filter commands

configure 
filter 
apply-groups reference
apply-groups-exclude reference
dhcp-filter number 
apply-groups reference
apply-groups-exclude reference
default-action 
drop 
description description
entry number 
action 
drop 
apply-groups reference
apply-groups-exclude reference
option 
absent 
match 
exact boolean
hex string
invert boolean
string string
number number
present 
dhcp6-filter number 
apply-groups reference
apply-groups-exclude reference
default-action 
drop 
description description
entry number 
action 
drop 
apply-groups reference
apply-groups-exclude reference
option 
absent 
match 
exact boolean
hex string
invert boolean
string string
number number
present 
ip-exception filter-name 
apply-groups reference
apply-groups-exclude reference
description description
entry number 
apply-groups reference
apply-groups-exclude reference
description description
match 
dst-ip 
address (ipv4-prefix-with-host-bits | ipv4-address)
mask ipv4-address
dst-port 
eq number
gt number
lt number
range 
end number
start number
icmp 
code number
type number
protocol (number | keyword)
src-ip 
address (ipv4-prefix-with-host-bits | ipv4-address)
mask ipv4-address
src-port 
eq number
gt number
lt number
range 
end number
start number
filter-id number
ip-filter filter-name 
apply-groups reference
apply-groups-exclude reference
chain-to-system-filter boolean
default-action keyword
description description
embed 
filter reference offset number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
entry number 
action 
accept 
apply-groups reference
apply-groups-exclude reference
drop 
drop-when 
extracted-traffic 
packet-length 
eq number
gt number
lt number
range 
end number
start number
ttl 
eq number
gt number
lt number
range 
end number
start number
forward 
next-hop 
nh-ip 
address ipv4-address
indirect boolean
nh-ip-vrf 
address ipv4-address
indirect boolean
router-instance string
redirect-policy reference
router-instance string
ignore-match 
nat 
nat-policy reference
rate-limit 
packet-length 
eq number
gt number
lt number
range 
end number
start number
pir (number | keyword)
policer named-item
ttl 
eq number
gt number
lt number
range 
end number
start number
reassemble 
secondary 
apply-groups reference
apply-groups-exclude reference
forward 
next-hop 
nh-ip-vrf 
address ipv4-address
indirect boolean
router-instance string
tcp-mss-adjust 
apply-groups reference
apply-groups-exclude reference
description description
log reference
match 
dscp keyword
dst-ip 
address (ipv4-prefix-with-host-bits | ipv4-address)
ip-prefix-list reference
mask ipv4-address
dst-port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
fragment keyword
icmp 
code number
type number
ip 
address (ipv4-prefix-with-host-bits | ipv4-address)
ip-prefix-list reference
mask ipv4-address
ip-option 
mask number
type number
multiple-option boolean
option-present boolean
port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
protocol (number | keyword)
protocol-list reference
src-ip 
address (ipv4-prefix-with-host-bits | ipv4-address)
ip-prefix-list reference
mask ipv4-address
src-port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
src-route-option boolean
tcp-established 
tcp-flags 
ack boolean
cwr boolean
ece boolean
fin boolean
ns boolean
psh boolean
rst boolean
syn boolean
urg boolean
pbr-down-action-override keyword
sticky-dest (number | keyword)
filter-id number
scope keyword
ipv6-exception filter-name 
apply-groups reference
apply-groups-exclude reference
description description
entry number 
apply-groups reference
apply-groups-exclude reference
description description
match 
dst-ip 
address (ipv6-prefix-with-host-bits | ipv6-address)
ipv6-prefix-list reference
mask ipv6-address
dst-port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
icmp 
code number
type number
next-header (number | keyword)
port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
src-ip 
address (ipv6-prefix-with-host-bits | ipv6-address)
ipv6-prefix-list reference
mask ipv6-address
src-port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
filter-id number
ipv6-filter filter-name 
apply-groups reference
apply-groups-exclude reference
chain-to-system-filter boolean
default-action keyword
description description
embed 
filter reference offset number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
entry number 
action 
accept 
apply-groups reference
apply-groups-exclude reference
drop 
drop-when 
extracted-traffic 
hop-limit 
eq number
gt number
lt number
range 
end number
start number
payload-length 
eq number
gt number
lt number
range 
end number
start number
forward 
next-hop 
nh-ip 
address ipv6-address
indirect boolean
nh-ip-vrf 
address ipv6-address
indirect boolean
router-instance string
redirect-policy reference
router-instance string
ignore-match 
rate-limit 
hop-limit 
eq number
gt number
lt number
range 
end number
start number
payload-length 
eq number
gt number
lt number
range 
end number
start number
pir (number | keyword)
policer named-item
secondary 
apply-groups reference
apply-groups-exclude reference
forward 
next-hop 
nh-ip-vrf 
address ipv6-address
indirect boolean
router-instance string
tcp-mss-adjust 
apply-groups reference
apply-groups-exclude reference
description description
log reference
match 
dscp keyword
dst-ip 
address (ipv6-prefix-with-host-bits | ipv6-address)
ipv6-prefix-list reference
mask ipv6-address
dst-port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
extension-header 
ah boolean
esp boolean
hop-by-hop boolean
routing-type0 boolean
flow-label 
mask number
value number
fragment keyword
icmp 
code number
type number
ip 
address (ipv6-prefix-with-host-bits | ipv6-address)
ipv6-prefix-list reference
mask ipv6-address
next-header (number | keyword)
next-header-list reference
port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
src-ip 
address (ipv6-prefix-with-host-bits | ipv6-address)
ipv6-prefix-list reference
mask ipv6-address
src-port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
tcp-established 
tcp-flags 
ack boolean
cwr boolean
ece boolean
fin boolean
ns boolean
psh boolean
rst boolean
syn boolean
urg boolean
pbr-down-action-override keyword
sticky-dest (number | keyword)
filter-id number
scope keyword
log number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description-or-empty
destination 
memory 
max-entries number
stop-on-full boolean
syslog 
name reference
summary 
admin-state keyword
summary-crit keyword
match-list 
apply-groups reference
apply-groups-exclude reference
ip-prefix-list named-item 
apply-groups reference
apply-groups-exclude reference
apply-path 
bgp-peers number 
apply-groups reference
apply-groups-exclude reference
group regular-expression-not-all-spaces
neighbor regular-expression-not-all-spaces
router-instance string
interfaces number 
apply-groups reference
apply-groups-exclude reference
interface regular-expression-not-all-spaces
router-instance string
description description
prefix ipv4-prefix 
prefix-exclude ipv4-prefix 
ipv6-prefix-list named-item 
apply-groups reference
apply-groups-exclude reference
apply-path 
bgp-peers number 
apply-groups reference
apply-groups-exclude reference
group regular-expression-not-all-spaces
neighbor regular-expression-not-all-spaces
router-instance string
interfaces number 
apply-groups reference
apply-groups-exclude reference
interface regular-expression-not-all-spaces
router-instance string
description description
prefix ipv6-prefix 
prefix-exclude ipv6-prefix 
port-list named-item 
apply-groups reference
apply-groups-exclude reference
description description
port number 
range start number end number 
protocol-list named-item 
apply-groups reference
apply-groups-exclude reference
description description
protocol (number | keyword) 
md-auto-id 
filter-id-range 
apply-groups reference
apply-groups-exclude reference
end number
start number
policer named-item 
apply-groups reference
apply-groups-exclude reference
description description
mbs (number | keyword)
pir number
scope keyword
redirect-policy named-item 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
destination (ipv4-address-no-zone | ipv6-address-no-zone) 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
ping-test 
apply-groups reference
apply-groups-exclude reference
drop-count number
hold-down number
interval number
source-address (ipv4-address-no-zone | ipv6-address-no-zone)
timeout number
priority number
unicast-rt-test 
notify-dest-change boolean
router-instance string
sticky-dest (number | keyword)
redirect-policy-binding named-item 
apply-groups reference
apply-groups-exclude reference
binding-operator keyword
redirect-policy reference 
apply-groups reference
apply-groups-exclude reference
destination reference 
system-filter 
apply-groups reference
apply-groups-exclude reference
ip reference 
ipv6 reference 

filter command descriptions

filter

Synopsis Enter the filter context
Context configure filter
Treefilter
Introduced25.3.R2

Platforms

7705 SAR-1

dhcp-filter [filter-id] number

Synopsis Enter the dhcp-filter list instance
Contextconfigure filter dhcp-filter number
Treedhcp-filter
Introduced25.3.R2

Platforms

7705 SAR-1

[filter-id] number
Synopsis Unique DHCP filter policy ID
Context configure filter dhcp-filter number
Treedhcp-filter
Range1 to 65535

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

default-action
Synopsis Enable the default-action context
Contextconfigure filter dhcp-filter number default-action
Treedefault-action
Introduced25.3.R2

Platforms

7705 SAR-1

drop
Synopsis DHCP host creation when the filter entry is matched
Contextconfigure filter dhcp-filter number default-action drop
Treedrop

Notes

The following elements are part of a mandatory choice: bypass-host-creation or drop.

Introduced25.3.R2

Platforms

7705 SAR-1

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure filter dhcp-filter number entry number
Treeentry
Max. instances10
Introduced25.3.R2

Platforms

7705 SAR-1

[entry-id] number
Synopsis DHCP filter entry ID
Context configure filter dhcp-filter number entry number
Treeentry
Range1 to 65535

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

action
Synopsis Enable the action context
Context configure filter dhcp-filter number entry number action
Treeaction
Introduced25.3.R2

Platforms

7705 SAR-1

drop
Synopsis DHCP host creation when the filter entry is matched
Contextconfigure filter dhcp-filter number entry number action drop
Treedrop

Notes

The following elements are part of a mandatory choice: bypass-host-creation or drop.

Introduced25.3.R2

Platforms

7705 SAR-1

option
Synopsis Enable the option context
Context configure filter dhcp-filter number entry number option
Treeoption
Introduced25.3.R2

Platforms

7705 SAR-1

absent
Synopsis Require the absence of related option
Contextconfigure filter dhcp-filter number entry number option absent
Treeabsent

Notes

The following elements are part of a mandatory choice: absent, match, or present.

Introduced25.3.R2

Platforms

7705 SAR-1

match
Synopsis Enable the match context
Context configure filter dhcp-filter number entry number option match
Treematch

Notes

The following elements are part of a mandatory choice: absent, match, or present.

Introduced25.3.R2

Platforms

7705 SAR-1

hex string
Synopsis Matching pattern for the filtered option
Contextconfigure filter dhcp-filter number entry number option match hex string
Treehex
String length1 to 256

Notes

The following elements are part of a mandatory choice: hex or string.

Introduced25.3.R2

Platforms

7705 SAR-1

string string
Synopsis Matching pattern for the filtered option
Contextconfigure filter dhcp-filter number entry number option match string string
Treestring
String length1 to 127

Notes

The following elements are part of a mandatory choice: hex or string.

Introduced25.3.R2

Platforms

7705 SAR-1

number number
Synopsis Number for DHCP or DHCPv6 option to filter on
Contextconfigure filter dhcp-filter number entry number option number number
Treenumber
Range0 to 255

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

present
Synopsis Require the presence of related option
Contextconfigure filter dhcp-filter number entry number option present
Treepresent

Notes

The following elements are part of a mandatory choice: absent, match, or present.

Introduced25.3.R2

Platforms

7705 SAR-1

dhcp6-filter [filter-id] number

Synopsis Enter the dhcp6-filter list instance
Contextconfigure filter dhcp6-filter number
Treedhcp6-filter
Introduced25.3.R2

Platforms

7705 SAR-1

[filter-id] number
Synopsis Unique DHCP filter policy ID
Context configure filter dhcp6-filter number
Treedhcp6-filter
Range1 to 65535

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure filter dhcp6-filter number entry number
Treeentry
Max. instances10
Introduced25.3.R2

Platforms

7705 SAR-1

[entry-id] number
Synopsis DHCP filter entry ID
Context configure filter dhcp6-filter number entry number
Treeentry
Range1 to 65535

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

action
Synopsis Enable the action context
Context configure filter dhcp6-filter number entry number action
Treeaction
Introduced25.3.R2

Platforms

7705 SAR-1

drop
Synopsis Drop DHCPv6 message (do not process)
Context configure filter dhcp6-filter number entry number action drop
Treedrop

Notes

The following elements are part of a mandatory choice: bypass-host-creation or drop.

