11.25. WiFi Command Reference

11.25.1. Command Hierarchies

11.25.1.1. WLAN-GW Commands

Note:

The wlan-gw commands apply only to the 7750 SR platform.

11.25.1.2. ISA Commands

config
isa-filtername [type {dsm}] [create]
— no isa-filter name
default-action {drop | forward}
description description-string
entry entry-id [create]
— no entry entry-id
action {drop | forward | none}
— no action
description description-string
match protocol {any | icmp | tcp | udp | gre}
— no match
dst-ip ip-prefix/length
— no dst-ip
dst-port operator port-number
— no dst-port
src-ip ip-prefix/length
— no src-ip
src-port operator port-number
— no src-port
— ipv6
default-action {drop | forward}
entry entry-id [create]
— no entry entry-id
action {drop | forward | none}
— no action
description description-string
— no description
match protocol {any | icmp | tcp | udp}
— no match
dst-ip ip-prefix/length
— no dst-ip
dst-port operator port-number
— no dst-port
src-ip ip-prefix/length
— no src-ip
src-port operator port-number
— no src-port
isa-policer policer-name [type policer-type] [create]
— no isa-policer policer-name
action {permit-deny | priority-mark}
— no action
adaptation-rule pir {max | min | closest} [cir {max | min | closest}]
cbs burst-size
— no cbs
description description-string
mbs burst-size
— no mbs
rate rate [cir rate]
— no rate
config service
— ies service-id/vprn service-id
— subscriber-interface ip-int-name
group-interface ip-int-name [create]
group-interface ip-int-name [create] lns
group-interface ip-int-name [create] wlangw
— no group-interface ip-int-name
range start [range] end [range]
range default
— no range start [range] end [range]
authentication-policy policy-name
hold-time [hrs hours] [min minutes] [sec seconds]
— no hold-time
accounting-policy policy-name
def-app-profile profile-name
dsm-ip-filter dsm-ip-filter-name
egress-policer [policer-name]
ingress-policer policer-name
one-time-redirect url rdr-url-string port port-num
[no] shutdown
vlan start [value] end [value] retail-svc-id service-id
— no vlan start [value] end [value]
wlan-gw-group group-id
— no] shutdown

11.25.1.3. WLAN-GW Service Commands

configure
— service
— ies service-id/vprn service-id
ipv6-tcp-mss-adjust segment-size
— subscriber-interface ip-int-name
link-addr ipv6-address
— no link-addr
pool-name name
— no pool-name
[no] shutdown
ia-na
link-addr ipv6-address
— no link-addr
pool-name name
— no pool-name
[no] shutdown
lease-query [max-retry Max nbr of retries]
server ipv6-address [ipv6-address... (up to 8 max)]
— no server [ipv6-address [ipv6-address... (up to 8 max)]]
slaac
link-addr ipv6-address
— no link-addr
pool-name name
— no pool-name
[no] shutdown
source-ip ipv6-address
— no source-ip
watermarks high high-percentage low low-percentage
— no watermarks
wlan-gw-group nat-group-id
export ip-prefix/length
— no export
monitor ip-prefix/length
— no monitor
[no] shutdown
group-interface ip-int-name [create]
group-interface ip-int-name [create] lns
group-interface ip-int-name [create] wlan
— no group-interface ip-int-name
brg
default-brg-profile profile-name
[no] shutdown
dhcp
ip-mtu octets
— no ip-mtu
anti-spoof {ip-mac | nh-mac}
— no anti-spoof
description description-string
def-app-profile app-profile-name
def-sla-profile sla-profile-name
def-sub-id string sub-id
def-sub-id use-auto-id
— no def-sub-id
def-sub-profile sub-profile-name
sub-ident-policy policy-name
egress
[no] agg-rate-limit
rate kilobits-per-second
— no rate
hold-time infinite
hold-time [time]
— no hold-time
qos policy-id
— no qos
scheduler-policy scheduler-policy-name
shaping {per-retailer | per-tunnel}
— no shaping
gw-address ip-address
— no gw-address
gw-ipv6-address ipv6-address
learn-ap-mac [delay-auth]
l2-ap sap-id [create]
— no l2-ap sap-id
encap-type {default | null | dot1q | qinq}
— no encap-type
[no] shutdown
l2-ap-auto-sub-id-fmt {include-ap-tags | sap-only}
l2-ap-encap-type {null | dot1q | qinq}
hold-time time in s
— no hold-time
[no] inter-vlan
trigger [data] [iapp] [control]
— no trigger
router router-instance
— no router
[no] shutdown
tcp-mss-adjust segment-size
learn-l2tp-cookie {if-match | never | always} [cookie hex string]
range start [range] end [range]
range default
— no range start [range] end [range]
authentication-policy policy-name
hold-time [hrs hours] [min minutes] [sec seconds]
dhcp
active-lease-time [hrs hours] [min minutes] [sec seconds]
initial-lease-time [hrs hours] [min minutes] [sec seconds]
l2-aware-ip-address ip-address
l2-aware-ip-address from-pool
primary-dns ip-address
primary-nbns ip-address
secondary-dns ip-address
secondary-nbns ip-address
[no] shutdown
dhcp6
active-preferred-lifetime [hrs hours] [min minutes] [sec seconds]
active-valid-lifetime [hrs hours] [min minutes] [sec seconds]
initial-preferred-lifetime [hrs hours] [min minutes] [sec seconds]
initial-valid-lifetime [hrs hours] [min minutes] [sec seconds]
[no] shutdown
accounting-policy policy-name
def-app-profile profile-name
dsm-ip-filter dsm-ip-filter-name
egress-policer [policer]
ingress-policer policer-name
one-time-redirect url rdr-url-string port port-num
[no] shutdown
idle-timeout action idle-timeout-action
http-redirect-policy policy-name
l2-service service-id
— no l2-service
description description-string
[no] shutdown
nat-policy policy-name
— no nat-policy
retail-svc-id service-id
configure
— service
— vprn service-id
ipv6-tcp-mss-adjust segment-size
interim-update include-counters [hold-down seconds]
configure
— service
— vpls service-id
— wlan-gw
description description-string
sap-template sap template
[no] shutdown

11.25.1.4. Subscriber Management vRGW (BRG Profile) Commands

configure
vrgw
— brg
brg-profile profile-name [create]
— no brg-profile profile-name
connectivity-verification [count nr-of-attempts] [timeout timeout-seconds] [retry-time retry-seconds]
description description-string
— no description
lease-time [days days] [hrs hrs] [min min] [sec sec]
lease-time seconds
— no lease-time
custom-option option-number address [ip-address]
custom-option option-number hex hex-string
custom-option option-number string ascii-string
— no custom-option option-number
standby-ip-lifetime [seconds]
subnet ip-prefix/prefix-length start ip-address end ip-address
hold-time seconds
— no hold-time
initial-hold-time [min min] [sec sec]
initial-hold-time seconds
password password [hash | hash2]
— no password
radius-server-policy policy-name
[no] radius-proxy-server router router-instance name server-name

11.25.1.5. Data Plane Related Commands

config
— isa
wlan-gw-group group-id [create] [redundancy unit]
— no wlan-gw-group group-id
active-iom-limit number
active-mda-limit number
description description-string
isa-aa-group aa-group-id
iom slot-number type {[load-balancer] [ue-anchor]}
— no iom slot-number
[no] mda mda-id
nat
radius-accounting-policy nat-accounting-policy
reserved num-sessions
— no reserved
watermarks high percentage low percentage
— no watermarks
mark entity high percentage-high low percentage-low

11.25.1.6. RADIUS Server and Proxy Commands

configure
— aaa
acct-on-off-group group-name [create]
— no acct-on-off-group group-name
description description-string
radius-server-policy policy-name [create]
— no radius-server-policy policy-name
accept-script-policy policy-name
acct-on-off monitor-group group-name
acct-on-off oper-state-change [group group-name]
[no] buffering
acct-interim min min-val max max-val lifetime lifetime
acct-stop min min-val max max-val lifetime lifetime
— no acct-stop
description description-string
access-algorithm {direct | round-robin | hash-based}
interval seconds
— no interval
password password [hash | hash2]
— no password
[no] shutdown
user-name user-name
— no user-name
hold-down-time [sec seconds] [min minutes] [hrs hours] [days days]
ipv6-source-address ipv6-address
router router-instance
router service-name service-name
— no router
server server-index name server-name
— no server server-index
source-address ip-address
timeout [sec seconds] [min minutes]
— no timeout
configure
— router
server server-name [address ip-address] [secret key ] [hash | hash2] [port port] [create]
— no server server-name
[no] accept-coa
acct-port port
— no acct-port
auth-port port
— no auth-port
coa-script-policy script-policy-name
description description-string
configure
— router
server server-name [create] [purpose {[accounting | authentication]}] [wlan-gw-group group-id]
— no server server-name
entry [entry] [prefix-string prefix-string] [accounting-server-policy policy-name] [authentication-server-policy policy-name] [suffix-string suffix-string]
— no entry [entry] [
type [type] [vendor-id vendor-id]
— no type
cache
key packet-type {accept | request} attribute-type attribute-type [vendor vendor-id]
— no key
[no] shutdown
timeout [hrs hours] [min minutes] [sec seconds]
— no timeout
track-accounting [start] [stop] [interim-update] [accounting-on] [accounting-off]
description description-string
[no] interface interface-name
load-balance-key [vendor vendor-id [vendor-id]] attribute-type attribute-type [attribute-type]
load-balance-key source-ip-udp
python-policy name
secret secret [hash | hash2]
— no secret
[no] shutdown
configure
— service
— vprn
server server-name [create] [purpose {[accounting | authentication]}] [wlan-gw-group group-id]
— no server server-name
[no] accept-coa
acct-port port
— no acct-port
entry [1..32] [prefix-string prefix-string] [accounting-server-policy policy-name] [authentication-server-policy policy-name] [suffix-string suffix-string]
— no entry [1..32]
type [type] [vendor-id vendor-id]
— no type
auth-port port
— no auth-port
cache
key packet-type {accept | request} attribute-type attribute-type [vendor vendor-id]
— no key
[no] shutdown
timeout [hrs hours] [min minutes] [sec seconds]
— no timeout
track-accounting [stop] [interim-update] [accounting-on] [accounting-off]
coa-script-policy script-policy-name
description description-string
[no] interface interface-name
load-balance-key [vendor vendor-id [vendor-id]] attribute-type attribute-type [attribute-type]
load-balance-key source-ip-udp
secret secret [hash | hash2]
— no secret
[no]shutdown

11.25.1.7. LUDB Matching for RADIUS Proxy Cache

config
— subscriber-mgmt
local-user-db local-user-db-name [create]
— no local-user-db local-user-db-name
dhcp
— host
fail-action {continue | drop}
mac-format mac-format
— no mac-format
match {circuit-id | mac | remote-id}
match option [option] [option6 [option6]]
match option6 [option]
— no match
server [service service-id] name server-name
— no server

11.25.1.8. Port Policy Commands

config
port-policy policy-name [create]
— no port-policy policy-name
description description-string
egress-scheduler-policy port-sched-plcy

11.25.1.9. WIFI Aggregation and Offload – Migrant User Support Commands

configure
— subscriber-mgmt
http-redirect-policy policy-name [create]
— no http-redirect-policy policy-name
description description-string
dst-port tcp-port
— no dst-port
dst-ip ip-address protocol ip-protocol dst-port port-number
dst-ip ip-address protocol ip-protocol dst-port port-number prefix-length prefix-length
— no dst-ip ip-address protocol ip-protocol dst-port port-number
portal-hold-time seconds
url rdr-url-string
— no url

11.25.1.10. Show Commands

show
ue [ieee-address] [detail]
— router
radius-proxy-server server-name
radius-proxy-server server-name cache
radius-proxy-server server-name cache hex-key hex-string
radius-proxy-server server-name cache string-key string
radius-proxy-server server-name cache summary
radius-proxy-server server-name statistics
isa-subnets [detail]
isa-subnets [detail] interface interface-name
isa-subnets prefix ipv6-address/prefix-length
tunnel-qos [detail]
tunnel-qos remote-ip ip-address [local-ip ip-address] [detail]
tunnels local-ip ip-address remote-ip ip-address ue
tunnels [local-ip ip-address] [remote-ip ip-address] [isa-group wlan-gw-group-id] [member [1..255]] [summary] [detail]
tunnels local-ip ip-address remote-ip ip-address ue
tunnels [local-ip ip-address] [remote-ip ip-address] [isa-group wlan-gw-group-id] [member [1..255]] [summary] [detail]
tunnels local-ip ip-address remote-ip ip-address ue
show
— aaa
acct-on-off-group group-name
radius-server-policy policy-name [acct-on-off]
radius-server-policy policy-name associations
radius-server-policy policy-name msg-buffer-stats
radius-server-policy policy-name statistics
radius-server-policy [acct-on-off]
show
— isa
wlan-gw-group wlan-gw-group-id
wlan-gw-group wlan-gw-group-id associations
wlan-gw-group wlan-gw-group-id member member-id
wlan-gw-group wlan-gw-group-id member member-id resource-statistics
wlan-gw-group wlan-gw-group-id member member-id statistics [type type] [non-zero-value-only]
show
— subscriber-mgmt
isa-filter name
isa-filter name associations
isa-filter name ipv4
isa-filter name ipv6
isa-policer policer-name
isa-policer policer-name associations
— vrgw
— brg
brg-profile name
brg-profile name associations
gateway brg-id brg-ident bindings [mac ieee-address]
gateway brg-id brg-ident host mac ieee-address ip ip-address
gateway brg-id brg-ident hosts
gateway brg-id brg-ident standby-ip-addresses
— wlan-gw
ssid
tunnels [router router-name] [remote-ip ip-address] [local-ip ip-address] [encapsulation encap [encap...(upto 3 max)]] [qtag1 qtag] [qtag2 qtag] [ap-sap sap-id] [min-num-ue minimum] [max-num-ue maximum] [ap-mac-learn-failed {true | false}] [get-num-results] [addr-family family] [ue-type ue-type [ue-type...(up to 5 max)]]
ue [vlan qtag] [mpls-label label] [retail-svc-id service-id] [ssid service-set-id] [previous-access-point ip-address] [bd bridge-id]
ue mac ieee-address [bd bridge-id]

11.25.1.11. Debug Commands

debug
[no] wlan-gw
— group
statistic type type name name
ue ieee-address [profile trace-profile-name]
— no ue ieee-address

11.25.1.12. Tools Commands

tools
— perform
— aaa
acct-on [radius-server-policy policy-name] [force]
acct-off acct-off [radius-server-policy policy-name] [force] [acct-terminate-cause number]
— dump
— aaa
radius-server-policy policy-name msg-buffer [session-id acct-session-id]]
— wlan-gw
— isa
performance mda mda-id last time-span time-unit
ue [wlan-gw-group wlan-gw-group-id] [mda mda-id] [next-index index] [summary] [detail] [bd bridge-id] [ue-mac ieee-address] [ue-vlan vlan] [state-description state] [tunnel-router router-instance] [tunnel-source-ip ip-address] [tunnel-destination-ip ip-address] [tunnel-type tunnel-type] [ue-ip ipv4-address] [dhcp6-addr ipv6-address] [slaac-prefix ipv6-address] [aggregate-summary]

11.25.1.13. Clear Commands

clear
— aaa
radius-server-policy policy-name msg-buffer [acct-session-id acct-session-id]
radius-server-policy policy-name statistics [msg-buffer-only]
radius-server-policy policy-name server server-index statistics
clear
— router
— wlan-gw
isa-subnets all
isa-subnets interface intfip-int-name
isa-subnets prefix ipv6-address/prefix-length
clear
— wlan-gw
— isa
wlan-gw-group group-id member member-id resource-peak-values
wlan-gw-group group-id member member-id statistics

11.25.2. WIFI Aggregation and Offload Commands

11.25.2.1. WIFI Aggregation and Offload Commands

11.25.2.1.1. Generic Commands

description

Syntax 
description description-string
no description
Context 
config>aaa>acct-on-off-grp
config>aaa>radius-srv-plcy
config>isa>wlan-gw-group
config>router>radius-server>server
config>router>radius-proxy>server
config>service>vprn>radius-proxy>server
config>service>vprn>radius-server>server
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
config>service>ies>sub-if>grp-if>sap-parameters
config>service>vprn>sub-if>grp-if>sap-parameters
config>subscr-mgmt>wlan-gw>dsm>dsm-ip-filter
config>subscr-mgmt>wlan-gw>dsm>dsm-ip-filter>ipv6
config>call-trace>trace-profile
config>subscr-mgmt>isa-filter
config>subscr-mgmt>isa-filter>ipv6>entry
config>subscr-mgmt>isa-filter>entry
config>subscriber-mgmt>isa-policer
Description 

This command creates a text description stored in the configuration file for a configuration context.

The description command associates a text string with a configuration context to help identify the context in the configuration file.

The no form of this command removes any description string from the context.

Parameters 
description-string—
Specifies a text string describing the entity. Allowed values are any string up to 80 characters long composed of printable, 7-bit ASCII characters excluding double quotes. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes.

shutdown

Syntax 
[no] shutdown
Context 
config>router>radius-proxy>cache
config>router>radius-proxy>server>cache
config>router>radius-proxy>server
config>service>vprn>radius-proxy>server>cache
config>service>vprn>radius-proxy>server
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
config>service>ies>sub-if>wlan-gw>pool-mgr>dhcp6-client>slaac
config>service>vprn>sub-if>wlan-gw>pool-mgr>dhcp6-client>slaac
config>service>ies >sub-if>wlan-gw>pool-mgr>dhcp6-client>ia-na
config>service>vprn>sub-if>wlan-gw>pool-mgr>dhcp6-client>ia-na
config>service>ies>sub-if>wlan-gw>pool-mgr>dhcp6-client>dhcpv4-nat
config>service>vprn>sub-if>wlan-gw>pool-mgr>dhcp6-client>dhcpv4-nat
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>brg
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>brg
config>service>ies>sub-if>grp-if>brg
config>service>vprn>sub-if>grp-if>brg
Description 

This command administratively disables the entity. When disabled, an entity does not change, reset, or remove any configuration settings or statistics. Many entities must be explicitly enabled using the no shutdown command.

The shutdown command administratively disables an entity. The operational state of the entity is disabled as well as the operational state of any entities contained within. Many objects must be shut down before they can be deleted.

Unlike other commands and parameters where the default state is not indicated in the configuration file, shutdown and no shutdown are always indicated in system generated configuration files.

The no form of the command puts an entity into the administratively enabled state.

Default 

no shutdown

subscriber-mgmt

Syntax 
subscriber-mgmt
Context 
config
Description 

This command enables the context to configure subscriber management entities. A subscriber is uniquely identified by a subscriber identification string. Each subscriber can have several DHCP sessions active at any time. Each session is referred to as a subscriber host and is identified by its IP address and MAC address.

All subscriber hosts belonging to the same subscriber are subject to the same hierarchical QoS (HQoS) processing. The HQoS processing is defined in the sub-profile (the subscriber profile). A sub-profile refers to an existing scheduler policy (configured in the config>qos>scheduler-policy context) and offers the possibility to overrule the rate of individual schedulers within this policy.

Because all subscriber hosts use the same scheduler policy instance, they must all reside on the same complex.

11.25.2.1.2. WLAN-GW Commands

Note:

The wlan-gw commands apply only to the 7750 SR platform.

wlan-gw

Syntax 
[no] wlan-gw
Context 
config>subscriber-mgmt
config>router
config>service>vprn
Description 

This command enables the context to configure WLAN Gateway parameters.

distributed-sub-mgmt

Syntax 
distributed-sub-mgmt
Context 
config>subscriber-mgmt>wlan-gw
config>router>wlan-gw
config>service>vprn>wlan-gw
Description 

This command enables the context to configure profiles, templates and policies that can be applied to DSM subscribers.

virtual-chassis-identifier

Syntax 
virtual-chassis-identifier dual-homing-key
no virtual-chassis-identifier
Context 
config>subscr-mgmt>wlan-gw
Description 

This command specifies a virtual chassis identifier that can link two wlan-gw’s together.

The no form of the command removes the dual-homing-key

Parameters 
dual-homing-key—
Specifies the name of the dual homing key up to 16 characters.

ipv6-tcp-mss-adjust

Syntax 
ipv6-tcp-mss-adjust segment-size
no ipv6-tcp-mss-adjust
Context 
config>router>wlan-gw>dsm
config>service>vprn>wlan-gw>dsm
Description 

This command specifies the value used for TCP-MSS-adjust in the IPv6 upstream direction for DSM. The downstream direction for both IPv4 and IPv6 are both configured under the group-interface. The upstream direction for IPv4 NAT hosts is configured under the NAT policy.

The defined segment size is inserted in a TCP SYN message if there is no existing MSS option or the value in the MSS option is bigger than the configured value.

The no form of the command disables upstream TCP MSS adjust for IPv6 DSM.

Default 

no ipv6-tcp-mss-adjust

Parameters 
segment-size—
Specifies the segment size to be inserted.
Values—
160 to 10240

 

gtp-peer-clear-timeout

Syntax 
gtp-peer-clear-timeout seconds
no gtp-peer-clear-timeout
Context 
config>service>vprn>wlan-gw>dsm
Description 

This command configures a GTP peer cleanup timeout to terminate a handover wait state.

Parameters 
seconds—
Specifies a GTP peer cleanup timeout, in seconds, to terminate a handover wait state.
Values—
0 to 3600

 

mobility-triggered-acct

Syntax 
mobility-triggered-acct
Context 
config>router>wlan-gw
config>service>vprn>wlan-gw
Description 

This command enters the configuration context of mobility-triggered-accounting in wlan-gw context under router or VPRN service.

interim-update

Syntax 
interim-update
interim-update include-counters [hold-down seconds]
no interim-update
Context 
config>router>wlan-gw>mobility-triggered-acct
config>service>vprn>wlan-gw>mobility-triggered-acct
Description 

This command enables the inclusion of counters with a hold-down time option in mobility-triggered interim-updates. When enabled, to disable the inclusion of counters, interim updates must be disabled and then re-enabled without the include-counters keyword. By default, the hold-down time is not imposed.

The no form of the command disables generation of flash interim accounting updates to RADIUS when change in location of the UE is detected.

Parameters 
include-counters—
Specifies the inclusion of counters in mobility triggered interim-updates.
seconds—
Specifies the time, in seconds, that must elapse after a mobility- triggered interim with counters sent for the next mobility-triggered interim with counters to be sent.
Values—
60 to 864000

 

11.25.2.1.2.1. Bridged Residential Gateway Commands

vrgw

Syntax 
vrgw
Context 
config>subscr-mgmt
Description 

This command enables the context to configure Virtual Residential Gateway parameters.

brg

Syntax 
brg
Context 
config>subscr-mgm>vrgw
Description 

This command enables the context to configure Bridged Residential Gateway parameters.

brg-profile

Syntax 
brg-profile profile-name [create]
Context 
config>subscr-mgmt>vrgw>brg
Description 

This command creates the profile Bridged Residential Gateway (BRG) devices. The BRG profile specifies default parameters that are used for host management under a single BRG.

The no form of the command removes the profile name from the configuration.

Parameters 
profile-name—
Specifies the name of the BRG profile.

connectivity-verification

Syntax 
connectivity-verification [count nr-of-attempts] [timeout timeout-seconds] [retry-time retry-seconds]
Context 
config>subscr-mgmt>vrgw>brg>brg-profile
Description 

This command configures the BRG connectivity verification. The system uses ICMP Echo request messages for connectivity verification.

When the last host associated to a BRG is removed, a ping mechanism is used to verify if the BRG is still active. This command specifies the parameters used in this mechanism.

The no form of the command disables the BRG ping mechanism and removes the BRG without verification. Any configured hold-time still applies.

Default 

connectivity-verification count 3 timeout 30 retry-time 900

Parameters 
nr-of-attempts
Specifies the number of connectivity verification attempts this system makes before a BRG is considered down.
Values—
1 to 5

 

timeout-seconds
Specifies the time, in seconds, after which an unanswered ping is considered failed.
Values—
5 to 60

 

retry-seconds
Specifies the time, in seconds, that the system waits while it considers a BRG down, before it starts a new connectivity verification cycle. If a ping succeeds, the mechanism is retried after this time.
Values—
300 to 3600

 

dhcp-pool

Syntax 
dhcp-pool
Context 
config>subscr-mgmt>vrgw>brg>brg-profile
Description 

This command enables the context to configure per-subscriber IPv4 address pool parameters to be used for address allocation. Pools for different subscribers can overlap. Specific pool parameters can be overridden by RADIUS.

lease-time

Syntax 
lease-time [days days] [hrs hrs] [min min] [sec sec]
lease-time seconds
no lease-time
Context 
config>subscr-mgmt>vrgw>brg>brg-profile>dhcp-pool
Description 

This command configures the lease time to be used when allocating addresses from the pool. This time should always be larger than the renew/rebind time.

The no form of the command reverts to the default.

Default 

lease-time hrs 6

Parameters 
days—
Specifies the lease time in days.
Values—
1 to 3650

 

hrs—
Specifies the lease time in hours.
Values—
1 to 23

 

min—
Specifies the lease time in minutes.
Values—
1 to 59

 

sec—
Specifies the in seconds.
Values—
1 to 58

 

seconds—
Specifies the lease time in seconds.
Values—
300 to 315446399

 

options

Syntax 
options
Context 
config>subscr-mgmt>vrgw>brg>brg-profile>dhcp-pool
Description 

This command enables the context to configure options that are reflected in DHCP.

custom-option

Syntax 
custom-option option-number address [ip-address (up to 4 max)]
custom-option option-number hex hex-string
custom-option option-number string ascii-string
no custom-option option-number
Context 
config>subscr-mgmt>vrgw>brg>brg-profile>dhcp-pool>options
Description 

This command configures DHCP options.

