Avocent Acs 800acs 8000 Advanced Console System Command Reference Guide
Avocent Acs 800acs 8000 Advanced Console System Command Reference Guide
This guide describes how to access and navigate the Command Line Interface (CLI) utility and how to use
it after the console system has been installed and assigned an IP address. For information on how to install
or operate your console system using the web user interface (UI), see the Avocent® ACS800/8000
Advanced Console System Installation/User Guide.
• Through a local terminal or a computer that has a terminal emulation program connected to
the console port of the console system with session settings of 9600, 8, N and 1, with no flow
control. The local console speed can be modified in the device's boot configuration.
• After the console system is connected to the network and has an IP address, it can be accessed
by one of the following methods:
• An SSH or Telnet client on a remote computer (if the SSH or Telnet protocol is enabled in
the selected Security Profile)
• With the Web Manager - Access - Appliance Viewer button
• With DSView management software
NOTE: For details on the remote access methods and IP address configuration options, see the
Avocent® ACS800/8000 Advanced Console System Installation/User Guide.
Administrators have full access to the CLI and to connected devices. An administrator can authorize
regular users to access ports, manage power, manage data buffer storage and use one or more console
system administration tools. Users can always change their own passwords.
To start the CLI:
1. An administrator can access the CLI through the console port, with Telnet, SSH or through the
web manager.
2. Enter the username and password at the prompt. The cli-> prompt appears.
-or-
A root user logs into the Linux shell by default. From the shell, type cli to launch the CLI.
The default password for admin is avocent and for root is linux. The password for these users may have
been changed during installation of the console system. If not, change the default root and admin
passwords to avoid potential security breaches.
For example, in the web manager, user configuration is done when an administrator selects Users - Local
Accounts - User Names to get to the User Names screen. To navigate to the equivalent configuration
level in the CLI, an administrator would use the cd command followed by the path: cd /users/local_
accounts/user_names.
Administrators should log into the CLI in one window and log into the web manager in another window to
see how the menu options in the web manager map to the navigation options in the CLI. Configuration
with the CLI also requires mastery of the following information on CLI navigation and of the CLI
commands. For more information, see CLI Command Set on page 5
1.3 CLI Navigation
The CLI navigation options are in a nested tree configuration.
When a command line is shown in an example, and the step starts with “Enter,” or when a syntax example
is given, the user should type the command as shown and then press Enter. The Enter key is not shown in
command line examples unless needed for clarity.
When a user logs in the CLI, the prompt indicates the user is at the / level.
--:- / cli->
At any CLI prompt at any level, if you type cd <space> Tab Tab or cd Tab Tab Tab, the navigation options
(path elements) for that level are listed. Different options appear for administrators and for authorized
users.
• When an administrator types the cd command and then presses Tab Tab at the / prompt, the
following navigation options (path elements) appear.
--:-/ cli->cd
access/ monitoring/ sensors/
active_sessions/ network/ system/
pluggable_ system_
authentication/
devices/ tools/
change_password/ ports/ users/
power_
events_and_logs/
management
When a regular user types the cd command and then presses Tab Tab at the / prompt, the following
navigation options appear.
Enter cd <one_or_more_path_elements> to move down one or more levels of the navigation tree:
At any level, you can press Tab Tab at the prompt to see the commands that can be entered at the
current level.
--:- / cli->
add pwd
cd quit
clone_ports reboot
reset_port_to_
commit
factory
restore_
configuration_integrity
configuration
delete revert
disable_ports save_configuration
echo scp
edit set
enable_ports set_cas
exit set_dial-in
factory_defaults set_dial-out
finish set_power
ftp set_socket-client
generate_|_download_
shell
certificate
help show
hostname shutdown
list_configuration upgrade_firmware
If you know the path, you can enter multiple path elements in a single command separated with forward
slashes (/).
Enter cd .. to move up one level of the navigation tree. Enter cd ../..[/..] to move up multiple levels.
1.4 Autocompletion
Autocompletion allows you to type the first few letters of a command or navigation option and then press
Tab. The rest of the name is filled in automatically if the letters typed are unique to one command or to a
navigation option at that level. If the letters match more than one of the commands or navigation options
for that level, the matching options are listed.
For example, if you type cd acc and press Tab at the CLI prompt from the / level, the access option will be
completed.