Introduced25.3.R2

Platforms

7705 SAR-1

option
Synopsis Enable the option context
Context configure filter dhcp6-filter number entry number option
Treeoption
Introduced25.3.R2

Platforms

7705 SAR-1

absent
Synopsis Require the absence of related option
Contextconfigure filter dhcp6-filter number entry number option absent
Treeabsent

Notes

The following elements are part of a mandatory choice: absent, match, or present.

Introduced25.3.R2

Platforms

7705 SAR-1

match
Synopsis Enable the match context
Context configure filter dhcp6-filter number entry number option match
Treematch

Notes

The following elements are part of a mandatory choice: absent, match, or present.

Introduced25.3.R2

Platforms

7705 SAR-1

hex string
Synopsis Matching pattern for the filtered option
Contextconfigure filter dhcp6-filter number entry number option match hex string
Treehex
String length1 to 256

Notes

The following elements are part of a mandatory choice: hex or string.

Introduced25.3.R2

Platforms

7705 SAR-1

string string
Synopsis Matching pattern for the filtered option
Contextconfigure filter dhcp6-filter number entry number option match string string
Treestring
String length1 to 127

Notes

The following elements are part of a mandatory choice: hex or string.

Introduced25.3.R2

Platforms

7705 SAR-1

number number
Synopsis Number for DHCP or DHCPv6 option to filter on
Contextconfigure filter dhcp6-filter number entry number option number number
Treenumber
Range0 to 255

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

present
Synopsis Require the presence of related option
Contextconfigure filter dhcp6-filter number entry number option present
Treepresent

Notes

The following elements are part of a mandatory choice: absent, match, or present.

Introduced25.3.R2

Platforms

7705 SAR-1

ip-exception [filter-name] filter-name

Synopsis Enter the ip-exception list instance
Contextconfigure filter ip-exception filter-name
Treeip-exception
Introduced25.3.R2

Platforms

7705 SAR-1

[filter-name] filter-name
Synopsis Filter name
Contextconfigure filter ip-exception filter-name
Treeip-exception
String length1 to 64

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure filter ip-exception filter-name entry number
Treeentry
Introduced25.3.R2

Platforms

7705 SAR-1

[entry-id] number
Synopsis ID for a match criteria and the corresponding action
Contextconfigure filter ip-exception filter-name entry number
Treeentry
Range1 to 2097151

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

match
Synopsis Enter the match context
Context configure filter ip-exception filter-name entry number match
Treematch
Introduced25.3.R2

Platforms

7705 SAR-1

dst-ip
Synopsis Enter the dst-ip context
Context configure filter ip-exception filter-name entry number match dst-ip
Treedst-ip
Introduced25.3.R2

Platforms

7705 SAR-1

address (ipv4-prefix-with-host-bits | ipv4-address)
Synopsis IP address to match
Context configure filter ip-exception filter-name entry number match dst-ip address (ipv4-prefix-with-host-bits | ipv4-address)
Treeaddress
Introduced25.3.R2

Platforms

7705 SAR-1

dst-port
Synopsis Enter the dst-port context
Context configure filter ip-exception filter-name entry number match dst-port
Treedst-port
Introduced25.3.R2

Platforms

7705 SAR-1

eq number
Synopsis Exact match criterion
Context configure filter ip-exception filter-name entry number match dst-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

gt number
Synopsis Greater than match criterion for the port number
Contextconfigure filter ip-exception filter-name entry number match dst-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

lt number
Synopsis Less than match criterion for the port
Contextconfigure filter ip-exception filter-name entry number match dst-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

range
Synopsis Enable the range context
Context configure filter ip-exception filter-name entry number match dst-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

end number
Synopsis Upper bound of the port range to match
Contextconfigure filter ip-exception filter-name entry number match dst-port range end number
Treeend
Range1 to 65535

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

icmp
Synopsis Enter the icmp context
Context configure filter ip-exception filter-name entry number match icmp
Treeicmp
Introduced25.3.R2

Platforms

7705 SAR-1

code number
Synopsis ICMP code value to match
Context configure filter ip-exception filter-name entry number match icmp code number
Treecode

Description

This command specifies the ICMP code value that must be present to match. The system matches on ICMP code or ICMP type, or on both values.

An entry containing Layer 4 non-zero match criteria does not match non initial (second, third, and so on) fragments of a fragmented packet because only the first fragment contains the Layer 4 information. Similarly, an entry containing an ICMP code value of 0 match criterion may match non initial fragments when the Layer 4 header is not present in a packet fragment and other match criteria are also met.

Range0 to 255
Introduced25.3.R2

Platforms

7705 SAR-1

type number
Synopsis ICMP type value to match
Context configure filter ip-exception filter-name entry number match icmp type number
Treetype

Description

This command specifies the ICMP type value that must be present to match. The system matches on ICMP code or ICMP type, or on both values.

An entry containing Layer 4 non-zero match criteria does not match non initial (second, third, and so on) fragments of a fragmented packet because only the first fragment contains the Layer 4 information. Similarly, an entry containing an ICMP type value of 0 match criterion may match non initial fragments when the Layer 4 header is not present in a packet fragment and other match criteria are also met.

Range0 to 255
Introduced25.3.R2

Platforms

7705 SAR-1

protocol (number | keyword)
Synopsis IP protocol as the match criterion
Context configure filter ip-exception filter-name entry number match protocol (number | keyword)
Treeprotocol
Range0 to 255
Optionstcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp
Introduced 25.3.R2

Platforms

7705 SAR-1

src-ip
Synopsis Enter the src-ip context
Context configure filter ip-exception filter-name entry number match src-ip
Treesrc-ip
Introduced25.3.R2

Platforms

7705 SAR-1

address (ipv4-prefix-with-host-bits | ipv4-address)
Synopsis IP address to match
Context configure filter ip-exception filter-name entry number match src-ip address (ipv4-prefix-with-host-bits | ipv4-address)
Treeaddress
Introduced25.3.R2

Platforms

7705 SAR-1

src-port
Synopsis Enter the src-port context
Context configure filter ip-exception filter-name entry number match src-port
Treesrc-port
Introduced25.3.R2

Platforms

7705 SAR-1

eq number
Synopsis Exact match criterion
Context configure filter ip-exception filter-name entry number match src-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

gt number
Synopsis Greater than match criterion for the port number
Contextconfigure filter ip-exception filter-name entry number match src-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

lt number
Synopsis Less than match criterion for the port
Contextconfigure filter ip-exception filter-name entry number match src-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

range
Synopsis Enable the range context
Context configure filter ip-exception filter-name entry number match src-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

end number
Synopsis Upper bound of the port range to match
Contextconfigure filter ip-exception filter-name entry number match src-port range end number
Treeend
Range1 to 65535

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

filter-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisFilter ID
Contextconfigure filter ip-exception filter-name filter-id number
Treefilter-id
Range1 to 65535
Introduced25.3.R2

Platforms

7705 SAR-1

ip-filter [filter-name] filter-name

Synopsis Enter the ip-filter list instance
Contextconfigure filter ip-filter filter-name
Treeip-filter
Introduced25.3.R2

Platforms

7705 SAR-1

[filter-name] filter-name
Synopsis Filter name
Contextconfigure filter ip-filter filter-name
Treeip-filter
String length1 to 64

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

default-action keyword
Synopsis Action for packets that do not match any entry
Contextconfigure filter ip-filter filter-name default-action keyword
Treedefault-action
Optionsdrop, accept
Default drop
Introduced25.3.R2

Platforms

7705 SAR-1

description description
Synopsis Text description
Context configure filter ip-filter filter-name description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR-1

embed
Synopsis Enter the embed context
Context configure filter ip-filter filter-name embed
Treeembed

Description

Commands in this context configure filter policy embedding.

A previously defined IPv4 embedded filter policy or Hybrid OpenFlow switch instance can be embedded into an exclusive, template, or system filter policy at the specified offset value. Rules derived from BGP FlowSpec can also be embedded into template filter policies only.

Introduced25.3.R2

Platforms

7705 SAR-1

filter [name] reference offset number
Synopsis Enter the filter list instance
Contextconfigure filter ip-filter filter-name embed filter reference offset number
Treefilter

Description

Commands in this context embed a previously defined IPv4 filter policy into the filter policy at the specified offset value.

Introduced25.3.R2

Platforms

7705 SAR-1

[name] reference
Synopsis IPv4 policy to be embedded in the filter
Contextconfigure filter ip-filter filter-name embed filter reference offset number
Treefilter

Reference

configure filter ip-filter filter-name

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

offset number
Synopsis Offset of the embedded filter policy
Context configure filter ip-filter filter-name embed filter reference offset number
Treefilter

Description

This command configures the offset of the embedded filter policy. The embedded filter entry X has an entry X + offset in the embedding filter.

Range0 to 2097150

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure filter ip-filter filter-name entry number
Treeentry
Introduced25.3.R2

Platforms

7705 SAR-1

[entry-id] number
Synopsis ID for a match criteria and the corresponding action
Contextconfigure filter ip-filter filter-name entry number
Treeentry
Range1 to 2097151

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

action
Synopsis Enable the action context
Context configure filter ip-filter filter-name entry number action
Treeaction
Introduced25.3.R2

Platforms

7705 SAR-1

accept
Synopsis Accept regular routing to forward a matching packet
Contextconfigure filter ip-filter filter-name entry number action accept
Treeaccept

Notes

The following elements are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.

Introduced25.3.R2

Platforms

7705 SAR-1

drop
Synopsis Drop a packet matching this entry
Context configure filter ip-filter filter-name entry number action drop
Treedrop

Notes

The following elements are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.

Introduced25.3.R2

Platforms

7705 SAR-1

drop-when
Synopsis Enable the drop-when context
Context configure filter ip-filter filter-name entry number action drop-when
Treedrop-when
Introduced25.3.R2

Platforms

7705 SAR-1

packet-length
Synopsis Enable the packet-length context
Contextconfigure filter ip-filter filter-name entry number action drop-when packet-length
Treepacket-length

Notes

The following elements are part of a choice: packet-length or ttl.

Introduced25.3.R2

Platforms

7705 SAR-1

eq number
Synopsis Exact match criterion for the length
Context configure filter ip-filter filter-name entry number action drop-when packet-length eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

gt number
Synopsis Greater than match criterion for the length
Contextconfigure filter ip-filter filter-name entry number action drop-when packet-length gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

lt number
Synopsis Less than match criterion for the length
Contextconfigure filter ip-filter filter-name entry number action drop-when packet-length lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

range
Synopsis Enable the range context
Context configure filter ip-filter filter-name entry number action drop-when packet-length range
Treerange

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

ttl
Synopsis Enable the ttl context
Context configure filter ip-filter filter-name entry number action drop-when ttl
Treettl

Notes

The following elements are part of a choice: packet-length or ttl.

Introduced25.3.R2

Platforms

7705 SAR-1

eq number
Synopsis Equal to condition match value
Context configure filter ip-filter filter-name entry number action drop-when ttl eq number
Treeeq
Range0 to 255

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

gt number
Synopsis Greater than condition match value
Context configure filter ip-filter filter-name entry number action drop-when ttl gt number
Treegt
Range0 to 254

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

lt number
Synopsis Less than condition match value
Context configure filter ip-filter filter-name entry number action drop-when ttl lt number
Treelt
Range1 to 255

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

range
Synopsis Enable the range context
Context configure filter ip-filter filter-name entry number action drop-when ttl range
Treerange

Description

This command in this context specify an inclusive range. When range is used, the start of the range (the first value entered) must be smaller than the end of the range (the second value entered).

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

forward
Synopsis Enter the forward context
Context configure filter ip-filter filter-name entry number action forward
Treeforward

Notes

The following elements are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.

Introduced25.3.R2

Platforms

7705 SAR-1

next-hop
Synopsis Enable the next-hop context
Context configure filter ip-filter filter-name entry number action forward next-hop
Treenext-hop

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, srv6-policy, or vprn-target.

Introduced25.3.R2

Platforms

7705 SAR-1

nh-ip
Synopsis Enable the nh-ip context
Context configure filter ip-filter filter-name entry number action forward next-hop nh-ip
Treenh-ip

Notes

The following elements are part of a mandatory choice: interface-name, nh-ip, or nh-ip-vrf.

