50. system Commands

configure
system
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
clear-message string
description string
normal-state keyword
trigger-message string
alarms
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
max-cleared number
— apply-groups reference
— apply-groups-exclude reference
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
device string
— apply-groups reference
— apply-groups-exclude reference
description string
module string
— apply-groups reference
— apply-groups-exclude reference
pairing-button boolean
passkey string
power-mode keyword
boot-bad-exec string
boot-good-exec string
— apply-groups reference
— apply-groups-exclude reference
bits
input
admin-state keyword
interface-type keyword
output
admin-state keyword
line-length keyword
ql-minimum keyword
source keyword
squelch boolean
ql-override keyword
ssm-bit number
ptp
admin-state keyword
ql-minimum keyword
ql-selection boolean
fifth keyword
first keyword
fourth keyword
second keyword
third keyword
ref1
admin-state keyword
ql-override keyword
source-port string
ref2
admin-state keyword
ql-override keyword
source-port string
revert boolean
synce
admin-state keyword
ql-override keyword
wait-to-restore number
clli-code string
contact string
coordinates string
— apply-groups reference
— apply-groups-exclude reference
optimized-mode boolean
cron
— apply-groups reference
— apply-groups-exclude reference
schedule string owner string
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
count number
day-of-month number
description string
date-and-time string
day keyword
time string
hour number
interval number
minute number
month (keyword | number)
name string
owner string
type keyword
weekday (keyword | number)
dhcp6
adv-noaddrs-global keyword
— apply-groups reference
— apply-groups-exclude reference
dns
address-pref keyword
— apply-groups reference
— apply-groups-exclude reference
dnssec
ad-validation keyword
efm-oam
— apply-groups reference
— apply-groups-exclude reference
grace-tx boolean
eth-cfm
— apply-groups reference
— apply-groups-exclude reference
grace boolean
— apply-groups reference
— apply-groups-exclude reference
end number
start number
— apply-groups reference
— apply-groups-exclude reference
end number
start number
— apply-groups reference
— apply-groups-exclude reference
mc-lag
propagate-hold-time (number | keyword)
standby-mep boolean
local-name string
type keyword
slm
— apply-groups reference
— apply-groups-exclude reference
inactivity-timer number
grpc
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
gnmi
admin-state keyword
auto-config-save boolean
gnoi
admin-state keyword
file
admin-state keyword
system
admin-state keyword
max-msg-size number
md-cli
admin-state keyword
rib-api
admin-state keyword
purge-timeout number
admin-state keyword
idle-time number
interval number
retries number
tls-server-profile reference
icmp-vse boolean
ip
— apply-groups reference
— apply-groups-exclude reference
forward-6in4 boolean
forward-ip-over-gre boolean
ipv6-eh keyword
mpls
l2tp
— apply-groups reference
— apply-groups-exclude reference
end number
start number
lacp
— apply-groups reference
— apply-groups-exclude reference
system-priority number
lldp
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
message-fast-tx number
reinit-delay number
tx-credit-max number
tx-hold-multiplier number
tx-interval number
— apply-groups reference
— apply-groups-exclude reference
l2tp-load-balancing boolean
l4-load-balancing boolean
lsr-load-balancing keyword
location string
— apply-groups reference
— apply-groups-exclude reference
exponential-backoff boolean
ftp
idle-timeout (keyword | number)
login-banner boolean
global-script string
file-name string
user-directory string
motd
text string
url string
message string
name boolean
ssh
graceful-shutdown boolean
ttl-security number
telnet
graceful-shutdown boolean
ttl-security number
— apply-groups reference
— apply-groups-exclude reference
cli
— apply-groups reference
— apply-groups-exclude reference
allow-immediate boolean
— apply-groups reference
— apply-groups-exclude reference
local-checkpoints number
location string
remote-checkpoints number
rescue
location string
cli-engine keyword
md-cli
— apply-groups reference
— apply-groups-exclude reference
auto-config-save boolean
enter boolean
space boolean
tab boolean
console
length number
width number
cli keyword
more boolean
admin-state keyword
delay number
type keyword
prompt
context boolean
newline boolean
timestamp boolean
time-display keyword
time-format keyword
configuration-mode keyword
— apply-groups reference
— apply-groups-exclude reference
netconf
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
auto-config-save boolean
candidate boolean
writable-running boolean
port number
— apply-groups reference
— apply-groups-exclude reference
asynchronous-execution (number | keyword)
asynchronous-retention (number | keyword)
synchronous-execution (number | keyword)
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
client-tls-profile reference
connection-timeout number
device-label string
device-name string
hello-interval number
manager string
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
client-tls-profile reference
connection-timeout number
description string
device-label string
device-name string
manager-address (ipv4-address-no-zone | ipv6-address-no-zone | fully-qualified-domain-name)
manager-port number
router-instance string
source-address (ipv4-address-no-zone | ipv6-address-no-zone)
source-port (number | keyword)
router-instance string
source-address (ipv4-address-no-zone | ipv6-address-no-zone)
source-port (number | keyword)
schema-path string
snmp
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
engine-id string
general-port number
packet-size number
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
— apply-groups reference
— apply-groups-exclude reference
base-r13-modules boolean
nokia-submodules boolean
openconfig-modules boolean
name string
— apply-groups reference
— apply-groups-exclude reference
generate-traps boolean
profile string
— apply-groups reference
— apply-groups-exclude reference
neid string
neip
— apply-groups reference
— apply-groups-exclude reference
ipv4
vendor-id-value number
ipv6
vendor-id-value number
ipv4 string
ipv6 string
platform-type string
system-mac string
vendor-id string
ancp
— apply-groups reference
— apply-groups-exclude reference
description string
location keyword
— apply-groups reference
— apply-groups-exclude reference
description string
location keyword
— apply-groups reference
— apply-groups-exclude reference
— apply-groups reference
— apply-groups-exclude reference
description string
location keyword
— apply-groups reference
— apply-groups-exclude reference
description string
location keyword
options
— apply-groups reference
— apply-groups-exclude reference
— apply-groups reference
— apply-groups-exclude reference
description string
location keyword
— apply-groups reference
— apply-groups-exclude reference
description string
location keyword
— apply-groups reference
— apply-groups-exclude reference
mode keyword
power-safety-alert number
power-safety-level number
— apply-groups reference
— apply-groups-exclude reference
script string owner string
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
description string
location string
script-policy string owner string
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
expire-time (number | keyword)
lifetime (number | keyword)
lock-override boolean
max-completed number
results string
script
name string
owner string
aaa
— apply-groups reference
— apply-groups-exclude reference
cli-session-group string
— apply-groups reference
— apply-groups-exclude reference
description string
ssh-max-sessions number
health-check (number | keyword)
— apply-groups reference
— apply-groups-exclude reference
profile string
— apply-groups reference
— apply-groups-exclude reference
cli-session-group reference
default-action keyword
entry number
action keyword
— apply-groups reference
— apply-groups-exclude reference
description string
match string
grpc
gnmi-capabilities keyword
gnmi-get keyword
gnmi-set keyword
gnmi-subscribe keyword
gnoi-file-get keyword
gnoi-file-put keyword
gnoi-file-remove keyword
gnoi-file-stat keyword
gnoi-system-reboot keyword
md-cli-session keyword
rib-api-getversion keyword
rib-api-modify keyword
li boolean
netconf
kill-session boolean
lock boolean
ssh-max-sessions number
— apply-groups reference
— apply-groups-exclude reference
md-cli
md-interfaces boolean
telemetry-data boolean
— apply-groups reference
— apply-groups-exclude reference
ldap
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
route-preference keyword
server number
address (ipv4-address-no-zone | ipv6-address-no-zone)
— apply-groups reference
— apply-groups-exclude reference
port number
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
password string
root-dn string
search
base-dn string
server-name string
tls-profile reference
server-retry number
server-timeout number
radius
access-algorithm keyword
accounting boolean
accounting-port number
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
authorization boolean
port number
route-preference keyword
server number
address (ipv4-address-no-zone | ipv6-address-no-zone)
— apply-groups reference
— apply-groups-exclude reference
secret string
server-retry number
server-timeout number
tacplus
record-type keyword
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
use-priv-lvl boolean
— apply-groups reference
— apply-groups-exclude reference
priv-lvl number
— apply-groups reference
— apply-groups-exclude reference
user-profile-name reference
route-preference keyword
server number
address (ipv4-address-no-zone | ipv6-address-no-zone)
— apply-groups reference
— apply-groups-exclude reference
port number
secret string
server-timeout number
user-template keyword
access
console boolean
ftp boolean
grpc boolean
li boolean
netconf boolean
— apply-groups reference
— apply-groups-exclude reference
console
login-exec string
home-directory (sat-url | cflash-without-slot-url)
profile string
restricted-to-home boolean
— apply-groups reference
— apply-groups-exclude reference
— apply-groups reference
— apply-groups-exclude reference
cron
cli-user reference
cli-user reference
vsd
cli-user reference
— apply-groups reference
— apply-groups-exclude reference
default-action keyword
admin-state keyword
entry number
action
accept
default
drop
queue reference
— apply-groups reference
— apply-groups-exclude reference
description string
log reference
match
dscp keyword
dst-ip
address (ipv4-address | ipv4-prefix-with-host-bits)
ip-prefix-list reference
mask string
eq number
mask number
port-list reference
range
end number
start number
fragment keyword
icmp
code number
type number
mask number
type number
multiple-option boolean
option-present boolean
port
eq number
mask number
port-list reference
range
end number
start number
protocol (number | keyword)
router-instance string
src-ip
address (ipv4-address | ipv4-prefix-with-host-bits)
ip-prefix-list reference
mask string
eq number
mask number
port-list reference
range
end number
start number
ack boolean
syn boolean
admin-state keyword
entry number
action
accept
default
drop
queue reference
— apply-groups reference
— apply-groups-exclude reference
description string
log reference
match
dscp keyword
dst-ip
address (ipv6-address | ipv6-prefix-with-host-bits)
ipv6-prefix-list reference
mask string
eq number
mask number
port-list reference
range
end number
start number
hop-by-hop boolean
flow-label number
fragment keyword
icmp
code number
type number
next-header (number | keyword)
port
eq number
mask number
port-list reference
range
end number
start number
router-instance string
src-ip
address (ipv6-address | ipv6-prefix-with-host-bits)
ipv6-prefix-list reference
mask string
eq number
mask number
port-list reference
range
end number
start number
ack boolean
syn boolean
admin-state keyword
entry number
action
accept
default
drop
queue reference
— apply-groups reference
— apply-groups-exclude reference
description string
log reference
match
eq number
gt number
lt number
range
end number
start number
dst-mac
address string
mask string
etype string
frame-type keyword
dsap number
mask number
mask number
ssap number
service reference
src-mac
address string
mask string
— apply-groups reference
— apply-groups-exclude reference
queue number
— apply-groups reference
— apply-groups-exclude reference
cbs number
mbs number
rate
cir (number | keyword)
pir (number | keyword)
— apply-groups reference
— apply-groups-exclude reference
dhcp boolean
gtp boolean
icmp boolean
igmp boolean
link-specific-rate (number | keyword)
policy number
alarm boolean
— apply-groups reference
— apply-groups-exclude reference
description string
eth-cfm
entry number
— apply-groups reference
— apply-groups-exclude reference
level start number end number
opcode start number end number
pir (number | keyword)
log-events boolean
pir (number | keyword)
overall-rate (number | keyword)
per-source-rate (number | keyword)
action-low-priority boolean
pir (number | keyword)
allow-sham-links boolean
block-pim-tunneled boolean
— apply-groups reference
— apply-groups-exclude reference
policy string
— apply-groups reference
— apply-groups-exclude reference
description string
— apply-groups reference
— apply-groups-exclude reference
description string
exceed-action keyword
log-events keyword
rate
kbps
limit (keyword | number)
mbs number
packets
initial-delay number
limit (keyword | number)
within number
protocol keyword
— apply-groups reference
— apply-groups-exclude reference
detection-time number
action keyword
hold-down (keyword | number)
log-events keyword
rate
kbps
limit (keyword | number)
mbs number
packets
initial-delay number
limit (keyword | number)
within number
dynamic
mon-policer-name reference
static
policer-name reference
static-policer string
— apply-groups reference
— apply-groups-exclude reference
description string
detection-time number
action keyword
hold-down (keyword | number)
log-events keyword
rate
kbps
limit (keyword | number)
mbs number
packets
initial-delay number
limit (keyword | number)
within number
type keyword
dot1x
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
radius-policy string
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
retry number
server number
accounting-port number
address string
— apply-groups reference
— apply-groups-exclude reference
secret string
type keyword
source-address string
timeout number
ftp-server boolean
— apply-groups reference
— apply-groups-exclude reference
read-algorithm keyword
write-algorithm keyword
grpc
hash-algorithm keyword
md-cli
hash-algorithm keyword
netconf
hash-algorithm keyword
keychain string
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
entry number
admin-state keyword
algorithm keyword
— apply-groups reference
— apply-groups-exclude reference
authentication-key string
begin-time string
option keyword
tolerance (number | keyword)
description string
receive
entry number
admin-state keyword
algorithm keyword
— apply-groups reference
— apply-groups-exclude reference
authentication-key string
begin-time string
end-time string
tolerance (number | keyword)
send
entry number
admin-state keyword
algorithm keyword
— apply-groups reference
— apply-groups-exclude reference
authentication-key string
begin-time string
receive keyword
send keyword
allow-ftp boolean
allow-grpc boolean
allow-netconf boolean
allow-ssh boolean
allow-telnet boolean
allow-telnet6 boolean
— apply-groups reference
— apply-groups-exclude reference
— apply-groups reference
— apply-groups-exclude reference
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
default-action keyword
entry number
action keyword
— apply-groups reference
— apply-groups-exclude reference
description string
log-events boolean
match
mask number
port number
cpm
lag string
port-id string
protocol (number | keyword)
router-instance string
src-ip
address (ipv4-prefix | ipv4-address)
ip-prefix-list reference
mask string
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
default-action keyword
entry number
action keyword
— apply-groups reference
— apply-groups-exclude reference
description string
log-events boolean
match
mask number
port number
flow-label number
cpm
lag string
port-id string
next-header (number | keyword)
router-instance string
src-ip
address (ipv6-prefix | ipv6-address)
ipv6-prefix-list reference
mask string
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
default-action keyword
entry number
action keyword
— apply-groups reference
— apply-groups-exclude reference
description string
log-events boolean
match
eq number
gt number
lt number
range
end number
start number
dot1p
mask number
priority number
dst-mac
address string
mask string
etype string
frame-type keyword
dsap number
mask number
mask number
ssap number
service string
snap-oui keyword
snap-pid number
src-mac
address string
mask string
per-peer-queuing boolean
pki
— apply-groups reference
— apply-groups-exclude reference
ca-profile string
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
url-entry number
— apply-groups reference
— apply-groups-exclude reference
transmission-profile reference
url http-url-path-loose
pre-update-time number
retry-interval number
schedule-type keyword
cert-file string
cmpv2
error-message boolean
pkiconf-message boolean
http
response-timeout number
version keyword
key string
— apply-groups reference
— apply-groups-exclude reference
password string
url
service-name string
url-string http-optional-url-loose
crl-file string
description string
ocsp
responder-url http-optional-url-loose
service-name string
transmission-profile reference
revocation-check keyword
hours number
repeat-hours number
common-name-list string
— apply-groups reference
— apply-groups-exclude reference
common-name number
— apply-groups reference
— apply-groups-exclude reference
cn-type keyword
cn-value string
hours number
repeat-hours number
imported-format keyword
snmp
access string context string security-model keyword security-level keyword
— apply-groups reference
— apply-groups-exclude reference
notify string
prefix-match keyword
read string
write string
— apply-groups reference
— apply-groups-exclude reference
— apply-groups reference
— apply-groups-exclude reference
count number
lockout number
time number
community string
access-permissions keyword
— apply-groups reference
— apply-groups-exclude reference
source-access-list reference
version keyword
source-access-list string
— apply-groups reference
— apply-groups-exclude reference
source-host string
address (ipv4-address-no-zone | ipv6-address-no-zone)
— apply-groups reference
— apply-groups-exclude reference
usm-community string
— apply-groups reference
— apply-groups-exclude reference
group string
source-access-list reference
view string subtree string
— apply-groups reference
— apply-groups-exclude reference
mask string
type keyword
ipv4 keyword
address string
— apply-groups reference
— apply-groups-exclude reference
interface-name string
ipv6 keyword
address string
— apply-groups reference
— apply-groups-exclude reference
ssh
— apply-groups reference
— apply-groups-exclude reference
— apply-groups reference
— apply-groups-exclude reference
cipher number
— apply-groups reference
— apply-groups-exclude reference
name keyword
— apply-groups reference
— apply-groups-exclude reference
cipher number
— apply-groups reference
— apply-groups-exclude reference
name keyword
kex number
— apply-groups reference
— apply-groups-exclude reference
name keyword
mac number
— apply-groups reference
— apply-groups-exclude reference
name keyword
client
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
mbytes (number | keyword)
minutes (number | keyword)
server
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
mbytes (number | keyword)
minutes (number | keyword)
preserve-key boolean
server-admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
cipher number
— apply-groups reference
— apply-groups-exclude reference
name keyword
— apply-groups reference
— apply-groups-exclude reference
cipher number
— apply-groups reference
— apply-groups-exclude reference
name keyword
kex number
— apply-groups reference
— apply-groups-exclude reference
name keyword
mac number
— apply-groups reference
— apply-groups-exclude reference
name keyword
version keyword
admin-password string
— apply-groups reference
— apply-groups-exclude reference
vsd-password string
— apply-groups reference
— apply-groups-exclude reference
ts-location (ts-sat-url | cflash-url | string)
telnet-server boolean
telnet6-server boolean
tls
— apply-groups reference
— apply-groups-exclude reference
cert-profile string
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
entry number
— apply-groups reference
— apply-groups-exclude reference
certificate-file string
key-file string
ca-profile reference
client-cipher-list string
— apply-groups reference
— apply-groups-exclude reference
cipher number
— apply-groups reference
— apply-groups-exclude reference
name keyword
client-tls-profile string
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
cert-profile reference
cipher-list reference
trust-anchor-profile reference
server-cipher-list string
— apply-groups reference
— apply-groups-exclude reference
cipher number
— apply-groups reference
— apply-groups-exclude reference
name keyword
server-tls-profile string
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
common-name-list reference
trust-anchor-profile reference
cert-profile reference
cipher-list reference
— apply-groups reference
— apply-groups-exclude reference
trust-anchor reference
— apply-groups reference
— apply-groups-exclude reference
count number
lockout number
time number
exit-on-reject boolean
order keyword
aging number
— apply-groups reference
— apply-groups-exclude reference
allow-user-name boolean
credits
lowercase number
numeric number
special-character number
uppercase number
minimum-classes number
minimum-length number
lowercase number
numeric number
special-character number
uppercase number
hashing keyword
history-size number
minimum-age number
minimum-change number
user string
access
console boolean
ftp boolean
grpc boolean
li boolean
netconf boolean
snmp boolean
— apply-groups reference
— apply-groups-exclude reference
cli-engine keyword
console
login-exec (sat-url | cflash-url | ftp-tftp-url | filename)
member reference
home-directory (sat-url | cflash-without-slot-url)
password string
ecdsa
ecdsa-key number
— apply-groups reference
— apply-groups-exclude reference
description string
key-value string
rsa
rsa-key number
— apply-groups reference
— apply-groups-exclude reference
description string
key-value string
restricted-to-home boolean
snmp
— apply-groups reference
— apply-groups-exclude reference
authentication-key string
privacy
privacy-key string
privacy-protocol keyword
group string
count number
window number
selective-fib boolean
— apply-groups reference
— apply-groups-exclude reference
description string
primary-location string
secondary-location string
tertiary-location string
— apply-groups reference
— apply-groups-exclude reference
admin-state keyword
sfm-loss-threshold number
— apply-groups reference
— apply-groups-exclude reference
destination-group string
— apply-groups reference
— apply-groups-exclude reference
description string
destination (ipv4-address-no-zone | ipv6-address-no-zone | fully-qualified-domain-name) port number
— apply-groups reference
— apply-groups-exclude reference
router-instance string
admin-state keyword
idle-time number
interval number
retries number
tls-client-profile reference
subscription string
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
description string
destination-group reference
encoding keyword
local-source-address (ipv4-address-no-zone | ipv6-address-no-zone)
mode keyword
sample-interval number
sensor-group reference
sensor-group string
— apply-groups reference
— apply-groups-exclude reference
description string
path string
— apply-groups reference
— apply-groups-exclude reference
falling-threshold number
interval number
rising-threshold number
rmon-event-type keyword
startup-alarm keyword
— apply-groups reference
— apply-groups-exclude reference
falling-threshold number
interval number
rising-threshold number
rmon-event-type keyword
startup-alarm keyword
— apply-groups reference
— apply-groups-exclude reference
falling-threshold number
interval number
rising-threshold number
rmon-event-type keyword
startup-alarm keyword
— apply-groups reference
— apply-groups-exclude reference
falling-threshold number
interval number
rising-threshold number
rmon-event-type keyword
startup-alarm keyword
rmon
alarm number
— apply-groups reference
— apply-groups-exclude reference
falling-event number
falling-threshold number
interval number
owner string
rising-event number
rising-threshold number
sample-type keyword
startup-alarm keyword
variable-oid string
event number
— apply-groups reference
— apply-groups-exclude reference
description string
event-type keyword
owner string
time
— apply-groups reference
— apply-groups-exclude reference
dst-zone string
— apply-groups reference
— apply-groups-exclude reference
end
day keyword
hours-minutes string
month keyword
week keyword
offset number
start
day keyword
hours-minutes string
month keyword
week keyword
ntp
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
authentication-key number
— apply-groups reference
— apply-groups-exclude reference
key string
type keyword
broadcast reference interface-name string
— apply-groups reference
— apply-groups-exclude reference
key-id reference
ttl number
version number
broadcast-client string interface-name string
— apply-groups reference
— apply-groups-exclude reference
authenticate boolean
— apply-groups reference
— apply-groups-exclude reference
key-id reference
version number
— apply-groups reference
— apply-groups-exclude reference
authenticate boolean
authenticate boolean
peer (ipv4-address-no-zone | ipv6-address-no-zone) router-instance string
— apply-groups reference
— apply-groups-exclude reference
key-id reference
prefer boolean
version number
server (ipv4-address-no-zone | ipv6-address-no-zone | keyword) router-instance string
— apply-groups reference
— apply-groups-exclude reference
key-id reference
prefer boolean
version number
prefer-local-time boolean
sntp
admin-state keyword
— apply-groups reference
— apply-groups-exclude reference
server (ipv4-address-no-zone | ipv6-address-no-zone)
— apply-groups reference
— apply-groups-exclude reference
interval number
prefer boolean
version number
sntp-state keyword
zone
name string
offset string
name keyword
— apply-groups reference
— apply-groups-exclude reference
redirection number
retry number
router-instance string
timeout number

50.1. system Command Descriptions

system

Synopsis

Enter the system context

Context
Tree
Description

Commands in this context enable debugging of general system level functions and router management protocols.

Introduced

16.0.R1

Platforms

All

alarm-contact-in-power boolean

Synopsis

Power the output pin on the CPM alarm interface port

Default

false

Introduced

16.0.R1

Platforms

7750 SR-a

alarm-contact-input [input-pin-number] number

Synopsis

Enter the alarm-contact-input list instance

Introduced

16.0.R1

Platforms

7750 SR-a

[input-pin-number] number

Synopsis

Alarm contact input pin

Range

1 to 4

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

7750 SR-a

admin-state keyword

Synopsis

Administrative state of the alarm contact input

Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

7750 SR-a

clear-message string

Synopsis

Text message sent in the log event when an alarm clears

String Length

1 to 80

Default

Alarm Input Cleared

Introduced

16.0.R1

Platforms

7750 SR-a

description string

Synopsis

Text description

String Length

1 to 160

Introduced

16.0.R1

Platforms

7750 SR-a

normal-state keyword

Synopsis

Normal state associated with the alarm contact input

Default

open

Options

open, closed

Introduced

16.0.R1

Platforms

7750 SR-a

trigger-message string

Synopsis

Text message sent in the log event when input changes

String Length

1 to 80

Default

Alarm Input Triggered

Introduced

16.0.R1

Platforms

7750 SR-a

alarms

Synopsis

Enter the alarms context

Tree
Introduced

16.0.R4

Platforms

All

admin-state keyword

Synopsis

Administrative state of the system alarm

Default

enable

Options

enable, disable

Introduced

16.0.R4

Platforms

All

max-cleared number

Synopsis

Maximum number of cleared alarms

Range

0 to 500

Default

500

Introduced

16.0.R4

Platforms

All

allow-boot-license-violations boolean

Synopsis

Allow boot license violations in boot-up configuration

Default

true

Introduced

16.0.R4

Platforms

All

bluetooth

Synopsis

Enter the bluetooth context

Tree
Introduced

16.0.R1

Platforms

7750 SR-1, 7750 SR-s

admin-state keyword

Synopsis

Specifies the desired administrative state of the bluetooth module.

