Enter the filter context
16.0.R1
All
Enter the dhcp-filter list instance
configure filter dhcp-filter number
16.0.R1
All
Unique DHCP filter policy ID
configure filter dhcp-filter number
1 to 65535
This element is part of a list key.
16.0.R1
All
Enable the default-action context
configure filter dhcp-filter number default-action
16.0.R1
All
Host creation options to bypass
The following are part of a mandatory choice: bypass-host-creation or drop.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
DHCP host creation when the filter entry is matched
configure filter dhcp-filter number default-action drop
The following are part of a mandatory choice: bypass-host-creation or drop.
16.0.R1
All
Text description
configure filter dhcp-filter number description string
1 to 80
16.0.R1
All
Enter the entry list instance
configure filter dhcp-filter number entry number
10
16.0.R1
All
DHCP filter entry index
configure filter dhcp-filter number entry number
1 to 65535
This element is part of a list key.
16.0.R1
All
Enable the action context
configure filter dhcp-filter number entry number action
16.0.R1
All
Host creation options to bypass
configure filter dhcp-filter number entry number action bypass-host-creation
The following are part of a mandatory choice: bypass-host-creation or drop.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
DHCP host creation when the filter entry is matched
The following are part of a mandatory choice: bypass-host-creation or drop.
16.0.R1
All
Enable the option context
configure filter dhcp-filter number entry number option
16.0.R1
All
Require the absence of related option
The following are part of a mandatory choice: absent, match, or present.
16.0.R1
All
Enable the match context
The following are part of a mandatory choice: absent, match, or present.
16.0.R1
All
Use an exact match pattern (not partial)
false
16.0.R1
All
Matching pattern for the filtered option
1 to 256
The following are part of a mandatory choice: hex or string.
16.0.R1
All
Invert (partial) matching criteria
false
16.0.R1
All
Matching pattern for the filtered option
1 to 127
The following are part of a mandatory choice: hex or string.
16.0.R1
All
Number for DHCP or DHCPv6 option to filter on
0 to 255
This element is mandatory.
16.0.R1
All
Require the presence of related option
The following are part of a mandatory choice: absent, match, or present.
16.0.R1
All
Enter the dhcp6-filter list instance
configure filter dhcp6-filter number
16.0.R1
All
Unique DHCP filter policy ID
configure filter dhcp6-filter number
1 to 65535
This element is part of a list key.
16.0.R1
All
Enable the default-action context
16.0.R1
All
Enable the bypass-host-creation context
The following are part of a mandatory choice: bypass-host-creation or drop.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
Bypass the DHCPv6 NA host creation
configure filter dhcp6-filter number default-action bypass-host-creation na boolean
true
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
Bypass the DHCPv6 PD host creation
configure filter dhcp6-filter number default-action bypass-host-creation pd boolean
true
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
Drop DHCPv6 message (do not process)
The following are part of a mandatory choice: bypass-host-creation or drop.
16.0.R1
All
Text description
configure filter dhcp6-filter number description string
1 to 80
16.0.R1
All
Enter the entry list instance
configure filter dhcp6-filter number entry number
10
16.0.R1
All
DHCP filter entry index
configure filter dhcp6-filter number entry number
1 to 65535
This element is part of a list key.
16.0.R1
All
Enable the action context
configure filter dhcp6-filter number entry number action
16.0.R1
All
Enable the bypass-host-creation context
configure filter dhcp6-filter number entry number action bypass-host-creation
The following are part of a mandatory choice: bypass-host-creation or drop.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
Bypass the DHCPv6 NA host creation
configure filter dhcp6-filter number entry number action bypass-host-creation na boolean
true
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
Bypass the DHCPv6 PD host creation
configure filter dhcp6-filter number entry number action bypass-host-creation pd boolean
true
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
Drop DHCPv6 message (do not process)
The following are part of a mandatory choice: bypass-host-creation or drop.
16.0.R1
All
Enable the option context
configure filter dhcp6-filter number entry number option
16.0.R1
All
Require the absence of related option
The following are part of a mandatory choice: absent, match, or present.
16.0.R1
All
Enable the match context
The following are part of a mandatory choice: absent, match, or present.
16.0.R1
All
Use an exact match pattern (not partial)
false
16.0.R1
All
Matching pattern for the filtered option
1 to 256
The following are part of a mandatory choice: hex or string.
16.0.R1
All
Invert (partial) matching criteria
false
16.0.R1
All
Matching pattern for the filtered option
1 to 127
The following are part of a mandatory choice: hex or string.
16.0.R1
All
Number for DHCP or DHCPv6 option to filter on
0 to 255
This element is mandatory.
16.0.R1
All
Require the presence of related option
The following are part of a mandatory choice: absent, match, or present.
16.0.R1
All
Enter the gre-tunnel-template list instance
configure filter gre-tunnel-template string
1023
16.0.R1
All
GRE tunnel template identifier
configure filter gre-tunnel-template string
1 to 32
This element is part of a list key.
16.0.R1
All
Text description
configure filter gre-tunnel-template string description string
1 to 80
16.0.R2
All
Enter the ipv4 context
configure filter gre-tunnel-template string ipv4
16.0.R1
All
Add a list entry for destination-address
configure filter gre-tunnel-template string ipv4 destination-address string
32
16.0.R1
All
Destination IP address
configure filter gre-tunnel-template string ipv4 destination-address string
This element is part of a list key.
16.0.R1
All
GRE key
configure filter gre-tunnel-template string ipv4 gre-key (keyword | number)
if-index
16.0.R1
All
Decrement TTL
configure filter gre-tunnel-template string ipv4 skip-ttl-decrement boolean
false
16.0.R1
All
Source IP address of the GRE encapsulated
configure filter gre-tunnel-template string ipv4 source-address string
16.0.R1
All
Enter the ip-exception list instance
configure filter ip-exception string
20.10.R1
VSR
Filter name
configure filter ip-exception string
1 to 64
This element is part of a list key.
20.10.R1
VSR
Text description
configure filter ip-exception string description string
1 to 80
20.10.R1
VSR
Enter the entry list instance
configure filter ip-exception string entry number
20.10.R1
VSR
ID for a match criteria and the corresponding action
configure filter ip-exception string entry number
1 to 2097151
This element is part of a list key.
20.10.R1
VSR
Text description
configure filter ip-exception string entry number description string
1 to 80
20.10.R1
VSR
Enter the match context
configure filter ip-exception string entry number match
20.10.R1
VSR
Enter the dst-ip context
20.10.R1
VSR
Specifies IP address to match.
20.10.R1
VSR
Specifies the mask that is applied as an AND to the IP address.
20.10.R1
VSR
Enter the dst-port context
20.10.R1
VSR
Condition on equality to specified value.
0 to 65535
The following are part of a choice: eq, gt, lt, or range.
20.10.R1
VSR
Condition on being greater than the specified value.
0 to 65534
The following are part of a choice: eq, gt, lt, or range.
20.10.R1
VSR
Condition on being less than the specified value.
1 to 65535
The following are part of a choice: eq, gt, lt, or range.
20.10.R1
VSR
Enable the range context
The following are part of a choice: eq, gt, lt, or range.
20.10.R1
VSR
Specifies upper bound port to match.
1 to 65535
This element is mandatory.
20.10.R1
VSR
Specifies lower bound port to match.
0 to 65534
This element is mandatory.
20.10.R1
VSR
Enter the icmp context
20.10.R1
VSR
ICMP code value to match
0 to 255
20.10.R1
VSR
ICMP type value to match
0 to 255
20.10.R1
VSR
IP protocol to match.
0 to 255
tcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp
20.10.R1
VSR
Enter the src-ip context
20.10.R1
VSR
Specifies IP address to match.
20.10.R1
VSR
Specifies the mask that is applied as an AND to the IP address.
20.10.R1
VSR
Enter the src-port context
20.10.R1
VSR
Condition on equality to specified value.
0 to 65535
The following are part of a choice: eq, gt, lt, or range.
20.10.R1
VSR
Condition on being greater than the specified value.
0 to 65534
The following are part of a choice: eq, gt, lt, or range.
20.10.R1
VSR
Condition on being less than the specified value.
1 to 65535
The following are part of a choice: eq, gt, lt, or range.
20.10.R1
VSR
Enable the range context
The following are part of a choice: eq, gt, lt, or range.
20.10.R1
VSR
Specifies upper bound port to match.
1 to 65535
This element is mandatory.
20.10.R1
VSR
Specifies lower bound port to match.
0 to 65534
This element is mandatory.
20.10.R1
VSR
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Configure ip-exception identifier.
configure filter ip-exception string filter-id number
1 to 65535
20.10.R1
VSR
Enter the ip-filter list instance
16.0.R1
All
Filter name
1 to 64
This element is part of a list key.
16.0.R1
All
Chain filter policy to the active IPvX system filter policy
configure filter ip-filter string chain-to-system-filter boolean
false
16.0.R1
All
Action for packets that do not match any entry
configure filter ip-filter string default-action keyword
drop
drop, accept
16.0.R1
All
Text description
configure filter ip-filter string description string
1 to 80
16.0.R1
All
Enter the embed context
Commands in this context embed a previously defined IPv4 embedded filter policy or Hybrid OpenFlow switch instance into an exclusive, template, or system filter policy at the specified offset value. Rules derived from the BGP FlowSpec can also be embedded into template filter policies only.
16.0.R1
All
Enter the filter list instance
16.0.R1
All
ID of the filter to insert
This element is part of a list key.
16.0.R1
All
Offset of the inserted entries
0 to 2097150
This element is part of a list key.
16.0.R1
All
Administrative state of this embedding
enable
enable, disable
16.0.R1
All
Offset of the inserted entries
0 to 2097151
This element is part of a list key.
16.0.R1
All
Administrative state of this embedding
enable
enable, disable
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Interface group ID for an external configured set of flowspec rules
0 to 16383
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Virtual router for an external configured set of flowspec rules
This element is mandatory.
16.0.R1
All
Enter the openflow list instance
16.0.R4
All
Referenced Hybrid OpenFlow Switch (OFS) name
This element is part of a list key.
16.0.R4
All
Offset of the inserted entries
0 to 2097150
This element is part of a list key.
16.0.R4
All
Administrative state of this embedding
enable
enable, disable
16.0.R4
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Global routing context
This element is the default part of a choice.
