service commands

configure 
service 
apply-groups reference
apply-groups-exclude reference
customer customer-name 
apply-groups reference
apply-groups-exclude reference
contact description
customer-id number
description description
multi-service-site named-item 
apply-groups reference
apply-groups-exclude reference
assignment 
card number
port port-named
description description
egress 
agg-rate 
limit-unused-bandwidth boolean
queue-frame-based-accounting boolean
rate number
policer-control-policy reference
scheduler-policy 
overrides 
scheduler named-item 
apply-groups reference
apply-groups-exclude reference
parent 
cir-weight number
weight number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
ingress 
policer-control-policy reference
scheduler-policy 
overrides 
scheduler named-item 
apply-groups reference
apply-groups-exclude reference
parent 
cir-weight number
weight number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
phone description
epipe service-name 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bgp number 
adv-service-mtu number
apply-groups reference
apply-groups-exclude reference
pw-template-binding reference 
apply-groups reference
apply-groups-exclude reference
endpoint reference
import-rt route-target
route-distinguisher (keyword | vpn-route-distinguisher)
route-target 
export route-target
import route-target
vsi-export reference
vsi-import reference
bgp-evpn 
apply-groups reference
apply-groups-exclude reference
evi number
local-attachment-circuit named-item 
apply-groups reference
apply-groups-exclude reference
bgp number
endpoint reference
eth-tag number
mpls number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
auto-bind-tunnel 
allow-flex-algo-fallback boolean
ecmp number
enforce-strict-tunnel-tagging boolean
enforce-untagged-route keyword
resolution keyword
resolution-filter 
bgp boolean
ldp boolean
rsvp boolean
sr-isis boolean
sr-ospf boolean
sr-ospf3 boolean
sr-policy boolean
sr-te boolean
weighted-ecmp boolean
control-word boolean
default-route-tag one-byte-value
domain-id domain-id
dynamic-egress-label-limit boolean
evi-three-byte-auto-rt boolean
force-vc-forwarding keyword
hash-label boolean
mh-mode keyword
oper-group reference
route-next-hop 
ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
system-ipv4 
system-ipv6 
send-tunnel-encap 
mpls boolean
remote-attachment-circuit named-item 
apply-groups reference
apply-groups-exclude reference
bgp number
endpoint reference
eth-tag number
bgp-mh-site named-item 
activation-timer number
admin-state keyword
apply-groups reference
apply-groups-exclude reference
boot-timer number
id number
min-down-timer number
preference number
sap sap
bgp-vpws 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
local-ve 
id number
name named-item
remote-ve named-item 
apply-groups reference
apply-groups-exclude reference
id number
customer reference
description description
endpoint named-item 
apply-groups reference
apply-groups-exclude reference
description description
hold-time-active number
revert-time (number | keyword)
standby-signaling keyword
ignore-l2vpn-mtu-mismatch boolean
load-balancing 
oper-group reference
sap sap 
accounting-policy reference
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bandwidth number
collect-stats boolean
description long-description
dist-cpu-protection reference
egress 
agg-rate 
queue-frame-based-accounting boolean
rate number
filter 
ip reference
ipv6 reference
qos 
policer-control-policy 
overrides 
apply-groups reference
apply-groups-exclude reference
root 
max-rate (number | keyword)
priority-mbs-thresholds 
min-thresh-separation (number | keyword)
priority number 
apply-groups reference
apply-groups-exclude reference
mbs-contribution (number | keyword)
policy-name reference
qinq-mark-top-only boolean
sap-egress 
overrides 
queue reference 
adaptation-rule 
cir keyword
pir keyword
apply-groups reference
apply-groups-exclude reference
avg-frame-overhead decimal-number
burst-limit (number | keyword)
cbs (number | keyword)
drop-tail 
low 
percent-reduction-from-mbs (number | keyword)
mbs (number | keyword)
parent 
cir-weight number
weight number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
port-redirect-group 
group-name reference
instance number
scheduler-policy 
overrides 
scheduler named-item 
apply-groups reference
apply-groups-exclude reference
parent 
cir-weight number
weight number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
endpoint reference
ignore-oper-down boolean
ingress 
filter 
ip reference
ipv6 reference
qos 
match-qinq-dot1p keyword
policer-control-policy 
overrides 
apply-groups reference
apply-groups-exclude reference
root 
max-rate (number | keyword)
priority-mbs-thresholds 
min-thresh-separation (number | keyword)
priority number 
apply-groups reference
apply-groups-exclude reference
mbs-contribution (number | keyword)
policy-name reference
sap-ingress 
fp-redirect-group 
group-name reference
instance number
overrides 
policer reference 
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
mbs (number | keyword)
packet-byte-offset number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
stat-mode keyword
queue reference 
adaptation-rule 
cir keyword
pir keyword
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
drop-tail 
low 
percent-reduction-from-mbs (number | keyword)
mbs (number | keyword)
parent 
cir-weight number
weight number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
scheduler-policy 
overrides 
scheduler named-item 
apply-groups reference
apply-groups-exclude reference
parent 
cir-weight number
weight number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
lag 
mc-ring 
apply-groups reference
apply-groups-exclude reference
ring-node named-item
monitor-oper-group reference
multi-service-site reference
oper-group reference
service-id number
service-mtu number
spoke-sdp sdp-bind-id 
accounting-policy reference
admin-state keyword
adv-service-mtu number
apply-groups reference
apply-groups-exclude reference
bandwidth (number | keyword)
collect-stats boolean
control-word boolean
description description
egress 
filter 
ip reference
ipv6 reference
qos 
network 
policy-name reference
port-redirect-group 
group-name reference
instance number
vc-label number
endpoint 
icb boolean
name reference
precedence (number | keyword)
force-vc-forwarding keyword
hash-label 
signal-capability 
ingress 
filter 
ip reference
ipv6 reference
qos 
network 
fp-redirect-group 
group-name reference
instance number
policy-name reference
vc-label number
monitor-oper-group reference
oper-group reference
pw-status 
block-on-peer-fault boolean
signaling boolean
standby-signaling-slave boolean
vc-type keyword
vlan-vc-tag number
test boolean
vc-switching boolean
vpn-id number
ies service-name 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
customer reference
description description
interface interface-name 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description very-long-description
dynamic-tunnel-redundant-nexthop ipv4-unicast-address
hold-time 
ipv4 
down 
init-only boolean
seconds number
up 
seconds number
ipv6 
down 
init-only boolean
seconds number
up 
seconds number
if-attribute 
admin-group reference
srlg-group reference 
ingress 
ip-mtu number
ip-tunnel-interface boolean
ipsec 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
ip-exception reference
ipsec-tunnel named-item 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bfd 
bfd-designate boolean
bfd-liveness 
dest-ip ipv4-unicast-address
interface interface-name
service-name service-name
clear-df-bit boolean
copy-traffic-class-upon-decapsulation boolean
description description
encapsulated-ip-mtu number
icmp-generation 
frag-required 
admin-state keyword
interval number
message-count number
icmp6-generation 
packet-too-big 
admin-state keyword
interval number
message-count number
ip-mtu number
key-exchange 
dynamic 
auto-establish boolean
cert 
cert-profile reference
status-verify 
default-result keyword
primary keyword
secondary keyword
trust-anchor-profile reference
id 
fqdn fully-qualified-domain-name
ipv4 ipv4-unicast-address
ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
ike-policy reference
ipsec-transform reference
ppk 
id reference
list reference
pre-shared-key encrypted-leaf
manual 
keys number direction keyword 
apply-groups reference
apply-groups-exclude reference
authentication-key hex-string
encryption-key hex-string
ipsec-transform reference
spi number
local-gateway-address-override (ipv4-address-no-zone | ipv6-address-no-zone)
max-history-key-records 
esp number
ike number
pmtu-discovery-aging number
private-sap number
private-service service-name
private-tcp-mss-adjust number
propagate-pmtu-v4 boolean
propagate-pmtu-v6 boolean
public-tcp-mss-adjust (number | keyword)
remote-gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
replay-window number
security-policy 
id number
strict-match boolean
ipv6-exception reference
public-sap number
tunnel-group reference
ipv4 
addresses 
address ipv4-unicast-address 
apply-groups reference
apply-groups-exclude reference
prefix-length number
allow-directed-broadcasts boolean
bfd 
admin-state keyword
echo-receive number
multiplier number
receive number
transmit-interval number
dhcp 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
gi-address ipv4-unicast-address
lease-populate 
max-leases number
option-82 
action keyword
circuit-id 
ascii-tuple 
ifindex 
none 
sap-id 
vlan-ascii-tuple 
remote-id 
ascii-string string-not-all-spaces
mac 
none 
vendor-specific-option 
client-mac-address boolean
pool-name boolean
sap-id boolean
service-id boolean
string string-not-all-spaces
system-id boolean
proxy-server 
admin-state keyword
emulated-server ipv4-unicast-address
lease-time 
radius-override boolean
value number
relay-plain-bootp boolean
relay-proxy 
release-update-src-ip boolean
siaddr-override ipv4-unicast-address
server ipv4-unicast-address
src-ip-addr keyword
trusted boolean
use-arp boolean
icmp 
mask-reply boolean
param-problem 
admin-state keyword
number number
seconds number
redirects 
admin-state keyword
number number
seconds number
ttl-expired 
admin-state keyword
number number
seconds number
unreachables 
admin-state keyword
number number
seconds number
ip-helper-address ipv4-unicast-address
local-dhcp-server reference
neighbor-discovery 
host-route 
populate keyword 
apply-groups reference
apply-groups-exclude reference
route-tag number
learn-unsolicited boolean
limit 
log-only boolean
max-entries number
threshold number
local-proxy-arp boolean
populate boolean
proactive-refresh boolean
proxy-arp-policy reference
remote-proxy-arp boolean
retry-timer number
static-neighbor ipv4-address 
apply-groups reference
apply-groups-exclude reference
mac-address mac-address
static-neighbor-unnumbered 
mac-address mac-address
timeout number
primary 
address ipv4-unicast-address
apply-groups reference
apply-groups-exclude reference
broadcast keyword
prefix-length number
secondary ipv4-unicast-address 
apply-groups reference
apply-groups-exclude reference
broadcast keyword
igp-inhibit boolean
prefix-length number
tcp-mss number
unnumbered 
ip-address ipv4-unicast-address
ip-int-name interface-name
system 
urpf-check 
ignore-default boolean
mode keyword
vrrp number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authentication-key encrypted-leaf
backup ipv4-unicast-address
bfd-liveness 
apply-groups reference
apply-groups-exclude reference
dest-ip ipv4-address
interface-name interface-name
service-name service-name
init-delay number
mac mac-unicast-address
master-int-inherit boolean
message-interval number
monitor-oper-group reference
ntp-reply boolean
oper-group reference
owner boolean
passive boolean
ping-reply boolean
policy reference
preempt boolean
priority number
ssh-reply boolean
standby-forwarding boolean
telnet-reply boolean
traceroute-reply boolean
ipv6 
address ipv6-address 
apply-groups reference
apply-groups-exclude reference
duplicate-address-detection boolean
eui-64 boolean
prefix-length number
primary-preference number
bfd 
admin-state keyword
echo-receive number
multiplier number
receive number
transmit-interval number
dhcp6 
apply-groups reference
apply-groups-exclude reference
relay 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
lease-populate 
max-nbr-of-leases number
route-populate 
na boolean
pd 
exclude boolean
ta boolean
option 
apply-groups reference
apply-groups-exclude reference
interface-id 
ascii-tuple 
if-index 
sap-id 
string string-not-all-spaces
remote-id boolean
server ipv6-address-with-zone
source-address ipv6-unicast-or-linklocal-address
duplicate-address-detection boolean
forward-ipv4-packets boolean
icmp6 
packet-too-big 
admin-state keyword
number number
seconds number
param-problem 
admin-state keyword
number number
seconds number
redirects 
admin-state keyword
number number
seconds number
time-exceeded 
admin-state keyword
number number
seconds number
unreachables 
admin-state keyword
number number
seconds number
link-local-address 
address ipv6-address
duplicate-address-detection boolean
local-dhcp-server reference
neighbor-discovery 
host-route 
populate keyword 
apply-groups reference
apply-groups-exclude reference
route-tag number
learn-unsolicited keyword
limit 
log-only boolean
max-entries number
threshold number
local-proxy-nd boolean
proactive-refresh keyword
proxy-nd-policy reference
reachable-time number
secure-nd 
admin-state keyword
allow-unsecured-msgs boolean
public-key-min-bits number
security-parameter number
stale-time number
static-neighbor ipv6-address 
apply-groups reference
apply-groups-exclude reference
mac-address mac-address
tcp-mss number
urpf-check 
ignore-default boolean
mode keyword
vrrp number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
backup ipv6-address
bfd-liveness 
apply-groups reference
apply-groups-exclude reference
dest-ip (ipv4-address-no-zone | ipv6-address-no-zone)
interface-name interface-name
service-name service-name
init-delay number
mac mac-unicast-address
master-int-inherit boolean
message-interval number
monitor-oper-group reference
ntp-reply boolean
oper-group reference
owner boolean
passive boolean
ping-reply boolean
policy reference
preempt boolean
priority number
standby-forwarding boolean
telnet-reply boolean
traceroute-reply boolean
load-balancing 
ip-load-balancing keyword
loopback boolean
mac mac-unicast-address
mac-accounting boolean
monitor-oper-group reference
multi-chassis-shunting-profile reference
multicast-network-domain reference
sap sap 
accounting-policy reference
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bandwidth number
collect-stats boolean
description long-description
dist-cpu-protection reference
egress 
agg-rate 
queue-frame-based-accounting boolean
rate number
filter 
ip reference
ipv6 reference
qos 
policer-control-policy 
overrides 
apply-groups reference
apply-groups-exclude reference
root 
max-rate (number | keyword)
priority-mbs-thresholds 
min-thresh-separation (number | keyword)
priority number 
apply-groups reference
apply-groups-exclude reference
mbs-contribution (number | keyword)
policy-name reference
qinq-mark-top-only boolean
sap-egress 
overrides 
queue reference 
adaptation-rule 
cir keyword
pir keyword
apply-groups reference
apply-groups-exclude reference
avg-frame-overhead decimal-number
burst-limit (number | keyword)
cbs (number | keyword)
drop-tail 
low 
percent-reduction-from-mbs (number | keyword)
mbs (number | keyword)
parent 
cir-weight number
weight number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
port-redirect-group 
group-name reference
instance number
scheduler-policy 
overrides 
scheduler named-item 
apply-groups reference
apply-groups-exclude reference
parent 
cir-weight number
weight number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
ingress 
filter 
ip reference
ipv6 reference
qos 
match-qinq-dot1p keyword
policer-control-policy 
overrides 
apply-groups reference
apply-groups-exclude reference
root 
max-rate (number | keyword)
priority-mbs-thresholds 
min-thresh-separation (number | keyword)
priority number 
apply-groups reference
apply-groups-exclude reference
mbs-contribution (number | keyword)
policy-name reference
sap-ingress 
fp-redirect-group 
group-name reference
instance number
overrides 
policer reference 
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
mbs (number | keyword)
packet-byte-offset number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
stat-mode keyword
queue reference 
adaptation-rule 
cir keyword
pir keyword
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
drop-tail 
low 
percent-reduction-from-mbs (number | keyword)
mbs (number | keyword)
parent 
cir-weight number
weight number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
scheduler-policy 
overrides 
scheduler named-item 
apply-groups reference
apply-groups-exclude reference
parent 
cir-weight number
weight number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
ip-tunnel interface-name 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
backup-remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
clear-df-bit boolean
delivery-service service-name
description description
dest-ip (ipv4-address-no-zone | ipv6-address-no-zone) 
dscp keyword
encapsulated-ip-mtu number
gre-header 
admin-state keyword
key 
admin-state keyword
receive number
send number
icmp-generation 
frag-required 
admin-state keyword
interval number
message-count number
icmp6-generation 
packet-too-big 
admin-state keyword
number number
seconds number
ip-mtu number
ipsec-transport-mode-profile reference
local-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
pmtu-discovery-aging number
private-tcp-mss-adjust number
propagate-pmtu-v4 boolean
propagate-pmtu-v6 boolean
public-tcp-mss-adjust (number | keyword)
reassembly (number | keyword)
remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
ipsec-gateway named-item 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
cert 
cert-profile reference
status-verify 
default-result keyword
primary keyword
secondary keyword
trust-anchor-profile reference
client-db 
fallback boolean
name reference
default-secure-service 
interface interface-name
service-name service-name
default-tunnel-template reference
dhcp-address-assignment 
dhcpv4 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
gi-address ipv4-unicast-address
send-release boolean
server 
address ipv4-unicast-address
router-instance router-instance-base-vprn-loose
dhcpv6 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
link-address ipv6-unicast-address
send-release boolean
server 
address ipv6-unicast-address
router-instance router-instance-base-vprn-loose
ike-policy reference
local 
address-assignment 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
ipv4 
dhcp-server named-item
pool named-item
router-instance router-instance-base-vprn-loose
secondary-pool named-item
ipv6 
dhcp-server named-item
pool named-item
router-instance router-instance-base-vprn-loose
gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
id 
auto 
fqdn fully-qualified-domain-name
ipv4 ipv4-unicast-address
ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
max-history-key-records 
esp number
ike number
pre-shared-key encrypted-leaf
radius 
accounting-policy reference
authentication-policy reference
ts-list reference
lag 
multi-service-site reference
spoke-sdp sdp-bind-id 
accounting-policy reference
admin-state keyword
apply-groups reference
apply-groups-exclude reference
collect-stats boolean
description description
egress 
filter 
ip reference
ipv6 reference
qos 
network 
policy-name reference
port-redirect-group 
group-name reference
instance number
vc-label number
hash-label 
signal-capability 
ingress 
filter 
ip reference
ipv6 reference
qos 
network 
fp-redirect-group 
group-name reference
instance number
policy-name reference
vc-label number
vc-type keyword
static-tunnel-redundant-nexthop ipv4-unicast-address
tos-marking-state keyword
tunnel boolean
vpls named-item-64 
apply-groups reference
apply-groups-exclude reference
egress 
reclassify-using-qos reference
routed-override-filter 
ip reference
ipv6 reference
evpn 
arp 
advertise keyword 
apply-groups reference
apply-groups-exclude reference
route-tag number
flood-garp-and-unknown-req boolean
learn-dynamic boolean
nd 
advertise keyword 
apply-groups reference
apply-groups-exclude reference
route-tag number
learn-dynamic boolean
ingress 
routed-override-filter 
ip reference
ipv6 reference
service-id number
vpn-id number
mac-list named-item 
apply-groups reference
apply-groups-exclude reference
description description
mac mac-address 
apply-groups reference
apply-groups-exclude reference
mask mac-address
md-auto-id 
customer-id-range 
apply-groups reference
apply-groups-exclude reference
end number
start number
pw-template-id-range 
apply-groups reference
apply-groups-exclude reference
end number
start number
service-id-range 
apply-groups reference
apply-groups-exclude reference
end number
start number
nat 
apply-groups reference
apply-groups-exclude reference
nat-policy external-named-item 
apply-groups reference
apply-groups-exclude reference
block-limit number
description description
filtering keyword
pool 
name named-item
router-instance string
port-limits 
forwarding number
watermarks 
high number
low number
session-limits 
max number
watermarks 
high number
low number
tcp 
mss-adjust number
timeouts 
icmp-query number
tcp 
established number
syn number
time-wait number
transitory number
udp 
dns number
initial number
normal number
udp 
inbound-refresh boolean
oper-group named-item 
apply-groups reference
apply-groups-exclude reference
bfd-liveness 
apply-groups reference
apply-groups-exclude reference
dest-ip ipv4-unicast-address
interface-name interface-name
router-instance string
hold-time 
down number
up number
proxy-arp-nd 
mac-list 
list named-item 
apply-groups reference
apply-groups-exclude reference
mac mac-unicast-address-no-zero 
pw-template pw-template-name 
accounting-policy number
allow-fragmentation boolean
apply-groups reference
apply-groups-exclude reference
auto-gre-sdp boolean
block-on-peer-fault boolean
collect-stats boolean
control-word boolean
egress 
filter 
ip named-item-64
ipv6 named-item-64
mac named-item-64
mfib-allowed-mda-destinations 
mda slot-mda 
qos 
network 
policy-name named-item-64
port-redirect-group 
group-name named-item
instance number
encryption-keygroup 
inbound number
outbound number
fdb 
auto-learn-mac-protect boolean
auto-learn-mac-protect-exclude-list named-item
discard-unknown-source boolean
limit-mac-move keyword
mac-learning 
aging boolean
learning boolean
mac-pinning boolean
maximum-mac-addresses number
protected-src-mac-violation-action keyword
force-vc-forwarding keyword
hash-label 
signal-capability 
igmp-snooping 
fast-leave boolean
import-policy named-item
maximum-number-groups number
query-interval number
query-last-member-interval number
query-response-interval number
robust-count number
send-queries boolean
version keyword
ingress 
filter 
ip named-item-64
ipv6 named-item-64
mac named-item-64
qos 
network 
fp-redirect-group 
group-name named-item
instance number
policy-name named-item-64
l2pt 
termination 
protocols 
cdp boolean
dtp boolean
pagp boolean
stp boolean
udld boolean
vtp boolean
path-mtu number
provisioned-sdp keyword
pw-template-id number
sdp-exclude reference 
sdp-include reference 
split-horizon-group 
description description
fdb 
saps 
auto-learn-mac-protect boolean
discard-unprotected-dest-mac boolean
protected-src-mac-violation-action keyword
name named-item
stp 
admin-state keyword
auto-edge boolean
edge-port boolean
link-type keyword
path-cost number
priority number
root-guard boolean
vc-type keyword
vlan-vc-tag number
sdp number 
accounting-policy reference
admin-state keyword
adv-mtu-override boolean
allow-fragmentation boolean
apply-groups reference
apply-groups-exclude reference
bgp-tunnel boolean
booking-factor number
collect-stats boolean
delivery-type keyword
description description
far-end 
ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
keep-alive 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
hello-time number
hold-down-time number
maximum-drop-count number
message-length number
timeout number
ldp boolean
local-end (ipv4-address-no-zone | ipv6-address-no-zone)
lsp named-item-64 
metric number
mixed-lsp-mode 
revert-time (number | keyword)
network-domain reference
path-mtu number
sdp-group reference 
signaling keyword
sr-isis boolean
sr-ospf boolean
tunnel-far-end (ipv4-address-no-zone | ipv6-address-no-zone)
vlan-vc-etype etype-value
weighted-ecmp boolean
sdp-group 
apply-groups reference
apply-groups-exclude reference
group-name named-item 
apply-groups reference
apply-groups-exclude reference
value number
system 
apply-groups reference
apply-groups-exclude reference
bgp 
evpn 
ad-per-es-route 
extended-evi-range boolean
route-distinguisher-ip-address ipv4-address
route-target-type keyword
ad-per-evi-routes 
attribute-propagation boolean
bgp-path-selection boolean
d-path-ignore boolean
etree-leaf-label boolean
etree-leaf-label-value (number | keyword)
ip-prefix-routes 
interface-ful 
attribute-uniform-propagation boolean
bgp-path-selection boolean
d-path-length-ignore boolean
multicast-leave-sync-propagation number
route-distinguisher vpn-route-distinguisher
bgp-auto-rd-range 
apply-groups reference
apply-groups-exclude reference
community-value 
end number
start number
ip-address ipv4-address
fdb 
apply-groups reference
apply-groups-exclude reference
table-size number
vpn-gre-source-ip ipv4-unicast-address
vpls service-name 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bgp number 
adv-service-mtu number
apply-groups reference
apply-groups-exclude reference
pw-template-binding reference 
apply-groups reference
apply-groups-exclude reference
import-rt route-target
monitor-oper-group reference
oper-group reference
split-horizon-group named-item
route-distinguisher (keyword | vpn-route-distinguisher)
route-target 
export route-target
import route-target
vsi-export reference
vsi-import reference
bgp-ad 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
vpls-id vpls-id
vsi-id-prefix ipv4-address
bgp-evpn 
apply-groups reference
apply-groups-exclude reference
evi number
ignore-mtu-mismatch boolean
incl-mcast-orig-ip ipv4-unicast-address
mac-duplication 
blackhole boolean
detect 
num-moves number
trusted-mac-move-factor number
window number
retry (number | keyword)
trusted-mac-time number
mpls number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
auto-bind-tunnel 
allow-flex-algo-fallback boolean
ecmp number
enforce-strict-tunnel-tagging boolean
enforce-untagged-route keyword
resolution keyword
resolution-filter 
bgp boolean
ldp boolean
rsvp boolean
sr-isis boolean
sr-ospf boolean
sr-ospf3 boolean
sr-policy boolean
sr-te boolean
weighted-ecmp boolean
control-word boolean
default-route-tag one-byte-value
dynamic-egress-label-limit boolean
evi-three-byte-auto-rt boolean
fdb 
protected-src-mac-violation-action keyword
force-vc-forwarding keyword
hash-label boolean
mh-mode keyword
oper-group reference
route-next-hop 
ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
system-ipv4 
system-ipv6 
send-tunnel-encap 
mpls boolean
split-horizon-group reference
routes 
incl-mcast 
advertise-ingress-replication boolean
advertise-l2-attributes boolean
ip-prefix 
advertise boolean
domain-id domain-id
include-direct-interface-host boolean
link-bandwidth 
advertise 
max-dynamic-weight number
weight (number | keyword)
weighted-ecmp boolean
mac-ip 
advertise boolean
arp-nd-extended-community boolean
arp-nd-only-with-fdb-advertisement boolean
sel-mcast 
advertise boolean
vlan-aware-bundle-eth-tag number
vlan-aware-bundle named-item
bgp-mh-site named-item 
activation-timer number
admin-state keyword
apply-groups reference
apply-groups-exclude reference
boot-timer number
failed-threshold (number | keyword)
id number
mesh-sdp-binds 
min-down-timer number
monitor-oper-group reference
sap sap
shg-name named-item
spoke-sdp sdp-bind-id
bgp-vpls 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
maximum-ve-id number
ve 
id number
name named-item
customer reference
description description
endpoint named-item 
apply-groups reference
apply-groups-exclude reference
block-on-mesh-failure boolean
description description
fdb 
auto-learn-mac-protect boolean
mac-pinning boolean
maximum-mac-addresses number
protected-src-mac-violation-action keyword
ignore-standby-signaling boolean
mc-endpoint number 
apply-groups reference
apply-groups-exclude reference
mc-ep-peer 
name named-item
peer-address reference
revert-time (number | keyword)
suppress-standby-signaling boolean
etree boolean
fdb 
discard-unknown boolean
mac-learning 
aging boolean
learning boolean
local-age-time number
remote-age-time number
mac-move 
admin-state keyword
hold-down-time number
move-frequency number
primary-cumulative-factor number
retry-count (number | keyword)
sap reference 
apply-groups reference
apply-groups-exclude reference
level keyword
secondary-cumulative-factor number
spoke-sdp reference 
apply-groups reference
apply-groups-exclude reference
level keyword
mac-subnet-length number
selective-learning boolean
static-mac 
mac mac-unicast-address-no-zero 
apply-groups reference
apply-groups-exclude reference
blackhole 
endpoint reference
mesh-sdp reference
monitor keyword
sap reference
spoke-sdp reference
table 
high-wmark number
low-wmark number
size number
igmp-snooping 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
query-interval number
query-source-address (keyword | ipv4-address)
report-source-address ipv4-address
robust-count number
ignore-l2vpn-mtu-mismatch boolean
interface interface-name 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description very-long-description
hold-time 
ipv4 
down 
init-only boolean
seconds number
up 
seconds number
ipv4 
neighbor-discovery 
static-neighbor ipv4-address 
apply-groups reference
apply-groups-exclude reference
mac-address mac-address
timeout number
primary 
address ipv4-address
apply-groups reference
apply-groups-exclude reference
prefix-length number
mac mac-unicast-address
isid-policy 
entry number 
advertise-local boolean
apply-groups reference
apply-groups-exclude reference
range 
end number
start number
use-def-mcast boolean
m-vpls boolean
mac-flush 
tldp 
propagate boolean
send-on-failure boolean
mac-protect 
mac mac-address 
mcast-ipv6-snooping-scope keyword
mcr-default-gtw 
apply-groups reference
apply-groups-exclude reference
ip ipv4-unicast-address
mac mac-address
mesh-sdp sdp-bind-id 
accounting-policy reference
admin-state keyword
adv-service-mtu number
apply-groups reference
apply-groups-exclude reference
collect-stats boolean
control-word boolean
description description
dhcp 
apply-groups reference
apply-groups-exclude reference
description description
snoop boolean
egress 
filter 
ip reference
ipv6 reference
mfib-allowed-mda-destinations 
mda slot-mda 
qos 
network 
policy-name reference
port-redirect-group 
group-name reference
instance number
vc-label number
etree-leaf boolean
etree-root-leaf-tag boolean
fdb 
auto-learn-mac-protect boolean
auto-learn-mac-protect-exclude-list reference
mac-pinning boolean
protected-src-mac-violation-action keyword
force-vc-forwarding keyword
hash-label 
signal-capability 
igmp-snooping 
apply-groups reference
apply-groups-exclude reference
fast-leave boolean
import-policy reference
maximum-number-group-sources number
maximum-number-groups number
maximum-number-sources number
mrouter-port boolean
query-interval number
query-last-member-interval number
query-response-interval number
robust-count number
router-alert-check boolean
send-queries boolean
static 
group ipv4-multicast-address 
apply-groups reference
apply-groups-exclude reference
source ipv4-unicast-address 
starg 
version keyword
ingress 
filter 
ip reference
ipv6 reference
qos 
network 
fp-redirect-group 
group-name reference
instance number
policy-name reference
vc-label number
mld-snooping 
apply-groups reference
apply-groups-exclude reference
fast-leave boolean
import-policy reference
maximum-number-groups number
mrouter-port boolean
query-interval number
query-last-member-interval number
query-response-interval number
robust-count number
router-alert-check boolean
send-queries boolean
static 
group ipv6-multicast-address 
apply-groups reference
apply-groups-exclude reference
source ipv6-unicast-address 
starg 
version keyword
vc-type keyword
vlan-vc-tag number
mfib 
table 
high-wmark number
low-wmark number
size number
mld-snooping 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
query-interval number
query-source-address (keyword | ipv6-address)
report-source-address ipv6-address
robust-count number
proxy-arp 
admin-state keyword
age-time (number | keyword)
apply-groups reference
apply-groups-exclude reference
duplicate-detect 
anti-spoof-mac mac-unicast-address-no-zero
hold-down-time (number | keyword)
num-moves number
static-blackhole boolean
window number
dynamic-arp 
ip-address ipv4-unicast-address 
apply-groups reference
apply-groups-exclude reference
mac-list reference
resolve-retry-time number
sap reference 
dynamic-populate boolean
evpn 
flood 
gratuitous-arp boolean
unknown-arp-req boolean
route-tag number
flood 
received-gratuitous-arp boolean
received-unknown-arp-req boolean
process-arp-probes boolean
restrict-non-configured-ip-address 
sponge-mac mac-unicast-address-no-zero
send-refresh (number | keyword)
static-arp 
ip-address ipv4-unicast-address 
apply-groups reference
apply-groups-exclude reference
mac mac-unicast-address-no-zero
table-size number
proxy-nd 
admin-state keyword
age-time (number | keyword)
apply-groups reference
apply-groups-exclude reference
duplicate-detect 
anti-spoof-mac mac-unicast-address-no-zero
hold-down-time (number | keyword)
num-moves number
static-blackhole boolean
window number
dynamic-neighbor 
ip-address ipv6-address 
apply-groups reference
apply-groups-exclude reference
mac-list reference
resolve-retry-time number
sap reference 
dynamic-populate boolean
evpn 
advertise-neighbor-type keyword
flood 
unknown-neighbor-advertise-host boolean
unknown-neighbor-advertise-router boolean
unknown-neighbor-solicitation boolean
route-tag number
flood 
received-unknown-neighbor-advertise-host boolean
received-unknown-neighbor-advertise-router boolean
received-unknown-neighbor-solicitation boolean
process-dad-neighbor-solicitations boolean
restrict-non-configured-ip-address 
sponge-mac mac-unicast-address-no-zero
send-refresh (number | keyword)
static-neighbor 
ip-address ipv6-address 
apply-groups reference
apply-groups-exclude reference
mac mac-unicast-address-no-zero
type keyword
table-size number
routed-vpls 
evpn-mpls-ecmp boolean
multicast 
apply-groups reference
apply-groups-exclude reference
ipv4 
ipv6 
mld-snooping 
mrouter-port boolean
sap sap 
accounting-policy reference
admin-state keyword
apply-groups reference
apply-groups-exclude reference
arp-reply-agent keyword
bandwidth number
bgp-vpls-mh-veid number
bpdu-translation keyword
collect-stats boolean
description long-description
dhcp 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
lease-populate 
max-leases number
option-82 
action keyword
circuit-id 
ascii-tuple 
hex-string hex-string
none 
vlan-ascii-tuple 
remote-id 
ascii-string string-not-all-spaces
hex-string hex-string
mac 
none 
vendor-specific-option 
client-mac-address boolean
sap-id boolean
service-id boolean
string string-not-all-spaces
system-id boolean
proxy-server 
admin-state keyword
emulated-server ipv4-unicast-address
lease-time 
radius-override boolean
value number
snoop boolean
dhcp6 
apply-groups reference
apply-groups-exclude reference
description description
ldra 
interface-type keyword
options 
interface-id 
ascii-tuple 
vlan-ascii-tuple 
remote-id 
mac 
string string
dist-cpu-protection reference
egress 
agg-rate 
queue-frame-based-accounting boolean
rate number
dest-mac-rewrite mac-unicast-address-no-zero
filter 
ip reference
ipv6 reference
qos 
policer-control-policy 
overrides 
apply-groups reference
apply-groups-exclude reference
root 
max-rate (number | keyword)
priority-mbs-thresholds 
min-thresh-separation (number | keyword)
priority number 
apply-groups reference
apply-groups-exclude reference
mbs-contribution (number | keyword)
policy-name reference
qinq-mark-top-only boolean
sap-egress 
overrides 
queue reference 
adaptation-rule 
cir keyword
pir keyword
apply-groups reference
apply-groups-exclude reference
avg-frame-overhead decimal-number
burst-limit (number | keyword)
cbs (number | keyword)
drop-tail 
low 
percent-reduction-from-mbs (number | keyword)
mbs (number | keyword)
parent 
cir-weight number
weight number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
port-redirect-group 
group-name reference
instance number
scheduler-policy 
overrides 
scheduler named-item 
apply-groups reference
apply-groups-exclude reference
parent 
cir-weight number
weight number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
etree-leaf boolean
etree-root-leaf-tag 
leaf number
fdb 
auto-learn-mac-protect boolean
auto-learn-mac-protect-exclude-list reference
discard-unknown-source boolean
discard-unprotected-dest-mac boolean
limit-mac-move keyword
mac-learning 
aging boolean
learning boolean
mac-pinning boolean
maximum-mac-addresses number
protected-src-mac-violation-action keyword
i-vpls-mac-flush 
bgp-evpn 
igmp-snooping 
apply-groups reference
apply-groups-exclude reference
fast-leave boolean
import-policy reference
maximum-number-group-sources number
maximum-number-groups number
maximum-number-sources number
mrouter-port boolean
query-interval number
query-last-member-interval number
query-response-interval number
robust-count number
router-alert-check boolean
send-queries boolean
static 
group ipv4-multicast-address 
apply-groups reference
apply-groups-exclude reference
source ipv4-unicast-address 
starg 
version keyword
ingress 
filter 
ip reference
ipv6 reference
qos 
match-qinq-dot1p keyword
policer-control-policy 
overrides 
apply-groups reference
apply-groups-exclude reference
root 
max-rate (number | keyword)
priority-mbs-thresholds 
min-thresh-separation (number | keyword)
priority number 
apply-groups reference
apply-groups-exclude reference
mbs-contribution (number | keyword)
policy-name reference
sap-ingress 
fp-redirect-group 
group-name reference
instance number
overrides 
policer reference 
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
mbs (number | keyword)
packet-byte-offset number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
stat-mode keyword
queue reference 
adaptation-rule 
cir keyword
pir keyword
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
drop-tail 
low 
percent-reduction-from-mbs (number | keyword)
mbs (number | keyword)
parent 
cir-weight number
weight number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
scheduler-policy 
overrides 
scheduler named-item 
apply-groups reference
apply-groups-exclude reference
parent 
cir-weight number
weight number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
l2pt 
force-boundary 
protocols 
cdp boolean
dtp boolean
pagp boolean
stp boolean
udld boolean
vtp boolean
termination 
protocols 
cdp boolean
dtp boolean
pagp boolean
stp boolean
udld boolean
vtp boolean
lag 
managed-vlan-list 
range string 
mc-ring 
apply-groups reference
apply-groups-exclude reference
ring-node named-item
mld-snooping 
apply-groups reference
apply-groups-exclude reference
fast-leave boolean
import-policy reference
maximum-number-groups number
mrouter-port boolean
query-interval number
query-last-member-interval number
query-response-interval number
robust-count number
router-alert-check boolean
send-queries boolean
static 
group ipv6-multicast-address 
apply-groups reference
apply-groups-exclude reference
source ipv6-unicast-address 
starg 
version keyword
monitor-oper-group reference
multi-service-site reference
oper-group reference
process-cpm-traffic-on-sap-down boolean
split-horizon-group reference
stp 
admin-state keyword
auto-edge boolean
edge-port boolean
link-type keyword
mst-instance number 
apply-groups reference
apply-groups-exclude reference
mst-path-cost number
mst-port-priority number
path-cost number
port-num number
priority number
root-guard boolean
service-id number
service-mtu number
split-horizon-group named-item 
apply-groups reference
apply-groups-exclude reference
description description
fdb 
saps 
auto-learn-mac-protect boolean
auto-learn-mac-protect-exclude-list reference
discard-unprotected-dest-mac boolean
protected-src-mac-violation-action keyword
residential boolean
spoke-sdp sdp-bind-id 
accounting-policy reference
admin-state keyword
adv-service-mtu number
apply-groups reference
apply-groups-exclude reference
block-on-mesh-failure boolean
bpdu-translation keyword
collect-stats boolean
control-word boolean
description description
dhcp 
apply-groups reference
apply-groups-exclude reference
description description
snoop boolean
egress 
filter 
ip reference
ipv6 reference
mfib-allowed-mda-destinations 
mda slot-mda 
qos 
network 
policy-name reference
port-redirect-group 
group-name reference
instance number
vc-label number
endpoint 
name reference
precedence (number | keyword)
etree-leaf boolean
etree-root-leaf-tag boolean
fdb 
auto-learn-mac-protect boolean
auto-learn-mac-protect-exclude-list reference
discard-unknown-source boolean
limit-mac-move keyword
mac-learning 
aging boolean
learning boolean
mac-pinning boolean
maximum-mac-addresses number
protected-src-mac-violation-action keyword
force-vc-forwarding keyword
hash-label 
signal-capability 
igmp-snooping 
apply-groups reference
apply-groups-exclude reference
fast-leave boolean
import-policy reference
maximum-number-group-sources number
maximum-number-groups number
maximum-number-sources number
mrouter-port boolean
query-interval number
query-last-member-interval number
query-response-interval number
robust-count number
router-alert-check boolean
send-queries boolean
static 
group ipv4-multicast-address 
apply-groups reference
apply-groups-exclude reference
source ipv4-unicast-address 
starg 
version keyword
ignore-standby-signaling boolean
ingress 
filter 
ip reference
ipv6 reference
qos 
network 
fp-redirect-group 
group-name reference
instance number
policy-name reference
vc-label number
l2pt 
termination 
protocols 
cdp boolean
dtp boolean
pagp boolean
stp boolean
udld boolean
vtp boolean
mld-snooping 
apply-groups reference
apply-groups-exclude reference
fast-leave boolean
import-policy reference
maximum-number-groups number
mrouter-port boolean
query-interval number
query-last-member-interval number
query-response-interval number
robust-count number
router-alert-check boolean
send-queries boolean
static 
group ipv6-multicast-address 
apply-groups reference
apply-groups-exclude reference
source ipv6-unicast-address 
starg 
version keyword
monitor-oper-group reference
oper-group reference
pw-status 
signaling boolean
split-horizon-group reference
stp 
admin-state keyword
auto-edge boolean
edge-port boolean
link-type keyword
path-cost number
port-num number
priority number
root-guard boolean
vc-type keyword
vlan-vc-tag number
stp 
admin-state keyword
forward-delay number
hello-time number
hold-count number
maximum-age number
mode keyword
mst-instance number 
apply-groups reference
apply-groups-exclude reference
mst-priority number
vlan-range string 
mst-maximum-hops number
mst-name named-item
mst-revision number
priority number
temp-flooding number
vpn-id number
vprn service-name 
aaa 
remote-servers 
radius 
access-algorithm keyword
accounting boolean
accounting-port number
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authorization boolean
interactive-authentication boolean
port number
server number 
address (ipv4-address-no-zone | ipv6-address-no-zone)
apply-groups reference
apply-groups-exclude reference
authenticator keyword
secret encrypted-leaf
tls-client-profile reference
server-retry number
server-timeout number
use-default-template boolean
tacplus 
accounting 
record-type keyword
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authorization 
request-format 
access-operation-cmd keyword
use-priv-lvl boolean
ignore-unknown-mandatory-vsas boolean
interactive-authentication boolean
priv-lvl-map 
priv-lvl number 
apply-groups reference
apply-groups-exclude reference
user-profile-name reference
server number 
address (ipv4-address-no-zone | ipv6-address-no-zone)
apply-groups reference
apply-groups-exclude reference
port number
secret encrypted-leaf
server-retry-timeout (number | keyword)
server-timeout number
service-request 
nokia-grpc-rpc-authorization boolean
nokia-netconf-base-op-authorization boolean
nokia-user boolean
nokia-user-profile boolean
use-default-template boolean
admin-state keyword
aggregates 
aggregate (ipv4-prefix | ipv6-prefix) 
aggregator 
address ipv4-unicast-address
as-number number
apply-groups reference
apply-groups-exclude reference
as-set boolean
blackhole 
generate-icmp boolean
community community
description description
discard-component-communities boolean
indirect (ipv4-address-no-zone | ipv6-address-no-zone)
local-preference number
policy reference
summary-only boolean
tunnel-group number
apply-groups reference
apply-groups-exclude reference
allow-export-bgp-vpn boolean
apply-groups reference
apply-groups-exclude reference
autonomous-system number
bgp 
admin-state keyword
advertise-inactive boolean
advertise-ipv6-next-hops 
ipv4 boolean
aggregator-id-zero boolean
apply-groups reference
apply-groups-exclude reference
asn-4-byte boolean
attribute-set 
remove boolean
authentication-key encrypted-leaf
authentication-keychain reference
backup-path 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
label-ipv6 boolean
best-path-selection 
always-compare-med 
med-value keyword
strict-as boolean
as-path-ignore 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
label-ipv6 boolean
compare-origin-validation-state boolean
deterministic-med boolean
ebgp-ibgp-equal 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
label-ipv6 boolean
ignore-nh-metric boolean
ignore-router-id 
origin-invalid-unusable boolean
bfd-liveness boolean
bfd-strict-mode 
advertise 
holdtime number
next-hop-reachability boolean
client-reflect boolean
cluster 
cluster-id ipv4-address
connect-retry number
convergence 
family keyword 
apply-groups reference
apply-groups-exclude reference
max-wait-to-advertise number
min-wait-to-advertise number
damp-peer-oscillations 
error-interval number
idle-hold-time 
initial-wait number
max-wait number
second-wait number
damping boolean
default-label-preference 
ebgp number
ibgp number
default-preference 
ebgp number
ibgp number
description description
dynamic-neighbor-limit number
ebgp-default-reject-policy 
export boolean
import boolean
eibgp-loadbalance boolean
enforce-first-as boolean
error-handling 
legacy-mode boolean
update-fault-tolerance boolean
export 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
extended-nh-encoding 
ipv4 boolean
family 
flow-ipv6 boolean
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
mcast-ipv4 boolean
mcast-ipv6 boolean
fast-external-failover boolean
graceful-restart 
gr-notification boolean
long-lived 
advertise-stale-to-all-neighbors boolean
advertised-stale-time number
family keyword 
advertised-stale-time number
apply-groups reference
apply-groups-exclude reference
helper-override-stale-time number
forwarding-bits-set keyword
helper-override-restart-time number
helper-override-stale-time number
without-no-export boolean
restart-time number
stale-routes-time number
group named-item-64 
admin-state keyword
advertise-inactive boolean
advertise-ipv6-next-hops 
ipv4 boolean
aggregator-id-zero boolean
apply-groups reference
apply-groups-exclude reference
as-override boolean
asn-4-byte boolean
authentication-key encrypted-leaf
authentication-keychain reference
bfd-liveness boolean
bfd-strict-mode 
advertise 
holdtime number
next-hop-reachability boolean
capability-negotiation boolean
client-reflect boolean
cluster 
cluster-id ipv4-address
connect-retry number
damp-peer-oscillations 
error-interval number
idle-hold-time 
initial-wait number
max-wait number
second-wait number
damping boolean
default-label-preference 
ebgp number
ibgp number
default-preference 
ebgp number
ibgp number
description description
dynamic-neighbor 
interface reference 
allowed-peer-as string
apply-groups reference
apply-groups-exclude reference
max-sessions number
match 
prefix (ipv4-prefix | ipv6-prefix) 
allowed-peer-as string
apply-groups reference
apply-groups-exclude reference
dynamic-neighbor-limit number
ebgp-default-reject-policy 
export boolean
import boolean
enforce-first-as boolean
error-handling 
update-fault-tolerance boolean
evpn-link-bandwidth 
add-to-received-bgp number
export 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
extended-nh-encoding 
ipv4 boolean
family 
flow-ipv6 boolean
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
mcast-ipv4 boolean
mcast-ipv6 boolean
fast-external-failover boolean
graceful-restart 
gr-notification boolean
long-lived 
advertise-stale-to-all-neighbors boolean
advertised-stale-time number
family keyword 
advertised-stale-time number
apply-groups reference
apply-groups-exclude reference
helper-override-stale-time number
forwarding-bits-set keyword
helper-override-restart-time number
helper-override-stale-time number
without-no-export boolean
restart-time number
stale-routes-time number
hold-time 
minimum-hold-time number
seconds number
import 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
initial-send-delay-zero boolean
keepalive number
label-preference number
link-bandwidth 
accept-from-ebgp 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
add-to-received-ebgp 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
aggregate-used-paths 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
send-to-ebgp 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
local-address (ipv4-address-no-zone | ipv6-address-no-zone | interface-name)
local-as 
as-number number
prepend-global-as boolean
private boolean
local-preference number
loop-detect keyword
loop-detect-threshold number
med-out (number | keyword)
min-route-advertisement number
multihop number
multipath-eligible boolean
next-hop-self boolean
origin-validation 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
passive boolean
path-mtu-discovery boolean
peer-as number
peer-ip-tracking boolean
preference number
prefix-limit keyword 
apply-groups reference
apply-groups-exclude reference
hold-excess number
idle-timeout number
log-only boolean
maximum number
post-import boolean
threshold number
remove-private 
limited boolean
replace boolean
skip-peer-as boolean
send-communities 
extended boolean
large boolean
standard boolean
send-default 
export-policy reference
ipv4 boolean
ipv6 boolean
split-horizon boolean
static-group boolean
tcp-mss (number | keyword)
third-party-nexthop boolean
ttl-security number
type keyword
hold-time 
minimum-hold-time number
seconds number
ibgp-multipath boolean
import 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
initial-send-delay-zero boolean
keepalive number
label-preference number
local-as 
as-number number
prepend-global-as boolean
private boolean
local-preference number
loop-detect keyword
loop-detect-threshold number
med-out (number | keyword)
min-route-advertisement number
multihop number
multipath 
ebgp number
family keyword 
apply-groups reference
apply-groups-exclude reference
ebgp number
ibgp number
max-paths number
restrict keyword
unequal-cost boolean
ibgp number
max-paths number
restrict keyword
unequal-cost boolean
neighbor (ipv4-address-with-zone | ipv6-address-with-zone) 
admin-state keyword
advertise-inactive boolean
advertise-ipv6-next-hops 
ipv4 boolean
aggregator-id-zero boolean
apply-groups reference
apply-groups-exclude reference
as-override boolean
asn-4-byte boolean
authentication-key encrypted-leaf
authentication-keychain reference
bfd-liveness boolean
bfd-strict-mode 
advertise 
holdtime number
next-hop-reachability boolean
capability-negotiation boolean
client-reflect boolean
cluster 
cluster-id ipv4-address
connect-retry number
damp-peer-oscillations 
error-interval number
idle-hold-time 
initial-wait number
max-wait number
second-wait number
damping boolean
default-label-preference 
ebgp number
ibgp number
default-preference 
ebgp number
ibgp number
description description
ebgp-default-reject-policy 
export boolean
import boolean
enforce-first-as boolean
error-handling 
update-fault-tolerance boolean
evpn-link-bandwidth 
add-to-received-bgp number
export 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
extended-nh-encoding 
ipv4 boolean
family 
flow-ipv6 boolean
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
mcast-ipv4 boolean
mcast-ipv6 boolean
fast-external-failover boolean
graceful-restart 
gr-notification boolean
long-lived 
advertise-stale-to-all-neighbors boolean
advertised-stale-time number
family keyword 
advertised-stale-time number
apply-groups reference
apply-groups-exclude reference
helper-override-stale-time number
forwarding-bits-set keyword
helper-override-restart-time number
helper-override-stale-time number
without-no-export boolean
restart-time number
stale-routes-time number
group reference
hold-time 
minimum-hold-time number
seconds number
import 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
initial-send-delay-zero boolean
keepalive number
label-preference number
link-bandwidth 
accept-from-ebgp 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
add-to-received-ebgp 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
aggregate-used-paths 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
send-to-ebgp 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
local-address (ipv4-address-no-zone | ipv6-address-no-zone | interface-name)
local-as 
as-number number
prepend-global-as boolean
private boolean
local-preference number
loop-detect keyword
loop-detect-threshold number
med-out (number | keyword)
min-route-advertisement number
multihop number
multipath-eligible boolean
next-hop-self boolean
origin-validation 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
passive boolean
path-mtu-discovery boolean
peer-as number
peer-creation-type keyword
peer-ip-tracking boolean
preference number
prefix-limit keyword 
apply-groups reference
apply-groups-exclude reference
hold-excess number
idle-timeout number
log-only boolean
maximum number
post-import boolean
threshold number
remove-private 
limited boolean
replace boolean
skip-peer-as boolean
send-communities 
extended boolean
large boolean
standard boolean
send-default 
export-policy reference
ipv4 boolean
ipv6 boolean
split-horizon boolean
tcp-mss (number | keyword)
third-party-nexthop boolean
ttl-security number
type keyword
next-hop-resolution 
policy reference
use-bgp-routes boolean
use-leaked-routes 
static boolean
path-mtu-discovery boolean
peer-ip-tracking boolean
peer-tracking-policy reference
preference number
rapid-withdrawal boolean
remove-private 
limited boolean
replace boolean
skip-peer-as boolean
rib-management 
ipv4 
leak-import 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
route-table-import 
apply-groups reference
apply-groups-exclude reference
policy-name reference
ipv6 
leak-import 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
route-table-import 
apply-groups reference
apply-groups-exclude reference
policy-name reference
label-ipv4 
leak-import 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
route-table-import 
apply-groups reference
apply-groups-exclude reference
policy-name reference
label-ipv6 
leak-import 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
router-id ipv4-address
send-communities 
extended boolean
large boolean
standard boolean
send-default 
export-policy reference
ipv4 boolean
ipv6 boolean
split-horizon boolean
tcp-mss number
third-party-nexthop boolean
bgp-evpn 
mpls number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
auto-bind-tunnel 
allow-flex-algo-fallback boolean
ecmp number
enforce-strict-tunnel-tagging boolean
enforce-untagged-route keyword
resolution keyword
resolution-filter 
bgp boolean
ldp boolean
rsvp boolean
sr-isis boolean
sr-ospf boolean
sr-ospf3 boolean
sr-policy boolean
sr-te boolean
default-route-tag one-byte-value
domain-id domain-id
dynamic-egress-label-limit boolean
evi number
evpn-link-bandwidth 
advertise 
max-dynamic-weight number
weight (number | keyword)
weighted-ecmp boolean
route-distinguisher (string | keyword)
send-tunnel-encap 
mpls boolean
vrf-export 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
vrf-import 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
vrf-target 
community route-target
export-community route-target
import-community route-target
bgp-ipvpn 
attribute-set 
export boolean
import keyword
mpls 
admin-state keyword
auto-bind-tunnel 
allow-flex-algo-fallback boolean
apply-groups reference
apply-groups-exclude reference
ecmp number
enforce-strict-tunnel-tagging boolean
enforce-untagged-route keyword
resolution keyword
resolution-filter 
bgp boolean
gre boolean
ldp boolean
rsvp boolean
sr-isis boolean
sr-ospf boolean
sr-ospf3 boolean
sr-policy boolean
sr-te boolean
static-blackhole-first boolean
weighted-ecmp boolean
domain-id domain-id
dynamic-egress-label-limit boolean
route-distinguisher (string | keyword)
vrf-export 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
vrf-import 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
vrf-target 
community route-target
export-community route-target
import-community route-target
bgp-shared-queue 
cir (number | keyword)
pir (number | keyword)
bgp-vpn-backup 
ipv4 boolean
ipv6 boolean
carrier-carrier-vpn boolean
confederation 
confed-as-num number
members number 
customer reference
d-path-length-ignore boolean
description description
dhcp-server 
apply-groups reference
apply-groups-exclude reference
dhcpv4 named-item 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
failover 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
ignore-mclt-on-takeover boolean
maximum-client-lead-time number
partner-down-delay number
peer reference 
apply-groups reference
apply-groups-exclude reference
sync-tag named-item
startup-wait-time number
force-renews boolean
lease-hold 
additional-scenarios 
internal-lease-ipsec boolean
solicited-release boolean
time number
pool named-item 
apply-groups reference
apply-groups-exclude reference
description description
failover 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
ignore-mclt-on-takeover boolean
maximum-client-lead-time number
partner-down-delay number
peer reference 
apply-groups reference
apply-groups-exclude reference
sync-tag named-item
startup-wait-time number
max-lease-time number
min-lease-time number
minimum-free 
absolute number
event-when-depleted boolean
percent number
nak-non-matching-subnet boolean
offer-time number
options 
option (number | keyword) 
apply-groups reference
apply-groups-exclude reference
ascii-string string-not-all-spaces
duration number
empty 
hex-string hex-string
ipv4-address ipv4-address
netbios-node-type keyword
subnet ipv4-unicast-prefix 
address-range ipv4-unicast-address end ipv4-unicast-address 
apply-groups reference
apply-groups-exclude reference
failover-control-type keyword
apply-groups reference
apply-groups-exclude reference
drain boolean
exclude-addresses ipv4-unicast-address end ipv4-unicast-address 
maximum-declined number
minimum-free 
absolute number
event-when-depleted boolean
percent number
options 
option (number | keyword) 
apply-groups reference
apply-groups-exclude reference
ascii-string string-not-all-spaces
duration number
empty 
hex-string hex-string
ipv4-address ipv4-address
netbios-node-type keyword
pool-selection 
use-gi-address 
scope keyword
use-pool-from-client 
delimiter string-not-all-spaces
user-db reference
user-identification keyword
dhcpv6 named-item 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
auto-provisioned boolean
defaults 
apply-groups reference
apply-groups-exclude reference
options 
option (number | keyword) 
apply-groups reference
apply-groups-exclude reference
ascii-string string-not-all-spaces
domain-string string
duration number
empty 
hex-string hex-string
ipv6-address ipv6-address
preferred-lifetime number
rebind-time number
renew-time number
valid-lifetime number
description description
failover 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
ignore-mclt-on-takeover boolean
maximum-client-lead-time number
partner-down-delay number
peer reference 
apply-groups reference
apply-groups-exclude reference
sync-tag named-item
startup-wait-time number
ignore-rapid-commit boolean
interface-id-mapping boolean
lease-hold 
additional-scenarios 
internal-lease-ipsec boolean
solicited-release boolean
time number
lease-query boolean
pool named-item 
apply-groups reference
apply-groups-exclude reference
delegated-prefix 
length number
maximum number
minimum number
description description
exclude-prefix ipv6-prefix 
failover 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
ignore-mclt-on-takeover boolean
maximum-client-lead-time number
partner-down-delay number
peer reference 
apply-groups reference
apply-groups-exclude reference
sync-tag named-item
startup-wait-time number
options 
option (number | keyword) 
apply-groups reference
apply-groups-exclude reference
ascii-string string-not-all-spaces
domain-string string
duration number
empty 
hex-string hex-string
ipv6-address ipv6-address
prefix ipv6-prefix 
apply-groups reference
apply-groups-exclude reference
drain boolean
failover-control-type keyword
options 
option (number | keyword) 
apply-groups reference
apply-groups-exclude reference
ascii-string string-not-all-spaces
domain-string string
duration number
empty 
hex-string hex-string
ipv6-address ipv6-address
preferred-lifetime number
prefix-length-threshold number 
absolute number
apply-groups reference
apply-groups-exclude reference
event-when-depleted boolean
percent number
prefix-type 
pd boolean
wan-host boolean
rebind-time number
renew-time number
valid-lifetime number
prefix-length-threshold number 
apply-groups reference
apply-groups-exclude reference
event-when-depleted boolean
minimum-free-percent number
pool-selection 
use-link-address 
scope keyword
use-pool-from-client 
delimiter string-not-all-spaces
server-id 
apply-groups reference
apply-groups-exclude reference
duid-enterprise 
ascii-string string-not-all-spaces
hex-string hex-string
duid-link-local 
user-db reference
user-identification keyword
dns 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
default-domain fully-qualified-domain-name
ipv4-source-address (keyword | ipv4-unicast-address)
ipv6-source-address (keyword | ipv6-unicast-address)
server (ipv4-address-no-zone | ipv6-address-no-zone)
ecmp number
ecmp-unequal-cost boolean
export-inactive-bgp boolean
export-inactive-bgp-enhanced boolean
fib-priority keyword
grt-leaking 
allow-local-management boolean
apply-groups reference
apply-groups-exclude reference
export-grt 
policy-name (policy-expr-string | string)
export-limit number
export-v6-limit number
grt-lookup boolean
import-grt 
policy-name (policy-expr-string | string)
hash-label boolean
igmp 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
group-if-query-source-address ipv4-unicast-address
interface interface-name 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
import-policy reference
maximum-number-group-sources number
maximum-number-groups number
maximum-number-sources number
query-interval number
query-last-member-interval number
query-response-interval number
redundant-mcast boolean
router-alert-check boolean
ssm-translate 
group-range start ipv4-multicast-address end ipv4-multicast-address 
apply-groups reference
apply-groups-exclude reference
source ipv4-unicast-address 
static 
group ipv4-multicast-address 
apply-groups reference
apply-groups-exclude reference
source ipv4-unicast-address 
starg 
group-range start ipv4-multicast-address end ipv4-multicast-address step ipv4-address 
apply-groups reference
apply-groups-exclude reference
source ipv4-unicast-address 
starg 
subnet-check boolean
version keyword
query-interval number
query-last-member-interval number
query-response-interval number
robust-count number
ssm-translate 
group-range start ipv4-multicast-address end ipv4-multicast-address 
apply-groups reference
apply-groups-exclude reference
source ipv4-unicast-address 
ignore-nh-metric boolean
interface interface-name 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description very-long-description
dynamic-tunnel-redundant-nexthop ipv4-unicast-address
hold-time 
ipv4 
down 
init-only boolean
seconds number
up 
seconds number
ipv6 
down 
init-only boolean
seconds number
up 
seconds number
if-attribute 
admin-group reference
srlg-group reference 
ingress 
ip-mtu number
ip-tunnel-interface boolean
ipsec 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
ip-exception reference
ipsec-tunnel named-item 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bfd 
bfd-designate boolean
bfd-liveness 
dest-ip ipv4-unicast-address
interface interface-name
service-name service-name
clear-df-bit boolean
copy-traffic-class-upon-decapsulation boolean
description description
encapsulated-ip-mtu number
icmp-generation 
frag-required 
admin-state keyword
interval number
message-count number
icmp6-generation 
packet-too-big 
admin-state keyword
interval number
message-count number
ip-mtu number
key-exchange 
dynamic 
auto-establish boolean
cert 
cert-profile reference
status-verify 
default-result keyword
primary keyword
secondary keyword
trust-anchor-profile reference
id 
fqdn fully-qualified-domain-name
ipv4 ipv4-unicast-address
ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
ike-policy reference
ipsec-transform reference
ppk 
id reference
list reference
pre-shared-key encrypted-leaf
manual 
keys number direction keyword 
apply-groups reference
apply-groups-exclude reference
authentication-key hex-string
encryption-key hex-string
ipsec-transform reference
spi number
local-gateway-address-override (ipv4-address-no-zone | ipv6-address-no-zone)
max-history-key-records 
esp number
ike number
pmtu-discovery-aging number
private-sap number
private-service service-name
private-tcp-mss-adjust number
propagate-pmtu-v4 boolean
propagate-pmtu-v6 boolean
public-tcp-mss-adjust (number | keyword)
remote-gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
replay-window number
security-policy 
id number
strict-match boolean
ipv6-exception reference
public-sap number
tunnel-group reference
ipv4 
addresses 
address ipv4-unicast-address 
apply-groups reference
apply-groups-exclude reference
prefix-length number
allow-directed-broadcasts boolean
bfd 
admin-state keyword
echo-receive number
multiplier number
receive number
transmit-interval number
dhcp 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
gi-address ipv4-unicast-address
lease-populate 
max-leases number
option-82 
action keyword
circuit-id 
ascii-tuple 
ifindex 
none 
sap-id 
vlan-ascii-tuple 
remote-id 
ascii-string string-not-all-spaces
mac 
none 
vendor-specific-option 
client-mac-address boolean
pool-name boolean
sap-id boolean
service-id boolean
string string-not-all-spaces
system-id boolean
proxy-server 
admin-state keyword
emulated-server ipv4-unicast-address
lease-time 
radius-override boolean
value number
relay-plain-bootp boolean
relay-proxy 
release-update-src-ip boolean
siaddr-override ipv4-unicast-address
server ipv4-unicast-address
src-ip-addr keyword
trusted boolean
use-arp boolean
icmp 
mask-reply boolean
param-problem 
admin-state keyword
number number
seconds number
redirects 
admin-state keyword
number number
seconds number
ttl-expired 
admin-state keyword
number number
seconds number
unreachables 
admin-state keyword
number number
seconds number
ip-helper-address ipv4-unicast-address
local-dhcp-server reference
neighbor-discovery 
host-route 
populate keyword 
apply-groups reference
apply-groups-exclude reference
route-tag number
learn-unsolicited boolean
limit 
log-only boolean
max-entries number
threshold number
local-proxy-arp boolean
populate boolean
proactive-refresh boolean
proxy-arp-policy reference
remote-proxy-arp boolean
retry-timer number
static-neighbor ipv4-address 
apply-groups reference
apply-groups-exclude reference
mac-address mac-address
static-neighbor-unnumbered 
mac-address mac-address
timeout number
primary 
address ipv4-unicast-address
apply-groups reference
apply-groups-exclude reference
broadcast keyword
prefix-length number
secondary ipv4-unicast-address 
apply-groups reference
apply-groups-exclude reference
broadcast keyword
igp-inhibit boolean
prefix-length number
tcp-mss number
unnumbered 
ip-address ipv4-unicast-address
ip-int-name interface-name
urpf-check 
ignore-default boolean
mode keyword
vrrp number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authentication-key encrypted-leaf
backup ipv4-unicast-address
bfd-liveness 
apply-groups reference
apply-groups-exclude reference
dest-ip ipv4-address
interface-name interface-name
service-name service-name
init-delay number
mac mac-unicast-address
master-int-inherit boolean
message-interval number
monitor-oper-group reference
ntp-reply boolean
oper-group reference
owner boolean
passive boolean
ping-reply boolean
policy reference
preempt boolean
priority number
ssh-reply boolean
standby-forwarding boolean
telnet-reply boolean
traceroute-reply boolean
ipv6 
address ipv6-address 
apply-groups reference
apply-groups-exclude reference
duplicate-address-detection boolean
eui-64 boolean
prefix-length number
primary-preference number
bfd 
admin-state keyword
echo-receive number
multiplier number
receive number
transmit-interval number
dhcp6 
apply-groups reference
apply-groups-exclude reference
relay 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
lease-populate 
max-nbr-of-leases number
route-populate 
na boolean
pd 
exclude boolean
ta boolean
option 
apply-groups reference
apply-groups-exclude reference
interface-id 
ascii-tuple 
if-index 
sap-id 
string string-not-all-spaces
remote-id boolean
server ipv6-address-with-zone
source-address ipv6-unicast-or-linklocal-address
duplicate-address-detection boolean
forward-ipv4-packets boolean
icmp6 
packet-too-big 
admin-state keyword
number number
seconds number
param-problem 
admin-state keyword
number number
seconds number
redirects 
admin-state keyword
number number
seconds number
time-exceeded 
admin-state keyword
number number
seconds number
unreachables 
admin-state keyword
number number
seconds number
link-local-address 
address ipv6-address
duplicate-address-detection boolean
local-dhcp-server reference
neighbor-discovery 
host-route 
populate keyword 
apply-groups reference
apply-groups-exclude reference
route-tag number
learn-unsolicited keyword
limit 
log-only boolean
max-entries number
threshold number
local-proxy-nd boolean
proactive-refresh keyword
proxy-nd-policy reference
reachable-time number
secure-nd 
admin-state keyword
allow-unsecured-msgs boolean
public-key-min-bits number
security-parameter number
stale-time number
static-neighbor ipv6-address 
apply-groups reference
apply-groups-exclude reference
mac-address mac-address
tcp-mss number
urpf-check 
ignore-default boolean
mode keyword
vrrp number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
backup ipv6-address
bfd-liveness 
apply-groups reference
apply-groups-exclude reference
dest-ip (ipv4-address-no-zone | ipv6-address-no-zone)
interface-name interface-name
service-name service-name
init-delay number
mac mac-unicast-address
master-int-inherit boolean
message-interval number
monitor-oper-group reference
ntp-reply boolean
oper-group reference
owner boolean
passive boolean
ping-reply boolean
policy reference
preempt boolean
priority number
standby-forwarding boolean
telnet-reply boolean
traceroute-reply boolean
load-balancing 
ip-load-balancing keyword
loopback boolean
mac mac-unicast-address
mac-accounting boolean
monitor-oper-group reference
multi-chassis-shunting-profile reference
sap sap 
accounting-policy reference
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bandwidth number
collect-stats boolean
description long-description
dist-cpu-protection reference
egress 
agg-rate 
queue-frame-based-accounting boolean
rate number
filter 
ip reference
ipv6 reference
qos 
policer-control-policy 
overrides 
apply-groups reference
apply-groups-exclude reference
root 
max-rate (number | keyword)
priority-mbs-thresholds 
min-thresh-separation (number | keyword)
priority number 
apply-groups reference
apply-groups-exclude reference
mbs-contribution (number | keyword)
policy-name reference
qinq-mark-top-only boolean
sap-egress 
overrides 
queue reference 
adaptation-rule 
cir keyword
pir keyword
apply-groups reference
apply-groups-exclude reference
avg-frame-overhead decimal-number
burst-limit (number | keyword)
cbs (number | keyword)
drop-tail 
low 
percent-reduction-from-mbs (number | keyword)
mbs (number | keyword)
parent 
cir-weight number
weight number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
port-redirect-group 
group-name reference
instance number
scheduler-policy 
overrides 
scheduler named-item 
apply-groups reference
apply-groups-exclude reference
parent 
cir-weight number
weight number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
ingress 
filter 
ip reference
ipv6 reference
qos 
match-qinq-dot1p keyword
policer-control-policy 
overrides 
apply-groups reference
apply-groups-exclude reference
root 
max-rate (number | keyword)
priority-mbs-thresholds 
min-thresh-separation (number | keyword)
priority number 
apply-groups reference
apply-groups-exclude reference
mbs-contribution (number | keyword)
policy-name reference
sap-ingress 
fp-redirect-group 
group-name reference
instance number
overrides 
policer reference 
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
mbs (number | keyword)
packet-byte-offset number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
stat-mode keyword
queue reference 
adaptation-rule 
cir keyword
pir keyword
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
drop-tail 
low 
percent-reduction-from-mbs (number | keyword)
mbs (number | keyword)
parent 
cir-weight number
weight number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
scheduler-policy 
overrides 
scheduler named-item 
apply-groups reference
apply-groups-exclude reference
parent 
cir-weight number
weight number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
ip-tunnel interface-name 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
backup-remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
clear-df-bit boolean
delivery-service service-name
description description
dest-ip (ipv4-address-no-zone | ipv6-address-no-zone) 
dscp keyword
encapsulated-ip-mtu number
gre-header 
admin-state keyword
key 
admin-state keyword
receive number
send number
icmp-generation 
frag-required 
admin-state keyword
interval number
message-count number
icmp6-generation 
packet-too-big 
admin-state keyword
number number
seconds number
ip-mtu number
ipsec-transport-mode-profile reference
local-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
pmtu-discovery-aging number
private-tcp-mss-adjust number
propagate-pmtu-v4 boolean
propagate-pmtu-v6 boolean
public-tcp-mss-adjust (number | keyword)
reassembly (number | keyword)
remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
ipsec-gateway named-item 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
cert 
cert-profile reference
status-verify 
default-result keyword
primary keyword
secondary keyword
trust-anchor-profile reference
client-db 
fallback boolean
name reference
default-secure-service 
interface interface-name
service-name service-name
default-tunnel-template reference
dhcp-address-assignment 
dhcpv4 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
gi-address ipv4-unicast-address
send-release boolean
server 
address ipv4-unicast-address
router-instance router-instance-base-vprn-loose
dhcpv6 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
link-address ipv6-unicast-address
send-release boolean
server 
address ipv6-unicast-address
router-instance router-instance-base-vprn-loose
ike-policy reference
local 
address-assignment 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
ipv4 
dhcp-server named-item
pool named-item
router-instance router-instance-base-vprn-loose
secondary-pool named-item
ipv6 
dhcp-server named-item
pool named-item
router-instance router-instance-base-vprn-loose
gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
id 
auto 
fqdn fully-qualified-domain-name
ipv4 ipv4-unicast-address
ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
max-history-key-records 
esp number
ike number
pre-shared-key encrypted-leaf
radius 
accounting-policy reference
authentication-policy reference
ts-list reference
ipsec-tunnel named-item 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bfd 
bfd-designate boolean
bfd-liveness 
dest-ip ipv4-unicast-address
interface interface-name
service-name service-name
clear-df-bit boolean
copy-traffic-class-upon-decapsulation boolean
description description
dest-ip (ipv4-address-no-zone | ipv6-address-no-zone) 
encapsulated-ip-mtu number
icmp-generation 
frag-required 
admin-state keyword
interval number
message-count number
icmp6-generation 
packet-too-big 
admin-state keyword
interval number
message-count number
ip-mtu number
key-exchange 
dynamic 
auto-establish boolean
cert 
cert-profile reference
status-verify 
default-result keyword
primary keyword
secondary keyword
trust-anchor-profile reference
id 
fqdn fully-qualified-domain-name
ipv4 ipv4-unicast-address
ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
ike-policy reference
ipsec-transform reference
ppk 
id reference
list reference
pre-shared-key encrypted-leaf
manual 
keys number direction keyword 
apply-groups reference
apply-groups-exclude reference
authentication-key hex-string
encryption-key hex-string
ipsec-transform reference
spi number
max-history-key-records 
esp number
ike number
pmtu-discovery-aging number
private-tcp-mss-adjust number
propagate-pmtu-v4 boolean
propagate-pmtu-v6 boolean
public-tcp-mss-adjust (number | keyword)
replay-window number
security-policy 
id reference
strict-match boolean
tunnel-endpoint 
delivery-service service-name
local-gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
lag 
multi-service-site reference
spoke-sdp sdp-bind-id 
accounting-policy reference
admin-state keyword
apply-groups reference
apply-groups-exclude reference
collect-stats boolean
description description
egress 
filter 
ip reference
ipv6 reference
qos 
network 
policy-name reference
port-redirect-group 
group-name reference
instance number
vc-label number
hash-label 
signal-capability 
ingress 
filter 
ip reference
ipv6 reference
qos 
network 
fp-redirect-group 
group-name reference
instance number
policy-name reference
vc-label number
vc-type keyword
static-tunnel-redundant-nexthop ipv4-unicast-address
tos-marking-state keyword
tunnel boolean
vpls named-item-64 
apply-groups reference
apply-groups-exclude reference
egress 
reclassify-using-qos reference
routed-override-filter 
ip reference
ipv6 reference
evpn 
arp 
advertise keyword 
apply-groups reference
apply-groups-exclude reference
interface-less-routing 
bgp-evpn-instance number
route-tag number
flood-garp-and-unknown-req boolean
learn-dynamic boolean
nd 
advertise keyword 
apply-groups reference
apply-groups-exclude reference
interface-less-routing 
bgp-evpn-instance number
route-tag number
learn-dynamic boolean
evpn-tunnel 
allow-bfd boolean
ipv6-gateway-address keyword
supplementary-broadcast-domain boolean
ingress 
routed-override-filter 
ip reference
ipv6 reference
ip-mirror-interface interface-name 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description very-long-description
spoke-sdp sdp-bind-id 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
ingress 
filter 
ip reference
vc-label number
ipsec 
allow-reverse-route-override-type keyword
multi-chassis-shunt-interface reference 
apply-groups reference
apply-groups-exclude reference
next-hop 
address (ipv4-address-no-zone | ipv6-address-no-zone)
multi-chassis-shunting-profile named-item 
apply-groups reference
apply-groups-exclude reference
peer reference 
apply-groups reference
apply-groups-exclude reference
multi-chassis-shunt-interface reference
overlapping-reverse-route boolean
security-policy number 
apply-groups reference
apply-groups-exclude reference
entry number 
apply-groups reference
apply-groups-exclude reference
local-ip 
address ipv4-prefix
any boolean
local-ipv6 
address ipv6-prefix
any boolean
remote-ip 
address ipv4-prefix
any boolean
remote-ipv6 
address ipv6-prefix
any boolean
ipv6 
neighbor-discovery 
reachable-time number
stale-time number
router-advertisement 
apply-groups reference
apply-groups-exclude reference
dns-options 
apply-groups reference
apply-groups-exclude reference
rdnss-lifetime (keyword | number)
server ipv6-address
interface reference 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
current-hop-limit number
dns-options 
apply-groups reference
apply-groups-exclude reference
include-rdnss boolean
rdnss-lifetime (number | keyword)
server ipv6-address
managed-configuration boolean
max-advertisement-interval number
min-advertisement-interval number
mtu number
nd-router-preference keyword
other-stateful-configuration boolean
prefix ipv6-prefix 
apply-groups reference
apply-groups-exclude reference
autonomous boolean
on-link boolean
preferred-lifetime (keyword | number)
valid-lifetime (keyword | number)
reachable-time number
retransmit-time number
router-lifetime number
use-virtual-mac boolean
isis number 
admin-state keyword
advertise-passive-only boolean
advertise-router-capability keyword
all-l1isis mac-address
all-l2isis mac-address
apply-groups reference
apply-groups-exclude reference
area-address area-address
authentication-check boolean
authentication-key encrypted-leaf
authentication-keychain reference
authentication-type keyword
csnp-authentication boolean
csnp-on-p2p boolean
default-route-tag number
export-limit 
log-percent number
number number
export-policy reference
graceful-restart 
helper-mode boolean
hello-authentication boolean
hello-padding keyword
ignore-attached-bit boolean
ignore-lsp-errors boolean
ignore-narrow-metric boolean
iid-tlv boolean
import-policy reference
interface interface-name 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bfd-liveness 
ipv4 
include-bfd-tlv boolean
ipv6 
include-bfd-tlv boolean
csnp-interval number
default-instance boolean
hello-authentication boolean
hello-authentication-key encrypted-leaf
hello-authentication-keychain reference
hello-authentication-type keyword
hello-padding keyword
interface-type keyword
ipv4-multicast boolean
ipv6-unicast boolean
level keyword 
apply-groups reference
apply-groups-exclude reference
hello-authentication-key encrypted-leaf
hello-authentication-keychain reference
hello-authentication-type keyword
hello-interval number
hello-multiplier number
hello-padding keyword
ipv4-multicast-metric number
ipv6-unicast-metric number
metric number
passive boolean
priority number
sd-offset number
sf-offset number
level-capability keyword
load-balancing-weight number
loopfree-alternate 
exclude boolean
policy-map 
route-nh-template reference
lsp-pacing-interval number
mesh-group 
blocked 
value number
passive boolean
retransmit-interval number
tag number
ipv4-multicast-routing keyword
ipv4-routing boolean
ipv6-routing keyword
level keyword 
advertise-router-capability boolean
apply-groups reference
apply-groups-exclude reference
authentication-key encrypted-leaf
authentication-keychain reference
authentication-type keyword
csnp-authentication boolean
default-ipv4-multicast-metric number
default-ipv6-unicast-metric number
default-metric number
external-preference number
hello-authentication boolean
hello-padding keyword
loopfree-alternate-exclude boolean
lsp-mtu-size number
preference number
psnp-authentication boolean
wide-metrics-only boolean
level-capability keyword
link-group named-item 
apply-groups reference
apply-groups-exclude reference
description very-long-description
level keyword 
apply-groups reference
apply-groups-exclude reference
ipv4-multicast-metric-offset number
ipv4-unicast-metric-offset number
ipv6-unicast-metric-offset number
member reference 
oper-members number
revert-members number
loopfree-alternate 
exclude 
prefix-policy reference
lsp-lifetime number
lsp-minimum-remaining-lifetime number
lsp-mtu-size number
lsp-refresh 
half-lifetime boolean
interval number
multi-topology 
ipv4-multicast boolean
ipv6-unicast boolean
multicast-import 
ipv4 boolean
overload 
max-metric boolean
overload-export-external boolean
overload-export-interlevel boolean
overload-fib-error-notify-only 
retry number
overload-on-boot 
max-metric boolean
timeout number
poi-tlv boolean
prefix-attributes-tlv boolean
prefix-limit 
limit number
log-only boolean
overload-timeout (number | keyword)
warning-threshold number
psnp-authentication boolean
reference-bandwidth number
rib-priority 
high 
prefix-list reference
tag number
router-id router-id
standard-multi-instance boolean
strict-adjacency-check boolean
summary-address (ipv4-prefix | ipv6-prefix) 
apply-groups reference
apply-groups-exclude reference
level-capability keyword
route-tag number
suppress-attached-bit boolean
system-id system-id
timers 
lsp-wait 
lsp-initial-wait number
lsp-max-wait number
lsp-second-wait number
spf-wait 
spf-initial-wait number
spf-max-wait number
spf-second-wait number
unicast-import 
ipv4 boolean
ipv6 boolean
label-mode keyword
local-routes-domain-id domain-id
log 
apply-groups reference
apply-groups-exclude reference
filter log-filter-name 
apply-groups reference
apply-groups-exclude reference
default-action keyword
description description
named-entry log-filter-entry-name 
action keyword
apply-groups reference
apply-groups-exclude reference
description description
match 
application 
eq keyword
neq keyword
event 
eq number
gt number
gte number
lt number
lte number
neq number
message 
eq string
neq string
regexp boolean
severity 
eq keyword
gt keyword
gte keyword
lt keyword
lte keyword
neq keyword
subject 
eq named-item
neq named-item
regexp boolean
log-id li-log-name 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
destination 
netconf 
max-entries number
snmp 
max-entries number
syslog reference
filter reference
netconf-stream named-item
source 
change boolean
debug boolean
main boolean
security boolean
time-format keyword
snmp-trap-group svc-vprn-snmp-trap-group-name 
apply-groups reference
apply-groups-exclude reference
description description
trap-target string 
address (ipv4-address-no-zone | ipv6-address-no-zone)
apply-groups reference
apply-groups-exclude reference
description description
notify-community string
port number
replay boolean
security-level keyword
version keyword
syslog log-vprn-syslog-name 
address (ipv4-address-no-zone | ipv6-address-no-zone)
apply-groups reference
apply-groups-exclude reference
description description
facility keyword
hostname 
use-system-name 
use-vprn-name 
value named-item-255
log-prefix (keyword | string)
port number
severity keyword
timestamp-format keyword
tls-client-profile reference
management 
allow-ftp boolean
allow-grpc boolean
allow-netconf boolean
allow-ssh boolean
allow-telnet boolean
allow-telnet6 boolean
apply-groups reference
apply-groups-exclude reference
maximum-ipv4-routes 
log-only boolean
threshold number
value number
maximum-ipv6-routes 
log-only boolean
threshold number
value number
mc-maximum-routes 
log-only boolean
threshold number
value number
mld 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
group-if-query-source-address ipv6-unicast-or-linklocal-address
interface interface-name 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
import-policy reference
maximum-number-group-sources number
maximum-number-groups number
maximum-number-sources number
query-interval number
query-last-member-interval number
query-response-interval number
router-alert-check boolean
ssm-translate 
group-range start ipv6-multicast-address end ipv6-multicast-address 
apply-groups reference
apply-groups-exclude reference
source ipv6-unicast-address 
static 
group ipv6-multicast-address 
apply-groups reference
apply-groups-exclude reference
source ipv6-unicast-address 
starg 
group-range start ipv6-multicast-address end ipv6-multicast-address step ipv6-address 
apply-groups reference
apply-groups-exclude reference
source ipv6-unicast-address 
starg 
version keyword
query-interval number
query-last-member-interval number
query-response-interval number
robust-count number
ssm-translate 
group-range start ipv6-multicast-address end ipv6-multicast-address 
apply-groups reference
apply-groups-exclude reference
source ipv6-unicast-address 
nat 
apply-groups reference
apply-groups-exclude reference
inside 
large-scale 
nat-policy reference
nat44 
destination-prefix ipv4-unicast-prefix 
apply-groups reference
apply-groups-exclude reference
nat-policy reference
deterministic 
address-map ipv4-address to ipv4-address nat-policy reference 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
outside-range ipv4-address
prefix-map ipv4-unicast-prefix nat-policy reference 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
map ipv4-address to ipv4-address 
apply-groups reference
apply-groups-exclude reference
first-outside-address ipv4-address
max-subscriber-limit number
outside 
filters 
downstream 
ipv4 reference
upstream 
ipv4 reference
mtu number
pool named-item 
address-range ipv4-unicast-address end ipv4-unicast-address 
apply-groups reference
apply-groups-exclude reference
description description
drain boolean
admin-state keyword
applications 
agnostic boolean
apply-groups reference
apply-groups-exclude reference
description description
icmp-echo-reply boolean
large-scale 
subscriber-limit number
mode keyword
nat-group reference
port-forwarding 
dynamic-block-reservation boolean
range-end number
port-reservation 
port-blocks number
ports number
type keyword
watermarks 
high number
low number
network 
apply-groups reference
apply-groups-exclude reference
ingress 
filter 
ip reference
ipv6 reference
qos 
fp-redirect-group reference
instance number
network-policy reference
urpf-check boolean
network-interface interface-name 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description very-long-description
dist-cpu-protection reference
egress 
filter 
ip reference
hold-time 
ipv4 
down 
init-only boolean
seconds number
up 
seconds number
ingress 
filter 
ip reference
ip-mtu number
ipv4 
allow-directed-broadcasts boolean
bfd 
admin-state keyword
echo-receive number
multiplier number
receive number
transmit-interval number
icmp 
mask-reply boolean
param-problem 
admin-state keyword
number number
seconds number
redirects 
admin-state keyword
number number
seconds number
ttl-expired 
admin-state keyword
number number
seconds number
unreachables 
admin-state keyword
number number
seconds number
neighbor-discovery 
retry-timer number
static-neighbor ipv4-address 
apply-groups reference
apply-groups-exclude reference
mac-address mac-address
timeout number
primary 
address ipv4-unicast-address
apply-groups reference
apply-groups-exclude reference
broadcast keyword
prefix-length number
secondary ipv4-unicast-address 
apply-groups reference
apply-groups-exclude reference
broadcast keyword
igp-inhibit boolean
prefix-length number
tcp-mss number
urpf-check 
ignore-default boolean
mode keyword
lag 
load-balancing 
ip-load-balancing keyword
lsr-load-balancing keyword
loopback 
mac mac-unicast-address
port port-and-encap
qos 
apply-groups reference
apply-groups-exclude reference
egress-instance number
egress-port-redirect-group reference
ingress-fp-redirect-group reference
ingress-instance number
network-policy reference
tos-marking-state keyword
ntp 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authenticate boolean
authentication-check boolean
authentication-key number 
apply-groups reference
apply-groups-exclude reference
key encrypted-leaf
type keyword
authentication-keychain reference
broadcast reference 
apply-groups reference
apply-groups-exclude reference
authentication-keychain reference
key-id reference
ttl number
version number
ospf number 
admin-state keyword
advertise-router-capability keyword
apply-groups reference
apply-groups-exclude reference
area ipv4-address 
advertise-ne-profile reference
advertise-router-capability boolean
apply-groups reference
apply-groups-exclude reference
area-range ipv4-unicast-prefix 
advertise boolean
apply-groups reference
apply-groups-exclude reference
blackhole-aggregate boolean
export-policy reference
import-policy reference
interface interface-name 
admin-state keyword
advertise-router-capability boolean
advertise-subnet boolean
apply-groups reference
apply-groups-exclude reference
authentication-key encrypted-leaf
authentication-keychain reference
authentication-type keyword
bfd-liveness 
remain-down-on-failure boolean
strict boolean
strict-mode-holddown number
dead-interval number
hello-interval number
interface-type keyword
load-balancing-weight number
loopfree-alternate 
exclude boolean
policy-map 
route-nh-template reference
lsa-filter-out keyword
message-digest-key number 
apply-groups reference
apply-groups-exclude reference
md5 encrypted-leaf
metric number
mtu number
neighbor ipv4-unicast-address 
passive boolean
poll-interval number
priority number
retransmit-interval number
rib-priority keyword
transit-delay number
loopfree-alternate-exclude boolean
nssa 
area-range ipv4-unicast-prefix 
advertise boolean
apply-groups reference
apply-groups-exclude reference
originate-default-route 
adjacency-check boolean
type-nssa boolean
redistribute-external boolean
summaries boolean
sham-link interface-name ip-address ipv4-unicast-address 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authentication-key encrypted-leaf
authentication-keychain reference
authentication-type keyword
dead-interval number
hello-interval number
message-digest-key number 
apply-groups reference
apply-groups-exclude reference
md5 encrypted-leaf
metric number
retransmit-interval number
transit-delay number
stub 
default-metric number
summaries boolean
virtual-link ipv4-address transit-area reference 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authentication-key encrypted-leaf
authentication-keychain reference
authentication-type keyword
dead-interval number
hello-interval number
message-digest-key number 
apply-groups reference
apply-groups-exclude reference
md5 encrypted-leaf
retransmit-interval number
transit-delay number
compatible-rfc1583 boolean
export-limit 
log-percent number
number number
export-policy reference
external-db-overflow 
interval number
limit number
external-preference number
graceful-restart 
helper-mode boolean
strict-lsa-checking boolean
ignore-dn-bit boolean
import-policy reference
loopfree-alternate 
exclude 
prefix-policy reference
multicast-import boolean
overload boolean
overload-include-ext-1 boolean
overload-include-ext-2 boolean
overload-include-stub boolean
overload-on-boot 
timeout number
preference number
reference-bandwidth number
rib-priority 
high 
prefix-list reference
router-id router-id
rtr-adv-lsa-limit 
log-only boolean
max-lsa-count number
overload-timeout (number | keyword)
warning-threshold number
super-backbone boolean
suppress-dn-bit boolean
timers 
incremental-spf-wait number
lsa-accumulate number
lsa-arrival number
lsa-generate 
lsa-initial-wait number
lsa-second-wait number
max-lsa-wait number
redistribute-delay number
spf-wait 
spf-initial-wait number
spf-max-wait number
spf-second-wait number
unicast-import boolean
vpn-domain 
id system-id
type keyword
vpn-tag number
ospf3 number 
admin-state keyword
advertise-router-capability keyword
apply-groups reference
apply-groups-exclude reference
area ipv4-address 
advertise-router-capability boolean
apply-groups reference
apply-groups-exclude reference
area-range (ipv4-prefix | ipv6-prefix) 
advertise boolean
apply-groups reference
apply-groups-exclude reference
blackhole-aggregate boolean
export-policy reference
import-policy reference
interface interface-name 
admin-state keyword
advertise-router-capability boolean
apply-groups reference
apply-groups-exclude reference
authentication 
inbound reference
outbound reference
bfd-liveness 
remain-down-on-failure boolean
strict boolean
strict-mode-holddown number
dead-interval number
hello-interval number
interface-type keyword
load-balancing-weight number
loopfree-alternate 
exclude boolean
policy-map 
route-nh-template reference
lsa-filter-out keyword
metric number
mtu number
neighbor (ipv4-address-no-zone | ipv6-address-no-zone) 
passive boolean
poll-interval number
priority number
retransmit-interval number
rib-priority keyword
transit-delay number
key-rollover-interval number
loopfree-alternate-exclude boolean
nssa 
area-range (ipv4-prefix | ipv6-prefix) 
advertise boolean
apply-groups reference
apply-groups-exclude reference
originate-default-route 
adjacency-check boolean
type-nssa boolean
redistribute-external boolean
summaries boolean
stub 
default-metric number
summaries boolean
virtual-link ipv4-address transit-area reference 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authentication 
inbound reference
outbound reference
dead-interval number
hello-interval number
retransmit-interval number
transit-delay number
export-limit 
log-percent number
number number
export-policy reference
external-db-overflow 
interval number
limit number
external-preference number
graceful-restart 
helper-mode boolean
strict-lsa-checking boolean
ignore-dn-bit boolean
import-policy reference
loopfree-alternate 
exclude 
prefix-policy reference
multicast-import boolean
overload boolean
overload-include-ext-1 boolean
overload-include-ext-2 boolean
overload-include-stub boolean
overload-on-boot 
timeout number
preference number
reference-bandwidth number
rib-priority 
high 
prefix-list reference
router-id router-id
rtr-adv-lsa-limit 
log-only boolean
max-lsa-count number
overload-timeout (number | keyword)
warning-threshold number
suppress-dn-bit boolean
timers 
incremental-spf-wait number
lsa-accumulate number
lsa-arrival number
lsa-generate 
lsa-initial-wait number
lsa-second-wait number
max-lsa-wait number
redistribute-delay number
spf-wait 
spf-initial-wait number
spf-max-wait number
spf-second-wait number
unicast-import boolean
pim 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
apply-to keyword
bgp-nh-override boolean
import 
join-policy reference
register-policy reference
interface interface-name 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
assert-period number
bfd-liveness 
ipv4 boolean
ipv6 boolean
bsm-check-rtr-alert boolean
hello-interval number
hello-multiplier number
improved-assert boolean
instant-prune-echo boolean
ipv4 
apply-groups reference
apply-groups-exclude reference
monitor-oper-group 
name reference
operation keyword
priority-delta number
multicast boolean
ipv6 
apply-groups reference
apply-groups-exclude reference
monitor-oper-group 
name reference
operation keyword
priority-delta number
multicast boolean
max-groups number
multicast-senders keyword
priority number
sticky-dr 
priority number
three-way-hello boolean
tracking-support boolean
ipv4 
admin-state keyword
rpf-table keyword
source-address 
register-message ipv4-unicast-address
ssm-assert-compatible-mode boolean
ssm-default-range boolean
ipv6 
admin-state keyword
rpf-table keyword
source-address 
register-message ipv6-unicast-address
ssm-default-range boolean
mtu-over-head number
non-dr-attract-traffic boolean
rp 
bootstrap 
export reference
import reference
ipv4 
anycast ipv4-unicast-address rp-set-peer ipv4-unicast-address 
auto-rp-discovery boolean
bsr-candidate 
address ipv4-unicast-address
admin-state keyword
hash-mask-len number
priority number
candidate boolean
mapping-agent boolean
rp-candidate 
address ipv4-unicast-address
admin-state keyword
group-range ipv4-multicast-prefix 
holdtime number
priority number
static 
address ipv4-unicast-address 
apply-groups reference
apply-groups-exclude reference
group-prefix ipv4-multicast-prefix 
override boolean
ipv6 
anycast ipv6-unicast-address rp-set-peer ipv6-unicast-address 
bsr-candidate 
address ipv6-unicast-address
admin-state keyword
hash-mask-len number
priority number
embedded-rp 
admin-state keyword
group-range ipv6-multicast-prefix 
rp-candidate 
address ipv6-unicast-address
admin-state keyword
group-range ipv6-multicast-prefix 
holdtime number
priority number
static 
address ipv6-unicast-address 
apply-groups reference
apply-groups-exclude reference
group-prefix ipv6-multicast-prefix 
override boolean
spt-switchover (ipv4-prefix | ipv6-prefix) 
apply-groups reference
apply-groups-exclude reference
threshold (number | keyword)
ssm-groups 
group-range (ipv4-prefix | ipv6-prefix) 
radius 
apply-groups reference
apply-groups-exclude reference
server named-item 
accept-coa boolean
acct-port number
address (ipv4-address-no-zone | ipv6-address-no-zone)
apply-groups reference
apply-groups-exclude reference
auth-port number
description description
pending-requests-limit number
secret encrypted-leaf
rip 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authentication-key encrypted-leaf
authentication-type keyword
bfd-liveness boolean
check-zero boolean
description description
export-limit 
log-percent number
number number
export-policy reference
group named-item 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authentication-key encrypted-leaf
authentication-type keyword
bfd-liveness boolean
check-zero boolean
description description
export-policy reference
import-policy reference
message-size number
metric-in number
metric-out number
neighbor interface-name 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authentication-key encrypted-leaf
authentication-type keyword
bfd-liveness boolean
check-zero boolean
description description
export-policy reference
import-policy reference
message-size number
metric-in number
metric-out number
preference number
receive keyword
send keyword
split-horizon boolean
timers 
flush number
timeout number
update number
unicast-address ipv4-unicast-address 
preference number
receive keyword
send keyword
split-horizon boolean
timers 
flush number
timeout number
update number
import-policy reference
message-size number
metric-in number
metric-out number
preference number
propagate-metric boolean
receive keyword
send keyword
split-horizon boolean
timers 
flush number
timeout number
update number
ripng 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bfd-liveness boolean
check-zero boolean
description description
export-limit 
log-percent number
number number
export-policy reference
group named-item 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bfd-liveness boolean
check-zero boolean
description description
export-policy reference
import-policy reference
message-size number
metric-in number
metric-out number
neighbor reference 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bfd-liveness boolean
check-zero boolean
description description
export-policy reference
import-policy reference
message-size number
metric-in number
metric-out number
preference number
receive keyword
send keyword
split-horizon boolean
timers 
flush number
timeout number
update number
unicast-address ipv6-unicast-address 
preference number
receive keyword
send keyword
split-horizon boolean
timers 
flush number
timeout number
update number
import-policy reference
message-size number
metric-in number
metric-out number
preference number
receive keyword
send keyword
split-horizon boolean
timers 
flush number
timeout number
update number
router-id router-id
service-id number
sfm-overload 
holdoff-time number
sgt-qos 
dot1p 
application keyword 
apply-groups reference
apply-groups-exclude reference
dot1p (keyword | number)
dscp 
application keyword 
apply-groups reference
apply-groups-exclude reference
dscp (keyword | number)
dscp-map keyword 
apply-groups reference
apply-groups-exclude reference
fc keyword
snmp 
access boolean
community encrypted-leaf 
access-permissions keyword
apply-groups reference
apply-groups-exclude reference
source-access-list reference
version keyword
source-address 
ipv4 keyword 
address ipv4-address
apply-groups reference
apply-groups-exclude reference
interface-name interface-name
ipv6 keyword 
address ipv6-address
apply-groups reference
apply-groups-exclude reference
spoke-sdp sdp-bind-id 
apply-groups reference
apply-groups-exclude reference
description description
static-routes 
apply-groups reference
apply-groups-exclude reference
hold-down 
initial number
max-value number
multiplier number
route (ipv4-prefix | ipv6-prefix) route-type keyword 
apply-groups reference
apply-groups-exclude reference
blackhole 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
community community
description description-allow-all-white-spaces
generate-icmp boolean
metric number
preference number
prefix-list 
flag keyword
name reference
router-instance string
tag number
community community
grt 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description-allow-all-white-spaces
metric number
preference number
indirect (ipv4-address-no-zone | ipv6-address-no-zone) 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
community community
cpe-check (ipv4-address-no-zone | ipv6-address-no-zone) 
apply-groups reference
apply-groups-exclude reference
drop-count number
interval number
log boolean
padding-size number
description description-allow-all-white-spaces
metric number
preference number
prefix-list 
flag keyword
name reference
router-instance string
tag number
interface interface-name 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
community community
cpe-check (ipv4-address-no-zone | ipv6-address-no-zone) 
apply-groups reference
apply-groups-exclude reference
drop-count number
interval number
log boolean
padding-size number
description description-allow-all-white-spaces
load-balancing-weight number
metric number
preference number
prefix-list 
flag keyword
name reference
router-instance string
tag number
ipsec-tunnel named-item 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
community community
description description-allow-all-white-spaces
metric number
preference number
tag number
next-hop (ipv4-address-with-zone | ipv6-address-with-zone) 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bfd-liveness boolean
community community
cpe-check (ipv4-address-no-zone | ipv6-address-no-zone) 
apply-groups reference
apply-groups-exclude reference
drop-count number
interval number
log boolean
padding-size number
description description-allow-all-white-spaces
load-balancing-weight number
metric number
preference number
prefix-list 
flag keyword
name reference
router-instance string
tag number
validate-next-hop boolean
tag number
ttl-propagate 
local keyword
transit keyword
twamp-light 
apply-groups reference
apply-groups-exclude reference
reflector 
admin-state keyword
allow-ipv6-udp-checksum-zero boolean
apply-groups reference
apply-groups-exclude reference
description description
prefix (ipv4-prefix | ipv6-prefix) 
apply-groups reference
apply-groups-exclude reference
description description
type keyword
udp-port number
vprn-type keyword
weighted-ecmp keyword

service command descriptions

service

Synopsis Enter the service context
Context configure service
Treeservice
Introduced25.3.R2

Platforms

7705 SAR Gen 2

customer [customer-name] customer-name

Synopsis Enter the customer list instance
Contextconfigure service customer customer-name
Treecustomer
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[customer-name] customer-name
Synopsis Customer name for a service
Context configure service customer customer-name
Treecustomer
String length1 to 64

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

contact description
Synopsis Service customer contact information
Context configure service customer customer-name contact description
Treecontact
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

customer-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisCustomer ID
Contextconfigure service customer customer-name customer-id number
Treecustomer-id
Range1 to 2147483647
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service customer customer-name description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

multi-service-site [multi-service-site-name] named-item
Synopsis Enter the multi-service-site list instance
Contextconfigure service customer customer-name multi-service-site named-item
Treemulti-service-site
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[multi-service-site-name] named-item
Synopsis Customer site name
Context configure service customer customer-name multi-service-site named-item
Treemulti-service-site
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

assignment
Synopsis Enter the assignment context
Context configure service customer customer-name multi-service-site named-item assignment
Treeassignment
Introduced25.3.R2

Platforms

7705 SAR Gen 2

card number
Synopsis Multi-service-site assignment to the card slot
Contextconfigure service customer customer-name multi-service-site named-item assignment card number
Treecard
Range1 to 20

Notes

The following elements are part of a choice: card, fpe, or port.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

port port-named
Synopsis Multi-service-site assignment to the port
Contextconfigure service customer customer-name multi-service-site named-item assignment port port-named
Treeport

Notes

The following elements are part of a choice: card, fpe, or port.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

egress
Synopsis Enter the egress context
Context configure service customer customer-name multi-service-site named-item egress
Treeegress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

agg-rate
Synopsis Enter the agg-rate context
Context configure service customer customer-name multi-service-site named-item egress agg-rate
Treeagg-rate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service customer customer-name multi-service-site named-item egress scheduler-policy
Treescheduler-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enter the overrides context
Context configure service customer customer-name multi-service-site named-item egress scheduler-policy overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

scheduler [scheduler-name] named-item
Synopsis Enter the scheduler list instance
Contextconfigure service customer customer-name multi-service-site named-item egress scheduler-policy overrides scheduler named-item
Treescheduler
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[scheduler-name] named-item
Synopsis Scheduler name
Contextconfigure service customer customer-name multi-service-site named-item egress scheduler-policy overrides scheduler named-item
Treescheduler

Description

This command specifies the scheduler name which is composed of printable 7-bit ASCII characters. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes. Each scheduler must have a unique name within the context of the scheduler policy. However, the same name can be reused in multiple scheduler policies. If the scheduler name already exists within the policy tier level, the context changes to that scheduler name for the purpose of editing the scheduler commands.

If the scheduler name exists within the policy on a different tier, an error occurs and the current context will not change. If the scheduler name does not exist in this or another tier within the scheduler policy, it is assumed that an attempt is being made to create a scheduler of that name.

If the provided scheduler name is invalid, a name syntax error occurs, the command does not execute, and the context does not change.

String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

parent
Synopsis Enter the parent context
Context configure service customer customer-name multi-service-site named-item egress scheduler-policy overrides scheduler named-item parent
Treeparent
Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate
Synopsis Enter the rate context
Context configure service customer customer-name multi-service-site named-item egress scheduler-policy overrides scheduler named-item rate
Treerate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ingress
Synopsis Enter the ingress context
Context configure service customer customer-name multi-service-site named-item ingress
Treeingress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service customer customer-name multi-service-site named-item ingress scheduler-policy
Treescheduler-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enter the overrides context
Context configure service customer customer-name multi-service-site named-item ingress scheduler-policy overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

scheduler [scheduler-name] named-item
Synopsis Enter the scheduler list instance
Contextconfigure service customer customer-name multi-service-site named-item ingress scheduler-policy overrides scheduler named-item
Treescheduler
Introduced25.3.R2

Platforms

7705 SAR Gen 2

parent
Synopsis Enter the parent context
Context configure service customer customer-name multi-service-site named-item ingress scheduler-policy overrides scheduler named-item parent
Treeparent
Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate
Synopsis Enter the rate context
Context configure service customer customer-name multi-service-site named-item ingress scheduler-policy overrides scheduler named-item rate
Treerate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

phone description
Synopsis Service customer telephone number information
Contextconfigure service customer customer-name phone description
Treephone
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

epipe [service-name] service-name

Synopsis Enter the epipe list instance
Context configure service epipe service-name
Treeepipe

Description

Commands in this context configure an Epipe service instance.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[service-name] service-name
Synopsis Administrative service name
Context configure service epipe service-name
Treeepipe
String length1 to 64

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the service
Context configure service epipe service-name admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp [bgp-instance] number
Synopsis Enter the bgp list instance
Context configure service epipe service-name bgp number
Treebgp

Description

Commands in this context configure the BGP related options that BGP uses for multihoming and BGP VPWS.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[bgp-instance] number
Synopsis BGP instance
Contextconfigure service epipe service-name bgp number
Treebgp
Range1 to 2

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

adv-service-mtu number
Synopsis Advertised service MTU value
Context configure service epipe service-name bgp number adv-service-mtu number
Treeadv-service-mtu

Description

This command configures the MTU signaled value used in the BGP for the service. When configured, the router uses the value for signaling and for validation with the received MTU instead of the service MTU. However, the value does not affect the locally enforced value, which is still based on the service MTU.

Range0 to 9782
Introduced25.3.R2

Platforms

7705 SAR Gen 2

pw-template-binding [pw-template-name] reference
Synopsis Enter the pw-template-binding list instance
Contextconfigure service epipe service-name bgp number pw-template-binding reference
Treepw-template-binding
Max. instances100
Introduced25.3.R2

Platforms

7705 SAR Gen 2

endpoint reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEndpoint name associated with the BGP PW template
Contextconfigure service epipe service-name bgp number pw-template-binding reference endpoint reference
Treeendpoint

Description

This command specifies the endpoint name associated with the BGP PW template. When an endpoint is associated to the PW template binding of a BGP VPWS service, EVPN MPLS can also be configured and associated to the same endpoint in the same Epipe service.

Reference

configure service epipe service-name endpoint named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

import-rt route-target
Synopsis Import route-target communities
Context configure service epipe service-name bgp number pw-template-binding reference import-rt route-target
Treeimport-rt
String length10 to 28
Max. instances5
Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-distinguisher (keyword | vpn-route-distinguisher)
Synopsis RD component for NLRI for L2VPN and EVPN families
Contextconfigure service epipe service-name bgp number route-distinguisher (keyword | vpn-route-distinguisher)
Treeroute-distinguisher
Optionsauto-rd
Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-target
Synopsis Enter the route-target context
Contextconfigure service epipe service-name bgp number route-target
Treeroute-target
Introduced25.3.R2

Platforms

7705 SAR Gen 2

export route-target
Synopsis Extended community name for default import policy
Contextconfigure service epipe service-name bgp number route-target export route-target
Treeexport
String length10 to 28
Introduced25.3.R2

Platforms

7705 SAR Gen 2

import route-target
Synopsis Extended community name for default import policy
Contextconfigure service epipe service-name bgp number route-target import route-target
Treeimport
String length10 to 28
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp-evpn
Synopsis Enable the bgp-evpn context
Context configure service epipe service-name bgp-evpn
Treebgp-evpn

Description

Commands in this context configure the BGP-EVPN options.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

evi number
Synopsis EVPN ID
Contextconfigure service epipe service-name bgp-evpn evi number
Treeevi

Description

This command configures an EVPN instance (EVI) unique in the system. It is used for the service-carving algorithm for multi-homing and auto-deriving route target and route distinguishers.

The following options are supported:

If this EVPN identifier is not specified, the value is zero and no route distinguisher or route target is automatically derived from it.If the specified EVPN identifier is lower than 65535 and no other route distinguisher or route target is configured in the service, the following applies:

  • the route distinguisher is derived from <system_ip>:evi

  • the route target is derived from <autonomous-system>:evi

If the specified EVPN identifier is higher than 65535 and no other route distinguisher or route target is configured in the service, the following applies.

  • The route distinguisher cannot be automatically derived. An error is generated if enabling EVPN is attempted without a route distinguisher. A manual or an auto-rd route distinguisher must be configured.

  • The route target can only be automatically derived if the evi-three-byte-auto-rt command is configured. If configured, the route target is automatically derived in accordance with the rules described in RFC8365. 

Range1 to 16777215
Introduced25.3.R2

Platforms

7705 SAR Gen 2

local-attachment-circuit [name] named-item
Synopsis Enter the local-attachment-circuit list instance
Contextconfigure service epipe service-name bgp-evpn local-attachment-circuit named-item
Treelocal-attachment-circuit
Max. instances2
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisBGP instance ID
Contextconfigure service epipe service-name bgp-evpn local-attachment-circuit named-item bgp number
Treebgp
Range1 to 2
Default1
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

eth-tag number
Synopsis Ethernet tag of the attachment circuit
Contextconfigure service epipe service-name bgp-evpn local-attachment-circuit named-item eth-tag number
Treeeth-tag

Description

This command configures the Ethernet tag value of the attachment circuit.

When configured in the local attachment circuit context, the tag value is used in the advertised AD per-EVI route sent for the attachment circuit.

When configured in the remote attachment circuit context, the value is compared with the Ethernet tag value of the imported D per-EVI routes for the service. When there is a match, the system creates an EVPN destination for the Epipe.

Range1 to 16777215
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mpls [bgp-instance] number
Synopsis Enter the mpls list instance
Context configure service epipe service-name bgp-evpn mpls number
Treempls

Description

Commands in this context configure the BGP-EVPN MPLS options.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[bgp-instance] number
Synopsis BGP instance
Contextconfigure service epipe service-name bgp-evpn mpls number
Treempls
Range1 to 2

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of BGP EVPN MPLS
Contextconfigure service epipe service-name bgp-evpn mpls number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

auto-bind-tunnel
Synopsis Enter the auto-bind-tunnel context
Contextconfigure service epipe service-name bgp-evpn mpls number auto-bind-tunnel
Treeauto-bind-tunnel

Description

Commands in this context configure automatic binding of a VPRN service using tunnels to MP-BGP peers.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

allow-flex-algo-fallback boolean
Synopsis Enable flexible algorithm fallback
Context configure service epipe service-name bgp-evpn mpls number auto-bind-tunnel allow-flex-algo-fallback boolean
Treeallow-flex-algo-fallback

Description

When configured to true, a BGP router with a Flex-Algorithm action configured (via the configure policy-options policy-statement entry action flex-algo command) can resolve to a tunnel with algorithm 0 if no target Flex-Algorithm tunnel is available.

When configured to false, the BGP router can resolve only to the intended Flex-Algorithm tunnel, which may cause traffic loss if no corresponding Flex-Algorithm tunnel is available.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

enforce-untagged-route keyword
Synopsis Untagged route type enforcement
Context configure service epipe service-name bgp-evpn mpls number auto-bind-tunnel enforce-untagged-route keyword
Treeenforce-untagged-route

Description

This command configures the enforcement of BGP routes with no administrative tag policy applied by modifying the next-hop resolution behavior for autobind services.

If the untagged-tunnel option is configured, untagged routes only bind to LSPs with no administrative tag configured. If both tagged and untagged tunnels to the next hop exist, the system only considers the untagged tunnels. If no untagged tunnels to the next hop exist, the resolution of untagged routes fails.

The untagged-tunnel option can be used in combination with the enforce-strict-tunnel-tagging command configured to true, in which case tagged routes resolve to tagged LSPs, and untagged routes only resolve to untagged LSPs.

When unconfigured, untagged routes can bind to tagged or untagged LSPs.

Options

none – Untagged routes can bind to tagged or untagged LSPs

untagged-tunnel – Untagged routes only bind to LSPs without an admin tag

Defaultnone
Introduced25.3.R2

Platforms

7705 SAR Gen 2

resolution-filter
Synopsis Enter the resolution-filter context
Contextconfigure service epipe service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter
Treeresolution-filter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp boolean
Synopsis Use BGP tunneling for next-hop resolution
Contextconfigure service epipe service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter bgp boolean
Treebgp

Description

When configured to true, BGP searches the BGP LSP for the address of the BGP next hop.

When configured to false, BGP tunneling is not used and inter-area or inter-as prefixes are not resolved.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ldp boolean
Synopsis Use LDP tunneling for next-hop resolution
Contextconfigure service epipe service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter ldp boolean
Treeldp

Description

When configured to true, BGP searches for an LDP LSP with a FEC prefix corresponding to the address of the BGP next hop.

When configured to false, LDP tunneling is not used for next-hop resolution.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

rsvp boolean
Synopsis Use RSVP tunneling for next-hop resolution
Contextconfigure service epipe service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter rsvp boolean
Treersvp

Description

When configured to true, BGP searches the best metric RSVP LSP to determine the address of the BGP next hop. This address can correspond to the system interface or to another loopback interface used by the BGP instance on the remote node. The LSP metric is provided by MPLS in the tunnel table. In the case of multiple RSVP LSPs with the same lowest metric, BGP selects the LSP with the lowest tunnel ID.

When configured to false, the RSVP LSP is not used for next-hop resolution.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sr-isis boolean
Synopsis Use IS-IS SR tunneling for next-hop resolution
Contextconfigure service epipe service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-isis boolean
Treesr-isis

Description

When configured to true, BGP uses an IS-IS tunnel type to resolve the BGP next hop.

When the sr-isis command is enabled, an SR tunnel to the BGP next hop is selected in the TTM according to the following procedure.

  • Select the SR tunnel submitted by the IS-IS instance with the lowest tunnel table preference.

  • If more than one SR tunnel exists, select the SR tunnel from the instance with the lowest metric.

  • If more than one SR tunnel exists, select the SR tunnel from the instance with the lowest instance ID.

When configured to false, IS-IS tunneling is not used for next-hop resolution.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sr-ospf boolean
Synopsis Use OSPF SR tunneling for next-hop resolution
Contextconfigure service epipe service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-ospf boolean
Treesr-ospf

Description

When configured to true, BGP uses an OSPF tunnel type to resolve the BGP next hop.

When enabled, an SR tunnel to the BGP next hop is selected in the TTM according to the following procedure.

  • Select the SR tunnel submitted by the OSPF instance with the lowest tunnel table preference.

  • If more than one SR tunnel exists, select the SR tunnel from the instance with the lowest metric.

  • If more than one SR tunnel exists, select the SR tunnel from the instance with the lowest instance ID.

When configured to false, OSPF tunneling is not used for next-hop resolution.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sr-ospf3 boolean
Synopsis Use OSPFv3 SR tunneling for next-hop resolution
Contextconfigure service epipe service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-ospf3 boolean
Treesr-ospf3

Description

When configured to true, BGP uses an OSPF3 tunnel type to resolve the BGP next hop.

When enabled, an SR tunnel to the BGP next hop is selected in the TTM according to the following procedure.

  • Select the SR tunnel submitted by the OSPFv3 instance with the lowest tunnel table preference.

  • If more than one SR tunnel exists, select the SR tunnel from the instance with the lowest metric.

  • If more than one SR tunnel exists, select the SR tunnel from the instance with the lowest instance ID.

When configured to false, OSPF3 tunneling is not used for next-hop resolution.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sr-policy boolean
Synopsis Use SR policies for next-hop resolution
Contextconfigure service epipe service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-policy boolean
Treesr-policy

Description

When configured to true, this command enables the use of SR policies to resolve the next hop of BGP-EVPN service routes.

This command configures BGP to search for an SR policy with:

  • a non-null endpoint that matches the next hop of the service route, and

  • a color value that matches the highest numbered color for the extended community attached to the service route

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sr-te boolean
Synopsis Use SR-TE tunneling for next-hop resolution
Contextconfigure service epipe service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-te boolean
Treesr-te

Description

When configured to true, BGP uses an SR-TE tunnel type to resolve the BGP next hop.

In the case of multiple SR-TE tunnels with the same lowest metric, BGP selects the tunnel with the lowest tunnel ID.

When configured to false, SR-TE tunneling is not used for next-hop resolution.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

weighted-ecmp boolean
Synopsis Allow weighted load balancing
Context configure service epipe service-name bgp-evpn mpls number auto-bind-tunnel weighted-ecmp boolean
Treeweighted-ecmp

Description

When configured to true, this router enables weighted ECMP for packets using tunnels that a VPLS or Epipe automatically binds to. Packets are sprayed across LSPs in the ECMP according to the outcome of the hash algorithm and the configured load balancing weight of each LSP.

When configured to false, this command disables weighted ECMP for next-hop tunnel selection.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

control-word boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable support for control word
Contextconfigure service epipe service-name bgp-evpn mpls number control-word boolean
Treecontrol-word

Description

When configured to true, the router enables the transmission and reception of the control word for all EVPN-MPLS destinations at the same time.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

default-route-tag one-byte-value
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDefault route tag
Contextconfigure service epipe service-name bgp-evpn mpls number default-route-tag one-byte-value
Treedefault-route-tag

Description

This command configures a route tag that is used when sending a route to the BGP application (for the corresponding service and BGP instance). If the corresponding BGP instance is enabled, the command cannot be changed.

When used for BGP EVPN contexts, only one route tag can be passed to BGP for matching on export policies. In case of a conflict with other route tags pushed by EVPN, the default route tag has the least priority.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

domain-id domain-id
Synopsis Domain ID of received BGP route before readvertisement
Contextconfigure service epipe service-name bgp-evpn mpls number domain-id domain-id
Treedomain-id

Description

This command specifies the domain ID. The domain ID identifies the network from which the BGP route was received before the RTM advertises it to a different neighbor. The domain ID is part of a domain, represented as domain-id:isf_safi_type in the D-PATH attribute, as described in draft-ietf-bess-evpn-ipvpn-interworking. Gateway routers modify the D-PATH attribute. A gateway is a PE where a VPRN is instantiated. The VPRN in this case advertises or receives routes from multiple BGP owners (for example, EVPN-IFL and BGP-IPVPN) or multiple instances of the same owner (for example, VPRN with two BGP-IPVPN instances).

Gateways use the D-PATH attribute to detect loops (for received routes where the D-PATH contains a local domain ID) and to make BGP best-path selection decisions based on the D-PATH length (shorter D-PATH is preferred).

In the following example, suppose a gateway receives prefix P in an EVPN-IFL instance with the following D-PATH from neighbor N:

Seg Len=1 / 65000:1:128

If the router imports the route in VPRN-1, BGP-EVPN SRv6 instance with domain 65000:2, it readvertises it to its BGP-IPVPN MPLS instance as follows:

Seg Len=2 / 65000:2:70 / 65000:1:128

That is, the gateway prepends the local domain ID and family to the D-PATH before readvertising the route into a different instance.

The command is also supported in Epipe services with two instances. As in the case of multi-instance VPRN services, the configured domain ID in an Epipe instance is prepended to the AD per EVI route redistributed to the other instance.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

dynamic-egress-label-limit boolean
Synopsis Enables dynamic egress label limit
Context configure service epipe service-name bgp-evpn mpls number dynamic-egress-label-limit boolean
Treedynamic-egress-label-limit

Description

When configured to true, this command relaxes the egress MPLS label limit check when resolving BGP next hops in the tunnel table.

For VPRN services, the OAM label is never computed and, therefore, one more egress label is allowed.

For EVPN (Epipe and VPLS) services, the system only computes the control word and ESI label if they are used. For the control word, the system reduces the egress label limit by one label if the control word is configured in the service. When configured, the ESI label is not counted for Epipes or VPLS services without an ES.

When configured to false this command, for EVPN, Epipe, and VPLS services, always accounts for the ESI label and control word.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

evi-three-byte-auto-rt boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAuto-derive the BGP EVPN route target
Contextconfigure service epipe service-name bgp-evpn mpls number evi-three-byte-auto-rt boolean
Treeevi-three-byte-auto-rt

Description

When configured to true, the BGP-EVPN instance import and export route target is auto-derived as described in RFC 8365 (Global-Administrator:A/Type/D-ID/Service-ID).

Where:

  • Global Administrator – is the configured 2-octet AS number; if the configured ASN exceeds the 2 byte limit, the low order 16-bit value is taken

  • A=0 (for auto-derivation)

  • Type=4 (EVI-based route-target)

  • D-ID= [1..2] – encodes the BGP instance, which allows the auto-derivation of different route-targets in multi-instance services; the value is inherited from the corresponding BGP instance

  • Service ID=3-octet EVI

When configured to false, route target derivation is not allowed.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hash-label boolean
Synopsis Default profile when the CP-provided profile is unknown
Contextconfigure service epipe service-name bgp-evpn mpls number hash-label boolean
Treehash-label

Description

When configured to true, the router pushes the hash label.

The hash label is never used for BUM packets.

The hash-label push is based on the following:

  • If advertise-l2-attributes (in the configure service vpls bgp-evpn routes incl-mcast context) is set to false, the hash label is pushed to a unicast EVPN destination.

  • If advertise-l2-attributes is set to true, the F bit is set to 1 in the Layer 2 Attributes Extended Community of the EVPN IMET route for the service. The hash label is pushed only if the remote PE signaled support for hash label (received F bit is set to 1).

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mh-mode keyword
Synopsis Multihoming mode
Context configure service epipe service-name bgp-evpn mpls number mh-mode keyword
Treemh-mode

Description

This command configures each BGP-EVPN instance in a multi-instance Epipe service to behave as network or access.

You can only configure one network instance for the service. If the service has a provider tunnel enabled, it requires a network instance.

Optionsaccess, network
Default network
Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-next-hop
Synopsis Enter the route-next-hop context
Contextconfigure service epipe service-name bgp-evpn mpls number route-next-hop
Treeroute-next-hop

Description

Commands in this context configure the next hop of the EVPN routes.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIP address of the next-hop for the service EVPN route
Contextconfigure service epipe service-name bgp-evpn mpls number route-next-hop ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeip-address

Notes

The following elements are part of a choice: ip-address, system-ipv4, or system-ipv6.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

system-ipv4
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSystem IPv4 address for service EVPN route next hop
Contextconfigure service epipe service-name bgp-evpn mpls number route-next-hop system-ipv4
Treesystem-ipv4

Notes

The following elements are part of a choice: ip-address, system-ipv4, or system-ipv6.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

system-ipv6
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSystem IPv6 address for service EVPN route next hop
Contextconfigure service epipe service-name bgp-evpn mpls number route-next-hop system-ipv6
Treesystem-ipv6

Notes

The following elements are part of a choice: ip-address, system-ipv4, or system-ipv6.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

send-tunnel-encap
Synopsis Enter the send-tunnel-encap context
Contextconfigure service epipe service-name bgp-evpn mpls number send-tunnel-encap
Treesend-tunnel-encap
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mpls boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable MPLS encapsulation
Contextconfigure service epipe service-name bgp-evpn mpls number send-tunnel-encap mpls boolean
Treempls
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

remote-attachment-circuit [name] named-item
Synopsis Enter the remote-attachment-circuit list instance
Contextconfigure service epipe service-name bgp-evpn remote-attachment-circuit named-item
Treeremote-attachment-circuit
Max. instances2
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisBGP instance ID
Contextconfigure service epipe service-name bgp-evpn remote-attachment-circuit named-item bgp number
Treebgp
Range1 to 2
Default1
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

eth-tag number
Synopsis Ethernet tag of the attachment circuit
Contextconfigure service epipe service-name bgp-evpn remote-attachment-circuit named-item eth-tag number
Treeeth-tag

Description

This command configures the Ethernet tag value of the attachment circuit.

When configured in the local attachment circuit context, the tag value is used in the advertised AD per-EVI route sent for the attachment circuit.

When configured in the remote attachment circuit context, the value is compared with the Ethernet tag value of the imported D per-EVI routes for the service. When there is a match, the system creates an EVPN destination for the Epipe.

