For feedback and comments:
documentation.feedback@alcatel-lucent.com

Table of Contents Previous Next PDF


IP Tunnel Command Reference
•
•
•
•
→
→
•
•
•
Configuration Commands
 
Hardware Commands
 
config
—
card slot-number
—
mda mda-slot
—
mda-type isa-tunnel
—
 
ISA Commands
config
—
—
tunnel-group tunnel-group-id [create]
—
no tunnel-group tunnel-group-id
—
—
—
backup mda-id
—
—
description description-string
—
—
—
mda mda-id
—
[no] mda
—
—
primary mda-id
—
—
reassembly [wait-msecs]
—
—
IPSec Commands
config
—
—
cert-profile profile-name [create]
—
no cert-profile profile-name
—
entry entry-id [create]
—
no entry entry-id
—
cert cert-filename
—
—
key key-filename
—
—
—
—
—
trust-anchor-profile name [create]
—
—
trust-anchor ca-profile-name
—
—
ts-list list-name [create]
—
no ts-list list-name
—
—
entry entry-id [create]
—
no entry entry-id
—
address prefix ip-prefix/ip-prefix-len
—
address from begin-ip-address to end-ip-address
—
config
—
—
ike-policy ike-policy-id [create]
—
no ike-policy ike-policy-id
—
auth-algorithm auth-algorithm
—
—
auth-method {psk|plain-psk-xauth|cert-auth|psk-radius|cert-radius|eap|auto-eap-radius}
—
—
auto-eap-method {psk|cert|psk-or-cert}
—
—
description description-string
—
—
dh-group {1 2 | 5 | 14 | 15}
—
—
dpd [interval interval] [max-retries max-retries] [reply-only]
—
—
encryption-algorithm {des | 3des | aes128 | aes192 | aes256}
—
—
ike-mode {main | aggressive}
—
—
—
ipsec-lifetime ipsec-lifetime
—
—
isakmp-lifetime isakmp-lifetime
—
—
—
nat-traversal [force] [keep-alive-interval keep-alive-interval] [force-keep-alive]
—
—
own-auth-method {psk | cert | eap-only}
—
—
pfs [dh-group {1 | 2 | 5 | 14 | 15}]
—
—
—
—
—
config
—
—
ipsec-transform transform-id [create]
—
no ipsec-transform transform-id
—
esp-auth-algorithm {null | md5 | sha1| sha256 | sha384 | sha512| aes-xcbc}
—
—
esp-encryption-algorithm {null | des | 3des | aes128 | aes192 | aes256}
—
 
config
—
—
[no] static-sa sa-name
—
authentication auth-algorithm ascii-key ascii-string
—
authentication auth-algorithm hex-key hex-string [hash|hash2]
—
—
description description-string
—
—
direction ipsec-direction
—
—
protocol ipsec-protocol
—
—
spi spi
—
 
config
—
—
tunnel-template ipsec template identifier [create]
—
no tunnel-templateipsec template identifier
—
—
description description-string
—
—
—
—
—
packet-too-big number [10..1000] seconds [1..60]
—
—
—
ip-mtu octets
—
—
replay-window {32 | 64 | 128 | 256 | 512}
—
—
—
transform transform-id [transform-id...(up to 4 max)]
—
 
config
—
—
—
—
—
—
—
—
—
—
—
radius-server-policy radius-server-policy-name
—
—
update-interval minutes [jitter seconds]
—
—
—
—
—
—
—
—
—
—
password password [hash|hash2]
—
—
radius-server-policy radius-server-policy-name
—
 
