New, modified, or deprecated CLI commands

Prev Next

The CLI commands in this section were added, modified, or deprecated for this release.

New commands

SSH server security enhancement

SSH server security now provides client IP address-based access control for specified user accounts using the following CLI commands:

  • [no] ssh server access-control allow-users <user-host-ip-pattern>

  • [no] ssh server access-control allow-users <user-host-ip-pattern> enable

  • [no] ssh server access-control deny-users <user-host-ip-pattern>

  • [no] ssh server access-control deny-users <user-host-ip-pattern> enable

  • [no] ssh server access-control enable

Analysis Live commands

These commands are added:

  • [no] analysis live controlled-live-mode enable

    Enables controlled live mode on the appliance.

  • [no] analysis live url-dynamic-analysis enable

    Enables the URL dynamic analysis feature for the appliance.

  • analysis live download-complete-timeout <seconds>

    Sets the download complete timeout in seconds.

  • analysis live download-disable-threshold <value>

    Sets the download disable threshold value on the appliance.

  • analysis live download-disable-timeout <seconds>

    Sets download disable timeout in seconds.

Splunk integration enhancement

These commands define the parameters for the HTTP events that are sent to the HTTP Event Collector (HEC) on a Splunk Enterprise instance.

  • fenotify http service <service_name> prefer splunk collector-type <raw | event-collector>

    Specifies the event collector to which the data is sent.

  • fenotify http service <service_name> prefer splunk token <token>

    Specifies the Splunk token to establish the connection between the appliance and the Splunk instance.

  • fenotify http service <service_name> prefer splunk host <hostname>

    Specifies the hostname of the appliance.

  • fenotify http service <service_name> prefer splunk source <source>

    Specifies the source.

  • fenotify http service <service_name> prefer splunk index <index>

    Specifies the name of an index by which the event data is indexed.

Watch command
  • watch "<show command>" interval <seconds>

    Watch enables 'show' cli commands to run continuously in regular intervals without manual intervention. The “watch” command can be run in all modes (standard, enable, and config). It allows you to configure intervals. The default interval (when not specified explicitly) is 30 seconds.

Modified commands

AV-suite commands

Some AV-suite commands are modified to replace AV-suite with gcache. The following are the modified commands:

  • fenet dti gcache service

  • [no] fenet dti gcache service override

  • [no] fenet dti gcache service proxy

  • [no] fenet dti gcache service type

Deprecated commands

AV-suite commands

A subset of AV-suite commands is deprecated.

  • fenet dti av-suite service

  • [no] fenet dti av-suite service override

  • [no] fenet dti av-suite gcache service proxy

  • [no] fenet dti av-suite gcache service type

  • static-analysis av-suite whitelist enable

email-analysis url-dynamic-analysis commands
  • email-analysis live-interface <interface name>

  • [no] email-analysis controlled-live-mode enable

  • [no] email-analysis url-dynamic-analysis enable

  • [no] email-analysis url-dynamic-analysis default-gateway ip <IP address>

  • email-analysis url-dynamic-analysis download-complete-timeout <30-3600>

  • email-analysis url-dynamic-analysis download-disable-timeout <30s-3600s>

  • email-analysis url-dynamic-analysis download-response-timeout <10-300>

  • [no] email-analysis url-dynamic-analysis external ip <IP address><netmask> or mask len. e.g 255.255.255.0 or /24>

  • [no] email-analysis url-dynamic-analysis http-proxy <IP address or FQDN for Proxy><port number>

  • email-analysis url-dynamic-analysis internal subnet ip<IP address> <netmask or mask len. e.g 255.255.255.0 or /24>

  • [no] email-analysis url-dynamic-analysis nameserver ip <IP address>

  • [no] email-analysis url-dynamic-analysis proxy-authentication <Username> <Password>

  • show email-analysis url-dynamic-analysis