Cisco CSACS-1121-K9 Reference Guide - Page 132

debug-adclient, access-setting accept-all, debug-adclient enable

Page 132 highlights

ACS Configuration Commands Appendix A ACS Command Reference Syntax Description No arguments or keywords. Defaults None. Command Modes ACS Configuration Usage Guidelines Use the access-setting accept-all command when all system administrators' access to an ACS node through the GUI is blocked. This problem occurs when an administrator defines an access list that includes all IP addresses and blocks access to the GUI. When you issue this command, IP address filtering is set to allow all IP addresses to connect the management pages, but the IP addresses defined in the IP Ranges table to allow or reject the IP addresses to access the management pages are not reset; therefore, you can reuse this table to set IP address filtering. Examples acs/admin(config-acs)# access-setting accept-all access setting allows all IP addresses to connect acs/admin(config-acs)# debug-adclient To enable debug logging for an Active Directory client, use the debug-adclient command in the ACS Configuration mode. To disable debug logging for an Active Directory client, use the no form of this command. Only the network-device admin can enable or disable debug logging for an Active Directory client. debug-adclient enable Syntax Description No arguments or keywords. Defaults Disabled. Command Modes ACS Configuration Usage Guidelines When you set the log level of debug logs to DEBUG for the following components, the active directory client logs are automatically enabled. Similarly, when you disable the DEBUG log level on one of these components, the active directory logs are disabled: • all • mgmt A-94 CLI Reference Guide for the Cisco Secure Access Control System 5.1 OL-18996-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190

A-94
CLI Reference Guide for the Cisco Secure Access Control System 5.1
OL-18996-01
Appendix A
ACS Command Reference
ACS Configuration Commands
Syntax Description
No arguments or keywords.
Defaults
None.
Command Modes
ACS Configuration
Usage Guidelines
Use the
access-setting accept-all
command when all system administrators' access to an ACS node
through the GUI is blocked. This problem occurs when an administrator defines an access list that
includes all IP addresses and blocks access to the GUI.
When you issue this command, IP address filtering is set to allow all IP addresses to connect the
management pages, but the IP addresses defined in the IP Ranges table to allow or reject the IP addresses
to access the management pages are not reset; therefore, you can reuse this table to set IP address
filtering.
Examples
acs/admin(config-acs)#
access-setting accept-all
access setting allows all IP addresses to connect
acs/admin(config-acs)#
debug-adclient
To enable debug logging for an Active Directory client, use the
debug-adclient
command in the ACS
Configuration mode. To disable debug logging for an Active Directory client, use the
no
form of this
command. Only the network-device admin can enable or disable debug logging for an Active Directory
client.
debug-adclient enable
Syntax Description
No arguments or keywords.
Defaults
Disabled.
Command Modes
ACS Configuration
Usage Guidelines
When you set the log level of debug logs to DEBUG for the following components, the active directory
client logs are automatically enabled. Similarly, when you disable the DEBUG log level on one of these
components, the active directory logs are disabled:
all
mgmt