filter commands

configure 
filter 
apply-groups reference
apply-groups-exclude reference
dhcp-filter number 
apply-groups reference
apply-groups-exclude reference
default-action 
drop 
description description
entry number 
action 
drop 
apply-groups reference
apply-groups-exclude reference
option 
absent 
match 
exact boolean
hex string
invert boolean
string string
number number
present 
dhcp6-filter number 
apply-groups reference
apply-groups-exclude reference
default-action 
drop 
description description
entry number 
action 
drop 
apply-groups reference
apply-groups-exclude reference
option 
absent 
match 
exact boolean
hex string
invert boolean
string string
number number
present 
ip-exception filter-name 
apply-groups reference
apply-groups-exclude reference
description description
entry number 
apply-groups reference
apply-groups-exclude reference
description description
match 
dst-ip 
address (ipv4-prefix-with-host-bits | ipv4-address)
mask ipv4-address
dst-port 
eq number
gt number
lt number
range 
end number
start number
icmp 
code number
type number
protocol (number | keyword)
src-ip 
address (ipv4-prefix-with-host-bits | ipv4-address)
mask ipv4-address
src-port 
eq number
gt number
lt number
range 
end number
start number
filter-id number
ip-filter filter-name 
apply-groups reference
apply-groups-exclude reference
chain-to-system-filter boolean
default-action keyword
description description
embed 
filter reference offset number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
entry number 
action 
accept 
apply-groups reference
apply-groups-exclude reference
drop 
drop-when 
extracted-traffic 
packet-length 
eq number
gt number
lt number
range 
end number
start number
ttl 
eq number
gt number
lt number
range 
end number
start number
forward 
next-hop 
nh-ip 
address ipv4-address
indirect boolean
nh-ip-vrf 
address ipv4-address
indirect boolean
router-instance string
redirect-policy reference
router-instance string
ignore-match 
nat 
nat-policy reference
rate-limit 
packet-length 
eq number
gt number
lt number
range 
end number
start number
pir (number | keyword)
policer reference
ttl 
eq number
gt number
lt number
range 
end number
start number
reassemble 
secondary 
apply-groups reference
apply-groups-exclude reference
forward 
next-hop 
nh-ip-vrf 
address ipv4-address
indirect boolean
router-instance string
tcp-mss-adjust 
apply-groups reference
apply-groups-exclude reference
description description
log reference
match 
dscp keyword
dst-ip 
address (ipv4-prefix-with-host-bits | ipv4-address)
ip-prefix-list reference
mask ipv4-address
dst-port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
fragment keyword
icmp 
code number
type number
ip 
address (ipv4-prefix-with-host-bits | ipv4-address)
ip-prefix-list reference
mask ipv4-address
ip-option 
mask number
type number
multiple-option boolean
option-present boolean
port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
protocol (number | keyword)
protocol-list reference
src-ip 
address (ipv4-prefix-with-host-bits | ipv4-address)
ip-prefix-list reference
mask ipv4-address
src-port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
src-route-option boolean
tcp-established 
tcp-flags 
ack boolean
cwr boolean
ece boolean
fin boolean
ns boolean
psh boolean
rst boolean
syn boolean
urg boolean
pbr-down-action-override keyword
sticky-dest (number | keyword)
filter-id number
scope keyword
ipv6-exception filter-name 
apply-groups reference
apply-groups-exclude reference
description description
entry number 
apply-groups reference
apply-groups-exclude reference
description description
match 
dst-ip 
address (ipv6-prefix-with-host-bits | ipv6-address)
ipv6-prefix-list reference
mask ipv6-address
dst-port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
icmp 
code number
type number
next-header (number | keyword)
port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
src-ip 
address (ipv6-prefix-with-host-bits | ipv6-address)
ipv6-prefix-list reference
mask ipv6-address
src-port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
filter-id number
ipv6-filter filter-name 
apply-groups reference
apply-groups-exclude reference
chain-to-system-filter boolean
default-action keyword
description description
embed 
filter reference offset number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
entry number 
action 
accept 
apply-groups reference
apply-groups-exclude reference
drop 
drop-when 
extracted-traffic 
hop-limit 
eq number
gt number
lt number
range 
end number
start number
payload-length 
eq number
gt number
lt number
range 
end number
start number
forward 
next-hop 
nh-ip 
address ipv6-address
indirect boolean
nh-ip-vrf 
address ipv6-address
indirect boolean
router-instance string
redirect-policy reference
router-instance string
ignore-match 
rate-limit 
hop-limit 
eq number
gt number
lt number
range 
end number
start number
payload-length 
eq number
gt number
lt number
range 
end number
start number
pir (number | keyword)
policer reference
secondary 
apply-groups reference
apply-groups-exclude reference
forward 
next-hop 
nh-ip-vrf 
address ipv6-address
indirect boolean
router-instance string
tcp-mss-adjust 
apply-groups reference
apply-groups-exclude reference
description description
log reference
match 
dscp keyword
dst-ip 
address (ipv6-prefix-with-host-bits | ipv6-address)
ipv6-prefix-list reference
mask ipv6-address
dst-port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
extension-header 
ah boolean
esp boolean
hop-by-hop boolean
routing-type0 boolean
flow-label 
mask number
value number
fragment keyword
icmp 
code number
type number
ip 
address (ipv6-prefix-with-host-bits | ipv6-address)
ipv6-prefix-list reference
mask ipv6-address
next-header (number | keyword)
next-header-list reference
port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
src-ip 
address (ipv6-prefix-with-host-bits | ipv6-address)
ipv6-prefix-list reference
mask ipv6-address
src-port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
tcp-established 
tcp-flags 
ack boolean
cwr boolean
ece boolean
fin boolean
ns boolean
psh boolean
rst boolean
syn boolean
urg boolean
pbr-down-action-override keyword
sticky-dest (number | keyword)
filter-id number
scope keyword
log number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description-or-empty
destination 
memory 
max-entries number
stop-on-full boolean
syslog 
name reference
summary 
admin-state keyword
summary-crit keyword
match-list 
apply-groups reference
apply-groups-exclude reference
ip-prefix-list named-item 
apply-groups reference
apply-groups-exclude reference
apply-path 
bgp-peers number 
apply-groups reference
apply-groups-exclude reference
group regular-expression-not-all-spaces
neighbor regular-expression-not-all-spaces
router-instance string
description description
prefix ipv4-prefix 
prefix-exclude ipv4-prefix 
ipv6-prefix-list named-item 
apply-groups reference
apply-groups-exclude reference
apply-path 
bgp-peers number 
apply-groups reference
apply-groups-exclude reference
group regular-expression-not-all-spaces
neighbor regular-expression-not-all-spaces
router-instance string
description description
prefix ipv6-prefix 
prefix-exclude ipv6-prefix 
port-list named-item 
apply-groups reference
apply-groups-exclude reference
description description
port number 
range start number end number 
protocol-list named-item 
apply-groups reference
apply-groups-exclude reference
description description
protocol (number | keyword) 
md-auto-id 
filter-id-range 
apply-groups reference
apply-groups-exclude reference
end number
start number
policer named-item 
apply-groups reference
apply-groups-exclude reference
description description
mbs (number | keyword)
pir number
scope keyword
redirect-policy named-item 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
destination (ipv4-address-no-zone | ipv6-address-no-zone) 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
ping-test 
apply-groups reference
apply-groups-exclude reference
drop-count number
hold-down number
interval number
source-address (ipv4-address-no-zone | ipv6-address-no-zone)
timeout number
priority number
unicast-rt-test 
notify-dest-change boolean
router-instance string
sticky-dest (number | keyword)
redirect-policy-binding named-item 
apply-groups reference
apply-groups-exclude reference
binding-operator keyword
redirect-policy reference 
apply-groups reference
apply-groups-exclude reference
destination reference 
system-filter 
apply-groups reference
apply-groups-exclude reference
ip reference 
ipv6 reference 

filter command descriptions

filter

Synopsis Enter the filter context
Context configure filter
Treefilter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dhcp-filter [filter-id] number

Synopsis Enter the dhcp-filter list instance
Contextconfigure filter dhcp-filter number
Treedhcp-filter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[filter-id] number
Synopsis Unique DHCP filter policy ID
Context configure filter dhcp-filter number
Treedhcp-filter
Range1 to 65535

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

default-action
Synopsis Enable the default-action context
Contextconfigure filter dhcp-filter number default-action
Treedefault-action
Introduced25.3.R2

Platforms

7705 SAR Gen 2

drop
Synopsis DHCP host creation when the filter entry is matched
Contextconfigure filter dhcp-filter number default-action drop
Treedrop

Notes

The following elements are part of a mandatory choice: bypass-host-creation or drop.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure filter dhcp-filter number description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure filter dhcp-filter number entry number
Treeentry
Max. instances10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[entry-id] number
Synopsis DHCP filter entry ID
Context configure filter dhcp-filter number entry number
Treeentry
Range1 to 65535

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

action
Synopsis Enable the action context
Context configure filter dhcp-filter number entry number action
Treeaction
Introduced25.3.R2

Platforms

7705 SAR Gen 2

drop
Synopsis DHCP host creation when the filter entry is matched
Contextconfigure filter dhcp-filter number entry number action drop
Treedrop

Notes

The following elements are part of a mandatory choice: bypass-host-creation or drop.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

option
Synopsis Enable the option context
Context configure filter dhcp-filter number entry number option
Treeoption
Introduced25.3.R2

Platforms

7705 SAR Gen 2

absent
Synopsis Require the absence of related option
Contextconfigure filter dhcp-filter number entry number option absent
Treeabsent

Notes

The following elements are part of a mandatory choice: absent, match, or present.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

match
Synopsis Enable the match context
Context configure filter dhcp-filter number entry number option match
Treematch

Notes

The following elements are part of a mandatory choice: absent, match, or present.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

hex string
Synopsis Matching pattern for the filtered option
Contextconfigure filter dhcp-filter number entry number option match hex string
Treehex
String length1 to 256

Notes

The following elements are part of a mandatory choice: hex or string.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

string string
Synopsis Matching pattern for the filtered option
Contextconfigure filter dhcp-filter number entry number option match string string
Treestring
String length1 to 127

Notes

The following elements are part of a mandatory choice: hex or string.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

number number
Synopsis Number for DHCP or DHCPv6 option to filter on
Contextconfigure filter dhcp-filter number entry number option number number
Treenumber
Range0 to 255

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

present
Synopsis Require the presence of related option
Contextconfigure filter dhcp-filter number entry number option present
Treepresent

Notes

The following elements are part of a mandatory choice: absent, match, or present.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

dhcp6-filter [filter-id] number

Synopsis Enter the dhcp6-filter list instance
Contextconfigure filter dhcp6-filter number
Treedhcp6-filter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[filter-id] number
Synopsis Unique DHCP filter policy ID
Context configure filter dhcp6-filter number
Treedhcp6-filter
Range1 to 65535