The following are part of a choice: grt, system, (sap and vpls), or vprn.
16.0.R4
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
SAP context
The following are part of a choice: grt, system, (sap and vpls), or vprn.
16.0.R4
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
System context
The following are part of a choice: grt, system, (sap and vpls), or vprn.
16.0.R4
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
VPLS context
The following are part of a choice: grt, system, (sap and vpls), or vprn.
16.0.R4
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
VPRN context
The following are part of a choice: grt, system, (sap and vpls), or vprn.
16.0.R4
All
ID for a match criteria and the corresponding action
1 to 2097151
This element is part of a list key.
16.0.R1
All
Enable the action context
16.0.R1
All
Accept regular routing to forward a packet that matches this entry
The following are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.
16.0.R1
All
Enable the accept-when context
19.5.R1
All
Enable the pattern context
19.5.R1
All
Pattern expression to match
configure filter ip-filter string entry number action accept-when pattern expression string
3 to 18
This element is mandatory.
19.5.R1
All
Mask for the pattern expression
3 to 18
This element is mandatory.
19.5.R1
All
Starting point reference for offset value of pattern
configure filter ip-filter string entry number action accept-when pattern offset-type keyword
layer-3, layer-4, data, dns-qtype
This element is mandatory.
19.5.R1
All
Offset value for the pattern expression
configure filter ip-filter string entry number action accept-when pattern offset-value number
0 to 255
This element is mandatory.
19.5.R1
All
Drop a packet matching this entry
The following are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.
16.0.R1
All
Enable the drop-when context
16.0.R1
All
Drop traffic extracted to CPM
16.0.R1
All
Enable the packet-length context
The following are part of a choice: packet-length or ttl.
16.0.R1
All
Exact match criterion for the length
0 to 65535
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Greater than match criterion for the length
min to 65534
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Less than match criterion for the length
1 to max
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Enable the range context
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Upper bound of the length range
1 to max
This element is mandatory.
16.0.R1
All
Lower bound of the length range
min to 65534
This element is mandatory.
16.0.R1
All
Enable the pattern context
16.0.R4
All
Pattern expression to match
3 to 18
This element is mandatory.
16.0.R4
All
Mask for the pattern expression
3 to 18
This element is mandatory.
16.0.R4
All
Starting point reference for offset value of pattern
layer-3, layer-4, data, dns-qtype
This element is mandatory.
16.0.R4
All
Offset value for the pattern expression
0 to 255
This element is mandatory.
16.0.R4
All
Enable the ttl context
The following are part of a choice: packet-length or ttl.
16.0.R1
All
Value to compare against 'equal' condition for entry match criteria
0 to 255
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Value to compare against 'greater than' condition for entry match criteria
min to 254
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Value to compare against 'less than' condition for entry match criteria
1 to max
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Enable the range context
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Upper bound value
1 to max
This element is mandatory.
16.0.R1
All
Lower bound value
min to 254
This element is mandatory.
16.0.R1
All
Class name to be forwarded for matching packets
be, l2, af, l1, h2, ef, h1, nc
16.0.R1
All
Enter the forward context
The following are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.
16.0.R1
All
Connection ID over which packet is forwarded
1 to 2
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the esi-l2 context
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
16.0.R1
All
ESI of the first ESI-identified appliance
This element is mandatory.
16.0.R1
All
VPLS service name
This element is mandatory.
16.0.R3
All
Enable the esi-l3 context
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
ESI of the first ESI-identified appliance
This element is mandatory.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
IP address of the service function to forward traffic
This element is mandatory.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Egress R-VPLS IP interface name
This element is mandatory.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
VPRN service name
This element is mandatory.
16.0.R4
All
GRE tunnel template ID that sets the location where an encapsulated matching packet is transported
configure filter gre-tunnel-template string
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
16.0.R1
All
LSP that is specified to forward a packet matching this entry
1 to 64
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
16.0.R1
All
Enable the mpls-policy context
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
19.10.R1
All
The MPLS forwarding policy endpoint IPv4 address
This element is mandatory.
19.10.R1
All
Enable the next-hop context
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
16.0.R1
All
IP interface name that forwards matching packets
1 to 32
The following are part of a mandatory choice: interface-name, nh-ip, or nh-ip-vrf.
16.0.R1
All
Enable the nh-ip context
The following are part of a mandatory choice: interface-name, nh-ip, or nh-ip-vrf.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
IPv4 address of next hop to forward matching packets
This element is mandatory.
16.0.R1
All
Allow next hop to be indirectly reachable
false
16.0.R1
All
Enable the nh-ip-vrf context
The following are part of a mandatory choice: interface-name, nh-ip, or nh-ip-vrf.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
IPv4 address of next hop to forward matching packets
This element is mandatory.
16.0.R1
All
Allow next hop to be indirectly reachable
false
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Routing context for route lookup for forwarding packets
This element is mandatory.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Next hop or forward next hop router that forwards a packet that matches this entry
configure filter redirect-policy string
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Specifies the routing context used for route lookup.
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
16.0.R1
All
Enable the sap context
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
16.0.R1
All
VPLS Ethernet SAP ID used to forward matching packets
This element is mandatory.
16.0.R1
All
VPLS associated with the SAP
This element is mandatory.
16.0.R1
All
Enable the sdp context
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
16.0.R1
All
VPLS SDP bind ID used to forward matching packets
3 to 16
This element is mandatory.
16.0.R1
All
VPLS associated with the SDP
This element is mandatory.
16.0.R1
All
Enable the srte-policy context
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
19.10.R1
All
The SR-TE policy color value
0 to 4294967295
This element is mandatory.
19.10.R1
All
The SR-TE policy endpoint IPv4 address
This element is mandatory.
19.10.R1
All
Enable the vprn-target context
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
16.0.R1
All
Advertised IP prefix for target destination
configure filter ip-filter string entry number action forward vprn-target adv-prefix string
16.0.R1
All
Target BGP next hop IP address
This element is mandatory.
16.0.R1
All
LSP that is specified to forward a packet matching this entry
1 to 64
16.0.R1
All
Routing context used for route lookup
This element is mandatory.
16.0.R4
All
Break out matching traffic locally from a GTP tunnel for GTP-subscriber-hosts, or forward for other entities
The following are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.
16.0.R1
7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the http-redirect context
The following are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.
16.0.R1
All
Override http-redirect by a RADIUS VSA
configure filter ip-filter string entry number action http-redirect allow-override boolean
false
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
URL that is used for redirecting
1 to 255
from-cpf
This element is mandatory.
16.0.R1
All
Ignore match criteria for the entry
The following are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.
16.0.R1
All
Divert traffic from an L2-Aware NAT subscriber
When configured to true, the filter action selectively diverts traffic from a L2-Aware NAT subscriber away from NAT. This action is only applicable to L2-Aware NAT subscribers and must be configured together with action accept. Traffic identified in the match condition bypasses L2-Aware NAT. An example is to bypass NAT for on-net destinations (within the customer network).
For selective NAT bypass to take effect, in addition to IP filter configuration, the L2-Aware NAT subscriber must be specifically enabled for selective bypass via the allow-bypass configuration option in the configure subscriber-mgmt sub-profile nat allow-bypass context.
When configured to false, traffic that is not classified for bypass automatically diverts to L2-Aware NAT, unless it is explicitly configured in the IP filter action to be dropped.
false
20.5.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the nat context
The following are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element clears ISA state, such as flow state, for the new value to take effect. |
NAT policy name when action is NAT
configure service nat nat-policy string
16.0.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the rate-limit context
16.0.R1
All
Enable the packet-length context
configure filter ip-filter string entry number action rate-limit packet-length
The following are part of a choice: packet-length or ttl.
16.0.R1
All
Exact match criterion for the length
configure filter ip-filter string entry number action rate-limit packet-length eq number
0 to 65535
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Greater than match criterion for the length
configure filter ip-filter string entry number action rate-limit packet-length gt number
min to 65534
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Less than match criterion for the length
configure filter ip-filter string entry number action rate-limit packet-length lt number
1 to max
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Enable the range context
configure filter ip-filter string entry number action rate-limit packet-length range
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Upper bound of the length range
configure filter ip-filter string entry number action rate-limit packet-length range end number
1 to max
This element is mandatory.
16.0.R1
All
Lower bound of the length range
configure filter ip-filter string entry number action rate-limit packet-length range start number
min to 65534
This element is mandatory.
16.0.R1
All
Enable the pattern context
16.0.R4
All
Pattern expression to match
configure filter ip-filter string entry number action rate-limit pattern expression string
3 to 18
This element is mandatory.
16.0.R4
All
Mask for the pattern expression
3 to 18
This element is mandatory.
16.0.R4
All
Starting point reference for offset value of pattern
configure filter ip-filter string entry number action rate-limit pattern offset-type keyword
layer-3, layer-4, data, dns-qtype
This element is mandatory.
16.0.R4
All
Offset value for the pattern expression
configure filter ip-filter string entry number action rate-limit pattern offset-value number
0 to 255
This element is mandatory.
16.0.R4
All
Peak information rate
0 to 2000000000
kilobps
max
This element is mandatory.
16.0.R1
All
Enable the ttl context
The following are part of a choice: packet-length or ttl.
16.0.R1
All
Value to compare against 'equal' condition for entry match criteria
0 to 255
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Value to compare against 'greater than' condition for entry match criteria
min to 254
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Value to compare against 'less than' condition for entry match criteria
1 to max
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Enable the range context
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Upper bound value
1 to max
This element is mandatory.
16.0.R1
All
Lower bound value
min to 254
This element is mandatory.
16.0.R1
All
Forward matching packets to reassembly function
The following are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the remark context
16.0.R1
All
Destination SAP
be, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63
This element is mandatory.
16.0.R1
All
Enable the secondary context
16.0.R1
All
Enter the forward context
This element is mandatory.
16.0.R1
All
Enable the next-hop context
The following are part of a choice: next-hop, sap, or sdp.
16.0.R1
All
Enable the nh-ip-vrf context
This element is mandatory.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
IPv4 address of next hop to forward matching packets
This element is mandatory.
16.0.R1
All
Allow next hop to be indirectly reachable
false
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Routing context for route lookup for forwarding packets
This element is mandatory.
16.0.R1
All
Enable the sap context
The following are part of a choice: next-hop, sap, or sdp.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
A packet matching the entry will be forwarded using the specified SAP
This element is mandatory.
