New, modified, or deprecated CLI commands

Prev Next

The CLI commands in this section were added, modified, or deprecated for this release.

New commands

SSH server security enhancement

SSH server security now provides client IP address-based access control for specified user accounts using the following CLI commands:

  • [no] ssh server access-control allow-users <user-host-ip-pattern>

  • [no] ssh server access-control allow-users <user-host-ip-pattern> enable

  • [no] ssh server access-control deny-users <user-host-ip-pattern>

  • [no] ssh server access-control deny-users <user-host-ip-pattern> enable

  • [no] ssh server access-control enable

Enabling ALPN

Use the following command to enable ALPN if it is in disabled state. ALPN is generally enabled by default.

  • policymgr ssl-intercept config alpn enable

DGA detection

NX devices detect Domain Generation Algorithms (DGA) attacks when you enable DGA detection. You can enable and disable DGA detection using the following CLI commands:

  • [no] smartvision dga-detect

    Enables or disables DGA detection.

  • smartvision dga-detect config update now

    Forces a DGA configuration update.

  • [no] smartvision dga-detect whitelist* <domain address>

    Configures an individual whitelist domain. Use the no parameter to delete the whitelist domain.

  • smartvision dga-detect alert-threshold-intv <0-3600>

    Sets the DGA alert threshold interval to between 0 and 3600 seconds.

  • show smartvision dga-detect activity <1-240>

    Displays DGA activity for the last number of hours up to 240 hours.

  • show smartvision dga-detect config

    Displays the DGA configuration.

BOTT alert thresholding redesign

These commands are used to configure IPS thresholding.

  • [no] bottracker ips event-filter enable

  • bottracker ips event-filter count <count>

  • bottracker ips event-filter count <count>

bottracker commands to support IOC feature

These commands enable the IOC feature for detection.

  • bottracker ioc ip enable

    Enables the IOC IP feature that allows the Network Security appliance to match IP addresses detected in the network traffic against the configured IOC IP addresses.

  • [no] bottracker ioc ip enable

    Disables the IPS event filtering feature to stop filtering IPS events.

  • bottracker ioc domain enable

    Enables the IOC domain feature that allows the Network Security appliance to match domains detected in network traffic.

  • bottracker ioc domain enable

    Disables the IOC domain feature from detection.

  • bottracker ioc url enable

    Enables the IOC URL feature that allows the Network Security appliance to match urls detected in the network traffic against the configure urls.

Commands for filtering IPS events

These commands enable the IPS Event filtering feature. You can enable or disable IPS event filtering feature using the following CLI commands:

  • bottracker ips event-filter enable

    Enables the IPS Event filtering feature and filter IPS events detected by the IPS-enabled appliance.

  • [no] bottracker ips event-filter enable

    Disables the IPS Event filtering feature for event detected.

  • bottracker ips event-filter count <count>

    Configures ips event count for reaching event filter limit.

  • bottracker ips event-filter timeout <seconds>

    Configures time period (in seconds) for which IPS event count is monitored.

Splunk integration enhancement

These commands define the parameters for the HTTP events that are sent to the HTTP Event Collector (HEC) on a Splunk Enterprise instance.

  • fenotify http service <service_name> prefer splunk collector-type <raw | event-collector>

    Specifies the event collector to which the data is sent.

  • fenotify http service <service_name> prefer splunk token <token>

    Specifies the Splunk token to establish the connection between the appliance and the Splunk instance.

  • fenotify http service <service_name> prefer splunk host <hostname>

    Specifies the hostname of the appliance.

  • fenotify http service <service_name> prefer splunk source <source>

    Specifies the source.

  • fenotify http service <service_name> prefer splunk index <index>

    Specifies the name of an index by which the event data is indexed.

Evidence Collector command

Evidence collector Edition for file extraction

  • foxd config object-extract enable

    Enables object extraction on the Evidence Collector edition Network Security NX sensor.

Watch command
  • watch "<show command>" interval <seconds>

    Watch enables 'show' cli commands to run continuously in regular intervals without manual intervention. The “watch” command can be run in all modes (standard, enable, and config). It allows you to configure intervals. The default interval (when not specified explicitly) is 30 seconds.

Interface network statistics
  • show network stats interface <interfaceName>

    Displays network statistics for the specified interface.

Localsig enhancements
  • show localsig file-hash

    Show local signature generated file hashes.

  • show localsig url

    show localsig url.

Modified commands

AV-suite commands

Some AV-suite commands are modified to replace AV-suite with gcache. The following are the modified commands:

  • fenet dti gcache service

  • [no] fenet dti gcache service override

  • [no] fenet dti gcache service proxy

  • [no] fenet dti gcache service type

Deprecated commands

AV-suite commands

A subset of AV-suite commands is deprecated.

  • fenet dti av-suite service

  • [no] fenet dti av-suite service override

  • [no] fenet dti av-suite gcache service proxy

  • [no] fenet dti av-suite gcache service type

  • static-analysis av-suite whitelist enable