If you then press Enter, you are changed to the access level, and the access level prompt appears.
The following example illustrates a case when more than one command matches the letters typed.
1.5 Parameters
Some CLI commands take parameters. If you press Tab Tab after a command that requires a parameter,
you are prompted to enter the parameter.
NOTE: Most of the commands work from any location when the path to the command parameter is
included.
NOTE: The word “node” refers to an entity such as a route, host or user, which can be added,
configured or deleted.
2.1.1 add
Add a node.
Syntax:
Example:
2.1.2 cd
Change directory (level).
Syntax:
Example:
Example:
--:- / cli->
Example:
--:- / cli->
Example:
2.1.3 commit
Save settings.
Syntax:
2.1.4 delete
Delete a node.
Syntax:
2.1.5 exit/quit
Exit the CLI and return to the login prompt.
-or-
2.1.6 ftp
Connect to a remote FTP server.
Syntax:
NOTE: You must log into the CLI as root to have full control over the local directory path. All normal
FTP commands apply.
2.1.7 help
Generate a help message about how to navigate the CLI.
Syntax:
2.1.8 list_configuration
List the configuration in a format that allows pasting the output directly on the appliance session
(console, SSH or Telnet) in order to (re)configure the unit.
All configurable parameters are listed under the current node. When the parameter is not configured, the
parameter name has the number sign character (#) as its prefix.
Syntax:
NOTE: Check the configuration of the program used to open a session against the appliance
(SSH/Telnet, TeraTerm / HypertTerminal for console, and so on) to avoid the inclusion of a line feed
character in lines that exceed terminal width, because this will affect the paste operation.
2.1.9 ls
Show the available directories or subnodes at the current location.
Syntax:
--:- / cli-> ls
Example:
2.1.10 opiepasswd
Configure a one time password (OTP) for the local user. After you type the command, you will be asked for
the passphrase to use for the OTP.
Syntax:
Example:
opiepasswd -f -c teste
Adding teste:
Only use this method from the console; NEVER from remote. If you are using telnet, xterm, or a dial-in,
type ^C now or exit with no password.
Then run opiepasswd without the -c parameter.
Using MD5 to compute responses.
Enter new secret pass phrase:
Again new secret pass phrase:
ID teste OTP key is 499 AC0241
FOOD HUGH SKI ALMA LURK BRAD
2.1.11 pwd
Display the path to the current level (print working directory).
Syntax:
2.1.12 passwd
Configure the password for the current user. The terminal does not echo the password.
Syntax:
2.1.13 revert
Undo a previous parameter setting.
Syntax:
2.1.14 scp
Perform a secure shell copy.
Syntax:
Syntax:
After a parameter has been changed using the set command, a pair of asterisks appear at the beginning
of the CLI prompt.
**:- / cli->
-or-
NOTE: After a commit or revert command, the asterisks at the beginning of the CLI prompt are
replaced by hyphens. Asterisks will not appear after the execution of the set command if using wizard
mode, which can be recognized by a prompt that has a pound sign after the colon and the current
directory in square brackets (example, --:#- [hosts] cli->).
2.1.16 show
Show the content of the current location (shows tables and parameters with current values).
Syntax:
Example:
2.1.17 wiz
Configures the IP parameters for the Eth0 interface. Shows the current configuration and asks for new
values for the following parameters:
After setting all parameters, confirm that all parameters are correct to save them.
2.1.18 connect
Connect to a serial port.
Syntax:
Example:
Password:
-or-
2.1.19 disconnect
Use the text session hotkey to suspend the target session and return to the CLI.
Syntax:
Ctrl+z
NOTE: Lock and unlock commands are only supported on Cyclades and Avocent PDUs.
2. Launch the power command with the argument being the target name or PDU ID.
2. Launch the power command with a specific outlet (number or name), range of outlets (use a
hyphen to specify the range) or list of outlets (number or name separated by a comma).
-or-
-or-
To power control (on, off, cycle, lock, unlock) outlets of one specific PDU under the power management
level:
1. Go to the outlet level for the specific PDU.
2. Launch the power command with a specific outlet number, range of outlets (use a hyphen to
specify the range) or list of outlets (number or name separated by a comma).
-or-
-or-
2.2.1 sniff
Connect to a serial port as an additional, view-only user.
