li commands

li 
li-filter 
associations 
li-ip-filter reference 
ip-filter string 
li-ipv6-filter reference 
ipv6-filter string 
li-mac-filter reference 
mac-filter string 
li-ip-filter string 
description string
entry number 
description string
match 
dst-ip 
address (ipv4-prefix-with-host-bits | ipv4-address)
mask string
dst-port 
eq number
gt number
lt number
range 
end number
start number
fragment keyword
protocol (number | keyword)
src-ip 
address (ipv4-prefix-with-host-bits | ipv4-address)
mask string
src-port 
eq number
gt number
lt number
range 
end number
start number
li-ipv6-filter string 
description string
entry number 
description string
match 
dst-ip 
address (ipv6-prefix-with-host-bits | ipv6-address)
mask string
dst-port 
eq number
gt number
lt number
range 
end number
start number
next-header (number | keyword)
src-ip 
address (ipv6-prefix-with-host-bits | ipv6-address)
mask string
src-port 
eq number
gt number
lt number
range 
end number
start number
li-mac-filter string 
description string
entry number 
description string
match 
dst-mac 
address string
mask string
frame-type keyword
outer-tag number
sap string
src-mac 
address string
mask string
lock-filter keyword
reserved-block string 
description string
entry-range 
end number
start number
ip-filter string 
ipv6-filter string 
mac-filter string 
li-source string 
admin-state keyword
li-ip-filter reference 
entry reference 
intercept-id number
session-id number
li-ipv6-filter reference 
entry reference 
intercept-id number
session-id number
li-mac-filter reference 
entry reference 
intercept-id number
session-id number
nat 
dslite string b4 string 
intercept-id number
session-id number
ethernet-header 
destination-address string
source-address string
type number
l2-aware string 
intercept-id number
session-id number
nat44 string ip string 
intercept-id number
session-id number
nat64 string ip string 
intercept-id number
session-id number
port string 
egress boolean
ingress boolean
sap string 
egress boolean
ingress boolean
intercept-id number
session-id number
subscriber string 
egress boolean
fc keyword
host-type keyword
ingress boolean
intercept-id number
ip-address string
ip-family keyword
mac-address string
sap-id string
session-id number
sla-profile string
wlan-gw-dsm-ue string 
intercept-id number
session-id number
log 
log-id string 
admin-state keyword
description string
destination 
memory 
max-entries number
netconf 
max-entries number
snmp 
max-entries number
send-using-vprn string
filter string
netconf-stream string
source 
li boolean
time-format keyword
mirror-dest-reservation 
end number
start number
mirror-dest-template string 
layer-3-encap 
direction-bit boolean
encap-type keyword
ip-source string
router-instance string
udp 
destination number
source number
type keyword
nat 
use-outside-ip-address boolean
radius 
mirror-dest-template reference
sci 
pfcp-li-shared-key string
x-interfaces 
admin-state keyword
correlation-id 
ipoe keyword
pppoe keyword
ine-identifier string
lic string 
authentication 
password string
private-ki string
sequence-group string
description string
identifier string
ipv4 
ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
port number
router-instance string
user-db string
x1 
ipv4 
local-address (ipv4-address-no-zone | ipv6-address-no-zone)
lic-peer reference
local-tcp-port number
timeouts 
message-timeout number
x2 
ipv4 
local-address (ipv4-address-no-zone | ipv6-address-no-zone)
lic-peer reference
timeouts 
keep-alive number
request number
x3 
alarms 
cpu-alarm 
high-threshold number
low-threshold number
memory-alarm 
high-threshold number
low-threshold number
throughput-alarm 
high-threshold number
low-threshold number
ipv4 
local-address-range 
end string
start string
li-group number
lic-peers reference 
session-limit number
timeouts 
keep-alive number
request number
target-retry-wait number

li command descriptions

li

Synopsis Configure lawful intercept
Context li
Tree li
Introduced19.10.R1

Platforms

All

li-filter

Synopsis Enter the li-filter context
Context li li-filter
Treeli-filter
Introduced19.10.R1

Platforms

All

associations
Synopsis Enter the associations context
Contextli li-filter associations
Treeassociations
Introduced19.10.R1

Platforms

All

li-ip-filter [li-filter-name] reference
Synopsis Enter the li-ip-filter list instance
Contextli li-filter associations li-ip-filter reference
Treeli-ip-filter
Introduced19.10.R1

Platforms

All

li-ipv6-filter [li-filter-name] reference
Synopsis Enter the li-ipv6-filter list instance
Contextli li-filter associations li-ipv6-filter reference
Treeli-ipv6-filter
Introduced19.10.R1

Platforms

All

ipv6-filter [filter-name] string
Synopsis Add a list entry for ipv6-filter
Contextli li-filter associations li-ipv6-filter reference ipv6-filter string
Treeipv6-filter
Max. Instances1
Min. Instances1
Introduced 19.10.R1

Platforms

All

li-mac-filter [li-filter-name] reference
Synopsis Enter the li-mac-filter list instance
Contextli li-filter associations li-mac-filter reference
Treeli-mac-filter
Introduced19.10.R1

Platforms

All

li-ip-filter [li-filter-name] string
Synopsis Enter the li-ip-filter list instance
Contextli li-filter li-ip-filter string
Treeli-ip-filter

Description

Commands in this context create LI IPv4 filter lists, which can be used to create confidential IPv4 filter based LI source entries.

The LI IPv4 filter entries are merged into normal IPv4 filters configured with the li li-filter associations and li li-filter reserved-block commands. The LI IPv4 filter entries are visible only to users with LI permissions.

Introduced19.10.R1

Platforms

All

[li-filter-name] string
Synopsis LI filter name
Contextli li-filter li-ip-filter string
Treeli-ip-filter

Description

This command specifies the LI filter name. Filter names cannot start with an underscore character (for example, “_my-filter”) and cannot use the name “default”.

String Length1 to 32

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

entry [li-entry-id] number
Synopsis Enter the entry list instance
Context li li-filter li-ip-filter string entry number
Treeentry

Description

Commands in this context configure an entry for the LI filter. 

