For feedback and comments:
documentation.feedback@alcatel-lucent.com

Table of Contents Previous Next Index PDF


Filter Command Reference
Command Hierarchies
 
Configuration Commands
DHCP Filter Policy Commands
config
dhcp-filter filter-id [create]
no dhcp-filter filter-id
description description-string
entry entry-id [create]
no entry entry-id
action {bypass-host-creation}
action drop
option dhcp-option-number {present | absent}
option dhcp-option-number match hex hex-string [exact] [invert-match]
option dhcp-option-number match string ascii-string [exact] [invert-match]
 
IP Filter Policy Commands
config
ip-filter filter-id [create]
ip-filter {filter-id | filter-name}
no ip-filter filter-id
default-action {drop | forward}
description description-string
embed-filter filter-id [offset offset ] [{active | inactive}]
embed-filter open-flow ofs-name [{system | service {service-id | service-name} | sap sap-id}] [offset offset ] [{active | inactive}]
embed-filter open-flow ofs-name [offset offset ] [{active | inactive}]
embed-filter open-flow ofs-name system [offset offset ] [{active | inactive}]
embed-filter open-flow ofs-name service {service-id | service-name} [offset offset ] [{active | inactive}]
embed-filter open-flow ofs-name sap sap-id}] [offset offset ] [{active | inactive}]
no embed-filter filter-id
no embed-filter open-flow ofs-name service {service-id | service-name}
no embed-filter open-flow ofs-name sap sap-id
no embed-filter open-flow ofs-name system
no embed-filter open-flow ofs-name [{system | service {service-id | service-name} | sap sap-id}]
entry entry-id [time-range time-range-name] [create]
no entry entry-id
drop packet-length {{lt | eq | gt} packet-length-value | range packet-length-value packet-length-value}
drop [ttl {{lt | gt | eq} ttl-value | range ttl-value ttl-value}]
forward esi esi sf-ip ip-address vas-interface interface-name router {router-instance | service-name service-name}
forward esi esi service-id vpls-service-id
forward lsp lsp-name
forward next-hop [indirect] ip-address
forward next-hop [indirect] ip-address router {router-instance | service-name service-name}
forward router {router-instance | service-name service-name}
forward sdp sdp-id:vc-id
http-redirect rdr-url-string [allow-radius-override]
nat [nat-policy nat-policy-name]
description description-string
egress-pbr {default-load-balancing | l4-load-balancing}
log log-id
match [protocol protocol-id]
dscp dscp-name
dst-ip {ip-address/mask | ip-address ipv4-address-mask | ip-prefix-list prefix-list-name}
dst-port {lt | gt | eq} dst-port-number
dst-port port-list-name
dst-port range dst-port-number dst-port-number
fragment {true|false|first-only|non-first-only}
icmp-code icmp-code
icmp-type icmp-type
ip-option ip-option-value [ip-option-mask]
multiple-option {true | false}
option-present {true | false}
port {lt|gt|eq} port-number
port port-list port-list-name
port range port-number port-number
src-ip{ip-address/mask | ip-address ipv4-address-mask | ip-prefix-list prefix-list-name}
src-port {{lt | gt | eq} src-port-number}
src-port port-list port-list-name
src-port range src-port-number src-port-number
src-route-option {true|false}
tcp-ack {true | false}
tcp-syn {true | false}
pbr-down-action-override {drop | forward | filter-default-action}
filter-name filter-name
renum old-entry-id new-entry-id
scope {exclusive | template | embedded | system}
shared-radius-filter-wmark low low-watermark high high-watermark
sub-insert-credit-control start-entry entry-id count count
sub-insert-radius start-entry entry-id count count
sub-insert-shared-pccrule start-entry entry-id count count
sub-insert-shared-radius start-entry entry-id count count
sub-insert-wmark low low-watermark high high-watermark
IPv6 Filter Policy Commands
 
