12.25. WiFi Command Reference

12.25.1. Command Hierarchies

12.25.1.1. WLAN-GW Commands

Note:

The wlan-gw commands apply only to the 7750 SR platform.

config
tunnel-query query-id [name name] [create]
no tunnel-query query-id
address-type {ipv4 | ipv6 | not-specified}
ap-mac-learn-failed {true | false | not-specified}
l2-inner-vlan q-tag
l2-outer-vlan q-tag
l2-sap sap-id
no l2-sap
local-address ip-address
max-num-ue maximum
min-num-ue minimum
no min-num-ue
remote-address ip-address
router router-instance
no router
[no] type
[no] gre
[no] l2
[no] l2tp
[no] vxlan
[no] ue-state
[no] dsm
[no] esm
[no] l2w
[no] migrant
[no] xcon
ue-query query-id [name name] [create]
no ue-query query-id
address-type {ipv4 | ipv6 | ipv4-only | ipv6-only | ipv4v6 | not-specified}
bd identifier
no bd
dhcp6-address ipv6-address
ipv4-address ip-address
mac-address ieee-address
slaac-prefix ipv6-address
[no] state
[no] cross-connect
[no] dsm
[no] esm
[no] ip-assigned
[no] l2
[no] portal
tunnel-local-address ip-address
tunnel-remote-address ip-address
tunnel-router router-instance
tunnel-type {gre | l2tp | l2 | vxlan | not-specified}
vlan tag
no vlan
wlan-gw-group wlan-gw-group-id [member member-id]
virtual-chassis-identifier dual-homing-key
configure
— router
ipv6-tcp-mss-adjust segment-size
interim-update include-counters [hold-down seconds]

12.25.1.2. ISA Commands

config
isa-filtername [type {dsm}] [create]
— no isa-filter name
default-action {drop | forward}
description description-string
entry entry-id [create]
— no entry entry-id
action {drop | forward | none}
action http-redirect rdr-url-string
— no action
description description-string
match protocol {any | icmp | tcp | udp | gre}
— no match
dst-ip ip-prefix/length
— no dst-ip
dst-port operator port-number
— no dst-port
src-ip ip-prefix/length
— no src-ip
src-port operator port-number
— no src-port
— ipv6
default-action {drop | forward}
entry entry-id [create]
— no entry entry-id
action {drop | forward | none}
action http-redirect rdr-url-string
— no action
description description-string
— no description
match protocol {any | icmp | tcp | udp}
— no match
dst-ip ip-prefix/length
— no dst-ip
dst-port operator port-number
— no dst-port
src-ip ip-prefix/length
— no src-ip
src-port operator port-number
— no src-port
isa-policer policer-name [type policer-type] [create]
— no isa-policer policer-name
action {permit-deny | priority-mark}
— no action
adaptation-rule pir {max | min | closest} [cir {max | min | closest}]
cbs burst-size
— no cbs
description description-string
mbs burst-size
— no mbs
rate rate [cir rate]
— no rate
config>service>ies service-id/vprn service-id
— subscriber-interface ip-int-name
group-interface ip-int-name [create]
group-interface ip-int-name [create] lns
group-interface ip-int-name [create] wlangw
— no group-interface ip-int-name
range start [range] end [range]
range default
— no range start [range] end [range]
authentication-policy policy-name
hold-time [hrs hours] [min minutes] [sec seconds]
— no hold-time
accounting-policy policy-name
def-app-profile profile-name
dsm-ip-filter dsm-ip-filter-name
egress-policer [policer-name]
ingress-policer policer-name
one-time-redirect url rdr-url-string port port-num
[no] shutdown
vlan start [value] end [value] retail-svc-id service-id
— no vlan start [value] end [value]
wlan-gw-group group-id
— no] shutdown

12.25.1.3. WLAN-GW Service Commands

configure
— service
— ies service-id/vprn service-id
ipv6-tcp-mss-adjust segment-size
— subscriber-interface ip-int-name
link-addr ipv6-address
— no link-addr
pool-name name
— no pool-name
[no] shutdown
ia-na
link-addr ipv6-address
— no link-addr
pool-name name
— no pool-name
[no] shutdown
lease-query [max-retry Max nbr of retries]
server ipv6-address [ipv6-address]
— no server [ipv6-address [ipv6-address]]
slaac
link-addr ipv6-address
— no link-addr
pool-name name
— no pool-name
[no] shutdown
source-ip ipv6-address
— no source-ip
watermarks high high-percentage low low-percentage
— no watermarks
wlan-gw-group nat-group-id
export ip-prefix/length
— no export
monitor ip-prefix/length
— no monitor
[no] shutdown
group-interface ip-int-name [create]
group-interface ip-int-name [create] lns
group-interface ip-int-name [create] wlangw
— no group-interface ip-int-name
brg
default-brg-profile profile-name
[no] shutdown
dhcp
ip-mtu octets
— no ip-mtu
anti-spoof {ip-mac | nh-mac}
— no anti-spoof
description description-string
def-app-profile app-profile-name
def-sla-profile sla-profile-name
def-sub-id string sub-id
def-sub-id use-auto-id
— no def-sub-id
def-sub-profile sub-profile-name
sub-ident-policy policy-name
egress
[no] agg-rate-limit
rate kilobits-per-second
— no rate
hold-time infinite
hold-time [time]
— no hold-time
qos policy-id
— no qos
scheduler-policy scheduler-policy-name
shaping {per-retailer | per-tunnel}
— no shaping
encryption-keygroup keygroup-id direction direction
— no encryption-keygroup direction direction
[no] address [ip-address | ipv6-address]
learn-ap-mac [delay-auth]
l2-ap sap-id [create]
— no l2-ap sap-id
encap-type {default | null | dot1q | qinq}
— no encap-type
[no] shutdown
l2-ap-auto-sub-id-fmt {include-ap-tags | sap-only}
l2-ap-encap-type {null | dot1q | qinq}
hold-time time in s
— no hold-time
[no] inter-vlan
trigger [data] [iapp] [control]
— no trigger
router router-instance
— no router
[no] shutdown
tcp-mss-adjust segment-size
learn-l2tp-cookie {if-match | never | always} [cookie hex string]
range start [range] end [range]
range default
— no range start [range] end [range]
authentication-policy policy-name
hold-time [hrs hours] [min minutes] [sec seconds]
dhcp
active-lease-time [hrs hours] [min minutes] [sec seconds]
initial-lease-time [hrs hours] [min minutes] [sec seconds]
l2-aware-ip-address ip-address
l2-aware-ip-address from-pool
primary-dns ip-address
primary-nbns ip-address
secondary-dns ip-address
secondary-nbns ip-address
[no] shutdown
dhcp6
active-preferred-lifetime [hrs hours] [min minutes] [sec seconds]
active-valid-lifetime [hrs hours] [min minutes] [sec seconds]
initial-preferred-lifetime [hrs hours] [min minutes] [sec seconds]
initial-valid-lifetime [hrs hours] [min minutes] [sec seconds]
[no] shutdown
accounting-policy policy-name
def-app-profile profile-name
dsm-ip-filter dsm-ip-filter-name
egress-policer [policer]
ingress-policer policer-name
one-time-redirect url rdr-url-string port port-num
[no] shutdown
idle-timeout action idle-timeout-action
http-redirect-policy policy-name
l2-service service-id
— no l2-service
description description-string
[no] shutdown
nat-policy policy-name
— no nat-policy
retail-svc-id service-id
configure
— service
— vprn service-id
ipv6-tcp-mss-adjust segment-size
interim-update include-counters [hold-down seconds]
configure
— service
— vpls service-id
— wlan-gw
description description-string
sap-template sap template
[no] shutdown

12.25.1.4. Data Plane Related Commands

config
— isa
wlan-gw-group group-id [create] [redundancy unit]
— no wlan-gw-group group-id
active-iom-limit number
active-mda-limit number
description description-string
isa-aa-group aa-group-id
iom slot-number type {[load-balancer] [ue-anchor]}
— no iom slot-number
[no] mda mda-id
nat
[no] lsn
radius-accounting-policy nat-accounting-policy
reserved num-sessions
— no reserved
upnp-mappings [upnp-mappings]
watermarks high percentage low percentage
— no watermarks
port-policy [port-policy]
[no] shutdown
tunnel-port-policy [tunnel-port-policy]
mark entity high percentage-high low percentage-low

12.25.1.5. RADIUS Server and Proxy Commands

configure
— aaa
acct-on-off-group group-name [create]
— no acct-on-off-group group-name
description description-string
radius-server-policy policy-name [create]
— no radius-server-policy policy-name
accept-script-policy policy-name
acct-on-off monitor-group group-name
acct-on-off oper-state-change [group group-name]
[no] buffering
acct-interim min min-val max max-val lifetime lifetime
acct-stop min min-val max max-val lifetime lifetime
— no acct-stop
description description-string
access-algorithm {direct | round-robin | hash-based}
interval seconds
— no interval
password password [hash | hash2| custom]
— no password
[no] shutdown
user-name user-name
— no user-name
hold-down-time [sec seconds] [min minutes] [hrs hours] [days days]
ipv6-source-address ipv6-address
router router-instance
router service-name service-name
— no router
server server-index name server-name
— no server server-index
source-address ip-address
timeout [sec seconds] [min minutes]
— no timeout
configure
— router
server server-name [address ip-address] [secret key] [hash | hash2 | custom] [create]
— no server server-name
[no] accept-coa
acct-port port
— no acct-port
auth-port port
— no auth-port
coa-script-policy script-policy-name
description description-string
configure
— router
server server-name [create] [purpose {[accounting | authentication]}] [wlan-gw-group group-id]
— no server server-name
entry [entry] [prefix-string prefix-string] [accounting-server-policy policy-name] [authentication-server-policy policy-name] [suffix-string suffix-string]
— no entry [entry] [
type [type] [vendor-id vendor-id]
— no type
cache
key packet-type {accept | request} attribute-type attribute-type [vendor vendor-id]
— no key
[no] shutdown
timeout [hrs hours] [min minutes] [sec seconds]
— no timeout
track-accounting [start] [stop] [interim-update] [accounting-on] [accounting-off]
description description-string
[no] interface interface-name
load-balance-key [vendor vendor-id [vendor-id]] attribute-type attribute-type [attribute-type]
load-balance-key source-ip-udp
python-policy name
secret secret [hash | hash2| custom]
— no secret
[no] shutdown
configure
— service
— vprn
server server-name [create] [purpose {[accounting | authentication]}] [wlan-gw-group group-id]
— no server server-name
[no] accept-coa
acct-port port
— no acct-port
entry [1..32] [prefix-string prefix-string] [accounting-server-policy policy-name] [authentication-server-policy policy-name] [suffix-string suffix-string]
— no entry [1..32]
type [type] [vendor-id vendor-id]
— no type
auth-port port
— no auth-port
cache
key packet-type {accept | request} attribute-type attribute-type [vendor vendor-id]
— no key
[no] shutdown
timeout [hrs hours] [min minutes] [sec seconds]
— no timeout
track-accounting [stop] [interim-update] [accounting-on] [accounting-off]
coa-script-policy script-policy-name
description description-string
[no] interface interface-name
load-balance-key [vendor vendor-id [vendor-id]] attribute-type attribute-type [attribute-type]
load-balance-key source-ip-udp
secret secret [hash | hash2| custom]
— no secret
[no]shutdown

12.25.1.6. LUDB Matching for RADIUS Proxy Cache

config
— subscriber-mgmt
local-user-db local-user-db-name [create]
— no local-user-db local-user-db-name
ipoe
— host
fail-action {continue | drop}
mac-format mac-format
— no mac-format
match {circuit-id | mac | remote-id}
match option [option] [option6 [option6]]
match option6 [option]
— no match
server [service service-id] name server-name
— no server

12.25.1.7. Port Policy Commands

config
port-policy policy-name [create]
— no port-policy policy-name
description description-string
egress-scheduler-policy port-sched-plcy

12.25.1.8. WIFI Aggregation and Offload – Migrant User Support Commands

configure
— subscriber-mgmt
http-redirect-policy policy-name [create]
— no http-redirect-policy policy-name
description description-string
dst-port tcp-port
— no dst-port
dst-ip ip-address protocol ip-protocol dst-port port-number
dst-ip ip-address protocol ip-protocol dst-port port-number prefix-length prefix-length
— no dst-ip ip-address protocol ip-protocol dst-port port-number
portal-hold-time seconds
url rdr-url-string
— no url

12.25.1.9. Show Commands

show
ue [ieee-address] [detail]
— router
radius-proxy-server server-name
radius-proxy-server server-name cache
radius-proxy-server server-name cache hex-key hex-string
radius-proxy-server server-name cache string-key string
radius-proxy-server server-name cache summary
radius-proxy-server server-name statistics
isa-subnets [detail]
isa-subnets [detail] interface interface-name
isa-subnets prefix ipv6-address/prefix-length
tunnel-qos [detail]
tunnel-qos remote-ip ip-address [local-ip ip-address] [detail]
tunnels local-ip ip-address remote-ip ip-address ue
tunnels [local-ip ip-address] [remote-ip ip-address] [isa-group wlan-gw-group-id] [member [1..255]] [summary] [detail]
tunnels local-ip ip-address remote-ip ip-address ue
tunnels [local-ip ip-address] [remote-ip ip-address] [isa-group wlan-gw-group-id] [member [1..255]] [summary] [detail]
tunnels local-ip ip-address remote-ip ip-address ue
show
— aaa
acct-on-off-group group-name
radius-server-policy policy-name [acct-on-off]
radius-server-policy policy-name associations
radius-server-policy policy-name msg-buffer-stats
radius-server-policy policy-name statistics
radius-server-policy [acct-on-off]
show
— isa
wlan-gw-group wlan-gw-group-id
wlan-gw-group wlan-gw-group-id associations
wlan-gw-group wlan-gw-group-id member member-id
wlan-gw-group wlan-gw-group-id member member-id resource-statistics
wlan-gw-group wlan-gw-group-id member member-id statistics [type type] [non-zero-value-only]
show
— subscriber-mgmt
isa-filter name
isa-filter name associations
isa-filter name ipv4
isa-filter name ipv6
isa-policer policer-name
isa-policer policer-name associations
— wlan-gw
ssid
tunnels [router router-name] [remote-ip ip-address] [local-ip ip-address] [encapsulation encap [encap]] [qtag1 qtag] [qtag2 qtag] [ap-sap sap-id] [min-num-ue minimum] [max-num-ue maximum] [ap-mac-learn-failed {true | false}] [get-num-results] [addr-family family] [ue-type ue-type [ue-type...(up to 5 max)]]
query-results id query-id
query-results name query-name
ue [vlan qtag] [mpls-label label] [retail-svc-id service-id] [ssid service-set-id] [previous-access-point ip-address] [bd bridge-id]
ue mac ieee-address [bd bridge-id]
query-results id query-id
query-results name query-name

12.25.1.10. Debug Commands

debug
[no] wlan-gw
— group
statistic type type name name
ue ieee-address [profile trace-profile-name]
— no ue ieee-address

12.25.1.11. Tools Commands

tools
— perform
— aaa
acct-on [radius-server-policy policy-name] [force]
acct-off acct-off [radius-server-policy policy-name] [force] [acct-terminate-cause number]
— dump
— aaa
radius-server-policy policy-name msg-buffer [session-id acct-session-id]]
— wlan-gw
— isa
performance mda mda-id last time-span time-unit
ue [wlan-gw-group wlan-gw-group-id] [mda mda-id] [next-index index] [summary] [detail] [bd bridge-id] [ue-mac ieee-address] [ue-vlan vlan] [state-description state] [tunnel-router router-instance] [tunnel-source-ip ip-address] [tunnel-destination-ip ip-address] [tunnel-type tunnel-type] [ue-ip ipv4-address] [dhcp6-addr ipv6-address] [slaac-prefix ipv6-address] [aggregate-summary]

12.25.1.12. Clear Commands

clear
— aaa
radius-server-policy policy-name msg-buffer [acct-session-id acct-session-id]
radius-server-policy policy-name statistics [msg-buffer-only]
radius-server-policy policy-name server server-index statistics
clear
— router
— wlan-gw
isa-subnets all
isa-subnets interface ip-int-name
isa-subnets prefix ipv6-address/prefix-length
clear
— wlan-gw
— isa
wlan-gw-group group-id member member-id resource-peak-values
wlan-gw-group group-id member member-id statistics

12.25.2. WIFI Aggregation and Offload Commands

12.25.2.1. WIFI Aggregation and Offload Commands

12.25.2.1.1. Generic Commands

description

Syntax 
description description-string
no description
Context 
config>aaa>acct-on-off-grp
config>aaa>radius-srv-plcy
config>isa>wlan-gw-group
config>router>radius-server>server
config>router>radius-proxy>server
config>service>vprn>radius-proxy>server
config>service>vprn>radius-server>server
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
config>service>ies>sub-if>grp-if>sap-parameters
config>service>vprn>sub-if>grp-if>sap-parameters
config>subscr-mgmt>wlan-gw>dsm>dsm-ip-filter
config>subscr-mgmt>wlan-gw>dsm>dsm-ip-filter>ipv6
config>call-trace>trace-profile
config>subscr-mgmt>isa-filter
config>subscr-mgmt>isa-filter>ipv6>entry
config>subscr-mgmt>isa-filter>entry
config>subscr-mgmt>isa-policer
Description 

This command creates a text description stored in the configuration file for a configuration context.

The description command associates a text string with a configuration context to help identify the context in the configuration file.

The no form of this command removes any description string from the context.

Parameters 
description-string—
Specifies a text string describing the entity. Allowed values are any string up to 80 characters composed of printable, 7-bit ASCII characters excluding double quotes. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes.

shutdown

Syntax 
[no] shutdown
Context 
config>router>radius-proxy>cache
config>router>radius-proxy>server>cache
config>router>radius-proxy>server
config>service>vprn>radius-proxy>server>cache
config>service>vprn>radius-proxy>server
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
config>service>ies>sub-if>wlan-gw>pool-mgr>dhcp6-client>slaac
config>service>vprn>sub-if>wlan-gw>pool-mgr>dhcp6-client>slaac
config>service>ies>sub-if>wlan-gw>pool-mgr>dhcp6-client>ia-na
config>service>vprn>sub-if>wlan-gw>pool-mgr>dhcp6-client>ia-na
config>service>ies>sub-if>wlan-gw>pool-mgr>dhcp6-client>dhcpv4-nat
config>service>vprn>sub-if>wlan-gw>pool-mgr>dhcp6-client>dhcpv4-nat
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>brg
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>brg
config>service>ies>sub-if>grp-if>brg
config>service>vprn>sub-if>grp-if>brg
Description 

This command administratively disables the entity. When disabled, an entity does not change, reset, or remove any configuration settings or statistics. Many entities must be explicitly enabled using the no shutdown command. The operational state of the entity is disabled as well as the operational state of any entities contained within. Many objects must be shut down before they may be deleted.

Unlike other commands and parameters where the default state is not indicated in the configuration file, shutdown and no shutdown are always indicated in system-generated configuration files.

The no form of this command places the entity into an administratively enabled state.

Default 

no shutdown

subscriber-mgmt

Syntax 
subscriber-mgmt
Context 
config
Description 

This command enables the context to configure subscriber management entities. A subscriber is uniquely identified by a subscriber identification string. Each subscriber can have several DHCP sessions active at any time. Each session is referred to as a subscriber host and is identified by its IP address and MAC address.

All subscriber hosts belonging to the same subscriber are subject to the same hierarchical QoS (HQoS) processing. The HQoS processing is defined in the sub-profile (the subscriber profile). A sub-profile refers to an existing scheduler policy (configured in the config>qos>scheduler-policy context) and offers the possibility to overrule the rate of individual schedulers within this policy.

Because all subscriber hosts use the same scheduler policy instance, they must all reside on the same complex.

12.25.2.1.2. WLAN-GW Commands

Note:

The wlan-gw commands apply only to the 7750 SR platform.

wlan-gw

Syntax 
[no] wlan-gw
Context 
config>subscr-mgmt
config>router
config>service>vprn
Description 

This command enables the context to configure WLAN Gateway parameters.

distributed-sub-mgmt

Syntax 
distributed-sub-mgmt
Context 
config>subscr-mgmt>wlan-gw
config>router>wlan-gw
config>service>vprn>wlan-gw
Description 

This command enables the context to configure profiles, templates and policies that can be applied to DSM subscribers.

tunnel-query

Syntax 
tunnel-query query-id [name name] [create]
no tunnel-query query-id
Context 
config>subscr-mgmt>wlan-gw
Description 

This command creates a tunnel query where filter criteria over WLAN-GW tunnels are defined. This query can later be used to retrieve the state of the tunnels and Layer 2 access points (which are modeled as tunnels) matching the configured criteria.

The no form of this command removes the query.

Parameters 
query-id—
Specifies the ID assigned to a query.
Values—
1 to 1024

 

name—
Specifies the name assigned to a query, up to 32 characters.
create—
Creates a tunnel query.

address-type

Syntax 
address-type {ipv4 | ipv6 | not-specified}
no address-type
Context 
config>subscr-mgmt>wlan-gw>tunnel-query
Description 

This command specifies the address type to match on tunnels.

The no form of this command reverts to the default.

Default 

address-type not-specified

Parameters 
ipv4—
Specifies the IPv4 address to match on tunnels.
ipv6—
Specifies the IPv6 address to match on tunnels.
not-specified—
Specifies that no address type matches on tunnels.

ap-mac-learn-failed

Syntax 
ap-mac-learn-failed {true | false | not-specified}
Context 
config>subscr-mgmt>wlan-gw>tunnel-query
Description 

This command specifies the matching criteria of tunnels based on whether or not learning the associated AP-MAC address last failed.

Default 

ap-mac-learn-failed not-specified

Parameters 
true—
Specifies matching of tunnels status where learning of the AP-MAC address succeeded.
false—
Specifies matching of tunnels status where learning of the AP-MAC address failed.
not-specified—
Specifies no matching on the AP-MAC address learning status.

calculate-counts

Syntax 
[no] calculate-counts
Context 
config>subscr-mgmt>wlan-gw>tunnel-query
Description 

This command specifies whether or not to count the number of tunnels matching the specified criteria.

Note:

Do not enable this command if the expected number of tunnels is large.

Default 

no calculate-counts

l2-inner-vlan

Syntax 
l2-inner-vlan q-tag
no l2-inner-vlan
Context 
config>subscr-mgmt>wlan-gw>tunnel-query
Description 

This command enables matching on a Layer 2 access point with a specified C-VLAN.

The no form of this command disables matching on a C-VLAN.

Default 

no l2-inner-vlan

Parameters 
q-tag—
Specifies the q-tag for the C-VLAN.
Values—
0 to 4095

 

l2-outer-vlan

Syntax 
l2-outer-vlan q-tag
no l2-outer-vlan
Context 
config>subscr-mgmt>wlan-gw>tunnel-query
Description 

This command enables matching on a Layer 2 access point with a specified S-VLAN.

The no form of this command disables matching on an S-VLAN.

Default 

no l2-outer-vlan

Parameters 
q-tag—
Specifies the q-tag for the S-VLAN.
Values—
0 to 4095

 

l2-sap

Syntax 
l2-sap sap-id
no l2-sap
Context 
config>subscr-mgmt>wlan-gw>tunnel-query
Description 

This command enables matching on Layer 2 access points active on the specified SAP.

The no form of this command disables matching on the SAP.

Default 

no l2-sap

Parameters 
sap-id—
Specifies the SAP ID. For details on SAP ID parameter values, refer to section Monitor CLI Commands in the 7450 ESS, 7750 SR, 7950 XRS, and VSR Basic System Configuration Guide.

local-address

Syntax 
local-address ip-address
no local-address
Context 
config>subscr-mgmt>wlan-gw>tunnel-query
Description 

This command enables matching on tunnels that are terminated by the specified IP address on the WLAN-GW.

The no form of this command disables matching on the local IP address.

Default 

no local-address

Parameters 
ip-address—
Specifies the IPv4 or IPv6 address.

max-num-ue

Syntax 
max-num-ue maximum
Context 
config>subscr-mgmt>wlan-gw>tunnel-query
Description 

This command enables matching only on tunnels that have, at most, the specified number of UEs connected.

Default 

max-num-ue 4294967295

Parameters 
maximum—
Specifies the maximum number of UEs.
Values—
0 to 4294967295

 

min-num-ue

Syntax 
min-num-ue minimum
no min-num-ue
Context 
config>subscr-mgmt>wlan-gw>tunnel-query
Description 

This command enables matching only on tunnels that have at least the specified number of UEs connected.

The no form of this command disables matching on a minimum number of UEs.

Default 

no min-num-ue

Parameters 
minimum—
Specifies the minimum number of UEs.
Values—
1 to 4294967295

 

remote-address

Syntax 
remote-address ip-address
no remote-address
Context 
config>subscr-mgmt>wlan-gw>tunnel-query
Description 

This command enables matching only on the tunnel that uses the specified source IP address.

The no form of this command disables matching on a tunnel’s source IP address.

Default 

no remote-address

Parameters 
ip-address—
Specifies the IPv4 or IPv6 remote address.
Values—

ipv4-address

a.b.c.d

ipv6-address

x:x:x:x:x:x:x:x (eight 16-bit pieces)

x:x:x:x:x:x:d.d.d.d

x: [0 to FFFF]H

d: [0 to 255]D

 

router

Syntax 
router router-instance
no router
Context 
config>subscr-mgmt>wlan-gw>tunnel-query
Description 

This command enables matching only on tunnels that are terminated in the specified routing instance.

The no form of this command disables matching on a routing instance.

Default 

no router

Parameters 
router-instance—
Specifies the routing instance in the form of router-name or vprn-svc-id.
Values—
router-name — Base
vprn-svc-id — 1 to 2147483647

 

type

Syntax 
[no] type
Context 
config>subscr-mgmt>wlan-gw>tunnel-query
Description 

This command enables matching on specific tunnel types. If no tunnel type match criteria is specified, type matching is implicitly disabled.

gre

Syntax 
[no] gre
Context 
config>subscr-mgmt>wlan-gw>tunnel-query>type
Description 

This command enables matching on GRE tunnels.

The no form of this command disables matching on GRE tunnels, unless no other tunnel type specifier is configured.

Default 

no gre

l2

Syntax 
[no] l2
Context 
config>subscr-mgmt>wlan-gw>tunnel-query>type
Description 

This command enables matching on Layer 2 tunnels.

The no form of this command disables matching on Layer 2 access points, unless no other tunnel type specifier is configured.

Default 

no l2

l2tp

Syntax 
[no] l2tp
Context 
config>subscr-mgmt>wlan-gw>tunnel-query>type
Description 

This command enables matching on L2TP tunnels.

The no form of this command disables matching on L2TP tunnels, unless no other tunnel type specifier is configured.

Default 

no l2tp

vxlan

Syntax 
[no] vxlan
Context 
config>subscr-mgmt>wlan-gw>tunnel-query>type
Description 

This command enables matching on VXLAN tunnels.

The no form of this command disables matching on VXLAN tunnels, unless no other tunnel type specifier is configured.

Default 

no vxlan

ue-state

Syntax 
[no] ue-state
Context 
config>subscr-mgmt>wlan-gw>tunnel-query
Description 

This command enables matching on a specific UE state. Multiple states can be provisioned. If no UE state specifier is configured, UE state matching is disabled (all UEs match).

This match criteria can be combined with minimum and maximum match criteria, which will then apply only to UEs of the specified state.

dsm

Syntax 
[no] dsm
Context 
config>subscr-mgmt>wlan-gw>tunnel-query>ue-state
Description 

This command enables matching on DSM UEs.