16.0.R1
All
VPLS the sdp-bind-id belongs to
This element is mandatory.
16.0.R1
All
Enable the sdp context
The following are part of a choice: next-hop, sap, or sdp.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
VPLS SDP bind ID used to forward matching packets
3 to 16
This element is mandatory.
16.0.R1
All
VPLS associated with the SDP
This element is mandatory.
16.0.R1
All
Enable the remark context
16.0.R1
All
Destination SAP
be, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63
This element is mandatory.
16.0.R1
All
Adjust MSS option of TCP matching packets to configured value of tcp-mss in router interface context
The following are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure filter ip-filter string entry number description string
1 to 80
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
PBR that has an effect when this filter is applied on egress
configure filter ip-filter string entry number egress-pbr keyword
true, true-with-l4lb
16.0.R1
All
Sample matching traffic if IP interface is set to cflowd ACL mode
configure filter ip-filter string entry number filter-sample boolean
false
16.0.R1
All
Sample matching traffic if IP interface is set to cflowd interface mode
configure filter ip-filter string entry number interface-sample boolean
true
16.0.R1
All
Log that is used for packets matching this entry
16.0.R1
All
Enter the match context
Commands in this context configure match criteria for the filter entry. When the match criteria are satisfied, the action associated with the match criteria is executed.
16.0.R1
All
Destination class as a match criterion
This command configures the BGP destination class value as a match criterion. Filtering egress traffic on the destination class requires the destination-class-lookup command (under the ingress context for the service interface) to be enabled (set to true).
1 to 255
20.7.R1
All
DSCP used as an IP filter match criterion
be, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63
16.0.R1
All
Enter the dst-ip context
16.0.R1
All
IP address used as the match criterion
The following are part of a choice: (address and mask) or ip-prefix-list.
16.0.R1
All
IP prefix list used as match criterion
configure filter match-list ip-prefix-list string
The following are part of a choice: (address and mask) or ip-prefix-list.
16.0.R1
All
Address mask as the match criterion
The following are part of a choice: (address and mask) or ip-prefix-list.
16.0.R1
All
Enter the dst-port context
The following are part of a choice: port or (dst-port and src-port).
16.0.R1
All
Exact match criterion for the port number
0 to 65535
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Greater than match criterion for the port number
0 to 65534
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Less than match criterion for the port number
1 to 65535
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Name of the port list as the match criterion
configure filter match-list port-list string
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Enable the range context
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Upper bound of the port range as port match criterion
1 to 65535
This element is mandatory.
16.0.R1
All
Lower bound of the port range as port match criterion
0 to 65534
This element is mandatory.
16.0.R1
All
Match criterion for fragmented packets
false, true, first-only, non-first-only
16.0.R1
All
Enter the icmp context
16.0.R1
All
ICMP code value to match
0 to 255
16.0.R1
All
ICMP type value to match
0 to 255
16.0.R1
All
Enable the ip-option context
16.0.R1
All
Mask that is ANDed with ip-option value in the packet header
1 to 255
255
16.0.R1
All
Specific IP option to match
0 to 255
This element is mandatory.
16.0.R1
All
Match based on presence of multiple options in header
16.0.R1
All
Match on the presence of any IP option in the packet
16.0.R1
All
Enable the packet-length context
19.5.R1
All
Exact match criterion for the length
0 to 65535
The following are part of a mandatory choice: eq, gt, lt, or range.
19.5.R1
All
Greater than match criterion for the length
min to 65534
The following are part of a mandatory choice: eq, gt, lt, or range.
19.5.R1
All
Less than match criterion for the length
1 to max
The following are part of a mandatory choice: eq, gt, lt, or range.
19.5.R1
All
Enable the range context
The following are part of a mandatory choice: eq, gt, lt, or range.
19.5.R1
All
Upper bound of the length range
1 to max
This element is mandatory.
19.5.R1
All
Lower bound of the length range
min to 65534
This element is mandatory.
19.5.R1
All
Enter the port context
The following are part of a choice: port or (dst-port and src-port).
16.0.R1
All
Exact match criterion for the port number
0 to 65535
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Greater than match criterion for the port number
0 to 65534
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Less than match criterion for the port number
1 to 65535
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Name of the port list as the match criterion
configure filter match-list port-list string
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Enable the range context
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Upper bound of the port range as port match criterion
1 to 65535
This element is mandatory.
16.0.R1
All
Lower bound of the port range as port match criterion
0 to 65534
This element is mandatory.
16.0.R1
All
IP protocol identifier as a match criterion
0 to 255
tcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp
The following are part of a choice: protocol or protocol-list.
16.0.R1
All
Name of the protocol list as a match criterion
configure filter match-list protocol-list string
The following are part of a choice: protocol or protocol-list.
20.7.R1
All
Enter the src-ip context
16.0.R1
All
IP address used as the match criterion
The following are part of a choice: (address and mask) or ip-prefix-list.
16.0.R1
All
IP prefix list used as match criterion
configure filter match-list ip-prefix-list string
The following are part of a choice: (address and mask) or ip-prefix-list.
16.0.R1
All
Address mask as the match criterion
The following are part of a choice: (address and mask) or ip-prefix-list.
16.0.R1
All
Enable the src-mac context
19.5.R1
All
MAC address used as the match criterion
This element is mandatory.
19.5.R1
All
MAC address mask as the match criterion
ff:ff:ff:ff:ff:ff
19.5.R1
All
Enter the src-port context
The following are part of a choice: port or (dst-port and src-port).
16.0.R1
All
Exact match criterion for the port number
0 to 65535
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Greater than match criterion for the port number
0 to 65534
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Less than match criterion for the port number
1 to 65535
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Name of the port list as the match criterion
configure filter match-list port-list string
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Enable the range context
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Upper bound of the port range as port match criterion
1 to 65535
This element is mandatory.
16.0.R1
All
Lower bound of the port range as port match criterion
0 to 65534
This element is mandatory.
16.0.R1
All
Match based on presence of source route option
16.0.R1
All
Enter the tcp-flags context
16.0.R1
All
Match TCP ACK as per value of the ACK TCP flag bit
16.0.R1
All
Match TCP CWR as per value of the CWR TCP flag bit
16.0.R1
All
Match TCP ECE as per value of the ECE TCP flag bit
16.0.R1
All
Match TCP FIN as per value of the FIN TCP flag bit
16.0.R1
All
Match TCP NS as per value of the NS TCP flag bit
16.0.R1
All
Match TCP PSH as per value of the PSH TCP flag bit
16.0.R1
All
Match TCP RST as per value of the RST TCP flag bit
16.0.R1
All
Match TCP SYN as per value of the SYN TCP flag bit
16.0.R1
All
Match TCP URG as per value of the URG TCP flag bit
16.0.R1
All
Action when PBR or PBF target for this entry is not available
configure filter ip-filter string entry number pbr-down-action-override keyword
drop, forward, filter-default-action
16.0.R1
All
Cflowd sample profile ID for matching packets
configure filter ip-filter string entry number sample-profile reference
This command allows traffic matching an IPv4 or IPv6 filter to be sampled for cflowd processing using a specific sample-profile sample-profile-id. This option is only compatible if the associated interface is configured for interface-based
sampling and in only supported for ingress sampling. An IP filter can only specify a single alternate sample-profile for cflowd sampling, but that sample-profile can be used in multiple entries.
configure cflowd sample-profile number
20.10.R1
All
Time before action with available PBR or PBF destination and highest priority
configure filter ip-filter string entry number sticky-dest (number | keyword)
0 to 65535
seconds
no-hold-time-up
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
IP filter ID
1 to 65535
16.0.R1
All
Scope of this filter definition
template
exclusive, template, embedded, system
16.0.R1
All
Enter the subscriber-mgmt context
configure filter ip-filter string subscriber-mgmt
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Enter the host-specific-entry context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Enter the credit-control context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Enable the range context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Upper bound of range for entries from Credit Control
configure filter ip-filter string subscriber-mgmt host-specific-entry credit-control range end number
1 to 2097151
This element is mandatory.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Lower bound of range for entries from Credit Control
configure filter ip-filter string subscriber-mgmt host-specific-entry credit-control range start number
1 to 2097151
This element is mandatory.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Enter the filter-rule context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Enable the range context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Upper bound of range for filter-rule entries from RADIUS/Diameter
configure filter ip-filter string subscriber-mgmt host-specific-entry filter-rule range end number
1 to 2097151
This element is mandatory.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Lower bound of range for subscriber host filter-rule entries from RADIUS/Diameter
configure filter ip-filter string subscriber-mgmt host-specific-entry filter-rule range start number
1 to 2097151
This element is mandatory.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Enter the watermark context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
High watermark for host-specific entries, to raise a table full alarm
configure filter ip-filter string subscriber-mgmt host-specific-entry watermark high number
0 to 100
95
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Low watermark for host-specific entries, to clear a table full alarm
configure filter ip-filter string subscriber-mgmt host-specific-entry watermark low number
0 to 100
90
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Enter the shared-entry context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Enter the filter-rule context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Enable the range context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Upper bound of range for shared-filter rules from RADIUS
configure filter ip-filter string subscriber-mgmt shared-entry filter-rule range end number
1 to 2097151
This element is mandatory.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Lower bound of range for shared filter-rules from RADIUS
configure filter ip-filter string subscriber-mgmt shared-entry filter-rule range start number
1 to 2097151
This element is mandatory.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Enter the pcc-rule context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Enable the range context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Upper bound of range for pcc-rule filter entries from Diameter
configure filter ip-filter string subscriber-mgmt shared-entry pcc-rule range end number
1 to 2097151
This element is mandatory.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Lower bound of range for pcc-rule filter entries from Diameter
configure filter ip-filter string subscriber-mgmt shared-entry pcc-rule range start number
1 to 2097151
This element is mandatory.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Enable the watermark context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Limit of RADIUS shared filters before generating high watermark notification
configure filter ip-filter string subscriber-mgmt shared-entry watermark high number
1 to 8000
This element is mandatory.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Limit of RADIUS or Diameter shared filters before clearing high watermark notification
configure filter ip-filter string subscriber-mgmt shared-entry watermark low number
0 to 7999
This element is mandatory.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Set of match criteria for the filter policy
normal
normal, src-mac, packet-length, destination-class
19.5.R1
All
Enter the ipv6-exception list instance
configure filter ipv6-exception string
20.10.R1
VSR
Filter name
configure filter ipv6-exception string
1 to 64
This element is part of a list key.
