cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
951
Views
0
Helpful
0
Replies

WLC Roles vs Command List in TACACS

I'm trying to define a user account for CLI access to a WLC running 8.3 and 8.5.  I'm trying to use this user account for simple automation efforts using BASH / Expect scripting that acquires information I can only glean from the CLI - particularly, the specific CLI command syntax on the device to allow text-based analysis in conjunction with other IOS, IOS XE, IOS XR, NX-OS, and ASA devices.

 

I currently have this user set to role MONITOR, but when I apply the command "config paging disable" I'm given an error that the command doesn't exist.  I understand that command isn't available in the MONITOR role, but needing to check and handle paging is... problematic, since I'm an accomplished network engineer, not an accomplished software engineer.  "show sysinfo" and "show run-config commands" are example CLI commands that require paging to be disabled.

 

I can set the role to something else, but then these roles are able to actually make changes to the system through the scripts and I'm concerned about my own well-meant mistakes (again... I'm not an accomplished software engineer).

 

  1. For other Cisco operating systems, I can define in TACACS the list of allowed and disallowed commands.  Will that work with the WLCs?
  2. Is there a role I can use besides MONITOR that will will allow me to actually use all commands that don't change the actual configuration (particularly the paging disable)?
  3. Is there a command I can try besides "config paging disable" that will disable paging?

 

weylin

0 Replies 0

Review Cisco Networking for a $25 gift card