Enter the application-assurance context
Commands in this context configure the attributes of Application Assurance (AA) operations.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the aarp list instance
configure application-assurance aarp number
Commands in this context define an Application Assurance Redundancy Protocol (AARP) instance. This instance is paired with the same AARP ID in a peer node, as part of the configuration to provide flow and packet asymmetry removal for traffic of a multi-homed SAP or spoke SDP.
100
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AARP ID
configure application-assurance aarp number
1 to 65535
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of the AARP instance
configure application-assurance aarp number admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance aarp number description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
AARP master selection mode
configure application-assurance aarp number master-selection-mode keyword
This command configures the AARP mode of operation with the peer instance. The modes affect the AARP state machine behavior according to the specified behavior.
minimize-switchovers
minimize-switchovers, inter-chassis-efficiency, priority-based-balance
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
AARP peer IP address
configure application-assurance aarp number peer (ipv4-address-no-zone | ipv6-address-no-zone)
This command defines the IP address of the AARP peer router, which must be a routable system IP address. If no peer is configured when the AARP is administratively enabled, it is configured as a single node AARP instance.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the peer-endpoint context
Commands in this context specify the attributes of the peer endpoint parent AA subscriber of the AARP peer.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the sap context
The following elements are part of a choice: sap or spoke-sdp.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Encapsulation type for peer endpoint SAP
configure application-assurance aarp number peer-endpoint sap encap-type keyword
null, dot1q, qinq
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AARP peer endpoint SAP ID
configure application-assurance aarp number peer-endpoint sap sap-id string
1 to 45
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AARP peer endpoint spoke SDP
configure application-assurance aarp number peer-endpoint spoke-sdp string
3 to 16
The following elements are part of a choice: sap or spoke-sdp.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
AARP priority
configure application-assurance aarp number priority number
This command defines the priority for the AARP instance. The priority value is used to determine the master and backup upon initialization or rebalance.
0 to 255
100
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the cflowd context
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the field list instance
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Cflowd record field name
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
User information comment
configure application-assurance cflowd field string comment string
1 to 32
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the flow-attribute context
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the attribute list instance
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Attribute name
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
User information comment
configure application-assurance flow-attribute attribute string comment string
1 to 32
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the group list instance
configure application-assurance group number
Commands in this context configure an Application Assurance group and partition parameters.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AA group ID
configure application-assurance group number
1 to 255
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the certificate-profile list instance
configure application-assurance group number certificate-profile string
Commands in this context create a certificate profile to be used for certificate-based encryption in HTTP header enrichment.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AA group certificate profile name
configure application-assurance group number certificate-profile string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of the AA certificate profile
configure application-assurance group number certificate-profile string admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number certificate-profile string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
Certificate file name
configure application-assurance group number certificate-profile string file string
1 to 95
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the cflowd context
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of cflowd export
configure application-assurance group number cflowd admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the collector list instance
Commands in this context configure flow data collectors for cflowd data.
In the current release, the system supports IPv4 addresses only for the cflowd collector host.
2
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP address of the remote cflowd collector host
This command configures the IP address of the remote cflowd collector host.
In the current release, the system supports IPv4 addresses only for the cflowd collector host.
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Cflowd collector host port number
This command configures the UDP port number used by the remote cflowd collector host.
In the MD-CLI, the default port is 4739.
1 to 65535
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of the cflowd export
configure application-assurance group number cflowd collector (ipv4-address-no-zone | ipv6-address-no-zone) port number admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number cflowd collector (ipv4-address-no-zone | ipv6-address-no-zone) port number description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the comprehensive context
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Cflowd flow sampling rate
configure application-assurance group number cflowd comprehensive flow-rate number
1 to 1000
flows per second
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Cflowd per-flow second sampling rate
configure application-assurance group number cflowd comprehensive flow-rate-2 number
1 to 1000
flows per second
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the template context
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the dynamic-fields context
Commands in this context configure the fields that are included in the exported cflowd template.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of the dynamic fields
configure application-assurance group number cflowd comprehensive template dynamic-fields admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Add a list entry for field
configure application-assurance group number cflowd comprehensive template dynamic-fields field string
This command adds a dynamic field to be included in the exported cflowd template.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Cflowd template dynamic field name
configure application-assurance group number cflowd comprehensive template dynamic-fields field string
This command specifies the name of the field to be included in the exported cflowd template.
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Field selection method
configure application-assurance group number cflowd comprehensive template field-selection keyword
This command configures the method for selecting the fields to be included in the exported cflowd template.
legacy
legacy, dynamic
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the direct-export context
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the collector list instance
configure application-assurance group number cflowd direct-export collector number
16
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Cflowd direct export collector ID
configure application-assurance group number cflowd direct-export collector number
1 to 65535
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the address list instance
configure application-assurance group number cflowd direct-export collector number address (ipv4-address-no-zone | ipv6-address-no-zone) port number
Commands in this context configure the cflowd direct export collector IP address.
In the current release, the system supports IPv4 addresses only for the cflowd direct export collector.
2
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP address of the remote cflowd collector host
configure application-assurance group number cflowd direct-export collector number address (ipv4-address-no-zone | ipv6-address-no-zone) port number
This command configures the IP address of the remote cflowd collector host.
In the current release, the system supports IPv4 addresses only for the cflowd collector host.
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Cflowd collector host port number
configure application-assurance group number cflowd direct-export collector number address (ipv4-address-no-zone | ipv6-address-no-zone) port number
This command configures the UDP port number used by the remote cflowd collector host.
In the MD-CLI, the default port is 4739.
1 to 65535
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of the cflowd direct export collector
configure application-assurance group number cflowd direct-export collector number address (ipv4-address-no-zone | ipv6-address-no-zone) port number admin-state keyword
This command sets the administrative state of the cflowd direct export collector.
In the current release, the system supports IPv4 addresses only for the cflowd direct export collector.
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description of the collector
configure application-assurance group number cflowd direct-export collector number description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Cflowd direct export VLAN ID
configure application-assurance group number cflowd direct-export vlan-id number
1 to 4094
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the export-override context
Commands in this context configure the AA subtype used in the cflowd record export. The cflowd statistics exported to the cflowd collector look identical to AA for the type of system defined by the mode. The following cflowd export fields are affected:
All AA cflowd record types are affected by export override. To change the export override or prefix, cflowd must first be disabled. When this command is set back to the default, the prefix will also be set back to its default.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
AA cflowd export override mode
configure application-assurance group number cflowd export-override mode keyword
This command specifies the type of system emulated for the cflowd export.
mobile, ifname-obfuscate
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
AA group cflowd export override prefix
configure application-assurance group number cflowd export-override prefix string
This command specifies the prefix-string associated with the export override. The prefix string specifies up to an 8 character string. If the 8 character prefix is "ABCDEFG_" for a particular node, the cflowd export override would generate IPv4 interface names such as ABCDEFG_255.255.255.255 or IPv6 as ABCDEFG_2001:DB8:EF01:2345::/64. By default, the prefix is left blank.
1 to 8
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the obfuscation context
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AES-128 encryption key
configure application-assurance group number cflowd obfuscation aes-128-encryption-key string
This command specifies the AES-128 key used to encrypt export cflowd fields.
51
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AES-256 encryption key
configure application-assurance group number cflowd obfuscation aes-256-encryption-key string
This command specifies the AES-256 key used to encrypt exported cflowd fields.
71
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the rtp-performance context
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the audio-template context
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the dynamic-fields context
Commands in this context configure dynamic fields to be included in the exported cflowd template.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of the dynamic fields
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Add a list entry for field
This command adds a list entry for fields to include in the exported cflowd template.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Cflowd template dynamic field name
This command specifies the name of the field to be included in the exported cflowd template.
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Field selection method
This command configures the method for selecting the fields to be included in the exported cflowd template.
legacy
legacy, dynamic
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Cflowd flow sampling rate
configure application-assurance group number cflowd rtp-performance flow-rate number
1 to 1000
flows per second
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Cflowd per-flow second sampling rate
configure application-assurance group number cflowd rtp-performance flow-rate-2 number
1 to 1000
flows per second
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the video-template context
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the dynamic-fields context
Commands in this context configure dynamic fields to be included in the exported cflowd template.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of the dynamic fields
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Add a list entry for field
This command adds a list entry for the fields to include in the exported cflowd template.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Cflowd template dynamic field name
This command specifies the name of the field to be included in the exported cflowd template.
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Field selection method
This command configures the method for selecting the fields to be included in the exported cflowd template.
legacy
legacy, dynamic
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the voice-template context
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the dynamic-fields context
Commands in this context configure dynamic fields to be included in the exported cflowd template.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of the dynamic fields
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Add a list entry for field
This command adds a cflowd record field to the list included in the exported cflowd template.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Cflowd template dynamic field name
This command specifies the name of the field to be included in the exported cflowd template.
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Field selection method
This command configures the method for selecting the fields to be included in the exported cflowd template.
legacy
legacy, dynamic
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the tcp-performance context
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Cflowd flow sampling rate
configure application-assurance group number cflowd tcp-performance flow-rate number
1 to 1000
flows per second
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Cflowd per-flow second sampling rate
configure application-assurance group number cflowd tcp-performance flow-rate-2 number
1 to 1000
flows per second
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the template context
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the dynamic-fields context
Commands in this context configure the fields to be included in the exported cflowd template.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of the dynamic fields
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Add a list entry for field
configure application-assurance group number cflowd tcp-performance template dynamic-fields field string
This command adds a list entry for fields to include in the exported cflowd template.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Cflowd template dynamic field name
configure application-assurance group number cflowd tcp-performance template dynamic-fields field string
This command specifies the name of the field to be included in the exported cflowd template.
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Field selection method
configure application-assurance group number cflowd tcp-performance template field-selection keyword
This command configures the method for selecting the fields to be included in the exported cflowd template.
legacy
legacy, dynamic
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Template retransmit time
configure application-assurance group number cflowd template-retransmit number
10 to 600
600
seconds
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the volume context
Commands in this context configure the cflowd volume export.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Cflowd packet sampling rate
1 to 10000
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the template context
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the dynamic-fields context
Commands in this context configure the fields to be included in the exported cflowd template.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of the dynamic fields
configure application-assurance group number cflowd volume template dynamic-fields admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Add a list entry for field
configure application-assurance group number cflowd volume template dynamic-fields field string
This command adds a list entry for the fields to be included in the exported cflowd template.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Cflowd template dynamic field name
configure application-assurance group number cflowd volume template dynamic-fields field string
This command specifies the name of the field to be included in the exported cflowd template.
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Field selection method
configure application-assurance group number cflowd volume template field-selection keyword
This command configures the method for selecting the fields to be included in the exported cflowd template.
legacy
legacy, dynamic
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the dns-ip-cache list instance
configure application-assurance group number dns-ip-cache string
Commands in this context configure a DNS IP cache that is used to snoop DNS requests generated by subscribers, to populate a cache of IP addresses that match a specified list of domain names. In the context of strengthening URL-content charging, Operators may also specify a list of trusted DNS servers to populate the DNS IP cache.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
DNS IP cache name within the AA group
configure application-assurance group number dns-ip-cache string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of the AA DNS IP cache object
configure application-assurance group number dns-ip-cache string admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number dns-ip-cache string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the dns-match context
configure application-assurance group number dns-ip-cache string dns-match
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the domain list instance
configure application-assurance group number dns-ip-cache string dns-match domain string
Commands in this context configure a domain expression to populate the DNS IP cache.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
DNS IP cache domain name
configure application-assurance group number dns-ip-cache string dns-match domain string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AA DNS domain expression to match
configure application-assurance group number dns-ip-cache string dns-match domain string expression string
This command specifies a domain name expression string used to define a pattern match. The domain expression uses the same syntax as the expressions used in configure application-assurance group partition policy app-filter entry app-filters configuration.
1 to 255
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the trusted-server-address list instance
configure application-assurance group number dns-ip-cache string dns-match trusted-server-address (ipv4-address-no-zone | ipv6-address-no-zone)
Commands in this context configure a trusted DNS server address. DNS responses from this DNS server are used to populate the DNS IP cache.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Trusted DNS server address
configure application-assurance group number dns-ip-cache string dns-match trusted-server-address (ipv4-address-no-zone | ipv6-address-no-zone)
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
DNS server name
configure application-assurance group number dns-ip-cache string dns-match trusted-server-address (ipv4-address-no-zone | ipv6-address-no-zone) server-name string
1 to 32
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the ip-cache context
configure application-assurance group number dns-ip-cache string ip-cache
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
High watermark value for the DNS IP cache
configure application-assurance group number dns-ip-cache string ip-cache high-watermark number
This command configures the high watermark value for the DNS IP cache. When the number of cached IP addresses exceeds the threshold, the system generates a trap.
0 to 100
90
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Low watermark value for the DNS IP cache
configure application-assurance group number dns-ip-cache string ip-cache low-watermark number
This command configures the low watermark value for the DNS IP cache. When the number of cached IP addresses exceeds the high watermark threshold, the system generates a trap based on the high watermark. The trap clears after the number of cached IP addresses drops below the configured low watermark value.
0 to 100
80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Maximum number of IP addresses stored in the cache
configure application-assurance group number dns-ip-cache string ip-cache size number
10 to 64000
10
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Add a list entry for static-address
configure application-assurance group number dns-ip-cache string ip-cache static-address (ipv4-address-no-zone | ipv6-address-no-zone)
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Trusted IP address for the DNS IP cache
configure application-assurance group number dns-ip-cache string ip-cache static-address (ipv4-address-no-zone | ipv6-address-no-zone)
This command configures an IP address to be used as a trusted IP address. For packets whose destination IP address matches that of the trusted IP address, a cache hit is assumed.
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the http-enrich list instance
configure application-assurance group number http-enrich string
Commands in this context configure the attributes of the HTTP enrichment policy.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP header enrichment policy name
configure application-assurance group number http-enrich string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of the HTTP enrichment policy
configure application-assurance group number http-enrich string admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number http-enrich string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the field list instance
configure application-assurance group number http-enrich string field string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Field name to insert into the HTTP header
configure application-assurance group number http-enrich string field string
This command specifies the field type to insert into the HTTTP header. The command must be repeated for each field to be inserted. The same field cannot be inserted twice into the header under different header names.
Note: AA can insert two copies of the following fields in the same HTTP header (with a different header name):
imei-hyphenated, imei-hyphenated-2, imsi, imsi-2, static-string, static-string-2, user-location-raw, and user-location-raw2.
The following field types are supported in any deployment:
static-string - header name for the inserted string
static-string-2 - header name for the inserted string
subscriber-id - header name for the subscriber ID
subscriber-ip - header name for the subscriber IP address
The following field types are supported in Fixed Wireless Access (FWA) deployments only:
apn - complete APN string
apn-ni - APN Network Identifier (APN-NI) used by the UE
billing-type - UE charging type (charging characteristics)
dynamic-acr - dynamic Anonymous Customer Record (ACR)
static-acr - static ACR
imei-hyphenated - subscriber IMEI with format AABBBBBB-CCCCCC-EE
imei-hyphenated-2 - subscriber IMEI with format AABBBBBB-CCCCCC-EE
imei-sv - subscriber IMEI with format AABBBBBBCCCCCCEE
imsi - subscriber IMSI
imsi-2 - subscriber IMSI
msisdn - subscriber MSISDN
msisdn-without-cc - subscriber MSISDN without a country code
pgw-ggsn-address - PGW/GGSN address serving the UE
plmn-id - Public Land Mobile Network (PLMN) ID of the SGSN/MME
rat-type - Radio Access Technology (RAT) type
timestamp - timestamp inserted in UNIX time format; for example, 1531204313
user-location - UE LOCATION (ULI)
user-location-3gpp - ULI encoded as defined in 3GPP 29.061
user-location-raw - ULI in raw format:<ULI-TYPE1>[+<ULI-TYPE2>]=<ULI HEX>
Example: x-locinfo: TAI+ECGI=1300622c46130062014adf16
user-location-raw-2 - ULI in raw format:<ULI-TYPE1>[+<ULI-TYPE2>]=<ULI HEX>
Example: x-locinfo: TAI+ECGI=1300622c46130062014adf16
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable anti-spoofing
configure application-assurance group number http-enrich string field string anti-spoof boolean
When configured to true, this command enables the HTTP header enrichment anti-spoofing functionality.
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable calling line identification
configure application-assurance group number http-enrich string field string calling-line-id boolean
When configured to true, this command configures the HTTP header for “x-up-calling-line-id” anti-spoofing.
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the encode context
configure application-assurance group number http-enrich string field string encode
Commands in this context configure the encoding applied to the HTTP header enrichment field.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Certificate profile name used for encryption
configure application-assurance group number http-enrich string field string encode cert-profile reference
configure application-assurance group number certificate-profile string
The following elements are part of a choice: cert-profile or key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the key context
configure application-assurance group number http-enrich string field string encode key
Commands in this context configure the encryption fields.
The following elements are part of a choice: cert-profile or key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Encoding type
configure application-assurance group number http-enrich string field string encode key type keyword
This command configures the encoding/ encryption method.
md5, rc4, rc4-md5-base64
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Secret key for encrypting the field
configure application-assurance group number http-enrich string field string encode key value string
1 to 114
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
HTTP header field name
configure application-assurance group number http-enrich string field string name string
1 to 32
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP header enrichment template field static string
configure application-assurance group number http-enrich string field string static-string string
1 to 16
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the rat-type-enrichment context
configure application-assurance group number http-enrich string rat-type-enrichment
Commands in this context configure Radio Access Type (RAT) enrichment.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the rat-type list instance
configure application-assurance group number http-enrich string rat-type-enrichment rat-type keyword
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
RAT type name
configure application-assurance group number http-enrich string rat-type-enrichment rat-type keyword
This command configures a customised RAT value for the specified RAT-Type.
utran, geran, wlan, gan, hspa-evol, eutran, virtual, eutran-nb, ehrpd, hrpd, cdma-1x, umb, wifi, nr, lte-m
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Customised RAT type value
configure application-assurance group number http-enrich string rat-type-enrichment rat-type keyword rat-string string
1 to 31
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the http-error-redirect list instance
configure application-assurance group number http-error-redirect string
Commands in this context configure an HTTP error redirect policy that contains important information relevant to the redirect server.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP error redirect policy name
configure application-assurance group number http-error-redirect string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of the HTTP error redirect object
configure application-assurance group number http-error-redirect string admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number http-error-redirect string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the error-code list instance
configure application-assurance group number http-error-redirect string error-code number
Commands in this context configure the HTTP error status codes to which a redirect action is applied. Only messages with sizes less than that configured for the custom-message-size command are eligible for redirect action.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP error code value for an HTTP error redirect
configure application-assurance group number http-error-redirect string error-code number
0 to 4294967295
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP error redirect error code custom message size
configure application-assurance group number http-error-redirect string error-code number custom-message-size number
This command specifies the maximum message size above which an HTTP error redirect is not performed.
0 to 4294967295
1024
octets
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP host for the HTTP error redirect object
configure application-assurance group number http-error-redirect string http-host string
This command specifies the HTTP hostname of the landing server (Barefruit or Xerocole). It is used in the HTTP GET operation from the client (which is being redirected) to the redirect search landing server. The hostname must contain a valid IP address or HTTP hostname or URI for the HTTP GET from the client to the landing server.
1 to 255
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Participant ID for the HTTP error redirect object
configure application-assurance group number http-error-redirect string participant-id string
This command specifies a string assigned to the operator by Barefruit. It is used by Barefruit landing servers (applies to template # 1 only).
1 to 32
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Template ID for the HTTP error redirect object
configure application-assurance group number http-error-redirect string template number
This command configures the template of parameters passed from the AA-ISA to the redirect server using JavaScript in the redirect packet. The template is specific to the redirect server used in the network. Currently, two partners are supported with AA-ISA redirect solution, Barefruit, and Xerocole.
0 to 4294967295
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the http-notification list instance
configure application-assurance group number http-notification string
Commands in this context configure an HTTP notification object for the subscriber in-browser notification.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP notification policy name
configure application-assurance group number http-notification string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of the AA HTTP notification object
configure application-assurance group number http-notification string admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number http-notification string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Minimum HTTP response notification interval
configure application-assurance group number http-notification string interval (number | keyword)
1 to 1440
one-time
minutes
one-time
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Script URL inserted into the HTTP response
configure application-assurance group number http-notification string script-url string
This command configures the URL of the script used by the HTTP notification policy.
1 to 255
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Template ID for the AA HTTP notification object
configure application-assurance group number http-notification string template number
This command configures the template that defines the format and attributes included in the HTTP notification message.
0 to 4294967295
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the http-redirect list instance
configure application-assurance group number http-redirect string
Commands in this context configure the parameters of the HTTP redirect policy.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP redirect policy name
configure application-assurance group number http-redirect string
This command specifies the applied HTTP redirect name. If no redirect name is specified, HTTP redirect is not enabled.
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of the AA HTTP redirect object
configure application-assurance group number http-redirect string admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the captive-redirect context
configure application-assurance group number http-redirect string captive-redirect
Commands in this context configure the captive redirect capability for an HTTP redirect policy. HTTP redirect policies using captive redirect can be used in conjunction with a session-filter policy to terminate TCP flows in the ISA-AA card before reaching the Internet to redirect subscribers to the predefined redirect URL.
Non-HTTP TCP flows are TCP reset. Captive redirect uses the provisioned VLAN ID to send the HTTP response to subscribers; therefore, this VLAN ID must be properly assigned in the same VPN as the subscriber.
The operator can select the URL arguments to include in the redirect URL using either a specific template ID or by configuring the redirect URL using a supported macro substitution keyword.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Captive redirect VLAN ID
configure application-assurance group number http-redirect string captive-redirect vlan-id number
This command configures the VLAN ID for a captive redirect. Captive redirect uses the provisioned VLAN ID to send the HTTP response to subscribers; therefore, this VLAN ID must be properly assigned in the same VPN as the subscriber.
1 to 4094
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number http-redirect string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable HTTPS redirect
configure application-assurance group number http-redirect string redirect-https boolean
When set to true, the HTTP redirect policy redirects HTTPS sessions to the configured redirect URL.
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP redirect URL
configure application-assurance group number http-redirect string redirect-url string
This command configures the HTTP redirect URL which is the URL (page) that the user is redirected to when an HTTP redirect takes effect.
The operator can select the URL arguments to include in the redirect URL, using either a specific template ID or by configuring any of the following macro substitution keywords:
Only ESM and ESM-MAC sub types support $MAC, $SAP, $CID, and $RID macro substitution.
