show running-config

Prev Next

To display the CLI commands for the settings in the running configuration, use the show running-config command in enable mode.

Note

The running configuration may include settings that have not been saved.

Syntax

show running-config [full | subtree nodename]

User role

All

Supported appliances

Command introduced before Release 7.6.0.

  • Endpoint Security (HX): Release 2.5

Parameters

full

Includes CLI commands for the factory default settings.

 subtree nodename

The root node of the node name for which commands are to be displayed.

Example

The following example lists all CLI commands for the saved active configuration.

hostname # show running-config
##
## Running database (file "initial" is currently active)
## Generated at 2015/04/28 20:25:48 +0000
## Software version: cms CMS (CMS) 7.6.0.347971 #347971 2015-04-26 16:26:55 x86_          64 build@vta114:FireEye/mammoth-dev (eng debug)
## Last config change ID: 478
## Hostname: IE-CM4400
##

##
## License keys
##
license install LK2-CONTENT_UPDATES-xxxx-xxxx-xxxx-xxxx-xxxx-xxxx-xxxx-xxxx-xxxx-xxxx-xxxx-xxxx-xxxx-xxx
license install LK2-FIREEYE_APPLIANCE-xxxx-xxxx-xxxx-xxxx-xxxx-xxxx-xxxx-xxxx                -xxxx-xxxx-xxxx-xxxx-xxxx-xxxx-xxxx-xxxx-xxxx-xxxx-xxx
license install LK2-FIREEYE_SUPPORT-xxxx-xxxx-xxxx-xxxx-xxxx-xxxx-xxxx-xxxx-xxxx-xxxx-xxxx-xxxx-xxxx-xxx
license install LK2-RESTRICTED_CMDS-xxxx-xxxx-xxxx-xxxx-xxxx-xxxx

##
## Network interface configuration
##
interface ether1 ip address 10.11.121.13 /24

##
## Routing configuration
##
ip default-gateway 10.11.121.1

##
## Other IP configuration
##
hostname IE-CM4400
ip domain-list fireeye.eng.com
ip name-server 10.11.10.11
ssh client global known-host "172.17.74.54 ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQ          EA2G4QnBmXStMRE1P2XKQh6uNjZ+xp6rEH3k93rcAF3PBUXuSdvkVq+shYK18BxfkpMngh2EtoBb/aTr
cuQeb6N7PPxn0gOCVCL8ZiVDUv8an9d/NNbhcD1Wgs0wGMOuunNCc9WjMISjcZF0VGKp9lrytz37UpCj

g7WWLaso7tdPh4+/tWdP66Oyhg4/BBCFKQ9wd7msJCZb467+tQrbJUcn1zHMi8C1zyKD2nXE7eXggLHd       
2+eriwqMmO1Jhy6D+becI/g9fT0F6JfyO05V+dvk5PrW6dIXI5hwjqYJByN9lTqTGM9VXB74HppA1vCW       DnjoyhQ8IPaAm0q1SbNsmteQ=="

##
## Local user account configuration
##
username admin password 7 $6$26eTwrZi$B09L6Wkb2Few.tqXs1exi6ykjjyORyt1Mi9ynWl          NMyr5YBNybe5OfJKT1fLCokrGHtdPWZ/TAF6T00KhW.pvD1

##
## AAA remote server configuration
##
fenet ssl cipher-list fips
# ldap bind-password ********
ldap ssl cipher-list fips
ldap ssl mode tls
# radius-server key ********
# tacacs-server key ********

##
## AAA configuration
##
aaa authentication password local length minimum 5

##
## SNMP configuration
##
snmp-server community QNBNkAa-5539GZm-D-qbf-S103-Ft79_ ro
snmp-server notify community sYy48vnK357RJ__eV7Y-d9--2-4LRhts

##
## Process Manager configuration
##
pm process cmsapi memory-limit 81919
pm process hx_aggregator launch auto
pm process hx_aggregator launch enable
no pm process openvpn launch enable
no pm process openvpn-mgr launch auto
no pm process openvpn-mgr launch enable
pm process rngd shutdown order 9999

##
## Network management configuration
##
#  fe-access proxy set username "" password ********
# email auth password ********
# email autosupport auth password ********
# fe-access set password *
# fenet dti mil service type CMS username engtest password ******
# fenet dti mil service type DTI username engtest password ******
# fenet dti source type CDN username engtest password ******
# fenet dti source type CMS username engtest password ******
# fenet dti source type DTI username engtest password ******
# fenet dti upload destination type CMS username engtest password ******
# fenet dti upload destination type DTI username engtest password ******
# fenet user fea-oi6yqxpbwepcm password ********
# lcd password ********
# web proxy auth basic password ********
boot bootmgr password 7 *
no cmc server backward-compatible enable
email mailhub mailhost
email notify recipient admin@acme.com class failure
email notify recipient admin@acme.com class info
no email notify recipient admin@acme.com detail
email notify recipient analyst@acme.com class failure
email notify recipient analyst@acme.com class info
email notify recipient analyst@acme.com detail
email notify recipient exec@acme.com class failure
email notify recipient exec@acme.com class info
email notify recipient exec@acme.com detail
email notify recipient testuser28@test.com class failure
email notify recipient testuser28@test.com class info
email notify recipient testuser28@test.com detail
email notify recipient user@acme.com class failure
email notify recipient user@acme.com class info
email notify recipient user@acme.com detail
no email notify recipient user@admin.com class failure
email notify recipient user@admin.com class info
email notify recipient user@admin.com detail
email return-addr notify@acme.com
email ssl cipher-list fips
email ssl mode tls
fenet dti mil service type DTI address mil-fenet1.fireeye.com port 443
no fenet license update enable
no fenet proxy enable
ipmi lan shutdown
no lcd actions enable
report email recipient analyst@acme.com
report email recipient exec@acme.com
web client ssl cipher-list fips
web server ssl cipher-list fips

