AA FW command reference

The 7705 SAR-Hm series of routers supports the AA FW commands listed in this section. For command descriptions, see the 7450 ESS, 7750 SR, 7950 XRS, and VSR Classic CLI Command Reference Guide.

ISA AA group commands

— config
            — isa
               — application-assurance-group application-assurance-group-index [create] [aa-subscale sub-scale]

               — no application-assurance-group application-assurance-group-index
                  — description description-string
                  — no description 
                  — divert-fc fc-name
                  — no divert-fc 
                  — [no] fail-to-open
                — [no] shutdown 
                — statistics
                    — performance
                    — [no] collect-stats


AA commands

— config
        — application-assurance
            — bit-rate-high-wmark high-watermark
            — no bit-rate-high-wmark 
            — bit-rate-low-wmark low-watermark
            — no bit-rate-low-wmark 
            — datapath-cpu-high-wmark high-watermark
            — datapath-cpu-high-wmark max
            — datapath-cpu-low-wmark low-watermark
            — flow-setup-high-wmark high-watermark
            — flow-setup-low-wmark low-watermark
            — no flow-setup-low-wmark 
            — flow-table-high-wmark high-watermark
            — no flow-table-high-wmark 
            — flow-table-low-wmark low-watermark
            — no flow-table-low-wmark 
            — packet-rate-high-wmark high-watermark
            — packet-rate-low-wmark low-watermark
            — no packet-rate-low-wmark low-watermark