The no form of this command disables matching on DSM UEs, unless UE state matching is disabled altogether.

Default 

no dsm

esm

Syntax 
[no] esm
Context 
config>subscr-mgmt>wlan-gw>tunnel-query>ue-state
Description 

This command enables matching on ESM UEs.

The no form of this command disables matching on DSM UEs, unless UE state matching is disabled altogether.

Default 

no esm

l2w

Syntax 
[no] l2w
Context 
config>subscr-mgmt>wlan-gw>tunnel-query>ue-state
Description 

This command enables matching on tunnels with L2W UEs.

The no form of this command disables matching on L2W UEs, unless UE state matching is disabled altogether.

Default 

no l2w

migrant

Syntax 
[no] migrant
Context 
config>subscr-mgmt>wlan-gw>tunnel-query>ue-state
Description 

This command enables matching on tunnels with migrant UEs.

The no form of this command disables matching on migrant UEs, unless UE state matching is disabled altogether.

Default 

no migrant

xcon

Syntax 
[no] xcon
Context 
config>subscr-mgmt>wlan-gw>tunnel-query>ue-state
Description 

This command enables matching on tunnels with cross-connect UEs.

The no form of this command disables matching on cross-connect UEs, unless UE state matching is disabled altogether.

Default 

no xcon

ue-query

Syntax 
ue-query query-id [name name] [create]
no ue-query query-id
Context 
config>subscr-mgmt>wlan-gw
Description 

This command creates a UE query where filter criteria over WLAN-GW ISA UEs are defined. This query can later be used to retrieve state of the UEs matching the configured criteria.

The no form of this command removes the query.

Parameters 
query-id—
Specifies the ID assigned to a query.
Values—
1 to 1024

 

name—
Specifies the name assigned to a query, up to 32 characters.
create—
Creates a UE query.

address-type

Syntax 
address-type {ipv4 | ipv6 | ipv4-only | ipv6-only | ipv4v6 | not-specified}
no address-type
Context 
config>subscr-mgmt>wlan-gw>ue-query
Description 

This command enables matching on UEs that have an address of the specified type.

The no form of this command reverts to the default.

Default 

address-type not-specified

Parameters 
ipv4—
Specifies matching on UEs that have an IPv4 stack active.
ipv6—
Specifies matching on UEs that have an IPv6 stack active.
ipv4-only—
Specifies matching on UEs that have only an IPv4 and no IPv6 stack active.
ipv6-only—
Specifies matching on UEs that have only an IPv6 and no IPv4 stack active.
ipv4v6—
Specifies matching on UEs that have both an IPv4 and IPv6 stack active.
not-specified—
Specifies that no address type matches on UEs.

bd

Syntax 
bd identifier
Context 
config>subscr-mgmt>wlan-gw>ue-query
Description 

This command enables matching on UEs that are part of the specified BD.

The no form of this command disables matching on the BD.

Default 

no bd

Parameters 
identifier—
Specifies the BD identifier.
Values—
0 to 4294967294

 

dhcp6-address

Syntax 
dhcp6-address ipv6-address
no dhcp6-address
Context 
config>subscr-mgmt>wlan-gw>ue-query
Description 

This command enables matching on UEs with the specified DHCPv6 IA-NA address.

The no form of this command disables matching on the IA-NA address.

Default 

no dhcp6-address

Parameters 
ipv6-address—
Specifies the IA-NA address.
Values—

ipv6-address

x:x:x:x:x:x:x:x (eight 16-bit pieces)

x:x:x:x:x:x:d.d.d.d

x: [0 to FFFF]H

d: [0 to 255]D

 

ipv4-address

Syntax 
ipv4-address ip-address
no ipv4-address
Context 
config>subscr-mgmt>wlan-gw>ue-query
Description 

This command enables matching on UEs with the specified IPv4 address.

The no form of this command disables matching on the IPv4 address.

Default 

no ipv4-address

Parameters 
ip-address—
Specifies the IPv4 address.
Values—
a.b.c.d

 

mac-address

Syntax 
mac-address ieee-address
no mac-address
Context 
config>subscr-mgmt>wlan-gw>ue-query
Description 

This command enables matching on UEs with the specified MAC address.

The no form of this command disables matching on the MAC address.

Default 

no mac-address

Parameters 
ieee-address—
Specifies the ethernet MAC address.
Values—
xx:xx:xx:xx:xx:xx or xx-xx-xx-xx-xx-xx

 

slaac-prefix

Syntax 
slaac-prefix ipv6-address
no slaac-prefix
Context 
config>subscr-mgmt>wlan-gw>ue-query
Description 

This command enables matching on UEs with the specified SLAAC prefix.

The no form of this command disables matching on the SLAAC prefix.

Default 

no slaac-prefix

Parameters 
ipv6-address—
Specifies the SLAAC prefix.
Values—

ipv6-address

x:x:x:x:x:x:x:x (eight 16-bit pieces)

x:x:x:x:x:x:d.d.d.d

x: [0 to FFFF]H

d: [0 to 255]D

 

state

Syntax 
[no] state
Context 
config>subscr-mgmt>wlan-gw>ue-query
Description 

This command enables matching on a specific UE state. Multiple states can be provisioned.

The no form of this command disables matching on the specified UE state (all UEs match).

already-signed-in

Syntax 
[no] already-signed-in
Context 
config>subscr-mgmt>wlan-gw>ue-query>state
Description 

This command enables matching on UEs that are already signed in.

The no form of this command disables matching on UEs that are already signed in, unless all state matching is disabled.

Default 

no already-signed-in

authorized-only

Syntax 
[no] authorized-only
Context 
config>subscr-mgmt>wlan-gw>ue-query>state
Description 

This command enables matching on UEs in an authorized state.

The no form of this command disables matching on UEs in an authorized state, unless all state matching is disabled.

Default 

no authorized-only

cross-connect

Syntax 
[no] cross-connect
Context 
config>subscr-mgmt>wlan-gw>ue-query>state
Description 

This command enables matching on cross-connected UEs.

The no form of this command disables matching on cross-connected UEs, unless all state matching is disabled.

Default 

no cross-connect

data-triggered

Syntax 
[no] data-triggered
Context 
config>subscr-mgmt>wlan-gw>ue-query>state
Description 

This command enables matching on UEs currently in a data-triggered state. This query only filters UEs that are currently authenticating due to a data trigger, not UEs that were originally authenticated due to data trigger, such as those in an ESM, DSM, or portal state.

The no form of this command disables matching on UEs in a data-triggered state, unless all state matching is disabled.

Default 

no data-triggered

delete-pending

Syntax 
[no] delete-pending
Context 
config>subscr-mgmt>wlan-gw>ue-query>state
Description 

This command enables matching on UEs that are in a delete-pending state.

The no form of this command disables matching on UEs in a delete pending-state, unless all state matching is disabled.

Default 

no delete-pending

dhcp-triggered

Syntax 
[no] dhcp-triggered
Context 
config>subscr-mgmt>wlan-gw>ue-query>state
Description 

This command enables matching on UEs currently in a DHCP-triggered state. This query only filters UEs that are currently authenticating due to a DHCP, DHCPv6, or RS trigger, not RADIUS-authenticated UEs in an ESM, DSM, or portal state that were originally authenticated due to a DHCP, DHCPv6, or RS trigger.

The no form of this command disables matching on UEs in a DHCP-triggered state, unless all state matching is disabled.

Default 

no dhcp-triggered

dsm

Syntax 
[no] dsm
Context 
config>subscr-mgmt>wlan-gw>ue-query>state
Description 

This command enables matching on UEs in a DSM state.

The no form of this command disables matching on UEs in a DSM state, unless all state matching is disabled.

Default 

no dsm

esm

Syntax 
[no] esm
Context 
config>subscr-mgmt>wlan-gw>ue-query>state
Description 

This command enables matching on UEs in an ESM state.

The no form of this command disables matching on UEs in an ESM state, unless all state matching is disabled.

Default 

no esm

gtp-authorized

Syntax 
[no] gtp-authorized
Context 
config>subscr-mgmt>wlan-gw>ue-query>state
Description 

This command enables matching on UEs in a GTP-authorized state.

The no form of this command disables matching on UEs in a GTP-authorized state, unless all state matching is disabled.

Default 

no gtp-authorized

ip-assigned

Syntax 
[no] ip-assigned
Context 
config>subscr-mgmt>wlan-gw>ue-query>state
Description 

This command enables matching on UEs in an IP-assigned state, meaning that the UE already has an IP assigned but it is not yet authorized. This usually only applies when auth-on-dhcp is not configured.

The no form of this command disables matching on UEs in an IP-assigned state, unless all state matching is disabled.

Default 

no ip-assigned

ip-assigned-authorized

Syntax 
[no] ip-assigned-authorized
Context 
config>subscr-mgmt>wlan-gw>ue-query>state
Description 

This command enables matching on UEs in an IP-assigned and authorized state, meaning that the UE already has an IP assigned and is authorized, but is not yet promoted to a final state such as ESM or DSM. This applies to UEs authenticated by distributed RADIUS proxy without auth-on-dhcp configured. UEs move to this state upon DHCP completion and continue to a more final state (such as DSM, ESM, or portal) upon receiving the first data packet.

The no form of this command disables matching on UEs in an IP-assigned and authorized state, unless all state matching is disabled.

Default 

no ip-assigned-authorized

l2

Syntax 
[no] l2
Context 
config>subscr-mgmt>wlan-gw>ue-query>state
Description 

This command enables matching on UEs in a Layer 2 wholesale state.

The no form of this command disables matching on UEs in a Layer 2 wholesale state, unless all state matching is disabled.

Default 

no l2

portal

Syntax 
[no] portal
Context 
config>subscr-mgmt>wlan-gw>ue-query>state
Description 

This command enables matching on UEs in a portal state.

The no form of this command disables matching on UEs in a portal state, unless all state matching is disabled.

Default 

no portal

tunnel-local-address

Syntax 
tunnel-local-address ip-address
no tunnel-local-address
Context 
config>subscr-mgmt>wlan-gw>ue-query
Description 

This command enables matching on UEs that are active on a tunnel which is connected to the specified IP address on the WLAN-GW.

The no form of this command disables matching on the local tunnel address.

Default 

no tunnel-local-address

Parameters 
ip-address—
Specifies the IPv4 or IPv6 address of the local tunnel.
Values—

ipv4-address

a.b.c.d

ipv6-address

x:x:x:x:x:x:x:x (eight 16-bit pieces)

x:x:x:x:x:x:d.d.d.d

x: [0 to FFFF]H

d: [0 to 255]D

 

tunnel-remote-address

Syntax 
tunnel-remote-address ip-address
no tunnel-remote-address
Context 
config>subscr-mgmt>wlan-gw>ue-query
Description 

This command enables matching on UEs that are active on a tunnel with the specified source IP address.

The no form of this command disables matching on the remote tunnel address.

Default 

no tunnel-remote-address

Parameters 
ip-address—
Specifies the IPv4 or IPv6 address of the remote tunnel.
Values—

ipv4-address

a.b.c.d

ipv6-address

x:x:x:x:x:x:x:x (eight 16-bit pieces)

x:x:x:x:x:x:d.d.d.d

x: [0 to FFFF]H

d: [0 to 255]D

 

tunnel-router

Syntax 
tunnel-router router-instance
no tunnel-router
Context 
config>subscr-mgmt>wlan-gw>ue-query
Description 

This command enables matching on UEs that are active on a tunnel which is terminated in the specified router instance.

The no form of this command disables matching on the tunnel router instance.

Default 

no tunnel-router

Parameters 
router-instance—
Specifies the routing instance.
Values—
router-name - Base
vprn-svc-id - 1 to 2147483647

 

tunnel-type

Syntax 
tunnel-type {gre | l2tp | l2 | vxlan | not-specified}
no tunnel-type
Context 
config>subscr-mgmt>wlan-gw>ue-query
Description 

This command enables matching on UEs that are active on a tunnel of the specified type. The not-specified value disables matching on the tunnel type.

The no form of this command reverts to the default.

Default 

tunnel-type not-specified

Parameters 
gre—
Specifies that the tunnel is of type GRE.
l2tp—
Specifies that the tunnel is of type L2TPv3.
l2—
Specifies that the UE is connected over a Layer 2 access point.
vxlan—
Specifies that the tunnel is of type VXLAN.
not-specified—
Specifies that no tunnel type matches on UEs.

vlan

Syntax 
vlan tag
no vlan
Context 
config>subscr-mgmt>wlan-gw>ue-query
Description 

This command enables matching on UEs, based on the VLAN tag within the tunnel, which typically used to indicate an SSID.

The no form of this command disables matching on the VLAN.

Default 

no vlan

Parameters 
tag—
Specifies the VLAN tag.
Values—
0 to 4096

 

wlan-gw-group

Syntax 
wlan-gw-group wlan-gw-group-id [member member-id]
no wlan-gw-group
Context 
config>subscr-mgmt>wlan-gw>ue-query
Description 

This command enables matching on UEs, based on the WLAN-GW group ID and, optionally, the specific ISA member they are installed on.

The no form of this command disables matching on the WLAN-GW group.

Default 

no wlan-gw-group

Parameters 
wlan-gw-group-id—
Specifies the WLAN-GW group ID.
Values—
1 to 4

 

member-id—
Specifies the ISA member ID within the group.
Values—
1 to 255

 

virtual-chassis-identifier

Syntax 
virtual-chassis-identifier dual-homing-key
no virtual-chassis-identifier
Context 
config>subscr-mgmt>wlan-gw
Description 

This command specifies a virtual chassis identifier that can link two wlan-gws together.

The no form of this command removes the dual-homing-key.

Parameters 
dual-homing-key—
Specifies the name of the dual homing key, up to 16 characters.

ipv6-tcp-mss-adjust

Syntax 
ipv6-tcp-mss-adjust segment-size
no ipv6-tcp-mss-adjust
Context 
config>router>wlan-gw>dsm
config>service>vprn>wlan-gw>dsm
Description 

This command specifies the value used for TCP-MSS-adjust in the IPv6 upstream direction for DSM. The downstream direction for both IPv4 and IPv6 are both configured under the group-interface. The upstream direction for IPv4 NAT hosts is configured under the NAT policy.

The defined segment size is inserted in a TCP SYN message if there is no existing MSS option or the value in the MSS option is bigger than the configured value.

The no form of this command disables upstream TCP MSS adjust for IPv6 DSM.

Parameters 
segment-size—
Specifies the segment size to be inserted.
Values—
160 to 10240

 

gtp-peer-clear-timeout

Syntax 
gtp-peer-clear-timeout seconds
no gtp-peer-clear-timeout
Context 
config>service>vprn>wlan-gw>dsm
Description 

This command configures a GTP peer cleanup timeout to terminate a handover wait state.

Parameters 
seconds—
Specifies a GTP peer cleanup timeout, in seconds, to terminate a handover wait state.
Values—
0 to 3600

 

mobility-triggered-acct

Syntax 
mobility-triggered-acct
Context 
config>router>wlan-gw
config>service>vprn>wlan-gw
Description 

This command enters the configuration context of mobility-triggered-accounting in wlan-gw context under router or VPRN service.

interim-update

Syntax 
interim-update
interim-update include-counters [hold-down seconds]
no interim-update
Context 
config>router>wlan-gw>mobility-triggered-acct
config>service>vprn>wlan-gw>mobility-triggered-acct
Description 

This command enables the inclusion of counters with a hold-down time option in mobility-triggered interim-updates. When enabled, to disable the inclusion of counters, interim updates must be disabled and then re-enabled without the include-counters keyword. By default, the hold-down time is not imposed.

The no form of this command disables generation of flash interim accounting updates to RADIUS when change in location of the UE is detected.

Parameters 
include-counters—
Specifies the inclusion of counters in mobility triggered interim-updates.
seconds—
Specifies the time, in seconds, that must elapse after a mobility- triggered interim with counters sent for the next mobility-triggered interim with counters to be sent.
Values—
60 to 864000

 

12.25.2.1.3. ISA Commands

isa-filter

Syntax 
isa-filter name [type {dsm}] [create]
no isa-filter name
Context 
config>subscr-mgmt
Description 

This command enables the context to configure ISA filter parameters.

Parameters 
name
Specifies the name of the filter.
type dsm
Selects DSM as the type.

default-action

Syntax 
default-action {drop | forward}
no default-action
Context 
config>subscr-mgmt>isa-filter
config>subscr-mgmt>isa-filter>ipv6
Description 

This command specifies what should happen to packets that do not match any of the configured entries.

The no form of this command reverts to the default value.

Default 

default-action drop

Parameters 
drop
Specifies that packets matching the filter entry are dropped.
forward
Specifies that packets matching the filter entry are forwarded.

entry

Syntax 
entry entry-id [create]
no entry entry-id
Context 
config>subscr-mgmt>isa-filter
config>subscr-mgmt>isa-filter>ipv6
Description 

This command creates a new entry for this filter. When processing a packet, entries are matched in order, starting with the lowest entry-id. A maximum of 128 IPv4 and 128 IPv6 DSM filter entries are allowed.

The no form of this command removes the specified entry from the ISA filter.

Parameters 
entry-id
Specifies the numeric identifier for the filter entry.

action

Syntax 
action {drop | forward | none}
action http-redirect rdr-url-string
no action
Context 
config>subscr-mgmt>isa-filter>entry
config>subscr-mgmt>isa-filter>ipv6>entry
Description 

This command specifies what should happen to packets that do match this entry.

The no form of this command reverts to the default value.

Default 

action none

Parameters 
drop
Specifies to drop the packet.
forward
Specifies to forward the packet.
none
Specifies to ignore the entry and continue processing with subsequent entries.
rdr-url-string
Specifies the URL to whicj matching HTTP flows are redirected, up to 255 characters. The URL can be overridden by AAA. Non-HTTP packets are dropped. The URL supports the $URL, $MAC, and $IP variables. For other macro substitutions, the string is not modified.

match

Syntax 
match protocol {any | icmp | tcp | upd | gre}
no match
Context 
config>subscr-mgmt>entry
config>subscr-mgmt>ipv6>entry
Description 

This command creates a match context for this entry. The protocol value specifies which Layer-4 protocol the packet should match.

The no form of this command removes the match context of this entry.

Default 

match protocol any

Parameters 
protocol
Specifies that the only supported match context is protocol.
any
Specifies to match any protocol.
icmp
Specifies to match ICMP packets in a v4 filter.
tcp
Specifies to match TCP packets.
udp
Specifies to match UDP packets.
gre
Specifies to match GRE over IP packets.

dst-port

Syntax 
dst-port operator port-number
no dst-port
Context 
config>subscr-mgmt>isa-filter>entry>match
config>subscr-mgmt>isa-filter>ipv6>entry>match
Description 

This command specifies that the packet’s UDP/TCP dst-port must match a specific value. This command is not valid in a match context that is not specific to UDP or TCP.

The no form of this command removes matching of the layer-4 port.

Parameters 
operator
Specifies that the only supported value is eq (equal to). The destination port value must be equal to the port-number value.
port-number
Specifies the number of the port to match.
Values—
0 to 65535

 

dst-ip

Syntax 
dst-ip ip-prefix/length
no dst-ip
Context 
config>subscr-mgmt>isa-filter>entry
config>subscr-mgmt>isa-filter>ipv6>entry
Description 

This command specifies that the packet’s destination IP address must match the specified IP prefix and mask.

The no form of this command disables the match on the destination IP.

Parameters 
ip-prefix/length
Specifies the IP prefix to match.

src-ip

Syntax 
src-ip ip-prefix/length
no src-ip
Context 
config>subscr-mgmt>isa-filter>entry>match
config>subscr-mgmt>isa-filter>ipv6>entry>match
Description 

This command configures the source IP or IPv6 address match condition.

The no form of this command reverts to the default value.

src-port

Syntax 
src-port operator port-number
no src-port
Context 
config>subscr-mgmt>isa-filter>entry>match
config>subscr-mgmt>isa-filter>ipv6>entry>match
Description 

This command configures the source port match condition.

The no form of this command reverts to the default value.

cbs

Syntax 
cbs burst-size
no cbs
Context 
config>subscr-mgmt>isa-policer
Description 

This command specifies the committed burst-size value of this policer. This can only be set on dual-bucket-bandwidth policers.

The no form of this command reverts to its default.

Default 

cbs 0

Parameters 
burst-size —
Specifies the committed burst-size in kbytes.
Values—
0 to 131071

 

mbs

Syntax 
mbs burst-size
no mbs
Context 
config>subscr-mgmt>isa-policer
Description 

This command specifies the maximum burst-size value of this policer.

The no form of this command reverts to its default.

Default 

mbs 0

Parameters 
burst-size —
The maximum burst-size in kbytes.
Values—
0 to 131071

 

rate

Syntax 
rate rate [cir cir-rate]
no rate
Context 
config>subscr-mgmt>isa-policer
Description 

This command specifies at which rate the policer drains packets. The cir value is only supported on dual-bucket-bandwidth policers. If rate max is configured, no actual rate limitations are applied.

The no form of this command reverts to the default.

Parameters 
rate —
Specifies the rate in Kb/s.
Values—
1 to 100000000, max

 

Default—
max
cir-rate —
Specifies the CIR rate in Kb/s.
Values—
1 to 100000000, max

 

Default—
max

isa-policer

Syntax 
isa-policer policer-name [type policer-type] [create]
no isa-policer policer-name
Context 
config>subscr-mgmt
Description 

This command creates the context to configure an ISA policer. When creating a policer for the first time, both the create and type parameters are required.

The no form of this command reverts to the default.

Parameters 
policer-name —
Specifies the name by which this policer is referenced up to 32 characters.
policer-type
Specifies the policer type. The dual-bucket-bandwidth policer applies both a CIR and PIR.
Values—
single-bucket-bandwidth, dual-bucket-bandwidth

 

action

Syntax 
action {permit-deny | priority-mark}
no action
Context 
config>subscr-mgmt>isa-policer
Description 

This command specifies what happens to packets that are in-profile and out-of-profile.

The no form of this command reverts to the default value.

Default 

action permit-deny

Parameters 
permit-deny
Drops all packets that are out of profile (they do not conform to the PIR).
priority-mark
Currently not supported. The policer will take no action.

adaptation-rule

Syntax 
adaptation-rule pir adaptation-rule [cir adaptation-rule]
no adaptation-rule
Context 
config>subscr-mgmt>isa-policer
Description 

For operational efficiency, the operational rate of a policer cannot take on every value in the configurable range. This configuration defines a rule that must be followed when mapping a configured rate to an operational rate.

The cir adaptation-rule can only be set on dual-bucket-bandwidth policers.

The no form of this command reverts to its default.

Default 

adaptation-rule pir closest cir closest

Parameters 
pir adaptation-rule—
Configures the rules to compute the PIR operational rates.
Values—
min — Specifies that the operational rate must minimally be the configured rate. The first operational value bigger or equal to the configured rate is chosen.
max — Specifies that the operational rate may maximally be the configured rate. The first operational value smaller or equal to the configured rate is chosen.
closest — Chooses the operational value closest to the configured value, lower or higher.

 

cir adaptation-rule
Configures the rules to compute the CIR operational rates.
Values—
adaptation-rule

 

12.25.2.1.4. RADIUS Server Policy Commands

acct-on-off-group

Syntax 
acct-on-off-group group-name [create]
no acct-on-off-group group-name
Context 
config>aaa
Description 

This command creates an acct-on-off-group.

An acct-on-off-group can be referenced by:

  1. A single radius-server-policy as controller — The acct-on-off oper-state of the acct-on-off-group is set to the acct-on-off oper-state of the radius-server-policy (acts as master).
  2. Multiple radius-server-policies as monitor — The acct-on-off oper-state of the radius-server-policy is inherited from the acct-on-off oper-state of the acct-on-off group. (acts as a slave).

The no form of this command deletes the acct-on-off-group.

Parameters 
group-name—
Specifies the name of an acct-on-off group up to 32 characters.

radius-server-policy

Syntax 
radius-server-policy policy-name [create]
no radius-server-policy policy-name
Context 
config>aaa
Description 

This command creates a radius-server-policy.

A RADIUS server policy can be used in

  1. radius-proxy, for application like EAP authentication for WIFI access
  2. authentication policy, for Enhanced Subscriber Management authentication
  3. radius accounting policy, for Enhanced Subscriber Management accounting
  4. dynamic data service RADIUS accounting
  5. AAA route downloader

The no form of this command removes the policy name from the configuration.

Parameters 
policy-name—
Specifies the name of the radius-server-policy up to 32 characters.
create—
Keyword used to create a radius-server-policy name. The create keyword requirement can be enabled/disabled in the environment>create context.

accept-script-policy

Syntax 
accept-script-policy policy-name
no accept-script-policy
Context 
config>aaa>radius-srv-plcy
Description 

This command specifies name of the radius-script-policy to be applied for access-accept.

Parameters 
policy-name—
Specifies the name of the accept-script-policy up to 32 characters.

acct-on-off

Syntax 
acct-on-off
acct-on-off monitor-group group-name
acct-on-off oper-state-change [group group-name]
Context 
config>aaa>radius-srv-plcy
Description 

This command controls the sending of Accounting-On and Accounting-Off messages and the acct-on-off oper-state of the radius-server-policy:

acct-on-off: enables the sending of Accounting-On and Accounting-Off messages for this radius-server-policy. The acct-on-off oper-state is always not blocked.

acct-on-off oper-state-change [group group-name]: enables the sending of Accounting-On and Accounting-Off messages for this radius-server-policy. The acct-on-off oper-state is function of the Accounting-response received for the Accounting-On and Accounting-Off. Optionally, sets the acct-on-off oper-state of the acct-on-off-group.

acct-on-off monitor-group group-name: no Accounting-On and Accounting-Off messages are sent for this radius-server-policy. The acct-on-off oper-state is inherited from the acct-on-off-group.

The no form of this command disables the sending of Accounting-On and Accounting-Off messages.

Parameters 
group-name—
Specifies the name of an acct-on-off group up to 32 characters.

acct-request-script-policy

Syntax 
acct-request-script-policy policy-name
no acct-request-script-policy
Context 
config>aaa>radius-srv-plcy
Description 

This command specifies the name of the acct-request-script-policy pointing to the Python script to be applied for RADIUS accounting request messages.

Parameters 
policy-name—
Specifies the name of the acct-request-script-policy up to 32 characters.

auth-request-script-policy

Syntax 
auth-request-script-policy policy-name
no auth-request-script-policy
Context 
config>aaa>radius-srv-plcy
Description 

This command specifies the name of the auth-request-script-policy pointing to the Python script to be applied for RADIUS access request messages.

Parameters 
policy-name—
Specifies the name of the auth-request-script-policy up to 32 characters

buffering

Syntax 
[no] buffering
Context 
config>aaa>radius-srv-plcy
Description 

This command enables the context to configure RADIUS message buffering.

The no form of this command disables RADIUS message buffering.

acct-interim

Syntax 
acct-interim min min-val max max-val lifetime lifetime
no acct-interim
Context 
config>aaa>radius-srv-plcy>servers>buffering
Description 

This command enables RADIUS accounting interim update message buffering.

  1. The message is stored in the buffer, a lifetime timer is started and the message is sent to the RADIUS server
  2. If after retry*timeout seconds no RADIUS accounting response is received for the interim update then a new attempt to send the message is started after minimum[(min-val*2n), max-val] seconds.
  3. Repeat step 2 until for one of the following:
    1. a RADIUS accounting response is received.
    2. the lifetime of the buffered message expires.
    3. a new RADIUS accounting interim-update or a RADIUS accounting stop for the same accounting session-id and radius-server-policy is stored in the buffer.
    4. the message is manually purged from the message buffer via a clear command.
  4. The message is purged from the buffer.

