service commands

configure 
service 
apply-groups reference
apply-groups-exclude reference
cpipe string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
customer reference
description string
endpoint string 
apply-groups reference
apply-groups-exclude reference
description string
hold-time-active number
revert-time (number | keyword)
sap string 
accounting-policy reference
admin-state keyword
apply-groups reference
apply-groups-exclude reference
cem 
packet 
jitter-buffer number
payload-size number
report-alarm 
buffer-overrun boolean
buffer-underrun boolean
malformed-packets boolean
packet-loss boolean
remote-fault boolean
remote-packet-loss boolean
remote-rdi boolean
stray-packets boolean
rtp-header boolean
collect-stats boolean
description string
dist-cpu-protection reference
egress 
agg-rate 
adaptation-rule keyword
burst-limit (number | keyword)
limit-unused-bandwidth boolean
rate number
qos 
policer-control-policy 
overrides 
apply-groups reference
apply-groups-exclude reference
root 
max-rate (number | keyword)
priority-mbs-thresholds 
min-thresh-separation (number | keyword)
priority number 
apply-groups reference
apply-groups-exclude reference
mbs-contribution (number | keyword)
policy-name reference
sap-egress 
overrides 
policer reference 
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
mbs (number | keyword)
packet-byte-offset number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
stat-mode keyword
queue reference 
adaptation-rule 
cir keyword
pir keyword
apply-groups reference
apply-groups-exclude reference
avg-frame-overhead decimal-number
burst-limit (number | keyword)
cbs (number | keyword)
drop-tail 
low 
percent-reduction-from-mbs (number | keyword)
hs-class-weight number
hs-wred-queue 
policy reference
hs-wrr-weight number
mbs (number | keyword)
monitor-queue-depth 
fast-polling boolean
violation-threshold decimal-number
parent 
cir-weight number
weight number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
scheduler-policy 
overrides 
scheduler string 
apply-groups reference
apply-groups-exclude reference
parent 
cir-weight number
weight number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
virtual-port 
vport-name reference
endpoint reference
ingress 
qos 
policer-control-policy 
overrides 
apply-groups reference
apply-groups-exclude reference
root 
max-rate (number | keyword)
priority-mbs-thresholds 
min-thresh-separation (number | keyword)
priority number 
apply-groups reference
apply-groups-exclude reference
mbs-contribution (number | keyword)
policy-name reference
sap-ingress 
overrides 
ip-criteria 
activate-entry-tag number
ipv6-criteria 
activate-entry-tag number
policer reference 
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
mbs (number | keyword)
packet-byte-offset number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
stat-mode keyword
queue reference 
adaptation-rule 
cir keyword
pir keyword
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
drop-tail 
low 
percent-reduction-from-mbs (number | keyword)
mbs (number | keyword)
monitor-queue-depth 
fast-polling boolean
parent 
cir-weight number
weight number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
queuing-type keyword
scheduler-policy 
overrides 
scheduler string 
apply-groups reference
apply-groups-exclude reference
parent 
cir-weight number
weight number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
lag 
multi-service-site reference
service-id number
service-mtu number
spoke-sdp string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bandwidth (number | keyword)
bfd 
bfd-liveness 
encap keyword
bfd-template reference
control-word boolean
description string
egress 
qos 
network 
policy-name reference
port-redirect-group 
group-name reference
instance number
vc-label number
endpoint 
icb boolean
name reference
precedence (number | keyword)
ingress 
qos 
network 
fp-redirect-group 
group-name reference
instance number
policy-name reference
vc-label number
test boolean
vc-switching boolean
vc-type keyword
vpn-id number
customer string 
apply-groups reference
apply-groups-exclude reference
contact string
customer-id number
description string
multi-service-site string 
apply-groups reference
apply-groups-exclude reference
assignment 
card number
fpe reference
port string
description string
egress 
agg-rate 
limit-unused-bandwidth boolean
queue-frame-based-accounting boolean
rate number
policer-control-policy reference
scheduler-policy 
overrides 
scheduler string 
apply-groups reference
apply-groups-exclude reference
parent 
cir-weight number
weight number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
ingress 
policer-control-policy reference
scheduler-policy 
overrides 
scheduler string 
apply-groups reference
apply-groups-exclude reference
parent 
cir-weight number
weight number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
phone string
epipe string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bgp number 
adv-service-mtu number
apply-groups reference
apply-groups-exclude reference
pw-template-binding reference 
apply-groups reference
apply-groups-exclude reference
bfd-liveness boolean
bfd-template reference
endpoint reference
import-rt string
route-distinguisher (keyword | vpn-route-distinguisher)
route-target 
export string
import string
vsi-export reference
vsi-import reference
bgp-evpn 
apply-groups reference
apply-groups-exclude reference
evi number
local-attachment-circuit string 
apply-groups reference
apply-groups-exclude reference
bgp number
endpoint reference
eth-tag number
mpls number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
auto-bind-tunnel 
allow-flex-algo-fallback boolean
ecmp number
enforce-strict-tunnel-tagging boolean
resolution keyword
resolution-filter 
bgp boolean
ldp boolean
mpls-fwd-policy boolean
rib-api boolean
rsvp boolean
sr-isis boolean
sr-ospf boolean
sr-ospf3 boolean
sr-policy boolean
sr-te boolean
udp boolean
weighted-ecmp boolean
control-word boolean
default-route-tag string
domain-id string
dynamic-egress-label-limit boolean
ecmp number
entropy-label boolean
evi-three-byte-auto-rt boolean
force-vc-forwarding keyword
hash-label boolean
mh-mode keyword
oper-group reference
route-next-hop 
ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
system-ipv4 
system-ipv6 
send-tunnel-encap 
mpls boolean
mpls-over-udp boolean
remote-attachment-circuit string 
apply-groups reference
apply-groups-exclude reference
bgp number
endpoint reference
eth-tag number
segment-routing-v6 number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
default-route-tag string
domain-id string
ecmp number
evi-three-byte-auto-rt boolean
force-vc-forwarding keyword
mh-mode keyword
oper-group reference
resolution keyword
route-next-hop 
ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
system-ipv4 
system-ipv6 
source-address string
srv6 
default-locator string
instance reference
vxlan number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
default-route-tag string
ecmp number
evi-three-byte-auto-rt boolean
send-tunnel-encap boolean
vxlan-instance reference
bgp-mh-site string 
activation-timer number
admin-state keyword
apply-groups reference
apply-groups-exclude reference
boot-timer number
id number
min-down-timer number
preference number
sap string
bgp-vpws 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
local-ve 
id number
name string
remote-ve string 
apply-groups reference
apply-groups-exclude reference
id number
customer reference
description string
endpoint string 
apply-groups reference
apply-groups-exclude reference
description string
hold-time-active number
revert-time (number | keyword)
standby-signaling keyword
eth-cfm 
apply-groups reference
apply-groups-exclude reference
ignore-l2vpn-mtu-mismatch boolean
load-balancing 
lbl-eth-or-ip-l4-teid boolean
per-service-hashing boolean
nat-outside number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
oper-group reference
pbb 
force-qtag-forwarding boolean
local-switch-service-state keyword
tunnel 
apply-groups reference
apply-groups-exclude reference
backbone-dest-mac string
backbone-dest-mac-name reference
backbone-vpls-service-name reference
isid number
sap string 
aarp 
id reference
type keyword
accounting-policy reference
admin-state keyword
app-profile reference
apply-groups reference
apply-groups-exclude reference
bandwidth number
cflowd boolean
collect-stats boolean
cpu-protection 
eth-cfm-monitoring 
aggregate 
car 
mac-monitoring 
policy-id reference
description string
dist-cpu-protection reference
egress 
agg-rate 
adaptation-rule keyword
burst-limit (number | keyword)
limit-unused-bandwidth boolean
queue-frame-based-accounting boolean
rate number
filter 
ip reference
ipv6 reference
mac reference
qos 
policer-control-policy 
overrides 
apply-groups reference
apply-groups-exclude reference
root 
max-rate (number | keyword)
priority-mbs-thresholds 
min-thresh-separation (number | keyword)
priority number 
apply-groups reference
apply-groups-exclude reference
mbs-contribution (number | keyword)
policy-name reference
qinq-mark-top-only boolean
sap-egress 
overrides 
hs-secondary-shaper string
hs-wrr-group reference 
apply-groups reference
apply-groups-exclude reference
hs-class-weight number
percent-rate decimal-number
rate (number | keyword)
policer reference 
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
mbs (number | keyword)
packet-byte-offset number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
stat-mode keyword
queue reference 
adaptation-rule 
cir keyword
pir keyword
apply-groups reference
apply-groups-exclude reference
avg-frame-overhead decimal-number
burst-limit (number | keyword)
cbs (number | keyword)
drop-tail 
low 
percent-reduction-from-mbs (number | keyword)
hs-class-weight number
hs-wred-queue 
policy reference
hs-wrr-weight number
mbs (number | keyword)
monitor-queue-depth 
fast-polling boolean
violation-threshold decimal-number
parent 
cir-weight number
weight number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
port-redirect-group 
group-name reference
instance number
scheduler-policy 
overrides 
scheduler string 
apply-groups reference
apply-groups-exclude reference
parent 
cir-weight number
weight number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
virtual-port 
vport-name reference
endpoint reference
eth-cfm 
ais boolean
apply-groups reference
apply-groups-exclude reference
collect-lmm-fc-stats 
fc keyword
fc-in-profile keyword
collect-lmm-stats boolean
mep md-admin-name reference ma-admin-name reference mep-id number 
admin-state keyword
ais 
client-meg-level number
interface-support boolean
interval number
low-priority-defect keyword
priority number
alarm-notification 
fng-alarm-time number
fng-reset-time number
apply-groups reference
apply-groups-exclude reference
ccm boolean
ccm-ltm-priority number
ccm-padding-size number
cfm-vlan-tag string
csf 
multiplier decimal-number
description string
direction keyword
eth-test 
bit-error-threshold number
test-pattern 
crc-tlv boolean
pattern keyword
fault-propagation keyword
grace 
eth-ed 
max-rx-defect-window number
priority number
rx-eth-ed boolean
tx-eth-ed boolean
eth-vsm-grace 
rx-eth-vsm-grace boolean
tx-eth-vsm-grace boolean
lbm-svc-act-responder boolean
low-priority-defect keyword
mac-address string
one-way-delay-threshold number
primary-vlan boolean
mip primary-vlan (number | keyword) 
apply-groups reference
apply-groups-exclude reference
cfm-vlan-tag string
mac-address string
squelch-ingress-ctag-levels number
squelch-ingress-levels number
ethernet 
llf 
admin-state keyword
ignore-oper-down boolean
ingress 
filter 
ip reference
ipv6 reference
mac reference
qos 
match-qinq-dot1p keyword
policer-control-policy 
overrides 
apply-groups reference
apply-groups-exclude reference
root 
max-rate (number | keyword)
priority-mbs-thresholds 
min-thresh-separation (number | keyword)
priority number 
apply-groups reference
apply-groups-exclude reference
mbs-contribution (number | keyword)
policy-name reference
sap-ingress 
fp-redirect-group 
group-name reference
instance number
overrides 
ip-criteria 
activate-entry-tag number
ipv6-criteria 
activate-entry-tag number
policer reference 
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
mbs (number | keyword)
packet-byte-offset number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
stat-mode keyword
queue reference 
adaptation-rule 
cir keyword
pir keyword
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
drop-tail 
low 
percent-reduction-from-mbs (number | keyword)
mbs (number | keyword)
monitor-queue-depth 
fast-polling boolean
parent 
cir-weight number
weight number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
queuing-type keyword
scheduler-policy 
overrides 
scheduler string 
apply-groups reference
apply-groups-exclude reference
parent 
cir-weight number
weight number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
qtag-manipulation 
c-tag (number | keyword)
push-dot1q-vlan (number | keyword)
s-tag number
l2tpv3-session 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
pseudo-wire 
ethernet 
ethernet-vlan-id number
router 
group string
router-instance string
vc-id number
lag 
link-map-profile number
per-link-hash 
class number
weight number
mc-ring 
apply-groups reference
apply-groups-exclude reference
ring-node string
monitor-oper-group reference
multi-service-site reference
oper-group reference
transit-policy 
ip reference
prefix reference
segment-routing-v6 number 
apply-groups reference
apply-groups-exclude reference
locator reference 
apply-groups reference
apply-groups-exclude reference
function 
end-dx2 
value number
micro-segment-locator reference 
apply-groups reference
apply-groups-exclude reference
function 
udx2 
value number
service-id number
service-mtu number
spoke-sdp string 
aarp 
id reference
type keyword
accounting-policy reference
admin-state keyword
adv-service-mtu number
app-profile reference
apply-groups reference
apply-groups-exclude reference
bandwidth (number | keyword)
bfd 
bfd-liveness 
encap keyword
bfd-template reference
failure-action keyword
wait-for-up-timer number
collect-stats boolean
control-word boolean
cpu-protection 
eth-cfm-monitoring 
aggregate 
car 
mac-monitoring 
policy-id reference
description string
egress 
filter 
ip reference
ipv6 reference
mac reference
l2tpv3 
cookie string
qos 
network 
policy-name reference
port-redirect-group 
group-name reference
instance number
vc-label number
endpoint 
icb boolean
name reference
precedence (number | keyword)
entropy-label 
eth-cfm 
apply-groups reference
apply-groups-exclude reference
collect-lmm-fc-stats 
fc keyword
fc-in-profile keyword
collect-lmm-stats boolean
mep md-admin-name reference ma-admin-name reference mep-id number 
admin-state keyword
ais 
client-meg-level number
interface-support boolean
interval number
low-priority-defect keyword
priority number
alarm-notification 
fng-alarm-time number
fng-reset-time number
apply-groups reference
apply-groups-exclude reference
ccm boolean
ccm-ltm-priority number
ccm-padding-size number
cfm-vlan-tag string
csf 
multiplier decimal-number
description string
direction keyword
eth-test 
bit-error-threshold number
test-pattern 
crc-tlv boolean
pattern keyword
fault-propagation keyword
grace 
eth-ed 
max-rx-defect-window number
priority number
rx-eth-ed boolean
tx-eth-ed boolean
eth-vsm-grace 
rx-eth-vsm-grace boolean
tx-eth-vsm-grace boolean
lbm-svc-act-responder boolean
low-priority-defect keyword
mac-address string
one-way-delay-threshold number
primary-vlan boolean
mip primary-vlan (number | keyword) 
apply-groups reference
apply-groups-exclude reference
cfm-vlan-tag string
mac-address string
squelch-ingress-ctag-levels number
squelch-ingress-levels number
force-vc-forwarding keyword
hash-label 
signal-capability 
ingress 
filter 
ip reference
ipv6 reference
mac reference
l2tpv3 
cookie 
cookie1 string
cookie2 string
qos 
network 
fp-redirect-group 
group-name reference
instance number
policy-name reference
vc-label number
monitor-oper-group reference
oper-group reference
pw-status 
block-on-peer-fault boolean
signaling boolean
standby-signaling-slave boolean
source-bmac 
use-sdp-bmac-lsb boolean
transit-policy 
ip reference
prefix reference
vc-type keyword
vlan-vc-tag number
test boolean
vc-switching boolean
vpn-id number
vxlan 
instance number 
apply-groups reference
apply-groups-exclude reference
egress-vtep 
ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
oper-group reference
vni number
source-vtep (ipv4-address-no-zone | ipv6-address-no-zone)
ies string 
aa-interface string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
ip-mtu number
ipv4 
primary 
address string
apply-groups reference
apply-groups-exclude reference
prefix-length number
sap string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
egress 
filter 
ip reference
qos 
sap-egress 
policy-name reference
virtual-port 
vport-name reference
fwd-wholesale 
pppoe-service reference
ingress 
qos 
sap-ingress 
overrides 
policy-name reference
lag 
aarp-interface string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
ip-mtu number
spoke-sdp string 
aarp 
id reference
type keyword
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
egress 
filter 
ip reference
vc-label number
ingress 
filter 
ip reference
vc-label number
admin-state keyword
apply-groups reference
apply-groups-exclude reference
customer reference
description string
eth-cfm 
apply-groups reference
apply-groups-exclude reference
igmp-host-tracking 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
expiry-time number
interface string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
cflowd-parameters 
sampling keyword 
apply-groups reference
apply-groups-exclude reference
direction keyword
sample-profile (keyword | number)
type keyword
cpu-protection reference
description string
dynamic-tunnel-redundant-nexthop string
hold-time 
ipv4 
down 
init-only boolean
seconds number
up 
seconds number
ipv6 
down 
init-only boolean
seconds number
up 
seconds number
if-attribute 
admin-group reference
srlg-group reference 
ingress 
destination-class-lookup boolean
policy-accounting reference
ingress-stats boolean
ip-mtu number
ipsec 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
ip-exception reference
ipsec-tunnel string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bfd 
bfd-designate boolean
bfd-liveness 
dest-ip string
interface string
service-name string
clear-df-bit boolean
copy-traffic-class-upon-decapsulation boolean
description string
encapsulated-ip-mtu number
icmp-generation 
frag-required 
admin-state keyword
interval number
message-count number
icmp6-generation 
packet-too-big 
admin-state keyword
interval number
message-count number
ip-mtu number
key-exchange 
dynamic 
auto-establish boolean
cert 
cert-profile reference
status-verify 
default-result keyword
primary keyword
secondary keyword
trust-anchor-profile reference
id 
fqdn string
ipv4 string
ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
ike-policy reference
ipsec-transform reference
pre-shared-key string
manual 
keys number direction keyword 
apply-groups reference
apply-groups-exclude reference
authentication-key string
encryption-key string
ipsec-transform reference
spi number
local-gateway-address-override (ipv4-address-no-zone | ipv6-address-no-zone)
max-history-key-records 
esp number
ike number
pmtu-discovery-aging number
private-sap number
private-service string
private-tcp-mss-adjust number
propagate-pmtu-v4 boolean
propagate-pmtu-v6 boolean
public-tcp-mss-adjust (number | keyword)
remote-gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
replay-window number
security-policy 
id number
strict-match boolean
ipv6-exception reference
public-sap number
tunnel-group reference
ipv4 
addresses 
address string 
apply-groups reference
apply-groups-exclude reference
prefix-length number
allow-directed-broadcasts boolean
bfd 
admin-state keyword
echo-receive number
multiplier number
receive number
transmit-interval number
type keyword
dhcp 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
gi-address string
lease-populate 
max-leases number
option-82 
action keyword
circuit-id 
ascii-tuple 
ifindex 
none 
sap-id 
vlan-ascii-tuple 
remote-id 
ascii-string string
mac 
none 
vendor-specific-option 
client-mac-address boolean
pool-name boolean
sap-id boolean
service-id boolean
string string
system-id boolean
proxy-server 
admin-state keyword
emulated-server string
lease-time 
radius-override boolean
value number
python-policy reference
relay-plain-bootp boolean
relay-proxy 
release-update-src-ip boolean
siaddr-override string
release-include-gi-address boolean
server string
src-ip-addr keyword
trusted boolean
use-arp boolean
icmp 
mask-reply boolean
param-problem 
admin-state keyword
number number
seconds number
redirects 
admin-state keyword
number number
seconds number
ttl-expired 
admin-state keyword
number number
seconds number
unreachables 
admin-state keyword
number number
seconds number
ip-helper-address string
local-dhcp-server reference
neighbor-discovery 
host-route 
populate keyword 
apply-groups reference
apply-groups-exclude reference
route-tag number
learn-unsolicited boolean
limit 
log-only boolean
max-entries number
threshold number
local-proxy-arp boolean
populate boolean
proactive-refresh boolean
proxy-arp-policy reference
remote-proxy-arp boolean
retry-timer number
static-neighbor string 
apply-groups reference
apply-groups-exclude reference
mac-address string
static-neighbor-unnumbered 
mac-address string
timeout number
primary 
address string
apply-groups reference
apply-groups-exclude reference
broadcast keyword
prefix-length number
track-srrp number
qos-route-lookup keyword
secondary string 
apply-groups reference
apply-groups-exclude reference
broadcast keyword
igp-inhibit boolean
prefix-length number
track-srrp number
tcp-mss number
unnumbered 
ip-address string
ip-int-name string
system 
urpf-check 
ignore-default boolean
mode keyword
vrrp number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authentication-key string
backup string
bfd-liveness 
apply-groups reference
apply-groups-exclude reference
dest-ip string
interface-name string
service-name string
init-delay number
mac string
master-int-inherit boolean
message-interval number
monitor-oper-group reference
ntp-reply boolean
oper-group reference
owner boolean
passive boolean
ping-reply boolean
policy reference
preempt boolean
priority number
ssh-reply boolean
standby-forwarding boolean
telnet-reply boolean
traceroute-reply boolean
ipv6 
address string 
apply-groups reference
apply-groups-exclude reference
duplicate-address-detection boolean
eui-64 boolean
prefix-length number
primary-preference number
track-srrp number
bfd 
admin-state keyword
echo-receive number
multiplier number
receive number
transmit-interval number
type keyword
dhcp6 
apply-groups reference
apply-groups-exclude reference
relay 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
lease-populate 
max-nbr-of-leases number
route-populate 
na boolean
pd 
exclude boolean
ta boolean
link-address string
neighbor-resolution boolean
option 
apply-groups reference
apply-groups-exclude reference
interface-id 
ascii-tuple 
if-index 
sap-id 
string string
remote-id boolean
python-policy reference
server string
source-address string
user-db reference
server 
apply-groups reference
apply-groups-exclude reference
max-nbr-of-leases number
prefix-delegation 
admin-state keyword
prefix string 
apply-groups reference
apply-groups-exclude reference
client-id 
duid string
iaid number
preferred-lifetime (number | keyword)
valid-lifetime (number | keyword)
duplicate-address-detection boolean
forward-ipv4-packets boolean
icmp6 
packet-too-big 
admin-state keyword
number number
seconds number
param-problem 
admin-state keyword
number number
seconds number
redirects 
admin-state keyword
number number
seconds number
time-exceeded 
admin-state keyword
number number
seconds number
unreachables 
admin-state keyword
number number
seconds number
link-local-address 
address string
duplicate-address-detection boolean
local-dhcp-server reference
neighbor-discovery 
host-route 
populate keyword 
apply-groups reference
apply-groups-exclude reference
route-tag number
learn-unsolicited keyword
limit 
log-only boolean
max-entries number
threshold number
local-proxy-nd boolean
proactive-refresh keyword
proxy-nd-policy reference
reachable-time number
secure-nd 
admin-state keyword
allow-unsecured-msgs boolean
public-key-min-bits number
security-parameter number
stale-time number
static-neighbor string 
apply-groups reference
apply-groups-exclude reference
mac-address string
qos-route-lookup keyword
tcp-mss number
urpf-check 
ignore-default boolean
mode keyword
vrrp number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
backup string
bfd-liveness 
apply-groups reference
apply-groups-exclude reference
dest-ip (ipv4-address-no-zone | ipv6-address-no-zone)
interface-name string
service-name string
init-delay number
mac string
master-int-inherit boolean
message-interval number
monitor-oper-group reference
ntp-reply boolean
oper-group reference
owner boolean
passive boolean
ping-reply boolean
policy reference
preempt boolean
priority number
standby-forwarding boolean
telnet-reply boolean
traceroute-reply boolean
load-balancing 
flow-label-load-balancing boolean
ip-load-balancing keyword
spi-load-balancing boolean
teid-load-balancing boolean
loopback boolean
mac string
mac-accounting boolean
monitor-oper-group reference
multi-chassis-shunting-profile reference
multicast-network-domain reference
ping-template 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
destination-address string
name reference
ptp-hw-assist 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
radius-auth-policy reference
sap string 
aarp 
id reference
type keyword
accounting-policy reference
admin-state keyword
anti-spoof keyword
app-profile reference
apply-groups reference
apply-groups-exclude reference
bandwidth number
calling-station-id string
collect-stats boolean
cpu-protection 
eth-cfm-monitoring 
aggregate 
car 
ip-src-monitoring 
mac-monitoring 
policy-id reference
description string
dist-cpu-protection reference
egress 
agg-rate 
adaptation-rule keyword
burst-limit (number | keyword)
limit-unused-bandwidth boolean
queue-frame-based-accounting boolean
rate number
filter 
ip reference
ipv6 reference
qos 
policer-control-policy 
overrides 
apply-groups reference
apply-groups-exclude reference
root 
max-rate (number | keyword)
priority-mbs-thresholds 
min-thresh-separation (number | keyword)
priority number 
apply-groups reference
apply-groups-exclude reference
mbs-contribution (number | keyword)
policy-name reference
qinq-mark-top-only boolean
sap-egress 
overrides 
hs-secondary-shaper string
hs-wrr-group reference 
apply-groups reference
apply-groups-exclude reference
hs-class-weight number
percent-rate decimal-number
rate (number | keyword)
policer reference 
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
mbs (number | keyword)
packet-byte-offset number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
stat-mode keyword
queue reference 
adaptation-rule 
cir keyword
pir keyword
apply-groups reference
apply-groups-exclude reference
avg-frame-overhead decimal-number
burst-limit (number | keyword)
cbs (number | keyword)
drop-tail 
low 
percent-reduction-from-mbs (number | keyword)
hs-class-weight number
hs-wred-queue 
policy reference
hs-wrr-weight number
mbs (number | keyword)
monitor-queue-depth 
fast-polling boolean
violation-threshold decimal-number
parent 
cir-weight number
weight number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
port-redirect-group 
group-name reference
instance number
scheduler-policy 
overrides 
scheduler string 
apply-groups reference
apply-groups-exclude reference
parent 
cir-weight number
weight number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
queue-group-redirect-list reference
virtual-port 
vport-name reference
eth-cfm 
apply-groups reference
apply-groups-exclude reference
collect-lmm-fc-stats 
fc keyword
fc-in-profile keyword
collect-lmm-stats boolean
mep md-admin-name reference ma-admin-name reference mep-id number 
admin-state keyword
ais boolean
alarm-notification 
fng-alarm-time number
fng-reset-time number
apply-groups reference
apply-groups-exclude reference
ccm boolean
ccm-ltm-priority number
ccm-padding-size number
csf 
multiplier decimal-number
description string
eth-test 
bit-error-threshold number
test-pattern 
crc-tlv boolean
pattern keyword
fault-propagation keyword
grace 
eth-ed 
max-rx-defect-window number
priority number
rx-eth-ed boolean
tx-eth-ed boolean
eth-vsm-grace 
rx-eth-vsm-grace boolean
tx-eth-vsm-grace boolean
low-priority-defect keyword
one-way-delay-threshold number
squelch-ingress-levels number
fwd-wholesale 
pppoe-service reference
host-admin-state keyword
host-lockout-policy reference
ingress 
filter 
ip reference
ipv6 reference
qos 
match-qinq-dot1p keyword
policer-control-policy 
overrides 
apply-groups reference
apply-groups-exclude reference
root 
max-rate (number | keyword)
priority-mbs-thresholds 
min-thresh-separation (number | keyword)
priority number 
apply-groups reference
apply-groups-exclude reference
mbs-contribution (number | keyword)
policy-name reference
sap-ingress 
fp-redirect-group 
group-name reference
instance number
overrides 
ip-criteria 
activate-entry-tag number
ipv6-criteria 
activate-entry-tag number
policer reference 
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
mbs (number | keyword)
packet-byte-offset number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
stat-mode keyword
queue reference 
adaptation-rule 
cir keyword
pir keyword
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
drop-tail 
low 
percent-reduction-from-mbs (number | keyword)
mbs (number | keyword)
monitor-queue-depth 
fast-polling boolean
parent 
cir-weight number
weight number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
queuing-type keyword
scheduler-policy 
overrides 
scheduler string 
apply-groups reference
apply-groups-exclude reference
parent 
cir-weight number
weight number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
queue-group-redirect-list reference
ip-tunnel string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
backup-remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
clear-df-bit boolean
delivery-service string
description string
dest-ip (ipv4-address-no-zone | ipv6-address-no-zone) 
dscp keyword
encapsulated-ip-mtu number
gre-header 
admin-state keyword
key 
admin-state keyword
receive number
send number
icmp-generation 
frag-required 
admin-state keyword
interval number
message-count number
icmp6-generation 
packet-too-big 
admin-state keyword
number number
seconds number
ip-mtu number
ipsec-transport-mode-profile reference
local-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
pmtu-discovery-aging number
private-tcp-mss-adjust number
propagate-pmtu-v4 boolean
propagate-pmtu-v6 boolean
public-tcp-mss-adjust (number | keyword)
reassembly (number | keyword)
remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
ipsec-gateway string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
cert 
cert-profile reference
status-verify 
default-result keyword
primary keyword
secondary keyword
trust-anchor-profile reference
client-db 
fallback boolean
name reference
default-secure-service 
interface string
service-name string
default-tunnel-template reference
dhcp-address-assignment 
dhcpv4 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
gi-address string
send-release boolean
server 
address string
router-instance string
dhcpv6 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
link-address string
send-release boolean
server 
address string
router-instance string
ike-policy reference
local 
address-assignment 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
ipv4 
dhcp-server string
pool string
router-instance string
secondary-pool string
ipv6 
dhcp-server string
pool string
router-instance string
gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
id 
auto 
fqdn string
ipv4 string
ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
max-history-key-records 
esp number
ike number
pre-shared-key string
radius 
accounting-policy reference
authentication-policy reference
ts-list reference
lag 
link-map-profile number
per-link-hash 
class number
weight number
multi-service-site reference
static-host 
ipv4 string mac string 
admin-state keyword
ancp-string string
app-profile 
profile reference
apply-groups reference
apply-groups-exclude reference
int-dest-id string
sla-profile reference
sub-profile reference
subscriber-id 
string string
use-sap-id 
transit-policy 
ip reference
prefix reference
shcv-policy-ipv4 reference
spoke-sdp string 
aarp 
id reference
type keyword
accounting-policy reference
admin-state keyword
app-profile reference
apply-groups reference
apply-groups-exclude reference
bfd 
bfd-liveness 
encap keyword
bfd-template reference
failure-action keyword
wait-for-up-timer number
collect-stats boolean
control-word boolean
cpu-protection 
eth-cfm-monitoring 
aggregate 
car 
ip-src-monitoring 
mac-monitoring 
policy-id reference
description string
egress 
filter 
ip reference
ipv6 reference
qos 
network 
policy-name reference
port-redirect-group 
group-name reference
instance number
vc-label number
entropy-label 
eth-cfm 
apply-groups reference
apply-groups-exclude reference
collect-lmm-fc-stats 
fc keyword
fc-in-profile keyword
collect-lmm-stats boolean
mep md-admin-name reference ma-admin-name reference mep-id number 
admin-state keyword
ais boolean
alarm-notification 
fng-alarm-time number
fng-reset-time number
apply-groups reference
apply-groups-exclude reference
ccm boolean
ccm-ltm-priority number
ccm-padding-size number
csf 
multiplier decimal-number
description string
eth-test 
bit-error-threshold number
test-pattern 
crc-tlv boolean
pattern keyword
fault-propagation keyword
grace 
eth-ed 
max-rx-defect-window number
priority number
rx-eth-ed boolean
tx-eth-ed boolean
eth-vsm-grace 
rx-eth-vsm-grace boolean
tx-eth-vsm-grace boolean
low-priority-defect keyword
one-way-delay-threshold number
squelch-ingress-levels number
hash-label 
signal-capability 
ingress 
filter 
ip reference
ipv6 reference
qos 
network 
fp-redirect-group 
group-name reference
instance number
policy-name reference
vc-label number
transit-policy 
ip reference
prefix reference
vc-type keyword
static-tunnel-redundant-nexthop string
tos-marking-state keyword
tunnel boolean
vas-if-type keyword
vpls string 
apply-groups reference
apply-groups-exclude reference
egress 
reclassify-using-qos reference
routed-override-filter 
ip reference
ipv6 reference
evpn 
arp 
advertise keyword 
apply-groups reference
apply-groups-exclude reference
route-tag number
flood-garp-and-unknown-req boolean
learn-dynamic boolean
nd 
advertise keyword 
apply-groups reference
apply-groups-exclude reference
route-tag number
learn-dynamic boolean
ingress 
routed-override-filter 
ip reference
ipv6 reference
redundant-interface string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
hold-time 
ipv4 
down 
init-only boolean
seconds number
up 
seconds number
ip-mtu number
ipv4 
primary 
address string
apply-groups reference
apply-groups-exclude reference
prefix-length number
remote-ip string
spoke-sdp string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
control-word boolean
description string
egress 
filter 
ip reference
vc-label number
ingress 
filter 
ip reference
vc-label number
service-id number
subscriber-interface string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
fwd-service reference
fwd-subscriber-interface reference
group-interface string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bonding-parameters 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
connection number 
apply-groups reference
apply-groups-exclude reference
service string
fpe reference
multicast 
connection (number | keyword)
brg 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authenticated-brg-only boolean
default-brg-profile reference
cflowd-parameters 
sampling keyword 
apply-groups reference
apply-groups-exclude reference
direction keyword
sample-profile (keyword | number)
type keyword
data-trigger 
accept-ipv6-link-local-address boolean
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
dynamic-routes-track-srrp 
hold-time number
gtp-parameters 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
fpe reference
gx-policy reference
ingress 
policy-accounting reference
ingress-stats boolean
ip-mtu number
ipoe-linking 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
gratuitous-router-advertisement boolean
shared-circuit-id boolean
ipoe-session 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
force-auth 
cid-change boolean
rid-change boolean
ipoe-session-policy reference
min-auth-interval (keyword | number)
radius-session-timeout keyword
sap-session-limit number
session-limit number
stateless-redundancy boolean
user-db reference
ipv4 
arp-host 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
host-limit number
min-auth-interval number
sap-host-limit number
dhcp 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
client-applications 
dhcp boolean
ppp boolean
description string
filter reference
gi-address string
lease-populate 
l2-header 
mac string
max-leases number
match-circuit-id boolean
offer-selection 
client-mac 
discover-delay number
mac-address keyword
discover-delay number
server string 
apply-groups reference
apply-groups-exclude reference
discover-delay number
option-82 
action keyword
circuit-id 
ascii-tuple 
ifindex 
none 
sap-id 
vlan-ascii-tuple 
remote-id 
ascii-string string
mac 
none 
vendor-specific-option 
client-mac-address boolean
pool-name boolean
sap-id boolean
service-id boolean
string string
system-id boolean
proxy-server 
admin-state keyword
emulated-server string
lease-time 
radius-override boolean
value number
python-policy reference
relay-proxy 
release-update-src-ip boolean
siaddr-override string
release-include-gi-address boolean
server string
src-ip-addr keyword
trusted boolean
user-db reference
icmp 
mask-reply boolean
param-problem 
admin-state keyword
number number
seconds number
redirects 
admin-state keyword
number number
seconds number
ttl-expired 
admin-state keyword
number number
seconds number
use-matching-address boolean
unreachables 
admin-state keyword
number number
seconds number
ignore-df-bit boolean
neighbor-discovery 
local-proxy-arp boolean
populate boolean
proxy-arp-policy reference
remote-proxy-arp boolean
timeout number
qos-route-lookup keyword
urpf-check 
mode keyword
ipv6 
allow-multiple-wan-addresses boolean
auto-reply 
neighbor-solicitation boolean
router-solicitation boolean
dhcp6 
allow-client-id-change boolean
apply-groups reference
apply-groups-exclude reference
filter reference
option 
apply-groups reference
apply-groups-exclude reference
interface-id 
ascii-tuple 
if-index 
sap-id 
string string
remote-id boolean
override-slaac boolean
pd-managed-route 
next-hop keyword
proxy-server 
admin-state keyword
client-applications 
dhcp boolean
ppp boolean
preferred-lifetime (number | keyword)
rebind-timer number
renew-timer number
server-id 
apply-groups reference
apply-groups-exclude reference
duid-en-ascii string
duid-en-hex string
duid-ll 
valid-lifetime (number | keyword)
python-policy reference
relay 
admin-state keyword
advertise-selection 
client-mac 
mac-address keyword
preference-option 
value number
solicit-delay number
preference-option 
value number
server string 
apply-groups reference
apply-groups-exclude reference
preference-option 
value number
solicit-delay number
solicit-delay number
client-applications 
dhcp boolean
ppp boolean
description string
lease-split 
admin-state keyword
valid-lifetime number
link-address string
server string
source-address string
snooping 
admin-state keyword
user-db reference
user-ident keyword
ipoe-bridged-mode boolean
neighbor-discovery 
apply-groups reference
apply-groups-exclude reference
dad-snooping boolean
neighbor-limit number
qos-route-lookup keyword
router-advertisements 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
force-mcast keyword
max-advertisement-interval number
min-advertisement-interval number
options 
current-hop-limit number
dns 
include-rdnss boolean
rdnss-lifetime (number | keyword)
managed-configuration boolean
mtu (number | keyword)
other-stateful-configuration boolean
reachable-time number
retransmit-timer number
router-lifetime (number | keyword)
prefix-options 
autonomous boolean
on-link boolean
preferred-lifetime (number | keyword)
valid-lifetime (number | keyword)
router-solicit 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
inactivity-timer (number | keyword)
min-auth-interval number
user-db reference
urpf-check 
mode keyword
local-address-assignment 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
ipv4 
client-applications 
ipoe boolean
ppp boolean
default-pool string
server reference
ipv6 
client-applications 
ipoe-slaac boolean
ipoe-wan boolean
ppp-slaac boolean
server reference
mac string
nasreq-auth-policy reference
oper-up-while-empty boolean
pppoe 
admin-state keyword
anti-spoof keyword
apply-groups reference
apply-groups-exclude reference
description string
dhcp-client 
client-id keyword
policy reference
python-policy reference
sap-session-limit number
session-limit number
user-db reference
radius-auth-policy reference
redundant-interface reference
sap string 
accounting-policy reference
admin-state keyword
anti-spoof keyword
app-profile reference
apply-groups reference
apply-groups-exclude reference
calling-station-id string
collect-stats boolean
cpu-protection 
eth-cfm-monitoring 
aggregate 
car 
ip-src-monitoring 
mac-monitoring 
policy-id reference
default-host 
ipv4 reference prefix-length number 
apply-groups reference
apply-groups-exclude reference
next-hop string
ipv6 string prefix-length number 
apply-groups reference
apply-groups-exclude reference
next-hop string
description string
dist-cpu-protection reference
egress 
agg-rate 
adaptation-rule keyword
burst-limit (number | keyword)
limit-unused-bandwidth boolean
queue-frame-based-accounting boolean
rate number
filter 
ip reference
ipv6 reference
qos 
policer-control-policy 
policy-name reference
qinq-mark-top-only boolean
sap-egress 
policy-name reference
scheduler-policy 
policy-name reference
virtual-port 
vport-name reference
eth-cfm 
apply-groups reference
apply-groups-exclude reference
collect-lmm-fc-stats 
fc keyword
fc-in-profile keyword
collect-lmm-stats boolean
mep md-admin-name reference ma-admin-name reference mep-id number 
admin-state keyword
ais boolean
alarm-notification 
fng-alarm-time number
fng-reset-time number
apply-groups reference
apply-groups-exclude reference
ccm boolean
ccm-ltm-priority number
ccm-padding-size number
csf 
multiplier decimal-number
description string
eth-test 
bit-error-threshold number
test-pattern 
crc-tlv boolean
pattern keyword
fault-propagation keyword
grace 
eth-ed 
max-rx-defect-window number
priority number
rx-eth-ed boolean
tx-eth-ed boolean
eth-vsm-grace 
rx-eth-vsm-grace boolean
tx-eth-vsm-grace boolean
low-priority-defect keyword
one-way-delay-threshold number
squelch-ingress-levels number
fwd-wholesale 
pppoe-service reference
host-admin-state keyword
host-lockout-policy reference
igmp-host-tracking 
apply-groups reference
apply-groups-exclude reference
expiry-time number
import-policy reference
maximum-number-group-sources number
maximum-number-groups number
maximum-number-sources number
router-alert-check boolean
ingress 
filter 
ip reference
ipv6 reference
qos 
match-qinq-dot1p keyword
policer-control-policy 
policy-name reference
sap-ingress 
policy-name reference
queuing-type keyword
scheduler-policy 
policy-name reference
lag 
link-map-profile number
per-link-hash 
class number
weight number
monitor-oper-group reference
multi-service-site reference
oper-group reference
static-host 
ipv4 string mac string 
admin-state keyword
ancp-string string
app-profile 
profile reference
scope keyword
apply-groups reference
apply-groups-exclude reference
int-dest-id string
managed-route string 
apply-groups reference
apply-groups-exclude reference
cpe-check 
apply-groups reference
apply-groups-exclude reference
destination-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
drop-count number
failed-action 
metric number
preference number
tag number
withdraw boolean
interval number
log boolean
padding-size number
source-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
timeout number
metric number
preference number
tag number
rip-policy reference
shcv 
sla-profile reference
sub-profile reference
subscriber-id 
string string
use-sap-id 
ipv6 string mac string 
admin-state keyword
ancp-string string
app-profile 
profile reference
scope keyword
apply-groups reference
apply-groups-exclude reference
int-dest-id string
mac-linking string
managed-route string 
apply-groups reference
apply-groups-exclude reference
cpe-check 
apply-groups reference
apply-groups-exclude reference
destination-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
drop-count number
failed-action 
metric number
preference number
tag number
withdraw boolean
interval number
log boolean
padding-size number
source-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
timeout number
metric number
preference number
tag number
retail-svc-id number
shcv 
sla-profile reference
sub-profile reference
subscriber-id 
string string
use-sap-id 
mac-learning 
data-triggered boolean
single-mac boolean
sub-sla-mgmt 
admin-state keyword
defaults 
app-profile reference
int-dest-id 
string string
top-q-tag 
sla-profile reference
sub-profile reference
subscriber-id 
auto-id 
sap-id 
string string
single-sub-parameters 
non-sub-traffic 
app-profile reference
sla-profile reference
sub-profile reference
subscriber-id string
profiled-traffic-only boolean
sub-ident-policy reference
subscriber-limit (keyword | number)
sap-parameters 
anti-spoof keyword
apply-groups reference
apply-groups-exclude reference
description string
sub-sla-mgmt 
defaults 
app-profile reference
sla-profile reference
sub-profile reference
subscriber-id 
auto-id 
string string
sub-ident-policy reference
shcv-policy reference
shcv-policy-ipv4 reference
shcv-policy-ipv6 reference
srrp number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bfd-liveness 
apply-groups reference
apply-groups-exclude reference
dest-ip string
interface-name string
service-name string
description string
gw-mac string
keep-alive-interval number
message-path reference
monitor-oper-group 
group-name reference
priority-step number
one-garp-per-sap boolean
policy reference
preempt boolean
priority number
send-fib-population-packets keyword
suppress-aa-sub boolean
tos-marking-state keyword
type keyword
wlan-gw 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
gateway-address (ipv4-address-no-zone | ipv6-address-no-zone) 
apply-groups reference
apply-groups-exclude reference
purpose 
xconnect boolean
gateway-router string
group-encryption 
encryption-keygroup-inbound reference
encryption-keygroup-outbound reference
l2-ap 
access-point string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
encap-type keyword
epipe-sap-template reference
auto-sub-id-fmt keyword
default-encap-type keyword
lanext 
max-bd number
learn-ap-mac 
delay-auth boolean
mcs-peer 
address reference
sync-tag string
mobility 
hold-time number
inter-tunnel-type boolean
inter-vlan boolean
trigger 
control boolean
data boolean
iapp boolean
oper-down-on-group-degrade boolean
promiscuous-mode boolean
tcp-mss-adjust number
tunnel-egress-qos 
admin-state keyword
agg-rate-limit (number | keyword)
granularity keyword
hold-time (number | keyword)
multi-client-only boolean
qos reference
scheduler-policy reference
tunnel-encaps 
learn-l2tp-cookie (keyword | hex-string)
vlan-range string 
apply-groups reference
apply-groups-exclude reference
authentication 
hold-time number
local 
coa-policy reference
default-ue-state keyword
on-control-plane boolean
policy reference
vlan-mismatch-timeout number
data-triggered-ue-creation 
admin-state keyword
arp boolean
create-proxy-cache-entry 
mac-format string
proxy-server 
name string
router-instance string
ospf boolean
dhcp4 
admin-state keyword
dns string
l2-aware-ip-address (ipv4-unicast-address | keyword)
lease-time 
active number
initial number
nbns string
dhcp6 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
preferred-lifetime 
active number
initial number
valid-lifetime 
active number
initial number
dsm 
accounting-policy reference
accounting-update 
interval number
admin-state keyword
application-assurance 
accounting-statistics boolean
profile reference
url-parameter string
apply-groups reference
apply-groups-exclude reference
egress 
policer reference
ingress 
ip-filter reference
policer reference
soft-quota-exhausted-filter reference
one-time-redirect 
port number
url string
volume-quota-direction keyword
dynamic-service boolean
extension string 
http-redirect-policy reference
idle-timeout-action keyword
l2-service 
admin-state keyword
description string
service reference
nat-policy reference
retail-service string
slaac 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
preferred-lifetime 
active number
initial number
valid-lifetime 
active number
initial number
vrgw 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
brg 
authenticated-brg-only boolean
default-brg-profile reference
lanext 
access 
max-mac number
multi-access boolean
policer reference
admin-state keyword
apply-groups reference
apply-groups-exclude reference
assistive-address-resolution boolean
bd-mac-prefix string
mac-translation boolean
network 
admin-state keyword
max-mac number
policer reference
xconnect 
accounting 
mobility-updates boolean
policy reference
update-interval number
admin-state keyword
apply-groups reference
apply-groups-exclude reference
wlan-gw-group reference
wpp 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
initial 
app-profile reference
sla-profile reference
sub-profile reference
lease-time number
portal 
name string
portal-group reference
router-instance string
restore-to-initial-on-disconnect boolean
triggered-hosts boolean
user-db reference
hold-time 
ipv4 
down 
init-only boolean
seconds number
up 
seconds number
ipv6 
down 
init-only boolean
seconds number
up 
seconds number
ipoe-linking 
apply-groups reference
apply-groups-exclude reference
gratuitous-router-advertisement boolean
ipoe-session 
apply-groups reference
apply-groups-exclude reference
session-limit number
ipv4 
address string 
apply-groups reference
apply-groups-exclude reference
gateway string
holdup-time number
populate-host-routes boolean
prefix-length number
track-srrp number
allow-unmatching-subnets boolean
default-dns string
dhcp 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
client-applications 
dhcp boolean
ppp boolean
description string
gi-address string
lease-populate 
max-leases number
option-82 
vendor-specific-option 
client-mac-address boolean
sap-id boolean
service-id boolean
string string
system-id boolean
proxy-server 
admin-state keyword
emulated-server string
lease-time 
radius-override boolean
value number
python-policy reference
relay-proxy 
release-update-src-ip boolean
siaddr-override string
release-include-gi-address boolean
server string
src-ip-addr keyword
virtual-subnet boolean
export-host-routes boolean
unnumbered 
ip-address string
ip-int-name string
ipv6 
address string 
apply-groups reference
apply-groups-exclude reference
host-type keyword
prefix-length number
allow-multiple-wan-addresses boolean
allow-unmatching-prefixes boolean
default-dns string
delegated-prefix-length (number | keyword)
dhcp6 
allow-client-id-change boolean
apply-groups reference
apply-groups-exclude reference
override-slaac boolean
pd-managed-route 
next-hop keyword
proxy-server 
admin-state keyword
client-applications 
dhcp boolean
ppp boolean
preferred-lifetime (number | keyword)
rebind-timer number
renew-timer number
server-id 
apply-groups reference
apply-groups-exclude reference
duid-en-ascii string
duid-en-hex string
duid-ll 
valid-lifetime (number | keyword)
python-policy reference
relay 
admin-state keyword
client-applications 
dhcp boolean
ppp boolean
description string
lease-split 
admin-state keyword
valid-lifetime number
link-address string
server string
source-address string
ipoe-bridged-mode boolean
link-local-address 
address string
prefix string 
apply-groups reference
apply-groups-exclude reference
holdup-time number
host-type keyword
track-srrp number
router-advertisements 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
force-mcast keyword
max-advertisement-interval number
min-advertisement-interval number
options 
current-hop-limit number
dns 
include-rdnss boolean
rdnss-lifetime (number | keyword)
managed-configuration boolean
mtu (number | keyword)
other-stateful-configuration boolean
reachable-time number
retransmit-timer number
router-lifetime (number | keyword)
prefix-options 
autonomous boolean
on-link boolean
preferred-lifetime (number | keyword)
valid-lifetime (number | keyword)
router-solicit 
apply-groups reference
apply-groups-exclude reference
inactivity-timer (number | keyword)
local-address-assignment 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
ipv4 
client-applications 
ppp boolean
default-pool string
server reference
ipv6 
client-applications 
ipoe-slaac boolean
ipoe-wan boolean
ppp-slaac boolean
server reference
pppoe 
apply-groups reference
apply-groups-exclude reference
description string
session-limit number
wan-mode keyword
wlan-gw 
apply-groups reference
apply-groups-exclude reference
pool-manager 
apply-groups reference
apply-groups-exclude reference
dhcp6-client 
dhcpv4-nat 
admin-state keyword
link-address string
pool-name string
ia-na 
admin-state keyword
link-address string
pool-name string
lease-query 
max-retries number
servers string
slaac 
admin-state keyword
link-address string
pool-name string
source-ip (keyword | ipv6-address)
watermarks 
high number
low number
wlan-gw-group reference
redundancy 
admin-state keyword
export string
monitor string
subscriber-mgmt 
apply-groups reference
apply-groups-exclude reference
multi-chassis-shunt-id number
up-resiliency 
monitor-oper-group reference 
apply-groups reference
apply-groups-exclude reference
health-drop number
video-interface string 
accounting-policy reference
address string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
channel string source string 
apply-groups reference
apply-groups-exclude reference
channel-name string
description string
scte35-action keyword
zone-channel string zone-source string 
adi-channel-name string
apply-groups reference
apply-groups-exclude reference
cpu-protection reference
description string
multicast-service number
output-format keyword
video-sap 
apply-groups reference
apply-groups-exclude reference
egress 
apply-groups reference
apply-groups-exclude reference
filter 
ip reference
qos 
policy-name reference
ingress 
apply-groups reference
apply-groups-exclude reference
filter 
ip reference
qos 
policy-name reference
video-group-id reference
vpn-id number
ipfix 
apply-groups reference
apply-groups-exclude reference
export-policy string 
apply-groups reference
apply-groups-exclude reference
collector router-instance string ip-address string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
mtu number
refresh-timeout number
source-ip-address string
description string
template-format keyword
ipipe string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
ce-address-discovery 
customer reference
description string
endpoint string 
apply-groups reference
apply-groups-exclude reference
description string
hold-time-active number
revert-time (number | keyword)
standby-signaling keyword
sap string 
accounting-policy reference
admin-state keyword
app-profile reference
apply-groups reference
apply-groups-exclude reference
bandwidth number
ce-address (ipv4-address-no-zone | ipv6-address-no-zone)
collect-stats boolean
cpu-protection 
mac-monitoring 
policy-id reference
description string
dist-cpu-protection reference
egress 
agg-rate 
adaptation-rule keyword
burst-limit (number | keyword)
limit-unused-bandwidth boolean
rate number
filter 
ip reference
ipv6 reference
qos 
policer-control-policy 
overrides 
apply-groups reference
apply-groups-exclude reference
root 
max-rate (number | keyword)
priority-mbs-thresholds 
min-thresh-separation (number | keyword)
priority number 
apply-groups reference
apply-groups-exclude reference
mbs-contribution (number | keyword)
policy-name reference
qinq-mark-top-only boolean
sap-egress 
overrides 
hs-secondary-shaper string
hs-wrr-group reference 
apply-groups reference
apply-groups-exclude reference
hs-class-weight number
percent-rate decimal-number
rate (number | keyword)
policer reference 
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
mbs (number | keyword)
packet-byte-offset number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
stat-mode keyword
queue reference 
adaptation-rule 
cir keyword
pir keyword
apply-groups reference
apply-groups-exclude reference
avg-frame-overhead decimal-number
burst-limit (number | keyword)
cbs (number | keyword)
drop-tail 
low 
percent-reduction-from-mbs (number | keyword)
hs-class-weight number
hs-wred-queue 
policy reference
hs-wrr-weight number
mbs (number | keyword)
monitor-queue-depth 
fast-polling boolean
violation-threshold decimal-number
parent 
cir-weight number
weight number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
port-redirect-group 
group-name reference
instance number
scheduler-policy 
overrides 
scheduler string 
apply-groups reference
apply-groups-exclude reference
parent 
cir-weight number
weight number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
virtual-port 
vport-name reference
endpoint reference
ingress 
filter 
ip reference
ipv6 reference
qos 
match-qinq-dot1p keyword
policer-control-policy 
overrides 
apply-groups reference
apply-groups-exclude reference
root 
max-rate (number | keyword)
priority-mbs-thresholds 
min-thresh-separation (number | keyword)
priority number 
apply-groups reference
apply-groups-exclude reference
mbs-contribution (number | keyword)
policy-name reference
sap-ingress 
fp-redirect-group 
group-name reference
instance number
overrides 
policer reference 
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
mbs (number | keyword)
packet-byte-offset number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
stat-mode keyword
queue reference 
adaptation-rule 
cir keyword
pir keyword
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
drop-tail 
low 
percent-reduction-from-mbs (number | keyword)
mbs (number | keyword)
monitor-queue-depth 
fast-polling boolean
parent 
cir-weight number
weight number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
queuing-type keyword
scheduler-policy 
overrides 
scheduler string 
apply-groups reference
apply-groups-exclude reference
parent 
cir-weight number
weight number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
lag 
link-map-profile number
per-link-hash 
class number
weight number
mac string
mac-refresh number
multi-service-site reference
transit-policy 
prefix reference
use-broadcast-mac boolean
service-id number
service-mtu number
spoke-sdp string 
aarp 
id reference
type keyword
admin-state keyword
app-profile reference
apply-groups reference
apply-groups-exclude reference
bandwidth (number | keyword)
bfd 
bfd-liveness 
encap keyword
bfd-template reference
ce-address (ipv4-address-no-zone | ipv6-address-no-zone)
control-word boolean
description string
egress 
filter 
ip reference
ipv6 reference
qos 
network 
policy-name reference
port-redirect-group 
group-name reference
instance number
vc-label number
endpoint 
name reference
precedence (number | keyword)
entropy-label 
hash-label 
signal-capability 
ingress 
filter 
ip reference
ipv6 reference
qos 
network 
fp-redirect-group 
group-name reference
instance number
policy-name reference
vc-label number
transit-policy 
prefix reference
vc-switching boolean
vpn-id number
mac-list string 
apply-groups reference
apply-groups-exclude reference
description string
mac string 
apply-groups reference
apply-groups-exclude reference
mask string
md-auto-id 
customer-id-range 
apply-groups reference
apply-groups-exclude reference
end number
start number
pw-template-id-range 
apply-groups reference
apply-groups-exclude reference
end number
start number
service-id-range 
apply-groups reference
apply-groups-exclude reference
end number
start number
mrp 
policy string 
apply-groups reference
apply-groups-exclude reference
default-action keyword
description string
entry number 
action keyword
apply-groups reference
apply-groups-exclude reference
description string
match 
isid number 
apply-groups reference
apply-groups-exclude reference
higher-value number
scope keyword
nat 
apply-groups reference
apply-groups-exclude reference
classifier string 
apply-groups reference
apply-groups-exclude reference
default 
action 
destination-nat 
ip-address string
forward 
dnat-ip-address string
description string
entry number 
action 
destination-nat 
ip-address string
forward 
apply-groups reference
apply-groups-exclude reference
description string
match 
dst-port-range 
end number
start number
foreign-ip-address string
protocol keyword
deterministic-script 
location string
firewall-policy string 
alg 
ftp boolean
rtsp boolean
sip boolean
apply-groups reference
apply-groups-exclude reference
description string
domain 
name string
router-instance string
filtering keyword
l2-outside 
port-limits 
forwarding number
priority-sessions 
fc 
af boolean
be boolean
ef boolean
h1 boolean
h2 boolean
l1 boolean
l2 boolean
nc boolean
session-limits 
max number
reserved number
watermarks 
high number
low number
tcp 
mss-adjust number
timeouts 
icmp6-query number
sip number
tcp 
established number
rst number
syn number
time-wait number
transitory number
udp 
dns number
initial number
normal number
unknown-protocol number
udp 
inbound-refresh boolean
unknown-protocols 
all 
protocol number
map-t 
domain string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
dmr-prefix string
ip-fragmentation 
v6-frag-header boolean
mapping-rule string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
ea-length number
ipv4-prefix string
psid-offset number
rule-prefix string
mtu number
tcp-mss-adjust number
nat-policy string 
alg 
ftp boolean
pptp boolean
rtsp boolean
sip boolean
apply-groups reference
apply-groups-exclude reference
block-limit number
description string
dnat 
classifier reference
dnat-only 
nat-group reference
router-instance string
wlan-gw-group reference
filtering keyword
flow-log-policy 
ipfix reference
syslog reference
l2-outside 
pool 
name string
router-instance string
port-forwarding-range-end number
port-limits 
dynamic-ports number
forwarding number
reserved number
watermarks 
high number
low number
priority-sessions 
fc 
af boolean
be boolean
ef boolean
h1 boolean
h2 boolean
l1 boolean
l2 boolean
nc boolean
session-limits 
max number
reserved number
watermarks 
high number
low number
tcp 
mss-adjust number
reset-unknown boolean
timeouts 
icmp-query number
sip number
subscriber-retention number
tcp 
established number
rst number
syn number
time-wait number
transitory number
udp 
dns number
initial number
normal number
udp 
inbound-refresh boolean
pcp-server-policy string 
apply-groups reference
apply-groups-exclude reference
description string
lifetime 
maximum number
minimum number
max-description-size number
opcode 
announce boolean
get boolean
map boolean
option 
description boolean
next boolean
port-reservation boolean
port-set boolean
prefer-failure boolean
third-party boolean
reuse-external-ip-address boolean
version 
maximum number
minimum number
prefix-list string 
application keyword
apply-groups reference
apply-groups-exclude reference
prefix string 
apply-groups reference
apply-groups-exclude reference
nat-policy reference
syslog 
export-policy string 
apply-groups reference
apply-groups-exclude reference
collector router-instance string ip-address string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
destination-port number
ipv4-source-address string
description string
facility keyword
include 
destination-ip boolean
foreign-ip boolean
foreign-port boolean
nat-policy-name boolean
sub-id boolean
log-prefix string
max-tx-delay number
mtu number
rate-limit number
severity-level keyword
up-nat-policy string 
alg 
ftp boolean
pptp boolean
rtsp boolean
sip boolean
apply-groups reference
apply-groups-exclude reference
block-limit number
default-host 
inside-router-instance string
ip-address string
rate-limit number
description string
filtering keyword
flow-log-policy 
ipfix reference
icmp-echo-reply boolean
port-block-extension 
ports number
watermarks 
high number
low number
port-limits 
dynamic-ports number
reserved number
watermarks 
high number
low number
priority-sessions 
fc 
af boolean
be boolean
ef boolean
h1 boolean
h2 boolean
l1 boolean
l2 boolean
nc boolean
session-limits 
max number
reserved number
watermarks 
high number
low number
tcp 
mss-adjust number
reset-unknown boolean
timeouts 
icmp-query number
sip number
subscriber-retention number
tcp 
established number
rst number
syn number
time-wait number
transitory number
udp 
dns number
initial number
normal number
udp 
inbound-refresh boolean
oper-group string 
apply-groups reference
apply-groups-exclude reference
bfd-liveness 
apply-groups reference
apply-groups-exclude reference
dest-ip string
interface-name string
router-instance string
hold-time 
down number
up number
pbb 
apply-groups reference
apply-groups-exclude reference
mac string 
address string
apply-groups reference
apply-groups-exclude reference
mac-notification 
apply-groups reference
apply-groups-exclude reference
count number
interval number
source-bmac 
address string
evpn-etree-leaf-address string
proxy-arp-nd 
mac-list 
list string 
apply-groups reference
apply-groups-exclude reference
mac string 
pw-template string 
accounting-policy number
allow-fragmentation boolean
apply-groups reference
apply-groups-exclude reference
auto-gre-sdp boolean
block-on-peer-fault boolean
collect-stats boolean
control-word boolean
egress 
filter 
ip string
ipv6 string
mac string
mfib-allowed-mda-destinations 
mda string 
qos 
network 
policy-name string
port-redirect-group 
group-name string
instance number
encryption-keygroup 
inbound number
outbound number
entropy-label 
fdb 
auto-learn-mac-protect boolean
auto-learn-mac-protect-exclude-list string
discard-unknown-source boolean
limit-mac-move keyword
mac-learning 
aging boolean
learning boolean
mac-pinning boolean
maximum-mac-addresses number
protected-src-mac-violation-action keyword
force-vc-forwarding keyword
hash-label 
signal-capability 
igmp-snooping 
fast-leave boolean
import-policy string
maximum-number-groups number
query-interval number
query-last-member-interval number
query-response-interval number
robust-count number
send-queries boolean
version keyword
ingress 
filter 
ip string
ipv6 string
mac string
qos 
network 
fp-redirect-group 
group-name string
instance number
policy-name string
l2pt 
termination 
protocols 
cdp boolean
dtp boolean
pagp boolean
stp boolean
udld boolean
vtp boolean
provisioned-sdp keyword
pw-template-id number
sdp-exclude reference 
sdp-include reference 
split-horizon-group 
description string
fdb 
saps 
auto-learn-mac-protect boolean
discard-unprotected-dest-mac boolean
protected-src-mac-violation-action keyword
name string
stp 
admin-state keyword
auto-edge boolean
edge-port boolean
link-type keyword
path-cost number
priority number
root-guard boolean
vc-type keyword
vlan-vc-tag number
sdp number 
accounting-policy reference
admin-state keyword
adv-mtu-override boolean
allow-fragmentation boolean
apply-groups reference
apply-groups-exclude reference
bgp-tunnel boolean
booking-factor number
class-forwarding 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
default-lsp reference
enforce-diffserv-lsp-fc boolean
fc keyword 
apply-groups reference
apply-groups-exclude reference
lsp reference
multicast-lsp reference
collect-stats boolean
delivery-type keyword
description string
far-end 
ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
keep-alive 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
hello-time number
hold-down-time number
maximum-drop-count number
message-length number
timeout number
ldp boolean
local-end (ipv4-address-no-zone | ipv6-address-no-zone)
lsp string 
metric number
mixed-lsp-mode 
revert-time (number | keyword)
network-domain reference
path-mtu number
pbb-etype string
pw-port 
binding-port string
sdp-group reference 
signaling keyword
source-bmac-lsb 
control-pw-vc-id number
value string
sr-isis boolean
sr-ospf boolean
tunnel-far-end (ipv4-address-no-zone | ipv6-address-no-zone)
vlan-vc-etype string
weighted-ecmp boolean
sdp-group 
apply-groups reference
apply-groups-exclude reference
group-name string 
apply-groups reference
apply-groups-exclude reference
value number
system 
apply-groups reference
apply-groups-exclude reference
bgp 
evpn 
ad-per-es-route 
extended-evi-range boolean
route-distinguisher-ip-address string
route-target-type keyword
ad-per-evi-routes 
attribute-propagation boolean
bgp-path-selection boolean
d-path-ignore boolean
ethernet-segment string 
ac-df-capability keyword
admin-state keyword
apply-groups reference
apply-groups-exclude reference
association 
lag reference 
apply-groups reference
apply-groups-exclude reference
virtual-ranges 
dot1q 
q-tag (number | keyword) 
apply-groups reference
apply-groups-exclude reference
end (number | keyword)
qinq 
s-tag (number | keyword) 
apply-groups reference
apply-groups-exclude reference
end (number | keyword)
s-tag-c-tag (number | keyword) c-tag-start (number | keyword) 
apply-groups reference
apply-groups-exclude reference
c-tag-end (number | keyword)
network-interconnect-vxlan number 
apply-groups reference
apply-groups-exclude reference
virtual-ranges 
service-id number 
apply-groups reference
apply-groups-exclude reference
end number
port reference 
apply-groups reference
apply-groups-exclude reference
virtual-ranges 
dot1q 
q-tag (number | keyword) 
apply-groups reference
apply-groups-exclude reference
end (number | keyword)
qinq 
s-tag (number | keyword) 
apply-groups reference
apply-groups-exclude reference
end (number | keyword)
s-tag-c-tag (number | keyword) c-tag-start (number | keyword) 
apply-groups reference
apply-groups-exclude reference
c-tag-end (number | keyword)
pw-port reference 
apply-groups reference
apply-groups-exclude reference
pw-port-headend boolean
virtual-ranges 
dot1q 
q-tag (number | keyword) 
apply-groups reference
apply-groups-exclude reference
end (number | keyword)
qinq 
s-tag (number | keyword) 
apply-groups reference
apply-groups-exclude reference
end (number | keyword)
s-tag-c-tag (number | keyword) c-tag-start (number | keyword) 
apply-groups reference
apply-groups-exclude reference
c-tag-end (number | keyword)
sdp reference 
apply-groups reference
apply-groups-exclude reference
virtual-ranges 
vc-id number 
apply-groups reference
apply-groups-exclude reference
end number
vprn-next-hop (ipv4-address-no-zone | ipv6-address-no-zone) 
apply-groups reference
apply-groups-exclude reference
virtual-ranges 
evi number 
auto-esi keyword
df-election 
es-activation-timer number
manual 
evi number 
apply-groups reference
apply-groups-exclude reference
end number
isid number 
apply-groups reference
apply-groups-exclude reference
end number
preference 
apply-groups reference
apply-groups-exclude reference
mode keyword
value number
service-carving-mode keyword
esi string
multi-homing-mode keyword
oper-group reference
orig-ip (ipv4-address-no-zone | ipv6-address-no-zone)
pbb 
es-bmac-table-size number
source-bmac-lsb string
route-next-hop (ipv4-address-no-zone | ipv6-address-no-zone)
type keyword
etree-leaf-label boolean
etree-leaf-label-value (number | keyword)
ip-prefix-routes 
d-path-length-ignore boolean
iff-attribute-uniform-propagation boolean
iff-bgp-path-selection boolean
multicast-leave-sync-propagation number
route-distinguisher string
bgp-auto-rd-range 
apply-groups reference
apply-groups-exclude reference
community-value 
end number
start number
ip-address string
extended-default-qinq-sap-lookup boolean
fdb 
apply-groups reference
apply-groups-exclude reference
table-size number
gre-eth-bridged 
tunnel-termination (ipv4-address-no-zone | ipv6-address-no-zone) 
apply-groups reference
apply-groups-exclude reference
fpe-id reference
pw-port-list 
port string 
vpn-gre-source-ip string
vxlan 
assisted-replication 
apply-groups reference
apply-groups-exclude reference
ip-address string
tunnel-termination (ipv4-address-no-zone | ipv6-address-no-zone) 
apply-groups reference
apply-groups-exclude reference
fpe-id reference
template 
epipe-sap-template string 
apply-groups reference
apply-groups-exclude reference
egress 
filter 
ip reference
ipv6 reference
mac reference
qos 
policy-name reference
ingress 
filter 
ip reference
ipv6 reference
mac reference
qos 
policy-name reference
queuing-type keyword
upnp 
policy string 
apply-groups reference
apply-groups-exclude reference
description string
mapping-limit number
port number
strict-mode boolean
vpls string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bgp number 
adv-service-mtu number
apply-groups reference
apply-groups-exclude reference
pw-template-binding reference 
apply-groups reference
apply-groups-exclude reference
bfd-liveness boolean
bfd-template reference
import-rt string
monitor-oper-group reference
oper-group reference
split-horizon-group string
route-distinguisher (keyword | vpn-route-distinguisher)
route-target 
export string
import string
vsi-export reference
vsi-import reference
bgp-ad 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
vpls-id string
vsi-id-prefix string
bgp-evpn 
accept-ivpls-evpn-flush boolean
apply-groups reference
apply-groups-exclude reference
evi number
ignore-mtu-mismatch boolean
incl-mcast-orig-ip string
isid-route-target 
range number 
apply-groups reference
apply-groups-exclude reference
end number
route-target string
type keyword
mac-duplication 
blackhole boolean
detect 
num-moves number
trusted-mac-move-factor number
window number
retry (number | keyword)
trusted-mac-time number
mpls number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
auto-bind-tunnel 
allow-flex-algo-fallback boolean
ecmp number
enforce-strict-tunnel-tagging boolean
resolution keyword
resolution-filter 
bgp boolean
ldp boolean
mpls-fwd-policy boolean
rib-api boolean
rsvp boolean
sr-isis boolean
sr-ospf boolean
sr-ospf3 boolean
sr-policy boolean
sr-te boolean
udp boolean
weighted-ecmp boolean
control-word boolean
default-route-tag string
dynamic-egress-label-limit boolean
ecmp number
entropy-label boolean
evi-three-byte-auto-rt boolean
fdb 
protected-src-mac-violation-action keyword
force-vc-forwarding keyword
hash-label boolean
ingress-replication-bum-label boolean
mh-mode keyword
oper-group reference
route-next-hop 
ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
system-ipv4 
system-ipv6 
send-tunnel-encap 
mpls boolean
mpls-over-udp boolean
split-horizon-group reference
routes 
incl-mcast 
advertise-ingress-replication boolean
advertise-l2-attributes boolean
ip-prefix 
advertise boolean
domain-id string
include-direct-interface-host boolean
link-bandwidth 
advertise 
max-dynamic-weight number
weight (number | keyword)
weighted-ecmp boolean
mac-ip 
advertise boolean
arp-nd-extended-community boolean
cfm-mac boolean
unknown-mac boolean
sel-mcast 
advertise boolean
segment-routing-v6 number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
default-route-tag string
ecmp number
evi-three-byte-auto-rt boolean
fdb 
protected-src-mac-violation-action keyword
force-vc-forwarding keyword
mh-mode keyword
oper-group reference
resolution keyword
route-next-hop 
ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
system-ipv4 
system-ipv6 
source-address string
split-horizon-group reference
srv6 
default-locator string
instance reference
vxlan number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
default-route-tag string
ecmp number
evi-three-byte-auto-rt boolean
mh-mode keyword
oper-group reference
routes 
auto-disc 
advertise boolean
send-incl-mcast-ir-on-ndf boolean
send-tunnel-encap boolean
vxlan-instance reference
bgp-mh-site string 
activation-timer number
admin-state keyword
apply-groups reference
apply-groups-exclude reference
boot-timer number
failed-threshold (number | keyword)
id number
mesh-sdp-binds 
min-down-timer number
monitor-oper-group reference
sap string
shg-name string
spoke-sdp string
bgp-vpls 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
maximum-ve-id number
ve 
id number
name string
capture-sap string 
admin-state keyword
allow-dot1q-msaps boolean
apply-groups reference
apply-groups-exclude reference
bandwidth number
cpu-protection 
mac-monitoring 
policy-id reference
description string
dhcp 
python-policy reference
user-db reference
dhcp6 
python-policy reference
user-db reference
dist-cpu-protection reference
host-lockout-policy reference
ingress 
filter 
mac reference
ipoe-session 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
ipoe-session-policy reference
user-db reference
msap-defaults 
group-interface string
policy reference
service-name string
nasreq-auth-policy reference
pfcp 
apply-groups reference
apply-groups-exclude reference
association reference
l2-access-id-alias string
up-resiliency 
monitor-oper-group reference 
apply-groups reference
apply-groups-exclude reference
health-drop number
pppoe 
policy reference
python-policy reference
user-db reference
radius-auth-policy reference
router-solicit 
user-db reference
track-srrp number
trigger-packet 
arp boolean
data boolean
dhcp boolean
dhcp6 boolean
pppoe boolean
rtr-solicit boolean
customer reference
description string
endpoint string 
apply-groups reference
apply-groups-exclude reference
block-on-mesh-failure boolean
description string
fdb 
auto-learn-mac-protect boolean
mac-pinning boolean
maximum-mac-addresses number
protected-src-mac-violation-action keyword
ignore-standby-signaling boolean
mc-endpoint number 
apply-groups reference
apply-groups-exclude reference
mc-ep-peer 
name string
peer-address reference
revert-time (number | keyword)
suppress-standby-signaling boolean
eth-cfm 
apply-groups reference
apply-groups-exclude reference
mep md-admin-name reference ma-admin-name reference mep-id number 
admin-state keyword
alarm-notification 
fng-alarm-time number
fng-reset-time number
apply-groups reference
apply-groups-exclude reference
ccm boolean
ccm-ltm-priority number
ccm-padding-size number
cfm-vlan-tag string
description string
eth-test 
bit-error-threshold number
test-pattern 
crc-tlv boolean
pattern keyword
grace 
eth-ed 
max-rx-defect-window number
priority number
rx-eth-ed boolean
tx-eth-ed boolean
eth-vsm-grace 
rx-eth-vsm-grace boolean
tx-eth-vsm-grace boolean
low-priority-defect keyword
mac-address string
one-way-delay-threshold number
etree boolean
fdb 
discard-unknown boolean
mac-learning 
aging boolean
learning boolean
local-age-time number
remote-age-time number
mac-move 
admin-state keyword
hold-down-time number
move-frequency number
primary-cumulative-factor number
retry-count (number | keyword)
sap reference 
apply-groups reference
apply-groups-exclude reference
level keyword
secondary-cumulative-factor number
spoke-sdp reference 
apply-groups reference
apply-groups-exclude reference
level keyword
mac-subnet-length number
selective-learning boolean
static-mac 
mac string 
apply-groups reference
apply-groups-exclude reference
blackhole 
endpoint reference
mesh-sdp reference
monitor keyword
sap reference
spoke-sdp reference
table 
high-wmark number
low-wmark number
size number
gsmp 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
group string 
admin-state keyword
ancp 
dynamic-topology-discovery boolean
oam boolean
apply-groups reference
apply-groups-exclude reference
description string
hold-multiplier number
idle-filter boolean
keepalive number
neighbor string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
local-address string
priority-marking 
dscp keyword
prec number
persistency boolean
igmp-host-tracking 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
expiry-time number
igmp-snooping 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
evpn-proxy 
admin-state keyword
mvr 
admin-state keyword
description string
group-policy string
query-interval number
query-source-address (keyword | ipv4-address)
report-source-address string
robust-count number
ignore-l2vpn-mtu-mismatch boolean
interface string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
hold-time 
ipv4 
down 
init-only boolean
seconds number
up 
seconds number
ipv4 
neighbor-discovery 
static-neighbor string 
apply-groups reference
apply-groups-exclude reference
mac-address string
timeout number
primary 
address string
apply-groups reference
apply-groups-exclude reference
prefix-length number
mac string
isid-policy 
entry number 
advertise-local boolean
apply-groups reference
apply-groups-exclude reference
range 
end number
start number
use-def-mcast boolean
load-balancing 
lbl-eth-or-ip-l4-teid boolean
per-service-hashing boolean
spi-load-balancing boolean
teid-load-balancing boolean
m-vpls boolean
mac-flush 
tldp 
propagate boolean
send-on-failure boolean
mac-protect 
mac string 
mcast-ipv6-snooping-scope keyword
mcr-default-gtw 
apply-groups reference
apply-groups-exclude reference
ip string
mac string
mesh-sdp string 
accounting-policy reference
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bfd 
bfd-liveness 
encap keyword
bfd-template reference
collect-stats boolean
control-word boolean
cpu-protection 
eth-cfm-monitoring 
aggregate 
car 
mac-monitoring 
policy-id reference
description string
dhcp 
apply-groups reference
apply-groups-exclude reference
description string
snoop boolean
egress 
filter 
ip reference
ipv6 reference
mac reference
mfib-allowed-mda-destinations 
mda string 
qos 
network 
policy-name reference
port-redirect-group 
group-name reference
instance number
vc-label number
entropy-label 
eth-cfm 
apply-groups reference
apply-groups-exclude reference
collect-lmm-fc-stats 
fc keyword
fc-in-profile keyword
collect-lmm-stats boolean
mep md-admin-name reference ma-admin-name reference mep-id number 
admin-state keyword
ais 
client-meg-level number
interface-support boolean
interval number
low-priority-defect keyword
priority number
alarm-notification 
fng-alarm-time number
fng-reset-time number
apply-groups reference
apply-groups-exclude reference
ccm boolean
ccm-ltm-priority number
ccm-padding-size number
cfm-vlan-tag string
csf 
multiplier decimal-number
description string
direction keyword
eth-test 
bit-error-threshold number
test-pattern 
crc-tlv boolean
pattern keyword
fault-propagation keyword
grace 
eth-ed 
max-rx-defect-window number
priority number
rx-eth-ed boolean
tx-eth-ed boolean
eth-vsm-grace 
rx-eth-vsm-grace boolean
tx-eth-vsm-grace boolean
lbm-svc-act-responder boolean
low-priority-defect keyword
mac-address string
one-way-delay-threshold number
primary-vlan boolean
mip primary-vlan (number | keyword) 
apply-groups reference
apply-groups-exclude reference
cfm-vlan-tag string
mac-address string
squelch-ingress-ctag-levels number
squelch-ingress-levels number
vmep-filter boolean
etree-leaf boolean
etree-root-leaf-tag boolean
fdb 
auto-learn-mac-protect boolean
auto-learn-mac-protect-exclude-list reference
mac-pinning boolean
protected-src-mac-violation-action keyword
force-vc-forwarding keyword
hash-label 
signal-capability 
igmp-snooping 
apply-groups reference
apply-groups-exclude reference
fast-leave boolean
import-policy reference
maximum-number-group-sources number
maximum-number-groups number
maximum-number-sources number
mcac 
bandwidth 
mandatory (number | keyword)
total (number | keyword)
interface-policy reference
policy reference
mrouter-port boolean
query-interval number
query-last-member-interval number
query-response-interval number
robust-count number
router-alert-check boolean
send-queries boolean
static 
group string 
apply-groups reference
apply-groups-exclude reference
source string 
starg 
version keyword
ingress 
filter 
ip reference
ipv6 reference
mac reference
qos 
network 
fp-redirect-group 
group-name reference
instance number
policy-name reference
vc-label number
mld-snooping 
apply-groups reference
apply-groups-exclude reference
fast-leave boolean
import-policy reference
maximum-number-groups number
mrouter-port boolean
query-interval number
query-last-member-interval number
query-response-interval number
robust-count number
router-alert-check boolean
send-queries boolean
static 
group string 
apply-groups reference
apply-groups-exclude reference
source string 
starg 
version keyword
mrp 
apply-groups reference
apply-groups-exclude reference
join-time number
leave-all-time number
leave-time number
periodic-time number
periodic-timer boolean
policy reference
pbb 
fault-propagation 
backbone-mac-address string 
backbone-mac-name reference 
vc-type keyword
vlan-vc-tag number
mfib 
table 
high-wmark number
low-wmark number
size number
mld-snooping 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
evpn-proxy 
admin-state keyword
mvr 
admin-state keyword
description string
group-policy string
query-interval number
query-source-address (keyword | ipv6-address)
report-source-address string
robust-count number
mrp 
admin-state keyword
mmrp 
admin-state keyword
attribute-table 
high-wmark number
low-wmark number
size number
end-station-only boolean
flood-time number
multicast-info-policy reference
pbb 
backbone-vpls reference 
apply-groups reference
apply-groups-exclude reference
fdb 
protected-src-mac-violation-action keyword
igmp-snooping 
mrouter-destination reference 
isid number
mesh-sdp reference 
apply-groups reference
apply-groups-exclude reference
igmp-snooping 
mrouter-port boolean
mld-snooping 
mrouter-port boolean
mld-snooping 
mrouter-destination reference 
sap reference 
apply-groups reference
apply-groups-exclude reference
igmp-snooping 
mrouter-port boolean
mld-snooping 
mrouter-port boolean
spoke-sdp reference 
apply-groups reference
apply-groups-exclude reference
igmp-snooping 
mrouter-port boolean
mld-snooping 
mrouter-port boolean
force-qtag-forwarding boolean
i-vpls-mac-flush 
bgp-evpn 
send-to-bvpls boolean
tldp 
propagate-from-bvpls boolean
send-on-bvpls-failure boolean
send-to-bvpls 
all-but-mine boolean
all-from-me boolean
mac-notification 
admin-state keyword
count number
interval number
renotify (number | keyword)
source-bmac 
address string
use-es-bmac-lsb boolean
use-mclag-bmac-lsb boolean
pbb-type keyword
pim-snooping 
apply-groups reference
apply-groups-exclude reference
group-policy string
hold-time number
ipv4 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
ipv6 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
provider-tunnel 
apply-groups reference
apply-groups-exclude reference
inclusive 
admin-state keyword
data-delay-interval number
mldp 
owner keyword
root-and-leaf boolean
rsvp 
lsp-template reference
selective 
admin-state keyword
data-delay-interval number
data-threshold 
group-prefix (ipv4-prefix | ipv6-prefix) 
apply-groups reference
apply-groups-exclude reference
pe-threshold-add number
pe-threshold-delete number
threshold number
maximum-p2mp-spmsi number
mldp boolean
owner keyword
wildcard-spmsi boolean
proxy-arp 
admin-state keyword
age-time (number | keyword)
apply-groups reference
apply-groups-exclude reference
duplicate-detect 
anti-spoof-mac string
hold-down-time (number | keyword)
num-moves number
static-blackhole boolean
window number
dynamic-arp 
ip-address string 
apply-groups reference
apply-groups-exclude reference
mac-list reference
resolve-retry-time number
dynamic-populate boolean
evpn 
flood 
gratuitous-arp boolean
unknown-arp-req boolean
route-tag number
process-arp-probes boolean
send-refresh (number | keyword)
static-arp 
ip-address string 
apply-groups reference
apply-groups-exclude reference
mac string
table-size number
proxy-nd 
admin-state keyword
age-time (number | keyword)
apply-groups reference
apply-groups-exclude reference
duplicate-detect 
anti-spoof-mac string
hold-down-time (number | keyword)
num-moves number
static-blackhole boolean
window number
dynamic-neighbor 
ip-address string 
apply-groups reference
apply-groups-exclude reference
mac-list reference
resolve-retry-time number
dynamic-populate boolean
evpn 
advertise-neighbor-type keyword
flood 
unknown-neighbor-advertise-host boolean
unknown-neighbor-advertise-router boolean
unknown-neighbor-solicitation boolean
route-tag number
process-dad-neighbor-solicitations boolean
send-refresh (number | keyword)
static-neighbor 
ip-address string 
apply-groups reference
apply-groups-exclude reference
mac string
type keyword
table-size number
routed-vpls 
evpn-mpls-ecmp boolean
multicast 
apply-groups reference
apply-groups-exclude reference
evpn-gateway 
admin-state keyword
advertise keyword
apply-groups reference
apply-groups-exclude reference
dr-activation-timer number
non-dr-attract-traffic keyword
ip-multicast-ecmp boolean
ipv4 
forward-to-ip-interface boolean
igmp-snooping 
mrouter-port boolean
ipv6 
forward-to-ip-interface boolean
mld-snooping 
mrouter-port boolean
vxlan-ipv4-tep-ecmp boolean
sap string 
accounting-policy reference
admin-state keyword
anti-spoof keyword
app-profile reference
apply-groups reference
apply-groups-exclude reference
arp-host 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
host-limit number
min-auth-interval number
arp-reply-agent keyword
bandwidth number
bgp-vpls-mh-veid number
bpdu-translation keyword
calling-station-id string
cflowd boolean
collect-stats boolean
cpu-protection 
eth-cfm-monitoring 
aggregate 
car 
mac-monitoring 
policy-id reference
description string
dhcp 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
lease-populate 
max-leases number
option-82 
action keyword
circuit-id 
ascii-tuple 
hex-string string
none 
vlan-ascii-tuple 
remote-id 
ascii-string string
hex-string string
mac 
none 
vendor-specific-option 
client-mac-address boolean
sap-id boolean
service-id boolean
string string
system-id boolean
proxy-server 
admin-state keyword
emulated-server string
lease-time 
radius-override boolean
value number
snoop boolean
dhcp6 
apply-groups reference
apply-groups-exclude reference
description string
ldra 
interface-type keyword
options 
interface-id 
ascii-tuple 
vlan-ascii-tuple 
remote-id 
mac 
string string
dist-cpu-protection reference
egress 
agg-rate 
adaptation-rule keyword
burst-limit (number | keyword)
limit-unused-bandwidth boolean
queue-frame-based-accounting boolean
rate number
dest-mac-rewrite string
filter 
ip reference
ipv6 reference
mac reference
qos 
policer-control-policy 
overrides 
apply-groups reference
apply-groups-exclude reference
root 
max-rate (number | keyword)
priority-mbs-thresholds 
min-thresh-separation (number | keyword)
priority number 
apply-groups reference
apply-groups-exclude reference
mbs-contribution (number | keyword)
policy-name reference
qinq-mark-top-only boolean
sap-egress 
overrides 
hs-secondary-shaper string
hs-wrr-group reference 
apply-groups reference
apply-groups-exclude reference
hs-class-weight number
percent-rate decimal-number
rate (number | keyword)
policer reference 
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
mbs (number | keyword)
packet-byte-offset number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
stat-mode keyword
queue reference 
adaptation-rule 
cir keyword
pir keyword
apply-groups reference
apply-groups-exclude reference
avg-frame-overhead decimal-number
burst-limit (number | keyword)
cbs (number | keyword)
drop-tail 
low 
percent-reduction-from-mbs (number | keyword)
hs-class-weight number
hs-wred-queue 
policy reference
hs-wrr-weight number
mbs (number | keyword)
monitor-queue-depth 
fast-polling boolean
violation-threshold decimal-number
parent 
cir-weight number
weight number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
port-redirect-group 
group-name reference
instance number
scheduler-policy 
overrides 
scheduler string 
apply-groups reference
apply-groups-exclude reference
parent 
cir-weight number
weight number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
virtual-port 
vport-name reference
eth-cfm 
apply-groups reference
apply-groups-exclude reference
collect-lmm-fc-stats 
fc keyword
fc-in-profile keyword
collect-lmm-stats boolean
mep md-admin-name reference ma-admin-name reference mep-id number 
admin-state keyword
ais 
client-meg-level number
interface-support boolean
interval number
low-priority-defect keyword
priority number
alarm-notification 
fng-alarm-time number
fng-reset-time number
apply-groups reference
apply-groups-exclude reference
ccm boolean
ccm-ltm-priority number
ccm-padding-size number
cfm-vlan-tag string
csf 
multiplier decimal-number
description string
direction keyword
eth-test 
bit-error-threshold number
test-pattern 
crc-tlv boolean
pattern keyword
fault-propagation keyword
grace 
eth-ed 
max-rx-defect-window number
priority number
rx-eth-ed boolean
tx-eth-ed boolean
eth-vsm-grace 
rx-eth-vsm-grace boolean
tx-eth-vsm-grace boolean
lbm-svc-act-responder boolean
low-priority-defect keyword
mac-address string
one-way-delay-threshold number
primary-vlan boolean
mip primary-vlan (number | keyword) 
apply-groups reference
apply-groups-exclude reference
cfm-vlan-tag string
mac-address string
squelch-ingress-ctag-levels number
squelch-ingress-levels number
vmep-filter boolean
eth-ring number
etree-leaf boolean
etree-root-leaf-tag 
leaf number
fdb 
auto-learn-mac-protect boolean
auto-learn-mac-protect-exclude-list reference
discard-unknown-source boolean
discard-unprotected-dest-mac boolean
limit-mac-move keyword
mac-learning 
aging boolean
learning boolean
mac-pinning boolean
maximum-mac-addresses number
protected-src-mac-violation-action keyword
host-admin-state keyword
host-lockout-policy reference
i-vpls-mac-flush 
bgp-evpn 
send-to-bvpls boolean
igmp-host-tracking 
apply-groups reference
apply-groups-exclude reference
expiry-time number
import-policy reference
maximum-number-group-sources number
maximum-number-groups number
maximum-number-sources number
router-alert-check boolean
igmp-snooping 
apply-groups reference
apply-groups-exclude reference
fast-leave boolean
import-policy reference
maximum-number-group-sources number
maximum-number-groups number
maximum-number-sources number
mcac 
bandwidth 
mandatory (number | keyword)
total (number | keyword)
interface-policy reference
mc-constraints 
level number 
apply-groups reference
apply-groups-exclude reference
bandwidth number
number-down number 
apply-groups reference
apply-groups-exclude reference
level number
use-lag-port-weight boolean
policy reference
mrouter-port boolean
mvr 
from-vpls reference
to-sap string
query-interval number
query-last-member-interval number
query-response-interval number
robust-count number
router-alert-check boolean
send-queries boolean
static 
group string 
apply-groups reference
apply-groups-exclude reference
source string 
starg 
version keyword
ingress 
filter 
ip reference
ipv6 reference
mac reference
qos 
match-qinq-dot1p keyword
policer-control-policy 
overrides 
apply-groups reference
apply-groups-exclude reference
root 
max-rate (number | keyword)
priority-mbs-thresholds 
min-thresh-separation (number | keyword)
priority number 
apply-groups reference
apply-groups-exclude reference
mbs-contribution (number | keyword)
policy-name reference
sap-ingress 
fp-redirect-group 
group-name reference
instance number
overrides 
ip-criteria 
activate-entry-tag number
ipv6-criteria 
activate-entry-tag number
policer reference 
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
mbs (number | keyword)
packet-byte-offset number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
stat-mode keyword
queue reference 
adaptation-rule 
cir keyword
pir keyword
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
drop-tail 
low 
percent-reduction-from-mbs (number | keyword)
mbs (number | keyword)
monitor-queue-depth 
fast-polling boolean
parent 
cir-weight number
weight number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
queuing-type keyword
scheduler-policy 
overrides 
scheduler string 
apply-groups reference
apply-groups-exclude reference
parent 
cir-weight number
weight number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
qtag-manipulation 
c-tag (number | keyword)
push-dot1q-vlan (number | keyword)
s-tag number
l2pt 
force-boundary 
protocols 
cdp boolean
dtp boolean
pagp boolean
stp boolean
udld boolean
vtp boolean
termination 
protocols 
cdp boolean
dtp boolean
pagp boolean
stp boolean
udld boolean
vtp boolean
l2tpv3-session 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
pseudo-wire 
ethernet 
ethernet-vlan-id number
router 
group string
router-instance string
vc-id number
lag 
link-map-profile number
per-link-hash 
class number
weight number
managed-vlan-list 
range string 
mc-ring 
apply-groups reference
apply-groups-exclude reference
ring-node string
mld-snooping 
apply-groups reference
apply-groups-exclude reference
fast-leave boolean
import-policy reference
maximum-number-groups number
mrouter-port boolean
mvr 
from-vpls reference
to-sap string
query-interval number
query-last-member-interval number
query-response-interval number
robust-count number
router-alert-check boolean
send-queries boolean
static 
group string 
apply-groups reference
apply-groups-exclude reference
source string 
starg 
version keyword
monitor-oper-group reference
mrp 
join-time number
leave-all-time number
leave-time number
periodic-time number
periodic-timer boolean
policy reference
multi-service-site reference
oper-group reference
pbb 
fault-propagation 
backbone-mac-address string 
backbone-mac-name reference 
pim-snooping 
apply-groups reference
apply-groups-exclude reference
maximum-number-groups number
process-cpm-traffic-on-sap-down boolean
radius-auth-policy reference
shcv-policy-ipv4 reference
spb 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
level number 
apply-groups reference
apply-groups-exclude reference
hello-interval number
hello-multiplier number
metric number
lsp-pacing-interval number
retransmit-interval number
split-horizon-group reference
static-host 
ipv4 string mac string 
admin-state keyword
ancp-string string
app-profile 
profile reference
apply-groups reference
apply-groups-exclude reference
int-dest-id string
shcv 
sla-profile reference
sub-profile reference
subscriber-id 
string string
use-sap-id 
static-isid 
range number 
apply-groups reference
apply-groups-exclude reference
end number
start number
stp 
admin-state keyword
auto-edge boolean
edge-port boolean
link-type keyword
mst-instance number 
apply-groups reference
apply-groups-exclude reference
mst-path-cost number
mst-port-priority number
path-cost number
port-num number
priority number
root-guard boolean
sub-sla-mgmt 
admin-state keyword
defaults 
app-profile reference
int-dest-id 
string string
top-q-tag 
sla-profile reference
sub-profile reference
subscriber-id 
auto-id 
sap-id 
string string
mac-da-hashing boolean
single-sub-parameters 
non-sub-traffic 
app-profile reference
sla-profile reference
sub-profile reference
subscriber-id string
profiled-traffic-only boolean
sub-ident-policy reference
subscriber-limit (keyword | number)
transit-policy 
ip reference
prefix reference
segment-routing-v6 number 
apply-groups reference
apply-groups-exclude reference
locator reference 
apply-groups reference
apply-groups-exclude reference
function 
end-dt2m 
value number
end-dt2u 
value number
micro-segment-locator reference 
apply-groups reference
apply-groups-exclude reference
function 
udt2m 
value number
udt2u 
value number
service-id number
service-mtu number
shcv-policy-ipv4 reference
spb 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
fid number
isis-instance number
level number 
apply-groups reference
apply-groups-exclude reference
bridge-priority number
ect-high-path-fid number 
forwarding-tree 
topology keyword
lsp-lifetime number
lsp-refresh-interval 
half-lifetime boolean
interval number
overload 
timeout number
overload-on-boot 
timeout number
timers 
lsp-wait 
initial-wait number
max-wait number
second-wait number
spf-wait 
initial-wait number
max-wait number
second-wait number
spbm-control-vpls 
fid number
service-name string
split-horizon-group string 
apply-groups reference
apply-groups-exclude reference
description string
fdb 
saps 
auto-learn-mac-protect boolean
auto-learn-mac-protect-exclude-list reference
discard-unprotected-dest-mac boolean
protected-src-mac-violation-action keyword
residential boolean
spoke-sdp string 
accounting-policy reference
admin-state keyword
app-profile reference
apply-groups reference
apply-groups-exclude reference
bfd 
bfd-liveness 
encap keyword
bfd-template reference
failure-action keyword
wait-for-up-timer number
block-on-mesh-failure boolean
bpdu-translation keyword
collect-stats boolean
control-word boolean
cpu-protection 
eth-cfm-monitoring 
aggregate 
car 
mac-monitoring 
policy-id reference
description string
dhcp 
apply-groups reference
apply-groups-exclude reference
description string
snoop boolean
egress 
filter 
ip reference
ipv6 reference
mac reference
mfib-allowed-mda-destinations 
mda string 
qos 
network 
policy-name reference
port-redirect-group 
group-name reference
instance number
vc-label number
endpoint 
name reference
precedence (number | keyword)
entropy-label 
eth-cfm 
apply-groups reference
apply-groups-exclude reference
collect-lmm-fc-stats 
fc keyword
fc-in-profile keyword
collect-lmm-stats boolean
mep md-admin-name reference ma-admin-name reference mep-id number 
admin-state keyword
ais 
client-meg-level number
interface-support boolean
interval number
low-priority-defect keyword
priority number
alarm-notification 
fng-alarm-time number
fng-reset-time number
apply-groups reference
apply-groups-exclude reference
ccm boolean
ccm-ltm-priority number
ccm-padding-size number
cfm-vlan-tag string
csf 
multiplier decimal-number
description string
direction keyword
eth-test 
bit-error-threshold number
test-pattern 
crc-tlv boolean
pattern keyword
fault-propagation keyword
grace 
eth-ed 
max-rx-defect-window number
priority number
rx-eth-ed boolean
tx-eth-ed boolean
eth-vsm-grace 
rx-eth-vsm-grace boolean
tx-eth-vsm-grace boolean
lbm-svc-act-responder boolean
low-priority-defect keyword
mac-address string
one-way-delay-threshold number
primary-vlan boolean
mip primary-vlan (number | keyword) 
apply-groups reference
apply-groups-exclude reference
cfm-vlan-tag string
mac-address string
squelch-ingress-ctag-levels number
squelch-ingress-levels number
vmep-filter boolean
etree-leaf boolean
etree-root-leaf-tag boolean
fdb 
auto-learn-mac-protect boolean
auto-learn-mac-protect-exclude-list reference
discard-unknown-source boolean
limit-mac-move keyword
mac-learning 
aging boolean
learning boolean
mac-pinning boolean
maximum-mac-addresses number
protected-src-mac-violation-action keyword
force-vc-forwarding keyword
hash-label 
signal-capability 
i-vpls-mac-flush 
bgp-evpn 
send-to-bvpls boolean
igmp-snooping 
apply-groups reference
apply-groups-exclude reference
fast-leave boolean
import-policy reference
maximum-number-group-sources number
maximum-number-groups number
maximum-number-sources number
mcac 
bandwidth 
mandatory (number | keyword)
total (number | keyword)
interface-policy reference
policy reference
mrouter-port boolean
query-interval number
query-last-member-interval number
query-response-interval number
robust-count number
router-alert-check boolean
send-queries boolean
static 
group string 
apply-groups reference
apply-groups-exclude reference
source string 
starg 
version keyword
ignore-standby-signaling boolean
ingress 
filter 
ip reference
ipv6 reference
mac reference
qos 
network 
fp-redirect-group 
group-name reference
instance number
policy-name reference
vc-label number
l2pt 
termination 
protocols 
cdp boolean
dtp boolean
pagp boolean
stp boolean
udld boolean
vtp boolean
mld-snooping 
apply-groups reference
apply-groups-exclude reference
fast-leave boolean
import-policy reference
maximum-number-groups number
mrouter-port boolean
query-interval number
query-last-member-interval number
query-response-interval number
robust-count number
router-alert-check boolean
send-queries boolean
static 
group string 
apply-groups reference
apply-groups-exclude reference
source string 
starg 
version keyword
monitor-oper-group reference
mrp 
apply-groups reference
apply-groups-exclude reference
join-time number
leave-all-time number
leave-time number
periodic-time number
periodic-timer boolean
policy reference
oper-group reference
pbb 
fault-propagation 
backbone-mac-address string 
backbone-mac-name reference 
pim-snooping 
apply-groups reference
apply-groups-exclude reference
maximum-number-groups number
pw-status 
signaling boolean
spb 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
level number 
apply-groups reference
apply-groups-exclude reference
hello-interval number
hello-multiplier number
metric number
lsp-pacing-interval number
retransmit-interval number
split-horizon-group reference
static-isid 
range number 
apply-groups reference
apply-groups-exclude reference
end number
start number
stp 
admin-state keyword
auto-edge boolean
edge-port boolean
link-type keyword
path-cost number
port-num number
priority number
root-guard boolean
transit-policy 
prefix reference
vc-type keyword
vlan-vc-tag number
stp 
admin-state keyword
forward-delay number
hello-time number
hold-count number
maximum-age number
mode keyword
mst-instance number 
apply-groups reference
apply-groups-exclude reference
mst-priority number
vlan-range string 
mst-maximum-hops number
mst-name string
mst-revision number
priority number
temp-flooding number
tunnel-elmi boolean
vpn-id number
vxlan 
instance number 
apply-groups reference
apply-groups-exclude reference
assisted-replication 
leaf 
acttime number
replicator 
egress-vtep (ipv4-address-no-zone | ipv6-address-no-zone) 
fdb 
discard-unknown-source boolean
mac-learning 
aging boolean
learning boolean
maximum-mac-addresses number
protected-src-mac-violation-action keyword
igmp-snooping 
mrouter-port boolean
mld-snooping 
mrouter-port boolean
network 
ingress 
qos 
network 
fp-redirect-group 
group-name reference
instance number
policy-name reference
rx-discard-on-ndf keyword
source-vtep-security boolean
vni number
source-vtep (ipv4-address-no-zone | ipv6-address-no-zone)
wlan-gw 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
wlan-gw-group reference
vprn string 
aa-interface string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
ip-mtu number
ipv4 
primary 
address string
apply-groups reference
apply-groups-exclude reference
prefix-length number
sap string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
egress 
filter 
ip reference
qos 
sap-egress 
policy-name reference
virtual-port 
vport-name reference
fwd-wholesale 
pppoe-service reference
ingress 
qos 
sap-ingress 
overrides 
policy-name reference
lag 
aaa 
remote-servers 
radius 
access-algorithm keyword
accounting boolean
accounting-port number
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authorization boolean
interactive-authentication boolean
port number
server number 
address (ipv4-address-no-zone | ipv6-address-no-zone)
apply-groups reference
apply-groups-exclude reference
authenticator keyword
secret string
tls-client-profile reference
server-retry number
server-timeout number
use-default-template boolean
tacplus 
accounting 
record-type keyword
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authorization 
request-format 
access-operation-cmd keyword
use-priv-lvl boolean
interactive-authentication boolean
priv-lvl-map 
priv-lvl number 
apply-groups reference
apply-groups-exclude reference
user-profile-name reference
server number 
address (ipv4-address-no-zone | ipv6-address-no-zone)
apply-groups reference
apply-groups-exclude reference
port number
secret string
server-timeout number
use-default-template boolean
aarp-interface string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
ip-mtu number
spoke-sdp string 
aarp 
id reference
type keyword
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
egress 
filter 
ip reference
vc-label number
ingress 
filter 
ip reference
vc-label number
admin-state keyword
aggregates 
aggregate (ipv4-prefix | ipv6-prefix) 
aggregator 
address string
as-number number
apply-groups reference
apply-groups-exclude reference
as-set boolean
blackhole 
generate-icmp boolean
community string
description string
discard-component-communities boolean
indirect (ipv4-address-no-zone | ipv6-address-no-zone)
local-preference number
policy reference
summary-only boolean
tunnel-group number
apply-groups reference
apply-groups-exclude reference
allow-export-bgp-vpn boolean
apply-groups reference
apply-groups-exclude reference
autonomous-system number
bgp 
admin-state keyword
advertise-inactive boolean
advertise-ipv6-next-hops 
ipv4 boolean
aggregator-id-zero boolean
apply-groups reference
apply-groups-exclude reference
asn-4-byte boolean
attribute-set 
remove boolean
authentication-key string
authentication-keychain reference
backup-path 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
label-ipv6 boolean
best-path-selection 
always-compare-med 
med-value keyword
strict-as boolean
as-path-ignore 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
label-ipv6 boolean
compare-origin-validation-state boolean
d-path-length-ignore boolean
deterministic-med boolean
ebgp-ibgp-equal 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
label-ipv6 boolean
ignore-nh-metric boolean
ignore-router-id 
origin-invalid-unusable boolean
bfd-liveness boolean
bfd-strict-mode 
advertise 
holdtime number
next-hop-reachability boolean
client-reflect boolean
cluster 
cluster-id string
connect-retry number
convergence 
family keyword 
apply-groups reference
apply-groups-exclude reference
max-wait-to-advertise number
min-wait-to-advertise number
damp-peer-oscillations 
error-interval number
idle-hold-time 
initial-wait number
max-wait number
second-wait number
damping boolean
default-label-preference 
ebgp number
ibgp number
default-preference 
ebgp number
ibgp number
description string
domain-id string
dynamic-neighbor-limit number
ebgp-default-reject-policy 
export boolean
import boolean
eibgp-loadbalance boolean
enforce-first-as boolean
error-handling 
update-fault-tolerance boolean
export 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
extended-nh-encoding 
ipv4 boolean
family 
flow-ipv4 boolean
flow-ipv6 boolean
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
mcast-ipv4 boolean
mcast-ipv6 boolean
fast-external-failover boolean
flowspec 
validate-dest-prefix boolean
validate-redirect-ip boolean
graceful-restart 
gr-notification boolean
long-lived 
advertise-stale-to-all-neighbors boolean
advertised-stale-time number
family keyword 
advertised-stale-time number
apply-groups reference
apply-groups-exclude reference
helper-override-stale-time number
forwarding-bits-set keyword
helper-override-restart-time number
helper-override-stale-time number
without-no-export boolean
restart-time number
stale-routes-time number
group string 
admin-state keyword
advertise-inactive boolean
advertise-ipv6-next-hops 
ipv4 boolean
aggregator-id-zero boolean
apply-groups reference
apply-groups-exclude reference
as-override boolean
asn-4-byte boolean
authentication-key string
authentication-keychain reference
bfd-liveness boolean
bfd-strict-mode 
advertise 
holdtime number
next-hop-reachability boolean
capability-negotiation boolean
client-reflect boolean
cluster 
cluster-id string
connect-retry number
damp-peer-oscillations 
error-interval number
idle-hold-time 
initial-wait number
max-wait number
second-wait number
damping boolean
default-label-preference 
ebgp number
ibgp number
default-preference 
ebgp number
ibgp number
description string
dynamic-neighbor 
interface reference 
allowed-peer-as string
apply-groups reference
apply-groups-exclude reference
max-sessions number
match 
prefix (ipv4-prefix | ipv6-prefix) 
allowed-peer-as string
apply-groups reference
apply-groups-exclude reference
dynamic-neighbor-limit number
ebgp-default-reject-policy 
export boolean
import boolean
enforce-first-as boolean
error-handling 
update-fault-tolerance boolean
evpn-link-bandwidth 
add-to-received-bgp number
export 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
extended-nh-encoding 
ipv4 boolean
family 
flow-ipv4 boolean
flow-ipv6 boolean
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
mcast-ipv4 boolean
mcast-ipv6 boolean
fast-external-failover boolean
graceful-restart 
gr-notification boolean
long-lived 
advertise-stale-to-all-neighbors boolean
advertised-stale-time number
family keyword 
advertised-stale-time number
apply-groups reference
apply-groups-exclude reference
helper-override-stale-time number
forwarding-bits-set keyword
helper-override-restart-time number
helper-override-stale-time number
without-no-export boolean
restart-time number
stale-routes-time number
hold-time 
minimum-hold-time number
seconds number
import 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
initial-send-delay-zero boolean
keepalive number
label-preference number
link-bandwidth 
accept-from-ebgp 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
add-to-received-ebgp 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
aggregate-used-paths 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
send-to-ebgp 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
local-address (ipv4-address-no-zone | ipv6-address-no-zone | interface-name)
local-as 
as-number number
prepend-global-as boolean
private boolean
local-preference number
loop-detect keyword
loop-detect-threshold number
med-out (number | keyword)
min-route-advertisement number
monitor 
admin-state keyword
all-stations boolean
apply-groups reference
apply-groups-exclude reference
route-monitoring 
post-policy boolean
pre-policy boolean
station reference 
multihop number
multipath-eligible boolean
next-hop-self boolean
origin-validation 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
passive boolean
path-mtu-discovery boolean
peer-as number
peer-ip-tracking boolean
preference number
prefix-limit keyword 
apply-groups reference
apply-groups-exclude reference
hold-excess number
idle-timeout number
log-only boolean
maximum number
post-import boolean
threshold number
remove-private 
limited boolean
replace boolean
skip-peer-as boolean
send-communities 
extended boolean
large boolean
standard boolean
send-default 
export-policy reference
ipv4 boolean
ipv6 boolean
split-horizon boolean
static-group boolean
tcp-mss (number | keyword)
third-party-nexthop boolean
ttl-security number
type keyword
hold-time 
minimum-hold-time number
seconds number
ibgp-multipath boolean
import 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
initial-send-delay-zero boolean
keepalive number
label-preference number
local-as 
as-number number
prepend-global-as boolean
private boolean
local-preference number
loop-detect keyword
loop-detect-threshold number
med-out (number | keyword)
min-route-advertisement number
monitor 
admin-state keyword
all-stations boolean
apply-groups reference
apply-groups-exclude reference
route-monitoring 
post-policy boolean
pre-policy boolean
station reference 
multihop number
multipath 
ebgp number
family keyword 
apply-groups reference
apply-groups-exclude reference
ebgp number
ibgp number
max-paths number
restrict keyword
unequal-cost boolean
ibgp number
max-paths number
restrict keyword
unequal-cost boolean
neighbor (ipv4-address-with-zone | ipv6-address-with-zone) 
admin-state keyword
advertise-inactive boolean
advertise-ipv6-next-hops 
ipv4 boolean
aggregator-id-zero boolean
apply-groups reference
apply-groups-exclude reference
as-override boolean
asn-4-byte boolean
authentication-key string
authentication-keychain reference
bfd-liveness boolean
bfd-strict-mode 
advertise 
holdtime number
next-hop-reachability boolean
capability-negotiation boolean
client-reflect boolean
cluster 
cluster-id string
connect-retry number
damp-peer-oscillations 
error-interval number
idle-hold-time 
initial-wait number
max-wait number
second-wait number
damping boolean
default-label-preference 
ebgp number
ibgp number
default-preference 
ebgp number
ibgp number
description string
ebgp-default-reject-policy 
export boolean
import boolean
enforce-first-as boolean
error-handling 
update-fault-tolerance boolean
evpn-link-bandwidth 
add-to-received-bgp number
export 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
extended-nh-encoding 
ipv4 boolean
family 
flow-ipv4 boolean
flow-ipv6 boolean
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
mcast-ipv4 boolean
mcast-ipv6 boolean
fast-external-failover boolean
graceful-restart 
gr-notification boolean
long-lived 
advertise-stale-to-all-neighbors boolean
advertised-stale-time number
family keyword 
advertised-stale-time number
apply-groups reference
apply-groups-exclude reference
helper-override-stale-time number
forwarding-bits-set keyword
helper-override-restart-time number
helper-override-stale-time number
without-no-export boolean
restart-time number
stale-routes-time number
group reference
hold-time 
minimum-hold-time number
seconds number
import 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
initial-send-delay-zero boolean
keepalive number
label-preference number
link-bandwidth 
accept-from-ebgp 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
add-to-received-ebgp 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
aggregate-used-paths 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
send-to-ebgp 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
local-address (ipv4-address-no-zone | ipv6-address-no-zone | interface-name)
local-as 
as-number number
prepend-global-as boolean
private boolean
local-preference number
loop-detect keyword
loop-detect-threshold number
med-out (number | keyword)
min-route-advertisement number
monitor 
admin-state keyword
all-stations boolean
apply-groups reference
apply-groups-exclude reference
route-monitoring 
post-policy boolean
pre-policy boolean
station reference 
multihop number
multipath-eligible boolean
next-hop-self boolean
origin-validation 
ipv4 boolean
ipv6 boolean
label-ipv4 boolean
passive boolean
path-mtu-discovery boolean
peer-as number
peer-creation-type keyword
peer-ip-tracking boolean
preference number
prefix-limit keyword 
apply-groups reference
apply-groups-exclude reference
hold-excess number
idle-timeout number
log-only boolean
maximum number
post-import boolean
threshold number
remove-private 
limited boolean
replace boolean
skip-peer-as boolean
send-communities 
extended boolean
large boolean
standard boolean
send-default 
export-policy reference
ipv4 boolean
ipv6 boolean
split-horizon boolean
tcp-mss (number | keyword)
third-party-nexthop boolean
ttl-security number
type keyword
next-hop-resolution 
policy reference
use-bgp-routes boolean
use-leaked-routes 
static boolean
path-mtu-discovery boolean
peer-ip-tracking boolean
peer-tracking-policy reference
preference number
rapid-withdrawal boolean
remove-private 
limited boolean
replace boolean
skip-peer-as boolean
rib-management 
ipv4 
leak-import 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
route-table-import 
apply-groups reference
apply-groups-exclude reference
policy-name reference
ipv6 
leak-import 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
route-table-import 
apply-groups reference
apply-groups-exclude reference
policy-name reference
label-ipv4 
leak-import 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
route-table-import 
apply-groups reference
apply-groups-exclude reference
policy-name reference
label-ipv6 
leak-import 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
router-id string
send-communities 
extended boolean
large boolean
standard boolean
send-default 
export-policy reference
ipv4 boolean
ipv6 boolean
split-horizon boolean
tcp-mss number
third-party-nexthop boolean
bgp-evpn 
mpls number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
auto-bind-tunnel 
allow-flex-algo-fallback boolean
ecmp number
enforce-strict-tunnel-tagging boolean
resolution keyword
resolution-filter 
bgp boolean
ldp boolean
mpls-fwd-policy boolean
rib-api boolean
rsvp boolean
sr-isis boolean
sr-ospf boolean
sr-ospf3 boolean
sr-policy boolean
sr-te boolean
udp boolean
default-route-tag string
domain-id string
dynamic-egress-label-limit boolean
evi number
evpn-link-bandwidth 
advertise 
max-dynamic-weight number
weight (number | keyword)
weighted-ecmp boolean
route-distinguisher (string | keyword)
send-tunnel-encap 
mpls boolean
mpls-over-udp boolean
vrf-export 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
vrf-import 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
vrf-target 
community string
export-community string
import-community string
segment-routing-v6 number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
default-route-tag string
domain-id string
evi number
evpn-link-bandwidth 
advertise 
max-dynamic-weight number
weight (number | keyword)
weighted-ecmp boolean
resolution keyword
route-distinguisher (string | keyword)
source-address string
srv6 
default-locator string
instance reference
vrf-export 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
vrf-import 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
vrf-target 
community string
export-community string
import-community string
bgp-ipvpn 
attribute-set 
export boolean
import keyword
mpls 
admin-state keyword
auto-bind-tunnel 
allow-flex-algo-fallback boolean
apply-groups reference
apply-groups-exclude reference
ecmp number
enforce-strict-tunnel-tagging boolean
resolution keyword
resolution-filter 
bgp boolean
gre boolean
ldp boolean
mpls-fwd-policy boolean
rib-api boolean
rsvp boolean
sr-isis boolean
sr-ospf boolean
sr-ospf3 boolean
sr-policy boolean
sr-te boolean
udp boolean
weighted-ecmp boolean
domain-id string
dynamic-egress-label-limit boolean
route-distinguisher (string | keyword)
vrf-export 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
vrf-import 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
vrf-target 
community string
export-community string
import-community string
segment-routing-v6 number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
default-route-tag string
domain-id string
resolution keyword
route-distinguisher (string | keyword)
source-address string
srv6 
default-locator string
instance reference
vrf-export 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
vrf-import 
apply-groups reference
apply-groups-exclude reference
policy (policy-expr-string | string)
vrf-target 
community string
export-community string
import-community string
bgp-shared-queue 
cir (number | keyword)
pir (number | keyword)
bgp-vpn-backup 
ipv4 boolean
ipv6 boolean
carrier-carrier-vpn boolean
class-forwarding boolean
confederation 
confed-as-num number
members number 
customer reference
d-path-length-ignore boolean
description string
dhcp-server 
apply-groups reference
apply-groups-exclude reference
dhcpv4 string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
failover 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
ignore-mclt-on-takeover boolean
maximum-client-lead-time number
partner-down-delay number
peer reference 
apply-groups reference
apply-groups-exclude reference
sync-tag string
startup-wait-time number
force-renews boolean
lease-hold 
additional-scenarios 
internal-lease-ipsec boolean
solicited-release boolean
time number
pool string 
apply-groups reference
apply-groups-exclude reference
description string
failover 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
ignore-mclt-on-takeover boolean
maximum-client-lead-time number
partner-down-delay number
peer reference 
apply-groups reference
apply-groups-exclude reference
sync-tag string
startup-wait-time number
max-lease-time number
min-lease-time number
minimum-free 
absolute number
event-when-depleted boolean
percent number
nak-non-matching-subnet boolean
offer-time number
options 
option (number | keyword) 
apply-groups reference
apply-groups-exclude reference
ascii-string string
duration number
empty 
hex-string string
ipv4-address string
netbios-node-type keyword
subnet string 
address-range string end string 
apply-groups reference
apply-groups-exclude reference
failover-control-type keyword
apply-groups reference
apply-groups-exclude reference
drain boolean
exclude-addresses string end string 
maximum-declined number
minimum-free 
absolute number
event-when-depleted boolean
percent number
options 
option (number | keyword) 
apply-groups reference
apply-groups-exclude reference
ascii-string string
duration number
empty 
hex-string string
ipv4-address string
netbios-node-type keyword
pool-selection 
use-gi-address 
scope keyword
use-pool-from-client 
delimiter string
user-db reference
user-identification keyword
dhcpv6 string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
auto-provisioned boolean
defaults 
apply-groups reference
apply-groups-exclude reference
options 
option (number | keyword) 
apply-groups reference
apply-groups-exclude reference
ascii-string string
domain-string string
duration number
empty 
hex-string string
ipv6-address string
preferred-lifetime number
rebind-time number
renew-time number
valid-lifetime number
description string
failover 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
ignore-mclt-on-takeover boolean
maximum-client-lead-time number
partner-down-delay number
peer reference 
apply-groups reference
apply-groups-exclude reference
sync-tag string
startup-wait-time number
ignore-rapid-commit boolean
interface-id-mapping boolean
lease-hold 
additional-scenarios 
internal-lease-ipsec boolean
solicited-release boolean
time number
lease-query boolean
pool string 
apply-groups reference
apply-groups-exclude reference
delegated-prefix 
length number
maximum number
minimum number
description string
exclude-prefix string 
failover 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
ignore-mclt-on-takeover boolean
maximum-client-lead-time number
partner-down-delay number
peer reference 
apply-groups reference
apply-groups-exclude reference
sync-tag string
startup-wait-time number
options 
option (number | keyword) 
apply-groups reference
apply-groups-exclude reference
ascii-string string
domain-string string
duration number
empty 
hex-string string
ipv6-address string
prefix string 
apply-groups reference
apply-groups-exclude reference
drain boolean
failover-control-type keyword
options 
option (number | keyword) 
apply-groups reference
apply-groups-exclude reference
ascii-string string
domain-string string
duration number
empty 
hex-string string
ipv6-address string
preferred-lifetime number
prefix-length-threshold number 
absolute number
apply-groups reference
apply-groups-exclude reference
event-when-depleted boolean
percent number
prefix-type 
pd boolean
wan-host boolean
rebind-time number
renew-time number
valid-lifetime number
prefix-length-threshold number 
apply-groups reference
apply-groups-exclude reference
event-when-depleted boolean
minimum-free-percent number
pool-selection 
use-link-address 
scope keyword
use-pool-from-client 
delimiter string
server-id 
apply-groups reference
apply-groups-exclude reference
duid-enterprise 
ascii-string string
hex-string string
duid-link-local 
user-identification keyword
dns 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
default-domain string
ipv4-source-address (keyword | ipv4-unicast-address)
ipv6-source-address (keyword | ipv6-unicast-address)
server (ipv4-address-no-zone | ipv6-address-no-zone)
ecmp number
ecmp-unequal-cost boolean
entropy-label boolean
eth-cfm 
apply-groups reference
apply-groups-exclude reference
export-inactive-bgp boolean
export-inactive-bgp-enhanced boolean
fib-priority keyword
firewall 
apply-groups reference
apply-groups-exclude reference
domain string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
dhcpv6-server 
name string
router-instance string
nat-group reference
prefix string 
apply-groups reference
apply-groups-exclude reference
description string
wlan-gw-group reference
flowspec 
apply-groups reference
apply-groups-exclude reference
filter-cam-type keyword
ip-filter-max-size number
ipv6-filter-max-size number
grt-leaking 
allow-local-management boolean
apply-groups reference
apply-groups-exclude reference
export-grt 
policy-name (policy-expr-string | string)
export-limit number
export-v6-limit number
grt-lookup boolean
import-grt 
policy-name (policy-expr-string | string)
gsmp 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
group string 
admin-state keyword
ancp 
dynamic-topology-discovery boolean
oam boolean
apply-groups reference
apply-groups-exclude reference
description string
hold-multiplier number
idle-filter boolean
keepalive number
neighbor string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
local-address string
priority-marking 
dscp keyword
prec number
persistency boolean
gtp 
s11 
interface reference 
apn-policy reference
apply-groups reference
apply-groups-exclude reference
peer-profile-map 
prefix (ipv4-prefix | ipv6-prefix) 
apply-groups reference
apply-groups-exclude reference
peer-profile reference
upf-data-endpoint 
apply-groups reference
apply-groups-exclude reference
fpe reference
interface reference
uplink 
apn string
apply-groups reference
apply-groups-exclude reference
pdn-type keyword
peer-profile-map 
prefix (ipv4-prefix | ipv6-prefix) 
apply-groups reference
apply-groups-exclude reference
peer-profile reference
hash-label boolean
igmp 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
forwarding-group-interface forwarding-service string group-interface-name reference 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
import-policy reference
maximum-number-group-sources number
maximum-number-groups number
maximum-number-sources number
mcac 
bandwidth 
mandatory (number | keyword)
total (number | keyword)
interface-policy reference
policy reference
query-interval number
query-last-member-interval number
query-response-interval number
query-source-address string
router-alert-check boolean
sub-hosts-only boolean
subnet-check boolean
version keyword
group-if-query-source-address string
group-interface reference 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
import-policy reference
maximum-number-group-sources number
maximum-number-groups number
maximum-number-sources number
mcac 
bandwidth 
mandatory (number | keyword)
total (number | keyword)
interface-policy reference
policy reference
query-interval number
query-last-member-interval number
query-response-interval number
query-source-address string
router-alert-check boolean
sub-hosts-only boolean
subnet-check boolean
version keyword
interface string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
import-policy reference
maximum-number-group-sources number
maximum-number-groups number
maximum-number-sources number
mcac 
bandwidth 
mandatory (number | keyword)
total (number | keyword)
interface-policy reference
mc-constraints 
level number 
apply-groups reference
apply-groups-exclude reference
bandwidth number
number-down number 
apply-groups reference
apply-groups-exclude reference
level number
use-lag-port-weight boolean
policy reference
query-interval number
query-last-member-interval number
query-response-interval number
redundant-mcast boolean
router-alert-check boolean
ssm-translate 
group-range start string end string 
apply-groups reference
apply-groups-exclude reference
source string 
static 
group string 
apply-groups reference
apply-groups-exclude reference
source string 
starg 
group-range start string end string step string 
apply-groups reference
apply-groups-exclude reference
source string 
starg 
subnet-check boolean
version keyword
query-interval number
query-last-member-interval number
query-response-interval number
robust-count number
ssm-translate 
group-range start string end string 
apply-groups reference
apply-groups-exclude reference
source string 
igmp-host-tracking 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
expiry-time number
ignore-nh-metric boolean
interface string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
cflowd-parameters 
sampling keyword 
apply-groups reference
apply-groups-exclude reference
direction keyword
sample-profile (keyword | number)
type keyword
cpu-protection reference
description string
dynamic-tunnel-redundant-nexthop string
external-reference 
openconfig 
subinterface number
hold-time 
ipv4 
down 
init-only boolean
seconds number
up 
seconds number
ipv6 
down 
init-only boolean
seconds number
up 
seconds number
if-attribute 
admin-group reference
srlg-group reference 
ingress 
destination-class-lookup boolean
policy-accounting reference
ingress-stats boolean
ip-mtu number
ipsec 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
ip-exception reference
ipsec-tunnel string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bfd 
bfd-designate boolean
bfd-liveness 
dest-ip string
interface string
service-name string
clear-df-bit boolean
copy-traffic-class-upon-decapsulation boolean
description string
encapsulated-ip-mtu number
icmp-generation 
frag-required 
admin-state keyword
interval number
message-count number
icmp6-generation 
packet-too-big 
admin-state keyword
interval number
message-count number
ip-mtu number
key-exchange 
dynamic 
auto-establish boolean
cert 
cert-profile reference
status-verify 
default-result keyword
primary keyword
secondary keyword
trust-anchor-profile reference
id 
fqdn string
ipv4 string
ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
ike-policy reference
ipsec-transform reference
pre-shared-key string
manual 
keys number direction keyword 
apply-groups reference
apply-groups-exclude reference
authentication-key string
encryption-key string
ipsec-transform reference
spi number
local-gateway-address-override (ipv4-address-no-zone | ipv6-address-no-zone)
max-history-key-records 
esp number
ike number
pmtu-discovery-aging number
private-sap number
private-service string
private-tcp-mss-adjust number
propagate-pmtu-v4 boolean
propagate-pmtu-v6 boolean
public-tcp-mss-adjust (number | keyword)
remote-gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
replay-window number
security-policy 
id number
strict-match boolean
ipv6-exception reference
public-sap number
tunnel-group reference
ipv4 
addresses 
address string 
apply-groups reference
apply-groups-exclude reference
prefix-length number
allow-directed-broadcasts boolean
bfd 
admin-state keyword
echo-receive number
multiplier number
receive number
transmit-interval number
type keyword
dhcp 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
gi-address string
lease-populate 
max-leases number
option-82 
action keyword
circuit-id 
ascii-tuple 
ifindex 
none 
sap-id 
vlan-ascii-tuple 
remote-id 
ascii-string string
mac 
none 
vendor-specific-option 
client-mac-address boolean
pool-name boolean
sap-id boolean
service-id boolean
string string
system-id boolean
proxy-server 
admin-state keyword
emulated-server string
lease-time 
radius-override boolean
value number
python-policy reference
relay-plain-bootp boolean
relay-proxy 
release-update-src-ip boolean
siaddr-override string
release-include-gi-address boolean
server string
src-ip-addr keyword
trusted boolean
use-arp boolean
icmp 
mask-reply boolean
param-problem 
admin-state keyword
number number
seconds number
redirects 
admin-state keyword
number number
seconds number
ttl-expired 
admin-state keyword
number number
seconds number
unreachables 
admin-state keyword
number number
seconds number
ip-helper-address string
local-dhcp-server reference
neighbor-discovery 
host-route 
populate keyword 
apply-groups reference
apply-groups-exclude reference
route-tag number
learn-unsolicited boolean
limit 
log-only boolean
max-entries number
threshold number
local-proxy-arp boolean
populate boolean
proactive-refresh boolean
proxy-arp-policy reference
remote-proxy-arp boolean
retry-timer number
static-neighbor string 
apply-groups reference
apply-groups-exclude reference
mac-address string
static-neighbor-unnumbered 
mac-address string
timeout number
primary 
address string
apply-groups reference
apply-groups-exclude reference
broadcast keyword
prefix-length number
track-srrp number
qos-route-lookup keyword
secondary string 
apply-groups reference
apply-groups-exclude reference
broadcast keyword
igp-inhibit boolean
prefix-length number
track-srrp number
tcp-mss number
unnumbered 
ip-address string
ip-int-name string
urpf-check 
ignore-default boolean
mode keyword
vrrp number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authentication-key string
backup string
bfd-liveness 
apply-groups reference
apply-groups-exclude reference
dest-ip string
interface-name string
service-name string
init-delay number
mac string
master-int-inherit boolean
message-interval number
monitor-oper-group reference
ntp-reply boolean
oper-group reference
owner boolean
passive boolean
ping-reply boolean
policy reference
preempt boolean
priority number
ssh-reply boolean
standby-forwarding boolean
telnet-reply boolean
traceroute-reply boolean
ipv6 
address string 
apply-groups reference
apply-groups-exclude reference
duplicate-address-detection boolean
eui-64 boolean
prefix-length number
primary-preference number
track-srrp number
bfd 
admin-state keyword
echo-receive number
multiplier number
receive number
transmit-interval number
type keyword
dhcp6 
apply-groups reference
apply-groups-exclude reference
relay 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
lease-populate 
max-nbr-of-leases number
route-populate 
na boolean
pd 
exclude boolean
ta boolean
link-address string
neighbor-resolution boolean
option 
apply-groups reference
apply-groups-exclude reference
interface-id 
ascii-tuple 
if-index 
sap-id 
string string
remote-id boolean
python-policy reference
server string
source-address string
user-db reference
server 
apply-groups reference
apply-groups-exclude reference
max-nbr-of-leases number
prefix-delegation 
admin-state keyword
prefix string 
apply-groups reference
apply-groups-exclude reference
client-id 
duid string
iaid number
preferred-lifetime (number | keyword)
valid-lifetime (number | keyword)
duplicate-address-detection boolean
forward-ipv4-packets boolean
icmp6 
packet-too-big 
admin-state keyword
number number
seconds number
param-problem 
admin-state keyword
number number
seconds number
redirects 
admin-state keyword
number number
seconds number
time-exceeded 
admin-state keyword
number number
seconds number
unreachables 
admin-state keyword
number number
seconds number
link-local-address 
address string
duplicate-address-detection boolean
local-dhcp-server reference
neighbor-discovery 
host-route 
populate keyword 
apply-groups reference
apply-groups-exclude reference
route-tag number
learn-unsolicited keyword
limit 
log-only boolean
max-entries number
threshold number
local-proxy-nd boolean
proactive-refresh keyword
proxy-nd-policy reference
reachable-time number
secure-nd 
admin-state keyword
allow-unsecured-msgs boolean
public-key-min-bits number
security-parameter number
stale-time number
static-neighbor string 
apply-groups reference
apply-groups-exclude reference
mac-address string
qos-route-lookup keyword
tcp-mss number
urpf-check 
ignore-default boolean
mode keyword
vrrp number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
backup string
bfd-liveness 
apply-groups reference
apply-groups-exclude reference
dest-ip (ipv4-address-no-zone | ipv6-address-no-zone)
interface-name string
service-name string
init-delay number
mac string
master-int-inherit boolean
message-interval number
monitor-oper-group reference
ntp-reply boolean
oper-group reference
owner boolean
passive boolean
ping-reply boolean
policy reference
preempt boolean
priority number
standby-forwarding boolean
telnet-reply boolean
traceroute-reply boolean
load-balancing 
flow-label-load-balancing boolean
ip-load-balancing keyword
spi-load-balancing boolean
teid-load-balancing boolean
loopback boolean
mac string
mac-accounting boolean
monitor-oper-group reference
multi-chassis-shunting-profile reference
ping-template 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
destination-address string
name reference
ptp-hw-assist 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
radius-auth-policy reference
sap string 
aarp 
id reference
type keyword
accounting-policy reference
admin-state keyword
anti-spoof keyword
app-profile reference
apply-groups reference
apply-groups-exclude reference
bandwidth number
calling-station-id string
collect-stats boolean
cpu-protection 
eth-cfm-monitoring 
aggregate 
car 
ip-src-monitoring 
mac-monitoring 
policy-id reference
description string
dist-cpu-protection reference
egress 
agg-rate 
adaptation-rule keyword
burst-limit (number | keyword)
limit-unused-bandwidth boolean
queue-frame-based-accounting boolean
rate number
filter 
ip reference
ipv6 reference
qos 
policer-control-policy 
overrides 
apply-groups reference
apply-groups-exclude reference
root 
max-rate (number | keyword)
priority-mbs-thresholds 
min-thresh-separation (number | keyword)
priority number 
apply-groups reference
apply-groups-exclude reference
mbs-contribution (number | keyword)
policy-name reference
qinq-mark-top-only boolean
sap-egress 
overrides 
hs-secondary-shaper string
hs-wrr-group reference 
apply-groups reference
apply-groups-exclude reference
hs-class-weight number
percent-rate decimal-number
rate (number | keyword)
policer reference 
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
mbs (number | keyword)
packet-byte-offset number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
stat-mode keyword
queue reference 
adaptation-rule 
cir keyword
pir keyword
apply-groups reference
apply-groups-exclude reference
avg-frame-overhead decimal-number
burst-limit (number | keyword)
cbs (number | keyword)
drop-tail 
low 
percent-reduction-from-mbs (number | keyword)
hs-class-weight number
hs-wred-queue 
policy reference
hs-wrr-weight number
mbs (number | keyword)
monitor-queue-depth 
fast-polling boolean
violation-threshold decimal-number
parent 
cir-weight number
weight number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
port-redirect-group 
group-name reference
instance number
scheduler-policy 
overrides 
scheduler string 
apply-groups reference
apply-groups-exclude reference
parent 
cir-weight number
weight number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
queue-group-redirect-list reference
virtual-port 
vport-name reference
eth-cfm 
apply-groups reference
apply-groups-exclude reference
collect-lmm-fc-stats 
fc keyword
fc-in-profile keyword
collect-lmm-stats boolean
mep md-admin-name reference ma-admin-name reference mep-id number 
admin-state keyword
ais boolean
alarm-notification 
fng-alarm-time number
fng-reset-time number
apply-groups reference
apply-groups-exclude reference
ccm boolean
ccm-ltm-priority number
ccm-padding-size number
csf 
multiplier decimal-number
description string
eth-test 
bit-error-threshold number
test-pattern 
crc-tlv boolean
pattern keyword
fault-propagation keyword
grace 
eth-ed 
max-rx-defect-window number
priority number
rx-eth-ed boolean
tx-eth-ed boolean
eth-vsm-grace 
rx-eth-vsm-grace boolean
tx-eth-vsm-grace boolean
low-priority-defect keyword
one-way-delay-threshold number
squelch-ingress-levels number
fwd-wholesale 
pppoe-service reference
host-admin-state keyword
host-lockout-policy reference
ingress 
filter 
ip reference
ipv6 reference
qos 
match-qinq-dot1p keyword
policer-control-policy 
overrides 
apply-groups reference
apply-groups-exclude reference
root 
max-rate (number | keyword)
priority-mbs-thresholds 
min-thresh-separation (number | keyword)
priority number 
apply-groups reference
apply-groups-exclude reference
mbs-contribution (number | keyword)
policy-name reference
sap-ingress 
fp-redirect-group 
group-name reference
instance number
overrides 
ip-criteria 
activate-entry-tag number
ipv6-criteria 
activate-entry-tag number
policer reference 
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
mbs (number | keyword)
packet-byte-offset number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
stat-mode keyword
queue reference 
adaptation-rule 
cir keyword
pir keyword
apply-groups reference
apply-groups-exclude reference
cbs (number | keyword)
drop-tail 
low 
percent-reduction-from-mbs (number | keyword)
mbs (number | keyword)
monitor-queue-depth 
fast-polling boolean
parent 
cir-weight number
weight number
percent-rate 
cir decimal-number
pir decimal-number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
queuing-type keyword
scheduler-policy 
overrides 
scheduler string 
apply-groups reference
apply-groups-exclude reference
parent 
cir-weight number
weight number
rate 
cir (number | keyword)
pir (number | keyword)
policy-name reference
queue-group-redirect-list reference
ip-tunnel string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
backup-remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
clear-df-bit boolean
delivery-service string
description string
dest-ip (ipv4-address-no-zone | ipv6-address-no-zone) 
dscp keyword
encapsulated-ip-mtu number
gre-header 
admin-state keyword
key 
admin-state keyword
receive number
send number
icmp-generation 
frag-required 
admin-state keyword
interval number
message-count number
icmp6-generation 
packet-too-big 
admin-state keyword
number number
seconds number
ip-mtu number
ipsec-transport-mode-profile reference
local-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
pmtu-discovery-aging number
private-tcp-mss-adjust number
propagate-pmtu-v4 boolean
propagate-pmtu-v6 boolean
public-tcp-mss-adjust (number | keyword)
reassembly (number | keyword)
remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
ipsec-gateway string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
cert 
cert-profile reference
status-verify 
default-result keyword
primary keyword
secondary keyword
trust-anchor-profile reference
client-db 
fallback boolean
name reference
default-secure-service 
interface string
service-name string
default-tunnel-template reference
dhcp-address-assignment 
dhcpv4 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
gi-address string
send-release boolean
server 
address string
router-instance string
dhcpv6 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
link-address string
send-release boolean
server 
address string
router-instance string
ike-policy reference
local 
address-assignment 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
ipv4 
dhcp-server string
pool string
router-instance string
secondary-pool string
ipv6 
dhcp-server string
pool string
router-instance string
gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
id 
auto 
fqdn string
ipv4 string
ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
max-history-key-records 
esp number
ike number
pre-shared-key string
radius 
accounting-policy reference
authentication-policy reference
ts-list reference
ipsec-tunnel string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bfd 
bfd-designate boolean
bfd-liveness 
dest-ip string
interface string
service-name string
clear-df-bit boolean
copy-traffic-class-upon-decapsulation boolean
description string
dest-ip (ipv4-address-no-zone | ipv6-address-no-zone) 
encapsulated-ip-mtu number
icmp-generation 
frag-required 
admin-state keyword
interval number
message-count number
icmp6-generation 
packet-too-big 
admin-state keyword
interval number
message-count number
ip-mtu number
key-exchange 
dynamic 
auto-establish boolean
cert 
cert-profile reference
status-verify 
default-result keyword
primary keyword
secondary keyword
trust-anchor-profile reference
id 
fqdn string
ipv4 string
ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
ike-policy reference
ipsec-transform reference
pre-shared-key string
manual 
keys number direction keyword 
apply-groups reference
apply-groups-exclude reference
authentication-key string
encryption-key string
ipsec-transform reference
spi number
max-history-key-records 
esp number
ike number
pmtu-discovery-aging number
private-tcp-mss-adjust number
propagate-pmtu-v4 boolean
propagate-pmtu-v6 boolean
public-tcp-mss-adjust (number | keyword)
replay-window number
security-policy 
id reference
strict-match boolean
tunnel-endpoint 
delivery-service string
local-gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
lag 
link-map-profile number
per-link-hash 
class number
weight number
multi-service-site reference
static-host 
ipv4 string mac string 
admin-state keyword
ancp-string string
app-profile 
profile reference
apply-groups reference
apply-groups-exclude reference
int-dest-id string
sla-profile reference
sub-profile reference
subscriber-id 
string string
use-sap-id 
transit-policy 
ip reference
prefix reference
shcv-policy-ipv4 reference
spoke-sdp string 
aarp 
id reference
type keyword
accounting-policy reference
admin-state keyword
app-profile reference
apply-groups reference
apply-groups-exclude reference
bfd 
bfd-liveness 
encap keyword
bfd-template reference
failure-action keyword
wait-for-up-timer number
collect-stats boolean
control-word boolean
cpu-protection 
eth-cfm-monitoring 
aggregate 
car 
ip-src-monitoring 
mac-monitoring 
policy-id reference
description string
egress 
filter 
ip reference
ipv6 reference
qos 
network 
policy-name reference
port-redirect-group 
group-name reference
instance number
vc-label number
entropy-label 
eth-cfm 
apply-groups reference
apply-groups-exclude reference
collect-lmm-fc-stats 
fc keyword
fc-in-profile keyword
collect-lmm-stats boolean
mep md-admin-name reference ma-admin-name reference mep-id number 
admin-state keyword
ais boolean
alarm-notification 
fng-alarm-time number
fng-reset-time number
apply-groups reference
apply-groups-exclude reference
ccm boolean
ccm-ltm-priority number
ccm-padding-size number
csf 
multiplier decimal-number
description string
eth-test 
bit-error-threshold number
test-pattern 
crc-tlv boolean
pattern keyword
fault-propagation keyword
grace 
eth-ed 
max-rx-defect-window number
priority number
rx-eth-ed boolean
tx-eth-ed boolean
eth-vsm-grace 
rx-eth-vsm-grace boolean
tx-eth-vsm-grace boolean
low-priority-defect keyword
one-way-delay-threshold number
squelch-ingress-levels number
hash-label 
signal-capability 
ingress 
filter 
ip reference
ipv6 reference
qos 
network 
fp-redirect-group 
group-name reference
instance number
policy-name reference
vc-label number
transit-policy 
ip reference
prefix reference
vc-type keyword
static-tunnel-redundant-nexthop string
tos-marking-state keyword
tunnel boolean
vas-if-type keyword
vpls string 
apply-groups reference
apply-groups-exclude reference
egress 
reclassify-using-qos reference
routed-override-filter 
ip reference
ipv6 reference
evpn 
arp 
advertise keyword 
apply-groups reference
apply-groups-exclude reference
route-tag number
flood-garp-and-unknown-req boolean
learn-dynamic boolean
nd 
advertise keyword 
apply-groups reference
apply-groups-exclude reference
route-tag number
learn-dynamic boolean
evpn-tunnel 
allow-bfd boolean
ipv6-gateway-address keyword
supplementary-broadcast-domain boolean
ingress 
routed-override-filter 
ip reference
ipv6 reference
ip-mirror-interface string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
spoke-sdp string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
ingress 
filter 
ip reference
vc-label number
ipsec 
allow-reverse-route-override-type keyword
multi-chassis-shunt-interface reference 
apply-groups reference
apply-groups-exclude reference
next-hop 
address (ipv4-address-no-zone | ipv6-address-no-zone)
multi-chassis-shunting-profile string 
apply-groups reference
apply-groups-exclude reference
peer reference 
apply-groups reference
apply-groups-exclude reference
multi-chassis-shunt-interface reference
security-policy number 
apply-groups reference
apply-groups-exclude reference
entry number 
apply-groups reference
apply-groups-exclude reference
local-ip 
address string
any boolean
local-ipv6 
address string
any boolean
remote-ip 
address string
any boolean
remote-ipv6 
address string
any boolean
ipv6 
neighbor-discovery 
reachable-time number
stale-time number
router-advertisement 
apply-groups reference
apply-groups-exclude reference
dns-options 
apply-groups reference
apply-groups-exclude reference
rdnss-lifetime (keyword | number)
server string
interface reference 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
current-hop-limit number
dns-options 
apply-groups reference
apply-groups-exclude reference
include-rdnss boolean
rdnss-lifetime (number | keyword)
server string
managed-configuration boolean
max-advertisement-interval number
min-advertisement-interval number
mtu number
nd-router-preference keyword
other-stateful-configuration boolean
prefix string 
apply-groups reference
apply-groups-exclude reference
autonomous boolean
on-link boolean
preferred-lifetime (keyword | number)
valid-lifetime (keyword | number)
reachable-time number
retransmit-time number
router-lifetime number
use-virtual-mac boolean
isis number 
admin-state keyword
advertise-passive-only boolean
advertise-router-capability keyword
all-l1isis string
all-l2isis string
apply-groups reference
apply-groups-exclude reference
area-address string
authentication-check boolean
authentication-key string
authentication-keychain reference
authentication-type keyword
csnp-authentication boolean
default-route-tag number
export-limit 
log-percent number
number number
export-policy reference
graceful-restart 
helper-mode boolean
hello-authentication boolean
hello-padding keyword
ignore-attached-bit boolean
ignore-lsp-errors boolean
ignore-narrow-metric boolean
iid-tlv boolean
import-policy reference
interface string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bfd-liveness 
ipv4 
include-bfd-tlv boolean
ipv6 
include-bfd-tlv boolean
csnp-interval number
default-instance boolean
hello-authentication boolean
hello-authentication-key string
hello-authentication-keychain reference
hello-authentication-type keyword
hello-padding keyword
interface-type keyword
ipv4-multicast boolean
ipv6-unicast boolean
level keyword 
apply-groups reference
apply-groups-exclude reference
hello-authentication-key string
hello-authentication-keychain reference
hello-authentication-type keyword
hello-interval number
hello-multiplier number
hello-padding keyword
ipv4-multicast-metric number
ipv6-unicast-metric number
metric number
passive boolean
priority number
sd-offset number
sf-offset number
level-capability keyword
load-balancing-weight number
loopfree-alternate 
exclude boolean
policy-map 
route-nh-template reference
lsp-pacing-interval number
mesh-group 
blocked 
value number
passive boolean
retransmit-interval number
tag number
ipv4-multicast-routing keyword
ipv4-routing boolean
ipv6-routing keyword
level keyword 
advertise-router-capability boolean
apply-groups reference
apply-groups-exclude reference
authentication-key string
authentication-keychain reference
authentication-type keyword
csnp-authentication boolean
default-ipv4-multicast-metric number
default-ipv6-unicast-metric number
default-metric number
external-preference number
hello-authentication boolean
hello-padding keyword
loopfree-alternate-exclude boolean
lsp-mtu-size number
preference number
psnp-authentication boolean
wide-metrics-only boolean
level-capability keyword
link-group string 
apply-groups reference
apply-groups-exclude reference
description string
level keyword 
apply-groups reference
apply-groups-exclude reference
ipv4-multicast-metric-offset number
ipv4-unicast-metric-offset number
ipv6-unicast-metric-offset number
member reference 
oper-members number
revert-members number
loopfree-alternate 
exclude 
prefix-policy reference
lsp-lifetime number
lsp-minimum-remaining-lifetime number
lsp-mtu-size number
lsp-refresh 
half-lifetime boolean
interval number
mru-mismatch-detection boolean
multi-topology 
ipv4-multicast boolean
ipv6-unicast boolean
multicast-import 
ipv4 boolean
overload 
max-metric boolean
overload-export-external boolean
overload-export-interlevel boolean
overload-fib-error-notify-only 
retry number
overload-on-boot 
max-metric boolean
timeout number
poi-tlv boolean
prefix-attributes-tlv boolean
prefix-limit 
limit number
log-only boolean
overload-timeout (number | keyword)
warning-threshold number
psnp-authentication boolean
reference-bandwidth number
rib-priority 
high 
prefix-list reference
tag number
router-id string
standard-multi-instance boolean
strict-adjacency-check boolean
summary-address (ipv4-prefix | ipv6-prefix) 
apply-groups reference
apply-groups-exclude reference
level-capability keyword
route-tag number
suppress-attached-bit boolean
system-id string
timers 
lsp-wait 
lsp-initial-wait number
lsp-max-wait number
lsp-second-wait number
spf-wait 
spf-initial-wait number
spf-max-wait number
spf-second-wait number
unicast-import 
ipv4 boolean
ipv6 boolean
l2tp 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
avp-hiding keyword
challenge boolean
destruct-timeout number
ethernet-tunnel 
reconnect-timeout (number | keyword)
exclude-avps 
calling-number boolean
initial-rx-lcp-conf-req boolean
failover 
recovery-max-session-lifetime number
recovery-method keyword
recovery-time number
track-srrp reference 
apply-groups reference
apply-groups-exclude reference
peer reference
sync-tag string
group string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
avp-hiding keyword
challenge keyword
description string
destruct-timeout number
ethernet-tunnel 
reconnect-timeout (number | keyword)
failover 
recovery-method keyword
recovery-time number
hello-interval (number | keyword)
idle-timeout (number | keyword)
l2tpv3 
cookie-length (number | keyword)
digest-type keyword
nonce-length number
password string
private-tcp-mss-adjust (number | keyword)
public-tcp-mss-adjust (number | keyword)
pw-cap-list 
ethernet boolean
ethernet-vlan boolean
rem-router-id string
track-password-change boolean
lac 
df-bit keyword
lns 
lns-group reference
load-balance-method keyword
mlppp 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
endpoint 
ip (ipv4-address | keyword)
mac (mac-address | keyword)
interleave boolean
max-fragment-delay (number | keyword)
max-links number
reassembly-timeout number
short-sequence-numbers boolean
ppp 
authentication keyword
authentication-policy string
chap-challenge-length 
end number
start number
default-group-interface 
interface string
service-name string
ipcp-subnet-negotiation boolean
keepalive 
interval number
multiplier number
lcp-force-ack-accm boolean
lcp-ignore-magic-numbers boolean
mtu number
proxy-authentication boolean
proxy-lcp boolean
reject-disabled-ncp boolean
user-db string
local-address string
local-name string
max-retries-estab number
max-retries-not-estab number
password string
protocol keyword
radius-accounting-policy reference
receive-window-size number
session-assign-method keyword
session-limit (number | keyword)
tunnel string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
auto-establish boolean
avp-hiding keyword
challenge keyword
description string
destruct-timeout number
failover 
recovery-method keyword
recovery-time number
hello-interval (number | keyword)
idle-timeout (number | keyword)
l2tpv3 
private-tcp-mss-adjust (number | keyword)
public-tcp-mss-adjust (number | keyword)
lac 
df-bit keyword
lns 
lns-group reference
load-balance-method keyword
mlppp 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
endpoint 
ip (ipv4-address | keyword)
mac (mac-address | keyword)
interleave keyword
max-fragment-delay number
max-links number
reassembly-timeout number
short-sequence-numbers keyword
ppp 
authentication keyword
authentication-policy string
chap-challenge-length 
end number
start number
default-group-interface 
interface string
service-name string
ipcp-subnet-negotiation keyword
keepalive 
interval number
multiplier number
lcp-force-ack-accm keyword
lcp-ignore-magic-numbers keyword
mtu number
proxy-authentication keyword
proxy-lcp keyword
reject-disabled-ncp keyword
user-db string
local-address string
local-name string
max-retries-estab number
max-retries-not-estab number
password string
peer string
preference number
radius-accounting-policy reference
receive-window-size number
remote-name string
session-limit (number | keyword)
group-session-limit number
hello-interval (number | keyword)
idle-timeout (number | keyword)
ignore-avps 
sequencing-required boolean
l2tpv3 
cookie-length number
digest-type keyword
nonce-length number
password string
private-tcp-mss-adjust number
public-tcp-mss-adjust number
transport-type 
ip boolean
lac 
calling-number-format string
cisco-nas-port 
ethernet string
df-bit boolean
local-address string
local-name string
max-retries-estab number
max-retries-not-estab number
next-attempt keyword
password string
peer-address-change-policy keyword
radius-accounting-policy reference
receive-window-size number
replace-result-code 
cdn-invalid-dst boolean
cdn-permanent-no-facilities boolean
cdn-temporary-no-facilities boolean
rtm-debounce-time (number | keyword)
session-assign-method keyword
session-limit number
tunnel-selection-blacklist 
add-tunnel-on 
address-change-timeout boolean
cdn-err-code boolean
cdn-invalid-dst boolean
cdn-permanent-no-facilities boolean
cdn-temporary-no-facilities boolean
stop-ccn-err-code boolean
stop-ccn-other boolean
tx-cdn-not-established-in-time boolean
max-list-length (number | keyword)
max-time number
timeout-action keyword
tunnel-session-limit number
label-mode keyword
local-routes-domain-id string
log 
apply-groups reference
apply-groups-exclude reference
filter string 
apply-groups reference
apply-groups-exclude reference
default-action keyword
description string
named-entry string 
action keyword
apply-groups reference
apply-groups-exclude reference
description string
match 
application 
eq keyword
neq keyword
event 
eq number
gt number
gte number
lt number
lte number
neq number
message 
eq string
neq string
regexp boolean
severity 
eq keyword
gt keyword
gte keyword
lt keyword
lte keyword
neq keyword
subject 
eq string
neq string
regexp boolean
log-id string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
destination 
netconf 
max-entries number
snmp 
max-entries number
syslog reference
filter reference
netconf-stream string
python-policy reference
source 
change boolean
debug boolean
main boolean
security boolean
time-format keyword
snmp-trap-group string 
apply-groups reference
apply-groups-exclude reference
description string
trap-target string 
address (ipv4-address-no-zone | ipv6-address-no-zone)
apply-groups reference
apply-groups-exclude reference
description string
notify-community string
port number
replay boolean
security-level keyword
version keyword
syslog string 
address (ipv4-address-no-zone | ipv6-address-no-zone)
apply-groups reference
apply-groups-exclude reference
description string
facility keyword
hostname 
use-system-name 
use-vprn-name 
value string
log-prefix (keyword | string)
port number
severity keyword
tls-client-profile reference
management 
allow-ftp boolean
allow-grpc boolean
allow-netconf boolean
allow-ssh boolean
allow-telnet boolean
allow-telnet6 boolean
apply-groups reference
apply-groups-exclude reference
maximum-ipv4-routes 
log-only boolean
threshold number
value number
maximum-ipv6-routes 
log-only boolean
threshold number
value number
mc-maximum-routes 
log-only boolean
threshold number
value number
mld 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
forwarding-group-interface forwarding-service string group-interface-name reference 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
import-policy reference
maximum-number-group-sources number
maximum-number-groups number
maximum-number-sources number
mcac 
bandwidth 
mandatory (number | keyword)
total (number | keyword)
interface-policy reference
policy reference
query-interval number
query-last-member-interval number
query-response-interval number
query-source-address string
router-alert-check boolean
sub-hosts-only boolean
subnet-check boolean
version keyword
group-if-query-source-address string
group-interface reference 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
import-policy reference
maximum-number-group-sources number
maximum-number-groups number
maximum-number-sources number
mcac 
bandwidth 
mandatory (number | keyword)
total (number | keyword)
interface-policy reference
policy reference
query-interval number
query-last-member-interval number
query-response-interval number
query-source-address string
router-alert-check boolean
sub-hosts-only boolean
subnet-check boolean
version keyword
interface string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
import-policy reference
maximum-number-group-sources number
maximum-number-groups number
maximum-number-sources number
mcac 
bandwidth 
mandatory (number | keyword)
total (number | keyword)
interface-policy reference
mc-constraints 
level number 
apply-groups reference
apply-groups-exclude reference
bandwidth number
number-down number 
apply-groups reference
apply-groups-exclude reference
level number
use-lag-port-weight boolean
policy reference
query-interval number
query-last-member-interval number
query-response-interval number
router-alert-check boolean
ssm-translate 
group-range start string end string 
apply-groups reference
apply-groups-exclude reference
source string 
static 
group string 
apply-groups reference
apply-groups-exclude reference
source string 
starg 
group-range start string end string step string 
apply-groups reference
apply-groups-exclude reference
source string 
starg 
version keyword
query-interval number
query-last-member-interval number
query-response-interval number
robust-count number
ssm-translate 
group-range start string end string 
apply-groups reference
apply-groups-exclude reference
source string 
msdp 
active-source-limit number
admin-state keyword
apply-groups reference
apply-groups-exclude reference
data-encapsulation boolean
export-policy reference
group string 
active-source-limit number
admin-state keyword
apply-groups reference
apply-groups-exclude reference
export-policy reference
import-policy reference
local-address string
mode keyword
peer string 
active-source-limit number
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authentication-key string
default-peer boolean
export-policy reference
import-policy reference
local-address string
receive-message-rate 
rate number
threshold number
time number
receive-message-rate 
rate number
threshold number
time number
import-policy reference
local-address string
peer string 
active-source-limit number
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authentication-key string
default-peer boolean
export-policy reference
import-policy reference
local-address string
receive-message-rate 
rate number
threshold number
time number
receive-message-rate 
rate number
threshold number
time number
rpf-table keyword
source string 
active-source-limit number
apply-groups reference
apply-groups-exclude reference
source-active-cache-lifetime number
mss-adjust 
apply-groups reference
apply-groups-exclude reference
nat-group number
segment-size number
mtrace2 
admin-state keyword
udp-port number
multicast-info-policy reference
mvpn 
apply-groups reference
apply-groups-exclude reference
auto-discovery 
source-address string
type keyword
c-mcast-signaling keyword
intersite-shared 
admin-state keyword
kat-type5-advertisement-withdraw boolean
persistent-type5-advertisement boolean
mdt-type keyword
provider-tunnel 
inclusive 
bier 
admin-state keyword
sub-domain number
bsr keyword
mldp 
admin-state keyword
p2mp-sr 
admin-state keyword
bfd-leaf boolean
bfd-root 
multiplier number
transmit-interval number
p2mp-policy boolean
static-policy reference
pim 
admin-state keyword
group-address string
hello-interval number
hello-multiplier number
improved-assert boolean
mode keyword
three-way-hello boolean
tracking-support boolean
rsvp 
admin-state keyword
bfd-leaf boolean
bfd-root 
multiplier number
transmit-interval number
lsp-template reference
umh-rate-monitoring 
revertive-timer number
traffic-rate-delta number
wildcard-spmsi boolean
selective 
asm-mdt boolean
auto-discovery boolean
bier 
admin-state keyword
sub-domain number
data-delay-interval number
data-threshold 
group-prefix (ipv4-prefix | ipv6-prefix) 
apply-groups reference
apply-groups-exclude reference
pe-threshold-add number
pe-threshold-delete number
threshold number
join-tlv-packing boolean
mldp 
admin-state keyword
maximum-p2mp-spmsi number
multistream-spmsi number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
group-prefix (ipv4-prefix | ipv6-prefix) source-prefix (ipv4-prefix | ipv6-prefix) 
lsp-template reference
p2mp-sr 
p2mp-policy boolean
static-policy reference
pim 
group-address string
mode keyword
p2mp-sr 
admin-state keyword
p2mp-policy boolean
static-policy reference
pim 
group-prefix string
mode keyword
rsvp 
admin-state keyword
lsp-template reference
maximum-p2mp-spmsi number
umh-rate-monitoring 
group (ipv4-prefix | ipv6-prefix) source (ipv4-prefix | ipv6-prefix) 
apply-groups reference
apply-groups-exclude reference
revertive-timer number
traffic-rate-delta number
redundant-source-list 
source-prefix (ipv4-prefix | ipv6-prefix) 
rpf-select 
core-mvpn reference 
apply-groups reference
apply-groups-exclude reference
group-prefix string 
apply-groups reference
apply-groups-exclude reference
starg boolean
umh-pe-backup 
umh-pe string 
apply-groups reference
apply-groups-exclude reference
standby string
umh-selection keyword
vrf-export 
policy (policy-expr-string | string)
unicast boolean
vrf-import 
policy (policy-expr-string | string)
unicast boolean
vrf-target 
community string
export 
community string
unicast boolean
import 
community string
unicast boolean
unicast boolean
nat 
apply-groups reference
apply-groups-exclude reference
inside 
l2-aware 
force-unique-ip-addresses boolean
subscribers string 
large-scale 
dnat-only 
source-prefix-list reference
dual-stack-lite 
admin-state keyword
deterministic 
prefix-map string nat-policy reference 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
map string to string 
apply-groups reference
apply-groups-exclude reference
first-outside-address string
endpoint string 
apply-groups reference
apply-groups-exclude reference
ip-fragmentation keyword
min-first-fragment-size-rx number
reassembly boolean
tunnel-mtu number
max-subscriber-limit number
subscriber-prefix-length number
filters 
downstream 
ipv4 reference
nat-policy reference
nat44 
destination-prefix string 
apply-groups reference
apply-groups-exclude reference
nat-policy reference
deterministic 
prefix-map string nat-policy reference 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
map string to string 
apply-groups reference
apply-groups-exclude reference
first-outside-address string
max-subscriber-limit number
nat-import reference
source-prefix string 
apply-groups reference
apply-groups-exclude reference
nat-policy reference
nat64 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
drop-zero-ipv4-checksum boolean
insert-ipv6-fragment-header boolean
ip-fragmentation keyword
ipv6-mtu number
prefix string
subscriber-prefix-length number
tos 
downstream 
use-ipv4 boolean
upstream 
set-tos (keyword | number)
redundancy 
peer string
peer6 string
steering-route string
static-port-forwards 
spf-nat-policy reference 
subscriber-identification 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
attribute 
type keyword
vendor keyword
description string
drop-unidentified-traffic boolean
radius-proxy-server 
router-instance string
server string
traffic-identification 
source-prefix-only boolean
map 
map-domain reference 
outside 
dnat-only 
route-limit number
filters 
downstream 
ipv4 reference
ipv6 reference
upstream 
ipv4 reference
ipv6 reference
mtu number
pool string 
address-pooling keyword
address-range string end string 
apply-groups reference
apply-groups-exclude reference
description string
drain boolean
admin-state keyword
applications 
agnostic boolean
flexible-port-allocation boolean
apply-groups reference
apply-groups-exclude reference
description string
icmp-echo-reply boolean
l2-aware 
default-host 
inside-router-instance string
ip-address string
rate-limit number
external-assignment boolean
port-block-extension 
ports number
subscriber 
watermarks 
high number
low number
subscriber-limit number
watermarks 
high number
low number
large-scale 
default-host 
inside-router-instance string
ip-address string
rate-limit number
deterministic 
port-reservation number
watermarks 
high number
low number
flexible-port-allocation 
free-port-limit 
icmp number
tcp number
udp number
redundancy 
admin-state keyword
export-route string
follow 
name string
router-instance string
monitor-route string
subscriber-limit number
mode keyword
nat-group reference
port-forwarding 
dynamic-block-reservation boolean
range-end number
range-start number
port-reservation 
port-blocks number
ports number
type keyword
watermarks 
high number
low number
wlan-gw-group reference
network 
apply-groups reference
apply-groups-exclude reference
ingress 
filter 
ip reference
ipv6 reference
qos 
fp-redirect-group reference
instance number
network-policy reference
urpf-check boolean
network-interface string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
cflowd-parameters 
sampling keyword 
apply-groups reference
apply-groups-exclude reference
direction keyword
sample-profile (keyword | number)
type keyword
cpu-protection reference
description string
dist-cpu-protection reference
egress 
filter 
ip reference
hold-time 
ipv4 
down 
init-only boolean
seconds number
up 
seconds number
ingress 
filter 
ip reference
ingress-stats boolean
ip-mtu number
ipv4 
allow-directed-broadcasts boolean
bfd 
admin-state keyword
echo-receive number
multiplier number
receive number
transmit-interval number
type keyword
icmp 
mask-reply boolean
param-problem 
admin-state keyword
number number
seconds number
redirects 
admin-state keyword
number number
seconds number
ttl-expired 
admin-state keyword
number number
seconds number
unreachables 
admin-state keyword
number number
seconds number
neighbor-discovery 
retry-timer number
static-neighbor string 
apply-groups reference
apply-groups-exclude reference
mac-address string
timeout number
primary 
address string
apply-groups reference
apply-groups-exclude reference
broadcast keyword
prefix-length number
secondary string 
apply-groups reference
apply-groups-exclude reference
broadcast keyword
igp-inhibit boolean
prefix-length number
tcp-mss number
urpf-check 
ignore-default boolean
mode keyword
lag 
link-map-profile number
per-link-hash 
class number
weight number
load-balancing 
flow-label-load-balancing boolean
ip-load-balancing keyword
lsr-load-balancing keyword
spi-load-balancing boolean
teid-load-balancing boolean
loopback 
mac string
port string
qos 
apply-groups reference
apply-groups-exclude reference
egress-instance number
egress-port-redirect-group reference
ingress-fp-redirect-group reference
ingress-instance number
network-policy reference
tos-marking-state keyword
ntp 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authenticate boolean
authentication-check boolean
authentication-key number 
apply-groups reference
apply-groups-exclude reference
key string
type keyword
authentication-keychain reference
broadcast reference 
apply-groups reference
apply-groups-exclude reference
authentication-keychain reference
key-id reference
ttl number
version number
ospf number 
admin-state keyword
advertise-router-capability keyword
apply-groups reference
apply-groups-exclude reference
area string 
advertise-ne-profile reference
advertise-router-capability boolean
apply-groups reference
apply-groups-exclude reference
area-range string 
advertise boolean
apply-groups reference
apply-groups-exclude reference
blackhole-aggregate boolean
export-policy reference
import-policy reference
interface string 
admin-state keyword
advertise-router-capability boolean
advertise-subnet boolean
apply-groups reference
apply-groups-exclude reference
authentication-key string
authentication-keychain reference
authentication-type keyword
bfd-liveness 
remain-down-on-failure boolean
strict boolean
strict-mode-holddown number
dead-interval number
hello-interval number
interface-type keyword
load-balancing-weight number
loopfree-alternate 
exclude boolean
policy-map 
route-nh-template reference
lsa-filter-out keyword
message-digest-key number 
apply-groups reference
apply-groups-exclude reference
md5 string
metric number
mtu number
neighbor string 
passive boolean
poll-interval number
priority number
retransmit-interval number
rib-priority keyword
transit-delay number
loopfree-alternate-exclude boolean
nssa 
area-range string 
advertise boolean
apply-groups reference
apply-groups-exclude reference
originate-default-route 
adjacency-check boolean
type-nssa boolean
redistribute-external boolean
summaries boolean
sham-link string ip-address string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authentication-key string
authentication-keychain reference
authentication-type keyword
dead-interval number
hello-interval number
message-digest-key number 
apply-groups reference
apply-groups-exclude reference
md5 string
metric number
retransmit-interval number
transit-delay number
stub 
default-metric number
summaries boolean
virtual-link string transit-area reference 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authentication-key string
authentication-keychain reference
authentication-type keyword
dead-interval number
hello-interval number
message-digest-key number 
apply-groups reference
apply-groups-exclude reference
md5 string
retransmit-interval number
transit-delay number
compatible-rfc1583 boolean
export-limit 
log-percent number
number number
export-policy reference
external-db-overflow 
interval number
limit number
external-preference number
graceful-restart 
helper-mode boolean
strict-lsa-checking boolean
ignore-dn-bit boolean
import-policy reference
loopfree-alternate 
exclude 
prefix-policy reference
multicast-import boolean
overload boolean
overload-include-ext-1 boolean
overload-include-ext-2 boolean
overload-include-stub boolean
overload-on-boot 
timeout number
preference number
reference-bandwidth number
rib-priority 
high 
prefix-list reference
router-id string
rtr-adv-lsa-limit 
log-only boolean
max-lsa-count number
overload-timeout (number | keyword)
warning-threshold number
super-backbone boolean
suppress-dn-bit boolean
timers 
incremental-spf-wait number
lsa-accumulate number
lsa-arrival number
lsa-generate 
lsa-initial-wait number
lsa-second-wait number
max-lsa-wait number
redistribute-delay number
spf-wait 
spf-initial-wait number
spf-max-wait number
spf-second-wait number
unicast-import boolean
vpn-domain 
id string
type keyword
vpn-tag number
ospf3 number 
admin-state keyword
advertise-router-capability keyword
apply-groups reference
apply-groups-exclude reference
area string 
advertise-router-capability boolean
apply-groups reference
apply-groups-exclude reference
area-range (ipv4-prefix | ipv6-prefix) 
advertise boolean
apply-groups reference
apply-groups-exclude reference
blackhole-aggregate boolean
export-policy reference
import-policy reference
interface string 
admin-state keyword
advertise-router-capability boolean
apply-groups reference
apply-groups-exclude reference
authentication 
inbound reference
outbound reference
bfd-liveness 
remain-down-on-failure boolean
strict boolean
strict-mode-holddown number
dead-interval number
hello-interval number
interface-type keyword
load-balancing-weight number
loopfree-alternate 
exclude boolean
policy-map 
route-nh-template reference
lsa-filter-out keyword
metric number
mtu number
neighbor (ipv4-address-no-zone | ipv6-address-no-zone) 
passive boolean
poll-interval number
priority number
retransmit-interval number
rib-priority keyword
transit-delay number
key-rollover-interval number
loopfree-alternate-exclude boolean
nssa 
area-range (ipv4-prefix | ipv6-prefix) 
advertise boolean
apply-groups reference
apply-groups-exclude reference
originate-default-route 
adjacency-check boolean
type-nssa boolean
redistribute-external boolean
summaries boolean
stub 
default-metric number
summaries boolean
virtual-link string transit-area reference 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authentication 
inbound reference
outbound reference
dead-interval number
hello-interval number
retransmit-interval number
transit-delay number
export-limit 
log-percent number
number number
export-policy reference
external-db-overflow 
interval number
limit number
external-preference number
graceful-restart 
helper-mode boolean
strict-lsa-checking boolean
ignore-dn-bit boolean
import-policy reference
loopfree-alternate 
exclude 
prefix-policy reference
multicast-import boolean
overload boolean
overload-include-ext-1 boolean
overload-include-ext-2 boolean
overload-include-stub boolean
overload-on-boot 
timeout number
preference number
reference-bandwidth number
rib-priority 
high 
prefix-list reference
router-id string
rtr-adv-lsa-limit 
log-only boolean
max-lsa-count number
overload-timeout (number | keyword)
warning-threshold number
suppress-dn-bit boolean
timers 
incremental-spf-wait number
lsa-accumulate number
lsa-arrival number
lsa-generate 
lsa-initial-wait number
lsa-second-wait number
max-lsa-wait number
redistribute-delay number
spf-wait 
spf-initial-wait number
spf-max-wait number
spf-second-wait number
unicast-import boolean
pcp 
server string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
dual-stack-lite-address string
fwd-inside-router string
interface reference 
policy reference
pim 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
apply-to keyword
bgp-nh-override boolean
import 
join-policy reference
register-policy reference
interface string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
assert-period number
bfd-liveness 
ipv4 boolean
ipv6 boolean
bsm-check-rtr-alert boolean
hello-interval number
hello-multiplier number
improved-assert boolean
instant-prune-echo boolean
ipv4 
apply-groups reference
apply-groups-exclude reference
monitor-oper-group 
name reference
operation keyword
priority-delta number
multicast boolean
ipv6 
apply-groups reference
apply-groups-exclude reference
monitor-oper-group 
name reference
operation keyword
priority-delta number
multicast boolean
max-groups number
mcac 
bandwidth 
mandatory (number | keyword)
total (number | keyword)
interface-policy reference
mc-constraints 
admin-state keyword
level number 
apply-groups reference
apply-groups-exclude reference
bandwidth number
number-down number 
apply-groups reference
apply-groups-exclude reference
level number
use-lag-port-weight boolean
policy reference
multicast-senders keyword
p2mp-ldp-tree-join 
ipv4 boolean
ipv6 boolean
priority number
sticky-dr 
priority number
three-way-hello boolean
tracking-support boolean
ipv4 
admin-state keyword
grt-extranet 
any 
group-prefix (ipv4-prefix | ipv6-prefix) 
apply-groups reference
apply-groups-exclude reference
starg boolean
rpf-table keyword
source-address 
register-message string
ssm-assert-compatible-mode boolean
ssm-default-range boolean
ipv6 
admin-state keyword
rpf-table keyword
source-address 
register-message string
ssm-default-range boolean
mc-ecmp-balance boolean
mc-ecmp-balance-hold number
mc-ecmp-hashing 
rebalance boolean
mtu-over-head number
non-dr-attract-traffic boolean
rp 
bootstrap 
export reference
import reference
ipv4 
anycast string rp-set-peer string 
auto-rp-discovery boolean
bsr-candidate 
address string
admin-state keyword
hash-mask-len number
priority number
candidate boolean
mapping-agent boolean
rp-candidate 
address string
admin-state keyword
group-range string 
holdtime number
priority number
static 
address string 
apply-groups reference
apply-groups-exclude reference
group-prefix string 
override boolean
ipv6 
anycast string rp-set-peer string 
bsr-candidate 
address string
admin-state keyword
hash-mask-len number
priority number
embedded-rp 
admin-state keyword
group-range string 
rp-candidate 
address string
admin-state keyword
group-range string 
holdtime number
priority number
static 
address string 
apply-groups reference
apply-groups-exclude reference
group-prefix string 
override boolean
spt-switchover (ipv4-prefix | ipv6-prefix) 
apply-groups reference
apply-groups-exclude reference
threshold (number | keyword)
ssm-groups 
group-range (ipv4-prefix | ipv6-prefix) 
radius 
apply-groups reference
apply-groups-exclude reference
proxy string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
attribute-matching 
entry number 
accounting-server-policy string
apply-groups reference
apply-groups-exclude reference
authentication-server-policy string
prefix-string string
suffix-string string
type number
vendor (number | keyword)
cache 
admin-state keyword
key 
attribute-type number
packet-type keyword
vendor (number | keyword)
timeout number
track-accounting 
accounting-off boolean
accounting-on boolean
interim-update boolean
start boolean
stop boolean
track-authentication 
accept boolean
track-delete-hold-time number
defaults 
accounting-server-policy string
authentication-server-policy string
description string
interface reference 
load-balance-key 
attribute-1 
type number
vendor (number | keyword)
attribute-2 
type number
vendor (number | keyword)
attribute-3 
type number
vendor (number | keyword)
attribute-4 
type number
vendor (number | keyword)
attribute-5 
type number
vendor (number | keyword)
source-ip-udp 
purpose keyword
python-policy reference
secret string
send-accounting-response boolean
wlan-gw 
address string
apply-groups reference
apply-groups-exclude reference
ipv6-address string
wlan-gw-group reference
server string 
accept-coa boolean
acct-port number
address (ipv4-address-no-zone | ipv6-address-no-zone)
apply-groups reference
apply-groups-exclude reference
auth-port number
description string
pending-requests-limit number
python-policy reference
secret string
reassembly 
apply-groups reference
apply-groups-exclude reference
nat-group number
to-base-network boolean
redundant-interface string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
hold-time 
ipv4 
down 
init-only boolean
seconds number
up 
seconds number
ip-mtu number
ipv4 
primary 
address string
apply-groups reference
apply-groups-exclude reference
prefix-length number
remote-ip string
spoke-sdp string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
control-word boolean
description string
egress 
filter 
ip reference
vc-label number
ingress 
filter 
ip reference
vc-label number
rip 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authentication-key string
authentication-type keyword
bfd-liveness boolean
check-zero boolean
description string
export-limit 
log-percent number
number number
export-policy reference
group string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authentication-key string
authentication-type keyword
bfd-liveness boolean
check-zero boolean
description string
export-policy reference
import-policy reference
message-size number
metric-in number
metric-out number
neighbor string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authentication-key string
authentication-type keyword
bfd-liveness boolean
check-zero boolean
description string
export-policy reference
import-policy reference
message-size number
metric-in number
metric-out number
preference number
receive keyword
send keyword
split-horizon boolean
timers 
flush number
timeout number
update number
unicast-address string 
preference number
receive keyword
send keyword
split-horizon boolean
timers 
flush number
timeout number
update number
import-policy reference
message-size number
metric-in number
metric-out number
preference number
propagate-metric boolean
receive keyword
send keyword
split-horizon boolean
timers 
flush number
timeout number
update number
ripng 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bfd-liveness boolean
check-zero boolean
description string
export-limit 
log-percent number
number number
export-policy reference
group string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bfd-liveness boolean
check-zero boolean
description string
export-policy reference
import-policy reference
message-size number
metric-in number
metric-out number
neighbor reference 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bfd-liveness boolean
check-zero boolean
description string
export-policy reference
import-policy reference
message-size number
metric-in number
metric-out number
preference number
receive keyword
send keyword
split-horizon boolean
timers 
flush number
timeout number
update number
unicast-address string 
preference number
receive keyword
send keyword
split-horizon boolean
timers 
flush number
timeout number
update number
import-policy reference
message-size number
metric-in number
metric-out number
preference number
receive keyword
send keyword
split-horizon boolean
timers 
flush number
timeout number
update number
router-id string
segment-routing-v6 number 
apply-groups reference
apply-groups-exclude reference
locator reference 
apply-groups reference
apply-groups-exclude reference
function 
end-dt4 
value number
end-dt46 
value number
end-dt6 
value number
micro-segment-locator reference 
apply-groups reference
apply-groups-exclude reference
function 
udt4 
value number
udt46 
value number
udt6 
value number
selective-fib boolean
service-id number
sfm-overload 
holdoff-time number
sgt-qos 
dot1p 
application keyword 
apply-groups reference
apply-groups-exclude reference
dot1p (keyword | number)
dscp 
application keyword 
apply-groups reference
apply-groups-exclude reference
dscp (keyword | number)
dscp-map keyword 
apply-groups reference
apply-groups-exclude reference
fc keyword
snmp 
access boolean
community string 
access-permissions keyword
apply-groups reference
apply-groups-exclude reference
source-access-list reference
version keyword
source-address 
ipv4 keyword 
address string
apply-groups reference
apply-groups-exclude reference
interface-name string
ipv6 keyword 
address string
apply-groups reference
apply-groups-exclude reference
spoke-sdp string 
apply-groups reference
apply-groups-exclude reference
description string
static-routes 
apply-groups reference
apply-groups-exclude reference
hold-down 
initial number
max-value number
multiplier number
route (ipv4-prefix | ipv6-prefix) route-type keyword 
apply-groups reference
apply-groups-exclude reference
backup-tag number
blackhole 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
community string
description string
generate-icmp boolean
metric number
preference number
prefix-list 
flag keyword
name reference
tag number
community string
grt 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
metric number
preference number
indirect (ipv4-address-no-zone | ipv6-address-no-zone) 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
community string
cpe-check (ipv4-address-no-zone | ipv6-address-no-zone) 
apply-groups reference
apply-groups-exclude reference
drop-count number
interval number
log boolean
padding-size number
description string
destination-class number
metric number
preference number
prefix-list 
flag keyword
name reference
qos 
forwarding-class keyword
priority keyword
source-class number
tag number
interface string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
community string
cpe-check (ipv4-address-no-zone | ipv6-address-no-zone) 
apply-groups reference
apply-groups-exclude reference
drop-count number
interval number
log boolean
padding-size number
description string
destination-class number
load-balancing-weight number
metric number
preference number
prefix-list 
flag keyword
name reference
qos 
forwarding-class keyword
priority keyword
source-class number
tag number
ipsec-tunnel string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
community string
description string
destination-class number
metric number
preference number
qos 
forwarding-class keyword
priority keyword
source-class number
tag number
next-hop (ipv4-address-with-zone | ipv6-address-with-zone) 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
backup-next-hop 
address (ipv4-address-no-zone | ipv6-address-no-zone)
bfd-liveness boolean
community string
cpe-check (ipv4-address-no-zone | ipv6-address-no-zone) 
apply-groups reference
apply-groups-exclude reference
drop-count number
interval number
log boolean
padding-size number
description string
destination-class number
load-balancing-weight number
metric number
preference number
prefix-list 
flag keyword
name reference
qos 
forwarding-class keyword
priority keyword
source-class number
tag number
validate-next-hop boolean
tag number
subscriber-interface string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
fwd-service reference
fwd-subscriber-interface reference
group-interface string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bonding-parameters 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
connection number 
apply-groups reference
apply-groups-exclude reference
service string
fpe reference
multicast 
connection (number | keyword)
brg 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
authenticated-brg-only boolean
default-brg-profile reference
cflowd-parameters 
sampling keyword 
apply-groups reference
apply-groups-exclude reference
direction keyword
sample-profile (keyword | number)
type keyword
data-trigger 
accept-ipv6-link-local-address boolean
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
dynamic-routes-track-srrp 
hold-time number
gtp-parameters 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
fpe reference
gx-policy reference
ingress 
policy-accounting reference
ingress-stats boolean
ip-mtu number
ipoe-linking 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
gratuitous-router-advertisement boolean
shared-circuit-id boolean
ipoe-session 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
force-auth 
cid-change boolean
rid-change boolean
ipoe-session-policy reference
min-auth-interval (keyword | number)
radius-session-timeout keyword
sap-session-limit number
session-limit number
stateless-redundancy boolean
user-db reference
ipv4 
arp-host 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
host-limit number
min-auth-interval number
sap-host-limit number
bfd 
admin-state keyword
echo-receive number
multiplier number
receive number
transmit-interval number
type keyword
dhcp 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
client-applications 
dhcp boolean
ppp boolean
description string
filter reference
gi-address string
lease-populate 
l2-header 
mac string
max-leases number
match-circuit-id boolean
offer-selection 
client-mac 
discover-delay number
mac-address keyword
discover-delay number
server string 
apply-groups reference
apply-groups-exclude reference
discover-delay number
option-82 
action keyword
circuit-id 
ascii-tuple 
ifindex 
none 
sap-id 
vlan-ascii-tuple 
remote-id 
ascii-string string
mac 
none 
vendor-specific-option 
client-mac-address boolean
pool-name boolean
sap-id boolean
service-id boolean
string string
system-id boolean
proxy-server 
admin-state keyword
emulated-server string
lease-time 
radius-override boolean
value number
python-policy reference
relay-proxy 
release-update-src-ip boolean
siaddr-override string
release-include-gi-address boolean
server string
src-ip-addr keyword
trusted boolean
user-db reference
icmp 
mask-reply boolean
param-problem 
admin-state keyword
number number
seconds number
redirects 
admin-state keyword
number number
seconds number
ttl-expired 
admin-state keyword
number number
seconds number
use-matching-address boolean
unreachables 
admin-state keyword
number number
seconds number
ignore-df-bit boolean
neighbor-discovery 
local-proxy-arp boolean
populate boolean
proxy-arp-policy reference
remote-proxy-arp boolean
timeout number
qos-route-lookup keyword
urpf-check 
mode keyword
ipv6 
allow-multiple-wan-addresses boolean
auto-reply 
neighbor-solicitation boolean
router-solicitation boolean
bfd 
admin-state keyword
echo-receive number
multiplier number
receive number
transmit-interval number
type keyword
dhcp6 
allow-client-id-change boolean
apply-groups reference
apply-groups-exclude reference
filter reference
option 
apply-groups reference
apply-groups-exclude reference
interface-id 
ascii-tuple 
if-index 
sap-id 
string string
remote-id boolean
override-slaac boolean
pd-managed-route 
next-hop keyword
proxy-server 
admin-state keyword
client-applications 
dhcp boolean
ppp boolean
preferred-lifetime (number | keyword)
rebind-timer number
renew-timer number
server-id 
apply-groups reference
apply-groups-exclude reference
duid-en-ascii string
duid-en-hex string
duid-ll 
valid-lifetime (number | keyword)
python-policy reference
relay 
admin-state keyword
advertise-selection 
client-mac 
mac-address keyword
preference-option 
value number
solicit-delay number
preference-option 
value number
server string 
apply-groups reference
apply-groups-exclude reference
preference-option 
value number
solicit-delay number
solicit-delay number
client-applications 
dhcp boolean
ppp boolean
description string
lease-split 
admin-state keyword
valid-lifetime number
link-address string
server string
source-address string
snooping 
admin-state keyword
user-db reference
user-ident keyword
ipoe-bridged-mode boolean
neighbor-discovery 
apply-groups reference
apply-groups-exclude reference
dad-snooping boolean
neighbor-limit number
qos-route-lookup keyword
router-advertisements 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
force-mcast keyword
max-advertisement-interval number
min-advertisement-interval number
options 
current-hop-limit number
dns 
include-rdnss boolean
rdnss-lifetime (number | keyword)
managed-configuration boolean
mtu (number | keyword)
other-stateful-configuration boolean
reachable-time number
retransmit-timer number
router-lifetime (number | keyword)
prefix-options 
autonomous boolean
on-link boolean
preferred-lifetime (number | keyword)
valid-lifetime (number | keyword)
router-solicit 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
inactivity-timer (number | keyword)
min-auth-interval number
user-db reference
urpf-check 
mode keyword
local-address-assignment 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
ipv4 
client-applications 
ipoe boolean
ppp boolean
default-pool string
server reference
ipv6 
client-applications 
ipoe-slaac boolean
ipoe-wan boolean
ppp-slaac boolean
server reference
mac string
nasreq-auth-policy reference
oper-up-while-empty boolean
pppoe 
admin-state keyword
anti-spoof keyword
apply-groups reference
apply-groups-exclude reference
description string
dhcp-client 
client-id keyword
policy reference
python-policy reference
sap-session-limit number
session-limit number
user-db reference
radius-auth-policy reference
redundant-interface reference
sap string 
accounting-policy reference
admin-state keyword
anti-spoof keyword
app-profile reference
apply-groups reference
apply-groups-exclude reference
calling-station-id string
collect-stats boolean
cpu-protection 
eth-cfm-monitoring 
aggregate 
car 
ip-src-monitoring 
mac-monitoring 
policy-id reference
default-host 
ipv4 reference prefix-length number 
apply-groups reference
apply-groups-exclude reference
next-hop string
ipv6 string prefix-length number 
apply-groups reference
apply-groups-exclude reference
next-hop string
description string
dist-cpu-protection reference
egress 
agg-rate 
adaptation-rule keyword
burst-limit (number | keyword)
limit-unused-bandwidth boolean
queue-frame-based-accounting boolean
rate number
filter 
ip reference
ipv6 reference
qos 
policer-control-policy 
policy-name reference
qinq-mark-top-only boolean
sap-egress 
policy-name reference
scheduler-policy 
policy-name reference
virtual-port 
vport-name reference
eth-cfm 
apply-groups reference
apply-groups-exclude reference
collect-lmm-fc-stats 
fc keyword
fc-in-profile keyword
collect-lmm-stats boolean
mep md-admin-name reference ma-admin-name reference mep-id number 
admin-state keyword
ais boolean
alarm-notification 
fng-alarm-time number
fng-reset-time number
apply-groups reference
apply-groups-exclude reference
ccm boolean
ccm-ltm-priority number
ccm-padding-size number
csf 
multiplier decimal-number
description string
eth-test 
bit-error-threshold number
test-pattern 
crc-tlv boolean
pattern keyword
fault-propagation keyword
grace 
eth-ed 
max-rx-defect-window number
priority number
rx-eth-ed boolean
tx-eth-ed boolean
eth-vsm-grace 
rx-eth-vsm-grace boolean
tx-eth-vsm-grace boolean
low-priority-defect keyword
one-way-delay-threshold number
squelch-ingress-levels number
fwd-wholesale 
pppoe-service reference
host-admin-state keyword
host-lockout-policy reference
igmp-host-tracking 
apply-groups reference
apply-groups-exclude reference
expiry-time number
import-policy reference
maximum-number-group-sources number
maximum-number-groups number
maximum-number-sources number
router-alert-check boolean
ingress 
filter 
ip reference
ipv6 reference
qos 
match-qinq-dot1p keyword
policer-control-policy 
policy-name reference
sap-ingress 
policy-name reference
queuing-type keyword
scheduler-policy 
policy-name reference
lag 
link-map-profile number
per-link-hash 
class number
weight number
monitor-oper-group reference
multi-service-site reference
oper-group reference
static-host 
ipv4 string mac string 
admin-state keyword
ancp-string string
app-profile 
profile reference
scope keyword
apply-groups reference
apply-groups-exclude reference
int-dest-id string
managed-route string 
apply-groups reference
apply-groups-exclude reference
cpe-check 
apply-groups reference
apply-groups-exclude reference
destination-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
drop-count number
failed-action 
metric number
preference number
tag number
withdraw boolean
interval number
log boolean
padding-size number
source-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
timeout number
metric number
preference number
tag number
rip-policy reference
shcv 
sla-profile reference
sub-profile reference
subscriber-id 
string string
use-sap-id 
ipv6 string mac string 
admin-state keyword
ancp-string string
app-profile 
profile reference
scope keyword
apply-groups reference
apply-groups-exclude reference
int-dest-id string
mac-linking string
managed-route string 
apply-groups reference
apply-groups-exclude reference
cpe-check 
apply-groups reference
apply-groups-exclude reference
destination-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
drop-count number
failed-action 
metric number
preference number
tag number
withdraw boolean
interval number
log boolean
padding-size number
source-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
timeout number
metric number
preference number
tag number
retail-svc-id number
shcv 
sla-profile reference
sub-profile reference
subscriber-id 
string string
use-sap-id 
mac-learning 
data-triggered boolean
single-mac boolean
sub-sla-mgmt 
admin-state keyword
defaults 
app-profile reference
int-dest-id 
string string
top-q-tag 
sla-profile reference
sub-profile reference
subscriber-id 
auto-id 
sap-id 
string string
single-sub-parameters 
non-sub-traffic 
app-profile reference
sla-profile reference
sub-profile reference
subscriber-id string
profiled-traffic-only boolean
sub-ident-policy reference
subscriber-limit (keyword | number)
sap-parameters 
anti-spoof keyword
apply-groups reference
apply-groups-exclude reference
description string
sub-sla-mgmt 
defaults 
app-profile reference
sla-profile reference
sub-profile reference
subscriber-id 
auto-id 
string string
sub-ident-policy reference
shcv-policy reference
shcv-policy-ipv4 reference
shcv-policy-ipv6 reference
srrp number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
bfd-liveness 
apply-groups reference
apply-groups-exclude reference
dest-ip string
interface-name string
service-name string
description string
gw-mac string
keep-alive-interval number
message-path reference
monitor-oper-group 
group-name reference
priority-step number
one-garp-per-sap boolean
policy reference
preempt boolean
priority number
send-fib-population-packets keyword
suppress-aa-sub boolean
tos-marking-state keyword
type keyword
wlan-gw 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
gateway-address (ipv4-address-no-zone | ipv6-address-no-zone) 
apply-groups reference
apply-groups-exclude reference
purpose 
xconnect boolean
gateway-router string
group-encryption 
encryption-keygroup-inbound reference
encryption-keygroup-outbound reference
l2-ap 
access-point string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
encap-type keyword
epipe-sap-template reference
auto-sub-id-fmt keyword
default-encap-type keyword
lanext 
max-bd number
learn-ap-mac 
delay-auth boolean
mcs-peer 
address reference
sync-tag string
mobility 
hold-time number
inter-tunnel-type boolean
inter-vlan boolean
trigger 
control boolean
data boolean
iapp boolean
oper-down-on-group-degrade boolean
promiscuous-mode boolean
tcp-mss-adjust number
tunnel-egress-qos 
admin-state keyword
agg-rate-limit (number | keyword)
granularity keyword
hold-time (number | keyword)
multi-client-only boolean
qos reference
scheduler-policy reference
tunnel-encaps 
learn-l2tp-cookie (keyword | hex-string)
vlan-range string 
apply-groups reference
apply-groups-exclude reference
authentication 
hold-time number
local 
coa-policy reference
default-ue-state keyword
on-control-plane boolean
policy reference
vlan-mismatch-timeout number
data-triggered-ue-creation 
admin-state keyword
arp boolean
create-proxy-cache-entry 
mac-format string
proxy-server 
name string
router-instance string
ospf boolean
dhcp4 
admin-state keyword
dns string
l2-aware-ip-address (ipv4-unicast-address | keyword)
lease-time 
active number
initial number
nbns string
dhcp6 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
preferred-lifetime 
active number
initial number
valid-lifetime 
active number
initial number
dsm 
accounting-policy reference
accounting-update 
interval number
admin-state keyword
application-assurance 
accounting-statistics boolean
profile reference
url-parameter string
apply-groups reference
apply-groups-exclude reference
egress 
policer reference
ingress 
ip-filter reference
policer reference
soft-quota-exhausted-filter reference
one-time-redirect 
port number
url string
volume-quota-direction keyword
dynamic-service boolean
extension string 
http-redirect-policy reference
idle-timeout-action keyword
l2-service 
admin-state keyword
description string
service reference
nat-policy reference
retail-service string
slaac 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
preferred-lifetime 
active number
initial number
valid-lifetime 
active number
initial number
vrgw 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
brg 
authenticated-brg-only boolean
default-brg-profile reference
lanext 
access 
max-mac number
multi-access boolean
policer reference
admin-state keyword
apply-groups reference
apply-groups-exclude reference
assistive-address-resolution boolean
bd-mac-prefix string
mac-translation boolean
network 
admin-state keyword
max-mac number
policer reference
xconnect 
accounting 
mobility-updates boolean
policy reference
update-interval number
admin-state keyword
apply-groups reference
apply-groups-exclude reference
wlan-gw-group reference
wpp 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
initial 
app-profile reference
sla-profile reference
sub-profile reference
lease-time number
portal 
name string
portal-group reference
router-instance string
restore-to-initial-on-disconnect boolean
triggered-hosts boolean
user-db reference
hold-time 
ipv4 
down 
init-only boolean
seconds number
up 
seconds number
ipv6 
down 
init-only boolean
seconds number
up 
seconds number
ipoe-linking 
apply-groups reference
apply-groups-exclude reference
gratuitous-router-advertisement boolean
ipoe-session 
apply-groups reference
apply-groups-exclude reference
session-limit number
ipv4 
address string 
apply-groups reference
apply-groups-exclude reference
gateway string
holdup-time number
populate-host-routes boolean
prefix-length number
track-srrp number
allow-unmatching-subnets boolean
arp-host 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
host-limit number
bfd 
admin-state keyword
echo-receive number
multiplier number
receive number
transmit-interval number
type keyword
default-dns string
dhcp 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
client-applications 
dhcp boolean
ppp boolean
description string
gi-address string
lease-populate 
max-leases number
offer-selection 
client-mac 
discover-delay number
mac-address keyword
discover-delay number
server string 
apply-groups reference
apply-groups-exclude reference
discover-delay number
option-82 
vendor-specific-option 
client-mac-address boolean
sap-id boolean
service-id boolean
string string
system-id boolean
proxy-server 
admin-state keyword
emulated-server string
lease-time 
radius-override boolean
value number
python-policy reference
relay-proxy 
release-update-src-ip boolean
siaddr-override string
release-include-gi-address boolean
server string
src-ip-addr keyword
virtual-subnet boolean
export-host-routes boolean
unnumbered 
ip-address string
ip-int-name string
ipv6 
address string 
apply-groups reference
apply-groups-exclude reference
host-type keyword
prefix-length number
allow-multiple-wan-addresses boolean
allow-unmatching-prefixes boolean
bfd 
admin-state keyword
echo-receive number
multiplier number
receive number
transmit-interval number
type keyword
default-dns string
delegated-prefix-length (number | keyword)
dhcp6 
allow-client-id-change boolean
apply-groups reference
apply-groups-exclude reference
override-slaac boolean
pd-managed-route 
next-hop keyword
proxy-server 
admin-state keyword
client-applications 
dhcp boolean
ppp boolean
preferred-lifetime (number | keyword)
rebind-timer number
renew-timer number
server-id 
apply-groups reference
apply-groups-exclude reference
duid-en-ascii string
duid-en-hex string
duid-ll 
valid-lifetime (number | keyword)
python-policy reference
relay 
admin-state keyword
advertise-selection 
client-mac 
mac-address keyword
preference-option 
value number
solicit-delay number
preference-option 
value number
server string 
apply-groups reference
apply-groups-exclude reference
preference-option 
value number
solicit-delay number
solicit-delay number
client-applications 
dhcp boolean
ppp boolean
description string
lease-split 
admin-state keyword
valid-lifetime number
link-address string
server string
source-address string
ipoe-bridged-mode boolean
link-local-address 
address string
prefix string 
apply-groups reference
apply-groups-exclude reference
holdup-time number
host-type keyword
track-srrp number
router-advertisements 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
force-mcast keyword
max-advertisement-interval number
min-advertisement-interval number
options 
current-hop-limit number
dns 
include-rdnss boolean
rdnss-lifetime (number | keyword)
managed-configuration boolean
mtu (number | keyword)
other-stateful-configuration boolean
reachable-time number
retransmit-timer number
router-lifetime (number | keyword)
prefix-options 
autonomous boolean
on-link boolean
preferred-lifetime (number | keyword)
valid-lifetime (number | keyword)
router-solicit 
apply-groups reference
apply-groups-exclude reference
inactivity-timer (number | keyword)
local-address-assignment 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
ipv4 
client-applications 
ppp boolean
default-pool string
server reference
ipv6 
client-applications 
ipoe-slaac boolean
ipoe-wan boolean
ppp-slaac boolean
server reference
pppoe 
apply-groups reference
apply-groups-exclude reference
description string
session-limit number
private-retail-subnets boolean
wan-mode keyword
wlan-gw 
apply-groups reference
apply-groups-exclude reference
pool-manager 
apply-groups reference
apply-groups-exclude reference
dhcp6-client 
dhcpv4-nat 
admin-state keyword
link-address string
pool-name string
ia-na 
admin-state keyword
link-address string
pool-name string
lease-query 
max-retries number
servers string
slaac 
admin-state keyword
link-address string
pool-name string
source-ip (keyword | ipv6-address)
watermarks 
high number
low number
wlan-gw-group reference
redundancy 
admin-state keyword
export string
monitor string
subscriber-mgmt 
apply-groups reference
apply-groups-exclude reference
dhcpv4 
apply-groups reference
apply-groups-exclude reference
routed-subnet-transparent-forward boolean
multi-chassis-shunt-id number
up-resiliency 
monitor-oper-group reference 
apply-groups reference
apply-groups-exclude reference
health-drop number
ttl-propagate 
local keyword
transit keyword
twamp-light 
apply-groups reference
apply-groups-exclude reference
reflector 
admin-state keyword
allow-ipv6-udp-checksum-zero boolean
apply-groups reference
apply-groups-exclude reference
description string
prefix (ipv4-prefix | ipv6-prefix) 
apply-groups reference
apply-groups-exclude reference
description string
type keyword
udp-port number
video-interface string 
accounting-policy reference
address string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
channel string source string 
apply-groups reference
apply-groups-exclude reference
channel-name string
description string
scte35-action keyword
zone-channel string zone-source string 
adi-channel-name string
apply-groups reference
apply-groups-exclude reference
cpu-protection reference
description string
multicast-service number
output-format keyword
video-sap 
apply-groups reference
apply-groups-exclude reference
egress 
apply-groups reference
apply-groups-exclude reference
filter 
ip reference
qos 
policy-name reference
ingress 
apply-groups reference
apply-groups-exclude reference
filter 
ip reference
qos 
policy-name reference
video-group-id reference
vprn-type keyword
vxlan 
tunnel-termination (ipv4-address-no-zone | ipv6-address-no-zone) 
apply-groups reference
apply-groups-exclude reference
fpe-id reference
weighted-ecmp keyword
wlan-gw 
apply-groups reference
apply-groups-exclude reference
distributed-subscriber-mgmt 
apply-groups reference
apply-groups-exclude reference
ipv6-tcp-mss-adjust number
mobility-triggered-accounting 
admin-state keyword
hold-down number
include-counters boolean
xconnect 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
tunnel-source-ip string
wlan-gw-group reference
wpp 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
portal string 
ack-auth-retry-count number
address (ipv4-address-no-zone | ipv6-address-no-zone)
admin-state keyword
apply-groups reference
apply-groups-exclude reference
ntf-logout-retry-count number
port-format keyword
retry-interval number
secret string
version number

service command descriptions

service

Synopsis Enter the service context
Context configure service
Treeservice
Introduced16.0.R1

Platforms

All

cpipe [service-name] string

Synopsis Enter the cpipe list instance
Context configure service cpipe string
Treecpipe
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

[service-name] string
Synopsis Administrative service name
Context configure service cpipe string
Treecpipe
String Length1 to 64

Notes

This element is part of a list key.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

admin-state keyword
Synopsis Administrative state of the service
Context configure service cpipe string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

customer reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisService customer ID
Contextconfigure service cpipe string customer reference
Treecustomer

Reference

configure service customer string

Notes

This element is mandatory.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

description string
Synopsis Text description
Context configure service cpipe string description string
Treedescription
String Length1 to 80
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

endpoint [name] string
Synopsis Enter the endpoint list instance
Contextconfigure service cpipe string endpoint string
Treeendpoint
Max. Instances2
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

[name] string
Synopsis Service endpoint name
Context configure service cpipe string endpoint string
Treeendpoint
String Length1 to 32

Notes

This element is part of a list key.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

description string
Synopsis Text description
Context configure service cpipe string endpoint string description string
Treedescription
String Length1 to 80
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

hold-time-active number
Synopsis Time before entering standby when MC-LAG SAP goes down
Contextconfigure service cpipe string endpoint string hold-time-active number
Treehold-time-active
Range1 to 60
Unitsdeciseconds
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

revert-time (number | keyword)
Synopsis Time to wait before reverting to primary spoke SDP
Contextconfigure service cpipe string endpoint string revert-time (number | keyword)
Treerevert-time
Range1 to 600
Unitsseconds
Options never, immediate
Defaultimmediate
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

sap [sap-id] string
Synopsis Enter the sap list instance
Context configure service cpipe string sap string
Treesap
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

[sap-id] string
Synopsis SAP ID
Contextconfigure service cpipe string sap string
Treesap
String Length1 to 45

Notes

This element is part of a list key.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

admin-state keyword
Synopsis Administrative state of the SAP
Context configure service cpipe string sap string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

cem
Synopsis Enter the cem context
Context configure service cpipe string sap string cem
Treecem
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

packet
Synopsis Enter the packet context
Context configure service cpipe string sap string cem packet
Treepacket
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

jitter-buffer number
Synopsis Jitter buffer size
Context configure service cpipe string sap string cem packet jitter-buffer number
Treejitter-buffer
Range1 to 250
Unitsmilliseconds
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

payload-size number
Synopsis Size of payload packets transmitted to PSN by CEM SAP
Contextconfigure service cpipe string sap string cem packet payload-size number
Treepayload-size
Range2 to 1514
Unitsbytes
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

report-alarm
Synopsis Enter the report-alarm context
Contextconfigure service cpipe string sap string cem report-alarm
Treereport-alarm
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

packet-loss boolean
Synopsis Report remote peer is currently in packet loss status
Contextconfigure service cpipe string sap string cem report-alarm packet-loss boolean
Treepacket-loss
Defaulttrue
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

remote-fault boolean
Synopsis Report remote TDM interface is currently not in service
Contextconfigure service cpipe string sap string cem report-alarm remote-fault boolean
Treeremote-fault
Defaultfalse
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

remote-rdi boolean
Synopsis Report remote TDM interface is currently in RDI status
Contextconfigure service cpipe string sap string cem report-alarm remote-rdi boolean
Treeremote-rdi
Defaultfalse
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

rtp-header boolean
Synopsis Use RTP header for transmitted packets to the PSN
Contextconfigure service cpipe string sap string cem rtp-header boolean
Treertp-header

Description

When configured to true, the router uses the RTP header when packets are transmitted to the packet service network (PSN) by the CEM SAP. This mode must be enabled for differential-timed E1s.