1 to 255
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable TCP client reset
configure application-assurance group number http-redirect string tcp-client-reset boolean
When set to true, this command enables an HTTP-redirect policy to initiate a TCP reset towards the client if the AA policy results in a redirect with packet drop but the HTTP redirect cannot be delivered. Scenarios for this include HTTP (TLS) sessions, blocking of non-HTTP TCP traffic, and blocking of existing flows after a policy re-evaluation of an existing subscriber.
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Template ID for the HTTP redirect object
configure application-assurance group number http-redirect string template number
This command configures the template that defines which parameters are appended to the HTTP host redirect field in the redirect message. The HTTP redirect template provides HTTP 302 redirect containing only the URL specified in the redirect policy, with no other parameters.
0 to 4294967295
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the partition list instance
configure application-assurance group number partition number
Commands in this context configure the AA partition-related policies.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Partition ID within the AA group
configure application-assurance group number partition number
0 to 65535
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the aa-sub-congestion-detection context
configure application-assurance group number partition number aa-sub-congestion-detection
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of congestion detection
configure application-assurance group number partition number aa-sub-congestion-detection admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the rat-type list instance
configure application-assurance group number partition number aa-sub-congestion-detection rat-type keyword
Commands in this context configure the RAT types for which unique RTT thresholds are configured.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Mobile radio access technology (RAT) type
configure application-assurance group number partition number aa-sub-congestion-detection rat-type keyword
utran, geran, wlan, gan, hspa-evol, eutran, virtual, eutran-nb, ehrpd, hrpd, cdma-1x, umb, wifi, nr, lte-m
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Round trip time congestion threshold for a RAT type
configure application-assurance group number partition number aa-sub-congestion-detection rat-type keyword rtt-threshold (number | keyword)
This command configures the maximum acceptable round trip time (RTT) under no congestion. Any measured RTT above the threshold is considered an indication of possible congestion.
1 to 500
milliseconds
not-applicable
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Round trip time congestion threshold
configure application-assurance group number partition number aa-sub-congestion-detection rtt-threshold (number | keyword)
This command configures the default round trip delay threshold used by the DEM gateway algorithm to determine subscriber congestion for NLB-DEM. This default value is used when the current RAT-Type is not known, or has no associated configured RTT threshold.
1 to 500
173
milliseconds
not-applicable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
RTT threshold tolerance for congestion detection
configure application-assurance group number partition number aa-sub-congestion-detection rtt-threshold-tolerance number
This command configures the round trip delay threshold tolerance used by the DEM gateway algorithm to determine subscriber-level congestion.
0 to 100
50
percent
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Reverse subscriber traffic direction
configure application-assurance group number partition number aa-sub-remote boolean
When configured to true, the direction of the from-subscriber and to-subscriber traffic is reversed for this group partition.
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the access-network-location context
configure application-assurance group number partition number access-network-location
Commands in this context configure parameters related to dynamic experience management, also known as Access Network Location (ANL).
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the source list instance
configure application-assurance group number partition number access-network-location source keyword
Commands in this context configure location sources for dynamic experience management.
1
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Access network location source
configure application-assurance group number partition number access-network-location source keyword
This command specifies the location or access technology. AA supports access points for WLGW access points or ULI-2gpp for mobile (for example, FWA).
mobile-3g, access-point, uli-3gpp
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the rat-type list instance
configure application-assurance group number partition number access-network-location source keyword rat-type keyword
Commands in this context configure the RAT types for which unique RTT thresholds are configured.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Access network location RAT type
configure application-assurance group number partition number access-network-location source keyword rat-type keyword
utran, geran, wlan, gan, hspa-evol, eutran, virtual, eutran-nb, ehrpd, hrpd, cdma-1x, umb, wifi, nr, lte-m
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
RTT congestion threshold for a RAT type
configure application-assurance group number partition number access-network-location source keyword rat-type keyword rtt-threshold (number | keyword)
This command specifies the maximum acceptable round trip time (RTT) under no congestion. Any measured RTT above the threshold is considered an indication of possible congestion.
1 to 500
milliseconds
not-applicable
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Source round trip time congestion threshold
configure application-assurance group number partition number access-network-location source keyword rtt-threshold (number | keyword)
This command configures the default round trip delay threshold used by the DEM gateway algorithm to determine ANL congestion. This default value is used when either the ANL RAT-Type is not known or has no associated configured RTT threshold.
1 to 500
173
milliseconds
not-applicable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Source round trip time congestion threshold tolerance
configure application-assurance group number partition number access-network-location source keyword rtt-threshold-tolerance number
This command configures the ANL round trip delay threshold tolerance used by the DEM gateway algorithm to determine ANL-level congestion.
0 to 100
50
percent
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Access network location source level
configure application-assurance group number partition number access-network-location source keyword source-level keyword
cell
cell, transport-network-link, mac-vlan
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable AQP initial lookup
configure application-assurance group number partition number aqp-initial-lookup boolean
When configured to true, this command allows AA to perform application QoS policy (AQP) lookups on flows prior to complete application identification. As usual, AQP will be looked up again when identification is complete. Without this, AA executes AQPs that are part of the sub-default policy. The sub-default policy is formed by regular AQPs that contain ASOs, subID, or flow direction as matching conditions.
This behavior is required, for example, to apply GTP and SCTP filtering on the first packet of a new GTP/SCTP flow (AQP matching conditions).
When configured to false, AA only performs AQP lookups when identification is complete.
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the cflowd context
configure application-assurance group number partition number cflowd
Commands in this context configure the AA partition-based cflowd fields.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the export-type list instance
configure application-assurance group number partition number cflowd export-type keyword
Commands in this context configure the scope of traffic subjected to AA cflowd export.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Cflowd flow export type for the partition
configure application-assurance group number partition number cflowd export-type keyword
This command allows the operator to configure the scope of traffic that can be sampled for cflowd export for the configured cflowd template.
volume, tcp-performance, rtp-performance, comprehensive
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of cflowd export
configure application-assurance group number partition number cflowd export-type keyword admin-state keyword
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the app-group list instance
configure application-assurance group number partition number cflowd export-type keyword app-group reference
Commands in this context configure application groups for flow sampling and cflowd export.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Application group name
configure application-assurance group number partition number cflowd export-type keyword app-group reference
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Cflowd rate to use for sampling
configure application-assurance group number partition number cflowd export-type keyword app-group reference rate-choice keyword
flow-rate
flow-rate, flow-rate-2
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the application list instance
configure application-assurance group number partition number cflowd export-type keyword application reference
Commands in this context configure applications for flow sampling and cflowd export.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Application name
configure application-assurance group number partition number cflowd export-type keyword application reference
configure application-assurance group number partition number policy application string
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Cflowd rate to use for sampling
configure application-assurance group number partition number cflowd export-type keyword application reference rate-choice keyword
flow-rate
flow-rate, flow-rate-2
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number partition number description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the event-log list instance
configure application-assurance group number partition number event-log string
Commands in this context configure an event log.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Partition event log name
configure application-assurance group number partition number event-log string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of the event log
configure application-assurance group number partition number event-log string admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
Event log buffer type
configure application-assurance group number partition number event-log string buffer-type keyword
linear
linear, circular, syslog
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
Maximum number of entries for the event log
configure application-assurance group number partition number event-log string max-entries number
1 to 100000
500
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
Enter the syslog context
Commands in this context configure the syslog options for the partition.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
Syslog host IP address
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number partition number event-log string syslog description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
AA syslog facility
This command configures the syslog facility. The syslog facility is an information field associated with a syslog message. It is defined by the syslog protocol and provides an indication of which part of the system originated the message.
local7
kernel, user, mail, systemd, auth, syslogd, printer, netnews, uucp, cron, authpriv, ftp, ntp, logaudit, logalert, cron2, local0, local1, local2, local3, local4, local5, local6, local7
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
Syslog host UDP port
This command specifies the UDP port used by application assurance for the syslog events.
0 to 65535
514
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
Syslog message severity level threshold
info
emergency, alert, critical, error, warning, notice, info, debug
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
ISA service port VLAN ID for sending syslog traffic
This command configures the service port VLAN ID to be used by application assurance to provide syslog events. This VLAN ID also needs to be configured for the application assurance interface.
1 to 4094
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the gtp context
configure application-assurance group number partition number gtp
Commands in this context configure GTP parameters.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of GTP
configure application-assurance group number partition number gtp admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the gtp-filter list instance
configure application-assurance group number partition number gtp gtp-filter string
Commands in this context allow AA to treat traffic on UDP port number 2152 as GTP-U. Without further specifying any other parameters within this GTP context, AA performs basic GTP-U header sanity checks and discards packets that are malformed. This GTP context also allows the operator to configure various GTP filters.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
GTP filter name
configure application-assurance group number partition number gtp gtp-filter string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number partition number gtp gtp-filter string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
GTP in GTP packet filtering
configure application-assurance group number partition number gtp gtp-filter string gtp-in-gtp keyword
permit
deny, permit
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the gtp-tunnel-database context
configure application-assurance group number partition number gtp gtp-filter string gtp-tunnel-database
Commands in this context configure GTP advanced firewall functions, such as validating GTP tunnels, sequence numbers, and source IP addresses).
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Default GTP tunnel endpoint limit
configure application-assurance group number partition number gtp gtp-filter string gtp-tunnel-database default-tunnel-endpoint-limit number
This command configures the maximum number of GTP endpoints requested in GTP-C messages by using, for example, the PDP Context Create message type.
The validate-gtp-tunnels command must be enabled before using this command.
1 to 4294967295
4294967295
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable GTP tunnel validation
configure application-assurance group number partition number gtp gtp-filter string gtp-tunnel-database validate-gtp-tunnels boolean
When configured to true, this command configures GTP tunnel validation. This allows for the validation of TEIDs and is a prerequisite for sequence checking and UE IP address validation. This command is only applicable when AA GTP FW is deployed on S8/S5/Gp/Gn interfaces. The gtpc-inspection command in the configure application-assurance group partition gtp context must be configured to true before using this command.
When configured to false, the GTP tunnels cannot be validated.
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable GTP sequence number checking
configure application-assurance group number partition number gtp gtp-filter string gtp-tunnel-database validate-sequence-number boolean
When configured to true, this command enables GTP sequence number checking. GTP packets that fail the sequence number check are discarded.
The validate-gtp-tunnels command in the configure application-assurance group partition gtp gtp-filter gtp-tunnel-database context must be configured to true before using this command.
When configured to false, the GTP packet sequence number cannot be checked.
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Validate source IP address in GTP frames
configure application-assurance group number partition number gtp gtp-filter string gtp-tunnel-database validate-source-ip-addr boolean
When configured to true, this command enables checking for spoofed or invalid UE IP addresses. Upstream GTP packets that contain invalid UE IP addresses are discarded. When a packet is dropped due to source-ip-address “invalid source IP add”, the statistics counter is updated.
The validate-gtp-tunnels command in the configure application-assurance group partition gtp gtp-filter gtp-tunnel-database context must be configured to true before using this command.
When configured to false, the spoofed or invalid UE IP addresses cannot be checked.
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the imsi-apn-filter context
configure application-assurance group number partition number gtp gtp-filter string imsi-apn-filter
Commands in this context configure IMSI and APN filtering.
The gtpc-inspection command in the configure application-assurance group partition gtp context must be configured to true before using this command.
This command is only applicable to the GTP packets that contain IMSI or APN information elements (IEs).
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IMSI APN filter default action
configure application-assurance group number partition number gtp gtp-filter string imsi-apn-filter default-action keyword
permit
deny, permit
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the entry list instance
configure application-assurance group number partition number gtp gtp-filter string imsi-apn-filter entry number
Commands in this context configure an entry within the IMSI-APN filter to allow for IMSI-APN match and action configuration.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AA IMSI-APN filter entry ID
configure application-assurance group number partition number gtp gtp-filter string imsi-apn-filter entry number
This command specifies the index in the IMSI-APN list that defines a custom filtering action.
1031 to 2030
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IMSI APN filter entry action
configure application-assurance group number partition number gtp gtp-filter string imsi-apn-filter entry number action keyword
permit
deny, permit
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
APN as GTP filter match criterion
configure application-assurance group number partition number gtp gtp-filter string imsi-apn-filter entry number apn string
This command configures a matching condition for an APN configured as a GTP filter. If no APN is specified, the entry is not checked for the APN IE in GTP-C packets. The values for this command are:
1 to 100
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IMSI (MCC-MNC) prefix as GTP filter match criterion
configure application-assurance group number partition number gtp gtp-filter string imsi-apn-filter entry number imsi-mcc-mnc-prefix string
This command configures a matching condition for the IMSI (MCC-MNC) prefix. This string represents the IMSI prefix to be matched against the IMSI IE of the packet, or the special value ANY_IMSI to indicate that an IMSI IE must be present as a matching condition regardless of the IMSI IE value. If no MCC-MNC prefix is specified, the entry will match GTP packets that have an IMSI IE containing any value.
1 to 8
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the src-gsn context
configure application-assurance group number partition number gtp gtp-filter string imsi-apn-filter entry number src-gsn
Commands in this context configure a matching condition for the GSN IP address. The IP address value is checked only against the source IP address of the GTP packets that contain an APN IE or an IMSI IE.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Source GSN IP address prefix as GTP filter match criterion
configure application-assurance group number partition number gtp gtp-filter string imsi-apn-filter entry number src-gsn ip-prefix (ipv4-prefix | ipv6-prefix)
This command specifies a valid unicast address associated with the IMSI-APN filter entry.
The following elements are part of a choice: ip-prefix or ip-prefix-list.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Source GSN IP address prefix list as match criterion
configure application-assurance group number partition number gtp gtp-filter string imsi-apn-filter entry number src-gsn ip-prefix-list reference
configure application-assurance group number partition number ip-prefix-list string
The following elements are part of a choice: ip-prefix or ip-prefix-list.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the log context
configure application-assurance group number partition number gtp gtp-filter string log
Commands in this context configure the AA group partition GTP filter log.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
GTP filter action to be logged
configure application-assurance group number partition number gtp gtp-filter string log action keyword
deny
deny, permit, all
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Event-log name to capture GTP filter events
configure application-assurance group number partition number gtp gtp-filter string log event-log reference
configure application-assurance group number partition number event-log string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Maximum allowed GTP payload length
configure application-assurance group number partition number gtp gtp-filter string max-payload-length number
0 to 65535
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the message-type context
configure application-assurance group number partition number gtp gtp-filter string message-type
Commands in this context configure the GTP message-type filtering. If no message type is specified within a filter, all GTP message types are allowed.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
GTP message type default action
configure application-assurance group number partition number gtp gtp-filter string message-type default-action keyword
permit
deny, permit
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the entry list instance
configure application-assurance group number partition number gtp gtp-filter string message-type entry number
Commands in this context configure an entry for a specific GTPv1 message type value.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
GTP filter entry ID
configure application-assurance group number partition number gtp gtp-filter string message-type entry number
This command specifies the index in the GTPv1 message value list that defines a custom message-type action.
1 to 255
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
GTPv1 filter message entry action
configure application-assurance group number partition number gtp gtp-filter string message-type entry number action keyword
deny, permit
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
GTPv1 filter message type value
configure application-assurance group number partition number gtp gtp-filter string message-type entry number value (number | keyword)
1 to 255
echo-request, echo-response, version-not-supported, node-alive-request, node-alive-response, redirection-request, redirection-response, create-pdp-context-request, create-pdp-context-response, update-pdp-context-request, update-pdp-context-response, delete-pdp-context-request, delete-pdp-context-response, initiate-pdp-context-activation-request, initiate-pdp-context-activation-response, error-indication, pdu-notification-request, pdu-notification-response, pdu-notification-reject-request, pdu-notification-reject-response, supported-extension-headers-notification, send-routing-information-for-gprs-request, send-routing-information-for-gprs-response, failure-report-request, failure-report-response, note-ms-gprs-present-request, note-ms-gprs-present-response, identification-request, identification-response, sgsn-context-request, sgsn-context-response, sgsn-context-acknowledge, forward-relocation-request, forward-relocation-response, forward-relocation-complete, relocation-cancel-request, relocation-cancel-response, forward-srns-context, forward-relocation-complete-acknowledge, forward-srns-context-acknowledge, ran-information-relay, mbms-notification-request, mbms-notification-response, mbms-notification-reject-request, mbms-notification-reject-response, create-mbms-context-request, create-mbms-context-response, update-mbms-context-request, update-mbms-context-response, delete-mbms-context-request, delete-mbms-context-response, mbms-registration-request, mbms-registration-response, mbms-de-registration-request, mbms-de-registration-response, mbms-session-start-request, mbms-session-start-response, mbms-session-stop-request, mbms-session-stop-response, mbms-session-update-request, mbms-session-update-response, ms-info-change-notification-request, ms-info-change-notification-response, data-record-transfer-request, data-record-transfer-response, end-marker, g-pdu
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the message-type-gtp-v2 context
configure application-assurance group number partition number gtp gtp-filter string message-type-gtp-v2
Commands in this context configure the GTPv2 message-type filtering.
If message-type GTPv2 is not specified within a filter, all GTP message types are allowed, except for the messages that are dropped by GTP-C inspection because they violate the expected GTP protocol for the deployment interface (for example, roaming deployment).
The gtpc-inspection command in the configure application-assurance group partition gtp context must be configured to true before configuring GTPv2 message-type filtering.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
GTPv2 message type default action
configure application-assurance group number partition number gtp gtp-filter string message-type-gtp-v2 default-action keyword
permit
deny, permit
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the entry list instance
configure application-assurance group number partition number gtp gtp-filter string message-type-gtp-v2 entry number
Commands in this context configure an entry for a specific GTPv2 message type value.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
GTPv2 filter entry ID
configure application-assurance group number partition number gtp gtp-filter string message-type-gtp-v2 entry number
This command configures the index in the GTP message value list that defines a custom message-type action.
516 to 770
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
GTPv2 filter message entry action
configure application-assurance group number partition number gtp gtp-filter string message-type-gtp-v2 entry number action keyword
This command specifies the action to take for packets that match this GTPv2 filter message entry.
deny, permit
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
GTPv2 filter message type value
configure application-assurance group number partition number gtp gtp-filter string message-type-gtp-v2 entry number value (number | keyword)
1 to 255
echo-request, echo-response, version-not-supported-indication, create-session-request, create-session-response, modify-bearer-request, modify-bearer-response, delete-session-request, delete-session-response, change-notification-request, change-notification-response, remote-ue-report-notification, remote-ue-report-acknowledge, modify-bearer-command, modify-bearer-failure-indication, delete-bearer-command, delete-bearer-failure-indication, bearer-resource-command, bearer-resource-failure-indication, downlink-data-notification-failure-indication, trace-session-activation, trace-session-deactivation, stop-paging-indication, create-bearer-request, create-bearer-response, update-bearer-request, update-bearer-response, delete-bearer-request, delete-bearer-response, delete-pdn-connection-set-request, delete-pdn-connection-set-response, pgw-downlink-triggering-notification, pgw-downlink-triggering-acknowledge, identification-request, identification-response, context-request, context-response, context-acknowledge, forward-relocation-request, forward-relocation-response, forward-relocation-complete-notification, forward-relocation-complete-acknowledge, forward-access-context-notification, forward-access-context-acknowledge, relocation-cancel-request, relocation-cancel-response, configuration-transfer-tunnel, detach-notification, detach-acknowledge, cs-paging-indication, ran-information-relay, alert-mme-notification, alert-mme-acknowledge, ue-activity-notification, ue-activity-acknowledge, isr-status-indication, create-forwarding-tunnel-request, create-forwarding-tunnel-response, suspend-notification, suspend-acknowledge, resume-notification, resume-acknowledge, create-indirect-data-forwarding-tunnel-request, create-indirect-data-forwarding-tunnel-response, delete-indirect-data-forwarding-tunnel-request, delete-indirect-data-forwarding-tunnel-response, release-access-bearers-request, release-access-bearers-response, downlink-data-notification, downlink-data-notification-acknowledge, pgw-restart-notification, pgw-restart-notification-acknowledge, update-pdn-connection-set-request, update-pdn-connection-set-response, modify-access-bearers-request, modify-access-bearers-response, mbms-session-start-request, mbms-session-start-response, mbms-session-update-request, mbms-session-update-response, mbms-session-stop-request, mbms-session-stop-response
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable inspection of GTP-C packets
configure application-assurance group number partition number gtp gtpc-inspection boolean
When configured to true, this command enables the inspection of GTP-C packets. This is relevant only when AA GTP FW is deployed on S8/S5/Gp/Gn interfaces. This command must be enabled before configuring related features, such as APN filtering, GTP tunnel validation, message-type-v2 filtering, sequence number validation, and SRC IP validation.
When configured to false, GTP-C packet inspection cannot be performed.
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the log context
Commands in this context configure the AA group partition GTP log.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
GTP log action
This command specifies the action on which the GTP log is raised.
deny
deny, permit, all
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Event log reference for logging GTP events
configure application-assurance group number partition number event-log string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
GTP mode
filtering
filtering, untunneling
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable HTTP matching for all requests for an expression
configure application-assurance group number partition number http-match-all-requests boolean
When configured to true, this command enables HTTP matching for all requests for an HTTP expression.
When configured to false, this command restores the default and removes the matching request for this particular expression.
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable X-Online-Host header field
configure application-assurance group number partition number http-x-online-host boolean
When configured to true, this command enables the X-Online-Host header field as a replacement for the HTTP Host header field.
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the ip-prefix-list list instance
configure application-assurance group number partition number ip-prefix-list string
Commands in this context configure an IP prefix list.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AA IP prefix list name
configure application-assurance group number partition number ip-prefix-list string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number partition number ip-prefix-list string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the prefix list instance
configure application-assurance group number partition number ip-prefix-list string prefix (ipv4-prefix | ipv6-prefix)
Commands in this context configure an IP prefix within the list.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AA IP prefix
configure application-assurance group number partition number ip-prefix-list string prefix (ipv4-prefix | ipv6-prefix)
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AA IP prefix name
configure application-assurance group number partition number ip-prefix-list string prefix (ipv4-prefix | ipv6-prefix) name string
1 to 32
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the policy context
configure application-assurance group number partition number policy
Commands in this context configure the fields for the Application Assurance policy.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the app-filter context
configure application-assurance group number partition number policy app-filter
Commands in this context configure an application filter for Application Assurance.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the entry list instance
configure application-assurance group number partition number policy app-filter entry number
Commands in this context create an application filter entry.
Application filter entries are an ordered list. The lowest numerical entry that matches the flow defines the application for that flow.