20.10.R1
VSR
Text description
configure filter ipv6-exception string description string
1 to 80
20.10.R1
VSR
Enter the entry list instance
configure filter ipv6-exception string entry number
20.10.R1
VSR
ID for a match criteria and the corresponding action
configure filter ipv6-exception string entry number
1 to 2097151
This element is part of a list key.
20.10.R1
VSR
Text description
configure filter ipv6-exception string entry number description string
1 to 80
20.10.R1
VSR
Enter the match context
configure filter ipv6-exception string entry number match
20.10.R1
VSR
Enter the dst-ip context
20.10.R1
VSR
IP address as the match criterion
The following are part of a choice: (address and mask) or ipv6-prefix-list.
20.10.R1
VSR
IPv6 prefix list as match criterion for IP address
configure filter ipv6-exception string entry number match dst-ip ipv6-prefix-list reference
The following are part of a choice: (address and mask) or ipv6-prefix-list.
20.10.R1
VSR
IPv6 address mask as the match criterion
The following are part of a choice: (address and mask) or ipv6-prefix-list.
20.10.R1
VSR
Enter the dst-port context
The following are part of a choice: port or (dst-port and src-port).
20.10.R1
VSR
Exact match criterion for the port number
0 to 65535
The following are part of a choice: eq, gt, lt, port-list, or range.
20.10.R1
VSR
Greater than match criterion for the port number
0 to 65534
The following are part of a choice: eq, gt, lt, port-list, or range.
20.10.R1
VSR
Less than match criterion for the port number
1 to 65535
The following are part of a choice: eq, gt, lt, port-list, or range.
20.10.R1
VSR
Name of the port list as the match criterion
configure filter match-list port-list string
The following are part of a choice: eq, gt, lt, port-list, or range.
20.10.R1
VSR
Enable the range context
The following are part of a choice: eq, gt, lt, port-list, or range.
20.10.R1
VSR
Upper bound of the port range as port match criterion
1 to 65535
This element is mandatory.
20.10.R1
VSR
Lower bound of the port range as port match criterion
0 to 65534
This element is mandatory.
20.10.R1
VSR
Enter the icmp context
20.10.R1
VSR
ICMPv6 code value to match
0 to 255
20.10.R1
VSR
ICMPv6 type value to match
0 to 255
20.10.R1
VSR
IP protocol to match
configure filter ipv6-exception string entry number match next-header (number | keyword)
0 to 255
tcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp
20.10.R1
VSR
Enter the port context
The following are part of a choice: port or (dst-port and src-port).
20.10.R1
VSR
Exact match criterion for the port number
0 to 65535
The following are part of a choice: eq, gt, lt, port-list, or range.
20.10.R1
VSR
Greater than match criterion for the port number
0 to 65534
The following are part of a choice: eq, gt, lt, port-list, or range.
20.10.R1
VSR
Less than match criterion for the port number
1 to 65535
The following are part of a choice: eq, gt, lt, port-list, or range.
20.10.R1
VSR
Name of the port list as the match criterion
configure filter match-list port-list string
The following are part of a choice: eq, gt, lt, port-list, or range.
20.10.R1
VSR
Enable the range context
The following are part of a choice: eq, gt, lt, port-list, or range.
20.10.R1
VSR
Upper bound of the port range as port match criterion
1 to 65535
This element is mandatory.
20.10.R1
VSR
Lower bound of the port range as port match criterion
0 to 65534
This element is mandatory.
20.10.R1
VSR
Enter the src-ip context
20.10.R1
VSR
IP address as the match criterion
The following are part of a choice: (address and mask) or ipv6-prefix-list.
20.10.R1
VSR
IPv6 prefix list as match criterion for IP address
configure filter ipv6-exception string entry number match src-ip ipv6-prefix-list reference
The following are part of a choice: (address and mask) or ipv6-prefix-list.
20.10.R1
VSR
IPv6 address mask as the match criterion
The following are part of a choice: (address and mask) or ipv6-prefix-list.
20.10.R1
VSR
Enter the src-port context
The following are part of a choice: port or (dst-port and src-port).
20.10.R1
VSR
Exact match criterion for the port number
0 to 65535
The following are part of a choice: eq, gt, lt, port-list, or range.
20.10.R1
VSR
Greater than match criterion for the port number
0 to 65534
The following are part of a choice: eq, gt, lt, port-list, or range.
20.10.R1
VSR
Less than match criterion for the port number
1 to 65535
The following are part of a choice: eq, gt, lt, port-list, or range.
20.10.R1
VSR
Name of the port list as the match criterion
configure filter match-list port-list string
The following are part of a choice: eq, gt, lt, port-list, or range.
20.10.R1
VSR
Enable the range context
The following are part of a choice: eq, gt, lt, port-list, or range.
20.10.R1
VSR
Upper bound of the port range as port match criterion
1 to 65535
This element is mandatory.
20.10.R1
VSR
Lower bound of the port range as port match criterion
0 to 65534
This element is mandatory.
20.10.R1
VSR
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Filter ID
configure filter ipv6-exception string filter-id number
1 to 65535
20.10.R1
VSR
Enter the ipv6-filter list instance
configure filter ipv6-filter string
16.0.R1
All
Filter name
configure filter ipv6-filter string
1 to 64
This element is part of a list key.
16.0.R1
All
Chain filter policy to the active IPvX system filter policy
configure filter ipv6-filter string chain-to-system-filter boolean
false
16.0.R1
All
Action for packets that do not match any entry
configure filter ipv6-filter string default-action keyword
drop
drop, accept
16.0.R1
All
Text description
configure filter ipv6-filter string description string
1 to 80
16.0.R1
All
Enter the embed context
configure filter ipv6-filter string embed
Commands in this context embed a previously defined IPv6 embedded filter policy or Hybrid OpenFlow switch instance into an exclusive, template, or system filter policy at the specified offset value. Rules derived from the BGP FlowSpec can also be embedded into template filter policies only.
16.0.R1
All
Enter the filter list instance
16.0.R1
All
ID of the filter to insert
configure filter ipv6-filter string
This element is part of a list key.
16.0.R1
All
Offset of the inserted entries
0 to 2097150
This element is part of a list key.
16.0.R1
All
Administrative state of this embedding
configure filter ipv6-filter string embed filter reference offset number admin-state keyword
enable
enable, disable
16.0.R1
All
Offset of the inserted entries
0 to 2097151
This element is part of a list key.
16.0.R1
All
Administrative state of this embedding
configure filter ipv6-filter string embed flowspec offset number admin-state keyword
enable
enable, disable
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Interface group ID for an external configured set of flowspec rules
0 to 16383
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Virtual router for an external configured set of flowspec rules
configure filter ipv6-filter string embed flowspec offset number router-instance string
This element is mandatory.
16.0.R1
All
Enter the openflow list instance
16.0.R4
All
Referenced Hybrid OpenFlow Switch (OFS) name
This element is part of a list key.
16.0.R4
All
Offset of the inserted entries
0 to 2097150
This element is part of a list key.
16.0.R4
All
Administrative state of this embedding
configure filter ipv6-filter string embed openflow reference offset number admin-state keyword
enable
enable, disable
16.0.R4
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Global routing context
This element is the default part of a choice.
The following are part of a choice: grt, system, (sap and vpls), or vprn.
16.0.R4
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
SAP context
The following are part of a choice: grt, system, (sap and vpls), or vprn.
16.0.R4
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
System context
The following are part of a choice: grt, system, (sap and vpls), or vprn.
16.0.R4
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
VPLS context
The following are part of a choice: grt, system, (sap and vpls), or vprn.
16.0.R4
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
VPRN context
The following are part of a choice: grt, system, (sap and vpls), or vprn.
16.0.R4
All
Enter the entry list instance
configure filter ipv6-filter string entry number
16.0.R1
All
ID for a match criteria and the corresponding action
configure filter ipv6-filter string entry number
1 to 2097151
This element is part of a list key.
16.0.R1
All
Enable the action context
configure filter ipv6-filter string entry number action
16.0.R1
All
Accept regular routing to forward a packet that matches this entry
The following are part of a mandatory choice: accept, drop, forward, http-redirect, ignore-match, nat, or tcp-mss-adjust.
16.0.R1
All
Enable the accept-when context
configure filter ipv6-filter string entry number action accept-when
19.5.R1
All
Enable the pattern context
configure filter ipv6-filter string entry number action accept-when pattern
19.5.R1
All
Pattern expression to match
configure filter ipv6-filter string entry number action accept-when pattern expression string
3 to 18
This element is mandatory.
19.5.R1
All
Mask for the pattern expression
configure filter ipv6-filter string entry number action accept-when pattern mask string
3 to 18
This element is mandatory.
19.5.R1
All
Starting point reference for offset value of pattern
configure filter ipv6-filter string entry number action accept-when pattern offset-type keyword
layer-3, layer-4, data, dns-qtype
This element is mandatory.
19.5.R1
All
Offset value for the pattern expression
configure filter ipv6-filter string entry number action accept-when pattern offset-value number
0 to 255
This element is mandatory.
19.5.R1
All
Drop a packet matching this entry
The following are part of a mandatory choice: accept, drop, forward, http-redirect, ignore-match, nat, or tcp-mss-adjust.
16.0.R1
All
Enable the drop-when context
16.0.R1
All
Drop traffic extracted to CPM
configure filter ipv6-filter string entry number action drop-when extracted-traffic
16.0.R1
All
Enable the hop-limit context
The following are part of a choice: hop-limit or payload-length.
16.0.R1
All
Value to compare against 'equal' condition for entry match criteria
0 to 255
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Value to compare against 'greater than' condition for entry match criteria
min to 254
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Value to compare against 'less than' condition for entry match criteria
1 to max
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Enable the range context
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Upper bound value
1 to max
This element is mandatory.
16.0.R1
All
Lower bound value
min to 254
This element is mandatory.
16.0.R1
All
Enable the pattern context
16.0.R4
All
Pattern expression to match
configure filter ipv6-filter string entry number action drop-when pattern expression string
3 to 18
This element is mandatory.
16.0.R4
All
Mask for the pattern expression
3 to 18
This element is mandatory.
