22. u Commands

22.1. ue

ue

Syntax 
ue [ieee-address] [detail]
Context 
[Tree] (show>call-trace>wlan-gw ue)
Full Contexts 
show call-trace wlan-gw ue
Description 

This command gives an overview of either all traces or a specific trace on the WLAN-GW.

Parameters 
ieee-address—
Displays information about the MAC address of this UE.
detail—
Displays detailed information about the job.
Output 

The following output is an example of traces of the UE being monitored.

Sample Output
Node# show call-trace hosts
===============================================================================
Call-trace hosts
===============================================================================
 MAC address Mask-name     Status      Msgs
-------------------------------------------------------------------------------
 00:0a:95:9d:68:16 N/A                running   16
-------------------------------------------------------------------------------
Number of call-trace debug jobs: 1
=============================================================================
Node# show call-trace hosts detail
===============================================================================
Call-trace  detail
===============================================================================
MAC address                            : 00:0a:95:95:34:0a                 Status : running
                   Capture format     : pcap
Nr. of captured msgs   : 4 Time limit            : 86400s
Size of captured msgs : 2620B Data limit             : 10MB
Started : NOV 12 2013, 15:28:17 UTC
Live output : N/A
-------------------------------------------------------------------------------
 
Supported Platforms 

7450 ESS, 7750 SR-7/12/12e, 7750 SR-a, 7750 SR-e, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

ue

Syntax 
ue [vlan qtag] [mpls-label label] [retail-svc-id service-id] [ssid service-set-id] [previous-access-point ip-address] [bd bridge-id]
ue mac ieee-address [bd bridge-id]
Context 
[Tree] (show>subscr-mgmt>wlan-gw ue)
Full Contexts 
show subscriber-mgmt wlan-gw ue
Description 

This command displays User Equipment (UE) information.

Parameters 
qtag
Displays information about the VLAN Q-tag present in the traffic received from this UE.
Values—
1 to 4095

 

label
Displays information about the MPLS label present in the traffic received from this UE.
service-id—
Specifies an existing service ID. If no svc-id is specified then it indicates that the interface is a network interface in the Base router instance.
Values—
{id | svc-name}

id:

1 to 2147483647

svc-name:

Specifies an existing service name, up to 64 characters (svc-name is an alias for input only. The svc-name gets replaced with an id automatically by SR OS in the configuration)

 

service-set-id
Displays information about the Service Set ID (SSID) of this UE.
ip-address
Displays information about the IP address of the previous Access Point (AP) of this UE.
bridge-id—
Displays specified HLE bridge domain information of this UE.
Values—
1 to 4294967295

 

ieee-address
Displays information about the MAC address of this UE.
Values—
xx:xx:xx:xx:xx:xx or xx-xx-xx-xx-xx-xx

 

Output 

The following displays WLAN-GW information.

Sample Output
System# show subscriber-mgmt wlan-gw ue
======================================================================
User Equipments
======================================================================
MAC address                 : 00:02:00:00:00:39
----------------------------------------------------------------------
VLAN Q-tag                  : 1
MPLS label                  : (Not Specified)
Tunnel router               : 50
Tunnel remote IP address    : 20C9::7:1:2
Tunnel local IP address     : 2032::1:1:7
Retail service              : N/A
SSID                        : 1
Previous Access Point IP    : (Not Specified)
IMSI                        : (Not Specified)
Last move time              : 2013/07/02 07:45:31
 
----------------------------------------------------------------------
No. of UE: 1
======================================================================
System#
Supported Platforms 

7750 SR, 7750 SR-e, 7750 SR-s, VSR

ue

Syntax 
ue [wlan-gw-group wlan-gw-group-id] [mda mda-id] [next-index index] [summary] [detail] [bd bridge-id] [ue-mac ieee-address] [ue-vlan vlan] [state-description state] [tunnel-router router-instance] [tunnel-source-ip ip-address] [tunnel-destination-ip ip-address] [tunnel-type tunnel-type] [ue-ip ipv4-address] [dhcp6-addr ipv6-address] [slaac-prefix ipv6-address] [aggregate-summary] [soft-quota-exhausted]
Context 
[Tree] (tools>dump>wlan-gw ue)
Full Contexts 
tools dump wlan-gw ue
Description 

This command dumps User Equipment (UE) information.

The summary option displays a count of UEs per ISA and the aggregate-summary displays a count of matched UEs over the whole WLAN-GW.

Output 

This command displays UE information.

Sample Output
/tools dump wlan-gw ue detail ue-mac 00:02:00:00:00:19 
===============================================================================
Matched 1 session on Slot #1 MDA #3
===============================================================================
Bridge Domain   : 0                    
UE-Mac          : 00:02:00:00:00:19     UE-vlan         : 3600                 
UE IP Addr      : N/A
UE Timeout      : N/A                  
DHCPv6 Timeout  : 3598 sec              SLAAC Timeout   : N/A                  
DHCPv6 IA-NA ID : 0x00000001            RA Timeout      : 1303 sec             
DHCPv6 Addr     : 4ffd:100:2d::1
SLAAC Prefix    : N/A
Description     : DSM-user
Auth/CoA-time   : 06/17/2021 07:18:10   Retail Service  : 300
Tunnel MDA/VM   : 1/3                   Tunnel Router   : 50                   
Shaper          : Default              
Tunnel Src IP   : 20c9::2:0:2
Tunnel Dst IP   : 2032::1:1:3
Tunnel Type     : L2TPv3                Tunnel Class    : Access               
L2TPv3 Session  : 0x0                   L2TPv3 Src Port : 1000                 
L2TPv3 Cookie   : 0x5                  
Anchor SAP      : 1/3/nat-out-ip:2049.2
Remote Type     : N/A                   Remote Service  : N/A                  
Remote Src IP   : N/A
Remote Dst IP   : N/A
AP-Mac          : 00:00:00:00:00:05     AP-RSSI         : Unknown              
AP-SSID         : "1"
Last-forward    : 06/17/2021 07:18:12   Last-move       : 06/17/2021 07:18:10  
Session Timeout : 06/17/2021 07:34:52   Idle Timeout    : 1000 sec
Acct Update     : 06/17/2021 07:18:12   Acct Interval   : 300 sec
Acct Session-Id : 01-02-00-00-00-19-00-00-00-01
Acct Policy     : wifi_isa_radius      
NAT Policy      : migrant_nat_300      
Redirect Policy : N/A                  
IP Filter       : N/A                  
App-profile     : N/A                  
Rx Oper PIR     : N/A                   Rx Oper CIR     : N/A                  
Tx Oper PIR     : N/A                   Tx Oper CIR     : N/A                  
Rx Frames       : 4                     Rx Octets       : 628                  
Tx Frames       : 2                     Tx Octets       : 466                  
Quota Direction : Both                 
Hard Octets     : N/A                   Soft Octets     : N/A                  
-------------------------------------------------------------------------------
===============================================================================
No sessions on Slot #1 MDA #4 match the query
No sessions on Slot #2 MDA #1 match the query
No sessions on Slot #2 MDA #2 match the query
Supported Platforms 