An application filter entry or entries configure match attributes of an application.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Application filter entry ID
configure application-assurance group number partition number policy app-filter entry number
1 to 65535
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of the AA application filter entry
configure application-assurance group number partition number policy app-filter entry number admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Application name
configure application-assurance group number partition number policy app-filter entry number application reference
configure application-assurance group number partition number policy application string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number partition number policy app-filter entry number description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the expression list instance
configure application-assurance group number partition number policy app-filter entry number expression number
Commands in this context configure string values to use in the application definition.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Application filter matching expression identifier
configure application-assurance group number partition number policy app-filter entry number expression number
1 to 4
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Exact match for application filter matching expression
configure application-assurance group number partition number policy app-filter entry number expression number eq string
1 to 255
The following elements are part of a mandatory choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Non-match for application filter matching expression
configure application-assurance group number partition number policy app-filter entry number expression number neq string
1 to 255
The following elements are part of a mandatory choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Application filter matching expression type
configure application-assurance group number partition number policy app-filter entry number expression number type keyword
http-host, http-uri, http-referer, sip-ua, sip-uri, sip-mt, citrix-app, http-user-agent, h323-product-id, tls-cert-subj-org-name, tls-cert-subj-common-name, rtsp-host, rtsp-uri, rtsp-ua, rtmp-page-host, rtmp-page-uri, rtmp-swf-host, rtmp-swf-uri, rtmp-tc-host, rtmp-tc-uri, dns-domain-name
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Traffic flow direction for the application filter entry
configure application-assurance group number partition number policy app-filter entry number flow-setup-direction keyword
both
subscriber-to-network, network-to-subscriber, both
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable HTTP matching for all requests
configure application-assurance group number partition number policy app-filter entry number http-match-all-requests boolean
When configured to true, this command enables HTTP matching for all requests for an HTTP expression.
When configured to false, this command restores the default for this app-filter entry which matches the first request.
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the http-port context
configure application-assurance group number partition number policy app-filter entry number http-port
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the eq context
configure application-assurance group number partition number policy app-filter entry number http-port eq
Commands in this context configure the exact value as the match criterion.
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Port list name
configure application-assurance group number partition number policy app-filter entry number http-port eq port-list reference
configure application-assurance group number partition number port-list string
The following elements are part of a choice: port-list or port-number.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Server port number
configure application-assurance group number partition number policy app-filter entry number http-port eq port-number number
0 | 1 to 65535
0
The following elements are part of a choice: port-list or port-number.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the neq context
configure application-assurance group number partition number policy app-filter entry number http-port neq
Commands in this context configure the non-match criterion used.
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Port list name
configure application-assurance group number partition number policy app-filter entry number http-port neq port-list reference
configure application-assurance group number partition number port-list string
The following elements are part of a choice: port-list or port-number.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Server port number
configure application-assurance group number partition number policy app-filter entry number http-port neq port-number number
0 | 1 to 65535
0
The following elements are part of a choice: port-list or port-number.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the ip-protocol context
configure application-assurance group number partition number policy app-filter entry number ip-protocol
Commands in this context configure the IP protocol to use in the application definition.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Exact match criterion used for the IP protocol number
configure application-assurance group number partition number policy app-filter entry number ip-protocol eq (number | keyword)
0 to 255
tcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Non-match criterion used for the IP protocol number
configure application-assurance group number partition number policy app-filter entry number ip-protocol neq (number | keyword)
0 to 255
tcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the network-address context
configure application-assurance group number partition number policy app-filter entry number network-address
Commands in this context configure the network address to use for the application filter entry. The network address is the address on the network side of AA, independent of whether the subscriber is acting as a client or server and is not normally used in AA app-filters. The network address will match the destination IP address in a from-sub flow or the source IP address in a to-sub flow.
The following elements are part of a choice: network-address or server-address.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the eq context
configure application-assurance group number partition number policy app-filter entry number network-address eq
Commands in this context specify an exact value as the match criterion for the network address.
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP prefix
configure application-assurance group number partition number policy app-filter entry number network-address eq ip-prefix (ipv4-prefix | ipv6-prefix)
The following elements are part of a choice: ip-prefix or ip-prefix-list.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP prefix list
configure application-assurance group number partition number policy app-filter entry number network-address eq ip-prefix-list reference
configure application-assurance group number partition number ip-prefix-list string
The following elements are part of a choice: ip-prefix or ip-prefix-list.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the neq context
configure application-assurance group number partition number policy app-filter entry number network-address neq
Commands in this context specify the non-match criterion used for the network address.
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP prefix
configure application-assurance group number partition number policy app-filter entry number network-address neq ip-prefix (ipv4-prefix | ipv6-prefix)
The following elements are part of a choice: ip-prefix or ip-prefix-list.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP prefix list
configure application-assurance group number partition number policy app-filter entry number network-address neq ip-prefix-list reference
configure application-assurance group number partition number ip-prefix-list string
The following elements are part of a choice: ip-prefix or ip-prefix-list.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the protocol context
configure application-assurance group number partition number policy app-filter entry number protocol
Commands in this context configure the protocol signature in the application definition.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Exact match criterion used for the AA protocol name
configure application-assurance group number partition number policy app-filter entry number protocol eq (string | named-item)
1 to 32
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Non-match criterion used for the AA protocol name
configure application-assurance group number partition number policy app-filter entry number protocol neq (string | named-item)
1 to 32
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the server-address context
configure application-assurance group number partition number policy app-filter entry number server-address
Commands in this context configure the server address to use for the application filter entry. The server address is the address on the server end of a client-server session.
The following elements are part of a choice: network-address or server-address.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the eq context
configure application-assurance group number partition number policy app-filter entry number server-address eq
Commands in this context configure the attributes of the IP address used for the exact match criterion for the application flow.
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
DNS IP cache name
configure application-assurance group number partition number policy app-filter entry number server-address eq dns-ip-cache reference
configure application-assurance group number dns-ip-cache string
The following elements are part of a choice: dns-ip-cache, ip-prefix, ip-prefix-list, or masked-ip.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP prefix
configure application-assurance group number partition number policy app-filter entry number server-address eq ip-prefix (ipv4-prefix | ipv6-prefix)
The following elements are part of a choice: dns-ip-cache, ip-prefix, ip-prefix-list, or masked-ip.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP prefix list
configure application-assurance group number partition number policy app-filter entry number server-address eq ip-prefix-list reference
configure application-assurance group number partition number ip-prefix-list string
The following elements are part of a choice: dns-ip-cache, ip-prefix, ip-prefix-list, or masked-ip.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the masked-ip context
configure application-assurance group number partition number policy app-filter entry number server-address eq masked-ip
Commands in this context configure the attributes of a masked IP address.
The following elements are part of a choice: dns-ip-cache, ip-prefix, ip-prefix-list, or masked-ip.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IPv4 or IPv6 address mask
configure application-assurance group number partition number policy app-filter entry number server-address eq masked-ip address (ipv4-address-no-zone | ipv6-address-no-zone)
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IPv4 or IPv6 address mask
configure application-assurance group number partition number policy app-filter entry number server-address eq masked-ip netmask (ipv4-address-no-zone | ipv6-address-no-zone)
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the neq context
configure application-assurance group number partition number policy app-filter entry number server-address neq
Commands in this context configure the attributes of the IP address used for non-matching criteria in the application flow.
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
DNS IP cache name
configure application-assurance group number partition number policy app-filter entry number server-address neq dns-ip-cache reference
configure application-assurance group number dns-ip-cache string
The following elements are part of a choice: dns-ip-cache, ip-prefix, ip-prefix-list, or masked-ip.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP prefix
configure application-assurance group number partition number policy app-filter entry number server-address neq ip-prefix (ipv4-prefix | ipv6-prefix)
The following elements are part of a choice: dns-ip-cache, ip-prefix, ip-prefix-list, or masked-ip.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP prefix list
configure application-assurance group number partition number policy app-filter entry number server-address neq ip-prefix-list reference
configure application-assurance group number partition number ip-prefix-list string
The following elements are part of a choice: dns-ip-cache, ip-prefix, ip-prefix-list, or masked-ip.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the masked-ip context
configure application-assurance group number partition number policy app-filter entry number server-address neq masked-ip
Commands in this context configure the attributes of a masked IP address.
The following elements are part of a choice: dns-ip-cache, ip-prefix, ip-prefix-list, or masked-ip.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IPv4 or IPv6 address mask
configure application-assurance group number partition number policy app-filter entry number server-address neq masked-ip address (ipv4-address-no-zone | ipv6-address-no-zone)
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IPv4 or IPv6 address mask
configure application-assurance group number partition number policy app-filter entry number server-address neq masked-ip netmask (ipv4-address-no-zone | ipv6-address-no-zone)
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the server-port context
configure application-assurance group number partition number policy app-filter entry number server-port
Commands in this context specify the server TCP or UDP port number to use in the application definition.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the eq context
configure application-assurance group number partition number policy app-filter entry number server-port eq
Commands in this context configure the exact value as the match criterion for the server TCP or UDP number in the app-filter.
The following elements are part of a choice: eq, gt, lt, or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
First packet policy
configure application-assurance group number partition number policy app-filter entry number server-port eq first-packet-policy keyword
This command configures the action to perform on the first packet.
first-packet-trusted, first-packet-validate
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Port-list name used in application filter criteria
configure application-assurance group number partition number policy app-filter entry number server-port eq port-list reference
configure application-assurance group number partition number port-list string
The following elements are part of a choice: port-list, port-number, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Server port number used as match criterion
configure application-assurance group number partition number policy app-filter entry number server-port eq port-number number
0 | 1 to 65535
0
The following elements are part of a choice: port-list, port-number, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the range context
configure application-assurance group number partition number policy app-filter entry number server-port eq range
Commands in this context specify the match value as the match criterion based on the starting or ending port number.
The following elements are part of a choice: port-list, port-number, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
TCP/UDP ending port number
configure application-assurance group number partition number policy app-filter entry number server-port eq range end number
0 | 1 to 65535
1
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
TCP/UDP starting port number
configure application-assurance group number partition number policy app-filter entry number server-port eq range start number
0 | 1 to 65535
0
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the gt context
configure application-assurance group number partition number policy app-filter entry number server-port gt
Commands in this context specify the greater than value as the match criterion for the server port number for the app-filter.
The following elements are part of a choice: eq, gt, lt, or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Server port number used as match criterion
configure application-assurance group number partition number policy app-filter entry number server-port gt port-number number
0 | 1 to 65535
0
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the lt context
configure application-assurance group number partition number policy app-filter entry number server-port lt
Commands in this context specify the less than value as the match criterion for the server port number for the app-filter.
The following elements are part of a choice: eq, gt, lt, or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Server port number used as match criterion
configure application-assurance group number partition number policy app-filter entry number server-port lt port-number number
0 | 1 to 65535
0
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the neq context
configure application-assurance group number partition number policy app-filter entry number server-port neq
Commands in this context configure non-match criterion used for the server TCP or UDP number in the app-filter.
The following elements are part of a choice: eq, gt, lt, or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Port-list name used in application filter criteria
configure application-assurance group number partition number policy app-filter entry number server-port neq port-list reference
configure application-assurance group number partition number port-list string
The following elements are part of a choice: port-list, port-number, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Server port number used as match criterion
configure application-assurance group number partition number policy app-filter entry number server-port neq port-number number
0 | 1 to 65535
0
The following elements are part of a choice: port-list, port-number, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the range context
configure application-assurance group number partition number policy app-filter entry number server-port neq range
Commands in this context specify the match value as the match criterion based on the starting or ending port number.
The following elements are part of a choice: port-list, port-number, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
TCP/UDP ending port number
configure application-assurance group number partition number policy app-filter entry number server-port neq range end number
0 | 1 to 65535
1
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
TCP/UDP starting port number
configure application-assurance group number partition number policy app-filter entry number server-port neq range start number
0 | 1 to 65535
0
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the app-group list instance
Commands in this context create an application group for an application assurance policy.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Application group name
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Charging group used in the AA application group policy
configure application-assurance group number partition number policy app-group string charging-group reference
configure application-assurance group number partition number policy charging-group string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number partition number policy app-group string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
App group export ID used in RADIUS accounting export
This command assigns an export ID value to a charging group, an application group, or an application that RADIUS accounting uses for accounting export identification. This export ID is encoded in the top two bytes of the RADIUS accounting VSA to identify which charging group the counter value represents.
If no export ID is assigned, the counter cannot be added to the AA subscriber stats RADIUS export-type. After a charging group index is referenced, it cannot be deleted without removing the reference.
1 to 255
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the app-profile list instance
configure application-assurance group number partition number policy app-profile string
Commands in this context create an application profile and configure the profile parameters.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
App-profile name
configure application-assurance group number partition number policy app-profile string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable AA suppression for subs with this app profile
configure application-assurance group number partition number policy app-profile string aa-sub-suppressible boolean
When configured to true, this command configures the ability to suppress Application Assurance for subscribers with this application profile.
This function is used in the context of an SRRP group interface. If an SRRP group interface is configured as configure service ies subscriber-interface group-interface suppress-aa-sub or configure service vprn subscriber-interface group-interface suppress-aa-sub, then subscribers with an application profile configured as suppressible are not diverted to Application Assurance.
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Application profile capacity cost
configure application-assurance group number partition number policy app-profile string capacity-cost number
This command configures an application profile capacity cost.
Capacity cost based load balancing allows a cost to be assigned to diverted SAPs (with the application profile). This allows for load balancing SAPs between ISAs and acts as a threshold to notify the operator if capacity planning is exceeded.
1 to 65535
1
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the characteristic list instance
configure application-assurance group number partition number policy app-profile string characteristic reference
Commands in this context assign one of the existing values of an existing application service option characteristic to the application profile.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Application service option characteristic name
configure application-assurance group number partition number policy app-profile string characteristic reference
configure application-assurance group number partition number policy app-service-options characteristic string
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
ASO characteristic value name
configure application-assurance group number partition number policy app-profile string characteristic reference value reference
configure application-assurance group number partition number policy app-service-options characteristic string value string
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number partition number policy app-profile string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable traffic redirection to AA ISAs or ESA VMs
configure application-assurance group number partition number policy app-profile string divert boolean
When configured to true, this command enables the redirection of traffic to AA ISAs or ESA VMs for the system-wide forwarding classes diverted to Application Assurance (configure isa application-assurance-group divert-fc) for AA subscribers using this application profile.
When configured to false, this command stops the redirection of traffic to AA ISAs or ESA VMs for the AA subscribers using this application profile.
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the app-qos-policy context
configure application-assurance group number partition number policy app-qos-policy
Commands in this context configure an application QoS policy.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the entry list instance
configure application-assurance group number partition number policy app-qos-policy entry number
Commands in this context create an application QoS policy (AQP) entry.
A flow that matches multiple AQP entries will have multiple AQP entries actions applied. If a conflict occurs for two or more actions, the action from the AQP entry with the lowest numerical value takes precedence.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AQP entry ID
configure application-assurance group number partition number policy app-qos-policy entry number
1 to 65535
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the action context
configure application-assurance group number partition number policy app-qos-policy entry number action
Commands in this context configure AQP actions to be performed on flows that match the match criteria of the AQP entry.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable abandoning TCP optimization for this entry
configure application-assurance group number partition number policy app-qos-policy entry number action abandon-tcp-optimization boolean
false
22.2.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the bandwidth-policer context
configure application-assurance group number partition number policy app-qos-policy entry number action bandwidth-policer
Commands in this context assign an existing bandwidth policer as an action on flows matching this AQP entry.
The match criteria for the AQP entry must specify a unidirectional traffic direction before a policer action can be configured. If a policer is used in one direction in an AQP match entry, the same policer name cannot be used by another AQP entry that uses different traffic direction match criteria.
When multiple policers apply to a single flow, the final action on a packet is the worst case of all policer outcomes (for example, if one of the policers marks packet out of profile, the final marking will reflect that).
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Access network locator bandwidth policer
configure application-assurance group number partition number policy app-qos-policy entry number action bandwidth-policer anl reference
This command creates an Application Assurance policy profile for a policer instance for each ANL that limits traffic bandwidth in the scope of that ANL. For ANL, only single-bucket bandwidth policers can be configured.
configure application-assurance group number policer anl-bandwidth-policer string
The following elements are part of a choice: anl, dual-bucket, or single-bucket.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Dual bucket bandwidth limiting policer
configure application-assurance group number partition number policy app-qos-policy entry number action bandwidth-policer dual-bucket reference
This command creates an Application Assurance policy profile for a dual bucket (PIR) bandwidth limiting policer.
configure application-assurance group number policer dual-bucket-bandwidth-policer string
The following elements are part of a choice: anl, dual-bucket, or single-bucket.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Single bucket bandwidth limiting policer
configure application-assurance group number partition number policy app-qos-policy entry number action bandwidth-policer single-bucket reference
This command creates an Application Assurance policy profile for a single bucket (PIR) bandwidth limiting policer.
The following elements are part of a choice: anl, dual-bucket, or single-bucket.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
DNS IP cache name
configure application-assurance group number partition number policy app-qos-policy entry number action dns-ip-cache reference
configure application-assurance group number dns-ip-cache string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable drop action for the AQP entry
configure application-assurance group number partition number policy app-qos-policy entry number action drop boolean
When configured to true, all flow traffic matching this AQP entry is dropped.
The drop action is performed first and no other action is invoked on that flow even if multiple other actions exist for the flow because of one or more AQP entry matches.
When configured to false, this command disables the drop action on flows matching this AQP entry.
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the error-drop context
configure application-assurance group number partition number policy app-qos-policy entry number action error-drop
Commands in this context configure a drop action for error flows (for instance, bad IP checksums or TCP/UDP port 0).
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Event log action for the AQP entry
configure application-assurance group number partition number policy app-qos-policy entry number action error-drop event-log reference
configure application-assurance group number partition number event-log string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the flow-count-limit-policer context
configure application-assurance group number partition number policy app-qos-policy entry number action flow-count-limit-policer
Commands in this context assign an existing flow count limit policer as an action on flows matching this AQP entry.
The match criteria for the AQP entry must specify a unidirectional traffic direction before a policer action can be configured. If a policer is used in one direction in an AQP match entry, the same policer name cannot be used by another AQP entry that uses different traffic direction match criteria.
When multiple policers are applied to a single flow, the final action on a packet is the worst case of all policer outcomes (for example, if one of the policers marks packet out of profile, the final marking will reflect that).
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Event log name
configure application-assurance group number partition number policy app-qos-policy entry number action flow-count-limit-policer event-log reference
configure application-assurance group number partition number event-log string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Policer name
configure application-assurance group number partition number policy app-qos-policy entry number action flow-count-limit-policer policer-name reference
This command specifies the name of the flow count limit policer for flows matching the AQP entry. The policer name is configured in the configure application-assurance group policer context.
configure application-assurance group number policer flow-count-limit-policer string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the flow-setup-rate-policer context
configure application-assurance group number partition number policy app-qos-policy entry number action flow-setup-rate-policer
Commands in this context assign an existing flow setup rate policer as an action on flows matching this AQP entry.
The match criteria for the AQP entry must specify a unidirectional traffic direction before a policer action can be configured. If a policer is used in one direction in an AQP match entry, the same policer name cannot be used for another AQP entry that uses different traffic direction match criteria.
When multiple policers are applied to a single flow, the final action on a packet is the worst case of all policer outcomes (for example, if one of the policers marks a packet out of profile, the final marking reflects that).
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Flow drop events log name due to flow-setup rate policer
configure application-assurance group number partition number policy app-qos-policy entry number action flow-setup-rate-policer event-log reference
configure application-assurance group number partition number event-log string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Policer name
configure application-assurance group number partition number policy app-qos-policy entry number action flow-setup-rate-policer policer-name reference
This command specifies the name of the flow setup rate policer for flows matching this AQP entry.
configure application-assurance group number policer flow-setup-rate-policer string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the fragment-drop context
configure application-assurance group number partition number policy app-qos-policy entry number action fragment-drop
Commands in this context specify the drop action options to apply to fragments.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Fragment-drop scope
configure application-assurance group number partition number policy app-qos-policy entry number action fragment-drop drop-scope keyword
This command specifies which fragments to drop as an action on flows matching this AQP entry.
all, out-of-order
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Event log name
configure application-assurance group number partition number policy app-qos-policy entry number action fragment-drop event-log reference
configure application-assurance group number partition number event-log string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
GTP filter executed for flows matching this AQP entry
configure application-assurance group number partition number policy app-qos-policy entry number action gtp-filter reference
configure application-assurance group number partition number gtp gtp-filter string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP header enrichment action for the AQP entry
configure application-assurance group number partition number policy app-qos-policy entry number action http-enrich reference
This command configures the HTTP header enrichment template name that is applied as defined in the tmnxBsxHttpEnrichTable. An empty value specifies no HTTP header enrichment template.
configure application-assurance group number http-enrich string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP error redirect for the AQP entry
configure application-assurance group number partition number policy app-qos-policy entry number action http-error-redirect reference
This command specifies the HTTP error redirect that is applied as defined in the redirect table. An empty value specifies no HTTP error redirect.
configure application-assurance group number http-error-redirect string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP notification to use for flows matching AQP entry
configure application-assurance group number partition number policy app-qos-policy entry number action http-notification reference
configure application-assurance group number http-notification string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the http-redirect context
configure application-assurance group number partition number policy app-qos-policy entry number action http-redirect
Commands in this context assign an existing HTTP redirect policy as an action on flows matching this AQP entry.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Flow type for HTTP redirect of flows matching the entry
configure application-assurance group number partition number policy app-qos-policy entry number action http-redirect flow-type keyword
This command assigns an existing HTTP redirect policy as an action on flows matching this AQP entry. The redirect only takes effect if the matching flows are HTTP and the condition specified is met.
The condition specified by dropped flows means the flow is dropped due to an AQP action, such as flow rate, count policers, or drop actions. The admitted flows condition allows the operator to redirect HTTP traffic to a web portal while allowing non-HTTP traffic matching the same AQP rule to be forwarded.
No HTTP redirect takes place if the HTTP redirect action and a drop/flow-police action are part of the default AQP policy. In this case, any flow drop actions take place before identification of the application/application-group.
dropped-flows, admitted-flows
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP redirect policy name
configure application-assurance group number partition number policy app-qos-policy entry number action http-redirect name reference
This command specifies the name of an existing HTTP policy redirect.
configure application-assurance group number http-redirect string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the mirror-source context
configure application-assurance group number partition number policy app-qos-policy entry number action mirror-source
Commands in this context configure an application-based policy mirroring service that uses the AQP entry of this AA ISA as a mirror source.