Syntax:
Example:
Password:
-or-
2.2.2 share
Connect to a serial port as an additional, read/write user.
Syntax:
Example:
Password:
-or-
2.2.3 list_shared_session
List the users connected to the shared serial port.
Syntax:
2.2.4 kill_shared_session
Terminate the connection of a user on the port. The user is returned to the cli-> prompt.
NOTE: You must enable the Kill Multi Session option from the Port Access Rights settings for this
command to be available.
Syntax:
Example:
2.2.5 sendmsg
Send a message to a user connected to the port.
NOTE: You must enable the Send Message Multi Session option from the Port Access Rights settings
for this command to be available.
Syntax:
Example:
Syntax:
View the data logging for the appliance. Appliance Session Data logging must be enabled in Events and
Logs/Appliance Logging.
Syntax:
Syntax:
Clear the data logging for the appliance. Appliance Session Data logging must be enabled in Events and
Logs/Appliance Logging.
Syntax:
3. Type set enable_ipv6= and press Tab to view the options for the parameter.
-or-
7. Enter commit.
By default, all users can access all enabled and configured ports. The administrator must decide whether
to restrict user access to ports by the assignment of authorizations to user groups. A user who is in an
authorized group is referred to as an authorized user.
Some port configuration tasks are provided as examples of how to use the CLI. See the Avocent® ACS
800/8000 Advanced Console System Installation/User Guide for an overview of the tasks the
administrator must do to configure restricted access to ports. For more information about how to follow
the web manager procedures in the CLI, see Configuration Tasks Performed With the CLI on page 2.
This section describes the following tasks related to port access, configuration, power management and
where the tasks are performed in the CLI.
3.1 View Information About the Console System and Connected Devices
When a regular user or an administrator enters show at the Access level, information about the following
appears in the format shown in Access Parameters on page 19.
For Appliance
Name Name assigned to the appliance (for example, ACS8048-1357908642)
Port N/A
Type N/A
Status N/A
For Serial Port
Name Either the default name [XX-XX-XX-p-n (where n=port_number)], an administrator-assigned alias or an auto-discovered server name
Port Number of the serial port
Type Serial
Status Idle / In-Use
For Power
Name PDU ID (either the default name in the format XX-XX-XXPXX_n or an administrator-assigned alias, such as myPDU)
2. Enter show. Information about the console system and the ports the current user is authorized
to access appears.
--:- access cli-> show
name port type status
================= ==== ===== =====
ACS8048-0011223344
21-67-72-p-1 1 serial in use
21-67-72-p-2 2 serial idle
21-67-72-p-3 3 serial idle
Type ls to see available sub-nodes.
--:- access cli->ls
21-67-72-p-1/
21-67-72-p-2/
21-67-72-p-3/
1. Log into the CLI and enter cd access to navigate to the Access level.
2. Enter connect <serial_port_name>. If authentication is configured for the port, the Password
prompt appears when single sign-on is disabled.
Password:
NOTE: The connect command above shows a connection to a port that has an alias of 77-77-70-p-2.
3. If prompted, enter the password for the port. The following prompt appears.
4. Press Enter to continue. You are connected to the device that is connected to the port. The
window shows the initial display for the device (usually a console banner and login prompt). An
example is shown below.
ts_menu options
-u <user> [-l] [-ro] <console port>
Invokes ts_menu as the user named by <user>. This requires a password to be entered. The user only has access to authorized
-u <user>
serial ports.
-l Generates a list of ports the user can access. Port aliases are shown if defined.
-ro Invokes ts_menu in read-only mode. You may connect in read-only mode to any port you have access to.
If issued, produces a direct connection to that port. If you have no access rights to the port or if the port does not exist, the application
<console port>
returns a console not found message and terminates. The console port may be the port alias or the port number.
-p Display TCP port.
-i Display Local IP assigned to the serial port.
-u <name> Username to be used in SSH/Telnet or Raw command.
-e <[^]char> Escape character used to close the target session. The default escape character is Ctrl-X.
--:- / cli->
2. Enter set_cas ports/serial_ports/ followed by a space and the number of the port you want to
configure (port 1 is used as an example).
4. Enter set status=enabled, then enter show and save as shown to enable the configured port
and verify and save the configuration.