Defaultfalse
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-a, 7750 SR-e

collect-stats boolean
Synopsis Collect accounting statistics
Context configure service cpipe string sap string collect-stats boolean
Treecollect-stats
Defaultfalse
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

description string
Synopsis Text description
Context configure service cpipe string sap string description string
Treedescription
String Length1 to 160
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

egress
Synopsis Enter the egress context
Context configure service cpipe string sap string egress
Treeegress
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

agg-rate
Synopsis Enter the agg-rate context
Context configure service cpipe string sap string egress agg-rate
Treeagg-rate
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

adaptation-rule keyword
Synopsis Adaptation rule to compute the operational PIR value when an aggregate shaper is used
Contextconfigure service cpipe string sap string egress agg-rate adaptation-rule keyword
Treeadaptation-rule
Optionsmax, min, closest
Defaultclosest
Introduced22.10.R1

Platforms

7750 SR-1, 7750 SR-s

burst-limit (number | keyword)
Synopsis Shaping burst size when an aggregate shaper is used
Contextconfigure service cpipe string sap string egress agg-rate burst-limit (number | keyword)
Treeburst-limit
Range1 to 14000000
Unitsbytes
Options auto
Default auto
Introduced22.10.R1

Platforms

7750 SR-1, 7750 SR-s

rate number
Synopsis Enforced aggregate rate for all queues
Contextconfigure service cpipe string sap string egress agg-rate rate number
Treerate
Range1 to 6400000000
Unitskilobps
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

qos
Synopsis Enter the qos context
Context configure service cpipe string sap string egress qos
Treeqos
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

policer-control-policy
Synopsis Enter the policer-control-policy context
Contextconfigure service cpipe string sap string egress qos policer-control-policy
Treepolicer-control-policy
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS

overrides
Synopsis Enable the overrides context
Context configure service cpipe string sap string egress qos policer-control-policy overrides
Treeoverrides
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS

root
Synopsis Enter the root context
Context configure service cpipe string sap string egress qos policer-control-policy overrides root
Treeroot
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS

priority-mbs-thresholds
Synopsis Enter the priority-mbs-thresholds context
Contextconfigure service cpipe string sap string egress qos policer-control-policy overrides root priority-mbs-thresholds
Treepriority-mbs-thresholds
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS

priority [priority-level] number
Synopsis Enter the priority list instance
Contextconfigure service cpipe string sap string egress qos policer-control-policy overrides root priority-mbs-thresholds priority number
Treepriority
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS

sap-egress
Synopsis Enter the sap-egress context
Context configure service cpipe string sap string egress qos sap-egress
Treesap-egress
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

overrides
Synopsis Enter the overrides context
Context configure service cpipe string sap string egress qos sap-egress overrides
Treeoverrides
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

policer [policer-id] reference
Synopsis Enter the policer list instance
Contextconfigure service cpipe string sap string egress qos sap-egress overrides policer reference
Treepolicer
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS

cbs (number | keyword)
Synopsis CBS
Contextconfigure service cpipe string sap string egress qos sap-egress overrides policer reference cbs (number | keyword)
Treecbs
Range0 to 268435456
Unitsbytes
Options auto
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS

mbs (number | keyword)
Synopsis MBS
Contextconfigure service cpipe string sap string egress qos sap-egress overrides policer reference mbs (number | keyword)
Treembs
Range0 to 268435456
Unitsbytes
Options auto
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service cpipe string sap string egress qos sap-egress overrides policer reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS

rate
Synopsis Enter the rate context
Context configure service cpipe string sap string egress qos sap-egress overrides policer reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS

stat-mode keyword
Synopsis Mode of statistics collected by the policer
Contextconfigure service cpipe string sap string egress qos sap-egress overrides policer reference stat-mode keyword
Treestat-mode
Optionsno-stats, minimal, offered-profile-no-cir, offered-total-cir, offered-profile-cir, offered-limited-capped-cir, offered-profile-capped-cir, offered-total-cir-exceed, offered-four-profile-no-cir, offered-total-cir-four-profile
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS

queue [queue-id] reference
Synopsis Enter the queue list instance
Context configure service cpipe string sap string egress qos sap-egress overrides queue reference
Treequeue
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure service cpipe string sap string egress qos sap-egress overrides queue reference adaptation-rule
Treeadaptation-rule
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

burst-limit (number | keyword)
Synopsis Explicit shaping burst size for the queue
Contextconfigure service cpipe string sap string egress qos sap-egress overrides queue reference burst-limit (number | keyword)
Treeburst-limit
Range1 to 14000000
Unitsbytes
Options auto
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

cbs (number | keyword)
Synopsis CBS
Contextconfigure service cpipe string sap string egress qos sap-egress overrides queue reference cbs (number | keyword)
Treecbs
Range0 to 1048576
Unitskilobytes
Optionsauto
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

drop-tail
Synopsis Enter the drop-tail context
Context configure service cpipe string sap string egress qos sap-egress overrides queue reference drop-tail
Treedrop-tail
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

low
Synopsis Enter the low context
Context configure service cpipe string sap string egress qos sap-egress overrides queue reference drop-tail low
Treelow
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

hs-wred-queue
Synopsis Enter the hs-wred-queue context
Contextconfigure service cpipe string sap string egress qos sap-egress overrides queue reference hs-wred-queue
Treehs-wred-queue
Introduced20.10.R1

Platforms

7750 SR-7/12/12e

mbs (number | keyword)
Synopsis MBS
Contextconfigure service cpipe string sap string egress qos sap-egress overrides queue reference mbs (number | keyword)
Treembs
Range0 to 1073741824
Unitsbytes
Options auto
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

monitor-queue-depth
Synopsis Enable the monitor-queue-depth context
Contextconfigure service cpipe string sap string egress qos sap-egress overrides queue reference monitor-queue-depth
Treemonitor-queue-depth
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fast-polling boolean
Synopsis Enable fast polling of the queue depth
Contextconfigure service cpipe string sap string egress qos sap-egress overrides queue reference monitor-queue-depth fast-polling boolean
Treefast-polling

Description

When configured to true, this command enables fast polling of the queue depth. Faster polling allows a more accurate view of the actual depth.

Defaultfalse
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

violation-threshold decimal-number
Synopsis Threshold for queue depth before violation is raised
Contextconfigure service cpipe string sap string egress qos sap-egress overrides queue reference monitor-queue-depth violation-threshold decimal-number
Treeviolation-threshold

Description

This command specifies the threshold for the queue MBS. When the queue depth exceeds the threshold value, a violation is registered.

Range0.01 to 99.99
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

parent
Synopsis Enter the parent context
Context configure service cpipe string sap string egress qos sap-egress overrides queue reference parent
Treeparent
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service cpipe string sap string egress qos sap-egress overrides queue reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

rate
Synopsis Enter the rate context
Context configure service cpipe string sap string egress qos sap-egress overrides queue reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

cir (number | keyword)
Synopsis CIR rate
Contextconfigure service cpipe string sap string egress qos sap-egress overrides queue reference rate cir (number | keyword)
Treecir
Range0 to 6400000000
Unitskilobps
Options max
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

pir (number | keyword)
Synopsis PIR rate
Contextconfigure service cpipe string sap string egress qos sap-egress overrides queue reference rate pir (number | keyword)
Treepir
Range1 to 6400000000
Unitskilobps
Options max
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service cpipe string sap string egress qos scheduler-policy
Treescheduler-policy
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

overrides
Synopsis Enter the overrides context
Context configure service cpipe string sap string egress qos scheduler-policy overrides
Treeoverrides
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

scheduler [scheduler-name] string
Synopsis Enter the scheduler list instance
Contextconfigure service cpipe string sap string egress qos scheduler-policy overrides scheduler string
Treescheduler
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

[scheduler-name] string
Synopsis Scheduler name
Contextconfigure service cpipe string sap string egress qos scheduler-policy overrides scheduler string
Treescheduler

Description

This command specifies the scheduler name which is composed of printable 7-bit ASCII characters. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes. Each scheduler must have a unique name within the context of the scheduler policy. However, the same name can be reused in multiple scheduler policies. If the scheduler name already exists within the policy tier level, the context changes to that scheduler name for the purpose of editing the scheduler commands.

If the scheduler name exists within the policy on a different tier, an error occurs and the current context does not change. If the scheduler name does not exist in this or another tier within the scheduler policy, it is assumed that an attempt is being made to create a scheduler of that name.

If the provided scheduler name is invalid, a name syntax error occurs, the command does not execute, and the context is not change.

String Length1 to 32

Notes

This element is part of a list key.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

parent
Synopsis Enter the parent context
Context configure service cpipe string sap string egress qos scheduler-policy overrides scheduler string parent
Treeparent
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

rate
Synopsis Enter the rate context
Context configure service cpipe string sap string egress qos scheduler-policy overrides scheduler string rate
Treerate
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

cir (number | keyword)
Synopsis CIR at which the queue it to operate
Context configure service cpipe string sap string egress qos scheduler-policy overrides scheduler string rate cir (number | keyword)
Treecir
Range0 to 6400000000
Unitskilobps
Options sum, max
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

pir (number | keyword)
Synopsis PIR at which the queue is to operate
Context configure service cpipe string sap string egress qos scheduler-policy overrides scheduler string rate pir (number | keyword)
Treepir
Range1 to 6400000000
Unitskilobps
Options max
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

virtual-port
Synopsis Enter the virtual-port context
Contextconfigure service cpipe string sap string egress virtual-port
Treevirtual-port
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

endpoint reference
Synopsis Endpoint name
Contextconfigure service cpipe string sap string endpoint reference
Treeendpoint

Reference

configure service cpipe string endpoint string

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ingress
Synopsis Enter the ingress context
Context configure service cpipe string sap string ingress
Treeingress
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

qos
Synopsis Enter the qos context
Context configure service cpipe string sap string ingress qos
Treeqos
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

policer-control-policy
Synopsis Enter the policer-control-policy context
Contextconfigure service cpipe string sap string ingress qos policer-control-policy
Treepolicer-control-policy
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS

overrides
Synopsis Enable the overrides context
Context configure service cpipe string sap string ingress qos policer-control-policy overrides
Treeoverrides
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS

root
Synopsis Enter the root context
Context configure service cpipe string sap string ingress qos policer-control-policy overrides root
Treeroot
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS

priority-mbs-thresholds
Synopsis Enter the priority-mbs-thresholds context
Contextconfigure service cpipe string sap string ingress qos policer-control-policy overrides root priority-mbs-thresholds
Treepriority-mbs-thresholds
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS

priority [priority-level] number
Synopsis Enter the priority list instance
Contextconfigure service cpipe string sap string ingress qos policer-control-policy overrides root priority-mbs-thresholds priority number
Treepriority
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS

sap-ingress
Synopsis Enter the sap-ingress context
Context configure service cpipe string sap string ingress qos sap-ingress
Treesap-ingress
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

overrides
Synopsis Enter the overrides context
Context configure service cpipe string sap string ingress qos sap-ingress overrides
Treeoverrides
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ip-criteria
Synopsis Enter the ip-criteria context
Context configure service cpipe string sap string ingress qos sap-ingress overrides ip-criteria
Treeip-criteria
Introduced20.10.R2

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ipv6-criteria
Synopsis Enter the ipv6-criteria context
Contextconfigure service cpipe string sap string ingress qos sap-ingress overrides ipv6-criteria
Treeipv6-criteria
Introduced20.10.R2

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

policer [policer-id] reference
Synopsis Enter the policer list instance
Contextconfigure service cpipe string sap string ingress qos sap-ingress overrides policer reference
Treepolicer
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service cpipe string sap string ingress qos sap-ingress overrides policer reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS

rate
Synopsis Enter the rate context
Context configure service cpipe string sap string ingress qos sap-ingress overrides policer reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS

stat-mode keyword
Synopsis Mode of statistics collected by the policer
Contextconfigure service cpipe string sap string ingress qos sap-ingress overrides policer reference stat-mode keyword
Treestat-mode
Optionsno-stats, minimal, offered-profile-no-cir, offered-total-cir, offered-priority-no-cir, offered-profile-cir, offered-priority-cir, offered-limited-profile-cir, offered-profile-capped-cir, offered-limited-capped-cir
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS

queue [queue-id] reference
Synopsis Enter the queue list instance
Context configure service cpipe string sap string ingress qos sap-ingress overrides queue reference
Treequeue
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure service cpipe string sap string ingress qos sap-ingress overrides queue reference adaptation-rule
Treeadaptation-rule
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

cbs (number | keyword)
Synopsis CBS
Contextconfigure service cpipe string sap string ingress qos sap-ingress overrides queue reference cbs (number | keyword)
Treecbs
Range0 to 1048576
Unitskilobytes
Optionsauto
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

drop-tail
Synopsis Enter the drop-tail context
Context configure service cpipe string sap string ingress qos sap-ingress overrides queue reference drop-tail
Treedrop-tail
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

low
Synopsis Enter the low context
Context configure service cpipe string sap string ingress qos sap-ingress overrides queue reference drop-tail low
Treelow
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mbs (number | keyword)
Synopsis MBS
Contextconfigure service cpipe string sap string ingress qos sap-ingress overrides queue reference mbs (number | keyword)
Treembs
Range0 to 1073741824
Unitsbytes
Options auto
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

monitor-queue-depth
Synopsis Enable the monitor-queue-depth context
Contextconfigure service cpipe string sap string ingress qos sap-ingress overrides queue reference monitor-queue-depth
Treemonitor-queue-depth
Introduced21.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

parent
Synopsis Enter the parent context
Context configure service cpipe string sap string ingress qos sap-ingress overrides queue reference parent
Treeparent
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service cpipe string sap string ingress qos sap-ingress overrides queue reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

rate
Synopsis Enter the rate context
Context configure service cpipe string sap string ingress qos sap-ingress overrides queue reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

cir (number | keyword)
Synopsis CIR rate
Contextconfigure service cpipe string sap string ingress qos sap-ingress overrides queue reference rate cir (number | keyword)
Treecir
Range0 to 6400000000
Unitskilobps
Options max
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

pir (number | keyword)
Synopsis PIR rate
Contextconfigure service cpipe string sap string ingress qos sap-ingress overrides queue reference rate pir (number | keyword)
Treepir
Range1 to 6400000000
Unitskilobps
Options max
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service cpipe string sap string ingress qos scheduler-policy
Treescheduler-policy
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

overrides
Synopsis Enter the overrides context
Context configure service cpipe string sap string ingress qos scheduler-policy overrides
Treeoverrides
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

scheduler [scheduler-name] string
Synopsis Enter the scheduler list instance
Contextconfigure service cpipe string sap string ingress qos scheduler-policy overrides scheduler string
Treescheduler
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

[scheduler-name] string
Synopsis Scheduler name
Contextconfigure service cpipe string sap string ingress qos scheduler-policy overrides scheduler string
Treescheduler

Description

This command specifies the scheduler name which is composed of printable 7-bit ASCII characters. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes. Each scheduler must have a unique name within the context of the scheduler policy. However, the same name can be reused in multiple scheduler policies. If the scheduler name already exists within the policy tier level, the context changes to that scheduler name for the purpose of editing the scheduler commands.

If the scheduler name exists within the policy on a different tier, an error occurs and the current context does not change. If the scheduler name does not exist in this or another tier within the scheduler policy, it is assumed that an attempt is being made to create a scheduler of that name.

If the provided scheduler name is invalid, a name syntax error occurs, the command does not execute, and the context is not change.

String Length1 to 32

Notes

This element is part of a list key.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

parent
Synopsis Enter the parent context
Context configure service cpipe string sap string ingress qos scheduler-policy overrides scheduler string parent
Treeparent
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

rate
Synopsis Enter the rate context
Context configure service cpipe string sap string ingress qos scheduler-policy overrides scheduler string rate
Treerate
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

cir (number | keyword)
Synopsis CIR at which the queue it to operate
Context configure service cpipe string sap string ingress qos scheduler-policy overrides scheduler string rate cir (number | keyword)
Treecir
Range0 to 6400000000
Unitskilobps
Options sum, max
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

lag
Synopsis Enter the lag context
Context configure service cpipe string sap string lag
Treelag
Introduced21.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

service-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisService ID
Contextconfigure service cpipe string service-id number
Treeservice-id
Range1 to 2147483647
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

service-mtu number
Synopsis MTU size
Contextconfigure service cpipe string service-mtu number
Treeservice-mtu
Range1 to 9194
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

spoke-sdp [sdp-bind-id] string
Synopsis Enter the spoke-sdp list instance
Contextconfigure service cpipe string spoke-sdp string
Treespoke-sdp
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

[sdp-bind-id] string
Synopsis SDP binding ID
Contextconfigure service cpipe string spoke-sdp string
Treespoke-sdp
String Length3 to 16

Notes

This element is part of a list key.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

admin-state keyword
Synopsis Administrative state of the SDP binding to the service
Contextconfigure service cpipe string spoke-sdp string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

bandwidth (number | keyword)
Synopsis Bandwidth that is reserved for this SDP binding
Contextconfigure service cpipe string spoke-sdp string bandwidth (number | keyword)
Treebandwidth
Range0 to 100000000
Unitskilobps
Options max
Default 0
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

bfd
Synopsis Enter the bfd context
Context configure service cpipe string spoke-sdp string bfd
Treebfd
Introduced21.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

bfd-liveness
Synopsis Enable the bfd-liveness context
Contextconfigure service cpipe string spoke-sdp string bfd bfd-liveness
Treebfd-liveness
Introduced21.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

encap keyword
Synopsis BFD encapsulation used on the SDP binding
Contextconfigure service cpipe string spoke-sdp string bfd bfd-liveness encap keyword
Treeencap
Optionsipv4
Defaultipv4
Introduced21.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

bfd-template reference
Synopsis BFD template associated with the SDP binding
Contextconfigure service cpipe string spoke-sdp string bfd bfd-template reference
Treebfd-template

Description

This command configures a named BFD template to be used by VCCV BFD on PWs belonging to the VLL service. The template specifies parameters, such as the minimum transmit and receive control packet timer intervals, used by the BFD session. Template parameters are configured under the configure router bfd context.

Reference

configure bfd bfd-template string

Introduced21.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

control-word boolean
Synopsis Use control word as part of packet encapsulation
Contextconfigure service cpipe string spoke-sdp string control-word boolean
Treecontrol-word
Defaulttrue
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

description string
Synopsis Text description
Context configure service cpipe string spoke-sdp string description string
Treedescription
String Length1 to 80
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

egress
Synopsis Enter the egress context
Context configure service cpipe string spoke-sdp string egress
Treeegress
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

qos
Synopsis Enter the qos context
Context configure service cpipe string spoke-sdp string egress qos
Treeqos
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

network
Synopsis Enter the network context
Context configure service cpipe string spoke-sdp string egress qos network
Treenetwork
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

port-redirect-group
Synopsis Enter the port-redirect-group context
Contextconfigure service cpipe string spoke-sdp string egress qos network port-redirect-group
Treeport-redirect-group
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEgress MPLS VC label to send packets to the far end
Contextconfigure service cpipe string spoke-sdp string egress vc-label number
Treevc-label
Range16 to 1048575
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

endpoint
Synopsis Enter the endpoint context
Context configure service cpipe string spoke-sdp string endpoint
Treeendpoint
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

icb boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisBind the SDP as the Inter-Chassis Backup (ICB) type
Contextconfigure service cpipe string spoke-sdp string endpoint icb boolean
Treeicb
Defaultfalse
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

name reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEndpoint name to which SDP bind is attached
Contextconfigure service cpipe string spoke-sdp string endpoint name reference
Treename

Reference

configure service cpipe string endpoint string

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

precedence (number | keyword)
Synopsis Precedence when multiple SDP binds are on one endpoint
Contextconfigure service cpipe string spoke-sdp string endpoint precedence (number | keyword)
Treeprecedence
Range1 to 4
Optionsprimary
Default4
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ingress
Synopsis Enter the ingress context
Context configure service cpipe string spoke-sdp string ingress
Treeingress
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

qos
Synopsis Enter the qos context
Context configure service cpipe string spoke-sdp string ingress qos
Treeqos
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

network
Synopsis Enter the network context
Context configure service cpipe string spoke-sdp string ingress qos network
Treenetwork
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fp-redirect-group
Synopsis Enter the fp-redirect-group context
Contextconfigure service cpipe string spoke-sdp string ingress qos network fp-redirect-group
Treefp-redirect-group
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIngress MPLS VC label to send packets to the far end
Contextconfigure service cpipe string spoke-sdp string ingress vc-label number
Treevc-label
Range1 to 1048575
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

test boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDesignate as a test service
Contextconfigure service cpipe string test boolean
Treetest
Defaultfalse
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

vc-switching boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisUse PW switching signaling for spoke SDPs in service
Contextconfigure service cpipe string vc-switching boolean
Treevc-switching
Defaultfalse
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

vc-type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisCircuit emulation service type signalled to the peer
Contextconfigure service cpipe string vc-type keyword
Treevc-type
Optionssatop-e1, satop-t1, cesopsn, cesopsn-cas
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

vpn-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVPN identifier for the service
Contextconfigure service cpipe string vpn-id number
Treevpn-id
Range1 to 2147483647
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

customer [customer-name] string

Synopsis Enter the customer list instance
Contextconfigure service customer string
Treecustomer
Introduced16.0.R1

Platforms

All

[customer-name] string
Synopsis Customer name for a service
Context configure service customer string
Treecustomer
String Length1 to 64

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

contact string
Synopsis Service customer contact information
Context configure service customer string contact string
Treecontact
String Length1 to 80
Introduced16.0.R1

Platforms

All

customer-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisCustomer ID
Contextconfigure service customer string customer-id number
Treecustomer-id
Range1 to 2147483647
Introduced16.0.R1

Platforms

All

multi-service-site [multi-service-site-name] string
Synopsis Enter the multi-service-site list instance
Contextconfigure service customer string multi-service-site string
Treemulti-service-site
Introduced16.0.R1

Platforms

All

assignment
Synopsis Enter the assignment context
Context configure service customer string multi-service-site string assignment
Treeassignment
Introduced16.0.R1

Platforms

All

card number
Synopsis Multi-service-site assignment to the card slot
Contextconfigure service customer string multi-service-site string assignment card number
Treecard
Range1 to 20

Notes

The following elements are part of a choice: card, fpe, or port.

Introduced16.0.R1

Platforms

All

fpe reference
Synopsis Multi-service-site assignment to the FPE object
Contextconfigure service customer string multi-service-site string assignment fpe reference
Treefpe

Description

When configured to true, this command identifies the MSS assignment to an FPE object to allow the creation of a scheduling hierarchy used to control bandwidth over a set of PW SAPs belonging to multiple PW ports. These PW ports must be associated with the same FPE to which MSS is assigned.

When configured to false, this command has no effect and returns no warnings or messages.

Reference

configure fwd-path-ext fpe number

Notes

The following elements are part of a choice: card, fpe, or port.

Introduced20.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

port string
Synopsis Multi-service-site assignment to the port
Contextconfigure service customer string multi-service-site string assignment port string
Treeport

Notes

The following elements are part of a choice: card, fpe, or port.

Introduced16.0.R1

Platforms

All

egress
Synopsis Enter the egress context
Context configure service customer string multi-service-site string egress
Treeegress
Introduced16.0.R1

Platforms

All

agg-rate
Synopsis Enter the agg-rate context
Context configure service customer string multi-service-site string egress agg-rate
Treeagg-rate
Introduced16.0.R1

Platforms

All

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service customer string multi-service-site string egress scheduler-policy
Treescheduler-policy
Introduced16.0.R1

Platforms

All

overrides
Synopsis Enter the overrides context
Context configure service customer string multi-service-site string egress scheduler-policy overrides
Treeoverrides
Introduced16.0.R1

Platforms

All

scheduler [scheduler-name] string
Synopsis Enter the scheduler list instance
Contextconfigure service customer string multi-service-site string egress scheduler-policy overrides scheduler string
Treescheduler
Introduced16.0.R1

Platforms

All

[scheduler-name] string
Synopsis Scheduler name
Contextconfigure service customer string multi-service-site string egress scheduler-policy overrides scheduler string
Treescheduler

Description

This command specifies the scheduler name which is composed of printable 7-bit ASCII characters. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes. Each scheduler must have a unique name within the context of the scheduler policy. However, the same name can be reused in multiple scheduler policies. If the scheduler name already exists within the policy tier level, the context changes to that scheduler name for the purpose of editing the scheduler commands.

If the scheduler name exists within the policy on a different tier, an error occurs and the current context will not change. If the scheduler name does not exist in this or another tier within the scheduler policy, it is assumed that an attempt is being made to create a scheduler of that name.

If the provided scheduler name is invalid, a name syntax error occurs, the command does not execute, and the context does not change.

String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

parent
Synopsis Enter the parent context
Context configure service customer string multi-service-site string egress scheduler-policy overrides scheduler string parent
Treeparent
Introduced16.0.R1

Platforms

All

rate
Synopsis Enter the rate context
Context configure service customer string multi-service-site string egress scheduler-policy overrides scheduler string rate
Treerate
Introduced16.0.R1

Platforms

All

ingress
Synopsis Enter the ingress context
Context configure service customer string multi-service-site string ingress
Treeingress
Introduced16.0.R1

Platforms

All

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service customer string multi-service-site string ingress scheduler-policy
Treescheduler-policy
Introduced16.0.R1

Platforms

All

overrides
Synopsis Enter the overrides context
Context configure service customer string multi-service-site string ingress scheduler-policy overrides
Treeoverrides
Introduced16.0.R1

Platforms

All

scheduler [scheduler-name] string
Synopsis Enter the scheduler list instance
Contextconfigure service customer string multi-service-site string ingress scheduler-policy overrides scheduler string
Treescheduler
Introduced16.0.R1

Platforms

All

parent
Synopsis Enter the parent context
Context configure service customer string multi-service-site string ingress scheduler-policy overrides scheduler string parent
Treeparent
Introduced16.0.R1

Platforms

All

rate
Synopsis Enter the rate context
Context configure service customer string multi-service-site string ingress scheduler-policy overrides scheduler string rate
Treerate
Introduced16.0.R1

Platforms

All

phone string
Synopsis Service customer telephone number information
Contextconfigure service customer string phone string
Treephone
String Length1 to 80
Introduced16.0.R1

Platforms

All

epipe [service-name] string

Synopsis Enter the epipe list instance
Context configure service epipe string
Treeepipe
Introduced16.0.R1

Platforms

All

[service-name] string
Synopsis Administrative service name
Context configure service epipe string
Treeepipe
String Length1 to 64

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the service
Context configure service epipe string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

bgp [bgp-instance] number
Synopsis Enter the bgp list instance
Context configure service epipe string bgp number
Treebgp

Description

Commands in this context configure the BGP related options that BGP uses for multihoming and BGP VPWS.

Introduced16.0.R1

Platforms

All

[bgp-instance] number
Synopsis BGP instance
Contextconfigure service epipe string bgp number
Treebgp
Range1 to 2

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

adv-service-mtu number
Synopsis Advertised service MTU value
Context configure service epipe string bgp number adv-service-mtu number
Treeadv-service-mtu

Description

This command configures the MTU signaled value used in the BGP for the service. When configured, the router uses the value for signaling and for validation with the received MTU instead of the service MTU. However, the value does not affect the locally enforced value, which is still based on the service MTU.

Range0 to 9782
Introduced22.2.R1

Platforms

All

pw-template-binding [pw-template-name] reference
Synopsis Enter the pw-template-binding list instance
Contextconfigure service epipe string bgp number pw-template-binding reference
Treepw-template-binding
Max. Instances100
Introduced16.0.R1

Platforms

All

endpoint reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEndpoint name associated with the BGP PW template
Contextconfigure service epipe string bgp number pw-template-binding reference endpoint reference
Treeendpoint

Description

This command specifies the endpoint name associated with the BGP PW template. When an endpoint is associated to the PW template binding of a BGP VPWS service, EVPN MPLS can also be configured and associated to the same endpoint in the same Epipe service.

Reference

configure service epipe string endpoint string

Introduced20.5.R1

Platforms

All

route-distinguisher (keyword | vpn-route-distinguisher)
Synopsis RD component for NLRI for L2VPN and EVPN families
Contextconfigure service epipe string bgp number route-distinguisher (keyword | vpn-route-distinguisher)
Treeroute-distinguisher
Optionsauto-rd
Introduced16.0.R1

Platforms

All

route-target
Synopsis Enter the route-target context
Contextconfigure service epipe string bgp number route-target
Treeroute-target
Introduced16.0.R1

Platforms

All

export string
Synopsis Extended community name for default import policy
Contextconfigure service epipe string bgp number route-target export string
Treeexport
String Length10 to 28
Introduced16.0.R1

Platforms

All

import string
Synopsis Extended community name for default import policy
Contextconfigure service epipe string bgp number route-target import string
Treeimport
String Length10 to 28
Introduced16.0.R1

Platforms

All

bgp-evpn
Synopsis Enable the bgp-evpn context
Context configure service epipe string bgp-evpn
Treebgp-evpn
Introduced16.0.R1

Platforms

All

evi number
Synopsis EVPN ID
Contextconfigure service epipe string bgp-evpn evi number
Treeevi

Description

This command configures an EVPN instance (EVI) unique in the system. It is used for the service-carving algorithm for multi-homing and auto-deriving route target and route distinguishers.

The following options are supported:

If this EVPN identifier is not specified, the value is zero and no route distinguisher or route target is automatically derived from it.If the specified EVPN identifier is lower than 65535 and no other route distinguisher or route target is configured in the service, the following applies:

  • the route distinguisher is derived from <system_ip>:evi

  • the route target is derived from <autonomous-system>:evi

If the specified EVPN identifier is higher than 65535 and no other route distinguisher or route target is configured in the service, the following applies.

  • The route distinguisher cannot be automatically derived. An error is generated if enabling EVPN is attempted without a route distinguisher. A manual or an auto-rd route distinguisher must be configured.

  • The route target can only be automatically derived if the evi-three-byte-auto-rt command is configured. If configured, the route target is automatically derived in accordance with the rules described in RFC8365. 

Range1 to 16777215
Introduced16.0.R1

Platforms

All

local-attachment-circuit [name] string
Synopsis Enter the local-attachment-circuit list instance
Contextconfigure service epipe string bgp-evpn local-attachment-circuit string
Treelocal-attachment-circuit
Max. Instances2
Introduced20.10.R1

Platforms

All

bgp number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisBGP instance ID
Contextconfigure service epipe string bgp-evpn local-attachment-circuit string bgp number
Treebgp
Range1 to 2
Default1
Introduced 23.10.R1

Platforms

All

eth-tag number
Synopsis Ethernet tag of the attachment circuit
Contextconfigure service epipe string bgp-evpn local-attachment-circuit string eth-tag number
Treeeth-tag

Description

This command configures the Ethernet tag value of the attachment circuit.

When configured in the local attachment circuit context, the tag value is used in the advertised AD per-EVI route sent for the attachment circuit.

When configured in the remote attachment circuit context, the value is compared with the Ethernet tag value of the imported D per-EVI routes for the service. When there is a match, the system creates an EVPN destination for the Epipe.

Range1 to 16777215
Introduced20.10.R1

Platforms

All

mpls [bgp-instance] number
Synopsis Enter the mpls list instance
Context configure service epipe string bgp-evpn mpls number
Treempls
Introduced16.0.R1

Platforms

All

[bgp-instance] number
Synopsis BGP instance
Contextconfigure service epipe string bgp-evpn mpls number
Treempls
Range1 to 2

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of BGP EVPN MPLS
Contextconfigure service epipe string bgp-evpn mpls number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

auto-bind-tunnel
Synopsis Enter the auto-bind-tunnel context
Contextconfigure service epipe string bgp-evpn mpls number auto-bind-tunnel
Treeauto-bind-tunnel
Introduced16.0.R1

Platforms

All

allow-flex-algo-fallback boolean
Synopsis Enable flexible algorithm fallback
Context configure service epipe string bgp-evpn mpls number auto-bind-tunnel allow-flex-algo-fallback boolean
Treeallow-flex-algo-fallback

Description

When configured to true, a BGP router with a Flex-Algorithm action configured (via the configure policy-options policy-statement entry action flex-algo command) can resolve to a tunnel with algorithm 0 if no target Flex-Algorithm tunnel is available.

When configured to false, the BGP router can resolve only to the intended Flex-Algorithm tunnel, which may cause traffic loss if no corresponding Flex-Algorithm tunnel is available.

Defaultfalse
Introduced20.10.R1

Platforms

All

resolution-filter
Synopsis Enter the resolution-filter context
Contextconfigure service epipe string bgp-evpn mpls number auto-bind-tunnel resolution-filter
Treeresolution-filter
Introduced16.0.R1

Platforms

All

bgp boolean
Synopsis Use BGP tunneling for next-hop resolution
Contextconfigure service epipe string bgp-evpn mpls number auto-bind-tunnel resolution-filter bgp boolean
Treebgp

Description

When configured to true, BGP searches the BGP LSP for the address of the BGP next hop.

When configured to false, BGP tunneling is not used and inter-area or inter-as prefixes are not resolved.

Defaultfalse
Introduced16.0.R1

Platforms

All

ldp boolean
Synopsis Use LDP tunneling for next-hop resolution
Contextconfigure service epipe string bgp-evpn mpls number auto-bind-tunnel resolution-filter ldp boolean
Treeldp

Description

When configured to true, BGP searches for an LDP LSP with a FEC prefix corresponding to the address of the BGP next hop.

When configured to false, LDP tunneling is not used for next-hop resolution.

Defaultfalse
Introduced16.0.R1

Platforms

All

mpls-fwd-policy boolean
Synopsis Use MPLS forwarding policy for next-hop resolution
Contextconfigure service epipe string bgp-evpn mpls number auto-bind-tunnel resolution-filter mpls-fwd-policy boolean
Treempls-fwd-policy

Description

When configured to true, BGP uses the MPLS forwarding policy to determine the address of the BGP next hop.

When configured to false, the MPLS forwarding policy is not used for next-hop resolution.

Defaultfalse
Introduced19.5.R1

Platforms

All

rib-api boolean
Synopsis Use RIB API gRPC service for next-hop resolution
Contextconfigure service epipe string bgp-evpn mpls number auto-bind-tunnel resolution-filter rib-api boolean
Treerib-api

Description

When configured to true, BGP uses tunnels programmed using the RIB API gRPC service to resolve the next hops of routes imported into the EVPN service.

When configured to false, the RIB API service tunnels are not used for next-hop resolution.

Defaultfalse
Introduced19.5.R1

Platforms

All

rsvp boolean
Synopsis Use RSVP tunneling for next-hop resolution
Contextconfigure service epipe string bgp-evpn mpls number auto-bind-tunnel resolution-filter rsvp boolean
Treersvp

Description

When configured to true, BGP searches the best metric RSVP LSP to determine the address of the BGP next hop. This address can correspond to the system interface or to another loopback interface used by the BGP instance on the remote node. The LSP metric is provided by MPLS in the tunnel table. In the case of multiple RSVP LSPs with the same lowest metric, BGP selects the LSP with the lowest tunnel ID.

When configured to false, the RSVP LSP is not used for next-hop resolution.

Defaultfalse
Introduced16.0.R1

Platforms

All

sr-isis boolean
Synopsis Use IS-IS SR tunneling for next-hop resolution
Contextconfigure service epipe string bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-isis boolean
Treesr-isis

Description

When configured to true, BGP uses an IS-IS tunnel type to determine the address of the BGP next hop.

The SR tunnel to the BGP next hop is selected in the TTM from the lowest-numbered IS-IS instance.

When configured to false, IS-IS tunneling is not used for next-hop resolution.

Defaultfalse
Introduced16.0.R1

Platforms

All

sr-ospf boolean
Synopsis Use OSPF SR tunneling for next-hop resolution
Contextconfigure service epipe string bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-ospf boolean
Treesr-ospf

Description

When configured to true, BGP uses an OSPF tunnel type to determine the address of the BGP next hop.

The SR tunnel to the BGP next hop is selected in the TTM from the lowest-numbered OPSF instance.

When configured to false, OSPF tunneling is not used for next-hop resolution.

Defaultfalse
Introduced16.0.R1

Platforms

All

sr-ospf3 boolean
Synopsis Use OSPFv3 SR tunneling for next-hop resolution
Contextconfigure service epipe string bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-ospf3 boolean
Treesr-ospf3

Description

When configured to true, BGP uses an OSPF3 tunnel type to determine the address of the BGP next hop.

The SR tunnel to the BGP next hop is selected in the TTM from the lowest-numbered OPSF3 instance.

When configured to false, OSPF3 tunneling is not used for next-hop resolution.

Defaultfalse
Introduced19.10.R1

Platforms

All

sr-policy boolean
Synopsis Use SR policies for next-hop resolution
Contextconfigure service epipe string bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-policy boolean
Treesr-policy

Description

When configured to true, this command instructs BGP to use an SR policy to determine the address of the BGP next hop. The SR policy search criteria includes a non-null endpoint and color value that matches the BGP next hop and color extended community value, respectively, of the EVPN route.

When configured to false, SR policies are not used for next-hop resolution.

Defaultfalse
Introduced19.5.R1

Platforms

All

sr-te boolean
Synopsis Use SR-TE tunneling for next-hop resolution
Contextconfigure service epipe string bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-te boolean
Treesr-te

Description

When configured to true, BGP uses an SR-TE tunnel type to determine the address of the BGP next hop.

The SR tunnel to the BGP next hop is selected in the TTM from the lowest-numbered tunnel ID.

When configured to false, SR-TE tunneling is not used for next-hop resolution.

Defaultfalse
Introduced16.0.R1

Platforms

All

udp boolean
Synopsis Use MPLS over UDP tunneling for next-hop resolution
Contextconfigure service epipe string bgp-evpn mpls number auto-bind-tunnel resolution-filter udp boolean
Treeudp

Description

When configured to true, BGP uses an MPLS over UDP tunnel type to determine the address of the BGP next hop.

When configured to false, MPLS over UDP tunneling is not used for next-hop resolution.

Defaultfalse
Introduced16.0.R1

Platforms

All

weighted-ecmp boolean
Synopsis Allow weighted load balancing
Context configure service epipe string bgp-evpn mpls number auto-bind-tunnel weighted-ecmp boolean
Treeweighted-ecmp

Description

When configured to true, this router enables weighted ECMP for packets using tunnels that a VPLS or Epipe automatically binds to. Packets are sprayed across LSPs in the ECMP according to the outcome of the hash algorithm and the configured load balancing weight of each LSP.

When configured to false, this command disables weighted ECMP for next-hop tunnel selection.

Defaultfalse
Introduced22.7.R1

Platforms

All

control-word boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable support for control word
Contextconfigure service epipe string bgp-evpn mpls number control-word boolean
Treecontrol-word

Description

When configured to true, the router enables the transmission and reception of the control word for all EVPN-MPLS destinations at the same time.

Defaultfalse
Introduced16.0.R1

Platforms

All

default-route-tag string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDefault route tag
Contextconfigure service epipe string bgp-evpn mpls number default-route-tag string
Treedefault-route-tag

Description

This command configures a route tag that is used when sending a route to the BGP application (for the corresponding service and BGP instance). If the corresponding BGP instance is enabled, the command cannot be changed.

When used for BGP EVPN contexts, only one route tag can be passed to BGP for matching on export policies. In case of a conflict with other route tags pushed by EVPN, the default route tag has the least priority. 

The following are examples of the conflict priority handling:

  • If a service is configured with both default-route-tag X and proxy-arp evpn-route-tag Y, the EVPN uses route tag Y when sending EVPN proxy-arp routes to the BGP RIB for advertisement.

  • If a given IP-prefix route is tagged in the route-table with tag A and the R-VPLS, in which the route is advertised, uses B as the default-route-tag, then EVPN keeps tag A when sending the route to the BGP RIB.

The default-route-tag configuration is only supported on EVPN and IP-VPN service routes. The route tag for ES and AD per-ES routes is always zero.

Introduced16.0.R4

Platforms

All

domain-id string
Synopsis Domain ID of received BGP route before readvertisement
Contextconfigure service epipe string bgp-evpn mpls number domain-id string
Treedomain-id

Description

This command specifies the domain ID. The domain ID identifies the network from which the BGP route was received before the RTM advertises it to a different neighbor. The domain ID is part of a domain, represented as domain-id:isf_safi_type in the D-PATH attribute, as described in draft-ietf-bess-evpn-ipvpn-interworking. Gateway routers modify the D-PATH attribute. A gateway is a PE where a VPRN is instantiated. The VPRN in this case advertises or receives routes from multiple BGP owners (for example, EVPN-IFL and BGP-IPVPN) or multiple instances of the same owner (for example, VPRN with two BGP-IPVPN instances).

Gateways use the D-PATH attribute to detect loops (for received routes where the D-PATH contains a local domain ID) and to make BGP best-path selection decisions based on the D-PATH length (shorter D-PATH is preferred).

In the following example, suppose a gateway receives prefix P in an EVPN-IFL instance with the following D-PATH from neighbor N:

Seg Len=1 / 65000:1:128

If the router imports the route in VPRN-1, BGP-EVPN SRv6 instance with domain 65000:2, it readvertises it to its BGP-IPVPN MPLS instance as follows:

Seg Len=2 / 65000:2:70 / 65000:1:128

That is, the gateway prepends the local domain ID and family to the D-PATH before readvertising the route into a different instance.

The command is also supported in Epipe services with two instances. As in the case of multi-instance VPRN services, the configured domain ID in an Epipe instance is prepended to the AD per EVI route redistributed to the other instance.

Introduced23.10.R1

Platforms

All

dynamic-egress-label-limit boolean
Synopsis Enables dynamic egress label limit
Context configure service epipe string bgp-evpn mpls number dynamic-egress-label-limit boolean
Treedynamic-egress-label-limit

Description

When configured to true, this command relaxes the egress MPLS label limit check when resolving BGP next hops in the tunnel table.

For VPRN services, the OAM label is never computed and, therefore, one more egress label is allowed.

For EVPN (Epipe and VPLS) services, the system only computes the control word and ESI label if they are used. For the control word, the system reduces the egress label limit by one label if the control word is configured in the service. When configured, the ESI label is not counted for Epipes or VPLS services without an ES.

When configured to false this command, for EVPN, Epipe, and VPLS services, always accounts for the ESI label and control word.

Defaultfalse
Introduced22.2.R1

Platforms

All

ecmp number
Synopsis Maximum ECMP routes information
Context configure service epipe string bgp-evpn mpls number ecmp number
Treeecmp
Range1 to 32
Default1
Introduced 16.0.R1

Platforms

All

evi-three-byte-auto-rt boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAuto-derive the BGP EVPN route target
Contextconfigure service epipe string bgp-evpn mpls number evi-three-byte-auto-rt boolean
Treeevi-three-byte-auto-rt

Description

When configured to true, the BGP-EVPN instance import and export route target is auto-derived as described in RFC 8365 (Global-Administrator:A/Type/D-ID/Service-ID).

Where:

  • Global Administrator – is the configured 2-octet AS number; if the configured ASN exceeds the 2 byte limit, the low order 16-bit value is taken

  • A=0 (for auto-derivation)

  • Type=4 (EVI-based route-target)

  • D-ID= [1..2] – encodes the BGP instance, which allows the auto-derivation of different route-targets in multi-instance services; the value is inherited from the corresponding BGP instance

  • Service ID=3-octet EVI

When configured to false, route target derivation is not allowed.

Defaultfalse
Introduced21.10.R1

Platforms

All

hash-label boolean
Synopsis Push hash label
Context configure service epipe string bgp-evpn mpls number hash-label boolean
Treehash-label

Description

When configured to true, the router pushes the hash label based on the following:

  • If advertise-l2-attributes (in the configure service vpls bgp-evpn routes incl-mcast context) is set to false, the hash label is pushed to a unicast EVPN destination.

  • If advertise-l2-attributes is set to true, the F bit is set to 1 in the Layer 2 Attributes Extended Community of the EVPN IMET route for the service. The hash label is pushed only if the remote PE signaled support for hash label (received F bit is set to 1).

When configured to false, the hash label is not pushed.

The hash label is never used for BUM packets.

Defaultfalse
Introduced23.10.R1

Platforms

All

mh-mode keyword
Synopsis Multihoming mode
Context configure service epipe string bgp-evpn mpls number mh-mode keyword
Treemh-mode

Description

This command configures each BGP-EVPN instance in a multi-instance Epipe service to behave as network or access.

You can only configure one network instance for the service. If the service has a provider tunnel enabled, it requires a network instance.

Optionsaccess, network
Default network
Introduced23.10.R1

Platforms

All

route-next-hop
Synopsis Enter the route-next-hop context
Contextconfigure service epipe string bgp-evpn mpls number route-next-hop
Treeroute-next-hop

Description

Commands in this context configure the next hop of the EVPN routes.

Introduced19.10.R1

Platforms

All

ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIP address of the next-hop for the service EVPN route
Contextconfigure service epipe string bgp-evpn mpls number route-next-hop ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeip-address

Notes

The following elements are part of a choice: ip-address, system-ipv4, or system-ipv6.

Introduced19.10.R1

Platforms

All

system-ipv4
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSystem IPv4 address for service EVPN route next hop
Contextconfigure service epipe string bgp-evpn mpls number route-next-hop system-ipv4
Treesystem-ipv4

Notes

The following elements are part of a choice: ip-address, system-ipv4, or system-ipv6.

Introduced19.10.R1

Platforms

All

system-ipv6
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSystem IPv6 address for service EVPN route next hop
Contextconfigure service epipe string bgp-evpn mpls number route-next-hop system-ipv6
Treesystem-ipv6

Notes

The following elements are part of a choice: ip-address, system-ipv4, or system-ipv6.

Introduced19.10.R1

Platforms

All

send-tunnel-encap
Synopsis Enter the send-tunnel-encap context
Contextconfigure service epipe string bgp-evpn mpls number send-tunnel-encap
Treesend-tunnel-encap
Introduced16.0.R1

Platforms

All

mpls boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable MPLS encapsulation
Contextconfigure service epipe string bgp-evpn mpls number send-tunnel-encap mpls boolean
Treempls
Defaulttrue
Introduced16.0.R1

Platforms

All

mpls-over-udp boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable MPLS over UDP encapsulation
Contextconfigure service epipe string bgp-evpn mpls number send-tunnel-encap mpls-over-udp boolean
Treempls-over-udp
Defaultfalse
Introduced16.0.R1

Platforms

All

remote-attachment-circuit [name] string
Synopsis Enter the remote-attachment-circuit list instance
Contextconfigure service epipe string bgp-evpn remote-attachment-circuit string
Treeremote-attachment-circuit
Max. Instances2
Introduced20.10.R1

Platforms

All

bgp number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisBGP instance ID
Contextconfigure service epipe string bgp-evpn remote-attachment-circuit string bgp number
Treebgp
Range1 to 2
Default1
Introduced 23.10.R1

Platforms

All

eth-tag number
Synopsis Ethernet tag of the attachment circuit
Contextconfigure service epipe string bgp-evpn remote-attachment-circuit string eth-tag number
Treeeth-tag

Description

This command configures the Ethernet tag value of the attachment circuit.

When configured in the local attachment circuit context, the tag value is used in the advertised AD per-EVI route sent for the attachment circuit.

When configured in the remote attachment circuit context, the value is compared with the Ethernet tag value of the imported D per-EVI routes for the service. When there is a match, the system creates an EVPN destination for the Epipe.

Range1 to 16777215
Introduced20.10.R1

Platforms

All

segment-routing-v6 [bgp-instance] number
Synopsis Enter the segment-routing-v6 list instance
Contextconfigure service epipe string bgp-evpn segment-routing-v6 number
Treesegment-routing-v6

Description

Commands in this context configure the SRv6 instance that is used in the service.

Introduced21.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

default-route-tag string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDefault route tag
Contextconfigure service epipe string bgp-evpn segment-routing-v6 number default-route-tag string
Treedefault-route-tag

Description

This command configures a route tag that is used when sending a route to the BGP application (for the corresponding service and BGP instance). If the corresponding BGP instance is enabled, the command cannot be changed.

When used for BGP EVPN contexts, only one route tag can be passed to BGP for matching on export policies. In case of a conflict with other route tags pushed by EVPN, the default route tag has the least priority. 

The following are examples of the conflict priority handling:

  • If a service is configured with both default-route-tag X and proxy-arp evpn-route-tag Y, the EVPN uses route tag Y when sending EVPN proxy-arp routes to the BGP RIB for advertisement.

  • If a given IP-prefix route is tagged in the route-table with tag A and the R-VPLS, in which the route is advertised, uses B as the default-route-tag, then EVPN keeps tag A when sending the route to the BGP RIB.

The default-route-tag configuration is only supported on EVPN and IP-VPN service routes. The route tag for ES and AD per-ES routes is always zero.

Introduced21.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

domain-id string
Synopsis Domain ID of received BGP route before readvertisement
Contextconfigure service epipe string bgp-evpn segment-routing-v6 number domain-id string
Treedomain-id

Description

This command specifies the domain ID. The domain ID identifies the network from which the BGP route was received before the RTM advertises it to a different neighbor. The domain ID is part of a domain, represented as domain-id:isf_safi_type in the D-PATH attribute, as described in draft-ietf-bess-evpn-ipvpn-interworking. Gateway routers modify the D-PATH attribute. A gateway is a PE where a VPRN is instantiated. The VPRN in this case advertises or receives routes from multiple BGP owners (for example, EVPN-IFL and BGP-IPVPN) or multiple instances of the same owner (for example, VPRN with two BGP-IPVPN instances).

Gateways use the D-PATH attribute to detect loops (for received routes where the D-PATH contains a local domain ID) and to make BGP best-path selection decisions based on the D-PATH length (shorter D-PATH is preferred).

In the following example, suppose a gateway receives prefix P in an EVPN-IFL instance with the following D-PATH from neighbor N:

Seg Len=1 / 65000:1:128

If the router imports the route in VPRN-1, BGP-EVPN SRv6 instance with domain 65000:2, it readvertises it to its BGP-IPVPN MPLS instance as follows:

Seg Len=2 / 65000:2:70 / 65000:1:128

That is, the gateway prepends the local domain ID and family to the D-PATH before readvertising the route into a different instance.

The command is also supported in Epipe services with two instances. As in the case of multi-instance VPRN services, the configured domain ID in an Epipe instance is prepended to the AD per EVI route redistributed to the other instance.

Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

ecmp number
Synopsis Maximum ECMP value configured on the service
Contextconfigure service epipe string bgp-evpn segment-routing-v6 number ecmp number
Treeecmp
Range1 to 32
Default1
Introduced 21.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

evi-three-byte-auto-rt boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAuto-derive the BGP EVPN route target
Contextconfigure service epipe string bgp-evpn segment-routing-v6 number evi-three-byte-auto-rt boolean
Treeevi-three-byte-auto-rt

Description

When configured to true, the BGP-EVPN instance import and export route target is auto-derived as described in RFC 8365 (Global-Administrator:A/Type/D-ID/Service-ID).

Where:

  • Global Administrator – is the configured 2-octet AS number; if the configured ASN exceeds the 2 byte limit, the low order 16-bit value is taken

  • A=0 (for auto-derivation)

  • Type=4 (EVI-based route-target)

  • D-ID= [1..2] – encodes the BGP instance, which allows the auto-derivation of different route-targets in multi-instance services; the value is inherited from the corresponding BGP instance

  • Service ID=3-octet EVI

When configured to false, route target derivation is not allowed.

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

force-vc-forwarding keyword
Synopsis Datapath forwarding to force vlan-vc-type
Contextconfigure service epipe string bgp-evpn segment-routing-v6 number force-vc-forwarding keyword
Treeforce-vc-forwarding

Description

This command allows the system to preserve the VLAN ID and 802.1p bits of the service-delimiting qtag in a new tag added in the customer frame before sending it to the EVPN destinations.

This command may be used in conjunction with the sap ingress vlan-translation command. If so used, the configured translated VLAN ID is the VLAN ID sent to the EVPN destinations as opposed to the service-delimiting tag VLAN ID. If the ingress SAP/SDP binding is 'null'-encapsulated, the output VLAN ID and pbits is zero.

Optionsvlan, qinq-c-tag-c-tag, qinq-s-tag-c-tag
Introduced21.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

oper-group reference
Synopsis Operational group
Context configure service epipe string bgp-evpn segment-routing-v6 number oper-group reference
Treeoper-group

Description

This command adds the BGP EVPN SRv6 instance or an Ethernet Segment (ES) as a member of the operational group.

When configured on a BGP EVPN instance, the operational group is up when it is either empty (meaning that the operational group has no members) or at least an EVPN destination is created under the EVPN instance added as member. When configured, no other SAP, SDP binding, or BGP EVPN instance can be added to the same operational group within the same or different service.

The operational group is down when it is applied on a BGP EVPN instance as well as:

  • the service is administratively disabled

  • the BGP EVPN MPLS and VXLAN is administratively disabled

  • all the EVPN destinations in the instance are removed

When configured on an ES, the state of the operational group depends on the state of the SAPs contained in the ES. The operational group transitions to up if at least one SAP in the ES is up. The operational group goes down when all the associated SAPs are operationally down. Monitor the ES operational group on the LAG associated with the ES, along with single-active multihoming, so that the NDF state can be signaled to the CE by LAG standby signaling.

Reference

configure service oper-group string

Introduced21.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

resolution keyword
Synopsis Resolution options for routes
Context configure service epipe string bgp-evpn segment-routing-v6 number resolution keyword
Treeresolution
Optionsroute-table, tunnel-table, fallback-tunnel-to-route-table
Defaultroute-table
Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

route-next-hop
Synopsis Enter the route-next-hop context
Contextconfigure service epipe string bgp-evpn segment-routing-v6 number route-next-hop
Treeroute-next-hop

Description

Commands in this context configure the next hop of the EVPN routes.

Introduced21.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIP address of the next-hop for the service EVPN route
Contextconfigure service epipe string bgp-evpn segment-routing-v6 number route-next-hop ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeip-address

Notes

The following elements are part of a choice: ip-address, system-ipv4, or system-ipv6.

Introduced21.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

system-ipv4
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSystem IPv4 address for service EVPN route next hop
Contextconfigure service epipe string bgp-evpn segment-routing-v6 number route-next-hop system-ipv4
Treesystem-ipv4

Notes

The following elements are part of a choice: ip-address, system-ipv4, or system-ipv6.

Introduced21.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

system-ipv6
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSystem IPv6 address for service EVPN route next hop
Contextconfigure service epipe string bgp-evpn segment-routing-v6 number route-next-hop system-ipv6
Treesystem-ipv6

Notes

The following elements are part of a choice: ip-address, system-ipv4, or system-ipv6.

Introduced21.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

source-address string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSource IPv6 address
Contextconfigure service epipe string bgp-evpn segment-routing-v6 number source-address string
Treesource-address

Description

When configured, this command specifies the source IPv6 address used in the SA field of the outer IPv6 header of the SRv6 encapsulated packet.

When not configured, the source IPv6 address is inherited from the configuration of the global default address in the router "base" segment-routing segment-routing-v6 source-address context.

A source IPv6 address must be configured in this context or in the base router context.

The system does not check if the address entered is a valid local address.

Introduced21.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

srv6
Synopsis Enter the srv6 context
Context configure service epipe string bgp-evpn segment-routing-v6 number srv6
Treesrv6
Introduced21.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

default-locator string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDefault route locator
Contextconfigure service epipe string bgp-evpn segment-routing-v6 number srv6 default-locator string
Treedefault-locator

Description

This command specifies the locator that exists in the SRv6 service instance and is used as the default locator for the service.

Introduced21.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

vxlan [bgp-instance] number
Synopsis Enter the vxlan list instance
Context configure service epipe string bgp-evpn vxlan number
Treevxlan
Introduced16.0.R1

Platforms

All

[bgp-instance] number
Synopsis BGP instance
Contextconfigure service epipe string bgp-evpn vxlan number
Treevxlan
Range1 to 2

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

default-route-tag string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDefault route tag
Contextconfigure service epipe string bgp-evpn vxlan number default-route-tag string
Treedefault-route-tag

Description

This command configures a route tag that is used when sending a route to the BGP application (for the corresponding service and BGP instance). If the corresponding BGP instance is enabled, the command cannot be changed.

When used for BGP EVPN contexts, only one route tag can be passed to BGP for matching on export policies. In case of a conflict with other route tags pushed by EVPN, the default route tag has the least priority. 

The following are examples of the conflict priority handling:

  • If a service is configured with both default-route-tag X and proxy-arp evpn-route-tag Y, the EVPN uses route tag Y when sending EVPN proxy-arp routes to the BGP RIB for advertisement.

  • If a given IP-prefix route is tagged in the route-table with tag A and the R-VPLS, in which the route is advertised, uses B as the default-route-tag, then EVPN keeps tag A when sending the route to the BGP RIB.

The default-route-tag configuration is only supported on EVPN and IP-VPN service routes. The route tag for ES and AD per-ES routes is always zero.

Introduced16.0.R4

Platforms

All

ecmp number
Synopsis Maximum ECMP routes information
Context configure service epipe string bgp-evpn vxlan number ecmp number
Treeecmp
Range1 to 32
Default1
Introduced 16.0.R1

Platforms

All

evi-three-byte-auto-rt boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAuto-derive the BGP EVPN route target
Contextconfigure service epipe string bgp-evpn vxlan number evi-three-byte-auto-rt boolean
Treeevi-three-byte-auto-rt

Description

When configured to true, the BGP-EVPN instance import and export route target is auto-derived as described in RFC 8365 (Global-Administrator:A/Type/D-ID/Service-ID).

Where:

  • Global Administrator – is the configured 2-octet AS number; if the configured ASN exceeds the 2 byte limit, the low order 16-bit value is taken

  • A=0 (for auto-derivation)

  • Type=4 (EVI-based route-target)

  • D-ID= [1..2] – encodes the BGP instance, which allows the auto-derivation of different route-targets in multi-instance services; the value is inherited from the corresponding BGP instance

  • Service ID=3-octet EVI

When configured to false, route target derivation is not allowed.

Defaultfalse
Introduced21.10.R1

Platforms

All

send-tunnel-encap boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSend VXLAN value in encapsulation extended community
Contextconfigure service epipe string bgp-evpn vxlan number send-tunnel-encap boolean
Treesend-tunnel-encap

Description

When configured to true, this command sends the VXLAN value in the encapsulation that is advertised with the EVPN routes for the service. The encapsulation is encoded in RFC5512-based tunnel encapsulation extended communities.

When configured to false, no encapsulation extended community is sent.

Defaulttrue
Introduced16.0.R1

Platforms

All

bgp-mh-site [site-name] string
Synopsis Enter the bgp-mh-site list instance
Contextconfigure service epipe string bgp-mh-site string
Treebgp-mh-site
Max. Instances1
Introduced16.0.R1

Platforms

All

[site-name] string
Synopsis Name for the specific site
Context configure service epipe string bgp-mh-site string
Treebgp-mh-site
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

boot-timer number
Synopsis Wait time after reboot to run the DF election algorithm
Contextconfigure service epipe string bgp-mh-site string boot-timer number
Treeboot-timer
Range0 to 600
Unitsseconds
Introduced 16.0.R1

Platforms

All

id number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSite ID for the service
Contextconfigure service epipe string bgp-mh-site string id number
Treeid

Description

This command configures the ID for the site. The ID must match between services but is local to the service.

Range1 to 65535
Introduced16.0.R1

Platforms

All

preference number
Synopsis Preference to advertise in NLRI L2 extended community
Contextconfigure service epipe string bgp-mh-site string preference number
Treepreference
Range1 to 65535
Introduced16.0.R1

Platforms

All

sap string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSAP to be associated with this site
Contextconfigure service epipe string bgp-mh-site string sap string
Treesap
String Length1 to 45
Introduced16.0.R1

Platforms

All

bgp-vpws
Synopsis Enable the bgp-vpws context
Context configure service epipe string bgp-vpws
Treebgp-vpws
Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the VPWS edge instance
Contextconfigure service epipe string bgp-vpws admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

local-ve
Synopsis Enter the local-ve context
Context configure service epipe string bgp-vpws local-ve
Treelocal-ve
Introduced16.0.R1

Platforms

All

id number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal VPWS edge ID
Contextconfigure service epipe string bgp-vpws local-ve id number
Treeid
Range1 to 65535
Introduced16.0.R1

Platforms

All

name string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal VPWS instance name
Contextconfigure service epipe string bgp-vpws local-ve name string
Treename
String Length1 to 32
Introduced16.0.R1

Platforms

All

remote-ve [name] string
Synopsis Enter the remote-ve list instance
Contextconfigure service epipe string bgp-vpws remote-ve string
Treeremote-ve
Max. Instances2
Introduced16.0.R1

Platforms

All

[name] string
Synopsis Remote PE name to which a PW is to be signaled
Contextconfigure service epipe string bgp-vpws remote-ve string
Treeremote-ve
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

id number
Synopsis Remote VPWS edge ID
Context configure service epipe string bgp-vpws remote-ve string id number
Treeid
Range1 to 65535
Introduced16.0.R1

Platforms

All

customer reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisService customer ID
Contextconfigure service epipe string customer reference
Treecustomer

Reference

configure service customer string

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

description string
Synopsis Text description
Context configure service epipe string description string
Treedescription
String Length1 to 80
Introduced16.0.R1

Platforms

All

endpoint [name] string
Synopsis Enter the endpoint list instance
Contextconfigure service epipe string endpoint string
Treeendpoint
Max. Instances2
Introduced16.0.R1

Platforms

All

[name] string
Synopsis Service endpoint name
Context configure service epipe string endpoint string
Treeendpoint
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

revert-time (number | keyword)
Synopsis Time to wait before reverting to primary spoke SDP
Contextconfigure service epipe string endpoint string revert-time (number | keyword)
Treerevert-time
Range1 to 600
Unitsseconds
Options never, immediate
Defaultimmediate
Introduced16.0.R1

Platforms

All

eth-cfm
Synopsis Enter the eth-cfm context
Context configure service epipe string eth-cfm
Treeeth-cfm
Introduced19.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ignore-l2vpn-mtu-mismatch boolean
Synopsis Ignore the L2 VPN MTU mismatch with local service MTU
Contextconfigure service epipe string ignore-l2vpn-mtu-mismatch boolean
Treeignore-l2vpn-mtu-mismatch

Description

When configured to true, the router does not check the value of the Layer 2 MTU in the Layer2 Info Extended Community received in a BGP update message against the local service MTU or locally signaled MTU. It may, therefore, bring up the BGP VPWS service regardless of any MTU mismatch.

When configured to false, an MTU mismatch prevents the system from bringing up a BGP-VPWS service.

Defaultfalse
Introduced22.2.R1

Platforms

All

load-balancing
Synopsis Enter the load-balancing context
Contextconfigure service epipe string load-balancing
Treeload-balancing
Introduced16.0.R1

Platforms

All

lbl-eth-or-ip-l4-teid boolean
Synopsis Enable hashing of MPLS ethernet and IP packets on SAPs
Contextconfigure service epipe string load-balancing lbl-eth-or-ip-l4-teid boolean
Treelbl-eth-or-ip-l4-teid

Description

When configured to true, this command enables hashing of MPLS Ethernet and MPLS IP packets received on the Epipe and VPLS service SAP using the MPLS labels, the inner IP addresses, the port numbers, and the GTP TEID field, if read by the system. This capability is supported on line cards that are FP4-based and later. 

Defaultfalse
Introduced22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

nat-outside [nat-group] number
Synopsis Enter the nat-outside list instance
Contextconfigure service epipe string nat-outside number
Treenat-outside
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[nat-group] number
Synopsis NAT group
Contextconfigure service epipe string nat-outside number
Treenat-outside
Max. Range0 to 4294967295

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of Epipe as a NAT outside service
Contextconfigure service epipe string nat-outside number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

pbb
Synopsis Enter the pbb context
Context configure service epipe string pbb
Treepbb
Introduced16.0.R1

Platforms

All

local-switch-service-state keyword
Synopsis Endpoint state used to determine PBB-Epipe state
Contextconfigure service epipe string pbb local-switch-service-state keyword
Treelocal-switch-service-state

Description

In a PBB Epipe with two SAPs and a PBB tunnel, this command controls whether the operational state of the PBB-Epipe service depends on the state of the PBB tunnel only, or on the state of two of the three endpoints (PBB tunnel and two SAPs). The second case implies that at least one of the SAPs must be up for the PBB-Epipe service to be operationally up.

Optionssap, pbb-tunnel
Default sap
Introduced21.7.R1

Platforms

All

tunnel
Synopsis Enable the tunnel context
Context configure service epipe string pbb tunnel
Treetunnel
Introduced16.0.R1

Platforms

All

backbone-dest-mac string
Synopsis Backbone Destination MAC address
Context configure service epipe string pbb tunnel backbone-dest-mac string
Treebackbone-dest-mac

Notes

The following elements are part of a mandatory choice: backbone-dest-mac or backbone-dest-mac-name.

Introduced16.0.R1

Platforms

All

isid number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisService instance ID
Contextconfigure service epipe string pbb tunnel isid number
Treeisid
Range0 to 16777215

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

sap [sap-id] string
Synopsis Enter the sap list instance
Context configure service epipe string sap string
Treesap
Max. Instances2
Introduced16.0.R1

Platforms

All

[sap-id] string
Synopsis SAP ID
Contextconfigure service epipe string sap string
Treesap
String Length1 to 45

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

aarp
Synopsis Enable the aarp context
Context configure service epipe string sap string aarp
Treeaarp
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

type keyword
Synopsis Role referenced by the AARP
Context configure service epipe string sap string aarp type keyword
Treetype
Optionsdual-homed, dual-homed-secondary
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the SAP
Context configure service epipe string sap string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

bandwidth number
Synopsis SAP bandwidth
Contextconfigure service epipe string sap string bandwidth number
Treebandwidth
Range1 to 6400000000
Unitskilobps
Introduced 16.0.R1

Platforms

All

cflowd boolean
Synopsis Enable Cflowd collection and analysis on this SAP
Contextconfigure service epipe string sap string cflowd boolean
Treecflowd
Defaultfalse
Introduced16.0.R1

Platforms

All

cpu-protection
Synopsis Enter the cpu-protection context
Contextconfigure service epipe string sap string cpu-protection
Treecpu-protection
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

eth-cfm-monitoring
Synopsis Enable the eth-cfm-monitoring context
Contextconfigure service epipe string sap string cpu-protection eth-cfm-monitoring
Treeeth-cfm-monitoring

Notes

The following elements are part of a choice: eth-cfm-monitoring or mac-monitoring.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

mac-monitoring
Synopsis Monitor MAC for CPU protection
Context configure service epipe string sap string cpu-protection mac-monitoring
Treemac-monitoring

Notes

The following elements are part of a choice: eth-cfm-monitoring or mac-monitoring.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

egress
Synopsis Enter the egress context
Context configure service epipe string sap string egress
Treeegress
Introduced16.0.R1

Platforms

All

agg-rate
Synopsis Enter the agg-rate context
Context configure service epipe string sap string egress agg-rate
Treeagg-rate

Notes

The following elements are part of a choice: agg-rate or percent-agg-rate.

Introduced16.0.R1

Platforms

All

adaptation-rule keyword
Synopsis Adaptation rule to compute the operational PIR value when an aggregate shaper is used
Contextconfigure service epipe string sap string egress agg-rate adaptation-rule keyword
Treeadaptation-rule
Optionsmax, min, closest
Defaultclosest
Introduced22.10.R1

Platforms

7750 SR-1, 7750 SR-s

burst-limit (number | keyword)
Synopsis Shaping burst size when an aggregate shaper is used
Contextconfigure service epipe string sap string egress agg-rate burst-limit (number | keyword)
Treeburst-limit
Range1 to 14000000
Unitsbytes
Options auto
Default auto
Introduced22.10.R1

Platforms

7750 SR-1, 7750 SR-s

rate number
Synopsis Enforced aggregate rate for all queues
Contextconfigure service epipe string sap string egress agg-rate rate number
Treerate
Range1 to 6400000000
Unitskilobps
Introduced 16.0.R1

Platforms

All

filter
Synopsis Enter the filter context
Context configure service epipe string sap string egress filter
Treefilter
Introduced16.0.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service epipe string sap string egress qos
Treeqos
Introduced16.0.R1

Platforms

All

policer-control-policy
Synopsis Enter the policer-control-policy context
Contextconfigure service epipe string sap string egress qos policer-control-policy
Treepolicer-control-policy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

overrides
Synopsis Enable the overrides context
Context configure service epipe string sap string egress qos policer-control-policy overrides
Treeoverrides
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

root
Synopsis Enter the root context
Context configure service epipe string sap string egress qos policer-control-policy overrides root
Treeroot
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

priority-mbs-thresholds
Synopsis Enter the priority-mbs-thresholds context
Contextconfigure service epipe string sap string egress qos policer-control-policy overrides root priority-mbs-thresholds
Treepriority-mbs-thresholds
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

priority [priority-level] number
Synopsis Enter the priority list instance
Contextconfigure service epipe string sap string egress qos policer-control-policy overrides root priority-mbs-thresholds priority number
Treepriority
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

sap-egress
Synopsis Enter the sap-egress context
Context configure service epipe string sap string egress qos sap-egress
Treesap-egress
Introduced16.0.R1

Platforms

All

overrides
Synopsis Enter the overrides context
Context configure service epipe string sap string egress qos sap-egress overrides
Treeoverrides
Introduced16.0.R1

Platforms

All

hs-wrr-group [group-id] reference
Synopsis Enter the hs-wrr-group list instance
Contextconfigure service epipe string sap string egress qos sap-egress overrides hs-wrr-group reference
Treehs-wrr-group
Introduced16.0.R1

Platforms

7750 SR-7/12/12e

rate (number | keyword)
Synopsis Scheduling rate override applied to the HS WRR group
Contextconfigure service epipe string sap string egress qos sap-egress overrides hs-wrr-group reference rate (number | keyword)
Treerate
Range1 to 2000000000
Unitskilobps
Options max

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

7750 SR-7/12/12e

policer [policer-id] reference
Synopsis Enter the policer list instance
Contextconfigure service epipe string sap string egress qos sap-egress overrides policer reference
Treepolicer
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

cbs (number | keyword)
Synopsis CBS
Contextconfigure service epipe string sap string egress qos sap-egress overrides policer reference cbs (number | keyword)
Treecbs
Range0 to 268435456
Unitsbytes
Options auto
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

mbs (number | keyword)
Synopsis MBS
Contextconfigure service epipe string sap string egress qos sap-egress overrides policer reference mbs (number | keyword)
Treembs
Range0 to 268435456
Unitsbytes
Options auto
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service epipe string sap string egress qos sap-egress overrides policer reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

rate
Synopsis Enter the rate context
Context configure service epipe string sap string egress qos sap-egress overrides policer reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

cir (number | keyword)
Synopsis CIR rate
Contextconfigure service epipe string sap string egress qos sap-egress overrides policer reference rate cir (number | keyword)
Treecir
Range0 to 6400000000
Unitskilobps
Options max
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

pir (number | keyword)
Synopsis PIR rate
Contextconfigure service epipe string sap string egress qos sap-egress overrides policer reference rate pir (number | keyword)
Treepir
Range1 to 6400000000
Unitskilobps
Options max
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

stat-mode keyword
Synopsis Mode of statistics collected by the policer
Contextconfigure service epipe string sap string egress qos sap-egress overrides policer reference stat-mode keyword
Treestat-mode
Optionsno-stats, minimal, offered-profile-no-cir, offered-total-cir, offered-profile-cir, offered-limited-capped-cir, offered-profile-capped-cir, offered-total-cir-exceed, offered-four-profile-no-cir, offered-total-cir-four-profile
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

queue [queue-id] reference
Synopsis Enter the queue list instance
Context configure service epipe string sap string egress qos sap-egress overrides queue reference
Treequeue
Introduced16.0.R1

Platforms

All

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure service epipe string sap string egress qos sap-egress overrides queue reference adaptation-rule
Treeadaptation-rule
Introduced16.0.R1

Platforms

All

drop-tail
Synopsis Enter the drop-tail context
Context configure service epipe string sap string egress qos sap-egress overrides queue reference drop-tail
Treedrop-tail
Introduced16.0.R1

Platforms

All

low
Synopsis Enter the low context
Context configure service epipe string sap string egress qos sap-egress overrides queue reference drop-tail low
Treelow
Introduced16.0.R1

Platforms

All

hs-wred-queue
Synopsis Enter the hs-wred-queue context
Contextconfigure service epipe string sap string egress qos sap-egress overrides queue reference hs-wred-queue
Treehs-wred-queue
Introduced16.0.R1

Platforms

7750 SR-7/12/12e

monitor-queue-depth
Synopsis Enable the monitor-queue-depth context
Contextconfigure service epipe string sap string egress qos sap-egress overrides queue reference monitor-queue-depth
Treemonitor-queue-depth
Introduced20.10.R1

Platforms

All

parent
Synopsis Enter the parent context
Context configure service epipe string sap string egress qos sap-egress overrides queue reference parent
Treeparent
Introduced16.0.R1

Platforms

All

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service epipe string sap string egress qos sap-egress overrides queue reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

All

rate
Synopsis Enter the rate context
Context configure service epipe string sap string egress qos sap-egress overrides queue reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

All

port-redirect-group
Synopsis Enter the port-redirect-group context
Contextconfigure service epipe string sap string egress qos sap-egress port-redirect-group
Treeport-redirect-group
Introduced16.0.R1

Platforms

All

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service epipe string sap string egress qos scheduler-policy
Treescheduler-policy
Introduced16.0.R1

Platforms

All

overrides
Synopsis Enter the overrides context
Context configure service epipe string sap string egress qos scheduler-policy overrides
Treeoverrides
Introduced16.0.R1

Platforms

All

scheduler [scheduler-name] string
Synopsis Enter the scheduler list instance
Contextconfigure service epipe string sap string egress qos scheduler-policy overrides scheduler string
Treescheduler
Introduced16.0.R1

Platforms

All

[scheduler-name] string
Synopsis Scheduler name
Contextconfigure service epipe string sap string egress qos scheduler-policy overrides scheduler string
Treescheduler

Description

This command specifies the scheduler name which is composed of printable 7-bit ASCII characters. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes. Each scheduler must have a unique name within the context of the scheduler policy. However, the same name can be reused in multiple scheduler policies. If the scheduler name already exists within the policy tier level, the context changes to that scheduler name for the purpose of editing the scheduler commands.

If the scheduler name exists within the policy on a different tier, an error occurs and the current context does not change. If the scheduler name does not exist in this or another tier within the scheduler policy, it is assumed that an attempt is being made to create a scheduler of that name.

If the provided scheduler name is invalid, a name syntax error occurs, the command does not execute, and the context is not change.

String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

parent
Synopsis Enter the parent context
Context configure service epipe string sap string egress qos scheduler-policy overrides scheduler string parent
Treeparent
Introduced16.0.R1

Platforms

All

rate
Synopsis Enter the rate context
Context configure service epipe string sap string egress qos scheduler-policy overrides scheduler string rate
Treerate
Introduced16.0.R1

Platforms

All

virtual-port
Synopsis Enter the virtual-port context
Contextconfigure service epipe string sap string egress virtual-port
Treevirtual-port
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

endpoint reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisName of the endpoint
Contextconfigure service epipe string sap string endpoint reference
Treeendpoint

Reference

configure service epipe string endpoint string

Introduced16.0.R1

Platforms

All

eth-cfm
Synopsis Enter the eth-cfm context
Context configure service epipe string sap string eth-cfm
Treeeth-cfm
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ais boolean
Synopsis Enable the generation and the reception of AIS messages
Contextconfigure service epipe string sap string eth-cfm ais boolean
Treeais
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

collect-lmm-fc-stats
Synopsis Enter the collect-lmm-fc-stats context
Contextconfigure service epipe string sap string eth-cfm collect-lmm-fc-stats
Treecollect-lmm-fc-stats

Description

Commands in this context configure per forwarding class (FC) LMM information collection.

The commands fc-in-profile and fc in this context are mutually exclusive. The commands apply to either profile-aware or profile-unaware FCs respectively. 

This command and the collect-lmm-stats command are mutually exclusive when there is entity resource contention.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fc keyword
Synopsis Forwarding class name for profile-unaware counter
Contextconfigure service epipe string sap string eth-cfm collect-lmm-fc-stats fc keyword
Treefc

Description

This command configures individual counters for the specified FCs without regard for profile. The system includes all countable packets that match a configured FC, regardless of profile, in this counter.

An FC specified as part of this command and for this specific context cannot be specified as a profile-aware FC using the fc-in-profile command under the collect-lmm-fc-stats context. 

When this command is reentered, a differential is performed. Omitted FCs stop counting, newly added FCs start counting, and unchanged FCs continue to count.

Optionsbe, l2, af, l1, h2, ef, h1, nc
Max. Instances 8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fc-in-profile keyword
Synopsis Forwarding class name for profile-aware counter
Contextconfigure service epipe string sap string eth-cfm collect-lmm-fc-stats fc-in-profile keyword
Treefc-in-profile

Description

This command configures individual counters for the specified FCs with regard to profile. The system includes all countable packets that match a configured FC and that are deemed to be in-profile in this counter.

An FC specified as part of this command and for this specific context cannot be specified as a profile-unaware FC using the fc command under the collect-lmm-fc-stats context.

When this command is reentered, a differential is performed. Omitted FCs stop counting, newly added FCs start counting, and unchanged FCs continue to count.

Optionsbe, l2, af, l1, h2, ef, h1, nc
Max. Instances 8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

collect-lmm-stats boolean
Synopsis Collect statistics for loss measurement message tests
Contextconfigure service epipe string sap string eth-cfm collect-lmm-stats boolean
Treecollect-lmm-stats
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mep md-admin-name reference ma-admin-name reference mep-id number
Synopsis Enter the mep list instance
Context configure service epipe string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number
Treemep
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mep-id number
Synopsis Maintenance Endpoint (MEP) ID
Context configure service epipe string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number
Treemep
Range1 to 8191

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ais
Synopsis Enable the ais context
Context configure service epipe string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number ais
Treeais
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

alarm-notification
Synopsis Enter the alarm-notification context
Contextconfigure service epipe string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number alarm-notification
Treealarm-notification

Description

Commands in this context configure the Fault Notification Generator (FNG) time values to raise an alarm or reset the CCM defect alarm. 

Use these timers for network management processes. The timers are not tied into delaying the notification to the fault management system on the network element and do not affect fault propagation mechanisms.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ccm-padding-size number
Synopsis Number of octets of padding to insert in CCM packets
Contextconfigure service epipe string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number ccm-padding-size number
Treeccm-padding-size

Description

This command sets the byte size of the optional Data TLV to be included in the ETH-CC PDU.

This command increases the size of the ETH-CC PDU by the configured value. The base size of the ETH-CC PDU, including the Interface Status TLV and Port Status TLV, is 83 bytes not including the Layer 2 encapsulation. CCM padding is not supported when the CCM interval (configured through configure eth-cfm domain association ccm-interval) is less than 1 second.

Range3 to 1500
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

csf
Synopsis Enable the csf context
Context configure service epipe string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number csf
Treecsf
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

direction keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDirection the MEP faces
Contextconfigure service epipe string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number direction keyword
Treedirection
Optionsdown, up
Default down
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-test
Synopsis Enable the eth-test context
Context configure service epipe string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test
Treeeth-test

Description

Commands in this context configure information used by the Ethernet Test (ETH-TST) packet. The commands must be configured on both the sender and the receiver nodes. The test packets are used with the oam eth-cfm eth-test command.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

test-pattern
Synopsis Enter the test-pattern context
Contextconfigure service epipe string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test test-pattern
Treetest-pattern

Description

Commands in this context specify the test pattern for the ETH-TST frames. The pattern does not have to be the same on the sender and the receiver.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

pattern keyword
Synopsis Test pattern for Ethernet Test frames
Contextconfigure service epipe string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test test-pattern pattern keyword
Treepattern

Description

This command specifies the test pattern of the Ethernet Test (ETH-TST) frames. This does not have to be configured the same on the sender and the receiver.

Optionsall-zeros, all-ones
Default all-zeros
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

grace
Synopsis Enter the grace context
Context configure service epipe string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace
Treegrace

Description

Commands in this context configure the Nokia ETH-CFM Grace function and the ITU-T Y.1731 Ethernet Expected Default (ETH-ED) function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-ed
Synopsis Enter the eth-ed context
Context configure service epipe string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-ed
Treeeth-ed

Description

Commands in this context configure the ITU-T Y.1731 ETH-ED function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

rx-eth-ed boolean
Synopsis Receive and process ETH-ED ITU-T Y.1731 PDUs on the MEP
Contextconfigure service epipe string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-ed rx-eth-ed boolean
Treerx-eth-ed

Description

This command enables the reception and processing of the ITU-T Y.1731 ETH-ED PDU on the MEP.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-vsm-grace
Synopsis Enter the eth-vsm-grace context
Contextconfigure service epipe string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace
Treeeth-vsm-grace

Description

Commands in this context configure the Nokia ETH-CFM Grace function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

rx-eth-vsm-grace boolean
Synopsis Receive and process Nokia ETH-CFM Grace PDU on the MEP
Contextconfigure service epipe string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace rx-eth-vsm-grace boolean
Treerx-eth-vsm-grace

Description

When configured to true, the router enables the Nokia Grace function, which is a vendor-specific PDU that informs MEP peers that the local node may be entering a period of expected defect.

When configured to false, the router disables the Nokia Grace function.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

tx-eth-vsm-grace boolean
Synopsis Transmit ETH-ED PDUs from the MEP
Context configure service epipe string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace tx-eth-vsm-grace boolean
Treetx-eth-vsm-grace

Description

When configured to true, the router can transmit the Nokia ETH-CFM Grace PDU from the MEP when a system soft reset notification is received for one or more cards.

The Nokia Grace function is a vendor-specific PDU that informs MEP peers that the local node may be entering a period of expected defect.

The operator must configure the configure system eth-cfm grace command to instruct the system that the node is capable of transmitting expected-defect windows to peers. The system can only transmit one form of ETH-CFM grace (Nokia ETH-CFM Grace or ITU-T Y.1731 ETH-ED).

When configured to false, the router disables the transmission of the Nokia ETH-CFM Grace PDU from the MEP.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mac-address string
Synopsis MAC address of the MEP
Context configure service epipe string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number mac-address string
Treemac-address

Description

This command specifies the MAC address of the MEP.

When unconfigured, the MAC address of the port (if the MEP is on a SAP) or the MAC address of a bridge (if the MEP is on a spoke) is used.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

primary-vlan boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisMEP provisioned using MA primary VLAN ID
Contextconfigure service epipe string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number primary-vlan boolean
Treeprimary-vlan
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mip primary-vlan (number | keyword)
Synopsis Enter the mip list instance
Context configure service epipe string sap string eth-cfm mip primary-vlan (number | keyword)
Treemip

Description

This command allows the CFM function to include additional VLAN tags to the CFM packet that are carried to the egress and treated as service delimited. Typically, this function is used to influence the VLAN carried over a binding that uses the vc-type vlan or the binding forces the use of one or more VLAN tag that results in a mismatch between the service data arriving at the binding and the locally generated ETH-CFM PDUs arriving at the same egress. When this command is included under the MEP or MIP configuration, the tags used as part of the configuration typically match the SAP service delimited configuration.

Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

primary-vlan (number | keyword)
Synopsis VLAN ID to which the MIP is attached
Context configure service epipe string sap string eth-cfm mip primary-vlan (number | keyword)
Treemip

Description

This command provides an option for linking a MIP with a Primary VLAN number or none. When the none option is provided, the MIP does not include the primary vlan.

Range1 to 4094
Optionsnone

Notes

This element is part of a list key.

Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

cfm-vlan-tag string
Synopsis VLAN tags to apply to CFM PDUs for egress processing
Contextconfigure service epipe string sap string eth-cfm mip primary-vlan (number | keyword) cfm-vlan-tag string
Treecfm-vlan-tag

Description

This command allows the CFM function to include additional VLAN tags to the CFM packet that are carried to the egress and treated as service delimited. Typically, this function is used to influence the VLAN carried over a binding that uses the vc-type vlan or the binding forces the use of one or more VLAN tag that results in a mismatch between the service data arriving at the binding and the locally generated ETH-CFM PDUs arriving at the same egress. When this command is included under the MEP or MIP configuration, the tags used as part of the configuration typically match the SAP service delimited configuration.

String Length1 to 9
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

squelch-ingress-ctag-levels number
Synopsis Squelch levels using additional VLAN C-Tag space
Contextconfigure service epipe string sap string eth-cfm squelch-ingress-ctag-levels number
Treesquelch-ingress-ctag-levels

Description

This command defines the levels of the ETH-CFM packets that are silently discarded on ingress into the SAP or SDP binding from the wire that matches the service delineation of the SAP or SDP binding plus an additional VLAN, up to a maximum tag length of two tags. All ETH-CFM packets inbound to the SAP or SDP binding that match the configured levels are dropped without regard for any other ETH-CFM criteria. No statistical information or drop count is available for any ETH-CFM packet that is silently discarded by this option.

The list of levels must be a complete contiguous list from 0 up to the highest level to be dropped.

Range0 to 7
Max. Instances8
Introduced 21.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

squelch-ingress-levels number
Synopsis Levels for which ETH-CFM packets are silently discarded
Contextconfigure service epipe string sap string eth-cfm squelch-ingress-levels number
Treesquelch-ingress-levels

Description

This command defines the levels of the ETH-CFM packets that are silently discarded on ingress into the SAP or SDP binding from the wire that matches the service delineation of the SAP or SDP binding. All ETH-CFM packets inbound to the SAP or SDP binding that match the configured levels are dropped without regard for any other ETH-CFM criteria. No statistical information or drop count is available for any ETH-CFM packet that is silently discarded by this option.

The list of levels must be a complete contiguous list from 0 up to the highest level that will be dropped.

Range0 to 7
Max. Instances8
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ethernet
Synopsis Enter the ethernet context
Context configure service epipe string sap string ethernet
Treeethernet
Introduced20.5.R1

Platforms

All

llf
Synopsis Enter the llf context
Context configure service epipe string sap string ethernet llf
Treellf

Description

Commands in this context enable Link Loss Forwarding (LLF) on an Ethernet port. This feature provides an end-to-end OAM fault notification for Ethernet VLL service. It brings down the Ethernet port (Ethernet LLF) or sends a SONET/SDH Path AIS (ATM LLF) toward the attached CE when there is a local fault on the pseudowire or service, or a remote fault on the SAP or pseudowire, signaled with label withdrawal or T-LDP status bits. It ceases when the fault disappears.

The Ethernet port must be configured for null encapsulation.

This feature is also supported in Epipes with BGP-EVPN enabled. In this case, upon removal of the EVPN destination, the port transitions to an operationally down state, however the AD per-EVI route for the SAP is still advertised (the SAP remains operationally up). The port transitions to the operationally up state when the EVPN destination is created.

Introduced20.5.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of Link Loss Forwarding
Contextconfigure service epipe string sap string ethernet llf admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced20.5.R1

Platforms

All

ignore-oper-down boolean
Synopsis Ignore operational down state of the SAP on SAP failure
Contextconfigure service epipe string sap string ignore-oper-down boolean
Treeignore-oper-down

Description

When configured to true, the Epipe service does not transition to the operational down state when the SAP fails. This command can only be set to true for a single SAP in an Epipe. The command can be used in Epipes with or without EVPN enabled.

When configured to false, the Epipe service transitions to the operational down state when SAP fails.

Defaultfalse
Introduced16.0.R1

Platforms

All

ingress
Synopsis Enter the ingress context
Context configure service epipe string sap string ingress
Treeingress
Introduced16.0.R1

Platforms

All

filter
Synopsis Enter the filter context
Context configure service epipe string sap string ingress filter
Treefilter
Introduced16.0.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service epipe string sap string ingress qos
Treeqos
Introduced16.0.R1

Platforms

All

policer-control-policy
Synopsis Enter the policer-control-policy context
Contextconfigure service epipe string sap string ingress qos policer-control-policy
Treepolicer-control-policy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

overrides
Synopsis Enable the overrides context
Context configure service epipe string sap string ingress qos policer-control-policy overrides
Treeoverrides
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

root
Synopsis Enter the root context
Context configure service epipe string sap string ingress qos policer-control-policy overrides root
Treeroot
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

priority-mbs-thresholds
Synopsis Enter the priority-mbs-thresholds context
Contextconfigure service epipe string sap string ingress qos policer-control-policy overrides root priority-mbs-thresholds
Treepriority-mbs-thresholds
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

priority [priority-level] number
Synopsis Enter the priority list instance
Contextconfigure service epipe string sap string ingress qos policer-control-policy overrides root priority-mbs-thresholds priority number
Treepriority
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

sap-ingress
Synopsis Enter the sap-ingress context
Context configure service epipe string sap string ingress qos sap-ingress
Treesap-ingress
Introduced16.0.R1

Platforms

All

fp-redirect-group
Synopsis Enter the fp-redirect-group context
Contextconfigure service epipe string sap string ingress qos sap-ingress fp-redirect-group
Treefp-redirect-group
Introduced16.0.R1

Platforms

All

overrides
Synopsis Enter the overrides context
Context configure service epipe string sap string ingress qos sap-ingress overrides
Treeoverrides
Introduced16.0.R1

Platforms

All

ip-criteria
Synopsis Enter the ip-criteria context
Context configure service epipe string sap string ingress qos sap-ingress overrides ip-criteria
Treeip-criteria
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ipv6-criteria
Synopsis Enter the ipv6-criteria context
Contextconfigure service epipe string sap string ingress qos sap-ingress overrides ipv6-criteria
Treeipv6-criteria
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

policer [policer-id] reference
Synopsis Enter the policer list instance
Contextconfigure service epipe string sap string ingress qos sap-ingress overrides policer reference
Treepolicer
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

cbs (number | keyword)
Synopsis CBS
Contextconfigure service epipe string sap string ingress qos sap-ingress overrides policer reference cbs (number | keyword)
Treecbs
Range0 to 268435456
Unitsbytes
Options auto
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

mbs (number | keyword)
Synopsis MBS
Contextconfigure service epipe string sap string ingress qos sap-ingress overrides policer reference mbs (number | keyword)
Treembs
Range0 to 268435456
Unitsbytes
Options auto
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service epipe string sap string ingress qos sap-ingress overrides policer reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

rate
Synopsis Enter the rate context
Context configure service epipe string sap string ingress qos sap-ingress overrides policer reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

stat-mode keyword
Synopsis Mode of statistics collected by the policer
Contextconfigure service epipe string sap string ingress qos sap-ingress overrides policer reference stat-mode keyword
Treestat-mode
Optionsno-stats, minimal, offered-profile-no-cir, offered-total-cir, offered-priority-no-cir, offered-profile-cir, offered-priority-cir, offered-limited-profile-cir, offered-profile-capped-cir, offered-limited-capped-cir
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

queue [queue-id] reference
Synopsis Enter the queue list instance
Context configure service epipe string sap string ingress qos sap-ingress overrides queue reference
Treequeue
Introduced16.0.R1

Platforms

All

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure service epipe string sap string ingress qos sap-ingress overrides queue reference adaptation-rule
Treeadaptation-rule
Introduced16.0.R1

Platforms

All

drop-tail
Synopsis Enter the drop-tail context
Context configure service epipe string sap string ingress qos sap-ingress overrides queue reference drop-tail
Treedrop-tail
Introduced16.0.R1

Platforms

All

low
Synopsis Enter the low context
Context configure service epipe string sap string ingress qos sap-ingress overrides queue reference drop-tail low
Treelow
Introduced16.0.R1

Platforms

All

monitor-queue-depth
Synopsis Enable the monitor-queue-depth context
Contextconfigure service epipe string sap string ingress qos sap-ingress overrides queue reference monitor-queue-depth
Treemonitor-queue-depth
Introduced21.7.R1

Platforms

All

parent
Synopsis Enter the parent context
Context configure service epipe string sap string ingress qos sap-ingress overrides queue reference parent
Treeparent
Introduced16.0.R1

Platforms

All

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service epipe string sap string ingress qos sap-ingress overrides queue reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

All

rate
Synopsis Enter the rate context
Context configure service epipe string sap string ingress qos sap-ingress overrides queue reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

All

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service epipe string sap string ingress qos scheduler-policy
Treescheduler-policy
Introduced16.0.R1

Platforms

All

overrides
Synopsis Enter the overrides context
Context configure service epipe string sap string ingress qos scheduler-policy overrides
Treeoverrides
Introduced16.0.R1

Platforms

All

scheduler [scheduler-name] string
Synopsis Enter the scheduler list instance
Contextconfigure service epipe string sap string ingress qos scheduler-policy overrides scheduler string
Treescheduler
Introduced16.0.R1

Platforms

All

[scheduler-name] string
Synopsis Scheduler name
Contextconfigure service epipe string sap string ingress qos scheduler-policy overrides scheduler string
Treescheduler

Description

This command specifies the scheduler name which is composed of printable 7-bit ASCII characters. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes. Each scheduler must have a unique name within the context of the scheduler policy. However, the same name can be reused in multiple scheduler policies. If the scheduler name already exists within the policy tier level, the context changes to that scheduler name for the purpose of editing the scheduler commands.

If the scheduler name exists within the policy on a different tier, an error occurs and the current context does not change. If the scheduler name does not exist in this or another tier within the scheduler policy, it is assumed that an attempt is being made to create a scheduler of that name.

If the provided scheduler name is invalid, a name syntax error occurs, the command does not execute, and the context is not change.

String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

parent
Synopsis Enter the parent context
Context configure service epipe string sap string ingress qos scheduler-policy overrides scheduler string parent
Treeparent
Introduced16.0.R1

Platforms

All

rate
Synopsis Enter the rate context
Context configure service epipe string sap string ingress qos scheduler-policy overrides scheduler string rate
Treerate
Introduced16.0.R1

Platforms

All

qtag-manipulation
Synopsis Enter the qtag-manipulation context
Contextconfigure service epipe string sap string ingress qtag-manipulation
Treeqtag-manipulation
Introduced16.0.R1

Platforms

All

c-tag (number | keyword)
Synopsis Inner ingress VLAN translation for two service delimiting VLAN values
Contextconfigure service epipe string sap string ingress qtag-manipulation c-tag (number | keyword)
Treec-tag
Range0 to 4094
Optionstag-*

Notes

The following elements are part of a choice: push-dot1q-vlan or (c-tag and s-tag).

Introduced16.0.R1

Platforms

All

push-dot1q-vlan (number | keyword)
Synopsis VLAN translation information
Context configure service epipe string sap string ingress qtag-manipulation push-dot1q-vlan (number | keyword)
Treepush-dot1q-vlan
Range0 to 4094
Optionsuse-sap-svlan

Notes

The following elements are part of a choice: push-dot1q-vlan or (c-tag and s-tag).

Introduced16.0.R1

Platforms

All

s-tag number
Synopsis Outer ingress VLN translation for two service delimiting VLAN values
Contextconfigure service epipe string sap string ingress qtag-manipulation s-tag number
Trees-tag
Range0 to 4094

Notes

The following elements are part of a choice: push-dot1q-vlan or (c-tag and s-tag).

Introduced16.0.R1

Platforms

All

l2tpv3-session
Synopsis Enable the l2tpv3-session context
Contextconfigure service epipe string sap string l2tpv3-session
Treel2tpv3-session
Introduced16.0.R4

Platforms

All

pseudo-wire
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the pseudo-wire context
Contextconfigure service epipe string sap string l2tpv3-session pseudo-wire
Treepseudo-wire
Introduced16.0.R4

Platforms

All

ethernet
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the Ethernet PW-type for the L2TPv3 session
Contextconfigure service epipe string sap string l2tpv3-session pseudo-wire ethernet
Treeethernet

Notes

The following elements are part of a choice: ethernet or ethernet-vlan-id.

Introduced16.0.R4

Platforms

All

ethernet-vlan-id number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEthernet-VLAN PW-type ID for the L2TPv3 session
Contextconfigure service epipe string sap string l2tpv3-session pseudo-wire ethernet-vlan-id number
Treeethernet-vlan-id
Range0 to 4095

Notes

The following elements are part of a choice: ethernet or ethernet-vlan-id.

Introduced16.0.R4

Platforms

All

router
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the router context
Contextconfigure service epipe string sap string l2tpv3-session router
Treerouter
Introduced16.0.R4

Platforms

All

group string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTunnel group name
Contextconfigure service epipe string sap string l2tpv3-session router group string
Treegroup
String Length1 to 32
Introduced16.0.R4

Platforms

All

router-instance string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRouter name used to identify the router instance
Contextconfigure service epipe string sap string l2tpv3-session router router-instance string
Treerouter-instance
String Length1 to 64
Introduced16.0.R4

Platforms

All

vc-id number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisVC ID for the L2TPv3 session
Contextconfigure service epipe string sap string l2tpv3-session vc-id number
Treevc-id
Range1 to 4294967295
Introduced16.0.R4

Platforms

All

lag
Synopsis Enter the lag context
Context configure service epipe string sap string lag
Treelag
Introduced16.0.R1

Platforms

All

per-link-hash
Synopsis Enter the per-link-hash context
Contextconfigure service epipe string sap string lag per-link-hash
Treeper-link-hash
Introduced16.0.R1

Platforms

All

class number
Synopsis Class used on LAG egress using weighted per-link-hash
Contextconfigure service epipe string sap string lag per-link-hash class number
Treeclass
Range1 to 3
Default1
Introduced 16.0.R1

Platforms

All

weight number
Synopsis Weight used on LAG egress using weighted per-link-hash
Contextconfigure service epipe string sap string lag per-link-hash weight number
Treeweight
Range1 to 1024
Default1
Introduced 16.0.R1

Platforms

All

mc-ring
Synopsis Enable the mc-ring context
Context configure service epipe string sap string mc-ring
Treemc-ring
Introduced16.0.R1

Platforms

All

ring-node string
Synopsis Name for the ring node associated with this SAP
Contextconfigure service epipe string sap string mc-ring ring-node string
Treering-node
String Length1 to 32

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

oper-group reference
Synopsis Operational group
Context configure service epipe string sap string oper-group reference
Treeoper-group

Reference

configure service oper-group string

Notes

The following elements are part of a choice: monitor-oper-group or oper-group.

Introduced16.0.R1

Platforms

All

transit-policy
Synopsis Enable the transit-policy context
Contextconfigure service epipe string sap string transit-policy
Treetransit-policy
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP transit policy ID
Contextconfigure service epipe string sap string transit-policy ip reference
Treeip

Reference

configure application-assurance group number partition number transit-ip-policy number

Notes

The following elements are part of a mandatory choice: ip or prefix.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

prefix reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP prefix policy ID
Contextconfigure service epipe string sap string transit-policy prefix reference
Treeprefix

Reference

configure application-assurance group number partition number transit-prefix-policy number

Notes

The following elements are part of a mandatory choice: ip or prefix.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

segment-routing-v6 [instance] number
Synopsis Enter the segment-routing-v6 list instance
Contextconfigure service epipe string segment-routing-v6 number
Treesegment-routing-v6

Description

Commands in this context configure the SRv6 instance that is used in the service.

Introduced21.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

[instance] number
Synopsis Segment routing v6 instance
Context configure service epipe string segment-routing-v6 number
Treesegment-routing-v6
Range1

Notes

This element is part of a list key.

Introduced21.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

locator [locator-name] reference
Synopsis Enter the locator list instance
Contextconfigure service epipe string segment-routing-v6 number locator reference
Treelocator
Max. Instances1
Introduced21.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

function
Synopsis Enter the function context
Context configure service epipe string segment-routing-v6 number locator reference function
Treefunction

Description

Commands in this context configure SRv6 SID function values and parameters for the locator.

Introduced21.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

end-dx2
Synopsis Enable the end-dx2 context
Context configure service epipe string segment-routing-v6 number locator reference function end-dx2
Treeend-dx2
Introduced21.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

value number
Synopsis SRv6 function value
Context configure service epipe string segment-routing-v6 number locator reference function end-dx2 value number
Treevalue

Description

This command assigns the optional static function value for the routes in the VPRN, VPLS, or Epipe instance.

When unconfigured, the system allocates a value dynamically.

Range1 to 1048575
Introduced21.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

micro-segment-locator [locator-name] reference
Synopsis Enter the micro-segment-locator list instance
Contextconfigure service epipe string segment-routing-v6 number micro-segment-locator reference
Treemicro-segment-locator
Max. Instances1
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

[locator-name] reference
Synopsis Micro-segment SRv6 locator name
Context configure service epipe string segment-routing-v6 number micro-segment-locator reference
Treemicro-segment-locator

Description

This command associates a pre-defined micro-segment SRv6 locator (defined in the configure router segment-routing segment-routing-v6 context) with the SRv6 instance in the service. The same micro-segment locator can be referenced in multiple BGP instances used by IPVPN or EVPN.

Reference

configure router string segment-routing segment-routing-v6 micro-segment-locator string

Notes

This element is part of a list key.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

function
Synopsis Enter the function context
Context configure service epipe string segment-routing-v6 number micro-segment-locator reference function
Treefunction
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

udx2
Synopsis Enable the udx2 context
Context configure service epipe string segment-routing-v6 number micro-segment-locator reference function udx2
Treeudx2

Description

Commands in this context configure the SRv6 micro-segment uDX2 behavior and the function value that is associated with the SRv6 instance in the service. When configured, decapsulation and cross-connect to the egress SAP occurs in the Epipe service.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

value number
Synopsis SRv6 function value
Context configure service epipe string segment-routing-v6 number micro-segment-locator reference function udx2 value number
Treevalue

Description

This command assigns the optional static function value for the routes in the VPRN, VPLS, or Epipe instance.

When unconfigured, the system allocates a value dynamically.

Range1 to 1048575
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

service-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisService ID
Contextconfigure service epipe string service-id number
Treeservice-id
Range1 to 2147483647
Introduced16.0.R1

Platforms

All

service-mtu number
Synopsis MTU size
Contextconfigure service epipe string service-mtu number
Treeservice-mtu

Description

This command configures the Maximum Transmission Unit (MTU) value (payload) for the service. The system uses the value to validate the operational state of the SAP and SDP binding within the service. The value overrides the default MTU for the service type.

The service MTU and a SAP’s service delineation encapsulation overhead (4 bytes for a dot1q tag) are used to derive the required MTU of the physical port or channel on which the SAP was created. If the required payload is larger than the port or channel MTU, the SAP is placed in an inoperative state. If the required MTU is equal to or less than the port or channel MTU, the SAP transitions to the operative state.

When binding an SDP to a service, the service MTU is compared to the path MTU associated with the SDP. The path MTU can be administratively defined in the context of the SDP. The default or administrative path MTU can be dynamically reduced due to the MTU capabilities discovered by the tunneling mechanism of the SDP or the egress interface MTU capabilities based on the next hop in the tunnel path. If the service MTU is larger than the path MTU, the SDP binding for the service is placed in an inoperative state. If the service MTU is equal to or less than the path MTU, the SDP binding is placed in an operational state.

If a service MTU, port or channel MTU, or path MTU is dynamically or administratively modified, all associated SAP and SDP binding operational states are automatically reevaluated.

Binding operational states are automatically reevaluated.

For I-VPLS and Epipes bound to a B-VPLS, the service MTU must be at least 18 bytes smaller than the B-VPLS service MTU to accommodate the PBB header.

Because this connects a Layer 2 to a Layer 3 service, adjust the service MTU under the Epipe service. The MTU that is advertised from the Epipe side is service MTU minus EtherHeaderSize.

In the configure service epipe spoke-sdp context, the adv-service-mtu command can be used to override the configured MTU value used in T-LDP signaling to the far-end of an Epipe spoke-sdp. The adv-service-mtu command is also used to validate the value signaled by the far-end PE.

Range1 to 9782
Introduced16.0.R1

Platforms

All

spoke-sdp [sdp-bind-id] string
Synopsis Enter the spoke-sdp list instance
Contextconfigure service epipe string spoke-sdp string
Treespoke-sdp
Introduced16.0.R1

Platforms

All

[sdp-bind-id] string
Synopsis SDP binding ID
Contextconfigure service epipe string spoke-sdp string
Treespoke-sdp
String Length3 to 16

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

aarp
Synopsis Enable the aarp context
Context configure service epipe string spoke-sdp string aarp
Treeaarp
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

type keyword
Synopsis Role referenced by the AARP
Context configure service epipe string spoke-sdp string aarp type keyword
Treetype
Optionsdual-homed, dual-homed-secondary
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the SDP binding to the service
Contextconfigure service epipe string spoke-sdp string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

adv-service-mtu number
Synopsis Service MTU used in signaling
Context configure service epipe string spoke-sdp string adv-service-mtu number
Treeadv-service-mtu

Description

This command configures the MTU value that is signaled in the targeted LDP for the spoke-SDP, instead of the service MTU. However, the configuration does not affect the locally enforced value, which is still based on the service MTU.

This MTU value cannot be configured on a spoke-SDP that is bound to an SDP with the adv-mtu-override command (configure service sdp context).

When unconfigured, an adjusted service MTU is used (service-mtu command).

Range0 to 9782
Introduced21.5.R1

Platforms

All

bandwidth (number | keyword)
Synopsis Bandwidth that is reserved for this SDP binding
Contextconfigure service epipe string spoke-sdp string bandwidth (number | keyword)
Treebandwidth
Range0 to 100000000
Unitskilobps
Options max
Default 0
Introduced16.0.R1

Platforms

All

bfd
Synopsis Enter the bfd context
Context configure service epipe string spoke-sdp string bfd
Treebfd
Introduced21.2.R1

Platforms

All

bfd-template reference
Synopsis BFD template associated with the SDP binding
Contextconfigure service epipe string spoke-sdp string bfd bfd-template reference
Treebfd-template

Description

This command configures a named BFD template to be used by VCCV BFD on PWs belonging to the VLL service. The template specifies parameters, such as the minimum transmit and receive control packet timer intervals, used by the BFD session. Template parameters are configured under the configure router bfd context.

Reference

configure bfd bfd-template string

Introduced21.2.R1

Platforms

All

failure-action keyword
Synopsis VCCV BFD action taken on the SDP binding
Contextconfigure service epipe string spoke-sdp string bfd failure-action keyword
Treefailure-action

Description

This command configures a named BFD template to be used by VCCV BFD on PWs belonging to the VLL service. The template specifies parameters, such as the minimum transmit and receive control packet timer intervals, used by the BFD session. Template parameters are configured under the configure router bfd context.

Optionsnone, down
Default none
Introduced21.2.R1

Platforms

All

wait-for-up-timer number
Synopsis Time waited for BFD up status
Context configure service epipe string spoke-sdp string bfd wait-for-up-timer number
Treewait-for-up-timer

Description

This command configures the time interval that is used to wait for a BFD session to come up.

This command is triggered when a spoke-SDP is first administratively enabled and a VCCV BFD session transitions from up to down. The command is required to allow time for BFD sessions to come up, and for BFD to settle before selecting the active spoke-SDP for use in a redundant set. In the case where a VCCV BFD session is bouncing, the timer prevents excessive flapping of the operational state of a spoke-SDP.

Range1 to 60
Unitsseconds
Introduced 21.2.R1

Platforms

All

cpu-protection
Synopsis Enter the cpu-protection context
Contextconfigure service epipe string spoke-sdp string cpu-protection
Treecpu-protection
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

eth-cfm-monitoring
Synopsis Enable the eth-cfm-monitoring context
Contextconfigure service epipe string spoke-sdp string cpu-protection eth-cfm-monitoring
Treeeth-cfm-monitoring

Notes

The following elements are part of a choice: eth-cfm-monitoring or mac-monitoring.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

mac-monitoring
Synopsis Monitor MAC for CPU protection
Context configure service epipe string spoke-sdp string cpu-protection mac-monitoring
Treemac-monitoring

Notes

The following elements are part of a choice: eth-cfm-monitoring or mac-monitoring.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

egress
Synopsis Enter the egress context
Context configure service epipe string spoke-sdp string egress
Treeegress
Introduced16.0.R1

Platforms

All

filter
Synopsis Enter the filter context
Context configure service epipe string spoke-sdp string egress filter
Treefilter
Introduced16.0.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service epipe string spoke-sdp string egress qos
Treeqos
Introduced16.0.R1

Platforms

All

network
Synopsis Enter the network context
Context configure service epipe string spoke-sdp string egress qos network
Treenetwork
Introduced16.0.R1

Platforms

All

port-redirect-group
Synopsis Enter the port-redirect-group context
Contextconfigure service epipe string spoke-sdp string egress qos network port-redirect-group
Treeport-redirect-group
Introduced16.0.R1

Platforms

All

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEgress MPLS VC label to send packets to the far end
Contextconfigure service epipe string spoke-sdp string egress vc-label number
Treevc-label
Range16 to 1048575
Introduced16.0.R1

Platforms

All

endpoint
Synopsis Enter the endpoint context
Context configure service epipe string spoke-sdp string endpoint
Treeendpoint
Introduced16.0.R1

Platforms

All

icb boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisBind SDP as type Inter-Chassis Backup (ICB)
Contextconfigure service epipe string spoke-sdp string endpoint icb boolean
Treeicb
Defaultfalse
Introduced16.0.R1

Platforms

All

name reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisService endpoint name
Contextconfigure service epipe string spoke-sdp string endpoint name reference
Treename

Reference

configure service epipe string endpoint string

Introduced16.0.R1

Platforms

All

precedence (number | keyword)
Synopsis Precedence when multiple SDP binds are on one endpoint
Contextconfigure service epipe string spoke-sdp string endpoint precedence (number | keyword)
Treeprecedence
Range1 to 4
Optionsprimary
Default4
Introduced 16.0.R1

Platforms

All

entropy-label
Synopsis Enable the use of entropy labels for spoke SDPs
Contextconfigure service epipe string spoke-sdp string entropy-label
Treeentropy-label

Notes

The following elements are part of a choice: entropy-label or hash-label.

Introduced16.0.R1

Platforms

All

eth-cfm
Synopsis Enter the eth-cfm context
Context configure service epipe string spoke-sdp string eth-cfm
Treeeth-cfm
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

collect-lmm-fc-stats
Synopsis Enter the collect-lmm-fc-stats context
Contextconfigure service epipe string spoke-sdp string eth-cfm collect-lmm-fc-stats
Treecollect-lmm-fc-stats

Description

Commands in this context configure per forwarding class (FC) LMM information collection.

The commands fc-in-profile and fc in this context are mutually exclusive. The commands apply to either profile-aware or profile-unaware FCs respectively. 

This command and the collect-lmm-stats command are mutually exclusive when there is entity resource contention.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fc keyword
Synopsis Forwarding class name for profile-unaware counter
Contextconfigure service epipe string spoke-sdp string eth-cfm collect-lmm-fc-stats fc keyword
Treefc

Description

This command configures individual counters for the specified FCs without regard for profile. The system includes all countable packets that match a configured FC, regardless of profile, in this counter.

An FC specified as part of this command and for this specific context cannot be specified as a profile-aware FC using the fc-in-profile command under the collect-lmm-fc-stats context. 

When this command is reentered, a differential is performed. Omitted FCs stop counting, newly added FCs start counting, and unchanged FCs continue to count.

Optionsbe, l2, af, l1, h2, ef, h1, nc
Max. Instances 8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fc-in-profile keyword
Synopsis Forwarding class name for profile-aware counter
Contextconfigure service epipe string spoke-sdp string eth-cfm collect-lmm-fc-stats fc-in-profile keyword
Treefc-in-profile

Description

This command configures individual counters for the specified FCs with regard to profile. The system includes all countable packets that match a configured FC and that are deemed to be in-profile in this counter.

An FC specified as part of this command and for this specific context cannot be specified as a profile-unaware FC using the fc command under the collect-lmm-fc-stats context.

When this command is reentered, a differential is performed. Omitted FCs stop counting, newly added FCs start counting, and unchanged FCs continue to count.

Optionsbe, l2, af, l1, h2, ef, h1, nc
Max. Instances 8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

collect-lmm-stats boolean
Synopsis Collect statistics for loss measurement message tests
Contextconfigure service epipe string spoke-sdp string eth-cfm collect-lmm-stats boolean
Treecollect-lmm-stats

Description

When configured to true, the router instantiates the statistical counter to transmit and receive packets for the LAG facility MEP bindings.

The show eth-cfm collect-lmm-stats command displays entities that have been enabled to collect transit and receive counters.

When configured to false, the router does not instantiate the counter and the LMM PDU associated with the MEP does not populate the counters in the packet.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mep md-admin-name reference ma-admin-name reference mep-id number
Synopsis Enter the mep list instance
Context configure service epipe string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number
Treemep
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mep-id number
Synopsis Maintenance Endpoint (MEP) ID
Context configure service epipe string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number
Treemep
Range1 to 8191

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ais
Synopsis Enable the ais context
Context configure service epipe string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number ais
Treeais
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

alarm-notification
Synopsis Enter the alarm-notification context
Contextconfigure service epipe string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number alarm-notification
Treealarm-notification

Description

Commands in this context configure the Fault Notification Generator (FNG) time values to raise an alarm or reset the CCM defect alarm. 

Use these timers for network management processes. The timers are not tied into delaying the notification to the fault management system on the network element and do not affect fault propagation mechanisms.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ccm-padding-size number
Synopsis Number of octets of padding to insert in CCM packets
Contextconfigure service epipe string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number ccm-padding-size number
Treeccm-padding-size

Description

This command sets the byte size of the optional Data TLV to be included in the ETH-CC PDU.

This command increases the size of the ETH-CC PDU by the configured value. The base size of the ETH-CC PDU, including the Interface Status TLV and Port Status TLV, is 83 bytes not including the Layer 2 encapsulation. CCM padding is not supported when the CCM interval (configured through configure eth-cfm domain association ccm-interval) is less than 1 second.

Range3 to 1500
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

csf
Synopsis Enable the csf context
Context configure service epipe string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number csf
Treecsf
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

direction keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDirection the MEP faces
Contextconfigure service epipe string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number direction keyword
Treedirection
Optionsdown, up
Default down
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-test
Synopsis Enable the eth-test context
Context configure service epipe string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test
Treeeth-test

Description

Commands in this context configure information used by the Ethernet Test (ETH-TST) packet. The commands must be configured on both the sender and the receiver nodes. The test packets are used with the oam eth-cfm eth-test command.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

test-pattern
Synopsis Enter the test-pattern context
Contextconfigure service epipe string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test test-pattern
Treetest-pattern

Description

Commands in this context specify the test pattern for the ETH-TST frames. The pattern does not have to be the same on the sender and the receiver.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

pattern keyword
Synopsis Test pattern for Ethernet Test frames
Contextconfigure service epipe string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test test-pattern pattern keyword
Treepattern

Description

This command specifies the test pattern of the Ethernet Test (ETH-TST) frames. This does not have to be configured the same on the sender and the receiver.

Optionsall-zeros, all-ones
Default all-zeros
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

grace
Synopsis Enter the grace context
Context configure service epipe string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace
Treegrace

Description

Commands in this context configure the Nokia ETH-CFM Grace function and the ITU-T Y.1731 Ethernet Expected Default (ETH-ED) function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-ed
Synopsis Enter the eth-ed context
Context configure service epipe string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-ed
Treeeth-ed

Description

Commands in this context configure the ITU-T Y.1731 ETH-ED function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

rx-eth-ed boolean
Synopsis Receive and process ETH-ED ITU-T Y.1731 PDUs on the MEP
Contextconfigure service epipe string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-ed rx-eth-ed boolean
Treerx-eth-ed

Description

This command enables the reception and processing of the ITU-T Y.1731 ETH-ED PDU on the MEP.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-vsm-grace
Synopsis Enter the eth-vsm-grace context
Contextconfigure service epipe string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace
Treeeth-vsm-grace

Description

Commands in this context configure the Nokia ETH-CFM Grace function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

rx-eth-vsm-grace boolean
Synopsis Receive and process Nokia ETH-CFM Grace PDU on the MEP
Contextconfigure service epipe string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace rx-eth-vsm-grace boolean
Treerx-eth-vsm-grace

Description

When configured to true, the router enables the Nokia Grace function, which is a vendor-specific PDU that informs MEP peers that the local node may be entering a period of expected defect.

When configured to false, the router disables the Nokia Grace function.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

tx-eth-vsm-grace boolean
Synopsis Transmit ETH-ED PDUs from the MEP
Context configure service epipe string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace tx-eth-vsm-grace boolean
Treetx-eth-vsm-grace

Description

When configured to true, the router can transmit the Nokia ETH-CFM Grace PDU from the MEP when a system soft reset notification is received for one or more cards.

The Nokia Grace function is a vendor-specific PDU that informs MEP peers that the local node may be entering a period of expected defect.

The operator must configure the configure system eth-cfm grace command to instruct the system that the node is capable of transmitting expected-defect windows to peers. The system can only transmit one form of ETH-CFM grace (Nokia ETH-CFM Grace or ITU-T Y.1731 ETH-ED).

When configured to false, the router disables the transmission of the Nokia ETH-CFM Grace PDU from the MEP.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mac-address string
Synopsis MAC address of the MEP
Context configure service epipe string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number mac-address string
Treemac-address

Description

This command specifies the MAC address of the MEP.

When unconfigured, the MAC address of the port (if the MEP is on a SAP) or the MAC address of a bridge (if the MEP is on a spoke) is used.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

primary-vlan boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisMEP provisioned using MA primary VLAN ID
Contextconfigure service epipe string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number primary-vlan boolean
Treeprimary-vlan
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mip primary-vlan (number | keyword)
Synopsis Enter the mip list instance
Context configure service epipe string spoke-sdp string eth-cfm mip primary-vlan (number | keyword)
Treemip
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

primary-vlan (number | keyword)
Synopsis VLAN ID to which the MIP is attached
Context configure service epipe string spoke-sdp string eth-cfm mip primary-vlan (number | keyword)
Treemip

Description

This command provides an option for linking a MIP with a Primary VLAN number or none. When the none option is provided, the MIP does not include the primary vlan.

Range1 to 4094
Optionsnone

Notes

This element is part of a list key.

Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

cfm-vlan-tag string
Synopsis VLAN tags to apply to CFM PDUs for egress processing
Contextconfigure service epipe string spoke-sdp string eth-cfm mip primary-vlan (number | keyword) cfm-vlan-tag string
Treecfm-vlan-tag

Description

This command allows the CFM function to include additional VLAN tags to the CFM packet that are carried to the egress and treated as service delimited. Typically, this function is used to influence the VLAN carried over a binding that uses the vc-type vlan or the binding forces the use of one or more VLAN tag that results in a mismatch between the service data arriving at the binding and the locally generated ETH-CFM PDUs arriving at the same egress. When this command is included under the MEP or MIP configuration, the tags used as part of the configuration typically match the SAP service delimited configuration.

String Length1 to 9
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

squelch-ingress-ctag-levels number
Synopsis Squelch levels using additional VLAN C-Tag space
Contextconfigure service epipe string spoke-sdp string eth-cfm squelch-ingress-ctag-levels number
Treesquelch-ingress-ctag-levels

Description

This command defines the levels of the ETH-CFM packets that are silently discarded on ingress into the SAP or SDP binding from the wire that matches the service delineation of the SAP or SDP binding plus an additional VLAN, up to a maximum tag length of two tags. All ETH-CFM packets inbound to the SAP or SDP binding that match the configured levels are dropped without regard for any other ETH-CFM criteria. No statistical information or drop count is available for any ETH-CFM packet that is silently discarded by this option.

The list of levels must be a complete contiguous list from 0 up to the highest level to be dropped.

Range0 to 7
Max. Instances8
Introduced 21.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

squelch-ingress-levels number
Synopsis Levels for which ETH-CFM packets are silently discarded
Contextconfigure service epipe string spoke-sdp string eth-cfm squelch-ingress-levels number
Treesquelch-ingress-levels

Description

This command defines the levels of the ETH-CFM packets that are silently discarded on ingress into the SAP or SDP binding from the wire that matches the service delineation of the SAP or SDP binding. All ETH-CFM packets inbound to the SAP or SDP binding that match the configured levels are dropped without regard for any other ETH-CFM criteria. No statistical information or drop count is available for any ETH-CFM packet that is silently discarded by this option.

The list of levels must be a complete contiguous list from 0 up to the highest level that will be dropped.

Range0 to 7
Max. Instances8
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

hash-label
Synopsis Enable the hash-label context
Context configure service epipe string spoke-sdp string hash-label
Treehash-label

Description

Commands in this context configure the use of hash labels for egress datapaths.

For information about hash-label handling, see the "Hash labels" section of the 7450 ESS, 7750 SR, 7950 XRS, and VSR MPLS Guide.

Notes

The following elements are part of a choice: entropy-label or hash-label.

Introduced16.0.R1

Platforms

All

signal-capability
Synopsis Signal hash label capability to the remote PE
Contextconfigure service epipe string spoke-sdp string hash-label signal-capability
Treesignal-capability

Description

When configured, this command enables the signaling and negotiating of the hash label between the local and remote PE nodes.

The signaling process outcome determines whether the local PE inserts the hash label on the user packets. This outcome can override the local PE configuration.

Introduced16.0.R1

Platforms

All

ingress
Synopsis Enter the ingress context
Context configure service epipe string spoke-sdp string ingress
Treeingress
Introduced16.0.R1

Platforms

All

filter
Synopsis Enter the filter context
Context configure service epipe string spoke-sdp string ingress filter
Treefilter
Introduced16.0.R1

Platforms

All

l2tpv3
Synopsis Enter the l2tpv3 context
Context configure service epipe string spoke-sdp string ingress l2tpv3
Treel2tpv3
Introduced16.0.R1

Platforms

All

cookie
Synopsis Enter the cookie context
Context configure service epipe string spoke-sdp string ingress l2tpv3 cookie
Treecookie
Introduced16.0.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service epipe string spoke-sdp string ingress qos
Treeqos
Introduced16.0.R1

Platforms

All

network
Synopsis Enter the network context
Context configure service epipe string spoke-sdp string ingress qos network
Treenetwork
Introduced16.0.R1

Platforms

All

fp-redirect-group
Synopsis Enter the fp-redirect-group context
Contextconfigure service epipe string spoke-sdp string ingress qos network fp-redirect-group
Treefp-redirect-group
Introduced16.0.R1

Platforms

All

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIngress MPLS VC label to send packets to the far end
Contextconfigure service epipe string spoke-sdp string ingress vc-label number
Treevc-label
Range1 to 1048575
Introduced16.0.R1

Platforms

All

oper-group reference
Synopsis Operational group identifier
Context configure service epipe string spoke-sdp string oper-group reference
Treeoper-group

Reference

configure service oper-group string

Notes

The following elements are part of a choice: monitor-oper-group or oper-group.

Introduced16.0.R1

Platforms

All

pw-status
Synopsis Enter the pw-status context
Context configure service epipe string spoke-sdp string pw-status
Treepw-status
Introduced16.0.R1

Platforms

All

block-on-peer-fault boolean
Synopsis Block transmit direction of PW based on status code
Contextconfigure service epipe string spoke-sdp string pw-status block-on-peer-fault boolean
Treeblock-on-peer-fault
Defaultfalse

Notes

The following elements are part of a choice: block-on-peer-fault or standby-signaling-slave.

Introduced16.0.R1

Platforms

All

transit-policy
Synopsis Enable the transit-policy context
Contextconfigure service epipe string spoke-sdp string transit-policy
Treetransit-policy
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP transit policy ID
Contextconfigure service epipe string spoke-sdp string transit-policy ip reference
Treeip

Reference

configure application-assurance group number partition number transit-ip-policy number

Notes

The following elements are part of a mandatory choice: ip or prefix.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

vc-type keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisVirtual circuit type associated with the SDP binding
Contextconfigure service epipe string spoke-sdp string vc-type keyword
Treevc-type
Optionsether, vlan
Default ether
Introduced16.0.R1

Platforms

All

test boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDesignate as a test service
Contextconfigure service epipe string test boolean
Treetest
Defaultfalse
Introduced16.0.R1

Platforms

All

vc-switching boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisUse PW switching signaling for spoke SDPs in service
Contextconfigure service epipe string vc-switching boolean
Treevc-switching
Defaultfalse
Introduced16.0.R1

Platforms

All

vpn-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVPN identifier for the service
Contextconfigure service epipe string vpn-id number
Treevpn-id
Range1 to 2147483647
Introduced16.0.R1

Platforms

All

vxlan
Synopsis Enter the vxlan context
Context configure service epipe string vxlan
Treevxlan
Introduced16.0.R1

Platforms

All

instance [vxlan-instance] number
Synopsis Enter the instance list instance
Contextconfigure service epipe string vxlan instance number
Treeinstance
Max. Instances1
Introduced16.0.R1

Platforms

All

[vxlan-instance] number
Synopsis VXLAN instance
Contextconfigure service epipe string vxlan instance number
Treeinstance
Range1

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

egress-vtep
Synopsis Enter the egress-vtep context
Context configure service epipe string vxlan instance number egress-vtep
Treeegress-vtep
Introduced16.0.R1

Platforms

All

ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis VTEP IP address used when originating VXLAN packets
Contextconfigure service epipe string vxlan instance number egress-vtep ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeip-address
Introduced16.0.R1

Platforms

All

vni number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVNI of the VXLAN
Contextconfigure service epipe string vxlan instance number vni number
Treevni
Range1 to 16777215

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

source-vtep (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Vxlan source virtual tunnel endpoint information
Contextconfigure service epipe string vxlan source-vtep (ipv4-address-no-zone | ipv6-address-no-zone)
Treesource-vtep
Introduced16.0.R1

Platforms

All

ies [service-name] string

Synopsis Enter the ies list instance
Context configure service ies string
Treeies
Introduced16.0.R1

Platforms

All

[service-name] string
Synopsis Administrative service name
Context configure service ies string
Treeies
String Length1 to 64

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

aa-interface [interface-name] string
Synopsis Enter the aa-interface list instance
Contextconfigure service ies string aa-interface string
Treeaa-interface
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[interface-name] string
Synopsis Interface name
Contextconfigure service ies string aa-interface string
Treeaa-interface
String Length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the interface
Contextconfigure service ies string aa-interface string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

description string
Synopsis Text description
Context configure service ies string aa-interface string description string
Treedescription
String Length1 to 255
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-mtu number
Synopsis IP MTU applied to outgoing packets
Context configure service ies string aa-interface string ip-mtu number
Treeip-mtu

Description

This command configures the IP maximum transmission unit (MTU) for the associated router IP interface.

Range512 to 9786
Unitsbytes
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ipv4
Synopsis Enter the ipv4 context
Context configure service ies string aa-interface string ipv4
Treeipv4
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

primary
Synopsis Enable the primary context
Context configure service ies string aa-interface string ipv4 primary
Treeprimary
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

address string
Synopsis Primary IPv4 address assigned to the interface
Contextconfigure service ies string aa-interface string ipv4 primary address string
Treeaddress

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

sap [sap-id] string
Synopsis Enter the sap list instance
Context configure service ies string aa-interface string sap string
Treesap
Max. Instances1
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[sap-id] string
Synopsis SAP ID
Contextconfigure service ies string aa-interface string sap string
Treesap
String Length1 to 45

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the SAP
Context configure service ies string aa-interface string sap string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

description string
Synopsis Text description
Context configure service ies string aa-interface string sap string description string
Treedescription
String Length1 to 160
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

egress
Synopsis Enter the egress context
Context configure service ies string aa-interface string sap string egress
Treeegress
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

qos
Synopsis Enter the qos context
Context configure service ies string aa-interface string sap string egress qos
Treeqos
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

sap-egress
Synopsis Enter the sap-egress context
Context configure service ies string aa-interface string sap string egress qos sap-egress
Treesap-egress
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

virtual-port
Synopsis Enter the virtual-port context
Contextconfigure service ies string aa-interface string sap string egress virtual-port
Treevirtual-port
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

fwd-wholesale
Synopsis Enter the fwd-wholesale context
Contextconfigure service ies string aa-interface string sap string fwd-wholesale
Treefwd-wholesale
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ingress
Synopsis Enter the ingress context
Context configure service ies string aa-interface string sap string ingress
Treeingress
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

qos
Synopsis Enter the qos context
Context configure service ies string aa-interface string sap string ingress qos
Treeqos
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

sap-ingress
Synopsis Enter the sap-ingress context
Context configure service ies string aa-interface string sap string ingress qos sap-ingress
Treesap-ingress
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

lag
Synopsis Enter the lag context
Context configure service ies string aa-interface string sap string lag
Treelag
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

aarp-interface [interface-name] string
Synopsis Enter the aarp-interface list instance
Contextconfigure service ies string aarp-interface string
Treeaarp-interface
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[interface-name] string
Synopsis Interface name
Contextconfigure service ies string aarp-interface string
Treeaarp-interface
String Length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the interface
Contextconfigure service ies string aarp-interface string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

description string
Synopsis Text description
Context configure service ies string aarp-interface string description string
Treedescription
String Length1 to 255
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-mtu number
Synopsis IP MTU applied to outgoing packets
Context configure service ies string aarp-interface string ip-mtu number
Treeip-mtu

Description

This command configures the IP maximum transmission unit (MTU) for the associated router IP interface.

Range512 to 9786
Unitsbytes
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

spoke-sdp [sdp-bind-id] string
Synopsis Enter the spoke-sdp list instance
Contextconfigure service ies string aarp-interface string spoke-sdp string
Treespoke-sdp
Max. Instances1
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[sdp-bind-id] string
Synopsis SDP binding ID
Contextconfigure service ies string aarp-interface string spoke-sdp string
Treespoke-sdp
String Length3 to 16

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

aarp
Synopsis Enable the aarp context
Context configure service ies string aarp-interface string spoke-sdp string aarp
Treeaarp
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

id reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisAARP instance ID
Contextconfigure service ies string aarp-interface string spoke-sdp string aarp id reference
Treeid

Reference

configure application-assurance aarp number

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisRole of the spoke SDP referenced by the AARP
Contextconfigure service ies string aarp-interface string spoke-sdp string aarp type keyword
Treetype
Optionssubscriber-side-shunt, network-side-shunt

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of this service SDP binding
Contextconfigure service ies string aarp-interface string spoke-sdp string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

egress
Synopsis Enter the egress context
Context configure service ies string aarp-interface string spoke-sdp string egress
Treeegress
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisVC egress value that indicates a specific connection
Contextconfigure service ies string aarp-interface string spoke-sdp string egress vc-label number
Treevc-label
Range16 to 1048575
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ingress
Synopsis Enter the ingress context
Context configure service ies string aarp-interface string spoke-sdp string ingress
Treeingress
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisVC ingress value that indicates a specific connection
Contextconfigure service ies string aarp-interface string spoke-sdp string ingress vc-label number
Treevc-label
Range1 to 1048575
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the service
Context configure service ies string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

customer reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisService customer ID
Contextconfigure service ies string customer reference
Treecustomer

Reference

configure service customer string

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

description string
Synopsis Text description
Context configure service ies string description string
Treedescription
String Length1 to 80
Introduced16.0.R1

Platforms

All

eth-cfm
Synopsis Enter the eth-cfm context
Context configure service ies string eth-cfm
Treeeth-cfm
Introduced19.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

igmp-host-tracking
Synopsis Enter the igmp-host-tracking context
Contextconfigure service ies string igmp-host-tracking
Treeigmp-host-tracking
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of IGMP host tracking
Contextconfigure service ies string igmp-host-tracking admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

expiry-time number
Synopsis Time that the system continues to track inactive hosts
Contextconfigure service ies string igmp-host-tracking expiry-time number
Treeexpiry-time
Range1 to 65535
Unitsseconds
Default 260
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

interface [interface-name] string
Synopsis Enter the interface list instance
Contextconfigure service ies string interface string
Treeinterface

Description

Commands in this context create a logical IP routing interface. When created, attributes such as an IP address and SAP ID can be associated with the IP interface.

Introduced16.0.R1

Platforms

All

[interface-name] string
Synopsis Interface name
Contextconfigure service ies string interface string
Treeinterface
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the interface
Contextconfigure service ies string interface string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

cflowd-parameters
Synopsis Enter the cflowd-parameters context
Contextconfigure service ies string interface string cflowd-parameters
Treecflowd-parameters
Introduced16.0.R1

Platforms

All

sampling [sampling-type] keyword
Synopsis Enter the sampling list instance
Contextconfigure service ies string interface string cflowd-parameters sampling keyword
Treesampling
Introduced16.0.R1

Platforms

All

[sampling-type] keyword
Synopsis Traffic sampling type
Context configure service ies string interface string cflowd-parameters sampling keyword
Treesampling

Description

This command configures the type of traffic to be sampled on the associated IP interface.

Optionsunicast, multicast, both

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

direction keyword
Synopsis Direction of traffic for cflowd sampling
Contextconfigure service ies string interface string cflowd-parameters sampling keyword direction keyword
Treedirection

Description

This command configures the direction in which sampling occurs on the associated IP interfaces.

Optionsingress-only, egress-only, both
Defaultingress-only
Introduced16.0.R1

Platforms

All

type keyword
Synopsis Type of cflowd analysis
Context configure service ies string interface string cflowd-parameters sampling keyword type keyword
Treetype

Description

This command configures the cflowd sampling type on the associated IP interface.

Optionsacl, interface

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

dynamic-tunnel-redundant-nexthop string
Synopsis Redundant next-hop address for the dynamic IPsec tunnel
Contextconfigure service ies string interface string dynamic-tunnel-redundant-nexthop string
Treedynamic-tunnel-redundant-nexthop

Description

This command specifies the redundant next-hop address on a public or private IPsec interface (with public or private tunnel SAP) for a dynamic IPsec tunnel. The next-hop address is used by a standby node to shunt traffic to a master if it receives the address.

The next-hop address is resolved in the routing table of a corresponding service.

Notes

The following elements are part of a choice: multi-chassis-shunting-profile or (dynamic-tunnel-redundant-nexthop and static-tunnel-redundant-nexthop).

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

hold-time
Synopsis Enter the hold-time context
Context configure service ies string interface string hold-time
Treehold-time
Introduced16.0.R1

Platforms

All

ipv4
Synopsis Enter the ipv4 context
Context configure service ies string interface string hold-time ipv4
Treeipv4
Introduced16.0.R1

Platforms

All

down
Synopsis Enter the down context
Context configure service ies string interface string hold-time ipv4 down
Treedown

Description

Commands in this context configure the down hold timer, which specifies the delay before activating the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface up, unless an operator configures the init-only command. 

Introduced16.0.R1

Platforms

All

init-only boolean
Synopsis Apply delay only at interface configuration or reboot
Contextconfigure service ies string interface string hold-time ipv4 down init-only boolean
Treeinit-only

Description

This command applies a delay only when the IP interface is first configured or after a system reboot.

Defaultfalse
Introduced16.0.R1

Platforms

All

up
Synopsis Enter the up context
Context configure service ies string interface string hold-time ipv4 up
Treeup

Description

Commands in this context configure the up hold timer, which specifies the delay before deactivation of the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface down.

Introduced16.0.R1

Platforms

All

ipv6
Synopsis Enter the ipv6 context
Context configure service ies string interface string hold-time ipv6
Treeipv6
Introduced16.0.R1

Platforms

All

down
Synopsis Enter the down context
Context configure service ies string interface string hold-time ipv6 down
Treedown

Description

Commands in this context configure the down hold timer, which specifies the delay before activation of the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface up, unless an operator configures the init-only command. 

Introduced16.0.R1

Platforms

All

init-only boolean
Synopsis Apply delay only at interface configuration or reboot
Contextconfigure service ies string interface string hold-time ipv6 down init-only boolean
Treeinit-only

Description

When configured to true, the system applies a delay only when the IP interface is first configured or after a system reboot.

Defaultfalse
Introduced16.0.R1

Platforms

All

up
Synopsis Enter the up context
Context configure service ies string interface string hold-time ipv6 up
Treeup

Description

Commands in this context configure the up hold timer, which specifies the delay before deactivation of the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface down.

Introduced16.0.R1

Platforms

All

if-attribute
Synopsis Enter the if-attribute context
Contextconfigure service ies string interface string if-attribute
Treeif-attribute
Introduced16.0.R1

Platforms

All

ingress
Synopsis Enter the ingress context
Context configure service ies string interface string ingress
Treeingress
Introduced19.7.R1

Platforms

All

destination-class-lookup boolean
Synopsis Enable BGP destination class lookup
Context configure service ies string interface string ingress destination-class-lookup boolean
Treedestination-class-lookup

Description

When configured to true, the router performs a destination class lookup. This command is supported on FP3-based cards and later and is used in combination with the destination-class match criterion for an IP filter policy to filter egress traffic based on BGP destination classes.

When configured to false, destination class lookup is not enabled.

Defaultfalse
Introduced20.7.R1

Platforms

All

ip-mtu number
Synopsis IP MTU applied to outgoing packets
Context configure service ies string interface string ip-mtu number
Treeip-mtu

Description

This command configures the IP maximum transmission unit (MTU) for the associated router IP interface.

Range512 to 9786
Unitsbytes
Introduced 16.0.R1

Platforms

All

ipsec
Synopsis Enable the ipsec context
Context configure service ies string interface string ipsec
Treeipsec

Description

Commands in this context configure an IPsec secured interface.

Introduced22.7.R1

Platforms

VSR

admin-state keyword
Synopsis Administrative state of IPsec secured interface
Contextconfigure service ies string interface string ipsec admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced22.7.R1

Platforms

VSR

ip-exception reference
Synopsis IP exception filter
Context configure service ies string interface string ipsec ip-exception reference
Treeip-exception

Description

This command configures the IP exception filter for the secured interface. All ingress traffic matching the specified filter bypasses IPsec processing.

Reference

configure filter ip-exception string

Introduced22.7.R1

Platforms

VSR

ipsec-tunnel [name] string
Synopsis Enter the ipsec-tunnel list instance
Contextconfigure service ies string interface string ipsec ipsec-tunnel string
Treeipsec-tunnel

Description

Commands in this context configure IPsec tunnels used to secure traffic forwarded over the interface.

Introduced22.7.R1

Platforms

VSR

bfd
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the bfd context
Contextconfigure service ies string interface string ipsec ipsec-tunnel string bfd
Treebfd
Introduced22.7.R1

Platforms

VSR

bfd-designate boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDesignate IPsec tunnel to carry BFD traffic
Contextconfigure service ies string interface string ipsec ipsec-tunnel string bfd bfd-designate boolean
Treebfd-designate
Defaultfalse
Introduced22.7.R1

Platforms

VSR

bfd-liveness
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the bfd-liveness context
Contextconfigure service ies string interface string ipsec ipsec-tunnel string bfd bfd-liveness
Treebfd-liveness

Description

Commands in this context configure a BFD session to provide a heart-beat mechanism for a specified IPsec tunnel. There can be only one BFD session assigned to any given IPsec tunnel, but there can be multiple IPsec tunnels using the same BFD session.

BFD controls the state of the association tunnel. If the BFD session goes down, the system brings down the associated non-designated IPsec tunnel.

Introduced22.7.R1

Platforms

VSR

dest-ip string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDestination address used for the BFD session
Contextconfigure service ies string interface string ipsec ipsec-tunnel string bfd bfd-liveness dest-ip string
Treedest-ip

Notes

This element is mandatory.

Introduced22.7.R1

Platforms

VSR

interface string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisName of the interface used by the BFD session
Contextconfigure service ies string interface string ipsec ipsec-tunnel string bfd bfd-liveness interface string
Treeinterface
String Length1 to 32

Notes

This element is mandatory.

Introduced22.7.R1

Platforms

VSR

service-name string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative service name
Contextconfigure service ies string interface string ipsec ipsec-tunnel string bfd bfd-liveness service-name string
Treeservice-name

Description

This command configures the name of the service where BFD traffic is forwarded to.

String Length1 to 64

Notes

This element is mandatory.

Introduced22.7.R1

Platforms

VSR

clear-df-bit boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisReset the DF bit to 0 in all payload IP packets
Contextconfigure service ies string interface string ipsec ipsec-tunnel string clear-df-bit boolean
Treeclear-df-bit

Description

When configured to true, the DF bit is set to 0 in all payload IP packets associated with the IPsec tunnel, before any potential fragmentation occurs.

Defaultfalse
Introduced22.7.R1

Platforms

VSR

copy-traffic-class-upon-decapsulation boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable traffic class copy upon decapsulation
Contextconfigure service ies string interface string ipsec ipsec-tunnel string copy-traffic-class-upon-decapsulation boolean
Treecopy-traffic-class-upon-decapsulation

Description

When configured to true, the system copies the traffic class from the outer tunnel IP packet header to the payload IP packet header in the decapsulating direction (public to private).

Defaultfalse
Introduced22.7.R1

Platforms

VSR

encapsulated-ip-mtu number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum size of the encapsulated tunnel packet
Contextconfigure service ies string interface string ipsec ipsec-tunnel string encapsulated-ip-mtu number
Treeencapsulated-ip-mtu

Description

This command specifies the maximum size of the encapsulated tunnel packet to the IPsec tunnel, the IP tunnel, or the dynamic tunnels terminated on the IPsec Gateway. If the encapsulated IPv4 or IPv6 tunnel packet exceeds this value, the system fragments the packet.

Range512 to 9000
Unitsbytes
Introduced 22.7.R1

Platforms

VSR

icmp-generation
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the icmp-generation context
Contextconfigure service ies string interface string ipsec ipsec-tunnel string icmp-generation
Treeicmp-generation

Description

Commands in this context configure settings for ICMPv4 message generation.

Introduced22.7.R1

Platforms

VSR

frag-required
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the frag-required context
Contextconfigure service ies string interface string ipsec ipsec-tunnel string icmp-generation frag-required
Treefrag-required

Description

Commands in this context configure the attributes for sending generated ICMP Destination Unreachable "fragmentation needed and DF set" messages (type 3, code 4) back to the source, if the received size of the IPv4 packet on the private side exceeds the private MTU size.

Introduced22.7.R1

Platforms

VSR

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of sending ICMP messages
Contextconfigure service ies string interface string ipsec ipsec-tunnel string icmp-generation frag-required admin-state keyword
Treeadmin-state

Description

This command configures the administrative state of sending ICMP Destination Unreachable "fragmentation needed, DF set" messages (type 3, code 4) messages to the source if the received size of the IPv4 packet on the private side exceeds the private MTU size.

Optionsenable, disable
Default enable
Introduced22.7.R1

Platforms

VSR

interval number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisInterval for sending ICMP messages
Contextconfigure service ies string interface string ipsec ipsec-tunnel string icmp-generation frag-required interval number
Treeinterval

Description

This command configures the interval for sending ICMP Destination Unreachable "fragmentation needed, DF set" messages (type 3, code 4).

Range1 to 60
Unitsseconds
Default 10
Introduced22.7.R1

Platforms

VSR

message-count number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of ICMP messages that can be sent
Contextconfigure service ies string interface string ipsec ipsec-tunnel string icmp-generation frag-required message-count number
Treemessage-count

Description

This command configures the maximum number of ICMP Destination Unreachable "fragmentation needed, DF set" messages (type 3, code 4) that can be sent during the configured interval.

Range10 to 1000
Default100
Introduced 22.7.R1

Platforms

VSR

icmp6-generation
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the icmp6-generation context
Contextconfigure service ies string interface string ipsec ipsec-tunnel string icmp6-generation
Treeicmp6-generation

Description

Commands in this context configure settings for ICMPv6 message generation.

Introduced22.7.R1

Platforms

VSR

packet-too-big
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the packet-too-big context
Contextconfigure service ies string interface string ipsec ipsec-tunnel string icmp6-generation packet-too-big
Treepacket-too-big

Description

Commands in this context configure the parameters to send ICMPv6 PTB (Packet Too Big) messages on the private side.

The system sends PTB messages if a received IPv6 packet on the private side is greater than 1280 bytes and it exceeds the private MTU of the tunnel.

The private MTU for the tunnel is configured via the configure router interface ipsec ipsec-tunnel ip-mtu command for the interface.

Introduced22.7.R1

Platforms

VSR

message-count number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of ICMPv6 PTB messages that can be sent
Contextconfigure service ies string interface string ipsec ipsec-tunnel string icmp6-generation packet-too-big message-count number
Treemessage-count

Description

This command configures the maximum number of PTB messages that can be sent during the configured interval.

Range10 to 1000
Default100
Introduced 22.7.R1

Platforms

VSR

ip-mtu number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPrivate MTU of the IPsec tunnel
Contextconfigure service ies string interface string ipsec ipsec-tunnel string ip-mtu number
Treeip-mtu

Description

This command specifies the private MTU of the IPsec tunnel. The private MTU is used to determine the need for fragmentation before encapsulation of the payload packet.

Range512 to 9000
Unitsbytes
Introduced 22.7.R1

Platforms

VSR

key-exchange
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the key-exchange context
Contextconfigure service ies string interface string ipsec ipsec-tunnel string key-exchange
Treekey-exchange
Introduced22.7.R1

Platforms

VSR

dynamic
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the dynamic context
Contextconfigure service ies string interface string ipsec ipsec-tunnel string key-exchange dynamic
Treedynamic

Notes

The following elements are part of a choice: dynamic or manual.

Introduced22.7.R1

Platforms

VSR

cert
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the cert context
Contextconfigure service ies string interface string ipsec ipsec-tunnel string key-exchange dynamic cert
Treecert

Description

Commands in this context configure the attributes of the dynamic keying certificate.

Introduced22.7.R1

Platforms

VSR

status-verify
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the status-verify context
Contextconfigure service ies string interface string ipsec ipsec-tunnel string key-exchange dynamic cert status-verify
Treestatus-verify

Description

Commands in this context configure attributes of Certificate Status Verification (CSV).

Introduced22.7.R1

Platforms

VSR

primary keyword
Synopsis Primary method of CSV to verify the revocation status
Contextconfigure service ies string interface string ipsec ipsec-tunnel string key-exchange dynamic cert status-verify primary keyword
Treeprimary

Description

This command configures the primary method of Certificate Status Verification (CSV) that is used to verify the revocation status of the certificate of the peer.

Optionscrl, ocsp
Default crl
Introduced22.7.R1

Platforms

VSR

secondary keyword
Synopsis Secondary method used to verify certificate revocation
Contextconfigure service ies string interface string ipsec ipsec-tunnel string key-exchange dynamic cert status-verify secondary keyword
Treesecondary

Description

This command specifies the secondary method of Certificate Status Verification (CSV) that is used to verify the revocation status of the peer certificate.

Optionsnone, crl, ocsp
Defaultnone
Introduced22.7.R1

Platforms

VSR

id
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the id context
Contextconfigure service ies string interface string ipsec ipsec-tunnel string key-exchange dynamic id
Treeid

Description

Commands in this context specify the local ID used for IDi or IDr for IKEv2 negotiation.

The default behavior depends on the local authentication method as follows:

  • Psk: local tunnel IP address

  • Cert-auth: subject of the local certificate

Introduced22.7.R1

Platforms

VSR

fqdn string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisFQDN used as the local ID IKE type
Contextconfigure service ies string interface string ipsec ipsec-tunnel string key-exchange dynamic id fqdn string
Treefqdn
String Length1 to 255

Notes

The following elements are part of a choice: fqdn, ipv4, or ipv6.

Introduced22.7.R1

Platforms

VSR

ipv4 string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPv4 as the local ID type
Contextconfigure service ies string interface string ipsec ipsec-tunnel string key-exchange dynamic id ipv4 string
Treeipv4

Notes

The following elements are part of a choice: fqdn, ipv4, or ipv6.

Introduced22.7.R1

Platforms

VSR

ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPv6 used as the local IKE ID type
Contextconfigure service ies string interface string ipsec ipsec-tunnel string key-exchange dynamic id ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
Treeipv6

Notes

The following elements are part of a choice: fqdn, ipv4, or ipv6.

Introduced22.7.R1

Platforms

VSR

ike-policy reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIKE policy ID
Contextconfigure service ies string interface string ipsec ipsec-tunnel string key-exchange dynamic ike-policy reference
Treeike-policy

Description

This command specifies the ID of the IKE policy used for IKE negotiation.

The ipsec-transport-mode-profile configuration only supports IKEv2.

Reference

configure ipsec ike-policy number

Introduced22.7.R1

Platforms

VSR

ipsec-transform reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPsec transform IDs used by the dynamic key
Contextconfigure service ies string interface string ipsec ipsec-tunnel string key-exchange dynamic ipsec-transform reference
Treeipsec-transform

Description

This command specifies IPsec transform IDs used for CHILD_SA negotiation.

Reference

configure ipsec ipsec-transform number

Max. Instances4
Introduced22.7.R1

Platforms

VSR

manual
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the manual context
Contextconfigure service ies string interface string ipsec ipsec-tunnel string key-exchange manual
Treemanual

Description

Commands in this context configure settings for manually configured security associations for the IPsec tunnel.

Notes

The following elements are part of a choice: dynamic or manual.

Introduced22.7.R1

Platforms

VSR

keys [security-association] number direction keyword
Synopsis Enter the keys list instance
Context configure service ies string interface string ipsec ipsec-tunnel string key-exchange manual keys number direction keyword
Treekeys

Description

Commands in this context configure the security association list for the tunnel.

Introduced22.7.R1

Platforms

VSR

spi number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSPI of inbound and outbound packets
Contextconfigure service ies string interface string ipsec ipsec-tunnel string key-exchange manual keys number direction keyword spi number
Treespi

Description

This command specifies the Security Parameter Index (SPI) used to look up the instruction to verify and decrypt the incoming IPsec packets when the direction is inbound. When the direction is outbound, the SPI is used in the encoding of the outgoing packets.

The remote node can use the SPI to look up the instruction to verify and decrypt the packet.

Range256 to 16383

Notes

This element is mandatory.

Introduced22.7.R1

Platforms

VSR

local-gateway-address-override (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal IPsec tunnel endpoint address
Contextconfigure service ies string interface string ipsec ipsec-tunnel string local-gateway-address-override (ipv4-address-no-zone | ipv6-address-no-zone)
Treelocal-gateway-address-override

Description

This command configures the local IPsec tunnel endpoint address. This overrides the default endpoint address, which is the interface address.

Introduced22.7.R1

Platforms

VSR

max-history-key-records
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the max-history-key-records context
Contextconfigure service ies string interface string ipsec ipsec-tunnel string max-history-key-records
Treemax-history-key-records

Description

Commands in this context configure the settings for recording historical IPsec keys.

Introduced22.7.R1

Platforms

VSR

esp number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of recent records
Contextconfigure service ies string interface string ipsec ipsec-tunnel string max-history-key-records esp number
Treeesp
Range1 to 48
Introduced22.7.R1

Platforms

VSR

ike number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of historical IKE key records
Contextconfigure service ies string interface string ipsec ipsec-tunnel string max-history-key-records ike number
Treeike
Range1 to 3
Introduced22.7.R1

Platforms

VSR

pmtu-discovery-aging number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAging out time of the learned path MTU
Contextconfigure service ies string interface string ipsec ipsec-tunnel string pmtu-discovery-aging number
Treepmtu-discovery-aging

Description

This command configures the temporary public and private MTU expiration time. The temporary MTU is used for MTU propagation.

Range900 to 3600
Unitsseconds
Default 900
Introduced22.7.R1

Platforms

VSR

private-sap number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPrivate SAP ID
Contextconfigure service ies string interface string ipsec ipsec-tunnel string private-sap number
Treeprivate-sap
Range0 to 4094

Notes

This element is mandatory.

Introduced22.7.R1

Platforms

VSR

private-service string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPrivate service name
Contextconfigure service ies string interface string ipsec ipsec-tunnel string private-service string
Treeprivate-service

Description

This command configures the private service name.

If unconfigured, the private service is the service where the secured interface resides.

String Length1 to 64
Introduced22.7.R1

Platforms

VSR

private-tcp-mss-adjust number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTCP maximum segment size (MSS) adjustment
Contextconfigure service ies string interface string ipsec ipsec-tunnel string private-tcp-mss-adjust number
Treeprivate-tcp-mss-adjust

Description

This command specifies the TCP MSS to adjust for the tunnel on the private side.

When configured, the system may use the value to update the MSS option in the received TCP SYN packet on the private side.

Range512 to 9000
Unitsbytes
Introduced 22.7.R1

Platforms

VSR

propagate-pmtu-v4 boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable propagation of the path MTU to IPv4 hosts
Contextconfigure service ies string interface string ipsec ipsec-tunnel string propagate-pmtu-v4 boolean
Treepropagate-pmtu-v4

Description

When configured to true, the system propagates the path MTU learned from the public side to the private side (IPv4 hosts).

Defaulttrue
Introduced22.7.R1

Platforms

VSR

propagate-pmtu-v6 boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable propagation of the path MTU to IPv6 hosts
Contextconfigure service ies string interface string ipsec ipsec-tunnel string propagate-pmtu-v6 boolean
Treepropagate-pmtu-v6

Description

When configured to true, the system propagates the path MTU learned from the public side to the private side (IPv6 hosts).

Defaulttrue
Introduced22.7.R1

Platforms

VSR

public-tcp-mss-adjust (number | keyword)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTCP maximum segment size (MSS) on the public network
Contextconfigure service ies string interface string ipsec ipsec-tunnel string public-tcp-mss-adjust (number | keyword)
Treepublic-tcp-mss-adjust

Description

This command configures the MSS for the TCP traffic in an IPsec tunnel that is sent from the public network to the private network. The system may use this value to adjust or insert the MSS option in the TCP SYN packet.

Range512 to 9000
Unitsbytes
Options auto
Introduced 22.7.R1

Platforms

VSR

remote-gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRemote IPsec tunnel endpoint address
Contextconfigure service ies string interface string ipsec ipsec-tunnel string remote-gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeremote-gateway-address
Introduced22.7.R1

Platforms

VSR

replay-window number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAnti-replay window size
Contextconfigure service ies string interface string ipsec ipsec-tunnel string replay-window number
Treereplay-window

Description

This command specifies the size of an IPsec anti-replay window. If unconfigured, IPsec anti-replay is disabled.

Range32 | 64 | 128 | 256 | 512
Unitspackets
Introduced22.7.R1

Platforms

VSR

security-policy
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the security-policy context
Contextconfigure service ies string interface string ipsec ipsec-tunnel string security-policy
Treesecurity-policy

Description

Commands in this context specify a security policy used by the tunnel.