Parameters 
option-number—
Specifies the number of this DHCP option.
ip-address
Specifies up to four IP addresses.
hex-string
Specifies a hex string.
ascii-string
Specifies the ASCII string.

standby-ip-lifetime

Syntax 
standby-ip-lifetime [days days] [hrs hrs] [min min] [sec sec]
standby-ip-lifetime seconds
no standby-ip-lifetime
Context 
config>subscr-mgmt>vrgw>brg>brg-profile>dhcp-pool
Description 

This command defines how long these addresses is kept aside when standby addresses are signaled to the pool. During this time these addresses can only be used by devices explicitly requesting the IP (for example, datatrigger or DHCP renew or rebind). When the timer expires the addresses will again become available for dynamic allocation.

Default 

standby-ip-lifetime hrs 6

Parameters 
seconds—
Specifies the lifetime in seconds.
Values—
300 to 315446399

 

days—
Specifies the lifetime in days.
Values—
1 to 3650

 

hrs—
Specifies the lifetime in hours.
Values—
1 to 23

 

min—
Specifies the lifetime in minutes/
Values—
1 to 59

 

sec—
Specifies the lifetime in seconds
Values—
1 to 59

 

subnet

Syntax 
subnet ip-prefix/prefix-length start ip-address end ip-address
Context 
config>subscr-mgmt>vrgw>brg>brg-profile>dhcp-pool
Description 

This command configures the subnet that is used for the l2aware-subscriber. This subnet is only locally significant and can overlap with other subscribers. The subnet is derived by ignoring the host bits of the IP address. The IP address specifies the default gateway that is signaled in DHCP along with the netmask derived from the prefix-length. The specified subnet must lie within an L2-Aware NAT inside prefix and should not contain the L2-Aware gateway address.

The start and end addresses specify the addresses that are suitable for allocation within the given subnet, the start and end address included. If the subnet address (host-bits 0), broadcast address (host-bits 1) or default-gw address fall in this range, they will not be considered for allocation.

Changing the subnet will only have effect for new subscribers. New and existing hosts for existing subscribers will keep allocating from the original subnet.

The no form of this command removes the subnet configuration. New l2-aware subscribers will no longer use this pool and fall back to a pool from radius. Existing subscribers will keep using the original subnet.

Default 

no subnet

Parameters 
ip-prefix/prefix-length—
Specifies the IP prefix and prefix length.
ip-address
Specifies the starting or ending IP address.

hold-time

Syntax 
hold-time [days days] [hrs hrs] [min min] [sec sec]
hold-time seconds
no hold-time
Context 
config>subscr-mgmt>vrgw>brg>brg-profile
Description 

When the BRG should be deleted this still holds the BRG object for the specified time. This applies when connectivity-verification fails or when the last host is removed and no connectivity-verification is enabled. Hold time does not apply to an explicit removal via radius or clear commands.

The no form of the command deletes the hold-time.

Default 

no hold-time

Parameters 
days—
Specifies the hold time in days.
Values—
1 to 30

 

hrs—
Specifies the hold time in hours.
Values—
1 to 23

 

min—
Specifies the hold time in minutes.
Values—
1 to 59

 

sec—
Specifies the hold time in seconds.
Values—
1 to 59

 

seconds—
Specifies the time to hold on to a BRG after this system considered it down.
Values—
30 to 2592000

 

initial-hold-time

Syntax 
initial-hold-time [min min] [sec sec]
initial-hold-time seconds
no initial-hold-time
Context 
config>subscr-mgmt>vrgw>brg>brg-profile
Description 

This command configures the time to hold on to a BRG immediately after the system detected its presence. The hold time does not apply in case this system removes the BRG context upon an explicit request.

Default 

initial-hold-time min 5

Parameters 
min—
Specifies the initial hold time in minutes.
Values—
1 to 15

 

sec—
Specifies the initial hold time in seconds.
Values—
1 to 59

 

seconds—
Specifies the initial hold time to hold on to a BRG after this system considered it down.
Values—
0 to 900

 

radius-authentication

Syntax 
radius-authentication
Context 
config>subscr-mgmt>vrgw>brg>brg-profile
Description 

This command configures RADIUS authentication of the BRG.

radius-proxy-server

Syntax 
[no] radius-proxy-server router router-instance name server-name
Context 
config>subscr-mgmt>vrgw>brg>brg-profile
Description 

This command enables BRG processing on the specified RADIUS proxy server. Whenever an Access-Accept is received with the attribute Alc-BRG-Id present, this will trigger the creation of a BRG. The BRG will use the BRG profile specified in Access-Accept or otherwise fall-back to this BRG profile. When the specified radius-proxy-server has a cache enabled, no cache entries is created for a transaction identified as BRG. A RADIUS proxy server can only be listed in one BRG profile.

This command can be executed multiple times.

The no form of this command removes BRG processing for the specified RADIUS proxy server.

Parameters 
router-instance
Specifies the ID of the VRF where the proxy server is located.
server-name
Specifies the name of the RADIUS proxy server.

radius-server-policy

Syntax 
radius-server-policy policy-name
no radius-server-policy
Context 
config>subscr-mgmt>vrgw>brg>brg-profile>radius-authentication
Description 

This command is used if the BRG needs to be authenticated to the PCMP by the BRG. This is required if the BRG does not perform radius authentication via the proxy itself. The BRG will originate a valid Access Request using the BRG ID as username.

The no form of this command removes the radius-server-policy from the configuration. Setup of an unauthenticated BRG will now fail.

Default 

no radius-server-policy

Parameters 
policy-name—
Specifies the RADIUS server policy, up to 32 characters, to be applied in this subscriber authentication policy.

sla-profile-string

Syntax 
sla-profile-string string
no sla-profile-string
Context 
config>subscr-mgmt>vrgw>brg>brg-profile
Description 

This command configures the SLA profile string which is used as a default for SLA-profile lookup. This string can be overridden during BRG or host authentication.

The no form of the command removes the string from the configuration.

Default 

no sla-profile-string

Parameters 
string—
Specifies the string to use to look up the subscriber profile.

sub-profile-string

Syntax 
sub-profile-string string
no sub-profile-string
Context 
config>subscr-mgmt>vrgw>brg>brg-profile
Description 

This string is used as a default for subscriber-profile lookup. This string can be overridden during BRG or host authentication. The no form of the command removes the string from the configuration.

Default 

no sub-profile-string

Parameters 
string—
Specifies the string used to look up the subscriber profile.

11.25.2.1.3. ISA Commands

isa-filter

Syntax 
isa-filter name [type {dsm}] [create]
no isa-filter name
Context 
config>subscr-mgmt
Description 

This command enables the context to configure ISA filter parameters.

Parameters 
name
Specifies the name of the filter
type dsm
Selects DSM as the type.

default-action

Syntax 
default-action {drop | forward}
no default-action
Context 
config>subscr-mgmt>isa-filter
config>subscr-mgmt>isa-filter>ipv6
Description 

This command specifies what should happen to packets that do not match any of the configured entries.

The no form of the command reverts to the default value.

Default 

default-action drop

Parameters 
drop
Specifies that packets matching the filter entry are dropped.
forward
Specifies that packets matching the filter entry are forwarded.

entry

Syntax 
entry entry-id [create]
no entry entry-id
Context 
config>subscr-mgmt>isa-filter
config>subscr-mgmt>isa-filter>ipv6
Description 

This command creates a new entry for this filter. When processing a packet, entries are matched in order, starting with the lowest entry-id. A maximum of 128 IPv4 and 128 IPv6 DSM filter entries are allowed.

The no form of the command removes the specified entry from the ISA filter.

Parameters 
entry-id
Specifies the numeric identifier for the filter entry.

action

Syntax 
action {drop | forward | none}
no action
Context 
config>subscr-mgmt>isa-filter>entry
config>subscr-mgmt>isa-filter>ipv6>entry
Description 

This command specifies what should happen to packets that do match this entry. If the configured action is none, this entry is not applied and processing continues to match against subsequent entries.

The no form of the command reverts to the default value.

Default 

action none

Parameters 
drop
Drops the packet.
forward
Forwards the packet.
none
Disables this entry. The packet processing continues with the next entry.

match

Syntax 
match protocol {any | icmp | tcp | upd | gre}
no match
Context 
config>subscr-mgmt>entry
config>subscr-mgmt>ipv6>entry
Description 

This command creates a match context for this entry. The protocol value specifies which Layer-4 protocol the packet should match.

The no form of the command removes the match context of this entry.

Default 

match protocol any

Parameters 
protocol
Specifies that the only supported match context is protocol.
any
Specifies to match any protocol.
icmp
Specifies to match ICMP packets in a v4 filter.
tcp
Specifies to match TCP packets.
udp
Specifies to match UDP packets.
gre
Specifies to match GRE over IP packets.

dst-port

Syntax 
dst-port operator port-number
no dst-port
Context 
config>subscr-mgmt>isa-filter>entry>match
config>subscr-mgmt>isa-filter>ipv6>entry>match
Description 

This command specifies that the packet’s UDP/TCP dst-port must match a specific value. This command is not valid in a match context that is not specific to UDP or TCP.

The no form of the command removes matching of the layer-4 port.

Default 

no dst-port

Parameters 
operator
Specifies that the only supported value is eq (equal to). The destination port value must be equal to the port-number value.
port-number
Specifies the number of the port to match.
Values—
0 to 65535

 

dst-ip

Syntax 
dst-ip ip-prefix/length
no dst-ip
Context 
config>subscr-mgmt>isa-filter>entry
config>subscr-mgmt>isa-filter>ipv6>entry
Description 

This command specifies that the packet’s destination IP address must match the specified IP prefix and mask.

The no form of the command disables the match on the destination IP.

Default 

no dst-ip

Parameters 
ip-prefix/length
Specifies the IP prefix to match.

src-ip

Syntax 
src-ip ip-prefix/length
no src-ip
Context 
config>subscr-mgmt>isa-filter>entry>match
config>subscr-mgmt>isa-filter>ipv6>entry>match
Description 

This command configures the source IP or IPv6 address match condition.

The no form of the command reverts to the default value.

Default 

no src-ip

src-port

Syntax 
src-port operator port-number
no src-port
Context 
config>subscr-mgmt>isa-filter>entry>match
config>subscr-mgmt>isa-filter>ipv6>entry>match
Description 

This command configures the source port match condition.

The no form of the command reverts to the default value.

Default 

no src-port

cbs

Syntax 
cbs burst-size
no cbs
Context 
config>subscr-mgmt>isa-policer
Description 

This command specifies the committed burst-size value of this policer. This can only be set on dual-bucket-bandwidth policers.

The no form of this command reverts to its default.

Default 

cbs 0

Parameters 
burst-size —
Specifies the committed burst-size in kbytes.
Values—
0 to 131071

 

mbs

Syntax 
mbs burst-size
no mbs
Context 
config>subscr-mgmt>isa-policer
Description 

This command specifies the maximum burst-size value of this policer.

The no form of this command reverts to its default.

Default 

mbs 0

Parameters 
burst-size —
The maximum burst-size in kbytes.
Values—
0 to 131071

 

rate

Syntax 
rate rate [cir cir-rate]
no rate
Context 
config>subscr-mgmt>isa-policer
Description 

This command specifies at which rate the policer drains packets. The cir value is only supported on dual-bucket-bandwidth policers. If rate max is configured, no actual rate limitations are applied.

The no form of this command reverts to the default.

Default 

no rate

Parameters 
rate —
Specifies the rate in Kbps.
Values—
1 to 100000000, max

 

Default—
max
cir-rate —
Specifies the CIR rate in Kbps.
Values—
1 to 100000000, max

 

Default—
max

isa-policer

Syntax 
isa-policer policer-name [type policer-type] [create]
no isa-policer policer-name
Context 
config>subscr-mgmt
Description 

This command creates the context to configure an ISA policer. When creating a policer for the first time, both the create and type parameters are required.

The no form of this command removes the.

Parameters 
policer-name —
Specifies the name by which this policer is referenced up to 32 characters.
policer-type
Specifies the policer type. The dual-bucket-bandwidth policer applies both a CIR and PIR.
Values—
single-bucket-bandwidth, dual-bucket-bandwidth

 

action

Syntax 
action {permit-deny | priority-mark}
no action
Context 
config>subscr-mgmt>isa-policer
Description 

This command specifies what happens to packets that are in-profile and out-of-profile.

The no form of the command reverts to the default value.

Default 

action permit-deny

Parameters 
permit-deny
Drops all packets that are out of profile (they do not conform to the PIR).
priority-mark
Currently not supported. The policer will take no action.

adaptation-rule

Syntax 
adaptation-rule pir adaptation-rule [cir adaptation-rule]
no adaptation-rule
Context 
config>subscr-mgmt>isa-policer
Description 

For operational efficiency, the operational rate of a policer cannot take on every value in the configurable range. This configuration defines a rule that must be followed when mapping a configured rate to an operational rate.

The cir adaptation-rule can only be set on dual-bucket-bandwidth policers.

The no form of this command reverts to its default.

Default 

adaptation-rule pir closest cir closest

Parameters 
pir adaptation-rule—
Configures the rules to compute the PIR operational rates.
Values—
min — Specifies that the operational rate must minimally be the configured rate. The first operational value bigger or equal to the configured rate is chosen.
max — Specifies that the operational rate may maximally be the configured rate. The first operational value smaller or equal to the configured rate is chosen.
closest — Chooses the operational value closest to the configured value, lower or higher.

 

cir adaptation-rule
Configures the rules to compute the CIR operational rates.
Values—
adaptation-rule

 

11.25.2.1.4. RADIUS Server Policy Commands

acct-on-off-group

Syntax 
acct-on-off-group group-name [create]
no acct-on-off-group group-name
Context 
config>aaa
Description 

This command creates an acct-on-off-group.

An acct-on-off-group can be referenced by:

  1. A single radius-server-policy as controller — The acct-on-off oper-state of the acct-on-off-group is set to the acct-on-off oper-state of the radius-server-policy (acts as master).
  2. Multiple radius-server-policies as monitor — The acct-on-off oper-state of the radius-server-policy is inherited from the acct-on-off oper-state of the acct-on-off group. (acts as a slave).

The no form of the command deletes the acct-on-off-group.

Parameters 
group-name—
Specifies the name of an acct-on-off group up to 32 characters.

radius-server-policy

Syntax 
radius-server-policy policy-name [create]
no radius-server-policy policy-name
Context 
config>aaa
Description 

This command creates a radius-server-policy.

A RADIUS server policy can be used in

  1. radius-proxy, for application like EAP authentication for WIFI access
  2. authentication policy, for Enhanced Subscriber Management authentication
  3. radius accounting policy, for Enhanced Subscriber Management accounting
  4. dynamic data service RADIUS accounting
  5. AAA route downloader

The no form of the command removes the policy name from the configuration.

Parameters 
policy-name—
Specifies the name of the radius-server-policy up to 32 characters.
create—
Keyword used to create a radius-server-policy name. The create keyword requirement can be enabled/disabled in the environment>create context.

accept-script-policy

Syntax 
accept-script-policy policy-name
no accept-script-policy
Context 
config>aaa>radius-srv-plcy
Description 

This command specifies name of the radius-script-policy to be applied for access-accept.

Default 

no accept-script-policy

Parameters 
policy-name—
Specifies the name of the accept-script-policy up to 32 characters.

acct-on-off

Syntax 
acct-on-off
acct-on-off monitor-group group-name
acct-on-off oper-state-change [group group-name]
Context 
config>aaa>radius-srv-plcy
Description 

This command controls the sending of Accounting-On and Accounting-Off messages and the acct-on-off oper-state of the radius-server-policy:

acct-on-off: enables the sending of Accounting-On and Accounting-Off messages for this radius-server-policy. The acct-on-off oper-state is always not blocked.

acct-on-off oper-state-change [group group-name]: enables the sending of Accounting-On and Accounting-Off messages for this radius-server-policy. The acct-on-off oper-state is function of the Accounting-response received for the Accounting-On and Accounting-Off. Optionally, sets the acct-on-off oper-state of the acct-on-off-group.

acct-on-off monitor-group group-name: no Accounting-On and Accounting-Off messages are sent for this radius-server-policy. The acct-on-off oper-state is inherited from the acct-on-off-group.

The no form of the command disables the sending of Accounting-On and Accounting-Off messages.

Default 

no acct-on-off

Parameters 
group-name—
Specifies the name of an acct-on-off group up to 32 characters.

acct-request-script-policy

Syntax 
acct-request-script-policy policy-name
no acct-request-script-policy
Context 
config>aaa>radius-srv-plcy
Description 

This command specifies the name of the acct-request-script-policy pointing to the Python script to be applied for RADIUS accounting request messages.

Default 

no acct-request-script-policy

Parameters 
policy-name—
Specifies the name of the acct-request-script-policy up to 32 characters.

auth-request-script-policy

Syntax 
auth-request-script-policy policy-name
no auth-request-script-policy
Context 
config>aaa>radius-srv-plcy
Description 

This command specifies the name of the auth-request-script-policy pointing to the Python script to be applied for RADIUS access request messages.

Default 

no auth-request-script-policy

Parameters 
policy-name—
Specifies the name of the auth-request-script-policy up to 32 characters

buffering

Syntax 
[no] buffering
Context 
config>aaa>radius-srv-plcy
Description 

This command enables the context to configure RADIUS message buffering.

The no form of the command disables RADIUS message buffering.

acct-interim

Syntax 
acct-interim min min-val max max-val lifetime lifetime
no acct-interim
Context 
config>aaa>radius-srv-plcy>servers>buffering
Description 

This command enables RADIUS accounting interim update message buffering.

  1. The message is stored in the buffer, a lifetime timer is started and the message is sent to the RADIUS server
  2. If after retry*timeout seconds no RADIUS accounting response is received for the interim update then a new attempt to send the message is started after minimum[(min-val*2n), max-val] seconds.
  3. Repeat step 2 until for one of the following:
    1. a RADIUS accounting response is received.
    2. the lifetime of the buffered message expires.
    3. a new RADIUS accounting interim-update or a RADIUS accounting stop for the same accounting session-id and radius-server-policy is stored in the buffer.
    4. the message is manually purged from the message buffer via a clear command.
  4. The message is purged from the buffer.

The no form of the command disables RADIUS accounting interim update message buffering.

Default 

no acct-interim

Parameters 
min-val—
Specifies the minimum interval in seconds between attempts to resend the RADIUS accounting interim update.
Values—
1 to 3600

 

max-val—
Specifies the maximum interval in seconds between attempts to resend the RADIUS accounting interim update.
Values—
1 to 3600

 

lifetime—
Specifies the lifetime in hours.
Values—
1 to 25

 

acct-stop

Syntax 
acct-stop min min-val max max-val lifetime lifetime
no acct-stop
Context 
config>aaa>radius-srv-plcy>servers>buffering
Description 

This command enables RADIUS accounting stop message buffering.

  1. The message is stored in the buffer, a lifetime timer is started and the message is sent to the RADIUS server
  2. If after retry*timeout seconds no RADIUS accounting response is received for the accounting stop, then a new attempt to send the message is started after minimum[(min-val*2n), max-val] seconds.
  3. Repeat step 2 until
    1. a RADIUS accounting response is received, or
    2. the lifetime of the buffered message expires, or
    3. the message is manually purged from the message buffer via a clear command
  4. The message is purged from the buffer.

The no form of the command disables RADIUS accounting stop message buffering.

Default 

no acct-stop

Parameters 
min-val—
Specifies the minimum interval in seconds between attempts to resend the RADIUS accounting stop.
Values—
1 to 3600

 

max-val—
Specifies the maximum interval in seconds between attempts to resend the RADIUS accounting stop.
Values—
1 to 3600

 

lifetime—
Specifies the lifetime in hours.
Values—
1 – 25

 

servers

Syntax 
servers
Context 
config>aaa>radius-srv-plcy
Description 

This command enables the context to configure radius-server-policy parameters.

access-algorithm

Syntax 
access-algorithm {direct | round-robin | hash-based}
no access-algorithm
Context 
config>aaa>radius-srv-plcy>servers
Description 

This command configures the algorithm used to select a RADIUS server from the pool of configured RADIUS servers.

Default 

access-algorithm direct

Parameters 
direct—
Specifies that the first server is used as primary server for all requests, the second as secondary and so on.
round-robin—
Specifies that the first server is used as primary server for the first request, the second server as primary for the second request, and so on. If the router gets to the end of the list, it starts again with the first server.
hash-based—
Select a RADIUS server based on the calculated hash result of the configured load-balance-key under the radius-proxy server hierarchy. This parameter is only applicable for radius-proxy server scenarios and results in an unpredictable RADIUS server selection if used in other scenarios.

disable-stickiness

Syntax 
[no] disable-stickiness
Context 
config>aaa>radius-srv-plcy>servers
Description 

This command disables a subscriber RADIUS accounting session from sticking with a single server under normal working conditions. If a direct algorithm is used, all subscriber RADIUS sessions will go directly to the server with the lowest configured index. If a failure occurs, a new in-service server with the next lowest index is used. When the original server recovers, if stickiness is not disabled, all existing sessions will continue to use the new server. This command disables stickiness, and as a result, the recovered original RADIUS server will again service every subscriber. If a round-robin algorithm is used and stickiness is not disabled, an accounting session for a particular subscriber (or host, depending on the accounting mode) will stay with the same server. This command removes the stickiness and all subscriber accounting messages will go through the list of servers in a round-robin manner.

Default 

no disable-stickiness

health-check

Syntax 
health-check
Context 
config>aaa>radius-server-policy>servers
Description 

This command enables the context to configure health check parameters for the RADIUS server.

test-account

Syntax 
test-account
Context 
config>aaa>radius-srv-plcy>servers>health-check
Description 

This command sets up a test account as a probing mechanism to check the connectivity of all configured RADIUS authentication servers within the RADIUS server policy.

interval

Syntax 
interval seconds
no interval
Context 
config>aaa>radius-srv-plcy>servers>health-check>test-account
Description 

This command specifies the intervals at which the test account will send its access requests to probe the RADIUS servers.

Default 

interval 3

Parameters 
seconds—
Specifies the probing interval.
Values—
1 to 60

 

password

Syntax 
password password [hash | hash2]
no password
Context 
config>aaa>radius-srv-plcy>servers>health-check>test-account
config>subscr-mgmt>vrgw>brg>brg-profile>radius-authentication
Description 

This command specifies the password that the test account will use to send access requests to probe the RADIUS servers.

Default 

no password

Parameters 
password—
Specifies the probing password up to 64 characters
hash—
Specifies the key is entered in an encrypted form. If the hash or hash2 parameter is not used, the key is assumed to be in an unencrypted, clear text form. For security, all keys are stored in encrypted form in the configuration file with the hash or hash2 parameter specified.
hash2—
Specifies the key is entered in a more complex encrypted form that involves more variables than the key value alone, meaning that the hash2 encrypted variable cannot be copied and pasted. If the hash or hash2 parameter is not used, the key is assumed to be in an unencrypted, clear text form. For security, all keys are stored in encrypted form in the configuration file with the hash or hash2 parameter specified.

shutdown

Syntax 
[no] shutdown
Context 
config>aaa>radius-srv-plcy>servers>health-check>test-account
Description 

This command disables the test account that probes the RADIUS server.

The no form of the command enables the capability.

Default 

shutdown

user-name

Syntax 
user-name user-name
no user-name
Context 
config>aaa>radius-srv-plcy>servers>health-check>test-account
Description 

This command specifies the username that the test account will use to send its access requests to probe the RADIUS servers.

The no form of the command removes the username from the test-account configuration.

Default 

no user-name

Parameters 
user-name—
Specifies the probing username up to 64 characters.

retry

Syntax 
retry count
no retry
Context 
config>aaa>radius-srv-plcy>servers
Description 

This command configures the number of times the router attempts to contact the RADIUS server, if not successful the first time.

The no form of the command reverts to the default.

Default 

retry 3

Parameters 
count—
Specifies the number of times a signaling request message is transmitted towards the same peer.
Values—
1 to 256

 

router

Syntax 
router router-instance
router service-name service-name
no router
Context 
config>aaa>radius-srv-plcy>servers
Description 

This command specifies the virtual router instance applicable for the set of configured RADIUS servers. This value cannot be changed once a RADIUS server is configured for this policy.

The no form of the command reverts to the default.

Default 

no router

Parameters 
router-instance —
Specifies the router instance.
Values—

service-name

Service name up to 64 characters.

router-instance:

router-name, service-id

router-name:

Base, management

service-id:

1 to 2147483647

 

service-name—
Specifies the router name service-id up to 64 characters.

server

Syntax 
server server-index name server-name
no server server-index
Context 
config>aaa>radius-srv-plcy>servers
Description 

This command adds a RADIUS server.

The no form of the command removes a RADIUS server.

Parameters 
index—
The index for the RADIUS server. The index determines the sequence in which the servers are queried for authentication requests. Servers are queried in order from lowest to highest index.
Values—
1 to 5

 

server-name—
Specifies the server name up to 32 characters.

source-address

Syntax 
source-address ip-address
no source-address
Context 
config>aaa>radius-srv-plcy>servers
Description 

This command configures the source address of the RADIUS packet. The system IP address must be configured in order for the RADIUS client to work. See Configuring a System Interface in the 7750 SR OS Configuration Guide.

Note:

The system IP address must only be configured if the source-address is not specified. When the no source-address command is executed, the source address is determined at the moment the request is sent. This address is also used in the nas-ip-address attribute: over there it is set to the system IP address if no source-address was given.

