System Manager command line interface operations

Last Updated : Jan 23, 2024 |

#

Command

Parameters

Description

Usage

1

changeIPFQDN

  • -IP <new Management interface or Out of Band Management IP address for System Manager>

  • -FQDN <new Management or Out of Band Management fully qualified domain name for System Manager>

  • -GATEWAY <new Management interface or Out of Band Management Gateway address for System Manager>

  • -NETMASK <new Management interface or Out of Band Management netmask address for System Manager>

  • -DNS <new DNS address for System Manager>

  • -SEARCH <new search list for DNS address>

Updates the existing Management interface or Out of Band Management IP address, FQDN, Gateway, Netmask, DNS, and the search list with the new value.

Note:

On the System Manager Release 7.1 and later, if you change the IP Address of System Manager using the changeIPFQDN command, the system changes the host ID of System Manager and invalidates the existing installed license file. Therefore, you must reinstall the license file on System Manager after changing the IP Address of System Manager.

  • changeIPFQDN -IP <new IP address>

  • changeIPFQDN -FQDN <new fully qualified domain name>

  • changeIPFQDN -IP <new IP address> -GATEWAY <new Gateway address for System Manager> -SEARCH <new search list for DNS address>

2

changePublicIPFQDN

  • -publicIP <new IP address for System Manager>

  • -publicFQDN <new fully qualified domain name for System Manager>

  • -publicGATEWAY <new Gateway address for System Manager>

  • -publicNETMASK <new netmask address for System Manage>

Updates the existing Public IP address, FQDN, Gateway, and Netmask with the new value.

  • changePublicIPFQDN -publicIP <new Public IP address>

  • changePublicIPFQDN -publicFQDN <new fully qualified domain name for public interface>

  • changePublicIPFQDN -publicIP <new Public IP address> -publicGATEWAY <new Public Gateway address for System Manager>

3

upgradeSMGR

<absolute path to the dmutility.bin> -m –v

Upgrades System Manager using the data migration utility.

upgradeSMGR dmutility *.bin -m –v

4

SMGRPatchdeploy

<absolute path to the System Manager service pack or the software patch>

Installs the software patch or the service pack for System Manager.

SMGRPatchdeploy <absolute path to SMGRservicepackName>

Note:

Copy the System Manager service pack or patches that you must install to /swlibrary.

5

configureTimeZone

Time zone that you select

Configures the time zone with the value that you select.

configureTimeZone

Select a time zone. For example, America/Denver

6

configureNTP

<IP address of NTP server>

Configures the NTP server details.

configureNTP <IP address of NTP server>

Separate IP addresses or hostnames of NTP servers with commas (,).

7

createCA

Creates a new Certificate Authority by using SHA2 signing algorithm and 2048 key size.

For more information, see, Creating a new Certificate Authority by using SHA2 signing algorithm and 2048 key size.

createCA

You must provide the desired Common Name (CN)

8

configureOOBM

Enables or disables the Out of Band Management configuration.

  • To enable Out of Band Management: configureOOBM –EnableOOBM

  • To disable Out of Band Management: configureOOBM -DisableOOBM

9

enableOOBMMultiTenancy

If Out of Band Management and MultiTenancy are enabled on system, use this command to provision tenant administrators to available on public interface.

10

setSecurityProfile

Enabling the commercial and military grade hardening.

  • Enabling commercial grade hardening: setSecurityProfile --enable-commercial-grade

  • Enabling military grade hardening: setSecurityProfile --enable-military-grade

11

EASGManage

Enables or disables EASG.

  • EASGManage --enableEASG

  • EASGManage --disableEASG

12

EASGStatus

Displays the status of EASG.

13

EASGProductCert

Displays the EASG certificate details.

EASGProductCert --certInfo

14

EASGSiteCertManage

To manage EASG Certificates.

15

editHosts

To add, replace, and delete the IP Address, FQDN, or hostname entries in the /etc/hosts file.