7750 SR, 7750 SR-e, 7750 SR-s, VSR

22.2. uni

uni

Syntax 
uni [port-id]
Context 
[Tree] (show>elmi uni)
Full Contexts 
show elmi uni
Description 

This command displays information about E-LMI mode, status, number of EVCs (SAPs) configured on the port for all of the ports on the service router.

Parameters 
port-id—
Displays UNI information for the specified port.
Values—
slot/mda/port

 

Output 

The following output is an example of elmi uni information.

Sample Output: show elmi uni
*A:Dut-C# show elmi uni  
===============================================================================
ELMI UNI-N Table
===============================================================================
Port     Mode  Status   #Evcs Uni Identifier                                   
-------------------------------------------------------------------------------
1/1/1    None  Up       0     10/100 Ethernet TX                               
1/1/2    None  Up       0     port-21                                          
1/1/3    None  Up       0     10/100 Ethernet TX                               
1/1/4    None  Up       0     10/100 Ethernet TX                               
1/1/5    Uni-N Up       2     UNI115                                           
1/1/6    None  Up       0     10/100 Ethernet TX                               
1/1/7    None  Up       0     10/100 Ethernet TX                               
1/1/8    None  Up       0     10/100 Ethernet TX                               
1/1/9    None  Up       0     10/100 Ethernet TX                               
1/1/10   None  Up       0     10/100 Ethernet TX                               
1/1/11   None  Up       0     10/100 Ethernet TX                               
1/1/12   None  Up       0     10/100 Ethernet TX                               
1/1/13   None  Up       0     10/100 Ethernet TX                               
1/1/14   None  Up       0     10/100 Ethernet TX                               
1/1/15   None  Up       0     10/100 Ethernet TX                               
1/1/16   None  Up       0     10/100 Ethernet TX                               
1/1/17   None  Up       0     10/100 Ethernet TX       
... 
===============================================================================
*A:Dut-C#
 
 
*A:Dut-C# show elmi uni 1/1/5 
===============================================================================
Uni-N Detailed Information
===============================================================================
Uni Mode      : Uni-N                  Link Status         : Up
Uni Identifier: UNI115
T391          : 10 seconds             T392                : 15 seconds
N393          : 4                      UniType             : Bundling
Rx Enq. Time  : 02/18/2010 17:11:44    Tx Status Time      : 02/18/2010 17:11:44
Rx Enq Msg    : 24                     Tx Status Msg       : 24
Rx Check Time : 02/18/2010 17:12:34   Tx Check Time       : 02/18/2010 17:12:34
Rx Inv. SeqNum: 0                     Tx Async Status Msg : 0
Enq Timeouts  : 0                     Discard Msg         : 0
===============================================================================
*A:Dut-C# 
Supported Platforms 

All

22.3. unicast

unicast

Syntax 
unicast [router router-instance | service-name service-name]
Context 
[Tree] (show>system>ptp unicast)
Full Contexts 
show system ptp unicast
Description 

This command displays unicast negotiation information.

Parameters 
router-instance—
Shows only the information for a specific router instance.
Values—
router-name – Base
vprn-svc-id – 1 to 2147483647

 

service-name—
Specifies the service name used to identify the router instance. The name can be up to 64 characters.
Output 

The following output is an example of PTP unicast information.

Sample Output
*A:Dut-C# show system ptp unicast                         
===============================================================================
IEEE 1588/PTP Unicast Negotiation Information
===============================================================================
Router                                                       
  IP Address      Dir Type     Rate       Duration State    Time
-------------------------------------------------------------------------------
100
  10.0.0.1        Rx  Announce 1 pkt/2 s  300      Granted  02/07/2014 16:52:35
  10.0.0.1        Rx  Sync     64 pkt/s   300      Granted  02/07/2014 16:52:39
  10.0.0.1        Tx  DelayReq 64 pkt/s   300      Granted  02/07/2014 16:52:39
  10.0.0.1        Rx  DelayRsp 64 pkt/s   300      Granted  02/07/2014 16:52:39
200
  192.168.0.2     Tx  Announce 1 pkt/2 s  300      Granted  02/07/2014 16:50:47
  192.168.0.2     Tx  Sync     64 pkt/s   300      Granted  02/07/2014 16:50:52
  192.168.0.2     Rx  DelayReq 64 pkt/s   300      Granted  02/07/2014 16:50:52
  192.168.0.2     Tx  DelayRsp 64 pkt/s   300      Granted  02/07/2014 16:50:52
-------------------------------------------------------------------------------
PTP Peers               : 2
Total Packet Rate       : 385 packets/second
===============================================================================
 