Range1 to 16777215
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp-mh-site [site-name] named-item
Synopsis Enter the bgp-mh-site list instance
Contextconfigure service epipe service-name bgp-mh-site named-item
Treebgp-mh-site
Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[site-name] named-item
Synopsis Name for the specific site
Context configure service epipe service-name bgp-mh-site named-item
Treebgp-mh-site
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the site
Context configure service epipe service-name bgp-mh-site named-item admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

boot-timer number
Synopsis Wait time after reboot to run the DF election algorithm
Contextconfigure service epipe service-name bgp-mh-site named-item boot-timer number
Treeboot-timer
Range0 to 600
Unitsseconds
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

id number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSite ID for the service
Contextconfigure service epipe service-name bgp-mh-site named-item id number
Treeid

Description

This command configures the ID for the site. The ID must match between services but is local to the service.

Range1 to 65535
Introduced25.3.R2

Platforms

7705 SAR Gen 2

min-down-timer number
Synopsis Minimum down time when site goes operationally down
Contextconfigure service epipe service-name bgp-mh-site named-item min-down-timer number
Treemin-down-timer
Range0 to 100
Unitsseconds
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

preference number
Synopsis Preference to advertise in NLRI L2 extended community
Contextconfigure service epipe service-name bgp-mh-site named-item preference number
Treepreference
Range1 to 65535
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sap sap
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSAP to be associated with this site
Contextconfigure service epipe service-name bgp-mh-site named-item sap sap
Treesap
String length1 to 45
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp-vpws
Synopsis Enable the bgp-vpws context
Context configure service epipe service-name bgp-vpws
Treebgp-vpws
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the VPWS edge instance
Contextconfigure service epipe service-name bgp-vpws admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

local-ve
Synopsis Enter the local-ve context
Context configure service epipe service-name bgp-vpws local-ve
Treelocal-ve
Introduced25.3.R2

Platforms

7705 SAR Gen 2

id number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal VPWS edge ID
Contextconfigure service epipe service-name bgp-vpws local-ve id number
Treeid
Range1 to 65535
Introduced25.3.R2

Platforms

7705 SAR Gen 2

name named-item
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal VPWS instance name
Contextconfigure service epipe service-name bgp-vpws local-ve name named-item
Treename
String length1 to 32
Introduced25.3.R2

Platforms

7705 SAR Gen 2

remote-ve [name] named-item
Synopsis Enter the remote-ve list instance
Contextconfigure service epipe service-name bgp-vpws remote-ve named-item
Treeremote-ve
Max. instances2
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[name] named-item
Synopsis Remote PE name to which a PW is to be signaled
Contextconfigure service epipe service-name bgp-vpws remote-ve named-item
Treeremote-ve
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

id number
Synopsis Remote VPWS edge ID
Context configure service epipe service-name bgp-vpws remote-ve named-item id number
Treeid
Range1 to 65535
Introduced25.3.R2

Platforms

7705 SAR Gen 2

customer reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisService customer ID
Contextconfigure service epipe service-name customer reference
Treecustomer

Reference

configure service customer customer-name

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service epipe service-name description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

endpoint [name] named-item
Synopsis Enter the endpoint list instance
Contextconfigure service epipe service-name endpoint named-item
Treeendpoint
Max. instances2
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[name] named-item
Synopsis Service endpoint name
Context configure service epipe service-name endpoint named-item
Treeendpoint
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service epipe service-name endpoint named-item description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hold-time-active number
Synopsis Time before entering standby when MC-LAG SAP goes down
Contextconfigure service epipe service-name endpoint named-item hold-time-active number
Treehold-time-active
Range1 to 60
Unitsdeciseconds
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

revert-time (number | keyword)
Synopsis Time to wait before reverting to primary spoke SDP
Contextconfigure service epipe service-name endpoint named-item revert-time (number | keyword)
Treerevert-time
Range1 to 600
Unitsseconds
Options never, immediate
Defaultimmediate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ignore-l2vpn-mtu-mismatch boolean
Synopsis Ignore the L2 VPN MTU mismatch with local service MTU
Contextconfigure service epipe service-name ignore-l2vpn-mtu-mismatch boolean
Treeignore-l2vpn-mtu-mismatch

Description

When configured to true, the router does not check the value of the Layer 2 MTU in the Layer2 Info Extended Community received in a BGP update message against the local service MTU or locally signaled MTU. It may, therefore, bring up the BGP VPWS service regardless of any MTU mismatch.

When configured to false, an MTU mismatch prevents the system from bringing up a BGP-VPWS service.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sap [sap-id] sap
Synopsis Enter the sap list instance
Context configure service epipe service-name sap sap
Treesap
Max. instances255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[sap-id] sap
Synopsis SAP ID
Contextconfigure service epipe service-name sap sap
Treesap
String length1 to 45

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the SAP
Context configure service epipe service-name sap sap admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bandwidth number
Synopsis SAP bandwidth
Contextconfigure service epipe service-name sap sap bandwidth number
Treebandwidth
Range1 to 6400000000
Unitskilobps
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

collect-stats boolean
Synopsis Collect accounting statistics
Context configure service epipe service-name sap sap collect-stats boolean
Treecollect-stats
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description long-description
Synopsis Text description
Context configure service epipe service-name sap sap description long-description
Treedescription
String length1 to 160
Introduced25.3.R2

Platforms

7705 SAR Gen 2

egress
Synopsis Enter the egress context
Context configure service epipe service-name sap sap egress
Treeegress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

agg-rate
Synopsis Enter the agg-rate context
Context configure service epipe service-name sap sap egress agg-rate
Treeagg-rate

Notes

The following elements are part of a choice: agg-rate or percent-agg-rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate number
Synopsis Enforced aggregate rate for all queues
Contextconfigure service epipe service-name sap sap egress agg-rate rate number
Treerate
Range1 to 6400000000
Unitskilobps
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

filter
Synopsis Enter the filter context
Context configure service epipe service-name sap sap egress filter
Treefilter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

qos
Synopsis Enter the qos context
Context configure service epipe service-name sap sap egress qos
Treeqos
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policer-control-policy
Synopsis Enter the policer-control-policy context
Contextconfigure service epipe service-name sap sap egress qos policer-control-policy
Treepolicer-control-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enable the overrides context
Context configure service epipe service-name sap sap egress qos policer-control-policy overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

root
Synopsis Enter the root context
Context configure service epipe service-name sap sap egress qos policer-control-policy overrides root
Treeroot
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority-mbs-thresholds
Synopsis Enter the priority-mbs-thresholds context
Contextconfigure service epipe service-name sap sap egress qos policer-control-policy overrides root priority-mbs-thresholds
Treepriority-mbs-thresholds
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority [priority-level] number
Synopsis Enter the priority list instance
Contextconfigure service epipe service-name sap sap egress qos policer-control-policy overrides root priority-mbs-thresholds priority number
Treepriority
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sap-egress
Synopsis Enter the sap-egress context
Context configure service epipe service-name sap sap egress qos sap-egress
Treesap-egress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enter the overrides context
Context configure service epipe service-name sap sap egress qos sap-egress overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

queue [queue-id] reference
Synopsis Enter the queue list instance
Context configure service epipe service-name sap sap egress qos sap-egress overrides queue reference
Treequeue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure service epipe service-name sap sap egress qos sap-egress overrides queue reference adaptation-rule
Treeadaptation-rule
Introduced25.3.R2

Platforms

7705 SAR Gen 2

avg-frame-overhead decimal-number
Synopsis Average packet-to-frame encapsulation overhead
Contextconfigure service epipe service-name sap sap egress qos sap-egress overrides queue reference avg-frame-overhead decimal-number
Treeavg-frame-overhead

Description

This command configures overrides for the average frame overhead. The overrides supersede the average frame overhead configuration under the queue.

For a full description of this command, see the configure qos network-queue queue avg-frame-overhead and configure qos sap-egress queue avg-frame-overhead contexts.

Range0.00 to 100.00
Introduced25.3.R2

Platforms

7705 SAR Gen 2

drop-tail
Synopsis Enter the drop-tail context
Context configure service epipe service-name sap sap egress qos sap-egress overrides queue reference drop-tail
Treedrop-tail
Introduced25.3.R2

Platforms

7705 SAR Gen 2

low
Synopsis Enter the low context
Context configure service epipe service-name sap sap egress qos sap-egress overrides queue reference drop-tail low
Treelow
Introduced25.3.R2

Platforms

7705 SAR Gen 2

parent
Synopsis Enter the parent context
Context configure service epipe service-name sap sap egress qos sap-egress overrides queue reference parent
Treeparent
Introduced25.3.R2

Platforms

7705 SAR Gen 2

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service epipe service-name sap sap egress qos sap-egress overrides queue reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate
Synopsis Enter the rate context
Context configure service epipe service-name sap sap egress qos sap-egress overrides queue reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

port-redirect-group
Synopsis Enter the port-redirect-group context
Contextconfigure service epipe service-name sap sap egress qos sap-egress port-redirect-group
Treeport-redirect-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service epipe service-name sap sap egress qos scheduler-policy
Treescheduler-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enter the overrides context
Context configure service epipe service-name sap sap egress qos scheduler-policy overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

scheduler [scheduler-name] named-item
Synopsis Enter the scheduler list instance
Contextconfigure service epipe service-name sap sap egress qos scheduler-policy overrides scheduler named-item
Treescheduler
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[scheduler-name] named-item
Synopsis Scheduler name
Contextconfigure service epipe service-name sap sap egress qos scheduler-policy overrides scheduler named-item
Treescheduler

Description

This command specifies the scheduler name which is composed of printable 7-bit ASCII characters. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes. Each scheduler must have a unique name within the context of the scheduler policy. However, the same name can be reused in multiple scheduler policies. If the scheduler name already exists within the policy tier level, the context changes to that scheduler name for the purpose of editing the scheduler commands.

If the scheduler name exists within the policy on a different tier, an error occurs and the current context does not change. If the scheduler name does not exist in this or another tier within the scheduler policy, it is assumed that an attempt is being made to create a scheduler of that name.

If the provided scheduler name is invalid, a name syntax error occurs, the command does not execute, and the context is not change.

String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

parent
Synopsis Enter the parent context
Context configure service epipe service-name sap sap egress qos scheduler-policy overrides scheduler named-item parent
Treeparent
Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate
Synopsis Enter the rate context
Context configure service epipe service-name sap sap egress qos scheduler-policy overrides scheduler named-item rate
Treerate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

endpoint reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisName of the endpoint
Contextconfigure service epipe service-name sap sap endpoint reference
Treeendpoint

Reference

configure service epipe service-name endpoint named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ignore-oper-down boolean
Synopsis Ignore operational down state of the SAP on SAP failure
Contextconfigure service epipe service-name sap sap ignore-oper-down boolean
Treeignore-oper-down

Description

When configured to true, the Epipe service does not transition to the operational down state when the SAP fails. This command can only be set to true for a single SAP in an Epipe. The command can be used in Epipes with or without EVPN enabled.

When configured to false, the Epipe service transitions to the operational down state when SAP fails.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ingress
Synopsis Enter the ingress context
Context configure service epipe service-name sap sap ingress
Treeingress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter
Synopsis Enter the filter context
Context configure service epipe service-name sap sap ingress filter
Treefilter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

qos
Synopsis Enter the qos context
Context configure service epipe service-name sap sap ingress qos
Treeqos
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policer-control-policy
Synopsis Enter the policer-control-policy context
Contextconfigure service epipe service-name sap sap ingress qos policer-control-policy
Treepolicer-control-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enable the overrides context
Context configure service epipe service-name sap sap ingress qos policer-control-policy overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

root
Synopsis Enter the root context
Context configure service epipe service-name sap sap ingress qos policer-control-policy overrides root
Treeroot
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority-mbs-thresholds
Synopsis Enter the priority-mbs-thresholds context
Contextconfigure service epipe service-name sap sap ingress qos policer-control-policy overrides root priority-mbs-thresholds
Treepriority-mbs-thresholds
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority [priority-level] number
Synopsis Enter the priority list instance
Contextconfigure service epipe service-name sap sap ingress qos policer-control-policy overrides root priority-mbs-thresholds priority number
Treepriority
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sap-ingress
Synopsis Enter the sap-ingress context
Context configure service epipe service-name sap sap ingress qos sap-ingress
Treesap-ingress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

fp-redirect-group
Synopsis Enter the fp-redirect-group context
Contextconfigure service epipe service-name sap sap ingress qos sap-ingress fp-redirect-group
Treefp-redirect-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enter the overrides context
Context configure service epipe service-name sap sap ingress qos sap-ingress overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policer [policer-id] reference
Synopsis Enter the policer list instance
Contextconfigure service epipe service-name sap sap ingress qos sap-ingress overrides policer reference
Treepolicer
Introduced25.3.R2

Platforms

7705 SAR Gen 2

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service epipe service-name sap sap ingress qos sap-ingress overrides policer reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate
Synopsis Enter the rate context
Context configure service epipe service-name sap sap ingress qos sap-ingress overrides policer reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

stat-mode keyword
Synopsis Mode of statistics collected by the policer
Contextconfigure service epipe service-name sap sap ingress qos sap-ingress overrides policer reference stat-mode keyword
Treestat-mode
Optionsno-stats, minimal, offered-profile-no-cir, offered-total-cir, offered-priority-no-cir, offered-profile-cir, offered-priority-cir, offered-limited-profile-cir, offered-profile-capped-cir, offered-limited-capped-cir
Introduced25.3.R2

Platforms

7705 SAR Gen 2

queue [queue-id] reference
Synopsis Enter the queue list instance
Context configure service epipe service-name sap sap ingress qos sap-ingress overrides queue reference
Treequeue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure service epipe service-name sap sap ingress qos sap-ingress overrides queue reference adaptation-rule
Treeadaptation-rule
Introduced25.3.R2

Platforms

7705 SAR Gen 2

drop-tail
Synopsis Enter the drop-tail context
Context configure service epipe service-name sap sap ingress qos sap-ingress overrides queue reference drop-tail
Treedrop-tail
Introduced25.3.R2

Platforms

7705 SAR Gen 2

low
Synopsis Enter the low context
Context configure service epipe service-name sap sap ingress qos sap-ingress overrides queue reference drop-tail low
Treelow
Introduced25.3.R2

Platforms

7705 SAR Gen 2

parent
Synopsis Enter the parent context
Context configure service epipe service-name sap sap ingress qos sap-ingress overrides queue reference parent
Treeparent
Introduced25.3.R2

Platforms

7705 SAR Gen 2

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service epipe service-name sap sap ingress qos sap-ingress overrides queue reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate
Synopsis Enter the rate context
Context configure service epipe service-name sap sap ingress qos sap-ingress overrides queue reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service epipe service-name sap sap ingress qos scheduler-policy
Treescheduler-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enter the overrides context
Context configure service epipe service-name sap sap ingress qos scheduler-policy overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

scheduler [scheduler-name] named-item
Synopsis Enter the scheduler list instance
Contextconfigure service epipe service-name sap sap ingress qos scheduler-policy overrides scheduler named-item
Treescheduler
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[scheduler-name] named-item
Synopsis Scheduler name
Contextconfigure service epipe service-name sap sap ingress qos scheduler-policy overrides scheduler named-item
Treescheduler

Description

This command specifies the scheduler name which is composed of printable 7-bit ASCII characters. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes. Each scheduler must have a unique name within the context of the scheduler policy. However, the same name can be reused in multiple scheduler policies. If the scheduler name already exists within the policy tier level, the context changes to that scheduler name for the purpose of editing the scheduler commands.

If the scheduler name exists within the policy on a different tier, an error occurs and the current context does not change. If the scheduler name does not exist in this or another tier within the scheduler policy, it is assumed that an attempt is being made to create a scheduler of that name.

If the provided scheduler name is invalid, a name syntax error occurs, the command does not execute, and the context is not change.

String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

parent
Synopsis Enter the parent context
Context configure service epipe service-name sap sap ingress qos scheduler-policy overrides scheduler named-item parent
Treeparent
Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate
Synopsis Enter the rate context
Context configure service epipe service-name sap sap ingress qos scheduler-policy overrides scheduler named-item rate
Treerate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

lag
Synopsis Enter the lag context
Context configure service epipe service-name sap sap lag
Treelag
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mc-ring
Synopsis Enable the mc-ring context
Context configure service epipe service-name sap sap mc-ring
Treemc-ring
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ring-node named-item
Synopsis Name for the ring node associated with this SAP
Contextconfigure service epipe service-name sap sap mc-ring ring-node named-item
Treering-node
String length1 to 32

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

monitor-oper-group reference
Synopsis Monitor operational group
Context configure service epipe service-name sap sap monitor-oper-group reference
Treemonitor-oper-group

Reference

configure service oper-group named-item

Notes

The following elements are part of a choice: monitor-oper-group or oper-group.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

oper-group reference
Synopsis Operational group
Context configure service epipe service-name sap sap oper-group reference
Treeoper-group

Reference

configure service oper-group named-item

Notes

The following elements are part of a choice: monitor-oper-group or oper-group.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

service-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisService ID
Contextconfigure service epipe service-name service-id number
Treeservice-id
Range1 to 2147483647
Introduced25.3.R2

Platforms

7705 SAR Gen 2

service-mtu number
Synopsis MTU size
Contextconfigure service epipe service-name service-mtu number
Treeservice-mtu

Description

This command configures the Maximum Transmission Unit (MTU) value (payload) for the service. The system uses the value to validate the operational state of the SAP and SDP binding within the service. The value overrides the default MTU for the service type.

The service MTU and a SAP’s service delineation encapsulation overhead (4 bytes for a dot1q tag) are used to derive the required MTU of the physical port or channel on which the SAP was created. If the required payload is larger than the port or channel MTU, the SAP is placed in an inoperative state. If the required MTU is equal to or less than the port or channel MTU, the SAP transitions to the operative state.

When binding an SDP to a service, the service MTU is compared to the path MTU associated with the SDP. The path MTU can be administratively defined in the context of the SDP. The default or administrative path MTU can be dynamically reduced due to the MTU capabilities discovered by the tunneling mechanism of the SDP or the egress interface MTU capabilities based on the next hop in the tunnel path. If the service MTU is larger than the path MTU, the SDP binding for the service is placed in an inoperative state. If the service MTU is equal to or less than the path MTU, the SDP binding is placed in an operational state.

If a service MTU, port or channel MTU, or path MTU is dynamically or administratively modified, all associated SAP and SDP binding operational states are automatically reevaluated.

Binding operational states are automatically reevaluated.

For I-VPLS and Epipes bound to a B-VPLS, the service MTU must be at least 18 bytes smaller than the B-VPLS service MTU to accommodate the PBB header.

Because this connects a Layer 2 to a Layer 3 service, adjust the service MTU under the Epipe service. The MTU that is advertised from the Epipe side is service MTU minus EtherHeaderSize.

In the configure service epipe spoke-sdp context, the adv-service-mtu command can be used to override the configured MTU value used in T-LDP signaling to the far-end of an Epipe spoke-sdp. The adv-service-mtu command is also used to validate the value signaled by the far-end PE.

Range1 to 9782
Introduced25.3.R2

Platforms

7705 SAR Gen 2

spoke-sdp [sdp-bind-id] sdp-bind-id
Synopsis Enter the spoke-sdp list instance
Contextconfigure service epipe service-name spoke-sdp sdp-bind-id
Treespoke-sdp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[sdp-bind-id] sdp-bind-id
Synopsis SDP binding ID
Contextconfigure service epipe service-name spoke-sdp sdp-bind-id
Treespoke-sdp
String length3 to 16

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the SDP binding to the service
Contextconfigure service epipe service-name spoke-sdp sdp-bind-id admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

adv-service-mtu number
Synopsis Service MTU used in signaling
Context configure service epipe service-name spoke-sdp sdp-bind-id adv-service-mtu number
Treeadv-service-mtu

Description

This command configures the MTU value that is signaled in the targeted LDP for the spoke-SDP, instead of the service MTU. However, the configuration does not affect the locally enforced value, which is still based on the service MTU.

This MTU value cannot be configured on a spoke-SDP that is bound to an SDP with the adv-mtu-override command (configure service sdp context).

When unconfigured, an adjusted service MTU is used (service-mtu command).

Range0 to 9782
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bandwidth (number | keyword)
Synopsis Bandwidth that is reserved for this SDP binding
Contextconfigure service epipe service-name spoke-sdp sdp-bind-id bandwidth (number | keyword)
Treebandwidth
Range0 to 100000000
Unitskilobps
Options max
Default 0
Introduced25.3.R2

Platforms

7705 SAR Gen 2

collect-stats boolean
Synopsis Allow agent to collect accounting statistics
Contextconfigure service epipe service-name spoke-sdp sdp-bind-id collect-stats boolean
Treecollect-stats
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service epipe service-name spoke-sdp sdp-bind-id description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

egress
Synopsis Enter the egress context
Context configure service epipe service-name spoke-sdp sdp-bind-id egress
Treeegress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter
Synopsis Enter the filter context
Context configure service epipe service-name spoke-sdp sdp-bind-id egress filter
Treefilter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

qos
Synopsis Enter the qos context
Context configure service epipe service-name spoke-sdp sdp-bind-id egress qos
Treeqos
Introduced25.3.R2

Platforms

7705 SAR Gen 2

network
Synopsis Enter the network context
Context configure service epipe service-name spoke-sdp sdp-bind-id egress qos network
Treenetwork
Introduced25.3.R2

Platforms

7705 SAR Gen 2

port-redirect-group
Synopsis Enter the port-redirect-group context
Contextconfigure service epipe service-name spoke-sdp sdp-bind-id egress qos network port-redirect-group
Treeport-redirect-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEgress MPLS VC label to send packets to the far end
Contextconfigure service epipe service-name spoke-sdp sdp-bind-id egress vc-label number
Treevc-label
Range16 to 1048575
Introduced25.3.R2

Platforms

7705 SAR Gen 2

endpoint
Synopsis Enter the endpoint context
Context configure service epipe service-name spoke-sdp sdp-bind-id endpoint
Treeendpoint
Introduced25.3.R2

Platforms

7705 SAR Gen 2

icb boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisBind SDP as type Inter-Chassis Backup (ICB)
Contextconfigure service epipe service-name spoke-sdp sdp-bind-id endpoint icb boolean
Treeicb
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

name reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisService endpoint name
Contextconfigure service epipe service-name spoke-sdp sdp-bind-id endpoint name reference
Treename

Reference

configure service epipe service-name endpoint named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

precedence (number | keyword)
Synopsis Precedence when multiple SDP binds are on one endpoint
Contextconfigure service epipe service-name spoke-sdp sdp-bind-id endpoint precedence (number | keyword)
Treeprecedence
Range1 to 4
Optionsprimary
Default4
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

hash-label
Synopsis Enable the hash-label context
Context configure service epipe service-name spoke-sdp sdp-bind-id hash-label
Treehash-label

Description

Commands in this context configure the use of hash labels for egress datapaths.

For information about hash-label handling, see the "Hash label" section of the 7705 SAR Gen 2 MPLS Guide.

Notes

The following elements are part of a choice: entropy-label or hash-label.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

signal-capability
Synopsis Signal hash label capability to the remote PE
Contextconfigure service epipe service-name spoke-sdp sdp-bind-id hash-label signal-capability
Treesignal-capability

Description

When configured, this command enables the signaling and negotiating of the hash label between the local and remote PE nodes.

The signaling process outcome determines whether the local PE inserts the hash label on the user packets. This outcome can override the local PE configuration.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ingress
Synopsis Enter the ingress context
Context configure service epipe service-name spoke-sdp sdp-bind-id ingress
Treeingress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter
Synopsis Enter the filter context
Context configure service epipe service-name spoke-sdp sdp-bind-id ingress filter
Treefilter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

qos
Synopsis Enter the qos context
Context configure service epipe service-name spoke-sdp sdp-bind-id ingress qos
Treeqos
Introduced25.3.R2

Platforms

7705 SAR Gen 2

network
Synopsis Enter the network context
Context configure service epipe service-name spoke-sdp sdp-bind-id ingress qos network
Treenetwork
Introduced25.3.R2

Platforms

7705 SAR Gen 2

fp-redirect-group
Synopsis Enter the fp-redirect-group context
Contextconfigure service epipe service-name spoke-sdp sdp-bind-id ingress qos network fp-redirect-group
Treefp-redirect-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIngress MPLS VC label to send packets to the far end
Contextconfigure service epipe service-name spoke-sdp sdp-bind-id ingress vc-label number
Treevc-label
Range1 to 1048575
Introduced25.3.R2

Platforms

7705 SAR Gen 2

monitor-oper-group reference
Synopsis Operational group that affects state of the SDP bind
Contextconfigure service epipe service-name spoke-sdp sdp-bind-id monitor-oper-group reference
Treemonitor-oper-group

Reference

configure service oper-group named-item

Notes

The following elements are part of a choice: monitor-oper-group or oper-group.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

oper-group reference
Synopsis Operational group identifier
Context configure service epipe service-name spoke-sdp sdp-bind-id oper-group reference
Treeoper-group

Reference

configure service oper-group named-item

Notes

The following elements are part of a choice: monitor-oper-group or oper-group.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

pw-status
Synopsis Enter the pw-status context
Context configure service epipe service-name spoke-sdp sdp-bind-id pw-status
Treepw-status
Introduced25.3.R2

Platforms

7705 SAR Gen 2

block-on-peer-fault boolean
Synopsis Block transmit direction of PW based on status code
Contextconfigure service epipe service-name spoke-sdp sdp-bind-id pw-status block-on-peer-fault boolean
Treeblock-on-peer-fault
Defaultfalse

Notes

The following elements are part of a choice: block-on-peer-fault or standby-signaling-slave.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

signaling boolean
Synopsis Allow SDP binding to support pseudowire status signaling
Contextconfigure service epipe service-name spoke-sdp sdp-bind-id pw-status signaling boolean
Treesignaling
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

standby-signaling-slave boolean
Synopsis Block spoke transmission based on PW standby status
Contextconfigure service epipe service-name spoke-sdp sdp-bind-id pw-status standby-signaling-slave boolean
Treestandby-signaling-slave
Defaultfalse

Notes

The following elements are part of a choice: block-on-peer-fault or standby-signaling-slave.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

vc-type keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisVirtual circuit type associated with the SDP binding
Contextconfigure service epipe service-name spoke-sdp sdp-bind-id vc-type keyword
Treevc-type
Optionsether, vlan
Default ether
Introduced25.3.R2

Platforms

7705 SAR Gen 2

test boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDesignate as a test service
Contextconfigure service epipe service-name test boolean
Treetest
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vc-switching boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisUse PW switching signaling for spoke SDPs in service
Contextconfigure service epipe service-name vc-switching boolean
Treevc-switching
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vpn-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVPN identifier for the service
Contextconfigure service epipe service-name vpn-id number
Treevpn-id
Range1 to 2147483647
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ies [service-name] service-name

Synopsis Enter the ies list instance
Context configure service ies service-name
Treeies
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[service-name] service-name
Synopsis Administrative service name
Context configure service ies service-name
Treeies
String length1 to 64

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the service
Context configure service ies service-name admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

customer reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisService customer ID
Contextconfigure service ies service-name customer reference
Treecustomer

Reference

configure service customer customer-name

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service ies service-name description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface [interface-name] interface-name
Synopsis Enter the interface list instance
Contextconfigure service ies service-name interface interface-name
Treeinterface

Description

Commands in this context create a logical IP routing interface. When created, attributes such as an IP address and SAP ID can be associated with the IP interface.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[interface-name] interface-name
Synopsis Interface name
Contextconfigure service ies service-name interface interface-name
Treeinterface
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the interface
Contextconfigure service ies service-name interface interface-name admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description very-long-description
Synopsis Text description
Context configure service ies service-name interface interface-name description very-long-description
Treedescription
String length1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dynamic-tunnel-redundant-nexthop ipv4-unicast-address
Synopsis Redundant next-hop address for the dynamic IPsec tunnel
Contextconfigure service ies service-name interface interface-name dynamic-tunnel-redundant-nexthop ipv4-unicast-address
Treedynamic-tunnel-redundant-nexthop

Description

This command configures a redundant next-hop address on a public or private IPsec interface (with a public or private tunnel SAP) for dynamic IPsec tunnel in 1:1 MC-IPsec. A standby node uses the specified next-hop address to shunt traffic to the master in case it receives traffic destined to a tunnel endpoint address. The standby tunnel group needs to be operationally up for the feature to work.

The next-hop address is resolved in the routing table of a corresponding service.

Notes

The following elements are part of a choice: multi-chassis-shunting-profile or (dynamic-tunnel-redundant-nexthop and static-tunnel-redundant-nexthop).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

hold-time
Synopsis Enter the hold-time context
Context configure service ies service-name interface interface-name hold-time
Treehold-time
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4
Synopsis Enter the ipv4 context
Context configure service ies service-name interface interface-name hold-time ipv4
Treeipv4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

down
Synopsis Enter the down context
Context configure service ies service-name interface interface-name hold-time ipv4 down
Treedown

Description

Commands in this context configure the down hold timer, which specifies the delay before activating the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface up, unless an operator configures the init-only command. 

Introduced25.3.R2

Platforms

7705 SAR Gen 2

init-only boolean
Synopsis Apply delay only at interface configuration or reboot
Contextconfigure service ies service-name interface interface-name hold-time ipv4 down init-only boolean
Treeinit-only

Description

This command applies a delay only when the IP interface is first configured or after a system reboot.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

up
Synopsis Enter the up context
Context configure service ies service-name interface interface-name hold-time ipv4 up
Treeup

Description

Commands in this context configure the up hold timer, which specifies the delay before deactivation of the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface down.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

seconds number
Synopsis Up hold time for the IP interface
Context configure service ies service-name interface interface-name hold-time ipv4 up seconds number
Treeseconds
Range1 to 1200
Unitsseconds
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

ipv6
Synopsis Enter the ipv6 context
Context configure service ies service-name interface interface-name hold-time ipv6
Treeipv6
Introduced25.3.R2

Platforms

7705 SAR Gen 2

down
Synopsis Enter the down context
Context configure service ies service-name interface interface-name hold-time ipv6 down
Treedown

Description

Commands in this context configure the down hold timer, which specifies the delay before activation of the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface up, unless an operator configures the init-only command. 

Introduced25.3.R2

Platforms

7705 SAR Gen 2

init-only boolean
Synopsis Apply delay only at interface configuration or reboot
Contextconfigure service ies service-name interface interface-name hold-time ipv6 down init-only boolean
Treeinit-only

Description

When configured to true, the system applies a delay only when the IP interface is first configured or after a system reboot.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

up
Synopsis Enter the up context
Context configure service ies service-name interface interface-name hold-time ipv6 up
Treeup

Description

Commands in this context configure the up hold timer, which specifies the delay before deactivation of the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface down.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

seconds number
Synopsis Up hold time for the IP interface
Context configure service ies service-name interface interface-name hold-time ipv6 up seconds number
Treeseconds
Range1 to 1200
Unitsseconds
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

if-attribute
Synopsis Enter the if-attribute context
Contextconfigure service ies service-name interface interface-name if-attribute
Treeif-attribute
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-group reference
Synopsis Administrative group name for the interface
Contextconfigure service ies service-name interface interface-name if-attribute admin-group reference
Treeadmin-group

Description

This command specifies the administrative group membership to an interface. 

The configured administrative group membership is applied in all levels or areas the interface is participating in. The same interface cannot have different memberships in different levels or areas.

Reference

configure routing-options if-attribute admin-group named-item

Max. instances32
Introduced25.3.R2

Platforms

7705 SAR Gen 2

srlg-group [name] reference
Synopsis Add a list entry for srlg-group
Contextconfigure service ies service-name interface interface-name if-attribute srlg-group reference
Treesrlg-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ingress
Synopsis Enter the ingress context
Context configure service ies service-name interface interface-name ingress
Treeingress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-mtu number
Synopsis IP MTU applied to outgoing packets
Context configure service ies service-name interface interface-name ip-mtu number
Treeip-mtu

Description

This command configures the IP maximum transmission unit (MTU) for the associated router IP interface.

Range512 to 9786
Unitsbytes
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

ip-tunnel-interface boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEnable IP tunnel interface
Contextconfigure service ies service-name interface interface-name ip-tunnel-interface boolean
Treeip-tunnel-interface

Description

When configured to true, the system enables a GRE virtual IP interface.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipsec
Synopsis Enable the ipsec context
Context configure service ies service-name interface interface-name ipsec
Treeipsec

Description

Commands in this context configure an IPsec secured interface.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of IPsec secured interface
Contextconfigure service ies service-name interface interface-name ipsec admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-exception reference
Synopsis IP exception filter
Context configure service ies service-name interface interface-name ipsec ip-exception reference
Treeip-exception

Description

This command configures the IP exception filter for the secured interface. All ingress traffic matching the specified filter bypasses IPsec processing.

Reference

configure filter ip-exception filter-name

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipsec-tunnel [name] named-item
Synopsis Enter the ipsec-tunnel list instance
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item
Treeipsec-tunnel

Description

Commands in this context configure IPsec tunnels used to secure traffic forwarded over the interface.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[name] named-item
Synopsis IPsec tunnel name
Context configure service ies service-name interface interface-name ipsec ipsec-tunnel named-item
Treeipsec-tunnel
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the bfd context
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item bfd
Treebfd
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd-designate boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDesignate IPsec tunnel to carry BFD traffic
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item bfd bfd-designate boolean
Treebfd-designate
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd-liveness
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the bfd-liveness context
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item bfd bfd-liveness
Treebfd-liveness

Description

Commands in this context configure a BFD session to provide a heart-beat mechanism for a specified IPsec tunnel. There can be only one BFD session assigned to any given IPsec tunnel, but there can be multiple IPsec tunnels using the same BFD session.

BFD controls the state of the association tunnel. If the BFD session goes down, the system brings down the associated non-designated IPsec tunnel.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

dest-ip ipv4-unicast-address
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDestination address used for the BFD session
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item bfd bfd-liveness dest-ip ipv4-unicast-address
Treedest-ip

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface interface-name
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisName of the interface used by the BFD session
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item bfd bfd-liveness interface interface-name
Treeinterface
String length1 to 32

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

service-name service-name
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative service name
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item bfd bfd-liveness service-name service-name
Treeservice-name

Description

This command configures the name of the service where BFD traffic is forwarded to.

String length1 to 64

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

clear-df-bit boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisReset the DF bit to 0 in all payload IP packets
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item clear-df-bit boolean
Treeclear-df-bit

Description

When configured to true, the DF bit is set to 0 in all payload IP packets associated with the IPsec tunnel, before any potential fragmentation occurs.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

copy-traffic-class-upon-decapsulation boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable traffic class copy upon decapsulation
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item copy-traffic-class-upon-decapsulation boolean
Treecopy-traffic-class-upon-decapsulation

Description

When configured to true, the system copies the traffic class from the outer tunnel IP packet header to the payload IP packet header in the decapsulating direction (public to private).

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

encapsulated-ip-mtu number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum size of the encapsulated tunnel packet
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item encapsulated-ip-mtu number
Treeencapsulated-ip-mtu

Description

This command specifies the maximum size of the encapsulated tunnel packet to the IPsec tunnel, the IP tunnel, or the dynamic tunnels terminated on the IPsec Gateway. If the encapsulated IPv4 or IPv6 tunnel packet exceeds this value, the system fragments the packet.

Range512 to 9000
Unitsbytes
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

icmp-generation
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the icmp-generation context
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item icmp-generation
Treeicmp-generation

Description

Commands in this context configure settings for ICMPv4 message generation.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

frag-required
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the frag-required context
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item icmp-generation frag-required
Treefrag-required

Description

Commands in this context configure the attributes for sending generated ICMP Destination Unreachable "fragmentation needed and DF set" messages (type 3, code 4) back to the source, if the received size of the IPv4 packet on the private side exceeds the private MTU size.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of sending ICMP messages
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item icmp-generation frag-required admin-state keyword
Treeadmin-state

Description

This command configures the administrative state of sending ICMP Destination Unreachable "fragmentation needed, DF set" messages (type 3, code 4) messages to the source if the received size of the IPv4 packet on the private side exceeds the private MTU size.

Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interval number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisInterval for sending ICMP messages
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item icmp-generation frag-required interval number
Treeinterval

Description

This command configures the interval for sending ICMP Destination Unreachable "fragmentation needed, DF set" messages (type 3, code 4).

Range1 to 60
Unitsseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

message-count number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of ICMP messages that can be sent
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item icmp-generation frag-required message-count number
Treemessage-count

Description

This command configures the maximum number of ICMP Destination Unreachable "fragmentation needed, DF set" messages (type 3, code 4) that can be sent during the configured interval.

Range10 to 1000
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

icmp6-generation
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the icmp6-generation context
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item icmp6-generation
Treeicmp6-generation

Description

Commands in this context configure settings for ICMPv6 message generation.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

packet-too-big
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the packet-too-big context
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item icmp6-generation packet-too-big
Treepacket-too-big

Description

Commands in this context configure the parameters to send ICMPv6 PTB (Packet Too Big) messages on the private side.

The system sends PTB messages if a received IPv6 packet on the private side is greater than 1280 bytes and it exceeds the private MTU of the tunnel.

The private MTU for the tunnel is configured via the configure router interface ipsec ipsec-tunnel ip-mtu command for the interface.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of Packet Too Big message sends
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item icmp6-generation packet-too-big admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interval number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisInterval for sending Packet Too Big messages
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item icmp6-generation packet-too-big interval number
Treeinterval
Range1 to 60
Unitsseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

message-count number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of ICMPv6 PTB messages that can be sent
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item icmp6-generation packet-too-big message-count number
Treemessage-count

Description

This command configures the maximum number of PTB messages that can be sent during the configured interval.

Range10 to 1000
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

ip-mtu number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPrivate MTU of the IPsec tunnel
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item ip-mtu number
Treeip-mtu

Description

This command specifies the private MTU of the IPsec tunnel. The private MTU is used to determine the need for fragmentation before encapsulation of the payload packet.

Range512 to 9000
Unitsbytes
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

key-exchange
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the key-exchange context
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange
Treekey-exchange
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dynamic
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the dynamic context
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic
Treedynamic

Notes

The following elements are part of a choice: dynamic or manual.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

auto-establish boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAttempt to establish a phase 1 exchange automatically
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic auto-establish boolean
Treeauto-establish
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

cert
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the cert context
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic cert
Treecert

Description

Commands in this context configure the attributes of the dynamic keying certificate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

status-verify
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the status-verify context
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic cert status-verify
Treestatus-verify

Description

Commands in this context configure attributes of Certificate Status Verification (CSV).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

primary keyword
Synopsis Primary method of CSV to verify the revocation status
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic cert status-verify primary keyword
Treeprimary

Description

This command configures the primary method of Certificate Status Verification (CSV) that is used to verify the revocation status of the certificate of the peer.

Optionscrl, ocsp
Default crl
Introduced25.3.R2

Platforms

7705 SAR Gen 2

secondary keyword
Synopsis Secondary method used to verify certificate revocation
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic cert status-verify secondary keyword
Treesecondary

Description

This command specifies the secondary method of Certificate Status Verification (CSV) that is used to verify the revocation status of the peer certificate.

Optionsnone, crl, ocsp
Defaultnone
Introduced25.3.R2

Platforms

7705 SAR Gen 2

id
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the id context
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic id
Treeid

Description

Commands in this context specify the local ID used for IDi or IDr for IKEv2 negotiation.

The default behavior depends on the local authentication method as follows:

  • Psk: local tunnel IP address

  • Cert-auth: subject of the local certificate

Introduced25.3.R2

Platforms

7705 SAR Gen 2

fqdn fully-qualified-domain-name
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisFQDN used as the local ID IKE type
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic id fqdn fully-qualified-domain-name
Treefqdn
String length1 to 255

Notes

The following elements are part of a choice: fqdn, ipv4, or ipv6.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4 ipv4-unicast-address
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPv4 as the local ID type
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic id ipv4 ipv4-unicast-address
Treeipv4

Notes

The following elements are part of a choice: fqdn, ipv4, or ipv6.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPv6 used as the local IKE ID type
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic id ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
Treeipv6

Notes

The following elements are part of a choice: fqdn, ipv4, or ipv6.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ike-policy reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIKE policy ID
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic ike-policy reference
Treeike-policy

Description

This command specifies the ID of the IKE policy used for IKE negotiation.

The ipsec-transport-mode-profile configuration only supports IKEv2.

Reference

configure ipsec ike-policy number

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipsec-transform reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPsec transform IDs used by the dynamic key
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic ipsec-transform reference
Treeipsec-transform

Description

This command specifies IPsec transform IDs used for CHILD_SA negotiation.

Reference

configure ipsec ipsec-transform number

Max. instances4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ppk
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the ppk context
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic ppk
Treeppk

Description

Commands in this context configure the PPKs to use for dynamic keying of the IPsec tunnel.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

id reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPPK ID
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic ppk id reference
Treeid

Reference

configure ipsec ppk-list named-item ppk named-item-64

Introduced25.3.R2

Platforms

7705 SAR Gen 2

list reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPPK list instance name
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic ppk list reference
Treelist

Reference

configure ipsec ppk-list named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

pre-shared-key encrypted-leaf
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPre-shared key for authentication
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic pre-shared-key encrypted-leaf
Treepre-shared-key
String length1 to 115
Introduced25.3.R2

Platforms

7705 SAR Gen 2

manual
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the manual context
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange manual
Treemanual

Description

Commands in this context configure settings for manually configured security associations for the IPsec tunnel.

Notes

The following elements are part of a choice: dynamic or manual.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

keys [security-association] number direction keyword
Synopsis Enter the keys list instance
Context configure service ies service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange manual keys number direction keyword
Treekeys

Description

Commands in this context configure the security association list for the tunnel.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

spi number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSPI of inbound and outbound packets
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange manual keys number direction keyword spi number
Treespi

Description

This command specifies the Security Parameter Index (SPI) used to look up the instruction to verify and decrypt the incoming IPsec packets when the direction is inbound. When the direction is outbound, the SPI is used in the encoding of the outgoing packets.

The remote node can use the SPI to look up the instruction to verify and decrypt the packet.

Range256 to 16383

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

local-gateway-address-override (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal IPsec tunnel endpoint address
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item local-gateway-address-override (ipv4-address-no-zone | ipv6-address-no-zone)
Treelocal-gateway-address-override

Description

This command configures the local IPsec tunnel endpoint address. This overrides the default endpoint address, which is the interface address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

max-history-key-records
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the max-history-key-records context
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item max-history-key-records
Treemax-history-key-records

Description

Commands in this context configure the settings for recording historical IPsec keys.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

esp number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of recent records
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item max-history-key-records esp number
Treeesp
Range1 to 48
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ike number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of historical IKE key records
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item max-history-key-records ike number
Treeike
Range1 to 3
Introduced25.3.R2

Platforms

7705 SAR Gen 2

pmtu-discovery-aging number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAging out time of the learned path MTU
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item pmtu-discovery-aging number
Treepmtu-discovery-aging

Description

This command configures the temporary public and private MTU expiration time. The temporary MTU is used for MTU propagation.

Range900 to 3600
Unitsseconds
Default 900
Introduced25.3.R2

Platforms

7705 SAR Gen 2

private-sap number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPrivate SAP ID
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item private-sap number
Treeprivate-sap
Range0 to 4094

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

private-service service-name
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPrivate service name
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item private-service service-name
Treeprivate-service

Description

This command configures the private service name.

If unconfigured, the private service is the service where the secured interface resides.

String length1 to 64
Introduced25.3.R2

Platforms

7705 SAR Gen 2

private-tcp-mss-adjust number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTCP maximum segment size (MSS) adjustment
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item private-tcp-mss-adjust number
Treeprivate-tcp-mss-adjust

Description

This command specifies the TCP MSS to adjust for the tunnel on the private side.

When configured, the system may use the value to update the MSS option in the received TCP SYN packet on the private side.

Range512 to 9000
Unitsbytes
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

propagate-pmtu-v4 boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable propagation of the path MTU to IPv4 hosts
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item propagate-pmtu-v4 boolean
Treepropagate-pmtu-v4

Description

When configured to true, the system propagates the path MTU learned from the public side to the private side (IPv4 hosts).

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

propagate-pmtu-v6 boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable propagation of the path MTU to IPv6 hosts
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item propagate-pmtu-v6 boolean
Treepropagate-pmtu-v6

Description

When configured to true, the system propagates the path MTU learned from the public side to the private side (IPv6 hosts).

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

public-tcp-mss-adjust (number | keyword)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTCP maximum segment size (MSS) on the public network
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item public-tcp-mss-adjust (number | keyword)
Treepublic-tcp-mss-adjust

Description

This command configures the MSS for the TCP traffic in an IPsec tunnel that is sent from the public network to the private network. The system may use this value to adjust or insert the MSS option in the TCP SYN packet.

Range512 to 9000
Unitsbytes
Options auto
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

remote-gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRemote IPsec tunnel endpoint address
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item remote-gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeremote-gateway-address
Introduced25.3.R2

Platforms

7705 SAR Gen 2

replay-window number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAnti-replay window size
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item replay-window number
Treereplay-window

Description

This command specifies the size of an IPsec anti-replay window. If unconfigured, IPsec anti-replay is disabled.

Range32 | 64 | 128 | 256 | 512
Unitspackets
Introduced25.3.R2

Platforms

7705 SAR Gen 2

security-policy
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the security-policy context
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item security-policy
Treesecurity-policy

Description

Commands in this context specify a security policy used by the tunnel.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

id number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSecurity policy ID for use by the tunnel
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item security-policy id number
Treeid
Max. range0 to 4294967295
Introduced25.3.R2

Platforms

7705 SAR Gen 2

strict-match boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable strict match of the security policy entry
Contextconfigure service ies service-name interface interface-name ipsec ipsec-tunnel named-item security-policy strict-match boolean
Treestrict-match

Description

When configured to true, this command enables strict match of the security policy entry.

When a CREATE_CHILD exchange request is received for a static IPsec tunnel, and this request is not a rekey request, ISA matches the received TSi and TSr with the configured security policy. This can be a match only when a received TS (in TSi or TSr) address range matches exactly with the subnet in a security policy entry.

If there is no match, the setup fails, and TS_UNACCEPTABLE is sent.

If there is a match, but there is an existing CHILD_SA for the matched security policy, the setup fails, and NO_PROPOSAL_CHOSEN is sent.

If there is a match, and there is not a CHILD_SA for the matched entry, the subnet is sent in the matched security policy entry as TSi and TSr, and the CHILD_SA is created.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6-exception reference
Synopsis IPv6 filter exception used to bypass encryption
Contextconfigure service ies service-name interface interface-name ipsec ipv6-exception reference
Treeipv6-exception

Description

This command specifies the IPv6 filter exception for an IPsec-secured IPv6 interface. When an IPv6 filter exception is added, clear text packets that match the exception criteria in the IPv6 filter exception can ingress the interface, even when IPsec is enabled on the interface.

Reference

configure filter ipv6-exception filter-name

Introduced25.3.R2

Platforms

7705 SAR Gen 2

public-sap number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPublic SAP ID
Contextconfigure service ies service-name interface interface-name ipsec public-sap number
Treepublic-sap
Range0 to 4094

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

tunnel-group reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTunnel group ID
Contextconfigure service ies service-name interface interface-name ipsec tunnel-group reference
Treetunnel-group

Reference

configure isa tunnel-group number

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4
Synopsis Enter the ipv4 context
Context configure service ies service-name interface interface-name ipv4
Treeipv4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

addresses
Synopsis Enter the addresses context
Context configure service ies service-name interface interface-name ipv4 addresses
Treeaddresses
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address [ipv4-address] ipv4-unicast-address
Synopsis Enter the address list instance
Contextconfigure service ies service-name interface interface-name ipv4 addresses address ipv4-unicast-address
Treeaddress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ipv4-address] ipv4-unicast-address
Synopsis IPv4 address for the interface
Context configure service ies service-name interface interface-name ipv4 addresses address ipv4-unicast-address
Treeaddress

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd
Synopsis Enter the bfd context
Context configure service ies service-name interface interface-name ipv4 bfd
Treebfd
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of BFD sessions
Context configure service ies service-name interface interface-name ipv4 bfd admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

echo-receive number
Synopsis Minimum echo interval over this interface
Contextconfigure service ies service-name interface interface-name ipv4 bfd echo-receive number
Treeecho-receive
Range100 to 100000
Unitsmilliseconds
Introduced25.3.R2

Platforms

7705 SAR Gen 2

multiplier number
Synopsis Number of consecutive BFD messages missed from the peer
Contextconfigure service ies service-name interface interface-name ipv4 bfd multiplier number
Treemultiplier

Description

This command configures the number of missed messages before the BFD session state is changed to down and the upper-level protocol is notified of the fault. A multiplier of less than 3 should not be used in production environments. 

Range1 to 20
Default3
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

receive number
Synopsis BFD receive interval over this interface
Contextconfigure service ies service-name interface interface-name ipv4 bfd receive number
Treereceive

Description

This command specifies the receive interval for the BFD session.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

transmit-interval number
Synopsis BFD transmit interval over this interface
Contextconfigure service ies service-name interface interface-name ipv4 bfd transmit-interval number
Treetransmit-interval

Description

This command configures the transmit intervals.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

dhcp
Synopsis Enter the dhcp context
Context configure service ies service-name interface interface-name ipv4 dhcp
Treedhcp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

gi-address ipv4-unicast-address
Synopsis GI address for the DHCP relay
Context configure service ies service-name interface interface-name ipv4 dhcp gi-address ipv4-unicast-address
Treegi-address

Description

This command configures the GI address to distinguish between the different subscriber interfaces (and potentially group interfaces) defined when the router functions as a DHCP relay.

By default, the GI address used in the relayed DHCP packet is the primary IP address of a normal IES interface. Specifying the GI address allows the user to choose a secondary address. For group interfaces, a GI address must be specified under the group interface DHCP context or subscriber interface DHCP context for DHCP to function.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

option-82
Synopsis Enter the option-82 context
Context configure service ies service-name interface interface-name ipv4 dhcp option-82
Treeoption-82

Description

Commands in this context configure the processing required when the router receives a DHCP request that already has an Option 82 field in the packet.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

action keyword
Synopsis Action to take with received DHCP Option 82
Contextconfigure service ies service-name interface interface-name ipv4 dhcp option-82 action keyword
Treeaction
Optionsreplace, drop, keep
Defaultkeep
Introduced25.3.R2

Platforms

7705 SAR Gen 2

circuit-id
Synopsis Enter the circuit-id context
Context configure service ies service-name interface interface-name ipv4 dhcp option-82 circuit-id
Treecircuit-id
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ascii-tuple
Synopsis Use the ASCII-encoded tuple for the circuit ID
Contextconfigure service ies service-name interface interface-name ipv4 dhcp option-82 circuit-id ascii-tuple
Treeascii-tuple

Notes

The following elements are part of a choice: ascii-tuple, ifindex, none, sap-id, or vlan-ascii-tuple.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ifindex
Synopsis Use the interface index for the circuit ID
Contextconfigure service ies service-name interface interface-name ipv4 dhcp option-82 circuit-id ifindex
Treeifindex

Notes

The following elements are part of a choice: ascii-tuple, ifindex, none, sap-id, or vlan-ascii-tuple.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

none
Synopsis Do not include the circuit ID
Context configure service ies service-name interface interface-name ipv4 dhcp option-82 circuit-id none
Treenone

Notes

The following elements are part of a choice: ascii-tuple, ifindex, none, sap-id, or vlan-ascii-tuple.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

sap-id
Synopsis Use the SAP ID
Contextconfigure service ies service-name interface interface-name ipv4 dhcp option-82 circuit-id sap-id
Treesap-id

Notes

The following elements are part of a choice: ascii-tuple, ifindex, none, sap-id, or vlan-ascii-tuple.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

vlan-ascii-tuple
Synopsis Include the VLAN ID and dot1p bits in the ASCII tuple
Contextconfigure service ies service-name interface interface-name ipv4 dhcp option-82 circuit-id vlan-ascii-tuple
Treevlan-ascii-tuple

Description

When configured, the router includes the VLAN ID and dot1p bits with the ASCII-tuple information. This only occurs on dot1q and QinQ-encapsulated ports. When the Option 82 bits are stripped, dot1p bits are copied to the Ethernet header of the outgoing packet.

When unconfigured, the router leaves the circuit ID sub-option of the DHCP packet empty.

Notes

The following elements are part of a choice: ascii-tuple, ifindex, none, sap-id, or vlan-ascii-tuple.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

remote-id
Synopsis Enter the remote-id context
Context configure service ies service-name interface interface-name ipv4 dhcp option-82 remote-id
Treeremote-id

Description

Commands in this context configure the remote IP sub-option of the DHCP packet with the identity of the remote host end (typically the DHCP client).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ascii-string string-not-all-spaces
Synopsis User-defined ASCII string for the remote ID
Contextconfigure service ies service-name interface interface-name ipv4 dhcp option-82 remote-id ascii-string string-not-all-spaces
Treeascii-string
String length1 to 32

Notes

The following elements are part of a choice: ascii-string, mac, or none.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac
Synopsis Use the MAC address for the remote ID
Contextconfigure service ies service-name interface interface-name ipv4 dhcp option-82 remote-id mac
Treemac

Notes

The following elements are part of a choice: ascii-string, mac, or none.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

none
Synopsis Do not include the remote ID
Context configure service ies service-name interface interface-name ipv4 dhcp option-82 remote-id none
Treenone

Notes

The following elements are part of a choice: ascii-string, mac, or none.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

vendor-specific-option
Synopsis Enter the vendor-specific-option context
Contextconfigure service ies service-name interface interface-name ipv4 dhcp option-82 vendor-specific-option
Treevendor-specific-option

Description

Commands in this context configure the Nokia Vendor-Specific Option (VSO) of the DHCP packet.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

proxy-server
Synopsis Enter the proxy-server context
Contextconfigure service ies service-name interface interface-name ipv4 dhcp proxy-server
Treeproxy-server
Introduced25.3.R2

Platforms

7705 SAR Gen 2

emulated-server ipv4-unicast-address
Synopsis IP address used as the DHCP server address for the SAP
Contextconfigure service ies service-name interface interface-name ipv4 dhcp proxy-server emulated-server ipv4-unicast-address
Treeemulated-server

Description

This command configures the IP address which will be used as the DHCP server address in the context of the SAP. Typically, the configured address should be in the context of the subnet represented by the service.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lease-time
Synopsis Enter the lease-time context
Context configure service ies service-name interface interface-name ipv4 dhcp proxy-server lease-time
Treelease-time
Introduced25.3.R2

Platforms

7705 SAR Gen 2

relay-proxy
Synopsis Enable the relay-proxy context
Contextconfigure service ies service-name interface interface-name ipv4 dhcp relay-proxy
Treerelay-proxy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

server ipv4-unicast-address
Synopsis IP addresses for DHCP server requests
Contextconfigure service ies service-name interface interface-name ipv4 dhcp server ipv4-unicast-address
Treeserver

Description

This command configures a list of servers that this interface forwards requests to.

The operator can enter the list of servers as either IP addresses or fully qualified domain names. The operator must specify at least one server specified for DHCP relay to work. If there are multiple servers, the system forwards the request to all the servers in the list.

Max. instances8

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

src-ip-addr keyword
Synopsis Type of source address to use for DHCP relay
Contextconfigure service ies service-name interface interface-name ipv4 dhcp src-ip-addr keyword
Treesrc-ip-addr
Optionsauto, gi-address
Default auto
Introduced25.3.R2

Platforms

7705 SAR Gen 2

trusted boolean
Synopsis Relay untrusted packets
Context configure service ies service-name interface interface-name ipv4 dhcp trusted boolean
Treetrusted

Description

When configured to true, the router enables the trusted mode on the interface. When enabled, the relay agent changes the existing GI address (of the request) to the ingress interface, and forwards the request.

A DHCP request that contains a GI address of 0.0.0.0 and an Option 82 field in the packet is discarded unless it arrives on a trusted circuit.

This behavior only applies if the Relay Agent Information Option action is to keep the existing information. When the Option 82 field is replaced by the relay agent, the original Option 82 information is lost, and there is no reason to enable the trusted option.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

use-arp boolean
Synopsis Use ARP to determine the destination hardware address
Contextconfigure service ies service-name interface interface-name ipv4 dhcp use-arp boolean
Treeuse-arp
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

icmp
Synopsis Enter the icmp context
Context configure service ies service-name interface interface-name ipv4 icmp
Treeicmp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mask-reply boolean
Synopsis Allow responses to ICMP mask requests on the interface
Contextconfigure service ies service-name interface interface-name ipv4 icmp mask-reply boolean
Treemask-reply
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

param-problem
Synopsis Enter the param-problem context
Contextconfigure service ies service-name interface interface-name ipv4 icmp param-problem
Treeparam-problem

Description

Commands in this context specify the settings for ICMP Parameter Problem messages generated by the interface.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

number number
Synopsis Maximum number of Parameter Problem messages to send
Contextconfigure service ies service-name interface interface-name ipv4 icmp param-problem number number
Treenumber
Range10 to 1000
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

seconds number
Synopsis Time used to limit number of Parameter Problem messages
Contextconfigure service ies service-name interface interface-name ipv4 icmp param-problem seconds number
Treeseconds
Range1 to 60
Unitsseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

redirects
Synopsis Enter the redirects context
Context configure service ies service-name interface interface-name ipv4 icmp redirects
Treeredirects

Description

Commands in this context configure the settings for ICMP redirect messages generated by the interface.

The system sends ICMP redirect messages to alert the sending node that a more optimal route is available on another router on the same subnetwork.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

number number
Synopsis Maximum number of ICMP redirect messages to send
Contextconfigure service ies service-name interface interface-name ipv4 icmp redirects number number
Treenumber
Range10 to 1000
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

seconds number
Synopsis Time used to limit the number of ICMP redirect messages
Contextconfigure service ies service-name interface interface-name ipv4 icmp redirects seconds number
Treeseconds
Range1 to 60
Unitsseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ttl-expired
Synopsis Enter the ttl-expired context
Context configure service ies service-name interface interface-name ipv4 icmp ttl-expired
Treettl-expired

Description

Commands in this context configure the settings for ICMP TTL expired messages generated by the interface.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

number number
Synopsis Maximum number of TTL expired messages to send
Contextconfigure service ies service-name interface interface-name ipv4 icmp ttl-expired number number
Treenumber
Range10 to 2000
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

seconds number
Synopsis Time used to limit the number of TTL expired messages
Contextconfigure service ies service-name interface interface-name ipv4 icmp ttl-expired seconds number
Treeseconds
Range1 to 60
Unitsseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

unreachables
Synopsis Enter the unreachables context
Contextconfigure service ies service-name interface interface-name ipv4 icmp unreachables
Treeunreachables

Description

Commands in this context specify the settings for ICMP host and network destination unreachable messages generated by the interface.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

seconds number
Synopsis Time to limit the number of ICMP unreachable messages
Contextconfigure service ies service-name interface interface-name ipv4 icmp unreachables seconds number
Treeseconds
Range1 to 60
Unitsseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

neighbor-discovery
Synopsis Enter the neighbor-discovery context
Contextconfigure service ies service-name interface interface-name ipv4 neighbor-discovery
Treeneighbor-discovery
Introduced25.3.R2

Platforms

7705 SAR Gen 2

host-route
Synopsis Enter the host-route context
Context configure service ies service-name interface interface-name ipv4 neighbor-discovery host-route
Treehost-route
Introduced25.3.R2

Platforms

7705 SAR Gen 2

populate [route-type] keyword
Synopsis Enter the populate list instance
Contextconfigure service ies service-name interface interface-name ipv4 neighbor-discovery host-route populate keyword
Treepopulate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-tag number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTag value used with the host route from an ARP/ND entry
Contextconfigure service ies service-name interface interface-name ipv4 neighbor-discovery host-route populate keyword route-tag number
Treeroute-tag

Description

This command specifies the route tag that is added in the route table for ARP or ND host routes. This tag can be matched on BGP VRF export and BGP peer export policies.

Range1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

learn-unsolicited boolean
Synopsis Learn new entries from any received NA message
Contextconfigure service ies service-name interface interface-name ipv4 neighbor-discovery learn-unsolicited boolean
Treelearn-unsolicited

Description

When configured to true, the router can learn neighbor entries from received unsolicited Neighbor Advertisement (NA) messages, with or without the solicited (S) flag set. The command can be enabled for global addresses, link-local addresses, or for both.

When configured to false, the router follows standard behavior for learning neighbor entries.

  • If an unsolicited NA (regardless of the S flag) is received from a neighbor that is not yet in the Neighbor Discovery (ND) cache, the NA is ignored.

  • If an NS, RS, RA, or Redirect message with a Link Layer Address (MAC) is received from a neighbor that is not yet in the ND cache, a new neighbor entry is created in the cache to store the received Link Layer MAC. The neighbor is put in the STALE state.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

limit
Synopsis Enter the limit context
Context configure service ies service-name interface interface-name ipv4 neighbor-discovery limit
Treelimit
Introduced25.3.R2

Platforms

7705 SAR Gen 2

local-proxy-arp boolean
Synopsis Enable local proxy ARP on interface
Context configure service ies service-name interface interface-name ipv4 neighbor-discovery local-proxy-arp boolean
Treelocal-proxy-arp

Description

When configured to true, the router enables local proxy ARP on the interface.

When configured to false, the router does not respond to ARP requests for addresses on the same subnet.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

proactive-refresh boolean
Synopsis Send a single refresh message before entry timeout
Contextconfigure service ies service-name interface interface-name ipv4 neighbor-discovery proactive-refresh boolean
Treeproactive-refresh

Description

When configured to true, the router always sends a refresh message 30 seconds before the timeout of the entry (a single refresh message with no retries).

When configured to false, the router marks an entry as stale 30 seconds before age-out, and the router only sends an ARP request to refresh the entry if the IOM receives traffic that uses it. Then, the IOM asks the ARP application to send a refresh message. With ARP proactive refresh enabled, the ARP module sends a refresh message regardless of the IOM receiving traffic.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static-neighbor [ipv4-address] ipv4-address
Synopsis Enter the static-neighbor list instance
Contextconfigure service ies service-name interface interface-name ipv4 neighbor-discovery static-neighbor ipv4-address
Treestatic-neighbor
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static-neighbor-unnumbered
Synopsis Enable the static-neighbor-unnumbered context
Contextconfigure service ies service-name interface interface-name ipv4 neighbor-discovery static-neighbor-unnumbered
Treestatic-neighbor-unnumbered
Introduced25.3.R2

Platforms

7705 SAR Gen 2

timeout number
Synopsis Timeout for an ARP entry learned on the interface
Contextconfigure service ies service-name interface interface-name ipv4 neighbor-discovery timeout number
Treetimeout

Description

This command configures the minimum time an ARP entry learned on the IP interface is stored in the ARP table. ARP entries are automatically refreshed when an ARP request or gratuitous ARP is seen by an IP host. Otherwise, the ARP entry is aged from the ARP table.

Range0 to 65535
Unitsseconds
Default 14400
Introduced25.3.R2

Platforms

7705 SAR Gen 2

primary
Synopsis Enable the primary context
Context configure service ies service-name interface interface-name ipv4 primary
Treeprimary
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address ipv4-unicast-address
Synopsis Primary IPv4 address assigned to the interface
Contextconfigure service ies service-name interface interface-name ipv4 primary address ipv4-unicast-address
Treeaddress

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

broadcast keyword
Synopsis Broadcast address format
Context configure service ies service-name interface interface-name ipv4 primary broadcast keyword
Treebroadcast
Optionsall-ones, host-ones
Default host-ones
Introduced25.3.R2

Platforms

7705 SAR Gen 2

secondary [address] ipv4-unicast-address
Synopsis Enter the secondary list instance
Contextconfigure service ies service-name interface interface-name ipv4 secondary ipv4-unicast-address
Treesecondary
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[address] ipv4-unicast-address
Synopsis Secondary IPv4 address assigned to the interface
Contextconfigure service ies service-name interface interface-name ipv4 secondary ipv4-unicast-address
Treesecondary

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

broadcast keyword
Synopsis Broadcast address format
Context configure service ies service-name interface interface-name ipv4 secondary ipv4-unicast-address broadcast keyword
Treebroadcast
Optionsall-ones, host-ones
Default host-ones
Introduced25.3.R2

Platforms

7705 SAR Gen 2

igp-inhibit boolean
Synopsis Disable the running IGP from recognizing secondary IP
Contextconfigure service ies service-name interface interface-name ipv4 secondary ipv4-unicast-address igp-inhibit boolean
Treeigp-inhibit

Description

When configured to true, the running IGP does not recognize the secondary IP address as a local interface.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

tcp-mss number
Synopsis TCP maximum segment size for the interface
Contextconfigure service ies service-name interface interface-name ipv4 tcp-mss number
Treetcp-mss
Range384 to 9746
Introduced25.3.R2

Platforms

7705 SAR Gen 2

unnumbered
Synopsis Enter the unnumbered context
Context configure service ies service-name interface interface-name ipv4 unnumbered
Treeunnumbered
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-address ipv4-unicast-address
Synopsis IP address of the unnumbered interface
Contextconfigure service ies service-name interface interface-name ipv4 unnumbered ip-address ipv4-unicast-address
Treeip-address

Notes

The following elements are part of a choice: ip-address, ip-int-name, or system.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-int-name interface-name
Synopsis IP interface name
Context configure service ies service-name interface interface-name ipv4 unnumbered ip-int-name interface-name
Treeip-int-name
String length1 to 32

Notes

The following elements are part of a choice: ip-address, ip-int-name, or system.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

system
Synopsis IP interface as an unnumbered interface
Contextconfigure service ies service-name interface interface-name ipv4 unnumbered system
Treesystem

Notes

The following elements are part of a choice: ip-address, ip-int-name, or system.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

urpf-check
Synopsis Enable the urpf-check context
Context configure service ies service-name interface interface-name ipv4 urpf-check
Treeurpf-check
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mode keyword
Synopsis Unicast RPF check mode
Context configure service ies service-name interface interface-name ipv4 urpf-check mode keyword
Treemode
Options

strict – Check source address match in RT and interface

loose – Check source address match in RT only

strict-no-ecmp – Check source address match in ECMP route

Defaultstrict
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vrrp [virtual-router-id] number
Synopsis Enter the vrrp list instance
Context configure service ies service-name interface interface-name ipv4 vrrp number
Treevrrp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[virtual-router-id] number
Synopsis Virtual Router Identifier (VRID) for the IP interface
Contextconfigure service ies service-name interface interface-name ipv4 vrrp number
Treevrrp
Range1 to 255

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of VRRP
Context configure service ies service-name interface interface-name ipv4 vrrp number admin-state keyword
Treeadmin-state

Description

The command determines the administrative state of non-owner virtual router instances.

Non-owner virtual router instances can be administratively disabled. This allows the termination of VRRP participation in the virtual router and stops all routing and other access capabilities with regards to the virtual router IP addresses. Disabling the virtual router instance provides a mechanism to maintain the virtual routers without causing false backup or master state changes.

When disabled, no VRRP advertisement messages are generated and all received VRRP advertisement messages are silently discarded with no processing.

Whenever the administrative or operational state of a virtual router instance transitions, a log message is generated.

An owner virtual router context does not use this command. To administratively disable an owner virtual router instance, use the admin-state command within the parent IP interface node which administratively disables the IP interface.

Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

authentication-key encrypted-leaf
Synopsis Password for simple text authentication
Contextconfigure service ies service-name interface interface-name ipv4 vrrp number authentication-key encrypted-leaf
Treeauthentication-key

Description

This command optionally assigns a simple text password authentication key to generate master VRRP advertisement messages and validate received VRRP advertisement messages.

If this command is re-executed with a different password key defined, the new key immediately replaces the old key. This command may be executed at any time. 

String length1 to 38
Introduced25.3.R2

Platforms

7705 SAR Gen 2

backup ipv4-unicast-address
Synopsis Virtual router IP addresses for the interface
Contextconfigure service ies service-name interface interface-name ipv4 vrrp number backup ipv4-unicast-address
Treebackup

Description

This command associates virtual router IP addresses with those of the parental IP interface.

This command has two different functions based on whether it is being executed on an owner or non-owner virtual router instance.

Non-owner virtual router instances create a routable IP interface address that is operationally dependent on the virtual router instance mode (master or backup). This command, when executed on an owner virtual router instance, does not create a routable IP interface address; it simply defines the existing IP addresses of the parental IP interface that are advertised by the virtual router instance.

For owner virtual router instances, this command defines the IP addresses that are advertised within VRRP advertisement messages. This communicates the IP addresses that the master is advertising to backup virtual routers receiving the messages. The specified unicast-ipv4-address must be equal to one of the existing IP addresses in the parental IP interface (primary or secondary) or this command fails.

See "Owner and non-owner VRRP" in the 7705 SAR Gen 2 Router Configuration Guide for more information about owner and non-owner virtual router instances.

Max. instances16
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd-liveness
Synopsis Enable the bfd-liveness context
Contextconfigure service ies service-name interface interface-name ipv4 vrrp number bfd-liveness
Treebfd-liveness
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dest-ip ipv4-address
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDestination IP address to use for BFD session
Contextconfigure service ies service-name interface interface-name ipv4 vrrp number bfd-liveness dest-ip ipv4-address
Treedest-ip

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface-name interface-name
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisName of the interface running BFD
Contextconfigure service ies service-name interface interface-name ipv4 vrrp number bfd-liveness interface-name interface-name
Treeinterface-name
String length1 to 32

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

service-name service-name
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisAdministrative service name
Contextconfigure service ies service-name interface interface-name ipv4 vrrp number bfd-liveness service-name service-name
Treeservice-name
String length1 to 64
Introduced25.3.R2

Platforms

7705 SAR Gen 2

init-delay number
Synopsis VRRP initialization delay timer
Context configure service ies service-name interface interface-name ipv4 vrrp number init-delay number
Treeinit-delay
Range1 to 65535
Unitsseconds
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

mac mac-unicast-address
Synopsis Virtual MAC address to use in ARP responses
Contextconfigure service ies service-name interface interface-name ipv4 vrrp number mac mac-unicast-address
Treemac

Description

This command sets an explicit MAC address for the virtual router instance that overrides the VRRP default derived from the VRID.

Changing the default MAC address is useful when an existing HSRP or other non-VRRP default MAC is in use by the IP hosts that use the virtual router IP address. Many hosts do not monitor unessential ARPs and continue to use the cached non-VRRP MAC address after the virtual router becomes master of the host’s gateway address.

Additionally, this command sets the MAC address used in ARP responses when the virtual router instance is master. Routing of IP packets with unicast-mac-address as the destination MAC is also enabled. The MAC must be the same for all virtual routers participating as a virtual router or indeterminate connectivity by the attached IP hosts results. All VRRP advertisement messages are transmitted with unicast-mac-address as the source MAC.

An operator can execute this command at any time and it takes effect immediately. When the virtual router MAC on a master virtual router instance changes, a gratuitous ARP is immediately sent with a VRRP advertisement message. If the virtual router instance is disabled or operating as a backup, the gratuitous ARP and VRRP advertisement messages are not sent.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

master-int-inherit boolean
Synopsis Allow master instance to dictate the master down timer
Contextconfigure service ies service-name interface interface-name ipv4 vrrp number master-int-inherit boolean
Treemaster-int-inherit

Description

When configured to true, the virtual router instance inherits the advertisement interval timer of the master VRRP router, which backup routers use to calculate the master down timer.

When configured to false, the locally configured message interval must match the master's VRRP advertisement message advertisement interval field value or the message is discarded.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

message-interval number
Synopsis Interval for sending VRRP advertisement messages
Contextconfigure service ies service-name interface interface-name ipv4 vrrp number message-interval number
Treemessage-interval

Description

This command configures the administrative advertisement message timer used by the master virtual router instance to send VRRP advertisement messages. The backup master down timer is derived from the value configured using this command.

The usage of this command varies for non-owner virtual router instances, depending on the state of the virtual router (master or backup) and the state of the master-int-inherit command:

  • When a non-owner is operating as master for the virtual router, the system uses the configured value of this command as the operational advertisement timer, similar to an owner virtual router instance. The master-int-inherit command has no effect when operating as master.

  • When a non-owner is in the backup state with master-int-inherit disabled, the system uses the configured value of this command to match the incoming advertisement interval field of the VRRP advertisement message. If the locally configured message interval does not match the advertisement interval field, the system discards the VRRP advertisement.

  • When a non-owner is in the backup state with master-int-inherit enabled, the configured value of this command is ignored. The master down timer is indirectly derived from the advertisement interval field value of the incoming VRRP advertisement message.

Range1 to 2559
Unitsdeciseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

monitor-oper-group reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVRRP instance to follow a specified operational group
Contextconfigure service ies service-name interface interface-name ipv4 vrrp number monitor-oper-group reference
Treemonitor-oper-group

Description

This command configures VRRP to associate with an operational group. When associated, VRRP notifies the operational group of its state changes so that other protocols can monitor it to provide a redundancy mechanism. When VRRP is the master router, the operational group is up and the operational group is down for all other VRRP states.

Reference

configure service oper-group named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ntp-reply boolean
Synopsis Allow processing of NTP requests
Context configure service ies service-name interface interface-name ipv4 vrrp number ntp-reply boolean
Treentp-reply

Description

When configured to true, the router redirects NTP requests to the VRRP virtual IP address. This behavior only applies to the router acting as the master VRRP router.

When configured to false, the router does not process NTP requests.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

oper-group reference
Synopsis Operational group name associated with the VRRP
Contextconfigure service ies service-name interface interface-name ipv4 vrrp number oper-group reference
Treeoper-group

Description

This command configures an operational group to associate with the VRRP. When associated, VRRP notifies the operational group of its state changes so that other protocols can monitor it to provide a redundancy mechanism. When VRRP is the master router (MR), the operational group is up. The operational group is down for all other VRRP states.

Reference

configure service oper-group named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

owner boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDesignate the virtual router instance as owner
Contextconfigure service ies service-name interface interface-name ipv4 vrrp number owner boolean
Treeowner

Description

When configured to true, the router designates this virtual router instance as the owner of the virtual router IP addresses. Therefore, this virtual router becomes responsible for forwarding packets sent to the virtual router IP addresses. The owner also assumes the role of master virtual router.

When configured to false, this virtual router instance is designated as a non-owner.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

passive boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSuppress the processing of VRRP advertisement messages
Contextconfigure service ies service-name interface interface-name ipv4 vrrp number passive boolean
Treepassive

Description

When configured to true, the router identifies this virtual router instance as passive; and therefore the owner of the virtual router IP addresses. A passive virtual router instance does not transmit or receive VRRP advertisement messages and is always in either the master state (if the interface is operationally up) or the init state (if the interface is operationally down).

When configured to false, this virtual router instance is not identified as passive, meaning that it transmits and receives VRRP advertisement messages. 

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ping-reply boolean
Synopsis Allow non-owner master to reply to ICMP echo requests
Contextconfigure service ies service-name interface interface-name ipv4 vrrp number ping-reply boolean
Treeping-reply

Description

When configured to true, the router allows the non-owner master to reply to ICMP echo requests directed at the IP addresses of the virtual router instance. Any routed interface can receive the ping request. Ping must not have been disabled at the management security level (either on the parental IP interface or on the Ping source host address).

When configured to false, ICMP echo requests sent to non-owner master virtual IP addresses are silently discarded.

Non-owner backup virtual routers never respond to ICMP echo requests, regardless of the configuration of this command.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy reference
Synopsis VRRP priority control policy
Context configure service ies service-name interface interface-name ipv4 vrrp number policy reference
Treepolicy

Description

This command configures a VRRP priority control policy to associate with the virtual router instance.

VRRP priority control policies can override or adjust the base priority value of the virtual router instance, depending on events or conditions within the chassis.

An operator can associate a policy with more than one virtual router instance. The priority events within the policy either override or diminish the base priority set with the priority command. As priority events clear in the policy, the in-use priority can eventually be restored to the base priority value.

For non-owner virtual router instances, if this command is not executed, the base priority is used as the in-use priority.

Reference

configure vrrp policy number

Introduced25.3.R2

Platforms

7705 SAR Gen 2

preempt boolean
Synopsis Allow the VRRP to override an existing non-owner master
Contextconfigure service ies service-name interface interface-name ipv4 vrrp number preempt boolean
Treepreempt

Description

When configured to true, this virtual router instance overrides any non-owner master with an in-use message priority value less than the in-use priority value of this virtual router.

When configured to false, this virtual router only becomes master if the master down timer expires before a VRRP advertisement message is received from another virtual router.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority number
Synopsis Base priority for the VRRP
Context configure service ies service-name interface interface-name ipv4 vrrp number priority number
Treepriority

Description

This command configures the base router priority for the virtual router instance, which defines the selection order of the virtual router in the master election process.

The in-use priority is derived from the base priority. However, the in-use priority is modified by optional VRRP priority control policies. An operator can use VRRP priority control policies to either override or adjust the base priority value depending on events or conditions within the chassis.

Range1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ssh-reply boolean
Synopsis Allow the non-owner master to reply to SSH requests
Contextconfigure service ies service-name interface interface-name ipv4 vrrp number ssh-reply boolean
Treessh-reply

Description

When configured to true, the router allows the non-owner master to reply to SSH requests directed at the IP addresses of the virtual router instance. Any routed interface can receive the SSH request. SSH cannot be disabled at the management security level (either on the parental IP interface or on the SSH source host address).

When configure to false, SSH requests to non-owner master virtual IP addresses are silently discarded.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

standby-forwarding boolean
Synopsis Allow standby router to forward traffic
Contextconfigure service ies service-name interface interface-name ipv4 vrrp number standby-forwarding boolean
Treestandby-forwarding

Description

When configured to true, the standby router forwards all traffic.

When configured to false, the standby router cannot forward traffic sent to the MAC address of the virtual router. However, the standby router still forwards traffic sent to its own MAC address.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

telnet-reply boolean
Synopsis Allow non-owner master to reply to Telnet requests
Contextconfigure service ies service-name interface interface-name ipv4 vrrp number telnet-reply boolean
Treetelnet-reply

Description

When configured to true, the router allows the non-owner master to reply to Telnet requests directed at the IP addresses of the virtual router instance. Any routed interface can receive Telnet requests. Telnet cannot be disabled at the management security level (either on the parental IP interface or on the Telnet source host address).

When configured to false, the router silently discards Telnet requests sent to non-owner master virtual IP addresses.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

traceroute-reply boolean
Synopsis Allow non-owner master to reply to traceroute requests
Contextconfigure service ies service-name interface interface-name ipv4 vrrp number traceroute-reply boolean
Treetraceroute-reply

Description

When configured to true, the router allows a non-owner master to reply to traceroute requests directed to the IP addresses of the virtual router instance.

When configured to false, the router silently discards traceroute requests sent to non-owner master virtual IP addresses.

Traceroute must not have been disabled at the management security level (either on the parental IP interface or the source host address).

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6
Synopsis Enable the ipv6 context
Context configure service ies service-name interface interface-name ipv6
Treeipv6
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address [ipv6-address] ipv6-address
Synopsis Enter the address list instance
Contextconfigure service ies service-name interface interface-name ipv6 address ipv6-address
Treeaddress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ipv6-address] ipv6-address
Synopsis IPv6 address assigned to the interface
Contextconfigure service ies service-name interface interface-name ipv6 address ipv6-address
Treeaddress

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

duplicate-address-detection boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEnable Duplicate Address Detection
Contextconfigure service ies service-name interface interface-name ipv6 address ipv6-address duplicate-address-detection boolean
Treeduplicate-address-detection

Description

When configured to true, the router enables Duplicate Address Detection (DAD).

When configured to false, the router disables DAD and sets the address to preferred, even if there is a duplicated address.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

eui-64 boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisForm IPv6 address from prefix and 64-bit interface ID
Contextconfigure service ies service-name interface interface-name ipv6 address ipv6-address eui-64 boolean
Treeeui-64

Description

When configured to true, the router forms a complete IPv6 address from the supplied prefix and 64-bit interface identifier. The 64-bit interface identifier is derived from the MAC address on Ethernet interfaces. For interfaces without a MAC address, for example POS interfaces, use the base MAC address of the chassis.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

primary-preference number
Synopsis Index assigned to the IPv6 address of the interface
Contextconfigure service ies service-name interface interface-name ipv6 address ipv6-address primary-preference number
Treeprimary-preference

Description

This command assigns a primary preference index to an IPv6 address of the interface to enforce the order in which the address is used by control plane protocols and applications that require a fixed address of the interface, such as LDP and Segment Routing. In cases where a fixed address is required when originating packets from the interface, the IPv6 address with the lowest primary preference index is selected. If the selected address is removed, the next IPv6 address with the next lowest primary preference index is selected.

If this index is not specified for the IPv6 address, the system assigns the next available index value to the address. The address index space is unique across all addresses of a given interface.

Range1 to 4294967295
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd
Synopsis Enter the bfd context
Context configure service ies service-name interface interface-name ipv6 bfd
Treebfd
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of BFD sessions
Context configure service ies service-name interface interface-name ipv6 bfd admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

echo-receive number
Synopsis Minimum echo interval over this interface
Contextconfigure service ies service-name interface interface-name ipv6 bfd echo-receive number
Treeecho-receive
Range100 to 100000
Unitsmilliseconds
Introduced25.3.R2

Platforms

7705 SAR Gen 2

multiplier number
Synopsis Number of consecutive BFD messages missed from the peer
Contextconfigure service ies service-name interface interface-name ipv6 bfd multiplier number
Treemultiplier

Description

This command configures the number of missed messages before the BFD session state is changed to down and the upper-level protocol is notified of the fault. A multiplier of less than 3 should not be used in production environments. 

Range1 to 20
Default3
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

receive number
Synopsis BFD receive interval over this interface
Contextconfigure service ies service-name interface interface-name ipv6 bfd receive number
Treereceive

Description

This command specifies the receive interval for the BFD session.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

transmit-interval number
Synopsis BFD transmit interval over this interface
Contextconfigure service ies service-name interface interface-name ipv6 bfd transmit-interval number
Treetransmit-interval

Description

This command configures the transmit intervals.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

dhcp6
Synopsis Enter the dhcp6 context
Context configure service ies service-name interface interface-name ipv6 dhcp6
Treedhcp6
Introduced25.3.R2

Platforms

7705 SAR Gen 2

relay
Synopsis Enter the relay context
Context configure service ies service-name interface interface-name ipv6 dhcp6 relay
Treerelay
Introduced25.3.R2

Platforms

7705 SAR Gen 2

lease-populate
Synopsis Enter the lease-populate context
Contextconfigure service ies service-name interface interface-name ipv6 dhcp6 relay lease-populate
Treelease-populate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-populate
Synopsis Enter the route-populate context
Contextconfigure service ies service-name interface interface-name ipv6 dhcp6 relay lease-populate route-populate
Treeroute-populate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

pd
Synopsis Enable the pd context
Context configure service ies service-name interface interface-name ipv6 dhcp6 relay lease-populate route-populate pd
Treepd
Introduced25.3.R2

Platforms

7705 SAR Gen 2

option
Synopsis Enter the option context
Context configure service ies service-name interface interface-name ipv6 dhcp6 relay option
Treeoption
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface-id
Synopsis Enter the interface-id context
Contextconfigure service ies service-name interface interface-name ipv6 dhcp6 relay option interface-id
Treeinterface-id
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sap-id
Synopsis Use SAP ID in interface ID option in relay packet
Contextconfigure service ies service-name interface interface-name ipv6 dhcp6 relay option interface-id sap-id
Treesap-id

Notes

The following elements are part of a choice: ascii-tuple, if-index, sap-id, or string.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

string string-not-all-spaces
Synopsis String for interface ID option in DHCPv6 relay packet
Contextconfigure service ies service-name interface interface-name ipv6 dhcp6 relay option interface-id string string-not-all-spaces
Treestring
String length1 to 80

Notes

The following elements are part of a choice: ascii-tuple, if-index, sap-id, or string.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

server ipv6-address-with-zone
Synopsis DHCPv6 server to which the DHCPv6 requests are forwarded
Contextconfigure service ies service-name interface interface-name ipv6 dhcp6 relay server ipv6-address-with-zone
Treeserver
Max. instances8

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

icmp6
Synopsis Enter the icmp6 context
Context configure service ies service-name interface interface-name ipv6 icmp6
Treeicmp6
Introduced25.3.R2

Platforms

7705 SAR Gen 2

packet-too-big
Synopsis Enter the packet-too-big context
Contextconfigure service ies service-name interface interface-name ipv6 icmp6 packet-too-big
Treepacket-too-big

Description

Commands in this context configure limiting the number of ICMPv6 Packet Too Big messages.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

param-problem
Synopsis Enter the param-problem context
Contextconfigure service ies service-name interface interface-name ipv6 icmp6 param-problem
Treeparam-problem
Introduced25.3.R2

Platforms

7705 SAR Gen 2

redirects
Synopsis Enter the redirects context
Context configure service ies service-name interface interface-name ipv6 icmp6 redirects
Treeredirects
Introduced25.3.R2

Platforms

7705 SAR Gen 2

number number
Synopsis Number to limit ICMPv6 Redirect messages per time frame
Contextconfigure service ies service-name interface interface-name ipv6 icmp6 redirects number number
Treenumber
Range10 to 1000
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

time-exceeded
Synopsis Enter the time-exceeded context
Contextconfigure service ies service-name interface interface-name ipv6 icmp6 time-exceeded
Treetime-exceeded
Introduced25.3.R2

Platforms

7705 SAR Gen 2

unreachables
Synopsis Enter the unreachables context
Contextconfigure service ies service-name interface interface-name ipv6 icmp6 unreachables
Treeunreachables
Introduced25.3.R2

Platforms

7705 SAR Gen 2

number number
Synopsis Number to limit Unreachable messages per time frame
Contextconfigure service ies service-name interface interface-name ipv6 icmp6 unreachables number number
Treenumber
Range10 to 2000
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

link-local-address
Synopsis Enter the link-local-address context
Contextconfigure service ies service-name interface interface-name ipv6 link-local-address
Treelink-local-address
Introduced25.3.R2

Platforms

7705 SAR Gen 2

duplicate-address-detection boolean
Synopsis Enable Duplicate Address Detection
Context configure service ies service-name interface interface-name ipv6 link-local-address duplicate-address-detection boolean
Treeduplicate-address-detection

Description

When configured to true, the router enables Duplicate Address Detection (DAD) on the interface.

When configured to false, the router disables DAD and sets the address to preferred, even if there is a duplicated address.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

neighbor-discovery
Synopsis Enter the neighbor-discovery context
Contextconfigure service ies service-name interface interface-name ipv6 neighbor-discovery
Treeneighbor-discovery
Introduced25.3.R2

Platforms

7705 SAR Gen 2

host-route
Synopsis Enter the host-route context
Context configure service ies service-name interface interface-name ipv6 neighbor-discovery host-route
Treehost-route
Introduced25.3.R2

Platforms

7705 SAR Gen 2

populate [route-type] keyword
Synopsis Enter the populate list instance
Contextconfigure service ies service-name interface interface-name ipv6 neighbor-discovery host-route populate keyword
Treepopulate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-tag number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTag value used with the host route from an ARP/ND entry
Contextconfigure service ies service-name interface interface-name ipv6 neighbor-discovery host-route populate keyword route-tag number
Treeroute-tag

Description

This command specifies the route tag that is added in the route table for ARP or ND host routes. This tag can be matched on BGP VRF export and BGP peer export policies.

Range1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

learn-unsolicited keyword
Synopsis Type of entries learned from unsolicited NA messages
Contextconfigure service ies service-name interface interface-name ipv6 neighbor-discovery learn-unsolicited keyword
Treelearn-unsolicited

Description

This command enables the ability to learn neighbor entries out of received unsolicited Neighbor Advertisement (NA) messages, with or without the solicited flag set.

When unconfigured, the router follows standard RFC 4861 behavior for learning of neighbor entries. The neighbor is put in the stale state. This is the standard RFC behavior.

Optionsglobal, link-local, both
Introduced25.3.R2

Platforms

7705 SAR Gen 2

limit
Synopsis Enter the limit context
Context configure service ies service-name interface interface-name ipv6 neighbor-discovery limit
Treelimit
Introduced25.3.R2

Platforms

7705 SAR Gen 2

log-only boolean
Synopsis Generate log entries when limit is reached
Contextconfigure service ies service-name interface interface-name ipv6 neighbor-discovery limit log-only boolean
Treelog-only

Description

When configured to true, the router sends the warning message at the specified threshold percentage or upon exceeding the specified limit. Entries that exceed the limit are learned.

When configured to false, the router does not send the warning message.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

max-entries number
Synopsis Maximum number of entries learned on an IP interface
Contextconfigure service ies service-name interface interface-name ipv6 neighbor-discovery limit max-entries number
Treemax-entries

Description

This command configures the maximum number of entries that can be learned on an IP interface.

When unconfigured, no maximum limit is imposed.

Range0 to 102400
Introduced25.3.R2

Platforms

7705 SAR Gen 2

local-proxy-nd boolean
Synopsis Enable local proxy neighbor discovery on the interface
Contextconfigure service ies service-name interface interface-name ipv6 neighbor-discovery local-proxy-nd boolean
Treelocal-proxy-nd

Description

When configured to true, the router enables local proxy neighbor discovery on the interface and replies to neighbor solicitation requests when both the hosts are on the same subnet. In this case, ICMP redirects are disabled.

When configured to false, the router disables local proxy neighbor discovery on the interface and does not reply to neighbor solicitation requests if both the hosts are on the same subnet.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

proactive-refresh keyword
Synopsis Proactive refresh of neighbor entries
Contextconfigure service ies service-name interface interface-name ipv6 neighbor-discovery proactive-refresh keyword
Treeproactive-refresh

Description

This command enables a proactive refresh of the neighbor entries. After the stale timer expires, the router sends an NUD message to the host (regardless of the existence of traffic to the IP address on the IOM), so the entry can be refreshed or removed.

Optionsglobal, link-local, both
Introduced25.3.R2

Platforms

7705 SAR Gen 2

secure-nd
Synopsis Enter the secure-nd context
Context configure service ies service-name interface interface-name ipv6 neighbor-discovery secure-nd
Treesecure-nd
Introduced25.3.R2

Platforms

7705 SAR Gen 2

allow-unsecured-msgs boolean
Synopsis Accept unsecured messages
Context configure service ies service-name interface interface-name ipv6 neighbor-discovery secure-nd allow-unsecured-msgs boolean
Treeallow-unsecured-msgs

Description

When configured to true, the router accepts unsecured messages. When Secure Neighbor Discovery (SeND) is enabled, only secure messages are accepted.

When configured to false, the router disables the acceptance of unsecured messages.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static-neighbor [ipv6-address] ipv6-address
Synopsis Enter the static-neighbor list instance
Contextconfigure service ies service-name interface interface-name ipv6 neighbor-discovery static-neighbor ipv6-address
Treestatic-neighbor
Introduced25.3.R2

Platforms

7705 SAR Gen 2

tcp-mss number
Synopsis TCP maximum segment size for the interface
Contextconfigure service ies service-name interface interface-name ipv6 tcp-mss number
Treetcp-mss
Range1220 to 9726
Introduced25.3.R2

Platforms

7705 SAR Gen 2

urpf-check
Synopsis Enable the urpf-check context
Context configure service ies service-name interface interface-name ipv6 urpf-check
Treeurpf-check
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mode keyword
Synopsis Unicast RPF check mode
Context configure service ies service-name interface interface-name ipv6 urpf-check mode keyword
Treemode
Options

strict – Check source address match in RT and interface

loose – Check source address match in RT only

strict-no-ecmp – Check source address match in ECMP route

Defaultstrict
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vrrp [virtual-router-id] number
Synopsis Enter the vrrp list instance
Context configure service ies service-name interface interface-name ipv6 vrrp number
Treevrrp
Max. instances4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[virtual-router-id] number
Synopsis Virtual Router Identifier (VRID) for the IP interface
Contextconfigure service ies service-name interface interface-name ipv6 vrrp number
Treevrrp
Range1 to 255

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of VRRP
Context configure service ies service-name interface interface-name ipv6 vrrp number admin-state keyword
Treeadmin-state

Description

The command determines the administrative state of non-owner virtual router instances.

Non-owner virtual router instances can be administratively disabled. This allows the termination of VRRP participation in the virtual router and stops all routing and other access capabilities with regards to the virtual router IP addresses. Disabling the virtual router instance provides a mechanism to maintain the virtual routers without causing false backup or master state changes.

When disabled, no VRRP advertisement messages are generated and all received VRRP advertisement messages are silently discarded with no processing.

Whenever the administrative or operational state of a virtual router instance transitions, a log message is generated.

An owner virtual router context does not use this command. To administratively disable an owner virtual router instance, use the admin-state command within the parent IP interface node which administratively disables the IP interface.

Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

backup ipv6-address
Synopsis Virtual router IP addresses for the interface
Contextconfigure service ies service-name interface interface-name ipv6 vrrp number backup ipv6-address
Treebackup

Description

This command associates router IPv6 virtual router IP addresses with those of the parental IP interface.

This command has two different functions based on whether it is being executed on an owner or non-owner virtual router instance.

Non-owner virtual router instance create a routable IP interface address that is operationally dependent on the virtual router instance mode (master or backup). This command, when executed on an owner virtual router instance, does not create a routable IP interface address; it simply defines the existing IP addresses of the parental IP interface that are advertised by the virtual router instance.

For owner virtual router instances, this command defines the IP addresses that are advertised within VRRP advertisement messages. This communicates the IP addresses that the master is representing to backup virtual routers receiving the messages. The specified IPv6 address must be equal to one of the existing parental IP addresses in the parental IP interface (primary or secondary) or this command fails.

See "Owner and non-owner VRRP" in the 7705 SAR Gen 2 Router Configuration Guide for more information about owner and non-owner virtual router instances.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd-liveness
Synopsis Enable the bfd-liveness context
Contextconfigure service ies service-name interface interface-name ipv6 vrrp number bfd-liveness
Treebfd-liveness
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dest-ip (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDestination address for the BFD session
Contextconfigure service ies service-name interface interface-name ipv6 vrrp number bfd-liveness dest-ip (ipv4-address-no-zone | ipv6-address-no-zone)
Treedest-ip

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface-name interface-name
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisName of the interface running BFD
Contextconfigure service ies service-name interface interface-name ipv6 vrrp number bfd-liveness interface-name interface-name
Treeinterface-name
String length1 to 32

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

service-name service-name
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisAdministrative service name
Contextconfigure service ies service-name interface interface-name ipv6 vrrp number bfd-liveness service-name service-name
Treeservice-name
String length1 to 64
Introduced25.3.R2

Platforms

7705 SAR Gen 2

init-delay number
Synopsis VRRP initialization delay timer
Context configure service ies service-name interface interface-name ipv6 vrrp number init-delay number
Treeinit-delay
Range1 to 65535
Unitsseconds
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

mac mac-unicast-address
Synopsis Virtual MAC address to use in ARP responses
Contextconfigure service ies service-name interface interface-name ipv6 vrrp number mac mac-unicast-address
Treemac

Description

This command sets an explicit MAC address for the virtual router instance that overrides the VRRP default derived from the VRID.

Changing the default MAC address is useful when an existing HSRP or other non-VRRP default MAC is in use by the IP hosts that use the virtual router IP address. Many hosts do not monitor unessential ARPs and continue to use the cached non-VRRP MAC address after the virtual router becomes master of the host’s gateway address.

Additionally, this command sets the MAC address used in ARP responses when the virtual router instance is master. Routing of IP packets with unicast-mac-address as the destination MAC is also enabled. The MAC must be the same for all virtual routers participating as a virtual router or indeterminate connectivity by the attached IP hosts results. All VRRP advertisement messages are transmitted with unicast-mac-address as the source MAC.

An operator can execute this command at any time and it takes effect immediately. When the virtual router MAC on a master virtual router instance changes, a gratuitous ARP is immediately sent with a VRRP advertisement message. If the virtual router instance is disabled or operating as a backup, the gratuitous ARP and VRRP advertisement messages are not sent.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

master-int-inherit boolean
Synopsis Allow master instance to dictate the master down timer
Contextconfigure service ies service-name interface interface-name ipv6 vrrp number master-int-inherit boolean
Treemaster-int-inherit

Description

When configured to true, the virtual router instance inherits the advertisement interval timer of the master VRRP router, which backup routers use to calculate the master down timer.

When configured to false, the locally configured message interval must match the master's VRRP advertisement message advertisement interval field value or the message is discarded.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

message-interval number
Synopsis Interval for sending VRRP advertisement messages
Contextconfigure service ies service-name interface interface-name ipv6 vrrp number message-interval number
Treemessage-interval

Description

This command configures the administrative advertisement message timer used by the master virtual router instance to send VRRP advertisement messages. The backup master down timer is derived from the value configured using this command.

The use of this command varies for non-owner virtual router instances, depending on the state of the virtual router (master or backup) and the state of the master-int-inherit command:

  • When a non-owner is operating as master for the virtual router, the system uses the configured value of this command as the operational advertisement timer, similar to an owner virtual router instance. The master-int-inherit command has no effect when operating as the master.

  • When a non-owner is in the backup state with master-int-inherit disabled, the system uses the configured value of this command to match the incoming advertisement interval field of the VRRP advertisement message. If the locally configured message interval does not match the advertisement interval field, the system discards the VRRP advertisement.

  • When a non-owner is in the backup state with master-int-inherit enabled, the configured value of this command is ignored. The master down timer is indirectly derived from the advertisement interval field value of the incoming VRRP advertisement message.

Range10 to 4095
Unitscentiseconds
Default 100
Introduced25.3.R2

Platforms

7705 SAR Gen 2

monitor-oper-group reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVRRP instance to follow a specified operational group
Contextconfigure service ies service-name interface interface-name ipv6 vrrp number monitor-oper-group reference
Treemonitor-oper-group

Description

This command configures VRRP to associate with an operational group. When associated, VRRP notifies the operational group of its state changes so that other protocols can monitor it to provide a redundancy mechanism. When VRRP is the master router, the operational group is up and the operational group is down for all other VRRP states.

Reference

configure service oper-group named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ntp-reply boolean
Synopsis Allow processing of NTP requests
Context configure service ies service-name interface interface-name ipv6 vrrp number ntp-reply boolean
Treentp-reply

Description

When configured to true, the router redirects NTP requests to the VRRP virtual IP address. This behavior only applies to the router acting as the master VRRP router.

When configured to false, the router does not process NTP requests.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

oper-group reference
Synopsis Operational group name associated with the VRRP
Contextconfigure service ies service-name interface interface-name ipv6 vrrp number oper-group reference
Treeoper-group

Description

This command configures an operational group to associate with the VRRP. When associated, VRRP notifies the operational group of its state changes so that other protocols can monitor it to provide a redundancy mechanism. When VRRP is the master router (MR), the operational group is up. The operational group is down for all other VRRP states.

Reference

configure service oper-group named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

owner boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDesignate the virtual router instance as owner
Contextconfigure service ies service-name interface interface-name ipv6 vrrp number owner boolean
Treeowner

Description

When configured to true, the router designates this virtual router instance as the owner of the virtual router IP addresses. Therefore, this virtual router becomes responsible for forwarding packets sent to the virtual router IP addresses. The owner also assumes the role of master virtual router.

When configured to false, this virtual router instance is designated as a non-owner.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

passive boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSuppress the processing of VRRP advertisement messages
Contextconfigure service ies service-name interface interface-name ipv6 vrrp number passive boolean
Treepassive

Description

When configured to true, the router identifies this virtual router instance as passive; and therefore the owner of the virtual router IP addresses. A passive virtual router instance does not transmit or receive VRRP advertisement messages and is always in either the master state (if the interface is operationally up) or the init state (if the interface is operationally down).

When configured to false, this virtual router instance is not identified as passive, meaning that it transmits and receives VRRP advertisement messages. 

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ping-reply boolean
Synopsis Allow non-owner master to reply to ICMP echo requests
Contextconfigure service ies service-name interface interface-name ipv6 vrrp number ping-reply boolean
Treeping-reply

Description

When configured to true, the router allows the non-owner master to reply to ICMP echo requests directed at the IP addresses of the virtual router instance. Any routed interface can receive the ping request. Ping must not have been disabled at the management security level (either on the parental IP interface or on the Ping source host address).

When configured to false, ICMP echo requests sent to non-owner master virtual IP addresses are silently discarded.

Non-owner backup virtual routers never respond to ICMP echo requests, regardless of the configuration of this command.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy reference
Synopsis VRRP priority control policy
Context configure service ies service-name interface interface-name ipv6 vrrp number policy reference
Treepolicy

Description

This command configures a VRRP priority control policy to associate with the virtual router instance.

VRRP priority control policies can override or adjust the base priority value of the virtual router instance, depending on events or conditions within the chassis.

An operator can associate a policy with more than one virtual router instance. The priority events within the policy either override or diminish the base priority set with the priority command. As priority events clear in the policy, the in-use priority can eventually be restored to the base priority value.

For non-owner virtual router instances, if this command is not executed, the base priority is used as the in-use priority.

Reference

configure vrrp policy number

Introduced25.3.R2

Platforms

7705 SAR Gen 2

preempt boolean
Synopsis Allow the VRRP to override an existing non-owner master
Contextconfigure service ies service-name interface interface-name ipv6 vrrp number preempt boolean
Treepreempt

Description

When configured to true, this virtual router instance overrides any non-owner master with an in-use message priority value less than the in-use priority value of this virtual router.

When configured to false, this virtual router only becomes master if the master down timer expires before a VRRP advertisement message is received from another virtual router.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority number
Synopsis Base priority for the VRRP
Context configure service ies service-name interface interface-name ipv6 vrrp number priority number
Treepriority

Description

This command configures the base router priority for the virtual router instance, which defines the selection order of the virtual router in the master election process.

The in-use priority is derived from the base priority. However, the in-use priority is modified by optional VRRP priority control policies. An operator can use VRRP priority control policies to either override or adjust the base priority value depending on events or conditions within the chassis.

Range1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

standby-forwarding boolean
Synopsis Allow standby router to forward traffic
Contextconfigure service ies service-name interface interface-name ipv6 vrrp number standby-forwarding boolean
Treestandby-forwarding

Description

When configured to true, the standby router forwards all traffic.

When configured to false, the standby router cannot forward traffic sent to the MAC address of the virtual router. However, the standby router still forwards traffic sent to its own MAC address.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

telnet-reply boolean
Synopsis Allow non-owner master to reply to Telnet requests
Contextconfigure service ies service-name interface interface-name ipv6 vrrp number telnet-reply boolean
Treetelnet-reply

Description

When configured to true, the router allows the non-owner master to reply to Telnet requests directed at the IP addresses of the virtual router instance. Any routed interface can receive Telnet requests. Telnet cannot be disabled at the management security level (either on the parental IP interface or on the Telnet source host address).

When configured to false, the router silently discards Telnet requests sent to non-owner master virtual IP addresses.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

traceroute-reply boolean
Synopsis Allow non-owner master to reply to traceroute requests
Contextconfigure service ies service-name interface interface-name ipv6 vrrp number traceroute-reply boolean
Treetraceroute-reply

Description

When configured to true, the router allows a non-owner master to reply to traceroute requests directed to the IP addresses of the virtual router instance.

When configured to false, the router silently discards traceroute requests sent to non-owner master virtual IP addresses.

Traceroute must not have been disabled at the management security level (either on the parental IP interface or the source host address).

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

load-balancing
Synopsis Enter the load-balancing context
Contextconfigure service ies service-name interface interface-name load-balancing
Treeload-balancing
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-load-balancing keyword
Synopsis IP load-balancing algorithm
Context configure service ies service-name interface interface-name load-balancing ip-load-balancing keyword
Treeip-load-balancing

Description

This command specifies whether to include the source address, destination address, or both in LAG or ECMP hash on IP interfaces. Additionally, when the l4-load-balancing command is enabled, this command also includes the source or destination port in the hash inputs.

Optionsboth, destination, source, inner-ip
Default both
Introduced25.3.R2

Platforms

7705 SAR Gen 2

loopback boolean
Synopsis Use interface as a loopback interface
Contextconfigure service ies service-name interface interface-name loopback boolean
Treeloopback
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac mac-unicast-address
Synopsis MAC address for the interface
Context configure service ies service-name interface interface-name mac mac-unicast-address
Treemac
Introduced25.3.R2

Platforms

7705 SAR Gen 2

multi-chassis-shunting-profile reference
Synopsis Multi-chassis shunting profile name
Context configure service ies service-name interface interface-name multi-chassis-shunting-profile reference
Treemulti-chassis-shunting-profile

Description

This command configures the name of a multi-chassis shunting profile to use on public or private tunnel interfaces.

Reference

configure router named-item-64 ipsec multi-chassis-shunting-profile named-item

Notes

The following elements are part of a choice: multi-chassis-shunting-profile or (dynamic-tunnel-redundant-nexthop and static-tunnel-redundant-nexthop).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

sap [sap-id] sap
Synopsis Enter the sap list instance
Context configure service ies service-name interface interface-name sap sap
Treesap
Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[sap-id] sap
Synopsis SAP ID
Contextconfigure service ies service-name interface interface-name sap sap
Treesap
String length1 to 45

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the SAP
Context configure service ies service-name interface interface-name sap sap admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bandwidth number
Synopsis SAP bandwidth
Contextconfigure service ies service-name interface interface-name sap sap bandwidth number
Treebandwidth
Range1 to 6400000000
Unitskilobps
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

description long-description
Synopsis Text description
Context configure service ies service-name interface interface-name sap sap description long-description
Treedescription
String length1 to 160
Introduced25.3.R2

Platforms

7705 SAR Gen 2

egress
Synopsis Enter the egress context
Context configure service ies service-name interface interface-name sap sap egress
Treeegress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

agg-rate
Synopsis Enter the agg-rate context
Context configure service ies service-name interface interface-name sap sap egress agg-rate
Treeagg-rate

Notes

The following elements are part of a choice: agg-rate or percent-agg-rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate number
Synopsis Enforced aggregate rate for all queues
Contextconfigure service ies service-name interface interface-name sap sap egress agg-rate rate number
Treerate
Range1 to 6400000000
Unitskilobps
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

filter
Synopsis Enter the filter context
Context configure service ies service-name interface interface-name sap sap egress filter
Treefilter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

qos
Synopsis Enter the qos context
Context configure service ies service-name interface interface-name sap sap egress qos
Treeqos
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policer-control-policy
Synopsis Enter the policer-control-policy context
Contextconfigure service ies service-name interface interface-name sap sap egress qos policer-control-policy
Treepolicer-control-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enable the overrides context
Context configure service ies service-name interface interface-name sap sap egress qos policer-control-policy overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

root
Synopsis Enter the root context
Context configure service ies service-name interface interface-name sap sap egress qos policer-control-policy overrides root
Treeroot
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority-mbs-thresholds
Synopsis Enter the priority-mbs-thresholds context
Contextconfigure service ies service-name interface interface-name sap sap egress qos policer-control-policy overrides root priority-mbs-thresholds
Treepriority-mbs-thresholds
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority [priority-level] number
Synopsis Enter the priority list instance
Contextconfigure service ies service-name interface interface-name sap sap egress qos policer-control-policy overrides root priority-mbs-thresholds priority number
Treepriority
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sap-egress
Synopsis Enter the sap-egress context
Context configure service ies service-name interface interface-name sap sap egress qos sap-egress
Treesap-egress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enter the overrides context
Context configure service ies service-name interface interface-name sap sap egress qos sap-egress overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

queue [queue-id] reference
Synopsis Enter the queue list instance
Context configure service ies service-name interface interface-name sap sap egress qos sap-egress overrides queue reference
Treequeue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure service ies service-name interface interface-name sap sap egress qos sap-egress overrides queue reference adaptation-rule
Treeadaptation-rule
Introduced25.3.R2

Platforms

7705 SAR Gen 2

avg-frame-overhead decimal-number
Synopsis Average packet-to-frame encapsulation overhead
Contextconfigure service ies service-name interface interface-name sap sap egress qos sap-egress overrides queue reference avg-frame-overhead decimal-number
Treeavg-frame-overhead

Description

This command configures overrides for the average frame overhead. The overrides supersede the average frame overhead configuration under the queue.

For a full description of this command, see the configure qos network-queue queue avg-frame-overhead and configure qos sap-egress queue avg-frame-overhead contexts.

Range0.00 to 100.00
Introduced25.3.R2

Platforms

7705 SAR Gen 2

drop-tail
Synopsis Enter the drop-tail context
Context configure service ies service-name interface interface-name sap sap egress qos sap-egress overrides queue reference drop-tail
Treedrop-tail
Introduced25.3.R2

Platforms

7705 SAR Gen 2

low
Synopsis Enter the low context
Context configure service ies service-name interface interface-name sap sap egress qos sap-egress overrides queue reference drop-tail low
Treelow
Introduced25.3.R2

Platforms

7705 SAR Gen 2

parent
Synopsis Enter the parent context
Context configure service ies service-name interface interface-name sap sap egress qos sap-egress overrides queue reference parent
Treeparent
Introduced25.3.R2

Platforms

7705 SAR Gen 2

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service ies service-name interface interface-name sap sap egress qos sap-egress overrides queue reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate
Synopsis Enter the rate context
Context configure service ies service-name interface interface-name sap sap egress qos sap-egress overrides queue reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

port-redirect-group
Synopsis Enter the port-redirect-group context
Contextconfigure service ies service-name interface interface-name sap sap egress qos sap-egress port-redirect-group
Treeport-redirect-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service ies service-name interface interface-name sap sap egress qos scheduler-policy
Treescheduler-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enter the overrides context
Context configure service ies service-name interface interface-name sap sap egress qos scheduler-policy overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

scheduler [scheduler-name] named-item
Synopsis Enter the scheduler list instance
Contextconfigure service ies service-name interface interface-name sap sap egress qos scheduler-policy overrides scheduler named-item
Treescheduler
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[scheduler-name] named-item
Synopsis Scheduler name
Contextconfigure service ies service-name interface interface-name sap sap egress qos scheduler-policy overrides scheduler named-item
Treescheduler

Description

This command specifies the scheduler name which is composed of printable 7-bit ASCII characters. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes. Each scheduler must have a unique name within the context of the scheduler policy. However, the same name can be reused in multiple scheduler policies. If the scheduler name already exists within the policy tier level, the context changes to that scheduler name for the purpose of editing the scheduler commands.

If the scheduler name exists within the policy on a different tier, an error occurs and the current context does not change. If the scheduler name does not exist in this or another tier within the scheduler policy, it is assumed that an attempt is being made to create a scheduler of that name.

If the provided scheduler name is invalid, a name syntax error occurs, the command does not execute, and the context is not change.

String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

parent
Synopsis Enter the parent context
Context configure service ies service-name interface interface-name sap sap egress qos scheduler-policy overrides scheduler named-item parent
Treeparent
Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate
Synopsis Enter the rate context
Context configure service ies service-name interface interface-name sap sap egress qos scheduler-policy overrides scheduler named-item rate
Treerate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ingress
Synopsis Enter the ingress context
Context configure service ies service-name interface interface-name sap sap ingress
Treeingress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter
Synopsis Enter the filter context
Context configure service ies service-name interface interface-name sap sap ingress filter
Treefilter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

qos
Synopsis Enter the qos context
Context configure service ies service-name interface interface-name sap sap ingress qos
Treeqos
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policer-control-policy
Synopsis Enter the policer-control-policy context
Contextconfigure service ies service-name interface interface-name sap sap ingress qos policer-control-policy
Treepolicer-control-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enable the overrides context
Context configure service ies service-name interface interface-name sap sap ingress qos policer-control-policy overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

root
Synopsis Enter the root context
Context configure service ies service-name interface interface-name sap sap ingress qos policer-control-policy overrides root
Treeroot
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority-mbs-thresholds
Synopsis Enter the priority-mbs-thresholds context
Contextconfigure service ies service-name interface interface-name sap sap ingress qos policer-control-policy overrides root priority-mbs-thresholds
Treepriority-mbs-thresholds
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority [priority-level] number
Synopsis Enter the priority list instance
Contextconfigure service ies service-name interface interface-name sap sap ingress qos policer-control-policy overrides root priority-mbs-thresholds priority number
Treepriority
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sap-ingress
Synopsis Enter the sap-ingress context
Context configure service ies service-name interface interface-name sap sap ingress qos sap-ingress
Treesap-ingress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

fp-redirect-group
Synopsis Enter the fp-redirect-group context
Contextconfigure service ies service-name interface interface-name sap sap ingress qos sap-ingress fp-redirect-group
Treefp-redirect-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enter the overrides context
Context configure service ies service-name interface interface-name sap sap ingress qos sap-ingress overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policer [policer-id] reference
Synopsis Enter the policer list instance
Contextconfigure service ies service-name interface interface-name sap sap ingress qos sap-ingress overrides policer reference
Treepolicer
Introduced25.3.R2

Platforms

7705 SAR Gen 2

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service ies service-name interface interface-name sap sap ingress qos sap-ingress overrides policer reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate
Synopsis Enter the rate context
Context configure service ies service-name interface interface-name sap sap ingress qos sap-ingress overrides policer reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

stat-mode keyword
Synopsis Mode of statistics collected by the policer
Contextconfigure service ies service-name interface interface-name sap sap ingress qos sap-ingress overrides policer reference stat-mode keyword
Treestat-mode
Optionsno-stats, minimal, offered-profile-no-cir, offered-total-cir, offered-priority-no-cir, offered-profile-cir, offered-priority-cir, offered-limited-profile-cir, offered-profile-capped-cir, offered-limited-capped-cir
Introduced25.3.R2

Platforms

7705 SAR Gen 2

queue [queue-id] reference
Synopsis Enter the queue list instance
Context configure service ies service-name interface interface-name sap sap ingress qos sap-ingress overrides queue reference
Treequeue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure service ies service-name interface interface-name sap sap ingress qos sap-ingress overrides queue reference adaptation-rule
Treeadaptation-rule
Introduced25.3.R2

Platforms

7705 SAR Gen 2

drop-tail
Synopsis Enter the drop-tail context
Context configure service ies service-name interface interface-name sap sap ingress qos sap-ingress overrides queue reference drop-tail
Treedrop-tail
Introduced25.3.R2

Platforms

7705 SAR Gen 2

low
Synopsis Enter the low context
Context configure service ies service-name interface interface-name sap sap ingress qos sap-ingress overrides queue reference drop-tail low
Treelow
Introduced25.3.R2

Platforms

7705 SAR Gen 2

parent
Synopsis Enter the parent context
Context configure service ies service-name interface interface-name sap sap ingress qos sap-ingress overrides queue reference parent
Treeparent
Introduced25.3.R2

Platforms

7705 SAR Gen 2

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service ies service-name interface interface-name sap sap ingress qos sap-ingress overrides queue reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate
Synopsis Enter the rate context
Context configure service ies service-name interface interface-name sap sap ingress qos sap-ingress overrides queue reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service ies service-name interface interface-name sap sap ingress qos scheduler-policy
Treescheduler-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enter the overrides context
Context configure service ies service-name interface interface-name sap sap ingress qos scheduler-policy overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

scheduler [scheduler-name] named-item
Synopsis Enter the scheduler list instance
Contextconfigure service ies service-name interface interface-name sap sap ingress qos scheduler-policy overrides scheduler named-item
Treescheduler
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[scheduler-name] named-item
Synopsis Scheduler name
Contextconfigure service ies service-name interface interface-name sap sap ingress qos scheduler-policy overrides scheduler named-item
Treescheduler

Description

This command specifies the scheduler name which is composed of printable 7-bit ASCII characters. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes. Each scheduler must have a unique name within the context of the scheduler policy. However, the same name can be reused in multiple scheduler policies. If the scheduler name already exists within the policy tier level, the context changes to that scheduler name for the purpose of editing the scheduler commands.

If the scheduler name exists within the policy on a different tier, an error occurs and the current context does not change. If the scheduler name does not exist in this or another tier within the scheduler policy, it is assumed that an attempt is being made to create a scheduler of that name.

If the provided scheduler name is invalid, a name syntax error occurs, the command does not execute, and the context is not change.

String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

parent
Synopsis Enter the parent context
Context configure service ies service-name interface interface-name sap sap ingress qos scheduler-policy overrides scheduler named-item parent
Treeparent
Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate
Synopsis Enter the rate context
Context configure service ies service-name interface interface-name sap sap ingress qos scheduler-policy overrides scheduler named-item rate
Treerate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-tunnel [tunnel-name] interface-name
Synopsis Enter the ip-tunnel list instance
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name
Treeip-tunnel

Description

Commands in this context configure an IP-GRE or IP-IP tunnel and associate it with a private tunnel SAP within an IES service.

Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[tunnel-name] interface-name
Synopsis IP tunnel name
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name
Treeip-tunnel
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the IP tunnel
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

backup-remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisBackup remote IP address that is applied to this tunnel
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name backup-remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treebackup-remote-ip-address
Introduced25.3.R2

Platforms

7705 SAR Gen 2

clear-df-bit boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisClear the Do-not-Fragment bit
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name clear-df-bit boolean
Treeclear-df-bit

Description

When configured to true, the DF bit is cleared (set to 0) in all payload IP packets associated with the GRE or IPsec tunnel, before any potential fragmentation resulting from the ip-mtu command. This requires a modification of the header checksum.

When configured to false, clearing of the DF bit is disabled.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

delivery-service service-name
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisService to originate and terminate GRE packets
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name delivery-service service-name
Treedelivery-service

Description

This command specifies the service used to originate and terminate the GRE encapsulated packets belonging to the GRE tunnel. The delivery service may be the same service that owns the private tunnel SAP associated with the GRE tunnel.

The GRE tunnel does not come up until a valid delivery service is configured.

String length1 to 64
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisText description
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dest-ip [dest-ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Add a list entry for dest-ip
Context configure service ies service-name interface interface-name sap sap ip-tunnel interface-name dest-ip (ipv4-address-no-zone | ipv6-address-no-zone)
Treedest-ip
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[dest-ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the remote IP tunnel endpoint
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name dest-ip (ipv4-address-no-zone | ipv6-address-no-zone)
Treedest-ip

Description

This command configures the IP address of the remote IP tunnel endpoint. If the remote IP address is not within the subnet of the IP interface associated with the tunnel, the tunnel fails to come up.

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

dscp keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDifferentiated Services Code Point (DSCP) name
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name dscp keyword
Treedscp
Optionsbe, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

encapsulated-ip-mtu number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum size of the encapsulated tunnel packet
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name encapsulated-ip-mtu number
Treeencapsulated-ip-mtu

Description

This command specifies the maximum size of the encapsulated tunnel packet for the IP tunnel. If the packet exceeds this value, the system fragments the packet.

Range512 to 9000
Unitsbytes
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

gre-header
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the gre-header context
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name gre-header
Treegre-header
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of the GRE header in the tunnel
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name gre-header admin-state keyword
Treeadmin-state
Optionsenable, disable
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

key
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the key context
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name gre-header key
Treekey
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of the keys in the GRE header
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name gre-header key admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

receive number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisReceive key of the GRE header
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name gre-header key receive number
Treereceive
Max. range0 to 4294967295
Default0
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

send number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSend key of the GRE header
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name gre-header key send number
Treesend
Max. range0 to 4294967295
Default0
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

icmp-generation
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the icmp-generation context
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name icmp-generation
Treeicmp-generation
Introduced25.3.R2

Platforms

7705 SAR Gen 2

frag-required
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the frag-required context
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name icmp-generation frag-required
Treefrag-required
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of sending ICMP messages
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name icmp-generation frag-required admin-state keyword
Treeadmin-state

Description

This command configures the administrative state of sending ICMP Destination Unreachable "fragmentation needed, DF set" messages (type 3, code 4) messages to the source if the received size of the IPv4 packet on the private side exceeds the private MTU size.

Optionsenable, disable
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

interval number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisInterval for sending ICMP messages
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name icmp-generation frag-required interval number
Treeinterval

Description

This command configures the interval for sending ICMP Destination Unreachable "fragmentation needed, DF set" messages (type 3, code 4).

Range1 to 60
Unitsseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

message-count number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of ICMP messages sent
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name icmp-generation frag-required message-count number
Treemessage-count

Description

This command configures the maximum number of ICMP messages that can be sent during the period specified by the interval command.

Range10 to 1000
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

icmp6-generation
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the icmp6-generation context
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name icmp6-generation
Treeicmp6-generation
Introduced25.3.R2

Platforms

7705 SAR Gen 2

packet-too-big
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the packet-too-big context
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name icmp6-generation packet-too-big
Treepacket-too-big
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of sending Packet Too Big messages
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name icmp6-generation packet-too-big admin-state keyword
Treeadmin-state
Optionsenable, disable
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

number number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of PTB ICMPv6 messages that can be sent
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name icmp6-generation packet-too-big number number
Treenumber

Description

This command configures the maximum number of ICMPv6 messages that can be sent during the configured interval.

Range10 to 1000
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

seconds number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum interval when PTB messages can be sent
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name icmp6-generation packet-too-big seconds number
Treeseconds
Range1 to 60
Unitsseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-mtu number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIP MTU for the interface
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name ip-mtu number
Treeip-mtu

Description

This command specifies the IP MTU for the interface. If the DF bit is not set in the packet, IP packet fragmentation is performed, if necessary, based on this configured value.

When unconfigured, all IP packets, regardless of the packet size or DF bit setting, are allowed into the tunnel without fragmentation.

Range512 to 9000
Unitsbytes
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

local-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal IP address of this tunnel
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name local-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treelocal-ip-address

Description

This command specifies the local IP address to use for the IP tunnel. This configuration applies to the outer IP header of the encapsulated packets. The address must belong to one of the IP subnets associated with the public SAP interface of the tunnel group. The source IP address, the remote IP address, and the backup remote IP address of a tunnel must all belong to the same address family (IPv4 or IPv6).

When this command specifies an IPv6 address, it must be a global unicast address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

pmtu-discovery-aging number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTime to age out the learned path MTU
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name pmtu-discovery-aging number
Treepmtu-discovery-aging

Description

This command configures the temporary public MTU expiration time. The temporary public MTU is used for MTU propagation.

Range900 to 3600
Unitsseconds
Default 900
Introduced25.3.R2

Platforms

7705 SAR Gen 2

private-tcp-mss-adjust number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTCP Maximum Segment Size (MSS) on the private side
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name private-tcp-mss-adjust number
Treeprivate-tcp-mss-adjust

Description

This command specifies the TCP MSS to adjust for tunnels on the private side. The value is used to adjust the TCP MSS option in the TCP SYN packet.