AA group commands

config
        — application-assurance
                    — group  aa-group-id[:partition-id [create]]
                    — no group  aa-group-id:partition-id 
                      — [no] aa-sub-remote 
                      — description description-string
                      — no description 
                      — event-log event-log-name [create]
                      — no event-log event-log-name 
                         — buffer-type buffer-type
                         — max-entries max-entries
                         — [no] shutdown
                         — syslog
                           — address ip-address
                           — no address 
                           — description description-string
                           — no description 
                           — facility syslog-facility
                           — port port
                           — severity syslog-severity
                           — vlan-id  service-port-vlan-id
                           — no vlan-id  
                      — ip-prefix-list ip-prefix-list-name [create]
                      — no ip-prefix-list ip-prefix-list-name
                          — description description-string
                          — no description 
                          — prefix ip-prefix/ip-prefix-length [name prefix-name]
                          — no prefix ip-prefix/ip-prefix-length 
                     — policer policer-name type type granularity granularity [create]
                     — no policer policer-name
                          — action  {priority-mark | permit-deny}
                          — adaptation-rule pir adaptation rule [cir {adaptation rule}]
                          — no adaptation-rule
                          — cbs  committed-burst-size
                          — no cbs  
                          — description description-string
                          — no description 
                          — flow-count flow-count
                          — no flow-count 
                          — mbs maximum-burst-size
                          — no mbs 
                          — rate  pir-rate [cir cir-rate]
                          — no rate  
                          — tod-override tod-override-id create
                          — no tod-override tod-override-id 
                              — cbs committed-burst-size
                              — no cbs 
                              — description  description-string
                              — no description  
                              — flow-count flow-count
                              — no flow-count 
                              — mbs maximum-burst-size
                              — no mbs 
                              — rate pir-rate [cir cir-rate]
                              — no rate 
                              — [no] shutdown 
                              — time-range daily start start-time end end-time [on day [day]]
                              — time-range weekly start start-time end end-time 
                              — no time-range
                     — policy
                          — abort
                          — app-profile app-profile-name [create]
                          — no app-profile app-profile-name 
                              — [no] aa-sub-suppressible
                              — capacity-cost cost
                              — no capacity-cost 
                              — characteristic  characteristic-name value value-name
                              — no characteristic  characteristic-name  
                              — description description-string
                              — no description 
                              — [no] divert
                          — app-qos-policy
                              — entry  entry-id [create]
                              — no entry  entry-id 
                                  — action 
                                      — bandwidth-policer policer-name
                                      — no bandwidth-policer 
                                      — [no] drop
                                      — error-drop [event-log event-log-name]
                                      — no error-drop 
                                      — flow-count-limit policer-name [event-log eventlogname]
                                      — no flow-count-limit [event-log eventlogname]
                                      — flow-rate-limit policer-name [event-log eventlogname]
                                      — no flow-rate-limit 
                                      — fragment-drop {all | out-of-order} [event-log event-log-name]
                                      — no fragment-drop
                                      — mirror-source [all-inclusive] mirror-service-id
                                      — no mirror-source 
                                      — [no] overload-drop
                                      — remark
                                          — dscp in-profile dscp-name out-profile dscp-name
                                          — no dscp
                                          — fc fc-name
                                          — no fc
                                          — priority priority-level
                                          — no priority
                                      — session-filter session-filter-name
                                      — no session-filter
                                      — tcp-mss-adjust segment-size
                                      — no tcp-mss-adjust 
                                      — tcp-validate tcp-validate-name
                                      — no tcp-validate 
                              — description description-string
                              — no description
                              — match
                                — aa-sub sap {eq | neq} sap-id
                                — aa-sub spoke-sdp {eq | neq} sdp-id:vc-id
                                — no aa-sub 
                                — dscp {eq | neq} dscp-name
                                — no dscp
                                — dst-ip {eq | neq} ip-address
                                — dst-ip {eq | neq} ip-prefix-list ip-prefix-list-name
                                — no dst-ip
                                — dst-port {eq | neq} port-num
                                — dst-port {eq | neq} port-list port-list-name
                                — dst-port {eq | neq} range start-port-num endport-num
                                — no dst-port 
                                — ip-protocol-num {eq | neq} protocol-id
                                — no ip-protocol-num 
                                — src-ip {eq | neq} ip-address
                                — src-ip {eq | neq} ip-prefix-list ip-prefix-list-name
                                — no src-ip
                                — src-port {eq | neq} port-num
                                — src-port {eq | neq} port-list port-list-name
                                — src-port {eq | neq} range start-port-num endport-num
                                — no src-port
                                — traffic-direction {subscriber-to-network | network-to-subscriber | both}
                            — [no] shutdown
                          — app-service-options
                             — characteristic charateristic-name [create]
                             — no characteristic charateristic-name 
                              — default-value value-name
                              — no default-value 
                              — [no] value value-name
                          — begin 
                          — commit 
                     — port-list port-list-name [create]
                     — no port-list port-list-name 
                          — description description-string
                          — no description 
                          — [no] port port-number
                          — [no] port range start-port-number end-port-number
                     — session-filter session-filter-name [create]
                     — no session-filter session-filter-name 
                          — default-action {permit | deny} [event-log event-log-name]
                          — description description-string
                          — no description 
                          — entry entry-id[create]
                          — no entry 
                             — action  {permit | deny | tcp-strict-order} [event-log event-logname]
                             — action  http-redirect http-redirect-name[event-log event-logname]
                             — description description-string
                             — no description 
                             — match 
                              — dst-ip ip-address
                              — dst-ip dns-ip-cache dns-ip-cache-name
                              — dst-ip ip-prefix-list ip-prefix-list-name
                              — no dst-ip 
                              — dst-port {eq | gt | lt} port-num
                              — dst-port port-list  port-list-name
                              — dst-port range  start-port-num end-port-num
                              — no dst-port 
                              — ip-protocol-num {ip-protocol-number | protocolname}
                              — no ip-protocol-num
                              — src-ip ip-address
                              — src-ip ip-prefix-list ip-prefix-list
                              — no src-ip 
                              — src-port  {eq | gt | lt} port-num
                              — src-port range  start-port-num end-port-num
                              — no src-port 
                     — statistics
                          — aa-admit-deny
                             — [no] collect-stats
                             — [no] policer-stats
                             — [no] policer-stats-resources
                             — [no] session-filter-stats
                             — [no] tcp-validate-stats
                          — aa-partition
                             — [no] collect-stats
                             — [no] traffic-type
                          — threshold-crossing-alert
                             — error-drop direction direction [create]
                             — no error-drop direction direction 
                              — high-wmark high-watermark low-wmark low-watermark
                             — fragment-drop-all direction direction [create]
                             — no fragment-drop-all direction direction 
                              — high-wmark high-watermark low-wmark low-watermark
                             — fragment-drop-out-of-order direction direction [create]
                             — no fragment-drop-out-of-order direction direction 
                              — high-wmark high-watermark low-wmark low-watermark
                          — overload-drop direction direction [create]
                          — no overload-drop direction direction 
                             — high-wmark  high-watermark low-wmark low-watermark
                          — policer policer-name direction direction [create]
                          — no policer policer-name direction direction 
                             — high-wmark high-watermark low-wmark low-watermark
                          — session-filter session-filter-name
                             — default-action direction direction [create]
                             — no default-action direction direction 
                              — high-wmark high-watermark low-wmark low-watermark
                             — entry entry-id direction direction [create]
                             — no entry entry-id direction direction 
                              — high-wmark high-watermark low-wmark low-watermark
                          — tcp-validate tcp-validate-name direction direction [create]
                          — no tcp-validate tcp-validate-name direction direction 
                              — high-wmark high-watermark low-wmark low-watermark
                — tcp-validate tcp-validate-name create
                — no tcp-validate tcp-validate-name 
                          — description description-string
                          — no description 
                          — event-log log event-log-name [all]
                          — no event-log 
                          — [no] strict

AA interface commands

config
        — service service-id
            — ies | vprn
                — aa-interface aa-if-name [create]
                — no aa-interface aa-if-name 
                    — address  {ip-address/mask | ip-address netmask} 
                    — no address  [ip-address/mask | ip-address netmask]
                    — description  description-string
                    — no description 
                    — ip-mtu octets
                    — no ip-mtu 
                    — sap  sap-id [create]
                    — no sap  sap-id
                        — description  description-string
                        — no description  
                        — egress 
                            — filter ip ip-filter-id
                            — no filter [ip ip-filter-id]
                            — qos  policy-id 
                            — no qos  [policy-id] 
                        — ingress
                            — qos  policy-id
                            — no qos  [policy-id]
                        — [no] shutdown
                    — [no] shutdown