When configured, the AQP entry becomes a mirror source for IP packets seen by AA. The mirrored packet is an IP packet analyzed by AA and does not include encapsulations present on the incoming interfaces.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Mirror flows matching the AQP subscriber default policy
configure application-assurance group number partition number policy app-qos-policy entry number action mirror-source all-inclusive boolean
This command specifies that all packets during the identification phase that could match a given AQP rule are mirrored in addition to packets after an application identification completes that match the AQP rule. This ensures that all packets of a flow are mirrored at a cost of sending some unidentified packets, which after the application is identified no longer match this AQP entry.
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Mirror source service ID for flows matching the entry
configure application-assurance group number partition number policy app-qos-policy entry number action mirror-source mirror-service reference
This command specifies the mirror source service ID to use for flows that match this policy.
configure mirror mirror-dest string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the overload-drop context
configure application-assurance group number partition number policy app-qos-policy entry number action overload-drop
Commands in this context configure a drop action for cases where flow records are not created (overload). This command is only applicable to ISA2 hardware.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Event log name
configure application-assurance group number partition number policy app-qos-policy entry number action overload-drop event-log reference
configure application-assurance group number partition number event-log string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the remark context
configure application-assurance group number partition number policy app-qos-policy entry number action remark
Commands in this context configure the remark action on flows matching this AQP entry.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the dscp context
configure application-assurance group number partition number policy app-qos-policy entry number action remark dscp
Commands in this context configure the DSCP remark action or actions on flows matching this AQP entry.
All packets for all flows matching this AQP entry are remarked to the configured DSCP name.
DSCP remark can only be applied when the entry remarks forwarding class or forwarding class and priority. In-profile and out-of-profile of a packet for DSCP remark is assessed after all AQP policing and priority remarking actions have taken place.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
DSCP name to remark matching in-profile flows
configure application-assurance group number partition number policy app-qos-policy entry number action remark dscp in-profile keyword
be, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
DSCP name to remark matching out-of-profile flows
configure application-assurance group number partition number policy app-qos-policy entry number action remark dscp out-profile keyword
be, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
FC remark action for flows matching this entry
configure application-assurance group number partition number policy app-qos-policy entry number action remark fc keyword
be, l2, af, l1, h2, ef, h1, nc
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Priority to use to remark flows matching this entry
configure application-assurance group number partition number policy app-qos-policy entry number action remark priority keyword
auto
low, high, auto
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
SCTP filter to use for flows matching the AQP entry
configure application-assurance group number partition number policy app-qos-policy entry number action sctp-filter reference
configure application-assurance group number partition number sctp-filter string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Session filter to use for flows matching the AQP entry
configure application-assurance group number partition number policy app-qos-policy entry number action session-filter reference
configure application-assurance group number partition number session-filter string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
TCP MSS adjustment traffic action and size
configure application-assurance group number partition number policy app-qos-policy entry number action tcp-mss-adjust number
160 to 10240
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
TCP validation policy action for entry matching flows
configure application-assurance group number partition number policy app-qos-policy entry number action tcp-validate reference
This command assigns an existing TCP validation policy as an action on flows matching this AQP entry.
TCP validation can only be called from AQP entries that:
configure application-assurance group number partition number tcp-validate string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP TLS enrichment action for the AQP entry
configure application-assurance group number partition number policy app-qos-policy entry number action tls-enrich reference
configure application-assurance group number http-enrich string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the url-filter context
configure application-assurance group number partition number policy app-qos-policy entry number action url-filter
Commands in this context configure a URL filter action for flows matching this entry.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
URL filter characteristic used for matching AQP entries
configure application-assurance group number partition number policy app-qos-policy entry number action url-filter characteristic reference
configure application-assurance group number partition number policy app-service-options characteristic string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
URL filter name
configure application-assurance group number partition number policy app-qos-policy entry number action url-filter name reference
configure application-assurance group number url-filter string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of the AA AQP entry
configure application-assurance group number partition number policy app-qos-policy entry number admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number partition number policy app-qos-policy entry number description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the match context
configure application-assurance group number partition number policy app-qos-policy entry number match
Commands in this context configure flow match rules for this AQP entry. A flow matches this AQP entry only if it matches all match rules defined (logical AND of all rules). If no match rule is specified, the entry will match all flows.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the aa-sub context
configure application-assurance group number partition number policy app-qos-policy entry number match aa-sub
Commands in this context specify a Service Access Point (SAP) or an Enhanced Subscriber Management (ESM) subscriber as matching criteria.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the esm context
configure application-assurance group number partition number policy app-qos-policy entry number match aa-sub esm
Commands in this context configure the ESM fields for the AA subscriber match entry.
The following elements are part of a choice: esm, esm-mac, sap, spoke-sdp, or transit.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Exact match criterion used for the ESM subscriber
1 to 32
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Non-match criterion used for ESM subscriber
1 to 32
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the esm-mac context
configure application-assurance group number partition number policy app-qos-policy entry number match aa-sub esm-mac
Commands in this context configure the ESM MAC fields for the AA subscriber match entry.
The following elements are part of a choice: esm, esm-mac, sap, spoke-sdp, or transit.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Exact match criterion used for ESM MAC subscriber
1 to 32
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Non-match criterion used for AA subscriber ESM MAC
1 to 32
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the sap context
configure application-assurance group number partition number policy app-qos-policy entry number match aa-sub sap
Commands in this context configure the SAP fields for the AA subscriber match entry.
The following elements are part of a choice: esm, esm-mac, sap, spoke-sdp, or transit.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Exact match criterion used for the SAP subscriber
1 to 45
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Non-match criterion used for the SAP subscriber
1 to 45
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the spoke-sdp context
configure application-assurance group number partition number policy app-qos-policy entry number match aa-sub spoke-sdp
Commands in this context configure the spoke SDP fields for the AA subscriber match entry.
The following elements are part of a choice: esm, esm-mac, sap, spoke-sdp, or transit.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Exact match criterion used for a spoke SDP subscriber
3 to 16
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Non-match criterion used for a spoke SDP subscriber
3 to 16
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the transit context
configure application-assurance group number partition number policy app-qos-policy entry number match aa-sub transit
Commands in this context configure the transit fields for the AA subscriber match entry.
The following elements are part of a choice: esm, esm-mac, sap, spoke-sdp, or transit.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Exact match criterion used for a transit AA subscriber
1 to 32
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Non-match criterion used for a transit AA subscriber
1 to 32
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Tethering detection status for flow match criterion
configure application-assurance group number partition number policy app-qos-policy entry number match aa-sub-tethering keyword
This command configures the match criteria for subscribers in a tethering state.
not-applicable
not-applicable, detected, not-detected
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the app-group context
configure application-assurance group number partition number policy app-qos-policy entry number match app-group
Commands in this context add an application group to the match criteria used by this AQP entry.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Exact match criterion used for the application group
configure application-assurance group number partition number policy app-qos-policy entry number match app-group eq reference
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Non-match criterion used for the application group
configure application-assurance group number partition number policy app-qos-policy entry number match app-group neq reference
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the application context
configure application-assurance group number partition number policy app-qos-policy entry number match application
Commands in this context add an application to match criteria used by this AQP entry.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Exact match criterion used for the application
configure application-assurance group number partition number policy app-qos-policy entry number match application eq reference
configure application-assurance group number partition number policy application string
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Non-match criterion used for the application
configure application-assurance group number partition number policy app-qos-policy entry number match application neq reference
configure application-assurance group number partition number policy application string
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the characteristic list instance
configure application-assurance group number partition number policy app-qos-policy entry number match characteristic reference
Commands in this context configure an existing characteristic and its value to the match criteria used by this AQP entry.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
ASO characteristic name for AQP entry matching
configure application-assurance group number partition number policy app-qos-policy entry number match characteristic reference
configure application-assurance group number partition number policy app-service-options characteristic string
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Match criterion used for AQP match characteristic
configure application-assurance group number partition number policy app-qos-policy entry number match characteristic reference eq reference
configure application-assurance group number partition number policy app-service-options characteristic string value string
The following elements are part of a mandatory choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Non-match criterion used for AQP match characteristic
configure application-assurance group number partition number policy app-qos-policy entry number match characteristic reference neq reference
configure application-assurance group number partition number policy app-service-options characteristic string value string
The following elements are part of a mandatory choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the charging-group context
configure application-assurance group number partition number policy app-qos-policy entry number match charging-group
Commands in this context add a charging group to match criteria used by this AQP entry.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Match criterion used for the charging group
configure application-assurance group number partition number policy app-qos-policy entry number match charging-group eq reference
configure application-assurance group number partition number policy charging-group string
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Non-match criterion used for the charging group
configure application-assurance group number partition number policy app-qos-policy entry number match charging-group neq reference
configure application-assurance group number partition number policy charging-group string
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the dscp context
configure application-assurance group number partition number policy app-qos-policy entry number match dscp
Commands in this context add a DSCP name to the match criteria used by this entry.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Exact match criterion used for the DSCP
configure application-assurance group number partition number policy app-qos-policy entry number match dscp eq keyword
be, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Non-match criterion used for the DSCP
configure application-assurance group number partition number policy app-qos-policy entry number match dscp neq keyword
be, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the dst-ip context
configure application-assurance group number partition number policy app-qos-policy entry number match dst-ip
Commands in this context configure a destination IP address to use as match criteria.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the eq context
configure application-assurance group number partition number policy app-qos-policy entry number match dst-ip eq
Commands in this context specify the exact match value as the match criterion. A successful match occurs when the flow matches the specified address or prefix.
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP address prefix used for match criterion
The following elements are part of a choice: ip-prefix or ip-prefix-list.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP address prefix list used for match criterion
configure application-assurance group number partition number policy app-qos-policy entry number match dst-ip eq ip-prefix-list reference
configure application-assurance group number partition number ip-prefix-list string
The following elements are part of a choice: ip-prefix or ip-prefix-list.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the neq context
configure application-assurance group number partition number policy app-qos-policy entry number match dst-ip neq
Commands in this context specify the non-match value as the match criterion. A successful match occurs when the flow does not match the specified address or prefix.
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP address prefix used for match criterion
The following elements are part of a choice: ip-prefix or ip-prefix-list.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP address prefix list used for match criterion
configure application-assurance group number partition number policy app-qos-policy entry number match dst-ip neq ip-prefix-list reference
configure application-assurance group number partition number ip-prefix-list string
The following elements are part of a choice: ip-prefix or ip-prefix-list.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the dst-port context
configure application-assurance group number partition number policy app-qos-policy entry number match dst-port
Commands in this context configure a destination TCP/UDP port, a destination port list, or a destination range to use as match criteria.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the eq context
configure application-assurance group number partition number policy app-qos-policy entry number match dst-port eq
Commands in this context specify the exact match criterion. A successful match occurs when the flow matches the specified port.
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP port list used as match criterion
configure application-assurance group number partition number port-list string
The following elements are part of a choice: port-list, port-number, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Server port number used as match criterion
configure application-assurance group number partition number policy app-qos-policy entry number match dst-port eq port-number number
0 | 1 to 65535
0
The following elements are part of a choice: port-list, port-number, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the range context
Commands in this context specify the match value as the match criterion based on the starting or ending port number.
The following elements are part of a choice: port-list, port-number, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
TCP/UDP ending port number
0 | 1 to 65535
1
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
TCP/UDP starting port number
0 | 1 to 65535
0
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the neq context
configure application-assurance group number partition number policy app-qos-policy entry number match dst-port neq
Commands in this context specify the non-match value as the match criterion. A successful match occurs when the flow does not match the specified port.
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP port list used as match criterion
configure application-assurance group number partition number port-list string
The following elements are part of a choice: port-list, port-number, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Server port number used as match criterion
configure application-assurance group number partition number policy app-qos-policy entry number match dst-port neq port-number number
0 | 1 to 65535
0
The following elements are part of a choice: port-list, port-number, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the range context
Commands in this context specify the match value as the match criterion based on the starting or ending port number.
The following elements are part of a choice: port-list, port-number, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
TCP/UDP ending port number
0 | 1 to 65535
1
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
TCP/UDP starting port number
0 | 1 to 65535
0
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the flow-attribute list instance
configure application-assurance group number partition number policy app-qos-policy entry number match flow-attribute string
Commands in this context configure a flow attribute to use as match criteria. The supported options are:
10
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Flow attribute name used as match criterion
configure application-assurance group number partition number policy app-qos-policy entry number match flow-attribute string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the confidence context
configure application-assurance group number partition number policy app-qos-policy entry number match flow-attribute string confidence
Commands in this context configure the confidence level of the flow attribute for use as match criteria.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Exact match criterion used for the flow-attribute confidence
configure application-assurance group number partition number policy app-qos-policy entry number match flow-attribute string confidence eq number
0 to 100
The following elements are part of a choice: eq, gte, or lt.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Greater than or equal to for confidence match criterion
configure application-assurance group number partition number policy app-qos-policy entry number match flow-attribute string confidence gte number
0 to 100
The following elements are part of a choice: eq, gte, or lt.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Less than value for confidence match criterion
configure application-assurance group number partition number policy app-qos-policy entry number match flow-attribute string confidence lt number
1 to 100
The following elements are part of a choice: eq, gte, or lt.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the ip-protocol context
configure application-assurance group number partition number policy app-qos-policy entry number match ip-protocol
Commands in this context configure the IP protocol to use in the application definition.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Exact match criterion used for the IP protocol
configure application-assurance group number partition number policy app-qos-policy entry number match ip-protocol eq (number | keyword)
0 to 255
tcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Non-match criterion used for the IP protocol
configure application-assurance group number partition number policy app-qos-policy entry number match ip-protocol neq (number | keyword)
0 to 255
tcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the src-ip context
configure application-assurance group number partition number policy app-qos-policy entry number match src-ip
Commands in this context configure a source IP address to use as match criteria.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the eq context
configure application-assurance group number partition number policy app-qos-policy entry number match src-ip eq
Commands in this context specify the exact match value as the match criterion. A successful match occurs when the flow matches the specified address or prefix.
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP address prefix used for match criterion
The following elements are part of a choice: ip-prefix or ip-prefix-list.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP address prefix list used for match criterion
configure application-assurance group number partition number policy app-qos-policy entry number match src-ip eq ip-prefix-list reference
configure application-assurance group number partition number ip-prefix-list string
The following elements are part of a choice: ip-prefix or ip-prefix-list.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the neq context
configure application-assurance group number partition number policy app-qos-policy entry number match src-ip neq
Commands in this context specify the non-match value as the match criterion. A successful match occurs when the flow does not match the specified address or prefix.
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP address prefix used for match criterion
The following elements are part of a choice: ip-prefix or ip-prefix-list.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP address prefix list used for match criterion
configure application-assurance group number partition number policy app-qos-policy entry number match src-ip neq ip-prefix-list reference
configure application-assurance group number partition number ip-prefix-list string
The following elements are part of a choice: ip-prefix or ip-prefix-list.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the src-port context
configure application-assurance group number partition number policy app-qos-policy entry number match src-port
Commands in this context specify a source IP port, a source port list, or a source range to use as match criteria.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the eq context
configure application-assurance group number partition number policy app-qos-policy entry number match src-port eq
Commands in this context specify the exact match criterion. A successful match occurs when the flow matches the specified port.
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP port list used as match criterion
configure application-assurance group number partition number port-list string
The following elements are part of a choice: port-list, port-number, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Server port number used as match criterion
configure application-assurance group number partition number policy app-qos-policy entry number match src-port eq port-number number
0 | 1 to 65535
0
The following elements are part of a choice: port-list, port-number, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the range context
Commands in this context specify the match value as the match criterion based on the starting or ending port number.
The following elements are part of a choice: port-list, port-number, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
TCP/UDP ending port number
0 | 1 to 65535
1
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
TCP/UDP starting port number
0 | 1 to 65535
0
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the neq context
configure application-assurance group number partition number policy app-qos-policy entry number match src-port neq
Commands in this context specify the non-match value as the match criterion. A successful match occurs when the flow does not match the specified port.
The following elements are part of a choice: eq or neq.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP port list used as match criterion
configure application-assurance group number partition number port-list string
The following elements are part of a choice: port-list, port-number, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Server port number used as match criterion
configure application-assurance group number partition number policy app-qos-policy entry number match src-port neq port-number number
0 | 1 to 65535
0
The following elements are part of a choice: port-list, port-number, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the range context
Commands in this context specify the match value as the match criterion based on the starting or ending port number.
The following elements are part of a choice: port-list, port-number, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
TCP/UDP ending port number
0 | 1 to 65535
1
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
TCP/UDP starting port number
0 | 1 to 65535
0
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Traffic direction to which AQP match entry is applied
configure application-assurance group number partition number policy app-qos-policy entry number match traffic-direction keyword
both
subscriber-to-network, network-to-subscriber, both
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the app-service-options context
configure application-assurance group number partition number policy app-service-options
Commands in this context configure application service option characteristics.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the characteristic list instance
configure application-assurance group number partition number policy app-service-options characteristic string
Commands in this context create the characteristic of the application service options.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
ASO characteristic name
configure application-assurance group number partition number policy app-service-options characteristic string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
ASO characteristic default value
configure application-assurance group number partition number policy app-service-options characteristic string default-value string
1 to 32
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Add a list entry for value
configure application-assurance group number partition number policy app-service-options characteristic string value string
Commands in this context configure a characteristic value.
64
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
ASO characteristic value name
configure application-assurance group number partition number policy app-service-options characteristic string value string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the application list instance
configure application-assurance group number partition number policy application string
Commands in this context configure the policy application of the Application Assurance group partition.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Application name
configure application-assurance group number partition number policy application string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Application group associated with the application
configure application-assurance group number partition number policy application string app-group reference
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Charging group associated with the application
configure application-assurance group number partition number policy application string charging-group reference
configure application-assurance group number partition number policy charging-group string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number partition number policy application string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Application export ID used for RADIUS accounting
configure application-assurance group number partition number policy application string export-id number
1 to 255
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the charging-group list instance
configure application-assurance group number partition number policy charging-group string
Commands in this context create a charging group for an Application Assurance policy.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Charging group name
configure application-assurance group number partition number policy charging-group string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number partition number policy charging-group string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Charging group export ID used for RADIUS accounting
configure application-assurance group number partition number policy charging-group string export-id number
This command assigns an export ID value to a charging group, an app application group, or an application to be used for accounting export identification in RADIUS accounting. This ID is encoded in the top 2 bytes of the RADIUS accounting VSA to identify which charging group the counter value represents.
1 to 255
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Start and stop notification for the charging group
configure application-assurance group number partition number policy charging-group string notify-start-stop keyword
none
none, flow, charging-group
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the custom-protocol list instance
configure application-assurance group number partition number policy custom-protocol string
Commands in this context configure custom protocols.
Custom protocols allow the creation of TCP and UDP-based custom protocols that employ pattern-match at offset in the protocol signature definition.
Operator-configurable custom protocols are evaluated ahead of any Nokia-provided protocol signature in order of custom protocol ID within the context the protocol is defined. The lower ID is matched first in case of flow matching multiple custom protocols.
Custom protocols must be created before they can be used in an application definition but do not have to be enabled. To reference a custom protocol in an application definition, or any other CLI configuration one must use the protocol name that is a concatenation of “custom_” and, (for example, custom_01, custom_02 ... custom_10, and so on). This concatenation is also used when reporting custom protocol statistics.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Custom protocol ID for the AA policy custom protocol
configure application-assurance group number partition number policy custom-protocol string
This command configures the index into the protocol list that defines a custom protocol for Application Assurance.
9
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of the custom protocol
configure application-assurance group number partition number policy custom-protocol string admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number partition number policy custom-protocol string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the expression list instance
configure application-assurance group number partition number policy custom-protocol string expression number
Commands in this context configure an expression string value for pattern-based custom protocols match.
A flow matches a custom protocol if the specified string is found at an offset of a TCP/UDP of the first payload packet.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Expression substring index for custom protocol matching
configure application-assurance group number partition number policy custom-protocol string expression number
1
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Flow direction for custom-protocol expression matching
configure application-assurance group number partition number policy custom-protocol string expression number direction keyword
This command configures the protocol direction to match against for a custom protocol.
client-to-server, server-to-client, any
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Exact match criterion for custom protocol expression
configure application-assurance group number partition number policy custom-protocol string expression number eq string
1 to 255
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Offset in protocol flow to start custom-protocol match
configure application-assurance group number partition number policy custom-protocol string expression number offset number
This command configures the offset into the protocol payload where the expr-string match criteria starts.
0 to 127
0
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
IP protocol number for custom-protocol match criterion
configure application-assurance group number partition number policy custom-protocol string ip-protocol keyword
This command configures the IP protocol number of the TCP and UDP-based custom protocols.
tcp, udp
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Default charging group
configure application-assurance group number partition number policy default-charging-group reference
This command associates a charging group with any applications or application groups that do not have an explicitly assigned charging group for the Application Assurance policy.
configure application-assurance group number partition number policy charging-group string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Default charging group for tethered traffic
configure application-assurance group number partition number policy default-tethered-charging-group reference
This command configures the default charging group to be assigned to all flows which are classified as tethered.
For flows that have been identified as tethered, the AA will replace the charging group configured at the application level with the charging group configured for tethered traffic (that is, configured with default-tethered-charging-group).
configure application-assurance group number partition number policy charging-group string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the policy-override context
configure application-assurance group number partition number policy-override
Commands in this context configure policy override parameters.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the aa-sub context
configure application-assurance group number partition number policy-override aa-sub
Commands in this context configure the AA policy override subscriber fields.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the sap list instance
configure application-assurance group number partition number policy-override aa-sub sap string
Commands in this context configure the Service Access Point (SAP) within the partition.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AA subscriber SAP ID
configure application-assurance group number partition number policy-override aa-sub sap string
1 to 45
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the characteristic list instance
configure application-assurance group number partition number policy-override aa-sub sap string characteristic reference
Commands in this context configure an override characteristic and value.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
ASO characteristic name
configure application-assurance group number partition number policy-override aa-sub sap string characteristic reference
configure application-assurance group number partition number policy app-service-options characteristic string
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Characteristic value used in subscriber policy override
configure application-assurance group number partition number policy-override aa-sub sap string characteristic reference value reference
configure application-assurance group number partition number policy app-service-options characteristic string value string
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the spoke-sdp list instance
configure application-assurance group number partition number policy-override aa-sub spoke-sdp string
Commands in this context configure the Service Distribution Point (SDP) for the policy override.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Spoke SDP ID for an AA subscriber
configure application-assurance group number partition number policy-override aa-sub spoke-sdp string
3 to 16
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the characteristic list instance
configure application-assurance group number partition number policy-override aa-sub spoke-sdp string characteristic reference
Commands in this context configure an override characteristic and value.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
ASO characteristic name
configure application-assurance group number partition number policy-override aa-sub spoke-sdp string characteristic reference
configure application-assurance group number partition number policy app-service-options characteristic string
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Characteristic value used in subscriber policy override
configure application-assurance group number partition number policy-override aa-sub spoke-sdp string characteristic reference value reference
configure application-assurance group number partition number policy app-service-options characteristic string value string
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the transit list instance
configure application-assurance group number partition number policy-override aa-sub transit string
Commands in this context configure the AA transit subscriber fields.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Transit subscriber name
configure application-assurance group number partition number policy-override aa-sub transit string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the characteristic list instance
configure application-assurance group number partition number policy-override aa-sub transit string characteristic reference
Commands in this context configure an override characteristic and value.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
ASO characteristic name
configure application-assurance group number partition number policy-override aa-sub transit string characteristic reference
configure application-assurance group number partition number policy app-service-options characteristic string
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Characteristic value used in subscriber policy override
configure application-assurance group number partition number policy-override aa-sub transit string characteristic reference value reference
configure application-assurance group number partition number policy app-service-options characteristic string value string
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the port-list list instance
configure application-assurance group number partition number port-list string
Commands in this context define an AA group or partition named port list, which contains a list of port numbers or port ranges.
