CLI Command Modes and Commands

Command Modes

The CLI is segregated into different command modes. Each mode has its own set of commands for configuration, maintenance, and monitoring. The commands available at any given time depend on the mode you are in, and to a lesser extent, the particular model used. Enter a question mark (?) at the system prompt to view a list of commands available for each command mode/instance.

Use specific commands to navigate from one command mode to another. The standard order is: USER EXEC mode, PRIV EXEC mode and GLOBAL CONFIG mode.

Click to expand in new window
Figure: Hierarchy of User Modes

A session generally begins in the USER EXEC mode (one of the two access levels of the EXEC mode). For security, only a limited subset of EXEC commands are available in the USER EXEC mode. This level is reserved for tasks that do not change the device‘s (wireless controller, service platform, or AP) configuration.

ap505-13403B>

The system prompt signifies the device name and the last three bytes of the device MAC address.

To access commands, enter the PRIV EXEC mode (the second access level for the EXEC mode). Once in the PRIV EXEC mode, enter any EXEC command. The PRIV EXEC mode is a superset of the USER EXEC mode.

ap505-13403B>en
ap505-13403B#

Most of the USER EXEC mode commands are one-time commands and are not saved across device reboots. Save the command by executing ‘commit‘ command. For example, the show command displays the current configuration and the clear command clears the interface.

Access the GLOBAL CONFIG mode from the PRIV EXEC mode. In the GLOBAL CONFIG mode, enter commands that set general system characteristics. Configuration modes, allow you to change the running configuration. If you save the configuration later, these commands are stored across device reboots.

Access a variety of protocol specific (or feature-specific) modes from the global configuration mode. The CLI hierarchy requires you to access specific configuration modes only through the global configuration mode.

ap505-13403B#configure terminal
Enter configuration commands, one per line.  End with CNTL/Z.
ap505-13403B(config)#

You can also access sub-modes from the global configuration mode. Configuration sub-modes define specific features within the context of a configuration mode.

ap505-13403B(config)#aaa-policy test
ap505-13403B(config-aaa-policy-test)#
To enter the logged device's configuration, execute the following command:
ap505-13403B(config)#self
ap505-13403B(config-device-94-9B-2C-13-40-38)#

CLI Modes and Applicable Commands

The following table summarizes the commands available for each mode:

User Exec Mode Priv Exec Mode Global Configuration Mode
captive-portal-page-upload archive aaa-policy
change-passwd boot aaa-tacacs-policy
clear captive-portal-page-upload alias
clock cd ap310
cluster change-passwd ap410
commit clear ap460
connect clock ap505
create-cluster cluster ap510
crypto commit ap560
crypto-cmp-cert-update configure ap7522
database connect ap7532
database-backup copy ap7562
database-restore cpe (supported on NX7500, NX9500, NX9600, CX9000 and VX9000) ap7612
debug create-cluster ap7632
device-upgrade crypto ap7662
disable crypto-cmp-cert-update ap8432
enable database ap8533
file-sync database-backup application
help database-restore application-group
join-cluster debug application-policy
l2tpv3 delete association-acl-policy
logging device-upgrade auto-provisioning-policy
mint diff bgp
no dir ble-data-export-policy
on disable bonjour-gw-discovery-policy
opendns edit bonjour-gw-forwarding-policy
page enable bonjour-gw-query-forwarding-policy
ping erase captive-portal
ping6 ex3500 (supported only on NX9500, NX9600, CX9000 and VX9000) clear
revert factory-reset client-identity
service file-sync client-identity-group
show halt clone
ssh help crypto-cmp-policy
telnet join-cluster customize
terminal l2tpv3 database-client-policy (supported only on CX9000 and VX9000)
time-it logging database-policy (supported only on NX9500, NX9600, CX9000 and VX9000)
traceroute mint device
traceroute6 mkdir device-categorization
virtual-machine (supported only on NX9500, NX9600, CX9000 and VX9000) more dhcp-server-policy
watch no dhcpv6-server-policy
write on dns-whitelist
clrscr opendns event-system-policy
exit page ex3500
ping ex3500-management-policy
ping6 ex3500-qos-class-map-policy
pwd ex3500-qos-policy-map
raid (supported only on NX9500, NX9600, CX9000 and NX7500) ex3524
re-elect ex3548
reload firewall-policy
remote-debug global-association-list
rename guest-management
revert help
rmdir host
igmp-snoop-policy (This command has been deprecated. IGMP snooping is now configurable under the profile/device configuration mode. For more information, see ip.
inline-password-encryption
self iot-device-type-imagotag-policy
service ip
set-personality ipv6
show ipv6-router-advertisement-policy
ssh l2tpv3
t5 (supported only on NX9500, NX9600, and VX9000) location-policy
telnet mac
terminal management-policy
time-it meshpoint
traceroute meshpoint-qos-policy
traceroute6 mint-policy
trigger-smart-sensor nac-list
upgrade no
upgrade-abort nsight-policy
virtual-machine (supported only on NX9500, NX9600, CX9000 and VX9000) NX5500 (supported only on NX9500, NX9600, CX9000 and VX9000)
watch NX7500 (supported only on NX9500, NX9600, CX9000 and VX9000)
write NX9000 (supported only on NX9500, NX9600, CX9000 and VX9000)
clrscr NX9600 (supported only on NX9600, CX9000 and VX9000)
exit passpoint-policy
password-encryption
profile
purview-application-group
purview-application-policy
radio-qos-policy
radius-group
radius-server-policy
radius-user-pool-policy
rename
replace
rf-domain
roaming-assist-policy
role-policy
route-map
routing-policy
rtl-server-policy
schedule-policy
self
sensor-policy
smart-rf-policy
t5 (supported only on NX7500, NX9500, NX9600 and VX9000)
url-filter (supported only on NX9500, NX9600, CX9000 and VX9000)
url-list (supported only on NX9500, NX9600, CX9000 and VX9000)
vx9000 (supported only on NX9500, NX9600, CX9000 and VX9000)
web-filter-policy
wips-policy
wlan
wlan-qos-policy
write
clrscr
commit
do
end
exit
revert
service
show