Multiple entries can be created using unique entry ID numbers within the filter.  An entry in an LI filter always has an implicit action of “forward”. LI filter entries can be used as LI source entries.

The entry numbers for LI filters serve only as keys for managing the entries (deleting entries, and so on). The order of the LI filter entries is not guaranteed to match the entry numbers and the software may reorder entries. Operators must therefore use LI entries in such a way that their relative order is not important.

Entries removed from the filter are immediately removed from all services or network ports where the associated filter is applied.

Introduced19.10.R1

Platforms

All

[li-entry-id] number
Synopsis LI filter entry ID
Context li li-filter li-ip-filter string entry number
Treeentry
Range1 to 65535

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

match
Synopsis Enter the match context
Context li li-filter li-ip-filter string entry number match
Treematch

Description

Commands in this context configure match criteria for the filter entry. If more than one match criteria (within one match statement) are configured, all criteria must be satisfied (and function) for a match to occur.

A match context may consist of multiple match criteria, but multiple match statements cannot be configured per entry.

Introduced19.10.R1

Platforms

All

dst-ip
Synopsis Enter the dst-ip context
Context li li-filter li-ip-filter string entry number match dst-ip
Treedst-ip
Introduced19.10.R1

Platforms

All

dst-port
Synopsis Enter the dst-port context
Context li li-filter li-ip-filter string entry number match dst-port
Treedst-port
Introduced19.10.R1

Platforms

All

eq number
Synopsis Condition on equality to specified value
Contextli li-filter li-ip-filter string entry number match dst-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

gt number
Synopsis Condition on being greater than the specified value
Contextli li-filter li-ip-filter string entry number match dst-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

lt number
Synopsis Condition on being less than the specified value
Contextli li-filter li-ip-filter string entry number match dst-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

range
Synopsis Enable the range context
Context li li-filter li-ip-filter string entry number match dst-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

protocol (number | keyword)
Synopsis IP protocol to match
Context li li-filter li-ip-filter string entry number match protocol (number | keyword)
Treeprotocol
Range0 to 255
Optionstcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp
Introduced 19.10.R1

Platforms

All

src-ip
Synopsis Enter the src-ip context
Context li li-filter li-ip-filter string entry number match src-ip
Treesrc-ip
Introduced19.10.R1

Platforms

All

src-port
Synopsis Enter the src-port context
Context li li-filter li-ip-filter string entry number match src-port
Treesrc-port
Introduced19.10.R1

Platforms

All

eq number
Synopsis Condition on equality to specified value
Contextli li-filter li-ip-filter string entry number match src-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

gt number
Synopsis Condition on being greater than the specified value
Contextli li-filter li-ip-filter string entry number match src-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

lt number
Synopsis Condition on being less than the specified value
Contextli li-filter li-ip-filter string entry number match src-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

range
Synopsis Enable the range context
Context li li-filter li-ip-filter string entry number match src-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

li-ipv6-filter [li-filter-name] string
Synopsis Enter the li-ipv6-filter list instance
Contextli li-filter li-ipv6-filter string
Treeli-ipv6-filter

Description

Commands in this context create LI IPv6 filter lists, which can be used to create confidential IPv6 filter based LI source entries.

The LI IPv6 filter entries are merged into normal IPv6 filters configured with the li li-filter associations and li li-filter reserved-block commands. However, the LI IPv6 filter entries are visible only to users with LI permissions.

Introduced19.10.R1

Platforms

All

[li-filter-name] string
Synopsis LI filter name
Contextli li-filter li-ipv6-filter string
Treeli-ipv6-filter

Description

This command specifies the LI filter name. Filter names cannot start with an underscore character (for example, “_my-filter”) and cannot use the name “default”.

String Length1 to 32

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

entry [li-entry-id] number
Synopsis Enter the entry list instance
Context li li-filter li-ipv6-filter string entry number
Treeentry

Description

Commands in this context configure an entry for the LI filter. 

Multiple entries can be created using unique entry ID numbers within the filter.  An entry in an LI filter always has an implicit action of “forward”. LI filter entries can be used as LI source entries.

The entry numbers for LI filters serve only as keys for managing the entries (deleting entries, and so on). The order of the LI filter entries is not guaranteed to match the entry numbers and the software may reorder entries. Operators must therefore use LI entries in such a way that their relative order is not important.

Entries removed from the filter are immediately removed from all services or network ports where the associated filter is applied.

Introduced19.10.R1

Platforms

All

[li-entry-id] number
Synopsis LI filter entry ID
Context li li-filter li-ipv6-filter string entry number
Treeentry
Range1 to 65535

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

match
Synopsis Enter the match context
Context li li-filter li-ipv6-filter string entry number match
Treematch

Description

Commands in this context configure match criteria for the filter entry. If more than one match criteria (within one match statement) are configured, all criteria must be satisfied (and function) for a match to occur.

A match context may consist of multiple match criteria, but multiple match statements cannot be configured per entry.

Introduced19.10.R1

Platforms

All

dst-ip
Synopsis Enter the dst-ip context
Context li li-filter li-ipv6-filter string entry number match dst-ip
Treedst-ip
Introduced19.10.R1

Platforms

All

dst-port
Synopsis Enter the dst-port context
Context li li-filter li-ipv6-filter string entry number match dst-port
Treedst-port
Introduced19.10.R1

Platforms

All

eq number
Synopsis Condition on equality to specified value
Contextli li-filter li-ipv6-filter string entry number match dst-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

gt number
Synopsis Condition on being greater than the specified value
Contextli li-filter li-ipv6-filter string entry number match dst-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

lt number
Synopsis Condition on being less than the specified value
Contextli li-filter li-ipv6-filter string entry number match dst-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

range
Synopsis Enable the range context
Context li li-filter li-ipv6-filter string entry number match dst-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

next-header (number | keyword)
Synopsis IP protocol to match
Context li li-filter li-ipv6-filter string entry number match next-header (number | keyword)
Treenext-header
Range0 to 255
Optionstcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp
Introduced 19.10.R1

