NSX CLI Guide

Associated Commands:

CLI Description Command

Clear bond interface stats


Clear the LACP stats for the bond interface with the specified name.
clear bond <bond name> stats

Clear cluster api service redirect host


Clear the cluster api service redirect host.
clear cluster api-service redirect-host

Clear Cluster Virtual IPv4 address


Clear Cluster Virtual IPv4 address.
clear cluster vip

Clears both cluster Virtual IPv4 & IPv6 addresses


Clears both cluster Virtual IPv4 & IPv6 addresses.
clear cluster vip all

Clear Cluster Virtual IPv6 address


Clear Cluster Virtual IPv6 address.
clear cluster vip ipv6

Reset flow cache stats for all fastpath cores


Clear flow cache statistics for all fastpath cores.
clear dataplane flow-cache stats

Clear Edge Cluster state history


Clear the Edge cluster state history.
clear edge-cluster history state

Clear flow table for all fastpaths


Clear flow table for all fastpaths
clear ens flow-table

Clear the gateway high availability state history


Clear the high availability state history for the specified gateway. Only service gateways have a high availability status. Use the get gateway command to get a list of gateways and their types.
clear gateway <nsxa-uuid-service-router-arg> high-availability history state

Clear the gateway high availability state history


Clear the high availability state history for the gateway in the VRF context.
clear gateway high-availability history state

Clear stats for a high-availability channel


Clear statistics for the specified high-availability channel
clear high-availability channel local-ip <ip-address> remote-ip <ip-address> stats

Clear stats for high-availability channels


Clear statistics for all high-availability channels.
clear high-availability channels stats

Clear the logical router high availability state history


Clear the high availability state history for the logical router in the VRF context.
clear high-availability history state

Clear stats for a high-availability session


Clear statistics for the specified high-availability session
clear high-availability session local-service-id <service-id-arg> peer-service-id <service-id-arg> stats

Clear stats for high-availability sessions


Clear statistics for all high-availability sessions.
clear high-availability sessions stats

Clear NSX Intelligence flows statistics


Clear NSX Intelligence flows statistics.
clear intelligence flows stats

Deletes LLDP Neighbor information on all devices


Deletes LLDP Neighbor information on all devices.
clear lldp neighbors

Deletes LLDP Neighbor information on given device


Deletes LLDP Neighbor information on given device.
clear lldp neighbors <lldp-interface-name>

Deletes LLDP Statistics on all devices


Deletes LLDP Statistics on all devices.
clear lldp stats

Deletes LLDP Statistics on given device


Deletes LLDP Statistics on given device.
clear lldp stats <lldp-interface-name>

Clear all configured logging-servers


Clear all logging server configuration.
clear logging-servers

Clear the logical router high availability state history


Clear the high availability state history for the specified logical router. Only service routers have a high availability status. Use the get logical-routers command to get a list of logical routers and their router types.
clear logical-router <nsxa-uuid-service-router-arg> high-availability history state

Clean up host state


Deletes all NSX configuration and modules from the host only. Please delete the corresponding transport node entries from NSX manager using GUI/API.
clear management-plane

Clear physical port stats by name


Clear statistics for the specified physical port.
clear physical-port <dpd-name-physical-port-arg> stats

Clear http service redirect host


Clear the HTTP service redirect host.
clear service http redirect-host

Clear install-upgrade service enabled property


Clear the install-upgrade service's enabled property.
clear service install-upgrade enabled

Clear manager service logging levels


Clear the log levels of the manager service.
clear service manager logging-level

Clear NTP service start on boot


Configure the NTP service to not start on boot.
clear service ntp start-on-boot

Clear snmp service start on boot


Configure the snmp service to not start on boot.
clear service snmp start-on-boot

Clear SSH service start on boot


Configure the SSH service to not start on boot.
clear service ssh start-on-boot

Clear SSH Root login property


Disable SSH Root login property
clear ssh root-login

Remove all other management nodes from the cluster


Remove all other management nodes from the cluster. This will effectively convert a multi-node management cluster into a single node setup. The system will prompt for confirmation for this operation. It is recommended to use GSS guidance before using this command.
deactivate cluster

Delete the host's public cloud gateway certificate


Delete the host's public cloud gateway certificate
del gateway certificate <ip-address>

Delete all the host's public cloud gateway certificates


Delete all the host's public cloud gateway certificates
del gateway certificates

Delete NSX Edge service container image


Delete NSX Edge service container image. Only images that are not in use can be deleted.
del image <configurable-image-name> version <configurable-image-version>

Delete logging-server


Delete the specified logging server configuration. You can use the get logging-servers command to display the current logging server configuration.
del logging-server <hostname-or-ip-address[:port]> proto <proto> level <level> [facility <facility>] [messageid <messageid>] [structured-data <structured-data>]

Delete NSX config


Delete NSX config on this node without removing it as transport node from management plane.
del nsx

Delete NSX from host


Destroy NSX environment on this host without removing its transport node from management plane. If there are no resources used by the NSX host switches, this command will delete the host switches and all NSX packages. If there are any resources on the host switches, the resources will first be migrated out of the NSX host switches and then the host switches and all NSX packages will be deleted.
del nsx

Delete NSX config, management IP, logs and filestore


Delete NSX config on this node without removing it as transport node from management plane. Additionally clear logs, filestore and management IP from the node.
del nsx all

Delete NSX from host


Destroy NSX environment on this host without removing its transport node from management plane. If there are no resources used by the NSX host switches, this command will delete the host switches and all NSX packages. If there are any resources on the host switches, the resources will first be migrated out of the NSX host switches and then the host switches and all NSX packages will be deleted. Skips the pre-checks.
del nsx force

Delete SNMP v2 Trap Targets


Delete SNMP v2 Trap Targets.
del snmp v2-targets <hostname-or-ip-address-optional-port-arg>

Delete SNMP v3 Trap Targets


Delete SNMP v3 Trap Targets.
del snmp v3-targets <hostname-or-ip-address-optional-port-arg>

Delete SNMP v3 Users


Delete SNMP v3 Users.
del snmp v3-users <user-id-arg>

Deregister Edge from management plane


Detach this Edge from the management plane.
detach management-plane <hostname-or-ip-address[:port]> username <username> thumbprint <thumbprint> [password <password>]

Detach host from management plane


Detach this hypervisor host from the management plane. You can specify any NSX Manager in the management cluster in this command.

Use the API username and password for the specified NSX Manager. If you do not provide a password on the command line, you will be prompted to enter one.

Get the NSX Manager thumbprint by running the get certificate api thumbprint command on the specified NSX Manager.

detach management-plane <hostname-or-ip-address[:port]> username <username> thumbprint <thumbprint> [password <password>]

Detach specified node from the cluster


Detach the specified node from the cluster.
detach node <node-id-arg>

Detach specified node from the cluster without checking repository-ip modification errors


Detach specified node from the cluster without checking repository-ip modification errors.
detach node <node-id-arg> ignore-repository-ip-check

Get bond interface stats


Display the bond interface with the specified name. Specify the stats argument to display the statistics for the interface.
get bond <bond name> [stats]

Get bond interface stats


Display all bond interfaces. Specify the stats argument to display the statistics for the interfaces.
get bonds [stats]

Display API server certificate


Display the API server's certificate.
get certificate api

Display API server certificate text


Display the API server's certificate text.
get certificate api text

Display API server certificate thumbprint


Display the API server's certificate thumbprint.
get certificate api thumbprint

Display cluster certificate


Display the clsuter certificate.
get certificate cluster

Display cluster certificate text


Display the cluster certificate text.
get certificate cluster text

Display cluster certificate thumbprint


Display the cluster certificate thumbprint.
get certificate cluster thumbprint

Show the cgroup translation


Display the translations for the specified container group. Optionally specify a translation type to display translations of that type.
get cgroup <uuid> [<translation-type>]