16.0.R4
All
Starting point reference for offset value of pattern
configure filter ipv6-filter string entry number action drop-when pattern offset-type keyword
layer-3, layer-4, data, dns-qtype
This element is mandatory.
16.0.R4
All
Offset value for the pattern expression
configure filter ipv6-filter string entry number action drop-when pattern offset-value number
0 to 255
This element is mandatory.
16.0.R4
All
Enable the payload-length context
configure filter ipv6-filter string entry number action drop-when payload-length
The following are part of a choice: hop-limit or payload-length.
16.0.R1
All
Exact match criterion for the length
configure filter ipv6-filter string entry number action drop-when payload-length eq number
0 to 65535
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Greater than match criterion for the length
configure filter ipv6-filter string entry number action drop-when payload-length gt number
min to 65534
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Less than match criterion for the length
configure filter ipv6-filter string entry number action drop-when payload-length lt number
1 to max
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Enable the range context
configure filter ipv6-filter string entry number action drop-when payload-length range
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Upper bound of the length range
configure filter ipv6-filter string entry number action drop-when payload-length range end number
1 to max
This element is mandatory.
16.0.R1
All
Lower bound of the length range
configure filter ipv6-filter string entry number action drop-when payload-length range start number
min to 65534
This element is mandatory.
16.0.R1
All
Class name to be forwarded for matching packets
be, l2, af, l1, h2, ef, h1, nc
16.0.R1
All
Enter the forward context
The following are part of a mandatory choice: accept, drop, forward, http-redirect, ignore-match, nat, or tcp-mss-adjust.
16.0.R1
All
Connection ID over which packet is forwarded
configure filter ipv6-filter string entry number action forward bonding-connection number
1 to 2
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the esi-l2 context
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
16.0.R1
All
ESI of the first ESI-identified appliance
This element is mandatory.
16.0.R1
All
VPLS service name
This element is mandatory.
16.0.R3
All
Enable the esi-l3 context
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
ESI of the first ESI-identified appliance
This element is mandatory.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
IP address of the service function to forward traffic
This element is mandatory.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Egress R-VPLS IP interface name
configure filter ipv6-filter string entry number action forward esi-l3 vas-interface reference
This element is mandatory.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
VPRN service name
This element is mandatory.
16.0.R4
All
GRE tunnel template ID that sets the location where an encapsulated matching packet is transported
configure filter ipv6-filter string entry number action forward gre-tunnel reference
configure filter gre-tunnel-template string
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
16.0.R1
All
LSP that is specified to forward a packet matching this entry
1 to 64
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
16.0.R1
All
Enable the mpls-policy context
configure filter ipv6-filter string entry number action forward mpls-policy
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
19.10.R1
All
The MPLS forwarding policy endpoint IPv6 address
configure filter ipv6-filter string entry number action forward mpls-policy endpoint string
This element is mandatory.
19.10.R1
All
Enable the next-hop context
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
16.0.R1
All
Enable the nh-ip context
The following are part of a mandatory choice: nh-ip or nh-ip-vrf.
16.0.R1
All
IPv6 address of next hop to forward matching packets
This element is mandatory.
16.0.R1
All
Allow next hop to be indirectly reachable
false
16.0.R1
All
Enable the nh-ip-vrf context
The following are part of a mandatory choice: nh-ip or nh-ip-vrf.
16.0.R1
All
IPv6 address of next hop to forward matching packets
This element is mandatory.
16.0.R1
All
Allow next hop to be indirectly reachable
false
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Routing context for route lookup for forwarding packets
configure filter ipv6-filter string entry number action forward next-hop nh-ip-vrf router-instance string
This element is mandatory.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Next hop or forward next hop router that forwards a packet that matches this entry
configure filter ipv6-filter string entry number action forward redirect-policy reference
configure filter redirect-policy string
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Specifies the routing context used for route lookup.
configure filter ipv6-filter string entry number action forward router-instance string
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
16.0.R1
All
Enable the sap context
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
16.0.R1
All
VPLS Ethernet SAP ID used to forward matching packets
This element is mandatory.
16.0.R1
All
VPLS associated with the SAP
This element is mandatory.
16.0.R1
All
Enable the sdp context
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
16.0.R1
All
VPLS SDP bind ID used to forward matching packets
configure filter ipv6-filter string entry number action forward sdp sdp-bind-id string
3 to 16
This element is mandatory.
16.0.R1
All
VPLS associated with the SDP
This element is mandatory.
16.0.R1
All
Enable the srte-policy context
configure filter ipv6-filter string entry number action forward srte-policy
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
19.10.R1
All
The SR-TE policy color value
configure filter ipv6-filter string entry number action forward srte-policy color number
0 to 4294967295
This element is mandatory.
19.10.R1
All
The SR-TE policy endpoint IPv6 address
configure filter ipv6-filter string entry number action forward srte-policy endpoint string
This element is mandatory.
19.10.R1
All
Enable the vprn-target context
configure filter ipv6-filter string entry number action forward vprn-target
The following are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.
16.0.R1
All
Advertised IP prefix for target destination
configure filter ipv6-filter string entry number action forward vprn-target adv-prefix string
16.0.R1
All
Target BGP next hop IP address
configure filter ipv6-filter string entry number action forward vprn-target bgp-nh string
This element is mandatory.
16.0.R1
All
LSP that is specified to forward a packet matching this entry
configure filter ipv6-filter string entry number action forward vprn-target lsp string
1 to 64
16.0.R1
All
Routing context used for route lookup
configure filter ipv6-filter string entry number action forward vprn-target vprn reference
This element is mandatory.
16.0.R4
All
Enable the http-redirect context
configure filter ipv6-filter string entry number action http-redirect
The following are part of a mandatory choice: accept, drop, forward, http-redirect, ignore-match, nat, or tcp-mss-adjust.
16.0.R1
All
Override http-redirect by a RADIUS VSA
configure filter ipv6-filter string entry number action http-redirect allow-override boolean
false
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
URL that is used for redirecting
configure filter ipv6-filter string entry number action http-redirect url (keyword | http-redirect-url)
1 to 255
from-cpf
This element is mandatory.
16.0.R1
All
Ignore match criteria for the entry
configure filter ipv6-filter string entry number action ignore-match
The following are part of a mandatory choice: accept, drop, forward, http-redirect, ignore-match, nat, or tcp-mss-adjust.
16.0.R1
All
Enable the nat context
The following are part of a mandatory choice: accept, drop, forward, http-redirect, ignore-match, nat, or tcp-mss-adjust.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element clears ISA state, such as flow state, for the new value to take effect. |
NAT policy name when action is NAT
configure filter ipv6-filter string entry number action nat nat-policy reference
configure service nat nat-policy string
16.0.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element clears ISA state, such as flow state, for the new value to take effect. |
NAT type to assign when action is NAT
dslite, nat64
This element is mandatory.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the rate-limit context
configure filter ipv6-filter string entry number action rate-limit
16.0.R1
All
Enable the hop-limit context
configure filter ipv6-filter string entry number action rate-limit hop-limit
The following are part of a choice: hop-limit or payload-length.
16.0.R1
All
Value to compare against 'equal' condition for entry match criteria
configure filter ipv6-filter string entry number action rate-limit hop-limit eq number
0 to 255
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Value to compare against 'greater than' condition for entry match criteria
configure filter ipv6-filter string entry number action rate-limit hop-limit gt number
min to 254
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Value to compare against 'less than' condition for entry match criteria
configure filter ipv6-filter string entry number action rate-limit hop-limit lt number
1 to max
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Enable the range context
configure filter ipv6-filter string entry number action rate-limit hop-limit range
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Upper bound value
configure filter ipv6-filter string entry number action rate-limit hop-limit range end number
1 to max
This element is mandatory.
16.0.R1
All
Lower bound value
configure filter ipv6-filter string entry number action rate-limit hop-limit range start number
min to 254
This element is mandatory.
16.0.R1
All
Enable the pattern context
configure filter ipv6-filter string entry number action rate-limit pattern
16.0.R4
All
Pattern expression to match
configure filter ipv6-filter string entry number action rate-limit pattern expression string
3 to 18
This element is mandatory.
16.0.R4
All
Mask for the pattern expression
configure filter ipv6-filter string entry number action rate-limit pattern mask string
3 to 18
This element is mandatory.
16.0.R4
All
Starting point reference for offset value of pattern
configure filter ipv6-filter string entry number action rate-limit pattern offset-type keyword
layer-3, layer-4, data, dns-qtype
This element is mandatory.
16.0.R4
All
Offset value for the pattern expression
configure filter ipv6-filter string entry number action rate-limit pattern offset-value number
0 to 255
This element is mandatory.
16.0.R4
All
Enable the payload-length context
configure filter ipv6-filter string entry number action rate-limit payload-length
The following are part of a choice: hop-limit or payload-length.
16.0.R1
All
Exact match criterion for the length
configure filter ipv6-filter string entry number action rate-limit payload-length eq number
0 to 65535
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Greater than match criterion for the length
configure filter ipv6-filter string entry number action rate-limit payload-length gt number
min to 65534
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Less than match criterion for the length
configure filter ipv6-filter string entry number action rate-limit payload-length lt number
1 to max
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Enable the range context
configure filter ipv6-filter string entry number action rate-limit payload-length range
The following are part of a mandatory choice: eq, gt, lt, or range.
16.0.R1
All
Upper bound of the length range
configure filter ipv6-filter string entry number action rate-limit payload-length range end number
1 to max
This element is mandatory.
16.0.R1
All
Lower bound of the length range
configure filter ipv6-filter string entry number action rate-limit payload-length range start number
min to 65534
This element is mandatory.
16.0.R1
All
Peak information rate
configure filter ipv6-filter string entry number action rate-limit pir (number | keyword)
0 to 2000000000
kilobps
max
This element is mandatory.
16.0.R1
All
Enable the remark context
16.0.R1
All
Destination SAP
be, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63
This element is mandatory.
16.0.R1
All
Enable the secondary context
16.0.R1
All
Enter the forward context
This element is mandatory.
16.0.R1
All
Enable the next-hop context
The following are part of a choice: next-hop, sap, or sdp.
16.0.R1
All
Enable the nh-ip-vrf context
This element is mandatory.
16.0.R1
All
IPv6 address of next hop to forward matching packets
This element is mandatory.