 
A:bksim1618# show system ptp router 1 unicast 
===============================================================================
IEEE 1588/PTP Unicast Negotiation Information
===============================================================================
Router                                                       
  IP Address      Dir Type     Rate       Duration State    Time
-------------------------------------------------------------------------------
1
  10.2.1.20       Rx  Announce 1 pkt/2 s  300      Granted  04/21/2013 19:14:19
  10.2.1.20       Tx  Announce 1 pkt/2 s  300      Granted  04/21/2013 19:13:25
  10.2.1.20       Tx  Sync     64 pkt/s   300      Granted  04/21/2013 19:13:30
  10.2.1.20       Rx  DelayReq 64 pkt/s   300      Granted  04/21/2013 19:13:30
  10.2.1.20       Tx  DelayRsp 64 pkt/s   300      Granted  04/21/2013 19:13:30
  10.3.1.19       Rx  Announce 1 pkt/2 s  300      Granted  04/21/2013 19:13:16
  10.3.1.19       Rx  Sync     64 pkt/s   300      Granted  04/21/2013 19:13:21
  10.3.1.19       Tx  DelayReq 64 pkt/s   300      Granted  04/21/2013 19:13:21
  10.3.1.19       Rx  DelayRsp 64 pkt/s   300      Granted  04/21/2013 19:13:21
-------------------------------------------------------------------------------
PTP Peers               : 2
Total Packet Rate       : 385 packets/second
===============================================================================
*A:bksim1618#
Supported Platforms 

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS-20, 7950 XRS-20e, 7950 XRS-40

22.4. unknown-origin

unknown-origin

Syntax 
unknown-origin
Context 
[Tree] (show>subscr-mgmt>errors unknown-origin)
Full Contexts 
show subscriber-mgmt errors unknown-origin
Description 

This command lists errors of an unknown origin. Errors shown do have a corresponding SAP ID or a SDP ID.

Supported Platforms 

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

22.5. unsubscribe-from

unsubscribe-from

Syntax 
unsubscribe-from log-id log-id
Context 
[Tree] (tools>perform>log unsubscribe-from)
Full Contexts 
tools perform log unsubscribe-from
Description 

This command cancels the subscription of the current CLI session to the specified CLI log.

Parameters 
log-id—
Specifies the log ID from which cancellation is requested.
Values—
1 to 101

 

Supported Platforms 

All

22.6. update-path

update-path

Syntax 
update-path {lsp lsp-name path current-path-name new-path new-path-name}
Context 
[Tree] (tools>perform>router>mpls update-path)
Full Contexts 
tools perform router mpls update-path
Description 

This command enables you to instruct MPLS to replace the path of a primary or secondary LSP. The primary or secondary LSP path is indirectly identified via the current-path-name value. The same path name cannot be used more than once in a given LSP name.

This command applies to both CSPF LSP and to a non-CSPF LSP. This command will only work when the specified current-path-name has the adaptive option enabled. The adaptive option can be enabled at the LSP level or the path level.

The new path must have been configured in the CLI or provided via SNMP. The CLI command for entering the path is

configure router mpls path path-name

The command fails if any of the following conditions exist:

  1. The specified current-path-name of this LSP does not have the adaptive option enabled.
  2. The specified new-path-name value does not correspond to a previously defined path.
  3. The specified new-path-name value exists but is being used by any path of the same LSP, including this one.

When you execute this command, MPLS performs the following procedures:

  1. MPLS performs a single MBB attempt to move the LSP path to the new path.
  2. If the MBB is successful, MPLS updates the new path
    1. MPLS writes the corresponding NHLFE in the data path if this path is the current backup path for the primary.
    2. If the current path is the active LSP path, it will update the path, write the new NHLFE in the data path that will cause traffic to switch to the new path.
  3. If the MBB is not successful, the path retains its current value.
  4. The update-path MBB has the same priority as the manual re-signal MBB.
Supported Platforms 

All

22.7. uplink

uplink

Syntax 
uplink
uplink mgw-address-cache [arec] [snaptr] [srv]
uplink mgw-address-cache apn apn-domain-string
Context 
[Tree] (show>router>gtp uplink)
Full Contexts 
show router gtp uplink
Description 

This command displays operational information related to the usage of GTP uplink interfaces (Gn, S2a, S2b) in this routing context.

Parameters 
arec—
Displays A-records.
snaptr—
Displays Straightforward-NAPTR information.
srv—
Displays SRV records.
apn-domain-string
Specifies the Access Point Name (APN) of this DNS cache entry.
Output 

The following is an example of GTP uplink information.

Sample Output
Node# show router 10 gtp uplink mgw-address-cache 
=============================================================================== 
Mobile Gateway address cache 
=============================================================================== 
APN : full.dotted.apn.apn.epc.mnc010.mcc206.3gppnetwork.org 
------------------------------------------------------------------------------- 
Mobile Gateway address : 5.20.1.2 
Time left (s) : 3587 
------------------------------------------------------------------------------- 
No. of cache entries: 1 
No. of Mobile gateways: 1 
=============================================================================== 
Supported Platforms 

7750 SR, 7750 SR-e, 7750 SR-s, VSR

uplink

Syntax 
uplink
uplink session imsi imsi apn apn-string
uplink session [peer-address ip-address] [router router-instance] [remote-control-teid teid] [local-control-teid teid] [detail]
uplink session imsi imsi
Context 
[Tree] (show>subscr-mgmt>gtp uplink)
Full Contexts 
show subscriber-mgmt gtp uplink
Description 

This command displays box-wide operational information related to the GTP uplink interfaces (Gn, S2a, S2b).