Introduced22.7.R1

Platforms

VSR

id number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSecurity policy ID for use by the tunnel
Contextconfigure service ies string interface string ipsec ipsec-tunnel string security-policy id number
Treeid
Max. Range0 to 4294967295
Introduced22.7.R1

Platforms

VSR

strict-match boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable strict match of the security policy entry
Contextconfigure service ies string interface string ipsec ipsec-tunnel string security-policy strict-match boolean
Treestrict-match

Description

When configured to true, this command enables strict match of the security policy entry.

When a CREATE_CHILD exchange request is received for a static IPsec tunnel, and this request is not a rekey request, ISA matches the received TSi and TSr with the configured security policy. This can be a match only when a received TS (in TSi or TSr) address range matches exactly with the subnet in a security policy entry.

If there is no match, the setup fails, and TS_UNACCEPTABLE is sent.

If there is a match, but there is an existing CHILD_SA for the matched security policy, the setup fails, and NO_PROPOSAL_CHOSEN is sent.

If there is a match, and there is not a CHILD_SA for the matched entry, the subnet is sent in the matched security policy entry as TSi and TSr, and the CHILD_SA is created.

Defaultfalse
Introduced22.7.R1

Platforms

VSR

ipv6-exception reference
Synopsis IPv6 filter exception used to bypass encryption
Contextconfigure service ies string interface string ipsec ipv6-exception reference
Treeipv6-exception

Description

This command specifies the IPv6 filter exception for an IPsec-secured IPv6 interface. When an IPv6 filter exception is added, clear text packets that match the exception criteria in the IPv6 filter exception can ingress the interface, even when IPsec is enabled on the interface.

Reference

configure filter ipv6-exception string

Introduced22.7.R1

Platforms

VSR

public-sap number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPublic SAP ID
Contextconfigure service ies string interface string ipsec public-sap number
Treepublic-sap
Range0 to 4094

Notes

This element is mandatory.

Introduced22.7.R1

Platforms

VSR

tunnel-group reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTunnel group ID
Contextconfigure service ies string interface string ipsec tunnel-group reference
Treetunnel-group

Reference

configure isa tunnel-group number

Notes

This element is mandatory.

Introduced22.7.R1

Platforms

VSR

ipv4
Synopsis Enter the ipv4 context
Context configure service ies string interface string ipv4
Treeipv4
Introduced16.0.R1

Platforms

All

addresses
Synopsis Enter the addresses context
Context configure service ies string interface string ipv4 addresses
Treeaddresses
Introduced16.0.R1

Platforms

All

address [ipv4-address] string
Synopsis Enter the address list instance
Contextconfigure service ies string interface string ipv4 addresses address string
Treeaddress
Introduced16.0.R1

Platforms

All

bfd
Synopsis Enter the bfd context
Context configure service ies string interface string ipv4 bfd
Treebfd
Introduced16.0.R1

Platforms

All

multiplier number
Synopsis Number of consecutive BFD messages missed from the peer
Contextconfigure service ies string interface string ipv4 bfd multiplier number
Treemultiplier

Description

This command configures the number of missed messages before the BFD session state is changed to down and the upper-level protocol is notified of the fault. A multiplier of less than 3 should not be used in production environments. 

Range1 to 20
Default3
Introduced 16.0.R1

Platforms

All

receive number
Synopsis BFD receive interval over this interface
Contextconfigure service ies string interface string ipv4 bfd receive number
Treereceive

Description

This command specifies the receive interval for the BFD session.

On the 7750 SR, this command can only be configured to a value less than 100 when the type command is configured to cpm-np.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 16.0.R1

Platforms

All

transmit-interval number
Synopsis BFD transmit interval over this interface
Contextconfigure service ies string interface string ipv4 bfd transmit-interval number
Treetransmit-interval

Description

This command configures the transmit intervals.

On the 7750 SR, this command can only be configured to a value less than 100 when the type command is configured to cpm-np.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 16.0.R1

Platforms

All

type keyword
Synopsis Local termination point for the BFD session
Contextconfigure service ies string interface string ipv4 bfd type keyword
Treetype

Description

This command sets the local termination point for the BFD session to allow for fast timers down to 10 ms granularity.

The options to specify where the BFD session runs are:

  • auto (default) – the system chooses and uses the line card CPU only for single-hop BFD sessions with timer intervals equal to or greater than 100ms. All others are placed on the cpm-np.

  • cpm-np – BFD session runs on the FP complex associated with the CPM. This is either the FP on the CPM or the one elected on smaller systems. 

  • fp – BFD session runs on the line card CPU. This option can only be used for single-hop BFD sessions with timers equal to or greater than 100ms.  

Optionscpm-np, auto, fp
Defaultauto
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

dhcp
Synopsis Enter the dhcp context
Context configure service ies string interface string ipv4 dhcp
Treedhcp
Introduced16.0.R1

Platforms

All

gi-address string
Synopsis GI address for the DHCP relay
Context configure service ies string interface string ipv4 dhcp gi-address string
Treegi-address

Description

This command configures the GI address to distinguish between the different subscriber interfaces (and potentially group interfaces) defined when the router functions as a DHCP relay.

By default, the GI address used in the relayed DHCP packet is the primary IP address of a normal IES interface. Specifying the GI address allows the user to choose a secondary address. For group interfaces, a GI address must be specified under the group interface DHCP context or subscriber interface DHCP context for DHCP to function.

Introduced16.0.R1

Platforms

All

option-82
Synopsis Enter the option-82 context
Context configure service ies string interface string ipv4 dhcp option-82
Treeoption-82

Description

Commands in this context configure the processing required when the router receives a DHCP request that already has an Option 82 field in the packet.

Introduced16.0.R1

Platforms

All

circuit-id
Synopsis Enter the circuit-id context
Context configure service ies string interface string ipv4 dhcp option-82 circuit-id
Treecircuit-id
Introduced16.0.R1

Platforms

All

ifindex
Synopsis Use the interface index for the circuit ID
Contextconfigure service ies string interface string ipv4 dhcp option-82 circuit-id ifindex
Treeifindex

Notes

The following elements are part of a choice: ascii-tuple, ifindex, none, sap-id, or vlan-ascii-tuple.

Introduced16.0.R1

Platforms

All

none
Synopsis Do not include the circuit ID
Context configure service ies string interface string ipv4 dhcp option-82 circuit-id none
Treenone

Notes

The following elements are part of a choice: ascii-tuple, ifindex, none, sap-id, or vlan-ascii-tuple.

Introduced16.0.R1

Platforms

All

vlan-ascii-tuple
Synopsis Include the VLAN ID and dot1p bits in the ASCII tuple
Contextconfigure service ies string interface string ipv4 dhcp option-82 circuit-id vlan-ascii-tuple
Treevlan-ascii-tuple

Description

When configured, the router includes the VLAN ID and dot1p bits with the ASCII-tuple information. This only occurs on dot1q and QinQ-encapsulated ports. When the Option 82 bits are stripped, dot1p bits are copied to the Ethernet header of the outgoing packet.

When unconfigured, the router leaves the circuit ID sub-option of the DHCP packet empty.

Notes

The following elements are part of a choice: ascii-tuple, ifindex, none, sap-id, or vlan-ascii-tuple.

Introduced16.0.R1

Platforms

All

remote-id
Synopsis Enter the remote-id context
Context configure service ies string interface string ipv4 dhcp option-82 remote-id
Treeremote-id

Description

Commands in this context configure the remote IP sub-option of the DHCP packet with the identity of the remote host end (typically the DHCP client).

Introduced16.0.R1

Platforms

All

mac
Synopsis Use the MAC address for the remote ID
Contextconfigure service ies string interface string ipv4 dhcp option-82 remote-id mac
Treemac

Notes

The following elements are part of a choice: ascii-string, mac, or none.

Introduced16.0.R1

Platforms

All

vendor-specific-option
Synopsis Enter the vendor-specific-option context
Contextconfigure service ies string interface string ipv4 dhcp option-82 vendor-specific-option
Treevendor-specific-option

Description

Commands in this context configure the Nokia Vendor-Specific Option (VSO) of the DHCP packet.

Introduced16.0.R1

Platforms

All

proxy-server
Synopsis Enter the proxy-server context
Contextconfigure service ies string interface string ipv4 dhcp proxy-server
Treeproxy-server
Introduced16.0.R1

Platforms

All

emulated-server string
Synopsis IP address used as the DHCP server address for the SAP
Contextconfigure service ies string interface string ipv4 dhcp proxy-server emulated-server string
Treeemulated-server

Description

This command configures the IP address which will be used as the DHCP server address in the context of the SAP. Typically, the configured address should be in the context of the subnet represented by the service.

Introduced16.0.R1

Platforms

All

lease-time
Synopsis Enter the lease-time context
Context configure service ies string interface string ipv4 dhcp proxy-server lease-time
Treelease-time
Introduced16.0.R1

Platforms

All

relay-proxy
Synopsis Enable the relay-proxy context
Contextconfigure service ies string interface string ipv4 dhcp relay-proxy
Treerelay-proxy
Introduced16.0.R1

Platforms

All

server string
Synopsis IP addresses for DHCP server requests
Contextconfigure service ies string interface string ipv4 dhcp server string
Treeserver

Description

This command configures a list of servers that this interface forwards requests to.

The operator can enter the list of servers as either IP addresses or fully qualified domain names. The operator must specify at least one server specified for DHCP relay to work. If there are multiple servers, the system forwards the request to all the servers in the list.

Max. Instances8

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

All

trusted boolean
Synopsis Relay untrusted packets
Context configure service ies string interface string ipv4 dhcp trusted boolean
Treetrusted

Description

When configured to true, the router enables the trusted mode on the interface. When enabled, the relay agent changes the existing GI address (of the request) to the ingress interface, and forwards the request.

A DHCP request that contains a GI address of 0.0.0.0 and an Option 82 field in the packet is discarded unless it arrives on a trusted circuit.

This behavior only applies if the Relay Agent Information Option action is to keep the existing information. When the Option 82 field is replaced by the relay agent, the original Option 82 information is lost, and there is no reason to enable the trusted option.

Defaultfalse
Introduced16.0.R1

Platforms

All

use-arp boolean
Synopsis Use ARP to determine the destination hardware address
Contextconfigure service ies string interface string ipv4 dhcp use-arp boolean
Treeuse-arp
Defaultfalse
Introduced16.0.R1

Platforms

All

icmp
Synopsis Enter the icmp context
Context configure service ies string interface string ipv4 icmp
Treeicmp
Introduced16.0.R1

Platforms

All

param-problem
Synopsis Enter the param-problem context
Contextconfigure service ies string interface string ipv4 icmp param-problem
Treeparam-problem

Description

Commands in this context specify the settings for ICMP Parameter Problem messages generated by the interface.

Introduced16.0.R1

Platforms

All

redirects
Synopsis Enter the redirects context
Context configure service ies string interface string ipv4 icmp redirects
Treeredirects

Description

Commands in this context configure the settings for ICMP redirect messages generated by the interface.

The system sends ICMP redirect messages to alert the sending node that a more optimal route is available on another router on the same subnetwork.

Introduced16.0.R1

Platforms

All

ttl-expired
Synopsis Enter the ttl-expired context
Context configure service ies string interface string ipv4 icmp ttl-expired
Treettl-expired

Description

Commands in this context configure the settings for ICMP TTL expired messages generated by the interface.

Introduced16.0.R1

Platforms

All

unreachables
Synopsis Enter the unreachables context
Contextconfigure service ies string interface string ipv4 icmp unreachables
Treeunreachables

Description

Commands in this context specify the settings for ICMP host and network destination unreachable messages generated by the interface.

Introduced16.0.R1

Platforms

All

neighbor-discovery
Synopsis Enter the neighbor-discovery context
Contextconfigure service ies string interface string ipv4 neighbor-discovery
Treeneighbor-discovery
Introduced16.0.R1

Platforms

All

host-route
Synopsis Enter the host-route context
Context configure service ies string interface string ipv4 neighbor-discovery host-route
Treehost-route
Introduced19.10.R1

Platforms

All

populate [route-type] keyword
Synopsis Enter the populate list instance
Contextconfigure service ies string interface string ipv4 neighbor-discovery host-route populate keyword
Treepopulate
Introduced19.10.R1

Platforms

All

route-tag number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTag value used with the host route from an ARP/ND entry
Contextconfigure service ies string interface string ipv4 neighbor-discovery host-route populate keyword route-tag number
Treeroute-tag

Description

This command specifies the route tag that is added in the route table for ARP or ND host routes. This tag can be matched on BGP VRF export and BGP peer export policies.

Range1 to 255
Introduced19.10.R1

Platforms

All

learn-unsolicited boolean
Synopsis Learn new entries from any received NA message
Contextconfigure service ies string interface string ipv4 neighbor-discovery learn-unsolicited boolean
Treelearn-unsolicited

Description

When configured to true, the router can learn neighbor entries from received unsolicited Neighbor Advertisement (NA) messages, with or without the solicited (S) flag set. The command can be enabled for global addresses, link-local addresses, or for both.

When configured to false, the router follows standard behavior for learning neighbor entries.

  • If an unsolicited NA (regardless of the S flag) is received from a neighbor that is not yet in the Neighbor Discovery (ND) cache, the NA is ignored.

  • If an NS, RS, RA, or Redirect message with a Link Layer Address (MAC) is received from a neighbor that is not yet in the ND cache, a new neighbor entry is created in the cache to store the received Link Layer MAC. The neighbor is put in the STALE state.

Defaultfalse
Introduced16.0.R1

Platforms

All

limit
Synopsis Enter the limit context
Context configure service ies string interface string ipv4 neighbor-discovery limit
Treelimit
Introduced16.0.R1

Platforms

All

local-proxy-arp boolean
Synopsis Enable local proxy ARP on interface
Context configure service ies string interface string ipv4 neighbor-discovery local-proxy-arp boolean
Treelocal-proxy-arp

Description

When configured to true, the router enables local proxy ARP on the interface.

When configured to false, the router does not respond to ARP requests for addresses on the same subnet.

Introduced16.0.R1

Platforms

All

proactive-refresh boolean
Synopsis Send a single refresh message before entry timeout
Contextconfigure service ies string interface string ipv4 neighbor-discovery proactive-refresh boolean
Treeproactive-refresh

Description

When configured to true, the router always sends a refresh message 30 seconds before the timeout of the entry (a single refresh message with no retries).

When configured to false, the router marks an entry as stale 30 seconds before age-out, and the router only sends an ARP request to refresh the entry if the IOM receives traffic that uses it. Then, the IOM asks the ARP application to send a refresh message. With ARP proactive refresh enabled, the ARP module sends a refresh message regardless of the IOM receiving traffic.

Defaultfalse
Introduced16.0.R1

Platforms

All

static-neighbor [ipv4-address] string
Synopsis Enter the static-neighbor list instance
Contextconfigure service ies string interface string ipv4 neighbor-discovery static-neighbor string
Treestatic-neighbor
Introduced16.0.R1

Platforms

All

static-neighbor-unnumbered
Synopsis Enable the static-neighbor-unnumbered context
Contextconfigure service ies string interface string ipv4 neighbor-discovery static-neighbor-unnumbered
Treestatic-neighbor-unnumbered
Introduced16.0.R1

Platforms

All

timeout number
Synopsis Timeout for an ARP entry learned on the interface
Contextconfigure service ies string interface string ipv4 neighbor-discovery timeout number
Treetimeout

Description

This command configures the minimum time an ARP entry learned on the IP interface is stored in the ARP table. ARP entries are automatically refreshed when an ARP request or gratuitous ARP is seen by an IP host. Otherwise, the ARP entry is aged from the ARP table.

Range0 to 65535
Unitsseconds
Default 14400
Introduced16.0.R1

Platforms

All

primary
Synopsis Enable the primary context
Context configure service ies string interface string ipv4 primary
Treeprimary
Introduced16.0.R1

Platforms

All

address string
Synopsis Primary IPv4 address assigned to the interface
Contextconfigure service ies string interface string ipv4 primary address string
Treeaddress

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

qos-route-lookup keyword
Synopsis IP address for QoS route lookup for ingress IP packets
Contextconfigure service ies string interface string ipv4 qos-route-lookup keyword
Treeqos-route-lookup

Description

This command specifies the IP address type used for QPPB enabled per-packet QoS handling (in terms of FC and priority). When using QPPB, routes are associated with a QoS treatment (FC and optionally priority) through either explicit configuration or the route policy. If an IPv4 or IPv6 packet arrives on an interface where the configuration of this command applies to the packet, the QoS treatment of the packet is based on the route that matched the destination IP address or the route that matched the source IP address.

See "Enabling QPPB on an IP interface" in the 7450 ESS, 7750 SR, 7950 XRS, and VSR Router Configuration Guide for more information about QPPB.

Optionsdestination, source, source-and-dest
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

secondary [address] string
Synopsis Enter the secondary list instance
Contextconfigure service ies string interface string ipv4 secondary string
Treesecondary
Introduced16.0.R1

Platforms

All

[address] string
Synopsis Secondary IPv4 address assigned to the interface
Contextconfigure service ies string interface string ipv4 secondary string
Treesecondary

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

igp-inhibit boolean
Synopsis Disable the running IGP from recognizing secondary IP
Contextconfigure service ies string interface string ipv4 secondary string igp-inhibit boolean
Treeigp-inhibit

Description

When configured to true, the running IGP does not recognize the secondary IP address as a local interface.

Defaultfalse
Introduced16.0.R1

Platforms

All

tcp-mss number
Synopsis TCP maximum segment size for the interface
Contextconfigure service ies string interface string ipv4 tcp-mss number
Treetcp-mss
Range384 to 9746
Introduced16.0.R1

Platforms

All

unnumbered
Synopsis Enter the unnumbered context
Context configure service ies string interface string ipv4 unnumbered
Treeunnumbered
Introduced16.0.R1

Platforms

All

ip-address string
Synopsis IP address of the unnumbered interface
Contextconfigure service ies string interface string ipv4 unnumbered ip-address string
Treeip-address

Notes

The following elements are part of a choice: ip-address, ip-int-name, or system.

Introduced16.0.R1

Platforms

All

ip-int-name string
Synopsis IP interface name
Context configure service ies string interface string ipv4 unnumbered ip-int-name string
Treeip-int-name
String Length1 to 32

Notes

The following elements are part of a choice: ip-address, ip-int-name, or system.

Introduced16.0.R1

Platforms

All

system
Synopsis IP interface as an unnumbered interface
Contextconfigure service ies string interface string ipv4 unnumbered system
Treesystem

Notes

The following elements are part of a choice: ip-address, ip-int-name, or system.

Introduced16.0.R1

Platforms

All

urpf-check
Synopsis Enable the urpf-check context
Context configure service ies string interface string ipv4 urpf-check
Treeurpf-check
Introduced16.0.R1

Platforms

All

mode keyword
Synopsis Unicast RPF check mode
Context configure service ies string interface string ipv4 urpf-check mode keyword
Treemode
Optionsstrict, loose, strict-no-ecmp
Defaultstrict
Introduced16.0.R1

Platforms

All

vrrp [virtual-router-id] number
Synopsis Enter the vrrp list instance
Context configure service ies string interface string ipv4 vrrp number
Treevrrp
Introduced16.0.R1

Platforms

All

[virtual-router-id] number
Synopsis Virtual Router Identifier (VRID) for the IP interface
Contextconfigure service ies string interface string ipv4 vrrp number
Treevrrp
Range1 to 255

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of VRRP
Context configure service ies string interface string ipv4 vrrp number admin-state keyword
Treeadmin-state

Description

The command determines the administrative state of non-owner virtual router instances.

Non-owner virtual router instances can be administratively disabled. This allows the termination of VRRP participation in the virtual router and stops all routing and other access capabilities with regards to the virtual router IP addresses. Disabling the virtual router instance provides a mechanism to maintain the virtual routers without causing false backup or master state changes.

When disabled, no VRRP advertisement messages are generated and all received VRRP advertisement messages are silently discarded with no processing.

Whenever the administrative or operational state of a virtual router instance transitions, a log message is generated.

An owner virtual router context does not use this command. To administratively disable an owner virtual router instance, use the admin-state command within the parent IP interface node which administratively disables the IP interface.

Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

authentication-key string
Synopsis Password for simple text authentication
Contextconfigure service ies string interface string ipv4 vrrp number authentication-key string
Treeauthentication-key

Description

This command optionally assigns a simple text password authentication key to generate master VRRP advertisement messages and validate received VRRP advertisement messages.

If this command is re-executed with a different password key defined, the new key immediately replaces the old key. This command may be executed at any time. 

String Length1 to 38
Introduced16.0.R1

Platforms

All

backup string
Synopsis Virtual router IP addresses for the interface
Contextconfigure service ies string interface string ipv4 vrrp number backup string
Treebackup

Description

This command associates virtual router IP addresses with those of the parental IP interface.

This command has two different functions based on whether it is being executed on an owner or non-owner virtual router instance.

Non-owner virtual router instances create a routable IP interface address that is operationally dependent on the virtual router instance mode (master or backup). This command, when executed on an owner virtual router instance, does not create a routable IP interface address; it simply defines the existing IP addresses of the parental IP interface that are advertised by the virtual router instance.

For owner virtual router instances, this command defines the IP addresses that are advertised within VRRP advertisement messages. This communicates the IP addresses that the master is advertising to backup virtual routers receiving the messages. The specified unicast-ipv4-address must be equal to one of the existing IP addresses in the parental IP interface (primary or secondary) or this command fails.

See "Owner and non-owner VRRP" in the 7450 ESS, 7750 SR, 7950 XRS, and VSR Router Configuration Guide for more information about owner and non-owner virtual router instances.

Max. Instances16
Introduced16.0.R1

Platforms

All

bfd-liveness
Synopsis Enable the bfd-liveness context
Contextconfigure service ies string interface string ipv4 vrrp number bfd-liveness
Treebfd-liveness
Introduced16.0.R1

Platforms

All

dest-ip string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDestination IP address to use for BFD session
Contextconfigure service ies string interface string ipv4 vrrp number bfd-liveness dest-ip string
Treedest-ip

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

interface-name string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisName of the interface running BFD
Contextconfigure service ies string interface string ipv4 vrrp number bfd-liveness interface-name string
Treeinterface-name
String Length1 to 32

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

service-name string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisAdministrative service name
Contextconfigure service ies string interface string ipv4 vrrp number bfd-liveness service-name string
Treeservice-name
String Length1 to 64
Introduced16.0.R1

Platforms

All

mac string
Synopsis Virtual MAC address to use in ARP responses
Contextconfigure service ies string interface string ipv4 vrrp number mac string
Treemac

Description

This command sets an explicit MAC address for the virtual router instance that overrides the VRRP default derived from the VRID.

Changing the default MAC address is useful when an existing HSRP or other non-VRRP default MAC is in use by the IP hosts that use the virtual router IP address. Many hosts do not monitor unessential ARPs and continue to use the cached non-VRRP MAC address after the virtual router becomes master of the host’s gateway address.

Additionally, this command sets the MAC address used in ARP responses when the virtual router instance is master. Routing of IP packets with unicast-mac-address as the destination MAC is also enabled. The MAC must be the same for all virtual routers participating as a virtual router or indeterminate connectivity by the attached IP hosts results. All VRRP advertisement messages are transmitted with unicast-mac-address as the source MAC.

An operator can execute this command at any time and it takes effect immediately. When the virtual router MAC on a master virtual router instance changes, a gratuitous ARP is immediately sent with a VRRP advertisement message. If the virtual router instance is disabled or operating as a backup, the gratuitous ARP and VRRP advertisement messages are not sent.

Introduced16.0.R1

Platforms

All

master-int-inherit boolean
Synopsis Allow master instance to dictate the master down timer
Contextconfigure service ies string interface string ipv4 vrrp number master-int-inherit boolean
Treemaster-int-inherit

Description

When configured to true, the virtual router instance inherits the advertisement interval timer of the master VRRP router, which backup routers use to calculate the master down timer.

When configured to false, the locally configured message interval must match the master's VRRP advertisement message advertisement interval field value or the message is discarded.

Introduced16.0.R1

Platforms

All

message-interval number
Synopsis Interval for sending VRRP advertisement messages
Contextconfigure service ies string interface string ipv4 vrrp number message-interval number
Treemessage-interval

Description

This command configures the administrative advertisement message timer used by the master virtual router instance to send VRRP advertisement messages. The backup master down timer is derived from the value configured using this command.

The usage of this command varies for non-owner virtual router instances, depending on the state of the virtual router (master or backup) and the state of the master-int-inherit command:

  • When a non-owner is operating as master for the virtual router, the system uses the configured value of this command as the operational advertisement timer, similar to an owner virtual router instance. The master-int-inherit command has no effect when operating as master.

  • When a non-owner is in the backup state with master-int-inherit disabled, the system uses the configured value of this command to match the incoming advertisement interval field of the VRRP advertisement message. If the locally configured message interval does not match the advertisement interval field, the system discards the VRRP advertisement.

  • When a non-owner is in the backup state with master-int-inherit enabled, the configured value of this command is ignored. The master down timer is indirectly derived from the advertisement interval field value of the incoming VRRP advertisement message.

Range1 to 2559
Unitsdeciseconds
Default 10
Introduced16.0.R1

Platforms

All

monitor-oper-group reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVRRP instance to follow a specified operational group
Contextconfigure service ies string interface string ipv4 vrrp number monitor-oper-group reference
Treemonitor-oper-group

Description

This command configures VRRP to associate with an operational group. When associated, VRRP notifies the operational group of its state changes so that other protocols can monitor it to provide a redundancy mechanism. When VRRP is the master router, the operational group is up and the operational group is down for all other VRRP states.

Reference

configure service oper-group string

Introduced22.2.R1

Platforms

All

ntp-reply boolean
Synopsis Allow processing of NTP requests
Context configure service ies string interface string ipv4 vrrp number ntp-reply boolean
Treentp-reply

Description

When configured to true, the router redirects NTP requests to the VRRP virtual IP address. This behavior only applies to the router acting as the master VRRP router.

When configured to false, the router does not process NTP requests.

Defaultfalse
Introduced20.2.R1

Platforms

All

oper-group reference
Synopsis Operational group name associated with the VRRP
Contextconfigure service ies string interface string ipv4 vrrp number oper-group reference
Treeoper-group

Description

This command configures an operational group to associate with the VRRP. When associated, VRRP notifies the operational group of its state changes so that other protocols can monitor it to provide a redundancy mechanism. When VRRP is the master router (MR), the operational group is up. The operational group is down for all other VRRP states.

Reference

configure service oper-group string

Introduced16.0.R1

Platforms

All

owner boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDesignate the virtual router instance as owner
Contextconfigure service ies string interface string ipv4 vrrp number owner boolean
Treeowner

Description

When configured to true, the router designates this virtual router instance as the owner of the virtual router IP addresses. Therefore, this virtual router becomes responsible for forwarding packets sent to the virtual router IP addresses. The owner also assumes the role of master virtual router.

When configured to false, this virtual router instance is designated as a non-owner.

Defaultfalse
Introduced16.0.R1

Platforms

All

passive boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSuppress the processing of VRRP advertisement messages
Contextconfigure service ies string interface string ipv4 vrrp number passive boolean
Treepassive

Description

When configured to true, the router identifies this virtual router instance as passive; and therefore the owner of the virtual router IP addresses. A passive virtual router instance does not transmit or receive VRRP advertisement messages and is always in either the master state (if the interface is operationally up) or the init state (if the interface is operationally down).

When configured to false, this virtual router instance is not identified as passive, meaning that it transmits and receives VRRP advertisement messages. 

Defaultfalse
Introduced16.0.R1

Platforms

All

ping-reply boolean
Synopsis Allow non-owner master to reply to ICMP echo requests
Contextconfigure service ies string interface string ipv4 vrrp number ping-reply boolean
Treeping-reply

Description

When configured to true, the router allows the non-owner master to reply to ICMP echo requests directed at the IP addresses of the virtual router instance. Any routed interface can receive the ping request. Ping must not have been disabled at the management security level (either on the parental IP interface or on the Ping source host address).

When configured to false, ICMP echo requests sent to non-owner master virtual IP addresses are silently discarded.

Non-owner backup virtual routers never respond to ICMP echo requests, regardless of the configuration of this command.

Defaultfalse
Introduced16.0.R1

Platforms

All

policy reference
Synopsis VRRP priority control policy
Context configure service ies string interface string ipv4 vrrp number policy reference
Treepolicy

Description

This command configures a VRRP priority control policy to associate with the virtual router instance.

VRRP priority control policies can override or adjust the base priority value of the virtual router instance, depending on events or conditions within the chassis.

An operator can associate a policy with more than one virtual router instance. The priority events within the policy either override or diminish the base priority set with the priority command. As priority events clear in the policy, the in-use priority can eventually be restored to the base priority value.

For non-owner virtual router instances, if this command is not executed, the base priority is used as the in-use priority.

Reference

configure vrrp policy number

Introduced16.0.R1

Platforms

All

preempt boolean
Synopsis Allow the VRRP to override an existing non-owner master
Contextconfigure service ies string interface string ipv4 vrrp number preempt boolean
Treepreempt

Description

When configured to true, this virtual router instance overrides any non-owner master with an in-use message priority value less than the in-use priority value of this virtual router.

When configured to false, this virtual router only becomes master if the master down timer expires before a VRRP advertisement message is received from another virtual router.

Defaulttrue
Introduced16.0.R1

Platforms

All

priority number
Synopsis Base priority for the VRRP
Context configure service ies string interface string ipv4 vrrp number priority number
Treepriority

Description

This command configures the base router priority for the virtual router instance, which defines the selection order of the virtual router in the master election process.

The in-use priority is derived from the base priority. However, the in-use priority is modified by optional VRRP priority control policies. An operator can use VRRP priority control policies to either override or adjust the base priority value depending on events or conditions within the chassis.

Range1 to 255
Introduced16.0.R1

Platforms

All

ssh-reply boolean
Synopsis Allow the non-owner master to reply to SSH requests
Contextconfigure service ies string interface string ipv4 vrrp number ssh-reply boolean
Treessh-reply

Description

When configured to true, the router allows the non-owner master to reply to SSH requests directed at the IP addresses of the virtual router instance. Any routed interface can receive the SSH request. SSH cannot be disabled at the management security level (either on the parental IP interface or on the SSH source host address).

When configure to false, SSH requests to non-owner master virtual IP addresses are silently discarded.

Defaultfalse
Introduced16.0.R1

Platforms

All

standby-forwarding boolean
Synopsis Allow standby router to forward traffic
Contextconfigure service ies string interface string ipv4 vrrp number standby-forwarding boolean
Treestandby-forwarding

Description

When configured to true, the standby router forwards all traffic.

When configured to false, the standby router cannot forward traffic sent to the MAC address of the virtual router. However, the standby router still forwards traffic sent to its own MAC address.

Defaultfalse
Introduced16.0.R1

Platforms

All

telnet-reply boolean
Synopsis Allow non-owner master to reply to Telnet requests
Contextconfigure service ies string interface string ipv4 vrrp number telnet-reply boolean
Treetelnet-reply

Description

When configured to true, the router allows the non-owner master to reply to Telnet requests directed at the IP addresses of the virtual router instance. Any routed interface can receive Telnet requests. Telnet cannot be disabled at the management security level (either on the parental IP interface or on the Telnet source host address).

When configured to false, the router silently discards Telnet requests sent to non-owner master virtual IP addresses.

Defaultfalse
Introduced16.0.R1

Platforms

All

traceroute-reply boolean
Synopsis Allow non-owner master to reply to traceroute requests
Contextconfigure service ies string interface string ipv4 vrrp number traceroute-reply boolean
Treetraceroute-reply

Description

When configured to true, the router allows a non-owner master to reply to traceroute requests directed to the IP addresses of the virtual router instance.

When configured to false, the router silently discards traceroute requests sent to non-owner master virtual IP addresses.

Traceroute must not have been disabled at the management security level (either on the parental IP interface or the source host address).

Defaultfalse
Introduced16.0.R1

Platforms

All

ipv6
Synopsis Enable the ipv6 context
Context configure service ies string interface string ipv6
Treeipv6
Introduced16.0.R1

Platforms

All

address [ipv6-address] string
Synopsis Enter the address list instance
Contextconfigure service ies string interface string ipv6 address string
Treeaddress
Introduced16.0.R1

Platforms

All

[ipv6-address] string
Synopsis IPv6 address assigned to the interface
Contextconfigure service ies string interface string ipv6 address string
Treeaddress

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

duplicate-address-detection boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEnable Duplicate Address Detection
Contextconfigure service ies string interface string ipv6 address string duplicate-address-detection boolean
Treeduplicate-address-detection

Description

When configured to true, the router enables Duplicate Address Detection (DAD).

When configured to false, the router disables DAD and sets the address to preferred, even if there is a duplicated address.

Defaulttrue
Introduced16.0.R1

Platforms

All

eui-64 boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisForm IPv6 address from prefix and 64-bit interface ID
Contextconfigure service ies string interface string ipv6 address string eui-64 boolean
Treeeui-64

Description

When configured to true, the router forms a complete IPv6 address from the supplied prefix and 64-bit interface identifier. The 64-bit interface identifier is derived from the MAC address on Ethernet interfaces. For interfaces without a MAC address, for example POS interfaces, use the base MAC address of the chassis.

Defaultfalse
Introduced16.0.R1

Platforms

All

primary-preference number
Synopsis Index assigned to the IPv6 address of the interface
Contextconfigure service ies string interface string ipv6 address string primary-preference number
Treeprimary-preference

Description

This command assigns a primary preference index to an IPv6 address of the interface to enforce the order in which the address is used by control plane protocols and applications that require a fixed address of the interface, such as LDP and Segment Routing. In cases where a fixed address is required when originating packets from the interface, the IPv6 address with the lowest primary preference index is selected. If the selected address is removed, the next IPv6 address with the next lowest primary preference index is selected.

If this index is not specified for the IPv6 address, the system assigns the next available index value to the address. The address index space is unique across all addresses of a given interface.

Range1 to 4294967295
Introduced16.0.R1

Platforms

All

bfd
Synopsis Enter the bfd context
Context configure service ies string interface string ipv6 bfd
Treebfd
Introduced16.0.R1

Platforms

All

multiplier number
Synopsis Number of consecutive BFD messages missed from the peer
Contextconfigure service ies string interface string ipv6 bfd multiplier number
Treemultiplier

Description

This command configures the number of missed messages before the BFD session state is changed to down and the upper-level protocol is notified of the fault. A multiplier of less than 3 should not be used in production environments. 

Range1 to 20
Default3
Introduced 16.0.R1

Platforms

All

receive number
Synopsis BFD receive interval over this interface
Contextconfigure service ies string interface string ipv6 bfd receive number
Treereceive

Description

This command specifies the receive interval for the BFD session.

On the 7750 SR, this command can only be configured to a value less than 100 when the type command is configured to cpm-np.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 16.0.R1

Platforms

All

transmit-interval number
Synopsis BFD transmit interval over this interface
Contextconfigure service ies string interface string ipv6 bfd transmit-interval number
Treetransmit-interval

Description

This command configures the transmit intervals.

On the 7750 SR, this command can only be configured to a value less than 100 when the type command is configured to cpm-np.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 16.0.R1

Platforms

All

type keyword
Synopsis Local termination point for the BFD session
Contextconfigure service ies string interface string ipv6 bfd type keyword
Treetype

Description

This command sets the local termination point for the BFD session to allow for fast timers down to 10 ms granularity.

The options to specify where the BFD session runs are:

  • auto (default) – the system chooses and uses the line card CPU only for single-hop BFD sessions with timer intervals equal to or greater than 100ms. All others are placed on the cpm-np.

  • cpm-np – BFD session runs on the FP complex associated with the CPM. This is either the FP on the CPM or the one elected on smaller systems. 

  • fp – BFD session runs on the line card CPU. This option can only be used for single-hop BFD sessions with timers equal to or greater than 100ms.  

Optionscpm-np, auto, fp
Defaultauto
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

dhcp6
Synopsis Enter the dhcp6 context
Context configure service ies string interface string ipv6 dhcp6
Treedhcp6
Introduced16.0.R1

Platforms

All

relay
Synopsis Enter the relay context
Context configure service ies string interface string ipv6 dhcp6 relay
Treerelay
Introduced16.0.R1

Platforms

All

lease-populate
Synopsis Enter the lease-populate context
Contextconfigure service ies string interface string ipv6 dhcp6 relay lease-populate
Treelease-populate
Introduced16.0.R1

Platforms

All

route-populate
Synopsis Enter the route-populate context
Contextconfigure service ies string interface string ipv6 dhcp6 relay lease-populate route-populate
Treeroute-populate
Introduced16.0.R1

Platforms

All

option
Synopsis Enter the option context
Context configure service ies string interface string ipv6 dhcp6 relay option
Treeoption
Introduced16.0.R1

Platforms

All

interface-id
Synopsis Enter the interface-id context
Contextconfigure service ies string interface string ipv6 dhcp6 relay option interface-id
Treeinterface-id
Introduced16.0.R1

Platforms

All

string string
Synopsis String for interface ID option in DHCPv6 relay packet
Contextconfigure service ies string interface string ipv6 dhcp6 relay option interface-id string string
Treestring
String Length1 to 80

Notes

The following elements are part of a choice: ascii-tuple, if-index, sap-id, or string.

Introduced16.0.R1

Platforms

All

server string
Synopsis DHCPv6 server to which the DHCPv6 requests are forwarded
Contextconfigure service ies string interface string ipv6 dhcp6 relay server string
Treeserver
Max. Instances8

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

All

server
Synopsis Enter the server context
Context configure service ies string interface string ipv6 dhcp6 server
Treeserver
Introduced16.0.R1

Platforms

All

prefix-delegation
Synopsis Enter the prefix-delegation context
Contextconfigure service ies string interface string ipv6 dhcp6 server prefix-delegation
Treeprefix-delegation

Description

Commands in this context configure the options for delegating a long-lived prefix from a delegating router to a requesting router, where the delegating router does not require knowledge about the link topology in the network to which the prefixes are assigned.

Introduced16.0.R1

Platforms

All

prefix [ipv6-prefix] string
Synopsis Enter the prefix list instance
Contextconfigure service ies string interface string ipv6 dhcp6 server prefix-delegation prefix string
Treeprefix

Description

Commands in this context configure the IPv6 prefix that is delegated by the system.

Introduced16.0.R1

Platforms

All

client-id
Synopsis Enter the client-id context
Context configure service ies string interface string ipv6 dhcp6 server prefix-delegation prefix string client-id
Treeclient-id
Introduced16.0.R1

Platforms

All

iaid number
Synopsis IAID from the requesting router to match
Contextconfigure service ies string interface string ipv6 dhcp6 server prefix-delegation prefix string client-id iaid number
Treeiaid

Description

This command configures the Identity Association ID (IAID) associated with a prefix delegation entry and must match the IAID sent by the requesting router for the prefix delegation to succeed.

Range1 to 4294967295
Introduced16.0.R1

Platforms

All

preferred-lifetime (number | keyword)
Synopsis Preferred lifetime of the prefix
Context configure service ies string interface string ipv6 dhcp6 server prefix-delegation prefix string preferred-lifetime (number | keyword)
Treepreferred-lifetime

Description

This command configures the preferred lifetime of the prefix. The value cannot be greater than the valid lifetime value.

Range1 to 4294967294
Unitsseconds
Options infinite
Default604800
Introduced 16.0.R1

Platforms

All

icmp6
Synopsis Enter the icmp6 context
Context configure service ies string interface string ipv6 icmp6
Treeicmp6
Introduced16.0.R1

Platforms

All

packet-too-big
Synopsis Enter the packet-too-big context
Contextconfigure service ies string interface string ipv6 icmp6 packet-too-big
Treepacket-too-big

Description

Commands in this context configure limiting the number of ICMPv6 Packet Too Big messages.

Introduced16.0.R1

Platforms

All

param-problem
Synopsis Enter the param-problem context
Contextconfigure service ies string interface string ipv6 icmp6 param-problem
Treeparam-problem
Introduced16.0.R1

Platforms

All

redirects
Synopsis Enter the redirects context
Context configure service ies string interface string ipv6 icmp6 redirects
Treeredirects
Introduced16.0.R1

Platforms

All

time-exceeded
Synopsis Enter the time-exceeded context
Contextconfigure service ies string interface string ipv6 icmp6 time-exceeded
Treetime-exceeded
Introduced16.0.R1

Platforms

All

unreachables
Synopsis Enter the unreachables context
Contextconfigure service ies string interface string ipv6 icmp6 unreachables
Treeunreachables
Introduced16.0.R1

Platforms

All

link-local-address
Synopsis Enter the link-local-address context
Contextconfigure service ies string interface string ipv6 link-local-address
Treelink-local-address
Introduced16.0.R1

Platforms

All

duplicate-address-detection boolean
Synopsis Enable Duplicate Address Detection
Context configure service ies string interface string ipv6 link-local-address duplicate-address-detection boolean
Treeduplicate-address-detection

Description

When configured to true, the router enables Duplicate Address Detection (DAD) on the interface.

When configured to false, the router disables DAD and sets the address to preferred, even if there is a duplicated address.

Defaulttrue
Introduced16.0.R1

Platforms

All

neighbor-discovery
Synopsis Enter the neighbor-discovery context
Contextconfigure service ies string interface string ipv6 neighbor-discovery
Treeneighbor-discovery
Introduced16.0.R1

Platforms

All

host-route
Synopsis Enter the host-route context
Context configure service ies string interface string ipv6 neighbor-discovery host-route
Treehost-route
Introduced20.2.R1

Platforms

All

populate [route-type] keyword
Synopsis Enter the populate list instance
Contextconfigure service ies string interface string ipv6 neighbor-discovery host-route populate keyword
Treepopulate
Introduced20.2.R1

Platforms

All

route-tag number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTag value used with the host route from an ARP/ND entry
Contextconfigure service ies string interface string ipv6 neighbor-discovery host-route populate keyword route-tag number
Treeroute-tag

Description

This command specifies the route tag that is added in the route table for ARP or ND host routes. This tag can be matched on BGP VRF export and BGP peer export policies.

Range1 to 255
Introduced20.2.R1

Platforms

All

learn-unsolicited keyword
Synopsis Type of entries learned from unsolicited NA messages
Contextconfigure service ies string interface string ipv6 neighbor-discovery learn-unsolicited keyword
Treelearn-unsolicited

Description

This command enables the ability to learn neighbor entries out of received unsolicited Neighbor Advertisement (NA) messages, with or without the solicited flag set.

When unconfigured, the router follows standard RFC 4861 behavior for learning of neighbor entries. The neighbor is put in the stale state. This is the standard RFC behavior.

Optionsglobal, link-local, both
Introduced16.0.R1

Platforms

All

limit
Synopsis Enter the limit context
Context configure service ies string interface string ipv6 neighbor-discovery limit
Treelimit
Introduced16.0.R1

Platforms

All

log-only boolean
Synopsis Generate log entries when limit is reached
Contextconfigure service ies string interface string ipv6 neighbor-discovery limit log-only boolean
Treelog-only

Description

When configured to true, the router sends the warning message at the specified threshold percentage or upon exceeding the specified limit. Entries that exceed the limit are learned.

When configured to false, the router does not send the warning message.

Defaultfalse
Introduced16.0.R1

Platforms

All

max-entries number
Synopsis Maximum number of entries learned on an IP interface
Contextconfigure service ies string interface string ipv6 neighbor-discovery limit max-entries number
Treemax-entries

Description

This command configures the maximum number of entries that can be learned on an IP interface.

When unconfigured, no maximum limit is imposed.

Range0 to 102400
Introduced16.0.R1

Platforms

All

local-proxy-nd boolean
Synopsis Enable local proxy neighbor discovery on the interface
Contextconfigure service ies string interface string ipv6 neighbor-discovery local-proxy-nd boolean
Treelocal-proxy-nd

Description

When configured to true, the router enables local proxy neighbor discovery on the interface and replies to neighbor solicitation requests when both the hosts are on the same subnet. In this case, ICMP redirects are disabled.

When configured to false, the router disables local proxy neighbor discovery on the interface and does not reply to neighbor solicitation requests if both the hosts are on the same subnet.

Defaultfalse
Introduced16.0.R1

Platforms

All

proactive-refresh keyword
Synopsis Proactive refresh of neighbor entries
Contextconfigure service ies string interface string ipv6 neighbor-discovery proactive-refresh keyword
Treeproactive-refresh

Description

This command enables a proactive refresh of the neighbor entries. After the stale timer expires, the router sends an NUD message to the host (regardless of the existence of traffic to the IP address on the IOM), so the entry can be refreshed or removed.

Optionsglobal, link-local, both
Introduced16.0.R1

Platforms

All

secure-nd
Synopsis Enter the secure-nd context
Context configure service ies string interface string ipv6 neighbor-discovery secure-nd
Treesecure-nd
Introduced16.0.R1

Platforms

All

allow-unsecured-msgs boolean
Synopsis Accept unsecured messages
Context configure service ies string interface string ipv6 neighbor-discovery secure-nd allow-unsecured-msgs boolean
Treeallow-unsecured-msgs

Description

When configured to true, the router accepts unsecured messages. When Secure Neighbor Discovery (SeND) is enabled, only secure messages are accepted.

When configured to false, the router disables the acceptance of unsecured messages.

Defaulttrue
Introduced16.0.R1

Platforms

All

static-neighbor [ipv6-address] string
Synopsis Enter the static-neighbor list instance
Contextconfigure service ies string interface string ipv6 neighbor-discovery static-neighbor string
Treestatic-neighbor
Introduced16.0.R1

Platforms

All

qos-route-lookup keyword
Synopsis IP address for QoS route lookup for ingress IP packets
Contextconfigure service ies string interface string ipv6 qos-route-lookup keyword
Treeqos-route-lookup

Description

This command specifies the IP address type used for QPPB enabled per-packet QoS handling (in terms of FC and priority). When using QPPB, routes are associated with a QoS treatment (FC and optionally priority) through either explicit configuration or the route policy. If an IPv4 or IPv6 packet arrives on an interface where the configuration of this command applies to the packet, the QoS treatment of the packet is based on the route that matched the destination IP address or the route that matched the source IP address.

See "Enabling QPPB on an IP interface" in the 7450 ESS, 7750 SR, 7950 XRS, and VSR Router Configuration Guide for more information about QPPB.

Optionsdestination, source, source-and-dest
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

tcp-mss number
Synopsis TCP maximum segment size for the interface
Contextconfigure service ies string interface string ipv6 tcp-mss number
Treetcp-mss
Range1220 to 9726
Introduced16.0.R1

Platforms

All

urpf-check
Synopsis Enable the urpf-check context
Context configure service ies string interface string ipv6 urpf-check
Treeurpf-check
Introduced16.0.R1

Platforms

All

mode keyword
Synopsis Unicast RPF check mode
Context configure service ies string interface string ipv6 urpf-check mode keyword
Treemode
Optionsstrict, loose, strict-no-ecmp
Defaultstrict
Introduced16.0.R1

Platforms

All

vrrp [virtual-router-id] number
Synopsis Enter the vrrp list instance
Context configure service ies string interface string ipv6 vrrp number
Treevrrp
Max. Instances4
Introduced16.0.R1

Platforms

All

[virtual-router-id] number
Synopsis Virtual Router Identifier (VRID) for the IP interface
Contextconfigure service ies string interface string ipv6 vrrp number
Treevrrp
Range1 to 255

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of VRRP
Context configure service ies string interface string ipv6 vrrp number admin-state keyword
Treeadmin-state

Description

The command determines the administrative state of non-owner virtual router instances.

Non-owner virtual router instances can be administratively disabled. This allows the termination of VRRP participation in the virtual router and stops all routing and other access capabilities with regards to the virtual router IP addresses. Disabling the virtual router instance provides a mechanism to maintain the virtual routers without causing false backup or master state changes.

When disabled, no VRRP advertisement messages are generated and all received VRRP advertisement messages are silently discarded with no processing.

Whenever the administrative or operational state of a virtual router instance transitions, a log message is generated.

An owner virtual router context does not use this command. To administratively disable an owner virtual router instance, use the admin-state command within the parent IP interface node which administratively disables the IP interface.

Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

backup string
Synopsis Virtual router IP addresses for the interface
Contextconfigure service ies string interface string ipv6 vrrp number backup string
Treebackup

Description

This command associates router IPv6 virtual router IP addresses with those of the parental IP interface.

This command has two different functions based on whether it is being executed on an owner or non-owner virtual router instance.

Non-owner virtual router instance create a routable IP interface address that is operationally dependent on the virtual router instance mode (master or backup). This command, when executed on an owner virtual router instance, does not create a routable IP interface address; it simply defines the existing IP addresses of the parental IP interface that are advertised by the virtual router instance.

For owner virtual router instances, this command defines the IP addresses that are advertised within VRRP advertisement messages. This communicates the IP addresses that the master is representing to backup virtual routers receiving the messages. The specified IPv6 address must be equal to one of the existing parental IP addresses in the parental IP interface (primary or secondary) or this command fails.

See "Owner and non-owner VRRP" in the 7450 ESS, 7750 SR, 7950 XRS, and VSR Router Configuration Guide for more information about owner and non-owner virtual router instances.

Max. Instances4
Introduced16.0.R1

Platforms

All

bfd-liveness
Synopsis Enable the bfd-liveness context
Contextconfigure service ies string interface string ipv6 vrrp number bfd-liveness
Treebfd-liveness
Introduced16.0.R1

Platforms

All

dest-ip (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDestination address for the BFD session
Contextconfigure service ies string interface string ipv6 vrrp number bfd-liveness dest-ip (ipv4-address-no-zone | ipv6-address-no-zone)
Treedest-ip

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

interface-name string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisName of the interface running BFD
Contextconfigure service ies string interface string ipv6 vrrp number bfd-liveness interface-name string
Treeinterface-name
String Length1 to 32

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

service-name string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisAdministrative service name
Contextconfigure service ies string interface string ipv6 vrrp number bfd-liveness service-name string
Treeservice-name
String Length1 to 64
Introduced16.0.R1

Platforms

All

mac string
Synopsis Virtual MAC address to use in ARP responses
Contextconfigure service ies string interface string ipv6 vrrp number mac string
Treemac

Description

This command sets an explicit MAC address for the virtual router instance that overrides the VRRP default derived from the VRID.

Changing the default MAC address is useful when an existing HSRP or other non-VRRP default MAC is in use by the IP hosts that use the virtual router IP address. Many hosts do not monitor unessential ARPs and continue to use the cached non-VRRP MAC address after the virtual router becomes master of the host’s gateway address.

Additionally, this command sets the MAC address used in ARP responses when the virtual router instance is master. Routing of IP packets with unicast-mac-address as the destination MAC is also enabled. The MAC must be the same for all virtual routers participating as a virtual router or indeterminate connectivity by the attached IP hosts results. All VRRP advertisement messages are transmitted with unicast-mac-address as the source MAC.

An operator can execute this command at any time and it takes effect immediately. When the virtual router MAC on a master virtual router instance changes, a gratuitous ARP is immediately sent with a VRRP advertisement message. If the virtual router instance is disabled or operating as a backup, the gratuitous ARP and VRRP advertisement messages are not sent.

Introduced16.0.R1

Platforms

All

master-int-inherit boolean
Synopsis Allow master instance to dictate the master down timer
Contextconfigure service ies string interface string ipv6 vrrp number master-int-inherit boolean
Treemaster-int-inherit

Description

When configured to true, the virtual router instance inherits the advertisement interval timer of the master VRRP router, which backup routers use to calculate the master down timer.

When configured to false, the locally configured message interval must match the master's VRRP advertisement message advertisement interval field value or the message is discarded.

Introduced16.0.R1

Platforms

All

message-interval number
Synopsis Interval for sending VRRP advertisement messages
Contextconfigure service ies string interface string ipv6 vrrp number message-interval number
Treemessage-interval

Description

This command configures the administrative advertisement message timer used by the master virtual router instance to send VRRP advertisement messages. The backup master down timer is derived from the value configured using this command.

The use of this command varies for non-owner virtual router instances, depending on the state of the virtual router (master or backup) and the state of the master-int-inherit command:

  • When a non-owner is operating as master for the virtual router, the system uses the configured value of this command as the operational advertisement timer, similar to an owner virtual router instance. The master-int-inherit command has no effect when operating as the master.

  • When a non-owner is in the backup state with master-int-inherit disabled, the system uses the configured value of this command to match the incoming advertisement interval field of the VRRP advertisement message. If the locally configured message interval does not match the advertisement interval field, the system discards the VRRP advertisement.

  • When a non-owner is in the backup state with master-int-inherit enabled, the configured value of this command is ignored. The master down timer is indirectly derived from the advertisement interval field value of the incoming VRRP advertisement message.

Range10 to 4095
Unitscentiseconds
Default 100
Introduced16.0.R1

Platforms

All

monitor-oper-group reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVRRP instance to follow a specified operational group
Contextconfigure service ies string interface string ipv6 vrrp number monitor-oper-group reference
Treemonitor-oper-group

Description

This command configures VRRP to associate with an operational group. When associated, VRRP notifies the operational group of its state changes so that other protocols can monitor it to provide a redundancy mechanism. When VRRP is the master router, the operational group is up and the operational group is down for all other VRRP states.

Reference

configure service oper-group string

Introduced22.2.R1

Platforms

All

ntp-reply boolean
Synopsis Allow processing of NTP requests
Context configure service ies string interface string ipv6 vrrp number ntp-reply boolean
Treentp-reply

Description

When configured to true, the router redirects NTP requests to the VRRP virtual IP address. This behavior only applies to the router acting as the master VRRP router.

When configured to false, the router does not process NTP requests.

Defaultfalse
Introduced20.2.R1

Platforms

All

oper-group reference
Synopsis Operational group name associated with the VRRP
Contextconfigure service ies string interface string ipv6 vrrp number oper-group reference
Treeoper-group

Description

This command configures an operational group to associate with the VRRP. When associated, VRRP notifies the operational group of its state changes so that other protocols can monitor it to provide a redundancy mechanism. When VRRP is the master router (MR), the operational group is up. The operational group is down for all other VRRP states.

Reference

configure service oper-group string

Introduced16.0.R1

Platforms

All

owner boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDesignate the virtual router instance as owner
Contextconfigure service ies string interface string ipv6 vrrp number owner boolean
Treeowner

Description

When configured to true, the router designates this virtual router instance as the owner of the virtual router IP addresses. Therefore, this virtual router becomes responsible for forwarding packets sent to the virtual router IP addresses. The owner also assumes the role of master virtual router.

When configured to false, this virtual router instance is designated as a non-owner.

Defaultfalse
Introduced16.0.R1

Platforms

All

passive boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSuppress the processing of VRRP advertisement messages
Contextconfigure service ies string interface string ipv6 vrrp number passive boolean
Treepassive

Description

When configured to true, the router identifies this virtual router instance as passive; and therefore the owner of the virtual router IP addresses. A passive virtual router instance does not transmit or receive VRRP advertisement messages and is always in either the master state (if the interface is operationally up) or the init state (if the interface is operationally down).

When configured to false, this virtual router instance is not identified as passive, meaning that it transmits and receives VRRP advertisement messages. 

Defaultfalse
Introduced16.0.R1

Platforms

All

ping-reply boolean
Synopsis Allow non-owner master to reply to ICMP echo requests
Contextconfigure service ies string interface string ipv6 vrrp number ping-reply boolean
Treeping-reply

Description

When configured to true, the router allows the non-owner master to reply to ICMP echo requests directed at the IP addresses of the virtual router instance. Any routed interface can receive the ping request. Ping must not have been disabled at the management security level (either on the parental IP interface or on the Ping source host address).

When configured to false, ICMP echo requests sent to non-owner master virtual IP addresses are silently discarded.

Non-owner backup virtual routers never respond to ICMP echo requests, regardless of the configuration of this command.

Defaultfalse
Introduced16.0.R1

Platforms

All

policy reference
Synopsis VRRP priority control policy
Context configure service ies string interface string ipv6 vrrp number policy reference
Treepolicy

Description

This command configures a VRRP priority control policy to associate with the virtual router instance.

VRRP priority control policies can override or adjust the base priority value of the virtual router instance, depending on events or conditions within the chassis.

An operator can associate a policy with more than one virtual router instance. The priority events within the policy either override or diminish the base priority set with the priority command. As priority events clear in the policy, the in-use priority can eventually be restored to the base priority value.

For non-owner virtual router instances, if this command is not executed, the base priority is used as the in-use priority.

Reference

configure vrrp policy number

Introduced16.0.R1

Platforms

All

preempt boolean
Synopsis Allow the VRRP to override an existing non-owner master
Contextconfigure service ies string interface string ipv6 vrrp number preempt boolean
Treepreempt

Description

When configured to true, this virtual router instance overrides any non-owner master with an in-use message priority value less than the in-use priority value of this virtual router.

When configured to false, this virtual router only becomes master if the master down timer expires before a VRRP advertisement message is received from another virtual router.

Defaulttrue
Introduced16.0.R1

Platforms

All

priority number
Synopsis Base priority for the VRRP
Context configure service ies string interface string ipv6 vrrp number priority number
Treepriority

Description

This command configures the base router priority for the virtual router instance, which defines the selection order of the virtual router in the master election process.

The in-use priority is derived from the base priority. However, the in-use priority is modified by optional VRRP priority control policies. An operator can use VRRP priority control policies to either override or adjust the base priority value depending on events or conditions within the chassis.

Range1 to 255
Introduced16.0.R1

Platforms

All

standby-forwarding boolean
Synopsis Allow standby router to forward traffic
Contextconfigure service ies string interface string ipv6 vrrp number standby-forwarding boolean
Treestandby-forwarding

Description

When configured to true, the standby router forwards all traffic.

When configured to false, the standby router cannot forward traffic sent to the MAC address of the virtual router. However, the standby router still forwards traffic sent to its own MAC address.

Defaultfalse
Introduced16.0.R1

Platforms

All

telnet-reply boolean
Synopsis Allow non-owner master to reply to Telnet requests
Contextconfigure service ies string interface string ipv6 vrrp number telnet-reply boolean
Treetelnet-reply

Description

When configured to true, the router allows the non-owner master to reply to Telnet requests directed at the IP addresses of the virtual router instance. Any routed interface can receive Telnet requests. Telnet cannot be disabled at the management security level (either on the parental IP interface or on the Telnet source host address).

When configured to false, the router silently discards Telnet requests sent to non-owner master virtual IP addresses.

Defaultfalse
Introduced16.0.R1

Platforms

All

traceroute-reply boolean
Synopsis Allow non-owner master to reply to traceroute requests
Contextconfigure service ies string interface string ipv6 vrrp number traceroute-reply boolean
Treetraceroute-reply

Description

When configured to true, the router allows a non-owner master to reply to traceroute requests directed to the IP addresses of the virtual router instance.

When configured to false, the router silently discards traceroute requests sent to non-owner master virtual IP addresses.

Traceroute must not have been disabled at the management security level (either on the parental IP interface or the source host address).

Defaultfalse
Introduced16.0.R1

Platforms

All

load-balancing
Synopsis Enter the load-balancing context
Contextconfigure service ies string interface string load-balancing
Treeload-balancing
Introduced16.0.R1

Platforms

All

flow-label-load-balancing boolean
Synopsis Enable flow label load balancing
Context configure service ies string interface string load-balancing flow-label-load-balancing boolean
Treeflow-label-load-balancing

Description

When configured to true, the router enables load balancing in ECMP and LAG based on the output of a hash performed on the triplet (SA, DA, flow label) in the header of an IPv6 packet received on an IES, VPRN, R-VPLS, CSC, or network interface.

When configured to false, the router disables load balancing in ECMP and LAG.

Defaultfalse
Introduced21.5.R1

Platforms

All

ip-load-balancing keyword
Synopsis IP load-balancing algorithm
Context configure service ies string interface string load-balancing ip-load-balancing keyword
Treeip-load-balancing

Description

This command specifies whether to include the source address, destination address, or both in LAG or ECMP hash on IP interfaces. Additionally, when the l4-load-balancing command is enabled, this command also includes the source or destination port in the hash inputs.

Optionsboth, destination, source, inner-ip
Default both
Introduced16.0.R3

Platforms

All

spi-load-balancing boolean
Synopsis Enable SPI use in hashing
Context configure service ies string interface string load-balancing spi-load-balancing boolean
Treespi-load-balancing

Description

When configured to true, the router uses the Security Parameter Index (SPI) in hashing for ESP and AH encrypted IPv4 and IPv6 traffic. This is a per-interface setting.

Defaultfalse
Introduced16.0.R1

Platforms

All

loopback boolean
Synopsis Use interface as a loopback interface
Contextconfigure service ies string interface string loopback boolean
Treeloopback
Defaultfalse
Introduced16.0.R1

Platforms

All

mac string
Synopsis MAC address for the interface
Context configure service ies string interface string mac string
Treemac
Introduced16.0.R1

Platforms

All

multi-chassis-shunting-profile reference
Synopsis Multi-chassis shunting profile name
Context configure service ies string interface string multi-chassis-shunting-profile reference
Treemulti-chassis-shunting-profile

Description

This command configures the name of a multi-chassis shunting profile to use on public or private tunnel interfaces.

Reference

configure router string ipsec multi-chassis-shunting-profile string

Notes

The following elements are part of a choice: multi-chassis-shunting-profile or (dynamic-tunnel-redundant-nexthop and static-tunnel-redundant-nexthop).

Introduced22.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ping-template
Synopsis Enable the ping-template context
Contextconfigure service ies string interface string ping-template
Treeping-template
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

admin-state keyword
Synopsis Administrative state of the ping template
Contextconfigure service ies string interface string ping-template admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

destination-address string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPing template destination address
Contextconfigure service ies string interface string ping-template destination-address string
Treedestination-address

Description

This command configures the address to where the ICMP echo requests are directed to test connectivity. The source of the ICMP echo request is the primary IPv4 address of the interface under which the ping-template is configured. The destination address must be on the same subnet as the source IP address.

Unnumbered interfaces and loopback addresses are not supported.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

name reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPing template name
Contextconfigure service ies string interface string ping-template name reference
Treename

Description

This command configures the name of the ping template to be assigned to the IP interface.

Reference

configure test-oam icmp ping-template string

Notes

This element is mandatory.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ptp-hw-assist
Synopsis Enter the ptp-hw-assist context
Contextconfigure service ies string interface string ptp-hw-assist
Treeptp-hw-assist

Description

Commands in this context enable the port-based timestamping assist of PTP packets at the physical interface. This capability is supported on specific hardware. The command may be blocked if not all hardware has the required level of support.

Only one interface per physical port can have port-based timestamping assist enabled. This feature cannot be enabled if the physical port supporting the interface is configured as a PTP port.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

admin-state keyword
Synopsis Administrative state of the PTP timestamping assist
Contextconfigure service ies string interface string ptp-hw-assist admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

sap [sap-id] string
Synopsis Enter the sap list instance
Context configure service ies string interface string sap string
Treesap
Max. Instances1
Introduced16.0.R1

Platforms

All

[sap-id] string
Synopsis SAP ID
Contextconfigure service ies string interface string sap string
Treesap
String Length1 to 45

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

aarp
Synopsis Enable the aarp context
Context configure service ies string interface string sap string aarp
Treeaarp
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

type keyword
Synopsis Role referenced by the AARP
Context configure service ies string interface string sap string aarp type keyword
Treetype
Optionsdual-homed, dual-homed-secondary
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the SAP
Context configure service ies string interface string sap string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

anti-spoof keyword
Synopsis Anti-spoof filtering
Context configure service ies string interface string sap string anti-spoof keyword
Treeanti-spoof
Optionssource-ip-addr, source-mac-addr, source-ip-and-mac-addr, next-hop-ip-and-mac-addr
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

cpu-protection
Synopsis Enter the cpu-protection context
Contextconfigure service ies string interface string sap string cpu-protection
Treecpu-protection
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

eth-cfm-monitoring
Synopsis Enable the eth-cfm-monitoring context
Contextconfigure service ies string interface string sap string cpu-protection eth-cfm-monitoring
Treeeth-cfm-monitoring

Notes

The following elements are part of a choice: eth-cfm-monitoring, ip-src-monitoring, or mac-monitoring.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

ip-src-monitoring
Synopsis Enable IP source monitoring for CPU protection
Contextconfigure service ies string interface string sap string cpu-protection ip-src-monitoring
Treeip-src-monitoring

Notes

The following elements are part of a choice: eth-cfm-monitoring, ip-src-monitoring, or mac-monitoring.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

mac-monitoring
Synopsis Monitor MAC for CPU protection
Context configure service ies string interface string sap string cpu-protection mac-monitoring
Treemac-monitoring

Notes

The following elements are part of a choice: eth-cfm-monitoring, ip-src-monitoring, or mac-monitoring.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

egress
Synopsis Enter the egress context
Context configure service ies string interface string sap string egress
Treeegress
Introduced16.0.R1

Platforms

All

agg-rate
Synopsis Enter the agg-rate context
Context configure service ies string interface string sap string egress agg-rate
Treeagg-rate

Notes

The following elements are part of a choice: agg-rate or percent-agg-rate.

Introduced16.0.R1

Platforms

All

adaptation-rule keyword
Synopsis Adaptation rule to compute the operational PIR value when an aggregate shaper is used
Contextconfigure service ies string interface string sap string egress agg-rate adaptation-rule keyword
Treeadaptation-rule
Optionsmax, min, closest
Defaultclosest
Introduced22.10.R1

Platforms

7750 SR-1, 7750 SR-s

burst-limit (number | keyword)
Synopsis Shaping burst size when an aggregate shaper is used
Contextconfigure service ies string interface string sap string egress agg-rate burst-limit (number | keyword)
Treeburst-limit
Range1 to 14000000
Unitsbytes
Options auto
Default auto
Introduced22.10.R1

Platforms

7750 SR-1, 7750 SR-s

rate number
Synopsis Enforced aggregate rate for all queues
Contextconfigure service ies string interface string sap string egress agg-rate rate number
Treerate
Range1 to 6400000000
Unitskilobps
Introduced 16.0.R1

Platforms

All

filter
Synopsis Enter the filter context
Context configure service ies string interface string sap string egress filter
Treefilter
Introduced16.0.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service ies string interface string sap string egress qos
Treeqos
Introduced16.0.R1

Platforms

All

policer-control-policy
Synopsis Enter the policer-control-policy context
Contextconfigure service ies string interface string sap string egress qos policer-control-policy
Treepolicer-control-policy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

overrides
Synopsis Enable the overrides context
Context configure service ies string interface string sap string egress qos policer-control-policy overrides
Treeoverrides
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

root
Synopsis Enter the root context
Context configure service ies string interface string sap string egress qos policer-control-policy overrides root
Treeroot
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

priority-mbs-thresholds
Synopsis Enter the priority-mbs-thresholds context
Contextconfigure service ies string interface string sap string egress qos policer-control-policy overrides root priority-mbs-thresholds
Treepriority-mbs-thresholds
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

priority [priority-level] number
Synopsis Enter the priority list instance
Contextconfigure service ies string interface string sap string egress qos policer-control-policy overrides root priority-mbs-thresholds priority number
Treepriority
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

sap-egress
Synopsis Enter the sap-egress context
Context configure service ies string interface string sap string egress qos sap-egress
Treesap-egress
Introduced16.0.R1

Platforms

All

overrides
Synopsis Enter the overrides context
Context configure service ies string interface string sap string egress qos sap-egress overrides
Treeoverrides
Introduced16.0.R1

Platforms

All

hs-wrr-group [group-id] reference
Synopsis Enter the hs-wrr-group list instance
Contextconfigure service ies string interface string sap string egress qos sap-egress overrides hs-wrr-group reference
Treehs-wrr-group
Introduced16.0.R1

Platforms

7750 SR-7/12/12e

rate (number | keyword)
Synopsis Scheduling rate override applied to the HS WRR group
Contextconfigure service ies string interface string sap string egress qos sap-egress overrides hs-wrr-group reference rate (number | keyword)
Treerate
Range1 to 2000000000
Unitskilobps
Options max

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

7750 SR-7/12/12e

policer [policer-id] reference
Synopsis Enter the policer list instance
Contextconfigure service ies string interface string sap string egress qos sap-egress overrides policer reference
Treepolicer
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service ies string interface string sap string egress qos sap-egress overrides policer reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

rate
Synopsis Enter the rate context
Context configure service ies string interface string sap string egress qos sap-egress overrides policer reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

stat-mode keyword
Synopsis Mode of statistics collected by the policer
Contextconfigure service ies string interface string sap string egress qos sap-egress overrides policer reference stat-mode keyword
Treestat-mode
Optionsno-stats, minimal, offered-profile-no-cir, offered-total-cir, offered-profile-cir, offered-limited-capped-cir, offered-profile-capped-cir, offered-total-cir-exceed, offered-four-profile-no-cir, offered-total-cir-four-profile
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

queue [queue-id] reference
Synopsis Enter the queue list instance
Context configure service ies string interface string sap string egress qos sap-egress overrides queue reference
Treequeue
Introduced16.0.R1

Platforms

All

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure service ies string interface string sap string egress qos sap-egress overrides queue reference adaptation-rule
Treeadaptation-rule
Introduced16.0.R1

Platforms

All

drop-tail
Synopsis Enter the drop-tail context
Context configure service ies string interface string sap string egress qos sap-egress overrides queue reference drop-tail
Treedrop-tail
Introduced16.0.R1

Platforms

All

low
Synopsis Enter the low context
Context configure service ies string interface string sap string egress qos sap-egress overrides queue reference drop-tail low
Treelow
Introduced16.0.R1

Platforms

All

hs-wred-queue
Synopsis Enter the hs-wred-queue context
Contextconfigure service ies string interface string sap string egress qos sap-egress overrides queue reference hs-wred-queue
Treehs-wred-queue
Introduced16.0.R1

Platforms

7750 SR-7/12/12e

monitor-queue-depth
Synopsis Enable the monitor-queue-depth context
Contextconfigure service ies string interface string sap string egress qos sap-egress overrides queue reference monitor-queue-depth
Treemonitor-queue-depth
Introduced20.10.R1

Platforms

All

parent
Synopsis Enter the parent context
Context configure service ies string interface string sap string egress qos sap-egress overrides queue reference parent
Treeparent
Introduced16.0.R1

Platforms

All

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service ies string interface string sap string egress qos sap-egress overrides queue reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

All

rate
Synopsis Enter the rate context
Context configure service ies string interface string sap string egress qos sap-egress overrides queue reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

All

port-redirect-group
Synopsis Enter the port-redirect-group context
Contextconfigure service ies string interface string sap string egress qos sap-egress port-redirect-group
Treeport-redirect-group
Introduced16.0.R1

Platforms

All

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service ies string interface string sap string egress qos scheduler-policy
Treescheduler-policy
Introduced16.0.R1

Platforms

All

overrides
Synopsis Enter the overrides context
Context configure service ies string interface string sap string egress qos scheduler-policy overrides
Treeoverrides
Introduced16.0.R1

Platforms

All

scheduler [scheduler-name] string
Synopsis Enter the scheduler list instance
Contextconfigure service ies string interface string sap string egress qos scheduler-policy overrides scheduler string
Treescheduler
Introduced16.0.R1

Platforms

All

[scheduler-name] string
Synopsis Scheduler name
Contextconfigure service ies string interface string sap string egress qos scheduler-policy overrides scheduler string
Treescheduler

Description

This command specifies the scheduler name which is composed of printable 7-bit ASCII characters. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes. Each scheduler must have a unique name within the context of the scheduler policy. However, the same name can be reused in multiple scheduler policies. If the scheduler name already exists within the policy tier level, the context changes to that scheduler name for the purpose of editing the scheduler commands.

If the scheduler name exists within the policy on a different tier, an error occurs and the current context does not change. If the scheduler name does not exist in this or another tier within the scheduler policy, it is assumed that an attempt is being made to create a scheduler of that name.

If the provided scheduler name is invalid, a name syntax error occurs, the command does not execute, and the context is not change.

String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

parent
Synopsis Enter the parent context
Context configure service ies string interface string sap string egress qos scheduler-policy overrides scheduler string parent
Treeparent
Introduced16.0.R1

Platforms

All

rate
Synopsis Enter the rate context
Context configure service ies string interface string sap string egress qos scheduler-policy overrides scheduler string rate
Treerate
Introduced16.0.R1

Platforms

All

virtual-port
Synopsis Enter the virtual-port context
Contextconfigure service ies string interface string sap string egress virtual-port
Treevirtual-port
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

eth-cfm
Synopsis Enter the eth-cfm context
Context configure service ies string interface string sap string eth-cfm
Treeeth-cfm
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

collect-lmm-fc-stats
Synopsis Enter the collect-lmm-fc-stats context
Contextconfigure service ies string interface string sap string eth-cfm collect-lmm-fc-stats
Treecollect-lmm-fc-stats

Description

Commands in this context configure per forwarding class (FC) LMM information collection.

The commands fc-in-profile and fc in this context are mutually exclusive. The commands apply to either profile-aware or profile-unaware FCs respectively. 

This command and the collect-lmm-stats command are mutually exclusive when there is entity resource contention.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fc keyword
Synopsis Forwarding class name for profile-unaware counter
Contextconfigure service ies string interface string sap string eth-cfm collect-lmm-fc-stats fc keyword
Treefc

Description

This command configures individual counters for the specified FCs without regard for profile. The system includes all countable packets that match a configured FC, regardless of profile, in this counter.

An FC specified as part of this command and for this specific context cannot be specified as a profile-aware FC using the fc-in-profile command under the collect-lmm-fc-stats context. 

When this command is reentered, a differential is performed. Omitted FCs stop counting, newly added FCs start counting, and unchanged FCs continue to count.

Optionsbe, l2, af, l1, h2, ef, h1, nc
Max. Instances 8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fc-in-profile keyword
Synopsis Forwarding class name for profile-aware counter
Contextconfigure service ies string interface string sap string eth-cfm collect-lmm-fc-stats fc-in-profile keyword
Treefc-in-profile

Description

This command configures individual counters for the specified FCs with regard to profile. The system includes all countable packets that match a configured FC and that are deemed to be in-profile in this counter.

An FC specified as part of this command and for this specific context cannot be specified as a profile-unaware FC using the fc command under the collect-lmm-fc-stats context.

When this command is reentered, a differential is performed. Omitted FCs stop counting, newly added FCs start counting, and unchanged FCs continue to count.

Optionsbe, l2, af, l1, h2, ef, h1, nc
Max. Instances 8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

collect-lmm-stats boolean
Synopsis Collect statistics for loss measurement message tests
Contextconfigure service ies string interface string sap string eth-cfm collect-lmm-stats boolean
Treecollect-lmm-stats

Description

When configured to true, the router instantiates the statistical counter to transmit and receive packets for the LAG facility MEP bindings.

The show eth-cfm collect-lmm-stats command displays entities that have been enabled to collect transit and receive counters.

When configured to false, the router does not instantiate the counter and the LMM PDU associated with the MEP does not populate the counters in the packet.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mep md-admin-name reference ma-admin-name reference mep-id number
Synopsis Enter the mep list instance
Context configure service ies string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number
Treemep
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mep-id number
Synopsis Maintenance Endpoint (MEP) ID
Context configure service ies string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number
Treemep
Range1 to 8191

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

alarm-notification
Synopsis Enter the alarm-notification context
Contextconfigure service ies string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number alarm-notification
Treealarm-notification

Description

Commands in this context configure the Fault Notification Generator (FNG) time values to raise an alarm or reset the CCM defect alarm. 

Use these timers for network management processes. The timers are not tied into delaying the notification to the fault management system on the network element and do not affect fault propagation mechanisms.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ccm-padding-size number
Synopsis Number of octets of padding to insert in CCM packets
Contextconfigure service ies string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number ccm-padding-size number
Treeccm-padding-size

Description

This command sets the byte size of the optional Data TLV to be included in the ETH-CC PDU.

This command increases the size of the ETH-CC PDU by the configured value. The base size of the ETH-CC PDU, including the Interface Status TLV and Port Status TLV, is 83 bytes not including the Layer 2 encapsulation. CCM padding is not supported when the CCM interval (configured through configure eth-cfm domain association ccm-interval) is less than 1 second.

Range3 to 1500
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

csf
Synopsis Enable the csf context
Context configure service ies string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number csf
Treecsf
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-test
Synopsis Enable the eth-test context
Context configure service ies string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test
Treeeth-test

Description

Commands in this context configure information used by the Ethernet Test (ETH-TST) packet. The commands must be configured on both the sender and the receiver nodes. The test packets are used with the oam eth-cfm eth-test command.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

test-pattern
Synopsis Enter the test-pattern context
Contextconfigure service ies string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test test-pattern
Treetest-pattern

Description

Commands in this context specify the test pattern for the ETH-TST frames. The pattern does not have to be the same on the sender and the receiver.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

pattern keyword
Synopsis Test pattern for Ethernet Test frames
Contextconfigure service ies string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test test-pattern pattern keyword
Treepattern

Description

This command specifies the test pattern of the Ethernet Test (ETH-TST) frames. This does not have to be configured the same on the sender and the receiver.

Optionsall-zeros, all-ones
Default all-zeros
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

grace
Synopsis Enter the grace context
Context configure service ies string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace
Treegrace

Description

Commands in this context configure the Nokia ETH-CFM Grace function and the ITU-T Y.1731 Ethernet Expected Default (ETH-ED) function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-ed
Synopsis Enter the eth-ed context
Context configure service ies string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-ed
Treeeth-ed

Description

Commands in this context configure the ITU-T Y.1731 ETH-ED function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

rx-eth-ed boolean
Synopsis Receive and process ETH-ED ITU-T Y.1731 PDUs on the MEP
Contextconfigure service ies string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-ed rx-eth-ed boolean
Treerx-eth-ed

Description

This command enables the reception and processing of the ITU-T Y.1731 ETH-ED PDU on the MEP.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-vsm-grace
Synopsis Enter the eth-vsm-grace context
Contextconfigure service ies string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace
Treeeth-vsm-grace

Description

Commands in this context configure the Nokia ETH-CFM Grace function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

rx-eth-vsm-grace boolean
Synopsis Receive and process Nokia ETH-CFM Grace PDU on the MEP
Contextconfigure service ies string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace rx-eth-vsm-grace boolean
Treerx-eth-vsm-grace

Description

When configured to true, the router enables the Nokia Grace function, which is a vendor-specific PDU that informs MEP peers that the local node may be entering a period of expected defect.

When configured to false, the router disables the Nokia Grace function.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

tx-eth-vsm-grace boolean
Synopsis Transmit ETH-ED PDUs from the MEP
Context configure service ies string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace tx-eth-vsm-grace boolean
Treetx-eth-vsm-grace

Description

When configured to true, the router can transmit the Nokia ETH-CFM Grace PDU from the MEP when a system soft reset notification is received for one or more cards.

The Nokia Grace function is a vendor-specific PDU that informs MEP peers that the local node may be entering a period of expected defect.

The operator must configure the configure system eth-cfm grace command to instruct the system that the node is capable of transmitting expected-defect windows to peers. The system can only transmit one form of ETH-CFM grace (Nokia ETH-CFM Grace or ITU-T Y.1731 ETH-ED).

When configured to false, the router disables the transmission of the Nokia ETH-CFM Grace PDU from the MEP.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

squelch-ingress-levels number
Synopsis Levels for which ETH-CFM packets are silently discarded
Contextconfigure service ies string interface string sap string eth-cfm squelch-ingress-levels number
Treesquelch-ingress-levels

Description

This command defines the levels of the ETH-CFM packets that are silently discarded on ingress into the SAP or SDP binding from the wire that matches the service delineation of the SAP or SDP binding. All ETH-CFM packets inbound to the SAP or SDP binding that match the configured levels are dropped without regard for any other ETH-CFM criteria. No statistical information or drop count is available for any ETH-CFM packet that is silently discarded by this option.

The list of levels must be a complete contiguous list from 0 up to the highest level that will be dropped.

Range0 to 7
Max. Instances8
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fwd-wholesale
Synopsis Enter the fwd-wholesale context
Contextconfigure service ies string interface string sap string fwd-wholesale
Treefwd-wholesale
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

host-admin-state keyword
Synopsis Administrative state of host creation on the SAP
Contextconfigure service ies string interface string sap string host-admin-state keyword
Treehost-admin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ingress
Synopsis Enter the ingress context
Context configure service ies string interface string sap string ingress
Treeingress
Introduced16.0.R1

Platforms

All

filter
Synopsis Enter the filter context
Context configure service ies string interface string sap string ingress filter
Treefilter
Introduced16.0.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service ies string interface string sap string ingress qos
Treeqos
Introduced16.0.R1

Platforms

All

policer-control-policy
Synopsis Enter the policer-control-policy context
Contextconfigure service ies string interface string sap string ingress qos policer-control-policy
Treepolicer-control-policy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

overrides
Synopsis Enable the overrides context
Context configure service ies string interface string sap string ingress qos policer-control-policy overrides
Treeoverrides
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

root
Synopsis Enter the root context
Context configure service ies string interface string sap string ingress qos policer-control-policy overrides root
Treeroot
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

priority-mbs-thresholds
Synopsis Enter the priority-mbs-thresholds context
Contextconfigure service ies string interface string sap string ingress qos policer-control-policy overrides root priority-mbs-thresholds
Treepriority-mbs-thresholds
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

priority [priority-level] number
Synopsis Enter the priority list instance
Contextconfigure service ies string interface string sap string ingress qos policer-control-policy overrides root priority-mbs-thresholds priority number
Treepriority
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

sap-ingress
Synopsis Enter the sap-ingress context
Context configure service ies string interface string sap string ingress qos sap-ingress
Treesap-ingress
Introduced16.0.R1

Platforms

All

fp-redirect-group
Synopsis Enter the fp-redirect-group context
Contextconfigure service ies string interface string sap string ingress qos sap-ingress fp-redirect-group
Treefp-redirect-group
Introduced16.0.R1

Platforms

All

overrides
Synopsis Enter the overrides context
Context configure service ies string interface string sap string ingress qos sap-ingress overrides
Treeoverrides
Introduced16.0.R1

Platforms

All

ip-criteria
Synopsis Enter the ip-criteria context
Context configure service ies string interface string sap string ingress qos sap-ingress overrides ip-criteria
Treeip-criteria
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ipv6-criteria
Synopsis Enter the ipv6-criteria context
Contextconfigure service ies string interface string sap string ingress qos sap-ingress overrides ipv6-criteria
Treeipv6-criteria
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

policer [policer-id] reference
Synopsis Enter the policer list instance
Contextconfigure service ies string interface string sap string ingress qos sap-ingress overrides policer reference
Treepolicer
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service ies string interface string sap string ingress qos sap-ingress overrides policer reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

rate
Synopsis Enter the rate context
Context configure service ies string interface string sap string ingress qos sap-ingress overrides policer reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

stat-mode keyword
Synopsis Mode of statistics collected by the policer
Contextconfigure service ies string interface string sap string ingress qos sap-ingress overrides policer reference stat-mode keyword
Treestat-mode
Optionsno-stats, minimal, offered-profile-no-cir, offered-total-cir, offered-priority-no-cir, offered-profile-cir, offered-priority-cir, offered-limited-profile-cir, offered-profile-capped-cir, offered-limited-capped-cir
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

queue [queue-id] reference
Synopsis Enter the queue list instance
Context configure service ies string interface string sap string ingress qos sap-ingress overrides queue reference
Treequeue
Introduced16.0.R1

Platforms

All

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure service ies string interface string sap string ingress qos sap-ingress overrides queue reference adaptation-rule
Treeadaptation-rule
Introduced16.0.R1

Platforms

All

drop-tail
Synopsis Enter the drop-tail context
Context configure service ies string interface string sap string ingress qos sap-ingress overrides queue reference drop-tail
Treedrop-tail
Introduced16.0.R1

Platforms

All

low
Synopsis Enter the low context
Context configure service ies string interface string sap string ingress qos sap-ingress overrides queue reference drop-tail low
Treelow
Introduced16.0.R1

Platforms

All

monitor-queue-depth
Synopsis Enable the monitor-queue-depth context
Contextconfigure service ies string interface string sap string ingress qos sap-ingress overrides queue reference monitor-queue-depth
Treemonitor-queue-depth
Introduced21.7.R1

Platforms

All

parent
Synopsis Enter the parent context
Context configure service ies string interface string sap string ingress qos sap-ingress overrides queue reference parent
Treeparent
Introduced16.0.R1

Platforms

All

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service ies string interface string sap string ingress qos sap-ingress overrides queue reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

All

rate
Synopsis Enter the rate context
Context configure service ies string interface string sap string ingress qos sap-ingress overrides queue reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

All

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service ies string interface string sap string ingress qos scheduler-policy
Treescheduler-policy
Introduced16.0.R1

Platforms

All

overrides
Synopsis Enter the overrides context
Context configure service ies string interface string sap string ingress qos scheduler-policy overrides
Treeoverrides
Introduced16.0.R1

Platforms

All

scheduler [scheduler-name] string
Synopsis Enter the scheduler list instance
Contextconfigure service ies string interface string sap string ingress qos scheduler-policy overrides scheduler string
Treescheduler
Introduced16.0.R1

Platforms

All

[scheduler-name] string
Synopsis Scheduler name
Contextconfigure service ies string interface string sap string ingress qos scheduler-policy overrides scheduler string
Treescheduler

Description

This command specifies the scheduler name which is composed of printable 7-bit ASCII characters. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes. Each scheduler must have a unique name within the context of the scheduler policy. However, the same name can be reused in multiple scheduler policies. If the scheduler name already exists within the policy tier level, the context changes to that scheduler name for the purpose of editing the scheduler commands.

If the scheduler name exists within the policy on a different tier, an error occurs and the current context does not change. If the scheduler name does not exist in this or another tier within the scheduler policy, it is assumed that an attempt is being made to create a scheduler of that name.

If the provided scheduler name is invalid, a name syntax error occurs, the command does not execute, and the context is not change.

String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

parent
Synopsis Enter the parent context
Context configure service ies string interface string sap string ingress qos scheduler-policy overrides scheduler string parent
Treeparent
Introduced16.0.R1

Platforms

All

rate
Synopsis Enter the rate context
Context configure service ies string interface string sap string ingress qos scheduler-policy overrides scheduler string rate
Treerate
Introduced16.0.R1

Platforms

All

ip-tunnel [tunnel-name] string
Synopsis Enter the ip-tunnel list instance
Contextconfigure service ies string interface string sap string ip-tunnel string
Treeip-tunnel

Description

Commands in this context configure an IP-GRE or IP-IP tunnel and associate it with a private tunnel SAP within an IES service.

Max. Instances1
Introduced16.0.R1

Platforms

All

[tunnel-name] string
Synopsis IP tunnel name
Contextconfigure service ies string interface string sap string ip-tunnel string
Treeip-tunnel
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

backup-remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisBackup remote IP address that is applied to this tunnel
Contextconfigure service ies string interface string sap string ip-tunnel string backup-remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treebackup-remote-ip-address
Introduced16.0.R1

Platforms

All

clear-df-bit boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisClear the Do-not-Fragment bit
Contextconfigure service ies string interface string sap string ip-tunnel string clear-df-bit boolean
Treeclear-df-bit

Description

When configured to true, the DF bit is cleared (set to 0) in all payload IP packets associated with the GRE or IPsec tunnel, before any potential fragmentation resulting from the ip-mtu command. This requires a modification of the header checksum.

When configured to false, clearing of the DF bit is disabled.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

delivery-service string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisService to originate and terminate GRE packets
Contextconfigure service ies string interface string sap string ip-tunnel string delivery-service string
Treedelivery-service

Description

This command specifies the service used to originate and terminate the GRE encapsulated packets belonging to the GRE tunnel. The delivery service may be the same service that owns the private tunnel SAP associated with the GRE tunnel.

The GRE tunnel does not come up until a valid delivery service is configured.

String Length1 to 64
Introduced16.0.R1

Platforms

All

description string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisText description
Contextconfigure service ies string interface string sap string ip-tunnel string description string
Treedescription
String Length1 to 80
Introduced16.0.R1

Platforms

All

dest-ip [dest-ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Add a list entry for dest-ip
Context configure service ies string interface string sap string ip-tunnel string dest-ip (ipv4-address-no-zone | ipv6-address-no-zone)
Treedest-ip
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[dest-ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the remote IP tunnel endpoint
Contextconfigure service ies string interface string sap string ip-tunnel string dest-ip (ipv4-address-no-zone | ipv6-address-no-zone)
Treedest-ip

Description

This command configures the IP address of the remote IP tunnel endpoint. If the remote IP address is not within the subnet of the IP interface associated with the tunnel, the tunnel fails to come up.

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dscp keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDifferentiated Services Code Point (DSCP) name
Contextconfigure service ies string interface string sap string ip-tunnel string dscp keyword
Treedscp
Optionsbe, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

encapsulated-ip-mtu number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum size of the encapsulated tunnel packet
Contextconfigure service ies string interface string sap string ip-tunnel string encapsulated-ip-mtu number
Treeencapsulated-ip-mtu

Description

This command specifies the maximum size of the encapsulated tunnel packet for the IP tunnel. If the packet exceeds this value, the system fragments the packet.

Range512 to 9000
Unitsbytes
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

gre-header
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the gre-header context
Contextconfigure service ies string interface string sap string ip-tunnel string gre-header
Treegre-header
Introduced16.0.R1

Platforms

All

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of the GRE header in the tunnel
Contextconfigure service ies string interface string sap string ip-tunnel string gre-header admin-state keyword
Treeadmin-state
Optionsenable, disable
Introduced 16.0.R1

Platforms

All

key
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the key context
Contextconfigure service ies string interface string sap string ip-tunnel string gre-header key
Treekey
Introduced16.0.R1

Platforms

All

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of the keys in the GRE header
Contextconfigure service ies string interface string sap string ip-tunnel string gre-header key admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

receive number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisReceive key of the GRE header
Contextconfigure service ies string interface string sap string ip-tunnel string gre-header key receive number
Treereceive
Max. Range0 to 4294967295
Default0
Introduced 16.0.R1

Platforms

All

send number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSend key of the GRE header
Contextconfigure service ies string interface string sap string ip-tunnel string gre-header key send number
Treesend
Max. Range0 to 4294967295
Default0
Introduced 16.0.R1

Platforms

All

icmp-generation
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the icmp-generation context
Contextconfigure service ies string interface string sap string ip-tunnel string icmp-generation
Treeicmp-generation
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

frag-required
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the frag-required context
Contextconfigure service ies string interface string sap string ip-tunnel string icmp-generation frag-required
Treefrag-required
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSend fragmentation required messages
Contextconfigure service ies string interface string sap string ip-tunnel string icmp-generation frag-required admin-state keyword
Treeadmin-state
Optionsenable, disable
Introduced 21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

interval number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum interval that the ICMP messages can be sent
Contextconfigure service ies string interface string sap string ip-tunnel string icmp-generation frag-required interval number
Treeinterval
Range1 to 60
Unitsseconds
Default 10
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

message-count number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of ICMP messages sent
Contextconfigure service ies string interface string sap string ip-tunnel string icmp-generation frag-required message-count number
Treemessage-count

Description

This command configures the maximum number of ICMP messages that can be sent during the period specified by the interval command.

Range10 to 1000
Default100
Introduced 21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

icmp6-generation
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the icmp6-generation context
Contextconfigure service ies string interface string sap string ip-tunnel string icmp6-generation
Treeicmp6-generation
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

packet-too-big
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the packet-too-big context
Contextconfigure service ies string interface string sap string ip-tunnel string icmp6-generation packet-too-big
Treepacket-too-big
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of sending Packet Too Big messages
Contextconfigure service ies string interface string sap string ip-tunnel string icmp6-generation packet-too-big admin-state keyword
Treeadmin-state
Optionsenable, disable
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

number number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of PTB ICMPv6 messages that can be sent
Contextconfigure service ies string interface string sap string ip-tunnel string icmp6-generation packet-too-big number number
Treenumber

Description

This command configures the maximum number of ICMPv6 messages that can be sent during the configured interval.

Range10 to 1000
Default100
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

seconds number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum interval when PTB messages can be sent
Contextconfigure service ies string interface string sap string ip-tunnel string icmp6-generation packet-too-big seconds number
Treeseconds
Range1 to 60
Unitsseconds
Default 10
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-mtu number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIP MTU for the interface
Contextconfigure service ies string interface string sap string ip-tunnel string ip-mtu number
Treeip-mtu

Description

This command specifies the IP MTU for the interface. If the DF bit is not set in the packet, IP packet fragmentation is performed, if necessary, based on this configured value.

When unconfigured, all IP packets, regardless of the packet size or DF bit setting, are allowed into the tunnel without fragmentation.

Range512 to 9000
Unitsbytes
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

local-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal IP address of this tunnel
Contextconfigure service ies string interface string sap string ip-tunnel string local-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treelocal-ip-address

Description

This command specifies the local IP address to use for the IP tunnel. This configuration applies to the outer IP header of the encapsulated packets. The address must belong to one of the IP subnets associated with the public SAP interface of the tunnel group. The source IP address, the remote IP address, and the backup remote IP address of a tunnel must all belong to the same address family (IPv4 or IPv6).

When this command specifies an IPv6 address, it must be a global unicast address.

Introduced16.0.R1

Platforms

All

pmtu-discovery-aging number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTime to age out the learned path MTU
Contextconfigure service ies string interface string sap string ip-tunnel string pmtu-discovery-aging number
Treepmtu-discovery-aging

Description

This command configures the temporary public MTU expiration time. The temporary public MTU is used for MTU propagation.

Range900 to 3600
Unitsseconds
Default 900
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

private-tcp-mss-adjust number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTCP Maximum Segment Size (MSS) on the private side
Contextconfigure service ies string interface string sap string ip-tunnel string private-tcp-mss-adjust number
Treeprivate-tcp-mss-adjust

Description

This command specifies the TCP MSS to adjust for tunnels on the private side. The value is used to adjust the TCP MSS option in the TCP SYN packet.

Range512 to 9000
Unitsbytes
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

propagate-pmtu-v4 boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable propagation of the path MTU to IPv4 hosts
Contextconfigure service ies string interface string sap string ip-tunnel string propagate-pmtu-v4 boolean
Treepropagate-pmtu-v4
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

propagate-pmtu-v6 boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable propagation of path MTU to IPv6 hosts
Contextconfigure service ies string interface string sap string ip-tunnel string propagate-pmtu-v6 boolean
Treepropagate-pmtu-v6
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

public-tcp-mss-adjust (number | keyword)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTCP Maximum Segment Size (MSS) on the public side
Contextconfigure service ies string interface string sap string ip-tunnel string public-tcp-mss-adjust (number | keyword)
Treepublic-tcp-mss-adjust

Description

This command specifies the TCP MSS for TCP traffic sent from the public network to the private network. The value is used to adjust the TCP MSS option in the TCP SYN packet.

Range512 to 9000
Unitsbytes
Options auto
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

reassembly (number | keyword)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum reassembly wait time
Contextconfigure service ies string interface string sap string ip-tunnel string reassembly (number | keyword)
Treereassembly

Description

This command configures the maximum time to wait to receive all fragments of a particular IPsec or GRE packet for reassembly.

Range1 to 5000
Unitsmilliseconds
Options use-tunnel-group-setting, none
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRemote IP address of the tunnel
Contextconfigure service ies string interface string sap string ip-tunnel string remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeremote-ip-address
Introduced16.0.R1

Platforms

All

ipsec-gateway [name] string
Synopsis Enter the ipsec-gateway list instance
Contextconfigure service ies string interface string sap string ipsec-gateway string
Treeipsec-gateway
Max. Instances1
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis IPsec gateway name
Context configure service ies string interface string sap string ipsec-gateway string
Treeipsec-gateway
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the IPsec gateway
Contextconfigure service ies string interface string sap string ipsec-gateway string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

cert
Synopsis Enter the cert context
Context configure service ies string interface string sap string ipsec-gateway string cert
Treecert
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

status-verify
Synopsis Enter the status-verify context
Contextconfigure service ies string interface string sap string ipsec-gateway string cert status-verify
Treestatus-verify

Description

Commands in this context configure certificate revocation status verification.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

default-result keyword
Synopsis Default result of Certificate Status Verification (CSV)
Contextconfigure service ies string interface string sap string ipsec-gateway string cert status-verify default-result keyword
Treedefault-result

Description

This command specifies the default result when both the primary and secondary methods fail to provide an answer.

Optionsrevoked, good
Default revoked
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

client-db
Synopsis Enable the client-db context
Context configure service ies string interface string sap string ipsec-gateway string client-db
Treeclient-db

Description

Commands in this context configure the IPsec client database. The client database is used to authenticate the IKEv2 dynamic LAN-to-LAN tunnel.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

fallback boolean
Synopsis Fall back to the default authentication policy
Contextconfigure service ies string interface string sap string ipsec-gateway string client-db fallback boolean
Treefallback

Description

When configured to true, this command specifies whether the IPsec gateway can fall back to the default authentication policy when the IPsec tunnel authentication request fails to match any clients in the IPsec database.

When configured to false and the client database lookup fails to return a matched result, the system fails the tunnel setup.

Defaulttrue
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

default-secure-service
Synopsis Enable the default-secure-service context
Contextconfigure service ies string interface string sap string ipsec-gateway string default-secure-service
Treedefault-secure-service
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

interface string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPrivate IPsec tunnel interface name
Contextconfigure service ies string interface string sap string ipsec-gateway string default-secure-service interface string
Treeinterface
String Length1 to 32
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

service-name string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDefault security service name
Contextconfigure service ies string interface string sap string ipsec-gateway string default-secure-service service-name string
Treeservice-name
String Length1 to 64
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dhcp-address-assignment
Synopsis Enter the dhcp-address-assignment context
Contextconfigure service ies string interface string sap string ipsec-gateway string dhcp-address-assignment
Treedhcp-address-assignment
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dhcpv4
Synopsis Enable the dhcpv4 context
Context configure service ies string interface string sap string ipsec-gateway string dhcp-address-assignment dhcpv4
Treedhcpv4
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

gi-address string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisGateway IP address of DHCPv4 packets sent by the system
Contextconfigure service ies string interface string sap string ipsec-gateway string dhcp-address-assignment dhcpv4 gi-address string
Treegi-address
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

send-release boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSend DHCPv4 release message when IPsec tunnel removed
Contextconfigure service ies string interface string sap string ipsec-gateway string dhcp-address-assignment dhcpv4 send-release boolean
Treesend-release
Defaulttrue
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

server
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the server context
Contextconfigure service ies string interface string sap string ipsec-gateway string dhcp-address-assignment dhcpv4 server
Treeserver
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

address string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDHCPv4 server addresses
Contextconfigure service ies string interface string sap string ipsec-gateway string dhcp-address-assignment dhcpv4 server address string
Treeaddress

Description

This command specifies DHCPv4 server addresses for the DHCPv4-based address assignment. If multiple server addresses are specified, the first advertised DHCPv4 address received is chosen.

Max. Instances8
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dhcpv6
Synopsis Enable the dhcpv6 context
Context configure service ies string interface string sap string ipsec-gateway string dhcp-address-assignment dhcpv6
Treedhcpv6
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

send-release boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSend DHCPv6 release message when IPsec tunnel removed
Contextconfigure service ies string interface string sap string ipsec-gateway string dhcp-address-assignment dhcpv6 send-release boolean
Treesend-release
Defaulttrue
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

server
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the server context
Contextconfigure service ies string interface string sap string ipsec-gateway string dhcp-address-assignment dhcpv6 server
Treeserver
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

address string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDHCPv6 server addresses
Contextconfigure service ies string interface string sap string ipsec-gateway string dhcp-address-assignment dhcpv6 server address string
Treeaddress

Description

This command specifies DHCPv6 server addresses for the DHCPv6-based address assignment. If multiple server addresses are specified, the first advertised DHCPv6 address received is chosen.

Max. Instances8
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

local
Synopsis Enter the local context
Context configure service ies string interface string sap string ipsec-gateway string local
Treelocal
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

address-assignment
Synopsis Enable the address-assignment context
Contextconfigure service ies string interface string sap string ipsec-gateway string local address-assignment
Treeaddress-assignment
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ipv4
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the ipv4 context
Contextconfigure service ies string interface string sap string ipsec-gateway string local address-assignment ipv4
Treeipv4
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dhcp-server string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal DHCPv4 server name
Contextconfigure service ies string interface string sap string ipsec-gateway string local address-assignment ipv4 dhcp-server string
Treedhcp-server
String Length1 to 32

Notes

This element is mandatory.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

pool string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisName of the pool defined in the specified DHCPv4 server
Contextconfigure service ies string interface string sap string ipsec-gateway string local address-assignment ipv4 pool string
Treepool
String Length1 to 32

Notes

This element is mandatory.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

router-instance string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRouter instance ID for the local DHCPv4 server
Contextconfigure service ies string interface string sap string ipsec-gateway string local address-assignment ipv4 router-instance string
Treerouter-instance
String Length1 to 64

Notes

This element is mandatory.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

secondary-pool string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisName of the secondary pool defined in the DHCPv4 server
Contextconfigure service ies string interface string sap string ipsec-gateway string local address-assignment ipv4 secondary-pool string
Treesecondary-pool
String Length1 to 32
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ipv6
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the ipv6 context
Contextconfigure service ies string interface string sap string ipsec-gateway string local address-assignment ipv6
Treeipv6
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dhcp-server string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal DHCPv6 server name
Contextconfigure service ies string interface string sap string ipsec-gateway string local address-assignment ipv6 dhcp-server string
Treedhcp-server
String Length1 to 32

Notes

This element is mandatory.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

pool string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSecondary pool name defined in the DHCPv6 server
Contextconfigure service ies string interface string sap string ipsec-gateway string local address-assignment ipv6 pool string
Treepool
String Length1 to 32

Notes

This element is mandatory.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

router-instance string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRouter instance ID hosting the DHCPv6 connection
Contextconfigure service ies string interface string sap string ipsec-gateway string local address-assignment ipv6 router-instance string
Treerouter-instance
String Length1 to 64

Notes

This element is mandatory.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal gateway address of the IPsec gateway
Contextconfigure service ies string interface string sap string ipsec-gateway string local gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treegateway-address
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

id
Synopsis Enter the id context
Context configure service ies string interface string sap string ipsec-gateway string local id
Treeid

Description

Commands in this context specify the local ID used for the Identification Indicator (IDi) or Identification Responder (IDr) in the IKEv2 tunnel.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

auto
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSelect ID based on authentication method in IKE policy
Contextconfigure service ies string interface string sap string ipsec-gateway string local id auto
Treeauto

Notes

The following elements are part of a choice: auto, fqdn, ipv4, or ipv6.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

fqdn string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisFQDN as the local ID type
Contextconfigure service ies string interface string sap string ipsec-gateway string local id fqdn string
Treefqdn
String Length1 to 255

Notes

The following elements are part of a choice: auto, fqdn, ipv4, or ipv6.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ipv4 string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPv4 address as the local ID type
Contextconfigure service ies string interface string sap string ipsec-gateway string local id ipv4 string
Treeipv4

Notes

The following elements are part of a choice: auto, fqdn, ipv4, or ipv6.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPv6 address as the local ID type
Contextconfigure service ies string interface string sap string ipsec-gateway string local id ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
Treeipv6

Notes

The following elements are part of a choice: auto, fqdn, ipv4, or ipv6.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

max-history-key-records
Synopsis Enter the max-history-key-records context
Contextconfigure service ies string interface string sap string ipsec-gateway string max-history-key-records
Treemax-history-key-records
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

radius
Synopsis Enter the radius context
Context configure service ies string interface string sap string ipsec-gateway string radius
Treeradius
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

lag
Synopsis Enter the lag context
Context configure service ies string interface string sap string lag
Treelag
Introduced16.0.R1

Platforms

All

link-map-profile number
Synopsis LAG link map profile for a SAP or network interface
Contextconfigure service ies string interface string sap string lag link-map-profile number
Treelink-map-profile

Description

This command assigns a preconfigured LAG link map profile to a SAP or network interface configured on a LAG or a PW port that exists on a LAG. After an operator assigns a LAG link map profile, the system rehashes the SAP or network interface egress traffic over the LAG as required by the new configuration.

If the LAG link map profile for a SAP or network interface is deleted, the system reverts back to per-flow hashing.

Range1 to 64
Introduced16.0.R1

Platforms

All

per-link-hash
Synopsis Enter the per-link-hash context
Contextconfigure service ies string interface string sap string lag per-link-hash
Treeper-link-hash
Introduced16.0.R1

Platforms

All

static-host
Synopsis Enter the static-host context
Context configure service ies string interface string sap string static-host
Treestatic-host
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv4 [ip] string mac string
Synopsis Enter the ipv4 list instance
Context configure service ies string interface string sap string static-host ipv4 string mac string
Treeipv4
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[ip] string
Synopsis IP address
Contextconfigure service ies string interface string sap string static-host ipv4 string mac string
Treeipv4
MD-CLI Default0.0.0.0

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

mac string
Synopsis MAC address
Contextconfigure service ies string interface string sap string static-host ipv4 string mac string
Treeipv4
MD-CLI Default00:00:00:00:00:00

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the static host
Contextconfigure service ies string interface string sap string static-host ipv4 string mac string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

app-profile
Synopsis Enter the app-profile context
Context configure service ies string interface string sap string static-host ipv4 string mac string app-profile
Treeapp-profile
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

subscriber-id
Synopsis Enter the subscriber-id context
Contextconfigure service ies string interface string sap string static-host ipv4 string mac string subscriber-id
Treesubscriber-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

string string
Synopsis Subscriber identification
Context configure service ies string interface string sap string static-host ipv4 string mac string subscriber-id string string
Treestring
String Length1 to 64

Notes

The following elements are part of a choice: string or use-sap-id.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

transit-policy
Synopsis Enable the transit-policy context
Contextconfigure service ies string interface string sap string transit-policy
Treetransit-policy
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP transit policy ID
Contextconfigure service ies string interface string sap string transit-policy ip reference
Treeip

Reference

configure application-assurance group number partition number transit-ip-policy number

Notes

The following elements are part of a mandatory choice: ip or prefix.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

prefix reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP prefix policy ID
Contextconfigure service ies string interface string sap string transit-policy prefix reference
Treeprefix

Reference

configure application-assurance group number partition number transit-prefix-policy number

Notes

The following elements are part of a mandatory choice: ip or prefix.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

spoke-sdp [sdp-bind-id] string
Synopsis Enter the spoke-sdp list instance
Contextconfigure service ies string interface string spoke-sdp string
Treespoke-sdp
Max. Instances1
Introduced16.0.R1

Platforms

All

[sdp-bind-id] string
Synopsis SDP binding ID
Contextconfigure service ies string interface string spoke-sdp string
Treespoke-sdp
String Length3 to 16

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

aarp
Synopsis Enable the aarp context
Context configure service ies string interface string spoke-sdp string aarp
Treeaarp
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

type keyword
Synopsis Role referenced by the AARP
Context configure service ies string interface string spoke-sdp string aarp type keyword
Treetype
Optionsdual-homed, dual-homed-secondary
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the SDP binding to the service
Contextconfigure service ies string interface string spoke-sdp string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

bfd
Synopsis Enter the bfd context
Context configure service ies string interface string spoke-sdp string bfd
Treebfd
Introduced21.2.R1

Platforms

All

bfd-template reference
Synopsis BFD template associated with the SDP binding
Contextconfigure service ies string interface string spoke-sdp string bfd bfd-template reference
Treebfd-template

Description

This command configures a named BFD template to be used by VCCV BFD on PWs belonging to the VLL service. The template specifies parameters, such as the minimum transmit and receive control packet timer intervals, used by the BFD session. Template parameters are configured under the configure router bfd context.

Reference

configure bfd bfd-template string

Introduced21.2.R1

Platforms

All

failure-action keyword
Synopsis VCCV BFD action taken on the SDP binding
Contextconfigure service ies string interface string spoke-sdp string bfd failure-action keyword
Treefailure-action

Description

This command configures a named BFD template to be used by VCCV BFD on PWs belonging to the VLL service. The template specifies parameters, such as the minimum transmit and receive control packet timer intervals, used by the BFD session. Template parameters are configured under the configure router bfd context.

Optionsnone, down
Default none
Introduced21.2.R1

Platforms

All

wait-for-up-timer number
Synopsis Time waited for BFD up status
Context configure service ies string interface string spoke-sdp string bfd wait-for-up-timer number
Treewait-for-up-timer

Description

This command configures the time interval that is used to wait for a BFD session to come up.

This command is triggered when a spoke-SDP is first administratively enabled and a VCCV BFD session transitions from up to down. The command is required to allow time for BFD sessions to come up, and for BFD to settle before selecting the active spoke-SDP for use in a redundant set. In the case where a VCCV BFD session is bouncing, the timer prevents excessive flapping of the operational state of a spoke-SDP.

Range1 to 60
Unitsseconds
Introduced 21.2.R1

Platforms

All

control-word boolean
Synopsis Use the control word as preferred
Context configure service ies string interface string spoke-sdp string control-word boolean
Treecontrol-word
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

cpu-protection
Synopsis Enter the cpu-protection context
Contextconfigure service ies string interface string spoke-sdp string cpu-protection
Treecpu-protection
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

eth-cfm-monitoring
Synopsis Enable the eth-cfm-monitoring context
Contextconfigure service ies string interface string spoke-sdp string cpu-protection eth-cfm-monitoring
Treeeth-cfm-monitoring

Notes

The following elements are part of a choice: eth-cfm-monitoring, ip-src-monitoring, or mac-monitoring.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

ip-src-monitoring
Synopsis Enable IP source monitoring for CPU protection
Contextconfigure service ies string interface string spoke-sdp string cpu-protection ip-src-monitoring
Treeip-src-monitoring

Notes

The following elements are part of a choice: eth-cfm-monitoring, ip-src-monitoring, or mac-monitoring.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

mac-monitoring
Synopsis Monitor MAC for CPU protection
Context configure service ies string interface string spoke-sdp string cpu-protection mac-monitoring
Treemac-monitoring

Notes

The following elements are part of a choice: eth-cfm-monitoring, ip-src-monitoring, or mac-monitoring.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

egress
Synopsis Enter the egress context
Context configure service ies string interface string spoke-sdp string egress
Treeegress
Introduced16.0.R1

Platforms

All

filter
Synopsis Enter the filter context
Context configure service ies string interface string spoke-sdp string egress filter
Treefilter
Introduced16.0.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service ies string interface string spoke-sdp string egress qos
Treeqos
Introduced16.0.R1

Platforms

All

network
Synopsis Enter the network context
Context configure service ies string interface string spoke-sdp string egress qos network
Treenetwork
Introduced16.0.R1

Platforms

All

port-redirect-group
Synopsis Enter the port-redirect-group context
Contextconfigure service ies string interface string spoke-sdp string egress qos network port-redirect-group
Treeport-redirect-group
Introduced16.0.R1

Platforms

All

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEgress MPLS VC label to send packets to the far end
Contextconfigure service ies string interface string spoke-sdp string egress vc-label number
Treevc-label
Range16 to 1048575
Introduced16.0.R1

Platforms

All

entropy-label
Synopsis Enable the use of entropy labels for spoke SDPs
Contextconfigure service ies string interface string spoke-sdp string entropy-label
Treeentropy-label

Notes

The following elements are part of a choice: entropy-label or hash-label.

Introduced16.0.R1

Platforms

All

eth-cfm
Synopsis Enter the eth-cfm context
Context configure service ies string interface string spoke-sdp string eth-cfm
Treeeth-cfm
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

collect-lmm-fc-stats
Synopsis Enter the collect-lmm-fc-stats context
Contextconfigure service ies string interface string spoke-sdp string eth-cfm collect-lmm-fc-stats
Treecollect-lmm-fc-stats

Description

Commands in this context configure per forwarding class (FC) LMM information collection.

The commands fc-in-profile and fc in this context are mutually exclusive. The commands apply to either profile-aware or profile-unaware FCs respectively. 

This command and the collect-lmm-stats command are mutually exclusive when there is entity resource contention.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fc keyword
Synopsis Forwarding class name for profile-unaware counter
Contextconfigure service ies string interface string spoke-sdp string eth-cfm collect-lmm-fc-stats fc keyword
Treefc

Description

This command configures individual counters for the specified FCs without regard for profile. The system includes all countable packets that match a configured FC, regardless of profile, in this counter.

An FC specified as part of this command and for this specific context cannot be specified as a profile-aware FC using the fc-in-profile command under the collect-lmm-fc-stats context. 

When this command is reentered, a differential is performed. Omitted FCs stop counting, newly added FCs start counting, and unchanged FCs continue to count.

Optionsbe, l2, af, l1, h2, ef, h1, nc
Max. Instances 8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fc-in-profile keyword
Synopsis Forwarding class name for profile-aware counter
Contextconfigure service ies string interface string spoke-sdp string eth-cfm collect-lmm-fc-stats fc-in-profile keyword
Treefc-in-profile

Description

This command configures individual counters for the specified FCs with regard to profile. The system includes all countable packets that match a configured FC and that are deemed to be in-profile in this counter.

An FC specified as part of this command and for this specific context cannot be specified as a profile-unaware FC using the fc command under the collect-lmm-fc-stats context.

When this command is reentered, a differential is performed. Omitted FCs stop counting, newly added FCs start counting, and unchanged FCs continue to count.

Optionsbe, l2, af, l1, h2, ef, h1, nc
Max. Instances 8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

collect-lmm-stats boolean
Synopsis Collect statistics for loss measurement message tests
Contextconfigure service ies string interface string spoke-sdp string eth-cfm collect-lmm-stats boolean
Treecollect-lmm-stats

Description

When configured to true, the router instantiates the statistical counter to transmit and receive packets for the LAG facility MEP bindings.

The show eth-cfm collect-lmm-stats command displays entities that have been enabled to collect transit and receive counters.

When configured to false, the router does not instantiate the counter and the LMM PDU associated with the MEP does not populate the counters in the packet.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mep md-admin-name reference ma-admin-name reference mep-id number
Synopsis Enter the mep list instance
Context configure service ies string interface string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number
Treemep
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

alarm-notification
Synopsis Enter the alarm-notification context
Contextconfigure service ies string interface string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number alarm-notification
Treealarm-notification

Description

Commands in this context configure the Fault Notification Generator (FNG) time values to raise an alarm or reset the CCM defect alarm. 

Use these timers for network management processes. The timers are not tied into delaying the notification to the fault management system on the network element and do not affect fault propagation mechanisms.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ccm-padding-size number
Synopsis Number of octets of padding to insert in CCM packets
Contextconfigure service ies string interface string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number ccm-padding-size number
Treeccm-padding-size

Description

This command sets the byte size of the optional Data TLV to be included in the ETH-CC PDU.

This command increases the size of the ETH-CC PDU by the configured value. The base size of the ETH-CC PDU, including the Interface Status TLV and Port Status TLV, is 83 bytes not including the Layer 2 encapsulation. CCM padding is not supported when the CCM interval (configured through configure eth-cfm domain association ccm-interval) is less than 1 second.

Range3 to 1500
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

csf
Synopsis Enable the csf context
Context configure service ies string interface string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number csf
Treecsf
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-test
Synopsis Enable the eth-test context
Context configure service ies string interface string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test
Treeeth-test

Description

Commands in this context configure information used by the Ethernet Test (ETH-TST) packet. The commands must be configured on both the sender and the receiver nodes. The test packets are used with the oam eth-cfm eth-test command.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

test-pattern
Synopsis Enter the test-pattern context
Contextconfigure service ies string interface string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test test-pattern
Treetest-pattern

Description

Commands in this context specify the test pattern for the ETH-TST frames. The pattern does not have to be the same on the sender and the receiver.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

pattern keyword
Synopsis Test pattern for Ethernet Test frames
Contextconfigure service ies string interface string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test test-pattern pattern keyword
Treepattern

Description

This command specifies the test pattern of the Ethernet Test (ETH-TST) frames. This does not have to be configured the same on the sender and the receiver.

Optionsall-zeros, all-ones
Default all-zeros
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

grace
Synopsis Enter the grace context
Context configure service ies string interface string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace
Treegrace

Description

Commands in this context configure the Nokia ETH-CFM Grace function and the ITU-T Y.1731 Ethernet Expected Default (ETH-ED) function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-ed
Synopsis Enter the eth-ed context
Context configure service ies string interface string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-ed
Treeeth-ed

Description

Commands in this context configure the ITU-T Y.1731 ETH-ED function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-vsm-grace
Synopsis Enter the eth-vsm-grace context
Contextconfigure service ies string interface string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace
Treeeth-vsm-grace

Description

Commands in this context configure the Nokia ETH-CFM Grace function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

rx-eth-vsm-grace boolean
Synopsis Receive and process Nokia ETH-CFM Grace PDU on the MEP
Contextconfigure service ies string interface string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace rx-eth-vsm-grace boolean
Treerx-eth-vsm-grace

Description

When configured to true, the router enables the Nokia Grace function, which is a vendor-specific PDU that informs MEP peers that the local node may be entering a period of expected defect.

When configured to false, the router disables the Nokia Grace function.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

tx-eth-vsm-grace boolean
Synopsis Transmit ETH-ED PDUs from the MEP
Context configure service ies string interface string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace tx-eth-vsm-grace boolean
Treetx-eth-vsm-grace

Description

When configured to true, the router can transmit the Nokia ETH-CFM Grace PDU from the MEP when a system soft reset notification is received for one or more cards.

The Nokia Grace function is a vendor-specific PDU that informs MEP peers that the local node may be entering a period of expected defect.

The operator must configure the configure system eth-cfm grace command to instruct the system that the node is capable of transmitting expected-defect windows to peers. The system can only transmit one form of ETH-CFM grace (Nokia ETH-CFM Grace or ITU-T Y.1731 ETH-ED).

When configured to false, the router disables the transmission of the Nokia ETH-CFM Grace PDU from the MEP.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

squelch-ingress-levels number
Synopsis Levels for which ETH-CFM packets are silently discarded
Contextconfigure service ies string interface string spoke-sdp string eth-cfm squelch-ingress-levels number
Treesquelch-ingress-levels

Description

This command defines the levels of the ETH-CFM packets that are silently discarded on ingress into the SAP or SDP binding from the wire that matches the service delineation of the SAP or SDP binding. All ETH-CFM packets inbound to the SAP or SDP binding that match the configured levels are dropped without regard for any other ETH-CFM criteria. No statistical information or drop count is available for any ETH-CFM packet that is silently discarded by this option.

The list of levels must be a complete contiguous list from 0 up to the highest level that will be dropped.

Range0 to 7
Max. Instances8
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

hash-label
Synopsis Enable the hash-label context
Context configure service ies string interface string spoke-sdp string hash-label
Treehash-label

Description

Commands in this context configure the use of hash labels for egress datapaths.

For information about hash-label handling, see the "Hash labels" section of the 7450 ESS, 7750 SR, 7950 XRS, and VSR MPLS Guide.

Notes

The following elements are part of a choice: entropy-label or hash-label.

Introduced16.0.R1

Platforms

All

signal-capability
Synopsis Signal hash label capability to the remote PE
Contextconfigure service ies string interface string spoke-sdp string hash-label signal-capability
Treesignal-capability

Description

When configured, this command enables the signaling and negotiating of the hash label between the local and remote PE nodes.

The signaling process outcome determines whether the local PE inserts the hash label on the user packets. This outcome can override the local PE configuration.

Introduced16.0.R1

Platforms

All

ingress
Synopsis Enter the ingress context
Context configure service ies string interface string spoke-sdp string ingress
Treeingress
Introduced16.0.R1

Platforms

All

filter
Synopsis Enter the filter context
Context configure service ies string interface string spoke-sdp string ingress filter
Treefilter
Introduced16.0.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service ies string interface string spoke-sdp string ingress qos
Treeqos
Introduced16.0.R1

Platforms

All

network
Synopsis Enter the network context
Context configure service ies string interface string spoke-sdp string ingress qos network
Treenetwork
Introduced16.0.R1

Platforms

All

fp-redirect-group
Synopsis Enter the fp-redirect-group context
Contextconfigure service ies string interface string spoke-sdp string ingress qos network fp-redirect-group
Treefp-redirect-group
Introduced16.0.R1

Platforms

All

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIngress MPLS VC label to send packets to the far end
Contextconfigure service ies string interface string spoke-sdp string ingress vc-label number
Treevc-label
Range1 to 1048575
Introduced16.0.R1

Platforms

All

transit-policy
Synopsis Enable the transit-policy context
Contextconfigure service ies string interface string spoke-sdp string transit-policy
Treetransit-policy
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP transit policy ID
Contextconfigure service ies string interface string spoke-sdp string transit-policy ip reference
Treeip

Reference

configure application-assurance group number partition number transit-ip-policy number

Notes

The following elements are part of a mandatory choice: ip or prefix.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

prefix reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP prefix policy ID
Contextconfigure service ies string interface string spoke-sdp string transit-policy prefix reference
Treeprefix

Reference

configure application-assurance group number partition number transit-prefix-policy number

Notes

The following elements are part of a mandatory choice: ip or prefix.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

vc-type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVirtual circuit type associated with the SDP binding
Contextconfigure service ies string interface string spoke-sdp string vc-type keyword
Treevc-type
Optionsether, ipipe
Default ether
Introduced16.0.R1

Platforms

All

static-tunnel-redundant-nexthop string
Synopsis Address for the static ISA tunnel redundant next-hop
Contextconfigure service ies string interface string static-tunnel-redundant-nexthop string
Treestatic-tunnel-redundant-nexthop

Description

This command specifies the redundant next-hop address on public or private IPsec interfaces (with a public or private tunnel SAP) for the static IPsec tunnel.

The next-hop address is resolved in the routing table of the corresponding service.

Notes

The following elements are part of a choice: multi-chassis-shunting-profile or (dynamic-tunnel-redundant-nexthop and static-tunnel-redundant-nexthop).

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

tunnel boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEnable/disable tunnel interface
Contextconfigure service ies string interface string tunnel boolean
Treetunnel
Defaultfalse
Introduced16.0.R1

Platforms

All

vas-if-type keyword
Synopsis VAS interface type
Context configure service ies string interface string vas-if-type keyword
Treevas-if-type
Optionsto-from-access, to-from-network, to-from-both
Introduced16.0.R1

Platforms

All

vpls [vpls-name] string
Synopsis Enter the vpls list instance
Context configure service ies string interface string vpls string
Treevpls
Max. Instances1
Introduced16.0.R1

Platforms

All

[vpls-name] string
Synopsis VPLS service
Contextconfigure service ies string interface string vpls string
Treevpls
String Length1 to 64

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

All

egress
Synopsis Enter the egress context
Context configure service ies string interface string vpls string egress
Treeegress
Introduced16.0.R1

Platforms

All

routed-override-filter
Synopsis Enter the routed-override-filter context
Contextconfigure service ies string interface string vpls string egress routed-override-filter
Treerouted-override-filter
Introduced16.0.R1

Platforms

All

evpn
Synopsis Enter the evpn context
Context configure service ies string interface string vpls string evpn
Treeevpn
Introduced19.10.R1

Platforms

All

arp
Synopsis Enter the arp context
Context configure service ies string interface string vpls string evpn arp
Treearp
Introduced19.10.R1

Platforms

All

advertise [route-type] keyword
Synopsis Enter the advertise list instance
Contextconfigure service ies string interface string vpls string evpn arp advertise keyword
Treeadvertise

Description

Commands in this context specify the configuration to allow ARP or ND entries that are installed in the ARP or ND cache to be advertised in EVPN MAC/IP routes.

The learn-dynamic command must be set to false when using this functionality.

Introduced19.10.R1

Platforms

All

[route-type] keyword
Synopsis Type of ARP or ND entries that generate host routes
Contextconfigure service ies string interface string vpls string evpn arp advertise keyword
Treeadvertise

Description

This command specifies the type of ARP or ND entries that are installed in the ARP or ND cache into EVPN MAC/IP routes.

Optionsstatic, dynamic

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

route-tag number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTag value used with the host route from an ARP/ND entry
Contextconfigure service ies string interface string vpls string evpn arp advertise keyword route-tag number
Treeroute-tag

Description

This command specifies the route tag that is added separately to dynamic or static ARP or ND entries that are advertised in EVPN MAC/IP routes. This tag can be matched on BGP vsi-export (in the R-VPLS) and BGP peer export policies. 

Range0 to 255
Introduced19.10.R1

Platforms

All

flood-garp-and-unknown-req boolean
Synopsis Allow CPM originated ARP frames to flood R-VPLS service
Contextconfigure service ies string interface string vpls string evpn arp flood-garp-and-unknown-req boolean
Treeflood-garp-and-unknown-req

Description

When configured to true, the system allows CPM-originated ARP frames to be flooded in the R-VPLS service. Any frames that are data path flooded such as the ARP messages received on a SAP, are flooded irrespective of this command.

When configured to false, CPM-originated ARP flooding is suppressed.

Defaulttrue
Introduced19.10.R1

Platforms

All

learn-dynamic boolean
Synopsis Process ARP or ND messages on EVPN tunnels
Contextconfigure service ies string interface string vpls string evpn arp learn-dynamic boolean
Treelearn-dynamic

Description

When configured to true, the system processes ARP or ND messages that arrive on EVPN tunnels.

When configured to false, learning is disabled and table entries are not created for these messages.

Defaulttrue
Introduced19.10.R1

Platforms

All

nd
Synopsis Enter the nd context
Context configure service ies string interface string vpls string evpn nd
Treend
Introduced20.5.R1

Platforms

All

advertise [route-type] keyword
Synopsis Enter the advertise list instance
Contextconfigure service ies string interface string vpls string evpn nd advertise keyword
Treeadvertise

Description

Commands in this context specify the configuration to allow ARP or ND entries that are installed in the ARP or ND cache to be advertised in EVPN MAC/IP routes.

The learn-dynamic command must be set to false when using this functionality.

Introduced20.5.R1

Platforms

All

[route-type] keyword
Synopsis Type of ARP or ND entries that generate host routes
Contextconfigure service ies string interface string vpls string evpn nd advertise keyword
Treeadvertise

Description

This command specifies the type of ARP or ND entries that are installed in the ARP or ND cache into EVPN MAC/IP routes.

Optionsstatic, dynamic

Notes

This element is part of a list key.

Introduced20.5.R1

Platforms

All

route-tag number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTag value used with the host route from an ARP/ND entry
Contextconfigure service ies string interface string vpls string evpn nd advertise keyword route-tag number
Treeroute-tag

Description

This command specifies the route tag that is added separately to dynamic or static ARP or ND entries that are advertised in EVPN MAC/IP routes. This tag can be matched on BGP vsi-export (in the R-VPLS) and BGP peer export policies. 

Range0 to 255
Introduced20.5.R1

Platforms

All

learn-dynamic boolean
Synopsis Process ARP or ND messages on EVPN tunnels
Contextconfigure service ies string interface string vpls string evpn nd learn-dynamic boolean
Treelearn-dynamic

Description

When configured to true, the system processes ARP or ND messages that arrive on EVPN tunnels.

When configured to false, learning is disabled and table entries are not created for these messages.

Defaulttrue
Introduced20.5.R1

Platforms

All

ingress
Synopsis Enter the ingress context
Context configure service ies string interface string vpls string ingress
Treeingress
Introduced16.0.R1

Platforms

All

routed-override-filter
Synopsis Enter the routed-override-filter context
Contextconfigure service ies string interface string vpls string ingress routed-override-filter
Treerouted-override-filter
Introduced16.0.R1

Platforms

All

redundant-interface [interface-name] string
Synopsis Enter the redundant-interface list instance
Contextconfigure service ies string redundant-interface string
Treeredundant-interface
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[interface-name] string
Synopsis Interface name
Contextconfigure service ies string redundant-interface string
Treeredundant-interface
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the interface
Contextconfigure service ies string redundant-interface string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

hold-time
Synopsis Enter the hold-time context
Context configure service ies string redundant-interface string hold-time
Treehold-time
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv4
Synopsis Enter the ipv4 context
Context configure service ies string redundant-interface string hold-time ipv4
Treeipv4
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

down
Synopsis Enter the down context
Context configure service ies string redundant-interface string hold-time ipv4 down
Treedown

Description

Commands in this context configure the down hold timer, which specifies the delay before activating the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface up, unless an operator configures the init-only command. 

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

init-only boolean
Synopsis Apply delay only at interface configuration or reboot
Contextconfigure service ies string redundant-interface string hold-time ipv4 down init-only boolean
Treeinit-only

Description

This command applies a delay only when the IP interface is first configured or after a system reboot.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

up
Synopsis Enter the up context
Context configure service ies string redundant-interface string hold-time ipv4 up
Treeup

Description

Commands in this context configure the up hold timer, which specifies the delay before deactivation of the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface down.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ip-mtu number
Synopsis IP MTU applied to outgoing packets
Context configure service ies string redundant-interface string ip-mtu number
Treeip-mtu

Description

This command configures the IP maximum transmission unit (MTU) for the associated router IP interface.

Range512 to 9786
Unitsbytes
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv4
Synopsis Enter the ipv4 context
Context configure service ies string redundant-interface string ipv4
Treeipv4
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

primary
Synopsis Enable the primary context
Context configure service ies string redundant-interface string ipv4 primary
Treeprimary
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

address string
Synopsis IPv4 address to be assigned to the interface
Contextconfigure service ies string redundant-interface string ipv4 primary address string
Treeaddress

Notes

This element is mandatory.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

spoke-sdp [sdp-bind-id] string
Synopsis Enter the spoke-sdp list instance
Contextconfigure service ies string redundant-interface string spoke-sdp string
Treespoke-sdp
Max. Instances1
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[sdp-bind-id] string
Synopsis SDP binding ID
Contextconfigure service ies string redundant-interface string spoke-sdp string
Treespoke-sdp
String Length3 to 16

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the SDP binding to the service
Contextconfigure service ies string redundant-interface string spoke-sdp string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

egress
Synopsis Enter the egress context
Context configure service ies string redundant-interface string spoke-sdp string egress
Treeegress
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

filter
Synopsis Enter the filter context
Context configure service ies string redundant-interface string spoke-sdp string egress filter
Treefilter
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEgress MPLS VC label to send packets to the far end
Contextconfigure service ies string redundant-interface string spoke-sdp string egress vc-label number
Treevc-label
Range16 to 1048575
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ingress
Synopsis Enter the ingress context
Context configure service ies string redundant-interface string spoke-sdp string ingress
Treeingress
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

filter
Synopsis Enter the filter context
Context configure service ies string redundant-interface string spoke-sdp string ingress filter
Treefilter
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIngress MPLS VC label to send packets to the far end
Contextconfigure service ies string redundant-interface string spoke-sdp string ingress vc-label number
Treevc-label
Range1 to 1048575
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

service-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisService ID
Contextconfigure service ies string service-id number
Treeservice-id
Range1 to 2147483647
Introduced16.0.R1

Platforms

All

subscriber-interface [interface-name] string
Synopsis Enter the subscriber-interface list instance
Contextconfigure service ies string subscriber-interface string
Treesubscriber-interface
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[interface-name] string
Synopsis Subscriber interface name
Context configure service ies string subscriber-interface string
Treesubscriber-interface
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the subscriber interface
Contextconfigure service ies string subscriber-interface string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

fwd-service reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisForwarding service name
Contextconfigure service ies string subscriber-interface string fwd-service reference
Treefwd-service

Reference

configure service vprn string

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

group-interface [group-interface-name] string
Synopsis Enter the group-interface list instance
Contextconfigure service ies string subscriber-interface string group-interface string
Treegroup-interface
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[group-interface-name] string
Synopsis Group interface name
Context configure service ies string subscriber-interface string group-interface string
Treegroup-interface
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

bonding-parameters
Synopsis Enter the bonding-parameters context
Contextconfigure service ies string subscriber-interface string group-interface string bonding-parameters
Treebonding-parameters
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

connection [connection-index] number
Synopsis Enter the connection list instance
Contextconfigure service ies string subscriber-interface string group-interface string bonding-parameters connection number
Treeconnection
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

fpe reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisFPE that provisions bonding functionality
Contextconfigure service ies string subscriber-interface string group-interface string bonding-parameters fpe reference
Treefpe

Reference

configure fwd-path-ext fpe number

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

multicast
Synopsis Enter the multicast context
Context configure service ies string subscriber-interface string group-interface string bonding-parameters multicast
Treemulticast
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

connection (number | keyword)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMulticast connection
Contextconfigure service ies string subscriber-interface string group-interface string bonding-parameters multicast connection (number | keyword)
Treeconnection
Range1 to 2
Optionsuse-incoming
Defaultuse-incoming
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

brg
Synopsis Enter the brg context
Context configure service ies string subscriber-interface string group-interface string brg
Treebrg
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

cflowd-parameters
Synopsis Enter the cflowd-parameters context
Contextconfigure service ies string subscriber-interface string group-interface string cflowd-parameters
Treecflowd-parameters
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

sampling [sampling-type] keyword
Synopsis Enter the sampling list instance
Contextconfigure service ies string subscriber-interface string group-interface string cflowd-parameters sampling keyword
Treesampling
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[sampling-type] keyword
Synopsis Traffic sampling type
Context configure service ies string subscriber-interface string group-interface string cflowd-parameters sampling keyword
Treesampling

Description

This command configures the type of traffic to be sampled on the associated IP interface.

Optionsunicast, multicast, both

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

direction keyword
Synopsis Direction of traffic for cflowd sampling
Contextconfigure service ies string subscriber-interface string group-interface string cflowd-parameters sampling keyword direction keyword
Treedirection

Description

This command configures the direction in which sampling occurs on the associated IP interfaces.

Optionsingress-only, egress-only, both
Defaultingress-only
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

type keyword
Synopsis Type of cflowd analysis
Context configure service ies string subscriber-interface string group-interface string cflowd-parameters sampling keyword type keyword
Treetype

Description

This command configures the cflowd sampling type on the associated IP interface.

Optionsacl, interface

Notes

This element is mandatory.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

data-trigger
Synopsis Enter the data-trigger context
Contextconfigure service ies string subscriber-interface string group-interface string data-trigger
Treedata-trigger
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

accept-ipv6-link-local-address boolean
Synopsis Enable IPv6 Link Local Address to start authentication
Contextconfigure service ies string subscriber-interface string group-interface string data-trigger accept-ipv6-link-local-address boolean
Treeaccept-ipv6-link-local-address

Description

When configured to true, the system triggers authentication of the subscriber based on an IPv6 packet with a source IP Link Local Address (LLA). The authentication trigger only occurs if the anti-spoof is type nh-mac. If the anti-spoof is not nh-mac, the packet with an IPv6 LLA is ignored.

When configured to false, the system ignores all IPv6 packets with a LLA as a source IP address.

Defaultfalse
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

dynamic-routes-track-srrp
Synopsis Enable the dynamic-routes-track-srrp context
Contextconfigure service ies string subscriber-interface string group-interface string dynamic-routes-track-srrp
Treedynamic-routes-track-srrp
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

gtp-parameters
Synopsis Enter the gtp-parameters context
Contextconfigure service ies string subscriber-interface string group-interface string gtp-parameters
Treegtp-parameters
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

fpe reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPE that provisions the GTP user interface
Contextconfigure service ies string subscriber-interface string group-interface string gtp-parameters fpe reference
Treefpe

Reference

configure fwd-path-ext fpe number

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

ingress
Synopsis Enter the ingress context
Context configure service ies string subscriber-interface string group-interface string ingress
Treeingress
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipoe-linking
Synopsis Enter the ipoe-linking context
Contextconfigure service ies string subscriber-interface string group-interface string ipoe-linking
Treeipoe-linking
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

gratuitous-router-advertisement boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSend unsolicited router advertisement after DHCP setup
Contextconfigure service ies string subscriber-interface string group-interface string ipoe-linking gratuitous-router-advertisement boolean
Treegratuitous-router-advertisement
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

shared-circuit-id boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable circuit ID in DHCPv4 Option82 to validate DHCPv6
Contextconfigure service ies string subscriber-interface string group-interface string ipoe-linking shared-circuit-id boolean
Treeshared-circuit-id
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipoe-session
Synopsis Enter the ipoe-session context
Contextconfigure service ies string subscriber-interface string group-interface string ipoe-session
Treeipoe-session
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

force-auth
Synopsis Enter the force-auth context
Context configure service ies string subscriber-interface string group-interface string ipoe-session force-auth
Treeforce-auth
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipoe-session-policy reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPoE Session policy to be used for new sessions
Contextconfigure service ies string subscriber-interface string group-interface string ipoe-session ipoe-session-policy reference
Treeipoe-session-policy

Reference

configure subscriber-mgmt ipoe-session-policy string

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

stateless-redundancy boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRemove IPoE sessions when the system becomes stand-by in a stateless multi-chassis redundancy setup
Contextconfigure service ies string subscriber-interface string group-interface string ipoe-session stateless-redundancy boolean
Treestateless-redundancy
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv4
Synopsis Enter the ipv4 context
Context configure service ies string subscriber-interface string group-interface string ipv4
Treeipv4
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

arp-host
Synopsis Enter the arp-host context
Context configure service ies string subscriber-interface string group-interface string ipv4 arp-host
Treearp-host
Introduced16.0.R6

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

dhcp
Synopsis Enter the dhcp context
Context configure service ies string subscriber-interface string group-interface string ipv4 dhcp
Treedhcp
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-applications
Synopsis Enter the client-applications context
Contextconfigure service ies string subscriber-interface string group-interface string ipv4 dhcp client-applications
Treeclient-applications
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

gi-address string
Synopsis GI address for the DHCP relay
Context configure service ies string subscriber-interface string group-interface string ipv4 dhcp gi-address string
Treegi-address

Description

This command configures the GI address to distinguish between the different subscriber interfaces (and potentially group interfaces) defined when the router functions as a DHCP relay.

By default, the GI address used in the relayed DHCP packet is the primary IP address of a normal IES interface. Specifying the GI address allows the user to choose a secondary address. For group interfaces, a GI address must be specified under the group interface DHCP context or subscriber interface DHCP context for DHCP to function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lease-populate
Synopsis Enter the lease-populate context
Contextconfigure service ies string subscriber-interface string group-interface string ipv4 dhcp lease-populate
Treelease-populate
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

l2-header
Synopsis Enable the l2-header context
Context configure service ies string subscriber-interface string group-interface string ipv4 dhcp lease-populate l2-header
Treel2-header
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

offer-selection
Synopsis Enter the offer-selection context
Contextconfigure service ies string subscriber-interface string group-interface string ipv4 dhcp offer-selection
Treeoffer-selection
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-mac
Synopsis Enter the client-mac context
Context configure service ies string subscriber-interface string group-interface string ipv4 dhcp offer-selection client-mac
Treeclient-mac

Notes

The following elements are part of a choice: client-mac or server.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

discover-delay number
Synopsis Delay before sending DHCP Discover messages
Contextconfigure service ies string subscriber-interface string group-interface string ipv4 dhcp offer-selection discover-delay number
Treediscover-delay

Description

This command configures the time to delay sending DHCP Discover messages. The delay is applied to all DHCP Discover messages for which no per DHCP server or per client MAC delay is configured.

Range1 to 100
Unitsdeciseconds
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

server [ipv4-address] string
Synopsis Enter the server list instance
Contextconfigure service ies string subscriber-interface string group-interface string ipv4 dhcp offer-selection server string
Treeserver
Max. Instances8

Notes

The following elements are part of a choice: client-mac or server.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

option-82
Synopsis Enter the option-82 context
Context configure service ies string subscriber-interface string group-interface string ipv4 dhcp option-82
Treeoption-82

Description

Commands in this context configure the processing required when the router receives a DHCP request that already has an Option 82 field in the packet.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

circuit-id
Synopsis Enter the circuit-id context
Context configure service ies string subscriber-interface string group-interface string ipv4 dhcp option-82 circuit-id
Treecircuit-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

vlan-ascii-tuple
Synopsis Include the VLAN ID and dot1p bits in the ASCII tuple
Contextconfigure service ies string subscriber-interface string group-interface string ipv4 dhcp option-82 circuit-id vlan-ascii-tuple
Treevlan-ascii-tuple

Description

When configured, the router includes the VLAN ID and dot1p bits with the ASCII-tuple information. This only occurs on dot1q and QinQ-encapsulated ports. When the Option 82 bits are stripped, dot1p bits are copied to the Ethernet header of the outgoing packet.

When unconfigured, the router leaves the circuit ID sub-option of the DHCP packet empty.

Notes

The following elements are part of a choice: ascii-tuple, ifindex, none, sap-id, or vlan-ascii-tuple.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

remote-id
Synopsis Enter the remote-id context
Context configure service ies string subscriber-interface string group-interface string ipv4 dhcp option-82 remote-id
Treeremote-id

Description

Commands in this context configure the remote IP sub-option of the DHCP packet with the identity of the remote host end (typically the DHCP client).

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

vendor-specific-option
Synopsis Enter the vendor-specific-option context
Contextconfigure service ies string subscriber-interface string group-interface string ipv4 dhcp option-82 vendor-specific-option
Treevendor-specific-option

Description

Commands in this context configure the Nokia Vendor-Specific Option (VSO) of the DHCP packet.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

proxy-server
Synopsis Enter the proxy-server context
Contextconfigure service ies string subscriber-interface string group-interface string ipv4 dhcp proxy-server
Treeproxy-server
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lease-time
Synopsis Enter the lease-time context
Context configure service ies string subscriber-interface string group-interface string ipv4 dhcp proxy-server lease-time
Treelease-time
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

relay-proxy
Synopsis Enable the relay-proxy context
Contextconfigure service ies string subscriber-interface string group-interface string ipv4 dhcp relay-proxy
Treerelay-proxy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

server string
Synopsis IP addresses for DHCP server requests
Contextconfigure service ies string subscriber-interface string group-interface string ipv4 dhcp server string
Treeserver

Description

This command configures a list of servers that this interface forwards requests to.

The operator can enter the list of servers as either IP addresses or fully qualified domain names. The operator must specify at least one server specified for DHCP relay to work. If there are multiple servers, the system forwards the request to all the servers in the list.

Max. Instances8

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

trusted boolean
Synopsis Relay untrusted packets
Context configure service ies string subscriber-interface string group-interface string ipv4 dhcp trusted boolean
Treetrusted

Description

When configured to true, the router enables the trusted mode on the interface. When enabled, the relay agent changes the existing GI address (of the request) to the ingress interface, and forwards the request.

A DHCP request that contains a GI address of 0.0.0.0 and an Option 82 field in the packet is discarded unless it arrives on a trusted circuit.

This behavior only applies if the Relay Agent Information Option action is to keep the existing information. When the Option 82 field is replaced by the relay agent, the original Option 82 information is lost, and there is no reason to enable the trusted option.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

icmp
Synopsis Enter the icmp context
Context configure service ies string subscriber-interface string group-interface string ipv4 icmp
Treeicmp
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

param-problem
Synopsis Enter the param-problem context
Contextconfigure service ies string subscriber-interface string group-interface string ipv4 icmp param-problem
Treeparam-problem

Description

Commands in this context specify the settings for ICMP Parameter Problem messages generated by the interface.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

redirects
Synopsis Enter the redirects context
Context configure service ies string subscriber-interface string group-interface string ipv4 icmp redirects
Treeredirects

Description

Commands in this context configure the settings for ICMP redirect messages generated by the interface.

The system sends ICMP redirect messages to alert the sending node that a more optimal route is available on another router on the same subnetwork.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ttl-expired
Synopsis Enter the ttl-expired context
Context configure service ies string subscriber-interface string group-interface string ipv4 icmp ttl-expired
Treettl-expired

Description

Commands in this context configure the settings for ICMP TTL expired messages generated by the interface.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

use-matching-address boolean
Synopsis Use the subscriber interface address as source address
Contextconfigure service ies string subscriber-interface string group-interface string ipv4 icmp ttl-expired use-matching-address boolean
Treeuse-matching-address

Description

When configured to true, the system uses a matching subscriber interface address as the source address of the ICMP TTL expired message.

For matching to occur, the source address of the offending packet must be in the same subnet of the subscriber interface address.

When configured to false, the system uses the first configured address.

Defaultfalse
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

unreachables
Synopsis Enter the unreachables context
Contextconfigure service ies string subscriber-interface string group-interface string ipv4 icmp unreachables
Treeunreachables

Description

Commands in this context specify the settings for ICMP host and network destination unreachable messages generated by the interface.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ignore-df-bit boolean
Synopsis Ignore DF bit in the IPv4 header when fragmenting
Contextconfigure service ies string subscriber-interface string group-interface string ipv4 ignore-df-bit boolean
Treeignore-df-bit

Description

When configured to true, fragmentation is applied according to the applicable egress MTU instead of the DF bit for frames egressing the WLAN-GW group. The DF bit is reset for frames that are fragmented.

When configured to false, the router fragments a packet larger than the MTU if the DF bit is set to 0 and drops the packet if the DF bit is set to 1.

Defaultfalse
Introduced20.5.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

neighbor-discovery
Synopsis Enter the neighbor-discovery context
Contextconfigure service ies string subscriber-interface string group-interface string ipv4 neighbor-discovery
Treeneighbor-discovery
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

local-proxy-arp boolean
Synopsis Enable local proxy ARP on interface
Context configure service ies string subscriber-interface string group-interface string ipv4 neighbor-discovery local-proxy-arp boolean
Treelocal-proxy-arp

Description

When configured to true, the router enables local proxy ARP on the interface.

When configured to false, the router does not respond to ARP requests for addresses on the same subnet.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

urpf-check
Synopsis Enable the urpf-check context
Context configure service ies string subscriber-interface string group-interface string ipv4 urpf-check
Treeurpf-check
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv6
Synopsis Enable the ipv6 context
Context configure service ies string subscriber-interface string group-interface string ipv6
Treeipv6
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

auto-reply
Synopsis Enter the auto-reply context
Context configure service ies string subscriber-interface string group-interface string ipv6 auto-reply
Treeauto-reply
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

dhcp6
Synopsis Enter the dhcp6 context
Context configure service ies string subscriber-interface string group-interface string ipv6 dhcp6
Treedhcp6
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

option
Synopsis Enter the option context
Context configure service ies string subscriber-interface string group-interface string ipv6 dhcp6 option
Treeoption
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

interface-id
Synopsis Enter the interface-id context
Contextconfigure service ies string subscriber-interface string group-interface string ipv6 dhcp6 option interface-id
Treeinterface-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

pd-managed-route
Synopsis Enable the pd-managed-route context
Contextconfigure service ies string subscriber-interface string group-interface string ipv6 dhcp6 pd-managed-route
Treepd-managed-route
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

proxy-server
Synopsis Enter the proxy-server context
Contextconfigure service ies string subscriber-interface string group-interface string ipv6 dhcp6 proxy-server
Treeproxy-server
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-applications
Synopsis Enter the client-applications context
Contextconfigure service ies string subscriber-interface string group-interface string ipv6 dhcp6 proxy-server client-applications
Treeclient-applications
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

server-id
Synopsis Enter the server-id context
Context configure service ies string subscriber-interface string group-interface string ipv6 dhcp6 proxy-server server-id
Treeserver-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

relay
Synopsis Enter the relay context
Context configure service ies string subscriber-interface string group-interface string ipv6 dhcp6 relay
Treerelay
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

advertise-selection
Synopsis Enter the advertise-selection context
Contextconfigure service ies string subscriber-interface string group-interface string ipv6 dhcp6 relay advertise-selection
Treeadvertise-selection
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-mac
Synopsis Enter the client-mac context
Context configure service ies string subscriber-interface string group-interface string ipv6 dhcp6 relay advertise-selection client-mac
Treeclient-mac

Notes

The following elements are part of a choice: client-mac or server.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

preference-option
Synopsis Enter the preference-option context
Contextconfigure service ies string subscriber-interface string group-interface string ipv6 dhcp6 relay advertise-selection client-mac preference-option
Treepreference-option

Description

Commands in this context configure the DHCPv6 preference option that is inserted in the DHCPv6 Advertise message.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

preference-option
Synopsis Enter the preference-option context
Contextconfigure service ies string subscriber-interface string group-interface string ipv6 dhcp6 relay advertise-selection preference-option
Treepreference-option

Description

Commands in this context configure the DHCPv6 preference option that is inserted in the DHCPv6 Advertise message.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

server [ipv6-address] string
Synopsis Enter the server list instance
Contextconfigure service ies string subscriber-interface string group-interface string ipv6 dhcp6 relay advertise-selection server string
Treeserver
Max. Instances8

Notes

The following elements are part of a choice: client-mac or server.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

preference-option
Synopsis Enter the preference-option context
Contextconfigure service ies string subscriber-interface string group-interface string ipv6 dhcp6 relay advertise-selection server string preference-option
Treepreference-option

Description

Commands in this context configure the DHCPv6 preference option that is inserted in the DHCPv6 Advertise message.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

solicit-delay number
Synopsis Delay before sending DHCPv6 Solicit messages
Contextconfigure service ies string subscriber-interface string group-interface string ipv6 dhcp6 relay advertise-selection solicit-delay number
Treesolicit-delay

Description

This command configures the time to delay DHCPv6 Solicit messages. The delay is applied to DHCPv6 Solicit messages for which no overriding value is configured in the server instance or the client-mac context.

Range1 to 100
Unitsdeciseconds
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-applications
Synopsis Enter the client-applications context
Contextconfigure service ies string subscriber-interface string group-interface string ipv6 dhcp6 relay client-applications
Treeclient-applications
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lease-split
Synopsis Enter the lease-split context
Context configure service ies string subscriber-interface string group-interface string ipv6 dhcp6 relay lease-split
Treelease-split

Description

Commands in this context configure DHCPv6 lease split.

DHCPv6 lease split is active when administratively enabled and for all IA_NA and IA_PD options in the transaction, the configured lease split valid lifetime (short lease time) is less than or equal to one of the following:

  • the renew time T1 committed by the server (long renew time)

  • half of the preferred lifetime committed by the server when T1 committed by the server equals zero

Introduced21.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

snooping
Synopsis Enter the snooping context
Context configure service ies string subscriber-interface string group-interface string ipv6 dhcp6 snooping
Treesnooping
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

neighbor-discovery
Synopsis Enter the neighbor-discovery context
Contextconfigure service ies string subscriber-interface string group-interface string ipv6 neighbor-discovery
Treeneighbor-discovery
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

router-advertisements
Synopsis Enter the router-advertisements context
Contextconfigure service ies string subscriber-interface string group-interface string ipv6 router-advertisements
Treerouter-advertisements
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

options
Synopsis Enter the options context
Context configure service ies string subscriber-interface string group-interface string ipv6 router-advertisements options
Treeoptions
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

dns
Synopsis Enter the dns context
Context configure service ies string subscriber-interface string group-interface string ipv6 router-advertisements options dns
Treedns
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

prefix-options
Synopsis Enter the prefix-options context
Contextconfigure service ies string subscriber-interface string group-interface string ipv6 router-advertisements prefix-options
Treeprefix-options
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

router-solicit
Synopsis Enter the router-solicit context
Contextconfigure service ies string subscriber-interface string group-interface string ipv6 router-solicit
Treerouter-solicit
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

urpf-check
Synopsis Enable the urpf-check context
Context configure service ies string subscriber-interface string group-interface string ipv6 urpf-check
Treeurpf-check
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

local-address-assignment
Synopsis Enter the local-address-assignment context
Contextconfigure service ies string subscriber-interface string group-interface string local-address-assignment
Treelocal-address-assignment
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv4
Synopsis Enter the ipv4 context
Context configure service ies string subscriber-interface string group-interface string local-address-assignment ipv4
Treeipv4
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-applications
Synopsis Enter the client-applications context
Contextconfigure service ies string subscriber-interface string group-interface string local-address-assignment ipv4 client-applications
Treeclient-applications
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv6
Synopsis Enter the ipv6 context
Context configure service ies string subscriber-interface string group-interface string local-address-assignment ipv6
Treeipv6
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-applications
Synopsis Enter the client-applications context
Contextconfigure service ies string subscriber-interface string group-interface string local-address-assignment ipv6 client-applications
Treeclient-applications
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

pppoe
Synopsis Enter the pppoe context
Context configure service ies string subscriber-interface string group-interface string pppoe
Treepppoe
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

dhcp-client
Synopsis Enter the dhcp-client context
Context configure service ies string subscriber-interface string group-interface string pppoe dhcp-client
Treedhcp-client
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

sap [sap-id] string
Synopsis Enter the sap list instance
Context configure service ies string subscriber-interface string group-interface string sap string
Treesap
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[sap-id] string
Synopsis SAP ID
Contextconfigure service ies string subscriber-interface string group-interface string sap string
Treesap
String Length1 to 45

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

anti-spoof keyword
Synopsis Type of anti-spoof filtering
Context configure service ies string subscriber-interface string group-interface string sap string anti-spoof keyword
Treeanti-spoof
Optionssource-ip-addr, source-ip-and-mac-addr, next-hop-ip-and-mac-addr
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

cpu-protection
Synopsis Enter the cpu-protection context
Contextconfigure service ies string subscriber-interface string group-interface string sap string cpu-protection
Treecpu-protection
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s

eth-cfm-monitoring
Synopsis Enable the eth-cfm-monitoring context
Contextconfigure service ies string subscriber-interface string group-interface string sap string cpu-protection eth-cfm-monitoring
Treeeth-cfm-monitoring

Notes

The following elements are part of a choice: eth-cfm-monitoring, ip-src-monitoring, or mac-monitoring.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s

default-host
Synopsis Enter the default-host context
Contextconfigure service ies string subscriber-interface string group-interface string sap string default-host
Treedefault-host
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

ipv4 [address] reference prefix-length number
Synopsis Enter the ipv4 list instance
Context configure service ies string subscriber-interface string group-interface string sap string default-host ipv4 reference prefix-length number
Treeipv4
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

ipv6 [address] string prefix-length number
Synopsis Enter the ipv6 list instance
Context configure service ies string subscriber-interface string group-interface string sap string default-host ipv6 string prefix-length number
Treeipv6
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

egress
Synopsis Enter the egress context
Context configure service ies string subscriber-interface string group-interface string sap string egress
Treeegress
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

agg-rate
Synopsis Enter the agg-rate context
Context configure service ies string subscriber-interface string group-interface string sap string egress agg-rate
Treeagg-rate
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

filter
Synopsis Enter the filter context
Context configure service ies string subscriber-interface string group-interface string sap string egress filter
Treefilter
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

qos
Synopsis Enter the qos context
Context configure service ies string subscriber-interface string group-interface string sap string egress qos
Treeqos
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

policer-control-policy
Synopsis Enter the policer-control-policy context
Contextconfigure service ies string subscriber-interface string group-interface string sap string egress qos policer-control-policy
Treepolicer-control-policy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

sap-egress
Synopsis Enter the sap-egress context
Context configure service ies string subscriber-interface string group-interface string sap string egress qos sap-egress
Treesap-egress
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service ies string subscriber-interface string group-interface string sap string egress qos scheduler-policy
Treescheduler-policy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

virtual-port
Synopsis Enter the virtual-port context
Contextconfigure service ies string subscriber-interface string group-interface string sap string egress virtual-port
Treevirtual-port
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

eth-cfm
Synopsis Enter the eth-cfm context
Context configure service ies string subscriber-interface string group-interface string sap string eth-cfm
Treeeth-cfm
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

collect-lmm-fc-stats
Synopsis Enter the collect-lmm-fc-stats context
Contextconfigure service ies string subscriber-interface string group-interface string sap string eth-cfm collect-lmm-fc-stats
Treecollect-lmm-fc-stats

Description

Commands in this context configure per forwarding class (FC) LMM information collection.

The commands fc-in-profile and fc in this context are mutually exclusive. The commands apply to either profile-aware or profile-unaware FCs respectively. 

This command and the collect-lmm-stats command are mutually exclusive when there is entity resource contention.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

fc keyword
Synopsis Forwarding class name for profile-unaware counter
Contextconfigure service ies string subscriber-interface string group-interface string sap string eth-cfm collect-lmm-fc-stats fc keyword
Treefc

Description

This command configures individual counters for the specified FCs without regard for profile. The system includes all countable packets that match a configured FC, regardless of profile, in this counter.

An FC specified as part of this command and for this specific context cannot be specified as a profile-aware FC using the fc-in-profile command under the collect-lmm-fc-stats context. 

When this command is reentered, a differential is performed. Omitted FCs stop counting, newly added FCs start counting, and unchanged FCs continue to count.

Optionsbe, l2, af, l1, h2, ef, h1, nc
Max. Instances 8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

fc-in-profile keyword
Synopsis Forwarding class name for profile-aware counter
Contextconfigure service ies string subscriber-interface string group-interface string sap string eth-cfm collect-lmm-fc-stats fc-in-profile keyword
Treefc-in-profile

Description

This command configures individual counters for the specified FCs with regard to profile. The system includes all countable packets that match a configured FC and that are deemed to be in-profile in this counter.

An FC specified as part of this command and for this specific context cannot be specified as a profile-unaware FC using the fc command under the collect-lmm-fc-stats context.

When this command is reentered, a differential is performed. Omitted FCs stop counting, newly added FCs start counting, and unchanged FCs continue to count.

Optionsbe, l2, af, l1, h2, ef, h1, nc
Max. Instances 8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

collect-lmm-stats boolean
Synopsis Collect statistics for loss measurement message tests
Contextconfigure service ies string subscriber-interface string group-interface string sap string eth-cfm collect-lmm-stats boolean
Treecollect-lmm-stats

Description

When configured to true, the router instantiates the statistical counter to transmit and receive packets for the LAG facility MEP bindings.

The show eth-cfm collect-lmm-stats command displays entities that have been enabled to collect transit and receive counters.

When configured to false, the router does not instantiate the counter and the LMM PDU associated with the MEP does not populate the counters in the packet.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

mep md-admin-name reference ma-admin-name reference mep-id number
Synopsis Enter the mep list instance
Context configure service ies string subscriber-interface string group-interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number
Treemep
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

alarm-notification
Synopsis Enter the alarm-notification context
Contextconfigure service ies string subscriber-interface string group-interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number alarm-notification
Treealarm-notification

Description

Commands in this context configure the Fault Notification Generator (FNG) time values to raise an alarm or reset the CCM defect alarm. 

Use these timers for network management processes. The timers are not tied into delaying the notification to the fault management system on the network element and do not affect fault propagation mechanisms.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

ccm-padding-size number
Synopsis Number of octets of padding to insert in CCM packets
Contextconfigure service ies string subscriber-interface string group-interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number ccm-padding-size number
Treeccm-padding-size

Description

This command sets the byte size of the optional Data TLV to be included in the ETH-CC PDU.

This command increases the size of the ETH-CC PDU by the configured value. The base size of the ETH-CC PDU, including the Interface Status TLV and Port Status TLV, is 83 bytes not including the Layer 2 encapsulation. CCM padding is not supported when the CCM interval (configured through configure eth-cfm domain association ccm-interval) is less than 1 second.

Range3 to 1500
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

csf
Synopsis Enable the csf context
Context configure service ies string subscriber-interface string group-interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number csf
Treecsf
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

eth-test
Synopsis Enable the eth-test context
Context configure service ies string subscriber-interface string group-interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test
Treeeth-test

Description

Commands in this context configure information used by the Ethernet Test (ETH-TST) packet. The commands must be configured on both the sender and the receiver nodes. The test packets are used with the oam eth-cfm eth-test command.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

test-pattern
Synopsis Enter the test-pattern context
Contextconfigure service ies string subscriber-interface string group-interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test test-pattern
Treetest-pattern

Description

Commands in this context specify the test pattern for the ETH-TST frames. The pattern does not have to be the same on the sender and the receiver.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

pattern keyword
Synopsis Test pattern for Ethernet Test frames
Contextconfigure service ies string subscriber-interface string group-interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test test-pattern pattern keyword
Treepattern

Description

This command specifies the test pattern of the Ethernet Test (ETH-TST) frames. This does not have to be configured the same on the sender and the receiver.

Optionsall-zeros, all-ones
Default all-zeros
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

grace
Synopsis Enter the grace context
Context configure service ies string subscriber-interface string group-interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace
Treegrace

Description

Commands in this context configure the Nokia ETH-CFM Grace function and the ITU-T Y.1731 Ethernet Expected Default (ETH-ED) function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

eth-ed
Synopsis Enter the eth-ed context
Context configure service ies string subscriber-interface string group-interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-ed
Treeeth-ed

Description

Commands in this context configure the ITU-T Y.1731 ETH-ED function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

eth-vsm-grace
Synopsis Enter the eth-vsm-grace context
Contextconfigure service ies string subscriber-interface string group-interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace
Treeeth-vsm-grace

Description

Commands in this context configure the Nokia ETH-CFM Grace function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

rx-eth-vsm-grace boolean
Synopsis Receive and process Nokia ETH-CFM Grace PDU on the MEP
Contextconfigure service ies string subscriber-interface string group-interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace rx-eth-vsm-grace boolean
Treerx-eth-vsm-grace

Description

When configured to true, the router enables the Nokia Grace function, which is a vendor-specific PDU that informs MEP peers that the local node may be entering a period of expected defect.

When configured to false, the router disables the Nokia Grace function.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

tx-eth-vsm-grace boolean
Synopsis Transmit ETH-ED PDUs from the MEP
Context configure service ies string subscriber-interface string group-interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace tx-eth-vsm-grace boolean
Treetx-eth-vsm-grace

Description

When configured to true, the router can transmit the Nokia ETH-CFM Grace PDU from the MEP when a system soft reset notification is received for one or more cards.

The Nokia Grace function is a vendor-specific PDU that informs MEP peers that the local node may be entering a period of expected defect.

The operator must configure the configure system eth-cfm grace command to instruct the system that the node is capable of transmitting expected-defect windows to peers. The system can only transmit one form of ETH-CFM grace (Nokia ETH-CFM Grace or ITU-T Y.1731 ETH-ED).

When configured to false, the router disables the transmission of the Nokia ETH-CFM Grace PDU from the MEP.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

squelch-ingress-levels number
Synopsis Levels for which ETH-CFM packets are silently discarded
Contextconfigure service ies string subscriber-interface string group-interface string sap string eth-cfm squelch-ingress-levels number
Treesquelch-ingress-levels

Description

This command defines the levels of the ETH-CFM packets that are silently discarded on ingress into the SAP or SDP binding from the wire that matches the service delineation of the SAP or SDP binding. All ETH-CFM packets inbound to the SAP or SDP binding that match the configured levels are dropped without regard for any other ETH-CFM criteria. No statistical information or drop count is available for any ETH-CFM packet that is silently discarded by this option.

The list of levels must be a complete contiguous list from 0 up to the highest level that will be dropped.

Range0 to 7
Max. Instances8
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

fwd-wholesale
Synopsis Enter the fwd-wholesale context
Contextconfigure service ies string subscriber-interface string group-interface string sap string fwd-wholesale
Treefwd-wholesale
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

igmp-host-tracking
Synopsis Enter the igmp-host-tracking context
Contextconfigure service ies string subscriber-interface string group-interface string sap string igmp-host-tracking
Treeigmp-host-tracking
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ingress
Synopsis Enter the ingress context
Context configure service ies string subscriber-interface string group-interface string sap string ingress
Treeingress
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

filter
Synopsis Enter the filter context
Context configure service ies string subscriber-interface string group-interface string sap string ingress filter
Treefilter
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

qos
Synopsis Enter the qos context
Context configure service ies string subscriber-interface string group-interface string sap string ingress qos
Treeqos
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

policer-control-policy
Synopsis Enter the policer-control-policy context
Contextconfigure service ies string subscriber-interface string group-interface string sap string ingress qos policer-control-policy
Treepolicer-control-policy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

sap-ingress
Synopsis Enter the sap-ingress context
Context configure service ies string subscriber-interface string group-interface string sap string ingress qos sap-ingress
Treesap-ingress
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service ies string subscriber-interface string group-interface string sap string ingress qos scheduler-policy
Treescheduler-policy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lag
Synopsis Enter the lag context
Context configure service ies string subscriber-interface string group-interface string sap string lag
Treelag
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

link-map-profile number
Synopsis LAG link map profile for a SAP or network interface
Contextconfigure service ies string subscriber-interface string group-interface string sap string lag link-map-profile number
Treelink-map-profile

Description

This command assigns a preconfigured LAG link map profile to a SAP or network interface configured on a LAG or a PW port that exists on a LAG. After an operator assigns a LAG link map profile, the system rehashes the SAP or network interface egress traffic over the LAG as required by the new configuration.

If the LAG link map profile for a SAP or network interface is deleted, the system reverts back to per-flow hashing.

Range1 to 64
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

per-link-hash
Synopsis Enter the per-link-hash context
Contextconfigure service ies string subscriber-interface string group-interface string sap string lag per-link-hash
Treeper-link-hash
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

static-host
Synopsis Enter the static-host context
Context configure service ies string subscriber-interface string group-interface string sap string static-host
Treestatic-host
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv4 [ip] string mac string
Synopsis Enter the ipv4 list instance
Context configure service ies string subscriber-interface string group-interface string sap string static-host ipv4 string mac string
Treeipv4
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

mac string
Synopsis MAC address used by the static host
Context configure service ies string subscriber-interface string group-interface string sap string static-host ipv4 string mac string
Treeipv4
MD-CLI Default00:00:00:00:00:00

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

app-profile
Synopsis Enter the app-profile context
Context configure service ies string subscriber-interface string group-interface string sap string static-host ipv4 string mac string app-profile
Treeapp-profile
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

managed-route [prefix] string
Synopsis Enter the managed-route list instance
Contextconfigure service ies string subscriber-interface string group-interface string sap string static-host ipv4 string mac string managed-route string
Treemanaged-route

Description

Commands in this context configure managed route parameters.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[prefix] string
Synopsis Managed route prefix associated with IPv4 static host
Contextconfigure service ies string subscriber-interface string group-interface string sap string static-host ipv4 string mac string managed-route string
Treemanaged-route

Description

This command configures the managed route prefix. The prefix length must be in the range of 1 to 32.

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

cpe-check
Synopsis Enable the cpe-check context
Context configure service ies string subscriber-interface string group-interface string sap string static-host ipv4 string mac string managed-route string cpe-check
Treecpe-check
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

destination-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP address of the target CPE device
Contextconfigure service ies string subscriber-interface string group-interface string sap string static-host ipv4 string mac string managed-route string cpe-check destination-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treedestination-ip-address
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

failed-action
Synopsis Enter the failed-action context
Contextconfigure service ies string subscriber-interface string group-interface string sap string static-host ipv4 string mac string managed-route string cpe-check failed-action
Treefailed-action
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

subscriber-id
Synopsis Enter the subscriber-id context
Contextconfigure service ies string subscriber-interface string group-interface string sap string static-host ipv4 string mac string subscriber-id
Treesubscriber-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv6 [prefix] string mac string
Synopsis Enter the ipv6 list instance
Context configure service ies string subscriber-interface string group-interface string sap string static-host ipv6 string mac string
Treeipv6
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

app-profile
Synopsis Enter the app-profile context
Context configure service ies string subscriber-interface string group-interface string sap string static-host ipv6 string mac string app-profile
Treeapp-profile
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

managed-route [ipv6-prefix] string
Synopsis Enter the managed-route list instance
Contextconfigure service ies string subscriber-interface string group-interface string sap string static-host ipv6 string mac string managed-route string
Treemanaged-route

Description

Commands in this context configure managed route parameters.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[ipv6-prefix] string
Synopsis Managed route prefix associated with IPv6 static host
Contextconfigure service ies string subscriber-interface string group-interface string sap string static-host ipv6 string mac string managed-route string
Treemanaged-route

Description

This command configures the managed route prefix. The prefix length must be in the range of 1 to 128.

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

cpe-check
Synopsis Enable the cpe-check context
Context configure service ies string subscriber-interface string group-interface string sap string static-host ipv6 string mac string managed-route string cpe-check
Treecpe-check
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

destination-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP address of the target CPE device
Contextconfigure service ies string subscriber-interface string group-interface string sap string static-host ipv6 string mac string managed-route string cpe-check destination-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treedestination-ip-address
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

failed-action
Synopsis Enter the failed-action context
Contextconfigure service ies string subscriber-interface string group-interface string sap string static-host ipv6 string mac string managed-route string cpe-check failed-action
Treefailed-action
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

subscriber-id
Synopsis Enter the subscriber-id context
Contextconfigure service ies string subscriber-interface string group-interface string sap string static-host ipv6 string mac string subscriber-id
Treesubscriber-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

mac-learning
Synopsis Enter the mac-learning context
Contextconfigure service ies string subscriber-interface string group-interface string sap string static-host mac-learning
Treemac-learning
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

sub-sla-mgmt
Synopsis Enter the sub-sla-mgmt context
Contextconfigure service ies string subscriber-interface string group-interface string sap string sub-sla-mgmt
Treesub-sla-mgmt
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

defaults
Synopsis Enter the defaults context
Context configure service ies string subscriber-interface string group-interface string sap string sub-sla-mgmt defaults
Treedefaults
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

int-dest-id
Synopsis Enter the int-dest-id context
Context configure service ies string subscriber-interface string group-interface string sap string sub-sla-mgmt defaults int-dest-id
Treeint-dest-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

subscriber-id
Synopsis Enter the subscriber-id context
Contextconfigure service ies string subscriber-interface string group-interface string sap string sub-sla-mgmt defaults subscriber-id
Treesubscriber-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

single-sub-parameters
Synopsis Enter the single-sub-parameters context
Contextconfigure service ies string subscriber-interface string group-interface string sap string sub-sla-mgmt single-sub-parameters
Treesingle-sub-parameters
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

non-sub-traffic
Synopsis Enable the non-sub-traffic context
Contextconfigure service ies string subscriber-interface string group-interface string sap string sub-sla-mgmt single-sub-parameters non-sub-traffic
Treenon-sub-traffic
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

sap-parameters
Synopsis Enter the sap-parameters context
Contextconfigure service ies string subscriber-interface string group-interface string sap-parameters
Treesap-parameters
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

sub-sla-mgmt
Synopsis Enter the sub-sla-mgmt context
Contextconfigure service ies string subscriber-interface string group-interface string sap-parameters sub-sla-mgmt
Treesub-sla-mgmt
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

defaults
Synopsis Enter the defaults context
Context configure service ies string subscriber-interface string group-interface string sap-parameters sub-sla-mgmt defaults
Treedefaults
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

subscriber-id
Synopsis Enter the subscriber-id context
Contextconfigure service ies string subscriber-interface string group-interface string sap-parameters sub-sla-mgmt defaults subscriber-id
Treesubscriber-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

srrp [srrp-id] number
Synopsis Enter the srrp list instance
Context configure service ies string subscriber-interface string group-interface string srrp number
Treesrrp
Max. Instances1
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[srrp-id] number
Synopsis SRRP instance ID
Context configure service ies string subscriber-interface string group-interface string srrp number
Treesrrp
Range1 to 4294967295

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

bfd-liveness
Synopsis Enable the bfd-liveness context
Contextconfigure service ies string subscriber-interface string group-interface string srrp number bfd-liveness
Treebfd-liveness
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

dest-ip string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDestination IPv4 prefix
Contextconfigure service ies string subscriber-interface string group-interface string srrp number bfd-liveness dest-ip string
Treedest-ip

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

interface-name string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisName of the interface running BFD
Contextconfigure service ies string subscriber-interface string group-interface string srrp number bfd-liveness interface-name string
Treeinterface-name
String Length1 to 32

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

message-path reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSAP to use as the SRRP message path
Contextconfigure service ies string subscriber-interface string group-interface string srrp number message-path reference
Treemessage-path

Reference

configure service ies string subscriber-interface string group-interface string sap string

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

monitor-oper-group
Synopsis Enter the monitor-oper-group context
Contextconfigure service ies string subscriber-interface string group-interface string srrp number monitor-oper-group
Treemonitor-oper-group
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

policy reference
Synopsis VRRP priority control policy associated with the SRRP
Contextconfigure service ies string subscriber-interface string group-interface string srrp number policy reference
Treepolicy

Reference

configure vrrp policy number

Max. Instances2

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisGroup interface type
Contextconfigure service ies string subscriber-interface string group-interface string type keyword
Treetype
Optionsplain, lns, wlan-gw, gtp, bonding
Defaultplain
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

wlan-gw
Synopsis Enter the wlan-gw context
Context configure service ies string subscriber-interface string group-interface string wlan-gw
Treewlan-gw
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

gateway-address [address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Enter the gateway-address list instance
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treegateway-address
Max. Instances10
Introduced16.0.R4

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

purpose
Synopsis Enter the purpose context
Context configure service ies string subscriber-interface string group-interface string wlan-gw gateway-address (ipv4-address-no-zone | ipv6-address-no-zone) purpose
Treepurpose
Introduced16.0.R4

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

gateway-router string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRouting instance the WLAN-GW endpoint resides in
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw gateway-router string
Treegateway-router
Introduced16.0.R4

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

group-encryption
Synopsis Enter the group-encryption context
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw group-encryption
Treegroup-encryption
Introduced21.10.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

l2-ap
Synopsis Enter the l2-ap context
Context configure service ies string subscriber-interface string group-interface string wlan-gw l2-ap
Treel2-ap
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

access-point [sap-id] string
Synopsis Enter the access-point list instance
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw l2-ap access-point string
Treeaccess-point
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

epipe-sap-template reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisParameters template for the L2 access point SAP
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw l2-ap access-point string epipe-sap-template reference
Treeepipe-sap-template

Reference

configure service template epipe-sap-template string

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

lanext
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the lanext context
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw lanext
Treelanext
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

max-bd number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of bridge domains
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw lanext max-bd number
Treemax-bd
Range1 to 131071
Default131071
Introduced 16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

learn-ap-mac
Synopsis Enable the learn-ap-mac context
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw learn-ap-mac
Treelearn-ap-mac
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

mcs-peer
Synopsis Enable the mcs-peer context
Context configure service ies string subscriber-interface string group-interface string wlan-gw mcs-peer
Treemcs-peer

Description

Commands in this context configure a multi-chassis synchronization peer.

Introduced23.10.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

address reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP address of the MCS peer
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw mcs-peer address reference
Treeaddress

Description

This command configures the IPv4 address or the global IPv6 unicast address for a multi-chassis synchronization peer.

Reference

configure redundancy multi-chassis peer (ipv4-address-no-zone | ipv6-address-no-zone)

Notes

This element is mandatory.

Introduced23.10.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

sync-tag string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSynchronization tag shared by MCS peers
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw mcs-peer sync-tag string
Treesync-tag

Description

This command configures the synchronization tag for synchronization of ESM and the tunnel state for ESM over soft-GRE with an MCS peer.

String Length1 to 32

Notes

This element is mandatory.

Introduced23.10.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

mobility
Synopsis Enter the mobility context
Context configure service ies string subscriber-interface string group-interface string wlan-gw mobility
Treemobility
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

trigger
Synopsis Enter the trigger context
Context configure service ies string subscriber-interface string group-interface string wlan-gw mobility trigger
Treetrigger
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

promiscuous-mode boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable promiscuous mode for this group interface
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw promiscuous-mode boolean
Treepromiscuous-mode

Description

When configured to true, the router accepts all traffic, including traffic that is not destined for a WLAN gateway group interface MAC or virtual MAC address for ESM processing.

When configured to false, the router only accepts traffic that is destined for a WLAN gateway group interface MAC or virtual MAC address for ESM processing.

Defaultfalse
Introduced23.10.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

tunnel-egress-qos
Synopsis Enter the tunnel-egress-qos context
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw tunnel-egress-qos
Treetunnel-egress-qos
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of egress QoS for WLAN-GW tunnels
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw tunnel-egress-qos admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

granularity keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisGranularity of the egress shaping for WLAN Gateway
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw tunnel-egress-qos granularity keyword
Treegranularity
Options

per-tunnel – Applied to each tunnel

per-retailer – Applied to each retailer Mobile Network Operator's fraction of the tunnel payload

Defaultper-tunnel
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

tunnel-encaps
Synopsis Enter the tunnel-encaps context
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw tunnel-encaps
Treetunnel-encaps
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

learn-l2tp-cookie (keyword | hex-string)
Synopsis System that learns the cookie from L2TP tunnels terminating on this interface
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw tunnel-encaps learn-l2tp-cookie (keyword | hex-string)
Treelearn-l2tp-cookie
String Length6
Options

never – Never interpret the cookie

always – Interpret cookie regardless of first two octets value

Defaultnever
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

vlan-range [range] string
Synopsis Enter the vlan-range list instance
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string
Treevlan-range
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

authentication
Synopsis Enter the authentication context
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string authentication
Treeauthentication
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

local
Synopsis Enable the local context
Context configure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string authentication local
Treelocal
Introduced22.2.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

data-triggered-ue-creation
Synopsis Enter the data-triggered-ue-creation context
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string data-triggered-ue-creation
Treedata-triggered-ue-creation

Description

Commands in this context configure data-triggered subscriber creation for Wi-Fi subscribers. Data-triggered UE creation only works upon receipt of TCP and UDP packets.