The no form of this command disables RADIUS accounting interim update message buffering.

Parameters 
min-val—
Specifies the minimum interval in seconds between attempts to resend the RADIUS accounting interim update.
Values—
1 to 3600

 

max-val—
Specifies the maximum interval in seconds between attempts to resend the RADIUS accounting interim update.
Values—
1 to 3600

 

lifetime—
Specifies the lifetime in hours.
Values—
1 to 25

 

acct-stop

Syntax 
acct-stop min min-val max max-val lifetime lifetime
no acct-stop
Context 
config>aaa>radius-srv-plcy>servers>buffering
Description 

This command enables RADIUS accounting stop message buffering.

  1. The message is stored in the buffer, a lifetime timer is started and the message is sent to the RADIUS server
  2. If after retry*timeout seconds no RADIUS accounting response is received for the accounting stop, then a new attempt to send the message is started after minimum[(min-val*2n), max-val] seconds.
  3. Repeat step 2 until
    1. a RADIUS accounting response is received, or
    2. the lifetime of the buffered message expires, or
    3. the message is manually purged from the message buffer via a clear command
  4. The message is purged from the buffer.

The no form of this command disables RADIUS accounting stop message buffering.

Parameters 
min-val—
Specifies the minimum interval in seconds between attempts to resend the RADIUS accounting stop.
Values—
1 to 3600

 

max-val—
Specifies the maximum interval in seconds between attempts to resend the RADIUS accounting stop.
Values—
1 to 3600

 

lifetime—
Specifies the lifetime in hours.
Values—
1 – 25

 

servers

Syntax 
servers
Context 
config>aaa>radius-srv-plcy
Description 

This command enables the context to configure radius-server-policy parameters.

access-algorithm

Syntax 
access-algorithm {direct | round-robin | hash-based}
no access-algorithm
Context 
config>aaa>radius-srv-plcy>servers
Description 

This command configures the algorithm used to select a RADIUS server from the pool of configured RADIUS servers.

Default 

access-algorithm direct

Parameters 
direct—
Specifies that the first server is used as primary server for all requests, the second as secondary and so on.
round-robin—
Specifies that the first server is used as primary server for the first request, the second server as primary for the second request, and so on. If the router gets to the end of the list, it starts again with the first server.
hash-based—
Select a RADIUS server based on the calculated hash result of the configured load-balance-key under the radius-proxy server hierarchy. This parameter is only applicable for radius-proxy server scenarios and results in an unpredictable RADIUS server selection if used in other scenarios.

disable-stickiness

Syntax 
[no] disable-stickiness
Context 
config>aaa>radius-srv-plcy>servers
Description 

This command disables a subscriber RADIUS accounting session from sticking with a single server under normal working conditions. If a direct algorithm is used, all subscriber RADIUS sessions will go directly to the server with the lowest configured index. If a failure occurs, a new in-service server with the next lowest index is used. When the original server recovers, if stickiness is not disabled, all existing sessions will continue to use the new server. This command disables stickiness, and as a result, the recovered original RADIUS server will again service every subscriber. If a round-robin algorithm is used and stickiness is not disabled, an accounting session for a particular subscriber (or host, depending on the accounting mode) will stay with the same server. This command removes the stickiness and all subscriber accounting messages will go through the list of servers in a round-robin manner.

health-check

Syntax 
health-check
Context 
config>aaa>radius-server-policy>servers
Description 

This command enables the context to configure health check parameters for the RADIUS server.

test-account

Syntax 
test-account
Context 
config>aaa>radius-srv-plcy>servers>health-check
Description 

This command sets up a test account as a probing mechanism to check the connectivity of all configured RADIUS authentication servers within the RADIUS server policy.

interval

Syntax 
interval seconds
no interval
Context 
config>aaa>radius-srv-plcy>servers>health-check>test-account
Description 

This command specifies the intervals at which the test account will send its access requests to probe the RADIUS servers.

Default 

interval 3

Parameters 
seconds—
Specifies the probing interval.
Values—
1 to 60

 

password

Syntax 
password password [hash | hash2| custom]
no password
Context 
config>aaa>radius-srv-plcy>servers>health-check>test-account
config>subscr-mgmt>vrgw>brg>brg-profile>radius-authentication
Description 

This command specifies the password that the test account will use to send access requests to probe the RADIUS servers.

Parameters 
password—
Specifies the probing password up to 64 characters.
hash—
Specifies the key is entered in an encrypted form. If the hash or hash2 parameter is not used, the key is assumed to be in an unencrypted, clear text form. For security, all keys are stored in encrypted form in the configuration file with the hash or hash2 parameter specified.
hash2—
Specifies the key is entered in a more complex encrypted form that involves more variables than the key value alone, meaning that the hash2 encrypted variable cannot be copied and pasted. If the hash or hash2 parameter is not used, the key is assumed to be in an unencrypted, clear text form. For security, all keys are stored in encrypted form in the configuration file with the hash or hash2 parameter specified.
custom—
Specifies the custom encryption to management interface.

shutdown

Syntax 
[no] shutdown
Context 
config>aaa>radius-srv-plcy>servers>health-check>test-account
Description 

This command disables the test account that probes the RADIUS server.

The no form of this command enables the capability.

Default 

shutdown

user-name

Syntax 
user-name user-name
no user-name
Context 
config>aaa>radius-srv-plcy>servers>health-check>test-account
Description 

This command specifies the username that the test account will use to send its access requests to probe the RADIUS servers.

The no form of this command removes the username from the test-account configuration.

Parameters 
user-name—
Specifies the probing username, up to 64 characters.

retry

Syntax 
retry count
no retry
Context 
config>aaa>radius-srv-plcy>servers
Description 

This command configures the number of times the router attempts to contact the RADIUS server, if not successful the first time.

The no form of this command reverts to the default.

Default 

retry 3

Parameters 
count—
Specifies the number of times a signaling request message is transmitted towards the same peer.
Values—
1 to 256

 

router

Syntax 
router router-instance
router service-name service-name
no router
Context 
config>aaa>radius-srv-plcy>servers
Description 

This command specifies the virtual router instance applicable for the set of configured RADIUS servers. This value cannot be changed once a RADIUS server is configured for this policy.

The no form of this command reverts to the default.

Parameters 
router-instance —
Specifies the router instance.
Values—

service-name

Service name, up to 64 characters.

router-instance:

router-name, service-id

router-name:

Base, management

service-id:

1 to 2147483647

 

service-name—
Specifies the router name service-id up to 64 characters.

server

Syntax 
server server-index name server-name
no server server-index
Context 
config>aaa>radius-srv-plcy>servers
Description 

This command adds a RADIUS server.

The no form of this command removes a RADIUS server.

Parameters 
index—
Specifies the index for the RADIUS server. The index determines the sequence in which the servers are queried for authentication requests. Servers are queried in order from lowest to highest index.
Values—
1 to 5

 

server-name—
Specifies the server name, up to 32 characters.

source-address

Syntax 
source-address ip-address
no source-address
Context 
config>aaa>radius-srv-plcy>servers
Description 

This command configures the source address of the RADIUS packet. The system IP address must be configured in order for the RADIUS client to work. See Configuring a System Interface in the 7750 SR OS Configuration Guide.

Note:

The system IP address must only be configured if the source-address is not specified. When the no source-address command is executed, the source address is determined at the moment the request is sent. This address is also used in the nas-ip-address attribute: over there it is set to the system IP address if no source-address was given.

The no form of this command reverts to the default value.

Parameters 
ip-address—
Specifies the source address of RADIUS packet.

timeout

Syntax 
timeout [sec seconds] [min minutes]
no timeout
Context 
config>aaa>radius-srv-plcy>servers
Description 

This command configures the time the router waits for a response from a RADIUS server.

The no form of this command reverts to the default value.

Default 

timeout sec 5

Parameters 
seconds—
Specifies the number of seconds for the timeout.
Values—
1 to 59

 

minutes—
Specifies the number of minutes for the timeout.
Values—
1 to 5

 

Values—
Max. value = 5 min 40 sec

 

hold-down-time

Syntax 
hold-down-time [sec seconds] [min minutes] [hrs hours] [days days]
no hold-down-time
Context 
config>aaa>radius-srv-plcy>servers
Description 

This command configures the hold time before re-using a RADIUS server.

The no form of this command reverts to the default value.

Default 

hold-down-time sec 30

Parameters 
seconds—
Specifies the number of seconds for the hold down time.
Values—
1 to 59

 

minutes —
Specifies the number of minutes for the hold down time.
Values—
1 to 59

 

hours—
Specifies the number of hours for the hold down time.
Values—
1 to 23

 

days —
Specifies the number of days for the hold down time.
Values—
1 to 1

 

ipv6-source-address

Syntax 
ipv6-source-address ipv6-address
no ipv6-source-address
Context 
config>aaa>radius-srv-plcy>servers
Description 

This command configures the source address of an IPv6 RADIUS packet.

When no ipv6-source-address is configured, the system IPv6 address (inband RADIUS server connection) or Boot Option File (BOF) IPv6 address (outband RADIUS server connection) must be configured in order for the RADIUS client to work with an IPv6 RADIUS server.

This address is also used in the NAS-IPv6-Address attribute.

The no form of this command reverts to the default value.

Parameters 
ipv6-address—
Specifies the source address of an IPv6 RADIUS packet.

12.25.2.2. CLI Command Description for RADIUS Server

radius-server

Syntax 
radius-server
Context 
config>router
config>service>vprn
Description 

This command enters the radius-server configuration context under router or VPRN service.

server

Syntax 
server server-name [address ip-address] [secret key] [hash | hash2| custom] [create]
no server server-name
Context 
config>router>radius-server
config>service>vprn>radius-server
Description 

This command either specifies an external RADIUS server in the corresponding routing instance or enters configuration context of an existing server. The configured server could be referenced in the radius-server-policy.

The no form of this command removes the parameters from the server configuration.

Parameters 
server-name—
Specifies the name of the external RADIUS server.
ip-address
Specifies the IPv4 or IPv6 IP address of the external RADIUS server.
key
Specifies the shared secret key of the external RADIUS server, up to 64 characters.
hash—
Specifies the key is entered in an encrypted form. If the hash or hash2 parameter is not used, the key is assumed to be in an unencrypted, clear text form. For security, all keys are stored in encrypted form in the configuration file with the hash or hash2 parameter specified.
hash2—
Specifies the key is entered in a more complex encrypted form that involves more variables than the key value alone, meaning that the hash2 encrypted variable cannot be copied and pasted. If the hash or hash2 parameter is not used, the key is assumed to be in an unencrypted, clear text form. For security, all keys are stored in encrypted form in the configuration file with the hash or hash2 parameter specified.
custom—
Specifies the custom encryption to management interface.

accept-coa

Syntax 
[no] accept-coa
Context 
config>router>radius-server>server
config>service>vprn>radius-server>server
Description 

This command configures this server for Change of Authorization messages. The system will process the CoA request from the external server if configured with this command; otherwise the CoA request is dropped.

The no form of this command disables the command.

acct-port

Syntax 
acct-port port
no acct-port
Context 
config>router>radius-server>server
config>service>vprn>radius-server>server
Description 

This command specifies the UDP listening port for RADIUS accounting requests.

The no form of this commands resets the UDP port to its default value (1813)

Default 

acct-port 1813

Parameters 
port—
Specifies the UDP listening port for accounting requests of the external RADIUS server.
Values—
1 to 65535

 

auth-port

Syntax 
auth-port port
no auth-port
Context 
config>router>radius-server>server
config>service>vprn>radius-server>server
Description 

This command specifies the UDP listening port for RADIUS authentication requests.

The no form of this commands resets the UDP port to its default value (1812)

Default 

auth-port 1812

Parameters 
port—
Specifies the UDP listening port for accounting requests of the external RADIUS server.
Values—
1 to 65535

 

coa-script-policy

Syntax 
coa-script-policy policy-name
no coa-script-policy
Context 
config>router>radius-server>server
config>service>vprn>radius-server>server
Description 

This command specifies radius-script-policy for CoA-Request sent from this RADIUS server.

The no form of this command removes the policy name from the configuration.

Parameters 
policy-name—
Specifies the name of radius-script-policy up to 80 characters.

pending-requests-limit

Syntax 
pending-request-limit limit
no pending-request-limit
Context 
config>router>radius-server>server
config>service>vprn>radius-server>server
Description 

This command specifies the per-server maximum number of outstanding requests sent to the RADIUS server. If the maximum number is exceeded, the next RADIUS server in the pool is selected.

The no form of this command removes the limit value from the configuration.

Default 

pending-requests-limit 4096

Parameters 
limit —
Specifies the maximum number of outstanding requests sent to the RADIUS server.
Values—
1 to 4096

 

12.25.2.3. CLI Command Description for RADIUS Proxy Server

radius-proxy

Syntax 
radius-proxy
Context 
config>router
config>service>vprn
Description 

This command context to configure RADIUS proxy parameters.

server

Syntax 
server server-name [create] [purpose {[accounting | authentication]}] [wlan-gw-group group-id]
no server server-name
Context 
config>router>radius-proxy
config>service>vprn>radius-proxy
Description 

This command creates a RADIUS-proxy server in the corresponding routing instance. The proxy server can be configured for the purpose of proxying authentication or accounting or both.

If a WLAN-GW ISA group is specified, then the RADIUS proxy server is instantiated on the set of ISAs in the specified wlan-gw group. The RADIUS messages from the AP are load-balanced to these ISAs. The ISA that processes the RADIUS message then hashes this message to the ISA that anchors the UE. The hash is based on UE MAC address (required to be present in the calling-station-id attribute) in the RADIUS message.

If the create parameter is not specified, then this command enters configuration context of the specified RADIUS-proxy server.

The no form of this command removes the server-name and parameters from the radius-proxy configuration.

Parameters 
server-name—
Specifies the name of the RADIUS-proxy server.
create—
Specifies that the system will create the specified RADIUS-proxy server.
purpose —
Specifies the purpose the RADIUS-proxy server.
Values—
accounting — proxy accounting packets
authentication — proxy authentication packets

 

group-id
Specifies the WLAN-GW ISA group.

attribute-matching

Syntax 
attribute-matching
Context 
config>router>radius-proxy>server
config>service>vprn>radius-proxy>server
Description 

This command enables the context for selecting the RADIUS policy for authentication and accounting based on the RADIUS attribute. This feature is supported for both the ESM RADIUS proxy and the ISA RADIUS proxy.

entry

Syntax 
entry [entry] [prefix-string prefix-string] [accounting-server-policy policy-name] [authentication-server-policy policy-name] [suffix-string suffix-string]
no entry [entry]
Context 
config>router>radius-proxy>server>attribute-matching
config>service>vprn>radius-proxy>server>attribute-matching
Description 

This command matches the specified prefix or suffix string with the selected accounting server policy or authentication server policy.

Parameters 
entry—
Specifies an entry ID.
Values—
1 to 32

 

prefix-string—
Specifies the prefix string for matching up to 128 characters. If the suffix-string is also used, the combined length cannot exceed 126 characters.
suffix-string—
Specifies the suffix string for matching up to 126 characters. If the prefix-string is also used, the combined length cannot exceed 126 characters.
policy-name—
Specifies the RADIUS accounting or authentication policy up to 32 characters.

type

Syntax 
type [type] [vendor-id vendor-id]
no type
Context 
config>router>radius-proxy>server>attribute-matching
config>service>vprn>radius-proxy>server>attribute-matching
Description 

This command specifies the RADIUS VSA type for the entries to be matched with.

Parameters 
type
Specifies the RADIUS server policy matching attribute-type.
Values—
1 to 255

 

vendor-id—
Specifies the vendor ID number.
Values—
1 to 16777215, nokia

 

cache

Syntax 
cache
Context 
config>router>radius-proxy>server
config>service>vprn>radius-proxy>server
Description 

This command enters the cache configuration context under radius-proxy server. The cache contains per-subscriber authentication information learned from RADIUS authentication messages, and is used to authorize subsequent DHCP requests.

default-accounting-server-policy

Syntax 
default-accounting-server-policy policy-name
no default-accounting-server-policy
Context 
config>router>radius-proxy>server
config>service>vprn>radius-proxy>server
Description 

This command specifies the default radius-server-policy for RADIUS accounting. This policy is used when there is no specific match based on username.

The no form of this command removes the policy name from the configuration.

Parameters 
policy-name—
Specifies the name of the default RADIUS server policy associated with this RADIUS Proxy server for accounting purposes.

default-authentication-server-policy

Syntax 
default-authentication-server-policy policy-name
no default-authentication-server-policy
Context 
config>router>radius-proxy>server
config>service>vprn>radius-proxy>server
Description 

This command specifies the default radius-server-policy for RADIUS authentication. This policy is used when there is no specific match based on username.

The no form of this command removes the policy name from the configuration.

Parameters 
policy-name—
Specifies the name of the default RADIUS server policy associated with this RADIUS proxy server for authentication purposes.

interface

Syntax 
[no] interface ip-int-name
Context 
config>router>radius-proxy>server
config>service>vprn>radius-proxy>server
Description 

This command configures the IP interface the RADIUS-proxy server will bind to. One RADIUS-proxy server could bind to multiple interfaces.

Parameters 
ip-int-name—
Specifies the name of an IP interface.

load-balance-key

Syntax 
load-balance-key [vendor vendor-id [vendor-id]] attribute-type attribute-type [attribute-type]
load-balance-key source-ip-udp
no load-balance-key
Context 
config>router>radius-proxy>server
config>service>vprn>radius-proxy>server
Description 

This command specifies the key used in calculating a hash to select an external RADIUS server from the pool of configured servers.

The key can be the source IP and source UDP port tuple, or the specified RADIUS attribute in RADIUS packets.

The no form of this command removes the parameters from the configuration.

Parameters 
vendor-id
Specifies the vendor-id of vendor-specific attribute.
Values—
0 to 16777215

 

attribute-type
Specifies that the key is constructed with the attributes in the RADIUS message.
Values—
1 to 255

 

source-ip-udp—
Specifies that the key consists of the source IP address and source UDP port of the RADIUS message.

python-policy

Syntax 
python-policy name
no python-policy
Context 
config>router>radius-proxy>server
Description 

This command specifies the Python policy used to change the RADIUS attributes of the different RADIUS messages.

The no form of this command removes the name from the configuration.

Parameters 
name—
Specifies the Python policy name up to 32 characters.

secret

Syntax 
secret secret [hash | hash2 | custom]
no secret
Context 
config>router>radius-proxy>server
config>service>vprn>radius-proxy>server
Description 

This command configures the shared secret key. The RADIUS client must have the same key to communicate with the RADIUS-proxy server.

The no form of this command removes the parameters from the configuration.

Parameters 
secret key
Specifies the secret key up to 64 characters to access the RADIUS server. This secret key must match the password on the RADIUS server.
Values—
hash-key: Up to 33 characters
hash2-key: Up to 55 characters.

 

hash—
Specifies that the key is entered in an encrypted form. If the hash or hash2 parameter is not used, the key is assumed to be in an unencrypted, clear text form. For security, all keys are stored in encrypted form in the configuration file with the hash or hash2 parameter specified.
hash2—
Specifies that the key is entered in a more complex encrypted form that involves more variables than the key value alone, meaning that the hash2 encrypted variable cannot be copied and pasted. If the hash or hash2 parameter is not used, the key is assumed to be in an unencrypted, clear text form. For security, all keys are stored in encrypted form in the configuration file with the hash or hash2 parameter specified.
custom—
Specifies the custom encryption to management interface.

send-accounting-response

Syntax 
[no] send-accounting-response
Context 
config>router>radius-proxy>server
config>service>vprn>radius-proxy>server
Description 

This command results in the system to always generate RADIUS accounting-response to acknowledge RADIUS accounting-request received from the RADIUS client.

The no form of this command disables the command.

key

Syntax 
key packet-type {accept | request} attribute-type attribute-type [vendor vendor-id]
no key
Context 
config>router>radius-proxy>server>cache
config>service>vprn>radius-proxy>server>cache
Description 

This command specifies the RADIUS cache key that is used to match the information in subsequent DHCP requests for authorization.

Parameters 
packet-type—
Specifies the packet type of the RADIUS messages to use to generate the key for the cache of this RADIUS proxy server.
Values—
accept, request

 

attribute-type
Specifies the RADIUS attribute type to cache for this RADIUS proxy. server.
Values—
1 to 255

 

vendor-id
Specifies the RADIUS vendor ID.
Values—
1 to 16777215, nokia

 

timeout

Syntax 
timeout [hrs hours] [min minutes] [sec seconds]
no timeout
Context 
config>router>radius-proxy>server>cache
config>service>vprn>radius-proxy>server>cache
Description 

This command configures the time for which the cache entry is kept if there is no corresponding DHCP DISCOVER. At the expiry of this time, the cache entry is deleted.

The no form of this command reverts to the default value.

Default 

timeout min 5

Parameters 
hours
Specifies, in hours, the timeout after which an entry in the cache will expire.
Values—
1

 

minutes
Specifies, in minutes, the timeout after which an entry in the cache will expire.
Values—
1 to 59

 

seconds
Specifies, in seconds, the timeout after which an entry in the cache will expire.
Values—
1 to 59

 

track-accounting

Syntax 
track-accounting [start] [stop][interim-update][accounting-on] [accounting-off]
no track-accounting
Context 
config>router>radius-proxy>server>cache
config>service>vprn>radius-proxy>server>cache
Description 

This command specifies the type of RADIUS accounting packets from RADIUS client (a WIFI AP) that the router should track.

The no form of this command removes the parameters from the configuration.

Parameters 
start—
Specifies that the router will update the associated ESM-host with the RADIUS client (for example, a WIFI AP) that generated the accounting-start. This is required in cases where a UE roams to a new AP that does not re-authenticate due to key caching.
stop—
Specifies that the router will remove the corresponding ESM host and forward the accounting-stop packet to the external RADIUS server.
accounting-on | accounting-off—
Specifies that the router will remove all ESM hosts associated with the RADIUS client (a WIFI AP), and forward the accounting-on packet to the external RADIUS server.
interim-update—
Specifies that the router will update the associated ESM-host with the RADIUS client (a WIFI AP) that generated the interim-update. The interim-updates with the updated information are sent to the RADIUS server as scheduled.

track-authentication

Syntax 
track-authentication [accept]
no track-authentication
Context 
config>router>radius-proxy>server>cache
config>service>vprn>radius-proxy>server>cache
Description 

This command specifies if RADIUS authentication (from the AP) should be tracked in order to update the ESM host with the RADIUS client (for example, WIFI AP) on UE mobility. It also specifies the authentication packet from RADIUS client (for example, a WIFI AP) that the router should track for mobility.

The no form of this command stops tracking authentication for UE mobility.

Default 

track-authentication accept

Parameters 
accept —
Indicates access-accept is tracked for mobility.

track-delete-hold-time

Syntax 
track-delete-hold-time seconds
no track-delete-hold-time
Context 
config>router>radius-proxy>server>cache
Description 

This command specifies the delete hold-time in case the DHCP host gets a trigger to delete from the matched RADIUS Proxy server.

The no form of this command reverts to the default.

Default 

track-delete-hold-time 0

Parameters 
seconds—
Specifies the delete hold time, in seconds.
Values—
0 to 600

 

12.25.2.4. LUDB Matching of RADIUS Proxy Cache Commands

local-user-db

Syntax 
local-user-db local-user-db-name [create]
no local-user-db local-user-db-name
Context 
config>subscr-mgmt
Description 

This command enables the context to configure a local user database.

The no form of this command removes the local user database name from the configuration.

Parameters 
local-user-db-name —
Specifies the name of a local user database, up to 32 characters.

ipoe

Syntax 
ipoe
Context 
config>subscr-mgmt>loc-user-db>ipoe
Description 

This command enables the context to configure DHCP IPoE host parameters.

host

Syntax 
host
Context 
config>subscr-mgmt>loc-user-db
Description 

This command enables the context to configure DHCP host parameters.

match-radius-proxy-cache

Syntax 
match-radius-proxy-cache
Context 
config>subscr-mgmt>loc-user-db>ipoe>host
Description 

This command enables the context to configure match-radius-proxy-cache parameters.

fail-action

Syntax 
fail-action {continue | drop}
no fail-action
Context 
config>subscr-mgmt>loc-user-db>ipoe>host>match-radprox-cache
Description 

This command specifies the router’s action when failed to find matched radius-proxy-server cache entry.

The no form of this command reverts to the default.

Default 

fail-action drop

Parameters 
continue—
Specifies that the will proceed with ESM authentication without dropping the DHCP packet.
drop—
Specifies that the router will drop the DHCP packet.

mac-format

Syntax 
mac-format format
no mac-format
Context 
config>subscr-mgmt>loc-user-db>ipoe>host>match-radprox-cache
Description 

This command specifies the format of MAC address used for matching incoming DHCP DISCOVER against the RADIUS proxy cache.

The no form of this command reverts to the default.

Default 

mac-format "aa:"

Parameters 
format—
Specifies the format string that specifies the format of MAC address.
Values—

mac-format: (only when match is equal to mac)

like ab: for 00:0c:f1:99:85:b8

or XY- for 00-0C-F1-99-85-B8

or mmmm. for 0002.03aa.abff

or xx for 000cf19985b8

 

match

Syntax 
match {circuit-id | mac | remote-id}
match option [option] [option6 [option6]]
match option6 [option6]
no match
Context 
config>subscr-mgmt>loc-user-db>ipoe>host>match-radprox-cache
Description 

This command specifies the field or option of a DHCP packet that is used as a lookup key to match against the RADIUS proxy cache.

The no form of this command reverts to the default.

Default 

match mac

Parameters 
circuit-id—
Specifies to match the circuit-id in DHCP option82.
remote-id—
Specifies to match the remote-id in DHCP option82.
mac—
Specifies to match the MAC address of DHCP client
option
Specifies to match the DHCPv4 option number.
Values—
1 to 254

 

option6
Specifies to match the DHCPv6 option number.
Values—
1 to 65535

 

server

Syntax 
server [service service-id] name server-name
no server
Context 
config>subscr-mgmt>loc-user-db>ipoe>host>match-radprox-cache
Description 

This command specifies the name of radius-proxy-server and optionally id of the service that the radius-proxy-server resides in.

The no form of this command removes the parameters from the configuration.

Parameters 
service service-id
Specifies the ID or name of the service.
Values—
1 to 214748365
svc-name up to 64 char maximum

 

name server-name
Specifies the name of radius-proxy-server up to 32 characters.

12.25.2.5. WLAN-GW-Group Commands

wlan-gw-group

Syntax 
wlan-gw-group group-id [create] [redundancy unit]
no wlan-gw-group group-id
Context 
config>isa
Description 

This command creates a WLAN GW group that contains a set of ISAs to be used in WLAN-GW functionality. A WLAN-GW group can also be used where a NAT group is expected. The WLAN-GW group ID shares the same number space with the NAT group.

At most, one WLAN-GW group may be configured.

The optional redundancy parameter determines the provisioning and redundancy mode.

  1. IOM mode
    A whole IOM is added to the group. The IOM must be fully provisioned with BB ISA modules. In IOM mode, when a single ISA fails, the entire IOM is considered to have failed and all subscribers are recovered on a backup IOM.
  2. ISA mode
    BB ISA modules are added separately with no restriction put on other MDAs in the IOM. When a single ISA fails, a backup ISA will try to recover as many subscribers as possible but may run out of resources (for example, queues, policers, host entries) during the recovery process. It is recommended to pair ISAs with MDAs and services that do not consume many IOM resources.

The no form of this command removes the group.