Platforms

All

src-ip
Synopsis Enter the src-ip context
Context li li-filter li-ipv6-filter string entry number match src-ip
Treesrc-ip
Introduced19.10.R1

Platforms

All

src-port
Synopsis Enter the src-port context
Context li li-filter li-ipv6-filter string entry number match src-port
Treesrc-port
Introduced19.10.R1

Platforms

All

eq number
Synopsis Condition on equality to specified value
Contextli li-filter li-ipv6-filter string entry number match src-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

gt number
Synopsis Condition on being greater than the specified value
Contextli li-filter li-ipv6-filter string entry number match src-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

lt number
Synopsis Condition on being less than the specified value
Contextli li-filter li-ipv6-filter string entry number match src-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

range
Synopsis Enable the range context
Context li li-filter li-ipv6-filter string entry number match src-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

li-mac-filter [li-filter-name] string
Synopsis Enter the li-mac-filter list instance
Contextli li-filter li-mac-filter string
Treeli-mac-filter

Description

Commands in this context configure LI MAC filter lists, which can be used to create confidential MAC filter based LI source entries. 

The LI MAC filter entries are merged into normal MAC filters as configured using the li-filter associations and li-filter reserved-block commands. The LI MAC filter entries are visible only to users with LI permissions.

Introduced19.10.R1

Platforms

All

[li-filter-name] string
Synopsis LI filter name
Contextli li-filter li-mac-filter string
Treeli-mac-filter

Description

This command specifies the LI filter name. Filter names cannot start with an underscore character (for example, “_my-filter”) and cannot use the name “default”.

String Length1 to 32

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

entry [li-entry-id] number
Synopsis Enter the entry list instance
Context li li-filter li-mac-filter string entry number
Treeentry

Description

Commands in this context configure an entry for the LI filter. 

Multiple entries can be created using unique entry ID numbers within the filter.  An entry in an LI filter always has an implicit action of “forward”. LI filter entries can be used as LI source entries.

The entry numbers for LI filters serve only as keys for managing the entries (deleting entries, and so on). The order of the LI filter entries is not guaranteed to match the entry numbers and the software may reorder entries. Operators must therefore use LI entries in such a way that their relative order is not important.

Entries removed from the filter are immediately removed from all services or network ports where the associated filter is applied.

Introduced19.10.R1

Platforms

All

[li-entry-id] number
Synopsis LI filter entry ID
Context li li-filter li-mac-filter string entry number
Treeentry
Range1 to 65535

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

match
Synopsis Enter the match context
Context li li-filter li-mac-filter string entry number match
Treematch

Description

Commands in this context configure match criteria for the filter entry. If more than one match criteria (within one match statement) is configured, all criteria must be satisfied (and function) for a match to occur.

A match context may consist of multiple match criteria, but multiple match statements cannot be configured per entry.

Introduced19.10.R1

Platforms

All

dst-mac
Synopsis Enable the dst-mac context
Context li li-filter li-mac-filter string entry number match dst-mac
Treedst-mac
Introduced19.10.R1

Platforms

All

frame-type keyword
Synopsis Frame type for MAC filter match
Context li li-filter li-mac-filter string entry number match frame-type keyword
Treeframe-type

Description

This command specifies the frame type for MAC filter entry matching. A filter can be edited even if an LI source references an entry in the filter.

Options802dot3, 802dot2-llc, 802dot2-snap, ethernet-ii
Default 802dot3
Introduced19.10.R1

Platforms

All

outer-tag number
Synopsis Outer tag for the QinQ SAP for filter match
Contextli li-filter li-mac-filter string entry number match outer-tag number
Treeouter-tag

Description

This command configures the outer-tag to match on and must be used in conjunction with match criteria SAP in order for the entry match to activate.

The match criteria SAP must be an exact match with the QinQ configured on the Epipe or VPLS service (for example 1/1/1:1.*, where the outer tag (C-tag) must be "*"). This feature mandates the provisioning of an associated outer-tag (example, 1), to be able to match on the QinQ packet. This example would perform LI on 1/1/1:1.1 on a 1/1/1:1.* SAP.

Range1 to 4094
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

sap string
Synopsis QinQ SAP for filter match
Context li li-filter li-mac-filter string entry number match sap string
Treesap

Description

This command specifies the QinQ SAP to match from the Epipe or VPLS service, where the S-tag must be a value and the outer tag (C-tag) must be of type *. This filter match is used in conjunction with match criteria outer-tag, where the outer-tag must also be provisioned for the entry match on the QinQ packet to activate.

The match criteria SAP must be an exact match with the QinQ configured on the Epipe or VPLS service (for example 1/1/1:1.*, where the outer tag (C-tag) must be "*"). An associated outer-tag (example, 1) must be provisioned to match on the QinQ packet. This example would perform LI on 1/1/1:1.1 on a 1/1/1:1.* SAP.

String Length1 to 45
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

src-mac
Synopsis Enable the src-mac context
Context li li-filter li-mac-filter string entry number match src-mac
Treesrc-mac
Introduced19.10.R1

Platforms

All

lock-filter keyword
Synopsis Lock state of LI filters
Context li li-filter lock-filter keyword
Treelock-filter
Optionslock, unlock
Default lock
Introduced19.10.R1

Platforms

All

reserved-block [block-name] string
Synopsis Enter the reserved-block list instance
Contextli li-filter reserved-block string
Treereserved-block
Max. Instances8
Introduced19.10.R1

Platforms

All

[block-name] string
Synopsis Object uniquely identifying an LI reserved block
Contextli li-filter reserved-block string
Treereserved-block
String Length1 to 32

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

entry-range
Synopsis Enable the entry-range context
Contextli li-filter reserved-block string entry-range
Treeentry-range
Introduced19.10.R1

Platforms

All

li-source [service-name] string

Synopsis Enter the li-source list instance
Contextli li-source string
Treeli-source
Introduced19.10.R1

Platforms

All

[service-name] string
Synopsis Administrative service name
Context li li-source string
Treeli-source
String Length1 to 64