The port list is then referenced in AA policy application filters, allowing increased flexibility in the use of server ports or HTTP proxy ports for application definition.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Port list name
configure application-assurance group number partition number port-list string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number partition number port-list string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Add a list entry for port
Commands in this context specify the server TCP or UDP port number to use in the port list definition.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Port number
0 to 65535
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Add a list entry for range
Commands in this context configure the AA group or partition named port-list range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Start value for the port range in the AA port list
0 to 65534
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
End value for the port range in the AA port list
1 to 65535
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the sctp-filter list instance
configure application-assurance group number partition number sctp-filter string
Commands in this context configure the Stream Control Transmission Protocol (SCTP) fields.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
SCTP filter name
configure application-assurance group number partition number sctp-filter string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number partition number sctp-filter string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Event log for packets dropped by the SCTP filter
configure application-assurance group number partition number sctp-filter string event-log reference
configure application-assurance group number partition number event-log string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the ppid context
configure application-assurance group number partition number sctp-filter string ppid
Commands in this context configure actions for specific or default Payload Protocol Identifiers (PPIDs).
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Default action for all SCTP PPIDs
configure application-assurance group number partition number sctp-filter string ppid default-action keyword
permit
deny, permit
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the entry list instance
configure application-assurance group number partition number sctp-filter string ppid entry number
Commands in this context specify SCTP PPID values and the corresponding action to apply.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
SCTP filter PPID entry ID
configure application-assurance group number partition number sctp-filter string ppid entry number
1 to 255
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
SCTP filter PPID entry action
configure application-assurance group number partition number sctp-filter string ppid entry number action keyword
deny, permit
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
PPID entry value
configure application-assurance group number partition number sctp-filter string ppid entry number value (number | keyword)
0 to 4294967295
iua, m2ua, m3ua, sua, m2pa, v5ua, h.248, bicc/q.2150.3, tali, dua, asap, enrp, h.323, q.ipc/q.2150.3, simco, ddp-segment-chunk, ddp-stream-session-control, s1-application-protocol, rua, hnbap, forces-hp, forces-mp, forces-lp, sbc-ap, nbap, x2ap, ircp, lcs-ap, mpich2, service-area-broadcast-protocol, fractal-generator-protocol, ping-pong-protocol, calcapp-protocol, scripting-service-protocol, netperfmeter-protocol-control-channel, netperfmeter-protocol-data-channel, echo, discard, daytime, character-generator, 3gpp-rna, 3gpp-m2ap, 3gpp-m3ap, ssh-over-sctp, diameter-in-a-sctp-data-chunk, diameter-in-a-dtls/sctp-data-chunk, r14p.-ber-encoded-asn.1-over-sctp, webrtc-control, domstring-last, binary-data-partial, binary-data-last, domstring-partial, 3gpp-pua, webrtc-string-empty, webrtc-binary-empty, 3gpp-xwap, 3gpp-xw-control-plane, 3gpp-ng-application-protocol, 3gpp-xn-application-protocol, 3gpp-f1-application-protocol, http-sctp, 3gpp-e1-application-protocol, ele2-lawful-interception, 3gpp-ngap-over-dtls-over-sctp, 3gpp-xnap-over-dtls-over-sctp, 3gpp-f1ap-over-dtls-over-sctp, 3gpp-e1ap-over-dtls-over-sctp, e2-cp, e2-up, e2-du, 3gpp-w1ap
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the ppid-range context
configure application-assurance group number partition number sctp-filter string ppid-range
Commands in this context specify the range of PPID values that are allowed by the AA SCTP filter firewall.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Maximum PPID value
configure application-assurance group number partition number sctp-filter string ppid-range max number
This command configures the maximum SCTP Payload Protocol Identifier (PPID) to be permitted by the SCTP filter. The value must be greater or equal to the minimum PPID value.
0 to 4294967295
4294967295
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Minimum PPID value
configure application-assurance group number partition number sctp-filter string ppid-range min number
This command configures the minimum SCTP Payload Protocol Identifier (PPID) to be permitted by the SCTP filter. The value must be less than or equal to the maximum PPID value.
0 to 4294967295
0
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the session-filter list instance
configure application-assurance group number partition number session-filter string
Commands in this context create a session filter.
300
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Session filter name
configure application-assurance group number partition number session-filter string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the default-action context
configure application-assurance group number partition number session-filter string default-action
Commands in this context specify the default action to take for packets that do not match any filter entries.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Default action for packets not matching filter entries
configure application-assurance group number partition number session-filter string default-action action keyword
deny
deny, permit
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Event logging of default action
configure application-assurance group number partition number session-filter string default-action event-log reference
configure application-assurance group number partition number event-log string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number partition number session-filter string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the entry list instance
configure application-assurance group number partition number session-filter string entry number
Commands in this context configure an AA session filter match entry.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Entry ID for the session filter entry
configure application-assurance group number partition number session-filter string entry number
1 to 65535
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the action context
configure application-assurance group number partition number session-filter string entry number action
Commands in this context configure the action for this entry.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Deny sessions matching the criteria
configure application-assurance group number partition number session-filter string entry number action deny
This element is the default part of a choice.
The following elements are part of a choice: deny, http-redirect, permit, or tcp-optimizer.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Event log name used to log the action
configure application-assurance group number partition number session-filter string entry number action event-log reference
configure application-assurance group number partition number event-log string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP redirect for matching sessions
configure application-assurance group number partition number session-filter string entry number action http-redirect reference
configure application-assurance group number http-redirect string
The following elements are part of a choice: deny, http-redirect, permit, or tcp-optimizer.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Permit sessions that match the criteria
configure application-assurance group number partition number session-filter string entry number action permit
The following elements are part of a choice: deny, http-redirect, permit, or tcp-optimizer.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
TCP optimizer to handle sessions matching the criteria
configure application-assurance group number partition number session-filter string entry number action tcp-optimizer reference
configure application-assurance group number tcp-optimizer string
The following elements are part of a choice: deny, http-redirect, permit, or tcp-optimizer.
22.2.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number partition number session-filter string entry number description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the match context
configure application-assurance group number partition number session-filter string entry number match
Commands in this context configure session conditions for this entry.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the dst-ip context
configure application-assurance group number partition number session-filter string entry number match dst-ip
Commands in this context configure the destination IP address to match.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Destination IPs in specified DNS IP Cache
configure application-assurance group number partition number session-filter string entry number match dst-ip dns-ip-cache reference
configure application-assurance group number dns-ip-cache string
The following elements are part of a choice: dns-ip-cache, ip-prefix, or ip-prefix-list.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Destination IP address prefix as match criterion
configure application-assurance group number partition number session-filter string entry number match dst-ip ip-prefix (ipv4-prefix | ipv6-prefix)
The following elements are part of a choice: dns-ip-cache, ip-prefix, or ip-prefix-list.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP address prefix list as match criterion
configure application-assurance group number partition number session-filter string entry number match dst-ip ip-prefix-list reference
configure application-assurance group number partition number ip-prefix-list string
The following elements are part of a choice: dns-ip-cache, ip-prefix, or ip-prefix-list.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the dst-port context
configure application-assurance group number partition number session-filter string entry number match dst-port
Commands in this context specify a destination TCP/UDP port, a destination port list, or a destination range to use as match criteria.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Match criterion used for destination or source port
configure application-assurance group number partition number session-filter string entry number match dst-port eq number
0 | 1 to 65535
0
The following elements are part of a choice: eq, gt, lt, port-list, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Greater than match criterion for the port number
configure application-assurance group number partition number session-filter string entry number match dst-port gt number
0 | 1 to 65535
0
The following elements are part of a choice: eq, gt, lt, port-list, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Less than match criterion for the port
configure application-assurance group number partition number session-filter string entry number match dst-port lt number
0 | 1 to 65535
0
The following elements are part of a choice: eq, gt, lt, port-list, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Destination or source port list
configure application-assurance group number partition number session-filter string entry number match dst-port port-list reference
configure application-assurance group number partition number port-list string
The following elements are part of a choice: eq, gt, lt, port-list, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the range context
configure application-assurance group number partition number session-filter string entry number match dst-port range
Commands in this context specify a destination IP port, a destination port list, or a destination range to use as match criteria.
The following elements are part of a choice: eq, gt, lt, port-list, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Upper bound of the port range as match criterion
configure application-assurance group number partition number session-filter string entry number match dst-port range end number
0 | 1 to 65535
1
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Lower bound of the port range as match criterion
configure application-assurance group number partition number session-filter string entry number match dst-port range start number
0 | 1 to 65535
0
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP protocol as a match criterion
configure application-assurance group number partition number session-filter string entry number match ip-protocol (number | keyword)
0 to 255
tcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the src-ip context
configure application-assurance group number partition number session-filter string entry number match src-ip
Commands in this context specify a source IP address to use as match criteria.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Source IP address prefix as match criterion
configure application-assurance group number partition number session-filter string entry number match src-ip ip-prefix (ipv4-prefix | ipv6-prefix)
The following elements are part of a choice: ip-prefix or ip-prefix-list.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Source IP address prefix list as match criterion
configure application-assurance group number partition number session-filter string entry number match src-ip ip-prefix-list reference
configure application-assurance group number partition number ip-prefix-list string
The following elements are part of a choice: ip-prefix or ip-prefix-list.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the src-port context
configure application-assurance group number partition number session-filter string entry number match src-port
Commands in this context specify a source IP port, a source port list, or a source range to use as match criteria.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Match criterion used for destination or source port
configure application-assurance group number partition number session-filter string entry number match src-port eq number
0 | 1 to 65535
0
The following elements are part of a choice: eq, gt, lt, port-list, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Greater than match criterion for the port number
configure application-assurance group number partition number session-filter string entry number match src-port gt number
0 | 1 to 65535
0
The following elements are part of a choice: eq, gt, lt, port-list, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Less than match criterion for the port
configure application-assurance group number partition number session-filter string entry number match src-port lt number
0 | 1 to 65535
0
The following elements are part of a choice: eq, gt, lt, port-list, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Destination or source port list
configure application-assurance group number partition number session-filter string entry number match src-port port-list reference
configure application-assurance group number partition number port-list string
The following elements are part of a choice: eq, gt, lt, port-list, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the range context
configure application-assurance group number partition number session-filter string entry number match src-port range
Commands in this context specify a destination IP port, a destination port list, or a destination range to use as match criteria.
The following elements are part of a choice: eq, gt, lt, port-list, or range.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Upper bound of the port range as match criterion
configure application-assurance group number partition number session-filter string entry number match src-port range end number
0 | 1 to 65535
1
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Lower bound of the port range as match criterion
configure application-assurance group number partition number session-filter string entry number match src-port range start number
0 | 1 to 65535
0
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable shallow inspection
configure application-assurance group number partition number shallow-inspection boolean
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the statistics context
configure application-assurance group number partition number statistics
Commands in this context configure accounting and billing statistics for this AA group.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the aa-admit-deny context
configure application-assurance group number partition number statistics aa-admit-deny
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Accounting policy
configure application-assurance group number partition number statistics aa-admit-deny accounting-policy reference
configure log accounting-policy number
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Collect statistics
configure application-assurance group number partition number statistics aa-admit-deny collect-stats boolean
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Include GTP filter statistics in admit-deny accounting records
configure application-assurance group number partition number statistics aa-admit-deny gtp-filter-stats boolean
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Include admit-deny policer statistics in accounting records
configure application-assurance group number partition number statistics aa-admit-deny policer-stats boolean
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Allocate ISA/ ESA resources for policer admit-deny statistics
configure application-assurance group number partition number statistics aa-admit-deny policer-stats-resources boolean
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Include SCTP filter admit-deny statistics in accounting
configure application-assurance group number partition number statistics aa-admit-deny sctp-filter-stats boolean
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Include session filter admit-deny statistics in accounting
configure application-assurance group number partition number statistics aa-admit-deny session-filter-stats boolean
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Include TCP validate admit-deny statistics in accounting
configure application-assurance group number partition number statistics aa-admit-deny tcp-validate-stats boolean
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the aa-app-group context
configure application-assurance group number partition number statistics aa-app-group
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Accounting policy ID
configure application-assurance group number partition number statistics aa-app-group accounting-policy reference
configure log accounting-policy number
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Collect statistics
configure application-assurance group number partition number statistics aa-app-group collect-stats boolean
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the aa-application context
configure application-assurance group number partition number statistics aa-application
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Accounting policy ID
configure application-assurance group number partition number statistics aa-application accounting-policy reference
configure log accounting-policy number
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Collect statistics
configure application-assurance group number partition number statistics aa-application collect-stats boolean
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the aa-partition context
configure application-assurance group number partition number statistics aa-partition
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Accounting policy
configure application-assurance group number partition number statistics aa-partition accounting-policy reference
configure log accounting-policy number
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Collect statistics
configure application-assurance group number partition number statistics aa-partition collect-stats boolean
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Collect tethering statistics
configure application-assurance group number partition number statistics aa-partition tethering-stats boolean
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Collect traffic type statistics
configure application-assurance group number partition number statistics aa-partition traffic-type-stats boolean
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the aa-protocol context
configure application-assurance group number partition number statistics aa-protocol
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Accounting policy ID
configure application-assurance group number partition number statistics aa-protocol accounting-policy reference
configure log accounting-policy number
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of protocol statistics
configure application-assurance group number partition number statistics aa-protocol admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Collect statistics
configure application-assurance group number partition number statistics aa-protocol collect-stats boolean
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the aa-sub context
configure application-assurance group number partition number statistics aa-sub
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Accounting policy ID
configure application-assurance group number partition number statistics aa-sub accounting-policy reference
configure log accounting-policy number
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Method of statistics export to be used
configure application-assurance group number partition number statistics aa-sub aggregate-stats-export-using keyword
accounting-policy, radius-accounting-policy
2
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the app-group list instance
configure application-assurance group number partition number statistics aa-sub app-group reference
Commands in this context configure accounting and statistics collection parameters for AA application groups for a specific AA group/partition.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Application group name
configure application-assurance group number partition number statistics aa-sub app-group reference
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Method used to export statistics
configure application-assurance group number partition number statistics aa-sub app-group reference export-using keyword
accounting-policy, radius-accounting-policy
2
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the application list instance
configure application-assurance group number partition number statistics aa-sub application reference
Commands in this context configure the AA subscriber accounting statistics for the export of AA applications for an AA group/partition.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Application name
configure application-assurance group number partition number statistics aa-sub application reference
configure application-assurance group number partition number policy application string
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Method used to export statistics
configure application-assurance group number partition number statistics aa-sub application reference export-using keyword
accounting-policy, radius-accounting-policy
2
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the charging-group list instance
configure application-assurance group number partition number statistics aa-sub charging-group reference
Commands in this context configure AA subscriber accounting statistics for the export of AA charging groups of an AA group/partition.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Charging group name
configure application-assurance group number partition number statistics aa-sub charging-group reference
This command specifies the AA charging group to be included in the exported accounting records.
configure application-assurance group number partition number policy charging-group string
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Method used to export statistics
configure application-assurance group number partition number statistics aa-sub charging-group reference export-using keyword
accounting-policy, radius-accounting-policy
2
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Collect statistics
configure application-assurance group number partition number statistics aa-sub collect-stats boolean
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Exclude TCP retransmission and error statistics
configure application-assurance group number partition number statistics aa-sub exclude-tcp-retrans boolean
When configured to true, TCP errors and retransmission packets are not counted for the purpose of content-based billing. Note: This command is only applicable to EPC.This setting has no impact on app/app-group aggregate AA stats.
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Collect maximum throughput statistics
configure application-assurance group number partition number statistics aa-sub max-throughput-stats boolean
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the protocol list instance
configure application-assurance group number partition number statistics aa-sub protocol string
Commands in this context configure AA subscriber accounting statistics for the export of aa-sub protocols of an AA group/partition.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AA protocol name
configure application-assurance group number partition number statistics aa-sub protocol string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Method used to export statistics
configure application-assurance group number partition number statistics aa-sub protocol string export-using keyword
accounting-policy, radius-accounting-policy
2
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
RADIUS accounting policy name
configure application-assurance group number partition number statistics aa-sub radius-accounting-policy reference
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Collect usage monitoring statistics
configure application-assurance group number partition number statistics aa-sub usage-monitoring boolean
When configured to true, this command allows the system to activate Gx usage monitoring at AA group/partition level, if enough usage monitoring resources exist for all existing subs.
When configured to false, this command silently removes all monitoring instances (no PCRF notifications) for AA subscribers and all subsequent AA Gx usage monitoring messages are ignored.
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the aa-sub-study list instance
configure application-assurance group number partition number statistics aa-sub-study keyword
Commands in this context configure accounting and statistics collection parameters per AA special study subscribers.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Statistic type that the study is using
configure application-assurance group number partition number statistics aa-sub-study keyword
protocol, application
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the aa-sub context
configure application-assurance group number partition number statistics aa-sub-study keyword aa-sub
Commands in this context add an existing subscriber identification to a group of special study subscribers.
Identifying a group of special study subscribers allows statistics and accounting records for those subscribers to be collected for protocols and applications through Application Assurance. When adding a subscriber to the special study group, accounting records and statistics generation commence immediately. When removing a subscriber from the group, special study statistics and accounting records for that subscriber in the current interval are lost.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Add a list entry for esm
configure application-assurance group number partition number statistics aa-sub-study keyword aa-sub esm string
Commands in this context configure the ESM fields.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
ESM subscriber name
configure application-assurance group number partition number statistics aa-sub-study keyword aa-sub esm string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Add a list entry for esm-mac
configure application-assurance group number partition number statistics aa-sub-study keyword aa-sub esm-mac string
Commands in this context configure the ESM MAC fields.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
ESM MAC subscriber name
configure application-assurance group number partition number statistics aa-sub-study keyword aa-sub esm-mac string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Add a list entry for sap
configure application-assurance group number partition number statistics aa-sub-study keyword aa-sub sap string
Commands in this context configure the Service Access Point (SAP) for the purpose of enabling special study statistics.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AA subscriber SAP ID
configure application-assurance group number partition number statistics aa-sub-study keyword aa-sub sap string
1 to 45
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Add a list entry for spoke-sdp
configure application-assurance group number partition number statistics aa-sub-study keyword aa-sub spoke-sdp string
Commands in this context specify the spoke SDP ID and VC ID for the purpose of including the subscriber into AA special study statistics.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Spoke SDP ID for an AA subscriber
configure application-assurance group number partition number statistics aa-sub-study keyword aa-sub spoke-sdp string
3 to 16
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Add a list entry for transit
configure application-assurance group number partition number statistics aa-sub-study keyword aa-sub transit string
Commands in the context specify an existing transit subscriber to be included in AA sub special study statistics.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Transit subscriber name
configure application-assurance group number partition number statistics aa-sub-study keyword aa-sub transit string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Accounting policy ID
configure application-assurance group number partition number statistics aa-sub-study keyword accounting-policy reference
configure log accounting-policy number
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Collect statistics
configure application-assurance group number partition number statistics aa-sub-study keyword collect-stats boolean
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the tcp-validate list instance
configure application-assurance group number partition number tcp-validate string
Commands in this context configure a TCP validation policy.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
TCP validation policy name
configure application-assurance group number partition number tcp-validate string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number partition number tcp-validate string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the log context
configure application-assurance group number partition number tcp-validate string log
Commands in this context enable event logging of traffic dropped by TCP validation.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable logging of all dropped TCP packets
configure application-assurance group number partition number tcp-validate string log all boolean
When configured to true, all dropped TCP packets are logged, including the following:
An event log must also be configured to enable logging of all dropped packets.
When configured to false, discards related to the described cases are not captured in any event log.
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Event log name
configure application-assurance group number partition number tcp-validate string log event-log reference
configure application-assurance group number partition number event-log string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable strict checking of TCP traffic
configure application-assurance group number partition number tcp-validate string strict boolean
When configured to true, the command specifies whether enforcement of TCP sequence and acknowledgment numbers are applied. If a packet does not meet the expected sequence or acknowledgment number, it is dropped. This command should only be enabled if the expected bit error rate or packet loss is low.
For example, if acknowledgments are lost before being detected by AA, the server timeouts are triggered and retransmissions occur. If strict is enabled, these retransmissions resemble a reply attack and are dropped by AA.
When configured to false, the command removes the TCP sequence and acknowledgment number enforcement.
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the tethering-detection context
configure application-assurance group number partition number tethering-detection
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of tethering detection
configure application-assurance group number partition number tethering-detection admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the single-device context
configure application-assurance group number partition number tethering-detection single-device
Commands in this context configure the single-device fields and expected TTL values for flow-level tethering detection.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Add a list entry for expected-ttl
configure application-assurance group number partition number tethering-detection single-device expected-ttl number
Commands in this context configure the TTL values for single-device tethering detection.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Expected TTL traffic value from host devices
configure application-assurance group number partition number tethering-detection single-device expected-ttl number
1 to 255
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the threshold-crossing-alert context
configure application-assurance group number partition number threshold-crossing-alert
Commands in this context configure the generation of threshold crossing alerts (TCAs).