Show all existing cgroups


Display all container groups.
get cgroups (Deprecated)

Lookup cgroups for the IP address


Display container groups with the specified IP address.
get cgroups with ip <ip46-address> (Deprecated)

Lookup cgroups for the hardware address


Display container groups with the specified MAC address.
get cgroups with mac <hardware-address> (Deprecated)

Lookup cgroups for the network interface


Display container groups with the specified network interface.
get cgroups with vif <vif-id-arg> (Deprecated)

Display cluster api-service configuration


Display cluster api-service configuration.
get cluster api-service

Get Cluster Config


Get Cluster Config.
get cluster config

Get Cluster Status


Get status of all the groups.
get cluster status

Get Cluster Status


Get status of all the groups. Show leadership if there is any.
get cluster status verbose

Get Cluster Virtual IP


Get Cluster Virtual IP.
get cluster vip

Get dataplane configurations


Display Data Plane Development Kit (DPDK) configurations, which include fastpath cores, hugepage reserved, NUMA, physical port bindings, etc.
get dataplane

Get the cpu stats for dataplane


Display data plane cpu statistics.
get dataplane cpu stats

Get the verbose cpu stats for dataplane


Display verbose data plane cpu statistics.
get dataplane cpu stats verbose

Get the list of supported devices on the system


Get the list of supported devices on the system.
get dataplane device list

Get flow cache configuration


Display the flow cache configurations.
get dataplane flow-cache config

Get flow cache stats for all fastpath cores


Display flow cache statistics for all fastpath cores.
get dataplane flow-cache stats

Get flow cache stats for cores selected in coremask


Display the flow cache statistics for the specified fastpath cores.
get dataplane flow-cache stats <lcore-list-all-arg>

Get geneve critical bit configuration


Display geneve critical bit configurations.
get dataplane geneve-cbit config

Get l2vpn pmtu message generation settings


Display l2vpn pmtu message generation settings.
get dataplane l2vpn-pmtu config

Get the memory stats for dataplane


Display data plane memory statistics.
get dataplane memory stats

Get dataplane perf stats


Display data plane performance statistics.
get dataplane perfstats <interval-arg>

Get dataplane pmtu learning settings


Display dataplane pmtu learning settings.
get dataplane pmtu-learning config

Get admin and operational state of QAT crypto acceleration


Get admin and operational state of QAT crypto acceleration.
get dataplane qat

Calculate all nics throughput given an interval


Calculate all nics throughput given an interval
get dataplane throughput <time>

Get edge config diagnosis


Get edge config diagnosis
get diagnosis config

Get runtime federation health check report


Get runtime federation health check report
get diagnosis health-check

Check for inconsistency


Check for any inconsistency on local edge
get diagnosis inconsistency

Get diagnosis analysis


Get diagnosis analysis
get diagnosis log

Get number of diagnosis entries


Get number of diagnosis entries
get diagnosis log limit <log-num>

Get two number of diagnosis entries


Get two number of diagnosis entries
get diagnosis log limit <log-num> context <context-line-num>

Get edge logical topology


Get logical topology on edge
get diagnosis topology

List docker containers in the system


List all the docker containers in the system (equivalent of 'docker ps -a').
get docker-containers

List docker images in the system


List docker images in the system (equivalent of 'docker images').
get docker-images

Get Edge Cluster state history


Display the Edge cluster state history.
get edge-cluster history state

Get Edge Cluster status


Display the Edge cluster status.
get edge-cluster status

Show ENS device affinity list


Show the current device affinity of enhanced datapath.
get ens dev affinity list

Get flow stats for an ENS switch with switch ID


Show flow stats for an ENS switch with switch ID
get ens flow-stats <switch-id-arg>

Get flow stats for an ENS fastpath with switch ID and lcore ID


Show flow stats for an ENS fastpath with switch ID and lcore ID
get ens flow-stats <switch-id-arg> <lcore-ID-arg>

Dump Flow Table for all lcores of requested switch ID


Dump Flow Table for all lcores of requested switch ID
get ens flow-table dump <switch-id-arg>

Dump Flow Table for a specific lcore from specific switch


Dump Flow Table for a specific lcore from specific switch
get ens flow-table dump <switch-id-arg> <lcore-ID-arg>

Get flow table size


Get flow table size
get ens flow-table size

Get flow timeout in seconds


Get flow timeout in seconds
get ens flow-table timeout

Get global FPO configuration


Get global FPO configuration
get ens fpo

Get FPO stats for a datapath with switch ID and lcore ID


Get FPO stats for a datapath with switch ID and lcore ID
get ens fpo stats <switch-id-arg> <lcore-ID-arg>

Get FPO stats for a datapath with uplink name


Get FPO stats for a datapath with uplink name
get ens fpo stats <uplink-arg>

Get FPO status for an uplink


Get FPO status for an uplink
get ens fpo status <uplink-arg>

Get HW flow cache counters on smart NIC


Get HW flow cache counters on smart NIC
get ens hw-flow-stats

Get the lcore latency config data


Get the lcore latency config data
get ens latency lcore config <switch-id-arg>

Dump the lcore latency stats data


Dump the lcore latency stats data
get ens latency lcore dump <switch-id-arg>

Dump latency histos for all vmxnet3 vnics and all lcores of this switch


Dump latency histos for all vmxnet3 vnics and all lcores of this switch
get ens latency system dump <switch-id-arg>

Show ENS lcore assignment mode


Show the current mode of enhanced datapath lcore assignment.
get ens lcore-assignment-mode <hs-name-arg>

List all ports in all switches


List all ports in all switches
get ens port list

List all ports in a specified ENS switch


List all ports in a specified ENS switch
get ens port list <switch-id-arg>

Get the netq information for a port


Get the netq information for a port
get ens port netq <switch-id-arg> <ens-port-id-arg>

Get PRP config for a switch


Get PRP config for a switch
get ens prp config <switch-id-arg>

List all active PRP nodes


List all active PRP nodes
get ens prp node <switch-id-arg>

Get a PRP node information


Get a PRP node information
get ens prp node <switch-id-arg> <vLAN-id-arg> <mac-arg>

List PRP per lcore stats


List PRP per lcore stats
get ens prp stats lcore <switch-id-arg> <lcore-aggr-arg>

List all active PRP nodes stats


List all active PRP nodes stats
get ens prp stats node <switch-id-arg>

List vDAN stats


List vDAN stats
get ens prp stats vdan <switch-id-arg>

List active vDANs


List active vDANs
get ens prp vdan list <switch-id-arg>

List all ENS switches


List all ENS switches
get ens switch list

List latest Telemetry related infra-counters.


