Module netmiko.cisco.cisco_ftd_ssh
Subclass specific to Cisco FTD.
Classes
class CiscoFtdSSH (ip: str = '',
host: str = '',
username: str = '',
password: str | None = None,
secret: str = '',
port: int | None = None,
device_type: str = '',
verbose: bool = False,
global_delay_factor: float = 1.0,
global_cmd_verify: bool | None = None,
use_keys: bool = False,
key_file: str | None = None,
pkey: paramiko.pkey.PKey | None = None,
passphrase: str | None = None,
disabled_algorithms: Dict[str, Any] | None = None,
disable_sha2_fix: bool = False,
allow_agent: bool = False,
ssh_strict: bool = False,
system_host_keys: bool = False,
alt_host_keys: bool = False,
alt_key_file: str = '',
ssh_config_file: str | None = None,
conn_timeout: float = 10,
auth_timeout: float | None = None,
banner_timeout: float = 15,
blocking_timeout: float = 20,
timeout: int = 100,
session_timeout: float = 60,
read_timeout_override: float | None = None,
keepalive: float = 0,
default_enter: str | None = None,
response_return: str | None = None,
serial_settings: Dict[str, Any] | None = None,
fast_cli: bool = True,
session_log: str | io.BufferedIOBase | SessionLog | None = None,
session_log_record_writes: bool = False,
session_log_file_mode: str = 'write',
allow_auto_change: bool = False,
encoding: str = 'utf-8',
sock: socket.socket | None = None,
sock_telnet: Dict[str, Any] | None = None,
auto_connect: bool = True,
delay_factor_compat: bool = False,
disable_lf_normalization: bool = False)-
Expand source code
class CiscoFtdSSH(NoConfig, CiscoSSHConnection): """Subclass specific to Cisco FTD. FTD has two CLI layers: 1. FTD CLI (top level) - where you land after SSH login. Prompt: firepower> No enable mode; no config mode. 2. Diagnostic CLI (ASA sub-shell) - entered via firepower> system support diagnostic-cli Attaching to Diagnostic CLI ... Type help or '?' for a list of available commands. firepower> enable Password: <-- Press Enter here (no password) firepower# Calling enable() enters the diagnostic CLI and elevates to '#'. Calling exit_enable_mode() returns to the top-level FTD CLI. """ def session_preparation(self) -> None: """Prepare the session after the connection has been established.""" self._test_channel_read(pattern=r"[>#]") self.set_base_prompt() def check_enable_mode(self, check_string: str = "#") -> bool: """Check if in enable mode (diagnostic CLI privileged exec).""" return super().check_enable_mode(check_string=check_string) def enable( self, cmd: str = "system support diagnostic-cli", pattern: str = "ssword", enable_pattern: Optional[str] = r"\#", check_state: bool = True, re_flags: int = re.IGNORECASE, ) -> str: """Enter enable mode on FTD via the diagnostic CLI. Sends 'system support diagnostic-cli' to enter the ASA/Lina sub-shell, then runs 'enable' if still at user-exec prompt ('>'). The diagnostic CLI enable password is always empty (always send null-string). """ output = "" if check_state and self.check_enable_mode(): return output # Enter the diagnostic CLI self.write_channel(self.normalize_cmd(cmd)) if self.global_cmd_verify is not False: output += self.read_until_pattern(pattern=re.escape(cmd.strip())) output += self.read_until_pattern(pattern=r"[>#]") # Track that we are inside the diagnostic CLI so exit_enable_mode # knows to send a second 'exit' to return to the FTD CLI. self._in_diagnostic_cli = True # If at user-exec mode ('>'), elevate to enable ('#') last_line = output.splitlines()[-1] if output.strip() else "" if re.search(r">\s*$", last_line): output += super().enable( cmd="enable", pattern=pattern, enable_pattern=enable_pattern, check_state=False, re_flags=re_flags, ) self.set_base_prompt() return output def exit_enable_mode(self, exit_command: str = "exit") -> str: """Exit diagnostic CLI and return to the top-level FTD CLI. Uses Ctrl+a, d to detach from the diagnostic CLI process, returning directly to the FTD CLI regardless of current privilege level (> or #). """ output = "" if getattr(self, "_in_diagnostic_cli", False): output += self._send_command_str("\x01d", expect_string=r">", cmd_verify=False) self._in_diagnostic_cli = False self.set_base_prompt() return output def send_config_set(self, *args: Any, **kwargs: Any) -> str: """Cannot change config on FTD via SSH.""" raise NotImplementedError def check_config_mode( self, check_string: str = "", pattern: str = "", force_regex: bool = False ) -> bool: """Cannot change config on FTD via SSH.""" return FalseSubclass specific to Cisco FTD.