Parameters 
imsi
Specifies the IMSI (International Mobile Subscriber Identity) of this UE.
apn-string
Specifies the APN (Access Point Name).
ip-address
Specifies the IP address of the Mobile Gateway (PGW or GGSN).
router-instance
Specifies the identifier of the virtual router instance where the GTP tunnel is terminated.
remote-control-teid teid
Specifies the remote control plane Tunnel Endpoint Identifier (TEID).
local-control-teid teid
Specifies the local control plane TEID.
detail—
Displays detailed information.
Output 

The following is an example of GTP uplink information

Sample Output
Node# show subscriber-mgmt gtp uplink session detail 
=============================================================================== 
GTP sessions 
=============================================================================== 
IMSI : 206100000000041 
APN : full.dotted.apn.mnc010.mcc206.gprs 
------------------------------------------------------------------------------- 
Mobile Gateway router : "Base" 
Mobile Gateway address : 5.20.1.2 
Remote control TEID : 1119232 
Local control TEID : 4293918976 
Bearer 5 rem TEID : 1074861061 
Bearer 5 loc TEID : 4293919013 
------------------------------------------------------------------------------- 
No. of GTP sessions: 1 
===============================================================================
Supported Platforms 

7750 SR, 7750 SR-e, 7750 SR-s, VSR

uplink

Syntax 
uplink
Context 
[Tree] (clear>router>gtp uplink)
Full Contexts 
clear router gtp uplink
Description 

This command clears information related to the GTP uplink state for the routing context.

Supported Platforms 

7750 SR, 7750 SR-e, 7750 SR-s, VSR

22.8. upnp

upnp

Syntax 
upnp
Context 
[Tree] (show>service upnp)
Full Contexts 
show service upnp
Description 

Commands in this context display UPnP policy parameters.

Supported Platforms 

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

22.9. upnp-mappings

upnp-mappings

Syntax 
upnp-mappings subscriber sub-ident-string protocol {tcp | udp} outside-port port-number
upnp-mappings subscriber sub-ident-string
Context 
[Tree] (clear>nat upnp-mappings)
Full Contexts 
clear nat upnp-mappings
Description 

This command remove UPnP mappings for the specified subscriber. If protocol and outside-port are not specified, then all UPnP mappings of subscriber will be removed.

Parameters 
subscriber sub-ident-string
clears mappings for the specified subscriber.
protocol {tcp | udp} —
Clears the mappings for the specified protocol.
outside-port port-number
Clears mappings for the specified outside-port.
Supported Platforms 

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

22.10. upnp-policy

upnp-policy

Syntax 
upnp-policy policy-name
upnp-policy policy-name statistics
upnp-policy
Context 
[Tree] (show>service>upnp upnp-policy)
Full Contexts 
show service upnp upnp-policy
Description 

This commands displays upnp-policy related information.

Without any parameters the system outputs a list of configured UPnP policies.

Parameters 
policy-name—
The system displays the configuration of the specified policy.
statistics—
The system displays statistics for the specified policy.
Output 

The following is sample output for this command.

Sample Output
show service upnp upnp-policy 
===============================================================================
UPnP policies
===============================================================================
Policy                           Description
-------------------------------------------------------------------------------
test                             
-------------------------------------------------------------------------------
No. of UPnP policies: 1
===============================================================================
 
show service upnp upnp-policy "test" 
===============================================================================
UPnP Policy test
===============================================================================
Description                 : (Not Specified)
Mapping limit               : 256
Strict mode                 : false
HTTP listening port         : 5000
Last Mgmt Change            : 01/26/2015 19:23:41
-------------------------------------------------------------------------------
Active mappings             : 2
Mapped subscribers          : 1
Associated subscribers      : 1
===============================================================================
 
 
show service upnp upnp-policy "test" statistics 
===============================================================================
UPnP Policy test Statistics
===============================================================================
rx SSDP M-SEARCH                                        : 109
rx HTTP GET device description                          : 0
rx HTTP GET service description                         : 109
rx UPnP AddPortMapping                                  : 6
rx UPnP ClearPortMapping                                : 0
rx UPnP DeletePortMapping                               : 1
rx UPnP ForceTermination                                : 0
rx UPnP GetConnectionTypeInfo                           : 0
rx UPnP GetExternalAddress                              : 6
rx UPnP GetGenericPortMappingEntry                      : 43
rx UPnP GetNATRSIPStatus                                : 8
rx UPnP GetSpecificPortMappingEntry                     : 1
rx UPnP GetStatusInfo                                   : 49
rx UPnP RequestConnection                               : 0
rx UPnP SetConnectionType                               : 0
rx UPnP unsupported optional action                     : 6
rx UPnP invalid request                                 : 0
tx SSDP M-SEARCH                                        : 109
tx TCP reset                                            : 0
tx HTTP OK                                              : 109
tx UPnP OK                                              : 101
tx UPnP error                                           : 19
drop no memory                                          : 0
portmapping created                                     : 4
portmapping updated                                     : 1
portmapping failed: conflict with other host            : 0
portmapping failed: conflict with pinhole               : 0
portmapping failed: hit limits                          : 0
portmapping failed: other reason                        : 0
rx HTTP (UN)SUBSCRIBE                                   :  0
tx HTTP 501 Not Implemented                             : 0
drop rate limited                                       : 0
 
===============================================================================
Supported Platforms 

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

22.11. upnp-policy-statistics

upnp-policy-statistics

Syntax 
upnp-policy-statistics policy-name
Context 
[Tree] (clear>nat upnp-policy-statistics)
Full Contexts 
clear nat upnp-policy-statistics
Description 

This command clears UPnP policy statistics.

Parameters 
policy-name—
Clears UPnP policy statistics for the specified policy.
Supported Platforms 

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

22.12. uptime

uptime

Syntax 
uptime
Context 
[Tree] (show uptime)
Full Contexts 
show uptime
Description 

This command displays the time since the system started.

Output 

The following output is an example of uptime information, and Table 557 describes the output field.

Sample Output
A:ALA-1# show uptime
System Up Time         : 11 days, 18:32:02.22 (hr:min:sec)
 
A:ALA-1#
Table 557:  Uptime Output

Label

Description

System Up Time

Displays the length of time the system has been up in days, hr:min:sec format.