Range512 to 9000
Unitsbytes
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

propagate-pmtu-v4 boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable propagation of the path MTU to IPv4 hosts
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name propagate-pmtu-v4 boolean
Treepropagate-pmtu-v4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

propagate-pmtu-v6 boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable propagation of path MTU to IPv6 hosts
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name propagate-pmtu-v6 boolean
Treepropagate-pmtu-v6
Introduced25.3.R2

Platforms

7705 SAR Gen 2

public-tcp-mss-adjust (number | keyword)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTCP Maximum Segment Size (MSS) on the public side
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name public-tcp-mss-adjust (number | keyword)
Treepublic-tcp-mss-adjust

Description

This command specifies the TCP MSS for TCP traffic sent from the public network to the private network. The value is used to adjust the TCP MSS option in the TCP SYN packet.

Range512 to 9000
Unitsbytes
Options auto
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

reassembly (number | keyword)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum reassembly wait time
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name reassembly (number | keyword)
Treereassembly

Description

This command configures the maximum time to wait to receive all fragments of a particular IPsec or GRE packet for reassembly.

Range1 to 5000
Unitsmilliseconds
Options use-tunnel-group-setting, none
Introduced25.3.R2

Platforms

7705 SAR Gen 2

remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRemote IP address of the tunnel
Contextconfigure service ies service-name interface interface-name sap sap ip-tunnel interface-name remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeremote-ip-address
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipsec-gateway [name] named-item
Synopsis Enter the ipsec-gateway list instance
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item
Treeipsec-gateway
Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[name] named-item
Synopsis IPsec gateway name
Context configure service ies service-name interface interface-name sap sap ipsec-gateway named-item
Treeipsec-gateway
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the IPsec gateway
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

cert
Synopsis Enter the cert context
Context configure service ies service-name interface interface-name sap sap ipsec-gateway named-item cert
Treecert
Introduced25.3.R2

Platforms

7705 SAR Gen 2

status-verify
Synopsis Enter the status-verify context
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item cert status-verify
Treestatus-verify

Description

Commands in this context configure certificate revocation status verification.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

default-result keyword
Synopsis Default result of Certificate Status Verification (CSV)
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item cert status-verify default-result keyword
Treedefault-result

Description

This command specifies the default result when both the primary and secondary methods fail to provide an answer.

Optionsrevoked, good
Default revoked
Introduced25.3.R2

Platforms

7705 SAR Gen 2

client-db
Synopsis Enable the client-db context
Context configure service ies service-name interface interface-name sap sap ipsec-gateway named-item client-db
Treeclient-db

Description

Commands in this context configure the IPsec client database. The client database is used to authenticate the IKEv2 dynamic LAN-to-LAN tunnel.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

fallback boolean
Synopsis Fall back to the default authentication policy
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item client-db fallback boolean
Treefallback

Description

When configured to true, this command specifies whether the IPsec gateway can fall back to the default authentication policy when the IPsec tunnel authentication request fails to match any clients in the IPsec database.

When configured to false and the client database lookup fails to return a matched result, the system fails the tunnel setup.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

default-secure-service
Synopsis Enable the default-secure-service context
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item default-secure-service
Treedefault-secure-service
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface interface-name
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPrivate IPsec tunnel interface name
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item default-secure-service interface interface-name
Treeinterface
String length1 to 32
Introduced25.3.R2

Platforms

7705 SAR Gen 2

service-name service-name
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDefault security service name
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item default-secure-service service-name service-name
Treeservice-name
String length1 to 64
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dhcp-address-assignment
Synopsis Enter the dhcp-address-assignment context
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item dhcp-address-assignment
Treedhcp-address-assignment
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dhcpv4
Synopsis Enable the dhcpv4 context
Context configure service ies service-name interface interface-name sap sap ipsec-gateway named-item dhcp-address-assignment dhcpv4
Treedhcpv4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

gi-address ipv4-unicast-address
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisGateway IP address of DHCPv4 packets sent by the system
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item dhcp-address-assignment dhcpv4 gi-address ipv4-unicast-address
Treegi-address
Introduced25.3.R2

Platforms

7705 SAR Gen 2

server
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the server context
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item dhcp-address-assignment dhcpv4 server
Treeserver
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address ipv4-unicast-address
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDHCPv4 server addresses
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item dhcp-address-assignment dhcpv4 server address ipv4-unicast-address
Treeaddress

Description

This command specifies DHCPv4 server addresses for the DHCPv4-based address assignment. If multiple server addresses are specified, the first advertised DHCPv4 address received is chosen.

Max. instances8
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dhcpv6
Synopsis Enable the dhcpv6 context
Context configure service ies service-name interface interface-name sap sap ipsec-gateway named-item dhcp-address-assignment dhcpv6
Treedhcpv6
Introduced25.3.R2

Platforms

7705 SAR Gen 2

server
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the server context
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item dhcp-address-assignment dhcpv6 server
Treeserver
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address ipv6-unicast-address
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDHCPv6 server addresses
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item dhcp-address-assignment dhcpv6 server address ipv6-unicast-address
Treeaddress

Description

This command specifies DHCPv6 server addresses for the DHCPv6-based address assignment. If multiple server addresses are specified, the first advertised DHCPv6 address received is chosen.

Max. instances8
Introduced25.3.R2

Platforms

7705 SAR Gen 2

local
Synopsis Enter the local context
Context configure service ies service-name interface interface-name sap sap ipsec-gateway named-item local
Treelocal
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address-assignment
Synopsis Enable the address-assignment context
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item local address-assignment
Treeaddress-assignment
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the ipv4 context
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item local address-assignment ipv4
Treeipv4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dhcp-server named-item
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal DHCPv4 server name
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item local address-assignment ipv4 dhcp-server named-item
Treedhcp-server
String length1 to 32

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

pool named-item
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisName of the pool defined in the specified DHCPv4 server
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item local address-assignment ipv4 pool named-item
Treepool
String length1 to 32

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

router-instance router-instance-base-vprn-loose
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRouter instance ID for the local DHCPv4 server
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item local address-assignment ipv4 router-instance router-instance-base-vprn-loose
Treerouter-instance
String length1 to 64

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

secondary-pool named-item
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisName of the secondary pool defined in the DHCPv4 server
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item local address-assignment ipv4 secondary-pool named-item
Treesecondary-pool
String length1 to 32
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the ipv6 context
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item local address-assignment ipv6
Treeipv6
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dhcp-server named-item
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal DHCPv6 server name
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item local address-assignment ipv6 dhcp-server named-item
Treedhcp-server
String length1 to 32

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

pool named-item
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSecondary pool name defined in the DHCPv6 server
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item local address-assignment ipv6 pool named-item
Treepool
String length1 to 32

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

router-instance router-instance-base-vprn-loose
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRouter instance ID hosting the DHCPv6 connection
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item local address-assignment ipv6 router-instance router-instance-base-vprn-loose
Treerouter-instance
String length1 to 64

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal gateway address of the IPsec gateway
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item local gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treegateway-address
Introduced25.3.R2

Platforms

7705 SAR Gen 2

id
Synopsis Enter the id context
Context configure service ies service-name interface interface-name sap sap ipsec-gateway named-item local id
Treeid

Description

Commands in this context specify the local ID used for the Identification Indicator (IDi) or Identification Responder (IDr) in the IKEv2 tunnel.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

auto
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSelect ID based on authentication method in IKE policy
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item local id auto
Treeauto

Notes

The following elements are part of a choice: auto, fqdn, ipv4, or ipv6.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

fqdn fully-qualified-domain-name
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisFQDN as the local ID type
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item local id fqdn fully-qualified-domain-name
Treefqdn
String length1 to 255

Notes

The following elements are part of a choice: auto, fqdn, ipv4, or ipv6.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4 ipv4-unicast-address
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPv4 address as the local ID type
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item local id ipv4 ipv4-unicast-address
Treeipv4

Notes

The following elements are part of a choice: auto, fqdn, ipv4, or ipv6.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPv6 address as the local ID type
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item local id ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
Treeipv6

Notes

The following elements are part of a choice: auto, fqdn, ipv4, or ipv6.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

max-history-key-records
Synopsis Enter the max-history-key-records context
Contextconfigure service ies service-name interface interface-name sap sap ipsec-gateway named-item max-history-key-records
Treemax-history-key-records
Introduced25.3.R2

Platforms

7705 SAR Gen 2

radius
Synopsis Enter the radius context
Context configure service ies service-name interface interface-name sap sap ipsec-gateway named-item radius
Treeradius
Introduced25.3.R2

Platforms

7705 SAR Gen 2

lag
Synopsis Enter the lag context
Context configure service ies service-name interface interface-name sap sap lag
Treelag
Introduced25.3.R2

Platforms

7705 SAR Gen 2

spoke-sdp [sdp-bind-id] sdp-bind-id
Synopsis Enter the spoke-sdp list instance
Contextconfigure service ies service-name interface interface-name spoke-sdp sdp-bind-id
Treespoke-sdp
Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[sdp-bind-id] sdp-bind-id
Synopsis SDP binding ID
Contextconfigure service ies service-name interface interface-name spoke-sdp sdp-bind-id
Treespoke-sdp
String length3 to 16

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the SDP binding to the service
Contextconfigure service ies service-name interface interface-name spoke-sdp sdp-bind-id admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

egress
Synopsis Enter the egress context
Context configure service ies service-name interface interface-name spoke-sdp sdp-bind-id egress
Treeegress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter
Synopsis Enter the filter context
Context configure service ies service-name interface interface-name spoke-sdp sdp-bind-id egress filter
Treefilter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

qos
Synopsis Enter the qos context
Context configure service ies service-name interface interface-name spoke-sdp sdp-bind-id egress qos
Treeqos
Introduced25.3.R2

Platforms

7705 SAR Gen 2

network
Synopsis Enter the network context
Context configure service ies service-name interface interface-name spoke-sdp sdp-bind-id egress qos network
Treenetwork
Introduced25.3.R2

Platforms

7705 SAR Gen 2

port-redirect-group
Synopsis Enter the port-redirect-group context
Contextconfigure service ies service-name interface interface-name spoke-sdp sdp-bind-id egress qos network port-redirect-group
Treeport-redirect-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEgress MPLS VC label to send packets to the far end
Contextconfigure service ies service-name interface interface-name spoke-sdp sdp-bind-id egress vc-label number
Treevc-label
Range16 to 1048575
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hash-label
Synopsis Enable the hash-label context
Context configure service ies service-name interface interface-name spoke-sdp sdp-bind-id hash-label
Treehash-label

Description

Commands in this context configure the use of hash labels for egress datapaths.

For information about hash-label handling, see the "Hash labels" section of the 7705 SAR Gen 2 MPLS Guide.

Notes

The following elements are part of a choice: entropy-label or hash-label.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

signal-capability
Synopsis Signal hash label capability to the remote PE
Contextconfigure service ies service-name interface interface-name spoke-sdp sdp-bind-id hash-label signal-capability
Treesignal-capability

Description

When configured, this command enables the signaling and negotiating of the hash label between the local and remote PE nodes.

The signaling process outcome determines whether the local PE inserts the hash label on the user packets. This outcome can override the local PE configuration.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ingress
Synopsis Enter the ingress context
Context configure service ies service-name interface interface-name spoke-sdp sdp-bind-id ingress
Treeingress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter
Synopsis Enter the filter context
Context configure service ies service-name interface interface-name spoke-sdp sdp-bind-id ingress filter
Treefilter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

qos
Synopsis Enter the qos context
Context configure service ies service-name interface interface-name spoke-sdp sdp-bind-id ingress qos
Treeqos
Introduced25.3.R2

Platforms

7705 SAR Gen 2

network
Synopsis Enter the network context
Context configure service ies service-name interface interface-name spoke-sdp sdp-bind-id ingress qos network
Treenetwork
Introduced25.3.R2

Platforms

7705 SAR Gen 2

fp-redirect-group
Synopsis Enter the fp-redirect-group context
Contextconfigure service ies service-name interface interface-name spoke-sdp sdp-bind-id ingress qos network fp-redirect-group
Treefp-redirect-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIngress MPLS VC label to send packets to the far end
Contextconfigure service ies service-name interface interface-name spoke-sdp sdp-bind-id ingress vc-label number
Treevc-label
Range1 to 1048575
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vc-type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVirtual circuit type associated with the SDP binding
Contextconfigure service ies service-name interface interface-name spoke-sdp sdp-bind-id vc-type keyword
Treevc-type
Optionsether, ipipe
Default ether
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static-tunnel-redundant-nexthop ipv4-unicast-address
Synopsis Address for the static ISA tunnel redundant next-hop
Contextconfigure service ies service-name interface interface-name static-tunnel-redundant-nexthop ipv4-unicast-address
Treestatic-tunnel-redundant-nexthop

Description

This command configures a redundant next-hop address on a public or private IPsec interface (with a public or private tunnel SAP) for a static IPsec tunnel in 1:1 MC-IPsec. A standby node uses the specified next-hop address to shunt traffic to the master in case it receives traffic destined to a tunnel endpoint address. The standby tunnel group needs to be operationally up for the feature to work.

The next-hop address is resolved in the routing table of the corresponding service.

Notes

The following elements are part of a choice: multi-chassis-shunting-profile or (dynamic-tunnel-redundant-nexthop and static-tunnel-redundant-nexthop).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

tunnel boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEnable/disable tunnel interface
Contextconfigure service ies service-name interface interface-name tunnel boolean
Treetunnel
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vpls [vpls-name] named-item-64
Synopsis Enter the vpls list instance
Context configure service ies service-name interface interface-name vpls named-item-64
Treevpls
Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[vpls-name] named-item-64
Synopsis VPLS service
Contextconfigure service ies service-name interface interface-name vpls named-item-64
Treevpls
String length1 to 64

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

egress
Synopsis Enter the egress context
Context configure service ies service-name interface interface-name vpls named-item-64 egress
Treeegress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

routed-override-filter
Synopsis Enter the routed-override-filter context
Contextconfigure service ies service-name interface interface-name vpls named-item-64 egress routed-override-filter
Treerouted-override-filter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

evpn
Synopsis Enter the evpn context
Context configure service ies service-name interface interface-name vpls named-item-64 evpn
Treeevpn
Introduced25.3.R2

Platforms

7705 SAR Gen 2

arp
Synopsis Enter the arp context
Context configure service ies service-name interface interface-name vpls named-item-64 evpn arp
Treearp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

advertise [route-type] keyword
Synopsis Enter the advertise list instance
Contextconfigure service ies service-name interface interface-name vpls named-item-64 evpn arp advertise keyword
Treeadvertise

Description

Commands in this context specify the configuration to allow ARP or ND entries that are installed in the ARP or ND cache to be advertised in EVPN MAC/IP routes.

The learn-dynamic command must be set to false when using this functionality.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[route-type] keyword
Synopsis Type of ARP or ND entries that generate host routes
Contextconfigure service ies service-name interface interface-name vpls named-item-64 evpn arp advertise keyword
Treeadvertise

Description

This command specifies the type of ARP or ND entries that are installed in the ARP or ND cache into EVPN MAC/IP routes.

Optionsstatic, dynamic

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-tag number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTag value used with the host route from an ARP/ND entry
Contextconfigure service ies service-name interface interface-name vpls named-item-64 evpn arp advertise keyword route-tag number
Treeroute-tag

Description

This command specifies the route tag that is added separately to dynamic or static ARP or ND entries that are advertised in EVPN MAC/IP routes. This tag can be matched on BGP vsi-export (in the R-VPLS) and BGP peer export policies. 

Range0 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

flood-garp-and-unknown-req boolean
Synopsis Allow CPM originated ARP frames to flood R-VPLS service
Contextconfigure service ies service-name interface interface-name vpls named-item-64 evpn arp flood-garp-and-unknown-req boolean
Treeflood-garp-and-unknown-req

Description

When configured to true, the system allows CPM-originated ARP frames to be flooded in the R-VPLS service. Any frames that are data path flooded such as the ARP messages received on a SAP, are flooded irrespective of this command.

When configured to false, CPM-originated ARP flooding is suppressed.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

learn-dynamic boolean
Synopsis Process ARP or ND messages on EVPN tunnels
Contextconfigure service ies service-name interface interface-name vpls named-item-64 evpn arp learn-dynamic boolean
Treelearn-dynamic

Description

When configured to true, the system processes ARP or ND messages that arrive on EVPN tunnels.

When configured to false, learning is disabled and table entries are not created for these messages.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

nd
Synopsis Enter the nd context
Context configure service ies service-name interface interface-name vpls named-item-64 evpn nd
Treend
Introduced25.3.R2

Platforms

7705 SAR Gen 2

advertise [route-type] keyword
Synopsis Enter the advertise list instance
Contextconfigure service ies service-name interface interface-name vpls named-item-64 evpn nd advertise keyword
Treeadvertise

Description

Commands in this context specify the configuration to allow ARP or ND entries that are installed in the ARP or ND cache to be advertised in EVPN MAC/IP routes.

The learn-dynamic command must be set to false when using this functionality.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[route-type] keyword
Synopsis Type of ARP or ND entries that generate host routes
Contextconfigure service ies service-name interface interface-name vpls named-item-64 evpn nd advertise keyword
Treeadvertise

Description

This command specifies the type of ARP or ND entries that are installed in the ARP or ND cache into EVPN MAC/IP routes.

Optionsstatic, dynamic

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-tag number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTag value used with the host route from an ARP/ND entry
Contextconfigure service ies service-name interface interface-name vpls named-item-64 evpn nd advertise keyword route-tag number
Treeroute-tag

Description

This command specifies the route tag that is added separately to dynamic or static ARP or ND entries that are advertised in EVPN MAC/IP routes. This tag can be matched on BGP vsi-export (in the R-VPLS) and BGP peer export policies. 

Range0 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

learn-dynamic boolean
Synopsis Process ARP or ND messages on EVPN tunnels
Contextconfigure service ies service-name interface interface-name vpls named-item-64 evpn nd learn-dynamic boolean
Treelearn-dynamic

Description

When configured to true, the system processes ARP or ND messages that arrive on EVPN tunnels.

When configured to false, learning is disabled and table entries are not created for these messages.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ingress
Synopsis Enter the ingress context
Context configure service ies service-name interface interface-name vpls named-item-64 ingress
Treeingress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

routed-override-filter
Synopsis Enter the routed-override-filter context
Contextconfigure service ies service-name interface interface-name vpls named-item-64 ingress routed-override-filter
Treerouted-override-filter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip reference
Synopsis IPv4 filter policy name
Context configure service ies service-name interface interface-name vpls named-item-64 ingress routed-override-filter ip reference
Treeip

Description

This command specifies an IP filter that is applied to routed unicast ingress packets entering the VPLS service and destined to the R-VPLS interface MAC address.

The filter overrides any existing ingress IP filter applied to SAPs or SDP bindings for packets associated with the routing IP interface. The override filter is optional and when it is not defined or it is removed, the IP routed packets use the existing ingress IP filter configured on the VPLS endpoint.

Reference

configure filter ip-filter filter-name

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6 reference
Synopsis IPv6 filter policy name
Context configure service ies service-name interface interface-name vpls named-item-64 ingress routed-override-filter ipv6 reference
Treeipv6

Description

This command specifies an IPv6 filter that is applied to routed unicast ingress packets entering the VPLS service and destined to the R-VPLS interface MAC address.

The filter overrides any existing ingress IP filter applied to SAPs or SDP bindings for packets associated with the routing IP interface. The override filter is optional and when it is not defined or it is removed, the IP routed packets use the existing ingress IP filter configured on the VPLS endpoint.

Reference

configure filter ipv6-filter filter-name

Introduced25.3.R2

Platforms

7705 SAR Gen 2

service-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisService ID
Contextconfigure service ies service-name service-id number
Treeservice-id
Range1 to 2147483647
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vpn-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVPN identifier for the service
Contextconfigure service ies service-name vpn-id number
Treevpn-id
Range1 to 2147483647
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac-list [name] named-item

Synopsis Enter the mac-list list instance
Contextconfigure service mac-list named-item
Treemac-list

Description

Commands in this context specify the MAC addresses to be included in a MAC list to be used with the Auto-Learn MAC Protect (ALMP) functionality. The list is used to exclude certain MAC addresses from protection, for example, on SAPs or spoke SDPs configured with ALMP where certain MAC addresses (such as VRRP virtual MAC addresses) must be able to move to other objects.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[name] named-item
Synopsis MAC list name
Contextconfigure service mac-list named-item
Treemac-list
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service mac-list named-item description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac [address] mac-address
Synopsis Enter the mac list instance
Context configure service mac-list named-item mac mac-address
Treemac
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[address] mac-address
Synopsis MAC address
Contextconfigure service mac-list named-item mac mac-address
Treemac

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mask mac-address
Synopsis Mask for the MAC address
Context configure service mac-list named-item mac mac-address mask mac-address
Treemask
Defaultff:ff:ff:ff:ff:ff
Introduced25.3.R2

Platforms

7705 SAR Gen 2

md-auto-id

Synopsis Enter the md-auto-id context
Context configure service md-auto-id
Treemd-auto-id
Introduced25.3.R2

Platforms

7705 SAR Gen 2

customer-id-range
Synopsis Enable the customer-id-range context
Contextconfigure service md-auto-id customer-id-range
Treecustomer-id-range
Introduced25.3.R2

Platforms

7705 SAR Gen 2

end number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisUpper bound of the ID range
Contextconfigure service md-auto-id customer-id-range end number
Treeend
Range2 to 2147483647

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

start number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisLower bound of the ID range
Contextconfigure service md-auto-id customer-id-range start number
Treestart
Range2 to 2147483647

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

pw-template-id-range
Synopsis Enable the pw-template-id-range context
Contextconfigure service md-auto-id pw-template-id-range
Treepw-template-id-range
Introduced25.3.R2

Platforms

7705 SAR Gen 2

end number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisUpper bound of the PW template ID range
Contextconfigure service md-auto-id pw-template-id-range end number
Treeend
Range1 to 2147483647

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

start number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisLower bound of the PW template ID range
Contextconfigure service md-auto-id pw-template-id-range start number
Treestart
Range1 to 2147483647

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

service-id-range
Synopsis Enable the service-id-range context
Contextconfigure service md-auto-id service-id-range
Treeservice-id-range
Introduced25.3.R2

Platforms

7705 SAR Gen 2

end number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisUpper bound of the service ID range
Contextconfigure service md-auto-id service-id-range end number
Treeend
Range1 to 2147483647

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

start number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisLower bound of the service ID range
Contextconfigure service md-auto-id service-id-range start number
Treestart
Range1 to 2147483647

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

nat

Synopsis Enter the nat context
Context configure service nat
Treenat
Introduced25.3.R2

Platforms

7705 SAR Gen 2

nat-policy [name] external-named-item
Synopsis Enter the nat-policy list instance
Contextconfigure service nat nat-policy external-named-item
Treenat-policy
Max. instances4096
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[name] external-named-item
Synopsis NAT policy name
Context configure service nat nat-policy external-named-item
Treenat-policy
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

block-limit number
Synopsis Maximum number of port blocks per subscriber
Contextconfigure service nat nat-policy external-named-item block-limit number
Treeblock-limit
Range1 to 40
Default1
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service nat nat-policy external-named-item description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

filtering keyword
Synopsis Filtering method for inbound traffic for the policy
Contextconfigure service nat nat-policy external-named-item filtering keyword
Treefiltering
Optionsendpoint-independent, address-and-port-dependent
Defaultendpoint-independent
Introduced25.3.R2

Platforms

7705 SAR Gen 2

pool
Synopsis Enter the pool context
Context configure service nat nat-policy external-named-item pool
Treepool

Notes

The following elements are part of a choice: dnat-only, l2-outside, or pool.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

name named-item
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisNAT pool name
Contextconfigure service nat nat-policy external-named-item pool name named-item
Treename
String length1 to 32
Introduced25.3.R2

Platforms

7705 SAR Gen 2

router-instance string
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisRouter or VPRN service name
Contextconfigure service nat nat-policy external-named-item pool router-instance string
Treerouter-instance
Introduced25.3.R2

Platforms

7705 SAR Gen 2

port-limits
Synopsis Enter the port-limits context
Context configure service nat nat-policy external-named-item port-limits
Treeport-limits
Introduced25.3.R2

Platforms

7705 SAR Gen 2

watermarks
Synopsis Enable the watermarks context
Context configure service nat nat-policy external-named-item port-limits watermarks
Treewatermarks

Description

This command configures watermarks for NAT resources.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

high number
Synopsis High watermark percentage
Context configure service nat nat-policy external-named-item port-limits watermarks high number
Treehigh

Description

This command configures the high threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

low number
Synopsis Low watermark percentage
Context configure service nat nat-policy external-named-item port-limits watermarks low number
Treelow

Description

This command configures the low threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

session-limits
Synopsis Enter the session-limits context
Contextconfigure service nat nat-policy external-named-item session-limits
Treesession-limits

Description

Commands in this context configure session-limit attributes for the policy.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

max number
Synopsis Maximum number of sessions per subscriber
Contextconfigure service nat nat-policy external-named-item session-limits max number
Treemax
Range1 to 65535
Default65535
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

watermarks
Synopsis Enable the watermarks context
Context configure service nat nat-policy external-named-item session-limits watermarks
Treewatermarks

Description

This command configures watermarks for NAT resources.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

high number
Synopsis High watermark percentage
Context configure service nat nat-policy external-named-item session-limits watermarks high number
Treehigh

Description

This command configures the high threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

low number
Synopsis Low watermark percentage
Context configure service nat nat-policy external-named-item session-limits watermarks low number
Treelow

Description

This command configures the low threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

tcp
Synopsis Enter the tcp context
Context configure service nat nat-policy external-named-item tcp
Treetcp

Description

Commands in this context configure the transmission control protocol (TCP) attributes of the policy.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mss-adjust number
Synopsis TCP MSS adjustment value
Context configure service nat nat-policy external-named-item tcp mss-adjust number
Treemss-adjust

Description

This command configures the value to use to adjust the TCP Maximum Segment Size (MSS) option, if not already present or the present value is higher.

Range160 to 10240
Introduced25.3.R2

Platforms

7705 SAR Gen 2

timeouts
Synopsis Enter the timeouts context
Context configure service nat nat-policy external-named-item timeouts
Treetimeouts

Description

Commands in this context configure the attributes of session idle timeouts for the policy.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

icmp-query number
Synopsis Timeout applied to an ICMP Query session
Contextconfigure service nat nat-policy external-named-item timeouts icmp-query number
Treeicmp-query
Range60 to 240
Unitsseconds
Default 60
Introduced25.3.R2

Platforms

7705 SAR Gen 2

tcp
Synopsis Enter the tcp context
Context configure service nat nat-policy external-named-item timeouts tcp
Treetcp

Description

Commands in this context configure TCP timeout attributes. 

Introduced25.3.R2

Platforms

7705 SAR Gen 2

established number
Synopsis Idle timeout for TCP session in established state
Contextconfigure service nat nat-policy external-named-item timeouts tcp established number
Treeestablished
Range60 to 86400
Unitsseconds
Default 7440
Introduced25.3.R2

Platforms

7705 SAR Gen 2

syn number
Synopsis TCP session timeout when synchronizing initial sequence
Contextconfigure service nat nat-policy external-named-item timeouts tcp syn number
Treesyn
Range6 to 86400
Unitsseconds
Default 15
Introduced25.3.R2

Platforms

7705 SAR Gen 2

time-wait number
Synopsis Timeout applied to a TCP session in the time-wait state
Contextconfigure service nat nat-policy external-named-item timeouts tcp time-wait number
Treetime-wait
Range0 to 240
Unitsseconds
Default 0
Introduced25.3.R2

Platforms

7705 SAR Gen 2

transitory number
Synopsis Idle timeout for TCP session in transitory state
Contextconfigure service nat nat-policy external-named-item timeouts tcp transitory number
Treetransitory
Range60 to 86400
Unitsseconds
Default 240
Introduced25.3.R2

Platforms

7705 SAR Gen 2

udp
Synopsis Enter the udp context
Context configure service nat nat-policy external-named-item timeouts udp
Treeudp

Description

Commands in this context configure the User Datagram Protocol (UDP) mapping timeout attributes.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

dns number
Synopsis Timeout applied to UDP session with destination port 53
Contextconfigure service nat nat-policy external-named-item timeouts udp dns number
Treedns
Range15 to 86400
Unitsseconds
Default 15
Introduced25.3.R2

Platforms

7705 SAR Gen 2

initial number
Synopsis UDP mapping timeout applied to new sessions
Contextconfigure service nat nat-policy external-named-item timeouts udp initial number
Treeinitial
Range10 to 300
Unitsseconds
Default 15
Introduced25.3.R2

Platforms

7705 SAR Gen 2

normal number
Synopsis UDP mapping timeout
Context configure service nat nat-policy external-named-item timeouts udp normal number
Treenormal
Range60 to 86400
Unitsseconds
Default 300
Introduced25.3.R2

Platforms

7705 SAR Gen 2

udp
Synopsis Enter the udp context
Context configure service nat nat-policy external-named-item udp
Treeudp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

inbound-refresh boolean
Synopsis Extend UDP session timeout on inbound traffic
Contextconfigure service nat nat-policy external-named-item udp inbound-refresh boolean
Treeinbound-refresh

Description

When configured to true, this command extends the UDP session timeout on inbound traffic. 

When configured to false, the UDP session timeout is not extended.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

oper-group [name] named-item

Synopsis Enter the oper-group list instance
Contextconfigure service oper-group named-item
Treeoper-group
Max. instances32768
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[name] named-item
Synopsis Operational group name
Context configure service oper-group named-item
Treeoper-group
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd-liveness
Synopsis Enable the bfd-liveness context
Contextconfigure service oper-group named-item bfd-liveness
Treebfd-liveness
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dest-ip ipv4-unicast-address
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDestination address for BFD
Contextconfigure service oper-group named-item bfd-liveness dest-ip ipv4-unicast-address
Treedest-ip

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface-name interface-name
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSource interface name
Contextconfigure service oper-group named-item bfd-liveness interface-name interface-name
Treeinterface-name
String length1 to 32

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

router-instance string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisRouting context used for route lookup
Contextconfigure service oper-group named-item bfd-liveness router-instance string
Treerouter-instance

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

hold-time
Synopsis Enter the hold-time context
Context configure service oper-group named-item hold-time
Treehold-time
Introduced25.3.R2

Platforms

7705 SAR Gen 2

down number
Synopsis Oper group hold down time
Context configure service oper-group named-item hold-time down number
Treedown
Range1 to 3600
Unitsseconds
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

up number
Synopsis Oper group hold up time
Context configure service oper-group named-item hold-time up number
Treeup
Range0 to 3600
Unitsseconds
Default 4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

proxy-arp-nd

Synopsis Enter the proxy-arp-nd context
Contextconfigure service proxy-arp-nd
Treeproxy-arp-nd
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac-list
Synopsis Enter the mac-list context
Context configure service proxy-arp-nd mac-list
Treemac-list
Introduced25.3.R2

Platforms

7705 SAR Gen 2

list [list-name] named-item
Synopsis Enter the list list instance
Context configure service proxy-arp-nd mac-list list named-item
Treelist
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[list-name] named-item
Synopsis Specify name for mac list
Context configure service proxy-arp-nd mac-list list named-item
Treelist
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac [address] mac-unicast-address-no-zero
Synopsis Add a list entry for mac
Context configure service proxy-arp-nd mac-list list named-item mac mac-unicast-address-no-zero
Treemac
Max. instances10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[address] mac-unicast-address-no-zero
Synopsis MAC address to be added to the list
Context configure service proxy-arp-nd mac-list list named-item mac mac-unicast-address-no-zero
Treemac

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

pw-template [pw-template-name] pw-template-name

Synopsis Enter the pw-template list instance
Contextconfigure service pw-template pw-template-name
Treepw-template
Max. instances2048
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[pw-template-name] pw-template-name
Synopsis SDP template name
Context configure service pw-template pw-template-name
Treepw-template
String length1 to 64

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

auto-gre-sdp boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisUse a GRE tunnel to automatically create an SDP
Contextconfigure service pw-template pw-template-name auto-gre-sdp boolean
Treeauto-gre-sdp
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

control-word boolean
Synopsis Enable/Disable the use of ControlWord
Contextconfigure service pw-template pw-template-name control-word boolean
Treecontrol-word
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

egress
Synopsis Enter the egress context
Context configure service pw-template pw-template-name egress
Treeegress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter
Synopsis Enter the filter context
Context configure service pw-template pw-template-name egress filter
Treefilter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip named-item-64
Synopsis IPv4 filter policy name
Context configure service pw-template pw-template-name egress filter ip named-item-64
Treeip
String length1 to 64
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6 named-item-64
Synopsis IPv6 filter policy name
Context configure service pw-template pw-template-name egress filter ipv6 named-item-64
Treeipv6
String length1 to 64
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac named-item-64
Synopsis MAC filter policy name
Context configure service pw-template pw-template-name egress filter mac named-item-64
Treemac
String length1 to 64
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mfib-allowed-mda-destinations
Synopsis Enter the mfib-allowed-mda-destinations context
Contextconfigure service pw-template pw-template-name egress mfib-allowed-mda-destinations
Treemfib-allowed-mda-destinations
Introduced25.3.R2

Platforms

7705 SAR Gen 2

qos
Synopsis Enter the qos context
Context configure service pw-template pw-template-name egress qos
Treeqos
Introduced25.3.R2

Platforms

7705 SAR Gen 2

network
Synopsis Enter the network context
Context configure service pw-template pw-template-name egress qos network
Treenetwork
Introduced25.3.R2

Platforms

7705 SAR Gen 2

port-redirect-group
Synopsis Enter the port-redirect-group context
Contextconfigure service pw-template pw-template-name egress qos network port-redirect-group
Treeport-redirect-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

encryption-keygroup
Synopsis Enter the encryption-keygroup context
Contextconfigure service pw-template pw-template-name encryption-keygroup
Treeencryption-keygroup
Introduced25.3.R2

Platforms

7705 SAR Gen 2

fdb
Synopsis Enter the fdb context
Context configure service pw-template pw-template-name fdb
Treefdb
Introduced25.3.R2

Platforms

7705 SAR Gen 2

auto-learn-mac-protect-exclude-list named-item
Synopsis Name of the MAC protect exclusion list
Contextconfigure service pw-template pw-template-name fdb auto-learn-mac-protect-exclude-list named-item
Treeauto-learn-mac-protect-exclude-list

Description

This command configures the name of a MAC protect exclusion list.

Dynamically-learned MAC Source Addresses (SA) are protected if they are learned on an object with ALMP configured and no exclusion list is associated with the object, or if the MAC SA does not match any entry in an associated exclusion list.

An exclusion list can be used in multiple objects of a service. If a list is empty, ALMP does not exclude any learned MAC SAs from protection on the object.

String length1 to 32
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac-learning
Synopsis Enter the mac-learning context
Contextconfigure service pw-template pw-template-name fdb mac-learning
Treemac-learning
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac-pinning boolean
Synopsis Enable MAC address pinning on this spoke SDP
Contextconfigure service pw-template pw-template-name fdb mac-pinning boolean
Treemac-pinning
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

maximum-mac-addresses number
Synopsis Maximum number of MAC address entries in the FDB
Contextconfigure service pw-template pw-template-name fdb maximum-mac-addresses number
Treemaximum-mac-addresses

Description

This command specifies the maximum number of FDB entries for both learned and static MAC addresses for this PW template.

When the configured limit is reached, no new addresses are learned from the SAP or spoke SDP until at least one FDB entry is aged out or cleared.

When the configured limit is reached and the configure service pw-template fdb discard-unknown-source command is set to true for this PW template, packets with unknown source MAC addresses are discarded. If discard-unknown-source is set to false, the packets are forwarded if their destination MAC addresses are known, or flooded if their destination MAC addresses are unknown.

However, if the configure service vpls fdb discard-unknown command is set to true, packets with unknown destination MAC addresses are discarded, even if the limit of FDB entries on the specific VPLS instance is not reached.

When unconfigured, the PW template uses the global MAC learning limitations.

Range1 to 511999
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hash-label
Synopsis Enable the hash-label context
Context configure service pw-template pw-template-name hash-label
Treehash-label

Description

Commands in this context configure the use of hash labels for egress datapaths.

For information about hash-label handling, see the "Hash labels" section of the 7705 SAR Gen 2 MPLS Guide.

Notes

The following elements are part of a choice: entropy-label or hash-label.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

signal-capability
Synopsis Signal hash label capability to the remote PE
Contextconfigure service pw-template pw-template-name hash-label signal-capability
Treesignal-capability

Description

When configured, this command enables the signaling and negotiating of the hash label between the local and remote PE nodes.

The signaling process outcome determines whether the local PE inserts the hash label on the user packets. This outcome can override the local PE configuration. The node must withdraw the label it sent to its peer and send a new label mapping message with the new value of the F-bit in the flow label interface option sub-TLV of the pseudowire ID FEC element.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

igmp-snooping
Synopsis Enter the igmp-snooping context
Contextconfigure service pw-template pw-template-name igmp-snooping
Treeigmp-snooping
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ingress
Synopsis Enter the ingress context
Context configure service pw-template pw-template-name ingress
Treeingress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter
Synopsis Enter the filter context
Context configure service pw-template pw-template-name ingress filter
Treefilter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip named-item-64
Synopsis IPv4 filter policy name
Context configure service pw-template pw-template-name ingress filter ip named-item-64
Treeip
String length1 to 64
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6 named-item-64
Synopsis IPv6 filter policy name
Context configure service pw-template pw-template-name ingress filter ipv6 named-item-64
Treeipv6
String length1 to 64
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac named-item-64
Synopsis MAC filter policy name
Context configure service pw-template pw-template-name ingress filter mac named-item-64
Treemac
String length1 to 64
Introduced25.3.R2

Platforms

7705 SAR Gen 2

qos
Synopsis Enter the qos context
Context configure service pw-template pw-template-name ingress qos
Treeqos
Introduced25.3.R2

Platforms

7705 SAR Gen 2

network
Synopsis Enter the network context
Context configure service pw-template pw-template-name ingress qos network
Treenetwork
Introduced25.3.R2

Platforms

7705 SAR Gen 2

fp-redirect-group
Synopsis Enter the fp-redirect-group context
Contextconfigure service pw-template pw-template-name ingress qos network fp-redirect-group
Treefp-redirect-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

l2pt
Synopsis Enter the l2pt context
Context configure service pw-template pw-template-name l2pt
Treel2pt
Introduced25.3.R2

Platforms

7705 SAR Gen 2

termination
Synopsis Enable the termination context
Contextconfigure service pw-template pw-template-name l2pt termination
Treetermination
Introduced25.3.R2

Platforms

7705 SAR Gen 2

protocols
Synopsis Enter the protocols context
Context configure service pw-template pw-template-name l2pt termination protocols
Treeprotocols
Introduced25.3.R2

Platforms

7705 SAR Gen 2

path-mtu number
Synopsis MTU the SDP can transmit
Context configure service pw-template pw-template-name path-mtu number
Treepath-mtu

Description

This command configures the path MTU that the SDP can transmit.

When an SDP created using the PW template is in use by a service, the path MTU cannot be modified.

When not configured, the path MTU is derived from the network interface IP MTU.

Range576 to 9782
Introduced25.3.R2

Platforms

7705 SAR Gen 2

provisioned-sdp keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisProvisioned SDP type
Contextconfigure service pw-template pw-template-name provisioned-sdp keyword
Treeprovisioned-sdp
Optionsuse, prefer
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

pw-template-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPW template ID
Contextconfigure service pw-template pw-template-name pw-template-id number
Treepw-template-id
Range1 to 2147483647
Introduced25.3.R2

Platforms

7705 SAR Gen 2

split-horizon-group
Synopsis Enter the split-horizon-group context
Contextconfigure service pw-template pw-template-name split-horizon-group
Treesplit-horizon-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

fdb
Synopsis Enter the fdb context
Context configure service pw-template pw-template-name split-horizon-group fdb
Treefdb
Introduced25.3.R2

Platforms

7705 SAR Gen 2

saps
Synopsis Enter the saps context
Context configure service pw-template pw-template-name split-horizon-group fdb saps
Treesaps
Introduced25.3.R2

Platforms

7705 SAR Gen 2

name named-item
Synopsis Split horizon group name to which the SDP belongs
Contextconfigure service pw-template pw-template-name split-horizon-group name named-item
Treename
String length1 to 32
Introduced25.3.R2

Platforms

7705 SAR Gen 2

stp
Synopsis Enter the stp context
Context configure service pw-template pw-template-name stp
Treestp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of STP
Context configure service pw-template pw-template-name stp admin-state keyword
Treeadmin-state
Optionsenable, disable
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

auto-edge boolean
Synopsis Enable automatic detection of edge port characteristics
Contextconfigure service pw-template pw-template-name stp auto-edge boolean
Treeauto-edge

Description

When configured to true, the router automatically detects the edge port characteristics of the SAP or spoke SDP. The STP concludes there is no bridge behind the spoke SDP, the OPER_EDGE variable is dynamically set to true. If a BPDU is received, the OPER_EDGE variable is dynamically set to false.

When configured to false, the router disables automatic detection.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

edge-port boolean
Synopsis Designate SAP or SDP as an edge port
Context configure service pw-template pw-template-name stp edge-port boolean
Treeedge-port
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

link-type keyword
Synopsis Configure STP link-type
Context configure service pw-template pw-template-name stp link-type keyword
Treelink-type
Optionspt-pt, shared
Default pt-pt
Introduced25.3.R2

Platforms

7705 SAR Gen 2

path-cost number
Synopsis Configure path-cost
Context configure service pw-template pw-template-name stp path-cost number
Treepath-cost
Range1 to 200000000
Default10
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

priority number
Synopsis Configure STP priority
Context configure service pw-template pw-template-name stp priority number
Treepriority
Range0 to 255
Default128
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

root-guard boolean
Synopsis Enable/disable STP root-guard
Context configure service pw-template pw-template-name stp root-guard boolean
Treeroot-guard
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vc-type keyword
Synopsis Virtual circuit type associated with the SDP bind
Contextconfigure service pw-template pw-template-name vc-type keyword
Treevc-type
Optionsether, vlan
Default ether
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sdp [sdp-id] number

Synopsis Enter the sdp list instance
Context configure service sdp number
Treesdp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[sdp-id] number
Synopsis Service Destination Point (SDP) ID
Context configure service sdp number
Treesdp
Range1 to 32767

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

accounting-policy reference
Synopsis Accounting policy associated with an SDP
Contextconfigure service sdp number accounting-policy reference
Treeaccounting-policy

Description

This command associates an accounting policy with an SDP.

When unconfigured, there is no accounting policy applied to the SDP.

Reference

configure log accounting-policy number

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the SDP
Context configure service sdp number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

adv-mtu-override boolean
Synopsis Override the advertised VC-type MTU using the SDP ID
Contextconfigure service sdp number adv-mtu-override boolean
Treeadv-mtu-override
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp-tunnel boolean
Synopsis Allow use of BGP route tunnels to reach far-end nodes
Contextconfigure service sdp number bgp-tunnel boolean
Treebgp-tunnel
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

booking-factor number
Synopsis Percentage of SDP max available bandwidth for VLL CAC
Contextconfigure service sdp number booking-factor number
Treebooking-factor
Range0 to 1000
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

collect-stats boolean
Synopsis Collect accounting statistics for this SDP
Contextconfigure service sdp number collect-stats boolean
Treecollect-stats
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

delivery-type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDelivery type used by the SDP
Contextconfigure service sdp number delivery-type keyword
Treedelivery-type
Optionsgre, mpls, l2tpv3, gre-eth-bridged
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service sdp number description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

far-end
Synopsis Enter the far-end context
Context configure service sdp number far-end
Treefar-end
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIP address of the far end destination router
Contextconfigure service sdp number far-end ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeip-address
Introduced25.3.R2

Platforms

7705 SAR Gen 2

keep-alive
Synopsis Enter the keep-alive context
Context configure service sdp number keep-alive
Treekeep-alive
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of keepalive mechanism for the SDP
Contextconfigure service sdp number keep-alive admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hello-time number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTime period between SDP keepalive messages
Contextconfigure service sdp number keep-alive hello-time number
Treehello-time
Range1 to 3600
Unitsseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hold-down-time number
Synopsis Minimum time the SDP remains in the down state
Contextconfigure service sdp number keep-alive hold-down-time number
Treehold-down-time
Range0 to 3600
Unitsseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

timeout number
Synopsis Time SDP waits before tearing down the session
Contextconfigure service sdp number keep-alive timeout number
Treetimeout
Range1 to 10
Unitsseconds
Default 5
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ldp boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable LDP-signaled LSPs
Contextconfigure service sdp number ldp boolean
Treeldp
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

local-end (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal end address of tunnel defined by the SDP
Contextconfigure service sdp number local-end (ipv4-address-no-zone | ipv6-address-no-zone)
Treelocal-end
Introduced25.3.R2

Platforms

7705 SAR Gen 2

lsp [lsp-name] named-item-64
Synopsis Add a list entry for lsp
Context configure service sdp number lsp named-item-64
Treelsp
Max. instances16
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[lsp-name] named-item-64
Synopsis LSP name to associate with the SDP
Context configure service sdp number lsp named-item-64
Treelsp
String length1 to 64

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

metric number
Synopsis Metric used in tunnel table manager for decision making
Contextconfigure service sdp number metric number
Treemetric
Range1 to 65535
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mixed-lsp-mode
Synopsis Enable the mixed-lsp-mode context
Contextconfigure service sdp number mixed-lsp-mode
Treemixed-lsp-mode
Introduced25.3.R2

Platforms

7705 SAR Gen 2

revert-time (number | keyword)
Synopsis Delay before SDP can revert to higher priority LSP type
Contextconfigure service sdp number mixed-lsp-mode revert-time (number | keyword)
Treerevert-time
Range1 to 600
Unitsseconds
Options never, immediate
Defaultimmediate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

path-mtu number
Synopsis Maximum Transmission Unit (MTU) the SDP can transmit
Contextconfigure service sdp number path-mtu number
Treepath-mtu
Range576 to 9782
Unitsbytes
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

signaling keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSignaling protocol used to obtain pseudowire labels
Contextconfigure service sdp number signaling keyword
Treesignaling

Description

This command specifies the signaling protocol used to obtain the ingress and egress pseudowire labels in frames transmitted and received on the SDP. The signaling value can only be changed while the administrative status of the SDP is down. Additionally, the signaling can only be changed on an SDP if the SDP is not in use by BGP-AD or BGP-VPLS. BGP signaling can only be enabled if the SDP does not already have pseudowires signaled over it. Also, BGP signaling is not supported with mixed mode LSP SDPs.

Note: If the tldp option is selected as the mechanism for exchanging service labels over an MPLS or GRE SDP and the T-LDP session is automatically established, an explicit T-LDP session that is subsequently configured takes precedence over the automatic T-LDP session. However, if the explicit, manually-configured session is then removed, the system does not revert to the automatic session and the automatic session is also deleted. To address this, recreate the T-LDP session by using the admin-state command to administratively disable and then enable the SDP.

Optionsoff, tldp, bgp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sr-isis boolean
Synopsis Enable Segment Routing for IS-IS
Context configure service sdp number sr-isis boolean
Treesr-isis
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sr-ospf boolean
Synopsis Enable an MPLS SDP of LSP type OSPF Segment Routing
Contextconfigure service sdp number sr-ospf boolean
Treesr-ospf
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

tunnel-far-end (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSystem address of the far-end router for the SDP
Contextconfigure service sdp number tunnel-far-end (ipv4-address-no-zone | ipv6-address-no-zone)
Treetunnel-far-end
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vlan-vc-etype etype-value
Synopsis VLAN VC Ethertype
Context configure service sdp number vlan-vc-etype etype-value
Treevlan-vc-etype
String length5 to 6
Default0x8100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

weighted-ecmp boolean
Synopsis Allow weighted load-balancing on an SDP
Contextconfigure service sdp number weighted-ecmp boolean
Treeweighted-ecmp
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sdp-group

Synopsis Enter the sdp-group context
Context configure service sdp-group
Treesdp-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

group-name [group-name] named-item
Synopsis Enter the group-name list instance
Contextconfigure service sdp-group group-name named-item
Treegroup-name
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[group-name] named-item
Synopsis SDP administrative group name
Context configure service sdp-group group-name named-item
Treegroup-name
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

value number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisUnique group value associated with the SDP admin group
Contextconfigure service sdp-group group-name named-item value number
Treevalue
Range0 to 31

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

system

Synopsis Enter the system context
Context configure service system
Treesystem
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp
Synopsis Enter the bgp context
Context configure service system bgp
Treebgp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

evpn
Synopsis Enter the evpn context
Context configure service system bgp evpn
Treeevpn

Description

Commands in this context configure BGP EVPN options.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ad-per-es-route
Synopsis Enter the ad-per-es-route context
Contextconfigure service system bgp evpn ad-per-es-route
Treead-per-es-route
Introduced25.3.R2

Platforms

7705 SAR Gen 2

extended-evi-range boolean
Synopsis Reserve extended RD comm-values for AD per-ES routes
Contextconfigure service system bgp evpn ad-per-es-route extended-evi-range boolean
Treeextended-evi-range

Description

When configured to true, the system reserves the Route Distinguisher (RD) comm-values 1 to 65535 out of the type 1 RD that is used for AD per-ES routes. If ad-per-es-route route-target-type is also configured to evi-route-target-set, the system can pack the maximum number of EVI route targets in the AD per-ES routes

When configured to false, this command only reserves comm-values 1 to 512.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ad-per-evi-routes
Synopsis Enter the ad-per-evi-routes context
Contextconfigure service system bgp evpn ad-per-evi-routes
Treead-per-evi-routes
Introduced25.3.R2

Platforms

7705 SAR Gen 2

attribute-propagation boolean
Synopsis Enable propagation of BGP path attributes
Contextconfigure service system bgp evpn ad-per-evi-routes attribute-propagation boolean
Treeattribute-propagation

Description

When configured to true, the router propagates the attributes in multi-instance Epipe services.

When configured to false, the router disables the propagation of the attributes, including D-PATH, even if the domain-id is configured in the service.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp-path-selection boolean
Synopsis Enable BGP path selection
Context configure service system bgp evpn ad-per-evi-routes bgp-path-selection boolean
Treebgp-path-selection

Description

When configured to true, the router compares the received EVPN VPWS AD per-EVI routes based on the BGP path attributes.

The attribute-propagation command must be configured to true.

When configured to false, the router does not compare the routes.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

d-path-ignore boolean
Synopsis Ignore D-PATH for BGP path selection
Context configure service system bgp evpn ad-per-evi-routes d-path-ignore boolean
Treed-path-ignore

Description

When configured to true, the router ignores the Domain PATH attribute (D-PATH) when BGP computes the best path selection for received routes.

When configured to false, the router considers the D-PATH length and value as a tiebreaker in determining the best-path selection. In accordance with draft-sr-bess-evpn-dpath, the router compares the D-PATH attribute received in AD per-EVI routes with the same key (same or different RD) as follows:

  • Routes with the shortest D-PATH are preferred; therefore, routes not tied for the shortest D-PATH are removed. Routes without D-PATH are considered zero-length D-PATH.

  • Routes with the numerically lowest left-most Domain-ID are preferred; therefore, routes not tied for the numerically lowest left-most Domain-ID are removed from consideration.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

etree-leaf-label boolean
Synopsis Enable E-Tree leaf label for PE
Context configure service system bgp evpn etree-leaf-label boolean
Treeetree-leaf-label

Description

When configured to true, this command enables EVPN Ethernet-Tree (E-Tree) VPLS services on the router (not B-VPLS), allocates an E-Tree leaf label for the Provider Edge (PE) device, and configures the ILM entry.This command ensures that in-flight traffic can perform an ILM entry lookup at any time, and avoids discards when administratively enabling or disabling services, or reduces the timing window so that it does not occur during normal operation or configuration. The value for the E-Tree leaf label is set via the etree-leaf-label-value command.

When configured to false, PE leaf labels are not supported.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-prefix-routes
Synopsis Enter the ip-prefix-routes context
Contextconfigure service system bgp evpn ip-prefix-routes
Treeip-prefix-routes
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface-ful
Synopsis Enter the interface-ful context
Contextconfigure service system bgp evpn ip-prefix-routes interface-ful
Treeinterface-ful

Description

Commands in this context configure IP prefix routes for Interface-ful (IFF) configurations.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

attribute-uniform-propagation boolean
Synopsis Enable attribute uniform propagation
Context configure service system bgp evpn ip-prefix-routes interface-ful attribute-uniform-propagation boolean
Treeattribute-uniform-propagation

Description

When configured to true, the system enables the uniform propagation of BGP attributes for EVPN-IFF routes.

When configured to false, the system re-originates the BGP path attributes when propagating EVPN-IFF routes into other inter-subnet forwarding families.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp-path-selection boolean
Synopsis Enable BGP path selection
Context configure service system bgp evpn ip-prefix-routes interface-ful bgp-path-selection boolean
Treebgp-path-selection

Description

When configured to true, the system enables BGP path selection for EVPN-IFF routes. The EVPN-IFF routes are ordered and selected in a similar manner as IP-VPN or EVPN-IFL routes, that is, based on the regular BGP path selection process.

When configured to false, the system orders EVPN-IFF routes based on their {R-VPLS Ifindex, RD, Ethernet Tag}. For example, if two EVPN-IFF routes with different Route Distinguishers (RDs) are received for the same prefix on the same R-VPLS, the route with the lowest RD is selected.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

multicast-leave-sync-propagation number
Synopsis Multicast leave group synchronization delay
Contextconfigure service system bgp evpn multicast-leave-sync-propagation number
Treemulticast-leave-sync-propagation

Description

This command configures the additional amount of time that the system waits before removing a multicast state that was synchronized in an Ethernet Segment via Multicast Join or Leave Synch routes. This value represents a delta corresponding to the time it takes for a BGP advertisement to propagate to ES peers.

The node triggering the route computes the maximum response time as the product of the locally configured values, Last Member Query Count and Last Member Query Interval, and adds the delta value to the maximum response time. The query count value is configured in the configure services vrpn igmp robust-count command. The query interval value is taken from the configure service vpls sap igmp-snooping query-last-member-interval or the configure service vpls spoke-sdp igmp-snooping query-last-member-interval configuration, depending on the Ethernet Segment.

Increasing the maximum response time by this value can help minimize the churn of removing and recreating the state on the node.

This value should be configured consistently in all ES peers.

Range0 to 300
Unitsseconds
Default 5
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp-auto-rd-range
Synopsis Enter the bgp-auto-rd-range context
Contextconfigure service system bgp-auto-rd-range
Treebgp-auto-rd-range
Introduced25.3.R2

Platforms

7705 SAR Gen 2

community-value
Synopsis Enter the community-value context
Contextconfigure service system bgp-auto-rd-range community-value
Treecommunity-value
Introduced25.3.R2

Platforms

7705 SAR Gen 2

fdb
Synopsis Enter the fdb context
Context configure service system fdb
Treefdb
Introduced25.3.R2

Platforms

7705 SAR Gen 2

table-size number
Synopsis Maximum FDB entries in the system
Context configure service system fdb table-size number
Treetable-size

Description

This command configures the maximum system FDB table size, which is dependent on the chassis type.

CPMs with at least 16 GB of memory are required when exceeding 500 000 MAC addresses in a system. This command cannot be set to a value lower than the default, which is chassis-dependent. The maximum system FDB table size also limits the maximum FDB table size of any card within the system.

The command default depends on the chassis type and available memory.

Range4095 to 2047999
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vpls [service-name] service-name

Synopsis Enter the vpls list instance
Context configure service vpls service-name
Treevpls

Description

Commands in this context create or edit a Virtual Private LAN Services (VPLS) instance.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[service-name] service-name
Synopsis Administrative service name
Context configure service vpls service-name
Treevpls
String length1 to 64

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the service
Context configure service vpls service-name admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp [bgp-instance] number
Synopsis Enter the bgp list instance
Context configure service vpls service-name bgp number
Treebgp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[bgp-instance] number
Synopsis BGP instance
Contextconfigure service vpls service-name bgp number
Treebgp
Range1 to 2

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

adv-service-mtu number
Synopsis Advertised service MTU value
Context configure service vpls service-name bgp number adv-service-mtu number
Treeadv-service-mtu

Description

This command configures the MTU signaled value used in the BGP for BGP-VPLS service and in the LDP for BGP-AD service. The router uses the value for signaling and for validation with the received MTU instead of the service MTU. However, the value does not affect the locally enforced value, which is still based on the service MTU.

Range0 to 9782
Introduced25.3.R2

Platforms

7705 SAR Gen 2

pw-template-binding [pw-template-name] reference
Synopsis Enter the pw-template-binding list instance
Contextconfigure service vpls service-name bgp number pw-template-binding reference
Treepw-template-binding
Max. instances100
Introduced25.3.R2

Platforms

7705 SAR Gen 2

import-rt route-target
Synopsis Import route-target communities
Context configure service vpls service-name bgp number pw-template-binding reference import-rt route-target
Treeimport-rt
String length10 to 28
Max. instances5
Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-distinguisher (keyword | vpn-route-distinguisher)
Synopsis High-order 6 bytes that are used as string to compose VSI-ID for use in NLRI
Contextconfigure service vpls service-name bgp number route-distinguisher (keyword | vpn-route-distinguisher)
Treeroute-distinguisher
Optionsauto-rd
Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-target
Synopsis Enter the route-target context
Contextconfigure service vpls service-name bgp number route-target
Treeroute-target
Introduced25.3.R2

Platforms

7705 SAR Gen 2

export route-target
Synopsis Extended community name for default import policy
Contextconfigure service vpls service-name bgp number route-target export route-target
Treeexport
String length10 to 28
Introduced25.3.R2

Platforms

7705 SAR Gen 2

import route-target
Synopsis Extended community name for default import policy
Contextconfigure service vpls service-name bgp number route-target import route-target
Treeimport
String length10 to 28
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp-ad
Synopsis Enable the bgp-ad context
Context configure service vpls service-name bgp-ad
Treebgp-ad
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of BGP Auto-Discovery
Contextconfigure service vpls service-name bgp-ad admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vpls-id vpls-id
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisVPLS identifier as a 8-byte route distinguisher
Contextconfigure service vpls service-name bgp-ad vpls-id vpls-id
Treevpls-id
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vsi-id-prefix ipv4-address
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisVSI prefix value
Contextconfigure service vpls service-name bgp-ad vsi-id-prefix ipv4-address
Treevsi-id-prefix
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp-evpn
Synopsis Enable the bgp-evpn context
Context configure service vpls service-name bgp-evpn
Treebgp-evpn

Description

Commands in this context to configure the BGP-EVPN options.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

evi number
Synopsis EVPN ID
Contextconfigure service vpls service-name bgp-evpn evi number
Treeevi

Description

This command configures a 2-byte EVPN instance (EVI) unique in the system. It is used for the service-carving algorithm for multi-homing and auto-deriving route target and route distinguishers.

If not specified, the EVPN ID value is zero and no route distinguisher or route targets are auto-derived from it.

If the EVI ID value is specified and no other route-distinguisher or route-target is configured in the service, the following rules apply:

  • the route distinguisher is derived from <system_ip>:evi

  • the route target is derived from <autonomous-system>:evi

If VSI import and export policies are configured, the route target must be configured in the policies and those values take precedence over the auto-derived route targets. If bgp-ad vpls-id and bgp-evpn evi are both configured on the same service, the VPLS ID auto-derived route target or route distinguisher takes precedence over the values auto-derived from the EVI. Use the show service id bgp command to display the operational route target for a service.

Range1 to 16777215
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ignore-mtu-mismatch boolean
Synopsis Ignore MTU mismatch
Context configure service vpls service-name bgp-evpn ignore-mtu-mismatch boolean
Treeignore-mtu-mismatch

Description

When configured to true, the system ignores the received Layer 2 MTU in the L2 Attributes extended community of the IMET route for a peer.

When configured to false, the system compares the local service MTU against the received Layer 2 MTU and if there is a mismatch, keeps the EVPN destination to the peer with operational state down.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac-duplication
Synopsis Enter the mac-duplication context
Contextconfigure service vpls service-name bgp-evpn mac-duplication
Treemac-duplication

Description

Commands in this context configure the BGP EVPN MAC duplication command options.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

detect
Synopsis Enter the detect context
Context configure service vpls service-name bgp-evpn mac-duplication detect
Treedetect

Description

Commands in this context monitor the number of moves of a MAC address for a period of time (window).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

trusted-mac-move-factor number
Synopsis Trusted MAC move factor
Context configure service vpls service-name bgp-evpn mac-duplication detect trusted-mac-move-factor number
Treetrusted-mac-move-factor

Description

This command configures the factor by which the number of moves is multiplied when detecting a MAC duplication event for trusted MACs. For example, if the number of moves is 5 and the trusted MAC move factor is 3, 5 moves, within the window, is enough to declare a non-trusted MAC as duplicate. However, 15 moves are needed to declare a trusted MAC as duplicate.

By default the factor for a trusted MAC is the same as for a non-trusted MAC. This provides a backwards compatible solution upon upgrade of the node.

Range1 to 10
Default1
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

retry (number | keyword)
Synopsis BGP EVPN MAC duplication retry time
Context configure service vpls service-name bgp-evpn mac-duplication retry (number | keyword)
Treeretry
Range2 to 60
Unitsminutes
Options never
Default 9
Introduced25.3.R2

Platforms

7705 SAR Gen 2

trusted-mac-time number
Synopsis Trusted MAC time
Context configure service vpls service-name bgp-evpn mac-duplication trusted-mac-time number
Treetrusted-mac-time

Description

This command configures how long a MAC address needs to stay in the FDB as type learned without being flushed or changed in its type so the MAC is declared as trusted for the MAC duplication procedures. If the MAC changes from SAP to SAP within the same VPLS service and node, the MAC does not reset its trusted MAC timer.

Range1 to 15
Unitsminutes
Default 5
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mpls [bgp-instance] number
Synopsis Enter the mpls list instance
Context configure service vpls service-name bgp-evpn mpls number
Treempls

Description

Commands in this context configure the BGP-EVPN MPLS options.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[bgp-instance] number
Synopsis BGP instance
Contextconfigure service vpls service-name bgp-evpn mpls number
Treempls
Range1 to 2

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of BGP EVPN MPLS
Contextconfigure service vpls service-name bgp-evpn mpls number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

auto-bind-tunnel
Synopsis Enter the auto-bind-tunnel context
Contextconfigure service vpls service-name bgp-evpn mpls number auto-bind-tunnel
Treeauto-bind-tunnel

Description

Commands in this context configure automatic binding of a VPRN service using tunnels to MP-BGP peers.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

allow-flex-algo-fallback boolean
Synopsis Enable flexible algorithm fallback
Context configure service vpls service-name bgp-evpn mpls number auto-bind-tunnel allow-flex-algo-fallback boolean
Treeallow-flex-algo-fallback

Description

When configured to true, a BGP router with a Flex-Algorithm action configured (via the configure policy-options policy-statement entry action flex-algo command) can resolve to a tunnel with algorithm 0 if no target Flex-Algorithm tunnel is available.

When configured to false, the BGP router can resolve only to the intended Flex-Algorithm tunnel, which may cause traffic loss if no corresponding Flex-Algorithm tunnel is available.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

enforce-untagged-route keyword
Synopsis Untagged route type enforcement
Context configure service vpls service-name bgp-evpn mpls number auto-bind-tunnel enforce-untagged-route keyword
Treeenforce-untagged-route

Description

This command configures the enforcement of BGP routes with no administrative tag policy applied by modifying the next-hop resolution behavior for autobind services.

If the untagged-tunnel option is configured, untagged routes only bind to LSPs with no administrative tag configured. If both tagged and untagged tunnels to the next hop exist, the system only considers the untagged tunnels. If no untagged tunnels to the next hop exist, the resolution of untagged routes fails.

The untagged-tunnel option can be used in combination with the enforce-strict-tunnel-tagging command configured to true, in which case tagged routes resolve to tagged LSPs, and untagged routes only resolve to untagged LSPs.

When unconfigured, untagged routes can bind to tagged or untagged LSPs.

Options

none – Untagged routes can bind to tagged or untagged LSPs

untagged-tunnel – Untagged routes only bind to LSPs without an admin tag

Defaultnone
Introduced25.3.R2

Platforms

7705 SAR Gen 2

resolution-filter
Synopsis Enter the resolution-filter context
Contextconfigure service vpls service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter
Treeresolution-filter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp boolean
Synopsis Use BGP tunneling for next-hop resolution
Contextconfigure service vpls service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter bgp boolean
Treebgp

Description

When configured to true, BGP searches the BGP LSP for the address of the BGP next hop.

When configured to false, BGP tunneling is not used and inter-area or inter-as prefixes are not resolved.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ldp boolean
Synopsis Use LDP tunneling for next-hop resolution
Contextconfigure service vpls service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter ldp boolean
Treeldp

Description

When configured to true, BGP searches for an LDP LSP with a FEC prefix corresponding to the address of the BGP next hop.

When configured to false, LDP tunneling is not used for next-hop resolution.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

rsvp boolean
Synopsis Use RSVP tunneling for next-hop resolution
Contextconfigure service vpls service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter rsvp boolean
Treersvp

Description

When configured to true, BGP searches the best metric RSVP LSP to determine the address of the BGP next hop. This address can correspond to the system interface or to another loopback interface used by the BGP instance on the remote node. The LSP metric is provided by MPLS in the tunnel table. In the case of multiple RSVP LSPs with the same lowest metric, BGP selects the LSP with the lowest tunnel ID.

When configured to false, the RSVP LSP is not used for next-hop resolution.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sr-isis boolean
Synopsis Use IS-IS SR tunneling for next-hop resolution
Contextconfigure service vpls service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-isis boolean
Treesr-isis

Description

When configured to true, BGP uses an IS-IS tunnel type to resolve the BGP next hop.

When the sr-isis command is enabled, an SR tunnel to the BGP next hop is selected in the TTM according to the following procedure.

  • Select the SR tunnel submitted by the IS-IS instance with the lowest tunnel table preference.

  • If more than one SR tunnel exists, select the SR tunnel from the instance with the lowest metric.

  • If more than one SR tunnel exists, select the SR tunnel from the instance with the lowest instance ID.

When configured to false, IS-IS tunneling is not used for next-hop resolution.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sr-ospf boolean
Synopsis Use OSPF SR tunneling for next-hop resolution
Contextconfigure service vpls service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-ospf boolean
Treesr-ospf

Description

When configured to true, BGP uses an OSPF tunnel type to resolve the BGP next hop.

When enabled, an SR tunnel to the BGP next hop is selected in the TTM according to the following procedure.

  • Select the SR tunnel submitted by the OSPF instance with the lowest tunnel table preference.

  • If more than one SR tunnel exists, select the SR tunnel from the instance with the lowest metric.

  • If more than one SR tunnel exists, select the SR tunnel from the instance with the lowest instance ID.

When configured to false, OSPF tunneling is not used for next-hop resolution.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sr-ospf3 boolean
Synopsis Use OSPFv3 SR tunneling for next-hop resolution
Contextconfigure service vpls service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-ospf3 boolean
Treesr-ospf3

Description

When configured to true, BGP uses an OSPF3 tunnel type to resolve the BGP next hop.

When enabled, an SR tunnel to the BGP next hop is selected in the TTM according to the following procedure.

  • Select the SR tunnel submitted by the OSPFv3 instance with the lowest tunnel table preference.

  • If more than one SR tunnel exists, select the SR tunnel from the instance with the lowest metric.

  • If more than one SR tunnel exists, select the SR tunnel from the instance with the lowest instance ID.

When configured to false, OSPF3 tunneling is not used for next-hop resolution.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sr-policy boolean
Synopsis Use SR policies for next-hop resolution
Contextconfigure service vpls service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-policy boolean
Treesr-policy

Description

When configured to true, this command enables the use of SR policies to resolve the next hop of BGP-EVPN service routes.

This command configures BGP to search for an SR policy with:

  • a non-null endpoint that matches the next hop of the service route, and

  • a color value that matches the highest numbered color for the extended community attached to the service route

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sr-te boolean
Synopsis Use SR-TE tunneling for next-hop resolution
Contextconfigure service vpls service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-te boolean
Treesr-te

Description

When configured to true, BGP uses an SR-TE tunnel type to resolve the BGP next hop.

In the case of multiple SR-TE tunnels with the same lowest metric, BGP selects the tunnel with the lowest tunnel ID.

When configured to false, SR-TE tunneling is not used for next-hop resolution.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

weighted-ecmp boolean
Synopsis Allow weighted load balancing
Context configure service vpls service-name bgp-evpn mpls number auto-bind-tunnel weighted-ecmp boolean
Treeweighted-ecmp

Description

When configured to true, this router enables weighted ECMP for packets using tunnels that a VPLS or Epipe automatically binds to. Packets are sprayed across LSPs in the ECMP according to the outcome of the hash algorithm and the configured load balancing weight of each LSP.

When configured to false, this command disables weighted ECMP for next-hop tunnel selection.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

control-word boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable control word support
Contextconfigure service vpls service-name bgp-evpn mpls number control-word boolean
Treecontrol-word

Description

When configured to true, the router enables the transmission and reception of the control word for all EVPN-MPLS destinations at the same time.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

default-route-tag one-byte-value
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDefault route tag
Contextconfigure service vpls service-name bgp-evpn mpls number default-route-tag one-byte-value
Treedefault-route-tag

Description

This command configures a route tag that is used when sending a route to the BGP application (for the corresponding service and BGP instance). If the corresponding BGP instance is enabled, the command cannot be changed.

When used for BGP EVPN contexts, only one route tag can be passed to BGP for matching on export policies. In case of a conflict with other route tags pushed by EVPN, the default route tag has the least priority.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

dynamic-egress-label-limit boolean
Synopsis Enables dynamic egress label limit
Context configure service vpls service-name bgp-evpn mpls number dynamic-egress-label-limit boolean
Treedynamic-egress-label-limit

Description

When configured to true, this command relaxes the egress MPLS label limit check when resolving BGP next hops in the tunnel table.

For VPRN services, the OAM label is never computed and, therefore, one more egress label is allowed.

For EVPN (Epipe and VPLS) services, the system only computes the control word and ESI label if they are used. For the control word, the system reduces the egress label limit by one label if the control word is configured in the service. When configured, the ESI label is not counted for Epipes or VPLS services without an ES.

When configured to false this command, for EVPN, Epipe, and VPLS services, always accounts for the ESI label and control word.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

evi-three-byte-auto-rt boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAuto-derive the BGP EVPN route target
Contextconfigure service vpls service-name bgp-evpn mpls number evi-three-byte-auto-rt boolean
Treeevi-three-byte-auto-rt

Description

When configured to true, the BGP-EVPN instance import and export route target is auto-derived as described in RFC 8365 (Global-Administrator:A/Type/D-ID/Service-ID).

Where:

  • Global Administrator – is the configured 2-octet AS number; if the configured ASN exceeds the 2 byte limit, the low order 16-bit value is taken

  • A=0 (for auto-derivation)

  • Type=4 (EVI-based route-target)

  • D-ID= [1..2] – encodes the BGP instance, which allows the auto-derivation of different route-targets in multi-instance services; the value is inherited from the corresponding BGP instance

  • Service ID=3-octet EVI

When configured to false, route target derivation is not allowed.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hash-label boolean
Synopsis Default profile when the CP-provided profile is unknown
Contextconfigure service vpls service-name bgp-evpn mpls number hash-label boolean
Treehash-label

Description

When configured to true, the router pushes the hash label.

The hash label is never used for BUM packets.

The hash-label push is based on the following:

  • If advertise-l2-attributes (in the configure service vpls bgp-evpn routes incl-mcast context) is set to false, the hash label is pushed to a unicast EVPN destination.

  • If advertise-l2-attributes is set to true, the F bit is set to 1 in the Layer 2 Attributes Extended Community of the EVPN IMET route for the service. The hash label is pushed only if the remote PE signaled support for hash label (received F bit is set to 1).

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mh-mode keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMultihoming mode
Contextconfigure service vpls service-name bgp-evpn mpls number mh-mode keyword
Treemh-mode

Description

This command configures the multihoming mode for BGP-EVPN. Users can configure only one network instance for the service.

If a provider tunnel is enabled for the service instance, this command must be configured using the network option.

Optionsaccess, network
Default network
Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-next-hop
Synopsis Enter the route-next-hop context
Contextconfigure service vpls service-name bgp-evpn mpls number route-next-hop
Treeroute-next-hop

Description

Commands in this context configure the next hop of the EVPN routes.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIP address of the next-hop for the service EVPN route
Contextconfigure service vpls service-name bgp-evpn mpls number route-next-hop ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeip-address

Notes

The following elements are part of a choice: ip-address, system-ipv4, or system-ipv6.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

system-ipv4
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSystem IPv4 address for service EVPN route next hop
Contextconfigure service vpls service-name bgp-evpn mpls number route-next-hop system-ipv4
Treesystem-ipv4

Notes

The following elements are part of a choice: ip-address, system-ipv4, or system-ipv6.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

system-ipv6
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSystem IPv6 address for service EVPN route next hop
Contextconfigure service vpls service-name bgp-evpn mpls number route-next-hop system-ipv6
Treesystem-ipv6

Notes

The following elements are part of a choice: ip-address, system-ipv4, or system-ipv6.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

send-tunnel-encap
Synopsis Enter the send-tunnel-encap context
Contextconfigure service vpls service-name bgp-evpn mpls number send-tunnel-encap
Treesend-tunnel-encap
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mpls boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable MPLS encapsulation
Contextconfigure service vpls service-name bgp-evpn mpls number send-tunnel-encap mpls boolean
Treempls
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

split-horizon-group reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSplit horizon group
Contextconfigure service vpls service-name bgp-evpn mpls number split-horizon-group reference
Treesplit-horizon-group

Description

This command configures the value of split-horizon group for all BGP-EVPN segment routing v6 instances.

Reference

configure service vpls service-name split-horizon-group named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

routes
Synopsis Enter the routes context
Context configure service vpls service-name bgp-evpn routes
Treeroutes
Introduced25.3.R2

Platforms

7705 SAR Gen 2

incl-mcast
Synopsis Enter the incl-mcast context
Context configure service vpls service-name bgp-evpn routes incl-mcast
Treeincl-mcast
Introduced25.3.R2

Platforms

7705 SAR Gen 2

advertise-l2-attributes boolean
Synopsis Advertise Layer 2 attributes
Context configure service vpls service-name bgp-evpn routes incl-mcast advertise-l2-attributes boolean
Treeadvertise-l2-attributes

Description

When configured to true, the router advertises the Layer 2 Attributes Extended Community including:

  • the service MTU in the Layer 2 MTU field

  • the F bit, which is set to 1 if the hash-label command is set to true (in the configure service vpls bgp-evpn mpls context); otherwise, the F bit is set to 0

  • the C bit, which is set to 1 if the control-word command is set to true (in the configure service vpls bgp-evpn mpls context); otherwise, the C bit is set to 0

The router compares the received Layer 2 MTU from a peer with the local service MTU. If there is a mismatch, the operation state of the EVPN destination is set to down, except if the configure service vpls bgp-evpn ignore-mtu-mistmatch command is set to true.

A mismatch between the received C bit and the local control-word setting (in the configure service vpls bgp-evpn mpls context) results in the operational state of the EVPN destination being set to down.

A mismatch between the received F bit and the local F bit (via the hash label configuration) results in the operational state of the EVPN destination being set to down.

When configured to false, the Layer 2 Attributes Extended Community is not advertised with the Inclusive Multicast Ethernet Tag route for the service.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-prefix
Synopsis Enter the ip-prefix context
Context configure service vpls service-name bgp-evpn routes ip-prefix
Treeip-prefix
Introduced25.3.R2

Platforms

7705 SAR Gen 2

domain-id domain-id
Synopsis Domain ID of received BGP route before readvertisement
Contextconfigure service vpls service-name bgp-evpn routes ip-prefix domain-id domain-id
Treedomain-id

Description

This command specifies the domain ID. The domain ID identifies the network from which the BGP route was received before the RTM advertises it to a different neighbor. The domain ID is part of a domain, represented as domain-id:isf_safi_type in the D-PATH attribute, as described in draft-ietf-bess-evpn-ipvpn-interworking. Gateway routers modify the D-PATH attribute. A gateway is a PE where a VPRN is instantiated. The VPRN in this case advertises or receives routes from multiple BGP owners (for example, EVPN-IFL and BGP-IPVPN) or multiple instances of the same owner (for example, VPRN with two BGP-IPVPN instances).

Gateways use the D-PATH attribute to detect loops (for received routes where the D-PATH contains a local domain ID) and to make BGP best-path selection decisions based on the D-PATH length (shorter D-PATH is preferred).

In the following example, suppose a gateway receives prefix P in an EVPN-IFL instance with the following D-PATH from neighbor N:

Seg Len=1 / 65000:1:128

If the router imports the route in VPRN-1, BGP-EVPN SRv6 instance with domain 65000:2, it readvertises it to its BGP-IPVPN MPLS instance as follows:

Seg Len=2 / 65000:2:70 / 65000:1:128

That is, the gateway prepends the local domain ID and family to the D-PATH before readvertising the route into a different instance.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

link-bandwidth
Synopsis Enter the link-bandwidth context
Contextconfigure service vpls service-name bgp-evpn routes ip-prefix link-bandwidth
Treelink-bandwidth
Introduced25.3.R2

Platforms

7705 SAR Gen 2

advertise
Synopsis Enable the advertise context
Context configure service vpls service-name bgp-evpn routes ip-prefix link-bandwidth advertise
Treeadvertise
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac-ip
Synopsis Enter the mac-ip context
Context configure service vpls service-name bgp-evpn routes mac-ip
Treemac-ip
Introduced25.3.R2

Platforms

7705 SAR Gen 2

arp-nd-extended-community boolean
Synopsis Enable ARP/ND extended community
Context configure service vpls service-name bgp-evpn routes mac-ip arp-nd-extended-community boolean
Treearp-nd-extended-community

Description

When configured to true, the system advertises the RFC9047 ARP/ND extended community along with the MAC/IP routes advertised for local static and dynamic proxy ARP or ND entries. The system also processes the ARP/ND extended community and selects the ARP or ND entries based on the immutable flag.

When configured to false, the system does not advertise the RFC9047 ARP/ND extended community.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

arp-nd-only-with-fdb-advertisement boolean
Synopsis Advertise ARP/ND entries if local MAC is in the FDB
Contextconfigure service vpls service-name bgp-evpn routes mac-ip arp-nd-only-with-fdb-advertisement boolean
Treearp-nd-only-with-fdb-advertisement

Description

When configured to true, the router advertises local ARP/ND entries of VPRN interfaces using this VPLS in this BGP-EVPN service when the corresponding local MAC is programmed in the FDB.

When configured to false, the router does not advertise local ARP/ND entries.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vlan-aware-bundle-eth-tag number
Synopsis Ethernet tag associated with VPLS service
Contextconfigure service vpls service-name bgp-evpn routes vlan-aware-bundle-eth-tag number
Treevlan-aware-bundle-eth-tag

Description

This command configures the Ethernet Tag ID in the EVPN routes for control-plane interoperability mode with VLAN-aware bundle services. The configuration of a non-default value requires the previous configuration of a VLAN-aware bundle name on the service.

When set to a non-zero value, the EVPN routes advertised for the VPLS service are advertised with this value into the Ethernet Tag ID field of the routes.

On reception of EVPN routes with non-zero Ethernet Tag ID, BGP imports the routes based on the import route target as usual. However, the system checks the received Ethernet Tag ID field and only processes those routes whose Ethernet Tag ID matches the local VLAN-aware bundle Ethernet Tag ID.

Range1 to 16777215
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vlan-aware-bundle named-item
Synopsis VLAN aware bundle name
Context configure service vpls service-name bgp-evpn vlan-aware-bundle named-item
Treevlan-aware-bundle

Description

This command configures the name that identifies a group of bundled VPLS services (broadcast domains). This name allows the user to execute show commands that are relevant to all the broadcast domains in a VLAN-aware bundle service group.

String length1 to 32
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp-mh-site [site-name] named-item
Synopsis Enter the bgp-mh-site list instance
Contextconfigure service vpls service-name bgp-mh-site named-item
Treebgp-mh-site
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[site-name] named-item
Synopsis Name for the specific site
Context configure service vpls service-name bgp-mh-site named-item
Treebgp-mh-site
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

activation-timer number
Synopsis Time that the local sites are in standby status, waiting for BGP updates
Contextconfigure service vpls service-name bgp-mh-site named-item activation-timer number
Treeactivation-timer
Range0 to 100
Unitsseconds
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the VPLS BGP multi-homing site
Contextconfigure service vpls service-name bgp-mh-site named-item admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

boot-timer number
Synopsis Wait time after reboot to run the DF election algorithm
Contextconfigure service vpls service-name bgp-mh-site named-item boot-timer number
Treeboot-timer
Range0 to 600
Unitsseconds
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

failed-threshold (number | keyword)
Synopsis Threshold for the site to be declared down
Contextconfigure service vpls service-name bgp-mh-site named-item failed-threshold (number | keyword)
Treefailed-threshold
Range1 to 1000
Optionsall
Defaultall
Introduced25.3.R2

Platforms

7705 SAR Gen 2

id number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSite ID
Contextconfigure service vpls service-name bgp-mh-site named-item id number
Treeid
Range1 to 65535
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mesh-sdp-binds
Synopsis Specify if a mesh-sdp-binding is associated with this site
Contextconfigure service vpls service-name bgp-mh-site named-item mesh-sdp-binds
Treemesh-sdp-binds

Notes

The following elements are part of a choice: mesh-sdp-binds, sap, shg-name, or spoke-sdp.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

min-down-timer number
Synopsis Minimum downtime for BGP multi-homing site after transition from up to down
Contextconfigure service vpls service-name bgp-mh-site named-item min-down-timer number
Treemin-down-timer
Range0 to 100
Unitsseconds
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

sap sap
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSAP to be associated with this site
Contextconfigure service vpls service-name bgp-mh-site named-item sap sap
Treesap
String length1 to 45

Notes

The following elements are part of a choice: mesh-sdp-binds, sap, shg-name, or spoke-sdp.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

shg-name named-item
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSHG name to be associated with the site
Contextconfigure service vpls service-name bgp-mh-site named-item shg-name named-item
Treeshg-name
String length1 to 32

Notes

The following elements are part of a choice: mesh-sdp-binds, sap, shg-name, or spoke-sdp.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

spoke-sdp sdp-bind-id
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSDP associated with the site
Contextconfigure service vpls service-name bgp-mh-site named-item spoke-sdp sdp-bind-id
Treespoke-sdp
String length3 to 16

Notes

The following elements are part of a choice: mesh-sdp-binds, sap, shg-name, or spoke-sdp.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp-vpls
Synopsis Enable the bgp-vpls context
Context configure service vpls service-name bgp-vpls
Treebgp-vpls
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the BGP-VPLS instance
Contextconfigure service vpls service-name bgp-vpls admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ve
Synopsis Enter the ve context
Context configure service vpls service-name bgp-vpls ve
Treeve
Introduced25.3.R2

Platforms

7705 SAR Gen 2

id number
Synopsis VPLS edge ID
Contextconfigure service vpls service-name bgp-vpls ve id number
Treeid
Range1 to 65535
Introduced25.3.R2

Platforms

7705 SAR Gen 2

name named-item
Synopsis VPLS Edge instance name
Context configure service vpls service-name bgp-vpls ve name named-item
Treename
String length1 to 32
Introduced25.3.R2

Platforms

7705 SAR Gen 2

customer reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisService customer ID
Contextconfigure service vpls service-name customer reference
Treecustomer

Reference

configure service customer customer-name

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service vpls service-name description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

endpoint [name] named-item
Synopsis Enter the endpoint list instance
Contextconfigure service vpls service-name endpoint named-item
Treeendpoint
Max. instances10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[name] named-item
Synopsis Service endpoint name
Context configure service vpls service-name endpoint named-item
Treeendpoint
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service vpls service-name endpoint named-item description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

fdb
Synopsis Enter the fdb context
Context configure service vpls service-name endpoint named-item fdb
Treefdb
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac-pinning boolean
Synopsis Activate MAC address pinning on this endpoint
Contextconfigure service vpls service-name endpoint named-item fdb mac-pinning boolean
Treemac-pinning
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

maximum-mac-addresses number
Synopsis Maximum number of MAC address entries in the FDB
Contextconfigure service vpls service-name endpoint named-item fdb maximum-mac-addresses number
Treemaximum-mac-addresses

Description

This command specifies the maximum number of FDB entries for both learned and static MAC addresses for this endpoint.

When the configured limit is reached, no new addresses are learned from the SAP or spoke SDP until at least one FDB entry is aged out or cleared. Packets with unknown source MAC addresses are still forwarded if their destination MAC addresses are known, or flooded if their destination MAC addresses are unknown.

However, if the configure service vpls fdb discard-unknown command is set to true, packets with unknown destination MAC addresses are discarded, even if the limit of FDB entries on the specific VPLS instance is not reached.

When unconfigured, the endpoint uses the global MAC learning limitations.

Range1 to 511999
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mc-endpoint [mc-ep-id] number
Synopsis Enter the mc-endpoint list instance
Contextconfigure service vpls service-name endpoint named-item mc-endpoint number
Treemc-endpoint
Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[mc-ep-id] number
Synopsis MC-EP ID
Contextconfigure service vpls service-name endpoint named-item mc-endpoint number
Treemc-endpoint

Description

This command configures the identifier associated with the MC-EP. The ID must be the same on both MC-EP peers.

Range1 to 4294967295

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mc-ep-peer
Synopsis Enter the mc-ep-peer context
Context configure service vpls service-name endpoint named-item mc-endpoint number mc-ep-peer
Treemc-ep-peer
Introduced25.3.R2

Platforms

7705 SAR Gen 2

name named-item
Synopsis Name of the MC-EP peer
Context configure service vpls service-name endpoint named-item mc-endpoint number mc-ep-peer name named-item
Treename
String length1 to 32

Notes

The following elements are part of a choice: name or peer-address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

revert-time (number | keyword)
Synopsis Time to wait before reverting to primary spoke SDP
Contextconfigure service vpls service-name endpoint named-item revert-time (number | keyword)
Treerevert-time
Range1 to 600
Unitsseconds
Options never, immediate
Defaultimmediate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

etree boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisUse VPLS service as an E-Tree VPLS
Contextconfigure service vpls service-name etree boolean
Treeetree
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

fdb
Synopsis Enter the fdb context
Context configure service vpls service-name fdb
Treefdb
Introduced25.3.R2

Platforms

7705 SAR Gen 2

discard-unknown boolean
Synopsis Discard packets with unknown destination MAC addresses
Contextconfigure service vpls service-name fdb discard-unknown boolean
Treediscard-unknown
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac-learning
Synopsis Enter the mac-learning context
Contextconfigure service vpls service-name fdb mac-learning
Treemac-learning
Introduced25.3.R2

Platforms

7705 SAR Gen 2

aging boolean
Synopsis Enable aging of MAC addresses
Context configure service vpls service-name fdb mac-learning aging boolean
Treeaging
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

local-age-time number
Synopsis Aging time for locally learned MAC addresses
Contextconfigure service vpls service-name fdb mac-learning local-age-time number
Treelocal-age-time

Description

This command configures the aging time for locally learned MAC addresses in the forwarding database (FDB) for the Virtual Private LAN Service (VPLS) instance. In a VPLS service, MAC addresses are associated with a Service Access Point (SAP) or a Service Destination Point (SDP). MACs associated with a SAP are classified as local MACs, and MACs associated with an SDP are remote MACs. In each VPLS service instance, there are independent aging timers for locally learned MAC and remotely learned MAC entries in the FDB.

As in a Layer 2 switch, learned MACs can be aged out if no packets are sourced from the MAC address for a period of time (the aging time).

Range60 to 86400
Default300
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

remote-age-time number
Synopsis Aging time for remotely learned MAC addresses
Contextconfigure service vpls service-name fdb mac-learning remote-age-time number
Treeremote-age-time

Description

This command configures the aging time for remotely learned MAC addresses in the forwarding database (FDB) for the Virtual Private LAN Service (VPLS) instance. In a VPLS service, MAC addresses are associated with a Service Access Point (SAP) or a Service Destination Point (SDP). MACs associated with a SAP are classified as local MACs, and MACs associated with an SDP are remote MACs. In each VPLS service instance, there are independent aging timers for locally learned MAC and remotely learned MAC entries in the FDB.

As in a Layer 2 switch, learned MACs can be aged out if no packets are sourced from the MAC address for a period of time (the aging time). To reduce the amount of signaling required between switches, configure this time larger than the local-age-time command.

Range60 to 86400
Default900
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

mac-move
Synopsis Enter the mac-move context
Context configure service vpls service-name fdb mac-move
Treemac-move
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of MAC move
Context configure service vpls service-name fdb mac-move admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

retry-count (number | keyword)
Synopsis Number of retries for re-enabling the SAP or SDP
Contextconfigure service vpls service-name fdb mac-move retry-count (number | keyword)
Treeretry-count
Range1 to 255
Optionsunlimited
Default3
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

sap [sap-id] reference
Synopsis Enter the sap list instance
Context configure service vpls service-name fdb mac-move sap reference
Treesap
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[sap-id] reference
Synopsis SAP identifier
Contextconfigure service vpls service-name fdb mac-move sap reference
Treesap

Reference

configure service vpls service-name sap sap

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

level keyword
Synopsis Primary or secondary port level
Context configure service vpls service-name fdb mac-move sap reference level keyword
Treelevel
Optionsprimary, secondary

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

spoke-sdp [sdp-bind-id] reference
Synopsis Enter the spoke-sdp list instance
Contextconfigure service vpls service-name fdb mac-move spoke-sdp reference
Treespoke-sdp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

level keyword
Synopsis Primary or secondary port level
Context configure service vpls service-name fdb mac-move spoke-sdp reference level keyword
Treelevel
Optionsprimary, secondary

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac-subnet-length number
Synopsis Number of bits performing MAC learning or MAC switching
Contextconfigure service vpls service-name fdb mac-subnet-length number
Treemac-subnet-length
Range24 to 48
Default48
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

static-mac
Synopsis Enter the static-mac context
Context configure service vpls service-name fdb static-mac
Treestatic-mac
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac [mac-address] mac-unicast-address-no-zero
Synopsis Enter the mac list instance
Context configure service vpls service-name fdb static-mac mac mac-unicast-address-no-zero
Treemac
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[mac-address] mac-unicast-address-no-zero
Synopsis Static MAC address to SAP/SDP-binding or black-hole
Contextconfigure service vpls service-name fdb static-mac mac mac-unicast-address-no-zero
Treemac

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

blackhole
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisCreate a static FDB entry for the MAC address to black-hole traffic
Contextconfigure service vpls service-name fdb static-mac mac mac-unicast-address-no-zero blackhole
Treeblackhole

Notes

The following elements are part of a mandatory choice: blackhole, endpoint, mesh-sdp, sap, or spoke-sdp.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

endpoint reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEndpoint associated with the MAC
Contextconfigure service vpls service-name fdb static-mac mac mac-unicast-address-no-zero endpoint reference
Treeendpoint

Reference

configure service vpls service-name endpoint named-item

Notes

The following elements are part of a mandatory choice: blackhole, endpoint, mesh-sdp, sap, or spoke-sdp.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mesh-sdp reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisMesh SDP bind associated with this MAC
Contextconfigure service vpls service-name fdb static-mac mac mac-unicast-address-no-zero mesh-sdp reference
Treemesh-sdp

Reference

configure service vpls service-name mesh-sdp sdp-bind-id

Notes

The following elements are part of a mandatory choice: blackhole, endpoint, mesh-sdp, sap, or spoke-sdp.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

monitor keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEntity to be monitored to decide whether this entry can be installed in the FDB
Contextconfigure service vpls service-name fdb static-mac mac mac-unicast-address-no-zero monitor keyword
Treemonitor
Optionsnone, forward-status
Defaultnone
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

sap reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSAP associated with this MAC
Contextconfigure service vpls service-name fdb static-mac mac mac-unicast-address-no-zero sap reference
Treesap

Reference

configure service vpls service-name sap sap

Notes

The following elements are part of a mandatory choice: blackhole, endpoint, mesh-sdp, sap, or spoke-sdp.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

spoke-sdp reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSpoke SDP bind associated with this MAC
Contextconfigure service vpls service-name fdb static-mac mac mac-unicast-address-no-zero spoke-sdp reference
Treespoke-sdp

Reference

configure service vpls service-name spoke-sdp sdp-bind-id

Notes

The following elements are part of a mandatory choice: blackhole, endpoint, mesh-sdp, sap, or spoke-sdp.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

table
Synopsis Enter the table context
Context configure service vpls service-name fdb table
Treetable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

high-wmark number
Synopsis High watermark for the FDB table
Context configure service vpls service-name fdb table high-wmark number
Treehigh-wmark
Range0 to 100
Default95
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

low-wmark number
Synopsis Low watermark for the FDB table
Context configure service vpls service-name fdb table low-wmark number
Treelow-wmark
Range0 to 100
Default90
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

size number
Synopsis Maximum MAC entries in the FDB
Context configure service vpls service-name fdb table size number
Treesize
Range1 to 511999
Default250
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

igmp-snooping
Synopsis Enter the igmp-snooping context
Contextconfigure service vpls service-name igmp-snooping
Treeigmp-snooping
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of snooping
Context configure service vpls service-name igmp-snooping admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ignore-l2vpn-mtu-mismatch boolean
Synopsis Ignore the L2 VPN MTU mismatch with local service MTU
Contextconfigure service vpls service-name ignore-l2vpn-mtu-mismatch boolean
Treeignore-l2vpn-mtu-mismatch

Description

When configured to true, the router ignores the value of the Layer 2 MTU in the Layer 2 Info Extended Community received in a BGP update message or the value of the MTU interface parameter received in an LDP label mapping message against the local service MTU or locally signaled MTU. It may, therefore, bring up the VPLS service regardless of any MTU mismatch.

When configured to false, an MTU mismatch prevents the system from bringing up a VPLS service.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface [interface-name] interface-name
Synopsis Enter the interface list instance
Contextconfigure service vpls service-name interface interface-name
Treeinterface
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[interface-name] interface-name
Synopsis IP interface name
Context configure service vpls service-name interface interface-name
Treeinterface
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the interface
Contextconfigure service vpls service-name interface interface-name admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description very-long-description
Synopsis Text description
Context configure service vpls service-name interface interface-name description very-long-description
Treedescription
String length1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hold-time
Synopsis Enter the hold-time context
Context configure service vpls service-name interface interface-name hold-time
Treehold-time
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4
Synopsis Enter the ipv4 context
Context configure service vpls service-name interface interface-name hold-time ipv4
Treeipv4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

down
Synopsis Enter the down context
Context configure service vpls service-name interface interface-name hold-time ipv4 down
Treedown

Description

Commands in this context configure the down hold timer, which specifies the delay before activating the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface up, unless an operator configures the init-only command. 

Introduced25.3.R2

Platforms

7705 SAR Gen 2

init-only boolean
Synopsis Apply delay only at interface configuration or reboot
Contextconfigure service vpls service-name interface interface-name hold-time ipv4 down init-only boolean
Treeinit-only

Description

This command applies a delay only when the IP interface is first configured or after a system reboot.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

up
Synopsis Enter the up context
Context configure service vpls service-name interface interface-name hold-time ipv4 up
Treeup

Description

Commands in this context configure the up hold timer, which specifies the delay before deactivation of the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface down.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4
Synopsis Enter the ipv4 context
Context configure service vpls service-name interface interface-name ipv4
Treeipv4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

neighbor-discovery
Synopsis Enter the neighbor-discovery context
Contextconfigure service vpls service-name interface interface-name ipv4 neighbor-discovery
Treeneighbor-discovery
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static-neighbor [ipv4-address] ipv4-address
Synopsis Enter the static-neighbor list instance
Contextconfigure service vpls service-name interface interface-name ipv4 neighbor-discovery static-neighbor ipv4-address
Treestatic-neighbor
Introduced25.3.R2

Platforms

7705 SAR Gen 2

timeout number
Synopsis ARP timeout value to determine how long an ARP entry remains in the ARP cache
Contextconfigure service vpls service-name interface interface-name ipv4 neighbor-discovery timeout number
Treetimeout
Range0 to 65535
Unitsseconds
Default 14400
Introduced25.3.R2

Platforms

7705 SAR Gen 2

primary
Synopsis Enable the primary context
Context configure service vpls service-name interface interface-name ipv4 primary
Treeprimary
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address ipv4-address
Synopsis IP address of the interface
Context configure service vpls service-name interface interface-name ipv4 primary address ipv4-address
Treeaddress

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac mac-unicast-address
Synopsis MAC address for the interface
Context configure service vpls service-name interface interface-name mac mac-unicast-address
Treemac
Introduced25.3.R2

Platforms

7705 SAR Gen 2

isid-policy
Synopsis Enter the isid-policy context
Context configure service vpls service-name isid-policy
Treeisid-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

entry [range-entry-id] number
Synopsis Enter the entry list instance
Context configure service vpls service-name isid-policy entry number
Treeentry
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[range-entry-id] number
Synopsis ISID policy entry ID
Context configure service vpls service-name isid-policy entry number
Treeentry
Range1 to 8191

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

range
Synopsis Enter the range context
Context configure service vpls service-name isid-policy entry number range
Treerange
Introduced25.3.R2

Platforms

7705 SAR Gen 2

end number
Synopsis Upper bound of the ISID range
Context configure service vpls service-name isid-policy entry number range end number
Treeend
Range1 to 16777215
Introduced25.3.R2

Platforms

7705 SAR Gen 2

start number
Synopsis Lower bound of the ISID range
Context configure service vpls service-name isid-policy entry number range start number
Treestart
Range1 to 16777215
Introduced25.3.R2

Platforms

7705 SAR Gen 2

m-vpls boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSpecify whether this is a management VPLS
Contextconfigure service vpls service-name m-vpls boolean
Treem-vpls
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac-flush
Synopsis Enter the mac-flush context
Context configure service vpls service-name mac-flush
Treemac-flush
Introduced25.3.R2

Platforms

7705 SAR Gen 2

tldp
Synopsis Enter the tldp context
Context configure service vpls service-name mac-flush tldp
Treetldp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

propagate boolean
Synopsis Propagate MAC flush messages received from the T-LDP
Contextconfigure service vpls service-name mac-flush tldp propagate boolean
Treepropagate
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac-protect
Synopsis Enter the mac-protect context
Context configure service vpls service-name mac-protect
Treemac-protect
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac [mac-address] mac-address
Synopsis Add a list entry for mac
Context configure service vpls service-name mac-protect mac mac-address
Treemac
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[mac-address] mac-address
Synopsis Protected MAC address
Context configure service vpls service-name mac-protect mac mac-address
Treemac

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mcr-default-gtw
Synopsis Enter the mcr-default-gtw context
Contextconfigure service vpls service-name mcr-default-gtw
Treemcr-default-gtw
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip ipv4-unicast-address
Synopsis Multi-chassis ring default gateway IP address
Contextconfigure service vpls service-name mcr-default-gtw ip ipv4-unicast-address
Treeip
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac mac-address
Synopsis Multi-chassis ring default gateway MAC address
Contextconfigure service vpls service-name mcr-default-gtw mac mac-address
Treemac
Default00:00:00:00:00:00
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mesh-sdp [sdp-bind-id] sdp-bind-id
Synopsis Enter the mesh-sdp list instance
Contextconfigure service vpls service-name mesh-sdp sdp-bind-id
Treemesh-sdp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[sdp-bind-id] sdp-bind-id
Synopsis SDP binding ID
Contextconfigure service vpls service-name mesh-sdp sdp-bind-id
Treemesh-sdp
String length3 to 16

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the SDP binding to the service
Contextconfigure service vpls service-name mesh-sdp sdp-bind-id admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

adv-service-mtu number
Synopsis Advertise service MTU value
Context configure service vpls service-name mesh-sdp sdp-bind-id adv-service-mtu number
Treeadv-service-mtu

Description

This command configures the MTU value that is signaled in the targeted LDP for the spoke-SDP. The router uses the value for signaling and for validation with the received MTU instead of the service MTU. However, the value does not affect the locally enforced value, which is still based on the service MTU.

This command cannot be configured on a spoke-SDP that is bound to an SDP with the adv-mtu-override command.

Range0 to 9782
Introduced25.3.R2

Platforms

7705 SAR Gen 2

collect-stats boolean
Synopsis Allow agent to collect accounting statistics
Contextconfigure service vpls service-name mesh-sdp sdp-bind-id collect-stats boolean
Treecollect-stats
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

control-word boolean
Synopsis Use the control word as preferred
Context configure service vpls service-name mesh-sdp sdp-bind-id control-word boolean
Treecontrol-word
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service vpls service-name mesh-sdp sdp-bind-id description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dhcp
Synopsis Enter the dhcp context
Context configure service vpls service-name mesh-sdp sdp-bind-id dhcp
Treedhcp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

snoop boolean
Synopsis Allow DHCP snooping of DHCP messages on the SAP or SDP
Contextconfigure service vpls service-name mesh-sdp sdp-bind-id dhcp snoop boolean
Treesnoop
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

egress
Synopsis Enter the egress context
Context configure service vpls service-name mesh-sdp sdp-bind-id egress
Treeegress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter
Synopsis Enter the filter context
Context configure service vpls service-name mesh-sdp sdp-bind-id egress filter
Treefilter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mfib-allowed-mda-destinations
Synopsis Enter the mfib-allowed-mda-destinations context
Contextconfigure service vpls service-name mesh-sdp sdp-bind-id egress mfib-allowed-mda-destinations
Treemfib-allowed-mda-destinations
Introduced25.3.R2

Platforms

7705 SAR Gen 2

qos
Synopsis Enter the qos context
Context configure service vpls service-name mesh-sdp sdp-bind-id egress qos
Treeqos
Introduced25.3.R2

Platforms

7705 SAR Gen 2

network
Synopsis Enter the network context
Context configure service vpls service-name mesh-sdp sdp-bind-id egress qos network
Treenetwork
Introduced25.3.R2

Platforms

7705 SAR Gen 2

port-redirect-group
Synopsis Enter the port-redirect-group context
Contextconfigure service vpls service-name mesh-sdp sdp-bind-id egress qos network port-redirect-group
Treeport-redirect-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEgress MPLS VC label to send packets to the far end
Contextconfigure service vpls service-name mesh-sdp sdp-bind-id egress vc-label number
Treevc-label
Range16 to 1048575
Introduced25.3.R2

Platforms

7705 SAR Gen 2

etree-leaf boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEnable etree leaf access-circuit status
Contextconfigure service vpls service-name mesh-sdp sdp-bind-id etree-leaf boolean
Treeetree-leaf
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

etree-root-leaf-tag boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisStatus for E-tree root leaf tag
Contextconfigure service vpls service-name mesh-sdp sdp-bind-id etree-root-leaf-tag boolean
Treeetree-root-leaf-tag
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

fdb
Synopsis Enter the fdb context
Context configure service vpls service-name mesh-sdp sdp-bind-id fdb
Treefdb
Introduced25.3.R2

Platforms

7705 SAR Gen 2

auto-learn-mac-protect-exclude-list reference
Synopsis Referenced MAC protect exclusion list name
Contextconfigure service vpls service-name mesh-sdp sdp-bind-id fdb auto-learn-mac-protect-exclude-list reference
Treeauto-learn-mac-protect-exclude-list

Description

This command references the name of a MAC protect exclusion list.

Dynamically-learned MAC Source Addresses (SA) are protected if they are learned on an object with ALMP configured and no exclusion list is associated with the object, or if the MAC SA does not match any entry in an associated exclusion list.

An exclusion list can be used in multiple objects of a service. If a list is empty, ALMP does not exclude any learned MAC SAs from protection on the object.

Reference

configure service mac-list named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac-pinning boolean
Synopsis MAC address pinning in active status
Context configure service vpls service-name mesh-sdp sdp-bind-id fdb mac-pinning boolean
Treemac-pinning
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hash-label
Synopsis Enable the hash-label context
Context configure service vpls service-name mesh-sdp sdp-bind-id hash-label
Treehash-label

Description

Commands in this context configure the use of hash labels for egress datapaths.

For information about hash-label handling, see the "Hash label" section of the 7705 SAR Gen 2 MPLS Guide.

Notes

The following elements are part of a choice: entropy-label or hash-label.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

signal-capability
Synopsis Signal hash label capability to the remote PE
Contextconfigure service vpls service-name mesh-sdp sdp-bind-id hash-label signal-capability
Treesignal-capability

Description

When configured, this command enables the signaling and negotiating of the hash label between the local and remote PE nodes.

The signaling process outcome determines whether the local PE inserts the hash label on the user packets. This outcome can override the local PE configuration.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

igmp-snooping
Synopsis Enter the igmp-snooping context
Contextconfigure service vpls service-name mesh-sdp sdp-bind-id igmp-snooping
Treeigmp-snooping
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static
Synopsis Enter the static context
Context configure service vpls service-name mesh-sdp sdp-bind-id igmp-snooping static
Treestatic
Introduced25.3.R2

Platforms

7705 SAR Gen 2

group [group-address] ipv4-multicast-address
Synopsis Enter the group list instance
Context configure service vpls service-name mesh-sdp sdp-bind-id igmp-snooping static group ipv4-multicast-address
Treegroup
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[group-address] ipv4-multicast-address
Synopsis Group address of static IGMP multicast channel
Contextconfigure service vpls service-name mesh-sdp sdp-bind-id igmp-snooping static group ipv4-multicast-address
Treegroup

Description

This command configures an address that receives data on an interface. The IP address must be unique for each static group.

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

source [source-address] ipv4-unicast-address
Synopsis Add a list entry for source
Context configure service vpls service-name mesh-sdp sdp-bind-id igmp-snooping static group ipv4-multicast-address source ipv4-unicast-address
Treesource

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[source-address] ipv4-unicast-address
Synopsis Source IP address of multicast channel sending data
Contextconfigure service vpls service-name mesh-sdp sdp-bind-id igmp-snooping static group ipv4-multicast-address source ipv4-unicast-address
Treesource

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

starg
Synopsis any source address (*,G)
Context configure service vpls service-name mesh-sdp sdp-bind-id igmp-snooping static group ipv4-multicast-address starg
Treestarg

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ingress
Synopsis Enter the ingress context
Context configure service vpls service-name mesh-sdp sdp-bind-id ingress
Treeingress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter
Synopsis Enter the filter context
Context configure service vpls service-name mesh-sdp sdp-bind-id ingress filter
Treefilter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

qos
Synopsis Enter the qos context
Context configure service vpls service-name mesh-sdp sdp-bind-id ingress qos
Treeqos
Introduced25.3.R2

Platforms

7705 SAR Gen 2

network
Synopsis Enter the network context
Context configure service vpls service-name mesh-sdp sdp-bind-id ingress qos network
Treenetwork
Introduced25.3.R2

Platforms

7705 SAR Gen 2

fp-redirect-group
Synopsis Enter the fp-redirect-group context
Contextconfigure service vpls service-name mesh-sdp sdp-bind-id ingress qos network fp-redirect-group
Treefp-redirect-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIngress MPLS VC label to send packets to the far end
Contextconfigure service vpls service-name mesh-sdp sdp-bind-id ingress vc-label number
Treevc-label
Range1 to 1048575
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mld-snooping
Synopsis Enter the mld-snooping context
Contextconfigure service vpls service-name mesh-sdp sdp-bind-id mld-snooping
Treemld-snooping
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static
Synopsis Enter the static context
Context configure service vpls service-name mesh-sdp sdp-bind-id mld-snooping static
Treestatic
Introduced25.3.R2

Platforms

7705 SAR Gen 2

group [group-address] ipv6-multicast-address
Synopsis Enter the group list instance
Context configure service vpls service-name mesh-sdp sdp-bind-id mld-snooping static group ipv6-multicast-address
Treegroup
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[group-address] ipv6-multicast-address
Synopsis Group address of multicast channel
Context configure service vpls service-name mesh-sdp sdp-bind-id mld-snooping static group ipv6-multicast-address
Treegroup

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

source [source-address] ipv6-unicast-address
Synopsis Add a list entry for source
Context configure service vpls service-name mesh-sdp sdp-bind-id mld-snooping static group ipv6-multicast-address source ipv6-unicast-address
Treesource

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[source-address] ipv6-unicast-address
Synopsis Source IP address
Context configure service vpls service-name mesh-sdp sdp-bind-id mld-snooping static group ipv6-multicast-address source ipv6-unicast-address
Treesource

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

starg
Synopsis any source address (*,G)
Context configure service vpls service-name mesh-sdp sdp-bind-id mld-snooping static group ipv6-multicast-address starg
Treestarg

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

version keyword
Synopsis Version of MLD running on the SAP or SDP
Contextconfigure service vpls service-name mesh-sdp sdp-bind-id mld-snooping version keyword
Treeversion
Options1, 2
Default 2
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vc-type keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisType of virtual circuit (VC) associated with the SDP binding; VPLS not supported
Contextconfigure service vpls service-name mesh-sdp sdp-bind-id vc-type keyword
Treevc-type
Optionsether, vlan
Default ether
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mfib
Synopsis Enter the mfib context
Context configure service vpls service-name mfib
Treemfib
Introduced25.3.R2

Platforms

7705 SAR Gen 2

table
Synopsis Enter the table context
Context configure service vpls service-name mfib table
Treetable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

high-wmark number
Synopsis High watermark for the MFIB table
Context configure service vpls service-name mfib table high-wmark number
Treehigh-wmark
Range0 to 100
Default95
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

low-wmark number
Synopsis Low watermark for the MFIB table
Context configure service vpls service-name mfib table low-wmark number
Treelow-wmark
Range0 to 100
Default90
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

size number
Synopsis Maximum SG entries in the MFIB
Context configure service vpls service-name mfib table size number
Treesize
Range1 to 40959
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mld-snooping
Synopsis Enter the mld-snooping context
Contextconfigure service vpls service-name mld-snooping
Treemld-snooping
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of snooping
Context configure service vpls service-name mld-snooping admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

query-interval number
Synopsis Time between two consecutive host-query messages
Contextconfigure service vpls service-name mld-snooping query-interval number
Treequery-interval
Range1 to 65535
Unitsseconds
Default 125
Introduced25.3.R2

Platforms

7705 SAR Gen 2

proxy-arp
Synopsis Enable the proxy-arp context
Context configure service vpls service-name proxy-arp
Treeproxy-arp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the proxy
Context configure service vpls service-name proxy-arp admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

age-time (number | keyword)
Synopsis Aging timer for proxy entries, where entries are flushed upon timer expiry
Contextconfigure service vpls service-name proxy-arp age-time (number | keyword)
Treeage-time
Range60 to 86400
Unitsseconds
Options never
Default never
Introduced25.3.R2

Platforms

7705 SAR Gen 2

duplicate-detect
Synopsis Enter the duplicate-detect context
Contextconfigure service vpls service-name proxy-arp duplicate-detect
Treeduplicate-detect
Introduced25.3.R2

Platforms

7705 SAR Gen 2

anti-spoof-mac mac-unicast-address-no-zero
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMAC address to replace the proxy-ARP/ND offending entry's MAC
Contextconfigure service vpls service-name proxy-arp duplicate-detect anti-spoof-mac mac-unicast-address-no-zero
Treeanti-spoof-mac
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static-blackhole boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisConsider anti-spoof MAC as black-hole static MAC in FDB
Contextconfigure service vpls service-name proxy-arp duplicate-detect static-blackhole boolean
Treestatic-blackhole
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

window number
Synopsis Time to monitor the MAC address in the anti-spoofing mechanism
Contextconfigure service vpls service-name proxy-arp duplicate-detect window number
Treewindow
Range1 to 15
Unitsminutes
Default 3
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dynamic-arp
Synopsis Enter the dynamic-arp context
Context configure service vpls service-name proxy-arp dynamic-arp
Treedynamic-arp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-address [ipv4-address] ipv4-unicast-address
Synopsis Enter the ip-address list instance
Contextconfigure service vpls service-name proxy-arp dynamic-arp ip-address ipv4-unicast-address
Treeip-address
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ipv4-address] ipv4-unicast-address
Synopsis Proxy ARP IPv4 address
Context configure service vpls service-name proxy-arp dynamic-arp ip-address ipv4-unicast-address
Treeip-address

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

sap [sap-id] reference
Synopsis Add a list entry for sap
Context configure service vpls service-name proxy-arp dynamic-arp ip-address ipv4-unicast-address sap reference
Treesap

Description

Commands in this context configure the proxy ARP or ND entry for creation when the ARP or neighbor advertisement (NA) packet for the configured IP address is received on the configured SAP, when configured under the dynamic-arp ip-address context. This command can be configured in combination with the mac-list for the entry, in which case, the MAC of the ARP or NA message and the SAP on which the ARP or NA packet is received are both checked before creating the entry.

Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dynamic-populate boolean
Synopsis Populate proxy ARP entries from snooped GARP/ARP/ND messages on SAPs/SDP-bindings
Contextconfigure service vpls service-name proxy-arp dynamic-populate boolean
Treedynamic-populate
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

evpn
Synopsis Enter the evpn context
Context configure service vpls service-name proxy-arp evpn
Treeevpn
Introduced25.3.R2

Platforms

7705 SAR Gen 2

flood
Synopsis Enter the flood context
Context configure service vpls service-name proxy-arp evpn flood
Treeflood
Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-tag number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRoute tag used on export policies to match MAC/IP routes generated by proxy-ARP or proxy-ND module
Contextconfigure service vpls service-name proxy-arp evpn route-tag number
Treeroute-tag
Range0 | 1 to 255
Default0
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

flood
Synopsis Enter the flood context
Context configure service vpls service-name proxy-arp flood
Treeflood
Introduced25.3.R2

Platforms

7705 SAR Gen 2

received-gratuitous-arp boolean
Synopsis Allow GARP requests or replies to flood the service
Contextconfigure service vpls service-name proxy-arp flood received-gratuitous-arp boolean
Treereceived-gratuitous-arp

Description

When configured to true, the system floods GARP requests and replies received on a SAP (or SDP-bind) to the service flood-list (which includes EVPN destinations and other SAPs and SDP-binds).

The GARPs impacted by this command are identified by the sender IP address being equal to the target IP address and the MAC DA that is broadcast.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

received-unknown-arp-req boolean
Synopsis Allow unknown ARP requests to flood the service
Contextconfigure service vpls service-name proxy-arp flood received-unknown-arp-req boolean
Treereceived-unknown-arp-req

Description

When configured to true, the unknown ARP requests received on a SAP (or SDP-bind) are flooded to the service flood-list (which includes EVPN destinations and other SAPs and SDP-binds).

By default if there is no active proxy ARP entry for the requested IP address, the system floods ARP requests, including EVPN (with source squelching).

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

restrict-non-configured-ip-address
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the restrict-non-configured-ip-address context
Contextconfigure service vpls service-name proxy-arp restrict-non-configured-ip-address
Treerestrict-non-configured-ip-address

Description

Commands in this context configure whether all the configured dynamic IP address entries are considered the only authorized entries in the proxy ARP or ND table. ARP or ND packets coming from a unauthorized sender IP are dropped. Therefore, unauthorized IP addresses are not learned in the proxy ARP or ND table, and ARP requests or neighbor solicitations (NS) coming from a unauthorized sender IP are not replied (unless the sponge-mac command option is configured).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

sponge-mac mac-unicast-address-no-zero
Synopsis Sponge MAC used to reply to unauthorized requests
Contextconfigure service vpls service-name proxy-arp restrict-non-configured-ip-address sponge-mac mac-unicast-address-no-zero
Treesponge-mac

Description

This command configures the system to ignore ARP requests or neighbor solicitations from an unauthorized IP address. These requests are not learned in the proxy ARP or ND table (when the restrict-non-configured-ip-address command is configured), and the system replies with the configured sponge MAC address. Any IP address that is not configured as proxy ARP, ND dynamic ARP, or neighbor IP address is considered unauthorized and there is no reply.

The configured sponge MAC address is not installed in the FDB or advertised in EVPN. If needed, the sponge MAC address can be configured as a static MAC in the same service in the node or a remote node.

This command supersedes the operation of the restrict-non-configured-ip-address command for replies to ARP requests or neighbor solicitation:

  • If only restrict-non-configured-ip-address is configured, all ARP or ND packets from unauthorized IPs are dropped.

  • If restrict-non-configured-ip-address sponge-mac is configured, ARP or ND packets from unauthorized IPs are dropped except for ARP requests or neighbor solicitation messages, to which the system replies with the configured sponge MAC address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

send-refresh (number | keyword)
Synopsis Time at which to send a refresh message
Contextconfigure service vpls service-name proxy-arp send-refresh (number | keyword)
Treesend-refresh
Range120 to 86400
Optionsnever
Defaultnever
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static-arp
Synopsis Enter the static-arp context
Context configure service vpls service-name proxy-arp static-arp
Treestatic-arp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-address [ipv4-address] ipv4-unicast-address
Synopsis Enter the ip-address list instance
Contextconfigure service vpls service-name proxy-arp static-arp ip-address ipv4-unicast-address
Treeip-address
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ipv4-address] ipv4-unicast-address
Synopsis Proxy ARP IPv4 address
Context configure service vpls service-name proxy-arp static-arp ip-address ipv4-unicast-address
Treeip-address

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac mac-unicast-address-no-zero
Synopsis Proxy ARP MAC address for static entry
Contextconfigure service vpls service-name proxy-arp static-arp ip-address ipv4-unicast-address mac mac-unicast-address-no-zero
Treemac

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

table-size number
Synopsis Maximum number of learned and static entries allowed in the proxy table of this service
Contextconfigure service vpls service-name proxy-arp table-size number
Treetable-size
Range1 to 16383
Default250
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

proxy-nd
Synopsis Enable the proxy-nd context
Context configure service vpls service-name proxy-nd
Treeproxy-nd
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the proxy
Context configure service vpls service-name proxy-nd admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

age-time (number | keyword)
Synopsis Aging timer for proxy entries, where entries are flushed upon timer expiry
Contextconfigure service vpls service-name proxy-nd age-time (number | keyword)
Treeage-time
Range60 to 86400
Unitsseconds
Options never
Default never
Introduced25.3.R2

Platforms

7705 SAR Gen 2

duplicate-detect
Synopsis Enter the duplicate-detect context
Contextconfigure service vpls service-name proxy-nd duplicate-detect
Treeduplicate-detect
Introduced25.3.R2

Platforms

7705 SAR Gen 2

anti-spoof-mac mac-unicast-address-no-zero
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMAC address to replace the proxy-ARP/ND offending entry's MAC
Contextconfigure service vpls service-name proxy-nd duplicate-detect anti-spoof-mac mac-unicast-address-no-zero
Treeanti-spoof-mac
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static-blackhole boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisConsider anti-spoof MAC as black-hole static MAC in FDB
Contextconfigure service vpls service-name proxy-nd duplicate-detect static-blackhole boolean
Treestatic-blackhole
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

window number
Synopsis Time to monitor the MAC address in the anti-spoofing mechanism
Contextconfigure service vpls service-name proxy-nd duplicate-detect window number
Treewindow
Range1 to 15
Unitsminutes
Default 3
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dynamic-neighbor
Synopsis Enter the dynamic-neighbor context
Contextconfigure service vpls service-name proxy-nd dynamic-neighbor
Treedynamic-neighbor
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-address [ipv6-address] ipv6-address
Synopsis Enter the ip-address list instance
Contextconfigure service vpls service-name proxy-nd dynamic-neighbor ip-address ipv6-address
Treeip-address
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sap [sap-id] reference
Synopsis Add a list entry for sap
Context configure service vpls service-name proxy-nd dynamic-neighbor ip-address ipv6-address sap reference
Treesap

Description

Commands in this context configure the proxy ARP or ND entry for creation when the ARP or neighbor advertisement (NA) packet for the configured IP address is received on the configured SAP, when configured under the dynamic-arp ip-address context. This command can be configured in combination with the mac-list for the entry, in which case, the MAC of the ARP or NA message and the SAP on which the ARP or NA packet is received are both checked before creating the entry.

Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dynamic-populate boolean
Synopsis Populate proxy ARP entries from snooped GARP/ARP/ND messages on SAPs/SDP-bindings
Contextconfigure service vpls service-name proxy-nd dynamic-populate boolean
Treedynamic-populate
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

evpn
Synopsis Enter the evpn context
Context configure service vpls service-name proxy-nd evpn
Treeevpn
Introduced25.3.R2

Platforms

7705 SAR Gen 2

advertise-neighbor-type keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdvertisement type of static or dynamic entries in EVPN
Contextconfigure service vpls service-name proxy-nd evpn advertise-neighbor-type keyword
Treeadvertise-neighbor-type

Description

This command enables the advertisement of static or dynamic entries that are learned as host, router, or host and router (only one option is possible in a specified service). It also determines the R flag (host or router) when sending Neighbor Advertisement (NA) messages for existing EVPN entries in the proxy-ND table.

The router-host command option is only possible when the ARP/ND extended community is advertised along with the MAC/IP routes. It determines that both host and router (dynamic and static) entries are advertised in MAC/IP routes, with an indication whether the entry is host or router in the R flag. These EVPN entries are installed as host or router entries depending on the R flag of the route, and NA messages for them are sent with the proper host or router indication.

Optionsrouter, host, router-host
Defaultrouter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

flood
Synopsis Enter the flood context
Context configure service vpls service-name proxy-nd evpn flood
Treeflood
Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-tag number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRoute tag used on export policies to match MAC/IP routes generated by proxy-ARP or proxy-ND module
Contextconfigure service vpls service-name proxy-nd evpn route-tag number
Treeroute-tag
Range0 | 1 to 255
Default0
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

flood
Synopsis Enter the flood context
Context configure service vpls service-name proxy-nd flood
Treeflood
Introduced25.3.R2

Platforms

7705 SAR Gen 2

received-unknown-neighbor-advertise-host boolean
Synopsis Allow unknown NA host messages to flood the service
Contextconfigure service vpls service-name proxy-nd flood received-unknown-neighbor-advertise-host boolean
Treereceived-unknown-neighbor-advertise-host

Description

When configured to true, the system floods received unsolicited NAs into the VPLS service (to EVPN destinations and SAPs or SDP-binds).