Default

disable

Options

enable, disable

Introduced

20.2.R1

Platforms

7750 SR-1, 7750 SR-s

advertising-timeout number

Synopsis

Bluetooth advertising timeout

Range

30 to 3600

Units

seconds

Introduced

16.0.R1

Platforms

7750 SR-1, 7750 SR-s

device [mac-address] string

Synopsis

Enter the device list instance

Tree
Max. Elements

5

Introduced

16.0.R1

Platforms

7750 SR-1, 7750 SR-s

[mac-address] string

Synopsis

Bluetooth client device MAC address

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

7750 SR-1, 7750 SR-s

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R1

Platforms

7750 SR-1, 7750 SR-s

module [cpm-slot] string

Synopsis

Enter the module list instance

Tree
Introduced

16.0.R1

Platforms

7750 SR-1, 7750 SR-s

[cpm-slot] string

Synopsis

CPM slot on which the module resides

String Length

1

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

7750 SR-1, 7750 SR-s

provisioned-identifier string

Synopsis

Bluetooth module ID

String Length

1 to 32

Introduced

16.0.R1

Platforms

7750 SR-1, 7750 SR-s

pairing-button boolean

Synopsis

Enable the pairing button

Default

false

Introduced

16.0.R1

Platforms

7750 SR-1, 7750 SR-s

passkey string

Synopsis

Bluetooth passkey

Tree
String Length

6

Default

123456

Introduced

16.0.R1

Platforms

7750 SR-1, 7750 SR-s

power-mode keyword

Synopsis

Bluetooth module(s) power mode.

Default

automatic

Options

manual, automatic

Introduced

20.2.R1

Platforms

7750 SR-1, 7750 SR-s

boot-bad-exec string

Synopsis

CLI script file to execute following a failed boot-up

String Length

1 to 180

Introduced

16.0.R1

Platforms

All

boot-good-exec string

Synopsis

CLI script file to execute following successful boot-up

String Length

1 to 180

Introduced

16.0.R1

Platforms

All

central-frequency-clock

Synopsis

Enter the central-frequency-clock context

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

bits

Synopsis

Enter the bits context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

input

Synopsis

Enter the input context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

admin-state keyword

Synopsis

Administrative state of BITS input timing reference

Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

interface-type keyword

Synopsis

Interface type of the BITS timing reference

Default

ds1-esf

Options

ds1-esf, ds1-sf, e1-pcm30crc, e1-pcm31crc, g703-2048khz

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

output

Synopsis

Enter the output context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

admin-state keyword

Synopsis

Administrative state of BITS output timing reference

Options

enable, disable

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

line-length keyword

Synopsis

Line length for the BITS output timing reference

Options

length-not-applicable, 110, 220, 330, 440, 550, 660

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ql-minimum keyword

Synopsis

Minimum signal quality level for BITSout port

Default

unused

Options

unused, prs, stu, st2, tnc, st3e, st3, prc, ssua, ssub, sec, eec1, eec2

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

source keyword

Synopsis

Source of the BITS output timing reference

Tree
Default

line-ref

Options

line-ref, internal-clock

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

squelch boolean

Synopsis

Squelch the signal of the BITS output timing reference

Tree
Default

false

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ql-override keyword

Synopsis

Override for the quality level of the timing reference

Default

unused

Options

unused, prs, stu, st2, tnc, st3e, st3, prc, ssua, ssub, sec

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ssm-bit number

Synopsis

Sa bit to convey SSM information

Tree
Range

4 to 8

Default

8

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ptp

Synopsis

Enter the ptp context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS-20, 7950 XRS-20e, 7950 XRS-40

admin-state keyword

Synopsis

Administrative state of the PTP timing reference

Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS-20, 7950 XRS-20e, 7950 XRS-40

ql-minimum keyword

Synopsis

Minimum signal quality level for system timing module

Default

unused

Options

unused, prs, stu, st2, tnc, st3e, st3, prc, ssua, ssub, sec, eec1, eec2

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ql-selection boolean

Synopsis

Consider quality level in system and BITS output timing

Default

false

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ref-order

Synopsis

Enter the ref-order context

Tree
Description

Commands in this context specify the priority order of the synchronous equipment timing subsystem.

If a reference source is disabled, this command defines the next reference source for the clock. If all reference sources are disabled, clocking is derived from a local oscillator.

If a timing reference is linked to a source port that is operationally down, the port is no longer a qualified, valid reference.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fifth keyword

Synopsis

The fifth most preferred timing reference source for the synchronous equipment timing subsystem.

Tree
Options

ref1, ref2, bits, ptp, none, synce, gnss

Introduced

19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-s, 7950 XRS-20, 7950 XRS-20e, 7950 XRS-40

first keyword

Synopsis

First preferred timing reference source

Tree
Options

ref1, ref2, bits, ptp, none, synce, gnss

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fourth keyword

Synopsis

Fourth preferred timing reference source

Tree
Options

ref1, ref2, bits, ptp, none, synce, gnss

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

second keyword

Synopsis

Second preferred timing reference source

Tree
Options

ref1, ref2, bits, ptp, none, synce, gnss

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

third keyword

Synopsis

Third preferred timing reference source

Tree
Options

ref1, ref2, bits, ptp, none, synce, gnss

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ref1

Synopsis

Enter the ref1 context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

admin-state keyword

Synopsis

Administrative state of the first timing reference

Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ql-override keyword

Synopsis

Quality level override of a timing reference

Default

unused

Options

unused, prs, stu, st2, tnc, st3e, st3, prc, ssua, ssub, sec, eec1, eec2

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

source-port string

Synopsis

Source port for the first timing reference

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ref2

Synopsis

Enter the ref2 context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

admin-state keyword

Synopsis

Administrative state of the second timing reference

Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ql-override keyword

Synopsis

Quality level override of a timing reference

Default

unused

Options

unused, prs, stu, st2, tnc, st3e, st3, prc, ssua, ssub, sec, eec1, eec2

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

source-port string

Synopsis

Source port for the second timing reference

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

revert boolean

Synopsis

Revert to higher-priority reference source

Tree
Default

false

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

synce

Synopsis

Enter the synce context

Tree
Introduced

19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-s, 7950 XRS-20, 7950 XRS-20e, 7950 XRS-40

admin-state keyword

Synopsis

Administrative state of the SyncE timing reference

Default

disable

Options

enable, disable

Introduced

19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-s, 7950 XRS-20, 7950 XRS-20e, 7950 XRS-40

ql-override keyword

Synopsis

Override the quality level of a timing reference

Default

unused

Options

unused, prs, stu, st2, tnc, st3e, st3, prc, ssua, ssub, sec, eec1, eec2

Introduced

19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-s, 7950 XRS-20, 7950 XRS-20e, 7950 XRS-40

wait-to-restore number

Synopsis

Time to re-validate a previously failed input reference

Range

1 to 12

Units

minutes

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

clli-code string

Synopsis

CLLI code value for the system

Context
Tree
String Length

11

Introduced

16.0.R1

Platforms

All

congestion-management boolean

Synopsis

Enable Virtual Service Router congestion management

Default

false

Introduced

16.0.R1

Platforms

VSR

contact string

Synopsis

Contact information for the managed node

Context
Tree
String Length

1 to 80

Introduced

16.0.R1

Platforms

All

coordinates string

Synopsis

GPS coordinates for the system location

String Length

1 to 80

Introduced

16.0.R1

Platforms

All

cpm-http-redirect

Synopsis

Enter the cpm-http-redirect context

Introduced

16.0.R4

Platforms

All

optimized-mode boolean

Synopsis

Enable optimized mode for CPM HTTP redirect messages

Default

true

Introduced

16.0.R4

Platforms

All

cron

Synopsis

Enter the cron context

Tree
Introduced

16.0.R1

Platforms

All

schedule [schedule-name] string owner string

Synopsis

Enter the schedule list instance

Context
Tree
Max. Elements

255

Introduced

16.0.R1

Platforms

All

[schedule-name] string

Synopsis

Schedule name

Context
String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

owner string

Synopsis

Schedule owner

Context
String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of the cron schedule

Context
Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

count number

Synopsis

Number of times to repeat a periodic schedule run

Context

configure system cron schedule string owner string count number

Tree
Range

1 to 65535

Introduced

16.0.R1

Platforms

All

day-of-month number

Synopsis

Days in a month when a schedule runs

Context
Range

-31 to -1 | 1 to 31

Max. Elements

62

Introduced

16.0.R1

Platforms

All

description string

Synopsis

Text description

Context
String Length

1 to 80

Introduced

16.0.R1

Platforms

All

end-time

Synopsis

Enter the end-time context

Context
Tree
Introduced

16.0.R1

Platforms

All

date-and-time string

Synopsis

Date and time to stop triggering the schedule

Notes

The following are part of a choice: date-and-time or (day and time).

Introduced

16.0.R1

Platforms

All

day keyword

Synopsis

Day to stop triggering this schedule

Context
Tree
Options

sunday, monday, tuesday, wednesday, thursday, friday, saturday

Notes

The following are part of a choice: date-and-time or (day and time).

Introduced

16.0.R1

Platforms

All

time string

Synopsis

Time to stop triggering the schedule

Context
Tree
String Length

5

Notes

The following are part of a choice: date-and-time or (day and time).

Introduced

16.0.R1

Platforms

All

hour number

Synopsis

Hours within a day when the schedule runs

Context

configure system cron schedule string owner string hour number

Tree
Range

0 to 23

Max. Elements

24

Introduced

16.0.R1

Platforms

All

interval number

Synopsis

Time between each periodic schedule run

Context
Tree
Range

30 to 42949672

Units

seconds

Introduced

16.0.R1

Platforms

All

minute number

Synopsis

Minutes in an hour when the schedule runs

Context

configure system cron schedule string owner string minute number

Tree
Range

0 to 59

Max. Elements

60

Introduced

16.0.R1

Platforms

All

month (keyword | number)

Synopsis

Months when the schedule runs

Context

configure system cron schedule string owner string month (keyword | number)

Tree
Range

1 to 12

Options

january, february, march, april, may, june, july, august, september, october, november, december

Max. Elements

12

Introduced

16.0.R1

Platforms

All

script-policy

Synopsis

Enter the script-policy context

Introduced

16.0.R1

Platforms

All

name string

Synopsis

Script policy name

Context
Tree
String Length

1 to 32

Introduced

16.0.R1

Platforms

All

owner string

Synopsis

Script policy owner

Context
Tree
String Length

1 to 32

Introduced

16.0.R1

Platforms

All

type keyword

Synopsis

Schedule type

Context

configure system cron schedule string owner string type keyword

Tree
Default

periodic

Options

periodic, calendar, oneshot

Introduced

16.0.R1

Platforms

All

weekday (keyword | number)

Synopsis

Weekdays when the schedule runs

Context

configure system cron schedule string owner string weekday (keyword | number)

Tree
Range

1 to 7

Options

sunday, monday, tuesday, wednesday, thursday, friday, saturday

Max. Elements

7

Introduced

16.0.R1

Platforms

All

dhcp6

Synopsis

Enter the dhcp6 context

Tree
Introduced

16.0.R4

Platforms

All

adv-noaddrs-global keyword

Synopsis

Applications to send NoAddrsAvail in Advertise messages

Options

esm-relay, server

Max. Elements

2

Introduced

16.0.R4

Platforms

All

dns

Synopsis

Enter the dns context

Tree
Introduced

16.0.R1

Platforms

All

address-pref keyword

Synopsis

Preference in DNS address resolving order

Options

ipv4-only, ipv6-first

Introduced

16.0.R1

Platforms

All

dnssec

Synopsis

Enter the dnssec context

Tree
Introduced

16.0.R1

Platforms

All

ad-validation keyword

Synopsis

Validation of AD-bit presence in DNS server responses

Options

fall-through, drop

Introduced

16.0.R1

Platforms

All

efm-oam

Synopsis

Enter the efm-oam context

Tree
Introduced

16.0.R1

Platforms

All

dying-gasp-tx-on-reset boolean

Synopsis

Generate Information OAM PDU on soft reset notification

Default

false

Introduced

16.0.R1

Platforms

All

grace-tx boolean

Synopsis

Send Grace TLVs for soft reset graceful recovery events

Tree
Default

false

Introduced

16.0.R1

Platforms

All

eth-cfm

Synopsis

Enter the eth-cfm context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

grace boolean

Synopsis

Allow system level capability of grace messaging

Context
Tree
Default

true

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

md-auto-id

Synopsis

Enter the md-auto-id context

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ma-index-range

Synopsis

Enable the ma-index-range context

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

end number

Warning:

Modifying this element recreates the parent element automatically for the new value to take effect.

Synopsis

Upper bound of the range

Tree
Range

1 to max

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

start number

Warning:

Modifying this element recreates the parent element automatically for the new value to take effect.

Synopsis

Lower bound of the range

Tree
Range

1 to max

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

md-index-range

Synopsis

Enable the md-index-range context

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

end number

Warning:

Modifying this element recreates the parent element automatically for the new value to take effect.

Synopsis

Upper bound of the range

Tree
Range

1 to max

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

start number

Warning:

Modifying this element recreates the parent element automatically for the new value to take effect.

Synopsis

Lower bound of the range

Tree
Range

1 to max

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

redundancy

Synopsis

Enter the redundancy context

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mc-lag

Synopsis

Enter the mc-lag context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

propagate-hold-time (number | keyword)

Synopsis

Delay timer value for the fault propagation

Range

1 to 60

Default

1

Units

seconds

Options

none

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

standby-mep boolean

Synopsis

Allow standby MC-LAG MEPs to act administratively down

Default

false

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

sender-id

Synopsis

Enter the sender-id context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

local-name string

Synopsis

Local name used in CFM PDUs

String Length

1 to 45

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

type keyword

Synopsis

ETH-CFM sender ID to be used in CFM PDUs

Tree
Default

system

Options

system, local

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

slm

Synopsis

Enter the slm context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

inactivity-timer number

Synopsis

SLR inactivity timer to maintain the stale test data

Range

10 to 100

Default

100

Units

seconds

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

grpc

Synopsis

Enter the grpc context

Tree
Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of gRPC server

Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

allow-unsecure-connection

Synopsis

Allow connection without secured transport protocol

Description

When configured, this command allows an unsecured connection to remote managers; TCP connections are not encrypted, including username and password information.

Notes

The following are part of a choice: allow-unsecure-connection or tls-server-profile.

Introduced

16.0.R1

Platforms

All

gnmi

Synopsis

Enter the gnmi context

Tree
Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of gNMI service

Default

enable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

auto-config-save boolean

Synopsis

Automatically save configuration as part of operation

Default

false

Introduced

16.0.R1

Platforms

All

gnoi

Synopsis

Enter the gnoi context

Tree
Introduced

19.10.R1

Platforms

All

cert-mgmt

Synopsis

Enter the cert-mgmt context

Tree
Introduced

19.10.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of gNOI CertificateManagement service.

Default

disable

Options

enable, disable

Introduced

19.10.R1

Platforms

All

file

Synopsis

Enter the file context

Tree
Introduced

21.2.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of gNOI File service.

Default

disable

Options

enable, disable

Introduced

21.2.R1

Platforms

All

system

Synopsis

Enter the system context

Tree
Introduced

20.5.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of gNOI System service.

Default

disable

Options

enable, disable

Introduced

20.5.R1

Platforms

All

max-msg-size number

Synopsis

Maximum size of received message

Range

1 to 1024

Default

512

Units

megabytes

Introduced

16.0.R1

Platforms

All

md-cli

Synopsis

Enter the md-cli context

Tree
Introduced

20.5.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of the MD-CLI service

Default

disable

Options

enable, disable

Introduced

20.5.R1

Platforms

All

rib-api

Synopsis

Enter the rib-api context

Tree
Introduced

16.0.R4

Platforms

All

admin-state keyword

Synopsis

Administrative state of RibAPI service

Default

disable

Options

enable, disable

Introduced

16.0.R4

Platforms

All

purge-timeout number

Synopsis

Number of seconds until stale entries are purged

Range

1 to 100000

Units

seconds

Introduced

16.0.R4

Platforms

All

tcp-keepalive

Synopsis

Enter the tcp-keepalive context

Introduced

16.0.R4

Platforms

All

admin-state keyword

Synopsis

Administrative state of the TCP keepalive algorithm

Default

disable

Options

enable, disable

Introduced

16.0.R4

Platforms

All

idle-time number

Synopsis

Time until the first TCP keepalive probe is sent

Tree
Range

1 to 100000

Default

600

Units

seconds

Introduced

16.0.R4

Platforms

All

interval number

Synopsis

Interval between TCP keep-alive probes

Tree
Range

1 to 100000

Default

15

Units

seconds

Introduced

16.0.R4

Platforms

All

retries number

Synopsis

Missed keepalives before the TCP connection is closed

Tree
Range

3 to 100

Default

4

Introduced

16.0.R4

Platforms

All

tls-server-profile reference

Synopsis

Preferred TLS server profile

Notes

The following are part of a choice: allow-unsecure-connection or tls-server-profile.

Introduced

16.0.R1

Platforms

All

icmp-vse boolean

Synopsis

Enable vendor-specific extensions to ICMP

Context
Tree
Default

false

Introduced

16.0.R1

Platforms

All

ip

Synopsis

Enter the ip context

Tree
Introduced

16.0.R1

Platforms

All

allow-qinq-network-interface boolean

Synopsis

Allow QinQ encapsulation for network interfaces

Default

false

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

enforce-unique-if-index boolean

Synopsis

Create IP interface indexes that are globally unique

Default

false

Introduced

16.0.R1

Platforms

All

forward-6in4 boolean

Synopsis

Allows the 6in4 forwarding of traffic sent to the system IP address.

Default

false

Introduced

19.10.R1

Platforms

All

forward-ip-over-gre boolean

Synopsis

Allows the forwarding of IP traffic encapsulated in GRE transport sent to the system IP address.

Default

false

Introduced

19.10.R1

Platforms

All

ipv6-eh keyword

Synopsis

Limit the number of IPv6 extension headers processed ingress/egress.

Context
Tree
Default

max

Options

max, limited

Introduced

20.5.R1

Platforms

All

mpls

Synopsis

Enter the mpls context

Tree
Introduced

19.10.R3

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

label-stack-statistics-count number

Synopsis

Specifies the MPLS label stack statistics count.

Range

1 to 2

Default

1

Introduced

19.10.R3

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

l2tp

Synopsis

Enter the l2tp context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

non-multi-chassis-tunnel-id-range

Synopsis

Enter the non-multi-chassis-tunnel-id-range context

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

end number

Synopsis

Upper bound of the range

Tree
Range

0 to 16383

Default

16383

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

start number

Synopsis

Lower bound of the range

Tree
Range

0 to 16383

Default

1

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lacp

Synopsis

Enter the lacp context

Tree
Introduced

16.0.R1

Platforms

All

system-priority number

Synopsis

LACP system priority on aggregated Ethernet interfaces

Range

1 to 65535

Default

32768

Introduced

16.0.R1

Platforms

All

lldp

Synopsis

Enter the lldp context

Tree
Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of LLDP

Default

enable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

message-fast-tx number

Synopsis

Interval at which LLDP frames are transmitted

Range

1 to 3600

Default

1

Units

seconds

Introduced

16.0.R1

Platforms

All

message-fast-tx-init number

Synopsis

PDUs to transmit during the fast transmission period

Range

1 to 8

Default

4

Introduced

16.0.R1

Platforms

All

notification-interval number

Synopsis

Minimum interval between change notifications

Range

5 to 3600

Default

5

Units

seconds

Introduced

16.0.R1

Platforms

All

reinit-delay number

Synopsis

Time required before re-initializing LLDP on a port

Range

1 to 10

Default

2

Units

seconds

Introduced

16.0.R1

Platforms

All

tx-credit-max number

Synopsis

Maximum consecutive LLDPDUs that can be transmitted

Range

1 to 100

Default

5

Introduced

16.0.R1

Platforms

All

tx-hold-multiplier number

Synopsis

Transmit interval multiplier

Range

2 to 10

Default

4

Introduced

16.0.R1

Platforms

All

tx-interval number

Synopsis

LLDP transmit interval

Range

5 to 32768

Default

30

Units

seconds

Introduced

16.0.R1

Platforms

All

load-balancing

Synopsis

Enter the load-balancing context

Introduced

16.0.R1

Platforms

All

l2tp-load-balancing boolean

Synopsis

Include L2TP header information for load balancing

Default

false

Introduced

16.0.R4

Platforms

All

l4-load-balancing boolean

Synopsis

Use load balancing based on Layer 4 fields

Introduced

16.0.R1

Platforms

All

lsr-load-balancing keyword

Synopsis

Hashing algorithm for system-wide LSR load balancing

Options

lbl-only, lbl-ip, ip-only, eth-encap-ip, lbl-ip-l4-teid

Introduced

16.0.R1

Platforms

All

mc-enh-load-balancing boolean

Synopsis

Enable enhanced egress multicast load balancing

Default

false

Introduced

16.0.R1

Platforms

All

service-id-lag-hashing boolean

Synopsis

Enable enhanced VLL LAG service ID hashing

Default

false

Introduced

16.0.R1

Platforms

All

system-ip-load-balancing boolean

Synopsis

Use system IP address for ECMP and LAG load balancing

Introduced

16.0.R1

Platforms

All

location string

Synopsis

Site location of the system

Context
Tree
String Length

1 to 80

Introduced

16.0.R1

Platforms

All

login-control

Synopsis

Enter the login-control context

Introduced

16.0.R1

Platforms

All

exponential-backoff boolean

Synopsis

Enable exponential-backoff of the login prompt

Default

false

Introduced

16.0.R1

Platforms

All

ftp

Synopsis

Enter the ftp context

Tree
Introduced

16.0.R1

Platforms

All

inbound-max-sessions number

Synopsis

Maximum number of concurrent inbound FTP sessions

Range

0 to 5

Default

3

Introduced

16.0.R1

Platforms

All

idle-timeout (keyword | number)

Synopsis

Idle timeout for FTP, console, or Telnet sessions

Context
Range

1 to 1440

Default

30

Units

minutes

Options

none

Introduced

16.0.R1

Platforms

All

login-banner boolean

Synopsis

Display login banner

Default

false

Introduced

16.0.R1

Platforms

All

login-scripts

Synopsis

Enter the login-scripts context

Introduced

16.0.R1

Platforms

All

global-script string

Synopsis

URL of the global CLI login script

String Length

1 to 180

Introduced

16.0.R1

Platforms

All

per-user-script

Synopsis

Enter the per-user-script context

Introduced

16.0.R1

Platforms

All

file-name string

Synopsis

File name of the per-user login script

Tree
String Length

1 to 180

Introduced

16.0.R1

Platforms

All

user-directory string

Synopsis

Directory name of user-defined login script

String Length

1 to 180

Introduced

16.0.R1

Platforms

All

motd

Synopsis

Enter the motd context

Tree
Introduced

16.0.R1

Platforms

All

text string

Synopsis

Message of the day displayed after console login

Tree
String Length

1 to 900

Notes

The following are part of a choice: text or url.

Introduced

16.0.R1

Platforms

All

url string

Synopsis

URL of the location of message of the day

Tree
String Length

1 to 180

Notes

The following are part of a choice: text or url.

Introduced

16.0.R1

Platforms

All

pre-login-message

Synopsis

Enter the pre-login-message context

Introduced

16.0.R1

Platforms

All

message string

Synopsis

Message displayed prior to the login prompt

Tree
String Length

1 to 900

Introduced

16.0.R1

Platforms

All

name boolean

Synopsis

Display the system name before the pre-login message

Tree
Default

false

Introduced

16.0.R1

Platforms

All

ssh

Synopsis

Enter the ssh context

Tree
Introduced

16.0.R1

Platforms

All

graceful-shutdown boolean

Synopsis

Allow graceful shutdown of SSH sessions

Default

true

Introduced

16.0.R1

Platforms

All

inbound-max-sessions number

Synopsis

Maximum number of concurrent inbound sessions

Range

0 to 50

Default

5

Introduced

16.0.R1

Platforms

All

outbound-max-sessions number

Synopsis

Maximum number of concurrent outbound sessions

Range

0 to 15

Default

5

Introduced

16.0.R1

Platforms

All

ttl-security number

Synopsis

Minimum TTL value for incoming BGP packets

Range

1 to 255

Introduced

16.0.R1

Platforms

All

telnet

Synopsis

Enter the telnet context

Tree
Introduced

16.0.R1

Platforms

All

graceful-shutdown boolean

Synopsis

Allow graceful shutdown of Telnet sessions

Default

false

Introduced

16.0.R1

Platforms

All

inbound-max-sessions number

Synopsis

Maximum number of concurrent inbound sessions

Range

0 to 50

Default

5

Introduced

16.0.R1

Platforms

All

outbound-max-sessions number

Synopsis

Maximum number of concurrent outbound sessions

Range

0 to 15

Default

5

Introduced

16.0.R1

Platforms

All

ttl-security number

Synopsis

Minimum TTL value for incoming BGP packets

Range

1 to 255

Introduced

16.0.R1

Platforms

All

management-interface

Synopsis

Enter the management-interface context

Introduced

16.0.R1

Platforms

All

cli

Synopsis

Enter the cli context

Tree
Introduced

16.0.R1

Platforms

All

classic-cli

Synopsis

Enter the classic-cli context

Introduced

16.0.R1

Platforms

All

allow-immediate boolean

Synopsis

Allow writable access in classic CLI configure branch

Default

true

Introduced

16.0.R1

Platforms

All

rollback

Synopsis

Enter the rollback context

Tree
Introduced

16.0.R1

Platforms

All

local-checkpoints number

Synopsis

Maximum number of rollback files on compact flash

Range

1 to 50

Default

10

Introduced

16.0.R1

Platforms

All

location string

Synopsis

Location and filename of the rollback checkpoint files

Tree
String Length

1 to 180

Introduced

16.0.R1

Platforms

All

remote-checkpoints number

Synopsis

Maximum rollback files saved at a remote location

Range

1 to 200

Default

10

Introduced

16.0.R1

Platforms

All

rescue

Synopsis

Enter the rescue context

Tree
Introduced

16.0.R1

Platforms

All

location string

Synopsis

Location of the rollback rescue file

Tree
String Length

1 to 180

Introduced

16.0.R1

Platforms

All

cli-engine keyword

Synopsis

System-wide CLI engine access configuration

Default

md-cli

Options

classic-cli, md-cli

Max. Elements

2

Notes

This element is ordered by the user.

