About the Firepower Management Center CLI
The Firepower Management Center CLI is available only when a user with the admin
user role has enabled it:
-
By default the CLI is not enabled, and users who log into the Firepower Management Center using CLI/shell accounts have direct access to the Linux shell.
-
When the CLI is enabled, users who log in the Firepower Management Center using shell/CLI accounts have access to the CLI and must use the
expert
command to access the Linux shell.
Caution |
We strongly recommend that you do not access the Linux shell unless directed by Cisco TAC or explicit instructions in the Firepower user documentation. |
Caution |
Users with Linux shell access can obtain root privileges, which can present a security risk. For system security reasons, we strongly recommend:
|
When the CLI is enabled, you can use the commands described in this appendix to view and troubleshoot your Firepower Management Center, as well as perform limited configuration operations.
Firepower Management Center CLI Modes
The CLI encompasses four modes. The default mode, CLI Management, includes commands for navigating within the CLI itself.
The remaining modes contain commands addressing three different areas of Firepower Management Center functionality; the commands within these modes begin with the mode name: system
, show
, or configure
.
When you enter a mode, the CLI prompt changes to reflect the current mode. For example, to display version information about system components, you can enter the full command at the standard CLI prompt:
> show version
If you have previously entered show
mode, you can enter the command without the show
keyword at the show mode CLI prompt:
show> version
Enabling the Firepower Management Center CLI
Smart License |
Classic License |
Supported Devices |
Supported Domains |
Access |
---|---|---|---|---|
N/A |
Any |
FMC |
Any |
|
Once the Firepower Management Center CLI is enabled, the initial access to the appliance for users logging in to the management interface will be via the CLI;
the Linux shell will be accessible only via the expert
command.
Note |
If the administrator has disabled access to the device shell with the |
Procedure
Step 1 |
Choose . |
Step 2 |
Click Console Configuration. |
Step 3 |
To enable or disable the Firepower Management Center CLI check or uncheck the Enable CLI Access checkbox. |
Step 4 |
Click Save. |