Parameters 
group-id —
Specifies WLAN Gateway Integrated Service Adaptor (ISA) Groups.
Values—
1 to 4

 

unit —
Specifies the provisioning and redundancy mode.
Values—
mda or iom

 

active-iom-limit

Syntax 
active-iom-limit number
no active-iom-limit
Context 
config>isa>wlan-gw-group
Description 

This command specifies the number of WLAN-GW IOMs used as active IOMs from the total number of configured WLAN-GW IOMs. If there are more configured IOM than active-iom-limit, then the remaining number of IOMs is designated as backup(s).

The no form of this command removes the number from the configuration.

Parameters 
number—
Specifies the number of IOMs in this WLAN Gateway ISA group that are intended for active use.
Values—
1 to 3

 

active-mda-limit

Syntax 
active-mda-limit number
no active-mda-limit
Context 
config>isa>wlan-gw-group
Description 

This command specifies how many ISAs may be in active use by the WLAN-GW group at the same time. If the maximum number of active ISAs is reached and more ISAs are added to the group, the new ISAs are considered to be in standby mode.

The no form of this command removes the limit on the maximum number of active ISAs.

Parameters 
number—
Specifies the number of WLAN-GW ISAs intended for active use.
Values—
1 to 14

 

distributed-sub-mgmt

Syntax 
[no] distributed-sub-mgmt
Context 
config>isa>wlan-gw-group
Description 

This command configures the WLAN gateway distributed subscriber management.

isa-aa-group

Syntax 
isa-aa-group aa-group-id
no isa-aa-group
Context 
config>isa>wlan-gw-group>distributed-sub-mgmt
Description 

This command configures an ISA application assurance group for WLAN gateway DSM subscribers.

isa-aa-oversubscription-factor

Syntax 
isa-aa-oversubscription-factor factor
no isa-aa-oversubscription-factor
Context 
config>isa>wlan-gw-group>distributed-sub-mgmt
Description 

This command specifies by how much an AA ISA is oversubscribed when linked to a WLAN-GW group. A factor of 1 indicates that each AA ISA is linked to a single WLAN-GW ISA, while a factor of 10 indicates that each AA ISA is linked to up to 10 WLAN-GW ISAs. The factor must be an integer but poses an oversubscription limit, not an exact ratio. For example, for 2 AA ISAs and 5 WLAN-GW ISAs, a factor of 3 or higher is valid. Additional standby ISAs can be added until the oversubscription limit is reached.

The no form of this command resets the configuration to the default value.

Default 

isa-aa-oversubscription-factor 1

Parameters 
factor—
The number of WLAN GW ISAs that can be served by a single AA ISA.
Values—
1 to 10

 

iom

Syntax 
iom slot-number type {[load-balancer] [ue-anchor]}
no iom slot-number
Context 
config>isa>wlan-gw-group
Description 

This command designates the specified IOM as a WLAN-GW IOM. Each WLAN-GW IOM must be provisioned with two ISA-BB modules on a hardware chassis and with an ISA-BB module in the first MDA slot in the VSR.

The no form of this command removes the IOM from the configuration.

Parameters 
slot-number—
Indicates the IOM slot to be used in the WLAN-GW group.
Values—
1 to 10

 

type {[load-balancer] [ue-anchor]}
This parameter is supported on the VSR only. It determines if an IOM slot is used for load-balancing or UE anchoring and processing, or both. When the wlan-gw-group has only a single IOM, it is required to put this IOM in both modes at the same time.

mda

Syntax 
[no] mda mda-id
Context 
config>isa>wlan-gw-group
Description 

This command enables an ISA for WLAN-GW functionality.

The no form of this command removes the ISA from the WLAN-GW configuration.

Parameters 
mda-id—
Indicates the IOM and MDA slot in format slot/mda.
Values—
slot — 1 to 10
mda — 1 to 2

 

nat

Syntax 
nat
Context 
config>isa>wlan-gw-group
Description 

This command enables the context to configure NAT parameters under wlan-gw-group.

lsn

Syntax 
[no] lsn
Context 
config>isa>wlan-gw-group>nat
Description 

This command enables Large Scale NAT (LSN).

The no form of this command disables LSN.

radius-accounting-policy

Syntax 
radius-accounting-policy nat-accounting-policy
no radius-accounting-policy
Context 
config>isa>wlan-gw-group>nat
Description 

This command configures the RADIUS accounting policy to use for each MDA in this ISA group.

The no form of this command removes the accounting policy from the configuration.

Parameters 
nat-accounting-policy—
Specifies the RADIUS accounting policy up to 32 characters.

session-limits

Syntax 
session-limits
Context 
config>isa>wlan-gw-group>nat
Description 

This command configures the ISA NAT group session limits.

upnp-mappings

Syntax 
upnp-mappings [upnp-mappings]
no upnp-mappings
Context 
config>isa>wlan-gw-group>nat>session-limits
Description 

This command limits the number of Universal Plug 'n Play mappings per member

The no form of this command reverts to the default value.

Default 

upnp-mappings 524288

Parameters 
upnp-mappings—
specifies, for each MDA in this ISA group, the maximum number of Universal Plug 'n Play (UPnP) mappings.
Values—
1 to 524288

 

reserved

Syntax 
reserved num-sessions
no reserved
Context 
config>isa>nat>session-limits
Description 

This command configures the number of sessions per block that is reserved for prioritized sessions.

The no form of this command reverts to the default.

Parameters 
num-sessions—
Specifies the number of sessions reserved for prioritized sessions.
Values—
0 to 6291456

 

watermarks

Syntax 
watermarks high percentage low percentage
no watermarks
Context 
config>isa>nat>session-limits
Description 

This command configures the ISA NAT group watermarks.

The no form of this command reverts to the default.

Parameters 
percentage
Specifies the high watermark of the number of sessions for each MDA in this NAT ISA group.
Values—
2 to 100

 

percentage—
Specifies the low watermark of the number of sessions for each MDA in this NAT ISA group.
Values—
1 to 99

 

suppress-lsn-events

Syntax 
[no] suppress-lsn-events
Context 
configure>isa>wlan-gw-group>nat
Description 

This command suppresses the generation of Large Scale NAT (LSN) events when RADIUS accounting is enabled.

By default, only one logging facility for tracking subscribers in LSN44, DS-Lite, and NAT64 can be enabled at the time, either the SR OS event logging facility or the RADIUS logging facility. Note that SR OS event logs can be sent to multiple destinations, such as the console session, a telnet or SSH session, memory logs, file destinations, SNMP trap groups, and syslog destinations.

If RADIUS logging is enabled, the NAT logs are sent to the RADIUS destination and the NAT logs are suppressed in the SR OS event logging facility, for example, NAT logs are not sent to the syslog server.

If RADIUS logging is disabled, the NAT logs are sent to the SR OS event logging facility, for example, syslog, assuming that the events are enabled via the SR OS event-control (config> log>event-control nat event generate).

The no form of this command, the NAT logs can be sent to both logging facilities simultaneously, the SR OS event logging facility and RADIUS logging facility.

Default 

suppress-lsn-events

suppress-lsn-sub-blks-free

Syntax 
[no] suppress-lsn-sub-blks-free
Context 
configure>isa>wlan-gw-group>nat
Description 

This command suppresses the tmnxNatLsnSubBlksFree summary notification and use the tmnxNatPlBlockAllocationLsn notifications. When the SR OS node is in a state of excessive logging, the queue associated with the transmission of logs on the MS-ISA can become congested. This event further delays the generation of logs, and with this, further allocations and deallocations of NAT resources (port-blocks) is stalled until the queue is relieved of congestion. For example, an excessive logging state in the system can be caused by issuing a command to clear a large number of NAT subscribers where a large number of resources (port-blocks) are released at once.

The suppress-lsn-sub-blks-free command enables the generation of individual logs carried in event-id 2012 for every released port block regardless of the state of the transmission queue (whether congested or not). If NAT subscribers have a large number of allocated port blocks (this could be hundreds of port blocks per subscriber), generating individual logs per port-block release contributes to the congestion.

To alleviate transmission queue congestion, this behavior can be changed by disabling this command (no suppress-lsn-sub-blks-free). This causes the suppression of logs related to the release of individual port blocks of a NAT subscriber when the transmission queue is congested. As a result, only a summarized release log via event-id 2021 for the subscriber is generated. The purpose of this new log is to inform the operator in a single message that all ports blocks for the subscriber are released. For example, the log message for LSN is “LSN subscriber all blocks freed”. The benefit of such summarization (or log aggregation) is to alleviate the congestion of the transmission queue and consequently accelerate resource releases. An effect is the decreased granularity of information.

If summarization is enabled (no suppress-lsn-sub-blks-free) while there is no logging congestion in the system, the port block releases continue to be logged individually via the event-id 2012 (assuming that this is enabled in the event control), except for the last port block of the subscriber. When the last port block is released, the log with event-id 2021 is generated indicating that all port blocks for the subscriber are now released without carrying the specific information about this last port block that is released.

port-policy

Syntax 
port-policy [port-policy]
no port-policy
Context 
config>isa>wlan-gw-group
Description 

This command configures the port policy of this WLAN Gateway ISA group. If a port policy is associated with a WLAN Gateway ISA group, ports created for this group can take applicable configuration from that port policy. This port policy is applicable to those ports that take part in the per-tunnel QoS processing.

The no form of the command removes the port-policy name from the configuration.

Default 

no port-policy

Parameters 
port-policy—
Specifies the port policy of this WLAN Gateway ISA group, up to 32 characters.

tunnel-port-policy

Syntax 
tunnel-port-policy [tunnel-port-policy]
no tunnel-port-policy
Context 
config>isa>wlan-gw-group
Description 

This command configures the tunnel port policy of this WLAN Gateway ISA group. If a tunnel port policy is associated with a WLAN Gateway ISA group, ports created for this group can take applicable configuration from that policy. This policy is applicable to those ports that take part in the per-tunnel QoS processing.

The no form of the command removes the tunnel-port-policy name from the configuration.

Default 

no-tunnel-policy

Parameters 
tunnel-port-policy—
Specifies the tunnel port policy of this WLAN Gateway ISA group, up to 32 characters.

watermarks

Syntax 
watermarks
Context 
config>isa>wlan-gw-group
Description 

This command enables the context to configure ISA watermark notifications.

mark

Syntax 
mark entity high percentage-high low percentage-low
no mark entity
Context 
config>isa>wlan-gw-group>watermarks
Description 

This command enables a watermark notification. If the watermark is set, it generates a notification when the corresponding resource consumption goes above the high percentage. No additional notifications are sent until resource consumption goes under the low watermark, upon which, a notification is sent indicating the high watermark is no longer hit.

The no form of this command disables the watermark notification.

Parameters 
entity
Specifies which watermark to set.
Values—
user-equipment | bridge-domain | radius-proxy-client

 

percentage-high
Specifies the high watermark in percentage of total resources available.
Values—
1 to 100

 

percentage-low—
Specifies the low watermark in percentage of total resources available.
Values—
0 to 99

 

12.25.2.6. Port Policy Commands

port-policy

Syntax 
port-policy port-policy-name [create]
no port-policy port-policy-name
Context 
config
Description 

This command either creates a new port-policy with create parameter or enters the configuration context of an existing port-policy.

The no form of this command removes the port policy name from the configuration.

Parameters 
port-policy-name—
Specifies the name of port-policy up to 32 characters.
create—
Creates the port-policy instance. The create keyword requirement can be enabled or disabled in the environment>create context.

egress-scheduler-policy

Syntax 
egress-scheduler-policy port-sched-plcy
egress-scheduler-policy
Context 
config>port-policy
Description 

This command specifies the port-scheduler-policy to use in the egress direction for the internal port connecting the WLAN-GW IOM to the MS-ISA.

The no form of this command removes the policy from the configuration.

Parameters 
port-sched-plcy—
Specifies the name of the port-scheduler-policy up to 32 characters.

12.25.2.7. WLAN-GW Group Interface Commands

Note:

The wlan-gw commands apply only to the 7750 SR platform.

group-interface

Syntax 
group-interface ip-int-name [create]
group-interface ip-int-name [create] lns
group-interface ip-int-name [create] wlangw
no group-interface ip-int-name [create]
Context 
config>service>ies>subscriber-interface
config>service>vprn>subscriber-interface
Description 

This command creates a group interface. This interface is designed for triple-play services where multiple SAPs are part of the same subnet. A group interface may contain one or more SAPs.

The no form of this command removes the group interface from the subscriber interface.

Parameters 
ip-int-name—
Specifies the interface name of a group interface. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes.
lns —
Specifies to use LNS.
wlangw—
Specifies the group interface for wlan-gw.

wlan-gw

Syntax 
wlan-gw
Context 
config>service>ies>sub-if>group-interface
config>service>vprn>sub-if> group-interface
Description 

This command enables the context to configure wlan-gw parameters.

vlan-tag-ranges

Syntax 
vlan-tag-ranges
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command enables the context to configure vlan-to-retail-map parameters to map dot1Q tags to retail-service-id. The WIFI AP could insert a dot1Q tag in the Layer 2 frame within the GRE tunnel to indicate the retail service provider for the subscriber.

range

Syntax 
range start [range] end [range]
range default
no range start [range] end [range]
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges
config>service>ies>sub-if>grp-if>wlan-gw>ranges
Description 

This command creates or enters the context of specified VLAN range for configuration applicable to that range of VLANs.

Default 

range default

Parameters 
start
Specifies the start of the VLAN range.
Values—
0 to 4096

 

end—
Specifies the end of VLAN the range.
Values—
0 to 4096

 

default—
Configures defaults for the interface.

authenticate-on-dhcp

Syntax 
[no] authenticate-on-dhcp
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range
Description 

This command enables initial authentication (when there is no state for the UE on the ISA), to be triggered by DHCP DISCOVER or REQUEST. The default behavior is authentication based on first Layer 3 packet.

The no form of this command reverts to the default.

authentication

Syntax 
authentication
Context 
config>service>vprn>sub-if>grp-if>wlan-gw
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range
Description 

This command enables the context to create configuration for authenticating a user from the WLAN-GW ISA.

authentication-policy

Syntax 
authentication-policy policy-name
no authentication-policy
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>authentication
config>service>ies>sub-if>grp-if>wlan-gw>authentication
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>authentication
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>authentication
Description 

This command specifies authentication policy configured under aaa context for authenticating users on WLAN-GW ISA.

The no form of this command removes the policy-name from the configuration.

Parameters 
policy-name —
Specifies the name of the authentication policy up to 32 characters.

hold-time

Syntax 
hold-time [hrs hours] [min minutes] [sec seconds]
no hold-time
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>authentication
config>service>ies>sub-if>grp-if>wlan-gw>authentication
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>authentication
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>authentication
Description 

This command configures the minimum time that a UE is held down after a failed authentication attempt.

The no form of this command reverts to the default.

Default 

hold-time sec 5

Parameters 
hours
Specifies the minimum time that a user is held down in hours.
Values—
1 to 1

 

minutes
Specifies the minimum time that a user is held down in minutes.
Values—
1 to 59

 

seconds
Specifies the minimum time that a user is held down in seconds.
Values—
0 to 59

 

vlan-mismatch-timeout

Syntax 
vlan-mismatch-timeout seconds
no vlan-mismatch-timeout
Context 
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>authentication
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>authentication
Description 

This command configures the timeout value for the RADIUS proxy cache if a packet is received with a non-matching VLAN tag. The new timeout value is the lesser of the vlan-mismatch-timeout value and the currently remaining proxy cache timeout value.

The no form of this command disables the timeout behavior. The cache timeout value will remain unchanged.

Parameters 
seconds—
Specifies the timeout value for the RADIUS proxy cache, in seconds.
Values—
5 to 60

 

distributed-sub-mgmt

Syntax 
distributed-sub-mgmt
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range
Description 

This command enables the context to configure distributed-sub-mgmt configuration per vlan-range. This also includes vlan-range default, which makes this configuration applicable to the wlan-gw group-interface.

accounting-policy

Syntax 
accounting-policy policy-name
no accounting-policy
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dsm
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dsm
Description 

This command specifies the isa-radius-policy used for accounting messages originated from the ISAs in the wlan-gw group. The policy can specify up to five accounting servers and configuration-specific to these accounting servers. It also specifies configuration specific to RADIUS client on ISAs and RADIUS attributes to be included in accounting messages.

Parameters 
policy-name—
Specifies the name of the account policy up to 32 characters.

accounting-update-interval

Syntax 
accounting-update-interval [interval]
no accounting-update-interval
Context 
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dsm
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dsm
Description 

This command enables the interim accounting and specifies the interim accounting interval.

Parameters 
interval
Specifies the interim accounting interval in seconds.
Values—
5 to 259200

 

collect-aa-acct-stats

Syntax 
[no] collect-aa-acct-stats
Context 
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dsm
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dsm
Description 

This command enables Application Assurance account statistics collection.

def-app-profile

Syntax 
def-app-profile profile-name
no def-app-profile
Context 
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dsm
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dsm
Description 

This command configures the default application profile.

dsm-ip-filter

Syntax 
dsm-ip-filter dsm-ip-filter-name
no dsm-ip-filter
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dsm
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dsm
Description 

This command configures an IP filter that is distributed on ISA cards.

This command specifies the IP filter applied to all UEs corresponding to default vlan-range (such as a group-interface) or the specified vlan-range. The IP filter can be created in the config>subscr-mgmt>isa-filter context, and can contain up to 1024 match entries. The IP filter can be overridden per UE from RADIUS via access-accept or COA.

The no form of this command reverts to the default.

Parameters 
dsm-ip-filter-name—
Specifies the identifier of the distributed-sub-mgmt IP filter.

egress-policer

Syntax 
egress-policer [policer-name]
no egress-policer
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dsm
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dsm
Description 

This command specifies the egress policer applied to all UEs corresponding to default vlan-range (such as, group-interface) or the specified vlan-range. The policer can be created in the config>subscr-mgmt>isa-policer context. The egress policer can be overridden per UE from RADIUS via access-accept or COA.

The no form of this command reverts to the default.

Parameters 
policer-name—
Specifies the identifier of the distributed-sub-mgmt policer for egress traffic up to 256 characters.

ingress-policer

Syntax 
ingress-policer policer-name
no ingress-policer
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dsm
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dsm
Description 

.This command specifies the ingress policer applied to all UEs corresponding to default vlan-range (such as group-interface) or the specified vlan-range. The policer can be created in the config>subscr-mgmt>isa-policer context. The ingress policer can be overridden per UE from RADIUS via access-accept or COA.

The no form of this command reverts to the default.

Parameters 
policer-name—
Specifies the identifier of the distributed-sub-mgmt policer for ingress traffic.

one-time-redirect

Syntax 
one-time-redirect url rdr-url-string port port-num
no one-time-redirect
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dsm
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dsm
Description 

This command enables one-time http-redirect to specify redirect URL for traffic matching the specified destination port.

The no form of this command reverts to the default.

Parameters 
url rdr-url-string
Specifies the HTTP web address that is sent to the user’s browser.
port port-num
Specifies the destination port number as a decimal hex or binary.
Values—
1 to 65535

 

default-retail-svc-id

Syntax 
default-retail-svc-id service-id
no default-retail-svc-id
Context 
config>service>ies>sub-if>grp-if>wlan-gw>vlan-tag-ranges
config>service>vprn>sub-if>grp-if>wlan-gw>vlan-tag-ranges
Description 

This command specifies the id of default retail service if there is no match found in VLAN to retail map configuration (specified by the vlan command). For DSM and migrant, this command is only applicable for non-NAT stacks.

Parameters 
service-id—
Specifies the identifier of the retail service to be used by default of a value in the retail service map of this interface.
Values—
1 to 2147483650
svc-name: up to 64 characters

 

vlan

Syntax 
vlan start [value] end [value] retail-svc-id service-id
no vlan start [value] end [value]
Context 
config>service>ies>sub-if>grp-if>wlan-gw>retailer
config>service>vprn>sub-if>grp-if>wlan-gw>retailer
Description 

This command creates a mapping from a range of VLANs (appearing in the wlan-gw encapsulated Layer 2 frame) to a retail service ID.

The no form of this command removes the parameters from the configuration.

Parameters 
start
Specifies the start VLAN tag of this range.
Values—
0 to 4095

 

end —
Specifies the end VLAN tag of this range.
Values—
0 to 4095

 

retail-svc-id service-id
Specifies the identifier of the retail service to be used by default of a value in the retail service map of this interface.
Values—
1 to 2147483650
svc-name: up to 64 characters

 

wlan-gw-group

Syntax 
wlan-gw-group group-id
no wlan-gw-group
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command specifies the ID of the wlan-gw-group that the wlan-gw gateway binds to.

The no form of this command removes the value from the wlan-gw configuration.

Parameters 
group-id—
Specifies the ISA WLAN-GW group.
Values—
1 to 4

 

ip-mtu

Syntax 
ip-mtu octets
no ip-mtu
Context 
config>service>ies>subscriber-interface
config>service>vprn>subscriber-interface
Description 

This command specifies the maximum size of frames on this group-interface. Packets larger than this will get fragmented.

The no form of this command removes this functionality.

Parameters 
octets.—
Specifies the largest frame size (in octets) that this interface can handle.
Values—
512 to 9000

 

sap-parameters

Syntax 
sap-parameters
Context 
config>service>ies>sub-if>grp-if
config>service>vprn>sub-if>grp-if
Description 

This command enables the context to configure parameters that can be applied to automatically-generated internal SAPs.

anti-spoof

Syntax 
anti-spoof {ip-mac | nh-mac}
no anti-spoof
Context 
config>service>ies>sub-if>grp-if>sap-parameters
config>service>vprn>sub-if>grp-if>sap-parameters
Description 

This command configures the anti-spoof type of the SAP.

The type of anti-spoof filtering defines what information in the incoming packet is used to generate the criteria to lookup an entry in the anti-spoof filter table. The type parameter (ip-mac or nh-mac) defines the anti-spoof filter type enforced by the SAP when anti-spoof filtering is enabled.

The no form of this command reverts to the default.

Default 

anti-spoof ip-mac

Parameters 
ip-mac—
Configures SAP anti-spoof filtering to use both the source IP address and the source MAC address in its lookup. The anti-spoof ip-mac command will fail if the default anti-spoof filter type of the SAP is ip-mac and the default is not overridden, or if the SAP does not support Ethernet encapsulation.
nh-mac—
Indicates that the ingress anti-spoof is based on the source MAC address and egress anti-spoof is based on the nh-ip-address.

sub-sla-mgmt

Syntax 
[no] sub-sla-mgmt
Context 
config>service>ies>sub-if>grp-if>sap-parameters
config>service>vprn>sub-if>grp-if>sap-parameters
Description 

This command enables the context to configure subscriber management parameters.

The no form of this command removes the parameters from the configuration.

Default 

sub-sla-mgmt

def-app-profile

Syntax 
def-app-profile profile-name
no def-app-profile
Context 
config>service>ies>sub-if>grp-if>sap-parameters>sub-sla-mgmt
config>service>vprn>sub-if>grp-if>sap-parameters>sub-sla-mgmt
Description 

This command configures the default application profile.

The no form of this command removes the profile name from the configuration.

Parameters 
profile-name—
Specifies the default application profile name up to 32 characters.

def-sla-profile

Syntax 
def-sla-profile default-sla-profile-name
no def-sla-profile
Context 
config>service>ies>sub-if>grp-if>sap-parameters>sub-sla-mgmt
config>service>vprn>sub-if>grp-if>sap-parameters>sub-sla-mgmt
Description 

This command specifies a default SLA profile for this SAP. The SLA profile must be defined prior to associating the profile with a SAP in the config>subscr-mgmt>sla-profile context.

An SLA profile is a named group of QoS parameters used to define per service QoS for all subscriber hosts common to the same subscriber within a provider service offering. A single SLA profile may define the QoS parameters for multiple subscriber hosts. SLA profiles are maintained in two locations, the subscriber identification policy and the subscriber profile templates. After a subscriber host is associated with an SLA profile name, either the subscriber identification policy used to identify the subscriber or the subscriber profile associated with the subscriber host must contain an SLA profile with that name. If both the subscriber identification policy and the subscriber profile contain the SLA profile name, the SLA profile in the subscriber profile is used.

The no form of this command removes the default SLA profile from the SAP configuration.

Parameters 
default-sla-profile-name—
Specifies a default SLA profile for this SAP. The SLA profile must be defined prior to associating the profile with a SAP in the config>subscr-mgmt>sla-profile context.

def-sub-id

Syntax 
def-sub-id string sub-id
def-sub-id use-auto-id
no def-sub-id
Context 
config>service>vprn>sub-if>grp-if>sap-parameters>sub-sla-mgmt
config>service>ies>sub-if>grp-if>sap-parameters>sub-sla-mgmt
Description 

This command configures the default subscriber ID. The default is used if no other source (like RADIUS) provides a subscriber identification string.

Parameters 
sub-id
Specifies the default subscriber identification up to 32 characters.
use-auto-id—
Specifies that the auto-generated subscriber identification string, is used as the default subscriber identification string.

def-sub-profile

Syntax 
def-sub-profile sub-profile-name
Context 
config>service>vprn>sub-if>grp-if>sap-parameters>sub-sla-mgmt
config>service>ies>sub-if>grp-if>sap-parameters>sub-sla-mgmt
Description 

This command specifies a default subscriber profile. The subscriber profile must be defined prior to associating the profile with a SAP in the config>subscr-mgmt>sub-profile context.

A subscriber profile defines the aggregate QoS for all hosts within a subscriber context. This is done through the definition of the egress and ingress scheduler policies that govern the aggregate SLA for subscriber using the subscriber profile. Subscriber profiles also allow for specific SLA profile definitions when the default definitions from the subscriber identification policy must be overridden.

The no form of this command removes the default SLA profile from the configuration.

Parameters 
sub-profile-name—
Specifies a default subscriber profile. The subscriber profile must be defined in the config>subscr-mgmt>sub-profile context.

sub-ident-policy

Syntax 
sub-ident-policy sub-ident-policy-name
Context 
config>service>vprn>sub-if>grp-if>sap-parameters>sub-sla-mgmt
config>service>ies>sub-if>grp-if>sap-parameters>sub-sla-mgmt
Description 

This command associates a subscriber identification policy. The subscriber identification policy must be defined in the config>subscr-mgmt>sub-ident-policy context.

Subscribers are managed by the system through the use of subscriber identification strings. A subscriber identification string uniquely identifies a subscriber. For static hosts, the subscriber identification string is explicitly defined with each static subscriber host.

For dynamic hosts, the subscriber identification string must be derived from the DHCP ACK message sent to the subscriber host. The default value for the string is the content of Option 82 CIRCUIT-ID and REMOTE-ID fields interpreted as an octet string. As an option, the DHCP ACK message may be processed by a subscriber identification policy which has the capability to parse the message into an alternative ASCII or octet string value.

When multiple hosts on the same port are associated with the same subscriber identification string they are considered to be host members of the same subscriber.

The no form of this command removes the default subscriber identification policy from the configuration.

Parameters 
sub-ident-policy-name—
Specifies a subscriber identification policy for this SAP. The subscriber profile must be defined prior to associating the profile with a SAP in the config>subscr-mgmt>sub-ident-policy context.

egress

Syntax 
egress
Context 
config>service>ies>sub-if>grp-if>wlan-gw
Description 

This command enables the context to configure egress QoS parameters for wlan-gw tunnels.

rate

Syntax 
rate {max | rate}
no rate
Context 
config>service>ies>sub-if>grp-if>wlan-gw>egress>agg-rate
config>service>vprn>sub-if>grp-if>wlan-gw>egress>agg-rate
Description 

This command defines the enforced aggregate rate for all queues associated with the agg-rate context. A rate must be specified for the agg-rate context to be considered to be active on the context’s object (SAP, subscriber, Vport, and so on).