IPv6 Filter Policy Commands
config
ipv6-filter filter-id [create]
ipv6-filter {filter-id | filter-name}
no ipv6-filter filter-id
default-action {drop | forward}
description description-string
embed-filter filter-id [offset offset ] [{active | inactive}]
embed-filter open-flow ofs-name [{system | service {service-id | service-name} | sap sap-id}] [offset offset ] [{active | inactive}]
embed-filter open-flow ofs-name [offset offset ] [{active | inactive}]
embed-filter open-flow ofs-name system [offset offset ] [{active | inactive}]
embed-filter open-flow ofs-name service {service-id | service-name} [offset offset ] [{active | inactive}]
embed-filter open-flow ofs-name sap sap-id}] [offset offset ] [{active | inactive}]
no embed-filter filter-id
no embed-filter open-flow ofs-name service {service-id | service-name}
no embed-filter open-flow ofs-name sap sap-id
no embed-filter open-flow ofs-name system
no embed-filter open-flow ofs-name [{system | service {service-id | service-name} | sap sap-id}]
entry entry-id [time-range time-range-name] [create]
no entry entry-id
drop packet-length {{lt | eq | gt} packet-length-value | range packet-length-value packet-length-value}
forward next-hop [indirect] ipv6-address
forward next-hop [indirect] ipv6-address router {router-instance | service-name service-name}
forward router{router-instance service-name service-name}
forward sdp sdp-id:vc-id
http-redirect rdr-url-string [allow-radius-override]
nat [nat-policy nat-policy-name] nat-type nat-type
description description-string
log log-id
match [next-header next-header]
ah-ext-hdr {true | false }
dscp dscp-name
dst-ip {ipv6-address/prefix-length | ipv6-address ipv6-address-mask | ipv6-prefix-list prefix-list-name}
dst-port {lt | gt | eq} dst-port-number
dst-port port-list port-list-name
dst-port range dst-port-number dst-port-number
esp-ext-hdr {true | false }
flow-label flow-label [mask]
fragment {true|false|first-only|non-first-only}
hop-by-hop-opt {true|false}
icmp-code icmp-code
icmp-type icmp-type
port {lt|gt|eq} port-number
port port-list port-list-name
port range port-number port-number
routing-type0 {true|false}
src-ip{ipv6-address/prefix-length | ipv6-address ipv6-address-mask | ipv6-prefix-list prefix-list-name}
src-port {lt | gt | eq} src-port-number}
src-port port-list port-list-name
src-port range src-port-number src-port-number
tcp-ack {true | false}
tcp-syn {true | false}
filter-name filter-name
renum old-entry-id new-entry-id
scope {exclusive | template | embedded | system}
shared-radius-filter-wmark low low-watermark high high-watermark
sub-insert-credit-control start-entry entry-id count count
sub-insert-radius start-entry entry-id count count
sub-insert-shared-pccrule start-entry entry-id count count
sub-insert-shared-radius start-entry entry-id count count
sub-insert-wmark low low-watermark high high-watermark
System Filter Policy Commands
config
ip filter-id
no ip filter-id
ipv6 filter-id
no ipv6 filter-id
 
Log Filter Commands
config
log log-id [create]
no log log-id
description description-string
destination memory num-entries | syslog syslog-id
summary-crit dst-addr
summary-crit src-addr
MAC Filter Commands
config
mac-filter filter-id [create]
mac-filter {filter-id | filter-name}
no mac-filter filter-id
description description-string
entry entry-id [time-range time-range-name]
no entry entry-id [create]
forward esi eso service-id vpls-service-id
forward sap sap-id
forward sdp sdp-id:vc-id
description description-string
log log-id
match [frame-type {802dot3 | 802dot2-llc | 802dot2-snap | ethernet_II}]
dot1p dot1p-value [dot1p-mask]
dsap dsap-value [dsap-mask]
dst-mac ieee-address [ieee-address-mask]
etype 0x0600..0xffff
inner-tag value [vid-mask]
isid value [to higher-value]
outer-tag value [vid-mask]
snap-oui {zero | non-zero}
snap-pid snap-pid
ssap ssap-value [ssap-mask]
src-mac ieee-address [ieee-address-mask]
pbr-down-action-override {drop | forward | filter-default-action}
renum old-entry-id new-entry-id
scope {exclusive | template}
type filter-type
 