The no form of the command reverts to the default value.

Default 

no source-address

Parameters 
ip-address—
Specifies the source address of radius packet.

timeout

Syntax 
timeout [sec seconds] [min minutes]
no timeout
Context 
config>aaa>radius-srv-plcy>servers
Description 

This command configures the time the router waits for a response from a RADIUS server.

The no form of the command reverts to the default value.

Default 

timeout sec 5

Parameters 
seconds—
Specifies the number of seconds for the timeout.
Values—
1 to 59

 

minutes—
Specifies the number of minutes for the timeout.
Values—
1 to 5

 

Values—
Max. value = 5 min 40 sec

 

hold-down-time

Syntax 
hold-down-time [sec seconds] [min minutes] [hrs hours] [days days]
no hold-down-time
Context 
config>aaa>radius-srv-plcy>servers
Description 

This command configures the hold time before re-using a RADIUS server.

The no form of the command reverts to the default value.

Default 

hold-down-time sec 30

Parameters 
seconds—
Specifies the number of seconds for the hold down time.
Values—
1 to 59

 

minutes —
Specifies the number of minutes for the hold down time.
Values—
1 to 59

 

hours—
Specifies the number of hours for the hold down time.
Values—
1 to 23

 

days —
Specifies the number of days for the hold down time.
Values—
1 to 1

 

ipv6-source-address

Syntax 
ipv6-source-address ipv6-address
no ipv6-source-address
Context 
config>aaa>radius-srv-plcy>servers
Description 

This command configures the source address of an IPv6 RADIUS packet.

When no ipv6-source-address is configured, the system IPv6 address (inband RADIUS server connection) or Boot Option File (BOF) IPv6 address (outband RADIUS server connection) must be configured in order for the RADIUS client to work with an IPv6 RADIUS server.

This address is also used in the NAS-IPv6-Address attribute.

The no form of the command reverts to the default value.

Default 

no ipv6-source-address

Parameters 
ipv6-address—
Specifies the source address of an IPv6 RADIUS packet.

11.25.2.2. CLI Command Description for RADIUS Server

radius-server

Syntax 
radius-server
Context 
config>router
config>service>vprn
Description 

This command enters the radius-server configuration context under router or VPRN service.

server

Syntax 
server server-name [address ip-address] [secret key] [hash | hash2] [create]
no server server-name
Context 
config>router>radius-server
config>service>vprn>radius-server
Description 

This command either specifies an external RADIUS server in the corresponding routing instance or enters configuration context of an existing server. The configured server could be referenced in the radius-server-policy.

The no form of the command removes the parameters from the server configuration.

Parameters 
server-name—
Specifies the name of the external RADIUS server.
ip-address
Specifies the IPv4 or IPv6 IP address of the external RADIUS server.
key
Specifies the shared secret key of the external RADIUS server, up to 64 characters.
hash—
Specifies the key is entered in an encrypted form. If the hash or hash2 parameter is not used, the key is assumed to be in an unencrypted, clear text form. For security, all keys are stored in encrypted form in the configuration file with the hash or hash2 parameter specified.
hash2—
Specifies the key is entered in a more complex encrypted form that involves more variables than the key value alone, meaning that the hash2 encrypted variable cannot be copied and pasted. If the hash or hash2 parameter is not used, the key is assumed to be in an unencrypted, clear text form. For security, all keys are stored in encrypted form in the configuration file with the hash or hash2 parameter specified.

accept-coa

Syntax 
[no] accept-coa
Context 
config>router>radius-server>server
config>service>vprn>radius-server>server
Description 

This command configures this server for Change of Authorization messages. The system will process the CoA request from the external server if configured with this command; otherwise the CoA request is dropped.

The no form of the command disables the command.

Default 

no accept-coa

acct-port

Syntax 
acct-port port
no acct-port
Context 
config>router>radius-server>server
config>service>vprn>radius-server>server
Description 

This command specifies the UDP listening port for RADIUS accounting requests.

The no form of the commands resets the UDP port to its default value (1813)

Default 

acct-port 1813

Parameters 
port—
Specifies the UDP listening port for accounting requests of the external RADIUS server.
Values—
1 to 65535

 

auth-port

Syntax 
auth-port port
no auth-port
Context 
config>router>radius-server>server
config>service>vprn>radius-server>server
Description 

This command specifies the UDP listening port for RADIUS authentication requests.

The no form of the commands resets the UDP port to its default value (1812)

Default 

auth-port 1812

Parameters 
port—
Specifies the UDP listening port for accounting requests of the external RADIUS server.
Values—
1 to 65535

 

coa-script-policy

Syntax 
coa-script-policy policy-name
no coa-script-policy
Context 
config>router>radius-server>server
config>service>vprn>radius-server>server
Description 

This command specifies radius-script-policy for CoA-Request sent from this RADIUS server.

The no form of the command removes the policy name from the configuration.

Default 

no coa-script-policy

Parameters 
policy-name—
Specifies the name of radius-script-policy up to 80 characters.

pending-requests-limit

Syntax 
pending-request-limit limit
no pending-request-limit
Context 
config>router>radius-server>server
config>service>vprn>radius-server>server
Description 

This command specifies the per-server maximum number of outstanding requests sent to the RADIUS server. If the maximum number is exceeded, the next RADIUS server in the pool is selected.

The no form of the command removes the limit value from the configuration.

Default 

pending-requests-limit 4096

Parameters 
limit —
Specifies the maximum number of outstanding requests sent to the RADIUS server.
Values—
1 to 4096

 

11.25.2.3. CLI Command Description for RADIUS Proxy Server

radius-proxy

Syntax 
radius-proxy
Context 
config>router
config>service>vprn
Description 

This command context to configure RADIUS proxy parameters.

server

Syntax 
server server-name [create] [purpose {[accounting | authentication]}] [wlan-gw-group group-id]
no server server-name
Context 
config>router>radius-proxy
config>service>vprn>radius-proxy
Description 

This command creates a RADIUS-proxy server in the corresponding routing instance. The proxy server can be configured for the purpose of proxying authentication or accounting or both.

If a WLAN-GW ISA group is specified, then the RADIUS proxy server is instantiated on the set of ISAs in the specified wlan-gw group. The RADIUS messages from the AP are load-balanced to these ISAs. The ISA that processes the RADIUS message then hashes this message to the ISA that anchors the UE. The hash is based on UE MAC address (required to be present in the calling-station-id attribute) in the RADIUS message.

If the create parameter is not specified, then this command enters configuration context of the specified RADIUS-proxy server.

The no form of the command removes the server-name and parameters from the radius-proxy configuration.

Default 

purpose authentication

Parameters 
server-name—
Specifies the name of the RADIUS-proxy server.
create—
Specifies that the system will create the specified RADIUS-proxy server.
purpose —
Specifies the purpose the RADIUS-proxy server.
Values—
accounting — proxy accounting packets
authentication — proxy authentication packets
both — Specifies both accounting and authentication proxy accounting packets

 

group-id
Specifies the WLAN-GW ISA group.

attribute-matching

Syntax 
attribute-matching
Context 
config>router>radius-proxy>server
config>service>vprn>radius-proxy>server
Description 

This command enables the context for selecting the RADIUS policy for authentication and accounting based on the RADIUS attribute. This feature is supported for both the ESM RADIUS proxy and the ISA RADIUS proxy.

entry

Syntax 
entry [entry] [prefix-string prefix-string] [accounting-server-policy policy-name] [authentication-server-policy policy-name] [suffix-string suffix-string]
no entry [entry]
Context 
config>router>radius-proxy>server>attribute-matching
config>service>vprn>radius-proxy>server>attribute-matching
Description 

This command matches the specified prefix or suffix string with the selected accounting server policy or authentication server policy.

Parameters 
entry—
Specifies an entry ID.
Values—
1 to 32

 

prefix-string—
Specifies the prefix string for matching up to 128 characters. If the suffix-string is also used, the combined length cannot exceed 126 characters.
suffix-string—
Specifies the suffix string for matching up to 126 characters. If the prefix-string is also used, the combined length cannot exceed 126 characters.
policy-name—
Specifies the RADIUS accounting or authentication policy up to 32 characters.

type

Syntax 
type [type] [vendor-id vendor-id]
no type
Context 
config>router>radius-proxy>server>attribute-matching
config>service>vprn>radius-proxy>server>attribute-matching
Description 

This command specifies the RADIUS VSA type for the entries to be matched with.

Default 

no type

Parameters 
type
Specifies the RADIUS server policy matching attribute-type and vendor-id.
Values—
1 to 255

 

vendor-id—
Specifies the vendor ID number.
Values—
1 to 16777215, nokia

 

cache

Syntax 
cache
Context 
config>router>radius-proxy>server
config>service>vprn>radius-proxy>server
Description 

This command enters the cache configuration context under radius-proxy server. The cache contains per-subscriber authentication information learned from RADIUS authentication messages, and is used to authorize subsequent DHCP requests.

default-accounting-server-policy

Syntax 
default-accounting-server-policy policy-name
no default-accounting-server-policy
Context 
config>router>radius-proxy>server
config>service>vprn>radius-proxy>server
Description 

This command specifies the default radius-server-policy for RADIUS accounting. This policy is used when there is no specific match based on username.

The no form of the command removes the policy name from the configuration.

Default 

no default-accounting-server-policy

Parameters 
policy-name—
Specifies the name of the default RADIUS server policy associated with this RADIUS Proxy server for accounting purposes.

default-authentication-server-policy

Syntax 
default-authentication-server-policy policy-name
no default-authentication-server-policy
Context 
config>router>radius-proxy>server
config>service>vprn>radius-proxy>server
Description 

This command specifies the default radius-server-policy for RADIUS authentication. This policy is used when there is no specific match based on username.

The no form of the command removes the policy name from the configuration.

Default 

no default-authentication-server-policy

Parameters 
policy-name—
Specifies the name of the default RADIUS server policy associated with this RADIUS proxy server for authentication purposes.

interface

Syntax 
[no] interface ip-int-name
Context 
config>router>radius-proxy>server
config>service>vprn>radius-proxy>server
Description 

This command configures the IP interface the RADIUS-proxy server will bind to. One RADIUS-proxy server could bind to multiple interfaces.

Parameters 
ip-int-name—
Specifies the name of an IP interface.

load-balance-key

Syntax 
load-balance-key [vendor vendor-id [vendor-id]] attribute-type attribute-type [attribute-type]
load-balance-key source-ip-udp
no load-balance-key
Context 
config>router>radius-proxy>server
config>service>vprn>radius-proxy>server
Description 

This command specifies the key used in calculating a hash to select an external RADIUS server from the pool of configured servers.

The key can be the source IP and source UDP port tuple, or the specified RADIUS attribute in RADIUS packets.

The no form of the command removes the parameters from the configuration.

Default 

no load-balance-key

Parameters 
vendor-id
Specifies the vendor-id of vendor-specific attribute
Values—
0 to 16777215

 

attribute-type
Specifies that the key is constructed with the attributes in the RADIUS message.
Values—
1 to 255

 

source-ip-udp—
Specifies that the key consists of the source IP address and source UDP port of the RADIUS message.

python-policy

Syntax 
python-policy name
no python-policy
Context 
config>router>radius-proxy>server
Description 

This command specifies the Python policy used to change the RADIUS attributes of the different RADIUS messages.

The no form of the command removes the name from the configuration.

Default 

no python-policy

Parameters 
name—
Specifies the Python policy name up to 32 characters.

secret

Syntax 
secret secret [hash | hash2]
no secret
Context 
config>router>radius-proxy>server
config>service>vprn>radius-proxy>server
Description 

This command configures the shared secret key. The RADIUS client must have the same key to communicate with the RADIUS-proxy server.

The no form of the command removes the parameters from the configuration.

Default 

no secret

Parameters 
secret key
Specifies the secret key up to 20 characters to access the RADIUS server. This secret key must match the password on the RADIUS server.
Values—
hash-key: Up to 33 characters
hash2-key: Up to 55 characters.

 

hash—
Specifies that the key is entered in an encrypted form. If the hash or hash2 parameter is not used, the key is assumed to be in an unencrypted, clear text form. For security, all keys are stored in encrypted form in the configuration file with the hash or hash2 parameter specified,
hash2—
Specifies that the key is entered in a more complex encrypted form that involves more variables than the key value alone, meaning that the hash2 encrypted variable cannot be copied and pasted. If the hash or hash2 parameter is not used, the key is assumed to be in an unencrypted, clear text form. For security, all keys are stored in encrypted form in the configuration file with the hash or hash2 parameter specified.

send-accounting-response

Syntax 
[no] send-accounting-response
Context 
config>router>radius-proxy>server
config>service>vprn>radius-proxy>server
Description 

This command results in the system to always generate RADIUS accounting-response to acknowledge RADIUS accounting-request received from the RADIUS client.

The no form of the command disables the command.

Default 

no send-accounting-response

key

Syntax 
key packet-type {accept | request} attribute-type attribute-type [vendor vendor-id]
no key
Context 
config>router>radius-proxy>server>cache
config>service>vprn>radius-proxy>server>cache
Description 

This command specifies the RADIUS cache key that is used to match the information in subsequent DHCP requests for authorization.

Default 

no key

Parameters 
packet-type—
Specifies the packet type of the RADIUS messages to use to generate the key for the cache of this RADIUS proxy server.
Values—
accept, request

 

attribute-type
Specifies the RADIUS attribute type to cache for this RADIUS proxy. server.
Values—
1 to 255

 

vendor vendor-id
Specifies the RADIUS vendor ID.
Values—
1 to 16777215, nokia

 

timeout

Syntax 
timeout [hrs hours] [min minutes] [sec seconds]
no timeout
Context 
config>router>radius-proxy>server>cache
config>service>vprn>radius-proxy>server>cache
Description 

This command configures the time for which the cache entry is kept if there is no corresponding DHCP DISCOVER. At the expiry of this time, the cache entry is deleted.

The no form of the command reverts to the default value.

Default 

timeout min 5

Parameters 
hours
Specifies, in hours, the timeout after which an entry in the cache will expire.
Values—
1

 

minutes
Specifies, in minutes, the timeout after which an entry in the cache will expire.
Values—
1 to 59

 

seconds
Specifies, in seconds, the timeout after which an entry in the cache will expire.
Values—
1 to 59

 

track-accounting

Syntax 
track-accounting [start] [stop][interim-update][accounting-on] [accounting-off]
no track-accounting
Context 
config>router>radius-proxy>server>cache
config>service>vprn>radius-proxy>server>cache
Description 

This command specifies the type of RADIUS accounting packets from RADIUS client (a WIFI AP) that the router should track.

The no form of the command removes the parameters from the configuration.

Default 

no track-accounting

Parameters 
start—
Specifies that the router will update the associated ESM-host with the RADIUS client (for example, a WIFI AP) that generated the accounting-start. This is required in cases where a UE roams to a new AP that does not re-authenticate due to key caching.
stop—
Specifies that the router will remove the corresponding ESM host and forward the accounting-stop packet to the external RADIUS server.
accounting-on | accounting-off—
Specifies that the router will remove all ESM hosts associated with the RADIUS client (a WIFI AP), and forward the accounting-on packet to the external RADIUS server.
interim-update—
Specifies that the router will update the associated ESM-host with the RADIUS client (a WIFI AP) that generated the interim-update. The interim-updates with the updated information are sent to the RADIUS server as scheduled.

track-authentication

Syntax 
track-authentication [accept]
no track-authentication
Context 
config>router>radius-proxy>server>cache
config>service>vprn>radius-proxy>server>cache
Description 

This command specifies if RADIUS authentication (from the AP) should be tracked in order to update the ESM host with the RADIUS client (for example, WIFI AP) on UE mobility. It also specifies the authentication packet from RADIUS client (for example, a WIFI AP) that the router should track for mobility.

The no form of this command stops tracking authentication for UE mobility.

Default 

track-authentication accept

Parameters 
accept —
Indicates access-accept is tracked for mobility.

track-delete-hold-time

Syntax 
track-delete-hold-time seconds
no track-delete-hold-time
Context 
config>router>radius-proxy>server>cache
Description 

This command specifies the delete hold-time in case the DHCP host gets a trigger to delete from the matched RADIUS Proxy server.

The no form of the command reverts to the default.

Default 

track-delete-hold-time 0

Parameters 
seconds—
Specifies the delete hold time, in seconds.
Values—
0 to 600

 

11.25.2.4. LUDB Matching of RADIUS Proxy Cache Commands

local-user-db

Syntax 
local-user-db local-user-db-name [create]
no local-user-db local-user-db-name
Context 
config>subscr-mgmt
Description 

This command enables the context to configure a local user database.

The no form of the command removes the local user database name from the configuration.

Parameters 
local-user-db-name —
Specifies the name of a local user database up to 32 characters.

dhcp

Syntax 
dhcp
Context 
config>subscr-mgmt>loc-user-db
Description 

This command configures DHCP host parameters.

host

Syntax 
host
Context 
config>subscr-mgmt>loc-user-db
Description 

This command enables the context to configure DHCP host parameters.

match-radius-proxy-cache

Syntax 
match-radius-proxy-cache
Context 
config>subscr-mgmt>loc-user-db>ipoe>host
Description 

This command enables the context to configure match-radius-proxy-cache parameters.

fail-action

Syntax 
fail-action {continue | drop}
no fail-action
Context 
config>subscr-mgmt>loc-user-db>ipoe>host>match-radprox-cache
Description 

This command specifies the router’s action when failed to find matched radius-proxy-server cache entry.

The no form of the command reverts to the default.

Default 

fail-action drop

Parameters 
continue—
Specifies that the will proceed with ESM authentication without dropping the DHCP packet.
drop—
Specifies that the router will drop the DHCP packet.

mac-format

Syntax 
mac-format format
no mac-format
Context 
config>subscr-mgmt>loc-user-db>ipoe>host>match-radprox-cache
Description 

This command specifies the format of MAC address used for matching incoming DHCP DISCOVER against the RADIUS proxy cache.

The no form of the command reverts to the default.

Default 

mac-format "aa:"

Parameters 
format—
Specifies the format string that specifies the format of MAC address.
Values—

mac-format: (only when match is equal to mac)

like ab: for 00:0c:f1:99:85:b8

or XY- for 00-0C-F1-99-85-B8

or mmmm. for 0002.03aa.abff

or xx for 000cf19985b8

 

match

Syntax 
match {circuit-id | mac | remote-id}
match option [option] [option6 [option6]]
match option6 [option6]
no match
Context 
config>subscr-mgmt>loc-user-db>ipoe>host>match-radprox-cache
Description 

This command specifies the field/option of DHCP packet that is used to match against the radius-proxy-server cache.

The no form of the command reverts to the default.

Default 

match mac

Parameters 
circuit-id—
Specifies to match the circuit-id in DHCP option82.
remote-id—
Specifies to match the remote

-id in DHCP option82.

mac—
Specifies to match the MAC address of DHCP client
option
Specifies to use the specified DHCP option.
Values—
1 to 254

 

option6
Specifies to use the specified DHCP option.
Values—
1 to 65535

 

number
Specifies the DHCPv6 option to retrieve the value to be used as lookup key in the RADIUS Proxy cache
Values—
1 to 65535

 

server

Syntax 
server [service service-id] name server-name
no server
Context 
config>subscr-mgmt>loc-user-db>ipoe>host>match-radprox-cache
Description 

This command specifies the name of radius-proxy-server and optionally id of the service that the radius-proxy-server resides in.

The no form of the command removes the parameters from the configuration.

Default 

no server

Parameters 
service service-id
Specifies the ID or name of the service.
Values—
1 to 214748365
svc-name up to 64 char maximum

 

name server-name
Specifies the name of radius-proxy-server up to 32 characters.

11.25.2.5. WLAN-GW-Group Commands

wlan-gw-group

Syntax 
wlan-gw-group group-id [create] [redundancy unit]
no wlan-gw-group group-id
Context 
config>isa
Description 

This command creates a WLAN GW group that contains a set of ISAs to be used in WLAN-GW functionality. A WLAN-GW group can also be used where a NAT group is expected. The WLAN-GW group ID shares the same number space with the NAT group.

At most, one WLAN-GW group may be configured.

The optional redundancy parameter determines the provisioning and redundancy mode.

  1. IOM mode
    A whole IOM is added to the group. The IOM must be fully provisioned with BB ISA modules. In IOM mode, when a single ISA fails, the entire IOM is considered to have failed and all subscribers are recovered on a backup IOM.
  2. ISA mode
    BB ISA modules are added separately with no restriction put on other MDAs in the IOM. When a single ISA fails, a backup ISA will try to recover as many subscribers as possible but may run out of resources (for example, queues, policers, host entries) during the recovery process. It is recommended to pair ISAs with MDAs and services that do not consume many IOM resources.

The no form of this command removes the group.

Parameters 
group-id —
Specifies WLAN Gateway Integrated Service Adaptor (ISA) Groups.
Values—
1 to 4

 

unit —
Specifies the provisioning and redundancy mode.
Values—
mda or iom

 

active-iom-limit

Syntax 
active-iom-limit number
no active-iom-limit
Context 
config>isa>wlan-gw-group
Description 

This command specifies the number of WLAN-GW IOMs used as active IOMs from the total number of configured WLAN-GW IOMs. If there are more configured IOM than active-iom-limit, then the remaining number of IOMs is designated as backup(s).

The no form of the command removes the number from the configuration.

Default 

no active-iom-limit

Parameters 
number—
Specifies the number of IOMs in this WLAN Gateway ISA group that are intended for active use.
Values—
1 to 3

 

active-mda-limit

Syntax 
active-mda-limit number
no active-mda-limit
Context 
config>isa>wlan-gw-group
Description 

This command specifies how many ISAs may be in active use by the WLAN-GW group at the same time. If the maximum number of active ISAs is reached and more ISAs are added to the group, the new ISAs are considered to be in standby mode.

The no form of this command removes the limit on the maximum number of active ISAs.

Default 

no active-mda-limit

Parameters 
number—
Specifies the number of WLAN-GW ISAs intended for active use.
Values—
1 to 14

 

distributed-sub-mgmt

Syntax 
[no] distributed-sub-mgmt
Context 
config>isa>wlan-gw-group
Description 

This command configures the WLAN gateway distributed subscriber management.

isa-aa-group

Syntax 
isa-aa-group aa-group-id
no isa-aa-group
Context 
config>isa>wlan-gw-group>distributed-sub-mgmt
Description 

This command configures an ISA application assurance group for WLAN gateway DSM subscribers.

Default 

no isa-aa-group

iom

Syntax 
iom slot-number type {[load-balancer] [ue-anchor]}
no iom slot-number
Context 
config>isa>wlan-gw-group
Description 

This command designates the specified IOM as a WLAN-GW IOM. Each WLAN-GW IOM must be provisioned with two ISA-BB modules on a hardware chassis and with an ISA-BB module in the first MDA slot in the VSR.

The no form of the command removes the IOM from the configuration.

Parameters 
slot-number—
Indicates the IOM slot to be used in the WLAN-GW group.
Values—
1 to 10

 

type {[load-balancer] [ue-anchor]}
This parameter is supported on the VSR only. It determines if an IOM slot is used for load-balancing or UE anchoring and processing, or both. When the wlan-gw-group has only a single IOM, it is required to put this IOM in both modes at the same time.

mda

Syntax 
[no] mda mda-id
Context 
config>isa>wlan-gw-group
Description 

This command enables an ISA for WLAN-GW functionality.

The no form of this command removes the ISA from the WLAN-GW configuration.

Parameters 
mda-id—
Indicates the IOM and MDA slot in format slot/mda.
Values—
slot — 1 to 10
mda — 1 to 2

 

nat

Syntax 
nat
Context 
config>isa>wlan-gw-group
Description 

This command enables the context to configure NAT parameters under wlan-gw-group.

radius-accounting-policy

Syntax 
radius-accounting-policy nat-accounting-policy
no radius-accounting-policy
Context 
config>isa>wlan-gw-group>nat
Description 

This command configures the RADIUS accounting policy to use for each MDA in this ISA group.

The no form of the command removes the accounting policy from the configuration.

Default 

no radius-accounting-policy

Parameters 
nat-accounting-policy—
Specifies the RADIUS accounting policy up to 32 characters.

session-limits

Syntax 
session-limits
Context 
config>isa>wlan-gw-group>nat
Description 

This command configures the ISA NAT group session limits.

reserved

Syntax 
reserved num-sessions
no reserved
Context 
config>isa>nat>session-limits
Description 

This command configures the number of sessions per block that is reserved for prioritized sessions.

The no form of the command reverts to the default.

Default 

no reserved

Parameters 
num-sessions—
Specifies the number of sessions reserved for prioritized sessions.
Values—
0 to 4194303

 

watermarks

Syntax 
watermarks high percentage low percentage
no watermarks
Context 
config>isa>nat>session-limits
Description 

This command configures the ISA NAT group watermarks.

The no form of the command reverts to the default.

Default 

no watermarks

Parameters 
percentage
Specifies the high watermark of the number of sessions for each MDA in this NAT ISA group.
Values—
2 to 100

 

percentage—
Specifies the low watermark of the number of sessions for each MDA in this NAT ISA group.
Values—
1 to 99

 

suppress-lsn-events

Syntax 
[no] suppress-lsn-events
Context 
configure>isa>wlan-gw-group>nat
Description 

This command suppresses the generation of Large Scale NAT (LSN) events when RADIUS accounting is enabled.

By default, only one logging facility for tracking subscribers in LSN44, DS-lite, and NAT64 can be enabled at the time, either the SR OS event logging facility or the RADIUS logging facility. Note that SR OS event logs can be sent to multiple destinations, such as the console session, a telnet or SSH session, memory logs, file destinations, SNMP trap groups, and syslog destinations.