List latest Telemetry related infra-counters.
get ens telemetry-infra-counters

Dump thread load balancer statistics


Dump thread load balancer statistics
get ens tlb stats

Dump thread load balancer statistics for a specific switch


Dump thread load balancer statistics for a specific switch
get ens tlb stats <switch-id-arg>

Get the current thread load balancer status


Get the current thread load balancer status
get ens tlb status <hs-name-arg>

Get the RSS setting of an uplink


Get the RSS setting of an uplink
get ens uplink rss list <uplink-arg>

Get the stats and private stats of an uplink port


Get the stats and private stats of an uplink port
get ens uplink stats <uplink-arg>

Dump the host's public cloud gateway certificate


Dump the host's public cloud gateway certificate
get gateway certificate <ip-address>

Dump the host's public cloud gateway certificates


Dump the host's public cloud gateway certificates.
get gateway certificates

Dump the host's public cloud gateway connection status


Dump the host's public cloud gateway connection status.
get gateway connection status

Get geneve critical bit


Get geneve critical bit.
get geneve-cbit dvs <dvs-name-arg>

Show the group translation


Display the translations for the specified container group. Optionally specify a translation type to display translations of that type.
get group <uuid> [<translation-type>]

Show all existing groups


Display all groups.
get groups

Lookup groups for the IP address


Display groups with the specified IP address.
get groups with ip <ip46-address>

Lookup groups for the hardware address


Display groups with the specified MAC address.
get groups with mac <hardware-address>

Lookup group for the network interface


Display groups with the specified network interface.
get groups with vif <vif-id-arg>

Display info for a high-availability channel


Display information about the specified high-availability channel.
get high-availability channel local-ip <ip-address> remote-ip <ip-address>

Display stats for a high-availability channel


Display statistics for the specified high-availability channel.
get high-availability channel local-ip <ip-address> remote-ip <ip-address> stats

Display info about high-availability channels


Display information about high-availability channels.
get high-availability channels

Display high-availability channel stats


Display statistics for the high-availability channels.
get high-availability channels stats

Display the logical router high availability state history


Display the high availability state history for the logical router in the VRF context.
get high-availability history state

Display the logical router high availability state history


Display the high availability state history for the logical router in the VRF context.
get high-availability history state details

Display info for a high-availability session


Display information about the specified high-availability session.
get high-availability session local-service-id <service-id-arg> peer-service-id <service-id-arg>

Display stats for a high-availability session


Display statistics for the specified high-availability session.
get high-availability session local-service-id <service-id-arg> peer-service-id <service-id-arg> stats

Display info about high-availability sessions


Display information about high-availability sessions.
get high-availability sessions

Display info about high-availability sessions of specified channel


Display information about high-availability sessions by remote-ip of the channel
get high-availability sessions remote-ip <ip-address>

Display info about high-availability sessions of specified service-type


Display information about high-availability sessions by service-type.
get high-availability sessions service-type <service-type-arg>

Display info about high-availability sessions of specified service-type and channel


Display information about high-availability sessions by service-type and remote-ip of the channel
get high-availability sessions service-type <service-type-arg> remote-ip <ip-address>

Display stats for high-availability sessions of specified service-type


Display statistics for the high-availability sessions of specified service-type.
get high-availability sessions service-type <service-type-arg> stats

Display high-availability sessions that have completed synchronization


Displays any high-availability sessions of a given type who have completed synchronization with peer
get high-availability sessions service-type <service-type-arg> sync complete

Display high-availability sessions whose synchronization is ongoing


Displays any high-availability sessions of a given type who have not yet completed synchronization with peer
get high-availability sessions service-type <service-type-arg> sync in-progress

Display high availability session synchronization status summary


Display the synchronization status of high-availability sessions of a given type on current node
get high-availability sessions service-type <service-type-arg> sync summary

Display stats for high-availability sessions


Display statistics for the high-availability sessions.
get high-availability sessions stats

Display Tunnels info on a host switch


Display Tunnels info on the specified host switch.
get host-switch <hs-name-arg> <bfd-cmd-type-arg>

Display Tunnel Detail info on a host switch


Display Tunnel Detail info on the specified DVPort of the specified host switch.
get host-switch <hs-name-arg> <bfd-cmd-type-arg> <local-ip-arg> <remote-ip-arg>

Display IPFIX setting on a DVPort of a host switch


Display IPFIX setting on the specified DVPort of the specified host switch
get host-switch <hs-name-arg> dvport <dvport-id-arg> ipfix setting

Display IPFIX stats on a DVPort of a host switch


Display IPFIX stats on the specified DVPort of the specified host switch
get host-switch <hs-name-arg> dvport <dvport-id-arg> ipfix stats

Display mcast filter mode for a Host switch


Display the mcast filter mode for the specified host switch and dvPort
get host-switch <hs-name-arg> dvport <dvport-id-arg> mcast-filter

Display mcast filter stats of the specified entry


Display the mcast filter stata of the specified entry
get host-switch <hs-name-arg> dvport <dvport-id-arg> mcast-filter <entry-mode-arg> <entry-group-arg>

Display IPFIX stats on a host switch


Display IPFIX stats on the specified host switch
get host-switch <hs-name-arg> ipfix stats

Display mcast filter mode for a host switch


Display the mcast filter mode for the specified host switch.
get host-switch <hs-name-arg> mcast-filter

Display stats of mirror on a host switch


Display the stats of mirror on the specified host switch.
get host-switch <hs-name-arg> mirror-session <ms-id-arg-esx>

Display mirror settings on a host switch


Display the mirror settings on the specified host switch.
get host-switch <hs-name-arg> mirror-sessions

Display IPFIX stats on an uplink of a host switch


Display IPFIX stats on the specified uplink of the specified host switch
get host-switch <hs-name-arg> uplink <uplink-arg> ipfix stats

Display host switch upgrade status


Display if host switch is getting upgraded.
get host-switch upgrade-status

Display VLAN table for the host switch


Display VLAN table for the host switch.
get host-switch vlan-table

Display host switches


Display information about all host switches.
get host-switches

Get CIF configuration by AppID


Display the container interface (CIF) configuration for the specified app.
get hyperbus app-id <app-ID> cif-config

Get CIF configuration cache table


Display the container interface (CIF) configuration table.
get hyperbus cif-table

Get VIF connection info


Display the virtual interface (VIF) connection information.
get hyperbus connection info

Get VIF connection version


Display the virtual interface (VIF) connection version information.
get hyperbus connection version

Get LIP IP pool


Display the LIP allocation pool.
get hyperbus lip ip-pool

Get CIF configuration by logical switch port ID


Display the container interface (CIF) configuration for the specified logical switch port.
get hyperbus logical-switch-port <logical-switch-port-ID> cif-config

Get connection info by VIF ID


Display the connection information for the specified virtual interface (VIF).
get hyperbus vif-id <vif-ID> connection info

Get LIP by VIF ID


Display the logical IP (LIP) for the specified virtual interface (VIF).
get hyperbus vif-id <vif-ID> lip

Get VIF LIP table


Display the VIF (virtual interface) LIP (logical IP) table.
get hyperbus vif-lip-table

Get connected VIF table


Display the connected virtual interfaces (VIFs). For ESXi, all connected container host VIFs are displayed. For KVM, all connected container host VIFs and CIFs are displayed.
get hyperbus vif-table

List all container images for given service


List all container images for given service.
get image <configurable-image-name>

List install history of container images for given service


List install history of container images for given service.
get image <configurable-image-name> install history

List all service container images


List all service container images.
get images

List install history for all service container images


List install history for all service container images.
get images install history

Display NSX Intelligence broker statistics


Display NSX Intelligence broker statistics.
get intelligence broker stats

Display NSX Intelligence flows configuration


Display NSX Intelligence flows configuration.
get intelligence flows config

Display NSX Intelligence flows aggregation mask


Display NSX Intelligence flows aggregation mask.
get intelligence flows mask

Display NSX Intelligence flows metrics


Display NSX Intelligence flows metrics.
get intelligence flows metrics

Display NSX Intelligence flows metrics for ports


Display NSX Intelligence flows metrics for ports.
get intelligence flows metrics ports

Display NSX Intelligence flows statistics


Display NSX Intelligence flows statistics.
get intelligence flows stats

Display NSX Intelligence flows acknowledgement statistics


Display NSX Intelligence flows acknowledgement statistics.
get intelligence flows stats ack

Display LLDP configuration on all devices


Display LLDP configuration on all devices.
get lldp config

Display LLDP Configuration on given device


Display LLDP configuration on given device.
get lldp config <lldp-interface-name-esx>