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

default-action
Synopsis Enable the default-action context
Contextconfigure filter dhcp6-filter number default-action
Treedefault-action
Introduced25.3.R2

Platforms

7705 SAR Gen 2

drop
Synopsis Drop DHCPv6 message (do not process)
Context configure filter dhcp6-filter number default-action drop
Treedrop

Notes

The following elements are part of a mandatory choice: bypass-host-creation or drop.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure filter dhcp6-filter number entry number
Treeentry
Max. instances10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[entry-id] number
Synopsis DHCP filter entry ID
Context configure filter dhcp6-filter number entry number
Treeentry
Range1 to 65535

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

action
Synopsis Enable the action context
Context configure filter dhcp6-filter number entry number action
Treeaction
Introduced25.3.R2

Platforms

7705 SAR Gen 2

drop
Synopsis Drop DHCPv6 message (do not process)
Context configure filter dhcp6-filter number entry number action drop
Treedrop

Notes

The following elements are part of a mandatory choice: bypass-host-creation or drop.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

option
Synopsis Enable the option context
Context configure filter dhcp6-filter number entry number option
Treeoption
Introduced25.3.R2

Platforms

7705 SAR Gen 2

absent
Synopsis Require the absence of related option
Contextconfigure filter dhcp6-filter number entry number option absent
Treeabsent

Notes

The following elements are part of a mandatory choice: absent, match, or present.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

match
Synopsis Enable the match context
Context configure filter dhcp6-filter number entry number option match
Treematch

Notes

The following elements are part of a mandatory choice: absent, match, or present.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

hex string
Synopsis Matching pattern for the filtered option
Contextconfigure filter dhcp6-filter number entry number option match hex string
Treehex
String length1 to 256

Notes

The following elements are part of a mandatory choice: hex or string.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

string string
Synopsis Matching pattern for the filtered option
Contextconfigure filter dhcp6-filter number entry number option match string string
Treestring
String length1 to 127

Notes

The following elements are part of a mandatory choice: hex or string.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

number number
Synopsis Number for DHCP or DHCPv6 option to filter on
Contextconfigure filter dhcp6-filter number entry number option number number
Treenumber
Range0 to 255

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

present
Synopsis Require the presence of related option
Contextconfigure filter dhcp6-filter number entry number option present
Treepresent

Notes

The following elements are part of a mandatory choice: absent, match, or present.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-exception [filter-name] filter-name

Synopsis Enter the ip-exception list instance
Contextconfigure filter ip-exception filter-name
Treeip-exception
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[filter-name] filter-name
Synopsis Filter name
Contextconfigure filter ip-exception filter-name
Treeip-exception
String length1 to 64

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure filter ip-exception filter-name description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure filter ip-exception filter-name entry number
Treeentry
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[entry-id] number
Synopsis ID for a match criterion and the corresponding action
Contextconfigure filter ip-exception filter-name entry number
Treeentry
Range1 to 2097151

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

match
Synopsis Enter the match context
Context configure filter ip-exception filter-name entry number match
Treematch
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dst-ip
Synopsis Enter the dst-ip context
Context configure filter ip-exception filter-name entry number match dst-ip
Treedst-ip
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address (ipv4-prefix-with-host-bits | ipv4-address)
Synopsis IP address to match
Context configure filter ip-exception filter-name entry number match dst-ip address (ipv4-prefix-with-host-bits | ipv4-address)
Treeaddress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mask ipv4-address
Synopsis Mask applied as an AND to the IP address
Contextconfigure filter ip-exception filter-name entry number match dst-ip mask ipv4-address
Treemask
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dst-port
Synopsis Enter the dst-port context
Context configure filter ip-exception filter-name entry number match dst-port
Treedst-port
Introduced25.3.R2

Platforms

7705 SAR Gen 2

eq number
Synopsis Exact match criterion
Context configure filter ip-exception filter-name entry number match dst-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gt number
Synopsis Greater than match criterion for the port number
Contextconfigure filter ip-exception filter-name entry number match dst-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lt number
Synopsis Less than match criterion for the port
Contextconfigure filter ip-exception filter-name entry number match dst-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

range
Synopsis Enable the range context
Context configure filter ip-exception filter-name entry number match dst-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

end number
Synopsis Upper bound of the port range to match
Contextconfigure filter ip-exception filter-name entry number match dst-port range end number
Treeend
Range1 to 65535

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

start number
Synopsis Lower bound of the port range to match
Contextconfigure filter ip-exception filter-name entry number match dst-port range start number
Treestart
Range0 to 65534

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

icmp
Synopsis Enter the icmp context
Context configure filter ip-exception filter-name entry number match icmp
Treeicmp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

code number
Synopsis ICMP code value to match
Context configure filter ip-exception filter-name entry number match icmp code number
Treecode

Description

This command specifies the ICMP code value that must be present to match. The system matches on ICMP code or ICMP type, or on both values.

An entry containing Layer 4 non-zero match criteria does not match non initial (second, third, and so on) fragments of a fragmented packet because only the first fragment contains the Layer 4 information. Similarly, an entry containing an ICMP code value of 0 match criterion may match non initial fragments when the Layer 4 header is not present in a packet fragment and other match criteria are also met.

Range0 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

type number
Synopsis ICMP type value to match
Context configure filter ip-exception filter-name entry number match icmp type number
Treetype

Description

This command specifies the ICMP type value that must be present to match. The system matches on ICMP code or ICMP type, or on both values.

An entry containing Layer 4 non-zero match criteria does not match non initial (second, third, and so on) fragments of a fragmented packet because only the first fragment contains the Layer 4 information. Similarly, an entry containing an ICMP type value of 0 match criterion may match non initial fragments when the Layer 4 header is not present in a packet fragment and other match criteria are also met.

Range0 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

protocol (number | keyword)
Synopsis IP protocol as the match criterion
Context configure filter ip-exception filter-name entry number match protocol (number | keyword)
Treeprotocol
Range0 to 255
Optionstcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

src-ip
Synopsis Enter the src-ip context
Context configure filter ip-exception filter-name entry number match src-ip
Treesrc-ip
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address (ipv4-prefix-with-host-bits | ipv4-address)
Synopsis IP address to match
Context configure filter ip-exception filter-name entry number match src-ip address (ipv4-prefix-with-host-bits | ipv4-address)
Treeaddress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mask ipv4-address
Synopsis Mask applied as an AND to the IP address
Contextconfigure filter ip-exception filter-name entry number match src-ip mask ipv4-address
Treemask
Introduced25.3.R2

Platforms

7705 SAR Gen 2

src-port
Synopsis Enter the src-port context
Context configure filter ip-exception filter-name entry number match src-port
Treesrc-port
Introduced25.3.R2

Platforms

7705 SAR Gen 2

eq number
Synopsis Exact match criterion
Context configure filter ip-exception filter-name entry number match src-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gt number
Synopsis Greater than match criterion for the port number
Contextconfigure filter ip-exception filter-name entry number match src-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lt number
Synopsis Less than match criterion for the port
Contextconfigure filter ip-exception filter-name entry number match src-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

range
Synopsis Enable the range context
Context configure filter ip-exception filter-name entry number match src-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

end number
Synopsis Upper bound of the port range to match
Contextconfigure filter ip-exception filter-name entry number match src-port range end number
Treeend
Range1 to 65535

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

start number
Synopsis Lower bound of the port range to match
Contextconfigure filter ip-exception filter-name entry number match src-port range start number
Treestart
Range0 to 65534

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisFilter ID
Contextconfigure filter ip-exception filter-name filter-id number
Treefilter-id
Range1 to 65535
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-filter [filter-name] filter-name

Synopsis Enter the ip-filter list instance
Contextconfigure filter ip-filter filter-name
Treeip-filter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[filter-name] filter-name
Synopsis Filter name
Contextconfigure filter ip-filter filter-name
Treeip-filter
String length1 to 64

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

default-action keyword
Synopsis Action for packets that do not match any entry
Contextconfigure filter ip-filter filter-name default-action keyword
Treedefault-action
Optionsdrop, accept
Default drop
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure filter ip-filter filter-name description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

embed
Synopsis Enter the embed context
Context configure filter ip-filter filter-name embed
Treeembed

Description

Commands in this context configure filter policy embedding.

A previously defined IPv4 embedded filter policy or Hybrid OpenFlow switch instance can be embedded into an exclusive, template, or system filter policy at the specified offset value. Rules derived from BGP FlowSpec can also be embedded into template filter policies only.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter [name] reference offset number
Synopsis Enter the filter list instance
Contextconfigure filter ip-filter filter-name embed filter reference offset number
Treefilter

Description

Commands in this context embed a previously defined IPv4 filter policy into the filter policy at the specified offset value.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[name] reference
Synopsis IPv4 policy to be embedded in the filter
Contextconfigure filter ip-filter filter-name embed filter reference offset number
Treefilter

Reference

configure filter ip-filter filter-name

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

offset number
Synopsis Offset of the embedded filter policy
Context configure filter ip-filter filter-name embed filter reference offset number
Treefilter

Description

This command configures the offset of the embedded filter policy. The embedded filter entry X has an entry X + offset in the embedding filter.

Range0 to 2097150

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the embedded filter
Contextconfigure filter ip-filter filter-name embed filter reference offset number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure filter ip-filter filter-name entry number
Treeentry
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[entry-id] number
Synopsis ID for a match criterion and the corresponding action
Contextconfigure filter ip-filter filter-name entry number
Treeentry
Range1 to 2097151

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

action
Synopsis Enable the action context
Context configure filter ip-filter filter-name entry number action
Treeaction
Introduced25.3.R2

Platforms

7705 SAR Gen 2

accept
Synopsis Accept regular routing to forward a matching packet
Contextconfigure filter ip-filter filter-name entry number action accept
Treeaccept

Notes

The following elements are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

drop
Synopsis Drop a packet matching this entry
Context configure filter ip-filter filter-name entry number action drop
Treedrop

Notes

The following elements are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

drop-when
Synopsis Enable the drop-when context
Context configure filter ip-filter filter-name entry number action drop-when
Treedrop-when
Introduced25.3.R2

Platforms

7705 SAR Gen 2

packet-length
Synopsis Enable the packet-length context
Contextconfigure filter ip-filter filter-name entry number action drop-when packet-length
Treepacket-length

Notes

The following elements are part of a choice: packet-length or ttl.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

eq number
Synopsis Exact match criterion for the length
Context configure filter ip-filter filter-name entry number action drop-when packet-length eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gt number
Synopsis Greater than match criterion for the length
Contextconfigure filter ip-filter filter-name entry number action drop-when packet-length gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lt number
Synopsis Less than match criterion for the length
Contextconfigure filter ip-filter filter-name entry number action drop-when packet-length lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

range
Synopsis Enable the range context
Context configure filter ip-filter filter-name entry number action drop-when packet-length range
Treerange

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ttl
Synopsis Enable the ttl context
Context configure filter ip-filter filter-name entry number action drop-when ttl
Treettl

Notes

The following elements are part of a choice: packet-length or ttl.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

eq number
Synopsis Equal to condition match value
Context configure filter ip-filter filter-name entry number action drop-when ttl eq number
Treeeq
Range0 to 255

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gt number
Synopsis Greater than condition match value
Context configure filter ip-filter filter-name entry number action drop-when ttl gt number
Treegt
Range0 to 254

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lt number
Synopsis Less than condition match value
Context configure filter ip-filter filter-name entry number action drop-when ttl lt number
Treelt
Range1 to 255

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

range
Synopsis Enable the range context
Context configure filter ip-filter filter-name entry number action drop-when ttl range
Treerange

Description

This command in this context specify an inclusive range. When range is used, the start of the range (the first value entered) must be smaller than the end of the range (the second value entered).