If RADIUS logging is enabled, the NAT logs are sent to the RADIUS destination and the NAT logs are suppressed in the SR OS event logging facility, for example, NAT logs are not sent to the syslog server.

If RADIUS logging is disabled, the NAT logs are sent to the SR OS event logging facility, for example, syslog, assuming that the events are enabled via the SR OS event-control (config> log>event-control nat event generate).

The no form of the command, the NAT logs can be sent to both logging facilities simultaneously, the SR OS event logging facility and RADIUS logging facility.

Default 

suppress-lsn-events

suppress-lsn-sub-blks-free

Syntax 
[no] suppress-lsn-sub-blks-free
Context 
configure>isa>wlan-gw-group>nat
Description 

This command suppresses the tmnxNatLsnSubBlksFree summary notification and use the tmnxNatPlBlockAllocationLsn notifications. When the SR OS node is in a state of excessive logging, the queue associated with the transmission of logs on the MS-ISA can become congested. This event further delays the generation of logs, and with this, further allocations and deallocations of NAT resources (port-blocks) is stalled until the queue is relieved of congestion. For example, an excessive logging state in the system can be caused by issuing a command to clear a large number of NAT subscribers where a large number of resources (port-blocks) are released at once.

The suppress-lsn-sub-blks-free command enables the generation of individual logs carried in event-id 2012 for every released port block regardless of the state of the transmission queue (whether congested or not). If NAT subscribers have a large number of allocated port blocks (this could be hundreds of port blocks per subscriber), generating individual logs per port-block release contributes to the congestion.

To alleviate transmission queue congestion, this behavior can be changed by disabling this command (no suppress-lsn-sub-blks-free). This causes the suppression of logs related to the release of individual port blocks of a NAT subscriber when the transmission queue is congested. As a result, only a summarized release log via event-id 2021 for the subscriber is generated. The purpose of this new log is to inform the operator in a single message that all ports blocks for the subscriber are released. For example, the log message for LSN is “LSN subscriber all blocks freed”. The benefit of such summarization (or log aggregation) is to alleviate the congestion of the transmission queue and consequently accelerate resource releases. An effect is the decreased granularity of information.

If summarization is enabled (no suppress-lsn-sub-blks-free) while there is no logging congestion in the system, the port block releases continue to be logged individually via the event-id 2012 (assuming that this is enabled in the event control), except for the last port block of the subscriber. When the last port block is released, the log with event-id 2021 is generated indicating that all port blocks for the subscriber are now released without carrying the specific information about this last port block that is released.

Default 

no suppress-lsn-sub-blks-free

watermarks

Syntax 
watermarks
Context 
config>isa>wlan-gw-group
Description 

This command enables the context to configure ISA watermark notifications.

mark

Syntax 
mark entity high percentage-high low percentage-low
no mark entity
Context 
config>isa>wlan-gw-group>watermarks
Description 

This command enables a watermark notification. If the watermark is set, it generates a notification when the corresponding resource consumption goes above the high percentage. No additional notifications are sent until resource consumption goes under the low watermark, upon which, a notification is sent indicating the high watermark is no longer hit.

The no form of the command disables the watermark notification.

Parameters 
entity
Specifies which watermark to set.
Values—
user-equipment | bridge-domain | radius-proxy-client

 

percentage-high
Specifies the high watermark in percentage of total resources available.
Values—
1 to 100

 

percentage-low—
Specifies the low watermark in percentage of total resources available.
Values—
0 to 99

 

11.25.2.6. Port Policy Commands

port-policy

Syntax 
port-policy port-policy-name [create]
no port-policy port-policy-name
Context 
config
Description 

This command either creates a new port-policy with create parameter or enters the configuration context of an existing port-policy.

The no form of the command removes the port policy name from the configuration.

Parameters 
port-policy-name—
Specifies the name of port-policy up to 32 characters in length.
create—
Keyword used to create a port-policy.

egress-scheduler-policy

Syntax 
egress-scheduler-policy port-sched-plcy
egress-scheduler-policy
Context 
config>port-policy
Description 

This command specifies the port-scheduler-policy to use in the egress direction for the internal port connecting the WLAN-GW IOM to the MS-ISA.

The no form of the command removes the policy from the configuration.

Default 

no egress-scheduler-policy

Parameters 
port-sched-plcy—
Specifies the name of the port-scheduler-policy up to 32 characters.

11.25.2.7. WLAN-GW Group Interface Commands

Note:

The wlan-gw commands apply only to the 7750 SR platform.

group-interface

Syntax 
group-interface ip-int-name [create]
group-interface ip-int-name [create] lns
group-interface ip-int-name [create] wlangw
no group-interface ip-int-name [create]
Context 
config>service>ies>subscriber-interface
config>service>vprn>subscriber-interface
Description 

This command creates a group interface. This interface is designed for triple-play services where multiple SAPs are part of the same subnet. A group interface may contain one or more SAPs.

The no form of the command removes the group interface from the subscriber interface.

Default 

no group interfaces configured

Parameters 
ip-int-name—
Specifies the interface name of a group interface. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes.
lns —
Specifies to use LNS.
wlangw—
Specifies the group interface for wlan-gw.

wlan-gw

Syntax 
wlan-gw
Context 
config>service>ies>sub-if>group-interface
config>service>vprn>sub-if> group-interface
Description 

This command enables the context to configure wlan-gw parameters.

vlan-tag-ranges

Syntax 
vlan-tag-ranges
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command enables the context to configure vlan-to-retail-map parameters to map dot1Q tags to retail-service-id. The WIFI AP could insert a dot1Q tag in the Layer 2 frame within the GRE tunnel to indicate the retail service provider for the subscriber.

range

Syntax 
range start [range] end [range]
range default
no range start [range] end [range]
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges
config>service>ies>sub-if>grp-if>wlan-gw>ranges
Description 

This command creates or enters the context of specified VLAN range for configuration applicable to that range of VLANs.

Default 

range default

Parameters 
start
Specifies the start of the VLAN range.
Values—
0 to 4096

 

end—
Specifies the end of VLAN the range.
Values—
0 to 4096

 

default—
Configures defaults for the interface.

authenticate-on-dhcp

Syntax 
[no] authenticate-on-dhcp
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range
Description 

This command enables initial authentication (when there is no state for the UE on the ISA), to be triggered by DHCP DISCOVER or REQUEST. The default behavior s authentication based on first Layer 3 packet.

The no form of the command reverts to the default.

Default 

no authenticate-on-dhcp

authentication

Syntax 
authentication
Context 
config>service>vprn>sub-if>grp-if>wlan-gw
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range
Description 

This command enables the context to create configuration for authenticating a user from the WLAN-GW ISA.

authentication-policy

Syntax 
authentication-policy policy-name
no authentication-policy
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>authentication
config>service>ies>sub-if>grp-if>wlan-gw>authentication
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>authentication
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>authentication
Description 

This command specifies authentication policy configured under aaa context for authenticating users on WLAN-GW ISA.

The no form of the command removes the policy-name from the configuration.

Default 

no authentication-policy

Parameters 
policy-name —
Specifies the name of the authentication policy up to 32 characters.

hold-time

Syntax 
hold-time [hrs hours] [min minutes] [sec seconds]
no hold-time
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>authentication
config>service>ies>sub-if>grp-if>wlan-gw>authentication
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>authentication
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>authentication
Description 

This command configures the minimum time that a user is held down after a failed authentication attempt.

The no form of the command reverts to the default.

Default 

no hold-time hold-time sec 5

Parameters 
hours
Specifies the minimum time that a user is held down in hours.
Values—
1 to 1

 

minutes
Specifies the minimum time that a user is held down in minutes.
Values—
1 to 59

 

seconds
Specifies the minimum time that a user is held down in seconds.
Values—
0to 59

 

vlan-mismatch-timeout

Syntax 
vlan-mismatch-timeout seconds
no vlan-mismatch-timeout
Context 
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>authentication
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>authentication
Description 

This command configures the timeout value for the RADIUS proxy cache if a packet is received with a non-matching VLAN tag. The new timeout value is the lesser of the vlan-mismatch-timeout value and the currently remaining proxy cache timeout value.

The no form of the command disables the timeout behavior. The cache timeout value will remain unchanged.

Default 

no vlan-mismatch-timeout

Parameters 
seconds—
Specifies the timeout value for the RADIUS proxy cache, in seconds.
Values—
5 to 60

 

distributed-sub-mgmt

Syntax 
distributed-sub-mgmt
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range
Description 

This command enables the context to configure distributed-sub-mgmt configuration per vlan-range. This also includes vlan-range default, which makes this configuration applicable to the wlan-gw group-interface.

accounting-policy

Syntax 
accounting-policy policy-name
no accounting-policy
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dsm
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dsm
Description 

This command specifies the isa-radius-policy used for accounting messages originated from the ISAs in the wlan-gw group. The policy can specify up to five accounting servers and configuration-specific to these accounting servers. It also specifies configuration specific to RADIUS client on ISAs and RADIUS attributes to be included in accounting messages.

Default 

no accounting-policy

Parameters 
policy-name—
Specifies the name of the account policy up to 32 characters.

accounting-update-interval

Syntax 
accounting-update-interval [interval]
no accounting-update-interval
Context 
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dsm
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dsm
Description 

This command enables the interim accounting and specifies the interim accounting interval.

Default 

no accounting-update-interval

Parameters 
interval
Specifies the interim accounting interval in seconds.
Values—
5 to 259200

 

collect-aa-acct-stats

Syntax 
[no] collect-aa-acct-stats
Context 
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dsm
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dsm
Description 

This command enables Application Assurance account statistics collection.

Default 

no collect-aa-acct-stats

def-app-profile

Syntax 
def-app-profile profile-name
no def-app-profile
Context 
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dsm
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dsm
Description 

This command configures the default application profile.

Default 

no def-app-profile

dsm-ip-filter

Syntax 
dsm-ip-filter dsm-ip-filter-name
no dsm-ip-filter
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dsm
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dsm
Description 

This command configures an IP filter that is distributed on ISA cards.

This command specifies the IP filter applied to all UEs corresponding to default vlan-range (such as a group-interface) or the specified vlan-range. The IP filter can be created in the config>subscr-mgmt>isa-filter context, and can contain up to 1024 match entries. The IP filter can be overridden per UE from RADIUS via access-accept or COA.

The no form of the command reverts to the default.

Default 

no dsm-ip-filter

Parameters 
dsm-ip-filter-name—
Specifies the identifier of the distributed-sub-mgmt IP filter.

egress-policer

Syntax 
egress-policer [policer-name]
no egress-policer
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dsm
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dsm
Description 

This command specifies the egress policer applied to all UEs corresponding to default vlan-range (such as, group-interface) or the specified vlan-range. The policer can be created in the config>subscr-mgmt>isa-policer context. The egress policer can be overridden per UE from RADIUS via access-accept or COA.

The no form of the command reverts to the default.

Default 

no egress-policer

Parameters 
policer-name—
Specifies the identifier of the distributed-sub-mgmt policer for egress traffic up to 256 characters.

ingress-policer

Syntax 
ingress-policer policer-name
no ingress-policer
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dsm
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dsm
Description 

.This command specifies the ingress policer applied to all UEs corresponding to default vlan-range (such as group-interface) or the specified vlan-range. The policer can be created in the config>subscr-mgmt>isa-policer context. The ingress policer can be overridden per UE from RADIUS via access-accept or COA.

The no form of the command reverts to the default.

Default 

no ingress-policer

Parameters 
policer-name—
Specifies the identifier of the distributed-sub-mgmt policer for ingress traffic.

one-time-redirect

Syntax 
one-time-redirect url rdr-url-string port port-num
no one-time-redirect
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dsm
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dsm
Description 

This command enables one-time http-redirect to specified redirect URL for traffic matching the specified destination port.

The no form of the command reverts to the default.

Default 

no one-time-redirect

Parameters 
url rdr-url-string
Specifies the HTTP web address that is sent to the user’s browser.
port port-num
Specifies the destination port number as a decimal hex or binary.
Values—
1 to 65535

 

default-retail-svc-id

Syntax 
default-retail-svc-id service-id
no default-retail-svc-id
Context 
config>service>ies>sub-if>grp-if>wlan-gw>vlan-tag-ranges
config>service>vprn>sub-if>grp-if>wlan-gw>vlan-tag-ranges
Description 

This command specifies the id of default retail service if there is no match found in VLAN to retail map configuration (specified by the vlan command). For DSM and migrant, this command is only applicable for non-NAT stacks.

Default 

no default-retail-svc-id

Parameters 
service-id—
Specifies the identifier of the retail service to be used by default of a value in the retail service map of this interface
Values—
1 to 2147483650
svc-name: up to 64 characters

 

vlan

Syntax 
vlan start [value] end [value] retail-svc-id service-id
no vlan start [value] end [value]
Context 
config>service>ies>sub-if>grp-if>wlan-gw>retailer
config>service>vprn>sub-if>grp-if>wlan-gw>retailer
Description 

This command creates a mapping from a range of VLANs (appearing in the wlan-gw encapsulated Layer 2 frame) to a retail service ID.

The no form of the command removes the parameters from the configuration.

Parameters 
start
Specifies the start VLAN tag of this range.
Values—
0 to 4095

 

end —
Specifies the end VLAN tag of this range.
Values—
0 to 4095

 

retail-svc-id service-id
Specifies the identifier of the retail service to be used by default of a value in the retail service map of this interface.
Values—
1 to 2147483650
svc-name: up to 64 characters

 

wlan-gw-group

Syntax 
wlan-gw-group group-id
no wlan-gw-group
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command specifies the ID of the wlan-gw-group that the wlan-gw gateway binds to.

The no form of the command removes the value from the wlan-gw configuration.

Parameters 
group-id—
Specifies the ISA WLAN-GW group.
Values—
1 to 4

 

ip-mtu

Syntax 
ip-mtu octets
no ip-mtu
Context 
config>service>ies>subscriber-interface
config>service>vprn>subscriber-interface
Description 

This command specifies the maximum size of frames on this group-interface. Packets larger than this will get fragmented.

The no form of the command removes this functionality.

Parameters 
octets.—
Specifies the largest frame size (in octets) that this interface can handle
Values—
512 to 9000

 

sap-parameters

Syntax 
sap-parameters
Context 
config>service>ies>sub-if>grp-if
config>service>vprn>sub-if>grp-if
Description 

This command enables the context to configure parameters that can be applied to automatically-generated internal SAPs.

anti-spoof

Syntax 
anti-spoof {ip-mac | nh-mac}
no anti-spoof
Context 
config>service>ies>sub-if>grp-if>sap-parameters
config>service>vprn>sub-if>grp-if>sap-parameters
Description 

This command configures the anti-spoof type of the SAP.

The type of anti-spoof filtering defines what information in the incoming packet is used to generate the criteria to lookup an entry in the anti-spoof filter table. The type parameter (ip-mac or nh-mac) defines the anti-spoof filter type enforced by the SAP when anti-spoof filtering is enabled.

The no form of the command reverts to the default.

Default 

anti-spoof ip-mac

Parameters 
ip-mac—
Configures SAP anti-spoof filtering to use both the source IP address and the source MAC address in its lookup. The anti-spoof ip-mac command will fail if the default anti-spoof filter type of the SAP is ip-mac and the default is not overridden, or if the SAP does not support Ethernet encapsulation.
nh-mac—
Indicates that the ingress anti-spoof is based on the source MAC address and egress anti-spoof is based on the nh-ip-address

sub-sla-mgmt

Syntax 
[no] sub-sla-mgmt
Context 
config>service>ies>sub-if>grp-if>sap-parameters
config>service>vprn>sub-if>grp-if>sap-parameters
Description 

This command enables the context to configure subscriber management parameters.

The no form of the command removes the parameters from the configuration.

Default 

sub-sla-mgmt

def-app-profile

Syntax 
def-app-profile profile-name
no def-app-profile
Context 
config>service>ies>sub-if>grp-if>sap-parameters>sub-sla-mgmt
config>service>vprn>sub-if>grp-if>sap-parameters>sub-sla-mgmt
Description 

This command configures the default application profile.

The no form of the command removes the profile name from the configuration.

Default 

no def-app-profile

Parameters 
profile-name—
Specifies the default application profile name up to 32 characters

def-sla-profile

Syntax 
def-sla-profile default-sla-profile-name
no def-sla-profile
Context 
config>service>ies>sub-if>grp-if>sap-parameters>sub-sla-mgmt
config>service>vprn>sub-if>grp-if>sap-parameters>sub-sla-mgmt
Description 

This command specifies a default SLA profile for this SAP. The SLA profile must be defined prior to associating the profile with a SAP in the config>subscr-mgmt>sla-profile context.

An SLA profile is a named group of QoS parameters used to define per service QoS for all subscriber hosts common to the same subscriber within a provider service offering. A single SLA profile may define the QoS parameters for multiple subscriber hosts. SLA profiles are maintained in two locations, the subscriber identification policy and the subscriber profile templates. After a subscriber host is associated with an SLA profile name, either the subscriber identification policy used to identify the subscriber or the subscriber profile associated with the subscriber host must contain an SLA profile with that name. If both the subscriber identification policy and the subscriber profile contain the SLA profile name, the SLA profile in the subscriber profile is used.

The no form of the command removes the default SLA profile from the SAP configuration.

Default 

no def-sla-profile

Parameters 
default-sla-profile-name—
Specifies a default SLA profile for this SAP. The SLA profile must be defined prior to associating the profile with a SAP in the config>subscr-mgmt>sla-profile context.

def-sub-id

Syntax 
def-sub-id string sub-id
def-sub-id use-auto-id
no def-sub-id
Context 
config>service>vprn>sub-if>grp-if>sap-parameters>sub-sla-mgmt
config>service>ies>sub-if>grp-if>sap-parameters>sub-sla-mgmt
Description 

This command configures the default subscriber ID. The default is used if no other source (like RADIUS) provides a subscriber identification string.

Default 

no def-sub-id

Parameters 
sub-id
Specifies the default subscriber identification up to 32 characters
use-auto-id—
Specifies that the auto-generated subscriber identification string, is used as the default subscriber identification string

def-sub-profile

Syntax 
def-sub-profile sub-profile-name
Context 
config>service>vprn>sub-if>grp-if>sap-parameters>sub-sla-mgmt
config>service>ies>sub-if>grp-if>sap-parameters>sub-sla-mgmt
Description 

This command specifies a default subscriber profile. The subscriber profile must be defined prior to associating the profile with a SAP in the config>subscr-mgmt>sub-profile context.

A subscriber profile defines the aggregate QoS for all hosts within a subscriber context. This is done through the definition of the egress and ingress scheduler policies that govern the aggregate SLA for subscriber using the subscriber profile. Subscriber profiles also allow for specific SLA profile definitions when the default definitions from the subscriber identification policy must be overridden.

The no form of the command removes the default SLA profile from the configuration.

Default 

no def-sub-profile

Parameters 
sub-profile-name—
Specifies a default subscriber profile. The subscriber profile must be defined in the config>subscr-mgmt>sub-profile context.

sub-ident-policy

Syntax 
sub-ident-policy sub-ident-policy-name
Context 
config>service>vprn>sub-if>grp-if>sap-parameters>sub-sla-mgmt
config>service>ies>sub-if>grp-if>sap-parameters>sub-sla-mgmt
Description 

This command associates a subscriber identification policy. The subscriber identification policy must be defined in the config>subscr-mgmt>sub-ident-policy context.

Subscribers are managed by the system through the use of subscriber identification strings. A subscriber identification string uniquely identifies a subscriber. For static hosts, the subscriber identification string is explicitly defined with each static subscriber host.

For dynamic hosts, the subscriber identification string must be derived from the DHCP ACK message sent to the subscriber host. The default value for the string is the content of Option 82 CIRCUIT-ID and REMOTE-ID fields interpreted as an octet string. As an option, the DHCP ACK message may be processed by a subscriber identification policy which has the capability to parse the message into an alternative ASCII or octet string value.

When multiple hosts on the same port are associated with the same subscriber identification string they are considered to be host members of the same subscriber.

The no form of the command removes the default subscriber identification policy from the configuration.

Default 

no sub-ident-policy

Parameters 
sub-ident-policy-name—
Specifies a subscriber identification policy for this SAP. The subscriber profile must be defined prior to associating the profile with a SAP in the config>subscr-mgmt>sub-ident-policy context.

egress

Syntax 
egress
Context 
config>service>ies>sub-if>grp-if>wlan-gw
Description 

This command enables the context to configure egress QoS parameters for wlan-gw tunnels.

rate

Syntax 
rate {max | rate}
no rate
Context 
config>service>ies>sub-if>grp-if>wlan-gw>egress>agg-rate
config>service>vprn>sub-if>grp-if>wlan-gw>egress>agg-rate
Description 

This command defines the enforced aggregate rate for all queues associated with the agg-rate context. A rate must be specified for the agg-rate context to be considered to be active on the context’s object (SAP, subscriber, Vport, and so on).

The no form of the command reverts to the default.

Default 

no rate

agg-rate-limit

Syntax 
agg-rate-limit kilobits-per-second
no agg-rate-limit
Context 
config>service>ies>sub-if>grp-if>wlan-gw>egress
config>service>vprn>sub-if>grp-if>wlan-gw>egress
Description 

This command controls an HQoS aggregate rate limit. It is used in conjunction with the following parameter commands: rate, limit-unused-bandwidth, and queue-frame-based-accounting.

The no form of the command removes the rate from the configuration.

Default 

no agg-rate-limit

Parameters 
kilobits-per-second—
Specifies the aggregate rate limit
Values—
1 to 100000000, max

 

hold-time

Syntax 
hold-time infinite
hold-time [time]
no hold-time
Context 
config>service>ies>sub-if>grp-if>wlan-gw>egress
config>service>vprn>sub-if>grp-if>wlan-gw>egress
Description 

This command configures the time for which egress shaping resources associated with a wlan-gw tunnel are held after the last subscriber on a tunnel is deleted.

Default 

no hold-time

Parameters 
time
Specifies the time, in seconds, for which shaping resources are held in seconds after last subscriber is deleted
Values—
infinite to 1 to 86400

 

qos

Syntax 
qos policy-id
no qos
Context 
config>service>ies>sub-if>grp-if>wlan-gw>egress
Description 

This command configures the identifier of the egress QoS policy associated with each wlan-gw tunnel of this interface.

The no form of the command removes the policy ID from the configuration.

Default 

qos 1

Parameters 
policy-id—
Specifies to apply the specified sap-egress-policy-id
Values—
1 to 65535
name: A string up to 64 characters

 

scheduler-policy

Syntax 
scheduler-policy scheduler-policy-name
no scheduler-policy
Context 
config>service>ies>sub-if>grp-if>wlan-gw>egress
Description 

This command configures the identifier of the egress scheduler policy associated with each wlan-gw tunnel of this interface.

The no form of the command removes the scheduler policy name from the configuration.

Default 

no scheduler-policy

Parameters 
scheduler-policy-name—
Specifies the identifier of the egress scheduler policy associated with each wlan-gw tunnel of this interface

shape-multi-client-only

Syntax 
[no] shape-multi-client-only
Context 
config>service>ies>sub-if>grp-if>wlan-gw>egress
Description 

This command enables the egress shaping is only enabled for a wlan-gw tunnel while there are multiple UE (User Equipment) using it.

The no form of the command disables the egress shaping.

Default 

no shape-multi-client-only

shaping

Syntax 
shaping {per-retailer | per-tunnel}
no shaping
Context 
config>service>ies>sub-if>grp-if>wlan-gw>egress
Description 

This command configures the granularity of the egress shaping for wlan-gw on this group interface.

The no form of the command removes the parameter from the configuration.

Default 

no shaping

Parameters 
per-tunnel—
Specifies that a separate shaper is applied to each wlan-gw tunnel
per-retailer—
Specifies that a separate shaper is applied to each retailer Mobile Network Operator's fraction of the wlan-gw tunnel payload

gw-address

Syntax 
gw-address ip-address
no gw-address
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command specifies gateway endpoint address for the wlan-gw tunnel.

The no form of the command removes the value from the wlan-gw configuration.

Default 

no gw-address

Parameters 
ip-address—
Specifies the IP address of the wlan-gw tunnels on this group interface

gw-ipv6-address

Syntax 
gw-ipv6-address ipv6-address
no gw-ipv6-address
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command specifies a gateway IPv6 endpoint address for the wlan-gw tunnel.

The no form of the command removes the IPv6 the gateway IPv6 endpoint address for the wlan-gw tunnel.

Default 

no gw-ipv6-address

Parameters 
ipv6-address—
Specifies the gateway IPv6 endpoint address
Values—

ipv6-address :

x:x:x:x:x:x:x:x (eight 16-bit pieces)

x:x:x:x:x:x:d.d.d.d

x - [0 to FFFF]H

d - [0 to 255]D

 

learn-ap-mac

Syntax 
learn-ap-mac [delay-auth]
no learn-ap-mac
Context 
config>service>vprn>sub-if>grp-if>wlan-gw
config>service>ies>sub-if>grp-if>wlan-gw
Description 

This command enables the sending of ARP or ND packets on the wlan-gw GRE tunnel upon certain events. The target IP address in the ARP/ND packet is the endpoint IP address of the AP. The ARP/ND response from the AP should contain the AP MAC, which subsequently can be reported in called-station-id. When enabled this is sent for following events:

  1. CPM: Mobility to an AP for which the AP-MAC is not yet known.
  1. CPM: RS-triggered authentication on an AP for which the AP-MAC is not yet known
  1. ISA: Any mobility event
  1. ISA: Any authentication where the AP-MAC is not yet known (for example, from RADIUS proxy cache, DHCP circuit-id, and so on). If the optional keyword delay-auth is provided the authentication is delayed until the ARP/ND is answered or timed out, after which the AP-MAC can be included in authentication.