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the criteria list instance
configure application-assurance group number partition number threshold-crossing-alert criteria keyword direction keyword
Commands in this context configure the TCA criteria for the partition.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Statistics TCA criteria ID
configure application-assurance group number partition number threshold-crossing-alert criteria keyword direction keyword
error-drop, fragment-drop-out-of-order, fragment-drop-all, overload-drop, gtp-sanity-drop
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Direction of traffic for the criteria statistics TCA
configure application-assurance group number partition number threshold-crossing-alert criteria keyword direction keyword
from-sub, to-sub
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
High watermark threshold
configure application-assurance group number partition number threshold-crossing-alert criteria keyword direction keyword high-watermark number
1 to 4294967295
4294967295
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Low watermark threshold
configure application-assurance group number partition number threshold-crossing-alert criteria keyword direction keyword low-watermark number
0 to 4294967294
0
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the gtp-filter list instance
configure application-assurance group number partition number threshold-crossing-alert gtp-filter reference criteria keyword direction keyword
Commands in this context configure TCA generation for a GTP filter.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
GTP filter name for TCA generation
configure application-assurance group number partition number threshold-crossing-alert gtp-filter reference criteria keyword direction keyword
configure application-assurance group number partition number gtp gtp-filter string
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Criteria ID for GTP filter TCA
configure application-assurance group number partition number threshold-crossing-alert gtp-filter reference criteria keyword direction keyword
max-payload-length, message-type-default-action, header-sanity, message-type-gtpv2-default-action, imsi-apn-filter-default-action, validate-gtp-tunnels, validate-sequence-number, validate-src-ip-addr, missing-mandatory-ie, gtp-in-gtp, gtp-tunnel-database-full, gtp-tunnel-endpoint-limit
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Direction of traffic for the GTP filter TCA
configure application-assurance group number partition number threshold-crossing-alert gtp-filter reference criteria keyword direction keyword
from-sub, to-sub
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
High watermark threshold
configure application-assurance group number partition number threshold-crossing-alert gtp-filter reference criteria keyword direction keyword high-watermark number
1 to 4294967295
4294967295
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Low watermark threshold
configure application-assurance group number partition number threshold-crossing-alert gtp-filter reference criteria keyword direction keyword low-watermark number
0 to 4294967294
0
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the gtp-filter-entry list instance
configure application-assurance group number partition number threshold-crossing-alert gtp-filter-entry reference entry-id number direction keyword
Commands in this context configure the AA GTP filter entry TCA fields.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AA GTP filter name for TCA configuration
configure application-assurance group number partition number threshold-crossing-alert gtp-filter-entry reference entry-id number direction keyword
configure application-assurance group number partition number gtp gtp-filter string
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Entry ID
configure application-assurance group number partition number threshold-crossing-alert gtp-filter-entry reference entry-id number direction keyword
This command configures the identifier for the statistics TCA GTP filter V1 message type entry, V2 message type entry, or imsi-apn filter entry.
0 to 4294967295
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Traffic direction for GTP filter entry TCA
configure application-assurance group number partition number threshold-crossing-alert gtp-filter-entry reference entry-id number direction keyword
from-sub, to-sub
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
High watermark threshold
configure application-assurance group number partition number threshold-crossing-alert gtp-filter-entry reference entry-id number direction keyword high-watermark number
1 to 4294967295
4294967295
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Low watermark threshold
configure application-assurance group number partition number threshold-crossing-alert gtp-filter-entry reference entry-id number direction keyword low-watermark number
0 to 4294967294
0
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the policer list instance
configure application-assurance group number partition number threshold-crossing-alert policer string direction keyword
Commands in this context configure a TCA for the counter capturing drops or admit events.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Policer name for TCA generation
configure application-assurance group number partition number threshold-crossing-alert policer string direction keyword
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Direction of traffic for the policer TCA
configure application-assurance group number partition number threshold-crossing-alert policer string direction keyword
from-sub, to-sub
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
High watermark threshold
configure application-assurance group number partition number threshold-crossing-alert policer string direction keyword high-watermark number
1 to 4294967295
4294967295
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Low watermark threshold
configure application-assurance group number partition number threshold-crossing-alert policer string direction keyword low-watermark number
0 to 4294967294
0
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the sctp-filter list instance
configure application-assurance group number partition number threshold-crossing-alert sctp-filter reference criteria keyword direction keyword
Commands in this context configure TCA generation for an SCTP filter.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
SCTP filter name for TCA generation
configure application-assurance group number partition number threshold-crossing-alert sctp-filter reference criteria keyword direction keyword
configure application-assurance group number partition number sctp-filter string
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Criteria ID for SCTP filter TCA
configure application-assurance group number partition number threshold-crossing-alert sctp-filter reference criteria keyword direction keyword
ppid-default-action, packet-sanity, ppid-range
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Direction of traffic for SCTP filter TCA
configure application-assurance group number partition number threshold-crossing-alert sctp-filter reference criteria keyword direction keyword
from-sub, to-sub
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
High watermark threshold
configure application-assurance group number partition number threshold-crossing-alert sctp-filter reference criteria keyword direction keyword high-watermark number
1 to 4294967295
4294967295
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Low watermark threshold
configure application-assurance group number partition number threshold-crossing-alert sctp-filter reference criteria keyword direction keyword low-watermark number
0 to 4294967294
0
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the sctp-filter-entry list instance
configure application-assurance group number partition number threshold-crossing-alert sctp-filter-entry reference entry-id reference direction keyword
Commands in this context configure the AA SCTP filter PPID entry TCA fields.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AA SCTP filter name for TCA configuration
configure application-assurance group number partition number threshold-crossing-alert sctp-filter-entry reference entry-id reference direction keyword
configure application-assurance group number partition number sctp-filter string
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
ID for SCTP filter entry TCA
configure application-assurance group number partition number threshold-crossing-alert sctp-filter-entry reference entry-id reference direction keyword
configure application-assurance group number partition number sctp-filter string ppid entry number
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Direction of traffic for TCA configuration
configure application-assurance group number partition number threshold-crossing-alert sctp-filter-entry reference entry-id reference direction keyword
from-sub, to-sub
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
High watermark threshold
configure application-assurance group number partition number threshold-crossing-alert sctp-filter-entry reference entry-id reference direction keyword high-watermark number
1 to 4294967295
4294967295
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Low watermark threshold
configure application-assurance group number partition number threshold-crossing-alert sctp-filter-entry reference entry-id reference direction keyword low-watermark number
0 to 4294967294
0
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the session-filter list instance
configure application-assurance group number partition number threshold-crossing-alert session-filter reference criteria keyword direction keyword
Commands in this context configure TCA generation for a session filter.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AA session filter name for TCA configuration
configure application-assurance group number partition number threshold-crossing-alert session-filter reference criteria keyword direction keyword
configure application-assurance group number partition number session-filter string
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
ID for session filter entry TCA
configure application-assurance group number partition number threshold-crossing-alert session-filter reference criteria keyword direction keyword
default-action
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Direction of traffic for TCA configuration
configure application-assurance group number partition number threshold-crossing-alert session-filter reference criteria keyword direction keyword
from-sub, to-sub
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
High watermark threshold
configure application-assurance group number partition number threshold-crossing-alert session-filter reference criteria keyword direction keyword high-watermark number
1 to 4294967295
4294967295
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Low watermark threshold
configure application-assurance group number partition number threshold-crossing-alert session-filter reference criteria keyword direction keyword low-watermark number
0 to 4294967294
0
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the session-filter-entry list instance
configure application-assurance group number partition number threshold-crossing-alert session-filter-entry reference entry-id reference direction keyword
Commands in this context configure the AA session filter entry TCA fields for the partition.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AA session filter name for TCA configuration
configure application-assurance group number partition number threshold-crossing-alert session-filter-entry reference entry-id reference direction keyword
configure application-assurance group number partition number session-filter string
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
ID for session filter entry TCA
configure application-assurance group number partition number threshold-crossing-alert session-filter-entry reference entry-id reference direction keyword
configure application-assurance group number partition number session-filter string entry number
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Direction of traffic for TCA configuration
configure application-assurance group number partition number threshold-crossing-alert session-filter-entry reference entry-id reference direction keyword
from-sub, to-sub
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
High watermark threshold
configure application-assurance group number partition number threshold-crossing-alert session-filter-entry reference entry-id reference direction keyword high-watermark number
1 to 4294967295
4294967295
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Low watermark threshold
configure application-assurance group number partition number threshold-crossing-alert session-filter-entry reference entry-id reference direction keyword low-watermark number
0 to 4294967294
0
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the tcp-validate list instance
configure application-assurance group number partition number threshold-crossing-alert tcp-validate reference direction keyword
Commands in this context configure TCP validation policy TCA fields for the partition.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AA TCP validate name for configuration
configure application-assurance group number partition number threshold-crossing-alert tcp-validate reference direction keyword
configure application-assurance group number partition number tcp-validate string
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Direction of traffic for TCA configuration
configure application-assurance group number partition number threshold-crossing-alert tcp-validate reference direction keyword
from-sub, to-sub
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
High watermark threshold
configure application-assurance group number partition number threshold-crossing-alert tcp-validate reference direction keyword high-watermark number
1 to 4294967295
4294967295
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Low watermark threshold
configure application-assurance group number partition number threshold-crossing-alert tcp-validate reference direction keyword low-watermark number
0 to 4294967294
0
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the transit-ip-policy list instance
configure application-assurance group number partition number transit-ip-policy number
Commands in this context define a transit AA subscriber IP policy. Transit AA subscribers are managed by the system through the use of this policy assigned to services, which determines how transit subs are created and removed for that service.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP transit policy ID
configure application-assurance group number partition number transit-ip-policy number
1 to 65535
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Default AA application profile
configure application-assurance group number partition number transit-ip-policy number default-app-profile reference
configure application-assurance group number partition number policy app-profile string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number partition number transit-ip-policy number description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Detect transit subscribers based on IP address
configure application-assurance group number partition number transit-ip-policy number detect-seen-ip boolean
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the dhcp context
configure application-assurance group number partition number transit-ip-policy number dhcp
Commands in this context enable dynamic DHCP-based management of transit aa-subs for the transit IP policy. Dynamic DHCP-based management and other types of management of transit subs for a transit IP policy are mutually exclusive.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state for learning DHCP dynamic transits
configure application-assurance group number partition number transit-ip-policy number dhcp admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the diameter context
configure application-assurance group number partition number transit-ip-policy number diameter
Commands in this context configure dynamic Diameter-based management of transit AA subs for the transit IP policy. This is mutually exclusive to other types of management of transit subs for a given transit IP policy.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state for Diameter dynamic transits
configure application-assurance group number partition number transit-ip-policy number diameter admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Diameter application policy name for IP transit policy
configure application-assurance group number partition number transit-ip-policy number diameter application-policy reference
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Length of the AA transit IP policy IPv6 address prefix
configure application-assurance group number partition number transit-ip-policy number ipv6-address-prefix-length number
32 to 64
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the radius context
configure application-assurance group number partition number transit-ip-policy number radius
Commands in this context enable dynamic RADIUS-based management of transit aa-subs for the transit IP policy. This is mutually exclusive to other types of management of transit subs for a given transit IP policy.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of learning RADIUS dynamic transit
configure application-assurance group number partition number transit-ip-policy number radius admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
RADIUS authentication policy
configure application-assurance group number partition number transit-ip-policy number radius authentication-policy reference
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
RADIUS accounting policy to enable seen-IP notification
configure application-assurance group number partition number transit-ip-policy number radius seen-ip-radius-acct-policy reference
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the static-aa-sub list instance
configure application-assurance group number partition number transit-ip-policy number static-aa-sub string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Static transit subscriber name
configure application-assurance group number partition number transit-ip-policy number static-aa-sub string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Application profile name
configure application-assurance group number partition number transit-ip-policy number static-aa-sub string app-profile reference
configure application-assurance group number partition number policy app-profile string
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Add a list entry for ip
configure application-assurance group number partition number transit-ip-policy number static-aa-sub string ip (ipv4-unicast-address | ipv6-prefix)
Commands in this context configure the IP address for a static transit aa-sub.
32
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
IP address for an AA static transit subscriber
configure application-assurance group number partition number transit-ip-policy number static-aa-sub string ip (ipv4-unicast-address | ipv6-prefix)
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Subscriber identification policy
configure application-assurance group number partition number transit-ip-policy number sub-ident-policy reference
This command defines the subscriber identification policy for the transit IP policy that will be associated with a SAP. The subscriber identification policy must be defined prior to associating the profile with a SAP in the configure subscriber-mgmt sub-ident-policy context. Subscribers are managed by the system through the use of subscriber identification strings. A subscriber identification string uniquely identifies a subscriber. For static hosts, the subscriber identification string is explicitly defined with each static subscriber host.
For dynamic hosts, the subscriber identification string must be derived from the DHCP ACK message sent to the subscriber host. The default value for the string is the content of Option 82 CIRCUIT-ID and REMOTE-ID fields interpreted as an octet string. As an option, the DHCP ACK message may be processed by a subscriber identification policy which has the capability to parse the message into an alternative ASCII or octet string value.
When multiple hosts on the same port are associated with the same subscriber identification string, they are considered to be host members of the same subscriber. A subscriber identification policy can also be used for identifying dynamic transit subscriber names.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the transit-auto-create context
configure application-assurance group number partition number transit-ip-policy number transit-auto-create
Commands in this context enable the seen-IP auto creation of transit subscribers using the transit IP policy name and subscriber IP address as the aa-sub name. The default app-profile configured against the transit IP policy is applied to these subscribers.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of the automatic dynamic transits
configure application-assurance group number partition number transit-ip-policy number transit-auto-create admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Monitor inactivity on auto-created transit subscribers
configure application-assurance group number partition number transit-ip-policy number transit-auto-create inactivity-monitor boolean
When configured to true, this command enables the auto-removal of inactive transit subscribers. Periodically, AA removes any inactive auto-created subscribers. An inactive subscriber is defined as having no active flows in the last period.
When configured to false, this command disables the auto-removal of inactive transit subscribers.
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the transit-prefix-policy list instance
configure application-assurance group number partition number transit-prefix-policy number
Commands in this context define a transit AA subscriber prefix policy. Transit AA subscribers are managed by the system through the use of this policy assigned to services, which determines how transit subscribers are created and removed for that service.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Transit prefix policy ID
configure application-assurance group number partition number transit-prefix-policy number
1 to 65535
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number partition number transit-prefix-policy number description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the entry list instance
configure application-assurance group number partition number transit-prefix-policy number entry number
Commands in this context configure the index to a specific entry of a transit prefix policy.
4095
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
ID for a transit prefix policy entry
configure application-assurance group number partition number transit-prefix-policy number entry number
1 to 4294967295
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Name of the transit prefix AA subscriber
configure application-assurance group number partition number transit-prefix-policy number entry number aa-sub reference
configure application-assurance group number partition number transit-prefix-policy number static-aa-sub string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the match context
configure application-assurance group number partition number transit-prefix-policy number entry number match
Commands in this context configure transit prefix policy entry match criteria.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AA subscriber IP address prefix
configure application-assurance group number partition number transit-prefix-policy number entry number match aa-sub-ip (ipv4-prefix | ipv6-prefix)
This command configures a transit prefix subscriber IP address prefix. It is used when the site is on the local side, the same side of the system as the parent SAP. The local aa-sub-ip addresses represent the source IP in the from-SAP direction and destination IP in the to-SAP direction.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Network IP address prefix
configure application-assurance group number partition number transit-prefix-policy number entry number match network-ip (ipv4-prefix | ipv6-prefix)
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the static-aa-sub list instance
configure application-assurance group number partition number transit-prefix-policy number static-aa-sub string
4095
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Static transit subscriber name
configure application-assurance group number partition number transit-prefix-policy number static-aa-sub string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Application profile name
configure application-assurance group number partition number transit-prefix-policy number static-aa-sub string app-profile reference
configure application-assurance group number partition number policy app-profile string
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Set transit subscriber as remote
configure application-assurance group number partition number transit-prefix-policy number static-aa-sub string is-remote boolean
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the wap1x context
configure application-assurance group number partition number wap1x
Commands in this context configure the Wireless Application Protocol (WAP) 1.X.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of WAP1x detection
configure application-assurance group number partition number wap1x admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the policer context
Commands in this context create application assurance policer profiles of a specified type. Policers can be bandwidth or flow-limiting and can have a granularity of system scope (limits traffic entering AA ISA for all or a subset of AA subscribers) or a subscriber scope (limits apply to each AA subscriber traffic).
The policer type and granularity can only be configured during creation. They cannot be modified. The policer profile must be removed from all AQPs to be removed. Changes to policer profile parameters take effect immediately for policers instantiated as a result of AQP actions using this profile.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the anl-bandwidth-policer list instance
configure application-assurance group number policer anl-bandwidth-policer string
Commands in this context configure the AA ANL policer.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Policer name
configure application-assurance group number policer anl-bandwidth-policer string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Action for packets violating configured policer rate
configure application-assurance group number policer anl-bandwidth-policer string action keyword
This command configures the action to be performed by single-bucket bandwidth policers for non-conformant traffic.
Dual bucket bandwidth policers cannot have their action configured and always mark traffic below CIR as in-profile, between CIR and PIR as out-of-profile, and drop traffic above PIR. Flow policers always discard non-conformant traffic.
When multiple application assurance policers are configured against a single flow (including policers at both subscriber and system), the flow/packet is dropped if one of the policers requires the packet to be discarded. This occurs regardless of the action of the other policers.
permit-deny
permit-deny, priority-mark
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the adaptation-rule context
Commands in this context configure the AA policer adaptation rule fields and define the method used by the system to derive the operational CIR and PIR values when the queue is provisioned. For the CIR and PIR values individually, the system attempts to find the best operational rate depending on the defined option. To change the CIR adaptation rule only, the current PIR rule must be part of the command executed.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Peak information rate value for the adaptation rule
configure application-assurance group number policer anl-bandwidth-policer string adaptation-rule pir keyword
This command configures the adaptation rule to be used while computing the operational PIR value. The adaptation rule specifies the rules to compute the operational values while maintaining minimum offset.
closest
max, min, closest
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number policer anl-bandwidth-policer string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
ANL bandwidth policer maximum burst size
configure application-assurance group number policer anl-bandwidth-policer string mbs number
This command configures the maximum burst size (MBS) for the policer. Nokia recommends configuring MBS larger than twice the MTU for the traffic handled by the policer to allow for some burstiness of the traffic. MBS is configurable for single-bucket, dual-bucket bandwidth, and flow setup rate policers only.
0 to 131071
0
kilobytes
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Rate used by Access-Network-Location policers
configure application-assurance group number policer anl-bandwidth-policer string rate-percentage number
This command configures the stage 1 congestion percentage used by Access-Network-Location (ANL) policers. Because ANL total bandwidth is dynamically measured and estimated by AA, this command allows the operator to configure the ratio of that measured bandwidth to be used by the ANL policer as the policer rate.
No limiting is performed if not specified.
0 to 200
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Rate used by Access-Network-Location policers
configure application-assurance group number policer anl-bandwidth-policer string rate-percentage-stage-2 number
This command configures the stage 2 congestion percentage rate used by Access-Network-Location (ANL) policers. Because ANL stage2 total bandwidth is dynamically measured and estimated by AA, this command allows the operator to configure the ratio of that measured bandwidth to be used by the ANL stage2 policer as the policer rate.
When unconfigured, limiting is not performed.
0 to 200
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the dual-bucket-bandwidth-policer list instance
configure application-assurance group number policer dual-bucket-bandwidth-policer string
Commands in this context configure the dual-bucket bandwidth policer.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Policer name
configure application-assurance group number policer dual-bucket-bandwidth-policer string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the adaptation-rule context
Commands in this context configure the AA policer adaptation rule fields and define the method used by the system to derive the operational CIR and PIR values when the queue is provisioned. For the CIR and PIR values individually, the system attempts to find the best operational rate depending on the defined option. To change the CIR adaptation rule only, the current PIR rule must be part of the command executed.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Committed information rate value for adaptation rule
configure application-assurance group number policer dual-bucket-bandwidth-policer string adaptation-rule cir keyword
This command configures the CIR for the dual-bucket-bandwidth-policer adaptation rule policer. Nokia recommends configuring CIR larger than twice the maximum MTU for the traffic handled by the policer to allow for some burstiness of the traffic. The CIR is configurable for dual-bucket bandwidth policers only.
closest
max, min, closest
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Peak information rate value for the adaptation rule
configure application-assurance group number policer dual-bucket-bandwidth-policer string adaptation-rule pir keyword
This command configures the adaptation rule to be used while computing the operational PIR value. The adaptation rule specifies the rules to compute the operational values while maintaining minimum offset.
closest
max, min, closest
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Committed burst size when in congested state
configure application-assurance group number policer dual-bucket-bandwidth-policer string cbs number
This command configures the committed burst size (CBS) for a policer. Nokia recommends that CBS is configured larger than twice the maximum MTU for the traffic handled by the policer to allow for some burstiness of the traffic. CBS is configurable for dual-bucket bandwidth policers only.
0 to 131071
0
kilobytes
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Committed information rate value for the policer
configure application-assurance group number policer dual-bucket-bandwidth-policer string cir (number | keyword)
This command configures the CIR for the dual-bucket-bandwidth-policer policer. Nokia recommends that the CIR is configured larger than twice the maximum MTU for the traffic handled by the policer to allow for some burstiness of the traffic. The CIR is configurable for dual-bucket bandwidth policers only.
0 to 100000000
0
kilobps
max
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the congestion-override context
Commands in this context configure the congestion bandwidth policer override rates.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Committed burst size in a congested stage 2 state
configure application-assurance group number policer dual-bucket-bandwidth-policer string congestion-override cbs number
This command configures the committed burst size for a policer. The configured CBS should be larger than twice the maximum MTU for the traffic handled by the policer to allow for some burstiness of the traffic. CBS is configurable for dual-bucket bandwidth policers only.
0 to 131071
0
kilobytes
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Committed information rate value for the policer override
configure application-assurance group number policer dual-bucket-bandwidth-policer string congestion-override cir (number | keyword)
This command configures the CIR for the dual-bucket bandwidth policer congestion override. Nokia recommends that the CIR is configured larger than twice the maximum MTU for the traffic handled by the policer to allow for some burstiness of the traffic. The CIR is configurable for dual-bucket bandwidth policers only.
0 to 100000000
0
kilobps
max
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Maximum burst size when in a congested state
configure application-assurance group number policer dual-bucket-bandwidth-policer string congestion-override mbs number
This command configures the maximum burst size (MBS) for the policer. Nokia recommends configuring MBS larger than twice the MTU for the traffic handled by the policer to allow for some burstiness of the traffic. MBS is configurable for single-bucket, dual-bucket bandwidth, and flow setup rate policers only.