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

forward
Synopsis Enter the forward context
Context configure filter ip-filter filter-name entry number action forward
Treeforward

Notes

The following elements are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

next-hop
Synopsis Enable the next-hop context
Context configure filter ip-filter filter-name entry number action forward next-hop
Treenext-hop

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, srv6-policy, or vprn-target.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

nh-ip
Synopsis Enable the nh-ip context
Context configure filter ip-filter filter-name entry number action forward next-hop nh-ip
Treenh-ip

Notes

The following elements are part of a mandatory choice: interface-name, nh-ip, or nh-ip-vrf.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

address ipv4-address
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIPv4 address of next hop to forward matching packets
Contextconfigure filter ip-filter filter-name entry number action forward next-hop nh-ip address ipv4-address
Treeaddress

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

nh-ip-vrf
Synopsis Enable the nh-ip-vrf context
Context configure filter ip-filter filter-name entry number action forward next-hop nh-ip-vrf
Treenh-ip-vrf

Notes

The following elements are part of a mandatory choice: interface-name, nh-ip, or nh-ip-vrf.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

address ipv4-address
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIPv4 address of next hop to forward matching packets
Contextconfigure filter ip-filter filter-name entry number action forward next-hop nh-ip-vrf address ipv4-address
Treeaddress

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

router-instance string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisRouting context for route lookup for forwarding packets
Contextconfigure filter ip-filter filter-name entry number action forward next-hop nh-ip-vrf router-instance string
Treerouter-instance

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

redirect-policy reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNext hop or forward next hop router that forwards a packet that matches this entry
Contextconfigure filter ip-filter filter-name entry number action forward redirect-policy reference
Treeredirect-policy

Reference

configure filter redirect-policy named-item

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, srv6-policy, or vprn-target.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

router-instance string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisRouter name or VPRN service name
Contextconfigure filter ip-filter filter-name entry number action forward router-instance string
Treerouter-instance

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, srv6-policy, or vprn-target.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ignore-match
Synopsis Ignore match criteria for the entry
Context configure filter ip-filter filter-name entry number action ignore-match
Treeignore-match

Notes

The following elements are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

nat
Synopsis Enable the nat context
Context configure filter ip-filter filter-name entry number action nat
Treenat

Notes

The following elements are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

nat-policy reference
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisNAT policy name when action is NAT
Contextconfigure filter ip-filter filter-name entry number action nat nat-policy reference
Treenat-policy

Reference

configure service nat nat-policy external-named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate-limit
Synopsis Enable the rate-limit context
Context configure filter ip-filter filter-name entry number action rate-limit
Treerate-limit
Introduced25.3.R2

Platforms

7705 SAR Gen 2

packet-length
Synopsis Enable the packet-length context
Contextconfigure filter ip-filter filter-name entry number action rate-limit packet-length
Treepacket-length

Notes

The following elements are part of a choice: packet-length or ttl.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

eq number
Synopsis Exact match criterion for the length
Context configure filter ip-filter filter-name entry number action rate-limit packet-length eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gt number
Synopsis Greater than match criterion for the length
Contextconfigure filter ip-filter filter-name entry number action rate-limit packet-length gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lt number
Synopsis Less than match criterion for the length
Contextconfigure filter ip-filter filter-name entry number action rate-limit packet-length lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

range
Synopsis Enable the range context
Context configure filter ip-filter filter-name entry number action rate-limit packet-length range
Treerange

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

pir (number | keyword)
Synopsis Peak information rate
Context configure filter ip-filter filter-name entry number action rate-limit pir (number | keyword)
Treepir
Range0 to 2000000000
Unitskilobps
Options max

Notes

The following elements are part of a mandatory choice: pir, policer, or pps-pir.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

policer reference
Synopsis Policer name to use for rate limiting traffic
Contextconfigure filter ip-filter filter-name entry number action rate-limit policer reference
Treepolicer

Reference

configure filter policer named-item

Notes

The following elements are part of a mandatory choice: pir, policer, or pps-pir.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ttl
Synopsis Enable the ttl context
Context configure filter ip-filter filter-name entry number action rate-limit ttl
Treettl

Notes

The following elements are part of a choice: packet-length or ttl.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

eq number
Synopsis Equal to condition match value
Context configure filter ip-filter filter-name entry number action rate-limit ttl eq number
Treeeq
Range0 to 255

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gt number
Synopsis Greater than condition match value
Context configure filter ip-filter filter-name entry number action rate-limit ttl gt number
Treegt
Range0 to 254

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lt number
Synopsis Less than condition match value
Context configure filter ip-filter filter-name entry number action rate-limit ttl lt number
Treelt
Range1 to 255

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

range
Synopsis Enable the range context
Context configure filter ip-filter filter-name entry number action rate-limit ttl range
Treerange

Description

This command in this context specify an inclusive range. When range is used, the start of the range (the first value entered) must be smaller than the end of the range (the second value entered).

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

reassemble
Synopsis Forward matching packets to reassembly function
Contextconfigure filter ip-filter filter-name entry number action reassemble
Treereassemble

Notes

The following elements are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

secondary
Synopsis Enable the secondary context
Context configure filter ip-filter filter-name entry number action secondary
Treesecondary
Introduced25.3.R2

Platforms

7705 SAR Gen 2

forward
Synopsis Enter the forward context
Context configure filter ip-filter filter-name entry number action secondary forward
Treeforward

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

next-hop
Synopsis Enable the next-hop context
Context configure filter ip-filter filter-name entry number action secondary forward next-hop
Treenext-hop

Notes

The following elements are part of a choice: next-hop, sap, sdp, or vprn-target.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

nh-ip-vrf
Synopsis Enable the nh-ip-vrf context
Context configure filter ip-filter filter-name entry number action secondary forward next-hop nh-ip-vrf
Treenh-ip-vrf

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

address ipv4-address
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIPv4 address of next hop to forward matching packets
Contextconfigure filter ip-filter filter-name entry number action secondary forward next-hop nh-ip-vrf address ipv4-address
Treeaddress

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

tcp-mss-adjust
Synopsis Adjust MSS option of TCP matching packets to configured value of tcp-mss in router interface context
Contextconfigure filter ip-filter filter-name entry number action tcp-mss-adjust
Treetcp-mss-adjust

Notes

The following elements are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure filter ip-filter filter-name entry number description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

log reference
Synopsis Log that is used for packets matching this entry
Contextconfigure filter ip-filter filter-name entry number log reference
Treelog

Reference

configure filter log number

Introduced25.3.R2

Platforms

7705 SAR Gen 2

match
Synopsis Enter the match context
Context configure filter ip-filter filter-name entry number match
Treematch

Description

Commands in this context configure match criteria for the filter entry. When the match criteria are satisfied, the action associated with the match criteria is executed.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

dscp keyword
Synopsis DSCP used as an IP filter match criterion
Contextconfigure filter ip-filter filter-name entry number match dscp keyword
Treedscp
Optionsbe, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

dst-ip
Synopsis Enter the dst-ip context
Context configure filter ip-filter filter-name entry number match dst-ip
Treedst-ip

Description

Commands in this context configure a destination address range that is used by filter policy match criteria.

Notes

The following elements are part of a choice: ip or (dst-ip and src-ip).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

address (ipv4-prefix-with-host-bits | ipv4-address)
Synopsis IPv4 address used as the match criterion
Contextconfigure filter ip-filter filter-name entry number match dst-ip address (ipv4-prefix-with-host-bits | ipv4-address)
Treeaddress

Notes

The following elements are part of a choice: (address and mask) or ip-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mask ipv4-address
Synopsis IPv4 address mask used as the match criterion
Contextconfigure filter ip-filter filter-name entry number match dst-ip mask ipv4-address
Treemask

Notes

The following elements are part of a choice: (address and mask) or ip-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

dst-port
Synopsis Enter the dst-port context
Context configure filter ip-filter filter-name entry number match dst-port
Treedst-port

Description

Commands in this context configure match criteria for the destination port.

Notes

The following elements are part of a choice: port or (dst-port and src-port).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

eq number
Synopsis Exact value as the match criterion
Context configure filter ip-filter filter-name entry number match dst-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gt number
Synopsis Greater than value as the match criterion
Contextconfigure filter ip-filter filter-name entry number match dst-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lt number
Synopsis Less than value as the match criterion
Contextconfigure filter ip-filter filter-name entry number match dst-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

range
Synopsis Enable the range context
Context configure filter ip-filter filter-name entry number match dst-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

end number
Synopsis Upper bound of the port range
Context configure filter ip-filter filter-name entry number match dst-port range end number
Treeend
Range1 to 65535

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

start number
Synopsis Lower bound of the port range
Context configure filter ip-filter filter-name entry number match dst-port range start number
Treestart
Range0 to 65534

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

fragment keyword
Synopsis Match criterion for fragmented packets
Contextconfigure filter ip-filter filter-name entry number match fragment keyword
Treefragment
Optionsfalse, true, first-only, non-first-only
Introduced25.3.R2

Platforms

7705 SAR Gen 2

icmp
Synopsis Enter the icmp context
Context configure filter ip-filter filter-name entry number match icmp
Treeicmp

Description

Commands in this context configure ICMP values to use as IP filter match criteria.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

code number
Synopsis ICMP code value to match
Context configure filter ip-filter filter-name entry number match icmp code number
Treecode

Description

This command specifies the ICMP code value that must be present to match. The system matches on ICMP code or ICMP type, or on both values.

An entry containing Layer 4 non-zero match criteria does not match non initial (second, third, and so on) fragments of a fragmented packet because only the first fragment contains the Layer 4 information. Similarly, an entry containing an ICMP code value of 0 match criterion may match non initial fragments when the Layer 4 header is not present in a packet fragment and other match criteria are also met.

Range0 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

type number
Synopsis ICMP type value to match
Context configure filter ip-filter filter-name entry number match icmp type number
Treetype

Description

This command specifies the ICMP type value that must be present to match. The system matches on ICMP code or ICMP type, or on both values.

An entry containing Layer 4 non-zero match criteria does not match non initial (second, third, and so on) fragments of a fragmented packet because only the first fragment contains the Layer 4 information. Similarly, an entry containing an ICMP type value of 0 match criterion may match non initial fragments when the Layer 4 header is not present in a packet fragment and other match criteria are also met.