Display LLDP configuration on given device


Display LLDP configuration on given device.
get lldp config <lldp-interface-name-kvm>

Displays LLDP Configuration on given device


Displays LLDP configuration given device.
get lldp config <lldp-interface-name>

Display LLDP Neighbor information on all devices


Display LLDP Neighbor information on all devices.
get lldp neighbors

Display LLDP Neighbor information on given device


Display LLDP Neighbor information on given device.
get lldp neighbors <lldp-interface-name-esx>

Display LLDP Neighbor information on given device


Display LLDP Neighbor information on given device.
get lldp neighbors <lldp-interface-name-kvm>

Displays LLDP Neighbor information on given device


Displays LLDP Neighbor information on given device.
get lldp neighbors <lldp-interface-name>

Displays LLDP Statistics on all devices


Displays LLDP Statistics on all devices.
get lldp stats

Displays LLDP Statistics on given device


Displays LLDP Statistics on given device.
get lldp stats <lldp-interface-name>

Show log file contents


Display the contents of the specified log file.
get log-file <log-file-arg>

Show log file contents


Display the last 10 lines of the specified log file and all new messages that are written to the log file.
get log-file <log-file-arg> follow

Display the list of logs files


Display the list of logs files
get log-file list

Display all configured logging servers


Display logging server configuration.
get logging-servers

Show logical service binding


Display a specific logical service binding.
get logical-service binding <uuid-string-arg>

Show all logical service bindings


Display all logical service bindings.
get logical-service bindings

Display a specific logical service port


Display information for the specified logical service port. Optionally specify an argument to display the statistics.
get logical-service port <uuid> [stats]

Display the logical service ports


Display information for all logical service ports. Optionally specify an argument to display the statistics.
get logical-service ports [stats]

Show logical service state


Display the state of a specific logical service.
get logical-service state <uuid-string-arg>

Show all logical service states


Display the state of all logical services.
get logical-service states

Display information about a mirror session


Display information about the specified mirror session.
get mirror-session <ms-id-arg>

Display mirror sessions


Display all mirror sessions on this host.
get mirror-sessions

Show physical port by name


Display the specified physical port.
get physical-port <dpd-name-physical-port-arg>

Show physical port stats by name


Display statistics for the specified physical port.
get physical-port <dpd-name-physical-port-arg> stats

Show physical port verbose stats by name


Display verbose statistics for the specified physical port.
get physical-port <dpd-name-physical-port-arg> stats verbose

Show physical port xstats by name


Display x statistics for the specified physical port.
get physical-port <dpd-name-physical-port-arg> xstats

Show physical port


Display all physical ports.
get physical-ports

Get the realization status for the specified transport node


Get the realization status for the specified transport node.
get realization-status <uuid-arg>

Get all connected receivers


Display all connected receivers.
get receivers

Display service properties


Display information about the specified service.
get service <service-name-arg>

Display global logging configuration


Display global logging configuration.
get service controller logging-config

Display configuration for logger with given log level


Display the logging configuration for components that have the specified log level.
get service controller logging-config logging-level <controller-logging-level-arg>

Display configuration for given logger


Display the logging configuration for the specified component.
get service controller logging-config name <string-arg-controller>

Display configuration for loggers matching to given regex


Display the logging configuration for components that match the specified pattern. The pattern can be a regular expression.
get service controller logging-config pattern <string-arg-controller>

Display the controller service logging level


Display the log level for the controller service.
get service controller logging-level

Get the dataplane service logging level


Display the log level of the dataplane service.
get service dataplane logging-level

Get the dhcp service logging level


Display the log level of the dhcp service.
get service dhcp logging-level

Display DHCP pool monitor configuration


Display DHCP pool monitor configuration
get service dhcp pool-monitor

Display IKE per tunnel debugging configuration


Display IKE per tunnel debugging configuration
get service ike debug-tunnel

Get the IKE service logging level


Display the log level of the IKE service.
get service ike logging-level

Get the local-controller service logging level


Display the log level of the local-controller service.
get service local-controller logging-level

Get local-controller service state


Display the state of the local controller service.
get service local-controller state

Get Node Management service logging level


Get the log level of the Node Management service.
get service node-mgmt logging-level

Get the log level of nsd


Get nsd logging level.
get service nsd logging-level

Get the log level of NSX Agent service.


Get service nsx-agent logging level.
get service nsx-agent logging-level

Get the whole cfgagent cache table


Display the whole cache table in cfgagent. Optionally specify arguments to display only the local configuration, remote configuration, local L2, or remote L2 information, and remote L3 information.
get service nsx-cfgagent cache-table [{config | l2 | l3} {local | remote | logical-switch | logical-switch-port | logical-switch-port-list | transport-node | bridge-cluster | group-relation | mirror | ipfix | profile | container}]

Get HyperBus vmknics


Display the status for HyperBus vmknic ports on this hypervisor host.
get service nsx-cfgagent hyperbus vmknic

Get service cfgagent hyperbus logging level


Get service cfgagent hyperbus logging level.
get service nsx-cfgagent lib-hyperbus logging-level

Get service cfgagent metrics logging level


Get service cfgagent metrics logging level
get service nsx-cfgagent lib-metrics logging-level

Get service cfgagent nestdb logging level


Get service cfgagent nestdb logging level
get service nsx-cfgagent lib-nestdb logging-level

Get service cfgagent net logging level


Get service cfgagent net logging level
get service nsx-cfgagent lib-net logging-level

Get service cfgagent rpc logging level


Get service cfgagent rpc logging level
get service nsx-cfgagent lib-rpc logging-level

Get service cfgagent SHA client logging level


Get service cfgagent SHA client logging level.
get service nsx-cfgagent lib-sha logging-level

Get service cfgagent upm logging level


Get service cfgagent upm logging level.
get service nsx-cfgagent lib-upm logging-level

Get service cfgagent workflow logging level


Get service cfgagent workflow logging level.
get service nsx-cfgagent lib-wft logging-level

Get service cfgagent workflow trace level


Get service cfgagent workflow trace level.
get service nsx-cfgagent lib-wft trace-level

Get service cfgagent logging level


Get service cfgagent logging level.
get service nsx-cfgagent logging-level

Get LS's attachment config


Display the attachment config logical switch on this hypervisor host.
get service nsx-cfgagent logical-switch attachment-config

Get LS's extra config


Display the extra config list for logical switch on this hypervisor host.
get service nsx-cfgagent logical-switch extra-config

Get LSP's extra config


Display the extra config list for logical switch port on this hypervisor host.
get service nsx-cfgagent logical-switch-port extra-config

Get nsx-context-mux feature status


Get nsx-context-mux feature status.
get service nsx-context-mux feature <context-mux-feature-type-arg> status

Get the log level of context-mux


Get service daemon log level for context-mux.
get service nsx-context-mux logging-level

Get current status of IDFW on host


Get current status of IDFW on host
get service nsx-ctxteng idfw status

Get current status of IDS on host


Get current status of IDS on host
get service nsx-ctxteng ids status

Get context engine protocol enable in the order TCP UDP ICMP


Get context engine protocol enable in the order TCP UDP ICMP
get service nsx-ctxteng protocol

Get service exporter SmartNIC demux logging level


Get service exporter SmartNIC demux logging level.
get service nsx-exporter lib-sndemux logging-level

Get the log level of the exporter service


Get exporter service logging level.
get service nsx-exporter logging-level

Display service properties for nsx-lastline-rapid


Display information about the nsx-lastline-rapid service.
get service nsx-lastline-rapid

Get the log level of nsx-lastline-rapid


Get nsx-lastline-rapid log level
get service nsx-lastline-rapid logging-level

Get service netopa logging level


Get service netopa logging level.
get service nsx-netopa logging-level

Get service opsagent SHA client logging level


Get service opsagent SHA client logging level.
get service nsx-opsagent lib-sha logging-level