Introduced25.3.R2

Platforms

7705 SAR-1

address ipv4-address
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIPv4 address of next hop to forward matching packets
Contextconfigure filter ip-filter filter-name entry number action forward next-hop nh-ip address ipv4-address
Treeaddress

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

nh-ip-vrf
Synopsis Enable the nh-ip-vrf context
Context configure filter ip-filter filter-name entry number action forward next-hop nh-ip-vrf
Treenh-ip-vrf

Notes

The following elements are part of a mandatory choice: interface-name, nh-ip, or nh-ip-vrf.

Introduced25.3.R2

Platforms

7705 SAR-1

address ipv4-address
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIPv4 address of next hop to forward matching packets
Contextconfigure filter ip-filter filter-name entry number action forward next-hop nh-ip-vrf address ipv4-address
Treeaddress

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

router-instance string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisRouting context for route lookup for forwarding packets
Contextconfigure filter ip-filter filter-name entry number action forward next-hop nh-ip-vrf router-instance string
Treerouter-instance

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

redirect-policy reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNext hop or forward next hop router that forwards a packet that matches this entry
Contextconfigure filter ip-filter filter-name entry number action forward redirect-policy reference
Treeredirect-policy

Reference

configure filter redirect-policy named-item

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, srv6-policy, or vprn-target.

Introduced25.3.R2

Platforms

7705 SAR-1

router-instance string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisRouter name or VPRN service name
Contextconfigure filter ip-filter filter-name entry number action forward router-instance string
Treerouter-instance

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, srv6-policy, or vprn-target.

Introduced25.3.R2

Platforms

7705 SAR-1

ignore-match
Synopsis Ignore match criteria for the entry
Context configure filter ip-filter filter-name entry number action ignore-match
Treeignore-match

Notes

The following elements are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.

Introduced25.3.R2

Platforms

7705 SAR-1

nat
Synopsis Enable the nat context
Context configure filter ip-filter filter-name entry number action nat
Treenat

Notes

The following elements are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.

Introduced25.3.R2

Platforms

7705 SAR-1

nat-policy reference
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisNAT policy name when action is NAT
Contextconfigure filter ip-filter filter-name entry number action nat nat-policy reference
Treenat-policy

Reference

configure service nat nat-policy external-named-item

Introduced25.3.R2

Platforms

7705 SAR-1

rate-limit
Synopsis Enable the rate-limit context
Context configure filter ip-filter filter-name entry number action rate-limit
Treerate-limit

Description

Commands in this context configure the rate-limit action for traffic that matches this filter entry.

Introduced25.3.R2

Platforms

7705 SAR-1

packet-length
Synopsis Enable the packet-length context
Contextconfigure filter ip-filter filter-name entry number action rate-limit packet-length
Treepacket-length

Notes

The following elements are part of a choice: packet-length or ttl.

Introduced25.3.R2

Platforms

7705 SAR-1

eq number
Synopsis Exact match criterion for the length
Context configure filter ip-filter filter-name entry number action rate-limit packet-length eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

gt number
Synopsis Greater than match criterion for the length
Contextconfigure filter ip-filter filter-name entry number action rate-limit packet-length gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

lt number
Synopsis Less than match criterion for the length
Contextconfigure filter ip-filter filter-name entry number action rate-limit packet-length lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

range
Synopsis Enable the range context
Context configure filter ip-filter filter-name entry number action rate-limit packet-length range
Treerange

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

pir (number | keyword)
Synopsis Peak information rate
Context configure filter ip-filter filter-name entry number action rate-limit pir (number | keyword)
Treepir
Range0 to 2000000000
Unitskilobps
Options max

Notes

The following elements are part of a mandatory choice: pir, policer, or pps-pir.

Introduced25.3.R2

Platforms

7705 SAR-1

policer named-item
Synopsis Policer name to use for rate limiting traffic
Contextconfigure filter ip-filter filter-name entry number action rate-limit policer named-item
Treepolicer
String length1 to 32

Notes

The following elements are part of a mandatory choice: pir, policer, or pps-pir.

Introduced25.3.R2

Platforms

7705 SAR-1

ttl
Synopsis Enable the ttl context
Context configure filter ip-filter filter-name entry number action rate-limit ttl
Treettl

Notes

The following elements are part of a choice: packet-length or ttl.

Introduced25.3.R2

Platforms

7705 SAR-1

eq number
Synopsis Equal to condition match value
Context configure filter ip-filter filter-name entry number action rate-limit ttl eq number
Treeeq
Range0 to 255

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

gt number
Synopsis Greater than condition match value
Context configure filter ip-filter filter-name entry number action rate-limit ttl gt number
Treegt
Range0 to 254

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

lt number
Synopsis Less than condition match value
Context configure filter ip-filter filter-name entry number action rate-limit ttl lt number
Treelt
Range1 to 255

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

range
Synopsis Enable the range context
Context configure filter ip-filter filter-name entry number action rate-limit ttl range
Treerange

Description

This command in this context specify an inclusive range. When range is used, the start of the range (the first value entered) must be smaller than the end of the range (the second value entered).

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

reassemble
Synopsis Forward matching packets to reassembly function
Contextconfigure filter ip-filter filter-name entry number action reassemble
Treereassemble

Notes

The following elements are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.

Introduced25.3.R2

Platforms

7705 SAR-1

secondary
Synopsis Enable the secondary context
Context configure filter ip-filter filter-name entry number action secondary
Treesecondary
Introduced25.3.R2

Platforms

7705 SAR-1

forward
Synopsis Enter the forward context
Context configure filter ip-filter filter-name entry number action secondary forward
Treeforward

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

next-hop
Synopsis Enable the next-hop context
Context configure filter ip-filter filter-name entry number action secondary forward next-hop
Treenext-hop

Notes

The following elements are part of a choice: next-hop, sap, sdp, or vprn-target.

Introduced25.3.R2

Platforms

7705 SAR-1

nh-ip-vrf
Synopsis Enable the nh-ip-vrf context
Context configure filter ip-filter filter-name entry number action secondary forward next-hop nh-ip-vrf
Treenh-ip-vrf

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

address ipv4-address
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIPv4 address of next hop to forward matching packets
Contextconfigure filter ip-filter filter-name entry number action secondary forward next-hop nh-ip-vrf address ipv4-address
Treeaddress

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

tcp-mss-adjust
Synopsis Adjust MSS option of TCP matching packets to configured value of tcp-mss in router interface context
Contextconfigure filter ip-filter filter-name entry number action tcp-mss-adjust
Treetcp-mss-adjust

Notes

The following elements are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.

Introduced25.3.R2

Platforms

7705 SAR-1

log reference
Synopsis Log that is used for packets matching this entry
Contextconfigure filter ip-filter filter-name entry number log reference
Treelog

Reference

configure filter log number

Introduced25.3.R2

Platforms

7705 SAR-1

match
Synopsis Enter the match context
Context configure filter ip-filter filter-name entry number match
Treematch

Description

Commands in this context configure match criteria for the filter entry. When the match criteria are satisfied, the action associated with the match criteria is executed.

Introduced25.3.R2

Platforms

7705 SAR-1

dscp keyword
Synopsis DSCP used as an IP filter match criterion
Contextconfigure filter ip-filter filter-name entry number match dscp keyword
Treedscp
Optionsbe, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63
Introduced 25.3.R2

Platforms

7705 SAR-1

dst-ip
Synopsis Enter the dst-ip context
Context configure filter ip-filter filter-name entry number match dst-ip
Treedst-ip

Description

Commands in this context configure a destination address range that is used by filter policy match criteria.

Notes

The following elements are part of a choice: ip or (dst-ip and src-ip).

Introduced25.3.R2

Platforms

7705 SAR-1

address (ipv4-prefix-with-host-bits | ipv4-address)
Synopsis IPv4 address used as the match criterion
Contextconfigure filter ip-filter filter-name entry number match dst-ip address (ipv4-prefix-with-host-bits | ipv4-address)
Treeaddress

Notes

The following elements are part of a choice: (address and mask) or ip-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR-1

mask ipv4-address
Synopsis IPv4 address mask used as the match criterion
Contextconfigure filter ip-filter filter-name entry number match dst-ip mask ipv4-address
Treemask

Notes

The following elements are part of a choice: (address and mask) or ip-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR-1

dst-port
Synopsis Enter the dst-port context
Context configure filter ip-filter filter-name entry number match dst-port
Treedst-port

Description

Commands in this context configure match criteria for the destination port.

Notes

The following elements are part of a choice: port or (dst-port and src-port).

Introduced25.3.R2

Platforms

7705 SAR-1

eq number
Synopsis Exact value as the match criterion
Context configure filter ip-filter filter-name entry number match dst-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

gt number
Synopsis Greater than value as the match criterion
Contextconfigure filter ip-filter filter-name entry number match dst-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

lt number
Synopsis Less than value as the match criterion
Contextconfigure filter ip-filter filter-name entry number match dst-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

range
Synopsis Enable the range context
Context configure filter ip-filter filter-name entry number match dst-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

end number
Synopsis Upper bound of the port range
Context configure filter ip-filter filter-name entry number match dst-port range end number
Treeend
Range1 to 65535

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

start number
Synopsis Lower bound of the port range
Context configure filter ip-filter filter-name entry number match dst-port range start number
Treestart
Range0 to 65534

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

fragment keyword
Synopsis Match criterion for fragmented packets
Contextconfigure filter ip-filter filter-name entry number match fragment keyword
Treefragment
Optionsfalse, true, first-only, non-first-only
Introduced25.3.R2

Platforms

7705 SAR-1

icmp
Synopsis Enter the icmp context
Context configure filter ip-filter filter-name entry number match icmp
Treeicmp

Description

Commands in this context configure ICMP values to use as IP filter match criteria.

Introduced25.3.R2

Platforms

7705 SAR-1

code number
Synopsis ICMP code value to match
Context configure filter ip-filter filter-name entry number match icmp code number
Treecode

Description

This command specifies the ICMP code value that must be present to match. The system matches on ICMP code or ICMP type, or on both values.

An entry containing Layer 4 non-zero match criteria does not match non initial (second, third, and so on) fragments of a fragmented packet because only the first fragment contains the Layer 4 information. Similarly, an entry containing an ICMP code value of 0 match criterion may match non initial fragments when the Layer 4 header is not present in a packet fragment and other match criteria are also met.

Range0 to 255
Introduced25.3.R2

Platforms

7705 SAR-1

type number
Synopsis ICMP type value to match
Context configure filter ip-filter filter-name entry number match icmp type number
Treetype

Description

This command specifies the ICMP type value that must be present to match. The system matches on ICMP code or ICMP type, or on both values.

An entry containing Layer 4 non-zero match criteria does not match non initial (second, third, and so on) fragments of a fragmented packet because only the first fragment contains the Layer 4 information. Similarly, an entry containing an ICMP type value of 0 match criterion may match non initial fragments when the Layer 4 header is not present in a packet fragment and other match criteria are also met.

Range0 to 255
Introduced25.3.R2

Platforms

7705 SAR-1

ip
Synopsis Enter the ip context
Context configure filter ip-filter filter-name entry number match ip
Treeip

Notes

The following elements are part of a choice: ip or (dst-ip and src-ip).

Introduced25.3.R2

Platforms

7705 SAR-1

address (ipv4-prefix-with-host-bits | ipv4-address)
Synopsis IPv4 address used as the match criterion
Contextconfigure filter ip-filter filter-name entry number match ip address (ipv4-prefix-with-host-bits | ipv4-address)
Treeaddress

Notes

The following elements are part of a choice: (address and mask) or ip-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR-1

mask ipv4-address
Synopsis IPv4 address mask used as the match criterion
Contextconfigure filter ip-filter filter-name entry number match ip mask ipv4-address
Treemask

Notes

The following elements are part of a choice: (address and mask) or ip-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR-1

ip-option
Synopsis Enable the ip-option context
Context configure filter ip-filter filter-name entry number match ip-option
Treeip-option

Description

Commands in this context configure matching packets with a specific IP option, or a range of IP options, in the first option of the IP header as an IP filter match criterion.