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of mirror service
Contextli li-source string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced19.10.R1

Platforms

All

li-ip-filter [li-filter-name] reference
Synopsis Enter the li-ip-filter list instance
Contextli li-source string li-ip-filter reference
Treeli-ip-filter
Introduced19.10.R1

Platforms

All

entry [li-entry-id] reference
Synopsis Enter the entry list instance
Context li li-source string li-ip-filter reference entry reference
Treeentry
Min. Instances1
Introduced19.10.R1

Platforms

All

intercept-id number
Synopsis Intercept ID of the traffic flow
Context li li-source string li-ip-filter reference entry reference intercept-id number
Treeintercept-id

Description

This command configures the intercept ID that is inserted into the packet header for all mirrrored packets of the associated LI source entry. This intercept ID can be used (for example by a downstream LI gateway) to identify the particular LI session to which the packet belongs.

For LI source entries, when the configure mirror mirror-dest encap layer-3-encap header-type command is configured with ip-udp-shim routable encap, an intercept-id field (as part of the routable encap) is always present in the mirrored packets. If there is no intercept ID configured for an LI source entry, the default value is inserted.

When the mirror service is configured with ip-gre routable encap under the header-type command, no intercept ID is inserted and none should be specified against the LI source entries.

Range1 to 1073741823
Introduced19.10.R1

Platforms

All

session-id number
Synopsis Session ID of the traffic flow
Context li li-source string li-ip-filter reference entry reference session-id number
Treesession-id

Description

This command configures the session ID that is inserted into the packet header for all mirrored packets of the associated LI source entry. This session ID can be used (for example by a downstream LI gateway) to identify the particular LI session to which the packet belongs.

The session ID is only valid and used for mirror services that are configured with ip-udp-shim routable encap under the configure mirror mirror-dest encap layer-3-encap header-type command. For all types of LI source entries, when the mirror service is configured with ip-udp-shim routable encap, a session ID field (as part of the routable encap) is always present in the mirrored packets. If no session ID is configured for an LI source entry, the default value is inserted.

When a mirror service is configured with ip-gre routable encap under the header-type command, no session ID is inserted and none is specified against the LI source entries.

Range1 to 4294967295
Introduced19.10.R1

Platforms

All

li-ipv6-filter [li-filter-name] reference
Synopsis Enter the li-ipv6-filter list instance
Contextli li-source string li-ipv6-filter reference
Treeli-ipv6-filter
Introduced19.10.R1

Platforms

All

entry [li-entry-id] reference
Synopsis Enter the entry list instance
Context li li-source string li-ipv6-filter reference entry reference
Treeentry
Min. Instances1
Introduced19.10.R1

Platforms

All

intercept-id number
Synopsis Intercept ID of the traffic flow
Context li li-source string li-ipv6-filter reference entry reference intercept-id number
Treeintercept-id

Description

This command configures the intercept ID that is inserted into the packet header for all mirrrored packets of the associated LI source entry. This intercept ID can be used (for example by a downstream LI gateway) to identify the particular LI session to which the packet belongs.

For LI source entries, when the configure mirror mirror-dest encap layer-3-encap header-type command is configured with ip-udp-shim routable encap, an intercept-id field (as part of the routable encap) is always present in the mirrored packets. If there is no intercept ID configured for an LI source entry, the default value is inserted.

When the mirror service is configured with ip-gre routable encap under the header-type command, no intercept ID is inserted and none should be specified against the LI source entries.

Range1 to 1073741823
Introduced19.10.R1

Platforms

All

session-id number
Synopsis Session ID of the traffic flow
Context li li-source string li-ipv6-filter reference entry reference session-id number
Treesession-id

Description

This command configures the session ID that is inserted into the packet header for all mirrored packets of the associated LI source entry. This session ID can be used (for example by a downstream LI gateway) to identify the particular LI session to which the packet belongs.

The session ID is only valid and used for mirror services that are configured with ip-udp-shim routable encap under the configure mirror mirror-dest encap layer-3-encap header-type command. For all types of LI source entries, when the mirror service is configured with ip-udp-shim routable encap, a session ID field (as part of the routable encap) is always present in the mirrored packets. If no session ID is configured for an LI source entry, the default value is inserted.

When a mirror service is configured with ip-gre routable encap under the header-type command, no session ID is inserted and none is specified against the LI source entries.

Range1 to 4294967295
Introduced19.10.R1

Platforms

All

li-mac-filter [li-filter-name] reference
Synopsis Enter the li-mac-filter list instance
Contextli li-source string li-mac-filter reference
Treeli-mac-filter
Introduced19.10.R1

Platforms

All

entry [li-entry-id] reference
Synopsis Enter the entry list instance
Context li li-source string li-mac-filter reference entry reference
Treeentry
Min. Instances1
Introduced19.10.R1

Platforms

All

intercept-id number
Synopsis Intercept ID of the traffic flow
Context li li-source string li-mac-filter reference entry reference intercept-id number
Treeintercept-id

Description

This command configures the intercept ID that is inserted into the packet header for all mirrrored packets of the associated LI source entry. This intercept ID can be used (for example by a downstream LI gateway) to identify the particular LI session to which the packet belongs.

For LI source entries, when the configure mirror mirror-dest encap layer-3-encap header-type command is configured with ip-udp-shim routable encap, an intercept-id field (as part of the routable encap) is always present in the mirrored packets. If there is no intercept ID configured for an LI source entry, the default value is inserted.

When the mirror service is configured with ip-gre routable encap under the header-type command, no intercept ID is inserted and none should be specified against the LI source entries.

Range1 to 1073741823
Introduced19.10.R1

Platforms

All

session-id number
Synopsis Session ID of the traffic flow
Context li li-source string li-mac-filter reference entry reference session-id number
Treesession-id

Description

This command configures the session ID that is inserted into the packet header for all mirrored packets of the associated LI source entry. This session ID can be used (for example by a downstream LI gateway) to identify the particular LI session to which the packet belongs.