Get service opsagent SmartNIC demux logging level


Get service opsagent SmartNIC demux logging level.
get service nsx-opsagent lib-sndemux logging-level

Get service opsagent workflow logging level


Get service opsagent workflow logging level.
get service nsx-opsagent lib-wft logging-level

Get service opsagent workflow trace level


Get service opsagent workflow trace level.
get service nsx-opsagent lib-wft trace-level

Get service OpsAgent logging level


Get service OpsAgent logging level.
get service nsx-opsagent logging-level

Get service nsx-proxy central logging level


Get service nsx-proxy central logging level.
get service nsx-proxy central logging-level

Get service nsx-proxy metrics logging level


Get service nsx-proxy metrics logging level.
get service nsx-proxy lib-metrics logging-level

Get service nsx-proxy nestdb logging level


Get service nsx-proxy nestdb logging level.
get service nsx-proxy lib-nestdb logging-level

Get service nsx-proxy net logging level


Get service nsx-proxy net logging level.
get service nsx-proxy lib-net logging-level

Get service nsx-proxy rpc logging level


Get service nsx-proxy rpc logging level.
get service nsx-proxy lib-rpc logging-level

Get service nsx-proxy logging level


Get service nsx-proxy logging level.
get service nsx-proxy logging-level

Get service nsx-snproxy central logging level


Get service nsx-snproxy central logging level.
get service nsx-snproxy central logging-level

Get service nsx-snproxy connection info


Get service nsx-snproxy connection info
get service nsx-snproxy conn-info

Get service nsx-snproxy net logging level


Get service nsx-snproxy net logging level.
get service nsx-snproxy lib-net logging-level

Get service nsx-snproxy rpc logging level


Get service nsx-snproxy rpc logging level.
get service nsx-snproxy lib-rpc logging-level

Get service nsx-snproxy logging level


Get service nsx-snproxy logging level.
get service nsx-snproxy logging-level

Display service properties for Security Hub


Display information about the SecurityHub service.
get service security-hub

Get the log level of EPSEC Library


Get EPSEC Library log level
get service security-hub epsec logging-level

Get configured SecurityHub feature details


Get configured SecurityHub feature details
get service security-hub feature

Get the log level of security-hub


Get security-hub log level
get service security-hub logging-level

Display service properties


Display information about all services.
get services

Show the remote site(s) and their sync status


Display the remote sites along with their sync status.
get site-replicator remote-sites

Get SNMP v2 configured status


Indicates whether the local SNMP agent is configured with community string(s).
get snmp v2-configured

Get SNMP v2 Trap Targets


Get SNMP v2 Trap Targets.
get snmp v2-targets

Get SNMP v3 configured status


Indicates whether the local SNMP agent is configured with v3 user(s).
get snmp v3-configured

Get SNMP v3 Engine ID


Get SNMP v3 Engine ID.
get snmp v3-engine-id

Get SNMP v3 Protocols


Get SNMP v3 Protocols auth_protocol and priv_protocol.
get snmp v3-protocols

Get SNMP v3 Trap Targets


Get SNMP v3 Trap Targets.
get snmp v3-targets

Get SNMP v3 User IDs


Get SNMP v3 User IDs.
get snmp v3-users

Show active network connections


Display active network connections.
get sockets

Show the stretched cgroup translation on both local and remote sites


Display both local and remote translations for the specified stretched container group. Optionally specify a translation type to display translations of that type.
get stretched cgroup <container-id> <translation-type> (Deprecated)

Show the stretched group translation on both local and remote sites


Display both local and remote translations for the specified stretched group. Optionally specify a translation type to display translations of that type.
get stretched group <group-id> <translation-type>

Display information about a IPFIX configuration


Display information about the specified IPFIX configuration.
get switch-ipfix logical-switch-port <logical-port-id-arg> setting

Display Switch Security config for a logical port


Displays Switch Security config for a logical port.
get switch-security config <logical-port>

Display Switch Security stats for a logical port


Displays Switch Security stats for a logical port.
get switch-security stats <logical-port>

Get the topology of the system


Display the topology of the system.
get topology

Display transport node agent status


Display agent status information for the specified transport node.
get transport-node <uuid-arg> agent-status

Display the ARP table for the specified transport node


Display the ARP table for the specified transport node.
get transport-node <uuid-arg> arp-table

Display the MAC address table for the specified transport node


Display the MAC address table for the specified transport node.
get transport-node <uuid-arg> mac-table

Display routing domains joined by the specified transport node


Display routing domains joined by the specified transport node.
get transport-node <uuid-arg> routing-domain

Display the routing vtep table for the specified transport node


Display the routing vtep table for the specified transport node.
get transport-node <uuid-arg> routing-vtep

Display transport node status


Display status information for the specified transport node.
get transport-node <uuid-arg> status

Display transport node status after querying all controller nodes in UA cluster.


Display status information for the specified transport node after querying all controller nodes in UA cluster.
get transport-node <uuid-arg> status-from-all-nodes

Display transport node status


Display status information for the specified transport node.
get transport-node <uuid-arg> threat-status

Display VIF information for the specified transport node


Display VIF information for the specified transport node.
get transport-node <uuid-arg> vifs

Display all VTEPs for the specified transport node


Display all tunnel end points for the specified transport node.
get transport-node <uuid-arg> vtep

Display status of all transport nodes


Display status information for all transport nodes.
get transport-nodes status

Display status of all transport nodes after querying all controller nodes in UA cluster.


Display status information for all transport nodes after querying all controller nodes in UA cluster.
get transport-nodes status-from-all-nodes

Display VIF info


Display information about the sepcified VIF. You can find VIF IDs with the get transport-node <uuid> vif command or the get logical-switch <uuid> ports command (see Child-UUID where Child-EntityType is VIF).
get vif <vif-id-arg>

Dump the host's network mode and tagged interface


Dump the host's network mode and tagged interface.
get vm-network-mode

Display info about EW policy service chain


Display information about EW policy service chain.
get vsip-si policy-service-chains

Display all selected service paths


Display selected paths info
get vsip-si selected-service-paths <chain_id_esx>

Display info about EW service chain


Display information about EW service chain.
get vsip-si service-chains

Display info about EW service path.


Display information about EW service path.
get vsip-si service-paths

Display all service paths in order


Display service paths info
get vsip-si service-paths <chain_id_esx>

Display active service paths in order of path selection policy


Display active service paths info
get vsip-si service-paths <chain_id_esx> active

Display all service paths in order of path selection policy


Display service paths info
get vsip-si service-paths <chain_id_esx> all

Display service paths in maintenance


Display maintanence service paths info
get vsip-si service-paths <chain_id_esx> maintenance-mode

Display info about EW service path with specific chain id.


Display information about EW service path with specific chain id.
get vsip-si service-paths <dpd-id-service-chain-arg>

Display info about service policies


Display information about service policies.
get vsip-si service-policies

Get MAC Table associated with a Team of a vswitch


Get MAC Table associated with a Team of a vswitch
get vswitch mac-table team <hs-name-arg>

Display vswitch runtime options


Display all vSwitch runtime options on this host.
get vswitch runtime

Get vxlan uplink queue filter


Get vxlan uplink queue filter.
get vxlan-uplink-queue-filter dvs <dvs-name-arg>

Install NSX Edge service container image


Install NSX Edge service container image.
install image <configurable-image-name> version <configurable-image-version>

Join this node to a NSX Cluster


Join this node to a management cluster. You must provide the API username and password of a node that is already in the cluster. On that node, you can run the get cluster config command to get the cluster ID, and run the get certificate api thumbprint command to get the thumbprint. If you do not provide a password on the command line, you will be prompted to enter one.
join <ip-address[:port]> cluster-id <cluster-id> thumbprint <thumbprint> [token <api-token>] [username <username> [password <password>]] [force]

Join node to the management plane


Join this node to the management plane.
join management-plane <hostname-or-ip-address[:port]> thumbprint <thumbprint> token <token> [node-uuid <uuid>] [replace]

Join host with management plane


Join this hypervisor host with the management plane. You can specify any NSX Manager in the management cluster in this command.

