This article applies to:
Question:
- What command line tools are available for server administration in NAC 5.0?
- How do I reset a NAC server to factory default?
- How do I join or rejoin a Sensor to a CM in NAC 5.0?
Information:
Command line tools available in NAC 5.0 include the following.
- Note: Consult Trustwave TAC before using these tools. Incorrect usage can cause the NAC installation to be unusable and can permanently lose configuration data.
setup
This tool performs initial setup for a NAC appliance. Basic usage of this tool is fully covered in the Getting Started Guide.
- You can re-run Setup to view and change network settings only. See article Q20587.
rejoin_to_cm
Usage: rejoin_to_cm -c [CM IP address] -p [password]
This command rejoins a Sensor to a CM. Use the -c flag to specify the IP of the CM. Use the -p flag to set the password. If an option is not passed it will be requested interactively.
This command cannot be run on a CM.
save-recovery-image
save-recovery-image does not take any options.
This command saves the current Trustwave NAC Configuration and OS Version to a separate partition that is recoverable with the system_reset command. One way to use this feature is to run this command before upgrading a Trustwave NAC Sensor in a lab environment. You can test the upgrade, then restore the setup from the time when this command was run using the -k option.
This command is not run during setup. To take advantage of this feature, you must run this command once (from the command line, or from the CM web interface).
system_reset
This tool allows you to reset or roll back configuration on a NAC device.
Usage: system_reset [-y] [-n] [-d|-k|-r] [-h]
You must provide one of -d, -r, or -k.
The recovery image mentioned can be saved using save-recovery-image (see above), or from the NAC CM web application.
-y --yes Yes: Default answers to yes
-n --quiet Quiet: Quiet output
-d --default Default: Reset to factory default configuration, keeping current software version.
-r --reset Reset: Reset to factory default configuration, using software version saved in recovery image.
-k --keep Keep: Roll back to configuration in recovery image, using software version saved in recovery image.
-h --help Help: Print command usage then exit
remote
This tool allows you to connect to the CM and run specified commands on a sensor.
Commands:
- remote cmd [command] [ARGUMENT...]
- Runs command on sensor
- remote copy [file]
- Copies file to same path from CM to sensor
- remote help [command]
- Describe available commands or one specific command
- remote ls
- List connected sensors
Options for all commands:
- -s, [--sensor=SENSOR]
- Run on specified sensor name, or if omitted, run on all sensors
- -l, [--limit=N]
- Run on at most LIMIT sensors at once.
- -o, [--output=OUTPUT]
- Output sensor specific status to OUTPUT.SENSOR instead of standard output
Notes:
These commands replace some commands found in earlier versions of NAC.