When configured to false, the system does not flood unsolicited NAs regardless of the configure service vpls proxy-nd evpn flood unknown-neighbor-advertise-host command configuration.

The NA messages impacted by this command are NA messages with the following flags: S=0 and R=0.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

received-unknown-neighbor-advertise-router boolean
Synopsis Allow unknown router NA host messages to flood service
Contextconfigure service vpls service-name proxy-nd flood received-unknown-neighbor-advertise-router boolean
Treereceived-unknown-neighbor-advertise-router

Description

When configured to true, the system floods received unsolicited router NAs into the VPLS service (to EVPN destinations and SAPs or SDP-binds).

When configured to false, the system does not flood unsolicited router NAs regardless of the configure service vpls proxy-nd evpn flood unknown-neighbor-advertise-router command configuration.

The NA messages impacted by this command are NA messages with the following flags: S=0 and R=1.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

received-unknown-neighbor-solicitation boolean
Synopsis Allow unknown NS messages to flood the service
Contextconfigure service vpls service-name proxy-nd flood received-unknown-neighbor-solicitation boolean
Treereceived-unknown-neighbor-solicitation

Description

When configured to true, the system floods unknown NS messages into the VPLS service (to EVPN destinations and SAPs or SDP-binds).

When configured to false, the system does not flood unknown NS messages regardless of the configure service vpls proxy-nd evpn flood unknown-neighbor-solicitation command configuration.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

restrict-non-configured-ip-address
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the restrict-non-configured-ip-address context
Contextconfigure service vpls service-name proxy-nd restrict-non-configured-ip-address
Treerestrict-non-configured-ip-address

Description

Commands in this context configure whether all the configured dynamic IP address entries are considered the only authorized entries in the proxy ARP or ND table. ARP or ND packets coming from a unauthorized sender IP are dropped. Therefore, unauthorized IP addresses are not learned in the proxy ARP or ND table, and ARP requests or neighbor solicitations (NS) coming from a unauthorized sender IP are not replied (unless the sponge-mac command option is configured).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

sponge-mac mac-unicast-address-no-zero
Synopsis Sponge MAC used to reply to unauthorized requests
Contextconfigure service vpls service-name proxy-nd restrict-non-configured-ip-address sponge-mac mac-unicast-address-no-zero
Treesponge-mac

Description

This command configures the system to ignore ARP requests or neighbor solicitations from an unauthorized IP address. These requests are not learned in the proxy ARP or ND table (when the restrict-non-configured-ip-address command is configured), and the system replies with the configured sponge MAC address. Any IP address that is not configured as proxy ARP, ND dynamic ARP, or neighbor IP address is considered unauthorized and there is no reply.

The configured sponge MAC address is not installed in the FDB or advertised in EVPN. If needed, the sponge MAC address can be configured as a static MAC in the same service in the node or a remote node.

This command supersedes the operation of the restrict-non-configured-ip-address command for replies to ARP requests or neighbor solicitation:

  • If only restrict-non-configured-ip-address is configured, all ARP or ND packets from unauthorized IPs are dropped.

  • If restrict-non-configured-ip-address sponge-mac is configured, ARP or ND packets from unauthorized IPs are dropped except for ARP requests or neighbor solicitation messages, to which the system replies with the configured sponge MAC address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

send-refresh (number | keyword)
Synopsis Time at which to send a refresh message
Contextconfigure service vpls service-name proxy-nd send-refresh (number | keyword)
Treesend-refresh
Range120 to 86400
Optionsnever
Defaultnever
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static-neighbor
Synopsis Enter the static-neighbor context
Contextconfigure service vpls service-name proxy-nd static-neighbor
Treestatic-neighbor
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-address [ipv6-address] ipv6-address
Synopsis Enter the ip-address list instance
Contextconfigure service vpls service-name proxy-nd static-neighbor ip-address ipv6-address
Treeip-address
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac mac-unicast-address-no-zero
Synopsis Proxy ARP MAC address for static entry
Contextconfigure service vpls service-name proxy-nd static-neighbor ip-address ipv6-address mac mac-unicast-address-no-zero
Treemac

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

table-size number
Synopsis Maximum number of learned and static entries allowed in the proxy table of this service
Contextconfigure service vpls service-name proxy-nd table-size number
Treetable-size
Range1 to 16383
Default250
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

routed-vpls
Synopsis Enable the routed-vpls context
Contextconfigure service vpls service-name routed-vpls
Treerouted-vpls
Introduced25.3.R2

Platforms

7705 SAR Gen 2

multicast
Synopsis Enter the multicast context
Context configure service vpls service-name routed-vpls multicast
Treemulticast
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6
Synopsis Enter the ipv6 context
Context configure service vpls service-name routed-vpls multicast ipv6
Treeipv6
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sap [sap-id] sap
Synopsis Enter the sap list instance
Context configure service vpls service-name sap sap
Treesap
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[sap-id] sap
Synopsis SAP identifier
Contextconfigure service vpls service-name sap sap
Treesap
String length1 to 45

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the SAP
Context configure service vpls service-name sap sap admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

arp-reply-agent keyword
Synopsis Enable arp-reply-agent function
Context configure service vpls service-name sap sap arp-reply-agent keyword
Treearp-reply-agent
Optionstrue, with-subscr-ident
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bandwidth number
Synopsis SAP bandwidth
Contextconfigure service vpls service-name sap sap bandwidth number
Treebandwidth
Range1 to 6400000000
Unitskilobps
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

bgp-vpls-mh-veid number
Synopsis BGP-VPLS multi-homing VE-ID
Context configure service vpls service-name sap sap bgp-vpls-mh-veid number
Treebgp-vpls-mh-veid

Description

This command specifies a VE ID that is configured on SAPs that are part of an EVPN single-active Ethernet Segment. The configuration of this command allows the advertisement of L2VPN routes that indicate the state of multi-homed SAPs to the remote BGP-VPLS PEs, which can trigger a MAC flush operation on the service to avoid traffic from being blackholed when a failure occurs in the active PE.

When unconfigured from the SAP, L2VPN routes are withdrawn, which causes MAC flush processing on the remote BGP-VPLS.

Range1 to 65535
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bpdu-translation keyword
Synopsis Bpdu translation on this SAP
Context configure service vpls service-name sap sap bpdu-translation keyword
Treebpdu-translation
Optionsauto, pvst, stp, pvst-rw, auto-rw
Introduced25.3.R2

Platforms

7705 SAR Gen 2

collect-stats boolean
Synopsis Collect accounting statistics
Context configure service vpls service-name sap sap collect-stats boolean
Treecollect-stats
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description long-description
Synopsis Text description
Context configure service vpls service-name sap sap description long-description
Treedescription
String length1 to 160
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dhcp
Synopsis Enter the dhcp context
Context configure service vpls service-name sap sap dhcp
Treedhcp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of DHCP
Context configure service vpls service-name sap sap dhcp admin-state keyword
Treeadmin-state
Optionsenable, disable
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service vpls service-name sap sap dhcp description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

option-82
Synopsis Enter the option-82 context
Context configure service vpls service-name sap sap dhcp option-82
Treeoption-82

Description

Commands in this context configure the processing required when the router receives a DHCP request that already has an Option 82 field in the packet.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

action keyword
Synopsis Action to take with received DHCP Option 82
Contextconfigure service vpls service-name sap sap dhcp option-82 action keyword
Treeaction
Optionsreplace, drop, keep
Defaultkeep
Introduced25.3.R2

Platforms

7705 SAR Gen 2

circuit-id
Synopsis Enter the circuit-id context
Context configure service vpls service-name sap sap dhcp option-82 circuit-id
Treecircuit-id
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ascii-tuple
Synopsis Use the ASCII-encoded tuple for the circuit ID
Contextconfigure service vpls service-name sap sap dhcp option-82 circuit-id ascii-tuple
Treeascii-tuple

Notes

The following elements are part of a choice: ascii-tuple, hex-string, none, or vlan-ascii-tuple.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

hex-string hex-string
Synopsis User-defined hexadeciaml value of the option
Contextconfigure service vpls service-name sap sap dhcp option-82 circuit-id hex-string hex-string
Treehex-string
String length1 to 66

Notes

The following elements are part of a choice: ascii-tuple, hex-string, none, or vlan-ascii-tuple.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

none
Synopsis Do not include the circuit ID
Context configure service vpls service-name sap sap dhcp option-82 circuit-id none
Treenone

Notes

The following elements are part of a choice: ascii-tuple, hex-string, none, or vlan-ascii-tuple.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

vlan-ascii-tuple
Synopsis Include the VLAN ID and dot1p bits in the ASCII tuple
Contextconfigure service vpls service-name sap sap dhcp option-82 circuit-id vlan-ascii-tuple
Treevlan-ascii-tuple

Description

When configured, the router includes the VLAN ID and dot1p bits with the ASCII-tuple information. This only occurs on dot1q and QinQ-encapsulated ports. When the Option 82 bits are stripped, dot1p bits are copied to the Ethernet header of the outgoing packet.

When unconfigured, the router leaves the circuit ID sub-option of the DHCP packet empty.

Notes

The following elements are part of a choice: ascii-tuple, hex-string, none, or vlan-ascii-tuple.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

remote-id
Synopsis Enter the remote-id context
Context configure service vpls service-name sap sap dhcp option-82 remote-id
Treeremote-id

Description

Commands in this context configure the remote IP sub-option of the DHCP packet with the identity of the remote host end (typically the DHCP client).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ascii-string string-not-all-spaces
Synopsis User-defined ASCII string for the remote ID
Contextconfigure service vpls service-name sap sap dhcp option-82 remote-id ascii-string string-not-all-spaces
Treeascii-string
String length1 to 32

Notes

The following elements are part of a choice: ascii-string, hex-string, mac, or none.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

hex-string hex-string
Synopsis Option as a hexadecimal string
Context configure service vpls service-name sap sap dhcp option-82 remote-id hex-string hex-string
Treehex-string
String length1 to 66

Notes

The following elements are part of a choice: ascii-string, hex-string, mac, or none.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac
Synopsis Use the MAC address for the remote ID
Contextconfigure service vpls service-name sap sap dhcp option-82 remote-id mac
Treemac

Notes

The following elements are part of a choice: ascii-string, hex-string, mac, or none.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

none
Synopsis Do not include the remote ID
Context configure service vpls service-name sap sap dhcp option-82 remote-id none
Treenone

Notes

The following elements are part of a choice: ascii-string, hex-string, mac, or none.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

vendor-specific-option
Synopsis Enter the vendor-specific-option context
Contextconfigure service vpls service-name sap sap dhcp option-82 vendor-specific-option
Treevendor-specific-option

Description

Commands in this context configure the Nokia Vendor-Specific Option (VSO) of the DHCP packet.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

proxy-server
Synopsis Enter the proxy-server context
Contextconfigure service vpls service-name sap sap dhcp proxy-server
Treeproxy-server
Introduced25.3.R2

Platforms

7705 SAR Gen 2

lease-time
Synopsis Enter the lease-time context
Context configure service vpls service-name sap sap dhcp proxy-server lease-time
Treelease-time
Introduced25.3.R2

Platforms

7705 SAR Gen 2

snoop boolean
Synopsis Enable DHCP snooping on the SAP
Context configure service vpls service-name sap sap dhcp snoop boolean
Treesnoop
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dhcp6
Synopsis Enter the dhcp6 context
Context configure service vpls service-name sap sap dhcp6
Treedhcp6
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service vpls service-name sap sap dhcp6 description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ldra
Synopsis Enable the ldra context
Context configure service vpls service-name sap sap dhcp6 ldra
Treeldra
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface-type keyword
Synopsis LDRA interface type
Context configure service vpls service-name sap sap dhcp6 ldra interface-type keyword
Treeinterface-type

Description

This command specifies the LDRA interface type.

client-facing - configure the SAP as an untrusted client-facing interface. Only DHCPv6 client messages are accepted and encapsulated in a Relay-Forward message. It is mandatory to configure an interface ID for client-facing SAPs. Relay-Forward, Relay-Reply, and DHCPv6 server messages are silently dropped when received on a client-facing SAP.

network-facing - configure the SAP as a network-facing interface. Only Relay-Reply messages are accepted: the server message is extracted from the Relay-Reply message and forwarded in the VPLS. All other DHCPv6 message types are silently dropped when received on a network-facing SAP.

Optionsclient-facing, network-facing

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

options
Synopsis Enter the options context
Context configure service vpls service-name sap sap dhcp6 ldra options
Treeoptions
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface-id
Synopsis Enable the interface-id context
Contextconfigure service vpls service-name sap sap dhcp6 ldra options interface-id
Treeinterface-id
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ascii-tuple
Synopsis Use an ASCII-encoded concatenated tuple
Contextconfigure service vpls service-name sap sap dhcp6 ldra options interface-id ascii-tuple
Treeascii-tuple

Description

This command specifies the use of the ASCII-encoded concatenated tuple, which consists of the system name, service ID, and SAP ID separated by "|".

Notes

The following elements are part of a mandatory choice: ascii-tuple or vlan-ascii-tuple.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

vlan-ascii-tuple
Synopsis Use an enhanced ASCII-encoded concatenated tuple
Contextconfigure service vpls service-name sap sap dhcp6 ldra options interface-id vlan-ascii-tuple
Treevlan-ascii-tuple

Description

This command specifies the use of the ASCII-encoded concatenated tuple enhanced with VLAN ID and dot1p bits, consisting of the system name, service ID, SAP ID, dot1p inner VLAN, and inner VLAN ID separated by "|".

Notes

The following elements are part of a mandatory choice: ascii-tuple or vlan-ascii-tuple.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

remote-id
Synopsis Enter the remote-id context
Context configure service vpls service-name sap sap dhcp6 ldra options remote-id
Treeremote-id

Description

Commands in this context configure the Relay-Agent remote ID contents inserted by the LDRA.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac
Synopsis Use the DHCPv6 client source MAC address
Contextconfigure service vpls service-name sap sap dhcp6 ldra options remote-id mac
Treemac

Description

This command sets the enterprise number field of the Relay Agent remote ID to 6527 and configures the DHCPv6 client source MAC address as six hexadecimal numbers.

Notes

The following elements are part of a choice: mac or string.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

string string
Synopsis User-defined ASCII string
Context configure service vpls service-name sap sap dhcp6 ldra options remote-id string string
Treestring

Description

This command sets the enterprise number field of the Relay-Agent remote ID to 6527 and configures the ASCII-encoded string.

String length1 to 32

Notes

The following elements are part of a choice: mac or string.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

egress
Synopsis Enter the egress context
Context configure service vpls service-name sap sap egress
Treeegress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

agg-rate
Synopsis Enter the agg-rate context
Context configure service vpls service-name sap sap egress agg-rate
Treeagg-rate

Notes

The following elements are part of a choice: agg-rate or percent-agg-rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate number
Synopsis Enforced aggregate rate for all queues
Contextconfigure service vpls service-name sap sap egress agg-rate rate number
Treerate
Range1 to 6400000000
Unitskilobps
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

filter
Synopsis Enter the filter context
Context configure service vpls service-name sap sap egress filter
Treefilter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

qos
Synopsis Enter the qos context
Context configure service vpls service-name sap sap egress qos
Treeqos
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policer-control-policy
Synopsis Enter the policer-control-policy context
Contextconfigure service vpls service-name sap sap egress qos policer-control-policy
Treepolicer-control-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enable the overrides context
Context configure service vpls service-name sap sap egress qos policer-control-policy overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

root
Synopsis Enter the root context
Context configure service vpls service-name sap sap egress qos policer-control-policy overrides root
Treeroot
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority-mbs-thresholds
Synopsis Enter the priority-mbs-thresholds context
Contextconfigure service vpls service-name sap sap egress qos policer-control-policy overrides root priority-mbs-thresholds
Treepriority-mbs-thresholds
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority [priority-level] number
Synopsis Enter the priority list instance
Contextconfigure service vpls service-name sap sap egress qos policer-control-policy overrides root priority-mbs-thresholds priority number
Treepriority
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sap-egress
Synopsis Enter the sap-egress context
Context configure service vpls service-name sap sap egress qos sap-egress
Treesap-egress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enter the overrides context
Context configure service vpls service-name sap sap egress qos sap-egress overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

queue [queue-id] reference
Synopsis Enter the queue list instance
Context configure service vpls service-name sap sap egress qos sap-egress overrides queue reference
Treequeue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure service vpls service-name sap sap egress qos sap-egress overrides queue reference adaptation-rule
Treeadaptation-rule
Introduced25.3.R2

Platforms

7705 SAR Gen 2

avg-frame-overhead decimal-number
Synopsis Average packet-to-frame encapsulation overhead
Contextconfigure service vpls service-name sap sap egress qos sap-egress overrides queue reference avg-frame-overhead decimal-number
Treeavg-frame-overhead

Description

This command configures overrides for the average frame overhead. The overrides supersede the average frame overhead configuration under the queue.

For a full description of this command, see the configure qos network-queue queue avg-frame-overhead and configure qos sap-egress queue avg-frame-overhead contexts.

Range0.00 to 100.00
Introduced25.3.R2

Platforms

7705 SAR Gen 2

drop-tail
Synopsis Enter the drop-tail context
Context configure service vpls service-name sap sap egress qos sap-egress overrides queue reference drop-tail
Treedrop-tail
Introduced25.3.R2

Platforms

7705 SAR Gen 2

low
Synopsis Enter the low context
Context configure service vpls service-name sap sap egress qos sap-egress overrides queue reference drop-tail low
Treelow
Introduced25.3.R2

Platforms

7705 SAR Gen 2

parent
Synopsis Enter the parent context
Context configure service vpls service-name sap sap egress qos sap-egress overrides queue reference parent
Treeparent
Introduced25.3.R2

Platforms

7705 SAR Gen 2

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service vpls service-name sap sap egress qos sap-egress overrides queue reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate
Synopsis Enter the rate context
Context configure service vpls service-name sap sap egress qos sap-egress overrides queue reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

port-redirect-group
Synopsis Enter the port-redirect-group context
Contextconfigure service vpls service-name sap sap egress qos sap-egress port-redirect-group
Treeport-redirect-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service vpls service-name sap sap egress qos scheduler-policy
Treescheduler-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enter the overrides context
Context configure service vpls service-name sap sap egress qos scheduler-policy overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

scheduler [scheduler-name] named-item
Synopsis Enter the scheduler list instance
Contextconfigure service vpls service-name sap sap egress qos scheduler-policy overrides scheduler named-item
Treescheduler
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[scheduler-name] named-item
Synopsis Scheduler name
Contextconfigure service vpls service-name sap sap egress qos scheduler-policy overrides scheduler named-item
Treescheduler

Description

This command specifies the scheduler name which is composed of printable 7-bit ASCII characters. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes. Each scheduler must have a unique name within the context of the scheduler policy. However, the same name can be reused in multiple scheduler policies. If the scheduler name already exists within the policy tier level, the context changes to that scheduler name for the purpose of editing the scheduler commands.

If the scheduler name exists within the policy on a different tier, an error occurs and the current context does not change. If the scheduler name does not exist in this or another tier within the scheduler policy, it is assumed that an attempt is being made to create a scheduler of that name.

If the provided scheduler name is invalid, a name syntax error occurs, the command does not execute, and the context is not change.

String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

parent
Synopsis Enter the parent context
Context configure service vpls service-name sap sap egress qos scheduler-policy overrides scheduler named-item parent
Treeparent
Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate
Synopsis Enter the rate context
Context configure service vpls service-name sap sap egress qos scheduler-policy overrides scheduler named-item rate
Treerate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

etree-leaf boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEnable etree leaf access-circuit status
Contextconfigure service vpls service-name sap sap etree-leaf boolean
Treeetree-leaf
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

etree-root-leaf-tag
Synopsis Enable the etree-root-leaf-tag context
Contextconfigure service vpls service-name sap sap etree-root-leaf-tag
Treeetree-root-leaf-tag
Introduced25.3.R2

Platforms

7705 SAR Gen 2

leaf number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisLeaf tag value
Contextconfigure service vpls service-name sap sap etree-root-leaf-tag leaf number
Treeleaf
Range1 to 4094

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

fdb
Synopsis Enter the fdb context
Context configure service vpls service-name sap sap fdb
Treefdb
Introduced25.3.R2

Platforms

7705 SAR Gen 2

auto-learn-mac-protect-exclude-list reference
Synopsis Referenced MAC protect exclusion list
Contextconfigure service vpls service-name sap sap fdb auto-learn-mac-protect-exclude-list reference
Treeauto-learn-mac-protect-exclude-list

Description

This command references the name of a MAC protect exclusion list.

Dynamically-learned MAC Source Addresses (SA) are protected if they are learned on an object with ALMP configured and no exclusion list is associated with the object, or if the MAC SA does not match any entry in an associated exclusion list.

An exclusion list can be used in multiple objects of a service. If a list is empty, ALMP does not exclude any learned MAC SAs from protection on the object.

Reference

configure service mac-list named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

limit-mac-move keyword
Synopsis MAC move
Contextconfigure service vpls service-name sap sap fdb limit-mac-move keyword
Treelimit-mac-move
Optionsblockable, non-blockable
Defaultblockable
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

mac-learning
Synopsis Enter the mac-learning context
Contextconfigure service vpls service-name sap sap fdb mac-learning
Treemac-learning
Introduced25.3.R2

Platforms

7705 SAR Gen 2

aging boolean
Synopsis Enable aging of MAC addresses
Context configure service vpls service-name sap sap fdb mac-learning aging boolean
Treeaging
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac-pinning boolean
Synopsis Enable MAC address pinning on this SAP
Contextconfigure service vpls service-name sap sap fdb mac-pinning boolean
Treemac-pinning
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

maximum-mac-addresses number
Synopsis Maximum number of MAC address entries in the FDB
Contextconfigure service vpls service-name sap sap fdb maximum-mac-addresses number
Treemaximum-mac-addresses

Description

This command specifies the maximum number of FDB entries for both learned and static MAC addresses for this SAP.

When the configured limit is reached, no new addresses are learned from the SAP or spoke SDP until at least one FDB entry is aged out or cleared.

When the configured limit is reached and the configure service pw-template fdb discard-unknown-source command is set to true for this SAP, packets with unknown source MAC addresses are discarded. If discard-unknown-source is set to false, the packets are forwarded if their destination MAC addresses are known, or flooded if their destination MAC addresses are unknown.

However, if the configure service vpls fdb discard-unknown command is set to true, packets with unknown destination MAC addresses are discarded, even if the limit of FDB entries on the specific VPLS instance is not reached.

When unconfigured, the SAP uses the global MAC learning limitations.

Range1 to 511999
Introduced25.3.R2

Platforms

7705 SAR Gen 2

igmp-snooping
Synopsis Enter the igmp-snooping context
Contextconfigure service vpls service-name sap sap igmp-snooping
Treeigmp-snooping
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static
Synopsis Enter the static context
Context configure service vpls service-name sap sap igmp-snooping static
Treestatic
Introduced25.3.R2

Platforms

7705 SAR Gen 2

group [group-address] ipv4-multicast-address
Synopsis Enter the group list instance
Context configure service vpls service-name sap sap igmp-snooping static group ipv4-multicast-address
Treegroup
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[group-address] ipv4-multicast-address
Synopsis Group address of static IGMP multicast channel
Contextconfigure service vpls service-name sap sap igmp-snooping static group ipv4-multicast-address
Treegroup

Description

This command configures an address that receives data on an interface. The IP address must be unique for each static group.

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

source [source-address] ipv4-unicast-address
Synopsis Add a list entry for source
Context configure service vpls service-name sap sap igmp-snooping static group ipv4-multicast-address source ipv4-unicast-address
Treesource

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[source-address] ipv4-unicast-address
Synopsis Source IP address of multicast channel sending data
Contextconfigure service vpls service-name sap sap igmp-snooping static group ipv4-multicast-address source ipv4-unicast-address
Treesource

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

starg
Synopsis any source address (*,G)
Context configure service vpls service-name sap sap igmp-snooping static group ipv4-multicast-address starg
Treestarg

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

version keyword
Synopsis IGMP protocol version
Context configure service vpls service-name sap sap igmp-snooping version keyword
Treeversion
Options1, 2, 3
Default3
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

ingress
Synopsis Enter the ingress context
Context configure service vpls service-name sap sap ingress
Treeingress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter
Synopsis Enter the filter context
Context configure service vpls service-name sap sap ingress filter
Treefilter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

qos
Synopsis Enter the qos context
Context configure service vpls service-name sap sap ingress qos
Treeqos
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policer-control-policy
Synopsis Enter the policer-control-policy context
Contextconfigure service vpls service-name sap sap ingress qos policer-control-policy
Treepolicer-control-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enable the overrides context
Context configure service vpls service-name sap sap ingress qos policer-control-policy overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

root
Synopsis Enter the root context
Context configure service vpls service-name sap sap ingress qos policer-control-policy overrides root
Treeroot
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority-mbs-thresholds
Synopsis Enter the priority-mbs-thresholds context
Contextconfigure service vpls service-name sap sap ingress qos policer-control-policy overrides root priority-mbs-thresholds
Treepriority-mbs-thresholds
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority [priority-level] number
Synopsis Enter the priority list instance
Contextconfigure service vpls service-name sap sap ingress qos policer-control-policy overrides root priority-mbs-thresholds priority number
Treepriority
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sap-ingress
Synopsis Enter the sap-ingress context
Context configure service vpls service-name sap sap ingress qos sap-ingress
Treesap-ingress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

fp-redirect-group
Synopsis Enter the fp-redirect-group context
Contextconfigure service vpls service-name sap sap ingress qos sap-ingress fp-redirect-group
Treefp-redirect-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enter the overrides context
Context configure service vpls service-name sap sap ingress qos sap-ingress overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policer [policer-id] reference
Synopsis Enter the policer list instance
Contextconfigure service vpls service-name sap sap ingress qos sap-ingress overrides policer reference
Treepolicer
Introduced25.3.R2

Platforms

7705 SAR Gen 2

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service vpls service-name sap sap ingress qos sap-ingress overrides policer reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate
Synopsis Enter the rate context
Context configure service vpls service-name sap sap ingress qos sap-ingress overrides policer reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

stat-mode keyword
Synopsis Mode of statistics collected by the policer
Contextconfigure service vpls service-name sap sap ingress qos sap-ingress overrides policer reference stat-mode keyword
Treestat-mode
Optionsno-stats, minimal, offered-profile-no-cir, offered-total-cir, offered-priority-no-cir, offered-profile-cir, offered-priority-cir, offered-limited-profile-cir, offered-profile-capped-cir, offered-limited-capped-cir
Introduced25.3.R2

Platforms

7705 SAR Gen 2

queue [queue-id] reference
Synopsis Enter the queue list instance
Context configure service vpls service-name sap sap ingress qos sap-ingress overrides queue reference
Treequeue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure service vpls service-name sap sap ingress qos sap-ingress overrides queue reference adaptation-rule
Treeadaptation-rule
Introduced25.3.R2

Platforms

7705 SAR Gen 2

drop-tail
Synopsis Enter the drop-tail context
Context configure service vpls service-name sap sap ingress qos sap-ingress overrides queue reference drop-tail
Treedrop-tail
Introduced25.3.R2

Platforms

7705 SAR Gen 2

low
Synopsis Enter the low context
Context configure service vpls service-name sap sap ingress qos sap-ingress overrides queue reference drop-tail low
Treelow
Introduced25.3.R2

Platforms

7705 SAR Gen 2

parent
Synopsis Enter the parent context
Context configure service vpls service-name sap sap ingress qos sap-ingress overrides queue reference parent
Treeparent
Introduced25.3.R2

Platforms

7705 SAR Gen 2

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service vpls service-name sap sap ingress qos sap-ingress overrides queue reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate
Synopsis Enter the rate context
Context configure service vpls service-name sap sap ingress qos sap-ingress overrides queue reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service vpls service-name sap sap ingress qos scheduler-policy
Treescheduler-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enter the overrides context
Context configure service vpls service-name sap sap ingress qos scheduler-policy overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

scheduler [scheduler-name] named-item
Synopsis Enter the scheduler list instance
Contextconfigure service vpls service-name sap sap ingress qos scheduler-policy overrides scheduler named-item
Treescheduler
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[scheduler-name] named-item
Synopsis Scheduler name
Contextconfigure service vpls service-name sap sap ingress qos scheduler-policy overrides scheduler named-item
Treescheduler

Description

This command specifies the scheduler name which is composed of printable 7-bit ASCII characters. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes. Each scheduler must have a unique name within the context of the scheduler policy. However, the same name can be reused in multiple scheduler policies. If the scheduler name already exists within the policy tier level, the context changes to that scheduler name for the purpose of editing the scheduler commands.

If the scheduler name exists within the policy on a different tier, an error occurs and the current context does not change. If the scheduler name does not exist in this or another tier within the scheduler policy, it is assumed that an attempt is being made to create a scheduler of that name.

If the provided scheduler name is invalid, a name syntax error occurs, the command does not execute, and the context is not change.

String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

parent
Synopsis Enter the parent context
Context configure service vpls service-name sap sap ingress qos scheduler-policy overrides scheduler named-item parent
Treeparent
Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate
Synopsis Enter the rate context
Context configure service vpls service-name sap sap ingress qos scheduler-policy overrides scheduler named-item rate
Treerate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

l2pt
Synopsis Enter the l2pt context
Context configure service vpls service-name sap sap l2pt
Treel2pt
Introduced25.3.R2

Platforms

7705 SAR Gen 2

force-boundary
Synopsis Enable the force-boundary context
Contextconfigure service vpls service-name sap sap l2pt force-boundary
Treeforce-boundary
Introduced25.3.R2

Platforms

7705 SAR Gen 2

protocols
Synopsis Enter the protocols context
Context configure service vpls service-name sap sap l2pt force-boundary protocols
Treeprotocols
Introduced25.3.R2

Platforms

7705 SAR Gen 2

termination
Synopsis Enable the termination context
Contextconfigure service vpls service-name sap sap l2pt termination
Treetermination
Introduced25.3.R2

Platforms

7705 SAR Gen 2

protocols
Synopsis Enter the protocols context
Context configure service vpls service-name sap sap l2pt termination protocols
Treeprotocols
Introduced25.3.R2

Platforms

7705 SAR Gen 2

lag
Synopsis Enter the lag context
Context configure service vpls service-name sap sap lag
Treelag
Introduced25.3.R2

Platforms

7705 SAR Gen 2

managed-vlan-list
Synopsis Enter the managed-vlan-list context
Contextconfigure service vpls service-name sap sap managed-vlan-list
Treemanaged-vlan-list
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mc-ring
Synopsis Enable the mc-ring context
Context configure service vpls service-name sap sap mc-ring
Treemc-ring
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ring-node named-item
Synopsis Name for the ring node associated with this SAP
Contextconfigure service vpls service-name sap sap mc-ring ring-node named-item
Treering-node
String length1 to 32

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mld-snooping
Synopsis Enter the mld-snooping context
Contextconfigure service vpls service-name sap sap mld-snooping
Treemld-snooping
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static
Synopsis Enter the static context
Context configure service vpls service-name sap sap mld-snooping static
Treestatic
Introduced25.3.R2

Platforms

7705 SAR Gen 2

group [group-address] ipv6-multicast-address
Synopsis Enter the group list instance
Context configure service vpls service-name sap sap mld-snooping static group ipv6-multicast-address
Treegroup
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[group-address] ipv6-multicast-address
Synopsis Group address of multicast channel
Context configure service vpls service-name sap sap mld-snooping static group ipv6-multicast-address
Treegroup

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

source [source-address] ipv6-unicast-address
Synopsis Add a list entry for source
Context configure service vpls service-name sap sap mld-snooping static group ipv6-multicast-address source ipv6-unicast-address
Treesource

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[source-address] ipv6-unicast-address
Synopsis Source IP address
Context configure service vpls service-name sap sap mld-snooping static group ipv6-multicast-address source ipv6-unicast-address
Treesource

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

starg
Synopsis any source address (*,G)
Context configure service vpls service-name sap sap mld-snooping static group ipv6-multicast-address starg
Treestarg

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

version keyword
Synopsis Version of MLD running on the SAP or SDP
Contextconfigure service vpls service-name sap sap mld-snooping version keyword
Treeversion
Options1, 2
Default 2
Introduced25.3.R2

Platforms

7705 SAR Gen 2

monitor-oper-group reference
Synopsis Monitor operational group
Context configure service vpls service-name sap sap monitor-oper-group reference
Treemonitor-oper-group

Reference

configure service oper-group named-item

Notes

The following elements are part of a choice: monitor-oper-group or oper-group.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

oper-group reference
Synopsis Operational group
Context configure service vpls service-name sap sap oper-group reference
Treeoper-group

Reference

configure service oper-group named-item

Notes

The following elements are part of a choice: monitor-oper-group or oper-group.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

stp
Synopsis Enter the stp context
Context configure service vpls service-name sap sap stp
Treestp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of STP
Context configure service vpls service-name sap sap stp admin-state keyword
Treeadmin-state
Optionsenable, disable
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

auto-edge boolean
Synopsis Enable automatic detection of edge port characteristics
Contextconfigure service vpls service-name sap sap stp auto-edge boolean
Treeauto-edge

Description

When configured to true, the router automatically detects the edge port characteristics of the SAP or spoke SDP. The STP concludes there is no bridge behind the spoke SDP, the OPER_EDGE variable is dynamically set to true. If a BPDU is received, the OPER_EDGE variable is dynamically set to false.

When configured to false, the router disables automatic detection.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

edge-port boolean
Synopsis Designate SAP or SDP as an edge port
Context configure service vpls service-name sap sap stp edge-port boolean
Treeedge-port
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

link-type keyword
Synopsis Configure STP link-type
Context configure service vpls service-name sap sap stp link-type keyword
Treelink-type
Optionspt-pt, shared
Default pt-pt
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mst-instance [mst-inst-number] number
Synopsis Enter the mst-instance list instance
Contextconfigure service vpls service-name sap sap stp mst-instance number
Treemst-instance
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[mst-inst-number] number
Synopsis Multiple Spanning Tree Instance number
Contextconfigure service vpls service-name sap sap stp mst-instance number
Treemst-instance
Range1 to 4094

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mst-port-priority number
Synopsis MSTI port priority
Context configure service vpls service-name sap sap stp mst-instance number mst-port-priority number
Treemst-port-priority
Range0 | 16 | 32 | 48 | 64 | 80 | 96 | 112 | 128 | 144 | 160 | 176 | 192 | 208 | 224 | 240
Default128
Introduced25.3.R2

Platforms

7705 SAR Gen 2

path-cost number
Synopsis Configure path-cost
Context configure service vpls service-name sap sap stp path-cost number
Treepath-cost
Range1 to 200000000
Default10
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

port-num number
Synopsis Configure virtual port number
Context configure service vpls service-name sap sap stp port-num number
Treeport-num
Range1 to 2047
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority number
Synopsis Configure STP priority
Context configure service vpls service-name sap sap stp priority number
Treepriority
Range0 to 255
Default128
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

root-guard boolean
Synopsis Enable/disable STP root-guard
Context configure service vpls service-name sap sap stp root-guard boolean
Treeroot-guard
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

service-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisService ID
Contextconfigure service vpls service-name service-id number
Treeservice-id
Range1 to 2147483647
Introduced25.3.R2

Platforms

7705 SAR Gen 2

service-mtu number
Synopsis MTU size
Contextconfigure service vpls service-name service-mtu number
Treeservice-mtu

Description

This command configures the Maximum Transmission Unit (MTU) value (payload) for the service. The system uses the value to validate the operational state of the SAP and SDP binding within the service. The value overrides the default MTU for the service type.

The service MTU and a SAP’s service delineation encapsulation overhead (4 bytes for a dot1q tag) are used to derive the required MTU of the physical port or channel on which the SAP was created. If the required payload is larger than the port or channel MTU, the SAP is placed in an inoperative state. If the required MTU is equal to or less than the port or channel MTU, the SAP transitions to the operative state.

When binding an SDP to a service, the service MTU is compared to the path MTU associated with the SDP. The path MTU can be administratively defined in the context of the SDP. The default or administrative path MTU can be dynamically reduced due to the MTU capabilities discovered by the tunneling mechanism of the SDP or the egress interface MTU capabilities based on the next hop in the tunnel path. If the service MTU is larger than the path MTU, the SDP binding for the service is placed in an inoperative state. If the service MTU is equal to or less than the path MTU, the SDP binding is placed in an operational state.

If a service MTU, port or channel MTU, or path MTU is dynamically or administratively modified, all associated SAP and SDP binding operational states are automatically reevaluated.

Binding operational states are automatically reevaluated.

For I-VPLS and Epipes bound to a B-VPLS, the service MTU must be at least 18 bytes smaller than the B-VPLS service MTU to accommodate the PBB header.

Because this connects a Layer 2 to a Layer 3 service, adjust the service MTU under the Epipe service. The MTU that is advertised from the Epipe side is service MTU minus EtherHeaderSize.

In the configure service epipe spoke-sdp context, the adv-service-mtu command can be used to override the configured MTU value used in T-LDP signaling to the far-end of an Epipe spoke-sdp. The adv-service-mtu command is also used to validate the value signaled by the far-end PE.

Range1 to 9782
Introduced25.3.R2

Platforms

7705 SAR Gen 2

split-horizon-group [shg-name] named-item
Synopsis Enter the split-horizon-group list instance
Contextconfigure service vpls service-name split-horizon-group named-item
Treesplit-horizon-group

Description

Commands in this context configure the split-horizon group options used in the VPLS instance.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[shg-name] named-item
Synopsis SHG name to which the SDP belongs
Context configure service vpls service-name split-horizon-group named-item
Treesplit-horizon-group
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

fdb
Synopsis Enter the fdb context
Context configure service vpls service-name split-horizon-group named-item fdb
Treefdb
Introduced25.3.R2

Platforms

7705 SAR Gen 2

saps
Synopsis Enter the saps context
Context configure service vpls service-name split-horizon-group named-item fdb saps
Treesaps
Introduced25.3.R2

Platforms

7705 SAR Gen 2

auto-learn-mac-protect-exclude-list reference
Synopsis Referenced MAC protect exclusion list name
Contextconfigure service vpls service-name split-horizon-group named-item fdb saps auto-learn-mac-protect-exclude-list reference
Treeauto-learn-mac-protect-exclude-list

Description

This command references the name of a MAC protect exclusion list.

Dynamically-learned MAC Source Addresses (SA) are protected if they are learned on an object with ALMP configured and no exclusion list is associated with the object, or if the MAC SA does not match any entry in an associated exclusion list.

An exclusion list can be used in multiple objects of a service. If a list is empty, ALMP does not exclude any learned MAC SAs from protection on the object.

Reference

configure service mac-list named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

residential boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDefine as a residential split horizon group
Contextconfigure service vpls service-name split-horizon-group named-item residential boolean
Treeresidential
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

spoke-sdp [sdp-bind-id] sdp-bind-id
Synopsis Enter the spoke-sdp list instance
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id
Treespoke-sdp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[sdp-bind-id] sdp-bind-id
Synopsis SDP binding ID
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id
Treespoke-sdp
String length3 to 16

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the SDP binding to the service
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

adv-service-mtu number
Synopsis Advertise service MTU value
Context configure service vpls service-name spoke-sdp sdp-bind-id adv-service-mtu number
Treeadv-service-mtu

Description

This command configures the MTU value that is signaled in the targeted LDP for the spoke-SDP. The router uses the value for signaling and for validation with the received MTU instead of the service MTU. However, the value does not affect the locally enforced value, which is still based on the service MTU.

This command cannot be configured on a spoke-SDP that is bound to an SDP with the adv-mtu-override command.

Range0 to 9782
Introduced25.3.R2

Platforms

7705 SAR Gen 2

collect-stats boolean
Synopsis Allow agent to collect accounting statistics
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id collect-stats boolean
Treecollect-stats
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

control-word boolean
Synopsis Use the control word as preferred
Context configure service vpls service-name spoke-sdp sdp-bind-id control-word boolean
Treecontrol-word
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service vpls service-name spoke-sdp sdp-bind-id description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dhcp
Synopsis Enter the dhcp context
Context configure service vpls service-name spoke-sdp sdp-bind-id dhcp
Treedhcp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

snoop boolean
Synopsis Allow DHCP snooping of DHCP messages on the SAP or SDP
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id dhcp snoop boolean
Treesnoop
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

egress
Synopsis Enter the egress context
Context configure service vpls service-name spoke-sdp sdp-bind-id egress
Treeegress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter
Synopsis Enter the filter context
Context configure service vpls service-name spoke-sdp sdp-bind-id egress filter
Treefilter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mfib-allowed-mda-destinations
Synopsis Enter the mfib-allowed-mda-destinations context
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id egress mfib-allowed-mda-destinations
Treemfib-allowed-mda-destinations
Introduced25.3.R2

Platforms

7705 SAR Gen 2

qos
Synopsis Enter the qos context
Context configure service vpls service-name spoke-sdp sdp-bind-id egress qos
Treeqos
Introduced25.3.R2

Platforms

7705 SAR Gen 2

network
Synopsis Enter the network context
Context configure service vpls service-name spoke-sdp sdp-bind-id egress qos network
Treenetwork
Introduced25.3.R2

Platforms

7705 SAR Gen 2

port-redirect-group
Synopsis Enter the port-redirect-group context
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id egress qos network port-redirect-group
Treeport-redirect-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEgress MPLS VC label to send packets to the far end
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id egress vc-label number
Treevc-label
Range16 to 1048575
Introduced25.3.R2

Platforms

7705 SAR Gen 2

endpoint
Synopsis Enter the endpoint context
Context configure service vpls service-name spoke-sdp sdp-bind-id endpoint
Treeendpoint
Introduced25.3.R2

Platforms

7705 SAR Gen 2

name reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisName of service endpoint to which SDP bind is attached
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id endpoint name reference
Treename

Reference

configure service vpls service-name endpoint named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

precedence (number | keyword)
Synopsis Precedence of this SDP bind when there are multiple SDP binds attached to one service endpoint
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id endpoint precedence (number | keyword)
Treeprecedence
Range1 to 4
Optionsprimary
Default4
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

etree-leaf boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEnable etree leaf access-circuit status
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id etree-leaf boolean
Treeetree-leaf
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

etree-root-leaf-tag boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisE-tree root leaf tag status
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id etree-root-leaf-tag boolean
Treeetree-root-leaf-tag
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

fdb
Synopsis Enter the fdb context
Context configure service vpls service-name spoke-sdp sdp-bind-id fdb
Treefdb
Introduced25.3.R2

Platforms

7705 SAR Gen 2

auto-learn-mac-protect-exclude-list reference
Synopsis Referenced MAC protect exclusion list name
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id fdb auto-learn-mac-protect-exclude-list reference
Treeauto-learn-mac-protect-exclude-list

Description

This command references the name of a MAC protect exclusion list.

Dynamically-learned MAC Source Addresses (SA) are protected if they are learned on an object with ALMP configured and no exclusion list is associated with the object, or if the MAC SA does not match any entry in an associated exclusion list.

An exclusion list can be used in multiple objects of a service. If a list is empty, ALMP does not exclude any learned MAC SAs from protection on the object.

Reference

configure service mac-list named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac-learning
Synopsis Enter the mac-learning context
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id fdb mac-learning
Treemac-learning
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac-pinning boolean
Synopsis MAC address pinning in active status
Context configure service vpls service-name spoke-sdp sdp-bind-id fdb mac-pinning boolean
Treemac-pinning
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

maximum-mac-addresses number
Synopsis Maximum number of MAC address entries in the FDB
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id fdb maximum-mac-addresses number
Treemaximum-mac-addresses

Description

This command specifies the maximum number of FDB entries for both learned and static MAC addresses for this spoke SDP.

When the configured limit is reached, no new addresses are learned from the SAP or spoke SDP until at least one FDB entry is aged out or cleared.

When the configured limit is reached and the configure service spoke-sdp fdb discard-unknown-source command is set to true for this spoke SDP, packets with unknown source MAC addresses are discarded. If discard-unknown-source is set to false, the packets are forwarded if their destination MAC addresses are known, or flooded if their destination MAC addresses are unknown.

However, if the configure service vpls fdb discard-unknown command is set to true, packets with unknown destination MAC addresses are discarded, even if the limit of FDB entries on the specific VPLS instance is not reached.

When unconfigured, the spoke SDP uses the global MAC learning limitations.

Range1 to 511999
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hash-label
Synopsis Enable the hash-label context
Context configure service vpls service-name spoke-sdp sdp-bind-id hash-label
Treehash-label

Description

Commands in this context configure the use of hash labels for egress datapaths.

For information about hash-label handling, see the "Hash label" section of the 7705 SAR Gen 2 MPLS Guide.

Notes

The following elements are part of a choice: entropy-label or hash-label.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

signal-capability
Synopsis Signal hash label capability to the remote PE
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id hash-label signal-capability
Treesignal-capability

Description

When configured, this command enables the signaling and negotiating of the hash label between the local and remote PE nodes.

The signaling process outcome determines whether the local PE inserts the hash label on the user packets. This outcome can override the local PE configuration.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

igmp-snooping
Synopsis Enter the igmp-snooping context
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id igmp-snooping
Treeigmp-snooping
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static
Synopsis Enter the static context
Context configure service vpls service-name spoke-sdp sdp-bind-id igmp-snooping static
Treestatic
Introduced25.3.R2

Platforms

7705 SAR Gen 2

group [group-address] ipv4-multicast-address
Synopsis Enter the group list instance
Context configure service vpls service-name spoke-sdp sdp-bind-id igmp-snooping static group ipv4-multicast-address
Treegroup
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[group-address] ipv4-multicast-address
Synopsis Group address of static IGMP multicast channel
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id igmp-snooping static group ipv4-multicast-address
Treegroup

Description

This command configures an address that receives data on an interface. The IP address must be unique for each static group.

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

source [source-address] ipv4-unicast-address
Synopsis Add a list entry for source
Context configure service vpls service-name spoke-sdp sdp-bind-id igmp-snooping static group ipv4-multicast-address source ipv4-unicast-address
Treesource

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[source-address] ipv4-unicast-address
Synopsis Source IP address of multicast channel sending data
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id igmp-snooping static group ipv4-multicast-address source ipv4-unicast-address
Treesource

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

starg
Synopsis any source address (*,G)
Context configure service vpls service-name spoke-sdp sdp-bind-id igmp-snooping static group ipv4-multicast-address starg
Treestarg

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ingress
Synopsis Enter the ingress context
Context configure service vpls service-name spoke-sdp sdp-bind-id ingress
Treeingress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter
Synopsis Enter the filter context
Context configure service vpls service-name spoke-sdp sdp-bind-id ingress filter
Treefilter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

qos
Synopsis Enter the qos context
Context configure service vpls service-name spoke-sdp sdp-bind-id ingress qos
Treeqos
Introduced25.3.R2

Platforms

7705 SAR Gen 2

network
Synopsis Enter the network context
Context configure service vpls service-name spoke-sdp sdp-bind-id ingress qos network
Treenetwork
Introduced25.3.R2

Platforms

7705 SAR Gen 2

fp-redirect-group
Synopsis Enter the fp-redirect-group context
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id ingress qos network fp-redirect-group
Treefp-redirect-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIngress MPLS VC label to send packets to the far end
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id ingress vc-label number
Treevc-label
Range1 to 1048575
Introduced25.3.R2

Platforms

7705 SAR Gen 2

l2pt
Synopsis Enter the l2pt context
Context configure service vpls service-name spoke-sdp sdp-bind-id l2pt
Treel2pt
Introduced25.3.R2

Platforms

7705 SAR Gen 2

termination
Synopsis Enable the termination context
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id l2pt termination
Treetermination
Introduced25.3.R2

Platforms

7705 SAR Gen 2

protocols
Synopsis Enter the protocols context
Context configure service vpls service-name spoke-sdp sdp-bind-id l2pt termination protocols
Treeprotocols
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mld-snooping
Synopsis Enter the mld-snooping context
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id mld-snooping
Treemld-snooping
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static
Synopsis Enter the static context
Context configure service vpls service-name spoke-sdp sdp-bind-id mld-snooping static
Treestatic
Introduced25.3.R2

Platforms

7705 SAR Gen 2

group [group-address] ipv6-multicast-address
Synopsis Enter the group list instance
Context configure service vpls service-name spoke-sdp sdp-bind-id mld-snooping static group ipv6-multicast-address
Treegroup
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[group-address] ipv6-multicast-address
Synopsis Group address of multicast channel
Context configure service vpls service-name spoke-sdp sdp-bind-id mld-snooping static group ipv6-multicast-address
Treegroup

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

source [source-address] ipv6-unicast-address
Synopsis Add a list entry for source
Context configure service vpls service-name spoke-sdp sdp-bind-id mld-snooping static group ipv6-multicast-address source ipv6-unicast-address
Treesource

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[source-address] ipv6-unicast-address
Synopsis Source IP address
Context configure service vpls service-name spoke-sdp sdp-bind-id mld-snooping static group ipv6-multicast-address source ipv6-unicast-address
Treesource

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

starg
Synopsis any source address (*,G)
Context configure service vpls service-name spoke-sdp sdp-bind-id mld-snooping static group ipv6-multicast-address starg
Treestarg

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

version keyword
Synopsis Version of MLD running on the SAP or SDP
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id mld-snooping version keyword
Treeversion
Options1, 2
Default 2
Introduced25.3.R2

Platforms

7705 SAR Gen 2

monitor-oper-group reference
Synopsis Operational group that affects state of the SDP bind
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id monitor-oper-group reference
Treemonitor-oper-group

Reference

configure service oper-group named-item

Notes

The following elements are part of a choice: monitor-oper-group or oper-group.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

oper-group reference
Synopsis Operational group identifier
Context configure service vpls service-name spoke-sdp sdp-bind-id oper-group reference
Treeoper-group

Reference

configure service oper-group named-item

Notes

The following elements are part of a choice: monitor-oper-group or oper-group.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

split-horizon-group reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisName of the split horizon group where the spoke SDP bind belongs to
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id split-horizon-group reference
Treesplit-horizon-group

Reference

configure service vpls service-name split-horizon-group named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

stp
Synopsis Enter the stp context
Context configure service vpls service-name spoke-sdp sdp-bind-id stp
Treestp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of STP
Context configure service vpls service-name spoke-sdp sdp-bind-id stp admin-state keyword
Treeadmin-state
Optionsenable, disable
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

auto-edge boolean
Synopsis Enable automatic detection of edge port characteristics
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id stp auto-edge boolean
Treeauto-edge

Description

When configured to true, the router automatically detects the edge port characteristics of the SAP or spoke SDP. The STP concludes there is no bridge behind the spoke SDP, the OPER_EDGE variable is dynamically set to true. If a BPDU is received, the OPER_EDGE variable is dynamically set to false.

When configured to false, the router disables automatic detection.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

edge-port boolean
Synopsis Designate SAP or SDP as an edge port
Context configure service vpls service-name spoke-sdp sdp-bind-id stp edge-port boolean
Treeedge-port
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

link-type keyword
Synopsis Configure STP link-type
Context configure service vpls service-name spoke-sdp sdp-bind-id stp link-type keyword
Treelink-type
Optionspt-pt, shared
Default pt-pt
Introduced25.3.R2

Platforms

7705 SAR Gen 2

path-cost number
Synopsis Configure path-cost
Context configure service vpls service-name spoke-sdp sdp-bind-id stp path-cost number
Treepath-cost
Range1 to 200000000
Default10
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

port-num number
Synopsis Virtual port number
Context configure service vpls service-name spoke-sdp sdp-bind-id stp port-num number
Treeport-num
Range1 to 2047
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority number
Synopsis Configure STP priority
Context configure service vpls service-name spoke-sdp sdp-bind-id stp priority number
Treepriority
Range0 to 255
Default128
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

root-guard boolean
Synopsis Enable/disable STP root-guard
Context configure service vpls service-name spoke-sdp sdp-bind-id stp root-guard boolean
Treeroot-guard
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vc-type keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisType of virtual circuit (VC) associated with the SDP binding; VPLS not supported
Contextconfigure service vpls service-name spoke-sdp sdp-bind-id vc-type keyword
Treevc-type
Optionsether, vlan
Default ether
Introduced25.3.R2

Platforms

7705 SAR Gen 2

stp
Synopsis Enter the stp context
Context configure service vpls service-name stp
Treestp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of STP
Context configure service vpls service-name stp admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

forward-delay number
Synopsis Configure forward-delay
Context configure service vpls service-name stp forward-delay number
Treeforward-delay
Range4 to 30
Default15
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

hello-time number
Synopsis Configure hello-time
Context configure service vpls service-name stp hello-time number
Treehello-time
Range1 to 10
Default2
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

hold-count number
Synopsis Configure BPDU transmit hold count
Context configure service vpls service-name stp hold-count number
Treehold-count
Range1 to 20
Default6
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

maximum-age number
Synopsis Configure maximum STP information age
Contextconfigure service vpls service-name stp maximum-age number
Treemaximum-age
Range6 to 40
Default20
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

mode keyword
Synopsis Configure protocol version
Context configure service vpls service-name stp mode keyword
Treemode
Optionsrstp, comp-dot1w, dot1w, mstp, pmstp
Defaultrstp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mst-instance [mst-inst-number] number
Synopsis Enter the mst-instance list instance
Contextconfigure service vpls service-name stp mst-instance number
Treemst-instance
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[mst-inst-number] number
Synopsis Multiple Spanning Tree Instance number
Contextconfigure service vpls service-name stp mst-instance number
Treemst-instance
Range1 to 4094

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mst-priority number
Synopsis Priority of multiple spanning tree instance
Contextconfigure service vpls service-name stp mst-instance number mst-priority number
Treemst-priority
Range0 | 4096 | 8192 | 12288 | 16384 | 20480 | 24576 | 28672 | 32768 | 36864 | 40960 | 45056 | 49152 | 53248 | 57344 | 61440
Default32768
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mst-maximum-hops number
Synopsis Maximum number of hops in an MSTP region
Contextconfigure service vpls service-name stp mst-maximum-hops number
Treemst-maximum-hops
Range1 to 40
Default20
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

mst-name named-item
Synopsis MST region name
Context configure service vpls service-name stp mst-name named-item
Treemst-name
String length1 to 32
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mst-revision number
Synopsis MST configuration revision
Context configure service vpls service-name stp mst-revision number
Treemst-revision
Range0 to 65535
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority number
Synopsis STP bridge priority
Context configure service vpls service-name stp priority number
Treepriority
Range0 to 65535
Default32768
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

temp-flooding number
Synopsis Temporary flooding
Context configure service vpls service-name temp-flooding number
Treetemp-flooding
Range3 to 600
Unitsseconds
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

vpn-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVPN identifier for the service
Contextconfigure service vpls service-name vpn-id number
Treevpn-id
Range1 to 2147483647
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vprn [service-name] service-name

Synopsis Enter the vprn list instance
Context configure service vprn service-name
Treevprn

Description

Commands in this context create or edit a VPRN service instance.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[service-name] service-name
Synopsis Administrative service name
Context configure service vprn service-name
Treevprn
String length1 to 64

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

aaa
Synopsis Enter the aaa context
Context configure service vprn service-name aaa
Treeaaa
Introduced25.3.R2

Platforms

7705 SAR Gen 2

remote-servers
Synopsis Enter the remote-servers context
Contextconfigure service vprn service-name aaa remote-servers
Treeremote-servers
Introduced25.3.R2

Platforms

7705 SAR Gen 2

radius
Synopsis Enable the radius context
Context configure service vprn service-name aaa remote-servers radius
Treeradius
Introduced25.3.R2

Platforms

7705 SAR Gen 2

port number
Synopsis UDP port number on which to contact RADIUS server
Contextconfigure service vprn service-name aaa remote-servers radius port number
Treeport
Range1 to 65535
Default1812
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

server [index] number
Synopsis Enter the server list instance
Contextconfigure service vprn service-name aaa remote-servers radius server number
Treeserver
Max. instances5
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[index] number
Synopsis RADIUS server ID
Context configure service vprn service-name aaa remote-servers radius server number
Treeserver
Range1 to 5

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the RADIUS server
Context configure service vprn service-name aaa remote-servers radius server number address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeaddress

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

authenticator keyword
Synopsis Authenticator hash algorithm for the RADIUS server
Contextconfigure service vprn service-name aaa remote-servers radius server number authenticator keyword
Treeauthenticator

Description

This command specifies the hash algorithm used to authenticate RADIUS Access-Request, Access-Accept, Access-Reject, Access-Challenge, Accounting-Request, and Accounting-Response packets.

Optionsmd5, sm3
Default md5
Introduced25.3.R2

Platforms

7705 SAR Gen 2

tacplus
Synopsis Enable the tacplus context
Context configure service vprn service-name aaa remote-servers tacplus
Treetacplus
Introduced25.3.R2

Platforms

7705 SAR Gen 2

authorization
Synopsis Enable the authorization context
Contextconfigure service vprn service-name aaa remote-servers tacplus authorization
Treeauthorization
Introduced25.3.R2

Platforms

7705 SAR Gen 2

request-format
Synopsis Enter the request-format context
Contextconfigure service vprn service-name aaa remote-servers tacplus authorization request-format
Treerequest-format

Description

Commands in this context configure access operations that are sent to the TACACS+ server during authorization.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

access-operation-cmd keyword
Synopsis Access operations sent in authorization requests
Contextconfigure service vprn service-name aaa remote-servers tacplus authorization request-format access-operation-cmd keyword
Treeaccess-operation-cmd

Description

This command sends an operation argument in authorization requests.

In model-driven interfaces, this command configures the system to send the operation in the cmd argument, and the path in the cmd-args argument, in TACACS+ authorization requests. This command does not apply to authorization requests in classic interfaces.

Optionsdelete
Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

use-priv-lvl boolean
Synopsis Allow privilege level mapping
Context configure service vprn service-name aaa remote-servers tacplus authorization use-priv-lvl boolean
Treeuse-priv-lvl

Description

When configured to true, this command automatically performs a single authorization request to the TACACS+ server for cmd* (all commands) immediately after login, and then uses the local profile associated (via the priv-lvl-map) with the priv-lvl returned by the TACACS+ server for all subsequent authorization (except enable-admin). After the initial authorization for cmd*, no further authorization requests are sent to the TACACS+ server (except enable-admin).

When configured to false, each command is sent to the TACACS+ server for authorization (this is true regardless of whether the tacplus use-default-template setting is enabled).

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ignore-unknown-mandatory-vsas boolean
Synopsis Ignore unknown mandatory VSAs and fail authentication
Contextconfigure service vprn service-name aaa remote-servers tacplus ignore-unknown-mandatory-vsas boolean
Treeignore-unknown-mandatory-vsas

Description

When configured to true, the system ignores unknown mandatory VSAs and authentication succeeds.

When configured to false, the system ignores unknown mandatory VSAs received in a reply from the TACACS+ server. Authentication fails and the user is disconnected because the system cannot process a mandatory VSA that is unknown.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priv-lvl-map
Synopsis Enter the priv-lvl-map context
Contextconfigure service vprn service-name aaa remote-servers tacplus priv-lvl-map
Treepriv-lvl-map
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priv-lvl [level] number
Synopsis Enter the priv-lvl list instance
Contextconfigure service vprn service-name aaa remote-servers tacplus priv-lvl-map priv-lvl number
Treepriv-lvl
Introduced25.3.R2

Platforms

7705 SAR Gen 2

server [index] number
Synopsis Enter the server list instance
Contextconfigure service vprn service-name aaa remote-servers tacplus server number
Treeserver
Max. instances5
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the TACACS+ server
Context configure service vprn service-name aaa remote-servers tacplus server number address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeaddress

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

port number
Synopsis TCP port ID on which to contact TACACS+ server
Contextconfigure service vprn service-name aaa remote-servers tacplus server number port number
Treeport
Range0 | 1 to 65535
Default49
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

secret encrypted-leaf
Synopsis Secret key to access the TACACS+ server
Contextconfigure service vprn service-name aaa remote-servers tacplus server number secret encrypted-leaf
Treesecret
String length1 to 199

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

server-retry-timeout (number | keyword)
Synopsis Time before retrying requests when health checks are disabled
Contextconfigure service vprn service-name aaa remote-servers tacplus server-retry-timeout (number | keyword)
Treeserver-retry-timeout

Description

This command configures the maximum timeout before retrying requests when health checks are disabled and all TACACS+ servers are operationally down. Set the value of this timer to a lower value or disable it to increase the interactive responsiveness of AAA requests after the servers become unreachable.

Range1 to 300
Unitsseconds
Options

none – Disable retry timeout and send requests immediately

Default300
Introduced25.3.R2

Platforms

7705 SAR Gen 2

service-request
Synopsis Enter the service-request context
Contextconfigure service vprn service-name aaa remote-servers tacplus service-request
Treeservice-request

Description

Commands in this context enable Nokia services to be requested from the TACACS+ server.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

nokia-user boolean
Synopsis Request nokia-user service VSAs
Context configure service vprn service-name aaa remote-servers tacplus service-request nokia-user boolean
Treenokia-user

Description

When configured to true, the nokia-user service is requested from the TACACS+ server after successful authentication.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the service
Context configure service vprn service-name admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

aggregates
Synopsis Enter the aggregates context
Context configure service vprn service-name aggregates
Treeaggregates
Introduced25.3.R2

Platforms

7705 SAR Gen 2

aggregate [ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis Enter the aggregate list instance
Contextconfigure service vprn service-name aggregates aggregate (ipv4-prefix | ipv6-prefix)
Treeaggregate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis Destination IP address prefix of the aggregate route
Contextconfigure service vprn service-name aggregates aggregate (ipv4-prefix | ipv6-prefix)
Treeaggregate

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

aggregator
Synopsis Enter the aggregator context
Context configure service vprn service-name aggregates aggregate (ipv4-prefix | ipv6-prefix) aggregator
Treeaggregator
Introduced25.3.R2

Platforms

7705 SAR Gen 2

as-set boolean
Synopsis Use AS_SET path segment type for the aggregate route
Contextconfigure service vprn service-name aggregates aggregate (ipv4-prefix | ipv6-prefix) as-set boolean
Treeas-set

Description

When configured to true, the AS_PATH attribute of the aggregate contains an AS_SET containing all AS numbers from the contributing routes. This can increase the amount of churn due to best-path changes.

When configured to false, the AS_PATH attribute contains no AS_SET and will be originated by the ESR.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

blackhole
Synopsis Enable the blackhole context
Context configure service vprn service-name aggregates aggregate (ipv4-prefix | ipv6-prefix) blackhole
Treeblackhole

Notes

The following elements are part of a choice: blackhole or indirect.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

generate-icmp boolean
Synopsis Send ICMP unreachable messages for aggregate routes
Contextconfigure service vprn service-name aggregates aggregate (ipv4-prefix | ipv6-prefix) blackhole generate-icmp boolean
Treegenerate-icmp

Description

When configured to true, ICMP unreachable messages are sent when packets match an aggregate route in the FIB with a black-hole next-hop.

When configured to false, ICMP unreachable messages are not generated.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

community community
Synopsis Community name that is added to the aggregate route
Contextconfigure service vprn service-name aggregates aggregate (ipv4-prefix | ipv6-prefix) community community
Treecommunity

Description

This command associates a BGP community with the aggregate route. The community name can be matched in route policies and is automatically added to BGP routes exported from the aggregate route.

String length1 to 72
Max. instances12

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

indirect (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisAddress of the indirect next hop
Contextconfigure service vprn service-name aggregates aggregate (ipv4-prefix | ipv6-prefix) indirect (ipv4-address-no-zone | ipv6-address-no-zone)
Treeindirect

Description

This command programs aggregate routes into the forwarding table with an indirect next hop. If a packet matches the aggregate route but not a contributing route, it is forwarded toward the indirect next hop rather than being discarded.

Notes

The following elements are part of a choice: blackhole or indirect.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

local-preference number
Synopsis Local preference used when aggregate route is exported
Contextconfigure service vprn service-name aggregates aggregate (ipv4-prefix | ipv6-prefix) local-preference number
Treelocal-preference

Description

This command configures the local preference value to use when the aggregate route is exported rather than using any of the local preference values assigned for any of the contributing routes.

Range0 to 4294967295
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy reference
Synopsis Policy name for the aggregated route
Context configure service vprn service-name aggregates aggregate (ipv4-prefix | ipv6-prefix) policy reference
Treepolicy

Description

This command associates an aggregate route with a policy reference. The aggregated route is activated only when there is at least one eligible active route in the sub-trees below it that is accepted by the policy evaluation. There is no evaluation into any sub-tree that starts with another active aggregate route. Eligible routes exclude host routes and LDP shortcut routes.

If an aggregate route has no policy, or the reference is to an empty policy, this configuration is treated as equivalent to a policy with one rule that accepts all routes.

Reference

configure policy-options policy-statement named-item-64

Introduced25.3.R2

Platforms

7705 SAR Gen 2

summary-only boolean
Synopsis Advertise the aggregate route only
Context configure service vprn service-name aggregates aggregate (ipv4-prefix | ipv6-prefix) summary-only boolean
Treesummary-only

Description

When configured to true, the router suppresses the advertisement of more specific component routes for the aggregate.

When configured to false, the router advertises both the aggregate route and its contributing routes.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

tunnel-group number
Synopsis Tunnel group from which to associate the MC IPSec state
Contextconfigure service vprn service-name aggregates aggregate (ipv4-prefix | ipv6-prefix) tunnel-group number
Treetunnel-group

Description

This command adds the MC-IPsec state of the specific tunnel-group to the aggregate route.

Range1 to 64
Introduced25.3.R2

Platforms

7705 SAR Gen 2

autonomous-system number
Synopsis AS number advertised to peers for this router
Contextconfigure service vprn service-name autonomous-system number
Treeautonomous-system

Description

This command configures the autonomous system (AS) number for the router. This value must be set before BGP can be activated.

If the AS number is changed on a router with an active BGP instance, the new AS number is not used until the BGP instance is restarted.

Range1 to 4294967295
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp
Synopsis Enable the bgp context
Context configure service vprn service-name bgp
Treebgp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the BGP instance
Contextconfigure service vprn service-name bgp admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

advertise-inactive boolean
Synopsis Advertise inactive BGP routes to peers
Contextconfigure service vprn service-name bgp advertise-inactive boolean
Treeadvertise-inactive

Description

When configured to true, this command allows any inactive BGP route to be advertised, even though it is not the used route.

When configured to false, the advertisement of inactive BGP routes to other BGP peers is disabled.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

aggregator-id-zero boolean
Synopsis Set router ID in the BGP AGGREGATOR attribute to 0
Contextconfigure service vprn service-name bgp aggregator-id-zero boolean
Treeaggregator-id-zero

Description

When configured to true, the router ID in the BGP AGGREGATOR path attribute is set to 0 when BGP aggregates routes. This prevents different routers within an AS from creating aggregate routes for the same prefix with different path attributes.

When configured to false, the AS number and router ID are added to the AGGREGATOR path attribute.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

asn-4-byte boolean
Synopsis Advertise support for 4-byte ASNs
Context configure service vprn service-name bgp asn-4-byte boolean
Treeasn-4-byte
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

attribute-set
Synopsis Enter the attribute-set context
Contextconfigure service vprn service-name bgp attribute-set
Treeattribute-set

Description

Commands in this context configure the handling of attribute set (ATTR_SET) attributes in BGP routes received from PE-CE peers of the VPRN.

ATTR_SET is an optional transitive BGP path attribute standardized by RFC 6368 that is added to BGP L3 VPN routes to provide logical separation between the BGP domain of a customer and the BGP domain of a service provider.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

remove boolean
Synopsis Remove ATTR_SET in received BGP routes from PE-CE peers
Contextconfigure service vprn service-name bgp attribute-set remove boolean
Treeremove

Description

When configured to true, BGP ignores and silently discards ATTR_SETs in BGP routes received from PE-CE peers of the VPRN. The discarded ATTR_SETs do not affect BGP best path selection in the VPRN, and they do not appear in the VPN-IP routes that result from the VRF export of the BGP routes. Nokia recommends configuring this command to true in most deployments.

When configured to false, BGP ignores ATTR_SETs in BGP routes received from PE-CE peers of the VPRN, but does not discard them. This allows the ATTR_SETs to propagate between CE devices connected to the VPRN and to other PE devices when the BGP routes are exported as VPN-IP routes.

Note: If the configuration of this command is changed, ROUTE_REFRESH messages are sent to all PE-CE peers of the VPRN.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

authentication-key encrypted-leaf
Synopsis BGP authentication key for all peers
Context configure service vprn service-name bgp authentication-key encrypted-leaf
Treeauthentication-key

Description

This command configures the authentication key used to protect all sessions. The stored format of the authentication key is based on the configure system security hash-control management-interface md-cli hash-algorithm setting.

String length1 to 370
Introduced25.3.R2

Platforms

7705 SAR Gen 2

authentication-keychain reference
Synopsis TCP authentication keychain for the session
Contextconfigure service vprn service-name bgp authentication-keychain reference
Treeauthentication-keychain

Description

This command associates the keychain to be used to authenticate the BGP session. The keychain allows the rollover of authentication keys during the lifetime of a session.

Reference

configure system security keychains keychain named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

backup-path
Synopsis Enter the backup-path context
Context configure service vprn service-name bgp backup-path
Treebackup-path

Description

Commands in this context enable the use of a backup path for specified BGP-learned prefixes belonging to the base router. Multiple paths must be received for a prefix in order to take advantage of this feature. When a prefix has a backup path and its primary paths fail, the affected traffic is rapidly diverted to the backup path without waiting for control plane re-convergence to occur. When many prefixes share the same primary paths and in some cases, the same backup path, the time to divert failover traffic to the backup path is independent of the number of prefixes.

By default, IPv4 and IPv6 prefixes do not have a backup path installed in the IOM.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4 boolean
Synopsis Enable support for unlabeled unicast IPv4 routes
Contextconfigure service vprn service-name bgp backup-path ipv4 boolean
Treeipv4
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6 boolean
Synopsis Enable support for unlabeled unicast IPv6 routes
Contextconfigure service vprn service-name bgp backup-path ipv6 boolean
Treeipv6
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

best-path-selection
Synopsis Enter the best-path-selection context
Contextconfigure service vprn service-name bgp best-path-selection
Treebest-path-selection
Introduced25.3.R2

Platforms

7705 SAR Gen 2

always-compare-med
Synopsis Enter the always-compare-med context
Contextconfigure service vprn service-name bgp best-path-selection always-compare-med
Treealways-compare-med

Description

Commands in this context determine how the BGP decision process is affected by the MED path attribute.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

strict-as boolean
Synopsis Compare MED only for routes from same neighbor AS
Contextconfigure service vprn service-name bgp best-path-selection always-compare-med strict-as boolean
Treestrict-as

Description

When configured to true, the route selection process can compare the MED path attribute between routes only if they come from the same neighbor AS.

When configured to false, the route selection process can compare the MED path attribute between routes even if they come from different neighbor ASs.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

as-path-ignore
Synopsis Enter the as-path-ignore context
Contextconfigure service vprn service-name bgp best-path-selection as-path-ignore
Treeas-path-ignore

Description

Commands in this context determine whether the AS path length is considered in the selection process for routes of the specified address families.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

compare-origin-validation-state boolean
Synopsis Allow comparison of origin validation states
Contextconfigure service vprn service-name bgp best-path-selection compare-origin-validation-state boolean
Treecompare-origin-validation-state

Description

When configured to true, the RPKI origin validation state is compared between BGP routes, where a Valid state is preferred over a Not-Found state, and a Not-Found state is preferred over an Invalid state.

When configured to false, the RPKI origin validate state comparison is not performed as part of the BGP route selection process.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

deterministic-med boolean
Synopsis Group paths based on AS before MED attribute comparison
Contextconfigure service vprn service-name bgp best-path-selection deterministic-med boolean
Treedeterministic-med

Description

When configured to true, BGP groups paths from the same AS that are equal up to the MED attribute comparison and then compares the best path from each group to select the overall best path. This process ensures that the best-path selection process is deterministic in all cases.

When configured to false, paths are not grouped and the overall best-path selection can depend on the order of route arrival.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ebgp-ibgp-equal
Synopsis Enter the ebgp-ibgp-equal context
Contextconfigure service vprn service-name bgp best-path-selection ebgp-ibgp-equal
Treeebgp-ibgp-equal

Description

Commands in this context allow BGP to ignore the difference between EBGP and IBGP routes in selecting the best path and eligible multipaths (if multipath and ECMP are enabled) for the specified address families. The result is a form of EIBGP load-balancing in a multipath scenario. This behavior can be applied selectively to certain address families.

By default, the BGP decision process prefers an EBGP learned route over an IBGP learned route.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ignore-nh-metric boolean
Synopsis Ignore next-hop distance in best path selection
Contextconfigure service vprn service-name bgp best-path-selection ignore-nh-metric boolean
Treeignore-nh-metric

Description

When configured to true, BGP ignores the resolved distance to the BGP next hop in its route selection process.

When configured to false, BGP factors the distance to the next hop into its decision process when it compares two BGP routes with the same NLRI learned from base router BGP peers (in the router context) or IP prefix learned from VPRN BGP peers (in the vprn context).

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ignore-router-id
Synopsis Enable the ignore-router-id context
Contextconfigure service vprn service-name bgp best-path-selection ignore-router-id
Treeignore-router-id

Description

Commands in this context determine whether the BGP selection process ignores the BGP identifier (router ID) comparison of two EBGP paths from different EBGP peers when determining the best path for the specified address families.

By default, BGP selects the path with the lower router ID when it compares two paths from EBGP peers.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

origin-invalid-unusable boolean
Synopsis Ignore routes with invalid origin validation state
Contextconfigure service vprn service-name bgp best-path-selection origin-invalid-unusable boolean
Treeorigin-invalid-unusable

Description

When configured to true, routes that have an RPKI origin validation state of Invalid are considered unusable by the best-path selection algorithm. These routes cannot be used for forwarding and cannot be advertised to BGP peers.

When configured to false, routes with an RPKI origin validation state of Invalid are compared to other usable routes for the same prefix, according to the BGP decision process.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd-liveness boolean
Synopsis Enable BFD
Contextconfigure service vprn service-name bgp bfd-liveness boolean
Treebfd-liveness

Description

When configured to true, BFD is enabled on all BGP sessions, subject to the association of those BGP sessions with IP interfaces that have BFD configurations.

When configured to false, BFD is not enabled globally for all BGP sessions.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd-strict-mode
Synopsis Enter the bfd-strict-mode context
Contextconfigure service vprn service-name bgp bfd-strict-mode
Treebfd-strict-mode
Introduced25.3.R2

Platforms

7705 SAR Gen 2

advertise
Synopsis Enable the advertise context
Context configure service vprn service-name bgp bfd-strict-mode advertise
Treeadvertise

Description

Commands in this context configure BGP to advertise the Strict-BFD capability to peers that are within scope of this command and meet the following requirements:

  • The inherited or configured value for the bfd-liveness command that applies to the peer is true.

  • The interface associated with the peer has a valid BFD configuration.

When the preceding conditions are satisfied and two peers attempting to form a session both advertise the Strict-BFD capability, the BGP finite state machine in each router transitions the session state to established after the BFD session with the peer enters the up state.

When unconfigured, BGP does not advertise the Strict-BFD capability to peers.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

holdtime number
Synopsis Maximum time BGP waits for the BFD session to come up
Contextconfigure service vprn service-name bgp bfd-strict-mode advertise holdtime number
Treeholdtime

Description

This command configures the maximum time BGP waits for the BFD session to come up, provided that the Strict-BFD procedures apply to a session, and the negotiated BGP hold time is zero (no keepalives). If the negotiated BGP hold time is greater than zero, the advertised hold time is not considered.

Range1 to 65535
Unitsseconds
Default 30
Introduced25.3.R2

Platforms

7705 SAR Gen 2

next-hop-reachability boolean
Synopsis Consider next hop unreachable if BFD session is down
Contextconfigure service vprn service-name bgp bfd-strict-mode next-hop-reachability boolean
Treenext-hop-reachability

Description

When configured to true, the router considers next-hop self routes belonging to specific address families received from a peer within scope of this command as having an unresolved next hop, provided that the following requirements are met:

  • The BFD session to the peer is in a down state.

  • There is a valid interface BFD configuration that applies to the peer.

  • There is a valid BFD liveness configuration that applies to the peer.

The unresolved state is maintained until the BFD session state changes to up or administratively down, even if there is a resolving route or tunnel that matches the BGP next-hop address.

Routes received from one peer with a BGP next-hop address equal to the address of another peer are not affected by the BFD session to the other peer.

The behavior of the router when this command is true does not depend on whether Strict-BFD is used, as both features are independent.

Configuring this command to true only affects routes belonging to the following address families:

  • IPv4

  • IPv6

  • IPv4 VPN

  • IPv6 VPN

  • labeled unicast IPv4

  • labeled unicast IPv6

  • EVPN

  • IPv4 multicast

  • IPv6 multicast

  • IPv4 VPN multicast

  • IPv6 VPN multicast

When configured to false, the router does not consider next-hop self routes belonging to the preceding address families as having an unresolved next hop if the BFD session goes down.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

client-reflect boolean
Synopsis Allow client reflection of routes by route reflector
Contextconfigure service vprn service-name bgp client-reflect boolean
Treeclient-reflect

Description

When configured to true, routes received from neighbors considered to be RR clients are reflected to other peers as expected.

When configured to false, routes received from neighbors considered to be RR clients are not reflected to other clients.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

cluster
Synopsis Enter the cluster context
Context configure service vprn service-name bgp cluster
Treecluster
Introduced25.3.R2

Platforms

7705 SAR Gen 2

cluster-id ipv4-address
Synopsis Route reflector cluster ID
Context configure service vprn service-name bgp cluster cluster-id ipv4-address
Treecluster-id

Description

The command specifies the cluster ID to associate with the routing instance, effectively making all IBGP peers of the routing instance RR clients.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

connect-retry number
Synopsis BGP connect retry timer value
Context configure service vprn service-name bgp connect-retry number
Treeconnect-retry

Description

This command configures the BGP connect retry timer. When the timer expires, BGP tries to reconnect to the configured peer.

Range1 to 65535
Default120
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

convergence
Synopsis Enter the convergence context
Context configure service vprn service-name bgp convergence
Treeconvergence
Introduced25.3.R2

Platforms

7705 SAR Gen 2

family [family-type] keyword
Synopsis Enter the family list instance
Contextconfigure service vprn service-name bgp convergence family keyword
Treefamily
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[family-type] keyword
Synopsis Address family for which convergence selection applies
Contextconfigure service vprn service-name bgp convergence family keyword
Treefamily
Optionsipv4, ipv6

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

damp-peer-oscillations
Synopsis Enable the damp-peer-oscillations context
Contextconfigure service vprn service-name bgp damp-peer-oscillations
Treedamp-peer-oscillations

Description

Commands in this context support the DampPeerOscillations FSM behavior described in section 8.1 of RFC 4271, A Border Gateway Protocol 4 (BGP-4).

When unconfigured, the router does not perform peer oscillation damping and immediately transitions out of the idle state after every reset.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

error-interval number
Synopsis Time after a reset that the session must be error-free
Contextconfigure service vprn service-name bgp damp-peer-oscillations error-interval number
Treeerror-interval

Description

This command sets the interval of time after a reset, during which the session must be error-free in order to reset the penalty counter and return the idle hold time to the initial wait time.

Range0 to 2048
Default30
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

idle-hold-time
Synopsis Enter the idle-hold-time context
Contextconfigure service vprn service-name bgp damp-peer-oscillations idle-hold-time
Treeidle-hold-time

Description

Commands in this context configure how long a BGP peer session remains in the idle state after some type of error causes the session to reset.

In the idle state, BGP does not initiate or respond to attempts to establish a new session. Repeated errors that occur in a short time period after each session reset cause longer and longer hold times in the idle state.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

second-wait number
Synopsis Time that doubles after each session failure
Contextconfigure service vprn service-name bgp damp-peer-oscillations idle-hold-time second-wait number
Treesecond-wait

Description

This command defines the hold time that doubles after each repeated session failure that occurs in a short span of time.

Range1 to 2048
Default5
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

damping boolean
Synopsis Use BGP route damping to reduce route flap
Contextconfigure service vprn service-name bgp damping boolean
Treedamping

Description

When configured to true, this command enables route damping to reduce the number of update messages sent between BGP peers and reduce the load on peers without affecting the route convergence time for stable routes.

Route damping is controlled by profiles set in route policies. If no profile is specified in the route policy, the default damping profile is used with the following parameters:

  • Half-life: 15 minutes

  • Max-suppress: 60 minutes

  • Suppress-threshold: 3000

  • Reuse-threshold: 750

When configured to false, BGP route damping for learned routes is disabled.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

default-label-preference
Synopsis Enter the default-label-preference context
Contextconfigure service vprn service-name bgp default-label-preference
Treedefault-label-preference
Introduced25.3.R2

Platforms

7705 SAR Gen 2

default-preference
Synopsis Enter the default-preference context
Contextconfigure service vprn service-name bgp default-preference
Treedefault-preference
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ebgp number
Synopsis Default preference for EBGP
Context configure service vprn service-name bgp default-preference ebgp number
Treeebgp
Range0 to 255
Default0
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

ibgp number
Synopsis Default preference for IBGP
Context configure service vprn service-name bgp default-preference ibgp number
Treeibgp
Range0 to 255
Default0
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service vprn service-name bgp description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dynamic-neighbor-limit number
Synopsis Max dynamic BGP sessions to accept from remote peers
Contextconfigure service vprn service-name bgp dynamic-neighbor-limit number
Treedynamic-neighbor-limit

Description

This command configures the maximum number of dynamic BGP sessions to accept from remote peers associated with the entire BGP instance. If accepting a new dynamic session causes the instance limit to be exceeded, the new session attempt is rejected and a Notification message is sent back to the remote peer.

Range1 to 8192
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ebgp-default-reject-policy
Synopsis Enter the ebgp-default-reject-policy context
Contextconfigure service vprn service-name bgp ebgp-default-reject-policy
Treeebgp-default-reject-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

enforce-first-as boolean
Synopsis Enforce the configured peer AS value in received routes
Contextconfigure service vprn service-name bgp enforce-first-as boolean
Treeenforce-first-as

Description

When configured to true for an EBGP session, all routes received from an EBGP peer are checked to ensure that the most recent ASN in the AS_PATH attribute of each route matches the configured AS of the session. If there is not a match, the session is reset (if the update-fault-tolerance command in the error-handling context is set to false) or the session is left up but the route is treated as withdrawn (if update-fault-tolerance is set to true).

This command does not flap an established session because it applies only to routes received after the command is issued.

When configured to false, received routes are not checked for compliance with the rule.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

error-handling
Synopsis Enter the error-handling context
Contextconfigure service vprn service-name bgp error-handling
Treeerror-handling
Introduced25.3.R2

Platforms

7705 SAR Gen 2

legacy-mode boolean
Synopsis Enable legacy-mode of BGP error handling
Contextconfigure service vprn service-name bgp error-handling legacy-mode boolean
Treelegacy-mode

Description

When configured to true, the BGP instance handles the BGP update error messages based on the configured update-fault-tolerance commands. If these commands are not explicitly configured, BGP error handling follows the legacy procedures described in RFC 4271, which can result in disruptive session resets.

When configured to false, the BGP instance ignores the configured update-fault-tolerance commands and applies the new error handling procedures described in RFC 7606 on all sessions.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

update-fault-tolerance boolean
Synopsis Tolerate non-critical errors in UPDATE messages
Contextconfigure service vprn service-name bgp error-handling update-fault-tolerance boolean
Treeupdate-fault-tolerance

Description

When configured to true, non-critical errors are handled with treat-as-withdraw, attribute-discard, and other non-disruptive approaches that do not cause a session reset. Critical errors still trigger a session reset.

When configured to false, most errors trigger a session reset.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

export
Synopsis Enable the export context
Context configure service vprn service-name bgp export
Treeexport
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy (policy-expr-string | string)
Synopsis Export policy name
Context configure service vprn service-name bgp export policy (policy-expr-string | string)
Treepolicy
String length1 to 255
Max. instances15
Min. instances1

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

family
Synopsis Enter the family context
Context configure service vprn service-name bgp family
Treefamily

Description

Commands in this context specify the BGP address families supported by the base router BGP sessions.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

flow-ipv6 boolean
Synopsis Advertise support for the FlowSpec-IPv6 address family
Contextconfigure service vprn service-name bgp family flow-ipv6 boolean
Treeflow-ipv6
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4 boolean
Synopsis Advertise MP-BGP support for the IPv4 address family
Contextconfigure service vprn service-name bgp family ipv4 boolean
Treeipv4
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6 boolean
Synopsis Advertise MP-BGP support for the IPv6 address family
Contextconfigure service vprn service-name bgp family ipv6 boolean
Treeipv6
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

label-ipv4 boolean
Synopsis Advertise support for the label-IPv4 address family
Contextconfigure service vprn service-name bgp family label-ipv4 boolean
Treelabel-ipv4
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mcast-ipv4 boolean
Synopsis Advertise support for the MCAST-IPv4 address family
Contextconfigure service vprn service-name bgp family mcast-ipv4 boolean
Treemcast-ipv4
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mcast-ipv6 boolean
Synopsis Advertise support for the MCAST-IPv6 address family
Contextconfigure service vprn service-name bgp family mcast-ipv6 boolean
Treemcast-ipv6
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

fast-external-failover boolean
Synopsis Drop external BGP session immediately when link fails
Contextconfigure service vprn service-name bgp fast-external-failover boolean
Treefast-external-failover

Description

When configured to true, the router drops an external BGP session to a single-hop neighbor immediately when the local interface goes down.

When configured to false, the BGP session remains up until the hold time expires.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

graceful-restart
Synopsis Enable the graceful-restart context
Contextconfigure service vprn service-name bgp graceful-restart
Treegraceful-restart
Introduced25.3.R2

Platforms

7705 SAR Gen 2

gr-notification boolean
Synopsis Perform Graceful Restart procedures
Context configure service vprn service-name bgp graceful-restart gr-notification boolean
Treegr-notification

Description

When configured to true, the Graceful Restart capability sent by the router indicates support for NOTIFICATION messages. If the peer also supports this capability, the session is restarted gracefully (while preserving forwarding) if either peer sends a NOTIFICATION message due to some type of event or error.

When configured to false, NOTIFICATION messages are not supported.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

long-lived
Synopsis Enable the long-lived context
Context configure service vprn service-name bgp graceful-restart long-lived
Treelong-lived
Introduced25.3.R2

Platforms

7705 SAR Gen 2

family [family-type] keyword
Synopsis Enter the family list instance
Contextconfigure service vprn service-name bgp graceful-restart long-lived family keyword
Treefamily
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[family-type] keyword
Synopsis Address family type for LLGR
Context configure service vprn service-name bgp graceful-restart long-lived family keyword
Treefamily
Optionsipv4, ipv6, flow-ipv4, flow-ipv6, label-ipv4

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

forwarding-bits-set keyword
Synopsis BGP LLGR forwarding-bit behavior for address family
Contextconfigure service vprn service-name bgp graceful-restart long-lived forwarding-bits-set keyword
Treeforwarding-bits-set

Description

This command determines the setting of the F bit in the GR and LLGR capabilities advertised by the router. When the F bit is set for an address family, it indicates that the advertising router is able to preserve forwarding state for the routes of that address family across the last restart. When the session is re-established after a restart and the F bit is not set, all stale routes from the peer are immediately removed for the corresponding address family.

This command allows the F bit to be set for all address families or only for non-forwarding address families (L2-VPN, route target, flow-IPv4, and flow-IPv6).

Optionsnone, all, non-fwd
Defaultnone
Introduced25.3.R2

Platforms

7705 SAR Gen 2

helper-override-restart-time number
Synopsis Locally-configured override for restart time
Contextconfigure service vprn service-name bgp graceful-restart long-lived helper-override-restart-time number
Treehelper-override-restart-time

Description

This command overrides the restart time advertised by a peer (in its GR capability) with a locally-configured value. This override applies only to AFI/SAFI that were included in the GR capability of the peer. The restart-time is always zero for AFI/SAFI not included in the GR capability. This command is useful if the local router wants to force the LLGR phase to begin after a set time for all protected AFI/SAFI.

Range0 to 4095
Introduced25.3.R2

Platforms

7705 SAR Gen 2

helper-override-stale-time number
Synopsis Locally-configured stale routes override time
Contextconfigure service vprn service-name bgp graceful-restart long-lived helper-override-stale-time number
Treehelper-override-stale-time

Description

This command configures a locally-imposed LLGR stale time that overrides the long-lived stale routes time that is advertised by the router in its LLGR capability.

This command applies to all AFI/SAFI in the advertised LLGR capability except for any AFI/SAFI with a family-specific override.

Range0 to 16777215
Introduced25.3.R2

Platforms

7705 SAR Gen 2

without-no-export boolean
Synopsis Advertise LLGR stale routes to non-LLGR peers
Contextconfigure service vprn service-name bgp graceful-restart long-lived without-no-export boolean
Treewithout-no-export

Description

When configured to true, LLGR stale routes can be advertised to any peer (EBGP or IBGP) that did not signal the LLGR capability. For IBGP and confederation-EBGP peers that did not advertise the LLGR capability, the local preference attribute in the advertised stale routes is automatically set to 0.

When configured to false, LLGR stale routes are not advertised to any EBGP peer that did not signal the LLGR capability. For IBGP and confederation-EBGP peers that did not advertise the LLGR capability, the local preference attribute in the advertised stale routes is automatically set to 0 and a NO_EXPORT standard community is automatically added to the routes.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

group [group-name] named-item-64
Synopsis Enter the group list instance
Context configure service vprn service-name bgp group named-item-64
Treegroup
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[group-name] named-item-64
Synopsis BGP peer group name
Context configure service vprn service-name bgp group named-item-64
Treegroup
String length1 to 64

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the BGP group
Contextconfigure service vprn service-name bgp group named-item-64 admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

advertise-inactive boolean
Synopsis Advertise an inactive BGP route to peers
Contextconfigure service vprn service-name bgp group named-item-64 advertise-inactive boolean
Treeadvertise-inactive

Description

When configured to true, this command allows an inactive BGP route to be advertised, even though it is not the most preferred route. The effect of the command on advertised unlabeled, labeled, and multicapt IPv4 and IPv6 routes depends on several factors.

  • If the active route for the IP prefix is a BGP route, that route is advertised.

  • If the active route is a non-BGP route and there are valid inactive BGP routes to the same destination, the best valid inactive route is advertise unless the active non-BGP route is matched and accepted by an export policy applied to the session

  • If the active route is a non-BGP route and there are no valid BGP routes to the same destination, no route is advertised unless the active non-BGP route is matched and accepted by an export policy applied to the session.

When unconfigured, the command inherits the value of the global-level setting (true or false). The command cannot be explicity configured to false.

When this command inherits a value of false, the advertisement of inactive BGP routes to other BGP peers is disabled.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

as-override boolean
Synopsis Replace the peer's ASN with the local ASN in AS Path
Contextconfigure service vprn service-name bgp group named-item-64 as-override boolean
Treeas-override

Description

When configured to true, the advertising router's local AS replaces all occurrences of the peer AS in the AS_PATH attribute.

This command should be used with caution, as it breaks BGP's loop detection mechanism.

When configured to false, no AS override is performed.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

asn-4-byte boolean
Synopsis Advertise the use of 4-byte ASNs
Context configure service vprn service-name bgp group named-item-64 asn-4-byte boolean
Treeasn-4-byte

Description

When this command inherits a value of true, the use of 4-byte ASNs is supported.

When unconfigured, the command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to true.

When configured to false, this command disables the use of 4-byte ASNs.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

authentication-key encrypted-leaf
Synopsis BGP authentication key for peers in the group
Contextconfigure service vprn service-name bgp group named-item-64 authentication-key encrypted-leaf
Treeauthentication-key

Description

This command configures the authentication key that must be configured on both peers. The stored format of the authentication key is based on the configure system security hash-control management-interface md-cli hash-algorithm setting.

String length1 to 370
Introduced25.3.R2

Platforms

7705 SAR Gen 2

authentication-keychain reference
Synopsis TCP authentication keychain for the session
Contextconfigure service vprn service-name bgp group named-item-64 authentication-keychain reference
Treeauthentication-keychain

Description

This command associates the keychain to be used to authenticate the BGP session. The keychain allows the rollover of authentication keys during the lifetime of a session.

Reference

configure system security keychains keychain named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd-strict-mode
Synopsis Enter the bfd-strict-mode context
Contextconfigure service vprn service-name bgp group named-item-64 bfd-strict-mode
Treebfd-strict-mode
Introduced25.3.R2

Platforms

7705 SAR Gen 2

advertise
Synopsis Enable the advertise context
Context configure service vprn service-name bgp group named-item-64 bfd-strict-mode advertise
Treeadvertise

Description

Commands in this context configure BGP to advertise the Strict-BFD capability to peers that are within scope of this command and meet the following requirements:

  • The inherited or configured value for the bfd-liveness command that applies to the peer is true.

  • The interface associated with the peer has a valid BFD configuration.

When the preceding conditions are satisfied and two peers attempting to form a session both advertise the Strict-BFD capability, the BGP finite state machine in each router transitions the session state to established after the BFD session with the peer enters the up state.

When unconfigured, BGP does not advertise the Strict-BFD capability to peers.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

holdtime number
Synopsis Maximum time BGP waits for the BFD session to come up
Contextconfigure service vprn service-name bgp group named-item-64 bfd-strict-mode advertise holdtime number
Treeholdtime

Description

This command configures the maximum time BGP waits for the BFD session to come up, provided that the Strict-BFD procedures apply to a session, and the negotiated BGP hold time is zero (no keepalives). If the negotiated BGP hold time is greater than zero, the advertised hold time is not considered.

Range1 to 65535
Unitsseconds
Default 30
Introduced25.3.R2

Platforms

7705 SAR Gen 2

next-hop-reachability boolean
Synopsis Consider next hop unreachable if BFD session is down
Contextconfigure service vprn service-name bgp group named-item-64 bfd-strict-mode next-hop-reachability boolean
Treenext-hop-reachability

Description

When configured to true, the router considers next-hop self routes belonging to specific address families received from a peer within scope of this command as having an unresolved next hop, provided that the following requirements are met:

  • The BFD session to the peer is in a down state.

  • There is a valid interface BFD configuration that applies to the peer.

  • There is a valid BFD liveness configuration that applies to the peer.

The unresolved state is maintained until the BFD session state changes to up or administratively down, even if there is a resolving route or tunnel that matches the BGP next-hop address.

Routes received from one peer with a BGP next-hop address equal to the address of another peer are not affected by the BFD session to the other peer.

The behavior of the router when this command is true does not depend on whether Strict-BFD is used, as both features are independent.

Configuring this command to true only affects routes belonging to the following address families:

  • IPv4

  • IPv6

  • IPv4 VPN

  • IPv6 VPN

  • labeled unicast IPv4

  • labeled unicast IPv6

  • EVPN

  • IPv4 multicast

  • IPv6 multicast

  • IPv4 VPN multicast

  • IPv6 VPN multicast

When configured to false, the router does not consider next-hop self routes belonging to the preceding address families as having an unresolved next hop if the BFD session goes down.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

capability-negotiation boolean
Synopsis Enable capability negotiation
Context configure service vprn service-name bgp group named-item-64 capability-negotiation boolean
Treecapability-negotiation

Description

When configured to true, this command enables the exchange of capabilities.

When configured to false and the peering is flapped, new capabilities are not negotiated and strictly IPv4 exchanges are supported with the peer.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

client-reflect boolean
Synopsis Allow cluster RR to advertise routes to its clients
Contextconfigure service vprn service-name bgp group named-item-64 client-reflect boolean
Treeclient-reflect

Description

When unconfigured, this command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to true.

When the command inherits a value of true, client reflection of routes is enabled.

When configured to false, this command disables client reflection of routes.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

damp-peer-oscillations
Synopsis Enable the damp-peer-oscillations context
Contextconfigure service vprn service-name bgp group named-item-64 damp-peer-oscillations
Treedamp-peer-oscillations

Description

Commands in this context specify how long a BGP peer session remains in the idle state after an error causes the session to reset. In the idle state, BGP does not initiate or respond to attempts to establish a new session. Repeated errors that occur a short time after each session reset cause longer and longer hold times in the idle state.

When unconfigured, command settings are inherited from the global-level configuration.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

error-interval number
Synopsis Time after a reset that the session must be error-free
Contextconfigure service vprn service-name bgp group named-item-64 damp-peer-oscillations error-interval number
Treeerror-interval

Description

This command sets the interval of time after a reset, during which the session must be error-free in order to reset the penalty counter and return the idle hold time to the initial wait time.

Range0 to 2048
Default30
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

idle-hold-time
Synopsis Enter the idle-hold-time context
Contextconfigure service vprn service-name bgp group named-item-64 damp-peer-oscillations idle-hold-time
Treeidle-hold-time
Introduced25.3.R2

Platforms

7705 SAR Gen 2

second-wait number
Synopsis Time that doubles after each repeated session failure
Contextconfigure service vprn service-name bgp group named-item-64 damp-peer-oscillations idle-hold-time second-wait number
Treesecond-wait

Description

This command defines the hold time that doubles after each repeated session failure that occurs in a short span of time.

Range1 to 2048
Default5
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

damping boolean
Synopsis Use BGP route damping to reduce route flap
Contextconfigure service vprn service-name bgp group named-item-64 damping boolean
Treedamping
Introduced25.3.R2

Platforms

7705 SAR Gen 2

default-label-preference
Synopsis Enter the default-label-preference context
Contextconfigure service vprn service-name bgp group named-item-64 default-label-preference
Treedefault-label-preference
Introduced25.3.R2

Platforms

7705 SAR Gen 2

default-preference
Synopsis Enter the default-preference context
Contextconfigure service vprn service-name bgp group named-item-64 default-preference
Treedefault-preference
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service vprn service-name bgp group named-item-64 description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dynamic-neighbor
Synopsis Enter the dynamic-neighbor context
Contextconfigure service vprn service-name bgp group named-item-64 dynamic-neighbor
Treedynamic-neighbor

Description

Commands in this context configure dynamic BGP sessions for a peer group.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface [interface-name] reference
Synopsis Enter the interface list instance
Contextconfigure service vprn service-name bgp group named-item-64 dynamic-neighbor interface reference
Treeinterface

Description

Commands in this context configure an unnumbered VPRN access IP interface for dynamic neighbors.

If this interface connects to a network with other BGP routers, sessions with the other routers can be set up automatically without explicitly configuring them as BGP neighbors. The interface must be IPv6 enabled, but because the interface is considered unnumbered, it does not require an IPv4 address or a global-unicast IPv6 address. The sessions are set up using IPv6 link-local addresses.

The BGP unnumbered feature supports all address families that allow IPv6 link-local BGP next-hop addresses. This includes IPv4 with the use of RFC 8950 extensions.

When an interface is added to the list of dynamic-neighbor interfaces, an outgoing connection attempt is initiated toward any directly connected router on the interface that announces itself using an ICMPv6 router advertisement message. The session attempt is unsuccessful if the peer type is not EBGP, the reported AS number of the peer does not match one of the allowed values, or the maximum session limit of the interface would be exceeded.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

allowed-peer-as string
Synopsis Allowed peer AS value or range of acceptable values
Contextconfigure service vprn service-name bgp group named-item-64 dynamic-neighbor interface reference allowed-peer-as string
Treeallowed-peer-as

Description

This command specifies a singular allowed peer AS value or a range of acceptable values in the format n1..n2.

All values greater than or equal to n1 and less than or equal to n2 are acceptable. For example, if the acceptable peer AS numbers are 65001 to 65005 (range) and 62100 (singular value), configure this command to use a value of [65001..65005 62100].

Max. instances32

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

max-sessions number
Synopsis Maximum number of dynamic sessions allowed
Contextconfigure service vprn service-name bgp group named-item-64 dynamic-neighbor interface reference max-sessions number
Treemax-sessions

Description

This command specifies the maximum number of dynamic sessions that are allowed to be set up on the interface as a result of accepting sessions from link-local addresses or initiating sessions by receiving IPv6 router advertisements.

Range1 to 255
Default1
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

match
Synopsis Enter the match context
Context configure service vprn service-name bgp group named-item-64 dynamic-neighbor match
Treematch
Introduced25.3.R2

Platforms

7705 SAR Gen 2

prefix [ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis Enter the prefix list instance
Contextconfigure service vprn service-name bgp group named-item-64 dynamic-neighbor match prefix (ipv4-prefix | ipv6-prefix)
Treeprefix
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis Dynamic peer prefix for the group
Context configure service vprn service-name bgp group named-item-64 dynamic-neighbor match prefix (ipv4-prefix | ipv6-prefix)
Treeprefix

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

allowed-peer-as string
Synopsis Allowed peer AS value or range of acceptable values
Contextconfigure service vprn service-name bgp group named-item-64 dynamic-neighbor match prefix (ipv4-prefix | ipv6-prefix) allowed-peer-as string
Treeallowed-peer-as

Description

This command specifies a singular allowed peer AS value or a range of acceptable values in the format n1..n2.

All values greater than or equal to n1 and less than or equal to n2 are acceptable. For example, if the acceptable peer AS numbers are 65001 to 65005 (range) and 62100 (singular value), configure this command to use a value of [65001..65005 62100].

Max. instances32

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

dynamic-neighbor-limit number
Synopsis Maximum dynamic BGP sessions to accept from remote peer
Contextconfigure service vprn service-name bgp group named-item-64 dynamic-neighbor-limit number
Treedynamic-neighbor-limit

Description

This command configures the maximum number of dynamic BGP sessions that are accepted from remote peers associated with a specific peer group. If accepting a new dynamic session causes the group limit to be exceeded, the new session attempt is rejected and a Notification message is sent back to the remote peer.

When unconfigured, the setting is inherited from the BGP global-level configuration.

Range1 to 8192
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ebgp-default-reject-policy
Synopsis Enable the ebgp-default-reject-policy context
Contextconfigure service vprn service-name bgp group named-item-64 ebgp-default-reject-policy
Treeebgp-default-reject-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

error-handling
Synopsis Enter the error-handling context
Contextconfigure service vprn service-name bgp group named-item-64 error-handling
Treeerror-handling
Introduced25.3.R2

Platforms

7705 SAR Gen 2

update-fault-tolerance boolean
Synopsis Tolerate non-critical errors in UPDATE messages
Contextconfigure service vprn service-name bgp group named-item-64 error-handling update-fault-tolerance boolean
Treeupdate-fault-tolerance

Description

When configured to true, non-critical errors are handled with treat-as-withdraw, attribute-discard, and other non-disruptive approaches that do not cause a session reset. Critical errors still trigger a session reset.

When unconfigured, the command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, all errors trigger a session reset.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

evpn-link-bandwidth
Synopsis Enter the evpn-link-bandwidth context
Contextconfigure service vprn service-name bgp group named-item-64 evpn-link-bandwidth
Treeevpn-link-bandwidth
Introduced25.3.R2

Platforms

7705 SAR Gen 2

add-to-received-bgp number
Synopsis Weight added to received PE-CE BGP routes
Contextconfigure service vprn service-name bgp group named-item-64 evpn-link-bandwidth add-to-received-bgp number
Treeadd-to-received-bgp

Description

This command configures the weight value added to all BGP PE-CE routes for the purpose of weighted ECMP if EVPN-IFL and BGP PE-CE routes are combined into the same ECMP set.

For the load-balancing betweeen EVPN-IFL and BGP PE-CE routes the configure service vprn bgp eibgp-loadbalance command must already be configured in the system.

Range1 to 128
Introduced25.3.R2

Platforms

7705 SAR Gen 2

export
Synopsis Enable the export context
Context configure service vprn service-name bgp group named-item-64 export
Treeexport
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy (policy-expr-string | string)
Synopsis Export policy name
Context configure service vprn service-name bgp group named-item-64 export policy (policy-expr-string | string)
Treepolicy
String length1 to 255
Max. instances15
Min. instances1

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

family
Synopsis Enable the family context
Context configure service vprn service-name bgp group named-item-64 family
Treefamily
Introduced25.3.R2

Platforms

7705 SAR Gen 2

flow-ipv6 boolean
Synopsis Advertise support for the FlowSpec-IPv6 address family
Contextconfigure service vprn service-name bgp group named-item-64 family flow-ipv6 boolean
Treeflow-ipv6
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4 boolean
Synopsis Add support for the IPv4 address family
Contextconfigure service vprn service-name bgp group named-item-64 family ipv4 boolean
Treeipv4
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6 boolean
Synopsis Advertise MP-BGP support for the IPv6 address family
Contextconfigure service vprn service-name bgp group named-item-64 family ipv6 boolean
Treeipv6
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

label-ipv4 boolean
Synopsis Advertise support for the label-IPv4 address family
Contextconfigure service vprn service-name bgp group named-item-64 family label-ipv4 boolean
Treelabel-ipv4
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mcast-ipv4 boolean
Synopsis Advertise support for the MCAST-IPv4 address family
Contextconfigure service vprn service-name bgp group named-item-64 family mcast-ipv4 boolean
Treemcast-ipv4
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mcast-ipv6 boolean
Synopsis Advertise support for the MCAST-IPv6 address family
Contextconfigure service vprn service-name bgp group named-item-64 family mcast-ipv6 boolean
Treemcast-ipv6
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

fast-external-failover boolean
Synopsis Drop external BGP session immediately when link fails
Contextconfigure service vprn service-name bgp group named-item-64 fast-external-failover boolean
Treefast-external-failover

Description

When this command inherits a value of true, the router drops an external BGP session on a single-hop route immediately when the local interface goes down.

When unconfigured, the command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to true.

When configured to false, the BGP session remains up until the hold time expires.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

graceful-restart
Synopsis Enable the graceful-restart context
Contextconfigure service vprn service-name bgp group named-item-64 graceful-restart
Treegraceful-restart
Introduced25.3.R2

Platforms

7705 SAR Gen 2

gr-notification boolean
Synopsis Perform graceful restart procedures after NOTIFICATION
Contextconfigure service vprn service-name bgp group named-item-64 graceful-restart gr-notification boolean
Treegr-notification

Description

When configured to true, the Graceful Restart capability sent by the router indicates support for NOTIFICATION messages. If the peer also supports this capability, the session is restarted gracefully (while preserving forwarding) if either peer sends a NOTIFICATION message due to some type of event or error.

When configured to false, NOTIFICATION messages are not supported.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

long-lived
Synopsis Enable the long-lived context
Context configure service vprn service-name bgp group named-item-64 graceful-restart long-lived
Treelong-lived
Introduced25.3.R2

Platforms

7705 SAR Gen 2

family [family-type] keyword
Synopsis Enter the family list instance
Contextconfigure service vprn service-name bgp group named-item-64 graceful-restart long-lived family keyword
Treefamily
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[family-type] keyword
Synopsis Address family type for LLGR
Context configure service vprn service-name bgp group named-item-64 graceful-restart long-lived family keyword
Treefamily
Optionsipv4, ipv6, flow-ipv4, flow-ipv6, label-ipv4

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

advertised-stale-time number
Synopsis LLGR stale routes time for family override
Contextconfigure service vprn service-name bgp group named-item-64 graceful-restart long-lived family keyword advertised-stale-time number
Treeadvertised-stale-time

Description

This command configures the long-lived stale routes time that is advertised by the router in its LLGR capability.

This command applies to all AFI/SAFI in the advertised LLGR capability with a family-specific override.

Range0 to 16777215
Default86400
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

helper-override-stale-time number
Synopsis Locally-configured stale routes override time
Contextconfigure service vprn service-name bgp group named-item-64 graceful-restart long-lived family keyword helper-override-stale-time number
Treehelper-override-stale-time

Description

This command configures a locally-imposed LLGR stale time that overrides the long-lived stale routes time that is advertised by the router in its LLGR capability. This is a family-specific override value.

Range0 to 16777216
Default16777216
Introduced25.3.R2

Platforms

7705 SAR Gen 2

forwarding-bits-set keyword
Synopsis BGP LLGR forwarding-bit behavior for address family
Contextconfigure service vprn service-name bgp group named-item-64 graceful-restart long-lived forwarding-bits-set keyword
Treeforwarding-bits-set

Description

This command determines the setting of the F bit in the GR and LLGR capabilities advertised by the router. When the F bit is set for an address family, it indicates that the advertising router is able to preserve forwarding state for the routes of that address family across the last restart. When the session is re-established after a restart and the F bit is not set, all stale routes from the peer are immediately removed for the corresponding address family.

This command allows the F bit to be set for all address families or only for non-forwarding address families (L2-VPN, route target, flow-IPv4, and flow-IPv6).

Optionsnone, all, non-fwd
Defaultnone
Introduced25.3.R2

Platforms

7705 SAR Gen 2

helper-override-restart-time number
Synopsis Locally-configured override for restart time
Contextconfigure service vprn service-name bgp group named-item-64 graceful-restart long-lived helper-override-restart-time number
Treehelper-override-restart-time

Description

This command overrides the restart time advertised by a peer (in its GR capability) with a locally-configured value. This override applies only to AFI/SAFI that were included in the GR capability of the peer. The restart-time is always zero for AFI/SAFI not included in the GR capability. This command is useful if the local router wants to force the LLGR phase to begin after a set time for all protected AFI/SAFI.

Range0 to 4095
Introduced25.3.R2

Platforms

7705 SAR Gen 2

helper-override-stale-time number
Synopsis Locally-configured stale routes override time
Contextconfigure service vprn service-name bgp group named-item-64 graceful-restart long-lived helper-override-stale-time number
Treehelper-override-stale-time

Description

This command configures a locally-imposed LLGR stale time that overrides the long-lived stale routes time that is advertised by the router in its LLGR capability.

This command applies to all AFI/SAFI in the advertised LLGR capability except for any AFI/SAFI with a family-specific override.

Range0 to 16777215
Introduced25.3.R2

Platforms

7705 SAR Gen 2

without-no-export boolean
Synopsis Advertise LLGR stale routes to non-LLGR peers
Contextconfigure service vprn service-name bgp group named-item-64 graceful-restart long-lived without-no-export boolean
Treewithout-no-export

Description

When configured to true, LLGR stale routes can be advertised to any peer (EBGP or IBGP) that did not signal the LLGR capability. For IBGP and confederation-EBGP peers that did not advertise the LLGR capability, the local preference attribute in the advertised stale routes is automatically set to 0.

When configured to false, LLGR stale routes are not advertised to any EBGP peer that did not signal the LLGR capability. For IBGP and confederation-EBGP peers that did not advertise the LLGR capability, the local preference attribute in the advertised stale routes is automatically set to 0 and a NO_EXPORT standard community is automatically added to the routes.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hold-time
Synopsis Enter the hold-time context
Context configure service vprn service-name bgp group named-item-64 hold-time
Treehold-time
Introduced25.3.R2

Platforms

7705 SAR Gen 2

minimum-hold-time number
Synopsis Minimum hold time between successive messages
Contextconfigure service vprn service-name bgp group named-item-64 hold-time minimum-hold-time number
Treeminimum-hold-time

Description

This command specifies the minimum hold time that is accepted for the session. If a peer proposes a hold time lower than this value, the session attempt is rejected.

When unconfigured, the command value is inherited from the BGP global-level setting.

Range0 | 3 to 65536
Default0
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

seconds number
Synopsis Maximum time BGP waits between successive messages
Contextconfigure service vprn service-name bgp group named-item-64 hold-time seconds number
Treeseconds

Description

This command configures the maximum time BGP waits between successive messages (either keepalive or update) from its peer before closing the connection.

Although the implementation allows setting the keepalive timer at the BGP group level times separately, the configured keepalive timer is overridden by this value under the following circumstances.

  • If the specified hold time is less than the configured keepalive time, the operational keepalive time is set to a third of the hold-time; the configured keepalive time is not changed.

  • If the hold time is set to zero, the operational value of the keepalive time is set to zero; the configured keepalive time is not changed. The connection with the peer is up permanently and no keepalive packets are sent to the peer.

When unconfigured, the command setting is inherited from the BGP global-level configuration.

Range0 | 3 to 65535
Introduced25.3.R2

Platforms

7705 SAR Gen 2

import
Synopsis Enable the import context
Context configure service vprn service-name bgp group named-item-64 import
Treeimport
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy (policy-expr-string | string)
Synopsis Route policy name
Context configure service vprn service-name bgp group named-item-64 import policy (policy-expr-string | string)
Treepolicy
String length1 to 255
Max. instances15
Min. instances1

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

initial-send-delay-zero boolean
Synopsis Send BGP updates as soon as the session comes up
Contextconfigure service vprn service-name bgp group named-item-64 initial-send-delay-zero boolean
Treeinitial-send-delay-zero

Description

When configured to true, BGP updates are sent as soon as the session comes up.

When unconfigured, the command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, BGP waits to send UPDATE messages for the minimum route advertisement time after a session is established.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

keepalive number
Synopsis Time after which the BGP KEEPALIVE message is sent
Contextconfigure service vprn service-name bgp group named-item-64 keepalive number
Treekeepalive

Description

This command configures the BGP keepalive timer value. A keepalive message is sent every time this timer expires.

This value is generally one-third of the hold time interval configured in the hold-time seconds context. Although the implementation allows this keepalive value and the hold time interval to be independently set, under the following circumstances, the configured keepalive value is overridden by the hold time interval value:

  • If the specified keepalive value is greater than the configured hold time, the specified keepalive value is ignored and the timer value is set to one third of the current hold time value.

  • If the specified hold time interval is less than the configured keepalive value, the keepalive value is reset to one third of the specified hold time interval.

  • If the hold time interval is set to zero, the configured keepalive value is ignored. This means that the connection with the peer is up permanently and no keepalive packets are sent to the peer.

When unconfigured, the command inherits the BGP global-level setting.

Range0 to 21845
Introduced25.3.R2

Platforms

7705 SAR Gen 2

label-preference number
Synopsis Route preference for routes from labeled-unicast peers
Contextconfigure service vprn service-name bgp group named-item-64 label-preference number
Treelabel-preference
Range1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

link-bandwidth
Synopsis Enter the link-bandwidth context
Contextconfigure service vprn service-name bgp group named-item-64 link-bandwidth
Treelink-bandwidth

Description

Commands in this context specify the handling of the Link Bandwidth Extended Community attached to specific BGP routes.

When all used multipaths of an IP prefix correspond to BGP routes with a Link Bandwidth EC, the datapath is programmed to use weighted ECMP across the BGP next hops in proportion to the bandwidth values.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

accept-from-ebgp
Synopsis Enter the accept-from-ebgp context
Contextconfigure service vprn service-name bgp group named-item-64 link-bandwidth accept-from-ebgp
Treeaccept-from-ebgp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

add-to-received-ebgp
Synopsis Enter the add-to-received-ebgp context
Contextconfigure service vprn service-name bgp group named-item-64 link-bandwidth add-to-received-ebgp
Treeadd-to-received-ebgp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

aggregate-used-paths
Synopsis Enter the aggregate-used-paths context
Contextconfigure service vprn service-name bgp group named-item-64 link-bandwidth aggregate-used-paths
Treeaggregate-used-paths
Introduced25.3.R2

Platforms

7705 SAR Gen 2

send-to-ebgp
Synopsis Enter the send-to-ebgp context
Contextconfigure service vprn service-name bgp group named-item-64 link-bandwidth send-to-ebgp
Treesend-to-ebgp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

local-address (ipv4-address-no-zone | ipv6-address-no-zone | interface-name)
Synopsis Local IP address used when communicating with BGP peers
Contextconfigure service vprn service-name bgp group named-item-64 local-address (ipv4-address-no-zone | ipv6-address-no-zone | interface-name)
Treelocal-address
String length1 to 32
Introduced25.3.R2

Platforms

7705 SAR Gen 2

local-as
Synopsis Enter the local-as context
Context configure service vprn service-name bgp group named-item-64 local-as
Treelocal-as
Introduced25.3.R2

Platforms

7705 SAR Gen 2

as-number number
Synopsis Local (or virtual) BGP AS number
Context configure service vprn service-name bgp group named-item-64 local-as as-number number
Treeas-number
Range1 to 4294967295
Introduced25.3.R2

Platforms

7705 SAR Gen 2

prepend-global-as boolean
Synopsis Prepend global ASN when advertising routes to BGP peer
Contextconfigure service vprn service-name bgp group named-item-64 local-as prepend-global-as boolean
Treeprepend-global-as

Description

When configured to true, the global ASN is added to the AS_PATH attribute in outbound routes sent to the peer.

When configured to false, the global ASN is not included in the AS_PATH attribute.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

private boolean
Synopsis Hide the local ASN in sent paths learned from peering
Contextconfigure service vprn service-name bgp group named-item-64 local-as private boolean
Treeprivate

Description

When configured to true, the local AS number is only advertised to peers that use the local ASN for establishing BGP peering sessions.

When configured to false, the local ASN is advertised to all peers, including those that can use the global ASN for establishing BGP peering sessions.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

local-preference number
Synopsis Default local preference if not in incoming routes
Contextconfigure service vprn service-name bgp group named-item-64 local-preference number
Treelocal-preference
Range0 to 4294967295
Introduced25.3.R2

Platforms

7705 SAR Gen 2

loop-detect keyword
Synopsis Strategy for loop detection in the AS path
Contextconfigure service vprn service-name bgp group named-item-64 loop-detect keyword
Treeloop-detect
Optionsdrop-peer, ignore-loop, off, discard-route
Introduced25.3.R2

Platforms

7705 SAR Gen 2

med-out (number | keyword)
Synopsis Default MED attribute value to advertise to peers
Contextconfigure service vprn service-name bgp group named-item-64 med-out (number | keyword)
Treemed-out
Max. range0 to 4294967295
Optionsigp-cost
Introduced25.3.R2

Platforms

7705 SAR Gen 2

multihop number
Synopsis TTL in IP packet headers for EBGP peers multi-hops away
Contextconfigure service vprn service-name bgp group named-item-64 multihop number
Treemultihop
Range1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

next-hop-self boolean
Synopsis Advertise routes with local address as next-hop address
Contextconfigure service vprn service-name bgp group named-item-64 next-hop-self boolean
Treenext-hop-self
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

origin-validation
Synopsis Enter the origin-validation context
Contextconfigure service vprn service-name bgp group named-item-64 origin-validation
Treeorigin-validation

Description

Commands in this context configure the marking of every inbound IPv4, IPv6, and labeled IPv4 route from the BGP peer with one of the following origin validation states:

  • Valid (0)

  • Not-Found (1)

  • Invalid (2)

The configurations apply to all types of VPRN BGP peers, but generally should be applied only to EBGP peers and groups that contain only EBGP peers.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4 boolean
Synopsis Enable support for unlabeled unicast IPv4 routes
Contextconfigure service vprn service-name bgp group named-item-64 origin-validation ipv4 boolean
Treeipv4
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6 boolean
Synopsis Enable support for unlabeled unicast IPv6 routes
Contextconfigure service vprn service-name bgp group named-item-64 origin-validation ipv6 boolean
Treeipv6
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

passive boolean
Synopsis Enable passive mode for BGP communication
Contextconfigure service vprn service-name bgp group named-item-64 passive boolean
Treepassive
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

path-mtu-discovery boolean
Synopsis Enable Path MTU Discovery
Context configure service vprn service-name bgp group named-item-64 path-mtu-discovery boolean
Treepath-mtu-discovery

Description

When configured to true, Path MTU Discovery (PMTUD) is enabled for the associated TCP connections.

When set to true, PMTUD is activated toward an IPv4 BGP neighbor and the Don’t Fragment (DF) bit is set in the IP header of all IPv4 packets sent to the peer. If any device along the path toward the peer cannot forward the packet because the IP MTU of the interface is smaller than the IP packet size, this device drops the packet and sends an ICMP or ICMPv6 error message encoding the interface MTU. When the router receives the ICMP or ICMPv6 message, it lowers the TCP maximum segment size limit from the previous value so that the IP MTU constraint can be accommodated.

When configured to false and there is no TCP MSS configuration that can be associated with a BGP neighbor (in either the BGP configuration or the first hop IP interface configuration), the router advertises a value of only 1024 bytes as the TCP MSS option value, limiting received TCP segments to that size.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

peer-as number
Synopsis Peer AS number
Contextconfigure service vprn service-name bgp group named-item-64 peer-as number
Treepeer-as
Range1 to 4294967295
Introduced25.3.R2

Platforms

7705 SAR Gen 2

peer-ip-tracking boolean
Synopsis Enable BGP peer tracking
Context configure service vprn service-name bgp group named-item-64 peer-ip-tracking boolean
Treepeer-ip-tracking

Description

When configured to true, this command enables BGP peer tracking.

Peer tracking should be used with caution. Peer tracking can tear a session down even if the loss of connectivity turns out to be short-lived (for example, while the IGP protocol is re-converging). Next-hop tracking, which is always enabled, handles temporary connectivity issues more effectively.

When unconfigured, the command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, peer tracking is disabled.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

preference number
Synopsis Route preference for routes learned from all peers
Contextconfigure service vprn service-name bgp group named-item-64 preference number
Treepreference
Range1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

prefix-limit [family] keyword
Synopsis Enter the prefix-limit list instance
Contextconfigure service vprn service-name bgp group named-item-64 prefix-limit keyword
Treeprefix-limit

Description

Commands in this context limit the number of BGP routes per address family received from a BGP peer and define the actions when crossing the configured maximum.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[family] keyword
Synopsis Address family to which the limit applies
Contextconfigure service vprn service-name bgp group named-item-64 prefix-limit keyword
Treeprefix-limit
Optionsipv4, ipv6, mcast-ipv4, flow-ipv4, flow-ipv6, mcast-ipv6, label-ipv4

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

hold-excess number
Synopsis Percentage of maximum routes to install in route table
Contextconfigure service vprn service-name bgp group named-item-64 prefix-limit keyword hold-excess number
Treehold-excess

Description

This command specifies the percentage of maximum routes that are allowed to be installed in the route table for the configured address family. If a peer within scope of the configuration exceeds the limit, the overflow routes are held in the BGP RIB as inactive routes and are ineligible for forwarding and advertisement to other peers. If the post-import command is configured to true, only routes not rejected by import policies count toward the limit.