The session ID is only valid and used for mirror services that are configured with ip-udp-shim routable encap under the configure mirror mirror-dest encap layer-3-encap header-type command. For all types of LI source entries, when the mirror service is configured with ip-udp-shim routable encap, a session ID field (as part of the routable encap) is always present in the mirrored packets. If no session ID is configured for an LI source entry, the default value is inserted.

When a mirror service is configured with ip-gre routable encap under the header-type command, no session ID is inserted and none is specified against the LI source entries.

Range1 to 4294967295
Introduced19.10.R1

Platforms

All

nat
Synopsis Enter the nat context
Context li li-source string nat
Treenat
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dslite [router-instance] string b4 string
Synopsis Enter the dslite list instance
Contextli li-source string nat dslite string b4 string
Treedslite
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[router-instance] string
Synopsis Name of the service
Context li li-source string nat dslite string b4 string
Treedslite
String Length1 to 64

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

b4 string
Synopsis B4 prefix of the subscriber
Context li li-source string nat dslite string b4 string
Treedslite

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

intercept-id number
Synopsis The intercept id of the traffic flow
Context li li-source string nat dslite string b4 string intercept-id number
Treeintercept-id
Range1 to 4294967295
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

session-id number
Synopsis The session id of the traffic flow
Context li li-source string nat dslite string b4 string session-id number
Treesession-id
Range1 to 4294967295
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ethernet-header
Synopsis Enter the ethernet-header context
Contextli li-source string nat ethernet-header
Treeethernet-header
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

type number
Synopsis Ethertype of the ethernet encapsulation
Contextli li-source string nat ethernet-header type number
Treetype
Range1536 to 65535
Default1792
Introduced 19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

l2-aware [subscriber-id] string
Synopsis Enter the l2-aware list instance
Contextli li-source string nat l2-aware string
Treel2-aware
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[subscriber-id] string
Synopsis The string identifying the subscribe
Context li li-source string nat l2-aware string
Treel2-aware
String Length1 to 64

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

intercept-id number
Synopsis The intercept id of the traffic flow
Context li li-source string nat l2-aware string intercept-id number
Treeintercept-id
Range1 to 4294967295
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

session-id number
Synopsis The session id of the traffic flow
Context li li-source string nat l2-aware string session-id number
Treesession-id
Range1 to 4294967295
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

nat44 [router-instance] string ip string
Synopsis Enter the nat44 list instance
Context li li-source string nat nat44 string ip string
Treenat44
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[router-instance] string
Synopsis Name of the service
Context li li-source string nat nat44 string ip string
Treenat44
String Length1 to 64

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip string
Synopsis IP address of the subscriber
Context li li-source string nat nat44 string ip string
Treenat44

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

intercept-id number
Synopsis The intercept id of the traffic flow
Context li li-source string nat nat44 string ip string intercept-id number
Treeintercept-id
Range1 to 4294967295
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

session-id number
Synopsis The session id of the traffic flow
Context li li-source string nat nat44 string ip string session-id number
Treesession-id
Range1 to 4294967295
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

nat64 [router-instance] string ip string
Synopsis Enter the nat64 list instance
Context li li-source string nat nat64 string ip string
Treenat64
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[router-instance] string
Synopsis Name of the service
Context li li-source string nat nat64 string ip string
Treenat64
String Length1 to 64

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip string
Synopsis IP prefix of the subscriber
Context li li-source string nat nat64 string ip string
Treenat64

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

intercept-id number
Synopsis The intercept id of the traffic flow
Context li li-source string nat nat64 string ip string intercept-id number
Treeintercept-id
Range1 to 4294967295
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

session-id number
Synopsis The session id of the traffic flow
Context li li-source string nat nat64 string ip string session-id number
Treesession-id
Range1 to 4294967295
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

port [port-id] string
Synopsis Enter the port list instance
Context li li-source string port string
Treeport
Introduced20.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

[port-id] string
Synopsis Port ID
Contextli li-source string port string
Treeport

Notes

This element is part of a list key.

Introduced20.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

egress boolean
Synopsis Perform lawful intercept on egress traffic
Contextli li-source string port string egress boolean
Treeegress

Description

When configured to true, the router allows lawful intercept on egress traffic. This command configures packets that egress the SAP to be mirrored. Egress packets are mirrored to the mirror destination after egress packet modification.

Defaultfalse
Introduced20.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ingress boolean
Synopsis Perform lawful intercept on ingress traffic
Contextli li-source string port string ingress boolean
Treeingress

Description

When configured to true, the router allows lawful intercept on ingress traffic. This command configures packets that ingress the SAP to be mirrored. Ingress packets are mirrored to the mirror destination before ingress packet modification.

Defaultfalse
Introduced20.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

sap [sap-id] string
Synopsis Enter the sap list instance
Context li li-source string sap string
Treesap

Description

Commands in this context create a service access point (SAP) within an LI configuration. The specified SAP must define a FastE, GigE, or XGigE, or XGigE access port with a dot1q, null, or q-in-q encapsulation type.

Introduced19.10.R1

Platforms

All

[sap-id] string
Synopsis SAP ID
Contextli li-source string sap string
Treesap

Description

This command specifies the physical port identifier portion of the SAP definition.

String Length1 to 45

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

egress boolean
Synopsis Perform lawful intercept on egress traffic
Contextli li-source string sap string egress boolean
Treeegress

Description

When configured to true, the router allows lawful intercept on egress traffic. This command configures packets that egress the SAP to be mirrored. Egress packets are mirrored to the mirror destination after egress packet modification.

Defaultfalse
Introduced19.10.R1

Platforms

All

ingress boolean
Synopsis Perform lawful intercept on ingress traffic
Contextli li-source string sap string ingress boolean
Treeingress

Description

When configured to true, the router allows lawful intercept on ingress traffic. This command configures packets that ingress the SAP to be mirrored. Ingress packets are mirrored to the mirror destination before ingress packet modification.