The no form of this command reverts to the default.

agg-rate-limit

Syntax 
agg-rate-limit kilobits-per-second
no agg-rate-limit
Context 
config>service>ies>sub-if>grp-if>wlan-gw>egress
config>service>vprn>sub-if>grp-if>wlan-gw>egress
Description 

This command controls an HQoS aggregate rate limit. It is used in conjunction with the following parameter commands: rate, limit-unused-bandwidth, and queue-frame-based-accounting.

The no form of this command removes the rate from the configuration.

Parameters 
kilobits-per-second—
Specifies the aggregate rate limit.
Values—
1 to 100000000, max

 

hold-time

Syntax 
hold-time infinite
hold-time [time]
no hold-time
Context 
config>service>ies>sub-if>grp-if>wlan-gw>egress
config>service>vprn>sub-if>grp-if>wlan-gw>egress
Description 

This command configures the time for which egress shaping resources associated with a wlan-gw tunnel are held after the last subscriber on a tunnel is deleted.

Parameters 
time
Specifies the time, in seconds, for which shaping resources are held in seconds after last subscriber is deleted.
Values—
infinite to 1 to 86400

 

qos

Syntax 
qos policy-id
no qos
Context 
config>service>ies>sub-if>grp-if>wlan-gw>egress
Description 

This command configures the identifier of the egress QoS policy associated with each wlan-gw tunnel of this interface.

The no form of this command removes the policy ID from the configuration.

Default 

qos 1

Parameters 
policy-id—
Specifies to apply the specified sap-egress-policy-id.
Values—
1 to 65535
name: A string up to 64 characters

 

scheduler-policy

Syntax 
scheduler-policy scheduler-policy-name
no scheduler-policy
Context 
config>service>ies>sub-if>grp-if>wlan-gw>egress
Description 

This command configures the identifier of the egress scheduler policy associated with each wlan-gw tunnel of this interface.

The no form of this command removes the scheduler policy name from the configuration.

Parameters 
scheduler-policy-name—
Specifies the identifier of the egress scheduler policy associated with each wlan-gw tunnel of this interface.

shape-multi-client-only

Syntax 
[no] shape-multi-client-only
Context 
config>service>ies>sub-if>grp-if>wlan-gw>egress
Description 

This command enables the egress shaping is only enabled for a wlan-gw tunnel while there are multiple UE (User Equipment) using it.

The no form of this command disables the egress shaping.

shaping

Syntax 
shaping {per-retailer | per-tunnel}
no shaping
Context 
config>service>ies>sub-if>grp-if>wlan-gw>egress
Description 

This command configures the granularity of the egress shaping for wlan-gw on this group interface.

The no form of this command removes the parameter from the configuration.

Parameters 
per-tunnel—
Specifies that a separate shaper is applied to each wlan-gw tunnel.
per-retailer—
Specifies that a separate shaper is applied to each retailer Mobile Network Operator's fraction of the wlan-gw tunnel payload.

group-encryption

Syntax 
group-encryption
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command configures group encryption for the WLAN-GW group interface.

encryption-keygroup

Syntax 
encryption-keygroup keygroup-id direction direction
no encryption-keygroup direction direction
Context 
config>service>ies>sub-if>grp-if>wlan-gw>group-encryption
config>service>vprn>sub-if>grp-if>wlan-gw>group-encryption
Description 

This command binds an encryption key-group to a WLAN-GW soft-GRE group interface. When configured in the inbound direction, received packets must be encrypted using one of the valid security-associations configured for the key-group. When configured in the outbound direction, L2oMPLSoGRE packets egressing the node use the “active-outbound-sa” associated with the key-group configured.

The no form of this command removes the encryption keygroup from the inbound or outbound group interface.

Parameters 
keygroup-id—
Specifies the ID number or name of the keygroup.
Values—
1 to 127, keygroup-name up to 64 characters

 

direction—
Applies the keygroup to the inbound or outbound direction of a service.
Values—
inbound | outbound

 

gw-addresses

Syntax 
gw-addresses
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command specifies gateway endpoint address for the wlan-gw tunnel.

The no form of this command removes the gateway ipv4 or IPv6 endpoint address for the wlan-gw tunnel.

Parameters 
ip-address—
Specifies the IP address of the wlan-gw tunnels on this group interface.

address

Syntax 
[no] address [ip-address | ipv6-address]
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command configures an IPv4 or IPv6 address of a WLAN Gateway.

The no form of this command removes the IPv4 or IPv6 address from the configuration.

Parameters 
ip-address—
Specifies up to four IPv4 addresses.
Values—
a.b.c.d

 

ipv6-address—
Specifies up to six gateway IPv6 endpoint addresses.
Values—

ipv6-address:

x:x:x:x:x:x:x:x (eight 16-bit pieces)

x:x:x:x:x:x:d.d.d.d

x - [0 to FFFF]H

d - [0 to 255]D

 

ipv6-address—
Specifies up to six IPv6 addresses.

learn-ap-mac

Syntax 
learn-ap-mac [delay-auth]
no learn-ap-mac
Context 
config>service>vprn>sub-if>grp-if>wlan-gw
config>service>ies>sub-if>grp-if>wlan-gw
Description 

This command enables the sending of ARP or ND packets on the wlan-gw GRE tunnel upon certain events. The target IP address in the ARP/ND packet is the endpoint IP address of the AP. The ARP/ND response from the AP should contain the AP MAC, which subsequently can be reported in called-station-id. When enabled this is sent for following events:

  1. CPM: Mobility to an AP for which the AP-MAC is not yet known.
  1. CPM: RS-triggered authentication on an AP for which the AP-MAC is not yet known
  1. ISA: Any mobility event
  1. ISA: Any authentication where the AP-MAC is not yet known (for example, from RADIUS proxy cache, DHCP circuit-id, and so on). If the optional keyword delay-auth is provided the authentication is delayed until the ARP/ND is answered or timed out, after which the AP-MAC can be included in authentication.

This configuration is ignored for l2-ap and l2tpv3 access.

Parameters 
delay-auth—
Specifies that authentication is delayed until the ARP/ND is answered or timed out, after which the AP-MAC can be included in authentication.

l2-access-points

Syntax 
l2-access-points
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command enables the context to configure Layer 2 Access Points in WLAN Gateway Group-Interfaces.

l2-ap

Syntax 
l2-ap sap-id [create]
no l2-ap sap-id
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>l2-access-points
config>service>ies>sub-if>grp-if>wlan-gw>l2-access-points
Description 

This command adds a specific SAP where Layer-2 WLAN-GW aggregation is performed. The following SAPs are supported.

  1. Ethernet
  2. LAG
  3. MPLS pseudowire SDPs

This command can be repeated multiple times to create multiple Layer-2 access points.

The no form of this command removes the Layer-2 access point. This is only allowed if the l2-ap SAP is shutdown.

Parameters 
sap-id—
Specifies SAP to be created.
create—
Keyword used to create the Layer-2 WLAN-GW aggregation instance. The create keyword requirement can be enabled/disabled in the environment>create context.

encap-type

Syntax 
encap-type {default | null | dot1q | qinq}
no encap-type
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>l2-access-points>l2-ap
config>service>ies>sub-if>grp-if>wlan-gw>l2-access-points>l2-ap
Description 

If different from default, this command overrides the value specified by l2-ap-encap-type on wlan-gw level. See the description of l2-ap-encap-type for more detail. This value can only be changed while the l2-ap is shut down.

The no form of this command sets the default value.

Default 

encap-type default

Parameters 
default
Specifies to use the value specified by l2-ap-encap-type.
null
Specifies to use both the SAP and the AP are not VLAN-tagged.
dot1q
Specifies to use either the AP or the SAP uses one VLAN tag.
qinq
Up to two VLAN tags are used by the AP or SAP.

epipe-sap-template

Syntax 
epipe-sap-template name
no epipe-sap-template
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>l2-access-points>l2-ap
config>service>ies>sub-if>grp-if>wlan-gw>l2-access-points>l2-ap
Description 

This command specifies which SAP parameter template should be applied to the l2-ap SAP. This can only be changed when the l2-ap is shut down.

The no form of this command removes the template, the SAP will use default parameters.

Parameters 
name—
Specifies the name of the template to use

shutdown

Syntax 
shutdown sap-id [create]
no shutdown sap-id
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>l2-access-points>l2-ap
config>service>ies>sub-if>grp-if>wlan-gw>l2-access-points>l2-ap
Description 

This command administratively enables this SAP to begin accepting Layer 2 packets for WIFI offloading.

The no form of this command disables this SAP.

Default 

shutdown

l2-ap-auto-sub-id-fmt

Syntax 
l2-ap-auto-sub-id-fmt {include-ap-tags | sap-only}
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command configures the contents of the auto-generated subscriber ID when the ipoe-sub-id-key command is set to include sap-id and the def-sub-id command is configured with use-auto-id. The VLANs must be configured so that the subscriber ID length is not exceeded.

This command can include either the SAP or the SAP + AP delimiting tags.

The no form of this command reverts to the default configuration.

Default 

l2-ap-auto-sub-id-fmt include-ap-tags

Parameters 
include-ap-tags—
Specifies that the SAP + AP delimiting tags is used.
sap-only—
Specifies that the SAP only is used.

l2-ap-encap-type

Syntax 
l2-ap-encap-type {null | dot1q | qinq}
Context 
config>service>vprn>sub-if>grp-if>wlan-gw
config>service>ies>sub-if>grp-if>wlan-gw
Description 

This parameter specifies the number of AP identifying VLAN tags for an AP. This is the default value that can be overridden per SAP. This value should at least be equal to the number of VLANs configured in the SAP or enabling a SAP will fail.

A SAP VLAN is explicitly configured, for example l2-ap 1/1/1:25. Other VLANs on the same port can still be used in other contexts.

The number of VLAN tags Epiped to WLAN-GW IOM equal the l2-ap-encap-type minus the encaps of the SAP. Upon receipt of a packet these VLANs is stored as a Layer 2 tunnel identifier, and are only used in context of WLAN-GW.

The no form of this command sets the default value.

Default 

l2-ap-encap-type null

Parameters 
null —
Both the SAP and the AP are not VLAN-tagged.
dot1q —
Either the AP or the SAP uses one VLAN tag.
qinq —
Up to two VLAN tags are used by the AP or SAP.

mobility

Syntax 
mobility
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command enables the context to configure mobility parameters.

hold-time

Syntax 
hold-time time
no hold-time
Context 
config>service>ies>sub-if>grp-if>wlan-gw>mobility
config>service>vprn>sub-if>grp-if>wlan-gw>mobility
Description 

This command configures the minimum time that a UE is held associated with its current Access Point (AP) before being associated with a new AP.

The hold time is used to prevent overwhelming the system with mobility triggers, by limiting the rate at which a UE can move from one AP to another while the system is very busy already.

Default 

hold-time 5

Parameters 
time—
Specifies a hold-down time, in seconds, for handling of successive mobility triggers for a UE. It is the minimal time a UE stays associated with an AP.
Values—
0 to 255

 

inter-vlan

Syntax 
[no] inter-vlan
Context 
config>service>ies>sub-if>grp-if>wlan-gw>mobility
config>service>vprn>sub-if>grp-if>wlan-gw>mobility
Description 

This command enables mobility within different VLANs of the same range. When enabled, mobility between different VLANs in a single vlan-range is allowed for the configured mobility triggers.

The no form of this command disables mobility between VLANs.

trigger

Syntax 
trigger [data] [iapp] [control]
no trigger
Context 
config>service>ies>sub-if>grp-if>wlan-gw>mobility
config>service>vprn>sub-if>grp-if>wlan-gw>mobility
Description 

This command specifies the type of packet used as a mobility trigger.

The no form of this command removes the parameters from the configuration and disables data-plane mobility.

Parameters 
data—
Specifies that data traffic be used as a trigger.
iapp—
Specifies that Inter Access Point Protocol (IAPP) messages be used as a trigger.
control—
Specifies that control traffic can be used as a trigger.

multi-tunnel-type

Syntax 
[no] multi-tunnel-type
Context 
config>service>ies>sub-if>grp-if>wlan-gw>mobility
config>service>vprn>sub-if>grp-if>wlan-gw>mobility
Description 

This command enables terminating multiple types of tunnels.

The no form of this command disables terminating multiple types of tunnels.

no multi-tunnel-type

oper-down-on-group-degrade

Syntax 
[no] oper-down-on-group-degrade
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command operationally brings down the WLAN-GW group if the total number of operational WLAN-GW IOMs in the WLAN-GW group fall below the configured number of active WLAN-GW IOMs. This triggers withdrawal of the route to tunnel endpoint and subscriber subnets in routing.

router

Syntax 
router router-instance
no router
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command specifies the routing instance that wlan-gw gateway endpoint resides in.

The no form of this command removes the value from the wlan-gw configuration.

Default 

router

Parameters 
router-instance—
Specifies the identifier of the virtual router instance where the tunneled UE traffic is routed.

tcp-mss-adjust

Syntax 
tcp-mss-adjust segment-size
no tcp-mss-adjust
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command configures the TCP Maximum Segment Size (MSS) adjustment for the wlan-gw gateway.

The no form of this command disables adjusting tcp-mss values.

For DSM, this only applies to packets sent in the downstream direction (TCP SYN towards UE). For the upstream direction, it is also required to configure MSS adjust under the applicable NAT-policy.

Parameters 
segment-size—
Specifies the value to put into the TCP Maximum Segment Size (MSS) option if not already present, or if the present value is higher.
Values—
160 to 10240

 

tunnel-encaps

Syntax 
tunnel-encaps
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command enables the context to configure tunnel encapsulation parameters.

learn-l2tp-cookie

Syntax 
learn-l2tp-cookie {if-match | never | always} [cookie hex string]
no learn-l2tp-cookie
Context 
config>service>ies>sub-if>grp-if>wlan-gw
config>service>vprn>sub-if>grp-if>wlan-gw
Description 

This command specifies when this system will learn the cookie from L2TP tunnels terminating on this interface. Learning the cookie means that the value of the octets 3-8 of the cookie is interpreted as an access point’s MAC address, and used as such, for example in the Called-Station-Id attribute of RADIUS Interim-Update messages.

Parameters 
if-match —
Specifies that the cookie is interpreted only if the value of the first two octets of the cookie is equal to the value of the object tmnxWlanGwSoftGreIfL2tpCookie.
cookie hex string
Specifies the value used to compare the first two bytes of the cookie. This parameter is only valid if if-match is configured.
Values—
0x0000 to 0xFFFF...(4 hex nibbles)

 

never —
Specifies that the cookie value will always be ignored.
always—
Always learn the AP-MAC from the cookie, regardless of the value of the first two bytes.

retail-svc-id

Syntax 
retail-svc-id service-id
no retail-svc-id
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range
Description 

This command configures the retailer service.

Parameters 
service-id—
Specifies the identifier of the retail service.
Values—
1 to 2147483650
svc-name: up to 64 characters

 

router-advertisements

Syntax 
[no] router-advertisements
Context 
config>service>vprn>sub-if>grp-if>ipv6
config>service>ies>sub-if>grp-if>ipv6
Description 

This command configures IPv6 router advertisements for this group-interface.

current-hop-limit

Syntax 
[no] current-hop-limit limit
Context 
config>service>vprn>sub-if>grp-if>ipv6>rtr-adv
config>service>ies>sub-if>ipv6>rtr-adv
Description 

This command configures the hop-limit advertised for this group-interface.

Default 

current-hop-limit

Parameters 
limit—
Specifies the default value to be placed in the current hop limit field in router advertisements sent from this interface.
Values—
0 to 255

 

pool-manager

Syntax 
pool-manager
Context 
config>service>ies>sub-if>wlan-gw
config>service>vprn>sub-if>wlan-gw
Description 

This command enables the context to configure pool manager data for a WLAN GW subscriber interface.

dhcpv6-client

Syntax 
dhcpv6-client
Context 
config>service>ies>sub-if>wlan-gw>pool-manager
config>service>vprn>sub-if>wlan-gw>pool-manager
Description 

This command configures the DHCPv6 client for the pool manager.

dhcpv4-nat

Syntax 
dhcpv4-nat
Context 
config>service>ies>sub-if>wlan-gw>pool-manager>dhcp6-client
config>service>vprn>sub-if>wlan-gw>pool-manager>dhcp6-client
Description 

This node enables address pools for DHCPv4 NAT inside addresses. This configuration is only available in wholesale interfaces.

ia-na

Syntax 
ia-na
Context 
config>service>ies>sub-if>wlan-gw>pool-manager>dhcp6-client
config>service>vprn>sub-if>wlan-gw>pool-manager>dhcp6-client
Description 

This command configures the IA-NA for the DHCPv6 client.

link-addr

Syntax 
link-addr ipv6-address
no link-addr
Context 
config>service>ies>sub-if>wlan-gw>pool-manager>dhcp6-client>slaac
config>service>vprn>sub-if>wlan-gw>pool-manager>dhcp6-client>slaac
config>service>ies>sub-if>wlan-gw>pool-manager>dhcp6-client>ia-na
config>service>vprn>sub-if>wlan-gw>pool-manager>dhcp6-client>ia-na
config>service>ies>sub-if>wlan-gw>pool-manager>dhcp6-client>dhcpv4-nat
config>service>vprn>sub-if>wlan-gw>pool-manager>dhcp6-client>dhcpv4-nat
Description 

This command specifies the ipv6-address that should be included in the link-address field of the relay header. This can be used for pool selection by the DHCPv6 server.

The no form of this command falls back to the default.

Parameters 
ipv6-address—
Specifies the IPv6 address up to 32 characters.

pool-name

Syntax 
pool-name name
no pool-name
Context 
config>service>ies>sub-if>wlan-gw>pool-manager>dhcp6-client>slaac
config>service>vprn>sub-if>wlan-gw>pool-manager>dhcp6-client>slaac
config>service>ies>sub-if>wlan-gw>pool-manager>dhcp6-client>ia-na
config>service>vprn>sub-if>wlan-gw>pool-manager>dhcp6-client>ia-na
config>service>ies>sub-if>wlan-gw>pool-manager>dhcp6-client>dhcpv4-nat
config>service>vprn>sub-if>wlan-gw>pool-manager>dhcp6-client>dhcpv4-nat
Description 

This command specifies the pool name that should be sent in the DHCPv6 messages. This is reflected in the Nokia vendor specific pool option (vendor-id 6527, option-id 0x02).

The no form of this command removes pool-name and the option will not be sent in DHCPv6.

Parameters 
name—
Specifies the pool name up with 32 characters.

lease-query

Syntax 
lease-query [max-retry Max nbr of retries]
no lease-query
Context 
config>service>vprn>sub-if>wlan-gw>pool-manager>dhcp6-client
config>service>ies>sub-if>wlan-gw>pool-manager>dhcp6-client
Description 

This command enables lease-query. If this is specified the dhcp6-client will retrieve any existing addresses when becoming active. The lease-query is performed for all of the configured servers

The no form of this command disables lease-query.

Parameters 
Max nbr of retries—
Specifies the maximum number of retries before the lease query assumes no existing subnets were allocated.
Values—
0 to 10

 

server

Syntax 
server ipv6-address [ipv6-address]
no server [ipv6-address [ipv6-address]]
Context 
config>service>vprn>sub-if>wlan-gw>pool-manager>dhcp6-client
config>service>ies>sub-if>wlan-gw>pool-manager>dhcp6-client
Description 

This specifies the DHCPv6 servers that are used for requesting addresses.

The no form of this command removes the server. This cannot be executed while any DHCPv6 client application is not shut down.

Parameters 
ipv6-address—
Specifies up to 8 unicast IPv6 addresses of a DHCP6 server.

slaac

Syntax 
slaac
Context 
config>service>vprn>sub-if>wlan-gw>pool-manager>dhcp6-client
config>service>ies>sub-if>wlan-gw>pool-manager>dhcp6-client
Description 

This command configures SLAAC for the DHCPv6 client.

source-ip

Syntax 
source-ip ipv6-address
no source-ip
Context 
config>service>vprn>sub-if>wlan-gw>pool-manager>dhcp6-client
config>service>ies>sub-if>wlan-gw>pool-manager>dhcp6-client
Description 

This command specifies the source-ip to be used by the DHCPv6 client.

The no form of this command removes the specific source-ip. In this case the DHCPv6 client will fall back to the IP address configured on the outgoing interface.

Parameters 
ipv6-address—
Specifies the IPv6 address, up to 32 characters.

watermarks

Syntax 
watermarks high high-percentage low low-percentage
no watermarks
Context 
config>service>vprn>sub-if>wlan-gw>pool-manager
config>service>ies>sub-if>wlan-gw>pool-manager
Description 

This command configures the watermarks used to determine if a new prefix should be allocated or an old prefix should be removed. A new prefix is allocated when the total usage level for the ISA reaches the high watermark. A prefix is freed if no addresses are currently in use and the usage level without this prefix would be below the low watermark.

The no form of this command resets the watermarks to its default values of 95% high and 90% low.

Default 

watermarks high 95 low 90

Parameters 
high-percentage
Specifies the high watermark.
Values—
80 to 99

 

low-percentage
Specifies the low watermark. The value must be lower than the high percentage value.
Values—
50 to 98

 

wlan-gw-group

Syntax 
wlan-gw-group nat-group-id
no wlan-gw-group
Context 
config>service>vprn>sub-if>wlan-gw>pool-manager
config>service>ies>sub-if>wlan-gw>pool-manager
Description 

This command specifies the ISA WLAN gateway group.

Parameters 
nat-group-id—
Specifies the identifier of the WLAN gateway group.
Values—
1 to 4

 

redundancy

Syntax 
redundancy
Context 
config>service>ies>sub-if>wlan-gw
Description 

This command enables the context to configure WLAN-GW redundancy-related parameters.

export

Syntax 
export ip-prefix/length
no export
Context 
config>service>ies>sub-if>wlan-gw>redundancy
Description 

This command specifies an IPv4 route (prefix/length) per subscriber-interface to be exported (announced) to indicate liveness of the subscriber-interface on the WLAN-GW. This route is the one that is monitored in routing by the peer WLAN-GW to decide its state with respect.

The no form of this command reverts to the default.

Parameters 
ip-prefix/length—
Specifies the IP prefix and length.
Values—
ip-prefix:a.b.c.d
ip-prefix-length: 0 to 32

 

monitor

Syntax 
monitor ip-prefix/length
no monitor
Context 
config>service>ies>sub-if>wlan-gw>redundancy
Description 

This command specifies an IPv4 route (prefix/length) per subscriber-interface to be monitored in the FDB to determine liveness of the subscriber-interface (and consequently all associated group-interfaces of type wlangw) on a peer WLAN-GW. This route is the one that is advertised in routing by the peer WLAN-GW when the subscriber-interface and WLAN-GW group are operationally up.

Parameters 
ip-prefix/length—
Specifies the IP prefix and length.
Values—
ip-prefix:a.b.c.d
ip-prefix-length: 0 to 32

 

12.25.2.8. Migrant User Support Commands

http-redirect-policy

Syntax 
http-redirect-policy policy-name
no http-redirect-policy
Context 
config>subscr-mgmt
Description 

This command configures the redirect policy to constrain forwarding of an unauthenticated “migrant” WIFI user.

Parameters 
policy-name —
Specifies the HTTP redirect policy name up to 32 characters.

forward-entries

Syntax 
forward-entries
Context 
config>subscr-mgmt>http-rdr-plcy
Description 

Enters the context to configure entries that need to be forwarded.

dst-port

Syntax 
dst-port tcp-port
no dst-port
Context 
config>subscr-mgmt>http-rdr-plcy
Description 

This command specifies the port to match the destination port in the HTTP request.

HTTP traffic that does not match this port, is not redirected.

The no form of this command reverts to the default.

Default 

dst-port 80

Parameters 
tcp-port—
Specifies the TCP port.
Values—
1 to 65535

 

dst-ip

Syntax 
dst-ip ip-address protocol ip-protocol dst-port port-number
dst-ip ip-address protocol ip-protocol dst-port port-number prefix-length prefix-length
no dst-ip ip-address protocol ip-protocol dst-port port-number
Context 
config>subscr-mgmt>http-rdr-plcy
Description 

This command configures traffic flow to be forwarded via match in the redirect policy.

Parameters 
ip-address—
Specifies the IPv4 or IPv6 address to match the destination address in the IP header of the traffic received from the subscriber.
prefix-length—
Specifies the length of the prefix specified by the ip-address.
Values—
1 to 128 for IPv6
1 to 32 for IPv4

 

ip-protocol
Specifies the protocol to match the IP protocol in the IP header of the traffic received from the subscriber.
Values—
tcp, udp

 

port-number
Specifies the port to match the destination port in the HTTP request.
Values—
1 to 65535

 

portal-hold-time

Syntax 
portal-hold-time seconds
no portal-hold-time
Context 
config>subscr-mgmt>http-rdr-plcy
Description 

This command configures the time for which the forwarding state applicable during redirect phase is held in the system, after the user has been authenticated on the portal. This allows the HTTP response from the portal to be forwarded back on the existing connection.

Parameters 
seconds—
Specifies how long the system holds on to re-direct forwarding resources of a subscriber, after it has left the re-direct portal.
Values—
1 to 60

 

url

Syntax 
url rdr-url-sting
no url
Context 
config>subscr-mgmt>http-rdr-plcy
Description 

This command configures the HTTP URL to re-direct the matching traffic to. It also can specify inclusion of original URL, MAC address and IP address of the subscriber in the redirect URL.

Parameters 
rdr-url-sting—
Specifies the URL to redirect to.
Values—

rdr-url-string

Up to 255 characters

macro substitutions:

$URL

Request-URI in the HTTP GET Request received

$MAC

A string that represents the MAC address of the subscriber host

$IP

A string that represents the IP address of the subscriber host

 

wlan-gw

Syntax 
wlan-gw
Context 
config>service>vprn>sub-if>grp-if
config>service>ies>sub-if>grp-if
Description 

This command enables the context to configure wlan-gw parameters.

vlan-tag-ranges

Syntax 
vlan-tag-ranges
Context 
config>service>vprn>sub-if>grp-if>wlan-gw
config>service>ies>sub-if>grp-if>wlan-gw
Description 

This command enables the context for per VLAN range configuration.

default-retail-svc-id

Syntax 
default-retail-svc-id service-id
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges
config>service>ies>sub-if>grp-if>wlan-gw>ranges
Description 

This command configures the default retailer service for WIFI users.

dhcp

Syntax 
dhcp
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges
config>service>ies>sub-if>grp-if>wlan-gw>ranges
Description 

This command enables the context to create DHCP configuration for WLAN-GW ISA subscribers (such as migrant subscribers).

dhcp6

Syntax 
dhcp6
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges
config>service>ies>sub-if>grp-if>wlan-gw>ranges
Description 

This command enables the context to create DHCP6 configuration for WLAN-GW ISA subscribers.

active-preferred-lifetime

Syntax 
active-preferred-lifetime [hrs hours] [min minutes] [sec seconds]
no active-preferred-lifetime
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dhcp6
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dhcp6
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>slaac
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>slaac
Description 

This command specifies the signaled preferred lifetime in DHCPv6 or SLAAC after full authentication. This is only applicable to DSM.

The no form of this command reverts to the default.

Default 

active-preferred-lifetime min 10

Parameters 
hours
Specifies the number of active preferred lifetime hours.
Values—
1 to 1

 

minutes
Specifies the number of active preferred lifetime minutes.
Values—
5 to 59

 

seconds
Specifies the number of active preferred lifetime seconds.
Values—
1 to 59

 

active-valid-lifetime

Syntax 
active-valid-lifetime [hrs hours] [min minutes] [sec seconds]
no active-valid-lifetime
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dhcp6
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dhcp6
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>slaac
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>slaac
Description 

This command specifies the signaled valid lifetime in DHCPv6 or SLAAC after full authentication. This is only applicable to DSM.