Introduced

16.0.R1

Platforms

All

md-cli

Synopsis

Enter the md-cli context

Tree
Introduced

16.0.R1

Platforms

All

auto-config-save boolean

Synopsis

Automatically save configuration as part of operation

Default

false

Introduced

16.0.R1

Platforms

All

environment

Synopsis

Enter the environment context

Introduced

16.0.R1

Platforms

All

command-completion

Synopsis

Enter the command-completion context

Introduced

16.0.R1

Platforms

All

enter boolean

Synopsis

Complete the command when the enter key is pressed

Tree
Default

true

Introduced

16.0.R1

Platforms

All

space boolean

Synopsis

Complete the command when the space key is pressed

Tree
Default

true

Introduced

16.0.R1

Platforms

All

tab boolean

Synopsis

Complete the command when the tab key is pressed

Tree
Default

true

Introduced

16.0.R1

Platforms

All

console

Synopsis

Enter the console context

Tree
Introduced

16.0.R1

Platforms

All

length number

Synopsis

Number of lines displayed on the screen

Tree
Range

24 to 512

Default

24

Introduced

16.0.R1

Platforms

All

width number

Synopsis

Number of columns displayed on the screen

Tree
Range

80 to 512

Default

80

Introduced

16.0.R1

Platforms

All

message-severity-level

Synopsis

Enter the message-severity-level context

Introduced

16.0.R1

Platforms

All

cli keyword

Synopsis

Message severity threshold for CLI messages

Tree
Default

info

Options

warning, info

Introduced

16.0.R1

Platforms

All

more boolean

Synopsis

Prompt to continue or stop when output text fills page

Tree
Default

true

Introduced

16.0.R1

Platforms

All

progress-indicator

Synopsis

Enter the progress-indicator context

Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of the progress indicator

Default

enable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

delay number

Synopsis

Delay before progress indicator is displayed

Tree
Range

0 to 10000

Default

1000

Units

milliseconds

Introduced

16.0.R1

Platforms

All

type keyword

Synopsis

Progress indicator output style

Tree
Default

dots

Options

dots

Introduced

16.0.R1

Platforms

All

prompt

Synopsis

Enter the prompt context

Tree
Introduced

16.0.R1

Platforms

All

context boolean

Synopsis

Show the current command context in the prompt

Tree
Default

true

Introduced

16.0.R1

Platforms

All

newline boolean

Synopsis

Add a new line before every prompt line

Tree
Default

true

Introduced

16.0.R1

Platforms

All

timestamp boolean

Synopsis

Show the timestamp before the first prompt line

Tree
Default

false

Introduced

16.0.R1

Platforms

All

uncommitted-changes-indicator boolean

Synopsis

Show an asterisk (*) when uncommitted changes exist

Default

true

Introduced

16.0.R1

Platforms

All

time-display keyword

Synopsis

Time zone displayed before the prompt

Default

local

Options

local, utc

Introduced

16.0.R1

Platforms

All

time-format keyword

Synopsis

Time format to display date and time

Default

rfc-3339

Options

iso-8601, rfc-1123, rfc-3339

Introduced

20.5.R1

Platforms

All

configuration-mode keyword

Synopsis

Configuration mode for the system

Default

classic

Options

classic, model-driven, mixed

Introduced

16.0.R1

Platforms

All

configuration-save

Synopsis

Enter the configuration-save context

Introduced

16.0.R1

Platforms

All

configuration-backups number

Synopsis

Maximum number of backup versions maintained

Range

1 to 200

Default

5

Introduced

16.0.R1

Platforms

All

netconf

Synopsis

Enter the netconf context

Tree
Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of NETCONF

Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

auto-config-save boolean

Synopsis

Automatically save configuration as part of operation

Default

false

Introduced

16.0.R1

Platforms

All

capabilities

Synopsis

Enter the capabilities context

Introduced

16.0.R1

Platforms

All

candidate boolean

Synopsis

Allow the NETCONF server to access the candidate datastore

Tree
Default

true

Introduced

16.0.R1

Platforms

All

writable-running boolean

Synopsis

Allow NETCONF server to access the running datastore

Default

false

Introduced

16.0.R1

Platforms

All

port number

Synopsis

Choose port on which the NETCONF server will listen for new connections.

Tree
Range

22 | 830

Default

830

Introduced

19.10.R1

Platforms

All

operations

Synopsis

Enter the operations context

Description

Commands in this context configure parameters associated with operational commands in model-driven interfaces.

Introduced

21.5.R1

Platforms

All

global-timeouts

Synopsis

Enter the global-timeouts context

Description

Commands in this context configure system timeout parameters for operational commands.

Timeout parameters provide default system-level control for various types of operational commands in model-driven interfaces. The timeout values are used when specific execution and retention timeouts are not requested for a specific operation.

Introduced

21.5.R1

Platforms

All

asynchronous-execution (number | keyword)

Synopsis

Timeout for asynchronous operation execution

Description

This command configures the period of time that operations launched as “asynchronous” are allowed to execute before being automatically stopped by the SR OS.

An asynchronous operation is not deleted from the system when it is stopped. See the asynchronous-retention command.

If a specific execution timeout is not included in the request for a particular asynchronous operation, this system-level timeout applies.

Note: This execution timeout is part of the general global operations infrastructure and is separate and independent from any operation-specific timeouts (for example, the ping operation also has its own timeout parameter).

Range

1 to 604800

Default

3600

Options

never

Introduced

21.5.R1

Platforms

All

asynchronous-retention (number | keyword)

Synopsis

Timeout for asynchronous operation data retention

Description

This command configures the period of time that data related to operations launched as “asynchronous” is retained in the system. After the retention timeout expires, all information related to the operation is deleted, including any status information and result data.

If a specific retention timeout is not included in the request for a particular asynchronous operation, this system-level timeout applies.

Range

1 to 604800

Default

86400

Options

never

Introduced

21.5.R1

Platforms

All

synchronous-execution (number | keyword)

Synopsis

Timeout for synchronous operation execution

Description

This command configures the period of time that operations launched as “'synchronous” (the default method for all operations) are allowed to execute before they are automatically stopped, and their associated data is deleted.

If a specific execution timeout is not included in the request for a particular synchronous operation, this system-level timeout applies.

Note: This execution timeout is part of the general global operations infrastructure and is separate and independent from any operation-specific timeouts (for example, the ping operation also has its own timeout parameter).

Caution: If this command is set with a specific time value, MD-CLI operations are subject to the timeout and are interrupted if they execute longer than the time value. This situation can arise because the timeout also applies to operations requested in the MD-CLI interface (for example, ping, file dir, and so on).

Range

1 to 604800

Default

never

Options

never

Introduced

21.5.R1

Platforms

All

remote-management

Synopsis

Enter the remote-management context

Description

Commands in this context configure remote management to manage multiple SR OS nodes running different SR OS versions from the same MD-CLI shell.

Introduced

20.5.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of remote management registration

Default

disable

Options

enable, disable

Introduced

20.5.R1

Platforms

All

allow-unsecure-connection

Synopsis

Allow connection without secured transport protocol

Description

When configured, this command allows an unsecured connection to remote managers; TCP connections are not encrypted, including username and password information.

Notes

The following are part of a choice: allow-unsecure-connection or client-tls-profile.

Introduced

20.5.R1

Platforms

All

client-tls-profile reference

Synopsis

TLS client profile name

Description

This command specifies the client TLS profile to all remote managers.

Notes

The following are part of a choice: allow-unsecure-connection or client-tls-profile.

Introduced

20.5.R1

Platforms

All

connection-timeout number

Synopsis

Time without a response before manager declared down

Range

1 to 3600

Default

60

Units

seconds

Introduced

20.5.R1

Platforms

All

device-label string

Synopsis

Device label supplied to the remote manager

Description

This command specifies a metadata label that is supplied to the manager. This label is used to group devices or network nodes with a common purpose or goal.

String Length

1 to 64

Introduced

20.5.R1

Platforms

All

device-name string

Synopsis

Device name supplied to the remote manager

Description

This command specifies a device name that is supplied to the manager. The name identifies a specific SR OS node in the network.

When unconfigured, the default system name is used.

String Length

1 to 64

Introduced

20.5.R1

Platforms

All

hello-interval number

Synopsis

Time between hello messages from SR OS node to manager

Range

10 to 3600

Default

10

Units

minutes

Introduced

20.5.R1

Platforms

All

manager [manager-name] string

Synopsis

Enter the manager list instance

Tree
Description

Commands in this context configure specific manager-related commands. Commands configured in this context take precedence over command values specified directly in the configure management-interface remote-management context.

If a command is not configured in this context, the command setting is inherited from the higher level context.

Max. Elements

2

Introduced

20.5.R1

Platforms

All

[manager-name] string

Synopsis

Remote management manager name

String Length

1 to 64

Notes

This element is part of a list key.

Introduced

20.5.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of remote management registration

Default

disable

Options

enable, disable

Introduced

20.5.R1

Platforms

All

allow-unsecure-connection

Synopsis

Allow connection without secured transport protocol

Description

When configured, this command allows an unsecured connection to remote managers; TCP connections are not encrypted, including username and password information.

Notes

The following are part of a choice: allow-unsecure-connection or client-tls-profile.

Introduced

20.5.R1

Platforms

All

client-tls-profile reference

Synopsis

TLS client profile name

Description

This command assigns a profile name to a remote manager.

Notes

The following are part of a choice: allow-unsecure-connection or client-tls-profile.

Introduced

20.5.R1

Platforms

All

connection-timeout number

Synopsis

Max time without response before manager declared down

Range

1 to 3600

Units

seconds

Introduced

20.5.R1

Platforms

All

description string

Synopsis

Text description

String Length

1 to 80

Introduced

20.5.R1

Platforms

All

device-label string

Synopsis

Device label supplied to the remote manager

Description

This command specifies a metadata label that is supplied to the manager. This label is used to group devices or network nodes with a common purpose or goal.

String Length

1 to 64

Introduced

20.5.R1

Platforms

All

device-name string

Synopsis

Device name supplied to the remote manager

Description

This command specifies a device name that is supplied to the manager. The name identifies a specific SR OS node in the network.

When unconfigured, the default system name is used.

String Length

1 to 64

Introduced

20.5.R1

Platforms

All

manager-address (ipv4-address-no-zone | ipv6-address-no-zone | fully-qualified-domain-name)

Synopsis

Destination IP address of the manager

Context

configure system management-interface remote-management manager string manager-address (ipv4-address-no-zone | ipv6-address-no-zone | fully-qualified-domain-name)

String Length

1 to 255

Introduced

20.5.R1

Platforms

All

manager-port number

Synopsis

Destination TCP port for gRPC connections to manager

Range

1 to 65535

Default

57400

Introduced

20.5.R1

Platforms

All

router-instance string

Synopsis

Reference to a router or VPRN service name

Introduced

20.5.R1

Platforms

All

source-address (ipv4-address-no-zone | ipv6-address-no-zone)

Synopsis

Source IP address for connection to the manager

Context

configure system management-interface remote-management manager string source-address (ipv4-address-no-zone | ipv6-address-no-zone)

Introduced

20.5.R1

Platforms

All

source-port (number | keyword)

Synopsis

Source TCP destination port number

Range

1 to 65535

Options

grpc-default

Introduced

20.5.R1

Platforms

All

router-instance string

Synopsis

Router name or VPRN service name

Default

management

Introduced

20.5.R1

Platforms

All

source-address (ipv4-address-no-zone | ipv6-address-no-zone)

Synopsis

Source IP address for connection to the manager

Context

configure system management-interface remote-management source-address (ipv4-address-no-zone | ipv6-address-no-zone)

Introduced

20.5.R1

Platforms

All

source-port (number | keyword)

Synopsis

Source TCP port number to connection to the manager

Range

1 to 65535

Default

grpc-default

Options

grpc-default

Introduced

20.5.R1

Platforms

All

schema-path string

Synopsis

Schema path URL

Description

This command specifies the schema path where the SR OS YANG modules can be manually copied by the user prior to using a <get-schema> request. It is recommended that the URL string not exceed 135 characters for the <get-schema> request to work properly with all schema files.

When unconfigured, the software upgrade process manages the YANG schema files to ensure the schema files are synchronized with the software image on both the primary and standby CPM.

String Length

1 to 180

Introduced

16.0.R4

Platforms

All

snmp

Synopsis

Enter the snmp context

Tree
Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of the SNMP daemon

Default

enable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

engine-id string

Synopsis

SNMP engine ID that identifies the SNMPv3 node

Tree
String Length

10 to 64

Introduced

16.0.R1

Platforms

All

general-port number

Synopsis

Port number to be used to send general SNMP messages.

Range

0 | 1 to 65535

Default

161

Introduced

16.0.R1

Platforms

All

packet-size number

Synopsis

Maximum SNMP packet size generated by the node

Range

484 to 9216

Default

1500

Introduced

16.0.R1

Platforms

All

streaming

Synopsis

Enter the streaming context

Tree
Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of the streaming daemon

Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

yang-modules

Synopsis

Enter the yang-modules context

Description

Commands in this context determine the system support of the Nokia YANG models.

The settings affect the data sent in a NETCONF <hello>, data populated in the RFC 6022 /netconf-state/schemas list, data returned in a <get-schema> request, and data populated in the RFC 8525 /yang-library.

Introduced

16.0.R1

Platforms

All

base-r13-modules boolean

Synopsis

Support base release 13 YANG models

Default

false

Introduced

16.0.R1

Platforms

All

nokia-combined-modules boolean

Synopsis

Support access to combined Nokia YANG models

Description

When configured to true, the system supports the combined Nokia YANG files for both configuration and state data in the NETCONF server.

When the system is operating in classic configuration mode, attempts to access (read or write) the configuration using the Nokia configuration modules or namespace via NETCONF result in errors, even if this command is set to true.

When configured to false, access to the combined Nokia YANG files is not supported.

This command and the nokia-submodules command cannot both be set to true at the same time.

Introduced

16.0.R4

Platforms

All

nokia-submodules boolean

Synopsis

Support submodule-based packaging of Nokia YANG models

Description

When configured to true, the system supports the alternative submodule-based packaging of the Nokia YANG files for both configuration and state data in the NETCONF server.

When the system is operating in classic configuration mode, attempts to access (read or write) the configuration using the Nokia configuration modules or namespace via NETCONF result in errors, even if this command is set to true.

When configured to false, access to the submodule-based packaging of the Nokia YANG files is not supported.

This command and the nokia-combined-modules command cannot both be set to true at the same time.

Introduced

21.2.R1

Platforms

All

openconfig-modules boolean

Synopsis

Support OpenConfig YANG models

Default

false

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

name string

Synopsis

Administrative name assigned to the system

Context
Tree
String Length

1 to 64

Introduced

16.0.R1

Platforms

All

network-element-discovery

Synopsis

Enter the network-element-discovery context

Introduced

19.5.R1

Platforms

All

generate-traps boolean

Synopsis

Generate NE discovery traps

Default

false

Introduced

19.5.R1

Platforms

All

profile [name] string

Synopsis

Enter the profile list instance

Tree
Max. Elements

1

Introduced

19.5.R1

Platforms

All

[name] string

Synopsis

Profile name

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

19.5.R1

Platforms

All

neid string

Synopsis

Network element ID of the advertised node

Tree
String Length

7 to 8

Introduced

19.5.R1

Platforms

All

neip

Synopsis

Enter the neip context

Tree
Introduced

19.5.R1

Platforms

All

auto-generate

Synopsis

Enter the auto-generate context

Introduced

21.2.R1

Platforms

All

ipv4

Synopsis

Enable the ipv4 context

Tree
Introduced

21.2.R1

Platforms

All

vendor-id-value number

Synopsis

Most significant byte if the NE IPv4 address

Range

1 to 255

Default

140

Introduced

21.2.R1

Platforms

All

ipv6

Synopsis

Enable the ipv6 context

Tree
Introduced

21.2.R1

Platforms

All

vendor-id-value number

Synopsis

Most significant byte of the NE IPv6 address

Range

1 to 255

Default

140

Introduced

21.2.R1

Platforms

All

ipv4 string

Synopsis

NEIP IPv4 address

Tree
Introduced

19.5.R1

Platforms

All

ipv6 string

Synopsis

NEIP IPv6 address

Tree
Introduced

19.5.R1

Platforms

All

platform-type string

Synopsis

Platform name and chassis type to be advertised

String Length

1 to 255

Introduced

19.5.R1

Platforms

All

system-mac string

Synopsis

MAC address of the advertised node

Introduced

19.5.R1

Platforms

All

vendor-id string

Synopsis

Vendor ID to be advertised

Tree
String Length

1 to 255

Default

Nokia

Introduced

19.5.R1

Platforms

All

ospf-dynamic-hostnames boolean

Synopsis

Process received OSPF dynamic hostname information

Description

When configured to true, OSPF dynamic hostnames are enabled. The router receiving the new dynamic hostname within the OSPF Router Information (RI) LSA is instructed to process the received dynamic hostname information.

When configured to false, dynamic hostname information is not processed.

Default

false

Introduced

20.2.R1

Platforms

All

persistence

Synopsis

Enter the persistence context

Introduced

16.0.R1

Platforms

All

ancp

Synopsis

Enter the ancp context

Tree
Introduced

16.0.R1

Platforms

All

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R1

Platforms

All

location keyword

Synopsis

CPM flash card where the information is stored

Tree
Options

cf1, cf2, cf3

Introduced

16.0.R1

Platforms

All

application-assurance

Synopsis

Enter the application-assurance context

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

location keyword

Synopsis

CPM flash card where the information is stored

Tree
Options

cf1, cf2, cf3

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dhcp-server

Synopsis

Enter the dhcp-server context

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

location keyword

Synopsis

CPM flash card where the information is stored

Tree
Options

cf1, cf2, cf3

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

nat-port-forwarding

Synopsis

Enter the nat-port-forwarding context

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

location keyword

Synopsis

CPM flash card where the information is stored

Tree
Options

cf1, cf2, cf3

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

options

Synopsis

Enter the options context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

dhcp-leasetime-threshold number

Synopsis

DHCP lease time limit to be eligible for persistence

Range

1 to 631152000

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

python-policy-cache

Synopsis

Enter the python-policy-cache context

Introduced

16.0.R1

Platforms

All

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R1

Platforms

All

location keyword

Synopsis

CPM flash card where the information is stored

Tree
Options

cf1, cf2, cf3

Introduced

16.0.R1

Platforms

All

subscriber-mgmt

Synopsis

Enter the subscriber-mgmt context

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

location keyword

Synopsis

CPM flash card where the information is stored

Tree
Options

cf1, cf2, cf3

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

power-management power-zone number

Synopsis

Enter the power-management list instance

Introduced

16.0.R1

Platforms

7750 SR-s, 7950 XRS

power-zone number

Synopsis

Power zone

Range

1 to 2

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

7750 SR-s, 7950 XRS

mode keyword

Synopsis

Power capacity mode algorithm

Tree
Default

basic

Options

none, basic, advanced

Introduced

16.0.R1

Platforms

7750 SR-s, 7950 XRS

power-safety-alert number

Synopsis

Power capacity to trigger a safety alert event

Range

0 to 120000

Default

0

Units

watts

Introduced

16.0.R1

Platforms

7750 SR-s, 7950 XRS

power-safety-level number

Synopsis

Minimum threshold to power off devices

Range

0 to 100

Default

100

Units

percent

Introduced

16.0.R1

Platforms

7750 SR-s, 7950 XRS

script-control

Synopsis

Enter the script-control context

Introduced

16.0.R1

Platforms

All

script [script-name] string owner string

Synopsis

Enter the script list instance

Context
Tree
Max. Elements

1500

Introduced

16.0.R1

Platforms

All

[script-name] string

Synopsis

Script name

Context
String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

owner string

Synopsis

Script owner

Context
String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of the policy

Context
Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

description string

Synopsis

Text description

Context
String Length

1 to 80

Introduced

16.0.R1

Platforms

All

location string

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Script location

Context
Tree
String Length

1 to 255

Introduced

16.0.R1

Platforms

All

script-policy [policy-name] string owner string

Synopsis

Enter the script-policy list instance

Max. Elements

1500

Introduced

16.0.R1

Platforms

All

[policy-name] string

Synopsis

Script policy name

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

owner string

Synopsis

Script policy owner

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of the script policy

Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

expire-time (number | keyword)

Synopsis

Maximum amount of time to keep a run history status

Context
Range

0 to 21474836

Default

3600

Units

seconds

Options

forever

Introduced

16.0.R1

Platforms

All

lifetime (number | keyword)

Synopsis

Maximum amount of time the script may run

Context

configure system script-control script-policy string owner string lifetime (number | keyword)

Tree
Range

0 to 21474836

Default

3600

Units

seconds

Options

forever

Introduced

16.0.R1

Platforms

All

lock-override boolean

Synopsis

Allow EHS/CRON script to break database explicit lock

Default

false

Introduced

19.10.R1

Platforms

All

max-completed number

Synopsis

Maximum number of script history status entries kept

Range

1 to 1500

Default

1

Introduced

16.0.R1

Platforms

All

results string

Synopsis

Location to receive CLI output of a script run

Tree
String Length

1 to 255

Introduced

16.0.R1

Platforms

All

script

Synopsis

Enter the script context

Tree
Introduced

16.0.R1

Platforms

All

name string

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Script name

Tree
String Length

1 to 32

Introduced

16.0.R1

Platforms

All

owner string

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Script owner

Tree
String Length

1 to 32

Introduced

16.0.R1

Platforms

All

security

Synopsis

Enter the security context

Tree
Description

Commands in this context configure central security settings such as DDoS protection, users, authorization profiles, and certificates.

Access to these commands should be restricted to highly trusted users and device administrators.

Introduced

16.0.R1

Platforms

All

aaa

Synopsis

Enter the aaa context

Tree
Introduced

16.0.R1

Platforms

All

cli-session-group [cli-session-group-name] string

Synopsis

Enter the cli-session-group list instance

Max. Elements

16

Introduced

16.0.R1

Platforms

All

[cli-session-group-name] string

Synopsis

CLI session group name

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R2

Platforms

All

combined-max-sessions number

Synopsis

Maximum number of concurrent SSH and Telnet sessions

Range

0 to 50

Introduced

16.0.R1

Platforms

All

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R1

Platforms

All

ssh-max-sessions number

Synopsis

Maximum number of concurrent SSH sessions

Range

0 to 50

Introduced

16.0.R1

Platforms

All

telnet-max-sessions number

Synopsis

Maximum number of concurrent Telnet sessions

Range

0 to 50

Introduced

16.0.R1

Platforms

All

health-check (number | keyword)

Synopsis

Polling interval of RADIUS, TACACS+, and LDAP servers

Context
Range

6 to 1500

Default

30

Units

seconds

Options

none

Introduced

16.0.R1

Platforms

All

local-profiles

Synopsis

Enter the local-profiles context

Introduced

16.0.R1

Platforms

All

profile [user-profile-name] string

Synopsis

Enter the profile list instance

Tree
Max. Elements

128

Introduced

16.0.R1

Platforms

All

[user-profile-name] string

Synopsis

User profile name

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

cli-session-group reference

Synopsis

CLI session group to which the profile belongs

Introduced

16.0.R1

Platforms

All

combined-max-sessions number

Synopsis

Maximum number of concurrent SSH and Telnet sessions

Range

0 to 50

Introduced

16.0.R1

Platforms

All

default-action keyword

Synopsis

Action for non-matching entry

Default

none

Options

deny-all, permit-all, none, read-only-all

Introduced

16.0.R1

Platforms

All

entry [entry-id] number

Synopsis

Enter the entry list instance

Tree
Introduced

16.0.R1

Platforms

All

[entry-id] number

Synopsis

User profile entry ID

Range

1 to 9999

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

action keyword

Synopsis

Action when a user command matches the entry

Tree
Default

none

Options

deny, permit, none, read-only

Introduced

16.0.R1

Platforms

All

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R1

Platforms

All

match string

Synopsis

Command to match the entry

Tree
String Length

1 to 255

Introduced

16.0.R1

Platforms

All

grpc

Synopsis

Enter the grpc context

Tree
Introduced

16.0.R1

Platforms

All

rpc-authorization

Synopsis

Enter the rpc-authorization context

Description

Commands in this context control the authorization of each RPC in gRPC interfaces.  