A BGP route in an overflow state is reconsidered for activation and reinstallation when an UPDATE message is received for the route.

This command is mutually exclusive with the idle-timeout and log-only commands.

Range1 to 100
Introduced25.3.R2

Platforms

7705 SAR Gen 2

idle-timeout number
Synopsis Time BGP peering remains idle before reconnecting
Contextconfigure service vprn service-name bgp group named-item-64 prefix-limit keyword idle-timeout number
Treeidle-timeout

Description

This command configures the time in minutes before a BGP peer is automatically re-established after reaching the prefix limit.

When unconfigured, the BGP peer stays down until the operator performs a reset. This command and log-only cannot be configured simultaneously.

Range1 to 1024
Introduced25.3.R2

Platforms

7705 SAR Gen 2

log-only boolean
Synopsis Send warning message at threshold instead of take-down
Contextconfigure service vprn service-name bgp group named-item-64 prefix-limit keyword log-only boolean
Treelog-only

Description

When configured to true, the router disables the BGP session from being taken down upon reaching the prefix limit. Instead, only a warning message is sent when the limit is reached. A warning message is also sent when the configured threshold percentage of the limit is reached.

This command and idle-timeout cannot be configured simultaneously.

When configured to false, the router generates a log event and takes the BGP session down upon reaching the prefix limit.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

maximum number
Synopsis Maximum number of routes to be learned from a peer
Contextconfigure service vprn service-name bgp group named-item-64 prefix-limit keyword maximum number
Treemaximum

Description

This command configures the maximum number of BGP routes of the specified address family that can be received from a peer before administrative action is taken.

When log-only is unconfigured, the BGP session is taken down whenever the limit of any family is exceeded even if the limits of the other family has not been exceeded.

Range1 to 4294967295

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

post-import boolean
Synopsis Apply limit only to routes accepted by import policies
Contextconfigure service vprn service-name bgp group named-item-64 prefix-limit keyword post-import boolean
Treepost-import

Description

When configured to true, the system limits the number of routes that are accepted by import policies. Routes rejected by import policies are not counted against the configured limit.

When configured to false, the system limits the number of routes to all routes received from the peer.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

threshold number
Synopsis Percentage threshold that triggers a warning message
Contextconfigure service vprn service-name bgp group named-item-64 prefix-limit keyword threshold number
Treethreshold
Range1 to 100
Default90
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

remove-private
Synopsis Enable the remove-private context
Contextconfigure service vprn service-name bgp group named-item-64 remove-private
Treeremove-private
Introduced25.3.R2

Platforms

7705 SAR Gen 2

limited boolean
Synopsis Remove private ASNs up to first public ASN encountered
Contextconfigure service vprn service-name bgp group named-item-64 remove-private limited boolean
Treelimited
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

replace boolean
Synopsis Replace private ASN with global ASN before advertising
Contextconfigure service vprn service-name bgp group named-item-64 remove-private replace boolean
Treereplace
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

send-communities
Synopsis Enter the send-communities context
Contextconfigure service vprn service-name bgp group named-item-64 send-communities
Treesend-communities
Introduced25.3.R2

Platforms

7705 SAR Gen 2

extended boolean
Synopsis Advertise the Extended Communities attribute to peers
Contextconfigure service vprn service-name bgp group named-item-64 send-communities extended boolean
Treeextended

Description

When unconfigured, this command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to true.

When this command inherits a value of true, BGP extended communities are sent to peers in the Extended Communities attribute.

When configured to false, all extended communities are removed from all routes advertised to BGP peers.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

large boolean
Synopsis Advertise the Large Communities attribute to peers
Contextconfigure service vprn service-name bgp group named-item-64 send-communities large boolean
Treelarge

Description

When unconfigured, this command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to true.

When this command inherits a value of true, BGP large communities are sent to peers in the Large Communities attribute.

When configured to false, all large communities are removed from all routes advertised to BGP peers.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

standard boolean
Synopsis Advertise the Communities attribute to peers
Contextconfigure service vprn service-name bgp group named-item-64 send-communities standard boolean
Treestandard

Description

When unconfigured, this command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to true.

When this command inherits a value of true, BGP standard communities are sent to peers in the Communities attribute.

When configured to false, all standard communities are removed from all routes advertised to BGP peers.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

send-default
Synopsis Enable the send-default context
Contextconfigure service vprn service-name bgp group named-item-64 send-default
Treesend-default
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4 boolean
Synopsis Generate and advertise an IPv4 default route (0/0)
Contextconfigure service vprn service-name bgp group named-item-64 send-default ipv4 boolean
Treeipv4
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6 boolean
Synopsis Generate and advertise an IPv6 default route (::/0)
Contextconfigure service vprn service-name bgp group named-item-64 send-default ipv6 boolean
Treeipv6
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

split-horizon boolean
Synopsis Prevent routes being reflected back to best-route peer
Contextconfigure service vprn service-name bgp group named-item-64 split-horizon boolean
Treesplit-horizon

Description

When configured to true, this command enables the use of split-horizon.

This command prevents routes from being reflected back to a peer that sends the best route. It applies to routes of all address families and to any type of sending peer; confed-EBGP, EBGP and IBGP.

Enabling the split-horizon functionality may have a detrimental impact on peer and route scaling and should only be used when absolutely necessary.

When unconfigured, the command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, the use of split-horizon is disabled.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

static-group boolean
Synopsis Use group for static peers
Context configure service vprn service-name bgp group named-item-64 static-group boolean
Treestatic-group
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

tcp-mss (number | keyword)
Synopsis TCP maximum segment size override
Context configure service vprn service-name bgp group named-item-64 tcp-mss (number | keyword)
Treetcp-mss

Description

This command configures an override for the TCP maximum segment size to use with a specific peer or set of peers (depending on the scope of the command).

The configured value controls two properties of the TCP connection as follows:

TCP MSS option - The router advertises the TCP MSS option value in the TCP SYN packet it sends as part of the 3-way handshake. The advertised value may be lower than the configured value, depending on the IP MTU of the first hop IP interface. The peers must abide by this value when sending TCP segments to the local router.

TCP maximum segment size - The actual transmitted size may be lower than the configured value, depending on the TCP MSS option value signaled by the peers, the effect of path MTU discovery, or other factors.

Range384 to 9746
Optionsip-stack
Introduced25.3.R2

Platforms

7705 SAR Gen 2

third-party-nexthop boolean
Synopsis Apply third-party next-hop processing to EBGP peers
Contextconfigure service vprn service-name bgp group named-item-64 third-party-nexthop boolean
Treethird-party-nexthop

Description

When configured to true, this command enables the router to send third-party next hop to EBGP peers in the same subnet as the source peer. The address family of the transport must match the address family of the route.

When an IPv4 or IPv6 route is received from one EBGP peer and advertised to another EBGP peer in the same IP subnet, the BGP next hop is left unchanged.

When unconfigured, the command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, third-party next-hop processing is disabled and the next hop carries the IP address of the interface used to establish the TCP connection to the peer.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ttl-security number
Synopsis Minimum TTL value for an incoming BGP packet
Contextconfigure service vprn service-name bgp group named-item-64 ttl-security number
Treettl-security

Description

This command configures the minimum TTL value that BGP accepst from an incoming packet. A packet with a TTL value less than the minimum configured TTL value is discarded.

Range1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

type keyword
Synopsis BGP peer type
Contextconfigure service vprn service-name bgp group named-item-64 type keyword
Treetype
Optionsno-type, internal, external
Defaultno-type
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hold-time
Synopsis Enter the hold-time context
Context configure service vprn service-name bgp hold-time
Treehold-time
Introduced25.3.R2

Platforms

7705 SAR Gen 2

minimum-hold-time number
Synopsis Minimum hold time between successive messages
Contextconfigure service vprn service-name bgp hold-time minimum-hold-time number
Treeminimum-hold-time

Description

This command specifies the minimum hold time that is accepted for the session. If a peer proposes a hold time lower than this value, the session attempt is rejected.

Range0 | 3 to 65535
Default0
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

seconds number
Synopsis Maximum time BGP waits between successive messages
Contextconfigure service vprn service-name bgp hold-time seconds number
Treeseconds

Description

This command configures the maximum time BGP waits between successive messages (either keepalive or update) from its peer before closing the connection.

Although the implementation allows setting the keepalive timer at the BGP global level times separately, the configured keepalive timer is overridden by this value under the following circumstances.

  • If the specified hold time is less than the configured keepalive time, the operational keepalive time is set to a third of the hold-time; the configured keepalive time is not changed.

  • If the hold time is set to zero, the operational value of the keepalive time is set to zero; the configured keepalive time is not changed. The connection with the peer is up permanently and no keepalive packets are sent to the peer.

Range0 | 3 to 65535
Default90
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

ibgp-multipath boolean
Synopsis Enable IBGP multipath load balancing
Context configure service vprn service-name bgp ibgp-multipath boolean
Treeibgp-multipath

Description

When configured to true, this command enables IBGP multipath load balancing when adding BGP routes to the route table if the route resolving the BGP next hop offers multiple next hops.

When configured to false, this command disables IBGP multipath load balancing.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

import
Synopsis Enable the import context
Context configure service vprn service-name bgp import
Treeimport
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy (policy-expr-string | string)
Synopsis Import policy name
Context configure service vprn service-name bgp import policy (policy-expr-string | string)
Treepolicy
String length1 to 255
Max. instances15
Min. instances1

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

keepalive number
Synopsis Time after which the BGP KEEPALIVE message is sent
Contextconfigure service vprn service-name bgp keepalive number
Treekeepalive
Range0 to 21845
Default30
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

label-preference number
Synopsis Route preference for routes from labeled-unicast peers
Contextconfigure service vprn service-name bgp label-preference number
Treelabel-preference
Range1 to 255
Default170
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

local-as
Synopsis Enter the local-as context
Context configure service vprn service-name bgp local-as
Treelocal-as
Introduced25.3.R2

Platforms

7705 SAR Gen 2

as-number number
Synopsis Local (or virtual) BGP AS number
Context configure service vprn service-name bgp local-as as-number number
Treeas-number
Range1 to 4294967295
Introduced25.3.R2

Platforms

7705 SAR Gen 2

prepend-global-as boolean
Synopsis Prepend global AS when advertising routes to BGP peer
Contextconfigure service vprn service-name bgp local-as prepend-global-as boolean
Treeprepend-global-as

Description

When configured to true, the global ASN is added to the AS_PATH attribute in outbound routes sent to the peer.

When configured to false, the global ASN is hidden in paths announced to the EBGP peer.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

private boolean
Synopsis Hide the local ASN in sent paths learned from peering
Contextconfigure service vprn service-name bgp local-as private boolean
Treeprivate

Description

When configured to true, the local ASN is hidden in paths learned from the peering.

When configured to false, the local ASN is advertised to all peers, including those that can use the global ASN for establishing BGP peering sessions.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

local-preference number
Synopsis Default local preference if not in incoming routes
Contextconfigure service vprn service-name bgp local-preference number
Treelocal-preference
Max. range0 to 4294967295
Default100
Introduced25.3.R2

Platforms

7705 SAR Gen 2

loop-detect keyword
Synopsis Strategy for loop detection in the AS path
Contextconfigure service vprn service-name bgp loop-detect keyword
Treeloop-detect
Optionsdrop-peer, ignore-loop, off, discard-route
Defaultignore-loop
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

med-out (number | keyword)
Synopsis Default MED attribute value to advertise to peers
Contextconfigure service vprn service-name bgp med-out (number | keyword)
Treemed-out
Max. range0 to 4294967295
Optionsigp-cost
Introduced25.3.R2

Platforms

7705 SAR Gen 2

multihop number
Synopsis TTL in IP packet headers for EBGP peers multi-hops away
Contextconfigure service vprn service-name bgp multihop number
Treemultihop

Description

This command configures the Time to Live (TTL) value entered in the IP header of packets sent to an EBGP peer multiple hops away. This command applies only to EBGP.

Range1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

multipath
Synopsis Enter the multipath context
Context configure service vprn service-name bgp multipath
Treemultipath
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ebgp number
Synopsis Maximum multipaths per prefix for EBGP learned routes
Contextconfigure service vprn service-name bgp multipath ebgp number
Treeebgp
Range1 to 64
Introduced25.3.R2

Platforms

7705 SAR Gen 2

family [family-type] keyword
Synopsis Enter the family list instance
Contextconfigure service vprn service-name bgp multipath family keyword
Treefamily

Description

Commands in this context set ECMP multipath parameters that apply only to the specified label unicast address family.

When multipath is enabled, traffic to the destination is load-shared across a set of paths (BGP routes) that the BGP decision process considers equal to the best path. The distribution of traffic over the multiple paths may or may not be equal. The distribution is based on weights derived from the Link Bandwidth Extended Community.

For more information about the criteria a non-best route must meet to qualify as a multipath, see “BGP route installation in the route table” in the 7705 SAR Gen 2 Unicast Routing Protocols User Guide.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[family-type] keyword
Synopsis Address family type for the multipath selection
Contextconfigure service vprn service-name bgp multipath family keyword
Treefamily
Optionsipv4, ipv6, label-ipv4, label-ipv6

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ebgp number
Synopsis Maximum multipaths when best path is EBGP learned route
Contextconfigure service vprn service-name bgp multipath family keyword ebgp number
Treeebgp

Description

This command configures the maximum number of multipaths per prefix or NLRI when the best path is an EBGP learned route. The limit configured using this command overrides the limit configured in the max-paths command. If the best path is an EBGP learned route, and this command is set to 1, multipaths are disabled.

Range1 to 64
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ibgp number
Synopsis Maximum multipaths when best path is IBGP learned route
Contextconfigure service vprn service-name bgp multipath family keyword ibgp number
Treeibgp

Description

This command configures the maximum number of multipaths per prefix or NLRI when the best path is an IBGP learned route. The limit configured using this command overrides the limit configured in the max-paths command. If the best path is an IBGP learned route and this command is set to 1, multipaths are disabled.

Range1 to 64
Introduced25.3.R2

Platforms

7705 SAR Gen 2

max-paths number
Synopsis Maximum number of multipaths per prefix or NLRI
Contextconfigure service vprn service-name bgp multipath family keyword max-paths number
Treemax-paths

Description

This command configures the maximum number of multipaths per prefix or NLRI for the IP family option specified using the family command.

Consider the following when configuring this command: 

  • If the best path is an EBGP-learned route and the ebgp command is configured, the limit configured in the ebgp command overrides the limit configured in this command. 

  • If the best path is an IBGP-learned route and the ibgp command is configured, the limit configured in the ibgp command overrides the limit configured in this command.

  • If the best path is an EBGP-learned route and the ebgp command is not configured, and this command is configured to 1, multipaths are disabled.

  • If the best path is an IBGP-learned route and the ibgp command is not configured, and this command is configured to 1, multipaths are disabled.

Range1 to 64
Introduced25.3.R2

Platforms

7705 SAR Gen 2

restrict keyword
Synopsis AS path restriction for the non-best path
Contextconfigure service vprn service-name bgp multipath family keyword restrict keyword
Treerestrict
Optionssame-as-path-length, same-neighbor-as, exact-as-path
Defaultsame-as-path-length
Introduced25.3.R2

Platforms

7705 SAR Gen 2

unequal-cost boolean
Synopsis Ignore differences in the next-hop cost for multipath
Contextconfigure service vprn service-name bgp multipath family keyword unequal-cost boolean
Treeunequal-cost

Description

When configured to true, BGP ignores differences in the next-hop cost when determining eligible multipaths.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ibgp number
Synopsis Maximum multipaths per prefix for IBGP learned routes
Contextconfigure service vprn service-name bgp multipath ibgp number
Treeibgp
Range1 to 64
Introduced25.3.R2

Platforms

7705 SAR Gen 2

max-paths number
Synopsis Maximum multipaths per prefix
Context configure service vprn service-name bgp multipath max-paths number
Treemax-paths
Range1 to 64
Default1
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

restrict keyword
Synopsis AS path restriction for the non-best path
Contextconfigure service vprn service-name bgp multipath restrict keyword
Treerestrict
Optionssame-as-path-length, same-neighbor-as, exact-as-path
Defaultsame-as-path-length
Introduced25.3.R2

Platforms

7705 SAR Gen 2

neighbor [ip-address] (ipv4-address-with-zone | ipv6-address-with-zone)
Synopsis Enter the neighbor list instance
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone)
Treeneighbor
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ip-address] (ipv4-address-with-zone | ipv6-address-with-zone)
Synopsis IP address of the BGP peer router
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone)
Treeneighbor

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the BGP neighbor
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

advertise-inactive boolean
Synopsis Advertise an inactive BGP route to peers
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) advertise-inactive boolean
Treeadvertise-inactive

Description

When configured to true, this command allows an inactive BGP route to be advertised, even though it is not the most preferred route. The effect of the command on advertised unlabeled, labeled, and multicast IPv4 and IPv6 routes depends on several factors.

  • If the active route for the IP prefix is a BGP route, that route is advertised.

  • If the active route is a non-BGP route and there are valid inactive BGP routes to the same destination, the best valid inactive route is advertised unless the active non-BGP route is matched and accepted by an export policy applied to the session.

  • If the active route is a non-BGP route and there are no valid BGP routes to the same destination, no route is advertised unless the active non-BGP route is matched and accepted by an export policy applied to the session.

When unconfigured, the command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, the advertisement of inactive BGP routes to other BGP peers is disabled.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

advertise-ipv6-next-hops
Synopsis Enable the advertise-ipv6-next-hops context
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) advertise-ipv6-next-hops
Treeadvertise-ipv6-next-hops
Introduced25.3.R2

Platforms

7705 SAR Gen 2

as-override boolean
Synopsis Replace the peer ASN with the local ASN in AS Path
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) as-override boolean
Treeas-override

Description

When configured to true, the advertising router's local AS replaces all occurrences of the peer AS in the AS_PATH attribute.

This command should be used with caution, as it breaks BGP's loop detection mechanism.

When unconfigured, the command inherits the value of the group-level setting (true or false). This command cannot be explicitly configured to false.

When the command inherits a value of false, no AS override is performed.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

asn-4-byte boolean
Synopsis Advertise the use of 4-byte ASNs
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) asn-4-byte boolean
Treeasn-4-byte
Introduced25.3.R2

Platforms

7705 SAR Gen 2

authentication-key encrypted-leaf
Synopsis BGP authentication key
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) authentication-key encrypted-leaf
Treeauthentication-key
String length1 to 370
Introduced25.3.R2

Platforms

7705 SAR Gen 2

authentication-keychain reference
Synopsis TCP authentication keychain for the session
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) authentication-keychain reference
Treeauthentication-keychain

Description

This command associates the keychain to be used to authenticate the BGP session. The keychain allows the rollover of authentication keys during the lifetime of a session.

Reference

configure system security keychains keychain named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd-liveness boolean
Synopsis Enable BFD
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) bfd-liveness boolean
Treebfd-liveness

Description

When configured to true, BFD is enabled on a given protocol interface where the state of the protocol interface is tied to the state of the BFD session between the local node and the remote node.

When unconfigured, the command inherits the value of the group-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, BFD is removed from the associated protocol adjacency.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd-strict-mode
Synopsis Enter the bfd-strict-mode context
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) bfd-strict-mode
Treebfd-strict-mode
Introduced25.3.R2

Platforms

7705 SAR Gen 2

advertise
Synopsis Enable the advertise context
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) bfd-strict-mode advertise
Treeadvertise

Description

Commands in this context configure BGP to advertise the Strict-BFD capability to peers that are within scope of this command and meet the following requirements:

  • The inherited or configured value for the bfd-liveness command that applies to the peer is true.

  • The interface associated with the peer has a valid BFD configuration.

When the preceding conditions are satisfied and two peers attempting to form a session both advertise the Strict-BFD capability, the BGP finite state machine in each router transitions the session state to established after the BFD session with the peer enters the up state.

When unconfigured, BGP does not advertise the Strict-BFD capability to peers.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

holdtime number
Synopsis Maximum time BGP waits for the BFD session to come up
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) bfd-strict-mode advertise holdtime number
Treeholdtime

Description

This command configures the maximum time BGP waits for the BFD session to come up, provided that the Strict-BFD procedures apply to a session, and the negotiated BGP hold time is zero (no keepalives). If the negotiated BGP hold time is greater than zero, the advertised hold time is not considered.

Range1 to 65535
Unitsseconds
Default 30
Introduced25.3.R2

Platforms

7705 SAR Gen 2

next-hop-reachability boolean
Synopsis Consider next hop unreachable if BFD session is down
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) bfd-strict-mode next-hop-reachability boolean
Treenext-hop-reachability

Description

When configured to true, the router considers next-hop self routes belonging to specific address families received from a peer within scope of this command as having an unresolved next hop, provided that the following requirements are met:

  • The BFD session to the peer is in a down state.

  • There is a valid interface BFD configuration that applies to the peer.

  • There is a valid BFD liveness configuration that applies to the peer.

The unresolved state is maintained until the BFD session state changes to up or administratively down, even if there is a resolving route or tunnel that matches the BGP next-hop address.

Routes received from one peer with a BGP next-hop address equal to the address of another peer are not affected by the BFD session to the other peer.The behavior of the router when this command is true does not depend on whether Strict-BFD is used, as both features are independent.

Configuring this command to true only affects routes belonging to the following address families:

  • IPv4

  • IPv6

  • IPv4 VPN

  • IPv6 VPN

  • labeled unicast IPv4

  • labeled unicast IPv6

  • EVPN

  • IPv4 multicast

  • IPv6 multicast

  • IPv4 VPN multicast

  • IPv6 VPN multicast

When configured to false, the router does not consider next-hop self routes belonging to the preceding address families as having an unresolved next hop if the BFD session goes down.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

client-reflect boolean
Synopsis Allow cluster RR to advertise routes to its clients
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) client-reflect boolean
Treeclient-reflect
Introduced25.3.R2

Platforms

7705 SAR Gen 2

cluster
Synopsis Enter the cluster context
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) cluster
Treecluster
Introduced25.3.R2

Platforms

7705 SAR Gen 2

cluster-id ipv4-address
Synopsis Route reflector cluster ID
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) cluster cluster-id ipv4-address
Treecluster-id
Introduced25.3.R2

Platforms

7705 SAR Gen 2

connect-retry number
Synopsis BGP connect retry timer value
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) connect-retry number
Treeconnect-retry
Range1 to 65535
Introduced25.3.R2

Platforms

7705 SAR Gen 2

damp-peer-oscillations
Synopsis Enable the damp-peer-oscillations context
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) damp-peer-oscillations
Treedamp-peer-oscillations
Introduced25.3.R2

Platforms

7705 SAR Gen 2

error-interval number
Synopsis Time after a reset that the session must be error-free
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) damp-peer-oscillations error-interval number
Treeerror-interval

Description

This command sets the interval of time after a reset, during which the session must be error-free in order to reset the penalty counter and return the idle hold time to the initial wait time.

Range0 to 2048
Default30
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

idle-hold-time
Synopsis Enter the idle-hold-time context
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) damp-peer-oscillations idle-hold-time
Treeidle-hold-time
Introduced25.3.R2

Platforms

7705 SAR Gen 2

second-wait number
Synopsis Time that doubles after each repeated session failure
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) damp-peer-oscillations idle-hold-time second-wait number
Treesecond-wait

Description

This command defines the hold time that doubles after each repeated session failure that occurs in a short span of time.

Range1 to 2048
Default5
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

damping boolean
Synopsis Use BGP route damping to reduce route flap
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) damping boolean
Treedamping
Introduced25.3.R2

Platforms

7705 SAR Gen 2

default-label-preference
Synopsis Enter the default-label-preference context
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) default-label-preference
Treedefault-label-preference
Introduced25.3.R2

Platforms

7705 SAR Gen 2

default-preference
Synopsis Enter the default-preference context
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) default-preference
Treedefault-preference
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ebgp number
Synopsis Default preference for EBGP
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) default-preference ebgp number
Treeebgp
Range0 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ibgp number
Synopsis Default preference for IBGP
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) default-preference ibgp number
Treeibgp
Range0 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ebgp-default-reject-policy
Synopsis Enable the ebgp-default-reject-policy context
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) ebgp-default-reject-policy
Treeebgp-default-reject-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

enforce-first-as boolean
Synopsis Enforce the configured peer AS value in received routes
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) enforce-first-as boolean
Treeenforce-first-as

Description

When configured to true for an EBGP session, all routes received from an EBGP peer are checked to ensure that the most recent ASN in the AS_PATH attribute of each route matches the configured AS of the session. If there is not a match, the session is reset (if the update-fault-tolerance command in the error-handling context is set to false) or the session is left up but the route is treated as withdrawn (if update-fault-tolerance is set to true).

This command does not flap an established session because it applies only to routes received after the command is issued.

When unconfigured, the command inherits the value of the group-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, received routes are not checked for compliance with the rule.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

error-handling
Synopsis Enter the error-handling context
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) error-handling
Treeerror-handling
Introduced25.3.R2

Platforms

7705 SAR Gen 2

update-fault-tolerance boolean
Synopsis Tolerate non-critical errors in UPDATE messages
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) error-handling update-fault-tolerance boolean
Treeupdate-fault-tolerance

Description

When configured to true, non-critical errors are handled with treat-as-withdraw, attribute-discard, and other non-disruptive approaches that do not cause a session reset. Critical errors still trigger a session reset.

When unconfigured, the command inherits the value of the group-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, all errors trigger a session reset.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

evpn-link-bandwidth
Synopsis Enter the evpn-link-bandwidth context
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) evpn-link-bandwidth
Treeevpn-link-bandwidth
Introduced25.3.R2

Platforms

7705 SAR Gen 2

add-to-received-bgp number
Synopsis Weight added to received PE-CE BGP routes
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) evpn-link-bandwidth add-to-received-bgp number
Treeadd-to-received-bgp

Description

This command configures the weight value added to all BGP PE-CE routes for the purpose of weighted ECMP if EVPN-IFL and BGP PE-CE routes are combined into the same ECMP set.

For the load-balancing betweeen EVPN-IFL and BGP PE-CE routes the configure service vprn bgp eibgp-loadbalance command must already be configured in the system.

Range1 to 128
Introduced25.3.R2

Platforms

7705 SAR Gen 2

export
Synopsis Enable the export context
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) export
Treeexport
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy (policy-expr-string | string)
Synopsis Export policy name
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) export policy (policy-expr-string | string)
Treepolicy
String length1 to 255
Max. instances15
Min. instances1

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

extended-nh-encoding
Synopsis Enable the extended-nh-encoding context
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) extended-nh-encoding
Treeextended-nh-encoding
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4 boolean
Synopsis Enable IPv4 family type
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) extended-nh-encoding ipv4 boolean
Treeipv4
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

family
Synopsis Enable the family context
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) family
Treefamily
Introduced25.3.R2

Platforms

7705 SAR Gen 2

flow-ipv6 boolean
Synopsis Advertise support for the FlowSpec-IPv6 address family
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) family flow-ipv6 boolean
Treeflow-ipv6
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4 boolean
Synopsis Add support for the IPv4 address family
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) family ipv4 boolean
Treeipv4
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6 boolean
Synopsis Advertise MP-BGP support for the IPv6 address family
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) family ipv6 boolean
Treeipv6
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

label-ipv4 boolean
Synopsis Advertise support for the label-IPv4 address family
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) family label-ipv4 boolean
Treelabel-ipv4
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mcast-ipv4 boolean
Synopsis Advertise support for the MCAST-IPv4 address family
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) family mcast-ipv4 boolean
Treemcast-ipv4
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mcast-ipv6 boolean
Synopsis Advertise support for the MCAST-IPv6 address family
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) family mcast-ipv6 boolean
Treemcast-ipv6
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

fast-external-failover boolean
Synopsis Drop external BGP session immediately when link fails
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) fast-external-failover boolean
Treefast-external-failover

Description

When this command inherits a value of true, the router drops an external BGP session on a single-hop route immediately when the local interface goes down.

When unconfigured, the command inherits the value of the group-level setting (true or false). The command cannot be explicitly configured to true.

When configured to false, the BGP session remains up until the hold time expires.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

graceful-restart
Synopsis Enable the graceful-restart context
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) graceful-restart
Treegraceful-restart
Introduced25.3.R2

Platforms

7705 SAR Gen 2

gr-notification boolean
Synopsis Perform graceful restart procedures after NOTIFICATION
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) graceful-restart gr-notification boolean
Treegr-notification

Description

When configured to true, the Graceful Restart capability sent by the router indicates support for NOTIFICATION messages. If the peer also supports this capability, the session is restarted gracefully (while preserving forwarding) if either peer sends a NOTIFICATION message due to some type of event or error.

When configured to false, NOTIFICATION messages are not supported.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

long-lived
Synopsis Enable the long-lived context
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) graceful-restart long-lived
Treelong-lived
Introduced25.3.R2

Platforms

7705 SAR Gen 2

family [family-type] keyword
Synopsis Enter the family list instance
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) graceful-restart long-lived family keyword
Treefamily
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[family-type] keyword
Synopsis Address family type for LLGR
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) graceful-restart long-lived family keyword
Treefamily
Optionsipv4, ipv6, flow-ipv4, flow-ipv6, label-ipv4

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

advertised-stale-time number
Synopsis LLGR stale routes time for family override
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) graceful-restart long-lived family keyword advertised-stale-time number
Treeadvertised-stale-time

Description

This command configures the long-lived stale routes time that is advertised by the router in its LLGR capability.

This command applies to all AFI/SAFI in the advertised LLGR capability with a family-specific override.

Range0 to 16777215
Default86400
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

helper-override-stale-time number
Synopsis Locally-configured stale routes override time
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) graceful-restart long-lived family keyword helper-override-stale-time number
Treehelper-override-stale-time

Description

This command configures a locally-imposed LLGR stale time that overrides the long-lived stale routes time that is advertised by the router in its LLGR capability. This is a family-specific override value.

Range0 to 16777216
Default16777216
Introduced25.3.R2

Platforms

7705 SAR Gen 2

forwarding-bits-set keyword
Synopsis BGP LLGR forwarding-bit behavior for address family
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) graceful-restart long-lived forwarding-bits-set keyword
Treeforwarding-bits-set

Description

This command determines the setting of the F bit in the GR and LLGR capabilities advertised by the router. When the F bit is set for an address family, it indicates that the advertising router is able to preserve forwarding state for the routes of that address family across the last restart. When the session is re-established after a restart and the F bit is not set, all stale routes from the peer are immediately removed for the corresponding address family.

This command allows the F bit to be set for all address families or only for non-forwarding address families (L2-VPN, route target, flow-IPv4, and flow-IPv6).

Optionsnone, all, non-fwd
Defaultnone
Introduced25.3.R2

Platforms

7705 SAR Gen 2

helper-override-restart-time number
Synopsis Locally-configured override for restart time
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) graceful-restart long-lived helper-override-restart-time number
Treehelper-override-restart-time

Description

This command overrides the restart time advertised by a peer (in its GR capability) with a locally-configured value. This override applies only to AFI/SAFI that were included in the GR capability of the peer. The restart-time is always zero for AFI/SAFI not included in the GR capability. This command is useful if the local router wants to force the LLGR phase to begin after a set time for all protected AFI/SAFI.

Range0 to 4095
Introduced25.3.R2

Platforms

7705 SAR Gen 2

helper-override-stale-time number
Synopsis Locally-configured stale routes override time
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) graceful-restart long-lived helper-override-stale-time number
Treehelper-override-stale-time

Description

This command configures a locally-imposed LLGR stale time that overrides the long-lived stale routes time that is advertised by the router in its LLGR capability.

This command applies to all AFI/SAFI in the advertised LLGR capability except for any AFI/SAFI with a family-specific override.

Range0 to 16777215
Introduced25.3.R2

Platforms

7705 SAR Gen 2

without-no-export boolean
Synopsis Advertise LLGR stale routes to non-LLGR peers
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) graceful-restart long-lived without-no-export boolean
Treewithout-no-export

Description

When configured to true, LLGR stale routes can be advertised to any peer (EBGP or IBGP) that did not signal the LLGR capability. For IBGP and confederation-EBGP peers that did not advertise the LLGR capability, the local preference attribute in the advertised stale routes is automatically set to 0.

When configured to false, LLGR stale routes are not advertised to any EBGP peer that did not signal the LLGR capability. For IBGP and confederation-EBGP peers that did not advertise the LLGR capability, the local preference attribute in the advertised stale routes is automatically set to 0 and a NO_EXPORT standard community is automatically added to the routes.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

group reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNeighbor to group
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) group reference
Treegroup

Reference

configure service vprn service-name bgp group named-item-64

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

hold-time
Synopsis Enter the hold-time context
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) hold-time
Treehold-time
Introduced25.3.R2

Platforms

7705 SAR Gen 2

seconds number
Synopsis Maximum hold time between successive messages
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) hold-time seconds number
Treeseconds

Description

The BGP hold time specifies the maximum time BGP waits between successive messages (either keepalive or update) from its peer, before closing the connection.

Even though the implementation allows setting the keepalive timer at the BGP neighbor level times separately, the configured keepalive timer is overridden by this value under the following circumstances:

  • If the specified hold time is less than the configured keepalive time, then the operational keepalive time is set to a third of the hold-time; the configured keepalive time is not changed.

  • If the hold time is set to zero, the operational value of the keepalive time is set to zero; the configured keepalive time is not changed. This means that the connection with the peer is up permanently and no keepalive packets are sent to the peer.

When unconfigured, the command setting is inherited from the BGP group-level configuration.

Range0 | 3 to 65535
Introduced25.3.R2

Platforms

7705 SAR Gen 2

import
Synopsis Enable the import context
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) import
Treeimport
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy (policy-expr-string | string)
Synopsis Route policy name
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) import policy (policy-expr-string | string)
Treepolicy
String length1 to 255
Max. instances15
Min. instances1

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

initial-send-delay-zero boolean
Synopsis Send BGP updates as soon as the session comes up
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) initial-send-delay-zero boolean
Treeinitial-send-delay-zero

Description

When configured to true, BGP updates are sent as soon as the session comes up.

When unconfigured, the command inherits the value of the group-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, BGP waits to send UPDATE messages for the minimum route advertisement time after a session is established.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

keepalive number
Synopsis Time after which the BGP KEEPALIVE message is sent
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) keepalive number
Treekeepalive
Range0 to 21845
Introduced25.3.R2

Platforms

7705 SAR Gen 2

label-preference number
Synopsis Route preference for routes from labeled-unicast peers
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) label-preference number
Treelabel-preference
Range1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

link-bandwidth
Synopsis Enter the link-bandwidth context
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) link-bandwidth
Treelink-bandwidth
Introduced25.3.R2

Platforms

7705 SAR Gen 2

accept-from-ebgp
Synopsis Enable the accept-from-ebgp context
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) link-bandwidth accept-from-ebgp
Treeaccept-from-ebgp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

add-to-received-ebgp
Synopsis Enable the add-to-received-ebgp context
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) link-bandwidth add-to-received-ebgp
Treeadd-to-received-ebgp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

aggregate-used-paths
Synopsis Enable the aggregate-used-paths context
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) link-bandwidth aggregate-used-paths
Treeaggregate-used-paths
Introduced25.3.R2

Platforms

7705 SAR Gen 2

send-to-ebgp
Synopsis Enable the send-to-ebgp context
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) link-bandwidth send-to-ebgp
Treesend-to-ebgp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

local-address (ipv4-address-no-zone | ipv6-address-no-zone | interface-name)
Synopsis Local IP address used when communicating with BGP peers
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) local-address (ipv4-address-no-zone | ipv6-address-no-zone | interface-name)
Treelocal-address
String length1 to 32
Introduced25.3.R2

Platforms

7705 SAR Gen 2

local-as
Synopsis Enter the local-as context
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) local-as
Treelocal-as
Introduced25.3.R2

Platforms

7705 SAR Gen 2

as-number number
Synopsis Local (or virtual) BGP AS number
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) local-as as-number number
Treeas-number
Range1 to 4294967295
Introduced25.3.R2

Platforms

7705 SAR Gen 2

prepend-global-as boolean
Synopsis Prepend global ASN when advertising routes to BGP peer
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) local-as prepend-global-as boolean
Treeprepend-global-as

Description

When configured to true, the global ASN is added to the AS_PATH attribute in outbound routes sent to the peer.

When configured to false, the global ASN is not included in the AS_PATH attribute.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

private boolean
Synopsis Hide the local ASN in sent paths learned from peering
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) local-as private boolean
Treeprivate

Description

When configured to true, the local AS number is only advertised to peers that use the local ASN for establishing BGP peering sessions.

When configured to false, the local ASN is advertised to all peers, including those that can use the global ASN for establishing BGP peering sessions.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

local-preference number
Synopsis Default local preference if not in incoming routes
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) local-preference number
Treelocal-preference
Range0 to 4294967295
Introduced25.3.R2

Platforms

7705 SAR Gen 2

loop-detect keyword
Synopsis Strategy for loop detection in the AS path
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) loop-detect keyword
Treeloop-detect
Optionsdrop-peer, ignore-loop, off, discard-route
Introduced25.3.R2

Platforms

7705 SAR Gen 2

med-out (number | keyword)
Synopsis Default MED attribute value to advertise to peers
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) med-out (number | keyword)
Treemed-out
Max. range0 to 4294967295
Optionsigp-cost
Introduced25.3.R2

Platforms

7705 SAR Gen 2

multihop number
Synopsis TTL in IP packet headers for EBGP peers multi-hops away
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) multihop number
Treemultihop
Range1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

next-hop-self boolean
Synopsis Advertise routes with local address as next-hop address
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) next-hop-self boolean
Treenext-hop-self

Description

When configured to true, this command configures BGP to advertise routes to members of a group using a local address of the BGP instance as the BGP next-hop address.

Note that this command is set without exception, regardless of the route source (EBGP or IBGP) or its family. When used with VPN-IPv4 and VPN-IPv6 routes, the configure router bgp rr-vpn-forwarding command should also be configured.

When unconfigured, the command inherits the value of the group-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, protocol standard behavior is applied to determine whether to set next-hop-self in advertised routes.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

origin-validation
Synopsis Enable the origin-validation context
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) origin-validation
Treeorigin-validation

Description

Commands in this context configure the marking of every inbound IPv4, IPv6, and labeled IPv4 route from the BGP peer with one of the following origin validation states:

  • Valid (0)

  • Not-Found (1)

  • Invalid (2)

The configurations apply to all types of VPRN BGP peers, but generally should be applied only to EBGP peers and groups that contain only EBGP peers.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4 boolean
Synopsis Enable support for unlabeled unicast IPv4 routes
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) origin-validation ipv4 boolean
Treeipv4
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6 boolean
Synopsis Enable support for unlabeled unicast IPv6 routes
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) origin-validation ipv6 boolean
Treeipv6
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

passive boolean
Synopsis Use passive mode for BGP communication
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) passive boolean
Treepassive
Introduced25.3.R2

Platforms

7705 SAR Gen 2

path-mtu-discovery boolean
Synopsis Enable path MTU discovery
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) path-mtu-discovery boolean
Treepath-mtu-discovery

Description

When configured to true, Path MTU Discovery (PMTUD) is enabled for the associated TCP connections.

When set to true, PMTUD is activated toward an IPv4 BGP neighbor and the Don’t Fragment (DF) bit is set in the IP header of all IPv4 packets sent to the peer. If any device along the path toward the peer cannot forward the packet because the IP MTU of the interface is smaller than the IP packet size, this device drops the packet and sends an ICMP or ICMPv6 error message encoding the interface MTU. When the router receives the ICMP or ICMPv6 message, it lowers the TCP maximum segment size limit from the previous value so that the IP MTU constraint can be accommodated.

When PMTUD is configured to false and there is no TCP MSS configuration that can be associated with a BGP neighbor (in either the BGP configuration or the first hop IP interface configuration), the router advertises a value of only 1024 bytes as the TCP MSS option value, limiting received TCP segments to that size.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

peer-as number
Synopsis Peer AS number
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) peer-as number
Treepeer-as

Description

This command configures the autonomous system number for the peer. The peer AS number must be configured for each configured peer.

For EBGP peers, the peer AS number configured must be different from the autonomous system number configured for this router under the global level since the peer will be in a different autonomous system than this router.

For IBGP peers, the peer AS number must be the same as the autonomous system number of this router configured under the global level.

Range1 to 4294967295
Introduced25.3.R2

Platforms

7705 SAR Gen 2

peer-creation-type keyword
Synopsis Peer creation type
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) peer-creation-type keyword
Treepeer-creation-type
Optionsstatic, dynamic, dynamic-if-remote, dynamic-if-local
Defaultstatic
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

peer-ip-tracking boolean
Synopsis Enable BGP peer tracking
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) peer-ip-tracking boolean
Treepeer-ip-tracking

Description

When configured to true, this command enables BGP peer tracking.

Peer tracking should be used with caution. Peer tracking can tear a session down even if the loss of connectivity turns out to be short-lived (for example, while the IGP protocol is re-converging). Next-hop tracking, which is always enabled, handles temporary connectivity issues more effectively.

When unconfigured, the command inherits the value of the group-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, peer tracking is disabled.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

preference number
Synopsis Route preference for routes learned from all peers
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) preference number
Treepreference

Description

This command configures the route preference for routes learned from the configured peers.

The lower the preference value, the higher the chance of the route being the active route. The router assigns BGP routes the highest default preference as compared to routes that are direct, static or learned via MPLS or OSPF.

When unconfigured, the command setting is inherited from the group-level configuration.

Range1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

prefix-limit [family] keyword
Synopsis Enter the prefix-limit list instance
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) prefix-limit keyword
Treeprefix-limit
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[family] keyword
Synopsis Address family to which the limit applies
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) prefix-limit keyword
Treeprefix-limit
Optionsipv4, ipv6, mcast-ipv4, flow-ipv4, flow-ipv6, mcast-ipv6, label-ipv4

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

hold-excess number
Synopsis Percentage of maximum routes to install in route table
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) prefix-limit keyword hold-excess number
Treehold-excess

Description

This command specifies the percentage of maximum routes that are allowed to be installed in the route table for the configured address family. If a peer within scope of the configuration exceeds the limit, the overflow routes are held in the BGP RIB as inactive routes and are ineligible for forwarding and advertisement to other peers. If the post-import command is configured to true, only routes not rejected by import policies count toward the limit.

A BGP route in an overflow state is reconsidered for activation and reinstallation when an UPDATE message is received for the route.

This command is mutually exclusive with the idle-timeout and log-only commands.

Range1 to 100
Introduced25.3.R2

Platforms

7705 SAR Gen 2

idle-timeout number
Synopsis Time which BGP peering remains idle before reconnecting
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) prefix-limit keyword idle-timeout number
Treeidle-timeout

Description

This command defines the idle time after an administrative take-down before BGP re-establishes a session and reconnects to a peer.

When unconfigured, the command inherits the value from the group-level configuration.

Range1 to 1024
Introduced25.3.R2

Platforms

7705 SAR Gen 2

log-only boolean
Synopsis Send warning message at threshold instead of take-down
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) prefix-limit keyword log-only boolean
Treelog-only
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

maximum number
Synopsis Maximum number of routes to be learned from a peer
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) prefix-limit keyword maximum number
Treemaximum

Description

This command configures the maximum number of BGP routes than can be received from a peer before administrative action is taken.

Range1 to 4294967295

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

post-import boolean
Synopsis Apply limit only to routes accepted by import policies
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) prefix-limit keyword post-import boolean
Treepost-import
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

threshold number
Synopsis Percentage threshold that triggers a warning message
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) prefix-limit keyword threshold number
Treethreshold
Range1 to 100
Default90
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

remove-private
Synopsis Enable the remove-private context
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) remove-private
Treeremove-private
Introduced25.3.R2

Platforms

7705 SAR Gen 2

limited boolean
Synopsis Remove private ASNs up to first public ASN encountered
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) remove-private limited boolean
Treelimited
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

replace boolean
Synopsis Replace private ASN with global ASN before advertising
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) remove-private replace boolean
Treereplace
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

send-communities
Synopsis Enter the send-communities context
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) send-communities
Treesend-communities
Introduced25.3.R2

Platforms

7705 SAR Gen 2

extended boolean
Synopsis Advertise the Extended Communities attribute to peers
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) send-communities extended boolean
Treeextended

Description

When unconfigured, this command inherits the value of the group-level setting (true or false). The command cannot be explicitly configured to true.

When this command inherits a value of true, BGP extended communities are sent to peers in the Extended Communities attribute.

When configured to false, all extended communities are removed from all routes advertised to BGP peers.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

large boolean
Synopsis Advertise the Large Communities attribute to peers
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) send-communities large boolean
Treelarge

Description

When unconfigured, this command inherits the value of the group-level setting (true or false). The command cannot be explicitly configured to true.

When this command inherits a value of true, BGP large communities are sent to peers in the Large Communities attribute.

When configured to false, all large communities are removed from all routes advertised to BGP peers.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

standard boolean
Synopsis Advertise the Communities attribute to peers
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) send-communities standard boolean
Treestandard

Description

When unconfigured, this command inherits the value of the group-level setting (true or false). The command cannot be explicitly configured to true.

When this command inherits a value of true, BGP standard communities are sent to peers in the Communities attribute.

When configured to false, all standard communities are removed from all routes advertised to BGP peers.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

send-default
Synopsis Enable the send-default context
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) send-default
Treesend-default
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4 boolean
Synopsis Enable IPv4 family type
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) send-default ipv4 boolean
Treeipv4
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6 boolean
Synopsis Enable IPv6 family type
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) send-default ipv6 boolean
Treeipv6
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

split-horizon boolean
Synopsis Prevent routes being reflected back to best-route peer
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) split-horizon boolean
Treesplit-horizon

Description

When configured to true, this command enables the use of split-horizon.

This command prevents routes from being reflected back to a peer that sends the best route. It applies to routes of all address families and to any type of sending peer; confed-EBGP, EBGP and IBGP.

Enabling the split-horizon functionality may have a detrimental impact on peer and route scaling and should only be used when absolutely necessary.

When unconfigured, the command inherits the value of the group-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, the use of split-horizon is disabled.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

tcp-mss (number | keyword)
Synopsis TCP maximum segment size override
Context configure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) tcp-mss (number | keyword)
Treetcp-mss

Description

This command configures an override for the TCP maximum segment size to use with a specific peer or set of peers (depending on the scope of the command).

The configured value controls two properties of the TCP connection as follows:

TCP MSS option - The router advertises the TCP MSS option value in the TCP SYN packet it sends as part of the 3-way handshake. The advertised value may be lower than the configured value, depending on the IP MTU of the first hop IP interface. The peers must abide by this value when sending TCP segments to the local router.

TCP maximum segment size - The actual transmitted size may be lower than the configured value, depending on the TCP MSS option value signaled by the peers, the effect of path MTU discovery, or other factors.

Range384 to 9746
Optionsip-stack
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ttl-security number
Synopsis Minimum TTL value for an incoming BGP packet
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) ttl-security number
Treettl-security

Description

This command configures the minimum TTL value that BGP will accept from an incoming packet. A packet with a TTL value less than the minimum configured TTL value is discarded.

When unconfigured, the command inherits the value of the group-level setting.

Range1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

type keyword
Synopsis BGP peer type
Contextconfigure service vprn service-name bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) type keyword
Treetype
Optionsno-type, internal, external
Introduced25.3.R2

Platforms

7705 SAR Gen 2

next-hop-resolution
Synopsis Enter the next-hop-resolution context
Contextconfigure service vprn service-name bgp next-hop-resolution
Treenext-hop-resolution
Introduced25.3.R2

Platforms

7705 SAR Gen 2

use-bgp-routes boolean
Synopsis Use BGP routes to resolve BGP next hops
Contextconfigure service vprn service-name bgp next-hop-resolution use-bgp-routes boolean
Treeuse-bgp-routes

Description

When configured to true, BGP routes resolve BGP next hops. When this command is enabled, any unlabeled IPv4 or IPv6 BGP route received from a VPRN BGP peer becomes resolvable by up to four other BGP routes in order to resolve the route to a VPRN IP interface. A VPRN BGP route is not resolvable by another VPRN BGP route or by a BGP-VPN route.

This command also allows unlabeled IPv4 or IPv6 BGP routes leaked from the GRT with unresolved next hops (in the GRT) to be resolvable by BGP-VPN routes (of the VPRN).

When configured to false, BGP next hops are not resolved.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

use-leaked-routes
Synopsis Enter the use-leaked-routes context
Contextconfigure service vprn service-name bgp next-hop-resolution use-leaked-routes
Treeuse-leaked-routes
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static boolean
Synopsis Use leaked static routes to resolve BGP next hop
Contextconfigure service vprn service-name bgp next-hop-resolution use-leaked-routes static boolean
Treestatic

Description

When configured to true, the router allows any non-leaked unlabeled unicast IPv4 or IPv6 route in the BGP RIB to be resolved by a leaked static route with direct next hops. A BGP route resolved this way cannot resolve other routes (including BGP routes) and cannot be redistributed into non-BGP protocols, such as IGP.

When configured to false, the router prevents the use of leaked static routes to resolve BGP routes.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

path-mtu-discovery boolean
Synopsis Enable Path MTU Discovery
Context configure service vprn service-name bgp path-mtu-discovery boolean
Treepath-mtu-discovery

Description

When configured to true, Path MTU Discovery (PMTUD) is activated toward an IPv4 BGP neighbor. The Don't Fragment (DF) bit is set in the IP header of all IPv4 packets sent to the peer. If any device along the path toward the peer cannot forward the packet because the IP MTU of the interface is smaller than the IP packet size, the device drops the packet and sends an ICMP or ICMPv6 error message encoding the interface MTU. When the router receives the ICMP or ICMPv6 message, it lowers the TCP maximum segment size limit from the previous value to accomodate the IP MTU constraint.

When configured to false, PMTUD is disabled and there is no TCP MSS configuration to associate with a BGP neighbor (in either the BGP configuration or the first-hop IP interface configuration). The router advertises a TCP MSS option of only 1024 bytes, limiting the received TCP segments to that size.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

peer-tracking-policy reference
Synopsis Policy for BGP peer tracking on router instance
Contextconfigure service vprn service-name bgp peer-tracking-policy reference
Treepeer-tracking-policy

Description

This command specifies the name of a policy statement to use with the BGP peer-tracking function on BGP sessions where peer tracking is enabled.

When unconfigured, the default peer-tracking policy allows any type of route to match the neighbor IP address except aggregate routes and LDP shortcut routes.

Peer tracking should be used with caution. The peer-tracking policy should only permit one of direct-interface or direct routes to be advertised to a BGP peer. Advertising both routes causes the best route to oscillate.

Reference

configure policy-options policy-statement named-item-64

Introduced25.3.R2

Platforms

7705 SAR Gen 2

preference number
Synopsis Route preference for routes learned from all peers
Contextconfigure service vprn service-name bgp preference number
Treepreference

Description

This command configures the route preference for routes learned from the configured peers.

The lower the preference value, the higher the chance of the route being the active route. The router assigns BGP routes the highest default preference as compared to routes that are direct, static or learned via MPLS or OSPF.

Range1 to 255
Default170
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

rapid-withdrawal boolean
Synopsis Send BGP withdrawal UPDATE messages immediately
Contextconfigure service vprn service-name bgp rapid-withdrawal boolean
Treerapid-withdrawal

Description

When configured to true, UPDATE messages containing withdrawn NLRI are sent immediately to a peer without waiting for the MRAI timer to expire. UPDATE messages containing reachable NLRI continue to wait for the MRAI timer to expire, or for a rapid update trigger.

When configured to false, withdrawal processing continues with the normal behavior.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

remove-private
Synopsis Enable the remove-private context
Contextconfigure service vprn service-name bgp remove-private
Treeremove-private
Introduced25.3.R2

Platforms

7705 SAR Gen 2

limited boolean
Synopsis Remove private ASNs up to first public ASN encountered
Contextconfigure service vprn service-name bgp remove-private limited boolean
Treelimited
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

replace boolean
Synopsis Replace private ASN with global ASN before advertising
Contextconfigure service vprn service-name bgp remove-private replace boolean
Treereplace
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

rib-management
Synopsis Enter the rib-management context
Contextconfigure service vprn service-name bgp rib-management
Treerib-management
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4
Synopsis Enter the ipv4 context
Context configure service vprn service-name bgp rib-management ipv4
Treeipv4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

leak-import
Synopsis Enter the leak-import context
Context configure service vprn service-name bgp rib-management ipv4 leak-import
Treeleak-import
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy (policy-expr-string | string)
Synopsis Leak import policy name
Context configure service vprn service-name bgp rib-management ipv4 leak-import policy (policy-expr-string | string)
Treepolicy

Description

This command specifies one or more leak import policies.

Policy names are limited to 64 characters except for the first policy. Only one object can be a policy logical expression consisting of policy names (enclosed in square brackets) and logical operators (AND, OR, NOT).

String length1 to 255
Max. instances15

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-table-import
Synopsis Enter the route-table-import context
Contextconfigure service vprn service-name bgp rib-management ipv4 route-table-import
Treeroute-table-import
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy-name reference
Synopsis Name of policy that controls route importation into RIB
Contextconfigure service vprn service-name bgp rib-management ipv4 route-table-import policy-name reference
Treepolicy-name

Description

This command specifies the name of a policy that controls the importation of active routes from the IP route table into one of the BGP RIBs.

When this command is configured, routes dropped or rejected by the policy are not installed in the associated RIB. Rejected routes cannot be advertised to BGP peers associated with the RIB, but they can still be used to resolve BGP next hops of routes in that RIB. If the active route for a prefix is rejected by the policy, the best BGP route for that prefix in the BGP RIB can be advertised to peers as though it is used.

Aggregate routes are always imported into each RIB, independent of the specified policy.

Route modifications specified in the actions of the policy are ignored and have no effect on the imported routes.

When unconfigured, or if the command refers to an empty policy, all non-BGP routes from the IP route table are imported into the applicable RIB.

Reference

configure policy-options policy-statement named-item-64

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6
Synopsis Enter the ipv6 context
Context configure service vprn service-name bgp rib-management ipv6
Treeipv6
Introduced25.3.R2

Platforms

7705 SAR Gen 2

leak-import
Synopsis Enter the leak-import context
Context configure service vprn service-name bgp rib-management ipv6 leak-import
Treeleak-import
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy (policy-expr-string | string)
Synopsis Leak import policy name
Context configure service vprn service-name bgp rib-management ipv6 leak-import policy (policy-expr-string | string)
Treepolicy

Description

This command specifies one or more leak import policies.

Policy names are limited to 64 characters except for the first policy. Only one object can be a policy logical expression consisting of policy names (enclosed in square brackets) and logical operators (AND, OR, NOT).

String length1 to 255
Max. instances15

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-table-import
Synopsis Enter the route-table-import context
Contextconfigure service vprn service-name bgp rib-management ipv6 route-table-import
Treeroute-table-import
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy-name reference
Synopsis Name of policy that controls route importation into RIB
Contextconfigure service vprn service-name bgp rib-management ipv6 route-table-import policy-name reference
Treepolicy-name

Description

This command specifies the name of a policy that controls the importation of active routes from the IP route table into one of the BGP RIBs.

When this command is configured, routes dropped or rejected by the policy are not installed in the associated RIB. Rejected routes cannot be advertised to BGP peers associated with the RIB, but they can still be used to resolve BGP next hops of routes in that RIB. If the active route for a prefix is rejected by the policy, the best BGP route for that prefix in the BGP RIB can be advertised to peers as though it is used.

Aggregate routes are always imported into each RIB, independent of the specified policy.

Route modifications specified in the actions of the policy are ignored and have no effect on the imported routes.

When unconfigured, or if the command refers to an empty policy, all non-BGP routes from the IP route table are imported into the applicable RIB.

Reference

configure policy-options policy-statement named-item-64

Introduced25.3.R2

Platforms

7705 SAR Gen 2

label-ipv4
Synopsis Enter the label-ipv4 context
Context configure service vprn service-name bgp rib-management label-ipv4
Treelabel-ipv4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

leak-import
Synopsis Enter the leak-import context
Context configure service vprn service-name bgp rib-management label-ipv4 leak-import
Treeleak-import
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy (policy-expr-string | string)
Synopsis Leak import policy name
Context configure service vprn service-name bgp rib-management label-ipv4 leak-import policy (policy-expr-string | string)
Treepolicy

Description

This command specifies one or more leak import policies.

Policy names are limited to 64 characters except for the first policy. Only one object can be a policy logical expression consisting of policy names (enclosed in square brackets) and logical operators (AND, OR, NOT).

String length1 to 255
Max. instances15

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-table-import
Synopsis Enter the route-table-import context
Contextconfigure service vprn service-name bgp rib-management label-ipv4 route-table-import
Treeroute-table-import
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy-name reference
Synopsis Name of policy that controls route importation into RIB
Contextconfigure service vprn service-name bgp rib-management label-ipv4 route-table-import policy-name reference
Treepolicy-name

Description

This command specifies the name of a policy that controls the importation of active routes from the IP route table into one of the BGP RIBs.

When this command is configured, routes dropped or rejected by the policy are not installed in the associated RIB. Rejected routes cannot be advertised to BGP peers associated with the RIB, but they can still be used to resolve BGP next hops of routes in that RIB. If the active route for a prefix is rejected by the policy, the best BGP route for that prefix in the BGP RIB can be advertised to peers as though it is used.

Aggregate routes are always imported into each RIB, independent of the specified policy.

Route modifications specified in the actions of the policy are ignored and have no effect on the imported routes.

When unconfigured, or if the command refers to an empty policy, all non-BGP routes from the IP route table are imported into the applicable RIB.

Reference

configure policy-options policy-statement named-item-64

Introduced25.3.R2

Platforms

7705 SAR Gen 2

label-ipv6
Synopsis Enter the label-ipv6 context
Context configure service vprn service-name bgp rib-management label-ipv6
Treelabel-ipv6
Introduced25.3.R2

Platforms

7705 SAR Gen 2

leak-import
Synopsis Enter the leak-import context
Context configure service vprn service-name bgp rib-management label-ipv6 leak-import
Treeleak-import
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy (policy-expr-string | string)
Synopsis Leak import policy name
Context configure service vprn service-name bgp rib-management label-ipv6 leak-import policy (policy-expr-string | string)
Treepolicy

Description

This command specifies one or more leak import policies.

Policy names are limited to 64 characters except for the first policy. Only one object can be a policy logical expression consisting of policy names (enclosed in square brackets) and logical operators (AND, OR, NOT).

String length1 to 255
Max. instances15

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

router-id ipv4-address
Synopsis Router ID for the BGP instance in the AS
Contextconfigure service vprn service-name bgp router-id ipv4-address
Treerouter-id

Description

This command specifies the router ID to be used with the BGP instance.

Changing the BGP router ID on an active BGP instance causes the BGP instance to restart with the new router ID.

When an SR OS is configured with an IPv6-only BOF and no IPv4 system interface address, explicitly-defined IPv4 router IDs are required for BGP as there is no mechanism to derive the router ID from an IPv6 system interface address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

send-communities
Synopsis Enter the send-communities context
Contextconfigure service vprn service-name bgp send-communities
Treesend-communities
Introduced25.3.R2

Platforms

7705 SAR Gen 2

large boolean
Synopsis Advertise the Large Communities attribute to peers
Contextconfigure service vprn service-name bgp send-communities large boolean
Treelarge
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

send-default
Synopsis Enter the send-default context
Contextconfigure service vprn service-name bgp send-default
Treesend-default
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4 boolean
Synopsis Enable IPv4 family type
Context configure service vprn service-name bgp send-default ipv4 boolean
Treeipv4
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6 boolean
Synopsis Enable IPv6 family type
Context configure service vprn service-name bgp send-default ipv6 boolean
Treeipv6
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

split-horizon boolean
Synopsis Prevent routes being reflected back to best-route peer
Contextconfigure service vprn service-name bgp split-horizon boolean
Treesplit-horizon

Description

When configured to true, this command enables the use of split-horizon.

This command prevents routes from being reflected back to a peer that sends the best route. It applies to routes of all address families and to any type of sending peer; confed-EBGP, EBGP and IBGP.

Enabling the split-horizon functionality may have a detrimental impact on peer and route scaling and should only be used when absolutely necessary.

When configured to false, the use of split-horizon is disabled.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

tcp-mss number
Synopsis TCP maximum segment size override
Context configure service vprn service-name bgp tcp-mss number
Treetcp-mss

Description

This command configures an override for the TCP maximum segment size to use with a specific peer or set of peers (depending on the scope of the command).

The configured value controls two properties of the TCP connection as follows:

TCP MSS option - The router advertises the TCP MSS option value in the TCP SYN packet it sends as part of the 3-way handshake. The advertised value may be lower than the configured value, depending on the IP MTU of the first hop IP interface. The peers must abide by this value when sending TCP segments to the local router.

TCP maximum segment size - The actual transmitted size may be lower than the configured value, depending on the TCP MSS option value signaled by the peers, the effect of path MTU discovery, or other factors.

Range384 to 9746
Introduced25.3.R2

Platforms

7705 SAR Gen 2

third-party-nexthop boolean
Synopsis Apply third-party next-hop processing to EBGP peers
Contextconfigure service vprn service-name bgp third-party-nexthop boolean
Treethird-party-nexthop

Description

When configured to true, this command enables the router to send third-party next hop to EBGP peers in the same subnet as the source peer. The address family of the transport must match the address family of the route.

When an IPv4 or IPv6 route is received from one EBGP peer and advertised to another EBGP peer in the same IP subnet, the BGP next hop is left unchanged.

When configured to false, third-party next-hop processing is disabled and the next hop carries the IP address of the interface used to establish the TCP connection to the peer.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp-evpn
Synopsis Enter the bgp-evpn context
Context configure service vprn service-name bgp-evpn
Treebgp-evpn
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mpls [bgp-instance] number
Synopsis Enter the mpls list instance
Context configure service vprn service-name bgp-evpn mpls number
Treempls
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[bgp-instance] number
Synopsis BGP instance ID
Context configure service vprn service-name bgp-evpn mpls number
Treempls
Range1

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of BGP-EVPN MPLS
Contextconfigure service vprn service-name bgp-evpn mpls number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

auto-bind-tunnel
Synopsis Enter the auto-bind-tunnel context
Contextconfigure service vprn service-name bgp-evpn mpls number auto-bind-tunnel
Treeauto-bind-tunnel

Description

Commands in this context configure the automatic binding options of a BGP-EVPN service using tunnels to MP-BGP peers.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

allow-flex-algo-fallback boolean
Synopsis Enable flexible algorithm fallback
Context configure service vprn service-name bgp-evpn mpls number auto-bind-tunnel allow-flex-algo-fallback boolean
Treeallow-flex-algo-fallback

Description

When configured to true, a BGP router with a Flex-Algorithm action configured (via the configure policy-options policy-statement entry action flex-algo command) can resolve to a tunnel with algorithm 0 if no target Flex-Algorithm tunnel is available.

When configured to false, the BGP router can resolve only to the intended Flex-Algorithm tunnel, which may cause traffic loss if no corresponding Flex-Algorithm tunnel is available.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ecmp number
Synopsis Maximum ECMP routes allowed
Context configure service vprn service-name bgp-evpn mpls number auto-bind-tunnel ecmp number
Treeecmp

Description

This command configures the maximum number of tunnels that can be used as ECMP next hops for the VPRN. This value overrides the ECMP value configured at the configure service vprn context level.

Range1 to 32
Default1
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

enforce-untagged-route keyword
Synopsis Untagged route type enforcement
Context configure service vprn service-name bgp-evpn mpls number auto-bind-tunnel enforce-untagged-route keyword
Treeenforce-untagged-route

Description

This command configures the enforcement of BGP routes with no administrative tag policy applied by modifying the next-hop resolution behavior for autobind services.

If the untagged-tunnel option is configured, untagged routes only bind to LSPs with no administrative tag configured. If both tagged and untagged tunnels to the next hop exist, the system only considers the untagged tunnels. If no untagged tunnels to the next hop exist, the resolution of untagged routes fails.

The untagged-tunnel option can be used in combination with the enforce-strict-tunnel-tagging command configured to true, in which case tagged routes resolve to tagged LSPs, and untagged routes only resolve to untagged LSPs.

When unconfigured, untagged routes can bind to tagged or untagged LSPs.

Options

none – Untagged routes can bind to tagged or untagged LSPs

untagged-tunnel – Untagged routes only bind to LSPs without an admin tag

Defaultnone
Introduced25.3.R2

Platforms

7705 SAR Gen 2

resolution-filter
Synopsis Enter the resolution-filter context
Contextconfigure service vprn service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter
Treeresolution-filter

Description

Commands in this context configure the subset of tunnel types that can be used in the resolution of BGP-EVPN routes within the automatic binding of the BGP-EVPN MPLS service to tunnels to MP-BGP peers.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp boolean
Synopsis Use BGP tunneling for next-hop resolution
Contextconfigure service vprn service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter bgp boolean
Treebgp

Description

When configured to true, BGP searches the BGP LSP for the address of the BGP next hop.

When configured to false, BGP tunneling is not used and inter-area or inter-as prefixes are not resolved.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ldp boolean
Synopsis Use LDP tunneling for next-hop resolution
Contextconfigure service vprn service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter ldp boolean
Treeldp

Description

When configured to true, BGP searches for an LDP LSP with a FEC prefix corresponding to the address of the BGP next hop.

When configured to false, LDP tunneling is not used for next-hop resolution.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

rsvp boolean
Synopsis Use RSVP tunneling for next-hop resolution
Contextconfigure service vprn service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter rsvp boolean
Treersvp

Description

When configured to true, BGP searches the best metric RSVP LSP to determine the address of the BGP next hop. This address can correspond to the system interface or to another loopback interface used by the BGP instance on the remote node. The LSP metric is provided by MPLS in the tunnel table. In the case of multiple RSVP LSPs with the same lowest metric, BGP selects the LSP with the lowest tunnel ID.

When configured to false, the RSVP LSP is not used for next-hop resolution.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sr-isis boolean
Synopsis Use IS-IS SR tunneling for next-hop resolution
Contextconfigure service vprn service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-isis boolean
Treesr-isis

Description

When configured to true, BGP uses an IS-IS tunnel type to resolve the BGP next hop.

When the sr-isis command is enabled, an SR tunnel to the BGP next hop is selected in the TTM according to the following procedure.

  • Select the SR tunnel submitted by the IS-IS instance with the lowest tunnel table preference.

  • If more than one SR tunnel exists, select the SR tunnel from the instance with the lowest metric.

  • If more than one SR tunnel exists, select the SR tunnel from the instance with the lowest instance ID.

When configured to false, IS-IS tunneling is not used for next-hop resolution.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sr-ospf boolean
Synopsis Use OSPF SR tunneling for next-hop resolution
Contextconfigure service vprn service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-ospf boolean
Treesr-ospf

Description

When configured to true, BGP uses an OSPF tunnel type to resolve the BGP next hop.

When enabled, an SR tunnel to the BGP next hop is selected in the TTM according to the following procedure.

  • Select the SR tunnel submitted by the OSPF instance with the lowest tunnel table preference.

  • If more than one SR tunnel exists, select the SR tunnel from the instance with the lowest metric.

  • If more than one SR tunnel exists, select the SR tunnel from the instance with the lowest instance ID.

When configured to false, OSPF tunneling is not used for next-hop resolution.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sr-ospf3 boolean
Synopsis Use OSPFv3 SR tunneling for next-hop resolution
Contextconfigure service vprn service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-ospf3 boolean
Treesr-ospf3

Description

When configured to true, BGP uses an OSPF3 tunnel type to resolve the BGP next hop.

When enabled, an SR tunnel to the BGP next hop is selected in the TTM according to the following procedure.

  • Select the SR tunnel submitted by the OSPFv3 instance with the lowest tunnel table preference.

  • If more than one SR tunnel exists, select the SR tunnel from the instance with the lowest metric.

  • If more than one SR tunnel exists, select the SR tunnel from the instance with the lowest instance ID.

When configured to false, OSPF3 tunneling is not used for next-hop resolution.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sr-policy boolean
Synopsis Use SR policies for next-hop resolution
Contextconfigure service vprn service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-policy boolean
Treesr-policy

Description

When configured to true, this command enables the use of SR policies to resolve the next hop of BGP-EVPN service routes.

This command configures BGP to search for an SR policy with:

  • a non-null endpoint that matches the next hop of the service route, and

  • a color value that matches the highest numbered color for the extended community attached to the service route

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sr-te boolean
Synopsis Use SR-TE tunneling for next-hop resolution
Contextconfigure service vprn service-name bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-te boolean
Treesr-te

Description

When configured to true, BGP uses an SR-TE tunnel type to resolve the BGP next hop.

In the case of multiple SR-TE tunnels with the same lowest metric, BGP selects the tunnel with the lowest tunnel ID.

When configured to false, SR-TE tunneling is not used for next-hop resolution.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

default-route-tag one-byte-value
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDefault route tag
Contextconfigure service vprn service-name bgp-evpn mpls number default-route-tag one-byte-value
Treedefault-route-tag

Description

This command configures a route tag that is used when sending a route to the BGP application (for the corresponding service and BGP instance). If the corresponding BGP instance is enabled, the command cannot be changed.

When used for BGP EVPN contexts, only one route tag can be passed to BGP for matching on export policies. In case of a conflict with other route tags pushed by EVPN, the default route tag has the least priority.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

domain-id domain-id
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDomain ID of received BGP route before readvertisement
Contextconfigure service vprn service-name bgp-evpn mpls number domain-id domain-id
Treedomain-id

Description

This command specifies the D-PATH domain ID. The domain ID identifies the network from which the BGP route was received before the RTM advertises it to a different neighbor. The domain ID is part of a domain, represented as domain-id:isf_safi_type in the D-PATH attribute, as described in draft-ietf-bess-evpn-ipvpn-interworking. Gateway routers modify the D-PATH attribute. A gateway is a PE where a VPRN is instantiated. The VPRN in this case advertises or receives routes from multiple BGP owners (for example, EVPN-IFL and BGP-IPVPN) or multiple instances of the same owner (for example, VPRN with two BGP-IPVPN instances).

Gateways use the D-PATH attribute to detect loops (for received routes where the D-PATH contains a local domain ID) and to make BGP best-path selection decisions based on the D-PATH length (shorter D-PATH is preferred).

In the following example, suppose a gateway receives prefix P in an EVPN-IFL instance with the following D-PATH from neighbor N:

Seg Len=1 / 65000:1:128

If the router imports the route in VPRN-1, BGP-EVPN SRv6 instance with domain 65000:2, it readvertises it to its BGP-IPVPN MPLS instance as follows:

Seg Len=2 / 65000:2:70 / 65000:1:128

That is, the gateway prepends the local domain ID and family to the D-PATH before readvertising the route into a different instance.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

dynamic-egress-label-limit boolean
Synopsis Enables dynamic egress label limit
Context configure service vprn service-name bgp-evpn mpls number dynamic-egress-label-limit boolean
Treedynamic-egress-label-limit

Description

When configured to true, this command relaxes the egress MPLS label limit check when resolving BGP next hops in the tunnel table.

For VPRN services, the OAM label is never computed and, therefore, one more egress label is allowed.

For EVPN (Epipe and VPLS) services, the system only computes the control word and ESI label if they are used. For the control word, the system reduces the egress label limit by one label if the control word is configured in the service. When configured, the ESI label is not counted for Epipes or VPLS services without an ES.

When configured to false this command, for EVPN, Epipe, and VPLS services, always accounts for the ESI label and control word.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

evi number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEVPN instance ID
Contextconfigure service vprn service-name bgp-evpn mpls number evi number
Treeevi

Description

This command configures the EVI that identifies the BGP EVPN instance in a VPRN (for the EVPN-IFL model) that is associated with the Layer 3 Ethernet segment. This configuration is required on the PEs attached to the Ethernet segment and on the remote PEs that need to create ES destinations to the MH Layer 3 Ethernet segment.

Range1 to 16777215
Introduced25.3.R2

Platforms

7705 SAR Gen 2

evpn-link-bandwidth
Synopsis Enter the evpn-link-bandwidth context
Contextconfigure service vprn service-name bgp-evpn mpls number evpn-link-bandwidth
Treeevpn-link-bandwidth
Introduced25.3.R2

Platforms

7705 SAR Gen 2

advertise
Synopsis Enable the advertise context
Context configure service vprn service-name bgp-evpn mpls number evpn-link-bandwidth advertise
Treeadvertise
Introduced25.3.R2

Platforms

7705 SAR Gen 2

max-dynamic-weight number
Synopsis Maximum dynamic weight of the route
Context configure service vprn service-name bgp-evpn mpls number evpn-link-bandwidth advertise max-dynamic-weight number
Treemax-dynamic-weight

Description

This command configures the maximum weight advertised in the EVPN link bandwidth extended community for the advertised EVPN IP-Prefix routes for the service. If weight dynamic is configured, the actual advertised weight is the minimum of the number of BGP PE-CE paths for the prefix and the configured maximum weight.

Range1 to 128
Default128
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

weight (number | keyword)
Synopsis Weight of the route
Context configure service vprn service-name bgp-evpn mpls number evpn-link-bandwidth advertise weight (number | keyword)
Treeweight

Description

This command configures the weight advertised in the EVPN link bandwidth extended community for the advertised EVPN IP-Prefix routes for the service.

If set to dynamic, the weight is dynamically set based on the number of BGP PE-CE paths for the IP-Prefix that is advertised in an EVPN IP-Prefix route.

Range1 to 128
Optionsdynamic
Defaultdynamic
Introduced25.3.R2

Platforms

7705 SAR Gen 2

weighted-ecmp boolean
Synopsis Enable weighted ECMP
Context configure service vprn service-name bgp-evpn mpls number evpn-link-bandwidth weighted-ecmp boolean
Treeweighted-ecmp

Description

When configured to true, the router supports the processing of the EVPN link bandwidth extended community when installing an ECMP set for an EVPN IP-Prefix route in the VPRN route table.

Flows to an IP Prefix received with a weight and a zero ESI value are sprayed according to the weight. If the EVPN IP-Prefix route received with the weight has a non-zero ESI, the weight is divided into the number of PEs attached to the Ethernet Segment (and rounded up if the result is not an integer).

The command also enables the weighted ECMP functionality for BGP CEs that are configured with an evpn-link-bandwidth add-to-received-bgp weight.

When configured to false, the router disables the processing of the EVPN link bandwidth extended community.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-distinguisher (string | keyword)
Synopsis Route distinguisher
Context configure service vprn service-name bgp-evpn mpls number route-distinguisher (string | keyword)
Treeroute-distinguisher

Description

This command specifies a unique route distinguisher (RD) to be associated with each routing instance to identify which VPN the route belongs to.

Optionsauto-rd
Introduced25.3.R2

Platforms

7705 SAR Gen 2

send-tunnel-encap
Synopsis Enter the send-tunnel-encap context
Contextconfigure service vprn service-name bgp-evpn mpls number send-tunnel-encap
Treesend-tunnel-encap
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mpls boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable MPLS encapsulation
Contextconfigure service vprn service-name bgp-evpn mpls number send-tunnel-encap mpls boolean
Treempls
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vrf-export
Synopsis Enable the vrf-export context
Context configure service vprn service-name bgp-evpn mpls number vrf-export
Treevrf-export

Description

Commands in this context specify route policies that control how routes are exported from the local VRF to other VRFs on the same or remote PE routers (via MP-BGP).

Aggregate routes are not advertised via MP-BGP protocols to other MP-BGP peers.

Route policies are configured in the configure policy-options context.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy (policy-expr-string | string)
Synopsis Policy name
Contextconfigure service vprn service-name bgp-evpn mpls number vrf-export policy (policy-expr-string | string)
Treepolicy

Description

This command configures VRF route policies that control routes between local VRFs and other VRFs on the same or remote PE routers (using MP-BGP).

Each referenced object is either a policy logical expression or the name of a single policy.

Only one referenced object can be a policy logical expression consisting of policy names (enclosed in square brackets) and logical operators (AND, OR, NOT). The objects are evaluated in the specified order to determine whether to accept or reject the route.

Only the first policy can have the maximum length and the rest can be up to 64 characters.

Aggregate routes are not advertised using MP-BGP protocols to the other MP-BGP peers.

String length1 to 255
Max. instances15
Min. instances1

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

vrf-import
Synopsis Enable the vrf-import context
Context configure service vprn service-name bgp-evpn mpls number vrf-import
Treevrf-import

Description

Commands in this context specify route policies that control how VPN-IP and EVPN-IFL routes that are exported by other VRFs on the same or remote PEs, are imported into the local VRF.

Route policies are configured in the configure policy-options context.

Unless the preference value is changed by the policy, the preference value for BGP-VPN and EVPN-IFL routes specified in this context is set to 170 when imported from remote PE routers, or the value is retained from the protocol preference value of the exported route when imported from other VRFs on the same router.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy (policy-expr-string | string)
Synopsis Policy name
Contextconfigure service vprn service-name bgp-evpn mpls number vrf-import policy (policy-expr-string | string)
Treepolicy

Description

This command configures VRF route policies that control routes between local VRFs and other VRFs on the same or remote PE routers (using MP-BGP).

Each referenced object is either a policy logical expression or the name of a single policy.

Only one referenced object can be a policy logical expression consisting of policy names (enclosed in square brackets) and logical operators (AND, OR, NOT). The objects are evaluated in the specified order to determine whether to accept or reject the route.

Only the first policy can have the maximum length and the rest can be up to 64 characters.

Aggregate routes are not advertised using MP-BGP protocols to the other MP-BGP peers.

String length1 to 255
Max. instances15
Min. instances1

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

vrf-target
Synopsis Enter the vrf-target context
Context configure service vprn service-name bgp-evpn mpls number vrf-target
Treevrf-target

Description

Commands in this context configure the route target that is added to advertised routes or compared against received routes from other VRFs on the same or remote PE routers (via MP-BGP).

BGP-VPN and EVPN-IFL routes imported using a VRF target configuration use the BGP preference value of 170 when imported from remote PE routers, or retain the protocol preference value of the exported route when imported from other VRFs in the same router.

Configured VRF import or export policies override the VRF target policy.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

community route-target
Synopsis Extended BGP community
Context configure service vprn service-name bgp-evpn mpls number vrf-target community route-target
Treecommunity

Description

This command configures an extended BGP community in the form type:x:y. Type can only be target and x and y are 16-bit integers.

String length10 to 28

Notes

The following elements are part of a choice: community or (export-community and import-community).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

export-community route-target
Synopsis Communities sent to remote PE neighbors
Contextconfigure service vprn service-name bgp-evpn mpls number vrf-target export-community route-target
Treeexport-community
String length10 to 28

Notes

The following elements are part of a choice: community or (export-community and import-community).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

import-community route-target
Synopsis Communities accepted from remote PE neighbors
Contextconfigure service vprn service-name bgp-evpn mpls number vrf-target import-community route-target
Treeimport-community
String length10 to 28

Notes

The following elements are part of a choice: community or (export-community and import-community).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp-ipvpn
Synopsis Enter the bgp-ipvpn context
Context configure service vprn service-name bgp-ipvpn
Treebgp-ipvpn
Introduced25.3.R2

Platforms

7705 SAR Gen 2

attribute-set
Synopsis Enter the attribute-set context
Contextconfigure service vprn service-name bgp-ipvpn attribute-set
Treeattribute-set

Description

Commands in this context configure the handling of attribute set (ATTR_SET) attributes attached to VPN-IP routes imported into or exported from the VPRN.

ATTR_SET is an optional transitive BGP path attribute standardized by RFC 6368 that is added to BGP L3 VPN routes to provide logical separation between the BGP domain of a customer and the BGP domain of a service provider.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

export boolean
Synopsis Add ATTR_SET path attribute to exported VPN-IP routes
Contextconfigure service vprn service-name bgp-ipvpn attribute-set export boolean
Treeexport

Description

When configured to true, the router adds an ATTR_SET path attribute to all VPN-IP routes that come from the VRF export of BGP routes advertised by PE-CE peers of the VPRN. This attribute contains an exact copy of all BGP path attributes (post-import policy) of the PE-CE BGP route, excluding the NEXT_HOP, MP_REACH, and MP_UNREACH attributes, as well as the AS4_PATH or AS4_AGGREGATOR attributes. The origin AS in the ATTR_SET encodes the ASN (or confederation ID, if configured) of the exporting VPRN service. Neither the VRF export policy nor a regular BGP export policy is allowed to modify the contents of the ATTR_SET.

When configured to false, the router does not add an ATTR_SET path attribute to VPN-IP routes exported by the VPRN. Nokia recommends configuring this command to false, unless there is a requirement for the VPRN to deliver an independent domain L3 VPN service.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

import keyword
Synopsis Reception behavior of ATTR_SET
Context configure service vprn service-name bgp-ipvpn attribute-set import keyword
Treeimport

Description

This command configures the reception behavior for ATTR_SETs in received VPN-IP routes.

  • accept — BGP accepts and processes ATTR_SETs in received unicast VPN-IP routes (MPLS or SRv6) when they are imported into the VPRN. The path attributes contained inside the ATTR_SET are used for best path selection within the VPRN, instead of the outer path attributes attached to the imported VPN-IP route. The path attributes inside the ATTR_SET determine the path attributes of BGP routes advertised to PE-CE peers of the VPRN. However, the ATTR_SET is removed at the time of advertisement. VPRN BGP routes with attributes derived from accept processing can only be advertised to EBGP peers and IBGP route reflector client peers. VPRN BGP routes cannot be advertised to BGP confederation peers. If the origin AS in the ATTR_SET attribute does not match the configured ASN, VPRN BGP routes with attributes derived from accept processing are advertised to IBGP peers that are not covered by a cluster configuration.

  • drop — BGP ignores and silently discards ATTR_SETs in received VPN-IP routes when they are imported into the VPRN. The path attributes contained inside the ATTR_SET are not used for best path selection within the VPRN. If a VPRN is not involved in an independent domain L3 VPN service, Nokia recommends configuring this command to use the drop option.

  • ignore — BGP ignores ATTR_SETs in received VPN-IP routes when they are imported into the VPRN. The path attributes contained inside the ATTR_SET are not used for best path selection within the VPRN. With the ignore option, the ATTR_SET attribute is transmitted unchanged to the CE. Nokia recommends not to configure this command to use the ignore option in most deployments.

Optionsignore, accept, drop
Defaultignore
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mpls
Synopsis Enter the mpls context
Context configure service vprn service-name bgp-ipvpn mpls
Treempls
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of BGP-IPVPN MPLS
Contextconfigure service vprn service-name bgp-ipvpn mpls admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

auto-bind-tunnel
Synopsis Enter the auto-bind-tunnel context
Contextconfigure service vprn service-name bgp-ipvpn mpls auto-bind-tunnel
Treeauto-bind-tunnel

Description

Commands in this context configure the automatic-binding options of a BGP-IPVPN service using tunnels to MP-BGP peers.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

allow-flex-algo-fallback boolean
Synopsis Enable flexible algorithm fallback
Context configure service vprn service-name bgp-ipvpn mpls auto-bind-tunnel allow-flex-algo-fallback boolean
Treeallow-flex-algo-fallback

Description

When configured to true, a BGP router with a Flex-Algorithm action configured (via the configure policy-options policy-statement entry action flex-algo command) can resolve to a tunnel with algorithm 0 if no target Flex-Algorithm tunnel is available.

When configured to false, the BGP router can resolve only to the intended Flex-Algorithm tunnel, which may cause traffic loss if no corresponding Flex-Algorithm tunnel is available.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ecmp number
Synopsis Maximum ECMP routes allowed
Context configure service vprn service-name bgp-ipvpn mpls auto-bind-tunnel ecmp number
Treeecmp

Description

This command configures the maximum number of tunnels that can be used as ECMP next hops for the VPRN. This value overrides the ECMP value configured at the configure service vprn context level.

Range1 to 32
Default1
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

enforce-strict-tunnel-tagging boolean
Synopsis Allow enforcement of strict tunnel tagging
Contextconfigure service vprn service-name bgp-ipvpn mpls auto-bind-tunnel enforce-strict-tunnel-tagging boolean
Treeenforce-strict-tunnel-tagging

Description

When configured to true, the system must only consider LSPs marked with an administrative tag for next-hop resolution.

When configured to false, tagged RSVP and SR-TE LSPs are considered first. The system then uses untagged LSPs of other types.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

enforce-untagged-route keyword
Synopsis Untagged route type enforcement
Context configure service vprn service-name bgp-ipvpn mpls auto-bind-tunnel enforce-untagged-route keyword
Treeenforce-untagged-route

Description

This command configures the enforcement of BGP routes with no administrative tag policy applied by modifying the next-hop resolution behavior for autobind services.

If the untagged-tunnel option is configured, untagged routes only bind to LSPs with no administrative tag configured. If both tagged and untagged tunnels to the next hop exist, the system only considers the untagged tunnels. If no untagged tunnels to the next hop exist, the resolution of untagged routes fails.

The untagged-tunnel option can be used in combination with the enforce-strict-tunnel-tagging command configured to true, in which case tagged routes resolve to tagged LSPs, and untagged routes only resolve to untagged LSPs.

When unconfigured, untagged routes can bind to tagged or untagged LSPs.

Options

none – Untagged routes can bind to tagged or untagged LSPs

untagged-tunnel – Untagged routes only bind to LSPs without an admin tag

Defaultnone
Introduced25.3.R2

Platforms

7705 SAR Gen 2

resolution-filter
Synopsis Enter the resolution-filter context
Contextconfigure service vprn service-name bgp-ipvpn mpls auto-bind-tunnel resolution-filter
Treeresolution-filter

Description

Commands in this context configure the subset of tunnel types that can be used in the resolution of BGP-IPVPN routes within the automatic binding of the BGP-IPVPN MPLS service to tunnels to MP-BGP peers.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp boolean
Synopsis Use BGP tunneling for next-hop resolution
Contextconfigure service vprn service-name bgp-ipvpn mpls auto-bind-tunnel resolution-filter bgp boolean
Treebgp

Description

When configured to true, BGP searches the BGP LSP for the address of the BGP next hop.

When configured to false, BGP tunneling is not used and inter-area or inter-as prefixes are not resolved.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

gre boolean
Synopsis Use GRE tunneling for next-hop resolution
Contextconfigure service vprn service-name bgp-ipvpn mpls auto-bind-tunnel resolution-filter gre boolean
Treegre

Description

When configured to true, this command enables setting the tunnel type for the auto bind tunnel.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ldp boolean
Synopsis Use LDP tunneling for next-hop resolution
Contextconfigure service vprn service-name bgp-ipvpn mpls auto-bind-tunnel resolution-filter ldp boolean
Treeldp

Description

When configured to true, BGP searches for an LDP LSP with a FEC prefix corresponding to the address of the BGP next hop.

When configured to false, LDP tunneling is not used for next-hop resolution.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

rsvp boolean
Synopsis Use RSVP tunneling for next-hop resolution
Contextconfigure service vprn service-name bgp-ipvpn mpls auto-bind-tunnel resolution-filter rsvp boolean
Treersvp

Description

When configured to true, BGP searches the best metric RSVP LSP to determine the address of the BGP next hop. This address can correspond to the system interface or to another loopback interface used by the BGP instance on the remote node. The LSP metric is provided by MPLS in the tunnel table. In the case of multiple RSVP LSPs with the same lowest metric, BGP selects the LSP with the lowest tunnel ID.

When configured to false, the RSVP LSP is not used for next-hop resolution.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sr-isis boolean
Synopsis Use IS-IS SR tunneling for next-hop resolution
Contextconfigure service vprn service-name bgp-ipvpn mpls auto-bind-tunnel resolution-filter sr-isis boolean
Treesr-isis

Description

When configured to true, BGP uses an IS-IS tunnel type to resolve the BGP next hop.

When the sr-isis command is enabled, an SR tunnel to the BGP next hop is selected in the TTM according to the following procedure.

  • Select the SR tunnel submitted by the IS-IS instance with the lowest tunnel table preference.

  • If more than one SR tunnel exists, select the SR tunnel from the instance with the lowest metric.

  • If more than one SR tunnel exists, select the SR tunnel from the instance with the lowest instance ID.

When configured to false, IS-IS tunneling is not used for next-hop resolution.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sr-ospf boolean
Synopsis Use OSPF SR tunneling for next-hop resolution
Contextconfigure service vprn service-name bgp-ipvpn mpls auto-bind-tunnel resolution-filter sr-ospf boolean
Treesr-ospf

Description

When configured to true, BGP uses an OSPF tunnel type to resolve the BGP next hop.

When enabled, an SR tunnel to the BGP next hop is selected in the TTM according to the following procedure.

  • Select the SR tunnel submitted by the OSPF instance with the lowest tunnel table preference.

  • If more than one SR tunnel exists, select the SR tunnel from the instance with the lowest metric.

  • If more than one SR tunnel exists, select the SR tunnel from the instance with the lowest instance ID.

When configured to false, OSPF tunneling is not used for next-hop resolution.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sr-ospf3 boolean
Synopsis Use OSPFv3 SR tunneling for next-hop resolution
Contextconfigure service vprn service-name bgp-ipvpn mpls auto-bind-tunnel resolution-filter sr-ospf3 boolean
Treesr-ospf3

Description

When configured to true, BGP uses an OSPF3 tunnel type to resolve the BGP next hop.

When enabled, an SR tunnel to the BGP next hop is selected in the TTM according to the following procedure.

  • Select the SR tunnel submitted by the OSPFv3 instance with the lowest tunnel table preference.

  • If more than one SR tunnel exists, select the SR tunnel from the instance with the lowest metric.

  • If more than one SR tunnel exists, select the SR tunnel from the instance with the lowest instance ID.

When configured to false, OSPF3 tunneling is not used for next-hop resolution.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sr-policy boolean
Synopsis Use SR policies for next-hop resolution
Contextconfigure service vprn service-name bgp-ipvpn mpls auto-bind-tunnel resolution-filter sr-policy boolean
Treesr-policy

Description

When configured to true, this command enables the use of SR policies to resolve the next hop of BGP IP-VPN service routes.

This command configures BGP to search for an SR policy with:

  • a non-null endpoint that matches the next hop of the service route, and

  • a color value that matches the highest numbered color for the extended community attached to the service route

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sr-te boolean
Synopsis Use SR-TE tunneling for next-hop resolution
Contextconfigure service vprn service-name bgp-ipvpn mpls auto-bind-tunnel resolution-filter sr-te boolean
Treesr-te

Description

When configured to true, BGP uses an SR-TE tunnel type to resolve the BGP next hop.

In the case of multiple SR-TE tunnels with the same lowest metric, BGP selects the tunnel with the lowest tunnel ID.

When configured to false, SR-TE tunneling is not used for next-hop resolution.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static-blackhole-first boolean
Synopsis Check for static blackhole route to resolve next hop
Contextconfigure service vprn service-name bgp-ipvpn mpls auto-bind-tunnel static-blackhole-first boolean
Treestatic-blackhole-first

Description

When configured to true, the router uses a modified next-hop resolution sequence for each imported VPN-IP route. The router first checks for a static route in the Base routing table that matches the BGP next-hop address. If at least one such static route exists, and the route that is the longest match of the BGP next-hop address is a blackhole static route, the router resolves the VPN-IP route and programs it into the VPRN IP FIB table with a next-hop action that discards all matching packets. If there is no matching static route, or the longest matching static route is not a blackhole, the router resolves the VPN-IP route in the Base routing table as normal, that is, according to the configured VPRN auto-bind filter options.

When configured to false, the router resolves the VPN-IP route in the Base routing table according to the configured VPRN auto-bind filter options.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

weighted-ecmp boolean
Synopsis Allow weighted load-balancing
Context configure service vprn service-name bgp-ipvpn mpls auto-bind-tunnel weighted-ecmp boolean
Treeweighted-ecmp

Description

When configured to true, this command enables weighted ECMP for packets using tunnels that a VPRN automatically binds to. Packets are sprayed across LSPs in the ECMP according to the outcome of the hash algorithm and the configured load balancing weight of each LSP.

When configured to false, this command disables weighted ECMP for next-hop tunnel selection.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

domain-id domain-id
Synopsis Domain ID of received BGP route before readvertisement
Contextconfigure service vprn service-name bgp-ipvpn mpls domain-id domain-id
Treedomain-id

Description

This command specifies the D-PATH domain ID. The domain ID identifies the network from which the BGP route was received before the RTM advertises it to a different neighbor. The domain ID is part of a domain, represented as domain-id:isf_safi_type in the D-PATH attribute, as described in draft-ietf-bess-evpn-ipvpn-interworking. Gateway routers modify the D-PATH attribute. A gateway is a PE where a VPRN is instantiated. The VPRN in this case advertises or receives routes from multiple BGP owners (for example, EVPN-IFL and BGP-IPVPN) or multiple instances of the same owner (for example, VPRN with two BGP-IPVPN instances).

Gateways use the D-PATH attribute to detect loops (for received routes where the D-PATH contains a local domain ID) and to make BGP best-path selection decisions based on the D-PATH length (shorter D-PATH is preferred).

In the following example, suppose a gateway receives prefix P in an EVPN-IFL instance with the following D-PATH from neighbor N:

Seg Len=1 / 65000:1:128

If the router imports the route in VPRN-1, BGP-EVPN SRv6 instance with domain 65000:2, it readvertises it to its BGP-IPVPN MPLS instance as follows:

Seg Len=2 / 65000:2:70 / 65000:1:128

That is, the gateway prepends the local domain ID and family to the D-PATH before readvertising the route into a different instance.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

dynamic-egress-label-limit boolean
Synopsis Enables dynamic egress label limit
Context configure service vprn service-name bgp-ipvpn mpls dynamic-egress-label-limit boolean
Treedynamic-egress-label-limit

Description

When configured to true, this command relaxes the egress MPLS label limit check when resolving BGP next hops in the tunnel table.

For VPRN services, the OAM label is never computed and, therefore, one more egress label is allowed.

For EVPN (Epipe and VPLS) services, the system only computes the control word and ESI label if they are used. For the control word, the system reduces the egress label limit by one label if the control word is configured in the service. When configured, the ESI label is not counted for Epipes or VPLS services without an ES.

When configured to false this command, for EVPN, Epipe, and VPLS services, always accounts for the ESI label and control word.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-distinguisher (string | keyword)
Synopsis Route distinguisher
Context configure service vprn service-name bgp-ipvpn mpls route-distinguisher (string | keyword)
Treeroute-distinguisher

Description

This command specifies a unique route distinguisher (RD) to be associated with each routing instance to identify which VPN the route belongs to.

Optionsauto-rd
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vrf-export
Synopsis Enable the vrf-export context
Context configure service vprn service-name bgp-ipvpn mpls vrf-export
Treevrf-export

Description

Commands in this context specify route policies that control how routes are exported from the local VRF to other VRFs on the same or remote PE routers (via MP-BGP).

Aggregate routes are not advertised via MP-BGP protocols to other MP-BGP peers.

Route policies are configured in the configure policy-options context.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy (policy-expr-string | string)
Synopsis Policy name
Contextconfigure service vprn service-name bgp-ipvpn mpls vrf-export policy (policy-expr-string | string)
Treepolicy

Description

This command configures VRF route policies that control routes between local VRFs and other VRFs on the same or remote PE routers (using MP-BGP).

Each referenced object is either a policy logical expression or the name of a single policy.

Only one referenced object can be a policy logical expression consisting of policy names (enclosed in square brackets) and logical operators (AND, OR, NOT). The objects are evaluated in the specified order to determine whether to accept or reject the route.

Only the first policy can have the maximum length and the rest can be up to 64 characters.

Aggregate routes are not advertised using MP-BGP protocols to the other MP-BGP peers.

String length1 to 255
Max. instances15
Min. instances1

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

vrf-import
Synopsis Enable the vrf-import context
Context configure service vprn service-name bgp-ipvpn mpls vrf-import
Treevrf-import

Description

Commands in this context specify route policies that control how VPN-IP and EVPN-IFL routes that are exported by other VRFs on the same or remote PEs, are imported into the local VRF.

Route policies are configured in the configure policy-options context.

Unless the preference value is changed by the policy, the preference value for BGP-VPN and EVPN-IFL routes specified in this context is set to 170 when imported from remote PE routers, or the value is retained from the protocol preference value of the exported route when imported from other VRFs on the same router.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy (policy-expr-string | string)
Synopsis Policy name
Contextconfigure service vprn service-name bgp-ipvpn mpls vrf-import policy (policy-expr-string | string)
Treepolicy

Description

This command configures VRF route policies that control routes between local VRFs and other VRFs on the same or remote PE routers (using MP-BGP).

Each referenced object is either a policy logical expression or the name of a single policy.

Only one referenced object can be a policy logical expression consisting of policy names (enclosed in square brackets) and logical operators (AND, OR, NOT). The objects are evaluated in the specified order to determine whether to accept or reject the route.

Only the first policy can have the maximum length and the rest can be up to 64 characters.

Aggregate routes are not advertised using MP-BGP protocols to the other MP-BGP peers.

String length1 to 255
Max. instances15
Min. instances1

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

vrf-target
Synopsis Enter the vrf-target context
Context configure service vprn service-name bgp-ipvpn mpls vrf-target
Treevrf-target

Description

Commands in this context configure the route target that is added to advertised routes or compared against received routes from other VRFs on the same or remote PE routers (via MP-BGP).

BGP-VPN and EVPN-IFL routes imported using a VRF target configuration use the BGP preference value of 170 when imported from remote PE routers, or retain the protocol preference value of the exported route when imported from other VRFs in the same router.

Configured VRF import or export policies override the VRF target policy.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

community route-target
Synopsis Extended BGP community
Context configure service vprn service-name bgp-ipvpn mpls vrf-target community route-target
Treecommunity

Description

This command configures an extended BGP community in the form type:x:y. Type can only be target and x and y are 16-bit integers.

String length10 to 28

Notes

The following elements are part of a choice: community or (export-community and import-community).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

export-community route-target
Synopsis Communities sent to remote PE neighbors
Contextconfigure service vprn service-name bgp-ipvpn mpls vrf-target export-community route-target
Treeexport-community
String length10 to 28

Notes

The following elements are part of a choice: community or (export-community and import-community).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

import-community route-target
Synopsis Communities accepted from remote PE neighbors
Contextconfigure service vprn service-name bgp-ipvpn mpls vrf-target import-community route-target
Treeimport-community
String length10 to 28

Notes

The following elements are part of a choice: community or (export-community and import-community).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp-shared-queue
Synopsis Enable the bgp-shared-queue context
Contextconfigure service vprn service-name bgp-shared-queue
Treebgp-shared-queue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

cir (number | keyword)
Synopsis Committed information rate for shared queue
Contextconfigure service vprn service-name bgp-shared-queue cir (number | keyword)
Treecir
Range0 to 100000000
Unitskilobps
Options max
Default 4000
Introduced25.3.R2

Platforms

7705 SAR Gen 2

pir (number | keyword)
Synopsis Peak information rate for shared queue
Contextconfigure service vprn service-name bgp-shared-queue pir (number | keyword)
Treepir
Range1 to 100000000
Unitskilobps
Options max
Default 4000
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp-vpn-backup
Synopsis Enter the bgp-vpn-backup context
Contextconfigure service vprn service-name bgp-vpn-backup
Treebgp-vpn-backup
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4 boolean
Synopsis Allow BGP-VPN to be used as backup for IPv4 prefixes
Contextconfigure service vprn service-name bgp-vpn-backup ipv4 boolean
Treeipv4
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6 boolean
Synopsis Allow BGP-VPN to be used as backup for IPv6 prefixes
Contextconfigure service vprn service-name bgp-vpn-backup ipv6 boolean
Treeipv6
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

carrier-carrier-vpn boolean
Synopsis Allow VPRN service to support a Carrier Supporting Carrier model
Contextconfigure service vprn service-name carrier-carrier-vpn boolean
Treecarrier-carrier-vpn
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

confederation
Synopsis Enter the confederation context
Contextconfigure service vprn service-name confederation
Treeconfederation
Introduced25.3.R2

Platforms

7705 SAR Gen 2

members [as-number] number
Synopsis Add a list entry for members
Context configure service vprn service-name confederation members number
Treemembers
Max. instances256
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[as-number] number
Synopsis Confederation AS number
Context configure service vprn service-name confederation members number
Treemembers
Range1 to 4294967295

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

customer reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisService customer ID
Contextconfigure service vprn service-name customer reference
Treecustomer

Reference

configure service customer customer-name

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

d-path-length-ignore boolean
Synopsis Enable D-PATH length ignore
Context configure service vprn service-name d-path-length-ignore boolean
Treed-path-length-ignore

Description

When configured to true, the VPRN RTM ignores the D-PATH domain segment length for best path selection purposes (for routes in the VPRN). This allows the user to control whether the RTM considers the D-PATH length when comparing two VPN routes with different RDs.

When configured to false, the router does not ignore the D-PATH domain segment length.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service vprn service-name description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dhcp-server
Synopsis Enter the dhcp-server context
Context configure service vprn service-name dhcp-server
Treedhcp-server
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dhcpv4 [name] named-item
Synopsis Enter the dhcpv4 list instance
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item
Treedhcpv4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[name] named-item
Synopsis DHCP server name
Context configure service vprn service-name dhcp-server dhcpv4 named-item
Treedhcpv4
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the DHCP server
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

failover
Synopsis Enter the failover context
Context configure service vprn service-name dhcp-server dhcpv4 named-item failover
Treefailover
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ignore-mclt-on-takeover boolean
Synopsis Ignore maximum client lead during takeover from partner
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item failover ignore-mclt-on-takeover boolean
Treeignore-mclt-on-takeover

Description

When configured to true, the remote IP address range can be taken over immediately when the intercommunication link enters the PARTNER-DOWN state, without having to wait for the MCLT to expire.

When configured to false, the DHCP lease time for new clients is restricted to the MCLT during a failure. For existing clients, the lease time is gradually reduced over time to the MCLT by consecutive DHCP renewals.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

maximum-client-lead-time number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum time that DHCP server can extend client's lease
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item failover maximum-client-lead-time number
Treemaximum-client-lead-time

Description

This command configures the maximum client lead time (MCLT), which is the maximum time that a DHCP server can extend the client's lease time beyond the lease time currently known by the DHCP partner node. In dual-homed environments, the initial lease time for all DHCP clients is restricted to the MCLT by default. Consecutive DHCP renewals can extend the lease time beyond the MCLT.

Range600 to 86399
Unitsseconds
Default 600
Introduced25.3.R2

Platforms

7705 SAR Gen 2

partner-down-delay number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDelay to prevent lease duplication during link failure
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item failover partner-down-delay number
Treepartner-down-delay

Description

This command configures the interval before a failed intercommunication link transitions from the COMM-INT state to the PARTNER-DOWN state. This delay prevents IP lease duplication during link failure by not allowing new IP addresses to be assigned from the remote IP address range. This timer is intended to provide the operator with enough time to remedy the failed situation and avoid duplication of IP addresses and prefixes during the failure.

Range0 to 86399
Unitsseconds
Default 86399
Introduced25.3.R2

Platforms

7705 SAR Gen 2

peer [address] reference
Synopsis Enter the peer list instance
Context configure service vprn service-name dhcp-server dhcpv4 named-item failover peer reference
Treepeer
Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sync-tag named-item
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTag that identifies synchronizing server or pool pairs
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item failover peer reference sync-tag named-item
Treesync-tag
String length1 to 32

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

startup-wait-time number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTime between initialization and assuming active role
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item failover startup-wait-time number
Treestartup-wait-time

Description

This command configures a delay that avoids transient issues during the initialization process. During startup wait time, each failover peer waits after the initialization process before assuming the active role for the prefix designated as local or remote.

Range60 to 3600
Unitsseconds
Default 120
Introduced25.3.R2

Platforms

7705 SAR Gen 2

force-renews boolean
Synopsis Send FORCERENEW messages to force renewals of leases
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item force-renews boolean
Treeforce-renews

Description

When configured to true, FORCERENEW messages are enabled for DHCP.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

lease-hold
Synopsis Enter the lease-hold context
Context configure service vprn service-name dhcp-server dhcpv4 named-item lease-hold
Treelease-hold
Introduced25.3.R2

Platforms

7705 SAR Gen 2

additional-scenarios
Synopsis Enter the additional-scenarios context
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item lease-hold additional-scenarios
Treeadditional-scenarios

Description

Commands in this context configure additional types of leases or triggers that cause the system to hold up leases.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

pool [pool-name] named-item
Synopsis Enter the pool list instance
Context configure service vprn service-name dhcp-server dhcpv4 named-item pool named-item
Treepool
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[pool-name] named-item
Synopsis DHCP server pool name
Context configure service vprn service-name dhcp-server dhcpv4 named-item pool named-item
Treepool
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

failover
Synopsis Enter the failover context
Context configure service vprn service-name dhcp-server dhcpv4 named-item pool named-item failover
Treefailover
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ignore-mclt-on-takeover boolean
Synopsis Ignore maximum client lead during takeover from partner
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item failover ignore-mclt-on-takeover boolean
Treeignore-mclt-on-takeover

Description

When configured to true, the remote IP address range can be taken over immediately when the intercommunication link enters the PARTNER-DOWN state, without having to wait for the MCLT to expire.

When configured to false, the DHCP lease time for new clients is restricted to the MCLT during a failure. For existing clients, the lease time is gradually reduced over time to the MCLT by consecutive DHCP renewals.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

maximum-client-lead-time number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum time that DHCP server can extend client's lease
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item failover maximum-client-lead-time number
Treemaximum-client-lead-time

Description

This command configures the maximum client lead time (MCLT), which is the maximum time that a DHCP server can extend the client's lease time beyond the lease time currently known by the DHCP partner node. In dual-homed environments, the initial lease time for all DHCP clients is restricted to the MCLT by default. Consecutive DHCP renewals can extend the lease time beyond the MCLT.

Range600 to 86399
Unitsseconds
Default 600
Introduced25.3.R2

Platforms

7705 SAR Gen 2

partner-down-delay number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDelay to prevent lease duplication during link failure
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item failover partner-down-delay number
Treepartner-down-delay

Description

This command configures the interval before a failed intercommunication link transitions from the COMM-INT state to the PARTNER-DOWN state. This delay prevents IP lease duplication during link failure by not allowing new IP addresses to be assigned from the remote IP address range. This timer is intended to provide the operator with enough time to remedy the failed situation and avoid duplication of IP addresses and prefixes during the failure.

Range0 to 86399
Unitsseconds
Default 86399
Introduced25.3.R2

Platforms

7705 SAR Gen 2

peer [address] reference
Synopsis Enter the peer list instance
Context configure service vprn service-name dhcp-server dhcpv4 named-item pool named-item failover peer reference
Treepeer
Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sync-tag named-item
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTag that identifies synchronizing server or pool pairs
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item failover peer reference sync-tag named-item
Treesync-tag
String length1 to 32

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

startup-wait-time number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTime between initialization and assuming active role
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item failover startup-wait-time number
Treestartup-wait-time

Description

This command configures a delay that avoids transient issues during the initialization process. During startup wait time, each failover peer waits after the initialization process before assuming the active role for the prefix designated as local or remote.

Range60 to 3600
Unitsseconds
Default 120
Introduced25.3.R2

Platforms

7705 SAR Gen 2

minimum-free
Synopsis Enter the minimum-free context
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item minimum-free
Treeminimum-free

Description

Commands in this context specify the minimum number of free addresses in this pool.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

absolute number
Synopsis Minimum number of free addresses in this pool or subnet
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item minimum-free absolute number
Treeabsolute
Range0 to 255
Default1

Notes

The following elements are part of a choice: absolute or percent.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

event-when-depleted boolean
Synopsis Generate notification when addresses are depleted
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item minimum-free event-when-depleted boolean
Treeevent-when-depleted

Description

When configured to true, a system-generated event is generated when all available addresses in the pool or subnet of a local DHCP server are depleted.

When configured to false, no action is taken when all available addresses in the pool or subnet of a local DHCP server are depleted.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

percent number
Synopsis Minimum free addresses as a percentage
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item minimum-free percent number
Treepercent
Range0 to 100
Default1

Notes

The following elements are part of a choice: absolute or percent.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

nak-non-matching-subnet boolean
Synopsis Send NAK if no match for request address pool range
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item nak-non-matching-subnet boolean
Treenak-non-matching-subnet

Description

When configured to true, a NAK response when the local DHCPv4 server receives a DHCP request with option 50 (the client is trying to request a previously allocated message). If the address-allocation algorithm uses a pool that does not contain the requested address, the system returns the DHCP NAK.

When configured to false or unconfigured, the system drops the DHCP packet.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

offer-time number
Synopsis Time interval during which a DHCP offer remains valid
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item offer-time number
Treeoffer-time
Range10 to 600
Unitsseconds
Default 60
Introduced25.3.R2

Platforms

7705 SAR Gen 2

options
Synopsis Enter the options context
Context configure service vprn service-name dhcp-server dhcpv4 named-item pool named-item options
Treeoptions
Introduced25.3.R2

Platforms

7705 SAR Gen 2

option [number] (number | keyword)
Synopsis Enter the option list instance
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item options option (number | keyword)
Treeoption
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[number] (number | keyword)
Synopsis DHCP option to send identification strings to client
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item options option (number | keyword)
Treeoption
Range1 to 254
Optionssubnet-mask, default-router, dns-server, domain-name, netbios-name-server, netbios-node-type, lease-time, lease-renew-time, lease-rebind-time

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ascii-string string-not-all-spaces
Synopsis DHCP option specified as an ASCII string
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item options option (number | keyword) ascii-string string-not-all-spaces
Treeascii-string
String length1 to 127

Notes

The following elements are part of a mandatory choice: ascii-string, duration, empty, hex-string, ipv4-address, or netbios-node-type.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

duration number
Synopsis DHCP option as time duration
Context configure service vprn service-name dhcp-server dhcpv4 named-item pool named-item options option (number | keyword) duration number
Treeduration
Range10 to 315446399
Unitsseconds

Notes

The following elements are part of a mandatory choice: ascii-string, duration, empty, hex-string, ipv4-address, or netbios-node-type.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

empty
Synopsis Remove DHCP option from the configuration
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item options option (number | keyword) empty
Treeempty

Notes

The following elements are part of a mandatory choice: ascii-string, duration, empty, hex-string, ipv4-address, or netbios-node-type.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

hex-string hex-string
Synopsis DHCP option specified as hexadecimal string
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item options option (number | keyword) hex-string hex-string
Treehex-string
String length1 to 256

Notes

The following elements are part of a mandatory choice: ascii-string, duration, empty, hex-string, ipv4-address, or netbios-node-type.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4-address ipv4-address
Synopsis DHCP option as a list of IPv4 addresses
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item options option (number | keyword) ipv4-address ipv4-address
Treeipv4-address
Max. instances4

Notes

The following elements are part of a mandatory choice: ascii-string, duration, empty, hex-string, ipv4-address, or netbios-node-type.

This element is ordered by the user.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

netbios-node-type keyword
Synopsis DHCP option as NetBIOS node type
Context configure service vprn service-name dhcp-server dhcpv4 named-item pool named-item options option (number | keyword) netbios-node-type keyword
Treenetbios-node-type
Optionsb-node, p-node, m-node, h-node

Notes

The following elements are part of a mandatory choice: ascii-string, duration, empty, hex-string, ipv4-address, or netbios-node-type.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

subnet [ipv4-prefix] ipv4-unicast-prefix
Synopsis Enter the subnet list instance
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item subnet ipv4-unicast-prefix
Treesubnet
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ipv4-prefix] ipv4-unicast-prefix
Synopsis IPv4 prefix for the subnet
Context configure service vprn service-name dhcp-server dhcpv4 named-item pool named-item subnet ipv4-unicast-prefix
Treesubnet

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

address-range [start] ipv4-unicast-address end ipv4-unicast-address
Synopsis Enter the address-range list instance
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item subnet ipv4-unicast-prefix address-range ipv4-unicast-address end ipv4-unicast-address
Treeaddress-range
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[start] ipv4-unicast-address
Synopsis Lower bound of the IP address range
Context configure service vprn service-name dhcp-server dhcpv4 named-item pool named-item subnet ipv4-unicast-prefix address-range ipv4-unicast-address end ipv4-unicast-address
Treeaddress-range

Description

This command specifies the start of a range of IP addresses that are excluded from the pool of IP addresses in this subnet.

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

end ipv4-unicast-address
Synopsis Upper bound of the IP address range
Context configure service vprn service-name dhcp-server dhcpv4 named-item pool named-item subnet ipv4-unicast-prefix address-range ipv4-unicast-address end ipv4-unicast-address
Treeaddress-range

Description

This command specifies the end of a range of IP addresses that are excluded from the pool of IP addresses in this subnet.

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

failover-control-type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisFailover control type for this range
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item subnet ipv4-unicast-prefix address-range ipv4-unicast-address end ipv4-unicast-address failover-control-type keyword
Treefailover-control-type
Optionslocal, remote, access-driven
Defaultlocal
Introduced25.3.R2

Platforms

7705 SAR Gen 2

drain boolean
Synopsis Prevent new lease assignment from this subnet
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item subnet ipv4-unicast-prefix drain boolean
Treedrain

Description

When configured to true, new leases cannot be assigned and existing leases are kept up until they are released.

When configured to false, the subnet is active and new leases can be assigned.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

exclude-addresses [start] ipv4-unicast-address end ipv4-unicast-address
Synopsis Add a list entry for exclude-addresses
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item subnet ipv4-unicast-prefix exclude-addresses ipv4-unicast-address end ipv4-unicast-address
Treeexclude-addresses
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[start] ipv4-unicast-address
Synopsis Lower bound of the IP address range
Context configure service vprn service-name dhcp-server dhcpv4 named-item pool named-item subnet ipv4-unicast-prefix exclude-addresses ipv4-unicast-address end ipv4-unicast-address
Treeexclude-addresses

Description

This command specifies the start of a range of IP addresses that are excluded from the pool of IP addresses in this subnet.

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

end ipv4-unicast-address
Synopsis Upper bound of the IP address range
Context configure service vprn service-name dhcp-server dhcpv4 named-item pool named-item subnet ipv4-unicast-prefix exclude-addresses ipv4-unicast-address end ipv4-unicast-address
Treeexclude-addresses

Description

This command specifies the end of a range of IP addresses that are excluded from the pool of IP addresses in this subnet.

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

minimum-free
Synopsis Enter the minimum-free context
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item subnet ipv4-unicast-prefix minimum-free
Treeminimum-free

Description

Commands in this context specify the minimum number of free addresses in this pool.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

absolute number
Synopsis Minimum number of free addresses in this pool or subnet
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item subnet ipv4-unicast-prefix minimum-free absolute number
Treeabsolute
Range0 to 255
Default1

Notes

The following elements are part of a choice: absolute or percent.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

event-when-depleted boolean
Synopsis Generate notification when addresses are depleted
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item subnet ipv4-unicast-prefix minimum-free event-when-depleted boolean
Treeevent-when-depleted

Description

When configured to true, a system-generated event is generated when all available addresses in the pool or subnet of a local DHCP server are depleted.

When configured to false, no action is taken when all available addresses in the pool or subnet of a local DHCP server are depleted.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

percent number
Synopsis Minimum free addresses as a percentage
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item subnet ipv4-unicast-prefix minimum-free percent number
Treepercent
Range0 to 100
Default1

Notes

The following elements are part of a choice: absolute or percent.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

options
Synopsis Enter the options context
Context configure service vprn service-name dhcp-server dhcpv4 named-item pool named-item subnet ipv4-unicast-prefix options
Treeoptions
Introduced25.3.R2

Platforms

7705 SAR Gen 2

option [number] (number | keyword)
Synopsis Enter the option list instance
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item subnet ipv4-unicast-prefix options option (number | keyword)
Treeoption
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[number] (number | keyword)
Synopsis DHCP option to send identification strings to client
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item subnet ipv4-unicast-prefix options option (number | keyword)
Treeoption
Range1 to 254
Optionssubnet-mask, default-router, dns-server, domain-name, netbios-name-server, netbios-node-type, lease-time, lease-renew-time, lease-rebind-time

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ascii-string string-not-all-spaces
Synopsis DHCP option specified as an ASCII string
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item subnet ipv4-unicast-prefix options option (number | keyword) ascii-string string-not-all-spaces
Treeascii-string
String length1 to 127

Notes

The following elements are part of a mandatory choice: ascii-string, duration, empty, hex-string, ipv4-address, or netbios-node-type.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

duration number
Synopsis DHCP option as time duration
Context configure service vprn service-name dhcp-server dhcpv4 named-item pool named-item subnet ipv4-unicast-prefix options option (number | keyword) duration number
Treeduration
Range10 to 315446399
Unitsseconds

Notes

The following elements are part of a mandatory choice: ascii-string, duration, empty, hex-string, ipv4-address, or netbios-node-type.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

empty
Synopsis Empty DHCP option
Context configure service vprn service-name dhcp-server dhcpv4 named-item pool named-item subnet ipv4-unicast-prefix options option (number | keyword) empty
Treeempty

Notes

The following elements are part of a mandatory choice: ascii-string, duration, empty, hex-string, ipv4-address, or netbios-node-type.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

hex-string hex-string
Synopsis DHCP option specified as hexadecimal string
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item subnet ipv4-unicast-prefix options option (number | keyword) hex-string hex-string
Treehex-string
String length1 to 256

Notes

The following elements are part of a mandatory choice: ascii-string, duration, empty, hex-string, ipv4-address, or netbios-node-type.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4-address ipv4-address
Synopsis DHCP option as a list of IPv4 addresses
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool named-item subnet ipv4-unicast-prefix options option (number | keyword) ipv4-address ipv4-address
Treeipv4-address
Max. instances4

Notes

The following elements are part of a mandatory choice: ascii-string, duration, empty, hex-string, ipv4-address, or netbios-node-type.

This element is ordered by the user.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

netbios-node-type keyword
Synopsis DHCP option as NetBIOS node type
Context configure service vprn service-name dhcp-server dhcpv4 named-item pool named-item subnet ipv4-unicast-prefix options option (number | keyword) netbios-node-type keyword
Treenetbios-node-type
Optionsb-node, p-node, m-node, h-node

Notes

The following elements are part of a mandatory choice: ascii-string, duration, empty, hex-string, ipv4-address, or netbios-node-type.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

pool-selection
Synopsis Enter the pool-selection context
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool-selection
Treepool-selection
Introduced25.3.R2

Platforms

7705 SAR Gen 2

use-gi-address
Synopsis Enable the use-gi-address context
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool-selection use-gi-address
Treeuse-gi-address

Description

Commands in this context configure gateway interface (GI) address matching. When configured, the pool can be used for address matching even if a subnet is not found. If the local user database name is not used, addresses are provided only by GI. If a user must be blocked from getting an address, the server maps to a local user database and configures the user with no address.

A pool can include multiple subnets. Since the GI is shared by multiple subnets in a subscriber interface, the pool can provide IP addresses from any of the subnets included when the GI is matched to one of its subnets. This allows a pool to be created that represents a sub-net.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

use-pool-from-client
Synopsis Enable the use-pool-from-client context
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool-selection use-pool-from-client
Treeuse-pool-from-client
Introduced25.3.R2

Platforms

7705 SAR Gen 2

delimiter string-not-all-spaces
Synopsis Delimiter to combine primary and secondary pool names
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item pool-selection use-pool-from-client delimiter string-not-all-spaces
Treedelimiter

Description

This command configures a single ASCII character that separates the pool names in DHCP vendor-specific option 82, which identifies the address pool to be used for this client.

String length1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

user-identification keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisUser identification method for the DHCP server
Contextconfigure service vprn service-name dhcp-server dhcpv4 named-item user-identification keyword
Treeuser-identification
Optionsmac-circuit-id, client-id, mac, circuit-id, remote-id
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dhcpv6 [name] named-item
Synopsis Enter the dhcpv6 list instance
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item
Treedhcpv6
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[name] named-item
Synopsis DHCP server name
Context configure service vprn service-name dhcp-server dhcpv6 named-item
Treedhcpv6
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the DHCP server
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

auto-provisioned boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisAuto-provision the pools of this server
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item auto-provisioned boolean
Treeauto-provisioned
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

defaults
Synopsis Enter the defaults context
Context configure service vprn service-name dhcp-server dhcpv6 named-item defaults
Treedefaults
Introduced25.3.R2

Platforms

7705 SAR Gen 2

options
Synopsis Enter the options context
Context configure service vprn service-name dhcp-server dhcpv6 named-item defaults options
Treeoptions
Introduced25.3.R2

Platforms

7705 SAR Gen 2

option [number] (number | keyword)
Synopsis Enter the option list instance
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item defaults options option (number | keyword)
Treeoption
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[number] (number | keyword)
Synopsis DHCP option to send as identification string
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item defaults options option (number | keyword)
Treeoption
Range1 to 65535
Optionsdns-server, domain-name

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ascii-string string-not-all-spaces
Synopsis DHCP option specified as an ASCII string
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item defaults options option (number | keyword) ascii-string string-not-all-spaces
Treeascii-string
String length1 to 127

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

domain-string string
Synopsis DHCP option specified as a domain name
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item defaults options option (number | keyword) domain-string string
Treedomain-string
String length1 to 127

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

duration number
Synopsis DHCP option specified as time
Context configure service vprn service-name dhcp-server dhcpv6 named-item defaults options option (number | keyword) duration number
Treeduration
Range10 to 315446399
Unitsseconds

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

empty
Synopsis Empty DHCP option
Context configure service vprn service-name dhcp-server dhcpv6 named-item defaults options option (number | keyword) empty
Treeempty

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

hex-string hex-string
Synopsis DHCP option specified as hexadecimal string
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item defaults options option (number | keyword) hex-string hex-string
Treehex-string
String length1 to 256

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6-address ipv6-address
Synopsis DHCP option specified as a list of IPv6 addresses
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item defaults options option (number | keyword) ipv6-address ipv6-address
Treeipv6-address
Max. instances4

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

This element is ordered by the user.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

preferred-lifetime number
Synopsis Time this lease remains preferred
Context configure service vprn service-name dhcp-server dhcpv6 named-item defaults preferred-lifetime number
Treepreferred-lifetime

Description

This command configures the preferred lifetime of the IPv6 lease address or prefix. When the preferred lifetime expires, any derived addresses are deprecated. The preferred lifetime must be less than or equal to the valid lifetime. 