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

create-proxy-cache-entry
Synopsis Enter the create-proxy-cache-entry context
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string data-triggered-ue-creation create-proxy-cache-entry
Treecreate-proxy-cache-entry
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

proxy-server
Synopsis Enable the proxy-server context
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string data-triggered-ue-creation create-proxy-cache-entry proxy-server
Treeproxy-server
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

dhcp4
Synopsis Enter the dhcp4 context
Context configure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string dhcp4
Treedhcp4
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

lease-time
Synopsis Enter the lease-time context
Context configure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string dhcp4 lease-time
Treelease-time
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

dhcp6
Synopsis Enter the dhcp6 context
Context configure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string dhcp6
Treedhcp6
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

preferred-lifetime
Synopsis Enter the preferred-lifetime context
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string dhcp6 preferred-lifetime
Treepreferred-lifetime
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

valid-lifetime
Synopsis Enter the valid-lifetime context
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string dhcp6 valid-lifetime
Treevalid-lifetime
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

dsm
Synopsis Enter the dsm context
Context configure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string dsm
Treedsm
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

accounting-update
Synopsis Enable the accounting-update context
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string dsm accounting-update
Treeaccounting-update
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

application-assurance
Synopsis Enter the application-assurance context
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string dsm application-assurance
Treeapplication-assurance
Introduced21.10.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

egress
Synopsis Enter the egress context
Context configure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string dsm egress
Treeegress
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

ingress
Synopsis Enter the ingress context
Context configure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string dsm ingress
Treeingress
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

soft-quota-exhausted-filter reference
Synopsis Filter applied when soft volume quota is reached
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string dsm ingress soft-quota-exhausted-filter reference
Treesoft-quota-exhausted-filter

Description

This command applies a filter when a soft volume quota is reached. The filter replaces the currently applied filter (which can be preconfigured using the ip-filter command in the configure service vprn subscriber-interface group-interface wlan-gw vlan-range dsm ingress ip-filter context or be set using a RADIUS CoA message) for the UE upon quota exhaustion. If the quota is extended using a RADIUS CoA message, the filter is automatically reverted. Configuration changes apply only to new DSM UEs and not to existing UEs. 

Reference

configure subscriber-mgmt isa-filter string

Introduced21.7.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

one-time-redirect
Synopsis Enter the one-time-redirect context
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string dsm one-time-redirect
Treeone-time-redirect
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

volume-quota-direction keyword
Synopsis Volume quota direction for WLAN GW
Context configure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string dsm volume-quota-direction keyword
Treevolume-quota-direction

Description

This command specifies the direction that volume quotas are applied. Configuration changes apply only to new DSM UEs and not to existing UEs.

Options

both – Both directions

ingress – Ingress direction (upstream)

egress – Egress direction (downstream)

Defaultboth
Introduced21.7.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

dynamic-service boolean
Synopsis Dynamically assign WLAN-GW subscriber to a VPLS service
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string dynamic-service boolean
Treedynamic-service

Description

When configured to true, the WLAN-GW subscriber is dynamically assigned to a VPLS service, based on RADIUS authentication reply attributes. This feature is used in conjunction with the configure service vpls wlan-gw wlan-gw-group command.

See "Dynamic VPLS service" in the 7450 ESS, 7750 SR, and VSR Triple Play Service Delivery Architecture Guide for more information about the dynamic VPLS service feature.

Defaultfalse
Introduced23.3.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

extension [extension-range] string
Synopsis Add a list entry for extension
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string extension string
Treeextension
Introduced21.7.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

[extension-range] string
Synopsis VLAN tag range used for matching
Context configure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string extension string
Treeextension

Description

This command configures the additional VLAN range that is used for matching. Any traffic within the extension range is considered part of the same VLAN range for purposes of intra-SSID mobility. 

Notes

This element is part of a list key.

Introduced21.7.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

l2-service
Synopsis Enable the l2-service context
Context configure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string l2-service
Treel2-service
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

slaac
Synopsis Enter the slaac context
Context configure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string slaac
Treeslaac
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

preferred-lifetime
Synopsis Enter the preferred-lifetime context
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string slaac preferred-lifetime
Treepreferred-lifetime
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

valid-lifetime
Synopsis Enter the valid-lifetime context
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string slaac valid-lifetime
Treevalid-lifetime
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

vrgw
Synopsis Enter the vrgw context
Context configure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string vrgw
Treevrgw
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

brg
Synopsis Enter the brg context
Context configure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string vrgw brg
Treebrg
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

default-brg-profile reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDefault BRG profile to use if the AAA server does not specify one
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string vrgw brg default-brg-profile reference
Treedefault-brg-profile

Reference

configure subscriber-mgmt vrgw brg-profile string

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

lanext
Synopsis Enter the lanext context
Context configure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string vrgw lanext
Treelanext
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

access
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the access context
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string vrgw lanext access
Treeaccess
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

network
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the network context
Contextconfigure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string vrgw lanext network
Treenetwork
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

xconnect
Synopsis Enter the xconnect context
Context configure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string xconnect
Treexconnect
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

accounting
Synopsis Enter the accounting context
Context configure service ies string subscriber-interface string group-interface string wlan-gw vlan-range string xconnect accounting
Treeaccounting
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

wpp
Synopsis Enable the wpp context
Context configure service ies string subscriber-interface string group-interface string wpp
Treewpp
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

initial
Synopsis Enter the initial context
Context configure service ies string subscriber-interface string group-interface string wpp initial
Treeinitial
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

portal
Synopsis Enter the portal context
Context configure service ies string subscriber-interface string group-interface string wpp portal
Treeportal
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

name string
Synopsis Web portal server name
Context configure service ies string subscriber-interface string group-interface string wpp portal name string
Treename
String Length1 to 32

Notes

The following elements are part of a choice: portal-group or (name and router-instance).

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

hold-time
Synopsis Enter the hold-time context
Context configure service ies string subscriber-interface string hold-time
Treehold-time
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv4
Synopsis Enter the ipv4 context
Context configure service ies string subscriber-interface string hold-time ipv4
Treeipv4
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

down
Synopsis Enter the down context
Context configure service ies string subscriber-interface string hold-time ipv4 down
Treedown

Description

Commands in this context configure the down hold timer, which specifies the delay before activating the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface up, unless an operator configures the init-only command. 

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

init-only boolean
Synopsis Apply delay only at interface configuration or reboot
Contextconfigure service ies string subscriber-interface string hold-time ipv4 down init-only boolean
Treeinit-only

Description

This command applies a delay only when the IP interface is first configured or after a system reboot.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

up
Synopsis Enter the up context
Context configure service ies string subscriber-interface string hold-time ipv4 up
Treeup

Description

Commands in this context configure the up hold timer, which specifies the delay before deactivation of the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface down.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv6
Synopsis Enter the ipv6 context
Context configure service ies string subscriber-interface string hold-time ipv6
Treeipv6
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

down
Synopsis Enter the down context
Context configure service ies string subscriber-interface string hold-time ipv6 down
Treedown

Description

Commands in this context configure the down hold timer, which specifies the delay before activation of the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface up, unless an operator configures the init-only command. 

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

init-only boolean
Synopsis Apply delay only at interface configuration or reboot
Contextconfigure service ies string subscriber-interface string hold-time ipv6 down init-only boolean
Treeinit-only

Description

When configured to true, the system applies a delay only when the IP interface is first configured or after a system reboot.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

up
Synopsis Enter the up context
Context configure service ies string subscriber-interface string hold-time ipv6 up
Treeup

Description

Commands in this context configure the up hold timer, which specifies the delay before deactivation of the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface down.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipoe-linking
Synopsis Enter the ipoe-linking context
Contextconfigure service ies string subscriber-interface string ipoe-linking
Treeipoe-linking
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipoe-session
Synopsis Enter the ipoe-session context
Contextconfigure service ies string subscriber-interface string ipoe-session
Treeipoe-session
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv4
Synopsis Enter the ipv4 context
Context configure service ies string subscriber-interface string ipv4
Treeipv4
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

address [ipv4-address] string
Synopsis Enter the address list instance
Contextconfigure service ies string subscriber-interface string ipv4 address string
Treeaddress
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[ipv4-address] string
Synopsis IP address associated with the subscriber subnet
Contextconfigure service ies string subscriber-interface string ipv4 address string
Treeaddress

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

default-dns string
Synopsis Default DNS server addresses
Context configure service ies string subscriber-interface string ipv4 default-dns string
Treedefault-dns
Max. Instances2

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

dhcp
Synopsis Enter the dhcp context
Context configure service ies string subscriber-interface string ipv4 dhcp
Treedhcp
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-applications
Synopsis Enter the client-applications context
Contextconfigure service ies string subscriber-interface string ipv4 dhcp client-applications
Treeclient-applications
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

gi-address string
Synopsis GI address for the DHCP relay
Context configure service ies string subscriber-interface string ipv4 dhcp gi-address string
Treegi-address

Description

This command configures the GI address to distinguish between the different subscriber interfaces (and potentially group interfaces) defined when the router functions as a DHCP relay.

By default, the GI address used in the relayed DHCP packet is the primary IP address of a normal IES interface. Specifying the GI address allows the user to choose a secondary address. For group interfaces, a GI address must be specified under the group interface DHCP context or subscriber interface DHCP context for DHCP to function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lease-populate
Synopsis Enter the lease-populate context
Contextconfigure service ies string subscriber-interface string ipv4 dhcp lease-populate
Treelease-populate
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

option-82
Synopsis Enter the option-82 context
Context configure service ies string subscriber-interface string ipv4 dhcp option-82
Treeoption-82

Description

Commands in this context configure the processing required when the router receives a DHCP request that already has an Option 82 field in the packet.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

vendor-specific-option
Synopsis Enter the vendor-specific-option context
Contextconfigure service ies string subscriber-interface string ipv4 dhcp option-82 vendor-specific-option
Treevendor-specific-option

Description

Commands in this context configure the Nokia Vendor-Specific Option (VSO) of the DHCP packet.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

proxy-server
Synopsis Enter the proxy-server context
Contextconfigure service ies string subscriber-interface string ipv4 dhcp proxy-server
Treeproxy-server
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lease-time
Synopsis Enter the lease-time context
Context configure service ies string subscriber-interface string ipv4 dhcp proxy-server lease-time
Treelease-time
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

relay-proxy
Synopsis Enable the relay-proxy context
Contextconfigure service ies string subscriber-interface string ipv4 dhcp relay-proxy
Treerelay-proxy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

server string
Synopsis DHCP server IP addresses
Context configure service ies string subscriber-interface string ipv4 dhcp server string
Treeserver
Max. Instances8

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

src-ip-addr keyword
Synopsis Type of source address to use for DHCP relay
Contextconfigure service ies string subscriber-interface string ipv4 dhcp src-ip-addr keyword
Treesrc-ip-addr
Optionsauto, gi-address
Default auto
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

unnumbered
Synopsis Enter the unnumbered context
Context configure service ies string subscriber-interface string ipv4 unnumbered
Treeunnumbered
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ip-address string
Synopsis IP address for the subscriber interface
Contextconfigure service ies string subscriber-interface string ipv4 unnumbered ip-address string
Treeip-address

Notes

The following elements are part of a choice: ip-address or ip-int-name.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ip-int-name string
Synopsis Interface name from which an IPv4 addressed is borrowed
Contextconfigure service ies string subscriber-interface string ipv4 unnumbered ip-int-name string
Treeip-int-name
String Length1 to 32

Notes

The following elements are part of a choice: ip-address or ip-int-name.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv6
Synopsis Enable the ipv6 context
Context configure service ies string subscriber-interface string ipv6
Treeipv6
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

address [ipv6-address] string
Synopsis Enter the address list instance
Contextconfigure service ies string subscriber-interface string ipv6 address string
Treeaddress
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[ipv6-address] string
Synopsis IPv6 address for the subscriber interface
Contextconfigure service ies string subscriber-interface string ipv6 address string
Treeaddress

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

host-type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisHost type for subscriber interface prefixes
Contextconfigure service ies string subscriber-interface string ipv6 address string host-type keyword
Treehost-type
Options

pd – IPv6 ESM hosts for DHCPv6 prefix-delegation

wan – ESM hosts for DHCPv6 addresses or by WAN interface

pd-wan – Both prefix-delegation and ESM hosts

Defaultpd
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

default-dns string
Synopsis Default DNS server addresses
Context configure service ies string subscriber-interface string ipv6 default-dns string
Treedefault-dns
Max. Instances2

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

dhcp6
Synopsis Enter the dhcp6 context
Context configure service ies string subscriber-interface string ipv6 dhcp6
Treedhcp6
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

pd-managed-route
Synopsis Enable the pd-managed-route context
Contextconfigure service ies string subscriber-interface string ipv6 dhcp6 pd-managed-route
Treepd-managed-route
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

proxy-server
Synopsis Enter the proxy-server context
Contextconfigure service ies string subscriber-interface string ipv6 dhcp6 proxy-server
Treeproxy-server
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-applications
Synopsis Enter the client-applications context
Contextconfigure service ies string subscriber-interface string ipv6 dhcp6 proxy-server client-applications
Treeclient-applications
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

server-id
Synopsis Enter the server-id context
Context configure service ies string subscriber-interface string ipv6 dhcp6 proxy-server server-id
Treeserver-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

relay
Synopsis Enter the relay context
Context configure service ies string subscriber-interface string ipv6 dhcp6 relay
Treerelay
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-applications
Synopsis Enter the client-applications context
Contextconfigure service ies string subscriber-interface string ipv6 dhcp6 relay client-applications
Treeclient-applications
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lease-split
Synopsis Enter the lease-split context
Context configure service ies string subscriber-interface string ipv6 dhcp6 relay lease-split
Treelease-split

Description

Commands in this context configure DHCPv6 lease split.

DHCPv6 lease split is active when administratively enabled and for all IA_NA and IA_PD options in the transaction, the configured lease split valid lifetime (short lease time) is less than or equal to one of the following:

  • the renew time T1 committed by the server (long renew time)

  • half of the preferred lifetime committed by the server when T1 committed by the server equals zero

Introduced21.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

server string
Synopsis DHCP6 server(s) to which the DHCP6 requests are forwarded
Contextconfigure service ies string subscriber-interface string ipv6 dhcp6 relay server string
Treeserver
Max. Instances8

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

link-local-address
Synopsis Enter the link-local-address context
Contextconfigure service ies string subscriber-interface string ipv6 link-local-address
Treelink-local-address
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

prefix [ipv6-prefix] string
Synopsis Enter the prefix list instance
Contextconfigure service ies string subscriber-interface string ipv6 prefix string
Treeprefix
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[ipv6-prefix] string
Synopsis IPv6 address for a router interface
Context configure service ies string subscriber-interface string ipv6 prefix string
Treeprefix

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

holdup-time number
Synopsis Time to wait before route accepts new state attribute
Contextconfigure service ies string subscriber-interface string ipv6 prefix string holdup-time number
Treeholdup-time
Range100 to 5000
Unitsmilliseconds
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

host-type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisHost type for subscriber interface prefixes
Contextconfigure service ies string subscriber-interface string ipv6 prefix string host-type keyword
Treehost-type
Options

pd – IPv6 ESM hosts for DHCPv6 prefix-delegation

wan – ESM hosts for DHCPv6 addresses or by WAN interface

pd-wan – Both prefix-delegation and ESM hosts

Defaultpd
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

track-srrp number
Synopsis SRRP instance whose state is tracked on this IP address
Contextconfigure service ies string subscriber-interface string ipv6 prefix string track-srrp number
Treetrack-srrp
Range1 to 4294967295
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

router-advertisements
Synopsis Enter the router-advertisements context
Contextconfigure service ies string subscriber-interface string ipv6 router-advertisements
Treerouter-advertisements
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

options
Synopsis Enter the options context
Context configure service ies string subscriber-interface string ipv6 router-advertisements options
Treeoptions
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

dns
Synopsis Enter the dns context
Context configure service ies string subscriber-interface string ipv6 router-advertisements options dns
Treedns
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

prefix-options
Synopsis Enter the prefix-options context
Contextconfigure service ies string subscriber-interface string ipv6 router-advertisements prefix-options
Treeprefix-options
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

router-solicit
Synopsis Enter the router-solicit context
Contextconfigure service ies string subscriber-interface string ipv6 router-solicit
Treerouter-solicit
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

local-address-assignment
Synopsis Enter the local-address-assignment context
Contextconfigure service ies string subscriber-interface string local-address-assignment
Treelocal-address-assignment
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv4
Synopsis Enter the ipv4 context
Context configure service ies string subscriber-interface string local-address-assignment ipv4
Treeipv4
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-applications
Synopsis Enter the client-applications context
Contextconfigure service ies string subscriber-interface string local-address-assignment ipv4 client-applications
Treeclient-applications
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv6
Synopsis Enter the ipv6 context
Context configure service ies string subscriber-interface string local-address-assignment ipv6
Treeipv6
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-applications
Synopsis Enter the client-applications context
Contextconfigure service ies string subscriber-interface string local-address-assignment ipv6 client-applications
Treeclient-applications
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

pppoe
Synopsis Enter the pppoe context
Context configure service ies string subscriber-interface string pppoe
Treepppoe
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

wan-mode keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisMode of operation for hosts with /128 WAN IPv6 address
Contextconfigure service ies string subscriber-interface string wan-mode keyword
Treewan-mode
Optionsmode64, mode128
Default mode64
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

wlan-gw
Synopsis Enable the wlan-gw context
Context configure service ies string subscriber-interface string wlan-gw
Treewlan-gw
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

pool-manager
Synopsis Enter the pool-manager context
Contextconfigure service ies string subscriber-interface string wlan-gw pool-manager
Treepool-manager
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

dhcp6-client
Synopsis Enter the dhcp6-client context
Contextconfigure service ies string subscriber-interface string wlan-gw pool-manager dhcp6-client
Treedhcp6-client
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

dhcpv4-nat
Synopsis Enter the dhcpv4-nat context
Context configure service ies string subscriber-interface string wlan-gw pool-manager dhcp6-client dhcpv4-nat
Treedhcpv4-nat
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

ia-na
Synopsis Enter the ia-na context
Context configure service ies string subscriber-interface string wlan-gw pool-manager dhcp6-client ia-na
Treeia-na
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

lease-query
Synopsis Enable the lease-query context
Contextconfigure service ies string subscriber-interface string wlan-gw pool-manager dhcp6-client lease-query
Treelease-query
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

slaac
Synopsis Enter the slaac context
Context configure service ies string subscriber-interface string wlan-gw pool-manager dhcp6-client slaac
Treeslaac
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

watermarks
Synopsis Enter the watermarks context
Context configure service ies string subscriber-interface string wlan-gw pool-manager watermarks
Treewatermarks
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

redundancy
Synopsis Enter the redundancy context
Context configure service ies string subscriber-interface string wlan-gw redundancy
Treeredundancy
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

export string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRoute to export to peer
Contextconfigure service ies string subscriber-interface string wlan-gw redundancy export string
Treeexport
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

monitor string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPeer route to monitor
Contextconfigure service ies string subscriber-interface string wlan-gw redundancy monitor string
Treemonitor
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

subscriber-mgmt
Synopsis Enter the subscriber-mgmt context
Contextconfigure service ies string subscriber-mgmt
Treesubscriber-mgmt
Introduced22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

multi-chassis-shunt-id number
Synopsis Shunt ID for a pair of resilient nodes
Contextconfigure service ies string subscriber-mgmt multi-chassis-shunt-id number
Treemulti-chassis-shunt-id

Description

This command configures the shunt ID that is used to shunt downstream traffic from a standby node to an active node. Because this ID identifies the traffic service on the standby node, the same ID must be configured per service on each node.

This configuration is required for inter-BNG-UP resiliency shunting, but not for non-BNG-UP shunting. However, when configured, it is also used for shunting non-BNG-UP sessions in the same service.

Range1 to 8191
Introduced22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

up-resiliency
Synopsis Enter the up-resiliency context
Contextconfigure service ies string subscriber-mgmt up-resiliency
Treeup-resiliency
Introduced22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

monitor-oper-group [oper-group] reference
Synopsis Enter the monitor-oper-group list instance
Contextconfigure service ies string subscriber-mgmt up-resiliency monitor-oper-group reference
Treemonitor-oper-group

Description

Commands in this context define parameters to derive the service health based on monitored operational groups. The BNG-UP sends the health value to the MAG-c. The MAG-c uses the value to determine the need for a BNG-UP status change (active or standby).

Note: The following is only applicable for the configure service vpls capture-sap context. If the configured groups are not the same for all capture SAPs sharing the same underlying port or LAG, the configuration of a Layer 2 access ID alias is required, or else the system chooses arbitrarily one set of configured groups.

Max. Instances2
Introduced22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

health-drop number
Synopsis Number subtracted from the health value per failure
Contextconfigure service ies string subscriber-mgmt up-resiliency monitor-oper-group reference health-drop number
Treehealth-drop

Description

This command configures the drop in the health value for every operational group member failure. Every failure of an operational group member decreases the base health value to a possible minimum of 0.

Range1 to 100
Default1
Introduced 22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

video-interface [interface-name] string
Synopsis Enter the video-interface list instance
Contextconfigure service ies string video-interface string
Treevideo-interface
Max. Instances9
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

[interface-name] string
Synopsis Video interface name
Context configure service ies string video-interface string
Treevideo-interface
String Length1 to 29

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

address [ip-address] string
Synopsis Add a list entry for address
Context configure service ies string video-interface string address string
Treeaddress
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

[ip-address] string
Synopsis IPv4 address for the video interface within the service
Contextconfigure service ies string video-interface string address string
Treeaddress

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

admin-state keyword
Synopsis Administrative state of the video interface
Contextconfigure service ies string video-interface string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

channel [mcast-address] string source string
Synopsis Enter the channel list instance
Contextconfigure service ies string video-interface string channel string source string
Treechannel
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

[mcast-address] string
Synopsis Multicast channel address
Context configure service ies string video-interface string channel string source string
Treechannel

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

source string
Synopsis Unicast source address
Context configure service ies string video-interface string channel string source string
Treechannel

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

channel-name string
Synopsis Channel name
Contextconfigure service ies string video-interface string channel string source string channel-name string
Treechannel-name
String Length1 to 32

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

scte35-action keyword
Synopsis Enable downstream forwarding of SCTE 35 cue avails
Contextconfigure service ies string video-interface string channel string source string scte35-action keyword
Treescte35-action
Optionsforward, drop
Default forward
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

zone-channel [zone-mcast-address] string zone-source string
Synopsis Enter the zone-channel list instance
Contextconfigure service ies string video-interface string channel string source string zone-channel string zone-source string
Treezone-channel
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

description string
Synopsis Text description
Context configure service ies string video-interface string description string
Treedescription
String Length1 to 80
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

output-format keyword
Synopsis Output format
Contextconfigure service ies string video-interface string output-format keyword
Treeoutput-format
Optionsudp, rtp-udp
Default rtp-udp
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

video-sap
Synopsis Enable the video-sap context
Context configure service ies string video-interface string video-sap
Treevideo-sap
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

egress
Synopsis Enter the egress context
Context configure service ies string video-interface string video-sap egress
Treeegress
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

filter
Synopsis Enter the filter context
Context configure service ies string video-interface string video-sap egress filter
Treefilter
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

qos
Synopsis Enter the qos context
Context configure service ies string video-interface string video-sap egress qos
Treeqos
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

ingress
Synopsis Enter the ingress context
Context configure service ies string video-interface string video-sap ingress
Treeingress
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

filter
Synopsis Enter the filter context
Context configure service ies string video-interface string video-sap ingress filter
Treefilter
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

qos
Synopsis Enter the qos context
Context configure service ies string video-interface string video-sap ingress qos
Treeqos
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

video-group-id reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVideo group ID
Contextconfigure service ies string video-interface string video-sap video-group-id reference
Treevideo-group-id

Reference

configure isa video-group number

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

vpn-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVPN identifier for the service
Contextconfigure service ies string vpn-id number
Treevpn-id
Range1 to 2147483647
Introduced16.0.R1

Platforms

All

ipfix

Synopsis Enter the ipfix context
Context configure service ipfix
Treeipfix
Introduced16.0.R1

Platforms

All

export-policy [name] string
Synopsis Enter the export-policy list instance
Contextconfigure service ipfix export-policy string
Treeexport-policy
Introduced16.0.R1

Platforms

All

[name] string
Synopsis IPFIX policy name
Context configure service ipfix export-policy string
Treeexport-policy
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

collector router-instance string ip-address string
Synopsis Enter the collector list instance
Contextconfigure service ipfix export-policy string collector router-instance string ip-address string
Treecollector
Introduced16.0.R1

Platforms

All

mtu number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum Transmission Unit
Contextconfigure service ipfix export-policy string collector router-instance string ip-address string mtu number
Treemtu
Range512 to 9212
Unitsoctets
Default 1500
Introduced16.0.R1

Platforms

All

ipipe [service-name] string

Synopsis Enter the ipipe list instance
Context configure service ipipe string
Treeipipe
Introduced20.10.R1

Platforms

All

[service-name] string
Synopsis Administrative service name
Context configure service ipipe string
Treeipipe
String Length1 to 64

Notes

This element is part of a list key.

Introduced20.10.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the service
Context configure service ipipe string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced20.10.R1

Platforms

All

customer reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisService customer ID
Contextconfigure service ipipe string customer reference
Treecustomer

Reference

configure service customer string

Notes

This element is mandatory.

Introduced20.10.R1

Platforms

All

description string
Synopsis Text description
Context configure service ipipe string description string
Treedescription
String Length1 to 80
Introduced20.10.R1

Platforms

All

endpoint [name] string
Synopsis Enter the endpoint list instance
Contextconfigure service ipipe string endpoint string
Treeendpoint
Max. Instances2
Introduced20.10.R1

Platforms

All

[name] string
Synopsis Service endpoint name
Context configure service ipipe string endpoint string
Treeendpoint
String Length1 to 32

Notes

This element is part of a list key.

Introduced20.10.R1

Platforms

All

revert-time (number | keyword)
Synopsis Time to wait before reverting to primary spoke SDP
Contextconfigure service ipipe string endpoint string revert-time (number | keyword)
Treerevert-time
Range1 to 600
Unitsseconds
Options never, immediate
Defaultimmediate
Introduced20.10.R1

Platforms

All

sap [sap-id] string
Synopsis Enter the sap list instance
Context configure service ipipe string sap string
Treesap
Introduced20.10.R1

Platforms

All

[sap-id] string
Synopsis SAP ID
Contextconfigure service ipipe string sap string
Treesap
String Length1 to 45

Notes

This element is part of a list key.

Introduced20.10.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the SAP
Context configure service ipipe string sap string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced20.10.R1

Platforms

All

bandwidth number
Synopsis SAP bandwidth
Contextconfigure service ipipe string sap string bandwidth number
Treebandwidth
Range1 to 6400000000
Unitskilobps
Introduced 20.10.R1

Platforms

All

ce-address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the CE device
Context configure service ipipe string sap string ce-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treece-address
Introduced20.10.R1

Platforms

All

cpu-protection
Synopsis Enter the cpu-protection context
Contextconfigure service ipipe string sap string cpu-protection
Treecpu-protection
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

egress
Synopsis Enter the egress context
Context configure service ipipe string sap string egress
Treeegress
Introduced20.10.R1

Platforms

All

agg-rate
Synopsis Enter the agg-rate context
Context configure service ipipe string sap string egress agg-rate
Treeagg-rate
Introduced20.10.R1

Platforms

All

adaptation-rule keyword
Synopsis Adaptation rule to compute the operational PIR value when an aggregate shaper is used
Contextconfigure service ipipe string sap string egress agg-rate adaptation-rule keyword
Treeadaptation-rule
Optionsmax, min, closest
Defaultclosest
Introduced22.10.R1

Platforms

7750 SR-1, 7750 SR-s

burst-limit (number | keyword)
Synopsis Shaping burst size when an aggregate shaper is used
Contextconfigure service ipipe string sap string egress agg-rate burst-limit (number | keyword)
Treeburst-limit
Range1 to 14000000
Unitsbytes
Options auto
Default auto
Introduced22.10.R1

Platforms

7750 SR-1, 7750 SR-s

rate number
Synopsis Enforced aggregate rate for all queues
Contextconfigure service ipipe string sap string egress agg-rate rate number
Treerate
Range1 to 6400000000
Unitskilobps
Introduced 20.10.R1

Platforms

All

filter
Synopsis Enter the filter context
Context configure service ipipe string sap string egress filter
Treefilter
Introduced20.10.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service ipipe string sap string egress qos
Treeqos
Introduced20.10.R1

Platforms

All

policer-control-policy
Synopsis Enter the policer-control-policy context
Contextconfigure service ipipe string sap string egress qos policer-control-policy
Treepolicer-control-policy
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

overrides
Synopsis Enable the overrides context
Context configure service ipipe string sap string egress qos policer-control-policy overrides
Treeoverrides
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

root
Synopsis Enter the root context
Context configure service ipipe string sap string egress qos policer-control-policy overrides root
Treeroot
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

priority-mbs-thresholds
Synopsis Enter the priority-mbs-thresholds context
Contextconfigure service ipipe string sap string egress qos policer-control-policy overrides root priority-mbs-thresholds
Treepriority-mbs-thresholds
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

priority [priority-level] number
Synopsis Enter the priority list instance
Contextconfigure service ipipe string sap string egress qos policer-control-policy overrides root priority-mbs-thresholds priority number
Treepriority
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

sap-egress
Synopsis Enter the sap-egress context
Context configure service ipipe string sap string egress qos sap-egress
Treesap-egress
Introduced20.10.R1

Platforms

All

overrides
Synopsis Enter the overrides context
Context configure service ipipe string sap string egress qos sap-egress overrides
Treeoverrides
Introduced20.10.R1

Platforms

All

hs-wrr-group [group-id] reference
Synopsis Enter the hs-wrr-group list instance
Contextconfigure service ipipe string sap string egress qos sap-egress overrides hs-wrr-group reference
Treehs-wrr-group
Introduced20.10.R1

Platforms

7750 SR-7/12/12e

rate (number | keyword)
Synopsis Scheduling rate override applied to the HS WRR group
Contextconfigure service ipipe string sap string egress qos sap-egress overrides hs-wrr-group reference rate (number | keyword)
Treerate
Range1 to 2000000000
Unitskilobps
Options max

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced20.10.R1

Platforms

7750 SR-7/12/12e

policer [policer-id] reference
Synopsis Enter the policer list instance
Contextconfigure service ipipe string sap string egress qos sap-egress overrides policer reference
Treepolicer
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

cbs (number | keyword)
Synopsis CBS
Contextconfigure service ipipe string sap string egress qos sap-egress overrides policer reference cbs (number | keyword)
Treecbs
Range0 to 268435456
Unitsbytes
Options auto
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

mbs (number | keyword)
Synopsis MBS
Contextconfigure service ipipe string sap string egress qos sap-egress overrides policer reference mbs (number | keyword)
Treembs
Range0 to 268435456
Unitsbytes
Options auto
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service ipipe string sap string egress qos sap-egress overrides policer reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

rate
Synopsis Enter the rate context
Context configure service ipipe string sap string egress qos sap-egress overrides policer reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

cir (number | keyword)
Synopsis CIR rate
Contextconfigure service ipipe string sap string egress qos sap-egress overrides policer reference rate cir (number | keyword)
Treecir
Range0 to 6400000000
Unitskilobps
Options max
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

pir (number | keyword)
Synopsis PIR rate
Contextconfigure service ipipe string sap string egress qos sap-egress overrides policer reference rate pir (number | keyword)
Treepir
Range1 to 6400000000
Unitskilobps
Options max
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

stat-mode keyword
Synopsis Mode of statistics collected by the policer
Contextconfigure service ipipe string sap string egress qos sap-egress overrides policer reference stat-mode keyword
Treestat-mode
Optionsno-stats, minimal, offered-profile-no-cir, offered-total-cir, offered-profile-cir, offered-limited-capped-cir, offered-profile-capped-cir, offered-total-cir-exceed, offered-four-profile-no-cir, offered-total-cir-four-profile
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

queue [queue-id] reference
Synopsis Enter the queue list instance
Context configure service ipipe string sap string egress qos sap-egress overrides queue reference
Treequeue
Introduced20.10.R1

Platforms

All

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure service ipipe string sap string egress qos sap-egress overrides queue reference adaptation-rule
Treeadaptation-rule
Introduced20.10.R1

Platforms

All

drop-tail
Synopsis Enter the drop-tail context
Context configure service ipipe string sap string egress qos sap-egress overrides queue reference drop-tail
Treedrop-tail
Introduced20.10.R1

Platforms

All

low
Synopsis Enter the low context
Context configure service ipipe string sap string egress qos sap-egress overrides queue reference drop-tail low
Treelow
Introduced20.10.R1

Platforms

All

hs-wred-queue
Synopsis Enter the hs-wred-queue context
Contextconfigure service ipipe string sap string egress qos sap-egress overrides queue reference hs-wred-queue
Treehs-wred-queue
Introduced20.10.R1

Platforms

7750 SR-7/12/12e

monitor-queue-depth
Synopsis Enable the monitor-queue-depth context
Contextconfigure service ipipe string sap string egress qos sap-egress overrides queue reference monitor-queue-depth
Treemonitor-queue-depth
Introduced20.10.R1

Platforms

All

parent
Synopsis Enter the parent context
Context configure service ipipe string sap string egress qos sap-egress overrides queue reference parent
Treeparent
Introduced20.10.R1

Platforms

All

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service ipipe string sap string egress qos sap-egress overrides queue reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced20.10.R1

Platforms

All

rate
Synopsis Enter the rate context
Context configure service ipipe string sap string egress qos sap-egress overrides queue reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced20.10.R1

Platforms

All

port-redirect-group
Synopsis Enter the port-redirect-group context
Contextconfigure service ipipe string sap string egress qos sap-egress port-redirect-group
Treeport-redirect-group
Introduced20.10.R1

Platforms

All

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service ipipe string sap string egress qos scheduler-policy
Treescheduler-policy
Introduced20.10.R1

Platforms

All

overrides
Synopsis Enter the overrides context
Context configure service ipipe string sap string egress qos scheduler-policy overrides
Treeoverrides
Introduced20.10.R1

Platforms

All

scheduler [scheduler-name] string
Synopsis Enter the scheduler list instance
Contextconfigure service ipipe string sap string egress qos scheduler-policy overrides scheduler string
Treescheduler
Introduced20.10.R1

Platforms

All

[scheduler-name] string
Synopsis Scheduler name
Contextconfigure service ipipe string sap string egress qos scheduler-policy overrides scheduler string
Treescheduler

Description

This command specifies the scheduler name which is composed of printable 7-bit ASCII characters. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes. Each scheduler must have a unique name within the context of the scheduler policy. However, the same name can be reused in multiple scheduler policies. If the scheduler name already exists within the policy tier level, the context changes to that scheduler name for the purpose of editing the scheduler commands.

If the scheduler name exists within the policy on a different tier, an error occurs and the current context does not change. If the scheduler name does not exist in this or another tier within the scheduler policy, it is assumed that an attempt is being made to create a scheduler of that name.

If the provided scheduler name is invalid, a name syntax error occurs, the command does not execute, and the context is not change.

String Length1 to 32

Notes

This element is part of a list key.

Introduced20.10.R1

Platforms

All

parent
Synopsis Enter the parent context
Context configure service ipipe string sap string egress qos scheduler-policy overrides scheduler string parent
Treeparent
Introduced20.10.R1

Platforms

All

rate
Synopsis Enter the rate context
Context configure service ipipe string sap string egress qos scheduler-policy overrides scheduler string rate
Treerate
Introduced20.10.R1

Platforms

All

virtual-port
Synopsis Enter the virtual-port context
Contextconfigure service ipipe string sap string egress virtual-port
Treevirtual-port
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ingress
Synopsis Enter the ingress context
Context configure service ipipe string sap string ingress
Treeingress
Introduced20.10.R1

Platforms

All

filter
Synopsis Enter the filter context
Context configure service ipipe string sap string ingress filter
Treefilter
Introduced20.10.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service ipipe string sap string ingress qos
Treeqos
Introduced20.10.R1

Platforms

All

policer-control-policy
Synopsis Enter the policer-control-policy context
Contextconfigure service ipipe string sap string ingress qos policer-control-policy
Treepolicer-control-policy
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

overrides
Synopsis Enable the overrides context
Context configure service ipipe string sap string ingress qos policer-control-policy overrides
Treeoverrides
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

root
Synopsis Enter the root context
Context configure service ipipe string sap string ingress qos policer-control-policy overrides root
Treeroot
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

priority-mbs-thresholds
Synopsis Enter the priority-mbs-thresholds context
Contextconfigure service ipipe string sap string ingress qos policer-control-policy overrides root priority-mbs-thresholds
Treepriority-mbs-thresholds
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

priority [priority-level] number
Synopsis Enter the priority list instance
Contextconfigure service ipipe string sap string ingress qos policer-control-policy overrides root priority-mbs-thresholds priority number
Treepriority
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

sap-ingress
Synopsis Enter the sap-ingress context
Context configure service ipipe string sap string ingress qos sap-ingress
Treesap-ingress
Introduced20.10.R1

Platforms

All

fp-redirect-group
Synopsis Enter the fp-redirect-group context
Contextconfigure service ipipe string sap string ingress qos sap-ingress fp-redirect-group
Treefp-redirect-group
Introduced20.10.R1

Platforms

All

overrides
Synopsis Enter the overrides context
Context configure service ipipe string sap string ingress qos sap-ingress overrides
Treeoverrides
Introduced20.10.R1

Platforms

All

policer [policer-id] reference
Synopsis Enter the policer list instance
Contextconfigure service ipipe string sap string ingress qos sap-ingress overrides policer reference
Treepolicer
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

cbs (number | keyword)
Synopsis CBS
Contextconfigure service ipipe string sap string ingress qos sap-ingress overrides policer reference cbs (number | keyword)
Treecbs
Range0 to 268435456
Unitsbytes
Options auto
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

mbs (number | keyword)
Synopsis MBS
Contextconfigure service ipipe string sap string ingress qos sap-ingress overrides policer reference mbs (number | keyword)
Treembs
Range0 to 268435456
Unitsbytes
Options auto
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service ipipe string sap string ingress qos sap-ingress overrides policer reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

rate
Synopsis Enter the rate context
Context configure service ipipe string sap string ingress qos sap-ingress overrides policer reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

stat-mode keyword
Synopsis Mode of statistics collected by the policer
Contextconfigure service ipipe string sap string ingress qos sap-ingress overrides policer reference stat-mode keyword
Treestat-mode
Optionsno-stats, minimal, offered-profile-no-cir, offered-total-cir, offered-priority-no-cir, offered-profile-cir, offered-priority-cir, offered-limited-profile-cir, offered-profile-capped-cir, offered-limited-capped-cir
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

queue [queue-id] reference
Synopsis Enter the queue list instance
Context configure service ipipe string sap string ingress qos sap-ingress overrides queue reference
Treequeue
Introduced20.10.R1

Platforms

All

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure service ipipe string sap string ingress qos sap-ingress overrides queue reference adaptation-rule
Treeadaptation-rule
Introduced20.10.R1

Platforms

All

drop-tail
Synopsis Enter the drop-tail context
Context configure service ipipe string sap string ingress qos sap-ingress overrides queue reference drop-tail
Treedrop-tail
Introduced20.10.R1

Platforms

All

low
Synopsis Enter the low context
Context configure service ipipe string sap string ingress qos sap-ingress overrides queue reference drop-tail low
Treelow
Introduced20.10.R1

Platforms

All

monitor-queue-depth
Synopsis Enable the monitor-queue-depth context
Contextconfigure service ipipe string sap string ingress qos sap-ingress overrides queue reference monitor-queue-depth
Treemonitor-queue-depth
Introduced21.7.R1

Platforms

All

parent
Synopsis Enter the parent context
Context configure service ipipe string sap string ingress qos sap-ingress overrides queue reference parent
Treeparent
Introduced20.10.R1

Platforms

All

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service ipipe string sap string ingress qos sap-ingress overrides queue reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced20.10.R1

Platforms

All

rate
Synopsis Enter the rate context
Context configure service ipipe string sap string ingress qos sap-ingress overrides queue reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced20.10.R1

Platforms

All

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service ipipe string sap string ingress qos scheduler-policy
Treescheduler-policy
Introduced20.10.R1

Platforms

All

overrides
Synopsis Enter the overrides context
Context configure service ipipe string sap string ingress qos scheduler-policy overrides
Treeoverrides
Introduced20.10.R1

Platforms

All

scheduler [scheduler-name] string
Synopsis Enter the scheduler list instance
Contextconfigure service ipipe string sap string ingress qos scheduler-policy overrides scheduler string
Treescheduler
Introduced20.10.R1

Platforms

All

[scheduler-name] string
Synopsis Scheduler name
Contextconfigure service ipipe string sap string ingress qos scheduler-policy overrides scheduler string
Treescheduler

Description

This command specifies the scheduler name which is composed of printable 7-bit ASCII characters. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes. Each scheduler must have a unique name within the context of the scheduler policy. However, the same name can be reused in multiple scheduler policies. If the scheduler name already exists within the policy tier level, the context changes to that scheduler name for the purpose of editing the scheduler commands.

If the scheduler name exists within the policy on a different tier, an error occurs and the current context does not change. If the scheduler name does not exist in this or another tier within the scheduler policy, it is assumed that an attempt is being made to create a scheduler of that name.

If the provided scheduler name is invalid, a name syntax error occurs, the command does not execute, and the context is not change.

String Length1 to 32

Notes

This element is part of a list key.

Introduced20.10.R1

Platforms

All

parent
Synopsis Enter the parent context
Context configure service ipipe string sap string ingress qos scheduler-policy overrides scheduler string parent
Treeparent
Introduced20.10.R1

Platforms

All

rate
Synopsis Enter the rate context
Context configure service ipipe string sap string ingress qos scheduler-policy overrides scheduler string rate
Treerate
Introduced20.10.R1

Platforms

All

lag
Synopsis Enter the lag context
Context configure service ipipe string sap string lag
Treelag
Introduced20.10.R1

Platforms

All

link-map-profile number
Synopsis LAG link map profile for a SAP or network interface
Contextconfigure service ipipe string sap string lag link-map-profile number
Treelink-map-profile

Description

This command assigns a preconfigured LAG link map profile to a SAP or network interface configured on a LAG or a PW port that exists on a LAG. After an operator assigns a LAG link map profile, the system rehashes the SAP or network interface egress traffic over the LAG as required by the new configuration.

If the LAG link map profile for a SAP or network interface is deleted, the system reverts back to per-flow hashing.

Range1 to 64
Introduced20.10.R1

Platforms

All

per-link-hash
Synopsis Enter the per-link-hash context
Contextconfigure service ipipe string sap string lag per-link-hash
Treeper-link-hash
Introduced20.10.R1

Platforms

All

class number
Synopsis Class used on LAG egress using weighted per-link-hash
Contextconfigure service ipipe string sap string lag per-link-hash class number
Treeclass
Range1 to 3
Default1
Introduced 20.10.R1

Platforms

All

weight number
Synopsis Weight used on LAG egress using weighted per-link-hash
Contextconfigure service ipipe string sap string lag per-link-hash weight number
Treeweight
Range1 to 1024
Default1
Introduced 20.10.R1

Platforms

All

mac string
Synopsis MAC address of the Ipipe Ethernet SAP
Contextconfigure service ipipe string sap string mac string
Treemac
Default00:00:00:00:00:00
Introduced20.10.R1

Platforms

All

mac-refresh number
Synopsis MAC refresh interval
Context configure service ipipe string sap string mac-refresh number
Treemac-refresh
Range0 to 65535
Default14400
Introduced 20.10.R1

Platforms

All

transit-policy
Synopsis Enable the transit-policy context
Contextconfigure service ipipe string sap string transit-policy
Treetransit-policy
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

service-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisService ID
Contextconfigure service ipipe string service-id number
Treeservice-id
Range1 to 2147483647
Introduced20.10.R1

Platforms

All

service-mtu number
Synopsis MTU size
Contextconfigure service ipipe string service-mtu number
Treeservice-mtu

Description

This command configures the Maximum Transmission Unit (MTU) value (payload) for the service. The system uses the value to validate the operational state of the SAP and SDP binding within the service. The value overrides the default MTU for the service type.

The service MTU and a SAP’s service delineation encapsulation overhead (4 bytes for a dot1q tag) are used to derive the required MTU of the physical port or channel on which the SAP was created. If the required payload is larger than the port or channel MTU, the SAP is placed in an inoperative state. If the required MTU is equal to or less than the port or channel MTU, the SAP transitions to the operative state.

When binding an SDP to a service, the service MTU is compared to the path MTU associated with the SDP. The path MTU can be administratively defined in the context of the SDP. The default or administrative path MTU can be dynamically reduced due to the MTU capabilities discovered by the tunneling mechanism of the SDP or the egress interface MTU capabilities based on the next hop in the tunnel path. If the service MTU is larger than the path MTU, the SDP binding for the service is placed in an inoperative state. If the service MTU is equal to or less than the path MTU, the SDP binding is placed in an operational state.

If a service MTU, port or channel MTU, or path MTU is dynamically or administratively modified, all associated SAP and SDP binding operational states are automatically reevaluated.

Binding operational states are automatically reevaluated.

For I-VPLS and Epipes bound to a B-VPLS, the service MTU must be at least 18 bytes smaller than the B-VPLS service MTU to accommodate the PBB header.

Because this connects a Layer 2 to a Layer 3 service, adjust the service MTU under the Epipe service. The MTU that is advertised from the Epipe side is service MTU minus EtherHeaderSize.

In the configure service epipe spoke-sdp context, the adv-service-mtu command can be used to override the configured MTU value used in T-LDP signaling to the far-end of an Epipe spoke-sdp. The adv-service-mtu command is also used to validate the value signaled by the far-end PE.

Range1 to 9194
Introduced20.10.R1

Platforms

All

spoke-sdp [sdp-bind-id] string
Synopsis Enter the spoke-sdp list instance
Contextconfigure service ipipe string spoke-sdp string
Treespoke-sdp
Introduced20.10.R1

Platforms

All

[sdp-bind-id] string
Synopsis SDP binding ID
Contextconfigure service ipipe string spoke-sdp string
Treespoke-sdp
String Length3 to 16

Notes

This element is part of a list key.

Introduced20.10.R1

Platforms

All

aarp
Synopsis Enable the aarp context
Context configure service ipipe string spoke-sdp string aarp
Treeaarp
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

id reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisAARP instance ID
Contextconfigure service ipipe string spoke-sdp string aarp id reference
Treeid

Reference

configure application-assurance aarp number

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisRole of the spoke SDP referenced by the AARP
Contextconfigure service ipipe string spoke-sdp string aarp type keyword
Treetype
Optionssubscriber-side-shunt, network-side-shunt

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the SDP binding to the service
Contextconfigure service ipipe string spoke-sdp string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced20.10.R1

Platforms

All

bandwidth (number | keyword)
Synopsis Bandwidth that is reserved for this SDP binding
Contextconfigure service ipipe string spoke-sdp string bandwidth (number | keyword)
Treebandwidth
Range0 to 100000000
Unitskilobps
Options max
Default 0
Introduced20.10.R1

Platforms

All

bfd
Synopsis Enter the bfd context
Context configure service ipipe string spoke-sdp string bfd
Treebfd
Introduced21.2.R1

Platforms

All

bfd-template reference
Synopsis BFD template associated with the SDP binding
Contextconfigure service ipipe string spoke-sdp string bfd bfd-template reference
Treebfd-template

Description

This command configures a named BFD template to be used by VCCV BFD on PWs belonging to the VLL service. The template specifies parameters, such as the minimum transmit and receive control packet timer intervals, used by the BFD session. Template parameters are configured under the configure router bfd context.

Reference

configure bfd bfd-template string

Introduced21.2.R1

Platforms

All

ce-address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the CE device
Context configure service ipipe string spoke-sdp string ce-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treece-address
Introduced20.10.R1

Platforms

All

egress
Synopsis Enter the egress context
Context configure service ipipe string spoke-sdp string egress
Treeegress
Introduced20.10.R1

Platforms

All

filter
Synopsis Enter the filter context
Context configure service ipipe string spoke-sdp string egress filter
Treefilter
Introduced20.10.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service ipipe string spoke-sdp string egress qos
Treeqos
Introduced20.10.R1

Platforms

All

network
Synopsis Enter the network context
Context configure service ipipe string spoke-sdp string egress qos network
Treenetwork
Introduced20.10.R1

Platforms

All

port-redirect-group
Synopsis Enter the port-redirect-group context
Contextconfigure service ipipe string spoke-sdp string egress qos network port-redirect-group
Treeport-redirect-group
Introduced20.10.R1

Platforms

All

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEgress MPLS VC label to send packets to the far end
Contextconfigure service ipipe string spoke-sdp string egress vc-label number
Treevc-label
Range16 to 1048575
Introduced20.10.R1

Platforms

All

endpoint
Synopsis Enter the endpoint context
Context configure service ipipe string spoke-sdp string endpoint
Treeendpoint
Introduced20.10.R1

Platforms

All

name reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEndpoint name to which SDP bind is attached
Contextconfigure service ipipe string spoke-sdp string endpoint name reference
Treename

Reference

configure service ipipe string endpoint string

Introduced20.10.R1

Platforms

All

precedence (number | keyword)
Synopsis Precedence when multiple SDP binds are on one endpoint
Contextconfigure service ipipe string spoke-sdp string endpoint precedence (number | keyword)
Treeprecedence
Range1 to 4
Optionsprimary
Default4
Introduced 20.10.R1

Platforms

All

entropy-label
Synopsis Enable the use of entropy labels for spoke SDPs
Contextconfigure service ipipe string spoke-sdp string entropy-label
Treeentropy-label

Notes

The following elements are part of a choice: entropy-label or hash-label.

Introduced20.10.R1

Platforms

All

hash-label
Synopsis Enable the hash-label context
Context configure service ipipe string spoke-sdp string hash-label
Treehash-label

Description

Commands in this context configure the use of hash labels for egress datapaths.

For information about hash-label handling, see the "Hash labels" section of the 7450 ESS, 7750 SR, 7950 XRS, and VSR MPLS Guide.

Notes

The following elements are part of a choice: entropy-label or hash-label.

Introduced20.10.R1

Platforms

All

signal-capability
Synopsis Signal hash label capability to the remote PE
Contextconfigure service ipipe string spoke-sdp string hash-label signal-capability
Treesignal-capability

Description

When configured, this command enables the signaling and negotiating of the hash label between the local and remote PE nodes.

The signaling process outcome determines whether the local PE inserts the hash label on the user packets. This outcome can override the local PE configuration.

Introduced20.10.R1

Platforms

All

ingress
Synopsis Enter the ingress context
Context configure service ipipe string spoke-sdp string ingress
Treeingress
Introduced20.10.R1

Platforms

All

filter
Synopsis Enter the filter context
Context configure service ipipe string spoke-sdp string ingress filter
Treefilter
Introduced20.10.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service ipipe string spoke-sdp string ingress qos
Treeqos
Introduced20.10.R1

Platforms

All

network
Synopsis Enter the network context
Context configure service ipipe string spoke-sdp string ingress qos network
Treenetwork
Introduced20.10.R1

Platforms

All

fp-redirect-group
Synopsis Enter the fp-redirect-group context
Contextconfigure service ipipe string spoke-sdp string ingress qos network fp-redirect-group
Treefp-redirect-group
Introduced20.10.R1

Platforms

All

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIngress MPLS VC label to send packets to the far end
Contextconfigure service ipipe string spoke-sdp string ingress vc-label number
Treevc-label
Range1 to 1048575
Introduced20.10.R1

Platforms

All

transit-policy
Synopsis Enable the transit-policy context
Contextconfigure service ipipe string spoke-sdp string transit-policy
Treetransit-policy
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

vc-switching boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisUse PW switching signaling for spoke SDPs in service
Contextconfigure service ipipe string vc-switching boolean
Treevc-switching
Defaultfalse
Introduced20.10.R1

Platforms

All

vpn-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVPN identifier for the service
Contextconfigure service ipipe string vpn-id number
Treevpn-id
Range1 to 2147483647
Introduced20.10.R1

Platforms

All

mac-list [name] string

Synopsis Enter the mac-list list instance
Contextconfigure service mac-list string
Treemac-list

Description

Commands in this context specify the MAC addresses to be included in a MAC list to be used with the Auto-Learn MAC Protect (ALMP) functionality. The list is used to exclude certain MAC addresses from protection, for example, on SAPs or spoke SDPs configured with ALMP where certain MAC addresses (such as VRRP virtual MAC addresses) must be able to move to other objects.

Introduced20.5.R1

Platforms

All

[name] string
Synopsis MAC list name
Contextconfigure service mac-list string
Treemac-list
String Length1 to 32

Notes

This element is part of a list key.

Introduced20.5.R1

Platforms

All

mac [address] string
Synopsis Enter the mac list instance
Context configure service mac-list string mac string
Treemac
Introduced20.5.R1

Platforms

All

[address] string
Synopsis MAC address
Contextconfigure service mac-list string mac string
Treemac

Notes

This element is part of a list key.

Introduced20.5.R1

Platforms

All

mask string
Synopsis Mask for the MAC address
Context configure service mac-list string mac string mask string
Treemask
Defaultff:ff:ff:ff:ff:ff
Introduced20.5.R1

Platforms

All

md-auto-id

Synopsis Enter the md-auto-id context
Context configure service md-auto-id
Treemd-auto-id
Introduced16.0.R1

Platforms

All

customer-id-range
Synopsis Enable the customer-id-range context
Contextconfigure service md-auto-id customer-id-range
Treecustomer-id-range
Introduced16.0.R1

Platforms

All

end number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisUpper bound of the ID range
Contextconfigure service md-auto-id customer-id-range end number
Treeend
Range2 to 2147483647

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

start number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisLower bound of the ID range
Contextconfigure service md-auto-id customer-id-range start number
Treestart
Range2 to 2147483647

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

pw-template-id-range
Synopsis Enable the pw-template-id-range context
Contextconfigure service md-auto-id pw-template-id-range
Treepw-template-id-range
Introduced16.0.R1

Platforms

All

end number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisUpper bound of the PW template ID range
Contextconfigure service md-auto-id pw-template-id-range end number
Treeend
Range1 to 2147483647

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

start number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisLower bound of the PW template ID range
Contextconfigure service md-auto-id pw-template-id-range start number
Treestart
Range1 to 2147483647

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

service-id-range
Synopsis Enable the service-id-range context
Contextconfigure service md-auto-id service-id-range
Treeservice-id-range
Introduced16.0.R1

Platforms

All

end number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisUpper bound of the service ID range
Contextconfigure service md-auto-id service-id-range end number
Treeend
Range1 to 2147483647

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

start number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisLower bound of the service ID range
Contextconfigure service md-auto-id service-id-range start number
Treestart
Range1 to 2147483647

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

mrp

Synopsis Enter the mrp context
Context configure service mrp
Treemrp
Introduced20.10.R1

Platforms

All

policy [policy-name] string
Synopsis Enter the policy list instance
Contextconfigure service mrp policy string
Treepolicy
Introduced20.10.R1

Platforms

All

[policy-name] string
Synopsis Specify the policy name associated with the MRP
Contextconfigure service mrp policy string
Treepolicy
String Length1 to 32

Notes

This element is part of a list key.

Introduced20.10.R1

Platforms

All

default-action keyword
Synopsis Action for packets not matching any MRP policy entries
Contextconfigure service mrp policy string default-action keyword
Treedefault-action
Optionsblock, allow
Default allow
Introduced20.10.R1

Platforms

All

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure service mrp policy string entry number
Treeentry
Introduced20.10.R1

Platforms

All

[entry-id] number
Synopsis Sepcify an id for the MRP policy entry
Contextconfigure service mrp policy string entry number
Treeentry
Range1 to 65535

Notes

This element is part of a list key.

Introduced20.10.R1

Platforms

All

action keyword
Synopsis Action applied for matching packets
Context configure service mrp policy string entry number action keyword
Treeaction
Optionsblock, allow, end-station
Introduced20.10.R1

Platforms

All

match
Synopsis Enter the match context
Context configure service mrp policy string entry number match
Treematch
Introduced20.10.R1

Platforms

All

isid [value] number
Synopsis Enter the isid list instance
Context configure service mrp policy string entry number match isid number
Treeisid
Introduced20.10.R1

Platforms

All

[value] number
Synopsis Lowest service instance ID to match the entry
Contextconfigure service mrp policy string entry number match isid number
Treeisid
Range0 to 16777215

Notes

This element is part of a list key.

Introduced20.10.R1

Platforms

All

scope keyword
Synopsis Specify the scope of the mrp-policy definition
Contextconfigure service mrp policy string scope keyword
Treescope
Optionsexclusive, template
Default template
Introduced20.10.R1

Platforms

All

nat

Synopsis Enter the nat context
Context configure service nat
Treenat
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

classifier [name] string
Synopsis Enter the classifier list instance
Contextconfigure service nat classifier string
Treeclassifier
Max. Instances8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis NAT classifier name
Context configure service nat classifier string
Treeclassifier
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

default
Synopsis Enter the default context
Context configure service nat classifier string default
Treedefault
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

action
Synopsis Enter the action context
Context configure service nat classifier string default action
Treeaction
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

destination-nat
Synopsis Enable the destination-nat context
Contextconfigure service nat classifier string default action destination-nat
Treedestination-nat

Notes

The following elements are part of a choice: (destination-nat, dnat, and dnat-ip-address) or forward.

Introduced21.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

forward
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisForward mode of operation
Contextconfigure service nat classifier string default action forward
Treeforward

Notes

The following elements are part of a choice: (destination-nat, dnat, and dnat-ip-address) or forward.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dnat-ip-address string
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisDefault destination IP address for matching entries with dNAT action
Contextconfigure service nat classifier string default dnat-ip-address string
Treednat-ip-address
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

description string
Synopsis Text description
Context configure service nat classifier string description string
Treedescription
String Length1 to 80
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

entry [id] number
Synopsis Enter the entry list instance
Context configure service nat classifier string entry number
Treeentry
Max. Instances32
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[id] number
Synopsis Classifier rule entry ID
Context configure service nat classifier string entry number
Treeentry
Range1 to 1000

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

action
Synopsis Enter the action context
Context configure service nat classifier string entry number action
Treeaction
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

destination-nat
Synopsis Enable the destination-nat context
Contextconfigure service nat classifier string entry number action destination-nat
Treedestination-nat

Notes

The following elements are part of a choice: (destination-nat, dnat, and dnat-ip-address) or forward.

Introduced21.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

forward
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisForward mode of operation
Contextconfigure service nat classifier string entry number action forward
Treeforward

Notes

The following elements are part of a choice: (destination-nat, dnat, and dnat-ip-address) or forward.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

match
Synopsis Enter the match context
Context configure service nat classifier string entry number match
Treematch
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dst-port-range
Synopsis Enter the dst-port-range context
Contextconfigure service nat classifier string entry number match dst-port-range
Treedst-port-range
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

end number
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisUpper bound of the port range
Contextconfigure service nat classifier string entry number match dst-port-range end number
Treeend
Range0 | 1 to 65535
Default65535
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

start number
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisLower bound of the port range
Contextconfigure service nat classifier string entry number match dst-port-range start number
Treestart
Range0 | 1 to 65535
Default0
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

foreign-ip-address string
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisForeign IP address as the match criterion
Contextconfigure service nat classifier string entry number match foreign-ip-address string
Treeforeign-ip-address
Introduced19.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

protocol keyword
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisIP protocol to match
Contextconfigure service nat classifier string entry number match protocol keyword
Treeprotocol
Optionstcp, udp
Default udp
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

firewall-policy [name] string
Synopsis Enter the firewall-policy list instance
Contextconfigure service nat firewall-policy string
Treefirewall-policy

Description

Commands in this context configure the attributes of the firewall policy, for use in contexts where basic protection from outside attack vectors is required.

Firewall policies cannot be deleted if they are in use.

Max. Instances2048
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis Firewall policy name
Context configure service nat firewall-policy string
Treefirewall-policy
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

alg
Synopsis Enter the alg context
Context configure service nat firewall-policy string alg
Treealg

Description

Commands in this context configure the Application Layer Gateway (ALG) attributes of the policy.

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

ftp boolean
Synopsis Use FTP ALG for the policy
Context configure service nat firewall-policy string alg ftp boolean
Treeftp
Defaulttrue
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

rtsp boolean
Synopsis Use RTSP ALG for the policy
Context configure service nat firewall-policy string alg rtsp boolean
Treertsp

Description

When configured to true, Real-Time Streaming Protocol (RTSP) ALG is used for the policy.

Defaultfalse
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

sip boolean
Synopsis Use SIP ALG for the policy
Context configure service nat firewall-policy string alg sip boolean
Treesip
Defaultfalse
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

domain
Synopsis Enter the domain context
Context configure service nat firewall-policy string domain
Treedomain

Description

Commands in this context configure the attributes of the domain for the firewall policy. All associated traffic must be part of the prefixes specified by this domain.

Notes

The following elements are part of a choice: domain or l2-outside.

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

name string
Synopsis Firewall domain name
Context configure service nat firewall-policy string domain name string
Treename
String Length1 to 32
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

router-instance string
Synopsis Router or VPRN service name
Context configure service nat firewall-policy string domain router-instance string
Treerouter-instance

Description

This command specifies the router instance or VPRN service for this domain. All associated traffic must be part of the prefixes specified by this domain.

Introduced16.0.R4

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

filtering keyword
Synopsis Filtering method for inbound traffic for the policy
Contextconfigure service nat firewall-policy string filtering keyword
Treefiltering
Optionsendpoint-independent, address-and-port-dependent
Defaultendpoint-independent
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

l2-outside
Synopsis Use Layer 2 outside service address location
Contextconfigure service nat firewall-policy string l2-outside
Treel2-outside

Description

This command specifies Layer 2 outside service address location for the NAT policy instead of Layer 3 outside service.

Notes

The following elements are part of a choice: domain or l2-outside.

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

priority-sessions
Synopsis Enter the priority-sessions context
Contextconfigure service nat firewall-policy string priority-sessions
Treepriority-sessions
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

fc
Synopsis Enter the fc context
Context configure service nat firewall-policy string priority-sessions fc
Treefc

Description

Commands in this context specify which Forwarding Class (FC) options have prioritized sessions. 

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

af boolean
Synopsis Prioritize traffic from AF forwarding classes
Contextconfigure service nat firewall-policy string priority-sessions fc af boolean
Treeaf

Description

When configured to true, traffic from Assured Forwarding (AF) FC sessions is prioritized. When configured to false, AF traffic is not prioritized.

Defaultfalse
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

be boolean
Synopsis Prioritize traffic from BE forwarding classes
Contextconfigure service nat firewall-policy string priority-sessions fc be boolean
Treebe

Description

When configured to true, traffic from Best Effort (BE) FC sessions is prioritized. When configured to false, BE traffic is not prioritized.

Defaultfalse
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

h1 boolean
Synopsis Prioritize traffic from H1 forwarding classes
Contextconfigure service nat firewall-policy string priority-sessions fc h1 boolean
Treeh1

Description

When configured to true, traffic from H1 sessions is prioritized. When configured to false, H1 traffic is not prioritized.

Defaultfalse
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

l2 boolean
Synopsis Prioritize traffic from L2 forwarding classes
Contextconfigure service nat firewall-policy string priority-sessions fc l2 boolean
Treel2

Description

When configured to true, traffic from L2 sessions is prioritized. When configured to false, L2 traffic is not prioritized.

Defaultfalse
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

session-limits
Synopsis Enter the session-limits context
Contextconfigure service nat firewall-policy string session-limits
Treesession-limits

Description

Commands in this context configure session-limit attributes for the policy.

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

max number
Synopsis Maximum number of sessions per subscriber
Contextconfigure service nat firewall-policy string session-limits max number
Treemax
Range1 to 65535
Default65535
Introduced 16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

reserved number
Synopsis Number of sessions reserved for prioritized sessions
Contextconfigure service nat firewall-policy string session-limits reserved number
Treereserved

Description

This command configures the number of sessions per block that are reserved for prioritized sessions.

Range1 to 65534
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

watermarks
Synopsis Enable the watermarks context
Context configure service nat firewall-policy string session-limits watermarks
Treewatermarks

Description

This command configures watermarks for NAT resources.

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

high number
Synopsis High watermark percentage
Context configure service nat firewall-policy string session-limits watermarks high number
Treehigh

Description

This command configures the high threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

low number
Synopsis Low watermark percentage
Context configure service nat firewall-policy string session-limits watermarks low number
Treelow

Description

This command configures the low threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

tcp
Synopsis Enter the tcp context
Context configure service nat firewall-policy string tcp
Treetcp

Description

Commands in this context configure the transmission control protocol (TCP) attributes of the policy. 

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

mss-adjust number
Synopsis TCP MSS adjustment value
Context configure service nat firewall-policy string tcp mss-adjust number
Treemss-adjust

Description

This command configures the value to use to adjust the TCP Maximum Segment Size (MSS) option, if not already present or the present value is higher.

Range160 to 10240
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

timeouts
Synopsis Enter the timeouts context
Context configure service nat firewall-policy string timeouts
Treetimeouts

Description

Commands in this context configure the attributes of session idle timeouts for the policy.

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

sip number
Synopsis SIP inactive media timeout
Context configure service nat firewall-policy string timeouts sip number
Treesip
Range10 to 7200
Unitsseconds
Default 120
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

tcp
Synopsis Enter the tcp context
Context configure service nat firewall-policy string timeouts tcp
Treetcp

Description

Commands in this context configure TCP timeout attributes. 

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

rst number
Synopsis Suspend time for TCP connection ports closed by RST
Contextconfigure service nat firewall-policy string timeouts tcp rst number
Treerst

Description

This command configures the suspend time for outside TCP ports that are used in translations for TCP connections, when they are closed by TCP Reset (RST). After the timer expires, the outside ports can be reused for new TCP translations.

Range0 to 240
Unitsseconds
Default 0
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

syn number
Synopsis TCP session timeout when synchronizing initial sequence
Contextconfigure service nat firewall-policy string timeouts tcp syn number
Treesyn
Range6 to 86400
Unitsseconds
Default 15
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

time-wait number
Synopsis Timeout applied to a TCP session in the time-wait state
Contextconfigure service nat firewall-policy string timeouts tcp time-wait number
Treetime-wait
Range0 to 240
Unitsseconds
Default 0
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

udp
Synopsis Enter the udp context
Context configure service nat firewall-policy string timeouts udp
Treeudp

Description

Commands in this context configure the User Datagram Protocol (UDP) mapping timeout attributes.

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

dns number
Synopsis Timeout applied to UDP session with destination port 53
Contextconfigure service nat firewall-policy string timeouts udp dns number
Treedns
Range15 to 86400
Unitsseconds
Default 15
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

initial number
Synopsis UDP mapping timeout applied to new sessions
Contextconfigure service nat firewall-policy string timeouts udp initial number
Treeinitial
Range10 to 300
Unitsseconds
Default 15
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

unknown-protocol number
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisTimeout for flows with an unknown protocol
Contextconfigure service nat firewall-policy string timeouts unknown-protocol number
Treeunknown-protocol
Range60 to 86400
Unitsseconds
Default 300
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

udp
Synopsis Enter the udp context
Context configure service nat firewall-policy string udp
Treeudp
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

inbound-refresh boolean
Synopsis Extend UDP session timeout on inbound traffic
Contextconfigure service nat firewall-policy string udp inbound-refresh boolean
Treeinbound-refresh

Description

When configured to true, this command extends the UDP session timeout on inbound traffic. 

When configured to false, the UDP session timeout is not extended.

Defaultfalse
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

unknown-protocols
Synopsis Enter the unknown-protocols context
Contextconfigure service nat firewall-policy string unknown-protocols
Treeunknown-protocols

Description

Commands in this context configure the treatment of flows of unknown Layer 4 protocols that cannot be natively handled by the system.

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

all
Synopsis Allow all protocols to create unknown flows
Contextconfigure service nat firewall-policy string unknown-protocols all
Treeall

Description

This command specifies that all protocols are permitted to create unknown flows. Protocol or IPv6 extension header values that are explicitly supported by SR OS are not treated as unknown protocols.

Notes

The following elements are part of a choice: all or protocol.

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

protocol number
Synopsis IANA number of protocol allowed to create unknown flow
Contextconfigure service nat firewall-policy string unknown-protocols protocol number
Treeprotocol

Description

This command specifies the Internet Assigned Numbers Authority (IANA) number of a protocol that is permitted to create unknown flows. Protocol or IPv6 extension header values that are explicitly supported by SR OS can be configured but are not treated as unknown protocols.

Range0 to 255
Max. Instances8

Notes

The following elements are part of a choice: all or protocol.

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

map-t
Synopsis Enter the map-t context
Context configure service nat map-t
Treemap-t
Introduced16.0.R4

Platforms

VSR

domain [name] string
Synopsis Enter the domain list instance
Contextconfigure service nat map-t domain string
Treedomain
Max. Instances63
Introduced16.0.R4

Platforms

VSR

[name] string
Synopsis MAP domain name
Context configure service nat map-t domain string
Treedomain
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

VSR

admin-state keyword
Synopsis Administrative state of the MAP domain
Contextconfigure service nat map-t domain string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R4

Platforms

VSR

dmr-prefix string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisThe Default Mapping Rule prefix
Contextconfigure service nat map-t domain string dmr-prefix string
Treedmr-prefix
Introduced16.0.R4

Platforms

VSR

mapping-rule [rule-name] string
Synopsis Enter the mapping-rule list instance
Contextconfigure service nat map-t domain string mapping-rule string
Treemapping-rule
Max. Instances16383
Introduced16.0.R4

Platforms

VSR

[rule-name] string
Synopsis The name that identifies this mapping rule
Contextconfigure service nat map-t domain string mapping-rule string
Treemapping-rule
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

VSR

ea-length number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisThe length of the EA bits field in the End-user IPv6 prefix part of the IPv6 Map Address
Contextconfigure service nat map-t domain string mapping-rule string ea-length number
Treeea-length
Range0 to 48
Default0
Introduced 16.0.R4

Platforms

VSR

ipv4-prefix string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisThe IPv4 prefix
Contextconfigure service nat map-t domain string mapping-rule string ipv4-prefix string
Treeipv4-prefix
Introduced16.0.R4

Platforms

VSR

psid-offset number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisThe offset of the Port Set ID (PSID) within a 16 bits wide port space
Contextconfigure service nat map-t domain string mapping-rule string psid-offset number
Treepsid-offset
Range0 to 16
Default6
Introduced 16.0.R4

Platforms

VSR

rule-prefix string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisThe IPv6 prefix
Contextconfigure service nat map-t domain string mapping-rule string rule-prefix string
Treerule-prefix
Introduced16.0.R4

Platforms

VSR

mtu number
Synopsis Configure the MTU
Context configure service nat map-t domain string mtu number
Treemtu
Range160 to 8686
Default8686
Introduced 16.0.R4

Platforms

VSR

nat-policy [name] string
Synopsis Enter the nat-policy list instance
Contextconfigure service nat nat-policy string
Treenat-policy
Max. Instances4096
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis NAT policy name
Context configure service nat nat-policy string
Treenat-policy
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

alg
Synopsis Enter the alg context
Context configure service nat nat-policy string alg
Treealg

Description

Commands in this context configure the Application Layer Gateway (ALG) attributes of the policy.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ftp boolean
Synopsis Use FTP ALG for the policy
Context configure service nat nat-policy string alg ftp boolean
Treeftp
Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

pptp boolean
Synopsis Use PPTP ALG for the policy
Context configure service nat nat-policy string alg pptp boolean
Treepptp

Description

When configured to true, the policy uses Point-to-Point Tunneling Protocol (PPTP) ALG. 

PPTP sessions can only be initiated from NAT inside. 

GRE traffic is allowed through NAT only if the corresponding mapping exists.

There can be seven calls (GRE tunnels) per control session.

When configured to false, PPTP ALG is not used.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

rtsp boolean
Synopsis Use RTSP ALG for the policy
Context configure service nat nat-policy string alg rtsp boolean
Treertsp

Description

When configured to true, Real-Time Streaming Protocol (RTSP) ALG is used for the policy.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

sip boolean
Synopsis Use SIP ALG for the policy
Context configure service nat nat-policy string alg sip boolean
Treesip
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

block-limit number
Synopsis Maximum number of port blocks per subscriber
Contextconfigure service nat nat-policy string block-limit number
Treeblock-limit
Range1 to 40
Default1
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

description string
Synopsis Text description
Context configure service nat nat-policy string description string
Treedescription
String Length1 to 80
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dnat
Synopsis Enter the dnat context
Context configure service nat nat-policy string dnat
Treednat
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

classifier reference
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisNAT classifier
Contextconfigure service nat nat-policy string dnat classifier reference
Treeclassifier

Description

When configured within the NAT policy, this command references a NAT classifier that activates DNAT functionality. The configuration uses a filter-like approach to identify the traffic that is subjected to DNAT. It is required for translation of the destination IP address. 

Reference

configure service nat classifier string

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dnat-only
Synopsis Enable the dnat-only context
Context configure service nat nat-policy string dnat-only
Treednat-only

Description

Commands in this context configure the attributes of DNAT-only. When DNAT-only is configured, no source or port NAT (SNAPT) is performed. Only the destination IP address (going from inside to outside) is translated; the source IP address and port are not translated.

Notes

The following elements are part of a choice: dnat-only, l2-outside, or pool.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

nat-group reference
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNAT group
Contextconfigure service nat nat-policy string dnat-only nat-group reference
Treenat-group

Description

This command configures the NAT group in which DNAT translation takes place for the outside routing context.

Reference

configure isa nat-group number

Notes

The following elements are part of a mandatory choice: nat-group or wlan-gw-group.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

router-instance string
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisRouter name or VPRN service name
Contextconfigure service nat nat-policy string dnat-only router-instance string
Treerouter-instance

Notes

This element is mandatory.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

wlan-gw-group reference
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisWLAN GW group used for NAT
Contextconfigure service nat nat-policy string dnat-only wlan-gw-group reference
Treewlan-gw-group

Description

This command configures the NAT WLAN Gateway (GW) group in which DNAT translation takes place for the outside routing context.

Reference

configure isa wlan-gw-group number

Notes

The following elements are part of a mandatory choice: nat-group or wlan-gw-group.

Introduced16.0.R4

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

filtering keyword
Synopsis Filtering method for inbound traffic for the policy
Contextconfigure service nat nat-policy string filtering keyword
Treefiltering
Optionsendpoint-independent, address-and-port-dependent
Defaultendpoint-independent
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

flow-log-policy
Synopsis Enter the flow-log-policy context
Contextconfigure service nat nat-policy string flow-log-policy
Treeflow-log-policy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ipfix reference
Synopsis IPFIX export policy
Context configure service nat nat-policy string flow-log-policy ipfix reference
Treeipfix

Description

This command specifies an IP flow information export policy for the flow-log policy.

Reference

configure service ipfix export-policy string

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

syslog reference
Synopsis Syslog export policy name
Context configure service nat nat-policy string flow-log-policy syslog reference
Treesyslog

Description

This command configures a syslog export policy with a set of transport parameters used to transmit NAT flow records in syslog format to an external collector node. The policy name is referenced from the NAT policy applied to an inside routing context.

Reference

configure service nat syslog export-policy string

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

l2-outside
Synopsis Use Layer 2 outside service address location
Contextconfigure service nat nat-policy string l2-outside
Treel2-outside

Description

This command specifies Layer 2 outside service address location for the NAT policy instead of Layer 3 outside service.

Notes

The following elements are part of a choice: dnat-only, l2-outside, or pool.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

pool
Synopsis Enter the pool context
Context configure service nat nat-policy string pool
Treepool

Notes

The following elements are part of a choice: dnat-only, l2-outside, or pool.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

name string
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisNAT pool name
Contextconfigure service nat nat-policy string pool name string
Treename
String Length1 to 32
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

router-instance string
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisRouter or VPRN service name
Contextconfigure service nat nat-policy string pool router-instance string
Treerouter-instance
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

port-forwarding-range-end number
Synopsis End of the port forwarding range
Context configure service nat nat-policy string port-forwarding-range-end number
Treeport-forwarding-range-end

Description

This command specifies the end of the port range available for port forwarding. The start of the range is always equal to one.  

The number of ports that can be configured is half of the available block => 64512 / 2 = 32256. In combination with the configured value for port-forwarding-range-end, the formulas are:

max port-reservation blocks = 65535 - port-forwarding-range-end

max port-reservation ports = (65535 - port-forwarding-range-end) / 2

If port-reservation is already configured, the following applies for the maximum port-forwarding-range-end: 

max port-forwarding-range-end = 65535 - port-reservation blocksmax port-forwarding-range-end = 65535 - (port-reservation ports * 2)

Range1023 to 65535
Default1023
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

port-limits
Synopsis Enter the port-limits context
Context configure service nat nat-policy string port-limits
Treeport-limits
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dynamic-ports number
Synopsis Maximum number of dynamic ports per subscriber
Contextconfigure service nat nat-policy string port-limits dynamic-ports number
Treedynamic-ports

Description

This command limits the number of ports per protocol on an outside IP address for a subscriber regardless of the pool pairing mode. This command applies to LSN44 pools with flexible port allocation.

Range1 to 65536
Default65536
Introduced 23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

reserved number
Synopsis Number of ports reserved for prioritized sessions
Contextconfigure service nat nat-policy string port-limits reserved number
Treereserved

Description

This command configures the number of ports per block that are reserved for prioritized sessions.

Range1 to 65534
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

watermarks
Synopsis Enable the watermarks context
Context configure service nat nat-policy string port-limits watermarks
Treewatermarks

Description

This command configures watermarks for NAT resources.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

high number
Synopsis High watermark percentage
Context configure service nat nat-policy string port-limits watermarks high number
Treehigh

Description

This command configures the high threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

low number
Synopsis Low watermark percentage
Context configure service nat nat-policy string port-limits watermarks low number
Treelow

Description

This command configures the low threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

priority-sessions
Synopsis Enter the priority-sessions context
Contextconfigure service nat nat-policy string priority-sessions
Treepriority-sessions
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

fc
Synopsis Enter the fc context
Context configure service nat nat-policy string priority-sessions fc
Treefc

Description

Commands in this context specify which Forwarding Class (FC) options have prioritized sessions. 

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

af boolean
Synopsis Prioritize traffic from AF forwarding classes
Contextconfigure service nat nat-policy string priority-sessions fc af boolean
Treeaf

Description

When configured to true, traffic from Assured Forwarding (AF) FC sessions is prioritized. When configured to false, AF traffic is not prioritized.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

be boolean
Synopsis Prioritize traffic from BE forwarding classes
Contextconfigure service nat nat-policy string priority-sessions fc be boolean
Treebe

Description

When configured to true, traffic from Best Effort (BE) FC sessions is prioritized. When configured to false, BE traffic is not prioritized.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ef boolean
Synopsis Prioritize traffic from EF forwarding classes
Contextconfigure service nat nat-policy string priority-sessions fc ef boolean
Treeef
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

h1 boolean
Synopsis Prioritize traffic from H1 forwarding classes
Contextconfigure service nat nat-policy string priority-sessions fc h1 boolean
Treeh1

Description

When configured to true, traffic from H1 sessions is prioritized. When configured to false, H1 traffic is not prioritized.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

h2 boolean
Synopsis Prioritize traffic from H2 forwarding classes
Contextconfigure service nat nat-policy string priority-sessions fc h2 boolean
Treeh2
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

l1 boolean
Synopsis Prioritize traffic from L1 forwarding classes
Contextconfigure service nat nat-policy string priority-sessions fc l1 boolean
Treel1
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

l2 boolean
Synopsis Prioritize traffic from L2 forwarding classes
Contextconfigure service nat nat-policy string priority-sessions fc l2 boolean
Treel2

Description

When configured to true, traffic from L2 sessions is prioritized. When configured to false, L2 traffic is not prioritized.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

nc boolean
Synopsis Prioritize traffic from NC forwarding classes
Contextconfigure service nat nat-policy string priority-sessions fc nc boolean
Treenc
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

session-limits
Synopsis Enter the session-limits context
Contextconfigure service nat nat-policy string session-limits
Treesession-limits

Description

Commands in this context configure session-limit attributes for the policy.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

max number
Synopsis Maximum number of sessions per subscriber
Contextconfigure service nat nat-policy string session-limits max number
Treemax
Range1 to 65535
Default65535
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

reserved number
Synopsis Number of sessions reserved for prioritized sessions
Contextconfigure service nat nat-policy string session-limits reserved number
Treereserved

Description

This command configures the number of sessions per block that are reserved for prioritized sessions.

Range1 to 65534
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

watermarks
Synopsis Enable the watermarks context
Context configure service nat nat-policy string session-limits watermarks
Treewatermarks

Description

This command configures watermarks for NAT resources.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

high number
Synopsis High watermark percentage
Context configure service nat nat-policy string session-limits watermarks high number
Treehigh

Description

This command configures the high threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

low number
Synopsis Low watermark percentage
Context configure service nat nat-policy string session-limits watermarks low number
Treelow

Description

This command configures the low threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

tcp
Synopsis Enter the tcp context
Context configure service nat nat-policy string tcp
Treetcp

Description

Commands in this context configure the transmission control protocol (TCP) attributes of the policy. 

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mss-adjust number
Synopsis TCP MSS adjustment value
Context configure service nat nat-policy string tcp mss-adjust number
Treemss-adjust

Description

This command configures the value to use to adjust the TCP Maximum Segment Size (MSS) option, if not already present or the present value is higher.

Range160 to 10240
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

reset-unknown boolean
Synopsis Generate TCP reset for packets from unknown flows
Contextconfigure service nat nat-policy string tcp reset-unknown boolean
Treereset-unknown

Description

When configured to true, TCP packets are dropped and a TCP reset is generated if the NAT inside receives a TCP packet without the SYN flag set for an unknown flow.

When configured to false, no TCP reset is generated.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

timeouts
Synopsis Enter the timeouts context
Context configure service nat nat-policy string timeouts
Treetimeouts

Description

Commands in this context configure the attributes of session idle timeouts for the policy.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

icmp-query number
Synopsis Timeout applied to an ICMP Query session
Contextconfigure service nat nat-policy string timeouts icmp-query number
Treeicmp-query
Range60 to 240
Unitsseconds
Default 60
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

sip number
Synopsis SIP inactive media timeout
Context configure service nat nat-policy string timeouts sip number
Treesip
Range10 to 7200
Unitsseconds
Default 120
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

subscriber-retention number
Synopsis IP address hold time after host and port blocks expire
Contextconfigure service nat nat-policy string timeouts subscriber-retention number
Treesubscriber-retention

Description

This command configures the time to keep a NAT subscriber and its associated IP address after all hosts and associated port blocks expire. If a NAT subscriber host appears before the retention timeout elapses, it is given the same outside IP address.

Range0 to 1440
Unitsminutes
Default 0
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

tcp
Synopsis Enter the tcp context
Context configure service nat nat-policy string timeouts tcp
Treetcp

Description

Commands in this context configure TCP timeout attributes. 

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

established number
Synopsis Idle timeout for TCP session in established state
Contextconfigure service nat nat-policy string timeouts tcp established number
Treeestablished
Range60 to 86400
Unitsseconds
Default 7440
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

rst number
Synopsis Suspend time for TCP connection ports closed by RST
Contextconfigure service nat nat-policy string timeouts tcp rst number
Treerst

Description

This command configures the suspend time for outside TCP ports that are used in translations for TCP connections, when they are closed by TCP Reset (RST). After the timer expires, the outside ports can be reused for new TCP translations.

Range0 to 240
Unitsseconds
Default 0
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

syn number
Synopsis TCP session timeout when synchronizing initial sequence
Contextconfigure service nat nat-policy string timeouts tcp syn number
Treesyn
Range6 to 86400
Unitsseconds
Default 15
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

time-wait number
Synopsis Timeout applied to a TCP session in the time-wait state
Contextconfigure service nat nat-policy string timeouts tcp time-wait number
Treetime-wait
Range0 to 240
Unitsseconds
Default 0
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

transitory number
Synopsis Idle timeout for TCP session in transitory state
Contextconfigure service nat nat-policy string timeouts tcp transitory number
Treetransitory
Range60 to 86400
Unitsseconds
Default 240
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

udp
Synopsis Enter the udp context
Context configure service nat nat-policy string timeouts udp
Treeudp

Description

Commands in this context configure the User Datagram Protocol (UDP) mapping timeout attributes.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dns number
Synopsis Timeout applied to UDP session with destination port 53
Contextconfigure service nat nat-policy string timeouts udp dns number
Treedns
Range15 to 86400
Unitsseconds
Default 15
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

initial number
Synopsis UDP mapping timeout applied to new sessions
Contextconfigure service nat nat-policy string timeouts udp initial number
Treeinitial
Range10 to 300
Unitsseconds
Default 15
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

normal number
Synopsis UDP mapping timeout
Context configure service nat nat-policy string timeouts udp normal number
Treenormal
Range60 to 86400
Unitsseconds
Default 300
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

udp
Synopsis Enter the udp context
Context configure service nat nat-policy string udp
Treeudp
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

inbound-refresh boolean
Synopsis Extend UDP session timeout on inbound traffic
Contextconfigure service nat nat-policy string udp inbound-refresh boolean
Treeinbound-refresh

Description

When configured to true, this command extends the UDP session timeout on inbound traffic. 

When configured to false, the UDP session timeout is not extended.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

pcp-server-policy [name] string
Synopsis Enter the pcp-server-policy list instance
Contextconfigure service nat pcp-server-policy string
Treepcp-server-policy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis PCP server policy name
Context configure service nat pcp-server-policy string
Treepcp-server-policy
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

lifetime
Synopsis Enter the lifetime context
Context configure service nat pcp-server-policy string lifetime
Treelifetime
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

maximum number
Synopsis Maximum lifetime of explicit mappings made by the PCP servers
Contextconfigure service nat pcp-server-policy string lifetime maximum number
Treemaximum
Range61 to 86400
Default86400
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

minimum number
Synopsis Minimum lifetime of explicit mappings made by the PCP servers
Contextconfigure service nat pcp-server-policy string lifetime minimum number
Treeminimum
Range60 to 86399
Default120
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

opcode
Synopsis Enter the opcode context
Context configure service nat pcp-server-policy string opcode
Treeopcode
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

get boolean
Synopsis Process the get PCP requests
Context configure service nat pcp-server-policy string opcode get boolean
Treeget
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

map boolean
Synopsis Process the map PCP requests
Context configure service nat pcp-server-policy string opcode map boolean
Treemap
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

option
Synopsis Enter the option context
Context configure service nat pcp-server-policy string option
Treeoption
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

next boolean
Synopsis Process the PCP requests that contain the next option
Contextconfigure service nat pcp-server-policy string option next boolean
Treenext
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

port-set boolean
Synopsis Support the PORT_SET option in PCP MAP requests
Contextconfigure service nat pcp-server-policy string option port-set boolean
Treeport-set

Description

When configured to true, the PCP MAP option optimizes PCP performance for applications that require multiple sets of port forwards. A range of consecutive port forwards can be requested by the PCP client with a single PCP request.  

When configured to false, the default behavior is applied, where a plain MAP option is used to allocate a single port in a single request.

Defaultfalse
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

reuse-external-ip-address boolean
Synopsis Reuse external IP address for NAT subscriber
Contextconfigure service nat pcp-server-policy string reuse-external-ip-address boolean
Treereuse-external-ip-address

Description

When configured to true, the system reuses the external IP address assigned to a subscriber when the requested well-known port or external IP mapping is not available.

When configured to false, a request for a well-known port is allocated as requested on a different external IP address if the port is already allocated to another subscriber sharing the same external IP address. The existing external IP address is initially allocated to the subscriber as a result of the initial traffic flow.

This configuration flag can be set dynamically but the flag affects only PCP port forwards that are created after the flag has been set.

Defaultfalse
Introduced19.10.R3

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

version
Synopsis Enter the version context
Context configure service nat pcp-server-policy string version
Treeversion
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

maximum number
Synopsis Maximum protocol version supported by the PCP servers
Contextconfigure service nat pcp-server-policy string version maximum number
Treemaximum
Range1 to 255
Default1
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

minimum number
Synopsis Minimum protocol version supported by the PCP servers
Contextconfigure service nat pcp-server-policy string version minimum number
Treeminimum
Range1 to 255
Default1
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

prefix-list [name] string
Synopsis Enter the prefix-list list instance
Contextconfigure service nat prefix-list string
Treeprefix-list
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis NAT prefix list name
Context configure service nat prefix-list string
Treeprefix-list
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

application keyword
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPrefix list for the application
Contextconfigure service nat prefix-list string application keyword
Treeapplication
Optionsl2-aware-dest-to-policy, dnat-only-subscribers
Defaultl2-aware-dest-to-policy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

prefix [ip-prefix] string
Synopsis Enter the prefix list instance
Contextconfigure service nat prefix-list string prefix string
Treeprefix
Max. Instances1024
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[ip-prefix] string
Synopsis NAT prefix
Contextconfigure service nat prefix-list string prefix string
Treeprefix

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

nat-policy reference
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNAT policy for LSN
Contextconfigure service nat prefix-list string prefix string nat-policy reference
Treenat-policy

Reference

configure service nat nat-policy string

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

syslog
Synopsis Enter the syslog context
Context configure service nat syslog
Treesyslog
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

export-policy [name] string
Synopsis Enter the export-policy list instance
Contextconfigure service nat syslog export-policy string
Treeexport-policy
Max. Instances8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis Syslog export policy name
Context configure service nat syslog export-policy string
Treeexport-policy
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

collector router-instance string ip-address string
Synopsis Enter the collector list instance
Contextconfigure service nat syslog export-policy string collector router-instance string ip-address string
Treecollector
Max. Instances2
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

facility keyword
Synopsis Facility number in the PRI part of the NAT SYSLOG messages
Contextconfigure service nat syslog export-policy string facility keyword
Treefacility
Optionskernel, user, mail, systemd, auth, syslogd, printer, netnews, uucp, cron, authpriv, ftp, ntp, logaudit, logalert, cron2, local0, local1, local2, local3, local4, local5, local6, local7
Default local0
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

include
Synopsis Enter the include context
Context configure service nat syslog export-policy string include
Treeinclude
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

log-prefix string
Synopsis Optional prefix text in the MSG part of the NAT syslog messages
Contextconfigure service nat syslog export-policy string log-prefix string
Treelog-prefix
String Length1 to 32
DefaultTMNX
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

max-tx-delay number
Synopsis Maximum time a syslog message delays in the output buffer to aggregate multiple events
Contextconfigure service nat syslog export-policy string max-tx-delay number
Treemax-tx-delay
Range0 to 100
Unitsdeciseconds
Default 3
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mtu number
Synopsis Maximum transmission unit
Context configure service nat syslog export-policy string mtu number
Treemtu
Range512 to 9000
Default1500
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

rate-limit number
Synopsis Frame limit
Contextconfigure service nat syslog export-policy string rate-limit number
Treerate-limit
Range10 to 2147483647
Unitspackets per second
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

severity-level keyword
Synopsis Severity level in the PRI part of the syslog messages
Contextconfigure service nat syslog export-policy string severity-level keyword
Treeseverity-level
Optionsemergency, alert, critical, error, warning, notice, info, debug
Default info
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

up-nat-policy [name] string
Synopsis Enter the up-nat-policy list instance
Contextconfigure service nat up-nat-policy string
Treeup-nat-policy
Max. Instances32
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis UP NAT policy name
Context configure service nat up-nat-policy string
Treeup-nat-policy

Description

This command specifies the UP NAT policy name. The name default has a special meaning representing the default UP NAT policy template. The system uses the default template when the BNG CPF does not receive a more specific name when the subscriber is instantiated.

String Length1 to 32

Notes

This element is part of a list key.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

alg
Synopsis Enter the alg context
Context configure service nat up-nat-policy string alg
Treealg

Description

Commands in this context configure the Application Layer Gateway (ALG) attributes of the policy.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ftp boolean
Synopsis Use FTP ALG for the policy
Context configure service nat up-nat-policy string alg ftp boolean
Treeftp
Defaulttrue
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

pptp boolean
Synopsis Use PPTP ALG for the policy
Context configure service nat up-nat-policy string alg pptp boolean
Treepptp

Description

When configured to true, the policy uses Point-to-Point Tunneling Protocol (PPTP) ALG. 

PPTP sessions can only be initiated from NAT inside. 

GRE traffic is allowed through NAT only if the corresponding mapping exists.

There can be seven calls (GRE tunnels) per control session.

When configured to false, PPTP ALG is not used.

Defaultfalse
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

rtsp boolean
Synopsis Use RTSP ALG for the policy
Context configure service nat up-nat-policy string alg rtsp boolean
Treertsp

Description

When configured to true, Real-Time Streaming Protocol (RTSP) ALG is used for the policy.

Defaultfalse
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

sip boolean
Synopsis Use SIP ALG for the policy
Context configure service nat up-nat-policy string alg sip boolean
Treesip
Defaultfalse
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

block-limit number
Synopsis Maximum number of port blocks per NAT subscriber
Contextconfigure service nat up-nat-policy string block-limit number
Treeblock-limit
Range1 to 10
Default1
Introduced 23.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

default-host
Synopsis Enable the default-host context
Contextconfigure service nat up-nat-policy string default-host
Treedefault-host

Description

Commands in this context configure the default DMZ host options. A default DMZ host is a node on the inside to which all unknown traffic is redirected by changing the destination IPv4 address in the traffic header. During this operation, the checksums in the Layer 3 and Layer 4 header (UDP and TCP) are recalculated. 

Unknown traffic in NAT represent all unmatched traffic arriving from the outside (where there is no pinhole or a matching flow record created by traffic initiated from the inside). The purpose of the default DMZ host is to capture and analyze the unknown traffic as part of threat analysis.

The rate of redirected unknown traffic can be restricted by configuration.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-address string
Synopsis IP address of the default DMZ host
Context configure service nat up-nat-policy string default-host ip-address string
Treeip-address

Description

This command configures the IP address of the default DMZ host. Redirection to the default DMZ host is achieved by replacing the destination IP address in the traffic header in the unknown traffic initiated from the outside with the one of the default DMZ host.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

rate-limit number
Synopsis Rate limit for unknown traffic sent to default DMZ host
Contextconfigure service nat up-nat-policy string default-host rate-limit number
Treerate-limit

Description

This command configures the rate limit of the unknown traffic sent to the default DMZ host.

Unknown traffic sent to the default DMZ host is rate limited by a configurable value expressed in mbps. The rate limit is configurable per NAT pool per ISA, vISA, or ESA-VM.

Range1 to 10000
Unitsmegabps
Default 10
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

filtering keyword
Synopsis Filtering method for inbound traffic for the policy
Contextconfigure service nat up-nat-policy string filtering keyword
Treefiltering
Optionsendpoint-independent, address-and-port-dependent
Defaultendpoint-independent
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

flow-log-policy
Synopsis Enter the flow-log-policy context
Contextconfigure service nat up-nat-policy string flow-log-policy
Treeflow-log-policy
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

port-block-extension
Synopsis Enable the port-block-extension context
Contextconfigure service nat up-nat-policy string port-block-extension
Treeport-block-extension

Description

Commands in this context configure the attributes for dynamic allocation of NAT port-blocks beyond the initial port-blocks.

Introduced23.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ports number
Synopsis Number of ports per dynamic port block
Contextconfigure service nat up-nat-policy string port-block-extension ports number
Treeports
Range10 to 5000

Notes

This element is mandatory.

Introduced23.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

watermarks
Synopsis Enable the watermarks context
Context configure service nat up-nat-policy string port-block-extension watermarks
Treewatermarks
Introduced23.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

high number
Synopsis High watermark percentage
Context configure service nat up-nat-policy string port-block-extension watermarks high number
Treehigh

Description

This command configures the high threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 23.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

low number
Synopsis Low watermark percentage
Context configure service nat up-nat-policy string port-block-extension watermarks low number
Treelow

Description

This command configures the low threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 23.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

port-limits
Synopsis Enter the port-limits context
Context configure service nat up-nat-policy string port-limits
Treeport-limits
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dynamic-ports number
Synopsis Maximum number of dynamic ports per subscriber
Contextconfigure service nat up-nat-policy string port-limits dynamic-ports number
Treedynamic-ports

Description

This command limits the number of ports per protocol on an outside IP address for a subscriber regardless of the pool pairing mode. This command applies to LSN44 pools with flexible port allocation.

Range1 to 65536
Default65536
Introduced 23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

reserved number
Synopsis Number of ports reserved for prioritized sessions
Contextconfigure service nat up-nat-policy string port-limits reserved number
Treereserved

Description

This command configures the number of ports per block that are reserved for prioritized sessions.

Range1 to 65534
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

watermarks
Synopsis Enable the watermarks context
Context configure service nat up-nat-policy string port-limits watermarks
Treewatermarks

Description

This command configures watermarks for NAT resources.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

high number
Synopsis High watermark percentage
Context configure service nat up-nat-policy string port-limits watermarks high number
Treehigh

Description

This command configures the high threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

low number
Synopsis Low watermark percentage
Context configure service nat up-nat-policy string port-limits watermarks low number
Treelow

Description

This command configures the low threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

priority-sessions
Synopsis Enter the priority-sessions context
Contextconfigure service nat up-nat-policy string priority-sessions
Treepriority-sessions
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

fc
Synopsis Enter the fc context
Context configure service nat up-nat-policy string priority-sessions fc
Treefc

Description

Commands in this context specify which Forwarding Class (FC) options have prioritized sessions. 

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

af boolean
Synopsis Prioritize traffic from AF forwarding classes
Contextconfigure service nat up-nat-policy string priority-sessions fc af boolean
Treeaf

Description

When configured to true, traffic from Assured Forwarding (AF) FC sessions is prioritized. When configured to false, AF traffic is not prioritized.

Defaultfalse
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

be boolean
Synopsis Prioritize traffic from BE forwarding classes
Contextconfigure service nat up-nat-policy string priority-sessions fc be boolean
Treebe

Description

When configured to true, traffic from Best Effort (BE) FC sessions is prioritized. When configured to false, BE traffic is not prioritized.

Defaultfalse
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ef boolean
Synopsis Prioritize traffic from EF forwarding classes
Contextconfigure service nat up-nat-policy string priority-sessions fc ef boolean
Treeef
Defaultfalse
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

h1 boolean
Synopsis Prioritize traffic from H1 forwarding classes
Contextconfigure service nat up-nat-policy string priority-sessions fc h1 boolean
Treeh1

Description

When configured to true, traffic from H1 sessions is prioritized. When configured to false, H1 traffic is not prioritized.

Defaultfalse
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

h2 boolean
Synopsis Prioritize traffic from H2 forwarding classes
Contextconfigure service nat up-nat-policy string priority-sessions fc h2 boolean
Treeh2
Defaultfalse
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

l1 boolean
Synopsis Prioritize traffic from L1 forwarding classes
Contextconfigure service nat up-nat-policy string priority-sessions fc l1 boolean
Treel1
Defaultfalse
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

l2 boolean
Synopsis Prioritize traffic from L2 forwarding classes
Contextconfigure service nat up-nat-policy string priority-sessions fc l2 boolean
Treel2

Description

When configured to true, traffic from L2 sessions is prioritized. When configured to false, L2 traffic is not prioritized.

Defaultfalse
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

nc boolean
Synopsis Prioritize traffic from NC forwarding classes
Contextconfigure service nat up-nat-policy string priority-sessions fc nc boolean
Treenc
Defaultfalse
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

session-limits
Synopsis Enter the session-limits context
Contextconfigure service nat up-nat-policy string session-limits
Treesession-limits

Description

Commands in this context configure session-limit attributes for the policy.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

max number
Synopsis Maximum number of sessions per subscriber
Contextconfigure service nat up-nat-policy string session-limits max number
Treemax
Range1 to 65535
Default65535
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

reserved number
Synopsis Number of sessions reserved for prioritized sessions
Contextconfigure service nat up-nat-policy string session-limits reserved number
Treereserved

Description

This command configures the number of sessions per block that are reserved for prioritized sessions.

Range1 to 65534
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

watermarks
Synopsis Enable the watermarks context
Context configure service nat up-nat-policy string session-limits watermarks
Treewatermarks

Description

This command configures watermarks for NAT resources.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

high number
Synopsis High watermark percentage
Context configure service nat up-nat-policy string session-limits watermarks high number
Treehigh

Description

This command configures the high threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

low number
Synopsis Low watermark percentage
Context configure service nat up-nat-policy string session-limits watermarks low number
Treelow

Description

This command configures the low threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

tcp
Synopsis Enter the tcp context
Context configure service nat up-nat-policy string tcp
Treetcp

Description

Commands in this context configure the transmission control protocol (TCP) attributes of the policy. 

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mss-adjust number
Synopsis TCP MSS adjustment value
Context configure service nat up-nat-policy string tcp mss-adjust number
Treemss-adjust

Description

This command configures the value to use to adjust the TCP Maximum Segment Size (MSS) option, if not already present or the present value is higher.

Range160 to 10240
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

reset-unknown boolean
Synopsis Generate TCP reset for packets from unknown flows
Contextconfigure service nat up-nat-policy string tcp reset-unknown boolean
Treereset-unknown

Description

When configured to true, TCP packets are dropped and a TCP reset is generated if the NAT inside receives a TCP packet without the SYN flag set for an unknown flow.

When configured to false, no TCP reset is generated.

Defaultfalse
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

timeouts
Synopsis Enter the timeouts context
Context configure service nat up-nat-policy string timeouts
Treetimeouts

Description

Commands in this context configure the attributes of session idle timeouts for the policy.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

icmp-query number
Synopsis Timeout applied to an ICMP Query session
Contextconfigure service nat up-nat-policy string timeouts icmp-query number
Treeicmp-query
Range60 to 240
Unitsseconds
Default 60
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

sip number
Synopsis SIP inactive media timeout
Context configure service nat up-nat-policy string timeouts sip number
Treesip
Range10 to 7200
Unitsseconds
Default 120
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

subscriber-retention number
Synopsis IP address hold time after host and port blocks expire
Contextconfigure service nat up-nat-policy string timeouts subscriber-retention number
Treesubscriber-retention

Description

This command configures the time to keep a NAT subscriber and its associated IP address after all hosts and associated port blocks expire. If a NAT subscriber host appears before the retention timeout elapses, it is given the same outside IP address.

Range0 to 1440
Unitsminutes
Default 0
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

tcp
Synopsis Enter the tcp context
Context configure service nat up-nat-policy string timeouts tcp
Treetcp

Description

Commands in this context configure TCP timeout attributes. 

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

established number
Synopsis Idle timeout for TCP session in established state
Contextconfigure service nat up-nat-policy string timeouts tcp established number
Treeestablished
Range60 to 86400
Unitsseconds
Default 7440
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

rst number
Synopsis Suspend time for TCP connection ports closed by RST
Contextconfigure service nat up-nat-policy string timeouts tcp rst number
Treerst

Description

This command configures the suspend time for outside TCP ports that are used in translations for TCP connections, when they are closed by TCP Reset (RST). After the timer expires, the outside ports can be reused for new TCP translations.

Range0 to 240
Unitsseconds
Default 0
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

syn number
Synopsis TCP session timeout when synchronizing initial sequence
Contextconfigure service nat up-nat-policy string timeouts tcp syn number
Treesyn
Range6 to 86400
Unitsseconds
Default 15
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

time-wait number
Synopsis Timeout applied to a TCP session in the time-wait state
Contextconfigure service nat up-nat-policy string timeouts tcp time-wait number
Treetime-wait
Range0 to 240
Unitsseconds
Default 0
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

transitory number
Synopsis Idle timeout for TCP session in transitory state
Contextconfigure service nat up-nat-policy string timeouts tcp transitory number
Treetransitory
Range60 to 86400
Unitsseconds
Default 240
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

udp
Synopsis Enter the udp context
Context configure service nat up-nat-policy string timeouts udp
Treeudp

Description

Commands in this context configure the User Datagram Protocol (UDP) mapping timeout attributes.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dns number
Synopsis Timeout applied to UDP session with destination port 53
Contextconfigure service nat up-nat-policy string timeouts udp dns number
Treedns
Range15 to 86400
Unitsseconds
Default 15
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

initial number
Synopsis UDP mapping timeout applied to new sessions
Contextconfigure service nat up-nat-policy string timeouts udp initial number
Treeinitial
Range10 to 300
Unitsseconds
Default 15
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

normal number
Synopsis UDP mapping timeout
Context configure service nat up-nat-policy string timeouts udp normal number
Treenormal
Range60 to 86400
Unitsseconds
Default 300
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

udp
Synopsis Enter the udp context
Context configure service nat up-nat-policy string udp
Treeudp
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

inbound-refresh boolean
Synopsis Extend UDP session timeout on inbound traffic
Contextconfigure service nat up-nat-policy string udp inbound-refresh boolean
Treeinbound-refresh

Description

When configured to true, this command extends the UDP session timeout on inbound traffic. 

When configured to false, the UDP session timeout is not extended.

Defaultfalse
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

oper-group [name] string

Synopsis Enter the oper-group list instance
Contextconfigure service oper-group string
Treeoper-group
Max. Instances32768
Introduced16.0.R1

Platforms

All

[name] string
Synopsis Operational group name
Context configure service oper-group string
Treeoper-group
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

bfd-liveness
Synopsis Enable the bfd-liveness context
Contextconfigure service oper-group string bfd-liveness
Treebfd-liveness
Introduced16.0.R1

Platforms

All

dest-ip string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDestination address for BFD
Contextconfigure service oper-group string bfd-liveness dest-ip string
Treedest-ip

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

interface-name string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSource interface name
Contextconfigure service oper-group string bfd-liveness interface-name string
Treeinterface-name
String Length1 to 32

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

router-instance string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisRouting context used for route lookup
Contextconfigure service oper-group string bfd-liveness router-instance string
Treerouter-instance

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

hold-time
Synopsis Enter the hold-time context
Context configure service oper-group string hold-time
Treehold-time
Introduced16.0.R1

Platforms

All

down number
Synopsis Oper group hold down time
Context configure service oper-group string hold-time down number
Treedown
Range1 to 3600
Unitsseconds
Introduced 16.0.R3

Platforms

All

up number
Synopsis Oper group hold up time
Context configure service oper-group string hold-time up number
Treeup
Range0 to 3600
Unitsseconds
Default 4
Introduced16.0.R3

Platforms

All

pbb

Synopsis Enter the pbb context
Context configure service pbb
Treepbb
Introduced16.0.R1

Platforms

All

mac [name] string
Synopsis Enter the mac list instance
Context configure service pbb mac string
Treemac
Introduced16.0.R1

Platforms

All

[name] string
Synopsis MAC name for the MAC address
Context configure service pbb mac string
Treemac
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

address string
Synopsis IEEE address assigned to the MAC name
Contextconfigure service pbb mac string address string
Treeaddress

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

mac-notification
Synopsis Enter the mac-notification context
Contextconfigure service pbb mac-notification
Treemac-notification
Introduced16.0.R1

Platforms

All

source-bmac
Synopsis Enter the source-bmac context
Context configure service pbb source-bmac
Treesource-bmac
Introduced16.0.R1

Platforms

All

proxy-arp-nd

Synopsis Enter the proxy-arp-nd context
Contextconfigure service proxy-arp-nd
Treeproxy-arp-nd
Introduced16.0.R1

Platforms

All

mac-list
Synopsis Enter the mac-list context
Context configure service proxy-arp-nd mac-list
Treemac-list
Introduced16.0.R1

Platforms

All

list [list-name] string
Synopsis Enter the list list instance
Context configure service proxy-arp-nd mac-list list string
Treelist
Introduced16.0.R1

Platforms

All

[list-name] string
Synopsis Specify name for mac list
Context configure service proxy-arp-nd mac-list list string
Treelist
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

pw-template [pw-template-name] string

Synopsis Enter the pw-template list instance
Contextconfigure service pw-template string
Treepw-template
Max. Instances2048
Introduced16.0.R1

Platforms

All

[pw-template-name] string
Synopsis SDP template name
Context configure service pw-template string
Treepw-template
String Length1 to 64

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

auto-gre-sdp boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisUse a GRE tunnel to automatically create an SDP
Contextconfigure service pw-template string auto-gre-sdp boolean
Treeauto-gre-sdp
Defaultfalse
Introduced16.0.R1

Platforms

All

egress
Synopsis Enter the egress context
Context configure service pw-template string egress
Treeegress
Introduced16.0.R1

Platforms

All

filter
Synopsis Enter the filter context
Context configure service pw-template string egress filter
Treefilter
Introduced16.0.R1

Platforms

All

ip string
Synopsis IPv4 filter policy name
Context configure service pw-template string egress filter ip string
Treeip
String Length1 to 64
Introduced16.0.R1

Platforms

All

mfib-allowed-mda-destinations
Synopsis Enter the mfib-allowed-mda-destinations context
Contextconfigure service pw-template string egress mfib-allowed-mda-destinations
Treemfib-allowed-mda-destinations
Introduced16.0.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service pw-template string egress qos
Treeqos
Introduced16.0.R1

Platforms

All

network
Synopsis Enter the network context
Context configure service pw-template string egress qos network
Treenetwork
Introduced16.0.R1

Platforms

All

port-redirect-group
Synopsis Enter the port-redirect-group context
Contextconfigure service pw-template string egress qos network port-redirect-group
Treeport-redirect-group
Introduced16.0.R1

Platforms

All

encryption-keygroup
Synopsis Enter the encryption-keygroup context
Contextconfigure service pw-template string encryption-keygroup
Treeencryption-keygroup
Introduced19.10.R1

Platforms

VSR

entropy-label
Synopsis Enable the use of an entropy label
Context configure service pw-template string entropy-label
Treeentropy-label

Notes

The following elements are part of a choice: entropy-label or hash-label.

Introduced16.0.R1

Platforms

All

fdb
Synopsis Enter the fdb context
Context configure service pw-template string fdb
Treefdb
Introduced16.0.R1

Platforms

All

auto-learn-mac-protect-exclude-list string
Synopsis Name of the MAC protect exclusion list
Contextconfigure service pw-template string fdb auto-learn-mac-protect-exclude-list string
Treeauto-learn-mac-protect-exclude-list

Description

This command configures the name of a MAC protect exclusion list.

Dynamically-learned MAC Source Addresses (SA) are protected if they are learned on an object with ALMP configured and no exclusion list is associated with the object, or if the MAC SA does not match any entry in an associated exclusion list.

An exclusion list can be used in multiple objects of a service. If a list is empty, ALMP does not exclude any learned MAC SAs from protection on the object.

String Length1 to 32
Introduced20.5.R1

Platforms

All

mac-learning
Synopsis Enter the mac-learning context
Contextconfigure service pw-template string fdb mac-learning
Treemac-learning
Introduced16.0.R1

Platforms

All

maximum-mac-addresses number
Synopsis Maximum number of MAC address entries in the FDB
Contextconfigure service pw-template string fdb maximum-mac-addresses number
Treemaximum-mac-addresses

Description

This command specifies the maximum number of FDB entries for both learned and static MAC addresses for this PW template.

When the configured limit is reached, no new addresses are learned from the SAP or spoke SDP until at least one FDB entry is aged out or cleared.

When the configured limit is reached and the configure service pw-template fdb discard-unknown-source command is set to true for this PW template, packets with unknown source MAC addresses are discarded. If discard-unknown-source is set to false, the packets are forwarded if their destination MAC addresses are known, or flooded if their destination MAC addresses are unknown.

However, if the configure service vpls fdb discard-unknown command is set to true, packets with unknown destination MAC addresses are discarded, even if the limit of FDB entries on the specific VPLS instance is not reached.

When unconfigured, the PW template uses the global MAC learning limitations.

Range1 to 511999
Introduced16.0.R1

Platforms

All

hash-label
Synopsis Enable the hash-label context
Context configure service pw-template string hash-label
Treehash-label

Description

Commands in this context configure the use of hash labels for egress datapaths.

For information about hash-label handling, see the "Hash labels" section of the 7450 ESS, 7750 SR, 7950 XRS, and VSR MPLS Guide.

Notes

The following elements are part of a choice: entropy-label or hash-label.

Introduced16.0.R1

Platforms

All

signal-capability
Synopsis Signal hash label capability to the remote PE
Contextconfigure service pw-template string hash-label signal-capability
Treesignal-capability

Description

When configured, this command enables the signaling and negotiating of the hash label between the local and remote PE nodes.

The signaling process outcome determines whether the local PE inserts the hash label on the user packets. This outcome can override the local PE configuration. The node must withdraw the label it sent to its peer and send a new label mapping message with the new value of the F-bit in the flow label interface option sub-TLV of the pseudowire ID FEC element.

Introduced16.0.R1

Platforms

All

igmp-snooping
Synopsis Enter the igmp-snooping context
Contextconfigure service pw-template string igmp-snooping
Treeigmp-snooping
Introduced16.0.R1

Platforms

All

ingress
Synopsis Enter the ingress context
Context configure service pw-template string ingress
Treeingress
Introduced16.0.R1

Platforms

All

filter
Synopsis Enter the filter context
Context configure service pw-template string ingress filter
Treefilter
Introduced16.0.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service pw-template string ingress qos
Treeqos
Introduced16.0.R1

Platforms

All

network
Synopsis Enter the network context
Context configure service pw-template string ingress qos network
Treenetwork
Introduced16.0.R1

Platforms

All

fp-redirect-group
Synopsis Enter the fp-redirect-group context
Contextconfigure service pw-template string ingress qos network fp-redirect-group
Treefp-redirect-group
Introduced16.0.R1

Platforms

All

l2pt
Synopsis Enter the l2pt context
Context configure service pw-template string l2pt
Treel2pt
Introduced16.0.R1

Platforms

All

termination
Synopsis Enable the termination context
Contextconfigure service pw-template string l2pt termination
Treetermination
Introduced16.0.R1

Platforms

All

protocols
Synopsis Enter the protocols context
Context configure service pw-template string l2pt termination protocols
Treeprotocols
Introduced16.0.R1

Platforms

All

provisioned-sdp keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisProvisioned SDP type
Contextconfigure service pw-template string provisioned-sdp keyword
Treeprovisioned-sdp
Optionsuse, prefer
Introduced 16.0.R1

Platforms

All

pw-template-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPW Template Id
Contextconfigure service pw-template string pw-template-id number
Treepw-template-id
Range1 to 2147483647
Introduced16.0.R1

Platforms

All

split-horizon-group
Synopsis Enter the split-horizon-group context
Contextconfigure service pw-template string split-horizon-group
Treesplit-horizon-group
Introduced16.0.R1

Platforms

All

fdb
Synopsis Enter the fdb context
Context configure service pw-template string split-horizon-group fdb
Treefdb
Introduced16.0.R1

Platforms

All

saps
Synopsis Enter the saps context
Context configure service pw-template string split-horizon-group fdb saps
Treesaps
Introduced16.0.R1

Platforms

All

stp
Synopsis Enter the stp context
Context configure service pw-template string stp
Treestp
Introduced16.0.R4

Platforms

All

auto-edge boolean
Synopsis Enable automatic detection of edge port characteristics
Contextconfigure service pw-template string stp auto-edge boolean
Treeauto-edge
Defaulttrue
Introduced16.0.R4

Platforms

All

link-type keyword
Synopsis Configure STP link-type
Context configure service pw-template string stp link-type keyword
Treelink-type
Optionspt-pt, shared
Default pt-pt
Introduced16.0.R4

Platforms

All

vc-type keyword
Synopsis Virtual circuit type associated with the SDP bind
Contextconfigure service pw-template string vc-type keyword
Treevc-type
Optionsether, vlan
Default ether
Introduced16.0.R1

Platforms

All

sdp [sdp-id] number

Synopsis Enter the sdp list instance
Context configure service sdp number
Treesdp
Introduced16.0.R1

Platforms

All

[sdp-id] number
Synopsis Service Distribution Point (SDP) identifier
Contextconfigure service sdp number
Treesdp
Range1 to 32767

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

accounting-policy reference
Synopsis Accounting policy associated with an SDP
Contextconfigure service sdp number accounting-policy reference
Treeaccounting-policy

Description

This command associates an accounting policy with an SDP.

When unconfigured, there is no accounting policy applied to the SDP.

Reference

configure log accounting-policy number

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the SDP
Context configure service sdp number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

adv-mtu-override boolean
Synopsis Override the advertised VC-type MTU using the SDP ID
Contextconfigure service sdp number adv-mtu-override boolean
Treeadv-mtu-override
Defaultfalse
Introduced16.0.R1

Platforms

All

bgp-tunnel boolean
Synopsis Allow use of BGP route tunnels to reach far-end nodes
Contextconfigure service sdp number bgp-tunnel boolean
Treebgp-tunnel
Defaultfalse
Introduced16.0.R1

Platforms

All

booking-factor number
Synopsis Percentage of SDP max available bandwidth for VLL CAC
Contextconfigure service sdp number booking-factor number
Treebooking-factor
Range0 to 1000
Default100
Introduced 16.0.R1

Platforms

All

class-forwarding
Synopsis Enable the class-forwarding context
Contextconfigure service sdp number class-forwarding
Treeclass-forwarding
Introduced16.0.R1

Platforms

All

fc [fc-name] keyword
Synopsis Enter the fc list instance
Context configure service sdp number class-forwarding fc keyword
Treefc
Introduced16.0.R1

Platforms

All

[fc-name] keyword
Synopsis Forwarding class to LSP mapping
Context configure service sdp number class-forwarding fc keyword
Treefc
Optionsbe, l2, af, l1, h2, ef, h1, nc

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

lsp reference
Synopsis LSP name used to forward service packets
Contextconfigure service sdp number class-forwarding fc keyword lsp reference
Treelsp

Reference

configure service sdp number lsp string

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

collect-stats boolean
Synopsis Collect accounting statistics for this SDP
Contextconfigure service sdp number collect-stats boolean
Treecollect-stats
Defaultfalse
Introduced16.0.R1

Platforms

All

delivery-type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDelivery type used by the SDP
Contextconfigure service sdp number delivery-type keyword
Treedelivery-type
Optionsgre, mpls, l2tpv3, gre-eth-bridged
Introduced16.0.R1

Platforms

All

description string
Synopsis Text description
Context configure service sdp number description string
Treedescription
String Length1 to 80
Introduced16.0.R1

Platforms

All

far-end
Synopsis Enter the far-end context
Context configure service sdp number far-end
Treefar-end
Introduced16.0.R1

Platforms

All

ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIP address of the far end destination router
Contextconfigure service sdp number far-end ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeip-address
Introduced16.0.R3

Platforms

All

keep-alive
Synopsis Enter the keep-alive context
Context configure service sdp number keep-alive
Treekeep-alive
Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of keepalive mechanism for the SDP
Contextconfigure service sdp number keep-alive admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

hello-time number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTime period between SDP keepalive messages
Contextconfigure service sdp number keep-alive hello-time number
Treehello-time
Range1 to 3600
Unitsseconds
Default 10
Introduced16.0.R1

Platforms

All

timeout number
Synopsis Time SDP waits before tearing down the session
Contextconfigure service sdp number keep-alive timeout number
Treetimeout
Range1 to 10
Unitsseconds
Default 5
Introduced16.0.R1

Platforms

All

ldp boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable LDP-signaled LSPs
Contextconfigure service sdp number ldp boolean
Treeldp
Defaultfalse
Introduced16.0.R1

Platforms

All

local-end (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal end address of tunnel defined by the SDP
Contextconfigure service sdp number local-end (ipv4-address-no-zone | ipv6-address-no-zone)
Treelocal-end
Introduced16.0.R1

Platforms

All

lsp [lsp-name] string
Synopsis Add a list entry for lsp
Context configure service sdp number lsp string
Treelsp
Max. Instances16
Introduced16.0.R1

Platforms

All

[lsp-name] string
Synopsis LSP name to associate with the SDP
Context configure service sdp number lsp string
Treelsp
String Length1 to 64

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

metric number
Synopsis Metric used in tunnel table manager for decision making
Contextconfigure service sdp number metric number
Treemetric
Range1 to 65535
Introduced16.0.R1

Platforms

All

mixed-lsp-mode
Synopsis Enable the mixed-lsp-mode context
Contextconfigure service sdp number mixed-lsp-mode
Treemixed-lsp-mode
Introduced16.0.R1

Platforms

All

revert-time (number | keyword)
Synopsis Delay before SDP can revert to higher priority LSP type
Contextconfigure service sdp number mixed-lsp-mode revert-time (number | keyword)
Treerevert-time
Range1 to 600
Unitsseconds
Options never, immediate
Defaultimmediate
Introduced16.0.R1

Platforms

All

path-mtu number
Synopsis Maximum Transmission Unit (MTU) the SDP can transmit
Contextconfigure service sdp number path-mtu number
Treepath-mtu
Range576 to 9782
Unitsbytes
Introduced 16.0.R1

Platforms

All

pbb-etype string
Synopsis Ethertype used for PBB
Context configure service sdp number pbb-etype string
Treepbb-etype
String Length5 to 6
Default0x88E7
Introduced 16.0.R1

Platforms

All

signaling keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSignaling protocol used to obtain pseudowire labels
Contextconfigure service sdp number signaling keyword
Treesignaling

Description

This command specifies the signaling protocol used to obtain the ingress and egress pseudowire labels in frames transmitted and received on the SDP. The signaling value can only be changed while the administrative status of the SDP is down. Additionally, the signaling can only be changed on an SDP if the SDP is not in use by BGP-AD or BGP-VPLS. BGP signaling can only be enabled if the SDP does not already have pseudowires signaled over it. Also, BGP signaling is not supported with mixed mode LSP SDPs.

Note: If the tldp option is selected as the mechanism for exchanging service labels over an MPLS or GRE SDP and the T-LDP session is automatically established, an explicit T-LDP session that is subsequently configured takes precedence over the automatic T-LDP session. However, if the explicit, manually-configured session is then removed, the system does not revert to the automatic session and the automatic session is also deleted. To address this, recreate the T-LDP session by using the admin-state command to administratively disable and then enable the SDP.

Optionsoff, tldp, bgp
Introduced16.0.R1

Platforms

All

source-bmac-lsb
Synopsis Enter the source-bmac-lsb context
Contextconfigure service sdp number source-bmac-lsb
Treesource-bmac-lsb
Introduced16.0.R1

Platforms

All

value string
Synopsis 16 least significant bits of virtual backbone MAC
Contextconfigure service sdp number source-bmac-lsb value string
Treevalue
Introduced16.0.R1

Platforms

All

sr-isis boolean
Synopsis Enable Segment Routing for IS-IS
Context configure service sdp number sr-isis boolean
Treesr-isis
Defaultfalse
Introduced16.0.R1

Platforms

All

sr-ospf boolean
Synopsis Enable an MPLS SDP of LSP type OSPF Segment Routing
Contextconfigure service sdp number sr-ospf boolean
Treesr-ospf
Defaultfalse
Introduced16.0.R1

Platforms

All

tunnel-far-end (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSystem address of the far-end router for the SDP
Contextconfigure service sdp number tunnel-far-end (ipv4-address-no-zone | ipv6-address-no-zone)
Treetunnel-far-end
Introduced16.0.R1

Platforms

All

vlan-vc-etype string
Synopsis VLAN VC Ethertype
Context configure service sdp number vlan-vc-etype string
Treevlan-vc-etype
String Length5 to 6
Default0x8100
Introduced 16.0.R1

Platforms

All

weighted-ecmp boolean
Synopsis Allow weighted load-balancing on an SDP
Contextconfigure service sdp number weighted-ecmp boolean
Treeweighted-ecmp
Defaultfalse
Introduced16.0.R1

Platforms

All

sdp-group

Synopsis Enter the sdp-group context
Context configure service sdp-group
Treesdp-group
Introduced16.0.R1

Platforms

All

group-name [group-name] string
Synopsis Enter the group-name list instance
Contextconfigure service sdp-group group-name string
Treegroup-name
Introduced16.0.R1

Platforms

All

[group-name] string
Synopsis SDP administrative group name
Context configure service sdp-group group-name string
Treegroup-name
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

value number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisUnique group value associated with the SDP admin group
Contextconfigure service sdp-group group-name string value number
Treevalue
Range0 to 31

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

system

Synopsis Enter the system context
Context configure service system
Treesystem
Introduced16.0.R1

Platforms

All

bgp
Synopsis Enter the bgp context
Context configure service system bgp
Treebgp
Introduced16.0.R1

Platforms

All

evpn
Synopsis Enter the evpn context
Context configure service system bgp evpn
Treeevpn
Introduced16.0.R1

Platforms

All

ad-per-es-route
Synopsis Enter the ad-per-es-route context
Contextconfigure service system bgp evpn ad-per-es-route
Treead-per-es-route
Introduced16.0.R1

Platforms

All

extended-evi-range boolean
Synopsis Reserve extended RD comm-values for AD per-ES routes
Contextconfigure service system bgp evpn ad-per-es-route extended-evi-range boolean
Treeextended-evi-range

Description

When configured to true, the system reserves the Route Distinguisher (RD) comm-values 1 to 65535 out of the type 1 RD that is used for AD per-ES routes. If ad-per-es-route route-target-type is also configured to evi-route-target-set, the system can pack the maximum number of EVI route targets in the AD per-ES routes

When configured to false, this command only reserves comm-values 1 to 512.

Defaultfalse
Introduced21.10.R1

Platforms

All

ad-per-evi-routes
Synopsis Enter the ad-per-evi-routes context
Contextconfigure service system bgp evpn ad-per-evi-routes
Treead-per-evi-routes
Introduced23.10.R1

Platforms

All

attribute-propagation boolean
Synopsis Enable propagation of BGP path attributes
Contextconfigure service system bgp evpn ad-per-evi-routes attribute-propagation boolean
Treeattribute-propagation

Description

When configured to true, the router propagates the attributes in multi-instance Epipe services.

When configured to false, the router disables the propagation of the attributes, including D-PATH, even if the domain-id is configured in the service.

Defaultfalse
Introduced23.10.R1

Platforms

All

bgp-path-selection boolean
Synopsis Enable BGP path selection
Context configure service system bgp evpn ad-per-evi-routes bgp-path-selection boolean
Treebgp-path-selection

Description

When configured to true, the router compares the received EVPN VPWS AD per-EVI routes based on the BGP path attributes.

The attribute-propagation command must be configured to true.

When configured to false, the router does not compare the routes.

Defaultfalse
Introduced23.10.R1

Platforms

All

d-path-ignore boolean
Synopsis Ignore D-PATH for BGP path selection
Context configure service system bgp evpn ad-per-evi-routes d-path-ignore boolean
Treed-path-ignore

Description

When configured to true, the router ignores the Domain PATH attribute (D-PATH) when BGP computes the best path selection for received routes.

When configured to false, the router considers the D-PATH length and value as a tiebreaker in determining the best-path selection. In accordance with draft-sr-bess-evpn-dpath, the router compares the D-PATH attribute received in AD per-EVI routes with the same key (same or different RD) as follows:

  • Routes with the shortest D-PATH are preferred; therefore, routes not tied for the shortest D-PATH are removed. Routes without D-PATH are considered zero-length D-PATH.

  • Routes with the numerically lowest left-most Domain-ID are preferred; therefore, routes not tied for the numerically lowest left-most Domain-ID are removed from consideration.

Defaultfalse
Introduced23.10.R1

Platforms

All

ethernet-segment [ethernet-segment-name] string
Synopsis Enter the ethernet-segment list instance
Contextconfigure service system bgp evpn ethernet-segment string
Treeethernet-segment
Max. Instances4095
Introduced16.0.R1

Platforms

All

ac-df-capability keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAC-influenced DF election capability
Contextconfigure service system bgp evpn ethernet-segment string ac-df-capability keyword
Treeac-df-capability

Description

This command configures the Attachment Circuit-influenced (AC-influenced) designated forwarder (DF) election capability (AC-DF) into the DF election for the Ethernet Segment (ES). 

AC-DF supports EVPN Auto-Discovery per EVI/ES (AD per EVI/ES) routes for a specific PE, to ensure the PE is included in the candidate DF election list.

When AC-DF is excluded on a specific ES, the presence or absence of the AD per EVI/ES routes from the ES peers does not modify the candidate DF election list for the ES. Excluding the AC-DF is recommended in ESs that use an operational group monitored by the access LAG to signal the standby LACP or to power-off.

Optionsinclude, exclude
Default include
Introduced21.5.R1

Platforms

All

association
Synopsis Enter the association context
Context configure service system bgp evpn ethernet-segment string association
Treeassociation
Introduced16.0.R1

Platforms

All

lag [lag-name] reference
Synopsis Enter the lag list instance
Context configure service system bgp evpn ethernet-segment string association lag reference
Treelag
Max. Instances1

Notes

The following elements are part of a choice: lag, network-interconnect-vxlan, port, pw-port, sdp, or vprn-next-hop.

Introduced16.0.R1

Platforms

All

virtual-ranges
Synopsis Enter the virtual-ranges context
Contextconfigure service system bgp evpn ethernet-segment string association lag reference virtual-ranges
Treevirtual-ranges
Introduced16.0.R4

Platforms

All

dot1q
Synopsis Enter the dot1q context
Context configure service system bgp evpn ethernet-segment string association lag reference virtual-ranges dot1q
Treedot1q
Introduced16.0.R4

Platforms

All

q-tag [start] (number | keyword)
Synopsis Enter the q-tag list instance
Context configure service system bgp evpn ethernet-segment string association lag reference virtual-ranges dot1q q-tag (number | keyword)
Treeq-tag
Max. Instances8
Introduced16.0.R4

Platforms

All

qinq
Synopsis Enter the qinq context
Context configure service system bgp evpn ethernet-segment string association lag reference virtual-ranges qinq
Treeqinq
Introduced16.0.R4

Platforms

All

s-tag [start] (number | keyword)
Synopsis Enter the s-tag list instance
Context configure service system bgp evpn ethernet-segment string association lag reference virtual-ranges qinq s-tag (number | keyword)
Trees-tag
Max. Instances8
Introduced16.0.R4

Platforms

All

s-tag-c-tag [s-tag] (number | keyword) c-tag-start (number | keyword)
Synopsis Enter the s-tag-c-tag list instance
Contextconfigure service system bgp evpn ethernet-segment string association lag reference virtual-ranges qinq s-tag-c-tag (number | keyword) c-tag-start (number | keyword)
Trees-tag-c-tag
Max. Instances8
Introduced16.0.R4

Platforms

All

network-interconnect-vxlan [network-interconnect-vxlan-id] number
Synopsis Enter the network-interconnect-vxlan list instance
Contextconfigure service system bgp evpn ethernet-segment string association network-interconnect-vxlan number
Treenetwork-interconnect-vxlan
Max. Instances1

Notes

The following elements are part of a choice: lag, network-interconnect-vxlan, port, pw-port, sdp, or vprn-next-hop.

Introduced16.0.R1

Platforms

All

virtual-ranges
Synopsis Enter the virtual-ranges context
Contextconfigure service system bgp evpn ethernet-segment string association network-interconnect-vxlan number virtual-ranges
Treevirtual-ranges
Introduced16.0.R4

Platforms

All

service-id [start] number
Synopsis Enter the service-id list instance
Contextconfigure service system bgp evpn ethernet-segment string association network-interconnect-vxlan number virtual-ranges service-id number
Treeservice-id
Max. Instances8
Introduced16.0.R4

Platforms

All

port [port-id] reference
Synopsis Enter the port list instance
Context configure service system bgp evpn ethernet-segment string association port reference
Treeport
Max. Instances1

Notes

The following elements are part of a choice: lag, network-interconnect-vxlan, port, pw-port, sdp, or vprn-next-hop.

Introduced16.0.R1

Platforms

All

virtual-ranges
Synopsis Enter the virtual-ranges context
Contextconfigure service system bgp evpn ethernet-segment string association port reference virtual-ranges
Treevirtual-ranges
Introduced16.0.R4

Platforms

All

dot1q
Synopsis Enter the dot1q context
Context configure service system bgp evpn ethernet-segment string association port reference virtual-ranges dot1q
Treedot1q
Introduced16.0.R4

Platforms

All

q-tag [start] (number | keyword)
Synopsis Enter the q-tag list instance
Context configure service system bgp evpn ethernet-segment string association port reference virtual-ranges dot1q q-tag (number | keyword)
Treeq-tag
Max. Instances8
Introduced16.0.R4

Platforms

All

qinq
Synopsis Enter the qinq context
Context configure service system bgp evpn ethernet-segment string association port reference virtual-ranges qinq
Treeqinq
Introduced16.0.R4

Platforms

All

s-tag [start] (number | keyword)
Synopsis Enter the s-tag list instance
Context configure service system bgp evpn ethernet-segment string association port reference virtual-ranges qinq s-tag (number | keyword)
Trees-tag
Max. Instances8
Introduced16.0.R4

Platforms

All

s-tag-c-tag [s-tag] (number | keyword) c-tag-start (number | keyword)
Synopsis Enter the s-tag-c-tag list instance
Contextconfigure service system bgp evpn ethernet-segment string association port reference virtual-ranges qinq s-tag-c-tag (number | keyword) c-tag-start (number | keyword)
Trees-tag-c-tag
Max. Instances8
Introduced16.0.R4

Platforms

All

pw-port [pw-port-id] reference
Synopsis Enter the pw-port list instance
Contextconfigure service system bgp evpn ethernet-segment string association pw-port reference
Treepw-port
Max. Instances1

Notes

The following elements are part of a choice: lag, network-interconnect-vxlan, port, pw-port, sdp, or vprn-next-hop.

Introduced16.0.R4

Platforms

All

pw-port-headend boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisControl state of PW SAPs on PW port using EVPN
Contextconfigure service system bgp evpn ethernet-segment string association pw-port reference pw-port-headend boolean
Treepw-port-headend

Description

When configured to true, this command allows EVPN and its multi-homing procedures to control the state of the PW SAPs on the PW port.

When configured to false, this command disallows EVPN and its multi-homing procedures to control the state of the PW SAPs on the PW port.

Defaultfalse
Introduced22.2.R1

Platforms

All

virtual-ranges
Synopsis Enter the virtual-ranges context
Contextconfigure service system bgp evpn ethernet-segment string association pw-port reference virtual-ranges
Treevirtual-ranges
Introduced16.0.R4

Platforms

All

dot1q
Synopsis Enter the dot1q context
Context configure service system bgp evpn ethernet-segment string association pw-port reference virtual-ranges dot1q
Treedot1q
Introduced16.0.R4

Platforms

All

q-tag [start] (number | keyword)
Synopsis Enter the q-tag list instance
Context configure service system bgp evpn ethernet-segment string association pw-port reference virtual-ranges dot1q q-tag (number | keyword)
Treeq-tag
Max. Instances8
Introduced16.0.R4

Platforms

All

qinq
Synopsis Enter the qinq context
Context configure service system bgp evpn ethernet-segment string association pw-port reference virtual-ranges qinq
Treeqinq
Introduced16.0.R4

Platforms

All

s-tag [start] (number | keyword)
Synopsis Enter the s-tag list instance
Context configure service system bgp evpn ethernet-segment string association pw-port reference virtual-ranges qinq s-tag (number | keyword)
Trees-tag
Max. Instances8
Introduced16.0.R4

Platforms

All

s-tag-c-tag [s-tag] (number | keyword) c-tag-start (number | keyword)
Synopsis Enter the s-tag-c-tag list instance
Contextconfigure service system bgp evpn ethernet-segment string association pw-port reference virtual-ranges qinq s-tag-c-tag (number | keyword) c-tag-start (number | keyword)
Trees-tag-c-tag
Max. Instances8
Introduced16.0.R4

Platforms

All

sdp [sdp-id] reference
Synopsis Enter the sdp list instance
Context configure service system bgp evpn ethernet-segment string association sdp reference
Treesdp
Max. Instances1

Notes

The following elements are part of a choice: lag, network-interconnect-vxlan, port, pw-port, sdp, or vprn-next-hop.

Introduced16.0.R1

Platforms

All

virtual-ranges
Synopsis Enter the virtual-ranges context
Contextconfigure service system bgp evpn ethernet-segment string association sdp reference virtual-ranges
Treevirtual-ranges
Introduced16.0.R4

Platforms

All

vc-id [start] number
Synopsis Enter the vc-id list instance
Context configure service system bgp evpn ethernet-segment string association sdp reference virtual-ranges vc-id number
Treevc-id
Max. Instances8
Introduced16.0.R4

Platforms

All

vprn-next-hop [ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Enter the vprn-next-hop list instance
Contextconfigure service system bgp evpn ethernet-segment string association vprn-next-hop (ipv4-address-no-zone | ipv6-address-no-zone)
Treevprn-next-hop

Description

Commands in this list instance are used to associate an IPv4 or IPv6 address to an Ethernet segment. A virtual Ethernet segment using this VPRN next-hop association represents a Layer 3 Ethernet segment as described in draft-sajassi-bess-evpn-ip-aliasing. This IP address must be installed in the route table of the VPRN service identified by the EVI so that the Auto-Discovery per-ES or EVI routes for the ES are advertised. Only one VPRN next hop is supported per Ethernet segment.

Max. Instances1

Notes

The following elements are part of a choice: lag, network-interconnect-vxlan, port, pw-port, sdp, or vprn-next-hop.

Introduced22.10.R1

Platforms

All

virtual-ranges
Synopsis Enter the virtual-ranges context
Contextconfigure service system bgp evpn ethernet-segment string association vprn-next-hop (ipv4-address-no-zone | ipv6-address-no-zone) virtual-ranges
Treevirtual-ranges
Introduced22.10.R1

Platforms

All

evi [start] number
Synopsis Add a list entry for evi
Context configure service system bgp evpn ethernet-segment string association vprn-next-hop (ipv4-address-no-zone | ipv6-address-no-zone) virtual-ranges evi number
Treeevi
Max. Instances1
Introduced22.10.R1

Platforms

All

auto-esi keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEVPN Ethernet segment auto-ESI type
Contextconfigure service system bgp evpn ethernet-segment string auto-esi keyword
Treeauto-esi

Description

This command configures the auto-ESI type to use in the Ethernet segment (ES).When type-1 is configured, a manual ESI cannot be configured and the ESI is automatically derived in accordance with the RFC 7432 ESI type 1 definition.When configured to none, a manual ESI must be configured.

Optionsnone, type-1
Default none
Introduced21.5.R1

Platforms

All

df-election
Synopsis Enter the df-election context
Context configure service system bgp evpn ethernet-segment string df-election
Treedf-election
Introduced16.0.R1

Platforms

All

manual
Synopsis Enter the manual context
Context configure service system bgp evpn ethernet-segment string df-election manual
Treemanual
Introduced16.0.R1

Platforms

All

evi [start] number
Synopsis Enter the evi list instance
Context configure service system bgp evpn ethernet-segment string df-election manual evi number
Treeevi
Introduced16.0.R1

Platforms

All

isid [start] number
Synopsis Enter the isid list instance
Context configure service system bgp evpn ethernet-segment string df-election manual isid number
Treeisid
Introduced16.0.R1

Platforms

All

preference
Synopsis Enable the preference context
Context configure service system bgp evpn ethernet-segment string df-election manual preference
Treepreference
Introduced16.0.R1

Platforms

All

mode keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisMethod used to elect the DF
Contextconfigure service system bgp evpn ethernet-segment string df-election manual preference mode keyword
Treemode
Optionsrevertive, non-revertive
Defaultrevertive
Introduced 16.0.R1

Platforms

All

service-carving-mode keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMode of service carving enabled per EVPN associated with this Ethernet segment entry
Contextconfigure service system bgp evpn ethernet-segment string df-election service-carving-mode keyword
Treeservice-carving-mode
Optionsauto, manual, off
Defaultauto
Introduced16.0.R1

Platforms

All

esi string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEthernet segment identifier
Contextconfigure service system bgp evpn ethernet-segment string esi string
Treeesi
Introduced16.0.R1

Platforms

All

multi-homing-mode keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMulti-homing mode of the Ethernet segment
Contextconfigure service system bgp evpn ethernet-segment string multi-homing-mode keyword
Treemulti-homing-mode
Optionsnone, single-active, single-active-no-esi-label, all-active
Default none
Introduced16.0.R1

Platforms

All

orig-ip (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisOriginating IP address advertised in the ES route
Contextconfigure service system bgp evpn ethernet-segment string orig-ip (ipv4-address-no-zone | ipv6-address-no-zone)
Treeorig-ip
Introduced16.0.R4

Platforms

All

pbb
Synopsis Enter the pbb context
Context configure service system bgp evpn ethernet-segment string pbb
Treepbb
Introduced16.0.R1

Platforms

All

source-bmac-lsb string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLeast significant bytes of the B-MAC for packet source
Contextconfigure service system bgp evpn ethernet-segment string pbb source-bmac-lsb string
Treesource-bmac-lsb
Introduced16.0.R1

Platforms

All

route-next-hop (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisNext-hop IP address for ES and AD per ES routes
Contextconfigure service system bgp evpn ethernet-segment string route-next-hop (ipv4-address-no-zone | ipv6-address-no-zone)
Treeroute-next-hop
Introduced16.0.R4

Platforms

All

type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEthernet Segment type
Contextconfigure service system bgp evpn ethernet-segment string type keyword
Treetype
Optionsnone, virtual
Default none
Introduced16.0.R1

Platforms

All

etree-leaf-label boolean
Synopsis Enable E-Tree leaf label for PE
Context configure service system bgp evpn etree-leaf-label boolean
Treeetree-leaf-label

Description

When configured to true, this command enables EVPN Ethernet-Tree (E-Tree) VPLS services on the router (not B-VPLS), allocates an E-Tree leaf label for the Provider Edge (PE) device, and configures the ILM entry.This command ensures that in-flight traffic can perform an ILM entry lookup at any time, and avoids discards when administratively enabling or disabling services, or reduces the timing window so that it does not occur during normal operation or configuration. The value for the E-Tree leaf label is set via the etree-leaf-label-value command.

When configured to false, PE leaf labels are not supported.

Defaultfalse
Introduced16.0.R1

Platforms

All

ip-prefix-routes
Synopsis Enter the ip-prefix-routes context
Contextconfigure service system bgp evpn ip-prefix-routes
Treeip-prefix-routes
Introduced21.2.R1

Platforms

All

iff-attribute-uniform-propagation boolean
Synopsis Enable uniform propagation of BGP attributes
Contextconfigure service system bgp evpn ip-prefix-routes iff-attribute-uniform-propagation boolean
Treeiff-attribute-uniform-propagation

Description

When configured to true, this command enables the uniform propagation of BGP attributes for EVPN-IFF (Interfaceful) routes. EVPN-IFF is used in R-VPLS services with bgp-evpn ip-route-advertisement. When enabled, the received EVPN-IFF routes for the R-VPLS can be propagated with the original BGP path attributes into EVPN-IFL, IPVPN, EVPN-IFF (in other R-VPLS services) or BGP IP routes advertised for the attached VPRN. The command also enables the attribute propagation in the opposite direction, for example, from EVPN-IFL/IPVPN/IP/EVPN-IFF routes into EVPN-IFF routes.

The propagation follows the uniform mode defined in draft-ietf-bess-evpn-ipvpn-interworking.

When configured to false, this command re-originates the BGP Path Attributes when propagating EVPN-IFF routes into other Inter-Subnet Forwarding families.

Defaultfalse
Introduced21.2.R1

Platforms

All

iff-bgp-path-selection boolean
Synopsis Enable BGP path selection for EVPN-IFF routes
Contextconfigure service system bgp evpn ip-prefix-routes iff-bgp-path-selection boolean
Treeiff-bgp-path-selection

Description

When configured to true, this command enables the EVPN-IFF routes to be ordered and selected in a similar manner as IPVPN or EVPN-IFL routes, that is, based on the regular BGP path selection process.

When configured to false, this command makes the system order EVPN-IFF routes based on their {RVPLS Ifindex, RD, Ethernet Tag}. For example, if two EVPN-IFF routes are received for the same prefix on the same R-VPLS and with different RDs (Route Distinguishers), the route with the lowest RD is selected.

Defaultfalse
Introduced21.2.R1

Platforms

All

multicast-leave-sync-propagation number
Synopsis Multicast leave group synchronization delay
Contextconfigure service system bgp evpn multicast-leave-sync-propagation number
Treemulticast-leave-sync-propagation

Description

This command configures the additional amount of time that the system waits before removing a multicast state that was synchronized in an Ethernet Segment via Multicast Join or Leave Synch routes. This value represents a delta corresponding to the time it takes for a BGP advertisement to propagate to ES peers.

The node triggering the route computes the maximum response time as the product of the locally configured values, Last Member Query Count and Last Member Query Interval, and adds the delta value to the maximum response time. The query count value is configured in the configure services vrpn igmp robust-count command. The query interval value is taken from the configure service vpls sap igmp-snooping query-last-member-interval or the configure service vpls spoke-sdp igmp-snooping query-last-member-interval configuration, depending on the Ethernet Segment.

Increasing the maximum response time by this value can help minimize the churn of removing and recreating the state on the node.

This value should be configured consistently in all ES peers.

Range0 to 300
Unitsseconds
Default 5
Introduced20.7.R1

Platforms

All

bgp-auto-rd-range
Synopsis Enter the bgp-auto-rd-range context
Contextconfigure service system bgp-auto-rd-range
Treebgp-auto-rd-range
Introduced16.0.R1

Platforms

All

community-value
Synopsis Enter the community-value context
Contextconfigure service system bgp-auto-rd-range community-value
Treecommunity-value
Introduced16.0.R1

Platforms

All

fdb
Synopsis Enter the fdb context
Context configure service system fdb
Treefdb
Introduced16.0.R1

Platforms

All

table-size number
Synopsis Maximum FDB entries in the system
Context configure service system fdb table-size number
Treetable-size

Description

This command determines the maximum number of MAC entries in the forwarding database (FDB) for the system instance on this node.

Do not configure the table-size command. This command is automatically initialized by SR OS on boot up.

Range4095 to 2047999
Introduced16.0.R1

Platforms

All

gre-eth-bridged
Synopsis Enter the gre-eth-bridged context
Contextconfigure service system gre-eth-bridged
Treegre-eth-bridged
Introduced16.0.R1

Platforms

All

tunnel-termination [ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Enter the tunnel-termination list instance
Contextconfigure service system gre-eth-bridged tunnel-termination (ipv4-address-no-zone | ipv6-address-no-zone)
Treetunnel-termination
Introduced16.0.R1

Platforms

All

[ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Tunnel end-point IP address in the SR OS node
Contextconfigure service system gre-eth-bridged tunnel-termination (ipv4-address-no-zone | ipv6-address-no-zone)
Treetunnel-termination

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

fpe-id reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisFPE ID
Contextconfigure service system gre-eth-bridged tunnel-termination (ipv4-address-no-zone | ipv6-address-no-zone) fpe-id reference
Treefpe-id

Reference

configure fwd-path-ext fpe number

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

vxlan
Synopsis Enter the vxlan context
Context configure service system vxlan
Treevxlan
Introduced16.0.R1

Platforms

All

tunnel-termination [ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Enter the tunnel-termination list instance
Contextconfigure service system vxlan tunnel-termination (ipv4-address-no-zone | ipv6-address-no-zone)
Treetunnel-termination
Introduced16.0.R1

Platforms

All

[ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Non-system IP address that terminates the VXLAN
Contextconfigure service system vxlan tunnel-termination (ipv4-address-no-zone | ipv6-address-no-zone)
Treetunnel-termination

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

fpe-id reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisFPE id for this entry
Contextconfigure service system vxlan tunnel-termination (ipv4-address-no-zone | ipv6-address-no-zone) fpe-id reference
Treefpe-id

Reference

configure fwd-path-ext fpe number

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

template

Synopsis Enter the template context
Context configure service template
Treetemplate
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

epipe-sap-template [name] string
Synopsis Enter the epipe-sap-template list instance
Contextconfigure service template epipe-sap-template string
Treeepipe-sap-template
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

egress
Synopsis Enter the egress context
Context configure service template epipe-sap-template string egress
Treeegress
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

filter
Synopsis Enter the filter context
Context configure service template epipe-sap-template string egress filter
Treefilter
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

ingress
Synopsis Enter the ingress context
Context configure service template epipe-sap-template string ingress
Treeingress
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

filter
Synopsis Enter the filter context
Context configure service template epipe-sap-template string ingress filter
Treefilter
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

qos
Synopsis Enter the qos context
Context configure service template epipe-sap-template string ingress qos
Treeqos
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

upnp

Synopsis Enter the upnp context
Context configure service upnp
Treeupnp

Description

Commands in this context configure Universal Plug 'n Play (UPnP) for the service.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

policy [name] string
Synopsis Enter the policy list instance
Contextconfigure service upnp policy string
Treepolicy

Description

Commands in this context configure the attributes of the UPnP policy.

Max. Instances255
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis UPnP policy name
Context configure service upnp policy string
Treepolicy
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

description string
Synopsis Text description
Context configure service upnp policy string description string
Treedescription
String Length1 to 80
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mapping-limit number
Synopsis Maximum number of UPnP mappings per subscriber
Contextconfigure service upnp policy string mapping-limit number
Treemapping-limit
Range1 to 256
Default256
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

port number
Synopsis HTTP TCP port to which the UPnP IGD listens
Contextconfigure service upnp policy string port number
Treeport
Range1 to 65535
Default5000
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

strict-mode boolean
Synopsis Enable UPnP strict mode
Context configure service upnp policy string strict-mode boolean
Treestrict-mode

Description

When configured to true, this command enables UPnP strict mode, in which the system only allows changes to an existing UPnP mapping if the request comes from the same UPnP client.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

vpls [service-name] string

Synopsis Enter the vpls list instance
Context configure service vpls string
Treevpls
Introduced16.0.R1

Platforms

All

[service-name] string
Synopsis Administrative service name
Context configure service vpls string
Treevpls
String Length1 to 64

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the service
Context configure service vpls string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

bgp [bgp-instance] number
Synopsis Enter the bgp list instance
Context configure service vpls string bgp number
Treebgp
Introduced16.0.R1

Platforms

All

[bgp-instance] number
Synopsis BGP instance
Contextconfigure service vpls string bgp number
Treebgp
Range1 to 2

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

adv-service-mtu number
Synopsis Advertised service MTU value
Context configure service vpls string bgp number adv-service-mtu number
Treeadv-service-mtu

Description

This command configures the MTU signaled value used in the BGP for the service. When configured, the router uses the value for signaling and for validation with the received MTU instead of the service MTU. However, the value does not affect the locally enforced value, which is still based on the service MTU.

Range0 to 9782
Introduced22.2.R1

Platforms

All

pw-template-binding [pw-template-name] reference
Synopsis Enter the pw-template-binding list instance
Contextconfigure service vpls string bgp number pw-template-binding reference
Treepw-template-binding
Max. Instances100
Introduced16.0.R1

Platforms

All

route-distinguisher (keyword | vpn-route-distinguisher)
Synopsis High-order 6 bytes that are used as string to compose VSI-ID for use in NLRI
Contextconfigure service vpls string bgp number route-distinguisher (keyword | vpn-route-distinguisher)
Treeroute-distinguisher
Optionsauto-rd
Introduced16.0.R1

Platforms

All

route-target
Synopsis Enter the route-target context
Contextconfigure service vpls string bgp number route-target
Treeroute-target
Introduced16.0.R1

Platforms

All

export string
Synopsis Extended community name for default import policy
Contextconfigure service vpls string bgp number route-target export string
Treeexport
String Length10 to 28
Introduced16.0.R1

Platforms

All

import string
Synopsis Extended community name for default import policy
Contextconfigure service vpls string bgp number route-target import string
Treeimport
String Length10 to 28
Introduced16.0.R1

Platforms

All

bgp-ad
Synopsis Enable the bgp-ad context
Context configure service vpls string bgp-ad
Treebgp-ad
Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of BGP Auto-Discovery
Contextconfigure service vpls string bgp-ad admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

vpls-id string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisVPLS identifier as a 8-byte route distinguisher
Contextconfigure service vpls string bgp-ad vpls-id string
Treevpls-id
Introduced16.0.R1

Platforms

All

vsi-id-prefix string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisVSI prefix value
Contextconfigure service vpls string bgp-ad vsi-id-prefix string
Treevsi-id-prefix
Introduced16.0.R1

Platforms

All

bgp-evpn
Synopsis Enable the bgp-evpn context
Context configure service vpls string bgp-evpn
Treebgp-evpn
Introduced16.0.R1

Platforms

All

evi number
Synopsis EVPN ID
Contextconfigure service vpls string bgp-evpn evi number
Treeevi

Description

This command configures a 2-byte EVPN instance (EVI) unique in the system. It is used for the service-carving algorithm for multi-homing and auto-deriving route target and route distinguishers.

If not specified, the EVPN ID value is zero and no route distinguisher or route targets are auto-derived from it.

If the EVI ID value is specified and no other route-distinguisher or route-target is configured in the service, the following rules apply:

  • the route distinguisher is derived from <system_ip>:evi

  • the route target is derived from <autonomous-system>:evi

If VSI import and export policies are configured, the route target must be configured in the policies and those values take precedence over the auto-derived route targets. If bgp-ad vpls-id and bgp-evpn evi are both configured on the same service, the VPLS ID auto-derived route target or route distinguisher takes precedence over the values auto-derived from the EVI. Use the show service id bgp command to display the operational route target for a service.

Range1 to 16777215
Introduced16.0.R1

Platforms

All

ignore-mtu-mismatch boolean
Synopsis Ignore MTU mismatch
Context configure service vpls string bgp-evpn ignore-mtu-mismatch boolean
Treeignore-mtu-mismatch

Description

When configured to true, the system ignores the received Layer 2 MTU in the L2 Attributes extended community of the IMET route for a peer.

When configured to false, the system compares the local service MTU against the received Layer 2 MTU and if there is a mismatch, keeps the EVPN destination to the peer with operational state down.

Defaultfalse
Introduced23.3.R1

Platforms

All

isid-route-target
Synopsis Enter the isid-route-target context
Contextconfigure service vpls string bgp-evpn isid-route-target
Treeisid-route-target
Introduced16.0.R1

Platforms

All

range [start] number
Synopsis Enter the range list instance
Context configure service vpls string bgp-evpn isid-route-target range number
Treerange
Max. Instances8192
Introduced16.0.R1

Platforms

All

[start] number
Synopsis Lower bound of the ISID range
Context configure service vpls string bgp-evpn isid-route-target range number
Treerange
Range1 to 16777215

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

route-target string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisRoute for the ISID range
Contextconfigure service vpls string bgp-evpn isid-route-target range number route-target string
Treeroute-target
String Length10 to 28
Introduced16.0.R1

Platforms

All

type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisMethod used to support the PBB-EVPN ISID-based route target advertisement
Contextconfigure service vpls string bgp-evpn isid-route-target range number type keyword
Treetype
Optionsauto, configured
Default auto
Introduced16.0.R1

Platforms

All

mac-duplication
Synopsis Enter the mac-duplication context
Contextconfigure service vpls string bgp-evpn mac-duplication
Treemac-duplication

Description

Commands in this context configure the BGP EVPN MAC duplication command options.

Introduced16.0.R1

Platforms

All

detect
Synopsis Enter the detect context
Context configure service vpls string bgp-evpn mac-duplication detect
Treedetect

Description

Commands in this context monitor the number of moves of a MAC address for a period of time (window).

Introduced16.0.R1

Platforms

All

trusted-mac-move-factor number
Synopsis Trusted MAC move factor
Context configure service vpls string bgp-evpn mac-duplication detect trusted-mac-move-factor number
Treetrusted-mac-move-factor

Description

This command configures the factor by which the number of moves is multiplied when detecting a MAC duplication event for trusted MACs. For example, if the number of moves is 5 and the trusted MAC move factor is 3, 5 moves, within the window, is enough to declare a non-trusted MAC as duplicate. However, 15 moves are needed to declare a trusted MAC as duplicate.

By default the factor for a trusted MAC is the same as for a non-trusted MAC. This provides a backwards compatible solution upon upgrade of the node.

Range1 to 10
Default1
Introduced 23.7.R1

Platforms

All

retry (number | keyword)
Synopsis BGP EVPN MAC duplication retry time
Context configure service vpls string bgp-evpn mac-duplication retry (number | keyword)
Treeretry
Range2 to 60
Unitsminutes
Options never
Default 9
Introduced16.0.R1

Platforms

All

trusted-mac-time number
Synopsis Trusted MAC time
Context configure service vpls string bgp-evpn mac-duplication trusted-mac-time number
Treetrusted-mac-time

Description

This command configures how long a MAC address needs to stay in the FDB as type learned without being flushed or changed in its type so the MAC is declared as trusted for the MAC duplication procedures. If the MAC changes from SAP to SAP within the same VPLS service and node, the MAC does not reset its trusted MAC timer.

Range1 to 15
Unitsminutes
Default 5
Introduced23.7.R1

Platforms

All

mpls [bgp-instance] number
Synopsis Enter the mpls list instance
Context configure service vpls string bgp-evpn mpls number
Treempls
Introduced16.0.R1

Platforms

All

[bgp-instance] number
Synopsis BGP instance
Contextconfigure service vpls string bgp-evpn mpls number
Treempls
Range1 to 2

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of BGP EVPN MPLS
Contextconfigure service vpls string bgp-evpn mpls number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

auto-bind-tunnel
Synopsis Enter the auto-bind-tunnel context
Contextconfigure service vpls string bgp-evpn mpls number auto-bind-tunnel
Treeauto-bind-tunnel
Introduced16.0.R1

Platforms

All

allow-flex-algo-fallback boolean
Synopsis Enable flexible algorithm fallback
Context configure service vpls string bgp-evpn mpls number auto-bind-tunnel allow-flex-algo-fallback boolean
Treeallow-flex-algo-fallback

Description

When configured to true, a BGP router with a Flex-Algorithm action configured (via the configure policy-options policy-statement entry action flex-algo command) can resolve to a tunnel with algorithm 0 if no target Flex-Algorithm tunnel is available.

When configured to false, the BGP router can resolve only to the intended Flex-Algorithm tunnel, which may cause traffic loss if no corresponding Flex-Algorithm tunnel is available.

Defaultfalse
Introduced20.10.R1

Platforms

All

resolution-filter
Synopsis Enter the resolution-filter context
Contextconfigure service vpls string bgp-evpn mpls number auto-bind-tunnel resolution-filter
Treeresolution-filter
Introduced16.0.R1

Platforms

All

bgp boolean
Synopsis Use BGP tunneling for next-hop resolution
Contextconfigure service vpls string bgp-evpn mpls number auto-bind-tunnel resolution-filter bgp boolean
Treebgp

Description

When configured to true, BGP searches the BGP LSP for the address of the BGP next hop.

When configured to false, BGP tunneling is not used and inter-area or inter-as prefixes are not resolved.

Defaultfalse
Introduced16.0.R1

Platforms

All

ldp boolean
Synopsis Use LDP tunneling for next-hop resolution
Contextconfigure service vpls string bgp-evpn mpls number auto-bind-tunnel resolution-filter ldp boolean
Treeldp

Description

When configured to true, BGP searches for an LDP LSP with a FEC prefix corresponding to the address of the BGP next hop.

When configured to false, LDP tunneling is not used for next-hop resolution.

Defaultfalse
Introduced16.0.R1

Platforms

All

mpls-fwd-policy boolean
Synopsis Use MPLS forwarding policy for next-hop resolution
Contextconfigure service vpls string bgp-evpn mpls number auto-bind-tunnel resolution-filter mpls-fwd-policy boolean
Treempls-fwd-policy

Description

When configured to true, BGP uses the MPLS forwarding policy to determine the address of the BGP next hop.

When configured to false, the MPLS forwarding policy is not used for next-hop resolution.

Defaultfalse
Introduced19.5.R1

Platforms

All

rib-api boolean
Synopsis Use RIB API gRPC service for next-hop resolution
Contextconfigure service vpls string bgp-evpn mpls number auto-bind-tunnel resolution-filter rib-api boolean
Treerib-api

Description

When configured to true, BGP uses tunnels programmed using the RIB API gRPC service to resolve the next hops of routes imported into the EVPN service.

When configured to false, the RIB API service tunnels are not used for next-hop resolution.

Defaultfalse
Introduced19.5.R1

Platforms

All

rsvp boolean
Synopsis Use RSVP tunneling for next-hop resolution
Contextconfigure service vpls string bgp-evpn mpls number auto-bind-tunnel resolution-filter rsvp boolean
Treersvp

Description

When configured to true, BGP searches the best metric RSVP LSP to determine the address of the BGP next hop. This address can correspond to the system interface or to another loopback interface used by the BGP instance on the remote node. The LSP metric is provided by MPLS in the tunnel table. In the case of multiple RSVP LSPs with the same lowest metric, BGP selects the LSP with the lowest tunnel ID.

When configured to false, the RSVP LSP is not used for next-hop resolution.

Defaultfalse
Introduced16.0.R1

Platforms

All

sr-isis boolean
Synopsis Use IS-IS SR tunneling for next-hop resolution
Contextconfigure service vpls string bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-isis boolean
Treesr-isis

Description

When configured to true, BGP uses an IS-IS tunnel type to determine the address of the BGP next hop.

The SR tunnel to the BGP next hop is selected in the TTM from the lowest-numbered IS-IS instance.

When configured to false, IS-IS tunneling is not used for next-hop resolution.

Defaultfalse
Introduced16.0.R1

Platforms

All

sr-ospf boolean
Synopsis Use OSPF SR tunneling for next-hop resolution
Contextconfigure service vpls string bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-ospf boolean
Treesr-ospf

Description

When configured to true, BGP uses an OSPF tunnel type to determine the address of the BGP next hop.

The SR tunnel to the BGP next hop is selected in the TTM from the lowest-numbered OPSF instance.

When configured to false, OSPF tunneling is not used for next-hop resolution.

Defaultfalse
Introduced16.0.R1

Platforms

All

sr-ospf3 boolean
Synopsis Use OSPFv3 SR tunneling for next-hop resolution
Contextconfigure service vpls string bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-ospf3 boolean
Treesr-ospf3

Description

When configured to true, BGP uses an OSPF3 tunnel type to determine the address of the BGP next hop.

The SR tunnel to the BGP next hop is selected in the TTM from the lowest-numbered OPSF3 instance.

When configured to false, OSPF3 tunneling is not used for next-hop resolution.

Defaultfalse
Introduced19.10.R1

Platforms

All

sr-policy boolean
Synopsis Use SR policies for next-hop resolution
Contextconfigure service vpls string bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-policy boolean
Treesr-policy

Description

When configured to true, this command instructs BGP to use an SR policy to determine the address of the BGP next hop. The SR policy search criteria includes a non-null endpoint and color value that matches the BGP next hop and color extended community value, respectively, of the EVPN route.

When configured to false, SR policies are not used for next-hop resolution.

Defaultfalse
Introduced19.5.R1

Platforms

All

sr-te boolean
Synopsis Use SR-TE tunneling for next-hop resolution
Contextconfigure service vpls string bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-te boolean
Treesr-te

Description

When configured to true, BGP uses an SR-TE tunnel type to determine the address of the BGP next hop.

The SR tunnel to the BGP next hop is selected in the TTM from the lowest-numbered tunnel ID.

When configured to false, SR-TE tunneling is not used for next-hop resolution.

Defaultfalse
Introduced16.0.R1

Platforms

All

udp boolean
Synopsis Use MPLS over UDP tunneling for next-hop resolution
Contextconfigure service vpls string bgp-evpn mpls number auto-bind-tunnel resolution-filter udp boolean
Treeudp

Description

When configured to true, BGP uses an MPLS over UDP tunnel type to determine the address of the BGP next hop.

When configured to false, MPLS over UDP tunneling is not used for next-hop resolution.

Defaultfalse
Introduced16.0.R1

Platforms

All

weighted-ecmp boolean
Synopsis Allow weighted load balancing
Context configure service vpls string bgp-evpn mpls number auto-bind-tunnel weighted-ecmp boolean
Treeweighted-ecmp

Description

When configured to true, this router enables weighted ECMP for packets using tunnels that a VPLS or Epipe automatically binds to. Packets are sprayed across LSPs in the ECMP according to the outcome of the hash algorithm and the configured load balancing weight of each LSP.

When configured to false, this command disables weighted ECMP for next-hop tunnel selection.

Defaultfalse
Introduced22.7.R1

Platforms

All

control-word boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable control word support
Contextconfigure service vpls string bgp-evpn mpls number control-word boolean
Treecontrol-word

Description

When configured to true, the router enables the transmission and reception of the control word for all EVPN-MPLS destinations at the same time.

Defaultfalse
Introduced16.0.R1

Platforms

All

default-route-tag string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDefault route tag
Contextconfigure service vpls string bgp-evpn mpls number default-route-tag string
Treedefault-route-tag

Description

This command configures a route tag that is used when sending a route to the BGP application (for the corresponding service and BGP instance). If the corresponding BGP instance is enabled, the command cannot be changed.

When used for BGP EVPN contexts, only one route tag can be passed to BGP for matching on export policies. In case of a conflict with other route tags pushed by EVPN, the default route tag has the least priority. 

The following are examples of the conflict priority handling:

  • If a service is configured with both default-route-tag X and proxy-arp evpn-route-tag Y, the EVPN uses route tag Y when sending EVPN proxy-arp routes to the BGP RIB for advertisement.

  • If a given IP-prefix route is tagged in the route-table with tag A and the R-VPLS, in which the route is advertised, uses B as the default-route-tag, then EVPN keeps tag A when sending the route to the BGP RIB.

The default-route-tag configuration is only supported on EVPN and IP-VPN service routes. The route tag for ES and AD per-ES routes is always zero.

Introduced16.0.R4

Platforms

All

dynamic-egress-label-limit boolean
Synopsis Enables dynamic egress label limit
Context configure service vpls string bgp-evpn mpls number dynamic-egress-label-limit boolean
Treedynamic-egress-label-limit

Description

When configured to true, this command relaxes the egress MPLS label limit check when resolving BGP next hops in the tunnel table.

For VPRN services, the OAM label is never computed and, therefore, one more egress label is allowed.

For EVPN (Epipe and VPLS) services, the system only computes the control word and ESI label if they are used. For the control word, the system reduces the egress label limit by one label if the control word is configured in the service. When configured, the ESI label is not counted for Epipes or VPLS services without an ES.

When configured to false this command, for EVPN, Epipe, and VPLS services, always accounts for the ESI label and control word.

Defaultfalse
Introduced22.2.R1

Platforms

All

ecmp number
Synopsis Maximum ECMP routes information
Context configure service vpls string bgp-evpn mpls number ecmp number
Treeecmp
Range1 to 32
Default1
Introduced 16.0.R1

Platforms

All

evi-three-byte-auto-rt boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAuto-derive the BGP EVPN route target
Contextconfigure service vpls string bgp-evpn mpls number evi-three-byte-auto-rt boolean
Treeevi-three-byte-auto-rt

Description

When configured to true, the BGP-EVPN instance import and export route target is auto-derived as described in RFC 8365 (Global-Administrator:A/Type/D-ID/Service-ID).

Where:

  • Global Administrator – is the configured 2-octet AS number; if the configured ASN exceeds the 2 byte limit, the low order 16-bit value is taken

  • A=0 (for auto-derivation)

  • Type=4 (EVI-based route-target)

  • D-ID= [1..2] – encodes the BGP instance, which allows the auto-derivation of different route-targets in multi-instance services; the value is inherited from the corresponding BGP instance

  • Service ID=3-octet EVI

When configured to false, route target derivation is not allowed.

Defaultfalse
Introduced21.10.R1

Platforms

All

hash-label boolean
Synopsis Push hash label
Context configure service vpls string bgp-evpn mpls number hash-label boolean
Treehash-label

Description

When configured to true, the router pushes the hash label based on the following:

  • If advertise-l2-attributes (in the configure service vpls bgp-evpn routes incl-mcast context) is set to false, the hash label is pushed to a unicast EVPN destination.

  • If advertise-l2-attributes is set to true, the F bit is set to 1 in the Layer 2 Attributes Extended Community of the EVPN IMET route for the service. The hash label is pushed only if the remote PE signaled support for hash label (received F bit is set to 1).

When configured to false, the hash label is not pushed.

The hash label is never used for BUM packets.

Defaultfalse
Introduced23.10.R1

Platforms

All

ingress-replication-bum-label boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisUse the same label as the one advertised for unicast traffic
Contextconfigure service vpls string bgp-evpn mpls number ingress-replication-bum-label boolean
Treeingress-replication-bum-label
Defaultfalse
Introduced16.0.R1

Platforms

All

mh-mode keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMultihoming mode
Contextconfigure service vpls string bgp-evpn mpls number mh-mode keyword
Treemh-mode

Description

This command configures the multihoming mode for BGP-EVPN. Users can configure only one network instance for the service.

If a provider tunnel is enabled for the service instance, this command must be configured using the network option.

Optionsaccess, network
Default network
Introduced21.10.R1

Platforms

All

route-next-hop
Synopsis Enter the route-next-hop context
Contextconfigure service vpls string bgp-evpn mpls number route-next-hop
Treeroute-next-hop

Description

Commands in this context configure the next hop of the EVPN routes.

Introduced19.10.R1

Platforms

All

ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIP address of the next-hop for the service EVPN route
Contextconfigure service vpls string bgp-evpn mpls number route-next-hop ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeip-address

Notes

The following elements are part of a choice: ip-address, system-ipv4, or system-ipv6.

Introduced19.10.R1

Platforms

All

system-ipv4
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSystem IPv4 address for service EVPN route next hop
Contextconfigure service vpls string bgp-evpn mpls number route-next-hop system-ipv4
Treesystem-ipv4

Notes

The following elements are part of a choice: ip-address, system-ipv4, or system-ipv6.

Introduced19.10.R1

Platforms

All

system-ipv6
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSystem IPv6 address for service EVPN route next hop
Contextconfigure service vpls string bgp-evpn mpls number route-next-hop system-ipv6
Treesystem-ipv6

Notes

The following elements are part of a choice: ip-address, system-ipv4, or system-ipv6.

Introduced19.10.R1

Platforms

All

send-tunnel-encap
Synopsis Enter the send-tunnel-encap context
Contextconfigure service vpls string bgp-evpn mpls number send-tunnel-encap
Treesend-tunnel-encap
Introduced16.0.R1

Platforms

All

mpls boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable MPLS encapsulation
Contextconfigure service vpls string bgp-evpn mpls number send-tunnel-encap mpls boolean
Treempls
Defaulttrue
Introduced16.0.R1

Platforms

All

mpls-over-udp boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable MPLS over UDP encapsulation
Contextconfigure service vpls string bgp-evpn mpls number send-tunnel-encap mpls-over-udp boolean
Treempls-over-udp
Defaultfalse
Introduced16.0.R1

Platforms

All

split-horizon-group reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSplit horizon group
Contextconfigure service vpls string bgp-evpn mpls number split-horizon-group reference
Treesplit-horizon-group

Description

This command configures the value of split-horizon group for all BGP-EVPN segment routing v6 instances.

Reference

configure service vpls string split-horizon-group string

Introduced16.0.R1

Platforms

All

routes
Synopsis Enter the routes context
Context configure service vpls string bgp-evpn routes
Treeroutes
Introduced16.0.R1

Platforms

All

incl-mcast
Synopsis Enter the incl-mcast context
Context configure service vpls string bgp-evpn routes incl-mcast
Treeincl-mcast
Introduced16.0.R1

Platforms

All

advertise-l2-attributes boolean
Synopsis Advertise Layer 2 attributes
Context configure service vpls string bgp-evpn routes incl-mcast advertise-l2-attributes boolean
Treeadvertise-l2-attributes

Description

When configured to true, the router advertises the Layer 2 Attributes Extended Community including:

  • the service MTU in the Layer 2 MTU field

  • the F bit, which is set to 1 if the hash-label command is set to true (in the configure service vpls bgp-evpn mpls context); otherwise, the F bit is set to 0

  • the C bit, which is set to 1 if the control-word command is set to true (in the configure service vpls bgp-evpn mpls context); otherwise, the C bit is set to 0

The router compares the received Layer 2 MTU from a peer with the local service MTU. If there is a mismatch, the operation state of the EVPN destination is set to down, except if the configure service vpls bgp-evpn ignore-mtu-mistmatch command is set to true.

A mismatch between the received C bit and the local control-word setting (in the configure service vpls bgp-evpn mpls context) results in the operational state of the EVPN destination being set to down.

A mismatch between the received F bit and the local F bit (via the hash label configuration) results in the operational state of the EVPN destination being set to down.

When configured to false, the Layer 2 Attributes Extended Community is not advertised with the Inclusive Multicast Ethernet Tag route for the service.

Defaultfalse
Introduced23.3.R1

Platforms

All

ip-prefix
Synopsis Enter the ip-prefix context
Context configure service vpls string bgp-evpn routes ip-prefix
Treeip-prefix
Introduced16.0.R1

Platforms

All

domain-id string
Synopsis Domain ID of received BGP route before readvertisement
Contextconfigure service vpls string bgp-evpn routes ip-prefix domain-id string
Treedomain-id

Description

This command specifies the domain ID. The domain ID identifies the network from which the BGP route was received before the RTM advertises it to a different neighbor. The domain ID is part of a domain, represented as domain-id:isf_safi_type in the D-PATH attribute, as described in draft-ietf-bess-evpn-ipvpn-interworking. Gateway routers modify the D-PATH attribute. A gateway is a PE where a VPRN is instantiated. The VPRN in this case advertises or receives routes from multiple BGP owners (for example, EVPN-IFL and BGP-IPVPN) or multiple instances of the same owner (for example, VPRN with two BGP-IPVPN instances).

Gateways use the D-PATH attribute to detect loops (for received routes where the D-PATH contains a local domain ID) and to make BGP best-path selection decisions based on the D-PATH length (shorter D-PATH is preferred).

In the following example, suppose a gateway receives prefix P in an EVPN-IFL instance with the following D-PATH from neighbor N:

Seg Len=1 / 65000:1:128

If the router imports the route in VPRN-1, BGP-EVPN SRv6 instance with domain 65000:2, it readvertises it to its BGP-IPVPN MPLS instance as follows:

Seg Len=2 / 65000:2:70 / 65000:1:128

That is, the gateway prepends the local domain ID and family to the D-PATH before readvertising the route into a different instance.

Introduced21.10.R1

Platforms

All

link-bandwidth
Synopsis Enter the link-bandwidth context
Contextconfigure service vpls string bgp-evpn routes ip-prefix link-bandwidth
Treelink-bandwidth
Introduced22.7.R1

Platforms

All

advertise
Synopsis Enable the advertise context
Context configure service vpls string bgp-evpn routes ip-prefix link-bandwidth advertise
Treeadvertise
Introduced22.7.R1

Platforms

All

mac-ip
Synopsis Enter the mac-ip context
Context configure service vpls string bgp-evpn routes mac-ip
Treemac-ip
Introduced16.0.R1

Platforms

All

arp-nd-extended-community boolean
Synopsis Enable ARP/ND extended community
Context configure service vpls string bgp-evpn routes mac-ip arp-nd-extended-community boolean
Treearp-nd-extended-community

Description

When configured to true, the system advertises the RFC9047 ARP/ND extended community along with the MAC/IP routes advertised for local static and dynamic proxy ARP or ND entries. The system also processes the ARP/ND extended community and selects the ARP or ND entries based on the immutable flag.

When configured to false, the system does not advertise the RFC9047 ARP/ND extended community.

Defaultfalse
Introduced23.3.R1

Platforms

All

segment-routing-v6 [bgp-instance] number
Synopsis Enter the segment-routing-v6 list instance
Contextconfigure service vpls string bgp-evpn segment-routing-v6 number
Treesegment-routing-v6

Description

Commands in this context configure the SRv6 instance used in the service.

Max. Instances1
Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

admin-state keyword
Synopsis Administrative state of segment routing over IPv6
Contextconfigure service vpls string bgp-evpn segment-routing-v6 number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

default-route-tag string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDefault route tag
Contextconfigure service vpls string bgp-evpn segment-routing-v6 number default-route-tag string
Treedefault-route-tag

Description

This command configures a route tag that is used when sending a route to the BGP application (for the corresponding service and BGP instance). If the corresponding BGP instance is enabled, the command cannot be changed.

When used for BGP EVPN contexts, only one route tag can be passed to BGP for matching on export policies. In case of a conflict with other route tags pushed by EVPN, the default route tag has the least priority. 

The following are examples of the conflict priority handling:

  • If a service is configured with both default-route-tag X and proxy-arp evpn-route-tag Y, the EVPN uses route tag Y when sending EVPN proxy-arp routes to the BGP RIB for advertisement.

  • If a given IP-prefix route is tagged in the route-table with tag A and the R-VPLS, in which the route is advertised, uses B as the default-route-tag, then EVPN keeps tag A when sending the route to the BGP RIB.

The default-route-tag configuration is only supported on EVPN and IP-VPN service routes. The route tag for ES and AD per-ES routes is always zero.

Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

ecmp number
Synopsis Maximum ECMP value configured on the service
Contextconfigure service vpls string bgp-evpn segment-routing-v6 number ecmp number
Treeecmp
Range1 to 32
Default1
Introduced 22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

evi-three-byte-auto-rt boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAuto-derive the BGP EVPN route target
Contextconfigure service vpls string bgp-evpn segment-routing-v6 number evi-three-byte-auto-rt boolean
Treeevi-three-byte-auto-rt

Description

When configured to true, the BGP-EVPN instance import and export route target is auto-derived as described in RFC 8365 (Global-Administrator:A/Type/D-ID/Service-ID).