Service Configuration Commands
 
IES Commands
config
—
—
ies service-id [customer customer-id] [vpn vpn-id]
—
[no] interface ip-int-name [tunnel]
—
—
—
—
—
[no] sap sap-id [create]
—
ip-tunnel ip-tunnel-name [create]
—
backup-remote-ip ip-address
—
—
—
delivery-service {service-id | svc-name}
—
—
description description-string
—
—
dscp dscp-name
—
—
[no] dest-ip ip-address
—
—
gre-header send-key send-key receive-key receive-key
—
—
ip-mtu octets
—
—
reassembly [wait-msecs]
—
—
remote-ip ip-address
—
—
—
source ip-address
—
—
—
—
cert filename
—
—
cert-profile profile
—
—
key filename
—
—
—
default-result {revoked|good}
—
—
primary {ocsp|crl}
—
—
secondary {ocsp|crl}
—
—
trust-anchor ca-profile-name
—
—
—
—
trust-anchor ca-profile-name
—
—
—
—
default-secure-service service-id ipsec-interface ip-int-name
—
—
default-tunnel-template ipsec template identifier
—
—
[no] dhcp
—
gi-address ip-address
—
—
—
server ip-address [ip-address...(upto 8 max)] router router-instance
—
server ip-address [ip-address...(upto 8 max)] service-name service-name
—
—
—
ike-policy ike-policy-id
—
—
—
—
address-source router router-instance dhcp-server local-dhcp4-svr-name pool dhcp4-server-pool
—
address-source service-name service-name dhcp-server local-dhcp4-svr-name pool dhcp4-server-pool
—
—
—
address-source router router-instance dhcp-server local-dhcp6-svr-name pool dhcp6-server-pool
—
address-source service-name service-name dhcp-server local-dhcp6-svr-name pool dhcp6-server-pool
—
—
—
—
—
local-id {ipv4 | fqnd| ipv6} [value [255 chars max]]
—
—
—
—
—
—
—
—
—
ts-negotiation ts-list list-name
—
VPRN Commands
config
—
—
vprn service-id [customer customer-id]
—
no vprn service-id
—
—
security-policy security-policy-id [create]
—
no security-policy security-policy-id
—
entry entry-id [create]
—
no entry entry-id
—
local-ip {ip-prefix/prefix-length | ip-prefix netmask | any}
—
local-v6-ip ipv6-prefix/prefix-length
—
—
—
remote-ip {ip-prefix/prefix-length | ip-prefix netmask | any}
—
—
remote-v6-ip ipv6-prefix/prefix-length
—
—
[no] interface ip-int-name
—
—
address ipv6-address/prefix-length [eui-64] [preferred] [track-srrp srrp-instance]
—
no address ipv6-address/prefix-length
—
link-local-address ipv6-address [preferred]
config
—
—
vprn service-id [customer customer-id]
—
no vprn service-id
—
[no] interface ip-int-name [create] [tunnel]
—
—
—
—
—
[no] sap sap-id [create]
—
ip-tunnel ip-tunnel-name [create]
—
backup-remote-ip ip-address
—
—
—
delivery-service {service-id | svc-name}
—
—
description description-string
—
—
dscp dscp-name
—
—
[no] dest-ip ip-address
—
—
ip-mtu octets
—
—
reassembly [wait-msecs]
—
—
remote-ip ip-address
—
—
—
source ip-address
—
—
—
—
cert filename
—
—
cert-profile profile
—
—
key filename
—
—
—
default-result {revoked|good}
—
—
primary {ocsp|crl}
—
—
secondary {ocsp|crl}
—
—
trust-anchor ca-profile-name
—
—
—
—
default-secure-service service-id ipsec-interface ip-int-name
—
—
default-tunnel-template ipsec template identifier
—
—
[no] dhcp
—
gi-address ip-address
—
—
—
server ip-address [ip-address...(upto 8 max)] router router-instance
—
server ip-address [ip-address...(upto 8 max)] service-name service-name
—
—
—
ike-policy ike-policy-id
—
—
—
—
address-source router router-instance dhcp-server local-dhcp4-svr-name pool dhcp4-server-pool
—
address-source service-name service-name dhcp-server local-dhcp4-svr-name pool dhcp4-server-pool
—
—
—
address-source router router-instance dhcp-server local-dhcp6-svr-name pool dhcp6-server-pool
—
address-source service-name service-name dhcp-server local-dhcp6-svr-name pool dhcp6-server-pool
—
—
—
—
—
local-id {ipv4 | fqdn |ipv6} [value [255 chars max]]
—
—
—
ts-negotiation ts-list list-name
—
—
ipsec-tunnel ipsec-tunnel-name [create]
—
no ipsec-tunnel ipsec-tunnel-name
—
—
bfd-enable service service-id interface interface-name dst-ip ip-address
—
—
description description-string
—
—
[no] dest-ip ip-address
—
—
—
—
cert filename
—
—
cert-profile profile
—
—
key filename
—
—
—
default-result {revoked|good}
—
—
primary {ocsp|crl}
—
—
secondary {ocsp|crl}
—
—
trust-anchor ca-profile-name
—
—
—
—
ike-policy ike-policy-id
—
—
local-id {ipv4 | fqdn |ipv6} [value [255 chars max]]
—
—
—
—
transform transform-id [transform-id...(up to 4 max)]
—
—
—
—
—
—
packet-too-big number [10..1000] seconds [1..60]
—
—
ip-mtu octets
—
—
local-gateway-address ip-address peer ip-address delivery-service service-id
—
—
local-id type type [value <[255 chars max]>
—
—
—
security-association security-entry-id authentication-key authentication-key encryption-key encryption-key spi spi transform transform-id direction {inbound|outbound}
—
no security-association security-entry-id direction {inbound|outbound}
—
replay-window replay-window-size
—
—
security-policy security-policy-id
—
IPSec Mastership Election Commands
configure
—
—
—
peer ip-address [create]
—
no peer ip-address
—
—
—
discovery-interval interval-secs [boot interval-secs]
—
—
—
—
—
—
tunnel-group tunnel-group-id [create]
—
no tunnel-group tunnel-group-id
—
peer-group tunnel-group-id
—
—
priority priority
—
—
 