Supported Platforms 

All

22.13. url-filter

url-filter

Syntax 
url-filter [url-filter-name]
url-filter url-filter-name isa mda-id/esa-vm-id [detail]
url-filter url-filter-name web-service [profile profile-name]
Context 
[Tree] (show>app-assure>group url-filter)
Full Contexts 
show application-assurance group url-filter
Description 

This command displays information about the configured url-filter policy along with some associated raw statistics. These output statistics are:

  1. Vlan Id: Vlan id used by the aa interfaces
  2. Admin Status: Up / Down
  3. Oper Status: Up / Down
  4. Oper Flags: adminDown, no-aa-if, aa-if-down, icap-server-down
  5. Default Action: default policy action taken by the url-filter
  6. ICAP HTTP Redirect: HTTP redirect Policy
  7. AQP Referenced: Yes/No
  8. HTTP Request: Number of subscriber HTTP requests
  9. HTTP Errors: Impossible to send an ICAP request, this can be caused by either no TCP connection available, associated flow with a drop action due to another aqp policy, system resource exhausted
  10. ICAP Request: Number of ICAP request sent
  11. ICAP Errors: ICAP request timeout, unexpected ICAP response, internal TCP errors.
  12. Custom-x-header: Name of the custom-x-header, if configured. If it is not configured, the value is "Not Specified".

In addition to these counters the system will count the type of action taken by the url-filter policy (allow, block, redirect, default) as well as the type of responses received from the icap server (allow, block, redirect, late).

Parameters 
url-filter-name—
Specifies the name of the url-filter policy.
mda-id/esa-vm-id—
Specifies the mda-id/esa-vm-id reference of the ISA card.
detail—
Specifies detailed statistics related to the ISA card.
profile-name—
Specifies the name of a configured profile for web service, up to 256characters.
Output 

The following is an example show output for the url-filter command.

Table 558 describes the output fields.

URL Filter Show Command Sample Output
# show application-assurance group 1 url-filter "web-serv1" isa 7/2
=============================================================================
Application Assurance Group 1 URL Filter " web-serv1" ISA 7/2
=============================================================================
Description            : Url filter WebService
Admin Status           : Up
Oper Status            : Down
Oper Flags             : web-service-down 
DNS Oper Status        : Down
DNS Oper Flags         : unreachable 
HTTP Request Filtering : all
AQP Referenced         : Yes
-----------------------------------------------------------------------------
URL Stats Summary
-----------------------------------------------------------------------------
Total Requests  : 0                     Default Action  : 0
Requests Allowed: 0                     Reqs Block/Redir: 0
-----------------------------------------------------------------------------
Local Filter
-----------------------------------------------------------------------------
allow-list             : allowlist1
  Admin Status         : Up
  Oper Status          : Up
  Oper Flags           : <none>
  Number of URLs       : 1
  URL-List Lookups     : 0
    Match              : 0
    Miss               : 0
 
deny-list              : denylist1
  Admin Status         : Up
  Oper Status          : Up
  Oper Flags           : <none>
  Number of URLs       : 1
  Default Action       : block-all 
  HTTP Redirect        : (Not Specified)
  URL-List Lookups     : 0
    Match              : 0            
    Miss               : 0
    Default Action     : 0
 
deny-list              : denylist2
  Admin Status         : Up
  Oper Status          : Up
  Oper Flags           : <none>
  Number of URLs       : 1
  Default Action       : block-all 
  HTTP Redirect        : (Not Specified)
  URL-List Lookups     : 0
    Match              : 0
    Miss               : 0
    Default Action     : 0
-----------------------------------------------------------------------------
Web Service Filter
-----------------------------------------------------------------------------
Classifier             : web-service-1
Category-set-id        : 1
default-profile        : prof1
VLAN Id                : 1
FQDN                   : nokia-api.webtitancloud.com
DNS Address            : 12.0.0.100
Default Action         : allow 
HTTP Redirect          : ws
AA Interface           : to_isa_7/2
Service                : VPRN 1
SAP Id                 : 7/2/aa-svc:1
Client IP              : 10.1.1.2/31
 
Web Service Filter Stats
Class Ovrd Lkup : 0                     Class Ovrd match: 0
Cache Lookup    : 0                     Cache size      : 0
Cache match     : 0                     Cache max size  : 20971520
Cache miss      : 0                     
 
URL Request     : 0                     Default Action  : 0
URL Response    : 0                     Late Response   : 0
  Allow         : 0                       Packet Discard: 0
  Block         : 0                       Octet Discard : 0
  Redirect      : 0                     
-----------------------------------------------------------------------------
ISA 7/2 Web Service Connection Stats
-----------------------------------------------------------------------------
Established Connections   : 0 of 0 connections
Request Rate              : 0 per second
Round Trip Time           : 0 microseconds
=============================================================================
Web-service URL Filter Show Command Sample Output
# show application-assurance group 1 url-filter "testFilter" web-service
-------------------------------------------------------------------------------
Web services for url-filter "testFilter"
-------------------------------------------------------------------------------
Category-set-id    : 1
-------------------------------------------------------------------------------
===============================================================================
Profile Categories
===============================================================================
Profile Name                            Blocked Categories  Allowed Categories
-------------------------------------------------------------------------------
testProfile                             1                   54
===============================================================================
# show application-assurance group 1 url-filter "testFilter" web-
service profile "testProfile"
-------------------------------------------------------------------------------
Web service profile "testProfile"
-------------------------------------------------------------------------------
Category-set-id    : 1
Description        :
-------------------------------------------------------------------------------
===============================================================================
Blocked Categories
===============================================================================
Category Id         Category Name
-------------------------------------------------------------------------------
25                  Personal Webpages
===============================================================================
===============================================================================
Allowed Categories
===============================================================================
Category Id         Category Name
-------------------------------------------------------------------------------
1                   Compromised
2                   Criminal Skills/Hacking
3                   Hate Speech
4                   Illegal Drugs
5                   Phishing/Fraud
6                   Spyware and Malicious Sites
7                   Nudity
8                   Mature
9                   Pornography/Sex
10                  Violence
11                  Weapons
12                  Anonymizer
13                  Computers and Technology
14                  Download Sites
15                  Translator
16                  Alcohol
17                  Health
18                  Pharmacy
19                  Tobacco
20                  Gambling
21                  Games
22                  Cars/Transportation
23                  Dating & Relationships
24                  Home/Leisure
26                  Restaurants
27                  Sports and Recreation
28                  Travel
29                  Government
30                  Military
31                  Non-profits
32                  Politics and Law
33                  Religion
34                  Education
35                  Art
36                  Entertainment and Videos
37                  Humor
38                  Music
39                  News
40                  Finance
41                  Internet Watch Foundation List
42                  Shopping
43                  Chat/IM
44                  Community Sites
45                  Social Networking
46                  Web-based Email
47                  Portal Sites
48                  Search Engines
49                  Online Ads
50                  Business/Services
51                  Job Search
52                  Real Estate
53                  Spam
54                  Miscellaneous
55                  Uncategorized
===============================================================================
Table 558:  Web-service URL Filter Show Command Field Descriptions

Label

Description

Category-set-id

The ID of the category set used for URL categorization.