16.0.R1
All
Allow next hop to be indirectly reachable
false
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Routing context for route lookup for forwarding packets
configure filter ipv6-filter string entry number action secondary forward next-hop nh-ip-vrf router-instance string
This element is mandatory.
16.0.R1
All
Enable the sap context
The following are part of a choice: next-hop, sap, or sdp.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
A packet matching the entry will be forwarded using the specified SAP
This element is mandatory.
16.0.R1
All
VPLS the sdp-bind-id belongs to
This element is mandatory.
16.0.R1
All
Enable the sdp context
The following are part of a choice: next-hop, sap, or sdp.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
VPLS SDP bind ID used to forward matching packets
configure filter ipv6-filter string entry number action secondary forward sdp sdp-bind-id string
3 to 16
This element is mandatory.
16.0.R1
All
VPLS associated with the SDP
This element is mandatory.
16.0.R1
All
Enable the remark context
16.0.R1
All
Destination SAP
be, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63
This element is mandatory.
16.0.R1
All
Adjust MSS option of TCP matching packets to configured value of tcp-mss in router interface context
configure filter ipv6-filter string entry number action tcp-mss-adjust
The following are part of a mandatory choice: accept, drop, forward, http-redirect, ignore-match, nat, or tcp-mss-adjust.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure filter ipv6-filter string entry number description string
1 to 80
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
PBR that has an effect when this filter is applied on egress
configure filter ipv6-filter string entry number egress-pbr keyword
true, true-with-l4lb
16.0.R1
All
Sample matching traffic if IP interface is set to cflowd ACL mode
configure filter ipv6-filter string entry number filter-sample boolean
false
16.0.R1
All
Sample matching traffic if IP interface is set to cflowd interface mode
configure filter ipv6-filter string entry number interface-sample boolean
true
16.0.R1
All
Log that is used for packets matching this entry
configure filter ipv6-filter string entry number log reference
16.0.R1
All
Enter the match context
configure filter ipv6-filter string entry number match
Commands in this context provide match criteria for the filter entry. When the match criteria are satisfied, the action associated with the match criteria is executed.
16.0.R1
All
Destination class as a match criterion
configure filter ipv6-filter string entry number match destination-class number
This command configures the BGP destination class value as a match criterion. Filtering egress traffic on the destination class requires the destination-class-lookup command (under the ingress context for the service interface) to be enabled (set to true).
1 to 255
20.7.R1
All
DSCP used as an IP filter match criterion
be, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63
16.0.R1
All
Enter the dst-ip context
16.0.R1
All
IP address as the match criterion
The following are part of a choice: (address and mask) or ipv6-prefix-list.
16.0.R1
All
IPv6 prefix list as match criterion for IP address
configure filter ipv6-filter string entry number match dst-ip ipv6-prefix-list reference
The following are part of a choice: (address and mask) or ipv6-prefix-list.
16.0.R1
All
IPv6 address mask as the match criterion
The following are part of a choice: (address and mask) or ipv6-prefix-list.
16.0.R1
All
Enter the dst-port context
The following are part of a choice: port or (dst-port and src-port).
16.0.R1
All
Exact match criterion for the port number
0 to 65535
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Greater than match criterion for the port number
0 to 65534
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Less than match criterion for the port number
1 to 65535
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Name of the port list as the match criterion
configure filter match-list port-list string
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Enable the range context
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Upper bound of the port range as port match criterion
1 to 65535
This element is mandatory.
16.0.R1
All
Lower bound of the port range as port match criterion
0 to 65534
This element is mandatory.
16.0.R1
All
Enter the extension-header context
configure filter ipv6-filter string entry number match extension-header
16.0.R1
All
Match a packet as per the existence of an AH Extension Header
configure filter ipv6-filter string entry number match extension-header ah boolean
16.0.R1
All
Match a packet as per the existence of an Encapsulation security payload extension header
configure filter ipv6-filter string entry number match extension-header esp boolean
16.0.R1
All
Match on Hop-by-Hop Options Extension Header existence
configure filter ipv6-filter string entry number match extension-header hop-by-hop boolean
16.0.R2
All
Match a packet as per the existence of a routing Extension Header
configure filter ipv6-filter string entry number match extension-header routing-type0 boolean
16.0.R1
All
Enable the flow-label context
configure filter ipv6-filter string entry number match flow-label
16.0.R1
All
Flow label mask for this policy IP filter entry
configure filter ipv6-filter string entry number match flow-label mask number
1 to 1048575
1048575
16.0.R1
All
Flow label as match criterion
configure filter ipv6-filter string entry number match flow-label value number
0 to 1048575
This element is mandatory.
16.0.R1
All
Match criterion for fragmented packages
false, true, first-only, non-first-only
16.0.R1
All
Enter the icmp context
16.0.R1
All
ICMPv6 code value to match
0 to 255
16.0.R1
All
ICMPv6 type value to match
0 to 255
16.0.R1
All
IP protocol to match
configure filter ipv6-filter string entry number match next-header (number | keyword)
0 to 255
tcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp
The following are part of a choice: next-header or next-header-list.
16.0.R1
All
Name of the protocol list as a match criterion
configure filter ipv6-filter string entry number match next-header-list reference
configure filter match-list protocol-list string
The following are part of a choice: next-header or next-header-list.
20.7.R1
All
Enable the packet-length context
configure filter ipv6-filter string entry number match packet-length
19.5.R1
All
Exact match criterion for the length
configure filter ipv6-filter string entry number match packet-length eq number
40 to 65575
The following are part of a mandatory choice: eq, gt, lt, or range.
19.5.R1
All
Greater than match criterion for the length
configure filter ipv6-filter string entry number match packet-length gt number
min to 65574
The following are part of a mandatory choice: eq, gt, lt, or range.
19.5.R1
All
Less than match criterion for the length
configure filter ipv6-filter string entry number match packet-length lt number
41 to max
The following are part of a mandatory choice: eq, gt, lt, or range.
19.5.R1
All
Enable the range context
configure filter ipv6-filter string entry number match packet-length range
The following are part of a mandatory choice: eq, gt, lt, or range.
19.5.R1
All
Upper bound of packet length range as match criterion
configure filter ipv6-filter string entry number match packet-length range end number
41 to max
This element is mandatory.
19.5.R1
All
Lower bound of packet length range as match criterion
configure filter ipv6-filter string entry number match packet-length range start number
min to 65574
This element is mandatory.
19.5.R1
All
Enter the port context
The following are part of a choice: port or (dst-port and src-port).
16.0.R1
All
Exact match criterion for the port number
0 to 65535
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Greater than match criterion for the port number
0 to 65534
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Less than match criterion for the port number
1 to 65535
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Name of the port list as the match criterion
configure filter match-list port-list string
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Enable the range context
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Upper bound of the port range as port match criterion
1 to 65535
This element is mandatory.
16.0.R1
All
Lower bound of the port range as port match criterion
0 to 65534
This element is mandatory.
16.0.R1
All
Enter the src-ip context
16.0.R1
All
IP address as the match criterion
The following are part of a choice: (address and mask) or ipv6-prefix-list.
16.0.R1
All
IPv6 prefix list as match criterion for IP address
configure filter ipv6-filter string entry number match src-ip ipv6-prefix-list reference
The following are part of a choice: (address and mask) or ipv6-prefix-list.
16.0.R1
All
IPv6 address mask as the match criterion
The following are part of a choice: (address and mask) or ipv6-prefix-list.
16.0.R1
All
Enable the src-mac context
19.5.R1
All
MAC address used as the match criterion
This element is mandatory.
19.5.R1
All
MAC address mask as the match criterion
ff:ff:ff:ff:ff:ff
19.5.R1
All
Enter the src-port context
The following are part of a choice: port or (dst-port and src-port).
16.0.R1
All
Exact match criterion for the port number
0 to 65535
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Greater than match criterion for the port number
0 to 65534
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Less than match criterion for the port number
1 to 65535
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Name of the port list as the match criterion
configure filter match-list port-list string
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Enable the range context
The following are part of a choice: eq, gt, lt, port-list, or range.
16.0.R1
All
Upper bound of the port range as port match criterion
1 to 65535
This element is mandatory.
16.0.R1
All
Lower bound of the port range as port match criterion
0 to 65534
This element is mandatory.
16.0.R1
All
Enter the tcp-flags context
16.0.R1
All
Match TCP ACK as per value of the ACK TCP flag bit
16.0.R1
All
Match TCP CWR as per value of the CWR TCP flag bit
16.0.R1
All
Match TCP ECE as per value of the ECE TCP flag bit
16.0.R1
All
Match TCP FIN as per value of the FIN TCP flag bit
16.0.R1
All
Match TCP NS as per value of the NS TCP flag bit
16.0.R1
All
Match TCP PSH as per value of the PSH TCP flag bit
16.0.R1
All
Match TCP RST as per value of the RST TCP flag bit
16.0.R1
All
Match TCP SYN as per value of the SYN TCP flag bit
16.0.R1
All
Match TCP URG as per value of the URG TCP flag bit
16.0.R1
All
Action when PBR or PBF target for this entry is not available
configure filter ipv6-filter string entry number pbr-down-action-override keyword
drop, forward, filter-default-action
16.0.R1
All
Cflowd sample profile ID for matching packets
configure filter ipv6-filter string entry number sample-profile reference
This command allows traffic matching an IPv4 or IPv6 filter to be sampled for cflowd processing using a specific sample-profile sample-profile-id. This option is only compatible if the associated interface is configured for interface-based
sampling and in only supported for ingress sampling. An IP filter can only specify a single alternate sample-profile for cflowd sampling, but that sample-profile can be used in multiple entries.