Defaultfalse
Introduced19.10.R1

Platforms

All

intercept-id number
Synopsis Intercept ID of the traffic flow
Context li li-source string sap string intercept-id number
Treeintercept-id

Description

This command configures the intercept ID that is inserted into the packet header for all mirrrored packets of the associated LI source entry. This intercept ID can be used (for example by a downstream LI gateway) to identify the particular LI session to which the packet belongs.

For LI source entries, when the configure mirror mirror-dest encap layer-3-encap header-type command is configured with ip-udp-shim routable encap, an intercept-id field (as part of the routable encap) is always present in the mirrored packets. If there is no intercept ID configured for an LI source entry, the default value is inserted.

When the mirror service is configured with ip-gre routable encap under the header-type command, no intercept ID is inserted and none should be specified against the LI source entries.

Range1 to 1073741823
Introduced19.10.R1

Platforms

All

session-id number
Synopsis Session ID of the traffic flow
Context li li-source string sap string session-id number
Treesession-id

Description

This command configures the session ID that is inserted into the packet header for all mirrored packets of the associated LI source entry. This session ID can be used (for example by a downstream LI gateway) to identify the particular LI session to which the packet belongs.

The session ID is only valid and used for mirror services that are configured with ip-udp-shim routable encap under the configure mirror mirror-dest encap layer-3-encap header-type command. For all types of LI source entries, when the mirror service is configured with ip-udp-shim routable encap, a session ID field (as part of the routable encap) is always present in the mirrored packets. If no session ID is configured for an LI source entry, the default value is inserted.

When a mirror service is configured with ip-gre routable encap under the header-type command, no session ID is inserted and none is specified against the LI source entries.

Range1 to 4294967295
Introduced19.10.R1

Platforms

All

subscriber [subscriber-id] string
Synopsis Enter the subscriber list instance
Contextli li-source string subscriber string
Treesubscriber

Description

Commands in this context add hosts of a subscriber to a mirroring service.

Introduced19.10.R1

Platforms

All

[subscriber-id] string
Synopsis Subscriber ID
Contextli li-source string subscriber string
Treesubscriber
String Length1 to 64

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

egress boolean
Synopsis Perform lawful intercept on egress traffic
Contextli li-source string subscriber string egress boolean
Treeegress

Description

When configured to true, the router allows lawful intercept on egress traffic. This command configures packets that egress the SAP to be mirrored. Egress packets are mirrored to the mirror destination after egress packet modification.

Defaultfalse
Introduced19.10.R1

Platforms

All

fc keyword
Synopsis Forwarding classes to be mirrored
Context li li-source string subscriber string fc keyword
Treefc

Description

This command specifies the name of the forwarding class with which to associate LI traffic. The forwarding class name must already be defined within the system.

If the FC name is not already defined, an error is returned and this command has no effect. If the FC name is defined, the forwarding class associated with the FC name overrides the default forwarding class.

Optionsbe, l2, af, l1, h2, ef, h1, nc
Max. Instances 8
Introduced19.10.R1

Platforms

All

host-type keyword
Synopsis Subscriber host type to be monitored
Context li li-source string subscriber string host-type keyword
Treehost-type

Description

This command specifies the host type for LI.

Optionsipoe, ppp
Introduced 19.10.R1

Platforms

All

ingress boolean
Synopsis Perform lawful intercept on ingress traffic
Contextli li-source string subscriber string ingress boolean
Treeingress

Description

When configured to true, the router allows lawful intercept on ingress traffic. This command configures packets that ingress the SAP to be mirrored. Ingress packets are mirrored to the mirror destination before ingress packet modification.

Defaultfalse
Introduced19.10.R1

Platforms

All

intercept-id number
Synopsis Intercept ID of the traffic flow
Context li li-source string subscriber string intercept-id number
Treeintercept-id

Description

This command configures the intercept ID that is inserted into the packet header for all mirrrored packets of the associated LI source entry. This intercept ID can be used (for example by a downstream LI gateway) to identify the particular LI session to which the packet belongs.

For LI source entries, when the configure mirror mirror-dest encap layer-3-encap header-type command is configured with ip-udp-shim routable encap, an intercept-id field (as part of the routable encap) is always present in the mirrored packets. If there is no intercept ID configured for an LI source entry, the default value is inserted.

When the mirror service is configured with ip-gre routable encap under the header-type command, no intercept ID is inserted and none should be specified against the LI source entries.

Range1 to 1073741823
Introduced19.10.R1

Platforms

All

ip-address string
Synopsis IP address of the subscriber
Context li li-source string subscriber string ip-address string
Treeip-address

Description

This command specifies the service IP address (system IP address) of the remote device sending LI traffic. If 0.0.0.0 is specified, any remote router is allowed to send to this service.

Notes

The following elements are part of a choice: (ip-address, mac-address, and sap-id) or sla-profile.

Introduced19.10.R1

Platforms

All

ip-family keyword
Synopsis IP family for LI
Context li li-source string subscriber string ip-family keyword
Treeip-family

Description

This command specifies the IP family for LI.

Optionsipv4, ipv6
Introduced 19.10.R1

Platforms

All

mac-address string
Synopsis The source MAC address
Context li li-source string subscriber string mac-address string
Treemac-address

Description

This command specifies a MAC address when defining a static host.

Multiple static hosts may be configured with the same MAC address because each definition is distinguished by a unique IP address.

Notes

The following elements are part of a choice: (ip-address, mac-address, and sap-id) or sla-profile.

Introduced19.10.R1

Platforms

All

sap-id string
Synopsis SAP ID
Contextli li-source string subscriber string sap-id string
Treesap-id
String Length1 to 45

Notes

The following elements are part of a choice: (ip-address, mac-address, and sap-id) or sla-profile.

Introduced19.10.R1

Platforms

All

session-id number
Synopsis Session ID of the traffic flow
Context li li-source string subscriber string session-id number
Treesession-id

Description

This command configures the session ID that is inserted into the packet header for all mirrored packets of the associated LI source entry. This session ID can be used (for example by a downstream LI gateway) to identify the particular LI session to which the packet belongs.