Related Commands
config
—
—
—
—
—
—
protocol protocol [all | instance instance]
—
—
state state
—
config
—
—
—
—
—
[no] ipsec
—
tunnel-group tunnel-group-id sync-tag tag-name [create]
—
no tunnel-group tunnel-group-id
 
CMPv2 Commands
config
—
—
—
—
—
ca-profile name [create]
—
—
—
—
—
—
—
—
http-version [1.0|1.1]
—
—
key password [hash|hash2] reference reference-number
—
no key reference reference-number
—
—
—
—
url url-string [service-id service-id]
—
—
revocation-check {crl | crl-optional}
 
admin
—
—
—
cert-request ca ca-profile-name current-key key-filename current-cert cert-filename [hash-alg hash-algorithm] newkey key-filename subject-dn subject-dn [domain-name <[255 chars max]> [ip-addr <ip-address|ipv6-address>] save-as save-path-of-result-cert
—
clear-request ca ca-profile-name
—
initial-registration ca ca-profile-name key-to-certify key-filename protection-alg {password password reference ref-number | signature [cert cert-file-name [send-chain [with-ca ca-profile-name]]] [protection-key key-file-name] [hash-alg {md5 | sha1 | sha224 | sha256 | sha384 | sha512}]} subject-dn dn [domain-name <[255 chars max]> [ip-addr <ip-address|ipv6-address>] save-as save-path-of-result-cert
—
key-update ca ca-profile-name newkey key-filename oldkey key-filename oldcert cert-filename [hash-alg hash-algorithm] save-as save-path-of-result-cert
—
poll ca ca-profile-name
—
show-request [ca ca-profile-name]
 
 
 
 
 
 
Auto-Update Commands
config
—
—
—
—
—
—
ipv6-source-address ipv6-address
—
—
—
—
retry count
—
—
router router-instance
—
timeout seconds
 
config
—
—
—
—
ca-profile name [create]
—
—
—
—
—
url-entry entry-id [create]
—
no url-entry entry-id
—
—
—
url url
—
—
periodic-update-interval [days days] [hrs hours] [min minutes] [sec seconds]
—
pre-update-time [days days] [hrs hours] [min minutes] [sec seconds]
—
—
—
pre-update-time schedule-type
—
schedule-type schedult-type
—
 
admin
—
—
crl-update ca ca-profile-name
 
Show Commands
show
—
—
cert-profile name association
—
—
cert-profile name entry [1..8]
—
certificate filename association
—
gateway name name
—
gateway [service service-id]
—
gateway tunnel [ip-address:port]
—
gateway name name tunnel ip-address:port
—
gateway name name tunnel
—
gateway [name name] tunnel state state
—
gateway [name name] tunnel idi-value idi-prefix
—
gateway tunnel count
—
ike-policy ike-policy-id
—
—
—
—
security-policy service-id [security-policy-id]
—
—
—
static-sa name sa-name
—
static-sa spi spi
—
transform [transform-id]
—
trust-anchor-profile trust-anchor-profile association
—
trust-anchor-profile [trust-anchor-profile ]
—
ts-list [list-name]
—
ts-list list-name association
—
ts-list list-name entry [1..32]
—
tunnel ipsec-tunnel-name
—
—
tunnel-template [ipsec template identifier]
—
—
—
mc-ipsec peer ip-address tunnel-group tunnel-group-id
—
mc-ipsec peer ip-address
 
 
Debug Commands
debug
—
—
[no] gateway name name tunnel ip-address[:port] [nat-ip nat-ip[:port]] [detail]
—
tunnel ipsec-tunnel-name [detail]
—
no tunnel ipsec-tunnel-name
—
[no] certificate filename
—
—
[no] ca-profile profile-name
—
 
 
 
Tools Commands
tools
—
—
—
—
—
force-switchover tunnel-group local-group-id [now][to {master|standby}]