Description

The description of the web-service profile.

Profile Name

The name of the web-service profile.

Blocked Categories

The blocked categories for the web-service profile.

Allowed Categories

The allowed categories for the web-service profile.

Category Id

The ID of the blocked or allowed category.

Category Name

The name of the blocked or allowed category.

Supported Platforms 

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

22.14. url-list

url-list

Syntax 
url-list url-list-name
Context 
[Tree] (show>app-assure>group url-list)
Full Contexts 
show application-assurance group url-list
Description 

This command displays information about the configured URL list.

Parameters 
url-list-name—
Specifies the name of the URL list.
Output 

The following output examples show URL list information.

Output
# show application-assurance group 1 url-list "allow-list1"
=============================================================================
Application Assurance Group 1 url-list "allow-list1"
=============================================================================
Description : Default Url-list object
Size : standard
Host Expressions : enabled
Admin Status : Up
Oper Status : Up
Oper Flags : <none>
File deployed to ISAs : Yes
-----------------------------------------------------------------------------
Upgrade Statistics
-----------------------------------------------------------------------------
Last Success : 06/19/2020 02:57:06
Deployed
File Name : cf1:/expr_15000.vm.only.expr
URL Entries : 15000 (100.00% full)
URL Characters : 249390 ( 5.08% full)
URL Host Expr Entries: 15000 (100.00% full)
Blank/Comment Lines : 60519
Last Attempt : 06/19/2020 02:57:06
Result : Success

Table 559 describes the URL list show command output fields.

Table 559:  URL List Show Command Field Descriptions

Label

Description

Description

The description of the URL list

Size

[standard | extended] Size parameter for the URL list

Host Expressions

If the host is enabled or disabled

Admin Status

[Up | down] - Administrative status of the URL list

Oper Status

[Up | down] - Operational status of the URL list

Oper Flags

[admin-down | file-does-not-exist |invalid-file-format | too-many-urls | switch-over-error]

File Deployed to ISA

[Yes | No] - This flag describes if the file located in the compact flash is the one deployed in the ISA, in the event the file is overwritten and before the admin upgrade command is used this flag will display "No".

Upgrade Statistics

Last Success

Last time the list was successfully upgraded

File Name

File name for the last successful upgrade

URL Entries

Number of URLs loaded at the last success and percentage to full

URL Characters

Number of characters loaded at the last success and percentage to full

URL Host Expr Entries

URL host expression entries

Blank/CommentLines

Number of blank or commented out lines

Last Attempt

Last time the operator tried to upgrade the list

Result

[Success | Failure]. Result of the last upgrade

File Name

File name for the last upgrade attempt

Supported Platforms 

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

22.15. usage

usage

Syntax 
usage
Context 
[Tree] (tools>dump>service>evpn usage)
Full Contexts 
tools dump service evpn usage
Description 

This command displays the consumed EVPN resources in the system. The Vxlan Destinations include static VXLAN destinations as well as Ethernet Segment (ES) Vxlan destinations.

Output 

Sample Output
*A:PE-1# tools dump service evpn usage            
 
vxlan-evpn-mpls usage statistics at 04/16/2018 17:56:02:
 
MPLS-TEP                                        :             0
VXLAN-TEP                                       :             3
Total-TEP                                       :      3/ 16383
 
Mpls Dests (TEP, Egress Label + ES + ES-BMAC)   :             0
Mpls Etree Leaf Dests                           :             0
Vxlan Dests (TEP, Egress VNI)                   :             5
Total-Dest                                      :      5/196607
 
Sdp Bind +  Evpn Dests                          :      5/245759
ES L2/L3 PBR                                    :      0/ 32767
Evpn Etree Remote BUM Leaf Labels               :             0
 

22.16. usage-monitor

usage-monitor

Syntax 
usage-monitor app-group [app-group-name] count
usage-monitor application [application-name] count
usage-monitor charging-group [charging-group-name] count
usage-monitor count
usage-monitor status
Context 
[Tree] (show>app-assure>group>aa-sub usage-monitor)
Full Contexts 
show application-assurance group aa-sub usage-monitor
Description 

This command displays per-subscriber usage-monitoring statistics.

Parameters 
app-group-name—
Specifies an application group name, up to 32 characters.
application-name—
Specifies an application name, up to 32 characters.
charging-group-name—
Specifies a charging group name, up to 32 characters.
count—
Displays counters.
status—
Displays the status.
Supported Platforms 

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

22.17. user

user

Syntax 
user [user-id] [detail]
user [user-id] lockout
Context 
[Tree] (show>system>security user)
Full Contexts 
show system security user
Description 

This command displays user registration information.

If no command line options are specified, summary information for all users displays.

Parameters 
user-id—
Displays information for the specified user.
Default—
All users
detail—
Displays detailed user information to the summary output.
lockout—
Displays information about any users who are currently locked out.
Output 

The following are examples of user output information.

Table 560 describes user output fields.