The session ID is only valid and used for mirror services that are configured with ip-udp-shim routable encap under the configure mirror mirror-dest encap layer-3-encap header-type command. For all types of LI source entries, when the mirror service is configured with ip-udp-shim routable encap, a session ID field (as part of the routable encap) is always present in the mirrored packets. If no session ID is configured for an LI source entry, the default value is inserted.

When a mirror service is configured with ip-gre routable encap under the header-type command, no session ID is inserted and none is specified against the LI source entries.

Range1 to 4294967295
Introduced19.10.R1

Platforms

All

sla-profile string
Synopsis SLA profile
Contextli li-source string subscriber string sla-profile string
Treesla-profile

Description

This command specifies an SLA profile name.

Each host of a subscriber can use a different SLA profile. This option allows interception of only the hosts using the specified SLA profile. In some deployments, SLA profiles are assigned per type of traffic. There can be, for example, a specific SLA profile for voice traffic (which could be used for all SIP hosts).

String Length1 to 32

Notes

The following elements are part of a choice: (ip-address, mac-address, and sap-id) or sla-profile.

Introduced19.10.R1

Platforms

All

wlan-gw-dsm-ue [mac] string
Synopsis Enter the wlan-gw-dsm-ue list instance
Contextli li-source string wlan-gw-dsm-ue string
Treewlan-gw-dsm-ue
Introduced19.10.R1

Platforms

All

log

Synopsis Enter the log context
Context li log
Treelog
Introduced19.10.R1

Platforms

All

log-id [name] string
Synopsis Enter the log-id list instance
Contextli log log-id string
Treelog-id
Max. Instances30
Introduced19.10.R1

Platforms

All

[name] string
Synopsis Log ID
Contextli log log-id string
Treelog-id
String Length1 to 64

Notes

This element is part of a list key.

Introduced21.2.R1

Platforms

All

admin-state keyword
Synopsis The administrative state of the log
Context li log log-id string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced19.10.R1

Platforms

All

destination
Synopsis Enter the destination context
Context li log log-id string destination
Treedestination

Description

Commands in this context specify where log event data is to be sent.

Introduced19.10.R1

Platforms

All

memory
Synopsis Enable the memory context
Context li log log-id string destination memory
Treememory

Description

Commands in this context configure log events directed to a memory file. A memory file is a circular buffer. When the file is full, each new entry replaces the oldest entry in the log.

Notes

The following elements are part of a choice: memory, netconf, or snmp.

Introduced19.10.R1

Platforms

All

max-entries number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNumber of events stored in this memory log
Contextli log log-id string destination memory max-entries number
Treemax-entries
Range50 to 1024
Default100
Introduced 19.10.R1

Platforms

All

netconf
Synopsis Enable the netconf context
Context li log log-id string destination netconf
Treenetconf

Description

Commands in this context configure log events directed to a NETCONF session as notifications. A NETCONF client can subscribe to a NETCONF log using the configured netconf-stream for the log in a subscription request. One or more NETCONF sessions can subscribe to a NETCONF log or stream.

Notes

The following elements are part of a choice: memory, netconf, or snmp.

Introduced20.2.R1

Platforms

All

max-entries number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisMaximum number of events stored in the NETCONF log
Contextli log log-id string destination netconf max-entries number
Treemax-entries

Description

This command configures the maximum number of events stored in the NETCONF log.

If this setting needs to be modified, the log ID must be removed and re-created.

Range50 to 1024
Default100
Introduced 20.2.R1

Platforms

All

snmp
Synopsis Enable the snmp context
Context li log log-id string destination snmp
Treesnmp

Description

Commands in this context configure log events directed to the snmp-trap-group associated with the log ID. A local circular memory log is maintained for SNMP logs.

Notes

The following elements are part of a choice: memory, netconf, or snmp.

Introduced19.10.R1

Platforms

All

max-entries number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNumber of events stored in this snmp log
Contextli log log-id string destination snmp max-entries number
Treemax-entries
Range50 to 1024
Default100
Introduced 19.10.R1

Platforms

All

send-using-vprn string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVPRN to use to send SNMP notifications
Contextli log log-id string destination snmp send-using-vprn string
Treesend-using-vprn

Description

This command configures lawful intercept (LI) SNMP notifications to transmit in a VPRN. This configuration is useful when doing management of LI via a VPRN.

The specified VPRN service must exist. After an LI log is configured using this command, the VPRN service cannot be deleted without removing the LI log ID.

When unconfigured, the outgoing routing instance of LI SNMP notifications is determined by the configure log route-preference command.

String Length1 to 64
Introduced23.10.R1

Platforms

All

filter string
Synopsis Event filter ID to associate with log ID configuration
Contextli log log-id string filter string
Treefilter
String Length1 to 64
Introduced19.10.R1

Platforms

All

source
Synopsis Enter the source context
Context li log log-id string source
Treesource
Introduced19.10.R1

Platforms

All

li boolean
Synopsis Event stream for events configured for LI activities
Contextli log log-id string source li boolean
Treeli
Defaultfalse
Introduced19.10.R1

Platforms

All

time-format keyword
Synopsis Time zone to display date and time
Context li log log-id string time-format keyword
Treetime-format
Optionsutc, local
Default utc
Introduced19.10.R1

Platforms

All

mirror-dest-reservation

Synopsis Enter the mirror-dest-reservation context
Contextli mirror-dest-reservation
Treemirror-dest-reservation

Description

Commands in this context configure the attributes to reserve mirror destination resources.