The no form of this command reverts to the default.

Default 

active-valid-lifetime min 10

Parameters 
hours
Specifies the number of active-valid-lifetime hours.
Values—
1 to 1

 

minutes
Specifies the number of active-valid-lifetime minutes.
Values—
5 to 59

 

seconds
Specifies the number of active-valid-lifetime seconds.
Values—
1 to 59

 

active-lease-time

Syntax 
active-lease-time [hrs hours] [min minutes] [sec seconds]
no active-lease-time
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>dhcp
config>service>ies>sub-if>grp-if>wlan-gw>dhcp
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dhcp
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dhcp
Description 

This command configures the lease time for an authenticated user.

Default 

active-lease-time min 10

Parameters 
hours
Specifies the number of active lease time hours.
Values—
1 to 1

 

minutes
Specifies the number of active lease time minutes.
Values—
5 to 59

 

seconds
Specifies the number of active lease time seconds.
Values—
1 to 59

 

initial-preferred-lifetime

Syntax 
initial-preferred-lifetime [hrs hours] [min minutes] [sec seconds]
no initial-preferred-lifetime
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dhcp6
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dhcp6
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>slaac
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>slaac
Description 

This command specifies the signaled preferred lifetime in DHCPv6 or SLAAC after full authentication (DSM and/or ESM).

The no form of this command reverts to the default.

Default 

initial-preferred-lifetime min 5

Parameters 
hours
Specifies the number of initial preferred lifetime hours.
Values—
1 to 1

 

minutes
Specifies the number of initial preferred lifetime minutes.
Values—
5 to 59

 

seconds
Specifies the number of initial preferred lifetime seconds.
Values—
1 to 59

 

Combined values: min 5 – hrs 1

initial-valid-lifetime

Syntax 
initial-valid-lifetime [hrs hours] [min minutes] [sec seconds]
no initial-valid-lifetime
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dhcp6
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dhcp6
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>slaac
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>slaac
Description 

This command specifies the signaled preferred lifetime in DHCPv6 or SLAAC during a migrant phase.

The no form of this command reverts to the default.

Default 

initial-valid-lifetime min 5

Parameters 
hours
Specifies the number of initial preferred lifetime hours.
Values—
1 to 1

 

minutes
Specifies the number of initial preferred lifetime minutes.
Values—
5 to 59

 

seconds
Specifies the number of initial preferred lifetime seconds.
Values—
1 to 59

 

Combined values: min 5 – hrs 1

initial-lease-time

Syntax 
initial-lease-time [hrs hours] [min minutes] [sec seconds]
no initial-lease-time
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>dhcp
config>service>ies>sub-if>grp-if>wlan-gw>dhcp
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dhcp
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dhcp
Description 

This command configures the lease time for a user which is migrant (unauthenticated).

Default 

initial-lease-time min 10

Parameters 
hours
Specifies the number of initial lease time hours.
Values—
1 to 1

 

minutes
Specifies the number of initial lease time minutes.
Values—
5 to 59

 

seconds
Specifies the number of initial lease time.
Values—
1 to 59

 

l2-aware-ip-address

Syntax 
l2-aware-ip-address ip-address
l2-aware-ip-address from-pool
no l2-aware-ip-address
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dhcp
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dhcp
Description 

This command configures the L2-Aware NAT inside IP address to be assigned via DHCP on WLAN-GW ISA.

If the from-pool parameter is specified instead of an IPv4 address, a unique address is allocated to each UE. The pool used is managed by the dhcpv4-nat pool manager, configured under the same subscriber interface. This option is only available when auth-on-dhcp is also configured.

The no form of this command reverts to the default.

Parameters 
ip-address—
Specifies the L2-Aware NAT inside IP address.
from-pool—
Specifies that the L2-Aware IP address is allocated from a pool.

primary-dns

Syntax 
primary-dns ip-address
no primary-dns
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dhcp
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dhcp
Description 

This command configures the primary DNS address to be returned via DHCP on WLAN-GW ISA.

The no form of this command reverts to the default.

Parameters 
ip-address—
Specifies the primary DNS address.

secondary-dns

Syntax 
secondary-dns ip-address
no secondary-dns
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dhcp
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dhcp
Description 

This command configures the secondary DNS address to be returned via DHCP on WLAN-GW ISA.

The no form of this command reverts to the default.

Parameters 
ip-address—
Specifies the secondary DNS address.

primary-nbns

Syntax 
primary-nbns ip-address
no primary-nbns
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dhcp
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dhcp
Description 

This command configures the primary NBNS address to be returned via DHCP on WLAN-GW ISA.

The no form of this command reverts to the default.

Parameters 
ip-address—
Specifies the primary NBNS address.

secondary-nbns

Syntax 
secondary-nbns ip-address
no secondary-nbns
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>dhcp
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>dhcp
Description 

This command configures the secondary NBNS address to be returned via DHCP on WLAN-GW ISA.

The no form of this command reverts to the default.

Parameters 
ip-address—
Specifies the secondary NBNS address.

idle-timeout

Syntax 
idle-timeout action idle-timeout-action
no idle-timeout
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range
Description 

This command specifies idle-timeout behavior for DSM UEs and UEs undergoing (ISA-based) portal authentication. This knob only specifies the desired action, idle-timeout is activated by RADIUS on a per-UE basis.

The no form of this command resets the idle-timeout to its default

Default 

idle-timeout action remove

Parameters 
action —
Specifies which action to perform when the idle-timeout timer goes off.
Values—
remove, shcv

 

http-redirect-policy

Syntax 
http-redirect-policy policy-name
no http-redirect-policy
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range
Description 

This command specifies http redirect policy on ISA to redirect http traffic to the URL specified in the policy.

The no form of this command reverts to the default.

Parameters 
policy-name —
Specifies the name of the http redirect policy under subscriber-management context.

l2-service

Syntax 
l2-service service-id
no l2-service
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range
Description 

This command specifies the VPLS service used for L2 wholesale. When such a service is configured no other configuration is allowed under the vlan-range.

The no form of this command removes the L2 wholesale service, this is only allowed if the l2-service node is shut down.

Parameters 
service-id—
Specifies the VPLS service ID to use for Layer 2 wholesale.

nat-policy

Syntax 
nat-policy policy-name
no nat-policy
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range
Description 

This command specifies the NAT policy for WLAN-GW ISA subscribers.

The no form of this command reverts to the default.

brg

Syntax 
brg
Context 
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range
config>service>ies>sub-if>grp-if
config>service>vprn>sub-if>grp-if
Description 

This command enables the context to configure BRG parameters. In the config>service>ies>sub-if>grp-if and config>service>vprn>sub-if>grp-if contexts, these commands are only available in the vlan-tag-ranges context.

authenticated-brg-only

Syntax 
[no] authenticated-brg-only
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>brg
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>brg
config>service>vprn>sub-if>grp-if>brg
config>service>ies>sub-if>grp-if>brg
Description 

This command indicates that only BRGs that are pre-authenticated using the RADIUS proxy are allowed in this context.

The no form of this command removes the restriction.

default-brg-profile

Syntax 
default-brg-profile profile-name
no default-brg-profile
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>brg
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>brg
config>service>vprn>sub-if>grp-if>brg
config>service>ies>sub-if>grp-if>brg
Description 

This command indicates that the default BRG profile must be used for new BRGs. This profile can be overridden by RADIUS.

The no form of this command removes the profile name from the configuration.

Parameters 
profile-name—
Specifies the name of the brg-profile to be applied.

data-triggered-ue-creation

Syntax 
[no] data-triggered-ue-creation
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range
Description 

This command enables or disables data-triggered subscriber creation for WIFI subscribers. Data triggered UE creation is currently only supported for UDP and TCP packets.

The no form of this command reverts to the default.

track-mobility

Syntax 
track-mobility
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range
Description 

This command enables the context to configure RADIUS-proxy cache information required for subscribers that are created via data-triggered authentication. The RADIUS proxy cache enables efficient handling of UE mobility.

mac-format

Syntax 
mac-format mac-format
no mac-format
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>track-mobility
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>track-mobility
Description 

This command configures how the MAC address is represented by the RADIUS proxy server.

Default 

no mac-format "aa:"

Parameters 
mac-format—
Specifies how the MAC address is represented by the RADIUS proxy server.
Values—

mac-format

like ab: for 00:0c:f1:99:85:b8

or XY- for 00-0C-F1-99-85-B8

or mmmm. for 0002.03aa.abff

or xx for 000cf19985b8

 

radius-proxy-cache

Syntax 
radius-proxy-cache router router-instance server server-name
no radius-proxy-cache
Context 
config>service>vprn>sub-if>grp-if>wlan-gw>ranges>range>track-mobility
config>service>ies>sub-if>grp-if>wlan-gw>ranges>range>track-mobility
Description 

This command specifies the RADIUS-proxy server to allow subscribers created via data-triggered authentication to create an entry. This RADIUS proxy cache entry allows efficient handling of UE mobility.

Parameters 
router-instance
Specifies the router instance.
Values—

router-name

Base

service-id

1 to 2147483647

 

server-name
Specifies the server name up to 32 characters.

sap-template

Syntax 
sap-template sap-template
no sap-template
Context 
config>service>vpls>wlan-gw
Description 

This command specifies the VPLS SAP template that is applied on the internal SAPs created for communication between the VPLS and the ISAs.

The no form of this command removes the SAP template.

Parameters 
sap-template —
Specifies the existing SAP template to apply. The template is created in the config>service>template context.

12.25.2.8.1. Show Commands

Note:

The command outputs in the following section are examples only; actual displays may differ depending on supported functionality and user configuration.

call-trace

Syntax 
call-trace
Context 
show
Description 

This command enables the context to display information related to the call-trace module.

wlan-gw

Syntax 
wlan-gw
Context 
show>call-trace
Description 

The command enables the context to display information related to the wlan-gw call-trace functionality.

ue

Syntax 
ue [ieee-address] [detail]
Context 
show>call-trace
Description 

This command gives an overview of either all traces or a specific trace on the WLAN-GW.

Parameters 
ieee-address—
Displays information about the MAC address of this UE.
detail—
Displays detailed information about the job.
Output 

The following output is an example of traces of the UE being monitored.

Sample Output
Node# show call-trace hosts
===============================================================================
Call-trace hosts
===============================================================================
 MAC address Mask-name     Status      Msgs
-------------------------------------------------------------------------------
 00:0a:95:9d:68:16 N/A                running   16
-------------------------------------------------------------------------------
Number of call-trace debug jobs: 1
=============================================================================
Node# show call-trace hosts detail
===============================================================================
Call-trace  detail
===============================================================================
MAC address                            : 00:0a:95:95:34:0a                 Status : running
                   Capture format     : pcap
Nr. of captured msgs   : 4 Time limit            : 86400s
Size of captured msgs : 2620B Data limit             : 10MB
Started : NOV 12 2013, 15:28:17 UTC
Live output : N/A
-------------------------------------------------------------------------------
 

acct-on-off-group

Syntax 
acct-on-off-group [group-name]
Context 
show>aaa
Description 

This command displays Acct-On-Off group information and the associated RADIUS server policies.

Parameters 
group-name—
Displays information pertaining to the specified acct-on-off group.
Output 

The following output is an example of AAA Acct-On-Off group information.

Sample Output
# show aaa acct-on-off-group "group-1" 
===============================================================================
Acct-On-Off-Group Information
===============================================================================
acct on off group name               : group-1
  - controlling Radius-Server-policy :  
        aaa-server-policy-3
  - monitored by Radius-Server-policy :  
        aaa-server-policy-4
-------------------------------------------------------------------------------
Nbr of Acct-on-off-groups displayed : 1
-------------------------------------------------------------------------------
===============================================================================
 
Table 168:  WiFi Acct-On-Off Field Descriptions 

Label

Description

acct on off group name

The name of a RADIUS server policy Accounting-On-Off-Group

controlling Radius-Server-policy

The controlling RADIUS server policy name

monitored by Radius-Server-policy

The policy monitored a RADIUS server policy.

Nbr of Acct-on-off-groups displayed

The RADIUS policy that controls the Acct-On-Off group

radius-proxy-server

Syntax 
radius-proxy-server server-name
radius-proxy-server server-name cache
radius-proxy-server server-name cache hex-key hex-string
radius-proxy-server server-name cache string-key string
radius-proxy-server server-name cache summary
radius-proxy-server server-name statistics
radius-proxy-server
Context 
show>router
Description 

This command displays summary of RADIUS-proxy cache or specific entries.

Parameters 
server-name—
Displays information about the specified server name.
cache—
Displays messages used to generate the key for the cache of this RADIUS proxy server.
hex-key hex-string
Displays information about the specified hex string.
Values—
0x0 to 0xFFFFFFFF (maximum of 64 hex nibbles)]

 

string
Displays information about the specified string.
summary—
Displays a summary of the cache of the RADIUS proxy servers.
statistics—
Displays statistics about the RADIUS proxy servers of this system.
Output 

The following is an example of RADIUS proxy server information.

Sample Output
system# show router 10 radius-proxy-server "myProxyServer1" 
===============================================================================
RADIUS Proxy server "myProxyServer1"
===============================================================================
Description                 : myDesc
Purpose                     : authentication 
Administrative state        : in-service
Default acct server policy  : myRadiusServerPolicy1
Default auth server policy  : myRadiusServerPolicy2
Send accounting response    : true
Last management change      : 02/17/2012 14:54:28
-------------------------------------------------------------------------------
Cache settings
-------------------------------------------------------------------------------
Administrative state        : enabled
Key packet type             : access-accept
Key attribute type          : 12
Key vendor ID               : (Not Specified)
Timeout (s)                 : 60
Track accounting            : stop interim-update accounting-on accounting-off 
Load balance key            : source-ip-udp
===============================================================================
Interfaces
-------------------------------------------------------------------------------
myInterface1                     
myInterface2                     
myInterface3                     
-------------------------------------------------------------------------------
No. of Interface(s): 3
===============================================================================
Usernames/RADIUS server policies
===============================================================================
Id Username-match                     RADIUS-server-policy             Purpose
------------------------------------------------------------------------------------
1.  aaa                                myRadiusServerPolicy2 auth
==============================================================================
system# 
Table 169:  RADIUS Proxy Server Field Descriptions 

Label

Description

Description

The description of this RADIUS proxy server

Purpose

The purpose of the RADIUS server, either accounting or authentication

Administrative state

The administrative state of this RADIUS server

Default acct server policy

The name of the default RADIUS server policy associated with this RADIUS proxy server for accounting purposes

Default auth server policy

The name of the default RADIUS server policy associated with this RADIUS proxy server for authentication purposes

Send accounting response

Specifies if this RADIUS Proxy server itself responds with an Accounting-Response message to each received Accounting-Request instead of proxying them to a configured RADIUS server

Last management change

The sysUpTime at the time of the most recent management-initiated change

Key packet type

The packet type of the RADIUS messages to use to generate the key for the cache of this RADIUS proxy server, access-request, access-accept, access-reject, access-challenge

Key attribute

type

The RADIUS attribute type to cache for this RADIUS proxy server. Refer to RFC 2865, Remote Authentication Dial In User Service (RADIUS), Section 5 Attributes.

Key vendor ID

The RADIUS Vendor-Id. Refer to RFC 2865, Remote Authentication Dial In User Service (RADIUS), Section 5.25 Vendor-Specific

Timeout (s)

Displays, in seconds, the timeout after which an entry in the cache will expire

Track accounting

The RADIUS accounting packets that have impact on the cache of this RADIUS proxy server

Load balance key

The key for load-balancing RADIUS messages between RADIUS servers

Id

The specifies the RADIUS Vendor-Id

Username

The user name

RADIUS-server-policy

The RADIUS server name

Purpose

The purpose of the RADIUS server, either accounting or authentication

wlan-gw

Syntax 
wlan-gw
Context 
show>router
Description 

This command displays Wireless LAN Gateway information.

isa-subnets

Syntax 
isa-subnets [detail]
isa-subnets [detail] interface interface-name
isa-subnets prefix ipv6-address/prefix-length
Context 
show>router>wlan-gw
Description 

This command outputs all the prefixes in use by the WLAN GW pool manager.

Parameters 
detail—
Displays detailed information for each prefix.
interface-name
Displays only the prefixes associated with this subscriber interface.
ipv6-address/prefix-length—
Displays details of a specific IPv6 address and prefix.
Output 

The following is an example of WLAN-GW ISA subnet information.

Sample Output
system# show router wlan-gw isa-subnets
===============================================================================
ISA Subnets
===============================================================================
Prefix                                                   MDA     Family  Usage
-------------------------------------------------------------------------------
2001:db8:0:1/48                                            3/1     dhcpv6  0%
2001:db8:1::/48                                          3/2     dhcpv6  0%
2001:db8:2::/48                                          4/1     dhcpv6  0%
2001:db8:3::/48                                          4/2     dhcpv6  0%
2001:db8:4::/48                                          5/1     dhcpv6  0%
2001:db8:5::/48                                          5/2     dhcpv6  0%
2001:db8:6::/48                                          3/1     slaac   0%
2001:db8:7::/48                                          3/2     slaac   0%
2001:db8:8::/48                                          4/1     slaac   0%
2001:db8:9::/48                                          4/2     slaac   0%
2001:db8:a::/48                                          5/1     slaac   0%
2001:db8:b::/48                                          5/2     slaac   0%
-------------------------------------------------------------------------------
No. of ISA subnets: 12
===============================================================================
 
*A:Dut-C# show router wlan-gw isa-subnets prefix 2001:db8::/48
===============================================================================
ISA Subnet Prefix           : 2001:db8::/48
-------------------------------------------------------------------------------
Group Id                    : 1
Member Id                   : 1
MDA                         : 3/1
Family                      : dhcpv6
Subscriber Interface        : wlangw-sub-itf
Pool Is Old                 : No
Usage Level                 : 0%
Remaining Lease Time        : 0d 23:50:54
DHCPv6 Options              : (length=512)
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                            : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
===============================================================================
 

mgw-address-cache

Syntax 
mgw-address-cache [arec] [snaptr] [srv]
mgw-address-cache apn apn-domain-string
Context 
show>router>wlan-gw
Description 

This command displays the mobile gateway's DNS lookup address cache.

Parameters 
arec—
Displays A-records.
snaptr—
Displays Straightforward-NAPTR information.
srv—
Displays SRV records.
apn-domain-string
Specifies the Access Point Name (APN) of this DNS cache entry.
Output 

The following output is an example of WLAN-GW DNS lookup address cache information.

Sample Output
*A:Dut-C# show router 300 wlan-gw mgw-address-cache 
===============================================================================
Mobile Gateway SNAPTR cache
===============================================================================
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.
                              3gppnetwork.org
Order                       : 10
Index                       : 1
-------------------------------------------------------------------------------
Preference                  : 10
Service                     : x-3gpp-pgw:x-gn-gtp
Next lookup                 : dns-srv
Replacement                 : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.
                              3gppnetwork.org
Time left (s)               : 3582
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.
                              3gppnetwork.org
Order                       : 20
Index                       : 2
-------------------------------------------------------------------------------
Preference                  : 20
Service                     : x-3gpp-pgw:x-s2a-gtp
Next lookup                 : dns-srv
Replacement                 : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.
                              3gppnetwork.org
Time left (s)               : 3582
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.
                              3gppnetwork.org
Order                       : 30
Index                       : 3
-------------------------------------------------------------------------------
Preference                  : 30
Service                     : x-3gpp-pgw:x-s2b-gtp
Next lookup                 : dns-srv
Replacement                 : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.
                              3gppnetwork.org
Time left (s)               : 3581
-------------------------------------------------------------------------------
No. of SNAPTR cache entries: 3
===============================================================================
===============================================================================
Mobile Gateway SRV cache
===============================================================================
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.
                              3gppnetwork.org
Priority                    : 10      
Index                       : 1
-------------------------------------------------------------------------------
Weight                      : 10
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a1.
                              3gppnetwork.org
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.
                              3gppnetwork.org
Priority                    : 20
Index                       : 2
-------------------------------------------------------------------------------
Weight                      : 20
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a2.
                              3gppnetwork.org
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.
                              3gppnetwork.org
Priority                    : 10
Index                       : 1
-------------------------------------------------------------------------------
Weight                      : 10      
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a1.
                              3gppnetwork.org
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.
                              3gppnetwork.org
Priority                    : 20
Index                       : 2
-------------------------------------------------------------------------------
Weight                      : 20
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a2.
                              3gppnetwork.org
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.
                              3gppnetwork.org
Priority                    : 10
Index                       : 1
-------------------------------------------------------------------------------
Weight                      : 10
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a1.
                              3gppnetwork.org
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.
                              3gppnetwork.org
Priority                    : 20
Index                       : 2
-------------------------------------------------------------------------------
Weight                      : 20
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a2.
                              3gppnetwork.org
Time left (s)               : 3581
-------------------------------------------------------------------------------
No. of SRV cache entries: 6
===============================================================================
===============================================================================
Mobile Gateway address cache
===============================================================================
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.23
Time left (s)               : 3581 
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.29
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      :  10.0.0.35
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      :  10.0.0.24
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.30
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.36
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.25
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.31
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.37
Time left (s)               : 3581
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.26
Time left (s)               : 3580
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.32
Time left (s)               : 3580
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.38
Time left (s)               : 3580
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.27
Time left (s)               : 3580
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.33
Time left (s)               : 3580
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.39
Time left (s)               : 3580
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.28
Time left (s)               : 3580
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.34
Time left (s)               : 3580
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.40
Time left (s)               : 3580
-------------------------------------------------------------------------------
No. of cache entries: 18
 
 
*A:Dut-C# show router 300 wlan-gw mgw-address-cache arec 
===============================================================================
Mobile Gateway address cache
===============================================================================
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.23
Time left (s)               : 3573
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.29
Time left (s)               : 3573
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.35
Time left (s)               : 3573
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.24
Time left (s)               : 3573
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.30
Time left (s)               : 3573
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.36
Time left (s)               : 3573
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.25
Time left (s)               : 3573
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.31
Time left (s)               : 3573
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.37
Time left (s)               : 3573
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.26
Time left (s)               : 3573
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.32
Time left (s)               : 3573
-----------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.38
Time left (s)               : 3572
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.27
Time left (s)               : 3572
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.33
Time left (s)               : 3572
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.39
Time left (s)               : 3572 
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.28
Time left (s)               : 3572
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.34
Time left (s)               : 3572
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.40
Time left (s)               : 3572
-------------------------------------------------------------------------------
No. of cache entries: 18
===============================================================================
 
 
*A:Dut-C# show router 300 wlan-gw mgw-address-cache srv  
===============================================================================
Mobile Gateway SRV cache
===============================================================================
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.
                              3gppnetwork.org
Priority                    : 10
Index                       : 1
-------------------------------------------------------------------------------
Weight                      : 10
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a1.
                              3gppnetwork.org
Time left (s)               : 3567
 
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.
                              3gppnetwork.org
Priority                    : 20
Index                       : 2
-------------------------------------------------------------------------------
Weight                      : 20
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a2.
                              3gppnetwork.org
Time left (s)               : 3567    
 
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.
                              3gppnetwork.org
Priority                    : 10
Index                       : 1
-------------------------------------------------------------------------------
Weight                      : 10
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a1.
                              3gppnetwork.org
Time left (s)               : 3566
 
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.
                              3gppnetwork.org
Priority                    : 20
Index                       : 2
-------------------------------------------------------------------------------
Weight                      : 20
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a2.
                              3gppnetwork.org
Time left (s)               : 3566
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.
                              3gppnetwork.org
Priority                    : 10
Index                       : 1
-------------------------------------------------------------------------------
Weight                      : 10
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a1.
                              3gppnetwork.org
Time left (s)               : 3566
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.
                              3gppnetwork.org
Priority                    : 20
Index                       : 2
-------------------------------------------------------------------------------
Weight                      : 20
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a2.
                              3gppnetwork.org
Time left (s)               : 3566
-------------------------------------------------------------------------------
No. of SRV cache entries: 6
===============================================================================
 
 
*A:Dut-C# show router 300 wlan-gw mgw-address-cache snaptr
===============================================================================
Mobile Gateway SNAPTR cache
===============================================================================
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.
                              3gppnetwork.org
Order                       : 10
Index                       : 1
-------------------------------------------------------------------------------
Preference                  : 10
Service                     : x-3gpp-pgw:x-gn-gtp
Next lookup                 : dns-srv
Replacement                 : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.
                              3gppnetwork.org
Time left (s)               : 3555
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.
                              3gppnetwork.org
Order                       : 20
Index                       : 2
-------------------------------------------------------------------------------
Preference                  : 20
Service                     : x-3gpp-pgw:x-s2a-gtp
Next lookup                 : dns-srv
Replacement                 : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.
                              3gppnetwork.org
Time left (s)               : 3555
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.
                              3gppnetwork.org
Order                       : 30
Index                       : 3
-------------------------------------------------------------------------------
Preference                  : 30
Service                     : x-3gpp-pgw:x-s2b-gtp
Next lookup                 : dns-srv
Replacement                 : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.
                              3gppnetwork.org
Time left (s)               : 3554
 
-------------------------------------------------------------------------------
No. of SNAPTR cache entries: 3
 
 
*A:Dut-C# show router 300 wlan-gw mgw-address-cache apn full.dotted.apn.apn.epc.mnc010.mcc206.3gppnetwork.org 
===============================================================================
Mobile Gateway APN Cache
===============================================================================
-------------------------------------------------------------------------------
APN > NAPTR
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.
                              3gppnetwork.org
Order                       : 10
Index                       : 1
-------------------------------------------------------------------------------
Preference                  : 10
Service                     : x-3gpp-pgw:x-gn-gtp
Next lookup                 : dns-srv
Replacement                 : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.
                              3gppnetwork.org
Time left (s)               : 3531
-------------------------------------------------------------------------------
APN > NAPTR > SRV
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.
                              3gppnetwork.org
Priority                    : 10
Index                       : 1
-------------------------------------------------------------------------------
Weight                      : 10
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a1.
                              3gppnetwork.org
Time left (s)               : 3531
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.23
Time left (s)               : 3530
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.29
Time left (s)               : 3530
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.35
Time left (s)               : 3530
-------------------------------------------------------------------------------
APN > NAPTR > SRV
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.
                              3gppnetwork.org
Priority                    : 20
Index                       : 2
-------------------------------------------------------------------------------
Weight                      : 20
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a2.
                              3gppnetwork.org
Time left (s)               : 3530
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.24
Time left (s)               : 3530
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10,0.0.30
Time left (s)               : 3530
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv1.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.36
Time left (s)               : 3530
-------------------------------------------------------------------------------
APN > NAPTR
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.
                              3gppnetwork.org
Order                       : 20
Index                       : 2       
-------------------------------------------------------------------------------
Preference                  : 20
Service                     : x-3gpp-pgw:x-s2a-gtp
Next lookup                 : dns-srv
Replacement                 : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.
                              3gppnetwork.org
Time left (s)               : 3530
-------------------------------------------------------------------------------
APN > NAPTR > SRV
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.
                              3gppnetwork.org
Priority                    : 10
Index                       : 1
-------------------------------------------------------------------------------
Weight                      : 10
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a1.
                              3gppnetwork.org
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.25
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.31
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.37
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.
                              3gppnetwork.org
Priority                    : 20
Index                       : 2
-------------------------------------------------------------------------------
Weight                      : 20
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a2.
                              3gppnetwork.org
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.26
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.32
Time left (s)               : 3529
                                      
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv2.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.38
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.
                              3gppnetwork.org
Order                       : 30
Index                       : 3
-------------------------------------------------------------------------------
Preference                  : 30
Service                     : x-3gpp-pgw:x-s2b-gtp
Next lookup                 : dns-srv
Replacement                 : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.
                              3gppnetwork.org
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.
                              3gppnetwork.org
Priority                    : 10
Index                       : 1
-------------------------------------------------------------------------------
Weight                      : 10
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a1.
                              3gppnetwork.org
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.27
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.33
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a1.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.39
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.
                              3gppnetwork.org
Priority                    : 20
Index                       : 2
-------------------------------------------------------------------------------
Weight                      : 20
Port                        : 2123
Target                      : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a2.
                              3gppnetwork.org
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A                 
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.28
Time left (s)               : 3529
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.34
Time left (s)               : 3528
-------------------------------------------------------------------------------
APN > NAPTR > SRV > A
-------------------------------------------------------------------------------
APN                         : full.dotted.apn.apn.epc.mnc010.mcc206.srv3.a2.
                              3gppnetwork.org
-------------------------------------------------------------------------------
Mobile Gateway address      : 10.0.0.40
Time left (s)               : 3528
-------------------------------------------------------------------------------
No. of cache entries: 18 

tunnel-qos

Syntax 
tunnel-qos [detail]
tunnel-qos remote-ip ip-address [local-ip ip-address] [detail]
Context 
show>router>wlan-gw
Description 

This command displays tunnel-QoS resource information.