0 to 131071
0
kilobytes
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Peak information rate value for the congestion override
configure application-assurance group number policer dual-bucket-bandwidth-policer string congestion-override pir (number | keyword)
1 to 100000000
max
kilobps
max
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the congestion-override-stage-2 context
This command enables the context to configure per-subscriber stage 2 congestion bandwidth policer override rates.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Committed burst size in a congested stage 2 state
configure application-assurance group number policer dual-bucket-bandwidth-policer string congestion-override-stage-2 cbs number
This command configures the committed burst size for a policer. The configured CBS should be larger than twice the maximum MTU for the traffic handled by the policer to allow for some burstiness of the traffic. CBS is configurable for dual-bucket bandwidth policers only.
0 to 131071
0
kilobytes
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Committed information rate value for the policer override
configure application-assurance group number policer dual-bucket-bandwidth-policer string congestion-override-stage-2 cir (number | keyword)
This command configures the CIR for the dual-bucket bandwidth policer congestion override. Nokia recommends that the CIR is configured larger than twice the maximum MTU for the traffic handled by the policer to allow for some burstiness of the traffic. The CIR is configurable for dual-bucket bandwidth policers only.
0 to 100000000
0
kilobps
max
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Maximum burst size when in a congested state
configure application-assurance group number policer dual-bucket-bandwidth-policer string congestion-override-stage-2 mbs number
This command configures the maximum burst size (MBS) for the policer. Nokia recommends configuring MBS larger than twice the MTU for the traffic handled by the policer to allow for some burstiness of the traffic. MBS is configurable for single-bucket, dual-bucket bandwidth, and flow setup rate policers only.
0 to 131071
0
kilobytes
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Peak information rate value for the congestion override
configure application-assurance group number policer dual-bucket-bandwidth-policer string congestion-override-stage-2 pir (number | keyword)
1 to 100000000
max
kilobps
max
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number policer dual-bucket-bandwidth-policer string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Bandwidth policer maximum burst size
configure application-assurance group number policer dual-bucket-bandwidth-policer string mbs number
This command configures the maximum burst size (MBS) for the policer. Nokia recommends configuring MBS larger than twice the MTU for the traffic handled by the policer to allow for some burstiness of the traffic. MBS is configurable for single-bucket, dual-bucket bandwidth, and flow setup rate policers only.
0 to 131071
0
kilobytes
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Peak information rate value for the bandwidth policer
configure application-assurance group number policer dual-bucket-bandwidth-policer string pir (number | keyword)
1 to 100000000
max
kilobps
max
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the time-of-day-override list instance
configure application-assurance group number policer dual-bucket-bandwidth-policer string time-of-day-override number
Commands in this context configure the time of day override policy for a given policer. Rate/mbs/cbs/flow-rate/flow-count configured in each override-id will override the default policer values at the specified time of day configured in the override.
8
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
ID for time of day override
configure application-assurance group number policer dual-bucket-bandwidth-policer string time-of-day-override number
1 to 255
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of this time of day policer
configure application-assurance group number policer dual-bucket-bandwidth-policer string time-of-day-override number admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Committed burst size for time of day override policer
configure application-assurance group number policer dual-bucket-bandwidth-policer string time-of-day-override number cbs number
This command configures the committed burst size (CBS) for a policer. Nokia recommends configuring CBS larger than twice the maximum MTU for the traffic handled by the policer to allow for some burstiness of the traffic. CBS is configurable for dual-bucket bandwidth policers only.
0 to 131071
0
kilobytes
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Committed information rate for time of day override
configure application-assurance group number policer dual-bucket-bandwidth-policer string time-of-day-override number cir (number | keyword)
This command configures the committed information rate (CIR) for the dual-bucket-bandwidth-policer policer time of day override. Nokia recommends that the CIR is configured larger than twice the maximum MTU for the traffic handled by the policer to allow for some burstiness of the traffic. The CIR is configurable for dual-bucket bandwidth policers only.
0 to 100000000
0
kilobps
max
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number policer dual-bucket-bandwidth-policer string time-of-day-override number description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Maximum burst size for the policer time of day override
configure application-assurance group number policer dual-bucket-bandwidth-policer string time-of-day-override number mbs number
This command configures the maximum burst size (MBS) for the policer. Nokia recommends that MBS is configured larger than twice the MTU for the traffic handled by the policer to allow for some burstiness of the traffic. MBS is configurable for single-bucket, dual-bucket bandwidth, and flow setup rate policers only.
0 to 131071
0
kilobytes
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Peak information rate value for the time of day override
configure application-assurance group number policer dual-bucket-bandwidth-policer string time-of-day-override number pir (number | keyword)
1 to 100000000
max
kilobps
max
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the time-range context
configure application-assurance group number policer dual-bucket-bandwidth-policer string time-of-day-override number time-range
Commands in this context configure the days of the week policer override is enabled as well as the time policer override starts and ends. When using a daily override the operator can select which days during the week from Sunday to Saturday it is applicable along with the start/end hour/min time range repeated over these days.When using a weekly override the operator can select between which days in the week the policy start up to the hours/min for both start day and end day.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the daily context
configure application-assurance group number policer dual-bucket-bandwidth-policer string time-of-day-override number time-range daily
Commands in this context configure the daily start and end times for policer override.
The following elements are part of a choice: daily or weekly.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable policer override on every day
configure application-assurance group number policer dual-bucket-bandwidth-policer string time-of-day-override number time-range daily all-days
This element is the default part of a choice.
The following elements are part of a choice: all-days or on.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Daily end time
configure application-assurance group number policer dual-bucket-bandwidth-policer string time-of-day-override number time-range daily end string
This command configures the daily end time of the policer override.
The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.
3 to 5
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Policer override on selected days
configure application-assurance group number policer dual-bucket-bandwidth-policer string time-of-day-override number time-range daily on keyword
sunday, monday, tuesday, wednesday, thursday, friday, saturday
6
The following elements are part of a choice: all-days or on.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Daily start time
configure application-assurance group number policer dual-bucket-bandwidth-policer string time-of-day-override number time-range daily start string
This command configures the daily start time of the policer override.
The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.
3 to 5
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the weekly context
configure application-assurance group number policer dual-bucket-bandwidth-policer string time-of-day-override number time-range weekly
Commands in this context configure the weekly start and end times for policer override.
The following elements are part of a choice: daily or weekly.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the end context
configure application-assurance group number policer dual-bucket-bandwidth-policer string time-of-day-override number time-range weekly end
Commands in this context configure the weekly end time for policer override.When using a weekly override, the operator can select between which days in the week the policy ends up to the hours or minutes for both start of the day and end of the day.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Weekly end day
configure application-assurance group number policer dual-bucket-bandwidth-policer string time-of-day-override number time-range weekly end day keyword
sunday, monday, tuesday, wednesday, thursday, friday, saturday
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Weekly end time
configure application-assurance group number policer dual-bucket-bandwidth-policer string time-of-day-override number time-range weekly end time string
This command configures the weekly end time of the policer override.
The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.
3 to 5
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the start context
configure application-assurance group number policer dual-bucket-bandwidth-policer string time-of-day-override number time-range weekly start
Commands in this context configure the weekly start time for policer override.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Weekly start day
configure application-assurance group number policer dual-bucket-bandwidth-policer string time-of-day-override number time-range weekly start day keyword
sunday, monday, tuesday, wednesday, thursday, friday, saturday
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Weekly start time
configure application-assurance group number policer dual-bucket-bandwidth-policer string time-of-day-override number time-range weekly start time string
This command configures the weekly start time of the policer override.
The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.
3 to 5
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the flow-count-limit-policer list instance
configure application-assurance group number policer flow-count-limit-policer string
Commands in this context configure the AA flow count limit policer.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Policer name
configure application-assurance group number policer flow-count-limit-policer string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Action for packets violating configured policer rate
configure application-assurance group number policer flow-count-limit-policer string action keyword
This command configures the action to be performed by single-bucket bandwidth policers for non-conformant traffic.
Dual bucket bandwidth policers cannot have their action configured and always mark traffic below CIR as in-profile, between CIR and PIR as out-of-profile, and drop traffic above PIR. Flow policers always discard non-conformant traffic.
When multiple application assurance policers are configured against a single flow (including policers at both subscriber and system), the flow/packet is dropped if one of the policers requires the packet to be discarded. This occurs regardless of the action of the other policers.
permit-deny
permit-deny, priority-mark
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number policer flow-count-limit-policer string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Policer granularity
configure application-assurance group number policer flow-count-limit-policer string granularity keyword
system, subscriber
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Limit concurrent GTP flows
configure application-assurance group number policer flow-count-limit-policer string limit-gtp-flows boolean
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Peak flow count limit
configure application-assurance group number policer flow-count-limit-policer string peak-flow-count (number | keyword)
0 to 100000000
max
flows per second
max
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the time-of-day-override list instance
configure application-assurance group number policer flow-count-limit-policer string time-of-day-override number
Commands in this context configure the time of day override policy for a specific policer. Rate/mbs/cbs/flow-rate/flow-count configured in each override ID overrides the default policer values at the specified time of day configured in the override.
8
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
ID for time of day override
configure application-assurance group number policer flow-count-limit-policer string time-of-day-override number
1 to 255
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of this time of day policer
configure application-assurance group number policer flow-count-limit-policer string time-of-day-override number admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number policer flow-count-limit-policer string time-of-day-override number description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Peak flow count limit
configure application-assurance group number policer flow-count-limit-policer string time-of-day-override number peak-flow-count (number | keyword)
0 to 100000000
max
flows per second
max
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the time-range context
configure application-assurance group number policer flow-count-limit-policer string time-of-day-override number time-range
Commands in this context configure the days of the week policer override is enabled as well as the time policer override starts and ends. When using a daily override the operator can select which days during the week from Sunday to Saturday it is applicable along with the start/end hour/min time range repeated over these days.When using a weekly override the operator can select between which days in the week the policy start up to the hours/min for both start day and end day.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the daily context
configure application-assurance group number policer flow-count-limit-policer string time-of-day-override number time-range daily
Commands in this context configure the daily start and end times for policer override.
The following elements are part of a choice: daily or weekly.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable policer override on every day
configure application-assurance group number policer flow-count-limit-policer string time-of-day-override number time-range daily all-days
This element is the default part of a choice.
The following elements are part of a choice: all-days or on.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Daily end time
configure application-assurance group number policer flow-count-limit-policer string time-of-day-override number time-range daily end string
This command configures the daily end time of the policer override.
The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.
3 to 5
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Policer override on selected days
configure application-assurance group number policer flow-count-limit-policer string time-of-day-override number time-range daily on keyword
sunday, monday, tuesday, wednesday, thursday, friday, saturday
6
The following elements are part of a choice: all-days or on.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Daily start time
configure application-assurance group number policer flow-count-limit-policer string time-of-day-override number time-range daily start string
This command configures the daily start time of the policer override.
The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.
3 to 5
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the weekly context
configure application-assurance group number policer flow-count-limit-policer string time-of-day-override number time-range weekly
Commands in this context configure the weekly start and end times for policer override.
The following elements are part of a choice: daily or weekly.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the end context
configure application-assurance group number policer flow-count-limit-policer string time-of-day-override number time-range weekly end
Commands in this context configure the weekly end time for policer override.When using a weekly override, the operator can select between which days in the week the policy ends up to the hours or minutes for both start of the day and end of the day.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Weekly end day
configure application-assurance group number policer flow-count-limit-policer string time-of-day-override number time-range weekly end day keyword
sunday, monday, tuesday, wednesday, thursday, friday, saturday
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Weekly end time
configure application-assurance group number policer flow-count-limit-policer string time-of-day-override number time-range weekly end time string
This command configures the weekly end time of the policer override.
The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.
3 to 5
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the start context
configure application-assurance group number policer flow-count-limit-policer string time-of-day-override number time-range weekly start
Commands in this context configure the weekly start time for policer override.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Weekly start day
configure application-assurance group number policer flow-count-limit-policer string time-of-day-override number time-range weekly start day keyword
sunday, monday, tuesday, wednesday, thursday, friday, saturday
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Weekly start time
configure application-assurance group number policer flow-count-limit-policer string time-of-day-override number time-range weekly start time string
This command configures the weekly start time of the policer override.
The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.
3 to 5
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the flow-setup-rate-policer list instance
configure application-assurance group number policer flow-setup-rate-policer string
Commands in this context configure the flow setup rate policer.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Policer name
configure application-assurance group number policer flow-setup-rate-policer string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Action for packets violating configured policer rate
configure application-assurance group number policer flow-setup-rate-policer string action keyword
This command configures the action to be performed by single-bucket bandwidth policers for non-conformant traffic.
Dual bucket bandwidth policers cannot have their action configured and always mark traffic below CIR as in-profile, between CIR and PIR as out-of-profile, and drop traffic above PIR. Flow policers always discard non-conformant traffic.
When multiple application assurance policers are configured against a single flow (including policers at both subscriber and system), the flow/packet is dropped if one of the policers requires the packet to be discarded. This occurs regardless of the action of the other policers.
permit-deny
permit-deny, priority-mark
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the adaptation-rule context
Commands in this context configure the AA policer adaptation rule fields and define the method used by the system to derive the operational CIR and PIR values when the queue is provisioned. For the CIR and PIR values individually, the system attempts to find the best operational rate depending on the defined option. To change the CIR adaptation rule only, the current PIR rule must be part of the command executed.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Peak flow setup rate adaptation rule
configure application-assurance group number policer flow-setup-rate-policer string adaptation-rule peak-flow-setup-rate keyword
closest
max, min, closest
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number policer flow-setup-rate-policer string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Maximum flow setup rate burst size
configure application-assurance group number policer flow-setup-rate-policer string flow-setup-rate-burst-size number
0 to 131071
0
flows
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Policer granularity
configure application-assurance group number policer flow-setup-rate-policer string granularity keyword
system, subscriber
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Peak flow setup rate
configure application-assurance group number policer flow-setup-rate-policer string peak-flow-setup-rate (number | keyword)
1 to 100000000
max
flows per second
max
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the time-of-day-override list instance
configure application-assurance group number policer flow-setup-rate-policer string time-of-day-override number
Commands in this context configure the time of day override policy for a given policer. Rate/mbs/cbs/flow-rate/flow-count configured in each override-id will override the default policer values at the specified time of day configured in the override.
8
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
ID for time of day override
configure application-assurance group number policer flow-setup-rate-policer string time-of-day-override number
1 to 255
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of this time of day policer
configure application-assurance group number policer flow-setup-rate-policer string time-of-day-override number admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number policer flow-setup-rate-policer string time-of-day-override number description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Maximum flow setup rate burst size
configure application-assurance group number policer flow-setup-rate-policer string time-of-day-override number flow-setup-rate-burst-size number
0 to 131071
0
flows
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Peak flow setup rate
configure application-assurance group number policer flow-setup-rate-policer string time-of-day-override number peak-flow-setup-rate (number | keyword)
1 to 100000000
max
flows per second
max
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the time-range context
configure application-assurance group number policer flow-setup-rate-policer string time-of-day-override number time-range
Commands in this context configure the days of the week policer override is enabled as well as the time policer override starts and ends. When using a daily override the operator can select which days during the week from Sunday to Saturday it is applicable along with the start/end hour/min time range repeated over these days.When using a weekly override the operator can select between which days in the week the policy start up to the hours/min for both start day and end day.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the daily context
configure application-assurance group number policer flow-setup-rate-policer string time-of-day-override number time-range daily
Commands in this context configure the daily start and end times for policer override.
The following elements are part of a choice: daily or weekly.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable policer override on every day
configure application-assurance group number policer flow-setup-rate-policer string time-of-day-override number time-range daily all-days
This element is the default part of a choice.
The following elements are part of a choice: all-days or on.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Daily end time
configure application-assurance group number policer flow-setup-rate-policer string time-of-day-override number time-range daily end string
This command configures the daily end time of the policer override.
The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.
3 to 5
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Policer override on selected days
configure application-assurance group number policer flow-setup-rate-policer string time-of-day-override number time-range daily on keyword
sunday, monday, tuesday, wednesday, thursday, friday, saturday
6
The following elements are part of a choice: all-days or on.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Daily start time
configure application-assurance group number policer flow-setup-rate-policer string time-of-day-override number time-range daily start string
This command configures the daily start time of the policer override.
The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.
3 to 5
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the weekly context
configure application-assurance group number policer flow-setup-rate-policer string time-of-day-override number time-range weekly
Commands in this context configure the weekly start and end times for policer override.
The following elements are part of a choice: daily or weekly.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the end context
configure application-assurance group number policer flow-setup-rate-policer string time-of-day-override number time-range weekly end
Commands in this context configure the weekly end time for policer override.When using a weekly override, the operator can select between which days in the week the policy ends up to the hours or minutes for both start of the day and end of the day.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Weekly end day
configure application-assurance group number policer flow-setup-rate-policer string time-of-day-override number time-range weekly end day keyword
sunday, monday, tuesday, wednesday, thursday, friday, saturday
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Weekly end time
configure application-assurance group number policer flow-setup-rate-policer string time-of-day-override number time-range weekly end time string
This command configures the weekly end time of the policer override.
The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.
3 to 5
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the start context
configure application-assurance group number policer flow-setup-rate-policer string time-of-day-override number time-range weekly start
Commands in this context configure the weekly start time for policer override.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Weekly start day
configure application-assurance group number policer flow-setup-rate-policer string time-of-day-override number time-range weekly start day keyword
sunday, monday, tuesday, wednesday, thursday, friday, saturday
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Weekly start time
configure application-assurance group number policer flow-setup-rate-policer string time-of-day-override number time-range weekly start time string
This command configures the weekly start time of the policer override.
The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.
3 to 5
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the single-bucket-bandwidth-policer list instance
Commands in this context configure the single-bucket bandwidth policer.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Policer name
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Action for packets violating configured policer rate
configure application-assurance group number policer single-bucket-bandwidth-policer string action keyword
This command configures the action to be performed by single-bucket bandwidth policers for non-conformant traffic.
Dual bucket bandwidth policers cannot have their action configured and always mark traffic below CIR as in-profile, between CIR and PIR as out-of-profile, and drop traffic above PIR. Flow policers always discard non-conformant traffic.
When multiple application assurance policers are configured against a single flow (including policers at both subscriber and system), the flow/packet is dropped if one of the policers requires the packet to be discarded. This occurs regardless of the action of the other policers.
permit-deny
permit-deny, priority-mark
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the adaptation-rule context
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Peak information rate value for the adaptation rule
configure application-assurance group number policer single-bucket-bandwidth-policer string adaptation-rule pir keyword
This command configures the adaptation rule to be used while computing the operational PIR value. The adaptation rule specifies the rules to compute the operational values while maintaining minimum offset.
closest
max, min, closest
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the congestion-override context
Commands in this context configure the congestion bandwidth policer override rates.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Maximum burst size when in a congested state
configure application-assurance group number policer single-bucket-bandwidth-policer string congestion-override mbs number
This command configures the maximum burst size (MBS) for the policer. Nokia recommends configuring MBS larger than twice the MTU for the traffic handled by the policer to allow for some burstiness of the traffic. MBS is configurable for single-bucket, dual-bucket bandwidth, and flow setup rate policers only.
0 to 131071
0
kilobytes
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Peak information rate value for the congestion override
configure application-assurance group number policer single-bucket-bandwidth-policer string congestion-override pir (number | keyword)
1 to 100000000
max
kilobps
max
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the congestion-override-stage-2 context
Commands in this context configure per-subscriber stage 2 congestion bandwidth policer override rates.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Maximum burst size when in a congested state
configure application-assurance group number policer single-bucket-bandwidth-policer string congestion-override-stage-2 mbs number
This command configures the maximum burst size (MBS) for the policer. Nokia recommends configuring MBS larger than twice the MTU for the traffic handled by the policer to allow for some burstiness of the traffic. MBS is configurable for single-bucket, dual-bucket bandwidth, and flow setup rate policers only.
0 to 131071
0
kilobytes
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Peak information rate value for the congestion override
configure application-assurance group number policer single-bucket-bandwidth-policer string congestion-override-stage-2 pir (number | keyword)
1 to 100000000
max
kilobps
max
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number policer single-bucket-bandwidth-policer string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element recreates the parent element automatically for the new value to take effect. |
Policer granularity
configure application-assurance group number policer single-bucket-bandwidth-policer string granularity keyword
system, subscriber
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Bandwidth policer maximum burst size
configure application-assurance group number policer single-bucket-bandwidth-policer string mbs number
This command configures the maximum burst size (MBS) for the policer. Nokia recommends configuring MBS larger than twice the MTU for the traffic handled by the policer to allow for some burstiness of the traffic. MBS is configurable for single-bucket, dual-bucket bandwidth, and flow setup rate policers only.
0 to 131071
0
kilobytes
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Peak information rate value for the bandwidth policer
configure application-assurance group number policer single-bucket-bandwidth-policer string pir (number | keyword)
1 to 100000000
max
kilobps
max
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the time-of-day-override list instance
configure application-assurance group number policer single-bucket-bandwidth-policer string time-of-day-override number
Commands in this context configure the time of day override policy for a given policer. Rate/mbs/cbs/flow-rate/flow-count configured in each override-id will override the default policer values at the specified time of day configured in the override.
8
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
ID for time of day override
configure application-assurance group number policer single-bucket-bandwidth-policer string time-of-day-override number
1 to 255
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of this time of day policer
configure application-assurance group number policer single-bucket-bandwidth-policer string time-of-day-override number admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number policer single-bucket-bandwidth-policer string time-of-day-override number description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Bandwidth policer maximum burst size for time of day override
configure application-assurance group number policer single-bucket-bandwidth-policer string time-of-day-override number mbs number
This command configures the maximum burst size (MBS) for the policer. Nokia recommends configuring MBS larger than twice the MTU for the traffic handled by the policer to allow for some burstiness of the traffic. MBS is configurable for single-bucket, dual-bucket bandwidth, and flow setup rate policers only.
0 to 131071
0
kilobytes
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Peak information rate value for time of day override
configure application-assurance group number policer single-bucket-bandwidth-policer string time-of-day-override number pir (number | keyword)
1 to 100000000
max
kilobps
max
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the time-range context
configure application-assurance group number policer single-bucket-bandwidth-policer string time-of-day-override number time-range
Commands in this context configure the days of the week policer override is enabled as well as the time policer override starts and ends. When using a daily override the operator can select which days during the week from Sunday to Saturday it is applicable along with the start/end hour/min time range repeated over these days.When using a weekly override the operator can select between which days in the week the policy start up to the hours/min for both start day and end day.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the daily context
configure application-assurance group number policer single-bucket-bandwidth-policer string time-of-day-override number time-range daily
Commands in this context configure the daily start and end times for policer override.