Introduced

16.0.R1

Platforms

All

gnmi-capabilities keyword

Synopsis

gNMI Capabilities RPC authorization

Default

permit

Options

permit, deny

Introduced

16.0.R1

Platforms

All

gnmi-get keyword

Synopsis

gNMI Get RPC authorization

Tree
Default

permit

Options

permit, deny

Introduced

16.0.R1

Platforms

All

gnmi-set keyword

Synopsis

gNMI Set RPC authorization

Tree
Default

permit

Options

permit, deny

Introduced

16.0.R1

Platforms

All

gnmi-subscribe keyword

Synopsis

gNMI Subscribe RPC authorization

Default

permit

Options

permit, deny

Introduced

16.0.R1

Platforms

All

gnoi-cert-mgmt-cangenerate keyword

Synopsis

CanGenerateCSR RPC usage

Default

deny

Options

permit, deny

Introduced

19.10.R1

Platforms

All

gnoi-cert-mgmt-getcert keyword

Synopsis

GetCertificates RPC usage

Default

deny

Options

permit, deny

Introduced

19.10.R1

Platforms

All

gnoi-cert-mgmt-install keyword

Synopsis

Install RPC usage

Default

deny

Options

permit, deny

Introduced

19.10.R1

Platforms

All

gnoi-cert-mgmt-revoke keyword

Synopsis

RevokeCertificates RPC usage

Default

deny

Options

permit, deny

Introduced

20.2.R1

Platforms

All

gnoi-cert-mgmt-rotate keyword

Synopsis

Rotate RPC usage

Default

deny

Options

permit, deny

Introduced

19.10.R1

Platforms

All

gnoi-file-get keyword

Synopsis

gNOI File Get RPC usage

Default

permit

Options

permit, deny

Introduced

21.2.R1

Platforms

All

gnoi-file-put keyword

Synopsis

gNOI File Put RPC usage

Default

permit

Options

permit, deny

Introduced

21.2.R1

Platforms

All

gnoi-file-remove keyword

Synopsis

gNOI File Remove RPC usage

Default

permit

Options

permit, deny

Introduced

21.2.R1

Platforms

All

gnoi-file-stat keyword

Synopsis

gNOI File Stat RPC usage

Default

permit

Options

permit, deny

Introduced

21.2.R1

Platforms

All

gnoi-system-cancelreboot keyword

Synopsis

gNOI System CancelReboot RPC usage

Default

deny

Options

permit, deny

Introduced

20.5.R1

Platforms

All

gnoi-system-reboot keyword

Synopsis

gNOI System Reboot RPC authorization

Default

deny

Options

permit, deny

Introduced

20.5.R1

Platforms

All

gnoi-system-rebootstatus keyword

Synopsis

gNOI System RebootStatus RPC authorization

Default

deny

Options

permit, deny

Introduced

20.5.R1

Platforms

All

gnoi-system-setpackage keyword

Synopsis

gNOI System SetPackage RPC usage

Default

deny

Options

permit, deny

Introduced

20.5.R1

Platforms

All

gnoi-system-switchcontrolprocessor keyword

Synopsis

gNOI System SwitchControlProcessor RPC usage

Default

deny

Options

permit, deny

Introduced

20.5.R1

Platforms

All

md-cli-session keyword

Synopsis

gNOI MdCli Session RPC authorization

Default

permit

Options

permit, deny

Introduced

20.5.R1

Platforms

All

rib-api-getversion keyword

Synopsis

RibApi GetVersion RPC authorization

Default

permit

Options

permit, deny

Introduced

16.0.R4

Platforms

All

rib-api-modify keyword

Synopsis

RibApi Modify RPC authorization

Default

permit

Options

permit, deny

Introduced

16.0.R4

Platforms

All

li boolean

Synopsis

Allow lawful intercept profile ID

Tree
Default

false

Introduced

19.10.R1

Platforms

All

netconf

Synopsis

Enter the netconf context

Tree
Introduced

16.0.R1

Platforms

All

base-op-authorization

Synopsis

Enter the base-op-authorization context

Introduced

16.0.R1

Platforms

All

kill-session boolean

Synopsis

Allow NETCONF kill-session operation

Default

false

Introduced

16.0.R1

Platforms

All

lock boolean

Synopsis

Allow NETCONF lock and unlock operations

Tree
Default

false

Introduced

16.0.R1

Platforms

All

ssh-max-sessions number

Synopsis

Maximum number of concurrent SSH sessions

Range

0 to 50

Introduced

16.0.R1

Platforms

All

telnet-max-sessions number

Synopsis

Maximum number of concurrent Telnet sessions

Range

0 to 50

Introduced

16.0.R1

Platforms

All

management-interface

Synopsis

Enter the management-interface context

Introduced

20.10.R1

Platforms

All

md-cli

Synopsis

Enter the md-cli context

Tree
Introduced

20.10.R1

Platforms

All

command-accounting-during-load boolean

Synopsis

Perform remote command accounting during a load or rollback operation

Default

true

Introduced

20.10.R1

Platforms

All

output-authorization

Synopsis

Enter the output-authorization context

Introduced

20.10.R1

Platforms

All

md-interfaces boolean

Synopsis

Perform output authorization

Default

true

Introduced

20.10.R1

Platforms

All

telemetry-data boolean

Synopsis

Perform telemetry data notification authorization

Default

false

Introduced

20.10.R1

Platforms

All

remote-servers

Synopsis

Enter the remote-servers context

Introduced

16.0.R1

Platforms

All

ldap

Synopsis

Enter the ldap context

Tree
Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of the LDAP protocol

Default

enable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

public-key-authentication boolean

Synopsis

Allow SSH public key authentication from LDAP server

Default

false

Introduced

16.0.R1

Platforms

All

route-preference keyword

Synopsis

Route preference to reach the AAA server

Description

This command specifies the routing preference to reach the AAA server. If the configured option is to use both in-band and out-of-band routes, the out-of-band routes in the Base routing instance are used to reach the server before the in-band routes in the management routing instance.

Default

both

Options

both, inband, outband

Introduced

21.5.R1

Platforms

All

server [index] number

Synopsis

Enter the server list instance

Tree
Max. Elements

5

Introduced

16.0.R1

Platforms

All

[index] number

Synopsis

LDAP server ID

Range

1 to 5

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

address [ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)

Synopsis

Enter the address list instance

Context

configure system security aaa remote-servers ldap server number address (ipv4-address-no-zone | ipv6-address-no-zone)

Tree
Max. Elements

1

Introduced

16.0.R1

Platforms

All

[ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)

Synopsis

LDAP server address

Context

configure system security aaa remote-servers ldap server number address (ipv4-address-no-zone | ipv6-address-no-zone)

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

port number

Synopsis

Port number on which to contact the LDAP server

Context

configure system security aaa remote-servers ldap server number address (ipv4-address-no-zone | ipv6-address-no-zone) port number

Tree
Range

1 to 65535

Default

389

Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of the LDAP server

Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

bind-authentication

Synopsis

Enter the bind-authentication context

Introduced

16.0.R1

Platforms

All

password string

Synopsis

Password used for authentication with the LDAP server

Tree
String Length

1 to 199

Introduced

16.0.R1

Platforms

All

root-dn string

Synopsis

Root domain used for authentication with LDAP server

Tree
String Length

1 to 512

Introduced

16.0.R1

Platforms

All

search

Synopsis

Enter the search context

Tree
Introduced

16.0.R1

Platforms

All

base-dn string

Synopsis

LDAP server search base domain name

Tree
String Length

1 to 512

Introduced

16.0.R1

Platforms

All

server-name string

Synopsis

LDAP server name

String Length

1 to 32

Introduced

16.0.R1

Platforms

All

tls-profile reference

Synopsis

TLS client profile used to encrypt the LDAP connection

Introduced

16.0.R1

Platforms

All

server-retry number

Synopsis

Number of attempts to retry contacting the LDAP server

Range

1 to 10

Default

3

Introduced

16.0.R1

Platforms

All

server-timeout number

Synopsis

Timeout for a response from the LDAP server

Range

1 to 90

Default

3

Units

seconds

Introduced

16.0.R1

Platforms

All

use-default-template boolean

Synopsis

Apply the default template to LDAP

Default

true

Introduced

16.0.R1

Platforms

All

radius

Synopsis

Enter the radius context

Tree
Introduced

16.0.R1

Platforms

All

access-algorithm keyword

Synopsis

Algorithm used to access the set of RADIUS servers

Default

direct

Options

direct, round-robin

Introduced

16.0.R1

Platforms

All

accounting boolean

Synopsis

Enable RADIUS command accounting

Default

false

Introduced

16.0.R1

Platforms

All

accounting-port number

Synopsis

Port number on RADIUS server for accounting requests

Range

1 to 65535

Default

1813

Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of RADIUS authentication

Default

enable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

authorization boolean

Synopsis

Enable RADIUS authorization

Default

false

Introduced

16.0.R1

Platforms

All

interactive-authentication boolean

Synopsis

Enable RADIUS interactive authentication

Default

false

Introduced

16.0.R1

Platforms

All

port number

Synopsis

TCP port number on which to contact RADIUS server

Tree
Range

1 to 65535

Default

1812

Introduced

16.0.R1

Platforms

All

route-preference keyword

Synopsis

Route preference to reach the AAA server

Description

This command specifies the routing preference to reach the AAA server. If the configured option is to use both in-band and out-of-band routes, the out-of-band routes in the Base routing instance are used to reach the server before the in-band routes in the management routing instance.

Default

both

Options

both, inband, outband

Introduced

21.5.R1

Platforms

All

server [index] number

Synopsis

Enter the server list instance

Tree
Max. Elements

5

Introduced

16.0.R1

Platforms

All

[index] number

Synopsis

RADIUS server ID

Range

1 to 5

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

address (ipv4-address-no-zone | ipv6-address-no-zone)

Synopsis

IP address of the RADIUS server

Context

configure system security aaa remote-servers radius server number address (ipv4-address-no-zone | ipv6-address-no-zone)

Tree
Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

secret string

Synopsis

Secret key to access the RADIUS server

Tree
String Length

1 to 115

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

server-retry number

Synopsis

Number of attempts to retry contacting RADIUS server

Range

1 to 10

Default

3

Introduced

16.0.R1

Platforms

All

server-timeout number

Synopsis

Time to wait for a response from the RADIUS server

Range

1 to 90

Default

3

Units

seconds

Introduced

16.0.R1

Platforms

All

use-default-template boolean

Synopsis

Apply the RADIUS default user template to RADIUS user

Default

false

Introduced

16.0.R1

Platforms

All

tacplus

Synopsis

Enter the tacplus context

Tree
Introduced

16.0.R1

Platforms

All

accounting

Synopsis

Enable the accounting context

Introduced

16.0.R1

Platforms

All

record-type keyword

Synopsis

Type of accounting record packet sent to TACACS+ server

Default

stop-only

Options

start-stop, stop-only

Introduced

16.0.R1

Platforms

All

admin-control

Synopsis

Enter the admin-control context

Introduced

16.0.R1

Platforms

All

tacplus-map-to-priv-lvl number

Synopsis

Interactive authentication from node to TACACS+ server

Range

0 to 15

Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of the TACACS+ protocol operation

Default

enable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

authorization

Synopsis

Enable the authorization context

Introduced

16.0.R1

Platforms

All

use-priv-lvl boolean

Synopsis

Allow privilege level mapping

Default

false

Introduced

16.0.R1

Platforms

All

interactive-authentication boolean

Synopsis

Allows TACACS+ interactive authentication

Default

false

Introduced

16.0.R1

Platforms

All

priv-lvl-map

Synopsis

Enter the priv-lvl-map context

Introduced

16.0.R1

Platforms

All

priv-lvl [level] number

Synopsis

Enter the priv-lvl list instance

Tree
Introduced

16.0.R1

Platforms

All

[level] number

Synopsis

Privilege level for the mapping

Range

0 to 15

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

user-profile-name reference

Synopsis

User profile for the mapping

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

route-preference keyword

Synopsis

Route preference to reach the AAA server

Description

This command specifies the routing preference to reach the AAA server. If the configured option is to use both in-band and out-of-band routes, the out-of-band routes in the Base routing instance are used to reach the server before the in-band routes in the management routing instance.

Default

both

Options

both, inband, outband

Introduced

21.5.R1

Platforms

All

server [index] number

Synopsis

Enter the server list instance

Tree
Max. Elements

5

Introduced

16.0.R1

Platforms

All

[index] number

Synopsis

TACACS+ server ID

Range

1 to 5

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

address (ipv4-address-no-zone | ipv6-address-no-zone)

Synopsis

IP address of TACACS+ server.

Context

configure system security aaa remote-servers tacplus server number address (ipv4-address-no-zone | ipv6-address-no-zone)

Tree
Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

port number

Synopsis

TCP port ID on which to contact TACACS+ server

Tree
Range

0 | 1 to 65535

Default

49

Introduced

16.0.R1

Platforms

All

secret string

Synopsis

Secret key to access the TACACS+ server

Tree
String Length

1 to 199

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

server-timeout number

Synopsis

Time to wait for a response from the TACACS+ server

Range

1 to 90

Default

3

Units

seconds

Introduced

16.0.R1

Platforms

All

use-default-template boolean

Synopsis

Apply TACACS+ default user-template to TACACS+ user

Default

true

Introduced

16.0.R1

Platforms

All

user-template [user-template-name] keyword

Synopsis

Enter the user-template list instance

Introduced

16.0.R1

Platforms

All

[user-template-name] keyword

Synopsis

Default user template applied to the system user

Options

ldap-default, radius-default, tacplus-default

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

access

Synopsis

Enter the access context

Tree
Introduced

16.0.R1

Platforms

All

console boolean

Synopsis

Allow console access (serial port or Telnet)

Tree
Default

true

Introduced

16.0.R1

Platforms

All

ftp boolean

Synopsis

Allow FTP access

Tree
Default

false

Introduced

16.0.R1

Platforms

All

grpc boolean

Synopsis

Allow gRPC access

Tree
Default

false

Introduced

16.0.R1

Platforms

All

li boolean

Synopsis

Allow access to lawful intercept

Tree
Default

false

Introduced

19.10.R1

Platforms

All

netconf boolean

Synopsis

Allow NETCONF session access

Tree
Default

false

Introduced

16.0.R1

Platforms

All

console

Synopsis

Enter the console context

Tree
Introduced

16.0.R1

Platforms

All

login-exec string

Synopsis

File to execute for a successful user login via console

String Length

1 to 200

Introduced

16.0.R1

Platforms

All

home-directory (sat-url | cflash-without-slot-url)

Synopsis

User local home directory based on the template

Context

configure system security aaa user-template keyword home-directory (sat-url | cflash-without-slot-url)

String Length

1 to 200

Introduced

16.0.R1

Platforms

All

profile string

Synopsis

User profile based on the template

Tree
String Length

1 to 32

Introduced

16.0.R1

Platforms

All

restricted-to-home boolean

Synopsis

Prevent user navigation above the home directory

Default

false

Introduced

16.0.R1

Platforms

All

cli-script

Synopsis

Enter the cli-script context

Introduced

16.0.R1

Platforms

All

authorization

Synopsis

Enter the authorization context

Introduced

16.0.R1

Platforms

All

cron

Synopsis

Enter the cron context

Tree
Introduced

16.0.R1

Platforms

All

cli-user reference

Synopsis

User profile name for CLI command script authorization

Tree
Introduced

16.0.R1

Platforms

All

event-handler

Synopsis

Enter the event-handler context

Introduced

16.0.R1

Platforms

All

cli-user reference

Synopsis

User profile name for CLI command script authorization

Tree
Introduced

16.0.R1

Platforms

All

vsd

Synopsis

Enter the vsd context

Tree
Introduced

16.0.R1

Platforms

All

cli-user reference

Synopsis

User profile name for CLI command script authorization

Tree
Introduced

16.0.R1

Platforms

All

cpm-filter

Synopsis

Enter the cpm-filter context

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

default-action keyword

Synopsis

Action for packets that do not match any filter entries

Default

accept

Options

drop, accept

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ip-filter

Synopsis

Enter the ip-filter context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

admin-state keyword

Synopsis

Administrative state of the CPM filter

Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

entry [entry-id] number

Synopsis

Enter the entry list instance

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

[entry-id] number

Synopsis

Filter entry ID

Range

1 to 131072

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

action

Synopsis

Enter the action context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

accept

Synopsis

Forward matching packets

Tree
Notes

The following are part of a choice: accept, default, drop, or queue.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

default

Synopsis

Use default action for matching packets

Tree
Notes

The following are part of a choice: accept, default, drop, or queue.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

drop

Synopsis

Drop matching packets

Tree
Notes

The following are part of a choice: accept, default, drop, or queue.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

queue reference

Synopsis

Forward matching packets to the CPM hardware queue

Tree
Notes

The following are part of a choice: accept, default, drop, or queue.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

log reference

Synopsis

Log ID where matching packets are entered

Tree
Reference
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

match

Synopsis

Enter the match context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

dscp keyword

Synopsis

DSCP used as the match criterion on the packet

Tree
Options

be, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

dst-ip

Synopsis

Enter the dst-ip context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

address (ipv4-address | ipv4-prefix-with-host-bits)

Synopsis

IP address used as the match criterion

Context

configure system security cpm-filter ip-filter entry number match dst-ip address (ipv4-address | ipv4-prefix-with-host-bits)

Tree
Notes

The following are part of a choice: (address and mask) or ip-prefix-list.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ip-prefix-list reference

Synopsis

IP prefix list used as match criterion

Notes

The following are part of a choice: (address and mask) or ip-prefix-list.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mask string

Synopsis

Address mask as the match criterion

Tree
Notes

The following are part of a choice: (address and mask) or ip-prefix-list.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

dst-port

Synopsis

Enter the dst-port context

Tree
Notes

The following are part of a choice: port or (dst-port and src-port).

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eq number

Synopsis

Port number as the match criterion

Tree
Range

0 to 65535

Notes

The following are part of a choice: (eq and mask), port-list, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mask number

Synopsis

Port mask as the match criterion

Tree
Range

1 to 65535

Default

65535

Notes

The following are part of a choice: (eq and mask), port-list, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

port-list reference

Synopsis

Port list as the match criterion

Tree
Notes

The following are part of a choice: (eq and mask), port-list, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

range

Synopsis

Enable the range context

Tree
Notes

The following are part of a choice: (eq and mask), port-list, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

end number

Synopsis

Upper bound of the port number to match

Tree
Range

0 to 65535

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

start number

Synopsis

Lower bound of the port number to match

Tree
Range

0 to 65535

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fragment keyword

Synopsis

Match criterion based on presence of fragmented packets

Tree
Options

false, true

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

icmp

Synopsis

Enter the icmp context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

code number

Synopsis

ICMP code to match

Tree
Range

0 to 255

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

type number

Synopsis

ICMP type to match

Tree
Range

0 to 255

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ip-option

Synopsis

Enable the ip-option context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mask number

Synopsis

Mask that is ANDed with ip-option value in the packet header

Tree
Range

1 to 255

Default

255

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

type number

Synopsis

Specific IP option to match

Tree
Range

0 to 255

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

multiple-option boolean

Synopsis

Specifies whether multiple options are to be matched.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

option-present boolean

Synopsis

Specifies whether IP options matching is enabled.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

port

Synopsis

Enter the port context

Tree
Notes

The following are part of a choice: port or (dst-port and src-port).

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eq number

Synopsis

Port number as the match criterion

Tree
Range

0 to 65535

Notes

The following are part of a choice: (eq and mask), port-list, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mask number

Synopsis

Port mask as the match criterion

Tree
Range

1 to 65535

Default

65535

Notes

The following are part of a choice: (eq and mask), port-list, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

port-list reference

Synopsis

Port list as the match criterion

Tree
Notes

The following are part of a choice: (eq and mask), port-list, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

range

Synopsis

Enable the range context

Tree
Notes

The following are part of a choice: (eq and mask), port-list, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

end number

Synopsis

Upper bound of the port number to match

Tree
Range

0 to 65535

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

start number

Synopsis

Lower bound of the port number to match

Tree
Range

0 to 65535

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

protocol (number | keyword)

Synopsis

IP protocol as the match criterion

Context
Tree
Range

0 to 255

Options

tcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

router-instance string

Synopsis

Router instance as the match criteria

String Length

1 to 64

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

src-ip

Synopsis

Enter the src-ip context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

address (ipv4-address | ipv4-prefix-with-host-bits)

Synopsis

IP address used as the match criterion

Context

configure system security cpm-filter ip-filter entry number match src-ip address (ipv4-address | ipv4-prefix-with-host-bits)

Tree
Notes

The following are part of a choice: (address and mask) or ip-prefix-list.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ip-prefix-list reference

Synopsis

IP prefix list used as match criterion

Notes

The following are part of a choice: (address and mask) or ip-prefix-list.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mask string

Synopsis

Address mask as the match criterion

Tree
Notes

The following are part of a choice: (address and mask) or ip-prefix-list.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

src-port

Synopsis

Enter the src-port context

Tree
Notes

The following are part of a choice: port or (dst-port and src-port).

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eq number

Synopsis

Port number as the match criterion

Tree
Range

0 to 65535

Notes

The following are part of a choice: (eq and mask), port-list, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mask number

Synopsis

Port mask as the match criterion

Tree
Range

1 to 65535

Default

65535

Notes

The following are part of a choice: (eq and mask), port-list, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

port-list reference

Synopsis

Port list as the match criterion

Tree
Notes

The following are part of a choice: (eq and mask), port-list, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

range

Synopsis

Enable the range context

Tree
Notes

The following are part of a choice: (eq and mask), port-list, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

end number

Synopsis

Upper bound of the port number to match

Tree
Range

0 to 65535

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

start number

Synopsis

Lower bound of the port number to match

Tree
Range

0 to 65535

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

tcp-flags

Synopsis

Enter the tcp-flags context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ack boolean

Synopsis

ACK bit in TCP header control bits as match criterion

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

syn boolean

Synopsis

SYN bit in TCP header control bits as match criterion

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ipv6-filter

Synopsis

Enter the ipv6-filter context

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

admin-state keyword

Synopsis

Administrative state of the CPM filter

Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

entry [entry-id] number

Synopsis

Enter the entry list instance

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

[entry-id] number

Synopsis

Filter entry ID

Range

1 to 131072

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

action

Synopsis

Enter the action context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

accept

Synopsis

Forward matching packets

Tree
Notes

The following are part of a choice: accept, default, drop, or queue.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

default

Synopsis

Use default action for matching packets

Tree
Notes

The following are part of a choice: accept, default, drop, or queue.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

drop

Synopsis

Drop matching packets

Tree
Notes

The following are part of a choice: accept, default, drop, or queue.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

queue reference

Synopsis

Forward matching packets to the CPM hardware queue

Tree
Notes

The following are part of a choice: accept, default, drop, or queue.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

log reference

Synopsis

Log ID where matching packets are entered

Tree
Reference
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

match

Synopsis

Enter the match context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

dscp keyword

Synopsis

DSCP used as the match criterion on the packet

Tree
Options

be, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

dst-ip

Synopsis

Enter the dst-ip context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

address (ipv6-address | ipv6-prefix-with-host-bits)

Synopsis

IP address as the match criterion

Context

configure system security cpm-filter ipv6-filter entry number match dst-ip address (ipv6-address | ipv6-prefix-with-host-bits)

Tree
Notes

The following are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ipv6-prefix-list reference

Synopsis

IPv6 prefix list as match criterion for IP address

Notes

The following are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mask string

Synopsis

IPv6 address mask as the match criterion

Tree
Notes

The following are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

dst-port

Synopsis

Enter the dst-port context

Tree
Notes

The following are part of a choice: port or (dst-port and src-port).

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eq number

Synopsis

Port number as the match criterion

Tree
Range

0 to 65535

Notes

The following are part of a choice: (eq and mask), port-list, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mask number

Synopsis

Port mask as the match criterion

Tree
Range

1 to 65535

Default

65535

Notes

The following are part of a choice: (eq and mask), port-list, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

port-list reference

Synopsis

Port list as the match criterion

Tree
Notes

The following are part of a choice: (eq and mask), port-list, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

range

Synopsis

Enable the range context

Tree
Notes

The following are part of a choice: (eq and mask), port-list, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

end number

Synopsis

Upper bound of the port number to match

Tree
Range

0 to 65535

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

start number

Synopsis

Lower bound of the port number to match

Tree
Range

0 to 65535

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

extension-header

Synopsis

Enter the extension-header context

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

hop-by-hop boolean

Synopsis

Match on existence of Hop-By-Hop Options Header

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

flow-label number

Synopsis

Flow label in the IPv6 header as the match criterion

Range

0 to 1048575

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fragment keyword

Synopsis

Match criterion based on presence of fragmented packets

Tree
Options

false, true

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

icmp

Synopsis

Enter the icmp context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

code number

Synopsis

ICMP code as the match criterion

Tree
Range

0 to 255

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

type number

Synopsis

ICMP type as the match criterion

Tree
Range

0 to 255

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

next-header (number | keyword)

Synopsis

IP protocol to match

Range

0 to 255

Options

tcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

port

Synopsis

Enter the port context

Tree
Notes

The following are part of a choice: port or (dst-port and src-port).

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eq number

Synopsis

Port number as the match criterion

Tree
Range

0 to 65535

Notes

The following are part of a choice: (eq and mask), port-list, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mask number

Synopsis

Port mask as the match criterion

Tree
Range

1 to 65535

Default

65535

Notes

The following are part of a choice: (eq and mask), port-list, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

port-list reference

Synopsis

Port list as the match criterion

Tree
Notes

The following are part of a choice: (eq and mask), port-list, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

range

Synopsis

Enable the range context

Tree
Notes

The following are part of a choice: (eq and mask), port-list, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

end number

Synopsis

Upper bound of the port number to match

Tree
Range

0 to 65535

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

start number

Synopsis

Lower bound of the port number to match

Tree
Range

0 to 65535

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

router-instance string

Synopsis

Router instance as the match criteria

String Length

1 to 64

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

src-ip

Synopsis

Enter the src-ip context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

address (ipv6-address | ipv6-prefix-with-host-bits)

Synopsis

IP address as the match criterion

Context

configure system security cpm-filter ipv6-filter entry number match src-ip address (ipv6-address | ipv6-prefix-with-host-bits)

Tree
Notes

The following are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ipv6-prefix-list reference

Synopsis

IPv6 prefix list as match criterion for IP address

Notes

The following are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mask string

Synopsis

IPv6 address mask as the match criterion

Tree
Notes

The following are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

src-port

Synopsis

Enter the src-port context

Tree
Notes

The following are part of a choice: port or (dst-port and src-port).

