dump controller mrl-tlsinfo
Focus
Focus
Prisma SD-WAN

dump controller mrl-tlsinfo

Table of Contents

dump controller mrl-tlsinfo

Use the dump controller mrl-tlsinfo command to display TLS connection information for MRL (Multi-Relay Layer) connections between the ION device and the Strata Cloud Manager controller. The output shows the TLS version, cipher suite, key exchange method, and Post-Quantum Cryptography (PQC) status for each active controller connection.

Command

dump controller mrl-tlsinfo

Options

None

Command Notes

RoleSuper, Read Only, Monitor
Related Commands
config controller tls13
config controller tls13-cipher
dump controller cipher
Introduced inRelease 6.8.1

Example

TLS 1.2 connection without Post-Quantum Cryptography:
dump controller mrl-tlsinfo MRL TLS Info -------------------------------------------------------------------------------------------------------------- Host : controller.local.cgnx.net TLS Version : TLSv1.2 Cipher : ECDHE-RSA-AES256-GCM-SHA384 Key Exchange : x25519 PQC : false
TLS 1.3 connection with Post-Quantum Cryptography:
dump controller mrl-tlsinfo MRL TLS Info -------------------------------------------------------------------------------------------------------------- Host : controller.local.cgnx.net TLS Version : TLSv1.3 Cipher : TLS_AES_256_GCM_SHA384 Key Exchange : X25519MLKEM768 PQC : true
In the output:
  • Host — The controller hostname for the MRL connection.
  • TLS Version — The negotiated TLS protocol version (TLSv1.2 or TLSv1.3). TLS 1.3 is the default for ION devices running release 6.8.1 or later when both the device and controller support it.
  • Cipher — The cipher suite used for the connection. TLS 1.3 cipher suites follow the format TLS_<algorithm>_<mode>_<hash>.
  • Key Exchange — The key exchange method used during the TLS handshake. For TLS 1.3 connections with Post-Quantum Cryptography enabled, this field shows hybrid key exchange groups such as X25519MLKEM768, SecP256r1MLKEM768, or SecP384r1MLKEM1024 that combine classical elliptic curve algorithms with NIST-approved ML-KEM algorithms.
  • PQC — Shows true when the connection uses quantum-resistant key exchange (TLS 1.3 with hybrid key exchange groups). Shows false for TLS 1.2 connections or TLS 1.3 connections using classical key exchange only.