Use the API username and password for the specified NSX Manager. If you do not provide a password on the command line, you will be prompted to enter one.

Get the NSX Manager thumbprint by running the get certificate api thumbprint command on the specified NSX Manager.

join management-plane <hostname-or-ip-address[:port]> username <username> thumbprint <thumbprint> [password <password>]

Join node to the management plane


Join this node to the management plane.
join management-plane <hostname-or-ip-address[:port]> username <username> thumbprint <thumbprint> [password <password>] [node-uuid <uuid>] [replace]

Push certificate to management plane


Pushes host certificate to management plane.

Use the API username and password for the specified NSX Manager. If you do not provide a password on the command line, you will be prompted to enter one.

Get the NSX Manager thumbprint by running the get certificate api thumbprint command on the specified NSX Manager.

push host-certificate <manager-hostname-or-ip-address-and-optional-port-arg> username <api-username> thumbprint <api-thumbprint>

Reset corelist related boot time option to factory default


Reset the corelist-related boot time option to factory default.
reset dataplane corelist

Reset custom list of supported devices on the system


Reset custom list of supported devices on the system.
reset dataplane device list

Reset hugepage related boot time option to factory default


Reset the hugepage-related boot time option to factory default.
reset dataplane hugepage

Recover management plane account on the host


Recover management plane account on the host. You can specify any NSX Manager in the management cluster in this command.

Use the API username and password for the specified NSX Manager. If you do not provide a password on the command line, you will be prompted to enter one.

Get the NSX Manager thumbprint by running the get certificate api thumbprint command on the specified NSX Manager.

reset management-plane <hostname-or-ip-address[:port]> username <username> thumbprint <thumbprint> [password <password>]

Restart service


Restart the specified service.
restart service <service-name-arg>

Restart service nsx-lastline-rapid


Restart the nsx-lastline-rapid service.
restart service nsx-lastline-rapid

Restart service Security Hub


Restart the Security Hub service.
restart service security-hub

Enable or disable basic authentication in API calls


Enable or disable basic authentication in API calls.
set cluster api-service basic-authentication <enabled-arg>

Set cluster API service API per-client concurrency limit, 0 to disable


Set the cluster API service API per-client concurrency limit value.
set cluster api-service client-api-concurrency-limit <api-service-client-api-concurrency-limit-arg>

Set per-client API rate limit, 0 to disable


Set the cluster API service API per-client rate limit value.
set cluster api-service client-api-rate-limit <api-service-client-api-rate-limit-arg>

Set cluster api service connection timeout, 0 to disable


Set the cluster api service connection timeout value.
set cluster api-service connection-timeout <api-service-conn-timeout-arg>

Enable or disable cookie-based authentication in API calls


Enable or disable cookie-based authentication in API calls.
set cluster api-service cookie-based-authentication <enabled-arg>

Set cluster API service API global concurrency limit, 0 to disable


Set the Cluster API ServiceAPI global concurrency limit value.
set cluster api-service global-api-concurrency-limit <api-service-global-api-concurrency-limit-arg>

Set cluster api service redirect host


Set the cluster api service redirect host.
set cluster api-service redirect-host <hostname-or-ip-address>

Set cluster api service session timeout, 0 to disable


Set the cluster api service session timeout value.
set cluster api-service session-timeout <api-service-timeout-arg>

Set Cluster Virtual IP


Set Cluster Virtual IP.
set cluster vip <ip46-address>

Enable/disable control packet prioritization


Enable/disable control packet prioritization
set dataplane ctrl-prio <enabled-arg>

Set the custom list of physical NICs


Set the custom list of physical NICs.
set dataplane device list <pci-address-arg>

Enable/disable flow cache


Enable or disable flow cache.
set dataplane flow-cache <enabled-arg>

Set the flow cache size for each core


Set the flow cache size for each core
set dataplane flow-cache-size <flow-cache-size-arg>

Enable/disable geneve critical bit


Enable or disable geneve critical bit.
set dataplane geneve-cbit <enabled-arg>

Enable/disable interrupt mode


Enable or disable interrupt mode.
set dataplane interrupt-mode <enabled-arg>

Change the size of the buffer pool for jumbo frame crypto operations


Change the jumbo mbuf pool size
set dataplane jumbo-mbuf-pool-size <jumbo-mbuf-pool-size-arg>

Enable/disable pmtu message generation in l2vpn


Enable or disable pmtu message generation in l2vpn.
set dataplane l2vpn-pmtu <enabled-arg>

Change the max number of packets that can be queued on each core


Change the per-core packet queue limit
set dataplane packet-queue-limit <packet-queue-limit-arg>

Enable/disable pmtu learning in dataplane


Enable or disable pmtu learning in dataplane.
set dataplane pmtu-learning <enabled-arg>

Enable/disable QAT device usage for IPsec (bare metal edge only)


Enable or disable QAT device usage for IPsec.
set dataplane qat <enabled-arg>

Set Rx/Tx queue number per port per core


Set Rx/Tx queue number per port per core
set dataplane queue-num-per-port-per-core <queue-num-per-port-per-core-arg>

Set the rx ring size for physical ports


Set the rx ring size for physical ports.
set dataplane ring-size rx <ring-size-arg>

Set the tx ring size for physical ports


Set the tx ring size for physical ports.
set dataplane ring-size tx <ring-size-arg>

Disable flow cache for all switches


Disable flow cache for all switches
set ens flow-table disable

Disable flow cache for a specific switch


Disable flow cache for a specific switch
set ens flow-table disable <switch-id-arg>

Enable flow cache for all switches


Enable flow cache for all switches
set ens flow-table enable

Enable flow cache for a specific switch


Enable flow cache for a specific switch
set ens flow-table enable <switch-id-arg>

Set flow table size per Lcore. Rounded up to nearest power of 2.


Set flow table size per Lcore. Rounded up to nearest power of 2.
set ens flow-table size <size-arg>

Enable/disable global FPO and configure FPO model


Enable/disable global FPO and configure FPO model
set ens fpo <fpo-config-arg>

Enable/disable per switch FPO and configure FPO model


Enable/disable per switch FPO and configure FPO model
set ens fpo <fpo-config-arg> <hs-name-arg>

Change ENS lcore assignment mode


Change mode of enhanced datapath lcore assignment.
set ens lcore-assignment-mode <hs-name-arg> <ens-lc-mode-arg>

Migrate port queue between lcores


Migrate port queue between lcores
set ens port migrate <switch-id-arg> <ens-port-id-arg> <queue-id-arg> <dir-arg> <lcore-ID-arg>

Disable usePerVnicQCb option of ENS switch


Disable usePerVnicQCb option of ENS switch
set ens switch use-per-vnic-qcb disable <hs-name-arg>

Enable usePerVnicQCb option of ENS switch


Enable usePerVnicQCb option of ENS switch
set ens switch use-per-vnic-qcb enable <hs-name-arg>

Disable automatic thread load balancing


Disable automatic thread load balancing
set ens tlb status disable <hs-name-arg>

Enable automatic thread load balancing


Enable automatic thread load balancing
set ens tlb status enable <hs-name-arg>

Enable automatic thread load balancing based on metric


Enable automatic thread load balancing based on metric
set ens tlb status enable <hs-name-arg> <metric-arg>