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eq number

Synopsis

Port number as the match criterion

Tree
Range

0 to 65535

Notes

The following are part of a choice: (eq and mask), port-list, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mask number

Synopsis

Port mask as the match criterion

Tree
Range

1 to 65535

Default

65535

Notes

The following are part of a choice: (eq and mask), port-list, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

port-list reference

Synopsis

Port list as the match criterion

Tree
Notes

The following are part of a choice: (eq and mask), port-list, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

range

Synopsis

Enable the range context

Tree
Notes

The following are part of a choice: (eq and mask), port-list, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

end number

Synopsis

Upper bound of the port number to match

Tree
Range

0 to 65535

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

start number

Synopsis

Lower bound of the port number to match

Tree
Range

0 to 65535

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

tcp-flags

Synopsis

Enter the tcp-flags context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ack boolean

Synopsis

ACK bit in TCP header control bits as match criterion

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

syn boolean

Synopsis

SYN bit in TCP header control bits as match criterion

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mac-filter

Synopsis

Enter the mac-filter context

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

admin-state keyword

Synopsis

Administrative state of the CPM filter

Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

entry [entry-id] number

Synopsis

Enter the entry list instance

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

[entry-id] number

Synopsis

Filter entry ID

Range

1 to 131072

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

action

Synopsis

Enter the action context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

accept

Synopsis

Forward matching packets

Tree
Notes

The following are part of a choice: accept, default, drop, or queue.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

default

Synopsis

Use default action for matching packets

Tree
Notes

The following are part of a choice: accept, default, drop, or queue.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

drop

Synopsis

Drop matching packets

Tree
Notes

The following are part of a choice: accept, default, drop, or queue.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

queue reference

Synopsis

Forward matching packets to the CPM hardware queue

Tree
Notes

The following are part of a choice: accept, default, drop, or queue.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

log reference

Synopsis

Log ID where matching packets are entered

Tree
Reference
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

match

Synopsis

Enter the match context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

cfm-opcode

Synopsis

Enter the cfm-opcode context

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eq number

Synopsis

Equal to comparison operator for the CFM opcode

Tree
Range

0 to 255

Notes

The following are part of a choice: eq, gt, lt, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

gt number

Synopsis

Greater than comparison operator for the CFM opcode

Tree
Range

0 to 254

Notes

The following are part of a choice: eq, gt, lt, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

lt number

Synopsis

Less than comparison operator for the CFM opcode

Tree
Range

1 to 255

Notes

The following are part of a choice: eq, gt, lt, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

range

Synopsis

Enable the range context

Tree
Notes

The following are part of a choice: eq, gt, lt, or range.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

end number

Synopsis

Upper bound of the Opcode range to match

Tree
Range

1 to 255

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

start number

Synopsis

Lower bound of the OpCode range to match

Tree
Range

0 to 254

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

dst-mac

Synopsis

Enable the dst-mac context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

address string

Synopsis

MAC address used as the match criterion

Tree
Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mask string

Synopsis

MAC address mask as the match criterion

Tree
Default

ff:ff:ff:ff:ff:ff

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

etype string

Synopsis

Ethernet type as the match criterion

Tree
Description

This command specifies an Ethernet type II Ethertype value to be used as a MAC filter match criterion.

The Ethernet type field is used by the Ethernet version-II frames and does not apply to IEEE 802.3 Ethernet frames.

String Length

5 to 6

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

frame-type keyword

Synopsis

MAC frame type as the match criterion

Options

802dot2-llc, ethernet-ii

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

llc-dsap

Synopsis

Enable the llc-dsap context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

dsap number

Synopsis

8-bit DSAP as the match criterion

Tree
Range

0 to 255

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mask number

Synopsis

Mask for DSAP value as the match criterion

Tree
Range

1 to 255

Default

255

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

llc-ssap

Synopsis

Enable the llc-ssap context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mask number

Synopsis

Mask for SSAP value as the match criterion

Tree
Range

1 to 255

Default

255

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ssap number

Synopsis

8-bit SSAP as the match criterion

Tree
Range

0 to 255

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

service reference

Synopsis

Service ID used as the match condition

Tree
Reference
Introduced

16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

src-mac

Synopsis

Enable the src-mac context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

address string

Synopsis

MAC address used as the match criterion

Tree
Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mask string

Synopsis

MAC address mask as the match criterion

Tree
Default

ff:ff:ff:ff:ff:ff

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

cpm-queue

Synopsis

Enter the cpm-queue context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

queue [queue-id] number

Synopsis

Enter the queue list instance

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

[queue-id] number

Synopsis

CPM queue ID

Range

33 to 2000

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

cbs number

Synopsis

Buffer size that can be drawn from queue buffer pool

Context
Tree
Range

0 to 131072

Units

kilobps

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mbs number

Synopsis

Maximum queue depth to which the queue can grow

Context
Tree
Range

0 to 131072

Units

kilobps

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

rate

Synopsis

Enter the rate context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

cir (number | keyword)

Synopsis

Amount of bandwidth committed to the queue

Context

configure system security cpm-queue queue number rate cir (number | keyword)

Tree
Range

0 to 100000000

Default

max

Units

kilobps

Options

max

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

pir (number | keyword)

Synopsis

Peak information Rate for the queue

Context

configure system security cpm-queue queue number rate pir (number | keyword)

Tree
Range

1 to 100000000

Default

max

Units

kilobps

Options

max

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

cpu-protection

Synopsis

Enter the cpu-protection context

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

ip-src-monitoring

Synopsis

Enter the ip-src-monitoring context

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

included-protocols

Synopsis

Enter the included-protocols context

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

dhcp boolean

Synopsis

Include extracted DHCP packets for IP source monitoring

Tree
Default

true

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

gtp boolean

Synopsis

Include extracted GTP packets for IP source monitoring

Tree
Default

false

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

icmp boolean

Synopsis

Include extracted ICMP packets for IP source monitoring

Tree
Default

false

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

igmp boolean

Synopsis

Include extracted IGMP packets for IP source monitoring

Tree
Default

false

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

link-specific-rate (number | keyword)

Synopsis

Packet arrival rate limit for link level protocols

Range

1 to 65535

Units

packets per second

Options

max

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

policy [policy-id] number

Synopsis

Enter the policy list instance

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

[policy-id] number

Synopsis

Policy ID

Range

1 to 255

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

alarm boolean

Synopsis

Generate an event when the rate is exceeded

Tree
Default

true

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

eth-cfm

Synopsis

Enter the eth-cfm context

Tree
Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

entry [id] number

Synopsis

Enter the entry list instance

Tree
Max. Elements

10

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

[id] number

Synopsis

Entry ID

Range

1 to 100

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

level start number end number

Synopsis

Add a list entry for level

Context
Tree
Min. Elements

1

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

start number

Synopsis

Lower bound of the level range

Context
Range

0 to 7

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

end number

Synopsis

Upper bound of the level range

Context
Range

0 to 7

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

opcode start number end number

Synopsis

Add a list entry for opcode

Context
Tree
Min. Elements

1

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

start number

Synopsis

Lower bound of the OpCode range

Context
Range

0 to 255

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

end number

Synopsis

Upper bound of the OpCode range

Context
Range

0 to 255

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

pir (number | keyword)

Synopsis

Packet arrival rate limit

Context

configure system security cpu-protection policy number eth-cfm entry number pir (number | keyword)

Tree
Range

0 to 65534

Default

max

Units

packets per second

Options

max

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

out-profile-rate

Synopsis

Enter the out-profile-rate context

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

log-events boolean

Synopsis

Generate a log event when the packet rate is exceeded

Default

false

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

pir (number | keyword)

Synopsis

Packet arrival rate limit

Tree
Range

1 to 65534

Units

packets per second

Options

max

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

overall-rate (number | keyword)

Synopsis

Overall packet arrival rate limit to apply for all sources of packets

Context
Range

1 to 65534

Units

packets per second

Options

max

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

per-source-parameters

Synopsis

Enter the per-source-parameters context

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

ip-src-monitoring

Synopsis

Enter the ip-src-monitoring context

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

limit-dhcp-ci-addr-zero boolean

Synopsis

Apply per-source rate limiting to DHCP packets containing Client IP address zero

Default

false

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

per-source-rate (number | keyword)

Synopsis

Per-source packet arrival rate limit

Context
Range

1 to 65534

Default

max

Units

packets per second

Options

max

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

port-overall-rate

Synopsis

Enter the port-overall-rate context

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

action-low-priority boolean

Synopsis

Mark packets that exceed the rate as low-priority

Default

false

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

pir (number | keyword)

Synopsis

Per-port packet arrival rate limit

Tree
Range

1 to 65535

Units

packets per second

Options

max

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

protocol-protection

Synopsis

Enable the protocol-protection context

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

allow-sham-links boolean

Synopsis

Allow OSPF sham-link traffic over VPRN transport tunnels

Default

false

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

block-pim-tunneled boolean

Synopsis

Block extraction and processing of PIM packets that arrive inside a tunnel

Default

false

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

dist-cpu-protection

Synopsis

Enter the dist-cpu-protection context

Introduced

16.0.R1

Platforms

All

policy [policy-name] string

Synopsis

Enter the policy list instance

Tree
Description

Commands in this context configure the attributes of DCP policies. These policies can be applied to objects such as SAPs, network interfaces or ports

Max. Elements

18

Introduced

16.0.R1

Platforms

All

[policy-name] string

Synopsis

Policy name

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R1

Platforms

All

local-monitoring-policer [policer-name] string

Synopsis

Enter the local-monitoring-policer list instance

Max. Elements

1

Introduced

16.0.R1

Platforms

All

[policer-name] string

Synopsis

Local monitoring policer name

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R1

Platforms

All

exceed-action keyword

Synopsis

Action taken when policer rates are exceeded

Default

none

Options

discard, low-priority, none

Introduced

16.0.R1

Platforms

All

log-events keyword

Synopsis

Control of log events creation for status and activity

Default

true

Options

false, true, verbose

Introduced

16.0.R1

Platforms

All

rate

Synopsis

Enter the rate context

Tree
Introduced

16.0.R1

Platforms

All

kbps

Synopsis

Enter the kbps context

Tree
Notes

The following are part of a choice: kbps or packets.

Introduced

16.0.R1

Platforms

All

limit (keyword | number)

Synopsis

Rate limit

Tree
Range

1 to 20000000

Default

max

Units

kilobps

Options

max

Introduced

16.0.R1

Platforms

All

mbs number

Synopsis

Tolerance for the rate

Tree
Range

0 to 4194304

Units

bytes

Introduced

16.0.R1

Platforms

All

packets

Synopsis

Enter the packets context

Tree
Notes

This element is the default part of a choice.

The following are part of a choice: kbps or packets.

Introduced

16.0.R1

Platforms

All

initial-delay number

Synopsis

Additional packets allowed in an initial burst

Range

0 to 255

Default

0

Units

packets

Introduced

16.0.R1

Platforms

All

limit (keyword | number)

Synopsis

Packets per interval limit

Tree
Range

0 to 8000

Default

max

Units

packets per interval

Options

max

Introduced

16.0.R1

Platforms

All

within number

Synopsis

Measurement interval for packets rate

Tree
Range

1 to 32767

Default

1

Units

seconds

Introduced

16.0.R1

Platforms

All

protocol [protocol-name] keyword

Synopsis

Enter the protocol list instance

Tree
Introduced

16.0.R1

Platforms

All

[protocol-name] keyword

Synopsis

Protocol name

Options

arp, dhcp, http-redirect, icmp, igmp, mld, ndis, pppoe-pppoa, all-unspecified, mpls-ttl, bfd-cpm, bgp, eth-cfm, isis, ldp, ospf, pim, rsvp, icmp-ping-check, lacp

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

dynamic-parameters

Synopsis

Enter the dynamic-parameters context

Introduced

16.0.R1

Platforms

All

detection-time number

Synopsis

Minimum time the dynamic policer remains allocated

Range

1 to 128000

Default

30

Units

seconds

Introduced

16.0.R1

Platforms

All

exceed-action

Synopsis

Enter the exceed-action context

Introduced

16.0.R1

Platforms

All

action keyword

Synopsis

Action taken on control packets when rates are exceeded

Tree
Default

none

Options

discard, low-priority, none

Introduced

16.0.R1

Platforms

All

hold-down (keyword | number)

Synopsis

Hold down behavior

Tree
Range

1 to 10080

Default

none

Units

seconds

Options

indefinite, none

Introduced

16.0.R1

Platforms

All

log-events keyword

Synopsis

Control of log events creation for status and activity

Default

true

Options

false, true, verbose

Introduced

16.0.R1

Platforms

All

rate

Synopsis

Enter the rate context

Tree
Introduced

16.0.R1

Platforms

All

kbps

Synopsis

Enter the kbps context

Tree
Notes

The following are part of a choice: kbps or packets.

Introduced

16.0.R1

Platforms

All

limit (keyword | number)

Synopsis

Rate limit

Tree
Range

1 to 20000000

Default

max

Units

kilobps

Options

max

Introduced

16.0.R1

Platforms

All

mbs number

Synopsis

Tolerance for the rate

Tree
Range

0 to 4194304

Units

bytes

Introduced

16.0.R1

Platforms

All

packets

Synopsis

Enter the packets context

Tree
Notes

This element is the default part of a choice.

The following are part of a choice: kbps or packets.

Introduced

16.0.R1

Platforms

All

initial-delay number

Synopsis

Additional packets allowed in an initial burst

Range

0 to 255

Default

0

Units

packets

Introduced

16.0.R1

Platforms

All

limit (keyword | number)

Synopsis

Packets per interval limit

Tree
Range

0 to 8000

Default

max

Units

packets per interval

Options

max

Introduced

16.0.R1

Platforms

All

within number

Synopsis

Measurement interval for packets rate

Tree
Range

1 to 32767

Default

1

Units

seconds

Introduced

16.0.R1

Platforms

All

enforcement

Synopsis

Enter the enforcement context

Introduced

16.0.R1

Platforms

All

dynamic

Synopsis

Enter the dynamic context

Tree
Notes

The following are part of a choice: dynamic, dynamic-local-mon-bypass, or static.

Introduced

16.0.R1

Platforms

All

mon-policer-name reference

Synopsis

Dynamic enforcement policer for the protocol

Introduced

16.0.R1

Platforms

All

dynamic-local-mon-bypass

Synopsis

Do not include packets in the local monitoring function

Notes

This element is the default part of a choice.

The following are part of a choice: dynamic, dynamic-local-mon-bypass, or static.

Introduced

16.0.R1

Platforms

All

static

Synopsis

Enter the static context

Tree
Notes

The following are part of a choice: dynamic, dynamic-local-mon-bypass, or static.

Introduced

16.0.R1

Platforms

All

policer-name reference

Synopsis

Static policer enforced by the protocol

Introduced

16.0.R1

Platforms

All

static-policer [policer-name] string

Synopsis

Enter the static-policer list instance

Max. Elements

18

Introduced

16.0.R1

Platforms

All

[policer-name] string

Synopsis

Static policer name

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R1

Platforms

All

detection-time number

Synopsis

Minimum time the dynamic policer remains allocated

Range

1 to 128000

Default

30

Units

seconds

Introduced

16.0.R1

Platforms

All

exceed-action

Synopsis

Enter the exceed-action context

Introduced

16.0.R1

Platforms

All

action keyword

Synopsis

Action taken on control packets when rates are exceeded

Tree
Default

none

Options

discard, low-priority, none

Introduced

16.0.R1

Platforms

All

hold-down (keyword | number)

Synopsis

Hold down behavior

Tree
Range

1 to 10080

Default

none

Units

seconds

Options

indefinite, none

Introduced

16.0.R1

Platforms

All

log-events keyword

Synopsis

Control of log events creation for status and activity

Default

true

Options

false, true, verbose

Introduced

16.0.R1

Platforms

All

rate

Synopsis

Enter the rate context

Tree
Introduced

16.0.R1

Platforms

All

kbps

Synopsis

Enter the kbps context

Tree
Notes

The following are part of a choice: kbps or packets.

Introduced

16.0.R1

Platforms

All

limit (keyword | number)

Synopsis

Rate limit

Tree
Range

1 to 20000000

Default

max

Units

kilobps

Options

max

Introduced

16.0.R1

Platforms

All

mbs number

Synopsis

Tolerance for the rate

Tree
Range

0 to 4194304

Units

bytes

Introduced

16.0.R1

Platforms

All

packets

Synopsis

Enter the packets context

Tree
Notes

This element is the default part of a choice.

The following are part of a choice: kbps or packets.

Introduced

16.0.R1

Platforms

All

initial-delay number

Synopsis

Additional packets allowed in an initial burst

Range

0 to 255

Default

0

Units

packets

Introduced

16.0.R1

Platforms

All

limit (keyword | number)

Synopsis

Packets per interval limit

Tree
Range

0 to 8000

Default

max

Units

packets per interval

Options

max

Introduced

16.0.R1

Platforms

All

within number

Synopsis

Measurement interval for packets rate

Tree
Range

1 to 32767

Default

1

Units

seconds

Introduced

16.0.R1

Platforms

All

type keyword

Warning:

Modifying this element recreates the parent element automatically for the new value to take effect.

Synopsis

Policy type

Tree
Options

access-network, port

Introduced

21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

dot1x

Synopsis

Enter the dot1x context

Tree
Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of port access control in a system

Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

radius-policy [policy-name] string

Synopsis

Enter the radius-policy list instance

Introduced

16.0.R1

Platforms

All

[policy-name] string

Synopsis

RADIUS server policy to use for 802.1X authentication

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of this RADIUS server policy

Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

retry number

Synopsis

Number of RADIUS requests toward the same RADIUS server

Tree
Range

1 to 10

Default

3

Introduced

16.0.R1

Platforms

All

server [server-index] number

Synopsis

Enter the server list instance

Tree
Max. Elements

5

Introduced

16.0.R1

Platforms

All

[server-index] number

Synopsis

RADIUS server index

Range

1 to 5

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

accounting-port number

Synopsis

UDP port number on which to contact the RADIUS server for accounting requests

Range

1 to 65535

Default

1813

Introduced

16.0.R1

Platforms

All

address string

Synopsis

IP address of the RADIUS server

Tree
Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

authentication-port number

Synopsis

UDP port number on which to contact the RADIUS server for authentication

Range

1 to 65535

Default

1812

Introduced

16.0.R1

Platforms

All

secret string

Synopsis

Secret key associated with the RADIUS server

Tree
String Length

1 to 54

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

type keyword

Synopsis

RADIUS server type

Context
Tree
Default

authorization

Options

authorization, accounting, combined

Introduced

16.0.R1

Platforms

All

source-address string

Synopsis

Source address of the RADIUS packet

Introduced

16.0.R1

Platforms

All

timeout number

Synopsis

Time assigned between the request retries toward the same RADIUS server

Tree
Range

1 to 90

Default

5

Units

seconds

Introduced

16.0.R1

Platforms

All

ftp-server boolean

Synopsis

Enable FTP servers running on the system

Default

false

Introduced

16.0.R1

Platforms

All

hash-control

Synopsis

Enter the hash-control context

Introduced

16.0.R4

Platforms

All

management-interface

Synopsis

Enter the management-interface context

Description

Commands in this context configure encryption parameters for different management interfaces.

Introduced

16.0.R4

Platforms

All

classic-cli

Synopsis

Enter the classic-cli context

Introduced

16.0.R4

Platforms

All

read-algorithm keyword

Synopsis

Global read algorithm for the system

Description

This command specifies how encrypted configuration secrets are interpreted and which encryption types are accepted when secrets are input into the system or read from a configuration file (for example, at system bootup time).

Default

all-hash

Options

all-hash, hash, hash2, custom

Introduced

16.0.R4

Platforms

All

write-algorithm keyword

Synopsis

Global write algorithm for the system

Description

This command specifies the format of the output for encrypted configuration secrets (for example, in the saved configuration file, or in the output of the info or show commands).

Default

hash2

Options

cleartext, hash, hash2, custom

Introduced

16.0.R4

Platforms

All

grpc

Synopsis

Enter the grpc context

Tree
Introduced

16.0.R4

Platforms

All

hash-algorithm keyword

Synopsis

Encryption format for configuration secrets

Description

This command specifies the format of the input and output for encrypted configuration secrets.

Default

hash2

Options

cleartext, hash, hash2, custom

Introduced

16.0.R4

Platforms

All

md-cli

Synopsis

Enter the md-cli context

Tree
Introduced

16.0.R4

Platforms

All

hash-algorithm keyword

Synopsis

Encryption format for configuration secrets

Description

This command specifies the format of the input and output for encrypted configuration secrets.

Default

hash2

Options

cleartext, hash, hash2, custom

Introduced

16.0.R4

Platforms

All

netconf

Synopsis

Enter the netconf context

Tree
Introduced

16.0.R4

Platforms

All

hash-algorithm keyword

Synopsis

Encryption format for configuration secrets

Description

This command specifies the format of the input and output for encrypted configuration secrets.

Default

hash2

Options

cleartext, hash, hash2, custom

Introduced

16.0.R4

Platforms

All

keychains

Synopsis

Enter the keychains context

Tree
Introduced

16.0.R1

Platforms

All

keychain [keychain-name] string

Synopsis

Enter the keychain list instance

Tree
Max. Elements

256

Introduced

16.0.R1

Platforms

All

[keychain-name] string

Synopsis

Keychain name

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of the keychain

Default

enable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

bidirectional

Synopsis

Enter the bidirectional context

Introduced

16.0.R1

Platforms

All

entry [keychain-entry-index] number

Synopsis

Enter the entry list instance

Tree
Introduced

16.0.R1

Platforms

All

[keychain-entry-index] number

Synopsis

Keychain identifier

Range

0 to 63 | 255

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of the keychain entry

Default

enable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

algorithm keyword

Warning:

Modifying this element recreates the parent element automatically for the new value to take effect.

Synopsis

Encryption algorithm used by the keychain key

Tree
Options

aes-128-cmac-96, hmac-sha-1-96, password, message-digest, hmac-md5, hmac-sha-1, hmac-sha-256

Introduced

16.0.R1

Platforms

All

authentication-key string

Warning:

Modifying this element recreates the parent element automatically for the new value to take effect.

Synopsis

The key used by the encryption algorithm to sign and authenticate protocol packets.

String Length

1 to 54

Introduced

16.0.R1

Platforms

All

begin-time string

Synopsis

Calendar date and time when the system starts using the key

Introduced

16.0.R1

Platforms

All

option keyword

Synopsis

Keychain key option

Tree
Default

none

Options

none, basic, isis-enhanced

Introduced

16.0.R1

Platforms

All

tolerance (number | keyword)

Synopsis

Time within which an eligible receive key should overlap with the active send key

Context
Tree
Range

0 to 4294967294

Default

300

Options

infinite

Introduced

16.0.R1

Platforms

All

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R1

Platforms

All

receive

Synopsis

Enter the receive context

Tree
Introduced

16.0.R1

Platforms

All

entry [keychain-entry-index] number

Synopsis

Enter the entry list instance

Tree
Introduced

16.0.R1

Platforms

All

[keychain-entry-index] number

Synopsis

Keychain identifier

Range

0 to 63 | 255

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of the keychain entry

Default

enable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

algorithm keyword

Warning:

Modifying this element recreates the parent element automatically for the new value to take effect.

Synopsis

Encryption algorithm used by the keychain key

Tree
Options

aes-128-cmac-96, hmac-sha-1-96, password, message-digest, hmac-md5, hmac-sha-1, hmac-sha-256

Introduced

16.0.R1

Platforms

All

authentication-key string

Warning:

Modifying this element recreates the parent element automatically for the new value to take effect.

Synopsis

The key used by the encryption algorithm to sign and authenticate protocol packets.

String Length

1 to 54

Introduced

16.0.R1

Platforms

All

begin-time string

Synopsis

Calendar date and time when the system starts using the key

Introduced

16.0.R1

Platforms

All

end-time string

Synopsis

Calendar date and time when the system should stop using the key

Tree
Introduced

16.0.R1

Platforms

All

tolerance (number | keyword)

Synopsis

Time within which an eligible receive key should overlap with the active send key

Context
Tree
Range

0 to 4294967294

Default

300

Options

infinite

Introduced

16.0.R1

Platforms

All

send

Synopsis

Enter the send context

Tree
Introduced

16.0.R1

Platforms

All

entry [keychain-entry-index] number

Synopsis

Enter the entry list instance

Tree
Introduced

16.0.R1

Platforms

All

[keychain-entry-index] number

Synopsis

Keychain identifier

Range

0 to 63 | 255

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of the keychain entry

Default

enable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

algorithm keyword

Warning:

Modifying this element recreates the parent element automatically for the new value to take effect.

Synopsis

Encryption algorithm used by the keychain key

Tree
Options

aes-128-cmac-96, hmac-sha-1-96, password, message-digest, hmac-md5, hmac-sha-1, hmac-sha-256

Introduced

16.0.R1

Platforms

All

authentication-key string

Warning:

Modifying this element recreates the parent element automatically for the new value to take effect.

Synopsis

The key used by the encryption algorithm to sign and authenticate protocol packets.

String Length

1 to 54

Introduced

16.0.R1

Platforms

All

begin-time string

Synopsis

Calendar date and time when the system starts using the key

Introduced

16.0.R1

Platforms

All

tcp-option-number

Synopsis

Enter the tcp-option-number context

Introduced

16.0.R1

Platforms

All

receive keyword

Synopsis

TCP option value expected in the TCP header of received packets

Tree
Default

option-254

Options

option-253, option-254, both, tcp-ao

Introduced

16.0.R1

Platforms

All

send keyword

Synopsis

TCP option value assigned in the TCP header of transmitted packets

Tree
Default

option-254

Options

option-253, option-254, tcp-ao

Introduced

16.0.R1

Platforms

All

management

Synopsis

Enter the management context

Description

Commands in this context control which management protocols can be used to access the SR OS router via the 'Base' and 'management' router instances.