Each address or prefix assigned to the client has associated preferred and valid lifetimes specified by the address assignment authority (such as the DHCP server, RADIUS, or ESM). To request an extension of the lifetimes assigned to an address, the client sends a renew message to the addressing authority. The authority sends a reply message to the client with the new lifetimes, allowing the client to continue to use the address/prefix without interruption. The lifetimes are transmitted from the addressing authority to the client in the identity association (IA) option at the top level of the message (not the address or prefix level).

Range300 to 315446399
Unitsseconds
Default 3600
Introduced25.3.R2

Platforms

7705 SAR Gen 2

rebind-time number
Synopsis Rebind time for the lease
Context configure service vprn service-name dhcp-server dhcpv6 named-item defaults rebind-time number
Treerebind-time

Description

This command configures the rebind time, known as T2, at which the client contacts the addressing authority to extend the lifetimes of its leases.

The IP addressing authority (such as the DHCP server, RADIUS, or ESM) controls the time for extending lifetimes on assigned addresses/prefixes through the T1 and T2 parameters assigned to an identity association (IA). At renew time, T1, the client initiates a renew or reply message exchange to extend the lifetimes of any addresses in the IA. The client includes an IA option with all addresses or prefixes currently assigned to the IA in its renew message.

Recommended values for T1 and T2 are 0.5 and 0.8 times the shortest preferred lifetime of the addresses or prefixes in the IA that the addressing authority is willing to extend, respectively. The configured rebind timer value should always be less than or equal to the rebind timer. The T1 and T2 values are carried in the IPV6 address option in the IA.

Range0 to 1209600
Unitsseconds
Default 2880
Introduced25.3.R2

Platforms

7705 SAR Gen 2

renew-time number
Synopsis Renew time for the lease
Context configure service vprn service-name dhcp-server dhcpv6 named-item defaults renew-time number
Treerenew-time

Description

This command configures the renew time, known as T1, at which the client makes a transition to the lease-renewal state.

The IP addressing authority (such as the DHCP server, RADIUS, or ESM) controls the time for extending lifetimes on assigned addresses/prefixes through the T1 and T2 parameters assigned to an identity association (IA). At renew time, T1, the client initiates a renew/reply message exchange to extend the lifetimes of any addresses in the IA. The client includes an IA option with all addresses/prefixes currently assigned to the IA in its renew message.

Recommended values for T1 and T2 are 0.5 and 0.8 times the shortest preferred lifetime of the addresses or prefixes in the IA that the addressing authority is willing to extend, respectively. The configured renew timer value should always be shorter than or equal to the rebind timer. The T1 and T2 values are carried in the IPV6 address option in the IA.

Range0 to 604800
Unitsseconds
Default 1800
Introduced25.3.R2

Platforms

7705 SAR Gen 2

valid-lifetime number
Synopsis Time for the lease to remain valid
Context configure service vprn service-name dhcp-server dhcpv6 named-item defaults valid-lifetime number
Treevalid-lifetime

Description

This command configures a valid lifetime for a DHCPv6 lease address or prefix. The valid lifetime is the length of time an address and prefix remains in the valid state. The valid lifetime must be greater than or equal to the preferred lifetime. When the valid lifetime expires, the address and prefix becomes invalid and must not be used in communications. RFC 2461 recommends a default value of 30 days.

Each address and prefix assigned to the client has associated preferred and valid lifetimes specified by the address assignment authority (such as the DHCP server, RADIUS, or ESM). To request an extension of the lifetimes assigned to an address, the client sends a renew message to the addressing authority. The authority sends a reply message to the client with the new lifetimes, allowing the client to continue to use the address and prefix without interruption. The lifetimes are transmitted from the addressing authority to the client in the identity association (IA) option at the top level of the message (not the address or prefix level).

Range300 to 315446399
Unitsseconds
Default 86400
Introduced25.3.R2

Platforms

7705 SAR Gen 2

failover
Synopsis Enter the failover context
Context configure service vprn service-name dhcp-server dhcpv6 named-item failover
Treefailover
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ignore-mclt-on-takeover boolean
Synopsis Ignore maximum client lead during takeover from partner
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item failover ignore-mclt-on-takeover boolean
Treeignore-mclt-on-takeover

Description

When configured to true, the remote IP address range can be taken over immediately when the intercommunication link enters the PARTNER-DOWN state, without having to wait for the MCLT to expire.

When configured to false, the DHCP lease time for new clients is restricted to the MCLT during a failure. For existing clients, the lease time is gradually reduced over time to the MCLT by consecutive DHCP renewals.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

maximum-client-lead-time number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum time that DHCP server can extend client's lease
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item failover maximum-client-lead-time number
Treemaximum-client-lead-time

Description

This command configures the maximum client lead time (MCLT), which is the maximum time that a DHCP server can extend the client's lease time beyond the lease time currently known by the DHCP partner node. In dual-homed environments, the initial lease time for all DHCP clients is restricted to the MCLT by default. Consecutive DHCP renewals can extend the lease time beyond the MCLT.

Range600 to 86399
Unitsseconds
Default 600
Introduced25.3.R2

Platforms

7705 SAR Gen 2

partner-down-delay number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDelay to prevent lease duplication during link failure
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item failover partner-down-delay number
Treepartner-down-delay

Description

This command configures the interval before a failed intercommunication link transitions from the COMM-INT state to the PARTNER-DOWN state. This delay prevents IP lease duplication during link failure by not allowing new IP addresses to be assigned from the remote IP address range. This timer is intended to provide the operator with enough time to remedy the failed situation and avoid duplication of IP addresses and prefixes during the failure.

Range0 to 86399
Unitsseconds
Default 86399
Introduced25.3.R2

Platforms

7705 SAR Gen 2

peer [address] reference
Synopsis Enter the peer list instance
Context configure service vprn service-name dhcp-server dhcpv6 named-item failover peer reference
Treepeer
Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sync-tag named-item
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTag that identifies synchronizing server or pool pairs
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item failover peer reference sync-tag named-item
Treesync-tag
String length1 to 32

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

startup-wait-time number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTime between initialization and assuming active role
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item failover startup-wait-time number
Treestartup-wait-time

Description

This command configures a delay that avoids transient issues during the initialization process. During startup wait time, each failover peer waits after the initialization process before assuming the active role for the prefix designated as local or remote.

Range60 to 3600
Unitsseconds
Default 120
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ignore-rapid-commit boolean
Synopsis Ignore Rapid Commit option
Context configure service vprn service-name dhcp-server dhcpv6 named-item ignore-rapid-commit boolean
Treeignore-rapid-commit

Description

When configured to true, the server ignores the Rapid Commit option sent by the client and uses the regular message exchange.   

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface-id-mapping boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMap hosts within interface-to-prefix combinations
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item interface-id-mapping boolean
Treeinterface-id-mapping

Description

When configured to true, this command specifies an interface-mapping method that uses a combination of unique /64 prefixes and interface IDs. A /64 prefix is allocated to each interface ID, and all clients with the same interface ID are assigned an address from the prefix. This method is used for bridging clients in the same local loop and SAP, so that sharing the prefix allows communication to stay local. For SLAAC-based assignment, downstream neighbor discovery is automatically enabled to resolve the assigned address.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

lease-hold
Synopsis Enter the lease-hold context
Context configure service vprn service-name dhcp-server dhcpv6 named-item lease-hold
Treelease-hold
Introduced25.3.R2

Platforms

7705 SAR Gen 2

additional-scenarios
Synopsis Enter the additional-scenarios context
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item lease-hold additional-scenarios
Treeadditional-scenarios

Description

Commands in this context configure additional types of leases or triggers that cause the system to hold up leases.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

pool [pool-name] named-item
Synopsis Enter the pool list instance
Context configure service vprn service-name dhcp-server dhcpv6 named-item pool named-item
Treepool
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[pool-name] named-item
Synopsis DHCP server pool name
Context configure service vprn service-name dhcp-server dhcpv6 named-item pool named-item
Treepool
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

delegated-prefix
Synopsis Enter the delegated-prefix context
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item delegated-prefix
Treedelegated-prefix
Introduced25.3.R2

Platforms

7705 SAR Gen 2

exclude-prefix [ipv6-prefix] ipv6-prefix
Synopsis Add a list entry for exclude-prefix
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item exclude-prefix ipv6-prefix
Treeexclude-prefix
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ipv6-prefix] ipv6-prefix
Synopsis IPv6 prefix to be excluded from available pool prefixes
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item exclude-prefix ipv6-prefix
Treeexclude-prefix

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

failover
Synopsis Enter the failover context
Context configure service vprn service-name dhcp-server dhcpv6 named-item pool named-item failover
Treefailover
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ignore-mclt-on-takeover boolean
Synopsis Ignore maximum client lead during takeover from partner
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item failover ignore-mclt-on-takeover boolean
Treeignore-mclt-on-takeover

Description

When configured to true, the remote IP address range can be taken over immediately when the intercommunication link enters the PARTNER-DOWN state, without having to wait for the MCLT to expire.

When configured to false, the DHCP lease time for new clients is restricted to the MCLT during a failure. For existing clients, the lease time is gradually reduced over time to the MCLT by consecutive DHCP renewals.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

maximum-client-lead-time number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum time that DHCP server can extend client's lease
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item failover maximum-client-lead-time number
Treemaximum-client-lead-time

Description

This command configures the maximum client lead time (MCLT), which is the maximum time that a DHCP server can extend the client's lease time beyond the lease time currently known by the DHCP partner node. In dual-homed environments, the initial lease time for all DHCP clients is restricted to the MCLT by default. Consecutive DHCP renewals can extend the lease time beyond the MCLT.

Range600 to 86399
Unitsseconds
Default 600
Introduced25.3.R2

Platforms

7705 SAR Gen 2

partner-down-delay number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDelay to prevent lease duplication during link failure
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item failover partner-down-delay number
Treepartner-down-delay

Description

This command configures the interval before a failed intercommunication link transitions from the COMM-INT state to the PARTNER-DOWN state. This delay prevents IP lease duplication during link failure by not allowing new IP addresses to be assigned from the remote IP address range. This timer is intended to provide the operator with enough time to remedy the failed situation and avoid duplication of IP addresses and prefixes during the failure.

Range0 to 86399
Unitsseconds
Default 86399
Introduced25.3.R2

Platforms

7705 SAR Gen 2

peer [address] reference
Synopsis Enter the peer list instance
Context configure service vprn service-name dhcp-server dhcpv6 named-item pool named-item failover peer reference
Treepeer
Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sync-tag named-item
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTag that identifies synchronizing server or pool pairs
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item failover peer reference sync-tag named-item
Treesync-tag
String length1 to 32

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

startup-wait-time number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTime between initialization and assuming active role
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item failover startup-wait-time number
Treestartup-wait-time

Description

This command configures a delay that avoids transient issues during the initialization process. During startup wait time, each failover peer waits after the initialization process before assuming the active role for the prefix designated as local or remote.

Range60 to 3600
Unitsseconds
Default 120
Introduced25.3.R2

Platforms

7705 SAR Gen 2

options
Synopsis Enter the options context
Context configure service vprn service-name dhcp-server dhcpv6 named-item pool named-item options
Treeoptions
Introduced25.3.R2

Platforms

7705 SAR Gen 2

option [number] (number | keyword)
Synopsis Enter the option list instance
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item options option (number | keyword)
Treeoption
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[number] (number | keyword)
Synopsis DHCP option to send as identification string
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item options option (number | keyword)
Treeoption
Range1 to 65535
Optionsdns-server, domain-name

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ascii-string string-not-all-spaces
Synopsis DHCP option specified as an ASCII string
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item options option (number | keyword) ascii-string string-not-all-spaces
Treeascii-string
String length1 to 127

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

domain-string string
Synopsis DHCP option specified as a domain name
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item options option (number | keyword) domain-string string
Treedomain-string
String length1 to 127

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

duration number
Synopsis DHCP option specified as time
Context configure service vprn service-name dhcp-server dhcpv6 named-item pool named-item options option (number | keyword) duration number
Treeduration
Range10 to 315446399
Unitsseconds

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

empty
Synopsis Empty DHCP option
Context configure service vprn service-name dhcp-server dhcpv6 named-item pool named-item options option (number | keyword) empty
Treeempty

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

hex-string hex-string
Synopsis DHCP option specified as hexadecimal string
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item options option (number | keyword) hex-string hex-string
Treehex-string
String length1 to 256

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6-address ipv6-address
Synopsis DHCP option specified as a list of IPv6 addresses
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item options option (number | keyword) ipv6-address ipv6-address
Treeipv6-address
Max. instances4

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

This element is ordered by the user.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

prefix [ipv6-prefix] ipv6-prefix
Synopsis Enter the prefix list instance
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item prefix ipv6-prefix
Treeprefix
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ipv6-prefix] ipv6-prefix
Synopsis IPv6 prefix to be excluded from available pool prefixes
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item prefix ipv6-prefix
Treeprefix

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

drain boolean
Synopsis No new leases can be assigned
Context configure service vprn service-name dhcp-server dhcpv6 named-item pool named-item prefix ipv6-prefix drain boolean
Treedrain
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

failover-control-type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisFailover control type for this range
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item prefix ipv6-prefix failover-control-type keyword
Treefailover-control-type
Optionslocal, remote, access-driven
Defaultlocal
Introduced25.3.R2

Platforms

7705 SAR Gen 2

options
Synopsis Enter the options context
Context configure service vprn service-name dhcp-server dhcpv6 named-item pool named-item prefix ipv6-prefix options
Treeoptions
Introduced25.3.R2

Platforms

7705 SAR Gen 2

option [number] (number | keyword)
Synopsis Enter the option list instance
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item prefix ipv6-prefix options option (number | keyword)
Treeoption
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[number] (number | keyword)
Synopsis DHCP option to send as identification string
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item prefix ipv6-prefix options option (number | keyword)
Treeoption
Range1 to 65535
Optionsdns-server, domain-name

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ascii-string string-not-all-spaces
Synopsis DHCP option specified as an ASCII string
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item prefix ipv6-prefix options option (number | keyword) ascii-string string-not-all-spaces
Treeascii-string
String length1 to 127

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

domain-string string
Synopsis DHCP option specified as a domain name
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item prefix ipv6-prefix options option (number | keyword) domain-string string
Treedomain-string
String length1 to 127

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

duration number
Synopsis DHCP option specified as time
Context configure service vprn service-name dhcp-server dhcpv6 named-item pool named-item prefix ipv6-prefix options option (number | keyword) duration number
Treeduration
Range10 to 315446399
Unitsseconds

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

empty
Synopsis Empty DHCP option
Context configure service vprn service-name dhcp-server dhcpv6 named-item pool named-item prefix ipv6-prefix options option (number | keyword) empty
Treeempty

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

hex-string hex-string
Synopsis DHCP option specified as hexadecimal string
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item prefix ipv6-prefix options option (number | keyword) hex-string hex-string
Treehex-string
String length1 to 256

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6-address ipv6-address
Synopsis DHCP option specified as a list of IPv6 addresses
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item prefix ipv6-prefix options option (number | keyword) ipv6-address ipv6-address
Treeipv6-address
Max. instances4

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

This element is ordered by the user.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

preferred-lifetime number
Synopsis Time this lease remains preferred
Context configure service vprn service-name dhcp-server dhcpv6 named-item pool named-item prefix ipv6-prefix preferred-lifetime number
Treepreferred-lifetime

Description

This command configures the preferred lifetime of the IPv6 lease address or prefix. When the preferred lifetime expires, any derived addresses are deprecated. The preferred lifetime must be less than or equal to the valid lifetime. 

Each address or prefix assigned to the client has associated preferred and valid lifetimes specified by the address assignment authority (such as the DHCP server, RADIUS, or ESM). To request an extension of the lifetimes assigned to an address, the client sends a renew message to the addressing authority. The authority sends a reply message to the client with the new lifetimes, allowing the client to continue to use the address/prefix without interruption. The lifetimes are transmitted from the addressing authority to the client in the identity association (IA) option at the top level of the message (not the address or prefix level).

Range300 to 315446399
Unitsseconds
Default 3600
Introduced25.3.R2

Platforms

7705 SAR Gen 2

prefix-length-threshold [prefix-length] number
Synopsis Enter the prefix-length-threshold list instance
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item prefix ipv6-prefix prefix-length-threshold number
Treeprefix-length-threshold
Max. instances8
Introduced25.3.R2

Platforms

7705 SAR Gen 2

prefix-type
Synopsis Enter the prefix-type context
Context configure service vprn service-name dhcp-server dhcpv6 named-item pool named-item prefix ipv6-prefix prefix-type
Treeprefix-type
Introduced25.3.R2

Platforms

7705 SAR Gen 2

pd boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisAllocate IA-PD prefixes from this prefix pool
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item prefix ipv6-prefix prefix-type pd boolean
Treepd
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

wan-host boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisAllocate IA-NA or SLAAC prefixes from this prefix pool
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item prefix ipv6-prefix prefix-type wan-host boolean
Treewan-host
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

rebind-time number
Synopsis Rebind time for the lease
Context configure service vprn service-name dhcp-server dhcpv6 named-item pool named-item prefix ipv6-prefix rebind-time number
Treerebind-time

Description

This command configures the rebind time, known as T2, at which the client contacts the addressing authority to extend the lifetimes of its leases.

The IP addressing authority (such as the DHCP server, RADIUS, or ESM) controls the time for extending lifetimes on assigned addresses/prefixes through the T1 and T2 parameters assigned to an identity association (IA). At renew time, T1, the client initiates a renew or reply message exchange to extend the lifetimes of any addresses in the IA. The client includes an IA option with all addresses or prefixes currently assigned to the IA in its renew message.

Recommended values for T1 and T2 are 0.5 and 0.8 times the shortest preferred lifetime of the addresses or prefixes in the IA that the addressing authority is willing to extend, respectively. The configured rebind timer value should always be less than or equal to the rebind timer. The T1 and T2 values are carried in the IPV6 address option in the IA.

Range0 to 1209600
Unitsseconds
Default 2880
Introduced25.3.R2

Platforms

7705 SAR Gen 2

renew-time number
Synopsis Renew time for the lease
Context configure service vprn service-name dhcp-server dhcpv6 named-item pool named-item prefix ipv6-prefix renew-time number
Treerenew-time

Description

This command configures the renew time, known as T1, at which the client makes a transition to the lease-renewal state.

The IP addressing authority (such as the DHCP server, RADIUS, or ESM) controls the time for extending lifetimes on assigned addresses/prefixes through the T1 and T2 parameters assigned to an identity association (IA). At renew time, T1, the client initiates a renew/reply message exchange to extend the lifetimes of any addresses in the IA. The client includes an IA option with all addresses/prefixes currently assigned to the IA in its renew message.

Recommended values for T1 and T2 are 0.5 and 0.8 times the shortest preferred lifetime of the addresses or prefixes in the IA that the addressing authority is willing to extend, respectively. The configured renew timer value should always be shorter than or equal to the rebind timer. The T1 and T2 values are carried in the IPV6 address option in the IA.

Range0 to 604800
Unitsseconds
Default 1800
Introduced25.3.R2

Platforms

7705 SAR Gen 2

valid-lifetime number
Synopsis Time for the lease to remain valid
Context configure service vprn service-name dhcp-server dhcpv6 named-item pool named-item prefix ipv6-prefix valid-lifetime number
Treevalid-lifetime

Description

This command configures a valid lifetime for a DHCPv6 lease address or prefix. The valid lifetime is the length of time an address and prefix remains in the valid state. The valid lifetime must be greater than or equal to the preferred lifetime. When the valid lifetime expires, the address and prefix becomes invalid and must not be used in communications. RFC 2461 recommends a default value of 30 days.

Each address and prefix assigned to the client has associated preferred and valid lifetimes specified by the address assignment authority (such as the DHCP server, RADIUS, or ESM). To request an extension of the lifetimes assigned to an address, the client sends a renew message to the addressing authority. The authority sends a reply message to the client with the new lifetimes, allowing the client to continue to use the address and prefix without interruption. The lifetimes are transmitted from the addressing authority to the client in the identity association (IA) option at the top level of the message (not the address or prefix level).

Range300 to 315446399
Unitsseconds
Default 86400
Introduced25.3.R2

Platforms

7705 SAR Gen 2

prefix-length-threshold [prefix-length] number
Synopsis Enter the prefix-length-threshold list instance
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool named-item prefix-length-threshold number
Treeprefix-length-threshold
Max. instances8
Introduced25.3.R2

Platforms

7705 SAR Gen 2

pool-selection
Synopsis Enter the pool-selection context
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool-selection
Treepool-selection
Introduced25.3.R2

Platforms

7705 SAR Gen 2

use-link-address
Synopsis Enable the use-link-address context
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool-selection use-link-address
Treeuse-link-address

Description

This command configures the local pool selection for DHCPv6 address or prefix assignment to use the link address. When configured, the selected pool contains a prefix covering the link address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

use-pool-from-client
Synopsis Enable the use-pool-from-client context
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool-selection use-pool-from-client
Treeuse-pool-from-client
Introduced25.3.R2

Platforms

7705 SAR Gen 2

delimiter string-not-all-spaces
Synopsis Delimiter to combine primary and secondary pool names
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item pool-selection use-pool-from-client delimiter string-not-all-spaces
Treedelimiter

Description

This command configures a single ASCII character that separates the pool names in DHCP vendor-specific option 82, which identifies the address pool to be used for this client.

String length1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

server-id
Synopsis Enter the server-id context
Context configure service vprn service-name dhcp-server dhcpv6 named-item server-id
Treeserver-id
Introduced25.3.R2

Platforms

7705 SAR Gen 2

duid-enterprise
Synopsis Enter the duid-enterprise context
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item server-id duid-enterprise
Treeduid-enterprise

Notes

The following elements are part of a choice: duid-enterprise or duid-link-local.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ascii-string string-not-all-spaces
Synopsis DUID enterprise server ID specified as an ASCII string
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item server-id duid-enterprise ascii-string string-not-all-spaces
Treeascii-string
String length1 to 58

Notes

The following elements are part of a choice: ascii-string or hex-string.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

hex-string hex-string
Synopsis DUID enterprise server ID specified as a hex string
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item server-id duid-enterprise hex-string hex-string
Treehex-string
String length1 to 118

Notes

The following elements are part of a choice: ascii-string or hex-string.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

user-identification keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisUser identification method for the DHCP server
Contextconfigure service vprn service-name dhcp-server dhcpv6 named-item user-identification keyword
Treeuser-identification
Optionsduid, interface-id, interface-id-link-local
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dns
Synopsis Enable the dns context
Context configure service vprn service-name dns
Treedns
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of DNS
Context configure service vprn service-name dns admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

default-domain fully-qualified-domain-name
Synopsis Domain name added in DNS retries
Context configure service vprn service-name dns default-domain fully-qualified-domain-name
Treedefault-domain

Description

This command configures the DNS domain name to be added in DNS retries when a DNS query is not replied or an empty DNS reply is received.

The name can contain only alphabetical characters (A-Z), numeric characters (0-9), the minus sign (-), and the period (.).

String length1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4-source-address (keyword | ipv4-unicast-address)
Synopsis Source address to contact an IPv4 DNS server
Contextconfigure service vprn service-name dns ipv4-source-address (keyword | ipv4-unicast-address)
Treeipv4-source-address
Optionsuse-interface-ip
Defaultuse-interface-ip
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6-source-address (keyword | ipv6-unicast-address)
Synopsis Source address to contact an IPv6 DNS server
Contextconfigure service vprn service-name dns ipv6-source-address (keyword | ipv6-unicast-address)
Treeipv6-source-address
Optionsuse-interface-ip
Defaultuse-interface-ip
Introduced25.3.R2

Platforms

7705 SAR Gen 2

server (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis DNS server used for DNS name resolution
Contextconfigure service vprn service-name dns server (ipv4-address-no-zone | ipv6-address-no-zone)
Treeserver
Max. instances3

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ecmp number
Synopsis Maximum equal-cost routes for routing table instance
Contextconfigure service vprn service-name ecmp number
Treeecmp

Description

This command configures ECMP and defines the number of routes for path sharing.

ECMP can be used only for routes learned with the same preference and the same protocol.

If available ECMP routes at the best preference exceed the maximum ECMP routes allowed, the system selects the route using the following criteria:

  1. The system selects the lowest next hop router ID.

  2. If the next hop goes to the same neighbor, the system selects the next hop with the lowest interface index.

Range1 to 64
Default1
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

export-inactive-bgp boolean
Synopsis Export preferred BGP route even if inactive
Contextconfigure service vprn service-name export-inactive-bgp boolean
Treeexport-inactive-bgp

Description

When configured to true, the preferred BGP route learned by a VPRN is exported as the VPN-IP route even if it is inactive in the route table because a preferred BGP VPRN route from another PE is present. This overrides the default state in which the VPRN cannot export an inactive BGP route. For the BGP route to be exported, the VRF export policy must accept it. This command applies to both MPLS VPN and SRv6 VPN routes. In SRv6 VPN routes the advertised instruction is an End.DT, while in MPLS VPN routes the advertised label is a per-next-hop label.This “best-external” type of route advertisement is useful in active/standby multi-homing scenarios because it ensures that all PEs know about the backup path provided by the standby PE.

When configured to false, the preferred BGP route is not exported if it is inactive.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

export-inactive-bgp-enhanced boolean
Synopsis Export best BGP route when better non-BGP route present
Contextconfigure service vprn service-name export-inactive-bgp-enhanced boolean
Treeexport-inactive-bgp-enhanced

Description

When configured to true, the router allows a BGP route that is inactive (because a better non-BGP route for the same prefix is present) to be exportable as a VPN-IP route.

A BGP route learned from a VPRN BGP peer is exportable as a VPN-IP route, only if it is the best route for the prefix and is installed in the route table of the VPRN. If the export-inactive-bgp command is true in the VPRN configuration, this rule is relaxed, and the best inactive VPRN BGP route is exportable as a VPN-IP route, provided that the active installed route for the prefix is an imported VPN-IP route.

The rule described in the preceding paragraph can be relaxed even further by configuring this command to true. When this command is true, the best inactive VPRN BGP route (best amongst all routes received from all CEs) is exportable as a VPN-IP route, regardless of the route type of the active installed route.

The configuration of this command overrides the export-inactive-bgp command. If this command is true, the export-inactive-bgp command does not need to be true.

When configured to false, the router disables allowing an inactive BGP route in the presence of a better non-BGP route to be exportable as a VPN-IP route.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

fib-priority keyword
Synopsis FIB priority for VPRN BGP routes
Context configure service vprn service-name fib-priority keyword
Treefib-priority

Description

This command prioritizes the order in which BGP FIB entries across different routing instances are pushed to the IOM for updating. This allows BGP route updates for higher priority router instances to occur as quickly as possible by assigning a FIB priority to the associated router instances (base and VPRN instances).

If routing updates are available for multiple router instances, the IOMs or IMMs update the FIB with entries with high priority router instances before entries with standard priority router instances.

Options

standard – Standard FIB priority for routing instances

high – High FIB priority for routing instances

Defaultstandard
Introduced25.3.R2

Platforms

7705 SAR Gen 2

grt-leaking
Synopsis Enter the grt-leaking context
Context configure service vprn service-name grt-leaking
Treegrt-leaking
Introduced25.3.R2

Platforms

7705 SAR Gen 2

allow-local-management boolean
Synopsis Enable management traffic
Context configure service vprn service-name grt-leaking allow-local-management boolean
Treeallow-local-management

Description

When configured to true, this command enables the support of specific management protocols over VPRN interfaces that terminate on Base routing context IPv4 and IPv6 interface addresses, including Base loopback and system addresses. 

This command does not control the support for management protocols terminating on VPRN interfaces directly. 

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

export-grt
Synopsis Enter the export-grt context
Context configure service vprn service-name grt-leaking export-grt
Treeexport-grt
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy-name (policy-expr-string | string)
Synopsis Route policy name or policy logical expression
Contextconfigure service vprn service-name grt-leaking export-grt policy-name (policy-expr-string | string)
Treepolicy-name
String length1 to 255
Max. instances5

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

export-limit number
Synopsis Maximum number of routes exported from VRF to GRT
Contextconfigure service vprn service-name grt-leaking export-limit number
Treeexport-limit
Range0 to 1000
Default5
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

import-grt
Synopsis Enter the import-grt context
Context configure service vprn service-name grt-leaking import-grt
Treeimport-grt
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy-name (policy-expr-string | string)
Synopsis Route policy name or policy logical expression
Contextconfigure service vprn service-name grt-leaking import-grt policy-name (policy-expr-string | string)
Treepolicy-name
String length1 to 255
Max. instances5

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

hash-label boolean
Synopsis Include hash label
Context configure service vprn service-name hash-label boolean
Treehash-label
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

igmp
Synopsis Enable the igmp context
Context configure service vprn service-name igmp
Treeigmp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of IGMP
Context configure service vprn service-name igmp admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface [ip-interface-name] interface-name
Synopsis Enter the interface list instance
Contextconfigure service vprn service-name igmp interface interface-name
Treeinterface
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ip-interface-name] interface-name
Synopsis IP interface name
Context configure service vprn service-name igmp interface interface-name
Treeinterface
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of IGMP
Context configure service vprn service-name igmp interface interface-name admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

import-policy reference
Synopsis Import policy that filters IGMP packets
Contextconfigure service vprn service-name igmp interface interface-name import-policy reference
Treeimport-policy

Description

This command configures the IGMP import policy, or filter, for an interface subscriber or a group interface. An IGMP filter is also known as a black or white list, and it is defined as a router policy option.

When redirection is applied, only the import policy from the subscriber is in effect. The import policy under the group interface is applicable only for IGMP states received directly on the SAP (AN in IGMP proxy mode).

Reference

configure policy-options policy-statement named-item-64

Introduced25.3.R2

Platforms

7705 SAR Gen 2

maximum-number-group-sources number
Synopsis Maximum number of group sources for this interface
Contextconfigure service vprn service-name igmp interface interface-name maximum-number-group-sources number
Treemaximum-number-group-sources

Description

This command configures the maximum number of group sources for which IGMP or MLD can have local receiver information based on received IGMP or MLD reports on this interface. When this configuration is changed dynamically to a lower value than the currently accepted number of group sources, the group sources that are already accepted are not deleted. Only new group sources are not allowed.

Range1 to 32000
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ssm-translate
Synopsis Enter the ssm-translate context
Contextconfigure service vprn service-name igmp interface interface-name ssm-translate
Treessm-translate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

group-range start ipv4-multicast-address end ipv4-multicast-address
Synopsis Enter the group-range list instance
Contextconfigure service vprn service-name igmp interface interface-name ssm-translate group-range start ipv4-multicast-address end ipv4-multicast-address
Treegroup-range
Introduced25.3.R2

Platforms

7705 SAR Gen 2

source [source-address] ipv4-unicast-address
Synopsis Add a list entry for source
Context configure service vprn service-name igmp interface interface-name ssm-translate group-range start ipv4-multicast-address end ipv4-multicast-address source ipv4-unicast-address
Treesource
Min. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[source-address] ipv4-unicast-address
Synopsis Source IP address of multicast channel sending data
Contextconfigure service vprn service-name igmp interface interface-name ssm-translate group-range start ipv4-multicast-address end ipv4-multicast-address source ipv4-unicast-address
Treesource

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

static
Synopsis Enter the static context
Context configure service vprn service-name igmp interface interface-name static
Treestatic
Introduced25.3.R2

Platforms

7705 SAR Gen 2

group [group-address] ipv4-multicast-address
Synopsis Enter the group list instance
Context configure service vprn service-name igmp interface interface-name static group ipv4-multicast-address
Treegroup
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[group-address] ipv4-multicast-address
Synopsis Group address of static IGMP multicast channel
Contextconfigure service vprn service-name igmp interface interface-name static group ipv4-multicast-address
Treegroup

Description

This command configures an address that receives data on an interface. The IP address must be unique for each static group.

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

source [source-address] ipv4-unicast-address
Synopsis Add a list entry for source
Context configure service vprn service-name igmp interface interface-name static group ipv4-multicast-address source ipv4-unicast-address
Treesource

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[source-address] ipv4-unicast-address
Synopsis Source IP address of multicast channel sending data
Contextconfigure service vprn service-name igmp interface interface-name static group ipv4-multicast-address source ipv4-unicast-address
Treesource

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

starg
Synopsis any source address (*,G)
Context configure service vprn service-name igmp interface interface-name static group ipv4-multicast-address starg
Treestarg

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

group-range start ipv4-multicast-address end ipv4-multicast-address step ipv4-address
Synopsis Enter the group-range list instance
Contextconfigure service vprn service-name igmp interface interface-name static group-range start ipv4-multicast-address end ipv4-multicast-address step ipv4-address
Treegroup-range
Introduced25.3.R2

Platforms

7705 SAR Gen 2

start ipv4-multicast-address
Synopsis IP address for the start of the static group range
Contextconfigure service vprn service-name igmp interface interface-name static group-range start ipv4-multicast-address end ipv4-multicast-address step ipv4-address
Treegroup-range

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

end ipv4-multicast-address
Synopsis IP address for the end of the static group range
Contextconfigure service vprn service-name igmp interface interface-name static group-range start ipv4-multicast-address end ipv4-multicast-address step ipv4-address
Treegroup-range

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

step ipv4-address
Synopsis Step interval in the group-range address
Contextconfigure service vprn service-name igmp interface interface-name static group-range start ipv4-multicast-address end ipv4-multicast-address step ipv4-address
Treegroup-range
MD-CLI default0.0.0.1

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

source [source-address] ipv4-unicast-address
Synopsis Add a list entry for source
Context configure service vprn service-name igmp interface interface-name static group-range start ipv4-multicast-address end ipv4-multicast-address step ipv4-address source ipv4-unicast-address
Treesource

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[source-address] ipv4-unicast-address
Synopsis Source IP address of multicast channel sending data
Contextconfigure service vprn service-name igmp interface interface-name static group-range start ipv4-multicast-address end ipv4-multicast-address step ipv4-address source ipv4-unicast-address
Treesource

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

starg
Synopsis any source address (*,G)
Context configure service vprn service-name igmp interface interface-name static group-range start ipv4-multicast-address end ipv4-multicast-address step ipv4-address starg
Treestarg

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

version keyword
Synopsis IGMP protocol version
Context configure service vprn service-name igmp interface interface-name version keyword
Treeversion
Options1, 2, 3
Default3
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

query-interval number
Synopsis Time between two consecutive host-query messages
Contextconfigure service vprn service-name igmp query-interval number
Treequery-interval

Description

This command configures the timing of the host-query messages that solicit group membership information. The messages are sent to the all-systems multicast group address, 224.0.0.1.

Range2 to 1024
Unitsseconds
Default 125
Introduced25.3.R2

Platforms

7705 SAR Gen 2

query-last-member-interval number
Synopsis Time between group-specific query messages
Contextconfigure service vprn service-name igmp query-last-member-interval number
Treequery-last-member-interval

Description

This command configures the timing of the query-message interval, defining the interval for leave-group messages among others. The lower the interval that is configured, the faster the detection of the loss of the last member of a group.

Range1 to 1023
Unitsseconds
Default 1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

robust-count number
Synopsis Number of retries after expected message loss
Contextconfigure service vprn service-name igmp robust-count number
Treerobust-count

Description

This command configures the level of expected packet loss on a subnet. If a subnet anticipates losses, this value can be increased.

Range2 to 10
Default2
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

ssm-translate
Synopsis Enter the ssm-translate context
Contextconfigure service vprn service-name igmp ssm-translate
Treessm-translate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

group-range start ipv4-multicast-address end ipv4-multicast-address
Synopsis Enter the group-range list instance
Contextconfigure service vprn service-name igmp ssm-translate group-range start ipv4-multicast-address end ipv4-multicast-address
Treegroup-range
Introduced25.3.R2

Platforms

7705 SAR Gen 2

start ipv4-multicast-address
Synopsis Lower bound of the IP address group range
Contextconfigure service vprn service-name igmp ssm-translate group-range start ipv4-multicast-address end ipv4-multicast-address
Treegroup-range

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

end ipv4-multicast-address
Synopsis Upper bound of the IP address group range
Contextconfigure service vprn service-name igmp ssm-translate group-range start ipv4-multicast-address end ipv4-multicast-address
Treegroup-range

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

source [source-address] ipv4-unicast-address
Synopsis Add a list entry for source
Context configure service vprn service-name igmp ssm-translate group-range start ipv4-multicast-address end ipv4-multicast-address source ipv4-unicast-address
Treesource
Min. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[source-address] ipv4-unicast-address
Synopsis Source IP address of multicast channel sending data
Contextconfigure service vprn service-name igmp ssm-translate group-range start ipv4-multicast-address end ipv4-multicast-address source ipv4-unicast-address
Treesource

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface [interface-name] interface-name
Synopsis Enter the interface list instance
Contextconfigure service vprn service-name interface interface-name
Treeinterface
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[interface-name] interface-name
Synopsis Interface name
Contextconfigure service vprn service-name interface interface-name
Treeinterface
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the interface
Contextconfigure service vprn service-name interface interface-name admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description very-long-description
Synopsis Text description
Context configure service vprn service-name interface interface-name description very-long-description
Treedescription
String length1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dynamic-tunnel-redundant-nexthop ipv4-unicast-address
Synopsis Redundant next-hop address for the dynamic IPsec tunnel
Contextconfigure service vprn service-name interface interface-name dynamic-tunnel-redundant-nexthop ipv4-unicast-address
Treedynamic-tunnel-redundant-nexthop

Description

This command configures a redundant next-hop address on a public or private IPsec interface (with a public or private tunnel SAP) for dynamic IPsec tunnel in 1:1 MC-IPsec. A standby node uses the specified next-hop address to shunt traffic to the master in case it receives traffic destined to a tunnel endpoint address. The standby tunnel group needs to be operationally up for the feature to work.

The next-hop address is resolved in the routing table of a corresponding service.

Notes

The following elements are part of a choice: multi-chassis-shunting-profile or (dynamic-tunnel-redundant-nexthop and static-tunnel-redundant-nexthop).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

hold-time
Synopsis Enter the hold-time context
Context configure service vprn service-name interface interface-name hold-time
Treehold-time
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4
Synopsis Enter the ipv4 context
Context configure service vprn service-name interface interface-name hold-time ipv4
Treeipv4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

down
Synopsis Enter the down context
Context configure service vprn service-name interface interface-name hold-time ipv4 down
Treedown

Description

Commands in this context configure the down hold timer, which specifies the delay before activating the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface up, unless an operator configures the init-only command. 

Introduced25.3.R2

Platforms

7705 SAR Gen 2

init-only boolean
Synopsis Apply delay only at interface configuration or reboot
Contextconfigure service vprn service-name interface interface-name hold-time ipv4 down init-only boolean
Treeinit-only

Description

This command applies a delay only when the IP interface is first configured or after a system reboot.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

up
Synopsis Enter the up context
Context configure service vprn service-name interface interface-name hold-time ipv4 up
Treeup

Description

Commands in this context configure the up hold timer, which specifies the delay before deactivation of the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface down.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6
Synopsis Enter the ipv6 context
Context configure service vprn service-name interface interface-name hold-time ipv6
Treeipv6
Introduced25.3.R2

Platforms

7705 SAR Gen 2

down
Synopsis Enter the down context
Context configure service vprn service-name interface interface-name hold-time ipv6 down
Treedown

Description

Commands in this context configure the down hold timer, which specifies the delay before activation of the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface up, unless an operator configures the init-only command. 

Introduced25.3.R2

Platforms

7705 SAR Gen 2

init-only boolean
Synopsis Apply delay only at interface configuration or reboot
Contextconfigure service vprn service-name interface interface-name hold-time ipv6 down init-only boolean
Treeinit-only

Description

When configured to true, the system applies a delay only when the IP interface is first configured or after a system reboot.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

up
Synopsis Enter the up context
Context configure service vprn service-name interface interface-name hold-time ipv6 up
Treeup

Description

Commands in this context configure the up hold timer, which specifies the delay before deactivation of the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface down.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

if-attribute
Synopsis Enter the if-attribute context
Contextconfigure service vprn service-name interface interface-name if-attribute
Treeif-attribute
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-group reference
Synopsis Administrative group name for the interface
Contextconfigure service vprn service-name interface interface-name if-attribute admin-group reference
Treeadmin-group

Description

This command specifies the administrative group membership to an interface. 

The configured administrative group membership is applied in all levels or areas the interface is participating in. The same interface cannot have different memberships in different levels or areas.

Reference

configure routing-options if-attribute admin-group named-item

Max. instances32
Introduced25.3.R2

Platforms

7705 SAR Gen 2

srlg-group [name] reference
Synopsis Add a list entry for srlg-group
Contextconfigure service vprn service-name interface interface-name if-attribute srlg-group reference
Treesrlg-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ingress
Synopsis Enter the ingress context
Context configure service vprn service-name interface interface-name ingress
Treeingress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-mtu number
Synopsis IP MTU applied to outgoing packets
Context configure service vprn service-name interface interface-name ip-mtu number
Treeip-mtu

Description

This command configures the IP maximum transmission unit (MTU) for the associated router IP interface.

Range512 to 9786
Unitsbytes
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

ip-tunnel-interface boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEnable IP tunnel interface
Contextconfigure service vprn service-name interface interface-name ip-tunnel-interface boolean
Treeip-tunnel-interface

Description

When configured to true, the system enables a GRE virtual IP interface.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipsec
Synopsis Enable the ipsec context
Context configure service vprn service-name interface interface-name ipsec
Treeipsec
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of IPsec secured interface
Contextconfigure service vprn service-name interface interface-name ipsec admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-exception reference
Synopsis IP exception filter
Context configure service vprn service-name interface interface-name ipsec ip-exception reference
Treeip-exception

Description

This command configures the IP exception filter for the secured interface. All ingress traffic matching the specified filter bypasses IPsec processing.

Reference

configure filter ip-exception filter-name

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipsec-tunnel [name] named-item
Synopsis Enter the ipsec-tunnel list instance
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item
Treeipsec-tunnel

Description

Commands in this context configure IPsec tunnels used to secure traffic forwarded over the interface.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[name] named-item
Synopsis IPsec tunnel name
Context configure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item
Treeipsec-tunnel
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the bfd context
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item bfd
Treebfd
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd-designate boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDesignate IPsec tunnel to carry BFD traffic
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item bfd bfd-designate boolean
Treebfd-designate
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd-liveness
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the bfd-liveness context
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item bfd bfd-liveness
Treebfd-liveness

Description

Commands in this context configure a BFD session to provide a heart-beat mechanism for a specified IPsec tunnel. There can be only one BFD session assigned to any given IPsec tunnel, but there can be multiple IPsec tunnels using the same BFD session.

BFD controls the state of the association tunnel. If the BFD session goes down, the system brings down the associated non-designated IPsec tunnel.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

dest-ip ipv4-unicast-address
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDestination address used for the BFD session
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item bfd bfd-liveness dest-ip ipv4-unicast-address
Treedest-ip

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface interface-name
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisName of the interface used by the BFD session
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item bfd bfd-liveness interface interface-name
Treeinterface
String length1 to 32

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

service-name service-name
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative service name
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item bfd bfd-liveness service-name service-name
Treeservice-name

Description

This command configures the name of the service where BFD traffic is forwarded to.

String length1 to 64

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

clear-df-bit boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisReset the DF bit to 0 in all payload IP packets
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item clear-df-bit boolean
Treeclear-df-bit

Description

When configured to true, the DF bit is set to 0 in all payload IP packets associated with the IPsec tunnel, before any potential fragmentation occurs.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

copy-traffic-class-upon-decapsulation boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable traffic class copy upon decapsulation
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item copy-traffic-class-upon-decapsulation boolean
Treecopy-traffic-class-upon-decapsulation

Description

When configured to true, the system copies the traffic class from the outer tunnel IP packet header to the payload IP packet header in the decapsulating direction (public to private).

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

encapsulated-ip-mtu number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum size of the encapsulated tunnel packet
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item encapsulated-ip-mtu number
Treeencapsulated-ip-mtu

Description

This command specifies the maximum size of the encapsulated tunnel packet to the IPsec tunnel, the IP tunnel, or the dynamic tunnels terminated on the IPsec Gateway. If the encapsulated IPv4 or IPv6 tunnel packet exceeds this value, the system fragments the packet.

Range512 to 9000
Unitsbytes
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

icmp-generation
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the icmp-generation context
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item icmp-generation
Treeicmp-generation

Description

Commands in this context configure settings for ICMPv4 message generation.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

frag-required
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the frag-required context
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item icmp-generation frag-required
Treefrag-required

Description

Commands in this context configure the attributes for sending generated ICMP Destination Unreachable "fragmentation needed and DF set" messages (type 3, code 4) back to the source, if the received size of the IPv4 packet on the private side exceeds the private MTU size.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of sending ICMP messages
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item icmp-generation frag-required admin-state keyword
Treeadmin-state

Description

This command configures the administrative state of sending ICMP Destination Unreachable "fragmentation needed, DF set" messages (type 3, code 4) messages to the source if the received size of the IPv4 packet on the private side exceeds the private MTU size.

Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interval number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisInterval for sending ICMP messages
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item icmp-generation frag-required interval number
Treeinterval

Description

This command configures the interval for sending ICMP Destination Unreachable "fragmentation needed, DF set" messages (type 3, code 4).

Range1 to 60
Unitsseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

message-count number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of ICMP messages that can be sent
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item icmp-generation frag-required message-count number
Treemessage-count

Description

This command configures the maximum number of ICMP Destination Unreachable "fragmentation needed, DF set" messages (type 3, code 4) that can be sent during the configured interval.

Range10 to 1000
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

icmp6-generation
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the icmp6-generation context
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item icmp6-generation
Treeicmp6-generation

Description

Commands in this context configure settings for ICMPv6 message generation.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

packet-too-big
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the packet-too-big context
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item icmp6-generation packet-too-big
Treepacket-too-big

Description

Commands in this context configure the parameters to send ICMPv6 PTB (Packet Too Big) messages on the private side.

The system sends PTB messages if a received IPv6 packet on the private side is greater than 1280 bytes and it exceeds the private MTU of the tunnel.

The private MTU for the tunnel is configured via the configure router interface ipsec ipsec-tunnel ip-mtu command for the interface.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of Packet Too Big message sends
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item icmp6-generation packet-too-big admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interval number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisInterval for sending Packet Too Big messages
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item icmp6-generation packet-too-big interval number
Treeinterval
Range1 to 60
Unitsseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

message-count number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of ICMPv6 PTB messages that can be sent
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item icmp6-generation packet-too-big message-count number
Treemessage-count

Description

This command configures the maximum number of PTB messages that can be sent during the configured interval.

Range10 to 1000
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

ip-mtu number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPrivate MTU of the IPsec tunnel
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item ip-mtu number
Treeip-mtu

Description

This command specifies the private MTU of the IPsec tunnel. The private MTU is used to determine the need for fragmentation before encapsulation of the payload packet.

Range512 to 9000
Unitsbytes
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

key-exchange
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the key-exchange context
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange
Treekey-exchange
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dynamic
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the dynamic context
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic
Treedynamic

Notes

The following elements are part of a choice: dynamic or manual.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

auto-establish boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAttempt to establish a phase 1 exchange automatically
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic auto-establish boolean
Treeauto-establish
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

cert
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the cert context
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic cert
Treecert

Description

Commands in this context configure the attributes of the dynamic keying certificate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

status-verify
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the status-verify context
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic cert status-verify
Treestatus-verify

Description

Commands in this context configure attributes of Certificate Status Verification (CSV).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

primary keyword
Synopsis Primary method of CSV to verify the revocation status
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic cert status-verify primary keyword
Treeprimary

Description

This command configures the primary method of Certificate Status Verification (CSV) that is used to verify the revocation status of the certificate of the peer.

Optionscrl, ocsp
Default crl
Introduced25.3.R2

Platforms

7705 SAR Gen 2

secondary keyword
Synopsis Secondary method used to verify certificate revocation
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic cert status-verify secondary keyword
Treesecondary

Description

This command specifies the secondary method of Certificate Status Verification (CSV) that is used to verify the revocation status of the peer certificate.

Optionsnone, crl, ocsp
Defaultnone
Introduced25.3.R2

Platforms

7705 SAR Gen 2

id
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the id context
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic id
Treeid

Description

Commands in this context specify the local ID used for IDi or IDr for IKEv2 negotiation.

The default behavior depends on the local authentication method as follows:

  • Psk: local tunnel IP address

  • Cert-auth: subject of the local certificate

Introduced25.3.R2

Platforms

7705 SAR Gen 2

fqdn fully-qualified-domain-name
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisFQDN used as the local ID IKE type
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic id fqdn fully-qualified-domain-name
Treefqdn
String length1 to 255

Notes

The following elements are part of a choice: fqdn, ipv4, or ipv6.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4 ipv4-unicast-address
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPv4 as the local ID type
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic id ipv4 ipv4-unicast-address
Treeipv4

Notes

The following elements are part of a choice: fqdn, ipv4, or ipv6.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPv6 used as the local IKE ID type
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic id ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
Treeipv6

Notes

The following elements are part of a choice: fqdn, ipv4, or ipv6.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ike-policy reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIKE policy ID
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic ike-policy reference
Treeike-policy

Description

This command specifies the ID of the IKE policy used for IKE negotiation.

The ipsec-transport-mode-profile configuration only supports IKEv2.

Reference

configure ipsec ike-policy number

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipsec-transform reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPsec transform IDs used by the dynamic key
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic ipsec-transform reference
Treeipsec-transform

Description

This command specifies IPsec transform IDs used for CHILD_SA negotiation.

Reference

configure ipsec ipsec-transform number

Max. instances4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ppk
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the ppk context
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic ppk
Treeppk

Description

Commands in this context configure the PPKs to use for dynamic keying of the IPsec tunnel.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

id reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPPK ID
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic ppk id reference
Treeid

Reference

configure ipsec ppk-list named-item ppk named-item-64

Introduced25.3.R2

Platforms

7705 SAR Gen 2

list reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPPK list instance name
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic ppk list reference
Treelist

Reference

configure ipsec ppk-list named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

pre-shared-key encrypted-leaf
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPre-shared key for authentication
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange dynamic pre-shared-key encrypted-leaf
Treepre-shared-key
String length1 to 115
Introduced25.3.R2

Platforms

7705 SAR Gen 2

manual
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the manual context
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange manual
Treemanual

Description

Commands in this context configure settings for manually configured security associations for the IPsec tunnel.

Notes

The following elements are part of a choice: dynamic or manual.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

keys [security-association] number direction keyword
Synopsis Enter the keys list instance
Context configure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange manual keys number direction keyword
Treekeys

Description

Commands in this context configure the security association list for the tunnel.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

spi number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSPI of inbound and outbound packets
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item key-exchange manual keys number direction keyword spi number
Treespi

Description

This command specifies the Security Parameter Index (SPI) used to look up the instruction to verify and decrypt the incoming IPsec packets when the direction is inbound. When the direction is outbound, the SPI is used in the encoding of the outgoing packets.

The remote node can use the SPI to look up the instruction to verify and decrypt the packet.

Range256 to 16383

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

local-gateway-address-override (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal IPsec tunnel endpoint address
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item local-gateway-address-override (ipv4-address-no-zone | ipv6-address-no-zone)
Treelocal-gateway-address-override

Description

This command configures the local IPsec tunnel endpoint address. This overrides the default endpoint address, which is the interface address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

max-history-key-records
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the max-history-key-records context
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item max-history-key-records
Treemax-history-key-records

Description

Commands in this context configure the settings for recording historical IPsec keys.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

esp number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of recent records
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item max-history-key-records esp number
Treeesp
Range1 to 48
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ike number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of historical IKE key records
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item max-history-key-records ike number
Treeike
Range1 to 3
Introduced25.3.R2

Platforms

7705 SAR Gen 2

pmtu-discovery-aging number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAging out time of the learned path MTU
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item pmtu-discovery-aging number
Treepmtu-discovery-aging

Description

This command configures the temporary public and private MTU expiration time. The temporary MTU is used for MTU propagation.

Range900 to 3600
Unitsseconds
Default 900
Introduced25.3.R2

Platforms

7705 SAR Gen 2

private-sap number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPrivate SAP ID
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item private-sap number
Treeprivate-sap
Range0 to 4094

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

private-service service-name
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPrivate service name
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item private-service service-name
Treeprivate-service

Description

This command configures the private service name.

If unconfigured, the private service is the service where the secured interface resides.

String length1 to 64
Introduced25.3.R2

Platforms

7705 SAR Gen 2

private-tcp-mss-adjust number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTCP maximum segment size (MSS) adjustment
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item private-tcp-mss-adjust number
Treeprivate-tcp-mss-adjust

Description

This command specifies the TCP MSS to adjust for the tunnel on the private side.

When configured, the system may use the value to update the MSS option in the received TCP SYN packet on the private side.

Range512 to 9000
Unitsbytes
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

propagate-pmtu-v4 boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable propagation of the path MTU to IPv4 hosts
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item propagate-pmtu-v4 boolean
Treepropagate-pmtu-v4

Description

When configured to true, the system propagates the path MTU learned from the public side to the private side (IPv4 hosts).

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

propagate-pmtu-v6 boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable propagation of the path MTU to IPv6 hosts
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item propagate-pmtu-v6 boolean
Treepropagate-pmtu-v6

Description

When configured to true, the system propagates the path MTU learned from the public side to the private side (IPv6 hosts).

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

public-tcp-mss-adjust (number | keyword)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTCP maximum segment size (MSS) on the public network
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item public-tcp-mss-adjust (number | keyword)
Treepublic-tcp-mss-adjust

Description

This command configures the MSS for the TCP traffic in an IPsec tunnel that is sent from the public network to the private network. The system may use this value to adjust or insert the MSS option in the TCP SYN packet.

Range512 to 9000
Unitsbytes
Options auto
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

remote-gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRemote IPsec tunnel endpoint address
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item remote-gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeremote-gateway-address
Introduced25.3.R2

Platforms

7705 SAR Gen 2

replay-window number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAnti-replay window size
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item replay-window number
Treereplay-window

Description

This command specifies the size of an IPsec anti-replay window. If unconfigured, IPsec anti-replay is disabled.

Range32 | 64 | 128 | 256 | 512
Unitspackets
Introduced25.3.R2

Platforms

7705 SAR Gen 2

security-policy
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the security-policy context
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item security-policy
Treesecurity-policy

Description

Commands in this context specify a security policy used by the tunnel.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

id number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSecurity policy ID for use by the tunnel
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item security-policy id number
Treeid
Max. range0 to 4294967295
Introduced25.3.R2

Platforms

7705 SAR Gen 2

strict-match boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable strict match of the security policy entry
Contextconfigure service vprn service-name interface interface-name ipsec ipsec-tunnel named-item security-policy strict-match boolean
Treestrict-match

Description

When configured to true, this command enables strict match of the security policy entry.

When a CREATE_CHILD exchange request is received for a static IPsec tunnel, and this request is not a rekey request, ISA matches the received TSi and TSr with the configured security policy. This can be a match only when a received TS (in TSi or TSr) address range matches exactly with the subnet in a security policy entry.

If there is no match, the setup fails, and TS_UNACCEPTABLE is sent.

If there is a match, but there is an existing CHILD_SA for the matched security policy, the setup fails, and NO_PROPOSAL_CHOSEN is sent.

If there is a match, and there is not a CHILD_SA for the matched entry, the subnet is sent in the matched security policy entry as TSi and TSr, and the CHILD_SA is created.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6-exception reference
Synopsis IPv6 filter exception used to bypass encryption
Contextconfigure service vprn service-name interface interface-name ipsec ipv6-exception reference
Treeipv6-exception

Description

This command specifies the IPv6 filter exception for an IPsec-secured IPv6 interface. When an IPv6 filter exception is added, clear text packets that match the exception criteria in the IPv6 filter exception can ingress the interface, even when IPsec is enabled on the interface.

Reference

configure filter ipv6-exception filter-name

Introduced25.3.R2

Platforms

7705 SAR Gen 2

public-sap number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPublic SAP ID
Contextconfigure service vprn service-name interface interface-name ipsec public-sap number
Treepublic-sap
Range0 to 4094

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

tunnel-group reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTunnel group ID
Contextconfigure service vprn service-name interface interface-name ipsec tunnel-group reference
Treetunnel-group

Reference

configure isa tunnel-group number

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4
Synopsis Enter the ipv4 context
Context configure service vprn service-name interface interface-name ipv4
Treeipv4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

addresses
Synopsis Enter the addresses context
Context configure service vprn service-name interface interface-name ipv4 addresses
Treeaddresses
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address [ipv4-address] ipv4-unicast-address
Synopsis Enter the address list instance
Contextconfigure service vprn service-name interface interface-name ipv4 addresses address ipv4-unicast-address
Treeaddress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ipv4-address] ipv4-unicast-address
Synopsis IPv4 address for the interface
Context configure service vprn service-name interface interface-name ipv4 addresses address ipv4-unicast-address
Treeaddress

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd
Synopsis Enter the bfd context
Context configure service vprn service-name interface interface-name ipv4 bfd
Treebfd
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of BFD sessions
Context configure service vprn service-name interface interface-name ipv4 bfd admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

echo-receive number
Synopsis Minimum echo interval over this interface
Contextconfigure service vprn service-name interface interface-name ipv4 bfd echo-receive number
Treeecho-receive
Range100 to 100000
Unitsmilliseconds
Introduced25.3.R2

Platforms

7705 SAR Gen 2

multiplier number
Synopsis Number of consecutive BFD messages missed from the peer
Contextconfigure service vprn service-name interface interface-name ipv4 bfd multiplier number
Treemultiplier

Description

This command configures the number of missed messages before the BFD session state is changed to down and the upper-level protocol is notified of the fault. A multiplier of less than 3 should not be used in production environments. 

Range1 to 20
Default3
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

receive number
Synopsis BFD receive interval over this interface
Contextconfigure service vprn service-name interface interface-name ipv4 bfd receive number
Treereceive

Description

This command specifies the receive interval for the BFD session.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

transmit-interval number
Synopsis BFD transmit interval over this interface
Contextconfigure service vprn service-name interface interface-name ipv4 bfd transmit-interval number
Treetransmit-interval

Description

This command configures the transmit intervals.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

dhcp
Synopsis Enter the dhcp context
Context configure service vprn service-name interface interface-name ipv4 dhcp
Treedhcp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

gi-address ipv4-unicast-address
Synopsis GI address for the DHCP relay
Context configure service vprn service-name interface interface-name ipv4 dhcp gi-address ipv4-unicast-address
Treegi-address

Description

This command configures the GI address to distinguish between the different subscriber interfaces (and potentially group interfaces) defined when the router functions as a DHCP relay.

By default, the GI address used in the relayed DHCP packet is the primary IP address of a normal IES interface. Specifying the GI address allows the user to choose a secondary address. For group interfaces, a GI address must be specified under the group interface DHCP context or subscriber interface DHCP context for DHCP to function.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

option-82
Synopsis Enter the option-82 context
Context configure service vprn service-name interface interface-name ipv4 dhcp option-82
Treeoption-82

Description

Commands in this context configure the processing required when the router receives a DHCP request that already has an Option 82 field in the packet.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

action keyword
Synopsis Action to take with received DHCP Option 82
Contextconfigure service vprn service-name interface interface-name ipv4 dhcp option-82 action keyword
Treeaction
Optionsreplace, drop, keep
Defaultkeep
Introduced25.3.R2

Platforms

7705 SAR Gen 2

circuit-id
Synopsis Enter the circuit-id context
Context configure service vprn service-name interface interface-name ipv4 dhcp option-82 circuit-id
Treecircuit-id
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ifindex
Synopsis Use the interface index for the circuit ID
Contextconfigure service vprn service-name interface interface-name ipv4 dhcp option-82 circuit-id ifindex
Treeifindex

Notes

The following elements are part of a choice: ascii-tuple, ifindex, none, sap-id, or vlan-ascii-tuple.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

none
Synopsis Do not include the circuit ID
Context configure service vprn service-name interface interface-name ipv4 dhcp option-82 circuit-id none
Treenone

Notes

The following elements are part of a choice: ascii-tuple, ifindex, none, sap-id, or vlan-ascii-tuple.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

sap-id
Synopsis Use the SAP ID
Contextconfigure service vprn service-name interface interface-name ipv4 dhcp option-82 circuit-id sap-id
Treesap-id

Notes

The following elements are part of a choice: ascii-tuple, ifindex, none, sap-id, or vlan-ascii-tuple.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

vlan-ascii-tuple
Synopsis Include the VLAN ID and dot1p bits in the ASCII tuple
Contextconfigure service vprn service-name interface interface-name ipv4 dhcp option-82 circuit-id vlan-ascii-tuple
Treevlan-ascii-tuple

Description

When configured, the router includes the VLAN ID and dot1p bits with the ASCII-tuple information. This only occurs on dot1q and QinQ-encapsulated ports. When the Option 82 bits are stripped, dot1p bits are copied to the Ethernet header of the outgoing packet.

When unconfigured, the router leaves the circuit ID sub-option of the DHCP packet empty.

Notes

The following elements are part of a choice: ascii-tuple, ifindex, none, sap-id, or vlan-ascii-tuple.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

remote-id
Synopsis Enter the remote-id context
Context configure service vprn service-name interface interface-name ipv4 dhcp option-82 remote-id
Treeremote-id

Description

Commands in this context configure the remote IP sub-option of the DHCP packet with the identity of the remote host end (typically the DHCP client).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ascii-string string-not-all-spaces
Synopsis User-defined ASCII string for the remote ID
Contextconfigure service vprn service-name interface interface-name ipv4 dhcp option-82 remote-id ascii-string string-not-all-spaces
Treeascii-string
String length1 to 32

Notes

The following elements are part of a choice: ascii-string, mac, or none.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac
Synopsis Use the MAC address for the remote ID
Contextconfigure service vprn service-name interface interface-name ipv4 dhcp option-82 remote-id mac
Treemac

Notes

The following elements are part of a choice: ascii-string, mac, or none.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

none
Synopsis Do not include the remote ID
Context configure service vprn service-name interface interface-name ipv4 dhcp option-82 remote-id none
Treenone

Notes

The following elements are part of a choice: ascii-string, mac, or none.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

vendor-specific-option
Synopsis Enter the vendor-specific-option context
Contextconfigure service vprn service-name interface interface-name ipv4 dhcp option-82 vendor-specific-option
Treevendor-specific-option

Description

Commands in this context configure the Nokia Vendor-Specific Option (VSO) of the DHCP packet.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

proxy-server
Synopsis Enter the proxy-server context
Contextconfigure service vprn service-name interface interface-name ipv4 dhcp proxy-server
Treeproxy-server
Introduced25.3.R2

Platforms

7705 SAR Gen 2

emulated-server ipv4-unicast-address
Synopsis IP address used as the DHCP server address for the SAP
Contextconfigure service vprn service-name interface interface-name ipv4 dhcp proxy-server emulated-server ipv4-unicast-address
Treeemulated-server

Description

This command configures the IP address which will be used as the DHCP server address in the context of the SAP. Typically, the configured address should be in the context of the subnet represented by the service.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lease-time
Synopsis Enter the lease-time context
Context configure service vprn service-name interface interface-name ipv4 dhcp proxy-server lease-time
Treelease-time
Introduced25.3.R2

Platforms

7705 SAR Gen 2

relay-proxy
Synopsis Enable the relay-proxy context
Contextconfigure service vprn service-name interface interface-name ipv4 dhcp relay-proxy
Treerelay-proxy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

server ipv4-unicast-address
Synopsis IP addresses for DHCP server requests
Contextconfigure service vprn service-name interface interface-name ipv4 dhcp server ipv4-unicast-address
Treeserver

Description

This command configures a list of servers that this interface forwards requests to.

The operator can enter the list of servers as either IP addresses or fully qualified domain names. The operator must specify at least one server specified for DHCP relay to work. If there are multiple servers, the system forwards the request to all the servers in the list.

Max. instances8

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

src-ip-addr keyword
Synopsis Type of source address to use for DHCP relay
Contextconfigure service vprn service-name interface interface-name ipv4 dhcp src-ip-addr keyword
Treesrc-ip-addr
Optionsauto, gi-address
Default auto
Introduced25.3.R2

Platforms

7705 SAR Gen 2

trusted boolean
Synopsis Relay untrusted packets
Context configure service vprn service-name interface interface-name ipv4 dhcp trusted boolean
Treetrusted

Description

When configured to true, the router enables the trusted mode on the interface. When enabled, the relay agent changes the existing GI address (of the request) to the ingress interface, and forwards the request.

A DHCP request that contains a GI address of 0.0.0.0 and an Option 82 field in the packet is discarded unless it arrives on a trusted circuit.

This behavior only applies if the Relay Agent Information Option action is to keep the existing information. When the Option 82 field is replaced by the relay agent, the original Option 82 information is lost, and there is no reason to enable the trusted option.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

use-arp boolean
Synopsis Use ARP to determine the destination hardware address
Contextconfigure service vprn service-name interface interface-name ipv4 dhcp use-arp boolean
Treeuse-arp
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

icmp
Synopsis Enter the icmp context
Context configure service vprn service-name interface interface-name ipv4 icmp
Treeicmp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mask-reply boolean
Synopsis Allow responses to ICMP mask requests on the interface
Contextconfigure service vprn service-name interface interface-name ipv4 icmp mask-reply boolean
Treemask-reply
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

param-problem
Synopsis Enter the param-problem context
Contextconfigure service vprn service-name interface interface-name ipv4 icmp param-problem
Treeparam-problem

Description

Commands in this context specify the settings for ICMP Parameter Problem messages generated by the interface.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

seconds number
Synopsis Time used to limit number of Parameter Problem messages
Contextconfigure service vprn service-name interface interface-name ipv4 icmp param-problem seconds number
Treeseconds
Range1 to 60
Unitsseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

redirects
Synopsis Enter the redirects context
Context configure service vprn service-name interface interface-name ipv4 icmp redirects
Treeredirects

Description

Commands in this context configure the settings for ICMP redirect messages generated by the interface.

The system sends ICMP redirect messages to alert the sending node that a more optimal route is available on another router on the same subnetwork.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

number number
Synopsis Maximum number of ICMP redirect messages to send
Contextconfigure service vprn service-name interface interface-name ipv4 icmp redirects number number
Treenumber
Range10 to 1000
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

seconds number
Synopsis Time used to limit the number of ICMP redirect messages
Contextconfigure service vprn service-name interface interface-name ipv4 icmp redirects seconds number
Treeseconds
Range1 to 60
Unitsseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ttl-expired
Synopsis Enter the ttl-expired context
Context configure service vprn service-name interface interface-name ipv4 icmp ttl-expired
Treettl-expired

Description

Commands in this context configure the settings for ICMP TTL expired messages generated by the interface.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

seconds number
Synopsis Time used to limit the number of TTL expired messages
Contextconfigure service vprn service-name interface interface-name ipv4 icmp ttl-expired seconds number
Treeseconds
Range1 to 60
Unitsseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

unreachables
Synopsis Enter the unreachables context
Contextconfigure service vprn service-name interface interface-name ipv4 icmp unreachables
Treeunreachables

Description

Commands in this context specify the settings for ICMP host and network destination unreachable messages generated by the interface.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

seconds number
Synopsis Time to limit the number of ICMP unreachable messages
Contextconfigure service vprn service-name interface interface-name ipv4 icmp unreachables seconds number
Treeseconds
Range1 to 60
Unitsseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

neighbor-discovery
Synopsis Enter the neighbor-discovery context
Contextconfigure service vprn service-name interface interface-name ipv4 neighbor-discovery
Treeneighbor-discovery
Introduced25.3.R2

Platforms

7705 SAR Gen 2

host-route
Synopsis Enter the host-route context
Context configure service vprn service-name interface interface-name ipv4 neighbor-discovery host-route
Treehost-route
Introduced25.3.R2

Platforms

7705 SAR Gen 2

populate [route-type] keyword
Synopsis Enter the populate list instance
Contextconfigure service vprn service-name interface interface-name ipv4 neighbor-discovery host-route populate keyword
Treepopulate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-tag number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTag value used with the host route from an ARP/ND entry
Contextconfigure service vprn service-name interface interface-name ipv4 neighbor-discovery host-route populate keyword route-tag number
Treeroute-tag

Description

This command specifies the route tag that is added in the route table for ARP or ND host routes. This tag can be matched on BGP VRF export and BGP peer export policies.

Range1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

learn-unsolicited boolean
Synopsis Learn new entries from any received NA message
Contextconfigure service vprn service-name interface interface-name ipv4 neighbor-discovery learn-unsolicited boolean
Treelearn-unsolicited

Description

When configured to true, the router can learn neighbor entries from received unsolicited Neighbor Advertisement (NA) messages, with or without the solicited (S) flag set. The command can be enabled for global addresses, link-local addresses, or for both.

When configured to false, the router follows standard behavior for learning neighbor entries.

  • If an unsolicited NA (regardless of the S flag) is received from a neighbor that is not yet in the Neighbor Discovery (ND) cache, the NA is ignored.

  • If an NS, RS, RA, or Redirect message with a Link Layer Address (MAC) is received from a neighbor that is not yet in the ND cache, a new neighbor entry is created in the cache to store the received Link Layer MAC. The neighbor is put in the STALE state.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

limit
Synopsis Enter the limit context
Context configure service vprn service-name interface interface-name ipv4 neighbor-discovery limit
Treelimit
Introduced25.3.R2

Platforms

7705 SAR Gen 2

local-proxy-arp boolean
Synopsis Enable local proxy ARP on interface
Context configure service vprn service-name interface interface-name ipv4 neighbor-discovery local-proxy-arp boolean
Treelocal-proxy-arp

Description

When configured to true, the router enables local proxy ARP on the interface.

When configured to false, the router does not respond to ARP requests for addresses on the same subnet.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

proactive-refresh boolean
Synopsis Send a single refresh message before entry timeout
Contextconfigure service vprn service-name interface interface-name ipv4 neighbor-discovery proactive-refresh boolean
Treeproactive-refresh

Description

When configured to true, the router always sends a refresh message 30 seconds before the timeout of the entry (a single refresh message with no retries).

When configured to false, the router marks an entry as stale 30 seconds before age-out, and the router only sends an ARP request to refresh the entry if the IOM receives traffic that uses it. Then, the IOM asks the ARP application to send a refresh message. With ARP proactive refresh enabled, the ARP module sends a refresh message regardless of the IOM receiving traffic.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static-neighbor [ipv4-address] ipv4-address
Synopsis Enter the static-neighbor list instance
Contextconfigure service vprn service-name interface interface-name ipv4 neighbor-discovery static-neighbor ipv4-address
Treestatic-neighbor
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static-neighbor-unnumbered
Synopsis Enable the static-neighbor-unnumbered context
Contextconfigure service vprn service-name interface interface-name ipv4 neighbor-discovery static-neighbor-unnumbered
Treestatic-neighbor-unnumbered
Introduced25.3.R2

Platforms

7705 SAR Gen 2

timeout number
Synopsis Timeout for an ARP entry learned on the interface
Contextconfigure service vprn service-name interface interface-name ipv4 neighbor-discovery timeout number
Treetimeout

Description

This command configures the minimum time an ARP entry learned on the IP interface is stored in the ARP table. ARP entries are automatically refreshed when an ARP request or gratuitous ARP is seen by an IP host. Otherwise, the ARP entry is aged from the ARP table.

Range0 to 65535
Unitsseconds
Default 14400
Introduced25.3.R2

Platforms

7705 SAR Gen 2

primary
Synopsis Enable the primary context
Context configure service vprn service-name interface interface-name ipv4 primary
Treeprimary
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address ipv4-unicast-address
Synopsis Primary IPv4 address assigned to the interface
Contextconfigure service vprn service-name interface interface-name ipv4 primary address ipv4-unicast-address
Treeaddress

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

broadcast keyword
Synopsis Broadcast address format
Context configure service vprn service-name interface interface-name ipv4 primary broadcast keyword
Treebroadcast
Optionsall-ones, host-ones
Default host-ones
Introduced25.3.R2

Platforms

7705 SAR Gen 2

secondary [address] ipv4-unicast-address
Synopsis Enter the secondary list instance
Contextconfigure service vprn service-name interface interface-name ipv4 secondary ipv4-unicast-address
Treesecondary
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[address] ipv4-unicast-address
Synopsis Secondary IPv4 address assigned to the interface
Contextconfigure service vprn service-name interface interface-name ipv4 secondary ipv4-unicast-address
Treesecondary

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

broadcast keyword
Synopsis Broadcast address format
Context configure service vprn service-name interface interface-name ipv4 secondary ipv4-unicast-address broadcast keyword
Treebroadcast
Optionsall-ones, host-ones
Default host-ones
Introduced25.3.R2

Platforms

7705 SAR Gen 2

igp-inhibit boolean
Synopsis Disable the running IGP from recognizing secondary IP
Contextconfigure service vprn service-name interface interface-name ipv4 secondary ipv4-unicast-address igp-inhibit boolean
Treeigp-inhibit

Description

When configured to true, the running IGP does not recognize the secondary IP address as a local interface.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

tcp-mss number
Synopsis TCP maximum segment size for the interface
Contextconfigure service vprn service-name interface interface-name ipv4 tcp-mss number
Treetcp-mss
Range384 to 9746
Introduced25.3.R2

Platforms

7705 SAR Gen 2

unnumbered
Synopsis Enter the unnumbered context
Context configure service vprn service-name interface interface-name ipv4 unnumbered
Treeunnumbered
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-address ipv4-unicast-address
Synopsis IP address for the interface
Context configure service vprn service-name interface interface-name ipv4 unnumbered ip-address ipv4-unicast-address
Treeip-address

Notes

The following elements are part of a choice: ip-address or ip-int-name.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-int-name interface-name
Synopsis IP interface name
Context configure service vprn service-name interface interface-name ipv4 unnumbered ip-int-name interface-name
Treeip-int-name
String length1 to 32

Notes

The following elements are part of a choice: ip-address or ip-int-name.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

urpf-check
Synopsis Enable the urpf-check context
Context configure service vprn service-name interface interface-name ipv4 urpf-check
Treeurpf-check
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mode keyword
Synopsis Unicast RPF check mode
Context configure service vprn service-name interface interface-name ipv4 urpf-check mode keyword
Treemode
Options

strict – Check source address match in RT and interface

loose – Check source address match in RT only

strict-no-ecmp – Check source address match in ECMP route

Defaultstrict
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vrrp [virtual-router-id] number
Synopsis Enter the vrrp list instance
Context configure service vprn service-name interface interface-name ipv4 vrrp number
Treevrrp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[virtual-router-id] number
Synopsis Virtual Router Identifier (VRID) for the IP interface
Contextconfigure service vprn service-name interface interface-name ipv4 vrrp number
Treevrrp
Range1 to 255

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of VRRP
Context configure service vprn service-name interface interface-name ipv4 vrrp number admin-state keyword
Treeadmin-state

Description

The command determines the administrative state of non-owner virtual router instances.

Non-owner virtual router instances can be administratively disabled. This allows the termination of VRRP participation in the virtual router and stops all routing and other access capabilities with regards to the virtual router IP addresses. Disabling the virtual router instance provides a mechanism to maintain the virtual routers without causing false backup or master state changes.

When disabled, no VRRP advertisement messages are generated and all received VRRP advertisement messages are silently discarded with no processing.

Whenever the administrative or operational state of a virtual router instance transitions, a log message is generated.

An owner virtual router context does not use this command. To administratively disable an owner virtual router instance, use the admin-state command within the parent IP interface node which administratively disables the IP interface.

Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

authentication-key encrypted-leaf
Synopsis Password for simple text authentication
Contextconfigure service vprn service-name interface interface-name ipv4 vrrp number authentication-key encrypted-leaf
Treeauthentication-key

Description

This command optionally assigns a simple text password authentication key to generate master VRRP advertisement messages and validate received VRRP advertisement messages.

If this command is re-executed with a different password key defined, the new key immediately replaces the old key. This command may be executed at any time. 

String length1 to 38
Introduced25.3.R2

Platforms

7705 SAR Gen 2

backup ipv4-unicast-address
Synopsis Virtual router IP addresses for the interface
Contextconfigure service vprn service-name interface interface-name ipv4 vrrp number backup ipv4-unicast-address
Treebackup

Description

This command associates virtual router IP addresses with those of the parental IP interface.

This command has two different functions based on whether it is being executed on an owner or non-owner virtual router instance.

Non-owner virtual router instances create a routable IP interface address that is operationally dependent on the virtual router instance mode (master or backup). This command, when executed on an owner virtual router instance, does not create a routable IP interface address; it simply defines the existing IP addresses of the parental IP interface that are advertised by the virtual router instance.

For owner virtual router instances, this command defines the IP addresses that are advertised within VRRP advertisement messages. This communicates the IP addresses that the master is advertising to backup virtual routers receiving the messages. The specified unicast-ipv4-address must be equal to one of the existing IP addresses in the parental IP interface (primary or secondary) or this command fails.

See "Owner and non-owner VRRP" in the 7705 SAR Gen 2 Router Configuration Guide for more information about owner and non-owner virtual router instances.

Max. instances16
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd-liveness
Synopsis Enable the bfd-liveness context
Contextconfigure service vprn service-name interface interface-name ipv4 vrrp number bfd-liveness
Treebfd-liveness
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dest-ip ipv4-address
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDestination IP address to use for BFD session
Contextconfigure service vprn service-name interface interface-name ipv4 vrrp number bfd-liveness dest-ip ipv4-address
Treedest-ip

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface-name interface-name
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisName of the interface running BFD
Contextconfigure service vprn service-name interface interface-name ipv4 vrrp number bfd-liveness interface-name interface-name
Treeinterface-name
String length1 to 32

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

service-name service-name
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisAdministrative service name
Contextconfigure service vprn service-name interface interface-name ipv4 vrrp number bfd-liveness service-name service-name
Treeservice-name
String length1 to 64
Introduced25.3.R2

Platforms

7705 SAR Gen 2

init-delay number
Synopsis VRRP initialization delay timer
Context configure service vprn service-name interface interface-name ipv4 vrrp number init-delay number
Treeinit-delay
Range1 to 65535
Unitsseconds
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

mac mac-unicast-address
Synopsis Virtual MAC address to use in ARP responses
Contextconfigure service vprn service-name interface interface-name ipv4 vrrp number mac mac-unicast-address
Treemac

Description

This command sets an explicit MAC address for the virtual router instance that overrides the VRRP default derived from the VRID.

Changing the default MAC address is useful when an existing HSRP or other non-VRRP default MAC is in use by the IP hosts that use the virtual router IP address. Many hosts do not monitor unessential ARPs and continue to use the cached non-VRRP MAC address after the virtual router becomes master of the host’s gateway address.

Additionally, this command sets the MAC address used in ARP responses when the virtual router instance is master. Routing of IP packets with unicast-mac-address as the destination MAC is also enabled. The MAC must be the same for all virtual routers participating as a virtual router or indeterminate connectivity by the attached IP hosts results. All VRRP advertisement messages are transmitted with unicast-mac-address as the source MAC.

An operator can execute this command at any time and it takes effect immediately. When the virtual router MAC on a master virtual router instance changes, a gratuitous ARP is immediately sent with a VRRP advertisement message. If the virtual router instance is disabled or operating as a backup, the gratuitous ARP and VRRP advertisement messages are not sent.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

master-int-inherit boolean
Synopsis Allow master instance to dictate the master down timer
Contextconfigure service vprn service-name interface interface-name ipv4 vrrp number master-int-inherit boolean
Treemaster-int-inherit

Description

When configured to true, the virtual router instance inherits the advertisement interval timer of the master VRRP router, which backup routers use to calculate the master down timer.

When configured to false, the locally configured message interval must match the master's VRRP advertisement message advertisement interval field value or the message is discarded.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

message-interval number
Synopsis Interval for sending VRRP advertisement messages
Contextconfigure service vprn service-name interface interface-name ipv4 vrrp number message-interval number
Treemessage-interval

Description

This command configures the administrative advertisement message timer used by the master virtual router instance to send VRRP advertisement messages. The backup master down timer is derived from the value configured using this command.

The usage of this command varies for non-owner virtual router instances, depending on the state of the virtual router (master or backup) and the state of the master-int-inherit command:

  • When a non-owner is operating as master for the virtual router, the system uses the configured value of this command as the operational advertisement timer, similar to an owner virtual router instance. The master-int-inherit command has no effect when operating as master.

  • When a non-owner is in the backup state with master-int-inherit disabled, the system uses the configured value of this command to match the incoming advertisement interval field of the VRRP advertisement message. If the locally configured message interval does not match the advertisement interval field, the system discards the VRRP advertisement.

  • When a non-owner is in the backup state with master-int-inherit enabled, the configured value of this command is ignored. The master down timer is indirectly derived from the advertisement interval field value of the incoming VRRP advertisement message.

Range1 to 2559
Unitsdeciseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

monitor-oper-group reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVRRP instance to follow a specified operational group
Contextconfigure service vprn service-name interface interface-name ipv4 vrrp number monitor-oper-group reference
Treemonitor-oper-group

Description

This command configures VRRP to associate with an operational group. When associated, VRRP notifies the operational group of its state changes so that other protocols can monitor it to provide a redundancy mechanism. When VRRP is the master router, the operational group is up and the operational group is down for all other VRRP states.

Reference

configure service oper-group named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ntp-reply boolean
Synopsis Allow processing of NTP requests
Context configure service vprn service-name interface interface-name ipv4 vrrp number ntp-reply boolean
Treentp-reply

Description

When configured to true, the router redirects NTP requests to the VRRP virtual IP address. This behavior only applies to the router acting as the master VRRP router.

When configured to false, the router does not process NTP requests.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

oper-group reference
Synopsis Operational group name associated with the VRRP
Contextconfigure service vprn service-name interface interface-name ipv4 vrrp number oper-group reference
Treeoper-group

Description

This command configures an operational group to associate with the VRRP. When associated, VRRP notifies the operational group of its state changes so that other protocols can monitor it to provide a redundancy mechanism. When VRRP is the master router (MR), the operational group is up. The operational group is down for all other VRRP states.

Reference

configure service oper-group named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

owner boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDesignate the virtual router instance as owner
Contextconfigure service vprn service-name interface interface-name ipv4 vrrp number owner boolean
Treeowner

Description

When configured to true, the router designates this virtual router instance as the owner of the virtual router IP addresses. Therefore, this virtual router becomes responsible for forwarding packets sent to the virtual router IP addresses. The owner also assumes the role of master virtual router.

When configured to false, this virtual router instance is designated as a non-owner.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

passive boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSuppress the processing of VRRP advertisement messages
Contextconfigure service vprn service-name interface interface-name ipv4 vrrp number passive boolean
Treepassive

Description

When configured to true, the router identifies this virtual router instance as passive; and therefore the owner of the virtual router IP addresses. A passive virtual router instance does not transmit or receive VRRP advertisement messages and is always in either the master state (if the interface is operationally up) or the init state (if the interface is operationally down).

When configured to false, this virtual router instance is not identified as passive, meaning that it transmits and receives VRRP advertisement messages. 

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ping-reply boolean
Synopsis Allow non-owner master to reply to ICMP echo requests
Contextconfigure service vprn service-name interface interface-name ipv4 vrrp number ping-reply boolean
Treeping-reply

Description

When configured to true, the router allows the non-owner master to reply to ICMP echo requests directed at the IP addresses of the virtual router instance. Any routed interface can receive the ping request. Ping must not have been disabled at the management security level (either on the parental IP interface or on the Ping source host address).

When configured to false, ICMP echo requests sent to non-owner master virtual IP addresses are silently discarded.

Non-owner backup virtual routers never respond to ICMP echo requests, regardless of the configuration of this command.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy reference
Synopsis VRRP priority control policy
Context configure service vprn service-name interface interface-name ipv4 vrrp number policy reference
Treepolicy

Description

This command configures a VRRP priority control policy to associate with the virtual router instance.

VRRP priority control policies can override or adjust the base priority value of the virtual router instance, depending on events or conditions within the chassis.

An operator can associate a policy with more than one virtual router instance. The priority events within the policy either override or diminish the base priority set with the priority command. As priority events clear in the policy, the in-use priority can eventually be restored to the base priority value.

For non-owner virtual router instances, if this command is not executed, the base priority is used as the in-use priority.

Reference

configure vrrp policy number

Introduced25.3.R2

Platforms

7705 SAR Gen 2

preempt boolean
Synopsis Allow the VRRP to override an existing non-owner master
Contextconfigure service vprn service-name interface interface-name ipv4 vrrp number preempt boolean
Treepreempt

Description

When configured to true, this virtual router instance overrides any non-owner master with an in-use message priority value less than the in-use priority value of this virtual router.

When configured to false, this virtual router only becomes master if the master down timer expires before a VRRP advertisement message is received from another virtual router.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority number
Synopsis Base priority for the VRRP
Context configure service vprn service-name interface interface-name ipv4 vrrp number priority number
Treepriority

Description

This command configures the base router priority for the virtual router instance, which defines the selection order of the virtual router in the master election process.

The in-use priority is derived from the base priority. However, the in-use priority is modified by optional VRRP priority control policies. An operator can use VRRP priority control policies to either override or adjust the base priority value depending on events or conditions within the chassis.

Range1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ssh-reply boolean
Synopsis Allow the non-owner master to reply to SSH requests
Contextconfigure service vprn service-name interface interface-name ipv4 vrrp number ssh-reply boolean
Treessh-reply

Description

When configured to true, the router allows the non-owner master to reply to SSH requests directed at the IP addresses of the virtual router instance. Any routed interface can receive the SSH request. SSH cannot be disabled at the management security level (either on the parental IP interface or on the SSH source host address).

When configure to false, SSH requests to non-owner master virtual IP addresses are silently discarded.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

standby-forwarding boolean
Synopsis Allow standby router to forward traffic
Contextconfigure service vprn service-name interface interface-name ipv4 vrrp number standby-forwarding boolean
Treestandby-forwarding

Description

When configured to true, the standby router forwards all traffic.

When configured to false, the standby router cannot forward traffic sent to the MAC address of the virtual router. However, the standby router still forwards traffic sent to its own MAC address.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

telnet-reply boolean
Synopsis Allow non-owner master to reply to Telnet requests
Contextconfigure service vprn service-name interface interface-name ipv4 vrrp number telnet-reply boolean
Treetelnet-reply

Description

When configured to true, the router allows the non-owner master to reply to Telnet requests directed at the IP addresses of the virtual router instance. Any routed interface can receive Telnet requests. Telnet cannot be disabled at the management security level (either on the parental IP interface or on the Telnet source host address).

When configured to false, the router silently discards Telnet requests sent to non-owner master virtual IP addresses.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

traceroute-reply boolean
Synopsis Allow non-owner master to reply to traceroute requests
Contextconfigure service vprn service-name interface interface-name ipv4 vrrp number traceroute-reply boolean
Treetraceroute-reply

Description

When configured to true, the router allows a non-owner master to reply to traceroute requests directed to the IP addresses of the virtual router instance.

When configured to false, the router silently discards traceroute requests sent to non-owner master virtual IP addresses.

Traceroute must not have been disabled at the management security level (either on the parental IP interface or the source host address).

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6
Synopsis Enable the ipv6 context
Context configure service vprn service-name interface interface-name ipv6
Treeipv6
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address [ipv6-address] ipv6-address
Synopsis Enter the address list instance
Contextconfigure service vprn service-name interface interface-name ipv6 address ipv6-address
Treeaddress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ipv6-address] ipv6-address
Synopsis IPv6 address assigned to the interface
Contextconfigure service vprn service-name interface interface-name ipv6 address ipv6-address
Treeaddress

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

duplicate-address-detection boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEnable Duplicate Address Detection
Contextconfigure service vprn service-name interface interface-name ipv6 address ipv6-address duplicate-address-detection boolean
Treeduplicate-address-detection

Description

When configured to true, the router enables Duplicate Address Detection (DAD).

When configured to false, the router disables DAD and sets the address to preferred, even if there is a duplicated address.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

eui-64 boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisForm IPv6 address from prefix and 64-bit interface ID
Contextconfigure service vprn service-name interface interface-name ipv6 address ipv6-address eui-64 boolean
Treeeui-64

Description

When configured to true, the router forms a complete IPv6 address from the supplied prefix and 64-bit interface identifier. The 64-bit interface identifier is derived from the MAC address on Ethernet interfaces. For interfaces without a MAC address, for example POS interfaces, use the base MAC address of the chassis.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

primary-preference number
Synopsis Index assigned to the IPv6 address of the interface
Contextconfigure service vprn service-name interface interface-name ipv6 address ipv6-address primary-preference number
Treeprimary-preference

Description

This command assigns a primary preference index to an IPv6 address of the interface to enforce the order in which the address is used by control plane protocols and applications that require a fixed address of the interface, such as LDP and Segment Routing. In cases where a fixed address is required when originating packets from the interface, the IPv6 address with the lowest primary preference index is selected. If the selected address is removed, the next IPv6 address with the next lowest primary preference index is selected.

If this index is not specified for the IPv6 address, the system assigns the next available index value to the address. The address index space is unique across all addresses of a given interface.

Range1 to 4294967295
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd
Synopsis Enter the bfd context
Context configure service vprn service-name interface interface-name ipv6 bfd
Treebfd
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of BFD sessions
Context configure service vprn service-name interface interface-name ipv6 bfd admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

echo-receive number
Synopsis Minimum echo interval over this interface
Contextconfigure service vprn service-name interface interface-name ipv6 bfd echo-receive number
Treeecho-receive
Range100 to 100000
Unitsmilliseconds
Introduced25.3.R2

Platforms

7705 SAR Gen 2

multiplier number
Synopsis Number of consecutive BFD messages missed from the peer
Contextconfigure service vprn service-name interface interface-name ipv6 bfd multiplier number
Treemultiplier

Description

This command configures the number of missed messages before the BFD session state is changed to down and the upper-level protocol is notified of the fault. A multiplier of less than 3 should not be used in production environments. 

Range1 to 20
Default3
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

receive number
Synopsis BFD receive interval over this interface
Contextconfigure service vprn service-name interface interface-name ipv6 bfd receive number
Treereceive

Description

This command specifies the receive interval for the BFD session.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

transmit-interval number
Synopsis BFD transmit interval over this interface
Contextconfigure service vprn service-name interface interface-name ipv6 bfd transmit-interval number
Treetransmit-interval

Description

This command configures the transmit intervals.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

dhcp6
Synopsis Enter the dhcp6 context
Context configure service vprn service-name interface interface-name ipv6 dhcp6
Treedhcp6
Introduced25.3.R2

Platforms

7705 SAR Gen 2

relay
Synopsis Enter the relay context
Context configure service vprn service-name interface interface-name ipv6 dhcp6 relay
Treerelay
Introduced25.3.R2

Platforms

7705 SAR Gen 2

lease-populate
Synopsis Enter the lease-populate context
Contextconfigure service vprn service-name interface interface-name ipv6 dhcp6 relay lease-populate
Treelease-populate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-populate
Synopsis Enter the route-populate context
Contextconfigure service vprn service-name interface interface-name ipv6 dhcp6 relay lease-populate route-populate
Treeroute-populate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

pd
Synopsis Enable the pd context
Context configure service vprn service-name interface interface-name ipv6 dhcp6 relay lease-populate route-populate pd
Treepd
Introduced25.3.R2

Platforms

7705 SAR Gen 2

option
Synopsis Enter the option context
Context configure service vprn service-name interface interface-name ipv6 dhcp6 relay option
Treeoption
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface-id
Synopsis Enter the interface-id context
Contextconfigure service vprn service-name interface interface-name ipv6 dhcp6 relay option interface-id
Treeinterface-id
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sap-id
Synopsis Use SAP ID in interface ID option in relay packet
Contextconfigure service vprn service-name interface interface-name ipv6 dhcp6 relay option interface-id sap-id
Treesap-id

Notes

The following elements are part of a choice: ascii-tuple, if-index, sap-id, or string.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

string string-not-all-spaces
Synopsis String for interface ID option in DHCPv6 relay packet
Contextconfigure service vprn service-name interface interface-name ipv6 dhcp6 relay option interface-id string string-not-all-spaces
Treestring
String length1 to 80

Notes

The following elements are part of a choice: ascii-tuple, if-index, sap-id, or string.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

server ipv6-address-with-zone
Synopsis DHCPv6 server to which the DHCPv6 requests are forwarded
Contextconfigure service vprn service-name interface interface-name ipv6 dhcp6 relay server ipv6-address-with-zone
Treeserver
Max. instances8

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

icmp6
Synopsis Enter the icmp6 context
Context configure service vprn service-name interface interface-name ipv6 icmp6
Treeicmp6
Introduced25.3.R2

Platforms

7705 SAR Gen 2

packet-too-big
Synopsis Enter the packet-too-big context
Contextconfigure service vprn service-name interface interface-name ipv6 icmp6 packet-too-big
Treepacket-too-big

Description

Commands in this context configure limiting the number of ICMPv6 Packet Too Big messages.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

param-problem
Synopsis Enter the param-problem context
Contextconfigure service vprn service-name interface interface-name ipv6 icmp6 param-problem
Treeparam-problem
Introduced25.3.R2

Platforms

7705 SAR Gen 2

redirects
Synopsis Enter the redirects context
Context configure service vprn service-name interface interface-name ipv6 icmp6 redirects
Treeredirects
Introduced25.3.R2

Platforms

7705 SAR Gen 2

number number
Synopsis Number to limit ICMPv6 Redirect messages per time frame
Contextconfigure service vprn service-name interface interface-name ipv6 icmp6 redirects number number
Treenumber
Range10 to 1000
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

time-exceeded
Synopsis Enter the time-exceeded context
Contextconfigure service vprn service-name interface interface-name ipv6 icmp6 time-exceeded
Treetime-exceeded
Introduced25.3.R2

Platforms

7705 SAR Gen 2

unreachables
Synopsis Enter the unreachables context
Contextconfigure service vprn service-name interface interface-name ipv6 icmp6 unreachables
Treeunreachables
Introduced25.3.R2

Platforms

7705 SAR Gen 2

link-local-address
Synopsis Enter the link-local-address context
Contextconfigure service vprn service-name interface interface-name ipv6 link-local-address
Treelink-local-address
Introduced25.3.R2

Platforms

7705 SAR Gen 2

duplicate-address-detection boolean
Synopsis Enable Duplicate Address Detection
Context configure service vprn service-name interface interface-name ipv6 link-local-address duplicate-address-detection boolean
Treeduplicate-address-detection

Description

When configured to true, the router enables Duplicate Address Detection (DAD) on the interface.

When configured to false, the router disables DAD and sets the address to preferred, even if there is a duplicated address.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

local-dhcp-server reference
Synopsis DHCP server for the interface
Context configure service vprn service-name interface interface-name ipv6 local-dhcp-server reference
Treelocal-dhcp-server

Description

This command instantiates a local DHCP server. A local DHCP server can serve multiple interfaces but is limited to the routing context in which it was created.

Reference

configure service vprn service-name dhcp-server dhcpv6 named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

neighbor-discovery
Synopsis Enter the neighbor-discovery context
Contextconfigure service vprn service-name interface interface-name ipv6 neighbor-discovery
Treeneighbor-discovery
Introduced25.3.R2

Platforms

7705 SAR Gen 2

host-route
Synopsis Enter the host-route context
Context configure service vprn service-name interface interface-name ipv6 neighbor-discovery host-route
Treehost-route
Introduced25.3.R2

Platforms

7705 SAR Gen 2

populate [route-type] keyword
Synopsis Enter the populate list instance
Contextconfigure service vprn service-name interface interface-name ipv6 neighbor-discovery host-route populate keyword
Treepopulate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-tag number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTag value used with the host route from an ARP/ND entry
Contextconfigure service vprn service-name interface interface-name ipv6 neighbor-discovery host-route populate keyword route-tag number
Treeroute-tag

Description

This command specifies the route tag that is added in the route table for ARP or ND host routes. This tag can be matched on BGP VRF export and BGP peer export policies.

Range1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

learn-unsolicited keyword
Synopsis Type of entries learned from unsolicited NA messages
Contextconfigure service vprn service-name interface interface-name ipv6 neighbor-discovery learn-unsolicited keyword
Treelearn-unsolicited

Description

This command enables the ability to learn neighbor entries out of received unsolicited Neighbor Advertisement (NA) messages, with or without the solicited flag set.

When unconfigured, the router follows standard RFC 4861 behavior for learning of neighbor entries. The neighbor is put in the stale state. This is the standard RFC behavior.

Optionsglobal, link-local, both
Introduced25.3.R2

Platforms

7705 SAR Gen 2

limit
Synopsis Enter the limit context
Context configure service vprn service-name interface interface-name ipv6 neighbor-discovery limit
Treelimit
Introduced25.3.R2

Platforms

7705 SAR Gen 2

log-only boolean
Synopsis Generate log entries when limit is reached
Contextconfigure service vprn service-name interface interface-name ipv6 neighbor-discovery limit log-only boolean
Treelog-only

Description

When configured to true, the router sends the warning message at the specified threshold percentage or upon exceeding the specified limit. Entries that exceed the limit are learned.

When configured to false, the router does not send the warning message.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

max-entries number
Synopsis Maximum number of entries learned on an IP interface
Contextconfigure service vprn service-name interface interface-name ipv6 neighbor-discovery limit max-entries number
Treemax-entries

Description

This command configures the maximum number of entries that can be learned on an IP interface.

When unconfigured, no maximum limit is imposed.

Range0 to 102400
Introduced25.3.R2

Platforms

7705 SAR Gen 2

local-proxy-nd boolean
Synopsis Enable local proxy neighbor discovery on the interface
Contextconfigure service vprn service-name interface interface-name ipv6 neighbor-discovery local-proxy-nd boolean
Treelocal-proxy-nd

Description

When configured to true, the router enables local proxy neighbor discovery on the interface and replies to neighbor solicitation requests when both the hosts are on the same subnet. In this case, ICMP redirects are disabled.

When configured to false, the router disables local proxy neighbor discovery on the interface and does not reply to neighbor solicitation requests if both the hosts are on the same subnet.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

proactive-refresh keyword
Synopsis Proactive refresh of neighbor entries
Contextconfigure service vprn service-name interface interface-name ipv6 neighbor-discovery proactive-refresh keyword
Treeproactive-refresh

Description

This command enables a proactive refresh of the neighbor entries. After the stale timer expires, the router sends an NUD message to the host (regardless of the existence of traffic to the IP address on the IOM), so the entry can be refreshed or removed.

Optionsglobal, link-local, both
Introduced25.3.R2

Platforms

7705 SAR Gen 2

secure-nd
Synopsis Enter the secure-nd context
Context configure service vprn service-name interface interface-name ipv6 neighbor-discovery secure-nd
Treesecure-nd
Introduced25.3.R2

Platforms

7705 SAR Gen 2

allow-unsecured-msgs boolean
Synopsis Accept unsecured messages
Context configure service vprn service-name interface interface-name ipv6 neighbor-discovery secure-nd allow-unsecured-msgs boolean
Treeallow-unsecured-msgs

Description

When configured to true, the router accepts unsecured messages. When Secure Neighbor Discovery (SeND) is enabled, only secure messages are accepted.

When configured to false, the router disables the acceptance of unsecured messages.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static-neighbor [ipv6-address] ipv6-address
Synopsis Enter the static-neighbor list instance
Contextconfigure service vprn service-name interface interface-name ipv6 neighbor-discovery static-neighbor ipv6-address
Treestatic-neighbor
Introduced25.3.R2

Platforms

7705 SAR Gen 2

tcp-mss number
Synopsis TCP maximum segment size for the interface
Contextconfigure service vprn service-name interface interface-name ipv6 tcp-mss number
Treetcp-mss
Range1220 to 9726
Introduced25.3.R2

Platforms

7705 SAR Gen 2

urpf-check
Synopsis Enable the urpf-check context
Context configure service vprn service-name interface interface-name ipv6 urpf-check
Treeurpf-check
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mode keyword
Synopsis Unicast RPF check mode
Context configure service vprn service-name interface interface-name ipv6 urpf-check mode keyword
Treemode
Options

strict – Check source address match in RT and interface

loose – Check source address match in RT only

strict-no-ecmp – Check source address match in ECMP route

Defaultstrict
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vrrp [virtual-router-id] number
Synopsis Enter the vrrp list instance
Context configure service vprn service-name interface interface-name ipv6 vrrp number
Treevrrp
Max. instances4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[virtual-router-id] number
Synopsis Virtual Router Identifier (VRID) for the IP interface
Contextconfigure service vprn service-name interface interface-name ipv6 vrrp number
Treevrrp
Range1 to 255

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of VRRP
Context configure service vprn service-name interface interface-name ipv6 vrrp number admin-state keyword
Treeadmin-state

Description

The command determines the administrative state of non-owner virtual router instances.

Non-owner virtual router instances can be administratively disabled. This allows the termination of VRRP participation in the virtual router and stops all routing and other access capabilities with regards to the virtual router IP addresses. Disabling the virtual router instance provides a mechanism to maintain the virtual routers without causing false backup or master state changes.

When disabled, no VRRP advertisement messages are generated and all received VRRP advertisement messages are silently discarded with no processing.

Whenever the administrative or operational state of a virtual router instance transitions, a log message is generated.

An owner virtual router context does not use this command. To administratively disable an owner virtual router instance, use the admin-state command within the parent IP interface node which administratively disables the IP interface.

Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

backup ipv6-address
Synopsis Virtual router IP addresses for the interface
Contextconfigure service vprn service-name interface interface-name ipv6 vrrp number backup ipv6-address
Treebackup

Description

This command associates router IPv6 virtual router IP addresses with those of the parental IP interface.

This command has two different functions based on whether it is being executed on an owner or non-owner virtual router instance.

Non-owner virtual router instance create a routable IP interface address that is operationally dependent on the virtual router instance mode (master or backup). This command, when executed on an owner virtual router instance, does not create a routable IP interface address; it simply defines the existing IP addresses of the parental IP interface that are advertised by the virtual router instance.

For owner virtual router instances, this command defines the IP addresses that are advertised within VRRP advertisement messages. This communicates the IP addresses that the master is representing to backup virtual routers receiving the messages. The specified IPv6 address must be equal to one of the existing parental IP addresses in the parental IP interface (primary or secondary) or this command fails.

See "Owner and non-owner VRRP" in the 7705 SAR Gen 2 Router Configuration Guide for more information about owner and non-owner virtual router instances.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd-liveness
Synopsis Enable the bfd-liveness context
Contextconfigure service vprn service-name interface interface-name ipv6 vrrp number bfd-liveness
Treebfd-liveness
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dest-ip (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDestination address for the BFD session
Contextconfigure service vprn service-name interface interface-name ipv6 vrrp number bfd-liveness dest-ip (ipv4-address-no-zone | ipv6-address-no-zone)
Treedest-ip

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface-name interface-name
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisName of the interface running BFD
Contextconfigure service vprn service-name interface interface-name ipv6 vrrp number bfd-liveness interface-name interface-name
Treeinterface-name
String length1 to 32

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

service-name service-name
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisAdministrative service name
Contextconfigure service vprn service-name interface interface-name ipv6 vrrp number bfd-liveness service-name service-name
Treeservice-name
String length1 to 64
Introduced25.3.R2

Platforms

7705 SAR Gen 2

init-delay number
Synopsis VRRP initialization delay timer
Context configure service vprn service-name interface interface-name ipv6 vrrp number init-delay number
Treeinit-delay
Range1 to 65535
Unitsseconds
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

mac mac-unicast-address
Synopsis Virtual MAC address to use in ARP responses
Contextconfigure service vprn service-name interface interface-name ipv6 vrrp number mac mac-unicast-address
Treemac

Description

This command sets an explicit MAC address for the virtual router instance that overrides the VRRP default derived from the VRID.

Changing the default MAC address is useful when an existing HSRP or other non-VRRP default MAC is in use by the IP hosts that use the virtual router IP address. Many hosts do not monitor unessential ARPs and continue to use the cached non-VRRP MAC address after the virtual router becomes master of the host’s gateway address.

Additionally, this command sets the MAC address used in ARP responses when the virtual router instance is master. Routing of IP packets with unicast-mac-address as the destination MAC is also enabled. The MAC must be the same for all virtual routers participating as a virtual router or indeterminate connectivity by the attached IP hosts results. All VRRP advertisement messages are transmitted with unicast-mac-address as the source MAC.

An operator can execute this command at any time and it takes effect immediately. When the virtual router MAC on a master virtual router instance changes, a gratuitous ARP is immediately sent with a VRRP advertisement message. If the virtual router instance is disabled or operating as a backup, the gratuitous ARP and VRRP advertisement messages are not sent.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

master-int-inherit boolean
Synopsis Allow master instance to dictate the master down timer
Contextconfigure service vprn service-name interface interface-name ipv6 vrrp number master-int-inherit boolean
Treemaster-int-inherit

Description

When configured to true, the virtual router instance inherits the advertisement interval timer of the master VRRP router, which backup routers use to calculate the master down timer.

When configured to false, the locally configured message interval must match the master's VRRP advertisement message advertisement interval field value or the message is discarded.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

message-interval number
Synopsis Interval for sending VRRP advertisement messages
Contextconfigure service vprn service-name interface interface-name ipv6 vrrp number message-interval number
Treemessage-interval

Description

This command configures the administrative advertisement message timer used by the master virtual router instance to send VRRP advertisement messages. The backup master down timer is derived from the value configured using this command.

The use of this command varies for non-owner virtual router instances, depending on the state of the virtual router (master or backup) and the state of the master-int-inherit command:

  • When a non-owner is operating as master for the virtual router, the system uses the configured value of this command as the operational advertisement timer, similar to an owner virtual router instance. The master-int-inherit command has no effect when operating as the master.

  • When a non-owner is in the backup state with master-int-inherit disabled, the system uses the configured value of this command to match the incoming advertisement interval field of the VRRP advertisement message. If the locally configured message interval does not match the advertisement interval field, the system discards the VRRP advertisement.

  • When a non-owner is in the backup state with master-int-inherit enabled, the configured value of this command is ignored. The master down timer is indirectly derived from the advertisement interval field value of the incoming VRRP advertisement message.

Range10 to 4095
Unitscentiseconds
Default 100
Introduced25.3.R2

Platforms

7705 SAR Gen 2

monitor-oper-group reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVRRP instance to follow a specified operational group
Contextconfigure service vprn service-name interface interface-name ipv6 vrrp number monitor-oper-group reference
Treemonitor-oper-group

Description

This command configures VRRP to associate with an operational group. When associated, VRRP notifies the operational group of its state changes so that other protocols can monitor it to provide a redundancy mechanism. When VRRP is the master router, the operational group is up and the operational group is down for all other VRRP states.

Reference

configure service oper-group named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ntp-reply boolean
Synopsis Allow processing of NTP requests
Context configure service vprn service-name interface interface-name ipv6 vrrp number ntp-reply boolean
Treentp-reply

Description

When configured to true, the router redirects NTP requests to the VRRP virtual IP address. This behavior only applies to the router acting as the master VRRP router.

When configured to false, the router does not process NTP requests.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

oper-group reference
Synopsis Operational group name associated with the VRRP
Contextconfigure service vprn service-name interface interface-name ipv6 vrrp number oper-group reference
Treeoper-group

Description

This command configures an operational group to associate with the VRRP. When associated, VRRP notifies the operational group of its state changes so that other protocols can monitor it to provide a redundancy mechanism. When VRRP is the master router (MR), the operational group is up. The operational group is down for all other VRRP states.

Reference

configure service oper-group named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

owner boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDesignate the virtual router instance as owner
Contextconfigure service vprn service-name interface interface-name ipv6 vrrp number owner boolean
Treeowner

Description

When configured to true, the router designates this virtual router instance as the owner of the virtual router IP addresses. Therefore, this virtual router becomes responsible for forwarding packets sent to the virtual router IP addresses. The owner also assumes the role of master virtual router.

When configured to false, this virtual router instance is designated as a non-owner.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

passive boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSuppress the processing of VRRP advertisement messages
Contextconfigure service vprn service-name interface interface-name ipv6 vrrp number passive boolean
Treepassive

Description

When configured to true, the router identifies this virtual router instance as passive; and therefore the owner of the virtual router IP addresses. A passive virtual router instance does not transmit or receive VRRP advertisement messages and is always in either the master state (if the interface is operationally up) or the init state (if the interface is operationally down).

When configured to false, this virtual router instance is not identified as passive, meaning that it transmits and receives VRRP advertisement messages. 

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ping-reply boolean
Synopsis Allow non-owner master to reply to ICMP echo requests
Contextconfigure service vprn service-name interface interface-name ipv6 vrrp number ping-reply boolean
Treeping-reply

Description

When configured to true, the router allows the non-owner master to reply to ICMP echo requests directed at the IP addresses of the virtual router instance. Any routed interface can receive the ping request. Ping must not have been disabled at the management security level (either on the parental IP interface or on the Ping source host address).

When configured to false, ICMP echo requests sent to non-owner master virtual IP addresses are silently discarded.

Non-owner backup virtual routers never respond to ICMP echo requests, regardless of the configuration of this command.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy reference
Synopsis VRRP priority control policy
Context configure service vprn service-name interface interface-name ipv6 vrrp number policy reference
Treepolicy

Description

This command configures a VRRP priority control policy to associate with the virtual router instance.

VRRP priority control policies can override or adjust the base priority value of the virtual router instance, depending on events or conditions within the chassis.

An operator can associate a policy with more than one virtual router instance. The priority events within the policy either override or diminish the base priority set with the priority command. As priority events clear in the policy, the in-use priority can eventually be restored to the base priority value.

For non-owner virtual router instances, if this command is not executed, the base priority is used as the in-use priority.

Reference

configure vrrp policy number

Introduced25.3.R2

Platforms

7705 SAR Gen 2

preempt boolean
Synopsis Allow the VRRP to override an existing non-owner master
Contextconfigure service vprn service-name interface interface-name ipv6 vrrp number preempt boolean
Treepreempt

Description

When configured to true, this virtual router instance overrides any non-owner master with an in-use message priority value less than the in-use priority value of this virtual router.

When configured to false, this virtual router only becomes master if the master down timer expires before a VRRP advertisement message is received from another virtual router.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority number
Synopsis Base priority for the VRRP
Context configure service vprn service-name interface interface-name ipv6 vrrp number priority number
Treepriority

Description

This command configures the base router priority for the virtual router instance, which defines the selection order of the virtual router in the master election process.

The in-use priority is derived from the base priority. However, the in-use priority is modified by optional VRRP priority control policies. An operator can use VRRP priority control policies to either override or adjust the base priority value depending on events or conditions within the chassis.

Range1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

standby-forwarding boolean
Synopsis Allow standby router to forward traffic
Contextconfigure service vprn service-name interface interface-name ipv6 vrrp number standby-forwarding boolean
Treestandby-forwarding

Description

When configured to true, the standby router forwards all traffic.

When configured to false, the standby router cannot forward traffic sent to the MAC address of the virtual router. However, the standby router still forwards traffic sent to its own MAC address.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

telnet-reply boolean
Synopsis Allow non-owner master to reply to Telnet requests
Contextconfigure service vprn service-name interface interface-name ipv6 vrrp number telnet-reply boolean
Treetelnet-reply

Description

When configured to true, the router allows the non-owner master to reply to Telnet requests directed at the IP addresses of the virtual router instance. Any routed interface can receive Telnet requests. Telnet cannot be disabled at the management security level (either on the parental IP interface or on the Telnet source host address).

When configured to false, the router silently discards Telnet requests sent to non-owner master virtual IP addresses.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

traceroute-reply boolean
Synopsis Allow non-owner master to reply to traceroute requests
Contextconfigure service vprn service-name interface interface-name ipv6 vrrp number traceroute-reply boolean
Treetraceroute-reply

Description

When configured to true, the router allows a non-owner master to reply to traceroute requests directed to the IP addresses of the virtual router instance.

When configured to false, the router silently discards traceroute requests sent to non-owner master virtual IP addresses.

Traceroute must not have been disabled at the management security level (either on the parental IP interface or the source host address).

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

load-balancing
Synopsis Enter the load-balancing context
Contextconfigure service vprn service-name interface interface-name load-balancing
Treeload-balancing
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-load-balancing keyword
Synopsis IP load-balancing algorithm
Context configure service vprn service-name interface interface-name load-balancing ip-load-balancing keyword
Treeip-load-balancing

Description

This command specifies whether to include the source address, destination address, or both in LAG or ECMP hash on IP interfaces. Additionally, when the l4-load-balancing command is enabled, this command also includes the source or destination port in the hash inputs.

Optionsboth, destination, source, inner-ip
Default both
Introduced25.3.R2

Platforms

7705 SAR Gen 2

loopback boolean
Synopsis Use interface as a loopback interface
Contextconfigure service vprn service-name interface interface-name loopback boolean
Treeloopback
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac mac-unicast-address
Synopsis MAC address for the interface
Context configure service vprn service-name interface interface-name mac mac-unicast-address
Treemac
Introduced25.3.R2

Platforms

7705 SAR Gen 2

multi-chassis-shunting-profile reference
Synopsis Multi-chassis shunting profile name
Context configure service vprn service-name interface interface-name multi-chassis-shunting-profile reference
Treemulti-chassis-shunting-profile

Description

This command configures the name of a multi-chassis shunting profile to use on public or private tunnel interfaces.

Reference

configure service vprn service-name ipsec multi-chassis-shunting-profile named-item

Notes

The following elements are part of a choice: multi-chassis-shunting-profile or (dynamic-tunnel-redundant-nexthop and static-tunnel-redundant-nexthop).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

sap [sap-id] sap
Synopsis Enter the sap list instance
Context configure service vprn service-name interface interface-name sap sap
Treesap
Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[sap-id] sap
Synopsis SAP ID
Contextconfigure service vprn service-name interface interface-name sap sap
Treesap
String length1 to 45

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the SAP
Context configure service vprn service-name interface interface-name sap sap admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bandwidth number
Synopsis SAP bandwidth
Contextconfigure service vprn service-name interface interface-name sap sap bandwidth number
Treebandwidth
Range1 to 6400000000
Unitskilobps
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

description long-description
Synopsis Text description
Context configure service vprn service-name interface interface-name sap sap description long-description
Treedescription
String length1 to 160
Introduced25.3.R2

Platforms

7705 SAR Gen 2

egress
Synopsis Enter the egress context
Context configure service vprn service-name interface interface-name sap sap egress
Treeegress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

agg-rate
Synopsis Enter the agg-rate context
Context configure service vprn service-name interface interface-name sap sap egress agg-rate
Treeagg-rate

Notes

The following elements are part of a choice: agg-rate or percent-agg-rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate number
Synopsis Enforced aggregate rate for all queues
Contextconfigure service vprn service-name interface interface-name sap sap egress agg-rate rate number
Treerate
Range1 to 6400000000
Unitskilobps
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

filter
Synopsis Enter the filter context
Context configure service vprn service-name interface interface-name sap sap egress filter
Treefilter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

qos
Synopsis Enter the qos context
Context configure service vprn service-name interface interface-name sap sap egress qos
Treeqos
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policer-control-policy
Synopsis Enter the policer-control-policy context
Contextconfigure service vprn service-name interface interface-name sap sap egress qos policer-control-policy
Treepolicer-control-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enable the overrides context
Context configure service vprn service-name interface interface-name sap sap egress qos policer-control-policy overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

root
Synopsis Enter the root context
Context configure service vprn service-name interface interface-name sap sap egress qos policer-control-policy overrides root
Treeroot
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority-mbs-thresholds
Synopsis Enter the priority-mbs-thresholds context
Contextconfigure service vprn service-name interface interface-name sap sap egress qos policer-control-policy overrides root priority-mbs-thresholds
Treepriority-mbs-thresholds
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority [priority-level] number
Synopsis Enter the priority list instance
Contextconfigure service vprn service-name interface interface-name sap sap egress qos policer-control-policy overrides root priority-mbs-thresholds priority number
Treepriority
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sap-egress
Synopsis Enter the sap-egress context
Context configure service vprn service-name interface interface-name sap sap egress qos sap-egress
Treesap-egress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enter the overrides context
Context configure service vprn service-name interface interface-name sap sap egress qos sap-egress overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

queue [queue-id] reference
Synopsis Enter the queue list instance
Context configure service vprn service-name interface interface-name sap sap egress qos sap-egress overrides queue reference
Treequeue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure service vprn service-name interface interface-name sap sap egress qos sap-egress overrides queue reference adaptation-rule
Treeadaptation-rule
Introduced25.3.R2

Platforms

7705 SAR Gen 2

avg-frame-overhead decimal-number
Synopsis Average packet-to-frame encapsulation overhead
Contextconfigure service vprn service-name interface interface-name sap sap egress qos sap-egress overrides queue reference avg-frame-overhead decimal-number
Treeavg-frame-overhead

Description

This command configures overrides for the average frame overhead. The overrides supersede the average frame overhead configuration under the queue.

For a full description of this command, see the configure qos network-queue queue avg-frame-overhead and configure qos sap-egress queue avg-frame-overhead contexts.

Range0.00 to 100.00
Introduced25.3.R2

Platforms

7705 SAR Gen 2

drop-tail
Synopsis Enter the drop-tail context
Context configure service vprn service-name interface interface-name sap sap egress qos sap-egress overrides queue reference drop-tail
Treedrop-tail
Introduced25.3.R2

Platforms

7705 SAR Gen 2

low
Synopsis Enter the low context
Context configure service vprn service-name interface interface-name sap sap egress qos sap-egress overrides queue reference drop-tail low
Treelow
Introduced25.3.R2

Platforms

7705 SAR Gen 2

parent
Synopsis Enter the parent context
Context configure service vprn service-name interface interface-name sap sap egress qos sap-egress overrides queue reference parent
Treeparent
Introduced25.3.R2

Platforms

7705 SAR Gen 2

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service vprn service-name interface interface-name sap sap egress qos sap-egress overrides queue reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate
Synopsis Enter the rate context
Context configure service vprn service-name interface interface-name sap sap egress qos sap-egress overrides queue reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

port-redirect-group
Synopsis Enter the port-redirect-group context
Contextconfigure service vprn service-name interface interface-name sap sap egress qos sap-egress port-redirect-group
Treeport-redirect-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service vprn service-name interface interface-name sap sap egress qos scheduler-policy
Treescheduler-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enter the overrides context
Context configure service vprn service-name interface interface-name sap sap egress qos scheduler-policy overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

scheduler [scheduler-name] named-item
Synopsis Enter the scheduler list instance
Contextconfigure service vprn service-name interface interface-name sap sap egress qos scheduler-policy overrides scheduler named-item
Treescheduler
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[scheduler-name] named-item
Synopsis Scheduler name
Contextconfigure service vprn service-name interface interface-name sap sap egress qos scheduler-policy overrides scheduler named-item
Treescheduler

Description

This command specifies the scheduler name which is composed of printable 7-bit ASCII characters. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes. Each scheduler must have a unique name within the context of the scheduler policy. However, the same name can be reused in multiple scheduler policies. If the scheduler name already exists within the policy tier level, the context changes to that scheduler name for the purpose of editing the scheduler commands.

If the scheduler name exists within the policy on a different tier, an error occurs and the current context does not change. If the scheduler name does not exist in this or another tier within the scheduler policy, it is assumed that an attempt is being made to create a scheduler of that name.

If the provided scheduler name is invalid, a name syntax error occurs, the command does not execute, and the context is not change.

String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

parent
Synopsis Enter the parent context
Context configure service vprn service-name interface interface-name sap sap egress qos scheduler-policy overrides scheduler named-item parent
Treeparent
Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate
Synopsis Enter the rate context
Context configure service vprn service-name interface interface-name sap sap egress qos scheduler-policy overrides scheduler named-item rate
Treerate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ingress
Synopsis Enter the ingress context
Context configure service vprn service-name interface interface-name sap sap ingress
Treeingress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter
Synopsis Enter the filter context
Context configure service vprn service-name interface interface-name sap sap ingress filter
Treefilter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

qos
Synopsis Enter the qos context
Context configure service vprn service-name interface interface-name sap sap ingress qos
Treeqos
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policer-control-policy
Synopsis Enter the policer-control-policy context
Contextconfigure service vprn service-name interface interface-name sap sap ingress qos policer-control-policy
Treepolicer-control-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enable the overrides context
Context configure service vprn service-name interface interface-name sap sap ingress qos policer-control-policy overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

root
Synopsis Enter the root context
Context configure service vprn service-name interface interface-name sap sap ingress qos policer-control-policy overrides root
Treeroot
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority-mbs-thresholds
Synopsis Enter the priority-mbs-thresholds context
Contextconfigure service vprn service-name interface interface-name sap sap ingress qos policer-control-policy overrides root priority-mbs-thresholds
Treepriority-mbs-thresholds
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority [priority-level] number
Synopsis Enter the priority list instance
Contextconfigure service vprn service-name interface interface-name sap sap ingress qos policer-control-policy overrides root priority-mbs-thresholds priority number
Treepriority
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sap-ingress
Synopsis Enter the sap-ingress context
Context configure service vprn service-name interface interface-name sap sap ingress qos sap-ingress
Treesap-ingress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

fp-redirect-group
Synopsis Enter the fp-redirect-group context
Contextconfigure service vprn service-name interface interface-name sap sap ingress qos sap-ingress fp-redirect-group
Treefp-redirect-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enter the overrides context
Context configure service vprn service-name interface interface-name sap sap ingress qos sap-ingress overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policer [policer-id] reference
Synopsis Enter the policer list instance
Contextconfigure service vprn service-name interface interface-name sap sap ingress qos sap-ingress overrides policer reference
Treepolicer
Introduced25.3.R2

Platforms

7705 SAR Gen 2

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service vprn service-name interface interface-name sap sap ingress qos sap-ingress overrides policer reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate
Synopsis Enter the rate context
Context configure service vprn service-name interface interface-name sap sap ingress qos sap-ingress overrides policer reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

stat-mode keyword
Synopsis Mode of statistics collected by the policer
Contextconfigure service vprn service-name interface interface-name sap sap ingress qos sap-ingress overrides policer reference stat-mode keyword
Treestat-mode
Optionsno-stats, minimal, offered-profile-no-cir, offered-total-cir, offered-priority-no-cir, offered-profile-cir, offered-priority-cir, offered-limited-profile-cir, offered-profile-capped-cir, offered-limited-capped-cir
Introduced25.3.R2

Platforms

7705 SAR Gen 2

queue [queue-id] reference
Synopsis Enter the queue list instance
Context configure service vprn service-name interface interface-name sap sap ingress qos sap-ingress overrides queue reference
Treequeue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure service vprn service-name interface interface-name sap sap ingress qos sap-ingress overrides queue reference adaptation-rule
Treeadaptation-rule
Introduced25.3.R2

Platforms

7705 SAR Gen 2

drop-tail
Synopsis Enter the drop-tail context
Context configure service vprn service-name interface interface-name sap sap ingress qos sap-ingress overrides queue reference drop-tail
Treedrop-tail
Introduced25.3.R2

Platforms

7705 SAR Gen 2

low
Synopsis Enter the low context
Context configure service vprn service-name interface interface-name sap sap ingress qos sap-ingress overrides queue reference drop-tail low
Treelow
Introduced25.3.R2

Platforms

7705 SAR Gen 2

parent
Synopsis Enter the parent context
Context configure service vprn service-name interface interface-name sap sap ingress qos sap-ingress overrides queue reference parent
Treeparent
Introduced25.3.R2

Platforms

7705 SAR Gen 2

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service vprn service-name interface interface-name sap sap ingress qos sap-ingress overrides queue reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate
Synopsis Enter the rate context
Context configure service vprn service-name interface interface-name sap sap ingress qos sap-ingress overrides queue reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service vprn service-name interface interface-name sap sap ingress qos scheduler-policy
Treescheduler-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overrides
Synopsis Enter the overrides context
Context configure service vprn service-name interface interface-name sap sap ingress qos scheduler-policy overrides
Treeoverrides
Introduced25.3.R2

Platforms

7705 SAR Gen 2

scheduler [scheduler-name] named-item
Synopsis Enter the scheduler list instance
Contextconfigure service vprn service-name interface interface-name sap sap ingress qos scheduler-policy overrides scheduler named-item
Treescheduler
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[scheduler-name] named-item
Synopsis Scheduler name
Contextconfigure service vprn service-name interface interface-name sap sap ingress qos scheduler-policy overrides scheduler named-item
Treescheduler

Description

This command specifies the scheduler name which is composed of printable 7-bit ASCII characters. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes. Each scheduler must have a unique name within the context of the scheduler policy. However, the same name can be reused in multiple scheduler policies. If the scheduler name already exists within the policy tier level, the context changes to that scheduler name for the purpose of editing the scheduler commands.