configure cflowd sample-profile number
20.10.R1
All
Time before action with available PBR or PBF destination and highest priority
configure filter ipv6-filter string entry number sticky-dest (number | keyword)
0 to 65535
seconds
no-hold-time-up
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
IPv6 filter identifier
configure filter ipv6-filter string filter-id number
1 to 65535
16.0.R1
All
Scope of this filter definition
configure filter ipv6-filter string scope keyword
template
exclusive, template, embedded, system
16.0.R1
All
Enter the subscriber-mgmt context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Enter the host-specific-entry context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Enter the credit-control context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Enable the range context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Upper bound of range for entries from Credit Control
configure filter ipv6-filter string subscriber-mgmt host-specific-entry credit-control range end number
1 to 2097151
This element is mandatory.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Lower bound of range for entries from Credit Control
configure filter ipv6-filter string subscriber-mgmt host-specific-entry credit-control range start number
1 to 2097151
This element is mandatory.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Enter the filter-rule context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Enable the range context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Upper bound of range for filter-rule entries from RADIUS/Diameter
configure filter ipv6-filter string subscriber-mgmt host-specific-entry filter-rule range end number
1 to 2097151
This element is mandatory.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Lower bound of range for subscriber host filter-rule entries from RADIUS/Diameter
configure filter ipv6-filter string subscriber-mgmt host-specific-entry filter-rule range start number
1 to 2097151
This element is mandatory.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Enter the watermark context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
High watermark for host-specific entries, to raise a table full alarm
configure filter ipv6-filter string subscriber-mgmt host-specific-entry watermark high number
0 to 100
95
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Low watermark for host-specific entries, to clear a table full alarm
configure filter ipv6-filter string subscriber-mgmt host-specific-entry watermark low number
0 to 100
90
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Enter the shared-entry context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Enter the filter-rule context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Enable the range context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Upper bound of range for shared-filter rules from RADIUS
configure filter ipv6-filter string subscriber-mgmt shared-entry filter-rule range end number
1 to 2097151
This element is mandatory.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Lower bound of range for shared filter-rules from RADIUS
configure filter ipv6-filter string subscriber-mgmt shared-entry filter-rule range start number
1 to 2097151
This element is mandatory.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Enter the pcc-rule context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Enable the range context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Upper bound of range for pcc-rule filter entries from Diameter
configure filter ipv6-filter string subscriber-mgmt shared-entry pcc-rule range end number
1 to 2097151
This element is mandatory.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Lower bound of range for pcc-rule filter entries from Diameter
configure filter ipv6-filter string subscriber-mgmt shared-entry pcc-rule range start number
1 to 2097151
This element is mandatory.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Enable the watermark context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Limit of RADIUS shared filters before generating high watermark notification
configure filter ipv6-filter string subscriber-mgmt shared-entry watermark high number
1 to 8000
This element is mandatory.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Limit of RADIUS or Diameter shared filters before clearing high watermark notification
configure filter ipv6-filter string subscriber-mgmt shared-entry watermark low number
0 to 7999
This element is mandatory.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
Set of match criteria for the filter policy
configure filter ipv6-filter string type keyword
normal
normal, src-mac, packet-length, destination-class
19.5.R1
All
Filter log identifier
101 to 199
This element is part of a list key.
16.0.R1
All
Administrative state of filter logging
configure filter log number admin-state keyword
enable
enable, disable
16.0.R1
All
Text description
configure filter log number description string
0 to 80
16.0.R1
All
Enter the destination context
configure filter log number destination
16.0.R1
All
Enter the memory context
configure filter log number destination memory
This element is the default part of a choice.
The following are part of a choice: memory or syslog.
16.0.R1
All
Maximum number of memory entries that the log can store
configure filter log number destination memory max-entries number
1 to 50000
1000
16.0.R1
All
Stop logging when maximum number of memory entries is reached or wrap-around is used
configure filter log number destination memory stop-on-full boolean
false
16.0.R1
All
Enter the syslog context
configure filter log number destination syslog
The following are part of a choice: memory or syslog.
16.0.R1
All
Specifies the syslog Id to be used as destination.
21.2.R1
All
Enter the summary context
16.0.R1
All
Administrative state of the summarization of filter log entries
configure filter log number destination syslog summary admin-state keyword
disable
enable, disable
16.0.R1
All
Summary for filter log entries
configure filter log number destination syslog summary summary-crit keyword
src-addr
src-addr, dst-addr
16.0.R1
All
Enter the mac-filter list instance
configure filter mac-filter string
16.0.R1
All
Filter name
configure filter mac-filter string
1 to 64
This element is part of a list key.
16.0.R1
All
Action for packets that do not match any entry
configure filter mac-filter string default-action keyword
drop
drop, accept
16.0.R1
All
Text description
configure filter mac-filter string description string
1 to 80
16.0.R1
All
Enter the embed context
configure filter mac-filter string embed
Commands in this context embed a previously defined MAC embedded filter policy or Hybrid OpenFlow switch instance into an exclusive, template, or system filter policy at the specified offset value. Rules derived from the BGP FlowSpec can also be embedded into template filter policies only.
For MAC filters, embedding is supported for VSD filters or filter entries only.
16.0.R1
All
Enter the entry list instance
configure filter mac-filter string entry number
16.0.R1
All
ID for a match criteria and the corresponding action
configure filter mac-filter string entry number
1 to 2097151
This element is part of a list key.
16.0.R1
All
Enable the action context
configure filter mac-filter string entry number action
16.0.R1
All
Accept regular routing to forward a packet that matches this entry
The following are part of a mandatory choice: accept, drop, forward, http-redirect, or ignore-match.
16.0.R1
All
Drop a packet matching this entry
The following are part of a mandatory choice: accept, drop, forward, http-redirect, or ignore-match.
16.0.R1
All
Enter the forward context
The following are part of a mandatory choice: accept, drop, forward, http-redirect, or ignore-match.
16.0.R1
All
Enable the esi-l2 context
The following are part of a choice: esi-l2, sap, or sdp.
16.0.R1
All
ESI of the first ESI-identified appliance
This element is mandatory.
16.0.R1
All
VPLS service name
This element is mandatory.
16.0.R3
All
Enable the sap context
The following are part of a choice: esi-l2, sap, or sdp.
16.0.R1
All
VPLS Ethernet SAP ID used to forward matching packets
This element is mandatory.
16.0.R1
All
VPLS associated with the SAP
This element is mandatory.
16.0.R1
All
Enable the sdp context
The following are part of a choice: esi-l2, sap, or sdp.
16.0.R1
All
VPLS SDP bind ID used to forward matching packets
configure filter mac-filter string entry number action forward sdp sdp-bind-id string
3 to 16
This element is mandatory.
16.0.R1
All
VPLS associated with the SDP
This element is mandatory.
16.0.R1
All
Enable the http-redirect context
configure filter mac-filter string entry number action http-redirect
The following are part of a mandatory choice: accept, drop, forward, http-redirect, or ignore-match.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
URL that is used for redirecting
configure filter mac-filter string entry number action http-redirect url string
1 to 255
This element is mandatory.
16.0.R1
All
Ignore match criteria for the entry
configure filter mac-filter string entry number action ignore-match
The following are part of a mandatory choice: accept, drop, forward, http-redirect, or ignore-match.
16.0.R1
All
Enable the rate-limit context
configure filter mac-filter string entry number action rate-limit
16.0.R1
All
Peak information rate
configure filter mac-filter string entry number action rate-limit pir (number | keyword)
0 to 2000000000
kilobps
max
This element is mandatory.
16.0.R1
All
Enable the secondary context
16.0.R1
All
Enter the forward context
This element is mandatory.
16.0.R1
All
Enable the sap context
The following are part of a choice: sap or sdp.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
A packet matching the entry will be forwarded using the specified SAP
This element is mandatory.
16.0.R1
All
VPLS the sdp-bind-id belongs to
This element is mandatory.
16.0.R1
All
Enable the sdp context
The following are part of a choice: sap or sdp.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
VPLS SDP bind ID used to forward matching packets
configure filter mac-filter string entry number action secondary forward sdp sdp-bind-id string
3 to 16
This element is mandatory.
16.0.R1
All
VPLS associated with the SDP
This element is mandatory.
16.0.R1
All
Text description
configure filter mac-filter string entry number description string
1 to 80
16.0.R1
All
Log that is used for packets matching this entry
configure filter mac-filter string entry number log reference
16.0.R1
All
Enter the match context
configure filter mac-filter string entry number match
16.0.R1
All
Enable the dot1p context
16.0.R1
All
802.1p mask value used as a MAC filter match criterion
1 to 7
7
16.0.R1
All
IEEE 802.1p value used as a MAC filter match criterion
0 to 7
This element is mandatory.
16.0.R1
All
Enable the dst-mac context
16.0.R1
All
MAC address used as the match criterion
This element is mandatory.
16.0.R1
All
MAC address mask as the match criterion
ff:ff:ff:ff:ff:ff
16.0.R1
All
Ethernet type
5 to 6
16.0.R1
All
MAC frame as match criteria
configure filter mac-filter string entry number match frame-type keyword
802dot3, 802dot2-llc, 802dot2-snap, ethernet-ii
16.0.R1
All
Enable the inner-tag context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
Mask to VID of the inner VLAN tag before comparing it with the inner-tag or outer-tag value
1 to 4095
4095
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
Matching value against VID of the second or first VLAN tag in the packet carried transparently
0 to 4095
This element is mandatory.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
Enter the isid context
16.0.R1
All
Enable the range context
The following are part of a choice: range or value.
16.0.R1
All
Highest value of 24-bit service instance identifier for the service matching this entry
0 to 16777215
This element is mandatory.
16.0.R1
All
Lowest value of 24-bit service instance identifier for the service matching this entry
0 to 16777215
This element is mandatory.
16.0.R1
All
Lowest value of 24-bit service instance identifier for the service matching this entry
0 to 16777215
The following are part of a choice: range or value.
16.0.R1
All
Enable the llc-dsap context
16.0.R1
All
DSAP value
0 to 255
This element is mandatory.
16.0.R1
All
Destination SAP mask
1 to 255
255
16.0.R1
All
Enable the llc-ssap context
16.0.R1
All
Source SAP mask
1 to 255
255
16.0.R1
All
Source or destination SAP value
0 to 255
This element is mandatory.
16.0.R1
All
Enable the outer-tag context
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
Mask to VID of the inner VLAN tag before comparing it with the inner-tag or outer-tag value
1 to 4095
4095
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
Matching value against VID of the second or first VLAN tag in the packet carried transparently
0 to 4095
This element is mandatory.
16.0.R1
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
Parameter snap-oui as a MAC filter match criteria
zero, non-zero
16.0.R1
All
Parameter snap-pid as a MAC filter match criteria
0 to 65535
16.0.R1
All
Enable the src-mac context
16.0.R1
All
MAC address used as the match criterion
This element is mandatory.