Set Tx and Rx ring size of an uplink


Set Tx and Rx ring size of an uplink
set ens uplink ring-size <uplink-arg> <tx-ring-size-arg> <rx-ring-size-arg>

Set geneve critical bit


Set geneve critical bit.
set geneve-cbit <boolean-arg> dvs <dvs-name-arg>

Set mcast filter mode for a host switch


Set the mcast filter mode for the specified host switch.
set host-switch <hs-name-arg> mcast-filter <mcast-filter-mode-arg>

Set host switch upgrade status


Set host switch upgrade status.
set host-switch upgrade-status <boolean-arg>

Set logging-server


Configure a logging server. The logging system uses the facility codes defined in RFC 5424. Facility local7 is used for audit messages, and local6 is used for non-audit messages.
set logging-server <hostname-or-ip-address[:port]> proto <proto> level <level> [facility <facility>] [messageid <messageid>] [serverca <filename>] [clientca <filename>] [certificate <filename>] [key <filename>] [structured-data <structured-data>]

Set kubeconfig file of the NAPP Kubernetes cluster


Set kubeconfig file of the NAPP Kubernetes cluster. This operation overrides any existing NAPP kubeconfig file.
set napp kubeconfig

Set the specified physical port mtu to given value


Set the specified physical port mtu to given value.
set physical-port <dpd-name-physical-port-arg> mtu <dpd-physical-port-mtu-arg>

Set the specified physical port admin state up or down


Set the specified physical port admin state up or down.
set physical-port <dpd-name-physical-port-arg> state <dpd-physical-port-state-arg>

Set repository state properties


Set current node's IP address as repository IP. This command will restart the install-upgrade service.
set repository-ip

Set async replicator service logging level


Set the log level of the async replicator service.
set service async_replicator logging-level <async-replicator-level-arg>

Set Auth service logging level


Set the log level of the Auth service.
set service auth logging-level <auth-level-arg>

Set the controller service logging level


Set the log level for the controller service.
set service controller logging-level <controller-logging-level-arg>

Set log level for given logger


Set the log level for the specified component.
set service controller logging-level name <string-arg-controller> <controller-logging-level-arg>

Set log level for loggers matching regex


Set the log level for components that match the specified pattern. The pattern can be a regular expression.
set service controller logging-level pattern <string-arg-controller> <controller-logging-level-arg>

Set the Dataplane service logging level


Set the log level of the Dataplane service.
set service dataplane logging-level <edge-service-logging-level-arg>

Set the DHCP service logging level


Set the log level of the DHCP service.
set service dhcp logging-level <edge-service-logging-level-arg>

Enable/Disable DHCP pool monitor and set monitor interval in seconds


Enable or disable DHCP pool monitor and set monitor interval in seconds
set service dhcp pool-monitor <monitor-flag-arg> monitor-interval <monitor-interval-arg>

Enable or disable basic authentication in API calls.


Enable or disable basic authentication in API calls.
set service http basic-authentication <enabled-arg>

Set http API per-client concurrency limit, 0 to disable


Set the HTTP API per-client concurrency limit value.
set service http client-api-concurrency-limit <http-client-api-concurrency-limit-arg>

Set http per-client API rate limit, 0 to disable


Set the HTTP API per-client rate limit value.
set service http client-api-rate-limit <http-client-api-rate-limit-arg>

Set http service connection timeout, 0 to disable


Set the HTTP service connection timeout value.
set service http connection-timeout <http-conn-timeout-arg>

Enable or disable cookie-based authentication in API calls.


Enable or disable cookie-based authentication in API calls.
set service http cookie-based-authentication <enabled-arg>

Set http API global concurrency limit, 0 to disable


Set the HTTP API global concurrency limit value.
set service http global-api-concurrency-limit <http-global-api-concurrency-limit-arg>

Set HTTP service logging level


Set the log level of the HTTP service.
set service http logging-level <http-level-arg>

Set http service redirect host


Set the HTTP service redirect host.
set service http redirect-host <hostname-or-ip-address>

Set http service session timeout, 0 to disable


Set the HTTP service session timeout value.
set service http session-timeout <http-timeout-arg>

Enable/Disable IKE per tunnel debugging


Enable or disable ike per tunnel debug mode
set service ike debug-tunnel local-ip <ip46-address> remote-ip <ip46-address> debug-level <debug-level-arg>

Enable/Disable IKE per tunnel debugging


Enable or disable ike per tunnel debug mode
set service ike debug-tunnel local-ip <ip46-address> remote-ip <ip46-address> debug-level <debug-level-arg> follow

Set the IKE service logging level


Set the log level of the IKE service.
set service ike logging-level <edge-service-logging-level-arg>

Set install-upgrade service enabled property


Set the install-upgrade service's enabled property.
set service install-upgrade enabled

Set the Local Controller service logging level


Set the log level of the Local Controller service.
set service local-controller logging-level <edge-service-logging-level-arg>

Set manager service logging level


Set the log level of the manager service.
set service manager logging-level <manager-level-arg>

Set manager service package logging level


Set the log level of the specified package in manager service.
set service manager logging-level <manager-level-arg> package <manager-package-name-arg>

Set Monitoring service logging level


Set the log level of the Monitoring service.
set service monitoring logging-level <monitoring-level-arg>

Set Node Management service logging level


Set the log level of the Node Management service.
set service node-mgmt logging-level <node-mgmt-level-arg>

Set the log level of nsd.


Dynamically set nsd log level.
set service nsd logging-level <level>

Set the log level of NSX Agent service.


Dynamically set service daemon log level.
set service nsx-agent logging-level <nsx-agent-logging-level-arg>

Set service cfgagent hyperbus logging level


Set service cfgagent hyperbus logging level.
set service nsx-cfgagent lib-hyperbus logging-level <cfgagent-logging-level-arg>

Set service cfgagent metrics logging level


Set service cfgagent metrics logging level
set service nsx-cfgagent lib-metrics logging-level <cfgagent-logging-level-arg>

Set service cfgagent nestdb logging level


Set service cfgagent nestdb logging level
set service nsx-cfgagent lib-nestdb logging-level <cfgagent-logging-level-arg>

Set service cfgagent net logging level


Set service cfgagent net logging level
set service nsx-cfgagent lib-net logging-level <cfgagent-logging-level-arg>

Set service cfgagent rpc logging level


Set service cfgagent rpc logging level
set service nsx-cfgagent lib-rpc logging-level <cfgagent-logging-level-arg>

Set service cfgagent SHA client logging level


Set service cfgagent SHA client logging level.
set service nsx-cfgagent lib-sha logging-level <cfgagent-logging-level-arg>

Set service cfgagent upm logging level


Set service cfgagent upm logging level.
set service nsx-cfgagent lib-upm logging-level <cfgagent-logging-level-arg>

Set service cfgagent workflow logging level


Set service cfgagent workflow logging level.
set service nsx-cfgagent lib-wft logging-level <cfgagent-logging-level-arg>

Set service cfgagent workflow trace level


Set service cfgagent workflow trace level.
set service nsx-cfgagent lib-wft trace-level <cfgagent-workflowtrace-level-arg>

Set service cfgagent logging level


Set service cfgagent logging level.
set service nsx-cfgagent logging-level <cfgagent-logging-level-arg>

Enable/Disable ContextMux feature


Enable/Disable ContextMux feature
set service nsx-context-mux feature <context-mux-feature-type-arg> <context-mux-feature-operation-arg>

Set the log level of nsx-context-mux


Dynamically set service daemon log level.
set service nsx-context-mux logging-level <context-mux-logging-level-arg>

Enable/disable TCP UDP ICMP events


Enable/disable TCP UDP ICMP events
set service nsx-ctxteng protocol <idfw-protocol> <idfw-enable>

Set service exporter SmartNIC demux logging level


Set service exporter SmartNIC demux logging level.
set service nsx-exporter lib-sndemux logging-level <exporter-sndemux-loglevel-arg>

Set the log level of exporter service.