Range0 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip
Synopsis Enter the ip context
Context configure filter ip-filter filter-name entry number match ip
Treeip

Notes

The following elements are part of a choice: ip or (dst-ip and src-ip).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

address (ipv4-prefix-with-host-bits | ipv4-address)
Synopsis IPv4 address used as the match criterion
Contextconfigure filter ip-filter filter-name entry number match ip address (ipv4-prefix-with-host-bits | ipv4-address)
Treeaddress

Notes

The following elements are part of a choice: (address and mask) or ip-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mask ipv4-address
Synopsis IPv4 address mask used as the match criterion
Contextconfigure filter ip-filter filter-name entry number match ip mask ipv4-address
Treemask

Notes

The following elements are part of a choice: (address and mask) or ip-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-option
Synopsis Enable the ip-option context
Context configure filter ip-filter filter-name entry number match ip-option
Treeip-option

Description

Commands in this context configure matching packets with a specific IP option, or a range of IP options, in the first option of the IP header as an IP filter match criterion.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mask number
Synopsis Mask used with the IP option value in the packet header
Contextconfigure filter ip-filter filter-name entry number match ip-option mask number
Treemask

Description

This command specifies an optional value that can be used when specifying a range of option numbers to use as the match criteria.

Range1 to 255
Default255
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

type number
Synopsis IP option to match
Context configure filter ip-filter filter-name entry number match ip-option type number
Treetype

Description

This command specifies the 8-bit option type in decimal integer, binary, or hexadecimal format. The mask is applied as an AND to the option byte, and the result is compared with the option value.

The decimal value entered for the match should be a combined value of the 8-bit option type field and not only the option number. For example, to match IP packets that contain the Router Alert option (option number = 20), enter the option type of 148 (10010100).

Range0 to 255

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

option-present boolean
Synopsis Match on any IP option present in the packet
Contextconfigure filter ip-filter filter-name entry number match option-present boolean
Treeoption-present

Description

When configured to true, the router matches on IP packets that contain any IP option in the IP header. An option field of zero is considered as no option present.

When configured to false, the router matches on IP packets that do not have an IP option present in the IP header.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

port
Synopsis Enter the port context
Context configure filter ip-filter filter-name entry number match port
Treeport

Notes

The following elements are part of a choice: port or (dst-port and src-port).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

eq number
Synopsis Exact value as the match criterion
Context configure filter ip-filter filter-name entry number match port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gt number
Synopsis Greater than value as the match criterion
Contextconfigure filter ip-filter filter-name entry number match port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lt number
Synopsis Less than value as the match criterion
Contextconfigure filter ip-filter filter-name entry number match port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

port-list reference
Synopsis Name of the port list as the match criterion
Contextconfigure filter ip-filter filter-name entry number match port port-list reference
Treeport-list

Reference

configure filter match-list port-list named-item

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

range
Synopsis Enable the range context
Context configure filter ip-filter filter-name entry number match port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

end number
Synopsis Upper bound of the port range
Context configure filter ip-filter filter-name entry number match port range end number
Treeend
Range1 to 65535

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

start number
Synopsis Lower bound of the port range
Context configure filter ip-filter filter-name entry number match port range start number
Treestart
Range0 to 65534

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

protocol (number | keyword)
Synopsis IP protocol identifier as a match criterion
Contextconfigure filter ip-filter filter-name entry number match protocol (number | keyword)
Treeprotocol
Range0 to 255
Optionstcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp

Notes

The following elements are part of a choice: protocol or protocol-list.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

src-ip
Synopsis Enter the src-ip context
Context configure filter ip-filter filter-name entry number match src-ip
Treesrc-ip

Description

Commands in this context configure a source address range that is used by filter policy match criteria.

Notes

The following elements are part of a choice: ip or (dst-ip and src-ip).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

address (ipv4-prefix-with-host-bits | ipv4-address)
Synopsis IPv4 address used as the match criterion
Contextconfigure filter ip-filter filter-name entry number match src-ip address (ipv4-prefix-with-host-bits | ipv4-address)
Treeaddress

Notes

The following elements are part of a choice: (address and mask) or ip-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mask ipv4-address
Synopsis IPv4 address mask used as the match criterion
Contextconfigure filter ip-filter filter-name entry number match src-ip mask ipv4-address
Treemask

Notes

The following elements are part of a choice: (address and mask) or ip-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

src-port
Synopsis Enter the src-port context
Context configure filter ip-filter filter-name entry number match src-port
Treesrc-port

Description

Commands in this context configure match criteria for the source port.

Notes

The following elements are part of a choice: port or (dst-port and src-port).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

eq number
Synopsis Exact value as the match criterion
Context configure filter ip-filter filter-name entry number match src-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gt number
Synopsis Greater than value as the match criterion
Contextconfigure filter ip-filter filter-name entry number match src-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lt number
Synopsis Less than value as the match criterion
Contextconfigure filter ip-filter filter-name entry number match src-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

range
Synopsis Enable the range context
Context configure filter ip-filter filter-name entry number match src-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

end number
Synopsis Upper bound of the port range
Context configure filter ip-filter filter-name entry number match src-port range end number
Treeend
Range1 to 65535

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

start number
Synopsis Lower bound of the port range
Context configure filter ip-filter filter-name entry number match src-port range start number
Treestart
Range0 to 65534

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

tcp-established
Synopsis Use ACK or RST status in TCP header as match criterion
Contextconfigure filter ip-filter filter-name entry number match tcp-established
Treetcp-established

Description

When configured to true, a match occurs when the ACK or the RST TCP flag bit is set in the TCP header of an IP packet.

Notes

The following elements are part of a choice: tcp-established or tcp-flags.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

tcp-flags
Synopsis Enter the tcp-flags context
Context configure filter ip-filter filter-name entry number match tcp-flags
Treetcp-flags

Description

Commands in this context configure the use of TCP flags as the IP filter match.

Notes

The following elements are part of a choice: tcp-established or tcp-flags.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ack boolean
Synopsis Use ACK TCP bit status in TCP header as match criterion
Contextconfigure filter ip-filter filter-name entry number match tcp-flags ack boolean
Treeack

Description

When configured to true, a match occurs when the ACK TCP flag bit, defined in RFC 793, is set in the TCP header of an IP packet.

When configured to false, a match occurs when the ACK TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

cwr boolean
Synopsis Use CWR TCP bit status in TCP header as match criterion
Contextconfigure filter ip-filter filter-name entry number match tcp-flags cwr boolean
Treecwr

Description

When configured to true, a match occurs when the Congestion Window Reduced (CWR) TCP flag bit, defined in RFC 3168, is set in the TCP header of an IP packet.

When configured to false, a match occurs when the CWR TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ece boolean
Synopsis Use ECE TCP bit status in TCP header as match criterion
Contextconfigure filter ip-filter filter-name entry number match tcp-flags ece boolean
Treeece

Description

When configured to true, a match occurs when the ECN-Echo (ECE) TCP flag bit, defined in RFC 3168, is set in the TCP header of an IP packet.

When configured to false, a match occurs when the ECE TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

fin boolean
Synopsis Use FIN TCP bit status in TCP header as match criterion
Contextconfigure filter ip-filter filter-name entry number match tcp-flags fin boolean
Treefin

Description

When configured to true, a match occurs when the FIN TCP flag bit is set in the TCP header of an IP packet.

When configured to false, a match occurs when the FIN TCP flag bit, defined in RFC 793, is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ns boolean
Synopsis Use NS TCP bit status in TCP header as match criterion
Contextconfigure filter ip-filter filter-name entry number match tcp-flags ns boolean
Treens

Description

When configured to true, a match occurs when the Nonce Sum (NS) TCP flag bit, defined in RFC 3540, is set in the TCP header of an IP packet.

When configured to false, a match occurs when the NS TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

psh boolean
Synopsis Use PSH TCP bit status in TCP header as match criterion
Contextconfigure filter ip-filter filter-name entry number match tcp-flags psh boolean
Treepsh

Description

When configured to true, a match occurs when the Push (PSH) TCP flag bit is set in the TCP header of an IP packet.

When configured to false, a match occurs when the Push (PSH) TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rst boolean
Synopsis Use RST TCP bit status in TCP header as match criterion
Contextconfigure filter ip-filter filter-name entry number match tcp-flags rst boolean
Treerst

Description

When configured to true, a match occurs when the RST TCP flag bit is set in the TCP header of an IP packet.

When configured to false, a match occurs when the RST TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

syn boolean
Synopsis Use SYN TCP bit status in TCP header as match criterion
Contextconfigure filter ip-filter filter-name entry number match tcp-flags syn boolean
Treesyn

Description

When configured to true, a match occurs when the Synchronize (SYN) TCP flag bit is set in the TCP header of an IP packet.

When configured to false, a match occurs when the SYN TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

urg boolean
Synopsis Use URG TCP bit status in TCP header as match criterion
Contextconfigure filter ip-filter filter-name entry number match tcp-flags urg boolean
Treeurg

Description

When configured to true, a match occurs when the Urgent (URG) TCP flag bit is set in the TCP header of an IP packet.

When configured to false, a match occurs when the URG TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

sticky-dest (number | keyword)
Synopsis Time before action with available PBR or PBF destination and highest priority
Contextconfigure filter ip-filter filter-name entry number sticky-dest (number | keyword)
Treesticky-dest
Range0 to 65535
Unitsseconds
Options no-hold-time-up
Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP filter ID
Contextconfigure filter ip-filter filter-name filter-id number
Treefilter-id
Range1 to 65535
Introduced25.3.R2

Platforms

7705 SAR Gen 2

scope keyword
Synopsis Scope of the filter definition
Context configure filter ip-filter filter-name scope keyword
Treescope

Description

This command configures the filter policy scope.

If the scope of the policy is template and is applied to one or more services or network interfaces, the scope cannot be changed.

Optionsexclusive, template, embedded, system, cpm
Defaulttemplate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6-exception [filter-name] filter-name

Synopsis Enter the ipv6-exception list instance
Contextconfigure filter ipv6-exception filter-name
Treeipv6-exception
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[filter-name] filter-name
Synopsis Filter name
Contextconfigure filter ipv6-exception filter-name
Treeipv6-exception
String length1 to 64

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure filter ipv6-exception filter-name entry number
Treeentry
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[entry-id] number
Synopsis ID for a match criterion and the corresponding action
Contextconfigure filter ipv6-exception filter-name entry number
Treeentry
Range1 to 2097151

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

match
Synopsis Enter the match context
Context configure filter ipv6-exception filter-name entry number match
Treematch
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dst-ip
Synopsis Enter the dst-ip context
Context configure filter ipv6-exception filter-name entry number match dst-ip
Treedst-ip
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address (ipv6-prefix-with-host-bits | ipv6-address)
Synopsis IPv6 address used as the match criterion
Contextconfigure filter ipv6-exception filter-name entry number match dst-ip address (ipv6-prefix-with-host-bits | ipv6-address)
Treeaddress

Notes

The following elements are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mask ipv6-address
Synopsis IPv6 address mask used as the match criterion
Contextconfigure filter ipv6-exception filter-name entry number match dst-ip mask ipv6-address
Treemask

Notes

The following elements are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

dst-port
Synopsis Enter the dst-port context
Context configure filter ipv6-exception filter-name entry number match dst-port
Treedst-port

Description

Commands in this context configure match criteria for the destination port.

