show cms peer-service

Prev Next

Displays configuration information and data that is associated with a Central Management System peer. Each administrator must verify the CM Peer Service connection to all CM peers.

A status refresh is triggered in the following instances:

  • Periodically about every 1 to 5 minutes. Different interactions and different peers can be refreshed at different 1-minute to 5-minute intervals.

  • Whenever any peer service configuration changes (for example, a new token is imported, a feature on a CM peer is disabled, and so on).

  • When Central Management System High Availability (HA) failover occurs (when the secondary becomes the new primary). For information about how the CM Peer Service (and associated features) works in a HA configuration, refer to the Central Management System High Availability Guide.

The status might display "UNKNOWN" temporarily until the status is retrieved at the beginning of the refresh cycle.

For details about the CM Peer Distributed Correlation and CM Peer Signature Sharing features, refer to the Central Management System Administration Guide. For details about the CM Peer Update feature, refer to the Central Management System High Availability Guide.

Syntax

show cms peer-service [<peer_hostname>]

Parameters

peer_hostname

Name of a CM peer

Output fields

The following table describes the output fields for the command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

CMS peer-service enabled

Whether the CM Peer Service is enabled on the participating Central Management System appliance.

Enabled

Communication status of a CM peer.

Hostname

Name of a CM peer.

Address

IP address of a CM peer.

Auth-token checksum

MD5 checksum of an authentication token for a CM peer.

Distributed CMS Correlation

Enabled

Whether the CM Peer Distributed Correlation feature is enabled on a CM peer.

Status

Date and time when the status for CM Peer Distributed Correlation was retrieved.

Dynamic Threat Intelligence (DTI)

Enabled

Whether DTI interaction is enabled between CM peers to share locally generated signatures with remote CM peers.

Proxy mode

Whether a CM peer can use a proxy server to connect to other remote CM peers.

Status

Date and time when the status for CM Peer Signature Sharing and proxy server were retrieved.

Update Peer

Enabled

Whether the CM Peer Update feature is enabled to send the new primary node's address information to the original primary node's peer after a failover. This feature allows seamless routing to the new primary node peer, and it is used in Central Management System HA configuration.

Status

Date and time when the status for CM Peer Update was retrieved.

Example

The following example displays the status for all the connected CM peers.

hostname # show cms peer-service
CMS peer-service enabled:          yes
-----------------------------------------------------------------------------
   CMS peer barcelona:
      Enabled:                     yes
      Hostname:                    barcelona
      Address:                     10.2.140.73
      Auth-token checksum:         ee4ea5aa3e6e8c6799b6343978f1b271
      Interactions with peer:
         Distributed CMS Correlation:
             Enabled:                      yes
             Status:                       OK @ 2016/02/03 22:20:50
         Dynamic Threat Intelligence (DTI):
             Enabled:                      yes
             Proxy mode:                   No proxy
             Status:                       OK @ 2016/02/03 22:20:50
         Update Peer:
             Enabled:                      yes
             Status:                       OK @ 2016/02/03 22:13:51
-----------------------------------------------------------------------------
   CMS peer fire:
      Enabled:                     yes
      Hostname:                    eye
      Address:                     172.16.140.6
      Auth-token checksum:         b1c5f30f02427797b76fbe08fcc3580d
      Interactions with peer:
         Distributed CMS Correlation:
             Enabled:                      yes
             Status:                       OK @ 2016/02/03 22:20:50
         Dynamic Threat Intelligence (DTI):
             Enabled:                      yes
             Proxy mode:                   No proxy
             Status:                       OK @ 2016/02/03 22:20:50
         Update Peer:
             Enabled:                      yes
             Status:                       OK @ 2016/02/03 22:16:52
-----------------------------------------------------------------------------

User role

Admin

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Central Management System: Release 7.8