This configuration is ignored for l2-ap and l2tpv3 access.

Default 

no learn-ap-mac

Parameters 
delay-auth—
Specifies that authentication is delayed until the ARP/ND is answered or timed out, after which the AP-MAC can be included in authentication

l2-access-points

Syntax 
l2-access-points
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command enables the context to configure Layer 2 Access Points in WLAN Gateway Group-Interfaces.

l2-ap

Syntax 
l2-ap sap-id [create]
no l2-ap sap-id
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>l2-access-points
config>service>ies >sub-if>grp-if>wlan-gw>l2-access-points
Description 

This command adds a specific SAP where Layer-2 WLAN-GW aggregation is performed. The following SAPs are supported.

  1. Ethernet
  2. LAG
  3. MPLS pseudowire SDPs

This command can be repeated multiple times to create multiple Layer-2 access points.

The no form of the command removes the Layer-2 access point. This is only allowed if the l2-ap SAP is shutdown.

Default 

No SAPs are defined

Parameters 
sap-id—
Specifies SAP to be created.
create—
Keyword used to create the Layer-2 WLAN-GW aggregation instance. The create keyword requirement can be enabled/disabled in the environment>create context.

encap-type

Syntax 
encap-type {default | null | dot1q | qinq}
no encap-type
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>l2-access-points>l2-ap
config>service>ies >sub-if>grp-if>wlan-gw>l2-access-points>l2-ap
Description 

If different from default, this command overrides the value specified by l2-ap-encap-type on wlan-gw level. See the description of l2-ap-encap-type for more detail. This value can only be changed while the l2-ap is shutdown.

The no form of the command sets the default value.

Default 

default

Parameters 
default
Specifies to use the value specified by l2-ap-encap-type
null
Specifies to use both the SAP and the AP are not VLAN-tagged
dot1q
Specifies to use either the AP or the SAP uses one VLAN tag
qinq
Up to two VLAN tags are used by the AP or SAP

epipe-sap-template

Syntax 
epipe-sap-template name
no epipe-sap-template
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>l2-access-points>l2-ap
config>service>ies >sub-if>grp-if>wlan-gw>l2-access-points>l2-ap
Description 

This command specifies which SAP parameter template should be applied to the l2-ap SAP. This can only be changed when the l2-ap is shutdown.

The no form of the command removes the template, the SAP will use default parameters.

Parameters 
name—
Specifies the name of the template to use

shutdown

Syntax 
shutdown sap-id [create]
no shutdown sap-id
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>l2-access-points>l2-ap
config>service>ies >sub-if>grp-if>wlan-gw>l2-access-points>l2-ap
Description 

This command administratively enables this SAP to begin accepting Layer 2 packets for WIFI offloading.

The no form of the command disables this SAP.

Default 

shutdown

l2-ap-auto-sub-id-fmt

Syntax 
l2-ap-auto-sub-id-fmt {include-ap-tags | sap-only}
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command configures the contents of the auto-generated subscriber ID when the ipoe-sub-id-key command is set to include sap-id and the def-sub-id command is configured with use-auto-id. The VLANs must be configured so that the subscriber ID length is not exceeded.

This command can include either the SAP or the SAP + AP delimiting tags.

The no form of the command reverts to the default configuration.

Default 

l2-ap-auto-sub-id-fmt include-ap-tags

Parameters 
include-ap-tags—
Specifies that the SAP + AP delimiting tags is used.
sap-only—
Specifies that the SAP only is used.

l2-ap-encap-type

Syntax 
l2-ap-encap-type {null | dot1q | qinq}
Context 
config>service>vprn>sub-if>grp-if>wlan-gw
config>service>ies >sub-if>grp-if>wlan-gw
Description 

This parameter specifies the number of AP identifying VLAN tags for an AP. This is the default value that can be overridden per SAP. This value should at least be equal to the number of VLANs configured in the SAP or enabling a SAP will fail.

A SAP VLAN is explicitly configured, for example l2-ap 1/1/1:25. Other VLANs on the same port can still be used in other contexts.

The number of VLAN tags Epiped to WLAN-GW IOM equal the l2-ap-encap-type minus the encaps of the SAP. Upon receipt of a packet these VLANs is stored as a Layer 2 tunnel identifier, and are only used in context of WLAN-GW.

The no form of the command sets the default value.

Default 

l2-ap-encap-type null

Parameters 
null —
Both the SAP and the AP are not VLAN-tagged
dot1q —
Either the AP or the SAP uses one VLAN tag
qinq —
Up to two VLAN tags are used by the AP or SAP

mobility

Syntax 
mobility
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command enables the context to configure mobility parameters.

hold-time

Syntax 
hold-time time
no hold-time
Context 
config>service>ies>sub-if>grp-if>wlan-gw>mobility
config>service>vprn>sub-if>grp-if>wlan-gw>mobility
Description 

This command configures the minimum time that a User Equipment is held associated with its current Access Point (AP) before being associated with a new AP.

The hold time is used to prevent overwhelming the system with mobility triggers, by limiting the rate at which a UE can move from one AP to another while the system is very busy already.

Default 

hold-time 5

Parameters 
time—
Specifies a hold-down time, in seconds, for handling of successive mobility triggers for a UE. It is the minimal time a UE stays associated with an AP.
Values—
0 to 255

 

inter-vlan

Syntax 
[no] inter-vlan
Context 
config>service>ies>sub-if>grp-if>wlan-gw>mobility
config>service>vprn>sub-if>grp-if>wlan-gw>mobility
Description 

This command enables mobility within different VLANs of the same range. When enabled, mobility between different VLANs in a single vlan-range is allowed for the configured mobility triggers.

The no form of this command disables mobility between VLANs.

Default 

no inter-vlan

trigger

Syntax 
trigger [data] [iapp] [control]
no trigger
Context 
config>service>ies>sub-if>grp-if>wlan-gw>mobility
config>service>vprn>sub-if>grp-if>wlan-gw>mobility
Description 

This command specifies the type of packet used as a mobility trigger.

The no form of the command removes the parameters from the configuration and disables data-plane mobility.

Default 

no trigger

Parameters 
data—
Specifies that data traffic be used as a trigger
iapp—
Specifies that Inter Access Point Protocol (IAPP) messages be used as a trigger
control—
Specifies that control traffic can be used as a trigger

multi-tunnel-type

Syntax 
[no] multi-tunnel-type
Context 
config>service>ies>sub-if>grp-if>wlan-gw>mobility
config>service>vprn>sub-if>grp-if>wlan-gw>mobility
Description 

This command enables terminating multiple types of tunnels.

The no form of the command disables terminating multiple types of tunnels.

no multi-tunnel-type

Default 

no oper-down-on-group-degrade

oper-down-on-group-degrade

Syntax 
[no] oper-down-on-group-degrade
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command operationally brings down the WLAN-GW group if the total number of operational WLAN-GW IOMs in the WLAN-GW group fall below the configured number of active WLAN-GW IOMs. This triggers withdrawal of the route to tunnel endpoint and subscriber subnets in routing.

Default 

no oper-down-on-group-degrade

router

Syntax 
router router-instance
no router
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command specifies the routing instance that wlan-gw gateway endpoint resides in.

The no form of the command removes the value from the wlan-gw configuration.

Default 

router

Parameters 
router-instance—
Specifies the identifier of the virtual router instance where the tunneled User Equipment traffic is routed.

tcp-mss-adjust

Syntax 
tcp-mss-adjust segment-size
no tcp-mss-adjust
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command configures the TCP Maximum Segment Size (MSS) adjustment for the wlan-gw gateway.

The no form of the command disables adjusting tcp-mss values.

For DSM, this only applies to packets sent in the downstream direction (TCP SYN towards UE). For the upstream direction, it is also required to configure MSS adjust under the applicable NAT-policy.

Default 

no tcp-mss-adjust

Parameters 
segment-size—
Specifies the value to put into the TCP Maximum Segment Size (MSS) option if not already present, or if the present value is higher.
Values—
160 to 10240

 

tunnel-encaps

Syntax 
tunnel-encaps
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command enables the context to configure tunnel encapsulation parameters.

learn-l2tp-cookie

Syntax 
learn-l2tp-cookie {if-match | never | always} [cookie hex string]
no learn-l2tp-cookie
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command specifies when this system will learn the cookie from L2TP tunnels terminating on this interface. Learning the cookie means that the value of the octets 3-8 of the cookie is interpreted as an access point’s MAC address, and used as such, for example in the Called-Station-Id attribute of RADIUS Interim-Update messages.

Default 

no learn-l2tp-cookie

Parameters 
if-match —
Specifies that the cookie is interpreted only if the value of the first two octets of the cookie is equal to the value of the object tmnxWlanGwSoftGreIfL2tpCookie.
cookie hex string
Specifies the value used to compare the first two bytes of the cookie. This parameter is only valid if if-match is configured.
Values—
0x0000 to 0xFFFF...(4 hex nibbles)

 

never —
Specifies that the cookie value will always be ignored.
always—
Always learn the AP-MAC from the cookie, regardless of the value of the first two bytes.

retail-svc-id

Syntax 
retail-svc-id service-id
no retail-svc-id
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range
Description 

This command configures the retailer service.

Default 

no retail-svc-id

Parameters 
service-id—
Specifies the identifier of the retail service.
Values—
1 to 2147483650
svc-name: up to 64 characters

 

router-advertisements

Syntax 
[no] router-advertisements
Context 
config>service>vprn>sub-if>grp-if>ipv6
config>service>ies>sub-if>grp-if>ipv6
Description 

This command configures IPv6 router advertisements for this group-interface.

current-hop-limit

Syntax 
[no] current-hop-limit limit
Context 
config>service>vprn>sub-if>grp-if>ipv6>rtr-adv
config>service>ies>sub-if>ipv6>rtr-adv
Description 

This command configures the hop-limit advertised for this group-interface.

Default 

current-hop-limit

Parameters 
limit—
Specifies the default value to be placed in the current hop limit field in router advertisements sent from this interface
Values—
0 to 255

 

pool-manager

Syntax 
pool-manager
Context 
config>service>ies>sub-if>wlan-gw
config>service>vprn>sub-if>wlan-gw
Description 

This command enables the context to configure pool manager data for a WLAN GW subscriber interface.

dhcpv6-client

Syntax 
dhcpv6-client
Context 
config>service>ies>sub-if>wlan-gw>pool-manager
config>service>vprn>sub-if>wlan-gw>pool-manager
Description 

This command configures the DHCPv6 client for the pool manager.

dhcpv4-nat

Syntax 
dhcpv4-nat
Context 
config>service>ies>sub-if>wlan-gw>pool-manager>dhcp6-client
config>service>vprn>sub-if>wlan-gw>pool-manager>dhcp6-client
Description 

This node enables address pools for DHCPv4 NAT inside addresses. This configuration is only available in wholesale interfaces.

ia-na

Syntax 
ia-na
Context 
config>service>ies>sub-if>wlan-gw>pool-manager>dhcp6-client
config>service>vprn>sub-if>wlan-gw>pool-manager>dhcp6-client
Description 

This command configures the IA-NA for the DHCPv6 client.

link-addr

Syntax 
link-addr ipv6-address
no link-addr
Context 
config>service>ies>sub-if>wlan-gw>pool-manager>dhcp6-client>slaac
config>service>vprn>sub-if>wlan-gw>pool-manager>dhcp6-client>slaac
config>service>ies>sub-if>wlan-gw>pool-manager>dhcp6-client>ia-na
config>service>vprn>sub-if>wlan-gw>pool-manager>dhcp6-client>ia-na
config>service>ies>sub-if>wlan-gw>pool-manager>dhcp6-client>dhcpv4-nat
config>service>vprn>sub-if>wlan-gw>pool-manager>dhcp6-client>dhcpv4-nat
Description 

This command specifies the ipv6-address that should be included in the link-address field of the relay header. This can be used for pool selection by the DHCPv6 server.

The no form of this command falls back to the default.

Default 

::

Parameters 
ipv6-address—
Specifies the IPv6 address up to 32 characters.

pool-name

Syntax 
pool-name name
no pool-name
Context 
config>service>ies>sub-if>wlan-gw>pool-manager>dhcp6-client>slaac
config>service>vprn>sub-if>wlan-gw>pool-manager>dhcp6-client>slaac
config>service>ies >sub-if>wlan-gw>pool-manager>dhcp6-client>ia-na
config>service>vprn>sub-if>wlan-gw>pool-manager>dhcp6-client>ia-na
config>service>ies>sub-if>wlan-gw>pool-manager>dhcp6-client>dhcpv4-nat
config>service>vprn>sub-if>wlan-gw>pool-manager>dhcp6-client>dhcpv4-nat
Description 

This command specifies the pool name that should be sent in the DHCPv6 messages. This is reflected in the Nokia vendor specific pool option (vendor-id 6527, option-id 0x02).

The no form of this command removes pool-name and the option will not be sent in DHCPv6.

Default 

no pool-name

Parameters 
name—
Specifies the pool name up with 32 characters,

lease-query

Syntax 
lease-query [max-retry Max nbr of retries]
no lease-query
Context 
config>service>vprn>sub-if>wlan-gw>pool-manager>dhcp6-client
config>service>ies>sub-if>wlan-gw>pool-manager>dhcp6-client
Description 

This command enables lease-query. If this is specified the dhcp6-client will retrieve any existing addresses when becoming active. The lease-query is performed for all of the configured servers

The no form of this command disables lease-query.

Default 

no lease-query

Parameters 
Max nbr of retries—
Specifies the maximum number of retries before the lease query assumes no existing subnets were allocated.
Values—
0 to 10

 

server

Syntax 
server ipv6-address [ipv6-address]
no server [ipv6-address [ipv6-address]]
Context 
config>service>vprn>sub-if>wlan-gw>pool-manager>dhcp6-client
config>service>ies>sub-if>wlan-gw>pool-manager>dhcp6-client
Description 

This specifies the DHCPv6 servers that are used for requesting addresses. Up to 8 servers can be used simultaneously.

The no form of this command removes the server. This cannot be executed while any DHCPv6 client application is not shutdown.

Parameters 
ipv6-address—
Specifies the unicast IPv6 address of a dhcp6 server

slaac

Syntax 
slaac
Context 
config>service>vprn>sub-if>wlan-gw>pool-manager>dhcp6-client
config>service>ies>sub-if>wlan-gw>pool-manager>dhcp6-client
Description 

This command configures SLAAC for the DHCPv6 client.

source-ip

Syntax 
source-ip ipv6-address
no source-ip
Context 
config>service>vprn>sub-if>wlan-gw>pool-manager>dhcp6-client
config>service>ies>sub-if>wlan-gw>pool-manager>dhcp6-client
Description 

This command specifies the source-ip to be used by the DHCPv6 client.

The no form of this command removes the specific source-ip. In this case the DHCPv6 client will fall back to the IP address configured on the outgoing interface.

Parameters 
ipv6-address—
Specifies the IPv6 address up to 32 characters

watermarks

Syntax 
watermarks high high-percentage low low-percentage
no watermarks
Context 
config>service>vprn>sub-if>wlan-gw>pool-manager
config>service>ies>sub-if>wlan-gw>pool-manager
Description 

This command configures the watermarks used to determine if a new prefix should be allocated or an old prefix should be removed. A new prefix is allocated when the total usage level for the ISA reaches the high watermark. A prefix is freed if no addresses are currently in use and the usage level without this prefix would be below the low watermark.

The no form of this command resets the watermarks to its default values of 95% high and 90% low.

Default 

watermarks high 95 low 90

Parameters 
high-percentage
Specifies the high watermark.
Values—
80 to 99

 

low-percentage
Specifies the low watermark. The value must be lower than the high percentage value.
Values—
50 to 98

 

wlan-gw-group

Syntax 
wlan-gw-group nat-group-id
no wlan-gw-group
Context 
config>service>vprn>sub-if>wlan-gw>pool-manager
config>service>ies>sub-if>wlan-gw>pool-manager
Description 

This command specifies the ISA WLAN gateway group.

Parameters 
nat-group-id—
Specifies the identifier of the WLAN gateway group.
Values—
1 to 4

 

redundancy

Syntax 
redundancy
Context 
config>service>ies>sub-if>wlan-gw
Description 

This command enables the context to configure WLAN-GW redundancy-related parameters.

export

Syntax 
export ip-prefix/length
no export
Context 
config>service>ies>sub-if>wlan-gw>redundancy
Description 

This command specifies an IPv4 route (prefix/length) per subscriber-interface to be exported (announced) to indicate liveness of the subscriber-interface on the WLAN-GW. This route is the one that is monitored in routing by the peer WLAN-GW to decide its state with respect.

The no form of the command reverts to the default.

Default 

no export

Parameters 
ip-prefix/length—
Specifies the IP prefix and length
Values—
ip-prefix:a.b.c.d
ip-prefix-length: 0 to 32

 

monitor

Syntax 
monitor ip-prefix/length
no monitor
Context 
config>service>ies>sub-if>wlan-gw>redundancy
Description 

This command specifies an IPv4 route (prefix/length) per subscriber-interface to be monitored in the FDB to determine liveness of the subscriber-interface (and consequently all associated group-interfaces of type wlangw) on a peer WLAN-GW. This route is the one that is advertised in routing by the peer WLAN-GW when the subscriber-interface and WLAN-GW group are operationally up

Default 

no monitor

Parameters 
ip-prefix/length—
Specifies the IP prefix and length
Values—
ip-prefix:a.b.c.d
ip-prefix-length: 0 to 32

 

11.25.2.8. Migrant User Support Commands

http-redirect-policy

Syntax 
http-redirect-policy policy-name
no http-redirect-policy
Context 
config>subscr-mgmt
Description 

This command configures the redirect policy to constrain forwarding of an unauthenticated “migrant” WIFI user.

Default 

no http-redirect-policy

Parameters 
policy-name —
Specifies the HTTP redirect policy name up to 32 characters.

forward-entries

Syntax 
forward-entries
Context 
config>subscr-mgmt>http-rdr-plcy
Description 

Enters the context to configure entries that need to be forwarded

dst-port

Syntax 
dst-port tcp-port
no dst-port
Context 
config>subscr-mgmt>http-rdr-plcy
Description 

This command specifies the port to match the destination port in the HTTP request.

HTTP traffic that does not match this port, is not redirected.

The no form of the command reverts to the default.

Default 

dst-port 80

Parameters 
tcp-port—
Specifies the TCP port.
Values—
1 to 65535

 

dst-ip

Syntax 
dst-ip ip-address protocol ip-protocol dst-port port-number
dst-ip ip-address protocol ip-protocol dst-port port-number prefix-length prefix-length
no dst-ip ip-address protocol ip-protocol dst-port port-number
Context 
config>subscr-mgmt>http-rdr-plcy
Description 

This command configures traffic flow to be forwarded via match in the redirect policy.

Parameters 
ip-address—
Specifies the IPv4 or IPv6 address to match the destination address in the IP header of the traffic received from the subscriber.
prefix-length—
Specifies the length of the prefix specified by the ip-address.
Values—
1 to 128 for IPv6
1 to 32 for IPv4

 

ip-protocol
Specifies the protocol to match the IP protocol in the IP header of the traffic received from the subscriber.
Values—
tcp, udp

 

port-number
Specifies the port to match the destination port in the HTTP request.
Values—
1 to 65535

 

portal-hold-time

Syntax 
portal-hold-time seconds
no portal-hold-time
Context 
config>subscr-mgmt>http-rdr-plcy
Description 

This command configures the time for which the forwarding state applicable during redirect phase is held in the system, after the user has been authenticated on the portal. This allows the HTTP response from the portal to be forwarded back on the existing connection.

Default 

no portal-hold-time

Parameters 
seconds—
Specifies how long the system holds on to re-direct forwarding resources of a subscriber, after it has left the re-direct portal.
Values—
1 to 60

 

url

Syntax 
url rdr-url-sting
no url
Context 
config>subscr-mgmt>http-rdr-plcy
Description 

This command configures the HTTP URL to re-direct the matching traffic to. It also can specify inclusion of original URL, MAC address and IP address of the subscriber in the redirect URL.

Default 

no url

Parameters 
rdr-url-sting—
Specifies the URL to redirect to
Values—

rdr-url-string

[255 chars max]

macro substitutions:

$URL

Request-URI in the HTTP GET Request received

$MAC

A string that represents the MAC address of the subscriber host

$IP

A string that represents the IP address of the subscriber host

 

wlan-gw

Syntax 
wlan-gw
Context 
config>service>vprn>sub-if>grp-if
config>service>ies>sub-if>grp-if
Description 

This command enables the context to configure wlan-gw parameters.

vlan-tag-ranges

Syntax 
vlan-tag-ranges
Context 
config>service>vprn>sub-if>grp-if>wlan-gw
config>service>ies>sub-if>grp-if>wlan-gw
Description 

This command enables the context for per vlan range configuration.

default-retail-svc-id

Syntax 
default-retail-svc-id service-id
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges
config>service>ies>sub-if>grp-if>wlan-gw>ranges
Description 

This command configures the default retailer service for WIFI users.

dhcp

Syntax 
dhcp
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges
config>service>ies>sub-if>grp-if>wlan-gw>ranges
Description 

This command enables the context to create DHCP configuration for WLAN-GW ISA subscribers (such as migrant subscribers).

dhcp6

Syntax 
dhcp6
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges
config>service>ies>sub-if>grp-if>wlan-gw>ranges
Description 

This command enables the context to create DHCP6 configuration for WLAN-GW ISA subscribers.

active-preferred-lifetime

Syntax 
active-preferred-lifetime [hrs hours] [min minutes] [sec seconds]
no active-preferred-lifetime
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dhcp6
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dhcp6
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>slaac
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>slaac
Description 

This command specifies the signaled preferred lifetime in DHCPv6 or SLAAC after full authentication. This is only applicable to DSM.

The no form of the command reverts to the default.

Default 

active-preferred-lifetime min 10

Parameters 
hours
Specifies the number of active preferred lifetime hours.
Values—
1 to 1

 

minutes
Specifies the number of active preferred lifetime minutes.
Values—
5 to 59

 

seconds
Specifies the number of active preferred lifetime seconds.
Values—
1 to 59

 

active-valid-lifetime

Syntax 
active-valid-lifetime [hrs hours] [min minutes] [sec seconds]
no active-valid-lifetime
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dhcp6
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dhcp6
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>slaac
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>slaac
Description 

This command specifies the signaled valid lifetime in DHCPv6 or SLAAC after full authentication. This is only applicable to DSM.

The no form of the command reverts to the default.

Default 

active-valid-lifetime min 10

Parameters 
hours
Specifies the number of active-valid-lifetime hours.
Values—
1 to 1

 

minutes
Specifies the number of active-valid-lifetime minutes.
Values—
5 to 59

 

seconds
Specifies the number of active-valid-lifetime seconds.
Values—
1 to 59

 

active-lease-time

Syntax 
active-lease-time [hrs hours] [min minutes] [sec seconds]
no active-lease-time
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>dhcp
config>service>ies>sub-if>grp-if>wlan-gw>dhcp
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dhcp
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dhcp
Description 

This command configures the lease time for an authenticated user.

Default 

active-lease-time min 10

Parameters 
hours
Specifies the number of active lease time hours.
Values—
1 to 1

 

minutes
Specifies the number of active lease time minutes.
Values—
5 to 59

 

seconds
Specifies the number of active lease time seconds.
Values—
1 to 59

 

initial-preferred-lifetime

Syntax 
initial-preferred-lifetime [hrs hours] [min minutes] [sec seconds]
no initial-preferred-lifetime
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dhcp6
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dhcp6
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>slaac
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>slaac
Description 

This command specifies the signaled preferred lifetime in DHCPv6 or SLAAC after full authentication (DSM and/or ESM).

The no form of the command reverts to the default.

Default 

initial-preferred-lifetime min 5

Parameters 
hours
Specifies the number of initial preferred lifetime hours.
Values—
1 to 1

 

minutes
Specifies the number of initial preferred lifetime minutes.
Values—
5 to 59

 

seconds
Specifies the number of initial preferred lifetime seconds.
Values—
1 to 59

 

Combined values: min 5 – hrs 1

initial-valid-lifetime

Syntax 
initial-valid-lifetime [hrs hours] [min minutes] [sec seconds]
no initial-valid-lifetime
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dhcp6
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dhcp6
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>slaac
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>slaac
Description 

This command specifies the signaled preferred lifetime in DHCPv6 or SLAAC during a migrant phase.

The no form of the command reverts to the default.

Default 

initial-valid-lifetime min 5

Parameters 
hours
Specifies the number of initial preferred lifetime hours.
Values—
1 to 1

 

minutes
Specifies the number of initial preferred lifetime minutes.
Values—
5 to 59

 

seconds
Specifies the number of initial preferred lifetime seconds.
Values—
1 to 59

 

Combined values: min 5 – hrs 1

initial-lease-time

Syntax 
initial-lease-time [hrs hours] [min minutes] [sec seconds]
no initial-lease-time
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>dhcp
config>service>ies>sub-if>grp-if>wlan-gw>dhcp
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dhcp
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dhcp
Description 

This command configures the lease time for a user which is migrant (unauthenticated).

Default 

initial-lease-time min 10

Parameters 
hours
Specifies the number of initial lease time hours.
Values—
1 to 1

 

minutes
Specifies the number of initial lease time minutes.
Values—
5 to 59

 

seconds
Specifies the number of initial lease time.
Values—
1 to 59

 

l2-aware-ip-address

Syntax 
l2-aware-ip-address ip-address
l2-aware-ip-address from-pool
no l2-aware-ip-address
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dhcp
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dhcp
Description 

This command configures the L2-Aware NAT inside IP address to be assigned via DHCP on WLAN-GW ISA.