Dynamically set service daemon log level.
set service nsx-exporter logging-level <level>

Set the log level of nsx-lastline-rapid


Dynamically set nsx-lastline-rapid log level
set service nsx-lastline-rapid logging-level <rapid-logging-level-arg>

Set service netopa logging level


Set service netopa logging level.
set service nsx-netopa logging-level <netopa-logging-level-arg>

Set service opsagent SHA client logging level


Set service opsagent SHA client logging level.
set service nsx-opsagent lib-sha logging-level <opsagent-logging-level-arg>

Set service opsagent SmartNIC demux logging level


Set service opsagent SmartNIC demux logging level.
set service nsx-opsagent lib-sndemux logging-level <opsagent-logging-level-arg>

Set service opsagent workflow logging level


Set service opsagent workflow logging level.
set service nsx-opsagent lib-wft logging-level <opsagent-logging-level-arg>

Set service opsagent workflow trace level


Set service opsagent workflow trace level.
set service nsx-opsagent lib-wft trace-level <opsagent-workflowtrace-level-arg>

Set service OpsAgent logging level


Set service OpsAgent logging level.
set service nsx-opsagent logging-level <opsagent-logging-level-arg>

Set the log level of platform client service.


Dynamically set service daemon log level.
set service nsx-platform-client logging-level <platform-client-logging-level-arg>

Set service nsx-proxy central logging level


Set service nsx-proxy central logging level
set service nsx-proxy central logging-level <nsxproxy-logging-level-arg>

Set service nsx-proxy metrics logging level


Set service nsx-proxy metrics logging level.
set service nsx-proxy lib-metrics logging-level <nsxproxy-logging-level-arg>

Set service nsx-proxy nestdb logging level


Set service nsx-proxy nestdb logging level.
set service nsx-proxy lib-nestdb logging-level <nsxproxy-logging-level-arg>

Set service nsx-proxy net logging level


Set service nsx-proxy net logging level.
set service nsx-proxy lib-net logging-level <nsxproxy-logging-level-arg>

Set service nsx-proxy rpc logging level


Set service nsx-proxy rpc logging level.
set service nsx-proxy lib-rpc logging-level <nsxproxy-logging-level-arg>

Set service nsx-proxy logging level


Set service nsx-proxy logging level.
set service nsx-proxy logging-level <nsxproxy-logging-level-arg>

Set service nsx-snproxy central logging level


Set service nsx-snproxy central logging level
set service nsx-snproxy central logging-level <nsx-snproxy-logging-level-arg>

Set service nsx-snproxy net logging level


Set service nsx-snproxy net logging level.
set service nsx-snproxy lib-net logging-level <nsx-snproxy-logging-level-arg>

Set service nsx-snproxy rpc logging level


Set service nsx-snproxy rpc logging level.
set service nsx-snproxy lib-rpc logging-level <nsx-snproxy-logging-level-arg>

Set service nsx-snproxy logging level


Set service nsx-snproxy logging level.
set service nsx-snproxy logging-level <nsx-snproxy-logging-level-arg>

Set NTP service start on boot


Configure the NTP service to start on boot.
set service ntp start-on-boot

Set log level for routing service


Set the log level of the FRR service.
set service router logging-level <edge-routing-service-logging-destination-arg> <edge-routing-service-logging-level-arg>

Set log level for routing platform service


Set the log level of the routing platform and config services.
set service routing-platform logging-level <edge-routing-platform-service-logging-level-arg>

Set the log level of EPSEC Library


Dynamically set EPSEC Library log level
set service security-hub epsec logging-level <epsec-lib-logging-level-arg>

Enable/Disable SecurityHub Fileless feature and sub-features


Enable/Disable SecurityHub Fileless feature and sub-features
set service security-hub fileless <fileless-feature-subtype-arg> <feature-operation-arg> vms <feature-target-arg>

Set the log level of security-hub


Dynamically set security-hub log level
set service security-hub logging-level <security-hub-logging-level-arg>

Set snmp service start on boot


Configure the snmp service to start on boot.
set service snmp start-on-boot

Set SSH service start on boot


Configure the SSH service to start on boot.
set service ssh start-on-boot

Set Telemetry service logging level


Set the log level of the Telemetry service.
set service telemetry logging-level <telemetry-level-arg>

Set SNMP service v1/v2c community string


Set the SNMP service v1/v2c community string in ciper text. This must be set before MIBs can be queried. Choose a string that is difficult to guess.
set snmp community

Set SNMP service v1/v2c community string


Set the SNMP service v1/v2c community string. This must be set before MIBs can be queried. Choose a string that is difficult to guess.
set snmp community <snmp-community-arg>

Set SNMP v2 Trap Targets


Set SNMP v2 Trap Targets.
set snmp v2-targets <hostname-or-ip-address-optional-port-arg> community <snmp-community-arg>

Set SNMP v3 Engine ID


Set SNMP v3 Engine ID.
set snmp v3-engine-id <v3-engine-id-arg>

Set SNMP v3 Protocols


Set SNMP v3 Protocols auth_protocol and priv_protocol.
set snmp v3-protocols auth-protocol <v3-auth-protocol-arg> priv-protocol <v3-priv-protocol-arg>

Set SNMP v3 Trap Targets


Set SNMP v3 Trap Targets.
set snmp v3-targets <hostname-or-ip-address-optional-port-arg> user <user-id-arg>

Set SNMP v3 users


Set SNMP v3 users,auth-password,priv-password in cipher text.
set snmp v3-users <user-id-arg>

Set SNMP v3 users


Set SNMP v3 users auth-password,priv-password in plain text.
set snmp v3-users <user-id-arg> auth-password <auth-password-arg> priv-password <priv-password-arg>

Set SSH Root login property


Enable SSH Root login property
set ssh root-login

set one vswitch runtime option


Set a runtime option for the specified vSwitch.
set vswitch runtime <option-name-arg> <option-value-arg>

Set vxlan uplink queue filter


Set vxlan uplink queue filter.
set vxlan-uplink-queue-filter <boolean-arg> dvs <dvs-name-arg>

Start Flow Monitor


Start flow monitor on a certain core for a given time. Flow monitor will start immediately and stop and dump the flow file automatically after the time passed. Dump file will be stored at /var/vmware/nsx/file-store/flow_mon.
start flow-monitor [core <core-id>] [timeout <time>]

Start service


Start the specified service.
start service <service-name-arg>

Start service nsx-lastline-rapid


Start the nsx-lastline-rapid service.
start service nsx-lastline-rapid

Start service Security Hub


Start the Security Hub service.
start service security-hub

Stop service


Stop the specified service.
stop service <service name> [force]

Stop service nsx-lastline-rapid


Stop the nsx-lastline-rapid service.
stop service nsx-lastline-rapid

Stop service Security Hub


Stop the Security Hub service.
stop service security-hub

Sync APH certificates from management plane


Syncs APH certificates from management plane to host. If you do not provide a password on the command line, you will be prompted to enter one.

Get the NSX Manager thumbprint by running the get certificate api thumbprint command on the specified NSX Manager.

sync-aph-certificates <manager-hostname-or-ip-address[:port]> username <username> thumbprint <thumbprint> [password <password>]

Verify NSX Edge service container image file


Verify NSX Edge service container image file.
verify image <configurable-image-filename>

Verify all configured logging servers


Verify iptables rules for all logging servers and update if needed
verify logging-servers

Total commands: 467