The Central Management System Peer Signature Sharing feature allows Central Management System peers to share locally generated signatures with remote Central Management System peers using the Central Management System Peer Service. When local signature generation settings are enabled, you can verify the number of active rules that are shared with local and remote Central Management System peers by using the show localsig command. When Central Management System Peer Signature Sharing is disabled, local and remote peers do not share locally generated signatures.
An enterprise customer can have geographically distributed Central Management System networks (for example, US, EU, APAC) with separate Central Management System appliances that are all connected using the Central Management System Peer Service. Central Management System Peer Signature Sharing allows the Central Management System appliance in the Central Management System network in the US to share locally generated signatures with the other platforms in the EU and APAC. When one peered Central Management System network identifies a malicious URL, the signature is shared with all the other peered Central Management System networks. When deployed inline, any appliance in the EU or APAC automatically blocks a malicious URL identified in the US. Therefore, all users are protected in all peered Central Management System networks.
Admin access to the Central Management System appliance.
A connection to the Dynamic Threat Intelligence (DTI) Cloud.
Network connectivity over SSH (port 22) and HTTPS (port 443) must be allowed on each of the participating Central Management System appliances.
The Network Security appliance must be deployed inline.
CM Peer Service must be enabled on each of the participating Central Management System appliances.
Authentication tokens must be exchanged for communication between the CM peers.
The local signature generation settings must be enabled on all the CM peers using the
localsig enablecommand.