Introduced25.3.R2

Platforms

7705 SAR-1

mask number
Synopsis Mask used with the IP option value in the packet header
Contextconfigure filter ip-filter filter-name entry number match ip-option mask number
Treemask

Description

This command specifies an optional value that can be used when specifying a range of option numbers to use as the match criteria.

Range1 to 255
Default255
Introduced 25.3.R2

Platforms

7705 SAR-1

type number
Synopsis IP option to match
Context configure filter ip-filter filter-name entry number match ip-option type number
Treetype

Description

This command specifies the 8-bit option type in decimal integer, binary, or hexadecimal format. The mask is applied as an AND to the option byte, and the result is compared with the option value.

The decimal value entered for the match should be a combined value of the 8-bit option type field and not only the option number. For example, to match IP packets that contain the Router Alert option (option number = 20), enter the option type of 148 (10010100).

Range0 to 255

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

option-present boolean
Synopsis Match on any IP option present in the packet
Contextconfigure filter ip-filter filter-name entry number match option-present boolean
Treeoption-present

Description

When configured to true, the router matches on IP packets that contain any IP option in the IP header. An option field of zero is considered as no option present.

When configured to false, the router matches on IP packets that do not have an IP option present in the IP header.

Introduced25.3.R2

Platforms

7705 SAR-1

port
Synopsis Enter the port context
Context configure filter ip-filter filter-name entry number match port
Treeport

Notes

The following elements are part of a choice: port or (dst-port and src-port).

Introduced25.3.R2

Platforms

7705 SAR-1

eq number
Synopsis Exact value as the match criterion
Context configure filter ip-filter filter-name entry number match port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

gt number
Synopsis Greater than value as the match criterion
Contextconfigure filter ip-filter filter-name entry number match port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

lt number
Synopsis Less than value as the match criterion
Contextconfigure filter ip-filter filter-name entry number match port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

range
Synopsis Enable the range context
Context configure filter ip-filter filter-name entry number match port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

end number
Synopsis Upper bound of the port range
Context configure filter ip-filter filter-name entry number match port range end number
Treeend
Range1 to 65535

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

start number
Synopsis Lower bound of the port range
Context configure filter ip-filter filter-name entry number match port range start number
Treestart
Range0 to 65534

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

protocol (number | keyword)
Synopsis IP protocol identifier as a match criterion
Contextconfigure filter ip-filter filter-name entry number match protocol (number | keyword)
Treeprotocol
Range0 to 255
Optionstcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp

Notes

The following elements are part of a choice: protocol or protocol-list.

Introduced25.3.R2

Platforms

7705 SAR-1

src-ip
Synopsis Enter the src-ip context
Context configure filter ip-filter filter-name entry number match src-ip
Treesrc-ip

Description

Commands in this context configure a source address range that is used by filter policy match criteria.

Notes

The following elements are part of a choice: ip or (dst-ip and src-ip).

Introduced25.3.R2

Platforms

7705 SAR-1

address (ipv4-prefix-with-host-bits | ipv4-address)
Synopsis IPv4 address used as the match criterion
Contextconfigure filter ip-filter filter-name entry number match src-ip address (ipv4-prefix-with-host-bits | ipv4-address)
Treeaddress

Notes

The following elements are part of a choice: (address and mask) or ip-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR-1

mask ipv4-address
Synopsis IPv4 address mask used as the match criterion
Contextconfigure filter ip-filter filter-name entry number match src-ip mask ipv4-address
Treemask

Notes

The following elements are part of a choice: (address and mask) or ip-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR-1

src-port
Synopsis Enter the src-port context
Context configure filter ip-filter filter-name entry number match src-port
Treesrc-port

Description

Commands in this context configure match criteria for the source port.

Notes

The following elements are part of a choice: port or (dst-port and src-port).

Introduced25.3.R2

Platforms

7705 SAR-1

eq number
Synopsis Exact value as the match criterion
Context configure filter ip-filter filter-name entry number match src-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

gt number
Synopsis Greater than value as the match criterion
Contextconfigure filter ip-filter filter-name entry number match src-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

lt number
Synopsis Less than value as the match criterion
Contextconfigure filter ip-filter filter-name entry number match src-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

range
Synopsis Enable the range context
Context configure filter ip-filter filter-name entry number match src-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

end number
Synopsis Upper bound of the port range
Context configure filter ip-filter filter-name entry number match src-port range end number
Treeend
Range1 to 65535

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

start number
Synopsis Lower bound of the port range
Context configure filter ip-filter filter-name entry number match src-port range start number
Treestart
Range0 to 65534

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

tcp-established
Synopsis Use ACK or RST status in TCP header as match criterion
Contextconfigure filter ip-filter filter-name entry number match tcp-established
Treetcp-established

Description

When configured to true, a match occurs when the ACK or the RST TCP flag bit is set in the TCP header of an IP packet.

Notes

The following elements are part of a choice: tcp-established or tcp-flags.

Introduced25.3.R2

Platforms

7705 SAR-1

tcp-flags
Synopsis Enter the tcp-flags context
Context configure filter ip-filter filter-name entry number match tcp-flags
Treetcp-flags

Description

Commands in this context configure the use of TCP flags as the IP filter match.

Notes

The following elements are part of a choice: tcp-established or tcp-flags.

Introduced25.3.R2

Platforms

7705 SAR-1

ack boolean
Synopsis Use ACK TCP bit status in TCP header as match criterion
Contextconfigure filter ip-filter filter-name entry number match tcp-flags ack boolean
Treeack

Description

When configured to true, a match occurs when the ACK TCP flag bit, defined in RFC 793, is set in the TCP header of an IP packet.

When configured to false, a match occurs when the ACK TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR-1

cwr boolean
Synopsis Use CWR TCP bit status in TCP header as match criterion
Contextconfigure filter ip-filter filter-name entry number match tcp-flags cwr boolean
Treecwr

Description

When configured to true, a match occurs when the Congestion Window Reduced (CWR) TCP flag bit, defined in RFC 3168, is set in the TCP header of an IP packet.

When configured to false, a match occurs when the CWR TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR-1

ece boolean
Synopsis Use ECE TCP bit status in TCP header as match criterion
Contextconfigure filter ip-filter filter-name entry number match tcp-flags ece boolean
Treeece

Description

When configured to true, a match occurs when the ECN-Echo (ECE) TCP flag bit, defined in RFC 3168, is set in the TCP header of an IP packet.

When configured to false, a match occurs when the ECE TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR-1

fin boolean
Synopsis Use FIN TCP bit status in TCP header as match criterion
Contextconfigure filter ip-filter filter-name entry number match tcp-flags fin boolean
Treefin

Description

When configured to true, a match occurs when the FIN TCP flag bit is set in the TCP header of an IP packet.

When configured to false, a match occurs when the FIN TCP flag bit, defined in RFC 793, is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR-1

ns boolean
Synopsis Use NS TCP bit status in TCP header as match criterion
Contextconfigure filter ip-filter filter-name entry number match tcp-flags ns boolean
Treens

Description

When configured to true, a match occurs when the Nonce Sum (NS) TCP flag bit, defined in RFC 3540, is set in the TCP header of an IP packet.

When configured to false, a match occurs when the NS TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR-1

psh boolean
Synopsis Use PSH TCP bit status in TCP header as match criterion
Contextconfigure filter ip-filter filter-name entry number match tcp-flags psh boolean
Treepsh

Description

When configured to true, a match occurs when the Push (PSH) TCP flag bit is set in the TCP header of an IP packet.

When configured to false, a match occurs when the Push (PSH) TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR-1

rst boolean
Synopsis Use RST TCP bit status in TCP header as match criterion
Contextconfigure filter ip-filter filter-name entry number match tcp-flags rst boolean
Treerst

Description

When configured to true, a match occurs when the RST TCP flag bit is set in the TCP header of an IP packet.

When configured to false, a match occurs when the RST TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR-1

syn boolean
Synopsis Use SYN TCP bit status in TCP header as match criterion
Contextconfigure filter ip-filter filter-name entry number match tcp-flags syn boolean
Treesyn

Description

When configured to true, a match occurs when the Synchronize (SYN) TCP flag bit is set in the TCP header of an IP packet.

When configured to false, a match occurs when the SYN TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR-1

urg boolean
Synopsis Use URG TCP bit status in TCP header as match criterion
Contextconfigure filter ip-filter filter-name entry number match tcp-flags urg boolean
Treeurg

Description

When configured to true, a match occurs when the Urgent (URG) TCP flag bit is set in the TCP header of an IP packet.

When configured to false, a match occurs when the URG TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR-1

sticky-dest (number | keyword)
Synopsis Time before action with available PBR or PBF destination and highest priority
Contextconfigure filter ip-filter filter-name entry number sticky-dest (number | keyword)
Treesticky-dest
Range0 to 65535
Unitsseconds
Options no-hold-time-up
Introduced25.3.R2

Platforms

7705 SAR-1

filter-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP filter ID
Contextconfigure filter ip-filter filter-name filter-id number
Treefilter-id
Range1 to 65535
Introduced25.3.R2

Platforms

7705 SAR-1

scope keyword
Synopsis Scope of the filter definition
Context configure filter ip-filter filter-name scope keyword
Treescope

Description

This command configures the filter policy scope.

If the scope of the policy is template and is applied to one or more services or network interfaces, the scope cannot be changed.

Optionsexclusive, template, embedded, system, cpm
Defaulttemplate
Introduced25.3.R2

Platforms

7705 SAR-1

ipv6-exception [filter-name] filter-name

Synopsis Enter the ipv6-exception list instance
Contextconfigure filter ipv6-exception filter-name
Treeipv6-exception
Introduced25.3.R2

Platforms

7705 SAR-1

[filter-name] filter-name
Synopsis Filter name
Contextconfigure filter ipv6-exception filter-name
Treeipv6-exception
String length1 to 64

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure filter ipv6-exception filter-name entry number
Treeentry
Introduced25.3.R2

Platforms

7705 SAR-1

[entry-id] number
Synopsis ID for a match criteria and the corresponding action
Contextconfigure filter ipv6-exception filter-name entry number
Treeentry
Range1 to 2097151

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

match
Synopsis Enter the match context
Context configure filter ipv6-exception filter-name entry number match
Treematch
Introduced25.3.R2

Platforms

7705 SAR-1

dst-ip
Synopsis Enter the dst-ip context
Context configure filter ipv6-exception filter-name entry number match dst-ip
Treedst-ip
Introduced25.3.R2

Platforms

7705 SAR-1

address (ipv6-prefix-with-host-bits | ipv6-address)
Synopsis IPv6 address used as the match criterion
Contextconfigure filter ipv6-exception filter-name entry number match dst-ip address (ipv6-prefix-with-host-bits | ipv6-address)
Treeaddress

Notes

The following elements are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR-1

mask ipv6-address
Synopsis IPv6 address mask used as the match criterion
Contextconfigure filter ipv6-exception filter-name entry number match dst-ip mask ipv6-address
Treemask

Notes

The following elements are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR-1

dst-port
Synopsis Enter the dst-port context
Context configure filter ipv6-exception filter-name entry number match dst-port
Treedst-port

Description

Commands in this context configure match criteria for the destination port.

Notes

The following elements are part of a choice: port or (dst-port and src-port).

Introduced25.3.R2

Platforms

7705 SAR-1

eq number
Synopsis Exact value as the match criterion
Context configure filter ipv6-exception filter-name entry number match dst-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

gt number
Synopsis Greater than value as the match criterion
Contextconfigure filter ipv6-exception filter-name entry number match dst-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

lt number
Synopsis Less than value as the match criterion
Contextconfigure filter ipv6-exception filter-name entry number match dst-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

range
Synopsis Enable the range context
Context configure filter ipv6-exception filter-name entry number match dst-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

icmp
Synopsis Enter the icmp context
Context configure filter ipv6-exception filter-name entry number match icmp
Treeicmp
Introduced25.3.R2

Platforms

7705 SAR-1

code number
Synopsis ICMPv6 code value to match
Context configure filter ipv6-exception filter-name entry number match icmp code number
Treecode

Description

This command specifies the ICMPv6 code value that must be present to match. The system matches on ICMP code or ICMP type, or on both values.

