stats

Display firewall address sets


Display firewall address sets
get firewall <vif-uuid-arg> addrsets

Display firewall fqdn attribute of profiles


Display firewall fqdn attribute of profiles.
get firewall <vif-uuid-arg> fqdn

Display firewall attribute profiles


Display firewall attribute profiles.
get firewall <vif-uuid-arg> profile

Display firewall rules


Display firewall rules
get firewall <vif-uuid-arg> ruleset rules

Display firewall interfaces


Display the logical router or switch interfaces which have firewall rules.
get firewall [logical-switch <uuid>] interfaces

Display firewall addresses for the specified address set


Display firewall addresses for the specified address set.
get firewall addrset name <uuid-arg>

Display firewall address sets for the available virtual interface


Display firewall address sets for the available virtual interface.
get firewall addrset sets

Display firewall connection state


Display the state of the firewall connections in the VRF context.
get firewall connection state

Display firewall fqdn attribute of profiles


Display firewall fqdn attribute of profiles.
get firewall context-profile <context-profile-id-arg> fqdn

Display firewall fqdn attribute of profiles


Display firewall fqdn attribute of profiles.
get firewall context-profiles

Display firewall exclude interfaces


Display firewall exclude interfaces.
get firewall exclude

Get the firewall exclusion list


Display the firewall exclusion list.
get firewall exclude-list

Display firewall exclusion


Display firewall exclusions.
get firewall exclusion

Display firewall interface statistics


Display firewall interface statistics for the specified logical router interface in the VRF context.
get firewall interface stats

Display firewall interfaces


Display the logical router or switch interfaces which have firewall rules.
get firewall interfaces

Display firewall sync interfaces


Display sync configuration for logical router interfaces with firewall rules.
get firewall interfaces sync

Display firewall ipfix containers


Display firewall ipfix containers.
get firewall ipfix-containers

Display firewall ipfix filters


Display firewall ipfix filters.
get firewall ipfix-filters

Display firewall ipfix profile configuration


Display firewall ipfix profile configration.
get firewall ipfix-profiles

Display firewall ipfix statistics


Display firewall ipfix statistics.
get firewall ipfix-stats

Display specific firewall L7 profile info based on UUID


Display specific firewall L7 profile information based on UUID.
get firewall l7-profile <uuid-string-arg>

Display specific firewall L7 profile entry stats based on UUID


Display specific firewall L7 profile entry stats information based on UUID.
get firewall l7-profile <uuid-string-arg> stats

Display all firewall L7 profiles info


Display all firewall L7 profiles information.
get firewall l7-profiles

Display all firewall L7 profile entry stats


Display all firewall L7 profile entry stats information.
get firewall l7-profiles stats

Show DFW packet log file contents


Display the contents of the DFW packet log file.
get firewall packetlog

Show last lines of DFW packet log file contents


Display last lines of the DFW packet log file.
get firewall packetlog last <line-count-arg>

Display firewall rule statistics


Display firewall rule statistics.
get firewall rule-stats

Display total firewall rule statistics


Display total firewall rule statistics.
get firewall rule-stats total

Display the summary of firewall rules


Display the summary of firewall rules.
get firewall rules

Display the firewall status


Display the firewall status.
get firewall status

Get the firewall summary


Display the firewall summary.
get firewall summary

Display firewall active/standby configuration


Display the active/standby configuration for the firewall on the specified logical router interface.
get firewall sync config

Display firewall synchronization statistics


Display the firewall synchronization statistics in the VRF context.
get firewall sync stats

Display firewall threshold alarms


Display firewall threshold alarms.
get firewall threshold-alarms

Display firewall thresholds


Display firewall thresholds.
get firewall thresholds

Display firewall VIFs


Display firewall VIFs
get firewall vifs

Display firewall vsipioctl fqdn entries with no debug


Display firewall vsipioctl fqdn entries with no debug.
get firewall vsipioctl <vsip_commands> [<vsip_param>]

Display reputation and category info about URL


Display reputation and category info about URL
get url-classification <url-string-arg>

Set peer configuration for firewall active/standby


Set the peer configuration for active/standby configuration. This configuration happens automatically when firewall rules are added to an active/standby logical router via the NSX Manager web interface or API.

This command should be used for advanced configuration or troubleshooting only.

If you manually configure the active/standby peer on an edge node, you must also configure its peer.

set firewall <dpd-uuid-firewall-port-arg> local-ip <ip-address> sync-peer <nsxa-uuid-lrouter-port-arg> sync-peer-ip <ip-address>

Set mode for firewall synchronization


Set the firewall synchronization mode for active/standby configuration. This configuration happens automatically when firewall rules are added to an active/standby logical router via the NSX Manager web interface or API.

This command should be used for advanced configuration or troubleshooting only.

If you manually configure the active/standby sync, you must correctly configure both edge nodes in the active/standby configuration. One node must be configured as primary and one as secondary. One node must be configured as active, and one as passive.

set firewall <dpd-uuid-firewall-port-arg> sync-rank <fw-primary-arg> sync-mode <fw-active-arg>

Start firewall synchronization for the logical router interface


Start firewall synchronization for the logical router interface. Synchronization happens automatically, but you can optionally start a bulk sync to more quickly synchronize a new or restarted standby router. The sync must be started from the primary router.
start firewall <dpd-uuid-firewall-port-arg> bulk-sync

Stop firewall bulk synchronization for the logical router interface


Stop firewall bulk synchronization for the logical router interface.
stop firewall <dpd-uuid-firewall-port-arg> bulk-sync

Total commands: 61