If the from-pool parameter is specified instead of an IPv4 address, a unique address is allocated to each UE. The pool used is managed by the dhcpv4-nat pool manager, configured under the same subscriber interface. This option is only available when auth-on-dhcp is also configured.

The no form of the command reverts to the default.

Default 

no l2-aware-ip-address

Parameters 
ip-address—
Specifies the L2-Aware NAT inside IP address.
from-pool—
Specifies that the L2-Aware IP address is allocated from a pool.

primary-dns

Syntax 
primary-dns ip-address
no primary-dns
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dhcp
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dhcp
Description 

This command configures the primary DNS address to be returned via DHCP on WLAN-GW ISA.

The no form of the command reverts to the default.

Default 

no primary-dns

Parameters 
ip-address—
Specifies the primary DNS address.

secondary-dns

Syntax 
secondary-dns ip-address
no secondary-dns
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dhcp
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dhcp
Description 

This command configures the secondary DNS address to be returned via DHCP on WLAN-GW ISA.

The no form of the command reverts to the default.

Default 

no secondary-dns

Parameters 
ip-address—
Specifies the secondary DNS address.

primary-nbns

Syntax 
primary-nbns ip-address
no primary-nbns
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dhcp
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dhcp
Description 

This command configures the primary NBNS address to be returned via DHCP on WLAN-GW ISA.

The no form of the command reverts to the default.

Default 

no primary-nbns

Parameters 
ip-address—
Specifies the primary NBNS address.

secondary-nbns

Syntax 
secondary-nbns ip-address
no secondary-nbns
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dhcp
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dhcp
Description 

This command configures the secondary NBNS address to be returned via DHCP on WLAN-GW ISA.

The no form of the command reverts to the default.

Default 

no secondary-nbns

Parameters 
ip-address—
Specifies the secondary NBNS address.

idle-timeout

Syntax 
idle-timeout action idle-timeout-action
no idle-timeout
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range
config>service>ies >sub-if>grp-if>wlan-gw>ranges>range
Description 

This command specifies idle-timeout behavior for DSM UEs and UEs undergoing (ISA-based) portal authentication. This knob only specifies the desired action, idle-timeout is activated by RADIUS on a per-UE basis.

The no form of the command resets the idle-timeout to its default

Default 

idle-timeout action remove

Parameters 
action —
Specifies which action to perform when the idle-timeout timer goes off.
Values—
remove, shcv

 

http-redirect-policy

Syntax 
http-redirect-policy policy-name
no http-redirect-policy
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range
Description 

This command specifies http redirect policy on ISA to redirect http traffic to the URL specified in the policy.

The no form of the command reverts to the default.

Default 

no http-redirect-policy

Parameters 
policy-name —
Specifies the name of the http redirect policy under subscriber-management context.

l2-service

Syntax 
l2-service service-id
no l2-service
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range
config>service>ies >sub-if>grp-if>wlan-gw>ranges>range
Description 

This command specifies the VPLS service used for L2 wholesale. When such a service is configured no other configuration is allowed under the vlan-range.

The no form of the command removes the L2 wholesale service, this is only allowed if the l2-service node is shutdown.

Default 

no l2-service

Parameters 
service-id—
Specifies the VPLS service ID to use for Layer 2 wholesale.

nat-policy

Syntax 
nat-policy policy-name
no nat-policy
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range
Description 

This command specifies the NAT policy for WLAN-GW ISA subscribers.

The no form of the command reverts to the default.

Default 

no nat-policy

brg

Syntax 
brg
Context 
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range
config>service>ies>sub-if>grp-if
config>service>vprn>sub-if>grp-if
Description 

This command enables the context to configure BRG parameters. In the config>service>ies>sub-if>grp-if and config>service>vprn>sub-if>grp-if contexts, these commands are only available in the vlan-tag-ranges context.

authenticated-brg-only

Syntax 
[no] authenticated-brg-only
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>brg
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>brg
config>service>vprn>sub-if>grp-if>brg
config>service>ies>sub-if>grp-if>brg
Description 

This command indicates that only BRGs that are pre-authenticated using the RADIUS proxy are allowed in this context.

The no form of the command removes the restriction

Default 

no authenticated-brg-only

default-brg-profile

Syntax 
default-brg-profile profile-name
no default-brg-profile
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>brg
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>brg
config>service>vprn>sub-if>grp-if>brg
config>service>ies>sub-if>grp-if>brg
Description 

This command indicates that the default BRG profile must be used for new BRGs. This profile can be overridden by RADIUS.

The no form of the command removes the profile name from the configuration.

Default 

no default-brg-profile

Parameters 
profile-name—
Specifies the name of the brg-profile to be applied.

data-triggered-ue-creation

Syntax 
[no] data-triggered-ue-creation
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range
Description 

This command enables or disables data-triggered subscriber creation for WIFI subscribers. Data triggered UE creation is currently only supported for UDP and TCP packets.

The no form of the command reverts to the default.

Default 

no data-triggered-ue-creation

track-mobility

Syntax 
track-mobility
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range
Description 

This command enables the context to configure RADIUS-proxy cache information required for subscribers that are created via data-triggered authentication. The RADIUS proxy cache enables efficient handling of UE mobility.

mac-format

Syntax 
mac-format mac-format
no mac-format
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>track-mobility
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>track-mobility
Description 

This command configures how the MAC address is represented by the RADIUS proxy server.

Default 

no mac-format "aa:"

Parameters 
mac-format—
Specifies how the MAC address is represented by the RADIUS proxy server.
Values—

mac-format

like ab: for 00:0c:f1:99:85:b8

or XY- for 00-0C-F1-99-85-B8

or mmmm. for 0002.03aa.abff

or xx for 000cf19985b8

 

radius-proxy-cache

Syntax 
radius-proxy-cache router router-instance server server-name
no radius-proxy-cache
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>track-mobility
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>track-mobility
Description 

This command specifies the RADIUS-proxy server to allow subscribers created via data-triggered authentication to create an entry. This RADIUS proxy cache entry allows efficient handling of UE mobility.

Default 

no radius-proxy-cache

Parameters 
router-instance
Specifies the router instance.
Values—

router-name

Base

service-id

1 to 2147483647

 

server-name
Specifies the server name up to 32 characters.

sap-template

Syntax 
sap-template sap-template
no sap-template
Context 
config>service>vpls>wlan-gw
Description 

This command specifies the VPLS SAP template that is applied on the internal SAPs created for communication between the VPLS and the ISAs.

The no form of the command removes the SAP template.

Default 

no sap-template

Parameters 
sap-template —
Specifies the existing SAP template to apply. The template is created in the config>service>template context.

11.25.2.8.1. Show Commands

Note:

The command outputs in the following section are examples only; actual displays may differ depending on supported functionality and user configuration.

call-trace

Syntax 
call-trace
Context 
show
Description 

This command enables the context to display information related to the call-trace module.

wlan-gw

Syntax 
wlan-gw
Context 
show>call-trace
Description 

The command enables the context to display information related to the wlan-gw call-trace functionality.

ue

Syntax 
ue [ieee-address] [detail]
Context 
show>call-trace
Description 

This command gives an overview of either all traces or a specific trace on the WLAN-GW.

Parameters 
ieee-address—
Displays information about the MAC address of this UE.
detail—
Displays detailed information about the job.
Output 

The following output is an example of traces of the UE being monitored.

Sample Output
Node# show call-trace hosts
===============================================================================
Call-trace hosts
===============================================================================
 MAC address Mask-name     Status      Msgs
-------------------------------------------------------------------------------
 00:0a:95:9d:68:16 N/A                running   16
-------------------------------------------------------------------------------
Number of call-trace debug jobs: 1
=============================================================================
Node# show call-trace hosts detail
===============================================================================
Call-trace  detail
===============================================================================
MAC address                            : 00:0a:95:95:34:0a                 Status : running
                   Capture format     : pcap
Nr. of captured msgs   : 4 Time limit            : 86400s
Size of captured msgs : 2620B Data limit             : 10MB
Started : NOV 12 2013, 15:28:17 UTC
Live output : N/A
-------------------------------------------------------------------------------
 

acct-on-off-group

Syntax 
acct-on-off-group [group-name]
Context 
show>aaa
Description 

This command displays Acct-On-Off group information and the associated RADIUS server policies.

Parameters 
group-name—
Displays information pertaining to the specified acct-on-off group.
Output 

The following output is an example of AAA Acct-On-Off group information.

Sample Output
# show aaa acct-on-off-group "group-1" 
===============================================================================
Acct-On-Off-Group Information
===============================================================================
acct on off group name               : group-1
  - controlling Radius-Server-policy :  
        aaa-server-policy-3
  - monitored by Radius-Server-policy :  
        aaa-server-policy-4
-------------------------------------------------------------------------------
Nbr of Acct-on-off-groups displayed : 1
-------------------------------------------------------------------------------
===============================================================================
 
Table 105:  WiFi Acct-On-Off Field Descriptions 

Label

Description  

acct on off group name

Displays the name of a RADIUS server policy Accounting-On-Off-Group.

controlling Radius-Server-policy

Displays the controlling RADIUS server policy name.

monitored by Radius-Server-policy

Displays the policy monitored a RADIUS server policy.

Nbr of Acct-on-off-groups displayed

Specifies the RADIUS policy that controls the Acct-On-Off group.

radius-proxy-server

Syntax 
radius-proxy-server server-name
radius-proxy-server server-name cache
radius-proxy-server server-name cache hex-key hex-string
radius-proxy-server server-name cache string-key string
radius-proxy-server server-name cache summary
radius-proxy-server server-name statistics
radius-proxy-server
Context 
show>router
Description 

This command displays summary of RADIUS-proxy cache or specific entries.

Parameters 
server-name—
Displays information about the specified server name.
cache—
Displays messages used to generate the key for the cache of this RADIUS proxy server.
hex-key hex-string
Displays information about the specified hex string.
Values—
0x0 to 0xFFFFFFFF (maximum of 64 hex nibbles)]

 

string
Displays information about the specified string.
summary—
Displays a summary of the cache of the RADIUS proxy servers.
statistics—
Displays statistics about the RADIUS proxy servers of this system.
Output 

The following is an example of RADIUS proxy server information.

Sample Output
system# show router 10 radius-proxy-server "myProxyServer1" 
===============================================================================
RADIUS Proxy server "myProxyServer1"
===============================================================================
Description                 : myDesc
Purpose                     : authentication 
Administrative state        : in-service
Default acct server policy  : myRadiusServerPolicy1
Default auth server policy  : myRadiusServerPolicy2
Send accounting response    : true
Last management change      : 02/17/2012 14:54:28
-------------------------------------------------------------------------------
Cache settings
-------------------------------------------------------------------------------
Administrative state        : enabled
Key packet type             : access-accept
Key attribute type          : 12
Key vendor ID               : (Not Specified)
Timeout (s)                 : 60
Track accounting            : stop interim-update accounting-on accounting-off 
Load balance key            : source-ip-udp
===============================================================================
Interfaces
-------------------------------------------------------------------------------
myInterface1                     
myInterface2                     
myInterface3                     
-------------------------------------------------------------------------------
No. of Interface(s): 3
===============================================================================
Usernames/RADIUS server policies
===============================================================================
Id Username-match                     RADIUS-server-policy             Purpose
------------------------------------------------------------------------------------
1.  aaa                                myRadiusServerPolicy2 auth
==============================================================================
system# 
Table 106:  RADIUS Proxy Server Field Descriptions 

Label

Description

Description

Displays the description of this RADIUS proxy server.

Purpose

Displays the purpose of the RADIUS server, either accounting or authentication.

Administrative state

Displays the administrative state of this RADIUS server.

Default acct server policy

Displays the name of the default RADIUS server policy associated with this RADIUS proxy server for accounting purposes.

Default auth server policy

Displays the name of the default RADIUS server policy associated with this RADIUS proxy server for authentication purposes.

Send accounting response

Specifies if this RADIUS Proxy server itself responds with an Accounting-Response message to each received Accounting-Request instead of proxying them to a configured RADIUS server.

Last management change

Displays the sysUpTime at the time of the most recent management-initiated change

Key packet type

Displays the packet type of the RADIUS messages to use to generate the key for the cache of this RADIUS proxy server, access-request, access-accept, access-reject, access-challenge

Key attribute

type

Displays the RADIUS attribute type to cache for this RADIUS proxy server. Refer to RFC 2865, Remote Authentication Dial In User Service (RADIUS), Section 5 Attributes.

Key vendor ID

Displays the RADIUS Vendor-Id. Refer to RFC 2865, Remote Authentication Dial In User Service (RADIUS), Section 5.25 Vendor-Specific.

Timeout (s)

Displays, in seconds, the timeout after which an entry in the cache will expire.

Track accounting

Displays the RADIUS accounting packets that have impact on the cache of this RADIUS proxy server.

Load balance key

Displays the key for load-balancing RADIUS messages between RADIUS servers.

Id

Displays the specifies the RADIUS Vendor-Id.

Username

Displays the user name.

RADIUS-server-policy

Displays the RADIUS server name.

Purpose

Displays the purpose of the RADIUS server, either accounting or authentication.

wlan-gw

Syntax 
wlan-gw
Context 
show>router
Description 

This command displays Wireless LAN Gateway information.

isa-subnets

Syntax 
isa-subnets [detail]
isa-subnets [detail] interface interface-name
isa-subnets prefix ipv6-address/prefix-length
Context 
show>router>wlan-gw
Description 

This command outputs all the prefixes in use by the wlan-gw pool-manager.

Parameters 
detail—
Displays detailed information for each prefix.
interface-name
Displays only the prefixes associated with this subscriber interface.
ipv6-address/prefix-length—
Displays details of a specific ipv6 address and prefix.
Output 

The following is an example of WLAN-GW ISA subnet information.

Sample Output
system# show router wlan-gw isa-subnets
===============================================================================
ISA Subnets
===============================================================================
Prefix                                                   MDA     Family  Usage
-------------------------------------------------------------------------------
2001:db8:0:1/48                                            3/1     dhcpv6  0%
2001:db8:1::/48                                          3/2     dhcpv6  0%
2001:db8:2::/48                                          4/1     dhcpv6  0%
2001:db8:3::/48                                          4/2     dhcpv6  0%
2001:db8:4::/48                                          5/1     dhcpv6  0%
2001:db8:5::/48                                          5/2     dhcpv6  0%
2001:db8:6::/48                                          3/1     slaac   0%
2001:db8:7::/48                                          3/2     slaac   0%
2001:db8:8::/48                                          4/1     slaac   0%
2001:db8:9::/48                                          4/2     slaac   0%
2001:db8:a::/48                                          5/1     slaac   0%
2001:db8:b::/48                                          5/2     slaac   0%
-------------------------------------------------------------------------------
No. of ISA subnets: 12
===============================================================================
 
*A:Dut-C# show router wlan-gw isa-subnets prefix 2001:db8::/48
===============================================================================
ISA Subnet Prefix           : 2001:db8::/48
-------------------------------------------------------------------------------
Group Id                    : 1
Member Id                   : 1
MDA                         : 3/1
Family                      : dhcpv6
Subscriber Interface        : wlangw-sub-itf
Pool Is Old                 : No
Usage Level                 : 0%
Remaining Lease Time        : 0d 23:50:54
DHCPv6 Options              : (length=512)
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
===============================================================================
 

mgw-address-cache

Syntax 
mgw-address-cache [arec] [snaptr] [srv]
mgw-address-cache apn apn-domain-string
Context 
show>router>wlan-gw
Description 

This command displays the mobile gateway's DNS lookup address cache.

Parameters 
arec—
Displays A-records.
snaptr—
Displays Straightforward-NAPTR information.
srv—
Displays SRV records.
apn-domain-string
Specifies the Access Point Name (APN) of this DNS cache entry.
Output 

The following output is an example of WLAN-GW DNS lookup address cache information.

Sample Output
*A:Dut-C# show router 300 wlan-gw mgw-address-cache 
===============================================================================
Mobile Gateway SNAPTR cache
===============================================================================
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.
                              3gppnetwork.org
Order                       : 10
Index                       : 1
-------------------------------------------------------------------------------
Preference                  : 10
Service                     : x-3gpp-pgw:x-gn-gtp
Next lookup                 : dns-srv
Replacement                 : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.
                              3gppnetwork.org
Time left (s)               : 3582
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.
                              3gppnetwork.org
Order                       : 20
Index                       : 2
-------------------------------------------------------------------------------
Preference                  : 20
Service                     : x-3gpp-pgw:x-s2a-gtp
Next lookup                 : dns-srv
Replacement                 : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.
                              3gppnetwork.org
Time left (s)               : 3582
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.
                              3gppnetwork.org
Order                       : 30
Index                       : 3
-------------------------------------------------------------------------------
Preference                  : 30
Service                     : x-3gpp-pgw:x-s2b-gtp
Next lookup                 : dns-srv
Replacement                 : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.
                              3gppnetwork.org
Time left (s)               : 3581
-------------------------------------------------------------------------------
No. of SNAPTR cache entries: 3
===============================================================================
===============================================================================
Mobile Gateway SRV cache
===============================================================================
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.
                              3gppnetwork.org
Priority                    : 10      
Index                       : 1
-------------------------------------------------------------------------------
Weight                      : 10
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a1.
                              3gppnetwork.org
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.
                              3gppnetwork.org
Priority                    : 20
Index                       : 2
-------------------------------------------------------------------------------
Weight                      : 20
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a2.
                              3gppnetwork.org
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.
                              3gppnetwork.org
Priority                    : 10
Index                       : 1
-------------------------------------------------------------------------------
Weight                      : 10      
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a1.
                              3gppnetwork.org
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.
                              3gppnetwork.org
Priority                    : 20
Index                       : 2
-------------------------------------------------------------------------------
Weight                      : 20
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a2.
                              3gppnetwork.org
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.
                              3gppnetwork.org
Priority                    : 10
Index                       : 1
-------------------------------------------------------------------------------
Weight                      : 10
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a1.
                              3gppnetwork.org
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.
                              3gppnetwork.org
Priority                    : 20
Index                       : 2
-------------------------------------------------------------------------------
Weight                      : 20
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a2.
                              3gppnetwork.org
Time left (s)               : 3581
-------------------------------------------------------------------------------
No. of SRV cache entries: 6
===============================================================================
===============================================================================
Mobile Gateway address cache
===============================================================================
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.23
Time left (s)               : 3581 
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.29
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      :  10.0.0.35
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      :  10.0.0.24
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.30
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.36
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.25
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.31
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.37
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.26
Time left (s)               : 3580
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.32
Time left (s)               : 3580
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.38
Time left (s)               : 3580
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.27
Time left (s)               : 3580
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.33
Time left (s)               : 3580
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.39
Time left (s)               : 3580
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.28
Time left (s)               : 3580
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.34
Time left (s)               : 3580
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.40
Time left (s)               : 3580
-------------------------------------------------------------------------------
No. of cache entries: 18
 
 
*A:Dut-C# show router 300 wlan-gw mgw-address-cache arec 
===============================================================================
Mobile Gateway address cache
===============================================================================
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.23
Time left (s)               : 3573
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.29
Time left (s)               : 3573
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.35
Time left (s)               : 3573
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.24
Time left (s)               : 3573
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.30
Time left (s)               : 3573
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.36
Time left (s)               : 3573
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.25
Time left (s)               : 3573
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.31
Time left (s)               : 3573
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.37
Time left (s)               : 3573
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.26
Time left (s)               : 3573
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.32
Time left (s)               : 3573
-----------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.38
Time left (s)               : 3572
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.27
Time left (s)               : 3572
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.33
Time left (s)               : 3572
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.39
Time left (s)               : 3572 
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.28
Time left (s)               : 3572
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.34
Time left (s)               : 3572
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.40
Time left (s)               : 3572
-------------------------------------------------------------------------------
No. of cache entries: 18
===============================================================================
 
 
*A:Dut-C# show router 300 wlan-gw mgw-address-cache srv  
===============================================================================
Mobile Gateway SRV cache
===============================================================================
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.
                              3gppnetwork.org
Priority                    : 10
Index                       : 1
-------------------------------------------------------------------------------
Weight                      : 10
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a1.
                              3gppnetwork.org
Time left (s)               : 3567
 
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.
                              3gppnetwork.org
Priority                    : 20
Index                       : 2
-------------------------------------------------------------------------------
Weight                      : 20
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a2.
                              3gppnetwork.org
Time left (s)               : 3567    
 
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.
                              3gppnetwork.org
Priority                    : 10
Index                       : 1
-------------------------------------------------------------------------------
Weight                      : 10
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a1.
                              3gppnetwork.org
Time left (s)               : 3566
 
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.
                              3gppnetwork.org
Priority                    : 20
Index                       : 2
-------------------------------------------------------------------------------
Weight                      : 20
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a2.
                              3gppnetwork.org
Time left (s)               : 3566
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.
                              3gppnetwork.org
Priority                    : 10
Index                       : 1
-------------------------------------------------------------------------------
Weight                      : 10
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a1.
                              3gppnetwork.org
Time left (s)               : 3566
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.
                              3gppnetwork.org
Priority                    : 20
Index                       : 2
-------------------------------------------------------------------------------
Weight                      : 20
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a2.
                              3gppnetwork.org
Time left (s)               : 3566
-------------------------------------------------------------------------------
No. of SRV cache entries: 6
===============================================================================
 
 
*A:Dut-C# show router 300 wlan-gw mgw-address-cache snaptr
===============================================================================
Mobile Gateway SNAPTR cache
===============================================================================
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.
                              3gppnetwork.org
Order                       : 10
Index                       : 1
-------------------------------------------------------------------------------
Preference                  : 10
Service                     : x-3gpp-pgw:x-gn-gtp
Next lookup                 : dns-srv
Replacement                 : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.
                              3gppnetwork.org
Time left (s)               : 3555
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.
                              3gppnetwork.org
Order                       : 20
Index                       : 2
-------------------------------------------------------------------------------
Preference                  : 20
Service                     : x-3gpp-pgw:x-s2a-gtp
Next lookup                 : dns-srv
Replacement                 : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.
                              3gppnetwork.org
Time left (s)               : 3555
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.
                              3gppnetwork.org
Order                       : 30
Index                       : 3
-------------------------------------------------------------------------------
Preference                  : 30
Service                     : x-3gpp-pgw:x-s2b-gtp
Next lookup                 : dns-srv
Replacement                 : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.
                              3gppnetwork.org
Time left (s)               : 3554
 
-------------------------------------------------------------------------------
No. of SNAPTR cache entries: 3
 
 
*A:Dut-C# show router 300 wlan-gw mgw-address-cache apn full.dotted.apn.apn.epc.mnc010.mcc206.3gppnetwork.org 
===============================================================================
Mobile Gateway APN Cache
===============================================================================
-------------------------------------------------------------------------------
APN > NAPTR
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.
                              3gppnetwork.org
Order                       : 10
Index                       : 1
-------------------------------------------------------------------------------
Preference                  : 10
Service                     : x-3gpp-pgw:x-gn-gtp
Next lookup                 : dns-srv
Replacement                 : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.
                              3gppnetwork.org
Time left (s)               : 3531
-------------------------------------------------------------------------------
APN > NAPTR > SRV
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.
                              3gppnetwork.org
Priority                    : 10
Index                       : 1
-------------------------------------------------------------------------------
Weight                      : 10
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a1.
                              3gppnetwork.org
Time left (s)               : 3531
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.23
Time left (s)               : 3530
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.29
Time left (s)               : 3530
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.35
Time left (s)               : 3530
-------------------------------------------------------------------------------
APN > NAPTR > SRV
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.
                              3gppnetwork.org
Priority                    : 20
Index                       : 2
-------------------------------------------------------------------------------
Weight                      : 20
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a2.
                              3gppnetwork.org
Time left (s)               : 3530
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.24
Time left (s)               : 3530
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.30
Time left (s)               : 3530
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.36
Time left (s)               : 3530
-------------------------------------------------------------------------------
APN > NAPTR
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.
                              3gppnetwork.org
Order                       : 20
Index                       : 2       
-------------------------------------------------------------------------------
Preference                  : 20
Service                     : x-3gpp-pgw:x-s2a-gtp
Next lookup                 : dns-srv
Replacement                 : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.
                              3gppnetwork.org
Time left (s)               : 3530
-------------------------------------------------------------------------------
APN > NAPTR > SRV
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.
                              3gppnetwork.org
Priority                    : 10
Index                       : 1
-------------------------------------------------------------------------------
Weight                      : 10
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a1.
                              3gppnetwork.org
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.25
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.31
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.37
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.
                              3gppnetwork.org
Priority                    : 20
Index                       : 2
-------------------------------------------------------------------------------
Weight                      : 20
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a2.
                              3gppnetwork.org
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.26
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.32
Time left (s)               : 3529
                                      
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.38
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.
                              3gppnetwork.org
Order                       : 30
Index                       : 3
-------------------------------------------------------------------------------
Preference                  : 30
Service                     : x-3gpp-pgw:x-s2b-gtp
Next lookup                 : dns-srv
Replacement                 : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.
                              3gppnetwork.org
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.
                              3gppnetwork.org
Priority                    : 10
Index                       : 1
-------------------------------------------------------------------------------
Weight                      : 10
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a1.
                              3gppnetwork.org
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.27
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.33
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.39
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.
                              3gppnetwork.org
Priority                    : 20
Index                       : 2
-------------------------------------------------------------------------------
Weight                      : 20
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a2.
                              3gppnetwork.org
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A                 
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.28
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.34
Time left (s)               : 3528
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.40
Time left (s)               : 3528
-------------------------------------------------------------------------------
No. of cache entries: 18 

tunnel-qos

Syntax 
tunnel-qos [detail]
tunnel-qos remote-ip ip-address [local-ip ip-address] [detail]
Context 
show>router>wlan-gw
Description 

This command displays tunnel-QoS resource information.