An entry containing Layer 4 non-zero match criteria does not match non initial (second, third, and so on) fragments of a fragmented packet because only the first fragment contains the Layer 4 information. Similarly, an entry containing an ICMP code value of 0 match criterion may match non-initial fragments when the Layer 4 header is not present in a packet fragment and other match criteria are also met.

Range0 to 255
Introduced25.3.R2

Platforms

7705 SAR-1

type number
Synopsis ICMPv6 type value to match
Context configure filter ipv6-exception filter-name entry number match icmp type number
Treetype

Description

This command specifies the ICMPv6 type value that must be present to match. The system matches on ICMP code or ICMP type, or on both values.

An entry containing Layer 4 non-zero match criteria does not match non initial (second, third, and so on) fragments of a fragmented packet because only the first fragment contains the Layer 4 information. Similarly, an entry containing an ICMP type value of 0 match criterion may match non initial fragments when the Layer 4 header is not present in a packet fragment and other match criteria are also met.

Range0 to 255
Introduced25.3.R2

Platforms

7705 SAR-1

next-header (number | keyword)
Synopsis IP protocol to match
Context configure filter ipv6-exception filter-name entry number match next-header (number | keyword)
Treenext-header
Range0 to 255
Optionstcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp
Introduced 25.3.R2

Platforms

7705 SAR-1

port
Synopsis Enter the port context
Context configure filter ipv6-exception filter-name entry number match port
Treeport

Notes

The following elements are part of a choice: port or (dst-port and src-port).

Introduced25.3.R2

Platforms

7705 SAR-1

eq number
Synopsis Exact value as the match criterion
Context configure filter ipv6-exception filter-name entry number match port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

gt number
Synopsis Greater than value as the match criterion
Contextconfigure filter ipv6-exception filter-name entry number match port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

lt number
Synopsis Less than value as the match criterion
Contextconfigure filter ipv6-exception filter-name entry number match port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

range
Synopsis Enable the range context
Context configure filter ipv6-exception filter-name entry number match port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

end number
Synopsis Upper bound of the port range
Context configure filter ipv6-exception filter-name entry number match port range end number
Treeend
Range1 to 65535

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

src-ip
Synopsis Enter the src-ip context
Context configure filter ipv6-exception filter-name entry number match src-ip
Treesrc-ip
Introduced25.3.R2

Platforms

7705 SAR-1

address (ipv6-prefix-with-host-bits | ipv6-address)
Synopsis IPv6 address used as the match criterion
Contextconfigure filter ipv6-exception filter-name entry number match src-ip address (ipv6-prefix-with-host-bits | ipv6-address)
Treeaddress

Notes

The following elements are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR-1

mask ipv6-address
Synopsis IPv6 address mask used as the match criterion
Contextconfigure filter ipv6-exception filter-name entry number match src-ip mask ipv6-address
Treemask

Notes

The following elements are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR-1

src-port
Synopsis Enter the src-port context
Context configure filter ipv6-exception filter-name entry number match src-port
Treesrc-port

Description

Commands in this context configure match criteria for the source port.

Notes

The following elements are part of a choice: port or (dst-port and src-port).

Introduced25.3.R2

Platforms

7705 SAR-1

eq number
Synopsis Exact value as the match criterion
Context configure filter ipv6-exception filter-name entry number match src-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

gt number
Synopsis Greater than value as the match criterion
Contextconfigure filter ipv6-exception filter-name entry number match src-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

lt number
Synopsis Less than value as the match criterion
Contextconfigure filter ipv6-exception filter-name entry number match src-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

range
Synopsis Enable the range context
Context configure filter ipv6-exception filter-name entry number match src-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

filter-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisFilter ID
Contextconfigure filter ipv6-exception filter-name filter-id number
Treefilter-id
Range1 to 65535
Introduced25.3.R2

Platforms

7705 SAR-1

ipv6-filter [filter-name] filter-name

Synopsis Enter the ipv6-filter list instance
Contextconfigure filter ipv6-filter filter-name
Treeipv6-filter

Description

Commands in this context create a configuration context for the specified IPv6 filter entry.

Introduced25.3.R2

Platforms

7705 SAR-1

[filter-name] filter-name
Synopsis Filter name
Contextconfigure filter ipv6-filter filter-name
Treeipv6-filter
String length1 to 64

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

default-action keyword
Synopsis Action for packets that do not match any entry
Contextconfigure filter ipv6-filter filter-name default-action keyword
Treedefault-action
Optionsdrop, accept
Default drop
Introduced25.3.R2

Platforms

7705 SAR-1

description description
Synopsis Text description
Context configure filter ipv6-filter filter-name description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR-1

embed
Synopsis Enter the embed context
Context configure filter ipv6-filter filter-name embed
Treeembed

Description

Commands in this context configure filter policy embedding.

A previously defined IPv6 embedded filter policy or Hybrid OpenFlow switch instance can be embedded into an exclusive, template, or system filter policy at the specified offset value. Rules derived from BGP FlowSpec can also be embedded into template filter policies only.

Introduced25.3.R2

Platforms

7705 SAR-1

filter [name] reference offset number
Synopsis Enter the filter list instance
Contextconfigure filter ipv6-filter filter-name embed filter reference offset number
Treefilter

Description

Commands in this context embed a previously defined IPv6 filter policy into the filter policy at the specified offset value.

Introduced25.3.R2

Platforms

7705 SAR-1

[name] reference
Synopsis IPv6 policy to be embedded in the filter
Contextconfigure filter ipv6-filter filter-name embed filter reference offset number
Treefilter

Reference

configure filter ipv6-filter filter-name

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

offset number
Synopsis Offset of the embedded filter policy
Context configure filter ipv6-filter filter-name embed filter reference offset number
Treefilter

Description

This command configures the offset of the embedded filter policy. The embedded filter entry X has an entry X + offset in the embedding filter.

Range0 to 2097150

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure filter ipv6-filter filter-name entry number
Treeentry

Description

Commands in this context create or edit a configuration context for the specified IPv6 filter entry.

Introduced25.3.R2

Platforms

7705 SAR-1

[entry-id] number
Synopsis ID for a match criteria and the corresponding action
Contextconfigure filter ipv6-filter filter-name entry number
Treeentry
Range1 to 2097151

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

action
Synopsis Enable the action context
Context configure filter ipv6-filter filter-name entry number action
Treeaction
Introduced25.3.R2

Platforms

7705 SAR-1

accept
Synopsis Accept regular routing to forward a matching packet
Contextconfigure filter ipv6-filter filter-name entry number action accept
Treeaccept

Notes

The following elements are part of a mandatory choice: accept, drop, forward, http-redirect, ignore-match, nat, or tcp-mss-adjust.

Introduced25.3.R2

Platforms

7705 SAR-1

drop
Synopsis Drop a packet matching this entry
Context configure filter ipv6-filter filter-name entry number action drop
Treedrop

Notes

The following elements are part of a mandatory choice: accept, drop, forward, http-redirect, ignore-match, nat, or tcp-mss-adjust.

Introduced25.3.R2

Platforms

7705 SAR-1

drop-when
Synopsis Enable the drop-when context
Context configure filter ipv6-filter filter-name entry number action drop-when
Treedrop-when
Introduced25.3.R2

Platforms

7705 SAR-1

hop-limit
Synopsis Enable the hop-limit context
Context configure filter ipv6-filter filter-name entry number action drop-when hop-limit
Treehop-limit

Notes

The following elements are part of a choice: hop-limit or payload-length.

Introduced25.3.R2

Platforms

7705 SAR-1

eq number
Synopsis Equal to condition match value
Context configure filter ipv6-filter filter-name entry number action drop-when hop-limit eq number
Treeeq
Range0 to 255

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

gt number
Synopsis Greater than condition match value
Context configure filter ipv6-filter filter-name entry number action drop-when hop-limit gt number
Treegt
Range0 to 254

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

lt number
Synopsis Less than condition match value
Context configure filter ipv6-filter filter-name entry number action drop-when hop-limit lt number
Treelt
Range1 to 255

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

range
Synopsis Enable the range context
Context configure filter ipv6-filter filter-name entry number action drop-when hop-limit range
Treerange

Description

This command in this context specify an inclusive range. When range is used, the start of the range (the first value entered) must be smaller than the end of the range (the second value entered).

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

payload-length
Synopsis Enable the payload-length context
Contextconfigure filter ipv6-filter filter-name entry number action drop-when payload-length
Treepayload-length

Notes

The following elements are part of a choice: hop-limit or payload-length.

Introduced25.3.R2

Platforms

7705 SAR-1

eq number
Synopsis Exact match criterion for the length
Context configure filter ipv6-filter filter-name entry number action drop-when payload-length eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

gt number
Synopsis Greater than match criterion for the length
Contextconfigure filter ipv6-filter filter-name entry number action drop-when payload-length gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

lt number
Synopsis Less than match criterion for the length
Contextconfigure filter ipv6-filter filter-name entry number action drop-when payload-length lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

range
Synopsis Enable the range context
Context configure filter ipv6-filter filter-name entry number action drop-when payload-length range
Treerange

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

forward
Synopsis Enter the forward context
Context configure filter ipv6-filter filter-name entry number action forward
Treeforward

Notes

The following elements are part of a mandatory choice: accept, drop, forward, http-redirect, ignore-match, nat, or tcp-mss-adjust.

Introduced25.3.R2

Platforms

7705 SAR-1

next-hop
Synopsis Enable the next-hop context
Context configure filter ipv6-filter filter-name entry number action forward next-hop
Treenext-hop

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, srv6-policy, or vprn-target.

Introduced25.3.R2

Platforms

7705 SAR-1

nh-ip
Synopsis Enable the nh-ip context
Context configure filter ipv6-filter filter-name entry number action forward next-hop nh-ip
Treenh-ip

Notes

The following elements are part of a mandatory choice: nh-ip or nh-ip-vrf.

Introduced25.3.R2

Platforms

7705 SAR-1

address ipv6-address
Synopsis IPv6 address of next hop to forward matching packets
Contextconfigure filter ipv6-filter filter-name entry number action forward next-hop nh-ip address ipv6-address
Treeaddress

Description

This command specifies the IPv6 address of a direct or indirect next hop to which matching packets are forwarded.

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

nh-ip-vrf
Synopsis Enable the nh-ip-vrf context
Context configure filter ipv6-filter filter-name entry number action forward next-hop nh-ip-vrf
Treenh-ip-vrf

Notes

The following elements are part of a mandatory choice: nh-ip or nh-ip-vrf.

Introduced25.3.R2

Platforms

7705 SAR-1

address ipv6-address
Synopsis IPv6 address of next hop to forward matching packets
Contextconfigure filter ipv6-filter filter-name entry number action forward next-hop nh-ip-vrf address ipv6-address
Treeaddress

Description

This command specifies the IPv6 address of a direct or indirect next hop to which matching packets are forwarded.

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

redirect-policy reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNext hop or forward next hop router that forwards a packet that matches this entry
Contextconfigure filter ipv6-filter filter-name entry number action forward redirect-policy reference
Treeredirect-policy

Reference

configure filter redirect-policy named-item

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, srv6-policy, or vprn-target.

Introduced25.3.R2

Platforms

7705 SAR-1

router-instance string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisRouter name or VPRN service name
Contextconfigure filter ipv6-filter filter-name entry number action forward router-instance string
Treerouter-instance

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, srv6-policy, or vprn-target.

Introduced25.3.R2

Platforms

7705 SAR-1

ignore-match
Synopsis Ignore match criteria for the entry
Context configure filter ipv6-filter filter-name entry number action ignore-match
Treeignore-match

Notes

The following elements are part of a mandatory choice: accept, drop, forward, http-redirect, ignore-match, nat, or tcp-mss-adjust.

Introduced25.3.R2

Platforms

7705 SAR-1

rate-limit
Synopsis Enable the rate-limit context
Context configure filter ipv6-filter filter-name entry number action rate-limit
Treerate-limit

Description

Commands in this context configure the rate-limit action for traffic that matches this filter entry.

Introduced25.3.R2

Platforms

7705 SAR-1

hop-limit
Synopsis Enable the hop-limit context
Context configure filter ipv6-filter filter-name entry number action rate-limit hop-limit
Treehop-limit

Notes

The following elements are part of a choice: hop-limit or payload-length.

