Management Commands

The following list of commands and command variants are required for administration of the TOE. These commands are available only after an administrator has successfully logged into the TOE.

Management Commands

Command Tested Command Variants Description
aaa aaa authentication

aaa authentication enable default radius local

aaa authentication login default radius local

aaa authentication web-server default local

Configures the AAA authentication functions

banner banner motd+

Manages the login banner

clock clock set time

Manages the internal clock

config config terminal

Switches to configuration mode

crypto crypto key generate

Invokes cryptographic functions.

crypto-ssl crypto-ssl certificate generate

Manages web server properties.

exit exit

Logs out or exits current session. Used to terminate both local console and remote SSH sessions.

fips

fips enable common-criteria

fips show

fips zeroize all

Manages FIPS and common criteria configuration.

interface interface ethernet 4/12

interface mac access-group 400 in

tunnel

Configures an interface or associates an ACL with an interface.

ip / ipv6 access-list

access-group

address

ssl profile (IPv4 only)

Configures IPv4 and IPv6 parameters.

logging logging host ip-address ssl-port port-number profile profile-name

Configures the audit logging host.

logging enable logging enable pki Configures PKI logging.
  logging enable pki pki-extended Configures PKI extended logging.
openssl openssl s_server

Configures secure connections (for example with syslog).

pki

pki

authenticate - Authenticates CA to router by obtaining the self-signed certificate of the CA.

cert-validate - Determines if a trustpoint has been successfully authenticated.

enroll - Requests certificates from the CA for each key pair of your router.

entity - Configures PKI end-user parameters.

export - Exports a PKI certificate manually.

import - Imports a PKI certificate manually.

profile-enrollment - Configures PKI enrollment parameters.

trustpoint - Configures PKI CA parameters.

Configures Public Key Infrastructure parameters.

radius-server radius-server host ip-address ssl-auth-port port profile profile-name authentication key value

radius-server retransmit retransmit period

radius-server timeout timeout period

radius-server key key name

Configures the RADIUS server.

reload reload

Reloads the current flash image.

server server ntp server ip minpoll time

Configures external services.

show show flash

show version

show clock

show ip client-pub-key

show ip ssl

show logging

show pki

show running-config

Displays information about specified configuration.

timeout

cli timeout time

Configures the timeout for CLI inactivity in minutes. The default is 2 minutes. The CLI session timeout also controls SSH sessions. Valid values are 0-240.

Note: It is recommended that you configure a non-zero value so that a timeout occurs any time the system is idle.

username username user password

Manages user accounts.

write write memory

Writes to persistent storage.