Parameters 
ip-address
Specifies the IP address of the Mobile Gateway that is the source IP address in the tunnel header of received packets.
Values—

ip-address:

ipv4-address - a.b.c.d

ipv6-address :

x:x:x:x:x:x:x:x (eight 16-bit pieces)

x:x:x:x:x:x:d.d.d.d

x - [0 to FFFF]H

d - [0 to 255]D

 

ip-address
Specifies the IP address of this system that is the destination IP address in the tunnel header of received packets.
Values—

ip-address:

ipv4-address - a.b.c.d

ipv6-address :

x:x:x:x:x:x:x:x (eight 16-bit pieces)

x:x:x:x:x:x:d.d.d.d

x - [0 to FFFF]H

d - [0 to 255]D

 

detail—
Displays detailed information.
Output 

The following output is an example of soft GRE tunnel QoS information.

Sample Output
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnel-qos 
===============================================================================
Soft GRE tunnel QoS
===============================================================================
Remote IP address           : 239.0.0.2
Local IP address            : 10.1.1.1
Operational state           : active
Number of UE                : 1
Remaining hold time (s)     : N/A
 
 
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnel-qos detail 
===============================================================================
Soft GRE tunnel QoS
===============================================================================
Remote IP address           : 239.0.0.2
Local IP address            : 10.1.1.1
Operational state           : active
Number of UE                : 1
Remaining hold time (s)     : N/A
Service Access Points(SAP)
===============================================================================
Service Id         : 2147483650               
SAP                : 5/1/lo-gre:1             Encap             : q-tag
Description        : Internal SAP
Admin State        : Up                       Oper State        : Up
Flags              : None
Multi Svc Site     : None                     
Last Status Change : 03/24/2014 15:03:48      
Last Mgmt Change   : 03/24/2014 15:14:00      
 
-------------------------------------------------------------------------------
Encap Group Specifics
-------------------------------------------------------------------------------
Encap Group Name   : _tmnx_SHAPER_GR000       Group Type        : ISID
Qos-per-member     : TRUE                     
Members            :
1                                     
 
-------------------------------------------------------------------------------
QOS
-------------------------------------------------------------------------------
E. qos-policy      : 1                        Q Frame-Based Acct: Disabled
E. Sched Policy    :                          E. Agg-limit      : -1
                                              Limit Unused BW   : Disabled
-------------------------------------------------------------------------------
Encap Group Member 1 Base Statistics
-------------------------------------------------------------------------------
Last Cleared Time     : N/A
 
Forwarding Engine Stats
                        Packets                 Octets
 
For. InProf           : 0                       0
For. OutProf          : 0                       0
Dro. InProf           : 0                       0
Dro. OutProf          : 0                       0
 
-------------------------------------------------------------------------------
Encap Group Member 1 Queue Statistics
-------------------------------------------------------------------------------
 
                        Packets                 Octets
 
Egress Queue 1                        
For. InProf           : 0                       0
For. OutProf          : 0                       0
Dro. InProf           : 0                       0
Dro. OutProf          : 0                       0
 
 
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnel-qos remote-ip 239.0.0.2 
===============================================================================
Soft GRE tunnel QoS
===============================================================================
Remote IP address           : 239.0.0.2
Local IP address            : 10.1.1.1
Operational state           : active
Number of UE                : 1
Remaining hold time (s)     : N/A
 
 
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnel-qos  remote-ip 239.0.0.2  local-ip 10.1.1.1 
===============================================================================
Soft GRE tunnel QoS
===============================================================================
Remote IP address           : 239.0.0.2
Local IP address            : 10.1.1.1
Operational state           : active
Number of UE                : 1
Remaining hold time (s)     : N/A
 
 
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnel-qos  remote-ip 239.0.0.2  local-ip 10.1.1.1 detail 
===============================================================================
Soft GRE tunnel QoS
===============================================================================
Remote IP address           : 239.0.0.2
Local IP address            : 10.1.1.1
Operational state           : active
Number of UE                : 1
Remaining hold time (s)     : N/A
Service Access Points(SAP)
===============================================================================
Service Id         : 2147483650               
SAP                : 5/1/lo-gre:1             Encap             : q-tag
Description        : Internal SAP
Admin State        : Up                       Oper State        : Up
Flags              : None
Multi Svc Site     : None                     
Last Status Change : 03/24/2014 15:03:48      
Last Mgmt Change   : 03/24/2014 15:14:00      
-------------------------------------------------------------------------------
Encap Group Specifics
-------------------------------------------------------------------------------
Encap Group Name   : _tmnx_SHAPER_GR000       Group Type        : ISID
Qos-per-member     : TRUE                     
Members            :
1                                                                       
-------------------------------------------------------------------------------
QOS
-------------------------------------------------------------------------------
E. qos-policy      : 1                        Q Frame-Based Acct: Disabled
E. Sched Policy    :                          E. Agg-limit      : -1
                                              Limit Unused BW   : Disabled
-------------------------------------------------------------------------------
Encap Group Member 1 Base Statistics
-------------------------------------------------------------------------------
Last Cleared Time     : N/A
 
Forwarding Engine Stats
                        Packets                 Octets
 
For. InProf           : 0                       0
For. OutProf          : 0                       0
Dro. InProf           : 0                       0
Dro. OutProf          : 0                       0
-------------------------------------------------------------------------------
Encap Group Member 1 Queue Statistics
-------------------------------------------------------------------------------
                        Packets                 Octets
 
Egress Queue 1
For. InProf           : 0                       0
For. OutProf          : 0                       0
Dro. InProf           : 0                       0
Dro. OutProf          : 0                       0
 

tunnels

Syntax 
tunnels local-ip ip-address remote-ip ip-address ue
tunnels [local-ip ip-address] [remote-ip ip-address] [isa-group wlan-gw-group-id] [member [1 to 255]] [summary] [detail]
Context 
show>router>wlan-gw
Description 

This command displays tunnel-QoS resource information.

Parameters 
ip-address
Specifies the remote IP address of the Mobile Gateway that is the source IP address in the tunnel header of received packets.
Values—

ip-address:

ipv4-address - a.b.c.d

ipv6-address :

x:x:x:x:x:x:x:x (eight 16-bit pieces)

x:x:x:x:x:x:d.d.d.d

x - [0 to FFFF]H

d - [0 to 255]D

 

ip-address
Specifies the local IP address of this system that is the destination IP address in the tunnel header of received packets.
Values—

ip-address:

ipv4-address - a.b.c.d

ipv6-address :

x:x:x:x:x:x:x:x (eight 16-bit pieces)

x:x:x:x:x:x:d.d.d.d

x - [0 to FFFF]H

d - [0 to 255]D

 

ue—
Displays information for the specified user equipment.
wlan-gw-group-id
Specifies the identifier of the WLAN Gateway ISA group that terminates GRE for this group interface.
Values—
1 to 4

 

member —
Specifies the identifier of this WLAN Gateway ISA Group member.
Values—
1 to 255

 

summary—
Displays a summary of the specified parameters.
detail—
Displays detailed information.
Output 

The following output is an example of WLAN-GW soft GRE tunnel information.

Sample Output
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnels
===============================================================================
Soft GRE tunnels
===============================================================================
Remote IP address           : 239.0.0.2
Local IP address            : 10.1.1.1
ISA group ID                : 1
ISA group member ID         : 5
Time established            : 2014/03/24 15:38:52
Number of UE                : 1
Access Point MAC            : 00:00:00:00:00:01
AP MAC learn failed         : false
 
Tunnel QoS
----------
Operational state           : active
Number of UE                : 1
Remaining hold time (s)     : N/A
 
-------------------------------------------------------------------------------
No. of tunnels: 1
 
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnels local-ip 10.1.1.1 
===============================================================================
Soft GRE tunnels
===============================================================================
Remote IP address           : 239.0.0.2
Local IP address            : 10.1.1.1
ISA group ID                : 1
ISA group member ID         : 5
Time established            : 2014/03/24 15:38:52
Number of UE                : 1
Access Point MAC            : 00:00:00:00:00:01
AP MAC learn failed         : false
 
Tunnel QoS
----------
Operational state           : active
Number of UE                : 1
Remaining hold time (s)     : N/A
-------------------------------------------------------------------------------
No. of tunnels: 1
 
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnels local-ip 10.1.1.1 remote-ip 239.0.0.2 
===============================================================================
Soft GRE tunnels
===============================================================================
Remote IP address           : 239.0.0.2
Local IP address            : 10.1.1.1
ISA group ID                : 1
ISA group member ID         : 5
Time established            : 2014/03/24 15:38:52
Number of UE                : 1
Access Point MAC            : 00:00:00:00:00:01
AP MAC learn failed         : false
 
Tunnel QoS
----------
Operational state           : active
Number of UE                : 1
Remaining hold time (s)     : N/A
-------------------------------------------------------------------------------
No. of tunnels: 1
 
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnels local-ip 10.1.1.1 remote-ip 239.0.0.2 ue 
===============================================================================
Tunnel User Equipments
===============================================================================
MAC address                 : 00:02:00:00:00:01
-------------------------------------------------------------------------------
VLAN Q-tag                  : 1
MPLS label                  : (Not Specified)
Tunnel router               : 50
Tunnel remote IP address    : 239.0.0.2
Tunnel local IP address     : 10.1.1.1
Retail service              : N/A
SSID                        : "1"
Previous Access Point IP    : (Not Specified)
IMSI                        : 206100000000001
MGW router                  : 300
Mobile Gateway              : 10.0.0.29
APN                         : full.dotted.apn.mnc010.mcc206.gprs
Last move time              : 2014/03/24 15:38:52
-------------------------------------------------------------------------------
No. of UE: 1
 
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnels local-ip 10.1.1.1 remote-ip 239.0.0.2 isa-group 1 
===============================================================================
Soft GRE tunnels
===============================================================================
Remote IP address           : 239.0.0.2
Local IP address            : 10.1.1.1
ISA group ID                : 1
ISA group member ID         : 5
Time established            : 2014/03/24 15:38:52
Number of UE                : 1
Access Point MAC            : 00:00:00:00:00:01
AP MAC learn failed         : false
 
Tunnel QoS
----------
Operational state           : active
Number of UE                : 1
Remaining hold time (s)     : N/A
-------------------------------------------------------------------------------
No. of tunnels: 1
 
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnels local-ip 10.1.1.1 remote-ip 239.0.0.2 isa-group 1 member 5 
===============================================================================
Soft GRE tunnels
===============================================================================
Remote IP address           : 239.0.0.2
Local IP address            : 10.1.1.1
ISA group ID                : 1
ISA group member ID         : 5
Time established            : 2014/03/24 15:38:52
Number of UE                : 1
Access Point MAC            : 00:00:00:00:00:01
AP MAC learn failed         : false
 
Tunnel QoS
----------
Operational state           : active
Number of UE                : 1
Remaining hold time (s)     : N/A
-------------------------------------------------------------------------------
No. of tunnels: 1
 
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnels local-ip 10.1.1.1 remote-ip 239.0.0.2 isa-group 1 member 5 summary 
===============================================================================
Soft GRE tunnels summary
===============================================================================
Remote IP address - Local IP address
-------------------------------------------------------------------------------
239.0.0.2 - 10.1.1.1
-------------------------------------------------------------------------------
No. of tunnels: 1
 
 
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnels local-ip 10.1.1.1 remote-ip 239.0.0.2 isa-group 1 member 5 detail  
===============================================================================
Soft GRE tunnels
===============================================================================
Remote IP address           : 239.0.0.2
Local IP address            : 10.1.1.1
ISA group ID                : 1
ISA group member ID         : 5
Time established            : 2014/03/24 15:38:52
Number of UE                : 1
Access Point MAC            : 00:00:00:00:00:01
AP MAC learn failed         : false
 
Tunnel QoS
----------
Operational state           : active
Number of UE                : 1
Remaining hold time (s)     : N/A
Service Access Points(SAP)
===============================================================================
Service Id         : 2147483650               
SAP                : 5/1/lo-gre:1             Encap             : q-tag
Description        : Internal SAP
Admin State        : Up                       Oper State        : Up
Flags              : None
Multi Svc Site     : None                     
Last Status Change : 03/24/2014 15:03:48      
Last Mgmt Change   : 03/24/2014 15:14:00      
-------------------------------------------------------------------------------
Encap Group Specifics
-------------------------------------------------------------------------------
Encap Group Name   : _tmnx_SHAPER_GR000       Group Type        : ISID
Qos-per-member     : TRUE                     
Members            :
1
-------------------------------------------------------------------------------
QOS
-------------------------------------------------------------------------------
E. qos-policy      : 1                        Q Frame-Based Acct: Disabled
E. Sched Policy    :                          E. Agg-limit      : -1
                                              Limit Unused BW   : Disabled
-------------------------------------------------------------------------------
Encap Group Member 1 Base Statistics
-------------------------------------------------------------------------------
Last Cleared Time     : N/A
 
Forwarding Engine Stats
                        Packets                 Octets
For. InProf           : 0                       0
For. OutProf          : 0                       0
Dro. InProf           : 0                       0
Dro. OutProf          : 0                       0
-------------------------------------------------------------------------------
Encap Group Member 1 Queue Statistics
-------------------------------------------------------------------------------
Packets                 Octets
 
Egress Queue 1
For. InProf           : 0                       0
For. OutProf          : 0                       0
Dro. InProf           : 0                       0
Dro. OutProf          : 0                       0
===============================================================================
-------------------------------------------------------------------------------
No. of tunnels: 1
 

tunnels

Syntax 
tunnels [local-ipip-address] [remote-ip ip-address] [isa-group wlan-gw-group-id] [member [1 to 255]] [summary] [detail]
tunnels local-ip ip-address remote-ip ip-address ue
Context 
show>router>wlan-gw
Description 

This command displays tunnel operation information.

Parameters 
ip-address
Specifies the local IP address of this system that is the destination IP address in the tunnel header of received packets.
Values—

ip-address:

ipv4-address - a.b.c.d

ipv6-address :

x:x:x:x:x:x:x:x (eight 16-bit pieces)

x:x:x:x:x:x:d.d.d.d

x - [0 to FFFF]H

d - [0 to 255]D

 

ip-address
Specifies the remote IP address of the Mobile Gateway that is the source IP address in the tunnel header of received packets.
Values—

ip-address:

ipv4-address - a.b.c.d

ipv6-address :

x:x:x:x:x:x:x:x (eight 16-bit pieces)

x:x:x:x:x:x:d.d.d.d

x - [0 to FFFF]H

d - [0 to 255]D

 

wlan-gw-group-id
Specifies the identifier of the WLAN gateway ISA group that terminates GRE for this group interface.
Values—
1 to 4

 

member —
Specifies the identifier of this WLAN gateway ISA group member.
Values—
1 to 255

 

summary—
Displays a summary of the specified parameters.
detail—
Displays detailed information.
ue—
Displays information for the specified user equipment.
Output 

The following output is an example of WLAN-GW tunnel information.

Sample Output
Note:

The remote/local IP addresses are locally generated for VLAN tunnels.

show router 50 wlan-gw tunnels
===============================================================================
Access Point tunnels
===============================================================================
Remote IP address           : fe80::3e8f:ffff:fe00:1901
Local IP address            : fe80::ff:fe02:202
ISA group ID                : 1
ISA group member ID         : 4
Time established            : 2015/01/07 17:42:01
Number of UE                : 1
Access Point MAC            : 00:00:00:00:00:05
AP MAC learn failed         : false
Encapsulation               : vlan
VLAN tag 1                  : 1000
VLAN tag 2                  : (None)
-------------------------------------------------------------------------------
No. of tunnels: 1
===============================================================================

radius-server-policy

Syntax 
radius-server-policy policy-name [acct-on-off]
radius-server-policy policy-name associations
radius-server-policy policy-name msg-buffer-stats
radius-server-policy policy-name statistics
radius-server-policy [acct-on-off]
Context 
show>aaa
Description 

This command displays RADIUS server policy information.

Parameters 
policy-name—
Displays information pertaining to the specified policy name.
associations—
Displays the association between the RADIUS server policy and the applications referencing the policy (RADIUS proxy, route downloader, authentication policy, accounting policy, dynamic services policy).
statistics—
Displays statistics of the RADIUS server policy and RADIUS servers referenced in the policy.
acct-on-off —
Displays the acct-on-off operational state for the RADIUS server policy.
msg-buffer-stats—
Displays statistics for the RADIUS message buffering.
Output 

The following is an example of RADIUS server policy information.

Sample Output
show aaa radius-server-policy "aaa-server-policy-1" 
===============================================================================
RADIUS server policy "aaa-server-policy-1"
===============================================================================
Description                 : Radius AAA server policy
Acct Request script policy  : (Not Specified)
Auth Request script policy  : (Not Specified)
Accept script policy        : script-policy-1
Acct-On-Off                 : Enabled (state Not Blocked)
-------------------------------------------------------------------------------
RADIUS server settings
-------------------------------------------------------------------------------
Router                      : "Base"
Source address              : (Not Specified)
Access algorithm            : direct
Retry                       : 3
Timeout (s)                 : 5
Hold down time (s)          : 30
Last management change      : 02/20/2013 13:32:05
===============================================================================
===============================================================================
Servers for "aaa-server-policy-1"
===============================================================================
Idx Name                             Address         Port        Oper State
                                                     Auth/Acct   
-------------------------------------------------------------------------------
1   server-1                         172.16.1.1      1812/1813   in-service
===============================================================================
 
 
# show aaa radius-server-policy acct-on-off 
==============================================================================
RADIUS server policies AcctOnOff state
==============================================================================
Name                                    OperState      LastStateChange
------------------------------------------------------------------------------
aaa-server-policy-1                     on             02/20/2013 21:23:57
aaa-server-policy-2                     NotApplicable  NotApplicable
aaa-server-policy-3                     sendAcctOn     NotApplicable
aaa-server-policy-4                     off            02/20/2013 21:40:57
------------------------------------------------------------------------------
No. of policies: 4
==============================================================================
 
# show aaa radius-server-policy "aaa-server-policy-1" acct-on-off 
===============================================================================
RADIUS server policy "aaa-server-policy-1" AcctOnOff info
===============================================================================
Oper state                  : on
Session Id                  : 242FFF0000000451253EED
Last state change           : 02/20/2013 21:23:57
Trigger                     : startUp
Server                      : "server-1"
===============================================================================
 
 
show aaa radius-server-policy "aaa-server-policy-3" msg-buffer-stats                                   
===============================================================================
RADIUS server policy "aaa-server-policy-3" message buffering stats
===============================================================================
buffering acct-interim      : enabled
  min interval (s)          : 60
  max interval (s)          : 3600
  lifetime (hrs)            : 12
buffering acct-stop         : enabled
  min interval (s)          : 60
  max interval (s)          : 3600
  lifetime (hrs)            : 12
 
Statistics
-------------------------------------------------------------------------------
Total acct-stop messages in buffer                        : 6
Total acct-interim messages in buffer                     : 10
Total acct-stop messages dropped (lifetime expired)       : 0
Total acct-interim messages dropped (lifetime expired)    : 0
Last buffer clear time                                    : N/A
Last buffer statistics clear time                         : N/A
-------------------------------------------------------------------------------
===============================================================================
 
 
show aaa radius-server-policy "aaa-server-policy-1" statistics 
===============================================================================
RADIUS server policy "aaa-server-policy-1" statistics
===============================================================================
Tx transaction requests                         : 383
Rx transaction responses                        : 383
Transaction requests timed out                  : 0
Transaction requests send failed                : 0
Packet retries                                  : 0
Transaction requests send rejected              : 0
Authentication requests failed                  : 0
Accounting requests failed                      : 0
Ratio of access-reject over auth responses      : 0%
Transaction success ratio                       : 100%
Transaction failure ratio                       : 0%
Statistics last reset at                        : n/a
 
Server 1 "server-1" address 172.16.1.1 auth-port 1812 acct-port 1813
-------------------------------------------------------------------------------
Tx request packets                              : 383
Rx response packets                             : 383
Request packets timed out                       : 0
Request packets send failed                     : 0
Request packets send failed (overload)          : 0
Request packets waiting for reply               : 0
Response packets with invalid authenticator     : 0
Response packets with invalid msg authenticator : 0
Authentication packets failed                   : 0
Accounting packets failed                       : 0
Avg auth response delay (10 100 1K 10K) in ms   :   27.1   22.8   22.8   22.8
Avg acct response delay (10 100 1K 10K) in ms   :   6.24   12.5   11.5   11.5
Statistics last reset at                        : n/a
 
===============================================================================
 
 
show aaa radius-server-policy "myRadiusServerPolicy1" associations
===============================================================================
RADIUS Proxy Associations
===============================================================================
Router RADIUS Proxy Server Purpose Username
-------------------------------------------------------------------------------
Base myProxyServerBase acc (default)
vprn10 myProxyServer1 acc (default)
-------------------------------------------------------------------------------
No. of associations: 2
 
 
show aaa radius-server-policy "aaa-server-policy-1" associations 
===============================================================================
RADIUS Proxy Associations
===============================================================================
Router RADIUS Proxy Server Purpose Username
-------------------------------------------------------------------------------
Base   myProxyServerBase   acc     (default)
-------------------------------------------------------------------------------
No. of associations: 1
===============================================================================
No route downloader entries found.
===============================================================================
Authentication Policy Associations
===============================================================================
Authentication Policy
-------------------------------------------------------------------------------
auth-policy-1
-------------------------------------------------------------------------------
No. of associations: 1
===============================================================================
===============================================================================
Accounting Policy Associations
===============================================================================
Accounting Policy
-------------------------------------------------------------------------------
acct-policy-1
acct-policy-2
-------------------------------------------------------------------------------
No. of associations: 2
===============================================================================
No dynamic-services policy entries found.

wlan-gw-group

Syntax 
wlan-gw-group wlan-gw-group-id
wlan-gw-group wlan-gw-group-id associations
wlan-gw-group wlan-gw-group-id member member-id
wlan-gw-group wlan-gw-group-id member member-id resource-statistics
wlan-gw-group wlan-gw-group-id member member-id statistics [type type] [non-zero-value-only]
wlan-gw-group
Context 
show>isa
Description 

This command displays WLAN-GW group information, including WLAN-GW tunnels.

Parameters 
wlan-gw-group-id—
Displays information about the specified WLAN-GW group ID.
Values—
1 to 4

 

associations—
Displays information about associations for the specified WLAN-GW group ID.
member member-id—
Displays information about the WLAN-GW-specific status and basic statistics information about the specified member.
Values—
1 to 255

 

type type
Displays a reduced output to only show statistics of the specified type.
Values—
packet-errors | host-errors | bd-errors | forwarding | reassembly | aa | radius | arp | dhcp | dhcp6 | icmp | icmp6

 

non-zero-value-only —
Displays a reduced output to only show statistics whose value is bigger than zero.
resource-statistics—
Displays the resource usage on the specified group member.
statistics—
Displays statistics information about the members of the specified WLAN-GW group.
Output 

The following output is an example of ISA WLAN-GW group information.

Sample Output
*A:Dut-B>config>isa>wlan-gw-group$ show isa wlan-gw-group 4 
===============================================================================
WLAN Gateway group 4
===============================================================================
Administrative state        : in-service
Operational state           : in-service
Degraded                    : false
Active IOM limit            : 0
Active MDA limit            : 14
Port policy                 : (Not Specified)
Tunnel port policy          : (Not Specified)
Dsm ISA AA group            : (Not Specified)
Last Mgmt Change            : 06/28/2017 15:07:34
-------------------------------------------------------------------------------
NAT specific information for ISA group 4
-------------------------------------------------------------------------------
Reserved sessions           : 0
High Watermark (%)          : (Not Specified)
Low Watermark (%)           : (Not Specified)
Accounting policy           : (Not Specified)
UPnP mapping limit          : 524288
Suppress LsnSubBlksFree     : false
LSN support                 : enabled
Last Mgmt Change            : 06/28/2017 15:06:40
-------------------------------------------------------------------------------
===============================================================================
===============================================================================
ISA Group 4 members
===============================================================================
Group Member     State          Mda  Addresses  Blocks     Se-% Hi Se-Prio
-------------------------------------------------------------------------------
4     1          active         3/1  0          0          < 1  N  0
4     2          active         3/2  0          0          < 1  N  0
4     3          active         4/1  0          0          < 1  N  0
4     4          active         4/2  0          0          < 1  N  0
4     5          active         5/1  0          0          < 1  N  0
4     6          active         5/2  0          0          < 1  N  0
4     7          active         6/1  0          0          < 1  N  0
4     8          active         6/2  0          0          < 1  N  0
4     9          active         7/1  0          0          < 1  N  0
4     10         active         7/2  0          0          < 1  N  0
4     11         active         8/1  0          0          < 1  N  0
4     12         active         8/2  0          0          < 1  N  0
4     13         active         9/1  0          0          < 1  N  0
4     14         active         9/2  0          0          < 1  N  0
-------------------------------------------------------------------------------
No. of members: 14

isa-filter

Syntax 
isa-filter
isa-filter name
isa-filter name associations
isa-filter name ipv4
isa-filter name ipv6
Context 
show>subscr-mgm
Description 

This command displays ISA filter information.