Sample Output
show system security user
===============================================================================
Users
===============================================================================
User ID   New  User Permissions                    Password Login   Failed Local
          Pwd  console ftp li snmp  netconf  grpc  Expires  Attempt Logins Conf
-------------------------------------------------------------------------------
admin     n    y       n   n  n              n     never    2       0      y
-------------------------------------------------------------------------------
Number of users : 1
===============================================================================
 
 
show system security user detail
===============================================================================
Users
===============================================================================
User ID      New User Permissions                 Password Login   Failed Local
             Pwd console ftp li snmp netconf grpc Expires  Attempt Logins Conf
-------------------------------------------------------------------------------
admin        n   y       y   n  y    y       n    never    2       0      y
-------------------------------------------------------------------------------
Number of users : 1
===============================================================================
===============================================================================
User Configuration Detail
===============================================================================
===============================================================================
user id            : admin
-------------------------------------------------------------------------------
console parameters
-------------------------------------------------------------------------------
new pw required    : no                 cannot change pw   : no
home directory     :
restricted to home : no
login exec file    :
profile            : default
profile            : administrative
locked-out         : no
-------------------------------------------------------------------------------
snmp parameters
-------------------------------------------------------------------------------
authentication     : sha      key    : 6b1f96ef120c735d6e4015054d615857bb474d1f
privacy            : aes      key    : 6b1f96ef120c735d6e4015054d615857
group              : moje
===============================================================================
 
show system security user lockout
===============================================================================
Currently Failed Login Attempts
===============================================================================
User ID Remaining Login attempts Remaining Lockout Time (min:sec)
-------------------------------------------------------------------------------
user123 N/A 9:56
-------------------------------------------------------------------------------
Number of users : 1
===============================================================================
Table 560:  Show System Security User Output Fields

Label

Description

User ID

The name of a system user.

Users

New Pwd

y — The user must change their password at the next login.

n — The user does not need to change their password at the next login.

User Permissions

console:

y — The user is authorized for console access.

n — The user is not authorized for console access.

ftp:

y — The user is authorized for FTP access.

n — The user is not authorized for FTP access.

li:

y — The user is authorized for LI access.

n — The user is not authorized for LI access.

snmp:

y — The user is authorized for SNMP access.

n — The user is not authorized for SNMP access.

netconf:

y — The user is authorized for NETCONF access.

n — The user is not authorized for NETCONF access.

grpc:

y — The user is authorized for gRPC access.

n — The user is not authorized for gRPC access.

Password Expires

The number of days after which the user must change their password.

Login Attempt

The number of times that the user has attempted to log in, irrespective of whether the login succeeded or failed.

Failed Logins

The number of unsuccessful login attempts.

Local Conf

y — Password authentication is based on the local password database.

n — Password authentication is not based on the local password database.

Number of users

The total number of listed users.

User Configuration Detail

new pw required

yes — The user must change their password at the next login.

no — The user does not need to change their password at the next login.

cannot change pw

yes — The user does not have the ability to change their password.

no — The user has the ability to change their password.

home directory

The local home directory for the user for both console and FTP access.

restricted to home

yes — The user is not allowed to navigate to a directory higher in the directory tree on the home directory device.

no — The user is allowed to navigate to a directory higher in the directory tree on the home directory device.

login exec file

The user’s login exec file which executes whenever the user successfully logs in to a console session.

profile

The security profiles associated with the user.

locked-out

Whether the user is currently locked out, and, if they are locked out, how much time remains before the user can attempt to log into the node again.

Currently Failed Login Attempts

Remaining Login Attempts

The number of login attempts remaining before the user is locked out.

Remaining Lockout Time (min:sec)

The number of minutes and seconds remaining until the lockout expires and the user can attempt to log in again.

With the introduction of the PKI on an SR (SSH Server) the authentication process can be done via PKI or password. SSH client usually authenticate via PKI and password if PKI is configured on the client. In this case PKI takes precedence over password in most clients.

All client authentications are logged and display in the show>system>security>user detail. Table 561 shows the rules where pass and fail attempts are logged.

Table 561:  Pass/Fail Login Attempts

Authentication Order

Client (such as, putty)

Server (such as, SR)

CLI Show System Security Attempts (SR)

Private Key Programmed

Public Key Configured

Password Configured

Logins Attempts

Failed Logins

1. Public Key

Yes

Yes

N/A

Increment

2. Password

Yes

Yes (No match between client and server. Go to password.)

Yes

Increment

Yes

No

Yes

Increment

No

N/A

Yes

Increment

No

N/A

No

Increment

1. Public Key (only)

Yes

Yes

N/A

Increment

Yes

Yes (No match between client and server. Go to password.)

Increment

Yes

N/A

Increment

No

N/A

Increment

Supported Platforms 

All

22.18. users

users

Syntax 
users
Context 
[Tree] (show users)
Full Contexts 
show users
Description 

Displays console user login and connection information.

Output 

The following is an example of user information.

Table 562 describes show users output fields.

Sample Console Users Output
*A:node-1# show users
===============================================================================
User                             Type      Login time           Idle time
  Session ID   From
===============================================================================
                                 Console         --             3d 10:11:02 --
  6            --
admin                            SSHv2     12OCT2018 20:44:15   0d 00:00:50 A-
  83           192.168.0.10
admin                            SSHv2     12OCT2018 21:09:25   0d 00:00:00 --
 #84           192.168.0.10
-------------------------------------------------------------------------------
Number of users: 2
'#' indicates the current active session
'A' indicates user is in admin mode
===============================================================================
Table 562:  Show Users Output Fields

Label

Description

User

The user name.

Type

The user is authorized this access type.

From

The originating IP address.

Login time

The time the user logged in.

Idle time

The amount of idle time for a specific login.

Number of users

Displays the total number of users logged in.

Supported Platforms 

All

22.19. utilization

utilization

Syntax 
utilization [detail]
Context 
[Tree] (show>chassis>power-management utilization)
Full Contexts 
show chassis power-management utilization
Description 

This command displays power management utilization.

Parameters 
detail—
Displays detailed breakdown of devices.
Output 

The following output is an example of power management utilization information, and Table 563 describes the output fields.