3. Enter set status=enabled then enter save to set the Serial_Profile to Power, enable the port
and commit the changes.
4. Enter show to verify the configuration.
--:-serial_ports cli-> show
NOTE: In the tables that show output from the show command, when an option that is followed by an
equal sign (=) is left blank, that option is not assigned a value by default.
4.1 System
1. Enter cd system to navigate to the System level.
3. Enter show followed by an option name to view information about each option.
4.2 System/Security
Enter cd system/security to navigate to the security level.
idle_timeout =
rpc =
enable_pluggable_device_detection =
enable_pluggable_storage_devices =
port access =
session =
port_access_kill_multi_session =
port_access_power_control =
port_access_data_buffer_management =
port_access_restful_menu =
bootp_enabled=
bootp_interface=
enable_live_configuration_retrieval=
ssh_allows_authentication_via_username|password =
security_profile=
enable_telnet_service=
enable_ftp_service= d
enable_snmp_service=
enable_ipsec=
answer_icmp_message=
ssh_version=
ssh_tcp_port=
ssh_allow_root_access=
ssh_minimum_cipher_and_mac_suite_level =
enable_http_session=
http_port=
enable_https_session
https_tls_version=
https_port=
https_minimum_cipher_suite_level=
redirect_http|https=
dsview
all_appliance_to_be_managed_by_dsview=
fips_140
enable_fips_140-2_module=
4.2.3 System/General
Enter cd system/general to navigate to the login_banner level.
NOTE: <login banner text> with new lines: Type the text between double quotes and enter the new line
as \\n (double back slash and the character).
boot mode=
boot image=
watchdog_timer=
console_speed=
4.2.5 System/Information
1. Enter cd system/information to navigate to the Information level.
4.3 Network
1. Enter cd network to navigate to the Network level.
2. Enter ls to view the list of available options.
settings/
devices/
ipv4_static_routes/
ipv6_static_routes/
hosts/
firewall/
ipsec(vpn)/
snmp/
4.3.1 Network/Settings
1. Enter cd network/settings to navigate to the Network settings level.
2. Enter show to view the list of available options.
Table 4.6 Network/Settings Navigation Tree
Settings
hostname=
primary_dns=
secondary_dns=
domain=
search=
enable_lldp=
enable_ipv6=
get_dns_from_dhcpv6=
get_domain_from_dhcpv6=
multiple_routing=
enable_bonding=
4.3.3 Network/Devices
The procedure to configure a static IP address for the primary Ethernet interface is usually performed
during installation so that administrators have a fixed IP address for access to the web manager and can
finish configuration.
To configure an IPv4 or IPv6 static IP address:
NOTE: This procedure configures either an IPv4 or IPv6 static IP address for the ETH0 (eth0) or the
ETH1 (eth1) port. You can configure an IPv6 static IP address only if IPv6 is enabled.
2. Enter set ipv<4|6>_method=static to set the method to static for IPv4 or IPv6.
eth0
set_as_primary_interface=
status=
ipv6_method=
mode=
eth1
set_as_primary_interface=
status=
ipv4_method=
ipv6_method=
mode=
4.3.4 Network/Hosts
The following procedure describes how to add a host to the hosts table.
To add a host to the host table:
1. Enter cd network/hosts to navigate to the Hosts level.
4. Enter set hostname=<hostname> ip=<IP_address> to add the name of a host and the IP address
for the host.
NOTE: Each parameter that follows the add command is separated by a space.
5. Enter commit.
8. Enter show to view the additions to the host table and the Settings option.
ip: 172.26.31.164
hostname = sharedacs8000
alias =
4.3.5 Network/Firewall
Enter cd network/firewall to navigate to the firewall level.
NOTE: To set a rule, you must enable the interface, set the rule for the interface and physically connect
the interface to the network.
4.3.6 Network/IPSec(VPN)
Enter cd network/ipsec(vpn) to navigate to the ipsec(vpn) level.
4.4 Network/SNMP
Enter cd network/snmp to navigate to the snmp level.
4.5 Sensors
An administrator can view and configure sensors on the console system.