If the scheduler name exists within the policy on a different tier, an error occurs and the current context does not change. If the scheduler name does not exist in this or another tier within the scheduler policy, it is assumed that an attempt is being made to create a scheduler of that name.

If the provided scheduler name is invalid, a name syntax error occurs, the command does not execute, and the context is not change.

String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

parent
Synopsis Enter the parent context
Context configure service vprn service-name interface interface-name sap sap ingress qos scheduler-policy overrides scheduler named-item parent
Treeparent
Introduced25.3.R2

Platforms

7705 SAR Gen 2

rate
Synopsis Enter the rate context
Context configure service vprn service-name interface interface-name sap sap ingress qos scheduler-policy overrides scheduler named-item rate
Treerate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-tunnel [tunnel-name] interface-name
Synopsis Enter the ip-tunnel list instance
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name
Treeip-tunnel
Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[tunnel-name] interface-name
Synopsis IP tunnel name
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name
Treeip-tunnel
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the IP tunnel
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

backup-remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisBackup remote IP address that is applied to this tunnel
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name backup-remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treebackup-remote-ip-address
Introduced25.3.R2

Platforms

7705 SAR Gen 2

clear-df-bit boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisClear the Do-not-Fragment bit
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name clear-df-bit boolean
Treeclear-df-bit

Description

When configured to true, the DF bit is cleared (set to 0) in all payload IP packets associated with the GRE or IPsec tunnel, before any potential fragmentation resulting from the ip-mtu command. This requires a modification of the header checksum.

When configured to false, clearing of the DF bit is disabled.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

delivery-service service-name
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisService to originate and terminate GRE packets
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name delivery-service service-name
Treedelivery-service

Description

This command specifies the service used to originate and terminate the GRE encapsulated packets belonging to the GRE tunnel. The delivery service may be the same service that owns the private tunnel SAP associated with the GRE tunnel.

The GRE tunnel does not come up until a valid delivery service is configured.

String length1 to 64
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisText description
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dest-ip [dest-ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Add a list entry for dest-ip
Context configure service vprn service-name interface interface-name sap sap ip-tunnel interface-name dest-ip (ipv4-address-no-zone | ipv6-address-no-zone)
Treedest-ip
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[dest-ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the remote IP tunnel endpoint
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name dest-ip (ipv4-address-no-zone | ipv6-address-no-zone)
Treedest-ip

Description

This command configures the IP address of the remote IP tunnel endpoint. If the remote IP address is not within the subnet of the IP interface associated with the tunnel, the tunnel fails to come up.

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

dscp keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDifferentiated Services Code Point (DSCP) name
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name dscp keyword
Treedscp
Optionsbe, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

encapsulated-ip-mtu number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum size of the encapsulated tunnel packet
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name encapsulated-ip-mtu number
Treeencapsulated-ip-mtu

Description

This command specifies the maximum size of the encapsulated tunnel packet for the IP tunnel. If the packet exceeds this value, the system fragments the packet.

Range512 to 9000
Unitsbytes
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

gre-header
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the gre-header context
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name gre-header
Treegre-header
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of the GRE header in the tunnel
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name gre-header admin-state keyword
Treeadmin-state
Optionsenable, disable
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

key
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the key context
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name gre-header key
Treekey
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of the keys in the GRE header
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name gre-header key admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

receive number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisReceive key of the GRE header
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name gre-header key receive number
Treereceive
Max. range0 to 4294967295
Default0
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

send number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSend key of the GRE header
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name gre-header key send number
Treesend
Max. range0 to 4294967295
Default0
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

icmp-generation
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the icmp-generation context
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name icmp-generation
Treeicmp-generation
Introduced25.3.R2

Platforms

7705 SAR Gen 2

frag-required
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the frag-required context
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name icmp-generation frag-required
Treefrag-required
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of sending ICMP messages
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name icmp-generation frag-required admin-state keyword
Treeadmin-state

Description

This command configures the administrative state of sending ICMP Destination Unreachable "fragmentation needed, DF set" messages (type 3, code 4) messages to the source if the received size of the IPv4 packet on the private side exceeds the private MTU size.

Optionsenable, disable
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

interval number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisInterval for sending ICMP messages
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name icmp-generation frag-required interval number
Treeinterval

Description

This command configures the interval for sending ICMP Destination Unreachable "fragmentation needed, DF set" messages (type 3, code 4).

Range1 to 60
Unitsseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

message-count number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of ICMP messages sent
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name icmp-generation frag-required message-count number
Treemessage-count

Description

This command configures the maximum number of ICMP messages that can be sent during the period specified by the interval command.

Range10 to 1000
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

icmp6-generation
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the icmp6-generation context
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name icmp6-generation
Treeicmp6-generation
Introduced25.3.R2

Platforms

7705 SAR Gen 2

packet-too-big
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the packet-too-big context
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name icmp6-generation packet-too-big
Treepacket-too-big
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of sending Packet Too Big messages
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name icmp6-generation packet-too-big admin-state keyword
Treeadmin-state
Optionsenable, disable
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

number number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of PTB ICMPv6 messages that can be sent
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name icmp6-generation packet-too-big number number
Treenumber

Description

This command configures the maximum number of ICMPv6 messages that can be sent during the configured interval.

Range10 to 1000
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

seconds number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum interval when PTB messages can be sent
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name icmp6-generation packet-too-big seconds number
Treeseconds
Range1 to 60
Unitsseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-mtu number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIP MTU for the interface
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name ip-mtu number
Treeip-mtu

Description

This command specifies the IP MTU for the interface. If the DF bit is not set in the packet, IP packet fragmentation is performed, if necessary, based on this configured value.

When unconfigured, all IP packets, regardless of the packet size or DF bit setting, are allowed into the tunnel without fragmentation.

Range512 to 9000
Unitsbytes
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

local-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal IP address of this tunnel
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name local-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treelocal-ip-address

Description

This command specifies the local IP address to use for the IP tunnel. This configuration applies to the outer IP header of the encapsulated packets. The address must belong to one of the IP subnets associated with the public SAP interface of the tunnel group. The source IP address, the remote IP address, and the backup remote IP address of a tunnel must all belong to the same address family (IPv4 or IPv6).

When this command specifies an IPv6 address, it must be a global unicast address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

pmtu-discovery-aging number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTime to age out the learned path MTU
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name pmtu-discovery-aging number
Treepmtu-discovery-aging

Description

This command configures the temporary public MTU expiration time. The temporary public MTU is used for MTU propagation.

Range900 to 3600
Unitsseconds
Default 900
Introduced25.3.R2

Platforms

7705 SAR Gen 2

private-tcp-mss-adjust number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTCP Maximum Segment Size (MSS) on the private side
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name private-tcp-mss-adjust number
Treeprivate-tcp-mss-adjust

Description

This command specifies the TCP MSS to adjust for tunnels on the private side. The value is used to adjust the TCP MSS option in the TCP SYN packet.

Range512 to 9000
Unitsbytes
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

propagate-pmtu-v4 boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable propagation of the path MTU to IPv4 hosts
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name propagate-pmtu-v4 boolean
Treepropagate-pmtu-v4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

propagate-pmtu-v6 boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable propagation of path MTU to IPv6 hosts
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name propagate-pmtu-v6 boolean
Treepropagate-pmtu-v6
Introduced25.3.R2

Platforms

7705 SAR Gen 2

public-tcp-mss-adjust (number | keyword)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTCP Maximum Segment Size (MSS) on the public side
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name public-tcp-mss-adjust (number | keyword)
Treepublic-tcp-mss-adjust

Description

This command specifies the TCP MSS for TCP traffic sent from the public network to the private network. The value is used to adjust the TCP MSS option in the TCP SYN packet.

Range512 to 9000
Unitsbytes
Options auto
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

reassembly (number | keyword)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum reassembly wait time
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name reassembly (number | keyword)
Treereassembly

Description

This command configures the maximum time to wait to receive all fragments of a particular IPsec or GRE packet for reassembly.

Range1 to 5000
Unitsmilliseconds
Options use-tunnel-group-setting, none
Introduced25.3.R2

Platforms

7705 SAR Gen 2

remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRemote IP address of the tunnel
Contextconfigure service vprn service-name interface interface-name sap sap ip-tunnel interface-name remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeremote-ip-address
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipsec-gateway [name] named-item
Synopsis Enter the ipsec-gateway list instance
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item
Treeipsec-gateway
Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[name] named-item
Synopsis IPsec gateway name
Context configure service vprn service-name interface interface-name sap sap ipsec-gateway named-item
Treeipsec-gateway
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

cert
Synopsis Enter the cert context
Context configure service vprn service-name interface interface-name sap sap ipsec-gateway named-item cert
Treecert
Introduced25.3.R2

Platforms

7705 SAR Gen 2

status-verify
Synopsis Enter the status-verify context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item cert status-verify
Treestatus-verify

Description

Commands in this context configure certificate revocation status verification.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

default-result keyword
Synopsis Default result of Certificate Status Verification (CSV)
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item cert status-verify default-result keyword
Treedefault-result

Description

This command specifies the default result when both the primary and secondary methods fail to provide an answer.

Optionsrevoked, good
Default revoked
Introduced25.3.R2

Platforms

7705 SAR Gen 2

client-db
Synopsis Enable the client-db context
Context configure service vprn service-name interface interface-name sap sap ipsec-gateway named-item client-db
Treeclient-db

Description

Commands in this context configure the IPsec client database. The client database is used to authenticate the IKEv2 dynamic LAN-to-LAN tunnel.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

fallback boolean
Synopsis Fall back to the default authentication policy
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item client-db fallback boolean
Treefallback

Description

When configured to true, this command specifies whether the IPsec gateway can fall back to the default authentication policy when the IPsec tunnel authentication request fails to match any clients in the IPsec database.

When configured to false and the client database lookup fails to return a matched result, the system fails the tunnel setup.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

default-secure-service
Synopsis Enable the default-secure-service context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item default-secure-service
Treedefault-secure-service
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface interface-name
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPrivate IPsec tunnel interface name
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item default-secure-service interface interface-name
Treeinterface
String length1 to 32
Introduced25.3.R2

Platforms

7705 SAR Gen 2

service-name service-name
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDefault security service name
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item default-secure-service service-name service-name
Treeservice-name
String length1 to 64
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dhcp-address-assignment
Synopsis Enter the dhcp-address-assignment context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item dhcp-address-assignment
Treedhcp-address-assignment
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dhcpv4
Synopsis Enable the dhcpv4 context
Context configure service vprn service-name interface interface-name sap sap ipsec-gateway named-item dhcp-address-assignment dhcpv4
Treedhcpv4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

gi-address ipv4-unicast-address
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisGateway IP address of DHCPv4 packets sent by the system
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item dhcp-address-assignment dhcpv4 gi-address ipv4-unicast-address
Treegi-address
Introduced25.3.R2

Platforms

7705 SAR Gen 2

server
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the server context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item dhcp-address-assignment dhcpv4 server
Treeserver
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address ipv4-unicast-address
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDHCPv4 server addresses
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item dhcp-address-assignment dhcpv4 server address ipv4-unicast-address
Treeaddress

Description

This command specifies DHCPv4 server addresses for the DHCPv4-based address assignment. If multiple server addresses are specified, the first advertised DHCPv4 address received is chosen.

Max. instances8
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dhcpv6
Synopsis Enable the dhcpv6 context
Context configure service vprn service-name interface interface-name sap sap ipsec-gateway named-item dhcp-address-assignment dhcpv6
Treedhcpv6
Introduced25.3.R2

Platforms

7705 SAR Gen 2

server
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the server context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item dhcp-address-assignment dhcpv6 server
Treeserver
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address ipv6-unicast-address
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDHCPv6 server addresses
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item dhcp-address-assignment dhcpv6 server address ipv6-unicast-address
Treeaddress

Description

This command specifies DHCPv6 server addresses for the DHCPv6-based address assignment. If multiple server addresses are specified, the first advertised DHCPv6 address received is chosen.

Max. instances8
Introduced25.3.R2

Platforms

7705 SAR Gen 2

local
Synopsis Enter the local context
Context configure service vprn service-name interface interface-name sap sap ipsec-gateway named-item local
Treelocal
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address-assignment
Synopsis Enable the address-assignment context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item local address-assignment
Treeaddress-assignment
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the ipv4 context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item local address-assignment ipv4
Treeipv4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dhcp-server named-item
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal DHCPv4 server name
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item local address-assignment ipv4 dhcp-server named-item
Treedhcp-server
String length1 to 32

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

pool named-item
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisName of the pool defined in the specified DHCPv4 server
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item local address-assignment ipv4 pool named-item
Treepool
String length1 to 32

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

router-instance router-instance-base-vprn-loose
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRouter instance ID for the local DHCPv4 server
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item local address-assignment ipv4 router-instance router-instance-base-vprn-loose
Treerouter-instance
String length1 to 64

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

secondary-pool named-item
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisName of the secondary pool defined in the DHCPv4 server
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item local address-assignment ipv4 secondary-pool named-item
Treesecondary-pool
String length1 to 32
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the ipv6 context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item local address-assignment ipv6
Treeipv6
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dhcp-server named-item
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal DHCPv6 server name
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item local address-assignment ipv6 dhcp-server named-item
Treedhcp-server
String length1 to 32

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

pool named-item
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSecondary pool name defined in the DHCPv6 server
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item local address-assignment ipv6 pool named-item
Treepool
String length1 to 32

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

router-instance router-instance-base-vprn-loose
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRouter instance ID hosting the DHCPv6 connection
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item local address-assignment ipv6 router-instance router-instance-base-vprn-loose
Treerouter-instance
String length1 to 64

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal gateway address of the IPsec gateway
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item local gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treegateway-address
Introduced25.3.R2

Platforms

7705 SAR Gen 2

id
Synopsis Enter the id context
Context configure service vprn service-name interface interface-name sap sap ipsec-gateway named-item local id
Treeid

Description

Commands in this context specify the local ID used for the Identification Indicator (IDi) or Identification Responder (IDr) in the IKEv2 tunnel.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

auto
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSelect ID based on authentication method in IKE policy
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item local id auto
Treeauto

Notes

The following elements are part of a choice: auto, fqdn, ipv4, or ipv6.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

fqdn fully-qualified-domain-name
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisFQDN as the local ID type
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item local id fqdn fully-qualified-domain-name
Treefqdn
String length1 to 255

Notes

The following elements are part of a choice: auto, fqdn, ipv4, or ipv6.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4 ipv4-unicast-address
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPv4 address as the local ID type
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item local id ipv4 ipv4-unicast-address
Treeipv4

Notes

The following elements are part of a choice: auto, fqdn, ipv4, or ipv6.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPv6 address as the local ID type
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item local id ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
Treeipv6

Notes

The following elements are part of a choice: auto, fqdn, ipv4, or ipv6.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

max-history-key-records
Synopsis Enter the max-history-key-records context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-gateway named-item max-history-key-records
Treemax-history-key-records
Introduced25.3.R2

Platforms

7705 SAR Gen 2

radius
Synopsis Enter the radius context
Context configure service vprn service-name interface interface-name sap sap ipsec-gateway named-item radius
Treeradius
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipsec-tunnel [name] named-item
Synopsis Enter the ipsec-tunnel list instance
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item
Treeipsec-tunnel
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[name] named-item
Synopsis IPsec tunnel name
Context configure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item
Treeipsec-tunnel
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the IPsec tunnel
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the bfd context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item bfd
Treebfd
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd-designate boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDesignate IPsec tunnel to carry BFD traffic
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item bfd bfd-designate boolean
Treebfd-designate
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd-liveness
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the bfd-liveness context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item bfd bfd-liveness
Treebfd-liveness

Description

Commands in this context configure a BFD session to provide a heart-beat mechanism for a specified IPsec tunnel. There can be only one BFD session assigned to any given IPsec tunnel, but there can be multiple IPsec tunnels using the same BFD session.

BFD controls the state of the association tunnel. If the BFD session goes down, the system brings down the associated non-designated IPsec tunnel.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

dest-ip ipv4-unicast-address
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDestination address used for the BFD session
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item bfd bfd-liveness dest-ip ipv4-unicast-address
Treedest-ip

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface interface-name
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisName of the interface used by the BFD session
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item bfd bfd-liveness interface interface-name
Treeinterface
String length1 to 32

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

service-name service-name
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative service name
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item bfd bfd-liveness service-name service-name
Treeservice-name

Description

This command configures the name of the service where BFD traffic is forwarded to.

String length1 to 64

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

clear-df-bit boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisReset the DF bit to 0 in all payload IP packets
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item clear-df-bit boolean
Treeclear-df-bit

Description

When configured to true, the DF bit is set to 0 in all payload IP packets associated with the IPsec tunnel, before any potential fragmentation occurs.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

copy-traffic-class-upon-decapsulation boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable traffic class copy upon decapsulation
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item copy-traffic-class-upon-decapsulation boolean
Treecopy-traffic-class-upon-decapsulation

Description

When configured to true, the system copies the traffic class from the outer tunnel IP packet header to the payload IP packet header in the decapsulating direction (public to private).

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dest-ip [address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Add a list entry for dest-ip
Context configure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item dest-ip (ipv4-address-no-zone | ipv6-address-no-zone)
Treedest-ip
Max. instances16
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Private IP address of the remote IP tunnel endpoint
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item dest-ip (ipv4-address-no-zone | ipv6-address-no-zone)
Treedest-ip

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

encapsulated-ip-mtu number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum size of the encapsulated tunnel packet
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item encapsulated-ip-mtu number
Treeencapsulated-ip-mtu

Description

This command specifies the maximum size of the encapsulated tunnel packet to the IPsec tunnel, the IP tunnel, or the dynamic tunnels terminated on the IPsec Gateway. If the encapsulated IPv4 or IPv6 tunnel packet exceeds this value, the system fragments the packet.

Range512 to 9000
Unitsbytes
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

icmp-generation
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the icmp-generation context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item icmp-generation
Treeicmp-generation

Description

Commands in this context configure settings for ICMPv4 message generation.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

frag-required
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the frag-required context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item icmp-generation frag-required
Treefrag-required

Description

Commands in this context configure the attributes for sending generated ICMP Destination Unreachable "fragmentation needed and DF set" messages (type 3, code 4) back to the source, if the received size of the IPv4 packet on the private side exceeds the private MTU size.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of sending ICMP messages
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item icmp-generation frag-required admin-state keyword
Treeadmin-state

Description

This command configures the administrative state of sending ICMP Destination Unreachable "fragmentation needed, DF set" messages (type 3, code 4) messages to the source if the received size of the IPv4 packet on the private side exceeds the private MTU size.

Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interval number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisInterval for sending ICMP messages
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item icmp-generation frag-required interval number
Treeinterval

Description

This command configures the interval for sending ICMP Destination Unreachable "fragmentation needed, DF set" messages (type 3, code 4).

Range1 to 60
Unitsseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

message-count number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of ICMP messages that can be sent
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item icmp-generation frag-required message-count number
Treemessage-count

Description

This command configures the maximum number of ICMP Destination Unreachable "fragmentation needed, DF set" messages (type 3, code 4) that can be sent during the configured interval.

Range10 to 1000
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

icmp6-generation
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the icmp6-generation context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item icmp6-generation
Treeicmp6-generation

Description

Commands in this context configure settings for ICMPv6 message generation.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

packet-too-big
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the packet-too-big context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item icmp6-generation packet-too-big
Treepacket-too-big

Description

Commands in this context configure the parameters to send ICMPv6 PTB (Packet Too Big) messages on the private side.

The system sends PTB messages if a received IPv6 packet on the private side is greater than 1280 bytes and it exceeds the private MTU of the tunnel.

The private MTU for the tunnel is configured via the configure router interface ipsec ipsec-tunnel ip-mtu command for the interface.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of Packet Too Big message sends
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item icmp6-generation packet-too-big admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interval number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisInterval for sending Packet Too Big messages
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item icmp6-generation packet-too-big interval number
Treeinterval
Range1 to 60
Unitsseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

message-count number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of ICMPv6 PTB messages that can be sent
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item icmp6-generation packet-too-big message-count number
Treemessage-count

Description

This command configures the maximum number of PTB messages that can be sent during the configured interval.

Range10 to 1000
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

ip-mtu number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPrivate MTU of the IPsec tunnel
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item ip-mtu number
Treeip-mtu

Description

This command specifies the private MTU of the IPsec tunnel. The private MTU is used to determine the need for fragmentation before encapsulation of the payload packet.

Range512 to 9000
Unitsbytes
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

key-exchange
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the key-exchange context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item key-exchange
Treekey-exchange
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dynamic
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the dynamic context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item key-exchange dynamic
Treedynamic

Notes

The following elements are part of a choice: dynamic or manual.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

auto-establish boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAttempt to establish a phase 1 exchange automatically
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item key-exchange dynamic auto-establish boolean
Treeauto-establish
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

cert
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the cert context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item key-exchange dynamic cert
Treecert

Description

Commands in this context configure the attributes of the dynamic keying certificate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

status-verify
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the status-verify context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item key-exchange dynamic cert status-verify
Treestatus-verify

Description

Commands in this context configure attributes of Certificate Status Verification (CSV).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

default-result keyword
Synopsis Default result for Certificate Status Verification
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item key-exchange dynamic cert status-verify default-result keyword
Treedefault-result

Description

This command specifies the default certificate revocation status result to use when all configured CSV methods fail to return a result.   

Optionsrevoked, good
Default revoked
Introduced25.3.R2

Platforms

7705 SAR Gen 2

primary keyword
Synopsis Primary method of CSV to verify the revocation status
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item key-exchange dynamic cert status-verify primary keyword
Treeprimary

Description

This command configures the primary method of Certificate Status Verification (CSV) that is used to verify the revocation status of the certificate of the peer.

Optionscrl, ocsp
Default crl
Introduced25.3.R2

Platforms

7705 SAR Gen 2

secondary keyword
Synopsis Secondary method used to verify certificate revocation
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item key-exchange dynamic cert status-verify secondary keyword
Treesecondary

Description

This command specifies the secondary method of Certificate Status Verification (CSV) that is used to verify the revocation status of the peer certificate.

Optionsnone, crl, ocsp
Defaultnone
Introduced25.3.R2

Platforms

7705 SAR Gen 2

id
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the id context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item key-exchange dynamic id
Treeid

Description

Commands in this context specify the local ID used for IDi or IDr for IKEv2 negotiation.

The default behavior depends on the local authentication method as follows:

  • Psk: local tunnel IP address

  • Cert-auth: subject of the local certificate

Introduced25.3.R2

Platforms

7705 SAR Gen 2

fqdn fully-qualified-domain-name
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisFQDN used as the local ID IKE type
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item key-exchange dynamic id fqdn fully-qualified-domain-name
Treefqdn
String length1 to 255

Notes

The following elements are part of a choice: fqdn, ipv4, or ipv6.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4 ipv4-unicast-address
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPv4 as the local ID type
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item key-exchange dynamic id ipv4 ipv4-unicast-address
Treeipv4

Notes

The following elements are part of a choice: fqdn, ipv4, or ipv6.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPv6 used as the local IKE ID type
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item key-exchange dynamic id ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
Treeipv6

Notes

The following elements are part of a choice: fqdn, ipv4, or ipv6.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ike-policy reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIKE policy ID
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item key-exchange dynamic ike-policy reference
Treeike-policy

Description

This command specifies the ID of the IKE policy used for IKE negotiation.

The ipsec-transport-mode-profile configuration only supports IKEv2.

Reference

configure ipsec ike-policy number

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipsec-transform reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPsec transform IDs used by the dynamic key
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item key-exchange dynamic ipsec-transform reference
Treeipsec-transform

Description

This command specifies IPsec transform IDs used for CHILD_SA negotiation.

Reference

configure ipsec ipsec-transform number

Max. instances4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ppk
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the ppk context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item key-exchange dynamic ppk
Treeppk

Description

Commands in this context configure the PPKs to use for dynamic keying of the IPsec tunnel.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

id reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPPK ID
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item key-exchange dynamic ppk id reference
Treeid

Reference

configure ipsec ppk-list named-item ppk named-item-64

Introduced25.3.R2

Platforms

7705 SAR Gen 2

list reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPPK list instance name
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item key-exchange dynamic ppk list reference
Treelist

Reference

configure ipsec ppk-list named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

pre-shared-key encrypted-leaf
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPre-shared key for authentication
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item key-exchange dynamic pre-shared-key encrypted-leaf
Treepre-shared-key
String length1 to 115
Introduced25.3.R2

Platforms

7705 SAR Gen 2

manual
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the manual context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item key-exchange manual
Treemanual

Notes

The following elements are part of a choice: dynamic or manual.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

keys [security-association] number direction keyword
Synopsis Enter the keys list instance
Context configure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item key-exchange manual keys number direction keyword
Treekeys

Description

Commands in this context configure the security association list for the tunnel.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

spi number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSPI of inbound and outbound packets
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item key-exchange manual keys number direction keyword spi number
Treespi

Description

This command specifies the Security Parameter Index (SPI) used to look up the instruction to verify and decrypt the incoming IPsec packets when the direction is inbound. When the direction is outbound, the SPI is used in the encoding of the outgoing packets.

The remote node can use the SPI to look up the instruction to verify and decrypt the packet.

Range256 to 16383

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

max-history-key-records
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the max-history-key-records context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item max-history-key-records
Treemax-history-key-records

Description

Commands in this context configure the settings for recording historical IPsec keys.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

esp number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of recent records
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item max-history-key-records esp number
Treeesp
Range1 to 48
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ike number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of historical IKE key records
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item max-history-key-records ike number
Treeike
Range1 to 3
Introduced25.3.R2

Platforms

7705 SAR Gen 2

pmtu-discovery-aging number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAging out time of the learned path MTU
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item pmtu-discovery-aging number
Treepmtu-discovery-aging

Description

This command configures the temporary public and private MTU expiration time. The temporary MTU is used for MTU propagation.

Range900 to 3600
Unitsseconds
Default 900
Introduced25.3.R2

Platforms

7705 SAR Gen 2

private-tcp-mss-adjust number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTCP maximum segment size (MSS) adjustment
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item private-tcp-mss-adjust number
Treeprivate-tcp-mss-adjust

Description

This command specifies the TCP MSS to adjust for the tunnel on the private side.

When configured, the system may use the value to update the MSS option in the received TCP SYN packet on the private side.

Range512 to 9000
Unitsbytes
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

propagate-pmtu-v4 boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable propagation of the path MTU to IPv4 hosts
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item propagate-pmtu-v4 boolean
Treepropagate-pmtu-v4

Description

When configured to true, the system propagates the path MTU learned from the public side to the private side (IPv4 hosts).

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

propagate-pmtu-v6 boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable propagation of the path MTU to IPv6 hosts
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item propagate-pmtu-v6 boolean
Treepropagate-pmtu-v6

Description

When configured to true, the system propagates the path MTU learned from the public side to the private side (IPv6 hosts).

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

public-tcp-mss-adjust (number | keyword)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTCP maximum segment size (MSS) on the public network
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item public-tcp-mss-adjust (number | keyword)
Treepublic-tcp-mss-adjust

Description

This command configures the MSS for the TCP traffic in an IPsec tunnel that is sent from the public network to the private network. The system may use this value to adjust or insert the MSS option in the TCP SYN packet.

Range512 to 9000
Unitsbytes
Options auto
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

replay-window number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAnti-replay window size
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item replay-window number
Treereplay-window

Description

This command specifies the size of an IPsec anti-replay window. If unconfigured, IPsec anti-replay is disabled.

Range32 | 64 | 128 | 256 | 512
Unitspackets
Introduced25.3.R2

Platforms

7705 SAR Gen 2

security-policy
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the security-policy context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item security-policy
Treesecurity-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

strict-match boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable strict match of the security policy entry
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item security-policy strict-match boolean
Treestrict-match

Description

When configured to true, this command enables strict match of the security policy entry.

When a CREATE_CHILD exchange request is received for a static IPsec tunnel, and this request is not a rekey request, ISA matches the received TSi and TSr with the configured security policy. This can be a match only when a received TS (in TSi or TSr) address range matches exactly with the subnet in a security policy entry.

If there is no match, the setup fails, and TS_UNACCEPTABLE is sent.

If there is a match, but there is an existing CHILD_SA for the matched security policy, the setup fails, and NO_PROPOSAL_CHOSEN is sent.

If there is a match, and there is not a CHILD_SA for the matched entry, the subnet is sent in the matched security policy entry as TSi and TSr, and the CHILD_SA is created.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

tunnel-endpoint
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the tunnel-endpoint context
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item tunnel-endpoint
Treetunnel-endpoint
Introduced25.3.R2

Platforms

7705 SAR Gen 2

delivery-service service-name
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDelivery service name
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item tunnel-endpoint delivery-service service-name
Treedelivery-service
String length1 to 64

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

local-gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAddress used for tunnel of the remote security gateway
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item tunnel-endpoint local-gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treelocal-gateway-address

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRemote IP address of the tunnel
Contextconfigure service vprn service-name interface interface-name sap sap ipsec-tunnel named-item tunnel-endpoint remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeremote-ip-address

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lag
Synopsis Enter the lag context
Context configure service vprn service-name interface interface-name sap sap lag
Treelag
Introduced25.3.R2

Platforms

7705 SAR Gen 2

spoke-sdp [sdp-bind-id] sdp-bind-id
Synopsis Enter the spoke-sdp list instance
Contextconfigure service vprn service-name interface interface-name spoke-sdp sdp-bind-id
Treespoke-sdp
Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[sdp-bind-id] sdp-bind-id
Synopsis SDP binding ID
Contextconfigure service vprn service-name interface interface-name spoke-sdp sdp-bind-id
Treespoke-sdp
String length3 to 16

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the SDP binding to the service
Contextconfigure service vprn service-name interface interface-name spoke-sdp sdp-bind-id admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

egress
Synopsis Enter the egress context
Context configure service vprn service-name interface interface-name spoke-sdp sdp-bind-id egress
Treeegress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter
Synopsis Enter the filter context
Context configure service vprn service-name interface interface-name spoke-sdp sdp-bind-id egress filter
Treefilter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

qos
Synopsis Enter the qos context
Context configure service vprn service-name interface interface-name spoke-sdp sdp-bind-id egress qos
Treeqos
Introduced25.3.R2

Platforms

7705 SAR Gen 2

network
Synopsis Enter the network context
Context configure service vprn service-name interface interface-name spoke-sdp sdp-bind-id egress qos network
Treenetwork
Introduced25.3.R2

Platforms

7705 SAR Gen 2

port-redirect-group
Synopsis Enter the port-redirect-group context
Contextconfigure service vprn service-name interface interface-name spoke-sdp sdp-bind-id egress qos network port-redirect-group
Treeport-redirect-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEgress MPLS VC label to send packets to the far end
Contextconfigure service vprn service-name interface interface-name spoke-sdp sdp-bind-id egress vc-label number
Treevc-label
Range16 to 1048575
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hash-label
Synopsis Enable the hash-label context
Context configure service vprn service-name interface interface-name spoke-sdp sdp-bind-id hash-label
Treehash-label

Description

Commands in this context configure the use of hash labels for egress datapaths.

For information about hash-label handling, see the "Hash labels" section of the 7705 SAR Gen 2 MPLS Guide.

Notes

The following elements are part of a choice: entropy-label or hash-label.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

signal-capability
Synopsis Signal hash label capability to the remote PE
Contextconfigure service vprn service-name interface interface-name spoke-sdp sdp-bind-id hash-label signal-capability
Treesignal-capability

Description

When configured, this command enables the signaling and negotiating of the hash label between the local and remote PE nodes.

The signaling process outcome determines whether the local PE inserts the hash label on the user packets. This outcome can override the local PE configuration.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ingress
Synopsis Enter the ingress context
Context configure service vprn service-name interface interface-name spoke-sdp sdp-bind-id ingress
Treeingress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter
Synopsis Enter the filter context
Context configure service vprn service-name interface interface-name spoke-sdp sdp-bind-id ingress filter
Treefilter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

qos
Synopsis Enter the qos context
Context configure service vprn service-name interface interface-name spoke-sdp sdp-bind-id ingress qos
Treeqos
Introduced25.3.R2

Platforms

7705 SAR Gen 2

network
Synopsis Enter the network context
Context configure service vprn service-name interface interface-name spoke-sdp sdp-bind-id ingress qos network
Treenetwork
Introduced25.3.R2

Platforms

7705 SAR Gen 2

fp-redirect-group
Synopsis Enter the fp-redirect-group context
Contextconfigure service vprn service-name interface interface-name spoke-sdp sdp-bind-id ingress qos network fp-redirect-group
Treefp-redirect-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIngress MPLS VC label to send packets to the far end
Contextconfigure service vprn service-name interface interface-name spoke-sdp sdp-bind-id ingress vc-label number
Treevc-label
Range1 to 1048575
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vc-type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisType of virtual circuit (VC) associated with the SDP binding
Contextconfigure service vprn service-name interface interface-name spoke-sdp sdp-bind-id vc-type keyword
Treevc-type
Optionsether, ipipe
Default ether
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static-tunnel-redundant-nexthop ipv4-unicast-address
Synopsis Address for the static ISA tunnel redundant next-hop
Contextconfigure service vprn service-name interface interface-name static-tunnel-redundant-nexthop ipv4-unicast-address
Treestatic-tunnel-redundant-nexthop

Description

This command configures a redundant next-hop address on a public or private IPsec interface (with a public or private tunnel SAP) for a static IPsec tunnel in 1:1 MC-IPsec. A standby node uses the specified next-hop address to shunt traffic to the master in case it receives traffic destined to a tunnel endpoint address. The standby tunnel group needs to be operationally up for the feature to work.

The next-hop address is resolved in the routing table of the corresponding service.

Notes

The following elements are part of a choice: multi-chassis-shunting-profile or (dynamic-tunnel-redundant-nexthop and static-tunnel-redundant-nexthop).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

tunnel boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEnable/disable tunnel interface
Contextconfigure service vprn service-name interface interface-name tunnel boolean
Treetunnel
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vpls [vpls-name] named-item-64
Synopsis Enter the vpls list instance
Context configure service vprn service-name interface interface-name vpls named-item-64
Treevpls
Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[vpls-name] named-item-64
Synopsis VPLS service
Contextconfigure service vprn service-name interface interface-name vpls named-item-64
Treevpls
String length1 to 64

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

egress
Synopsis Enter the egress context
Context configure service vprn service-name interface interface-name vpls named-item-64 egress
Treeegress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

routed-override-filter
Synopsis Enter the routed-override-filter context
Contextconfigure service vprn service-name interface interface-name vpls named-item-64 egress routed-override-filter
Treerouted-override-filter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

evpn
Synopsis Enter the evpn context
Context configure service vprn service-name interface interface-name vpls named-item-64 evpn
Treeevpn
Introduced25.3.R2

Platforms

7705 SAR Gen 2

arp
Synopsis Enter the arp context
Context configure service vprn service-name interface interface-name vpls named-item-64 evpn arp
Treearp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

advertise [route-type] keyword
Synopsis Enter the advertise list instance
Contextconfigure service vprn service-name interface interface-name vpls named-item-64 evpn arp advertise keyword
Treeadvertise

Description

Commands in this context specify the configuration to allow ARP or ND entries that are installed in the ARP or ND cache to be advertised in EVPN MAC/IP routes.

The learn-dynamic command must be set to false when using this functionality.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[route-type] keyword
Synopsis Type of ARP or ND entries that generate host routes
Contextconfigure service vprn service-name interface interface-name vpls named-item-64 evpn arp advertise keyword
Treeadvertise

Description

This command specifies the type of ARP or ND entries that are installed in the ARP or ND cache into EVPN MAC/IP routes.

Optionsstatic, dynamic

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface-less-routing
Synopsis Enable the interface-less-routing context
Contextconfigure service vprn service-name interface interface-name vpls named-item-64 evpn arp advertise keyword interface-less-routing
Treeinterface-less-routing

Description

Commands in this context enable the entries for advertisement in EVPN MAC/IP advertisement routes that include:

  • the label1 and route target of the R-VPLS EVPN service

  • the label2 value and route target of the EVPN interface-less instance in the linked VPRN

Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp-evpn-instance number
Synopsis EVPN interface-less VPRN instance
Context configure service vprn service-name interface interface-name vpls named-item-64 evpn arp advertise keyword interface-less-routing bgp-evpn-instance number
Treebgp-evpn-instance

Description

This command configures the EVPN interface-less BGP instance from which the label and route target are taken when advertising the entry in an EVPN MAC/IP advertisement route.

Range1
Default 1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-tag number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTag value used with the host route from an ARP/ND entry
Contextconfigure service vprn service-name interface interface-name vpls named-item-64 evpn arp advertise keyword route-tag number
Treeroute-tag

Description

This command specifies the route tag that is added separately to dynamic or static ARP or ND entries that are advertised in EVPN MAC/IP routes. This tag can be matched on BGP vsi-export (in the R-VPLS) and BGP peer export policies. 

Range0 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

flood-garp-and-unknown-req boolean
Synopsis Allow CPM originated ARP frames to flood R-VPLS service
Contextconfigure service vprn service-name interface interface-name vpls named-item-64 evpn arp flood-garp-and-unknown-req boolean
Treeflood-garp-and-unknown-req

Description

When configured to true, the system allows CPM-originated ARP frames to be flooded in the R-VPLS service. Any frames that are data path flooded such as the ARP messages received on a SAP, are flooded irrespective of this command.

When configured to false, CPM-originated ARP flooding is suppressed.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

learn-dynamic boolean
Synopsis Process ARP or ND messages on EVPN tunnels
Contextconfigure service vprn service-name interface interface-name vpls named-item-64 evpn arp learn-dynamic boolean
Treelearn-dynamic

Description

When configured to true, the system processes ARP or ND messages that arrive on EVPN tunnels.

When configured to false, learning is disabled and table entries are not created for these messages.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

nd
Synopsis Enter the nd context
Context configure service vprn service-name interface interface-name vpls named-item-64 evpn nd
Treend
Introduced25.3.R2

Platforms

7705 SAR Gen 2

advertise [route-type] keyword
Synopsis Enter the advertise list instance
Contextconfigure service vprn service-name interface interface-name vpls named-item-64 evpn nd advertise keyword
Treeadvertise

Description

Commands in this context specify the configuration to allow ARP or ND entries that are installed in the ARP or ND cache to be advertised in EVPN MAC/IP routes.

The learn-dynamic command must be set to false when using this functionality.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[route-type] keyword
Synopsis Type of ARP or ND entries that generate host routes
Contextconfigure service vprn service-name interface interface-name vpls named-item-64 evpn nd advertise keyword
Treeadvertise

Description

This command specifies the type of ARP or ND entries that are installed in the ARP or ND cache into EVPN MAC/IP routes.

Optionsstatic, dynamic

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface-less-routing
Synopsis Enable the interface-less-routing context
Contextconfigure service vprn service-name interface interface-name vpls named-item-64 evpn nd advertise keyword interface-less-routing
Treeinterface-less-routing

Description

Commands in this context enable the entries for advertisement in EVPN MAC/IP advertisement routes that include:

  • the label1 and route target of the R-VPLS EVPN service

  • the label2 value and route target of the EVPN interface-less instance in the linked VPRN

Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp-evpn-instance number
Synopsis EVPN interface-less VPRN instance
Context configure service vprn service-name interface interface-name vpls named-item-64 evpn nd advertise keyword interface-less-routing bgp-evpn-instance number
Treebgp-evpn-instance

Description

This command configures the EVPN interface-less BGP instance from which the label and route target are taken when advertising the entry in an EVPN MAC/IP advertisement route.

Range1
Default 1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-tag number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTag value used with the host route from an ARP/ND entry
Contextconfigure service vprn service-name interface interface-name vpls named-item-64 evpn nd advertise keyword route-tag number
Treeroute-tag

Description

This command specifies the route tag that is added separately to dynamic or static ARP or ND entries that are advertised in EVPN MAC/IP routes. This tag can be matched on BGP vsi-export (in the R-VPLS) and BGP peer export policies. 

Range0 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

learn-dynamic boolean
Synopsis Process ARP or ND messages on EVPN tunnels
Contextconfigure service vprn service-name interface interface-name vpls named-item-64 evpn nd learn-dynamic boolean
Treelearn-dynamic

Description

When configured to true, the system processes ARP or ND messages that arrive on EVPN tunnels.

When configured to false, learning is disabled and table entries are not created for these messages.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

evpn-tunnel
Synopsis Enable the evpn-tunnel context
Contextconfigure service vprn service-name interface interface-name vpls named-item-64 evpn-tunnel
Treeevpn-tunnel
Introduced25.3.R2

Platforms

7705 SAR Gen 2

supplementary-broadcast-domain boolean
Synopsis Use the EVPN tunnel as a Supplementary Broadcast Domain
Contextconfigure service vprn service-name interface interface-name vpls named-item-64 evpn-tunnel supplementary-broadcast-domain boolean
Treesupplementary-broadcast-domain

Description

When configured to true, this command allows the EVPN tunnel to be used as a Supplementary Broadcast Domain (SBD). The SBD is used in EVPN OISM to advertise the SMET routes and to receive the multicast traffic on egress PEs that are not attached to the source R-VPLS service.

When configured to false, this command disables EVPN tunnel use as an SBD.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ingress
Synopsis Enter the ingress context
Context configure service vprn service-name interface interface-name vpls named-item-64 ingress
Treeingress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

routed-override-filter
Synopsis Enter the routed-override-filter context
Contextconfigure service vprn service-name interface interface-name vpls named-item-64 ingress routed-override-filter
Treerouted-override-filter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip reference
Synopsis IPv4 filter policy name
Context configure service vprn service-name interface interface-name vpls named-item-64 ingress routed-override-filter ip reference
Treeip

Description

This command specifies an IP filter that is applied to routed unicast ingress packets entering the VPLS service and destined to the R-VPLS interface MAC address.

The filter overrides any existing ingress IP filter applied to SAPs or SDP bindings for packets associated with the routing IP interface. The override filter is optional and when it is not defined or it is removed, the IP routed packets use the existing ingress IP filter configured on the VPLS endpoint.

Reference

configure filter ip-filter filter-name

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6 reference
Synopsis IPv6 filter policy name
Context configure service vprn service-name interface interface-name vpls named-item-64 ingress routed-override-filter ipv6 reference
Treeipv6

Description

This command specifies an IPv6 filter that is applied to routed unicast ingress packets entering the VPLS service and destined to the R-VPLS interface MAC address.

The filter overrides any existing ingress IP filter applied to SAPs or SDP bindings for packets associated with the routing IP interface. The override filter is optional and when it is not defined or it is removed, the IP routed packets use the existing ingress IP filter configured on the VPLS endpoint.

Reference

configure filter ipv6-filter filter-name

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-mirror-interface [interface-name] interface-name
Synopsis Enter the ip-mirror-interface list instance
Contextconfigure service vprn service-name ip-mirror-interface interface-name
Treeip-mirror-interface
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[interface-name] interface-name
Synopsis Interface name
Contextconfigure service vprn service-name ip-mirror-interface interface-name
Treeip-mirror-interface
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

spoke-sdp [sdp-bind-id] sdp-bind-id
Synopsis Enter the spoke-sdp list instance
Contextconfigure service vprn service-name ip-mirror-interface interface-name spoke-sdp sdp-bind-id
Treespoke-sdp
Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[sdp-bind-id] sdp-bind-id
Synopsis SDP binding ID
Contextconfigure service vprn service-name ip-mirror-interface interface-name spoke-sdp sdp-bind-id
Treespoke-sdp
String length3 to 16

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ingress
Synopsis Enter the ingress context
Context configure service vprn service-name ip-mirror-interface interface-name spoke-sdp sdp-bind-id ingress
Treeingress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSpoke SDP ingress VC label
Contextconfigure service vprn service-name ip-mirror-interface interface-name spoke-sdp sdp-bind-id ingress vc-label number
Treevc-label
Range1 to 1048575
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipsec
Synopsis Enter the ipsec context
Context configure service vprn service-name ipsec
Treeipsec
Introduced25.3.R2

Platforms

7705 SAR Gen 2

allow-reverse-route-override-type keyword
Synopsis System behavior for new reverse route
Contextconfigure service vprn service-name ipsec allow-reverse-route-override-type keyword
Treeallow-reverse-route-override-type

Description

This command specifies the system behavior when a new reverse route overlaps with an existing reverse route.

When unconfigured, the system does not allow a new dynamic LAN-to-LAN tunnel that terminates in the private VPRN service to be created with an overlapping reverse route.

Optionssame-idi, any-idi
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

multi-chassis-shunt-interface [name] reference
Synopsis Enter the multi-chassis-shunt-interface list instance
Contextconfigure service vprn service-name ipsec multi-chassis-shunt-interface reference
Treemulti-chassis-shunt-interface
Introduced25.3.R2

Platforms

7705 SAR Gen 2

next-hop
Synopsis Enter the next-hop context
Context configure service vprn service-name ipsec multi-chassis-shunt-interface reference next-hop
Treenext-hop

Description

Commands in this context configure the next hop for shunting over the interface.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

multi-chassis-shunting-profile [name] named-item
Synopsis Enter the multi-chassis-shunting-profile list instance
Contextconfigure service vprn service-name ipsec multi-chassis-shunting-profile named-item
Treemulti-chassis-shunting-profile
Max. instances64
Introduced25.3.R2

Platforms

7705 SAR Gen 2

peer [ip-address] reference
Synopsis Enter the peer list instance
Context configure service vprn service-name ipsec multi-chassis-shunting-profile named-item peer reference
Treepeer
Max. instances3
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overlapping-reverse-route boolean
Synopsis Accept overlapping DL2L tunnel reverse routes
Contextconfigure service vprn service-name ipsec overlapping-reverse-route boolean
Treeoverlapping-reverse-route

Description

When configured to true, the router accepts overlapping DL2L tunnel reverse routes from different tunnels and installs the routes based on the preference, metric, or ECMP configuration.

When configured to false, the router does not accept overlapping reverse routes and handles the overlapping route according to the configure service vprn ipsec allow-reverse-route-override-type command configuration.

This command is mutually exclusive with the allow-reverse-route-override-type command.

See the 7705 SAR Gen 2 Multiservice ISA and ESA Guide for more information.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

security-policy [id] number
Synopsis Enter the security-policy list instance
Contextconfigure service vprn service-name ipsec security-policy number
Treesecurity-policy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[id] number
Synopsis IPsec security policy ID
Context configure service vprn service-name ipsec security-policy number
Treesecurity-policy
Range1 to 32768

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure service vprn service-name ipsec security-policy number entry number
Treeentry
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[entry-id] number
Synopsis IPsec security policy entry ID
Context configure service vprn service-name ipsec security-policy number entry number
Treeentry
Range1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

local-ip
Synopsis Enter the local-ip context
Context configure service vprn service-name ipsec security-policy number entry number local-ip
Treelocal-ip

Description

Commands in this context configure the local (from the VPN) IPv4 prefix/mask for the policy entry.

The system evaluates the local IP as the source IP when traffic is examined in the direction of the flows from private to public and as the destination IP when traffic flows from public to private.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

address ipv4-prefix
Synopsis Destination IPv4 address of the aggregate route
Contextconfigure service vprn service-name ipsec security-policy number entry number local-ip address ipv4-prefix
Treeaddress

Notes

The following elements are part of a choice: address or any.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

any boolean
Synopsis Use any IP address
Context configure service vprn service-name ipsec security-policy number entry number local-ip any boolean
Treeany
Defaultfalse

Notes

The following elements are part of a choice: address or any.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

local-ipv6
Synopsis Enter the local-ipv6 context
Context configure service vprn service-name ipsec security-policy number entry number local-ipv6
Treelocal-ipv6

Description

Commands in this context configure the local (from the VPN) IPv6 prefix/mask for the policy entry.

The system evaluates the local IP as the source IP when traffic is examined in the direction of the flows from private to public and as the destination IP when traffic flows from public to private.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

address ipv6-prefix
Synopsis Destination IPv6 address of the aggregate route
Contextconfigure service vprn service-name ipsec security-policy number entry number local-ipv6 address ipv6-prefix
Treeaddress

Notes

The following elements are part of a choice: address or any.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

any boolean
Synopsis Use any IP address
Context configure service vprn service-name ipsec security-policy number entry number local-ipv6 any boolean
Treeany
Defaultfalse

Notes

The following elements are part of a choice: address or any.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

remote-ip
Synopsis Enter the remote-ip context
Context configure service vprn service-name ipsec security-policy number entry number remote-ip
Treeremote-ip

Description

Commands in this context configure the remote (from the tunnel) IP prefix/mask for the policy entry.

The system evaluates the remote IP as the source IP when traffic flows public to private and as the destination IP when traffic flows from private to public.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

address ipv4-prefix
Synopsis Destination IPv4 address of the aggregate route
Contextconfigure service vprn service-name ipsec security-policy number entry number remote-ip address ipv4-prefix
Treeaddress

Notes

The following elements are part of a choice: address or any.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

any boolean
Synopsis Use any IP address
Context configure service vprn service-name ipsec security-policy number entry number remote-ip any boolean
Treeany
Defaultfalse

Notes

The following elements are part of a choice: address or any.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

remote-ipv6
Synopsis Enter the remote-ipv6 context
Context configure service vprn service-name ipsec security-policy number entry number remote-ipv6
Treeremote-ipv6

Description

Commands in this context configure the remote (from the tunnel) IPv6 prefix/mask for the policy entry.

The system evaluates the remote IP as the source IP when traffic flows from public to private and as the destination IP when traffic flows from private to public.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

address ipv6-prefix
Synopsis Destination IPv6 address of the aggregate route
Contextconfigure service vprn service-name ipsec security-policy number entry number remote-ipv6 address ipv6-prefix
Treeaddress

Notes

The following elements are part of a choice: address or any.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

any boolean
Synopsis Use any IP address
Context configure service vprn service-name ipsec security-policy number entry number remote-ipv6 any boolean
Treeany
Defaultfalse

Notes

The following elements are part of a choice: address or any.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6
Synopsis Enter the ipv6 context
Context configure service vprn service-name ipv6
Treeipv6
Introduced25.3.R2

Platforms

7705 SAR Gen 2

neighbor-discovery
Synopsis Enter the neighbor-discovery context
Contextconfigure service vprn service-name ipv6 neighbor-discovery
Treeneighbor-discovery
Introduced25.3.R2

Platforms

7705 SAR Gen 2

router-advertisement
Synopsis Enter the router-advertisement context
Contextconfigure service vprn service-name ipv6 router-advertisement
Treerouter-advertisement
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dns-options
Synopsis Enable the dns-options context
Contextconfigure service vprn service-name ipv6 router-advertisement dns-options
Treedns-options
Introduced25.3.R2

Platforms

7705 SAR Gen 2

rdnss-lifetime (keyword | number)
Synopsis Maximum time over which the RDNSS address is valid
Contextconfigure service vprn service-name ipv6 router-advertisement dns-options rdnss-lifetime (keyword | number)
Treerdnss-lifetime

Description

This command specifies the maximum time that the RDNSS address is used for name resolution by the client.

Range0 | 4 to 3600
Unitsseconds
Options infinite
Defaultinfinite
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

interface [ip-int-name] reference
Synopsis Enter the interface list instance
Contextconfigure service vprn service-name ipv6 router-advertisement interface reference
Treeinterface
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dns-options
Synopsis Enable the dns-options context
Contextconfigure service vprn service-name ipv6 router-advertisement interface reference dns-options
Treedns-options
Introduced25.3.R2

Platforms

7705 SAR Gen 2

nd-router-preference keyword
Synopsis Default router preference for Router Advertisements
Contextconfigure service vprn service-name ipv6 router-advertisement interface reference nd-router-preference keyword
Treend-router-preference

Description

This command configures the default router preference for Router Advertisements (RAs) and allows IPv6 hosts to discover and select a default gateway address by listening to RAs.

This feature provides basic traffic engineering functionality for host devices. When this command is applied, the router advertises the respective router preference to the connected host to assist in its selection of the most appropriate default gateway on a link.

This extension is backward compatible, both for routers (setting the router preference bits) and hosts (interpreting the router preference bits). These bits are ignored by hosts that do not implement the RFC 4191 functionality by configuring this command. Similarly, hosts that do not implement the RFC 4191 functionality interpret the values sent by devices that do not implement the RFC 4191 extension as a medium preference.

Optionsmedium, high, low
Defaultmedium
Introduced25.3.R2

Platforms

7705 SAR Gen 2

prefix [ipv6-prefix] ipv6-prefix
Synopsis Enter the prefix list instance
Contextconfigure service vprn service-name ipv6 router-advertisement interface reference prefix ipv6-prefix
Treeprefix
Max. instances254
Introduced25.3.R2

Platforms

7705 SAR Gen 2

isis [isis-instance] number
Synopsis Enter the isis list instance
Context configure service vprn service-name isis number
Treeisis
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[isis-instance] number
Synopsis Instance ID for the IS-IS instance
Context configure service vprn service-name isis number
Treeisis
Range0 to 127
MD-CLI default0

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the IS-IS instance
Contextconfigure service vprn service-name isis number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

all-l1isis mac-address
Synopsis Destination MAC address for all L1 IS-IS routers
Contextconfigure service vprn service-name isis number all-l1isis mac-address
Treeall-l1isis
Default01:80:C2:00:00:14
Introduced25.3.R2

Platforms

7705 SAR Gen 2

all-l2isis mac-address
Synopsis Destination MAC address for all L2 IS-IS routers
Contextconfigure service vprn service-name isis number all-l2isis mac-address
Treeall-l2isis
Default01:80:C2:00:00:15
Introduced25.3.R2

Platforms

7705 SAR Gen 2

area-address area-address
Synopsis Area address portion of the NSAP address
Contextconfigure service vprn service-name isis number area-address area-address
Treearea-address
String length2 to 38
Max. instances3
Introduced25.3.R2

Platforms

7705 SAR Gen 2

authentication-key encrypted-leaf
Synopsis Authentication key to verify PDUs sent from neighbors
Contextconfigure service vprn service-name isis number authentication-key encrypted-leaf
Treeauthentication-key
String length1 to 366
Introduced25.3.R2

Platforms

7705 SAR Gen 2

csnp-on-p2p boolean
Synopsis Send periodic CSNP PDUs on point-to-point interfaces
Contextconfigure service vprn service-name isis number csnp-on-p2p boolean
Treecsnp-on-p2p
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

export-limit
Synopsis Enable the export-limit context
Contextconfigure service vprn service-name isis number export-limit
Treeexport-limit
Introduced25.3.R2

Platforms

7705 SAR Gen 2

number number
Synopsis Maximum routes or prefixes exported from route table
Contextconfigure service vprn service-name isis number export-limit number number
Treenumber
Range1 to 4294967295

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

export-policy reference
Synopsis Export policies that determine exported routes
Contextconfigure service vprn service-name isis number export-policy reference
Treeexport-policy

Description

This command configures export routing policies for the routes exported from the routing table to IS-IS.

If the export policy is undefined, the system does not export non IS-IS routes from the routing table manager to IS-IS.

If multiple policy names are specified, the policies are evaluated in the order they are specified. The first policy that matches is applied.

If the aggregate command is also configured in the configure router context, the aggregation is applied before the export policy is applied.

Routing policies are created in the configure router policy-options context.

Reference

configure policy-options policy-statement named-item-64

Max. instances5

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

hello-padding keyword
Synopsis IS-IS Hello message padding
Context configure service vprn service-name isis number hello-padding keyword
Treehello-padding
Optionsadaptive, loose, strict, none
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

iid-tlv boolean
Synopsis Use IID TLVs with IS-IS multi-instance
Contextconfigure service vprn service-name isis number iid-tlv boolean
Treeiid-tlv
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface [interface-name] interface-name
Synopsis Enter the interface list instance
Contextconfigure service vprn service-name isis number interface interface-name
Treeinterface
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[interface-name] interface-name
Synopsis IP interface name
Context configure service vprn service-name isis number interface interface-name
Treeinterface
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the IS-IS interface
Contextconfigure service vprn service-name isis number interface interface-name admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd-liveness
Synopsis Enter the bfd-liveness context
Contextconfigure service vprn service-name isis number interface interface-name bfd-liveness
Treebfd-liveness

Description

Commands in this context enable the use of bidirectional forwarding (BFD) to control IPv4 and IPv6 adjacencies. Enabling BFD on an IPv4 or IPv6 protocol interface ties the protocol interface state to the BFD session state between the local and remote nodes. BFD must be enabled on the applicable IP interface.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

csnp-interval number
Synopsis Time interval between successive CSN PDUs sent
Contextconfigure service vprn service-name isis number interface interface-name csnp-interval number
Treecsnp-interval
Range1 to 65535
Unitsseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hello-padding keyword
Synopsis Padding on IS-IS Hello packets
Context configure service vprn service-name isis number interface interface-name hello-padding keyword
Treehello-padding
Optionsadaptive, loose, strict, none
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

interface-type keyword
Synopsis Interface type to broadcast, point-to-point, or to be default
Contextconfigure service vprn service-name isis number interface interface-name interface-type keyword
Treeinterface-type
Optionspoint-to-point, broadcast
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

ipv6-unicast boolean
Synopsis Enable IPv6 unicast routing for the interface
Contextconfigure service vprn service-name isis number interface interface-name ipv6-unicast boolean
Treeipv6-unicast
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

level [level-number] keyword
Synopsis Enter the level list instance
Context configure service vprn service-name isis number interface interface-name level keyword
Treelevel
Max. instances2
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[level-number] keyword
Synopsis ISIS protocol level number
Context configure service vprn service-name isis number interface interface-name level keyword
Treelevel
Options1, 2

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

hello-authentication-key encrypted-leaf
Synopsis Authentication key for Hello PDUs
Context configure service vprn service-name isis number interface interface-name level keyword hello-authentication-key encrypted-leaf
Treehello-authentication-key

Description

This command configures the authentication key (password) for Hello PDUs. Both the Hello authentication key and the Hello authentication type on a segment must match.

If both IS-IS and Hello authentication are configured, Hello messages are validated using Hello authentication. If only IS-IS authentication is configured, it is used to authenticate all IS-IS (including Hello) protocol PDUs.

String length1 to 366
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hello-authentication-type keyword
Synopsis Hello authentication enabled on the context
Contextconfigure service vprn service-name isis number interface interface-name level keyword hello-authentication-type keyword
Treehello-authentication-type

Description

This command enables Hello authentication at the level context. Both the Hello authentication key and the Hello authentication type on a segment must match. The Hello authentication-key statement must also be included.

Optionspassword, message-digest
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hello-interval number
Synopsis Interval between Hello messages sent on this level
Contextconfigure service vprn service-name isis number interface interface-name level keyword hello-interval number
Treehello-interval
Range1 to 20000
Unitsseconds
Default 9
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hello-multiplier number
Synopsis Hello messages missed from neighbor before router declares adjacency down
Contextconfigure service vprn service-name isis number interface interface-name level keyword hello-multiplier number
Treehello-multiplier
Range2 to 100
Default3
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

hello-padding keyword
Synopsis Padding on IS-IS Hello packets
Context configure service vprn service-name isis number interface interface-name level keyword hello-padding keyword
Treehello-padding
Optionsadaptive, loose, strict, none
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

metric number
Synopsis IS-IS interface metric applied for IPv4 unicast
Contextconfigure service vprn service-name isis number interface interface-name level keyword metric number
Treemetric
Range1 to 16777215
Introduced25.3.R2

Platforms

7705 SAR Gen 2

passive boolean
Synopsis Passive interface
Context configure service vprn service-name isis number interface interface-name level keyword passive boolean
Treepassive
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

priority number
Synopsis Router to become the designated router on a multi-access network
Contextconfigure service vprn service-name isis number interface interface-name level keyword priority number
Treepriority
Range0 to 127
Default64
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

sd-offset number
Synopsis Value of the signal degrade offset
Context configure service vprn service-name isis number interface interface-name level keyword sd-offset number
Treesd-offset
Range1 to 16777215
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sf-offset number
Synopsis Value of the signal fail offset
Context configure service vprn service-name isis number interface interface-name level keyword sf-offset number
Treesf-offset
Range1 to 16777215
Introduced25.3.R2

Platforms

7705 SAR Gen 2

loopfree-alternate
Synopsis Enter the loopfree-alternate context
Contextconfigure service vprn service-name isis number interface interface-name loopfree-alternate
Treeloopfree-alternate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy-map
Synopsis Enable the policy-map context
Context configure service vprn service-name isis number interface interface-name loopfree-alternate policy-map
Treepolicy-map
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mesh-group
Synopsis Enable the mesh-group context
Context configure service vprn service-name isis number interface interface-name mesh-group
Treemesh-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

blocked
Synopsis Prevent the interface from flooding LSPs
Contextconfigure service vprn service-name isis number interface interface-name mesh-group blocked
Treeblocked

Notes

The following elements are part of a choice: blocked or value.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

value number
Synopsis Mesh group for the interface
Context configure service vprn service-name isis number interface interface-name mesh-group value number
Treevalue
Range1 to 2000000000

Notes

The following elements are part of a choice: blocked or value.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

passive boolean
Synopsis Passive interface
Context configure service vprn service-name isis number interface interface-name passive boolean
Treepassive
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

retransmit-interval number
Synopsis Minimum time between LSP PDU retransmissions on point-to-point interface
Contextconfigure service vprn service-name isis number interface interface-name retransmit-interval number
Treeretransmit-interval
Range1 to 65535
Unitsseconds
Default 5
Introduced25.3.R2

Platforms

7705 SAR Gen 2

tag number
Synopsis Route tag for IP address of interface
Contextconfigure service vprn service-name isis number interface interface-name tag number
Treetag
Range1 to 4294967295
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4-routing boolean
Synopsis Support IPv4 routing for IS-IS instance
Contextconfigure service vprn service-name isis number ipv4-routing boolean
Treeipv4-routing
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6-routing keyword
Synopsis Routing topology for IPv6
Context configure service vprn service-name isis number ipv6-routing keyword
Treeipv6-routing
Optionsfalse, native, mt
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

level [level-number] keyword
Synopsis Enter the level list instance
Context configure service vprn service-name isis number level keyword
Treelevel
Max. instances2
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[level-number] keyword
Synopsis ISIS protocol level number
Context configure service vprn service-name isis number level keyword
Treelevel
Options1, 2

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

authentication-key encrypted-leaf
Synopsis Authentication key to verify PDUs sent on the interface
Contextconfigure service vprn service-name isis number level keyword authentication-key encrypted-leaf
Treeauthentication-key

Description

This command sets the authentication key used to verify PDUs sent by neighboring routers on the interface.

Neighboring routers use passwords to authenticate PDUs sent from an interface. For authentication to work, both the authentication key and the authentication type on a segment must match. The authentication-type command must also be included.

String length1 to 366
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hello-padding keyword
Synopsis Padding on IS-IS Hello packets
Context configure service vprn service-name isis number level keyword hello-padding keyword
Treehello-padding
Optionsadaptive, loose, strict, none
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

lsp-mtu-size number
Synopsis LSP MTU size
Contextconfigure service vprn service-name isis number level keyword lsp-mtu-size number
Treelsp-mtu-size
Range490 to 9778
Unitsbytes
Default 1492
Introduced25.3.R2

Platforms

7705 SAR Gen 2

preference number
Synopsis External route preference at level
Context configure service vprn service-name isis number level keyword preference number
Treepreference
Range1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

link-group [link-group-name] named-item
Synopsis Enter the link-group list instance
Contextconfigure service vprn service-name isis number link-group named-item
Treelink-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[link-group-name] named-item
Synopsis Link group name for the IS-IS protocol
Contextconfigure service vprn service-name isis number link-group named-item
Treelink-group
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

description very-long-description
Synopsis Text description
Context configure service vprn service-name isis number link-group named-item description very-long-description
Treedescription
String length1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

level [level-number] keyword
Synopsis Enter the level list instance
Context configure service vprn service-name isis number link-group named-item level keyword
Treelevel
Max. instances2
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[level-number] keyword
Synopsis ISIS protocol level number
Context configure service vprn service-name isis number link-group named-item level keyword
Treelevel
Options1, 2

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

member [interface-name] reference
Synopsis Add a list entry for member
Context configure service vprn service-name isis number link-group named-item level keyword member reference
Treemember
Max. instances8
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[interface-name] reference
Synopsis Interface name for the associated link group
Contextconfigure service vprn service-name isis number link-group named-item level keyword member reference
Treemember

Reference

configure service vprn service-name isis number interface interface-name

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

revert-members number
Synopsis Minimum number of operational links to return link group to normal state and remove offsets
Contextconfigure service vprn service-name isis number link-group named-item level keyword revert-members number
Treerevert-members
Range1 to 8
Introduced25.3.R2

Platforms

7705 SAR Gen 2

loopfree-alternate
Synopsis Enable the loopfree-alternate context
Contextconfigure service vprn service-name isis number loopfree-alternate
Treeloopfree-alternate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

exclude
Synopsis Enter the exclude context
Context configure service vprn service-name isis number loopfree-alternate exclude
Treeexclude
Introduced25.3.R2

Platforms

7705 SAR Gen 2

prefix-policy reference
Synopsis Policy to exclude prefixes from LFA SPF calculation
Contextconfigure service vprn service-name isis number loopfree-alternate exclude prefix-policy reference
Treeprefix-policy

Description

This command specifies the name of the policy for the prefixes to exclude from the LFA SPF calculation.

An excluded prefix is not included in LFA calculation regardless of its priority. The prefix tag is, however, used in the main SPF.

Reference

configure policy-options policy-statement named-item-64

Max. instances5

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lsp-lifetime number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAmount of time during which an LSP is considered valid
Contextconfigure service vprn service-name isis number lsp-lifetime number
Treelsp-lifetime
Range350 to 65535
Unitsseconds
Default 1200
Introduced25.3.R2

Platforms

7705 SAR Gen 2

lsp-mtu-size number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLSP MTU size
Contextconfigure service vprn service-name isis number lsp-mtu-size number
Treelsp-mtu-size
Range490 to 9778
Unitsbytes
Default 1492
Introduced25.3.R2

Platforms

7705 SAR Gen 2

lsp-refresh
Synopsis Enter the lsp-refresh context
Context configure service vprn service-name isis number lsp-refresh
Treelsp-refresh
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interval number
Synopsis Refresh timer interval
Context configure service vprn service-name isis number lsp-refresh interval number
Treeinterval
Range150 to 65535
Unitsseconds
Default 600
Introduced25.3.R2

Platforms

7705 SAR Gen 2

multi-topology
Synopsis Enable the multi-topology context
Contextconfigure service vprn service-name isis number multi-topology
Treemulti-topology
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overload
Synopsis Enable the overload context
Context configure service vprn service-name isis number overload
Treeoverload
Introduced25.3.R2

Platforms

7705 SAR Gen 2

max-metric boolean
Synopsis Advertise transit links with maximum metric instead of setting overload bit
Contextconfigure service vprn service-name isis number overload max-metric boolean
Treemax-metric
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overload-fib-error-notify-only
Synopsis Enable the overload-fib-error-notify-only context
Contextconfigure service vprn service-name isis number overload-fib-error-notify-only
Treeoverload-fib-error-notify-only

Description

Commands in this context configure the IS-IS router to send a notification when an overload condition occurs while programming the FIB, instead of advertising the overload condition of the router in the IS-IS LSP.

Note: Nokia recommends being careful using this command. When you configure the router not to advertise the IS-IS overload state in the IS-IS LSP, other routers are not instructed to take the overloaded router out of the IS-IS forwarding topology and this will cause suboptimal forwarding and non-deterministic behavior on the overloaded router. To avoid changing the default IS-IS overflow behavior, leave this command disabled.

When this command is configured, the IS-IS router enters a suboptimal state where it sends only a notification trap; transit traffic can still use the router in this state.

The IS-IS router tracks the segment routing prefix SIDs where FIB programming failed. With the retry command configured, the router retries programming the segment routing prefix SIDs in the FIB using this tracked information.

When this command is not configured, during normal operation, the system may force the router to enter an overload state because of a lack of FIB resources. In this state, the router is used to terminate traffic and is not used to transit traffic.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

retry number
Synopsis Time to retry programming failed entries in the FIB
Contextconfigure service vprn service-name isis number overload-fib-error-notify-only retry number
Treeretry

Description

This command configures the time the router uses to retry programming the failed entries in the FIB.

The overload-fib-error-notify-only command must be configured to use the retry timer. The removal of the overload-fib-error-notify-only configuration causes the system to program the failed entries in the FIB by triggering an immediate SPF.

Range10 to 1800
Unitsseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overload-on-boot
Synopsis Enable the overload-on-boot context
Contextconfigure service vprn service-name isis number overload-on-boot
Treeoverload-on-boot
Introduced25.3.R2

Platforms

7705 SAR Gen 2

max-metric boolean
Synopsis Advertise transit links with maximum metric instead of setting overload bit
Contextconfigure service vprn service-name isis number overload-on-boot max-metric boolean
Treemax-metric
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

timeout number
Synopsis Time during which the router operates in overload state after reboot
Contextconfigure service vprn service-name isis number overload-on-boot timeout number
Treetimeout
Range60 to 1800
Unitsseconds
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

poi-tlv boolean
Synopsis Purge Originator Identification TLV
Context configure service vprn service-name isis number poi-tlv boolean
Treepoi-tlv
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

prefix-attributes-tlv boolean
Synopsis Use IS-IS Prefix Attributes TLV to exchange extended IPv4 and IPv6 reachability information
Contextconfigure service vprn service-name isis number prefix-attributes-tlv boolean
Treeprefix-attributes-tlv
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

prefix-limit
Synopsis Enable the prefix-limit context
Contextconfigure service vprn service-name isis number prefix-limit
Treeprefix-limit
Introduced25.3.R2

Platforms

7705 SAR Gen 2

limit number
Synopsis Maximum number of prefixes for IS-IS instance
Contextconfigure service vprn service-name isis number prefix-limit limit number
Treelimit
Range1 to 4294967295

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

log-only boolean
Synopsis Send warning message when the prefix limit is reached
Contextconfigure service vprn service-name isis number prefix-limit log-only boolean
Treelog-only
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overload-timeout (number | keyword)
Synopsis Time in overload state when prefix limit is reached
Contextconfigure service vprn service-name isis number prefix-limit overload-timeout (number | keyword)
Treeoverload-timeout
Range1 to 1800
Unitsseconds
Options forever
Defaultforever
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

psnp-authentication boolean
Synopsis Authenticate individual IS-IS protocol packets of partial sequence number PDU (PSNP) type
Contextconfigure service vprn service-name isis number psnp-authentication boolean
Treepsnp-authentication
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

reference-bandwidth number
Synopsis Reference bandwidth for bandwidth relative costing
Contextconfigure service vprn service-name isis number reference-bandwidth number
Treereference-bandwidth
Range1 to 18446744073709551615
Unitskilobps
Introduced25.3.R2

Platforms

7705 SAR Gen 2

rib-priority
Synopsis Enter the rib-priority context
Contextconfigure service vprn service-name isis number rib-priority
Treerib-priority
Introduced25.3.R2

Platforms

7705 SAR Gen 2

high
Synopsis Enter the high context
Context configure service vprn service-name isis number rib-priority high
Treehigh
Introduced25.3.R2

Platforms

7705 SAR Gen 2

prefix-list reference
Synopsis List used to select routes processed at higher priority through OSPF route calculation process
Contextconfigure service vprn service-name isis number rib-priority high prefix-list reference
Treeprefix-list

Reference

configure policy-options prefix-list named-item-64

Notes

The following elements are part of a choice: prefix-list or tag.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

tag number
Synopsis Tag value that is used to match IS-IS routes
Contextconfigure service vprn service-name isis number rib-priority high tag number
Treetag
Range1 to 4294967295

Notes

The following elements are part of a choice: prefix-list or tag.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

router-id router-id
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisUnique router ID for the ISIS instance
Contextconfigure service vprn service-name isis number router-id router-id
Treerouter-id
Introduced25.3.R2

Platforms

7705 SAR Gen 2

summary-address [ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis Enter the summary-address list instance
Contextconfigure service vprn service-name isis number summary-address (ipv4-prefix | ipv6-prefix)
Treesummary-address
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis IP prefix for the summary address
Context configure service vprn service-name isis number summary-address (ipv4-prefix | ipv6-prefix)
Treesummary-address

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-tag number
Synopsis Route tag assigned to the summary address
Contextconfigure service vprn service-name isis number summary-address (ipv4-prefix | ipv6-prefix) route-tag number
Treeroute-tag
Range1 to 4294967295
Introduced25.3.R2

Platforms

7705 SAR Gen 2

system-id system-id
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSystem ID
Contextconfigure service vprn service-name isis number system-id system-id
Treesystem-id
String length14
Default0000.0000.0000
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

timers
Synopsis Enter the timers context
Context configure service vprn service-name isis number timers
Treetimers
Introduced25.3.R2

Platforms

7705 SAR Gen 2

lsp-wait
Synopsis Enter the lsp-wait context
Context configure service vprn service-name isis number timers lsp-wait
Treelsp-wait
Introduced25.3.R2

Platforms

7705 SAR Gen 2

lsp-max-wait number
Synopsis Maximum time between two consecutive LSP occurrences
Contextconfigure service vprn service-name isis number timers lsp-wait lsp-max-wait number
Treelsp-max-wait
Range10 to 120000
Unitsmilliseconds
Default5000
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

spf-wait
Synopsis Enter the spf-wait context
Context configure service vprn service-name isis number timers spf-wait
Treespf-wait
Introduced25.3.R2

Platforms

7705 SAR Gen 2

spf-max-wait number
Synopsis Maximum interval amid two consecutive SPF calculations
Contextconfigure service vprn service-name isis number timers spf-wait spf-max-wait number
Treespf-max-wait
Range10 to 120000
Unitsmilliseconds
Default10000
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

unicast-import
Synopsis Enter the unicast-import context
Contextconfigure service vprn service-name isis number unicast-import
Treeunicast-import
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4 boolean
Synopsis Submit IPv4 routes into unicast RTM
Context configure service vprn service-name isis number unicast-import ipv4 boolean
Treeipv4
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6 boolean
Synopsis Submit IPv6 routes into unicast RTM
Context configure service vprn service-name isis number unicast-import ipv6 boolean
Treeipv6
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

label-mode keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAllocation mode for VPRN service labels
Contextconfigure service vprn service-name label-mode keyword
Treelabel-mode
Optionsvrf, next-hop
Default vrf
Introduced25.3.R2

Platforms

7705 SAR Gen 2

local-routes-domain-id domain-id
Synopsis Local routes domain ID
Context configure service vprn service-name local-routes-domain-id domain-id
Treelocal-routes-domain-id

Description

This command specifies the domain ID that is used in the D-PATH attribute for local routes before those routes are exported to a BGP neighbor using BGP-IPVPN, EVPN-IFF, EVPN-IFL, or PE-CE BGP. A local route is a non-BGP route installed in the VPRN route table and learned using static route or an IGP.

The domain IDs are used in the D-PATH attribute, in accordance with draft-ietf-bess-evpn-ipvpn-interworking. Gateway routers modify the D-PATH attribute. A gateway is a PE where a VPRN is instantiated. The VPRN in this case advertises or receives routes from multiple BGP owners (for example, EVPN IFL and BGP IPVPN).

Gateways use the D-PATH attribute to detect loops (for received routes where the D-PATH contains a local domain ID) and to make BGP best-path selection decisions based on the D-PATH length (shorter D-PATH is preferred).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

log
Synopsis Enter the log context
Context configure service vprn service-name log
Treelog
Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter [filter-name] log-filter-name
Synopsis Enter the filter list instance
Contextconfigure service vprn service-name log filter log-filter-name
Treefilter
Max. instances1500
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[filter-name] log-filter-name
Synopsis Filter ID
Contextconfigure service vprn service-name log filter log-filter-name
Treefilter
String length1 to 64

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

default-action keyword
Synopsis Default action for the event filter
Context configure service vprn service-name log filter log-filter-name default-action keyword
Treedefault-action
Optionsdrop, forward
Default forward
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service vprn service-name log filter log-filter-name description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

named-entry [entry-name] log-filter-entry-name
Synopsis Enter the named-entry list instance
Contextconfigure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name
Treenamed-entry

Description

Commands in this context create or edit an event filter entry.

Max. instances999

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[entry-name] log-filter-entry-name
Synopsis Entry name
Contextconfigure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name
Treenamed-entry
String length1 to 64

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

action keyword
Synopsis Action for this event filter entry
Context configure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name action keyword
Treeaction
Optionsdrop, forward
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

match
Synopsis Enter the match context
Context configure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match
Treematch
Introduced25.3.R2

Platforms

7705 SAR Gen 2

application
Synopsis Enter the application context
Context configure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match application
Treeapplication
Introduced25.3.R2

Platforms

7705 SAR Gen 2

eq keyword
Synopsis Application to match
Context configure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match application eq keyword
Treeeq
Optionsapplication-assurance, aps, bgp, cflowd, chassis, debug, dhcp, dhcps, diameter, dot1x, efm-oam, elmi, ering, eth-cfm, etun, filter, gsmp, igmp, igmp-snooping, ip, ipsec, isis, l2tp, lag, ldp, li, lldp, logger, mcpath, mc-redundancy, mirror, mld, mld-snooping, mpls, msdp, nat, ntp, oam, ospf, pim, pim-snooping, port, pppoe, ptp, rip, route-policy, rsvp, security, snmp, stp, svcmgr, system, user, video, vrrp, vrtr, radius, wpp, wlan-gw, dynsvc, mpls-tp, bfd, python, ripng, openflow, sflow, rpki, pcep, calltrace, satellite, ldap, pppoe-clnt, tls, adp, mgmt-core, macsec, sr-policy, pcap, auto-prov, bier, pfcp, tree-sid, srv6, sr-mpls, anysec

Notes

The following elements are part of a choice: eq or neq.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

neq keyword
Synopsis Application to be filtered out
Context configure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match application neq keyword
Treeneq
Optionsapplication-assurance, aps, bgp, cflowd, chassis, debug, dhcp, dhcps, diameter, dot1x, efm-oam, elmi, ering, eth-cfm, etun, filter, gsmp, igmp, igmp-snooping, ip, ipsec, isis, l2tp, lag, ldp, li, lldp, logger, mcpath, mc-redundancy, mirror, mld, mld-snooping, mpls, msdp, nat, ntp, oam, ospf, pim, pim-snooping, port, pppoe, ptp, rip, route-policy, rsvp, security, snmp, stp, svcmgr, system, user, video, vrrp, vrtr, radius, wpp, wlan-gw, dynsvc, mpls-tp, bfd, python, ripng, openflow, sflow, rpki, pcep, calltrace, satellite, ldap, pppoe-clnt, tls, adp, mgmt-core, macsec, sr-policy, pcap, auto-prov, bier, pfcp, tree-sid, srv6, sr-mpls, anysec

Notes

The following elements are part of a choice: eq or neq.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

event
Synopsis Enter the event context
Context configure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match event
Treeevent
Introduced25.3.R2

Platforms

7705 SAR Gen 2

eq number
Synopsis Log event message to match
Context configure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match event eq number
Treeeq
Range1 to 4294967295

Notes

The following elements are part of a choice: eq, gt, gte, lt, lte, or neq.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gt number
Synopsis Number of the log event to match
Context configure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match event gt number
Treegt
Range1 to 4294967295

Notes

The following elements are part of a choice: eq, gt, gte, lt, lte, or neq.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gte number
Synopsis Number of the log event to match
Context configure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match event gte number
Treegte
Range1 to 4294967295

Notes

The following elements are part of a choice: eq, gt, gte, lt, lte, or neq.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lt number
Synopsis Number of the log event to match
Context configure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match event lt number
Treelt
Range1 to 4294967295

Notes

The following elements are part of a choice: eq, gt, gte, lt, lte, or neq.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lte number
Synopsis Number of the log event to match
Context configure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match event lte number
Treelte
Range1 to 4294967295

Notes

The following elements are part of a choice: eq, gt, gte, lt, lte, or neq.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

neq number
Synopsis Log event message to filter out
Context configure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match event neq number
Treeneq
Range1 to 4294967295

Notes

The following elements are part of a choice: eq, gt, gte, lt, lte, or neq.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

message
Synopsis Enter the message context
Context configure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match message
Treemessage
Introduced25.3.R2

Platforms

7705 SAR Gen 2

eq string
Synopsis Log event message to match
Context configure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match message eq string
Treeeq
String length1 to 400

Notes

The following elements are part of a choice: eq or neq.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

neq string
Synopsis Log event message to be filtered out
Context configure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match message neq string
Treeneq
String length1 to 400

Notes

The following elements are part of a choice: eq or neq.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

regexp boolean
Synopsis String comparison to determine if the log event matches the value of pattern
Contextconfigure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match message regexp boolean
Treeregexp
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

severity
Synopsis Enter the severity context
Context configure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match severity
Treeseverity
Introduced25.3.R2

Platforms

7705 SAR Gen 2

eq keyword
Synopsis Log event severity level to match
Context configure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match severity eq keyword
Treeeq
Optionscleared, indeterminate, critical, major, minor, warning

Notes

The following elements are part of a choice: eq, gt, gte, lt, lte, or neq.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gt keyword
Synopsis Log event severity level
Context configure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match severity gt keyword
Treegt
Optionscleared, indeterminate, critical, major, minor, warning

Notes

The following elements are part of a choice: eq, gt, gte, lt, lte, or neq.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

gte keyword
Synopsis Log event severity level
Context configure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match severity gte keyword
Treegte
Optionscleared, indeterminate, critical, major, minor, warning

Notes

The following elements are part of a choice: eq, gt, gte, lt, lte, or neq.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lt keyword
Synopsis Log event severity level
Context configure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match severity lt keyword
Treelt
Optionscleared, indeterminate, critical, major, minor, warning

Notes

The following elements are part of a choice: eq, gt, gte, lt, lte, or neq.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

lte keyword
Synopsis Log event severity level
Context configure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match severity lte keyword
Treelte
Optionscleared, indeterminate, critical, major, minor, warning

Notes

The following elements are part of a choice: eq, gt, gte, lt, lte, or neq.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

neq keyword
Synopsis Log event severity level to filter out
Contextconfigure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match severity neq keyword
Treeneq
Optionscleared, indeterminate, critical, major, minor, warning

Notes

The following elements are part of a choice: eq, gt, gte, lt, lte, or neq.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

subject
Synopsis Enter the subject context
Context configure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match subject
Treesubject
Introduced25.3.R2

Platforms

7705 SAR Gen 2

eq named-item
Synopsis Log event subject string to match
Context configure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match subject eq named-item
Treeeq
String length1 to 32

Notes

The following elements are part of a choice: eq or neq.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

neq named-item
Synopsis Log event subject string to filter out
Contextconfigure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match subject neq named-item
Treeneq
String length1 to 32

Notes

The following elements are part of a choice: eq or neq.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

regexp boolean
Synopsis String comparison to determine if the log event matches the value of subject
Contextconfigure service vprn service-name log filter log-filter-name named-entry log-filter-entry-name match subject regexp boolean
Treeregexp
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

log-id [name] li-log-name
Synopsis Enter the log-id list instance
Contextconfigure service vprn service-name log log-id li-log-name
Treelog-id
Max. instances30
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[name] li-log-name
Synopsis Log ID
Contextconfigure service vprn service-name log log-id li-log-name
Treelog-id
String length1 to 64

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the log
Context configure service vprn service-name log log-id li-log-name admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service vprn service-name log log-id li-log-name description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

destination
Synopsis Enter the destination context
Context configure service vprn service-name log log-id li-log-name destination
Treedestination
Introduced25.3.R2

Platforms

7705 SAR Gen 2

netconf
Synopsis Enable the netconf context
Context configure service vprn service-name log log-id li-log-name destination netconf
Treenetconf

Notes

The following elements are part of a choice: netconf, snmp, or syslog.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

max-entries number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNumber of events stored in the NETCONF log
Contextconfigure service vprn service-name log log-id li-log-name destination netconf max-entries number
Treemax-entries
Range50 to 3000
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

snmp
Synopsis Enable the snmp context
Context configure service vprn service-name log log-id li-log-name destination snmp
Treesnmp

Notes

The following elements are part of a choice: netconf, snmp, or syslog.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

max-entries number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNumber of events stored in the memory log
Contextconfigure service vprn service-name log log-id li-log-name destination snmp max-entries number
Treemax-entries
Range50 to 3000
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

syslog reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIndex with the information to format event messages sent to a specific SYSLOG collector
Contextconfigure service vprn service-name log log-id li-log-name destination syslog reference
Treesyslog

Reference

configure service vprn service-name log syslog log-vprn-syslog-name

Notes

The following elements are part of a choice: netconf, snmp, or syslog.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter reference
Synopsis Event filter policy with the log destination
Contextconfigure service vprn service-name log log-id li-log-name filter reference
Treefilter

Reference

configure service vprn service-name log filter log-filter-name

Introduced25.3.R2

Platforms

7705 SAR Gen 2

netconf-stream named-item
Synopsis Destination NETCONF stream name
Context configure service vprn service-name log log-id li-log-name netconf-stream named-item
Treenetconf-stream
String length1 to 32
Introduced25.3.R2

Platforms

7705 SAR Gen 2

source
Synopsis Enter the source context
Context configure service vprn service-name log log-id li-log-name source
Treesource
Introduced25.3.R2

Platforms

7705 SAR Gen 2

change boolean
Synopsis Collect log events from the change event stream
Contextconfigure service vprn service-name log log-id li-log-name source change boolean
Treechange
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

debug boolean
Synopsis Collect log events from the debug event stream
Contextconfigure service vprn service-name log log-id li-log-name source debug boolean
Treedebug
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

main boolean
Synopsis Collect log events from the main event stream
Contextconfigure service vprn service-name log log-id li-log-name source main boolean
Treemain
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

security boolean
Synopsis Collect log events from the security event stream
Contextconfigure service vprn service-name log log-id li-log-name source security boolean
Treesecurity
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

time-format keyword
Synopsis Time zone output for file log contents and syslog
Contextconfigure service vprn service-name log log-id li-log-name time-format keyword
Treetime-format
Optionsutc, local
Default utc
Introduced25.3.R2

Platforms

7705 SAR Gen 2

snmp-trap-group [log-name] svc-vprn-snmp-trap-group-name
Synopsis Enter the snmp-trap-group list instance
Contextconfigure service vprn service-name log snmp-trap-group svc-vprn-snmp-trap-group-name
Treesnmp-trap-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[log-name] svc-vprn-snmp-trap-group-name
Synopsis Log ID
Contextconfigure service vprn service-name log snmp-trap-group svc-vprn-snmp-trap-group-name
Treesnmp-trap-group
String length1 to 17

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

trap-target [name] string
Synopsis Enter the trap-target list instance
Contextconfigure service vprn service-name log snmp-trap-group svc-vprn-snmp-trap-group-name trap-target string
Treetrap-target
Max. instances25
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[name] string
Synopsis Trap target name
Context configure service vprn service-name log snmp-trap-group svc-vprn-snmp-trap-group-name trap-target string
Treetrap-target
String length1 to 28

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the trap receiver
Context configure service vprn service-name log snmp-trap-group svc-vprn-snmp-trap-group-name trap-target string address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeaddress

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

notify-community string
Synopsis SNMPv1 or SNMPv2c community name string, or SNMPv3 security name, for sending a notification
Contextconfigure service vprn service-name log snmp-trap-group svc-vprn-snmp-trap-group-name trap-target string notify-community string
Treenotify-community
String length1 to 31

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

port number
Synopsis UDP port number to send messages to this remote SNMP notification collector
Contextconfigure service vprn service-name log snmp-trap-group svc-vprn-snmp-trap-group-name trap-target string port number
Treeport
Range0 | 1 to 65535
Default162
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

security-level keyword
Synopsis Security level at which SNMP notification messages are sent to SNMP notification collector
Contextconfigure service vprn service-name log snmp-trap-group svc-vprn-snmp-trap-group-name trap-target string security-level keyword
Treesecurity-level
Optionsno-auth-no-privacy, auth-no-privacy, privacy
Defaultno-auth-no-privacy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

version keyword
Synopsis SNMP version to format notification messages sent to this SNMP notification collector
Contextconfigure service vprn service-name log snmp-trap-group svc-vprn-snmp-trap-group-name trap-target string version keyword
Treeversion
Optionssnmpv1, snmpv2c, snmpv3
Defaultsnmpv3
Introduced25.3.R2

Platforms

7705 SAR Gen 2

syslog [syslog-name] log-vprn-syslog-name
Synopsis Enter the syslog list instance
Contextconfigure service vprn service-name log syslog log-vprn-syslog-name
Treesyslog
Max. instances30
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[syslog-name] log-vprn-syslog-name
Synopsis Syslog name
Contextconfigure service vprn service-name log syslog log-vprn-syslog-name
Treesyslog
String length1 to 64

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the Syslog target host
Context configure service vprn service-name log syslog log-vprn-syslog-name address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeaddress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service vprn service-name log syslog log-vprn-syslog-name description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

facility keyword
Synopsis Facility code for messages
Context configure service vprn service-name log syslog log-vprn-syslog-name facility keyword
Treefacility
Optionskernel, user, mail, systemd, auth, syslogd, printer, netnews, uucp, cron, authpriv, ftp, ntp, logaudit, logalert, cron2, local0, local1, local2, local3, local4, local5, local6, local7
Default local7
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hostname
Synopsis Enter the hostname context
Context configure service vprn service-name log syslog log-vprn-syslog-name hostname
Treehostname

Description

Commands in this context control how the HOSTNAME field of syslog messages is populated.

If no command option is configured, the HOSTNAME is populated with an IP address.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

use-system-name
Synopsis Enable the use-system-name context
Contextconfigure service vprn service-name log syslog log-vprn-syslog-name hostname use-system-name
Treeuse-system-name

Description

Commands in this context configure the system to use the system name configured with the configure system name command as the HOSTNAME field of syslog messages.

Do not use any spaces in the system name if it is used for the syslog HOSTNAME.

Notes

The following elements are part of a choice: use-system-name, use-vprn-name, or value.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

use-vprn-name
Synopsis Enable the use-vprn-name context
Contextconfigure service vprn service-name log syslog log-vprn-syslog-name hostname use-vprn-name
Treeuse-vprn-name

Description

Commands in this context configure the system to use the VPRN service name configured with the configure service vprn service-name command as the HOSTNAME field of syslog messages sent in this VPRN.

Do not use any spaces in the VPRN name if it is used for the syslog HOSTNAME.

Notes

The following elements are part of a choice: use-system-name, use-vprn-name, or value.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

value named-item-255
Synopsis Syslog HOSTNAME field value
Context configure service vprn service-name log syslog log-vprn-syslog-name hostname value named-item-255
Treevalue

Description

This command configures a string as the HOSTNAME field of syslog messages.

Do not use any spaces in the string used for the syslog HOSTNAME.

String length1 to 255

Notes

The following elements are part of a choice: use-system-name, use-vprn-name, or value.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

log-prefix (keyword | string)
Synopsis Prefix string to log message sent to target syslog host
Contextconfigure service vprn service-name log syslog log-vprn-syslog-name log-prefix (keyword | string)
Treelog-prefix
String length1 to 32
Optionsno-prefix
DefaultTMNX
Introduced25.3.R2

Platforms

7705 SAR Gen 2

port number
Synopsis Destination port when sending syslog over UDP
Contextconfigure service vprn service-name log syslog log-vprn-syslog-name port number
Treeport
Range0 | 1 to 65535
Default514
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

severity keyword
Synopsis Severity level threshold for the syslog message
Contextconfigure service vprn service-name log syslog log-vprn-syslog-name severity keyword
Treeseverity
Optionsemergency, alert, critical, error, warning, notice, info, debug
Default info
Introduced25.3.R2

Platforms

7705 SAR Gen 2

timestamp-format keyword
Synopsis Syslog timestamp format
Context configure service vprn service-name log syslog log-vprn-syslog-name timestamp-format keyword
Treetimestamp-format
Options

millisecond – Set timestamp format to milliseconds

Introduced25.3.R2

Platforms

7705 SAR Gen 2

tls-client-profile reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTLS client profile used to encrypt syslog communication
Contextconfigure service vprn service-name log syslog log-vprn-syslog-name tls-client-profile reference
Treetls-client-profile

Description

This command specifies the Transport Layer Security (TLS) client profile used to encrypt syslog communications. When configured, syslog messages are sent using TLS.  

Any change to this command results in a brief interruption of the event log, which may cause the loss of a few syslog messages.

When this command is unconfigured, the syslog messages are sent over UDP.

Reference

configure system security tls client-tls-profile named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

management
Synopsis Enable the management context
Context configure service vprn service-name management
Treemanagement

Description

Commands in this context control which management protocols can be used to access the SR OS router via the VPRN router instance.

For SNMP control, see the configure service vprn snmp access command.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

allow-ftp boolean
Synopsis Allow access to the FTP server
Context configure service vprn service-name management allow-ftp boolean
Treeallow-ftp

Description

When configured to true, this command allows FTP access to the SR OS router via the VPRN router instance.

When configured to false, this command disallows access to the SR OS FTP server.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

allow-grpc boolean
Synopsis Allow access to the gRPC server
Context configure service vprn service-name management allow-grpc boolean
Treeallow-grpc

Description

When configured to true, this command allows access to the gRPC server via the VPRN router instance.

When configured to false, this command disallows gRPC server access.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

allow-netconf boolean
Synopsis Allow access to the NETCONF server
Context configure service vprn service-name management allow-netconf boolean
Treeallow-netconf

Description

When configured to true, this command allows NETCONF server access to the SR OS router via the VPRN router instance.

When configured to false, this command disallows access to the NETCONF server.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

allow-ssh boolean
Synopsis Allow access to the SSH server
Context configure service vprn service-name management allow-ssh boolean
Treeallow-ssh

Description

When configured to true, this command allows SSH server access to the SR OS router via the VPRN router instance.

When configured to false, this command disallows SSH server access.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

allow-telnet boolean
Synopsis Allow access to the IPv4 Telnet server
Contextconfigure service vprn service-name management allow-telnet boolean
Treeallow-telnet

Description

When configured to true, this command allows IPv4 Telnet server access to the SR OS router via the VPRN router instance.

When configured to false, this command disallows access to the IPv4 Telnet server.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

allow-telnet6 boolean
Synopsis Allow access to the Telnet IPv6 server
Contextconfigure service vprn service-name management allow-telnet6 boolean
Treeallow-telnet6

Description

When configured to true, this command allows IPv6 Telnet server access to the SR OS router via the VPRN router instance.

When configured to false, this command removes access to the IPv6 Telnet server.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

maximum-ipv4-routes
Synopsis Enter the maximum-ipv4-routes context
Contextconfigure service vprn service-name maximum-ipv4-routes
Treemaximum-ipv4-routes
Introduced25.3.R2

Platforms

7705 SAR Gen 2

log-only boolean
Synopsis Action when the maximum number of routes, held within a VRF context, is reached
Contextconfigure service vprn service-name maximum-ipv4-routes log-only boolean
Treelog-only
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

threshold number
Synopsis Mid-level water marker for the number of routes which this VRF holds
Contextconfigure service vprn service-name maximum-ipv4-routes threshold number
Treethreshold
Range1 to 100
Unitspercent
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

value number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of routes that are configured on this virtual router
Contextconfigure service vprn service-name maximum-ipv4-routes value number
Treevalue
Range1 to 2147483647
Introduced25.3.R2

Platforms

7705 SAR Gen 2

maximum-ipv6-routes
Synopsis Enter the maximum-ipv6-routes context
Contextconfigure service vprn service-name maximum-ipv6-routes
Treemaximum-ipv6-routes
Introduced25.3.R2

Platforms

7705 SAR Gen 2

log-only boolean
Synopsis Action when the maximum number of routes, held within a VRF context, is reached
Contextconfigure service vprn service-name maximum-ipv6-routes log-only boolean
Treelog-only
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

threshold number
Synopsis Mid-level water marker for the number of routes which this VRF holds
Contextconfigure service vprn service-name maximum-ipv6-routes threshold number
Treethreshold
Range1 to 100
Unitspercent
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

value number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of routes that are configured on this virtual router
Contextconfigure service vprn service-name maximum-ipv6-routes value number
Treevalue
Range1 to 2147483647
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mc-maximum-routes
Synopsis Enter the mc-maximum-routes context
Contextconfigure service vprn service-name mc-maximum-routes
Treemc-maximum-routes
Introduced25.3.R2

Platforms

7705 SAR Gen 2

threshold number
Synopsis Maximum multicast routes which the VRF holds
Contextconfigure service vprn service-name mc-maximum-routes threshold number
Treethreshold
Range1 to 100
Unitspercent
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

value number
Synopsis Maximum multicast routes configured on virtual router
Contextconfigure service vprn service-name mc-maximum-routes value number
Treevalue
Range1 to 2147483647
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mld
Synopsis Enable the mld context
Context configure service vprn service-name mld
Treemld
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of MLD
Context configure service vprn service-name mld admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface [ip-interface-name] interface-name
Synopsis Enter the interface list instance
Contextconfigure service vprn service-name mld interface interface-name
Treeinterface
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ip-interface-name] interface-name
Synopsis IP interface name
Context configure service vprn service-name mld interface interface-name
Treeinterface
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the MLD interface
Contextconfigure service vprn service-name mld interface interface-name admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

maximum-number-group-sources number
Synopsis Maximum number of group sources for this interface
Contextconfigure service vprn service-name mld interface interface-name maximum-number-group-sources number
Treemaximum-number-group-sources

Description

This command configures the maximum number of group sources for which IGMP or MLD can have local receiver information based on received IGMP or MLD reports on this interface. When this configuration is changed dynamically to a lower value than the currently accepted number of group sources, the group sources that are already accepted are not deleted. Only new group sources are not allowed.

Range1 to 32000
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ssm-translate
Synopsis Enter the ssm-translate context
Contextconfigure service vprn service-name mld interface interface-name ssm-translate
Treessm-translate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

group-range start ipv6-multicast-address end ipv6-multicast-address
Synopsis Enter the group-range list instance
Contextconfigure service vprn service-name mld interface interface-name ssm-translate group-range start ipv6-multicast-address end ipv6-multicast-address
Treegroup-range
Introduced25.3.R2

Platforms

7705 SAR Gen 2

source [source-address] ipv6-unicast-address
Synopsis Add a list entry for source
Context configure service vprn service-name mld interface interface-name ssm-translate group-range start ipv6-multicast-address end ipv6-multicast-address source ipv6-unicast-address
Treesource
Min. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[source-address] ipv6-unicast-address
Synopsis Source IP address
Context configure service vprn service-name mld interface interface-name ssm-translate group-range start ipv6-multicast-address end ipv6-multicast-address source ipv6-unicast-address
Treesource

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

static
Synopsis Enter the static context
Context configure service vprn service-name mld interface interface-name static
Treestatic
Introduced25.3.R2

Platforms

7705 SAR Gen 2

group [group-address] ipv6-multicast-address
Synopsis Enter the group list instance
Context configure service vprn service-name mld interface interface-name static group ipv6-multicast-address
Treegroup
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[group-address] ipv6-multicast-address
Synopsis Group address of multicast channel
Context configure service vprn service-name mld interface interface-name static group ipv6-multicast-address
Treegroup

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

source [source-address] ipv6-unicast-address
Synopsis Add a list entry for source
Context configure service vprn service-name mld interface interface-name static group ipv6-multicast-address source ipv6-unicast-address
Treesource

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[source-address] ipv6-unicast-address
Synopsis Source IP address
Context configure service vprn service-name mld interface interface-name static group ipv6-multicast-address source ipv6-unicast-address
Treesource

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

starg
Synopsis any source address (*,G)
Context configure service vprn service-name mld interface interface-name static group ipv6-multicast-address starg
Treestarg

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

group-range start ipv6-multicast-address end ipv6-multicast-address step ipv6-address
Synopsis Enter the group-range list instance
Contextconfigure service vprn service-name mld interface interface-name static group-range start ipv6-multicast-address end ipv6-multicast-address step ipv6-address
Treegroup-range
Introduced25.3.R2

Platforms

7705 SAR Gen 2

start ipv6-multicast-address
Synopsis Lower bound of the static multicast group
Contextconfigure service vprn service-name mld interface interface-name static group-range start ipv6-multicast-address end ipv6-multicast-address step ipv6-address
Treegroup-range

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

end ipv6-multicast-address
Synopsis Upper bound of the static multicast group
Contextconfigure service vprn service-name mld interface interface-name static group-range start ipv6-multicast-address end ipv6-multicast-address step ipv6-address
Treegroup-range

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

step ipv6-address
Synopsis Step interval for the group-range addresses
Contextconfigure service vprn service-name mld interface interface-name static group-range start ipv6-multicast-address end ipv6-multicast-address step ipv6-address
Treegroup-range
MD-CLI default::1

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

source [source-address] ipv6-unicast-address
Synopsis Add a list entry for source
Context configure service vprn service-name mld interface interface-name static group-range start ipv6-multicast-address end ipv6-multicast-address step ipv6-address source ipv6-unicast-address
Treesource

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[source-address] ipv6-unicast-address
Synopsis Source IP address
Context configure service vprn service-name mld interface interface-name static group-range start ipv6-multicast-address end ipv6-multicast-address step ipv6-address source ipv6-unicast-address
Treesource

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

starg
Synopsis any source address (*,G)
Context configure service vprn service-name mld interface interface-name static group-range start ipv6-multicast-address end ipv6-multicast-address step ipv6-address starg
Treestarg

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

version keyword
Synopsis MLD protocol version
Context configure service vprn service-name mld interface interface-name version keyword
Treeversion
Options1, 2
Default 2
Introduced25.3.R2

Platforms

7705 SAR Gen 2

query-interval number
Synopsis Time between two consecutive host-query messages
Contextconfigure service vprn service-name mld query-interval number
Treequery-interval
Range2 to 1024
Unitsseconds
Default 125
Introduced25.3.R2

Platforms

7705 SAR Gen 2

robust-count number
Synopsis Number of retries after expected message loss
Contextconfigure service vprn service-name mld robust-count number
Treerobust-count
Range2 to 10
Default2
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

ssm-translate
Synopsis Enter the ssm-translate context
Contextconfigure service vprn service-name mld ssm-translate
Treessm-translate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

group-range start ipv6-multicast-address end ipv6-multicast-address
Synopsis Enter the group-range list instance
Contextconfigure service vprn service-name mld ssm-translate group-range start ipv6-multicast-address end ipv6-multicast-address
Treegroup-range
Introduced25.3.R2

Platforms

7705 SAR Gen 2

start ipv6-multicast-address
Synopsis Lower bound of the group range
Context configure service vprn service-name mld ssm-translate group-range start ipv6-multicast-address end ipv6-multicast-address
Treegroup-range

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

end ipv6-multicast-address
Synopsis Upper bound of the group range
Context configure service vprn service-name mld ssm-translate group-range start ipv6-multicast-address end ipv6-multicast-address
Treegroup-range

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

source [source-address] ipv6-unicast-address
Synopsis Add a list entry for source
Context configure service vprn service-name mld ssm-translate group-range start ipv6-multicast-address end ipv6-multicast-address source ipv6-unicast-address
Treesource
Min. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[source-address] ipv6-unicast-address
Synopsis Source IP address
Context configure service vprn service-name mld ssm-translate group-range start ipv6-multicast-address end ipv6-multicast-address source ipv6-unicast-address
Treesource

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

nat
Synopsis Enable the nat context
Context configure service vprn service-name nat
Treenat
Introduced25.3.R2

Platforms

7705 SAR Gen 2

inside
Synopsis Enter the inside context
Context configure service vprn service-name nat inside
Treeinside
Introduced25.3.R2

Platforms

7705 SAR Gen 2

large-scale
Synopsis Enter the large-scale context
Context configure service vprn service-name nat inside large-scale
Treelarge-scale
Introduced25.3.R2

Platforms

7705 SAR Gen 2

nat-policy reference
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisNAT policy name for LSN
Contextconfigure service vprn service-name nat inside large-scale nat-policy reference
Treenat-policy

Reference

configure service nat nat-policy external-named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

nat44
Synopsis Enter the nat44 context
Context configure service vprn service-name nat inside large-scale nat44
Treenat44
Introduced25.3.R2

Platforms

7705 SAR Gen 2

destination-prefix [ip-prefix-length] ipv4-unicast-prefix
Synopsis Enter the destination-prefix list instance
Contextconfigure service vprn service-name nat inside large-scale nat44 destination-prefix ipv4-unicast-prefix
Treedestination-prefix
Max. instances6144
Introduced25.3.R2

Platforms

7705 SAR Gen 2

deterministic
Synopsis Enter the deterministic context
Contextconfigure service vprn service-name nat inside large-scale nat44 deterministic
Treedeterministic
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address-map [from] ipv4-address to ipv4-address nat-policy reference
Synopsis Enter the address-map list instance
Contextconfigure service vprn service-name nat inside large-scale nat44 deterministic address-map ipv4-address to ipv4-address nat-policy reference
Treeaddress-map

Description

Commands in this context map inside IPv4 addresses of deterministic NAT44 subscribers to the outside IPv4 addresses in a NAT pool.

This context is only applicable to deterministic NAT44 with a single ESA-VM in a NAT-group. The number of subscribers per outside IPv4 address is flexible and not restricted to a discrete range governed by the 2^n rule.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[from] ipv4-address
Synopsis First IP address of inside IP NAT range
Contextconfigure service vprn service-name nat inside large-scale nat44 deterministic address-map ipv4-address to ipv4-address nat-policy reference
Treeaddress-map

Description

This command specifies the starting IPv4 address, IPv6 address, or IPv6 prefix on the inside IP address range.

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

to ipv4-address
Synopsis Ending IP address of inside IP NAT range
Contextconfigure service vprn service-name nat inside large-scale nat44 deterministic address-map ipv4-address to ipv4-address nat-policy reference
Treeaddress-map

Description

This command specifies the ending IPv4 address, IPv6 address, or IPv6 prefix on the inside IP address range.

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

outside-range ipv4-address
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisFirst outside IP address in NAT pool
Contextconfigure service vprn service-name nat inside large-scale nat44 deterministic address-map ipv4-address to ipv4-address nat-policy reference outside-range ipv4-address
Treeoutside-range

Description

This command specifies the first outside IP address in the NAT pool.

The last outside IP address is determined by the number of subscribers mapped to an outside IP address via the configure router nat outside pool large-scale subscriber-limit and configure service vprn nat outside pool large-scale subscriber-limit commands.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

prefix-map [source-prefix] ipv4-unicast-prefix nat-policy reference
Synopsis Enter the prefix-map list instance
Contextconfigure service vprn service-name nat inside large-scale nat44 deterministic prefix-map ipv4-unicast-prefix nat-policy reference
Treeprefix-map
Introduced25.3.R2

Platforms

7705 SAR Gen 2

map [from] ipv4-address to ipv4-address
Synopsis Enter the map list instance
Context configure service vprn service-name nat inside large-scale nat44 deterministic prefix-map ipv4-unicast-prefix nat-policy reference map ipv4-address to ipv4-address
Treemap
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[from] ipv4-address
Synopsis First IP address of inside IP NAT range
Contextconfigure service vprn service-name nat inside large-scale nat44 deterministic prefix-map ipv4-unicast-prefix nat-policy reference map ipv4-address to ipv4-address
Treemap

Description

This command specifies the starting IPv4 address, IPv6 address, or IPv6 prefix on the inside IP address range.

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

to ipv4-address
Synopsis Ending IP address of inside IP NAT range
Contextconfigure service vprn service-name nat inside large-scale nat44 deterministic prefix-map ipv4-unicast-prefix nat-policy reference map ipv4-address to ipv4-address
Treemap

Description

This command specifies the ending IPv4 address, IPv6 address, or IPv6 prefix on the inside IP address range.

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

first-outside-address ipv4-address
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisOutside IP address mapped to inside IP address range
Contextconfigure service vprn service-name nat inside large-scale nat44 deterministic prefix-map ipv4-unicast-prefix nat-policy reference map ipv4-address to ipv4-address first-outside-address ipv4-address
Treefirst-outside-address

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

max-subscriber-limit number
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisLargest value for all subscriber limits in each deterministic pool
Contextconfigure service vprn service-name nat inside large-scale nat44 max-subscriber-limit number
Treemax-subscriber-limit
Range1 | 2 | 4 | 8 | 16 | 32 | 64 | 128 | 256 | 512 | 1024 | 2048 | 4096 | 8192 | 16384 | 32768
Introduced25.3.R2

Platforms

7705 SAR Gen 2

outside
Synopsis Enter the outside context
Context configure service vprn service-name nat outside
Treeoutside
Introduced25.3.R2

Platforms

7705 SAR Gen 2

filters
Synopsis Enter the filters context
Context configure service vprn service-name nat outside filters
Treefilters
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mtu number
Synopsis MTU for downstream traffic
Context configure service vprn service-name nat outside mtu number
Treemtu
Range512 to 9000
Introduced25.3.R2

Platforms

7705 SAR Gen 2

pool [name] named-item
Synopsis Enter the pool list instance
Context configure service vprn service-name nat outside pool named-item
Treepool
Max. instances4096
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[name] named-item
Synopsis NAT pool name
Contextconfigure service vprn service-name nat outside pool named-item
Treepool
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

address-range [start] ipv4-unicast-address end ipv4-unicast-address
Synopsis Enter the address-range list instance
Contextconfigure service vprn service-name nat outside pool named-item address-range ipv4-unicast-address end ipv4-unicast-address
Treeaddress-range
Max. instances4096
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[start] ipv4-unicast-address
Synopsis Lower bound of the NAT address range
Context configure service vprn service-name nat outside pool named-item address-range ipv4-unicast-address end ipv4-unicast-address
Treeaddress-range

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

end ipv4-unicast-address
Synopsis Upper bound of the NAT address range
Context configure service vprn service-name nat outside pool named-item address-range ipv4-unicast-address end ipv4-unicast-address
Treeaddress-range

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

drain boolean
Synopsis Start or stop draining this NAT address range
Contextconfigure service vprn service-name nat outside pool named-item address-range ipv4-unicast-address end ipv4-unicast-address drain boolean
Treedrain
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the outside routing NAT pool
Contextconfigure service vprn service-name nat outside pool named-item admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

applications
Synopsis Enter the applications context
Contextconfigure service vprn service-name nat outside pool named-item applications
Treeapplications
Introduced25.3.R2

Platforms

7705 SAR Gen 2

agnostic boolean
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNAT pool to create in the outside routing context
Contextconfigure service vprn service-name nat outside pool named-item applications agnostic boolean
Treeagnostic
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

icmp-echo-reply boolean
Synopsis Allow NAT pool IP addresses to respond to ICMP PINGs
Contextconfigure service vprn service-name nat outside pool named-item icmp-echo-reply boolean
Treeicmp-echo-reply

Description

This command allows IP addresses in the NAT pool to respond to ICMP Echo requests (PINGs). The configuration can be toggled while the pool is in use.

In L2-aware NAT when port-block-extensions is disabled, the reply from an outside IP address is generated only when this IP address has at least one host (binding) behind it.

In L2-aware NAT when port-block-extensions is enabled, the reply from an outside IP address is generated regardless if a binding is present.

In LSN, the reply from an outside IP address is generated regardless if a binding is present.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

large-scale
Synopsis Enter the large-scale context
Context configure service vprn service-name nat outside pool named-item large-scale
Treelarge-scale
Introduced25.3.R2

Platforms

7705 SAR Gen 2

subscriber-limit number
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisMaximum number of subscribers per IP address
Contextconfigure service vprn service-name nat outside pool named-item large-scale subscriber-limit number
Treesubscriber-limit
Range1 to 65535 | 4294967295
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mode keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisMode of operation of this NAT address pool
Contextconfigure service vprn service-name nat outside pool named-item mode keyword
Treemode
Optionsauto, napt, one-to-one
Introduced25.3.R2

Platforms

7705 SAR Gen 2

nat-group reference
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisCreate a NAT group
Contextconfigure service vprn service-name nat outside pool named-item nat-group reference
Treenat-group

Reference

configure isa nat-group number

Notes

The following elements are part of a mandatory choice: nat-group or wlan-gw-group.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

port-forwarding
Synopsis Enter the port-forwarding context
Contextconfigure service vprn service-name nat outside pool named-item port-forwarding
Treeport-forwarding
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dynamic-block-reservation boolean
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisReserve dynamic block for subscriber
Contextconfigure service vprn service-name nat outside pool named-item port-forwarding dynamic-block-reservation boolean
Treedynamic-block-reservation

Description

When configured to true, the system reserves dynamic port block when the first port forward for the subscriber is created. The dynamic port block allocation is logged only if the block is being used and mappings are created. Dynamic port block reservation due to the port forward creation but without any dynamic mapping, is not logged.

The reserved port block is released only when the last mapping in the block expires and there are no port forwards associated with the subscriber. The de-allocation log (syslog or RADIUS) is generated when the dynamic port block is completely released.

Dynamic port block reservations can be enabled only if the configured maximum number of subscribers per outside IP addresses are less than or equal to the maximum number of configured port blocks per outside IP address.

When configured to false, dynamic port blocks are not reserved when the first port forward for the subscriber is created.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

range-end number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisEnd of the wildcard range for port forwards
Contextconfigure service vprn service-name nat outside pool named-item port-forwarding range-end number
Treerange-end

Description

This command configures the upper boundary of the wildcard port range dedicated to port forwarding in a NAT pool, whereas the range-start command configures the lower boundary (the starting port) of the wildcard port range dedicated to port forwarding in a NAT pool.

If unconfigured, the range-end implicit value is set to 1023, that represents the end of the well-known port range that is always enabled.

Port forwards are supported only in pools in NAPT mode. Pools in 1:1 mode do not support port-forwards.

Range0 | 1023 to 65535
Introduced25.3.R2

Platforms

7705 SAR Gen 2

port-reservation
Synopsis Enter the port-reservation context
Contextconfigure service vprn service-name nat outside pool named-item port-reservation
Treeport-reservation
Introduced25.3.R2

Platforms

7705 SAR Gen 2

port-blocks number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisPort block size for NAT subscribers
Contextconfigure service vprn service-name nat outside pool named-item port-reservation port-blocks number
Treeport-blocks

Description

In CGN, this command specifies the number of port-blocks per outside IP address in the NAT pool. The available ports per outside IP address (the end port minus the upper bound value of the static port-forwarding range) are divided into the number of port blocks specified in this command. This implicitly determines the size of each port block.

For L2-aware NAT, this command can be configured only if the port block extensions (extended port blocks) are disabled. You must disable the l2-aware port-block-extension hierarchy in the NAT pool.

Range0 to 64512

Notes

The following elements are part of a choice: port-blocks or ports.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ports number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisSize of the port block for NAT subscribers
Contextconfigure service vprn service-name nat outside pool named-item port-reservation ports number
Treeports

Description

For carrier-grade NAT (CGN), this command specifies the size of port blocks for NAT subscribers in the NAT pool.

For Layer 2 aware NAT, this command specifies the size of the initial port block of a subscriber in the pool. Additional port blocks (extended port blocks) for the Layer 2 aware subscriber must be explicitly enabled under the l2-aware port-block-extension hierarchy in the NAT pool.

This command does not affect the size of extended port blocks.

For deterministic pools, the port range begins with zero. However, for non-deterministic pools, the port range begins with one.

Range0 to 64512

Notes

The following elements are part of a choice: port-blocks or ports.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

type keyword
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNAT pool type
Contextconfigure service vprn service-name nat outside pool named-item type keyword
Treetype
Optionslarge-scale, l2-aware, wlan-gw-anchor

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

watermarks
Synopsis Enable the watermarks context
Context configure service vprn service-name nat outside pool named-item watermarks
Treewatermarks

Description

This command configures watermarks for NAT resources.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

high number
Synopsis High watermark percentage
Context configure service vprn service-name nat outside pool named-item watermarks high number
Treehigh

Description

This command configures the high threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

low number
Synopsis Low watermark percentage
Context configure service vprn service-name nat outside pool named-item watermarks low number
Treelow

Description

This command configures the low threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

network
Synopsis Enter the network context
Context configure service vprn service-name network
Treenetwork
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ingress
Synopsis Enter the ingress context
Context configure service vprn service-name network ingress
Treeingress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

filter
Synopsis Enter the filter context
Context configure service vprn service-name network ingress filter
Treefilter
Introduced25.3.R2

Platforms

7705 SAR Gen 2

qos
Synopsis Enter the qos context
Context configure service vprn service-name network ingress qos
Treeqos
Introduced25.3.R2

Platforms

7705 SAR Gen 2

instance number
Synopsis Forwarding plane ingress queue group instance
Contextconfigure service vprn service-name network ingress qos instance number
Treeinstance
Range1 to 65535
Introduced25.3.R2

Platforms

7705 SAR Gen 2

urpf-check boolean
Synopsis Enable unicast RPF check of network ingress traffic
Contextconfigure service vprn service-name network ingress urpf-check boolean
Treeurpf-check
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

network-interface [interface-name] interface-name
Synopsis Enter the network-interface list instance
Contextconfigure service vprn service-name network-interface interface-name
Treenetwork-interface
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[interface-name] interface-name
Synopsis Network interface name
Context configure service vprn service-name network-interface interface-name
Treenetwork-interface
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the interface
Contextconfigure service vprn service-name network-interface interface-name admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description very-long-description
Synopsis Text description
Context configure service vprn service-name network-interface interface-name description very-long-description
Treedescription
String length1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

egress
Synopsis Enter the egress context
Context configure service vprn service-name network-interface interface-name egress
Treeegress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hold-time
Synopsis Enter the hold-time context
Context configure service vprn service-name network-interface interface-name hold-time
Treehold-time
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4
Synopsis Enter the ipv4 context
Context configure service vprn service-name network-interface interface-name hold-time ipv4
Treeipv4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

down
Synopsis Enter the down context
Context configure service vprn service-name network-interface interface-name hold-time ipv4 down
Treedown

Description

Commands in this context configure the down hold timer, which specifies the delay before activating the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface up, unless an operator configures the init-only command. 

Introduced25.3.R2

Platforms

7705 SAR Gen 2

init-only boolean
Synopsis Apply delay only at interface configuration or reboot
Contextconfigure service vprn service-name network-interface interface-name hold-time ipv4 down init-only boolean
Treeinit-only

Description

This command applies a delay only when the IP interface is first configured or after a system reboot.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

up
Synopsis Enter the up context
Context configure service vprn service-name network-interface interface-name hold-time ipv4 up
Treeup

Description

Commands in this context configure the up hold timer, which specifies the delay before deactivation of the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface down.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ingress
Synopsis Enter the ingress context
Context configure service vprn service-name network-interface interface-name ingress
Treeingress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-mtu number
Synopsis IP MTU applied to outgoing packets
Context configure service vprn service-name network-interface interface-name ip-mtu number
Treeip-mtu

Description

This command configures the IP maximum transmission unit (MTU) for the associated router IP interface.

Range512 to 9786
Unitsbytes
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

ipv4
Synopsis Enter the ipv4 context
Context configure service vprn service-name network-interface interface-name ipv4
Treeipv4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd
Synopsis Enter the bfd context
Context configure service vprn service-name network-interface interface-name ipv4 bfd
Treebfd
Introduced25.3.R2

Platforms

7705 SAR Gen 2

multiplier number
Synopsis Number of consecutive BFD messages missed from the peer
Contextconfigure service vprn service-name network-interface interface-name ipv4 bfd multiplier number
Treemultiplier

Description

This command configures the number of missed messages before the BFD session state is changed to down and the upper-level protocol is notified of the fault. A multiplier of less than 3 should not be used in production environments. 