Notes

The following elements are part of a choice: port or (dst-port and src-port).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

eq number
Synopsis Exact value as the match criterion
Context configure filter ipv6-exception filter-name entry number match dst-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gt number
Synopsis Greater than value as the match criterion
Contextconfigure filter ipv6-exception filter-name entry number match dst-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lt number
Synopsis Less than value as the match criterion
Contextconfigure filter ipv6-exception filter-name entry number match dst-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

range
Synopsis Enable the range context
Context configure filter ipv6-exception filter-name entry number match dst-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

icmp
Synopsis Enter the icmp context
Context configure filter ipv6-exception filter-name entry number match icmp
Treeicmp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

code number
Synopsis ICMPv6 code value to match
Context configure filter ipv6-exception filter-name entry number match icmp code number
Treecode

Description

This command specifies the ICMPv6 code value that must be present to match. The system matches on ICMP code or ICMP type, or on both values.

An entry containing Layer 4 non-zero match criteria does not match non initial (second, third, and so on) fragments of a fragmented packet because only the first fragment contains the Layer 4 information. Similarly, an entry containing an ICMP code value of 0 match criterion may match non-initial fragments when the Layer 4 header is not present in a packet fragment and other match criteria are also met.

Range0 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

type number
Synopsis ICMPv6 type value to match
Context configure filter ipv6-exception filter-name entry number match icmp type number
Treetype

Description

This command specifies the ICMPv6 type value that must be present to match. The system matches on ICMP code or ICMP type, or on both values.

An entry containing Layer 4 non-zero match criteria does not match non initial (second, third, and so on) fragments of a fragmented packet because only the first fragment contains the Layer 4 information. Similarly, an entry containing an ICMP type value of 0 match criterion may match non initial fragments when the Layer 4 header is not present in a packet fragment and other match criteria are also met.

Range0 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

next-header (number | keyword)
Synopsis IP protocol to match
Context configure filter ipv6-exception filter-name entry number match next-header (number | keyword)
Treenext-header
Range0 to 255
Optionstcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

port
Synopsis Enter the port context
Context configure filter ipv6-exception filter-name entry number match port
Treeport

Notes

The following elements are part of a choice: port or (dst-port and src-port).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

eq number
Synopsis Exact value as the match criterion
Context configure filter ipv6-exception filter-name entry number match port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gt number
Synopsis Greater than value as the match criterion
Contextconfigure filter ipv6-exception filter-name entry number match port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lt number
Synopsis Less than value as the match criterion
Contextconfigure filter ipv6-exception filter-name entry number match port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

range
Synopsis Enable the range context
Context configure filter ipv6-exception filter-name entry number match port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

end number
Synopsis Upper bound of the port range
Context configure filter ipv6-exception filter-name entry number match port range end number
Treeend
Range1 to 65535

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

start number
Synopsis Lower bound of the port range
Context configure filter ipv6-exception filter-name entry number match port range start number
Treestart
Range0 to 65534

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

src-ip
Synopsis Enter the src-ip context
Context configure filter ipv6-exception filter-name entry number match src-ip
Treesrc-ip
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address (ipv6-prefix-with-host-bits | ipv6-address)
Synopsis IPv6 address used as the match criterion
Contextconfigure filter ipv6-exception filter-name entry number match src-ip address (ipv6-prefix-with-host-bits | ipv6-address)
Treeaddress

Notes

The following elements are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mask ipv6-address
Synopsis IPv6 address mask used as the match criterion
Contextconfigure filter ipv6-exception filter-name entry number match src-ip mask ipv6-address
Treemask

Notes

The following elements are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

src-port
Synopsis Enter the src-port context
Context configure filter ipv6-exception filter-name entry number match src-port
Treesrc-port

Description

Commands in this context configure match criteria for the source port.

Notes

The following elements are part of a choice: port or (dst-port and src-port).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

eq number
Synopsis Exact value as the match criterion
Context configure filter ipv6-exception filter-name entry number match src-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gt number
Synopsis Greater than value as the match criterion
Contextconfigure filter ipv6-exception filter-name entry number match src-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lt number
Synopsis Less than value as the match criterion
Contextconfigure filter ipv6-exception filter-name entry number match src-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

range
Synopsis Enable the range context
Context configure filter ipv6-exception filter-name entry number match src-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisFilter ID
Contextconfigure filter ipv6-exception filter-name filter-id number
Treefilter-id
Range1 to 65535
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6-filter [filter-name] filter-name

Synopsis Enter the ipv6-filter list instance
Contextconfigure filter ipv6-filter filter-name
Treeipv6-filter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[filter-name] filter-name
Synopsis Filter name
Contextconfigure filter ipv6-filter filter-name
Treeipv6-filter
String length1 to 64

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

default-action keyword
Synopsis Action for packets that do not match any entry
Contextconfigure filter ipv6-filter filter-name default-action keyword
Treedefault-action
Optionsdrop, accept
Default drop
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure filter ipv6-filter filter-name description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

embed
Synopsis Enter the embed context
Context configure filter ipv6-filter filter-name embed
Treeembed

Description

Commands in this context configure filter policy embedding.

A previously defined IPv6 embedded filter policy or Hybrid OpenFlow switch instance can be embedded into an exclusive, template, or system filter policy at the specified offset value. Rules derived from BGP FlowSpec can also be embedded into template filter policies only.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter [name] reference offset number
Synopsis Enter the filter list instance
Contextconfigure filter ipv6-filter filter-name embed filter reference offset number
Treefilter

Description

Commands in this context embed a previously defined IPv6 filter policy into the filter policy at the specified offset value.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[name] reference
Synopsis IPv6 policy to be embedded in the filter
Contextconfigure filter ipv6-filter filter-name embed filter reference offset number
Treefilter

Reference

configure filter ipv6-filter filter-name

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

offset number
Synopsis Offset of the embedded filter policy
Context configure filter ipv6-filter filter-name embed filter reference offset number
Treefilter

Description

This command configures the offset of the embedded filter policy. The embedded filter entry X has an entry X + offset in the embedding filter.

Range0 to 2097150

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure filter ipv6-filter filter-name entry number
Treeentry
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[entry-id] number
Synopsis ID for a match criterion and the corresponding action
Contextconfigure filter ipv6-filter filter-name entry number
Treeentry
Range1 to 2097151

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

action
Synopsis Enable the action context
Context configure filter ipv6-filter filter-name entry number action
Treeaction
Introduced25.3.R2

Platforms

7705 SAR Gen 2

accept
Synopsis Accept regular routing to forward a matching packet
Contextconfigure filter ipv6-filter filter-name entry number action accept
Treeaccept

Notes

The following elements are part of a mandatory choice: accept, drop, forward, http-redirect, ignore-match, nat, or tcp-mss-adjust.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

drop
Synopsis Drop a packet matching this entry
Context configure filter ipv6-filter filter-name entry number action drop
Treedrop

Notes

The following elements are part of a mandatory choice: accept, drop, forward, http-redirect, ignore-match, nat, or tcp-mss-adjust.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

drop-when
Synopsis Enable the drop-when context
Context configure filter ipv6-filter filter-name entry number action drop-when
Treedrop-when
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hop-limit
Synopsis Enable the hop-limit context
Context configure filter ipv6-filter filter-name entry number action drop-when hop-limit
Treehop-limit

Notes

The following elements are part of a choice: hop-limit or payload-length.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

eq number
Synopsis Equal to condition match value
Context configure filter ipv6-filter filter-name entry number action drop-when hop-limit eq number
Treeeq
Range0 to 255

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gt number
Synopsis Greater than condition match value
Context configure filter ipv6-filter filter-name entry number action drop-when hop-limit gt number
Treegt
Range0 to 254

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lt number
Synopsis Less than condition match value
Context configure filter ipv6-filter filter-name entry number action drop-when hop-limit lt number
Treelt
Range1 to 255

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

range
Synopsis Enable the range context
Context configure filter ipv6-filter filter-name entry number action drop-when hop-limit range
Treerange

Description

This command in this context specify an inclusive range. When range is used, the start of the range (the first value entered) must be smaller than the end of the range (the second value entered).

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

payload-length
Synopsis Enable the payload-length context
Contextconfigure filter ipv6-filter filter-name entry number action drop-when payload-length
Treepayload-length

Notes

The following elements are part of a choice: hop-limit or payload-length.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

eq number
Synopsis Exact match criterion for the length
Context configure filter ipv6-filter filter-name entry number action drop-when payload-length eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gt number
Synopsis Greater than match criterion for the length
Contextconfigure filter ipv6-filter filter-name entry number action drop-when payload-length gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lt number
Synopsis Less than match criterion for the length
Contextconfigure filter ipv6-filter filter-name entry number action drop-when payload-length lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

range
Synopsis Enable the range context
Context configure filter ipv6-filter filter-name entry number action drop-when payload-length range
Treerange

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

forward
Synopsis Enter the forward context
Context configure filter ipv6-filter filter-name entry number action forward
Treeforward

Notes

The following elements are part of a mandatory choice: accept, drop, forward, http-redirect, ignore-match, nat, or tcp-mss-adjust.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

next-hop
Synopsis Enable the next-hop context
Context configure filter ipv6-filter filter-name entry number action forward next-hop
Treenext-hop

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, srv6-policy, or vprn-target.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

nh-ip
Synopsis Enable the nh-ip context
Context configure filter ipv6-filter filter-name entry number action forward next-hop nh-ip
Treenh-ip

Notes

The following elements are part of a mandatory choice: nh-ip or nh-ip-vrf.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

address ipv6-address
Synopsis IPv6 address of next hop to forward matching packets
Contextconfigure filter ipv6-filter filter-name entry number action forward next-hop nh-ip address ipv6-address
Treeaddress

Description

This command specifies the IPv6 address of a direct or indirect next hop to which matching packets are forwarded.

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

nh-ip-vrf
Synopsis Enable the nh-ip-vrf context
Context configure filter ipv6-filter filter-name entry number action forward next-hop nh-ip-vrf
Treenh-ip-vrf

Notes

The following elements are part of a mandatory choice: nh-ip or nh-ip-vrf.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

address ipv6-address
Synopsis IPv6 address of next hop to forward matching packets
Contextconfigure filter ipv6-filter filter-name entry number action forward next-hop nh-ip-vrf address ipv6-address
Treeaddress

Description

This command specifies the IPv6 address of a direct or indirect next hop to which matching packets are forwarded.

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

redirect-policy reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNext hop or forward next hop router that forwards a packet that matches this entry
Contextconfigure filter ipv6-filter filter-name entry number action forward redirect-policy reference
Treeredirect-policy

Reference

configure filter redirect-policy named-item

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, srv6-policy, or vprn-target.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

router-instance string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisRouter name or VPRN service name
Contextconfigure filter ipv6-filter filter-name entry number action forward router-instance string
Treerouter-instance

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, srv6-policy, or vprn-target.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ignore-match
Synopsis Ignore match criteria for the entry
Context configure filter ipv6-filter filter-name entry number action ignore-match
Treeignore-match

Notes

The following elements are part of a mandatory choice: accept, drop, forward, http-redirect, ignore-match, nat, or tcp-mss-adjust.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate-limit
Synopsis Enable the rate-limit context
Context configure filter ipv6-filter filter-name entry number action rate-limit
Treerate-limit
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hop-limit
Synopsis Enable the hop-limit context
Context configure filter ipv6-filter filter-name entry number action rate-limit hop-limit
Treehop-limit

Notes

The following elements are part of a choice: hop-limit or payload-length.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

eq number
Synopsis Equal to condition match value
Context configure filter ipv6-filter filter-name entry number action rate-limit hop-limit eq number
Treeeq
Range0 to 255

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gt number
Synopsis Greater than condition match value
Context configure filter ipv6-filter filter-name entry number action rate-limit hop-limit gt number
Treegt
Range0 to 254

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lt number
Synopsis Less than condition match value
Context configure filter ipv6-filter filter-name entry number action rate-limit hop-limit lt number
Treelt
Range1 to 255

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

range
Synopsis Enable the range context
Context configure filter ipv6-filter filter-name entry number action rate-limit hop-limit range
Treerange

Description

This command in this context specify an inclusive range. When range is used, the start of the range (the first value entered) must be smaller than the end of the range (the second value entered).

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

payload-length
Synopsis Enable the payload-length context
Contextconfigure filter ipv6-filter filter-name entry number action rate-limit payload-length
Treepayload-length

Notes

The following elements are part of a choice: hop-limit or payload-length.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

eq number
Synopsis Exact match criterion for the length
Context configure filter ipv6-filter filter-name entry number action rate-limit payload-length eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gt number
Synopsis Greater than match criterion for the length
Contextconfigure filter ipv6-filter filter-name entry number action rate-limit payload-length gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lt number
Synopsis Less than match criterion for the length
Contextconfigure filter ipv6-filter filter-name entry number action rate-limit payload-length lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

range
Synopsis Enable the range context
Context configure filter ipv6-filter filter-name entry number action rate-limit payload-length range
Treerange

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

pir (number | keyword)
Synopsis Peak information rate
Context configure filter ipv6-filter filter-name entry number action rate-limit pir (number | keyword)
Treepir
Range0 to 2000000000
Unitskilobps
Options max

Notes

The following elements are part of a mandatory choice: pir, policer, or pps-pir.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

policer reference
Synopsis Policer name to use for rate limiting traffic
Contextconfigure filter ipv6-filter filter-name entry number action rate-limit policer reference
Treepolicer

Reference

configure filter policer named-item

Notes

The following elements are part of a mandatory choice: pir, policer, or pps-pir.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

secondary
Synopsis Enable the secondary context
Context configure filter ipv6-filter filter-name entry number action secondary
Treesecondary
Introduced25.3.R2

Platforms

7705 SAR Gen 2

forward
Synopsis Enter the forward context
Context configure filter ipv6-filter filter-name entry number action secondary forward
Treeforward

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

next-hop
Synopsis Enable the next-hop context
Context configure filter ipv6-filter filter-name entry number action secondary forward next-hop
Treenext-hop

Notes

The following elements are part of a choice: next-hop, sap, sdp, or vprn-target.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

nh-ip-vrf
Synopsis Enable the nh-ip-vrf context
Context configure filter ipv6-filter filter-name entry number action secondary forward next-hop nh-ip-vrf
Treenh-ip-vrf

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

address ipv6-address
Synopsis IPv6 address of next hop to forward matching packets
Contextconfigure filter ipv6-filter filter-name entry number action secondary forward next-hop nh-ip-vrf address ipv6-address
Treeaddress

Description

This command specifies the IPv6 address of a direct or indirect next hop to which matching packets are forwarded.

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

tcp-mss-adjust
Synopsis Adjust MSS option of TCP matching packets to configured value of tcp-mss in router interface context
Contextconfigure filter ipv6-filter filter-name entry number action tcp-mss-adjust
Treetcp-mss-adjust

Notes

The following elements are part of a mandatory choice: accept, drop, forward, http-redirect, ignore-match, nat, or tcp-mss-adjust.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

log reference
Synopsis Log that is used for packets matching this entry
Contextconfigure filter ipv6-filter filter-name entry number log reference
Treelog

Reference

configure filter log number

Introduced25.3.R2

Platforms

7705 SAR Gen 2

match
Synopsis Enter the match context
Context configure filter ipv6-filter filter-name entry number match
Treematch

Description

Commands in this context provide match criteria for the filter entry. When the match criteria are satisfied, the action associated with the match criteria is executed.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

dscp keyword
Synopsis DSCP used as an IP filter match criterion
Contextconfigure filter ipv6-filter filter-name entry number match dscp keyword
Treedscp
Optionsbe, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

dst-ip
Synopsis Enter the dst-ip context
Context configure filter ipv6-filter filter-name entry number match dst-ip
Treedst-ip

Description

Commands in this context configure a destination address range that is used by filter policy match criteria.

Notes

The following elements are part of a choice: ip or (dst-ip and src-ip).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

address (ipv6-prefix-with-host-bits | ipv6-address)
Synopsis IPv6 address used as the match criterion
Contextconfigure filter ipv6-filter filter-name entry number match dst-ip address (ipv6-prefix-with-host-bits | ipv6-address)
Treeaddress

Notes

The following elements are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mask ipv6-address
Synopsis IPv6 address mask used as the match criterion
Contextconfigure filter ipv6-filter filter-name entry number match dst-ip mask ipv6-address
Treemask

Notes

The following elements are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

dst-port
Synopsis Enter the dst-port context
Context configure filter ipv6-filter filter-name entry number match dst-port
Treedst-port

Description

Commands in this context configure match criteria for the destination port.

Notes

The following elements are part of a choice: port or (dst-port and src-port).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

eq number
Synopsis Exact value as the match criterion
Context configure filter ipv6-filter filter-name entry number match dst-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gt number
Synopsis Greater than value as the match criterion
Contextconfigure filter ipv6-filter filter-name entry number match dst-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lt number
Synopsis Less than value as the match criterion
Contextconfigure filter ipv6-filter filter-name entry number match dst-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

range
Synopsis Enable the range context
Context configure filter ipv6-filter filter-name entry number match dst-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

end number
Synopsis Upper bound of the port range
Context configure filter ipv6-filter filter-name entry number match dst-port range end number
Treeend
Range1 to 65535

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

extension-header
Synopsis Enter the extension-header context
Contextconfigure filter ipv6-filter filter-name entry number match extension-header
Treeextension-header
Introduced25.3.R2

Platforms

7705 SAR Gen 2

esp boolean
Synopsis Match a packet as per the existence of an Encapsulation security payload extension header
Contextconfigure filter ipv6-filter filter-name entry number match extension-header esp boolean
Treeesp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

flow-label
Synopsis Enable the flow-label context
Context configure filter ipv6-filter filter-name entry number match flow-label
Treeflow-label

Description

Commands in this context configure the flow label and optional mask match condition.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mask number
Synopsis Flow label mask for the IPv6 filter entry
Contextconfigure filter ipv6-filter filter-name entry number match flow-label mask number
Treemask

Description

This command specifies the IPv6 address mask for the flow label filter entry. This value can be expressed in decimal, hexadecimal, or binary format.

Range1 to 1048575
Default1048575
Introduced25.3.R2

Platforms

7705 SAR Gen 2

value number
Synopsis Flow label as a match criterion
Context configure filter ipv6-filter filter-name entry number match flow-label value number
Treevalue

Description

This command specifies the flow label to use as a match criterion. This value can be expressed in decimal, hexadecimal, or binary format.

Range0 to 1048575

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

fragment keyword
Synopsis Match criterion for fragmented packages
Contextconfigure filter ipv6-filter filter-name entry number match fragment keyword
Treefragment
Optionsfalse, true, first-only, non-first-only
Introduced25.3.R2

Platforms

7705 SAR Gen 2

icmp
Synopsis Enter the icmp context
Context configure filter ipv6-filter filter-name entry number match icmp
Treeicmp

Description

Commands in this context configure ICMP values to use as IPv6 filter match criteria.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

code number
Synopsis ICMPv6 code value to match
Context configure filter ipv6-filter filter-name entry number match icmp code number
Treecode

Description

This command specifies the ICMPv6 code value that must be present to match. The system matches on ICMP code or ICMP type, or on both values.

An entry containing Layer 4 non-zero match criteria does not match non initial (second, third, and so on) fragments of a fragmented packet because only the first fragment contains the Layer 4 information. Similarly, an entry containing an ICMP code value of 0 match criterion may match non-initial fragments when the Layer 4 header is not present in a packet fragment and other match criteria are also met.

Range0 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

type number
Synopsis ICMPv6 type value to match
Context configure filter ipv6-filter filter-name entry number match icmp type number
Treetype

Description

This command specifies the ICMPv6 type value that must be present to match. The system matches on ICMP code or ICMP type, or on both values.

An entry containing Layer 4 non-zero match criteria does not match non initial (second, third, and so on) fragments of a fragmented packet because only the first fragment contains the Layer 4 information. Similarly, an entry containing an ICMP type value of 0 match criterion may match non initial fragments when the Layer 4 header is not present in a packet fragment and other match criteria are also met.

Range0 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip
Synopsis Enter the ip context
Context configure filter ipv6-filter filter-name entry number match ip
Treeip

Notes

The following elements are part of a choice: ip or (dst-ip and src-ip).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

address (ipv6-prefix-with-host-bits | ipv6-address)
Synopsis IPv6 address used as the match criterion
Contextconfigure filter ipv6-filter filter-name entry number match ip address (ipv6-prefix-with-host-bits | ipv6-address)
Treeaddress

Notes

The following elements are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mask ipv6-address
Synopsis IPv6 address mask used as the match criterion
Contextconfigure filter ipv6-filter filter-name entry number match ip mask ipv6-address
Treemask

Notes

The following elements are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

next-header (number | keyword)
Synopsis IP protocol to match
Context configure filter ipv6-filter filter-name entry number match next-header (number | keyword)
Treenext-header
Range0 to 255
Optionstcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp

Notes

The following elements are part of a choice: next-header or next-header-list.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

port
Synopsis Enter the port context
Context configure filter ipv6-filter filter-name entry number match port
Treeport

Notes

The following elements are part of a choice: port or (dst-port and src-port).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

eq number
Synopsis Exact value as the match criterion
Context configure filter ipv6-filter filter-name entry number match port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gt number
Synopsis Greater than value as the match criterion
Contextconfigure filter ipv6-filter filter-name entry number match port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lt number
Synopsis Less than value as the match criterion
Contextconfigure filter ipv6-filter filter-name entry number match port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

range
Synopsis Enable the range context
Context configure filter ipv6-filter filter-name entry number match port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

end number
Synopsis Upper bound of the port range
Context configure filter ipv6-filter filter-name entry number match port range end number
Treeend
Range1 to 65535

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

start number
Synopsis Lower bound of the port range
Context configure filter ipv6-filter filter-name entry number match port range start number
Treestart
Range0 to 65534

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

src-ip
Synopsis Enter the src-ip context
Context configure filter ipv6-filter filter-name entry number match src-ip
Treesrc-ip

Description

Commands in this context configure a source address range that is used by filter policy match criteria.