Parameters 
ip-address
Specifies the IPv4 address of the Mobile Gateway that is the source IPv4 address in the tunnel header of received packets.
Values—

ipv4-address:

a.b.c.d

ipv6-address :

x:x:x:x:x:x:x:x (eight 16-bit pieces)

x:x:x:x:x:x:d.d.d.d

x - [0 to FFFF]H

d - [0 to 255]D

 

ip-address
Specifies the IPv4 address of this system that is the destination IPv4 address in the tunnel header of received packets.
Values—

ipv4-address:

a.b.c.d

ipv6-address :

x:x:x:x:x:x:x:x (eight 16-bit pieces)

x:x:x:x:x:x:d.d.d.d

x - [0 to FFFF]H

d - [0 to 255]D

 

detail—
Displays detailed information.
Output 

The following output is an example of soft GRE tunnel QoS information.

Sample Output
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnel-qos 
===============================================================================
Soft GRE tunnel QoS
===============================================================================
Remote IP address           : 239.0.0.2
Local IP address            : 10.1.1.1
Operational state           : active
Number of UE                : 1
Remaining hold time (s)     : N/A
 
 
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnel-qos detail 
===============================================================================
Soft GRE tunnel QoS
===============================================================================
Remote IP address           : 239.0.0.2
Local IP address            : 10.1.1.1
Operational state           : active
Number of UE                : 1
Remaining hold time (s)     : N/A
Service Access Points(SAP)
===============================================================================
Service Id         : 2147483650               
SAP                : 5/1/lo-gre:1             Encap             : q-tag
Description        : Internal SAP
Admin State        : Up                       Oper State        : Up
Flags              : None
Multi Svc Site     : None                     
Last Status Change : 03/24/2014 15:03:48      
Last Mgmt Change   : 03/24/2014 15:14:00      
 
-------------------------------------------------------------------------------
Encap Group Specifics
-------------------------------------------------------------------------------
Encap Group Name   : _tmnx_SHAPER_GR000       Group Type        : ISID
Qos-per-member     : TRUE                     
Members            :
1                                     
 
-------------------------------------------------------------------------------
QOS
-------------------------------------------------------------------------------
E. qos-policy      : 1                        Q Frame-Based Acct: Disabled
E. Sched Policy    :                          E. Agg-limit      : -1
                                              Limit Unused BW   : Disabled
-------------------------------------------------------------------------------
Encap Group Member 1 Base Statistics
-------------------------------------------------------------------------------
Last Cleared Time     : N/A
 
Forwarding Engine Stats
                        Packets                 Octets
 
For. InProf           : 0                       0
For. OutProf          : 0                       0
Dro. InProf           : 0                       0
Dro. OutProf          : 0                       0
 
-------------------------------------------------------------------------------
Encap Group Member 1 Queue Statistics
-------------------------------------------------------------------------------
 
                        Packets                 Octets
 
Egress Queue 1                        
For. InProf           : 0                       0
For. OutProf          : 0                       0
Dro. InProf           : 0                       0
Dro. OutProf          : 0                       0
 
 
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnel-qos remote-ip 239.0.0.2 
===============================================================================
Soft GRE tunnel QoS
===============================================================================
Remote IP address           : 239.0.0.2
Local IP address            : 10.1.1.1
Operational state           : active
Number of UE                : 1
Remaining hold time (s)     : N/A
 
 
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnel-qos  remote-ip 239.0.0.2  local-ip 10.1.1.1 
===============================================================================
Soft GRE tunnel QoS
===============================================================================
Remote IP address           : 239.0.0.2
Local IP address            : 10.1.1.1
Operational state           : active
Number of UE                : 1
Remaining hold time (s)     : N/A
 
 
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnel-qos  remote-ip 239.0.0.2  local-ip 10.1.1.1 detail 
===============================================================================
Soft GRE tunnel QoS
===============================================================================
Remote IP address           : 239.0.0.2
Local IP address            : 10.1.1.1
Operational state           : active
Number of UE                : 1
Remaining hold time (s)     : N/A
Service Access Points(SAP)
===============================================================================
Service Id         : 2147483650               
SAP                : 5/1/lo-gre:1             Encap             : q-tag
Description        : Internal SAP
Admin State        : Up                       Oper State        : Up
Flags              : None
Multi Svc Site     : None                     
Last Status Change : 03/24/2014 15:03:48      
Last Mgmt Change   : 03/24/2014 15:14:00      
-------------------------------------------------------------------------------
Encap Group Specifics
-------------------------------------------------------------------------------
Encap Group Name   : _tmnx_SHAPER_GR000       Group Type        : ISID
Qos-per-member     : TRUE                     
Members            :
1                                                                       
-------------------------------------------------------------------------------
QOS
-------------------------------------------------------------------------------
E. qos-policy      : 1                        Q Frame-Based Acct: Disabled
E. Sched Policy    :                          E. Agg-limit      : -1
                                              Limit Unused BW   : Disabled
-------------------------------------------------------------------------------
Encap Group Member 1 Base Statistics
-------------------------------------------------------------------------------
Last Cleared Time     : N/A
 
Forwarding Engine Stats
                        Packets                 Octets
 
For. InProf           : 0                       0
For. OutProf          : 0                       0
Dro. InProf           : 0                       0
Dro. OutProf          : 0                       0
-------------------------------------------------------------------------------
Encap Group Member 1 Queue Statistics
-------------------------------------------------------------------------------
                        Packets                 Octets
 
Egress Queue 1
For. InProf           : 0                       0
For. OutProf          : 0                       0
Dro. InProf           : 0                       0
Dro. OutProf          : 0                       0
 

tunnels

Syntax 
tunnels local-ip ip-address remote-ip ip-address ue
tunnels [local-ip ip-address] [remote-ip ip-address] [isa-group wlan-gw-group-id] [member [1 to 255]] [summary] [detail]
Context 
show>router>wlan-gw
Description 

This command displays tunnel-QoS resource information.

Parameters 
ip-address
Specifies the remote address of the Mobile Gateway that is the source address in the tunnel header of received packets.
Values—

ipv4-address:

a.b.c.d

ipv6-address :

x:x:x:x:x:x:x:x (eight 16-bit pieces)

x:x:x:x:x:x:d.d.d.d

x - [0 to FFFF]H

d - [0 to 255]D

 

ip-address
Specifies the local address of this system that is the destination address in the tunnel header of received packets.
Values—

ipv4-address:

a.b.c.d

ipv6-address :

x:x:x:x:x:x:x:x (eight 16-bit pieces)

x:x:x:x:x:x:d.d.d.d

x - [0 to FFFF]H

d - [0 to 255]D

 

ue—
Displays information for the specified User Equipment.
wlan-gw-group-id
Specifies the identifier of the WLAN Gateway ISA group that terminates GRE for this group interface.
Values—
1 to 4

 

member —
Specifies the identifier of this WLAN Gateway ISA group member.
Values—
1 to 255

 

summary—
Displays a summary of the specified parameters.
detail—
Displays detailed information.
Output 

The following output is an example of WLAN-GW soft GRE tunnel information.

Sample Output
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnels
===============================================================================
Soft GRE tunnels
===============================================================================
Remote IP address           : 239.0.0.2
Local IP address            : 10.1.1.1
ISA group ID                : 1
ISA group member ID         : 5
Time established            : 2014/03/24 15:38:52
Number of UE                : 1
Access Point MAC            : 00:00:00:00:00:01
AP MAC learn failed         : false
 
Tunnel QoS
----------
Operational state           : active
Number of UE                : 1
Remaining hold time (s)     : N/A
 
-------------------------------------------------------------------------------
No. of tunnels: 1
 
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnels local-ip 10.1.1.1 
===============================================================================
Soft GRE tunnels
===============================================================================
Remote IP address           : 239.0.0.2
Local IP address            : 10.1.1.1
ISA group ID                : 1
ISA group member ID         : 5
Time established            : 2014/03/24 15:38:52
Number of UE                : 1
Access Point MAC            : 00:00:00:00:00:01
AP MAC learn failed         : false
 
Tunnel QoS
----------
Operational state           : active
Number of UE                : 1
Remaining hold time (s)     : N/A
-------------------------------------------------------------------------------
No. of tunnels: 1
 
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnels local-ip 10.1.1.1 remote-ip 239.0.0.2 
===============================================================================
Soft GRE tunnels
===============================================================================
Remote IP address           : 239.0.0.2
Local IP address            : 10.1.1.1
ISA group ID                : 1
ISA group member ID         : 5
Time established            : 2014/03/24 15:38:52
Number of UE                : 1
Access Point MAC            : 00:00:00:00:00:01
AP MAC learn failed         : false
 
Tunnel QoS
----------
Operational state           : active
Number of UE                : 1
Remaining hold time (s)     : N/A
-------------------------------------------------------------------------------
No. of tunnels: 1
 
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnels local-ip 10.1.1.1 remote-ip 239.0.0.2 ue 
===============================================================================
Tunnel User Equipments
===============================================================================
MAC address                 : 00:02:00:00:00:01
-------------------------------------------------------------------------------
VLAN Q-tag                  : 1
MPLS label                  : (Not Specified)
Tunnel router               : 50
Tunnel remote IP address    : 239.0.0.2
Tunnel local IP address     : 10.1.1.1
Retail service              : N/A
SSID                        : "1"
Previous Access Point IP    : (Not Specified)
IMSI                        : 206100000000001
MGW router                  : 300
Mobile Gateway              : 10.0.0.29
APN                         : full.dotted.apn.mnc010.mcc206.gprs
Last move time              : 2014/03/24 15:38:52
-------------------------------------------------------------------------------
No. of UE: 1
 
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnels local-ip 10.1.1.1 remote-ip 239.0.0.2 isa-group 1 
===============================================================================
Soft GRE tunnels
===============================================================================
Remote IP address           : 239.0.0.2
Local IP address            : 10.1.1.1
ISA group ID                : 1
ISA group member ID         : 5
Time established            : 2014/03/24 15:38:52
Number of UE                : 1
Access Point MAC            : 00:00:00:00:00:01
AP MAC learn failed         : false
 
Tunnel QoS
----------
Operational state           : active
Number of UE                : 1
Remaining hold time (s)     : N/A
-------------------------------------------------------------------------------
No. of tunnels: 1
 
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnels local-ip 10.1.1.1 remote-ip 239.0.0.2 isa-group 1 member 5 
===============================================================================
Soft GRE tunnels
===============================================================================
Remote IP address           : 239.0.0.2
Local IP address            : 10.1.1.1
ISA group ID                : 1
ISA group member ID         : 5
Time established            : 2014/03/24 15:38:52
Number of UE                : 1
Access Point MAC            : 00:00:00:00:00:01
AP MAC learn failed         : false
 
Tunnel QoS
----------
Operational state           : active
Number of UE                : 1
Remaining hold time (s)     : N/A
-------------------------------------------------------------------------------
No. of tunnels: 1
 
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnels local-ip 10.1.1.1 remote-ip 239.0.0.2 isa-group 1 member 5 summary 
===============================================================================
Soft GRE tunnels summary
===============================================================================
Remote IP address - Local IP address
-------------------------------------------------------------------------------
239.0.0.2 - 10.1.1.1
-------------------------------------------------------------------------------
No. of tunnels: 1
 
 
*A:Dut-C# show router 50 wlan-gw soft-gre-tunnels local-ip 10.1.1.1 remote-ip 239.0.0.2 isa-group 1 member 5 detail  
===============================================================================
Soft GRE tunnels
===============================================================================
Remote IP address           : 239.0.0.2
Local IP address            : 10.1.1.1
ISA group ID                : 1
ISA group member ID         : 5
Time established            : 2014/03/24 15:38:52
Number of UE                : 1
Access Point MAC            : 00:00:00:00:00:01
AP MAC learn failed         : false
 
Tunnel QoS
----------
Operational state           : active
Number of UE                : 1
Remaining hold time (s)     : N/A
Service Access Points(SAP)
===============================================================================
Service Id         : 2147483650               
SAP                : 5/1/lo-gre:1             Encap             : q-tag
Description        : Internal SAP
Admin State        : Up                       Oper State        : Up
Flags              : None
Multi Svc Site     : None                     
Last Status Change : 03/24/2014 15:03:48      
Last Mgmt Change   : 03/24/2014 15:14:00      
-------------------------------------------------------------------------------
Encap Group Specifics
-------------------------------------------------------------------------------
Encap Group Name   : _tmnx_SHAPER_GR000       Group Type        : ISID
Qos-per-member     : TRUE                     
Members            :
1
-------------------------------------------------------------------------------
QOS
-------------------------------------------------------------------------------
E. qos-policy      : 1                        Q Frame-Based Acct: Disabled
E. Sched Policy    :                          E. Agg-limit      : -1
                                              Limit Unused BW   : Disabled
-------------------------------------------------------------------------------
Encap Group Member 1 Base Statistics
-------------------------------------------------------------------------------
Last Cleared Time     : N/A
 
Forwarding Engine Stats
                        Packets                 Octets
For. InProf           : 0                       0
For. OutProf          : 0                       0
Dro. InProf           : 0                       0
Dro. OutProf          : 0                       0
-------------------------------------------------------------------------------
Encap Group Member 1 Queue Statistics
-------------------------------------------------------------------------------
Packets                 Octets
 
Egress Queue 1
For. InProf           : 0                       0
For. OutProf          : 0                       0
Dro. InProf           : 0                       0
Dro. OutProf          : 0                       0
===============================================================================
-------------------------------------------------------------------------------
No. of tunnels: 1
 

tunnels

Syntax 
tunnels [local-ipip-address] [remote-ip ip-address] [isa-group wlan-gw-group-id] [member [1 to 255]] [summary] [detail]
tunnels local-ip ip-address remote-ip ip-address ue
Context 
show>router>wlan-gw
Description 

This command displays tunnel operation information.

Parameters 
ip-address
Specifies the local IP address of this system that is the destination IP address in the tunnel header of received packets.
Values—

ip-address:

ipv4-address - a.b.c.d

ipv6-address :

x:x:x:x:x:x:x:x (eight 16-bit pieces)

x:x:x:x:x:x:d.d.d.d

x - [0 to FFFF]H

d - [0 to 255]D

 

ip-address
Specifies the remote IP address of the Mobile Gateway that is the source IP address in the tunnel header of received packets.
Values—

ip-address:

ipv4-address - a.b.c.d

ipv6-address :

x:x:x:x:x:x:x:x (eight 16-bit pieces)

x:x:x:x:x:x:d.d.d.d

x - [0 to FFFF]H

d - [0 to 255]D

 

wlan-gw-group-id
Specifies the identifier of the WLAN gateway ISA group that terminates GRE for this group interface.
Values—
1 to 4

 

member —
Specifies the identifier of this WLAN gateway ISA group member.
Values—
1 to 255

 

summary—
Displays a summary of the specified parameter.
detail—
Displays detailed information.
ue—
Displays information for the specified User Equipment.
Output 

The following output is an example of WLAN-GW tunnel information.

Sample Output
Note:

The remote/local IP addresses are locally generated for VLAN tunnels.

show router 50 wlan-gw tunnels
===============================================================================
Access Point tunnels
===============================================================================
Remote IP address           : fe80::3e8f:ffff:fe00:1901
Local IP address            : fe80::ff:fe02:202
ISA group ID                : 1
ISA group member ID         : 4
Time established            : 2015/01/07 17:42:01
Number of UE                : 1
Access Point MAC            : 00:00:00:00:00:05
AP MAC learn failed         : false
Encapsulation               : vlan
VLAN tag 1                  : 1000
VLAN tag 2                  : (None)
-------------------------------------------------------------------------------
No. of tunnels: 1
===============================================================================

radius-server-policy

Syntax 
radius-server-policy policy-name [acct-on-off]
radius-server-policy policy-name associations
radius-server-policy policy-name msg-buffer-stats
radius-server-policy policy-name statistics
radius-server-policy [acct-on-off]
Context 
show>aaa
Description 

This command displays RADIUS server policy information.

Parameters 
policy-name—
Displays information pertaining to the specified policy name.
associations—
Displays the association between the RADIUS server policy and the applications referencing the policy (RADIUS proxy, route downloader, authentication policy, accounting policy, dynamic services policy).
statistics—
Displays statistics of the RADIUS server policy and RADIUS servers referenced in the policy.
acct-on-off —
Displays the acct-on-off operational state for the RADIUS server policy.
msg-buffer-stats—
Displays statistics for the RADIUS message buffering.
Output 

The following is an example of RADIUS server policy information.

Sample Output
show aaa radius-server-policy "aaa-server-policy-1" 
===============================================================================
RADIUS server policy "aaa-server-policy-1"
===============================================================================
Description                 : Radius AAA server policy
Acct Request script policy  : (Not Specified)
Auth Request script policy  : (Not Specified)
Accept script policy        : script-policy-1
Acct-On-Off                 : Enabled (state Not Blocked)
-------------------------------------------------------------------------------
RADIUS server settings
-------------------------------------------------------------------------------
Router                      : "Base"
Source address              : (Not Specified)
Access algorithm            : direct
Retry                       : 3
Timeout (s)                 : 5
Hold down time (s)          : 30
Last management change      : 02/20/2013 13:32:05
===============================================================================
===============================================================================
Servers for "aaa-server-policy-1"
===============================================================================
Idx Name                             Address         Port        Oper State
                                                     Auth/Acct   
-------------------------------------------------------------------------------
1   server-1                         172.16.1.1      1812/1813   in-service
===============================================================================
 
 
# show aaa radius-server-policy acct-on-off 
==============================================================================
RADIUS server policies AcctOnOff state
==============================================================================
Name                                    OperState      LastStateChange
------------------------------------------------------------------------------
aaa-server-policy-1                     on             02/20/2013 21:23:57
aaa-server-policy-2                     NotApplicable  NotApplicable
aaa-server-policy-3                     sendAcctOn     NotApplicable
aaa-server-policy-4                     off            02/20/2013 21:40:57
------------------------------------------------------------------------------
No. of policies: 4
==============================================================================
 
# show aaa radius-server-policy "aaa-server-policy-1" acct-on-off 
===============================================================================
RADIUS server policy "aaa-server-policy-1" AcctOnOff info
===============================================================================
Oper state                  : on
Session Id                  : 242FFF0000000451253EED
Last state change           : 02/20/2013 21:23:57
Trigger                     : startUp
Server                      : "server-1"
===============================================================================
 
 
show aaa radius-server-policy "aaa-server-policy-3" msg-buffer-stats                                   
===============================================================================
RADIUS server policy "aaa-server-policy-3" message buffering stats
===============================================================================
buffering acct-interim      : enabled
  min interval (s)          : 60
  max interval (s)          : 3600
  lifetime (hrs)            : 12
buffering acct-stop         : enabled
  min interval (s)          : 60
  max interval (s)          : 3600
  lifetime (hrs)            : 12
 
Statistics
-------------------------------------------------------------------------------
Total acct-stop messages in buffer                        : 6
Total acct-interim messages in buffer                     : 10
Total acct-stop messages dropped (lifetime expired)       : 0
Total acct-interim messages dropped (lifetime expired)    : 0
Last buffer clear time                                    : N/A
Last buffer statistics clear time                         : N/A
-------------------------------------------------------------------------------
===============================================================================
 
 
show aaa radius-server-policy "aaa-server-policy-1" statistics 
===============================================================================
RADIUS server policy "aaa-server-policy-1" statistics
===============================================================================
Tx transaction requests                         : 383
Rx transaction responses                        : 383
Transaction requests timed out                  : 0
Transaction requests send failed                : 0
Packet retries                                  : 0
Transaction requests send rejected              : 0
Authentication requests failed                  : 0
Accounting requests failed                      : 0
Ratio of access-reject over auth responses      : 0%
Transaction success ratio                       : 100%
Transaction failure ratio                       : 0%
Statistics last reset at                        : n/a
 
Server 1 "server-1" address 172.16.1.1 auth-port 1812 acct-port 1813
-------------------------------------------------------------------------------
Tx request packets                              : 383
Rx response packets                             : 383
Request packets timed out                       : 0
Request packets send failed                     : 0
Request packets send failed (overload)          : 0
Request packets waiting for reply               : 0
Response packets with invalid authenticator     : 0
Response packets with invalid msg authenticator : 0
Authentication packets failed                   : 0
Accounting packets failed                       : 0
Avg auth response delay (10 100 1K 10K) in ms   :   27.1   22.8   22.8   22.8
Avg acct response delay (10 100 1K 10K) in ms   :   6.24   12.5   11.5   11.5
Statistics last reset at                        : n/a
 
===============================================================================
 
 
show aaa radius-server-policy "myRadiusServerPolicy1" associations
===============================================================================
RADIUS Proxy Associations
===============================================================================
Router RADIUS Proxy Server Purpose Username
-------------------------------------------------------------------------------
Base myProxyServerBase acc (default)
vprn10 myProxyServer1 acc (default)
-------------------------------------------------------------------------------
No. of associations: 2
 
 
show aaa radius-server-policy "aaa-server-policy-1" associations 
===============================================================================
RADIUS Proxy Associations
===============================================================================
Router RADIUS Proxy Server Purpose Username
-------------------------------------------------------------------------------
Base   myProxyServerBase   acc     (default)
-------------------------------------------------------------------------------
No. of associations: 1
===============================================================================
No route downloader entries found.
===============================================================================
Authentication Policy Associations
===============================================================================
Authentication Policy
-------------------------------------------------------------------------------
auth-policy-1
-------------------------------------------------------------------------------
No. of associations: 1
===============================================================================
===============================================================================
Accounting Policy Associations
===============================================================================
Accounting Policy
-------------------------------------------------------------------------------
acct-policy-1
acct-policy-2
-------------------------------------------------------------------------------
No. of associations: 2
===============================================================================
No dynamic-services policy entries found.

wlan-gw-group

Syntax 
wlan-gw-group wlan-gw-group-id
wlan-gw-group wlan-gw-group-id associations
wlan-gw-group wlan-gw-group-id member member-id
wlan-gw-group wlan-gw-group-id member member-id resource-statistics
wlan-gw-group wlan-gw-group-id member member-id statistics [type type] [non-zero-value-only]
wlan-gw-group
Context 
show>isa
Description 

This command displays WLAN-GW group information, including WLAN-GW tunnels.

Parameters 
wlan-gw-group-id—
Displays information about the specified WLAN-GW group ID.
Values—
1 to 4

 

associations—
Displays information about associations for the specified WLAN-GW group ID.
member member-id—
Displays information about the WLAN-GW-specific status and basic statistics information about the specified member.
Values—
1 to 255

 

type type
Displays a reduced output to only show statistics of the specified type.
Values—
packet-errors, host-errors, bd-errors, forwarding, reassembly, aa, radius, arp, dhcp, dhcp6, icmp, icmp6

 

non-zero-value-only —
Displays a reduced output to only show statistics whose value is bigger than zero.
resource-statistics—
Displays the resource usage on the specified group member.
statistics—
Displays statistics information about the members of the specified WLAN-GW group.
Output 

The following output is an example of ISA WLAN-GW group information.

Sample Output
*A:Dut-B>config>isa>wlan-gw-group$ show isa wlan-gw-group 4 
===============================================================================
WLAN Gateway group 4
===============================================================================
Administrative state        : in-service
Operational state           : in-service
Degraded                    : false
Active IOM limit            : 0
Active MDA limit            : 14
Port policy                 : (Not Specified)
Tunnel port policy          : (Not Specified)
Dsm ISA AA group            : (Not Specified)
Last Mgmt Change            : 06/28/2017 15:07:34
-------------------------------------------------------------------------------
NAT specific information for ISA group 4
-------------------------------------------------------------------------------
Reserved sessions           : 0
High Watermark (%)          : (Not Specified)
Low Watermark (%)           : (Not Specified)
Accounting policy           : (Not Specified)
UPnP mapping limit          : 524288
Suppress LsnSubBlksFree     : false
LSN support                 : enabled
Last Mgmt Change            : 06/28/2017 15:06:40
-------------------------------------------------------------------------------
===============================================================================
===============================================================================
ISA Group 4 members
===============================================================================
Group Member     State          Mda  Addresses  Blocks     Se-% Hi Se-Prio
-------------------------------------------------------------------------------
4     1          active         3/1  0          0          < 1  N  0
4     2          active         3/2  0          0          < 1  N  0
4     3          active         4/1  0          0          < 1  N  0
4     4          active         4/2  0          0          < 1  N  0
4     5          active         5/1  0          0          < 1  N  0
4     6          active         5/2  0          0          < 1  N  0
4     7          active         6/1  0          0          < 1  N  0
4     8          active         6/2  0          0          < 1  N  0
4     9          active         7/1  0          0          < 1  N  0
4     10         active         7/2  0          0          < 1  N  0
4     11         active         8/1  0          0          < 1  N  0
4     12         active         8/2  0          0          < 1  N  0
4     13         active         9/1  0          0          < 1  N  0
4     14         active         9/2  0          0          < 1  N  0
-------------------------------------------------------------------------------
No. of members: 14

isa-filter

Syntax 
isa-filter
isa-filter name
isa-filter name associations
isa-filter name ipv4
isa-filter name ipv6
Context 
show>subscr-mgmt
Description 

This command displays ISA filter information.

Parameters 
name—
Specifies the ISA filter name, up to 32 characters.
associations—
Displays associated information about the specified ISA filter name.
ipv4—
Display IPv4 ISA filter information for the specified ISA filter name.
ipv6—
Display IPv6 ISA filter information for the specified ISA filter name.

isa-policer

Syntax 
isa-policer policer-name
isa-policer policer-name associations
isa-policer
Context 
show>subscr-mgmt
Description 

This command displays ISA policer information.

Parameters 
policer-name—
Specifies the ISA policer name, up to 32 characters.
associations—
Displays associated information about the specified ISA policer name.

gtp-session

Syntax 
gtp-session imsi imsi apn apn-string | gtp-session [mgw-address ip-address] [mgw-router router-instance] [remote-control-teid teid] [local-control-teid teid] [detail]
gtp-session imsi imsi
gtp-statistics
Context 
show>subscr-mgmt>wlan-gw
Description 

This command displays GTP session information

Parameters 
imsi
Specifies the IMSI (International Mobile Subscriber Identity) of this UE.
apn-string
Specifies the APN (Access Point Name).
ip-address
Specifies the IP address of the Mobile Gateway, that is the source IP address in the tunnel header of received packets.
router-instance
Specifies the identifier of the virtual router instance where the GTP tunnel is terminated.
teid
Specifies the remote control plane Tunnel Endpoint Identifier (TEID).
teid
Specifies the local control plane TEID.
detail—
Displays detailed information.
Output 

The following is an example of subscriber management WLAN-GW GTP session information.