##
## IPv4 packet filtering configuration
##
ip filter chain INPUT rule append tail target ACCEPT dup-delete in-intf "ether+"       
ip filter chain OUTPUT rule append tail target ACCEPT dup-delete out-intf "ether+"     

##
## IPv6 packet filtering configuration
##
ipv6 filter chain INPUT rule append tail target ACCEPT dup-delete in-intf "ether+"     
ipv6 filter chain OUTPUT rule append tail target ACCEPT dup-delete out-intf "ether+"         
##
## CMC configuration
##
# cmc appliance IE-EX3400 auth password password ********
# cmc auth ssh-rsa2 identity admin private ********
# cmc client server auth password password ********
# cmc rendezvous client auth password password ********
# cmc rendezvous server auth default password password ********
cmc appliance IE-EX3400
cmc appliance IE-EX3400 address 172.17.74.54
cmc appliance IE-EX3400 auth password username admin
cmc appliance IE-EX3400 auth ssh-dsa2 identity ""
cmc appliance IE-EX3400 auth ssh-dsa2 username admin
cmc appliance IE-EX3400 auth ssh-rsa2 identity ""
cmc appliance IE-EX3400 auth ssh-rsa2 username admin
cmc appliance IE-EX3400 authtype password
cmc appliance IE-EX3400 check-status
cmc appliance IE-EX3400 client-requests enable
cmc appliance IE-EX3400 comment ""
cmc appliance IE-EX3400 connection auto
cmc appliance IE-EX3400 enable
cmc appliance IE-EX3400 port 22
cmc appliance IE-EX3400 source address 0.0.0.0
cmc appliance IE-EX3400 source port 0
cmc appliance IE-EX3400 web port http 11000
cmc appliance IE-EX3400 web port https 443
cmc appliance IE-EX3400 web protocol http
cmc auth ssh cipher-list fips
cmc auth ssh host-key global-only
cmc auth ssh host-key strict
cmc auth ssh min-key-length 2048
cmc auth ssh-rsa2 identity admin public "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAAB          AQCy7znhlKF4NmqKx2/HQvhljcc/o75ts8ixWOqZhj8RWiu2nwC2tEXG1yvHLsBET/pF0Bo3SxP/ul1W       
uJecdGHAVfbmpXIKpYmxSHLP2trQ4PTnJtHi7tzSM4TIq3X4qaF5KCURPeyBdlOfHDu3qdcCCzlaD0/0       
QwyDP4cmpQfQAbFq6fXsaEg0O6UOag55al6CFgIZEu9+CI6rnainJxWfaUE2ojPbyMV0iMOH+X4w8Og1       
n3NjOVJddDqCbjafzdTaQyMV7D6MQgVzLXuVuroRMn6AuRVtk7fWWjMuqaQFmNcC4eLpGW0cGxWU4RhO       2EJ+vLjW9o1LavrgWqPboRH7"
cmc client enable
cmc group all appliance IE-EX3400
cmc group sysgroup.Email_MPS appliance IE-EX3400
cmc group sysgroup.Email_MPS comment "System Group: eMPS"
cmc group sysgroup.File_MPS comment "System Group: fMPS"
cmc group sysgroup.HX comment "System Group: HX"
cmc group sysgroup.Web_MPS comment "System Group: wMPS"

##
## SSH and Key configuration
##
ssh client global cipher-list fips
ssh client min-key-length 2048
ssh server cipher-list fips
ssh server min-key-length 2048

##
## X.509 certificates configuration
##
## Certificate name system-self-signed, ID e4f9ff2582b3b428b8e7c142347b37cc0cc262b3      
## (public-cert config omitted since private-key config is hidden)
crypto certificate min-key-size 2048
crypto certificate secure-hashes-only

##
## Managed Defense configuration
### managed-defense vpn http-proxy host "" port 0 auth-type none username "" password ********      

##
## Compliance configuration
##
compliance options fips-mode-crypto enable
no compliance options ftp-file-transfer enable
no compliance options http-file-transfer enable
no compliance options manual-key-entry enable
no compliance options restricted-license enable
compliance options snmp-crypto-limit enable

##
## Miscellaneous other settings
##
internal set modify - /fireeye/wicadfish/config/wicad_enable value bool true
internal set modify - /mvx/cluster/config/cloud_mvx/license/enable value bool true
internal set modify - /pegasus/bott/config/enable value bool false
internal set modify - /pm/process/rngd/delete_trespassers value bool false