Sensors
appliance
internal
maximum_cpu_temperature_(deg_c)=
maximum_cpu_temperature_threshold_(deg_c)=
minimum_cpu_temperature_(deg_c) =
minimum_cpu_temperature_threshold_(deg_c) =
maximum_board_temperature_(deg_c) =
maximum_board_temperature_threshold_(deg_c) =
minimum_board_temperature_threshold_(deg_c) =
minimum_board_temperature_(deg_c) =
1-wire
name=
address=
value=
max=
min=
average=
digital_in
<sensor>
name=
location=
type=
alarm=
pdu
<sensor>
name:
pdu:
type:
value:
max:
min:
average:
At the command prompt at the / level, enter wiz to view the current IP configuration. To change the IP
configuration, press Tab to move through the parameters, and press Esc + Tab to edit the selected
parameter. When you are finished, enter yes to confirm that all parameters are correct and to save the
new parameters.
enable_ipv6 = yes
get_dns_from_dhcpv6 = no
get_domain_from_dhcpv6 = no
Other hints:
- Use backslash '\' to escape spaces, '\' and other control
characters when assigning values to parameters.
4.6 Ports
Enter cd ports to navigate to the Ports level.
Edits the command to configure a list of serial ports with the CAS profile. Syntax: set_cas<serial port number>, <serial port number>
set_cas
This command has five sub-nodes: physical, cas, data_buffering, alerts and power.
set_dial-in Edits the command to configure one serial port with the Dial-In profile. Syntax: set_dial-in<serial port number>
set_dial-out Edits the command to configure one serial port with Dial-out on demand profile. Syntax: set_dial-out <serial port number>
Edits the command to configure a list of serial ports with the Power profile. Syntax: set_power<serial port number>, [<serial port
set_power
number>] This edit has two sub-nodes: physical and power.
set_socket-
Edits the command to configure one serial port with Socket Client profile. Syntax: set_socket-client <serial port number>
client
clone_ports Copies the configuration from one port to a list of serial ports. Syntax: clone_ports<serial port number>
reset_port_to_ Resets the serial ports to factory configuration. (This is disabled for CAS profile.) Syntax: reset_port_to_factory<serial port number>,
factory [<serial port number>]
enable_ports Enables serial ports. Syntax: enable_ports<serial port number>, [<serial port number>]
disable_ports Disables serial ports. Syntax: disable_ports<serial port number>, [<serial port number>]
Example of how to set a list of serial ports 2, 5 and 6 with the CAS Profile and enable the status:
If an internal modem is factory installed, the port profile can be set for either Dial-in or Dial-out on demand.
The port name is ttyM1.
device name device type card device path device info status port
========== ========= ===== ========= ======== ===== ====
ttyACM0 Console usb usbslot 1-1.4 inserted 34
ttyUsB0 Console usb usbslot 1-1.1.1. inserted 35
4.8 Authentication
Enter cd authentication to navigate to the authentication level.
appliance_authentication
authentication_type=
enable_fallback_to_local_type_for_root_user_in_appliance_
console_port=
enable_single_sign-on=
authentication_servers
radius
first_authentication_server=
first_accounting_server=
second_authentication_server=
second_accounting_server=
secret=
timeout=
retries=
enable_servicetype=
tacacs+
first_authentication_server=
first_accounting_server=
second_authentication_server=
second_accounting_server=
service=
secret=
timeout=
retries=
tacacs+_version=
enable_user-level=
ldap(s)|ad
server=
base=
secure=
database_user_name=
database_password=
login_attributes=
dsview
ip_address_1=
ip_address_3=
ip_address_4=
4.9 Users
Enter cd users to navigate to the users level.
