Skip to content
BerryCade BETA
User manual

12. Command line

Everything you configure in the panel can also be done from the command line, on the device console or over SSH. In the restricted console or as root, type berrycade <command>.

The Tab key completes commands, sections, names that already exist in the configuration (policies, addresses, zones, interfaces…), fields and possible values. berrycade --help lists all commands and berrycade <command> --help shows the details of each one.

Panel console: htop, ping and the CLI help

Figure 23 — Panel console: htop, ping and the CLI help

12.1 How changes are applied

The command line uses the same API and the same apply mechanism as the panel:

12.2 Configuration

CommandWhat it does
berrycade sectionsLists the configuration sections (12.3).
berrycade fields <section>Lists the fields of the section, with their types and possible values.
berrycade show <section> [key]Shows the section as a table, or one complete item. --yaml shows the whole section in YAML.
berrycade add <section> field=value …Creates an item.
berrycade set <section> <key> field=value …Changes fields of an item; the others stay as they are.
berrycade set <setting> field=value …Changes the general settings: system, ids, webfilter and tailscale.
berrycade del <section> <key>Removes an item (refused if it is in use).
berrycade refs <section> <key>Shows what uses an item.
berrycade move <section> <key> before|after <other>Reorders policies (policies) or central NAT rules (snat_rules).
berrycade pending · confirm · cancelShows, confirms or undoes the change that is waiting for confirmation.
berrycade revisions · diff <rev> · rollback <rev>Revision history, what a revision changed, and rolling back to a revision.

Field format:

12.3 Configuration sections

SectionContents
zonesSecurity zones.
interfacesPhysical ports (LAN/WAN), addressing, DHCP and panel access.
vlans802.1Q VLANs.
addressesAddress objects and groups.
servicesService objects (ports) and groups.
ip_poolsIP pools for source NAT.
virtual_ipsVirtual IPs / port forwarding.
policiesFirewall policies (order matters).
snat_rulesCentral NAT (order matters).
ipsecIPsec tunnels.
static_routesStatic routes.
dhcp_bansMACs banned from DHCP.
device_namesCustom device names.
access_pointsUniFi access points.
webfilter_profilesWeb filter profiles.
ssl_profilesSSL inspection profiles.
system (setting)Name, time zone, DNS, panel port and access, confirmation time limit.
ids (setting)IDS/IPS (Suricata).
webfilter (setting)Automatic update of the web filter lists.
tailscale (setting)Tailscale VPN.

12.4 Operation

CommandWhat it does
berrycade dashboardDevice summary: CPU, memory, temperature, interfaces and services.
berrycade countersBytes and packets per policy.
berrycade dhcp clientsDHCP clients (leases, reservations and banned).
berrycade dhcp reserve <mac> <ip> <interface>Reserves an IP (--nome gives the device a name). unreserve <mac> removes it.
berrycade dhcp revoke · ban · unban <mac>Revokes the lease; bans a MAC (--motivo, the reason) or lifts its ban.
berrycade connections list · clearActive sessions (--filtro, --limite); ends all of them or those from --origem <IP>.
berrycade logs <type>traffic, audit, system, webfilter or ids, with --limite and --filtro. For traffic: --tipo accepted|denied and --zona; for system: --servico <unit>.
berrycade service list · restart <service>Service status; restarts one of them.
berrycade ids status · alerts · rules-updateIDS/IPS status and rules, recent alerts, rule update.
berrycade ids zone <zone> off|alert|blockIDS/IPS mode in a zone.
berrycade ipsec status · up · down <tunnel>Tunnel status; brings a tunnel up or down.
berrycade tailscale status · login · logoutTailscale status and authentication (--auth-key).
berrycade certs list · generate · import-caIPsec certificates: lists, generates (<name> <CN> [--dias]) or imports a CA (<name> <file.pem>).
berrycade webfilter catalog · update · logCategories and counts, list download (the ones in use or the ones you specify), recent blocks.
berrycade webfilter block-page show|reset|setBlock page: shows it, restores the default or uses an HTML file.
berrycade ssl-ca show · export · regenerateSSL inspection CA: details, save to a file (pem, der, crt), generate a new one.
berrycade firmware status · check · downloadInstalled versions and the available one; checks for and downloads a new version.
berrycade firmware install · discard · rollback <version>Installs the uploaded firmware, discards it or rolls back to an earlier version.
berrycade backup export <file>Saves a configuration backup (--senha encrypts it; --sem-admins, --sem-certs).
berrycade wifi status · refreshAccess points and Wi-Fi clients.
berrycade admins list · add · del · hostsPanel administrators and their trusted hosts.
berrycade reboot · poweroff · restart-apiRestarts or shuts down the device; restarts the panel (they ask for confirmation).
berrycade api <method> <path> [field=value …]Direct access to any panel API route (advanced).

12.5 Recovery and access

These commands work even when the panel is stopped:

CommandWhat it does
berrycade statusShows the active revision and the status of the services.
berrycade revisionsLists the revision history.
berrycade rollback <rev>Rolls back to a revision.
berrycade applyReapplies the current configuration.
berrycade reset-adminResets the admin user with the password admin (change required) and ends its sessions.
berrycade factory-resetRestores the factory configuration.
berrycade usersLists the panel users with open sessions, lockouts and trusted hosts.
berrycade passwd <user>Resets the password of a panel user. --temporary generates a temporary password that must be changed.
berrycade blockedLists users and IPs locked out after failed login attempts.
berrycade unblock <user|IP>Removes a lockout (--all removes all of them).
berrycade sessionsLists the open panel sessions.
berrycade logout <user>Ends a user's sessions.
berrycade rules-updateUpdates the IDS rules now.

12.6 Examples

View the policies and the details of the first one:

berrycade show policies
berrycade show policies 1

Create an address object and allow it in policy 1:

berrycade add addresses name=servidor type=subnet value=10.0.0.10/32 "comment=Servidor de arquivos"
berrycade set policies 1 src_addr+=servidor

Create a user VLAN with its own zone and DHCP (the .100–.200 range is filled in automatically):

berrycade add zones name=usuarios "description=VLAN de usuários"
berrycade add vlans name=usuarios parent=lan vid=10 zone=usuarios address=192.168.10.1/24 dhcp_server.enabled=true

General settings, web filter and IDS:

berrycade set system dns.servers=8.8.8.8,1.1.1.1
berrycade set webfilter_profiles Libera_Tudo categories.malware=block
berrycade ids zone lan alert

DHCP, logs and backup:

berrycade dhcp reserve 60:c7:27:08:bb:ae 172.16.1.50 lan --nome notebook
berrycade logs traffic --tipo denied --limite 20
berrycade backup export /root/backup.swbk --senha