Sample Output: show chassis power-management utilization
*A:Dut-A# show chassis power-management utilization 
===============================================================================
Chassis Power Utilization
===============================================================================
              SUPPLY                               PEAK DEMAND 
Power Capacity   : 22000.00 Watts        Fan           :   695.00 Watts (  3%)
Safety Level     : 13203.00 Watts (100%) IO Module     :  7163.09 Watts ( 33%)
Alert Level      :     0.00 Watts        CPM Module    :   392.86 Watts (  2%)
                                         Fabric Module :  1622.25 Watts (  7%)
                                         MDA Module    :  6023.07 Watts ( 27%)+
                                         CCM Module    :    50.82 Watts (  0%)
                                         Peak Util.    :  9924.02 Watts ( 45%)
                                                   CURRENT DEMAND
                                         Current Util. :  9623.01 Watts ( 44%)
===============================================================================
+  Power utilization of device already included in IO Module value
===============================================================================
Sample Output: show chassis power-management utilization detail
*A:DUT-A# show chassis power-management utilization                
===============================================================================
Chassis Power Zone 1 Utilization
===============================================================================
              SUPPLY                               PEAK DEMAND
Power Capacity   : 24000.00 Watts        Chassis/Fan   :   635.16 Watts (  3%)
                                         IO Module     :   355.67 Watts (  1%)
                                         CPM Module    :   546.64 Watts (  2%)
                                         Fabric Module :   746.00 Watts (  3%)
                                         MDA Module    :   748.69 Watts (  3%)
                                         XIOM Module   :   476.29 Watts (  2%)
                                         Peak Util.    :  3508.45 Watts ( 15%)
 
Mode             :    basic              Current util. :  3356.82 Watts ( 14%)
Reserved Power   :  6000.00 Watts        Safety Level  :  2892.00 Watts ( 20%)
Util. + Reserve  :  9356.82 Watts ( 39%) Safety Alert  : +1000.00 Watts
Remaining Power  : 14643.18 Watts        Alert Level   :  3892.00 Watts ( 26%)
===============================================================================
*A:DUT-A# show chassis power-management utilization detail
===============================================================================
Chassis Power Zone 1 Utilization (detail)
===============================================================================
              SUPPLY                               PEAK DEMAND
Power Capacity   : 24000.00 Watts        Chassis/Fan  
Power Module 1/1 :  6000.00 Watts          1/1         :    86.06 Watts (  0%)
Power Module 1/2 :  6000.00 Watts          1/2         :    77.45 Watts (  0%)
Power Module 1/3 :     0.00 Watts          1/3         :    76.62 Watts (  0%)
Power Module 1/4 :     0.00 Watts          1/4         :    86.06 Watts (  0%)
Power Module 1/5 :     0.00 Watts          1/5         :    76.62 Watts (  0%)
Power Module 1/6 :     0.00 Watts          1/6         :    77.45 Watts (  0%)
Power Module 1/7 :     0.00 Watts          1/7         :    77.45 Watts (  0%)
Power Module 1/8 :     0.00 Watts          1/8         :    77.45 Watts (  0%)
Power Module 1/9 :     0.00 Watts        IO Module    
Power Module 1/10:     0.00 Watts          Slot 2      :   355.67 Watts (  1%)
Power Module 2/1 :  6000.00 Watts        CPM Module   
Power Module 2/2 :  6000.00 Watts          Slot A      :   276.28 Watts (  1%)
Power Module 2/3 :     0.00 Watts          Slot B      :   270.36 Watts (  1%)
Power Module 2/4 :     0.00 Watts        Fabric Module
Power Module 2/5 :     0.00 Watts          Sfm 1       :    94.78 Watts (  0%)
Power Module 2/6 :     0.00 Watts          Sfm 2       :    91.44 Watts (  0%)
Power Module 2/7 :     0.00 Watts          Sfm 3       :    92.56 Watts (  0%)
Power Module 2/8 :     0.00 Watts          Sfm 4       :    94.78 Watts (  0%)
Power Module 2/9 :     0.00 Watts          Sfm 5       :    93.67 Watts (  0%)
Power Module 2/10:     0.00 Watts          Sfm 6       :    91.44 Watts (  0%)
                                           Sfm 7       :    93.67 Watts (  0%)
                                           Sfm 8       :    93.67 Watts (  0%)
                                         MDA Module   
                                           MDA 2/1     :   582.28 Watts (  2%)
                                           MDA 2/x2/1  :    72.63 Watts (  0%)
                                           MDA 2/x2/2  :    93.77 Watts (  0%)
                                         XIOM Module  
                                           XIOM 2/x2   :   476.29 Watts (  2%)
                                         Peak Util.    :  3508.45 Watts ( 15%)
 
Mode             :    basic              Current util. :  3329.57 Watts ( 14%)
Reserved Power   :  6000.00 Watts        Safety Level  :  2892.00 Watts ( 20%)
Util. + Reserve  :  9329.57 Watts ( 39%) Safety Alert  : +1000.00 Watts
Remaining Power  : 14670.43 Watts        Alert Level   :  3892.00 Watts ( 26%)
===============================================================================
*A:DUT-A#
Table 563:  Output Fields: show chassis power-management utilization

Label

Description

SUPPLY

Power Capacity

Indicates the total amount of power available to the chassis.

Safety Level

Specifies the configured Power Safety Level, which is a percentage of the worst case power consumption level.

Alert Level

Specifies the configured power level in watts, which causes the system to raise an alarm if the available power level drops below a set level.

DEMAND

Fan

Specifies the amount of power used for the fan tray indicated.

IO Module

Specifies the amount of power used for the IO Module indicated.

CPM Module

Specifies the amount of power used for the CPM indicated.

Fabric Module

Specifies the amount of power used for the SFM indicated.

MDA Module

Specifies the amount of power used for the line card indicated.

Current Util.

Specifies the total amount of power used for all system elements.

Peak Util.

Specifies peak utilization starting from bootup.

Supported Platforms 

7750 SR-s, 7950 XRS