2. Enter add. Then enter set with the parameters all on one line separated by spaces as shown.
3. Enter save.
4. Enter show to verify that the new user has been added.
authorization
groups
admin
members
admin
root
login_profile
session_timeout=
enable_log-in_profile=cd
access_rights
power
appliance
appliance-admin
members
login_profile
enable_log-in_profile=
access_rights
serial
power
appliance
shell-login-profile
members
root
login_profile
session_timeout=
enable_log-in_profile=
profile=
cli_cmd=
exit_after_executing=
access_rights
serial
power
appliance
user
members
login_profile
session_timeout=
enable_log-in_profile=
access_rights
serial
power
appliance
dsview_access_rights
map_to_=
multi_access_mode=
kill_multi_session=
send_message_multi-session=
local_accounts
user_names
admin
root
settings
user_name=
password=
password_change_at_next_login=
user_group=
password_minimum_days=
password_maximum_days=
password_inactive_days=
password_warning_days=
account_expiration_date=
access_rights
serial
power
appliance
password_rules
check_password_complexity=
min_digits=
min_upper_case_characters=
min_special_characters=
minimum_size=
def_expiration_min_days=
def_experiation_max_days=
def_expiration_warning_days=
number_of_permitted_failed_attempts_
{0|disabled}=
account_lockout_duration_after_each_failed_login_
{min}=
unlock_account_after_{min}_{0|manual_unlock}=
4.10 Events_and_Logs
Enter cd events_and_logs to navigate to the events_and_logs level.
Allows an authorized user to reboot, restore factory default settings or to rename PDU(s). Also allows the authorized user to view
pdus information about each PDU, monitor sensors, clear sensor values, set up syslogging of events related to the PDU, configure an alarm and
the LED display mode, and to manage outlets on the PDU.
login Lists the username and password for each type of PDU connected to the console system.
outlet_ Lists all configured outlet groups that the current user is authorized to manage (to manage outlet groups, the user must be in a user group
groups that is authorized to manage all the outlets in the outlet group). An administrator can configure outlet groups
network_ Allows an administrator to add, edit or delete PDUs connected to the network. These PDUs will show up in the PDUs node when they are
pdus discovered. Only power control opearation is supported by these PDUs.
ups Allows an authorized user to reboot, restore factory default settings, rename or view UPSs.
network_
Allows an administrator to add, edit or delete UPSs connected to the network.
ups
To rename a PDU:
1. Log onto the CLI as an administrator and enter cd power_management/pdus to navigate to
the pdus level.
NOTE: See the Avocent® ACS800/8000 Advanced Console System Installation/User guide for how to
perform other authorized PDU configuration options.
To manage power for a selected outlet:
See cycle, on, off, lock and unlock on page 11 for how to manage power at the power_management level.
Appendix A: Recovering a Console System That Will Not Boot From Flash
The following procedure should only be used as a last resort for a console system that will not boot from
flash. You will need physical access to both the console system and the console port using a PC with a
serial port using PuTTY or another terminal emulation program.
IMPORTANT! This procedure will completely re-initialize the console system flash to its factory
defaults and erase all configuration and data.
To recover a console system that will not boot from flash:
1. Turn off the console system.
2. Connect a PC to the console port of the console system using 9600 baud and 8, N, 1 for data
bits, parity and stop bits.
3. Turn on the console system.
4. Press any key on your keyboard to obtain the U-Boot prompt when you see the message "Hit
any key to stop autoboot."
5. Place a Vertiv-provided firmware file named firmware-ngacs.fl on a fresh 1GB, 2GB or
4GB USB stick.
6. Insert the USB stick into any USB port on the console system.
NOTE: The USB stick should be the only USB device connected to the console system.
After the console system reboots, you can upgrade the firmware from the web UI.
NOTE: References to an ACS Advanced Console Server in this section refer to the ACS Advanced
Console Server or the ACS5000 Advanced Console Server.
In the ACS800/8000 console system, the login profile for the user “root” goes directly to the shell prompt.
This will allow the root user to run Migration CLI commands out of the ACS800/8000 console system. A
new group, “login-profile-shell,” is created with only root as a member. To run commands based from an
ACS advanced console server, a root user should type CLI before the command.
cli_mus_ttySxx Users who can open a second session to a serial port. Access to a serial port in a multi-session (read/write or read only)
cli_power_ttySxx Users who have power control in a serial port. Power control (on/off/cycle) of outlets merged to a serial port.
cli_access_ttySxx Users who can access a serial port in a single session. Access to a serial port in a single read/write session.
cli_pmd_
<username> Power control of the outlet
<username>
B.2 Exceptions
This section will list all console system CLI commands not available in the Migration CLI for the
ACS800/8000 console system. For a list of available commands, see the Avocent® ACS Advanced Console
Server Installation/User Guide or Avocent® ACS5000 Advanced Console Server Installation/User Guide.
