ADC CLI Commands

system-user

The following operations can be performed on “system-user”:

unbind unset show bind rm add set

unbind system user

Unbinds a command policy or partition from the system user.

Synopsis

unbind system user \( | -partitionName )

Arguments

userName Name of the user entry from which to unbind the command policy.

policyName Name of the command policy to unbind.

partitionName Name of the Partition to unbind.

unset system user

Resets the specified system user parameters.Refer to the set system user command for meanings of the arguments.

Synopsis

unset system user [-allowedManagementInterface …] [-externalAuth] [-promptString] [-timeout] [-logging] [-maxsession]

show system user

Displays information about all system users configured on the appliance, or about the specified user.

Synopsis

show system user []

Arguments

userName Name of a system user about whom to display information.

Output

groupName The system group.

policyName The name of command policy.

priority The priority of the policy.

password Password for the system user. Can include any ASCII character.

encrypted hashmethod externalAuth Whether to use external authentication servers for the system user authentication or not

promptString String to display at the command-line prompt. Can consist of letters, numbers, hyphen (-), period (.), hash (#), space ( ), at (@), equal (=), colon (:), underscore (_), and the following variables:

  • %u - Will be replaced by the user name.
  • %h - Will be replaced by the hostname of the Citrix ADC.
  • %t - Will be replaced by the current time in 12-hour format.
  • %T - Will be replaced by the current time in 24-hour format.
  • %d - Will be replaced by the current date.
  • %s - Will be replaced by the state of the Citrix ADC.

Note: The 63-character limit for the length of the string does not apply to the characters that replace the variables.

promptInheritedFrom From where the prompt has been inherited.

timeout CLI session inactivity timeout, in seconds. If Restrictedtimeout argument of system parameter is enabled, Timeout can have values in the range [300-86400] seconds. If Restrictedtimeout argument of system parameter is disabled, Timeout can have values in the range [0, 10-100000000] seconds. Default value is 900 seconds.

timeoutKind From where the timeout has been inherited.

partitionName Name of the Partition to bind to the system user.

logging Users logging privilege

maxsession Maximum number of client connection allowed per user

allowedManagementInterface Allowed Management interfaces to the system user. By default user is allowed from both API and CLI interfaces. If management interface for a user is set to API, then user is not allowed to access NS through CLI. GUI interface will come under API interface

allowedManagementInterfaceKind Value of allowed interface which can be inherited from Global, Group or User.

lastpwdchangetimestamp Timestamp for the last password change for nsroot user

devno count stateflag

bind system user

Binds a command policy or partition to a system user.

Synopsis

bind system user \(\( ) | -partitionName )

Arguments

userName Name of the system-user entry to which to bind the command policy.

policyName Name of the command policy to bind to the system user.

priority Integer specifying the priority of the command policy. A lower number specifies a higher priority. Policies are evaluated in the order of their priority numbers. Minimum value: 0 Maximum value: 999999999

partitionName Name of the Partition to bind to the system user.

rm system user

Removes a system user from the appliance.

Synopsis

rm system user

Arguments

userName Name of the system user to remove.

add system user

Adds a new user to the system. Note: You must provide the password after the user name.

Synopsis

add system user \[-externalAuth \( ENABLED | DISABLED )] \[-promptString ] \[-timeout ] \[-logging \( ENABLED | DISABLED )] \[-maxsession <positive\_integer>] \[-allowedManagementInterface \( CLI | API ) ...]

Arguments

userName Name for a user. Must begin with a letter, number, or the underscore (_) character, and must contain only alphanumeric, hyphen (-), period (.), hash (#), space ( ), at (@), equal (=), colon (:), and underscore characters. Cannot be changed after the user is added.

CLI Users: If the name includes one or more spaces, enclose the name in double or single quotation marks (for example, “my user” or ‘my user’).

password Password for the system user. Can include any ASCII character.

externalAuth Whether to use external authentication servers for the system user authentication or not

Possible values: ENABLED, DISABLED Default value: ENABLED

promptString String to display at the command-line prompt. Can consist of letters, numbers, hyphen (-), period (.), hash (#), space ( ), at (@), equal (=), colon (:), underscore (_), and the following variables:

  • %u - Will be replaced by the user name.
  • %h - Will be replaced by the hostname of the Citrix ADC.
  • %t - Will be replaced by the current time in 12-hour format.
  • %T - Will be replaced by the current time in 24-hour format.
  • %d - Will be replaced by the current date.
  • %s - Will be replaced by the state of the Citrix ADC.

Note: The 63-character limit for the length of the string does not apply to the characters that replace the variables.

timeout CLI session inactivity timeout, in seconds. If Restrictedtimeout argument of system parameter is enabled, Timeout can have values in the range [300-86400] seconds. If Restrictedtimeout argument of system parameter is disabled, Timeout can have values in the range [0, 10-100000000] seconds. Default value is 900 seconds.

logging Users logging privilege

Possible values: ENABLED, DISABLED Default value: DISABLED

maxsession Maximum number of client connection allowed per user Minimum value: 1 Maximum value: 40

allowedManagementInterface Allowed Management interfaces to the system user. By default user is allowed from both API and CLI interfaces. If management interface for a user is set to API, then user is not allowed to access NS through CLI. GUI interface will come under API interface Default value: NS_INTERFACE_ALL

set system user

Modifies the specified parameters of a system-user entry.

Synopsis

set system user {-password } \[-externalAuth \( ENABLED | DISABLED )] \[-promptString ] \[-timeout ] \[-logging \( ENABLED | DISABLED )] \[-maxsession <positive\_integer>] \[-allowedManagementInterface \( CLI | API ) ...]

Arguments

userName Name of the system-user entry to modify.

password Password for the system user. Can include any ASCII character.

externalAuth Whether to use external authentication servers for the system user authentication or not

Possible values: ENABLED, DISABLED Default value: ENABLED

promptString String to display at the command-line prompt. Can consist of letters, numbers, hyphen (-), period (.), hash (#), space ( ), at (@), equal (=), colon (:), underscore (_), and the following variables:

  • %u - Will be replaced by the user name.
  • %h - Will be replaced by the hostname of the Citrix ADC.
  • %t - Will be replaced by the current time in 12-hour format.
  • %T - Will be replaced by the current time in 24-hour format.
  • %d - Will be replaced by the current date.
  • %s - Will be replaced by the state of the Citrix ADC.

Note: The 63-character limit for the length of the string does not apply to the characters that replace the variables.

timeout CLI session inactivity timeout, in seconds. If Restrictedtimeout argument of system parameter is enabled, Timeout can have values in the range [300-86400] seconds. If Restrictedtimeout argument of system parameter is disabled, Timeout can have values in the range [0, 10-100000000] seconds. Default value is 900 seconds.

logging Users logging privilege

Possible values: ENABLED, DISABLED Default value: DISABLED

maxsession Maximum number of client connection allowed per user Minimum value: 1 Maximum value: 40

allowedManagementInterface Allowed Management interfaces to the system user. By default user is allowed from both API and CLI interfaces. If management interface for a user is set to API, then user is not allowed to access NS through CLI. GUI interface will come under API interface Default value: NS_INTERFACE_ALL

system-user