Introduced

16.0.R5

Platforms

All

allow-ftp boolean

Synopsis

Allow access to the FTP server

Tree
Description

When configured to true, this command allows FTP access to the SR OS router via the 'Base' and 'management' router instances.

When configured to false, this command disallows access to the SR OS FTP server.

Default

true

Introduced

16.0.R6

Platforms

All

allow-grpc boolean

Synopsis

Allow access to the gRPC server

Description

When configured to true, this command allows access to the gRPC server via the 'Base' and 'management' router instances.

When configured to false, this command disallows gRPC server access.

Default

true

Introduced

19.5.R1

Platforms

All

allow-netconf boolean

Synopsis

Allow access to the NETCONF server

Description

When configured to true, this command allows NETCONF server access to the SR OS router via the 'Base' and 'management' router instances.

When configured to false, this command disallows access to the NETCONF server.

Default

true

Introduced

19.5.R1

Platforms

All

allow-ssh boolean

Synopsis

Allow access to the SSH server

Tree
Description

When configured to true, this command allows SSH server access to the SR OS router via the 'Base' and 'management' router instances.

When configured to false, this command disallows SSH server access.

Default

true

Introduced

16.0.R5

Platforms

All

allow-telnet boolean

Synopsis

Allow access to the IPv4 Telnet server

Description

When configured to true, this command allows IPv4 Telnet server access to the SR OS router via the 'Base' and 'management' router instances.

When configured to false, this command disallows access to the IPv4 Telnet server.

Default

true

Introduced

16.0.R5

Platforms

All

allow-telnet6 boolean

Synopsis

Allow access to the Telnet IPv6 server

Description

When configured to true, this command allows IPv6 Telnet server access to the SR OS router via the 'Base' and 'management' router instances.

When configured to false, this command disallows access to the IPv6 Telnet server.

Default

true

Introduced

16.0.R5

Platforms

All

management-access-filter

Synopsis

Enter the management-access-filter context

Introduced

16.0.R4

Platforms

All

ip-filter

Synopsis

Enter the ip-filter context

Tree
Introduced

16.0.R4

Platforms

All

admin-state keyword

Synopsis

Administrative state of management-access filters

Default

enable

Options

enable, disable

Introduced

16.0.R4

Platforms

All

default-action keyword

Synopsis

Default action for the management access filter

Default

ignore-match

Options

ignore-match, accept, drop, reject

Introduced

16.0.R4

Platforms

All

entry [entry-id] number

Synopsis

Enter the entry list instance

Tree
Introduced

16.0.R4

Platforms

All

[entry-id] number

Synopsis

The id used to uniquely identify this filter entry.

Range

1 to 9999

Notes

This element is part of a list key.

Introduced

16.0.R4

Platforms

All

action keyword

Synopsis

Specifies the default action for management access in the absence of a specific management access filter entry match.

Tree
Default

ignore-match

Options

ignore-match, accept, drop, reject

Introduced

16.0.R4

Platforms

All

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R4

Platforms

All

log-events boolean

Synopsis

Enable match logging

Default

false

Introduced

16.0.R4

Platforms

All

match

Synopsis

Enter the match context

Tree
Introduced

16.0.R4

Platforms

All

dst-port

Synopsis

Enable the dst-port context

Tree
Introduced

16.0.R4

Platforms

All

mask number

Synopsis

IP address mask as the match criterion

Tree
Range

1 to 65535

Default

65535

Introduced

16.0.R4

Platforms

All

port number

Synopsis

TCP or UDP port number as the match criterion

Tree
Range

1 to 65535

Notes

This element is mandatory.

Introduced

16.0.R4

Platforms

All

mgmt-port

Synopsis

Enter the mgmt-port context

Tree
Introduced

16.0.R4

Platforms

All

cpm

Synopsis

Specifies source cpm.

Tree
Notes

The following are part of a choice: cpm, (lag and lag-id), or port-id.

Introduced

16.0.R4

Platforms

All

lag string

Synopsis

LAG ID as the match criterion

Tree
String Length

1 to 27

Notes

The following are part of a choice: cpm, (lag and lag-id), or port-id.

Introduced

21.2.R1

Platforms

All

port-id string

Synopsis

Port ID as the match criterion

Tree
Notes

The following are part of a choice: cpm, (lag and lag-id), or port-id.

Introduced

16.0.R4

Platforms

All

protocol (number | keyword)

Synopsis

IP protocol as the match criterion

Tree
Range

0 to 255

Options

tcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp

Introduced

16.0.R4

Platforms

All

router-instance string

Synopsis

Router instance as the match criterion

Introduced

16.0.R4

Platforms

All

src-ip

Synopsis

Enter the src-ip context

Tree
Introduced

16.0.R4

Platforms

All

address (ipv4-prefix | ipv4-address)

Synopsis

IP address or IP prefix as the match criterion

Tree
Notes

The following are part of a choice: (address and mask) or ip-prefix-list.

Introduced

16.0.R4

Platforms

All

ip-prefix-list reference

Synopsis

IP prefix list as the match criterion

Notes

The following are part of a choice: (address and mask) or ip-prefix-list.

Introduced

20.7.R1

Platforms

All

mask string

Synopsis

IP address mask as the match criterion

Tree
Notes

The following are part of a choice: (address and mask) or ip-prefix-list.

Introduced

16.0.R4

Platforms

All

ipv6-filter

Synopsis

Enter the ipv6-filter context

Introduced

16.0.R4

Platforms

All

admin-state keyword

Synopsis

Administrative state of management-access filters

Default

enable

Options

enable, disable

Introduced

16.0.R4

Platforms

All

default-action keyword

Synopsis

Default action for the management access filter

Default

ignore-match

Options

ignore-match, accept, drop, reject

Introduced

16.0.R4

Platforms

All

entry [entry-id] number

Synopsis

Enter the entry list instance

Tree
Introduced

16.0.R4

Platforms

All

[entry-id] number

Synopsis

The id used to uniquely identify this filter entry.

Range

1 to 9999

Notes

This element is part of a list key.

Introduced

16.0.R4

Platforms

All

action keyword

Synopsis

Specifies the default action for management access in the absence of a specific management access filter entry match.

Tree
Default

ignore-match

Options

ignore-match, accept, drop, reject

Introduced

16.0.R4

Platforms

All

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R4

Platforms

All

log-events boolean

Synopsis

Enable match logging

Default

false

Introduced

16.0.R4

Platforms

All

match

Synopsis

Enter the match context

Tree
Introduced

16.0.R4

Platforms

All

dst-port

Synopsis

Enable the dst-port context

Tree
Introduced

16.0.R4

Platforms

All

mask number

Synopsis

IP address mask as the match criterion

Tree
Range

1 to 65535

Default

65535

Introduced

16.0.R4

Platforms

All

port number

Synopsis

TCP or UDP port number as the match criterion

Tree
Range

1 to 65535

Notes

This element is mandatory.

Introduced

16.0.R4

Platforms

All

flow-label number

Synopsis

Specifies the flow label to be matched.

Range

0 to 1048575

Introduced

16.0.R4

Platforms

All

mgmt-port

Synopsis

Enter the mgmt-port context

Tree
Introduced

16.0.R4

Platforms

All

cpm

Synopsis

Specifies source cpm.

Tree
Notes

The following are part of a choice: cpm, (lag and lag-id), or port-id.

Introduced

16.0.R4

Platforms

All

lag string

Synopsis

LAG ID as the match criterion

Tree
String Length

1 to 27

Notes

The following are part of a choice: cpm, (lag and lag-id), or port-id.

Introduced

21.2.R1

Platforms

All

port-id string

Synopsis

Port ID as the match criterion

Tree
Notes

The following are part of a choice: cpm, (lag and lag-id), or port-id.

Introduced

16.0.R4

Platforms

All

next-header (number | keyword)

Synopsis

IP protocol to match

Range

0 to 255

Options

tcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp

Introduced

16.0.R4

Platforms

All

router-instance string

Synopsis

Router instance as the match criterion

Introduced

16.0.R4

Platforms

All

src-ip

Synopsis

Enter the src-ip context

Tree
Introduced

16.0.R4

Platforms

All

address (ipv6-prefix | ipv6-address)

Synopsis

IPv6 address or IPv6 prefix to match

Tree
Notes

The following are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced

16.0.R4

Platforms

All

ipv6-prefix-list reference

Synopsis

IPv6 prefix list as the match criterion

Notes

The following are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced

20.7.R1

Platforms

All

mask string

Synopsis

IPv6 address mask as the match criterion

Tree
Notes

The following are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced

16.0.R4

Platforms

All

mac-filter

Synopsis

Enter the mac-filter context

Introduced

16.0.R4

Platforms

All

admin-state keyword

Synopsis

Administrative state of management access MAC filter

Default

enable

Options

enable, disable

Introduced

16.0.R4

Platforms

All

default-action keyword

Synopsis

Default action for the management access filter

Default

ignore-match

Options

ignore-match, accept, drop

Introduced

16.0.R4

Platforms

All

entry [entry-id] number

Synopsis

Enter the entry list instance

Tree
Introduced

16.0.R4

Platforms

All

[entry-id] number

Synopsis

The id used to uniquely identify this filter entry.

Range

1 to 9999

Notes

This element is part of a list key.

Introduced

16.0.R4

Platforms

All

action keyword

Synopsis

Action associated with the management access filter

Tree
Default

ignore-match

Options

ignore-match, accept, drop

Introduced

16.0.R4

Platforms

All

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R4

Platforms

All

log-events boolean

Synopsis

If is 'true', entry match logging is enabled.

Default

false

Introduced

16.0.R4

Platforms

All

match

Synopsis

Enter the match context

Tree
Introduced

16.0.R4

Platforms

All

cfm-opcode

Synopsis

Enter the cfm-opcode context

Introduced

16.0.R4

Platforms

All

eq number

Synopsis

Equal to comparison operator for the CFM opcode

Tree
Range

0 to 255

Notes

The following are part of a choice: eq, gt, lt, or range.

Introduced

16.0.R4

Platforms

All

gt number

Synopsis

Greater than comparison operator for the CFM opcode

Tree
Range

0 to 254

Notes

The following are part of a choice: eq, gt, lt, or range.

Introduced

16.0.R4

Platforms

All

lt number

Synopsis

Less than comparison operator for the CFM opcode

Tree
Range

1 to 255

Notes

The following are part of a choice: eq, gt, lt, or range.

Introduced

16.0.R4

Platforms

All

range

Synopsis

Enable the range context

Tree
Notes

The following are part of a choice: eq, gt, lt, or range.

Introduced

16.0.R4

Platforms

All

end number

Synopsis

Upper bound of the range for the OpCode to match

Tree
Range

1 to 255

Notes

This element is mandatory.

Introduced

16.0.R4

Platforms

All

start number

Synopsis

Lower bound of the range for the OpCode to match

Tree
Range

0 to 254

Notes

This element is mandatory.

Introduced

16.0.R4

Platforms

All

dot1p

Synopsis

Enable the dot1p context

Tree
Introduced

16.0.R4

Platforms

All

mask number

Synopsis

3-bit mask as the match criterion

Tree
Range

1 to 7

Default

7

Introduced

16.0.R4

Platforms

All

priority number

Synopsis

IEEE 802.1p value as the match criterion

Tree
Range

0 to 7

Notes

This element is mandatory.

Introduced

16.0.R4

Platforms

All

dst-mac

Synopsis

Enable the dst-mac context

Tree
Introduced

16.0.R4

Platforms

All

address string

Synopsis

MAC address used as the match criterion

Tree
Notes

This element is mandatory.

Introduced

16.0.R4

Platforms

All

mask string

Synopsis

MAC address mask as the match criterion

Tree
Default

ff:ff:ff:ff:ff:ff

Introduced

16.0.R4

Platforms

All

etype string

Synopsis

Ethernet type II Ethertype value as the match criterion

Tree
String Length

5 to 6

Introduced

16.0.R4

Platforms

All

frame-type keyword

Synopsis

MAC frame type as the match criterion

Default

802dot3

Options

802dot3, 802dot2-llc, 802dot2-snap, ethernet-ii, 802dot1-ag

Introduced

16.0.R4

Platforms

All

llc-dsap

Synopsis

Enable the llc-dsap context

Tree
Introduced

16.0.R4

Platforms

All

dsap number

Synopsis

8-bit DSAP as the match criterion

Tree
Range

0 to 255

Notes

This element is mandatory.

Introduced

16.0.R4

Platforms

All

mask number

Synopsis

Mask for DSAP value as the match criterion

Tree
Range

1 to 255

Default

255

Introduced

16.0.R4

Platforms

All

llc-ssap

Synopsis

Enable the llc-ssap context

Tree
Introduced

16.0.R4

Platforms

All

mask number

Synopsis

Mask for SSAP value as the match criterion

Tree
Range

1 to 255

Default

255

Introduced

16.0.R4

Platforms

All

ssap number

Synopsis

8-bit SSAP as the match criterion

Tree
Range

0 to 255

Notes

This element is mandatory.

Introduced

16.0.R4

Platforms

All

service string

Synopsis

Service ID used as the match condition

Tree
String Length

1 to 64

Introduced

16.0.R4

Platforms

All

snap-oui keyword

Synopsis

IEEE 802.3 LLC SNAP Ethernet Frame OUI value for match

Tree
Options

zero, non-zero

Introduced

16.0.R4

Platforms

All

snap-pid number

Synopsis

IEEE 802.3 LLC SNAP Ethernet Frame PID as the match

Tree
Range

0 to 65535

Introduced

16.0.R4

Platforms

All

src-mac

Synopsis

Enable the src-mac context

Tree
Introduced

16.0.R4

Platforms

All

address string

Synopsis

MAC address used as the match criterion

Tree
Notes

This element is mandatory.

Introduced

16.0.R4

Platforms

All

mask string

Synopsis

MAC address mask as the match criterion

Tree
Default

ff:ff:ff:ff:ff:ff

Introduced

16.0.R4

Platforms

All

per-peer-queuing boolean

Synopsis

Allow a separate control plane queue for each LDP and BGP peering session to improve DoS protection

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

pki

Synopsis

Enter the pki context

Tree
Introduced

16.0.R1

Platforms

All

ca-profile [ca-profile-name] string

Synopsis

Enter the ca-profile list instance

Max. Elements

128

Introduced

16.0.R1

Platforms

All

[ca-profile-name] string

Synopsis

Certificate Authority (CA) profile name

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of the CA profile

Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

auto-crl-update

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Enable the auto-crl-update context

Introduced

16.0.R1

Platforms

All

admin-state keyword

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Administrative state of the automatic CRL update

Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

crl-urls

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Enter the crl-urls context

Tree
Introduced

16.0.R1

Platforms

All

url-entry [entry-id] number

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Enter the url-entry list instance

Tree
Introduced

16.0.R1

Platforms

All

[entry-id] number

Synopsis

URL on this system

Range

1 to 8

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

transmission-profile reference

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

File transmission profile to update CRL

Introduced

16.0.R4

Platforms

All

url http-url-path-loose

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Location of updated CRL

Context
Tree
String Length

1 to 180

Introduced

16.0.R1

Platforms

All

periodic-update-interval number

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Interval between two consecutive CRL updates

Range

3600 to 31622400

Default

86400

Units

seconds

Introduced

16.0.R1

Platforms

All

pre-update-time number

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Time prior to the next update time of the current CRL

Range

0 to 31622400

Default

3600

Units

seconds

Introduced

16.0.R1

Platforms

All

retry-interval number

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Interval before retrying to update CRL

Range

0 to 31622400

Default

3600

Units

seconds

Introduced

16.0.R1

Platforms

All

schedule-type keyword

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Time scheduler type for an automated CRL update

Default

next-update-based

Options

next-update-based, periodic

Introduced

16.0.R1

Platforms

All

cert-file string

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Certificate file name

Tree
String Length

1 to 95

Introduced

16.0.R1

Platforms

All

cmpv2

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Enter the cmpv2 context

Tree
Introduced

16.0.R1

Platforms

All

accept-unprotected-message

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Enter the accept-unprotected-message context

Introduced

16.0.R1

Platforms

All

error-message boolean

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Accept unprotected error messages

Default

false

Introduced

16.0.R1

Platforms

All

pkiconf-message boolean

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Accept unprotected PKI confirmation messages

Default

false

Introduced

16.0.R1

Platforms

All

always-set-sender-for-ir boolean

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Subject name in CMPv2 header for all Initial Registration (IR) messages

Default

false

Introduced

16.0.R1

Platforms

All

http

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Enter the http context

Tree
Introduced

16.0.R1

Platforms

All

response-timeout number

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

HTTP response timeout

Range

1 to 3600

Default

30

Units

seconds

Introduced

16.0.R1

Platforms

All

version keyword

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

HTTP version for CMPv2 messages

Tree
Default

1.1

Options

1.0, 1.1

Introduced

16.0.R1

Platforms

All

key-list

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Enter the key-list context

Tree
Introduced

16.0.R1

Platforms

All

key [reference-number] string

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Enter the key list instance

Tree
Max. Elements

128

Introduced

16.0.R1

Platforms

All

[reference-number] string

Synopsis

Unique identifier for the CA initial authentication key

String Length

1 to 64

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

password string

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Shared secret for this CA initial authentication key

Tree
String Length

1 to 115

Introduced

16.0.R1

Platforms

All

response-signing-cert string

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

File name of the certificate to verify the signature of received CMPv2 responses

String Length

1 to 95

Introduced

16.0.R1

Platforms

All

same-recipient-nonce-for-poll-request boolean

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Same recipNonce as the last CMPv2 response for a poll request

Default

false

Introduced

16.0.R1

Platforms

All

url

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Enter the url context

Tree
Introduced

16.0.R1

Platforms

All

service-name string

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Administrative service name

String Length

1 to 64

Introduced

16.0.R1

Platforms

All

url-string http-optional-url-loose

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

URL for CMPv2

Context

configure system security pki ca-profile string cmpv2 url url-string http-optional-url-loose

String Length

1 to 180

Introduced

16.0.R1

Platforms

All

crl-file string

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Certificate Revocation List (CRL) file name

Tree
String Length

1 to 95

Introduced

16.0.R1

Platforms

All

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R1

Platforms

All

ocsp

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Enter the ocsp context

Tree
Introduced

16.0.R1

Platforms

All

responder-url http-optional-url-loose

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

HTTP URL of the OCSP responder for the CA

Context

configure system security pki ca-profile string ocsp responder-url http-optional-url-loose

String Length

1 to 180

Introduced

16.0.R1

Platforms

All

service-name string

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Administrative service name

String Length

1 to 64

Introduced

16.0.R1

Platforms

All

transmission-profile reference

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

The transmission profile for OCSP.

Introduced

16.0.R6

Platforms

All

revocation-check keyword

Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

Synopsis

Method to verify the revocation status of certificates issued by the CA

Default

crl

Options

crl, crl-optional

Introduced

16.0.R1

Platforms

All

certificate-display-format keyword

Synopsis

Display format for certificates and Certificate Revocation Lists (CRLs)

Default

ascii

Options

ascii, utf8

Introduced

16.0.R1

Platforms

All

certificate-expiration-warning

Synopsis

Enter the certificate-expiration-warning context

Introduced

16.0.R1

Platforms

All

hours number

Synopsis

Time at which the system generates the certificate expiration warning trap for in-use certificates

Tree
Range

0 to 8760

Units

hours

Introduced

16.0.R1

Platforms

All

repeat-hours number

Synopsis

Time period when the system repeatedly generates the certificate expiration warning trap

Range

0 to 8760

Default

0

Units

hours

Introduced

16.0.R1

Platforms

All

common-name-list [cn-list-name] string

Synopsis

Enter the common-name-list list instance

Max. Elements

64

Introduced

16.0.R1

Platforms

All

[cn-list-name] string

Synopsis

Name for the common name list

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

common-name [cn-index] number

Synopsis

Enter the common-name list instance

Introduced

16.0.R1

Platforms

All

[cn-index] number

Synopsis

Common name index

Range

1 to 128

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

cn-type keyword

Synopsis

Common name type

Tree
Options

ip-address, domain-name

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

cn-value string

Synopsis

Common name value

Tree
String Length

1 to 255

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

crl-expiration-warning

Synopsis

Enter the crl-expiration-warning context

Introduced

16.0.R1

Platforms

All

hours number

Synopsis

Time when the system generates the Certificate Revocation List (CRL) expiration warning trap

Tree
Range

0 to 8760

Units

hours

Introduced

16.0.R1

Platforms

All

repeat-hours number

Synopsis

Time when the system repeatedly generates the Certificate Revocation List (CRL) expiration warning trap

Range

0 to 8760

Default

0

Units

hours

Introduced

16.0.R1

Platforms

All

imported-format keyword

Synopsis

The supported encrypted file formats

Default

any

Options

any, secure

Introduced

16.0.R6

Platforms

All

maximum-cert-chain-depth number

Synopsis

Maximum depth of certificate chain verification

Range

1 to 7

Default

7

Introduced

16.0.R1

Platforms

All

snmp

Synopsis

Enter the snmp context

Tree
Introduced

16.0.R1

Platforms

All

access [group] string context string security-model keyword security-level keyword

Synopsis

Enter the access list instance

Context
Tree
Introduced

16.0.R1

Platforms

All

[group] string

Synopsis

Group name

Context
String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

context string

Synopsis

String against which the context name should match to gain access rights

Context
String Length

1 to 32

Default

_sros_none

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

security-model keyword

Synopsis

Security model

Context
Options

snmpv1, snmpv2c, usm

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

security-level keyword

Synopsis

Minimum level of security required to gain the access rights allowed by this entry

Context
Options

no-auth-no-privacy, auth-no-privacy, privacy

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

notify string

Synopsis

SNMP view for notification access

Context
Tree
Description

This command specifies the SNMP view used to control which MIB objects can be accessed for notifications.

String Length

1 to 32

Introduced

16.0.R1

Platforms

All

prefix-match keyword

Synopsis

Match type for the context

Context
Options

exact, prefix

Introduced

16.0.R1

Platforms

All

read string

Synopsis

SNMP view for read access

Context
Tree
Description

This command specifies the SNMP view used to control which MIB objects can be accessed using a read (get) operation.

String Length

1 to 32

Introduced

16.0.R1

Platforms

All

write string

Synopsis

SNMP view for write access

Context
Tree
Description

This command specifies the SNMP view used to control which MIB objects can be accessed using a write (set) operation.

String Length

1 to 32

Introduced

16.0.R1

Platforms

All

attempts

Synopsis

Enter the attempts context

Tree
Introduced

16.0.R1

Platforms

All

count number

Synopsis

Maximum unsuccessful SNMP attempts that are allowed for the specified time

Tree
Range

1 to 64

Default

20

Introduced

16.0.R1

Platforms

All

lockout number

Synopsis

Lockout period during which the host is not allowed to log in

Tree
Range

0 to 1440

Default

10

Units

minutes

Introduced

16.0.R1

Platforms

All

time number

Synopsis

Time when a number of unsuccessful attempts are made before the host is locked out

Tree
Range

0 to 60

Default

5

Units

minutes

Introduced

16.0.R1

Platforms

All

community [community-string] string

Synopsis

Enter the community list instance

Tree
Introduced

16.0.R1

Platforms

All

[community-string] string

Synopsis

Management information that is accessed when using the community string

String Length

1 to 114

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

access-permissions keyword

Synopsis

SNMP community name(s) to be used with the associated VPRN instance

Options

r, rw, rwa, mgmt, vpls-mgmt

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

source-access-list reference

Synopsis

Management information to be accessed when using the community string

Introduced

16.0.R1

Platforms

All

version keyword

Synopsis

SNMP version

Tree
Default

both

Options

v1, v2c, both

Introduced

16.0.R1

Platforms

All

source-access-list [list-name] string

Synopsis

Enter the source-access-list list instance

Max. Elements

16

Introduced

16.0.R1

Platforms

All

[list-name] string

Synopsis

Value for the name given to source access list

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

source-host [host-name] string

Synopsis

Enter the source-host list instance

Max. Elements

16

Introduced

16.0.R1

Platforms

All

[host-name] string

Synopsis

Source host entry name

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

address (ipv4-address-no-zone | ipv6-address-no-zone)

Synopsis

Address of the source host entry

Context

configure system security snmp source-access-list string source-host string address (ipv4-address-no-zone | ipv6-address-no-zone)

Tree
Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

usm-community [community-string] string

Synopsis

Enter the usm-community list instance

Introduced

16.0.R1

Platforms

All

[community-string] string

Synopsis

SNMPv1/SNMPv2 community string to determine the SNMPv3 access permission

String Length

1 to 114

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

group string

Synopsis

Group to manage the access rights of the community string

Tree
String Length

1 to 32

Introduced

16.0.R1

Platforms

All

source-access-list reference

Synopsis

Management information to be accessed when using the community string

Introduced

16.0.R1

Platforms

All

view [view-name] string subtree string

Synopsis

Enter the view list instance

Context
Tree
Introduced

16.0.R1

Platforms

All

[view-name] string

Synopsis

Name of the view to display output

Context
String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

subtree string

Synopsis

Object Identifier (OID) value

Context
String Length

1 to 256

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

mask string

Synopsis

Mask value as binary value, or hex value

Context
Tree
String Length

1 to 16

Introduced

16.0.R1

Platforms

All

type keyword

Synopsis

Type of SNMP security view mask

Context

configure system security snmp view string subtree string type keyword

Tree
Options

included, excluded

Introduced

16.0.R1

Platforms

All

source-address

Synopsis

Enter the source-address context

Introduced

16.0.R1

Platforms

All

ipv4 [application] keyword

Synopsis

Enter the ipv4 list instance

Tree
Introduced

16.0.R1

Platforms

All

[application] keyword

Synopsis

Application that uses the source IP address

Options

telnet, ftp, ssh, radius, tacplus, snmptrap, syslog, ping, traceroute, dns, sntp, ntp, cflowd, ptp, mcreporter, sflow, icmp-error, ldap

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

address string

Warning:

Modifying this element recreates the parent element automatically for the new value to take effect.