The following commands or values are not supported by the Migration CLI:
administration
backupconfig loadfrom sd N/A
backupconfig saveto sd N/A
upgradefw checkum N/A
application
connect N/A
pm N/A
view N/A
config administration bootconf
bootype bootp/both/ftp
flashtest full/skip
maxevents <number>
ramtest full/quick/skip
config administration notifications
addemail N/A
addpager N/A
addsnmptrap N/A
alarm N/A
delete N/A
edit N/A
config application pmdconfig general
add N/A
delete N/A
config application terminalmenu
add N/A
delete N/A
menutitle N/A
config network hostSettings
secipaddress <nnn.nnn.nnn.nnn>
secsubnetmask <nnn.nnn.nnn.nnn>
mtu N/A
config physicalports access
users/groups accepts only list of usernames
authtype assume local
termshell <shell command>
logintimeout <login timeout in seconds>
config physicalports databuffering
mode cir/lin
showmenu file/fileanderase/no/noerase/yes
syslogsize <record length in bytes[40-255]>
config physicalports general
pmsessions none/ssh/ssh_telnet/telnet
protocol bidirectionaltelnet, consoleraw, cslip, local, rawsocket, slip, sshv1, sshv2, telnet
config physicalports multiuser
users accepts only list of users
sniffmode in/inout/no/out
config physicalports other
SSHexitkey <SSH exit key>
banner <login banner>
host <host>
sttyoptions <stty options>
tcpkeepalive <number>
terminaltype aixterm, att6386, linux-lat, vt100, vt320, xtermcolor, ansi, ibm3151, scoansi, vt102, vt52, at386, linux, sun, vt220, xterm
winems no/yes
idletimeout <number>
config physicalports power management
enableIPMI N/A
disableIPMI N/A
key N/A
server N/A
config security
addgroup/delgroup N/A
config security adduser
shell <shell cmd but “ts_menu”>
comments <comments>
config security profile custom
ports auth2sport no/yes
ports bidirect no/yes
ports raw2sport no/yes
ports ssh2sport no/yes
ports telnet2sport no/yes
ssh ssh_x509 no/yes
config virtualport
config ipmi <all or range/list[1-numberOfPorts]>
security authentication
authtype Otp, Otp/Local
pppauthtype Otp, Otp/Local
timeout
-t<time> Time-out in minutes
-T Disable the idle time-out. Same as -t0
config security loadkey
url N/A
username N/A
C.1 Su command
Using the su (switch user) command, a user can switch to another user account to execute commands
not authorized with their normal account. If used without a username, the su command defaults to root.
Only users who are members of the wheel group can execute the su command to log in as root.
NOTE: The wheel group is a Linux group and is included in the firmware by default.
You will be prompted for the password of the account you’re trying to switch to with the su command. You
will remain logged into that account until you either press Ctrl-D or type exit.
NOTE: The su command will open a shell session instead of the restricted shell. The user will receive
the shell prompt. Improper use of shell commands could lead to data loss. Double-check your syntax
when using shell commands.
Syntax:
su [options][-][username[arguments]]
The following table describes options that can be used with the su command.
Uses an environment similar to that had the user logged in directly. When - is used, it must be specified as the last su
-, -l, --login
option.
-m, -p, --preserve-
Preserves the current environment.
environment
Optional arguments may be provided after the username, in which case they are supplied to the shell
(/bin/sh).
To add a member to the wheel group:
1. Create the user using the web manager or CLI.
2. Open a session in the appliance and log in as root.
3. In the shell prompt, run the usermod command to add the user to the wheel group.
# groups <username>
Syntax:
sudo <command>
Configuring sudo
A system administrator configures the /etc/sudoers file to give groups or users access to some or all
commands not authorized with their normal account. An administrator should log into the console system
as a root user and edit the /etc/sudoers file by using the /usr/sbin/visudo command to configure sudo.
The sudoers file is composed of aliases and user specifications. When multiple entries match for a user,
they are applied in order. Where there are conflicting values, the last match is used.
Since the sudoers file is parsed in a single pass, order is important. You should structure sudoers so that
the Host_Alias, User_Alias, and Cmnd_Alias specifications come first, followed by any Default_Entry lines,
and finally the Runas_Alias and user specifications.
In the preceding example, the users millert, mikef and dowdy can execute the kill, shutdown, reboot and
su commands while the users bostley, jwfox and crawl can only shut down and reboot the console system.