Cisco Identity Services Engine CLI Reference Guide, Release 1.4
Total Page:16
File Type:pdf, Size:1020Kb
Cisco Identity Services Engine CLI Reference Guide, Release 1.4 First Published: 2015-02-20 Last Modified: 2015-04-29 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax: 408 527-0883 THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL STATEMENTS, INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL ARE BELIEVED TO BE ACCURATE BUT ARE PRESENTED WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. USERS MUST TAKE FULL RESPONSIBILITY FOR THEIR APPLICATION OF ANY PRODUCTS. THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH IN THE INFORMATION PACKET THAT SHIPPED WITH THE PRODUCT AND ARE INCORPORATED HEREIN BY THIS REFERENCE. IF YOU ARE UNABLE TO LOCATE THE SOFTWARE LICENSE OR LIMITED WARRANTY, CONTACT YOUR CISCO REPRESENTATIVE FOR A COPY. The Cisco implementation of TCP header compression is an adaptation of a program developed by the University of California, Berkeley (UCB) as part of UCB's public domain version of the UNIX operating system. All rights reserved. Copyright © 1981, Regents of the University of California. NOTWITHSTANDING ANY OTHER WARRANTY HEREIN, ALL DOCUMENT FILES AND SOFTWARE OF THESE SUPPLIERS ARE PROVIDED “AS IS" WITH ALL FAULTS. CISCO AND THE ABOVE-NAMED SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESSED OR IMPLIED, INCLUDING, WITHOUT LIMITATION, THOSE OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OR ARISING FROM A COURSE OF DEALING, USAGE, OR TRADE PRACTICE. IN NO EVENT SHALL CISCO OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT, SPECIAL, CONSEQUENTIAL, OR INCIDENTAL DAMAGES, INCLUDING, WITHOUT LIMITATION, LOST PROFITS OR LOSS OR DAMAGE TO DATA ARISING OUT OF THE USE OR INABILITY TO USE THIS MANUAL, EVEN IF CISCO OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network topology diagrams, and other figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional and coincidental. All printed copies and duplicate soft copies of this document are considered uncontrolled. See the current online version for the latest version. Cisco has more than 200 offices worldwide. Addresses and phone numbers are listed on the Cisco website at www.cisco.com/go/offices. Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: https://www.cisco.com/c/en/us/about/legal/trademarks.html. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1721R) © 2015 Cisco Systems, Inc. All rights reserved. CONTENTS CHAPTER 1 Cisco ISE Command-Line Interface 1 Cisco ISE Administration and Configuration Using CLI 2 Accessing the Cisco ISE CLI Using a Local System 2 Accessing the Cisco ISE CLI with Secure Shell 3 Cisco ISE CLI Administrator Account 4 Cisco ISE CLI User Accounts 5 Creating a Cisco ISE CLI User Account 5 Cisco ISE CLI User Account Privileges 6 Supported Hardware and Software Platforms for Cisco ISE CLI 7 CHAPTER 2 Cisco ISE CLI Commands in EXEC Mode 9 Cisco ISE CLI Session Begins in EXEC Mode 11 application install 12 application configure 14 Monitoring Database Settings 14 Live Statistics of Profiling Events 15 Export and Import Internal CA Store 16 Create Missing Indexes 16 Enable ACS Migration 16 application remove 18 application reset-config 19 application reset-passwd 21 application start 23 application stop 26 application upgrade 28 backup 32 Cisco Identity Services Engine CLI Reference Guide, Release 1.4 iii Contents Backing up Cisco ISE Configuration Data 33 Backing up Cisco ISE Operational Data 34 backup-logs 35 clear screen 37 clock 38 cls 40 configure 41 copy 42 Running Configuration 43 Copying Running Configuration to a Remote Location 44 Copying Running Configuration from a Remote Location 44 Startup configuration 44 Copying Startup Configuration to a Remote Location 45 Copying Startup Configuration from a Remote Location 45 Copying Log files 45 crypto 46 debug 49 delete 53 dir 54 exit 56 forceout 57 halt 58 help 59 mkdir 60 nslookup 61 password 63 patch install 64 patch remove 66 ping 68 ping6 69 reload 71 restore 72 Restoring Cisco ISE Configuration Data from the Backup 73 Restoring Cisco ISE Operational Data from the Backup 75 Cisco Identity Services Engine CLI Reference Guide, Release 1.4 iv Contents Restoring Cisco ISE Configuration Data and Cisco ADE OS data from the Backup 75 rmdir 77 ssh 78 tech 80 telnet 82 terminal length 83 terminal session-timeout 84 terminal