1-9
CLI Reference Guide for the Cisco Secure Access Control System 5.1
OL-18996-01
Chapter 1 Overview of the ACS Command Line Interface
Types of Command Modes in ACS
Ta b l e 1-4 Summary of ACS Configuration Commands
Command Description Required User Role
access-setting
accept-all
Resets IP address filtering to allow all IP
addresses to access the management pages
of an ACS server.
Only the super admin can issue this
command on a primary ACS node.
debug-adclient
Enables debug logging of an Active
Directory client.
Only the network-device admin can
issue this command.
debug-log
Defines the local debug logging level for
the ACS components.
Any user, irrespective of role, can issue
this command.
decrypt-support-b
undle
Decrypts an ACS support bundle that was
generated using the acs support
command.
Only the super admin can issue this
command.
export-data
Exports configuration data from an ACS
local store to a remote repository.
Only users who have Read permission
to a specific configuration object in the
GUI can export that particular
configuration data to a remote
repository.
import-data
Imports configuration data from a remote
repository to an ACS local store.
Only users who have Create, Read,
Update, and Delete (CRUD)
permissions to a specific configuration
object in the GUI can import that
particular configuration data to an ACS
local store.
import-export-ab
ort
Aborts specific (or all) import and export
processes.
Only the super admin can
simultaneously abort a running process
and all pending import and export
processes. However, a user who owns a
particular import or export process can
abort that particular process by using the
process ID, or by stopping the process
when it is in progress.
import-export-sta
tus
Displays the status of the import and
export processes.
Any user, irrespective of role, can issue
this command.
no
debug-adclient
Disables debug logging of an Active
Directory client.
Only the network-device admin can
issue this command.
no debug-log
Restores the default local debug logging
level of the ACS components.
Any user, irrespective of role, can issue
this command.
replication
force-sync
Synchronizes configuration information
between the primary and secondary ACS.
Only the super admin or system admin
can issue this command on a secondary
ACS node.
reset-manageme
nt-interface-certif
icate
Resets the management interface
certificate to the default self-signed
certificate.
Only the super admin or system admin
can issue this command.