FTD has two CLI layers:
-
FTD CLI (top level) - where you land after SSH login. Prompt: firepower> No enable mode; no config mode.
-
Diagnostic CLI (ASA sub-shell) - entered via firepower> system support diagnostic-cli Attaching to Diagnostic CLI … Type help or '?' for a list of available commands.
firepower> enable Password: <– Press Enter here (no password) firepower#
Calling enable() enters the diagnostic CLI and elevates to '#'. Calling exit_enable_mode() returns to the top-level FTD CLI.
Initialize attributes for establishing connection to target device. :param ip: IP address of target device. Not required if <code>host</code> is provided. :param host: Hostname of target device. Not required if <code>ip</code> is provided. :param username: Username to authenticate against target device if required. :param password: Password to authenticate against target device if required. :param secret: The enable password if target device requires one. :param port: The destination port used to connect to the target device. :param device_type: Class selection based on device type. :param verbose: Enable additional messages to standard output. :param global_delay_factor: Multiplication factor affecting Netmiko delays (default: 1). :param use_keys: Connect to target device using SSH keys. :param key_file: Filename path of the SSH key file to use. :param pkey: SSH key object to use. :param passphrase: Passphrase to use for encrypted key; password will be used for key decryption if not specified. :param disabled_algorithms: Dictionary of SSH algorithms to disable. Refer to the Paramiko documentation for a description of the expected format. :param disable_sha2_fix: Boolean that fixes Paramiko issue with missing server-sig-algs <https://github.com/paramiko/paramiko/issues/1961> (default: False) :param allow_agent: Enable use of SSH key-agent. :param ssh_strict: Automatically reject unknown SSH host keys (default: False, which means unknown SSH host keys will be accepted). :param system_host_keys: Load host keys from the users known_hosts file. :param alt_host_keys: If <code>True</code> host keys will be loaded from the file specified in alt_key_file. :param alt_key_file: SSH host key file to use (if alt_host_keys=True). :param ssh_config_file: File name of OpenSSH configuration file. :param conn_timeout: TCP connection timeout. :param session_timeout: Set a timeout for parallel requests. :param auth_timeout: Set a timeout (in seconds) to wait for an authentication response. :param banner_timeout: Set a timeout to wait for the SSH banner (pass to Paramiko). :param read_timeout_override: Set a timeout that will override the default read_timeout of both send_command and send_command_timing. This is useful for 3rd party libraries where directly accessing method arguments might be impractical. :param keepalive: Send SSH keepalive packets at a specific interval, in seconds. Currently defaults to 0, for backwards compatibility (it will not attempt to keep the connection alive). :param default_enter: Character(s) to send to correspond to enter key (default:).
:param response_return: Character(s) to use in normalized return data to represent enter key (default:)
:param serial_settings: Dictionary of settings for use with serial port (pySerial). :param fast_cli: Provide a way to optimize for performance. Converts select_delay_factor to select smallest of global and specific. Sets default global_delay_factor to .1 (default: True) :param session_log: File path, SessionLog object, or BufferedIOBase subclass object to write the session log to. :param session_log_record_writes: The session log generally only records channel reads due to eliminate command duplication due to command echo. You can enable this if you want to record both channel reads and channel writes in the log (default: False). :param session_log_file_mode: "write" or "append" for session_log file mode (default: "write") :param allow_auto_change: Allow automatic configuration changes for terminal settings. (default: False) :param encoding: Encoding to be used when writing bytes to the output channel. (default: "utf-8") :param sock: An open socket or socket-like object (such as a <code>.Channel</code>) to use for communication to the target host (default: None). :param sock_telnet: A dictionary of telnet socket parameters (SOCKS proxy). See telnet_proxy.py code for details. :param global_cmd_verify: Control whether command echo verification is enabled or disabled (default: None). Global attribute takes precedence over function <code>cmd\_verify</code> argument. Value of <code>None</code> indicates to use function <code>cmd\_verify</code> argument. :param auto_connect: Control whether Netmiko automatically establishes the connection as part of the object creation (default: True). :param delay_factor_compat: Set send_command and send_command_timing back to using Netmiko 3.x behavior for delay_factor/global_delay_factor/max_loops. This argument will be eliminated in Netmiko 5.x (default: False). :param disable_lf_normalization: Disable Netmiko's linefeed normalization behavior (default: False)Ancestors
Methods
def check_config_mode(self, check_string: str = '', pattern: str = '', force_regex: bool = False) ‑> bool-
Expand source code
def check_config_mode( self, check_string: str = "", pattern: str = "", force_regex: bool = False ) -> bool: """Cannot change config on FTD via SSH.""" return FalseCannot change config on FTD via SSH.
