Cisco ASA Series Cli Configuration Manual page 929

Software version 9.0 for the services module
Hide thumbs Also See for ASA Series:
Table of Contents

Advertisement

Chapter 1
Configuring the ASA to Integrate with Cisco TrustSec
Monitoring Environment Data
Syntax:
show cts sxp connections
Description:
This command displays the Cisco TrustSec environment information contained in security group table
on the ASA. This information includes the expiry timeout and security group name table. The security
group table is populated with data from the ISE when you import the PAC file.
You can select a specific table entry to display by specifying either a SGT or security group name. A
security group has a single name assigned to it. The same name can only be associated with a single SGT.
sgt value
name name-value
If you do not specify either an SGT or a name, the ASA displays all the environment data contained in
the security group table.
When an entry includes "reserved," the SGT was assigned from a reserved range.
Output:
This example displays the environment data that appears when the ASA is unable to import the PAC file:
hostname# show cts environment-data
CTS Environment Data
====================
Status:
Last download attempt:
Retry_timer (60 secs) is running
This example displays the environment data that appears when the ASA has successfully imported the
PAC file:
hostname# show cts environment-data
CTS Environment Data
====================
Status:
Last download attempt:
Environment Data Lifetime: 1036800 secs
Last update time:
Env-data expires in
Env-data refreshes in
This example displays the environment data that is contained in the security group table:
hostname# show cts environment-data sg-table
Valid until: 04:16:29 EST Feb 16 2012
Total number of entries: 4
Number of entries shown: 4
SG Name
-------
security-group-table [sgt value | name name-value]
Displays environment data for the security group name that matches
the specified SGT value; where value is a number from 1 to 65533.
Display environment data for the security group name that you
specify; where name-value is a 32-byte case-sensitive string.
Expired
Failed
Active
Successful
16:43:39 EDT May 5 2011
11:01:18:27 (dd:hr:mm:sec)
11:01:08:27 (dd:hr:mm:sec)
SG Tag Type
------- ------------
Monitoring the ASA Integrated with Cisco TrustSec
Cisco ASA Series CLI Configuration Guide
1-25

Advertisement

Table of Contents
loading

Table of Contents