The following elements are part of a choice: daily or weekly.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable policer override on every day
configure application-assurance group number policer single-bucket-bandwidth-policer string time-of-day-override number time-range daily all-days
This element is the default part of a choice.
The following elements are part of a choice: all-days or on.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Daily end time
configure application-assurance group number policer single-bucket-bandwidth-policer string time-of-day-override number time-range daily end string
This command configures the daily end time of the policer override.
The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.
3 to 5
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Policer override on selected days
configure application-assurance group number policer single-bucket-bandwidth-policer string time-of-day-override number time-range daily on keyword
sunday, monday, tuesday, wednesday, thursday, friday, saturday
6
The following elements are part of a choice: all-days or on.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Daily start time
configure application-assurance group number policer single-bucket-bandwidth-policer string time-of-day-override number time-range daily start string
This command configures the daily start time of the policer override.
The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.
3 to 5
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the weekly context
configure application-assurance group number policer single-bucket-bandwidth-policer string time-of-day-override number time-range weekly
Commands in this context configure the weekly start and end times for policer override.
The following elements are part of a choice: daily or weekly.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the end context
configure application-assurance group number policer single-bucket-bandwidth-policer string time-of-day-override number time-range weekly end
Commands in this context configure the weekly end time for policer override.When using a weekly override, the operator can select between which days in the week the policy ends up to the hours or minutes for both start of the day and end of the day.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Weekly end day
configure application-assurance group number policer single-bucket-bandwidth-policer string time-of-day-override number time-range weekly end day keyword
sunday, monday, tuesday, wednesday, thursday, friday, saturday
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Weekly end time
configure application-assurance group number policer single-bucket-bandwidth-policer string time-of-day-override number time-range weekly end time string
This command configures the weekly end time of the policer override.
The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.
3 to 5
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enable the start context
configure application-assurance group number policer single-bucket-bandwidth-policer string time-of-day-override number time-range weekly start
Commands in this context configure the weekly start time for policer override.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Weekly start day
configure application-assurance group number policer single-bucket-bandwidth-policer string time-of-day-override number time-range weekly start day keyword
sunday, monday, tuesday, wednesday, thursday, friday, saturday
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Weekly start time
configure application-assurance group number policer single-bucket-bandwidth-policer string time-of-day-override number time-range weekly start time string
This command configures the weekly start time of the policer override.
The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.
3 to 5
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the tcp-optimizer list instance
configure application-assurance group number tcp-optimizer string
Commands in this context configure the TCP optimizer policy. When a TCP optimizer policy is removed or deleted, the existing flows using this policy are abandoned, and optimization is stopped.
22.2.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
TCP optimizer name
configure application-assurance group number tcp-optimizer string
This command configures the name of the TCP optimizer policy.
1 to 32
This element is part of a list key.
22.2.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Delayed acknowledgment timeout for client and server
configure application-assurance group number tcp-optimizer string dack-timeout number
This command configures a delay ACK (DACK) timeout for the TCP optimizer. By entering this command a default of 200 ms timeout is enabled for delayed acknowledgment. This value is not configurable.
200
milliseconds
22.2.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number tcp-optimizer string description string
1 to 80
22.2.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Initial congestion window of the TCP optimizer
configure application-assurance group number tcp-optimizer string initial-cwnd number
This command configures the initial TCP congestion window (cwnd) used during the TCP Slow Start (SS) period.
1 to 256
8
22.2.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Initial TCP Slow Start threshold for client and server
configure application-assurance group number tcp-optimizer string initial-ss-threshold (number | keyword)
This command configures the initial Slow Start (SS) threshold for a specific TCP optimizer policy. Nokia recommends setting the threshold close to the access network Bandwidth Delay Product (BDP).
0 to 1000000
1000000
kilobytes
auto
22.2.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Network round trip time threshold
configure application-assurance group number tcp-optimizer string network-rtt-threshold number
This command configures the threshold of the Round Trip Time (RTT) delay of the network side (between AA and the content provider) above which TCP Optimization (TCPO) is performed. This enables the operator to disable optimization for content that is served from a location close to the TCP optimizer.
1 to 100
milliseconds
22.2.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
TCP stack congestion control algorithm
configure application-assurance group number tcp-optimizer string tcp-stack keyword
This command configures the TCP stack used toward the subscriber.
Note: The TCP stack used toward the core network is new-reno, and it is not configurable. TCP BBR, TCP Illinois, and TCP Westwood implement a sender-side modification of the TCP congestion window algorithm that improves the performance of TCP Reno in wireless networks with lossy links.
westwood
westwood, illinois, new-reno, bbr
22.2.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the url-filter list instance
configure application-assurance group number url-filter string
Commands in this context configure a URL filter action for flows of a specific type matching this entry. If no URL filters are specified, then no URL filters are evaluated.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
URL filter name
configure application-assurance group number url-filter string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of the AA URL filter
configure application-assurance group number url-filter string admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Use function-specific behavior for action or redirect
configure application-assurance group number url-filter string apply-function-specific-behaviour boolean
When configured to true, the function-specific configurations for URL list, ICAP, and web service (url-list, icap, and web-service) are used for default action (default-action) and HTTP redirect (http-redirect).
When configured to false, the configuration at the URL filter level (url-filter) is used for default action and HTTP redirect.
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the default-action context
configure application-assurance group number url-filter string default-action
Commands in this context configure the default action to take effect when the URL filter cannot be used. This may occur in the following cases:
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Allow all requests as the default URL filter action
configure application-assurance group number url-filter string default-action allow
When configured, this command allows all requests as the default URL filter action when the URL filter cannot be used.
The following elements are part of a choice: allow, block-all, or block-http-redirect.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Block all requests as the default URL filter action
configure application-assurance group number url-filter string default-action block-all
When configured, this command blocks all requests as the default URL filter action when the URL filter cannot be used.
This element is the default part of a choice.
The following elements are part of a choice: allow, block-all, or block-http-redirect.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP URL name for block and redirect request action
configure application-assurance group number url-filter string default-action block-http-redirect reference
This command blocks traffic and redirects the user to an information page that can be different from the page the user is redirected to when the site that the user tried to access is found in the URL filter. This page is configured using the configure AA group url-filter http-redirect command
configure application-assurance group number http-redirect string
The following elements are part of a choice: allow, block-all, or block-http-redirect.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number url-filter string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP redirect for a blocked HTTP request
configure application-assurance group number url-filter string http-redirect reference
configure application-assurance group number http-redirect string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP filtering for all HTTP requests
configure application-assurance group number url-filter string http-request-filtering keyword
This command selects between HTTP filtering for all HTTP requests in a flow or only the first HTTP request.
all
all, first
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the icap context
configure application-assurance group number url-filter string icap
Commands in this context configure the URL filter ICAP policy fields.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Custom x-header field name to include in ICAP requests
configure application-assurance group number url-filter string icap custom-x-header string
This command configures the URL filter ICAP policy to include a new x-header field; the content of the x-header is populated based on the AQP URL filter action which can optionally specify the ASO characteristic value to include in the x-header.
1 to 32
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the default-action context
configure application-assurance group number url-filter string icap default-action
Commands in this context configure a default action for the URL filter. The default action takes effect when the URL filter cannot be used. This may happen when all TCP connections are busy or down.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Allow all requests as the default action
configure application-assurance group number url-filter string icap default-action allow
When configured, this command allows all traffic when the URL filter cannot be used.
The following elements are part of a choice: allow, block-all, or block-http-redirect.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Block all requests as the default action
configure application-assurance group number url-filter string icap default-action block-all
When configured, this command blocks all traffic when the URL filter cannot be used.
This element is the default part of a choice.
The following elements are part of a choice: allow, block-all, or block-http-redirect.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP URL for redirection when URL filter cannot be used
configure application-assurance group number url-filter string icap default-action block-http-redirect reference
This command blocks traffic and redirects the user to an information page, which can be different than the page the user is redirected to when the site they attempted to access was found in the URL filter; this page is configured using the configure application-assurance group url-filter http-redirect command.
configure application-assurance group number http-redirect string
The following elements are part of a choice: allow, block-all, or block-http-redirect.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP redirect object used when ICAP blocks HTTP request
configure application-assurance group number url-filter string icap http-redirect reference
configure application-assurance group number http-redirect string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the server list instance
configure application-assurance group number url-filter string icap server (ipv4-address-no-zone | ipv6-address-no-zone) port number
Commands in this context configure the IP address and server port of the ICAP server.
In the current release, the system supports IPv4 addresses only for the ICAP server.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
ICAP server IP address
configure application-assurance group number url-filter string icap server (ipv4-address-no-zone | ipv6-address-no-zone) port number
This command configures the ICAP server address.
In the current release, the system supports IPv4 addresses only for the ICAP server.
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
ICAP server port
configure application-assurance group number url-filter string icap server (ipv4-address-no-zone | ipv6-address-no-zone) port number
1 to 65535
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of this URL filter ICAP server
configure application-assurance group number url-filter string icap server (ipv4-address-no-zone | ipv6-address-no-zone) port number admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number url-filter string icap server (ipv4-address-no-zone | ipv6-address-no-zone) port number description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
VLAN ID of the ICAP server service port
configure application-assurance group number url-filter string icap vlan-id number
1 to 4094
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the local-filtering context
configure application-assurance group number url-filter string local-filtering
Commands in this context configure a URL filter policy for local filtering to filter traffic based on a list of URLs located on a file stored in the router compact flash.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
Local filtering URL list for allowed URLs
configure application-assurance group number url-filter string local-filtering allow-list reference
configure application-assurance group number url-list string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the deny-list list instance
configure application-assurance group number url-filter string local-filtering deny-list reference
Commands in this context configure a list of denied URLs to be added to the local URL filter policy.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
URL list name
configure application-assurance group number url-filter string local-filtering deny-list reference
This command adds a deny-list URL list to the local URL filter policy.
configure application-assurance group number url-list string
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the default-action context
configure application-assurance group number url-filter string local-filtering deny-list reference default-action
Commands in this context configure a default action for the URL filter. The default action takes effect when the URL filter cannot be used. This may happen in the case of a local URL list when the URL list is disabled or the file is not loaded due to an error.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Allow all requests as the default action
configure application-assurance group number url-filter string local-filtering deny-list reference default-action allow
This command allows all traffic when the URL filter cannot be used.
The following elements are part of a choice: allow, block-all, or block-http-redirect.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Block all requests as the default action
configure application-assurance group number url-filter string local-filtering deny-list reference default-action block-all
This command blocks all traffic when the URL filter cannot be used.
This element is the default part of a choice.
The following elements are part of a choice: allow, block-all, or block-http-redirect.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP URL for redirection when URL filter cannot be used
configure application-assurance group number url-filter string local-filtering deny-list reference default-action block-http-redirect reference
This command blocks traffic and redirects the user to an information page, which can be different than the page the user is redirected to when the site they attempted to access was found in the URL filter; this page is configured using the configure application-assurance group url-filter http-redirect command.
configure application-assurance group number http-redirect string
The following elements are part of a choice: allow, block-all, or block-http-redirect.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP redirect object applied to blocked HTTP requests
configure application-assurance group number url-filter string local-filtering deny-list reference http-redirect reference
configure application-assurance group number http-redirect string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the web-service context
configure application-assurance group number url-filter string web-service
Commands in this context configure the URL filter policy using web-service filtering. The operator must configure the web service, hostname, DNS server to use, the AA interface VLAN ID, and provision the category profiles.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
Web service category ID
configure application-assurance group number url-filter string web-service category-set number
1 to 65535
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the classification-overrides context
Commands in this context create a classification override and allow the operator to manually set the category of a hostname.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the entry list instance
configure application-assurance group number url-filter string web-service classification-overrides entry number
Commands in this context configure a classification override, manually setting the category of a hostname.
200
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Classification override entry ID
configure application-assurance group number url-filter string web-service classification-overrides entry number
1 to 65535
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Web service category name
configure application-assurance group number url-filter string web-service classification-overrides entry number category-name string
1 to 32
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Hostname of the configured override category
configure application-assurance group number url-filter string web-service classification-overrides entry number expression string
1 to 255
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
Web service classifier
configure application-assurance group number url-filter string web-service classifier keyword
web-service-1
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the default-action context
configure application-assurance group number url-filter string web-service default-action
Commands in this context configure a default action for the URL filter. The default action takes effect when the URL filter cannot be used. This may happen when all TCP connections are busy or down.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Allow all requests as the default action
configure application-assurance group number url-filter string web-service default-action allow
This command allows all traffic when the web service is unavailable.
The following elements are part of a choice: allow, block-all, or block-http-redirect.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Block all requests as the default action
configure application-assurance group number url-filter string web-service default-action block-all
This command blocks all traffic when the web service is unavailable.
This element is the default part of a choice.
The following elements are part of a choice: allow, block-all, or block-http-redirect.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP URL for redirection when the web service is unavailable
configure application-assurance group number url-filter string web-service default-action block-http-redirect reference
This command blocks traffic and redirects the user to an information page, which can be different than the page the user is redirected to when the site they attempted to access was found in the URL filter; this page is configured using the configure application-assurance group url-filter http-redirect command.
configure application-assurance group number http-redirect string
The following elements are part of a choice: allow, block-all, or block-http-redirect.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
Web service default profile
configure application-assurance group number url-filter string web-service default-profile reference
configure application-assurance group number url-filter string web-service profile string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
Web service DNS server
configure application-assurance group number url-filter string web-service dns-server (ipv4-address-no-zone | ipv6-address-no-zone)
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
Web service fully qualified domain name
configure application-assurance group number url-filter string web-service fqdn string
1 to 255
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Web service HTTP redirect
configure application-assurance group number url-filter string web-service http-redirect reference
configure application-assurance group number http-redirect string
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the profile list instance
configure application-assurance group number url-filter string web-service profile string
Commands in this context configure the category profiles of the web service.
8
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Web service profile name
configure application-assurance group number url-filter string web-service profile string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the block context
configure application-assurance group number url-filter string web-service profile string block
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Add a list entry for category
configure application-assurance group number url-filter string web-service profile string block category string
Commands in this context configure the category that is blocked in the category profile.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Web service profile category name to be blocked
configure application-assurance group number url-filter string web-service profile string block category string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number url-filter string web-service profile string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
Web-service VLAN ID
configure application-assurance group number url-filter string web-service vlan-id number
This command configures the VLAN ID on which the AA ISA emits the traffic mapping to a preconfigured AA interface.
1 to 4094
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the url-list list instance
configure application-assurance group number url-list string
Commands in this context configure a URL list object. The URL list points to a file containing a list of URLs located on the system Compact Flash and is then referenced in a URL filter object to filter and redirect subscribers when a URL from this file is accessed.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
URL list name
configure application-assurance group number url-list string
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of the URL list
configure application-assurance group number url-list string admin-state keyword
disable
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance group number url-list string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
File name of the URL list on compact flash
configure application-assurance group number url-list string file string
1 to 180
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
Allow URL list to contain hostnames with wildcards
configure application-assurance group number url-list string host-expressions boolean
When configured to true, this command adds hostnames with wildcards to the URL list.
When configured to false, the URL list containing hostnames with wildcards is removed from the configuration.
false
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
URL list decryption key
configure application-assurance group number url-list string key string
This command configures the secret key for decrypting the URL list.
1 to 115
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
![]() | Warning: Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect. |
Size limit of the URL list
configure application-assurance group number url-list string size keyword
standard
standard, extended
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the http-enrich context
Commands in this context should not be used by the operators. Configuring them has no effect. Operators should use the commands in the application-assurance group context.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the field list instance
Commands in this context should not be used by the operators. Configuring them has no effect. Operators should use the commands in the application-assurance group context.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP enrich field name (void, do not use)
This command should not be used by the operators. Configuring it has no effect. Operators should use the commands in the application-assurance group context.
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
User information comment
configure application-assurance http-enrich field string comment string
1 to 32
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the http-error-redirect context
Commands in this context should not be used by the operators. Configuring them has no effect. Operators should use the commands in the application-assurance group context.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the error-code list instance
Commands in this context should not be used by the operators. Configuring them has no effect. Operators should use the commands in the application-assurance group context.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Error code for HTTP error redirection
0 to 4294967295
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
User information comment
configure application-assurance http-error-redirect error-code number comment string
1 to 32
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the template list instance
Commands in this context should not be used by the operators. Configuring them has no effect. Operators should use the commands in the application-assurance group context.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP error redirect template ID
0 to 4294967295
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
User information comment
configure application-assurance http-error-redirect template number comment string
1 to 32
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the http-notification context
Commands in this context should not be used by the operators. Configuring them has no effect. Operators should use the commands in the application-assurance group context.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the template list instance
Commands in this context should not be used by the operators. Configuring them has no effect. Operators should use the commands in the application-assurance group context.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP notification template ID
0 to 4294967295
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
User information comment
configure application-assurance http-notification template number comment string
1 to 32
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the http-redirect context
Commands in this context should not be used by the operators. Configuring them has no effect. Operators should use the commands in the application-assurance group context.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the template list instance
Commands in this context should not be used by the operators. Configuring them has no effect. Operators should use the commands in the application-assurance group context.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
HTTP redirect template ID
This command configures the HTTP policy redirect template ID.
The available options are:
0 to 4294967295
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
User information comment
configure application-assurance http-redirect template number comment string
1 to 32
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the protocol list instance
Commands in this context configure the administrative state of system-wide protocols.Some protocols are always enabled and cannot be disabled. These are "base protocols" that were present in R1 of the release.Some protocols are disabled by default and can be enabled. There are protocols that were introduced post R1, which are all enabled by default but may be disabled if not desired.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AA protocol name
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Administrative state of the protocol
configure application-assurance protocol string admin-state keyword
enable, disable
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the radius-accounting-policy list instance
Commands in this context configure an existing subscriber RADIUS-based accounting policy to use for AA. RADIUS accounting policies are configured in the configure application-assurance radius-accounting-policy context.
8
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AA RADIUS accounting policy name
1 to 32
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Text description
configure application-assurance radius-accounting-policy string description string
1 to 80
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
AA RADIUS accounting policy interim update interval
5 to 1080
minutes
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the radius-accounting-server context
Commands in this context configure an existing subscriber RADIUS-based accounting policy to use for AA. RADIUS accounting policies are configured in the configure application-assurance radius-accounting-policy context.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Access algorithm for the list of RADIUS servers
direct
direct, round-robin
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Number of retries for contacting the RADIUS server
1 to 10
3
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Router or VPRN service name
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the server list instance
Commands in this context configure the RADIUS server and the RADIUS server IP address, index, and key values.
RADIUS servers are accessed in order from lowest to highest index for authentication requests until a response from a server is received. A higher indexed server is only queried if no response is received from a lower indexed server (which implies that the server is not available). If a response from a server is received, no other RADIUS servers are queried.
5
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
RADIUS accounting server index
This command configures the index for the RADIUS server. The index determines the sequence in which the servers are queried for authentication requests. Servers are queried in order from lowest to highest index.
1 to 5
This element is part of a list key.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
RADIUS server IP address
configure application-assurance radius-accounting-policy string radius-accounting-server server number address string
This command configures the IP address of the RADIUS server. Two RADIUS servers cannot have the same IP address. An error message is generated if the server address is a duplicate.
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
RADIUS server UDP port used for authentication
configure application-assurance radius-accounting-policy string radius-accounting-server server number port number
1 to 65535
1813
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
RADIUS server secret key
configure application-assurance radius-accounting-policy string radius-accounting-server server number secret string
This command configures the secret key to access the RADIUS server. This secret key must match the password on the RADIUS server.
1 to 54
This element is mandatory.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Source IP address of RADIUS packets
This command configures the source IP address of the RADIUS packet.
The system IP address must be configured for the RADIUS client to work. The system IP address must only be configured if the source address is not specified. When this command reverts to its default, the source address is determined at the moment the request is sent.
This address is also used in the nas-ip-address command in the configure aaa radius isa-policy accounting include-attributes and configure aaa radius isa-policy authentication include-attributes contexts as it is set to the system IP address if no source address was given.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
RADIUS accounting server response timeout
1 to 90
5
seconds
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Change delta for RADIUS accounting record updates
This command configures the number of changes required to generate the record.
1
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Enter the usage-alert-thresholds context
Commands in this context configure the AA performance monitoring alerts.
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
High watermark for bit rate alarms
configure application-assurance usage-alert-thresholds bit-rate-high-wmark (number | keyword)
This command configures the high watermark for bit rate alarms. The value must be larger than or equal to the low watermark value.
1 to 100000
max
megabps
max
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Low watermark for bit rate alarms
This command configures the utilization of the flow records on the ISA-AA group when the full alarm is cleared by the agent.
0 to 99999
0
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
High watermark for datapath CPU alarms
configure application-assurance usage-alert-thresholds datapath-cpu-high-wmark (number | keyword)
This command configures the system-wide high watermark threshold as a percentage of the per-ISA datapath core CPU utilization, where an alarm is raised by the agent. CPU usage is the average usage across all datapath cores.
0 to 100
95
percent
max
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Low watermark for datapath CPU alarms
This command configures the system-wide low watermark threshold as a percentage of the per-ISA datapath core CPU utilization, where an alarm is raised by the agent. CPU usage is the average usage across all datapath cores.
0 to 100
90
percent
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
High watermark for flow setup rate
configure application-assurance usage-alert-thresholds flow-setup-rate-high-wmark (number | keyword)
This command configures the system-wide high watermark threshold for per-ISA throughput in packets/second when an alarm is raised by the agent. The value must be larger than or equal to the packet-rate-low-wmark value.
1 to 2000000
max
max
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Low watermark for flow setup rate
This command configures the flow setup rate on the ISA-AA when a flow setup alarm is raised by the agent.
0 to 1999999
0
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Flow table high watermark
This command configures the system-wide high watermark threshold as a percentage of the flow table size for the per-ISA utilization of the flow records when a full alarm is raised by the agent.
0 to 100
95
percent
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Flow table low watermark
This command configures the system-wide low watermark threshold as a percentage of the flow table size for per-ISA.
0 to 100
90
percent
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Packet rate high watermark
configure application-assurance usage-alert-thresholds packet-rate-high-wmark (number | keyword)
This command configures the packet rate on the ISA-AA when a packet rate alarm is raised by the agent.
1 to 148809524
max
max
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
Packet rate low watermark
This command configures the packet rate on the ISA-AA when a packet rate alarm is cleared by the agent.
0 to 148809523
0
21.10.R1
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR