isa commands

configure 
isa 
apply-groups reference
apply-groups-exclude reference
nat-group number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
log 
suppress-lsn-events boolean
suppress-lsn-sub-blocks-free boolean
mda slot-mda 
redundancy 
active-mda-limit number
intra-chassis 
active-standby 
tunnel-group number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
backup slot-mda
description description
ipsec-responder-only boolean
isa-scale-mode keyword
multi-active 
active-isa-number number
isa slot-mda 
member-pool reference
primary slot-mda
reassembly 
max-wait-time number
stats-collection 
isa-dp-cpu-usage boolean
tunnel-member-pool named-item 
apply-groups reference
apply-groups-exclude reference
description description
isa slot-mda 

isa command descriptions

isa

Synopsis Enter the isa context
Context configure isa
Treeisa

Description

Commands in this context configure the Integrated Services Adapter (ISA).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

nat-group [id] number

Synopsis Enter the nat-group list instance
Contextconfigure isa nat-group number
Treenat-group
Max. instances4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[id] number
Synopsis NAT group ID
Contextconfigure isa nat-group number
Treenat-group
Range1 to 4

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the NAT group
Contextconfigure isa nat-group number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure isa nat-group number description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

log
Synopsis Enter the log context
Context configure isa nat-group number log
Treelog
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mda [mda-id] slot-mda
Synopsis Add a list entry for mda
Context configure isa nat-group number mda slot-mda
Treemda
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[mda-id] slot-mda
Synopsis MDA ID for ISA NAT group
Context configure isa nat-group number mda slot-mda
Treemda

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

redundancy
Synopsis Enter the redundancy context
Context configure isa nat-group number redundancy
Treeredundancy

Description

Commands in this context configure intra-chassis redundancy mode for the NAT group.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

active-mda-limit number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisNumber of active ESA-VM or ISA members in the NAT group
Contextconfigure isa nat-group number redundancy active-mda-limit number
Treeactive-mda-limit

Description

This command configures the number of active ESA-VM or ISA members in a NAT group.

The system automatically selects which ESA-VMs or ISAs are active. In active/standby (A/S) redundancy mode, the correlation between ESA-VM or ISA members is direct, meaning each ESA-VM or ISA equates to one member. In active/active (A/A) redundancy mode, an individual ESA-VM or ISA may be associated with multiple members.

For A/S redundancy, any surplus ESA-VMs or ISAs beyond the configured active threshold automatically transition to standby. These standby units remain idle until an active unit fails, at which point a standby unit takes over, handling traffic from only one failed active unit. This setup allows for the configuration of multiple standby units to provide resilience against several concurrent failures.

In A/A redundancy, the combination of this command and the failed-mda-limit command guides the distribution of resources among ESA-VMs or ISAs, essentially defining how the members are structured.

In both A/S and A/A modes, the system strives to maintain the configured number of active members as outlined by the active MDA limit, drawing from the pool of available spare resources to compensate for any failures. If the actual number of active members drops below this limit because of a lack of available spares, the NAT group status changes to degraded. In this state, traffic intended for the missing ESA-VM or ISA members (up to the active MDA limit) is blackholed. In Layer 2-aware NAT this condition can be circumvented where traffic can bypass NAT altogether and be directly routed within the internal network that may have an alternate path to a backup NAT system.

Range1 to 28
Introduced25.3.R2

Platforms

7705 SAR Gen 2

intra-chassis
Synopsis Enter the intra-chassis context
Contextconfigure isa nat-group number redundancy intra-chassis
Treeintra-chassis

Notes

The following elements are part of a choice: inter-chassis or intra-chassis.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

active-standby
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisActive-standby intra-chassis NAT redundancy model
Contextconfigure isa nat-group number redundancy intra-chassis active-standby
Treeactive-standby

Notes

The following elements are part of a choice: active-active, active-standby, or l2aware-bypass.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

tunnel-group [id] number

Synopsis Enter the tunnel-group list instance
Contextconfigure isa tunnel-group number
Treetunnel-group

Description

Commands in this context create or edit a tunnel group. A tunnel group is a set of one or more MS-ISAs that support the origination and termination of IPsec and IP/GRE tunnels. On a VSR, the isa-scale-mode command must be specified, which defines the maximum number of tunnels on each ISA.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[id] number
Synopsis Tunnel group ID
Context configure isa tunnel-group number
Treetunnel-group
Range1 to 64

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the ISA tunnel group
Contextconfigure isa tunnel-group number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

backup slot-mda
Synopsis IPsec module configured in the slot to the IPsec group
Contextconfigure isa tunnel-group number backup slot-mda
Treebackup

Notes

The following elements are part of a choice: multi-active or (backup and primary).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure isa tunnel-group number description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipsec-responder-only boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAct as an IKE responder except upon MC-IPsec switchover
Contextconfigure isa tunnel-group number ipsec-responder-only boolean
Treeipsec-responder-only
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

isa-scale-mode keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTunnel limit on each ISA for the tunnel group
Contextconfigure isa tunnel-group number isa-scale-mode keyword
Treeisa-scale-mode
Optionstunnel-limit-2k, tunnel-limit-32k, tunnel-limit-64k, tunnel-limit-8, tunnel-limit-32, tunnel-limit-4k

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

multi-active
Synopsis Enable the multi-active context
Contextconfigure isa tunnel-group number multi-active
Treemulti-active

Notes

The following elements are part of a choice: multi-active or (backup and primary).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

active-isa-number number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisNumber of active MS-ISAs in the tunnel group
Contextconfigure isa tunnel-group number multi-active active-isa-number number
Treeactive-isa-number
Range1 to 16
Default1
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

isa [isa-id] slot-mda
Synopsis Add a list entry for isa
Context configure isa tunnel-group number multi-active isa slot-mda
Treeisa

Notes

The following elements are part of a choice: esa, isa, or member-pool.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[isa-id] slot-mda
Synopsis ISA ID associated with the tunnel member pool
Contextconfigure isa tunnel-group number multi-active isa slot-mda
Treeisa

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

primary slot-mda
Synopsis Primary ISA IPsec module assigned for the tunnel group
Contextconfigure isa tunnel-group number primary slot-mda
Treeprimary

Notes

The following elements are part of a choice: multi-active or (backup and primary).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

stats-collection
Synopsis Enter the stats-collection context
Contextconfigure isa tunnel-group number stats-collection
Treestats-collection

Description

Commands in this context configure the ISA statistics collection.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

isa-dp-cpu-usage boolean
Synopsis Collect statistics used to derive ISA DP CPU usage
Contextconfigure isa tunnel-group number stats-collection isa-dp-cpu-usage boolean
Treeisa-dp-cpu-usage

Description

When configured to true, this command collects statistics used to derive ISA CPU DP usage and impacts the ISA performance.

When configured to false, statistics are not collected.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

tunnel-member-pool [name] named-item

Synopsis Enter the tunnel-member-pool list instance
Contextconfigure isa tunnel-member-pool named-item
Treetunnel-member-pool
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[name] named-item
Synopsis ISA tunnel-member pool name
Context configure isa tunnel-member-pool named-item
Treetunnel-member-pool
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

isa [isa-id] slot-mda
Synopsis Add a list entry for isa
Context configure isa tunnel-member-pool named-item isa slot-mda
Treeisa
Max. instances16

Notes

The following elements are part of a choice: esa or isa.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[isa-id] slot-mda
Synopsis ISA ID associated with the tunnel member pool
Contextconfigure isa tunnel-member-pool named-item isa slot-mda
Treeisa

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2