Where:

  • Global Administrator – is the configured 2-octet AS number; if the configured ASN exceeds the 2 byte limit, the low order 16-bit value is taken

  • A=0 (for auto-derivation)

  • Type=4 (EVI-based route-target)

  • D-ID= [1..2] – encodes the BGP instance, which allows the auto-derivation of different route-targets in multi-instance services; the value is inherited from the corresponding BGP instance

  • Service ID=3-octet EVI

When configured to false, route target derivation is not allowed.

Defaultfalse
Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

fdb
Synopsis Enter the fdb context
Context configure service vpls string bgp-evpn segment-routing-v6 number fdb
Treefdb
Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

force-vc-forwarding keyword
Synopsis Datapath forwarding to force vlan-vc-type
Contextconfigure service vpls string bgp-evpn segment-routing-v6 number force-vc-forwarding keyword
Treeforce-vc-forwarding

Description

This command allows the system to preserve the VLAN ID and 802.1p bits of the service-delimiting qtag in a new tag added in the customer frame before sending it to the EVPN destinations.

This command may be used in conjunction with the sap ingress vlan-translation command. If so used, the configured translated VLAN ID is the VLAN ID sent to the EVPN destinations as opposed to the service-delimiting tag VLAN ID. If the ingress SAP/SDP binding is 'null'-encapsulated, the output VLAN ID and pbits is zero.

Optionsvlan, qinq-c-tag-c-tag, qinq-s-tag-c-tag
Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

mh-mode keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMultihoming mode
Contextconfigure service vpls string bgp-evpn segment-routing-v6 number mh-mode keyword
Treemh-mode
Optionsaccess, network
Default network
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

oper-group reference
Synopsis Operational group
Context configure service vpls string bgp-evpn segment-routing-v6 number oper-group reference
Treeoper-group

Description

This command adds the BGP EVPN SRv6 instance or an Ethernet Segment (ES) as a member of the operational group.

When configured on a BGP EVPN instance, the operational group is up when it is either empty (meaning that the operational group has no members) or at least an EVPN destination is created under the EVPN instance added as member. When configured, no other SAP, SDP binding, or BGP EVPN instance can be added to the same operational group within the same or different service.

The operational group is down when it is applied on a BGP EVPN instance as well as:

  • the service is administratively disabled

  • the BGP EVPN MPLS and VXLAN is administratively disabled

  • all the EVPN destinations in the instance are removed

When configured on an ES, the state of the operational group depends on the state of the SAPs contained in the ES. The operational group transitions to up if at least one SAP in the ES is up. The operational group goes down when all the associated SAPs are operationally down. Monitor the ES operational group on the LAG associated with the ES, along with single-active multihoming, so that the NDF state can be signaled to the CE by LAG standby signaling.

Reference

configure service oper-group string

Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

resolution keyword
Synopsis Resolution options for routes
Context configure service vpls string bgp-evpn segment-routing-v6 number resolution keyword
Treeresolution
Optionsroute-table, tunnel-table, fallback-tunnel-to-route-table
Defaultroute-table
Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

route-next-hop
Synopsis Enter the route-next-hop context
Contextconfigure service vpls string bgp-evpn segment-routing-v6 number route-next-hop
Treeroute-next-hop

Description

Commands in this context configure the next hop of the EVPN routes.

Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIP address of the next-hop for the service EVPN route
Contextconfigure service vpls string bgp-evpn segment-routing-v6 number route-next-hop ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeip-address

Notes

The following elements are part of a choice: ip-address, system-ipv4, or system-ipv6.

Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

system-ipv4
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSystem IPv4 address for service EVPN route next hop
Contextconfigure service vpls string bgp-evpn segment-routing-v6 number route-next-hop system-ipv4
Treesystem-ipv4

Notes

The following elements are part of a choice: ip-address, system-ipv4, or system-ipv6.

Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

system-ipv6
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSystem IPv6 address for service EVPN route next hop
Contextconfigure service vpls string bgp-evpn segment-routing-v6 number route-next-hop system-ipv6
Treesystem-ipv6

Notes

The following elements are part of a choice: ip-address, system-ipv4, or system-ipv6.

Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

source-address string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSource IPv6 address
Contextconfigure service vpls string bgp-evpn segment-routing-v6 number source-address string
Treesource-address

Description

When configured, this command specifies the source IPv6 address used in the SA field of the outer IPv6 header of the SRv6 encapsulated packet.

When not configured, the source IPv6 address is inherited from the configuration of the global default address in the router "base" segment-routing segment-routing-v6 source-address context.

A source IPv6 address must be configured in this context or in the base router context.

The system does not check if the address entered is a valid local address.

Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

split-horizon-group reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSplit horizon group
Contextconfigure service vpls string bgp-evpn segment-routing-v6 number split-horizon-group reference
Treesplit-horizon-group

Description

This command configures the value of split-horizon group for all BGP-EVPN segment routing v6 instances.

Reference

configure service vpls string split-horizon-group string

Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

srv6
Synopsis Enter the srv6 context
Context configure service vpls string bgp-evpn segment-routing-v6 number srv6
Treesrv6
Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

default-locator string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDefault route locator
Contextconfigure service vpls string bgp-evpn segment-routing-v6 number srv6 default-locator string
Treedefault-locator

Description

This command specifies the locator that exists in the SRv6 service instance and is used as the default locator for the service.

Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

vxlan [bgp-instance] number
Synopsis Enter the vxlan list instance
Context configure service vpls string bgp-evpn vxlan number
Treevxlan
Introduced16.0.R1

Platforms

All

[bgp-instance] number
Synopsis BGP instance
Contextconfigure service vpls string bgp-evpn vxlan number
Treevxlan
Range1 to 2

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of VXLAN auto-bindings creation
Contextconfigure service vpls string bgp-evpn vxlan number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

default-route-tag string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDefault route tag
Contextconfigure service vpls string bgp-evpn vxlan number default-route-tag string
Treedefault-route-tag

Description

This command configures a route tag that is used when sending a route to the BGP application (for the corresponding service and BGP instance). If the corresponding BGP instance is enabled, the command cannot be changed.

When used for BGP EVPN contexts, only one route tag can be passed to BGP for matching on export policies. In case of a conflict with other route tags pushed by EVPN, the default route tag has the least priority. 

The following are examples of the conflict priority handling:

  • If a service is configured with both default-route-tag X and proxy-arp evpn-route-tag Y, the EVPN uses route tag Y when sending EVPN proxy-arp routes to the BGP RIB for advertisement.

  • If a given IP-prefix route is tagged in the route-table with tag A and the R-VPLS, in which the route is advertised, uses B as the default-route-tag, then EVPN keeps tag A when sending the route to the BGP RIB.

The default-route-tag configuration is only supported on EVPN and IP-VPN service routes. The route tag for ES and AD per-ES routes is always zero.

Introduced16.0.R4

Platforms

All

ecmp number
Synopsis Number of paths to reach a specified MAC address
Contextconfigure service vpls string bgp-evpn vxlan number ecmp number
Treeecmp
Range1 to 32
Default1
Introduced 19.5.R1

Platforms

All

evi-three-byte-auto-rt boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAuto-derive the BGP EVPN route target
Contextconfigure service vpls string bgp-evpn vxlan number evi-three-byte-auto-rt boolean
Treeevi-three-byte-auto-rt

Description

When configured to true, the BGP-EVPN instance import and export route target is auto-derived as described in RFC 8365 (Global-Administrator:A/Type/D-ID/Service-ID).

Where:

  • Global Administrator – is the configured 2-octet AS number; if the configured ASN exceeds the 2 byte limit, the low order 16-bit value is taken

  • A=0 (for auto-derivation)

  • Type=4 (EVI-based route-target)

  • D-ID= [1..2] – encodes the BGP instance, which allows the auto-derivation of different route-targets in multi-instance services; the value is inherited from the corresponding BGP instance

  • Service ID=3-octet EVI

When configured to false, route target derivation is not allowed.

Defaultfalse
Introduced21.10.R1

Platforms

All

mh-mode keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMulti-homing mode
Contextconfigure service vpls string bgp-evpn vxlan number mh-mode keyword
Treemh-mode
Optionsaccess, network
Default access
Introduced19.5.R1

Platforms

All

routes
Synopsis Enter the routes context
Context configure service vpls string bgp-evpn vxlan number routes
Treeroutes
Introduced19.5.R1

Platforms

All

auto-disc
Synopsis Enter the auto-disc context
Context configure service vpls string bgp-evpn vxlan number routes auto-disc
Treeauto-disc
Introduced19.5.R1

Platforms

All

advertise boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdvertise routes on auto-discovery
Contextconfigure service vpls string bgp-evpn vxlan number routes auto-disc advertise boolean
Treeadvertise
Defaultfalse
Introduced19.5.R1

Platforms

All

send-tunnel-encap boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSend VXLAN value in encapsulation extended community
Contextconfigure service vpls string bgp-evpn vxlan number send-tunnel-encap boolean
Treesend-tunnel-encap

Description

When configured to true, this command sends the VXLAN value in the encapsulation that is advertised with the EVPN routes for the service. The encapsulation is encoded in RFC5512-based tunnel encapsulation extended communities.

When configured to false, no encapsulation extended community is sent.

Defaulttrue
Introduced16.0.R1

Platforms

All

vxlan-instance reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVXLAN instance
Contextconfigure service vpls string bgp-evpn vxlan number vxlan-instance reference
Treevxlan-instance

Reference

configure service vpls string vxlan instance number

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

bgp-mh-site [site-name] string
Synopsis Enter the bgp-mh-site list instance
Contextconfigure service vpls string bgp-mh-site string
Treebgp-mh-site
Introduced16.0.R1

Platforms

All

[site-name] string
Synopsis Name for the specific site
Context configure service vpls string bgp-mh-site string
Treebgp-mh-site
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the VPLS BGP multi-homing site
Contextconfigure service vpls string bgp-mh-site string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

boot-timer number
Synopsis Wait time after reboot to run the DF election algorithm
Contextconfigure service vpls string bgp-mh-site string boot-timer number
Treeboot-timer
Range0 to 600
Unitsseconds
Introduced 16.0.R1

Platforms

All

id number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSite ID
Contextconfigure service vpls string bgp-mh-site string id number
Treeid
Range1 to 65535
Introduced16.0.R1

Platforms

All

mesh-sdp-binds
Synopsis Specify if a mesh-sdp-binding is associated with this site
Contextconfigure service vpls string bgp-mh-site string mesh-sdp-binds
Treemesh-sdp-binds

Notes

The following elements are part of a choice: mesh-sdp-binds, sap, shg-name, or spoke-sdp.

Introduced16.0.R1

Platforms

All

min-down-timer number
Synopsis Minimum downtime for BGP multi-homing site after transition from up to down
Contextconfigure service vpls string bgp-mh-site string min-down-timer number
Treemin-down-timer
Range0 to 100
Unitsseconds
Introduced 16.0.R1

Platforms

All

sap string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSAP to be associated with this site
Contextconfigure service vpls string bgp-mh-site string sap string
Treesap
String Length1 to 45

Notes

The following elements are part of a choice: mesh-sdp-binds, sap, shg-name, or spoke-sdp.

Introduced16.0.R1

Platforms

All

shg-name string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSHG name to be associated with the site
Contextconfigure service vpls string bgp-mh-site string shg-name string
Treeshg-name
String Length1 to 32

Notes

The following elements are part of a choice: mesh-sdp-binds, sap, shg-name, or spoke-sdp.

Introduced16.0.R1

Platforms

All

spoke-sdp string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSDP associated with the site
Contextconfigure service vpls string bgp-mh-site string spoke-sdp string
Treespoke-sdp
String Length3 to 16

Notes

The following elements are part of a choice: mesh-sdp-binds, sap, shg-name, or spoke-sdp.

Introduced16.0.R1

Platforms

All

bgp-vpls
Synopsis Enable the bgp-vpls context
Context configure service vpls string bgp-vpls
Treebgp-vpls
Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the BGP-VPLS instance
Contextconfigure service vpls string bgp-vpls admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

ve
Synopsis Enter the ve context
Context configure service vpls string bgp-vpls ve
Treeve
Introduced16.0.R1

Platforms

All

id number
Synopsis VPLS edge ID
Contextconfigure service vpls string bgp-vpls ve id number
Treeid
Range1 to 65535
Introduced16.0.R1

Platforms

All

name string
Synopsis VPLS Edge instance name
Context configure service vpls string bgp-vpls ve name string
Treename
String Length1 to 32
Introduced16.0.R1

Platforms

All

capture-sap [sap-id] string
Synopsis Enter the capture-sap list instance
Contextconfigure service vpls string capture-sap string
Treecapture-sap
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[sap-id] string
Synopsis SAP identifier
Contextconfigure service vpls string capture-sap string
Treecapture-sap
String Length1 to 45

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the SAP
Context configure service vpls string capture-sap string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

allow-dot1q-msaps boolean
Synopsis Enable support for triggering managed SAP creation
Contextconfigure service vpls string capture-sap string allow-dot1q-msaps boolean
Treeallow-dot1q-msaps
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

bandwidth number
Synopsis SAP bandwidth
Contextconfigure service vpls string capture-sap string bandwidth number
Treebandwidth
Range1 to 6400000000
Unitskilobps
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

cpu-protection
Synopsis Enter the cpu-protection context
Contextconfigure service vpls string capture-sap string cpu-protection
Treecpu-protection
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s

description string
Synopsis Text description
Context configure service vpls string capture-sap string description string
Treedescription
String Length1 to 160
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

dhcp
Synopsis Enter the dhcp context
Context configure service vpls string capture-sap string dhcp
Treedhcp
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

dhcp6
Synopsis Enter the dhcp6 context
Context configure service vpls string capture-sap string dhcp6
Treedhcp6
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ingress
Synopsis Enter the ingress context
Context configure service vpls string capture-sap string ingress
Treeingress
Introduced19.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipoe-session
Synopsis Enter the ipoe-session context
Contextconfigure service vpls string capture-sap string ipoe-session
Treeipoe-session
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of IPoE session management
Contextconfigure service vpls string capture-sap string ipoe-session admin-state keyword
Treeadmin-state
Optionsenable, disable
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

user-db reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal user database for IPoE session authentication
Contextconfigure service vpls string capture-sap string ipoe-session user-db reference
Treeuser-db

Reference

configure subscriber-mgmt local-user-db string

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

msap-defaults
Synopsis Enter the msap-defaults context
Contextconfigure service vpls string capture-sap string msap-defaults
Treemsap-defaults
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

pfcp
Synopsis Enter the pfcp context
Context configure service vpls string capture-sap string pfcp
Treepfcp
Introduced20.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

association reference
Synopsis Association used for PFCP messages on the capture SAP
Contextconfigure service vpls string capture-sap string pfcp association reference
Treeassociation

Description

This command links the capture SAP to a PFCP association. This enables CUPS for the capture SAP and any trigger packets are forwarded to the BNG CUPS CPF.

Reference

configure subscriber-mgmt pfcp association string

Introduced20.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

l2-access-id-alias string
Synopsis String used as Layer 2 access ID for the capture SAP
Contextconfigure service vpls string capture-sap string pfcp l2-access-id-alias string
Treel2-access-id-alias

Description

This command defines a Layer 2 access ID alias for the capture SAP. It replaces the default underlying port-based or LAG-based Layer 2 access ID. Different capture SAPs on the same underlying port or LAG can have different Layer 2 access ID aliases. 

String Length1 to 32
Introduced22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

up-resiliency
Synopsis Enter the up-resiliency context
Contextconfigure service vpls string capture-sap string pfcp up-resiliency
Treeup-resiliency
Introduced22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

monitor-oper-group [oper-group] reference
Synopsis Enter the monitor-oper-group list instance
Contextconfigure service vpls string capture-sap string pfcp up-resiliency monitor-oper-group reference
Treemonitor-oper-group

Description

Commands in this context define parameters to derive the service health based on monitored operational groups. The BNG-UP sends the health value to the MAG-c. The MAG-c uses the value to determine the need for a BNG-UP status change (active or standby).

Note: The following is only applicable for the configure service vpls capture-sap context. If the configured groups are not the same for all capture SAPs sharing the same underlying port or LAG, the configuration of a Layer 2 access ID alias is required, or else the system chooses arbitrarily one set of configured groups.

Max. Instances2
Introduced22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

health-drop number
Synopsis Number subtracted from the health value per failure
Contextconfigure service vpls string capture-sap string pfcp up-resiliency monitor-oper-group reference health-drop number
Treehealth-drop

Description

This command configures the drop in the health value for every operational group member failure. Every failure of an operational group member decreases the base health value to a possible minimum of 0.

Range1 to 100
Default1
Introduced 22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

pppoe
Synopsis Enter the pppoe context
Context configure service vpls string capture-sap string pppoe
Treepppoe
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

router-solicit
Synopsis Enter the router-solicit context
Contextconfigure service vpls string capture-sap string router-solicit
Treerouter-solicit
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

track-srrp number
Synopsis SRRP instance that this capture SAP tracks
Contextconfigure service vpls string capture-sap string track-srrp number
Treetrack-srrp
Range1 to 4294967295
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

trigger-packet
Synopsis Enter the trigger-packet context
Contextconfigure service vpls string capture-sap string trigger-packet
Treetrigger-packet
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

arp boolean
Synopsis ARP packet
Contextconfigure service vpls string capture-sap string trigger-packet arp boolean
Treearp
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

data boolean
Synopsis Data packet
Contextconfigure service vpls string capture-sap string trigger-packet data boolean
Treedata
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

dhcp boolean
Synopsis DHCP packet
Contextconfigure service vpls string capture-sap string trigger-packet dhcp boolean
Treedhcp
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

customer reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisService customer ID
Contextconfigure service vpls string customer reference
Treecustomer

Reference

configure service customer string

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

description string
Synopsis Text description
Context configure service vpls string description string
Treedescription
String Length1 to 80
Introduced16.0.R1

Platforms

All

endpoint [name] string
Synopsis Enter the endpoint list instance
Contextconfigure service vpls string endpoint string
Treeendpoint
Max. Instances10
Introduced16.0.R1

Platforms

All

[name] string
Synopsis Service endpoint name
Context configure service vpls string endpoint string
Treeendpoint
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

fdb
Synopsis Enter the fdb context
Context configure service vpls string endpoint string fdb
Treefdb
Introduced16.0.R1

Platforms

All

maximum-mac-addresses number
Synopsis Maximum number of MAC address entries in the FDB
Contextconfigure service vpls string endpoint string fdb maximum-mac-addresses number
Treemaximum-mac-addresses

Description

This command specifies the maximum number of FDB entries for both learned and static MAC addresses for this endpoint.

When the configured limit is reached, no new addresses are learned from the SAP or spoke SDP until at least one FDB entry is aged out or cleared. Packets with unknown source MAC addresses are still forwarded if their destination MAC addresses are known, or flooded if their destination MAC addresses are unknown.

However, if the configure service vpls fdb discard-unknown command is set to true, packets with unknown destination MAC addresses are discarded, even if the limit of FDB entries on the specific VPLS instance is not reached.

When unconfigured, the endpoint uses the global MAC learning limitations.

Range1 to 511999
Introduced16.0.R1

Platforms

All

mc-endpoint [mc-ep-id] number
Synopsis Enter the mc-endpoint list instance
Contextconfigure service vpls string endpoint string mc-endpoint number
Treemc-endpoint
Max. Instances1
Introduced22.10.R1

Platforms

All

[mc-ep-id] number
Synopsis MC-EP ID
Contextconfigure service vpls string endpoint string mc-endpoint number
Treemc-endpoint

Description

This command configures the identifier associated with the MC-EP. The ID must be the same on both MC-EP peers.

Range1 to 4294967295

Notes

This element is part of a list key.

Introduced22.10.R1

Platforms

All

mc-ep-peer
Synopsis Enter the mc-ep-peer context
Context configure service vpls string endpoint string mc-endpoint number mc-ep-peer
Treemc-ep-peer
Introduced22.10.R1

Platforms

All

name string
Synopsis Name of the MC-EP peer
Context configure service vpls string endpoint string mc-endpoint number mc-ep-peer name string
Treename
String Length1 to 32

Notes

The following elements are part of a choice: name or peer-address.

Introduced22.10.R1

Platforms

All

revert-time (number | keyword)
Synopsis Time to wait before reverting to primary spoke SDP
Contextconfigure service vpls string endpoint string revert-time (number | keyword)
Treerevert-time
Range1 to 600
Unitsseconds
Options never, immediate
Defaultimmediate
Introduced16.0.R1

Platforms

All

eth-cfm
Synopsis Enter the eth-cfm context
Context configure service vpls string eth-cfm
Treeeth-cfm
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mep md-admin-name reference ma-admin-name reference mep-id number
Synopsis Enter the mep list instance
Context configure service vpls string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number
Treemep
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

md-admin-name reference
Synopsis Maintenance Domain (MD) name
Context configure service vpls string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number
Treemep

Reference

configure eth-cfm domain string

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mep-id number
Synopsis Maintenance Endpoint (MEP) ID
Context configure service vpls string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number
Treemep
Range1 to 8191

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

alarm-notification
Synopsis Enter the alarm-notification context
Contextconfigure service vpls string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number alarm-notification
Treealarm-notification

Description

Commands in this context configure the Fault Notification Generator (FNG) time values to raise an alarm or reset the CCM defect alarm. 

Use these timers for network management processes. The timers are not tied into delaying the notification to the fault management system on the network element and do not affect fault propagation mechanisms.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ccm-padding-size number
Synopsis Number of octets of padding to insert in CCM packets
Contextconfigure service vpls string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number ccm-padding-size number
Treeccm-padding-size

Description

This command sets the byte size of the optional Data TLV to be included in the ETH-CC PDU.

This command increases the size of the ETH-CC PDU by the configured value. The base size of the ETH-CC PDU, including the Interface Status TLV and Port Status TLV, is 83 bytes not including the Layer 2 encapsulation. CCM padding is not supported when the CCM interval (configured through configure eth-cfm domain association ccm-interval) is less than 1 second.

Range3 to 1500
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-test
Synopsis Enable the eth-test context
Context configure service vpls string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test
Treeeth-test

Description

Commands in this context configure information used by the Ethernet Test (ETH-TST) packet. The commands must be configured on both the sender and the receiver nodes. The test packets are used with the oam eth-cfm eth-test command.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

test-pattern
Synopsis Enter the test-pattern context
Contextconfigure service vpls string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test test-pattern
Treetest-pattern

Description

Commands in this context specify the test pattern for the ETH-TST frames. The pattern does not have to be the same on the sender and the receiver.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

pattern keyword
Synopsis Test pattern for Ethernet Test frames
Contextconfigure service vpls string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test test-pattern pattern keyword
Treepattern

Description

This command specifies the test pattern of the Ethernet Test (ETH-TST) frames. This does not have to be configured the same on the sender and the receiver.

Optionsall-zeros, all-ones
Default all-zeros
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

grace
Synopsis Enter the grace context
Context configure service vpls string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace
Treegrace

Description

Commands in this context configure the Nokia ETH-CFM Grace function and the ITU-T Y.1731 Ethernet Expected Default (ETH-ED) function.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-ed
Synopsis Enter the eth-ed context
Context configure service vpls string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-ed
Treeeth-ed

Description

Commands in this context configure the ITU-T Y.1731 ETH-ED function.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

rx-eth-ed boolean
Synopsis Receive and process ETH-ED ITU-T Y.1731 PDUs on the MEP
Contextconfigure service vpls string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-ed rx-eth-ed boolean
Treerx-eth-ed

Description

This command enables the reception and processing of the ITU-T Y.1731 ETH-ED PDU on the MEP.

Defaulttrue
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-vsm-grace
Synopsis Enter the eth-vsm-grace context
Contextconfigure service vpls string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace
Treeeth-vsm-grace

Description

Commands in this context configure the Nokia ETH-CFM Grace function.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

rx-eth-vsm-grace boolean
Synopsis Receive and process Nokia ETH-CFM Grace PDU on the MEP
Contextconfigure service vpls string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace rx-eth-vsm-grace boolean
Treerx-eth-vsm-grace

Description

When configured to true, the router enables the Nokia Grace function, which is a vendor-specific PDU that informs MEP peers that the local node may be entering a period of expected defect.

When configured to false, the router disables the Nokia Grace function.

Defaulttrue
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

tx-eth-vsm-grace boolean
Synopsis Transmit ETH-ED PDUs from the MEP
Context configure service vpls string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace tx-eth-vsm-grace boolean
Treetx-eth-vsm-grace

Description

When configured to true, the router can transmit the Nokia ETH-CFM Grace PDU from the MEP when a system soft reset notification is received for one or more cards.

The Nokia Grace function is a vendor-specific PDU that informs MEP peers that the local node may be entering a period of expected defect.

The operator must configure the configure system eth-cfm grace command to instruct the system that the node is capable of transmitting expected-defect windows to peers. The system can only transmit one form of ETH-CFM grace (Nokia ETH-CFM Grace or ITU-T Y.1731 ETH-ED).

When configured to false, the router disables the transmission of the Nokia ETH-CFM Grace PDU from the MEP.

Defaulttrue
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mac-address string
Synopsis MAC address of the MEP
Context configure service vpls string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number mac-address string
Treemac-address

Description

This command specifies the MAC address of the MEP.

When unconfigured, the MAC address of the port (if the MEP is on a SAP) or the MAC address of a bridge (if the MEP is on a spoke) is used.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

etree boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisUse VPLS service as an E-Tree VPLS
Contextconfigure service vpls string etree boolean
Treeetree
Defaultfalse
Introduced16.0.R1

Platforms

All

fdb
Synopsis Enter the fdb context
Context configure service vpls string fdb
Treefdb
Introduced16.0.R1

Platforms

All

mac-learning
Synopsis Enter the mac-learning context
Contextconfigure service vpls string fdb mac-learning
Treemac-learning
Introduced16.0.R1

Platforms

All

local-age-time number
Synopsis Aging time for locally learned MAC addresses
Contextconfigure service vpls string fdb mac-learning local-age-time number
Treelocal-age-time

Description

This command configures the aging time for locally learned MAC addresses in the forwarding database (FDB) for the Virtual Private LAN Service (VPLS) instance. In a VPLS service, MAC addresses are associated with a Service Access Point (SAP) or a Service Distribution Point (SDP). MACs associated with a SAP are classified as local MACs, and MACs associated with an SDP are remote MACs. In each VPLS service instance, there are independent aging timers for locally learned MAC and remotely learned MAC entries in the FDB.

As in a Layer 2 switch, learned MACs can be aged out if no packets are sourced from the MAC address for a period of time (the aging time).

Range60 to 86400
Default300
Introduced 16.0.R1

Platforms

All

remote-age-time number
Synopsis Aging time for remotely learned MAC addresses
Contextconfigure service vpls string fdb mac-learning remote-age-time number
Treeremote-age-time

Description

This command configures the aging time for remotely learned MAC addresses in the forwarding database (FDB) for the Virtual Private LAN Service (VPLS) instance. In a VPLS service, MAC addresses are associated with a Service Access Point (SAP) or a Service Distribution Point (SDP). MACs associated with a SAP are classified as local MACs, and MACs associated with an SDP are remote MACs. In each VPLS service instance, there are independent aging timers for locally learned MAC and remotely learned MAC entries in the FDB.

As in a Layer 2 switch, learned MACs can be aged out if no packets are sourced from the MAC address for a period of time (the aging time). To reduce the amount of signaling required between switches, configure this time larger than the local-age-time command.

Range60 to 86400
Default900
Introduced 16.0.R1

Platforms

All

mac-move
Synopsis Enter the mac-move context
Context configure service vpls string fdb mac-move
Treemac-move
Introduced16.0.R1

Platforms

All

retry-count (number | keyword)
Synopsis Number of retries for re-enabling the SAP or SDP
Contextconfigure service vpls string fdb mac-move retry-count (number | keyword)
Treeretry-count
Range1 to 255
Optionsunlimited
Default3
Introduced 16.0.R1

Platforms

All

sap [sap-id] reference
Synopsis Enter the sap list instance
Context configure service vpls string fdb mac-move sap reference
Treesap
Introduced19.7.R1

Platforms

All

[sap-id] reference
Synopsis SAP identifier
Contextconfigure service vpls string fdb mac-move sap reference
Treesap

Reference

configure service vpls string sap string

Notes

This element is part of a list key.

Introduced19.7.R1

Platforms

All

level keyword
Synopsis Primary or secondary port level
Context configure service vpls string fdb mac-move sap reference level keyword
Treelevel
Optionsprimary, secondary

Notes

This element is mandatory.

Introduced19.7.R1

Platforms

All

spoke-sdp [sdp-bind-id] reference
Synopsis Enter the spoke-sdp list instance
Contextconfigure service vpls string fdb mac-move spoke-sdp reference
Treespoke-sdp
Introduced19.7.R1

Platforms

All

level keyword
Synopsis Primary or secondary port level
Context configure service vpls string fdb mac-move spoke-sdp reference level keyword
Treelevel
Optionsprimary, secondary

Notes

This element is mandatory.

Introduced19.7.R1

Platforms

All

static-mac
Synopsis Enter the static-mac context
Context configure service vpls string fdb static-mac
Treestatic-mac
Introduced16.0.R1

Platforms

All

mac [mac-address] string
Synopsis Enter the mac list instance
Context configure service vpls string fdb static-mac mac string
Treemac
Introduced16.0.R1

Platforms

All

[mac-address] string
Synopsis Static MAC address to SAP/SDP-binding or black-hole
Contextconfigure service vpls string fdb static-mac mac string
Treemac

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

blackhole
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisCreate a static FDB entry for the MAC address to black-hole traffic
Contextconfigure service vpls string fdb static-mac mac string blackhole
Treeblackhole

Notes

The following elements are part of a mandatory choice: blackhole, endpoint, mesh-sdp, sap, or spoke-sdp.

Introduced16.0.R1

Platforms

All

endpoint reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEndpoint associated with the MAC
Contextconfigure service vpls string fdb static-mac mac string endpoint reference
Treeendpoint

Reference

configure service vpls string endpoint string

Notes

The following elements are part of a mandatory choice: blackhole, endpoint, mesh-sdp, sap, or spoke-sdp.

Introduced16.0.R1

Platforms

All

mesh-sdp reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisMesh SDP bind associated with this MAC
Contextconfigure service vpls string fdb static-mac mac string mesh-sdp reference
Treemesh-sdp

Reference

configure service vpls string mesh-sdp string

Notes

The following elements are part of a mandatory choice: blackhole, endpoint, mesh-sdp, sap, or spoke-sdp.

Introduced16.0.R1

Platforms

All

monitor keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEntity to be monitored to decide whether this entry can be installed in the FDB
Contextconfigure service vpls string fdb static-mac mac string monitor keyword
Treemonitor
Optionsnone, forward-status
Defaultnone
Introduced 16.0.R1

Platforms

All

sap reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSAP associated with this MAC
Contextconfigure service vpls string fdb static-mac mac string sap reference
Treesap

Reference

configure service vpls string sap string

Notes

The following elements are part of a mandatory choice: blackhole, endpoint, mesh-sdp, sap, or spoke-sdp.

Introduced16.0.R1

Platforms

All

spoke-sdp reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSpoke SDP bind associated with this MAC
Contextconfigure service vpls string fdb static-mac mac string spoke-sdp reference
Treespoke-sdp

Reference

configure service vpls string spoke-sdp string

Notes

The following elements are part of a mandatory choice: blackhole, endpoint, mesh-sdp, sap, or spoke-sdp.

Introduced16.0.R1

Platforms

All

table
Synopsis Enter the table context
Context configure service vpls string fdb table
Treetable
Introduced16.0.R1

Platforms

All

high-wmark number
Synopsis High watermark for the FDB table
Context configure service vpls string fdb table high-wmark number
Treehigh-wmark
Range0 to 100
Default95
Introduced 16.0.R1

Platforms

All

low-wmark number
Synopsis Low watermark for the FDB table
Context configure service vpls string fdb table low-wmark number
Treelow-wmark
Range0 to 100
Default90
Introduced 16.0.R1

Platforms

All

size number
Synopsis Maximum MAC entries in the FDB
Context configure service vpls string fdb table size number
Treesize
Range1 to 511999
Default250
Introduced 16.0.R1

Platforms

All

gsmp
Synopsis Enter the gsmp context
Context configure service vpls string gsmp
Treegsmp
Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of GSMP
Context configure service vpls string gsmp admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

group [name] string
Synopsis Enter the group list instance
Context configure service vpls string gsmp group string
Treegroup
Max. Instances1024
Introduced16.0.R1

Platforms

All

[name] string
Synopsis GSMP group name
Context configure service vpls string gsmp group string
Treegroup
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the GSMP group
Contextconfigure service vpls string gsmp group string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

ancp
Synopsis Enter the ancp context
Context configure service vpls string gsmp group string ancp
Treeancp
Introduced16.0.R1

Platforms

All

oam boolean
Synopsis Enable GSMP ANCP OAM capability at startup of GSMP connection
Contextconfigure service vpls string gsmp group string ancp oam boolean
Treeoam
Defaultfalse
Introduced16.0.R1

Platforms

All

keepalive number
Synopsis Keepalive value for the GSMP connections in this group
Contextconfigure service vpls string gsmp group string keepalive number
Treekeepalive
Range1 to 25
Unitsseconds
Default 10
Introduced16.0.R1

Platforms

All

neighbor [remote-address] string
Synopsis Enter the neighbor list instance
Contextconfigure service vpls string gsmp group string neighbor string
Treeneighbor
Introduced16.0.R1

Platforms

All

[remote-address] string
Synopsis GSMP neighbor remote IP address
Context configure service vpls string gsmp group string neighbor string
Treeneighbor

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

local-address string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRestrict connections to this local address only within the service running ANCP
Contextconfigure service vpls string gsmp group string neighbor string local-address string
Treelocal-address
Introduced16.0.R1

Platforms

All

priority-marking
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the priority-marking context
Contextconfigure service vpls string gsmp group string neighbor string priority-marking
Treepriority-marking
Introduced16.0.R1

Platforms

All

dscp keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDSCP that is used while remarking the in profile packets
Contextconfigure service vpls string gsmp group string neighbor string priority-marking dscp keyword
Treedscp
Optionsbe, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63

Notes

The following elements are part of a choice: dscp or prec.

Introduced16.0.R1

Platforms

All

prec number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPrecedence priority marking
Contextconfigure service vpls string gsmp group string neighbor string priority-marking prec number
Treeprec
Range0 to 7

Notes

The following elements are part of a choice: dscp or prec.

Introduced16.0.R1

Platforms

All

persistency boolean
Synopsis Store DSL line information when the GSMP connection terminates
Contextconfigure service vpls string gsmp group string persistency boolean
Treepersistency
Defaultfalse
Introduced16.0.R1

Platforms

All

igmp-host-tracking
Synopsis Enter the igmp-host-tracking context
Contextconfigure service vpls string igmp-host-tracking
Treeigmp-host-tracking
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of IGMP host tracking
Contextconfigure service vpls string igmp-host-tracking admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

expiry-time number
Synopsis Time that the system continues to track inactive hosts
Contextconfigure service vpls string igmp-host-tracking expiry-time number
Treeexpiry-time
Range1 to 65535
Unitsseconds
Default 260
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

igmp-snooping
Synopsis Enter the igmp-snooping context
Contextconfigure service vpls string igmp-snooping
Treeigmp-snooping
Introduced16.0.R1

Platforms

All

mvr
Synopsis Enter the mvr context
Context configure service vpls string igmp-snooping mvr
Treemvr
Introduced16.0.R1

Platforms

All

ignore-l2vpn-mtu-mismatch boolean
Synopsis Ignore the L2 VPN MTU mismatch with local service MTU
Contextconfigure service vpls string ignore-l2vpn-mtu-mismatch boolean
Treeignore-l2vpn-mtu-mismatch

Description

When configured to true, the router does not check the value of the Layer 2 MTU in the Layer2 Info Extended Community received in a BGP update message against the local service MTU or locally signaled MTU. It may, therefore, bring up the BGP VPLS service regardless of any MTU mismatch.

When configured to false, an MTU mismatch prevents the system from bringing up a BGP-VPLS service.

Defaultfalse
Introduced22.2.R1

Platforms

All

interface [interface-name] string
Synopsis Enter the interface list instance
Contextconfigure service vpls string interface string
Treeinterface
Introduced16.0.R1

Platforms

All

[interface-name] string
Synopsis IP interface name
Context configure service vpls string interface string
Treeinterface
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the interface
Contextconfigure service vpls string interface string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

hold-time
Synopsis Enter the hold-time context
Context configure service vpls string interface string hold-time
Treehold-time
Introduced16.0.R1

Platforms

All

ipv4
Synopsis Enter the ipv4 context
Context configure service vpls string interface string hold-time ipv4
Treeipv4
Introduced16.0.R1

Platforms

All

down
Synopsis Enter the down context
Context configure service vpls string interface string hold-time ipv4 down
Treedown

Description

Commands in this context configure the down hold timer, which specifies the delay before activating the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface up, unless an operator configures the init-only command. 

Introduced16.0.R1

Platforms

All

init-only boolean
Synopsis Apply delay only at interface configuration or reboot
Contextconfigure service vpls string interface string hold-time ipv4 down init-only boolean
Treeinit-only

Description

This command applies a delay only when the IP interface is first configured or after a system reboot.

Defaultfalse
Introduced16.0.R1

Platforms

All

up
Synopsis Enter the up context
Context configure service vpls string interface string hold-time ipv4 up
Treeup

Description

Commands in this context configure the up hold timer, which specifies the delay before deactivation of the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface down.

Introduced16.0.R1

Platforms

All

ipv4
Synopsis Enter the ipv4 context
Context configure service vpls string interface string ipv4
Treeipv4
Introduced16.0.R1

Platforms

All

neighbor-discovery
Synopsis Enter the neighbor-discovery context
Contextconfigure service vpls string interface string ipv4 neighbor-discovery
Treeneighbor-discovery
Introduced16.0.R1

Platforms

All

static-neighbor [ipv4-address] string
Synopsis Enter the static-neighbor list instance
Contextconfigure service vpls string interface string ipv4 neighbor-discovery static-neighbor string
Treestatic-neighbor
Introduced16.0.R1

Platforms

All

primary
Synopsis Enable the primary context
Context configure service vpls string interface string ipv4 primary
Treeprimary
Introduced16.0.R1

Platforms

All

mac string
Synopsis MAC address for the interface
Context configure service vpls string interface string mac string
Treemac
Introduced16.0.R1

Platforms

All

isid-policy
Synopsis Enter the isid-policy context
Context configure service vpls string isid-policy
Treeisid-policy
Introduced19.10.R1

Platforms

All

entry [range-entry-id] number
Synopsis Enter the entry list instance
Context configure service vpls string isid-policy entry number
Treeentry
Introduced19.10.R1

Platforms

All

[range-entry-id] number
Synopsis ISID policy entry ID
Context configure service vpls string isid-policy entry number
Treeentry
Range1 to 8191

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

range
Synopsis Enter the range context
Context configure service vpls string isid-policy entry number range
Treerange
Introduced19.10.R1

Platforms

All

load-balancing
Synopsis Enter the load-balancing context
Contextconfigure service vpls string load-balancing
Treeload-balancing
Introduced16.0.R1

Platforms

All

lbl-eth-or-ip-l4-teid boolean
Synopsis Enable hashing of MPLS ethernet and IP packets on SAPs
Contextconfigure service vpls string load-balancing lbl-eth-or-ip-l4-teid boolean
Treelbl-eth-or-ip-l4-teid

Description

When configured to true, this command enables hashing of MPLS Ethernet and MPLS IP packets received on the Epipe and VPLS service SAP using the MPLS labels, the inner IP addresses, the port numbers, and the GTP TEID field, if read by the system. This capability is supported on line cards that are FP4-based and later. 

Defaultfalse
Introduced22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

m-vpls boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSpecify whether this is a management VPLS
Contextconfigure service vpls string m-vpls boolean
Treem-vpls
Defaultfalse
Introduced16.0.R1

Platforms

All

mac-flush
Synopsis Enter the mac-flush context
Context configure service vpls string mac-flush
Treemac-flush
Introduced16.0.R1

Platforms

All

tldp
Synopsis Enter the tldp context
Context configure service vpls string mac-flush tldp
Treetldp
Introduced16.0.R1

Platforms

All

mac-protect
Synopsis Enter the mac-protect context
Context configure service vpls string mac-protect
Treemac-protect
Introduced19.10.R1

Platforms

All

mac [mac-address] string
Synopsis Add a list entry for mac
Context configure service vpls string mac-protect mac string
Treemac
Introduced19.10.R1

Platforms

All

[mac-address] string
Synopsis Protected MAC address
Context configure service vpls string mac-protect mac string
Treemac

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

mcr-default-gtw
Synopsis Enter the mcr-default-gtw context
Contextconfigure service vpls string mcr-default-gtw
Treemcr-default-gtw
Introduced16.0.R1

Platforms

All

ip string
Synopsis Multi-chassis ring default gateway IP address
Contextconfigure service vpls string mcr-default-gtw ip string
Treeip
Introduced16.0.R1

Platforms

All

mac string
Synopsis Multi-chassis ring default gateway MAC address
Contextconfigure service vpls string mcr-default-gtw mac string
Treemac
Default00:00:00:00:00:00
Introduced16.0.R1

Platforms

All

mesh-sdp [sdp-bind-id] string
Synopsis Enter the mesh-sdp list instance
Contextconfigure service vpls string mesh-sdp string
Treemesh-sdp
Introduced16.0.R1

Platforms

All

[sdp-bind-id] string
Synopsis SDP binding ID
Contextconfigure service vpls string mesh-sdp string
Treemesh-sdp
String Length3 to 16

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the SDP binding to the service
Contextconfigure service vpls string mesh-sdp string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

bfd
Synopsis Enter the bfd context
Context configure service vpls string mesh-sdp string bfd
Treebfd
Introduced21.2.R1

Platforms

All

bfd-template reference
Synopsis BFD template associated with the SDP binding
Contextconfigure service vpls string mesh-sdp string bfd bfd-template reference
Treebfd-template

Description

This command configures a named BFD template to be used by VCCV BFD on PWs belonging to the VLL service. The template specifies parameters, such as the minimum transmit and receive control packet timer intervals, used by the BFD session. Template parameters are configured under the configure router bfd context.

Reference

configure bfd bfd-template string

Introduced21.2.R1

Platforms

All

cpu-protection
Synopsis Enter the cpu-protection context
Contextconfigure service vpls string mesh-sdp string cpu-protection
Treecpu-protection
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

eth-cfm-monitoring
Synopsis Enable the eth-cfm-monitoring context
Contextconfigure service vpls string mesh-sdp string cpu-protection eth-cfm-monitoring
Treeeth-cfm-monitoring

Notes

The following elements are part of a choice: eth-cfm-monitoring or mac-monitoring.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

mac-monitoring
Synopsis Monitor MAC for CPU protection
Context configure service vpls string mesh-sdp string cpu-protection mac-monitoring
Treemac-monitoring

Notes

The following elements are part of a choice: eth-cfm-monitoring or mac-monitoring.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

dhcp
Synopsis Enter the dhcp context
Context configure service vpls string mesh-sdp string dhcp
Treedhcp
Introduced16.0.R1

Platforms

All

snoop boolean
Synopsis Allow DHCP snooping of DHCP messages on the SAP or SDP
Contextconfigure service vpls string mesh-sdp string dhcp snoop boolean
Treesnoop
Defaultfalse
Introduced16.0.R1

Platforms

All

egress
Synopsis Enter the egress context
Context configure service vpls string mesh-sdp string egress
Treeegress
Introduced16.0.R1

Platforms

All

filter
Synopsis Enter the filter context
Context configure service vpls string mesh-sdp string egress filter
Treefilter
Introduced16.0.R1

Platforms

All

mfib-allowed-mda-destinations
Synopsis Enter the mfib-allowed-mda-destinations context
Contextconfigure service vpls string mesh-sdp string egress mfib-allowed-mda-destinations
Treemfib-allowed-mda-destinations
Introduced16.0.R4

Platforms

All

qos
Synopsis Enter the qos context
Context configure service vpls string mesh-sdp string egress qos
Treeqos
Introduced16.0.R1

Platforms

All

network
Synopsis Enter the network context
Context configure service vpls string mesh-sdp string egress qos network
Treenetwork
Introduced16.0.R1

Platforms

All

port-redirect-group
Synopsis Enter the port-redirect-group context
Contextconfigure service vpls string mesh-sdp string egress qos network port-redirect-group
Treeport-redirect-group
Introduced16.0.R1

Platforms

All

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEgress MPLS VC label to send packets to the far end
Contextconfigure service vpls string mesh-sdp string egress vc-label number
Treevc-label
Range16 to 1048575
Introduced16.0.R1

Platforms

All

entropy-label
Synopsis Enable the use of entropy labels for spoke SDPs
Contextconfigure service vpls string mesh-sdp string entropy-label
Treeentropy-label

Notes

The following elements are part of a choice: entropy-label or hash-label.

Introduced16.0.R1

Platforms

All

eth-cfm
Synopsis Enter the eth-cfm context
Context configure service vpls string mesh-sdp string eth-cfm
Treeeth-cfm
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

collect-lmm-fc-stats
Synopsis Enter the collect-lmm-fc-stats context
Contextconfigure service vpls string mesh-sdp string eth-cfm collect-lmm-fc-stats
Treecollect-lmm-fc-stats

Description

Commands in this context configure per forwarding class (FC) LMM information collection.

The commands fc-in-profile and fc in this context are mutually exclusive. The commands apply to either profile-aware or profile-unaware FCs respectively. 

This command and the collect-lmm-stats command are mutually exclusive when there is entity resource contention.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fc keyword
Synopsis Forwarding class name for profile-unaware counter
Contextconfigure service vpls string mesh-sdp string eth-cfm collect-lmm-fc-stats fc keyword
Treefc

Description

This command configures individual counters for the specified FCs without regard for profile. The system includes all countable packets that match a configured FC, regardless of profile, in this counter.

An FC specified as part of this command and for this specific context cannot be specified as a profile-aware FC using the fc-in-profile command under the collect-lmm-fc-stats context. 

When this command is reentered, a differential is performed. Omitted FCs stop counting, newly added FCs start counting, and unchanged FCs continue to count.

Optionsbe, l2, af, l1, h2, ef, h1, nc
Max. Instances 8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fc-in-profile keyword
Synopsis Forwarding class name for profile-aware counter
Contextconfigure service vpls string mesh-sdp string eth-cfm collect-lmm-fc-stats fc-in-profile keyword
Treefc-in-profile

Description

This command configures individual counters for the specified FCs with regard to profile. The system includes all countable packets that match a configured FC and that are deemed to be in-profile in this counter.

An FC specified as part of this command and for this specific context cannot be specified as a profile-unaware FC using the fc command under the collect-lmm-fc-stats context.

When this command is reentered, a differential is performed. Omitted FCs stop counting, newly added FCs start counting, and unchanged FCs continue to count.

Optionsbe, l2, af, l1, h2, ef, h1, nc
Max. Instances 8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

collect-lmm-stats boolean
Synopsis Collect statistics for loss measurement message tests
Contextconfigure service vpls string mesh-sdp string eth-cfm collect-lmm-stats boolean
Treecollect-lmm-stats

Description

When configured to true, the router instantiates the statistical counter to transmit and receive packets for the LAG facility MEP bindings.

The show eth-cfm collect-lmm-stats command displays entities that have been enabled to collect transit and receive counters.

When configured to false, the router does not instantiate the counter and the LMM PDU associated with the MEP does not populate the counters in the packet.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mep md-admin-name reference ma-admin-name reference mep-id number
Synopsis Enter the mep list instance
Context configure service vpls string mesh-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number
Treemep
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mep-id number
Synopsis Maintenance Endpoint (MEP) ID
Context configure service vpls string mesh-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number
Treemep
Range1 to 8191

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ais
Synopsis Enable the ais context
Context configure service vpls string mesh-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number ais
Treeais
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

alarm-notification
Synopsis Enter the alarm-notification context
Contextconfigure service vpls string mesh-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number alarm-notification
Treealarm-notification

Description

Commands in this context configure the Fault Notification Generator (FNG) time values to raise an alarm or reset the CCM defect alarm. 

Use these timers for network management processes. The timers are not tied into delaying the notification to the fault management system on the network element and do not affect fault propagation mechanisms.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ccm-padding-size number
Synopsis Number of octets of padding to insert in CCM packets
Contextconfigure service vpls string mesh-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number ccm-padding-size number
Treeccm-padding-size

Description

This command sets the byte size of the optional Data TLV to be included in the ETH-CC PDU.

This command increases the size of the ETH-CC PDU by the configured value. The base size of the ETH-CC PDU, including the Interface Status TLV and Port Status TLV, is 83 bytes not including the Layer 2 encapsulation. CCM padding is not supported when the CCM interval (configured through configure eth-cfm domain association ccm-interval) is less than 1 second.

Range3 to 1500
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

csf
Synopsis Enable the csf context
Context configure service vpls string mesh-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number csf
Treecsf
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

direction keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDirection the MEP faces
Contextconfigure service vpls string mesh-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number direction keyword
Treedirection
Optionsdown, up
Default down
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-test
Synopsis Enable the eth-test context
Context configure service vpls string mesh-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test
Treeeth-test

Description

Commands in this context configure information used by the Ethernet Test (ETH-TST) packet. The commands must be configured on both the sender and the receiver nodes. The test packets are used with the oam eth-cfm eth-test command.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

test-pattern
Synopsis Enter the test-pattern context
Contextconfigure service vpls string mesh-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test test-pattern
Treetest-pattern

Description

Commands in this context specify the test pattern for the ETH-TST frames. The pattern does not have to be the same on the sender and the receiver.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

pattern keyword
Synopsis Test pattern for Ethernet Test frames
Contextconfigure service vpls string mesh-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test test-pattern pattern keyword
Treepattern

Description

This command specifies the test pattern of the Ethernet Test (ETH-TST) frames. This does not have to be configured the same on the sender and the receiver.

Optionsall-zeros, all-ones
Default all-zeros
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

grace
Synopsis Enter the grace context
Context configure service vpls string mesh-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace
Treegrace

Description

Commands in this context configure the Nokia ETH-CFM Grace function and the ITU-T Y.1731 Ethernet Expected Default (ETH-ED) function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-ed
Synopsis Enter the eth-ed context
Context configure service vpls string mesh-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-ed
Treeeth-ed

Description

Commands in this context configure the ITU-T Y.1731 ETH-ED function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

rx-eth-ed boolean
Synopsis Receive and process ETH-ED ITU-T Y.1731 PDUs on the MEP
Contextconfigure service vpls string mesh-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-ed rx-eth-ed boolean
Treerx-eth-ed

Description

This command enables the reception and processing of the ITU-T Y.1731 ETH-ED PDU on the MEP.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-vsm-grace
Synopsis Enter the eth-vsm-grace context
Contextconfigure service vpls string mesh-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace
Treeeth-vsm-grace

Description

Commands in this context configure the Nokia ETH-CFM Grace function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

rx-eth-vsm-grace boolean
Synopsis Receive and process Nokia ETH-CFM Grace PDU on the MEP
Contextconfigure service vpls string mesh-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace rx-eth-vsm-grace boolean
Treerx-eth-vsm-grace

Description

When configured to true, the router enables the Nokia Grace function, which is a vendor-specific PDU that informs MEP peers that the local node may be entering a period of expected defect.

When configured to false, the router disables the Nokia Grace function.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

tx-eth-vsm-grace boolean
Synopsis Transmit ETH-ED PDUs from the MEP
Context configure service vpls string mesh-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace tx-eth-vsm-grace boolean
Treetx-eth-vsm-grace

Description

When configured to true, the router can transmit the Nokia ETH-CFM Grace PDU from the MEP when a system soft reset notification is received for one or more cards.

The Nokia Grace function is a vendor-specific PDU that informs MEP peers that the local node may be entering a period of expected defect.

The operator must configure the configure system eth-cfm grace command to instruct the system that the node is capable of transmitting expected-defect windows to peers. The system can only transmit one form of ETH-CFM grace (Nokia ETH-CFM Grace or ITU-T Y.1731 ETH-ED).

When configured to false, the router disables the transmission of the Nokia ETH-CFM Grace PDU from the MEP.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mac-address string
Synopsis MAC address of the MEP
Context configure service vpls string mesh-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number mac-address string
Treemac-address

Description

This command specifies the MAC address of the MEP.

When unconfigured, the MAC address of the port (if the MEP is on a SAP) or the MAC address of a bridge (if the MEP is on a spoke) is used.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

primary-vlan boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisMEP provisioned using MA primary VLAN ID
Contextconfigure service vpls string mesh-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number primary-vlan boolean
Treeprimary-vlan
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mip primary-vlan (number | keyword)
Synopsis Enter the mip list instance
Context configure service vpls string mesh-sdp string eth-cfm mip primary-vlan (number | keyword)
Treemip
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

primary-vlan (number | keyword)
Synopsis VLAN ID to which the MIP is attached
Context configure service vpls string mesh-sdp string eth-cfm mip primary-vlan (number | keyword)
Treemip

Description

This command provides an option for linking a MIP with a Primary VLAN number or none. When the none option is provided, the MIP does not include the primary vlan.

Range1 to 4094
Optionsnone

Notes

This element is part of a list key.

Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

cfm-vlan-tag string
Synopsis VLAN tags to apply to CFM PDUs for egress processing
Contextconfigure service vpls string mesh-sdp string eth-cfm mip primary-vlan (number | keyword) cfm-vlan-tag string
Treecfm-vlan-tag

Description

This command allows the CFM function to include additional VLAN tags to the CFM packet that are carried to the egress and treated as service delimited. Typically, this function is used to influence the VLAN carried over a binding that uses the vc-type vlan or the binding forces the use of one or more VLAN tag that results in a mismatch between the service data arriving at the binding and the locally generated ETH-CFM PDUs arriving at the same egress. When this command is included under the MEP or MIP configuration, the tags used as part of the configuration typically match the SAP service delimited configuration.

String Length1 to 9
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

squelch-ingress-ctag-levels number
Synopsis Squelch levels using additional VLAN C-Tag space
Contextconfigure service vpls string mesh-sdp string eth-cfm squelch-ingress-ctag-levels number
Treesquelch-ingress-ctag-levels

Description

This command defines the levels of the ETH-CFM packets that are silently discarded on ingress into the SAP or SDP binding from the wire that matches the service delineation of the SAP or SDP binding plus an additional VLAN, up to a maximum tag length of two tags. All ETH-CFM packets inbound to the SAP or SDP binding that match the configured levels are dropped without regard for any other ETH-CFM criteria. No statistical information or drop count is available for any ETH-CFM packet that is silently discarded by this option.

The list of levels must be a complete contiguous list from 0 up to the highest level to be dropped.

Range0 to 7
Max. Instances8
Introduced 21.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

squelch-ingress-levels number
Synopsis Levels for which ETH-CFM packets are silently discarded
Contextconfigure service vpls string mesh-sdp string eth-cfm squelch-ingress-levels number
Treesquelch-ingress-levels

Description

This command defines the levels of the ETH-CFM packets that are silently discarded on ingress into the SAP or SDP binding from the wire that matches the service delineation of the SAP or SDP binding. All ETH-CFM packets inbound to the SAP or SDP binding that match the configured levels are dropped without regard for any other ETH-CFM criteria. No statistical information or drop count is available for any ETH-CFM packet that is silently discarded by this option.

The list of levels must be a complete contiguous list from 0 up to the highest level that will be dropped.

Range0 to 7
Max. Instances8
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

vmep-filter boolean
Synopsis Suppress eth-cfm PDUs based on level lower than or equal to configured Virtual MEP
Contextconfigure service vpls string mesh-sdp string eth-cfm vmep-filter boolean
Treevmep-filter
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

etree-leaf boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEnable etree leaf access-circuit status
Contextconfigure service vpls string mesh-sdp string etree-leaf boolean
Treeetree-leaf
Defaultfalse
Introduced16.0.R1

Platforms

All

etree-root-leaf-tag boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisStatus for E-tree root leaf tag
Contextconfigure service vpls string mesh-sdp string etree-root-leaf-tag boolean
Treeetree-root-leaf-tag
Defaultfalse
Introduced16.0.R1

Platforms

All

fdb
Synopsis Enter the fdb context
Context configure service vpls string mesh-sdp string fdb
Treefdb
Introduced16.0.R1

Platforms

All

auto-learn-mac-protect-exclude-list reference
Synopsis Referenced MAC protect exclusion list name
Contextconfigure service vpls string mesh-sdp string fdb auto-learn-mac-protect-exclude-list reference
Treeauto-learn-mac-protect-exclude-list

Description

This command references the name of a MAC protect exclusion list.

Dynamically-learned MAC Source Addresses (SA) are protected if they are learned on an object with ALMP configured and no exclusion list is associated with the object, or if the MAC SA does not match any entry in an associated exclusion list.

An exclusion list can be used in multiple objects of a service. If a list is empty, ALMP does not exclude any learned MAC SAs from protection on the object.

Reference

configure service mac-list string

Introduced20.5.R1

Platforms

All

hash-label
Synopsis Enable the hash-label context
Context configure service vpls string mesh-sdp string hash-label
Treehash-label

Description

Commands in this context configure the use of hash labels for egress datapaths.

For information about hash-label handling, see the "Hash labels" section of the 7450 ESS, 7750 SR, 7950 XRS, and VSR MPLS Guide.

Notes

The following elements are part of a choice: entropy-label or hash-label.

Introduced16.0.R1

Platforms

All

signal-capability
Synopsis Signal hash label capability to the remote PE
Contextconfigure service vpls string mesh-sdp string hash-label signal-capability
Treesignal-capability

Description

When configured, this command enables the signaling and negotiating of the hash label between the local and remote PE nodes.

The signaling process outcome determines whether the local PE inserts the hash label on the user packets. This outcome can override the local PE configuration.

Introduced16.0.R1

Platforms

All

igmp-snooping
Synopsis Enter the igmp-snooping context
Contextconfigure service vpls string mesh-sdp string igmp-snooping
Treeigmp-snooping
Introduced16.0.R1

Platforms

All

mcac
Synopsis Enter the mcac context
Context configure service vpls string mesh-sdp string igmp-snooping mcac
Treemcac
Introduced16.0.R1

Platforms

All

bandwidth
Synopsis Enter the bandwidth context
Context configure service vpls string mesh-sdp string igmp-snooping mcac bandwidth
Treebandwidth
Introduced16.0.R1

Platforms

All

policy reference
Synopsis Multicast CAC policy name
Context configure service vpls string mesh-sdp string igmp-snooping mcac policy reference
Treepolicy

Description

This command configures the name of the global channel bandwidth definition policy that is used for (H)MCAC and HQoS adjustment.

Within the scope of HQoS adjustment, the channel definition policy under the group interface is used if redirection is unconfigured. In this case, the HQoS adjustment can be applied to IPoE subscribers in per-SAP replication mode.

If redirection is configured, the channel bandwidth definition policy applied under the Layer 3 redirected interface is in effect.

Hierarchical MCAC (HMCAC) is supported on two levels simultaneously:

  • subscriber level and redirected interface when redirection is configured

  • subscriber level and group-interface level when redirection is unconfigured

In HMCAC, the subscriber is checked against its bandwidth limits first, then against the bandwidth limits of the redirected or group interface. If redirection is configured but the policy is referenced only under the group interface, no admission control is executed (HMCAC or MCAC).

Reference

configure mcac policy string

Introduced16.0.R1

Platforms

All

static
Synopsis Enter the static context
Context configure service vpls string mesh-sdp string igmp-snooping static
Treestatic
Introduced16.0.R1

Platforms

All

group [group-address] string
Synopsis Enter the group list instance
Context configure service vpls string mesh-sdp string igmp-snooping static group string
Treegroup
Introduced16.0.R1

Platforms

All

[group-address] string
Synopsis Group address of static IGMP multicast channel
Contextconfigure service vpls string mesh-sdp string igmp-snooping static group string
Treegroup

Description

This command configures an address that receives data on an interface. The IP address must be unique for each static group.

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

source [source-address] string
Synopsis Add a list entry for source
Context configure service vpls string mesh-sdp string igmp-snooping static group string source string
Treesource

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced16.0.R1

Platforms

All

ingress
Synopsis Enter the ingress context
Context configure service vpls string mesh-sdp string ingress
Treeingress
Introduced16.0.R1

Platforms

All

filter
Synopsis Enter the filter context
Context configure service vpls string mesh-sdp string ingress filter
Treefilter
Introduced16.0.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service vpls string mesh-sdp string ingress qos
Treeqos
Introduced16.0.R1

Platforms

All

network
Synopsis Enter the network context
Context configure service vpls string mesh-sdp string ingress qos network
Treenetwork
Introduced16.0.R1

Platforms

All

fp-redirect-group
Synopsis Enter the fp-redirect-group context
Contextconfigure service vpls string mesh-sdp string ingress qos network fp-redirect-group
Treefp-redirect-group
Introduced16.0.R1

Platforms

All

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIngress MPLS VC label to send packets to the far end
Contextconfigure service vpls string mesh-sdp string ingress vc-label number
Treevc-label
Range1 to 1048575
Introduced16.0.R1

Platforms

All

mld-snooping
Synopsis Enter the mld-snooping context
Contextconfigure service vpls string mesh-sdp string mld-snooping
Treemld-snooping
Introduced16.0.R1

Platforms

All

static
Synopsis Enter the static context
Context configure service vpls string mesh-sdp string mld-snooping static
Treestatic
Introduced16.0.R1

Platforms

All

group [group-address] string
Synopsis Enter the group list instance
Context configure service vpls string mesh-sdp string mld-snooping static group string
Treegroup
Introduced16.0.R1

Platforms

All

[group-address] string
Synopsis Group address of multicast channel
Context configure service vpls string mesh-sdp string mld-snooping static group string
Treegroup

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

source [source-address] string
Synopsis Add a list entry for source
Context configure service vpls string mesh-sdp string mld-snooping static group string source string
Treesource

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced16.0.R1

Platforms

All

mrp
Synopsis Enter the mrp context
Context configure service vpls string mesh-sdp string mrp
Treemrp
Introduced20.10.R1

Platforms

All

join-time number
Synopsis Maximum rate for attribute join messages sent on SDP
Contextconfigure service vpls string mesh-sdp string mrp join-time number
Treejoin-time
Range1 to 10
Unitsdeciseconds
Default 2
Introduced20.10.R1

Platforms

All

leave-all-time number
Synopsis Frequency of LeaveAll PDUs by LeaveAll state machine
Contextconfigure service vpls string mesh-sdp string mrp leave-all-time number
Treeleave-all-time
Range60 to 300
Unitsdeciseconds
Default 100
Introduced20.10.R1

Platforms

All

leave-time number
Synopsis Time in LV state before transition to MT state
Contextconfigure service vpls string mesh-sdp string mrp leave-time number
Treeleave-time
Range30 to 60
Unitsdeciseconds
Default 30
Introduced20.10.R1

Platforms

All

periodic-time number
Synopsis Frequency of periodic events generated by state machine
Contextconfigure service vpls string mesh-sdp string mrp periodic-time number
Treeperiodic-time
Range10 to 100
Unitsdeciseconds
Default 10
Introduced20.10.R1

Platforms

All

pbb
Synopsis Enter the pbb context
Context configure service vpls string mesh-sdp string pbb
Treepbb
Introduced20.10.R1

Platforms

All

fault-propagation
Synopsis Enter the fault-propagation context
Contextconfigure service vpls string mesh-sdp string pbb fault-propagation
Treefault-propagation
Introduced20.10.R1

Platforms

All

backbone-mac-name [name] reference
Synopsis Add a list entry for backbone-mac-name
Contextconfigure service vpls string mesh-sdp string pbb fault-propagation backbone-mac-name reference
Treebackbone-mac-name
Introduced20.10.R1

Platforms

All

vc-type keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisType of virtual circuit (VC) associated with the SDP binding; VPLS not supported
Contextconfigure service vpls string mesh-sdp string vc-type keyword
Treevc-type
Optionsether, vlan
Default ether
Introduced16.0.R1

Platforms

All

mfib
Synopsis Enter the mfib context
Context configure service vpls string mfib
Treemfib
Introduced16.0.R1

Platforms

All

table
Synopsis Enter the table context
Context configure service vpls string mfib table
Treetable
Introduced16.0.R1

Platforms

All

low-wmark number
Synopsis Low watermark for the MFIB table
Context configure service vpls string mfib table low-wmark number
Treelow-wmark
Range0 to 100
Default90
Introduced 16.0.R1

Platforms

All

size number
Synopsis Maximum SG entries in the MFIB
Context configure service vpls string mfib table size number
Treesize
Range1 to 40959
Introduced16.0.R1

Platforms

All

mld-snooping
Synopsis Enter the mld-snooping context
Contextconfigure service vpls string mld-snooping
Treemld-snooping
Introduced16.0.R1

Platforms

All

mvr
Synopsis Enter the mvr context
Context configure service vpls string mld-snooping mvr
Treemvr
Introduced16.0.R1

Platforms

All

mrp
Synopsis Enter the mrp context
Context configure service vpls string mrp
Treemrp
Introduced20.10.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of MRP
Context configure service vpls string mrp admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced20.10.R1

Platforms

All

mmrp
Synopsis Enter the mmrp context
Context configure service vpls string mrp mmrp
Treemmrp
Introduced20.10.R1

Platforms

All

attribute-table
Synopsis Enter the attribute-table context
Contextconfigure service vpls string mrp mmrp attribute-table
Treeattribute-table
Introduced20.10.R1

Platforms

All

size number
Synopsis Maximum number of attributes accepted by B-VPLS
Contextconfigure service vpls string mrp mmrp attribute-table size number
Treesize
Range1 to 8192
Default2048
Introduced 20.10.R1

Platforms

All

flood-time number
Synopsis Time when traffic is flooded after status change
Contextconfigure service vpls string mrp mmrp flood-time number
Treeflood-time
Range3 to 600
Introduced20.10.R1

Platforms

All

pbb
Synopsis Enter the pbb context
Context configure service vpls string pbb
Treepbb
Introduced16.0.R1

Platforms

All

backbone-vpls [backbone-vpls-service-name] reference
Synopsis Enter the backbone-vpls list instance
Contextconfigure service vpls string pbb backbone-vpls reference
Treebackbone-vpls
Max. Instances1
Introduced16.0.R1

Platforms

All

igmp-snooping
Synopsis Enter the igmp-snooping context
Contextconfigure service vpls string pbb backbone-vpls reference igmp-snooping
Treeigmp-snooping
Introduced16.0.R1

Platforms

All

mrouter-destination [mac-reference] reference
Synopsis Add a list entry for mrouter-destination
Contextconfigure service vpls string pbb backbone-vpls reference igmp-snooping mrouter-destination reference
Treemrouter-destination
Introduced16.0.R1

Platforms

All

isid number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisBackbone VPLS ISID
Contextconfigure service vpls string pbb backbone-vpls reference isid number
Treeisid
Range0 to 16777215

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

mesh-sdp [sdp-bind-id] reference
Synopsis Enter the mesh-sdp list instance
Contextconfigure service vpls string pbb backbone-vpls reference mesh-sdp reference
Treemesh-sdp
Introduced16.0.R1

Platforms

All

mld-snooping
Synopsis Enter the mld-snooping context
Contextconfigure service vpls string pbb backbone-vpls reference mld-snooping
Treemld-snooping
Introduced16.0.R1

Platforms

All

mrouter-destination [mac-reference] reference
Synopsis Add a list entry for mrouter-destination
Contextconfigure service vpls string pbb backbone-vpls reference mld-snooping mrouter-destination reference
Treemrouter-destination
Introduced16.0.R1

Platforms

All

sap [sap-id] reference
Synopsis Enter the sap list instance
Context configure service vpls string pbb backbone-vpls reference sap reference
Treesap
Introduced16.0.R1

Platforms

All

[sap-id] reference
Synopsis Backbone VPLS SAP
Context configure service vpls string pbb backbone-vpls reference sap reference
Treesap

Reference

configure service vpls string sap string

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

spoke-sdp [sdp-bind-id] reference
Synopsis Enter the spoke-sdp list instance
Contextconfigure service vpls string pbb backbone-vpls reference spoke-sdp reference
Treespoke-sdp
Introduced16.0.R1

Platforms

All

i-vpls-mac-flush
Synopsis Enter the i-vpls-mac-flush context
Contextconfigure service vpls string pbb i-vpls-mac-flush
Treei-vpls-mac-flush
Introduced16.0.R1

Platforms

All

tldp
Synopsis Enter the tldp context
Context configure service vpls string pbb i-vpls-mac-flush tldp
Treetldp
Introduced16.0.R1

Platforms

All

send-to-bvpls
Synopsis Enter the send-to-bvpls context
Contextconfigure service vpls string pbb i-vpls-mac-flush tldp send-to-bvpls
Treesend-to-bvpls
Introduced16.0.R1

Platforms

All

mac-notification
Synopsis Enter the mac-notification context
Contextconfigure service vpls string pbb mac-notification
Treemac-notification
Introduced16.0.R1

Platforms

All

renotify (number | keyword)
Synopsis Re-notify interval for MAC-notification messages
Contextconfigure service vpls string pbb mac-notification renotify (number | keyword)
Treerenotify
Range240 to 840
Unitsseconds
Options none
Default none
Introduced16.0.R1

Platforms

All

source-bmac
Synopsis Enter the source-bmac context
Context configure service vpls string pbb source-bmac
Treesource-bmac
Introduced16.0.R1

Platforms

All

pbb-type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPBB VPLS type
Contextconfigure service vpls string pbb-type keyword
Treepbb-type
Optionsb-vpls, i-vpls
Introduced 16.0.R1

Platforms

All

pim-snooping
Synopsis Enable the pim-snooping context
Contextconfigure service vpls string pim-snooping
Treepim-snooping
Introduced16.0.R1

Platforms

All

group-policy string
Synopsis Group policy name
Context configure service vpls string pim-snooping group-policy string
Treegroup-policy
String Length1 to 255
Max. Instances5

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

All

hold-time number
Synopsis Duration that allows the PIM-snooping switch to snoop all the PIM states in the VPLS
Contextconfigure service vpls string pim-snooping hold-time number
Treehold-time
Range0 to 300
Unitsseconds
Default 90
Introduced16.0.R1

Platforms

All

provider-tunnel
Synopsis Enable the provider-tunnel context
Contextconfigure service vpls string provider-tunnel
Treeprovider-tunnel
Introduced19.7.R1

Platforms

All

inclusive
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the inclusive context
Contextconfigure service vpls string provider-tunnel inclusive
Treeinclusive
Introduced19.7.R1

Platforms

All

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of P2MP LSP as the I-PMSI
Contextconfigure service vpls string provider-tunnel inclusive admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced19.7.R1

Platforms

All

data-delay-interval number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisI-PMSI data delay timer
Contextconfigure service vpls string provider-tunnel inclusive data-delay-interval number
Treedata-delay-interval
Range3 to 180
Unitsseconds
Default 15
Introduced19.7.R1

Platforms

All

mldp
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable/Disable MLDP
Contextconfigure service vpls string provider-tunnel inclusive mldp
Treemldp

Notes

The following elements are part of a choice: mldp or rsvp.

Introduced19.7.R1

Platforms

All

owner keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisConfigure provider-tunnel owner
Contextconfigure service vpls string provider-tunnel inclusive owner keyword
Treeowner
Optionsbgp-ad, bgp-vpls, bgp-evpn-mpls
Introduced19.7.R1

Platforms

All

root-and-leaf boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisConfigure whether the provider tunnel acts as a leaf or both a root and leaf
Contextconfigure service vpls string provider-tunnel inclusive root-and-leaf boolean
Treeroot-and-leaf
Defaultfalse
Introduced19.7.R1

Platforms

All

rsvp
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the rsvp context
Contextconfigure service vpls string provider-tunnel inclusive rsvp
Treersvp

Notes

The following elements are part of a choice: mldp or rsvp.

Introduced19.7.R1

Platforms

All

selective
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the selective context
Contextconfigure service vpls string provider-tunnel selective
Treeselective
Introduced23.3.R1

Platforms

All

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of the selective provider tunnel
Contextconfigure service vpls string provider-tunnel selective admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced23.3.R1

Platforms

All

data-delay-interval number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisS-PMSI data delay timer
Contextconfigure service vpls string provider-tunnel selective data-delay-interval number
Treedata-delay-interval

Description

This command configures the S-PMSI data delay timer.

The data delay interval determines the time the router takes to switch over the traffic from the Ingress Replication binds to the wildcard S-PMSI or from the wildcard S-PMSI to the S-PMSI, after the S-PMSI is created. This time should account for the time it takes for BGP to propagate the S-PMSI A-D route to the downstream PEs and the time it takes the downstream PEs to join the tree all the way up to the root.

Range3 to 180
Unitsseconds
Default 3
Introduced23.3.R1

Platforms

All

data-threshold
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the data-threshold context
Contextconfigure service vpls string provider-tunnel selective data-threshold
Treedata-threshold

Description

Commands in this context specify the data rate threshold that triggers the switch from the inclusive provider tunnel to the selective provider tunnel for (C-S, C-G) within the group range.

Optionally, PE thresholds to create or delete ng-MVPN S-PMSI may also be specified. Omitting the PE thresholds preserves the currently set value (or defaults if never set). Multiple statements (one per a unique group) are allowed in the configuration.

This command is not applicable to multistream S-PMSI.

This command for S-PMSI trees can also be used in EVPN services. The command options are used in the same way as in MVPN when applied to EVPN, in particular the rate and PE thresholds.

Introduced23.3.R1

Platforms

All

group-prefix [ip-group-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis Enter the group-prefix list instance
Contextconfigure service vpls string provider-tunnel selective data-threshold group-prefix (ipv4-prefix | ipv6-prefix)
Treegroup-prefix
Introduced23.3.R1

Platforms

All

pe-threshold-add number
Synopsis Number of receiver PEs for S-PMSI tunnel creation
Contextconfigure service vpls string provider-tunnel selective data-threshold group-prefix (ipv4-prefix | ipv6-prefix) pe-threshold-add number
Treepe-threshold-add

Description

This command specifies the number of Receiver PEs for creating S-PMSI.

A S-PMSI is created when the following apply:

  • The number of receiver PEs for a multicast group is non-zero.

  • The number of receiver PEs is below the threshold.

  • The BW threshold is satisfied.

Range1 to 65535
Default65535
Introduced 23.3.R1

Platforms

All

pe-threshold-delete number
Synopsis Number of receiver PEs for S-PMSI tunnel deletion
Contextconfigure service vpls string provider-tunnel selective data-threshold group-prefix (ipv4-prefix | ipv6-prefix) pe-threshold-delete number
Treepe-threshold-delete

Description

This command specifies the number of Receiver PEs to delete S-PMSI. When the number of receiver PEs for a multicast group configuration is above the threshold, S-PMSI is deleted and the multicast group is moved to IR or a wildcard S-PMSI. Nokia recommends that the delete threshold be configured to be significantly larger than the add threshold to avoid re-signaling of S-PMSI as the Receiver PE count fluctuates

Range2 to 65535
Default65535
Introduced 23.3.R1

Platforms

All

threshold number
Synopsis Threshold rate for a group prefix
Context configure service vpls string provider-tunnel selective data-threshold group-prefix (ipv4-prefix | ipv6-prefix) threshold number
Treethreshold

Description

This command specifies the threshold rate for a group prefix. If the rate for a (C-S, C-G) within the specified group range exceeds the threshold, traffic for the (C-S, C-G) is switched to the selective provider tunnel.

Range0 to 4294967294
Unitskilobps

Notes

This element is mandatory.

Introduced23.3.R1

Platforms

All

maximum-p2mp-spmsi number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of P2MP S-PMSIi tunnels
Contextconfigure service vpls string provider-tunnel selective maximum-p2mp-spmsi number
Treemaximum-p2mp-spmsi

Description

This command specifies the maximum number of S-PMSI tunnels for the EVPN service. When the limit is reached, no more RSVP P2MP S-PMSI or LDP P2MP S-PMSI are created and traffic over the data threshold value stays on I-PMSI

Range1 to 4000
Default10
Introduced 23.3.R1

Platforms

All

mldp boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable MLDP
Contextconfigure service vpls string provider-tunnel selective mldp boolean
Treemldp

Description

When configured to true, this command enables the use of MLDP as a protocol for an LDP P2MP LSP that is used for forwarding Broadcast, Unicast unknown, and Multicast (BUM) packets of a VPLS or B-VPLS instance. This command is also used used for forwarding IP multicast packets of an EVPN VPLS or R-VPLS service.

When configured to false, this command disables the use of MLDP as a protocol to set up the P2MP LSP.

Defaultfalse
Introduced23.3.R1

Platforms

All

owner keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisProvider-tunnel selective owner
Contextconfigure service vpls string provider-tunnel selective owner keyword
Treeowner

Description

This command selects the owner protocol of the S-PMSI tunnel in the service.

The owner must be explicitly set before the provider tunnel can be enabled.

Optionsbgp-evpn-mpls
Introduced23.3.R1

Platforms

All

wildcard-spmsi boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable wildcard S-PMSI support
Contextconfigure service vpls string provider-tunnel selective wildcard-spmsi boolean
Treewildcard-spmsi

Description

When configured to true, the system enables RFC 6625 (C-*, C-*) S-PMSI functionality for EVPN VPLS or R-VPLS services. When enabled, (C-*, C-*) S-PMSI is used instead of I-PMSI for this EVPN VPLS or RVPLS service.

The configure service vprn pim rp auto-rp-discovery command and this command are mutually exclusive.

When configured to false, the system disables the (C-*, C-*) S-PMSI functionality.

Defaultfalse
Introduced23.3.R1

Platforms

All

proxy-arp
Synopsis Enable the proxy-arp context
Context configure service vpls string proxy-arp
Treeproxy-arp
Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the proxy
Context configure service vpls string proxy-arp admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

age-time (number | keyword)
Synopsis Aging timer for proxy entries, where entries are flushed upon timer expiry
Contextconfigure service vpls string proxy-arp age-time (number | keyword)
Treeage-time
Range60 to 86400
Unitsseconds
Options never
Default never
Introduced16.0.R1

Platforms

All

duplicate-detect
Synopsis Enter the duplicate-detect context
Contextconfigure service vpls string proxy-arp duplicate-detect
Treeduplicate-detect
Introduced16.0.R1

Platforms

All

anti-spoof-mac string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMAC address to replace the proxy-ARP/ND offending entry's MAC
Contextconfigure service vpls string proxy-arp duplicate-detect anti-spoof-mac string
Treeanti-spoof-mac
Introduced16.0.R1

Platforms

All

static-blackhole boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisConsider anti-spoof MAC as black-hole static MAC in FDB
Contextconfigure service vpls string proxy-arp duplicate-detect static-blackhole boolean
Treestatic-blackhole
Defaultfalse
Introduced16.0.R1

Platforms

All

window number
Synopsis Time to monitor the MAC address in the anti-spoofing mechanism
Contextconfigure service vpls string proxy-arp duplicate-detect window number
Treewindow
Range1 to 15
Unitsminutes
Default 3
Introduced16.0.R1

Platforms

All

dynamic-arp
Synopsis Enter the dynamic-arp context
Context configure service vpls string proxy-arp dynamic-arp
Treedynamic-arp
Introduced16.0.R1

Platforms

All

ip-address [ipv4-address] string
Synopsis Enter the ip-address list instance
Contextconfigure service vpls string proxy-arp dynamic-arp ip-address string
Treeip-address
Introduced16.0.R1

Platforms

All

evpn
Synopsis Enter the evpn context
Context configure service vpls string proxy-arp evpn
Treeevpn
Introduced16.0.R1

Platforms

All

flood
Synopsis Enter the flood context
Context configure service vpls string proxy-arp evpn flood
Treeflood
Introduced16.0.R1

Platforms

All

route-tag number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRoute tag used on export policies to match MAC/IP routes generated by proxy-ARP or proxy-ND module
Contextconfigure service vpls string proxy-arp evpn route-tag number
Treeroute-tag
Range0 | 1 to 255
Default0
Introduced 16.0.R1

Platforms

All

send-refresh (number | keyword)
Synopsis Time at which to send a refresh message
Contextconfigure service vpls string proxy-arp send-refresh (number | keyword)
Treesend-refresh
Range120 to 86400
Optionsnever
Defaultnever
Introduced16.0.R1

Platforms

All

static-arp
Synopsis Enter the static-arp context
Context configure service vpls string proxy-arp static-arp
Treestatic-arp
Introduced16.0.R1

Platforms

All

ip-address [ipv4-address] string
Synopsis Enter the ip-address list instance
Contextconfigure service vpls string proxy-arp static-arp ip-address string
Treeip-address
Introduced16.0.R1

Platforms

All

table-size number
Synopsis Maximum number of learned and static entries allowed in the proxy table of this service
Contextconfigure service vpls string proxy-arp table-size number
Treetable-size
Range1 to 16383
Default250
Introduced 16.0.R1

Platforms

All

proxy-nd
Synopsis Enable the proxy-nd context
Context configure service vpls string proxy-nd
Treeproxy-nd
Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the proxy
Context configure service vpls string proxy-nd admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

age-time (number | keyword)
Synopsis Aging timer for proxy entries, where entries are flushed upon timer expiry
Contextconfigure service vpls string proxy-nd age-time (number | keyword)
Treeage-time
Range60 to 86400
Unitsseconds
Options never
Default never
Introduced16.0.R1

Platforms

All

duplicate-detect
Synopsis Enter the duplicate-detect context
Contextconfigure service vpls string proxy-nd duplicate-detect
Treeduplicate-detect
Introduced16.0.R1

Platforms

All

anti-spoof-mac string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMAC address to replace the proxy-ARP/ND offending entry's MAC
Contextconfigure service vpls string proxy-nd duplicate-detect anti-spoof-mac string
Treeanti-spoof-mac
Introduced16.0.R1

Platforms

All

static-blackhole boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisConsider anti-spoof MAC as black-hole static MAC in FDB
Contextconfigure service vpls string proxy-nd duplicate-detect static-blackhole boolean
Treestatic-blackhole
Defaultfalse
Introduced16.0.R1

Platforms

All

window number
Synopsis Time to monitor the MAC address in the anti-spoofing mechanism
Contextconfigure service vpls string proxy-nd duplicate-detect window number
Treewindow
Range1 to 15
Unitsminutes
Default 3
Introduced16.0.R1

Platforms

All

dynamic-neighbor
Synopsis Enter the dynamic-neighbor context
Contextconfigure service vpls string proxy-nd dynamic-neighbor
Treedynamic-neighbor
Introduced16.0.R1

Platforms

All

ip-address [ipv6-address] string
Synopsis Enter the ip-address list instance
Contextconfigure service vpls string proxy-nd dynamic-neighbor ip-address string
Treeip-address
Introduced16.0.R1

Platforms

All

evpn
Synopsis Enter the evpn context
Context configure service vpls string proxy-nd evpn
Treeevpn
Introduced16.0.R1

Platforms

All

advertise-neighbor-type keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdvertisement type of static or dynamic entries in EVPN
Contextconfigure service vpls string proxy-nd evpn advertise-neighbor-type keyword
Treeadvertise-neighbor-type

Description

This command enables the advertisement of static or dynamic entries that are learned as host, router, or host and router (only one option is possible in a specified service). It also determines the R flag (host or router) when sending Neighbor Advertisement (NA) messages for existing EVPN entries in the proxy-ND table.

The router-host command option is only possible when the ARP/ND extended community is advertised along with the MAC/IP routes. It determines that both host and router (dynamic and static) entries are advertised in MAC/IP routes, with an indication whether the entry is host or router in the R flag. These EVPN entries are installed as host or router entries depending on the R flag of the route, and NA messages for them are sent with the proper host or router indication.

Optionsrouter, host, router-host
Defaultrouter
Introduced16.0.R1

Platforms

All

flood
Synopsis Enter the flood context
Context configure service vpls string proxy-nd evpn flood
Treeflood
Introduced16.0.R1

Platforms

All

route-tag number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRoute tag used on export policies to match MAC/IP routes generated by proxy-ARP or proxy-ND module
Contextconfigure service vpls string proxy-nd evpn route-tag number
Treeroute-tag
Range0 | 1 to 255
Default0
Introduced 16.0.R1

Platforms

All

send-refresh (number | keyword)
Synopsis Time at which to send a refresh message
Contextconfigure service vpls string proxy-nd send-refresh (number | keyword)
Treesend-refresh
Range120 to 86400
Optionsnever
Defaultnever
Introduced16.0.R1

Platforms

All

static-neighbor
Synopsis Enter the static-neighbor context
Contextconfigure service vpls string proxy-nd static-neighbor
Treestatic-neighbor
Introduced16.0.R1

Platforms

All

ip-address [ipv6-address] string
Synopsis Enter the ip-address list instance
Contextconfigure service vpls string proxy-nd static-neighbor ip-address string
Treeip-address
Introduced16.0.R1

Platforms

All

table-size number
Synopsis Maximum number of learned and static entries allowed in the proxy table of this service
Contextconfigure service vpls string proxy-nd table-size number
Treetable-size
Range1 to 16383
Default250
Introduced 16.0.R1

Platforms

All

routed-vpls
Synopsis Enable the routed-vpls context
Contextconfigure service vpls string routed-vpls
Treerouted-vpls
Introduced16.0.R1

Platforms

All

multicast
Synopsis Enter the multicast context
Context configure service vpls string routed-vpls multicast
Treemulticast
Introduced16.0.R1

Platforms

All

evpn-gateway
Synopsis Enable the evpn-gateway context
Contextconfigure service vpls string routed-vpls multicast evpn-gateway
Treeevpn-gateway
Introduced21.10.R1

Platforms

All

advertise keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisType of the multicast EVPN gateway
Contextconfigure service vpls string routed-vpls multicast evpn-gateway advertise keyword
Treeadvertise

Description

This command configures EVPN OISM to advertise the type of OISM gateway function in the Inclusive Multicast Ethernet Tag routes.

Optionsmvpn-pim, mvpn-only, pim-only
Defaultmvpn-pim
Introduced21.10.R1

Platforms

All

dr-activation-timer number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDR activation timer for the EVPN gateway
Contextconfigure service vpls string routed-vpls multicast evpn-gateway dr-activation-timer number
Treedr-activation-timer

Description

This command configures the the designated router (DR) activation timer for the EVPN gateway.

After the DR activation timer expires, each provider edge router (PE) runs the MEG or PEG DR election. The timer allows the PE to collect Inclusive Multicast Ethernet Tag routes from other MEG or PEG gateways and avoids running the DR election multiple times.

Range0 to 100
Unitsseconds
Default 3
Introduced21.10.R1

Platforms

All

non-dr-attract-traffic keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMulticast traffic attraction option on non-DR router GW
Contextconfigure service vpls string routed-vpls multicast evpn-gateway non-dr-attract-traffic keyword
Treenon-dr-attract-traffic
Optionsnone, from-evpn, from-pim-mvpn, from-evpn-pim-mvpn
Defaultfrom-pim-mvpn
Introduced 21.10.R1

Platforms

All

ipv4
Synopsis Enter the ipv4 context
Context configure service vpls string routed-vpls multicast ipv4
Treeipv4
Introduced16.0.R1

Platforms

All

ipv6
Synopsis Enter the ipv6 context
Context configure service vpls string routed-vpls multicast ipv6
Treeipv6
Introduced16.0.R1

Platforms

All

sap [sap-id] string
Synopsis Enter the sap list instance
Context configure service vpls string sap string
Treesap
Introduced16.0.R1

Platforms

All

[sap-id] string
Synopsis SAP identifier
Contextconfigure service vpls string sap string
Treesap
String Length1 to 45

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the SAP
Context configure service vpls string sap string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

anti-spoof keyword
Synopsis Type of anti-spoof filtering
Context configure service vpls string sap string anti-spoof keyword
Treeanti-spoof
Optionssource-ip-addr, source-mac-addr, source-ip-and-mac-addr, next-hop-ip-and-mac-addr
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

arp-host
Synopsis Enter the arp-host context
Context configure service vpls string sap string arp-host
Treearp-host
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of ARP hosts
Context configure service vpls string sap string arp-host admin-state keyword
Treeadmin-state
Optionsenable, disable
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

host-limit number
Synopsis Maximum number of ARP triggered hosts
Contextconfigure service vpls string sap string arp-host host-limit number
Treehost-limit
Range1 to 131071
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

min-auth-interval number
Synopsis Minimum authentication interval
Context configure service vpls string sap string arp-host min-auth-interval number
Treemin-auth-interval
Range1 to 6000
Unitsminutes
Default 15
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

bandwidth number
Synopsis SAP bandwidth
Contextconfigure service vpls string sap string bandwidth number
Treebandwidth
Range1 to 6400000000
Unitskilobps
Introduced 16.0.R1

Platforms

All

bgp-vpls-mh-veid number
Synopsis BGP-VPLS multi-homing VE-ID
Context configure service vpls string sap string bgp-vpls-mh-veid number
Treebgp-vpls-mh-veid

Description

This command specifies a VE ID that is configured on SAPs that are part of an EVPN single-active Ethernet Segment. The configuration of this command allows the advertisement of L2VPN routes that indicate the state of multi-homed SAPs to the remote BGP-VPLS PEs, which can trigger a MAC flush operation on the service to avoid traffic from being blackholed when a failure occurs in the active PE.

When unconfigured from the SAP, L2VPN routes are withdrawn, which causes MAC flush processing on the remote BGP-VPLS.

Range1 to 65535
Introduced20.5.R1

Platforms

All

calling-station-id string
Synopsis Calling station ID
Context configure service vpls string sap string calling-station-id string
Treecalling-station-id
String Length1 to 64
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

cflowd boolean
Synopsis Enable Cflowd collection and analysis on this SAP
Contextconfigure service vpls string sap string cflowd boolean
Treecflowd
Defaultfalse
Introduced16.0.R1

Platforms

All

cpu-protection
Synopsis Enter the cpu-protection context
Contextconfigure service vpls string sap string cpu-protection
Treecpu-protection
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

eth-cfm-monitoring
Synopsis Enable the eth-cfm-monitoring context
Contextconfigure service vpls string sap string cpu-protection eth-cfm-monitoring
Treeeth-cfm-monitoring

Notes

The following elements are part of a choice: eth-cfm-monitoring or mac-monitoring.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

mac-monitoring
Synopsis Monitor MAC for CPU protection
Context configure service vpls string sap string cpu-protection mac-monitoring
Treemac-monitoring

Notes

The following elements are part of a choice: eth-cfm-monitoring or mac-monitoring.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

description string
Synopsis Text description
Context configure service vpls string sap string description string
Treedescription
String Length1 to 160
Introduced16.0.R1

Platforms

All

dhcp
Synopsis Enter the dhcp context
Context configure service vpls string sap string dhcp
Treedhcp
Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of DHCP
Context configure service vpls string sap string dhcp admin-state keyword
Treeadmin-state
Optionsenable, disable
Introduced 16.0.R1

Platforms

All

option-82
Synopsis Enter the option-82 context
Context configure service vpls string sap string dhcp option-82
Treeoption-82

Description

Commands in this context configure the processing required when the router receives a DHCP request that already has an Option 82 field in the packet.

Introduced16.0.R1

Platforms

All

action keyword
Synopsis Action to take with received DHCP Option 82
Contextconfigure service vpls string sap string dhcp option-82 action keyword
Treeaction
Optionsreplace, drop, keep
Defaultkeep
Introduced16.0.R1

Platforms

All

circuit-id
Synopsis Enter the circuit-id context
Context configure service vpls string sap string dhcp option-82 circuit-id
Treecircuit-id
Introduced16.0.R1

Platforms

All

ascii-tuple
Synopsis Use the ASCII-encoded tuple for the circuit ID
Contextconfigure service vpls string sap string dhcp option-82 circuit-id ascii-tuple
Treeascii-tuple

Notes

The following elements are part of a choice: ascii-tuple, hex-string, none, or vlan-ascii-tuple.

Introduced16.0.R1

Platforms

All

hex-string string
Synopsis User-defined hexadeciaml value of the option
Contextconfigure service vpls string sap string dhcp option-82 circuit-id hex-string string
Treehex-string
String Length1 to 66

Notes

The following elements are part of a choice: ascii-tuple, hex-string, none, or vlan-ascii-tuple.

Introduced16.0.R1

Platforms

All

none
Synopsis Do not include the circuit ID
Context configure service vpls string sap string dhcp option-82 circuit-id none
Treenone

Notes

The following elements are part of a choice: ascii-tuple, hex-string, none, or vlan-ascii-tuple.

Introduced16.0.R1

Platforms

All

vlan-ascii-tuple
Synopsis Include the VLAN ID and dot1p bits in the ASCII tuple
Contextconfigure service vpls string sap string dhcp option-82 circuit-id vlan-ascii-tuple
Treevlan-ascii-tuple

Description

When configured, the router includes the VLAN ID and dot1p bits with the ASCII-tuple information. This only occurs on dot1q and QinQ-encapsulated ports. When the Option 82 bits are stripped, dot1p bits are copied to the Ethernet header of the outgoing packet.

When unconfigured, the router leaves the circuit ID sub-option of the DHCP packet empty.

Notes

The following elements are part of a choice: ascii-tuple, hex-string, none, or vlan-ascii-tuple.

Introduced16.0.R1

Platforms

All

remote-id
Synopsis Enter the remote-id context
Context configure service vpls string sap string dhcp option-82 remote-id
Treeremote-id

Description

Commands in this context configure the remote IP sub-option of the DHCP packet with the identity of the remote host end (typically the DHCP client).

Introduced16.0.R1

Platforms

All

ascii-string string
Synopsis User-defined ASCII string for the remote ID
Contextconfigure service vpls string sap string dhcp option-82 remote-id ascii-string string
Treeascii-string
String Length1 to 32

Notes

The following elements are part of a choice: ascii-string, hex-string, mac, or none.

Introduced16.0.R1

Platforms

All

hex-string string
Synopsis Option as a hexadecimal string
Context configure service vpls string sap string dhcp option-82 remote-id hex-string string
Treehex-string
String Length1 to 66

Notes

The following elements are part of a choice: ascii-string, hex-string, mac, or none.

Introduced16.0.R1

Platforms

All

mac
Synopsis Use the MAC address for the remote ID
Contextconfigure service vpls string sap string dhcp option-82 remote-id mac
Treemac

Notes

The following elements are part of a choice: ascii-string, hex-string, mac, or none.

Introduced16.0.R1

Platforms

All

none
Synopsis Do not include the remote ID
Context configure service vpls string sap string dhcp option-82 remote-id none
Treenone

Notes

The following elements are part of a choice: ascii-string, hex-string, mac, or none.

Introduced16.0.R1

Platforms

All

vendor-specific-option
Synopsis Enter the vendor-specific-option context
Contextconfigure service vpls string sap string dhcp option-82 vendor-specific-option
Treevendor-specific-option

Description

Commands in this context configure the Nokia Vendor-Specific Option (VSO) of the DHCP packet.

Introduced16.0.R1

Platforms

All

proxy-server
Synopsis Enter the proxy-server context
Contextconfigure service vpls string sap string dhcp proxy-server
Treeproxy-server
Introduced16.0.R1

Platforms

All

lease-time
Synopsis Enter the lease-time context
Context configure service vpls string sap string dhcp proxy-server lease-time
Treelease-time
Introduced16.0.R1

Platforms

All

snoop boolean
Synopsis Enable DHCP snooping on the SAP
Context configure service vpls string sap string dhcp snoop boolean
Treesnoop
Defaultfalse
Introduced16.0.R1

Platforms

All

dhcp6
Synopsis Enter the dhcp6 context
Context configure service vpls string sap string dhcp6
Treedhcp6
Introduced23.10.R1

Platforms

All

ldra
Synopsis Enable the ldra context
Context configure service vpls string sap string dhcp6 ldra
Treeldra
Introduced23.10.R1

Platforms

All

interface-type keyword
Synopsis LDRA interface type
Context configure service vpls string sap string dhcp6 ldra interface-type keyword
Treeinterface-type

Description

This command specifies the LDRA interface type.

client-facing - configure the SAP as an untrusted client-facing interface. Only DHCPv6 client messages are accepted and encapsulated in a Relay-Forward message. It is mandatory to configure an interface ID for client-facing SAPs. Relay-Forward, Relay-Reply, and DHCPv6 server messages are silently dropped when received on a client-facing SAP.

network-facing - configure the SAP as a network-facing interface. Only Relay-Reply messages are accepted: the server message is extracted from the Relay-Reply message and forwarded in the VPLS. All other DHCPv6 message types are silently dropped when received on a network-facing SAP.

Optionsclient-facing, network-facing

Notes

This element is mandatory.

Introduced23.10.R1

Platforms

All

options
Synopsis Enter the options context
Context configure service vpls string sap string dhcp6 ldra options
Treeoptions
Introduced23.10.R1

Platforms

All

interface-id
Synopsis Enable the interface-id context
Contextconfigure service vpls string sap string dhcp6 ldra options interface-id
Treeinterface-id
Introduced23.10.R1

Platforms

All

ascii-tuple
Synopsis Use an ASCII-encoded concatenated tuple
Contextconfigure service vpls string sap string dhcp6 ldra options interface-id ascii-tuple
Treeascii-tuple

Description

This command specifies the use of the ASCII-encoded concatenated tuple, which consists of the system name, service ID, and SAP ID separated by "|".

Notes

The following elements are part of a mandatory choice: ascii-tuple or vlan-ascii-tuple.

Introduced23.10.R1

Platforms

All

vlan-ascii-tuple
Synopsis Use an enhanced ASCII-encoded concatenated tuple
Contextconfigure service vpls string sap string dhcp6 ldra options interface-id vlan-ascii-tuple
Treevlan-ascii-tuple

Description

This command specifies the use of the ASCII-encoded concatenated tuple enhanced with VLAN ID and dot1p bits, consisting of the system name, service ID, SAP ID, dot1p inner VLAN, and inner VLAN ID separated by "|".

Notes

The following elements are part of a mandatory choice: ascii-tuple or vlan-ascii-tuple.

Introduced23.10.R1

Platforms

All

remote-id
Synopsis Enter the remote-id context
Context configure service vpls string sap string dhcp6 ldra options remote-id
Treeremote-id

Description

Commands in this context configure the Relay-Agent remote ID contents inserted by the LDRA.

Introduced23.10.R1

Platforms

All

mac
Synopsis Use the DHCPv6 client source MAC address
Contextconfigure service vpls string sap string dhcp6 ldra options remote-id mac
Treemac

Description

This command sets the enterprise number field of the Relay Agent remote ID to 6527 and configures the DHCPv6 client source MAC address as six hexadecimal numbers.

Notes

The following elements are part of a choice: mac or string.

Introduced23.10.R1

Platforms

All

string string
Synopsis User-defined ASCII string
Context configure service vpls string sap string dhcp6 ldra options remote-id string string
Treestring

Description

This command sets the enterprise number field of the Relay-Agent remote ID to 6527 and configures the ASCII-encoded string.

String Length1 to 32

Notes

The following elements are part of a choice: mac or string.

Introduced23.10.R1

Platforms

All

egress
Synopsis Enter the egress context
Context configure service vpls string sap string egress
Treeegress
Introduced16.0.R1

Platforms

All

agg-rate
Synopsis Enter the agg-rate context
Context configure service vpls string sap string egress agg-rate
Treeagg-rate

Notes

The following elements are part of a choice: agg-rate or percent-agg-rate.

Introduced16.0.R1

Platforms

All

adaptation-rule keyword
Synopsis Adaptation rule to compute the operational PIR value when an aggregate shaper is used
Contextconfigure service vpls string sap string egress agg-rate adaptation-rule keyword
Treeadaptation-rule
Optionsmax, min, closest
Defaultclosest
Introduced22.10.R1

Platforms

7750 SR-1, 7750 SR-s

burst-limit (number | keyword)
Synopsis Shaping burst size when an aggregate shaper is used
Contextconfigure service vpls string sap string egress agg-rate burst-limit (number | keyword)
Treeburst-limit
Range1 to 14000000
Unitsbytes
Options auto
Default auto
Introduced22.10.R1

Platforms

7750 SR-1, 7750 SR-s

rate number
Synopsis Enforced aggregate rate for all queues
Contextconfigure service vpls string sap string egress agg-rate rate number
Treerate
Range1 to 6400000000
Unitskilobps
Introduced 16.0.R1

Platforms

All

filter
Synopsis Enter the filter context
Context configure service vpls string sap string egress filter
Treefilter
Introduced16.0.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service vpls string sap string egress qos
Treeqos
Introduced16.0.R1

Platforms

All

policer-control-policy
Synopsis Enter the policer-control-policy context
Contextconfigure service vpls string sap string egress qos policer-control-policy
Treepolicer-control-policy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

overrides
Synopsis Enable the overrides context
Context configure service vpls string sap string egress qos policer-control-policy overrides
Treeoverrides
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

root
Synopsis Enter the root context
Context configure service vpls string sap string egress qos policer-control-policy overrides root
Treeroot
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

priority-mbs-thresholds
Synopsis Enter the priority-mbs-thresholds context
Contextconfigure service vpls string sap string egress qos policer-control-policy overrides root priority-mbs-thresholds
Treepriority-mbs-thresholds
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

priority [priority-level] number
Synopsis Enter the priority list instance
Contextconfigure service vpls string sap string egress qos policer-control-policy overrides root priority-mbs-thresholds priority number
Treepriority
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

sap-egress
Synopsis Enter the sap-egress context
Context configure service vpls string sap string egress qos sap-egress
Treesap-egress
Introduced16.0.R1

Platforms

All

overrides
Synopsis Enter the overrides context
Context configure service vpls string sap string egress qos sap-egress overrides
Treeoverrides
Introduced16.0.R1

Platforms

All

hs-wrr-group [group-id] reference
Synopsis Enter the hs-wrr-group list instance
Contextconfigure service vpls string sap string egress qos sap-egress overrides hs-wrr-group reference
Treehs-wrr-group
Introduced16.0.R1

Platforms

7750 SR-7/12/12e

rate (number | keyword)
Synopsis Scheduling rate override applied to the HS WRR group
Contextconfigure service vpls string sap string egress qos sap-egress overrides hs-wrr-group reference rate (number | keyword)
Treerate
Range1 to 2000000000
Unitskilobps
Options max

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

7750 SR-7/12/12e

policer [policer-id] reference
Synopsis Enter the policer list instance
Contextconfigure service vpls string sap string egress qos sap-egress overrides policer reference
Treepolicer
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

cbs (number | keyword)
Synopsis CBS
Contextconfigure service vpls string sap string egress qos sap-egress overrides policer reference cbs (number | keyword)
Treecbs
Range0 to 268435456
Unitsbytes
Options auto
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

mbs (number | keyword)
Synopsis MBS
Contextconfigure service vpls string sap string egress qos sap-egress overrides policer reference mbs (number | keyword)
Treembs
Range0 to 268435456
Unitsbytes
Options auto
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service vpls string sap string egress qos sap-egress overrides policer reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

rate
Synopsis Enter the rate context
Context configure service vpls string sap string egress qos sap-egress overrides policer reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

cir (number | keyword)
Synopsis CIR rate
Contextconfigure service vpls string sap string egress qos sap-egress overrides policer reference rate cir (number | keyword)
Treecir
Range0 to 6400000000
Unitskilobps
Options max
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

pir (number | keyword)
Synopsis PIR rate
Contextconfigure service vpls string sap string egress qos sap-egress overrides policer reference rate pir (number | keyword)
Treepir
Range1 to 6400000000
Unitskilobps
Options max
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

stat-mode keyword
Synopsis Mode of statistics collected by the policer
Contextconfigure service vpls string sap string egress qos sap-egress overrides policer reference stat-mode keyword
Treestat-mode
Optionsno-stats, minimal, offered-profile-no-cir, offered-total-cir, offered-profile-cir, offered-limited-capped-cir, offered-profile-capped-cir, offered-total-cir-exceed, offered-four-profile-no-cir, offered-total-cir-four-profile
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

queue [queue-id] reference
Synopsis Enter the queue list instance
Context configure service vpls string sap string egress qos sap-egress overrides queue reference
Treequeue
Introduced16.0.R1

Platforms

All

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure service vpls string sap string egress qos sap-egress overrides queue reference adaptation-rule
Treeadaptation-rule
Introduced16.0.R1

Platforms

All

drop-tail
Synopsis Enter the drop-tail context
Context configure service vpls string sap string egress qos sap-egress overrides queue reference drop-tail
Treedrop-tail
Introduced16.0.R1

Platforms

All

low
Synopsis Enter the low context
Context configure service vpls string sap string egress qos sap-egress overrides queue reference drop-tail low
Treelow
Introduced16.0.R1

Platforms

All

hs-wred-queue
Synopsis Enter the hs-wred-queue context
Contextconfigure service vpls string sap string egress qos sap-egress overrides queue reference hs-wred-queue
Treehs-wred-queue
Introduced16.0.R1

Platforms

7750 SR-7/12/12e

monitor-queue-depth
Synopsis Enable the monitor-queue-depth context
Contextconfigure service vpls string sap string egress qos sap-egress overrides queue reference monitor-queue-depth
Treemonitor-queue-depth
Introduced20.10.R1

Platforms

All

parent
Synopsis Enter the parent context
Context configure service vpls string sap string egress qos sap-egress overrides queue reference parent
Treeparent
Introduced16.0.R1

Platforms

All

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service vpls string sap string egress qos sap-egress overrides queue reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

All

rate
Synopsis Enter the rate context
Context configure service vpls string sap string egress qos sap-egress overrides queue reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

All

port-redirect-group
Synopsis Enter the port-redirect-group context
Contextconfigure service vpls string sap string egress qos sap-egress port-redirect-group
Treeport-redirect-group
Introduced16.0.R1

Platforms

All

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service vpls string sap string egress qos scheduler-policy
Treescheduler-policy
Introduced16.0.R1

Platforms

All

overrides
Synopsis Enter the overrides context
Context configure service vpls string sap string egress qos scheduler-policy overrides
Treeoverrides
Introduced16.0.R1

Platforms

All

scheduler [scheduler-name] string
Synopsis Enter the scheduler list instance
Contextconfigure service vpls string sap string egress qos scheduler-policy overrides scheduler string
Treescheduler
Introduced16.0.R1

Platforms

All

[scheduler-name] string
Synopsis Scheduler name
Contextconfigure service vpls string sap string egress qos scheduler-policy overrides scheduler string
Treescheduler

Description

This command specifies the scheduler name which is composed of printable 7-bit ASCII characters. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes. Each scheduler must have a unique name within the context of the scheduler policy. However, the same name can be reused in multiple scheduler policies. If the scheduler name already exists within the policy tier level, the context changes to that scheduler name for the purpose of editing the scheduler commands.

If the scheduler name exists within the policy on a different tier, an error occurs and the current context does not change. If the scheduler name does not exist in this or another tier within the scheduler policy, it is assumed that an attempt is being made to create a scheduler of that name.

If the provided scheduler name is invalid, a name syntax error occurs, the command does not execute, and the context is not change.

String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

parent
Synopsis Enter the parent context
Context configure service vpls string sap string egress qos scheduler-policy overrides scheduler string parent
Treeparent
Introduced16.0.R1

Platforms

All

rate
Synopsis Enter the rate context
Context configure service vpls string sap string egress qos scheduler-policy overrides scheduler string rate
Treerate
Introduced16.0.R1

Platforms

All

virtual-port
Synopsis Enter the virtual-port context
Contextconfigure service vpls string sap string egress virtual-port
Treevirtual-port
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

eth-cfm
Synopsis Enter the eth-cfm context
Context configure service vpls string sap string eth-cfm
Treeeth-cfm
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

collect-lmm-fc-stats
Synopsis Enter the collect-lmm-fc-stats context
Contextconfigure service vpls string sap string eth-cfm collect-lmm-fc-stats
Treecollect-lmm-fc-stats

Description

Commands in this context configure per forwarding class (FC) LMM information collection.

The commands fc-in-profile and fc in this context are mutually exclusive. The commands apply to either profile-aware or profile-unaware FCs respectively. 

This command and the collect-lmm-stats command are mutually exclusive when there is entity resource contention.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fc keyword
Synopsis Forwarding class name for profile-unaware counter
Contextconfigure service vpls string sap string eth-cfm collect-lmm-fc-stats fc keyword
Treefc

Description

This command configures individual counters for the specified FCs without regard for profile. The system includes all countable packets that match a configured FC, regardless of profile, in this counter.

An FC specified as part of this command and for this specific context cannot be specified as a profile-aware FC using the fc-in-profile command under the collect-lmm-fc-stats context. 

When this command is reentered, a differential is performed. Omitted FCs stop counting, newly added FCs start counting, and unchanged FCs continue to count.

Optionsbe, l2, af, l1, h2, ef, h1, nc
Max. Instances 8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fc-in-profile keyword
Synopsis Forwarding class name for profile-aware counter
Contextconfigure service vpls string sap string eth-cfm collect-lmm-fc-stats fc-in-profile keyword
Treefc-in-profile

Description

This command configures individual counters for the specified FCs with regard to profile. The system includes all countable packets that match a configured FC and that are deemed to be in-profile in this counter.

An FC specified as part of this command and for this specific context cannot be specified as a profile-unaware FC using the fc command under the collect-lmm-fc-stats context.

When this command is reentered, a differential is performed. Omitted FCs stop counting, newly added FCs start counting, and unchanged FCs continue to count.

Optionsbe, l2, af, l1, h2, ef, h1, nc
Max. Instances 8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

collect-lmm-stats boolean
Synopsis Collect statistics for loss measurement message tests
Contextconfigure service vpls string sap string eth-cfm collect-lmm-stats boolean
Treecollect-lmm-stats
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mep md-admin-name reference ma-admin-name reference mep-id number
Synopsis Enter the mep list instance
Context configure service vpls string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number
Treemep
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

md-admin-name reference
Synopsis Maintenance Domain (MD) name
Context configure service vpls string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number
Treemep

Reference

configure eth-cfm domain string

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mep-id number
Synopsis Maintenance Endpoint (MEP) ID
Context configure service vpls string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number
Treemep
Range1 to 8191

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ais
Synopsis Enable the ais context
Context configure service vpls string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number ais
Treeais
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

alarm-notification
Synopsis Enter the alarm-notification context
Contextconfigure service vpls string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number alarm-notification
Treealarm-notification

Description

Commands in this context configure the Fault Notification Generator (FNG) time values to raise an alarm or reset the CCM defect alarm. 

Use these timers for network management processes. The timers are not tied into delaying the notification to the fault management system on the network element and do not affect fault propagation mechanisms.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ccm-padding-size number
Synopsis Number of octets of padding to insert in CCM packets
Contextconfigure service vpls string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number ccm-padding-size number
Treeccm-padding-size

Description

This command sets the byte size of the optional Data TLV to be included in the ETH-CC PDU.

This command increases the size of the ETH-CC PDU by the configured value. The base size of the ETH-CC PDU, including the Interface Status TLV and Port Status TLV, is 83 bytes not including the Layer 2 encapsulation. CCM padding is not supported when the CCM interval (configured through configure eth-cfm domain association ccm-interval) is less than 1 second.

Range3 to 1500
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

csf
Synopsis Enable the csf context
Context configure service vpls string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number csf
Treecsf
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

direction keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDirection the MEP faces
Contextconfigure service vpls string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number direction keyword
Treedirection
Optionsdown, up
Default down
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-test
Synopsis Enable the eth-test context
Context configure service vpls string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test
Treeeth-test

Description

Commands in this context configure information used by the Ethernet Test (ETH-TST) packet. The commands must be configured on both the sender and the receiver nodes. The test packets are used with the oam eth-cfm eth-test command.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

test-pattern
Synopsis Enter the test-pattern context
Contextconfigure service vpls string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test test-pattern
Treetest-pattern

Description

Commands in this context specify the test pattern for the ETH-TST frames. The pattern does not have to be the same on the sender and the receiver.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

pattern keyword
Synopsis Test pattern for Ethernet Test frames
Contextconfigure service vpls string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test test-pattern pattern keyword
Treepattern

Description

This command specifies the test pattern of the Ethernet Test (ETH-TST) frames. This does not have to be configured the same on the sender and the receiver.

Optionsall-zeros, all-ones
Default all-zeros
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

grace
Synopsis Enter the grace context
Context configure service vpls string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace
Treegrace

Description

Commands in this context configure the Nokia ETH-CFM Grace function and the ITU-T Y.1731 Ethernet Expected Default (ETH-ED) function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-ed
Synopsis Enter the eth-ed context
Context configure service vpls string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-ed
Treeeth-ed

Description

Commands in this context configure the ITU-T Y.1731 ETH-ED function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

rx-eth-ed boolean
Synopsis Receive and process ETH-ED ITU-T Y.1731 PDUs on the MEP
Contextconfigure service vpls string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-ed rx-eth-ed boolean
Treerx-eth-ed

Description

This command enables the reception and processing of the ITU-T Y.1731 ETH-ED PDU on the MEP.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-vsm-grace
Synopsis Enter the eth-vsm-grace context
Contextconfigure service vpls string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace
Treeeth-vsm-grace

Description

Commands in this context configure the Nokia ETH-CFM Grace function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

rx-eth-vsm-grace boolean
Synopsis Receive and process Nokia ETH-CFM Grace PDU on the MEP
Contextconfigure service vpls string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace rx-eth-vsm-grace boolean
Treerx-eth-vsm-grace

Description

When configured to true, the router enables the Nokia Grace function, which is a vendor-specific PDU that informs MEP peers that the local node may be entering a period of expected defect.

When configured to false, the router disables the Nokia Grace function.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

tx-eth-vsm-grace boolean
Synopsis Transmit ETH-ED PDUs from the MEP
Context configure service vpls string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace tx-eth-vsm-grace boolean
Treetx-eth-vsm-grace

Description

When configured to true, the router can transmit the Nokia ETH-CFM Grace PDU from the MEP when a system soft reset notification is received for one or more cards.

The Nokia Grace function is a vendor-specific PDU that informs MEP peers that the local node may be entering a period of expected defect.

The operator must configure the configure system eth-cfm grace command to instruct the system that the node is capable of transmitting expected-defect windows to peers. The system can only transmit one form of ETH-CFM grace (Nokia ETH-CFM Grace or ITU-T Y.1731 ETH-ED).

When configured to false, the router disables the transmission of the Nokia ETH-CFM Grace PDU from the MEP.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mac-address string
Synopsis MAC address of the MEP
Context configure service vpls string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number mac-address string
Treemac-address

Description

This command specifies the MAC address of the MEP.

When unconfigured, the MAC address of the port (if the MEP is on a SAP) or the MAC address of a bridge (if the MEP is on a spoke) is used.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

primary-vlan boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisMEP provisioned using MA primary VLAN ID
Contextconfigure service vpls string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number primary-vlan boolean
Treeprimary-vlan
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mip primary-vlan (number | keyword)
Synopsis Enter the mip list instance
Context configure service vpls string sap string eth-cfm mip primary-vlan (number | keyword)
Treemip
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

primary-vlan (number | keyword)
Synopsis VLAN ID to which the MIP is attached
Context configure service vpls string sap string eth-cfm mip primary-vlan (number | keyword)
Treemip

Description

This command provides an option for linking a MIP with a Primary VLAN number or none. When the none option is provided, the MIP does not include the primary vlan.

Range1 to 4094
Optionsnone

Notes

This element is part of a list key.

Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

cfm-vlan-tag string
Synopsis VLAN tags to apply to CFM PDUs for egress processing
Contextconfigure service vpls string sap string eth-cfm mip primary-vlan (number | keyword) cfm-vlan-tag string
Treecfm-vlan-tag

Description

This command allows the CFM function to include additional VLAN tags to the CFM packet that are carried to the egress and treated as service delimited. Typically, this function is used to influence the VLAN carried over a binding that uses the vc-type vlan or the binding forces the use of one or more VLAN tag that results in a mismatch between the service data arriving at the binding and the locally generated ETH-CFM PDUs arriving at the same egress. When this command is included under the MEP or MIP configuration, the tags used as part of the configuration typically match the SAP service delimited configuration.

String Length1 to 9
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

squelch-ingress-ctag-levels number
Synopsis Squelch levels using additional VLAN C-Tag space
Contextconfigure service vpls string sap string eth-cfm squelch-ingress-ctag-levels number
Treesquelch-ingress-ctag-levels

Description

This command defines the levels of the ETH-CFM packets that are silently discarded on ingress into the SAP or SDP binding from the wire that matches the service delineation of the SAP or SDP binding plus an additional VLAN, up to a maximum tag length of two tags. All ETH-CFM packets inbound to the SAP or SDP binding that match the configured levels are dropped without regard for any other ETH-CFM criteria. No statistical information or drop count is available for any ETH-CFM packet that is silently discarded by this option.

The list of levels must be a complete contiguous list from 0 up to the highest level to be dropped.

Range0 to 7
Max. Instances8
Introduced 21.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

squelch-ingress-levels number
Synopsis Levels for which ETH-CFM packets are silently discarded
Contextconfigure service vpls string sap string eth-cfm squelch-ingress-levels number
Treesquelch-ingress-levels

Description

This command defines the levels of the ETH-CFM packets that are silently discarded on ingress into the SAP or SDP binding from the wire that matches the service delineation of the SAP or SDP binding. All ETH-CFM packets inbound to the SAP or SDP binding that match the configured levels are dropped without regard for any other ETH-CFM criteria. No statistical information or drop count is available for any ETH-CFM packet that is silently discarded by this option.

The list of levels must be a complete contiguous list from 0 up to the highest level that will be dropped.

Range0 to 7
Max. Instances8
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

vmep-filter boolean
Synopsis Suppress eth-cfm PDUs based on level lower than or equal to configured Virtual MEP
Contextconfigure service vpls string sap string eth-cfm vmep-filter boolean
Treevmep-filter
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-ring number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEthernet ring operation
Contextconfigure service vpls string sap string eth-ring number
Treeeth-ring
Range1 to 128
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

etree-leaf boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEnable etree leaf access-circuit status
Contextconfigure service vpls string sap string etree-leaf boolean
Treeetree-leaf
Defaultfalse
Introduced16.0.R1

Platforms

All

etree-root-leaf-tag
Synopsis Enable the etree-root-leaf-tag context
Contextconfigure service vpls string sap string etree-root-leaf-tag
Treeetree-root-leaf-tag
Introduced16.0.R1

Platforms

All

leaf number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisLeaf tag value
Contextconfigure service vpls string sap string etree-root-leaf-tag leaf number
Treeleaf
Range1 to 4094

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

fdb
Synopsis Enter the fdb context
Context configure service vpls string sap string fdb
Treefdb
Introduced16.0.R1

Platforms

All

auto-learn-mac-protect-exclude-list reference
Synopsis Referenced MAC protect exclusion list
Contextconfigure service vpls string sap string fdb auto-learn-mac-protect-exclude-list reference
Treeauto-learn-mac-protect-exclude-list

Description

This command references the name of a MAC protect exclusion list.

Dynamically-learned MAC Source Addresses (SA) are protected if they are learned on an object with ALMP configured and no exclusion list is associated with the object, or if the MAC SA does not match any entry in an associated exclusion list.

An exclusion list can be used in multiple objects of a service. If a list is empty, ALMP does not exclude any learned MAC SAs from protection on the object.

Reference

configure service mac-list string

Introduced20.5.R1

Platforms

All

mac-learning
Synopsis Enter the mac-learning context
Contextconfigure service vpls string sap string fdb mac-learning
Treemac-learning
Introduced16.0.R1

Platforms

All

mac-pinning boolean
Synopsis Enable MAC address pinning on this SAP
Contextconfigure service vpls string sap string fdb mac-pinning boolean
Treemac-pinning
Defaultfalse
Introduced16.0.R1

Platforms

All

maximum-mac-addresses number
Synopsis Maximum number of MAC address entries in the FDB
Contextconfigure service vpls string sap string fdb maximum-mac-addresses number
Treemaximum-mac-addresses

Description

This command specifies the maximum number of FDB entries for both learned and static MAC addresses for this SAP.

When the configured limit is reached, no new addresses are learned from the SAP or spoke SDP until at least one FDB entry is aged out or cleared.

When the configured limit is reached and the configure service pw-template fdb discard-unknown-source command is set to true for this SAP, packets with unknown source MAC addresses are discarded. If discard-unknown-source is set to false, the packets are forwarded if their destination MAC addresses are known, or flooded if their destination MAC addresses are unknown.

However, if the configure service vpls fdb discard-unknown command is set to true, packets with unknown destination MAC addresses are discarded, even if the limit of FDB entries on the specific VPLS instance is not reached.

When unconfigured, the SAP uses the global MAC learning limitations.

Range1 to 511999
Introduced16.0.R1

Platforms

All

host-admin-state keyword
Synopsis Administrative state of the hosts
Context configure service vpls string sap string host-admin-state keyword
Treehost-admin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

i-vpls-mac-flush
Synopsis Enter the i-vpls-mac-flush context
Contextconfigure service vpls string sap string i-vpls-mac-flush
Treei-vpls-mac-flush
Introduced16.0.R1

Platforms

All

igmp-host-tracking
Synopsis Enter the igmp-host-tracking context
Contextconfigure service vpls string sap string igmp-host-tracking
Treeigmp-host-tracking
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

expiry-time number
Synopsis Time that the system continues to track inactive hosts
Contextconfigure service vpls string sap string igmp-host-tracking expiry-time number
Treeexpiry-time
Range1 to 65535
Unitsseconds
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

igmp-snooping
Synopsis Enter the igmp-snooping context
Contextconfigure service vpls string sap string igmp-snooping
Treeigmp-snooping
Introduced16.0.R1

Platforms

All

mcac
Synopsis Enter the mcac context
Context configure service vpls string sap string igmp-snooping mcac
Treemcac
Introduced16.0.R1

Platforms

All

bandwidth
Synopsis Enter the bandwidth context
Context configure service vpls string sap string igmp-snooping mcac bandwidth
Treebandwidth
Introduced16.0.R1

Platforms

All

mandatory (number | keyword)
Synopsis Pre-reserved bandwidth for all mandatory channels
Contextconfigure service vpls string sap string igmp-snooping mcac bandwidth mandatory (number | keyword)
Treemandatory
Range0 to 2147483647
Optionsunlimited
Defaultunlimited
Introduced16.0.R1

Platforms

All

total (number | keyword)
Synopsis Maximum allowed bandwidth
Context configure service vpls string sap string igmp-snooping mcac bandwidth total (number | keyword)
Treetotal
Range0 to 2147483647
Optionsunlimited
Defaultunlimited
Introduced16.0.R1

Platforms

All

mc-constraints
Synopsis Enter the mc-constraints context
Contextconfigure service vpls string sap string igmp-snooping mcac mc-constraints
Treemc-constraints
Introduced16.0.R1

Platforms

All

level [level-id] number
Synopsis Enter the level list instance
Context configure service vpls string sap string igmp-snooping mcac mc-constraints level number
Treelevel
Introduced16.0.R1

Platforms

All

number-down [number-lag-port-down] number
Synopsis Enter the number-down list instance
Contextconfigure service vpls string sap string igmp-snooping mcac mc-constraints number-down number
Treenumber-down
Introduced16.0.R1

Platforms

All

level number
Synopsis Level ID to associate with number of down LAG ports
Contextconfigure service vpls string sap string igmp-snooping mcac mc-constraints number-down number level number
Treelevel

Description

This command specifies the bandwidth for a given level. Level 1 has the highest priority and level 8 has the lowest priority.

Range1 to 8

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

use-lag-port-weight boolean
Synopsis Use LAG port weight in calculating MCAC constraints
Contextconfigure service vpls string sap string igmp-snooping mcac mc-constraints use-lag-port-weight boolean
Treeuse-lag-port-weight

Description

When configured to true, port weight is used when determining available bandwidth per level when LAG ports go down or come up. This command is required for proper operation on mixed port-speed LAGs and can also be used for unmixed port-speed LAGs.

Defaultfalse
Introduced16.0.R1

Platforms

All

policy reference
Synopsis Multicast CAC policy name
Context configure service vpls string sap string igmp-snooping mcac policy reference
Treepolicy

Description

This command configures the name of the global channel bandwidth definition policy that is used for (H)MCAC and HQoS adjustment.

Within the scope of HQoS adjustment, the channel definition policy under the group interface is used if redirection is unconfigured. In this case, the HQoS adjustment can be applied to IPoE subscribers in per-SAP replication mode.

If redirection is configured, the channel bandwidth definition policy applied under the Layer 3 redirected interface is in effect.

Hierarchical MCAC (HMCAC) is supported on two levels simultaneously:

  • subscriber level and redirected interface when redirection is configured

  • subscriber level and group-interface level when redirection is unconfigured

In HMCAC, the subscriber is checked against its bandwidth limits first, then against the bandwidth limits of the redirected or group interface. If redirection is configured but the policy is referenced only under the group interface, no admission control is executed (HMCAC or MCAC).

Reference

configure mcac policy string

Introduced16.0.R1

Platforms

All

mvr
Synopsis Enter the mvr context
Context configure service vpls string sap string igmp-snooping mvr
Treemvr
Introduced16.0.R1

Platforms

All

static
Synopsis Enter the static context
Context configure service vpls string sap string igmp-snooping static
Treestatic
Introduced16.0.R1

Platforms

All

group [group-address] string
Synopsis Enter the group list instance
Context configure service vpls string sap string igmp-snooping static group string
Treegroup
Introduced16.0.R1

Platforms

All

[group-address] string
Synopsis Group address of static IGMP multicast channel
Contextconfigure service vpls string sap string igmp-snooping static group string
Treegroup

Description

This command configures an address that receives data on an interface. The IP address must be unique for each static group.

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

source [source-address] string
Synopsis Add a list entry for source
Context configure service vpls string sap string igmp-snooping static group string source string
Treesource

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced16.0.R1

Platforms

All

[source-address] string
Synopsis Source IP address of multicast channel sending data
Contextconfigure service vpls string sap string igmp-snooping static group string source string
Treesource

Notes

This element is part of a list key.

Introduced16.0.R2

Platforms

All

starg
Synopsis any source address (*,G)
Context configure service vpls string sap string igmp-snooping static group string starg
Treestarg

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced16.0.R2

Platforms

All

ingress
Synopsis Enter the ingress context
Context configure service vpls string sap string ingress
Treeingress
Introduced16.0.R1

Platforms

All

filter
Synopsis Enter the filter context
Context configure service vpls string sap string ingress filter
Treefilter
Introduced16.0.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service vpls string sap string ingress qos
Treeqos
Introduced16.0.R1

Platforms

All

policer-control-policy
Synopsis Enter the policer-control-policy context
Contextconfigure service vpls string sap string ingress qos policer-control-policy
Treepolicer-control-policy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

overrides
Synopsis Enable the overrides context
Context configure service vpls string sap string ingress qos policer-control-policy overrides
Treeoverrides
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

root
Synopsis Enter the root context
Context configure service vpls string sap string ingress qos policer-control-policy overrides root
Treeroot
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

priority-mbs-thresholds
Synopsis Enter the priority-mbs-thresholds context
Contextconfigure service vpls string sap string ingress qos policer-control-policy overrides root priority-mbs-thresholds
Treepriority-mbs-thresholds
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

priority [priority-level] number
Synopsis Enter the priority list instance
Contextconfigure service vpls string sap string ingress qos policer-control-policy overrides root priority-mbs-thresholds priority number
Treepriority
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

sap-ingress
Synopsis Enter the sap-ingress context
Context configure service vpls string sap string ingress qos sap-ingress
Treesap-ingress
Introduced16.0.R1

Platforms

All

fp-redirect-group
Synopsis Enter the fp-redirect-group context
Contextconfigure service vpls string sap string ingress qos sap-ingress fp-redirect-group
Treefp-redirect-group
Introduced16.0.R1

Platforms

All

overrides
Synopsis Enter the overrides context
Context configure service vpls string sap string ingress qos sap-ingress overrides
Treeoverrides
Introduced16.0.R1

Platforms

All

ip-criteria
Synopsis Enter the ip-criteria context
Context configure service vpls string sap string ingress qos sap-ingress overrides ip-criteria
Treeip-criteria
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ipv6-criteria
Synopsis Enter the ipv6-criteria context
Contextconfigure service vpls string sap string ingress qos sap-ingress overrides ipv6-criteria
Treeipv6-criteria
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

policer [policer-id] reference
Synopsis Enter the policer list instance
Contextconfigure service vpls string sap string ingress qos sap-ingress overrides policer reference
Treepolicer
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

cbs (number | keyword)
Synopsis CBS
Contextconfigure service vpls string sap string ingress qos sap-ingress overrides policer reference cbs (number | keyword)
Treecbs
Range0 to 268435456
Unitsbytes
Options auto
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

mbs (number | keyword)
Synopsis MBS
Contextconfigure service vpls string sap string ingress qos sap-ingress overrides policer reference mbs (number | keyword)
Treembs
Range0 to 268435456
Unitsbytes
Options auto
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service vpls string sap string ingress qos sap-ingress overrides policer reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

rate
Synopsis Enter the rate context
Context configure service vpls string sap string ingress qos sap-ingress overrides policer reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

stat-mode keyword
Synopsis Mode of statistics collected by the policer
Contextconfigure service vpls string sap string ingress qos sap-ingress overrides policer reference stat-mode keyword
Treestat-mode
Optionsno-stats, minimal, offered-profile-no-cir, offered-total-cir, offered-priority-no-cir, offered-profile-cir, offered-priority-cir, offered-limited-profile-cir, offered-profile-capped-cir, offered-limited-capped-cir
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

queue [queue-id] reference
Synopsis Enter the queue list instance
Context configure service vpls string sap string ingress qos sap-ingress overrides queue reference
Treequeue
Introduced16.0.R1

Platforms

All

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure service vpls string sap string ingress qos sap-ingress overrides queue reference adaptation-rule
Treeadaptation-rule
Introduced16.0.R1

Platforms

All

drop-tail
Synopsis Enter the drop-tail context
Context configure service vpls string sap string ingress qos sap-ingress overrides queue reference drop-tail
Treedrop-tail
Introduced16.0.R1

Platforms

All

low
Synopsis Enter the low context
Context configure service vpls string sap string ingress qos sap-ingress overrides queue reference drop-tail low
Treelow
Introduced16.0.R1

Platforms

All

monitor-queue-depth
Synopsis Enable the monitor-queue-depth context
Contextconfigure service vpls string sap string ingress qos sap-ingress overrides queue reference monitor-queue-depth
Treemonitor-queue-depth
Introduced21.7.R1

Platforms

All

parent
Synopsis Enter the parent context
Context configure service vpls string sap string ingress qos sap-ingress overrides queue reference parent
Treeparent
Introduced16.0.R1

Platforms

All

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service vpls string sap string ingress qos sap-ingress overrides queue reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

All

rate
Synopsis Enter the rate context
Context configure service vpls string sap string ingress qos sap-ingress overrides queue reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

All

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service vpls string sap string ingress qos scheduler-policy
Treescheduler-policy
Introduced16.0.R1

Platforms

All

overrides
Synopsis Enter the overrides context
Context configure service vpls string sap string ingress qos scheduler-policy overrides
Treeoverrides
Introduced16.0.R1

Platforms

All

scheduler [scheduler-name] string
Synopsis Enter the scheduler list instance
Contextconfigure service vpls string sap string ingress qos scheduler-policy overrides scheduler string
Treescheduler
Introduced16.0.R1

Platforms

All

[scheduler-name] string
Synopsis Scheduler name
Contextconfigure service vpls string sap string ingress qos scheduler-policy overrides scheduler string
Treescheduler

Description

This command specifies the scheduler name which is composed of printable 7-bit ASCII characters. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes. Each scheduler must have a unique name within the context of the scheduler policy. However, the same name can be reused in multiple scheduler policies. If the scheduler name already exists within the policy tier level, the context changes to that scheduler name for the purpose of editing the scheduler commands.

If the scheduler name exists within the policy on a different tier, an error occurs and the current context does not change. If the scheduler name does not exist in this or another tier within the scheduler policy, it is assumed that an attempt is being made to create a scheduler of that name.

If the provided scheduler name is invalid, a name syntax error occurs, the command does not execute, and the context is not change.

String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

parent
Synopsis Enter the parent context
Context configure service vpls string sap string ingress qos scheduler-policy overrides scheduler string parent
Treeparent
Introduced16.0.R1

Platforms

All

rate
Synopsis Enter the rate context
Context configure service vpls string sap string ingress qos scheduler-policy overrides scheduler string rate
Treerate
Introduced16.0.R1

Platforms

All

qtag-manipulation
Synopsis Enter the qtag-manipulation context
Contextconfigure service vpls string sap string ingress qtag-manipulation
Treeqtag-manipulation
Introduced16.0.R1

Platforms

All

c-tag (number | keyword)
Synopsis Inner ingress vlan translation for two service delimiting vlan values
Contextconfigure service vpls string sap string ingress qtag-manipulation c-tag (number | keyword)
Treec-tag
Range0 to 4094
Optionstag-*

Notes

The following elements are part of a choice: push-dot1q-vlan or (c-tag and s-tag).

Introduced22.10.R1

Platforms

All

push-dot1q-vlan (number | keyword)
Synopsis VLAN translation information
Context configure service vpls string sap string ingress qtag-manipulation push-dot1q-vlan (number | keyword)
Treepush-dot1q-vlan
Range0 to 4094
Optionsuse-sap-svlan

Notes

The following elements are part of a choice: push-dot1q-vlan or (c-tag and s-tag).

Introduced16.0.R1

Platforms

All

s-tag number
Synopsis Outer ingress VLAN translation for two service delimiting VLAN values
Contextconfigure service vpls string sap string ingress qtag-manipulation s-tag number
Trees-tag
Range0 to 4094

Notes

The following elements are part of a choice: push-dot1q-vlan or (c-tag and s-tag).

Introduced22.10.R1

Platforms

All

l2pt
Synopsis Enter the l2pt context
Context configure service vpls string sap string l2pt
Treel2pt
Introduced16.0.R1

Platforms

All

force-boundary
Synopsis Enable the force-boundary context
Contextconfigure service vpls string sap string l2pt force-boundary
Treeforce-boundary
Introduced16.0.R1

Platforms

All

protocols
Synopsis Enter the protocols context
Context configure service vpls string sap string l2pt force-boundary protocols
Treeprotocols
Introduced16.0.R1

Platforms

All

termination
Synopsis Enable the termination context
Contextconfigure service vpls string sap string l2pt termination
Treetermination
Introduced16.0.R1

Platforms

All

protocols
Synopsis Enter the protocols context
Context configure service vpls string sap string l2pt termination protocols
Treeprotocols
Introduced16.0.R1

Platforms

All

l2tpv3-session
Synopsis Enable the l2tpv3-session context
Contextconfigure service vpls string sap string l2tpv3-session
Treel2tpv3-session
Introduced16.0.R4

Platforms

All

pseudo-wire
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the pseudo-wire context
Contextconfigure service vpls string sap string l2tpv3-session pseudo-wire
Treepseudo-wire
Introduced16.0.R4

Platforms

All

ethernet
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the Ethernet PW-type for the L2TPv3 session
Contextconfigure service vpls string sap string l2tpv3-session pseudo-wire ethernet
Treeethernet

Notes

The following elements are part of a choice: ethernet or ethernet-vlan-id.

Introduced16.0.R4

Platforms

All

ethernet-vlan-id number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEthernet-VLAN PW-type ID for the L2TPv3 session
Contextconfigure service vpls string sap string l2tpv3-session pseudo-wire ethernet-vlan-id number
Treeethernet-vlan-id
Range0 to 4095

Notes

The following elements are part of a choice: ethernet or ethernet-vlan-id.

Introduced16.0.R4

Platforms

All

router
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the router context
Contextconfigure service vpls string sap string l2tpv3-session router
Treerouter
Introduced16.0.R4

Platforms

All

group string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTunnel group name
Contextconfigure service vpls string sap string l2tpv3-session router group string
Treegroup
String Length1 to 32
Introduced16.0.R4

Platforms

All

router-instance string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRouter name used to identify the router instance
Contextconfigure service vpls string sap string l2tpv3-session router router-instance string
Treerouter-instance
String Length1 to 64
Introduced16.0.R4

Platforms

All

vc-id number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisVC ID for the L2TPv3 session
Contextconfigure service vpls string sap string l2tpv3-session vc-id number
Treevc-id
Range1 to 4294967295
Introduced16.0.R4

Platforms

All

lag
Synopsis Enter the lag context
Context configure service vpls string sap string lag
Treelag
Introduced16.0.R1

Platforms

All

link-map-profile number
Synopsis LAG link map profile for a SAP or network interface
Contextconfigure service vpls string sap string lag link-map-profile number
Treelink-map-profile

Description

This command assigns a preconfigured LAG link map profile to a SAP or network interface configured on a LAG or a PW port that exists on a LAG. After an operator assigns a LAG link map profile, the system rehashes the SAP or network interface egress traffic over the LAG as required by the new configuration.

If the LAG link map profile for a SAP or network interface is deleted, the system reverts back to per-flow hashing.

Range1 to 64
Introduced16.0.R1

Platforms

All

per-link-hash
Synopsis Enter the per-link-hash context
Contextconfigure service vpls string sap string lag per-link-hash
Treeper-link-hash
Introduced16.0.R1

Platforms

All

class number
Synopsis Class used on LAG egress using weighted per-link-hash
Contextconfigure service vpls string sap string lag per-link-hash class number
Treeclass
Range1 to 3
Default1
Introduced 16.0.R1

Platforms

All

weight number
Synopsis Weight used on LAG egress using weighted per-link-hash
Contextconfigure service vpls string sap string lag per-link-hash weight number
Treeweight
Range1 to 1024
Default1
Introduced 16.0.R1

Platforms

All

managed-vlan-list
Synopsis Enter the managed-vlan-list context
Contextconfigure service vpls string sap string managed-vlan-list
Treemanaged-vlan-list
Introduced19.10.R1

Platforms

All

mc-ring
Synopsis Enable the mc-ring context
Context configure service vpls string sap string mc-ring
Treemc-ring
Introduced16.0.R1

Platforms

All

ring-node string
Synopsis Name for the ring node associated with this SAP
Contextconfigure service vpls string sap string mc-ring ring-node string
Treering-node
String Length1 to 32

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

mld-snooping
Synopsis Enter the mld-snooping context
Contextconfigure service vpls string sap string mld-snooping
Treemld-snooping
Introduced16.0.R1

Platforms

All

mvr
Synopsis Enter the mvr context
Context configure service vpls string sap string mld-snooping mvr
Treemvr
Introduced16.0.R1

Platforms

All

to-sap string
Synopsis SAP to which the multicast channels are copied
Contextconfigure service vpls string sap string mld-snooping mvr to-sap string
Treeto-sap
String Length1 to 45
Introduced16.0.R1

Platforms

All

static
Synopsis Enter the static context
Context configure service vpls string sap string mld-snooping static
Treestatic
Introduced16.0.R1

Platforms

All

group [group-address] string
Synopsis Enter the group list instance
Context configure service vpls string sap string mld-snooping static group string
Treegroup
Introduced16.0.R1

Platforms

All

[group-address] string
Synopsis Group address of multicast channel
Context configure service vpls string sap string mld-snooping static group string
Treegroup

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

source [source-address] string
Synopsis Add a list entry for source
Context configure service vpls string sap string mld-snooping static group string source string
Treesource

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced16.0.R1

Platforms

All

starg
Synopsis any source address (*,G)
Context configure service vpls string sap string mld-snooping static group string starg
Treestarg

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced16.0.R2

Platforms

All

version keyword
Synopsis Version of MLD running on the SAP or SDP
Contextconfigure service vpls string sap string mld-snooping version keyword
Treeversion
Options1, 2
Default 2
Introduced16.0.R1

Platforms

All

mrp
Synopsis Enter the mrp context
Context configure service vpls string sap string mrp
Treemrp
Introduced20.10.R1

Platforms

All

join-time number
Synopsis Interval between transmit opportunities
Contextconfigure service vpls string sap string mrp join-time number
Treejoin-time
Range1 to 10
Default2
Introduced 20.10.R1

Platforms

All

leave-all-time number
Synopsis Frequency that LeaveAll PDUs are generated
Contextconfigure service vpls string sap string mrp leave-all-time number
Treeleave-all-time
Range60 to 300
Default100
Introduced 20.10.R1

Platforms

All

leave-time number
Synopsis Time in leave state before transitioning to MT state
Contextconfigure service vpls string sap string mrp leave-time number
Treeleave-time
Range30 to 60
Default30
Introduced 20.10.R1

Platforms

All

periodic-time number
Synopsis Frequency of periodic events generation
Contextconfigure service vpls string sap string mrp periodic-time number
Treeperiodic-time
Range10 to 100
Default10
Introduced 20.10.R1

Platforms

All

oper-group reference
Synopsis Operational group
Context configure service vpls string sap string oper-group reference
Treeoper-group

Reference

configure service oper-group string

Notes

The following elements are part of a choice: monitor-oper-group or oper-group.

Introduced16.0.R1

Platforms

All

pbb
Synopsis Enter the pbb context
Context configure service vpls string sap string pbb
Treepbb
Introduced20.10.R1

Platforms

All

fault-propagation
Synopsis Enter the fault-propagation context
Contextconfigure service vpls string sap string pbb fault-propagation
Treefault-propagation
Introduced20.10.R1

Platforms

All

backbone-mac-name [name] reference
Synopsis Add a list entry for backbone-mac-name
Contextconfigure service vpls string sap string pbb fault-propagation backbone-mac-name reference
Treebackbone-mac-name
Introduced20.10.R1

Platforms

All

spb
Synopsis Enable the spb context
Context configure service vpls string sap string spb
Treespb
Introduced21.10.R1

Platforms

All

admin-state keyword
Synopsis Admin state
Contextconfigure service vpls string sap string spb admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced21.10.R1

Platforms

All

level [id] number
Synopsis Enter the level list instance
Context configure service vpls string sap string spb level number
Treelevel
Introduced21.10.R1

Platforms

All

[id] number
Synopsis Level identifier
Context configure service vpls string sap string spb level number
Treelevel
Range1

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

All

metric number
Synopsis Metric
Contextconfigure service vpls string sap string spb level number metric number
Treemetric
Range0 to 16777215
Default0
Introduced 21.10.R1

Platforms

All

static-host
Synopsis Enter the static-host context
Context configure service vpls string sap string static-host
Treestatic-host
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv4 [ip] string mac string
Synopsis Enter the ipv4 list instance
Context configure service vpls string sap string static-host ipv4 string mac string
Treeipv4
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[ip] string
Synopsis IP address
Contextconfigure service vpls string sap string static-host ipv4 string mac string
Treeipv4
MD-CLI Default0.0.0.0

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

mac string
Synopsis MAC address
Contextconfigure service vpls string sap string static-host ipv4 string mac string
Treeipv4
MD-CLI Default00:00:00:00:00:00

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the static host
Contextconfigure service vpls string sap string static-host ipv4 string mac string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

app-profile
Synopsis Enter the app-profile context
Context configure service vpls string sap string static-host ipv4 string mac string app-profile
Treeapp-profile
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

int-dest-id string
Synopsis Intermediate destination ID
Context configure service vpls string sap string static-host ipv4 string mac string int-dest-id string
Treeint-dest-id
String Length1 to 32
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

shcv
Synopsis Enter the shcv context
Context configure service vpls string sap string static-host ipv4 string mac string shcv
Treeshcv
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

subscriber-id
Synopsis Enter the subscriber-id context
Contextconfigure service vpls string sap string static-host ipv4 string mac string subscriber-id
Treesubscriber-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

string string
Synopsis Subscriber identification
Context configure service vpls string sap string static-host ipv4 string mac string subscriber-id string string
Treestring
String Length1 to 64

Notes

The following elements are part of a choice: string or use-sap-id.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

use-sap-id
Synopsis Use the SAP id as subscriber ID
Context configure service vpls string sap string static-host ipv4 string mac string subscriber-id use-sap-id
Treeuse-sap-id

Notes

The following elements are part of a choice: string or use-sap-id.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

static-isid
Synopsis Enter the static-isid context
Context configure service vpls string sap string static-isid
Treestatic-isid
Introduced19.10.R1

Platforms

All

range [range-id] number
Synopsis Enter the range list instance
Context configure service vpls string sap string static-isid range number
Treerange
Introduced19.10.R1

Platforms

All

[range-id] number
Synopsis Range ID for static ISID
Context configure service vpls string sap string static-isid range number
Treerange
Range1 to 8191

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

end number
Synopsis Upper bound of the ISID range
Context configure service vpls string sap string static-isid range number end number
Treeend
Range1 to 16777215
Introduced19.10.R1

Platforms

All

stp
Synopsis Enter the stp context
Context configure service vpls string sap string stp
Treestp
Introduced16.0.R4

Platforms

All

admin-state keyword
Synopsis Administrative state of STP
Context configure service vpls string sap string stp admin-state keyword
Treeadmin-state
Optionsenable, disable
Introduced 16.0.R4

Platforms

All

auto-edge boolean
Synopsis Enable automatic detection of edge port characteristics
Contextconfigure service vpls string sap string stp auto-edge boolean
Treeauto-edge
Defaulttrue
Introduced16.0.R4

Platforms

All

edge-port boolean
Synopsis Designate SAP or SDP as an edge port
Context configure service vpls string sap string stp edge-port boolean
Treeedge-port
Defaultfalse
Introduced16.0.R4

Platforms

All

link-type keyword
Synopsis Configure STP link-type
Context configure service vpls string sap string stp link-type keyword
Treelink-type
Optionspt-pt, shared
Default pt-pt
Introduced16.0.R4

Platforms

All

mst-instance [mst-inst-number] number
Synopsis Enter the mst-instance list instance
Contextconfigure service vpls string sap string stp mst-instance number
Treemst-instance
Introduced19.10.R1

Platforms

All

[mst-inst-number] number
Synopsis Multiple Spanning Tree Instance number
Contextconfigure service vpls string sap string stp mst-instance number
Treemst-instance
Range1 to 4094

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

path-cost number
Synopsis Configure path-cost
Context configure service vpls string sap string stp path-cost number
Treepath-cost
Range1 to 200000000
Default10
Introduced 16.0.R4

Platforms

All

port-num number
Synopsis Configure virtual port number
Context configure service vpls string sap string stp port-num number
Treeport-num
Range1 to 2047
Introduced16.0.R4

Platforms

All

priority number
Synopsis Configure STP priority
Context configure service vpls string sap string stp priority number
Treepriority
Range0 to 255
Default128
Introduced 16.0.R4

Platforms

All

root-guard boolean
Synopsis Enable/disable STP root-guard
Context configure service vpls string sap string stp root-guard boolean
Treeroot-guard
Defaultfalse
Introduced16.0.R4

Platforms

All

sub-sla-mgmt
Synopsis Enter the sub-sla-mgmt context
Contextconfigure service vpls string sap string sub-sla-mgmt
Treesub-sla-mgmt
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of SAP subscriber management
Contextconfigure service vpls string sap string sub-sla-mgmt admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

defaults
Synopsis Enter the defaults context
Context configure service vpls string sap string sub-sla-mgmt defaults
Treedefaults
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

int-dest-id
Synopsis Enter the int-dest-id context
Context configure service vpls string sap string sub-sla-mgmt defaults int-dest-id
Treeint-dest-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

string string
Synopsis Use the configured string
Context configure service vpls string sap string sub-sla-mgmt defaults int-dest-id string string
Treestring
String Length1 to 32

Notes

The following elements are part of a choice: string or top-q-tag.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

subscriber-id
Synopsis Enter the subscriber-id context
Contextconfigure service vpls string sap string sub-sla-mgmt defaults subscriber-id
Treesubscriber-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

auto-id
Synopsis Use auto-generated subscriber identification string
Contextconfigure service vpls string sap string sub-sla-mgmt defaults subscriber-id auto-id
Treeauto-id

Notes

The following elements are part of a choice: auto-id, sap-id, or string.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

sap-id
Synopsis Use SAP ID as default subscriber identification string
Contextconfigure service vpls string sap string sub-sla-mgmt defaults subscriber-id sap-id
Treesap-id

Notes

The following elements are part of a choice: auto-id, sap-id, or string.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

string string
Synopsis Default subscriber identification string for the SAP
Contextconfigure service vpls string sap string sub-sla-mgmt defaults subscriber-id string string
Treestring
String Length1 to 64

Notes

The following elements are part of a choice: auto-id, sap-id, or string.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

mac-da-hashing boolean
Synopsis Use destination MAC address instead of subscriber ID to select egress LAG link
Contextconfigure service vpls string sap string sub-sla-mgmt mac-da-hashing boolean
Treemac-da-hashing
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

single-sub-parameters
Synopsis Enter the single-sub-parameters context
Contextconfigure service vpls string sap string sub-sla-mgmt single-sub-parameters
Treesingle-sub-parameters
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

non-sub-traffic
Synopsis Enable the non-sub-traffic context
Contextconfigure service vpls string sap string sub-sla-mgmt single-sub-parameters non-sub-traffic
Treenon-sub-traffic
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

subscriber-limit (keyword | number)
Synopsis Maximum number of subscribers on this SAP
Contextconfigure service vpls string sap string sub-sla-mgmt subscriber-limit (keyword | number)
Treesubscriber-limit
Range1 to 131071
Optionsno-limit
Default1
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

transit-policy
Synopsis Enable the transit-policy context
Contextconfigure service vpls string sap string transit-policy
Treetransit-policy
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP transit policy ID
Contextconfigure service vpls string sap string transit-policy ip reference
Treeip

Reference

configure application-assurance group number partition number transit-ip-policy number

Notes

The following elements are part of a mandatory choice: ip or prefix.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

prefix reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP prefix policy ID
Contextconfigure service vpls string sap string transit-policy prefix reference
Treeprefix

Reference

configure application-assurance group number partition number transit-prefix-policy number

Notes

The following elements are part of a mandatory choice: ip or prefix.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

segment-routing-v6 [instance] number
Synopsis Enter the segment-routing-v6 list instance
Contextconfigure service vpls string segment-routing-v6 number
Treesegment-routing-v6
Max. Instances1
Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

[instance] number
Synopsis Segment routing v6 instance
Context configure service vpls string segment-routing-v6 number
Treesegment-routing-v6
Range1

Notes

This element is part of a list key.

Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

locator [locator-name] reference
Synopsis Enter the locator list instance
Contextconfigure service vpls string segment-routing-v6 number locator reference
Treelocator
Max. Instances1
Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

function
Synopsis Enter the function context
Context configure service vpls string segment-routing-v6 number locator reference function
Treefunction
Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

end-dt2m
Synopsis Enable the end-dt2m context
Context configure service vpls string segment-routing-v6 number locator reference function end-dt2m
Treeend-dt2m
Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

value number
Synopsis SRv6 function value
Context configure service vpls string segment-routing-v6 number locator reference function end-dt2m value number
Treevalue

Description

This command assigns the optional static function value for the routes in the VPRN, VPLS, or Epipe instance.

When unconfigured, the system allocates a value dynamically.

Range1 to 1048575
Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

end-dt2u
Synopsis Enable the end-dt2u context
Context configure service vpls string segment-routing-v6 number locator reference function end-dt2u
Treeend-dt2u
Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

value number
Synopsis SRv6 function value
Context configure service vpls string segment-routing-v6 number locator reference function end-dt2u value number
Treevalue

Description

This command assigns the optional static function value for the routes in the VPRN, VPLS, or Epipe instance.

When unconfigured, the system allocates a value dynamically.

Range1 to 1048575
Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

micro-segment-locator [locator-name] reference
Synopsis Enter the micro-segment-locator list instance
Contextconfigure service vpls string segment-routing-v6 number micro-segment-locator reference
Treemicro-segment-locator
Max. Instances1
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

[locator-name] reference
Synopsis Micro-segment SRv6 locator name
Context configure service vpls string segment-routing-v6 number micro-segment-locator reference
Treemicro-segment-locator

Description

This command associates a pre-defined micro-segment SRv6 locator (defined in the configure router segment-routing segment-routing-v6 context) with the SRv6 instance in the service. The same micro-segment locator can be referenced in multiple BGP instances used by IPVPN or EVPN.

Reference

configure router string segment-routing segment-routing-v6 micro-segment-locator string

Notes

This element is part of a list key.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

function
Synopsis Enter the function context
Context configure service vpls string segment-routing-v6 number micro-segment-locator reference function
Treefunction
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

udt2m
Synopsis Enable the udt2m context
Context configure service vpls string segment-routing-v6 number micro-segment-locator reference function udt2m
Treeudt2m

Description

Commands in this context configure the SRv6 uDT2M behavior and the function value that is associated to the SRv6 instance in the service. When configured, decapsulation and table lookup for IPv6 prefixes occurs in the VPLS service.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

value number
Synopsis SRv6 function value
Context configure service vpls string segment-routing-v6 number micro-segment-locator reference function udt2m value number
Treevalue

Description

This command assigns the optional static function value for the routes in the VPRN, VPLS, or Epipe instance.

When unconfigured, the system allocates a value dynamically.

Range1 to 1048575
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

udt2u
Synopsis Enable the udt2u context
Context configure service vpls string segment-routing-v6 number micro-segment-locator reference function udt2u
Treeudt2u

Description

Commands in this context configure the SRv6 uDT2U behavior and the function value that is associated to the SRv6 instance in the service. When configured, decapsulation and table lookup for IPv6 prefixes occurs in the VPLS service.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

value number
Synopsis SRv6 function value
Context configure service vpls string segment-routing-v6 number micro-segment-locator reference function udt2u value number
Treevalue

Description

This command assigns the optional static function value for the routes in the VPRN, VPLS, or Epipe instance.

When unconfigured, the system allocates a value dynamically.

Range1 to 1048575
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

service-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisService ID
Contextconfigure service vpls string service-id number
Treeservice-id
Range1 to 2147483647
Introduced16.0.R1

Platforms

All

service-mtu number
Synopsis MTU size
Contextconfigure service vpls string service-mtu number
Treeservice-mtu

Description

This command configures the Maximum Transmission Unit (MTU) value (payload) for the service. The system uses the value to validate the operational state of the SAP and SDP binding within the service. The value overrides the default MTU for the service type.

The service MTU and a SAP’s service delineation encapsulation overhead (4 bytes for a dot1q tag) are used to derive the required MTU of the physical port or channel on which the SAP was created. If the required payload is larger than the port or channel MTU, the SAP is placed in an inoperative state. If the required MTU is equal to or less than the port or channel MTU, the SAP transitions to the operative state.

When binding an SDP to a service, the service MTU is compared to the path MTU associated with the SDP. The path MTU can be administratively defined in the context of the SDP. The default or administrative path MTU can be dynamically reduced due to the MTU capabilities discovered by the tunneling mechanism of the SDP or the egress interface MTU capabilities based on the next hop in the tunnel path. If the service MTU is larger than the path MTU, the SDP binding for the service is placed in an inoperative state. If the service MTU is equal to or less than the path MTU, the SDP binding is placed in an operational state.

If a service MTU, port or channel MTU, or path MTU is dynamically or administratively modified, all associated SAP and SDP binding operational states are automatically reevaluated.

Binding operational states are automatically reevaluated.

For I-VPLS and Epipes bound to a B-VPLS, the service MTU must be at least 18 bytes smaller than the B-VPLS service MTU to accommodate the PBB header.

Because this connects a Layer 2 to a Layer 3 service, adjust the service MTU under the Epipe service. The MTU that is advertised from the Epipe side is service MTU minus EtherHeaderSize.

In the configure service epipe spoke-sdp context, the adv-service-mtu command can be used to override the configured MTU value used in T-LDP signaling to the far-end of an Epipe spoke-sdp. The adv-service-mtu command is also used to validate the value signaled by the far-end PE.

Range1 to 9782
Introduced16.0.R1

Platforms

All

spb
Synopsis Enable the spb context
Context configure service vpls string spb
Treespb
Introduced21.10.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of SPB
Context configure service vpls string spb admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced21.10.R1

Platforms

All

fid number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisFID identifier
Contextconfigure service vpls string spb fid number
Treefid
Range1 to 4095
Default1
Introduced 21.10.R1

Platforms

All

isis-instance number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisISIS instance
Contextconfigure service vpls string spb isis-instance number
Treeisis-instance
Range1024 to 2047
Default1024
Introduced 21.10.R1

Platforms

All

level [id] number
Synopsis Enter the level list instance
Context configure service vpls string spb level number
Treelevel
Introduced21.10.R1

Platforms

All

[id] number
Synopsis Level identifier
Context configure service vpls string spb level number
Treelevel
Range1

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

All

lsp-lifetime number
Synopsis Time LSP is considered valid by other routers
Contextconfigure service vpls string spb lsp-lifetime number
Treelsp-lifetime
Range350 to 65535
Default1200
Introduced 21.10.R1

Platforms

All

lsp-refresh-interval
Synopsis Enter the lsp-refresh-interval context
Contextconfigure service vpls string spb lsp-refresh-interval
Treelsp-refresh-interval
Introduced21.10.R1

Platforms

All

overload
Synopsis Enable the overload context
Context configure service vpls string spb overload
Treeoverload
Introduced21.10.R1

Platforms

All

timeout number
Synopsis Time the router operates in overloaded state
Contextconfigure service vpls string spb overload timeout number
Treetimeout
Range0 | 60 to 1800
Unitsseconds
Default 0
Introduced21.10.R1

Platforms

All

timers
Synopsis Enter the timers context
Context configure service vpls string spb timers
Treetimers
Introduced21.10.R1

Platforms

All

lsp-wait
Synopsis Enable the lsp-wait context
Context configure service vpls string spb timers lsp-wait
Treelsp-wait
Introduced21.10.R1

Platforms

All

spf-wait
Synopsis Enable the spf-wait context
Context configure service vpls string spb timers spf-wait
Treespf-wait
Introduced21.10.R1

Platforms

All

spbm-control-vpls
Synopsis Enter the spbm-control-vpls context
Contextconfigure service vpls string spbm-control-vpls
Treespbm-control-vpls
Introduced21.10.R1

Platforms

All

split-horizon-group [shg-name] string
Synopsis Enter the split-horizon-group list instance
Contextconfigure service vpls string split-horizon-group string
Treesplit-horizon-group
Introduced16.0.R1

Platforms

All

fdb
Synopsis Enter the fdb context
Context configure service vpls string split-horizon-group string fdb
Treefdb
Introduced16.0.R1

Platforms

All

saps
Synopsis Enter the saps context
Context configure service vpls string split-horizon-group string fdb saps
Treesaps
Introduced16.0.R1

Platforms

All

auto-learn-mac-protect-exclude-list reference
Synopsis Referenced MAC protect exclusion list name
Contextconfigure service vpls string split-horizon-group string fdb saps auto-learn-mac-protect-exclude-list reference
Treeauto-learn-mac-protect-exclude-list

Description

This command references the name of a MAC protect exclusion list.

Dynamically-learned MAC Source Addresses (SA) are protected if they are learned on an object with ALMP configured and no exclusion list is associated with the object, or if the MAC SA does not match any entry in an associated exclusion list.

An exclusion list can be used in multiple objects of a service. If a list is empty, ALMP does not exclude any learned MAC SAs from protection on the object.

Reference

configure service mac-list string

Introduced20.5.R1

Platforms

All

residential boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDefine as a residential split horizon group
Contextconfigure service vpls string split-horizon-group string residential boolean
Treeresidential
Defaultfalse
Introduced16.0.R1

Platforms

All

spoke-sdp [sdp-bind-id] string
Synopsis Enter the spoke-sdp list instance
Contextconfigure service vpls string spoke-sdp string
Treespoke-sdp
Introduced16.0.R1

Platforms

All

[sdp-bind-id] string
Synopsis SDP binding ID
Contextconfigure service vpls string spoke-sdp string
Treespoke-sdp
String Length3 to 16

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the SDP binding to the service
Contextconfigure service vpls string spoke-sdp string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

bfd
Synopsis Enter the bfd context
Context configure service vpls string spoke-sdp string bfd
Treebfd
Introduced21.2.R1

Platforms

All

bfd-template reference
Synopsis BFD template associated with the SDP binding
Contextconfigure service vpls string spoke-sdp string bfd bfd-template reference
Treebfd-template

Description

This command configures a named BFD template to be used by VCCV BFD on PWs belonging to the VLL service. The template specifies parameters, such as the minimum transmit and receive control packet timer intervals, used by the BFD session. Template parameters are configured under the configure router bfd context.

Reference

configure bfd bfd-template string

Introduced21.2.R1

Platforms

All

failure-action keyword
Synopsis VCCV BFD action taken on the SDP binding
Contextconfigure service vpls string spoke-sdp string bfd failure-action keyword
Treefailure-action

Description

This command configures a named BFD template to be used by VCCV BFD on PWs belonging to the VLL service. The template specifies parameters, such as the minimum transmit and receive control packet timer intervals, used by the BFD session. Template parameters are configured under the configure router bfd context.

Optionsnone, down
Default none
Introduced21.2.R1

Platforms

All

wait-for-up-timer number
Synopsis Time waited for BFD up status
Context configure service vpls string spoke-sdp string bfd wait-for-up-timer number
Treewait-for-up-timer

Description

This command configures the time interval that is used to wait for a BFD session to come up.

This command is triggered when a spoke-SDP is first administratively enabled and a VCCV BFD session transitions from up to down. The command is required to allow time for BFD sessions to come up, and for BFD to settle before selecting the active spoke-SDP for use in a redundant set. In the case where a VCCV BFD session is bouncing, the timer prevents excessive flapping of the operational state of a spoke-SDP.

Range1 to 60
Unitsseconds
Introduced 21.2.R1

Platforms

All

cpu-protection
Synopsis Enter the cpu-protection context
Contextconfigure service vpls string spoke-sdp string cpu-protection
Treecpu-protection
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

eth-cfm-monitoring
Synopsis Enable the eth-cfm-monitoring context
Contextconfigure service vpls string spoke-sdp string cpu-protection eth-cfm-monitoring
Treeeth-cfm-monitoring

Notes

The following elements are part of a choice: eth-cfm-monitoring or mac-monitoring.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

mac-monitoring
Synopsis Monitor MAC for CPU protection
Context configure service vpls string spoke-sdp string cpu-protection mac-monitoring
Treemac-monitoring

Notes

The following elements are part of a choice: eth-cfm-monitoring or mac-monitoring.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

dhcp
Synopsis Enter the dhcp context
Context configure service vpls string spoke-sdp string dhcp
Treedhcp
Introduced16.0.R1

Platforms

All

snoop boolean
Synopsis Allow DHCP snooping of DHCP messages on the SAP or SDP
Contextconfigure service vpls string spoke-sdp string dhcp snoop boolean
Treesnoop
Defaultfalse
Introduced16.0.R1

Platforms

All

egress
Synopsis Enter the egress context
Context configure service vpls string spoke-sdp string egress
Treeegress
Introduced16.0.R1

Platforms

All

filter
Synopsis Enter the filter context
Context configure service vpls string spoke-sdp string egress filter
Treefilter
Introduced16.0.R1

Platforms

All

mfib-allowed-mda-destinations
Synopsis Enter the mfib-allowed-mda-destinations context
Contextconfigure service vpls string spoke-sdp string egress mfib-allowed-mda-destinations
Treemfib-allowed-mda-destinations
Introduced16.0.R4

Platforms

All

qos
Synopsis Enter the qos context
Context configure service vpls string spoke-sdp string egress qos
Treeqos
Introduced16.0.R1

Platforms

All

network
Synopsis Enter the network context
Context configure service vpls string spoke-sdp string egress qos network
Treenetwork
Introduced16.0.R1

Platforms

All

port-redirect-group
Synopsis Enter the port-redirect-group context
Contextconfigure service vpls string spoke-sdp string egress qos network port-redirect-group
Treeport-redirect-group
Introduced16.0.R1

Platforms

All

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEgress MPLS VC label to send packets to the far end
Contextconfigure service vpls string spoke-sdp string egress vc-label number
Treevc-label
Range16 to 1048575
Introduced16.0.R1

Platforms

All

endpoint
Synopsis Enter the endpoint context
Context configure service vpls string spoke-sdp string endpoint
Treeendpoint
Introduced16.0.R1

Platforms

All

name reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisName of service endpoint to which SDP bind is attached
Contextconfigure service vpls string spoke-sdp string endpoint name reference
Treename

Reference

configure service vpls string endpoint string

Introduced16.0.R1

Platforms

All

precedence (number | keyword)
Synopsis Precedence of this SDP bind when there are multiple SDP binds attached to one service endpoint
Contextconfigure service vpls string spoke-sdp string endpoint precedence (number | keyword)
Treeprecedence
Range1 to 4
Optionsprimary
Default4
Introduced 16.0.R1

Platforms

All

entropy-label
Synopsis Enable the use of entropy labels for spoke SDPs
Contextconfigure service vpls string spoke-sdp string entropy-label
Treeentropy-label

Notes

The following elements are part of a choice: entropy-label or hash-label.

Introduced16.0.R1

Platforms

All

eth-cfm
Synopsis Enter the eth-cfm context
Context configure service vpls string spoke-sdp string eth-cfm
Treeeth-cfm
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

collect-lmm-fc-stats
Synopsis Enter the collect-lmm-fc-stats context
Contextconfigure service vpls string spoke-sdp string eth-cfm collect-lmm-fc-stats
Treecollect-lmm-fc-stats

Description

Commands in this context configure per forwarding class (FC) LMM information collection.

The commands fc-in-profile and fc in this context are mutually exclusive. The commands apply to either profile-aware or profile-unaware FCs respectively. 

This command and the collect-lmm-stats command are mutually exclusive when there is entity resource contention.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fc keyword
Synopsis Forwarding class name for profile-unaware counter
Contextconfigure service vpls string spoke-sdp string eth-cfm collect-lmm-fc-stats fc keyword
Treefc

Description

This command configures individual counters for the specified FCs without regard for profile. The system includes all countable packets that match a configured FC, regardless of profile, in this counter.

An FC specified as part of this command and for this specific context cannot be specified as a profile-aware FC using the fc-in-profile command under the collect-lmm-fc-stats context. 

When this command is reentered, a differential is performed. Omitted FCs stop counting, newly added FCs start counting, and unchanged FCs continue to count.

Optionsbe, l2, af, l1, h2, ef, h1, nc
Max. Instances 8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fc-in-profile keyword
Synopsis Forwarding class name for profile-aware counter
Contextconfigure service vpls string spoke-sdp string eth-cfm collect-lmm-fc-stats fc-in-profile keyword
Treefc-in-profile

Description

This command configures individual counters for the specified FCs with regard to profile. The system includes all countable packets that match a configured FC and that are deemed to be in-profile in this counter.

An FC specified as part of this command and for this specific context cannot be specified as a profile-unaware FC using the fc command under the collect-lmm-fc-stats context.

When this command is reentered, a differential is performed. Omitted FCs stop counting, newly added FCs start counting, and unchanged FCs continue to count.

Optionsbe, l2, af, l1, h2, ef, h1, nc
Max. Instances 8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

collect-lmm-stats boolean
Synopsis Collect statistics for loss measurement message tests
Contextconfigure service vpls string spoke-sdp string eth-cfm collect-lmm-stats boolean
Treecollect-lmm-stats

Description

When configured to true, the router instantiates the statistical counter to transmit and receive packets for the LAG facility MEP bindings.

The show eth-cfm collect-lmm-stats command displays entities that have been enabled to collect transit and receive counters.

When configured to false, the router does not instantiate the counter and the LMM PDU associated with the MEP does not populate the counters in the packet.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mep md-admin-name reference ma-admin-name reference mep-id number
Synopsis Enter the mep list instance
Context configure service vpls string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number
Treemep
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mep-id number
Synopsis Maintenance Endpoint (MEP) ID
Context configure service vpls string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number
Treemep
Range1 to 8191

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ais
Synopsis Enable the ais context
Context configure service vpls string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number ais
Treeais
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

alarm-notification
Synopsis Enter the alarm-notification context
Contextconfigure service vpls string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number alarm-notification
Treealarm-notification

Description

Commands in this context configure the Fault Notification Generator (FNG) time values to raise an alarm or reset the CCM defect alarm. 

Use these timers for network management processes. The timers are not tied into delaying the notification to the fault management system on the network element and do not affect fault propagation mechanisms.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ccm-padding-size number
Synopsis Number of octets of padding to insert in CCM packets
Contextconfigure service vpls string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number ccm-padding-size number
Treeccm-padding-size

Description

This command sets the byte size of the optional Data TLV to be included in the ETH-CC PDU.

This command increases the size of the ETH-CC PDU by the configured value. The base size of the ETH-CC PDU, including the Interface Status TLV and Port Status TLV, is 83 bytes not including the Layer 2 encapsulation. CCM padding is not supported when the CCM interval (configured through configure eth-cfm domain association ccm-interval) is less than 1 second.

Range3 to 1500
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

csf
Synopsis Enable the csf context
Context configure service vpls string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number csf
Treecsf
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

direction keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDirection the MEP faces
Contextconfigure service vpls string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number direction keyword
Treedirection
Optionsdown, up
Default down
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-test
Synopsis Enable the eth-test context
Context configure service vpls string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test
Treeeth-test

Description

Commands in this context configure information used by the Ethernet Test (ETH-TST) packet. The commands must be configured on both the sender and the receiver nodes. The test packets are used with the oam eth-cfm eth-test command.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

test-pattern
Synopsis Enter the test-pattern context
Contextconfigure service vpls string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test test-pattern
Treetest-pattern

Description

Commands in this context specify the test pattern for the ETH-TST frames. The pattern does not have to be the same on the sender and the receiver.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

pattern keyword
Synopsis Test pattern for Ethernet Test frames
Contextconfigure service vpls string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test test-pattern pattern keyword
Treepattern

Description

This command specifies the test pattern of the Ethernet Test (ETH-TST) frames. This does not have to be configured the same on the sender and the receiver.

Optionsall-zeros, all-ones
Default all-zeros
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

grace
Synopsis Enter the grace context
Context configure service vpls string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace
Treegrace

Description

Commands in this context configure the Nokia ETH-CFM Grace function and the ITU-T Y.1731 Ethernet Expected Default (ETH-ED) function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-ed
Synopsis Enter the eth-ed context
Context configure service vpls string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-ed
Treeeth-ed

Description

Commands in this context configure the ITU-T Y.1731 ETH-ED function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

rx-eth-ed boolean
Synopsis Receive and process ETH-ED ITU-T Y.1731 PDUs on the MEP
Contextconfigure service vpls string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-ed rx-eth-ed boolean
Treerx-eth-ed

Description

This command enables the reception and processing of the ITU-T Y.1731 ETH-ED PDU on the MEP.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-vsm-grace
Synopsis Enter the eth-vsm-grace context
Contextconfigure service vpls string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace
Treeeth-vsm-grace

Description

Commands in this context configure the Nokia ETH-CFM Grace function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

rx-eth-vsm-grace boolean
Synopsis Receive and process Nokia ETH-CFM Grace PDU on the MEP
Contextconfigure service vpls string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace rx-eth-vsm-grace boolean
Treerx-eth-vsm-grace

Description

When configured to true, the router enables the Nokia Grace function, which is a vendor-specific PDU that informs MEP peers that the local node may be entering a period of expected defect.

When configured to false, the router disables the Nokia Grace function.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

tx-eth-vsm-grace boolean
Synopsis Transmit ETH-ED PDUs from the MEP
Context configure service vpls string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace tx-eth-vsm-grace boolean
Treetx-eth-vsm-grace

Description

When configured to true, the router can transmit the Nokia ETH-CFM Grace PDU from the MEP when a system soft reset notification is received for one or more cards.

The Nokia Grace function is a vendor-specific PDU that informs MEP peers that the local node may be entering a period of expected defect.

The operator must configure the configure system eth-cfm grace command to instruct the system that the node is capable of transmitting expected-defect windows to peers. The system can only transmit one form of ETH-CFM grace (Nokia ETH-CFM Grace or ITU-T Y.1731 ETH-ED).

When configured to false, the router disables the transmission of the Nokia ETH-CFM Grace PDU from the MEP.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mac-address string
Synopsis MAC address of the MEP
Context configure service vpls string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number mac-address string
Treemac-address

Description

This command specifies the MAC address of the MEP.

When unconfigured, the MAC address of the port (if the MEP is on a SAP) or the MAC address of a bridge (if the MEP is on a spoke) is used.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

primary-vlan boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisMEP provisioned using MA primary VLAN ID
Contextconfigure service vpls string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number primary-vlan boolean
Treeprimary-vlan
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mip primary-vlan (number | keyword)
Synopsis Enter the mip list instance
Context configure service vpls string spoke-sdp string eth-cfm mip primary-vlan (number | keyword)
Treemip
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

primary-vlan (number | keyword)
Synopsis VLAN ID to which the MIP is attached
Context configure service vpls string spoke-sdp string eth-cfm mip primary-vlan (number | keyword)
Treemip

Description

This command provides an option for linking a MIP with a Primary VLAN number or none. When the none option is provided, the MIP does not include the primary vlan.

Range1 to 4094
Optionsnone

Notes

This element is part of a list key.

Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

cfm-vlan-tag string
Synopsis VLAN tags to apply to CFM PDUs for egress processing
Contextconfigure service vpls string spoke-sdp string eth-cfm mip primary-vlan (number | keyword) cfm-vlan-tag string
Treecfm-vlan-tag

Description

This command allows the CFM function to include additional VLAN tags to the CFM packet that are carried to the egress and treated as service delimited. Typically, this function is used to influence the VLAN carried over a binding that uses the vc-type vlan or the binding forces the use of one or more VLAN tag that results in a mismatch between the service data arriving at the binding and the locally generated ETH-CFM PDUs arriving at the same egress. When this command is included under the MEP or MIP configuration, the tags used as part of the configuration typically match the SAP service delimited configuration.

String Length1 to 9
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

squelch-ingress-ctag-levels number
Synopsis Squelch levels using additional VLAN C-Tag space
Contextconfigure service vpls string spoke-sdp string eth-cfm squelch-ingress-ctag-levels number
Treesquelch-ingress-ctag-levels

Description

This command defines the levels of the ETH-CFM packets that are silently discarded on ingress into the SAP or SDP binding from the wire that matches the service delineation of the SAP or SDP binding plus an additional VLAN, up to a maximum tag length of two tags. All ETH-CFM packets inbound to the SAP or SDP binding that match the configured levels are dropped without regard for any other ETH-CFM criteria. No statistical information or drop count is available for any ETH-CFM packet that is silently discarded by this option.

The list of levels must be a complete contiguous list from 0 up to the highest level to be dropped.

Range0 to 7
Max. Instances8
Introduced 21.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

squelch-ingress-levels number
Synopsis Levels for which ETH-CFM packets are silently discarded
Contextconfigure service vpls string spoke-sdp string eth-cfm squelch-ingress-levels number
Treesquelch-ingress-levels

Description

This command defines the levels of the ETH-CFM packets that are silently discarded on ingress into the SAP or SDP binding from the wire that matches the service delineation of the SAP or SDP binding. All ETH-CFM packets inbound to the SAP or SDP binding that match the configured levels are dropped without regard for any other ETH-CFM criteria. No statistical information or drop count is available for any ETH-CFM packet that is silently discarded by this option.

The list of levels must be a complete contiguous list from 0 up to the highest level that will be dropped.

Range0 to 7
Max. Instances8
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

vmep-filter boolean
Synopsis Suppress eth-cfm PDUs based on level lower than or equal to configured Virtual MEP
Contextconfigure service vpls string spoke-sdp string eth-cfm vmep-filter boolean
Treevmep-filter
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

etree-leaf boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEnable etree leaf access-circuit status
Contextconfigure service vpls string spoke-sdp string etree-leaf boolean
Treeetree-leaf
Defaultfalse
Introduced16.0.R1

Platforms

All

etree-root-leaf-tag boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisE-tree root leaf tag status
Contextconfigure service vpls string spoke-sdp string etree-root-leaf-tag boolean
Treeetree-root-leaf-tag
Defaultfalse
Introduced16.0.R1

Platforms

All

fdb
Synopsis Enter the fdb context
Context configure service vpls string spoke-sdp string fdb
Treefdb
Introduced16.0.R1

Platforms

All

auto-learn-mac-protect-exclude-list reference
Synopsis Referenced MAC protect exclusion list name
Contextconfigure service vpls string spoke-sdp string fdb auto-learn-mac-protect-exclude-list reference
Treeauto-learn-mac-protect-exclude-list

Description

This command references the name of a MAC protect exclusion list.

Dynamically-learned MAC Source Addresses (SA) are protected if they are learned on an object with ALMP configured and no exclusion list is associated with the object, or if the MAC SA does not match any entry in an associated exclusion list.

An exclusion list can be used in multiple objects of a service. If a list is empty, ALMP does not exclude any learned MAC SAs from protection on the object.

Reference

configure service mac-list string

Introduced20.5.R1

Platforms

All

mac-learning
Synopsis Enter the mac-learning context
Contextconfigure service vpls string spoke-sdp string fdb mac-learning
Treemac-learning
Introduced16.0.R1

Platforms

All

maximum-mac-addresses number
Synopsis Maximum number of MAC address entries in the FDB
Contextconfigure service vpls string spoke-sdp string fdb maximum-mac-addresses number
Treemaximum-mac-addresses

Description

This command specifies the maximum number of FDB entries for both learned and static MAC addresses for this spoke SDP.