16

  • swversion

  • swversion -s

  • swversion: Displays the System Manager software information.

  • swversion -s: Displays the System Manager software version and also displays information about the application name, profile, and deployment type.

  • Note:

    The output varies based on the application deployment and the virtualization environment.

17

changeVFQDN

To change the System Manager Virtual FQDN.

changeVFQDN

Type the System Manager Virtual FQDN.

Note:

When you run the changeVFQDN command on System Manager, data replication synchronization between System Manager with Session Manager and other elements fails To correct VFQDN on other elements and to retrieve new VFQDN from System Manager, see product-specific Administering document.

18

pairIPFQDN

Changing the IP address and FQDN on the secondary System Manager server when the secondary is in the standby or active mode.

  • If you changed both the IP address and FQDN of primary server, type the following on the secondary server: #sh $MGMT_HOME/utils/ipfqdnchange/pairIpFqdnChange.sh -OLDIP <Old IP of the primary server> -NEWIP <New IP of the primary server> -OLDFQDN <Old FQDN of the primary server> -NEWFQDN <New FQDN of the primary server>

  • If you changed the IP address of primary server, type the following on secondary server: #sh $MGMT_HOME/utils/ipfqdnchange/pairIpFqdnChange.sh -OLDIP <Old IP of the primary server> -NEWIP <New IP of the primary server>

  • If you changed FQDN of primary server, type the following on secondary server: #sh $MGMT_HOME/utils/ipfqdnchange/pairIpFqdnChange.sh -OLDFQDN <Old FQDN of the primary server> -NEWFQDN <New FQDN of the primary server>

19

smgr

Starts, stops, and checks the status of the Application server.

smgr start/stop/status

20

smgr-db

Starts, stops, and checks the status of postgresql.service.

smgr-db start/stop/status

21

getUserAuthCert

Generates a user specific certificate for System Manager to facilitate certificate-based authentication.

22

changeCipherSuiteList

Configures cipher suite mode for System Manager

  • To configure strict cipher suite list, type the following command. This would disable CBC ciphers: changeCipherSuiteList LIST2

  • To configure relax cipher suite list, type the following command. This would enable CBC ciphers: changeCipherSuiteList LIST1

23

collectLogs

Collects the required logs.

  • To collect all the logs: collectLogs

  • To collect all the logs along with backup: collectLogs -Db

  • To collect all the logs along with CND data: collectLogs –CND

24

rebootVM

Reboots the System Manager virtual machine.

Important:

If you configured a NFS mount on System Manager for Session Manager Performance Data (perfdata) collection, then, if and when you reboot/boot System Manager virtual machine, you need to ensure that you manually re-mount the NFS store once the System Manager VM is up and you are able to log in to the VM through SSH. Failure to re-mount the NFS partition will result in the Session Manager perfdata to go, by default, into a folder which is in the root (/) partition of the System Manager file system. This might cause the partition to get full which in-turn might cause issues with the System Manager application.

Type y or n to reboot the System Manager virtual machine.

25

powerOffVM

Power off the System Manager virtual machine.

Type y or n to power off the System Manager virtual machine.

26

sudo /bin/systemctl (parameter) snmpd

start/stop/restart/status

To start or stop, and to check status of the SNMP service.

27

sudo /bin/systemctl (parameter) spiritAgent

start/stop/restart/status

To start or stop, and to check status of the Spirit Agent service.

28

sudo /bin/systemctl (parameter) cnd

start/stop/restart/status

To start or stop, and to check status of the CND service.

29

encryptionPassphrase

[add | change | remove | list]

To add, change, remove, and display the encryption passphrase.

  • encryptionPassphrase add: To add encryption passphrase.

  • encryptionPassphrase change: To change existing encryption passphrase.

  • encryptionPassphrase remove: To remove encryption passphrase.

  • encryptionPassphrase list: To display the encryption passphrase and slot assignment.

30

encryptionRemoteKey

[add | remove | list]

To add, remove, and display the remote key server.