Parameters 
name—
Specifies the ISA filter name up to 32 characters.
associations—
Displays associated information about the specified ISA filter name.
ipv4—
Display IPv4 ISA filter information for the specified ISA filter name.
ipv6—
Display IPv6 ISA filter information for the specified ISA filter name.

isa-policer

Syntax 
isa-policer policer-name
isa-policer policer-name associations
isa-policer
Context 
show>subscr-mgm
Description 

This command displays ISA policer information.

Parameters 
policer-name—
Specifies the ISA policer name up to 32 characters.
associations—
Displays associated information about the specified ISA policer name.

brg-profile

Syntax 
brg-profile name
brg-profile
brg-profile name associations
Context 
show>subscr-mgmt>vrgw>brg
Description 

This command displays Bridged Residential Gateway profile information.

Parameters 
name—
Specifies the BRG profile name up to 32 characters.
associations—
Displays associated information about the specified BRG profile name.

gateway

Syntax 
gateway brg-id brg-ident bindings [mac ieee-address]
gateway brg-id brg-ident host mac ieee-address ip ip-address
gateway brg-id brg-ident hosts
gateway brg-id brg-ident standby-ip-addresses
Context 
show>subscr-mgmt>vrgw>brg
Description 

This command lists all addresses that the vRGW currently keeps aside for data-triggered host creation.

Parameters 
brg-ident
Displays information about the BRG identifier up to 32 characters.
ieee-address—
Displays information about associated home-aware pool IP address bindings.
host—
Displays information about a particular host associated with a gateway.
hosts
Displays information about the hosts of a gateway.
standby-ip-addresses—
Displays associated home-aware pool standby IP addresses.
Output 

The following is an example of subscriber management BRG standby IP addresses.

Sample Output
Node# show subscriber-mgmt brg gateway brg-id "00:00:5e:00:53:05" standby-ip-addresses
===============================================================================
Bridged Residential Gateway home-aware pool standby IP addresses
===============================================================================
Home-aware pool : 00:00:5e:00:53:05
-------------------------------------------------------------------------------
192.0.2.10
192.0.2.11
192.0.2.12
-------------------------------------------------------------------------------
No. of standby IP addresses: 3
===============================================================================

gtp-session

Syntax 
gtp-session imsi imsi apn apn-string | gtp-session [mgw-address ip-address] [mgw-router router-instance] [remote-control-teid teid] [local-control-teid teid] [detail]
gtp-session imsi imsi
gtp-statistics
Context 
show>subscr-mgmt>wlan-gw
Description 

This command displays GTP session information

Parameters 
imsi
Specifies the IMSI (International Mobile Subscriber Identity) of this UE.
apn-string
Specifies the APN (Access Point Name).
ip-address
Specifies the IP address of the Mobile Gateway, \that is the source IP address in the tunnel header of received packets.
router-instance
Specifies the identifier of the virtual router instance where the GTP tunnel is terminated.
teid
Specifies the remote control plane Tunnel Endpoint Identifier (TEID).
teid
Specifies the local control plane TEID.
detail—
Displays detailed information.
Output 

The following is an example of subscriber management WLAN-GW GTP session information.

Sample Output
*A:Dut-C# show subscriber-mgmt wlan-gw gtp-session
===============================================================================
GTP sessions
===============================================================================
IMSI                        : 206100000000001
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : 300
Mobile Gateway address      : 10.20.1.2
Remote control TEID         : 66592
Local control TEID          : 4291821824
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
IMSI                        : 206100000000002
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : 300
Mobile Gateway address      : 10.20.1.2
Remote control TEID         : 66608
Local control TEID          : 4290773248
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
IMSI                        : 206100000000033
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : "Base"
Mobile Gateway address      : 10.20.1.2
Remote control TEID         : 66560
Local control TEID          : 4293918976
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
IMSI                        : 206100000000034
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : "Base"
Mobile Gateway address      : 10.20.1.2
Remote control TEID         : 66576
Local control TEID          : 4292870400
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
-------------------------------------------------------------------------------
No. of GTP sessions: 4
===============================================================================
*A:Dut-C#
*A:Dut-C# show subscriber-mgmt wlan-gw gtp-session imsi 206100000000001 apn full.dotted.apn.mnc010.mcc206.gprs
===============================================================================
GTP session
===============================================================================
IMSI                        : 206100000000001
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : 300
Mobile Gateway address      : 10.20.1.2
Remote control TEID         : 66592
Local control TEID          : 4291821824
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
Bearer 5
  rem TEID                  : 1073808421
  loc TEID                  : 4291821861
  uplink GBR (kbps)         : 0
  uplink MBR (kbps)         : 4992
  downlink GBR (kbps)       : 0
  downlink MBR (kbps)       : 1984
  QoS Class ID              : 8
  alloc/ret priority        : 1
===============================================================================
*A:Dut-C#
*A:Dut-C# show subscriber-mgmt wlan-gw gtp-session imsi 206100000000001
===============================================================================
GTP sessions
===============================================================================
IMSI                        : 206100000000001
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : 300
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66592
Local control TEID          : 4291821824
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
Bearer 5
  rem TEID                  : 1073808421
  loc TEID                  : 4291821861
  uplink GBR (kbps)         : 0
  uplink MBR (kbps)         : 4992
  downlink GBR (kbps)       : 0
  downlink MBR (kbps)       : 1984
  QoS Class ID              : 8
  alloc/ret priority        : 1
-------------------------------------------------------------------------------
No. of GTP sessions: 1
===============================================================================
*A:Dut-C#
*A:Dut-C# show subscriber-mgmt wlan-gw gtp-session mgw-address 10.20.12
===============================================================================
GTP sessions
===============================================================================
IMSI                        : 206100000000001
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : 300
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66592
Local control TEID          : 4291821824
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
IMSI                        : 206100000000002
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : 300
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66608
Local control TEID          : 4290773248
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
IMSI                        : 206100000000033
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : "Base"
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66560
Local control TEID          : 4293918976
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
IMSI                        : 206100000000034
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : "Base"
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66576
Local control TEID          : 4292870400
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
-------------------------------------------------------------------------------
No. of GTP sessions: 4
===============================================================================
*A:Dut-C#
*A:Dut-C# show subscriber-mgmt wlan-gw gtp-session mgw-address 10.20.12 mgw-router "Base"
===============================================================================
GTP sessions
===============================================================================
IMSI                        : 206100000000033
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : "Base"
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66560
Local control TEID          : 4293918976
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
IMSI                        : 206100000000034
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : "Base"
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66576
Local control TEID          : 4292870400
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
-------------------------------------------------------------------------------
No. of GTP sessions: 2
===============================================================================
*A:Dut-C#
*A:Dut-C# show subscriber-mgmt wlan-gw gtp-session mgw-router 300
===============================================================================
GTP sessions
===============================================================================
IMSI                        : 206100000000001
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : 300
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66592
Local control TEID          : 4291821824
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
IMSI                        : 206100000000002
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : 300
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66608
Local control TEID          : 4290773248
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
-------------------------------------------------------------------------------
No. of GTP sessions: 2
===============================================================================
*A:Dut-C#
*A:Dut-C# show subscriber-mgmt wlan-gw gtp-session remote-control-teid 66560
===============================================================================
GTP sessions
===============================================================================
IMSI                        : 206100000000033
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : "Base"
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66560
Local control TEID          : 4293918976
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
-------------------------------------------------------------------------------
No. of GTP sessions: 1
===============================================================================
*A:Dut-C# show subscriber-mgmt wlan-gw gtp-session local-control-teid 4292870400
===============================================================================
GTP sessions
===============================================================================
IMSI                        : 206100000000034
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : "Base"
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66576
Local control TEID          : 4292870400
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
-------------------------------------------------------------------------------
No. of GTP sessions: 1
===============================================================================
*A:Dut-C#
*A:Dut-C# show subscriber-mgmt wlan-gw gtp-session mgw-address 10.20.12 mgw-router "Base" local-control-teid 4292870400 remote-control-teid 66576
===============================================================================
GTP sessions
===============================================================================
IMSI                        : 206100000000034
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : "Base"
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66576
Local control TEID          : 4292870400
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
-------------------------------------------------------------------------------
No. of GTP sessions: 1
===============================================================================
*A:Dut-C# show subscriber-mgmt wlan-gw gtp-session mgw-address 10.20.12 mgw-router "Base" local-control-teid 4292870400 remote-control-teid 66576 detail
===============================================================================
GTP sessions
===============================================================================
IMSI                        : 206100000000034
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : "Base"
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66576
Local control TEID          : 4292870400
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
Bearer 5
  rem TEID                  : 1073808405
  loc TEID                  : 4292870437
  uplink GBR (kbps)         : 0
  uplink MBR (kbps)         : 4992
  downlink GBR (kbps)       : 0
  downlink MBR (kbps)       : 1984
  QoS Class ID              : 8
  alloc/ret priority        : 1
-------------------------------------------------------------------------------
No. of GTP sessions: 1
===============================================================================
*A:Dut-C#

gtp-statistics

Syntax 
gtp-statistics
Context 
show>subscr-mgmt>wlan-gw
Description 

This command displays GTP statistics.

Output 

The following is an example of WLAN-GW GTP statistics.

Sample Output
*A:Dut-C# show subscriber-mgmt wlan-gw gtp-statistics
===============================================================================
GTP statistics
===============================================================================
tx echo requests                                        : 33
tx echo responses                                       : 0
tx errors                                               : 0
rx echo requests                                        : 0
rx echo responses                                       : 33
rx errors                                               : 0
rx version not supported                                : 0
rx zero TEID responses                                  : 0
path faults                                             : 0
path restarts                                           : 0
tx invalid msgs                                         : 0
tx create PDP context requests                          : 4
tx create PDP context responses                         : 0
tx delete PDP context requests                          : 0
tx delete PDP context responses                         : 0
tx create session requests                              : 0
tx create session responses                             : 0
tx delete session requests                              : 0
tx delete session responses                             : 0
tx delete bearer requests                               : 0
tx delete bearer responses                              : 0
tx create bearer responses                              : 0
tx update bearer responses                              : 0
tx modify bearer requests                               : 0
tx modify bearer responses                              : 0
tx error indication count                               : 0
rx invalid msgs                                         : 0
rx create PDP context requests                          : 0
rx create PDP context responses                         : 4
rx delete PDP context requests                          : 0
rx delete PDP context responses                         : 0
rx create session requests                              : 0
rx create session responses                             : 0
rx delete session requests                              : 0
rx delete session responses                             : 0
rx delete bearer requests                               : 0
rx delete bearer responses                              : 0
rx create bearer requests                               : 0
rx update bearer requests                               : 0
rx modify bearer requests                               : 0
rx modify bearer responses                              : 0
rx error indication count                               : 0
rx invalid pkt length                                   : 0
rx unknown pkts                                         : 0
rx missing IE pkts                                      : 0
rx bad IP header pkts                                   : 0
rx bad UDP header pkts                                  : 0
rx discarded pkts                                       : 0
rx in-session discarded pkts                            : 0
rx pkts                                                 : 37
tx discarded pkts                                       : 0
tx pkts                                                 : 37
===============================================================================
*A:Dut-C#

ssid

Syntax 
ssid
Context 
show>subscr-mgmt>wlan-gw
Description 

This command displays SSID information.

statistics

Syntax 
statistics
Context 
show>subscr-mgmt>wlan-gw
Description 

This command displays statistics information.

tunnels

Syntax 
tunnels [router router-name] [remote-ip ip-address] [local-ip ip-address] [encapsulation encap [encap...(upto 3 max)]] [qtag1 qtag] [qtag2 qtag] [ap-sap sap-id] [min-num-ue minimum] [max-num-ue maximum] [ap-mac-learn-failed {true | false}] [get-num-results] [addr-family family] [ue-type ue-type [ue-type...(upto 5 max)]]
Context 
show>subscr-mgmt>wlan-gw
Description 

This command displays all the WLAN-GW tunnels matching the specified criteria. Unlike the similar command in the show>router>vprn context, this command also includes information on tunnels containing ISA-only UEs such as migrant, DSM and l2-wholesale.

Parameters 
router-name —
The name or ID of the router where the tunnel terminates.
ip-address —
The IPv4 or IPv6 address indicating one, or both, of the tunnel endpoint IP addresses.
encap —
The tunnel encapsulation type, for example GRE, L2TP, or VLAN.
qtag —
The Q-tags specifying the l2-ap-delimiting tags.
sap-id —
The SAP-ID of the l2-ap SAP.
minimum—
The minimum number of UEs on the tunnel, after applying the UE type filter.
maximum—
The maximum number of UEs on the tunnel, after applying the UE type filter.
ap-mac-learn-failed true | false —
Filters the results to display only tunnels that have learned the AP-MAC (false) or have not learned the AP-MAC (true).
get-num-results—
Displays the total number of tunnels at the end of each tunnel record.
family—
Specifies the tunnel’s IP family type (IPv4 or IPv6).
ue-type—
Filters the display based on the presence of specified UE types and is used in conjunction with min-num-ue and max-num-ue.
Values—
migrant, dsm, l2w, esm, or xcon

 

Output 

The following is an example of WLAN-GW tunnels.

Sample Output
Node# show subscriber-mgmt wlan-gw tunnels
===============================================================================
Access Point tunnels
===============================================================================
Router                      : 50
Encapsulation               : gre
Remote IP address           : 192.0.2.1
Local IP address            : 192.0.2.2
-------------------------------------------------------------------------------
First move time             : N/A
ISA group ID                : 1
ISA member ID               : 3
Interface                   : grp-vprn_ue-2/1/2:50
Interface Service ID        : 4
AP MAC address              : 00:53:00:00:00:05
AP MAC learn failed         : false
AP SAP                      : (Unknown)
Remote UDP port             : N/A
Tag 1                       : N/A
Tag 2                       : N/A
No. of UE                   : 1
No. of migrant UE           : 0
No. of DSM UE               : 1
No. of layer-2 wholesale UE : 0
No. of cross-connect UE     : 0
No. of ESM UE               : 0
-------------------------------------------------------------------------------
No. of Access point tunnels: 1
===============================================================================

ue

Syntax 
ue [vlan qtag] [mpls-label label] [retail-svc-id service-id] [ssid service-set-id] [previous-access-point ip-address] [bd bridge-id]
ue mac ieee-address [bd bridge-id]
Context 
show>subscr-mgmt>wlan-gw
Description 

This command displays user equipment (UE) information.

Parameters 
qtag
Displays information about the VLAN Q-tag present in the traffic received from this UE.
Values—
1 to 4095

 

label
Displays information about the MPLS label present in the traffic received from this UE.
service-id—
Specifies an existing service ID. If no svc-id is specified then it indicates that the interface is a network interface in the Base router instance.

Values—
{id | svc-name}

id:

1 to 2147483647

svc-name:

Specifies an existing service name up to 64 characters (svc-name is an alias for input only. The svc-name gets replaced with an id automatically by SR OS in the configuration)

 

service-set-id
Displays information about the Service Set ID (SSID) of this UE.
ip-address
Displays information about the IP address of the previous Access Point (AP) of this UE.
bridge-id—
Displays specified HLE bridge domain information of this UE.
Values—
1 to 4294967295

 

ieee-address
Displays information about the MAC address of this UE.
Values—
xx:xx:xx:xx:xx:xx or xx-xx-xx-xx-xx-xx

 

Output 

The following displays WLAN-GW information.

Sample Output
System# show subscriber-mgmt wlan-gw ue
======================================================================
User Equipments
======================================================================
MAC address                 : 00:02:00:00:00:39
----------------------------------------------------------------------
VLAN Q-tag                  : 1
MPLS label                  : (Not Specified)
Tunnel router               : 50
Tunnel remote IP address    : 20C9::7:1:2
Tunnel local IP address     : 2032::1:1:7
Retail service              : N/A
SSID                        : 1
Previous Access Point IP    : (Not Specified)
IMSI                        : (Not Specified)
Last move time              : 2013/07/02 07:45:31
 
----------------------------------------------------------------------
No. of UE: 1
======================================================================
System#

11.25.2.8.2. Debug Commands

call-trace

Syntax 
call-trace
Context 
debug
Description 

This command enables the context to set up various call-trace debug sessions.

wlan-gw

Syntax 
[no] wlan-gw
Context 
debug
Description 

This node contains all the parameters to set up specific call-trace debug sessions for WLAN-GW. The no form of this command will stop all configured WLAN-GW traces.

statistic

Syntax 
statistic type type name name
no statistic
Context 
debug>wlan-gw>group
Description 

This command enables debugging of the specified statistic. The first packet that causes an increase of the specified statistic is shown in debug output. After the first packet, debugging of the counter is stopped.

Parameters 
type—
Displays the type of statistic to be debugged; for example, DHCP or Radius.
Values—
packet-errors | host-errors | bd-errors | forwarding | reassembly | aa | radius | arp | dhcp | dhcp6 | icmp | icmp6

 

name
Specifies the name, up to 256 characters, of the statistic within that group. For a complete list, see the command show isa wlan-gw-group wlan-gw-group-id member member-id statistics.

ue

Syntax 
ue ieee-address [profile trace-profile-name]
no ue ieee-address
Context 
debug>call-trace>wlan-gw
Description 

This command starts tracing the UE with the specified MAC address. The trace is started with default parameters or optionally parameters specified in the trace-profile.The no form of this command stops the trace and make sure no new traces are started.

Parameters 
ieee-address—
Displays information about the MAC address of this UE.
trace-profile-name
Specifies the name of a configured trace profile.

11.25.2.8.3. Tools Commands

acct-on

Syntax 
acct-on [radius-server-policy policy-name] [force]
Context 
tools>perform>aaa
Description 

This command triggers a RADIUS Accounting-On message:

  1. for all radius-server-policies that have acct-on-off configured.
  2. for the specified radius-server-policy if the acct-on-off is configured

The Accounting-On message is not sent when the last successful event for the RADIUS server policy was an Accounting-On message. In this case, an Accounting-Off should be sent first. By specifying the keyword force, this is overruled.

Parameters 
policy-name
Specifies the radius-server-policy for which the Accounting-On should be sent.
force—
Sends an Accounting-On also if the last successful event was an Accounting-On.

acct-off

Syntax 
acct-off [radius-server-policy policy-name] [force] [acct-terminate-cause number]
Context 
tools>perform>aaa
Description 

This command triggers a RADIUS Accounting-Off message:

  1. for all radius-server-policies that have acct-on-off configured.
  2. for the specified radius-server-policy if the acct-on-off is configured

The Accounting-Off message is not sent when the last successful event for the radius server policy was an Accounting-Off message. In this case, an Accounting-On should be sent first. By specifying the keyword force, this is overruled.

Parameters 
policy-name
Specifies the radius-server-policy for which the Accounting-Off should be sent.
force—
Sends an Accounting-On also if the last successful event was an Accounting-Off.
number
Overrides the default Acct-Terminate-Cause (User-Request) in the Accounting-Off message.

radius-acct-terminate-cause

Syntax 
radius-acct-terminate-cause
Context 
tools>dump>aaa
Description 

This command shows all available termination causes and their respective number values. The TermCause is equivalent to VSA 226 alc-error-code numeric values. The description is equivalent to VSA 227alc-error-message string.

radius-server-policy

Syntax 
radius-server-policy policy-name msg-buffer [session-id acct-session-id]
Context 
tools>perform>aaa
tools>dump>aaa
Description 

This command dumps the RADIUS message buffer content for the specified radius-server-policy:

  1. message-type (acct-interim or acct-stop)
  2. Acct-Session-Id
  3. Remaining lifetime

When specifying the session-id, the message details are displayed.

Parameters 
policy-name
Specifies the radius-server-policy for which the message buffer content should be displayed
acct-session-id
Displays the RADIUS message details for the message with specified session-id that is stored in the RADIUS message buffer

performance

Syntax 
performance mda mda-id last time-span time-unit
Context 
tools>dump>wlan-gw>isa
Description 

This command generates an overview of the processing load and data processed by the specified ISA over a period of time. The following time periods are supported:

  1. last minute with seconds granularity
  2. last hour with minutes granularity
  3. last day with hours granularity
  4. last 30 days with days granularity
Parameters 
mda-id
Specifies the MDA for getting performance measurements in format slot/mda.
Values—
slot — 1 to 10
mda — 1 to 2

 

time-span
Specifies the period for which to get measurements.
Values—
1 to 60 (sec) | 1 to 60 (min) | 1 to 24 (hrs) | 1 to 30 (days)

 

time-unit
Specifies the period for which to get measurements.
Values—
sec | min | hrs | days

 

Output 

This command displays performance information.

Sample Output
Node# /tools dump wlan-gw isa performance mda 2/1 last 5 min
===============================================================================
Measurements for last 5 minutes on Slot #2 MDA #1
===============================================================================
Timestamp            |     Wait     Idle     Work | Total jobs |    Total data
---------------------+----------------------------+------------+---------------
01/22/2018 10:14:04  |   99.47%    0.53%    0.00% |          0 |          - -
01/22/2018 10:13:41  |   99.46%    0.54%    0.00% |          3 |          3 Kb
01/22/2018 10:12:41  |   99.47%    0.53%    0.00% |          0 |          - -
01/22/2018 10:11:41  |   99.47%    0.53%    0.00% |          0 |          - -
01/22/2018 10:10:41  |   99.45%    0.55%    0.00% |          0 |          - -
===============================================================================

ue

Syntax 
ue [wlan-gw-group wlan-gw-group-id] [mda mda-id] [next-index index] [summary] [detail] [bd bridge-id] [ue-mac ieee-address] [ue-vlan vlan] [state-description state] [tunnel-router router-instance] [tunnel-source-ip ip-address] [tunnel-destination-ip ip-address] [tunnel-type tunnel-type] [ue-ip ipv4-address] [dhcp6-addr ipv6-address] [slaac-prefix ipv6-address] [aggregate-summary]
Context 
tools>dump>wlan-gw
Description 

This command dumps user equipment (UE) information.

The summary option displays a count of UEs per ISA and the aggregate-summary displays a count of matched UEs over the whole WLAN-GW.

Output 

This command displays UE information.

Sample Output
tools dump wlan-gw ue
===============================================================================
Matched 1 session on Slot #4 MDA #1
===============================================================================
UE-Mac          : 00:02:00:00:00:11     UE-vlan         : 3600
UE IP Addr      : N/A                   UE timeout      : N/A
UE IP6 Addr     : N/A
Description     : L2-user
Auth/CoA-time   : 01/07/2015 18:56:01
Tunnel MDA      : 5/1                   Tunnel Router   : 50
MPLS label      : N/A                   Shaper          : Default
Tunnel Src IP   : 203.0.113.235         Tunnel Dst IP   : 10.1.1.1
Tunnel Type     : GRE
Anchor SAP      : 4/1/nat-out-ip:2049.6
AP-Mac          : Unknown               AP-RSSI         : Unknown
AP-SSID         : Unknown
Last-forward    : 01/07/2015 18:56:01   Last-move       : None
Session Timeout : None                  Idle Timeout    : 300 sec
Acct Update     : None                  Acct Interval   : N/A
Acct Session-Id : N/A
Acct Policy     : N/A
NAT Policy      : N/A
Redirect Policy : N/A
IP Filter       : N/A
App-profile     : N/A
Rx Oper PIR     : N/A                   Rx Oper CIR     : N/A
Tx Oper PIR     : N/A                   Tx Oper CIR     : N/A
Rx Frames       : 0                     Rx Octets       : 0
Tx Frames       : 0                     Tx Octets       : 0
-------------------------------------------------------------------------------
===============================================================================
No sessions on Slot #4 MDA #2 match the query
No sessions on Slot #5 MDA #1 match the query
No sessions on Slot #5 MDA #2 match the query
 

11.25.2.8.4. Clear Commands

radius-server-policy

Syntax 
radius-server-policy policy-name msg-buffer [acct-session-id acct-session-id]
radius-server-policy policy-name statistics [msg-buffer-only]
radius-server-policy policy-name server server-index statistics
Context 
clear>aaa
Description 

This command dumps the RADIUS message buffer content for the specified radius-server-policy:

  1. message-type (acct-interim or acct-stop)
  2. Acct-Session-Id
  3. Remaining lifetime

When specifying the session-id, the message details are displayed.

Parameters 
policy-name
Specifies the radius-server-policy for which the information should be cleared.
acct-session-id
Deletes all RADIUS messages or the RADIUS message with specified session-id from the RADIUS message buffer.
msg-buffer-only—
Clears all statistics for the specified radius-server-policy: radius-server-policy statistics, RADIUS server statistics and RADIUS message buffer statistics. With the optional keyword “msg-buffer-only”, only the RADIUS message buffer statistics are cleared.
server-index
Clears the RADIUS server statistics for the specified server-index in the specified radius-server-policy.

isa-subnets

Syntax 
isa-subnets all
isa-subnets interface ip-int-name
isa-subnets prefix ipv6-address/prefix-length
Context 
clear>router>wlan-gw
Description 

This command clears specific subnets from the pool-manager. Associated UE’s is removed from the system.

When clearing the last subnet on an ISA the pool-manager will automatically allocate a new subnet with allocation-level 0%.

Parameters 
all—
Clears all the isa-subnets.
ip-int-name
Clears all the isa-subnets of a specific subscriber-interface.
ipv6-address/prefix-length—
Clears a specific IPv6 address and prefix length.

wlan-gw-group

Syntax 
wlan-gw-group group-id member member-id resource-peak-values
wlan-gw-group group-id member member-id statistics
Context 
clear>wlan-gw>isa
Description 

This command resets wlan-gw statistics per group member.

Parameters 
group-id—
Specifies the WLAN-GW group ID.
Values—
1 to 4

 

member member-id—
Specifies the member ID.
Values—
1 to 255

 

statistics—
Resets the statistics measurements to zero.
resource-peak-values—
Resets the resource peak values to the current resource measurements.