When the configured limit is reached, no new addresses are learned from the SAP or spoke SDP until at least one FDB entry is aged out or cleared.

When the configured limit is reached and the configure service spoke-sdp fdb discard-unknown-source command is set to true for this spoke SDP, packets with unknown source MAC addresses are discarded. If discard-unknown-source is set to false, the packets are forwarded if their destination MAC addresses are known, or flooded if their destination MAC addresses are unknown.

However, if the configure service vpls fdb discard-unknown command is set to true, packets with unknown destination MAC addresses are discarded, even if the limit of FDB entries on the specific VPLS instance is not reached.

When unconfigured, the spoke SDP uses the global MAC learning limitations.

Range1 to 511999
Introduced16.0.R1

Platforms

All

hash-label
Synopsis Enable the hash-label context
Context configure service vpls string spoke-sdp string hash-label
Treehash-label

Description

Commands in this context configure the use of hash labels for egress datapaths.

For information about hash-label handling, see the "Hash labels" section of the 7450 ESS, 7750 SR, 7950 XRS, and VSR MPLS Guide.

Notes

The following elements are part of a choice: entropy-label or hash-label.

Introduced16.0.R1

Platforms

All

signal-capability
Synopsis Signal hash label capability to the remote PE
Contextconfigure service vpls string spoke-sdp string hash-label signal-capability
Treesignal-capability

Description

When configured, this command enables the signaling and negotiating of the hash label between the local and remote PE nodes.

The signaling process outcome determines whether the local PE inserts the hash label on the user packets. This outcome can override the local PE configuration.

Introduced16.0.R1

Platforms

All

i-vpls-mac-flush
Synopsis Enter the i-vpls-mac-flush context
Contextconfigure service vpls string spoke-sdp string i-vpls-mac-flush
Treei-vpls-mac-flush
Introduced16.0.R1

Platforms

All

igmp-snooping
Synopsis Enter the igmp-snooping context
Contextconfigure service vpls string spoke-sdp string igmp-snooping
Treeigmp-snooping
Introduced16.0.R1

Platforms

All

mcac
Synopsis Enter the mcac context
Context configure service vpls string spoke-sdp string igmp-snooping mcac
Treemcac
Introduced16.0.R1

Platforms

All

bandwidth
Synopsis Enter the bandwidth context
Context configure service vpls string spoke-sdp string igmp-snooping mcac bandwidth
Treebandwidth
Introduced16.0.R1

Platforms

All

policy reference
Synopsis Multicast CAC policy name
Context configure service vpls string spoke-sdp string igmp-snooping mcac policy reference
Treepolicy

Description

This command configures the name of the global channel bandwidth definition policy that is used for (H)MCAC and HQoS adjustment.

Within the scope of HQoS adjustment, the channel definition policy under the group interface is used if redirection is unconfigured. In this case, the HQoS adjustment can be applied to IPoE subscribers in per-SAP replication mode.

If redirection is configured, the channel bandwidth definition policy applied under the Layer 3 redirected interface is in effect.

Hierarchical MCAC (HMCAC) is supported on two levels simultaneously:

  • subscriber level and redirected interface when redirection is configured

  • subscriber level and group-interface level when redirection is unconfigured

In HMCAC, the subscriber is checked against its bandwidth limits first, then against the bandwidth limits of the redirected or group interface. If redirection is configured but the policy is referenced only under the group interface, no admission control is executed (HMCAC or MCAC).

Reference

configure mcac policy string

Introduced16.0.R1

Platforms

All

static
Synopsis Enter the static context
Context configure service vpls string spoke-sdp string igmp-snooping static
Treestatic
Introduced16.0.R1

Platforms

All

group [group-address] string
Synopsis Enter the group list instance
Context configure service vpls string spoke-sdp string igmp-snooping static group string
Treegroup
Introduced16.0.R1

Platforms

All

[group-address] string
Synopsis Group address of static IGMP multicast channel
Contextconfigure service vpls string spoke-sdp string igmp-snooping static group string
Treegroup

Description

This command configures an address that receives data on an interface. The IP address must be unique for each static group.

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

source [source-address] string
Synopsis Add a list entry for source
Context configure service vpls string spoke-sdp string igmp-snooping static group string source string
Treesource

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced16.0.R1

Platforms

All

ingress
Synopsis Enter the ingress context
Context configure service vpls string spoke-sdp string ingress
Treeingress
Introduced16.0.R1

Platforms

All

filter
Synopsis Enter the filter context
Context configure service vpls string spoke-sdp string ingress filter
Treefilter
Introduced16.0.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service vpls string spoke-sdp string ingress qos
Treeqos
Introduced16.0.R1

Platforms

All

network
Synopsis Enter the network context
Context configure service vpls string spoke-sdp string ingress qos network
Treenetwork
Introduced16.0.R1

Platforms

All

fp-redirect-group
Synopsis Enter the fp-redirect-group context
Contextconfigure service vpls string spoke-sdp string ingress qos network fp-redirect-group
Treefp-redirect-group
Introduced16.0.R1

Platforms

All

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIngress MPLS VC label to send packets to the far end
Contextconfigure service vpls string spoke-sdp string ingress vc-label number
Treevc-label
Range1 to 1048575
Introduced16.0.R1

Platforms

All

l2pt
Synopsis Enter the l2pt context
Context configure service vpls string spoke-sdp string l2pt
Treel2pt
Introduced16.0.R1

Platforms

All

termination
Synopsis Enable the termination context
Contextconfigure service vpls string spoke-sdp string l2pt termination
Treetermination
Introduced16.0.R1

Platforms

All

protocols
Synopsis Enter the protocols context
Context configure service vpls string spoke-sdp string l2pt termination protocols
Treeprotocols
Introduced16.0.R1

Platforms

All

mld-snooping
Synopsis Enter the mld-snooping context
Contextconfigure service vpls string spoke-sdp string mld-snooping
Treemld-snooping
Introduced16.0.R1

Platforms

All

static
Synopsis Enter the static context
Context configure service vpls string spoke-sdp string mld-snooping static
Treestatic
Introduced16.0.R1

Platforms

All

group [group-address] string
Synopsis Enter the group list instance
Context configure service vpls string spoke-sdp string mld-snooping static group string
Treegroup
Introduced16.0.R1

Platforms

All

source [source-address] string
Synopsis Add a list entry for source
Context configure service vpls string spoke-sdp string mld-snooping static group string source string
Treesource

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced16.0.R1

Platforms

All

mrp
Synopsis Enter the mrp context
Context configure service vpls string spoke-sdp string mrp
Treemrp
Introduced20.10.R1

Platforms

All

join-time number
Synopsis Maximum rate for attribute join messages sent on SDP
Contextconfigure service vpls string spoke-sdp string mrp join-time number
Treejoin-time
Range1 to 10
Unitsdeciseconds
Default 2
Introduced20.10.R1

Platforms

All

leave-all-time number
Synopsis Frequency of LeaveAll PDUs by LeaveAll state machine
Contextconfigure service vpls string spoke-sdp string mrp leave-all-time number
Treeleave-all-time
Range60 to 300
Unitsdeciseconds
Default 100
Introduced20.10.R1

Platforms

All

leave-time number
Synopsis Time in LV state before transition to MT state
Contextconfigure service vpls string spoke-sdp string mrp leave-time number
Treeleave-time
Range30 to 60
Unitsdeciseconds
Default 30
Introduced20.10.R1

Platforms

All

periodic-time number
Synopsis Frequency of periodic events generated by state machine
Contextconfigure service vpls string spoke-sdp string mrp periodic-time number
Treeperiodic-time
Range10 to 100
Unitsdeciseconds
Default 10
Introduced20.10.R1

Platforms

All

oper-group reference
Synopsis Operational group identifier
Context configure service vpls string spoke-sdp string oper-group reference
Treeoper-group

Reference

configure service oper-group string

Notes

The following elements are part of a choice: monitor-oper-group or oper-group.

Introduced16.0.R1

Platforms

All

pbb
Synopsis Enter the pbb context
Context configure service vpls string spoke-sdp string pbb
Treepbb
Introduced20.10.R1

Platforms

All

fault-propagation
Synopsis Enter the fault-propagation context
Contextconfigure service vpls string spoke-sdp string pbb fault-propagation
Treefault-propagation
Introduced20.10.R1

Platforms

All

backbone-mac-name [name] reference
Synopsis Add a list entry for backbone-mac-name
Contextconfigure service vpls string spoke-sdp string pbb fault-propagation backbone-mac-name reference
Treebackbone-mac-name
Introduced20.10.R1

Platforms

All

spb
Synopsis Enable the spb context
Context configure service vpls string spoke-sdp string spb
Treespb
Introduced21.10.R1

Platforms

All

level [id] number
Synopsis Enter the level list instance
Context configure service vpls string spoke-sdp string spb level number
Treelevel
Introduced21.10.R1

Platforms

All

[id] number
Synopsis Level identifier
Context configure service vpls string spoke-sdp string spb level number
Treelevel
Range1

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

All

static-isid
Synopsis Enter the static-isid context
Context configure service vpls string spoke-sdp string static-isid
Treestatic-isid
Introduced19.10.R1

Platforms

All

range [range-id] number
Synopsis Enter the range list instance
Context configure service vpls string spoke-sdp string static-isid range number
Treerange
Introduced19.10.R1

Platforms

All

[range-id] number
Synopsis Range ID for static ISID
Context configure service vpls string spoke-sdp string static-isid range number
Treerange
Range1 to 8191

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

stp
Synopsis Enter the stp context
Context configure service vpls string spoke-sdp string stp
Treestp
Introduced16.0.R4

Platforms

All

auto-edge boolean
Synopsis Enable automatic detection of edge port characteristics
Contextconfigure service vpls string spoke-sdp string stp auto-edge boolean
Treeauto-edge
Defaulttrue
Introduced16.0.R4

Platforms

All

link-type keyword
Synopsis Configure STP link-type
Context configure service vpls string spoke-sdp string stp link-type keyword
Treelink-type
Optionspt-pt, shared
Default pt-pt
Introduced16.0.R4

Platforms

All

transit-policy
Synopsis Enable the transit-policy context
Contextconfigure service vpls string spoke-sdp string transit-policy
Treetransit-policy
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

vc-type keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisType of virtual circuit (VC) associated with the SDP binding; VPLS not supported
Contextconfigure service vpls string spoke-sdp string vc-type keyword
Treevc-type
Optionsether, vlan
Default ether
Introduced16.0.R1

Platforms

All

stp
Synopsis Enter the stp context
Context configure service vpls string stp
Treestp
Introduced16.0.R4

Platforms

All

admin-state keyword
Synopsis Administrative state of STP
Context configure service vpls string stp admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R4

Platforms

All

hello-time number
Synopsis Configure hello-time
Context configure service vpls string stp hello-time number
Treehello-time
Range1 to 10
Default2
Introduced 16.0.R4

Platforms

All

hold-count number
Synopsis Configure BPDU transmit hold count
Context configure service vpls string stp hold-count number
Treehold-count
Range1 to 20
Default6
Introduced 16.0.R4

Platforms

All

maximum-age number
Synopsis Configure maximum STP information age
Contextconfigure service vpls string stp maximum-age number
Treemaximum-age
Range6 to 40
Default20
Introduced 16.0.R4

Platforms

All

mode keyword
Synopsis Configure protocol version
Context configure service vpls string stp mode keyword
Treemode
Optionsrstp, comp-dot1w, dot1w, mstp, pmstp
Defaultrstp
Introduced16.0.R4

Platforms

All

mst-instance [mst-inst-number] number
Synopsis Enter the mst-instance list instance
Contextconfigure service vpls string stp mst-instance number
Treemst-instance
Introduced19.10.R1

Platforms

All

[mst-inst-number] number
Synopsis Multiple Spanning Tree Instance number
Contextconfigure service vpls string stp mst-instance number
Treemst-instance
Range1 to 4094

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

mst-priority number
Synopsis Priority of multiple spanning tree instance
Contextconfigure service vpls string stp mst-instance number mst-priority number
Treemst-priority
Range0 | 4096 | 8192 | 12288 | 16384 | 20480 | 24576 | 28672 | 32768 | 36864 | 40960 | 45056 | 49152 | 53248 | 57344 | 61440
Default32768
Introduced19.10.R1

Platforms

All

mst-name string
Synopsis MST region name
Context configure service vpls string stp mst-name string
Treemst-name
String Length1 to 32
Introduced19.10.R1

Platforms

All

priority number
Synopsis STP bridge priority
Context configure service vpls string stp priority number
Treepriority
Range0 to 65535
Default32768
Introduced 16.0.R4

Platforms

All

tunnel-elmi boolean
Synopsis Allow E-LMI tunneling
Context configure service vpls string tunnel-elmi boolean
Treetunnel-elmi

Description

When configured to true, the router allows E-LMI packets in a VPLS service to be tunneled. The following must also be the case for this command to function:

  • the configure port ethernet elmi mode uni-n command is not configured

  • the E-LMI packets map to that VPLS service

When configured to false, tunneling of the E-LMI packets for a VPLS service is disabled.

Defaultfalse
Introduced23.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

vpn-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVPN identifier for the service
Contextconfigure service vpls string vpn-id number
Treevpn-id
Range1 to 2147483647
Introduced16.0.R1

Platforms

All

vxlan
Synopsis Enter the vxlan context
Context configure service vpls string vxlan
Treevxlan
Introduced16.0.R1

Platforms

All

instance [vxlan-instance] number
Synopsis Enter the instance list instance
Contextconfigure service vpls string vxlan instance number
Treeinstance
Introduced16.0.R1

Platforms

All

[vxlan-instance] number
Synopsis VXLAN instance
Contextconfigure service vpls string vxlan instance number
Treeinstance
Range1 to 2

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

assisted-replication
Synopsis Enter the assisted-replication context
Contextconfigure service vpls string vxlan instance number assisted-replication
Treeassisted-replication
Introduced16.0.R1

Platforms

All

egress-vtep [ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Add a list entry for egress-vtep
Contextconfigure service vpls string vxlan instance number egress-vtep (ipv4-address-no-zone | ipv6-address-no-zone)
Treeegress-vtep
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

[ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis VTEP IP address used when originating VXLAN packets
Contextconfigure service vpls string vxlan instance number egress-vtep (ipv4-address-no-zone | ipv6-address-no-zone)
Treeegress-vtep

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fdb
Synopsis Enter the fdb context
Context configure service vpls string vxlan instance number fdb
Treefdb
Introduced16.0.R1

Platforms

All

mac-learning
Synopsis Enter the mac-learning context
Contextconfigure service vpls string vxlan instance number fdb mac-learning
Treemac-learning
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

aging boolean
Synopsis Enable/disable aging of MAC addresses
Contextconfigure service vpls string vxlan instance number fdb mac-learning aging boolean
Treeaging
Defaultfalse
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

network
Synopsis Enter the network context
Context configure service vpls string vxlan instance number network
Treenetwork
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

ingress
Synopsis Enter the ingress context
Context configure service vpls string vxlan instance number network ingress
Treeingress
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

qos
Synopsis Enter the qos context
Context configure service vpls string vxlan instance number network ingress qos
Treeqos
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

network
Synopsis Enter the network context
Context configure service vpls string vxlan instance number network ingress qos network
Treenetwork
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

fp-redirect-group
Synopsis Enter the fp-redirect-group context
Contextconfigure service vpls string vxlan instance number network ingress qos network fp-redirect-group
Treefp-redirect-group
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

vni number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVNI of the VXLAN
Contextconfigure service vpls string vxlan instance number vni number
Treevni
Range1 to 16777215

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

source-vtep (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Vxlan source virtual tunnel endpoint information
Contextconfigure service vpls string vxlan source-vtep (ipv4-address-no-zone | ipv6-address-no-zone)
Treesource-vtep
Introduced16.0.R1

Platforms

All

wlan-gw
Synopsis Enter the wlan-gw context
Context configure service vpls string wlan-gw
Treewlan-gw
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of WLAN-GW
Context configure service vpls string wlan-gw admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

description string
Synopsis Text description
Context configure service vpls string wlan-gw description string
Treedescription
String Length1 to 80
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

wlan-gw-group reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisWLAN-GW endpoint within the VPLS service
Contextconfigure service vpls string wlan-gw wlan-gw-group reference
Treewlan-gw-group

Description

This command specifies a WLAN-GW group to be used as an endpoint within the VPLS. This feature is used in conjunction with the configure service vprn subscriber-interface group-interface wlan-gw vlan-range dynamic-service command for a VPRN service and the configure service ies subscriber-interface group-interface wlan-gw vlan-range dynamic-service command for an IES service.

See "Dynamic VPLS service" in the 7450 ESS, 7750 SR, and VSR Triple Play Service Delivery Architecture Guide for more information about the dynamic VPLS service feature.

Reference

configure isa wlan-gw-group number

Introduced23.3.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

vprn [service-name] string

Synopsis Enter the vprn list instance
Context configure service vprn string
Treevprn
Introduced16.0.R1

Platforms

All

[service-name] string
Synopsis Administrative service name
Context configure service vprn string
Treevprn
String Length1 to 64

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

aa-interface [interface-name] string
Synopsis Enter the aa-interface list instance
Contextconfigure service vprn string aa-interface string
Treeaa-interface
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[interface-name] string
Synopsis Interface name
Contextconfigure service vprn string aa-interface string
Treeaa-interface
String Length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the interface
Contextconfigure service vprn string aa-interface string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

description string
Synopsis Text description
Context configure service vprn string aa-interface string description string
Treedescription
String Length1 to 255
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-mtu number
Synopsis IP MTU applied to outgoing packets
Context configure service vprn string aa-interface string ip-mtu number
Treeip-mtu

Description

This command configures the IP maximum transmission unit (MTU) for the associated router IP interface.

Range512 to 9786
Unitsbytes
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ipv4
Synopsis Enter the ipv4 context
Context configure service vprn string aa-interface string ipv4
Treeipv4
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

primary
Synopsis Enable the primary context
Context configure service vprn string aa-interface string ipv4 primary
Treeprimary
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

address string
Synopsis Primary IPv4 address assigned to the interface
Contextconfigure service vprn string aa-interface string ipv4 primary address string
Treeaddress

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

sap [sap-id] string
Synopsis Enter the sap list instance
Context configure service vprn string aa-interface string sap string
Treesap
Max. Instances1
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[sap-id] string
Synopsis SAP ID
Contextconfigure service vprn string aa-interface string sap string
Treesap
String Length1 to 45

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the SAP
Context configure service vprn string aa-interface string sap string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

description string
Synopsis Text description
Context configure service vprn string aa-interface string sap string description string
Treedescription
String Length1 to 160
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

egress
Synopsis Enter the egress context
Context configure service vprn string aa-interface string sap string egress
Treeegress
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

qos
Synopsis Enter the qos context
Context configure service vprn string aa-interface string sap string egress qos
Treeqos
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

sap-egress
Synopsis Enter the sap-egress context
Context configure service vprn string aa-interface string sap string egress qos sap-egress
Treesap-egress
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

virtual-port
Synopsis Enter the virtual-port context
Contextconfigure service vprn string aa-interface string sap string egress virtual-port
Treevirtual-port
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

fwd-wholesale
Synopsis Enter the fwd-wholesale context
Contextconfigure service vprn string aa-interface string sap string fwd-wholesale
Treefwd-wholesale
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ingress
Synopsis Enter the ingress context
Context configure service vprn string aa-interface string sap string ingress
Treeingress
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

qos
Synopsis Enter the qos context
Context configure service vprn string aa-interface string sap string ingress qos
Treeqos
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

sap-ingress
Synopsis Enter the sap-ingress context
Context configure service vprn string aa-interface string sap string ingress qos sap-ingress
Treesap-ingress
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

lag
Synopsis Enter the lag context
Context configure service vprn string aa-interface string sap string lag
Treelag
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

aaa
Synopsis Enter the aaa context
Context configure service vprn string aaa
Treeaaa
Introduced16.0.R4

Platforms

All

remote-servers
Synopsis Enter the remote-servers context
Contextconfigure service vprn string aaa remote-servers
Treeremote-servers
Introduced16.0.R4

Platforms

All

radius
Synopsis Enable the radius context
Context configure service vprn string aaa remote-servers radius
Treeradius
Introduced16.0.R4

Platforms

All

port number
Synopsis UDP port number on which to contact RADIUS server
Contextconfigure service vprn string aaa remote-servers radius port number
Treeport
Range1 to 65535
Default1812
Introduced 16.0.R4

Platforms

All

server [index] number
Synopsis Enter the server list instance
Contextconfigure service vprn string aaa remote-servers radius server number
Treeserver
Max. Instances5
Introduced16.0.R4

Platforms

All

address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the RADIUS server
Context configure service vprn string aaa remote-servers radius server number address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeaddress

Notes

This element is mandatory.

Introduced16.0.R4

Platforms

All

authenticator keyword
Synopsis Authenticator hash algorithm for the RADIUS server
Contextconfigure service vprn string aaa remote-servers radius server number authenticator keyword
Treeauthenticator

Description

This command specifies the hash algorithm used to authenticate RADIUS Access-Request, Access-Accept, Access-Reject, Access-Challenge, Accounting-Request, and Accounting-Response packets.

Optionsmd5, sm3
Default md5
Introduced22.10.R1

Platforms

All

tacplus
Synopsis Enable the tacplus context
Context configure service vprn string aaa remote-servers tacplus
Treetacplus
Introduced16.0.R4

Platforms

All

authorization
Synopsis Enable the authorization context
Contextconfigure service vprn string aaa remote-servers tacplus authorization
Treeauthorization
Introduced16.0.R4

Platforms

All

request-format
Synopsis Enter the request-format context
Contextconfigure service vprn string aaa remote-servers tacplus authorization request-format
Treerequest-format

Description

Commands in this context configure access operations that are sent to the TACACS+ server during authorization.

Introduced21.10.R3

Platforms

All

access-operation-cmd keyword
Synopsis Access operations sent in authorization requests
Contextconfigure service vprn string aaa remote-servers tacplus authorization request-format access-operation-cmd keyword
Treeaccess-operation-cmd

Description

This command sends an operation argument in authorization requests.

In model-driven interfaces, this command configures the system to send the operation in the cmd argument, and the path in the cmd-args argument, in TACACS+ authorization requests. This command does not apply to authorization requests in classic interfaces.

Optionsdelete
Max. Instances1
Introduced21.10.R3

Platforms

All

use-priv-lvl boolean
Synopsis Allow privilege level mapping
Context configure service vprn string aaa remote-servers tacplus authorization use-priv-lvl boolean
Treeuse-priv-lvl

Description

When configured to true, this command automatically performs a single authorization request to the TACACS+ server for cmd* (all commands) immediately after login, and then uses the local profile associated (via the priv-lvl-map) with the priv-lvl returned by the TACACS+ server for all subsequent authorization (except enable-admin). After the initial authorization for cmd*, no further authorization requests are sent to the TACACS+ server (except enable-admin).

When configured to false, each command is sent to the TACACS+ server for authorization (this is true regardless of whether the tacplus use-default-template setting is enabled).

Defaultfalse
Introduced16.0.R4

Platforms

All

priv-lvl-map
Synopsis Enter the priv-lvl-map context
Contextconfigure service vprn string aaa remote-servers tacplus priv-lvl-map
Treepriv-lvl-map
Introduced16.0.R4

Platforms

All

priv-lvl [level] number
Synopsis Enter the priv-lvl list instance
Contextconfigure service vprn string aaa remote-servers tacplus priv-lvl-map priv-lvl number
Treepriv-lvl
Introduced16.0.R4

Platforms

All

server [index] number
Synopsis Enter the server list instance
Contextconfigure service vprn string aaa remote-servers tacplus server number
Treeserver
Max. Instances5
Introduced16.0.R4

Platforms

All

address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the TACACS+ server
Context configure service vprn string aaa remote-servers tacplus server number address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeaddress

Notes

This element is mandatory.

Introduced16.0.R4

Platforms

All

aarp-interface [interface-name] string
Synopsis Enter the aarp-interface list instance
Contextconfigure service vprn string aarp-interface string
Treeaarp-interface
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[interface-name] string
Synopsis Interface name
Contextconfigure service vprn string aarp-interface string
Treeaarp-interface
String Length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the interface
Contextconfigure service vprn string aarp-interface string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-mtu number
Synopsis IP MTU applied to outgoing packets
Context configure service vprn string aarp-interface string ip-mtu number
Treeip-mtu

Description

This command configures the IP maximum transmission unit (MTU) for the associated router IP interface.

Range512 to 9786
Unitsbytes
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

spoke-sdp [sdp-bind-id] string
Synopsis Enter the spoke-sdp list instance
Contextconfigure service vprn string aarp-interface string spoke-sdp string
Treespoke-sdp
Max. Instances1
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[sdp-bind-id] string
Synopsis SDP binding ID
Contextconfigure service vprn string aarp-interface string spoke-sdp string
Treespoke-sdp
String Length3 to 16

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

aarp
Synopsis Enable the aarp context
Context configure service vprn string aarp-interface string spoke-sdp string aarp
Treeaarp
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

id reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisAARP instance ID
Contextconfigure service vprn string aarp-interface string spoke-sdp string aarp id reference
Treeid

Reference

configure application-assurance aarp number

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisRole of the spoke SDP referenced by the AARP
Contextconfigure service vprn string aarp-interface string spoke-sdp string aarp type keyword
Treetype
Optionssubscriber-side-shunt, network-side-shunt

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of this service SDP binding
Contextconfigure service vprn string aarp-interface string spoke-sdp string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

egress
Synopsis Enter the egress context
Context configure service vprn string aarp-interface string spoke-sdp string egress
Treeegress
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisStatic MPLS VC label to send packets to far-end device
Contextconfigure service vprn string aarp-interface string spoke-sdp string egress vc-label number
Treevc-label
Range16 to 1048575
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ingress
Synopsis Enter the ingress context
Context configure service vprn string aarp-interface string spoke-sdp string ingress
Treeingress
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisVC ingress value that indicates a specific connection
Contextconfigure service vprn string aarp-interface string spoke-sdp string ingress vc-label number
Treevc-label
Range1 to 1048575
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the service
Context configure service vprn string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

aggregates
Synopsis Enter the aggregates context
Context configure service vprn string aggregates
Treeaggregates
Introduced16.0.R1

Platforms

All

aggregate [ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis Enter the aggregate list instance
Contextconfigure service vprn string aggregates aggregate (ipv4-prefix | ipv6-prefix)
Treeaggregate
Introduced16.0.R1

Platforms

All

[ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis Destination IP address prefix of the aggregate route
Contextconfigure service vprn string aggregates aggregate (ipv4-prefix | ipv6-prefix)
Treeaggregate

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

aggregator
Synopsis Enter the aggregator context
Context configure service vprn string aggregates aggregate (ipv4-prefix | ipv6-prefix) aggregator
Treeaggregator
Introduced16.0.R1

Platforms

All

as-set boolean
Synopsis Use AS_SET path segment type for the aggregate route
Contextconfigure service vprn string aggregates aggregate (ipv4-prefix | ipv6-prefix) as-set boolean
Treeas-set

Description

When configured to true, the AS_PATH attribute of the aggregate contains an AS_SET containing all AS numbers from the contributing routes. This can increase the amount of churn due to best-path changes.

When configured to false, the AS_PATH attribute contains no AS_SET and will be originated by the ESR.

Defaultfalse
Introduced16.0.R1

Platforms

All

blackhole
Synopsis Enable the blackhole context
Context configure service vprn string aggregates aggregate (ipv4-prefix | ipv6-prefix) blackhole
Treeblackhole

Notes

The following elements are part of a choice: blackhole or indirect.

Introduced16.0.R1

Platforms

All

generate-icmp boolean
Synopsis Send ICMP unreachable messages for aggregate routes
Contextconfigure service vprn string aggregates aggregate (ipv4-prefix | ipv6-prefix) blackhole generate-icmp boolean
Treegenerate-icmp

Description

When configured to true, ICMP unreachable messages are sent when packets match an aggregate route in the FIB with a black-hole next-hop.

When configured to false, ICMP unreachable messages are not generated.

Defaultfalse
Introduced16.0.R2

Platforms

All

community string
Synopsis Community name that is added to the aggregate route
Contextconfigure service vprn string aggregates aggregate (ipv4-prefix | ipv6-prefix) community string
Treecommunity

Description

This command associates a BGP community with the aggregate route. The community name can be matched in route policies and is automatically added to BGP routes exported from the aggregate route.

String Length1 to 72
Max. Instances12

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

All

indirect (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisAddress of the indirect next hop
Contextconfigure service vprn string aggregates aggregate (ipv4-prefix | ipv6-prefix) indirect (ipv4-address-no-zone | ipv6-address-no-zone)
Treeindirect

Description

This command programs aggregate routes into the forwarding table with an indirect next hop. If a packet matches the aggregate route but not a contributing route, it is forwarded toward the indirect next hop rather than being discarded.

Notes

The following elements are part of a choice: blackhole or indirect.

Introduced16.0.R1

Platforms

All

local-preference number
Synopsis Local preference used when aggregate route is exported
Contextconfigure service vprn string aggregates aggregate (ipv4-prefix | ipv6-prefix) local-preference number
Treelocal-preference

Description

This command configures the local preference value to use when the aggregate route is exported rather than using any of the local preference values assigned for any of the contributing routes.

Range0 to 4294967295
Introduced16.0.R1

Platforms

All

policy reference
Synopsis Policy name for the aggregated route
Context configure service vprn string aggregates aggregate (ipv4-prefix | ipv6-prefix) policy reference
Treepolicy

Description

This command associates an aggregate route with a policy reference. The aggregated route is activated only when there is at least one eligible active route in the sub-trees below it that is accepted by the policy evaluation. There is no evaluation into any sub-tree that starts with another active aggregate route. Eligible routes exclude host routes and LDP shortcut routes.

If an aggregate route has no policy, or the reference is to an empty policy, this configuration is treated as equivalent to a policy with one rule that accepts all routes.

Reference

configure policy-options policy-statement string

Introduced20.10.R1

Platforms

All

summary-only boolean
Synopsis Advertise the aggregate route only
Context configure service vprn string aggregates aggregate (ipv4-prefix | ipv6-prefix) summary-only boolean
Treesummary-only

Description

When configured to true, the router suppresses the advertisement of more specific component routes for the aggregate.

When configured to false, the router advertises both the aggregate route and its contributing routes.

Defaultfalse
Introduced16.0.R1

Platforms

All

tunnel-group number
Synopsis Tunnel group from which to associate the MC IPSec state
Contextconfigure service vprn string aggregates aggregate (ipv4-prefix | ipv6-prefix) tunnel-group number
Treetunnel-group

Description

This command adds the MC-IPsec state of the specific tunnel-group to the aggregate route.

Range1 to 64
Introduced20.7.R1

Platforms

All

autonomous-system number
Synopsis AS number advertised to peers for this router
Contextconfigure service vprn string autonomous-system number
Treeautonomous-system

Description

This command configures the autonomous system (AS) number for the router. This value must be set before BGP can be activated.

If the AS number is changed on a router with an active BGP instance, the new AS number is not used until the BGP instance is restarted.

Range1 to 4294967295
Introduced16.0.R1

Platforms

All

bgp
Synopsis Enable the bgp context
Context configure service vprn string bgp
Treebgp
Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the BGP instance
Contextconfigure service vprn string bgp admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

advertise-inactive boolean
Synopsis Advertise inactive BGP routes to peers
Contextconfigure service vprn string bgp advertise-inactive boolean
Treeadvertise-inactive

Description

When configured to true, this command allows any inactive BGP route to be advertised, even though it is not the used route.

When configured to false, the advertisement of inactive BGP routes to other BGP peers is disabled.

Defaultfalse
Introduced16.0.R1

Platforms

All

aggregator-id-zero boolean
Synopsis Set router ID in the BGP AGGREGATOR attribute to 0
Contextconfigure service vprn string bgp aggregator-id-zero boolean
Treeaggregator-id-zero

Description

When configured to true, the router ID in the BGP AGGREGATOR path attribute is set to 0 when BGP aggregates routes. This prevents different routers within an AS from creating aggregate routes for the same prefix with different path attributes.

When configured to false, the AS number and router ID are added to the AGGREGATOR path attribute.

Defaultfalse
Introduced16.0.R1

Platforms

All

asn-4-byte boolean
Synopsis Advertise support for 4-byte ASNs
Context configure service vprn string bgp asn-4-byte boolean
Treeasn-4-byte
Defaulttrue
Introduced16.0.R1

Platforms

All

attribute-set
Synopsis Enter the attribute-set context
Contextconfigure service vprn string bgp attribute-set
Treeattribute-set

Description

Commands in this context configure the handling of attribute set (ATTR_SET) attributes in BGP routes received from PE-CE peers of the VPRN.

ATTR_SET is an optional transitive BGP path attribute standardized by RFC 6368 that is added to BGP L3 VPN routes to provide logical separation between the BGP domain of a customer and the BGP domain of a service provider.

Introduced23.10.R1

Platforms

All

remove boolean
Synopsis Remove ATTR_SET in received BGP routes from PE-CE peers
Contextconfigure service vprn string bgp attribute-set remove boolean
Treeremove

Description

When configured to true, BGP ignores and silently discards ATTR_SETs in BGP routes received from PE-CE peers of the VPRN. The discarded ATTR_SETs do not affect BGP best path selection in the VPRN, and they do not appear in the VPN-IP routes that result from the VRF export of the BGP routes. Nokia recommends configuring this command to true in most deployments.

When configured to false, BGP ignores ATTR_SETs in BGP routes received from PE-CE peers of the VPRN, but does not discard them. This allows the ATTR_SETs to propagate between CE devices connected to the VPRN and to other PE devices when the BGP routes are exported as VPN-IP routes.

Note: If the configuration of this command is changed, ROUTE_REFRESH messages are sent to all PE-CE peers of the VPRN.

Defaultfalse
Introduced23.10.R1

Platforms

All

authentication-key string
Synopsis BGP authentication key for all peers
Context configure service vprn string bgp authentication-key string
Treeauthentication-key

Description

This command configures the authentication key used to protect all sessions. The stored format of the authentication key is based on the configure system security hash-control management-interface md-cli hash-algorithm setting.

String Length1 to 370
Introduced16.0.R1

Platforms

All

authentication-keychain reference
Synopsis TCP authentication keychain for the session
Contextconfigure service vprn string bgp authentication-keychain reference
Treeauthentication-keychain

Description

This command associates the keychain to be used to authenticate the BGP session. The keychain allows the rollover of authentication keys during the lifetime of a session.

Reference

configure system security keychains keychain string

Introduced16.0.R3

Platforms

All

backup-path
Synopsis Enter the backup-path context
Context configure service vprn string bgp backup-path
Treebackup-path

Description

Commands in this context enable the use of a backup path for specified BGP-learned prefixes belonging to the base router. Multiple paths must be received for a prefix in order to take advantage of this feature. When a prefix has a backup path and its primary paths fail, the affected traffic is rapidly diverted to the backup path without waiting for control plane re-convergence to occur. When many prefixes share the same primary paths and in some cases, the same backup path, the time to divert failover traffic to the backup path is independent of the number of prefixes.

By default, IPv4 and IPv6 prefixes do not have a backup path installed in the IOM.

Introduced16.0.R1

Platforms

All

ipv4 boolean
Synopsis Enable support for unlabeled unicast IPv4 routes
Contextconfigure service vprn string bgp backup-path ipv4 boolean
Treeipv4
Defaultfalse
Introduced16.0.R1

Platforms

All

ipv6 boolean
Synopsis Enable support for unlabeled unicast IPv6 routes
Contextconfigure service vprn string bgp backup-path ipv6 boolean
Treeipv6
Defaultfalse
Introduced16.0.R1

Platforms

All

best-path-selection
Synopsis Enter the best-path-selection context
Contextconfigure service vprn string bgp best-path-selection
Treebest-path-selection
Introduced16.0.R1

Platforms

All

always-compare-med
Synopsis Enter the always-compare-med context
Contextconfigure service vprn string bgp best-path-selection always-compare-med
Treealways-compare-med

Description

Commands in this context determine how the BGP decision process is affected by the MED path attribute.

Introduced16.0.R1

Platforms

All

strict-as boolean
Synopsis Compare MED only for routes from same neighbor AS
Contextconfigure service vprn string bgp best-path-selection always-compare-med strict-as boolean
Treestrict-as

Description

When configured to true, the route selection process can compare the MED path attribute between routes only if they come from the same neighbor AS.

When configured to false, the route selection process can compare the MED path attribute between routes even if they come from different neighbor ASs.

Defaulttrue
Introduced16.0.R1

Platforms

All

as-path-ignore
Synopsis Enter the as-path-ignore context
Contextconfigure service vprn string bgp best-path-selection as-path-ignore
Treeas-path-ignore

Description

Commands in this context determine whether the AS path length is considered in the selection process for routes of the specified address families.

Introduced16.0.R1

Platforms

All

d-path-length-ignore boolean
Synopsis Enable D-PATH length ignore
Context configure service vprn string bgp best-path-selection d-path-length-ignore boolean
Treed-path-length-ignore

Description

When configured to true, this command, enables the router to ignore the D-PATH domain segment length during best-path selection.

At the base router level (or VPRN BGP level for PE-CE routers), this command allows BGP to ignore the D-PATH domain segment length for best-path selection purposes. BGP ignores the D-PATH length when comparing two VPN routes or two IFL routes within the same RD. However, these VPN/IFL routes are processed in the main-BGP instance.

At the VPRN router level, this command allows the VPRN RTM to ignore the D-PATH domain segment length for best-path selection purposes (for routes in VPRN). The user can control whether the RTM considers the D-PATH length when comparing two VPN routes with different RDs.

Best-path selection for EVPN-IFF routes against other owners (for example, EVPN-IFL or IPVPN) still relies on RTM preference. When EVPN-IFF RTM preference matches the RTM preference of another BGP owner, the existing RTM selection applies and D-PATH is not considered, irrespective of the d-path-length-ignore configuration.

When configured to false, this command disables the ability to ignore the D-PATH domain segment length.

Defaultfalse
Introduced21.10.R1

Platforms

All

deterministic-med boolean
Synopsis Group paths based on AS before MED attribute comparison
Contextconfigure service vprn string bgp best-path-selection deterministic-med boolean
Treedeterministic-med

Description

When configured to true, BGP groups paths from the same AS that are equal up to the MED attribute comparison and then compares the best path from each group to select the overall best path. This process ensures that the best-path selection process is deterministic in all cases.

When configured to false, paths are not grouped and the overall best-path selection can depend on the order of route arrival.

Defaultfalse
Introduced16.0.R1

Platforms

All

ebgp-ibgp-equal
Synopsis Enter the ebgp-ibgp-equal context
Contextconfigure service vprn string bgp best-path-selection ebgp-ibgp-equal
Treeebgp-ibgp-equal

Description

Commands in this context allow BGP to ignore the difference between EBGP and IBGP routes in selecting the best path and eligible multipaths (if multipath and ECMP are enabled) for the specified address families. The result is a form of EIBGP load-balancing in a multipath scenario. This behavior can be applied selectively to certain address families.

By default, the BGP decision process prefers an EBGP learned route over an IBGP learned route.

Introduced16.0.R1

Platforms

All

ignore-nh-metric boolean
Synopsis Ignore next-hop distance in best path selection
Contextconfigure service vprn string bgp best-path-selection ignore-nh-metric boolean
Treeignore-nh-metric

Description

When configured to true, BGP ignores the resolved distance to the BGP next hop in its route selection process.

When configured to false, BGP factors the distance to the next hop into its decision process when it compares two BGP routes with the same NLRI learned from base router BGP peers (in the router context) or IP prefix learned from VPRN BGP peers (in the vprn context).

Defaultfalse
Introduced16.0.R1

Platforms

All

ignore-router-id
Synopsis Enable the ignore-router-id context
Contextconfigure service vprn string bgp best-path-selection ignore-router-id
Treeignore-router-id

Description

Commands in this context determine whether the BGP selection process ignores the BGP identifier (router ID) comparison of two EBGP paths from different EBGP peers when determining the best path for the specified address families.

By default, BGP selects the path with the lower router ID when it compares two paths from EBGP peers.

Introduced16.0.R1

Platforms

All

bfd-liveness boolean
Synopsis Enable BFD
Contextconfigure service vprn string bgp bfd-liveness boolean
Treebfd-liveness

Description

When configured to true, BFD is enabled on all BGP sessions, subject to the association of those BGP sessions with IP interfaces that have BFD configurations.

When configured to false, BFD is not enabled globally for all BGP sessions.

Defaultfalse
Introduced16.0.R1

Platforms

All

bfd-strict-mode
Synopsis Enter the bfd-strict-mode context
Contextconfigure service vprn string bgp bfd-strict-mode
Treebfd-strict-mode
Introduced23.7.R1

Platforms

All

advertise
Synopsis Enable the advertise context
Context configure service vprn string bgp bfd-strict-mode advertise
Treeadvertise

Description

Commands in this context configure BGP to advertise the Strict-BFD capability to peers that are within scope of this command and meet the following requirements:

  • The inherited or configured value for the bfd-liveness command that applies to the peer is true.

  • The interface associated with the peer has a valid BFD configuration.

When the preceding conditions are satisfied and two peers attempting to form a session both advertise the Strict-BFD capability, the BGP finite state machine in each router transitions the session state to established after the BFD session with the peer enters the up state.

When unconfigured, BGP does not advertise the Strict-BFD capability to peers.

Introduced23.7.R1

Platforms

All

holdtime number
Synopsis Maximum time BGP waits for the BFD session to come up
Contextconfigure service vprn string bgp bfd-strict-mode advertise holdtime number
Treeholdtime

Description

This command configures the maximum time BGP waits for the BFD session to come up, provided that the Strict-BFD procedures apply to a session, and the negotiated BGP hold time is zero (no keepalives). If the negotiated BGP hold time is greater than zero, the advertised hold time is not considered.

Range1 to 65535
Unitsseconds
Default 30
Introduced23.7.R1

Platforms

All

next-hop-reachability boolean
Synopsis Consider next hop unreachable if BFD session is down
Contextconfigure service vprn string bgp bfd-strict-mode next-hop-reachability boolean
Treenext-hop-reachability

Description

When configured to true, the router considers next-hop self routes belonging to specific address families received from a peer within scope of this command as having an unresolved next hop, provided that the following requirements are met:

  • The BFD session to the peer is in a down state.

  • There is a valid interface BFD configuration that applies to the peer.

  • There is a valid BFD liveness configuration that applies to the peer.

The unresolved state is maintained until the BFD session state changes to up or administratively down, even if there is a resolving route or tunnel that matches the BGP next-hop address.

Routes received from one peer with a BGP next-hop address equal to the address of another peer are not affected by the BFD session to the other peer.

The behavior of the router when this command is true does not depend on whether Strict-BFD is used, as both features are independent.

Configuring this command to true only affects routes belonging to the following address families:

  • IPv4

  • IPv6

  • IPv4 VPN

  • IPv6 VPN

  • labeled unicast IPv4

  • labeled unicast IPv6

  • EVPN

  • IPv4 multicast

  • IPv6 multicast

  • IPv4 VPN multicast

  • IPv6 VPN multicast

When configured to false, the router does not consider next-hop self routes belonging to the preceding address families as having an unresolved next hop if the BFD session goes down.

Defaultfalse
Introduced23.7.R1

Platforms

All

client-reflect boolean
Synopsis Allow client reflection of routes by route reflector
Contextconfigure service vprn string bgp client-reflect boolean
Treeclient-reflect

Description

When configured to true, routes received from neighbors considered to be RR clients are reflected to other peers as expected.

When configured to false, routes received from neighbors considered to be RR clients are not reflected to other clients.

Defaulttrue
Introduced16.0.R1

Platforms

All

cluster
Synopsis Enter the cluster context
Context configure service vprn string bgp cluster
Treecluster
Introduced16.0.R1

Platforms

All

cluster-id string
Synopsis Route reflector cluster ID
Context configure service vprn string bgp cluster cluster-id string
Treecluster-id

Description

The command specifies the cluster ID to associate with the routing instance, effectively making all IBGP peers of the routing instance RR clients.

Introduced16.0.R1

Platforms

All

connect-retry number
Synopsis BGP connect retry timer value
Context configure service vprn string bgp connect-retry number
Treeconnect-retry

Description

This command configures the BGP connect retry timer. When the timer expires, BGP tries to reconnect to the configured peer.

Range1 to 65535
Default120
Introduced 16.0.R1

Platforms

All

convergence
Synopsis Enter the convergence context
Context configure service vprn string bgp convergence
Treeconvergence
Introduced19.7.R1

Platforms

All

family [family-type] keyword
Synopsis Enter the family list instance
Contextconfigure service vprn string bgp convergence family keyword
Treefamily
Introduced19.7.R1

Platforms

All

[family-type] keyword
Synopsis Address family for which convergence selection applies
Contextconfigure service vprn string bgp convergence family keyword
Treefamily
Optionsipv4, ipv6

Notes

This element is part of a list key.

Introduced19.7.R1

Platforms

All

damp-peer-oscillations
Synopsis Enable the damp-peer-oscillations context
Contextconfigure service vprn string bgp damp-peer-oscillations
Treedamp-peer-oscillations

Description

Commands in this context support the DampPeerOscillations FSM behavior described in section 8.1 of RFC 4271, A Border Gateway Protocol 4 (BGP-4).

When unconfigured, the router does not perform peer oscillation damping and immediately transitions out of the idle state after every reset.

Introduced16.0.R1

Platforms

All

error-interval number
Synopsis Time after a reset that the session must be error-free
Contextconfigure service vprn string bgp damp-peer-oscillations error-interval number
Treeerror-interval

Description

This command sets the interval of time after a reset, during which the session must be error-free in order to reset the penalty counter and return the idle hold time to the initial wait time.

Range0 to 2048
Default30
Introduced 16.0.R1

Platforms

All

idle-hold-time
Synopsis Enter the idle-hold-time context
Contextconfigure service vprn string bgp damp-peer-oscillations idle-hold-time
Treeidle-hold-time

Description

Commands in this context configure how long a BGP peer session remains in the idle state after some type of error causes the session to reset.

In the idle state, BGP does not initiate or respond to attempts to establish a new session. Repeated errors that occur in a short time period after each session reset cause longer and longer hold times in the idle state.

Introduced16.0.R1

Platforms

All

second-wait number
Synopsis Time that doubles after each session failure
Contextconfigure service vprn string bgp damp-peer-oscillations idle-hold-time second-wait number
Treesecond-wait

Description

This command defines the hold time that doubles after each repeated session failure that occurs in a short span of time.

Range1 to 2048
Default5
Introduced 16.0.R1

Platforms

All

damping boolean
Synopsis Use BGP route damping to reduce route flap
Contextconfigure service vprn string bgp damping boolean
Treedamping

Description

When configured to true, this command enables route damping to reduce the number of update messages sent between BGP peers and reduce the load on peers without affecting the route convergence time for stable routes.

Route damping is controlled by profiles set in route policies. If no profile is specified in the route policy, the default damping profile is used with the following parameters:

  • Half-life: 15 minutes

  • Max-suppress: 60 minutes

  • Suppress-threshold: 3000

  • Reuse-threshold: 750

When configured to false, BGP route damping for learned routes is disabled.

Defaultfalse
Introduced16.0.R1

Platforms

All

default-label-preference
Synopsis Enter the default-label-preference context
Contextconfigure service vprn string bgp default-label-preference
Treedefault-label-preference
Introduced19.5.R1

Platforms

All

default-preference
Synopsis Enter the default-preference context
Contextconfigure service vprn string bgp default-preference
Treedefault-preference
Introduced19.5.R1

Platforms

All

domain-id string
Synopsis Domain ID of received BGP route before readvertisement
Contextconfigure service vprn string bgp domain-id string
Treedomain-id

Description

This command specifies the domain ID. The domain ID identifies the network from which the BGP route was received before the RTM advertises it to a different neighbor. The domain ID is part of a domain, represented as domain-id:isf_safi_type in the D-PATH attribute, as described in draft-ietf-bess-evpn-ipvpn-interworking. Gateway routers modify the D-PATH attribute. A gateway is a PE where a VPRN is instantiated. The VPRN in this case advertises or receives routes from multiple BGP owners (for example, EVPN-IFL and BGP-IPVPN) or multiple instances of the same owner (for example, VPRN with two BGP-IPVPN instances).

Gateways use the D-PATH attribute to detect loops (for received routes where the D-PATH contains a local domain ID) and to make BGP best-path selection decisions based on the D-PATH length (shorter D-PATH is preferred).

In the following example, suppose a gateway receives prefix P in an EVPN-IFL instance with the following D-PATH from neighbor N:

Seg Len=1 / 65000:1:128

If the router imports the route in VPRN-1, BGP-EVPN SRv6 instance with domain 65000:2, it readvertises it to its BGP-IPVPN MPLS instance as follows:

Seg Len=2 / 65000:2:70 / 65000:1:128

That is, the gateway prepends the local domain ID and family to the D-PATH before readvertising the route into a different instance.

Introduced21.10.R1

Platforms

All

dynamic-neighbor-limit number
Synopsis Max dynamic BGP sessions to accept from remote peers
Contextconfigure service vprn string bgp dynamic-neighbor-limit number
Treedynamic-neighbor-limit

Description

This command configures the maximum number of dynamic BGP sessions to accept from remote peers associated with the entire BGP instance. If accepting a new dynamic session causes the instance limit to be exceeded, the new session attempt is rejected and a Notification message is sent back to the remote peer.

Range1 to 8192
Introduced16.0.R1

Platforms

All

ebgp-default-reject-policy
Synopsis Enter the ebgp-default-reject-policy context
Contextconfigure service vprn string bgp ebgp-default-reject-policy
Treeebgp-default-reject-policy
Introduced19.5.R1

Platforms

All

enforce-first-as boolean
Synopsis Enforce the configured peer AS value in received routes
Contextconfigure service vprn string bgp enforce-first-as boolean
Treeenforce-first-as

Description

When configured to true for an EBGP session, all routes received from an EBGP peer are checked to ensure that the most recent ASN in the AS_PATH attribute of each route matches the configured AS of the session. If there is not a match, the session is reset (if the update-fault-tolerance command in the error-handling context is set to false) or the session is left up but the route is treated as withdrawn (if update-fault-tolerance is set to true).

This command does not flap an established session because it applies only to routes received after the command is issued.

When configured to false, received routes are not checked for compliance with the rule.

Defaultfalse
Introduced16.0.R1

Platforms

All

error-handling
Synopsis Enter the error-handling context
Contextconfigure service vprn string bgp error-handling
Treeerror-handling
Introduced16.0.R1

Platforms

All

update-fault-tolerance boolean
Synopsis Tolerate non-critical errors in UPDATE messages
Contextconfigure service vprn string bgp error-handling update-fault-tolerance boolean
Treeupdate-fault-tolerance

Description

When configured to true, non-critical errors are handled with treat-as-withdraw, attribute-discard, and other non-disruptive approaches that do not cause a session reset. Critical errors still trigger a session reset.

When configured to false, most errors trigger a session reset.

Defaultfalse
Introduced16.0.R1

Platforms

All

export
Synopsis Enable the export context
Context configure service vprn string bgp export
Treeexport
Introduced16.0.R1

Platforms

All

policy (policy-expr-string | string)
Synopsis Export policy name
Context configure service vprn string bgp export policy (policy-expr-string | string)
Treepolicy
String Length1 to 255
Max. Instances15
Min. Instances1

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

All

family
Synopsis Enter the family context
Context configure service vprn string bgp family
Treefamily

Description

Commands in this context specify the BGP address families supported by the base router BGP sessions.

Introduced16.0.R1

Platforms

All

flow-ipv4 boolean
Synopsis Advertise support for the flowspec-IPv4 address family
Contextconfigure service vprn string bgp family flow-ipv4 boolean
Treeflow-ipv4
Defaultfalse
Introduced16.0.R1

Platforms

All

flow-ipv6 boolean
Synopsis Advertise support for the flowspec-IPv6 address family
Contextconfigure service vprn string bgp family flow-ipv6 boolean
Treeflow-ipv6
Defaultfalse
Introduced16.0.R1

Platforms

All

ipv4 boolean
Synopsis Advertise MP-BGP support for the IPv4 address family
Contextconfigure service vprn string bgp family ipv4 boolean
Treeipv4
Defaulttrue
Introduced16.0.R1

Platforms

All

ipv6 boolean
Synopsis Advertise MP-BGP support for the IPv6 address family
Contextconfigure service vprn string bgp family ipv6 boolean
Treeipv6
Defaultfalse
Introduced16.0.R1

Platforms

All

label-ipv4 boolean
Synopsis Advertise support for the label-IPv4 address family
Contextconfigure service vprn string bgp family label-ipv4 boolean
Treelabel-ipv4
Defaultfalse
Introduced16.0.R1

Platforms

All

mcast-ipv4 boolean
Synopsis Advertise support for the MCAST-IPv4 address family
Contextconfigure service vprn string bgp family mcast-ipv4 boolean
Treemcast-ipv4
Defaultfalse
Introduced16.0.R1

Platforms

All

mcast-ipv6 boolean
Synopsis Advertise support for the MCAST-IPv6 address family
Contextconfigure service vprn string bgp family mcast-ipv6 boolean
Treemcast-ipv6
Defaultfalse
Introduced16.0.R1

Platforms

All

fast-external-failover boolean
Synopsis Drop external BGP session immediately when link fails
Contextconfigure service vprn string bgp fast-external-failover boolean
Treefast-external-failover

Description

When configured to true, the router drops an external BGP session to a single-hop neighbor immediately when the local interface goes down.

When configured to false, the BGP session remains up until the hold time expires.

Defaulttrue
Introduced16.0.R1

Platforms

All

flowspec
Synopsis Enter the flowspec context
Context configure service vprn string bgp flowspec
Treeflowspec
Introduced16.0.R1

Platforms

All

validate-dest-prefix boolean
Synopsis Validate destination prefix in FlowSpec-IPv4/IPv6 route
Contextconfigure service vprn string bgp flowspec validate-dest-prefix boolean
Treevalidate-dest-prefix

Description

When configured to true, this command enables validation of received IPv4 and IPv6 FlowSpec routes that contain a destination-prefix subcomponent.

A FlowSpec route with a destination-prefix subcomponent is considered invalid if both of the following are true:

  • it was originated outside the local AS of the receiving BGP router

  • the neighbor AS of the FlowSpec route does not match the neighbor AS of the best match BGP (unicast) route for the destination prefix or the neighbor AS of any longer match BGP (unicast) route for the destination prefix

An invalid route is retained in the BGP but it is not used for filtering traffic or propagated to other BGP routers.

When configured to false, destination-prefix validation is disabled.

Defaultfalse
Introduced16.0.R1

Platforms

All

validate-redirect-ip boolean
Synopsis Validate the redirect-to-IPv4 action in FlowSpec route
Contextconfigure service vprn string bgp flowspec validate-redirect-ip boolean
Treevalidate-redirect-ip

Description

When configured to true, this command enables procedures to validate the redirect-to-IPv4 action attached to FlowSpec-IPv4 routes that are received by the BGP instance.

A FlowSpec-IPv4 route is considered invalid and is not installed as a filter rule if the FlowSpec-IPv4 route is deemed to have originated from a different AS than the IP route that resolves the redirection IPv4 address. The originating AS of a FlowSpec route is determined from its AS path.

When configured to false, the validation check is disabled.

Defaultfalse
Introduced16.0.R1

Platforms

All

graceful-restart
Synopsis Enable the graceful-restart context
Contextconfigure service vprn string bgp graceful-restart
Treegraceful-restart
Introduced16.0.R1

Platforms

All

gr-notification boolean
Synopsis Perform Graceful Restart procedures
Context configure service vprn string bgp graceful-restart gr-notification boolean
Treegr-notification

Description

When configured to true, the Graceful Restart capability sent by the router indicates support for NOTIFICATION messages. If the peer also supports this capability, the session is restarted gracefully (while preserving forwarding) if either peer sends a NOTIFICATION message due to some type of event or error.

When configured to false, NOTIFICATION messages are not supported.

Defaultfalse
Introduced16.0.R1

Platforms

All

long-lived
Synopsis Enable the long-lived context
Context configure service vprn string bgp graceful-restart long-lived
Treelong-lived
Introduced16.0.R1

Platforms

All

family [family-type] keyword
Synopsis Enter the family list instance
Contextconfigure service vprn string bgp graceful-restart long-lived family keyword
Treefamily
Introduced16.0.R1

Platforms

All

[family-type] keyword
Synopsis Address family type for LLGR
Context configure service vprn string bgp graceful-restart long-lived family keyword
Treefamily
Optionsipv4, ipv6, flow-ipv4, flow-ipv6, label-ipv4

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

forwarding-bits-set keyword
Synopsis BGP LLGR forwarding-bit behavior for address family
Contextconfigure service vprn string bgp graceful-restart long-lived forwarding-bits-set keyword
Treeforwarding-bits-set

Description

This command determines the setting of the F bit in the GR and LLGR capabilities advertised by the router. When the F bit is set for an address family, it indicates that the advertising router is able to preserve forwarding state for the routes of that address family across the last restart. When the session is re-established after a restart and the F bit is not set, all stale routes from the peer are immediately removed for the corresponding address family.

This command allows the F bit to be set for all address families or only for non-forwarding address families (L2-VPN, route target, flow-IPv4, and flow-IPv6).

Optionsnone, all, non-fwd
Defaultnone
Introduced16.0.R1

Platforms

All

helper-override-restart-time number
Synopsis Locally-configured override for restart time
Contextconfigure service vprn string bgp graceful-restart long-lived helper-override-restart-time number
Treehelper-override-restart-time

Description

This command overrides the restart time advertised by a peer (in its GR capability) with a locally-configured value. This override applies only to AFI/SAFI that were included in the GR capability of the peer. The restart-time is always zero for AFI/SAFI not included in the GR capability. This command is useful if the local router wants to force the LLGR phase to begin after a set time for all protected AFI/SAFI.

Range0 to 4095
Introduced16.0.R1

Platforms

All

helper-override-stale-time number
Synopsis Locally-configured stale routes override time
Contextconfigure service vprn string bgp graceful-restart long-lived helper-override-stale-time number
Treehelper-override-stale-time

Description

This command configures a locally-imposed LLGR stale time that overrides the long-lived stale routes time that is advertised by the router in its LLGR capability.

This command applies to all AFI/SAFI in the advertised LLGR capability except for any AFI/SAFI with a family-specific override.

Range0 to 16777215
Introduced16.0.R1

Platforms

All

without-no-export boolean
Synopsis Advertise LLGR stale routes to non-LLGR peers
Contextconfigure service vprn string bgp graceful-restart long-lived without-no-export boolean
Treewithout-no-export

Description

When configured to true, LLGR stale routes can be advertised to any peer (EBGP or IBGP) that did not signal the LLGR capability. For IBGP and confederation-EBGP peers that did not advertise the LLGR capability, the local preference attribute in the advertised stale routes is automatically set to 0.

When configured to false, LLGR stale routes are not advertised to any EBGP peer that did not signal the LLGR capability. For IBGP and confederation-EBGP peers that did not advertise the LLGR capability, the local preference attribute in the advertised stale routes is automatically set to 0 and a NO_EXPORT standard community is automatically added to the routes.

Defaultfalse
Introduced16.0.R1

Platforms

All

group [group-name] string
Synopsis Enter the group list instance
Context configure service vprn string bgp group string
Treegroup
Introduced16.0.R1

Platforms

All

[group-name] string
Synopsis BGP peer group name
Context configure service vprn string bgp group string
Treegroup
String Length1 to 64

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the BGP group
Contextconfigure service vprn string bgp group string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

advertise-inactive boolean
Synopsis Advertise an inactive BGP route to peers
Contextconfigure service vprn string bgp group string advertise-inactive boolean
Treeadvertise-inactive

Description

When configured to true, this command allows an inactive BGP route to be advertised, even though it is not the most preferred route. The effect of the command on advertised unlabeled, labeled, and multicast IPv4 and IPv6 routes depends on several factors.

  • If the active route for the IP prefix is a BGP route, that route is advertised.

  • If the active route is a non-BGP route and there are valid inactive BGP routes to the same destination, the best valid inactive route is advertised unless the active non-BGP route is matched and accepted by an export policy applied to the session.

  • If the active route is a non-BGP route and there are no valid BGP routes to the same destination, no route is advertised unless the active non-BGP route is matched and accepted by an export policy applied to the session.

When unconfigured, the command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, the advertisement of inactive BGP routes to other BGP peers is disabled.

Introduced16.0.R1

Platforms

All

as-override boolean
Synopsis Replace the peer's ASN with the local ASN in AS Path
Contextconfigure service vprn string bgp group string as-override boolean
Treeas-override

Description

When configured to true, the advertising router's local AS replaces all occurrences of the peer AS in the AS_PATH attribute.

This command should be used with caution, as it breaks BGP's loop detection mechanism.

When configured to false, no AS override is performed.

Defaultfalse
Introduced16.0.R1

Platforms

All

asn-4-byte boolean
Synopsis Advertise the use of 4-byte ASNs
Context configure service vprn string bgp group string asn-4-byte boolean
Treeasn-4-byte

Description

When this command inherits a value of true, the use of 4-byte ASNs is supported.

When unconfigured, the command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to true.

When configured to false, this command disables the use of 4-byte ASNs.

Introduced16.0.R1

Platforms

All

authentication-key string
Synopsis BGP authentication key for peers in the group
Contextconfigure service vprn string bgp group string authentication-key string
Treeauthentication-key

Description

This command configures the authentication key that must be configured on both peers. The stored format of the authentication key is based on the configure system security hash-control management-interface md-cli hash-algorithm setting.

String Length1 to 370
Introduced16.0.R1

Platforms

All

bfd-liveness boolean
Synopsis Enable BFD
Contextconfigure service vprn string bgp group string bfd-liveness boolean
Treebfd-liveness

Description

When configured to true, BFD is enabled on a given protocol interface where the state of the protocol interface is tied to the state of the BFD session between the local node and the remote node.

When unconfigured, the command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, BFD is removed from the associated protocol adjacency.

Introduced16.0.R1

Platforms

All

bfd-strict-mode
Synopsis Enter the bfd-strict-mode context
Contextconfigure service vprn string bgp group string bfd-strict-mode
Treebfd-strict-mode
Introduced23.7.R1

Platforms

All

advertise
Synopsis Enable the advertise context
Context configure service vprn string bgp group string bfd-strict-mode advertise
Treeadvertise

Description

Commands in this context configure BGP to advertise the Strict-BFD capability to peers that are within scope of this command and meet the following requirements:

  • The inherited or configured value for the bfd-liveness command that applies to the peer is true.

  • The interface associated with the peer has a valid BFD configuration.

When the preceding conditions are satisfied and two peers attempting to form a session both advertise the Strict-BFD capability, the BGP finite state machine in each router transitions the session state to established after the BFD session with the peer enters the up state.

When unconfigured, BGP does not advertise the Strict-BFD capability to peers.

Introduced23.7.R1

Platforms

All

holdtime number
Synopsis Maximum time BGP waits for the BFD session to come up
Contextconfigure service vprn string bgp group string bfd-strict-mode advertise holdtime number
Treeholdtime

Description

This command configures the maximum time BGP waits for the BFD session to come up, provided that the Strict-BFD procedures apply to a session, and the negotiated BGP hold time is zero (no keepalives). If the negotiated BGP hold time is greater than zero, the advertised hold time is not considered.

Range1 to 65535
Unitsseconds
Default 30
Introduced23.7.R1

Platforms

All

next-hop-reachability boolean
Synopsis Consider next hop unreachable if BFD session is down
Contextconfigure service vprn string bgp group string bfd-strict-mode next-hop-reachability boolean
Treenext-hop-reachability

Description

When configured to true, the router considers next-hop self routes belonging to specific address families received from a peer within scope of this command as having an unresolved next hop, provided that the following requirements are met:

  • The BFD session to the peer is in a down state.

  • There is a valid interface BFD configuration that applies to the peer.

  • There is a valid BFD liveness configuration that applies to the peer.

The unresolved state is maintained until the BFD session state changes to up or administratively down, even if there is a resolving route or tunnel that matches the BGP next-hop address.

Routes received from one peer with a BGP next-hop address equal to the address of another peer are not affected by the BFD session to the other peer.

The behavior of the router when this command is true does not depend on whether Strict-BFD is used, as both features are independent.

Configuring this command to true only affects routes belonging to the following address families:

  • IPv4

  • IPv6

  • IPv4 VPN

  • IPv6 VPN

  • labeled unicast IPv4

  • labeled unicast IPv6

  • EVPN

  • IPv4 multicast

  • IPv6 multicast

  • IPv4 VPN multicast

  • IPv6 VPN multicast

When configured to false, the router does not consider next-hop self routes belonging to the preceding address families as having an unresolved next hop if the BFD session goes down.

Introduced23.7.R1

Platforms

All

capability-negotiation boolean
Synopsis Enable capability negotiation
Context configure service vprn string bgp group string capability-negotiation boolean
Treecapability-negotiation

Description

When configured to true, this command enables the exchange of capabilities.

When configured to false and the peering is flapped, new capabilities are not negotiated and strictly IPv4 exchanges are supported with the peer.

Defaulttrue
Introduced16.0.R1

Platforms

All

client-reflect boolean
Synopsis Allow cluster RR to advertise routes to its clients
Contextconfigure service vprn string bgp group string client-reflect boolean
Treeclient-reflect

Description

When unconfigured, this command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to true.

When the command inherits a value of true, client reflection of routes is enabled.

When configured to false, this command disables client reflection of routes.

Introduced16.0.R1

Platforms

All

damp-peer-oscillations
Synopsis Enable the damp-peer-oscillations context
Contextconfigure service vprn string bgp group string damp-peer-oscillations
Treedamp-peer-oscillations

Description

Commands in this context specify how long a BGP peer session remains in the idle state after an error causes the session to reset. In the idle state, BGP does not initiate or respond to attempts to establish a new session. Repeated errors that occur a short time after each session reset cause longer and longer hold times in the idle state.

When unconfigured, command settings are inherited from the global-level configuration.

Introduced16.0.R1

Platforms

All

error-interval number
Synopsis Time after a reset that the session must be error-free
Contextconfigure service vprn string bgp group string damp-peer-oscillations error-interval number
Treeerror-interval

Description

This command sets the interval of time after a reset, during which the session must be error-free in order to reset the penalty counter and return the idle hold time to the initial wait time.

Range0 to 2048
Default30
Introduced 16.0.R1

Platforms

All

idle-hold-time
Synopsis Enter the idle-hold-time context
Contextconfigure service vprn string bgp group string damp-peer-oscillations idle-hold-time
Treeidle-hold-time
Introduced16.0.R1

Platforms

All

second-wait number
Synopsis Time that doubles after each repeated session failure
Contextconfigure service vprn string bgp group string damp-peer-oscillations idle-hold-time second-wait number
Treesecond-wait

Description

This command defines the hold time that doubles after each repeated session failure that occurs in a short span of time.

Range1 to 2048
Default5
Introduced 16.0.R1

Platforms

All

damping boolean
Synopsis Use BGP route damping to reduce route flap
Contextconfigure service vprn string bgp group string damping boolean
Treedamping
Introduced16.0.R1

Platforms

All

default-label-preference
Synopsis Enter the default-label-preference context
Contextconfigure service vprn string bgp group string default-label-preference
Treedefault-label-preference
Introduced19.5.R1

Platforms

All

default-preference
Synopsis Enter the default-preference context
Contextconfigure service vprn string bgp group string default-preference
Treedefault-preference
Introduced19.5.R1

Platforms

All

dynamic-neighbor
Synopsis Enter the dynamic-neighbor context
Contextconfigure service vprn string bgp group string dynamic-neighbor
Treedynamic-neighbor

Description

Commands in this context configure dynamic BGP sessions for a peer group.

Introduced16.0.R1

Platforms

All

interface [interface-name] reference
Synopsis Enter the interface list instance
Contextconfigure service vprn string bgp group string dynamic-neighbor interface reference
Treeinterface

Description

Commands in this context configure an unnumbered VPRN access IP interface for dynamic neighbors.

If this interface connects to a network with other BGP routers, sessions with the other routers can be set up automatically without explicitly configuring them as BGP neighbors. The interface must be IPv6 enabled, but because the interface is considered unnumbered, it does not require an IPv4 address or a global-unicast IPv6 address. The sessions are set up using IPv6 link-local addresses.

The BGP unnumbered feature supports all address families that allow IPv6 link-local BGP next-hop addresses. This includes IPv4 with the use of RFC 8950 extensions.

When an interface is added to the list of dynamic-neighbor interfaces, an outgoing connection attempt is initiated toward any directly connected router on the interface that announces itself using an ICMPv6 router advertisement message. The session attempt is unsuccessful if the peer type is not EBGP, the reported AS number of the peer does not match one of the allowed values, or the maximum session limit of the interface would be exceeded.

Introduced22.10.R1

Platforms

All

allowed-peer-as string
Synopsis Allowed peer AS value or range of acceptable values
Contextconfigure service vprn string bgp group string dynamic-neighbor interface reference allowed-peer-as string
Treeallowed-peer-as

Description

This command specifies a singular allowed peer AS value or a range of acceptable values in the format n1..n2.

All values greater than or equal to n1 and less than or equal to n2 are acceptable. For example, if the acceptable peer AS numbers are 65001 to 65005 (range) and 62100 (singular value), configure this command to use a value of [65001..65005 62100].

Max. Instances32

Notes

This element is ordered by the user.

Introduced22.10.R1

Platforms

All

max-sessions number
Synopsis Maximum number of dynamic sessions allowed
Contextconfigure service vprn string bgp group string dynamic-neighbor interface reference max-sessions number
Treemax-sessions

Description

This command specifies the maximum number of dynamic sessions that are allowed to be set up on the interface as a result of accepting sessions from link-local addresses or initiating sessions by receiving IPv6 router advertisements.

Range1 to 255
Default1
Introduced 22.10.R1

Platforms

All

match
Synopsis Enter the match context
Context configure service vprn string bgp group string dynamic-neighbor match
Treematch
Introduced19.5.R1

Platforms

All

prefix [ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis Enter the prefix list instance
Contextconfigure service vprn string bgp group string dynamic-neighbor match prefix (ipv4-prefix | ipv6-prefix)
Treeprefix
Introduced19.5.R1

Platforms

All

[ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis Dynamic peer prefix for the group
Context configure service vprn string bgp group string dynamic-neighbor match prefix (ipv4-prefix | ipv6-prefix)
Treeprefix

Notes

This element is part of a list key.

Introduced19.5.R1

Platforms

All

allowed-peer-as string
Synopsis Allowed peer AS value or range of acceptable values
Contextconfigure service vprn string bgp group string dynamic-neighbor match prefix (ipv4-prefix | ipv6-prefix) allowed-peer-as string
Treeallowed-peer-as

Description

This command specifies a singular allowed peer AS value or a range of acceptable values in the format n1..n2.

All values greater than or equal to n1 and less than or equal to n2 are acceptable. For example, if the acceptable peer AS numbers are 65001 to 65005 (range) and 62100 (singular value), configure this command to use a value of [65001..65005 62100].

Max. Instances32

Notes

This element is ordered by the user.

Introduced19.5.R1

Platforms

All

dynamic-neighbor-limit number
Synopsis Maximum dynamic BGP sessions to accept from remote peer
Contextconfigure service vprn string bgp group string dynamic-neighbor-limit number
Treedynamic-neighbor-limit

Description

This command configures the maximum number of dynamic BGP sessions that are accepted from remote peers associated with a specific peer group. If accepting a new dynamic session causes the group limit to be exceeded, the new session attempt is rejected and a Notification message is sent back to the remote peer.

When unconfigured, the setting is inherited from the BGP global-level configuration.

Range1 to 8192
Introduced16.0.R1

Platforms

All

ebgp-default-reject-policy
Synopsis Enable the ebgp-default-reject-policy context
Contextconfigure service vprn string bgp group string ebgp-default-reject-policy
Treeebgp-default-reject-policy
Introduced19.5.R1

Platforms

All

error-handling
Synopsis Enter the error-handling context
Contextconfigure service vprn string bgp group string error-handling
Treeerror-handling
Introduced16.0.R1

Platforms

All

update-fault-tolerance boolean
Synopsis Tolerate non-critical errors in UPDATE messages
Contextconfigure service vprn string bgp group string error-handling update-fault-tolerance boolean
Treeupdate-fault-tolerance

Description

When configured to true, non-critical errors are handled with treat-as-withdraw, attribute-discard, and other non-disruptive approaches that do not cause a session reset. Critical errors still trigger a session reset.

When unconfigured, the command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, all errors trigger a session reset.

Introduced16.0.R1

Platforms

All

evpn-link-bandwidth
Synopsis Enter the evpn-link-bandwidth context
Contextconfigure service vprn string bgp group string evpn-link-bandwidth
Treeevpn-link-bandwidth
Introduced22.7.R1

Platforms

All

add-to-received-bgp number
Synopsis Weight added to received PE-CE BGP routes
Contextconfigure service vprn string bgp group string evpn-link-bandwidth add-to-received-bgp number
Treeadd-to-received-bgp

Description

This command configures the weight value added to all BGP PE-CE routes for the purpose of weighted ECMP if EVPN-IFL and BGP PE-CE routes are combined into the same ECMP set.

For the load-balancing betweeen EVPN-IFL and BGP PE-CE routes the configure service vprn bgp eibgp-loadbalance command must already be configured in the system.

Range1 to 128
Introduced22.7.R1

Platforms

All

export
Synopsis Enable the export context
Context configure service vprn string bgp group string export
Treeexport
Introduced16.0.R1

Platforms

All

policy (policy-expr-string | string)
Synopsis Export policy name
Context configure service vprn string bgp group string export policy (policy-expr-string | string)
Treepolicy
String Length1 to 255
Max. Instances15
Min. Instances1

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

All

family
Synopsis Enable the family context
Context configure service vprn string bgp group string family
Treefamily
Introduced16.0.R1

Platforms

All

flow-ipv4 boolean
Synopsis Advertise support for the flowspec-IPv4 address family
Contextconfigure service vprn string bgp group string family flow-ipv4 boolean
Treeflow-ipv4
Defaultfalse
Introduced16.0.R1

Platforms

All

flow-ipv6 boolean
Synopsis Advertise support for the flowspec-IPv6 address family
Contextconfigure service vprn string bgp group string family flow-ipv6 boolean
Treeflow-ipv6
Defaultfalse
Introduced16.0.R1

Platforms

All

ipv4 boolean
Synopsis Add support for the IPv4 address family
Contextconfigure service vprn string bgp group string family ipv4 boolean
Treeipv4
Defaultfalse
Introduced16.0.R1

Platforms

All

ipv6 boolean
Synopsis Advertise MP-BGP support for the IPv6 address family
Contextconfigure service vprn string bgp group string family ipv6 boolean
Treeipv6
Defaultfalse
Introduced16.0.R1

Platforms

All

fast-external-failover boolean
Synopsis Drop external BGP session immediately when link fails
Contextconfigure service vprn string bgp group string fast-external-failover boolean
Treefast-external-failover

Description

When this command inherits a value of true, the router drops an external BGP session on a single-hop route immediately when the local interface goes down.

When unconfigured, the command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to true.

When configured to false, the BGP session remains up until the hold time expires.

Introduced16.0.R1

Platforms

All

graceful-restart
Synopsis Enable the graceful-restart context
Contextconfigure service vprn string bgp group string graceful-restart
Treegraceful-restart
Introduced16.0.R1

Platforms

All

gr-notification boolean
Synopsis Perform graceful restart procedures after NOTIFICATION
Contextconfigure service vprn string bgp group string graceful-restart gr-notification boolean
Treegr-notification

Description

When configured to true, the Graceful Restart capability sent by the router indicates support for NOTIFICATION messages. If the peer also supports this capability, the session is restarted gracefully (while preserving forwarding) if either peer sends a NOTIFICATION message due to some type of event or error.

When configured to false, NOTIFICATION messages are not supported.

Defaultfalse
Introduced16.0.R1

Platforms

All

long-lived
Synopsis Enable the long-lived context
Context configure service vprn string bgp group string graceful-restart long-lived
Treelong-lived
Introduced16.0.R1

Platforms

All

family [family-type] keyword
Synopsis Enter the family list instance
Contextconfigure service vprn string bgp group string graceful-restart long-lived family keyword
Treefamily
Introduced16.0.R1

Platforms

All

[family-type] keyword
Synopsis Address family type for LLGR
Context configure service vprn string bgp group string graceful-restart long-lived family keyword
Treefamily
Optionsipv4, ipv6, flow-ipv4, flow-ipv6, label-ipv4

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

advertised-stale-time number
Synopsis LLGR stale routes time for family override
Contextconfigure service vprn string bgp group string graceful-restart long-lived family keyword advertised-stale-time number
Treeadvertised-stale-time

Description

This command configures the long-lived stale routes time that is advertised by the router in its LLGR capability.

This command applies to all AFI/SAFI in the advertised LLGR capability with a family-specific override.

Range0 to 16777215
Default86400
Introduced 16.0.R1

Platforms

All

helper-override-stale-time number
Synopsis Locally-configured stale routes override time
Contextconfigure service vprn string bgp group string graceful-restart long-lived family keyword helper-override-stale-time number
Treehelper-override-stale-time

Description

This command configures a locally-imposed LLGR stale time that overrides the long-lived stale routes time that is advertised by the router in its LLGR capability. This is a family-specific override value.

Range0 to 16777216
Default16777216
Introduced16.0.R1

Platforms

All

forwarding-bits-set keyword
Synopsis BGP LLGR forwarding-bit behavior for address family
Contextconfigure service vprn string bgp group string graceful-restart long-lived forwarding-bits-set keyword
Treeforwarding-bits-set

Description

This command determines the setting of the F bit in the GR and LLGR capabilities advertised by the router. When the F bit is set for an address family, it indicates that the advertising router is able to preserve forwarding state for the routes of that address family across the last restart. When the session is re-established after a restart and the F bit is not set, all stale routes from the peer are immediately removed for the corresponding address family.

This command allows the F bit to be set for all address families or only for non-forwarding address families (L2-VPN, route target, flow-IPv4, and flow-IPv6).

Optionsnone, all, non-fwd
Defaultnone
Introduced16.0.R1

Platforms

All

helper-override-restart-time number
Synopsis Locally-configured override for restart time
Contextconfigure service vprn string bgp group string graceful-restart long-lived helper-override-restart-time number
Treehelper-override-restart-time

Description

This command overrides the restart time advertised by a peer (in its GR capability) with a locally-configured value. This override applies only to AFI/SAFI that were included in the GR capability of the peer. The restart-time is always zero for AFI/SAFI not included in the GR capability. This command is useful if the local router wants to force the LLGR phase to begin after a set time for all protected AFI/SAFI.

Range0 to 4095
Introduced16.0.R1

Platforms

All

helper-override-stale-time number
Synopsis Locally-configured stale routes override time
Contextconfigure service vprn string bgp group string graceful-restart long-lived helper-override-stale-time number
Treehelper-override-stale-time

Description

This command configures a locally-imposed LLGR stale time that overrides the long-lived stale routes time that is advertised by the router in its LLGR capability.

This command applies to all AFI/SAFI in the advertised LLGR capability except for any AFI/SAFI with a family-specific override.

Range0 to 16777215
Introduced16.0.R1

Platforms

All

without-no-export boolean
Synopsis Advertise LLGR stale routes to non-LLGR peers
Contextconfigure service vprn string bgp group string graceful-restart long-lived without-no-export boolean
Treewithout-no-export

Description

When configured to true, LLGR stale routes can be advertised to any peer (EBGP or IBGP) that did not signal the LLGR capability. For IBGP and confederation-EBGP peers that did not advertise the LLGR capability, the local preference attribute in the advertised stale routes is automatically set to 0.

When configured to false, LLGR stale routes are not advertised to any EBGP peer that did not signal the LLGR capability. For IBGP and confederation-EBGP peers that did not advertise the LLGR capability, the local preference attribute in the advertised stale routes is automatically set to 0 and a NO_EXPORT standard community is automatically added to the routes.

Defaultfalse
Introduced16.0.R1

Platforms

All

hold-time
Synopsis Enter the hold-time context
Context configure service vprn string bgp group string hold-time
Treehold-time
Introduced16.0.R1

Platforms

All

minimum-hold-time number
Synopsis Minimum hold time between successive messages
Contextconfigure service vprn string bgp group string hold-time minimum-hold-time number
Treeminimum-hold-time

Description

This command specifies the minimum hold time that is accepted for the session. If a peer proposes a hold time lower than this value, the session attempt is rejected.

When unconfigured, the command value is inherited from the BGP global-level setting.

Range0 | 3 to 65536
Default0
Introduced 16.0.R1

Platforms

All

seconds number
Synopsis Maximum time BGP waits between successive messages
Contextconfigure service vprn string bgp group string hold-time seconds number
Treeseconds

Description

This command configures the maximum time BGP waits between successive messages (either keepalive or update) from its peer before closing the connection.

Although the implementation allows setting the keepalive timer at the BGP group level times separately, the configured keepalive timer is overridden by this value under the following circumstances.

  • If the specified hold time is less than the configured keepalive time, the operational keepalive time is set to a third of the hold-time; the configured keepalive time is not changed.

  • If the hold time is set to zero, the operational value of the keepalive time is set to zero; the configured keepalive time is not changed. The connection with the peer is up permanently and no keepalive packets are sent to the peer.

When unconfigured, the command setting is inherited from the BGP global-level configuration.

Range0 | 3 to 65535
Introduced16.0.R1

Platforms

All

import
Synopsis Enable the import context
Context configure service vprn string bgp group string import
Treeimport
Introduced16.0.R1

Platforms

All

policy (policy-expr-string | string)
Synopsis Route policy name
Context configure service vprn string bgp group string import policy (policy-expr-string | string)
Treepolicy
String Length1 to 255
Max. Instances15
Min. Instances1

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

All

initial-send-delay-zero boolean
Synopsis Send BGP updates as soon as the session comes up
Contextconfigure service vprn string bgp group string initial-send-delay-zero boolean
Treeinitial-send-delay-zero

Description

When configured to true, BGP updates are sent as soon as the session comes up.

When unconfigured, the command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, BGP waits to send UPDATE messages for the minimum route advertisement time after a session is established.

Introduced16.0.R1

Platforms

All

keepalive number
Synopsis Time after which the BGP KEEPALIVE message is sent
Contextconfigure service vprn string bgp group string keepalive number
Treekeepalive

Description

This command configures the BGP keepalive timer value. A keepalive message is sent every time this timer expires.

This value is generally one-third of the hold time interval configured in the hold-time seconds context. Although the implementation allows this keepalive value and the hold time interval to be independently set, under the following circumstances, the configured keepalive value is overridden by the hold time interval value:

  • If the specified keepalive value is greater than the configured hold time, the specified keepalive value is ignored and the timer value is set to one third of the current hold time value.

  • If the specified hold time interval is less than the configured keepalive value, the keepalive value is reset to one third of the specified hold time interval.

  • If the hold time interval is set to zero, the configured keepalive value is ignored. This means that the connection with the peer is up permanently and no keepalive packets are sent to the peer.

When unconfigured, the command inherits the BGP global-level setting.

Range0 to 21845
Introduced16.0.R1

Platforms

All

link-bandwidth
Synopsis Enter the link-bandwidth context
Contextconfigure service vprn string bgp group string link-bandwidth
Treelink-bandwidth

Description

Commands in this context specify the handling of the Link Bandwidth Extended Community attached to specific BGP routes.

When all used multipaths of an IP prefix correspond to BGP routes with a Link Bandwidth EC, the datapath is programmed to use weighted ECMP across the BGP next hops in proportion to the bandwidth values.

Introduced16.0.R3

Platforms

All

accept-from-ebgp
Synopsis Enter the accept-from-ebgp context
Contextconfigure service vprn string bgp group string link-bandwidth accept-from-ebgp
Treeaccept-from-ebgp
Introduced16.0.R4

Platforms

All

add-to-received-ebgp
Synopsis Enter the add-to-received-ebgp context
Contextconfigure service vprn string bgp group string link-bandwidth add-to-received-ebgp
Treeadd-to-received-ebgp
Introduced16.0.R3

Platforms

All

aggregate-used-paths
Synopsis Enter the aggregate-used-paths context
Contextconfigure service vprn string bgp group string link-bandwidth aggregate-used-paths
Treeaggregate-used-paths
Introduced16.0.R4

Platforms

All

send-to-ebgp
Synopsis Enter the send-to-ebgp context
Contextconfigure service vprn string bgp group string link-bandwidth send-to-ebgp
Treesend-to-ebgp
Introduced16.0.R4

Platforms

All

local-address (ipv4-address-no-zone | ipv6-address-no-zone | interface-name)
Synopsis Local IP address used when communicating with BGP peers
Contextconfigure service vprn string bgp group string local-address (ipv4-address-no-zone | ipv6-address-no-zone | interface-name)
Treelocal-address
String Length1 to 32
Introduced16.0.R1

Platforms

All

local-as
Synopsis Enter the local-as context
Context configure service vprn string bgp group string local-as
Treelocal-as
Introduced16.0.R1

Platforms

All

prepend-global-as boolean
Synopsis Prepend global ASN when advertising routes to BGP peer
Contextconfigure service vprn string bgp group string local-as prepend-global-as boolean
Treeprepend-global-as

Description

When configured to true, the global ASN is added to the AS_PATH attribute in outbound routes sent to the peer.

When configured to false, the global ASN is not included in the AS_PATH attribute.

Defaulttrue
Introduced16.0.R1

Platforms

All

private boolean
Synopsis Hide the local ASN in sent paths learned from peering
Contextconfigure service vprn string bgp group string local-as private boolean
Treeprivate

Description

When configured to true, the local AS number is only advertised to peers that use the local ASN for establishing BGP peering sessions.

When configured to false, the local ASN is advertised to all peers, including those that can use the global ASN for establishing BGP peering sessions.

Defaultfalse
Introduced16.0.R1

Platforms

All

loop-detect keyword
Synopsis Strategy for loop detection in the AS path
Contextconfigure service vprn string bgp group string loop-detect keyword
Treeloop-detect
Optionsdrop-peer, ignore-loop, off, discard-route
Introduced16.0.R1

Platforms

All

med-out (number | keyword)
Synopsis Default MED attribute value to advertise to peers
Contextconfigure service vprn string bgp group string med-out (number | keyword)
Treemed-out
Max. Range0 to 4294967295
Optionsigp-cost
Introduced16.0.R1

Platforms

All

monitor
Synopsis Enable the monitor context
Context configure service vprn string bgp group string monitor
Treemonitor
Introduced16.0.R1

Platforms

All

all-stations boolean
Synopsis Send BMP messages to all configured stations
Contextconfigure service vprn string bgp group string monitor all-stations boolean
Treeall-stations

Description

When configured to true, this command specifies that BMP messages are to be sent to all configured BMP monitoring stations.

When configured to false, the command is not used to indicate the stations which can receive BMP messages. The station command (at the same context level) identifies the BMP stations for which BMP messages are to be sent.

Defaultfalse
Introduced16.0.R1

Platforms

All

route-monitoring
Synopsis Enter the route-monitoring context
Contextconfigure service vprn string bgp group string monitor route-monitoring
Treeroute-monitoring
Introduced16.0.R1

Platforms

All

multihop number
Synopsis TTL in IP packet headers for EBGP peers multi-hops away
Contextconfigure service vprn string bgp group string multihop number
Treemultihop
Range1 to 255
Introduced16.0.R1

Platforms

All

next-hop-self boolean
Synopsis Advertise routes with local address as next-hop address
Contextconfigure service vprn string bgp group string next-hop-self boolean
Treenext-hop-self
Defaultfalse
Introduced16.0.R1

Platforms

All

origin-validation
Synopsis Enter the origin-validation context
Contextconfigure service vprn string bgp group string origin-validation
Treeorigin-validation
Introduced19.7.R1

Platforms

All

passive boolean
Synopsis Enable passive mode for BGP communication
Contextconfigure service vprn string bgp group string passive boolean
Treepassive
Defaultfalse
Introduced16.0.R1

Platforms

All

path-mtu-discovery boolean
Synopsis Enable Path MTU Discovery
Context configure service vprn string bgp group string path-mtu-discovery boolean
Treepath-mtu-discovery

Description

When configured to true, Path MTU Discovery (PMTUD) is enabled for the associated TCP connections.

When set to true, PMTUD is activated toward an IPv4 BGP neighbor and the Don’t Fragment (DF) bit is set in the IP header of all IPv4 packets sent to the peer. If any device along the path toward the peer cannot forward the packet because the IP MTU of the interface is smaller than the IP packet size, this device drops the packet and sends an ICMP or ICMPv6 error message encoding the interface MTU. When the router receives the ICMP or ICMPv6 message, it lowers the TCP maximum segment size limit from the previous value so that the IP MTU constraint can be accommodated.

When configured to false and there is no TCP MSS configuration that can be associated with a BGP neighbor (in either the BGP configuration or the first hop IP interface configuration), the router advertises a value of only 1024 bytes as the TCP MSS option value, limiting received TCP segments to that size.

Introduced16.0.R1

Platforms

All

peer-as number
Synopsis Peer AS number
Contextconfigure service vprn string bgp group string peer-as number
Treepeer-as
Range1 to 4294967295
Introduced16.0.R1

Platforms

All

peer-ip-tracking boolean
Synopsis Enable BGP peer tracking
Context configure service vprn string bgp group string peer-ip-tracking boolean
Treepeer-ip-tracking

Description

When configured to true, this command enables BGP peer tracking.

Peer tracking should be used with caution. Peer tracking can tear a session down even if the loss of connectivity turns out to be short-lived (for example, while the IGP protocol is re-converging). Next-hop tracking, which is always enabled, handles temporary connectivity issues more effectively.

When unconfigured, the command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, peer tracking is disabled.

Introduced16.0.R1

Platforms

All

preference number
Synopsis Route preference for routes learned from all peers
Contextconfigure service vprn string bgp group string preference number
Treepreference
Range1 to 255
Introduced16.0.R1

Platforms

All

prefix-limit [family] keyword
Synopsis Enter the prefix-limit list instance
Contextconfigure service vprn string bgp group string prefix-limit keyword
Treeprefix-limit

Description

Commands in this context limit the number of BGP routes per address family received from a BGP peer and define the actions when crossing the configured maximum.

Introduced16.0.R1

Platforms

All

[family] keyword
Synopsis Address family to which the limit applies
Contextconfigure service vprn string bgp group string prefix-limit keyword
Treeprefix-limit
Optionsipv4, ipv6, mcast-ipv4, flow-ipv4, flow-ipv6, mcast-ipv6, label-ipv4

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

hold-excess number
Synopsis Percentage of maximum routes to install in route table
Contextconfigure service vprn string bgp group string prefix-limit keyword hold-excess number
Treehold-excess

Description

This command specifies the percentage of maximum routes that are allowed to be installed in the route table for the configured address family. If a peer within scope of the configuration exceeds the limit, the overflow routes are held in the BGP RIB as inactive routes and are ineligible for forwarding and advertisement to other peers. If the post-import command is configured to true, only routes not rejected by import policies count toward the limit.

A BGP route in an overflow state is reconsidered for activation and reinstallation when an UPDATE message is received for the route.

This command is mutually exclusive with the idle-timeout and log-only commands.

Range1 to 100
Introduced23.7.R1

Platforms

All

idle-timeout number
Synopsis Time BGP peering remains idle before reconnecting
Contextconfigure service vprn string bgp group string prefix-limit keyword idle-timeout number
Treeidle-timeout

Description

This command configures the time in minutes before a BGP peer is automatically re-established after reaching the prefix limit.

When unconfigured, the BGP peer stays down until the operator performs a reset. This command and log-only cannot be configured simultaneously.

Range1 to 1024
Introduced16.0.R1

Platforms

All

log-only boolean
Synopsis Send warning message at threshold instead of take-down
Contextconfigure service vprn string bgp group string prefix-limit keyword log-only boolean
Treelog-only

Description

When configured to true, the router disables the BGP session from being taken down upon reaching the prefix limit. Instead, only a warning message is sent when the limit is reached. A warning message is also sent when the configured threshold percentage of the limit is reached.

This command and idle-timeout cannot be configured simultaneously.

When configured to false, the router generates a log event and takes the BGP session down upon reaching the prefix limit.

Defaultfalse
Introduced16.0.R1

Platforms

All

maximum number
Synopsis Maximum number of routes to be learned from a peer
Contextconfigure service vprn string bgp group string prefix-limit keyword maximum number
Treemaximum

Description

This command configures the maximum number of BGP routes of the specified address family that can be received from a peer before administrative action is taken.

When log-only is unconfigured, the BGP session is taken down whenever the limit of any family is exceeded even if the limits of the other family has not been exceeded.

Range1 to 4294967295

Notes

This element is mandatory.

Introduced16.0.R2

Platforms

All

post-import boolean
Synopsis Apply limit only to routes accepted by import policies
Contextconfigure service vprn string bgp group string prefix-limit keyword post-import boolean
Treepost-import

Description

When configured to true, the system limits the number of routes that are accepted by import policies. Routes rejected by import policies are not counted against the configured limit.

When configured to false, the system limits the number of routes to all routes received from the peer.

Defaultfalse
Introduced16.0.R1

Platforms

All

remove-private
Synopsis Enable the remove-private context
Contextconfigure service vprn string bgp group string remove-private
Treeremove-private
Introduced16.0.R1

Platforms

All

send-communities
Synopsis Enter the send-communities context
Contextconfigure service vprn string bgp group string send-communities
Treesend-communities
Introduced16.0.R1

Platforms

All

extended boolean
Synopsis Advertise the Extended Communities attribute to peers
Contextconfigure service vprn string bgp group string send-communities extended boolean
Treeextended

Description

When unconfigured, this command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to true.

When this command inherits a value of true, BGP extended communities are sent to peers in the Extended Communities attribute.

When configured to false, all extended communities are removed from all routes advertised to BGP peers.

Introduced16.0.R1

Platforms

All

large boolean
Synopsis Advertise the Large Communities attribute to peers
Contextconfigure service vprn string bgp group string send-communities large boolean
Treelarge

Description

When unconfigured, this command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to true.

When this command inherits a value of true, BGP large communities are sent to peers in the Large Communities attribute.

When configured to false, all large communities are removed from all routes advertised to BGP peers.

Introduced16.0.R1

Platforms

All

standard boolean
Synopsis Advertise the Communities attribute to peers
Contextconfigure service vprn string bgp group string send-communities standard boolean
Treestandard

Description

When unconfigured, this command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to true.

When this command inherits a value of true, BGP standard communities are sent to peers in the Communities attribute.

When configured to false, all standard communities are removed from all routes advertised to BGP peers.

Introduced16.0.R1

Platforms

All

send-default
Synopsis Enable the send-default context
Contextconfigure service vprn string bgp group string send-default
Treesend-default
Introduced19.7.R1

Platforms

All

ipv4 boolean
Synopsis Generate and advertise an IPv4 default route (0/0)
Contextconfigure service vprn string bgp group string send-default ipv4 boolean
Treeipv4
Defaultfalse
Introduced19.7.R1

Platforms

All

ipv6 boolean
Synopsis Generate and advertise an IPv6 default route (::/0)
Contextconfigure service vprn string bgp group string send-default ipv6 boolean
Treeipv6
Defaultfalse
Introduced19.7.R1

Platforms

All

split-horizon boolean
Synopsis Prevent routes being reflected back to best-route peer
Contextconfigure service vprn string bgp group string split-horizon boolean
Treesplit-horizon

Description

When configured to true, this command enables the use of split-horizon.

This command prevents routes from being reflected back to a peer that sends the best route. It applies to routes of all address families and to any type of sending peer; confed-EBGP, EBGP and IBGP.

Enabling the split-horizon functionality may have a detrimental impact on peer and route scaling and should only be used when absolutely necessary.

When unconfigured, the command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, the use of split-horizon is disabled.

Introduced16.0.R1

Platforms

All

tcp-mss (number | keyword)
Synopsis TCP maximum segment size override
Context configure service vprn string bgp group string tcp-mss (number | keyword)
Treetcp-mss

Description

This command configures an override for the TCP maximum segment size to use with a specific peer or set of peers (depending on the scope of the command).

The configured value controls two properties of the TCP connection as follows:

TCP MSS option - The router advertises the TCP MSS option value in the TCP SYN packet it sends as part of the 3-way handshake. The advertised value may be lower than the configured value, depending on the IP MTU of the first hop IP interface. The peers must abide by this value when sending TCP segments to the local router.

TCP maximum segment size - The actual transmitted size may be lower than the configured value, depending on the TCP MSS option value signaled by the peers, the effect of path MTU discovery, or other factors.

Range384 to 9746
Optionsip-stack
Introduced21.2.R1

Platforms

All

third-party-nexthop boolean
Synopsis Apply third-party next-hop processing to EBGP peers
Contextconfigure service vprn string bgp group string third-party-nexthop boolean
Treethird-party-nexthop

Description

When configured to true, this command enables the router to send third-party next hop to EBGP peers in the same subnet as the source peer. The address family of the transport must match the address family of the route.

When an IPv4 or IPv6 route is received from one EBGP peer and advertised to another EBGP peer in the same IP subnet, the BGP next hop is left unchanged.

When unconfigured, the command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, third-party next-hop processing is disabled and the next hop carries the IP address of the interface used to establish the TCP connection to the peer.

Introduced16.0.R1

Platforms

All

ttl-security number
Synopsis Minimum TTL value for an incoming BGP packet
Contextconfigure service vprn string bgp group string ttl-security number
Treettl-security

Description

This command configures the minimum TTL value that BGP accepst from an incoming packet. A packet with a TTL value less than the minimum configured TTL value is discarded.

Range1 to 255
Introduced16.0.R1

Platforms

All

type keyword
Synopsis BGP peer type
Contextconfigure service vprn string bgp group string type keyword
Treetype
Optionsno-type, internal, external
Defaultno-type
Introduced16.0.R1

Platforms

All

hold-time
Synopsis Enter the hold-time context
Context configure service vprn string bgp hold-time
Treehold-time
Introduced16.0.R1

Platforms

All

minimum-hold-time number
Synopsis Minimum hold time between successive messages
Contextconfigure service vprn string bgp hold-time minimum-hold-time number
Treeminimum-hold-time

Description

This command specifies the minimum hold time that is accepted for the session. If a peer proposes a hold time lower than this value, the session attempt is rejected.

Range0 | 3 to 65535
Default0
Introduced 16.0.R1

Platforms

All

seconds number
Synopsis Maximum time BGP waits between successive messages
Contextconfigure service vprn string bgp hold-time seconds number
Treeseconds

Description

This command configures the maximum time BGP waits between successive messages (either keepalive or update) from its peer before closing the connection.

Although the implementation allows setting the keepalive timer at the BGP global level times separately, the configured keepalive timer is overridden by this value under the following circumstances.

  • If the specified hold time is less than the configured keepalive time, the operational keepalive time is set to a third of the hold-time; the configured keepalive time is not changed.

  • If the hold time is set to zero, the operational value of the keepalive time is set to zero; the configured keepalive time is not changed. The connection with the peer is up permanently and no keepalive packets are sent to the peer.

Range0 | 3 to 65535
Default90
Introduced 16.0.R1

Platforms

All

ibgp-multipath boolean
Synopsis Enable IBGP multipath load balancing
Context configure service vprn string bgp ibgp-multipath boolean
Treeibgp-multipath

Description

When configured to true, this command enables IBGP multipath load balancing when adding BGP routes to the route table if the route resolving the BGP next hop offers multiple next hops.

When configured to false, this command disables IBGP multipath load balancing.

Defaultfalse
Introduced16.0.R1

Platforms

All

import
Synopsis Enable the import context
Context configure service vprn string bgp import
Treeimport
Introduced16.0.R1

Platforms

All

policy (policy-expr-string | string)
Synopsis Import policy name
Context configure service vprn string bgp import policy (policy-expr-string | string)
Treepolicy
String Length1 to 255
Max. Instances15
Min. Instances1

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

All

keepalive number
Synopsis Time after which the BGP KEEPALIVE message is sent
Contextconfigure service vprn string bgp keepalive number
Treekeepalive
Range0 to 21845
Default30
Introduced 16.0.R1

Platforms

All

label-preference number
Synopsis Route preference for routes from labeled-unicast peers
Contextconfigure service vprn string bgp label-preference number
Treelabel-preference
Range1 to 255
Default170
Introduced 16.0.R1

Platforms

All

local-as
Synopsis Enter the local-as context
Context configure service vprn string bgp local-as
Treelocal-as
Introduced16.0.R1

Platforms

All

prepend-global-as boolean
Synopsis Prepend global AS when advertising routes to BGP peer
Contextconfigure service vprn string bgp local-as prepend-global-as boolean
Treeprepend-global-as

Description

When configured to true, the global ASN is added to the AS_PATH attribute in outbound routes sent to the peer.

When configured to false, the global ASN is hidden in paths announced to the EBGP peer.

Defaulttrue
Introduced16.0.R1

Platforms

All

private boolean
Synopsis Hide the local ASN in sent paths learned from peering
Contextconfigure service vprn string bgp local-as private boolean
Treeprivate

Description

When configured to true, the local ASN is hidden in paths learned from the peering.

When configured to false, the local ASN is advertised to all peers, including those that can use the global ASN for establishing BGP peering sessions.

Defaultfalse
Introduced16.0.R1

Platforms

All

local-preference number
Synopsis Default local preference if not in incoming routes
Contextconfigure service vprn string bgp local-preference number
Treelocal-preference
Max. Range0 to 4294967295
Default100
Introduced16.0.R1

Platforms

All

loop-detect keyword
Synopsis Strategy for loop detection in the AS path
Contextconfigure service vprn string bgp loop-detect keyword
Treeloop-detect
Optionsdrop-peer, ignore-loop, off, discard-route
Defaultignore-loop
Introduced 16.0.R1

Platforms

All

med-out (number | keyword)
Synopsis Default MED attribute value to advertise to peers
Contextconfigure service vprn string bgp med-out (number | keyword)
Treemed-out
Max. Range0 to 4294967295
Optionsigp-cost
Introduced16.0.R1

Platforms

All

monitor
Synopsis Enable the monitor context
Context configure service vprn string bgp monitor
Treemonitor
Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of BMP monitoring
Contextconfigure service vprn string bgp monitor admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

all-stations boolean
Synopsis Send BMP messages to all configured stations
Contextconfigure service vprn string bgp monitor all-stations boolean
Treeall-stations

Description

When configured to true, this command specifies that BMP messages are to be sent to all configured BMP monitoring stations.

When configured to false, the command is not used to indicate the stations which can receive BMP messages. The station command (at the same context level) identifies the BMP stations for which BMP messages are to be sent.

Defaultfalse
Introduced16.0.R1

Platforms

All

route-monitoring
Synopsis Enter the route-monitoring context
Contextconfigure service vprn string bgp monitor route-monitoring
Treeroute-monitoring
Introduced16.0.R1

Platforms

All

multihop number
Synopsis TTL in IP packet headers for EBGP peers multi-hops away
Contextconfigure service vprn string bgp multihop number
Treemultihop

Description

This command configures the Time to Live (TTL) value entered in the IP header of packets sent to an EBGP peer multiple hops away. This command applies only to EBGP.

Range1 to 255
Introduced16.0.R1

Platforms

All

multipath
Synopsis Enter the multipath context
Context configure service vprn string bgp multipath
Treemultipath
Introduced16.0.R1

Platforms

All

ebgp number
Synopsis Maximum multipaths per prefix for EBGP learned routes
Contextconfigure service vprn string bgp multipath ebgp number
Treeebgp
Range1 to 64
Introduced16.0.R1

Platforms

All

family [family-type] keyword
Synopsis Enter the family list instance
Contextconfigure service vprn string bgp multipath family keyword
Treefamily

Description

Commands in this context set ECMP multipath parameters that apply only to the specified label unicast address family.

When multipath is enabled, traffic to the destination is load-shared across a set of paths (BGP routes) that the BGP decision process considers equal to the best path. The distribution of traffic over the multiple paths may or may not be equal. The distribution is based on weights derived from the Link Bandwidth Extended Community.

For more information about the criteria a non-best route must meet to qualify as a multipath, see “BGP route installation in the route table” in the 7450 ESS 7750 SR 7950 XRS VSR Unicast Routing Protocols User Guide.

Introduced19.5.R1

Platforms

All

[family-type] keyword
Synopsis Address family type for the multipath selection
Contextconfigure service vprn string bgp multipath family keyword
Treefamily
Optionsipv4, ipv6, label-ipv4, label-ipv6

Notes

This element is part of a list key.

Introduced19.5.R1

Platforms

All

ebgp number
Synopsis Maximum multipaths when best path is EBGP learned route
Contextconfigure service vprn string bgp multipath family keyword ebgp number
Treeebgp

Description

This command configures the maximum number of multipaths per prefix or NLRI when the best path is an EBGP learned route. The limit configured using this command overrides the limit configured in the max-paths command. If the best path is an EBGP learned route, and this command is set to 1, multipaths are disabled.

Range1 to 64
Introduced19.5.R1

Platforms

All

ibgp number
Synopsis Maximum multipaths when best path is IBGP learned route
Contextconfigure service vprn string bgp multipath family keyword ibgp number
Treeibgp

Description

This command configures the maximum number of multipaths per prefix or NLRI when the best path is an IBGP learned route. The limit configured using this command overrides the limit configured in the max-paths command. If the best path is an IBGP learned route and this command is set to 1, multipaths are disabled.

Range1 to 64
Introduced19.5.R1

Platforms

All

max-paths number
Synopsis Maximum number of multipaths per prefix or NLRI
Contextconfigure service vprn string bgp multipath family keyword max-paths number
Treemax-paths

Description

This command configures the maximum number of multipaths per prefix or NLRI for the IP family option specified using the family command.

Consider the following when configuring this command: 

  • If the best path is an EBGP-learned route and the ebgp command is configured, the limit configured in the ebgp command overrides the limit configured in this command. 

  • If the best path is an IBGP-learned route and the ibgp command is configured, the limit configured in the ibgp command overrides the limit configured in this command.

  • If the best path is an EBGP-learned route and the ebgp command is not configured, and this command is configured to 1, multipaths are disabled.

  • If the best path is an IBGP-learned route and the ibgp command is not configured, and this command is configured to 1, multipaths are disabled.

Range1 to 64
Introduced19.5.R1

Platforms

All

restrict keyword
Synopsis AS path restriction for the non-best path
Contextconfigure service vprn string bgp multipath family keyword restrict keyword
Treerestrict
Optionssame-as-path-length, same-neighbor-as, exact-as-path
Defaultsame-as-path-length
Introduced19.5.R1

Platforms

All

unequal-cost boolean
Synopsis Ignore differences in the next-hop cost for multipath
Contextconfigure service vprn string bgp multipath family keyword unequal-cost boolean
Treeunequal-cost

Description

When configured to true, BGP ignores differences in the next-hop cost when determining eligible multipaths.

Defaultfalse
Introduced19.5.R1

Platforms

All

ibgp number
Synopsis Maximum multipaths per prefix for IBGP learned routes
Contextconfigure service vprn string bgp multipath ibgp number
Treeibgp
Range1 to 64
Introduced16.0.R1

Platforms

All

restrict keyword
Synopsis AS path restriction for the non-best path
Contextconfigure service vprn string bgp multipath restrict keyword
Treerestrict
Optionssame-as-path-length, same-neighbor-as, exact-as-path
Defaultsame-as-path-length
Introduced16.0.R1

Platforms

All

neighbor [ip-address] (ipv4-address-with-zone | ipv6-address-with-zone)
Synopsis Enter the neighbor list instance
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone)
Treeneighbor
Introduced16.0.R1

Platforms

All

[ip-address] (ipv4-address-with-zone | ipv6-address-with-zone)
Synopsis IP address of the BGP peer router
Context configure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone)
Treeneighbor

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the BGP neighbor
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

advertise-inactive boolean
Synopsis Advertise an inactive BGP route to peers
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) advertise-inactive boolean
Treeadvertise-inactive

Description

When configured to true, this command allows an inactive BGP route to be advertised, even though it is not the most preferred route. The effect of the command on advertised unlabeled, labeled, and multicast IPv4 and IPv6 routes depends on several factors.

  • If the active route for the IP prefix is a BGP route, that route is advertised.

  • If the active route is a non-BGP route and there are valid inactive BGP routes to the same destination, the best valid inactive route is advertised unless the active non-BGP route is matched and accepted by an export policy applied to the session.

  • If the active route is a non-BGP route and there are no valid BGP routes to the same destination, no route is advertised unless the active non-BGP route is matched and accepted by an export policy applied to the session.

When unconfigured, the command inherits the value of the global-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, the advertisement of inactive BGP routes to other BGP peers is disabled.

Introduced16.0.R1

Platforms

All

advertise-ipv6-next-hops
Synopsis Enable the advertise-ipv6-next-hops context
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) advertise-ipv6-next-hops
Treeadvertise-ipv6-next-hops
Introduced19.5.R1

Platforms

All

as-override boolean
Synopsis Replace the peer ASN with the local ASN in AS Path
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) as-override boolean
Treeas-override

Description

When configured to true, the advertising router's local AS replaces all occurrences of the peer AS in the AS_PATH attribute.

This command should be used with caution, as it breaks BGP's loop detection mechanism.

When unconfigured, the command inherits the value of the group-level setting (true or false). This command cannot be explicitly configured to false.

When the command inherits a value of false, no AS override is performed.

Introduced16.0.R1

Platforms

All

asn-4-byte boolean
Synopsis Advertise the use of 4-byte ASNs
Context configure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) asn-4-byte boolean
Treeasn-4-byte
Introduced16.0.R1

Platforms

All

authentication-keychain reference
Synopsis TCP authentication keychain for the session
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) authentication-keychain reference
Treeauthentication-keychain

Description

This command associates the keychain to be used to authenticate the BGP session. The keychain allows the rollover of authentication keys during the lifetime of a session.

Reference

configure system security keychains keychain string

Introduced16.0.R3

Platforms

All

bfd-liveness boolean
Synopsis Enable BFD
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) bfd-liveness boolean
Treebfd-liveness

Description

When configured to true, BFD is enabled on a given protocol interface where the state of the protocol interface is tied to the state of the BFD session between the local node and the remote node.

When unconfigured, the command inherits the value of the group-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, BFD is removed from the associated protocol adjacency.

Introduced16.0.R1

Platforms

All

bfd-strict-mode
Synopsis Enter the bfd-strict-mode context
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) bfd-strict-mode
Treebfd-strict-mode
Introduced23.7.R1

Platforms

All

advertise
Synopsis Enable the advertise context
Context configure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) bfd-strict-mode advertise
Treeadvertise

Description

Commands in this context configure BGP to advertise the Strict-BFD capability to peers that are within scope of this command and meet the following requirements:

  • The inherited or configured value for the bfd-liveness command that applies to the peer is true.

  • The interface associated with the peer has a valid BFD configuration.

When the preceding conditions are satisfied and two peers attempting to form a session both advertise the Strict-BFD capability, the BGP finite state machine in each router transitions the session state to established after the BFD session with the peer enters the up state.

When unconfigured, BGP does not advertise the Strict-BFD capability to peers.

Introduced23.7.R1

Platforms

All

holdtime number
Synopsis Maximum time BGP waits for the BFD session to come up
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) bfd-strict-mode advertise holdtime number
Treeholdtime

Description

This command configures the maximum time BGP waits for the BFD session to come up, provided that the Strict-BFD procedures apply to a session, and the negotiated BGP hold time is zero (no keepalives). If the negotiated BGP hold time is greater than zero, the advertised hold time is not considered.

Range1 to 65535
Unitsseconds
Default 30
Introduced23.7.R1

Platforms

All

next-hop-reachability boolean
Synopsis Consider next hop unreachable if BFD session is down
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) bfd-strict-mode next-hop-reachability boolean
Treenext-hop-reachability

Description

When configured to true, the router considers next-hop self routes belonging to specific address families received from a peer within scope of this command as having an unresolved next hop, provided that the following requirements are met:

  • The BFD session to the peer is in a down state.

  • There is a valid interface BFD configuration that applies to the peer.

  • There is a valid BFD liveness configuration that applies to the peer.

The unresolved state is maintained until the BFD session state changes to up or administratively down, even if there is a resolving route or tunnel that matches the BGP next-hop address.

Routes received from one peer with a BGP next-hop address equal to the address of another peer are not affected by the BFD session to the other peer.The behavior of the router when this command is true does not depend on whether Strict-BFD is used, as both features are independent.

Configuring this command to true only affects routes belonging to the following address families:

  • IPv4

  • IPv6

  • IPv4 VPN

  • IPv6 VPN

  • labeled unicast IPv4

  • labeled unicast IPv6

  • EVPN

  • IPv4 multicast

  • IPv6 multicast

  • IPv4 VPN multicast

  • IPv6 VPN multicast

When configured to false, the router does not consider next-hop self routes belonging to the preceding address families as having an unresolved next hop if the BFD session goes down.

Introduced23.7.R1

Platforms

All

client-reflect boolean
Synopsis Allow cluster RR to advertise routes to its clients
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) client-reflect boolean
Treeclient-reflect
Introduced16.0.R1

Platforms

All

connect-retry number
Synopsis BGP connect retry timer value
Context configure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) connect-retry number
Treeconnect-retry
Range1 to 65535
Introduced16.0.R1

Platforms

All

damp-peer-oscillations
Synopsis Enable the damp-peer-oscillations context
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) damp-peer-oscillations
Treedamp-peer-oscillations
Introduced16.0.R1

Platforms

All

error-interval number
Synopsis Time after a reset that the session must be error-free
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) damp-peer-oscillations error-interval number
Treeerror-interval

Description

This command sets the interval of time after a reset, during which the session must be error-free in order to reset the penalty counter and return the idle hold time to the initial wait time.

Range0 to 2048
Default30
Introduced 16.0.R1

Platforms

All

idle-hold-time
Synopsis Enter the idle-hold-time context
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) damp-peer-oscillations idle-hold-time
Treeidle-hold-time
Introduced16.0.R1

Platforms

All

second-wait number
Synopsis Time that doubles after each repeated session failure
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) damp-peer-oscillations idle-hold-time second-wait number
Treesecond-wait

Description

This command defines the hold time that doubles after each repeated session failure that occurs in a short span of time.

Range1 to 2048
Default5
Introduced 16.0.R1

Platforms

All

damping boolean
Synopsis Use BGP route damping to reduce route flap
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) damping boolean
Treedamping
Introduced16.0.R1

Platforms

All

default-label-preference
Synopsis Enter the default-label-preference context
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) default-label-preference
Treedefault-label-preference
Introduced19.5.R1

Platforms

All

default-preference
Synopsis Enter the default-preference context
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) default-preference
Treedefault-preference
Introduced19.5.R1

Platforms

All

description string
Synopsis Text description
Context configure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) description string
Treedescription
String Length1 to 80
Introduced16.0.R1

Platforms

All

ebgp-default-reject-policy
Synopsis Enable the ebgp-default-reject-policy context
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) ebgp-default-reject-policy
Treeebgp-default-reject-policy
Introduced19.5.R1

Platforms

All

enforce-first-as boolean
Synopsis Enforce the configured peer AS value in received routes
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) enforce-first-as boolean
Treeenforce-first-as

Description

When configured to true for an EBGP session, all routes received from an EBGP peer are checked to ensure that the most recent ASN in the AS_PATH attribute of each route matches the configured AS of the session. If there is not a match, the session is reset (if the update-fault-tolerance command in the error-handling context is set to false) or the session is left up but the route is treated as withdrawn (if update-fault-tolerance is set to true).

This command does not flap an established session because it applies only to routes received after the command is issued.

When unconfigured, the command inherits the value of the group-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, received routes are not checked for compliance with the rule.

Introduced16.0.R1

Platforms

All

error-handling
Synopsis Enter the error-handling context
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) error-handling
Treeerror-handling
Introduced16.0.R1

Platforms

All

update-fault-tolerance boolean
Synopsis Tolerate non-critical errors in UPDATE messages
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) error-handling update-fault-tolerance boolean
Treeupdate-fault-tolerance

Description

When configured to true, non-critical errors are handled with treat-as-withdraw, attribute-discard, and other non-disruptive approaches that do not cause a session reset. Critical errors still trigger a session reset.

When unconfigured, the command inherits the value of the group-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, all errors trigger a session reset.

Introduced16.0.R1

Platforms

All

evpn-link-bandwidth
Synopsis Enter the evpn-link-bandwidth context
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) evpn-link-bandwidth
Treeevpn-link-bandwidth
Introduced22.7.R1

Platforms

All

add-to-received-bgp number
Synopsis Weight added to received PE-CE BGP routes
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) evpn-link-bandwidth add-to-received-bgp number
Treeadd-to-received-bgp

Description

This command configures the weight value added to all BGP PE-CE routes for the purpose of weighted ECMP if EVPN-IFL and BGP PE-CE routes are combined into the same ECMP set.

For the load-balancing betweeen EVPN-IFL and BGP PE-CE routes the configure service vprn bgp eibgp-loadbalance command must already be configured in the system.

Range1 to 128
Introduced22.7.R1

Platforms

All

export
Synopsis Enable the export context
Context configure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) export
Treeexport
Introduced16.0.R1

Platforms

All

policy (policy-expr-string | string)
Synopsis Export policy name
Context configure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) export policy (policy-expr-string | string)
Treepolicy
String Length1 to 255
Max. Instances15
Min. Instances1

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

All

family
Synopsis Enable the family context
Context configure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) family
Treefamily
Introduced16.0.R1

Platforms

All

flow-ipv4 boolean
Synopsis Advertise support for the flowspec-IPv4 address family
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) family flow-ipv4 boolean
Treeflow-ipv4
Defaultfalse
Introduced16.0.R1

Platforms

All

flow-ipv6 boolean
Synopsis Advertise support for the flowspec-IPv6 address family
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) family flow-ipv6 boolean
Treeflow-ipv6
Defaultfalse
Introduced16.0.R1

Platforms

All

ipv4 boolean
Synopsis Add support for the IPv4 address family
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) family ipv4 boolean
Treeipv4
Defaultfalse
Introduced16.0.R1

Platforms

All

ipv6 boolean
Synopsis Advertise MP-BGP support for the IPv6 address family
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) family ipv6 boolean
Treeipv6
Defaultfalse
Introduced16.0.R1

Platforms

All

label-ipv4 boolean
Synopsis Advertise support for the label-IPv4 address family
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) family label-ipv4 boolean
Treelabel-ipv4
Defaultfalse
Introduced16.0.R1

Platforms

All

mcast-ipv4 boolean
Synopsis Advertise support for the MCAST-IPv4 address family
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) family mcast-ipv4 boolean
Treemcast-ipv4
Defaultfalse
Introduced16.0.R1

Platforms

All

mcast-ipv6 boolean
Synopsis Advertise support for the MCAST-IPv6 address family
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) family mcast-ipv6 boolean
Treemcast-ipv6
Defaultfalse
Introduced16.0.R1

Platforms

All

fast-external-failover boolean
Synopsis Drop external BGP session immediately when link fails
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) fast-external-failover boolean
Treefast-external-failover

Description

When this command inherits a value of true, the router drops an external BGP session on a single-hop route immediately when the local interface goes down.

When unconfigured, the command inherits the value of the group-level setting (true or false). The command cannot be explicitly configured to true.

When configured to false, the BGP session remains up until the hold time expires.

Introduced16.0.R1

Platforms

All

graceful-restart
Synopsis Enable the graceful-restart context
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) graceful-restart
Treegraceful-restart
Introduced16.0.R1

Platforms

All

gr-notification boolean
Synopsis Perform graceful restart procedures after NOTIFICATION
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) graceful-restart gr-notification boolean
Treegr-notification

Description

When configured to true, the Graceful Restart capability sent by the router indicates support for NOTIFICATION messages. If the peer also supports this capability, the session is restarted gracefully (while preserving forwarding) if either peer sends a NOTIFICATION message due to some type of event or error.

When configured to false, NOTIFICATION messages are not supported.

Defaultfalse
Introduced16.0.R1

Platforms

All

long-lived
Synopsis Enable the long-lived context
Context configure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) graceful-restart long-lived
Treelong-lived
Introduced16.0.R1

Platforms

All

family [family-type] keyword
Synopsis Enter the family list instance
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) graceful-restart long-lived family keyword
Treefamily
Introduced16.0.R1

Platforms

All

[family-type] keyword
Synopsis Address family type for LLGR
Context configure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) graceful-restart long-lived family keyword
Treefamily
Optionsipv4, ipv6, flow-ipv4, flow-ipv6, label-ipv4

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

advertised-stale-time number
Synopsis LLGR stale routes time for family override
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) graceful-restart long-lived family keyword advertised-stale-time number
Treeadvertised-stale-time

Description

This command configures the long-lived stale routes time that is advertised by the router in its LLGR capability.

This command applies to all AFI/SAFI in the advertised LLGR capability with a family-specific override.

Range0 to 16777215
Default86400
Introduced 16.0.R1

Platforms

All

helper-override-stale-time number
Synopsis Locally-configured stale routes override time
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) graceful-restart long-lived family keyword helper-override-stale-time number
Treehelper-override-stale-time

Description

This command configures a locally-imposed LLGR stale time that overrides the long-lived stale routes time that is advertised by the router in its LLGR capability. This is a family-specific override value.

Range0 to 16777216
Default16777216
Introduced16.0.R1

Platforms

All

forwarding-bits-set keyword
Synopsis BGP LLGR forwarding-bit behavior for address family
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) graceful-restart long-lived forwarding-bits-set keyword
Treeforwarding-bits-set

Description

This command determines the setting of the F bit in the GR and LLGR capabilities advertised by the router. When the F bit is set for an address family, it indicates that the advertising router is able to preserve forwarding state for the routes of that address family across the last restart. When the session is re-established after a restart and the F bit is not set, all stale routes from the peer are immediately removed for the corresponding address family.

This command allows the F bit to be set for all address families or only for non-forwarding address families (L2-VPN, route target, flow-IPv4, and flow-IPv6).

Optionsnone, all, non-fwd
Defaultnone
Introduced16.0.R1

Platforms

All

helper-override-restart-time number
Synopsis Locally-configured override for restart time
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) graceful-restart long-lived helper-override-restart-time number
Treehelper-override-restart-time

Description

This command overrides the restart time advertised by a peer (in its GR capability) with a locally-configured value. This override applies only to AFI/SAFI that were included in the GR capability of the peer. The restart-time is always zero for AFI/SAFI not included in the GR capability. This command is useful if the local router wants to force the LLGR phase to begin after a set time for all protected AFI/SAFI.

Range0 to 4095
Introduced16.0.R1

Platforms

All

helper-override-stale-time number
Synopsis Locally-configured stale routes override time
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) graceful-restart long-lived helper-override-stale-time number
Treehelper-override-stale-time

Description

This command configures a locally-imposed LLGR stale time that overrides the long-lived stale routes time that is advertised by the router in its LLGR capability.

This command applies to all AFI/SAFI in the advertised LLGR capability except for any AFI/SAFI with a family-specific override.

Range0 to 16777215
Introduced16.0.R1

Platforms

All

without-no-export boolean
Synopsis Advertise LLGR stale routes to non-LLGR peers
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) graceful-restart long-lived without-no-export boolean
Treewithout-no-export

Description

When configured to true, LLGR stale routes can be advertised to any peer (EBGP or IBGP) that did not signal the LLGR capability. For IBGP and confederation-EBGP peers that did not advertise the LLGR capability, the local preference attribute in the advertised stale routes is automatically set to 0.

When configured to false, LLGR stale routes are not advertised to any EBGP peer that did not signal the LLGR capability. For IBGP and confederation-EBGP peers that did not advertise the LLGR capability, the local preference attribute in the advertised stale routes is automatically set to 0 and a NO_EXPORT standard community is automatically added to the routes.

Defaultfalse
Introduced16.0.R1

Platforms

All

group reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNeighbor to group
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) group reference
Treegroup

Reference

configure service vprn string bgp group string

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

hold-time
Synopsis Enter the hold-time context
Context configure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) hold-time
Treehold-time
Introduced16.0.R1

Platforms

All

seconds number
Synopsis Maximum hold time between successive messages
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) hold-time seconds number
Treeseconds

Description

The BGP hold time specifies the maximum time BGP waits between successive messages (either keepalive or update) from its peer, before closing the connection.

Even though the implementation allows setting the keepalive timer at the BGP neighbor level times separately, the configured keepalive timer is overridden by this value under the following circumstances:

  • If the specified hold time is less than the configured keepalive time, then the operational keepalive time is set to a third of the hold-time; the configured keepalive time is not changed.

  • If the hold time is set to zero, the operational value of the keepalive time is set to zero; the configured keepalive time is not changed. This means that the connection with the peer is up permanently and no keepalive packets are sent to the peer.

When unconfigured, the command setting is inherited from the BGP group-level configuration.

Range0 | 3 to 65535
Introduced16.0.R1

Platforms

All

import
Synopsis Enable the import context
Context configure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) import
Treeimport
Introduced16.0.R1

Platforms

All

policy (policy-expr-string | string)
Synopsis Route policy name
Context configure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) import policy (policy-expr-string | string)
Treepolicy
String Length1 to 255
Max. Instances15
Min. Instances1

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

All

initial-send-delay-zero boolean
Synopsis Send BGP updates as soon as the session comes up
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) initial-send-delay-zero boolean
Treeinitial-send-delay-zero

Description

When configured to true, BGP updates are sent as soon as the session comes up.

When unconfigured, the command inherits the value of the group-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, BGP waits to send UPDATE messages for the minimum route advertisement time after a session is established.

Introduced16.0.R1

Platforms

All

keepalive number
Synopsis Time after which the BGP KEEPALIVE message is sent
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) keepalive number
Treekeepalive
Range0 to 21845
Introduced16.0.R1

Platforms

All

label-preference number
Synopsis Route preference for routes from labeled-unicast peers
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) label-preference number
Treelabel-preference
Range1 to 255
Introduced16.0.R1

Platforms

All

link-bandwidth
Synopsis Enter the link-bandwidth context
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) link-bandwidth
Treelink-bandwidth
Introduced16.0.R3

Platforms

All

accept-from-ebgp
Synopsis Enable the accept-from-ebgp context
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) link-bandwidth accept-from-ebgp
Treeaccept-from-ebgp
Introduced16.0.R4

Platforms

All

add-to-received-ebgp
Synopsis Enable the add-to-received-ebgp context
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) link-bandwidth add-to-received-ebgp
Treeadd-to-received-ebgp
Introduced16.0.R3

Platforms

All

aggregate-used-paths
Synopsis Enable the aggregate-used-paths context
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) link-bandwidth aggregate-used-paths
Treeaggregate-used-paths
Introduced16.0.R4

Platforms

All

send-to-ebgp
Synopsis Enable the send-to-ebgp context
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) link-bandwidth send-to-ebgp
Treesend-to-ebgp
Introduced16.0.R4

Platforms

All

local-address (ipv4-address-no-zone | ipv6-address-no-zone | interface-name)
Synopsis Local IP address used when communicating with BGP peers
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) local-address (ipv4-address-no-zone | ipv6-address-no-zone | interface-name)
Treelocal-address
String Length1 to 32
Introduced16.0.R1

Platforms

All

local-as
Synopsis Enter the local-as context
Context configure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) local-as
Treelocal-as
Introduced16.0.R1

Platforms

All

as-number number
Synopsis Local (or virtual) BGP AS number
Context configure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) local-as as-number number
Treeas-number
Range1 to 4294967295
Introduced16.0.R1

Platforms

All

prepend-global-as boolean
Synopsis Prepend global ASN when advertising routes to BGP peer
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) local-as prepend-global-as boolean
Treeprepend-global-as

Description

When configured to true, the global ASN is added to the AS_PATH attribute in outbound routes sent to the peer.

When configured to false, the global ASN is not included in the AS_PATH attribute.

Defaulttrue
Introduced16.0.R1

Platforms

All

private boolean
Synopsis Hide the local ASN in sent paths learned from peering
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) local-as private boolean
Treeprivate

Description

When configured to true, the local AS number is only advertised to peers that use the local ASN for establishing BGP peering sessions.

When configured to false, the local ASN is advertised to all peers, including those that can use the global ASN for establishing BGP peering sessions.

Defaultfalse
Introduced16.0.R1

Platforms

All

local-preference number
Synopsis Default local preference if not in incoming routes
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) local-preference number
Treelocal-preference
Range0 to 4294967295
Introduced16.0.R1

Platforms

All

loop-detect keyword
Synopsis Strategy for loop detection in the AS path
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) loop-detect keyword
Treeloop-detect
Optionsdrop-peer, ignore-loop, off, discard-route
Introduced16.0.R1

Platforms

All

med-out (number | keyword)
Synopsis Default MED attribute value to advertise to peers
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) med-out (number | keyword)
Treemed-out
Max. Range0 to 4294967295
Optionsigp-cost
Introduced16.0.R1

Platforms

All

monitor
Synopsis Enable the monitor context
Context configure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) monitor
Treemonitor
Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of BMP monitoring
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) monitor admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

all-stations boolean
Synopsis Send BMP messages to all configured stations
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) monitor all-stations boolean
Treeall-stations

Description

When configured to true, this command specifies that BMP messages are to be sent to all configured BMP monitoring stations.

When configured to false, the command is not used to indicate the stations which can receive BMP messages. The station command (at the same context level) identifies the BMP stations for which BMP messages are to be sent.

Defaultfalse
Introduced16.0.R1

Platforms

All

route-monitoring
Synopsis Enter the route-monitoring context
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) monitor route-monitoring
Treeroute-monitoring
Introduced16.0.R1

Platforms

All

station [station-name] reference
Synopsis Add a list entry for station
Context configure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) monitor station reference
Treestation
Max. Instances8
Introduced16.0.R1

Platforms

All

[station-name] reference
Synopsis BMP monitoring station
Context configure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) monitor station reference
Treestation

Reference

configure bmp station string

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

multihop number
Synopsis TTL in IP packet headers for EBGP peers multi-hops away
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) multihop number
Treemultihop
Range1 to 255
Introduced16.0.R1

Platforms

All

next-hop-self boolean
Synopsis Advertise routes with local address as next-hop address
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) next-hop-self boolean
Treenext-hop-self

Description

When configured to true, this command configures BGP to advertise routes to members of a group using a local address of the BGP instance as the BGP next-hop address.

Note that this command is set without exception, regardless of the route source (EBGP or IBGP) or its family. When used with VPN-IPv4 and VPN-IPv6 routes, the configure router bgp rr-vpn-forwarding command should also be configured.

When unconfigured, the command inherits the value of the group-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, protocol standard behavior is applied to determine whether to set next-hop-self in advertised routes.

Introduced16.0.R1

Platforms

All

origin-validation
Synopsis Enable the origin-validation context
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) origin-validation
Treeorigin-validation
Introduced19.7.R1

Platforms

All

ipv4 boolean
Synopsis Enable support for unlabeled unicast IPv4 routes
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) origin-validation ipv4 boolean
Treeipv4
Defaultfalse
Introduced19.7.R1

Platforms

All

ipv6 boolean
Synopsis Enable support for unlabeled unicast IPv6 routes
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) origin-validation ipv6 boolean
Treeipv6
Defaultfalse
Introduced19.7.R1

Platforms

All

passive boolean
Synopsis Use passive mode for BGP communication
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) passive boolean
Treepassive
Introduced16.0.R1

Platforms

All

path-mtu-discovery boolean
Synopsis Enable path MTU discovery
Context configure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) path-mtu-discovery boolean
Treepath-mtu-discovery

Description

When configured to true, Path MTU Discovery (PMTUD) is enabled for the associated TCP connections.

When set to true, PMTUD is activated toward an IPv4 BGP neighbor and the Don’t Fragment (DF) bit is set in the IP header of all IPv4 packets sent to the peer. If any device along the path toward the peer cannot forward the packet because the IP MTU of the interface is smaller than the IP packet size, this device drops the packet and sends an ICMP or ICMPv6 error message encoding the interface MTU. When the router receives the ICMP or ICMPv6 message, it lowers the TCP maximum segment size limit from the previous value so that the IP MTU constraint can be accommodated.

When PMTUD is configured to false and there is no TCP MSS configuration that can be associated with a BGP neighbor (in either the BGP configuration or the first hop IP interface configuration), the router advertises a value of only 1024 bytes as the TCP MSS option value, limiting received TCP segments to that size.

Introduced16.0.R1

Platforms

All

peer-as number
Synopsis Peer AS number
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) peer-as number
Treepeer-as

Description

This command configures the autonomous system number for the peer. The peer AS number must be configured for each configured peer.

For EBGP peers, the peer AS number configured must be different from the autonomous system number configured for this router under the global level since the peer will be in a different autonomous system than this router.

For IBGP peers, the peer AS number must be the same as the autonomous system number of this router configured under the global level.

Range1 to 4294967295
Introduced16.0.R1

Platforms

All

peer-creation-type keyword
Synopsis Peer creation type
Context configure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) peer-creation-type keyword
Treepeer-creation-type
Optionsstatic, dynamic, dynamic-if-remote, dynamic-if-local
Defaultstatic
Introduced 16.0.R1

Platforms

All

peer-ip-tracking boolean
Synopsis Enable BGP peer tracking
Context configure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) peer-ip-tracking boolean
Treepeer-ip-tracking

Description

When configured to true, this command enables BGP peer tracking.

Peer tracking should be used with caution. Peer tracking can tear a session down even if the loss of connectivity turns out to be short-lived (for example, while the IGP protocol is re-converging). Next-hop tracking, which is always enabled, handles temporary connectivity issues more effectively.

When unconfigured, the command inherits the value of the group-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, peer tracking is disabled.

Introduced16.0.R1

Platforms

All

preference number
Synopsis Route preference for routes learned from all peers
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) preference number
Treepreference

Description

This command configures the route preference for routes learned from the configured peers.

The lower the preference value, the higher the chance of the route being the active route. The router assigns BGP routes the highest default preference as compared to routes that are direct, static or learned via MPLS or OSPF.

When unconfigured, the command setting is inherited from the group-level configuration.

Range1 to 255
Introduced16.0.R1

Platforms

All

prefix-limit [family] keyword
Synopsis Enter the prefix-limit list instance
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) prefix-limit keyword
Treeprefix-limit
Introduced16.0.R1

Platforms

All

[family] keyword
Synopsis Address family to which the limit applies
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) prefix-limit keyword
Treeprefix-limit
Optionsipv4, ipv6, mcast-ipv4, flow-ipv4, flow-ipv6, mcast-ipv6, label-ipv4

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

hold-excess number
Synopsis Percentage of maximum routes to install in route table
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) prefix-limit keyword hold-excess number
Treehold-excess

Description

This command specifies the percentage of maximum routes that are allowed to be installed in the route table for the configured address family. If a peer within scope of the configuration exceeds the limit, the overflow routes are held in the BGP RIB as inactive routes and are ineligible for forwarding and advertisement to other peers. If the post-import command is configured to true, only routes not rejected by import policies count toward the limit.

A BGP route in an overflow state is reconsidered for activation and reinstallation when an UPDATE message is received for the route.

This command is mutually exclusive with the idle-timeout and log-only commands.

Range1 to 100
Introduced23.7.R1

Platforms

All

idle-timeout number
Synopsis Time which BGP peering remains idle before reconnecting
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) prefix-limit keyword idle-timeout number
Treeidle-timeout

Description

This command defines the idle time after an administrative take-down before BGP re-establishes a session and reconnects to a peer.

When unconfigured, the command inherits the value from the group-level configuration.

Range1 to 1024
Introduced16.0.R1

Platforms

All

log-only boolean
Synopsis Send warning message at threshold instead of take-down
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) prefix-limit keyword log-only boolean
Treelog-only
Defaultfalse
Introduced16.0.R1

Platforms

All

maximum number
Synopsis Maximum number of routes to be learned from a peer
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) prefix-limit keyword maximum number
Treemaximum

Description

This command configures the maximum number of BGP routes than can be received from a peer before administrative action is taken.

Range1 to 4294967295

Notes

This element is mandatory.

Introduced16.0.R2

Platforms

All

post-import boolean
Synopsis Apply limit only to routes accepted by import policies
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) prefix-limit keyword post-import boolean
Treepost-import
Defaultfalse
Introduced16.0.R1

Platforms

All

threshold number
Synopsis Percentage threshold that triggers a warning message
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) prefix-limit keyword threshold number
Treethreshold
Range1 to 100
Default90
Introduced 16.0.R1

Platforms

All

remove-private
Synopsis Enable the remove-private context
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) remove-private
Treeremove-private
Introduced16.0.R1

Platforms

All

limited boolean
Synopsis Remove private ASNs up to first public ASN encountered
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) remove-private limited boolean
Treelimited
Defaultfalse
Introduced16.0.R1

Platforms

All

replace boolean
Synopsis Replace private ASN with global ASN before advertising
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) remove-private replace boolean
Treereplace
Defaultfalse
Introduced19.10.R1

Platforms

All

send-communities
Synopsis Enter the send-communities context
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) send-communities
Treesend-communities
Introduced16.0.R1

Platforms

All

extended boolean
Synopsis Advertise the Extended Communities attribute to peers
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) send-communities extended boolean
Treeextended

Description

When unconfigured, this command inherits the value of the group-level setting (true or false). The command cannot be explicitly configured to true.

When this command inherits a value of true, BGP extended communities are sent to peers in the Extended Communities attribute.

When configured to false, all extended communities are removed from all routes advertised to BGP peers.

Introduced16.0.R1

Platforms

All

large boolean
Synopsis Advertise the Large Communities attribute to peers
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) send-communities large boolean
Treelarge

Description

When unconfigured, this command inherits the value of the group-level setting (true or false). The command cannot be explicitly configured to true.

When this command inherits a value of true, BGP large communities are sent to peers in the Large Communities attribute.

When configured to false, all large communities are removed from all routes advertised to BGP peers.

Introduced16.0.R1

Platforms

All

standard boolean
Synopsis Advertise the Communities attribute to peers
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) send-communities standard boolean
Treestandard

Description

When unconfigured, this command inherits the value of the group-level setting (true or false). The command cannot be explicitly configured to true.

When this command inherits a value of true, BGP standard communities are sent to peers in the Communities attribute.

When configured to false, all standard communities are removed from all routes advertised to BGP peers.

Introduced16.0.R1

Platforms

All

send-default
Synopsis Enable the send-default context
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) send-default
Treesend-default
Introduced19.7.R1

Platforms

All

ipv4 boolean
Synopsis Enable IPv4 family type
Context configure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) send-default ipv4 boolean
Treeipv4
Defaultfalse
Introduced19.7.R1

Platforms

All

ipv6 boolean
Synopsis Enable IPv6 family type
Context configure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) send-default ipv6 boolean
Treeipv6
Defaultfalse
Introduced19.7.R1

Platforms

All

split-horizon boolean
Synopsis Prevent routes being reflected back to best-route peer
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) split-horizon boolean
Treesplit-horizon

Description

When configured to true, this command enables the use of split-horizon.

This command prevents routes from being reflected back to a peer that sends the best route. It applies to routes of all address families and to any type of sending peer; confed-EBGP, EBGP and IBGP.

Enabling the split-horizon functionality may have a detrimental impact on peer and route scaling and should only be used when absolutely necessary.

When unconfigured, the command inherits the value of the group-level setting (true or false). The command cannot be explicitly configured to false.

When this command inherits a value of false, the use of split-horizon is disabled.

Introduced16.0.R1

Platforms

All

tcp-mss (number | keyword)
Synopsis TCP maximum segment size override
Context configure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) tcp-mss (number | keyword)
Treetcp-mss

Description

This command configures an override for the TCP maximum segment size to use with a specific peer or set of peers (depending on the scope of the command).

The configured value controls two properties of the TCP connection as follows:

TCP MSS option - The router advertises the TCP MSS option value in the TCP SYN packet it sends as part of the 3-way handshake. The advertised value may be lower than the configured value, depending on the IP MTU of the first hop IP interface. The peers must abide by this value when sending TCP segments to the local router.

TCP maximum segment size - The actual transmitted size may be lower than the configured value, depending on the TCP MSS option value signaled by the peers, the effect of path MTU discovery, or other factors.

Range384 to 9746
Optionsip-stack
Introduced21.2.R1

Platforms

All

ttl-security number
Synopsis Minimum TTL value for an incoming BGP packet
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) ttl-security number
Treettl-security

Description

This command configures the minimum TTL value that BGP will accept from an incoming packet. A packet with a TTL value less than the minimum configured TTL value is discarded.

When unconfigured, the command inherits the value of the group-level setting.

Range1 to 255
Introduced16.0.R1

Platforms

All

type keyword
Synopsis BGP peer type
Contextconfigure service vprn string bgp neighbor (ipv4-address-with-zone | ipv6-address-with-zone) type keyword
Treetype
Optionsno-type, internal, external
Introduced16.0.R1

Platforms

All

next-hop-resolution
Synopsis Enter the next-hop-resolution context
Contextconfigure service vprn string bgp next-hop-resolution
Treenext-hop-resolution
Introduced16.0.R1

Platforms

All

use-bgp-routes boolean
Synopsis Use BGP routes to resolve BGP next hops
Contextconfigure service vprn string bgp next-hop-resolution use-bgp-routes boolean
Treeuse-bgp-routes

Description

When configured to true, BGP routes resolve BGP next hops. When this command is enabled, any unlabeled IPv4 or IPv6 BGP route received from a VPRN BGP peer becomes resolvable by up to four other BGP routes in order to resolve the route to a VPRN IP interface. A VPRN BGP route is not resolvable by another VPRN BGP route or by a BGP-VPN route.

This command also allows unlabeled IPv4 or IPv6 BGP routes leaked from the GRT with unresolved next hops (in the GRT) to be resolvable by BGP-VPN routes (of the VPRN).

When configured to false, BGP next hops are not resolved.

Defaultfalse
Introduced19.10.R1

Platforms

All

use-leaked-routes
Synopsis Enter the use-leaked-routes context
Contextconfigure service vprn string bgp next-hop-resolution use-leaked-routes
Treeuse-leaked-routes
Introduced23.7.R1

Platforms

All

static boolean
Synopsis Use leaked static routes to resolve BGP next hop
Contextconfigure service vprn string bgp next-hop-resolution use-leaked-routes static boolean
Treestatic

Description

When configured to true, the router allows any non-leaked unlabeled unicast IPv4 or IPv6 route in the BGP RIB to be resolved by a leaked static route with direct next hops. A BGP route resolved this way cannot resolve other routes (including BGP routes) and cannot be redistributed into non-BGP protocols, such as IGP.

When configured to false, the router prevents the use of leaked static routes to resolve BGP routes.

Defaultfalse
Introduced23.7.R1

Platforms

All

path-mtu-discovery boolean
Synopsis Enable Path MTU Discovery
Context configure service vprn string bgp path-mtu-discovery boolean
Treepath-mtu-discovery

Description

When configured to true, Path MTU Discovery (PMTUD) is activated toward an IPv4 BGP neighbor. The Don't Fragment (DF) bit is set in the IP header of all IPv4 packets sent to the peer. If any device along the path toward the peer cannot forward the packet because the IP MTU of the interface is smaller than the IP packet size, the device drops the packet and sends an ICMP or ICMPv6 error message encoding the interface MTU. When the router receives the ICMP or ICMPv6 message, it lowers the TCP maximum segment size limit from the previous value to accomodate the IP MTU constraint.

When configured to false, PMTUD is disabled and there is no TCP MSS configuration to associate with a BGP neighbor (in either the BGP configuration or the first-hop IP interface configuration). The router advertises a TCP MSS option of only 1024 bytes, limiting the received TCP segments to that size.

Defaultfalse
Introduced16.0.R1

Platforms

All

peer-tracking-policy reference
Synopsis Policy for BGP peer tracking on router instance
Contextconfigure service vprn string bgp peer-tracking-policy reference
Treepeer-tracking-policy

Description

This command specifies the name of a policy statement to use with the BGP peer-tracking function on BGP sessions where peer tracking is enabled.

When unconfigured, the default peer-tracking policy allows any type of route to match the neighbor IP address except aggregate routes and LDP shortcut routes.

Peer tracking should be used with caution. The peer-tracking policy should only permit one of direct-interface or direct routes to be advertised to a BGP peer. Advertising both routes causes the best route to oscillate.

Reference

configure policy-options policy-statement string

Introduced16.0.R1

Platforms

All

preference number
Synopsis Route preference for routes learned from all peers
Contextconfigure service vprn string bgp preference number
Treepreference

Description

This command configures the route preference for routes learned from the configured peers.

The lower the preference value, the higher the chance of the route being the active route. The router assigns BGP routes the highest default preference as compared to routes that are direct, static or learned via MPLS or OSPF.

Range1 to 255
Default170
Introduced 16.0.R1

Platforms

All

rapid-withdrawal boolean
Synopsis Send BGP withdrawal UPDATE messages immediately
Contextconfigure service vprn string bgp rapid-withdrawal boolean
Treerapid-withdrawal

Description

When configured to true, UPDATE messages containing withdrawn NLRI are sent immediately to a peer without waiting for the MRAI timer to expire. UPDATE messages containing reachable NLRI continue to wait for the MRAI timer to expire, or for a rapid update trigger.

When configured to false, withdrawal processing continues with the normal behavior.

Defaultfalse
Introduced16.0.R1

Platforms

All

remove-private
Synopsis Enable the remove-private context
Contextconfigure service vprn string bgp remove-private
Treeremove-private
Introduced16.0.R1

Platforms

All

rib-management
Synopsis Enter the rib-management context
Contextconfigure service vprn string bgp rib-management
Treerib-management
Introduced16.0.R1

Platforms

All

ipv4
Synopsis Enter the ipv4 context
Context configure service vprn string bgp rib-management ipv4
Treeipv4
Introduced16.0.R1

Platforms

All

leak-import
Synopsis Enter the leak-import context
Context configure service vprn string bgp rib-management ipv4 leak-import
Treeleak-import
Introduced16.0.R1

Platforms

All

policy (policy-expr-string | string)
Synopsis Leak import policy name
Context configure service vprn string bgp rib-management ipv4 leak-import policy (policy-expr-string | string)
Treepolicy

Description

This command specifies one or more leak import policies.

Policy names are limited to 64 characters except for the first policy. Only one object can be a policy logical expression consisting of policy names (enclosed in square brackets) and logical operators (AND, OR, NOT).

String Length1 to 255
Max. Instances15

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

All

route-table-import
Synopsis Enter the route-table-import context
Contextconfigure service vprn string bgp rib-management ipv4 route-table-import
Treeroute-table-import
Introduced16.0.R1

Platforms

All

policy-name reference
Synopsis Name of policy that controls route importation into RIB
Contextconfigure service vprn string bgp rib-management ipv4 route-table-import policy-name reference
Treepolicy-name

Description

This command specifies the name of a policy that controls the importation of active routes from the IP route table into one of the BGP RIBs.

When this command is configured, routes dropped or rejected by the policy are not installed in the associated RIB. Rejected routes cannot be advertised to BGP peers associated with the RIB, but they can still be used to resolve BGP next hops of routes in that RIB. If the active route for a prefix is rejected by the policy, the best BGP route for that prefix in the BGP RIB can be advertised to peers as though it is used.

Aggregate routes are always imported into each RIB, independent of the specified policy.

Route modifications specified in the actions of the policy are ignored and have no effect on the imported routes.

When unconfigured, or if the command refers to an empty policy, all non-BGP routes from the IP route table are imported into the applicable RIB.

Reference

configure policy-options policy-statement string

Introduced16.0.R1

Platforms

All

ipv6
Synopsis Enter the ipv6 context
Context configure service vprn string bgp rib-management ipv6
Treeipv6
Introduced16.0.R1

Platforms

All

leak-import
Synopsis Enter the leak-import context
Context configure service vprn string bgp rib-management ipv6 leak-import
Treeleak-import
Introduced16.0.R1

Platforms

All

policy (policy-expr-string | string)
Synopsis Leak import policy name
Context configure service vprn string bgp rib-management ipv6 leak-import policy (policy-expr-string | string)
Treepolicy

Description

This command specifies one or more leak import policies.

Policy names are limited to 64 characters except for the first policy. Only one object can be a policy logical expression consisting of policy names (enclosed in square brackets) and logical operators (AND, OR, NOT).

String Length1 to 255
Max. Instances15

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

All

route-table-import
Synopsis Enter the route-table-import context
Contextconfigure service vprn string bgp rib-management ipv6 route-table-import
Treeroute-table-import
Introduced16.0.R1

Platforms

All

policy-name reference
Synopsis Name of policy that controls route importation into RIB
Contextconfigure service vprn string bgp rib-management ipv6 route-table-import policy-name reference
Treepolicy-name

Description

This command specifies the name of a policy that controls the importation of active routes from the IP route table into one of the BGP RIBs.

When this command is configured, routes dropped or rejected by the policy are not installed in the associated RIB. Rejected routes cannot be advertised to BGP peers associated with the RIB, but they can still be used to resolve BGP next hops of routes in that RIB. If the active route for a prefix is rejected by the policy, the best BGP route for that prefix in the BGP RIB can be advertised to peers as though it is used.

Aggregate routes are always imported into each RIB, independent of the specified policy.

Route modifications specified in the actions of the policy are ignored and have no effect on the imported routes.

When unconfigured, or if the command refers to an empty policy, all non-BGP routes from the IP route table are imported into the applicable RIB.

Reference

configure policy-options policy-statement string

Introduced16.0.R1

Platforms

All

label-ipv4
Synopsis Enter the label-ipv4 context
Context configure service vprn string bgp rib-management label-ipv4
Treelabel-ipv4
Introduced16.0.R1

Platforms

All

leak-import
Synopsis Enter the leak-import context
Context configure service vprn string bgp rib-management label-ipv4 leak-import
Treeleak-import
Introduced16.0.R1

Platforms

All

policy (policy-expr-string | string)
Synopsis Leak import policy name
Context configure service vprn string bgp rib-management label-ipv4 leak-import policy (policy-expr-string | string)
Treepolicy

Description

This command specifies one or more leak import policies.

Policy names are limited to 64 characters except for the first policy. Only one object can be a policy logical expression consisting of policy names (enclosed in square brackets) and logical operators (AND, OR, NOT).

String Length1 to 255
Max. Instances15

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

All

route-table-import
Synopsis Enter the route-table-import context
Contextconfigure service vprn string bgp rib-management label-ipv4 route-table-import
Treeroute-table-import
Introduced16.0.R1

Platforms

All

policy-name reference
Synopsis Name of policy that controls route importation into RIB
Contextconfigure service vprn string bgp rib-management label-ipv4 route-table-import policy-name reference
Treepolicy-name

Description

This command specifies the name of a policy that controls the importation of active routes from the IP route table into one of the BGP RIBs.

When this command is configured, routes dropped or rejected by the policy are not installed in the associated RIB. Rejected routes cannot be advertised to BGP peers associated with the RIB, but they can still be used to resolve BGP next hops of routes in that RIB. If the active route for a prefix is rejected by the policy, the best BGP route for that prefix in the BGP RIB can be advertised to peers as though it is used.

Aggregate routes are always imported into each RIB, independent of the specified policy.

Route modifications specified in the actions of the policy are ignored and have no effect on the imported routes.

When unconfigured, or if the command refers to an empty policy, all non-BGP routes from the IP route table are imported into the applicable RIB.

Reference

configure policy-options policy-statement string

Introduced16.0.R1

Platforms

All

label-ipv6
Synopsis Enter the label-ipv6 context
Context configure service vprn string bgp rib-management label-ipv6
Treelabel-ipv6
Introduced22.2.R1

Platforms

All

leak-import
Synopsis Enter the leak-import context
Context configure service vprn string bgp rib-management label-ipv6 leak-import
Treeleak-import
Introduced22.2.R1

Platforms

All

policy (policy-expr-string | string)
Synopsis Leak import policy name
Context configure service vprn string bgp rib-management label-ipv6 leak-import policy (policy-expr-string | string)
Treepolicy

Description

This command specifies one or more leak import policies.

Policy names are limited to 64 characters except for the first policy. Only one object can be a policy logical expression consisting of policy names (enclosed in square brackets) and logical operators (AND, OR, NOT).

String Length1 to 255
Max. Instances15

Notes

This element is ordered by the user.

Introduced22.2.R1

Platforms

All

router-id string
Synopsis Router ID for the BGP instance in the AS
Contextconfigure service vprn string bgp router-id string
Treerouter-id

Description

This command specifies the router ID to be used with the BGP instance.

Changing the BGP router ID on an active BGP instance causes the BGP instance to restart with the new router ID.

When an SR OS is configured with an IPv6-only BOF and no IPv4 system interface address, explicitly-defined IPv4 router IDs are required for BGP as there is no mechanism to derive the router ID from an IPv6 system interface address.

Introduced16.0.R1

Platforms

All

send-communities
Synopsis Enter the send-communities context
Contextconfigure service vprn string bgp send-communities
Treesend-communities
Introduced16.0.R1

Platforms

All

send-default
Synopsis Enter the send-default context
Contextconfigure service vprn string bgp send-default
Treesend-default
Introduced19.7.R1

Platforms

All

split-horizon boolean
Synopsis Prevent routes being reflected back to best-route peer
Contextconfigure service vprn string bgp split-horizon boolean
Treesplit-horizon

Description

When configured to true, this command enables the use of split-horizon.

This command prevents routes from being reflected back to a peer that sends the best route. It applies to routes of all address families and to any type of sending peer; confed-EBGP, EBGP and IBGP.

Enabling the split-horizon functionality may have a detrimental impact on peer and route scaling and should only be used when absolutely necessary.

When configured to false, the use of split-horizon is disabled.

Defaultfalse
Introduced16.0.R1

Platforms

All

tcp-mss number
Synopsis TCP maximum segment size override
Context configure service vprn string bgp tcp-mss number
Treetcp-mss

Description

This command configures an override for the TCP maximum segment size to use with a specific peer or set of peers (depending on the scope of the command).

The configured value controls two properties of the TCP connection as follows:

TCP MSS option - The router advertises the TCP MSS option value in the TCP SYN packet it sends as part of the 3-way handshake. The advertised value may be lower than the configured value, depending on the IP MTU of the first hop IP interface. The peers must abide by this value when sending TCP segments to the local router.

TCP maximum segment size - The actual transmitted size may be lower than the configured value, depending on the TCP MSS option value signaled by the peers, the effect of path MTU discovery, or other factors.

Range384 to 9746
Introduced21.2.R1

Platforms

All

third-party-nexthop boolean
Synopsis Apply third-party next-hop processing to EBGP peers
Contextconfigure service vprn string bgp third-party-nexthop boolean
Treethird-party-nexthop

Description

When configured to true, this command enables the router to send third-party next hop to EBGP peers in the same subnet as the source peer. The address family of the transport must match the address family of the route.

When an IPv4 or IPv6 route is received from one EBGP peer and advertised to another EBGP peer in the same IP subnet, the BGP next hop is left unchanged.

When configured to false, third-party next-hop processing is disabled and the next hop carries the IP address of the interface used to establish the TCP connection to the peer.

Defaultfalse
Introduced16.0.R1

Platforms

All

bgp-evpn
Synopsis Enter the bgp-evpn context
Context configure service vprn string bgp-evpn
Treebgp-evpn
Introduced20.10.R1

Platforms

All

mpls [bgp-instance] number
Synopsis Enter the mpls list instance
Context configure service vprn string bgp-evpn mpls number
Treempls
Introduced20.10.R1

Platforms

All

[bgp-instance] number
Synopsis BGP instance ID
Context configure service vprn string bgp-evpn mpls number
Treempls
Range1

Notes

This element is part of a list key.

Introduced20.10.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of BGP-EVPN MPLS
Contextconfigure service vprn string bgp-evpn mpls number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced20.10.R1

Platforms

All

auto-bind-tunnel
Synopsis Enter the auto-bind-tunnel context
Contextconfigure service vprn string bgp-evpn mpls number auto-bind-tunnel
Treeauto-bind-tunnel

Description

Commands in this context configure the automatic binding parameters of a BGP-EVPN service using tunnels to MP-BGP peers.

Introduced20.10.R1

Platforms

All

allow-flex-algo-fallback boolean
Synopsis Enable flexible algorithm fallback
Context configure service vprn string bgp-evpn mpls number auto-bind-tunnel allow-flex-algo-fallback boolean
Treeallow-flex-algo-fallback

Description

When configured to true, a BGP router with a Flex-Algorithm action configured (via the configure policy-options policy-statement entry action flex-algo command) can resolve to a tunnel with algorithm 0 if no target Flex-Algorithm tunnel is available.

When configured to false, the BGP router can resolve only to the intended Flex-Algorithm tunnel, which may cause traffic loss if no corresponding Flex-Algorithm tunnel is available.

Defaultfalse
Introduced20.10.R3

Platforms

All

resolution-filter
Synopsis Enter the resolution-filter context
Contextconfigure service vprn string bgp-evpn mpls number auto-bind-tunnel resolution-filter
Treeresolution-filter

Description

Commands in this context configure the subset of tunnel types that can be used in the resolution of BGP-EVPN routes within the automatic binding of the BGP-EVPN MPLS service to tunnels to MP-BGP peers.

Introduced20.10.R1

Platforms

All

bgp boolean
Synopsis Use BGP tunneling for next-hop resolution
Contextconfigure service vprn string bgp-evpn mpls number auto-bind-tunnel resolution-filter bgp boolean
Treebgp

Description

When configured to true, BGP searches the BGP LSP for the address of the BGP next hop.

When configured to false, BGP tunneling is not used and inter-area or inter-as prefixes are not resolved.

Defaultfalse
Introduced20.10.R1

Platforms

All

ldp boolean
Synopsis Use LDP tunneling for next-hop resolution
Contextconfigure service vprn string bgp-evpn mpls number auto-bind-tunnel resolution-filter ldp boolean
Treeldp

Description

When configured to true, BGP searches for an LDP LSP with a FEC prefix corresponding to the address of the BGP next hop.

When configured to false, LDP tunneling is not used for next-hop resolution.

Defaultfalse
Introduced20.10.R1

Platforms

All

mpls-fwd-policy boolean
Synopsis Use MPLS forwarding policy for next-hop resolution
Contextconfigure service vprn string bgp-evpn mpls number auto-bind-tunnel resolution-filter mpls-fwd-policy boolean
Treempls-fwd-policy

Description

When configured to true, BGP uses the MPLS forwarding policy to determine the address of the BGP next hop.

When configured to false, the MPLS forwarding policy is not used for next-hop resolution.

Defaultfalse
Introduced20.10.R1

Platforms

All

rib-api boolean
Synopsis Use RIB API gRPC service for next-hop resolution
Contextconfigure service vprn string bgp-evpn mpls number auto-bind-tunnel resolution-filter rib-api boolean
Treerib-api

Description

When configured to true, BGP uses tunnels programmed using the RIB API gRPC service to resolve the next hops of routes imported into the EVPN service.

When configured to false, the RIB API service tunnels are not used for next-hop resolution.

Defaultfalse
Introduced20.10.R1

Platforms

All

rsvp boolean
Synopsis Use RSVP tunneling for next-hop resolution
Contextconfigure service vprn string bgp-evpn mpls number auto-bind-tunnel resolution-filter rsvp boolean
Treersvp

Description

When configured to true, BGP searches the best metric RSVP LSP to determine the address of the BGP next hop. This address can correspond to the system interface or to another loopback interface used by the BGP instance on the remote node. The LSP metric is provided by MPLS in the tunnel table. In the case of multiple RSVP LSPs with the same lowest metric, BGP selects the LSP with the lowest tunnel ID.

When configured to false, the RSVP LSP is not used for next-hop resolution.

Defaultfalse
Introduced20.10.R1

Platforms

All

sr-isis boolean
Synopsis Use IS-IS SR tunneling for next-hop resolution
Contextconfigure service vprn string bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-isis boolean
Treesr-isis

Description

When configured to true, BGP uses an IS-IS tunnel type to determine the address of the BGP next hop.

The SR tunnel to the BGP next hop is selected in the TTM from the lowest-numbered IS-IS instance.

When configured to false, IS-IS tunneling is not used for next-hop resolution.

Defaultfalse
Introduced20.10.R1

Platforms

All

sr-ospf boolean
Synopsis Use OSPF SR tunneling for next-hop resolution
Contextconfigure service vprn string bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-ospf boolean
Treesr-ospf

Description

When configured to true, BGP uses an OSPF tunnel type to determine the address of the BGP next hop.

The SR tunnel to the BGP next hop is selected in the TTM from the lowest-numbered OPSF instance.

When configured to false, OSPF tunneling is not used for next-hop resolution.

Defaultfalse
Introduced20.10.R1

Platforms

All

sr-ospf3 boolean
Synopsis Use OSPFv3 SR tunneling for next-hop resolution
Contextconfigure service vprn string bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-ospf3 boolean
Treesr-ospf3

Description

When configured to true, BGP uses an OSPF3 tunnel type to determine the address of the BGP next hop.

The SR tunnel to the BGP next hop is selected in the TTM from the lowest-numbered OPSF3 instance.

When configured to false, OSPF3 tunneling is not used for next-hop resolution.

Defaultfalse
Introduced20.10.R1

Platforms

All

sr-policy boolean
Synopsis Use SR policies for next-hop resolution
Contextconfigure service vprn string bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-policy boolean
Treesr-policy

Description

When configured to true, this command instructs BGP to use an SR policy to determine the address of the BGP next hop. The SR policy search criteria includes a non-null endpoint and color value that matches the BGP next hop and color extended community value, respectively, of the EVPN route.

When configured to false, SR policies are not used for next-hop resolution.

Defaultfalse
Introduced20.10.R1

Platforms

All

sr-te boolean
Synopsis Use SR-TE tunneling for next-hop resolution
Contextconfigure service vprn string bgp-evpn mpls number auto-bind-tunnel resolution-filter sr-te boolean
Treesr-te

Description

When configured to true, BGP uses an SR-TE tunnel type to determine the address of the BGP next hop.

The SR tunnel to the BGP next hop is selected in the TTM from the lowest-numbered tunnel ID.

When configured to false, SR-TE tunneling is not used for next-hop resolution.

Defaultfalse
Introduced20.10.R1

Platforms

All

udp boolean
Synopsis Use MPLS over UDP tunneling for next-hop resolution
Contextconfigure service vprn string bgp-evpn mpls number auto-bind-tunnel resolution-filter udp boolean
Treeudp

Description

When configured to true, BGP uses an MPLS over UDP tunnel type to determine the address of the BGP next hop.

When configured to false, MPLS over UDP tunneling is not used for next-hop resolution.

Defaultfalse
Introduced20.10.R1

Platforms

All

default-route-tag string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDefault route tag
Contextconfigure service vprn string bgp-evpn mpls number default-route-tag string
Treedefault-route-tag

Description

This command configures a route tag that is used when sending a route to the BGP application (for the corresponding service and BGP instance). If the corresponding BGP instance is enabled, the command cannot be changed.

When used for BGP EVPN contexts, only one route tag can be passed to BGP for matching on export policies. In case of a conflict with other route tags pushed by EVPN, the default route tag has the least priority. 

The following are examples of the conflict priority handling:

  • If a service is configured with both default-route-tag X and proxy-arp evpn-route-tag Y, the EVPN uses route tag Y when sending EVPN proxy-arp routes to the BGP RIB for advertisement.

  • If a given IP-prefix route is tagged in the route-table with tag A and the R-VPLS, in which the route is advertised, uses B as the default-route-tag, then EVPN keeps tag A when sending the route to the BGP RIB.

The default-route-tag configuration is only supported on EVPN and IP-VPN service routes. The route tag for ES and AD per-ES routes is always zero.

Introduced20.10.R1

Platforms

All

domain-id string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDomain ID of received BGP route before readvertisement
Contextconfigure service vprn string bgp-evpn mpls number domain-id string
Treedomain-id

Description

This command specifies the domain ID. The domain ID identifies the network from which the BGP route was received before the RTM advertises it to a different neighbor. The domain ID is part of a domain, represented as domain-id:isf_safi_type in the D-PATH attribute, as described in draft-ietf-bess-evpn-ipvpn-interworking. Gateway routers modify the D-PATH attribute. A gateway is a PE where a VPRN is instantiated. The VPRN in this case advertises or receives routes from multiple BGP owners (for example, EVPN-IFL and BGP-IPVPN) or multiple instances of the same owner (for example, VPRN with two BGP-IPVPN instances).

Gateways use the D-PATH attribute to detect loops (for received routes where the D-PATH contains a local domain ID) and to make BGP best-path selection decisions based on the D-PATH length (shorter D-PATH is preferred).

In the following example, suppose a gateway receives prefix P in an EVPN-IFL instance with the following D-PATH from neighbor N:

Seg Len=1 / 65000:1:128

If the router imports the route in VPRN-1, BGP-EVPN SRv6 instance with domain 65000:2, it readvertises it to its BGP-IPVPN MPLS instance as follows:

Seg Len=2 / 65000:2:70 / 65000:1:128

That is, the gateway prepends the local domain ID and family to the D-PATH before readvertising the route into a different instance.

Introduced21.10.R1

Platforms

All

dynamic-egress-label-limit boolean
Synopsis Enables dynamic egress label limit
Context configure service vprn string bgp-evpn mpls number dynamic-egress-label-limit boolean
Treedynamic-egress-label-limit

Description

When configured to true, this command relaxes the egress MPLS label limit check when resolving BGP next hops in the tunnel table.

For VPRN services, the OAM label is never computed and, therefore, one more egress label is allowed.

For EVPN (Epipe and VPLS) services, the system only computes the control word and ESI label if they are used. For the control word, the system reduces the egress label limit by one label if the control word is configured in the service. When configured, the ESI label is not counted for Epipes or VPLS services without an ES.

When configured to false this command, for EVPN, Epipe, and VPLS services, always accounts for the ESI label and control word.

Defaultfalse
Introduced22.2.R1

Platforms

All

evi number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEVPN instance ID
Contextconfigure service vprn string bgp-evpn mpls number evi number
Treeevi

Description

This command configures the EVI that identifies the BGP EVPN instance in a VPRN (for the EVPN-IFL model) that is associated with the Layer 3 Ethernet segment. This configuration is required on the PEs attached to the Ethernet segment and on the remote PEs that need to create ES destinations to the MH Layer 3 Ethernet segment.

Range1 to 16777215
Introduced22.10.R1

Platforms

All

evpn-link-bandwidth
Synopsis Enter the evpn-link-bandwidth context
Contextconfigure service vprn string bgp-evpn mpls number evpn-link-bandwidth
Treeevpn-link-bandwidth
Introduced22.7.R1

Platforms

All

advertise
Synopsis Enable the advertise context
Context configure service vprn string bgp-evpn mpls number evpn-link-bandwidth advertise
Treeadvertise
Introduced22.7.R1

Platforms

All

max-dynamic-weight number
Synopsis Maximum dynamic weight of the route
Context configure service vprn string bgp-evpn mpls number evpn-link-bandwidth advertise max-dynamic-weight number
Treemax-dynamic-weight

Description

This command configures the maximum weight advertised in the EVPN link bandwidth extended community for the advertised EVPN IP-Prefix routes for the service. If weight dynamic is configured, the actual advertised weight is the minimum of the number of BGP PE-CE paths for the prefix and the configured maximum weight.

Range1 to 128
Default128
Introduced 22.7.R1

Platforms

All

weight (number | keyword)
Synopsis Weight of the route
Context configure service vprn string bgp-evpn mpls number evpn-link-bandwidth advertise weight (number | keyword)
Treeweight

Description

This command configures the weight advertised in the EVPN link bandwidth extended community for the advertised EVPN IP-Prefix routes for the service.

If set to dynamic, the weight is dynamically set based on the number of BGP PE-CE paths for the IP-Prefix that is advertised in an EVPN IP-Prefix route.

Range1 to 128
Optionsdynamic
Defaultdynamic
Introduced22.7.R1

Platforms

All

weighted-ecmp boolean
Synopsis Enable weighted ECMP
Context configure service vprn string bgp-evpn mpls number evpn-link-bandwidth weighted-ecmp boolean
Treeweighted-ecmp

Description

When configured to true, the router supports the processing of the EVPN link bandwidth extended community when installing an ECMP set for an EVPN IP-Prefix route in the VPRN route table.

Flows to an IP Prefix received with a weight and a zero ESI value are sprayed according to the weight. If the EVPN IP-Prefix route received with the weight has a non-zero ESI, the weight is divided into the number of PEs attached to the Ethernet Segment (and rounded up if the result is not an integer).

The command also enables the weighted ECMP functionality for BGP CEs that are configured with an evpn-link-bandwidth add-to-received-bgp weight.

When configured to false, the router disables the processing of the EVPN link bandwidth extended community.

Defaultfalse
Introduced22.7.R1

Platforms

All

route-distinguisher (string | keyword)
Synopsis Route distinguisher
Context configure service vprn string bgp-evpn mpls number route-distinguisher (string | keyword)
Treeroute-distinguisher

Description

This command specifies a unique route distinguisher (RD) to be associated with each routing instance to identify which VPN the route belongs to.

Optionsauto-rd
Introduced20.10.R1

Platforms

All

send-tunnel-encap
Synopsis Enter the send-tunnel-encap context
Contextconfigure service vprn string bgp-evpn mpls number send-tunnel-encap
Treesend-tunnel-encap
Introduced20.10.R1

Platforms

All

mpls boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable MPLS encapsulation
Contextconfigure service vprn string bgp-evpn mpls number send-tunnel-encap mpls boolean
Treempls
Defaulttrue
Introduced20.10.R1

Platforms

All

mpls-over-udp boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable MPLS over UDP encapsulation
Contextconfigure service vprn string bgp-evpn mpls number send-tunnel-encap mpls-over-udp boolean
Treempls-over-udp
Defaultfalse
Introduced20.10.R1

Platforms

All

vrf-export
Synopsis Enable the vrf-export context
Context configure service vprn string bgp-evpn mpls number vrf-export
Treevrf-export
Introduced20.10.R1

Platforms

All

policy (policy-expr-string | string)
Synopsis Policy name
Contextconfigure service vprn string bgp-evpn mpls number vrf-export policy (policy-expr-string | string)
Treepolicy

Description

This command configures VRF route policies that control routes between local VRFs and other VRFs on the same or remote PE routers (using MP-BGP). 

Each referenced object is either a policy logical expression or the name of a single policy.

Only one referenced object can be a policy logical expression consisting of policy names (enclosed in square brackets) and logical operators (AND, OR, NOT). The objects are evaluated in the specified order to determine whether to accept or reject the route.

Only the first policy can have the maximum length and the rest can be up to 64 characters.

Aggregate routes are not advertised using MP-BGP protocols to the other MP-BGP peers.

String Length1 to 255
Max. Instances15
Min. Instances1

Notes

This element is ordered by the user.

Introduced20.10.R1

Platforms

All

vrf-import
Synopsis Enable the vrf-import context
Context configure service vprn string bgp-evpn mpls number vrf-import
Treevrf-import
Introduced20.10.R1

Platforms

All

policy (policy-expr-string | string)
Synopsis Policy name
Contextconfigure service vprn string bgp-evpn mpls number vrf-import policy (policy-expr-string | string)
Treepolicy

Description

This command configures VRF route policies that control routes between local VRFs and other VRFs on the same or remote PE routers (using MP-BGP). 

Each referenced object is either a policy logical expression or the name of a single policy.

Only one referenced object can be a policy logical expression consisting of policy names (enclosed in square brackets) and logical operators (AND, OR, NOT). The objects are evaluated in the specified order to determine whether to accept or reject the route.

Only the first policy can have the maximum length and the rest can be up to 64 characters.

Aggregate routes are not advertised using MP-BGP protocols to the other MP-BGP peers.

String Length1 to 255
Max. Instances15
Min. Instances1

Notes

This element is ordered by the user.

Introduced20.10.R1

Platforms

All

vrf-target
Synopsis Enter the vrf-target context
Context configure service vprn string bgp-evpn mpls number vrf-target
Treevrf-target

Description

Commands in this context configure the route target that is added to advertised routes or compared against received routes from other VRFs on the same or remote PE routers (via MP-BGP).

BGP-VPN and EVPN-IFL routes imported using a VRF target configuration use the BGP preference value of 170 when imported from remote PE routers, or retain the protocol preference value of the exported route when imported from other VRFs in the same router.

Configured VRF import or export policies override the VRF target policy.

Introduced20.10.R1

Platforms

All

community string
Synopsis Extended BGP community
Context configure service vprn string bgp-evpn mpls number vrf-target community string
Treecommunity

Description

This command configures an extended BGP community in the form type:x:y. Type can only be target and x and y are 16-bit integers.

String Length10 to 28

Notes

The following elements are part of a choice: community or (export-community and import-community).

Introduced20.10.R1

Platforms

All

export-community string
Synopsis Communities sent to remote PE neighbors
Contextconfigure service vprn string bgp-evpn mpls number vrf-target export-community string
Treeexport-community
String Length10 to 28

Notes

The following elements are part of a choice: community or (export-community and import-community).

Introduced20.10.R1

Platforms

All

import-community string
Synopsis Communities accepted from remote PE neighbors
Contextconfigure service vprn string bgp-evpn mpls number vrf-target import-community string
Treeimport-community
String Length10 to 28

Notes

The following elements are part of a choice: community or (export-community and import-community).

Introduced20.10.R1

Platforms

All

segment-routing-v6 [bgp-instance] number
Synopsis Enter the segment-routing-v6 list instance
Contextconfigure service vprn string bgp-evpn segment-routing-v6 number
Treesegment-routing-v6
Introduced22.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

admin-state keyword
Synopsis Administrative state of segment routing over IPv6
Contextconfigure service vprn string bgp-evpn segment-routing-v6 number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced22.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

default-route-tag string
Synopsis Default route tag
Context configure service vprn string bgp-evpn segment-routing-v6 number default-route-tag string
Treedefault-route-tag

Description

This command configures a route tag that is used when sending a route to the BGP application (for the corresponding service and BGP instance). If the corresponding BGP instance is enabled, the command cannot be changed.

When used for BGP EVPN contexts, only one route tag can be passed to BGP for matching on export policies. In case of a conflict with other route tags pushed by EVPN, the default route tag has the least priority. 

The following are examples of the conflict priority handling:

  • If a service is configured with both default-route-tag X and proxy-arp evpn-route-tag Y, the EVPN uses route tag Y when sending EVPN proxy-arp routes to the BGP RIB for advertisement.

  • If a given IP-prefix route is tagged in the route-table with tag A and the R-VPLS, in which the route is advertised, uses B as the default-route-tag, then EVPN keeps tag A when sending the route to the BGP RIB.

The default-route-tag configuration is only supported on EVPN and IP-VPN service routes. The route tag for ES and AD per-ES routes is always zero.

Introduced22.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

domain-id string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDomain ID of received BGP route before readvertisement
Contextconfigure service vprn string bgp-evpn segment-routing-v6 number domain-id string
Treedomain-id

Description

This command specifies the domain ID. The domain ID identifies the network from which the BGP route was received before the RTM advertises it to a different neighbor. The domain ID is part of a domain, represented as domain-id:isf_safi_type in the D-PATH attribute, as described in draft-ietf-bess-evpn-ipvpn-interworking. Gateway routers modify the D-PATH attribute. A gateway is a PE where a VPRN is instantiated. The VPRN in this case advertises or receives routes from multiple BGP owners (for example, EVPN-IFL and BGP-IPVPN) or multiple instances of the same owner (for example, VPRN with two BGP-IPVPN instances).

Gateways use the D-PATH attribute to detect loops (for received routes where the D-PATH contains a local domain ID) and to make BGP best-path selection decisions based on the D-PATH length (shorter D-PATH is preferred).

In the following example, suppose a gateway receives prefix P in an EVPN-IFL instance with the following D-PATH from neighbor N:

Seg Len=1 / 65000:1:128

If the router imports the route in VPRN-1, BGP-EVPN SRv6 instance with domain 65000:2, it readvertises it to its BGP-IPVPN MPLS instance as follows:

Seg Len=2 / 65000:2:70 / 65000:1:128

That is, the gateway prepends the local domain ID and family to the D-PATH before readvertising the route into a different instance.

Introduced22.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

evi number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEVI information
Contextconfigure service vprn string bgp-evpn segment-routing-v6 number evi number
Treeevi

Description

This command configures the EVI that identifies the BGP EVPN instance in a VPRN (for the EVPN-IFL model) or an R-VPLS (for the EVPN-IFF model) that is associated with the Layer 3 Ethernet segment. This configuration is required on the PEs attached to the Ethernet segment and on the remote PEs that need to create ES destinations to the MH Layer 3 Ethernet segment.

