Management Commands

The following list of commands and command variants are required for administration of the TOE. These commands are available only after an administrator has successfully logged into the TOE.

Management Commands

Command Tested Command Variants Description
aaa aaa authentication

aaa authentication enable default radius local

aaa authentication login default radius local

aaa authentication web-server default local

Configures the AAA authentication functions

access-list access-list deny host IP address

access-list 1 deny 10.157.29.12

access-list 1 deny host IPHost1

access-list 1 permit any

Creates ACL rules

banner banner motd+

Manages the login banner

clock clock set time

Manages the internal clock

config config terminal

Switches to configuration mode

crypto crypto key generate

Invokes cryptographic functions.

crypto-ssl crypto-ssl certificate generate

Manages web server properties.

enable enable aaa

enable password-min-length 15

Enables console login features.

exit exit

Logs out or exits current session.

fips

fips enable common-criteria

fips show

fips zeroize all

Manages FIPS and common criteria configuration.

ikev2

ikev2 auth-proposal

ikev2 nat keepalive

ikev2 nat-enable

ikev2 proposal

ikev2 profile

ikev2 policy

Configures IKEv2 properties.

interface interface ethernet 4/12

interface mac access-group 400 in

tunnel

Configures an interface or associates an ACL with an interface.

ip / ipv6 access-list

access-group

address

ssl profile (IPv4 only)

Configures IPv4 and IPv6 parameters.

ipsec ipsec proposal

ipsec profile

Configures IPsec properties.

lifetime (IKEv2) lifetime lifetime in minutes Configures the IKEv2 security association (SA) lifetime value in minutes in the IKEv2 profile config mode. For example:

device(config-ike-profile-ipsec-abcd)# lifetime 400.

Default is 43200. Valid range is 10 through 43200 (decimal).

Note: In the CC configuration, the lifetime must be configured below 24 hours (below 3600).
lifetime (IPsec) lifetime lifetime in minutes

Configures the IPsec SA lifetime value in minutes in the IPsec profile config mode. For example:

device(config-ipsec-profile-ipsec-abcd)# lifetime 240

Default is 480. Valid range is 60 through 480.

Note: In the CC configuration, any value may be chosen.
logging logging host ip-address ssl-port port-number profile profile-name

Configures the audit logging host.

logging enable logging enable ikev2 Configures IKEv2 logging.
  logging enable ikev2 ikev2-extended Configured IKEv2 extended logging.
  logging enable ikev2 ikev2-packet Configures logging of IKEv2 packets.
  logging enable pki Configures PKI logging.
  logging enable pki pki-extended Configures PKI extended logging.
logout logout

Used to terminate both local console and remote SSH sessions.

ntp ntp

Switches to NTP configuration mode.

openssl openssl s_server

Configures secure connections (for example with syslog).

pki

pki

authenticate - Authenticates CA to router by obtaining the self-signed certificate of the CA.

cert-validate - Determines if a trustpoint has been successfully authenticated.

enroll - Requests certificates from the CA for each key pair of your router.

entity - Configures PKI end-user parameters.

export - Exports a PKI certificate manually.

import - Imports a PKI certificate manually.

profile-enrollment - Configures PKI enrollment parameters.

trustpoint - Configures PKI CA parameters.

Configures Public Key Infrastructure parameters.

radius-server radius-server host ip-address ssl-auth-port port profile profile-name authentication key value

radius-server retransmit retransmit period

radius-server timeout timeout period

radius-server key key name

Configures the RADIUS server.

reload reload

Reloads the current flash image.

server server ntp server ipminpoll time

Configures external services.

show show flash

show version

show clock

show ip client-pub-key

show ip ssl

show logging

show pki

show run

Displays information about specified configuration.

timeout

console timeout time

ip ssh timeout time

Configures the console timeout in minutes. Default is 0. Valid values are 0-240. 1 2

Configures the SSH timeout in minutes. Default is 120. Valid values are 1-120.

tunnel tunnel protection ipsec ipv4 ipsec profile name

Enables IPsec on an interface.

username username user password

Manages user accounts.

write write memory

Writes to persistent storage.