Synopsis

Source IPv4 address

Tree
Notes

The following are part of a mandatory choice: address or interface-name.

Introduced

16.0.R1

Platforms

All

interface-name string

Warning:

Modifying this element recreates the parent element automatically for the new value to take effect.

Synopsis

Interface name whose IP address to be used in all packets sent by the application

String Length

1 to 32

Notes

The following are part of a mandatory choice: address or interface-name.

Introduced

16.0.R1

Platforms

All

ipv6 [application] keyword

Synopsis

Enter the ipv6 list instance

Tree
Introduced

16.0.R1

Platforms

All

[application] keyword

Synopsis

Application which uses the source IPv6 address

Options

telnet, ftp, radius, tacplus, snmptrap, syslog, ping, traceroute, dns, cflowd, ntp, sflow, icmp6-error, ldap

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

address string

Warning:

Modifying this element recreates the parent element automatically for the new value to take effect.

Synopsis

Source IPv6 address

Tree
Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

ssh

Synopsis

Enter the ssh context

Tree
Introduced

16.0.R1

Platforms

All

client-cipher-list-v1

Synopsis

Enter the client-cipher-list-v1 context

Introduced

16.0.R1

Platforms

All

cipher [index] number

Synopsis

Enter the cipher list instance

Tree
Introduced

16.0.R1

Platforms

All

[index] number

Synopsis

Cipher index in the list

Range

1 to 255

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

name keyword

Synopsis

Cipher name value

Tree
Options

des, 3des, blowfish

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

client-cipher-list-v2

Synopsis

Enter the client-cipher-list-v2 context

Introduced

16.0.R1

Platforms

All

cipher [index] number

Synopsis

Enter the cipher list instance

Tree
Introduced

16.0.R1

Platforms

All

[index] number

Synopsis

Cipher index in the list

Range

1 to 255

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

name keyword

Synopsis

Cipher name value

Tree
Options

3des-cbc, blowfish-cbc, cast128-cbc, arcfour, aes128-cbc, aes192-cbc, aes256-cbc, rijndael-cbc, aes128-ctr, aes192-ctr, aes256-ctr

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

client-kex-list-v2

Synopsis

Enter the client-kex-list-v2 context

Introduced

19.10.R3

Platforms

All

kex [index] number

Synopsis

Enter the kex list instance

Tree
Introduced

19.10.R3

Platforms

All

[index] number

Synopsis

SSHv2 KEX algorithm index

Range

1 to 255

Notes

This element is part of a list key.

Introduced

19.10.R3

Platforms

All

name keyword

Synopsis

KEX algorithm for computing a shared secret key

Tree
Options

diffie-hellman-group1-sha1, diffie-hellman-group14-sha1, diffie-hellman-group-exchange-sha1, diffie-hellman-group14-sha256, diffie-hellman-group16-sha512

Notes

This element is mandatory.

Introduced

19.10.R3

Platforms

All

client-mac-list-v2

Synopsis

Enter the client-mac-list-v2 context

Introduced

16.0.R1

Platforms

All

mac [index] number

Synopsis

Enter the mac list instance

Tree
Introduced

16.0.R1

Platforms

All

[index] number

Synopsis

MAC algorithm index

Range

1 to 255

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

name keyword

Synopsis

MAC algorithm that performs encryption or decryption

Tree
Options

hmac-sha2-512, hmac-sha2-256, hmac-sha1, hmac-sha1-96, hmac-md5, hmac-ripemd160, hmac-ripemd160-openssh-com, hmac-md5-96

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

key-re-exchange

Synopsis

Enter the key-re-exchange context

Introduced

16.0.R1

Platforms

All

client

Synopsis

Enter the client context

Tree
Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of the key re-exchange

Default

enable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

mbytes (number | keyword)

Synopsis

Maximum bytes transmitted before key re-exchange begins

Tree
Range

1 to 64000

Default

1024

Units

megabytes

Options

infinite

Introduced

16.0.R1

Platforms

All

minutes (number | keyword)

Synopsis

Maximum time before key re-exchange is initiated

Tree
Range

1 to 1440

Default

60

Units

minutes

Options

infinite

Introduced

16.0.R1

Platforms

All

server

Synopsis

Enter the server context

Tree
Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of the key re-exchange

Default

enable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

mbytes (number | keyword)

Synopsis

Maximum bytes transmitted before key re-exchange begins

Tree
Range

1 to 64000

Default

1024

Units

megabytes

Options

infinite

Introduced

16.0.R1

Platforms

All

minutes (number | keyword)

Synopsis

Maximum time before key re-exchange is initiated

Tree
Range

1 to 1440

Default

60

Units

minutes

Options

infinite

Introduced

16.0.R1

Platforms

All

preserve-key boolean

Synopsis

Preserve keys and restore on system or server restart

Default

false

Introduced

16.0.R1

Platforms

All

server-admin-state keyword

Synopsis

Administrative state of the SSH server

Default

enable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

server-cipher-list-v1

Synopsis

Enter the server-cipher-list-v1 context

Introduced

16.0.R1

Platforms

All

cipher [index] number

Synopsis

Enter the cipher list instance

Tree
Introduced

16.0.R1

Platforms

All

[index] number

Synopsis

Cipher index in the list

Range

1 to 255

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

name keyword

Synopsis

Cipher name value

Tree
Options

des, 3des, blowfish

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

server-cipher-list-v2

Synopsis

Enter the server-cipher-list-v2 context

Introduced

16.0.R1

Platforms

All

cipher [index] number

Synopsis

Enter the cipher list instance

Tree
Introduced

16.0.R1

Platforms

All

[index] number

Synopsis

Cipher index in the list

Range

1 to 255

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

name keyword

Synopsis

Cipher name value

Tree
Options

3des-cbc, blowfish-cbc, cast128-cbc, arcfour, aes128-cbc, aes192-cbc, aes256-cbc, rijndael-cbc, aes128-ctr, aes192-ctr, aes256-ctr

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

server-kex-list-v2

Synopsis

Enter the server-kex-list-v2 context

Introduced

19.10.R3

Platforms

All

kex [index] number

Synopsis

Enter the kex list instance

Tree
Introduced

19.10.R3

Platforms

All

[index] number

Synopsis

SSHv2 KEX algorithm index

Range

1 to 255

Notes

This element is part of a list key.

Introduced

19.10.R3

Platforms

All

name keyword

Synopsis

KEX algorithm for computing a shared secret key

Tree
Options

diffie-hellman-group1-sha1, diffie-hellman-group14-sha1, diffie-hellman-group-exchange-sha1, diffie-hellman-group14-sha256, diffie-hellman-group16-sha512

Notes

This element is mandatory.

Introduced

19.10.R3

Platforms

All

server-mac-list-v2

Synopsis

Enter the server-mac-list-v2 context

Introduced

16.0.R1

Platforms

All

mac [index] number

Synopsis

Enter the mac list instance

Tree
Introduced

16.0.R1

Platforms

All

[index] number

Synopsis

MAC algorithm index

Range

1 to 255

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

name keyword

Synopsis

MAC algorithm that performs encryption or decryption

Tree
Options

hmac-sha2-512, hmac-sha2-256, hmac-sha1, hmac-sha1-96, hmac-md5, hmac-ripemd160, hmac-ripemd160-openssh-com, hmac-md5-96

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

version keyword

Synopsis

SSH protocol version supported by the SSH server

Tree
Default

2

Options

1, 2, 1-2

Introduced

16.0.R1

Platforms

All

system-passwords

Synopsis

Enter the system-passwords context

Introduced

16.0.R1

Platforms

All

admin-password string

Synopsis

Password that assigns the user as administrator

String Length

3 to 136

Introduced

16.0.R1

Platforms

All

vsd-password string

Synopsis

Password that allows the user to assign VSD services

String Length

3 to 136

Introduced

16.0.R1

Platforms

All

tech-support

Synopsis

Enter the tech-support context

Introduced

16.0.R1

Platforms

All

ts-location (ts-sat-url | cflash-url | string)

Synopsis

Default file path for generated tech-support files

Context

configure system security tech-support ts-location (ts-sat-url | cflash-url | string)

String Length

1 to 180

Introduced

16.0.R1

Platforms

All

telnet-server boolean

Synopsis

Enable Telnet servers running on the system

Default

false

Introduced

16.0.R1

Platforms

All

telnet6-server boolean

Synopsis

Enable Telnet IPv6 servers running on the system

Default

false

Introduced

16.0.R1

Platforms

All

tls

Synopsis

Enter the tls context

Tree
Introduced

16.0.R1

Platforms

All

cert-profile [cert-profile-name] string

Synopsis

Enter the cert-profile list instance

Max. Elements

16

Introduced

16.0.R1

Platforms

All

[cert-profile-name] string

Synopsis

TLS certificate profile name

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of the certificate profile

Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

entry [entry-id] number

Synopsis

Enter the entry list instance

Tree
Max. Elements

8

Introduced

16.0.R1

Platforms

All

[entry-id] number

Synopsis

Certificate profile ID

Range

1 to 8

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

certificate-file string

Synopsis

Certificate file name

String Length

1 to 95

Introduced

16.0.R1

Platforms

All

key-file string

Synopsis

Key file name

Context
Tree
String Length

1 to 95

Introduced

16.0.R1

Platforms

All

send-chain

Synopsis

Enter the send-chain context

Introduced

16.0.R1

Platforms

All

ca-profile [ca-profile-name] reference

Synopsis

Add a list entry for ca-profile

Max. Elements

7

Introduced

16.0.R1

Platforms

All

[ca-profile-name] reference

Synopsis

Certificate Authority (CA) profile name

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

client-cipher-list [client-cipher-list-name] string

Synopsis

Enter the client-cipher-list list instance

Max. Elements

16

Introduced

16.0.R1

Platforms

All

[client-cipher-list-name] string

Synopsis

TLS client cipher list

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

cipher [index] number

Synopsis

Enter the cipher list instance

Tree
Introduced

16.0.R1

Platforms

All

[index] number

Synopsis

Index of the cipher

Range

1 to 255

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

name keyword

Synopsis

Value for the cipher suite code

Context
Tree
Options

tls-rsa-with3des-ede-cbc-sha, tls-rsa-with-aes128-cbc-sha, tls-rsa-with-aes256-cbc-sha, tls-rsa-with-aes128-cbc-sha256, tls-rsa-with-aes256-cbc-sha256

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

client-tls-profile [client-profile-name] string

Synopsis

Enter the client-tls-profile list instance

Max. Elements

16

Introduced

16.0.R1

Platforms

All

[client-profile-name] string

Synopsis

Name of TLS client profile.

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of the client TLS profile

Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

cert-profile reference

Synopsis

Certificate profile ID

Introduced

16.0.R1

Platforms

All

cipher-list reference

Synopsis

Specifies the ordered list of supported cipher suite codes associated with this TLS client profile.

Introduced

16.0.R1

Platforms

All

trust-anchor-profile reference

Synopsis

Trust anchor profile

Introduced

16.0.R1

Platforms

All

server-cipher-list [server-cipher-list-name] string

Synopsis

Enter the server-cipher-list list instance

Max. Elements

16

Introduced

16.0.R1

Platforms

All

[server-cipher-list-name] string

Synopsis

Name of TLS server cipher list.

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

cipher [index] number

Synopsis

Enter the cipher list instance

Tree
Introduced

16.0.R1

Platforms

All

[index] number

Synopsis

Index of the cipher

Range

1 to 255

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

name keyword

Synopsis

Value for the cipher suite code

Context
Tree
Options

tls-rsa-with3des-ede-cbc-sha, tls-rsa-with-aes128-cbc-sha, tls-rsa-with-aes256-cbc-sha, tls-rsa-with-aes128-cbc-sha256, tls-rsa-with-aes256-cbc-sha256

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

server-tls-profile [server-profile-name] string

Synopsis

Enter the server-tls-profile list instance

Max. Elements

16

Introduced

16.0.R1

Platforms

All

[server-profile-name] string

Synopsis

Name of TLS server profile.

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of the server TLS profile

Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

authenticate-client

Synopsis

Enter the authenticate-client context

Introduced

16.0.R1

Platforms

All

common-name-list reference

Synopsis

Common name list for TLS client certificate authentication

Introduced

16.0.R1

Platforms

All

trust-anchor-profile reference

Synopsis

Trust anchor profile for TLS client certificate authentication

Introduced

16.0.R1

Platforms

All

cert-profile reference

Synopsis

Certificate profile ID

Introduced

16.0.R1

Platforms

All

cipher-list reference

Synopsis

Specifies the ordered list of supported cipher suite codes associated with this TLS client profile.

Introduced

16.0.R1

Platforms

All

tls-re-negotiate-timer number

Synopsis

TLS HELLO request timer

Range

0 to 65000

Default

0

Units

minutes

Introduced

16.0.R1

Platforms

All

trust-anchor-profile [trust-anchor-profile-name] string

Synopsis

Enter the trust-anchor-profile list instance

Max. Elements

16

Introduced

16.0.R1

Platforms

All

[trust-anchor-profile-name] string

Synopsis

Name of TLS trust anchor profile

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

trust-anchor [ca-profile-name] reference

Synopsis

Add a list entry for trust-anchor

Max. Elements

8

Introduced

16.0.R1

Platforms

All

[ca-profile-name] reference

Synopsis

Trusted CA profile

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

user-params

Synopsis

Enter the user-params context

Introduced

16.0.R1

Platforms

All

attempts

Synopsis

Enter the attempts context

Tree
Introduced

16.0.R1

Platforms

All

count number

Synopsis

Number of unsuccessful login attempts

Tree
Range

1 to 64

Default

3

Introduced

16.0.R1

Platforms

All

lockout number

Synopsis

Lockout period after unsuccessful login attempts

Tree
Range

0 to 1440

Default

10

Units

minutes

Introduced

16.0.R1

Platforms

All

time number

Synopsis

Time frame of unsuccessful login attempts

Tree
Range

0 to 60

Default

5

Units

minutes

Introduced

16.0.R1

Platforms

All

authentication-order

Synopsis

Enter the authentication-order context

Introduced

16.0.R1

Platforms

All

exit-on-reject boolean

Synopsis

Ignore subsequent AAA methods in authentication order when a reject is received

Default

false

Introduced

16.0.R1

Platforms

All

order keyword

Synopsis

Sequence of password authentication, authorization, and accounting

Tree
Options

local, radius, tacplus, ldap

Max. Elements

4

Notes

This element is ordered by the user.

Introduced

16.0.R1

Platforms

All

local-user

Synopsis

Enter the local-user context

Introduced

16.0.R1

Platforms

All

password

Synopsis

Enter the password context

Tree
Introduced

16.0.R1

Platforms

All

aging number

Synopsis

Maximum time during which a user password is valid

Tree
Range

1 to 500

Units

days

Introduced

16.0.R1

Platforms

All

complexity-rules

Synopsis

Enter the complexity-rules context

Introduced

16.0.R1

Platforms

All

allow-user-name boolean

Synopsis

User name as part of the password

Default

false

Introduced

16.0.R1

Platforms

All

credits

Synopsis

Enter the credits context

Tree
Notes

The following are part of a choice: credits or required.

Introduced

16.0.R1

Platforms

All

lowercase number

Synopsis

Maximum credits given for the usage of lowercase letters

Tree
Range

1 to 10

Introduced

16.0.R1

Platforms

All

numeric number

Synopsis

Maximum credits given for the usage of numeric characters

Tree
Range

1 to 10

Introduced

16.0.R1

Platforms

All

special-character number

Synopsis

Maximum credits given for the usage of special characters

Range

1 to 10

Introduced

16.0.R1

Platforms

All

uppercase number

Synopsis

Maximum credits given for the usage of uppercase letters

Tree
Range

1 to 10

Introduced

16.0.R1

Platforms

All

minimum-classes number

Synopsis

Force the use of different character classes for a minimum number

Range

2 to 4

Introduced

16.0.R1

Platforms

All

minimum-length number

Synopsis

Minimum length required for local passwords

Range

6 to 50

Default

6

Introduced

16.0.R1

Platforms

All

repeated-characters number

Synopsis

Number of times the same character appears consecutively

Range

2 to 8

Introduced

16.0.R1

Platforms

All

required

Synopsis

Enter the required context

Tree
Notes

The following are part of a choice: credits or required.

Introduced

16.0.R1

Platforms

All

lowercase number

Synopsis

Number required for lowercase letters

Tree
Range

1 to 10

Introduced

16.0.R1

Platforms

All

numeric number

Synopsis

Number required for numeric characters

Tree
Range

1 to 10

Introduced

16.0.R1

Platforms

All

special-character number

Synopsis

Number required for special characters

Range

1 to 10

Introduced

16.0.R1

Platforms

All

uppercase number

Synopsis

Number required for uppercase letters

Tree
Range

1 to 10

Introduced

16.0.R1

Platforms

All

hashing keyword

Synopsis

Password hashing algorithm

Tree
Default

bcrypt

Options

bcrypt, sha2-pbkdf2, sha3-pbkdf2

Introduced

20.7.R1

Platforms

All

history-size number

Synopsis

New password to match against previous ones

Range

0 to 20

Introduced

16.0.R1

Platforms

All

minimum-age number

Synopsis

Minimum age required for a password before changing it

Range

0 to 86400

Default

600

Units

seconds

Introduced

16.0.R1

Platforms

All

minimum-change number

Synopsis

Minimum distance required between the old and the new password

Range

1 to 20

Default

5

Introduced

16.0.R1

Platforms

All

user [user-name] string

Synopsis

Enter the user list instance

Tree
Introduced

16.0.R1

Platforms

All

[user-name] string

Synopsis

Local user name

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

access

Synopsis

Enter the access context

Tree
Introduced

16.0.R1

Platforms

All

console boolean

Synopsis

Allow console access (serial port or Telnet)

Tree
Default

false

Introduced

16.0.R1

Platforms

All

ftp boolean

Synopsis

Allow FTP access

Tree
Default

false

Introduced

16.0.R1

Platforms

All

grpc boolean

Synopsis

Allow gRPC access

Tree
Default

false

Introduced

16.0.R1

Platforms

All

li boolean

Synopsis

Enable/disable access to LI.

Tree
Default

false

Introduced

19.10.R1

Platforms

All

netconf boolean

Synopsis

Allow NETCONF session access

Tree
Default

false

Introduced

16.0.R1

Platforms

All

snmp boolean

Synopsis

Allow SNMP access

Tree
Default

false

Introduced

16.0.R1

Platforms

All

cli-engine keyword

Synopsis

User level override for CLI engine access

Default

md-cli

Options

classic-cli, md-cli

Max. Elements

2

Notes

This element is ordered by the user.

Introduced

16.0.R1

Platforms

All

console

Synopsis

Enter the console context

Tree
Introduced

16.0.R1

Platforms

All

cannot-change-password boolean

Synopsis

Change password privileges

Default

false

Introduced

16.0.R1

Platforms

All

login-exec (sat-url | cflash-url | ftp-tftp-url | filename)

Synopsis

File to execute when a user successfully logs in

Context

configure system security user-params local-user user string console login-exec (sat-url | cflash-url | ftp-tftp-url | filename)

String Length

1 to 200

Introduced

16.0.R1

Platforms

All

member reference

Synopsis

User profiles for this user

Tree
Max. Elements

8

Notes

This element is ordered by the user.

Introduced

16.0.R1

Platforms

All

new-password-at-login boolean

Synopsis

Prompt a user to change password at next console login

Default

false

Introduced

16.0.R1

Platforms

All

home-directory (sat-url | cflash-without-slot-url)

Synopsis

Home directory for the user

Context

configure system security user-params local-user user string home-directory (sat-url | cflash-without-slot-url)

String Length

1 to 200

Introduced

16.0.R1

Platforms

All

password string

Synopsis

Password to authenticate the user for console and FTP access

Tree
String Length

3 to 136

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

public-keys

Synopsis

Enter the public-keys context

Introduced

16.0.R1

Platforms

All

ecdsa

Synopsis

Enter the ecdsa context

Tree
Introduced

16.0.R1

Platforms

All

ecdsa-key [ecdsa-public-key-id] number

Synopsis

Enter the ecdsa-key list instance

Tree
Introduced

16.0.R1

Platforms

All

[ecdsa-public-key-id] number

Synopsis

Number of the Secure Shell version 2 (SSHv2) ECDSA public key that is associated with system user

Range

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R1

Platforms

All

key-value string

Synopsis

Number of the Secure Shell version 2 (SSHv2) ECDSA public key that is associated with system user

Tree
String Length

1 to 255

Introduced

16.0.R1

Platforms

All

rsa

Synopsis

Enter the rsa context

Tree
Introduced

16.0.R1

Platforms

All

rsa-key [rsa-public-key-id] number

Synopsis

Enter the rsa-key list instance

Tree
Introduced

16.0.R1

Platforms

All

[rsa-public-key-id] number

Synopsis

Number of the Secure Shell version 2 (SSHv2) RSA public key that is associated with system user

Range

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R1

Platforms

All

key-value string

Synopsis

Number of the Secure Shell version 2 (SSHv2) RSA public key that is associated with system user

Tree
String Length

1 to 800

Introduced

16.0.R1

Platforms

All

restricted-to-home boolean

Synopsis

Users prevented from navigating above their home directories to access file

Default

false

Introduced

16.0.R1

Platforms

All

snmp

Synopsis

Enter the snmp context

Tree
Introduced

16.0.R1

Platforms

All

authentication

Synopsis

Enable the authentication context

Introduced

16.0.R1

Platforms

All

authentication-key string

Synopsis

Authentication key for authentication protocol

String Length

1 to 54

Introduced

16.0.R1

Platforms

All

authentication-protocol keyword

Synopsis

Authentication protocol

Options

md5, sha

Introduced

16.0.R1

Platforms

All

privacy

Synopsis

Enable the privacy context

Tree
Introduced

16.0.R1

Platforms

All

privacy-key string

Synopsis

Localized privacy key for authentication

String Length

1 to 51

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

privacy-protocol keyword

Synopsis

Encryption protocol for authentication

Options

des, aes-128-cfb

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

group string

Synopsis

User to associate with a group name

Tree
String Length

1 to 32

Introduced

16.0.R1

Platforms

All

vprn-network-exceptions

Synopsis

Enable the vprn-network-exceptions context

Introduced

16.0.R1

Platforms

All

count number

Synopsis

Limit of exception messages received

Tree
Range

10 to 1000

Default

100

Introduced

16.0.R1

Platforms

All

window number

Synopsis

Time interval to measure exception messages

Tree
Range

1 to 60

Default

10

Units

seconds

Introduced

16.0.R1

Platforms

All

selective-fib boolean

Synopsis

FIB assigned to the system

Default

false

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

software-repository [repository-name] string

Synopsis

Enter the software-repository list instance

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

[repository-name] string

Synopsis

Unique name for the system software repository

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

primary-location string

Synopsis

Primary location for the files in the software repository

String Length

1 to 180

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

secondary-location string

Synopsis

Secondary location for the files in the software repository

String Length

1 to 180

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

tertiary-location string

Synopsis

Tertiary location for the files in the software repository

String Length

1 to 180

Introduced

16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

switch-fabric

Synopsis

Enter the switch-fabric context

Description

Commands in this context configure system level attributes related to the switch fabric.

Introduced

20.5.R1

Platforms

7450 ESS, 7750 SR-7, 7750 SR-7s, 7750 SR-14s, 7950 XRS-20, 7950 XRS-20e, 7950 XRS-40

failure-recovery

Synopsis

Enter the failure-recovery context

Description

Commands in this context configure the attributes related to the automatic switch fabric recovery process. This process is triggered when there are two resets of an IOM/XCM due to ICC failures within a small time frame. The recovery process involves the sequential resetting of SFM in case the issues are due to one of the SFM in the ICC communication path. As the final step in the recovery process, a CPM switchover is triggered to reset the active CPM.

Introduced

21.2.R1

Platforms

7450 ESS, 7750 SR-7, 7950 XRS-20, 7950 XRS-20e, 7950 XRS-40

admin-state keyword

Synopsis

Administrative state of the failure recovery process

Default

disable

Options

enable, disable

Introduced

21.2.R1

Platforms

7450 ESS, 7750 SR-7, 7950 XRS-20, 7950 XRS-20e, 7950 XRS-40

sfm-loss-threshold number

Synopsis

Number of SFMs that can fail before SFM overload state

Description

This command specifies the number of SFMs that are permitted to fail before the system goes into SFM overload state.

The default value for the 7750 SR-7s is 1 and the default value for the 7750 SR-14s is 2. Users can select the SFM limit based on the number possible for the system minus one. For the 7750 SR-7s, the limit is 3 and the limit for the 7750 SR-14s is 7.

Range

1 to 7

Introduced

20.5.R1

Platforms

7750 SR-7s, 7750 SR-14s

telemetry

Synopsis

Enter the telemetry context

Tree
Description

Commands in this context configure the parameters for the dial-out telemetry functionality.

Introduced

20.2.R1

Platforms

All

destination-group [name] string

Synopsis

Enter the destination-group list instance

Description

Commands in this context configure parameters for destination groups.

Max. Elements

225

Introduced

20.5.R1

Platforms

All

[name] string

Synopsis

Destination group name

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

20.5.R1

Platforms

All

allow-unsecure-connection

Synopsis

Allow unsecured operation of gRPC connections

Notes

The following are part of a choice: allow-unsecure-connection or tls-client-profile.