Notes

The following elements are part of a choice: ip or (dst-ip and src-ip).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

address (ipv6-prefix-with-host-bits | ipv6-address)
Synopsis IPv6 address used as the match criterion
Contextconfigure filter ipv6-filter filter-name entry number match src-ip address (ipv6-prefix-with-host-bits | ipv6-address)
Treeaddress

Notes

The following elements are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mask ipv6-address
Synopsis IPv6 address mask used as the match criterion
Contextconfigure filter ipv6-filter filter-name entry number match src-ip mask ipv6-address
Treemask

Notes

The following elements are part of a choice: (address and mask) or ipv6-prefix-list.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

src-port
Synopsis Enter the src-port context
Context configure filter ipv6-filter filter-name entry number match src-port
Treesrc-port

Description

Commands in this context configure match criteria for the source port.

Notes

The following elements are part of a choice: port or (dst-port and src-port).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

eq number
Synopsis Exact value as the match criterion
Context configure filter ipv6-filter filter-name entry number match src-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gt number
Synopsis Greater than value as the match criterion
Contextconfigure filter ipv6-filter filter-name entry number match src-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lt number
Synopsis Less than value as the match criterion
Contextconfigure filter ipv6-filter filter-name entry number match src-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

range
Synopsis Enable the range context
Context configure filter ipv6-filter filter-name entry number match src-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

end number
Synopsis Upper bound of the port range
Context configure filter ipv6-filter filter-name entry number match src-port range end number
Treeend
Range1 to 65535

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

tcp-established
Synopsis Use ACK or RST status in TCP header as match criterion
Contextconfigure filter ipv6-filter filter-name entry number match tcp-established
Treetcp-established

Description

When configured to true, a match occurs when the ACK or the RST TCP flag bit is set in the TCP header of an IP packet.

Notes

The following elements are part of a choice: tcp-established or tcp-flags.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

tcp-flags
Synopsis Enter the tcp-flags context
Context configure filter ipv6-filter filter-name entry number match tcp-flags
Treetcp-flags

Description

Commands in this context configure the use of TCP flags as the IP filter match.

Notes

The following elements are part of a choice: tcp-established or tcp-flags.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ack boolean
Synopsis Use ACK TCP bit status in TCP header as match criterion
Contextconfigure filter ipv6-filter filter-name entry number match tcp-flags ack boolean
Treeack

Description

When configured to true, a match occurs when the ACK TCP flag bit, defined in RFC 793, is set in the TCP header of an IP packet.

When configured to false, a match occurs when the ACK TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

cwr boolean
Synopsis Use CWR TCP bit status in TCP header as match criterion
Contextconfigure filter ipv6-filter filter-name entry number match tcp-flags cwr boolean
Treecwr

Description

When configured to true, a match occurs when the Congestion Window Reduced (CWR) TCP flag bit, defined in RFC 3168, is set in the TCP header of an IP packet.

When configured to false, a match occurs when the CWR TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ece boolean
Synopsis Use ECE TCP bit status in TCP header as match criterion
Contextconfigure filter ipv6-filter filter-name entry number match tcp-flags ece boolean
Treeece

Description

When configured to true, a match occurs when the ECN-Echo (ECE) TCP flag bit, defined in RFC 3168, is set in the TCP header of an IP packet.

When configured to false, a match occurs when the ECE TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

fin boolean
Synopsis Use FIN TCP bit status in TCP header as match criterion
Contextconfigure filter ipv6-filter filter-name entry number match tcp-flags fin boolean
Treefin

Description

When configured to true, a match occurs when the FIN TCP flag bit is set in the TCP header of an IP packet.

When configured to false, a match occurs when the FIN TCP flag bit, defined in RFC 793, is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ns boolean
Synopsis Use NS TCP bit status in TCP header as match criterion
Contextconfigure filter ipv6-filter filter-name entry number match tcp-flags ns boolean
Treens

Description

When configured to true, a match occurs when the Nonce Sum (NS) TCP flag bit, defined in RFC 3540, is set in the TCP header of an IP packet.

When configured to false, a match occurs when the NS TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

psh boolean
Synopsis Use PSH TCP bit status in TCP header as match criterion
Contextconfigure filter ipv6-filter filter-name entry number match tcp-flags psh boolean
Treepsh

Description

When configured to true, a match occurs when the Push (PSH) TCP flag bit is set in the TCP header of an IP packet.

When configured to false, a match occurs when the Push (PSH) TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rst boolean
Synopsis Use RST TCP bit status in TCP header as match criterion
Contextconfigure filter ipv6-filter filter-name entry number match tcp-flags rst boolean
Treerst

Description

When configured to true, a match occurs when the RST TCP flag bit is set in the TCP header of an IP packet.

When configured to false, a match occurs when the RST TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

syn boolean
Synopsis Use SYN TCP bit status in TCP header as match criterion
Contextconfigure filter ipv6-filter filter-name entry number match tcp-flags syn boolean
Treesyn

Description

When configured to true, a match occurs when the Synchronize (SYN) TCP flag bit is set in the TCP header of an IP packet.

When configured to false, a match occurs when the SYN TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

urg boolean
Synopsis Use URG TCP bit status in TCP header as match criterion
Contextconfigure filter ipv6-filter filter-name entry number match tcp-flags urg boolean
Treeurg

Description

When configured to true, a match occurs when the Urgent (URG) TCP flag bit is set in the TCP header of an IP packet.

When configured to false, a match occurs when the URG TCP flag bit is not set in the TCP header of an IP packet.

When unconfigured, the system does not use the TCP flag as a match criterion.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

sticky-dest (number | keyword)
Synopsis Time before action with available PBR or PBF destination and highest priority
Contextconfigure filter ipv6-filter filter-name entry number sticky-dest (number | keyword)
Treesticky-dest
Range0 to 65535
Unitsseconds
Options no-hold-time-up
Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIPv6 filter identifier
Contextconfigure filter ipv6-filter filter-name filter-id number
Treefilter-id
Range1 to 65535
Introduced25.3.R2

Platforms

7705 SAR Gen 2

scope keyword
Synopsis Scope of the filter definition
Context configure filter ipv6-filter filter-name scope keyword
Treescope

Description

This command configures the filter policy scope.

If the scope of the policy is template and is applied to one or more services or network interfaces, the scope cannot be changed.

Optionsexclusive, template, embedded, system, cpm
Defaulttemplate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

log [log-id] number

Synopsis Enter the log list instance
Context configure filter log number
Treelog
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[log-id] number
Synopsis Filter log identifier
Context configure filter log number
Treelog
Range101 to 199

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of filter logging
Contextconfigure filter log number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description-or-empty
Synopsis Text description
Context configure filter log number description description-or-empty
Treedescription
String length0 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

destination
Synopsis Enter the destination context
Context configure filter log number destination
Treedestination
Introduced25.3.R2

Platforms

7705 SAR Gen 2

memory
Synopsis Enter the memory context
Context configure filter log number destination memory
Treememory

Notes

The following elements are part of a choice: memory or syslog.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

max-entries number
Synopsis Maximum number of memory entries that the log can store
Contextconfigure filter log number destination memory max-entries number
Treemax-entries
Range1 to 50000
Default1000
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

stop-on-full boolean
Synopsis Stop logging when maximum number of memory entries is reached or wrap-around is used
Contextconfigure filter log number destination memory stop-on-full boolean
Treestop-on-full
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

syslog
Synopsis Enter the syslog context
Context configure filter log number destination syslog
Treesyslog

Notes

The following elements are part of a choice: memory or syslog.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

name reference
Synopsis Syslog server definition ID
Context configure filter log number destination syslog name reference
Treename

Reference

configure log syslog log-syslog-name

Introduced25.3.R2

Platforms

7705 SAR Gen 2

summary
Synopsis Enter the summary context
Context configure filter log number destination syslog summary
Treesummary
Introduced25.3.R2

Platforms

7705 SAR Gen 2

match-list

Synopsis Enter the match-list context
Context configure filter match-list
Treematch-list

Description

Commands in this context configure match lists to be used in filter policies (IOM/FP and CPM).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-prefix-list [prefix-list-name] named-item
Synopsis Enter the ip-prefix-list list instance
Contextconfigure filter match-list ip-prefix-list named-item
Treeip-prefix-list
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[prefix-list-name] named-item
Synopsis IP prefix list name
Context configure filter match-list ip-prefix-list named-item
Treeip-prefix-list
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

apply-path
Synopsis Enter the apply-path context
Context configure filter match-list ip-prefix-list named-item apply-path
Treeapply-path
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp-peers [criterion-index] number
Synopsis Enter the bgp-peers list instance
Contextconfigure filter match-list ip-prefix-list named-item apply-path bgp-peers number
Treebgp-peers
Introduced25.3.R2

Platforms

7705 SAR Gen 2

group regular-expression-not-all-spaces
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisRegular expression to match against the base router BGP instance group configuration
Contextconfigure filter match-list ip-prefix-list named-item apply-path bgp-peers number group regular-expression-not-all-spaces
Treegroup
String length1 to 255

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

neighbor regular-expression-not-all-spaces
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisRegular expression to match against the base router BGP instance neighbor configuration
Contextconfigure filter match-list ip-prefix-list named-item apply-path bgp-peers number neighbor regular-expression-not-all-spaces
Treeneighbor
String length1 to 255

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

prefix [ip-prefix] ipv4-prefix
Synopsis Add a list entry for prefix
Context configure filter match-list ip-prefix-list named-item prefix ipv4-prefix
Treeprefix

Description

Commands in this context add IPv4 prefixes to the prefix match list. Prefixes can overlap IPv4 address space.

An IPv4 prefix addition is blocked if resource exhaustion is detected anywhere in the system due to filter policies that use the prefix list.

Max. instances8192
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ip-prefix] ipv4-prefix
Synopsis IPv4 prefix to be added to the prefix list
Contextconfigure filter match-list ip-prefix-list named-item prefix ipv4-prefix
Treeprefix

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

prefix-exclude [ip-prefix] ipv4-prefix
Synopsis Add a list entry for prefix-exclude
Contextconfigure filter match-list ip-prefix-list named-item prefix-exclude ipv4-prefix
Treeprefix-exclude

Description

Commands in this context exclude IPv4 prefixes from the prefix match list.