def check_enable_mode(self, check_string: str = '#') ‑> bool-
Expand source code
def check_enable_mode(self, check_string: str = "#") -> bool: """Check if in enable mode (diagnostic CLI privileged exec).""" return super().check_enable_mode(check_string=check_string)Check if in enable mode (diagnostic CLI privileged exec).
def enable(self,
cmd: str = 'system support diagnostic-cli',
pattern: str = 'ssword',
enable_pattern: str | None = '\\#',
check_state: bool = True,
re_flags: int = re.IGNORECASE) ‑> str-
Expand source code
def enable( self, cmd: str = "system support diagnostic-cli", pattern: str = "ssword", enable_pattern: Optional[str] = r"\#", check_state: bool = True, re_flags: int = re.IGNORECASE, ) -> str: """Enter enable mode on FTD via the diagnostic CLI. Sends 'system support diagnostic-cli' to enter the ASA/Lina sub-shell, then runs 'enable' if still at user-exec prompt ('>'). The diagnostic CLI enable password is always empty (always send null-string). """ output = "" if check_state and self.check_enable_mode(): return output # Enter the diagnostic CLI self.write_channel(self.normalize_cmd(cmd)) if self.global_cmd_verify is not False: output += self.read_until_pattern(pattern=re.escape(cmd.strip())) output += self.read_until_pattern(pattern=r"[>#]") # Track that we are inside the diagnostic CLI so exit_enable_mode # knows to send a second 'exit' to return to the FTD CLI. self._in_diagnostic_cli = True # If at user-exec mode ('>'), elevate to enable ('#') last_line = output.splitlines()[-1] if output.strip() else "" if re.search(r">\s*$", last_line): output += super().enable( cmd="enable", pattern=pattern, enable_pattern=enable_pattern, check_state=False, re_flags=re_flags, ) self.set_base_prompt() return outputEnter enable mode on FTD via the diagnostic CLI.
Sends 'system support diagnostic-cli' to enter the ASA/Lina sub-shell, then runs 'enable' if still at user-exec prompt ('>'). The diagnostic CLI enable password is always empty (always send null-string).
def exit_enable_mode(self, exit_command: str = 'exit') ‑> str-
Expand source code
def exit_enable_mode(self, exit_command: str = "exit") -> str: """Exit diagnostic CLI and return to the top-level FTD CLI. Uses Ctrl+a, d to detach from the diagnostic CLI process, returning directly to the FTD CLI regardless of current privilege level (> or #). """ output = "" if getattr(self, "_in_diagnostic_cli", False): output += self._send_command_str("\x01d", expect_string=r">", cmd_verify=False) self._in_diagnostic_cli = False self.set_base_prompt() return outputExit diagnostic CLI and return to the top-level FTD CLI.
Uses Ctrl+a, d to detach from the diagnostic CLI process, returning directly to the FTD CLI regardless of current privilege level (> or #).
def send_config_set(self, *args: Any, **kwargs: Any) ‑> str-
Expand source code
def send_config_set(self, *args: Any, **kwargs: Any) -> str: """Cannot change config on FTD via SSH.""" raise NotImplementedErrorCannot change config on FTD via SSH.
def session_preparation(self) ‑> None-
Expand source code
def session_preparation(self) -> None: """Prepare the session after the connection has been established.""" self._test_channel_read(pattern=r"[>#]") self.set_base_prompt()Prepare the session after the connection has been established.
Inherited members
CiscoSSHConnection:cleanupclear_buffercommitconfig_modedisable_pagingdisconnectenable_secret_handlerestablish_connectionexit_config_modefind_promptis_alivenormalize_cmdnormalize_linefeedsparamiko_cleanupread_channelread_channel_timingread_until_patternread_until_promptread_until_prompt_or_patternrun_ttpsave_configselect_delay_factorsend_commandsend_command_expectsend_command_timingsend_config_from_filesend_multilineset_base_promptset_terminal_widthspecial_login_handlerstrip_ansi_escape_codesstrip_backspacesstrip_commandstrip_prompttelnet_loginwrite_channel
-