Range1 to 16777215
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

evpn-link-bandwidth
Synopsis Enter the evpn-link-bandwidth context
Contextconfigure service vprn string bgp-evpn segment-routing-v6 number evpn-link-bandwidth
Treeevpn-link-bandwidth
Introduced23.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

advertise
Synopsis Enable the advertise context
Context configure service vprn string bgp-evpn segment-routing-v6 number evpn-link-bandwidth advertise
Treeadvertise
Introduced23.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

max-dynamic-weight number
Synopsis Maximum dynamic weight of the route
Context configure service vprn string bgp-evpn segment-routing-v6 number evpn-link-bandwidth advertise max-dynamic-weight number
Treemax-dynamic-weight

Description

This command configures the maximum weight advertised in the EVPN link bandwidth extended community for the advertised EVPN IP-Prefix routes for the service. The actual advertised weight is the minimum of the number of BGP PE-CE paths for the prefix and the configured maximum weight.

Range1 to 128
Default128
Introduced 23.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

weight (number | keyword)
Synopsis Weight of the route
Context configure service vprn string bgp-evpn segment-routing-v6 number evpn-link-bandwidth advertise weight (number | keyword)
Treeweight

Description

This command configures the weight advertised in the EVPN link bandwidth extended community for the advertised EVPN IP-Prefix routes for the service.

Range1 to 128
Optionsdynamic
Defaultdynamic
Introduced23.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

weighted-ecmp boolean
Synopsis Enable weighted ECMP
Context configure service vprn string bgp-evpn segment-routing-v6 number evpn-link-bandwidth weighted-ecmp boolean
Treeweighted-ecmp

Description

When configured to true, the router supports the processing of the EVPN link bandwidth extended community when installing an ECMP set for an EVPN IP-Prefix route in the VPRN route table.

Flows to an IP Prefix received with a weight and a zero ESI value are sprayed according to the weight. If the EVPN IP-Prefix route received with the weight has a non-zero ESI, the weight is divided into the number of PEs attached to the Ethernet Segment (and rounded up if the result is not an integer).

The command also enables the weighted ECMP functionality for BGP CEs that are configured with an evpn-link-bandwidth add-to-received-bgp weight.

When configured to false, the router disables the processing of the EVPN link bandwidth extended community.

Defaultfalse
Introduced23.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

resolution keyword
Synopsis Resolution options for routes
Context configure service vprn string bgp-evpn segment-routing-v6 number resolution keyword
Treeresolution
Optionsroute-table, tunnel-table, fallback-tunnel-to-route-table
Defaultroute-table
Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

route-distinguisher (string | keyword)
Synopsis Route distinguisher
Context configure service vprn string bgp-evpn segment-routing-v6 number route-distinguisher (string | keyword)
Treeroute-distinguisher

Description

This command specifies a unique route distinguisher (RD) to be associated with each routing instance to identify the VPN to which the route belongs.

Alternatively, the system can automatically generate an RD based on the BGP automatic RD range configured at the configure service system level.

Optionsauto-rd
Introduced22.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

source-address string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSource IPv6 address
Contextconfigure service vprn string bgp-evpn segment-routing-v6 number source-address string
Treesource-address

Description

When configured, this command specifies the source IPv6 address used in the SA field of the outer IPv6 header of the SRv6 encapsulated packet.

When not configured, the source IPv6 address is inherited from the configuration of the global default address in the router "base" segment-routing segment-routing-v6 source-address context.

A source IPv6 address must be configured in this context or in the base router context.

The system does not check if the address entered is a valid local address.

Introduced22.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

srv6
Synopsis Enter the srv6 context
Context configure service vprn string bgp-evpn segment-routing-v6 number srv6
Treesrv6
Introduced22.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

vrf-export
Synopsis Enable the vrf-export context
Context configure service vprn string bgp-evpn segment-routing-v6 number vrf-export
Treevrf-export
Introduced22.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

policy (policy-expr-string | string)
Synopsis Policy name
Contextconfigure service vprn string bgp-evpn segment-routing-v6 number vrf-export policy (policy-expr-string | string)
Treepolicy

Description

This command configures VRF route policies that control routes between local VRFs and other VRFs on the same or remote PE routers (using MP-BGP). 

Each referenced object is either a policy logical expression or the name of a single policy.

Only one referenced object can be a policy logical expression consisting of policy names (enclosed in square brackets) and logical operators (AND, OR, NOT). The objects are evaluated in the specified order to determine whether to accept or reject the route.

Only the first policy can have the maximum length and the rest can be up to 64 characters.

Aggregate routes are not advertised using MP-BGP protocols to the other MP-BGP peers.

String Length1 to 255
Max. Instances15
Min. Instances1

Notes

This element is ordered by the user.

Introduced22.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

vrf-import
Synopsis Enable the vrf-import context
Context configure service vprn string bgp-evpn segment-routing-v6 number vrf-import
Treevrf-import
Introduced22.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

policy (policy-expr-string | string)
Synopsis Policy name
Contextconfigure service vprn string bgp-evpn segment-routing-v6 number vrf-import policy (policy-expr-string | string)
Treepolicy

Description

This command configures VRF route policies that control routes between local VRFs and other VRFs on the same or remote PE routers (using MP-BGP). 

Each referenced object is either a policy logical expression or the name of a single policy.

Only one referenced object can be a policy logical expression consisting of policy names (enclosed in square brackets) and logical operators (AND, OR, NOT). The objects are evaluated in the specified order to determine whether to accept or reject the route.

Only the first policy can have the maximum length and the rest can be up to 64 characters.

Aggregate routes are not advertised using MP-BGP protocols to the other MP-BGP peers.

String Length1 to 255
Max. Instances15
Min. Instances1

Notes

This element is ordered by the user.

Introduced22.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

vrf-target
Synopsis Enter the vrf-target context
Context configure service vprn string bgp-evpn segment-routing-v6 number vrf-target
Treevrf-target

Description

Commands in this context configure the route target that is added to advertised routes or compared against received routes from other VRFs on the same or remote PE routers (via MP-BGP).

BGP-VPN and EVPN-IFL routes imported using a VRF target configuration use the BGP preference value of 170 when imported from remote PE routers, or retain the protocol preference value of the exported route when imported from other VRFs in the same router.

Configured VRF import or export policies override the VRF target policy.

Introduced22.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

community string
Synopsis Extended BGP community
Context configure service vprn string bgp-evpn segment-routing-v6 number vrf-target community string
Treecommunity

Description

This command configures an extended BGP community in the form type:x:y. Type can only be target and x and y are 16-bit integers.

String Length10 to 28

Notes

The following elements are part of a choice: community or (export-community and import-community).

Introduced22.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

export-community string
Synopsis Communities sent to remote PE neighbors
Contextconfigure service vprn string bgp-evpn segment-routing-v6 number vrf-target export-community string
Treeexport-community
String Length10 to 28

Notes

The following elements are part of a choice: community or (export-community and import-community).

Introduced22.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

import-community string
Synopsis Communities accepted from remote PE neighbors
Contextconfigure service vprn string bgp-evpn segment-routing-v6 number vrf-target import-community string
Treeimport-community
String Length10 to 28

Notes

The following elements are part of a choice: community or (export-community and import-community).

Introduced22.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

bgp-ipvpn
Synopsis Enter the bgp-ipvpn context
Context configure service vprn string bgp-ipvpn
Treebgp-ipvpn
Introduced21.2.R1

Platforms

All

attribute-set
Synopsis Enter the attribute-set context
Contextconfigure service vprn string bgp-ipvpn attribute-set
Treeattribute-set

Description

Commands in this context configure the handling of attribute set (ATTR_SET) attributes attached to VPN-IP routes imported into or exported from the VPRN.

ATTR_SET is an optional transitive BGP path attribute standardized by RFC 6368 that is added to BGP L3 VPN routes to provide logical separation between the BGP domain of a customer and the BGP domain of a service provider.

Introduced23.10.R1

Platforms

All

export boolean
Synopsis Add ATTR_SET path attribute to exported VPN-IP routes
Contextconfigure service vprn string bgp-ipvpn attribute-set export boolean
Treeexport

Description

When configured to true, the router adds an ATTR_SET path attribute to all VPN-IP routes that come from the VRF export of BGP routes advertised by PE-CE peers of the VPRN. This attribute contains an exact copy of all BGP path attributes (post-import policy) of the PE-CE BGP route, excluding the NEXT_HOP, MP_REACH, and MP_UNREACH attributes, as well as the AS4_PATH or AS4_AGGREGATOR attributes. The origin AS in the ATTR_SET encodes the ASN (or confederation ID, if configured) of the exporting VPRN service. Neither the VRF export policy nor a regular BGP export policy is allowed to modify the contents of the ATTR_SET.

When configured to false, the router does not add an ATTR_SET path attribute to VPN-IP routes exported by the VPRN. Nokia recommends configuring this command to false, unless there is a requirement for the VPRN to deliver an independent domain L3 VPN service.

Defaultfalse
Introduced23.10.R1

Platforms

All

import keyword
Synopsis Reception behavior of ATTR_SET
Context configure service vprn string bgp-ipvpn attribute-set import keyword
Treeimport

Description

This command configures the reception behavior for ATTR_SETs in received VPN-IP routes.

  • accept — BGP accepts and processes ATTR_SETs in received unicast VPN-IP routes (MPLS or SRv6) when they are imported into the VPRN. The path attributes contained inside the ATTR_SET are used for best path selection within the VPRN, instead of the outer path attributes attached to the imported VPN-IP route. The path attributes inside the ATTR_SET determine the path attributes of BGP routes advertised to PE-CE peers of the VPRN. However, the ATTR_SET is removed at the time of advertisement. VPRN BGP routes with attributes derived from accept processing can only be advertised to EBGP peers and IBGP route reflector client peers. VPRN BGP routes cannot be advertised to BGP confederation peers. If the origin AS in the ATTR_SET attribute does not match the configured ASN, VPRN BGP routes with attributes derived from accept processing are advertised to IBGP peers that are not covered by a cluster configuration.

  • drop — BGP ignores and silently discards ATTR_SETs in received VPN-IP routes when they are imported into the VPRN. The path attributes contained inside the ATTR_SET are not used for best path selection within the VPRN. If a VPRN is not involved in an independent domain L3 VPN service, Nokia recommends configuring this command to use the drop option.

  • ignore — BGP ignores ATTR_SETs in received VPN-IP routes when they are imported into the VPRN. The path attributes contained inside the ATTR_SET are not used for best path selection within the VPRN. With the ignore option, the ATTR_SET attribute is transmitted unchanged to the CE. Nokia recommends not to configure this command to use the ignore option in most deployments.

Optionsignore, accept, drop
Defaultignore
Introduced23.10.R1

Platforms

All

mpls
Synopsis Enter the mpls context
Context configure service vprn string bgp-ipvpn mpls
Treempls
Introduced21.2.R1

Platforms

All

auto-bind-tunnel
Synopsis Enter the auto-bind-tunnel context
Contextconfigure service vprn string bgp-ipvpn mpls auto-bind-tunnel
Treeauto-bind-tunnel

Description

Commands in this context configure the automatic binding parameters of a BGP-IPVPN service using tunnels to MP-BGP peers.

Introduced21.2.R1

Platforms

All

allow-flex-algo-fallback boolean
Synopsis Enable flexible algorithm fallback
Context configure service vprn string bgp-ipvpn mpls auto-bind-tunnel allow-flex-algo-fallback boolean
Treeallow-flex-algo-fallback

Description

When configured to true, a BGP router with a Flex-Algorithm action configured (via the configure policy-options policy-statement entry action flex-algo command) can resolve to a tunnel with algorithm 0 if no target Flex-Algorithm tunnel is available.

When configured to false, the BGP router can resolve only to the intended Flex-Algorithm tunnel, which may cause traffic loss if no corresponding Flex-Algorithm tunnel is available.

Defaultfalse
Introduced21.2.R1

Platforms

All

ecmp number
Synopsis Maximum ECMP routes allowed
Context configure service vprn string bgp-ipvpn mpls auto-bind-tunnel ecmp number
Treeecmp

Description

This command configures the maximum number of tunnels that can be used as ECMP next hops for the VPRN. This value overrides the ECMP value configured at the configure service vprn context level.

Range1 to 32
Default1
Introduced 21.2.R1

Platforms

All

enforce-strict-tunnel-tagging boolean
Synopsis Allow enforcement of strict tunnel tagging
Contextconfigure service vprn string bgp-ipvpn mpls auto-bind-tunnel enforce-strict-tunnel-tagging boolean
Treeenforce-strict-tunnel-tagging

Description

When configured to true, the system must only consider LSPs marked with an administrative tag for next-hop resolution.

When configured to false, tagged RSVP and SR-TE LSPs are considered first. The system then uses untagged LSPs of other types.

Defaultfalse
Introduced21.2.R1

Platforms

All

resolution-filter
Synopsis Enter the resolution-filter context
Contextconfigure service vprn string bgp-ipvpn mpls auto-bind-tunnel resolution-filter
Treeresolution-filter

Description

Commands in this context configure the subset of tunnel types that can be used in the resolution of BGP-IPVPN routes within the automatic binding of the BGP-IPVPN MPLS service to tunnels to MP-BGP peers.

Introduced21.2.R1

Platforms

All

bgp boolean
Synopsis Use BGP tunneling for next-hop resolution
Contextconfigure service vprn string bgp-ipvpn mpls auto-bind-tunnel resolution-filter bgp boolean
Treebgp

Description

When configured to true, BGP searches the BGP LSP for the address of the BGP next hop.

When configured to false, BGP tunneling is not used and inter-area or inter-as prefixes are not resolved.

Defaulttrue
Introduced21.2.R1

Platforms

All

gre boolean
Synopsis Use GRE tunneling for next-hop resolution
Contextconfigure service vprn string bgp-ipvpn mpls auto-bind-tunnel resolution-filter gre boolean
Treegre

Description

When configured to true, this command enables setting the tunnel type for the auto bind tunnel.

Defaultfalse
Introduced21.2.R1

Platforms

All

ldp boolean
Synopsis Use LDP tunneling for next-hop resolution
Contextconfigure service vprn string bgp-ipvpn mpls auto-bind-tunnel resolution-filter ldp boolean
Treeldp

Description

When configured to true, BGP searches for an LDP LSP with a FEC prefix corresponding to the address of the BGP next hop.

When configured to false, LDP tunneling is not used for next-hop resolution.

Defaultfalse
Introduced21.2.R1

Platforms

All

mpls-fwd-policy boolean
Synopsis Use MPLS forwarding policy for next-hop resolution
Contextconfigure service vprn string bgp-ipvpn mpls auto-bind-tunnel resolution-filter mpls-fwd-policy boolean
Treempls-fwd-policy

Description

When configured to true, BGP uses the MPLS forwarding policy to determine the address of the BGP next hop.

When configured to false, the MPLS forwarding policy is not used for next-hop resolution.

Defaultfalse
Introduced21.2.R1

Platforms

All

rib-api boolean
Synopsis Use RIB API gRPC service for next-hop resolution
Contextconfigure service vprn string bgp-ipvpn mpls auto-bind-tunnel resolution-filter rib-api boolean
Treerib-api

Description

When configured to true, BGP uses tunnels programmed using the RIB API gRPC service to resolve the next hops of routes imported into the EVPN service.

When configured to false, the RIB API service tunnels are not used for next-hop resolution.

Defaultfalse
Introduced21.2.R1

Platforms

All

rsvp boolean
Synopsis Use RSVP tunneling for next-hop resolution
Contextconfigure service vprn string bgp-ipvpn mpls auto-bind-tunnel resolution-filter rsvp boolean
Treersvp

Description

When configured to true, BGP searches the best metric RSVP LSP to determine the address of the BGP next hop. This address can correspond to the system interface or to another loopback interface used by the BGP instance on the remote node. The LSP metric is provided by MPLS in the tunnel table. In the case of multiple RSVP LSPs with the same lowest metric, BGP selects the LSP with the lowest tunnel ID.

When configured to false, the RSVP LSP is not used for next-hop resolution.

Defaultfalse
Introduced21.2.R1

Platforms

All

sr-isis boolean
Synopsis Use IS-IS SR tunneling for next-hop resolution
Contextconfigure service vprn string bgp-ipvpn mpls auto-bind-tunnel resolution-filter sr-isis boolean
Treesr-isis

Description

When configured to true, BGP uses an IS-IS tunnel type to determine the address of the BGP next hop.

The SR tunnel to the BGP next hop is selected in the TTM from the lowest-numbered IS-IS instance.

When configured to false, IS-IS tunneling is not used for next-hop resolution.

Defaultfalse
Introduced21.2.R1

Platforms

All

sr-ospf boolean
Synopsis Use OSPF SR tunneling for next-hop resolution
Contextconfigure service vprn string bgp-ipvpn mpls auto-bind-tunnel resolution-filter sr-ospf boolean
Treesr-ospf

Description

When configured to true, BGP uses an OSPF tunnel type to determine the address of the BGP next hop.

The SR tunnel to the BGP next hop is selected in the TTM from the lowest-numbered OSPF instance.

When configured to false, OSPF tunneling is not used for next-hop resolution.

Defaultfalse
Introduced21.2.R1

Platforms

All

sr-ospf3 boolean
Synopsis Use OSPFv3 SR tunneling for next-hop resolution
Contextconfigure service vprn string bgp-ipvpn mpls auto-bind-tunnel resolution-filter sr-ospf3 boolean
Treesr-ospf3

Description

When configured to true, BGP uses an OSPFv3 tunnel type to determine the address of the BGP next hop.

The SR tunnel to the BGP next hop is selected in the TTM from the lowest-numbered OSPFv3 instance.

When configured to false, OSPFv3 tunneling is not used for next-hop resolution.

Defaultfalse
Introduced21.2.R1

Platforms

All

sr-policy boolean
Synopsis Use SR policies for next-hop resolution
Contextconfigure service vprn string bgp-ipvpn mpls auto-bind-tunnel resolution-filter sr-policy boolean
Treesr-policy

Description

When configured to true, SR policies are used to determine the address of the BGP next hop.

The SR policy search criteria includes a non-null endpoint and color value that matches the BGP next hop and color extended community value, respectively, of the EVPN route.

When configured to false, SR policies are not used for next-hop resolution.

Defaultfalse
Introduced21.2.R1

Platforms

All

sr-te boolean
Synopsis Use SR-TE tunneling for next-hop resolution
Contextconfigure service vprn string bgp-ipvpn mpls auto-bind-tunnel resolution-filter sr-te boolean
Treesr-te

Description

When configured to true, BGP uses an SR-TE tunnel type to determine the address of the BGP next hop.

The SR tunnel to the BGP next hop is selected in the TTM from the lowest-numbered tunnel ID.

When configured to false, SR-TE tunneling is not used for next-hop resolution.

Defaultfalse
Introduced21.2.R1

Platforms

All

udp boolean
Synopsis Use MPLS over UDP tunneling for next-hop resolution
Contextconfigure service vprn string bgp-ipvpn mpls auto-bind-tunnel resolution-filter udp boolean
Treeudp

Description

When configured to true, BGP uses an MPLS over UDP tunnel type to determine the address of the BGP next hop.

When configured to false, MPLS over UDP tunneling is not used for next-hop resolution.

Defaultfalse
Introduced21.2.R1

Platforms

All

weighted-ecmp boolean
Synopsis Allow weighted load-balancing
Context configure service vprn string bgp-ipvpn mpls auto-bind-tunnel weighted-ecmp boolean
Treeweighted-ecmp

Description

When configured to true, this command enables weighted ECMP for packets using tunnels that a VPRN automatically binds to. Packets are sprayed across LSPs in the ECMP according to the outcome of the hash algorithm and the configured load balancing weight of each LSP.

When configured to false, this command disables weighted ECMP for next-hop tunnel selection.

Defaultfalse
Introduced21.2.R1

Platforms

All

domain-id string
Synopsis Domain ID of received BGP route before readvertisement
Contextconfigure service vprn string bgp-ipvpn mpls domain-id string
Treedomain-id

Description

This command specifies the domain ID. The domain ID identifies the network from which the BGP route was received before the RTM advertises it to a different neighbor. The domain ID is part of a domain, represented as domain-id:isf_safi_type in the D-PATH attribute, as described in draft-ietf-bess-evpn-ipvpn-interworking. Gateway routers modify the D-PATH attribute. A gateway is a PE where a VPRN is instantiated. The VPRN in this case advertises or receives routes from multiple BGP owners (for example, EVPN-IFL and BGP-IPVPN) or multiple instances of the same owner (for example, VPRN with two BGP-IPVPN instances).

Gateways use the D-PATH attribute to detect loops (for received routes where the D-PATH contains a local domain ID) and to make BGP best-path selection decisions based on the D-PATH length (shorter D-PATH is preferred).

In the following example, suppose a gateway receives prefix P in an EVPN-IFL instance with the following D-PATH from neighbor N:

Seg Len=1 / 65000:1:128

If the router imports the route in VPRN-1, BGP-EVPN SRv6 instance with domain 65000:2, it readvertises it to its BGP-IPVPN MPLS instance as follows:

Seg Len=2 / 65000:2:70 / 65000:1:128

That is, the gateway prepends the local domain ID and family to the D-PATH before readvertising the route into a different instance.

Introduced21.10.R1

Platforms

All

dynamic-egress-label-limit boolean
Synopsis Enables dynamic egress label limit
Context configure service vprn string bgp-ipvpn mpls dynamic-egress-label-limit boolean
Treedynamic-egress-label-limit

Description

When configured to true, this command relaxes the egress MPLS label limit check when resolving BGP next hops in the tunnel table.

For VPRN services, the OAM label is never computed and, therefore, one more egress label is allowed.

For EVPN (Epipe and VPLS) services, the system only computes the control word and ESI label if they are used. For the control word, the system reduces the egress label limit by one label if the control word is configured in the service. When configured, the ESI label is not counted for Epipes or VPLS services without an ES.

When configured to false this command, for EVPN, Epipe, and VPLS services, always accounts for the ESI label and control word.

Defaultfalse
Introduced22.2.R1

Platforms

All

route-distinguisher (string | keyword)
Synopsis Route distinguisher
Context configure service vprn string bgp-ipvpn mpls route-distinguisher (string | keyword)
Treeroute-distinguisher

Description

This command specifies a unique route distinguisher (RD) to be associated with each routing instance to identify which VPN the route belongs to.

Optionsauto-rd
Introduced21.2.R1

Platforms

All

vrf-export
Synopsis Enable the vrf-export context
Context configure service vprn string bgp-ipvpn mpls vrf-export
Treevrf-export
Introduced21.2.R1

Platforms

All

policy (policy-expr-string | string)
Synopsis Policy name
Contextconfigure service vprn string bgp-ipvpn mpls vrf-export policy (policy-expr-string | string)
Treepolicy

Description

This command configures VRF route policies that control routes between local VRFs and other VRFs on the same or remote PE routers (using MP-BGP). 

Each referenced object is either a policy logical expression or the name of a single policy.

Only one referenced object can be a policy logical expression consisting of policy names (enclosed in square brackets) and logical operators (AND, OR, NOT). The objects are evaluated in the specified order to determine whether to accept or reject the route.

Only the first policy can have the maximum length and the rest can be up to 64 characters.

Aggregate routes are not advertised using MP-BGP protocols to the other MP-BGP peers.

String Length1 to 255
Max. Instances15
Min. Instances1

Notes

This element is ordered by the user.

Introduced21.2.R1

Platforms

All

vrf-import
Synopsis Enable the vrf-import context
Context configure service vprn string bgp-ipvpn mpls vrf-import
Treevrf-import
Introduced21.2.R1

Platforms

All

policy (policy-expr-string | string)
Synopsis Policy name
Contextconfigure service vprn string bgp-ipvpn mpls vrf-import policy (policy-expr-string | string)
Treepolicy

Description

This command configures VRF route policies that control routes between local VRFs and other VRFs on the same or remote PE routers (using MP-BGP). 

Each referenced object is either a policy logical expression or the name of a single policy.

Only one referenced object can be a policy logical expression consisting of policy names (enclosed in square brackets) and logical operators (AND, OR, NOT). The objects are evaluated in the specified order to determine whether to accept or reject the route.

Only the first policy can have the maximum length and the rest can be up to 64 characters.

Aggregate routes are not advertised using MP-BGP protocols to the other MP-BGP peers.

String Length1 to 255
Max. Instances15
Min. Instances1

Notes

This element is ordered by the user.

Introduced21.2.R1

Platforms

All

vrf-target
Synopsis Enter the vrf-target context
Context configure service vprn string bgp-ipvpn mpls vrf-target
Treevrf-target

Description

Commands in this context configure the route target that is added to advertised routes or compared against received routes from other VRFs on the same or remote PE routers (via MP-BGP).

BGP-VPN and EVPN-IFL routes imported using a VRF target configuration use the BGP preference value of 170 when imported from remote PE routers, or retain the protocol preference value of the exported route when imported from other VRFs in the same router.

Configured VRF import or export policies override the VRF target policy.

Introduced21.2.R1

Platforms

All

community string
Synopsis Extended BGP community
Context configure service vprn string bgp-ipvpn mpls vrf-target community string
Treecommunity

Description

This command configures an extended BGP community in the form type:x:y. Type can only be target and x and y are 16-bit integers.

String Length10 to 28

Notes

The following elements are part of a choice: community or (export-community and import-community).

Introduced21.2.R1

Platforms

All

export-community string
Synopsis Communities sent to remote PE neighbors
Contextconfigure service vprn string bgp-ipvpn mpls vrf-target export-community string
Treeexport-community
String Length10 to 28

Notes

The following elements are part of a choice: community or (export-community and import-community).

Introduced21.2.R1

Platforms

All

import-community string
Synopsis Communities accepted from remote PE neighbors
Contextconfigure service vprn string bgp-ipvpn mpls vrf-target import-community string
Treeimport-community
String Length10 to 28

Notes

The following elements are part of a choice: community or (export-community and import-community).

Introduced21.2.R1

Platforms

All

segment-routing-v6 [bgp-instance] number
Synopsis Enter the segment-routing-v6 list instance
Contextconfigure service vprn string bgp-ipvpn segment-routing-v6 number
Treesegment-routing-v6
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

default-route-tag string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDefault route tag
Contextconfigure service vprn string bgp-ipvpn segment-routing-v6 number default-route-tag string
Treedefault-route-tag

Description

This command configures a route tag that is used when sending a route to the BGP application (for the corresponding service and BGP instance). If the corresponding BGP instance is enabled, the command cannot be changed.

When used for BGP EVPN contexts, only one route tag can be passed to BGP for matching on export policies. In case of a conflict with other route tags pushed by EVPN, the default route tag has the least priority. 

The following are examples of the conflict priority handling:

  • If a service is configured with both default-route-tag X and proxy-arp evpn-route-tag Y, the EVPN uses route tag Y when sending EVPN proxy-arp routes to the BGP RIB for advertisement.

  • If a given IP-prefix route is tagged in the route-table with tag A and the R-VPLS, in which the route is advertised, uses B as the default-route-tag, then EVPN keeps tag A when sending the route to the BGP RIB.

The default-route-tag configuration is only supported on EVPN and IP-VPN service routes. The route tag for ES and AD per-ES routes is always zero.

Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

domain-id string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDomain ID of received BGP route before readvertisement
Contextconfigure service vprn string bgp-ipvpn segment-routing-v6 number domain-id string
Treedomain-id

Description

This command specifies the domain ID. The domain ID identifies the network from which the BGP route was received before the RTM advertises it to a different neighbor. The domain ID is part of a domain, represented as domain-id:isf_safi_type in the D-PATH attribute, as described in draft-ietf-bess-evpn-ipvpn-interworking. Gateway routers modify the D-PATH attribute. A gateway is a PE where a VPRN is instantiated. The VPRN in this case advertises or receives routes from multiple BGP owners (for example, EVPN-IFL and BGP-IPVPN) or multiple instances of the same owner (for example, VPRN with two BGP-IPVPN instances).

Gateways use the D-PATH attribute to detect loops (for received routes where the D-PATH contains a local domain ID) and to make BGP best-path selection decisions based on the D-PATH length (shorter D-PATH is preferred).

In the following example, suppose a gateway receives prefix P in an EVPN-IFL instance with the following D-PATH from neighbor N:

Seg Len=1 / 65000:1:128

If the router imports the route in VPRN-1, BGP-EVPN SRv6 instance with domain 65000:2, it readvertises it to its BGP-IPVPN MPLS instance as follows:

Seg Len=2 / 65000:2:70 / 65000:1:128

That is, the gateway prepends the local domain ID and family to the D-PATH before readvertising the route into a different instance.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

resolution keyword
Synopsis Resolution options for routes
Context configure service vprn string bgp-ipvpn segment-routing-v6 number resolution keyword
Treeresolution
Optionsroute-table, tunnel-table, fallback-tunnel-to-route-table
Defaultroute-table
Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

route-distinguisher (string | keyword)
Synopsis Route distinguisher
Context configure service vprn string bgp-ipvpn segment-routing-v6 number route-distinguisher (string | keyword)
Treeroute-distinguisher

Description

This command specifies a unique route distinguisher (RD) to be associated with each routing instance to identify the VPN to which the route belongs.

Alternatively, the system can automatically generate an RD based on the BGP automatic RD range configured at the configure service system level.

Optionsauto-rd
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

source-address string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSource IPv6 address
Contextconfigure service vprn string bgp-ipvpn segment-routing-v6 number source-address string
Treesource-address

Description

When configured, this command specifies the source IPv6 address used in the SA field of the outer IPv6 header of the SRv6 encapsulated packet.

When not configured, the source IPv6 address is inherited from the configuration of the global default address in the router "base" segment-routing segment-routing-v6 source-address context.

A source IPv6 address must be configured in this context or in the base router context.

The system does not check if the address entered is a valid local address.

Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

srv6
Synopsis Enter the srv6 context
Context configure service vprn string bgp-ipvpn segment-routing-v6 number srv6
Treesrv6
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

vrf-export
Synopsis Enable the vrf-export context
Context configure service vprn string bgp-ipvpn segment-routing-v6 number vrf-export
Treevrf-export
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

policy (policy-expr-string | string)
Synopsis Policy name
Contextconfigure service vprn string bgp-ipvpn segment-routing-v6 number vrf-export policy (policy-expr-string | string)
Treepolicy

Description

This command configures VRF route policies that control routes between local VRFs and other VRFs on the same or remote PE routers (using MP-BGP). 

Each referenced object is either a policy logical expression or the name of a single policy.

Only one referenced object can be a policy logical expression consisting of policy names (enclosed in square brackets) and logical operators (AND, OR, NOT). The objects are evaluated in the specified order to determine whether to accept or reject the route.

Only the first policy can have the maximum length and the rest can be up to 64 characters.

Aggregate routes are not advertised using MP-BGP protocols to the other MP-BGP peers.

String Length1 to 255
Max. Instances15
Min. Instances1

Notes

This element is ordered by the user.

Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

vrf-import
Synopsis Enable the vrf-import context
Context configure service vprn string bgp-ipvpn segment-routing-v6 number vrf-import
Treevrf-import
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

policy (policy-expr-string | string)
Synopsis Policy name
Contextconfigure service vprn string bgp-ipvpn segment-routing-v6 number vrf-import policy (policy-expr-string | string)
Treepolicy

Description

This command configures VRF route policies that control routes between local VRFs and other VRFs on the same or remote PE routers (using MP-BGP). 

Each referenced object is either a policy logical expression or the name of a single policy.

Only one referenced object can be a policy logical expression consisting of policy names (enclosed in square brackets) and logical operators (AND, OR, NOT). The objects are evaluated in the specified order to determine whether to accept or reject the route.

Only the first policy can have the maximum length and the rest can be up to 64 characters.

Aggregate routes are not advertised using MP-BGP protocols to the other MP-BGP peers.

String Length1 to 255
Max. Instances15
Min. Instances1

Notes

This element is ordered by the user.

Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

vrf-target
Synopsis Enter the vrf-target context
Context configure service vprn string bgp-ipvpn segment-routing-v6 number vrf-target
Treevrf-target

Description

Commands in this context configure the route target that is added to advertised routes or compared against received routes from other VRFs on the same or remote PE routers (via MP-BGP).

BGP-VPN and EVPN-IFL routes imported using a VRF target configuration use the BGP preference value of 170 when imported from remote PE routers, or retain the protocol preference value of the exported route when imported from other VRFs in the same router.

Configured VRF import or export policies override the VRF target policy.

Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

community string
Synopsis Extended BGP community
Context configure service vprn string bgp-ipvpn segment-routing-v6 number vrf-target community string
Treecommunity

Description

This command configures an extended BGP community in the form type:x:y. Type can only be target and x and y are 16-bit integers.

String Length10 to 28

Notes

The following elements are part of a choice: community or (export-community and import-community).

Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

import-community string
Synopsis Communities accepted from remote PE neighbors
Contextconfigure service vprn string bgp-ipvpn segment-routing-v6 number vrf-target import-community string
Treeimport-community
String Length10 to 28

Notes

The following elements are part of a choice: community or (export-community and import-community).

Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

bgp-shared-queue
Synopsis Enable the bgp-shared-queue context
Contextconfigure service vprn string bgp-shared-queue
Treebgp-shared-queue
Introduced16.0.R1

Platforms

All

cir (number | keyword)
Synopsis Committed information rate for shared queue
Contextconfigure service vprn string bgp-shared-queue cir (number | keyword)
Treecir
Range0 to 100000000
Unitskilobps
Options max
Default 4000
Introduced16.0.R1

Platforms

All

pir (number | keyword)
Synopsis Peak information rate for shared queue
Contextconfigure service vprn string bgp-shared-queue pir (number | keyword)
Treepir
Range1 to 100000000
Unitskilobps
Options max
Default 4000
Introduced16.0.R1

Platforms

All

bgp-vpn-backup
Synopsis Enter the bgp-vpn-backup context
Contextconfigure service vprn string bgp-vpn-backup
Treebgp-vpn-backup
Introduced16.0.R1

Platforms

All

ipv4 boolean
Synopsis Allow BGP-VPN to be used as backup for IPv4 prefixes
Contextconfigure service vprn string bgp-vpn-backup ipv4 boolean
Treeipv4
Defaultfalse
Introduced16.0.R1

Platforms

All

ipv6 boolean
Synopsis Allow BGP-VPN to be used as backup for IPv6 prefixes
Contextconfigure service vprn string bgp-vpn-backup ipv6 boolean
Treeipv6
Defaultfalse
Introduced16.0.R1

Platforms

All

confederation
Synopsis Enter the confederation context
Contextconfigure service vprn string confederation
Treeconfederation
Introduced16.0.R1

Platforms

All

customer reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisService customer ID
Contextconfigure service vprn string customer reference
Treecustomer

Reference

configure service customer string

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

d-path-length-ignore boolean
Synopsis Enable D-PATH length ignore
Context configure service vprn string d-path-length-ignore boolean
Treed-path-length-ignore

Description

When configured to true, the VPRN RTM ignores the D-PATH domain segment length for best path selection purposes (for routes in the VPRN). This allows the user to control whether the RTM considers the D-PATH length when comparing two VPN routes with different RDs.

When configured to false, the router does not ignore the D-PATH domain segment length.

Defaultfalse
Introduced21.10.R1

Platforms

All

description string
Synopsis Text description
Context configure service vprn string description string
Treedescription
String Length1 to 80
Introduced16.0.R1

Platforms

All

dhcp-server
Synopsis Enter the dhcp-server context
Context configure service vprn string dhcp-server
Treedhcp-server
Introduced16.0.R1

Platforms

All

dhcpv4 [name] string
Synopsis Enter the dhcpv4 list instance
Contextconfigure service vprn string dhcp-server dhcpv4 string
Treedhcpv4
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis DHCP server name
Context configure service vprn string dhcp-server dhcpv4 string
Treedhcpv4
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the DHCP server
Contextconfigure service vprn string dhcp-server dhcpv4 string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

failover
Synopsis Enter the failover context
Context configure service vprn string dhcp-server dhcpv4 string failover
Treefailover
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the failover mechanism
Contextconfigure service vprn string dhcp-server dhcpv4 string failover admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ignore-mclt-on-takeover boolean
Synopsis Ignore maximum client lead during takeover from partner
Contextconfigure service vprn string dhcp-server dhcpv4 string failover ignore-mclt-on-takeover boolean
Treeignore-mclt-on-takeover

Description

When configured to true, the remote IP address range can be taken over immediately when the intercommunication link enters the PARTNER-DOWN state, without having to wait for the MCLT to expire.

When configured to false, the DHCP lease time for new clients is restricted to the MCLT during a failure. For existing clients, the lease time is gradually reduced over time to the MCLT by consecutive DHCP renewals.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

maximum-client-lead-time number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum time that DHCP server can extend client's lease
Contextconfigure service vprn string dhcp-server dhcpv4 string failover maximum-client-lead-time number
Treemaximum-client-lead-time

Description

This command configures the maximum client lead time (MCLT), which is the maximum time that a DHCP server can extend the client's lease time beyond the lease time currently known by the DHCP partner node. In dual-homed environments, the initial lease time for all DHCP clients is restricted to the MCLT by default. Consecutive DHCP renewals can extend the lease time beyond the MCLT.

Range600 to 86399
Unitsseconds
Default 600
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

partner-down-delay number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDelay to prevent lease duplication during link failure
Contextconfigure service vprn string dhcp-server dhcpv4 string failover partner-down-delay number
Treepartner-down-delay

Description

This command configures the interval before a failed intercommunication link transitions from the COMM-INT state to the PARTNER-DOWN state. This delay prevents IP lease duplication during link failure by not allowing new IP addresses to be assigned from the remote IP address range. This timer is intended to provide the operator with enough time to remedy the failed situation and avoid duplication of IP addresses and prefixes during the failure.

Range0 to 86399
Unitsseconds
Default 86399
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

peer [address] reference
Synopsis Enter the peer list instance
Context configure service vprn string dhcp-server dhcpv4 string failover peer reference
Treepeer
Max. Instances1
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[address] reference
Synopsis IP address of the failover peer
Context configure service vprn string dhcp-server dhcpv4 string failover peer reference
Treepeer

Reference

configure redundancy multi-chassis peer (ipv4-address-no-zone | ipv6-address-no-zone)

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

sync-tag string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTag that identifies synchronizing server or pool pairs
Contextconfigure service vprn string dhcp-server dhcpv4 string failover peer reference sync-tag string
Treesync-tag
String Length1 to 32

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

startup-wait-time number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTime between initialization and assuming active role
Contextconfigure service vprn string dhcp-server dhcpv4 string failover startup-wait-time number
Treestartup-wait-time

Description

This command configures a delay that avoids transient issues during the initialization process. During startup wait time, each failover peer waits after the initialization process before assuming the active role for the prefix designated as local or remote.

Range60 to 3600
Unitsseconds
Default 120
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

force-renews boolean
Synopsis Send FORCERENEW messages to force renewals of leases
Contextconfigure service vprn string dhcp-server dhcpv4 string force-renews boolean
Treeforce-renews

Description

When configured to true, FORCERENEW messages are enabled for DHCP.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lease-hold
Synopsis Enter the lease-hold context
Context configure service vprn string dhcp-server dhcpv4 string lease-hold
Treelease-hold
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

additional-scenarios
Synopsis Enter the additional-scenarios context
Contextconfigure service vprn string dhcp-server dhcpv4 string lease-hold additional-scenarios
Treeadditional-scenarios

Description

Commands in this context configure additional types of leases or triggers that cause the system to hold up leases.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

solicited-release boolean
Synopsis Apply lease hold timer for solicited releases
Contextconfigure service vprn string dhcp-server dhcpv4 string lease-hold additional-scenarios solicited-release boolean
Treesolicited-release

Description

This command enables the server to hold up a lease even for a solicited release, for example, when the server receives a normal DHCP release message.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

time number
Synopsis Lease hold time
Context configure service vprn string dhcp-server dhcpv4 string lease-hold time number
Treetime
Range1 to 631152000
Unitsseconds
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

pool [pool-name] string
Synopsis Enter the pool list instance
Context configure service vprn string dhcp-server dhcpv4 string pool string
Treepool
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[pool-name] string
Synopsis DHCP server pool name
Context configure service vprn string dhcp-server dhcpv4 string pool string
Treepool
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

failover
Synopsis Enter the failover context
Context configure service vprn string dhcp-server dhcpv4 string pool string failover
Treefailover
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the failover mechanism
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string failover admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ignore-mclt-on-takeover boolean
Synopsis Ignore maximum client lead during takeover from partner
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string failover ignore-mclt-on-takeover boolean
Treeignore-mclt-on-takeover

Description

When configured to true, the remote IP address range can be taken over immediately when the intercommunication link enters the PARTNER-DOWN state, without having to wait for the MCLT to expire.

When configured to false, the DHCP lease time for new clients is restricted to the MCLT during a failure. For existing clients, the lease time is gradually reduced over time to the MCLT by consecutive DHCP renewals.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

maximum-client-lead-time number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum time that DHCP server can extend client's lease
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string failover maximum-client-lead-time number
Treemaximum-client-lead-time

Description

This command configures the maximum client lead time (MCLT), which is the maximum time that a DHCP server can extend the client's lease time beyond the lease time currently known by the DHCP partner node. In dual-homed environments, the initial lease time for all DHCP clients is restricted to the MCLT by default. Consecutive DHCP renewals can extend the lease time beyond the MCLT.

Range600 to 86399
Unitsseconds
Default 600
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

partner-down-delay number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDelay to prevent lease duplication during link failure
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string failover partner-down-delay number
Treepartner-down-delay

Description

This command configures the interval before a failed intercommunication link transitions from the COMM-INT state to the PARTNER-DOWN state. This delay prevents IP lease duplication during link failure by not allowing new IP addresses to be assigned from the remote IP address range. This timer is intended to provide the operator with enough time to remedy the failed situation and avoid duplication of IP addresses and prefixes during the failure.

Range0 to 86399
Unitsseconds
Default 86399
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

peer [address] reference
Synopsis Enter the peer list instance
Context configure service vprn string dhcp-server dhcpv4 string pool string failover peer reference
Treepeer
Max. Instances1
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[address] reference
Synopsis IP address of the failover peer
Context configure service vprn string dhcp-server dhcpv4 string pool string failover peer reference
Treepeer

Reference

configure redundancy multi-chassis peer (ipv4-address-no-zone | ipv6-address-no-zone)

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

sync-tag string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTag that identifies synchronizing server or pool pairs
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string failover peer reference sync-tag string
Treesync-tag
String Length1 to 32

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

startup-wait-time number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTime between initialization and assuming active role
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string failover startup-wait-time number
Treestartup-wait-time

Description

This command configures a delay that avoids transient issues during the initialization process. During startup wait time, each failover peer waits after the initialization process before assuming the active role for the prefix designated as local or remote.

Range60 to 3600
Unitsseconds
Default 120
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

minimum-free
Synopsis Enter the minimum-free context
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string minimum-free
Treeminimum-free

Description

Commands in this context specify the minimum number of free addresses in this pool.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

absolute number
Synopsis Minimum number of free addresses in this pool or subnet
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string minimum-free absolute number
Treeabsolute
Range0 to 255
Default1

Notes

The following elements are part of a choice: absolute or percent.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

event-when-depleted boolean
Synopsis Generate notification when addresses are depleted
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string minimum-free event-when-depleted boolean
Treeevent-when-depleted

Description

When configured to true, a system-generated event is generated when all available addresses in the pool or subnet of a local DHCP server are depleted.

When configured to false, no action is taken when all available addresses in the pool or subnet of a local DHCP server are depleted.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

percent number
Synopsis Minimum free addresses as a percentage
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string minimum-free percent number
Treepercent
Range0 to 100
Default1

Notes

The following elements are part of a choice: absolute or percent.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

nak-non-matching-subnet boolean
Synopsis Send NAK if no match for request address pool range
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string nak-non-matching-subnet boolean
Treenak-non-matching-subnet

Description

When configured to true, a NAK response when the local DHCPv4 server receives a DHCP request with option 50 (the client is trying to request a previously allocated message). If the address-allocation algorithm uses a pool that does not contain the requested address, the system returns the DHCP NAK.

When configured to false or unconfigured, the system drops the DHCP packet.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

offer-time number
Synopsis Time interval during which a DHCP offer remains valid
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string offer-time number
Treeoffer-time
Range10 to 600
Unitsseconds
Default 60
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

options
Synopsis Enter the options context
Context configure service vprn string dhcp-server dhcpv4 string pool string options
Treeoptions
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

option [number] (number | keyword)
Synopsis Enter the option list instance
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string options option (number | keyword)
Treeoption
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[number] (number | keyword)
Synopsis DHCP option to send identification strings to client
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string options option (number | keyword)
Treeoption
Range1 to 254
Optionssubnet-mask, default-router, dns-server, domain-name, netbios-name-server, netbios-node-type, lease-time, lease-renew-time, lease-rebind-time

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ascii-string string
Synopsis DHCP option specified as an ASCII string
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string options option (number | keyword) ascii-string string
Treeascii-string
String Length1 to 127

Notes

The following elements are part of a mandatory choice: ascii-string, duration, empty, hex-string, ipv4-address, or netbios-node-type.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

duration number
Synopsis DHCP option as time duration
Context configure service vprn string dhcp-server dhcpv4 string pool string options option (number | keyword) duration number
Treeduration
Range10 to 315446399
Unitsseconds

Notes

The following elements are part of a mandatory choice: ascii-string, duration, empty, hex-string, ipv4-address, or netbios-node-type.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

empty
Synopsis Empty DHCP option.
Context configure service vprn string dhcp-server dhcpv4 string pool string options option (number | keyword) empty
Treeempty

Notes

The following elements are part of a mandatory choice: ascii-string, duration, empty, hex-string, ipv4-address, or netbios-node-type.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

hex-string string
Synopsis DHCP option specified as hexadecimal string
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string options option (number | keyword) hex-string string
Treehex-string
String Length1 to 256

Notes

The following elements are part of a mandatory choice: ascii-string, duration, empty, hex-string, ipv4-address, or netbios-node-type.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv4-address string
Synopsis DHCP option as a list of IPv4 addresses
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string options option (number | keyword) ipv4-address string
Treeipv4-address
Max. Instances4

Notes

The following elements are part of a mandatory choice: ascii-string, duration, empty, hex-string, ipv4-address, or netbios-node-type.

This element is ordered by the user.

Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

netbios-node-type keyword
Synopsis DHCP option as NetBIOS node type
Context configure service vprn string dhcp-server dhcpv4 string pool string options option (number | keyword) netbios-node-type keyword
Treenetbios-node-type
Optionsb-node, p-node, m-node, h-node

Notes

The following elements are part of a mandatory choice: ascii-string, duration, empty, hex-string, ipv4-address, or netbios-node-type.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

subnet [ipv4-prefix] string
Synopsis Enter the subnet list instance
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string subnet string
Treesubnet
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[ipv4-prefix] string
Synopsis IPv4 prefix for the subnet
Context configure service vprn string dhcp-server dhcpv4 string pool string subnet string
Treesubnet

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

address-range [start] string end string
Synopsis Enter the address-range list instance
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string subnet string address-range string end string
Treeaddress-range
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[start] string
Synopsis Lower bound of the IP address range
Context configure service vprn string dhcp-server dhcpv4 string pool string subnet string address-range string end string
Treeaddress-range

Description

This command specifies the start of a range of IP addresses that are excluded from the pool of IP addresses in this subnet.

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

end string
Synopsis Upper bound of the IP address range
Context configure service vprn string dhcp-server dhcpv4 string pool string subnet string address-range string end string
Treeaddress-range

Description

This command specifies the end of a range of IP addresses that are excluded from the pool of IP addresses in this subnet.

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

failover-control-type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisFailover control type for this range
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string subnet string address-range string end string failover-control-type keyword
Treefailover-control-type
Optionslocal, remote, access-driven
Defaultlocal
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

drain boolean
Synopsis Prevent new lease assignment from this subnet
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string subnet string drain boolean
Treedrain

Description

When configured to true, new leases cannot be assigned and existing leases are kept up until they are released.

When configured to false, the subnet is active and new leases can be assigned.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

exclude-addresses [start] string end string
Synopsis Add a list entry for exclude-addresses
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string subnet string exclude-addresses string end string
Treeexclude-addresses
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[start] string
Synopsis Lower bound of the IP address range
Context configure service vprn string dhcp-server dhcpv4 string pool string subnet string exclude-addresses string end string
Treeexclude-addresses

Description

This command specifies the start of a range of IP addresses that are excluded from the pool of IP addresses in this subnet.

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

end string
Synopsis Upper bound of the IP address range
Context configure service vprn string dhcp-server dhcpv4 string pool string subnet string exclude-addresses string end string
Treeexclude-addresses

Description

This command specifies the end of a range of IP addresses that are excluded from the pool of IP addresses in this subnet.

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

minimum-free
Synopsis Enter the minimum-free context
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string subnet string minimum-free
Treeminimum-free

Description

Commands in this context specify the minimum number of free addresses in this pool.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

absolute number
Synopsis Minimum number of free addresses in this pool or subnet
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string subnet string minimum-free absolute number
Treeabsolute
Range0 to 255
Default1

Notes

The following elements are part of a choice: absolute or percent.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

event-when-depleted boolean
Synopsis Generate notification when addresses are depleted
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string subnet string minimum-free event-when-depleted boolean
Treeevent-when-depleted

Description

When configured to true, a system-generated event is generated when all available addresses in the pool or subnet of a local DHCP server are depleted.

When configured to false, no action is taken when all available addresses in the pool or subnet of a local DHCP server are depleted.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

percent number
Synopsis Minimum free addresses as a percentage
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string subnet string minimum-free percent number
Treepercent
Range0 to 100
Default1

Notes

The following elements are part of a choice: absolute or percent.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

options
Synopsis Enter the options context
Context configure service vprn string dhcp-server dhcpv4 string pool string subnet string options
Treeoptions
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

option [number] (number | keyword)
Synopsis Enter the option list instance
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string subnet string options option (number | keyword)
Treeoption
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[number] (number | keyword)
Synopsis DHCP option to send identification strings to client
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string subnet string options option (number | keyword)
Treeoption
Range1 to 254
Optionssubnet-mask, default-router, dns-server, domain-name, netbios-name-server, netbios-node-type, lease-time, lease-renew-time, lease-rebind-time

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ascii-string string
Synopsis DHCP option specified as an ASCII string
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string subnet string options option (number | keyword) ascii-string string
Treeascii-string
String Length1 to 127

Notes

The following elements are part of a mandatory choice: ascii-string, duration, empty, hex-string, ipv4-address, or netbios-node-type.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

duration number
Synopsis DHCP option as time duration
Context configure service vprn string dhcp-server dhcpv4 string pool string subnet string options option (number | keyword) duration number
Treeduration
Range10 to 315446399
Unitsseconds

Notes

The following elements are part of a mandatory choice: ascii-string, duration, empty, hex-string, ipv4-address, or netbios-node-type.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

empty
Synopsis Empty DHCP option
Context configure service vprn string dhcp-server dhcpv4 string pool string subnet string options option (number | keyword) empty
Treeempty

Notes

The following elements are part of a mandatory choice: ascii-string, duration, empty, hex-string, ipv4-address, or netbios-node-type.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

hex-string string
Synopsis DHCP option specified as hexadecimal string
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string subnet string options option (number | keyword) hex-string string
Treehex-string
String Length1 to 256

Notes

The following elements are part of a mandatory choice: ascii-string, duration, empty, hex-string, ipv4-address, or netbios-node-type.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv4-address string
Synopsis DHCP option as a list of IPv4 addresses
Contextconfigure service vprn string dhcp-server dhcpv4 string pool string subnet string options option (number | keyword) ipv4-address string
Treeipv4-address
Max. Instances4

Notes

The following elements are part of a mandatory choice: ascii-string, duration, empty, hex-string, ipv4-address, or netbios-node-type.

This element is ordered by the user.

Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

netbios-node-type keyword
Synopsis DHCP option as NetBIOS node type
Context configure service vprn string dhcp-server dhcpv4 string pool string subnet string options option (number | keyword) netbios-node-type keyword
Treenetbios-node-type
Optionsb-node, p-node, m-node, h-node

Notes

The following elements are part of a mandatory choice: ascii-string, duration, empty, hex-string, ipv4-address, or netbios-node-type.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

pool-selection
Synopsis Enter the pool-selection context
Contextconfigure service vprn string dhcp-server dhcpv4 string pool-selection
Treepool-selection
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

use-gi-address
Synopsis Enable the use-gi-address context
Contextconfigure service vprn string dhcp-server dhcpv4 string pool-selection use-gi-address
Treeuse-gi-address

Description

Commands in this context configure gateway interface (GI) address matching. When configured, the pool can be used for address matching even if a subnet is not found. If the local user database name is not used, addresses are provided only by GI. If a user must be blocked from getting an address, the server maps to a local user database and configures the user with no address.

A pool can include multiple subnets. Since the GI is shared by multiple subnets in a subscriber interface, the pool can provide IP addresses from any of the subnets included when the GI is matched to one of its subnets. This allows a pool to be created that represents a sub-net.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

use-pool-from-client
Synopsis Enable the use-pool-from-client context
Contextconfigure service vprn string dhcp-server dhcpv4 string pool-selection use-pool-from-client
Treeuse-pool-from-client
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

delimiter string
Synopsis Delimiter to combine primary and secondary pool names
Contextconfigure service vprn string dhcp-server dhcpv4 string pool-selection use-pool-from-client delimiter string
Treedelimiter

Description

This command configures a single ASCII character that separates the pool names in DHCP vendor-specific option 82, which identifies the address pool to be used for this client.

String Length1
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

user-identification keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisUser identification method for the DHCP server
Contextconfigure service vprn string dhcp-server dhcpv4 string user-identification keyword
Treeuser-identification
Optionsmac-circuit-id, client-id, mac, circuit-id, remote-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

dhcpv6 [name] string
Synopsis Enter the dhcpv6 list instance
Contextconfigure service vprn string dhcp-server dhcpv6 string
Treedhcpv6
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis DHCP server name
Context configure service vprn string dhcp-server dhcpv6 string
Treedhcpv6
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the DHCP server
Contextconfigure service vprn string dhcp-server dhcpv6 string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

auto-provisioned boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisAuto-provision the pools of this server
Contextconfigure service vprn string dhcp-server dhcpv6 string auto-provisioned boolean
Treeauto-provisioned
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

defaults
Synopsis Enter the defaults context
Context configure service vprn string dhcp-server dhcpv6 string defaults
Treedefaults
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

options
Synopsis Enter the options context
Context configure service vprn string dhcp-server dhcpv6 string defaults options
Treeoptions
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

option [number] (number | keyword)
Synopsis Enter the option list instance
Contextconfigure service vprn string dhcp-server dhcpv6 string defaults options option (number | keyword)
Treeoption
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[number] (number | keyword)
Synopsis DHCP option to send as identification string
Contextconfigure service vprn string dhcp-server dhcpv6 string defaults options option (number | keyword)
Treeoption
Range1 to 65535
Optionsdns-server, domain-name

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ascii-string string
Synopsis DHCP option specified as an ASCII string
Contextconfigure service vprn string dhcp-server dhcpv6 string defaults options option (number | keyword) ascii-string string
Treeascii-string
String Length1 to 127

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

domain-string string
Synopsis DHCP option specified as a domain name
Contextconfigure service vprn string dhcp-server dhcpv6 string defaults options option (number | keyword) domain-string string
Treedomain-string
String Length1 to 127

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

duration number
Synopsis DHCP option specified as time
Context configure service vprn string dhcp-server dhcpv6 string defaults options option (number | keyword) duration number
Treeduration
Range10 to 315446399
Unitsseconds

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

empty
Synopsis Empty DHCP option
Context configure service vprn string dhcp-server dhcpv6 string defaults options option (number | keyword) empty
Treeempty

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

hex-string string
Synopsis DHCP option specified as hexadecimal string
Contextconfigure service vprn string dhcp-server dhcpv6 string defaults options option (number | keyword) hex-string string
Treehex-string
String Length1 to 256

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv6-address string
Synopsis DHCP option specified as a list of IPv6 addresses
Contextconfigure service vprn string dhcp-server dhcpv6 string defaults options option (number | keyword) ipv6-address string
Treeipv6-address
Max. Instances4

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

This element is ordered by the user.

Introduced 16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

preferred-lifetime number
Synopsis Time this lease remains preferred
Context configure service vprn string dhcp-server dhcpv6 string defaults preferred-lifetime number
Treepreferred-lifetime

Description

This command configures the preferred lifetime of the IPv6 lease address or prefix. When the preferred lifetime expires, any derived addresses are deprecated. The preferred lifetime must be less than or equal to the valid lifetime. 

Each address or prefix assigned to the client has associated preferred and valid lifetimes specified by the address assignment authority (such as the DHCP server, RADIUS, or ESM). To request an extension of the lifetimes assigned to an address, the client sends a renew message to the addressing authority. The authority sends a reply message to the client with the new lifetimes, allowing the client to continue to use the address/prefix without interruption. The lifetimes are transmitted from the addressing authority to the client in the identity association (IA) option at the top level of the message (not the address or prefix level).

Range300 to 315446399
Unitsseconds
Default 3600
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

rebind-time number
Synopsis Rebind time for the lease
Context configure service vprn string dhcp-server dhcpv6 string defaults rebind-time number
Treerebind-time

Description

This command configures the rebind time, known as T2, at which the client contacts the addressing authority to extend the lifetimes of its leases.

The IP addressing authority (such as the DHCP server, RADIUS, or ESM) controls the time for extending lifetimes on assigned addresses/prefixes through the T1 and T2 parameters assigned to an identity association (IA). At renew time, T1, the client initiates a renew or reply message exchange to extend the lifetimes of any addresses in the IA. The client includes an IA option with all addresses or prefixes currently assigned to the IA in its renew message.

Recommended values for T1 and T2 are 0.5 and 0.8 times the shortest preferred lifetime of the addresses or prefixes in the IA that the addressing authority is willing to extend, respectively. The configured rebind timer value should always be less than or equal to the rebind timer. The T1 and T2 values are carried in the IPV6 address option in the IA.

Range0 to 1209600
Unitsseconds
Default 2880
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

renew-time number
Synopsis Renew time for the lease
Context configure service vprn string dhcp-server dhcpv6 string defaults renew-time number
Treerenew-time

Description

This command configures the renew time, known as T1, at which the client makes a transition to the lease-renewal state.

The IP addressing authority (such as the DHCP server, RADIUS, or ESM) controls the time for extending lifetimes on assigned addresses/prefixes through the T1 and T2 parameters assigned to an identity association (IA). At renew time, T1, the client initiates a renew/reply message exchange to extend the lifetimes of any addresses in the IA. The client includes an IA option with all addresses/prefixes currently assigned to the IA in its renew message.

Recommended values for T1 and T2 are 0.5 and 0.8 times the shortest preferred lifetime of the addresses or prefixes in the IA that the addressing authority is willing to extend, respectively. The configured renew timer value should always be shorter than or equal to the rebind timer. The T1 and T2 values are carried in the IPV6 address option in the IA.

Range0 to 604800
Unitsseconds
Default 1800
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

valid-lifetime number
Synopsis Time for the lease to remain valid
Context configure service vprn string dhcp-server dhcpv6 string defaults valid-lifetime number
Treevalid-lifetime

Description

This command configures a valid lifetime for a DHCPv6 lease address or prefix. The valid lifetime is the length of time an address and prefix remains in the valid state. The valid lifetime must be greater than or equal to the preferred lifetime. When the valid lifetime expires, the address and prefix becomes invalid and must not be used in communications. RFC 2461 recommends a default value of 30 days.

Each address and prefix assigned to the client has associated preferred and valid lifetimes specified by the address assignment authority (such as the DHCP server, RADIUS, or ESM). To request an extension of the lifetimes assigned to an address, the client sends a renew message to the addressing authority. The authority sends a reply message to the client with the new lifetimes, allowing the client to continue to use the address and prefix without interruption. The lifetimes are transmitted from the addressing authority to the client in the identity association (IA) option at the top level of the message (not the address or prefix level).

Range300 to 315446399
Unitsseconds
Default 86400
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

failover
Synopsis Enter the failover context
Context configure service vprn string dhcp-server dhcpv6 string failover
Treefailover
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the failover mechanism
Contextconfigure service vprn string dhcp-server dhcpv6 string failover admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ignore-mclt-on-takeover boolean
Synopsis Ignore maximum client lead during takeover from partner
Contextconfigure service vprn string dhcp-server dhcpv6 string failover ignore-mclt-on-takeover boolean
Treeignore-mclt-on-takeover

Description

When configured to true, the remote IP address range can be taken over immediately when the intercommunication link enters the PARTNER-DOWN state, without having to wait for the MCLT to expire.

When configured to false, the DHCP lease time for new clients is restricted to the MCLT during a failure. For existing clients, the lease time is gradually reduced over time to the MCLT by consecutive DHCP renewals.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

maximum-client-lead-time number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum time that DHCP server can extend client's lease
Contextconfigure service vprn string dhcp-server dhcpv6 string failover maximum-client-lead-time number
Treemaximum-client-lead-time

Description

This command configures the maximum client lead time (MCLT), which is the maximum time that a DHCP server can extend the client's lease time beyond the lease time currently known by the DHCP partner node. In dual-homed environments, the initial lease time for all DHCP clients is restricted to the MCLT by default. Consecutive DHCP renewals can extend the lease time beyond the MCLT.

Range600 to 86399
Unitsseconds
Default 600
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

partner-down-delay number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDelay to prevent lease duplication during link failure
Contextconfigure service vprn string dhcp-server dhcpv6 string failover partner-down-delay number
Treepartner-down-delay

Description

This command configures the interval before a failed intercommunication link transitions from the COMM-INT state to the PARTNER-DOWN state. This delay prevents IP lease duplication during link failure by not allowing new IP addresses to be assigned from the remote IP address range. This timer is intended to provide the operator with enough time to remedy the failed situation and avoid duplication of IP addresses and prefixes during the failure.

Range0 to 86399
Unitsseconds
Default 86399
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

peer [address] reference
Synopsis Enter the peer list instance
Context configure service vprn string dhcp-server dhcpv6 string failover peer reference
Treepeer
Max. Instances1
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[address] reference
Synopsis IP address of the failover peer
Context configure service vprn string dhcp-server dhcpv6 string failover peer reference
Treepeer

Reference

configure redundancy multi-chassis peer (ipv4-address-no-zone | ipv6-address-no-zone)

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

sync-tag string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTag that identifies synchronizing server or pool pairs
Contextconfigure service vprn string dhcp-server dhcpv6 string failover peer reference sync-tag string
Treesync-tag
String Length1 to 32

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

startup-wait-time number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTime between initialization and assuming active role
Contextconfigure service vprn string dhcp-server dhcpv6 string failover startup-wait-time number
Treestartup-wait-time

Description

This command configures a delay that avoids transient issues during the initialization process. During startup wait time, each failover peer waits after the initialization process before assuming the active role for the prefix designated as local or remote.

Range60 to 3600
Unitsseconds
Default 120
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ignore-rapid-commit boolean
Synopsis Ignore Rapid Commit option
Context configure service vprn string dhcp-server dhcpv6 string ignore-rapid-commit boolean
Treeignore-rapid-commit

Description

When configured to true, the server ignores the Rapid Commit option sent by the client and uses the regular message exchange.   

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

interface-id-mapping boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMap hosts within interface-to-prefix combinations
Contextconfigure service vprn string dhcp-server dhcpv6 string interface-id-mapping boolean
Treeinterface-id-mapping

Description

When configured to true, this command specifies an interface-mapping method that uses a combination of unique /64 prefixes and interface IDs. A /64 prefix is allocated to each interface ID, and all clients with the same interface ID are assigned an address from the prefix. This method is used for bridging clients in the same local loop and SAP, so that sharing the prefix allows communication to stay local. For SLAAC-based assignment, downstream neighbor discovery is automatically enabled to resolve the assigned address.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lease-hold
Synopsis Enter the lease-hold context
Context configure service vprn string dhcp-server dhcpv6 string lease-hold
Treelease-hold
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

additional-scenarios
Synopsis Enter the additional-scenarios context
Contextconfigure service vprn string dhcp-server dhcpv6 string lease-hold additional-scenarios
Treeadditional-scenarios

Description

Commands in this context configure additional types of leases or triggers that cause the system to hold up leases.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

solicited-release boolean
Synopsis Apply lease hold timer for solicited releases
Contextconfigure service vprn string dhcp-server dhcpv6 string lease-hold additional-scenarios solicited-release boolean
Treesolicited-release

Description

This command enables the server to hold up a lease even for a solicited release, for example, when the server receives a normal DHCP release message.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

time number
Synopsis Lease hold time
Context configure service vprn string dhcp-server dhcpv6 string lease-hold time number
Treetime
Range1 to 631152000
Unitsseconds
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lease-query boolean
Synopsis Handle and reply to lease query messages
Contextconfigure service vprn string dhcp-server dhcpv6 string lease-query boolean
Treelease-query
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

pool [pool-name] string
Synopsis Enter the pool list instance
Context configure service vprn string dhcp-server dhcpv6 string pool string
Treepool
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[pool-name] string
Synopsis DHCP server pool name
Context configure service vprn string dhcp-server dhcpv6 string pool string
Treepool
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

delegated-prefix
Synopsis Enter the delegated-prefix context
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string delegated-prefix
Treedelegated-prefix
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

exclude-prefix [ipv6-prefix] string
Synopsis Add a list entry for exclude-prefix
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string exclude-prefix string
Treeexclude-prefix
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[ipv6-prefix] string
Synopsis IPv6 prefix to be excluded from available pool prefixes
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string exclude-prefix string
Treeexclude-prefix

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

failover
Synopsis Enter the failover context
Context configure service vprn string dhcp-server dhcpv6 string pool string failover
Treefailover
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the failover mechanism
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string failover admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ignore-mclt-on-takeover boolean
Synopsis Ignore maximum client lead during takeover from partner
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string failover ignore-mclt-on-takeover boolean
Treeignore-mclt-on-takeover

Description

When configured to true, the remote IP address range can be taken over immediately when the intercommunication link enters the PARTNER-DOWN state, without having to wait for the MCLT to expire.

When configured to false, the DHCP lease time for new clients is restricted to the MCLT during a failure. For existing clients, the lease time is gradually reduced over time to the MCLT by consecutive DHCP renewals.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

maximum-client-lead-time number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum time that DHCP server can extend client's lease
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string failover maximum-client-lead-time number
Treemaximum-client-lead-time

Description

This command configures the maximum client lead time (MCLT), which is the maximum time that a DHCP server can extend the client's lease time beyond the lease time currently known by the DHCP partner node. In dual-homed environments, the initial lease time for all DHCP clients is restricted to the MCLT by default. Consecutive DHCP renewals can extend the lease time beyond the MCLT.

Range600 to 86399
Unitsseconds
Default 600
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

partner-down-delay number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDelay to prevent lease duplication during link failure
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string failover partner-down-delay number
Treepartner-down-delay

Description

This command configures the interval before a failed intercommunication link transitions from the COMM-INT state to the PARTNER-DOWN state. This delay prevents IP lease duplication during link failure by not allowing new IP addresses to be assigned from the remote IP address range. This timer is intended to provide the operator with enough time to remedy the failed situation and avoid duplication of IP addresses and prefixes during the failure.

Range0 to 86399
Unitsseconds
Default 86399
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

peer [address] reference
Synopsis Enter the peer list instance
Context configure service vprn string dhcp-server dhcpv6 string pool string failover peer reference
Treepeer
Max. Instances1
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[address] reference
Synopsis IP address of the failover peer
Context configure service vprn string dhcp-server dhcpv6 string pool string failover peer reference
Treepeer

Reference

configure redundancy multi-chassis peer (ipv4-address-no-zone | ipv6-address-no-zone)

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

sync-tag string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTag that identifies synchronizing server or pool pairs
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string failover peer reference sync-tag string
Treesync-tag
String Length1 to 32

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

startup-wait-time number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTime between initialization and assuming active role
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string failover startup-wait-time number
Treestartup-wait-time

Description

This command configures a delay that avoids transient issues during the initialization process. During startup wait time, each failover peer waits after the initialization process before assuming the active role for the prefix designated as local or remote.

Range60 to 3600
Unitsseconds
Default 120
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

options
Synopsis Enter the options context
Context configure service vprn string dhcp-server dhcpv6 string pool string options
Treeoptions
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

option [number] (number | keyword)
Synopsis Enter the option list instance
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string options option (number | keyword)
Treeoption
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[number] (number | keyword)
Synopsis DHCP option to send as identification string
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string options option (number | keyword)
Treeoption
Range1 to 65535
Optionsdns-server, domain-name

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ascii-string string
Synopsis DHCP option specified as an ASCII string
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string options option (number | keyword) ascii-string string
Treeascii-string
String Length1 to 127

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

domain-string string
Synopsis DHCP option specified as a domain name
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string options option (number | keyword) domain-string string
Treedomain-string
String Length1 to 127

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

duration number
Synopsis DHCP option specified as time
Context configure service vprn string dhcp-server dhcpv6 string pool string options option (number | keyword) duration number
Treeduration
Range10 to 315446399
Unitsseconds

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

empty
Synopsis Empty DHCP option
Context configure service vprn string dhcp-server dhcpv6 string pool string options option (number | keyword) empty
Treeempty

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

hex-string string
Synopsis DHCP option specified as hexadecimal string
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string options option (number | keyword) hex-string string
Treehex-string
String Length1 to 256

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv6-address string
Synopsis DHCP option specified as a list of IPv6 addresses
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string options option (number | keyword) ipv6-address string
Treeipv6-address
Max. Instances4

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

This element is ordered by the user.

Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

prefix [ipv6-prefix] string
Synopsis Enter the prefix list instance
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string prefix string
Treeprefix
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[ipv6-prefix] string
Synopsis IPv6 prefix to be excluded from available pool prefixes
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string prefix string
Treeprefix

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

drain boolean
Synopsis No new leases can be assigned
Context configure service vprn string dhcp-server dhcpv6 string pool string prefix string drain boolean
Treedrain
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

failover-control-type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisFailover control type for this range
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string prefix string failover-control-type keyword
Treefailover-control-type
Optionslocal, remote, access-driven
Defaultlocal
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

options
Synopsis Enter the options context
Context configure service vprn string dhcp-server dhcpv6 string pool string prefix string options
Treeoptions
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

option [number] (number | keyword)
Synopsis Enter the option list instance
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string prefix string options option (number | keyword)
Treeoption
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[number] (number | keyword)
Synopsis DHCP option to send as identification string
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string prefix string options option (number | keyword)
Treeoption
Range1 to 65535
Optionsdns-server, domain-name

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ascii-string string
Synopsis DHCP option specified as an ASCII string
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string prefix string options option (number | keyword) ascii-string string
Treeascii-string
String Length1 to 127

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

domain-string string
Synopsis DHCP option specified as a domain name
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string prefix string options option (number | keyword) domain-string string
Treedomain-string
String Length1 to 127

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

duration number
Synopsis DHCP option specified as time
Context configure service vprn string dhcp-server dhcpv6 string pool string prefix string options option (number | keyword) duration number
Treeduration
Range10 to 315446399
Unitsseconds

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

empty
Synopsis Empty DHCP option
Context configure service vprn string dhcp-server dhcpv6 string pool string prefix string options option (number | keyword) empty
Treeempty

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

hex-string string
Synopsis DHCP option specified as hexadecimal string
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string prefix string options option (number | keyword) hex-string string
Treehex-string
String Length1 to 256

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv6-address string
Synopsis DHCP option specified as a list of IPv6 addresses
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string prefix string options option (number | keyword) ipv6-address string
Treeipv6-address
Max. Instances4

Notes

The following elements are part of a mandatory choice: ascii-string, domain-string, duration, empty, hex-string, or ipv6-address.

This element is ordered by the user.

Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

preferred-lifetime number
Synopsis Time this lease remains preferred
Context configure service vprn string dhcp-server dhcpv6 string pool string prefix string preferred-lifetime number
Treepreferred-lifetime

Description

This command configures the preferred lifetime of the IPv6 lease address or prefix. When the preferred lifetime expires, any derived addresses are deprecated. The preferred lifetime must be less than or equal to the valid lifetime. 

Each address or prefix assigned to the client has associated preferred and valid lifetimes specified by the address assignment authority (such as the DHCP server, RADIUS, or ESM). To request an extension of the lifetimes assigned to an address, the client sends a renew message to the addressing authority. The authority sends a reply message to the client with the new lifetimes, allowing the client to continue to use the address/prefix without interruption. The lifetimes are transmitted from the addressing authority to the client in the identity association (IA) option at the top level of the message (not the address or prefix level).

Range300 to 315446399
Unitsseconds
Default 3600
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

prefix-length-threshold [prefix-length] number
Synopsis Enter the prefix-length-threshold list instance
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string prefix string prefix-length-threshold number
Treeprefix-length-threshold
Max. Instances8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

absolute number
Synopsis Minimum number of free prefixes for this prefix length
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string prefix string prefix-length-threshold number absolute number
Treeabsolute
Range1 to 4294967295

Notes

The following elements are part of a choice: absolute or percent.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

percent number
Synopsis Minimum percentage of free prefixes for prefix length
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string prefix string prefix-length-threshold number percent number
Treepercent
Range1 to 100

Notes

The following elements are part of a choice: absolute or percent.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

prefix-type
Synopsis Enter the prefix-type context
Context configure service vprn string dhcp-server dhcpv6 string pool string prefix string prefix-type
Treeprefix-type
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

pd boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisAllocate IA-PD prefixes from this prefix pool
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string prefix string prefix-type pd boolean
Treepd
Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

wan-host boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisAllocate IA-NA or SLAAC prefixes from this prefix pool
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string prefix string prefix-type wan-host boolean
Treewan-host
Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

rebind-time number
Synopsis Rebind time for the lease
Context configure service vprn string dhcp-server dhcpv6 string pool string prefix string rebind-time number
Treerebind-time

Description

This command configures the rebind time, known as T2, at which the client contacts the addressing authority to extend the lifetimes of its leases.

The IP addressing authority (such as the DHCP server, RADIUS, or ESM) controls the time for extending lifetimes on assigned addresses/prefixes through the T1 and T2 parameters assigned to an identity association (IA). At renew time, T1, the client initiates a renew or reply message exchange to extend the lifetimes of any addresses in the IA. The client includes an IA option with all addresses or prefixes currently assigned to the IA in its renew message.

Recommended values for T1 and T2 are 0.5 and 0.8 times the shortest preferred lifetime of the addresses or prefixes in the IA that the addressing authority is willing to extend, respectively. The configured rebind timer value should always be less than or equal to the rebind timer. The T1 and T2 values are carried in the IPV6 address option in the IA.

Range0 to 1209600
Unitsseconds
Default 2880
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

renew-time number
Synopsis Renew time for the lease
Context configure service vprn string dhcp-server dhcpv6 string pool string prefix string renew-time number
Treerenew-time

Description

This command configures the renew time, known as T1, at which the client makes a transition to the lease-renewal state.

The IP addressing authority (such as the DHCP server, RADIUS, or ESM) controls the time for extending lifetimes on assigned addresses/prefixes through the T1 and T2 parameters assigned to an identity association (IA). At renew time, T1, the client initiates a renew/reply message exchange to extend the lifetimes of any addresses in the IA. The client includes an IA option with all addresses/prefixes currently assigned to the IA in its renew message.

Recommended values for T1 and T2 are 0.5 and 0.8 times the shortest preferred lifetime of the addresses or prefixes in the IA that the addressing authority is willing to extend, respectively. The configured renew timer value should always be shorter than or equal to the rebind timer. The T1 and T2 values are carried in the IPV6 address option in the IA.

Range0 to 604800
Unitsseconds
Default 1800
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

valid-lifetime number
Synopsis Time for the lease to remain valid
Context configure service vprn string dhcp-server dhcpv6 string pool string prefix string valid-lifetime number
Treevalid-lifetime

Description

This command configures a valid lifetime for a DHCPv6 lease address or prefix. The valid lifetime is the length of time an address and prefix remains in the valid state. The valid lifetime must be greater than or equal to the preferred lifetime. When the valid lifetime expires, the address and prefix becomes invalid and must not be used in communications. RFC 2461 recommends a default value of 30 days.

Each address and prefix assigned to the client has associated preferred and valid lifetimes specified by the address assignment authority (such as the DHCP server, RADIUS, or ESM). To request an extension of the lifetimes assigned to an address, the client sends a renew message to the addressing authority. The authority sends a reply message to the client with the new lifetimes, allowing the client to continue to use the address and prefix without interruption. The lifetimes are transmitted from the addressing authority to the client in the identity association (IA) option at the top level of the message (not the address or prefix level).

Range300 to 315446399
Unitsseconds
Default 86400
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

prefix-length-threshold [prefix-length] number
Synopsis Enter the prefix-length-threshold list instance
Contextconfigure service vprn string dhcp-server dhcpv6 string pool string prefix-length-threshold number
Treeprefix-length-threshold
Max. Instances8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

pool-selection
Synopsis Enter the pool-selection context
Contextconfigure service vprn string dhcp-server dhcpv6 string pool-selection
Treepool-selection
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

use-link-address
Synopsis Enable the use-link-address context
Contextconfigure service vprn string dhcp-server dhcpv6 string pool-selection use-link-address
Treeuse-link-address

Description

This command configures the local pool selection for DHCPv6 address or prefix assignment to use the link address. When configured, the selected pool contains a prefix covering the link address.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

use-pool-from-client
Synopsis Enable the use-pool-from-client context
Contextconfigure service vprn string dhcp-server dhcpv6 string pool-selection use-pool-from-client
Treeuse-pool-from-client
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

delimiter string
Synopsis Delimiter to combine primary and secondary pool names
Contextconfigure service vprn string dhcp-server dhcpv6 string pool-selection use-pool-from-client delimiter string
Treedelimiter

Description

This command configures a single ASCII character that separates the pool names in DHCP vendor-specific option 82, which identifies the address pool to be used for this client.

String Length1
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

server-id
Synopsis Enter the server-id context
Context configure service vprn string dhcp-server dhcpv6 string server-id
Treeserver-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

duid-enterprise
Synopsis Enter the duid-enterprise context
Contextconfigure service vprn string dhcp-server dhcpv6 string server-id duid-enterprise
Treeduid-enterprise

Notes

The following elements are part of a choice: duid-enterprise or duid-link-local.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ascii-string string
Synopsis DUID enterprise server ID specified as an ASCII string
Contextconfigure service vprn string dhcp-server dhcpv6 string server-id duid-enterprise ascii-string string
Treeascii-string
String Length1 to 58

Notes

The following elements are part of a choice: ascii-string or hex-string.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

hex-string string
Synopsis DUID enterprise server ID specified as a hex string
Contextconfigure service vprn string dhcp-server dhcpv6 string server-id duid-enterprise hex-string string
Treehex-string
String Length1 to 118

Notes

The following elements are part of a choice: ascii-string or hex-string.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

duid-link-local
Synopsis Derive DUID server ID from a system link-layer address
Contextconfigure service vprn string dhcp-server dhcpv6 string server-id duid-link-local
Treeduid-link-local

Notes

The following elements are part of a choice: duid-enterprise or duid-link-local.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

user-identification keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisUser identification method for the DHCP server
Contextconfigure service vprn string dhcp-server dhcpv6 string user-identification keyword
Treeuser-identification
Optionsduid, interface-id, interface-id-link-local
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

dns
Synopsis Enable the dns context
Context configure service vprn string dns
Treedns
Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of DNS
Context configure service vprn string dns admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

default-domain string
Synopsis Domain name added in DNS retries
Context configure service vprn string dns default-domain string
Treedefault-domain

Description

This command configures the DNS domain name to be added in DNS retries when a DNS query is not replied or an empty DNS reply is received.

The name can contain only alphabetical characters (A-Z), numeric characters (0-9), the minus sign (-), and the period (.).

String Length1 to 255
Introduced20.2.R1

Platforms

All

ipv4-source-address (keyword | ipv4-unicast-address)
Synopsis Source address to contact an IPv4 DNS server
Contextconfigure service vprn string dns ipv4-source-address (keyword | ipv4-unicast-address)
Treeipv4-source-address
Optionsuse-interface-ip
Defaultuse-interface-ip
Introduced16.0.R1

Platforms

All

ipv6-source-address (keyword | ipv6-unicast-address)
Synopsis Source address to contact an IPv6 DNS server
Contextconfigure service vprn string dns ipv6-source-address (keyword | ipv6-unicast-address)
Treeipv6-source-address
Optionsuse-interface-ip
Defaultuse-interface-ip
Introduced16.0.R1

Platforms

All

server (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis DNS server used for DNS name resolution
Contextconfigure service vprn string dns server (ipv4-address-no-zone | ipv6-address-no-zone)
Treeserver
Max. Instances3

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

All

ecmp number
Synopsis Maximum equal-cost routes for routing table instance
Contextconfigure service vprn string ecmp number
Treeecmp

Description

This command configures ECMP and defines the number of routes for path sharing.

ECMP can be used only for routes learned with the same preference and the same protocol.

If available ECMP routes at the best preference exceed the maximum ECMP routes allowed, the system selects the route using the following criteria:

  1. The system selects the lowest next hop router ID.

  2. If the next hop goes to the same neighbor, the system selects the next hop with the lowest interface index.

Range1 to 64
Default1
Introduced 16.0.R1

Platforms

All

entropy-label boolean
Synopsis Use entropy label
Context configure service vprn string entropy-label boolean
Treeentropy-label

Description

When configured to true, this command enables the use of entropy labels.

The entropy label and indicator (EL/ELI) are inserted on relevant packets. Applicable packets are those for which at least one LSP in the stack at the far end has advertised the entropy-label capability. These LSPs are in LDP or RSVP tunnels used by an IGP or BGP shortcut. If the tunnel is of type RSVP, the entropy-label capability must also be enabled under the configure router mpls or configure router mpls lsp context.

This command also results in other traffic that is forwarded over an LDP or RSVP LSP for which this router is the LER, and for which there is no explicit service endpoint on this router, to have the EL/ELI enabled, subject to the LSP far-end advertising entropy-label-capability. An example of such traffic includes packets arriving on a stitched LDP LSP forwarded over an RSVP LSP.

The entropy label and the hash label features are mutually exclusive. The entropy label cannot be configured on a spoke SDP or service where the hash label feature has already been configured.

When configured to false, the use of entropy labels is disabled.

Defaultfalse
Introduced16.0.R1

Platforms

All

eth-cfm
Synopsis Enter the eth-cfm context
Context configure service vprn string eth-cfm
Treeeth-cfm
Introduced19.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

export-inactive-bgp boolean
Synopsis Export preferred BGP route even if inactive
Contextconfigure service vprn string export-inactive-bgp boolean
Treeexport-inactive-bgp

Description

When configured to true, the preferred BGP route learned by a VPRN is exported as the VPN-IP route even if it is inactive in the route table because a preferred BGP VPRN route from another PE is present. This overrides the default state in which the VPRN cannot export an inactive BGP route. For the BGP route to be exported, the VRF export policy must accept it. This command applies to both MPLS VPN and SRv6 VPN routes. In SRv6 VPN routes the advertised instruction is an End.DT, while in MPLS VPN routes the advertised label is a per-next-hop label.This “best-external” type of route advertisement is useful in active/standby multi-homing scenarios because it ensures that all PEs know about the backup path provided by the standby PE.

When configured to false, the preferred BGP route is not exported if it is inactive.

Defaultfalse
Introduced16.0.R1

Platforms

All

export-inactive-bgp-enhanced boolean
Synopsis Export best BGP route when better non-BGP route present
Contextconfigure service vprn string export-inactive-bgp-enhanced boolean
Treeexport-inactive-bgp-enhanced

Description

When configured to true, the router allows a BGP route that is inactive (because a better non-BGP route for the same prefix is present) to be exportable as a VPN-IP route.

A BGP route learned from a VPRN BGP peer is exportable as a VPN-IP route, only if it is the best route for the prefix and is installed in the route table of the VPRN. If the export-inactive-bgp command is true in the VPRN configuration, this rule is relaxed, and the best inactive VPRN BGP route is exportable as a VPN-IP route, provided that the active installed route for the prefix is an imported VPN-IP route.

The rule described in the preceding paragraph can be relaxed even further by configuring this command to true. When this command is true, the best inactive VPRN BGP route (best amongst all routes received from all CEs) is exportable as a VPN-IP route, regardless of the route type of the active installed route.

The configuration of this command overrides the export-inactive-bgp command. If this command is true, the export-inactive-bgp command does not need to be true.

When configured to false, the router disables allowing an inactive BGP route in the presence of a better non-BGP route to be exportable as a VPN-IP route.

Defaultfalse
Introduced23.7.R1

Platforms

All

fib-priority keyword
Synopsis FIB priority for VPRN BGP routes
Context configure service vprn string fib-priority keyword
Treefib-priority
Optionsstandard, high
Default standard
Introduced16.0.R1

Platforms

All

firewall
Synopsis Enter the firewall context
Context configure service vprn string firewall
Treefirewall
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

domain [name] string
Synopsis Enter the domain list instance
Contextconfigure service vprn string firewall domain string
Treedomain
Max. Instances1024
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis Firewall domain name
Context configure service vprn string firewall domain string
Treedomain
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the firewall domain
Contextconfigure service vprn string firewall domain string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

dhcpv6-server
Synopsis Enter the dhcpv6-server context
Contextconfigure service vprn string firewall domain string dhcpv6-server
Treedhcpv6-server
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

name string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDHCPv6 server name
Contextconfigure service vprn string firewall domain string dhcpv6-server name string
Treename
String Length1 to 32
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

router-instance string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRouter name
Contextconfigure service vprn string firewall domain string dhcpv6-server router-instance string
Treerouter-instance
Introduced16.0.R4

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

nat-group reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNAT group for this domain
Contextconfigure service vprn string firewall domain string nat-group reference
Treenat-group

Reference

configure isa nat-group number

Notes

The following elements are part of a mandatory choice: nat-group or wlan-gw-group.

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

prefix [ip-prefix] string
Synopsis Enter the prefix list instance
Contextconfigure service vprn string firewall domain string prefix string
Treeprefix
Max. Instances4096
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

[ip-prefix] string
Synopsis IP prefix and prefix length for the domain firewall
Contextconfigure service vprn string firewall domain string prefix string
Treeprefix

Description

This command configures a prefix for which firewall functionality applies within the domain. Prefixes cannot be shared or duplicated across multiple domains in the same routing context. A domain can contain multiple prefixes.

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

wlan-gw-group reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisWLAN GW group used for NAT
Contextconfigure service vprn string firewall domain string wlan-gw-group reference
Treewlan-gw-group

Reference

configure isa wlan-gw-group number

Notes

The following elements are part of a mandatory choice: nat-group or wlan-gw-group.

Introduced16.0.R4

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

flowspec
Synopsis Enter the flowspec context
Context configure service vprn string flowspec
Treeflowspec
Introduced16.0.R1

Platforms

All

filter-cam-type keyword
Synopsis Filter policy type for FlowSpec embedding
Contextconfigure service vprn string flowspec filter-cam-type keyword
Treefilter-cam-type

Description

This command specifies the filter type that is required to embed FlowSpec entries. The filter type defines the match criteria that are available in the filter policy.

Optionsnormal, packet-length
Defaultnormal
Introduced 20.7.R1

Platforms

All

ip-filter-max-size number
Synopsis Maximum number of flowspec rule entries in IPv4 filter
Contextconfigure service vprn string flowspec ip-filter-max-size number
Treeip-filter-max-size

Description

This command configures the maximum number of IPv4 flowspec routes, or rules, that can be entered in the auto-created embedded filter, fSpec-X. Flowspec filter entries embedded in a filter policy in this routing instance will use filter entries from the range between the embedding offset and (offset + ip-filter-max-size – 1).

The sum of the maximum-size value and the highest offset in any IPv4 filter that embeds IPv4 flowspec rules from this routing instance (excluding filters that embed at offset 262143) must not exceed 262143.

The maximum size can be adjusted up or down at any time. If the current number of IPv4 flowspec rules is greater than the new maximum, the extra rules are removed immediately but retained in the BGP RIB. If the limit is increased, new rules are programmed only as they are received in new BGP updates.

Range0 to 262143
Default512
Introduced 16.0.R1

Platforms

All

ipv6-filter-max-size number
Synopsis Maximum number of flowspec rule entries in IPv6 filter
Contextconfigure service vprn string flowspec ipv6-filter-max-size number
Treeipv6-filter-max-size

Description

This command configures the maximum number of IPv6 flowspec routes or rules that can be embedded into an ingress IPv6 filter policy for a specified routing instance. Flowspec filter entries embedded in a filter policy in this routing instance will use filter entries from the range between the embedding offset and (offset + ip-filter-max-size – 1).

The sum of the maximum-size value and the highest offset in any IPv6 filter that embeds IPv6 flowspec rules from this routing instance (excluding filters that embed at offset 262143) must not exceed 262143.

The maximum size can be adjusted up or down at any time. If the current number of IPv6 flowspec rules is greater than the new maximum, the extra rules are removed immediately but retained in the BGP RIB. If the limit is increased, new rules are programmed only as they are received in new BGP updates.

Range0 to 262143
Default512
Introduced 16.0.R1

Platforms

All

grt-leaking
Synopsis Enter the grt-leaking context
Context configure service vprn string grt-leaking
Treegrt-leaking
Introduced16.0.R1

Platforms

All

allow-local-management boolean
Synopsis Enable management traffic
Context configure service vprn string grt-leaking allow-local-management boolean
Treeallow-local-management

Description

When configured to true, this command enables the support of specific management protocols over VPRN interfaces that terminate on Base routing context IPv4 and IPv6 interface addresses, including Base loopback and system addresses. 

This command does not control the support for management protocols terminating on VPRN interfaces directly. 

Defaultfalse
Introduced16.0.R1

Platforms

All

export-grt
Synopsis Enter the export-grt context
Context configure service vprn string grt-leaking export-grt
Treeexport-grt
Introduced16.0.R1

Platforms

All

policy-name (policy-expr-string | string)
Synopsis Route policy name or policy logical expression
Contextconfigure service vprn string grt-leaking export-grt policy-name (policy-expr-string | string)
Treepolicy-name
String Length1 to 255
Max. Instances5

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

All

import-grt
Synopsis Enter the import-grt context
Context configure service vprn string grt-leaking import-grt
Treeimport-grt
Introduced16.0.R4

Platforms

All

policy-name (policy-expr-string | string)
Synopsis Route policy name or policy logical expression
Contextconfigure service vprn string grt-leaking import-grt policy-name (policy-expr-string | string)
Treepolicy-name
String Length1 to 255
Max. Instances5

Notes

This element is ordered by the user.

Introduced16.0.R4

Platforms

All

gsmp
Synopsis Enter the gsmp context
Context configure service vprn string gsmp
Treegsmp
Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of GSMP
Context configure service vprn string gsmp admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

group [name] string
Synopsis Enter the group list instance
Context configure service vprn string gsmp group string
Treegroup
Max. Instances1024
Introduced16.0.R1

Platforms

All

[name] string
Synopsis GSMP group name
Context configure service vprn string gsmp group string
Treegroup
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the GSMP group
Contextconfigure service vprn string gsmp group string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

ancp
Synopsis Enter the ancp context
Context configure service vprn string gsmp group string ancp
Treeancp
Introduced16.0.R1

Platforms

All

oam boolean
Synopsis Enable GSMP ANCP OAM capability at startup of GSMP connection
Contextconfigure service vprn string gsmp group string ancp oam boolean
Treeoam
Defaultfalse
Introduced16.0.R1

Platforms

All

keepalive number
Synopsis Keepalive value for the GSMP connections in this group
Contextconfigure service vprn string gsmp group string keepalive number
Treekeepalive
Range1 to 25
Unitsseconds
Default 10
Introduced16.0.R1

Platforms

All

neighbor [remote-address] string
Synopsis Enter the neighbor list instance
Contextconfigure service vprn string gsmp group string neighbor string
Treeneighbor
Introduced16.0.R1

Platforms

All

[remote-address] string
Synopsis GSMP neighbor remote IP address
Context configure service vprn string gsmp group string neighbor string
Treeneighbor

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

local-address string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRestrict connections to this local address only within the service running ANCP
Contextconfigure service vprn string gsmp group string neighbor string local-address string
Treelocal-address
Introduced16.0.R1

Platforms

All

priority-marking
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the priority-marking context
Contextconfigure service vprn string gsmp group string neighbor string priority-marking
Treepriority-marking
Introduced16.0.R1

Platforms

All

dscp keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDSCP that is used while remarking the in profile packets
Contextconfigure service vprn string gsmp group string neighbor string priority-marking dscp keyword
Treedscp
Optionsbe, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63

Notes

The following elements are part of a choice: dscp or prec.

Introduced16.0.R1

Platforms

All

prec number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPrecedence priority marking
Contextconfigure service vprn string gsmp group string neighbor string priority-marking prec number
Treeprec
Range0 to 7

Notes

The following elements are part of a choice: dscp or prec.

Introduced16.0.R1

Platforms

All

persistency boolean
Synopsis Store DSL line information when the GSMP connection terminates
Contextconfigure service vprn string gsmp group string persistency boolean
Treepersistency
Defaultfalse
Introduced16.0.R1

Platforms

All

gtp
Synopsis Enter the gtp context
Context configure service vprn string gtp
Treegtp
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

s11
Synopsis Enter the s11 context
Context configure service vprn string gtp s11
Trees11
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

interface [interface-name] reference
Synopsis Enter the interface list instance
Contextconfigure service vprn string gtp s11 interface reference
Treeinterface
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

[interface-name] reference
Synopsis Interface name
Contextconfigure service vprn string gtp s11 interface reference
Treeinterface

Reference

configure service vprn string interface string

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

peer-profile-map
Synopsis Enter the peer-profile-map context
Contextconfigure service vprn string gtp s11 peer-profile-map
Treepeer-profile-map
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

prefix [peer-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis Enter the prefix list instance
Contextconfigure service vprn string gtp s11 peer-profile-map prefix (ipv4-prefix | ipv6-prefix)
Treeprefix
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

[peer-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis IP prefix and prefix length of the subnet
Contextconfigure service vprn string gtp s11 peer-profile-map prefix (ipv4-prefix | ipv6-prefix)
Treeprefix

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

upf-data-endpoint
Synopsis Enable the upf-data-endpoint context
Contextconfigure service vprn string gtp upf-data-endpoint
Treeupf-data-endpoint

Description

Commands in this context configure a GTP-U service endpoint used by BNG CUPS FWA sessions.

Introduced21.2.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

fpe reference
Synopsis FPE used to encapsulate and decapsulate GTP-U traffic
Contextconfigure service vprn string gtp upf-data-endpoint fpe reference
Treefpe

Reference

configure fwd-path-ext fpe number

Notes

This element is mandatory.

Introduced21.5.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

uplink
Synopsis Enable the uplink context
Context configure service vprn string gtp uplink
Treeuplink
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

apn string
Synopsis Network Identifier part of APN
Context configure service vprn string gtp uplink apn string
Treeapn
String Length1 to 80
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

pdn-type keyword
Synopsis Default 3GPP PDN in GTP
Context configure service vprn string gtp uplink pdn-type keyword
Treepdn-type
Optionsipv4, ipv6, ipv4v6
Defaultipv4
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

peer-profile-map
Synopsis Enter the peer-profile-map context
Contextconfigure service vprn string gtp uplink peer-profile-map
Treepeer-profile-map
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

prefix [peer-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis Enter the prefix list instance
Contextconfigure service vprn string gtp uplink peer-profile-map prefix (ipv4-prefix | ipv6-prefix)
Treeprefix
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

[peer-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis IP prefix and prefix length of the subnet
Contextconfigure service vprn string gtp uplink peer-profile-map prefix (ipv4-prefix | ipv6-prefix)
Treeprefix

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

hash-label boolean
Synopsis Include hash label
Context configure service vprn string hash-label boolean
Treehash-label
Defaultfalse
Introduced16.0.R1

Platforms

All

igmp
Synopsis Enable the igmp context
Context configure service vprn string igmp
Treeigmp
Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of IGMP
Context configure service vprn string igmp admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

forwarding-group-interface forwarding-service string group-interface-name reference
Synopsis Enter the forwarding-group-interface list instance
Contextconfigure service vprn string igmp forwarding-group-interface forwarding-service string group-interface-name reference
Treeforwarding-group-interface
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

import-policy reference
Synopsis Import policy that filters IGMP packets
Contextconfigure service vprn string igmp forwarding-group-interface forwarding-service string group-interface-name reference import-policy reference
Treeimport-policy

Description

This command configures the IGMP import policy, or filter, for an interface subscriber or a group interface. An IGMP filter is also known as a black or white list, and it is defined as a router policy option.

When redirection is applied, only the import policy from the subscriber is in effect. The import policy under the group interface is applicable only for IGMP states received directly on the SAP (AN in IGMP proxy mode).

Reference

configure policy-options policy-statement string

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

maximum-number-group-sources number
Synopsis Maximum number of group sources for this interface
Contextconfigure service vprn string igmp forwarding-group-interface forwarding-service string group-interface-name reference maximum-number-group-sources number
Treemaximum-number-group-sources

Description

This command configures the maximum number of group sources for which IGMP or MLD can have local receiver information based on received IGMP or MLD reports on this interface. When this configuration is changed dynamically to a lower value than the currently accepted number of group sources, the group sources that are already accepted are not deleted. Only new group sources are not allowed.

Range1 to 32000
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

mcac
Synopsis Enter the mcac context
Context configure service vprn string igmp forwarding-group-interface forwarding-service string group-interface-name reference mcac
Treemcac
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

bandwidth
Synopsis Enter the bandwidth context
Context configure service vprn string igmp forwarding-group-interface forwarding-service string group-interface-name reference mcac bandwidth
Treebandwidth
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

policy reference
Synopsis Multicast CAC policy name
Context configure service vprn string igmp forwarding-group-interface forwarding-service string group-interface-name reference mcac policy reference
Treepolicy

Description

This command configures the name of the global channel bandwidth definition policy that is used for (H)MCAC and HQoS adjustment.

Within the scope of HQoS adjustment, the channel definition policy under the group interface is used if redirection is unconfigured. In this case, the HQoS adjustment can be applied to IPoE subscribers in per-SAP replication mode.

If redirection is configured, the channel bandwidth definition policy applied under the Layer 3 redirected interface is in effect.

Hierarchical MCAC (HMCAC) is supported on two levels simultaneously:

  • subscriber level and redirected interface when redirection is configured

  • subscriber level and group-interface level when redirection is unconfigured

In HMCAC, the subscriber is checked against its bandwidth limits first, then against the bandwidth limits of the redirected or group interface. If redirection is configured but the policy is referenced only under the group interface, no admission control is executed (HMCAC or MCAC).

Reference

configure mcac policy string

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

group-interface [group-interface-name] reference
Synopsis Enter the group-interface list instance
Contextconfigure service vprn string igmp group-interface reference
Treegroup-interface
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of IGMP
Context configure service vprn string igmp group-interface reference admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

import-policy reference
Synopsis Import policy that filters IGMP packets
Contextconfigure service vprn string igmp group-interface reference import-policy reference
Treeimport-policy

Description

This command configures the IGMP import policy, or filter, for an interface subscriber or a group interface. An IGMP filter is also known as a black or white list, and it is defined as a router policy option.

When redirection is applied, only the import policy from the subscriber is in effect. The import policy under the group interface is applicable only for IGMP states received directly on the SAP (AN in IGMP proxy mode).

Reference

configure policy-options policy-statement string

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

maximum-number-group-sources number
Synopsis Maximum number of group sources for this interface
Contextconfigure service vprn string igmp group-interface reference maximum-number-group-sources number
Treemaximum-number-group-sources

Description

This command configures the maximum number of group sources for which IGMP or MLD can have local receiver information based on received IGMP or MLD reports on this interface. When this configuration is changed dynamically to a lower value than the currently accepted number of group sources, the group sources that are already accepted are not deleted. Only new group sources are not allowed.

Range1 to 32000
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

mcac
Synopsis Enter the mcac context
Context configure service vprn string igmp group-interface reference mcac
Treemcac
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

bandwidth
Synopsis Enter the bandwidth context
Context configure service vprn string igmp group-interface reference mcac bandwidth
Treebandwidth
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

mandatory (number | keyword)
Synopsis Pre-reserved bandwidth for all mandatory channels
Contextconfigure service vprn string igmp group-interface reference mcac bandwidth mandatory (number | keyword)
Treemandatory
Range0 to 2147483647
Optionsunlimited
Defaultunlimited
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

total (number | keyword)
Synopsis Maximum allowed bandwidth
Context configure service vprn string igmp group-interface reference mcac bandwidth total (number | keyword)
Treetotal
Range0 to 2147483647
Optionsunlimited
Defaultunlimited
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

policy reference
Synopsis Multicast CAC policy name
Context configure service vprn string igmp group-interface reference mcac policy reference
Treepolicy

Description

This command configures the name of the global channel bandwidth definition policy that is used for (H)MCAC and HQoS adjustment.

Within the scope of HQoS adjustment, the channel definition policy under the group interface is used if redirection is unconfigured. In this case, the HQoS adjustment can be applied to IPoE subscribers in per-SAP replication mode.

If redirection is configured, the channel bandwidth definition policy applied under the Layer 3 redirected interface is in effect.

Hierarchical MCAC (HMCAC) is supported on two levels simultaneously:

  • subscriber level and redirected interface when redirection is configured

  • subscriber level and group-interface level when redirection is unconfigured

In HMCAC, the subscriber is checked against its bandwidth limits first, then against the bandwidth limits of the redirected or group interface. If redirection is configured but the policy is referenced only under the group interface, no admission control is executed (HMCAC or MCAC).

Reference

configure mcac policy string

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

query-source-address string
Synopsis Source address for IGMP queries
Context configure service vprn string igmp group-interface reference query-source-address string
Treequery-source-address

Description

This command configures the query source IP address for the group interface. This IP address overrides the source IP address configured at the router level.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

version keyword
Synopsis IGMP protocol version
Context configure service vprn string igmp group-interface reference version keyword
Treeversion
Options1, 2, 3
Default3
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

interface [ip-interface-name] string
Synopsis Enter the interface list instance
Contextconfigure service vprn string igmp interface string
Treeinterface
Introduced16.0.R1

Platforms

All

[ip-interface-name] string
Synopsis IP interface name
Context configure service vprn string igmp interface string
Treeinterface
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R2

Platforms

All

import-policy reference
Synopsis Import policy that filters IGMP packets
Contextconfigure service vprn string igmp interface string import-policy reference
Treeimport-policy

Description

This command configures the IGMP import policy, or filter, for an interface subscriber or a group interface. An IGMP filter is also known as a black or white list, and it is defined as a router policy option.

When redirection is applied, only the import policy from the subscriber is in effect. The import policy under the group interface is applicable only for IGMP states received directly on the SAP (AN in IGMP proxy mode).

Reference

configure policy-options policy-statement string

Introduced16.0.R1

Platforms

All

maximum-number-group-sources number
Synopsis Maximum number of group sources for this interface
Contextconfigure service vprn string igmp interface string maximum-number-group-sources number
Treemaximum-number-group-sources

Description

This command configures the maximum number of group sources for which IGMP or MLD can have local receiver information based on received IGMP or MLD reports on this interface. When this configuration is changed dynamically to a lower value than the currently accepted number of group sources, the group sources that are already accepted are not deleted. Only new group sources are not allowed.

Range1 to 32000
Introduced16.0.R1

Platforms

All

mcac
Synopsis Enter the mcac context
Context configure service vprn string igmp interface string mcac
Treemcac
Introduced16.0.R1

Platforms

All

bandwidth
Synopsis Enter the bandwidth context
Context configure service vprn string igmp interface string mcac bandwidth
Treebandwidth
Introduced16.0.R1

Platforms

All

mandatory (number | keyword)
Synopsis Pre-reserved bandwidth for all mandatory channels
Contextconfigure service vprn string igmp interface string mcac bandwidth mandatory (number | keyword)
Treemandatory
Range0 to 2147483647
Optionsunlimited
Defaultunlimited
Introduced16.0.R1

Platforms

All

total (number | keyword)
Synopsis Maximum allowed bandwidth
Context configure service vprn string igmp interface string mcac bandwidth total (number | keyword)
Treetotal
Range0 to 2147483647
Optionsunlimited
Defaultunlimited
Introduced16.0.R1

Platforms

All

mc-constraints
Synopsis Enter the mc-constraints context
Contextconfigure service vprn string igmp interface string mcac mc-constraints
Treemc-constraints
Introduced16.0.R1

Platforms

All

level [level-id] number
Synopsis Enter the level list instance
Context configure service vprn string igmp interface string mcac mc-constraints level number
Treelevel
Introduced16.0.R1

Platforms

All

number-down [number-lag-port-down] number
Synopsis Enter the number-down list instance
Contextconfigure service vprn string igmp interface string mcac mc-constraints number-down number
Treenumber-down
Introduced16.0.R1

Platforms

All

level number
Synopsis Level ID to associate with number of down LAG ports
Contextconfigure service vprn string igmp interface string mcac mc-constraints number-down number level number
Treelevel

Description

This command specifies the bandwidth for a given level. Level 1 has the highest priority and level 8 has the lowest priority.

Range1 to 8

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

use-lag-port-weight boolean
Synopsis Use LAG port weight in calculating MCAC constraints
Contextconfigure service vprn string igmp interface string mcac mc-constraints use-lag-port-weight boolean
Treeuse-lag-port-weight

Description

When configured to true, port weight is used when determining available bandwidth per level when LAG ports go down or come up. This command is required for proper operation on mixed port-speed LAGs and can also be used for unmixed port-speed LAGs.

Defaultfalse
Introduced16.0.R1

Platforms

All

policy reference
Synopsis Multicast CAC policy name
Context configure service vprn string igmp interface string mcac policy reference
Treepolicy

Description

This command configures the name of the global channel bandwidth definition policy that is used for (H)MCAC and HQoS adjustment.

Within the scope of HQoS adjustment, the channel definition policy under the group interface is used if redirection is unconfigured. In this case, the HQoS adjustment can be applied to IPoE subscribers in per-SAP replication mode.

If redirection is configured, the channel bandwidth definition policy applied under the Layer 3 redirected interface is in effect.

Hierarchical MCAC (HMCAC) is supported on two levels simultaneously:

  • subscriber level and redirected interface when redirection is configured

  • subscriber level and group-interface level when redirection is unconfigured

In HMCAC, the subscriber is checked against its bandwidth limits first, then against the bandwidth limits of the redirected or group interface. If redirection is configured but the policy is referenced only under the group interface, no admission control is executed (HMCAC or MCAC).

Reference

configure mcac policy string

Introduced16.0.R1

Platforms

All

ssm-translate
Synopsis Enter the ssm-translate context
Contextconfigure service vprn string igmp interface string ssm-translate
Treessm-translate
Introduced16.0.R1

Platforms

All

group-range start string end string
Synopsis Enter the group-range list instance
Contextconfigure service vprn string igmp interface string ssm-translate group-range start string end string
Treegroup-range
Introduced16.0.R1

Platforms

All

source [source-address] string
Synopsis Add a list entry for source
Context configure service vprn string igmp interface string ssm-translate group-range start string end string source string
Treesource
Min. Instances1
Introduced16.0.R1

Platforms

All

static
Synopsis Enter the static context
Context configure service vprn string igmp interface string static
Treestatic
Introduced16.0.R1

Platforms

All

group [group-address] string
Synopsis Enter the group list instance
Context configure service vprn string igmp interface string static group string
Treegroup
Introduced16.0.R1

Platforms

All

[group-address] string
Synopsis Group address of static IGMP multicast channel
Contextconfigure service vprn string igmp interface string static group string
Treegroup

Description

This command configures an address that receives data on an interface. The IP address must be unique for each static group.

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

source [source-address] string
Synopsis Add a list entry for source
Context configure service vprn string igmp interface string static group string source string
Treesource

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced16.0.R1

Platforms

All

[source-address] string
Synopsis Source IP address of multicast channel sending data
Contextconfigure service vprn string igmp interface string static group string source string
Treesource

Notes

This element is part of a list key.

Introduced16.0.R2

Platforms

All

starg
Synopsis any source address (*,G)
Context configure service vprn string igmp interface string static group string starg
Treestarg

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced16.0.R2

Platforms

All

group-range start string end string step string
Synopsis Enter the group-range list instance
Contextconfigure service vprn string igmp interface string static group-range start string end string step string
Treegroup-range
Introduced16.0.R1

Platforms

All

source [source-address] string
Synopsis Add a list entry for source
Context configure service vprn string igmp interface string static group-range start string end string step string source string
Treesource

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced16.0.R1

Platforms

All

query-interval number
Synopsis Time between two consecutive host-query messages
Contextconfigure service vprn string igmp query-interval number
Treequery-interval

Description

This command configures the timing of the host-query messages that solicit group membership information. The messages are sent to the all-systems multicast group address, 224.0.0.1.

Range2 to 1024
Unitsseconds
Default 125
Introduced16.0.R1

Platforms

All

query-last-member-interval number
Synopsis Time between group-specific query messages
Contextconfigure service vprn string igmp query-last-member-interval number
Treequery-last-member-interval

Description

This command configures the timing of the query-message interval, defining the interval for leave-group messages among others. The lower the interval that is configured, the faster the detection of the loss of the last member of a group.

Range1 to 1023
Unitsseconds
Default 1
Introduced16.0.R1

Platforms

All

robust-count number
Synopsis Number of retries after expected message loss
Contextconfigure service vprn string igmp robust-count number
Treerobust-count

Description

This command configures the level of expected packet loss on a subnet. If a subnet anticipates losses, this value can be increased.

Range2 to 10
Default2
Introduced 16.0.R1

Platforms

All

ssm-translate
Synopsis Enter the ssm-translate context
Contextconfigure service vprn string igmp ssm-translate
Treessm-translate
Introduced16.0.R1

Platforms

All

group-range start string end string
Synopsis Enter the group-range list instance
Contextconfigure service vprn string igmp ssm-translate group-range start string end string
Treegroup-range
Introduced16.0.R1

Platforms

All

source [source-address] string
Synopsis Add a list entry for source
Context configure service vprn string igmp ssm-translate group-range start string end string source string
Treesource
Min. Instances1
Introduced16.0.R1

Platforms

All

igmp-host-tracking
Synopsis Enter the igmp-host-tracking context
Contextconfigure service vprn string igmp-host-tracking
Treeigmp-host-tracking
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of IGMP host tracking
Contextconfigure service vprn string igmp-host-tracking admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

expiry-time number
Synopsis Time that the system continues to track inactive hosts
Contextconfigure service vprn string igmp-host-tracking expiry-time number
Treeexpiry-time
Range1 to 65535
Unitsseconds
Default 260
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

interface [interface-name] string
Synopsis Enter the interface list instance
Contextconfigure service vprn string interface string
Treeinterface
Introduced16.0.R1

Platforms

All

[interface-name] string
Synopsis Interface name
Contextconfigure service vprn string interface string
Treeinterface
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the interface
Contextconfigure service vprn string interface string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

cflowd-parameters
Synopsis Enter the cflowd-parameters context
Contextconfigure service vprn string interface string cflowd-parameters
Treecflowd-parameters
Introduced16.0.R1

Platforms

All

sampling [sampling-type] keyword
Synopsis Enter the sampling list instance
Contextconfigure service vprn string interface string cflowd-parameters sampling keyword
Treesampling
Introduced16.0.R1

Platforms

All

[sampling-type] keyword
Synopsis Traffic sampling type
Context configure service vprn string interface string cflowd-parameters sampling keyword
Treesampling

Description

This command configures the type of traffic to be sampled on the associated IP interface.

Optionsunicast, multicast, both

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

direction keyword
Synopsis Direction of traffic for cflowd sampling
Contextconfigure service vprn string interface string cflowd-parameters sampling keyword direction keyword
Treedirection

Description

This command configures the direction in which sampling occurs on the associated IP interfaces.

Optionsingress-only, egress-only, both
Defaultingress-only
Introduced16.0.R1

Platforms

All

type keyword
Synopsis Type of cflowd analysis
Context configure service vprn string interface string cflowd-parameters sampling keyword type keyword
Treetype

Description

This command configures the cflowd sampling type on the associated IP interface.

Optionsacl, interface

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

dynamic-tunnel-redundant-nexthop string
Synopsis Redundant next-hop address for the dynamic IPsec tunnel
Contextconfigure service vprn string interface string dynamic-tunnel-redundant-nexthop string
Treedynamic-tunnel-redundant-nexthop

Description

This command specifies the redundant next-hop address on a public or private IPsec interface (with public or private tunnel SAP) for a dynamic IPsec tunnel. The next-hop address is used by a standby node to shunt traffic to a master if it receives the address.

The next-hop address is resolved in the routing table of a corresponding service.

Notes

The following elements are part of a choice: multi-chassis-shunting-profile or (dynamic-tunnel-redundant-nexthop and static-tunnel-redundant-nexthop).

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

external-reference
Synopsis Enter the external-reference context
Contextconfigure service vprn string interface string external-reference
Treeexternal-reference
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

openconfig
Synopsis Enter the openconfig context
Context configure service vprn string interface string external-reference openconfig
Treeopenconfig

Description

Commands in this context configure the OpenConfig reference key used to map a Nokia vendor-specific configuration and the OpenConfig state.

Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

subinterface number
Synopsis Reference to the subinterface
Context configure service vprn string interface string external-reference openconfig subinterface number
Treesubinterface

Description

This command configures the subinterface used to map a Nokia vendor-specific configuration and the OpenConfig state.

This command configures the ability to query the OpenConfig state through NETCONF, gRPC, and the MD-CLI from any configuration mode, without having to add any OpenConfig model configuration. As part of the configuration, a user must also add a port to the Layer 3 interface.

Range0 to 4294967295
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

hold-time
Synopsis Enter the hold-time context
Context configure service vprn string interface string hold-time
Treehold-time
Introduced16.0.R1

Platforms

All

ipv4
Synopsis Enter the ipv4 context
Context configure service vprn string interface string hold-time ipv4
Treeipv4
Introduced16.0.R1

Platforms

All

down
Synopsis Enter the down context
Context configure service vprn string interface string hold-time ipv4 down
Treedown

Description

Commands in this context configure the down hold timer, which specifies the delay before activating the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface up, unless an operator configures the init-only command. 

Introduced16.0.R1

Platforms

All

init-only boolean
Synopsis Apply delay only at interface configuration or reboot
Contextconfigure service vprn string interface string hold-time ipv4 down init-only boolean
Treeinit-only

Description

This command applies a delay only when the IP interface is first configured or after a system reboot.

Defaultfalse
Introduced16.0.R1

Platforms

All

up
Synopsis Enter the up context
Context configure service vprn string interface string hold-time ipv4 up
Treeup

Description

Commands in this context configure the up hold timer, which specifies the delay before deactivation of the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface down.

Introduced16.0.R1

Platforms

All

ipv6
Synopsis Enter the ipv6 context
Context configure service vprn string interface string hold-time ipv6
Treeipv6
Introduced16.0.R1

Platforms

All

down
Synopsis Enter the down context
Context configure service vprn string interface string hold-time ipv6 down
Treedown

Description

Commands in this context configure the down hold timer, which specifies the delay before activation of the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface up, unless an operator configures the init-only command. 

Introduced16.0.R1

Platforms

All

init-only boolean
Synopsis Apply delay only at interface configuration or reboot
Contextconfigure service vprn string interface string hold-time ipv6 down init-only boolean
Treeinit-only

Description

When configured to true, the system applies a delay only when the IP interface is first configured or after a system reboot.

Defaultfalse
Introduced16.0.R1

Platforms

All

up
Synopsis Enter the up context
Context configure service vprn string interface string hold-time ipv6 up
Treeup

Description

Commands in this context configure the up hold timer, which specifies the delay before deactivation of the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface down.

Introduced16.0.R1

Platforms

All

if-attribute
Synopsis Enter the if-attribute context
Contextconfigure service vprn string interface string if-attribute
Treeif-attribute
Introduced16.0.R1

Platforms

All

ingress
Synopsis Enter the ingress context
Context configure service vprn string interface string ingress
Treeingress
Introduced19.7.R1

Platforms

All

destination-class-lookup boolean
Synopsis Enable BGP destination class lookup
Context configure service vprn string interface string ingress destination-class-lookup boolean
Treedestination-class-lookup

Description

When configured to true, the router performs a destination class lookup. This command is supported on FP3-based cards and later and is used in combination with the destination-class match criterion for an IP filter policy to filter egress traffic based on BGP destination classes.

When configured to false, destination class lookup is not enabled.

Defaultfalse
Introduced20.7.R1

Platforms

All

ip-mtu number
Synopsis IP MTU applied to outgoing packets
Context configure service vprn string interface string ip-mtu number
Treeip-mtu

Description

This command configures the IP maximum transmission unit (MTU) for the associated router IP interface.

Range512 to 9786
Unitsbytes
Introduced 16.0.R1

Platforms

All

ipsec
Synopsis Enable the ipsec context
Context configure service vprn string interface string ipsec
Treeipsec
Introduced22.7.R1

Platforms

VSR

admin-state keyword
Synopsis Administrative state of IPsec secured interface
Contextconfigure service vprn string interface string ipsec admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced22.7.R1

Platforms

VSR

ip-exception reference
Synopsis IP exception filter
Context configure service vprn string interface string ipsec ip-exception reference
Treeip-exception

Description

This command configures the IP exception filter for the secured interface. All ingress traffic matching the specified filter bypasses IPsec processing.

Reference

configure filter ip-exception string

Introduced22.7.R1

Platforms

VSR

ipsec-tunnel [name] string
Synopsis Enter the ipsec-tunnel list instance
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string
Treeipsec-tunnel

Description

Commands in this context configure IPsec tunnels used to secure traffic forwarded over the interface.

Introduced22.7.R1

Platforms

VSR

bfd
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the bfd context
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string bfd
Treebfd
Introduced22.7.R1

Platforms

VSR

bfd-designate boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDesignate IPsec tunnel to carry BFD traffic
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string bfd bfd-designate boolean
Treebfd-designate
Defaultfalse
Introduced22.7.R1

Platforms

VSR

bfd-liveness
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the bfd-liveness context
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string bfd bfd-liveness
Treebfd-liveness

Description

Commands in this context configure a BFD session to provide a heart-beat mechanism for a specified IPsec tunnel. There can be only one BFD session assigned to any given IPsec tunnel, but there can be multiple IPsec tunnels using the same BFD session.

BFD controls the state of the association tunnel. If the BFD session goes down, the system brings down the associated non-designated IPsec tunnel.

Introduced22.7.R1

Platforms

VSR

dest-ip string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDestination address used for the BFD session
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string bfd bfd-liveness dest-ip string
Treedest-ip

Notes

This element is mandatory.

Introduced22.7.R1

Platforms

VSR

interface string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisName of the interface used by the BFD session
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string bfd bfd-liveness interface string
Treeinterface
String Length1 to 32

Notes

This element is mandatory.

Introduced22.7.R1

Platforms

VSR

service-name string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative service name
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string bfd bfd-liveness service-name string
Treeservice-name

Description

This command configures the name of the service where BFD traffic is forwarded to.

String Length1 to 64

Notes

This element is mandatory.

Introduced22.7.R1

Platforms

VSR

clear-df-bit boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisReset the DF bit to 0 in all payload IP packets
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string clear-df-bit boolean
Treeclear-df-bit

Description

When configured to true, the DF bit is set to 0 in all payload IP packets associated with the IPsec tunnel, before any potential fragmentation occurs.

Defaultfalse
Introduced22.7.R1

Platforms

VSR

copy-traffic-class-upon-decapsulation boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable traffic class copy upon decapsulation
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string copy-traffic-class-upon-decapsulation boolean
Treecopy-traffic-class-upon-decapsulation

Description

When configured to true, the system copies the traffic class from the outer tunnel IP packet header to the payload IP packet header in the decapsulating direction (public to private).

Defaultfalse
Introduced22.7.R1

Platforms

VSR

encapsulated-ip-mtu number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum size of the encapsulated tunnel packet
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string encapsulated-ip-mtu number
Treeencapsulated-ip-mtu

Description

This command specifies the maximum size of the encapsulated tunnel packet to the IPsec tunnel, the IP tunnel, or the dynamic tunnels terminated on the IPsec Gateway. If the encapsulated IPv4 or IPv6 tunnel packet exceeds this value, the system fragments the packet.

Range512 to 9000
Unitsbytes
Introduced 22.7.R1

Platforms

VSR

icmp-generation
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the icmp-generation context
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string icmp-generation
Treeicmp-generation

Description

Commands in this context configure settings for ICMPv4 message generation.

Introduced22.7.R1

Platforms

VSR

frag-required
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the frag-required context
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string icmp-generation frag-required
Treefrag-required

Description

Commands in this context configure the attributes for sending generated ICMP Destination Unreachable "fragmentation needed and DF set" messages (type 3, code 4) back to the source, if the received size of the IPv4 packet on the private side exceeds the private MTU size.

Introduced22.7.R1

Platforms

VSR

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of sending ICMP messages
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string icmp-generation frag-required admin-state keyword
Treeadmin-state

Description

This command configures the administrative state of sending ICMP Destination Unreachable "fragmentation needed, DF set" messages (type 3, code 4) messages to the source if the received size of the IPv4 packet on the private side exceeds the private MTU size.

Optionsenable, disable
Default enable
Introduced22.7.R1

Platforms

VSR

interval number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisInterval for sending ICMP messages
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string icmp-generation frag-required interval number
Treeinterval

Description

This command configures the interval for sending ICMP Destination Unreachable "fragmentation needed, DF set" messages (type 3, code 4).

Range1 to 60
Unitsseconds
Default 10
Introduced22.7.R1

Platforms

VSR

message-count number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of ICMP messages that can be sent
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string icmp-generation frag-required message-count number
Treemessage-count

Description

This command configures the maximum number of ICMP Destination Unreachable "fragmentation needed, DF set" messages (type 3, code 4) that can be sent during the configured interval.

Range10 to 1000
Default100
Introduced 22.7.R1

Platforms

VSR

icmp6-generation
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the icmp6-generation context
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string icmp6-generation
Treeicmp6-generation

Description

Commands in this context configure settings for ICMPv6 message generation.

Introduced22.7.R1

Platforms

VSR

packet-too-big
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the packet-too-big context
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string icmp6-generation packet-too-big
Treepacket-too-big

Description

Commands in this context configure the parameters to send ICMPv6 PTB (Packet Too Big) messages on the private side.

The system sends PTB messages if a received IPv6 packet on the private side is greater than 1280 bytes and it exceeds the private MTU of the tunnel.

The private MTU for the tunnel is configured via the configure router interface ipsec ipsec-tunnel ip-mtu command for the interface.

Introduced22.7.R1

Platforms

VSR

message-count number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of ICMPv6 PTB messages that can be sent
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string icmp6-generation packet-too-big message-count number
Treemessage-count

Description

This command configures the maximum number of PTB messages that can be sent during the configured interval.

Range10 to 1000
Default100
Introduced 22.7.R1

Platforms

VSR

ip-mtu number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPrivate MTU of the IPsec tunnel
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string ip-mtu number
Treeip-mtu

Description

This command specifies the private MTU of the IPsec tunnel. The private MTU is used to determine the need for fragmentation before encapsulation of the payload packet.

Range512 to 9000
Unitsbytes
Introduced 22.7.R1

Platforms

VSR

key-exchange
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the key-exchange context
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string key-exchange
Treekey-exchange
Introduced22.7.R1

Platforms

VSR

dynamic
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the dynamic context
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string key-exchange dynamic
Treedynamic

Notes

The following elements are part of a choice: dynamic or manual.

Introduced22.7.R1

Platforms

VSR

cert
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the cert context
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string key-exchange dynamic cert
Treecert

Description

Commands in this context configure the attributes of the dynamic keying certificate.

Introduced22.7.R1

Platforms

VSR

status-verify
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the status-verify context
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string key-exchange dynamic cert status-verify
Treestatus-verify

Description

Commands in this context configure attributes of Certificate Status Verification (CSV).

Introduced22.7.R1

Platforms

VSR

primary keyword
Synopsis Primary method of CSV to verify the revocation status
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string key-exchange dynamic cert status-verify primary keyword
Treeprimary

Description

This command configures the primary method of Certificate Status Verification (CSV) that is used to verify the revocation status of the certificate of the peer.

Optionscrl, ocsp
Default crl
Introduced22.7.R1

Platforms

VSR

secondary keyword
Synopsis Secondary method used to verify certificate revocation
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string key-exchange dynamic cert status-verify secondary keyword
Treesecondary

Description

This command specifies the secondary method of Certificate Status Verification (CSV) that is used to verify the revocation status of the peer certificate.

Optionsnone, crl, ocsp
Defaultnone
Introduced22.7.R1

Platforms

VSR

id
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the id context
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string key-exchange dynamic id
Treeid

Description

Commands in this context specify the local ID used for IDi or IDr for IKEv2 negotiation.

The default behavior depends on the local authentication method as follows:

  • Psk: local tunnel IP address

  • Cert-auth: subject of the local certificate

Introduced22.7.R1

Platforms

VSR

fqdn string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisFQDN used as the local ID IKE type
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string key-exchange dynamic id fqdn string
Treefqdn
String Length1 to 255

Notes

The following elements are part of a choice: fqdn, ipv4, or ipv6.

Introduced22.7.R1

Platforms

VSR

ipv4 string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPv4 as the local ID type
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string key-exchange dynamic id ipv4 string
Treeipv4

Notes

The following elements are part of a choice: fqdn, ipv4, or ipv6.

Introduced22.7.R1

Platforms

VSR

ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPv6 used as the local IKE ID type
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string key-exchange dynamic id ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
Treeipv6

Notes

The following elements are part of a choice: fqdn, ipv4, or ipv6.

Introduced22.7.R1

Platforms

VSR

ike-policy reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIKE policy ID
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string key-exchange dynamic ike-policy reference
Treeike-policy

Description

This command specifies the ID of the IKE policy used for IKE negotiation.

The ipsec-transport-mode-profile configuration only supports IKEv2.

Reference

configure ipsec ike-policy number

Introduced22.7.R1

Platforms

VSR

ipsec-transform reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPsec transform IDs used by the dynamic key
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string key-exchange dynamic ipsec-transform reference
Treeipsec-transform

Description

This command specifies IPsec transform IDs used for CHILD_SA negotiation.

Reference

configure ipsec ipsec-transform number

Max. Instances4
Introduced22.7.R1

Platforms

VSR

manual
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the manual context
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string key-exchange manual
Treemanual

Description

Commands in this context configure settings for manually configured security associations for the IPsec tunnel.

Notes

The following elements are part of a choice: dynamic or manual.

Introduced22.7.R1

Platforms

VSR

keys [security-association] number direction keyword
Synopsis Enter the keys list instance
Context configure service vprn string interface string ipsec ipsec-tunnel string key-exchange manual keys number direction keyword
Treekeys

Description

Commands in this context configure the security association list for the tunnel.

Introduced22.7.R1

Platforms

VSR

spi number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSPI of inbound and outbound packets
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string key-exchange manual keys number direction keyword spi number
Treespi

Description

This command specifies the Security Parameter Index (SPI) used to look up the instruction to verify and decrypt the incoming IPsec packets when the direction is inbound. When the direction is outbound, the SPI is used in the encoding of the outgoing packets.

The remote node can use the SPI to look up the instruction to verify and decrypt the packet.

Range256 to 16383

Notes

This element is mandatory.

Introduced22.7.R1

Platforms

VSR

local-gateway-address-override (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal IPsec tunnel endpoint address
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string local-gateway-address-override (ipv4-address-no-zone | ipv6-address-no-zone)
Treelocal-gateway-address-override

Description

This command configures the local IPsec tunnel endpoint address. This overrides the default endpoint address, which is the interface address.

Introduced22.7.R1

Platforms

VSR

max-history-key-records
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the max-history-key-records context
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string max-history-key-records
Treemax-history-key-records

Description

Commands in this context configure the settings for recording historical IPsec keys.

Introduced22.7.R1

Platforms

VSR

esp number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of recent records
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string max-history-key-records esp number
Treeesp
Range1 to 48
Introduced22.7.R1

Platforms

VSR

ike number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of historical IKE key records
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string max-history-key-records ike number
Treeike
Range1 to 3
Introduced22.7.R1

Platforms

VSR

pmtu-discovery-aging number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAging out time of the learned path MTU
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string pmtu-discovery-aging number
Treepmtu-discovery-aging

Description

This command configures the temporary public and private MTU expiration time. The temporary MTU is used for MTU propagation.

Range900 to 3600
Unitsseconds
Default 900
Introduced22.7.R1

Platforms

VSR

private-sap number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPrivate SAP ID
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string private-sap number
Treeprivate-sap
Range0 to 4094

Notes

This element is mandatory.

Introduced22.7.R1

Platforms

VSR

private-service string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPrivate service name
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string private-service string
Treeprivate-service

Description

This command configures the private service name.

If unconfigured, the private service is the service where the secured interface resides.

String Length1 to 64
Introduced22.7.R1

Platforms

VSR

private-tcp-mss-adjust number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTCP maximum segment size (MSS) adjustment
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string private-tcp-mss-adjust number
Treeprivate-tcp-mss-adjust

Description

This command specifies the TCP MSS to adjust for the tunnel on the private side.

When configured, the system may use the value to update the MSS option in the received TCP SYN packet on the private side.

Range512 to 9000
Unitsbytes
Introduced 22.7.R1

Platforms

VSR

propagate-pmtu-v4 boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable propagation of the path MTU to IPv4 hosts
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string propagate-pmtu-v4 boolean
Treepropagate-pmtu-v4

Description

When configured to true, the system propagates the path MTU learned from the public side to the private side (IPv4 hosts).

Defaulttrue
Introduced22.7.R1

Platforms

VSR

propagate-pmtu-v6 boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable propagation of the path MTU to IPv6 hosts
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string propagate-pmtu-v6 boolean
Treepropagate-pmtu-v6

Description

When configured to true, the system propagates the path MTU learned from the public side to the private side (IPv6 hosts).

Defaulttrue
Introduced22.7.R1

Platforms

VSR

public-tcp-mss-adjust (number | keyword)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTCP maximum segment size (MSS) on the public network
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string public-tcp-mss-adjust (number | keyword)
Treepublic-tcp-mss-adjust

Description

This command configures the MSS for the TCP traffic in an IPsec tunnel that is sent from the public network to the private network. The system may use this value to adjust or insert the MSS option in the TCP SYN packet.

Range512 to 9000
Unitsbytes
Options auto
Introduced 22.7.R1

Platforms

VSR

remote-gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRemote IPsec tunnel endpoint address
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string remote-gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeremote-gateway-address
Introduced22.7.R1

Platforms

VSR

replay-window number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAnti-replay window size
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string replay-window number
Treereplay-window

Description

This command specifies the size of an IPsec anti-replay window. If unconfigured, IPsec anti-replay is disabled.

Range32 | 64 | 128 | 256 | 512
Unitspackets
Introduced22.7.R1

Platforms

VSR

security-policy
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the security-policy context
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string security-policy
Treesecurity-policy

Description

Commands in this context specify a security policy used by the tunnel.

Introduced22.7.R1

Platforms

VSR

id number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSecurity policy ID for use by the tunnel
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string security-policy id number
Treeid
Max. Range0 to 4294967295
Introduced22.7.R1

Platforms

VSR

strict-match boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable strict match of the security policy entry
Contextconfigure service vprn string interface string ipsec ipsec-tunnel string security-policy strict-match boolean
Treestrict-match

Description

When configured to true, this command enables strict match of the security policy entry.

When a CREATE_CHILD exchange request is received for a static IPsec tunnel, and this request is not a rekey request, ISA matches the received TSi and TSr with the configured security policy. This can be a match only when a received TS (in TSi or TSr) address range matches exactly with the subnet in a security policy entry.

If there is no match, the setup fails, and TS_UNACCEPTABLE is sent.

If there is a match, but there is an existing CHILD_SA for the matched security policy, the setup fails, and NO_PROPOSAL_CHOSEN is sent.

If there is a match, and there is not a CHILD_SA for the matched entry, the subnet is sent in the matched security policy entry as TSi and TSr, and the CHILD_SA is created.

Defaultfalse
Introduced22.7.R1

Platforms

VSR

ipv6-exception reference
Synopsis IPv6 filter exception used to bypass encryption
Contextconfigure service vprn string interface string ipsec ipv6-exception reference
Treeipv6-exception

Description

This command specifies the IPv6 filter exception for an IPsec-secured IPv6 interface. When an IPv6 filter exception is added, clear text packets that match the exception criteria in the IPv6 filter exception can ingress the interface, even when IPsec is enabled on the interface.

Reference

configure filter ipv6-exception string

Introduced22.7.R1

Platforms

VSR

public-sap number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPublic SAP ID
Contextconfigure service vprn string interface string ipsec public-sap number
Treepublic-sap
Range0 to 4094

Notes

This element is mandatory.

Introduced22.7.R1

Platforms

VSR

tunnel-group reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTunnel group ID
Contextconfigure service vprn string interface string ipsec tunnel-group reference
Treetunnel-group

Reference

configure isa tunnel-group number

Notes

This element is mandatory.

Introduced22.7.R1

Platforms

VSR

ipv4
Synopsis Enter the ipv4 context
Context configure service vprn string interface string ipv4
Treeipv4
Introduced16.0.R1

Platforms

All

addresses
Synopsis Enter the addresses context
Context configure service vprn string interface string ipv4 addresses
Treeaddresses
Introduced16.0.R1

Platforms

All

address [ipv4-address] string
Synopsis Enter the address list instance
Contextconfigure service vprn string interface string ipv4 addresses address string
Treeaddress
Introduced16.0.R1

Platforms

All

bfd
Synopsis Enter the bfd context
Context configure service vprn string interface string ipv4 bfd
Treebfd
Introduced16.0.R1

Platforms

All

multiplier number
Synopsis Number of consecutive BFD messages missed from the peer
Contextconfigure service vprn string interface string ipv4 bfd multiplier number
Treemultiplier

Description

This command configures the number of missed messages before the BFD session state is changed to down and the upper-level protocol is notified of the fault. A multiplier of less than 3 should not be used in production environments. 

Range1 to 20
Default3
Introduced 16.0.R1

Platforms

All

receive number
Synopsis BFD receive interval over this interface
Contextconfigure service vprn string interface string ipv4 bfd receive number
Treereceive

Description

This command specifies the receive interval for the BFD session.

On the 7750 SR, this command can only be configured to a value less than 100 when the type command is configured to cpm-np.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 16.0.R1

Platforms

All

transmit-interval number
Synopsis BFD transmit interval over this interface
Contextconfigure service vprn string interface string ipv4 bfd transmit-interval number
Treetransmit-interval

Description

This command configures the transmit intervals.

On the 7750 SR, this command can only be configured to a value less than 100 when the type command is configured to cpm-np.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 16.0.R1

Platforms

All

type keyword
Synopsis Local termination point for the BFD session
Contextconfigure service vprn string interface string ipv4 bfd type keyword
Treetype

Description

This command sets the local termination point for the BFD session to allow for fast timers down to 10 ms granularity.

The options to specify where the BFD session runs are:

  • auto (default) – the system chooses and uses the line card CPU only for single-hop BFD sessions with timer intervals equal to or greater than 100ms. All others are placed on the cpm-np.

  • cpm-np – BFD session runs on the FP complex associated with the CPM. This is either the FP on the CPM or the one elected on smaller systems. 

  • fp – BFD session runs on the line card CPU. This option can only be used for single-hop BFD sessions with timers equal to or greater than 100ms.  

Optionscpm-np, auto, fp
Defaultauto
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

dhcp
Synopsis Enter the dhcp context
Context configure service vprn string interface string ipv4 dhcp
Treedhcp
Introduced16.0.R1

Platforms

All

gi-address string
Synopsis GI address for the DHCP relay
Context configure service vprn string interface string ipv4 dhcp gi-address string
Treegi-address

Description

This command configures the GI address to distinguish between the different subscriber interfaces (and potentially group interfaces) defined when the router functions as a DHCP relay.

By default, the GI address used in the relayed DHCP packet is the primary IP address of a normal IES interface. Specifying the GI address allows the user to choose a secondary address. For group interfaces, a GI address must be specified under the group interface DHCP context or subscriber interface DHCP context for DHCP to function.

Introduced16.0.R1

Platforms

All

option-82
Synopsis Enter the option-82 context
Context configure service vprn string interface string ipv4 dhcp option-82
Treeoption-82

Description

Commands in this context configure the processing required when the router receives a DHCP request that already has an Option 82 field in the packet.

Introduced16.0.R1

Platforms

All

circuit-id
Synopsis Enter the circuit-id context
Context configure service vprn string interface string ipv4 dhcp option-82 circuit-id
Treecircuit-id
Introduced16.0.R1

Platforms

All

none
Synopsis Do not include the circuit ID
Context configure service vprn string interface string ipv4 dhcp option-82 circuit-id none
Treenone

Notes

The following elements are part of a choice: ascii-tuple, ifindex, none, sap-id, or vlan-ascii-tuple.

Introduced16.0.R1

Platforms

All

vlan-ascii-tuple
Synopsis Include the VLAN ID and dot1p bits in the ASCII tuple
Contextconfigure service vprn string interface string ipv4 dhcp option-82 circuit-id vlan-ascii-tuple
Treevlan-ascii-tuple

Description

When configured, the router includes the VLAN ID and dot1p bits with the ASCII-tuple information. This only occurs on dot1q and QinQ-encapsulated ports. When the Option 82 bits are stripped, dot1p bits are copied to the Ethernet header of the outgoing packet.

When unconfigured, the router leaves the circuit ID sub-option of the DHCP packet empty.

Notes

The following elements are part of a choice: ascii-tuple, ifindex, none, sap-id, or vlan-ascii-tuple.

Introduced16.0.R1

Platforms

All

remote-id
Synopsis Enter the remote-id context
Context configure service vprn string interface string ipv4 dhcp option-82 remote-id
Treeremote-id

Description

Commands in this context configure the remote IP sub-option of the DHCP packet with the identity of the remote host end (typically the DHCP client).

Introduced16.0.R1

Platforms

All

vendor-specific-option
Synopsis Enter the vendor-specific-option context
Contextconfigure service vprn string interface string ipv4 dhcp option-82 vendor-specific-option
Treevendor-specific-option

Description

Commands in this context configure the Nokia Vendor-Specific Option (VSO) of the DHCP packet.

Introduced16.0.R1

Platforms

All

proxy-server
Synopsis Enter the proxy-server context
Contextconfigure service vprn string interface string ipv4 dhcp proxy-server
Treeproxy-server
Introduced16.0.R1

Platforms

All

emulated-server string
Synopsis IP address used as the DHCP server address for the SAP
Contextconfigure service vprn string interface string ipv4 dhcp proxy-server emulated-server string
Treeemulated-server

Description

This command configures the IP address which will be used as the DHCP server address in the context of the SAP. Typically, the configured address should be in the context of the subnet represented by the service.

Introduced16.0.R1

Platforms

All

lease-time
Synopsis Enter the lease-time context
Context configure service vprn string interface string ipv4 dhcp proxy-server lease-time
Treelease-time
Introduced16.0.R1

Platforms

All

relay-proxy
Synopsis Enable the relay-proxy context
Contextconfigure service vprn string interface string ipv4 dhcp relay-proxy
Treerelay-proxy
Introduced16.0.R1

Platforms

All

server string
Synopsis IP addresses for DHCP server requests
Contextconfigure service vprn string interface string ipv4 dhcp server string
Treeserver

Description

This command configures a list of servers that this interface forwards requests to.

The operator can enter the list of servers as either IP addresses or fully qualified domain names. The operator must specify at least one server specified for DHCP relay to work. If there are multiple servers, the system forwards the request to all the servers in the list.

Max. Instances8

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

All

trusted boolean
Synopsis Relay untrusted packets
Context configure service vprn string interface string ipv4 dhcp trusted boolean
Treetrusted

Description

When configured to true, the router enables the trusted mode on the interface. When enabled, the relay agent changes the existing GI address (of the request) to the ingress interface, and forwards the request.

A DHCP request that contains a GI address of 0.0.0.0 and an Option 82 field in the packet is discarded unless it arrives on a trusted circuit.

This behavior only applies if the Relay Agent Information Option action is to keep the existing information. When the Option 82 field is replaced by the relay agent, the original Option 82 information is lost, and there is no reason to enable the trusted option.

Defaultfalse
Introduced16.0.R1

Platforms

All

use-arp boolean
Synopsis Use ARP to determine the destination hardware address
Contextconfigure service vprn string interface string ipv4 dhcp use-arp boolean
Treeuse-arp
Defaultfalse
Introduced16.0.R1

Platforms

All

icmp
Synopsis Enter the icmp context
Context configure service vprn string interface string ipv4 icmp
Treeicmp
Introduced16.0.R1

Platforms

All

param-problem
Synopsis Enter the param-problem context
Contextconfigure service vprn string interface string ipv4 icmp param-problem
Treeparam-problem

Description

Commands in this context specify the settings for ICMP Parameter Problem messages generated by the interface.

Introduced16.0.R1

Platforms

All

redirects
Synopsis Enter the redirects context
Context configure service vprn string interface string ipv4 icmp redirects
Treeredirects

Description

Commands in this context configure the settings for ICMP redirect messages generated by the interface.

The system sends ICMP redirect messages to alert the sending node that a more optimal route is available on another router on the same subnetwork.

Introduced16.0.R1

Platforms

All

ttl-expired
Synopsis Enter the ttl-expired context
Context configure service vprn string interface string ipv4 icmp ttl-expired
Treettl-expired

Description

Commands in this context configure the settings for ICMP TTL expired messages generated by the interface.

Introduced16.0.R1

Platforms

All

unreachables
Synopsis Enter the unreachables context
Contextconfigure service vprn string interface string ipv4 icmp unreachables
Treeunreachables

Description

Commands in this context specify the settings for ICMP host and network destination unreachable messages generated by the interface.

Introduced16.0.R1

Platforms

All

neighbor-discovery
Synopsis Enter the neighbor-discovery context
Contextconfigure service vprn string interface string ipv4 neighbor-discovery
Treeneighbor-discovery
Introduced16.0.R1

Platforms

All

host-route
Synopsis Enter the host-route context
Context configure service vprn string interface string ipv4 neighbor-discovery host-route
Treehost-route
Introduced19.10.R1

Platforms

All

populate [route-type] keyword
Synopsis Enter the populate list instance
Contextconfigure service vprn string interface string ipv4 neighbor-discovery host-route populate keyword
Treepopulate
Introduced19.10.R1

Platforms

All

route-tag number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTag value used with the host route from an ARP/ND entry
Contextconfigure service vprn string interface string ipv4 neighbor-discovery host-route populate keyword route-tag number
Treeroute-tag

Description

This command specifies the route tag that is added in the route table for ARP or ND host routes. This tag can be matched on BGP VRF export and BGP peer export policies.

Range1 to 255
Introduced19.10.R1

Platforms

All

learn-unsolicited boolean
Synopsis Learn new entries from any received NA message
Contextconfigure service vprn string interface string ipv4 neighbor-discovery learn-unsolicited boolean
Treelearn-unsolicited

Description

When configured to true, the router can learn neighbor entries from received unsolicited Neighbor Advertisement (NA) messages, with or without the solicited (S) flag set. The command can be enabled for global addresses, link-local addresses, or for both.

When configured to false, the router follows standard behavior for learning neighbor entries.

  • If an unsolicited NA (regardless of the S flag) is received from a neighbor that is not yet in the Neighbor Discovery (ND) cache, the NA is ignored.

  • If an NS, RS, RA, or Redirect message with a Link Layer Address (MAC) is received from a neighbor that is not yet in the ND cache, a new neighbor entry is created in the cache to store the received Link Layer MAC. The neighbor is put in the STALE state.

Defaultfalse
Introduced16.0.R1

Platforms

All

limit
Synopsis Enter the limit context
Context configure service vprn string interface string ipv4 neighbor-discovery limit
Treelimit
Introduced16.0.R1

Platforms

All

local-proxy-arp boolean
Synopsis Enable local proxy ARP on interface
Context configure service vprn string interface string ipv4 neighbor-discovery local-proxy-arp boolean
Treelocal-proxy-arp

Description

When configured to true, the router enables local proxy ARP on the interface.

When configured to false, the router does not respond to ARP requests for addresses on the same subnet.

Introduced16.0.R1

Platforms

All

proactive-refresh boolean
Synopsis Send a single refresh message before entry timeout
Contextconfigure service vprn string interface string ipv4 neighbor-discovery proactive-refresh boolean
Treeproactive-refresh

Description

When configured to true, the router always sends a refresh message 30 seconds before the timeout of the entry (a single refresh message with no retries).

When configured to false, the router marks an entry as stale 30 seconds before age-out, and the router only sends an ARP request to refresh the entry if the IOM receives traffic that uses it. Then, the IOM asks the ARP application to send a refresh message. With ARP proactive refresh enabled, the ARP module sends a refresh message regardless of the IOM receiving traffic.

Defaultfalse
Introduced16.0.R1

Platforms

All

static-neighbor [ipv4-address] string
Synopsis Enter the static-neighbor list instance
Contextconfigure service vprn string interface string ipv4 neighbor-discovery static-neighbor string
Treestatic-neighbor
Introduced16.0.R1

Platforms

All

static-neighbor-unnumbered
Synopsis Enable the static-neighbor-unnumbered context
Contextconfigure service vprn string interface string ipv4 neighbor-discovery static-neighbor-unnumbered
Treestatic-neighbor-unnumbered
Introduced16.0.R1

Platforms

All

timeout number
Synopsis Timeout for an ARP entry learned on the interface
Contextconfigure service vprn string interface string ipv4 neighbor-discovery timeout number
Treetimeout

Description

This command configures the minimum time an ARP entry learned on the IP interface is stored in the ARP table. ARP entries are automatically refreshed when an ARP request or gratuitous ARP is seen by an IP host. Otherwise, the ARP entry is aged from the ARP table.

Range0 to 65535
Unitsseconds
Default 14400
Introduced16.0.R1

Platforms

All

primary
Synopsis Enable the primary context
Context configure service vprn string interface string ipv4 primary
Treeprimary
Introduced16.0.R1

Platforms

All

address string
Synopsis Primary IPv4 address assigned to the interface
Contextconfigure service vprn string interface string ipv4 primary address string
Treeaddress

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

qos-route-lookup keyword
Synopsis IP address for QoS route lookup for ingress IP packets
Contextconfigure service vprn string interface string ipv4 qos-route-lookup keyword
Treeqos-route-lookup

Description

This command specifies the IP address type used for QPPB enabled per-packet QoS handling (in terms of FC and priority). When using QPPB, routes are associated with a QoS treatment (FC and optionally priority) through either explicit configuration or the route policy. If an IPv4 or IPv6 packet arrives on an interface where the configuration of this command applies to the packet, the QoS treatment of the packet is based on the route that matched the destination IP address or the route that matched the source IP address.

See "Enabling QPPB on an IP interface" in the 7450 ESS, 7750 SR, 7950 XRS, and VSR Router Configuration Guide for more information about QPPB.

Optionsdestination, source, source-and-dest
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

secondary [address] string
Synopsis Enter the secondary list instance
Contextconfigure service vprn string interface string ipv4 secondary string
Treesecondary
Introduced16.0.R1

Platforms

All

[address] string
Synopsis Secondary IPv4 address assigned to the interface
Contextconfigure service vprn string interface string ipv4 secondary string
Treesecondary

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

igp-inhibit boolean
Synopsis Disable the running IGP from recognizing secondary IP
Contextconfigure service vprn string interface string ipv4 secondary string igp-inhibit boolean
Treeigp-inhibit

Description

When configured to true, the running IGP does not recognize the secondary IP address as a local interface.

Defaultfalse
Introduced16.0.R1

Platforms

All

tcp-mss number
Synopsis TCP maximum segment size for the interface
Contextconfigure service vprn string interface string ipv4 tcp-mss number
Treetcp-mss
Range384 to 9746
Introduced16.0.R1

Platforms

All

unnumbered
Synopsis Enter the unnumbered context
Context configure service vprn string interface string ipv4 unnumbered
Treeunnumbered
Introduced16.0.R1

Platforms

All

ip-int-name string
Synopsis IP interface name
Context configure service vprn string interface string ipv4 unnumbered ip-int-name string
Treeip-int-name
String Length1 to 32

Notes

The following elements are part of a choice: ip-address or ip-int-name.

Introduced16.0.R1

Platforms

All

urpf-check
Synopsis Enable the urpf-check context
Context configure service vprn string interface string ipv4 urpf-check
Treeurpf-check
Introduced16.0.R1

Platforms

All

mode keyword
Synopsis Unicast RPF check mode
Context configure service vprn string interface string ipv4 urpf-check mode keyword
Treemode
Optionsstrict, loose, strict-no-ecmp
Defaultstrict
Introduced16.0.R1

Platforms

All

vrrp [virtual-router-id] number
Synopsis Enter the vrrp list instance
Context configure service vprn string interface string ipv4 vrrp number
Treevrrp
Introduced16.0.R1

Platforms

All

[virtual-router-id] number
Synopsis Virtual Router Identifier (VRID) for the IP interface
Contextconfigure service vprn string interface string ipv4 vrrp number
Treevrrp
Range1 to 255

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of VRRP
Context configure service vprn string interface string ipv4 vrrp number admin-state keyword
Treeadmin-state

Description

The command determines the administrative state of non-owner virtual router instances.

Non-owner virtual router instances can be administratively disabled. This allows the termination of VRRP participation in the virtual router and stops all routing and other access capabilities with regards to the virtual router IP addresses. Disabling the virtual router instance provides a mechanism to maintain the virtual routers without causing false backup or master state changes.

When disabled, no VRRP advertisement messages are generated and all received VRRP advertisement messages are silently discarded with no processing.

Whenever the administrative or operational state of a virtual router instance transitions, a log message is generated.

An owner virtual router context does not use this command. To administratively disable an owner virtual router instance, use the admin-state command within the parent IP interface node which administratively disables the IP interface.

Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

authentication-key string
Synopsis Password for simple text authentication
Contextconfigure service vprn string interface string ipv4 vrrp number authentication-key string
Treeauthentication-key

Description

This command optionally assigns a simple text password authentication key to generate master VRRP advertisement messages and validate received VRRP advertisement messages.

If this command is re-executed with a different password key defined, the new key immediately replaces the old key. This command may be executed at any time. 

String Length1 to 38
Introduced16.0.R1

Platforms

All

backup string
Synopsis Virtual router IP addresses for the interface
Contextconfigure service vprn string interface string ipv4 vrrp number backup string
Treebackup

Description

This command associates virtual router IP addresses with those of the parental IP interface.

This command has two different functions based on whether it is being executed on an owner or non-owner virtual router instance.

Non-owner virtual router instances create a routable IP interface address that is operationally dependent on the virtual router instance mode (master or backup). This command, when executed on an owner virtual router instance, does not create a routable IP interface address; it simply defines the existing IP addresses of the parental IP interface that are advertised by the virtual router instance.

For owner virtual router instances, this command defines the IP addresses that are advertised within VRRP advertisement messages. This communicates the IP addresses that the master is advertising to backup virtual routers receiving the messages. The specified unicast-ipv4-address must be equal to one of the existing IP addresses in the parental IP interface (primary or secondary) or this command fails.

See "Owner and non-owner VRRP" in the 7450 ESS, 7750 SR, 7950 XRS, and VSR Router Configuration Guide for more information about owner and non-owner virtual router instances.

Max. Instances16
Introduced16.0.R1

Platforms

All

bfd-liveness
Synopsis Enable the bfd-liveness context
Contextconfigure service vprn string interface string ipv4 vrrp number bfd-liveness
Treebfd-liveness
Introduced16.0.R1

Platforms

All

dest-ip string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDestination IP address to use for BFD session
Contextconfigure service vprn string interface string ipv4 vrrp number bfd-liveness dest-ip string
Treedest-ip

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

interface-name string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisName of the interface running BFD
Contextconfigure service vprn string interface string ipv4 vrrp number bfd-liveness interface-name string
Treeinterface-name
String Length1 to 32

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

service-name string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisAdministrative service name
Contextconfigure service vprn string interface string ipv4 vrrp number bfd-liveness service-name string
Treeservice-name
String Length1 to 64
Introduced16.0.R1

Platforms

All

mac string
Synopsis Virtual MAC address to use in ARP responses
Contextconfigure service vprn string interface string ipv4 vrrp number mac string
Treemac

Description

This command sets an explicit MAC address for the virtual router instance that overrides the VRRP default derived from the VRID.

Changing the default MAC address is useful when an existing HSRP or other non-VRRP default MAC is in use by the IP hosts that use the virtual router IP address. Many hosts do not monitor unessential ARPs and continue to use the cached non-VRRP MAC address after the virtual router becomes master of the host’s gateway address.

Additionally, this command sets the MAC address used in ARP responses when the virtual router instance is master. Routing of IP packets with unicast-mac-address as the destination MAC is also enabled. The MAC must be the same for all virtual routers participating as a virtual router or indeterminate connectivity by the attached IP hosts results. All VRRP advertisement messages are transmitted with unicast-mac-address as the source MAC.

An operator can execute this command at any time and it takes effect immediately. When the virtual router MAC on a master virtual router instance changes, a gratuitous ARP is immediately sent with a VRRP advertisement message. If the virtual router instance is disabled or operating as a backup, the gratuitous ARP and VRRP advertisement messages are not sent.

Introduced16.0.R1

Platforms

All

master-int-inherit boolean
Synopsis Allow master instance to dictate the master down timer
Contextconfigure service vprn string interface string ipv4 vrrp number master-int-inherit boolean
Treemaster-int-inherit

Description

When configured to true, the virtual router instance inherits the advertisement interval timer of the master VRRP router, which backup routers use to calculate the master down timer.

When configured to false, the locally configured message interval must match the master's VRRP advertisement message advertisement interval field value or the message is discarded.

Introduced16.0.R1

Platforms

All

message-interval number
Synopsis Interval for sending VRRP advertisement messages
Contextconfigure service vprn string interface string ipv4 vrrp number message-interval number
Treemessage-interval

Description

This command configures the administrative advertisement message timer used by the master virtual router instance to send VRRP advertisement messages. The backup master down timer is derived from the value configured using this command.

The usage of this command varies for non-owner virtual router instances, depending on the state of the virtual router (master or backup) and the state of the master-int-inherit command:

  • When a non-owner is operating as master for the virtual router, the system uses the configured value of this command as the operational advertisement timer, similar to an owner virtual router instance. The master-int-inherit command has no effect when operating as master.

  • When a non-owner is in the backup state with master-int-inherit disabled, the system uses the configured value of this command to match the incoming advertisement interval field of the VRRP advertisement message. If the locally configured message interval does not match the advertisement interval field, the system discards the VRRP advertisement.

  • When a non-owner is in the backup state with master-int-inherit enabled, the configured value of this command is ignored. The master down timer is indirectly derived from the advertisement interval field value of the incoming VRRP advertisement message.

Range1 to 2559
Unitsdeciseconds
Default 10
Introduced16.0.R1

Platforms

All

monitor-oper-group reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVRRP instance to follow a specified operational group
Contextconfigure service vprn string interface string ipv4 vrrp number monitor-oper-group reference
Treemonitor-oper-group

Description

This command configures VRRP to associate with an operational group. When associated, VRRP notifies the operational group of its state changes so that other protocols can monitor it to provide a redundancy mechanism. When VRRP is the master router, the operational group is up and the operational group is down for all other VRRP states.

Reference

configure service oper-group string

Introduced22.2.R1

Platforms

All

ntp-reply boolean
Synopsis Allow processing of NTP requests
Context configure service vprn string interface string ipv4 vrrp number ntp-reply boolean
Treentp-reply

Description

When configured to true, the router redirects NTP requests to the VRRP virtual IP address. This behavior only applies to the router acting as the master VRRP router.

When configured to false, the router does not process NTP requests.

Defaultfalse
Introduced20.2.R1

Platforms

All

oper-group reference
Synopsis Operational group name associated with the VRRP
Contextconfigure service vprn string interface string ipv4 vrrp number oper-group reference
Treeoper-group

Description

This command configures an operational group to associate with the VRRP. When associated, VRRP notifies the operational group of its state changes so that other protocols can monitor it to provide a redundancy mechanism. When VRRP is the master router (MR), the operational group is up. The operational group is down for all other VRRP states.

Reference

configure service oper-group string

Introduced16.0.R1

Platforms

All

owner boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDesignate the virtual router instance as owner
Contextconfigure service vprn string interface string ipv4 vrrp number owner boolean
Treeowner

Description

When configured to true, the router designates this virtual router instance as the owner of the virtual router IP addresses. Therefore, this virtual router becomes responsible for forwarding packets sent to the virtual router IP addresses. The owner also assumes the role of master virtual router.

When configured to false, this virtual router instance is designated as a non-owner.

Defaultfalse
Introduced16.0.R1

Platforms

All

passive boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSuppress the processing of VRRP advertisement messages
Contextconfigure service vprn string interface string ipv4 vrrp number passive boolean
Treepassive

Description

When configured to true, the router identifies this virtual router instance as passive; and therefore the owner of the virtual router IP addresses. A passive virtual router instance does not transmit or receive VRRP advertisement messages and is always in either the master state (if the interface is operationally up) or the init state (if the interface is operationally down).

When configured to false, this virtual router instance is not identified as passive, meaning that it transmits and receives VRRP advertisement messages. 

Defaultfalse
Introduced16.0.R1

Platforms

All

ping-reply boolean
Synopsis Allow non-owner master to reply to ICMP echo requests
Contextconfigure service vprn string interface string ipv4 vrrp number ping-reply boolean
Treeping-reply

Description

When configured to true, the router allows the non-owner master to reply to ICMP echo requests directed at the IP addresses of the virtual router instance. Any routed interface can receive the ping request. Ping must not have been disabled at the management security level (either on the parental IP interface or on the Ping source host address).

When configured to false, ICMP echo requests sent to non-owner master virtual IP addresses are silently discarded.

Non-owner backup virtual routers never respond to ICMP echo requests, regardless of the configuration of this command.

Defaultfalse
Introduced16.0.R1

Platforms

All

policy reference
Synopsis VRRP priority control policy
Context configure service vprn string interface string ipv4 vrrp number policy reference
Treepolicy

Description

This command configures a VRRP priority control policy to associate with the virtual router instance.

VRRP priority control policies can override or adjust the base priority value of the virtual router instance, depending on events or conditions within the chassis.

An operator can associate a policy with more than one virtual router instance. The priority events within the policy either override or diminish the base priority set with the priority command. As priority events clear in the policy, the in-use priority can eventually be restored to the base priority value.

For non-owner virtual router instances, if this command is not executed, the base priority is used as the in-use priority.

Reference

configure vrrp policy number

Introduced16.0.R1

Platforms

All

preempt boolean
Synopsis Allow the VRRP to override an existing non-owner master
Contextconfigure service vprn string interface string ipv4 vrrp number preempt boolean
Treepreempt

Description

When configured to true, this virtual router instance overrides any non-owner master with an in-use message priority value less than the in-use priority value of this virtual router.

When configured to false, this virtual router only becomes master if the master down timer expires before a VRRP advertisement message is received from another virtual router.

Defaulttrue
Introduced16.0.R1

Platforms

All

priority number
Synopsis Base priority for the VRRP
Context configure service vprn string interface string ipv4 vrrp number priority number
Treepriority

Description

This command configures the base router priority for the virtual router instance, which defines the selection order of the virtual router in the master election process.

The in-use priority is derived from the base priority. However, the in-use priority is modified by optional VRRP priority control policies. An operator can use VRRP priority control policies to either override or adjust the base priority value depending on events or conditions within the chassis.

Range1 to 255
Introduced16.0.R1

Platforms

All

ssh-reply boolean
Synopsis Allow the non-owner master to reply to SSH requests
Contextconfigure service vprn string interface string ipv4 vrrp number ssh-reply boolean
Treessh-reply

Description

When configured to true, the router allows the non-owner master to reply to SSH requests directed at the IP addresses of the virtual router instance. Any routed interface can receive the SSH request. SSH cannot be disabled at the management security level (either on the parental IP interface or on the SSH source host address).

When configure to false, SSH requests to non-owner master virtual IP addresses are silently discarded.

Defaultfalse
Introduced16.0.R1

Platforms

All

standby-forwarding boolean
Synopsis Allow standby router to forward traffic
Contextconfigure service vprn string interface string ipv4 vrrp number standby-forwarding boolean
Treestandby-forwarding

Description

When configured to true, the standby router forwards all traffic.

When configured to false, the standby router cannot forward traffic sent to the MAC address of the virtual router. However, the standby router still forwards traffic sent to its own MAC address.

Defaultfalse
Introduced16.0.R1

Platforms

All

telnet-reply boolean
Synopsis Allow non-owner master to reply to Telnet requests
Contextconfigure service vprn string interface string ipv4 vrrp number telnet-reply boolean
Treetelnet-reply

Description

When configured to true, the router allows the non-owner master to reply to Telnet requests directed at the IP addresses of the virtual router instance. Any routed interface can receive Telnet requests. Telnet cannot be disabled at the management security level (either on the parental IP interface or on the Telnet source host address).

When configured to false, the router silently discards Telnet requests sent to non-owner master virtual IP addresses.

Defaultfalse
Introduced16.0.R1

Platforms

All

traceroute-reply boolean
Synopsis Allow non-owner master to reply to traceroute requests
Contextconfigure service vprn string interface string ipv4 vrrp number traceroute-reply boolean
Treetraceroute-reply

Description

When configured to true, the router allows a non-owner master to reply to traceroute requests directed to the IP addresses of the virtual router instance.

When configured to false, the router silently discards traceroute requests sent to non-owner master virtual IP addresses.

Traceroute must not have been disabled at the management security level (either on the parental IP interface or the source host address).

Defaultfalse
Introduced16.0.R1

Platforms

All

ipv6
Synopsis Enable the ipv6 context
Context configure service vprn string interface string ipv6
Treeipv6
Introduced16.0.R1

Platforms

All

address [ipv6-address] string
Synopsis Enter the address list instance
Contextconfigure service vprn string interface string ipv6 address string
Treeaddress
Introduced16.0.R1

Platforms

All

[ipv6-address] string
Synopsis IPv6 address assigned to the interface
Contextconfigure service vprn string interface string ipv6 address string
Treeaddress

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

duplicate-address-detection boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEnable Duplicate Address Detection
Contextconfigure service vprn string interface string ipv6 address string duplicate-address-detection boolean
Treeduplicate-address-detection

Description

When configured to true, the router enables Duplicate Address Detection (DAD).

When configured to false, the router disables DAD and sets the address to preferred, even if there is a duplicated address.

Defaulttrue
Introduced16.0.R1

Platforms

All

eui-64 boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisForm IPv6 address from prefix and 64-bit interface ID
Contextconfigure service vprn string interface string ipv6 address string eui-64 boolean
Treeeui-64

Description

When configured to true, the router forms a complete IPv6 address from the supplied prefix and 64-bit interface identifier. The 64-bit interface identifier is derived from the MAC address on Ethernet interfaces. For interfaces without a MAC address, for example POS interfaces, use the base MAC address of the chassis.

Defaultfalse
Introduced16.0.R1

Platforms

All

primary-preference number
Synopsis Index assigned to the IPv6 address of the interface
Contextconfigure service vprn string interface string ipv6 address string primary-preference number
Treeprimary-preference

Description

This command assigns a primary preference index to an IPv6 address of the interface to enforce the order in which the address is used by control plane protocols and applications that require a fixed address of the interface, such as LDP and Segment Routing. In cases where a fixed address is required when originating packets from the interface, the IPv6 address with the lowest primary preference index is selected. If the selected address is removed, the next IPv6 address with the next lowest primary preference index is selected.

If this index is not specified for the IPv6 address, the system assigns the next available index value to the address. The address index space is unique across all addresses of a given interface.

Range1 to 4294967295
Introduced16.0.R1

Platforms

All

bfd
Synopsis Enter the bfd context
Context configure service vprn string interface string ipv6 bfd
Treebfd
Introduced16.0.R1

Platforms

All

multiplier number
Synopsis Number of consecutive BFD messages missed from the peer
Contextconfigure service vprn string interface string ipv6 bfd multiplier number
Treemultiplier

Description

This command configures the number of missed messages before the BFD session state is changed to down and the upper-level protocol is notified of the fault. A multiplier of less than 3 should not be used in production environments. 

Range1 to 20
Default3
Introduced 16.0.R1

Platforms

All

receive number
Synopsis BFD receive interval over this interface
Contextconfigure service vprn string interface string ipv6 bfd receive number
Treereceive

Description

This command specifies the receive interval for the BFD session.

On the 7750 SR, this command can only be configured to a value less than 100 when the type command is configured to cpm-np.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 16.0.R1

Platforms

All

transmit-interval number
Synopsis BFD transmit interval over this interface
Contextconfigure service vprn string interface string ipv6 bfd transmit-interval number
Treetransmit-interval

Description

This command configures the transmit intervals.

On the 7750 SR, this command can only be configured to a value less than 100 when the type command is configured to cpm-np.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 16.0.R1

Platforms

All

type keyword
Synopsis Local termination point for the BFD session
Contextconfigure service vprn string interface string ipv6 bfd type keyword
Treetype

Description

This command sets the local termination point for the BFD session to allow for fast timers down to 10 ms granularity.

The options to specify where the BFD session runs are:

  • auto (default) – the system chooses and uses the line card CPU only for single-hop BFD sessions with timer intervals equal to or greater than 100ms. All others are placed on the cpm-np.

  • cpm-np – BFD session runs on the FP complex associated with the CPM. This is either the FP on the CPM or the one elected on smaller systems. 

  • fp – BFD session runs on the line card CPU. This option can only be used for single-hop BFD sessions with timers equal to or greater than 100ms.  

Optionscpm-np, auto, fp
Defaultauto
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

dhcp6
Synopsis Enter the dhcp6 context
Context configure service vprn string interface string ipv6 dhcp6
Treedhcp6
Introduced16.0.R1

Platforms

All

relay
Synopsis Enter the relay context
Context configure service vprn string interface string ipv6 dhcp6 relay
Treerelay
Introduced16.0.R1

Platforms

All

lease-populate
Synopsis Enter the lease-populate context
Contextconfigure service vprn string interface string ipv6 dhcp6 relay lease-populate
Treelease-populate
Introduced16.0.R1

Platforms

All

route-populate
Synopsis Enter the route-populate context
Contextconfigure service vprn string interface string ipv6 dhcp6 relay lease-populate route-populate
Treeroute-populate
Introduced16.0.R1

Platforms

All

option
Synopsis Enter the option context
Context configure service vprn string interface string ipv6 dhcp6 relay option
Treeoption
Introduced16.0.R1

Platforms

All

interface-id
Synopsis Enter the interface-id context
Contextconfigure service vprn string interface string ipv6 dhcp6 relay option interface-id
Treeinterface-id
Introduced16.0.R1

Platforms

All

string string
Synopsis String for interface ID option in DHCPv6 relay packet
Contextconfigure service vprn string interface string ipv6 dhcp6 relay option interface-id string string
Treestring
String Length1 to 80

Notes

The following elements are part of a choice: ascii-tuple, if-index, sap-id, or string.

Introduced16.0.R1

Platforms

All

server string
Synopsis DHCPv6 server to which the DHCPv6 requests are forwarded
Contextconfigure service vprn string interface string ipv6 dhcp6 relay server string
Treeserver
Max. Instances8

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

All

server
Synopsis Enter the server context
Context configure service vprn string interface string ipv6 dhcp6 server
Treeserver
Introduced16.0.R1

Platforms

All

prefix-delegation
Synopsis Enter the prefix-delegation context
Contextconfigure service vprn string interface string ipv6 dhcp6 server prefix-delegation
Treeprefix-delegation

Description

Commands in this context configure the options for delegating a long-lived prefix from a delegating router to a requesting router, where the delegating router does not require knowledge about the link topology in the network to which the prefixes are assigned.

Introduced16.0.R1

Platforms

All

prefix [ipv6-prefix] string
Synopsis Enter the prefix list instance
Contextconfigure service vprn string interface string ipv6 dhcp6 server prefix-delegation prefix string
Treeprefix

Description

Commands in this context configure the IPv6 prefix that is delegated by the system.

Introduced16.0.R1

Platforms

All

client-id
Synopsis Enter the client-id context
Context configure service vprn string interface string ipv6 dhcp6 server prefix-delegation prefix string client-id
Treeclient-id
Introduced16.0.R1

Platforms

All

iaid number
Synopsis IAID from the requesting router to match
Contextconfigure service vprn string interface string ipv6 dhcp6 server prefix-delegation prefix string client-id iaid number
Treeiaid

Description

This command configures the Identity Association ID (IAID) associated with a prefix delegation entry and must match the IAID sent by the requesting router for the prefix delegation to succeed.

Range1 to 4294967295
Introduced16.0.R1

Platforms

All

preferred-lifetime (number | keyword)
Synopsis Preferred lifetime of the prefix
Context configure service vprn string interface string ipv6 dhcp6 server prefix-delegation prefix string preferred-lifetime (number | keyword)
Treepreferred-lifetime

Description

This command configures the preferred lifetime of the prefix. The value cannot be greater than the valid lifetime value.

Range1 to 4294967294
Unitsseconds
Options infinite
Default604800
Introduced 16.0.R1

Platforms

All

icmp6
Synopsis Enter the icmp6 context
Context configure service vprn string interface string ipv6 icmp6
Treeicmp6
Introduced16.0.R1

Platforms

All

packet-too-big
Synopsis Enter the packet-too-big context
Contextconfigure service vprn string interface string ipv6 icmp6 packet-too-big
Treepacket-too-big

Description

Commands in this context configure limiting the number of ICMPv6 Packet Too Big messages.

Introduced16.0.R1

Platforms

All

param-problem
Synopsis Enter the param-problem context
Contextconfigure service vprn string interface string ipv6 icmp6 param-problem
Treeparam-problem
Introduced16.0.R1

Platforms

All

redirects
Synopsis Enter the redirects context
Context configure service vprn string interface string ipv6 icmp6 redirects
Treeredirects
Introduced16.0.R1

Platforms

All

time-exceeded
Synopsis Enter the time-exceeded context
Contextconfigure service vprn string interface string ipv6 icmp6 time-exceeded
Treetime-exceeded
Introduced16.0.R1

Platforms

All

unreachables
Synopsis Enter the unreachables context
Contextconfigure service vprn string interface string ipv6 icmp6 unreachables
Treeunreachables
Introduced16.0.R1

Platforms

All

link-local-address
Synopsis Enter the link-local-address context
Contextconfigure service vprn string interface string ipv6 link-local-address
Treelink-local-address
Introduced16.0.R1

Platforms

All

duplicate-address-detection boolean
Synopsis Enable Duplicate Address Detection
Context configure service vprn string interface string ipv6 link-local-address duplicate-address-detection boolean
Treeduplicate-address-detection

Description

When configured to true, the router enables Duplicate Address Detection (DAD) on the interface.

When configured to false, the router disables DAD and sets the address to preferred, even if there is a duplicated address.

Defaulttrue
Introduced16.0.R1

Platforms

All

neighbor-discovery
Synopsis Enter the neighbor-discovery context
Contextconfigure service vprn string interface string ipv6 neighbor-discovery
Treeneighbor-discovery
Introduced16.0.R1

Platforms

All

host-route
Synopsis Enter the host-route context
Context configure service vprn string interface string ipv6 neighbor-discovery host-route
Treehost-route
Introduced20.2.R1

Platforms

All

populate [route-type] keyword
Synopsis Enter the populate list instance
Contextconfigure service vprn string interface string ipv6 neighbor-discovery host-route populate keyword
Treepopulate
Introduced20.2.R1

Platforms

All

route-tag number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTag value used with the host route from an ARP/ND entry
Contextconfigure service vprn string interface string ipv6 neighbor-discovery host-route populate keyword route-tag number
Treeroute-tag

Description

This command specifies the route tag that is added in the route table for ARP or ND host routes. This tag can be matched on BGP VRF export and BGP peer export policies.

Range1 to 255
Introduced20.2.R1

Platforms

All

learn-unsolicited keyword
Synopsis Type of entries learned from unsolicited NA messages
Contextconfigure service vprn string interface string ipv6 neighbor-discovery learn-unsolicited keyword
Treelearn-unsolicited

Description

This command enables the ability to learn neighbor entries out of received unsolicited Neighbor Advertisement (NA) messages, with or without the solicited flag set.

When unconfigured, the router follows standard RFC 4861 behavior for learning of neighbor entries. The neighbor is put in the stale state. This is the standard RFC behavior.

Optionsglobal, link-local, both
Introduced16.0.R1

Platforms

All

limit
Synopsis Enter the limit context
Context configure service vprn string interface string ipv6 neighbor-discovery limit
Treelimit
Introduced16.0.R1

Platforms

All

log-only boolean
Synopsis Generate log entries when limit is reached
Contextconfigure service vprn string interface string ipv6 neighbor-discovery limit log-only boolean
Treelog-only

Description

When configured to true, the router sends the warning message at the specified threshold percentage or upon exceeding the specified limit. Entries that exceed the limit are learned.

When configured to false, the router does not send the warning message.

Defaultfalse
Introduced16.0.R1

Platforms

All

max-entries number
Synopsis Maximum number of entries learned on an IP interface
Contextconfigure service vprn string interface string ipv6 neighbor-discovery limit max-entries number
Treemax-entries

Description

This command configures the maximum number of entries that can be learned on an IP interface.

When unconfigured, no maximum limit is imposed.

Range0 to 102400
Introduced16.0.R1

Platforms

All

local-proxy-nd boolean
Synopsis Enable local proxy neighbor discovery on the interface
Contextconfigure service vprn string interface string ipv6 neighbor-discovery local-proxy-nd boolean
Treelocal-proxy-nd

Description

When configured to true, the router enables local proxy neighbor discovery on the interface and replies to neighbor solicitation requests when both the hosts are on the same subnet. In this case, ICMP redirects are disabled.

When configured to false, the router disables local proxy neighbor discovery on the interface and does not reply to neighbor solicitation requests if both the hosts are on the same subnet.

Defaultfalse
Introduced16.0.R1

Platforms

All

proactive-refresh keyword
Synopsis Proactive refresh of neighbor entries
Contextconfigure service vprn string interface string ipv6 neighbor-discovery proactive-refresh keyword
Treeproactive-refresh

Description

This command enables a proactive refresh of the neighbor entries. After the stale timer expires, the router sends an NUD message to the host (regardless of the existence of traffic to the IP address on the IOM), so the entry can be refreshed or removed.

Optionsglobal, link-local, both
Introduced16.0.R1

Platforms

All

secure-nd
Synopsis Enter the secure-nd context
Context configure service vprn string interface string ipv6 neighbor-discovery secure-nd
Treesecure-nd
Introduced16.0.R1

Platforms

All

allow-unsecured-msgs boolean
Synopsis Accept unsecured messages
Context configure service vprn string interface string ipv6 neighbor-discovery secure-nd allow-unsecured-msgs boolean
Treeallow-unsecured-msgs

Description

When configured to true, the router accepts unsecured messages. When Secure Neighbor Discovery (SeND) is enabled, only secure messages are accepted.

When configured to false, the router disables the acceptance of unsecured messages.

Defaulttrue
Introduced16.0.R1

Platforms

All

static-neighbor [ipv6-address] string
Synopsis Enter the static-neighbor list instance
Contextconfigure service vprn string interface string ipv6 neighbor-discovery static-neighbor string
Treestatic-neighbor
Introduced16.0.R1

Platforms

All

qos-route-lookup keyword
Synopsis IP address for QoS route lookup for ingress IP packets
Contextconfigure service vprn string interface string ipv6 qos-route-lookup keyword
Treeqos-route-lookup

Description

This command specifies the IP address type used for QPPB enabled per-packet QoS handling (in terms of FC and priority). When using QPPB, routes are associated with a QoS treatment (FC and optionally priority) through either explicit configuration or the route policy. If an IPv4 or IPv6 packet arrives on an interface where the configuration of this command applies to the packet, the QoS treatment of the packet is based on the route that matched the destination IP address or the route that matched the source IP address.

See "Enabling QPPB on an IP interface" in the 7450 ESS, 7750 SR, 7950 XRS, and VSR Router Configuration Guide for more information about QPPB.

Optionsdestination, source, source-and-dest
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

tcp-mss number
Synopsis TCP maximum segment size for the interface
Contextconfigure service vprn string interface string ipv6 tcp-mss number
Treetcp-mss
Range1220 to 9726
Introduced16.0.R1

Platforms

All

urpf-check
Synopsis Enable the urpf-check context
Context configure service vprn string interface string ipv6 urpf-check
Treeurpf-check
Introduced16.0.R1

Platforms

All

mode keyword
Synopsis Unicast RPF check mode
Context configure service vprn string interface string ipv6 urpf-check mode keyword
Treemode
Optionsstrict, loose, strict-no-ecmp
Defaultstrict
Introduced16.0.R1

Platforms

All

vrrp [virtual-router-id] number
Synopsis Enter the vrrp list instance
Context configure service vprn string interface string ipv6 vrrp number
Treevrrp
Max. Instances4
Introduced16.0.R1

Platforms

All

[virtual-router-id] number
Synopsis Virtual Router Identifier (VRID) for the IP interface
Contextconfigure service vprn string interface string ipv6 vrrp number
Treevrrp
Range1 to 255

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of VRRP
Context configure service vprn string interface string ipv6 vrrp number admin-state keyword
Treeadmin-state

Description

The command determines the administrative state of non-owner virtual router instances.