Match Filter List Commands
config
ip-prefix-list ip-prefix-list-name [create]
no ip-prefix-list ip-prefix-list-name
bgp-peers index group reg-exp neighbor reg-exp
description description-string
[no] prefix ip-prefix/prefix-length
ipv6-prefix-list ipv6-prefix-list-name [create]
no ipv6-prefix-list ipv6-prefix-list-name
bgp-peers index group reg-exp neighbor reg-exp
description description-string
[no] prefix ipv6-prefix/prefix-length
port-list port-list-name create
no port-list port-list-name
description description-string
[no] port port number
[no] port range start end
 
 
Redirect Policy Configuration Commands
config
Redirect policy commands
redirect-policy redirect-policy-name [create]
no redirect-policy redirect-policy-name
description description-string
destination ip-address [create]
no destination ip-address
destination ipv6-address [create]
no destination ipv6-address
description description-string
drop-count consecutive-failures [hold-down seconds]
interval seconds
timeout seconds
priority [priority]
router router-instance
router service-name service-name
snmp-test test-name [create]
no snmp-test test-name
drop-count consecutive-failures [hold-down seconds]
interval seconds
oid oid-string community community-string
return-value return-value type return-type [disable | lower-priority priority | raise-priority priority]
no return-value return-value type return-type
timeout seconds
sticky-dest {hold-time-up seconds | no-hold-time-up}
url-test test-name [create]
no url-test test-name
drop-count consecutive-failures [hold-down seconds]
interval seconds
return-code return-code-1 [return-code-2] [disable | lower-priority priority | raise-priority priority]
no return-code return-code-1 [return-code-2]
timeout seconds
url url-string [http-version version-string]
[no] router [router-instance | service-name service-name]
Copy Filter Commands
config
copy ip-filter src-filter-id [src-entry src-entry-id] to dst-filter-id [dst-entry dst-entry-id] [overwrite]
copy ipv6-filter src-filter-id [src-entry src-entry-id] to dst-filter-id [dst-entry dst-entry-id] [overwrite]
copy mac-filter src-filter-id [src-entry src-entry-id] to dst-filter-id [dst-entry dst-entry-id] [overwrite]
Show Commands
show
dhcp [filter-id]
dhcp6 [filter-id]
ip [filter-type filter-type]
ip embedded [inactive]
ip ip-filter-id embedded [inactive]
ip ip-filter-id [detail]
ip ip-filter-id associations
ip ip-filter-id type entry-type
ip ip-filter-id counters [type entry-type]
ip ip-filter-id entry entry-id counters
ip ip-filter-id entry entry-id [detail]
ipv6 [filter-type filter-type]
ipv6 embedded [inactive]
ipv6 ipv6-filter-id embedded [inactive]
ipv6 ipv6-filter-id [detail]
ipv6 ipv6-filter-id associations
ipv6 ipv6-filter-id type entry-type
ipv6 ipv6-filter-id counters [type entry-type]
ipv6 ipv6-filter-id entry entry-id counters
ipv6 ipv6-filter-id entry entry-id [detail]
log [bindings]
log log-id [match string]
mac {mac-filter-id [entry entry-id] [association | counters]}
ip-prefix-list [prefix-list-name]
ip-prefix-list prefix-list-name references
ipv6-prefix-list [prefix-list-name]
ipv6-prefix-list prefix-list-name references
port-list [port-list-name]
port-list port-list-name references
redirect-policy {redirect-policy-name [dest ip-address] [association]}
system-filter [chained-to]
Clear Commands
clear
ip filter-id [entry entry-id] [ingress | egress]
ipv6 filter-id [entry entry-id] [ingress | egress]
log log-id
mac filter-id [entry entry-id] [ingress | egress]
Monitor Commands
monitor
filter ip ip-filter-id entry entry-id [interval seconds] [repeat repeat] [absolute | rate]
filter ipv6 ipv6-filter-id entry entry-id [interval seconds] [repeat repeat] [absolute | rate]
filter mac mac-filter-id entry entry-id [interval seconds] [repeat repeat] [absolute | rate]
Debug Commands
tools
Redirect policy commands
egress-pbr [detail]
ip <filter-id>
ip <filter-id>
ipv6 <filter-id>
mac <filter-id>