Introduced19.10.R1

Platforms

All

end number
Synopsis Upper bound of the mirror destination ID
Contextli mirror-dest-reservation end number
Treeend
Range1 to 2147483647
Introduced19.10.R1

Platforms

All

mirror-dest-template [name] string

Synopsis Enter the mirror-dest-template list instance
Contextli mirror-dest-template string
Treemirror-dest-template
Max. Instances8
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis Mirror destination template name
Context li mirror-dest-template string
Treemirror-dest-template
String Length1 to 32

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

layer-3-encap
Synopsis Enter the layer-3-encap context
Contextli mirror-dest-template string layer-3-encap
Treelayer-3-encap
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

encap-type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisThe header type of the layer 3 encapsulation.
Contextli mirror-dest-template string layer-3-encap encap-type keyword
Treeencap-type
Optionsip-udp-shim, ip-gre
Default ip-udp-shim
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

udp
Synopsis Enter the udp context
Context li mirror-dest-template string layer-3-encap udp
Treeudp
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEncapsulation type supported by the mirror service
Contextli mirror-dest-template string type keyword
Treetype
Optionsether, ip-only
Default ether
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

nat

Synopsis Enter the nat context
Context li nat
Treenat
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

use-outside-ip-address boolean
Synopsis Report outside IP address for L2-Aware NAT subscribers
Contextli nat use-outside-ip-address boolean
Treeuse-outside-ip-address
Defaultfalse
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

sci

Synopsis Enter the sci context
Context li sci
Treesci
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

pfcp-li-shared-key string
Synopsis Key used to encrypt and decrypt exchanged LI PFCP IEs
Contextli sci pfcp-li-shared-key string
Treepfcp-li-shared-key

Description

This command configures the shared secret key that the SR OS uses in its role as a user plane (UP) to the MAG-c. The UP uses the shared secret key to encrypt and decrypt the LI PFCP IEs it exchanges with the MAG-c. The SR OS UP and the MAG-c must use matching secret keys. The system only accepts a secret key configured as a printable string.

String Length1 to 199
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

x-interfaces

Synopsis Enter the x-interfaces context
Contextli x-interfaces
Treex-interfaces
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

admin-state keyword
Synopsis Administrative state of the x-interfaces
Contextli x-interfaces admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

correlation-id
Synopsis Enter the correlation-id context
Contextli x-interfaces correlation-id
Treecorrelation-id
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

ipoe keyword
Synopsis RADIUS accounting ID type for subscriber correlation
Contextli x-interfaces correlation-id ipoe keyword
Treeipoe
Optionsradius-host-acct-id, radius-queue-acct-id, radius-session-acct-id
Defaultradius-host-acct-id
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

pppoe keyword
Synopsis RADIUS accounting ID type for subscriber correlation
Contextli x-interfaces correlation-id pppoe keyword
Treepppoe
Optionsradius-host-acct-id, radius-queue-acct-id, radius-session-acct-id
Defaultradius-host-acct-id
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

lic [name] string
Synopsis Enter the lic list instance
Context li x-interfaces lic string
Treelic
Max. Instances18
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

[name] string
Synopsis LIC name
Contextli x-interfaces lic string
Treelic
String Length1 to 32

Notes

This element is part of a list key.

Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

authentication
Synopsis Enter the authentication context
Contextli x-interfaces lic string authentication
Treeauthentication
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

ipv4
Synopsis Enter the ipv4 context
Context li x-interfaces lic string ipv4
Treeipv4
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the LIC
Context li x-interfaces lic string ipv4 ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeip-address
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

port number
Synopsis TCP port associated with the LIC
Context li x-interfaces lic string port number
Treeport
Range0 to 65535
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

router-instance string
Synopsis Virtual router instance used by the X-interfaces
Contextli x-interfaces lic string router-instance string
Treerouter-instance
String Length0 to 64
Default
Introduced 21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

user-db string
Synopsis Location of the data-trigger host for the LIC
Contextli x-interfaces user-db string
Treeuser-db
String Length1 to 32
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

x1
Synopsis Enter the x1 context
Context li x-interfaces x1
Treex1
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

ipv4
Synopsis Enter the ipv4 context
Context li x-interfaces x1 ipv4
Treeipv4
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

local-address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis X1 interface IP address
Context li x-interfaces x1 ipv4 local-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treelocal-address
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

x2
Synopsis Enter the x2 context
Context li x-interfaces x2
Treex2
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

ipv4
Synopsis Enter the ipv4 context
Context li x-interfaces x2 ipv4
Treeipv4
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

local-address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis X2 interface IP address
Context li x-interfaces x2 ipv4 local-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treelocal-address
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

timeouts
Synopsis Enter the timeouts context
Context li x-interfaces x2 timeouts
Treetimeouts
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

request number
Synopsis Tx2-normal timeout
Context li x-interfaces x2 timeouts request number
Treerequest
Range5 to 30
Unitsseconds
Default 5
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

x3
Synopsis Enter the x3 context
Context li x-interfaces x3
Treex3
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

alarms
Synopsis Enter the alarms context
Context li x-interfaces x3 alarms
Treealarms
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

cpu-alarm
Synopsis Enter the cpu-alarm context
Context li x-interfaces x3 alarms cpu-alarm
Treecpu-alarm
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

memory-alarm
Synopsis Enter the memory-alarm context
Contextli x-interfaces x3 alarms memory-alarm
Treememory-alarm
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

throughput-alarm
Synopsis Enter the throughput-alarm context
Contextli x-interfaces x3 alarms throughput-alarm
Treethroughput-alarm
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

ipv4
Synopsis Enter the ipv4 context
Context li x-interfaces x3 ipv4
Treeipv4
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

local-address-range
Synopsis Enter the local-address-range context
Contextli x-interfaces x3 ipv4 local-address-range
Treelocal-address-range
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

li-group number
Synopsis ISA group of the X3 interface
Context li x-interfaces x3 li-group number
Treeli-group
Range1 to 4
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

lic-peers [name] reference
Synopsis Add a list entry for lic-peers
Contextli x-interfaces x3 lic-peers reference
Treelic-peers
Max. Instances16
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

session-limit number
Synopsis Maximum number of X3 sessions initiated to the LIC
Contextli x-interfaces x3 session-limit number
Treesession-limit
Range1 to 32
Default32
Introduced 21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

timeouts
Synopsis Enter the timeouts context
Context li x-interfaces x3 timeouts
Treetimeouts
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

request number
Synopsis Tx3-normal timeout
Context li x-interfaces x3 timeouts request number
Treerequest
Range5 to 30
Unitsseconds
Default 5
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e