  • encryptionRemoteKey add: To add remote key server.

  • encryptionRemoteKey remove: To remove remote key server.

  • encryptionRemoteKey list: To display the remote key server and slot assignment.

31

encryptionLocalKey

[enable | disable]

To enable and disable the local key store.

  • encryptionLocalKey enable: To enable local key store.

  • encryptionLocalKey disable: To disable local key store.

32

encryptionStatus

Displays information about encryption on the system.

encryptionStatus displays information about encryption on the system.

33

updateLogRetention.sh

[-p] [-v] [maxRetentionTime]

Manages the log retention time.

34

pruneAllLogs.sh

[-b] [-t] [-v] [-h] [maxRetentionTime]

Manages the deletion of log files.

35

manageEntityClassWhitelist

[-h] [addAll -e <ENTITY_CLASS_NAME> -f <INPUT_FILE> -u <USERNAME> -p <PASSWORD>] [add -e <ENTITY_CLASS_NAME> -s <SUBJECT_NAME> -u <USERNAME> -p <PASSWORD>] [list -e <ENTITY_CLASS_NAME> -f <OUTPUT_FILE> -u <USERNAME> -p <PASSWORD> -pn <PAGENUMBER> -ps <PAGESIZE>] [view -e <ENTITY_CLASS_NAME> -s <SUBJECT_NAME> -f <OUTPUT_FILE> -u <USERNAME> -p <PASSWORD>] [subjectCheck -e <ENTITY_CLASS_NAME> -u <USERNAME> -p <PASSWORD>] [deleteAll -e <ENTITY_CLASS_NAME> -u <USERNAME> -p <PASSWORD>] [delete -e <ENTITY_CLASS_NAME> -s <SUBJECT_NAME> -u <USERNAME> -p <PASSWORD>]

You can add, list, view, and delete the subject names for the provided entity class.

You can add and delete the bulk entries of subject names and check the status of the subject name validation for the entity class.

36

outboundConnectionLogging

[enable] [disable]

If you enable this, you can capture the logs in the /var/log/Avaya/connections file for every new outgoing connections initiated from System Manager.

37

configureOutboundFirewall

[add {-s} {-f}] [list] [status] [remove {-e} {-f}] [disable] [overwrite {-s} {-f}] [enable-logging] [disable-logging] [logging-status]

If you enable this, you can configure System Manager outbound firewall.

38

setSecurityPolicy

[--status] [--display-only] [--restore-standard] [--refresh-custom]

You can modify the default password policy settings of System Manager by using the setSecurityPolicy command. This command is only applicable for changing or setting up the password for the CLI user or root user that gets created at the time of deployment.

39

configureSyslog

-h [-e] [-s <syslog server destination> ""]

You can configure, list, and delete the remote syslog server by using the configureSyslog command.

40

ASP_SSH

[enable] [status]

If System Manager is deployed on the Avaya Solutions Platform 130 Release 5.1 host, you can enable SSH and check the SSH status of the Avaya Solutions Platform 130 host.

41

toggleOldWebLMClientCommunication

Run this utility as the following:

  • Type 1 to check the old WebLM client communication status

  • Type 2 to enable the old WebLM client communication status

  • Type 3 to disable the old WebLM client communication status

Note:

The user can enter the values specified above based on their usage.

This utility is used to check, enable, and disable the old WebLM client communication status with releases 10.1.3.1 and later. For the older WebLM client communication, the default status is ENABLED.

  • Type 1 to check the old WebLM client communication status.

  • Type 2 to enable the old WebLM client communication status.

  • Type 3 to disable the old WebLM client communication status.

If your input is 1 and the current status is enabled, the message
Old WebLM client communication status is ENABLED
is displayed.
If the current status is disabled, the message
Old WebLM client communication status is DISABLED
is displayed.
If your input is 2, the message
Old WebLM client communication is now ENABLED
is displayed.
If your input is 3, the message
Old WebLM client communication is now DISABLED
is displayed.