1-25
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring the ASA to Integrate with Cisco TrustSec
Monitoring the ASA Integrated with Cisco TrustSec
Monitoring Environment Data
Syntax:
show
cts
sxp
connections
security-group-table
[
sgt
value
|
name
name-value
]
Description:
This command displays the Cisco TrustSec environment information contained in security group table
on the ASA. This information includes the expiry timeout and security group name table. The security
group table is populated with data from the ISE when you import the PAC file.
You can select a specific table entry to display by specifying either a SGT or security group name. A
security group has a single name assigned to it. The same name can only be associated with a single SGT.
If you do not specify either an SGT or a name, the ASA displays all the environment data contained in
the security group table.
When an entry includes “reserved,” the SGT was assigned from a reserved range.
Output:
This example displays the environment data that appears when the ASA is unable to import the PAC file:
hostname# show cts environment-data
CTS Environment Data
====================
Status: Expired
Last download attempt: Failed
Retry_timer (60 secs) is running
This example displays the environment data that appears when the ASA has successfully imported the
PAC file:
hostname# show cts environment-data
CTS Environment Data
====================
Status: Active
Last download attempt: Successful
Environment Data Lifetime: 1036800 secs
Last update time: 16:43:39 EDT May 5 2011
Env-data expires in 11:01:18:27 (dd:hr:mm:sec)
Env-data refreshes in 11:01:08:27 (dd:hr:mm:sec)
This example displays the environment data that is contained in the security group table:
hostname# show cts environment-data sg-table
Valid until: 04:16:29 EST Feb 16 2012
Total number of entries: 4
Number of entries shown: 4
SG Name
SG Tag
Type
-------
------- ------------
sgt
value
Displays environment data for the security group name that matches
the specified SGT value; where
value
is a number from 1 to 65533.
name
name-value
Display environment data for the security group name that you
specify; where name-
value
is a 32-byte case-sensitive string.
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......