This command is mutually exclusive with the apply-path command.

Max. instances512
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6-prefix-list [prefix-list-name] named-item
Synopsis Enter the ipv6-prefix-list list instance
Contextconfigure filter match-list ipv6-prefix-list named-item
Treeipv6-prefix-list
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[prefix-list-name] named-item
Synopsis IP prefix list name
Context configure filter match-list ipv6-prefix-list named-item
Treeipv6-prefix-list
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

apply-path
Synopsis Enter the apply-path context
Context configure filter match-list ipv6-prefix-list named-item apply-path
Treeapply-path
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp-peers [criterion-index] number
Synopsis Enter the bgp-peers list instance
Contextconfigure filter match-list ipv6-prefix-list named-item apply-path bgp-peers number
Treebgp-peers
Introduced25.3.R2

Platforms

7705 SAR Gen 2

group regular-expression-not-all-spaces
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisRegular expression to match against the base router BGP instance group configuration
Contextconfigure filter match-list ipv6-prefix-list named-item apply-path bgp-peers number group regular-expression-not-all-spaces
Treegroup
String length1 to 255

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

neighbor regular-expression-not-all-spaces
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisRegular expression to match against the base router BGP instance neighbor configuration
Contextconfigure filter match-list ipv6-prefix-list named-item apply-path bgp-peers number neighbor regular-expression-not-all-spaces
Treeneighbor
String length1 to 255

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

prefix-exclude [ipv6-prefix] ipv6-prefix
Synopsis Add a list entry for prefix-exclude
Contextconfigure filter match-list ipv6-prefix-list named-item prefix-exclude ipv6-prefix
Treeprefix-exclude

Description

Commands in this context exclude IPv6 prefixes from the prefix match list.

This command is mutually exclusive with the apply-path command.

Max. instances512
Introduced25.3.R2

Platforms

7705 SAR Gen 2

port-list [port-list-name] named-item
Synopsis Enter the port-list list instance
Contextconfigure filter match-list port-list named-item
Treeport-list
Max. instances5120
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[port-list-name] named-item
Synopsis Port list name
Contextconfigure filter match-list port-list named-item
Treeport-list

Description

This command specifies the port list name. If special characters are used (#, $, spaces, and so on), the string must be enclosed within double quotes.

String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

port [value] number
Synopsis Add a list entry for port
Context configure filter match-list port-list named-item port number
Treeport
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[value] number
Synopsis Port value
Contextconfigure filter match-list port-list named-item port number
Treeport
Range0 to 65535

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

range start number end number
Synopsis Add a list entry for range
Context configure filter match-list port-list named-item range start number end number
Treerange
Introduced25.3.R2

Platforms

7705 SAR Gen 2

start number
Synopsis Lower bound of the port list range
Context configure filter match-list port-list named-item range start number end number
Treerange
Range0 to 65534

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

end number
Synopsis Upper bound of the port list range
Context configure filter match-list port-list named-item range start number end number
Treerange
Range1 to 65535

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

protocol-list [protocol-list-name] named-item
Synopsis Enter the protocol-list list instance
Contextconfigure filter match-list protocol-list named-item
Treeprotocol-list
Max. instances512
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[protocol-list-name] named-item
Synopsis Protocol list name
Context configure filter match-list protocol-list named-item
Treeprotocol-list
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

protocol [protocol-id] (number | keyword)
Synopsis Add a list entry for protocol
Context configure filter match-list protocol-list named-item protocol (number | keyword)
Treeprotocol
Max. instances32
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[protocol-id] (number | keyword)
Synopsis IP protocol identifier
Context configure filter match-list protocol-list named-item protocol (number | keyword)
Treeprotocol
Range0 to 255
Optionsicmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

md-auto-id

Synopsis Enter the md-auto-id context
Context configure filter md-auto-id
Treemd-auto-id
Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter-id-range
Synopsis Enable the filter-id-range context
Contextconfigure filter md-auto-id filter-id-range
Treefilter-id-range
Introduced25.3.R2

Platforms

7705 SAR Gen 2

end number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisUpper bound of the ID range
Contextconfigure filter md-auto-id filter-id-range end number
Treeend
Range1 to 65535

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

start number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisLower bound of the ID range
Contextconfigure filter md-auto-id filter-id-range start number
Treestart
Range1 to 65535

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

policer [policer-name] named-item

Synopsis Enter the policer list instance
Contextconfigure filter policer named-item
Treepolicer

Description

Commands in this context configure policer options.

Max. instances8192
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[policer-name] named-item
Synopsis Name of the policer for use in a filter policy
Contextconfigure filter policer named-item
Treepolicer
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure filter policer named-item description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mbs (number | keyword)
Synopsis Maximum burst size
Context configure filter policer named-item mbs (number | keyword)
Treembs
Range0 to 268435456
Unitsbytes
Options auto
Default auto

Notes

The following elements are part of a choice: (mbs and pir) or pps-pir.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

pir number
Synopsis Peak information rate
Context configure filter policer named-item pir number
Treepir
Range0 to 2000000000
Unitskilobps

Notes

The following elements are part of a choice: (mbs and pir) or pps-pir.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

scope keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPolicer scope
Contextconfigure filter policer named-item scope keyword
Treescope

Description

This command configures the scope for the policer object.

When the system scope is configured, it creates an instance of the policer for each direction immediately after the policer is configured and shares the instance with all filter entries that reference that policer name applied in the same direction.

When the filter scope is configured, it configures the policer instance to be shared by rate-limit entries that are part of the same filter policy and are applied in the same direction.

Options

filter – Policer shared by entries in same filter policer

system – Single policer shared by the system

Defaultfilter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

redirect-policy [redirect-policy-name] named-item

Synopsis Enter the redirect-policy list instance
Contextconfigure filter redirect-policy named-item
Treeredirect-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[redirect-policy-name] named-item
Synopsis Redirect policy name
Context configure filter redirect-policy named-item
Treeredirect-policy

Description

This command specifies the redirect policy name. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes.

String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the redirect policy
Contextconfigure filter redirect-policy named-item admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

destination [destination-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Enter the destination list instance
Contextconfigure filter redirect-policy named-item destination (ipv4-address-no-zone | ipv6-address-no-zone)
Treedestination
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[destination-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address and type of destination
Context configure filter redirect-policy named-item destination (ipv4-address-no-zone | ipv6-address-no-zone)
Treedestination

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the destination
Contextconfigure filter redirect-policy named-item destination (ipv4-address-no-zone | ipv6-address-no-zone) admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ping-test
Synopsis Enable the ping-test context
Context configure filter redirect-policy named-item destination (ipv4-address-no-zone | ipv6-address-no-zone) ping-test
Treeping-test
Introduced25.3.R2

Platforms

7705 SAR Gen 2

drop-count number
Synopsis Number of consecutive requests that fail before destination is declared unreachable
Contextconfigure filter redirect-policy named-item destination (ipv4-address-no-zone | ipv6-address-no-zone) ping-test drop-count number
Treedrop-count
Range1 to 60
Default3
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

hold-down number
Synopsis Time for the system to be held down if this test has marked it unreachable
Contextconfigure filter redirect-policy named-item destination (ipv4-address-no-zone | ipv6-address-no-zone) ping-test hold-down number
Treehold-down
Range0 to 86400
Unitsseconds
Default 0
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interval number
Synopsis Time between consecutive requests which are sent to the far end host
Contextconfigure filter redirect-policy named-item destination (ipv4-address-no-zone | ipv6-address-no-zone) ping-test interval number
Treeinterval
Range1 to 60
Unitsseconds
Default 1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

source-address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Source address to use in the IP packet of the ping test
Contextconfigure filter redirect-policy named-item destination (ipv4-address-no-zone | ipv6-address-no-zone) ping-test source-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treesource-address
Introduced25.3.R2

Platforms

7705 SAR Gen 2

timeout number
Synopsis Time required to receive a response from the far end host
Contextconfigure filter redirect-policy named-item destination (ipv4-address-no-zone | ipv6-address-no-zone) ping-test timeout number
Treetimeout
Range1 to 60
Unitsseconds
Default 1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority number
Synopsis Priority for this destination
Context configure filter redirect-policy named-item destination (ipv4-address-no-zone | ipv6-address-no-zone) priority number
Treepriority
Range1 to 255
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

notify-dest-change boolean
Synopsis Send notifications when the active destination changes
Contextconfigure filter redirect-policy named-item notify-dest-change boolean
Treenotify-dest-change

Description

When configured to true, notifications (such as Log and SNMP) are sent when the active destination of a redirect policy changes. No notification is sent when there are no more active destinations (as this scenario is covered by another notification).

When configured to false, the notification generation is disabled.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sticky-dest (number | keyword)
Synopsis Time required by system before applying the current best destination as active destination
Contextconfigure filter redirect-policy named-item sticky-dest (number | keyword)
Treesticky-dest
Range0 to 65535
Unitsseconds
Options no-hold-time-up
Introduced25.3.R2

Platforms

7705 SAR Gen 2

redirect-policy-binding [binding-name] named-item

Synopsis Enter the redirect-policy-binding list instance
Contextconfigure filter redirect-policy-binding named-item
Treeredirect-policy-binding
Max. instances16
Introduced25.3.R2

Platforms

7705 SAR Gen 2

binding-operator keyword
Synopsis Logical operator used to obtain the master test result
Contextconfigure filter redirect-policy-binding named-item binding-operator keyword
Treebinding-operator

Description

This command configures the logical operator to use with the destinations' test results to obtain the master test result (the redirect policy binding test result).

Optionsand, or
Default and
Introduced25.3.R2

Platforms

7705 SAR Gen 2

redirect-policy [redirect-policy-name] reference
Synopsis Enter the redirect-policy list instance
Contextconfigure filter redirect-policy-binding named-item redirect-policy reference
Treeredirect-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

destination [destination-address] reference
Synopsis Add a list entry for destination
Contextconfigure filter redirect-policy-binding named-item redirect-policy reference destination reference
Treedestination
Min. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

system-filter

Synopsis Enter the system-filter context
Contextconfigure filter system-filter
Treesystem-filter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip [ip-filter] reference
Synopsis Add a list entry for ip
Context configure filter system-filter ip reference
Treeip
Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ip-filter] reference
Synopsis Active IPv4 system filter policy
Context configure filter system-filter ip reference
Treeip

Reference

configure filter ip-filter filter-name

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6 [ipv6-filter] reference
Synopsis Add a list entry for ipv6
Context configure filter system-filter ipv6 reference
Treeipv6
Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ipv6-filter] reference
Synopsis Active IPv6 system filter policy
Context configure filter system-filter ipv6 reference
Treeipv6

Reference

configure filter ipv6-filter filter-name

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2