16.0.R1
All
MAC address mask as the match criterion
ff:ff:ff:ff:ff:ff
16.0.R1
All
Action when PBR or PBF target for this entry is not available
configure filter mac-filter string entry number pbr-down-action-override keyword
drop, forward, filter-default-action
16.0.R1
All
Time before action with available PBR or PBF destination and highest priority
configure filter mac-filter string entry number sticky-dest (number | keyword)
0 to 65535
seconds
no-hold-time-up
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
MAC filter ID
configure filter mac-filter string filter-id number
1 to 65535
16.0.R1
All
Scope of this filter definition
configure filter mac-filter string scope keyword
template
exclusive, template, embedded, system
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
MAC filter policy
configure filter mac-filter string type keyword
normal
normal, isid, vid
16.0.R1
All
Enter the match-list context
16.0.R1
All
Enter the ip-prefix-list list instance
configure filter match-list ip-prefix-list string
16.0.R1
All
Prefix list name that is used for this prefix list
configure filter match-list ip-prefix-list string
1 to 32
This element is part of a list key.
16.0.R1
All
Enter the apply-path context
16.0.R1
All
Enter the bgp-peers list instance
configure filter match-list ip-prefix-list string apply-path bgp-peers number
16.0.R1
All
Value of the enumerating BGP peers autogeneration configuration within list
configure filter match-list ip-prefix-list string apply-path bgp-peers number
1 to 255
This element is part of a list key.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Regular expression to match against the base router BGP instance group configuration
configure filter match-list ip-prefix-list string apply-path bgp-peers number group string
1 to 255
This element is mandatory.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Regular expression to match against the base router BGP instance neighbor configuration
configure filter match-list ip-prefix-list string apply-path bgp-peers number neighbor string
1 to 255
This element is mandatory.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Target routing instance
configure filter match-list ip-prefix-list string apply-path bgp-peers number router-instance string
Base
16.0.R1
All
Text description
configure filter match-list ip-prefix-list string description string
1 to 80
16.0.R1
All
Add a list entry for prefix
configure filter match-list ip-prefix-list string prefix string
8192
16.0.R1
All
IPv4 prefix to be added to the prefix list
configure filter match-list ip-prefix-list string prefix string
This element is part of a list key.
16.0.R3
All
Add a list entry for prefix-exclude
configure filter match-list ip-prefix-list string prefix-exclude string
512
16.0.R4
All
IPv4 prefix to be added to the prefix list
configure filter match-list ip-prefix-list string prefix-exclude string
This element is part of a list key.
16.0.R4
All
Enter the ipv6-prefix-list list instance
16.0.R1
All
Prefix list name that is used for this prefix list
1 to 32
This element is part of a list key.
16.0.R1
All
Enter the apply-path context
16.0.R1
All
Enter the bgp-peers list instance
configure filter match-list ipv6-prefix-list string apply-path bgp-peers number
16.0.R1
All
Value of the enumerating BGP peers autogeneration configuration within list
configure filter match-list ipv6-prefix-list string apply-path bgp-peers number
1 to 255
This element is part of a list key.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Regular expression to match against the base router BGP instance group configuration
configure filter match-list ipv6-prefix-list string apply-path bgp-peers number group string
1 to 255
This element is mandatory.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Regular expression to match against the base router BGP instance neighbor configuration
configure filter match-list ipv6-prefix-list string apply-path bgp-peers number neighbor string
1 to 255
This element is mandatory.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Target routing instance
configure filter match-list ipv6-prefix-list string apply-path bgp-peers number router-instance string
Base
16.0.R1
All
Text description
configure filter match-list ipv6-prefix-list string description string
1 to 80
16.0.R1
All
Add a list entry for prefix
configure filter match-list ipv6-prefix-list string prefix string
8192
16.0.R1
All
Add IPv6 prefix to the list.
configure filter match-list ipv6-prefix-list string prefix string
This element is part of a list key.
16.0.R3
All
Add a list entry for prefix-exclude
configure filter match-list ipv6-prefix-list string prefix-exclude string
512
16.0.R4
All
Add IPv6 prefix to the list.
configure filter match-list ipv6-prefix-list string prefix-exclude string
This element is part of a list key.
16.0.R4
All
Enter the port-list list instance
configure filter match-list port-list string
1024
16.0.R1
All
Port list name
configure filter match-list port-list string
1 to 32
This element is part of a list key.
16.0.R1
All
Text description
configure filter match-list port-list string description string
1 to 80
16.0.R1
All
Add a list entry for port
configure filter match-list port-list string port number
16.0.R1
All
Port value
configure filter match-list port-list string port number
0 to 65535
This element is part of a list key.
16.0.R1
All
Add a list entry for range
16.0.R1
All
Highest value for TCP/UDP port range
0 to 65534
This element is part of a list key.
16.0.R1
All
Highest value for TCP/UDP port range
1 to 65535
This element is part of a list key.
16.0.R1
All
Enter the protocol-list list instance
configure filter match-list protocol-list string
512
20.7.R1
All
Protocol list name
configure filter match-list protocol-list string
1 to 32
This element is part of a list key.
20.7.R1
All
Text description
configure filter match-list protocol-list string description string
1 to 80
20.7.R1
All
Add a list entry for protocol
configure filter match-list protocol-list string protocol (number | keyword)
32
20.7.R1
All
IP protocol identifier
configure filter match-list protocol-list string protocol (number | keyword)
0 to 255
icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp
This element is part of a list key.
20.7.R1
All
Enter the md-auto-id context
16.0.R1
All
Enable the filter-id-range context
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Upper value of the ID range, must be greater than or equal to start value
configure filter md-auto-id filter-id-range end number
1 to 65535
This element is mandatory.
16.0.R1
All
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Lower value of the ID range, must be less than or equal to end value
1 to 65535
This element is mandatory.
16.0.R1
All
Enter the redirect-policy list instance
configure filter redirect-policy string
16.0.R1
All
Redirect policy name
configure filter redirect-policy string
1 to 32
This element is part of a list key.
16.0.R1
All
Administrative state of the policy
configure filter redirect-policy string admin-state keyword
disable
enable, disable
16.0.R1
All
Text description
configure filter redirect-policy string description string
1 to 80
16.0.R1
All
Enter the destination list instance
configure filter redirect-policy string destination (ipv4-address-no-zone | ipv6-address-no-zone)
16.0.R1
All
IP address and type of destination
configure filter redirect-policy string destination (ipv4-address-no-zone | ipv6-address-no-zone)
This element is part of a list key.
16.0.R1
All
Administrative state of the destination
configure filter redirect-policy string destination (ipv4-address-no-zone | ipv6-address-no-zone) admin-state keyword
disable
enable, disable
16.0.R1
All
Text description
configure filter redirect-policy string destination (ipv4-address-no-zone | ipv6-address-no-zone) description string
1 to 80
16.0.R1
All
Enable the ping-test context
configure filter redirect-policy string destination (ipv4-address-no-zone | ipv6-address-no-zone) ping-test
16.0.R1
All
Number of consecutive requests that fail before destination is declared unreachable
configure filter redirect-policy string destination (ipv4-address-no-zone | ipv6-address-no-zone) ping-test drop-count number
1 to 60
3
16.0.R1
All
Time for the system to be held down if this test has marked it unreachable
configure filter redirect-policy string destination (ipv4-address-no-zone | ipv6-address-no-zone) ping-test hold-down number
0 to 86400
0
seconds
16.0.R1
All
Time between consecutive requests which are sent to the far end host
configure filter redirect-policy string destination (ipv4-address-no-zone | ipv6-address-no-zone) ping-test interval number
1 to 60
1
seconds
16.0.R1
All
Source address to use in the IP packet of the ping test
configure filter redirect-policy string destination (ipv4-address-no-zone | ipv6-address-no-zone) ping-test source-address (ipv4-address-no-zone | ipv6-address-no-zone)
16.0.R4
All
Time required to receive a response from the far end host
configure filter redirect-policy string destination (ipv4-address-no-zone | ipv6-address-no-zone) ping-test timeout number
1 to 60
1
seconds
16.0.R1
All
Priority for this destination
configure filter redirect-policy string destination (ipv4-address-no-zone | ipv6-address-no-zone) priority number
1 to 255
100
16.0.R1
All
Enable the unicast-rt-test context
configure filter redirect-policy string destination (ipv4-address-no-zone | ipv6-address-no-zone) unicast-rt-test
16.0.R1
All
The value of the object indicates whether to send tFilterRPActiveDestChangeEvent notification for this redirect policy active destination changes.
configure filter redirect-policy string notify-dest-change boolean
false
16.0.R4
All
Routing context to use for route lookup
configure filter redirect-policy string router-instance string
16.0.R1
All
Time required by system before applying the current best destination as active destination
configure filter redirect-policy string sticky-dest (number | keyword)
0 to 65535
seconds
no-hold-time-up
16.0.R1
All
Enter the redirect-policy-binding list instance
16
16.0.R4
All
Binding name
1 to 32
This element is part of a list key.
16.0.R4
All
The value of the this object indicates the logical operator to use when combining result of different destinations' tests.
configure filter redirect-policy-binding string binding-operator keyword
and
and, or
16.0.R4
All
Enter the redirect-policy list instance
configure filter redirect-policy-binding string redirect-policy reference
16.0.R4
All
The redirect-policy identifier.
configure filter redirect-policy-binding string redirect-policy reference
configure filter redirect-policy string
This element is part of a list key.
16.0.R4
All
Add a list entry for destination
configure filter redirect-policy-binding string redirect-policy reference destination reference
1
16.0.R4
All
IP address of redirect policy destination to binding
configure filter redirect-policy-binding string redirect-policy reference destination reference
configure filter redirect-policy string destination (ipv4-address-no-zone | ipv6-address-no-zone)
This element is part of a list key.
16.0.R4
All
Enter the system-filter context
16.0.R1
All
Add a list entry for ip
configure filter system-filter ip reference
1
16.0.R1
All
The name of the IPv4 filter policy to be selected as the active system filter policy
configure filter system-filter ip reference
This element is part of a list key.
16.0.R3
All
Add a list entry for ipv6
configure filter system-filter ipv6 reference
1
16.0.R1
All
The name of the IPv6 filter policy to be selected as the active system filter policy
configure filter system-filter ipv6 reference
configure filter ipv6-filter string
This element is part of a list key.
16.0.R3
All