session-welcome 85 terminal terminal-type 86 traceroute 87 undebug 88 which 91 write 92 CHAPTER 3 Cisco ISE CLI Commands in EXEC Show Mode 93 show 94 show application 95 show backup 97 show banner 99 show cdp 100 show clock 102 show crypto 103 show disks 104 show icmp-status 106 show interface 108 show inventory 110 show ip 112 show logging 113 show logins 116 show memory 117 show ntp 118 show ports 119 show process 121 show repository 123 Cisco Identity Services Engine CLI Reference Guide, Release 1.4 v Contents show restore 124 show running-config 125 show startup-config 127 show tech-support 129 show terminal 130 show timezone 131 show timezones 132 show udi 133 show uptime 134 show users 135 show version 136 CHAPTER 4 Cisco ISE CLI Commands in Configuration Mode 137 Switch to Configuration Mode in EXEC Mode 139 Configuring Cisco ISE in the Configuration Mode 140 Configuring Cisco ISE in the Configuration Submode 141 CLI Configuration Command Default Settings 142 cdp holdtime 143 cdp run 144 cdp timer 145 clear screen 146 clock timezone 147 Changing the Time Zone on Cisco ISE Nodes 148 Common Time Zones 148 Australia Time Zones 149 Asia Time Zones 150 cls 151 conn-limit 152 do 153 end 157 exit 158 hostname 159 icmp echo 161 interface 162 Cisco Identity Services Engine CLI Reference Guide, Release 1.4 vi Contents ip address 164 ip default-gateway 166 ip domain-name 167 ip host 169 ip name-server 171 ip route 173 ipv6 address autoconfig 175 Configuring IPv6 Auto Configuration 175 Verifying the Privacy Extensions Feature 176 ipv6 address dhcp 177 kron occurrence 179 kron policy-list 182 logging 184 max-ssh-sessions 185 ntp 186 ntp authenticate 188 ntp authentication-key 189 ntp server 191 Configuring Trusted Keys for NTP Server Authentication 192 Verifying the Status of Synchronization 192 ntp trusted-key 194 rate-limit 195 password-policy 196 repository 198 service 201 shutdown 203 snmp-server community 204 snmp-server contact 206 snmp-server location 207 synflood-limit 208 username 209 which 211 Cisco Identity Services Engine CLI Reference Guide, Release 1.4 vii Contents Cisco Identity Services Engine CLI Reference Guide, Release 1.4 viii Cisco ISE Command-Line Interface Note The documentation set for this product strives to use bias-free language. For purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. This chapter provides information on the Cisco Identity Services Engine (Cisco ISE) command-line interface (CLI) that you can use to configure and maintain Cisco ISE. • Cisco ISE Administration and Configuration Using CLI, on page 2 • Cisco ISE CLI Administrator Account, on page 4 • Cisco ISE CLI User Accounts, on page 5 • Cisco ISE CLI User Account Privileges, on page 6 • Supported Hardware and Software Platforms for Cisco ISE CLI, on page 7 Cisco Identity Services Engine CLI Reference Guide, Release 1.4 1 Cisco ISE Command-Line Interface Cisco ISE Administration and Configuration Using CLI Cisco ISE Administration and Configuration Using CLI The Cisco ISE command-line interface (CLI) allows you to perform system-level configuration in EXEC mode and other configuration tasks in configuration mode (some of which cannot be performed from the Cisco ISE Admin portal), and generate operational logs for troubleshooting. You can use either the Cisco ISE Admin portal or the CLI to apply Cisco ISE application software patches, generate operational logs for troubleshooting, and backup the Cisco ISE application data. Additionally, you can use the Cisco ISE CLI to start and stop the Cisco ISE application software, restore the application data from a backup, upgrade the application software, view all system and application logs for troubleshooting, and reload or shutdown the Cisco ISE device. Refer to Cisco ISE CLI Commands in EXEC Mode, Cisco ISE CLI Commands in EXEC Show Mode, or Cisco ISE CLI Commands in Configuration Mode for command syntax, usage guidelines, and examples. Accessing the Cisco ISE CLI Using a Local System If you need to configure Cisco ISE locally without connecting to a wired Local Area Network (LAN), you can connect a system to the console port in the Cisco ISE device by using a null-modem cable. The serial console connector (port) provides access to the Cisco ISE CLI locally by connecting a terminal to the console port. The terminal is a system running terminal-emulation software or an ASCII terminal.