Introduced

20.5.R1

Platforms

All

description string

Synopsis

Text description

String Length

1 to 80

Introduced

20.5.R1

Platforms

All

destination [address] (ipv4-address-no-zone | ipv6-address-no-zone | fully-qualified-domain-name) port number

Synopsis

Enter the destination list instance

Context

configure system telemetry destination-group string destination (ipv4-address-no-zone | ipv6-address-no-zone | fully-qualified-domain-name) port number

Max. Elements

4

Notes

This element is ordered by the user.

Introduced

20.5.R1

Platforms

All

[address] (ipv4-address-no-zone | ipv6-address-no-zone | fully-qualified-domain-name)

Synopsis

Address of the destination within the destination group

Context

configure system telemetry destination-group string destination (ipv4-address-no-zone | ipv6-address-no-zone | fully-qualified-domain-name) port number

String Length

1 to 255

Notes

This element is part of a list key.

Introduced

20.5.R1

Platforms

All

port number

Synopsis

TCP port number for the destination

Context

configure system telemetry destination-group string destination (ipv4-address-no-zone | ipv6-address-no-zone | fully-qualified-domain-name) port number

Range

0 | 1 to 65535

Notes

This element is part of a list key.

Introduced

20.5.R1

Platforms

All

router-instance string

Synopsis

Router instance for the destination group

Context

configure system telemetry destination-group string destination (ipv4-address-no-zone | ipv6-address-no-zone | fully-qualified-domain-name) port number router-instance string

Introduced

20.5.R1

Platforms

All

tcp-keepalive

Synopsis

Enter the tcp-keepalive context

Introduced

20.5.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of the TCP keep-alive algorithm

Default

disable

Options

enable, disable

Introduced

20.5.R1

Platforms

All

idle-time number

Synopsis

Time until the first TCP keepalive probe is sent

Tree
Range

1 to 100000

Default

600

Units

seconds

Introduced

20.5.R1

Platforms

All

interval number

Synopsis

Time between TCP keepalive probes

Tree
Range

1 to 100000

Default

15

Units

seconds

Introduced

20.5.R1

Platforms

All

retries number

Synopsis

Number of probe retries before closing the connection

Tree
Description

This command configures the number of missed TCP keepalive probes before closing the TCP connection and attempting to reach the other destinations within the same destination group.

Range

3 to 100

Default

4

Introduced

20.5.R1

Platforms

All

tls-client-profile reference

Synopsis

TLS client profile assigned to the destination group

Notes

The following are part of a choice: allow-unsecure-connection or tls-client-profile.

Introduced

20.5.R1

Platforms

All

persistent-subscriptions

Synopsis

Enter the persistent-subscriptions context

Introduced

20.5.R1

Platforms

All

subscription [name] string

Synopsis

Enter the subscription list instance

Max. Elements

225

Introduced

20.5.R1

Platforms

All

[name] string

Synopsis

Persistent subscription name

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

20.5.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of the persistent subscription

Default

disable

Options

enable, disable

Introduced

20.5.R1

Platforms

All

description string

Synopsis

Text description

String Length

1 to 80

Introduced

20.5.R1

Platforms

All

destination-group reference

Synopsis

Name of the destination group used in the subscription

Introduced

20.5.R1

Platforms

All

encoding keyword

Synopsis

Encoding used for telemetry notifications

Tree
Description

This command specifies the encoding used for telemetry notifications as defined by the gNMI OpenConfig standard.

Default

json

Options

json, bytes, proto, json-ietf

Introduced

20.5.R1

Platforms

All

local-source-address (ipv4-address-no-zone | ipv6-address-no-zone)

Synopsis

Local IP address of packets sent from the source

Context

configure system telemetry persistent-subscriptions subscription string local-source-address (ipv4-address-no-zone | ipv6-address-no-zone)

Introduced

20.5.R1

Platforms

All

mode keyword

Synopsis

Mode for telemetry notifications

Tree
Description

This command specifies the subscription path mode for telemetry notifications sent out for the persistent subscription.

Options

target-defined, on-change, sample

Introduced

20.5.R1

Platforms

All

originated-qos-marking keyword

Synopsis

QoS marking used for telemetry notification packets

Options

be, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63

Introduced

20.5.R1

Platforms

All

sample-interval number

Synopsis

Sampling interval for the persistent subscription

Description

This command configures the sampling interval for the persistent subscription. The interval applies only in sampling or target-defined modes.

Range

1000 to max

Default

10000

Units

milliseconds

Introduced

20.5.R1

Platforms

All

sensor-group reference

Synopsis

Sensor group used in the persistent subscription

Description

This command specifies the sensor group to be used in the persistent subscription. If no valid paths exist in the sensor group, the configuration is accepted, however, no gRPC connection is established when persistent subscription is activated.

Introduced

20.5.R1

Platforms

All

sensor-groups

Synopsis

Enter the sensor-groups context

Introduced

20.5.R1

Platforms

All

sensor-group [name] string

Synopsis

Enter the sensor-group list instance

Max. Elements

225

Introduced

20.5.R1

Platforms

All

[name] string

Synopsis

Sensor group name

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

20.5.R1

Platforms

All

description string

Synopsis

Text description

String Length

1 to 80

Introduced

20.5.R1

Platforms

All

path [xpath] string

Synopsis

Add a list entry for path

Tree
Max. Elements

4500

Introduced

20.5.R1

Platforms

All

[xpath] string

Synopsis

YANG model path indicating the data to be streamed

Description

The command specifies the path from which data is streamed to the collector. Streamed data includes all descendants of the tree indicated by the path.

String Length

1 to 512

Notes

This element is part of a list key.

Introduced

20.5.R1

Platforms

All

thresholds

Synopsis

Enter the thresholds context

Introduced

16.0.R1

Platforms

All

cflash-cap-alarm-percent [cflash-id] string

Synopsis

Enter the cflash-cap-alarm-percent list instance

Introduced

16.0.R1

Platforms

All

[cflash-id] string

Synopsis

Capacity that monitors the cflash (compact flash) assigned in this command

String Length

1 to 200

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

falling-threshold number

Synopsis

Specifies the falling threshold percentage value for sampled statistics of cflash capacity alarm entry.

Range

0 to 100

Units

percent

Introduced

16.0.R4

Platforms

All

interval number

Synopsis

Polling period over which data is sampled and compared

Tree
Range

1 to 2147483647

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

rising-threshold number

Synopsis

Specifies the rising threshold percentage value for sampled statistics of cflash capacity alarm entry.

Range

0 to 100

Units

percent

Notes

This element is mandatory.

Introduced

16.0.R4

Platforms

All

rmon-event-type keyword

Synopsis

Notification type specifying action when event occurs

Default

both

Options

none, log, trap, both

Introduced

16.0.R1

Platforms

All

startup-alarm keyword

Synopsis

Alarm type when the alarm is first created

Default

either

Options

rising, falling, either

Introduced

16.0.R1

Platforms

All

cflash-cap-warn-percent [cflash-id] string

Synopsis

Enter the cflash-cap-warn-percent list instance

Introduced

16.0.R1

Platforms

All

[cflash-id] string

Synopsis

Capacity that monitors the cflash (compact flash) assigned in this command

String Length

1 to 200

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

falling-threshold number

Synopsis

Specifies the falling threshold percentage value for sampled statistics of cflash capacity alarm entry.

Range

0 to 100

Units

percent

Introduced

16.0.R4

Platforms

All

interval number

Synopsis

Polling period over which data is sampled and compared

Tree
Range

1 to 2147483647

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

rising-threshold number

Synopsis

Specifies the rising threshold percentage value for sampled statistics of cflash capacity alarm entry.

Range

0 to 100

Units

percent

Notes

This element is mandatory.

Introduced

16.0.R4

Platforms

All

rmon-event-type keyword

Synopsis

Notification type specifying action when event occurs

Default

both

Options

none, log, trap, both

Introduced

16.0.R1

Platforms

All

startup-alarm keyword

Synopsis

Alarm type when the alarm is first created

Default

either

Options

rising, falling, either

Introduced

16.0.R1

Platforms

All

kb-memory-use-alarm

Synopsis

Enable the kb-memory-use-alarm context

Introduced

16.0.R4

Platforms

All

falling-threshold number

Synopsis

Specifies the threshold for the sampled statistic for the falling threshold event.

Range

-2147483648 to 2147483647

Introduced

16.0.R4

Platforms

All

interval number

Synopsis

Polling period over which data is sampled and compared

Tree
Range

1 to 2147483647

Notes

This element is mandatory.

Introduced

16.0.R4

Platforms

All

rising-threshold number

Synopsis

Specifies the threshold for the sampled statistic for the rising threshold event.

Range

-2147483648 to 2147483647

Notes

This element is mandatory.

Introduced

16.0.R4

Platforms

All

rmon-event-type keyword

Synopsis

Notification type specifying action when event occurs

Default

both

Options

none, log, trap, both

Introduced

16.0.R4

Platforms

All

startup-alarm keyword

Synopsis

Alarm type when the alarm is first created

Default

either

Options

rising, falling, either

Introduced

16.0.R4

Platforms

All

kb-memory-use-warn

Synopsis

Enable the kb-memory-use-warn context

Introduced

16.0.R4

Platforms

All

falling-threshold number

Synopsis

Specifies the threshold for the sampled statistic for the falling threshold event.

Range

-2147483648 to 2147483647

Introduced

16.0.R4

Platforms

All

interval number

Synopsis

Polling period over which data is sampled and compared

Tree
Range

1 to 2147483647

Notes

This element is mandatory.

Introduced

16.0.R4

Platforms

All

rising-threshold number

Synopsis

Specifies the threshold for the sampled statistic for the rising threshold event.

Range

-2147483648 to 2147483647

Notes

This element is mandatory.

Introduced

16.0.R4

Platforms

All

rmon-event-type keyword

Synopsis

Notification type specifying action when event occurs

Default

both

Options

none, log, trap, both

Introduced

16.0.R4

Platforms

All

startup-alarm keyword

Synopsis

Alarm type when the alarm is first created

Default

either

Options

rising, falling, either

Introduced

16.0.R4

Platforms

All

rmon

Synopsis

Enter the rmon context

Tree
Introduced

16.0.R1

Platforms

All

alarm [rmon-alarm-id] number

Synopsis

Enter the alarm list instance

Tree
Max. Elements

1200

Introduced

16.0.R1

Platforms

All

[rmon-alarm-id] number

Synopsis

Index ID for an entry in the alarm table

Range

0 to 65400

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

falling-event number

Synopsis

RMON event ID used when a falling threshold crossing event occurs

Range

0 to 65400

Introduced

16.0.R1

Platforms

All

falling-threshold number

Synopsis

Falling threshold for the sampled statistic

Description

This command specifies a falling threshold for the sampled statistic. When the current sampled value is less than or equal to this threshold and the value at the last sampling interval was greater than this threshold, a single threshold crossing event is generated. A single threshold crossing event is also generated if the first sample taken is less than or equal to this threshold and the associated startup-alarm command is set to falling or either.

After a falling threshold crossing event is generated, another such event is not generated until the sampled value exceeds this threshold and reaches or exceeds the rising-threshold command setting.

Range

-2147483648 to 2147483647

Introduced

16.0.R1

Platforms

All

interval number

Synopsis

Polling period over which data is sampled and compared

Tree
Description

This command specifies the polling interval over which the data is sampled and compared with the rising and falling thresholds

Range

1 to 2147483647

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

owner string

Synopsis

Owner that created this entry and uses the resources

Context
Tree
String Length

1 to 80

Default

TiMOS CLI

Introduced

16.0.R1

Platforms

All

rising-event number

Synopsis

RMON event ID used when a rising event threshold event occurs

Range

0 to 65400

Introduced

16.0.R1

Platforms

All

rising-threshold number

Synopsis

Rising threshold for the sampled statistic

Description

This command specifies the rising threshold for the sampled statistic. When the current sampled value is greater than or equal to this threshold and the value at the last sampling interval was below this threshold, a single threshold crossing event is generated. A single threshold crossing event is also generated if the first sample taken is greater than or equal to this threshold and the associated startup-alarm command is set to rising or either.

After a rising threshold crossing event is generated, another such event is not generated until the sampled value falls below this threshold and reaches or falls below the falling-threshold command setting.

Range

-2147483648 to 2147483647

Introduced

16.0.R1

Platforms

All

sample-type keyword

Synopsis

Method to sample the selected variable and calculate the value comparing against the thresholds

Default

absolute

Options

absolute, delta

Introduced

16.0.R1

Platforms

All

startup-alarm keyword

Synopsis

Alarm to send when this entry is first set to valid

Default

either

Options

rising, falling, either

Introduced

16.0.R1

Platforms

All

variable-oid string

Synopsis

Object identifier to sample the specific variable

String Length

1 to 255

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

event [rmon-event-id] number

Synopsis

Enter the event list instance

Tree
Max. Elements

1200

Introduced

16.0.R1

Platforms

All

[rmon-event-id] number

Synopsis

Index ID for an entry in the event table

Range

1 to 65400

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

description string

Synopsis

Text description

String Length

1 to 80

Introduced

16.0.R1

Platforms

All

event-type keyword

Synopsis

Type of notification action to be taken when this event occurs

Default

both

Options

none, log, trap, both

Introduced

16.0.R1

Platforms

All

owner string

Synopsis

Owner that created this entry and uses the resources

Context
Tree
String Length

1 to 80

Default

TiMOS CLI

Introduced

16.0.R1

Platforms

All

time

Synopsis

Enter the time context

Tree
Introduced

16.0.R1

Platforms

All

dst-zone [summer-time-zone] string

Synopsis

Enter the dst-zone list instance

Context
Tree
Max. Elements

1

Introduced

16.0.R1

Platforms

All

[summer-time-zone] string

Synopsis

Name of a summer time zone

Context
String Length

1 to 5

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

end

Synopsis

Enter the end context

Context
Tree
Introduced

16.0.R1

Platforms

All

day keyword

Synopsis

Day of the week when the daylight savings time setting ends

Context
Tree
Default

sunday

Options

sunday, monday, tuesday, wednesday, thursday, friday, saturday

Introduced

16.0.R1

Platforms

All

hours-minutes string

Synopsis

Hour and number of minutes after which the daylight savings time ends

String Length

5

Default

00:00

Introduced

16.0.R1

Platforms

All

month keyword

Synopsis

Month of the week when the daylight savings time setting ends

Context
Tree
Default

january

Options

january, february, march, april, may, june, july, august, september, october, november, december

Introduced

16.0.R1

Platforms

All

week keyword

Synopsis

Week of the month when the daylight savings time setting ends

Context
Tree
Default

first

Options

first, second, third, fourth, last

Introduced

16.0.R1

Platforms

All

offset number

Synopsis

Offset for summer time setting

Context
Tree
Range

0 to 60

Default

60

Units

minutes

Introduced

16.0.R1

Platforms

All

start

Synopsis

Enter the start context

Tree
Introduced

16.0.R1

Platforms

All

day keyword

Synopsis

Day of the week when the daylight savings time setting starts

Context
Tree
Default

sunday

Options

sunday, monday, tuesday, wednesday, thursday, friday, saturday

Introduced

16.0.R1

Platforms

All

hours-minutes string

Synopsis

Hour and number of minutes after which the daylight savings time starts

String Length

5

Default

00:00

Introduced

16.0.R1

Platforms

All

month keyword

Synopsis

Month of the week when the daylight savings time setting starts

Context
Tree
Default

january

Options

january, february, march, april, may, june, july, august, september, october, november, december

Introduced

16.0.R1

Platforms

All

week keyword

Synopsis

Week of the month when the daylight savings time setting starts

Context
Tree
Default

first

Options

first, second, third, fourth, last

Introduced

16.0.R1

Platforms

All

ntp

Synopsis

Enable the ntp context

Tree
Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of NTP execution

Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

authentication-check boolean

Synopsis

Reject NTP PDUs that do not match the authentication key-id, type, or key requirements

Default

true

Introduced

16.0.R1

Platforms

All

authentication-key [key-id] number

Synopsis

Enter the authentication-key list instance

Introduced

16.0.R1

Platforms

All

[key-id] number

Synopsis

Index of the NTP authentication key table that uniquely identifies an authentication key and type

Range

1 to 255

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

key string

Synopsis

Key to authenticate NTP packets

Tree
String Length

1 to 71

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

type keyword

Synopsis

Type of authentication method to authenticate NTP packet

Tree
Options

des, message-digest

Notes

This element is mandatory.

Introduced

16.0.R1

Platforms

All

broadcast [router-instance] reference interface-name string

Synopsis

Enter the broadcast list instance

Context
Tree
Introduced

16.0.R1

Platforms

All

[router-instance] reference

Synopsis

Router name

Context
Reference
Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

interface-name string

Synopsis

Router interface name

Context
String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

key-id reference

Synopsis

Specifies the key-id of the authentication key and its authentication type used by this node to receive and transmit NTP packets to and from an NTP node.

Context
Tree
Introduced

16.0.R1

Platforms

All

ttl number

Synopsis

TTL value of messages transmitted by this broadcast address

Context
Tree
Range

1 to 255

Default

127

Introduced

16.0.R1

Platforms

All

version number

Synopsis

NTP version number generated or accepted by this node in NTP packets

Context
Tree
Range

2 to 4

Default

4

Introduced

16.0.R1

Platforms

All

broadcast-client [router-instance] string interface-name string

Synopsis

Enter the broadcast-client list instance

Introduced

16.0.R1

Platforms

All

[router-instance] string

Synopsis

Router name or VPRN service name

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

interface-name string

Synopsis

Router interface name

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

authenticate boolean

Synopsis

NTP PDUs authentication required when acting as a broadcast client

Default

false

Introduced

16.0.R1

Platforms

All

multicast

Synopsis

Enable the multicast context

Tree
Introduced

16.0.R1

Platforms

All

key-id reference

Synopsis

Specifies the key-id of the authentication key and its authentication type used by this node to receive and transmit NTP packets to and from an NTP node.

Tree
Introduced

16.0.R1

Platforms

All

version number

Synopsis

NTP version number generated by the node

Tree
Description

This command specifies the NTP version number that is generated by the node. This command does not need to be configured when in client mode, in which case all three versions are accepted.

Range

2 to 4

Default

4

Introduced

16.0.R1

Platforms

All

multicast-client

Synopsis

Enable the multicast-client context

Introduced

16.0.R1

Platforms

All

authenticate boolean

Synopsis

Authentication of NTP PDUs required when acting as a client

Default

false

Introduced

16.0.R1

Platforms

All

ntp-server

Synopsis

Enable the ntp-server context

Introduced

16.0.R1

Platforms

All

authenticate boolean

Synopsis

Authentication of NTP PDUs when acting as a server

Default

false

Introduced

16.0.R1

Platforms

All

peer [ip-address] (ipv4-address-no-zone | ipv6-address-no-zone) router-instance string

Synopsis

Enter the peer list instance

Context

configure system time ntp peer (ipv4-address-no-zone | ipv6-address-no-zone) router-instance string

Tree
Introduced

16.0.R1

Platforms

All

[ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)

Synopsis

Identifies a node that will provide time to the NTP client of this system.

Context

configure system time ntp peer (ipv4-address-no-zone | ipv6-address-no-zone) router-instance string

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

router-instance string

Synopsis

Router name or VPRN service name

Context

configure system time ntp peer (ipv4-address-no-zone | ipv6-address-no-zone) router-instance string

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

key-id reference

Synopsis

Specifies the key-id of the authentication key and its authentication type used by this node to receive and transmit NTP packets to and from an NTP node.

Context

configure system time ntp peer (ipv4-address-no-zone | ipv6-address-no-zone) router-instance string key-id reference

Tree
Introduced

16.0.R1

Platforms

All

prefer boolean

Synopsis

NTP server from which is preferred to receive time

Context

configure system time ntp peer (ipv4-address-no-zone | ipv6-address-no-zone) router-instance string prefer boolean

Tree
Default

false

Introduced

16.0.R1

Platforms

All

version number

Synopsis

NTP version number generated by the node

Context

configure system time ntp peer (ipv4-address-no-zone | ipv6-address-no-zone) router-instance string version number

Tree
Description

This command specifies the NTP version number that is generated by the node. This command does not need to be configured when in client mode, in which case all three versions are accepted.

Range

2 to 4

Default

4

Introduced

16.0.R1

Platforms

All

server [ip-address] (ipv4-address-no-zone | ipv6-address-no-zone | keyword) router-instance string

Synopsis

Enter the server list instance

Context

configure system time ntp server (ipv4-address-no-zone | ipv6-address-no-zone | keyword) router-instance string

Tree
Introduced

16.0.R1

Platforms

All

[ip-address] (ipv4-address-no-zone | ipv6-address-no-zone | keyword)

Synopsis

IP address of an external NTP server

Context

configure system time ntp server (ipv4-address-no-zone | ipv6-address-no-zone | keyword) router-instance string

Options

ptp

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

router-instance string

Synopsis

Router name or VPRN service name

Context

configure system time ntp server (ipv4-address-no-zone | ipv6-address-no-zone | keyword) router-instance string

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

key-id reference

Synopsis

Specifies the key-id of the authentication key and its authentication type used by this node to receive and transmit NTP packets to and from an NTP node.

Context

configure system time ntp server (ipv4-address-no-zone | ipv6-address-no-zone | keyword) router-instance string key-id reference

Tree
Introduced

16.0.R1

Platforms

All

prefer boolean

Synopsis

NTP server from which is preferred to receive time

Context

configure system time ntp server (ipv4-address-no-zone | ipv6-address-no-zone | keyword) router-instance string prefer boolean

Tree
Default

false

Introduced

16.0.R1

Platforms

All

version number

Synopsis

NTP version number generated by the node

Context

configure system time ntp server (ipv4-address-no-zone | ipv6-address-no-zone | keyword) router-instance string version number

Tree
Description

This command specifies the NTP version number that is generated by the node. This command does not need to be configured when in client mode, in which case all three versions are accepted.

Range

2 to 4

Default

4

Introduced

16.0.R1

Platforms

All

prefer-local-time boolean

Synopsis

Use local time over UTC time in the system

Default

false

Introduced

16.0.R1

Platforms

All

sntp

Synopsis

Enter the sntp context

Tree
Introduced

16.0.R1

Platforms

All

admin-state keyword

Synopsis

Administrative state of the SNTP protocol execution

Default

disable

Options

enable, disable

Introduced

16.0.R1

Platforms

All

server [ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)

Synopsis

Enter the server list instance

Context

configure system time sntp server (ipv4-address-no-zone | ipv6-address-no-zone)

Tree
Introduced

16.0.R1

Platforms

All

[ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)

Synopsis

IP address of the SNTP server

Context

configure system time sntp server (ipv4-address-no-zone | ipv6-address-no-zone)

Notes

This element is part of a list key.

Introduced

16.0.R1

Platforms

All

interval number

Synopsis

Frequency of querying the server

Context

configure system time sntp server (ipv4-address-no-zone | ipv6-address-no-zone) interval number

Tree
Range

64 to 1024

Default

64

Units

seconds

Introduced

16.0.R1

Platforms

All

prefer boolean

Synopsis

Preference value for this SNTP server

Context

configure system time sntp server (ipv4-address-no-zone | ipv6-address-no-zone) prefer boolean

Tree
Default

false

Introduced

16.0.R1

Platforms

All

version number

Synopsis

SNTP version supported by this server

Context

configure system time sntp server (ipv4-address-no-zone | ipv6-address-no-zone) version number

Tree
Range

1 to 3

Default

3

Introduced

16.0.R1

Platforms

All

sntp-state keyword

Synopsis

Mode for Simple Network Time Protocol (SNTP)

Default

unicast

Options

unicast, broadcast

Introduced

16.0.R1

Platforms

All

zone

Synopsis

Enter the zone context

Tree
Introduced

16.0.R1

Platforms

All

non-standard

Synopsis

Enter the non-standard context

Notes

The following are part of a choice: non-standard or standard.

Introduced

16.0.R1

Platforms

All

name string

Synopsis

Active non-standard time zone in this managed system

Tree
String Length

1 to 5

Introduced

16.0.R1

Platforms

All

offset string

Synopsis

Number of hours and minutes by which the time zone offsets from UTC

Tree
String Length

5 to 6

Introduced

16.0.R1

Platforms

All

standard

Synopsis

Enter the standard context

Tree
Notes

The following are part of a choice: non-standard or standard.

Introduced

16.0.R1

Platforms

All

name keyword

Synopsis

Active standard time zone in this managed system

Tree
Default

utc

Options

hst, akst, pst, mst, cst, est, ast, nst, utc, gmt, wet, cet, eet, msk, msd, awst, acst, aest, nzst

Introduced

16.0.R1

Platforms

All

transmission-profile [name] string

Synopsis

Enter the transmission-profile list instance

Introduced

16.0.R4

Platforms

All

[name] string

Synopsis

Name of file transmission profile

String Length

1 to 32

Notes

This element is part of a list key.

Introduced

16.0.R4

Platforms

All

ipv4-source-address string

Synopsis

IPv4 source address of the file transmission connections

Introduced

16.0.R4

Platforms

All

ipv6-source-address string

Synopsis

IPv6 source address of the file transmission connections

Introduced

16.0.R4

Platforms

All

redirection number

Synopsis

Maximum level of redirection

Range

1 to 8

Introduced

16.0.R4

Platforms

All

retry number

Synopsis

Number of attempts to reconnecting to the server

Tree
Range

1 to 256

Introduced

16.0.R4

Platforms

All

router-instance string

Synopsis

Router instance that hosts the file transmission connection

String Length

1 to 64

Default

Base

Introduced

16.0.R4

Platforms

All

timeout number

Synopsis

Timeout for a response from the server

Tree
Range

1 to 3600

Default

60

Units

seconds

Introduced

16.0.R4

Platforms

All