Introduced25.3.R2

Platforms

7705 SAR-1

eq number
Synopsis Equal to condition match value
Context configure filter ipv6-filter filter-name entry number action rate-limit hop-limit eq number
Treeeq
Range0 to 255

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

gt number
Synopsis Greater than condition match value
Context configure filter ipv6-filter filter-name entry number action rate-limit hop-limit gt number
Treegt
Range0 to 254

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

lt number
Synopsis Less than condition match value
Context configure filter ipv6-filter filter-name entry number action rate-limit hop-limit lt number
Treelt
Range1 to 255

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

range
Synopsis Enable the range context
Context configure filter ipv6-filter filter-name entry number action rate-limit hop-limit range
Treerange

Description

This command in this context specify an inclusive range. When range is used, the start of the range (the first value entered) must be smaller than the end of the range (the second value entered).

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

payload-length
Synopsis Enable the payload-length context
Contextconfigure filter ipv6-filter filter-name entry number action rate-limit payload-length
Treepayload-length

Notes

The following elements are part of a choice: hop-limit or payload-length.

Introduced25.3.R2

Platforms

7705 SAR-1

eq number
Synopsis Exact match criterion for the length
Context configure filter ipv6-filter filter-name entry number action rate-limit payload-length eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

gt number
Synopsis Greater than match criterion for the length
Contextconfigure filter ipv6-filter filter-name entry number action rate-limit payload-length gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

lt number
Synopsis Less than match criterion for the length
Contextconfigure filter ipv6-filter filter-name entry number action rate-limit payload-length lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

range
Synopsis Enable the range context
Context configure filter ipv6-filter filter-name entry number action rate-limit payload-length range
Treerange

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

pir (number | keyword)
Synopsis Peak information rate
Context configure filter ipv6-filter filter-name entry number action rate-limit pir (number | keyword)
Treepir
Range0 to 2000000000
Unitskilobps
Options max

Notes

The following elements are part of a mandatory choice: pir, policer, or pps-pir.

Introduced25.3.R2

Platforms

7705 SAR-1

policer named-item
Synopsis Policer name to use for rate limiting traffic
Contextconfigure filter ipv6-filter filter-name entry number action rate-limit policer named-item
Treepolicer
String length1 to 32

Notes

The following elements are part of a mandatory choice: pir, policer, or pps-pir.

Introduced25.3.R2

Platforms

7705 SAR-1

secondary
Synopsis Enable the secondary context
Context configure filter ipv6-filter filter-name entry number action secondary
Treesecondary
Introduced25.3.R2

Platforms

7705 SAR-1

forward
Synopsis Enter the forward context
Context configure filter ipv6-filter filter-name entry number action secondary forward
Treeforward

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

next-hop
Synopsis Enable the next-hop context
Context configure filter ipv6-filter filter-name entry number action secondary forward next-hop
Treenext-hop

Notes

The following elements are part of a choice: next-hop, sap, sdp, or vprn-target.

Introduced25.3.R2

Platforms

7705 SAR-1

nh-ip-vrf
Synopsis Enable the nh-ip-vrf context
Context configure filter ipv6-filter filter-name entry number action secondary forward next-hop nh-ip-vrf
Treenh-ip-vrf

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

address ipv6-address
Synopsis IPv6 address of next hop to forward matching packets
Contextconfigure filter ipv6-filter filter-name entry number action secondary forward next-hop nh-ip-vrf address ipv6-address
Treeaddress

Description

This command specifies the IPv6 address of a direct or indirect next hop to which matching packets are forwarded.

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

tcp-mss-adjust
Synopsis Adjust MSS option of TCP matching packets to configured value of tcp-mss in router interface context
Contextconfigure filter ipv6-filter filter-name entry number action tcp-mss-adjust
Treetcp-mss-adjust

Notes

The following elements are part of a mandatory choice: accept, drop, forward, http-redirect, ignore-match, nat, or tcp-mss-adjust.

Introduced25.3.R2

Platforms

7705 SAR-1

log reference
Synopsis Log that is used for packets matching this entry
Contextconfigure filter ipv6-filter filter-name entry number log reference
Treelog

Reference

configure filter log number

Introduced25.3.R2

Platforms

7705 SAR-1

match
Synopsis Enter the match context
Context configure filter ipv6-filter filter-name entry number match
Treematch

Description

Commands in this context provide match criteria for the filter entry. When the match criteria are satisfied, the action associated with the match criteria is executed.

Introduced25.3.R2

Platforms

7705 SAR-1

dscp keyword
Synopsis DSCP used as an IP filter match criterion
Contextconfigure filter ipv6-filter filter-name entry number match dscp keyword
Treedscp
Optionsbe, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63
Introduced 25.3.R2

Platforms

7705 SAR-1

dst-ip
Synopsis Enter the dst-ip context
Context configure filter ipv6-filter filter-name entry number match dst-ip
Treedst-ip

Description

Commands in this context configure a destination address range that is used by filter policy match criteria.

Notes

The following elements are part of a choice: ip or (dst-ip and src-ip).

Introduced25.3.R2

Platforms

7705 SAR-1

address (ipv6-prefix-with-host-bits | ipv6-address)
Synopsis IPv6 address used as the match criterion
Contextconfigure filter ipv6-filter filter-name entry number match dst-ip address (ipv6-prefix-with-host-bits | ipv6-address)
Treeaddress

Notes

The following elements are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR-1

mask ipv6-address
Synopsis IPv6 address mask used as the match criterion
Contextconfigure filter ipv6-filter filter-name entry number match dst-ip mask ipv6-address
Treemask

Notes

The following elements are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR-1

dst-port
Synopsis Enter the dst-port context
Context configure filter ipv6-filter filter-name entry number match dst-port
Treedst-port

Description

Commands in this context configure match criteria for the destination port.

Notes

The following elements are part of a choice: port or (dst-port and src-port).

Introduced25.3.R2

Platforms

7705 SAR-1

eq number
Synopsis Exact value as the match criterion
Context configure filter ipv6-filter filter-name entry number match dst-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

gt number
Synopsis Greater than value as the match criterion
Contextconfigure filter ipv6-filter filter-name entry number match dst-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

lt number
Synopsis Less than value as the match criterion
Contextconfigure filter ipv6-filter filter-name entry number match dst-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

range
Synopsis Enable the range context
Context configure filter ipv6-filter filter-name entry number match dst-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

end number
Synopsis Upper bound of the port range
Context configure filter ipv6-filter filter-name entry number match dst-port range end number
Treeend
Range1 to 65535

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

extension-header
Synopsis Enter the extension-header context
Contextconfigure filter ipv6-filter filter-name entry number match extension-header
Treeextension-header
Introduced25.3.R2

Platforms

7705 SAR-1

esp boolean
Synopsis Match a packet as per the existence of an Encapsulation security payload extension header
Contextconfigure filter ipv6-filter filter-name entry number match extension-header esp boolean
Treeesp
Introduced25.3.R2

Platforms

7705 SAR-1

flow-label
Synopsis Enable the flow-label context
Context configure filter ipv6-filter filter-name entry number match flow-label
Treeflow-label

Description

Commands in this context configure the flow label and optional mask match condition.

Introduced25.3.R2

Platforms

7705 SAR-1

mask number
Synopsis Flow label mask for the IPv6 filter entry
Contextconfigure filter ipv6-filter filter-name entry number match flow-label mask number
Treemask

Description

This command specifies the IPv6 address mask for the flow label filter entry. This value can be expressed in decimal, hexadecimal, or binary format.

Range1 to 1048575
Default1048575
Introduced25.3.R2

Platforms

7705 SAR-1

value number
Synopsis Flow label as a match criterion
Context configure filter ipv6-filter filter-name entry number match flow-label value number
Treevalue

Description

This command specifies the flow label to use as a match criterion. This value can be expressed in decimal, hexadecimal, or binary format.

Range0 to 1048575

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

fragment keyword
Synopsis Match criterion for fragmented packages
Contextconfigure filter ipv6-filter filter-name entry number match fragment keyword
Treefragment
Optionsfalse, true, first-only, non-first-only
Introduced25.3.R2

Platforms

7705 SAR-1

icmp
Synopsis Enter the icmp context
Context configure filter ipv6-filter filter-name entry number match icmp
Treeicmp

Description

Commands in this context configure ICMP values to use as IPv6 filter match criteria.

Introduced25.3.R2

Platforms

7705 SAR-1

code number
Synopsis ICMPv6 code value to match
Context configure filter ipv6-filter filter-name entry number match icmp code number
Treecode

Description

This command specifies the ICMPv6 code value that must be present to match. The system matches on ICMP code or ICMP type, or on both values.

An entry containing Layer 4 non-zero match criteria does not match non initial (second, third, and so on) fragments of a fragmented packet because only the first fragment contains the Layer 4 information. Similarly, an entry containing an ICMP code value of 0 match criterion may match non-initial fragments when the Layer 4 header is not present in a packet fragment and other match criteria are also met.

Range0 to 255
Introduced25.3.R2

Platforms

7705 SAR-1

type number
Synopsis ICMPv6 type value to match
Context configure filter ipv6-filter filter-name entry number match icmp type number
Treetype

Description

This command specifies the ICMPv6 type value that must be present to match. The system matches on ICMP code or ICMP type, or on both values.

An entry containing Layer 4 non-zero match criteria does not match non initial (second, third, and so on) fragments of a fragmented packet because only the first fragment contains the Layer 4 information. Similarly, an entry containing an ICMP type value of 0 match criterion may match non initial fragments when the Layer 4 header is not present in a packet fragment and other match criteria are also met.

Range0 to 255
Introduced25.3.R2

Platforms

7705 SAR-1

ip
Synopsis Enter the ip context
Context configure filter ipv6-filter filter-name entry number match ip
Treeip

Notes

The following elements are part of a choice: ip or (dst-ip and src-ip).

Introduced25.3.R2

Platforms

7705 SAR-1

address (ipv6-prefix-with-host-bits | ipv6-address)
Synopsis IPv6 address used as the match criterion
Contextconfigure filter ipv6-filter filter-name entry number match ip address (ipv6-prefix-with-host-bits | ipv6-address)
Treeaddress

Notes

The following elements are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR-1

mask ipv6-address
Synopsis IPv6 address mask used as the match criterion
Contextconfigure filter ipv6-filter filter-name entry number match ip mask ipv6-address
Treemask

Notes

The following elements are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR-1

next-header (number | keyword)
Synopsis IP protocol to match
Context configure filter ipv6-filter filter-name entry number match next-header (number | keyword)
Treenext-header
Range0 to 255
Optionstcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp

Notes

The following elements are part of a choice: next-header or next-header-list.

Introduced25.3.R2

Platforms

7705 SAR-1

port
Synopsis Enter the port context
Context configure filter ipv6-filter filter-name entry number match port
Treeport

Notes

The following elements are part of a choice: port or (dst-port and src-port).

Introduced25.3.R2

Platforms

7705 SAR-1

eq number
Synopsis Exact value as the match criterion
Context configure filter ipv6-filter filter-name entry number match port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

gt number
Synopsis Greater than value as the match criterion
Contextconfigure filter ipv6-filter filter-name entry number match port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

lt number
Synopsis Less than value as the match criterion
Contextconfigure filter ipv6-filter filter-name entry number match port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

range
Synopsis Enable the range context
Context configure filter ipv6-filter filter-name entry number match port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

end number
Synopsis Upper bound of the port range
Context configure filter ipv6-filter filter-name entry number match port range end number
Treeend
Range1 to 65535

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

start number
Synopsis Lower bound of the port range
Context configure filter ipv6-filter filter-name entry number match port range start number
Treestart
Range0 to 65534

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

src-ip
Synopsis Enter the src-ip context
Context configure filter ipv6-filter filter-name entry number match src-ip
Treesrc-ip

Description

Commands in this context configure a source address range that is used by filter policy match criteria.

Notes

The following elements are part of a choice: ip or (dst-ip and src-ip).

Introduced25.3.R2

Platforms

7705 SAR-1

address (ipv6-prefix-with-host-bits | ipv6-address)
Synopsis IPv6 address used as the match criterion
Contextconfigure filter ipv6-filter filter-name entry number match src-ip address (ipv6-prefix-with-host-bits | ipv6-address)
Treeaddress

Notes

The following elements are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR-1

mask ipv6-address
Synopsis IPv6 address mask used as the match criterion
Contextconfigure filter ipv6-filter filter-name entry number match src-ip mask ipv6-address
Treemask

Notes

The following elements are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR-1

src-port
Synopsis Enter the src-port context
Context configure filter ipv6-filter filter-name entry number match src-port
Treesrc-port

Description

Commands in this context configure match criteria for the source port.