Range1 to 20
Default3
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

receive number
Synopsis BFD receive interval over this interface
Contextconfigure service vprn service-name network-interface interface-name ipv4 bfd receive number
Treereceive

Description

This command specifies the receive interval for the BFD session.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

transmit-interval number
Synopsis BFD transmit interval over this interface
Contextconfigure service vprn service-name network-interface interface-name ipv4 bfd transmit-interval number
Treetransmit-interval

Description

This command configures the transmit intervals.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

icmp
Synopsis Enter the icmp context
Context configure service vprn service-name network-interface interface-name ipv4 icmp
Treeicmp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

param-problem
Synopsis Enter the param-problem context
Contextconfigure service vprn service-name network-interface interface-name ipv4 icmp param-problem
Treeparam-problem

Description

Commands in this context specify the settings for ICMP Parameter Problem messages generated by the interface.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

redirects
Synopsis Enter the redirects context
Context configure service vprn service-name network-interface interface-name ipv4 icmp redirects
Treeredirects

Description

Commands in this context configure the settings for ICMP redirect messages generated by the interface.

The system sends ICMP redirect messages to alert the sending node that a more optimal route is available on another router on the same subnetwork.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ttl-expired
Synopsis Enter the ttl-expired context
Context configure service vprn service-name network-interface interface-name ipv4 icmp ttl-expired
Treettl-expired

Description

Commands in this context configure the settings for ICMP TTL expired messages generated by the interface.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

unreachables
Synopsis Enter the unreachables context
Contextconfigure service vprn service-name network-interface interface-name ipv4 icmp unreachables
Treeunreachables

Description

Commands in this context specify the settings for ICMP host and network destination unreachable messages generated by the interface.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

neighbor-discovery
Synopsis Enter the neighbor-discovery context
Contextconfigure service vprn service-name network-interface interface-name ipv4 neighbor-discovery
Treeneighbor-discovery
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static-neighbor [ipv4-address] ipv4-address
Synopsis Enter the static-neighbor list instance
Contextconfigure service vprn service-name network-interface interface-name ipv4 neighbor-discovery static-neighbor ipv4-address
Treestatic-neighbor
Introduced25.3.R2

Platforms

7705 SAR Gen 2

timeout number
Synopsis Timeout for an ARP entry learned on the interface
Contextconfigure service vprn service-name network-interface interface-name ipv4 neighbor-discovery timeout number
Treetimeout

Description

This command configures the minimum time an ARP entry learned on the IP interface is stored in the ARP table. ARP entries are automatically refreshed when an ARP request or gratuitous ARP is seen by an IP host. Otherwise, the ARP entry is aged from the ARP table.

Range0 to 65535
Unitsseconds
Default 14400
Introduced25.3.R2

Platforms

7705 SAR Gen 2

primary
Synopsis Enable the primary context
Context configure service vprn service-name network-interface interface-name ipv4 primary
Treeprimary
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address ipv4-unicast-address
Synopsis Primary IPv4 address assigned to the interface
Contextconfigure service vprn service-name network-interface interface-name ipv4 primary address ipv4-unicast-address
Treeaddress

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

secondary [address] ipv4-unicast-address
Synopsis Enter the secondary list instance
Contextconfigure service vprn service-name network-interface interface-name ipv4 secondary ipv4-unicast-address
Treesecondary
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[address] ipv4-unicast-address
Synopsis Secondary IPv4 address assigned to the interface
Contextconfigure service vprn service-name network-interface interface-name ipv4 secondary ipv4-unicast-address
Treesecondary

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

igp-inhibit boolean
Synopsis Disable the running IGP from recognizing secondary IP
Contextconfigure service vprn service-name network-interface interface-name ipv4 secondary ipv4-unicast-address igp-inhibit boolean
Treeigp-inhibit

Description

When configured to true, the running IGP does not recognize the secondary IP address as a local interface.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

tcp-mss number
Synopsis TCP maximum segment size for the interface
Contextconfigure service vprn service-name network-interface interface-name ipv4 tcp-mss number
Treetcp-mss
Range384 to 9746
Introduced25.3.R2

Platforms

7705 SAR Gen 2

urpf-check
Synopsis Enable the urpf-check context
Context configure service vprn service-name network-interface interface-name ipv4 urpf-check
Treeurpf-check
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mode keyword
Synopsis Unicast RPF check mode
Context configure service vprn service-name network-interface interface-name ipv4 urpf-check mode keyword
Treemode
Options

strict – Check source address match in RT and interface

loose – Check source address match in RT only

strict-no-ecmp – Check source address match in ECMP route

Defaultstrict
Introduced25.3.R2

Platforms

7705 SAR Gen 2

load-balancing
Synopsis Enter the load-balancing context
Contextconfigure service vprn service-name network-interface interface-name load-balancing
Treeload-balancing
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-load-balancing keyword
Synopsis IP load-balancing algorithm
Context configure service vprn service-name network-interface interface-name load-balancing ip-load-balancing keyword
Treeip-load-balancing

Description

This command specifies whether to include the source address, destination address, or both in LAG or ECMP hash on IP interfaces. Additionally, when the l4-load-balancing command is enabled, this command also includes the source or destination port in the hash inputs.

Optionsboth, destination, source, inner-ip
Default both
Introduced25.3.R2

Platforms

7705 SAR Gen 2

lsr-load-balancing keyword
Synopsis LSR load-balancing algorithm
Context configure service vprn service-name network-interface interface-name load-balancing lsr-load-balancing keyword
Treelsr-load-balancing

Description

This command specifies whether the IP header is used in the LAG and ECMP LSR hashing algorithm. This is the per-interface setting.

Optionslbl-only, lbl-ip, ip-only, eth-encap-ip, lbl-ip-l4-teid
Introduced25.3.R2

Platforms

7705 SAR Gen 2

loopback
Synopsis Use interface as a loopback interface
Contextconfigure service vprn service-name network-interface interface-name loopback
Treeloopback

Notes

The following elements are part of a choice: loopback or port.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mac mac-unicast-address
Synopsis MAC address for the interface
Context configure service vprn service-name network-interface interface-name mac mac-unicast-address
Treemac
Introduced25.3.R2

Platforms

7705 SAR Gen 2

port port-and-encap
Synopsis Port to bind the interface
Context configure service vprn service-name network-interface interface-name port port-and-encap
Treeport
String length1 to 45

Notes

The following elements are part of a choice: loopback or port.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

qos
Synopsis Enter the qos context
Context configure service vprn service-name network-interface interface-name qos
Treeqos
Introduced25.3.R2

Platforms

7705 SAR Gen 2

egress-instance number
Synopsis Port egress queue group instance for this interface
Contextconfigure service vprn service-name network-interface interface-name qos egress-instance number
Treeegress-instance

Description

This command specifies which instance to associate with this specific network IP interface since multiple instances of the same egress queue-group can be applied to the same port.

Range1 to 65535
Introduced25.3.R2

Platforms

7705 SAR Gen 2

egress-port-redirect-group reference
Synopsis QoS queue group name
Context configure service vprn service-name network-interface interface-name qos egress-port-redirect-group reference
Treeegress-port-redirect-group

Description

This command configures the egress queue group used for all egress forwarding-class redirections specified within the network QoS policy ID. The specified queue group name must exist as an egress queue group applied to the egress context of the port associated with the IP interface.

Reference

configure qos queue-group-templates egress queue-group named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ingress-fp-redirect-group reference
Synopsis Forwarding plane queue group policy for the interface
Contextconfigure service vprn service-name network-interface interface-name qos ingress-fp-redirect-group reference
Treeingress-fp-redirect-group

Description

This command configures the ingress queue-group used for all ingress forwarding-class redirections specified within the network QoS policy ID. The specified queue group name must exist as an ingress queue group applied to the ingress context of the forwarding plane associated with the IP interface.

Reference

configure qos queue-group-templates ingress queue-group named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ingress-instance number
Synopsis Forwarding plane ingress queue group for this interface
Contextconfigure service vprn service-name network-interface interface-name qos ingress-instance number
Treeingress-instance

Description

This command configures which instance to associate with this specific network IP interface. An operator can apply multiple instances of the same ingress queue group to the same forwarding plane.

Range1 to 65535
Introduced25.3.R2

Platforms

7705 SAR Gen 2

network-policy reference
Synopsis Network policy name associated with a network interface
Contextconfigure service vprn service-name network-interface interface-name qos network-policy reference
Treenetwork-policy

Description

This command associates an existing network policy name with the IP interface.

Reference

configure qos network network-policy-name

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ntp
Synopsis Enable the ntp context
Context configure service vprn service-name ntp
Treentp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of NTP execution
Contextconfigure service vprn service-name ntp admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

authenticate boolean
Synopsis Authentication of NTP PDUs when acting as a server
Contextconfigure service vprn service-name ntp authenticate boolean
Treeauthenticate
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

authentication-key [key-id] number
Synopsis Enter the authentication-key list instance
Contextconfigure service vprn service-name ntp authentication-key number
Treeauthentication-key
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[key-id] number
Synopsis Authentication key ID used for NTP packets
Contextconfigure service vprn service-name ntp authentication-key number
Treeauthentication-key
Range1 to 255

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

key encrypted-leaf
Synopsis Key to authenticate NTP packets
Context configure service vprn service-name ntp authentication-key number key encrypted-leaf
Treekey
String length1 to 71

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

type keyword
Synopsis Authentication method to authenticate NTP packet
Contextconfigure service vprn service-name ntp authentication-key number type keyword
Treetype
Optionsdes, message-digest

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

authentication-keychain reference
Synopsis Authentication keychain for unsolicited traffic
Contextconfigure service vprn service-name ntp authentication-keychain reference
Treeauthentication-keychain

Description

This command configures the authentication keychain used to handle unsolicited NTP requests.

If a request is received with a key ID that matches both a configured key and the keychain, the MAC is checked first using the key information. If the authentication fails, the MAC is checked using the information from the keychain.

Reference

configure system security keychains keychain named-item

Introduced25.3.R2

Platforms

7705 SAR Gen 2

broadcast [interface-name] reference
Synopsis Enter the broadcast list instance
Contextconfigure service vprn service-name ntp broadcast reference
Treebroadcast
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[interface-name] reference
Synopsis Local interface used to transmit NTP broadcast packets
Contextconfigure service vprn service-name ntp broadcast reference
Treebroadcast

Reference

configure service vprn service-name interface interface-name

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

authentication-keychain reference
Synopsis Keychain used to authenticate broadcast messages
Contextconfigure service vprn service-name ntp broadcast reference authentication-keychain reference
Treeauthentication-keychain

Description

This command configures the keychain used to authenticate messages sent by this node.

The keychain infrastructure is queried using this keychain name to get the youngest key used for generating the authentication value for the message. When an NTP packet is received by this node, the keychain infrastructure is queried using the keychain name and the key ID extracted from the received message to get the key used to perform the authentication check. If authentication does not pass, the packet is rejected. Keychain entries also have a direction. The key ID and authentication keychain are mutually exclusive. When neither one is set, for example, the key ID has a value of '0' and the value of this command is empty, no authentication is performed.

Reference

configure system security keychains keychain named-item

Notes

The following elements are part of a choice: authentication-keychain or key-id.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

key-id reference
Synopsis Authentication key and type used by the node
Contextconfigure service vprn service-name ntp broadcast reference key-id reference
Treekey-id

Reference

configure service vprn service-name ntp authentication-key number

Notes

The following elements are part of a choice: authentication-keychain or key-id.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ttl number
Synopsis TTL of messages transmitted by the broadcast address
Contextconfigure service vprn service-name ntp broadcast reference ttl number
Treettl
Range1 to 255
Default127
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

version number
Synopsis NTP version number generated by the node
Contextconfigure service vprn service-name ntp broadcast reference version number
Treeversion
Range2 to 4
Default4
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

ospf [ospf-instance] number
Synopsis Enter the ospf list instance
Context configure service vprn service-name ospf number
Treeospf
Max. instances32
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ospf-instance] number
Synopsis Integrated OSPF instance
Context configure service vprn service-name ospf number
Treeospf
Range0
MD-CLI default 0

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the OSPF instance
Contextconfigure service vprn service-name ospf number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

area [area-id] ipv4-address
Synopsis Enter the area list instance
Context configure service vprn service-name ospf number area ipv4-address
Treearea
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[area-id] ipv4-address
Synopsis Area-ID attribute
Context configure service vprn service-name ospf number area ipv4-address
Treearea

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

area-range [ip-prefix-mask] ipv4-unicast-prefix
Synopsis Enter the area-range list instance
Contextconfigure service vprn service-name ospf number area ipv4-address area-range ipv4-unicast-prefix
Treearea-range
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ip-prefix-mask] ipv4-unicast-prefix
Synopsis IPv4 unicast address prefix and mask
Context configure service vprn service-name ospf number area ipv4-address area-range ipv4-unicast-prefix
Treearea-range

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

advertise boolean
Synopsis Advertise summarized range of addresses to other areas
Contextconfigure service vprn service-name ospf number area ipv4-address area-range ipv4-unicast-prefix advertise boolean
Treeadvertise
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface [interface-name] interface-name
Synopsis Enter the interface list instance
Contextconfigure service vprn service-name ospf number area ipv4-address interface interface-name
Treeinterface
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[interface-name] interface-name
Synopsis IP interface name
Context configure service vprn service-name ospf number area ipv4-address interface interface-name
Treeinterface
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the OSPF interface
Contextconfigure service vprn service-name ospf number area ipv4-address interface interface-name admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd-liveness
Synopsis Enable the bfd-liveness context
Contextconfigure service vprn service-name ospf number area ipv4-address interface interface-name bfd-liveness
Treebfd-liveness
Introduced25.3.R2

Platforms

7705 SAR Gen 2

strict boolean
Synopsis Enable BFD strict mode
Context configure service vprn service-name ospf number area ipv4-address interface interface-name bfd-liveness strict boolean
Treestrict

Description

When configured to true, the system uses BFD strict-mode. BFD strict-mode mandates that an active BFD session must exist between the OSPF neighbors before establishing a full adjacency. When configured to true, the router uses Link-Local Signaling (LLS) with the B-flag set to instruct the OSPF neighbors that BFD must be enabled on the link. BFD strict-mode requires both sides to have the B-flag set.

During OSPFv3 BFD strict-mode operations, the router advertises the local interface IPv4 address TLV using LLS, but the SR OS router continues to use IPv6-based BFD sessions for both the IPv4 and IPv6 address families.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

strict-mode-holddown number
Synopsis Adjacency up time delay after BFD session establishment
Contextconfigure service vprn service-name ospf number area ipv4-address interface interface-name bfd-liveness strict-mode-holddown number
Treestrict-mode-holddown

Description

This command configures a delay timer before bringing up the OSPF adjacency after the BFD session establishment. Holddown helps mitigate potential routing churn when BFD sessions are unstable. The holddown timer is reset when a BFD session operationally toggles.

Range1 to 600
Unitsseconds
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

dead-interval number
Synopsis OSPF wait time for Hellos before neighbor declared down
Contextconfigure service vprn service-name ospf number area ipv4-address interface interface-name dead-interval number
Treedead-interval
Range2 to 65535
Unitsseconds
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

hello-interval number
Synopsis Time between OSPF Hellos of this interface
Contextconfigure service vprn service-name ospf number area ipv4-address interface interface-name hello-interval number
Treehello-interval
Range1 to 65535
Unitsseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface-type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisInterface type
Contextconfigure service vprn service-name ospf number area ipv4-address interface interface-name interface-type keyword
Treeinterface-type

Description

This command specifies the interface type.

broadcast - Broadcast network

To significantly improve adjacency forming and network convergence, configure a network as point-to-point if only two routers are connected, even if the network is a broadcast media such as Ethernet.

non-broadcast - Non-broadcast network

point-to-point - Point-to-point link

Set the interface type of an Ethernet link to point-to-point to avoid having to carry the broadcast adjacency maintenance overhead if the Ethernet link provided is used as a point-to-point.

p2mp-nbma - Point-to-multipoint on a link without broadcast or multicast support

No designated router or backup designated router is elected on this type of interface and all OSPF neighbors connect through individual point-to-point links. Only VPRN and IES services interfaces support this interface type.

secondary - Multiple secondary adjacencies allowed

A secondary interface allows multiple secondary adjacencies, in addition to the primary adjacency, to be established over a single IP interface. This interface type can also be applied to the system interface and to loopback interfaces to allow them to participate in multiple areas, although no adjacencies are formed over these types of interfaces.

Optionsbroadcast, non-broadcast, point-to-point, secondary, p2mp-nbma
Introduced25.3.R2

Platforms

7705 SAR Gen 2

loopfree-alternate
Synopsis Enter the loopfree-alternate context
Contextconfigure service vprn service-name ospf number area ipv4-address interface interface-name loopfree-alternate
Treeloopfree-alternate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy-map
Synopsis Enable the policy-map context
Context configure service vprn service-name ospf number area ipv4-address interface interface-name loopfree-alternate policy-map
Treepolicy-map
Introduced25.3.R2

Platforms

7705 SAR Gen 2

lsa-filter-out keyword
Synopsis LSA flooding reduction
Context configure service vprn service-name ospf number area ipv4-address interface interface-name lsa-filter-out keyword
Treelsa-filter-out
Optionsnone, all, except-own-rtrlsa, except-own-rtrlsa-and-defaults
Defaultnone
Introduced25.3.R2

Platforms

7705 SAR Gen 2

message-digest-key [key-id] number
Synopsis Enter the message-digest-key list instance
Contextconfigure service vprn service-name ospf number area ipv4-address interface interface-name message-digest-key number
Treemessage-digest-key
Introduced25.3.R2

Platforms

7705 SAR Gen 2

md5 encrypted-leaf
Synopsis MD5 hash key
Contextconfigure service vprn service-name ospf number area ipv4-address interface interface-name message-digest-key number md5 encrypted-leaf
Treemd5
String length1 to 51

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

metric number
Synopsis Route cost metric for the interface
Context configure service vprn service-name ospf number area ipv4-address interface interface-name metric number
Treemetric
Range1 to 65535
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mtu number
Synopsis MTU for the OSPF to use on the interface
Contextconfigure service vprn service-name ospf number area ipv4-address interface interface-name mtu number
Treemtu
Range512 to 9786
Introduced25.3.R2

Platforms

7705 SAR Gen 2

neighbor [address] ipv4-unicast-address
Synopsis Add a list entry for neighbor
Context configure service vprn service-name ospf number area ipv4-address interface interface-name neighbor ipv4-unicast-address
Treeneighbor
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[address] ipv4-unicast-address
Synopsis IPv4 address of the OSPFv2 neighbor
Context configure service vprn service-name ospf number area ipv4-address interface interface-name neighbor ipv4-unicast-address
Treeneighbor

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

passive boolean
Synopsis Advertise passive interfaces as OSPF interfaces
Contextconfigure service vprn service-name ospf number area ipv4-address interface interface-name passive boolean
Treepassive
Introduced25.3.R2

Platforms

7705 SAR Gen 2

poll-interval number
Synopsis Interval for Hellos to non-adjacent OSPF NBMA neighbor
Contextconfigure service vprn service-name ospf number area ipv4-address interface interface-name poll-interval number
Treepoll-interval
Max. range0 to 4294967295
Unitsseconds
Default120
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

priority number
Synopsis Interface priority in the DR election on the subnet
Contextconfigure service vprn service-name ospf number area ipv4-address interface interface-name priority number
Treepriority
Range0 to 255
Default1
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

transit-delay number
Synopsis Required LSA transmit time
Context configure service vprn service-name ospf number area ipv4-address interface interface-name transit-delay number
Treetransit-delay
Range1 to 1800
Unitsseconds
Default 1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

nssa
Synopsis Enable the nssa context
Context configure service vprn service-name ospf number area ipv4-address nssa
Treenssa
Introduced25.3.R2

Platforms

7705 SAR Gen 2

area-range [ip-prefix-mask] ipv4-unicast-prefix
Synopsis Enter the area-range list instance
Contextconfigure service vprn service-name ospf number area ipv4-address nssa area-range ipv4-unicast-prefix
Treearea-range
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ip-prefix-mask] ipv4-unicast-prefix
Synopsis IPv4 unicast address prefix and mask
Context configure service vprn service-name ospf number area ipv4-address nssa area-range ipv4-unicast-prefix
Treearea-range

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

advertise boolean
Synopsis Advertise summarized range of addresses to other areas
Contextconfigure service vprn service-name ospf number area ipv4-address nssa area-range ipv4-unicast-prefix advertise boolean
Treeadvertise
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

originate-default-route
Synopsis Enable the originate-default-route context
Contextconfigure service vprn service-name ospf number area ipv4-address nssa originate-default-route
Treeoriginate-default-route
Introduced25.3.R2

Platforms

7705 SAR Gen 2

summaries boolean
Synopsis Send summary (Type 3) LSAs into the NSSA on an ABR
Contextconfigure service vprn service-name ospf number area ipv4-address nssa summaries boolean
Treesummaries
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sham-link [interface] interface-name ip-address ipv4-unicast-address
Synopsis Enter the sham-link list instance
Contextconfigure service vprn service-name ospf number area ipv4-address sham-link interface-name ip-address ipv4-unicast-address
Treesham-link
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[interface] interface-name
Synopsis Local interface name used for the sham-link
Contextconfigure service vprn service-name ospf number area ipv4-address sham-link interface-name ip-address ipv4-unicast-address
Treesham-link
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-address ipv4-unicast-address
Synopsis IP address of the sham-link neighbor
Context configure service vprn service-name ospf number area ipv4-address sham-link interface-name ip-address ipv4-unicast-address
Treesham-link

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the OSPF interface
Contextconfigure service vprn service-name ospf number area ipv4-address sham-link interface-name ip-address ipv4-unicast-address admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dead-interval number
Synopsis OSPF wait time for Hellos before neighbor declared down
Contextconfigure service vprn service-name ospf number area ipv4-address sham-link interface-name ip-address ipv4-unicast-address dead-interval number
Treedead-interval
Range2 to 65535
Unitsseconds
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

message-digest-key [key-id] number
Synopsis Enter the message-digest-key list instance
Contextconfigure service vprn service-name ospf number area ipv4-address sham-link interface-name ip-address ipv4-unicast-address message-digest-key number
Treemessage-digest-key
Introduced25.3.R2

Platforms

7705 SAR Gen 2

md5 encrypted-leaf
Synopsis MD5 key or hash key
Context configure service vprn service-name ospf number area ipv4-address sham-link interface-name ip-address ipv4-unicast-address message-digest-key number md5 encrypted-leaf
Treemd5
String length1 to 51

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

metric number
Synopsis Explicit route cost metric that is applied to the sham link
Contextconfigure service vprn service-name ospf number area ipv4-address sham-link interface-name ip-address ipv4-unicast-address metric number
Treemetric
Range1 to 65535
Default1
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

stub
Synopsis Enable the stub context
Context configure service vprn service-name ospf number area ipv4-address stub
Treestub
Introduced25.3.R2

Platforms

7705 SAR Gen 2

default-metric number
Synopsis Metric used by ABR for default route into the stub area
Contextconfigure service vprn service-name ospf number area ipv4-address stub default-metric number
Treedefault-metric
Range1 to 16777214
Default1
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

summaries boolean
Synopsis Send summary (Type 3) LSAs into the stub area on an ABR
Contextconfigure service vprn service-name ospf number area ipv4-address stub summaries boolean
Treesummaries
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

virtual-link [router-id] ipv4-address transit-area reference
Synopsis Enter the virtual-link list instance
Contextconfigure service vprn service-name ospf number area ipv4-address virtual-link ipv4-address transit-area reference
Treevirtual-link
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[router-id] ipv4-address
Synopsis Router identity of the virtual link neighbor
Contextconfigure service vprn service-name ospf number area ipv4-address virtual-link ipv4-address transit-area reference
Treevirtual-link

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

transit-area reference
Synopsis Transit area that links backbone area to area without physical connection with the backbone
Contextconfigure service vprn service-name ospf number area ipv4-address virtual-link ipv4-address transit-area reference
Treevirtual-link

Reference

configure service vprn service-name ospf number area ipv4-address

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

message-digest-key [key-id] number
Synopsis Enter the message-digest-key list instance
Contextconfigure service vprn service-name ospf number area ipv4-address virtual-link ipv4-address transit-area reference message-digest-key number
Treemessage-digest-key
Introduced25.3.R2

Platforms

7705 SAR Gen 2

export-limit
Synopsis Enable the export-limit context
Contextconfigure service vprn service-name ospf number export-limit
Treeexport-limit
Introduced25.3.R2

Platforms

7705 SAR Gen 2

number number
Synopsis Maximum routes or prefixes exported from route table
Contextconfigure service vprn service-name ospf number export-limit number number
Treenumber
Range1 to 4294967295

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

export-policy reference
Synopsis Export policies that determine exported routes
Contextconfigure service vprn service-name ospf number export-policy reference
Treeexport-policy

Description

This command configures export routing policies for the routes exported from the routing table to IS-IS.

If the export policy is undefined, the system does not export non IS-IS routes from the routing table manager to IS-IS.

If multiple policy names are specified, the policies are evaluated in the order they are specified. The first policy that matches is applied.

If the aggregate command is also configured in the configure router context, the aggregation is applied before the export policy is applied.

Routing policies are created in the configure router policy-options context.

Reference

configure policy-options policy-statement named-item-64

Max. instances5

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

external-db-overflow
Synopsis Enable the external-db-overflow context
Contextconfigure service vprn service-name ospf number external-db-overflow
Treeexternal-db-overflow
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interval number
Synopsis Time during which the router operates in overload
Contextconfigure service vprn service-name ospf number external-db-overflow interval number
Treeinterval
Range0 to 2147483647
Unitsseconds
Default 0
Introduced25.3.R2

Platforms

7705 SAR Gen 2

limit number
Synopsis Number of external LSA at which overload is triggered
Contextconfigure service vprn service-name ospf number external-db-overflow limit number
Treelimit
Range0 to 2147483647
Default0
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

graceful-restart
Synopsis Enable the graceful-restart context
Contextconfigure service vprn service-name ospf number graceful-restart
Treegraceful-restart
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ignore-dn-bit boolean
Synopsis Ignore the DN bit for OSPF LSA packets for the instance
Contextconfigure service vprn service-name ospf number ignore-dn-bit boolean
Treeignore-dn-bit
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

loopfree-alternate
Synopsis Enable the loopfree-alternate context
Contextconfigure service vprn service-name ospf number loopfree-alternate
Treeloopfree-alternate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

exclude
Synopsis Enter the exclude context
Context configure service vprn service-name ospf number loopfree-alternate exclude
Treeexclude
Introduced25.3.R2

Platforms

7705 SAR Gen 2

prefix-policy reference
Synopsis Policy to exclude prefixes from LFA SPF calculation
Contextconfigure service vprn service-name ospf number loopfree-alternate exclude prefix-policy reference
Treeprefix-policy

Description

This command specifies the name of the policy for the prefixes to exclude from the LFA SPF calculation.

An excluded prefix is not included in LFA calculation regardless of its priority. The prefix tag is, however, used in the main SPF.

Reference

configure policy-options policy-statement named-item-64

Max. instances5

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

multicast-import boolean
Synopsis Submit routes into the multicast Route Table Manager
Contextconfigure service vprn service-name ospf number multicast-import boolean
Treemulticast-import
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overload boolean
Synopsis Change local router state to appear overloaded
Contextconfigure service vprn service-name ospf number overload boolean
Treeoverload
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overload-on-boot
Synopsis Enable the overload-on-boot context
Contextconfigure service vprn service-name ospf number overload-on-boot
Treeoverload-on-boot
Introduced25.3.R2

Platforms

7705 SAR Gen 2

timeout number
Synopsis Time during which the router operates in overload state before reestablishing normal operations
Contextconfigure service vprn service-name ospf number overload-on-boot timeout number
Treetimeout
Range60 to 1800
Unitsseconds
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

preference number
Synopsis Preference for OSPF internal routes
Context configure service vprn service-name ospf number preference number
Treepreference
Range1 to 255
Default10
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

reference-bandwidth number
Synopsis Bandwidth to reference default costing of interfaces
Contextconfigure service vprn service-name ospf number reference-bandwidth number
Treereference-bandwidth
Range1 to 18446744073709551615
Unitskilobps
Default100000000
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

rib-priority
Synopsis Enter the rib-priority context
Contextconfigure service vprn service-name ospf number rib-priority
Treerib-priority
Introduced25.3.R2

Platforms

7705 SAR Gen 2

router-id router-id
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisUnique router ID for the OSPF instance
Contextconfigure service vprn service-name ospf number router-id router-id
Treerouter-id
Introduced25.3.R2

Platforms

7705 SAR Gen 2

rtr-adv-lsa-limit
Synopsis Enable the rtr-adv-lsa-limit context
Contextconfigure service vprn service-name ospf number rtr-adv-lsa-limit
Treertr-adv-lsa-limit
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overload-timeout (number | keyword)
Synopsis Maximum time in overload after LSA limit is reached
Contextconfigure service vprn service-name ospf number rtr-adv-lsa-limit overload-timeout (number | keyword)
Treeoverload-timeout
Range1 to 1800
Unitsseconds
Options forever
Defaultforever
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

super-backbone boolean
Synopsis Enable super backbone functionality
Context configure service vprn service-name ospf number super-backbone boolean
Treesuper-backbone
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

suppress-dn-bit boolean
Synopsis Suppress the DN bit setting for OSPF LSA packets
Contextconfigure service vprn service-name ospf number suppress-dn-bit boolean
Treesuppress-dn-bit
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

timers
Synopsis Enter the timers context
Context configure service vprn service-name ospf number timers
Treetimers
Introduced25.3.R2

Platforms

7705 SAR Gen 2

lsa-accumulate number
Synopsis Delay to gather LSAs before advertising to neighbors
Contextconfigure service vprn service-name ospf number timers lsa-accumulate number
Treelsa-accumulate
Range0 to 1000
Unitsmilliseconds
Default 1000
Introduced25.3.R2

Platforms

7705 SAR Gen 2

lsa-arrival number
Synopsis Min delay between receipt of same LSAs from neighbors
Contextconfigure service vprn service-name ospf number timers lsa-arrival number
Treelsa-arrival
Range0 to 600000
Unitsmilliseconds
Default 1000
Introduced25.3.R2

Platforms

7705 SAR Gen 2

lsa-generate
Synopsis Enter the lsa-generate context
Contextconfigure service vprn service-name ospf number timers lsa-generate
Treelsa-generate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

spf-wait
Synopsis Enter the spf-wait context
Context configure service vprn service-name ospf number timers spf-wait
Treespf-wait
Introduced25.3.R2

Platforms

7705 SAR Gen 2

spf-max-wait number
Synopsis Max interval between two consecutive SPF calculations
Contextconfigure service vprn service-name ospf number timers spf-wait spf-max-wait number
Treespf-max-wait
Range10 to 120000
Unitsmilliseconds
Default10000
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

unicast-import boolean
Synopsis Submit routes into the unicast Route Table Manager
Contextconfigure service vprn service-name ospf number unicast-import boolean
Treeunicast-import
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

vpn-domain
Synopsis Enable the vpn-domain context
Context configure service vprn service-name ospf number vpn-domain
Treevpn-domain
Introduced25.3.R2

Platforms

7705 SAR Gen 2

id system-id
Synopsis OSPF VPN domain ID
Context configure service vprn service-name ospf number vpn-domain id system-id
Treeid

Description

This command specifies the OSPF VPN domain. This is exchanged using BGP in the Extended Community attribute associated with a prefix.

String length14
Default0000.0000.0000
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

type keyword
Synopsis VPN domain type
Context configure service vprn service-name ospf number vpn-domain type keyword
Treetype
Options0005, 0105, 0205, 8005

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

vpn-tag number
Synopsis OSPF VPN tag
Contextconfigure service vprn service-name ospf number vpn-tag number
Treevpn-tag
Max. range0 to 4294967295
Default0
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

ospf3 [ospf-instance] number
Synopsis Enter the ospf3 list instance
Context configure service vprn service-name ospf3 number
Treeospf3
Max. instances32
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ospf-instance] number
Synopsis Integrated OSPF instance
Context configure service vprn service-name ospf3 number
Treeospf3
Range0 to 31 | 64 to 95
MD-CLI default0

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the OSPF instance
Contextconfigure service vprn service-name ospf3 number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

area [area-id] ipv4-address
Synopsis Enter the area list instance
Context configure service vprn service-name ospf3 number area ipv4-address
Treearea
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[area-id] ipv4-address
Synopsis Area-ID attribute
Context configure service vprn service-name ospf3 number area ipv4-address
Treearea

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

area-range [ip-prefix-mask] (ipv4-prefix | ipv6-prefix)
Synopsis Enter the area-range list instance
Contextconfigure service vprn service-name ospf3 number area ipv4-address area-range (ipv4-prefix | ipv6-prefix)
Treearea-range
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ip-prefix-mask] (ipv4-prefix | ipv6-prefix)
Synopsis Address ranges to create on an ABR for route summarization or suppression
Contextconfigure service vprn service-name ospf3 number area ipv4-address area-range (ipv4-prefix | ipv6-prefix)
Treearea-range

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

advertise boolean
Synopsis Advertise summarized range of addresses to other areas
Contextconfigure service vprn service-name ospf3 number area ipv4-address area-range (ipv4-prefix | ipv6-prefix) advertise boolean
Treeadvertise
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface [interface-name] interface-name
Synopsis Enter the interface list instance
Contextconfigure service vprn service-name ospf3 number area ipv4-address interface interface-name
Treeinterface
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[interface-name] interface-name
Synopsis IP interface name
Context configure service vprn service-name ospf3 number area ipv4-address interface interface-name
Treeinterface
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the OSPF interface
Contextconfigure service vprn service-name ospf3 number area ipv4-address interface interface-name admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

authentication
Synopsis Enable the authentication context
Contextconfigure service vprn service-name ospf3 number area ipv4-address interface interface-name authentication
Treeauthentication
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd-liveness
Synopsis Enable the bfd-liveness context
Contextconfigure service vprn service-name ospf3 number area ipv4-address interface interface-name bfd-liveness
Treebfd-liveness
Introduced25.3.R2

Platforms

7705 SAR Gen 2

strict boolean
Synopsis Enable BFD strict mode
Context configure service vprn service-name ospf3 number area ipv4-address interface interface-name bfd-liveness strict boolean
Treestrict

Description

When configured to true, the system uses BFD strict-mode. BFD strict-mode mandates that an active BFD session must exist between the OSPF neighbors before establishing a full adjacency. When configured to true, the router uses Link-Local Signaling (LLS) with the B-flag set to instruct the OSPF neighbors that BFD must be enabled on the link. BFD strict-mode requires both sides to have the B-flag set.

During OSPFv3 BFD strict-mode operations, the router advertises the local interface IPv4 address TLV using LLS, but the SR OS router continues to use IPv6-based BFD sessions for both the IPv4 and IPv6 address families.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

strict-mode-holddown number
Synopsis Adjacency up time delay after BFD session establishment
Contextconfigure service vprn service-name ospf3 number area ipv4-address interface interface-name bfd-liveness strict-mode-holddown number
Treestrict-mode-holddown

Description

This command configures a delay timer before bringing up the OSPF adjacency after the BFD session establishment. Holddown helps mitigate potential routing churn when BFD sessions are unstable. The holddown timer is reset when a BFD session operationally toggles.

Range1 to 600
Unitsseconds
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

dead-interval number
Synopsis OSPF wait time for Hellos before neighbor declared down
Contextconfigure service vprn service-name ospf3 number area ipv4-address interface interface-name dead-interval number
Treedead-interval
Range2 to 65535
Unitsseconds
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

hello-interval number
Synopsis Time between OSPF Hellos of this interface
Contextconfigure service vprn service-name ospf3 number area ipv4-address interface interface-name hello-interval number
Treehello-interval
Range1 to 65535
Unitsseconds
Default 10
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface-type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisInterface type
Contextconfigure service vprn service-name ospf3 number area ipv4-address interface interface-name interface-type keyword
Treeinterface-type

Description

This command specifies the interface type.

broadcast - Broadcast network

To significantly improve adjacency forming and network convergence, configure a network as point-to-point if only two routers are connected, even if the network is a broadcast media such as Ethernet.

non-broadcast - Non-broadcast network

point-to-point - Point-to-point link

Set the interface type of an Ethernet link to point-to-point to avoid having to carry the broadcast adjacency maintenance overhead if the Ethernet link provided is used as a point-to-point.

p2mp-nbma - Point-to-multipoint on a link without broadcast or multicast support

No designated router or backup designated router is elected on this type of interface and all OSPF neighbors connect through individual point-to-point links. Only VPRN and IES services interfaces support this interface type.

secondary - Multiple secondary adjacencies allowed

A secondary interface allows multiple secondary adjacencies, in addition to the primary adjacency, to be established over a single IP interface. This interface type can also be applied to the system interface and to loopback interfaces to allow them to participate in multiple areas, although no adjacencies are formed over these types of interfaces.

Optionsbroadcast, non-broadcast, point-to-point, secondary, p2mp-nbma
Introduced25.3.R2

Platforms

7705 SAR Gen 2

loopfree-alternate
Synopsis Enter the loopfree-alternate context
Contextconfigure service vprn service-name ospf3 number area ipv4-address interface interface-name loopfree-alternate
Treeloopfree-alternate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

policy-map
Synopsis Enable the policy-map context
Context configure service vprn service-name ospf3 number area ipv4-address interface interface-name loopfree-alternate policy-map
Treepolicy-map
Introduced25.3.R2

Platforms

7705 SAR Gen 2

lsa-filter-out keyword
Synopsis LSA flooding reduction
Context configure service vprn service-name ospf3 number area ipv4-address interface interface-name lsa-filter-out keyword
Treelsa-filter-out
Optionsnone, all, except-own-rtrlsa, except-own-rtrlsa-and-defaults
Defaultnone
Introduced25.3.R2

Platforms

7705 SAR Gen 2

metric number
Synopsis Route cost metric for the interface
Context configure service vprn service-name ospf3 number area ipv4-address interface interface-name metric number
Treemetric
Range1 to 65535
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mtu number
Synopsis MTU for the OSPF to use on the interface
Contextconfigure service vprn service-name ospf3 number area ipv4-address interface interface-name mtu number
Treemtu
Range512 to 9786
Introduced25.3.R2

Platforms

7705 SAR Gen 2

neighbor [address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Add a list entry for neighbor
Context configure service vprn service-name ospf3 number area ipv4-address interface interface-name neighbor (ipv4-address-no-zone | ipv6-address-no-zone)
Treeneighbor
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IPv6 link local address of the OSPFv3 neighbor
Contextconfigure service vprn service-name ospf3 number area ipv4-address interface interface-name neighbor (ipv4-address-no-zone | ipv6-address-no-zone)
Treeneighbor

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

passive boolean
Synopsis Advertise passive interfaces as OSPF interfaces
Contextconfigure service vprn service-name ospf3 number area ipv4-address interface interface-name passive boolean
Treepassive
Introduced25.3.R2

Platforms

7705 SAR Gen 2

poll-interval number
Synopsis Interval for Hellos to non-adjacent OSPF NBMA neighbor
Contextconfigure service vprn service-name ospf3 number area ipv4-address interface interface-name poll-interval number
Treepoll-interval
Max. range0 to 4294967295
Unitsseconds
Default120
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

priority number
Synopsis Interface priority in the DR election on the subnet
Contextconfigure service vprn service-name ospf3 number area ipv4-address interface interface-name priority number
Treepriority
Range0 to 255
Default1
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

nssa
Synopsis Enable the nssa context
Context configure service vprn service-name ospf3 number area ipv4-address nssa
Treenssa
Introduced25.3.R2

Platforms

7705 SAR Gen 2

area-range [ip-prefix-mask] (ipv4-prefix | ipv6-prefix)
Synopsis Enter the area-range list instance
Contextconfigure service vprn service-name ospf3 number area ipv4-address nssa area-range (ipv4-prefix | ipv6-prefix)
Treearea-range
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ip-prefix-mask] (ipv4-prefix | ipv6-prefix)
Synopsis Address ranges to create on an ABR for route summarization or suppression
Contextconfigure service vprn service-name ospf3 number area ipv4-address nssa area-range (ipv4-prefix | ipv6-prefix)
Treearea-range

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

advertise boolean
Synopsis Advertise summarized range of addresses to other areas
Contextconfigure service vprn service-name ospf3 number area ipv4-address nssa area-range (ipv4-prefix | ipv6-prefix) advertise boolean
Treeadvertise
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

originate-default-route
Synopsis Enable the originate-default-route context
Contextconfigure service vprn service-name ospf3 number area ipv4-address nssa originate-default-route
Treeoriginate-default-route
Introduced25.3.R2

Platforms

7705 SAR Gen 2

summaries boolean
Synopsis Send summary (Type 3) LSAs into the NSSA on an ABR
Contextconfigure service vprn service-name ospf3 number area ipv4-address nssa summaries boolean
Treesummaries
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

stub
Synopsis Enable the stub context
Context configure service vprn service-name ospf3 number area ipv4-address stub
Treestub
Introduced25.3.R2

Platforms

7705 SAR Gen 2

default-metric number
Synopsis Metric used by ABR for default route into the stub area
Contextconfigure service vprn service-name ospf3 number area ipv4-address stub default-metric number
Treedefault-metric
Range1 to 16777214
Default1
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

summaries boolean
Synopsis Send summary (Type 3) LSAs into the stub area on an ABR
Contextconfigure service vprn service-name ospf3 number area ipv4-address stub summaries boolean
Treesummaries
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

virtual-link [router-id] ipv4-address transit-area reference
Synopsis Enter the virtual-link list instance
Contextconfigure service vprn service-name ospf3 number area ipv4-address virtual-link ipv4-address transit-area reference
Treevirtual-link
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[router-id] ipv4-address
Synopsis Router identity of the virtual link neighbor
Contextconfigure service vprn service-name ospf3 number area ipv4-address virtual-link ipv4-address transit-area reference
Treevirtual-link

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

transit-area reference
Synopsis Transit area that links backbone area to area without physical connection with the backbone
Contextconfigure service vprn service-name ospf3 number area ipv4-address virtual-link ipv4-address transit-area reference
Treevirtual-link

Reference

configure service vprn service-name ospf3 number area ipv4-address

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

authentication
Synopsis Enable the authentication context
Contextconfigure service vprn service-name ospf3 number area ipv4-address virtual-link ipv4-address transit-area reference authentication
Treeauthentication
Introduced25.3.R2

Platforms

7705 SAR Gen 2

export-limit
Synopsis Enable the export-limit context
Contextconfigure service vprn service-name ospf3 number export-limit
Treeexport-limit
Introduced25.3.R2

Platforms

7705 SAR Gen 2

number number
Synopsis Maximum routes or prefixes exported from route table
Contextconfigure service vprn service-name ospf3 number export-limit number number
Treenumber
Range1 to 4294967295

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

export-policy reference
Synopsis Export policies that determine exported routes
Contextconfigure service vprn service-name ospf3 number export-policy reference
Treeexport-policy

Description

This command configures export routing policies for the routes exported from the routing table to IS-IS.

If the export policy is undefined, the system does not export non IS-IS routes from the routing table manager to IS-IS.

If multiple policy names are specified, the policies are evaluated in the order they are specified. The first policy that matches is applied.

If the aggregate command is also configured in the configure router context, the aggregation is applied before the export policy is applied.

Routing policies are created in the configure router policy-options context.

Reference

configure policy-options policy-statement named-item-64

Max. instances5

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

external-db-overflow
Synopsis Enable the external-db-overflow context
Contextconfigure service vprn service-name ospf3 number external-db-overflow
Treeexternal-db-overflow
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interval number
Synopsis Time during which the router operates in overload
Contextconfigure service vprn service-name ospf3 number external-db-overflow interval number
Treeinterval
Range0 to 2147483647
Unitsseconds
Default 0
Introduced25.3.R2

Platforms

7705 SAR Gen 2

limit number
Synopsis Number of external LSA at which overload is triggered
Contextconfigure service vprn service-name ospf3 number external-db-overflow limit number
Treelimit
Range0 to 2147483647
Default0
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

graceful-restart
Synopsis Enable the graceful-restart context
Contextconfigure service vprn service-name ospf3 number graceful-restart
Treegraceful-restart
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ignore-dn-bit boolean
Synopsis Ignore the DN bit for OSPF LSA packets for the instance
Contextconfigure service vprn service-name ospf3 number ignore-dn-bit boolean
Treeignore-dn-bit
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

loopfree-alternate
Synopsis Enable the loopfree-alternate context
Contextconfigure service vprn service-name ospf3 number loopfree-alternate
Treeloopfree-alternate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

exclude
Synopsis Enter the exclude context
Context configure service vprn service-name ospf3 number loopfree-alternate exclude
Treeexclude
Introduced25.3.R2

Platforms

7705 SAR Gen 2

prefix-policy reference
Synopsis Policy to exclude prefixes from LFA SPF calculation
Contextconfigure service vprn service-name ospf3 number loopfree-alternate exclude prefix-policy reference
Treeprefix-policy

Description

This command specifies the name of the policy for the prefixes to exclude from the LFA SPF calculation.

An excluded prefix is not included in LFA calculation regardless of its priority. The prefix tag is, however, used in the main SPF.

Reference

configure policy-options policy-statement named-item-64

Max. instances5

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

multicast-import boolean
Synopsis Submit routes into the multicast Route Table Manager
Contextconfigure service vprn service-name ospf3 number multicast-import boolean
Treemulticast-import
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overload boolean
Synopsis Change local router state to appear overloaded
Contextconfigure service vprn service-name ospf3 number overload boolean
Treeoverload
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overload-on-boot
Synopsis Enable the overload-on-boot context
Contextconfigure service vprn service-name ospf3 number overload-on-boot
Treeoverload-on-boot
Introduced25.3.R2

Platforms

7705 SAR Gen 2

timeout number
Synopsis Time during which the router operates in overload state before reestablishing normal operations
Contextconfigure service vprn service-name ospf3 number overload-on-boot timeout number
Treetimeout
Range60 to 1800
Unitsseconds
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

preference number
Synopsis Preference for OSPF internal routes
Context configure service vprn service-name ospf3 number preference number
Treepreference
Range1 to 255
Default10
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

reference-bandwidth number
Synopsis Bandwidth to reference default costing of interfaces
Contextconfigure service vprn service-name ospf3 number reference-bandwidth number
Treereference-bandwidth
Range1 to 18446744073709551615
Unitskilobps
Default100000000
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

rib-priority
Synopsis Enter the rib-priority context
Contextconfigure service vprn service-name ospf3 number rib-priority
Treerib-priority
Introduced25.3.R2

Platforms

7705 SAR Gen 2

router-id router-id
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisUnique router ID for the OSPF instance
Contextconfigure service vprn service-name ospf3 number router-id router-id
Treerouter-id
Introduced25.3.R2

Platforms

7705 SAR Gen 2

rtr-adv-lsa-limit
Synopsis Enable the rtr-adv-lsa-limit context
Contextconfigure service vprn service-name ospf3 number rtr-adv-lsa-limit
Treertr-adv-lsa-limit
Introduced25.3.R2

Platforms

7705 SAR Gen 2

overload-timeout (number | keyword)
Synopsis Maximum time in overload after LSA limit is reached
Contextconfigure service vprn service-name ospf3 number rtr-adv-lsa-limit overload-timeout (number | keyword)
Treeoverload-timeout
Range1 to 1800
Unitsseconds
Options forever
Defaultforever
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

suppress-dn-bit boolean
Synopsis Suppress the DN bit setting for OSPF LSA packets
Contextconfigure service vprn service-name ospf3 number suppress-dn-bit boolean
Treesuppress-dn-bit
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

timers
Synopsis Enter the timers context
Context configure service vprn service-name ospf3 number timers
Treetimers
Introduced25.3.R2

Platforms

7705 SAR Gen 2

lsa-accumulate number
Synopsis Delay to gather LSAs before advertising to neighbors
Contextconfigure service vprn service-name ospf3 number timers lsa-accumulate number
Treelsa-accumulate
Range0 to 1000
Unitsmilliseconds
Default 1000
Introduced25.3.R2

Platforms

7705 SAR Gen 2

lsa-arrival number
Synopsis Min delay between receipt of same LSAs from neighbors
Contextconfigure service vprn service-name ospf3 number timers lsa-arrival number
Treelsa-arrival
Range0 to 600000
Unitsmilliseconds
Default 1000
Introduced25.3.R2

Platforms

7705 SAR Gen 2

lsa-generate
Synopsis Enter the lsa-generate context
Contextconfigure service vprn service-name ospf3 number timers lsa-generate
Treelsa-generate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

spf-wait
Synopsis Enter the spf-wait context
Context configure service vprn service-name ospf3 number timers spf-wait
Treespf-wait
Introduced25.3.R2

Platforms

7705 SAR Gen 2

spf-max-wait number
Synopsis Max interval between two consecutive SPF calculations
Contextconfigure service vprn service-name ospf3 number timers spf-wait spf-max-wait number
Treespf-max-wait
Range10 to 120000
Unitsmilliseconds
Default10000
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

unicast-import boolean
Synopsis Submit routes into the unicast Route Table Manager
Contextconfigure service vprn service-name ospf3 number unicast-import boolean
Treeunicast-import
Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

pim
Synopsis Enable the pim context
Context configure service vprn service-name pim
Treepim
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of PIM
Context configure service vprn service-name pim admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

apply-to keyword
Synopsis IES and non-IES interfaces to create in PIM
Contextconfigure service vprn service-name pim apply-to keyword
Treeapply-to
Optionsall, none
Default none
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bgp-nh-override boolean
Synopsis Disable VRF import EC support for next-hop resolution
Contextconfigure service vprn service-name pim bgp-nh-override boolean
Treebgp-nh-override

Description

When configured to true, the RPF check is performed using IPv4 VPN AF next-hop instead of IPv4 AF VRF import extended community (EC).

When configured to false, the RPF check is performed using IPv4 AF VRF import EC.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

import
Synopsis Enter the import context
Context configure service vprn service-name pim import
Treeimport
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface [interface-name] interface-name
Synopsis Enter the interface list instance
Contextconfigure service vprn service-name pim interface interface-name
Treeinterface
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[interface-name] interface-name
Synopsis Interface name
Contextconfigure service vprn service-name pim interface interface-name
Treeinterface
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the PIM interface
Contextconfigure service vprn service-name pim interface interface-name admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

assert-period number
Synopsis Time for periodic refreshes of PIM Assert messages on an interface
Contextconfigure service vprn service-name pim interface interface-name assert-period number
Treeassert-period
Range1 to 300
Default60
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

bfd-liveness
Synopsis Enter the bfd-liveness context
Contextconfigure service vprn service-name pim interface interface-name bfd-liveness
Treebfd-liveness
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4 boolean
Synopsis Use Bidirectional Forwarding Detection for IPv4 on PIM interface
Contextconfigure service vprn service-name pim interface interface-name bfd-liveness ipv4 boolean
Treeipv4
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6 boolean
Synopsis Use Bidirectional Forwarding Detection for IPv6 on PIM interface
Contextconfigure service vprn service-name pim interface interface-name bfd-liveness ipv6 boolean
Treeipv6
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hello-interval number
Synopsis Frequency at which PIM Hello messages are sent over this interface
Contextconfigure service vprn service-name pim interface interface-name hello-interval number
Treehello-interval
Range0 to 255
Default30
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

instant-prune-echo boolean
Synopsis Allow PIM to send an instant prune echo when router starts the prune pending timer for PIM interface
Contextconfigure service vprn service-name pim interface interface-name instant-prune-echo boolean
Treeinstant-prune-echo
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4
Synopsis Enter the ipv4 context
Context configure service vprn service-name pim interface interface-name ipv4
Treeipv4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

monitor-oper-group
Synopsis Enter the monitor-oper-group context
Contextconfigure service vprn service-name pim interface interface-name ipv4 monitor-oper-group
Treemonitor-oper-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6
Synopsis Enter the ipv6 context
Context configure service vprn service-name pim interface interface-name ipv6
Treeipv6
Introduced25.3.R2

Platforms

7705 SAR Gen 2

monitor-oper-group
Synopsis Enter the monitor-oper-group context
Contextconfigure service vprn service-name pim interface interface-name ipv6 monitor-oper-group
Treemonitor-oper-group
Introduced25.3.R2

Platforms

7705 SAR Gen 2

max-groups number
Synopsis Maximum number of groups for the interface
Contextconfigure service vprn service-name pim interface interface-name max-groups number
Treemax-groups
Range0 | 1 to 16000
Default0
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

priority number
Synopsis DR election priority for this interface
Contextconfigure service vprn service-name pim interface interface-name priority number
Treepriority
Range1 to 4294967295
Default1
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

ipv4
Synopsis Enter the ipv4 context
Context configure service vprn service-name pim ipv4
Treeipv4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of PIM operation for IPv4
Contextconfigure service vprn service-name pim ipv4 admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

rpf-table keyword
Synopsis Route table for RPF lookup
Context configure service vprn service-name pim ipv4 rpf-table keyword
Treerpf-table
Optionsrtable-m, rtable-u, both
Defaultrtable-u
Introduced25.3.R2

Platforms

7705 SAR Gen 2

source-address
Synopsis Enter the source-address context
Contextconfigure service vprn service-name pim ipv4 source-address
Treesource-address

Description

Commands in this context configure the source IP address for PIM messages.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

register-message ipv4-unicast-address
Synopsis Source IPv4 address for PIM register messages
Contextconfigure service vprn service-name pim ipv4 source-address register-message ipv4-unicast-address
Treeregister-message

Description

This command configures the source IPv4 address for register messages in this PIM instance. The IP address can be set to any unicast address, regardless of whether it resides on the node. Ensure that the specified IP address is configured on the router as a loopback or interface IP address.

When unconfigured, the source IP address for register messages is selected by choosing the smallest IP address from available interfaces on the node.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6
Synopsis Enter the ipv6 context
Context configure service vprn service-name pim ipv6
Treeipv6
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of PIM operation for IPv6
Contextconfigure service vprn service-name pim ipv6 admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

rpf-table keyword
Synopsis Route table for RPF lookup
Context configure service vprn service-name pim ipv6 rpf-table keyword
Treerpf-table
Optionsrtable-m, rtable-u, both
Defaultrtable-u
Introduced25.3.R2

Platforms

7705 SAR Gen 2

source-address
Synopsis Enter the source-address context
Contextconfigure service vprn service-name pim ipv6 source-address
Treesource-address

Description

Commands in this context configure the source IP address for PIM messages.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

register-message ipv6-unicast-address
Synopsis Source IPv6 address for PIM register messages
Contextconfigure service vprn service-name pim ipv6 source-address register-message ipv6-unicast-address
Treeregister-message

Description

This command configures the source IPv6 address for register messages in this PIM instance. The IP address can be set to any unicast address, regardless of whether it resides on the node. Ensure that the specified IP address is configured on the router as a loopback or interface IP address.

When unconfigured, the source IP address for register messages is selected by choosing the smallest IP address from available interfaces on the node.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

mtu-over-head number
Synopsis MVPN tunnel MTU size reduction to allow for BIER header
Contextconfigure service vprn service-name pim mtu-over-head number
Treemtu-over-head

Description

This command subtracts the specified value from the MVPN tunnel MTU to allow a BIER header to be added without exceeding the network MTU.

Range0 | 44 | 76 | 140 | 268 | 536
Default0
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

rp
Synopsis Enter the rp context
Context configure service vprn service-name pim rp
Treerp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bootstrap
Synopsis Enter the bootstrap context
Context configure service vprn service-name pim rp bootstrap
Treebootstrap
Introduced25.3.R2

Platforms

7705 SAR Gen 2

export reference
Synopsis Export policy to control the flow of bootstrap messages
Contextconfigure service vprn service-name pim rp bootstrap export reference
Treeexport

Reference

configure policy-options policy-statement named-item-64

Max. instances5

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

import reference
Synopsis Import policy to control the flow of bootstrap messages
Contextconfigure service vprn service-name pim rp bootstrap import reference
Treeimport

Reference

configure policy-options policy-statement named-item-64

Max. instances5

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4
Synopsis Enter the ipv4 context
Context configure service vprn service-name pim rp ipv4
Treeipv4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

anycast [ipv4-address] ipv4-unicast-address rp-set-peer ipv4-unicast-address
Synopsis Add a list entry for anycast
Context configure service vprn service-name pim rp ipv4 anycast ipv4-unicast-address rp-set-peer ipv4-unicast-address
Treeanycast
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ipv4-address] ipv4-unicast-address
Synopsis Loopback IP address shared by routes in RP set
Contextconfigure service vprn service-name pim rp ipv4 anycast ipv4-unicast-address rp-set-peer ipv4-unicast-address
Treeanycast

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rp-set-peer ipv4-unicast-address
Synopsis Peer in the anycast RP-set
Context configure service vprn service-name pim rp ipv4 anycast ipv4-unicast-address rp-set-peer ipv4-unicast-address
Treeanycast

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

auto-rp-discovery boolean
Synopsis Enable auto-RP discovery mode and auto-RP listener
Contextconfigure service vprn service-name pim rp ipv4 auto-rp-discovery boolean
Treeauto-rp-discovery

Description

When configured to true, the system enables the auto-RP protocol in discovery mode and the auto-RP listener functionality.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bsr-candidate
Synopsis Enter the bsr-candidate context
Contextconfigure service vprn service-name pim rp ipv4 bsr-candidate
Treebsr-candidate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address ipv4-unicast-address
Synopsis Candidate BSR IP address for Bootstrap Router election
Contextconfigure service vprn service-name pim rp ipv4 bsr-candidate address ipv4-unicast-address
Treeaddress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

candidate boolean
Synopsis Enable auto-RP to advertise candidate RP information
Contextconfigure service vprn service-name pim rp ipv4 candidate boolean
Treecandidate

Description

When configured to true, the auto-RP is enabled to advertise the candidate RP information. The auto-RP candidate RP announces the candidate RP messages on the 224.0.1.39 multicast address. This functionality is in addition to the listener functionality enabled by the auto RP discovery.

When configured to false, the candidate RP information is not specified.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

mapping-agent boolean
Synopsis Enable the mapping agent on the node
Context configure service vprn service-name pim rp ipv4 mapping-agent boolean
Treemapping-agent

Description

When configured to true, the mapping agent is enabled on the node. The auto-RP MA observes the auto-rp-announcement messages, selects the RP and generates the RP discovery 224.0.1.40 messages. This functionality is in addition to the auto-RP discovery functionality.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

rp-candidate
Synopsis Enter the rp-candidate context
Contextconfigure service vprn service-name pim rp ipv4 rp-candidate
Treerp-candidate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address ipv4-unicast-address
Synopsis Local RP address
Context configure service vprn service-name pim rp ipv4 rp-candidate address ipv4-unicast-address
Treeaddress

Description

This command specifies the local RP address that is sent in the RP candidate advertisements to the Bootstrap Router.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

group-range [ipv4-prefix] ipv4-multicast-prefix
Synopsis Add a list entry for group-range
Contextconfigure service vprn service-name pim rp ipv4 rp-candidate group-range ipv4-multicast-prefix
Treegroup-range
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ipv4-prefix] ipv4-multicast-prefix
Synopsis IPv4 address and prefix length
Context configure service vprn service-name pim rp ipv4 rp-candidate group-range ipv4-multicast-prefix
Treegroup-range

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

holdtime number
Synopsis Time during which the neighboring router considers this router to be up
Contextconfigure service vprn service-name pim rp ipv4 rp-candidate holdtime number
Treeholdtime
Range5 to 255
Unitsseconds
Default 150
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static
Synopsis Enter the static context
Context configure service vprn service-name pim rp ipv4 static
Treestatic
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address [ipv4-address] ipv4-unicast-address
Synopsis Enter the address list instance
Contextconfigure service vprn service-name pim rp ipv4 static address ipv4-unicast-address
Treeaddress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ipv4-address] ipv4-unicast-address
Synopsis IPv4 address for the static RP
Context configure service vprn service-name pim rp ipv4 static address ipv4-unicast-address
Treeaddress

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

group-prefix [ipv4-prefix] ipv4-multicast-prefix
Synopsis Add a list entry for group-prefix
Contextconfigure service vprn service-name pim rp ipv4 static address ipv4-unicast-address group-prefix ipv4-multicast-prefix
Treegroup-prefix
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ipv4-prefix] ipv4-multicast-prefix
Synopsis IPv4 address and prefix length
Context configure service vprn service-name pim rp ipv4 static address ipv4-unicast-address group-prefix ipv4-multicast-prefix
Treegroup-prefix

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

override boolean
Synopsis Change the precedence for static RP over dynamically learnt RP
Contextconfigure service vprn service-name pim rp ipv4 static address ipv4-unicast-address override boolean
Treeoverride
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6
Synopsis Enter the ipv6 context
Context configure service vprn service-name pim rp ipv6
Treeipv6
Introduced25.3.R2

Platforms

7705 SAR Gen 2

anycast [ipv6-address] ipv6-unicast-address rp-set-peer ipv6-unicast-address
Synopsis Add a list entry for anycast
Context configure service vprn service-name pim rp ipv6 anycast ipv6-unicast-address rp-set-peer ipv6-unicast-address
Treeanycast
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ipv6-address] ipv6-unicast-address
Synopsis Loopback IP address shared by routes in RP set
Contextconfigure service vprn service-name pim rp ipv6 anycast ipv6-unicast-address rp-set-peer ipv6-unicast-address
Treeanycast

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rp-set-peer ipv6-unicast-address
Synopsis Peer in the anycast RP set
Context configure service vprn service-name pim rp ipv6 anycast ipv6-unicast-address rp-set-peer ipv6-unicast-address
Treeanycast

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

bsr-candidate
Synopsis Enter the bsr-candidate context
Contextconfigure service vprn service-name pim rp ipv6 bsr-candidate
Treebsr-candidate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address ipv6-unicast-address
Synopsis Candidate BSR IP address for Bootstrap Router election
Contextconfigure service vprn service-name pim rp ipv6 bsr-candidate address ipv6-unicast-address
Treeaddress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

embedded-rp
Synopsis Enable the embedded-rp context
Contextconfigure service vprn service-name pim rp ipv6 embedded-rp
Treeembedded-rp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

group-range [ipv6-prefix] ipv6-multicast-prefix
Synopsis Add a list entry for group-range
Contextconfigure service vprn service-name pim rp ipv6 embedded-rp group-range ipv6-multicast-prefix
Treegroup-range
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ipv6-prefix] ipv6-multicast-prefix
Synopsis IPv6 address and prefix length
Context configure service vprn service-name pim rp ipv6 embedded-rp group-range ipv6-multicast-prefix
Treegroup-range

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rp-candidate
Synopsis Enter the rp-candidate context
Contextconfigure service vprn service-name pim rp ipv6 rp-candidate
Treerp-candidate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

group-range [ipv6-prefix] ipv6-multicast-prefix
Synopsis Add a list entry for group-range
Contextconfigure service vprn service-name pim rp ipv6 rp-candidate group-range ipv6-multicast-prefix
Treegroup-range
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ipv6-prefix] ipv6-multicast-prefix
Synopsis IPv6 address and prefix length
Context configure service vprn service-name pim rp ipv6 rp-candidate group-range ipv6-multicast-prefix
Treegroup-range

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

holdtime number
Synopsis Time during which the neighboring router considers this router to be up
Contextconfigure service vprn service-name pim rp ipv6 rp-candidate holdtime number
Treeholdtime
Range5 to 255
Unitsseconds
Default 150
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static
Synopsis Enter the static context
Context configure service vprn service-name pim rp ipv6 static
Treestatic
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address [ipv6-address] ipv6-unicast-address
Synopsis Enter the address list instance
Contextconfigure service vprn service-name pim rp ipv6 static address ipv6-unicast-address
Treeaddress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ipv6-address] ipv6-unicast-address
Synopsis Static IP address of the RP
Context configure service vprn service-name pim rp ipv6 static address ipv6-unicast-address
Treeaddress

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

group-prefix [ipv6-prefix] ipv6-multicast-prefix
Synopsis Add a list entry for group-prefix
Contextconfigure service vprn service-name pim rp ipv6 static address ipv6-unicast-address group-prefix ipv6-multicast-prefix
Treegroup-prefix
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ipv6-prefix] ipv6-multicast-prefix
Synopsis IPv6 address and prefix length
Context configure service vprn service-name pim rp ipv6 static address ipv6-unicast-address group-prefix ipv6-multicast-prefix
Treegroup-prefix

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

override boolean
Synopsis Change the precedence for static RP over dynamically learnt RP
Contextconfigure service vprn service-name pim rp ipv6 static address ipv6-unicast-address override boolean
Treeoverride
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

spt-switchover [ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis Enter the spt-switchover list instance
Contextconfigure service vprn service-name pim spt-switchover (ipv4-prefix | ipv6-prefix)
Treespt-switchover
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis IP address and mask length
Context configure service vprn service-name pim spt-switchover (ipv4-prefix | ipv6-prefix)
Treespt-switchover

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

threshold (number | keyword)
Synopsis SPT switchover threshold
Context configure service vprn service-name pim spt-switchover (ipv4-prefix | ipv6-prefix) threshold (number | keyword)
Treethreshold
Range1 to 4294967294
Unitskilobps
Options infinity

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ssm-groups
Synopsis Enter the ssm-groups context
Context configure service vprn service-name pim ssm-groups
Treessm-groups
Introduced25.3.R2

Platforms

7705 SAR Gen 2

group-range [ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis Add a list entry for group-range
Contextconfigure service vprn service-name pim ssm-groups group-range (ipv4-prefix | ipv6-prefix)
Treegroup-range
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis IP address and mask length
Context configure service vprn service-name pim ssm-groups group-range (ipv4-prefix | ipv6-prefix)
Treegroup-range

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

radius
Synopsis Enter the radius context
Context configure service vprn service-name radius
Treeradius
Introduced25.3.R2

Platforms

7705 SAR Gen 2

server [name] named-item
Synopsis Enter the server list instance
Contextconfigure service vprn service-name radius server named-item
Treeserver
Max. instances64
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[name] named-item
Synopsis External RADIUS server name
Context configure service vprn service-name radius server named-item
Treeserver
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

accept-coa boolean
Synopsis Process Change of Authorization (CoA) messages
Contextconfigure service vprn service-name radius server named-item accept-coa boolean
Treeaccept-coa
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

acct-port number
Synopsis UDP port number of the RADIUS for accounting events
Contextconfigure service vprn service-name radius server named-item acct-port number
Treeacct-port
Range1 to 65535
Default1813
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the RADIUS server
Context configure service vprn service-name radius server named-item address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeaddress

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

auth-port number
Synopsis UDP port number of the RADIUS to be used as match criteria
Contextconfigure service vprn service-name radius server named-item auth-port number
Treeauth-port
Range1 to 65535
Default1812
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

secret encrypted-leaf
Synopsis Secret key associated with this RADIUS server
Contextconfigure service vprn service-name radius server named-item secret encrypted-leaf
Treesecret
String length1 to 115

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rip
Synopsis Enable the rip context
Context configure service vprn service-name rip
Treerip
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the RIP instance
Contextconfigure service vprn service-name rip admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

authentication-key encrypted-leaf
Synopsis Authentication password passed between RIP neighbors
Contextconfigure service vprn service-name rip authentication-key encrypted-leaf
Treeauthentication-key

Description

This command sets the authentication password to be passed between RIP neighbors. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes.

The authentication type and authentication key must match exactly for the RIP message to be considered authentic and processed.

When unconfigured, this command removes the authentication password from the configuration and disables authentication.

String length1 to 51
Introduced25.3.R2

Platforms

7705 SAR Gen 2

authentication-type keyword
Synopsis Authentication type used between RIP neighbors
Contextconfigure service vprn service-name rip authentication-type keyword
Treeauthentication-type

Description

This command sets the type of authentication to be used between RIP neighbors.

The authentication type and authentication key must match exactly for the RIP message to be considered authentic and processed.

When unconfigured, this command removes the authentication type from the configuration and effectively disables authentication.

Optionsnone, password, md5, md20
Default none
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd-liveness boolean
Synopsis Enable BFD to control the state of protocol adjacency
Contextconfigure service vprn service-name rip bfd-liveness boolean
Treebfd-liveness

Description

When configured to true, this command enables BFD to control the state of the associated protocol adjacency.

When configured to false, this command removes BFD from the associated protocol adjacency.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

check-zero boolean
Synopsis Enable checking of mandatory zero fields
Contextconfigure service vprn service-name rip check-zero boolean
Treecheck-zero

Description

When configured to true, this command enables checking of the mandatory zero fields in the RIPv1 and RIPv2 specifications and rejecting non-compliant RIP messages.

When configured to false, this command disables the check and allows the receipt of RIP messages even if the mandatory zero fields are non-zero.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service vprn service-name rip description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

export-limit
Synopsis Enable the export-limit context
Contextconfigure service vprn service-name rip export-limit
Treeexport-limit
Introduced25.3.R2

Platforms

7705 SAR Gen 2

number number
Synopsis Maximum routes or prefixes exported from route table
Contextconfigure service vprn service-name rip export-limit number number
Treenumber
Range1 to 4294967295

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

group [group-name] named-item
Synopsis Enter the group list instance
Context configure service vprn service-name rip group named-item
Treegroup
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[group-name] named-item
Synopsis RIP group name
Contextconfigure service vprn service-name rip group named-item
Treegroup
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of RIP neighbor interface group
Contextconfigure service vprn service-name rip group named-item admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

authentication-key encrypted-leaf
Synopsis Authentication password passed between RIP neighbors
Contextconfigure service vprn service-name rip group named-item authentication-key encrypted-leaf
Treeauthentication-key

Description

This command sets the authentication password to be passed between RIP neighbors. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes.

The authentication type and authentication key must match exactly for the RIP message to be considered authentic and processed.

When unconfigured, the authentication password is removed from the configuration and authentication is disabled.

String length1 to 51
Introduced25.3.R2

Platforms

7705 SAR Gen 2

authentication-type keyword
Synopsis Authentication type
Context configure service vprn service-name rip group named-item authentication-type keyword
Treeauthentication-type

Description

This command configures the type of authentication to be used.

The authentication type and authentication key must match exactly for the RIP message to be considered authentic and processed.

When unconfigured, this command removes the authentication type from the configuration and effectively disables authentication.

Optionsnone, password, md5, md20
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

bfd-liveness boolean
Synopsis Enable BFD to control the state of protocol adjacency
Contextconfigure service vprn service-name rip group named-item bfd-liveness boolean
Treebfd-liveness

Description

When configured to true, this command enables BFD to control the state of the associated protocol adjacency.

When configured to false, this command removes BFD from the associated protocol adjacency.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

check-zero boolean
Synopsis Enable checking of mandatory zero fields
Contextconfigure service vprn service-name rip group named-item check-zero boolean
Treecheck-zero

Description

When configured to true, this command enables checking of the mandatory zero fields in the RIPv1 and RIPv2 specifications and rejecting non-compliant RIP messages.

When configured to false, this command disables the check and allows the receipt of RIP messages even if the mandatory zero fields are non-zero.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service vprn service-name rip group named-item description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

export-policy reference
Synopsis Policies used to rule which routes are exported to RIP
Contextconfigure service vprn service-name rip group named-item export-policy reference
Treeexport-policy

Description

This command specifies the export route policies used to determine which routes are exported to RIP.

If multiple policy names are specified, the policies are evaluated in the order they are specified. The first policy that matches is applied.

Reference

configure policy-options policy-statement named-item-64

Max. instances5

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

import-policy reference
Synopsis Policies to decide routes accepted from RIP neighbors
Contextconfigure service vprn service-name rip group named-item import-policy reference
Treeimport-policy

Description

This command configures import route policies to determine which routes are accepted from RIP neighbors.

If multiple policy names are specified, the policies are evaluated in the order they are specified. The first policy that matches is applied.

Reference

configure policy-options policy-statement named-item-64

Max. instances5

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

message-size number
Synopsis Maximum number of routes per RIP update message
Contextconfigure service vprn service-name rip group named-item message-size number
Treemessage-size
Range25 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

metric-in number
Synopsis Metric added to routes received from a RIP neighbor
Contextconfigure service vprn service-name rip group named-item metric-in number
Treemetric-in
Range1 to 16
Introduced25.3.R2

Platforms

7705 SAR Gen 2

metric-out number
Synopsis Metric added to routes exported into RIP
Contextconfigure service vprn service-name rip group named-item metric-out number
Treemetric-out
Range1 to 16
Introduced25.3.R2

Platforms

7705 SAR Gen 2

neighbor [interface-name] interface-name
Synopsis Enter the neighbor list instance
Contextconfigure service vprn service-name rip group named-item neighbor interface-name
Treeneighbor
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[interface-name] interface-name
Synopsis IP interface name
Context configure service vprn service-name rip group named-item neighbor interface-name
Treeneighbor
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the RIP neighbor interface
Contextconfigure service vprn service-name rip group named-item neighbor interface-name admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

authentication-key encrypted-leaf
Synopsis Authentication password passed between RIP neighbors
Contextconfigure service vprn service-name rip group named-item neighbor interface-name authentication-key encrypted-leaf
Treeauthentication-key

Description

This command sets the authentication password to be passed between RIP neighbors. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes.

The authentication type and authentication key must match exactly for the RIP message to be considered authentic and processed.

When unconfigured, this command removes the authentication password from the configuration and disables authentication.

String length1 to 51
Introduced25.3.R2

Platforms

7705 SAR Gen 2

authentication-type keyword
Synopsis Authentication type
Context configure service vprn service-name rip group named-item neighbor interface-name authentication-type keyword
Treeauthentication-type

Description

This command configures the type of authentication to be used.

The authentication type and authentication key must match exactly for the RIP message to be considered authentic and processed.

When unconfigured, this command removes the authentication type from the configuration and effectively disables authentication.

Optionsnone, password, md5, md20
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

bfd-liveness boolean
Synopsis Enable BFD to control the state of protocol adjacency
Contextconfigure service vprn service-name rip group named-item neighbor interface-name bfd-liveness boolean
Treebfd-liveness

Description

When configured to true, this command enables BFD to control the state of the associated protocol adjacency.

When configured to false, this command removes BFD from the associated protocol adjacency.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

check-zero boolean
Synopsis Enable checking of mandatory zero fields
Contextconfigure service vprn service-name rip group named-item neighbor interface-name check-zero boolean
Treecheck-zero

Description

When configured to true, this command enables checking of the mandatory zero fields in the RIPv1 and RIPv2 specifications and rejecting non-compliant RIP messages.

When configured to false, this command disables the check and allows the receipt of RIP messages even if the mandatory zero fields are non-zero.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

export-policy reference
Synopsis Policies used to rule which routes are exported to RIP
Contextconfigure service vprn service-name rip group named-item neighbor interface-name export-policy reference
Treeexport-policy

Description

This command specifies the export route policies used to determine which routes are exported to RIP.

If multiple policy names are specified, the policies are evaluated in the order they are specified. The first policy that matches is applied.

Reference

configure policy-options policy-statement named-item-64

Max. instances5

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

import-policy reference
Synopsis Policies to decide routes accepted from RIP neighbors
Contextconfigure service vprn service-name rip group named-item neighbor interface-name import-policy reference
Treeimport-policy

Description

This command configures import route policies to determine which routes are accepted from RIP neighbors.

If multiple policy names are specified, the policies are evaluated in the order they are specified. The first policy that matches is applied.

Reference

configure policy-options policy-statement named-item-64

Max. instances5

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

message-size number
Synopsis Maximum number of routes per RIP update message
Contextconfigure service vprn service-name rip group named-item neighbor interface-name message-size number
Treemessage-size
Range25 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

metric-in number
Synopsis Metric added to routes received from a RIP neighbor
Contextconfigure service vprn service-name rip group named-item neighbor interface-name metric-in number
Treemetric-in
Range1 to 16
Introduced25.3.R2

Platforms

7705 SAR Gen 2

metric-out number
Synopsis Metric added to routes exported into RIP
Contextconfigure service vprn service-name rip group named-item neighbor interface-name metric-out number
Treemetric-out
Range1 to 16
Introduced25.3.R2

Platforms

7705 SAR Gen 2

receive keyword
Synopsis Accepted version on received packets
Context configure service vprn service-name rip group named-item neighbor interface-name receive keyword
Treereceive
Optionsversion-1, version-2, both, none
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

send keyword
Synopsis RIP version and method used to send RIP updates
Contextconfigure service vprn service-name rip group named-item neighbor interface-name send keyword
Treesend
Optionsnone, version-1, broadcast, multicast, unicast
Introduced25.3.R2

Platforms

7705 SAR Gen 2

split-horizon boolean
Synopsis Enable split horizon and poison reverse
Contextconfigure service vprn service-name rip group named-item neighbor interface-name split-horizon boolean
Treesplit-horizon

Description

When configured to true, this command enables the use of split horizon with poison reverse. Split-horizon with poison reverse means that routes learned from a neighbor through a given interface are advertised in updates out of the same interface but with a metric of 16 (infinity).

When configured to false. this command enables split horizon without poison reverse. This allows the routes to be re-advertised on interfaces other than the interface that learned the route, with the advertised metric equaling an increment of the metric-in value.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

timers
Synopsis Enable the timers context
Context configure service vprn service-name rip group named-item neighbor interface-name timers
Treetimers
Introduced25.3.R2

Platforms

7705 SAR Gen 2

flush number
Synopsis RIP flush timer
Context configure service vprn service-name rip group named-item neighbor interface-name timers flush number
Treeflush

Description

This command specifies the time a route is maintained in the RIP database after it has been declared invalid. When the timer expires, the route is flushed from the RIP database completely.

Range1 to 1200
Unitsseconds

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

timeout number
Synopsis RIP timeout timer
Context configure service vprn service-name rip group named-item neighbor interface-name timers timeout number
Treetimeout

Description

This command specifies the RIP timeout timer. If a route is not updated by the time the timer expires, the route is declared invalid, but the route is maintained in the RIP database.

Range1 to 1200
Unitsseconds

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

update number
Synopsis Timer that controls the frequency of updates
Contextconfigure service vprn service-name rip group named-item neighbor interface-name timers update number
Treeupdate
Range1 to 600
Unitsseconds

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

unicast-address [address] ipv4-unicast-address
Synopsis Add a list entry for unicast-address
Contextconfigure service vprn service-name rip group named-item neighbor interface-name unicast-address ipv4-unicast-address
Treeunicast-address
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[address] ipv4-unicast-address
Synopsis Unicast IPv6 address for the neighbor
Contextconfigure service vprn service-name rip group named-item neighbor interface-name unicast-address ipv4-unicast-address
Treeunicast-address

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

preference number
Synopsis Route preference
Context configure service vprn service-name rip group named-item preference number
Treepreference
Range1 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

receive keyword
Synopsis Accepted version on received packets
Context configure service vprn service-name rip group named-item receive keyword
Treereceive
Optionsversion-1, version-2, both, none
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

send keyword
Synopsis RIP version and method used to send RIP updates
Contextconfigure service vprn service-name rip group named-item send keyword
Treesend
Optionsnone, version-1, broadcast, multicast
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

split-horizon boolean
Synopsis Enable split horizon and poison reverse
Contextconfigure service vprn service-name rip group named-item split-horizon boolean
Treesplit-horizon

Description

When configured to true, this command enables the use of split horizon with poison reverse. Split-horizon with poison reverse means that routes learned from a neighbor through a given interface are advertised in updates out of the same interface but with a metric of 16 (infinity).

When configured to false. this command enables split horizon without poison reverse. This allows the routes to be re-advertised on interfaces other than the interface that learned the route, with the advertised metric equaling an increment of the metric-in value.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

timers
Synopsis Enable the timers context
Context configure service vprn service-name rip group named-item timers
Treetimers
Introduced25.3.R2

Platforms

7705 SAR Gen 2

flush number
Synopsis RIP flush timer
Context configure service vprn service-name rip group named-item timers flush number
Treeflush

Description

This command specifies the time a route is maintained in the RIP database after it has been declared invalid. When the timer expires, the route is flushed from the RIP database completely.

Range1 to 1200
Unitsseconds

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

timeout number
Synopsis RIP timeout timer
Context configure service vprn service-name rip group named-item timers timeout number
Treetimeout

Description

This command specifies the RIP timeout timer. If a route is not updated by the time the timer expires, the route is declared invalid, but the route is maintained in the RIP database.

Range1 to 1200
Unitsseconds

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

update number
Synopsis Timer that controls the frequency of updates
Contextconfigure service vprn service-name rip group named-item timers update number
Treeupdate
Range1 to 600
Unitsseconds

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

message-size number
Synopsis Maximum number of routes in the RIP message
Contextconfigure service vprn service-name rip message-size number
Treemessage-size
Range25 to 255
Default25
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

metric-in number
Synopsis Metric added to routes received from a RIP neighbor
Contextconfigure service vprn service-name rip metric-in number
Treemetric-in
Range1 to 16
Default1
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

metric-out number
Synopsis Metric added to routes exported into RIP
Contextconfigure service vprn service-name rip metric-out number
Treemetric-out
Range1 to 16
Default1
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

preference number
Synopsis Route preference
Context configure service vprn service-name rip preference number
Treepreference
Range1 to 255
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

propagate-metric boolean
Synopsis Enable the BGP MED used to configure the RIP metric
Contextconfigure service vprn service-name rip propagate-metric boolean
Treepropagate-metric

Description

When configured to true, this command enables the BGP MED to be used to configure the RIP metric at the BGP to RIP transition on egress routers.

When configured to false, this command sets the RIP metric to the optional value configured with the metric-out command plus one.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

receive keyword
Synopsis Accepted version on received packets
Context configure service vprn service-name rip receive keyword
Treereceive
Optionsversion-1, version-2, both, none
Default both
Introduced25.3.R2

Platforms

7705 SAR Gen 2

send keyword
Synopsis RIP version and method used to send RIP updates
Contextconfigure service vprn service-name rip send keyword
Treesend
Optionsnone, version-1, broadcast, multicast
Default broadcast
Introduced25.3.R2

Platforms

7705 SAR Gen 2

split-horizon boolean
Synopsis Enable split horizon and poison reverse
Contextconfigure service vprn service-name rip split-horizon boolean
Treesplit-horizon

Description

When configured to true, this command enables the use of split horizon with poison reverse. Split-horizon with poison reverse means that routes learned from a neighbor through a given interface are advertised in updates out of the same interface but with a metric of 16 (infinity).

When configured to false. this command enables split horizon without poison reverse. This allows the routes to be re-advertised on interfaces other than the interface that learned the route, with the advertised metric equaling an increment of the metric-in value.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

timers
Synopsis Enable the timers context
Context configure service vprn service-name rip timers
Treetimers
Introduced25.3.R2

Platforms

7705 SAR Gen 2

flush number
Synopsis RIP flush timer
Context configure service vprn service-name rip timers flush number
Treeflush

Description

This command specifies the time a route is maintained in the RIP database after it has been declared invalid. When the timer expires, the route is flushed from the RIP database completely.

Range1 to 1200
Unitsseconds

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

timeout number
Synopsis RIP timeout timer
Context configure service vprn service-name rip timers timeout number
Treetimeout

Description

This command specifies the RIP timeout timer. If a route is not updated by the time the timer expires, the route is declared invalid, but the route is maintained in the RIP database.

Range1 to 1200
Unitsseconds

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

update number
Synopsis Timer that controls the frequency of updates
Contextconfigure service vprn service-name rip timers update number
Treeupdate
Range1 to 600
Unitsseconds

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

ripng
Synopsis Enable the ripng context
Context configure service vprn service-name ripng
Treeripng
Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the RIPng instance
Contextconfigure service vprn service-name ripng admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd-liveness boolean
Synopsis Enable BFD to control the state of protocol adjacency
Contextconfigure service vprn service-name ripng bfd-liveness boolean
Treebfd-liveness

Description

When configured to true, this command enables BFD to control the state of the associated protocol adjacency.

When configured to false, this command removes BFD from the associated protocol adjacency.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

check-zero boolean
Synopsis Enable checking of mandatory zero fields
Contextconfigure service vprn service-name ripng check-zero boolean
Treecheck-zero

Description

When configured to true, this command enables checking of the mandatory zero fields in the RIPv1 and RIPv2 specifications and rejecting non-compliant RIP messages.

When configured to false, this command disables the check and allows the receipt of RIP messages even if the mandatory zero fields are non-zero.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service vprn service-name ripng description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

export-limit
Synopsis Enable the export-limit context
Contextconfigure service vprn service-name ripng export-limit
Treeexport-limit
Introduced25.3.R2

Platforms

7705 SAR Gen 2

number number
Synopsis Maximum routes or prefixes exported from route table
Contextconfigure service vprn service-name ripng export-limit number number
Treenumber
Range1 to 4294967295

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

group [group-name] named-item
Synopsis Enter the group list instance
Context configure service vprn service-name ripng group named-item
Treegroup
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[group-name] named-item
Synopsis RIP group name
Contextconfigure service vprn service-name ripng group named-item
Treegroup
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of RIPng neighbor interface group
Contextconfigure service vprn service-name ripng group named-item admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd-liveness boolean
Synopsis Enable BFD to control the state of protocol adjacency
Contextconfigure service vprn service-name ripng group named-item bfd-liveness boolean
Treebfd-liveness

Description

When configured to true, this command enables BFD to control the state of the associated protocol adjacency.

When configured to false, this command removes BFD from the associated protocol adjacency.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

check-zero boolean
Synopsis Enable checking of mandatory zero fields
Contextconfigure service vprn service-name ripng group named-item check-zero boolean
Treecheck-zero

Description

When configured to true, this command enables checking of the mandatory zero fields in the RIPv1 and RIPv2 specifications and rejecting non-compliant RIP messages.

When configured to false, this command disables the check and allows the receipt of RIP messages even if the mandatory zero fields are non-zero.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service vprn service-name ripng group named-item description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

export-policy reference
Synopsis Policies used to rule which routes are exported to RIP
Contextconfigure service vprn service-name ripng group named-item export-policy reference
Treeexport-policy

Description

This command specifies the export route policies used to determine which routes are exported to RIP.

If multiple policy names are specified, the policies are evaluated in the order they are specified. The first policy that matches is applied.

Reference

configure policy-options policy-statement named-item-64

Max. instances5

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

import-policy reference
Synopsis Policies to decide routes accepted from RIP neighbors
Contextconfigure service vprn service-name ripng group named-item import-policy reference
Treeimport-policy

Description

This command configures import route policies to determine which routes are accepted from RIP neighbors.

If multiple policy names are specified, the policies are evaluated in the order they are specified. The first policy that matches is applied.

Reference

configure policy-options policy-statement named-item-64

Max. instances5

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

message-size number
Synopsis Maximum number of routes in the message
Contextconfigure service vprn service-name ripng group named-item message-size number
Treemessage-size
Range25 to 255
Introduced25.3.R2

Platforms

7705 SAR Gen 2

metric-in number
Synopsis Metric added to routes received from the neighbor
Contextconfigure service vprn service-name ripng group named-item metric-in number
Treemetric-in
Range1 to 16
Introduced25.3.R2

Platforms

7705 SAR Gen 2

metric-out number
Synopsis Metric added to routes exported into RIPng
Contextconfigure service vprn service-name ripng group named-item metric-out number
Treemetric-out
Range1 to 16
Introduced25.3.R2

Platforms

7705 SAR Gen 2

neighbor [interface-name] reference
Synopsis Enter the neighbor list instance
Contextconfigure service vprn service-name ripng group named-item neighbor reference
Treeneighbor
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[interface-name] reference
Synopsis IP interface name
Context configure service vprn service-name ripng group named-item neighbor reference
Treeneighbor

Reference

configure service vprn service-name interface interface-name

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the RIPng neighbor
Contextconfigure service vprn service-name ripng group named-item neighbor reference admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bfd-liveness boolean
Synopsis Enable BFD to control the state of protocol adjacency
Contextconfigure service vprn service-name ripng group named-item neighbor reference bfd-liveness boolean
Treebfd-liveness

Description

When configured to true, this command enables BFD to control the state of the associated protocol adjacency.

When configured to false, this command removes BFD from the associated protocol adjacency.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

check-zero boolean
Synopsis Enable checking of mandatory zero fields
Contextconfigure service vprn service-name ripng group named-item neighbor reference check-zero boolean
Treecheck-zero

Description

When configured to true, this command enables checking of the mandatory zero fields in the RIPv1 and RIPv2 specifications and rejecting non-compliant RIP messages.

When configured to false, this command disables the check and allows the receipt of RIP messages even if the mandatory zero fields are non-zero.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

export-policy reference
Synopsis Policies used to rule which routes are exported to RIP
Contextconfigure service vprn service-name ripng group named-item neighbor reference export-policy reference
Treeexport-policy

Description

This command specifies the export route policies used to determine which routes are exported to RIP.

If multiple policy names are specified, the policies are evaluated in the order they are specified. The first policy that matches is applied.

Reference

configure policy-options policy-statement named-item-64

Max. instances5

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

import-policy reference
Synopsis Policies to decide routes accepted from RIP neighbors
Contextconfigure service vprn service-name ripng group named-item neighbor reference import-policy reference
Treeimport-policy

Description

This command configures import route policies to determine which routes are accepted from RIP neighbors.

If multiple policy names are specified, the policies are evaluated in the order they are specified. The first policy that matches is applied.

Reference

configure policy-options policy-statement named-item-64

Max. instances5

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

metric-in number
Synopsis Metric added to routes received from the neighbor
Contextconfigure service vprn service-name ripng group named-item neighbor reference metric-in number
Treemetric-in
Range1 to 16
Introduced25.3.R2

Platforms

7705 SAR Gen 2

receive keyword
Synopsis Accepted version on received packets
Context configure service vprn service-name ripng group named-item neighbor reference receive keyword
Treereceive
Optionsnone, ripng
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

send keyword
Synopsis RIPng version and method used to send RIPng updates
Contextconfigure service vprn service-name ripng group named-item neighbor reference send keyword
Treesend
Optionsnone, ripng, unicast
Introduced25.3.R2

Platforms

7705 SAR Gen 2

split-horizon boolean
Synopsis Enable split horizon and poison reverse
Contextconfigure service vprn service-name ripng group named-item neighbor reference split-horizon boolean
Treesplit-horizon

Description

When configured to true, this command enables the use of split horizon with poison reverse. Split-horizon with poison reverse means that routes learned from a neighbor through a given interface are advertised in updates out of the same interface but with a metric of 16 (infinity).

When configured to false. this command enables split horizon without poison reverse. This allows the routes to be re-advertised on interfaces other than the interface that learned the route, with the advertised metric equaling an increment of the metric-in value.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

timers
Synopsis Enable the timers context
Context configure service vprn service-name ripng group named-item neighbor reference timers
Treetimers
Introduced25.3.R2

Platforms

7705 SAR Gen 2

flush number
Synopsis RIP flush timer
Context configure service vprn service-name ripng group named-item neighbor reference timers flush number
Treeflush

Description

This command specifies the time a route is maintained in the RIP database after it has been declared invalid. When the timer expires, the route is flushed from the RIP database completely.

Range1 to 1200
Unitsseconds

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

timeout number
Synopsis RIP timeout timer
Context configure service vprn service-name ripng group named-item neighbor reference timers timeout number
Treetimeout

Description

This command specifies the RIP timeout timer. If a route is not updated by the time the timer expires, the route is declared invalid, but the route is maintained in the RIP database.

Range1 to 1200
Unitsseconds

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

update number
Synopsis Timer that controls the frequency of updates
Contextconfigure service vprn service-name ripng group named-item neighbor reference timers update number
Treeupdate
Range1 to 600
Unitsseconds

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

unicast-address [address] ipv6-unicast-address
Synopsis Add a list entry for unicast-address
Contextconfigure service vprn service-name ripng group named-item neighbor reference unicast-address ipv6-unicast-address
Treeunicast-address
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[address] ipv6-unicast-address
Synopsis Unicast IPv6 address for the neighbor
Contextconfigure service vprn service-name ripng group named-item neighbor reference unicast-address ipv6-unicast-address
Treeunicast-address

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

receive keyword
Synopsis Accepted version on received packets
Context configure service vprn service-name ripng group named-item receive keyword
Treereceive
Optionsnone, ripng
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

send keyword
Synopsis RIPng version and method used to send RIPng updates
Contextconfigure service vprn service-name ripng group named-item send keyword
Treesend
Optionsnone, ripng
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

split-horizon boolean
Synopsis Enable split horizon and poison reverse
Contextconfigure service vprn service-name ripng group named-item split-horizon boolean
Treesplit-horizon

Description

When configured to true, this command enables the use of split horizon with poison reverse. Split-horizon with poison reverse means that routes learned from a neighbor through a given interface are advertised in updates out of the same interface but with a metric of 16 (infinity).

When configured to false. this command enables split horizon without poison reverse. This allows the routes to be re-advertised on interfaces other than the interface that learned the route, with the advertised metric equaling an increment of the metric-in value.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

timers
Synopsis Enable the timers context
Context configure service vprn service-name ripng group named-item timers
Treetimers
Introduced25.3.R2

Platforms

7705 SAR Gen 2

flush number
Synopsis RIP flush timer
Context configure service vprn service-name ripng group named-item timers flush number
Treeflush

Description

This command specifies the time a route is maintained in the RIP database after it has been declared invalid. When the timer expires, the route is flushed from the RIP database completely.

Range1 to 1200
Unitsseconds

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

timeout number
Synopsis RIP timeout timer
Context configure service vprn service-name ripng group named-item timers timeout number
Treetimeout

Description

This command specifies the RIP timeout timer. If a route is not updated by the time the timer expires, the route is declared invalid, but the route is maintained in the RIP database.

Range1 to 1200
Unitsseconds

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

update number
Synopsis Timer that controls the frequency of updates
Contextconfigure service vprn service-name ripng group named-item timers update number
Treeupdate
Range1 to 600
Unitsseconds

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

message-size number
Synopsis Maximum number of routes in the message
Contextconfigure service vprn service-name ripng message-size number
Treemessage-size
Range25 to 255
Default25
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

metric-in number
Synopsis Metric added to routes received from the neighbor
Contextconfigure service vprn service-name ripng metric-in number
Treemetric-in
Range1 to 16
Default1
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

metric-out number
Synopsis Metric added to routes exported into RIPng
Contextconfigure service vprn service-name ripng metric-out number
Treemetric-out
Range1 to 16
Default1
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

preference number
Synopsis Route preference
Context configure service vprn service-name ripng preference number
Treepreference
Range1 to 255
Default100
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

receive keyword
Synopsis Accepted version on received packets
Context configure service vprn service-name ripng receive keyword
Treereceive
Optionsnone, ripng
Default ripng
Introduced25.3.R2

Platforms

7705 SAR Gen 2

send keyword
Synopsis RIPng version and method used to send RIPng updates
Contextconfigure service vprn service-name ripng send keyword
Treesend
Optionsnone, ripng
Default ripng
Introduced25.3.R2

Platforms

7705 SAR Gen 2

split-horizon boolean
Synopsis Enable split horizon and poison reverse
Contextconfigure service vprn service-name ripng split-horizon boolean
Treesplit-horizon

Description

When configured to true, this command enables the use of split horizon with poison reverse. Split-horizon with poison reverse means that routes learned from a neighbor through a given interface are advertised in updates out of the same interface but with a metric of 16 (infinity).

When configured to false, this command enables split horizon without poison reverse. This allows the routes to be re-advertised on interfaces other than the interface that learned the route, with the advertised metric equaling an increment of the metric-in value.

Defaulttrue
Introduced25.3.R2

Platforms

7705 SAR Gen 2

timers
Synopsis Enable the timers context
Context configure service vprn service-name ripng timers
Treetimers
Introduced25.3.R2

Platforms

7705 SAR Gen 2

flush number
Synopsis RIP flush timer
Context configure service vprn service-name ripng timers flush number
Treeflush

Description

This command specifies the time a route is maintained in the RIP database after it has been declared invalid. When the timer expires, the route is flushed from the RIP database completely.

Range1 to 1200
Unitsseconds

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

timeout number
Synopsis RIP timeout timer
Context configure service vprn service-name ripng timers timeout number
Treetimeout

Description

This command specifies the RIP timeout timer. If a route is not updated by the time the timer expires, the route is declared invalid, but the route is maintained in the RIP database.

Range1 to 1200
Unitsseconds

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

update number
Synopsis Timer that controls the frequency of updates
Contextconfigure service vprn service-name ripng timers update number
Treeupdate
Range1 to 600
Unitsseconds

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

router-id router-id
Synopsis Unique router ID for the router in the AS
Contextconfigure service vprn service-name router-id router-id
Treerouter-id
Introduced25.3.R2

Platforms

7705 SAR Gen 2

service-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisService ID
Contextconfigure service vprn service-name service-id number
Treeservice-id
Range1 to 2147483647
Introduced25.3.R2

Platforms

7705 SAR Gen 2

sfm-overload
Synopsis Enable the sfm-overload context
Contextconfigure service vprn service-name sfm-overload
Treesfm-overload
Introduced25.3.R2

Platforms

7705 SAR Gen 2

holdoff-time number
Synopsis Delay in detecting SFM failures and setting overload
Contextconfigure service vprn service-name sfm-overload holdoff-time number
Treeholdoff-time
Range1 to 600
Unitsseconds
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

sgt-qos
Synopsis Enter the sgt-qos context
Context configure service vprn service-name sgt-qos
Treesgt-qos
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dot1p
Synopsis Enter the dot1p context
Context configure service vprn service-name sgt-qos dot1p
Treedot1p
Introduced25.3.R2

Platforms

7705 SAR Gen 2

application [dot1p-app-name] keyword
Synopsis Enter the application list instance
Contextconfigure service vprn service-name sgt-qos dot1p application keyword
Treeapplication
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[dot1p-app-name] keyword
Synopsis Dot1p application ID that generates control traffic
Contextconfigure service vprn service-name sgt-qos dot1p application keyword
Treeapplication
Optionsarp, isis, pppoe

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

dot1p (keyword | number)
Synopsis Dot1p value to the traffic generated by this application
Contextconfigure service vprn service-name sgt-qos dot1p application keyword dot1p (keyword | number)
Treedot1p
Range0 to 7
Options

be – Best effort

l2 – Low 2 (best effort)

af – Assured forwarding (assured)

l1 – Low 1 (assured)

h2 – High 2 (high priority)

ef – Expedited forwarding (high priority)

h1 – High 1 (high priority)

nc – Network control (high priority)

Introduced25.3.R2

Platforms

7705 SAR Gen 2

dscp
Synopsis Enter the dscp context
Context configure service vprn service-name sgt-qos dscp
Treedscp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

application [dscp-app-name] keyword
Synopsis Enter the application list instance
Contextconfigure service vprn service-name sgt-qos dscp application keyword
Treeapplication

Description

Commands in this context configure DSCP remarking for self-generated application traffic.

All packets generated by the configured application instance use the value configured for the DSCP name or value. The instance can be Base, router, VPRN, or management.

The system uses the DSCP value configured in this instance to:

  • set the DSCP bits in the IP packet

  • signal from the CPM to the egress FC QoS policy to set the Ethernet 802.1p and MPLS EXP bits including, PPPoE, and IS-IS packets that do not carry DSCP bits

  • configure the DSCP value in the egress IP header (which the egress QoS policy does not overwrite)

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[dscp-app-name] keyword
Synopsis DSCP application ID that generates control traffic
Contextconfigure service vprn service-name sgt-qos dscp application keyword
Treeapplication

Description

This command configures the DSCP application ID that generates control traffic.

Optionsbgp, dhcp, dns, ftp, icmp, igmp, l2tp, ldp, mld, msdp, ndis, ntp, ospf, pim, radius, rip, rsvp, snmp, snmp-notification, srrp, ssh, syslog, tacplus, telnet, tftp, traceroute, vrrp, ptp, gtp, diameter, pcep, call-trace, bmp, grpc, mtrace2, http, pfcp, ibcp, bfd

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

dscp (keyword | number)
Synopsis DSCP value to the traffic generated by this application
Contextconfigure service vprn service-name sgt-qos dscp application keyword dscp (keyword | number)
Treedscp
Range0 to 63
Optionsbe, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63
Introduced25.3.R2

Platforms

7705 SAR Gen 2

dscp-map [dscp-name] keyword
Synopsis Enter the dscp-map list instance
Contextconfigure service vprn service-name sgt-qos dscp dscp-map keyword
Treedscp-map
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[dscp-name] keyword
Synopsis DSCP name mapped to forwarding class
Context configure service vprn service-name sgt-qos dscp dscp-map keyword
Treedscp-map
Optionsbe, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

fc keyword
Synopsis Value for the forwarding class for this mapping
Contextconfigure service vprn service-name sgt-qos dscp dscp-map keyword fc keyword
Treefc
Options

be – Best effort

l2 – Low 2 (best effort)

af – Assured forwarding (assured)

l1 – Low 1 (assured)

h2 – High 2 (high priority)

ef – Expedited forwarding (high priority)

h1 – High 1 (high priority)

nc – Network control (high priority)

Introduced25.3.R2

Platforms

7705 SAR Gen 2

snmp
Synopsis Enter the snmp context
Context configure service vprn service-name snmp
Treesnmp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

access boolean
Synopsis Enable SNMP access for the VPRN service
Contextconfigure service vprn service-name snmp access boolean
Treeaccess
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

community [community-string] encrypted-leaf
Synopsis Enter the community list instance
Contextconfigure service vprn service-name snmp community encrypted-leaf
Treecommunity

Description

Commands in this context set the SNMP community names to be used with the associated VPRN instance. These VPRN community names are used to associate SNMP v1/v2c requests with a particular VPRN context and to return a reply that contains VPRN-specific data or limit SNMP access to data in a specific VPRN instance.

VPRN SNMP communities configured with an access permission of 'r' are automatically associated with the default access group "snmp-vprn-ro” and the “vprn-view” view (read only). VPRN SNMP communities configured with an access permission of 'rw' are automatically associated with the default access group "snmp-vprn” and the “vprn-view” view (read/write).

The community in an SNMP v1/v2 request determines the SNMP context (that is, the VPRN number for accessing SNMP tables) and not the VPRN of the incoming interface on which the request was received. For example, when an SNMP request arrives on VPRN 5 interface “ringo” with a destination IP address equal to the “ringo” interface, but the community in the SNMP request is the community configured against VPRN 101, the SNMP request is processed using the VPRN 101 context. (the response contains information about VPRN 101). Nokia recommends avoiding the use of a simple series of VPRN SNMP community values that are similar to each other (for example, avoid my-vprncomm-1, my-vprn-comm-2, and so on).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[community-string] encrypted-leaf
Synopsis SNMP v1/v2c community name associated with the VPRN
Contextconfigure service vprn service-name snmp community encrypted-leaf
Treecommunity
String length1 to 114

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

source-access-list reference
Synopsis List name used to validate the source IP address
Contextconfigure service vprn service-name snmp community encrypted-leaf source-access-list reference
Treesource-access-list

Description

This command specifies the SNMP source access list to use with the SNMP community. The source access list is used to validate the source IP address of all received SNMP requests that use the community.

Reference

configure system security snmp source-access-list string-not-all-spaces

Introduced25.3.R2

Platforms

7705 SAR Gen 2

version keyword
Synopsis SNMP version
Contextconfigure service vprn service-name snmp community encrypted-leaf version keyword
Treeversion
Optionsv1, v2c, both
Defaultboth
Introduced25.3.R2

Platforms

7705 SAR Gen 2

source-address
Synopsis Enter the source-address context
Contextconfigure service vprn service-name source-address
Treesource-address

Description

Commands in this context configure the source address and application to use in all unsolicited packets.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv4 [application] keyword
Synopsis Enter the ipv4 list instance
Context configure service vprn service-name source-address ipv4 keyword
Treeipv4
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[application] keyword
Synopsis Application that uses the source IP address
Contextconfigure service vprn service-name source-address ipv4 keyword
Treeipv4
Optionstelnet, ssh, snmptrap, ping, traceroute, ntp, cflowd, ptp, icmp-error

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

address ipv4-address
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSource IPv4 address
Contextconfigure service vprn service-name source-address ipv4 keyword address ipv4-address
Treeaddress

Notes

The following elements are part of a mandatory choice: address or interface-name.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface-name interface-name
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP interface name
Contextconfigure service vprn service-name source-address ipv4 keyword interface-name interface-name
Treeinterface-name
String length1 to 32

Notes

The following elements are part of a mandatory choice: address or interface-name.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipv6 [application] keyword
Synopsis Enter the ipv6 list instance
Context configure service vprn service-name source-address ipv6 keyword
Treeipv6
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[application] keyword
Synopsis Application that uses the source IP address
Contextconfigure service vprn service-name source-address ipv6 keyword
Treeipv6
Optionstelnet, snmptrap, ping, traceroute, cflowd, ntp, icmp6-error, ssh, ptp

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

address ipv6-address
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSource IPv6 address
Contextconfigure service vprn service-name source-address ipv6 keyword address ipv6-address
Treeaddress

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

spoke-sdp [sdp-bind-id] sdp-bind-id
Synopsis Enter the spoke-sdp list instance
Contextconfigure service vprn service-name spoke-sdp sdp-bind-id
Treespoke-sdp
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[sdp-bind-id] sdp-bind-id
Synopsis SDP binding ID
Contextconfigure service vprn service-name spoke-sdp sdp-bind-id
Treespoke-sdp
String length3 to 16

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description
Synopsis Text description
Context configure service vprn service-name spoke-sdp sdp-bind-id description description
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

static-routes
Synopsis Enter the static-routes context
Contextconfigure service vprn service-name static-routes
Treestatic-routes
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hold-down
Synopsis Enable the hold-down context
Context configure service vprn service-name static-routes hold-down
Treehold-down

Description

Commands in this context enable the hold-down time feature globally for static routes in the system.

The static route hold-down time is a mechanism to protect from rapid, fluctuating state changes of static routes resulting from issues with reachability because of link flap.

The commands in this context apply to all static routes in the VPRN and the base router instance in which this hold-down time is configured in.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

initial number
Synopsis Value for the initial hold-down time
Context configure service vprn service-name static-routes hold-down initial number
Treeinitial

Description

This command specifies the initial value of the hold-down time globally for static routes in the system.

When a static route is ready to become active, it remains inactive for the hold-down time before activating the static-route. If, during this hold-down period, the static route becomes inactive again because of factors such as interface failure, the hold-down timer is reset, effectively postponing the activation of the route until the next opportunity.

Range1 to 65535

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

max-value number
Synopsis Maximum value of the hold-down time
Context configure service vprn service-name static-routes hold-down max-value number
Treemax-value

Description

This command specifies the maximum value of the hold-down time globally for static routes in the system.

Range1 to 65535

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

multiplier number
Synopsis Multiplier of the previous hold-down time
Contextconfigure service vprn service-name static-routes hold-down multiplier number
Treemultiplier

Description

This command specifies the multiplier value by which the previous hold-down time is multiplied to calculate the new one. This value applies globally for static routes in the system.

Range1 to 10

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

route [ip-prefix] (ipv4-prefix | ipv6-prefix) route-type keyword
Synopsis Enter the route list instance
Context configure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword
Treeroute
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis IP prefix and prefix length for the static routes
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword
Treeroute

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

route-type keyword
Synopsis Static route type
Context configure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword
Treeroute
Optionsunicast, multicast

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

blackhole
Synopsis Enable the blackhole context
Context configure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword blackhole
Treeblackhole
Introduced25.3.R2

Platforms

7705 SAR Gen 2

prefix-list
Synopsis Enter the prefix-list context
Context configure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword blackhole prefix-list
Treeprefix-list
Introduced25.3.R2

Platforms

7705 SAR Gen 2

router-instance string
Synopsis Router instance used for matching prefix list
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword blackhole prefix-list router-instance string
Treerouter-instance

Description

This command configures the router instance used for matching against the prefix list. If the conditional static route is configured in a VPRN and the router instance is configured as "Base", the activation of the static route is dependent on the existence of routes in the Base router and the evaluation of the prefix list and flag is done in that context.

By default there is no configured value for this command option, and the conditional static route is dependent on the existence of routes in the same router instance as the static route itself, subject to the details of the prefix list and the flag setting.

Entries in a referenced prefix list that are not match type 'exact' are interpreted as though they are 'exact'.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

community community
Synopsis Community ID associated with the static route
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword community community
Treecommunity
String length1 to 72
Max. instances12

Notes

This element is ordered by the user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

grt
Synopsis Enable the grt context
Context configure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword grt
Treegrt
Introduced25.3.R2

Platforms

7705 SAR Gen 2

indirect [ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Enter the indirect list instance
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone)
Treeindirect
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Next-hop IP address used to reach the destination
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone)
Treeindirect

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the static route operation
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) admin-state keyword
Treeadmin-state
Optionsenable, disable
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

community community
Synopsis Community ID associated with the static route
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) community community
Treecommunity
String length1 to 72
Introduced25.3.R2

Platforms

7705 SAR Gen 2

cpe-check [address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Enter the cpe-check list instance
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) cpe-check (ipv4-address-no-zone | ipv6-address-no-zone)
Treecpe-check

Description

When configured, this command enables the Customer Premises Equipment (CPE) check feature and specifies the IP address of the target CPE device.

This option initiates a background ICMP ping test to the configured target IP address. The IP address can either be an IPv4 address for IPv4 static routes or an IPv6 address for IPv6 static routes. To avoid possible circular references, the target IP address cannot exist in the same subnet as the static route subnet. This command is mutually exclusive with BFD support on a specific static route.

Note: A node that is sourcing CPE-check packets waits an additional full interval before taking action, which gives the CPE time to respond. For example, with a drop-count of 3 and an interval of 1s, three CPE-check packets are sent out and the node waits for the duration of another interval before acting on the loss. Failure declaration may take extra time depending on the load, interval, and other factors. In line with multitasking, multi-priority operating principles of the node, and the relative priority of cpe-ping, the node paces these minor events.

Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the target CPE device
Context configure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) cpe-check (ipv4-address-no-zone | ipv6-address-no-zone)
Treecpe-check

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

drop-count number
Synopsis Consecutive ping replies missed before CPE deemed down
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) cpe-check (ipv4-address-no-zone | ipv6-address-no-zone) drop-count number
Treedrop-count
Range1 to 255
Default3
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

interval number
Synopsis Interval between ICMP pings to target CPE IP address
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) cpe-check (ipv4-address-no-zone | ipv6-address-no-zone) interval number
Treeinterval
Range1 to 255
Unitsseconds
Default 1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

log boolean
Synopsis Log CPE connectivity checks transitions
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) cpe-check (ipv4-address-no-zone | ipv6-address-no-zone) log boolean
Treelog
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

padding-size number
Synopsis Padding size for CPE connectivity checks
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) cpe-check (ipv4-address-no-zone | ipv6-address-no-zone) padding-size number
Treepadding-size
Range0 to 16384
Unitsbytes
Default 56
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description-allow-all-white-spaces
Synopsis Text description
Context configure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) description description-allow-all-white-spaces
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

metric number
Synopsis Static route metric
Context configure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) metric number
Treemetric
Range0 to 65535
Default1
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

preference number
Synopsis Priority of this static route over the routes from different sources
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) preference number
Treepreference
Range1 to 255
Default5
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

prefix-list
Synopsis Enter the prefix-list context
Context configure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) prefix-list
Treeprefix-list
Introduced25.3.R2

Platforms

7705 SAR Gen 2

flag keyword
Synopsis Static route match condition from prefix list
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) prefix-list flag keyword
Treeflag
Optionsany, all, none
Defaultany
Introduced25.3.R2

Platforms

7705 SAR Gen 2

router-instance string
Synopsis Router instance used for matching prefix list
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) prefix-list router-instance string
Treerouter-instance

Description

This command configures the router instance used for matching against the prefix list. If the conditional static route is configured in a VPRN and the router instance is configured as "Base", the activation of the static route is dependent on the existence of routes in the Base router and the evaluation of the prefix list and flag is done in that context.

By default there is no configured value for this command option, and the conditional static route is dependent on the existence of routes in the same router instance as the static route itself, subject to the details of the prefix list and the flag setting.

Entries in a referenced prefix list that are not match type 'exact' are interpreted as though they are 'exact'.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

tag number
Synopsis Static route tag
Context configure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) tag number
Treetag
Range1 to 4294967295
Introduced25.3.R2

Platforms

7705 SAR Gen 2

interface [interface-name] interface-name
Synopsis Enter the interface list instance
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword interface interface-name
Treeinterface
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[interface-name] interface-name
Synopsis Router interface name
Context configure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword interface interface-name
Treeinterface
String length1 to 32

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

cpe-check [address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Enter the cpe-check list instance
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword interface interface-name cpe-check (ipv4-address-no-zone | ipv6-address-no-zone)
Treecpe-check

Description

When configured, this command enables the Customer Premises Equipment (CPE) check feature and specifies the IP address of the target CPE device.

This option initiates a background ICMP ping test to the configured target IP address. The IP address can either be an IPv4 address for IPv4 static routes or an IPv6 address for IPv6 static routes. To avoid possible circular references, the target IP address cannot exist in the same subnet as the static route subnet. This command is mutually exclusive with BFD support on a specific static route.

Note: A node that is sourcing CPE-check packets waits an additional full interval before taking action, which gives the CPE time to respond. For example, with a drop-count of 3 and an interval of 1s, three CPE-check packets are sent out and the node waits for the duration of another interval before acting on the loss. Failure declaration may take extra time depending on the load, interval, and other factors. In line with multitasking, multi-priority operating principles of the node, and the relative priority of cpe-ping, the node paces these minor events.

Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the target CPE device
Context configure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword interface interface-name cpe-check (ipv4-address-no-zone | ipv6-address-no-zone)
Treecpe-check

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

interval number
Synopsis Interval between ICMP pings to target CPE IP address
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword interface interface-name cpe-check (ipv4-address-no-zone | ipv6-address-no-zone) interval number
Treeinterval
Range1 to 255
Unitsseconds
Default 1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

log boolean
Synopsis Log CPE connectivity checks transitions
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword interface interface-name cpe-check (ipv4-address-no-zone | ipv6-address-no-zone) log boolean
Treelog
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

prefix-list
Synopsis Enter the prefix-list context
Context configure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword interface interface-name prefix-list
Treeprefix-list
Introduced25.3.R2

Platforms

7705 SAR Gen 2

router-instance string
Synopsis Router instance used for matching prefix list
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword interface interface-name prefix-list router-instance string
Treerouter-instance

Description

This command configures the router instance used for matching against the prefix list. If the conditional static route is configured in a VPRN and the router instance is configured as "Base", the activation of the static route is dependent on the existence of routes in the Base router and the evaluation of the prefix list and flag is done in that context.

By default there is no configured value for this command option, and the conditional static route is dependent on the existence of routes in the same router instance as the static route itself, subject to the details of the prefix list and the flag setting.

Entries in a referenced prefix list that are not match type 'exact' are interpreted as though they are 'exact'.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipsec-tunnel [ipsec-tunnel-name] named-item
Synopsis Enter the ipsec-tunnel list instance
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword ipsec-tunnel named-item
Treeipsec-tunnel
Introduced25.3.R2

Platforms

7705 SAR Gen 2

next-hop [ip-address] (ipv4-address-with-zone | ipv6-address-with-zone)
Synopsis Enter the next-hop list instance
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone)
Treenext-hop
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ip-address] (ipv4-address-with-zone | ipv6-address-with-zone)
Synopsis Next-hop IP address used to reach the destination
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone)
Treenext-hop

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

admin-state keyword
Synopsis Administrative state of the static route operation
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) admin-state keyword
Treeadmin-state
Optionsenable, disable
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

community community
Synopsis Community ID associated with the static route
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) community community
Treecommunity
String length1 to 72
Introduced25.3.R2

Platforms

7705 SAR Gen 2

cpe-check [address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Enter the cpe-check list instance
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) cpe-check (ipv4-address-no-zone | ipv6-address-no-zone)
Treecpe-check
Max. instances1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the target CPE device
Context configure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) cpe-check (ipv4-address-no-zone | ipv6-address-no-zone)
Treecpe-check

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

drop-count number
Synopsis Consecutive ping replies missed before CPE deemed down
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) cpe-check (ipv4-address-no-zone | ipv6-address-no-zone) drop-count number
Treedrop-count
Range1 to 255
Default3
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

interval number
Synopsis Interval between ICMP pings to target CPE IP address
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) cpe-check (ipv4-address-no-zone | ipv6-address-no-zone) interval number
Treeinterval
Range1 to 255
Unitsseconds
Default 1
Introduced25.3.R2

Platforms

7705 SAR Gen 2

log boolean
Synopsis Log CPE connectivity checks transitions
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) cpe-check (ipv4-address-no-zone | ipv6-address-no-zone) log boolean
Treelog
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

padding-size number
Synopsis Padding size for CPE connectivity checks
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) cpe-check (ipv4-address-no-zone | ipv6-address-no-zone) padding-size number
Treepadding-size
Range0 to 16384
Unitsbytes
Default 56
Introduced25.3.R2

Platforms

7705 SAR Gen 2

description description-allow-all-white-spaces
Synopsis Text description
Context configure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) description description-allow-all-white-spaces
Treedescription
String length1 to 80
Introduced25.3.R2

Platforms

7705 SAR Gen 2

metric number
Synopsis Static route metric
Context configure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) metric number
Treemetric
Range0 to 65535
Default1
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

preference number
Synopsis Priority of this static route over the routes from different sources
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) preference number
Treepreference
Range1 to 255
Default5
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

prefix-list
Synopsis Enter the prefix-list context
Context configure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) prefix-list
Treeprefix-list
Introduced25.3.R2

Platforms

7705 SAR Gen 2

flag keyword
Synopsis Static route match condition from prefix list
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) prefix-list flag keyword
Treeflag
Optionsany, all, none
Defaultany
Introduced25.3.R2

Platforms

7705 SAR Gen 2

router-instance string
Synopsis Router instance used for matching prefix list
Contextconfigure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) prefix-list router-instance string
Treerouter-instance

Description

This command configures the router instance used for matching against the prefix list. If the conditional static route is configured in a VPRN and the router instance is configured as "Base", the activation of the static route is dependent on the existence of routes in the Base router and the evaluation of the prefix list and flag is done in that context.

By default there is no configured value for this command option, and the conditional static route is dependent on the existence of routes in the same router instance as the static route itself, subject to the details of the prefix list and the flag setting.

Entries in a referenced prefix list that are not match type 'exact' are interpreted as though they are 'exact'.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

tag number
Synopsis Static route tag
Context configure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) tag number
Treetag
Range1 to 4294967295
Introduced25.3.R2

Platforms

7705 SAR Gen 2

tag number
Synopsis Static route tag
Context configure service vprn service-name static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword tag number
Treetag
Range1 to 4294967295
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ttl-propagate
Synopsis Enter the ttl-propagate context
Contextconfigure service vprn service-name ttl-propagate
Treettl-propagate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

local keyword
Synopsis Local TTL propagation control for the VPRN
Contextconfigure service vprn service-name ttl-propagate local keyword
Treelocal

Description

This command specifies the local TTL propagation control for the VPRN and overrides the global configuration of the TTL propagation for locally generated packets that are forwarded over MPLS LSPs in a given VPRN service context.

Optionsnone, all, vc-only, use-base
Default use-base
Introduced25.3.R2

Platforms

7705 SAR Gen 2

transit keyword
Synopsis Transit TTL propagation control for the VPRN
Contextconfigure service vprn service-name ttl-propagate transit keyword
Treetransit

Description

This command overrides the global configuration of the TTL propagation for in transit packets that are forwarded over MPLS LSPs in a given VPRN service context.

Optionsnone, all, vc-only, use-base
Default use-base
Introduced25.3.R2

Platforms

7705 SAR Gen 2

twamp-light
Synopsis Enter the twamp-light context
Context configure service vprn service-name twamp-light
Treetwamp-light
Introduced25.3.R2

Platforms

7705 SAR Gen 2

reflector
Synopsis Enable the reflector context
Context configure service vprn service-name twamp-light reflector
Treereflector
Introduced25.3.R2

Platforms

7705 SAR Gen 2

allow-ipv6-udp-checksum-zero boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisProcess IPv6 packets with a zero UDP checksum
Contextconfigure service vprn service-name twamp-light reflector allow-ipv6-udp-checksum-zero boolean
Treeallow-ipv6-udp-checksum-zero

Description

When configured to true, this command allows the processing of IPv6 packets that arrive with a UDP checksum of zero. The destination UDP ports that are registered as TWAMP Test packets as part of this template allow this behavior. 

When configured to false, IPv6 packets that arrive with a UDP checksum of zero are discarded.

Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2

prefix [ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis Enter the prefix list instance
Contextconfigure service vprn service-name twamp-light reflector prefix (ipv4-prefix | ipv6-prefix)
Treeprefix
Max. instances50
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis Source prefix for the TWAMP-Light reflector
Contextconfigure service vprn service-name twamp-light reflector prefix (ipv4-prefix | ipv6-prefix)
Treeprefix

Notes

This element is part of a list key.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

type keyword
Synopsis Processing behavior type for the reflector
Contextconfigure service vprn service-name twamp-light reflector type keyword
Treetype

Description

This command configures the processing behavior of the TWAMP Light reflector. When the value is twamp-light the reflector does not check the received PDU as a traditional base TWAMP Light packet without TLV processing. When the value is stamp, the reflector attempts to find and process supported STAMP TLVs that follow the base STAMP packet. 

In mixed environments where different types of Session-Senders may be targeting a common TWAMP Light reflector, set the value to stamp. When the reflector is operating in stamp mode, the primary parsing is based on STAMP, checking and processing known TLVs, or determining if the arriving PDU is a TWAMP Light PDU. A Session-Sender launching a TWAMP Light-based packet must use all zeros padding pattern when the pad size is non zero.

Optionsstamp, twamp-light
Default twamp-light
Introduced25.3.R2

Platforms

7705 SAR Gen 2

udp-port number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisUDP port on which the specified TWAMP-Light reflector listens for TWAMP PDUs
Contextconfigure service vprn service-name twamp-light reflector udp-port number
Treeudp-port
Range862 | 64364 to 64373

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

vprn-type keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisVPRN type
Contextconfigure service vprn service-name vprn-type keyword
Treevprn-type
Optionsregular, hub, spoke, subscriber-split-horizon
Defaultregular
Introduced25.3.R2

Platforms

7705 SAR Gen 2

weighted-ecmp keyword
Synopsis Weighted load-balancing capability for ECMP routes
Contextconfigure service vprn service-name weighted-ecmp keyword
Treeweighted-ecmp
Optionsfalse, true, strict
Defaultfalse
Introduced25.3.R2

Platforms

7705 SAR Gen 2