Sample Output
*A:Dut-C# show subscriber-mgmt wlan-gw gtp-session
===============================================================================
GTP sessions
===============================================================================
IMSI                        : 206100000000001
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : 300
Mobile Gateway address      : 10.20.1.2
Remote control TEID         : 66592
Local control TEID          : 4291821824
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
IMSI                        : 206100000000002
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : 300
Mobile Gateway address      : 10.20.1.2
Remote control TEID         : 66608
Local control TEID          : 4290773248
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
IMSI                        : 206100000000033
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : "Base"
Mobile Gateway address      : 10.20.1.2
Remote control TEID         : 66560
Local control TEID          : 4293918976
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
IMSI                        : 206100000000034
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : "Base"
Mobile Gateway address      : 10.20.1.2
Remote control TEID         : 66576
Local control TEID          : 4292870400
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
-------------------------------------------------------------------------------
No. of GTP sessions: 4
===============================================================================
*A:Dut-C#
 
*A:Dut-C# show subscriber-mgmt wlan-gw gtp-session imsi 206100000000001 apn full.dotted.apn.mnc010.mcc206.gprs
===============================================================================
GTP session
===============================================================================
IMSI                        : 206100000000001
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : 300
Mobile Gateway address      : 10.20.1.2
Remote control TEID         : 66592
Local control TEID          : 4291821824
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
Bearer 5
  rem TEID                  : 1073808421
  loc TEID                  : 4291821861
  uplink GBR (kbps)         : 0
  uplink MBR (kbps)         : 4992
  downlink GBR (kbps)       : 0
  downlink MBR (kbps)       : 1984
  QoS Class ID              : 8
  alloc/ret priority        : 1
===============================================================================
*A:Dut-C#
 
*A:Dut-C# show subscriber-mgmt wlan-gw gtp-session imsi 206100000000001
===============================================================================
GTP sessions
===============================================================================
IMSI                        : 206100000000001
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : 300
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66592
Local control TEID          : 4291821824
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
Bearer 5
  rem TEID                  : 1073808421
  loc TEID                  : 4291821861
  uplink GBR (kbps)         : 0
  uplink MBR (kbps)         : 4992
  downlink GBR (kbps)       : 0
  downlink MBR (kbps)       : 1984
  QoS Class ID              : 8
  alloc/ret priority        : 1
-------------------------------------------------------------------------------
No. of GTP sessions: 1
===============================================================================
*A:Dut-C#
 
*A:Dut-C# show subscriber-mgmt wlan-gw gtp-session mgw-address 10.20.12
===============================================================================
GTP sessions
===============================================================================
IMSI                        : 206100000000001
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : 300
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66592
Local control TEID          : 4291821824
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
IMSI                        : 206100000000002
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : 300
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66608
Local control TEID          : 4290773248
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
IMSI                        : 206100000000033
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : "Base"
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66560
Local control TEID          : 4293918976
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
IMSI                        : 206100000000034
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : "Base"
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66576
Local control TEID          : 4292870400
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
-------------------------------------------------------------------------------
No. of GTP sessions: 4
===============================================================================
*A:Dut-C#
 
*A:Dut-C# show subscriber-mgmt wlan-gw gtp-session mgw-address 10.20.12 mgw-router "Base"
===============================================================================
GTP sessions
===============================================================================
IMSI                        : 206100000000033
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : "Base"
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66560
Local control TEID          : 4293918976
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
IMSI                        : 206100000000034
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : "Base"
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66576
Local control TEID          : 4292870400
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
-------------------------------------------------------------------------------
No. of GTP sessions: 2
===============================================================================
*A:Dut-C#
 
*A:Dut-C# show subscriber-mgmt wlan-gw gtp-session mgw-router 300
===============================================================================
GTP sessions
===============================================================================
IMSI                        : 206100000000001
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : 300
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66592
Local control TEID          : 4291821824
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
IMSI                        : 206100000000002
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : 300
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66608
Local control TEID          : 4290773248
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
-------------------------------------------------------------------------------
No. of GTP sessions: 2
===============================================================================
*A:Dut-C#
 
*A:Dut-C# show subscriber-mgmt wlan-gw gtp-session remote-control-teid 66560
===============================================================================
GTP sessions
===============================================================================
IMSI                        : 206100000000033
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : "Base"
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66560
Local control TEID          : 4293918976
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
-------------------------------------------------------------------------------
No. of GTP sessions: 1
===============================================================================
*A:Dut-C# show subscriber-mgmt wlan-gw gtp-session local-control-teid 4292870400
===============================================================================
GTP sessions
===============================================================================
IMSI                        : 206100000000034
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : "Base"
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66576
Local control TEID          : 4292870400
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
-------------------------------------------------------------------------------
No. of GTP sessions: 1
===============================================================================
*A:Dut-C#
 
*A:Dut-C# show subscriber-mgmt wlan-gw gtp-session mgw-address 10.20.12 mgw-router "Base" local-control-teid 4292870400 remote-control-teid 66576
===============================================================================
GTP sessions
===============================================================================
IMSI                        : 206100000000034
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : "Base"
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66576
Local control TEID          : 4292870400
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
-------------------------------------------------------------------------------
No. of GTP sessions: 1
===============================================================================
 
*A:Dut-C# show subscriber-mgmt wlan-gw gtp-session mgw-address 10.20.12 mgw-router "Base" local-control-teid 4292870400 remote-control-teid 66576 detail
===============================================================================
GTP sessions
===============================================================================
IMSI                        : 206100000000034
APN                         : full.dotted.apn.mnc010.mcc206.gprs
-------------------------------------------------------------------------------
Mobile Gateway router       : "Base"
Mobile Gateway address      : 10.20.12
Remote control TEID         : 66576
Local control TEID          : 4292870400
Charging characteristics    : (None)
Uplink AMBR (kbps)          : (None)
Downlink AMBR (kbps)        : (None)
Bearer 5
  rem TEID                  : 1073808405
  loc TEID                  : 4292870437
  uplink GBR (kbps)         : 0
  uplink MBR (kbps)         : 4992
  downlink GBR (kbps)       : 0
  downlink MBR (kbps)       : 1984
  QoS Class ID              : 8
  alloc/ret priority        : 1
-------------------------------------------------------------------------------
No. of GTP sessions: 1
===============================================================================
*A:Dut-C#

gtp-statistics

Syntax 
gtp-statistics
Context 
show>subscr-mgmt>wlan-gw
Description 

This command displays GTP statistics.

Output 

The following is an example of WLAN-GW GTP statistics.

Sample Output
*A:Dut-C# show subscriber-mgmt wlan-gw gtp-statistics
===============================================================================
GTP statistics
===============================================================================
tx echo requests                                        : 33
tx echo responses                                       : 0
tx errors                                               : 0
rx echo requests                                        : 0
rx echo responses                                       : 33
rx errors                                               : 0
rx version not supported                                : 0
rx zero TEID responses                                  : 0
path faults                                             : 0
path restarts                                           : 0
tx invalid msgs                                         : 0
tx create PDP context requests                          : 4
tx create PDP context responses                         : 0
tx delete PDP context requests                          : 0
tx delete PDP context responses                         : 0
tx create session requests                              : 0
tx create session responses                             : 0
tx delete session requests                              : 0
tx delete session responses                             : 0
tx delete bearer requests                               : 0
tx delete bearer responses                              : 0
tx create bearer responses                              : 0
tx update bearer responses                              : 0
tx modify bearer requests                               : 0
tx modify bearer responses                              : 0
tx error indication count                               : 0
rx invalid msgs                                         : 0
rx create PDP context requests                          : 0
rx create PDP context responses                         : 4
rx delete PDP context requests                          : 0
rx delete PDP context responses                         : 0
rx create session requests                              : 0
rx create session responses                             : 0
rx delete session requests                              : 0
rx delete session responses                             : 0
rx delete bearer requests                               : 0
rx delete bearer responses                              : 0
rx create bearer requests                               : 0
rx update bearer requests                               : 0
rx modify bearer requests                               : 0
rx modify bearer responses                              : 0
rx error indication count                               : 0
rx invalid pkt length                                   : 0
rx unknown pkts                                         : 0
rx missing IE pkts                                      : 0
rx bad IP header pkts                                   : 0
rx bad UDP header pkts                                  : 0
rx discarded pkts                                       : 0
rx in-session discarded pkts                            : 0
rx pkts                                                 : 37
tx discarded pkts                                       : 0
tx pkts                                                 : 37
===============================================================================
*A:Dut-C#

ssid

Syntax 
ssid
Context 
show>subscr-mgmt>wlan-gw
Description 

This command displays SSID information.

statistics

Syntax 
statistics
Context 
show>subscr-mgmt>wlan-gw
Description 

This command displays statistics information.

tunnels

Syntax 
tunnels [router router-name] [remote-ip ip-address] [local-ip ip-address] [encapsulation encap [encap] [qtag1 qtag] [qtag2 qtag] [ap-sap sap-id] [min-num-ue minimum] [max-num-ue maximum] [ap-mac-learn-failed {true | false}] [get-num-results] [addr-family family] [ue-type ue-type [ue-type]]
Context 
show>subscr-mgmt>wlan-gw
Description 

This command displays all the WLAN-GW tunnels matching the specified criteria. Unlike the similar command in the show>router>vprn context, this command also includes information on tunnels containing ISA-only UEs such as migrant, DSM and l2-wholesale.

Parameters 
router-name —
Specifies the name or ID of the router where the tunnel terminates.
ip-address —
Specifies the IPv4 or IPv6 address indicating one, or both, of the tunnel endpoint IP addresses.
encap —
Specifies up to three tunnel encapsulation types, for example GRE, L2TP, or VLAN.
qtag —
Specifies the Q-tags specifying the l2-ap-delimiting tags.
sap-id —
Specifies the SAP-ID of the l2-ap SAP.
minimum—
Specifies the minimum number of UEs on the tunnel, after applying the UE type filter.
maximum—
Specifies the maximum number of UEs on the tunnel, after applying the UE type filter.
ap-mac-learn-failed true | false —
Filters the results to display only tunnels that have learned the AP-MAC (false) or have not learned the AP-MAC (true).
get-num-results—
Displays the total number of tunnels at the end of each tunnel record.
family—
Specifies the tunnel’s IP family type (IPv4 or IPv6).
ue-type—
Filters up to five display based on the presence of specified UE types and is used in conjunction with min-num-ue and max-num-ue.
Values—
migrant, dsm, l2w, esm, or xcon

 

Output 

The following is an example of WLAN-GW tunnels.

Sample Output
Node# show subscriber-mgmt wlan-gw tunnels
===============================================================================
Access Point tunnels
===============================================================================
Router                      : 50
Encapsulation               : gre
Remote IP address           : 192.0.2.1
Local IP address            : 192.0.2.2
-------------------------------------------------------------------------------
First move time             : N/A
ISA group ID                : 1
ISA member ID               : 3
Interface                   : grp-vprn_ue-2/1/2:50
Interface Service ID        : 4
AP MAC address              : 00:53:00:00:00:05
AP MAC learn failed         : false
AP SAP                      : (Unknown)
Remote UDP port             : N/A
Tag 1                       : N/A
Tag 2                       : N/A
No. of UE                   : 1
No. of migrant UE           : 0
No. of DSM UE               : 1
No. of layer-2 wholesale UE : 0
No. of cross-connect UE     : 0
No. of ESM UE               : 0
-------------------------------------------------------------------------------
No. of Access point tunnels: 1
===============================================================================

query-results

Syntax 
query-results id query-id
query-results name query-name
Context 
show>subscr-mgmt>wlan-gw>tunnels
Description 

This command shows the results of a query configured under subscr-mgmt>wlan-gw>ue-query.

Parameters 
query-id—
Identifies the query by numeric ID.
Values—
1 to 1024

 

query-name—
Identifies the query name, up to 32 characters.
Output 

The following output is an example of the results of a tunnel query.

Sample Output
WLAN-GW> show subscriber-mgmt wlan-gw tunnels query-results name "min_3_dsm_ue"
===============================================================================
WLAN-GW tunnels
===============================================================================
Router                      : 10
Encapsulation               : gre
Remote IP address           : 10.0.0.2
Local IP address            : 10.0.0.10
ISA group ID                : 1
ISA member ID               : 1
Interface                   : grp-itf
Interface Service ID        : 5
First move time             : N/A
AP MAC address              : (Unknown)
AP MAC learn failed         : true
No. of UE                   : 3
No. of migrant UE           : 0
No. of DSM UE               : 3
No. of layer-2 wholesale UE : 0
No. of cross-connect UE     : 0
No. of ESM UE               : 0
-------------------------------------------------------------------------------
Router                      : 10
Encapsulation               : gre
Remote IP address           : 10.0.0.4
Local IP address            : 10.0.0.10
ISA group ID                : 1
ISA member ID               : 1
Interface                   : grp-itf
Interface Service ID        : 5
First move time             : N/A
AP MAC address              : (Unknown)
AP MAC learn failed         : true
No. of UE                   : 4
No. of migrant UE           : 0
No. of DSM UE               : 4
No. of layer-2 wholesale UE : 0
No. of cross-connect UE     : 0
No. of ESM UE               : 0
-------------------------------------------------------------------------------
No. of WLAN-GW tunnels: 2
===============================================================================

ue

Syntax 
ue [vlan qtag] [mpls-label label] [retail-svc-id service-id] [ssid service-set-id] [previous-access-point ip-address] [bd bridge-id]
ue mac ieee-address [bd bridge-id]
Context 
show>subscr-mgmt>wlan-gw
Description 

This command displays User Equipment (UE) information.

Parameters 
qtag
Displays information about the VLAN Q-tag present in the traffic received from this UE.
Values—
1 to 4095

 

label
Displays information about the MPLS label present in the traffic received from this UE.
service-id—
Specifies an existing service ID. If no svc-id is specified then it indicates that the interface is a network interface in the Base router instance.
Values—
{id | svc-name}

id:

1 to 2147483647

svc-name:

Specifies an existing service name, up to 64 characters (svc-name is an alias for input only. The svc-name gets replaced with an id automatically by SR OS in the configuration)

 

service-set-id
Displays information about the Service Set ID (SSID) of this UE.
ip-address
Displays information about the IP address of the previous Access Point (AP) of this UE.
bridge-id—
Displays specified HLE bridge domain information of this UE.
Values—
1 to 4294967295

 

ieee-address
Displays information about the MAC address of this UE.
Values—
xx:xx:xx:xx:xx:xx or xx-xx-xx-xx-xx-xx

 

Output 

The following displays WLAN-GW information.

Sample Output
System# show subscriber-mgmt wlan-gw ue
======================================================================
User Equipments
======================================================================
MAC address                 : 00:02:00:00:00:39
----------------------------------------------------------------------
VLAN Q-tag                  : 1
MPLS label                  : (Not Specified)
Tunnel router               : 50
Tunnel remote IP address    : 20C9::7:1:2
Tunnel local IP address     : 2032::1:1:7
Retail service              : N/A
SSID                        : 1
Previous Access Point IP    : (Not Specified)
IMSI                        : (Not Specified)
Last move time              : 2013/07/02 07:45:31
 
----------------------------------------------------------------------
No. of UE: 1
======================================================================
System#

query-results

Syntax 
query-results id query-id
query-results name query-name
Context 
show>subscr-mgmt>wlan-gw>ue
Description 

This command shows the results of a query configured under subscr-mgmt>wlan-gw>ue-query.

Parameters 
query-id—
Identifies the query by numeric ID.
Values—
1 to 1024

 

query-name—
Identifies the query name, up to 32 characters.
Output 

The following output is an example of the results of a UE query.

Sample Output
WLAN-GW>show subscriber-mgmt wlan-gw ue query-results name "by_mac"
===============================================================================
WLAN-GW UE
===============================================================================
Tunnel Router               : 10
Encapsulation               : gre
Tunnel Remote IP address    : 10.0.0.2
Tunnel Local IP address     : 10.0.0.10
MAC address                 : 00:00:5e:00:53:11
IP address                  : 10.16.0.3
State                       : distributed-sub-mgmt
ISA group ID                : 1
ISA member ID               : 1
Last move time              : N/A
AP MAC address              : (Unknown)
Service Set ID (SSID)       : (Not Specified)
MPLS label                  : (Not Specified)
Expiry time                 : 2019/01/21 14:37:56
Idle timeout (s)            : (Not Specified)
Session expiry time         : 2019/01/21 14:37:56
NAT policy                  : dsm_nat
HTTP redirect policy        : (Not Specified)
DSM IP filter               : (Not Specified)
Accounting policy           : dsm_aaa
Accounting update period (s): 300
Accounting update time      : 2019/01/21 14:07:56
Ingress PIR (kilobps)       : max
Ingress CIR (kilobps)       : max
Egress PIR (kilobps)        : max
Egress CIR (kilobps)        : max
Application profile         : (Not Specified)
IP address family           : ipv4-only
SLAAC prefix                : ::
SLAAC address 1             : ::
SLAAC address 2             : ::
SLAAC address 3             : ::
SLAAC expiry time           : N/A
DHCP addres deprecated      : no
DHCPv6 address              : ::
DHCPv6 addres deprecated    : no
Identity Association ID     : (Not Specified)
Identity Association ID val*: no
DHCPv6 lease expiry time    : N/A
Bridge ID                   : (Not Specified)
Received packets            : 4
Received bytes              : 440
Transmitted packets         : 5
Transmitted bytes           : 788
Result number               : 1/1
-------------------------------------------------------------------------------
No. of WLAN-GW UE: 1
===============================================================================
* indicates that the corresponding row element may have been truncated.

12.25.2.8.2. Debug Commands

call-trace

Syntax 
call-trace
Context 
debug
Description 

This command enables the context to set up various call-trace debug sessions.

wlan-gw

Syntax 
[no] wlan-gw
Context 
debug
Description 

This node contains all the parameters to set up specific call-trace debug sessions for WLAN-GW. The no form of this command will stop all configured WLAN-GW traces.

statistic

Syntax 
statistic type type name name
no statistic
Context 
debug>wlan-gw>group
Description 

This command enables debugging of the specified statistic. The first packet that causes an increase of the specified statistic is shown in debug output. After the first packet, debugging of the counter is stopped.

Parameters 
type—
Displays the type of statistic to be debugged; for example, DHCP or RADIUS.
Values—
packet-errors, host-errors, bd-errors, forwarding, reassembly, aa, radius, arp, dhcp, dhcp6, icmp, icmp6

 

name
Specifies the name, up to 256 characters, of the statistic within that group. For a complete list, see the command show isa wlan-gw-group wlan-gw-group-id member member-id statistics.

ue

Syntax 
ue ieee-address [profile trace-profile-name]
no ue ieee-address
Context 
debug>call-trace>wlan-gw
Description 

This command starts tracing the UE with the specified MAC address. The trace is started with default parameters or optionally parameters specified in the trace-profile.The no form of this command stops the trace and make sure no new traces are started.

Parameters 
ieee-address—
Displays information about the MAC address of this UE.
trace-profile-name
Specifies the name of a configured trace profile.

12.25.2.8.3. Tools Commands

acct-on

Syntax 
acct-on [radius-server-policy policy-name] [force]
Context 
tools>perform>aaa
Description 

This command triggers a RADIUS Accounting-On message:

  1. for all radius-server-policies that have acct-on-off configured.
  2. for the specified radius-server-policy if the acct-on-off is configured

The Accounting-On message is not sent when the last successful event for the RADIUS server policy was an Accounting-On message. In this case, an Accounting-Off should be sent first. By specifying the keyword force, this is overruled.

Parameters 
policy-name
Specifies the radius-server-policy for which the Accounting-On should be sent.
force—
Sends an Accounting-On also if the last successful event was an Accounting-On.

acct-off

Syntax 
acct-off [radius-server-policy policy-name] [force] [acct-terminate-cause number]
Context 
tools>perform>aaa
Description 

This command triggers a RADIUS Accounting-Off message:

  1. for all radius-server-policies that have acct-on-off configured
  2. for the specified radius-server-policy if the acct-on-off is configured

The Accounting-Off message is not sent when the last successful event for the radius server policy was an Accounting-Off message. In this case, an Accounting-On should be sent first. By specifying the keyword force, this is overruled.

Parameters 
policy-name
Specifies the radius-server-policy for which the Accounting-Off should be sent.
force—
Sends an Accounting-On also if the last successful event was an Accounting-Off.
number
Overrides the default Acct-Terminate-Cause (User-Request) in the Accounting-Off message.

radius-acct-terminate-cause

Syntax 
radius-acct-terminate-cause
Context 
tools>dump>aaa
Description 

This command shows all available termination causes and their respective number values. The TermCause is equivalent to VSA 226 Alc-Error-Code numeric values. The description is equivalent to VSA 227Alc-Error-Message string.

radius-server-policy

Syntax 
radius-server-policy policy-name msg-buffer [session-id acct-session-id]
Context 
tools>perform>aaa
tools>dump>aaa
Description 

This command dumps the RADIUS message buffer content for the specified radius-server-policy:

  1. message-type (acct-interim or acct-stop)
  2. Acct-Session-Id
  3. Remaining lifetime

When specifying the session-id, the message details are displayed.

Parameters 
policy-name
Specifies the radius-server-policy for which the message buffer content should be displayed.
acct-session-id
Displays the RADIUS message details for the message with specified session-id that is stored in the RADIUS message buffer.

performance

Syntax 
performance mda mda-id last time-span time-unit
Context 
tools>dump>wlan-gw>isa
Description 

This command generates an overview of the processing load and data processed by the specified ISA over a period of time. The following time periods are supported:

  1. last minute with seconds granularity
  2. last hour with minutes granularity
  3. last day with hours granularity
  4. last day with days granularity
Parameters 
mda-id
Specifies the MDA for getting performance measurements in slot/mda format.
Values—
slot — 1 to 10
mda — 1 to 2

 

time-span
Specifies the period for which to get measurements.
Values—
1 to 60 (sec), 1 to 60 (min), 1 to 24 (hrs), 1 (days)

 

time-unit
Specifies the period for which to get measurements.
Values—
sec, min, hrs, days

 

Output 

This command displays performance information.

Sample Output
Node# /tools dump wlan-gw isa performance mda 2/1 last 5 min
===============================================================================
Measurements for last 5 minutes on Slot #2 MDA #1
===============================================================================
Timestamp            |     Wait     Idle     Work | Total jobs |    Total data
---------------------+----------------------------+------------+---------------
01/22/2018 10:14:04  |   99.47%    0.53%    0.00% |          0 |          - -
01/22/2018 10:13:41  |   99.46%    0.54%    0.00% |          3 |          3 Kb
01/22/2018 10:12:41  |   99.47%    0.53%    0.00% |          0 |          - -
01/22/2018 10:11:41  |   99.47%    0.53%    0.00% |          0 |          - -
01/22/2018 10:10:41  |   99.45%    0.55%    0.00% |          0 |          - -
===============================================================================

ue

Syntax 
ue [wlan-gw-group wlan-gw-group-id] [mda mda-id] [next-index index] [summary] [detail] [bd bridge-id] [ue-mac ieee-address] [ue-vlan vlan] [state-description state] [tunnel-router router-instance] [tunnel-source-ip ip-address] [tunnel-destination-ip ip-address] [tunnel-type tunnel-type] [ue-ip ipv4-address] [dhcp6-addr ipv6-address] [slaac-prefix ipv6-address] [aggregate-summary]
Context 
tools>dump>wlan-gw
Description 

This command dumps User Equipment (UE) information.

The summary option displays a count of UEs per ISA and the aggregate-summary displays a count of matched UEs over the whole WLAN-GW.

Output 

This command displays UE information.

Sample Output
tools dump wlan-gw ue
===============================================================================
Matched 1 session on Slot #4 MDA #1
===============================================================================
UE-Mac          : 00:02:00:00:00:11     UE-vlan         : 3600
UE IP Addr      : N/A                   UE timeout      : N/A
UE IP6 Addr     : N/A
Description     : L2-user
Auth/CoA-time   : 01/07/2015 18:56:01
Tunnel MDA      : 5/1                   Tunnel Router   : 50
MPLS label      : N/A                   Shaper          : Default
Tunnel Src IP   : 203.0.113.235         Tunnel Dst IP   : 10.1.1.1
Tunnel Type     : GRE
Anchor SAP      : 4/1/nat-out-ip:2049.6
AP-Mac          : Unknown               AP-RSSI         : Unknown
AP-SSID         : Unknown
Last-forward    : 01/07/2015 18:56:01   Last-move       : None
Session Timeout : None                  Idle Timeout    : 300 sec
Acct Update     : None                  Acct Interval   : N/A
Acct Session-Id : N/A
Acct Policy     : N/A
NAT Policy      : N/A
Redirect Policy : N/A
IP Filter       : N/A
App-profile     : N/A
Rx Oper PIR     : N/A                   Rx Oper CIR     : N/A
Tx Oper PIR     : N/A                   Tx Oper CIR     : N/A
Rx Frames       : 0                     Rx Octets       : 0
Tx Frames       : 0                     Tx Octets       : 0
-------------------------------------------------------------------------------
===============================================================================
No sessions on Slot #4 MDA #2 match the query
No sessions on Slot #5 MDA #1 match the query
No sessions on Slot #5 MDA #2 match the query
 

12.25.2.8.4. Clear Commands

radius-server-policy

Syntax 
radius-server-policy policy-name msg-buffer [acct-session-id acct-session-id]
radius-server-policy policy-name statistics [msg-buffer-only]
radius-server-policy policy-name server server-index statistics
Context 
clear>aaa
Description 

This command dumps the RADIUS message buffer content for the specified radius-server-policy:

  1. message-type (acct-interim or acct-stop)
  2. Acct-Session-Id
  3. Remaining lifetime

When specifying the session-id, the message details are displayed.

Parameters 
policy-name
Specifies the radius-server-policy for which the information should be cleared.
acct-session-id
Deletes all RADIUS messages or the RADIUS message with specified session-id from the RADIUS message buffer.
msg-buffer-only—
Clears all statistics for the specified radius-server-policy: radius-server-policy statistics, RADIUS server statistics and RADIUS message buffer statistics. With the optional keyword msg-buffer-only, only the RADIUS message buffer statistics are cleared.
server-index
Clears the RADIUS server statistics for the specified server-index in the specified radius-server-policy.

isa-subnets

Syntax 
isa-subnets all
isa-subnets interface ip-int-name
isa-subnets prefix ipv6-address/prefix-length
Context 
clear>router>wlan-gw
Description 

This command clears specific subnets from the pool-manager. Associated UE’s is removed from the system.

When clearing the last subnet on an ISA the pool-manager will automatically allocate a new subnet with allocation-level 0%.

Parameters 
all—
Clears all the isa-subnets.
ip-int-name
Clears all the isa-subnets of a specific subscriber-interface.
ipv6-address/prefix-length—
Clears a specific IPv6 address and prefix length.

wlan-gw-group

Syntax 
wlan-gw-group group-id member member-id resource-peak-values
wlan-gw-group group-id member member-id statistics
Context 
clear>wlan-gw>isa
Description 

This command resets wlan-gw statistics per group member.

Parameters 
group-id—
Specifies the WLAN-GW group ID.
Values—
1 to 4

 

member member-id—
Specifies the member ID.
Values—
1 to 255

 

statistics—
Resets the statistics measurements to zero.
resource-peak-values—
Resets the resource peak values to the current resource measurements.