Notes

The following elements are part of a choice: port or (dst-port and src-port).

Introduced25.3.R2

Platforms

7705 SAR-1

eq number
Synopsis Exact value as the match criterion
Context configure filter ipv6-filter filter-name entry number match src-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

gt number
Synopsis Greater than value as the match criterion
Contextconfigure filter ipv6-filter filter-name entry number match src-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

lt number
Synopsis Less than value as the match criterion
Contextconfigure filter ipv6-filter filter-name entry number match src-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

range
Synopsis Enable the range context
Context configure filter ipv6-filter filter-name entry number match src-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR-1

end number
Synopsis Upper bound of the port range
Context configure filter ipv6-filter filter-name entry number match src-port range end number
Treeend
Range1 to 65535

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

tcp-established
Synopsis Use ACK or RST status in TCP header as match criterion
Contextconfigure filter ipv6-filter filter-name entry number match tcp-established
Treetcp-established

Description

When configured to true, a match occurs when the ACK or the RST TCP flag bit is set in the TCP header of an IP packet.

Notes

The following elements are part of a choice: tcp-established or tcp-flags.

Introduced25.3.R2

Platforms

7705 SAR-1

tcp-flags
Synopsis Enter the tcp-flags context
Context configure filter ipv6-filter filter-name entry number match tcp-flags
Treetcp-flags

Description

Commands in this context configure the use of TCP flags as the IP filter match.

Notes

The following elements are part of a choice: tcp-established or tcp-flags.

Introduced25.3.R2

Platforms

7705 SAR-1

ack boolean
Synopsis Use ACK TCP bit status in TCP header as match criterion
Contextconfigure filter ipv6-filter filter-name entry number match tcp-flags ack boolean
Treeack

Description

When configured to true, a match occurs when the ACK TCP flag bit, defined in RFC 793, is set in the TCP header of an IP packet.

When configured to false, a match occurs when the ACK TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR-1

cwr boolean
Synopsis Use CWR TCP bit status in TCP header as match criterion
Contextconfigure filter ipv6-filter filter-name entry number match tcp-flags cwr boolean
Treecwr

Description

When configured to true, a match occurs when the Congestion Window Reduced (CWR) TCP flag bit, defined in RFC 3168, is set in the TCP header of an IP packet.

When configured to false, a match occurs when the CWR TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR-1

ece boolean
Synopsis Use ECE TCP bit status in TCP header as match criterion
Contextconfigure filter ipv6-filter filter-name entry number match tcp-flags ece boolean
Treeece

Description

When configured to true, a match occurs when the ECN-Echo (ECE) TCP flag bit, defined in RFC 3168, is set in the TCP header of an IP packet.

When configured to false, a match occurs when the ECE TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR-1

fin boolean
Synopsis Use FIN TCP bit status in TCP header as match criterion
Contextconfigure filter ipv6-filter filter-name entry number match tcp-flags fin boolean
Treefin

Description

When configured to true, a match occurs when the FIN TCP flag bit is set in the TCP header of an IP packet.

When configured to false, a match occurs when the FIN TCP flag bit, defined in RFC 793, is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR-1

ns boolean
Synopsis Use NS TCP bit status in TCP header as match criterion
Contextconfigure filter ipv6-filter filter-name entry number match tcp-flags ns boolean
Treens

Description

When configured to true, a match occurs when the Nonce Sum (NS) TCP flag bit, defined in RFC 3540, is set in the TCP header of an IP packet.

When configured to false, a match occurs when the NS TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR-1

psh boolean
Synopsis Use PSH TCP bit status in TCP header as match criterion
Contextconfigure filter ipv6-filter filter-name entry number match tcp-flags psh boolean
Treepsh

Description

When configured to true, a match occurs when the Push (PSH) TCP flag bit is set in the TCP header of an IP packet.

When configured to false, a match occurs when the Push (PSH) TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR-1

rst boolean
Synopsis Use RST TCP bit status in TCP header as match criterion
Contextconfigure filter ipv6-filter filter-name entry number match tcp-flags rst boolean
Treerst

Description

When configured to true, a match occurs when the RST TCP flag bit is set in the TCP header of an IP packet.

When configured to false, a match occurs when the RST TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR-1

syn boolean
Synopsis Use SYN TCP bit status in TCP header as match criterion
Contextconfigure filter ipv6-filter filter-name entry number match tcp-flags syn boolean
Treesyn

Description

When configured to true, a match occurs when the Synchronize (SYN) TCP flag bit is set in the TCP header of an IP packet.

When configured to false, a match occurs when the SYN TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR-1

urg boolean
Synopsis Use URG TCP bit status in TCP header as match criterion
Contextconfigure filter ipv6-filter filter-name entry number match tcp-flags urg boolean
Treeurg

Description

When configured to true, a match occurs when the Urgent (URG) TCP flag bit is set in the TCP header of an IP packet.

When configured to false, a match occurs when the URG TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR-1

sticky-dest (number | keyword)
Synopsis Time before action with available PBR or PBF destination and highest priority
Contextconfigure filter ipv6-filter filter-name entry number sticky-dest (number | keyword)
Treesticky-dest
Range0 to 65535
Unitsseconds
Options no-hold-time-up
Introduced25.3.R2

Platforms

7705 SAR-1

filter-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIPv6 filter identifier
Contextconfigure filter ipv6-filter filter-name filter-id number
Treefilter-id
Range1 to 65535
Introduced25.3.R2

Platforms

7705 SAR-1

scope keyword
Synopsis Scope of the filter definition
Context configure filter ipv6-filter filter-name scope keyword
Treescope

Description

This command configures the filter policy scope.

If the scope of the policy is template and is applied to one or more services or network interfaces, the scope cannot be changed.

Optionsexclusive, template, embedded, system, cpm
Defaulttemplate
Introduced25.3.R2

Platforms

7705 SAR-1

log [log-id] number

Synopsis Enter the log list instance
Context configure filter log number
Treelog
Introduced25.3.R2

Platforms

7705 SAR-1

[log-id] number
Synopsis Filter log identifier
Context configure filter log number
Treelog
Range101 to 199

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

admin-state keyword
Synopsis Administrative state of filter logging
Contextconfigure filter log number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR-1

description description-or-empty
Synopsis Text description
Context configure filter log number description description-or-empty
Treedescription
String length0 to 80
Introduced25.3.R2

Platforms

7705 SAR-1

destination
Synopsis Enter the destination context
Context configure filter log number destination
Treedestination
Introduced25.3.R2

Platforms

7705 SAR-1

memory
Synopsis Enter the memory context
Context configure filter log number destination memory
Treememory

Notes

The following elements are part of a choice: memory or syslog.

Introduced25.3.R2

Platforms

7705 SAR-1

stop-on-full boolean
Synopsis Stop logging when maximum number of memory entries is reached or wrap-around is used
Contextconfigure filter log number destination memory stop-on-full boolean
Treestop-on-full
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR-1

syslog
Synopsis Enter the syslog context
Context configure filter log number destination syslog
Treesyslog

Notes

The following elements are part of a choice: memory or syslog.

Introduced25.3.R2

Platforms

7705 SAR-1

summary
Synopsis Enter the summary context
Context configure filter log number destination syslog summary
Treesummary
Introduced25.3.R2

Platforms

7705 SAR-1

match-list

Synopsis Enter the match-list context
Context configure filter match-list
Treematch-list

Description

Commands in this context configure match lists to be used in filter policies (IOM/FP and CPM).

Introduced25.3.R2

Platforms

7705 SAR-1

ip-prefix-list [prefix-list-name] named-item
Synopsis Enter the ip-prefix-list list instance
Contextconfigure filter match-list ip-prefix-list named-item
Treeip-prefix-list

Description

Commands in this context configure a list of IPv4 prefixes for match criteria in IPv4 ACL and CPM filter policies.

Introduced25.3.R2

Platforms

7705 SAR-1

[prefix-list-name] named-item
Synopsis IP prefix list name
Context configure filter match-list ip-prefix-list named-item
Treeip-prefix-list
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

apply-path
Synopsis Enter the apply-path context
Context configure filter match-list ip-prefix-list named-item apply-path
Treeapply-path

Description

Commands in this context configure the autogeneration of address prefixes for IPv4 address prefix match lists.

Introduced25.3.R2

Platforms

7705 SAR-1

bgp-peers [criterion-index] number
Synopsis Enter the bgp-peers list instance
Contextconfigure filter match-list ip-prefix-list named-item apply-path bgp-peers number
Treebgp-peers

Description

Commands in this context configure the unique index for BGP peers.

Introduced25.3.R2

Platforms

7705 SAR-1

group regular-expression-not-all-spaces
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisRegular expression to match against the base router BGP instance group configuration
Contextconfigure filter match-list ip-prefix-list named-item apply-path bgp-peers number group regular-expression-not-all-spaces
Treegroup
String length1 to 255

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

neighbor regular-expression-not-all-spaces
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisRegular expression to match against the base router BGP instance neighbor configuration
Contextconfigure filter match-list ip-prefix-list named-item apply-path bgp-peers number neighbor regular-expression-not-all-spaces
Treeneighbor
String length1 to 255

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

interfaces [criterion-index] number
Synopsis Enter the interfaces list instance
Contextconfigure filter match-list ip-prefix-list named-item apply-path interfaces number
Treeinterfaces

Description

Commands in this context configure the interfaces configuration to be used for autogeneration of IPv4 address filter prefix lists.

Introduced25.10.R1

Platforms

7705 SAR-1

interface regular-expression-not-all-spaces
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisRegular expression defining a match string
Contextconfigure filter match-list ip-prefix-list named-item apply-path interfaces number interface regular-expression-not-all-spaces
Treeinterface

Description

This command configures a regular expression to match against interface names under the Base router, IES, and VPRN service configuration.

String length1 to 255

Notes

This element is mandatory.

Introduced25.10.R1

Platforms

7705 SAR-1

prefix [ip-prefix] ipv4-prefix
Synopsis Add a list entry for prefix
Context configure filter match-list ip-prefix-list named-item prefix ipv4-prefix
Treeprefix

Description

Commands in this context add IPv4 prefixes to the prefix match list. Prefixes can overlap IPv4 address space.

An IPv4 prefix addition is blocked if resource exhaustion is detected anywhere in the system due to filter policies that use the prefix list.

Max. instances8192
Introduced25.3.R2

Platforms

7705 SAR-1

[ip-prefix] ipv4-prefix
Synopsis IPv4 prefix to be added to the prefix list
Contextconfigure filter match-list ip-prefix-list named-item prefix ipv4-prefix
Treeprefix

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

prefix-exclude [ip-prefix] ipv4-prefix
Synopsis Add a list entry for prefix-exclude
Contextconfigure filter match-list ip-prefix-list named-item prefix-exclude ipv4-prefix
Treeprefix-exclude

Description

Commands in this context exclude IPv4 prefixes from the prefix match list.

This command is mutually exclusive with the apply-path command.

Max. instances512
Introduced25.3.R2

Platforms

7705 SAR-1

ipv6-prefix-list [prefix-list-name] named-item
Synopsis Enter the ipv6-prefix-list list instance
Contextconfigure filter match-list ipv6-prefix-list named-item
Treeipv6-prefix-list

Description

Commands in this context configure a list of IPv6 prefixes for match criteria in ACL and CPM IPv6 filter policies.

Introduced25.3.R2

Platforms

7705 SAR-1

[prefix-list-name] named-item
Synopsis IP prefix list name
Context configure filter match-list ipv6-prefix-list named-item
Treeipv6-prefix-list
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

apply-path
Synopsis Enter the apply-path context
Context configure filter match-list ipv6-prefix-list named-item apply-path
Treeapply-path

Description

Commands in this context configure the autogeneration of address prefixes for IPv6 address prefix match lists.

Introduced25.3.R2

Platforms

7705 SAR-1

bgp-peers [criterion-index] number
Synopsis Enter the bgp-peers list instance
Contextconfigure filter match-list ipv6-prefix-list named-item apply-path bgp-peers number
Treebgp-peers

Description

Commands in this context configure the unique index for BGP peers.

Introduced25.3.R2

Platforms

7705 SAR-1

group regular-expression-not-all-spaces
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisRegular expression to match against the base router BGP instance group configuration
Contextconfigure filter match-list ipv6-prefix-list named-item apply-path bgp-peers number group regular-expression-not-all-spaces
Treegroup
String length1 to 255

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

neighbor regular-expression-not-all-spaces
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisRegular expression to match against the base router BGP instance neighbor configuration
Contextconfigure filter match-list ipv6-prefix-list named-item apply-path bgp-peers number neighbor regular-expression-not-all-spaces
Treeneighbor
String length1 to 255

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

interfaces [criterion-index] number
Synopsis Enter the interfaces list instance
Contextconfigure filter match-list ipv6-prefix-list named-item apply-path interfaces number
Treeinterfaces

Description

Commands in this context configure the interfaces configuration to be used for the autogeneration of IPv6 address filter prefix lists.

Introduced25.10.R1

Platforms

7705 SAR-1

interface regular-expression-not-all-spaces
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisRegular expression defining a match string
Contextconfigure filter match-list ipv6-prefix-list named-item apply-path interfaces number interface regular-expression-not-all-spaces
Treeinterface

Description

This command configures a regular expression to match against interface names under the Base router, IES, and VPRN service configuration.

String length1 to 255

Notes

This element is mandatory.

Introduced25.10.R1

Platforms

7705 SAR-1

prefix-exclude [ipv6-prefix] ipv6-prefix
Synopsis Add a list entry for prefix-exclude
Contextconfigure filter match-list ipv6-prefix-list named-item prefix-exclude ipv6-prefix
Treeprefix-exclude

Description

Commands in this context exclude IPv6 prefixes from the prefix match list.

This command is mutually exclusive with the apply-path command.

Max. instances512
Introduced25.3.R2

Platforms

7705 SAR-1

port-list [port-list-name] named-item
Synopsis Enter the port-list list instance
Contextconfigure filter match-list port-list named-item
Treeport-list
Max. instances5120
Introduced25.3.R2

Platforms

7705 SAR-1

[port-list-name] named-item
Synopsis Port list name
Contextconfigure filter match-list port-list named-item
Treeport-list

Description

This command specifies the port list name. If special characters are used (#, $, spaces, and so on), the string must be enclosed within double quotes.

String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

port [value] number
Synopsis Add a list entry for port
Context configure filter match-list port-list named-item port number
Treeport
Introduced25.3.R2

Platforms

7705 SAR-1

[value] number
Synopsis Port value
Contextconfigure filter match-list port-list named-item port number
Treeport
Range0 to 65535

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

range start number end number
Synopsis Add a list entry for range
Context configure filter match-list port-list named-item range start number end number
Treerange
Introduced25.3.R2

Platforms

7705 SAR-1

start number
Synopsis Lower bound of the port list range
Context configure filter match-list port-list named-item range start number end number
Treerange
Range0 to 65534

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

end number
Synopsis Upper bound of the port list range
Context configure filter match-list port-list named-item range start number end number
Treerange
Range1 to 65535

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

protocol-list [protocol-list-name] named-item
Synopsis Enter the protocol-list list instance
Contextconfigure filter match-list protocol-list named-item
Treeprotocol-list
Max. instances512
Introduced25.3.R2

Platforms

7705 SAR-1

[protocol-list-name] named-item
Synopsis Protocol list name
Context configure filter match-list protocol-list named-item
Treeprotocol-list
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

protocol [protocol-id] (number | keyword)
Synopsis Add a list entry for protocol
Context configure filter match-list protocol-list named-item protocol (number | keyword)
Treeprotocol
Max. instances32
Introduced25.3.R2

Platforms

7705 SAR-1

[protocol-id] (number | keyword)
Synopsis IP protocol identifier
Context configure filter match-list protocol-list named-item protocol (number | keyword)
Treeprotocol
Range0 to 255
Optionsicmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

md-auto-id

Synopsis Enter the md-auto-id context
Context configure filter md-auto-id
Treemd-auto-id
Introduced25.3.R2

Platforms

7705 SAR-1

filter-id-range
Synopsis Enable the filter-id-range context
Contextconfigure filter md-auto-id filter-id-range
Treefilter-id-range
Introduced25.3.R2

Platforms

7705 SAR-1

end number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisUpper bound of the ID range
Contextconfigure filter md-auto-id filter-id-range end number
Treeend
Range1 to 65535

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

start number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisLower bound of the ID range
Contextconfigure filter md-auto-id filter-id-range start number
Treestart
Range1 to 65535

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR-1

policer [policer-name] named-item

Synopsis Enter the policer list instance
Contextconfigure filter policer named-item
Treepolicer

Description

Commands in this context configure policer options.

Max. instances8192
Introduced25.3.R2

Platforms

7705 SAR-1

[policer-name] named-item
Synopsis Name of the policer for use in a filter policy
Contextconfigure filter policer named-item
Treepolicer
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

description description
Synopsis Text description
Context configure filter policer named-item description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR-1

mbs (number | keyword)
Synopsis Maximum burst size
Context configure filter policer named-item mbs (number | keyword)
Treembs
Range0 to 268435456
Unitsbytes
Options auto
Default auto

Notes

The following elements are part of a choice: (mbs and pir) or pps-pir.

Introduced25.3.R2

Platforms

7705 SAR-1

pir number
Synopsis Peak information rate
Context configure filter policer named-item pir number
Treepir
Range0 to 2000000000
Unitskilobps

Notes

The following elements are part of a choice: (mbs and pir) or pps-pir.

Introduced25.3.R2

Platforms

7705 SAR-1

scope keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPolicer scope
Contextconfigure filter policer named-item scope keyword
Treescope

Description

This command configures the scope for the policer object.

When the system scope is configured, it creates an instance of the policer for each direction immediately after the policer is configured and shares the instance with all filter entries that reference that policer name applied in the same direction.

When the filter scope is configured, it configures the policer instance to be shared by rate-limit entries that are part of the same filter policy and are applied in the same direction.

Options

filter – Policer shared by entries in same filter policer

system – Single policer shared by the system

Defaultfilter
Introduced25.3.R2

Platforms

7705 SAR-1

redirect-policy [redirect-policy-name] named-item

Synopsis Enter the redirect-policy list instance
Contextconfigure filter redirect-policy named-item
Treeredirect-policy
Introduced25.3.R2

Platforms

7705 SAR-1

[redirect-policy-name] named-item
Synopsis Redirect policy name
Context configure filter redirect-policy named-item
Treeredirect-policy

Description

This command specifies the redirect policy name. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes.

String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

admin-state keyword
Synopsis Administrative state of the redirect policy
Contextconfigure filter redirect-policy named-item admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR-1

destination [destination-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Enter the destination list instance
Contextconfigure filter redirect-policy named-item destination (ipv4-address-no-zone | ipv6-address-no-zone)
Treedestination
Introduced25.3.R2

Platforms

7705 SAR-1

[destination-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address and type of destination
Context configure filter redirect-policy named-item destination (ipv4-address-no-zone | ipv6-address-no-zone)
Treedestination

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

admin-state keyword
Synopsis Administrative state of the destination
Contextconfigure filter redirect-policy named-item destination (ipv4-address-no-zone | ipv6-address-no-zone) admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR-1

ping-test
Synopsis Enable the ping-test context
Context configure filter redirect-policy named-item destination (ipv4-address-no-zone | ipv6-address-no-zone) ping-test
Treeping-test
Introduced25.3.R2

Platforms

7705 SAR-1

drop-count number
Synopsis Number of consecutive requests that fail before destination is declared unreachable
Contextconfigure filter redirect-policy named-item destination (ipv4-address-no-zone | ipv6-address-no-zone) ping-test drop-count number
Treedrop-count
Range1 to 60
Default3
Introduced 25.3.R2

Platforms

7705 SAR-1

hold-down number
Synopsis Time for the system to be held down if this test has marked it unreachable
Contextconfigure filter redirect-policy named-item destination (ipv4-address-no-zone | ipv6-address-no-zone) ping-test hold-down number
Treehold-down
Range0 to 86400
Unitsseconds
Default 0
Introduced25.3.R2

Platforms

7705 SAR-1

interval number
Synopsis Time between consecutive requests which are sent to the far end host
Contextconfigure filter redirect-policy named-item destination (ipv4-address-no-zone | ipv6-address-no-zone) ping-test interval number
Treeinterval
Range1 to 60
Unitsseconds
Default 1
Introduced25.3.R2

Platforms

7705 SAR-1

source-address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Source address to use in the IP packet of the ping test
Contextconfigure filter redirect-policy named-item destination (ipv4-address-no-zone | ipv6-address-no-zone) ping-test source-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treesource-address
Introduced25.3.R2

Platforms

7705 SAR-1

timeout number
Synopsis Time required to receive a response from the far end host
Contextconfigure filter redirect-policy named-item destination (ipv4-address-no-zone | ipv6-address-no-zone) ping-test timeout number
Treetimeout
Range1 to 60
Unitsseconds
Default 1
Introduced25.3.R2

Platforms

7705 SAR-1

priority number
Synopsis Priority for this destination
Context configure filter redirect-policy named-item destination (ipv4-address-no-zone | ipv6-address-no-zone) priority number
Treepriority
Range1 to 255
Default100
Introduced 25.3.R2

Platforms

7705 SAR-1

notify-dest-change boolean
Synopsis Send notifications when the active destination changes
Contextconfigure filter redirect-policy named-item notify-dest-change boolean
Treenotify-dest-change

Description

When configured to true, notifications (such as Log and SNMP) are sent when the active destination of a redirect policy changes. No notification is sent when there are no more active destinations (as this scenario is covered by another notification).

When configured to false, the notification generation is disabled.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR-1

sticky-dest (number | keyword)
Synopsis Time required by system before applying the current best destination as active destination
Contextconfigure filter redirect-policy named-item sticky-dest (number | keyword)
Treesticky-dest
Range0 to 65535
Unitsseconds
Options no-hold-time-up
Introduced25.3.R2

Platforms

7705 SAR-1

redirect-policy-binding [binding-name] named-item

Synopsis Enter the redirect-policy-binding list instance
Contextconfigure filter redirect-policy-binding named-item
Treeredirect-policy-binding
Max. instances16
Introduced25.3.R2

Platforms

7705 SAR-1

binding-operator keyword
Synopsis Logical operator used to obtain the master test result
Contextconfigure filter redirect-policy-binding named-item binding-operator keyword
Treebinding-operator

Description

This command configures the logical operator to use with the destinations' test results to obtain the master test result (the redirect policy binding test result).

Optionsand, or
Default and
Introduced25.3.R2

Platforms

7705 SAR-1

redirect-policy [redirect-policy-name] reference
Synopsis Enter the redirect-policy list instance
Contextconfigure filter redirect-policy-binding named-item redirect-policy reference
Treeredirect-policy
Introduced25.3.R2

Platforms

7705 SAR-1

destination [destination-address] reference
Synopsis Add a list entry for destination
Contextconfigure filter redirect-policy-binding named-item redirect-policy reference destination reference
Treedestination
Min. instances1
Introduced25.3.R2

Platforms

7705 SAR-1

system-filter

Synopsis Enter the system-filter context
Contextconfigure filter system-filter
Treesystem-filter
Introduced25.3.R2

Platforms

7705 SAR-1

ip [ip-filter] reference
Synopsis Add a list entry for ip
Context configure filter system-filter ip reference
Treeip
Max. instances1
Introduced25.3.R2

Platforms

7705 SAR-1

[ip-filter] reference
Synopsis Active IPv4 system filter policy
Context configure filter system-filter ip reference
Treeip

Reference

configure filter ip-filter filter-name

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1

ipv6 [ipv6-filter] reference
Synopsis Add a list entry for ipv6
Context configure filter system-filter ipv6 reference
Treeipv6
Max. instances1
Introduced25.3.R2

Platforms

7705 SAR-1

[ipv6-filter] reference
Synopsis Active IPv6 system filter policy
Context configure filter system-filter ipv6 reference
Treeipv6

Reference

configure filter ipv6-filter filter-name

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR-1