Non-owner virtual router instances can be administratively disabled. This allows the termination of VRRP participation in the virtual router and stops all routing and other access capabilities with regards to the virtual router IP addresses. Disabling the virtual router instance provides a mechanism to maintain the virtual routers without causing false backup or master state changes.

When disabled, no VRRP advertisement messages are generated and all received VRRP advertisement messages are silently discarded with no processing.

Whenever the administrative or operational state of a virtual router instance transitions, a log message is generated.

An owner virtual router context does not use this command. To administratively disable an owner virtual router instance, use the admin-state command within the parent IP interface node which administratively disables the IP interface.

Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

backup string
Synopsis Virtual router IP addresses for the interface
Contextconfigure service vprn string interface string ipv6 vrrp number backup string
Treebackup

Description

This command associates router IPv6 virtual router IP addresses with those of the parental IP interface.

This command has two different functions based on whether it is being executed on an owner or non-owner virtual router instance.

Non-owner virtual router instance create a routable IP interface address that is operationally dependent on the virtual router instance mode (master or backup). This command, when executed on an owner virtual router instance, does not create a routable IP interface address; it simply defines the existing IP addresses of the parental IP interface that are advertised by the virtual router instance.

For owner virtual router instances, this command defines the IP addresses that are advertised within VRRP advertisement messages. This communicates the IP addresses that the master is representing to backup virtual routers receiving the messages. The specified IPv6 address must be equal to one of the existing parental IP addresses in the parental IP interface (primary or secondary) or this command fails.

See "Owner and non-owner VRRP" in the 7450 ESS, 7750 SR, 7950 XRS, and VSR Router Configuration Guide for more information about owner and non-owner virtual router instances.

Max. Instances4
Introduced16.0.R1

Platforms

All

bfd-liveness
Synopsis Enable the bfd-liveness context
Contextconfigure service vprn string interface string ipv6 vrrp number bfd-liveness
Treebfd-liveness
Introduced16.0.R1

Platforms

All

dest-ip (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDestination address for the BFD session
Contextconfigure service vprn string interface string ipv6 vrrp number bfd-liveness dest-ip (ipv4-address-no-zone | ipv6-address-no-zone)
Treedest-ip

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

interface-name string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisName of the interface running BFD
Contextconfigure service vprn string interface string ipv6 vrrp number bfd-liveness interface-name string
Treeinterface-name
String Length1 to 32

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

service-name string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisAdministrative service name
Contextconfigure service vprn string interface string ipv6 vrrp number bfd-liveness service-name string
Treeservice-name
String Length1 to 64
Introduced16.0.R1

Platforms

All

mac string
Synopsis Virtual MAC address to use in ARP responses
Contextconfigure service vprn string interface string ipv6 vrrp number mac string
Treemac

Description

This command sets an explicit MAC address for the virtual router instance that overrides the VRRP default derived from the VRID.

Changing the default MAC address is useful when an existing HSRP or other non-VRRP default MAC is in use by the IP hosts that use the virtual router IP address. Many hosts do not monitor unessential ARPs and continue to use the cached non-VRRP MAC address after the virtual router becomes master of the host’s gateway address.

Additionally, this command sets the MAC address used in ARP responses when the virtual router instance is master. Routing of IP packets with unicast-mac-address as the destination MAC is also enabled. The MAC must be the same for all virtual routers participating as a virtual router or indeterminate connectivity by the attached IP hosts results. All VRRP advertisement messages are transmitted with unicast-mac-address as the source MAC.

An operator can execute this command at any time and it takes effect immediately. When the virtual router MAC on a master virtual router instance changes, a gratuitous ARP is immediately sent with a VRRP advertisement message. If the virtual router instance is disabled or operating as a backup, the gratuitous ARP and VRRP advertisement messages are not sent.

Introduced16.0.R1

Platforms

All

master-int-inherit boolean
Synopsis Allow master instance to dictate the master down timer
Contextconfigure service vprn string interface string ipv6 vrrp number master-int-inherit boolean
Treemaster-int-inherit

Description

When configured to true, the virtual router instance inherits the advertisement interval timer of the master VRRP router, which backup routers use to calculate the master down timer.

When configured to false, the locally configured message interval must match the master's VRRP advertisement message advertisement interval field value or the message is discarded.

Introduced16.0.R1

Platforms

All

message-interval number
Synopsis Interval for sending VRRP advertisement messages
Contextconfigure service vprn string interface string ipv6 vrrp number message-interval number
Treemessage-interval

Description

This command configures the administrative advertisement message timer used by the master virtual router instance to send VRRP advertisement messages. The backup master down timer is derived from the value configured using this command.

The use of this command varies for non-owner virtual router instances, depending on the state of the virtual router (master or backup) and the state of the master-int-inherit command:

  • When a non-owner is operating as master for the virtual router, the system uses the configured value of this command as the operational advertisement timer, similar to an owner virtual router instance. The master-int-inherit command has no effect when operating as the master.

  • When a non-owner is in the backup state with master-int-inherit disabled, the system uses the configured value of this command to match the incoming advertisement interval field of the VRRP advertisement message. If the locally configured message interval does not match the advertisement interval field, the system discards the VRRP advertisement.

  • When a non-owner is in the backup state with master-int-inherit enabled, the configured value of this command is ignored. The master down timer is indirectly derived from the advertisement interval field value of the incoming VRRP advertisement message.

Range10 to 4095
Unitscentiseconds
Default 100
Introduced16.0.R1

Platforms

All

monitor-oper-group reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVRRP instance to follow a specified operational group
Contextconfigure service vprn string interface string ipv6 vrrp number monitor-oper-group reference
Treemonitor-oper-group

Description

This command configures VRRP to associate with an operational group. When associated, VRRP notifies the operational group of its state changes so that other protocols can monitor it to provide a redundancy mechanism. When VRRP is the master router, the operational group is up and the operational group is down for all other VRRP states.

Reference

configure service oper-group string

Introduced22.2.R1

Platforms

All

ntp-reply boolean
Synopsis Allow processing of NTP requests
Context configure service vprn string interface string ipv6 vrrp number ntp-reply boolean
Treentp-reply

Description

When configured to true, the router redirects NTP requests to the VRRP virtual IP address. This behavior only applies to the router acting as the master VRRP router.

When configured to false, the router does not process NTP requests.

Defaultfalse
Introduced20.2.R1

Platforms

All

oper-group reference
Synopsis Operational group name associated with the VRRP
Contextconfigure service vprn string interface string ipv6 vrrp number oper-group reference
Treeoper-group

Description

This command configures an operational group to associate with the VRRP. When associated, VRRP notifies the operational group of its state changes so that other protocols can monitor it to provide a redundancy mechanism. When VRRP is the master router (MR), the operational group is up. The operational group is down for all other VRRP states.

Reference

configure service oper-group string

Introduced16.0.R1

Platforms

All

owner boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDesignate the virtual router instance as owner
Contextconfigure service vprn string interface string ipv6 vrrp number owner boolean
Treeowner

Description

When configured to true, the router designates this virtual router instance as the owner of the virtual router IP addresses. Therefore, this virtual router becomes responsible for forwarding packets sent to the virtual router IP addresses. The owner also assumes the role of master virtual router.

When configured to false, this virtual router instance is designated as a non-owner.

Defaultfalse
Introduced16.0.R1

Platforms

All

passive boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSuppress the processing of VRRP advertisement messages
Contextconfigure service vprn string interface string ipv6 vrrp number passive boolean
Treepassive

Description

When configured to true, the router identifies this virtual router instance as passive; and therefore the owner of the virtual router IP addresses. A passive virtual router instance does not transmit or receive VRRP advertisement messages and is always in either the master state (if the interface is operationally up) or the init state (if the interface is operationally down).

When configured to false, this virtual router instance is not identified as passive, meaning that it transmits and receives VRRP advertisement messages. 

Defaultfalse
Introduced16.0.R1

Platforms

All

ping-reply boolean
Synopsis Allow non-owner master to reply to ICMP echo requests
Contextconfigure service vprn string interface string ipv6 vrrp number ping-reply boolean
Treeping-reply

Description

When configured to true, the router allows the non-owner master to reply to ICMP echo requests directed at the IP addresses of the virtual router instance. Any routed interface can receive the ping request. Ping must not have been disabled at the management security level (either on the parental IP interface or on the Ping source host address).

When configured to false, ICMP echo requests sent to non-owner master virtual IP addresses are silently discarded.

Non-owner backup virtual routers never respond to ICMP echo requests, regardless of the configuration of this command.

Defaultfalse
Introduced16.0.R1

Platforms

All

policy reference
Synopsis VRRP priority control policy
Context configure service vprn string interface string ipv6 vrrp number policy reference
Treepolicy

Description

This command configures a VRRP priority control policy to associate with the virtual router instance.

VRRP priority control policies can override or adjust the base priority value of the virtual router instance, depending on events or conditions within the chassis.

An operator can associate a policy with more than one virtual router instance. The priority events within the policy either override or diminish the base priority set with the priority command. As priority events clear in the policy, the in-use priority can eventually be restored to the base priority value.

For non-owner virtual router instances, if this command is not executed, the base priority is used as the in-use priority.

Reference

configure vrrp policy number

Introduced16.0.R1

Platforms

All

preempt boolean
Synopsis Allow the VRRP to override an existing non-owner master
Contextconfigure service vprn string interface string ipv6 vrrp number preempt boolean
Treepreempt

Description

When configured to true, this virtual router instance overrides any non-owner master with an in-use message priority value less than the in-use priority value of this virtual router.

When configured to false, this virtual router only becomes master if the master down timer expires before a VRRP advertisement message is received from another virtual router.

Defaulttrue
Introduced16.0.R1

Platforms

All

priority number
Synopsis Base priority for the VRRP
Context configure service vprn string interface string ipv6 vrrp number priority number
Treepriority

Description

This command configures the base router priority for the virtual router instance, which defines the selection order of the virtual router in the master election process.

The in-use priority is derived from the base priority. However, the in-use priority is modified by optional VRRP priority control policies. An operator can use VRRP priority control policies to either override or adjust the base priority value depending on events or conditions within the chassis.

Range1 to 255
Introduced16.0.R1

Platforms

All

standby-forwarding boolean
Synopsis Allow standby router to forward traffic
Contextconfigure service vprn string interface string ipv6 vrrp number standby-forwarding boolean
Treestandby-forwarding

Description

When configured to true, the standby router forwards all traffic.

When configured to false, the standby router cannot forward traffic sent to the MAC address of the virtual router. However, the standby router still forwards traffic sent to its own MAC address.

Defaultfalse
Introduced16.0.R1

Platforms

All

telnet-reply boolean
Synopsis Allow non-owner master to reply to Telnet requests
Contextconfigure service vprn string interface string ipv6 vrrp number telnet-reply boolean
Treetelnet-reply

Description

When configured to true, the router allows the non-owner master to reply to Telnet requests directed at the IP addresses of the virtual router instance. Any routed interface can receive Telnet requests. Telnet cannot be disabled at the management security level (either on the parental IP interface or on the Telnet source host address).

When configured to false, the router silently discards Telnet requests sent to non-owner master virtual IP addresses.

Defaultfalse
Introduced16.0.R1

Platforms

All

traceroute-reply boolean
Synopsis Allow non-owner master to reply to traceroute requests
Contextconfigure service vprn string interface string ipv6 vrrp number traceroute-reply boolean
Treetraceroute-reply

Description

When configured to true, the router allows a non-owner master to reply to traceroute requests directed to the IP addresses of the virtual router instance.

When configured to false, the router silently discards traceroute requests sent to non-owner master virtual IP addresses.

Traceroute must not have been disabled at the management security level (either on the parental IP interface or the source host address).

Defaultfalse
Introduced16.0.R1

Platforms

All

load-balancing
Synopsis Enter the load-balancing context
Contextconfigure service vprn string interface string load-balancing
Treeload-balancing
Introduced16.0.R1

Platforms

All

flow-label-load-balancing boolean
Synopsis Enable flow label load balancing
Context configure service vprn string interface string load-balancing flow-label-load-balancing boolean
Treeflow-label-load-balancing

Description

When configured to true, the router enables load balancing in ECMP and LAG based on the output of a hash performed on the triplet (SA, DA, flow label) in the header of an IPv6 packet received on an IES, VPRN, R-VPLS, CSC, or network interface.

When configured to false, the router disables load balancing in ECMP and LAG.

Defaultfalse
Introduced21.5.R1

Platforms

All

ip-load-balancing keyword
Synopsis IP load-balancing algorithm
Context configure service vprn string interface string load-balancing ip-load-balancing keyword
Treeip-load-balancing

Description

This command specifies whether to include the source address, destination address, or both in LAG or ECMP hash on IP interfaces. Additionally, when the l4-load-balancing command is enabled, this command also includes the source or destination port in the hash inputs.

Optionsboth, destination, source, inner-ip
Default both
Introduced16.0.R3

Platforms

All

spi-load-balancing boolean
Synopsis Enable SPI use in hashing
Context configure service vprn string interface string load-balancing spi-load-balancing boolean
Treespi-load-balancing

Description

When configured to true, the router uses the Security Parameter Index (SPI) in hashing for ESP and AH encrypted IPv4 and IPv6 traffic. This is a per-interface setting.

Defaultfalse
Introduced16.0.R1

Platforms

All

loopback boolean
Synopsis Use interface as a loopback interface
Contextconfigure service vprn string interface string loopback boolean
Treeloopback
Defaultfalse
Introduced16.0.R1

Platforms

All

mac string
Synopsis MAC address for the interface
Context configure service vprn string interface string mac string
Treemac
Introduced16.0.R1

Platforms

All

multi-chassis-shunting-profile reference
Synopsis Multi-chassis shunting profile name
Context configure service vprn string interface string multi-chassis-shunting-profile reference
Treemulti-chassis-shunting-profile

Description

This command configures the name of a multi-chassis shunting profile to use on public or private tunnel interfaces.

Reference

configure service vprn string ipsec multi-chassis-shunting-profile string

Notes

The following elements are part of a choice: multi-chassis-shunting-profile or (dynamic-tunnel-redundant-nexthop and static-tunnel-redundant-nexthop).

Introduced22.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ping-template
Synopsis Enable the ping-template context
Contextconfigure service vprn string interface string ping-template
Treeping-template
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

admin-state keyword
Synopsis Administrative state of the ping template
Contextconfigure service vprn string interface string ping-template admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

destination-address string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPing template destination address
Contextconfigure service vprn string interface string ping-template destination-address string
Treedestination-address

Description

This command configures the address to where the ICMP echo requests are directed to test connectivity. The source of the ICMP echo request is the primary IPv4 address of the interface under which the ping-template is configured. The destination address must be on the same subnet as the source IP address.

Unnumbered interfaces and loopback addresses are not supported.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

name reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPing template name
Contextconfigure service vprn string interface string ping-template name reference
Treename

Description

This command configures the name of the ping template to be assigned to the IP interface.

Reference

configure test-oam icmp ping-template string

Notes

This element is mandatory.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ptp-hw-assist
Synopsis Enter the ptp-hw-assist context
Contextconfigure service vprn string interface string ptp-hw-assist
Treeptp-hw-assist

Description

Commands in this context enable the port-based timestamping assist of PTP packets at the physical interface. This capability is supported on specific hardware. The command may be blocked if not all hardware has the required level of support.

Only one interface per physical port can have port-based timestamping assist enabled. This feature cannot be enabled if the physical port supporting the interface is configured as a PTP port.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

admin-state keyword
Synopsis Administrative state of the PTP timestamping assist
Contextconfigure service vprn string interface string ptp-hw-assist admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

sap [sap-id] string
Synopsis Enter the sap list instance
Context configure service vprn string interface string sap string
Treesap
Max. Instances1
Introduced16.0.R1

Platforms

All

[sap-id] string
Synopsis SAP ID
Contextconfigure service vprn string interface string sap string
Treesap
String Length1 to 45

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

aarp
Synopsis Enable the aarp context
Context configure service vprn string interface string sap string aarp
Treeaarp
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

type keyword
Synopsis Role referenced by the AARP
Context configure service vprn string interface string sap string aarp type keyword
Treetype
Optionsdual-homed, dual-homed-secondary
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the SAP
Context configure service vprn string interface string sap string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

anti-spoof keyword
Synopsis Anti-spoof filtering
Context configure service vprn string interface string sap string anti-spoof keyword
Treeanti-spoof
Optionssource-ip-addr, source-mac-addr, source-ip-and-mac-addr, next-hop-ip-and-mac-addr
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

cpu-protection
Synopsis Enter the cpu-protection context
Contextconfigure service vprn string interface string sap string cpu-protection
Treecpu-protection
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

eth-cfm-monitoring
Synopsis Enable the eth-cfm-monitoring context
Contextconfigure service vprn string interface string sap string cpu-protection eth-cfm-monitoring
Treeeth-cfm-monitoring

Notes

The following elements are part of a choice: eth-cfm-monitoring, ip-src-monitoring, or mac-monitoring.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

ip-src-monitoring
Synopsis Enable IP source monitoring for CPU protection
Contextconfigure service vprn string interface string sap string cpu-protection ip-src-monitoring
Treeip-src-monitoring

Notes

The following elements are part of a choice: eth-cfm-monitoring, ip-src-monitoring, or mac-monitoring.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

mac-monitoring
Synopsis Monitor MAC for CPU protection
Context configure service vprn string interface string sap string cpu-protection mac-monitoring
Treemac-monitoring

Notes

The following elements are part of a choice: eth-cfm-monitoring, ip-src-monitoring, or mac-monitoring.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

egress
Synopsis Enter the egress context
Context configure service vprn string interface string sap string egress
Treeegress
Introduced16.0.R1

Platforms

All

agg-rate
Synopsis Enter the agg-rate context
Context configure service vprn string interface string sap string egress agg-rate
Treeagg-rate

Notes

The following elements are part of a choice: agg-rate or percent-agg-rate.

Introduced16.0.R1

Platforms

All

burst-limit (number | keyword)
Synopsis Shaping burst size when an aggregate shaper is used
Contextconfigure service vprn string interface string sap string egress agg-rate burst-limit (number | keyword)
Treeburst-limit
Range1 to 14000000
Unitsbytes
Options auto
Default auto
Introduced22.10.R1

Platforms

7750 SR-1, 7750 SR-s

rate number
Synopsis Enforced aggregate rate for all queues
Contextconfigure service vprn string interface string sap string egress agg-rate rate number
Treerate
Range1 to 6400000000
Unitskilobps
Introduced 16.0.R1

Platforms

All

filter
Synopsis Enter the filter context
Context configure service vprn string interface string sap string egress filter
Treefilter
Introduced16.0.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service vprn string interface string sap string egress qos
Treeqos
Introduced16.0.R1

Platforms

All

policer-control-policy
Synopsis Enter the policer-control-policy context
Contextconfigure service vprn string interface string sap string egress qos policer-control-policy
Treepolicer-control-policy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

overrides
Synopsis Enable the overrides context
Context configure service vprn string interface string sap string egress qos policer-control-policy overrides
Treeoverrides
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

root
Synopsis Enter the root context
Context configure service vprn string interface string sap string egress qos policer-control-policy overrides root
Treeroot
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

priority-mbs-thresholds
Synopsis Enter the priority-mbs-thresholds context
Contextconfigure service vprn string interface string sap string egress qos policer-control-policy overrides root priority-mbs-thresholds
Treepriority-mbs-thresholds
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

priority [priority-level] number
Synopsis Enter the priority list instance
Contextconfigure service vprn string interface string sap string egress qos policer-control-policy overrides root priority-mbs-thresholds priority number
Treepriority
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

sap-egress
Synopsis Enter the sap-egress context
Context configure service vprn string interface string sap string egress qos sap-egress
Treesap-egress
Introduced16.0.R1

Platforms

All

overrides
Synopsis Enter the overrides context
Context configure service vprn string interface string sap string egress qos sap-egress overrides
Treeoverrides
Introduced16.0.R1

Platforms

All

hs-wrr-group [group-id] reference
Synopsis Enter the hs-wrr-group list instance
Contextconfigure service vprn string interface string sap string egress qos sap-egress overrides hs-wrr-group reference
Treehs-wrr-group
Introduced16.0.R1

Platforms

7750 SR-7/12/12e

rate (number | keyword)
Synopsis Scheduling rate override applied to the HS WRR group
Contextconfigure service vprn string interface string sap string egress qos sap-egress overrides hs-wrr-group reference rate (number | keyword)
Treerate
Range1 to 2000000000
Unitskilobps
Options max

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

7750 SR-7/12/12e

policer [policer-id] reference
Synopsis Enter the policer list instance
Contextconfigure service vprn string interface string sap string egress qos sap-egress overrides policer reference
Treepolicer
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service vprn string interface string sap string egress qos sap-egress overrides policer reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

rate
Synopsis Enter the rate context
Context configure service vprn string interface string sap string egress qos sap-egress overrides policer reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

stat-mode keyword
Synopsis Mode of statistics collected by the policer
Contextconfigure service vprn string interface string sap string egress qos sap-egress overrides policer reference stat-mode keyword
Treestat-mode
Optionsno-stats, minimal, offered-profile-no-cir, offered-total-cir, offered-profile-cir, offered-limited-capped-cir, offered-profile-capped-cir, offered-total-cir-exceed, offered-four-profile-no-cir, offered-total-cir-four-profile
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

queue [queue-id] reference
Synopsis Enter the queue list instance
Context configure service vprn string interface string sap string egress qos sap-egress overrides queue reference
Treequeue
Introduced16.0.R1

Platforms

All

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure service vprn string interface string sap string egress qos sap-egress overrides queue reference adaptation-rule
Treeadaptation-rule
Introduced16.0.R1

Platforms

All

drop-tail
Synopsis Enter the drop-tail context
Context configure service vprn string interface string sap string egress qos sap-egress overrides queue reference drop-tail
Treedrop-tail
Introduced16.0.R1

Platforms

All

low
Synopsis Enter the low context
Context configure service vprn string interface string sap string egress qos sap-egress overrides queue reference drop-tail low
Treelow
Introduced16.0.R1

Platforms

All

hs-wred-queue
Synopsis Enter the hs-wred-queue context
Contextconfigure service vprn string interface string sap string egress qos sap-egress overrides queue reference hs-wred-queue
Treehs-wred-queue
Introduced16.0.R1

Platforms

7750 SR-7/12/12e

monitor-queue-depth
Synopsis Enable the monitor-queue-depth context
Contextconfigure service vprn string interface string sap string egress qos sap-egress overrides queue reference monitor-queue-depth
Treemonitor-queue-depth
Introduced20.10.R1

Platforms

All

parent
Synopsis Enter the parent context
Context configure service vprn string interface string sap string egress qos sap-egress overrides queue reference parent
Treeparent
Introduced16.0.R1

Platforms

All

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service vprn string interface string sap string egress qos sap-egress overrides queue reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

All

rate
Synopsis Enter the rate context
Context configure service vprn string interface string sap string egress qos sap-egress overrides queue reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

All

port-redirect-group
Synopsis Enter the port-redirect-group context
Contextconfigure service vprn string interface string sap string egress qos sap-egress port-redirect-group
Treeport-redirect-group
Introduced16.0.R1

Platforms

All

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service vprn string interface string sap string egress qos scheduler-policy
Treescheduler-policy
Introduced16.0.R1

Platforms

All

overrides
Synopsis Enter the overrides context
Context configure service vprn string interface string sap string egress qos scheduler-policy overrides
Treeoverrides
Introduced16.0.R1

Platforms

All

scheduler [scheduler-name] string
Synopsis Enter the scheduler list instance
Contextconfigure service vprn string interface string sap string egress qos scheduler-policy overrides scheduler string
Treescheduler
Introduced16.0.R1

Platforms

All

[scheduler-name] string
Synopsis Scheduler name
Contextconfigure service vprn string interface string sap string egress qos scheduler-policy overrides scheduler string
Treescheduler

Description

This command specifies the scheduler name which is composed of printable 7-bit ASCII characters. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes. Each scheduler must have a unique name within the context of the scheduler policy. However, the same name can be reused in multiple scheduler policies. If the scheduler name already exists within the policy tier level, the context changes to that scheduler name for the purpose of editing the scheduler commands.

If the scheduler name exists within the policy on a different tier, an error occurs and the current context does not change. If the scheduler name does not exist in this or another tier within the scheduler policy, it is assumed that an attempt is being made to create a scheduler of that name.

If the provided scheduler name is invalid, a name syntax error occurs, the command does not execute, and the context is not change.

String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

parent
Synopsis Enter the parent context
Context configure service vprn string interface string sap string egress qos scheduler-policy overrides scheduler string parent
Treeparent
Introduced16.0.R1

Platforms

All

rate
Synopsis Enter the rate context
Context configure service vprn string interface string sap string egress qos scheduler-policy overrides scheduler string rate
Treerate
Introduced16.0.R1

Platforms

All

virtual-port
Synopsis Enter the virtual-port context
Contextconfigure service vprn string interface string sap string egress virtual-port
Treevirtual-port
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

eth-cfm
Synopsis Enter the eth-cfm context
Context configure service vprn string interface string sap string eth-cfm
Treeeth-cfm
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

collect-lmm-fc-stats
Synopsis Enter the collect-lmm-fc-stats context
Contextconfigure service vprn string interface string sap string eth-cfm collect-lmm-fc-stats
Treecollect-lmm-fc-stats

Description

Commands in this context configure per forwarding class (FC) LMM information collection.

The commands fc-in-profile and fc in this context are mutually exclusive. The commands apply to either profile-aware or profile-unaware FCs respectively. 

This command and the collect-lmm-stats command are mutually exclusive when there is entity resource contention.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fc keyword
Synopsis Forwarding class name for profile-unaware counter
Contextconfigure service vprn string interface string sap string eth-cfm collect-lmm-fc-stats fc keyword
Treefc

Description

This command configures individual counters for the specified FCs without regard for profile. The system includes all countable packets that match a configured FC, regardless of profile, in this counter.

An FC specified as part of this command and for this specific context cannot be specified as a profile-aware FC using the fc-in-profile command under the collect-lmm-fc-stats context. 

When this command is reentered, a differential is performed. Omitted FCs stop counting, newly added FCs start counting, and unchanged FCs continue to count.

Optionsbe, l2, af, l1, h2, ef, h1, nc
Max. Instances 8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fc-in-profile keyword
Synopsis Forwarding class name for profile-aware counter
Contextconfigure service vprn string interface string sap string eth-cfm collect-lmm-fc-stats fc-in-profile keyword
Treefc-in-profile

Description

This command configures individual counters for the specified FCs with regard to profile. The system includes all countable packets that match a configured FC and that are deemed to be in-profile in this counter.

An FC specified as part of this command and for this specific context cannot be specified as a profile-unaware FC using the fc command under the collect-lmm-fc-stats context.

When this command is reentered, a differential is performed. Omitted FCs stop counting, newly added FCs start counting, and unchanged FCs continue to count.

Optionsbe, l2, af, l1, h2, ef, h1, nc
Max. Instances 8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

collect-lmm-stats boolean
Synopsis Collect statistics for loss measurement message tests
Contextconfigure service vprn string interface string sap string eth-cfm collect-lmm-stats boolean
Treecollect-lmm-stats

Description

When configured to true, the router instantiates the statistical counter to transmit and receive packets for the LAG facility MEP bindings.

The show eth-cfm collect-lmm-stats command displays entities that have been enabled to collect transit and receive counters.

When configured to false, the router does not instantiate the counter and the LMM PDU associated with the MEP does not populate the counters in the packet.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mep md-admin-name reference ma-admin-name reference mep-id number
Synopsis Enter the mep list instance
Context configure service vprn string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number
Treemep
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mep-id number
Synopsis Maintenance Endpoint (MEP) ID
Context configure service vprn string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number
Treemep
Range1 to 8191

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

alarm-notification
Synopsis Enter the alarm-notification context
Contextconfigure service vprn string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number alarm-notification
Treealarm-notification

Description

Commands in this context configure the Fault Notification Generator (FNG) time values to raise an alarm or reset the CCM defect alarm. 

Use these timers for network management processes. The timers are not tied into delaying the notification to the fault management system on the network element and do not affect fault propagation mechanisms.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ccm-padding-size number
Synopsis Number of octets of padding to insert in CCM packets
Contextconfigure service vprn string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number ccm-padding-size number
Treeccm-padding-size

Description

This command sets the byte size of the optional Data TLV to be included in the ETH-CC PDU.

This command increases the size of the ETH-CC PDU by the configured value. The base size of the ETH-CC PDU, including the Interface Status TLV and Port Status TLV, is 83 bytes not including the Layer 2 encapsulation. CCM padding is not supported when the CCM interval (configured through configure eth-cfm domain association ccm-interval) is less than 1 second.

Range3 to 1500
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

csf
Synopsis Enable the csf context
Context configure service vprn string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number csf
Treecsf
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-test
Synopsis Enable the eth-test context
Context configure service vprn string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test
Treeeth-test

Description

Commands in this context configure information used by the Ethernet Test (ETH-TST) packet. The commands must be configured on both the sender and the receiver nodes. The test packets are used with the oam eth-cfm eth-test command.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

test-pattern
Synopsis Enter the test-pattern context
Contextconfigure service vprn string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test test-pattern
Treetest-pattern

Description

Commands in this context specify the test pattern for the ETH-TST frames. The pattern does not have to be the same on the sender and the receiver.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

pattern keyword
Synopsis Test pattern for Ethernet Test frames
Contextconfigure service vprn string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test test-pattern pattern keyword
Treepattern

Description

This command specifies the test pattern of the Ethernet Test (ETH-TST) frames. This does not have to be configured the same on the sender and the receiver.

Optionsall-zeros, all-ones
Default all-zeros
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

grace
Synopsis Enter the grace context
Context configure service vprn string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace
Treegrace

Description

Commands in this context configure the Nokia ETH-CFM Grace function and the ITU-T Y.1731 Ethernet Expected Default (ETH-ED) function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-ed
Synopsis Enter the eth-ed context
Context configure service vprn string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-ed
Treeeth-ed

Description

Commands in this context configure the ITU-T Y.1731 ETH-ED function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

rx-eth-ed boolean
Synopsis Receive and process ETH-ED ITU-T Y.1731 PDUs on the MEP
Contextconfigure service vprn string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-ed rx-eth-ed boolean
Treerx-eth-ed

Description

This command enables the reception and processing of the ITU-T Y.1731 ETH-ED PDU on the MEP.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-vsm-grace
Synopsis Enter the eth-vsm-grace context
Contextconfigure service vprn string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace
Treeeth-vsm-grace

Description

Commands in this context configure the Nokia ETH-CFM Grace function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

rx-eth-vsm-grace boolean
Synopsis Receive and process Nokia ETH-CFM Grace PDU on the MEP
Contextconfigure service vprn string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace rx-eth-vsm-grace boolean
Treerx-eth-vsm-grace

Description

When configured to true, the router enables the Nokia Grace function, which is a vendor-specific PDU that informs MEP peers that the local node may be entering a period of expected defect.

When configured to false, the router disables the Nokia Grace function.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

tx-eth-vsm-grace boolean
Synopsis Transmit ETH-ED PDUs from the MEP
Context configure service vprn string interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace tx-eth-vsm-grace boolean
Treetx-eth-vsm-grace

Description

When configured to true, the router can transmit the Nokia ETH-CFM Grace PDU from the MEP when a system soft reset notification is received for one or more cards.

The Nokia Grace function is a vendor-specific PDU that informs MEP peers that the local node may be entering a period of expected defect.

The operator must configure the configure system eth-cfm grace command to instruct the system that the node is capable of transmitting expected-defect windows to peers. The system can only transmit one form of ETH-CFM grace (Nokia ETH-CFM Grace or ITU-T Y.1731 ETH-ED).

When configured to false, the router disables the transmission of the Nokia ETH-CFM Grace PDU from the MEP.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

squelch-ingress-levels number
Synopsis Levels for which ETH-CFM packets are silently discarded
Contextconfigure service vprn string interface string sap string eth-cfm squelch-ingress-levels number
Treesquelch-ingress-levels

Description

This command defines the levels of the ETH-CFM packets that are silently discarded on ingress into the SAP or SDP binding from the wire that matches the service delineation of the SAP or SDP binding. All ETH-CFM packets inbound to the SAP or SDP binding that match the configured levels are dropped without regard for any other ETH-CFM criteria. No statistical information or drop count is available for any ETH-CFM packet that is silently discarded by this option.

The list of levels must be a complete contiguous list from 0 up to the highest level that will be dropped.

Range0 to 7
Max. Instances8
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fwd-wholesale
Synopsis Enter the fwd-wholesale context
Contextconfigure service vprn string interface string sap string fwd-wholesale
Treefwd-wholesale
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

host-admin-state keyword
Synopsis Administrative state of the hosts
Context configure service vprn string interface string sap string host-admin-state keyword
Treehost-admin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ingress
Synopsis Enter the ingress context
Context configure service vprn string interface string sap string ingress
Treeingress
Introduced16.0.R1

Platforms

All

filter
Synopsis Enter the filter context
Context configure service vprn string interface string sap string ingress filter
Treefilter
Introduced16.0.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service vprn string interface string sap string ingress qos
Treeqos
Introduced16.0.R1

Platforms

All

policer-control-policy
Synopsis Enter the policer-control-policy context
Contextconfigure service vprn string interface string sap string ingress qos policer-control-policy
Treepolicer-control-policy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

overrides
Synopsis Enable the overrides context
Context configure service vprn string interface string sap string ingress qos policer-control-policy overrides
Treeoverrides
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

root
Synopsis Enter the root context
Context configure service vprn string interface string sap string ingress qos policer-control-policy overrides root
Treeroot
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

priority-mbs-thresholds
Synopsis Enter the priority-mbs-thresholds context
Contextconfigure service vprn string interface string sap string ingress qos policer-control-policy overrides root priority-mbs-thresholds
Treepriority-mbs-thresholds
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

priority [priority-level] number
Synopsis Enter the priority list instance
Contextconfigure service vprn string interface string sap string ingress qos policer-control-policy overrides root priority-mbs-thresholds priority number
Treepriority
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

sap-ingress
Synopsis Enter the sap-ingress context
Context configure service vprn string interface string sap string ingress qos sap-ingress
Treesap-ingress
Introduced16.0.R1

Platforms

All

fp-redirect-group
Synopsis Enter the fp-redirect-group context
Contextconfigure service vprn string interface string sap string ingress qos sap-ingress fp-redirect-group
Treefp-redirect-group
Introduced16.0.R1

Platforms

All

overrides
Synopsis Enter the overrides context
Context configure service vprn string interface string sap string ingress qos sap-ingress overrides
Treeoverrides
Introduced16.0.R1

Platforms

All

ip-criteria
Synopsis Enter the ip-criteria context
Context configure service vprn string interface string sap string ingress qos sap-ingress overrides ip-criteria
Treeip-criteria
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ipv6-criteria
Synopsis Enter the ipv6-criteria context
Contextconfigure service vprn string interface string sap string ingress qos sap-ingress overrides ipv6-criteria
Treeipv6-criteria
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

policer [policer-id] reference
Synopsis Enter the policer list instance
Contextconfigure service vprn string interface string sap string ingress qos sap-ingress overrides policer reference
Treepolicer
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service vprn string interface string sap string ingress qos sap-ingress overrides policer reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

rate
Synopsis Enter the rate context
Context configure service vprn string interface string sap string ingress qos sap-ingress overrides policer reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

stat-mode keyword
Synopsis Mode of statistics collected by the policer
Contextconfigure service vprn string interface string sap string ingress qos sap-ingress overrides policer reference stat-mode keyword
Treestat-mode
Optionsno-stats, minimal, offered-profile-no-cir, offered-total-cir, offered-priority-no-cir, offered-profile-cir, offered-priority-cir, offered-limited-profile-cir, offered-profile-capped-cir, offered-limited-capped-cir
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

queue [queue-id] reference
Synopsis Enter the queue list instance
Context configure service vprn string interface string sap string ingress qos sap-ingress overrides queue reference
Treequeue
Introduced16.0.R1

Platforms

All

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure service vprn string interface string sap string ingress qos sap-ingress overrides queue reference adaptation-rule
Treeadaptation-rule
Introduced16.0.R1

Platforms

All

drop-tail
Synopsis Enter the drop-tail context
Context configure service vprn string interface string sap string ingress qos sap-ingress overrides queue reference drop-tail
Treedrop-tail
Introduced16.0.R1

Platforms

All

low
Synopsis Enter the low context
Context configure service vprn string interface string sap string ingress qos sap-ingress overrides queue reference drop-tail low
Treelow
Introduced16.0.R1

Platforms

All

monitor-queue-depth
Synopsis Enable the monitor-queue-depth context
Contextconfigure service vprn string interface string sap string ingress qos sap-ingress overrides queue reference monitor-queue-depth
Treemonitor-queue-depth
Introduced21.7.R1

Platforms

All

parent
Synopsis Enter the parent context
Context configure service vprn string interface string sap string ingress qos sap-ingress overrides queue reference parent
Treeparent
Introduced16.0.R1

Platforms

All

percent-rate
Synopsis Enter the percent-rate context
Contextconfigure service vprn string interface string sap string ingress qos sap-ingress overrides queue reference percent-rate
Treepercent-rate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

All

rate
Synopsis Enter the rate context
Context configure service vprn string interface string sap string ingress qos sap-ingress overrides queue reference rate
Treerate

Notes

The following elements are part of a choice: percent-rate or rate.

Introduced16.0.R1

Platforms

All

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service vprn string interface string sap string ingress qos scheduler-policy
Treescheduler-policy
Introduced16.0.R1

Platforms

All

overrides
Synopsis Enter the overrides context
Context configure service vprn string interface string sap string ingress qos scheduler-policy overrides
Treeoverrides
Introduced16.0.R1

Platforms

All

scheduler [scheduler-name] string
Synopsis Enter the scheduler list instance
Contextconfigure service vprn string interface string sap string ingress qos scheduler-policy overrides scheduler string
Treescheduler
Introduced16.0.R1

Platforms

All

[scheduler-name] string
Synopsis Scheduler name
Contextconfigure service vprn string interface string sap string ingress qos scheduler-policy overrides scheduler string
Treescheduler

Description

This command specifies the scheduler name which is composed of printable 7-bit ASCII characters. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes. Each scheduler must have a unique name within the context of the scheduler policy. However, the same name can be reused in multiple scheduler policies. If the scheduler name already exists within the policy tier level, the context changes to that scheduler name for the purpose of editing the scheduler commands.

If the scheduler name exists within the policy on a different tier, an error occurs and the current context does not change. If the scheduler name does not exist in this or another tier within the scheduler policy, it is assumed that an attempt is being made to create a scheduler of that name.

If the provided scheduler name is invalid, a name syntax error occurs, the command does not execute, and the context is not change.

String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

parent
Synopsis Enter the parent context
Context configure service vprn string interface string sap string ingress qos scheduler-policy overrides scheduler string parent
Treeparent
Introduced16.0.R1

Platforms

All

rate
Synopsis Enter the rate context
Context configure service vprn string interface string sap string ingress qos scheduler-policy overrides scheduler string rate
Treerate
Introduced16.0.R1

Platforms

All

ip-tunnel [tunnel-name] string
Synopsis Enter the ip-tunnel list instance
Contextconfigure service vprn string interface string sap string ip-tunnel string
Treeip-tunnel
Max. Instances1
Introduced16.0.R1

Platforms

All

[tunnel-name] string
Synopsis IP tunnel name
Contextconfigure service vprn string interface string sap string ip-tunnel string
Treeip-tunnel
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

backup-remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisBackup remote IP address that is applied to this tunnel
Contextconfigure service vprn string interface string sap string ip-tunnel string backup-remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treebackup-remote-ip-address
Introduced16.0.R1

Platforms

All

clear-df-bit boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisClear the Do-not-Fragment bit
Contextconfigure service vprn string interface string sap string ip-tunnel string clear-df-bit boolean
Treeclear-df-bit

Description

When configured to true, the DF bit is cleared (set to 0) in all payload IP packets associated with the GRE or IPsec tunnel, before any potential fragmentation resulting from the ip-mtu command. This requires a modification of the header checksum.

When configured to false, clearing of the DF bit is disabled.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

delivery-service string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisService to originate and terminate GRE packets
Contextconfigure service vprn string interface string sap string ip-tunnel string delivery-service string
Treedelivery-service

Description

This command specifies the service used to originate and terminate the GRE encapsulated packets belonging to the GRE tunnel. The delivery service may be the same service that owns the private tunnel SAP associated with the GRE tunnel.

The GRE tunnel does not come up until a valid delivery service is configured.

String Length1 to 64
Introduced16.0.R1

Platforms

All

description string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisText description
Contextconfigure service vprn string interface string sap string ip-tunnel string description string
Treedescription
String Length1 to 80
Introduced16.0.R1

Platforms

All

dest-ip [dest-ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Add a list entry for dest-ip
Context configure service vprn string interface string sap string ip-tunnel string dest-ip (ipv4-address-no-zone | ipv6-address-no-zone)
Treedest-ip
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[dest-ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the remote IP tunnel endpoint
Contextconfigure service vprn string interface string sap string ip-tunnel string dest-ip (ipv4-address-no-zone | ipv6-address-no-zone)
Treedest-ip

Description

This command configures the IP address of the remote IP tunnel endpoint. If the remote IP address is not within the subnet of the IP interface associated with the tunnel, the tunnel fails to come up.

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dscp keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDifferentiated Services Code Point (DSCP) name
Contextconfigure service vprn string interface string sap string ip-tunnel string dscp keyword
Treedscp
Optionsbe, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

encapsulated-ip-mtu number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum size of the encapsulated tunnel packet
Contextconfigure service vprn string interface string sap string ip-tunnel string encapsulated-ip-mtu number
Treeencapsulated-ip-mtu

Description

This command specifies the maximum size of the encapsulated tunnel packet for the IP tunnel. If the packet exceeds this value, the system fragments the packet.

Range512 to 9000
Unitsbytes
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

gre-header
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the gre-header context
Contextconfigure service vprn string interface string sap string ip-tunnel string gre-header
Treegre-header
Introduced16.0.R1

Platforms

All

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of the GRE header in the tunnel
Contextconfigure service vprn string interface string sap string ip-tunnel string gre-header admin-state keyword
Treeadmin-state
Optionsenable, disable
Introduced 16.0.R1

Platforms

All

key
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the key context
Contextconfigure service vprn string interface string sap string ip-tunnel string gre-header key
Treekey
Introduced16.0.R1

Platforms

All

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of the keys in the GRE header
Contextconfigure service vprn string interface string sap string ip-tunnel string gre-header key admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

receive number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisReceive key of the GRE header
Contextconfigure service vprn string interface string sap string ip-tunnel string gre-header key receive number
Treereceive
Max. Range0 to 4294967295
Default0
Introduced 16.0.R1

Platforms

All

send number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSend key of the GRE header
Contextconfigure service vprn string interface string sap string ip-tunnel string gre-header key send number
Treesend
Max. Range0 to 4294967295
Default0
Introduced 16.0.R1

Platforms

All

icmp-generation
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the icmp-generation context
Contextconfigure service vprn string interface string sap string ip-tunnel string icmp-generation
Treeicmp-generation
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

frag-required
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the frag-required context
Contextconfigure service vprn string interface string sap string ip-tunnel string icmp-generation frag-required
Treefrag-required
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSend fragmentation required messages
Contextconfigure service vprn string interface string sap string ip-tunnel string icmp-generation frag-required admin-state keyword
Treeadmin-state
Optionsenable, disable
Introduced 21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

interval number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum interval that the ICMP messages can be sent
Contextconfigure service vprn string interface string sap string ip-tunnel string icmp-generation frag-required interval number
Treeinterval
Range1 to 60
Unitsseconds
Default 10
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

message-count number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of ICMP messages sent
Contextconfigure service vprn string interface string sap string ip-tunnel string icmp-generation frag-required message-count number
Treemessage-count

Description

This command configures the maximum number of ICMP messages that can be sent during the period specified by the interval command.

Range10 to 1000
Default100
Introduced 21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

icmp6-generation
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the icmp6-generation context
Contextconfigure service vprn string interface string sap string ip-tunnel string icmp6-generation
Treeicmp6-generation
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

packet-too-big
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the packet-too-big context
Contextconfigure service vprn string interface string sap string ip-tunnel string icmp6-generation packet-too-big
Treepacket-too-big
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of sending Packet Too Big messages
Contextconfigure service vprn string interface string sap string ip-tunnel string icmp6-generation packet-too-big admin-state keyword
Treeadmin-state
Optionsenable, disable
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

number number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of PTB ICMPv6 messages that can be sent
Contextconfigure service vprn string interface string sap string ip-tunnel string icmp6-generation packet-too-big number number
Treenumber

Description

This command configures the maximum number of ICMPv6 messages that can be sent during the configured interval.

Range10 to 1000
Default100
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

seconds number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum interval when PTB messages can be sent
Contextconfigure service vprn string interface string sap string ip-tunnel string icmp6-generation packet-too-big seconds number
Treeseconds
Range1 to 60
Unitsseconds
Default 10
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-mtu number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIP MTU for the interface
Contextconfigure service vprn string interface string sap string ip-tunnel string ip-mtu number
Treeip-mtu

Description

This command specifies the IP MTU for the interface. If the DF bit is not set in the packet, IP packet fragmentation is performed, if necessary, based on this configured value.

When unconfigured, all IP packets, regardless of the packet size or DF bit setting, are allowed into the tunnel without fragmentation.

Range512 to 9000
Unitsbytes
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

local-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal IP address of this tunnel
Contextconfigure service vprn string interface string sap string ip-tunnel string local-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treelocal-ip-address

Description

This command specifies the local IP address to use for the IP tunnel. This configuration applies to the outer IP header of the encapsulated packets. The address must belong to one of the IP subnets associated with the public SAP interface of the tunnel group. The source IP address, the remote IP address, and the backup remote IP address of a tunnel must all belong to the same address family (IPv4 or IPv6).

When this command specifies an IPv6 address, it must be a global unicast address.

Introduced16.0.R1

Platforms

All

pmtu-discovery-aging number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTime to age out the learned path MTU
Contextconfigure service vprn string interface string sap string ip-tunnel string pmtu-discovery-aging number
Treepmtu-discovery-aging

Description

This command configures the temporary public MTU expiration time. The temporary public MTU is used for MTU propagation.

Range900 to 3600
Unitsseconds
Default 900
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

private-tcp-mss-adjust number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTCP Maximum Segment Size (MSS) on the private side
Contextconfigure service vprn string interface string sap string ip-tunnel string private-tcp-mss-adjust number
Treeprivate-tcp-mss-adjust

Description

This command specifies the TCP MSS to adjust for tunnels on the private side. The value is used to adjust the TCP MSS option in the TCP SYN packet.

Range512 to 9000
Unitsbytes
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

propagate-pmtu-v4 boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable propagation of the path MTU to IPv4 hosts
Contextconfigure service vprn string interface string sap string ip-tunnel string propagate-pmtu-v4 boolean
Treepropagate-pmtu-v4
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

propagate-pmtu-v6 boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable propagation of path MTU to IPv6 hosts
Contextconfigure service vprn string interface string sap string ip-tunnel string propagate-pmtu-v6 boolean
Treepropagate-pmtu-v6
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

public-tcp-mss-adjust (number | keyword)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTCP Maximum Segment Size (MSS) on the public side
Contextconfigure service vprn string interface string sap string ip-tunnel string public-tcp-mss-adjust (number | keyword)
Treepublic-tcp-mss-adjust

Description

This command specifies the TCP MSS for TCP traffic sent from the public network to the private network. The value is used to adjust the TCP MSS option in the TCP SYN packet.

Range512 to 9000
Unitsbytes
Options auto
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

reassembly (number | keyword)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum reassembly wait time
Contextconfigure service vprn string interface string sap string ip-tunnel string reassembly (number | keyword)
Treereassembly

Description

This command configures the maximum time to wait to receive all fragments of a particular IPsec or GRE packet for reassembly.

Range1 to 5000
Unitsmilliseconds
Options use-tunnel-group-setting, none
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRemote IP address of the tunnel
Contextconfigure service vprn string interface string sap string ip-tunnel string remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeremote-ip-address
Introduced16.0.R1

Platforms

All

ipsec-gateway [name] string
Synopsis Enter the ipsec-gateway list instance
Contextconfigure service vprn string interface string sap string ipsec-gateway string
Treeipsec-gateway
Max. Instances1
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis IPsec gateway name
Context configure service vprn string interface string sap string ipsec-gateway string
Treeipsec-gateway
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the IPsec gateway
Contextconfigure service vprn string interface string sap string ipsec-gateway string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

cert
Synopsis Enter the cert context
Context configure service vprn string interface string sap string ipsec-gateway string cert
Treecert
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

status-verify
Synopsis Enter the status-verify context
Contextconfigure service vprn string interface string sap string ipsec-gateway string cert status-verify
Treestatus-verify

Description

Commands in this context configure certificate revocation status verification.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

default-result keyword
Synopsis Default result of Certificate Status Verification (CSV)
Contextconfigure service vprn string interface string sap string ipsec-gateway string cert status-verify default-result keyword
Treedefault-result

Description

This command specifies the default result when both the primary and secondary methods fail to provide an answer.

Optionsrevoked, good
Default revoked
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

client-db
Synopsis Enable the client-db context
Context configure service vprn string interface string sap string ipsec-gateway string client-db
Treeclient-db

Description

Commands in this context configure the IPsec client database. The client database is used to authenticate the IKEv2 dynamic LAN-to-LAN tunnel.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

fallback boolean
Synopsis Fall back to the default authentication policy
Contextconfigure service vprn string interface string sap string ipsec-gateway string client-db fallback boolean
Treefallback

Description

When configured to true, this command specifies whether the IPsec gateway can fall back to the default authentication policy when the IPsec tunnel authentication request fails to match any clients in the IPsec database.

When configured to false and the client database lookup fails to return a matched result, the system fails the tunnel setup.

Defaulttrue
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

default-secure-service
Synopsis Enable the default-secure-service context
Contextconfigure service vprn string interface string sap string ipsec-gateway string default-secure-service
Treedefault-secure-service
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

interface string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPrivate IPsec tunnel interface name
Contextconfigure service vprn string interface string sap string ipsec-gateway string default-secure-service interface string
Treeinterface
String Length1 to 32
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

service-name string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDefault security service name
Contextconfigure service vprn string interface string sap string ipsec-gateway string default-secure-service service-name string
Treeservice-name
String Length1 to 64
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dhcp-address-assignment
Synopsis Enter the dhcp-address-assignment context
Contextconfigure service vprn string interface string sap string ipsec-gateway string dhcp-address-assignment
Treedhcp-address-assignment
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dhcpv4
Synopsis Enable the dhcpv4 context
Context configure service vprn string interface string sap string ipsec-gateway string dhcp-address-assignment dhcpv4
Treedhcpv4
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

gi-address string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisGateway IP address of DHCPv4 packets sent by the system
Contextconfigure service vprn string interface string sap string ipsec-gateway string dhcp-address-assignment dhcpv4 gi-address string
Treegi-address
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

send-release boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSend DHCPv4 release message when IPsec tunnel removed
Contextconfigure service vprn string interface string sap string ipsec-gateway string dhcp-address-assignment dhcpv4 send-release boolean
Treesend-release
Defaulttrue
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

server
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the server context
Contextconfigure service vprn string interface string sap string ipsec-gateway string dhcp-address-assignment dhcpv4 server
Treeserver
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

address string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDHCPv4 server addresses
Contextconfigure service vprn string interface string sap string ipsec-gateway string dhcp-address-assignment dhcpv4 server address string
Treeaddress

Description

This command specifies DHCPv4 server addresses for the DHCPv4-based address assignment. If multiple server addresses are specified, the first advertised DHCPv4 address received is chosen.

Max. Instances8
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dhcpv6
Synopsis Enable the dhcpv6 context
Context configure service vprn string interface string sap string ipsec-gateway string dhcp-address-assignment dhcpv6
Treedhcpv6
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

send-release boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSend DHCPv6 release message when IPsec tunnel removed
Contextconfigure service vprn string interface string sap string ipsec-gateway string dhcp-address-assignment dhcpv6 send-release boolean
Treesend-release
Defaulttrue
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

server
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the server context
Contextconfigure service vprn string interface string sap string ipsec-gateway string dhcp-address-assignment dhcpv6 server
Treeserver
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

address string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDHCPv6 server addresses
Contextconfigure service vprn string interface string sap string ipsec-gateway string dhcp-address-assignment dhcpv6 server address string
Treeaddress

Description

This command specifies DHCPv6 server addresses for the DHCPv6-based address assignment. If multiple server addresses are specified, the first advertised DHCPv6 address received is chosen.

Max. Instances8
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

local
Synopsis Enter the local context
Context configure service vprn string interface string sap string ipsec-gateway string local
Treelocal
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

address-assignment
Synopsis Enable the address-assignment context
Contextconfigure service vprn string interface string sap string ipsec-gateway string local address-assignment
Treeaddress-assignment
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ipv4
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the ipv4 context
Contextconfigure service vprn string interface string sap string ipsec-gateway string local address-assignment ipv4
Treeipv4
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dhcp-server string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal DHCPv4 server name
Contextconfigure service vprn string interface string sap string ipsec-gateway string local address-assignment ipv4 dhcp-server string
Treedhcp-server
String Length1 to 32

Notes

This element is mandatory.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

pool string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisName of the pool defined in the specified DHCPv4 server
Contextconfigure service vprn string interface string sap string ipsec-gateway string local address-assignment ipv4 pool string
Treepool
String Length1 to 32

Notes

This element is mandatory.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

router-instance string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRouter instance ID for the local DHCPv4 server
Contextconfigure service vprn string interface string sap string ipsec-gateway string local address-assignment ipv4 router-instance string
Treerouter-instance
String Length1 to 64

Notes

This element is mandatory.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

secondary-pool string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisName of the secondary pool defined in the DHCPv4 server
Contextconfigure service vprn string interface string sap string ipsec-gateway string local address-assignment ipv4 secondary-pool string
Treesecondary-pool
String Length1 to 32
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ipv6
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the ipv6 context
Contextconfigure service vprn string interface string sap string ipsec-gateway string local address-assignment ipv6
Treeipv6
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dhcp-server string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal DHCPv6 server name
Contextconfigure service vprn string interface string sap string ipsec-gateway string local address-assignment ipv6 dhcp-server string
Treedhcp-server
String Length1 to 32

Notes

This element is mandatory.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

pool string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSecondary pool name defined in the DHCPv6 server
Contextconfigure service vprn string interface string sap string ipsec-gateway string local address-assignment ipv6 pool string
Treepool
String Length1 to 32

Notes

This element is mandatory.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

router-instance string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRouter instance ID hosting the DHCPv6 connection
Contextconfigure service vprn string interface string sap string ipsec-gateway string local address-assignment ipv6 router-instance string
Treerouter-instance
String Length1 to 64

Notes

This element is mandatory.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLocal gateway address of the IPsec gateway
Contextconfigure service vprn string interface string sap string ipsec-gateway string local gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treegateway-address
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

id
Synopsis Enter the id context
Context configure service vprn string interface string sap string ipsec-gateway string local id
Treeid

Description

Commands in this context specify the local ID used for the Identification Indicator (IDi) or Identification Responder (IDr) in the IKEv2 tunnel.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

auto
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSelect ID based on authentication method in IKE policy
Contextconfigure service vprn string interface string sap string ipsec-gateway string local id auto
Treeauto

Notes

The following elements are part of a choice: auto, fqdn, ipv4, or ipv6.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

fqdn string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisFQDN as the local ID type
Contextconfigure service vprn string interface string sap string ipsec-gateway string local id fqdn string
Treefqdn
String Length1 to 255

Notes

The following elements are part of a choice: auto, fqdn, ipv4, or ipv6.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ipv4 string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPv4 address as the local ID type
Contextconfigure service vprn string interface string sap string ipsec-gateway string local id ipv4 string
Treeipv4

Notes

The following elements are part of a choice: auto, fqdn, ipv4, or ipv6.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPv6 address as the local ID type
Contextconfigure service vprn string interface string sap string ipsec-gateway string local id ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
Treeipv6

Notes

The following elements are part of a choice: auto, fqdn, ipv4, or ipv6.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

max-history-key-records
Synopsis Enter the max-history-key-records context
Contextconfigure service vprn string interface string sap string ipsec-gateway string max-history-key-records
Treemax-history-key-records
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

radius
Synopsis Enter the radius context
Context configure service vprn string interface string sap string ipsec-gateway string radius
Treeradius
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ipsec-tunnel [name] string
Synopsis Enter the ipsec-tunnel list instance
Contextconfigure service vprn string interface string sap string ipsec-tunnel string
Treeipsec-tunnel
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis IPsec tunnel name
Context configure service vprn string interface string sap string ipsec-tunnel string
Treeipsec-tunnel
String Length1 to 32

Notes

This element is part of a list key.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the IPsec tunnel
Contextconfigure service vprn string interface string sap string ipsec-tunnel string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

bfd
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the bfd context
Contextconfigure service vprn string interface string sap string ipsec-tunnel string bfd
Treebfd
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

bfd-designate boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDesignate IPsec tunnel to carry BFD traffic
Contextconfigure service vprn string interface string sap string ipsec-tunnel string bfd bfd-designate boolean
Treebfd-designate
Defaultfalse
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

bfd-liveness
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the bfd-liveness context
Contextconfigure service vprn string interface string sap string ipsec-tunnel string bfd bfd-liveness
Treebfd-liveness

Description

Commands in this context configure a BFD session to provide a heart-beat mechanism for a specified IPsec tunnel. There can be only one BFD session assigned to any given IPsec tunnel, but there can be multiple IPsec tunnels using the same BFD session.

BFD controls the state of the association tunnel. If the BFD session goes down, the system brings down the associated non-designated IPsec tunnel.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dest-ip string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDestination address used for the BFD session
Contextconfigure service vprn string interface string sap string ipsec-tunnel string bfd bfd-liveness dest-ip string
Treedest-ip

Notes

This element is mandatory.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

interface string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisName of the interface used by the BFD session
Contextconfigure service vprn string interface string sap string ipsec-tunnel string bfd bfd-liveness interface string
Treeinterface
String Length1 to 32

Notes

This element is mandatory.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

service-name string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative service name
Contextconfigure service vprn string interface string sap string ipsec-tunnel string bfd bfd-liveness service-name string
Treeservice-name

Description

This command configures the name of the service where BFD traffic is forwarded to.

String Length1 to 64

Notes

This element is mandatory.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

clear-df-bit boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisReset the DF bit to 0 in all payload IP packets
Contextconfigure service vprn string interface string sap string ipsec-tunnel string clear-df-bit boolean
Treeclear-df-bit

Description

When configured to true, the DF bit is set to 0 in all payload IP packets associated with the IPsec tunnel, before any potential fragmentation occurs.

Defaultfalse
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

copy-traffic-class-upon-decapsulation boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable traffic class copy upon decapsulation
Contextconfigure service vprn string interface string sap string ipsec-tunnel string copy-traffic-class-upon-decapsulation boolean
Treecopy-traffic-class-upon-decapsulation

Description

When configured to true, the system copies the traffic class from the outer tunnel IP packet header to the payload IP packet header in the decapsulating direction (public to private).

Defaultfalse
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dest-ip [address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Add a list entry for dest-ip
Context configure service vprn string interface string sap string ipsec-tunnel string dest-ip (ipv4-address-no-zone | ipv6-address-no-zone)
Treedest-ip
Max. Instances16
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Private IP address of the remote IP tunnel endpoint
Contextconfigure service vprn string interface string sap string ipsec-tunnel string dest-ip (ipv4-address-no-zone | ipv6-address-no-zone)
Treedest-ip

Notes

This element is part of a list key.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

encapsulated-ip-mtu number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum size of the encapsulated tunnel packet
Contextconfigure service vprn string interface string sap string ipsec-tunnel string encapsulated-ip-mtu number
Treeencapsulated-ip-mtu

Description

This command specifies the maximum size of the encapsulated tunnel packet to the IPsec tunnel, the IP tunnel, or the dynamic tunnels terminated on the IPsec Gateway. If the encapsulated IPv4 or IPv6 tunnel packet exceeds this value, the system fragments the packet.

Range512 to 9000
Unitsbytes
Introduced 19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

icmp-generation
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the icmp-generation context
Contextconfigure service vprn string interface string sap string ipsec-tunnel string icmp-generation
Treeicmp-generation

Description

Commands in this context configure settings for ICMPv4 message generation.

Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

frag-required
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the frag-required context
Contextconfigure service vprn string interface string sap string ipsec-tunnel string icmp-generation frag-required
Treefrag-required

Description

Commands in this context configure the attributes for sending generated ICMP Destination Unreachable "fragmentation needed and DF set" messages (type 3, code 4) back to the source, if the received size of the IPv4 packet on the private side exceeds the private MTU size.

Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of sending ICMP messages
Contextconfigure service vprn string interface string sap string ipsec-tunnel string icmp-generation frag-required admin-state keyword
Treeadmin-state

Description

This command configures the administrative state of sending ICMP Destination Unreachable "fragmentation needed, DF set" messages (type 3, code 4) messages to the source if the received size of the IPv4 packet on the private side exceeds the private MTU size.

Optionsenable, disable
Default enable
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

interval number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisInterval for sending ICMP messages
Contextconfigure service vprn string interface string sap string ipsec-tunnel string icmp-generation frag-required interval number
Treeinterval

Description

This command configures the interval for sending ICMP Destination Unreachable "fragmentation needed, DF set" messages (type 3, code 4).

Range1 to 60
Unitsseconds
Default 10
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

message-count number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of ICMP messages that can be sent
Contextconfigure service vprn string interface string sap string ipsec-tunnel string icmp-generation frag-required message-count number
Treemessage-count

Description

This command configures the maximum number of ICMP Destination Unreachable "fragmentation needed, DF set" messages (type 3, code 4) that can be sent during the configured interval.

Range10 to 1000
Default100
Introduced 21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

icmp6-generation
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the icmp6-generation context
Contextconfigure service vprn string interface string sap string ipsec-tunnel string icmp6-generation
Treeicmp6-generation

Description

Commands in this context configure settings for ICMPv6 message generation.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

packet-too-big
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the packet-too-big context
Contextconfigure service vprn string interface string sap string ipsec-tunnel string icmp6-generation packet-too-big
Treepacket-too-big

Description

Commands in this context configure the parameters to send ICMPv6 PTB (Packet Too Big) messages on the private side.

The system sends PTB messages if a received IPv6 packet on the private side is greater than 1280 bytes and it exceeds the private MTU of the tunnel.

The private MTU for the tunnel is configured via the configure router interface ipsec ipsec-tunnel ip-mtu command for the interface.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdministrative state of Packet Too Big message sends
Contextconfigure service vprn string interface string sap string ipsec-tunnel string icmp6-generation packet-too-big admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

interval number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisInterval for sending Packet Too Big messages
Contextconfigure service vprn string interface string sap string ipsec-tunnel string icmp6-generation packet-too-big interval number
Treeinterval
Range1 to 60
Unitsseconds
Default 10
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

message-count number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of ICMPv6 PTB messages that can be sent
Contextconfigure service vprn string interface string sap string ipsec-tunnel string icmp6-generation packet-too-big message-count number
Treemessage-count

Description

This command configures the maximum number of PTB messages that can be sent during the configured interval.

Range10 to 1000
Default100
Introduced 19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-mtu number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPrivate MTU of the IPsec tunnel
Contextconfigure service vprn string interface string sap string ipsec-tunnel string ip-mtu number
Treeip-mtu

Description

This command specifies the private MTU of the IPsec tunnel. The private MTU is used to determine the need for fragmentation before encapsulation of the payload packet.

Range512 to 9000
Unitsbytes
Introduced 19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

key-exchange
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the key-exchange context
Contextconfigure service vprn string interface string sap string ipsec-tunnel string key-exchange
Treekey-exchange
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dynamic
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the dynamic context
Contextconfigure service vprn string interface string sap string ipsec-tunnel string key-exchange dynamic
Treedynamic

Notes

The following elements are part of a choice: dynamic or manual.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

auto-establish boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAttempt to establish a phase 1 exchange automatically
Contextconfigure service vprn string interface string sap string ipsec-tunnel string key-exchange dynamic auto-establish boolean
Treeauto-establish
Defaultfalse
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

cert
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the cert context
Contextconfigure service vprn string interface string sap string ipsec-tunnel string key-exchange dynamic cert
Treecert

Description

Commands in this context configure the attributes of the dynamic keying certificate.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

status-verify
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the status-verify context
Contextconfigure service vprn string interface string sap string ipsec-tunnel string key-exchange dynamic cert status-verify
Treestatus-verify

Description

Commands in this context configure attributes of Certificate Status Verification (CSV).

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

default-result keyword
Synopsis Default result for Certificate Status Verification
Contextconfigure service vprn string interface string sap string ipsec-tunnel string key-exchange dynamic cert status-verify default-result keyword
Treedefault-result

Description

This command specifies the default certificate revocation status result to use when all configured CSV methods fail to return a result.   

Optionsrevoked, good
Default revoked
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

primary keyword
Synopsis Primary method of CSV to verify the revocation status
Contextconfigure service vprn string interface string sap string ipsec-tunnel string key-exchange dynamic cert status-verify primary keyword
Treeprimary

Description

This command configures the primary method of Certificate Status Verification (CSV) that is used to verify the revocation status of the certificate of the peer.

Optionscrl, ocsp
Default crl
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

secondary keyword
Synopsis Secondary method used to verify certificate revocation
Contextconfigure service vprn string interface string sap string ipsec-tunnel string key-exchange dynamic cert status-verify secondary keyword
Treesecondary

Description

This command specifies the secondary method of Certificate Status Verification (CSV) that is used to verify the revocation status of the peer certificate.

Optionsnone, crl, ocsp
Defaultnone
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

id
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the id context
Contextconfigure service vprn string interface string sap string ipsec-tunnel string key-exchange dynamic id
Treeid

Description

Commands in this context specify the local ID used for IDi or IDr for IKEv2 negotiation.

The default behavior depends on the local authentication method as follows:

  • Psk: local tunnel IP address

  • Cert-auth: subject of the local certificate

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

fqdn string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisFQDN used as the local ID IKE type
Contextconfigure service vprn string interface string sap string ipsec-tunnel string key-exchange dynamic id fqdn string
Treefqdn
String Length1 to 255

Notes

The following elements are part of a choice: fqdn, ipv4, or ipv6.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ipv4 string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPv4 as the local ID type
Contextconfigure service vprn string interface string sap string ipsec-tunnel string key-exchange dynamic id ipv4 string
Treeipv4

Notes

The following elements are part of a choice: fqdn, ipv4, or ipv6.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPv6 used as the local IKE ID type
Contextconfigure service vprn string interface string sap string ipsec-tunnel string key-exchange dynamic id ipv6 (ipv4-address-no-zone | ipv6-address-no-zone)
Treeipv6

Notes

The following elements are part of a choice: fqdn, ipv4, or ipv6.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ike-policy reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIKE policy ID
Contextconfigure service vprn string interface string sap string ipsec-tunnel string key-exchange dynamic ike-policy reference
Treeike-policy

Description

This command specifies the ID of the IKE policy used for IKE negotiation.

The ipsec-transport-mode-profile configuration only supports IKEv2.

Reference

configure ipsec ike-policy number

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ipsec-transform reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPsec transform IDs used by the dynamic key
Contextconfigure service vprn string interface string sap string ipsec-tunnel string key-exchange dynamic ipsec-transform reference
Treeipsec-transform

Description

This command specifies IPsec transform IDs used for CHILD_SA negotiation.

Reference

configure ipsec ipsec-transform number

Max. Instances4
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

pre-shared-key string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPre-shared key for authentication
Contextconfigure service vprn string interface string sap string ipsec-tunnel string key-exchange dynamic pre-shared-key string
Treepre-shared-key
String Length1 to 115
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

manual
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the manual context
Contextconfigure service vprn string interface string sap string ipsec-tunnel string key-exchange manual
Treemanual

Notes

The following elements are part of a choice: dynamic or manual.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

keys [security-association] number direction keyword
Synopsis Enter the keys list instance
Context configure service vprn string interface string sap string ipsec-tunnel string key-exchange manual keys number direction keyword
Treekeys

Description

Commands in this context configure the security association list for the tunnel.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ipsec-transform reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTransform entry used by manual SAs
Contextconfigure service vprn string interface string sap string ipsec-tunnel string key-exchange manual keys number direction keyword ipsec-transform reference
Treeipsec-transform

Reference

configure ipsec ipsec-transform number

Notes

This element is mandatory.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

spi number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSPI of inbound and outbound packets
Contextconfigure service vprn string interface string sap string ipsec-tunnel string key-exchange manual keys number direction keyword spi number
Treespi

Description

This command specifies the Security Parameter Index (SPI) used to look up the instruction to verify and decrypt the incoming IPsec packets when the direction is inbound. When the direction is outbound, the SPI is used in the encoding of the outgoing packets.

The remote node can use the SPI to look up the instruction to verify and decrypt the packet.

Range256 to 16383

Notes

This element is mandatory.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

max-history-key-records
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the max-history-key-records context
Contextconfigure service vprn string interface string sap string ipsec-tunnel string max-history-key-records
Treemax-history-key-records

Description

Commands in this context configure the settings for recording historical IPsec keys.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

esp number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of recent records
Contextconfigure service vprn string interface string sap string ipsec-tunnel string max-history-key-records esp number
Treeesp
Range1 to 48
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ike number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of historical IKE key records
Contextconfigure service vprn string interface string sap string ipsec-tunnel string max-history-key-records ike number
Treeike
Range1 to 3
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

pmtu-discovery-aging number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAging out time of the learned path MTU
Contextconfigure service vprn string interface string sap string ipsec-tunnel string pmtu-discovery-aging number
Treepmtu-discovery-aging

Description

This command configures the temporary public and private MTU expiration time. The temporary MTU is used for MTU propagation.

Range900 to 3600
Unitsseconds
Default 900
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

private-tcp-mss-adjust number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTCP maximum segment size (MSS) adjustment
Contextconfigure service vprn string interface string sap string ipsec-tunnel string private-tcp-mss-adjust number
Treeprivate-tcp-mss-adjust

Description

This command specifies the TCP MSS to adjust for the tunnel on the private side.

When configured, the system may use the value to update the MSS option in the received TCP SYN packet on the private side.

Range512 to 9000
Unitsbytes
Introduced 19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

propagate-pmtu-v4 boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable propagation of the path MTU to IPv4 hosts
Contextconfigure service vprn string interface string sap string ipsec-tunnel string propagate-pmtu-v4 boolean
Treepropagate-pmtu-v4

Description

When configured to true, the system propagates the path MTU learned from the public side to the private side (IPv4 hosts).

Defaulttrue
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

propagate-pmtu-v6 boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable propagation of the path MTU to IPv6 hosts
Contextconfigure service vprn string interface string sap string ipsec-tunnel string propagate-pmtu-v6 boolean
Treepropagate-pmtu-v6

Description

When configured to true, the system propagates the path MTU learned from the public side to the private side (IPv6 hosts).

Defaulttrue
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

public-tcp-mss-adjust (number | keyword)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTCP maximum segment size (MSS) on the public network
Contextconfigure service vprn string interface string sap string ipsec-tunnel string public-tcp-mss-adjust (number | keyword)
Treepublic-tcp-mss-adjust

Description

This command configures the MSS for the TCP traffic in an IPsec tunnel that is sent from the public network to the private network. The system may use this value to adjust or insert the MSS option in the TCP SYN packet.

Range512 to 9000
Unitsbytes
Options auto
Introduced 19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

replay-window number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAnti-replay window size
Contextconfigure service vprn string interface string sap string ipsec-tunnel string replay-window number
Treereplay-window

Description

This command specifies the size of an IPsec anti-replay window. If unconfigured, IPsec anti-replay is disabled.

Range32 | 64 | 128 | 256 | 512
Unitspackets
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

security-policy
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the security-policy context
Contextconfigure service vprn string interface string sap string ipsec-tunnel string security-policy
Treesecurity-policy
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

id reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPsec security policy ID
Contextconfigure service vprn string interface string sap string ipsec-tunnel string security-policy id reference
Treeid

Reference

configure service vprn string ipsec security-policy number

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

strict-match boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable strict match of the security policy entry
Contextconfigure service vprn string interface string sap string ipsec-tunnel string security-policy strict-match boolean
Treestrict-match

Description

When configured to true, this command enables strict match of the security policy entry.

When a CREATE_CHILD exchange request is received for a static IPsec tunnel, and this request is not a rekey request, ISA matches the received TSi and TSr with the configured security policy. This can be a match only when a received TS (in TSi or TSr) address range matches exactly with the subnet in a security policy entry.

If there is no match, the setup fails, and TS_UNACCEPTABLE is sent.

If there is a match, but there is an existing CHILD_SA for the matched security policy, the setup fails, and NO_PROPOSAL_CHOSEN is sent.

If there is a match, and there is not a CHILD_SA for the matched entry, the subnet is sent in the matched security policy entry as TSi and TSr, and the CHILD_SA is created.

Defaultfalse
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

tunnel-endpoint
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the tunnel-endpoint context
Contextconfigure service vprn string interface string sap string ipsec-tunnel string tunnel-endpoint
Treetunnel-endpoint
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

delivery-service string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDelivery service name
Contextconfigure service vprn string interface string sap string ipsec-tunnel string tunnel-endpoint delivery-service string
Treedelivery-service
String Length1 to 64

Notes

This element is mandatory.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

local-gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAddress used for tunnel of the remote security gateway
Contextconfigure service vprn string interface string sap string ipsec-tunnel string tunnel-endpoint local-gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treelocal-gateway-address

Notes

This element is mandatory.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRemote IP address of this tunnel.
Contextconfigure service vprn string interface string sap string ipsec-tunnel string tunnel-endpoint remote-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeremote-ip-address

Notes

This element is mandatory.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

lag
Synopsis Enter the lag context
Context configure service vprn string interface string sap string lag
Treelag
Introduced16.0.R1

Platforms

All

link-map-profile number
Synopsis LAG link map profile for a SAP or network interface
Contextconfigure service vprn string interface string sap string lag link-map-profile number
Treelink-map-profile

Description

This command assigns a preconfigured LAG link map profile to a SAP or network interface configured on a LAG or a PW port that exists on a LAG. After an operator assigns a LAG link map profile, the system rehashes the SAP or network interface egress traffic over the LAG as required by the new configuration.

If the LAG link map profile for a SAP or network interface is deleted, the system reverts back to per-flow hashing.

Range1 to 64
Introduced16.0.R1

Platforms

All

per-link-hash
Synopsis Enter the per-link-hash context
Contextconfigure service vprn string interface string sap string lag per-link-hash
Treeper-link-hash
Introduced16.0.R1

Platforms

All

static-host
Synopsis Enter the static-host context
Context configure service vprn string interface string sap string static-host
Treestatic-host
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv4 [ip] string mac string
Synopsis Enter the ipv4 list instance
Context configure service vprn string interface string sap string static-host ipv4 string mac string
Treeipv4
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[ip] string
Synopsis IP address
Contextconfigure service vprn string interface string sap string static-host ipv4 string mac string
Treeipv4
MD-CLI Default0.0.0.0

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

mac string
Synopsis MAC address
Contextconfigure service vprn string interface string sap string static-host ipv4 string mac string
Treeipv4
MD-CLI Default00:00:00:00:00:00

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the static host
Contextconfigure service vprn string interface string sap string static-host ipv4 string mac string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

app-profile
Synopsis Enter the app-profile context
Context configure service vprn string interface string sap string static-host ipv4 string mac string app-profile
Treeapp-profile
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

subscriber-id
Synopsis Enter the subscriber-id context
Contextconfigure service vprn string interface string sap string static-host ipv4 string mac string subscriber-id
Treesubscriber-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

string string
Synopsis Subscriber identification
Context configure service vprn string interface string sap string static-host ipv4 string mac string subscriber-id string string
Treestring
String Length1 to 64

Notes

The following elements are part of a choice: string or use-sap-id.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

transit-policy
Synopsis Enable the transit-policy context
Contextconfigure service vprn string interface string sap string transit-policy
Treetransit-policy
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP transit policy ID
Contextconfigure service vprn string interface string sap string transit-policy ip reference
Treeip

Reference

configure application-assurance group number partition number transit-ip-policy number

Notes

The following elements are part of a mandatory choice: ip or prefix.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

prefix reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP prefix policy ID
Contextconfigure service vprn string interface string sap string transit-policy prefix reference
Treeprefix

Reference

configure application-assurance group number partition number transit-prefix-policy number

Notes

The following elements are part of a mandatory choice: ip or prefix.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

spoke-sdp [sdp-bind-id] string
Synopsis Enter the spoke-sdp list instance
Contextconfigure service vprn string interface string spoke-sdp string
Treespoke-sdp
Max. Instances1
Introduced16.0.R1

Platforms

All

[sdp-bind-id] string
Synopsis SDP binding ID
Contextconfigure service vprn string interface string spoke-sdp string
Treespoke-sdp
String Length3 to 16

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

aarp
Synopsis Enable the aarp context
Context configure service vprn string interface string spoke-sdp string aarp
Treeaarp
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

type keyword
Synopsis Role referenced by the AARP
Context configure service vprn string interface string spoke-sdp string aarp type keyword
Treetype
Optionsdual-homed, dual-homed-secondary
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the SDP binding to the service
Contextconfigure service vprn string interface string spoke-sdp string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

bfd
Synopsis Enter the bfd context
Context configure service vprn string interface string spoke-sdp string bfd
Treebfd
Introduced21.2.R1

Platforms

All

bfd-template reference
Synopsis BFD template associated with the SDP binding
Contextconfigure service vprn string interface string spoke-sdp string bfd bfd-template reference
Treebfd-template

Description

This command configures a named BFD template to be used by VCCV BFD on PWs belonging to the VLL service. The template specifies parameters, such as the minimum transmit and receive control packet timer intervals, used by the BFD session. Template parameters are configured under the configure router bfd context.

Reference

configure bfd bfd-template string

Introduced21.2.R1

Platforms

All

failure-action keyword
Synopsis VCCV BFD action taken on the SDP binding
Contextconfigure service vprn string interface string spoke-sdp string bfd failure-action keyword
Treefailure-action

Description

This command configures a named BFD template to be used by VCCV BFD on PWs belonging to the VLL service. The template specifies parameters, such as the minimum transmit and receive control packet timer intervals, used by the BFD session. Template parameters are configured under the configure router bfd context.

Optionsnone, down
Default none
Introduced21.2.R1

Platforms

All

wait-for-up-timer number
Synopsis Time waited for BFD up status
Context configure service vprn string interface string spoke-sdp string bfd wait-for-up-timer number
Treewait-for-up-timer

Description

This command configures the time interval that is used to wait for a BFD session to come up.

This command is triggered when a spoke-SDP is first administratively enabled and a VCCV BFD session transitions from up to down. The command is required to allow time for BFD sessions to come up, and for BFD to settle before selecting the active spoke-SDP for use in a redundant set. In the case where a VCCV BFD session is bouncing, the timer prevents excessive flapping of the operational state of a spoke-SDP.

Range1 to 60
Unitsseconds
Introduced 21.2.R1

Platforms

All

control-word boolean
Synopsis Use the control word as preferred
Context configure service vprn string interface string spoke-sdp string control-word boolean
Treecontrol-word
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

cpu-protection
Synopsis Enter the cpu-protection context
Contextconfigure service vprn string interface string spoke-sdp string cpu-protection
Treecpu-protection
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

eth-cfm-monitoring
Synopsis Enable the eth-cfm-monitoring context
Contextconfigure service vprn string interface string spoke-sdp string cpu-protection eth-cfm-monitoring
Treeeth-cfm-monitoring

Notes

The following elements are part of a choice: eth-cfm-monitoring, ip-src-monitoring, or mac-monitoring.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

ip-src-monitoring
Synopsis Enable IP source monitoring for CPU protection
Contextconfigure service vprn string interface string spoke-sdp string cpu-protection ip-src-monitoring
Treeip-src-monitoring

Notes

The following elements are part of a choice: eth-cfm-monitoring, ip-src-monitoring, or mac-monitoring.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

mac-monitoring
Synopsis Monitor MAC for CPU protection
Context configure service vprn string interface string spoke-sdp string cpu-protection mac-monitoring
Treemac-monitoring

Notes

The following elements are part of a choice: eth-cfm-monitoring, ip-src-monitoring, or mac-monitoring.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS

egress
Synopsis Enter the egress context
Context configure service vprn string interface string spoke-sdp string egress
Treeegress
Introduced16.0.R1

Platforms

All

filter
Synopsis Enter the filter context
Context configure service vprn string interface string spoke-sdp string egress filter
Treefilter
Introduced16.0.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service vprn string interface string spoke-sdp string egress qos
Treeqos
Introduced16.0.R1

Platforms

All

network
Synopsis Enter the network context
Context configure service vprn string interface string spoke-sdp string egress qos network
Treenetwork
Introduced16.0.R1

Platforms

All

port-redirect-group
Synopsis Enter the port-redirect-group context
Contextconfigure service vprn string interface string spoke-sdp string egress qos network port-redirect-group
Treeport-redirect-group
Introduced16.0.R1

Platforms

All

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEgress MPLS VC label to send packets to the far end
Contextconfigure service vprn string interface string spoke-sdp string egress vc-label number
Treevc-label
Range16 to 1048575
Introduced16.0.R1

Platforms

All

entropy-label
Synopsis Enable the use of entropy labels for spoke SDPs
Contextconfigure service vprn string interface string spoke-sdp string entropy-label
Treeentropy-label

Notes

The following elements are part of a choice: entropy-label or hash-label.

Introduced16.0.R1

Platforms

All

eth-cfm
Synopsis Enter the eth-cfm context
Context configure service vprn string interface string spoke-sdp string eth-cfm
Treeeth-cfm
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

collect-lmm-fc-stats
Synopsis Enter the collect-lmm-fc-stats context
Contextconfigure service vprn string interface string spoke-sdp string eth-cfm collect-lmm-fc-stats
Treecollect-lmm-fc-stats

Description

Commands in this context configure per forwarding class (FC) LMM information collection.

The commands fc-in-profile and fc in this context are mutually exclusive. The commands apply to either profile-aware or profile-unaware FCs respectively. 

This command and the collect-lmm-stats command are mutually exclusive when there is entity resource contention.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fc keyword
Synopsis Forwarding class name for profile-unaware counter
Contextconfigure service vprn string interface string spoke-sdp string eth-cfm collect-lmm-fc-stats fc keyword
Treefc

Description

This command configures individual counters for the specified FCs without regard for profile. The system includes all countable packets that match a configured FC, regardless of profile, in this counter.

An FC specified as part of this command and for this specific context cannot be specified as a profile-aware FC using the fc-in-profile command under the collect-lmm-fc-stats context. 

When this command is reentered, a differential is performed. Omitted FCs stop counting, newly added FCs start counting, and unchanged FCs continue to count.

Optionsbe, l2, af, l1, h2, ef, h1, nc
Max. Instances 8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

fc-in-profile keyword
Synopsis Forwarding class name for profile-aware counter
Contextconfigure service vprn string interface string spoke-sdp string eth-cfm collect-lmm-fc-stats fc-in-profile keyword
Treefc-in-profile

Description

This command configures individual counters for the specified FCs with regard to profile. The system includes all countable packets that match a configured FC and that are deemed to be in-profile in this counter.

An FC specified as part of this command and for this specific context cannot be specified as a profile-unaware FC using the fc command under the collect-lmm-fc-stats context.

When this command is reentered, a differential is performed. Omitted FCs stop counting, newly added FCs start counting, and unchanged FCs continue to count.

Optionsbe, l2, af, l1, h2, ef, h1, nc
Max. Instances 8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

collect-lmm-stats boolean
Synopsis Collect statistics for loss measurement message tests
Contextconfigure service vprn string interface string spoke-sdp string eth-cfm collect-lmm-stats boolean
Treecollect-lmm-stats

Description

When configured to true, the router instantiates the statistical counter to transmit and receive packets for the LAG facility MEP bindings.

The show eth-cfm collect-lmm-stats command displays entities that have been enabled to collect transit and receive counters.

When configured to false, the router does not instantiate the counter and the LMM PDU associated with the MEP does not populate the counters in the packet.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

mep md-admin-name reference ma-admin-name reference mep-id number
Synopsis Enter the mep list instance
Context configure service vprn string interface string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number
Treemep
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

alarm-notification
Synopsis Enter the alarm-notification context
Contextconfigure service vprn string interface string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number alarm-notification
Treealarm-notification

Description

Commands in this context configure the Fault Notification Generator (FNG) time values to raise an alarm or reset the CCM defect alarm. 

Use these timers for network management processes. The timers are not tied into delaying the notification to the fault management system on the network element and do not affect fault propagation mechanisms.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ccm-padding-size number
Synopsis Number of octets of padding to insert in CCM packets
Contextconfigure service vprn string interface string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number ccm-padding-size number
Treeccm-padding-size

Description

This command sets the byte size of the optional Data TLV to be included in the ETH-CC PDU.

This command increases the size of the ETH-CC PDU by the configured value. The base size of the ETH-CC PDU, including the Interface Status TLV and Port Status TLV, is 83 bytes not including the Layer 2 encapsulation. CCM padding is not supported when the CCM interval (configured through configure eth-cfm domain association ccm-interval) is less than 1 second.

Range3 to 1500
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

csf
Synopsis Enable the csf context
Context configure service vprn string interface string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number csf
Treecsf
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-test
Synopsis Enable the eth-test context
Context configure service vprn string interface string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test
Treeeth-test

Description

Commands in this context configure information used by the Ethernet Test (ETH-TST) packet. The commands must be configured on both the sender and the receiver nodes. The test packets are used with the oam eth-cfm eth-test command.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

test-pattern
Synopsis Enter the test-pattern context
Contextconfigure service vprn string interface string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test test-pattern
Treetest-pattern

Description

Commands in this context specify the test pattern for the ETH-TST frames. The pattern does not have to be the same on the sender and the receiver.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

pattern keyword
Synopsis Test pattern for Ethernet Test frames
Contextconfigure service vprn string interface string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test test-pattern pattern keyword
Treepattern

Description

This command specifies the test pattern of the Ethernet Test (ETH-TST) frames. This does not have to be configured the same on the sender and the receiver.

Optionsall-zeros, all-ones
Default all-zeros
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

grace
Synopsis Enter the grace context
Context configure service vprn string interface string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace
Treegrace

Description

Commands in this context configure the Nokia ETH-CFM Grace function and the ITU-T Y.1731 Ethernet Expected Default (ETH-ED) function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-ed
Synopsis Enter the eth-ed context
Context configure service vprn string interface string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-ed
Treeeth-ed

Description

Commands in this context configure the ITU-T Y.1731 ETH-ED function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

eth-vsm-grace
Synopsis Enter the eth-vsm-grace context
Contextconfigure service vprn string interface string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace
Treeeth-vsm-grace

Description

Commands in this context configure the Nokia ETH-CFM Grace function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

rx-eth-vsm-grace boolean
Synopsis Receive and process Nokia ETH-CFM Grace PDU on the MEP
Contextconfigure service vprn string interface string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace rx-eth-vsm-grace boolean
Treerx-eth-vsm-grace

Description

When configured to true, the router enables the Nokia Grace function, which is a vendor-specific PDU that informs MEP peers that the local node may be entering a period of expected defect.

When configured to false, the router disables the Nokia Grace function.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

tx-eth-vsm-grace boolean
Synopsis Transmit ETH-ED PDUs from the MEP
Context configure service vprn string interface string spoke-sdp string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace tx-eth-vsm-grace boolean
Treetx-eth-vsm-grace

Description

When configured to true, the router can transmit the Nokia ETH-CFM Grace PDU from the MEP when a system soft reset notification is received for one or more cards.

The Nokia Grace function is a vendor-specific PDU that informs MEP peers that the local node may be entering a period of expected defect.

The operator must configure the configure system eth-cfm grace command to instruct the system that the node is capable of transmitting expected-defect windows to peers. The system can only transmit one form of ETH-CFM grace (Nokia ETH-CFM Grace or ITU-T Y.1731 ETH-ED).

When configured to false, the router disables the transmission of the Nokia ETH-CFM Grace PDU from the MEP.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

squelch-ingress-levels number
Synopsis Levels for which ETH-CFM packets are silently discarded
Contextconfigure service vprn string interface string spoke-sdp string eth-cfm squelch-ingress-levels number
Treesquelch-ingress-levels

Description

This command defines the levels of the ETH-CFM packets that are silently discarded on ingress into the SAP or SDP binding from the wire that matches the service delineation of the SAP or SDP binding. All ETH-CFM packets inbound to the SAP or SDP binding that match the configured levels are dropped without regard for any other ETH-CFM criteria. No statistical information or drop count is available for any ETH-CFM packet that is silently discarded by this option.

The list of levels must be a complete contiguous list from 0 up to the highest level that will be dropped.

Range0 to 7
Max. Instances8
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

hash-label
Synopsis Enable the hash-label context
Context configure service vprn string interface string spoke-sdp string hash-label
Treehash-label

Description

Commands in this context configure the use of hash labels for egress datapaths.

For information about hash-label handling, see the "Hash labels" section of the 7450 ESS, 7750 SR, 7950 XRS, and VSR MPLS Guide.

Notes

The following elements are part of a choice: entropy-label or hash-label.

Introduced16.0.R1

Platforms

All

signal-capability
Synopsis Signal hash label capability to the remote PE
Contextconfigure service vprn string interface string spoke-sdp string hash-label signal-capability
Treesignal-capability

Description

When configured, this command enables the signaling and negotiating of the hash label between the local and remote PE nodes.

The signaling process outcome determines whether the local PE inserts the hash label on the user packets. This outcome can override the local PE configuration.

Introduced16.0.R1

Platforms

All

ingress
Synopsis Enter the ingress context
Context configure service vprn string interface string spoke-sdp string ingress
Treeingress
Introduced16.0.R1

Platforms

All

filter
Synopsis Enter the filter context
Context configure service vprn string interface string spoke-sdp string ingress filter
Treefilter
Introduced16.0.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service vprn string interface string spoke-sdp string ingress qos
Treeqos
Introduced16.0.R1

Platforms

All

network
Synopsis Enter the network context
Context configure service vprn string interface string spoke-sdp string ingress qos network
Treenetwork
Introduced16.0.R1

Platforms

All

fp-redirect-group
Synopsis Enter the fp-redirect-group context
Contextconfigure service vprn string interface string spoke-sdp string ingress qos network fp-redirect-group
Treefp-redirect-group
Introduced16.0.R1

Platforms

All

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIngress MPLS VC label to send packets to the far end
Contextconfigure service vprn string interface string spoke-sdp string ingress vc-label number
Treevc-label
Range1 to 1048575
Introduced16.0.R1

Platforms

All

transit-policy
Synopsis Enable the transit-policy context
Contextconfigure service vprn string interface string spoke-sdp string transit-policy
Treetransit-policy
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP transit policy ID
Contextconfigure service vprn string interface string spoke-sdp string transit-policy ip reference
Treeip

Reference

configure application-assurance group number partition number transit-ip-policy number

Notes

The following elements are part of a mandatory choice: ip or prefix.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

prefix reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP prefix policy ID
Contextconfigure service vprn string interface string spoke-sdp string transit-policy prefix reference
Treeprefix

Reference

configure application-assurance group number partition number transit-prefix-policy number

Notes

The following elements are part of a mandatory choice: ip or prefix.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

vc-type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisType of virtual circuit (VC) associated with the SDP binding
Contextconfigure service vprn string interface string spoke-sdp string vc-type keyword
Treevc-type
Optionsether, ipipe
Default ether
Introduced16.0.R1

Platforms

All

static-tunnel-redundant-nexthop string
Synopsis Address for the static ISA tunnel redundant next-hop
Contextconfigure service vprn string interface string static-tunnel-redundant-nexthop string
Treestatic-tunnel-redundant-nexthop

Description

This command specifies the redundant next-hop address on public or private IPsec interfaces (with a public or private tunnel SAP) for the static IPsec tunnel.

The next-hop address is resolved in the routing table of the corresponding service.

Notes

The following elements are part of a choice: multi-chassis-shunting-profile or (dynamic-tunnel-redundant-nexthop and static-tunnel-redundant-nexthop).

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

tunnel boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEnable/disable tunnel interface
Contextconfigure service vprn string interface string tunnel boolean
Treetunnel
Defaultfalse
Introduced16.0.R1

Platforms

All

vas-if-type keyword
Synopsis VAS interface type
Context configure service vprn string interface string vas-if-type keyword
Treevas-if-type
Optionsto-from-access, to-from-network, to-from-both
Introduced16.0.R1

Platforms

All

vpls [vpls-name] string
Synopsis Enter the vpls list instance
Context configure service vprn string interface string vpls string
Treevpls
Max. Instances1
Introduced16.0.R1

Platforms

All

[vpls-name] string
Synopsis VPLS service
Contextconfigure service vprn string interface string vpls string
Treevpls
String Length1 to 64

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

All

egress
Synopsis Enter the egress context
Context configure service vprn string interface string vpls string egress
Treeegress
Introduced16.0.R1

Platforms

All

routed-override-filter
Synopsis Enter the routed-override-filter context
Contextconfigure service vprn string interface string vpls string egress routed-override-filter
Treerouted-override-filter
Introduced16.0.R1

Platforms

All

evpn
Synopsis Enter the evpn context
Context configure service vprn string interface string vpls string evpn
Treeevpn
Introduced19.10.R1

Platforms

All

arp
Synopsis Enter the arp context
Context configure service vprn string interface string vpls string evpn arp
Treearp
Introduced19.10.R1

Platforms

All

advertise [route-type] keyword
Synopsis Enter the advertise list instance
Contextconfigure service vprn string interface string vpls string evpn arp advertise keyword
Treeadvertise

Description

Commands in this context specify the configuration to allow ARP or ND entries that are installed in the ARP or ND cache to be advertised in EVPN MAC/IP routes.

The learn-dynamic command must be set to false when using this functionality.

Introduced19.10.R1

Platforms

All

[route-type] keyword
Synopsis Type of ARP or ND entries that generate host routes
Contextconfigure service vprn string interface string vpls string evpn arp advertise keyword
Treeadvertise

Description

This command specifies the type of ARP or ND entries that are installed in the ARP or ND cache into EVPN MAC/IP routes.

Optionsstatic, dynamic

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

route-tag number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTag value used with the host route from an ARP/ND entry
Contextconfigure service vprn string interface string vpls string evpn arp advertise keyword route-tag number
Treeroute-tag

Description

This command specifies the route tag that is added separately to dynamic or static ARP or ND entries that are advertised in EVPN MAC/IP routes. This tag can be matched on BGP vsi-export (in the R-VPLS) and BGP peer export policies. 

Range0 to 255
Introduced19.10.R1

Platforms

All

flood-garp-and-unknown-req boolean
Synopsis Allow CPM originated ARP frames to flood R-VPLS service
Contextconfigure service vprn string interface string vpls string evpn arp flood-garp-and-unknown-req boolean
Treeflood-garp-and-unknown-req

Description

When configured to true, the system allows CPM-originated ARP frames to be flooded in the R-VPLS service. Any frames that are data path flooded such as the ARP messages received on a SAP, are flooded irrespective of this command.

When configured to false, CPM-originated ARP flooding is suppressed.

Defaulttrue
Introduced19.10.R1

Platforms

All

learn-dynamic boolean
Synopsis Process ARP or ND messages on EVPN tunnels
Contextconfigure service vprn string interface string vpls string evpn arp learn-dynamic boolean
Treelearn-dynamic

Description

When configured to true, the system processes ARP or ND messages that arrive on EVPN tunnels.

When configured to false, learning is disabled and table entries are not created for these messages.

Defaulttrue
Introduced19.10.R1

Platforms

All

nd
Synopsis Enter the nd context
Context configure service vprn string interface string vpls string evpn nd
Treend
Introduced20.5.R1

Platforms

All

advertise [route-type] keyword
Synopsis Enter the advertise list instance
Contextconfigure service vprn string interface string vpls string evpn nd advertise keyword
Treeadvertise

Description

Commands in this context specify the configuration to allow ARP or ND entries that are installed in the ARP or ND cache to be advertised in EVPN MAC/IP routes.

The learn-dynamic command must be set to false when using this functionality.

Introduced20.5.R1

Platforms

All

[route-type] keyword
Synopsis Type of ARP or ND entries that generate host routes
Contextconfigure service vprn string interface string vpls string evpn nd advertise keyword
Treeadvertise

Description

This command specifies the type of ARP or ND entries that are installed in the ARP or ND cache into EVPN MAC/IP routes.

Optionsstatic, dynamic

Notes

This element is part of a list key.

Introduced20.5.R1

Platforms

All

route-tag number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTag value used with the host route from an ARP/ND entry
Contextconfigure service vprn string interface string vpls string evpn nd advertise keyword route-tag number
Treeroute-tag

Description

This command specifies the route tag that is added separately to dynamic or static ARP or ND entries that are advertised in EVPN MAC/IP routes. This tag can be matched on BGP vsi-export (in the R-VPLS) and BGP peer export policies. 

Range0 to 255
Introduced20.5.R1

Platforms

All

learn-dynamic boolean
Synopsis Process ARP or ND messages on EVPN tunnels
Contextconfigure service vprn string interface string vpls string evpn nd learn-dynamic boolean
Treelearn-dynamic

Description

When configured to true, the system processes ARP or ND messages that arrive on EVPN tunnels.

When configured to false, learning is disabled and table entries are not created for these messages.

Defaulttrue
Introduced20.5.R1

Platforms

All

evpn-tunnel
Synopsis Enable the evpn-tunnel context
Contextconfigure service vprn string interface string vpls string evpn-tunnel
Treeevpn-tunnel
Introduced16.0.R1

Platforms

All

supplementary-broadcast-domain boolean
Synopsis Use the EVPN tunnel as a Supplementary Broadcast Domain
Contextconfigure service vprn string interface string vpls string evpn-tunnel supplementary-broadcast-domain boolean
Treesupplementary-broadcast-domain

Description

When configured to true, this command allows the EVPN tunnel to be used as a Supplementary Broadcast Domain (SBD). The SBD is used in EVPN OISM to advertise the SMET routes and to receive the multicast traffic on egress PEs that are not attached to the source R-VPLS service.

When configured to false, this command disables EVPN tunnel use as an SBD.

Defaultfalse
Introduced19.10.R1

Platforms

All

ingress
Synopsis Enter the ingress context
Context configure service vprn string interface string vpls string ingress
Treeingress
Introduced16.0.R1

Platforms

All

routed-override-filter
Synopsis Enter the routed-override-filter context
Contextconfigure service vprn string interface string vpls string ingress routed-override-filter
Treerouted-override-filter
Introduced16.0.R1

Platforms

All

ip-mirror-interface [interface-name] string
Synopsis Enter the ip-mirror-interface list instance
Contextconfigure service vprn string ip-mirror-interface string
Treeip-mirror-interface
Introduced16.0.R1

Platforms

All

spoke-sdp [sdp-bind-id] string
Synopsis Enter the spoke-sdp list instance
Contextconfigure service vprn string ip-mirror-interface string spoke-sdp string
Treespoke-sdp
Max. Instances1
Introduced16.0.R1

Platforms

All

ingress
Synopsis Enter the ingress context
Context configure service vprn string ip-mirror-interface string spoke-sdp string ingress
Treeingress
Introduced16.0.R1

Platforms

All

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSpoke SDP ingress VC label
Contextconfigure service vprn string ip-mirror-interface string spoke-sdp string ingress vc-label number
Treevc-label
Range1 to 1048575
Introduced16.0.R1

Platforms

All

ipsec
Synopsis Enter the ipsec context
Context configure service vprn string ipsec
Treeipsec
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

allow-reverse-route-override-type keyword
Synopsis System behavior for new reverse route
Contextconfigure service vprn string ipsec allow-reverse-route-override-type keyword
Treeallow-reverse-route-override-type

Description

This command specifies the system behavior when a new reverse route overlaps with an existing reverse route.

When unconfigured, the system does not allow a new dynamic LAN-to-LAN tunnel that terminates in the private VPRN service to be created with an overlapping reverse route.

Optionssame-idi, any-idi
Introduced 20.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

multi-chassis-shunt-interface [name] reference
Synopsis Enter the multi-chassis-shunt-interface list instance
Contextconfigure service vprn string ipsec multi-chassis-shunt-interface reference
Treemulti-chassis-shunt-interface
Introduced22.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

next-hop
Synopsis Enter the next-hop context
Context configure service vprn string ipsec multi-chassis-shunt-interface reference next-hop
Treenext-hop

Description

Commands in this context configure the next hop for shunting over the interface.

Introduced22.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Next hop address for the shunting interface
Contextconfigure service vprn string ipsec multi-chassis-shunt-interface reference next-hop address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeaddress
Introduced22.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

multi-chassis-shunting-profile [name] string
Synopsis Enter the multi-chassis-shunting-profile list instance
Contextconfigure service vprn string ipsec multi-chassis-shunting-profile string
Treemulti-chassis-shunting-profile
Max. Instances64
Introduced22.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

peer [ip-address] reference
Synopsis Enter the peer list instance
Context configure service vprn string ipsec multi-chassis-shunting-profile string peer reference
Treepeer
Max. Instances3
Introduced22.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

security-policy [id] number
Synopsis Enter the security-policy list instance
Contextconfigure service vprn string ipsec security-policy number
Treesecurity-policy
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[id] number
Synopsis IPsec security policy ID
Context configure service vprn string ipsec security-policy number
Treesecurity-policy
Range1 to 32768

Notes

This element is part of a list key.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure service vprn string ipsec security-policy number entry number
Treeentry
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[entry-id] number
Synopsis IPsec security policy entry ID
Context configure service vprn string ipsec security-policy number entry number
Treeentry
Range1 to 16

Notes

This element is part of a list key.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

local-ip
Synopsis Enter the local-ip context
Context configure service vprn string ipsec security-policy number entry number local-ip
Treelocal-ip

Description

Commands in this context configure the local (from the VPN) IPv4 prefix/mask for the policy entry.

The system evaluates the local IP as the source IP when traffic is examined in the direction of the flows from private to public and as the destination IP when traffic flows from public to private.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

address string
Synopsis Destination IPv4 address of the aggregate route
Contextconfigure service vprn string ipsec security-policy number entry number local-ip address string
Treeaddress

Notes

The following elements are part of a choice: address or any.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

any boolean
Synopsis Use any IP address
Context configure service vprn string ipsec security-policy number entry number local-ip any boolean
Treeany
Defaultfalse

Notes

The following elements are part of a choice: address or any.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

local-ipv6
Synopsis Enter the local-ipv6 context
Context configure service vprn string ipsec security-policy number entry number local-ipv6
Treelocal-ipv6

Description

Commands in this context configure the local (from the VPN) IPv6 prefix/mask for the policy entry.

The system evaluates the local IP as the source IP when traffic is examined in the direction of the flows from private to public and as the destination IP when traffic flows from public to private.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

address string
Synopsis Destination IPv6 address of the aggregate route
Contextconfigure service vprn string ipsec security-policy number entry number local-ipv6 address string
Treeaddress

Notes

The following elements are part of a choice: address or any.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

any boolean
Synopsis Use any IP address
Context configure service vprn string ipsec security-policy number entry number local-ipv6 any boolean
Treeany
Defaultfalse

Notes

The following elements are part of a choice: address or any.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

remote-ip
Synopsis Enter the remote-ip context
Context configure service vprn string ipsec security-policy number entry number remote-ip
Treeremote-ip

Description

Commands in this context configure the remote (from the tunnel) IP prefix/mask for the policy entry.

The system evaluates the remote IP as the source IP when traffic flows public to private and as the destination IP when traffic flows from private to public.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

address string
Synopsis Destination IPv4 address of the aggregate route
Contextconfigure service vprn string ipsec security-policy number entry number remote-ip address string
Treeaddress

Notes

The following elements are part of a choice: address or any.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

any boolean
Synopsis Use any IP address
Context configure service vprn string ipsec security-policy number entry number remote-ip any boolean
Treeany
Defaultfalse

Notes

The following elements are part of a choice: address or any.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

remote-ipv6
Synopsis Enter the remote-ipv6 context
Context configure service vprn string ipsec security-policy number entry number remote-ipv6
Treeremote-ipv6

Description

Commands in this context configure the remote (from the tunnel) IPv6 prefix/mask for the policy entry.

The system evaluates the remote IP as the source IP when traffic flows from public to private and as the destination IP when traffic flows from private to public.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

address string
Synopsis Destination IPv6 address of the aggregate route
Contextconfigure service vprn string ipsec security-policy number entry number remote-ipv6 address string
Treeaddress

Notes

The following elements are part of a choice: address or any.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

any boolean
Synopsis Use any IP address
Context configure service vprn string ipsec security-policy number entry number remote-ipv6 any boolean
Treeany
Defaultfalse

Notes

The following elements are part of a choice: address or any.

Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ipv6
Synopsis Enter the ipv6 context
Context configure service vprn string ipv6
Treeipv6
Introduced16.0.R1

Platforms

All

neighbor-discovery
Synopsis Enter the neighbor-discovery context
Contextconfigure service vprn string ipv6 neighbor-discovery
Treeneighbor-discovery
Introduced16.0.R1

Platforms

All

router-advertisement
Synopsis Enter the router-advertisement context
Contextconfigure service vprn string ipv6 router-advertisement
Treerouter-advertisement
Introduced16.0.R1

Platforms

All

dns-options
Synopsis Enable the dns-options context
Contextconfigure service vprn string ipv6 router-advertisement dns-options
Treedns-options
Introduced16.0.R1

Platforms

All

rdnss-lifetime (keyword | number)
Synopsis Maximum time over which the RDNSS address is valid
Contextconfigure service vprn string ipv6 router-advertisement dns-options rdnss-lifetime (keyword | number)
Treerdnss-lifetime

Description

This command specifies the maximum time that the RDNSS address is used for name resolution by the client.

Range0 | 4 to 3600
Unitsseconds
Options infinite
Defaultinfinite
Introduced 16.0.R1

Platforms

All

interface [ip-int-name] reference
Synopsis Enter the interface list instance
Contextconfigure service vprn string ipv6 router-advertisement interface reference
Treeinterface
Introduced16.0.R1

Platforms

All

dns-options
Synopsis Enable the dns-options context
Contextconfigure service vprn string ipv6 router-advertisement interface reference dns-options
Treedns-options
Introduced16.0.R1

Platforms

All

nd-router-preference keyword
Synopsis Default router preference for Router Advertisements
Contextconfigure service vprn string ipv6 router-advertisement interface reference nd-router-preference keyword
Treend-router-preference

Description

This command configures the default router preference for Router Advertisements (RAs) and allows IPv6 hosts to discover and select a default gateway address by listening to RAs.

This feature provides basic traffic engineering functionality for host devices. When this command is applied, the router advertises the respective router preference to the connected host to assist in its selection of the most appropriate default gateway on a link.

This extension is backward compatible, both for routers (setting the router preference bits) and hosts (interpreting the router preference bits). These bits are ignored by hosts that do not implement the RFC 4191 functionality by configuring this command. Similarly, hosts that do not implement the RFC 4191 functionality interpret the values sent by devices that do not implement the RFC 4191 extension as a medium preference.

Optionsmedium, high, low
Defaultmedium
Introduced23.10.R1

Platforms

All

prefix [ipv6-prefix] string
Synopsis Enter the prefix list instance
Contextconfigure service vprn string ipv6 router-advertisement interface reference prefix string
Treeprefix
Max. Instances254
Introduced16.0.R1

Platforms

All

isis [isis-instance] number
Synopsis Enter the isis list instance
Context configure service vprn string isis number
Treeisis
Introduced16.0.R1

Platforms

All

[isis-instance] number
Synopsis Instance ID for the IS-IS instance
Context configure service vprn string isis number
Treeisis
Range0 to 127
MD-CLI Default0

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the IS-IS instance
Contextconfigure service vprn string isis number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

all-l1isis string
Synopsis Destination MAC address for all L1 IS-IS routers
Contextconfigure service vprn string isis number all-l1isis string
Treeall-l1isis
Default01:80:C2:00:00:14
Introduced16.0.R1

Platforms

All

all-l2isis string
Synopsis Destination MAC address for all L2 IS-IS routers
Contextconfigure service vprn string isis number all-l2isis string
Treeall-l2isis
Default01:80:C2:00:00:15
Introduced16.0.R1

Platforms

All

area-address string
Synopsis Area address portion of the NSAP address
Contextconfigure service vprn string isis number area-address string
Treearea-address
String Length2 to 38
Max. Instances3
Introduced16.0.R1

Platforms

All

export-limit
Synopsis Enable the export-limit context
Contextconfigure service vprn string isis number export-limit
Treeexport-limit
Introduced16.0.R1

Platforms

All

number number
Synopsis Maximum routes or prefixes exported from route table
Contextconfigure service vprn string isis number export-limit number number
Treenumber
Range1 to 4294967295

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

export-policy reference
Synopsis Export policies that determine exported routes
Contextconfigure service vprn string isis number export-policy reference
Treeexport-policy

Description

This command configures export routing policies for the routes exported from the routing table to IS-IS.

If the export policy is undefined, the system does not export non IS-IS routes from the routing table manager to IS-IS.

If multiple policy names are specified, the policies are evaluated in the order they are specified. The first policy that matches is applied.

If the aggregate command is also configured in the configure router context, the aggregation is applied before the export policy is applied.

Routing policies are created in the configure router policy-options context.

Reference

configure policy-options policy-statement string

Max. Instances5

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

All

hello-padding keyword
Synopsis IS-IS Hello message padding
Context configure service vprn string isis number hello-padding keyword
Treehello-padding
Optionsadaptive, loose, strict, none
Introduced 16.0.R1

Platforms

All

iid-tlv boolean
Synopsis Use IID TLVs with IS-IS multi-instance
Contextconfigure service vprn string isis number iid-tlv boolean
Treeiid-tlv
Defaultfalse
Introduced16.0.R1

Platforms

All

interface [interface-name] string
Synopsis Enter the interface list instance
Contextconfigure service vprn string isis number interface string
Treeinterface
Introduced16.0.R1

Platforms

All

[interface-name] string
Synopsis IP interface name
Context configure service vprn string isis number interface string
Treeinterface
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the IS-IS interface
Contextconfigure service vprn string isis number interface string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

bfd-liveness
Synopsis Enter the bfd-liveness context
Contextconfigure service vprn string isis number interface string bfd-liveness
Treebfd-liveness

Description

Commands in this context enable the use of bidirectional forwarding (BFD) to control IPv4 and IPv6 adjacencies. Enabling BFD on an IPv4 or IPv6 protocol interface ties the protocol interface state to the BFD session state between the local and remote nodes. BFD must be enabled on the applicable IP interface.

Introduced16.0.R1

Platforms

All

csnp-interval number
Synopsis Time interval between successive CSN PDUs sent
Contextconfigure service vprn string isis number interface string csnp-interval number
Treecsnp-interval
Range1 to 65535
Unitsseconds
Default 10
Introduced16.0.R1

Platforms

All

interface-type keyword
Synopsis Interface type to broadcast, point-to-point, or to be default
Contextconfigure service vprn string isis number interface string interface-type keyword
Treeinterface-type
Optionspoint-to-point, broadcast
Introduced 16.0.R1

Platforms

All

level [level-number] keyword
Synopsis Enter the level list instance
Context configure service vprn string isis number interface string level keyword
Treelevel
Max. Instances2
Introduced16.0.R1

Platforms

All

[level-number] keyword
Synopsis ISIS protocol level number
Context configure service vprn string isis number interface string level keyword
Treelevel
Options1, 2

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

hello-authentication-key string
Synopsis Authentication key for Hello PDUs
Context configure service vprn string isis number interface string level keyword hello-authentication-key string
Treehello-authentication-key

Description

This command configures the authentication key (password) for Hello PDUs. Both the Hello authentication key and the Hello authentication type on a segment must match.

If both IS-IS and Hello authentication are configured, Hello messages are validated using Hello authentication. If only IS-IS authentication is configured, it is used to authenticate all IS-IS (including Hello) protocol PDUs.

String Length1 to 366
Introduced16.0.R1

Platforms

All

hello-authentication-type keyword
Synopsis Hello authentication enabled on the context
Contextconfigure service vprn string isis number interface string level keyword hello-authentication-type keyword
Treehello-authentication-type

Description

This command enables Hello authentication at the level context. Both the Hello authentication key and the Hello authentication type on a segment must match. The Hello authentication-key statement must also be included.

Optionspassword, message-digest
Introduced16.0.R1

Platforms

All

metric number
Synopsis IS-IS interface metric applied for IPv4 unicast
Contextconfigure service vprn string isis number interface string level keyword metric number
Treemetric
Range1 to 16777215
Introduced16.0.R1

Platforms

All

priority number
Synopsis Router to become the designated router on a multi-access network
Contextconfigure service vprn string isis number interface string level keyword priority number
Treepriority
Range0 to 127
Default64
Introduced 16.0.R1

Platforms

All

loopfree-alternate
Synopsis Enter the loopfree-alternate context
Contextconfigure service vprn string isis number interface string loopfree-alternate
Treeloopfree-alternate
Introduced16.0.R3

Platforms

All

policy-map
Synopsis Enable the policy-map context
Context configure service vprn string isis number interface string loopfree-alternate policy-map
Treepolicy-map
Introduced16.0.R3

Platforms

All

mesh-group
Synopsis Enable the mesh-group context
Context configure service vprn string isis number interface string mesh-group
Treemesh-group
Introduced16.0.R1

Platforms

All

blocked
Synopsis Prevent the interface from flooding LSPs
Contextconfigure service vprn string isis number interface string mesh-group blocked
Treeblocked

Notes

The following elements are part of a choice: blocked or value.

Introduced16.0.R1

Platforms

All

value number
Synopsis Mesh group for the interface
Context configure service vprn string isis number interface string mesh-group value number
Treevalue
Range1 to 2000000000

Notes

The following elements are part of a choice: blocked or value.

Introduced16.0.R1

Platforms

All

tag number
Synopsis Route tag for IP address of interface
Contextconfigure service vprn string isis number interface string tag number
Treetag
Range1 to 4294967295
Introduced16.0.R1

Platforms

All

ipv4-routing boolean
Synopsis Support IPv4 routing for IS-IS instance
Contextconfigure service vprn string isis number ipv4-routing boolean
Treeipv4-routing
Defaulttrue
Introduced16.0.R1

Platforms

All

ipv6-routing keyword
Synopsis Routing topology for IPv6
Context configure service vprn string isis number ipv6-routing keyword
Treeipv6-routing
Optionsfalse, native, mt
Defaultfalse
Introduced16.0.R1

Platforms

All

level [level-number] keyword
Synopsis Enter the level list instance
Context configure service vprn string isis number level keyword
Treelevel
Max. Instances2
Introduced16.0.R1

Platforms

All

[level-number] keyword
Synopsis ISIS protocol level number
Context configure service vprn string isis number level keyword
Treelevel
Options1, 2

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

authentication-key string
Synopsis Authentication key to verify PDUs sent on the interface
Contextconfigure service vprn string isis number level keyword authentication-key string
Treeauthentication-key

Description

This command sets the authentication key used to verify PDUs sent by neighboring routers on the interface.

Neighboring routers use passwords to authenticate PDUs sent from an interface. For authentication to work, both the authentication key and the authentication type on a segment must match. The authentication-type command must also be included.

String Length1 to 366
Introduced16.0.R1

Platforms

All

hello-padding keyword
Synopsis Padding on IS-IS Hello packets
Context configure service vprn string isis number level keyword hello-padding keyword
Treehello-padding
Optionsadaptive, loose, strict, none
Introduced 16.0.R1

Platforms

All

lsp-mtu-size number
WARNING:

Modifying this element requires the admin-state of the parent element to be toggled manually for the new value to take effect.

SynopsisLSP MTU size
Contextconfigure service vprn string isis number level keyword lsp-mtu-size number
Treelsp-mtu-size
Range490 to 9778
Unitsbytes
Default 1492
Introduced16.0.R1

Platforms

All

preference number
Synopsis External route preference at level
Context configure service vprn string isis number level keyword preference number
Treepreference
Range1 to 255
Introduced16.0.R1

Platforms

All

link-group [link-group-name] string
Synopsis Enter the link-group list instance
Contextconfigure service vprn string isis number link-group string
Treelink-group
Introduced16.0.R1

Platforms

All

[link-group-name] string
Synopsis Link group name for the IS-IS protocol
Contextconfigure service vprn string isis number link-group string
Treelink-group
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

level [level-number] keyword
Synopsis Enter the level list instance
Context configure service vprn string isis number link-group string level keyword
Treelevel
Max. Instances2
Introduced16.0.R1

Platforms

All

[level-number] keyword
Synopsis ISIS protocol level number
Context configure service vprn string isis number link-group string level keyword
Treelevel
Options1, 2

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

member [interface-name] reference
Synopsis Add a list entry for member
Context configure service vprn string isis number link-group string level keyword member reference
Treemember
Max. Instances8
Introduced16.0.R1

Platforms

All

[interface-name] reference
Synopsis Interface name for the associated link group
Contextconfigure service vprn string isis number link-group string level keyword member reference
Treemember

Reference

configure service vprn string isis number interface string

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

loopfree-alternate
Synopsis Enable the loopfree-alternate context
Contextconfigure service vprn string isis number loopfree-alternate
Treeloopfree-alternate
Introduced16.0.R1

Platforms

All

exclude
Synopsis Enter the exclude context
Context configure service vprn string isis number loopfree-alternate exclude
Treeexclude
Introduced16.0.R3

Platforms

All

prefix-policy reference
Synopsis Policy to exclude prefixes from LFA SPF calculation
Contextconfigure service vprn string isis number loopfree-alternate exclude prefix-policy reference
Treeprefix-policy

Description

This command specifies the name of the policy for the prefixes to exclude from the LFA SPF calculation.

An excluded prefix is not included in LFA calculation regardless of its priority. The prefix tag is, however, used in the main SPF.

Reference

configure policy-options policy-statement string

Max. Instances5

Notes

This element is ordered by the user.

Introduced16.0.R3

Platforms

All

lsp-lifetime number
WARNING:

Modifying this element requires the admin-state of the parent element to be toggled manually for the new value to take effect.

SynopsisAmount of time during which an LSP is considered valid
Contextconfigure service vprn string isis number lsp-lifetime number
Treelsp-lifetime
Range350 to 65535
Unitsseconds
Default 1200
Introduced16.0.R1

Platforms

All

lsp-mtu-size number
WARNING:

Modifying this element requires the admin-state of the parent element to be toggled manually for the new value to take effect.

SynopsisLSP MTU size
Contextconfigure service vprn string isis number lsp-mtu-size number
Treelsp-mtu-size
Range490 to 9778
Unitsbytes
Default 1492
Introduced16.0.R1

Platforms

All

lsp-refresh
Synopsis Enter the lsp-refresh context
Context configure service vprn string isis number lsp-refresh
Treelsp-refresh
Introduced16.0.R1

Platforms

All

interval number
Synopsis Refresh timer interval
Context configure service vprn string isis number lsp-refresh interval number
Treeinterval
Range150 to 65535
Unitsseconds
Default 600
Introduced16.0.R1

Platforms

All

mru-mismatch-detection boolean
Synopsis Enable detection of MRU mismatch
Context configure service vprn string isis number mru-mismatch-detection boolean
Treemru-mismatch-detection

Description

When configured to true, this command verifies that the received IS-IS Hello (IIH) packet size does not exceed the configured maximum port MTU size. The received IIH packet is dropped when its size exceeds the maximum port MTU size.

When configured to false, the IS-IS router instance will not drop oversized IIH packets.

By default, FP-based hardware can receive oversized packets but it will not originate them.

Defaultfalse
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

multi-topology
Synopsis Enable the multi-topology context
Contextconfigure service vprn string isis number multi-topology
Treemulti-topology
Introduced16.0.R1

Platforms

All

overload
Synopsis Enable the overload context
Context configure service vprn string isis number overload
Treeoverload
Introduced16.0.R1

Platforms

All

max-metric boolean
Synopsis Advertise transit links with maximum metric instead of setting overload bit
Contextconfigure service vprn string isis number overload max-metric boolean
Treemax-metric
Defaultfalse
Introduced16.0.R1

Platforms

All

overload-fib-error-notify-only
Synopsis Enable the overload-fib-error-notify-only context
Contextconfigure service vprn string isis number overload-fib-error-notify-only
Treeoverload-fib-error-notify-only

Description

Commands in this context configure the IS-IS router to send a notification when an overload condition occurs while programming the FIB, instead of advertising the overload condition of the router in the IS-IS LSP.

Note: Nokia recommends being careful using this command. When you configure the router not to advertise the IS-IS overload state in the IS-IS LSP, other routers are not instructed to take the overloaded router out of the IS-IS forwarding topology and this will cause suboptimal forwarding and non-deterministic behavior on the overloaded router. To avoid changing the default IS-IS overflow behavior, leave this command disabled.

When this command is configured, the IS-IS router enters a suboptimal state where it sends only a notification trap; transit traffic can still use the router in this state.

The IS-IS router tracks the segment routing prefix SIDs where FIB programming failed. With the retry command configured, the router retries programming the segment routing prefix SIDs in the FIB using this tracked information.

When this command is not configured, during normal operation, the system may force the router to enter an overload state because of a lack of FIB resources. In this state, the router is used to terminate traffic and is not used to transit traffic.

Introduced23.7.R1

Platforms

All

retry number
Synopsis Time to retry programming failed entries in the FIB
Contextconfigure service vprn string isis number overload-fib-error-notify-only retry number
Treeretry

Description

This command configures the time the router uses to retry programming the failed entries in the FIB.

The overload-fib-error-notify-only command must be configured to use the retry timer. The removal of the overload-fib-error-notify-only configuration causes the system to program the failed entries in the FIB by triggering an immediate SPF.

Range10 to 1800
Unitsseconds
Default 10
Introduced23.7.R1

Platforms

All

overload-on-boot
Synopsis Enable the overload-on-boot context
Contextconfigure service vprn string isis number overload-on-boot
Treeoverload-on-boot
Introduced16.0.R1

Platforms

All

timeout number
Synopsis Time during which the router operates in overload state after reboot
Contextconfigure service vprn string isis number overload-on-boot timeout number
Treetimeout
Range60 to 1800
Unitsseconds
Introduced 16.0.R1

Platforms

All

poi-tlv boolean
Synopsis Purge Originator Identification TLV
Context configure service vprn string isis number poi-tlv boolean
Treepoi-tlv
Defaultfalse
Introduced16.0.R1

Platforms

All

prefix-limit
Synopsis Enable the prefix-limit context
Contextconfigure service vprn string isis number prefix-limit
Treeprefix-limit
Introduced16.0.R1

Platforms

All

limit number
Synopsis Maximum number of prefixes for IS-IS instance
Contextconfigure service vprn string isis number prefix-limit limit number
Treelimit
Range1 to 4294967295

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

log-only boolean
Synopsis Send warning message when the prefix limit is reached
Contextconfigure service vprn string isis number prefix-limit log-only boolean
Treelog-only
Defaultfalse
Introduced16.0.R1

Platforms

All

overload-timeout (number | keyword)
Synopsis Time in overload state when prefix limit is reached
Contextconfigure service vprn string isis number prefix-limit overload-timeout (number | keyword)
Treeoverload-timeout
Range1 to 1800
Unitsseconds
Options forever
Defaultforever
Introduced 16.0.R1

Platforms

All

psnp-authentication boolean
Synopsis Authenticate individual IS-IS protocol packets of partial sequence number PDU (PSNP) type
Contextconfigure service vprn string isis number psnp-authentication boolean
Treepsnp-authentication
Defaulttrue
Introduced16.0.R1

Platforms

All

rib-priority
Synopsis Enter the rib-priority context
Contextconfigure service vprn string isis number rib-priority
Treerib-priority
Introduced16.0.R1

Platforms

All

high
Synopsis Enter the high context
Context configure service vprn string isis number rib-priority high
Treehigh
Introduced16.0.R1

Platforms

All

tag number
Synopsis Tag value that is used to match IS-IS routes
Contextconfigure service vprn string isis number rib-priority high tag number
Treetag
Range1 to 4294967295

Notes

The following elements are part of a choice: prefix-list or tag.

Introduced16.0.R1

Platforms

All

router-id string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisUnique router ID for the ISIS instance
Contextconfigure service vprn string isis number router-id string
Treerouter-id
Introduced16.0.R1

Platforms

All

summary-address [ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis Enter the summary-address list instance
Contextconfigure service vprn string isis number summary-address (ipv4-prefix | ipv6-prefix)
Treesummary-address
Introduced16.0.R1

Platforms

All

[ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis IP prefix for the summary address
Context configure service vprn string isis number summary-address (ipv4-prefix | ipv6-prefix)
Treesummary-address

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

route-tag number
Synopsis Route tag assigned to the summary address
Contextconfigure service vprn string isis number summary-address (ipv4-prefix | ipv6-prefix) route-tag number
Treeroute-tag
Range1 to 4294967295
Introduced16.0.R1

Platforms

All

system-id string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSystem ID
Contextconfigure service vprn string isis number system-id string
Treesystem-id
String Length14
Default0000.0000.0000
Introduced 16.0.R1

Platforms

All

timers
Synopsis Enter the timers context
Context configure service vprn string isis number timers
Treetimers
Introduced16.0.R1

Platforms

All

lsp-wait
Synopsis Enter the lsp-wait context
Context configure service vprn string isis number timers lsp-wait
Treelsp-wait
Introduced16.0.R1

Platforms

All

spf-wait
Synopsis Enter the spf-wait context
Context configure service vprn string isis number timers spf-wait
Treespf-wait
Introduced16.0.R1

Platforms

All

spf-max-wait number
Synopsis Maximum interval amid two consecutive SPF calculations
Contextconfigure service vprn string isis number timers spf-wait spf-max-wait number
Treespf-max-wait
Range10 to 120000
Unitsmilliseconds
Default10000
Introduced 16.0.R1

Platforms

All

unicast-import
Synopsis Enter the unicast-import context
Contextconfigure service vprn string isis number unicast-import
Treeunicast-import
Introduced16.0.R1

Platforms

All

ipv4 boolean
Synopsis Submit IPv4 routes into unicast RTM
Context configure service vprn string isis number unicast-import ipv4 boolean
Treeipv4
Defaulttrue
Introduced16.0.R1

Platforms

All

ipv6 boolean
Synopsis Submit IPv6 routes into unicast RTM
Context configure service vprn string isis number unicast-import ipv6 boolean
Treeipv6
Defaulttrue
Introduced16.0.R1

Platforms

All

l2tp
Synopsis Enable the l2tp context
Context configure service vprn string l2tp
Treel2tp
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of L2TP
Context configure service vprn string l2tp admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

avp-hiding keyword
Synopsis Attribute of the Value Pair (AVP) hiding algorithm
Contextconfigure service vprn string l2tp avp-hiding keyword
Treeavp-hiding
Optionssensitive, always
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

challenge boolean
Synopsis Use challenge-response authentication
Contextconfigure service vprn string l2tp challenge boolean
Treechallenge
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

destruct-timeout number
Synopsis Destruction timeout
Context configure service vprn string l2tp destruct-timeout number
Treedestruct-timeout
Range60 to 86400
Unitsseconds
Default 60
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ethernet-tunnel
Synopsis Enter the ethernet-tunnel context
Contextconfigure service vprn string l2tp ethernet-tunnel
Treeethernet-tunnel
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

reconnect-timeout (number | keyword)
Synopsis Timeout for a session setup retry
Context configure service vprn string l2tp ethernet-tunnel reconnect-timeout (number | keyword)
Treereconnect-timeout
Range10 to 3600
Unitsseconds
Options infinite
Defaultinfinite
Introduced 16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

exclude-avps
Synopsis Enter the exclude-avps context
Contextconfigure service vprn string l2tp exclude-avps
Treeexclude-avps
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

failover
Synopsis Enter the failover context
Context configure service vprn string l2tp failover
Treefailover
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

recovery-method keyword
Synopsis Recovery method of the sequence numbers after failover
Contextconfigure service vprn string l2tp failover recovery-method keyword
Treerecovery-method
Optionsmcs, recovery-tunnel
Defaultmcs
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

recovery-time number
Synopsis Time requested from the L2TP peer before assuming failover as failed
Contextconfigure service vprn string l2tp failover recovery-time number
Treerecovery-time
Range0 to 900
Unitsseconds
Default 0
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

track-srrp [id] reference
Synopsis Enter the track-srrp list instance
Contextconfigure service vprn string l2tp failover track-srrp reference
Treetrack-srrp
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

peer reference
Synopsis Multi-chassis peer address
Context configure service vprn string l2tp failover track-srrp reference peer reference
Treepeer

Reference

configure redundancy multi-chassis peer (ipv4-address-no-zone | ipv6-address-no-zone)

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

sync-tag string
Synopsis Synchronization tag on the multi-chassis peer
Contextconfigure service vprn string l2tp failover track-srrp reference sync-tag string
Treesync-tag
String Length1 to 32

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

group [tunnel-group-name] string
Synopsis Enter the group list instance
Context configure service vprn string l2tp group string
Treegroup
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[tunnel-group-name] string
Synopsis Tunnel group name
Context configure service vprn string l2tp group string
Treegroup
String Length1 to 63

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the L2TP tunnel group
Contextconfigure service vprn string l2tp group string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

avp-hiding keyword
Synopsis The AVP hiding algorithm
Context configure service vprn string l2tp group string avp-hiding keyword
Treeavp-hiding
Optionsnever, sensitive, always
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

challenge keyword
Synopsis Enable use of challenge-response authentication
Contextconfigure service vprn string l2tp group string challenge keyword
Treechallenge
Optionsfalse, true
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

description string
Synopsis Text description
Context configure service vprn string l2tp group string description string
Treedescription
String Length1 to 80
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

destruct-timeout number
Synopsis Destruction timeout
Context configure service vprn string l2tp group string destruct-timeout number
Treedestruct-timeout
Range60 to 86400
Unitsseconds
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ethernet-tunnel
Synopsis Enter the ethernet-tunnel context
Contextconfigure service vprn string l2tp group string ethernet-tunnel
Treeethernet-tunnel
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

reconnect-timeout (number | keyword)
Synopsis Timeout for a session setup retry at group level
Contextconfigure service vprn string l2tp group string ethernet-tunnel reconnect-timeout (number | keyword)
Treereconnect-timeout
Range10 to 3600
Unitsseconds
Options infinite
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

failover
Synopsis Enter the failover context
Context configure service vprn string l2tp group string failover
Treefailover
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

recovery-method keyword
Synopsis Recovery method of the sequence numbers after failover
Contextconfigure service vprn string l2tp group string failover recovery-method keyword
Treerecovery-method
Optionsmcs, recovery-tunnel
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

recovery-time number
Synopsis Time requested from the L2TP peer before assuming failover as failed
Contextconfigure service vprn string l2tp group string failover recovery-time number
Treerecovery-time
Range0 to 900
Unitsseconds
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

hello-interval (number | keyword)
Synopsis Hello interval
Contextconfigure service vprn string l2tp group string hello-interval (number | keyword)
Treehello-interval
Range10 to 3600
Unitsseconds
Options infinite
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

idle-timeout (number | keyword)
Synopsis Idle timeout
Contextconfigure service vprn string l2tp group string idle-timeout (number | keyword)
Treeidle-timeout
Range0 to 3600
Unitsseconds
Options infinite
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

l2tpv3
Synopsis Enter the l2tpv3 context
Context configure service vprn string l2tp group string l2tpv3
Treel2tpv3
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

cookie-length (number | keyword)
Synopsis Cookie field length
Context configure service vprn string l2tp group string l2tpv3 cookie-length (number | keyword)
Treecookie-length
Range4 | 8
Optionsdisable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

digest-type keyword
Synopsis Hashing algorithm that calculates the message digest
Contextconfigure service vprn string l2tp group string l2tpv3 digest-type keyword
Treedigest-type
Optionsnone, md5, sha1
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

nonce-length number
Synopsis Length for the local L2TPv3 nonce (random number)
Contextconfigure service vprn string l2tp group string l2tpv3 nonce-length number
Treenonce-length
Range0 | 16 to 64
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

password string
Synopsis L2TPv3 password
Context configure service vprn string l2tp group string l2tpv3 password string
Treepassword
String Length1 to 115
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

private-tcp-mss-adjust (number | keyword)
Synopsis TCP maximum segment size (MSS) on private network
Contextconfigure service vprn string l2tp group string l2tpv3 private-tcp-mss-adjust (number | keyword)
Treeprivate-tcp-mss-adjust
Range512 to 9000
Unitsoctets
Options disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

public-tcp-mss-adjust (number | keyword)
Synopsis TCP Maximum Segment Size (MSS) on public network
Contextconfigure service vprn string l2tp group string l2tpv3 public-tcp-mss-adjust (number | keyword)
Treepublic-tcp-mss-adjust
Range512 to 9000
Unitsoctets
Options disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

pw-cap-list
Synopsis Enter the pw-cap-list context
Context configure service vprn string l2tp group string l2tpv3 pw-cap-list
Treepw-cap-list
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ethernet boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdvertise Ethernet pseudowire type
Contextconfigure service vprn string l2tp group string l2tpv3 pw-cap-list ethernet boolean
Treeethernet
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ethernet-vlan boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAdvertise Ethernet VLAN pseudowire type
Contextconfigure service vprn string l2tp group string l2tpv3 pw-cap-list ethernet-vlan boolean
Treeethernet-vlan
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lac
Synopsis Enter the lac context
Context configure service vprn string l2tp group string lac
Treelac
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

df-bit keyword
Synopsis DF (do not fragment) bit in data traffic transmitted as LAC
Contextconfigure service vprn string l2tp group string lac df-bit keyword
Treedf-bit
Optionsfalse, true
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lns
Synopsis Enter the lns context
Context configure service vprn string l2tp group string lns
Treelns
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mlppp
Synopsis Enter the mlppp context
Context configure service vprn string l2tp group string lns mlppp
Treemlppp
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s

admin-state keyword
Synopsis Administrative state of MLPPP in the L2TP tunnel group
Contextconfigure service vprn string l2tp group string lns mlppp admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s

endpoint
Synopsis Enter the endpoint context
Context configure service vprn string l2tp group string lns mlppp endpoint
Treeendpoint
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s

ip (ipv4-address | keyword)
Synopsis Endpoint ID as an IP address
Context configure service vprn string l2tp group string lns mlppp endpoint ip (ipv4-address | keyword)
Treeip
Optionssystem

Notes

The following elements are part of a choice: ip or mac.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s

mac (mac-address | keyword)
Synopsis Endpoint ID as a MAC address
Context configure service vprn string l2tp group string lns mlppp endpoint mac (mac-address | keyword)
Treemac
Optionssystem

Notes

The following elements are part of a choice: ip or mac.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s

interleave boolean
Synopsis Enable link fragmentation and interleaving
Contextconfigure service vprn string l2tp group string lns mlppp interleave boolean
Treeinterleave
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s

max-fragment-delay (number | keyword)
Synopsis Maximum fragment delay caused by transmission on a link
Contextconfigure service vprn string l2tp group string lns mlppp max-fragment-delay (number | keyword)
Treemax-fragment-delay
Range5 to 1000
Unitsmilliseconds
Options no-fragmentation
Defaultno-fragmentation
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s

max-links number
Synopsis Maximum MLPPP links
Context configure service vprn string l2tp group string lns mlppp max-links number
Treemax-links
Range1 to 8
Default1
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s

ppp
Synopsis Enter the ppp context
Context configure service vprn string l2tp group string lns ppp
Treeppp
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

authentication keyword
Synopsis PPP authentication protocol to negotiate
Contextconfigure service vprn string l2tp group string lns ppp authentication keyword
Treeauthentication
Optionspap, chap, pref-chap, pref-pap
Default pref-chap
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

chap-challenge-length
Synopsis Enter the chap-challenge-length context
Contextconfigure service vprn string l2tp group string lns ppp chap-challenge-length
Treechap-challenge-length
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

end number
Synopsis Upper bound of the PPP CHAP challenge length
Contextconfigure service vprn string l2tp group string lns ppp chap-challenge-length end number
Treeend
Range8 to 64
Unitsoctets
Default 64
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

default-group-interface
Synopsis Enter the default-group-interface context
Contextconfigure service vprn string l2tp group string lns ppp default-group-interface
Treedefault-group-interface
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

keepalive
Synopsis Enter the keepalive context
Context configure service vprn string l2tp group string lns ppp keepalive
Treekeepalive
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

interval number
Synopsis PPP keepalive interval
Context configure service vprn string l2tp group string lns ppp keepalive interval number
Treeinterval
Range10 to 300
Unitsseconds
Default 30
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

lcp-force-ack-accm boolean
Synopsis Force acknowledgement of the LCP Asynchronous Control Character Map (ACCM) option
Contextconfigure service vprn string l2tp group string lns ppp lcp-force-ack-accm boolean
Treelcp-force-ack-accm
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mtu number
Synopsis Maximum PPP MTU size
Context configure service vprn string l2tp group string lns ppp mtu number
Treemtu
Range512 to 9212
Unitsoctets
Default 1500
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

proxy-lcp boolean
Synopsis Proxy LCP AVPs that are received from LAC
Contextconfigure service vprn string l2tp group string lns ppp proxy-lcp boolean
Treeproxy-lcp
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

user-db string
Synopsis Local user database for PPP PAP and CHAP authentication
Contextconfigure service vprn string l2tp group string lns ppp user-db string
Treeuser-db
String Length1 to 32
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

local-name string
Synopsis Local host name used to distinguish tunnels
Contextconfigure service vprn string l2tp group string local-name string
Treelocal-name
String Length1 to 64
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

max-retries-estab number
Synopsis Maximum retries for established tunnels
Contextconfigure service vprn string l2tp group string max-retries-estab number
Treemax-retries-estab
Range2 to 7
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

password string
Synopsis Password between L2TP LAC and LNS
Context configure service vprn string l2tp group string password string
Treepassword
String Length1 to 115
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

protocol keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisProtocol version
Contextconfigure service vprn string l2tp group string protocol keyword
Treeprotocol
Optionsv2, v3, v3draft
Defaultv2
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

session-limit (number | keyword)
Synopsis Session limit
Contextconfigure service vprn string l2tp group string session-limit (number | keyword)
Treesession-limit
Range1 to 250000
Optionsunlimited
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

tunnel [tunnel-name] string
Synopsis Enter the tunnel list instance
Contextconfigure service vprn string l2tp group string tunnel string
Treetunnel
Max. Instances31
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[tunnel-name] string
Synopsis Tunnel name
Contextconfigure service vprn string l2tp group string tunnel string
Treetunnel
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the L2TP tunnel
Contextconfigure service vprn string l2tp group string tunnel string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

auto-establish boolean
Synopsis Allow the tunnel to be automatically set up by the system
Contextconfigure service vprn string l2tp group string tunnel string auto-establish boolean
Treeauto-establish
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

avp-hiding keyword
Synopsis The AVP hiding algorithm
Context configure service vprn string l2tp group string tunnel string avp-hiding keyword
Treeavp-hiding
Optionsnever, sensitive, always
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

challenge keyword
Synopsis Enable use of challenge-response authentication
Contextconfigure service vprn string l2tp group string tunnel string challenge keyword
Treechallenge
Optionsfalse, true
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

description string
Synopsis Text description
Context configure service vprn string l2tp group string tunnel string description string
Treedescription
String Length1 to 80
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

failover
Synopsis Enter the failover context
Context configure service vprn string l2tp group string tunnel string failover
Treefailover
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

recovery-method keyword
Synopsis Recovery method of the sequence numbers after failover
Contextconfigure service vprn string l2tp group string tunnel string failover recovery-method keyword
Treerecovery-method
Optionsmcs, recovery-tunnel
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

recovery-time number
Synopsis Time requested from the L2TP peer before assuming failover as failed
Contextconfigure service vprn string l2tp group string tunnel string failover recovery-time number
Treerecovery-time
Range0 to 900
Unitsseconds
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

hello-interval (number | keyword)
Synopsis Hello interval
Contextconfigure service vprn string l2tp group string tunnel string hello-interval (number | keyword)
Treehello-interval
Range10 to 3600
Unitsseconds
Options infinite
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

idle-timeout (number | keyword)
Synopsis Idle timeout
Contextconfigure service vprn string l2tp group string tunnel string idle-timeout (number | keyword)
Treeidle-timeout
Range0 to 3600
Unitsseconds
Options infinite
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

l2tpv3
Synopsis Enter the l2tpv3 context
Context configure service vprn string l2tp group string tunnel string l2tpv3
Treel2tpv3
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lac
Synopsis Enter the lac context
Context configure service vprn string l2tp group string tunnel string lac
Treelac
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

df-bit keyword
Synopsis DF (do not fragment) bit in data traffic transmitted as LAC
Contextconfigure service vprn string l2tp group string tunnel string lac df-bit keyword
Treedf-bit
Optionsfalse, true
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lns
Synopsis Enter the lns context
Context configure service vprn string l2tp group string tunnel string lns
Treelns
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mlppp
Synopsis Enter the mlppp context
Context configure service vprn string l2tp group string tunnel string lns mlppp
Treemlppp
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s

admin-state keyword
Synopsis Administrative state of MLPPP in the L2TP tunnel
Contextconfigure service vprn string l2tp group string tunnel string lns mlppp admin-state keyword
Treeadmin-state
Optionsenable, disable
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s

endpoint
Synopsis Enter the endpoint context
Context configure service vprn string l2tp group string tunnel string lns mlppp endpoint
Treeendpoint
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s

ip (ipv4-address | keyword)
Synopsis Endpoint ID as an IP address
Context configure service vprn string l2tp group string tunnel string lns mlppp endpoint ip (ipv4-address | keyword)
Treeip
Optionssystem

Notes

The following elements are part of a choice: ip or mac.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s

mac (mac-address | keyword)
Synopsis Endpoint ID as a MAC address
Context configure service vprn string l2tp group string tunnel string lns mlppp endpoint mac (mac-address | keyword)
Treemac
Optionssystem

Notes

The following elements are part of a choice: ip or mac.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s

interleave keyword
Synopsis Use of Link fragmentation and interleaving
Contextconfigure service vprn string l2tp group string tunnel string lns mlppp interleave keyword
Treeinterleave
Optionsfalse, true
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s

ppp
Synopsis Enter the ppp context
Context configure service vprn string l2tp group string tunnel string lns ppp
Treeppp
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

authentication keyword
Synopsis PPP authentication protocol to negotiate
Contextconfigure service vprn string l2tp group string tunnel string lns ppp authentication keyword
Treeauthentication
Optionspap, chap, pref-chap, pref-pap
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

chap-challenge-length
Synopsis Enter the chap-challenge-length context
Contextconfigure service vprn string l2tp group string tunnel string lns ppp chap-challenge-length
Treechap-challenge-length
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

default-group-interface
Synopsis Enter the default-group-interface context
Contextconfigure service vprn string l2tp group string tunnel string lns ppp default-group-interface
Treedefault-group-interface
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

keepalive
Synopsis Enter the keepalive context
Context configure service vprn string l2tp group string tunnel string lns ppp keepalive
Treekeepalive
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mtu number
Synopsis Maximum PPP MTU size
Context configure service vprn string l2tp group string tunnel string lns ppp mtu number
Treemtu
Range512 to 9212
Unitsoctets
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

proxy-lcp keyword
Synopsis Use the Proxy LCP AVPs that are received from the LAC
Contextconfigure service vprn string l2tp group string tunnel string lns ppp proxy-lcp keyword
Treeproxy-lcp
Optionsfalse, true
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

user-db string
Synopsis Local user database for PPP PAP and CHAP authentication
Contextconfigure service vprn string l2tp group string tunnel string lns ppp user-db string
Treeuser-db
String Length1 to 32
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

local-name string
Synopsis Local host name used to distinguish tunnels
Contextconfigure service vprn string l2tp group string tunnel string local-name string
Treelocal-name
String Length1 to 64
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

password string
Synopsis Password between L2TP LAC and LNS
Context configure service vprn string l2tp group string tunnel string password string
Treepassword
String Length1 to 115
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

peer string
Synopsis Peer address
Contextconfigure service vprn string l2tp group string tunnel string peer string
Treepeer
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

preference number
Synopsis Tunnel preference number with its group
Contextconfigure service vprn string l2tp group string tunnel string preference number
Treepreference
Range0 to 16777215
Default50
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

remote-name string
Synopsis Remote tunnel host name
Context configure service vprn string l2tp group string tunnel string remote-name string
Treeremote-name
String Length1 to 64
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

session-limit (number | keyword)
Synopsis L2TP session limit for each tunnel of this router
Contextconfigure service vprn string l2tp group string tunnel string session-limit (number | keyword)
Treesession-limit
Range1 to 65534
Optionsunlimited
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

group-session-limit number
Synopsis L2TP session limit for each group of this router
Contextconfigure service vprn string l2tp group-session-limit number
Treegroup-session-limit
Range1 to 250000
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

hello-interval (number | keyword)
Synopsis Hello interval
Contextconfigure service vprn string l2tp hello-interval (number | keyword)
Treehello-interval
Range10 to 3600
Unitsseconds
Options infinite
Default300
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

idle-timeout (number | keyword)
Synopsis Idle timeout
Contextconfigure service vprn string l2tp idle-timeout (number | keyword)
Treeidle-timeout
Range0 to 3600
Unitsseconds
Options infinite
Defaultinfinite
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

l2tpv3
Synopsis Enter the l2tpv3 context
Context configure service vprn string l2tp l2tpv3
Treel2tpv3
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

digest-type keyword
Synopsis Hashing algorithm that calculates the message digest
Contextconfigure service vprn string l2tp l2tpv3 digest-type keyword
Treedigest-type
Optionsmd5, sha1
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

nonce-length number
Synopsis Length of the local L2TPv3 nonce (random number)
Contextconfigure service vprn string l2tp l2tpv3 nonce-length number
Treenonce-length
Range0 | 16 to 64
Default0
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

password string
Synopsis L2TPv3 password
Context configure service vprn string l2tp l2tpv3 password string
Treepassword
String Length1 to 115
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

transport-type
Synopsis Enter the transport-type context
Contextconfigure service vprn string l2tp l2tpv3 transport-type
Treetransport-type
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ip boolean
Synopsis Use IP as the transport type for the L2TPv3 tunnel
Contextconfigure service vprn string l2tp l2tpv3 transport-type ip boolean
Treeip
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lac
Synopsis Enter the lac context
Context configure service vprn string l2tp lac
Treelac
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

calling-number-format string
Synopsis Calling Number AVP for L2TP control messages
Contextconfigure service vprn string l2tp lac calling-number-format string
Treecalling-number-format
String Length1 to 255
Default%S %s
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

cisco-nas-port
Synopsis Enter the cisco-nas-port context
Contextconfigure service vprn string l2tp lac cisco-nas-port
Treecisco-nas-port
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ethernet string
Synopsis L2TP Cisco NAS port AVP with binary patterns for Ethernet
Contextconfigure service vprn string l2tp lac cisco-nas-port ethernet string
Treeethernet
String Length1 to 255
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

df-bit boolean
Synopsis Send all L2TP packets with DF bit set to 1
Contextconfigure service vprn string l2tp lac df-bit boolean
Treedf-bit
Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

local-address string
Synopsis Local address
Contextconfigure service vprn string l2tp local-address string
Treelocal-address
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

local-name string
Synopsis Local host name
Context configure service vprn string l2tp local-name string
Treelocal-name
String Length1 to 64
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

max-retries-estab number
Synopsis Maximum retries for established tunnels
Contextconfigure service vprn string l2tp max-retries-estab number
Treemax-retries-estab
Range2 to 7
Default5
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

next-attempt keyword
Synopsis Tunnel that is selected when previous session setup failed
Contextconfigure service vprn string l2tp next-attempt keyword
Treenext-attempt
Optionssame-preference-level, next-preference-level
Defaultnext-preference-level
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

password string
Synopsis L2TP password
Contextconfigure service vprn string l2tp password string
Treepassword
String Length1 to 115
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

replace-result-code
Synopsis Enter the replace-result-code context
Contextconfigure service vprn string l2tp replace-result-code
Treereplace-result-code
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

rtm-debounce-time (number | keyword)
Synopsis Debounce timer that declares L2TP action for route table management events
Contextconfigure service vprn string l2tp rtm-debounce-time (number | keyword)
Treertm-debounce-time
Range0 to 5000
Unitsmilliseconds
Options infinite
Defaultinfinite
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

session-assign-method keyword
Synopsis Session assignment method
Context configure service vprn string l2tp session-assign-method keyword
Treesession-assign-method
Optionsexisting-first, weighted, weighted-random
Defaultexisting-first
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

session-limit number
Synopsis L2TP session limit of this router
Context configure service vprn string l2tp session-limit number
Treesession-limit
Range1 to 250000
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

tunnel-selection-blacklist
Synopsis Enter the tunnel-selection-blacklist context
Contextconfigure service vprn string l2tp tunnel-selection-blacklist
Treetunnel-selection-blacklist
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

add-tunnel-on
Synopsis Enter the add-tunnel-on context
Contextconfigure service vprn string l2tp tunnel-selection-blacklist add-tunnel-on
Treeadd-tunnel-on
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

max-time number
Synopsis Time that a tunnel or peer can remain in the denylist
Contextconfigure service vprn string l2tp tunnel-selection-blacklist max-time number
Treemax-time
Range1 to 60
Unitsminutes
Default 5
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

timeout-action keyword
Synopsis Action when a tunnel or peer exceeds time in denylist
Contextconfigure service vprn string l2tp tunnel-selection-blacklist timeout-action keyword
Treetimeout-action
Optionsremove-from-blacklist, try-one-session
Defaultremove-from-blacklist
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

tunnel-session-limit number
Synopsis L2TP session limit for each tunnel of this router
Contextconfigure service vprn string l2tp tunnel-session-limit number
Treetunnel-session-limit
Range1 to 65534
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

label-mode keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAllocation mode for VPRN service labels
Contextconfigure service vprn string label-mode keyword
Treelabel-mode
Optionsvrf, next-hop
Default vrf
Introduced16.0.R1

Platforms

All

local-routes-domain-id string
Synopsis Local routes domain ID
Context configure service vprn string local-routes-domain-id string
Treelocal-routes-domain-id

Description

This command specifies the domain ID that is used in the D-PATH attribute for local routes before those routes are exported to a BGP neighbor using BGP-IPVPN, EVPN-IFF, EVPN-IFL, or PE-CE BGP. A local route is a non-BGP route installed in the VPRN route table and learned using static route or an IGP.

The domain IDs are used in the D-PATH attribute, in accordance with draft-ietf-bess-evpn-ipvpn-interworking. Gateway routers modify the D-PATH attribute. A gateway is a PE where a VPRN is instantiated. The VPRN in this case advertises or receives routes from multiple BGP owners (for example, EVPN IFL and BGP IPVPN).

Gateways use the D-PATH attribute to detect loops (for received routes where the D-PATH contains a local domain ID) and to make BGP best-path selection decisions based on the D-PATH length (shorter D-PATH is preferred).

Introduced21.10.R1

Platforms

All

log
Synopsis Enter the log context
Context configure service vprn string log
Treelog
Introduced16.0.R1

Platforms

All

filter [filter-name] string
Synopsis Enter the filter list instance
Contextconfigure service vprn string log filter string
Treefilter
Max. Instances1500
Introduced16.0.R1

Platforms

All

[filter-name] string
Synopsis Filter ID
Contextconfigure service vprn string log filter string
Treefilter
String Length1 to 64

Notes

This element is part of a list key.

Introduced21.2.R1

Platforms

All

named-entry [entry-name] string
Synopsis Enter the named-entry list instance
Contextconfigure service vprn string log filter string named-entry string
Treenamed-entry

Description

Commands in this context create or edit an event filter entry.

Max. Instances999

Notes

This element is ordered by the user.

Introduced21.2.R1

Platforms

All

[entry-name] string
Synopsis Entry name
Contextconfigure service vprn string log filter string named-entry string
Treenamed-entry
String Length1 to 64

Notes

This element is part of a list key.

Introduced21.2.R1

Platforms

All

match
Synopsis Enter the match context
Context configure service vprn string log filter string named-entry string match
Treematch
Introduced21.2.R1

Platforms

All

application
Synopsis Enter the application context
Context configure service vprn string log filter string named-entry string match application
Treeapplication
Introduced21.2.R1

Platforms

All

eq keyword
Synopsis Application to match
Context configure service vprn string log filter string named-entry string match application eq keyword
Treeeq
Optionsapplication-assurance, aps, bgp, cflowd, chassis, debug, dhcp, dhcps, diameter, dot1x, efm-oam, elmi, ering, eth-cfm, etun, filter, gsmp, igmp, igmp-snooping, ip, ipsec, isis, l2tp, lag, ldp, li, lldp, logger, mcpath, mc-redundancy, mirror, mld, mld-snooping, mpls, msdp, nat, ntp, oam, ospf, pim, pim-snooping, port, pppoe, ptp, rip, route-policy, rsvp, security, snmp, stp, svcmgr, system, user, video, vrrp, vrtr, radius, wpp, wlan-gw, dynsvc, mpls-tp, bfd, python, ripng, openflow, sflow, rpki, pcep, calltrace, satellite, ldap, pppoe-clnt, tls, adp, mgmt-core, macsec, sr-policy, pcap, auto-prov, bier, pfcp, tree-sid, srv6, sr-mpls, anysec

Notes

The following elements are part of a choice: eq or neq.

Introduced21.2.R1

Platforms

All

neq keyword
Synopsis Application to be filtered out
Context configure service vprn string log filter string named-entry string match application neq keyword
Treeneq
Optionsapplication-assurance, aps, bgp, cflowd, chassis, debug, dhcp, dhcps, diameter, dot1x, efm-oam, elmi, ering, eth-cfm, etun, filter, gsmp, igmp, igmp-snooping, ip, ipsec, isis, l2tp, lag, ldp, li, lldp, logger, mcpath, mc-redundancy, mirror, mld, mld-snooping, mpls, msdp, nat, ntp, oam, ospf, pim, pim-snooping, port, pppoe, ptp, rip, route-policy, rsvp, security, snmp, stp, svcmgr, system, user, video, vrrp, vrtr, radius, wpp, wlan-gw, dynsvc, mpls-tp, bfd, python, ripng, openflow, sflow, rpki, pcep, calltrace, satellite, ldap, pppoe-clnt, tls, adp, mgmt-core, macsec, sr-policy, pcap, auto-prov, bier, pfcp, tree-sid, srv6, sr-mpls, anysec

Notes

The following elements are part of a choice: eq or neq.

Introduced21.2.R1

Platforms

All

event
Synopsis Enter the event context
Context configure service vprn string log filter string named-entry string match event
Treeevent
Introduced21.2.R1

Platforms

All

eq number
Synopsis Log event message to match
Context configure service vprn string log filter string named-entry string match event eq number
Treeeq
Range1 to 4294967295

Notes

The following elements are part of a choice: eq, gt, gte, lt, lte, or neq.

Introduced21.2.R1

Platforms

All

gt number
Synopsis Number of the log event to match
Context configure service vprn string log filter string named-entry string match event gt number
Treegt
Range1 to 4294967295

Notes

The following elements are part of a choice: eq, gt, gte, lt, lte, or neq.

Introduced21.2.R1

Platforms

All

gte number
Synopsis Number of the log event to match
Context configure service vprn string log filter string named-entry string match event gte number
Treegte
Range1 to 4294967295

Notes

The following elements are part of a choice: eq, gt, gte, lt, lte, or neq.

Introduced21.2.R1

Platforms

All

lt number
Synopsis Number of the log event to match
Context configure service vprn string log filter string named-entry string match event lt number
Treelt
Range1 to 4294967295

Notes

The following elements are part of a choice: eq, gt, gte, lt, lte, or neq.

Introduced21.2.R1

Platforms

All

lte number
Synopsis Number of the log event to match
Context configure service vprn string log filter string named-entry string match event lte number
Treelte
Range1 to 4294967295

Notes

The following elements are part of a choice: eq, gt, gte, lt, lte, or neq.

Introduced21.2.R1

Platforms

All

neq number
Synopsis Log event message to filter out
Context configure service vprn string log filter string named-entry string match event neq number
Treeneq
Range1 to 4294967295

Notes

The following elements are part of a choice: eq, gt, gte, lt, lte, or neq.

Introduced21.2.R1

Platforms

All

message
Synopsis Enter the message context
Context configure service vprn string log filter string named-entry string match message
Treemessage
Introduced21.2.R1

Platforms

All

eq string
Synopsis Log event message to match
Context configure service vprn string log filter string named-entry string match message eq string
Treeeq
String Length1 to 400

Notes

The following elements are part of a choice: eq or neq.

Introduced21.2.R1

Platforms

All

neq string
Synopsis Log event message to be filtered out
Context configure service vprn string log filter string named-entry string match message neq string
Treeneq
String Length1 to 400

Notes

The following elements are part of a choice: eq or neq.

Introduced21.2.R1

Platforms

All

severity
Synopsis Enter the severity context
Context configure service vprn string log filter string named-entry string match severity
Treeseverity
Introduced21.2.R1

Platforms

All

eq keyword
Synopsis Log event severity level to match
Context configure service vprn string log filter string named-entry string match severity eq keyword
Treeeq
Optionscleared, indeterminate, critical, major, minor, warning

Notes

The following elements are part of a choice: eq, gt, gte, lt, lte, or neq.

Introduced21.2.R1

Platforms

All

gt keyword
Synopsis Log event severity level
Context configure service vprn string log filter string named-entry string match severity gt keyword
Treegt
Optionscleared, indeterminate, critical, major, minor, warning

Notes

The following elements are part of a choice: eq, gt, gte, lt, lte, or neq.

Introduced21.2.R1

Platforms

All

gte keyword
Synopsis Log event severity level
Context configure service vprn string log filter string named-entry string match severity gte keyword
Treegte
Optionscleared, indeterminate, critical, major, minor, warning

Notes

The following elements are part of a choice: eq, gt, gte, lt, lte, or neq.

Introduced21.2.R1

Platforms

All

lt keyword
Synopsis Log event severity level
Context configure service vprn string log filter string named-entry string match severity lt keyword
Treelt
Optionscleared, indeterminate, critical, major, minor, warning

Notes

The following elements are part of a choice: eq, gt, gte, lt, lte, or neq.

Introduced21.2.R1

Platforms

All

lte keyword
Synopsis Log event severity level
Context configure service vprn string log filter string named-entry string match severity lte keyword
Treelte
Optionscleared, indeterminate, critical, major, minor, warning

Notes

The following elements are part of a choice: eq, gt, gte, lt, lte, or neq.

Introduced21.2.R1

Platforms

All

neq keyword
Synopsis Log event severity level to filter out
Contextconfigure service vprn string log filter string named-entry string match severity neq keyword
Treeneq
Optionscleared, indeterminate, critical, major, minor, warning

Notes

The following elements are part of a choice: eq, gt, gte, lt, lte, or neq.

Introduced21.2.R1

Platforms

All

subject
Synopsis Enter the subject context
Context configure service vprn string log filter string named-entry string match subject
Treesubject
Introduced21.2.R1

Platforms

All

eq string
Synopsis Log event subject string to match
Context configure service vprn string log filter string named-entry string match subject eq string
Treeeq
String Length1 to 32

Notes

The following elements are part of a choice: eq or neq.

Introduced21.2.R1

Platforms

All

neq string
Synopsis Log event subject string to filter out
Contextconfigure service vprn string log filter string named-entry string match subject neq string
Treeneq
String Length1 to 32

Notes

The following elements are part of a choice: eq or neq.

Introduced21.2.R1

Platforms

All

log-id [name] string
Synopsis Enter the log-id list instance
Contextconfigure service vprn string log log-id string
Treelog-id
Max. Instances30
Introduced16.0.R1

Platforms

All

[name] string
Synopsis Log ID
Contextconfigure service vprn string log log-id string
Treelog-id
String Length1 to 64

Notes

This element is part of a list key.

Introduced21.2.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the log
Context configure service vprn string log log-id string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

destination
Synopsis Enter the destination context
Context configure service vprn string log log-id string destination
Treedestination
Introduced16.0.R1

Platforms

All

netconf
Synopsis Enable the netconf context
Context configure service vprn string log log-id string destination netconf
Treenetconf

Notes

The following elements are part of a choice: netconf, snmp, or syslog.

Introduced16.0.R1

Platforms

All

max-entries number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNumber of events stored in the NETCONF log
Contextconfigure service vprn string log log-id string destination netconf max-entries number
Treemax-entries
Range50 to 3000
Default100
Introduced 16.0.R1

Platforms

All

snmp
Synopsis Enable the snmp context
Context configure service vprn string log log-id string destination snmp
Treesnmp

Notes

The following elements are part of a choice: netconf, snmp, or syslog.

Introduced16.0.R1

Platforms

All

max-entries number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNumber of events stored in the memory log
Contextconfigure service vprn string log log-id string destination snmp max-entries number
Treemax-entries
Range50 to 3000
Default100
Introduced 16.0.R1

Platforms

All

syslog reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIndex with the information to format event messages sent to a specific SYSLOG collector
Contextconfigure service vprn string log log-id string destination syslog reference
Treesyslog

Reference

configure service vprn string log syslog string

Notes

The following elements are part of a choice: netconf, snmp, or syslog.

Introduced16.0.R1

Platforms

All

source
Synopsis Enter the source context
Context configure service vprn string log log-id string source
Treesource
Introduced16.0.R1

Platforms

All

change boolean
Synopsis Collect log events from the change event stream
Contextconfigure service vprn string log log-id string source change boolean
Treechange
Defaultfalse
Introduced16.0.R1

Platforms

All

debug boolean
Synopsis Collect log events from the debug event stream
Contextconfigure service vprn string log log-id string source debug boolean
Treedebug
Defaultfalse
Introduced19.10.R1

Platforms

All

main boolean
Synopsis Collect log events from the main event stream
Contextconfigure service vprn string log log-id string source main boolean
Treemain
Defaultfalse
Introduced16.0.R1

Platforms

All

security boolean
Synopsis Collect log events from the security event stream
Contextconfigure service vprn string log log-id string source security boolean
Treesecurity
Defaultfalse
Introduced19.10.R1

Platforms

All

time-format keyword
Synopsis Time zone output for file log contents and syslog
Contextconfigure service vprn string log log-id string time-format keyword
Treetime-format
Optionsutc, local
Default utc
Introduced16.0.R1

Platforms

All

snmp-trap-group [log-name] string
Synopsis Enter the snmp-trap-group list instance
Contextconfigure service vprn string log snmp-trap-group string
Treesnmp-trap-group
Introduced16.0.R1

Platforms

All

trap-target [name] string
Synopsis Enter the trap-target list instance
Contextconfigure service vprn string log snmp-trap-group string trap-target string
Treetrap-target
Max. Instances25
Introduced16.0.R1

Platforms

All

address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the trap receiver
Context configure service vprn string log snmp-trap-group string trap-target string address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeaddress

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

port number
Synopsis UDP port number to send messages to this remote SNMP notification collector
Contextconfigure service vprn string log snmp-trap-group string trap-target string port number
Treeport
Range0 | 1 to 65535
Default162
Introduced 16.0.R1

Platforms

All

security-level keyword
Synopsis Security level at which SNMP notification messages are sent to SNMP notification collector
Contextconfigure service vprn string log snmp-trap-group string trap-target string security-level keyword
Treesecurity-level
Optionsno-auth-no-privacy, auth-no-privacy, privacy
Defaultno-auth-no-privacy
Introduced16.0.R1

Platforms

All

version keyword
Synopsis SNMP version to format notification messages sent to this SNMP notification collector
Contextconfigure service vprn string log snmp-trap-group string trap-target string version keyword
Treeversion
Optionssnmpv1, snmpv2c, snmpv3
Defaultsnmpv3
Introduced16.0.R1

Platforms

All

syslog [syslog-name] string
Synopsis Enter the syslog list instance
Contextconfigure service vprn string log syslog string
Treesyslog
Max. Instances30
Introduced16.0.R1

Platforms

All

[syslog-name] string
Synopsis Syslog name
Contextconfigure service vprn string log syslog string
Treesyslog
String Length1 to 64

Notes

This element is part of a list key.

Introduced21.2.R1

Platforms

All

address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the Syslog target host
Context configure service vprn string log syslog string address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeaddress
Introduced16.0.R1

Platforms

All

facility keyword
Synopsis Facility code for messages
Context configure service vprn string log syslog string facility keyword
Treefacility
Optionskernel, user, mail, systemd, auth, syslogd, printer, netnews, uucp, cron, authpriv, ftp, ntp, logaudit, logalert, cron2, local0, local1, local2, local3, local4, local5, local6, local7
Default local7
Introduced16.0.R1

Platforms

All

hostname
Synopsis Enter the hostname context
Context configure service vprn string log syslog string hostname
Treehostname

Description

Commands in this context control how the HOSTNAME field of syslog messages is populated.

If no command option is configured, the HOSTNAME is populated with an IP address.

Introduced23.7.R1

Platforms

All

use-system-name
Synopsis Enable the use-system-name context
Contextconfigure service vprn string log syslog string hostname use-system-name
Treeuse-system-name

Description

Commands in this context configure the system to use the system name configured with the configure system name command as the HOSTNAME field of syslog messages.

Do not use any spaces in the system name if it is used for the syslog HOSTNAME.

Notes

The following elements are part of a choice: use-system-name, use-vprn-name, or value.

Introduced23.7.R1

Platforms

All

use-vprn-name
Synopsis Enable the use-vprn-name context
Contextconfigure service vprn string log syslog string hostname use-vprn-name
Treeuse-vprn-name

Description

Commands in this context configure the system to use the VPRN service name configured with the configure service vprn service-name command as the HOSTNAME field of syslog messages sent in this VPRN.

Do not use any spaces in the VPRN name if it is used for the syslog HOSTNAME.

Notes

The following elements are part of a choice: use-system-name, use-vprn-name, or value.

Introduced23.7.R1

Platforms

All

value string
Synopsis Syslog HOSTNAME field value
Context configure service vprn string log syslog string hostname value string
Treevalue

Description

This command configures a string as the HOSTNAME field of syslog messages.

Do not use any spaces in the string used for the syslog HOSTNAME.

String Length1 to 255

Notes

The following elements are part of a choice: use-system-name, use-vprn-name, or value.

Introduced23.7.R1

Platforms

All

log-prefix (keyword | string)
Synopsis Prefix string to log message sent to target syslog host
Contextconfigure service vprn string log syslog string log-prefix (keyword | string)
Treelog-prefix
String Length1 to 32
Optionsno-prefix
DefaultTMNX
Introduced16.0.R1

Platforms

All

port number
Synopsis Destination port when sending syslog over UDP
Contextconfigure service vprn string log syslog string port number
Treeport
Range0 | 1 to 65535
Default514
Introduced 16.0.R1

Platforms

All

severity keyword
Synopsis Severity level threshold for the syslog message
Contextconfigure service vprn string log syslog string severity keyword
Treeseverity
Optionsemergency, alert, critical, error, warning, notice, info, debug
Default info
Introduced16.0.R1

Platforms

All

tls-client-profile reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisTLS client profile used to encrypt syslog communication
Contextconfigure service vprn string log syslog string tls-client-profile reference
Treetls-client-profile

Description

This command specifies the Transport Layer Security (TLS) client profile used to encrypt syslog communications. When configured, syslog messages are sent using TLS.  

Any change to this command results in a brief interruption of the event log, which may cause the loss of a few syslog messages.

When this command is unconfigured, the syslog messages are sent over UDP.

Reference

configure system security tls client-tls-profile string

Introduced21.10.R1

Platforms

All

management
Synopsis Enable the management context
Context configure service vprn string management
Treemanagement
Introduced16.0.R4

Platforms

All

allow-ftp boolean
Synopsis Allow access to the FTP server
Context configure service vprn string management allow-ftp boolean
Treeallow-ftp

Description

When configured to true, this command allows FTP access to the SR OS router via the VPRN router instance.

When configured to false, this command disallows access to the SR OS FTP server.

Defaultfalse
Introduced16.0.R6

Platforms

All

allow-grpc boolean
Synopsis Allow access to the gRPC server
Context configure service vprn string management allow-grpc boolean
Treeallow-grpc

Description

When configured to true, this command allows access to the gRPC server via the VPRN router instance.

When configured to false, this command disallows gRPC server access.

Defaultfalse
Introduced19.5.R1

Platforms

All

allow-netconf boolean
Synopsis Allow access to the NETCONF server
Context configure service vprn string management allow-netconf boolean
Treeallow-netconf

Description

When configured to true, this command allows NETCONF server access to the SR OS router via the VPRN router instance.

When configured to false, this command disallows access to the NETCONF server.

Defaultfalse
Introduced19.5.R1

Platforms

All

allow-ssh boolean
Synopsis Allow access to the SSH server
Context configure service vprn string management allow-ssh boolean
Treeallow-ssh

Description

When configured to true, this command allows SSH server access to the SR OS router via the VPRN router instance.

When configured to false, this command disallows SSH server access.

Defaultfalse
Introduced16.0.R5

Platforms

All

allow-telnet boolean
Synopsis Allow access to the IPv4 Telnet server
Contextconfigure service vprn string management allow-telnet boolean
Treeallow-telnet

Description

When configured to true, this command allows IPv4 Telnet server access to the SR OS router via the VPRN router instance.

When configured to false, this command disallows access to the IPv4 Telnet server.

Defaultfalse
Introduced16.0.R5

Platforms

All

allow-telnet6 boolean
Synopsis Allow access to the Telnet IPv6 server
Contextconfigure service vprn string management allow-telnet6 boolean
Treeallow-telnet6

Description

When configured to true, this command allows IPv6 Telnet server access to the SR OS router via the VPRN router instance.

When configured to false, this command removes access to the IPv6 Telnet server.

Defaultfalse
Introduced16.0.R5

Platforms

All

maximum-ipv4-routes
Synopsis Enter the maximum-ipv4-routes context
Contextconfigure service vprn string maximum-ipv4-routes
Treemaximum-ipv4-routes
Introduced16.0.R1

Platforms

All

log-only boolean
Synopsis Action when the maximum number of routes, held within a VRF context, is reached
Contextconfigure service vprn string maximum-ipv4-routes log-only boolean
Treelog-only
Defaultfalse
Introduced16.0.R1

Platforms

All

threshold number
Synopsis Mid-level water marker for the number of routes which this VRF holds
Contextconfigure service vprn string maximum-ipv4-routes threshold number
Treethreshold
Range1 to 100
Unitspercent
Introduced 16.0.R1

Platforms

All

value number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of routes that are configured on this virtual router
Contextconfigure service vprn string maximum-ipv4-routes value number
Treevalue
Range1 to 2147483647
Introduced16.0.R1

Platforms

All

maximum-ipv6-routes
Synopsis Enter the maximum-ipv6-routes context
Contextconfigure service vprn string maximum-ipv6-routes
Treemaximum-ipv6-routes
Introduced16.0.R1

Platforms

All

log-only boolean
Synopsis Action when the maximum number of routes, held within a VRF context, is reached
Contextconfigure service vprn string maximum-ipv6-routes log-only boolean
Treelog-only
Defaultfalse
Introduced16.0.R1

Platforms

All

threshold number
Synopsis Mid-level water marker for the number of routes which this VRF holds
Contextconfigure service vprn string maximum-ipv6-routes threshold number
Treethreshold
Range1 to 100
Unitspercent
Introduced 16.0.R1

Platforms

All

value number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of routes that are configured on this virtual router
Contextconfigure service vprn string maximum-ipv6-routes value number
Treevalue
Range1 to 2147483647
Introduced16.0.R1

Platforms

All

mc-maximum-routes
Synopsis Enter the mc-maximum-routes context
Contextconfigure service vprn string mc-maximum-routes
Treemc-maximum-routes
Introduced16.0.R1

Platforms

All

value number
Synopsis Maximum multicast routes configured on virtual router
Contextconfigure service vprn string mc-maximum-routes value number
Treevalue
Range1 to 2147483647
Introduced16.0.R1

Platforms

All

mld
Synopsis Enable the mld context
Context configure service vprn string mld
Treemld
Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of MLD
Context configure service vprn string mld admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

forwarding-group-interface forwarding-service string group-interface-name reference
Synopsis Enter the forwarding-group-interface list instance
Contextconfigure service vprn string mld forwarding-group-interface forwarding-service string group-interface-name reference
Treeforwarding-group-interface
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

maximum-number-group-sources number
Synopsis Maximum number of group sources for this interface
Contextconfigure service vprn string mld forwarding-group-interface forwarding-service string group-interface-name reference maximum-number-group-sources number
Treemaximum-number-group-sources

Description

This command configures the maximum number of group sources for which IGMP or MLD can have local receiver information based on received IGMP or MLD reports on this interface. When this configuration is changed dynamically to a lower value than the currently accepted number of group sources, the group sources that are already accepted are not deleted. Only new group sources are not allowed.

Range1 to 32000
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

mcac
Synopsis Enter the mcac context
Context configure service vprn string mld forwarding-group-interface forwarding-service string group-interface-name reference mcac
Treemcac
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

bandwidth
Synopsis Enter the bandwidth context
Context configure service vprn string mld forwarding-group-interface forwarding-service string group-interface-name reference mcac bandwidth
Treebandwidth
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

policy reference
Synopsis Multicast CAC policy name
Context configure service vprn string mld forwarding-group-interface forwarding-service string group-interface-name reference mcac policy reference
Treepolicy

Description

This command configures the name of the global channel bandwidth definition policy that is used for (H)MCAC and HQoS adjustment.

Within the scope of HQoS adjustment, the channel definition policy under the group interface is used if redirection is unconfigured. In this case, the HQoS adjustment can be applied to IPoE subscribers in per-SAP replication mode.

If redirection is configured, the channel bandwidth definition policy applied under the Layer 3 redirected interface is in effect.

Hierarchical MCAC (HMCAC) is supported on two levels simultaneously:

  • subscriber level and redirected interface when redirection is configured

  • subscriber level and group-interface level when redirection is unconfigured

In HMCAC, the subscriber is checked against its bandwidth limits first, then against the bandwidth limits of the redirected or group interface. If redirection is configured but the policy is referenced only under the group interface, no admission control is executed (HMCAC or MCAC).

Reference

configure mcac policy string

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

group-interface [group-interface-name] reference
Synopsis Enter the group-interface list instance
Contextconfigure service vprn string mld group-interface reference
Treegroup-interface
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the MLD interface
Contextconfigure service vprn string mld group-interface reference admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

maximum-number-group-sources number
Synopsis Maximum number of group sources for this interface
Contextconfigure service vprn string mld group-interface reference maximum-number-group-sources number
Treemaximum-number-group-sources

Description

This command configures the maximum number of group sources for which IGMP or MLD can have local receiver information based on received IGMP or MLD reports on this interface. When this configuration is changed dynamically to a lower value than the currently accepted number of group sources, the group sources that are already accepted are not deleted. Only new group sources are not allowed.

Range1 to 32000
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

mcac
Synopsis Enter the mcac context
Context configure service vprn string mld group-interface reference mcac
Treemcac
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

bandwidth
Synopsis Enter the bandwidth context
Context configure service vprn string mld group-interface reference mcac bandwidth
Treebandwidth
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

mandatory (number | keyword)
Synopsis Pre-reserved bandwidth for all mandatory channels
Contextconfigure service vprn string mld group-interface reference mcac bandwidth mandatory (number | keyword)
Treemandatory
Range0 to 2147483647
Optionsunlimited
Defaultunlimited
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

total (number | keyword)
Synopsis Maximum allowed bandwidth
Context configure service vprn string mld group-interface reference mcac bandwidth total (number | keyword)
Treetotal
Range0 to 2147483647
Optionsunlimited
Defaultunlimited
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

policy reference
Synopsis Multicast CAC policy name
Context configure service vprn string mld group-interface reference mcac policy reference
Treepolicy

Description

This command configures the name of the global channel bandwidth definition policy that is used for (H)MCAC and HQoS adjustment.

Within the scope of HQoS adjustment, the channel definition policy under the group interface is used if redirection is unconfigured. In this case, the HQoS adjustment can be applied to IPoE subscribers in per-SAP replication mode.

If redirection is configured, the channel bandwidth definition policy applied under the Layer 3 redirected interface is in effect.

Hierarchical MCAC (HMCAC) is supported on two levels simultaneously:

  • subscriber level and redirected interface when redirection is configured

  • subscriber level and group-interface level when redirection is unconfigured

In HMCAC, the subscriber is checked against its bandwidth limits first, then against the bandwidth limits of the redirected or group interface. If redirection is configured but the policy is referenced only under the group interface, no admission control is executed (HMCAC or MCAC).

Reference

configure mcac policy string

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

query-interval number
Synopsis Time between two consecutive host-query messages
Contextconfigure service vprn string mld group-interface reference query-interval number
Treequery-interval
Range2 to 1024
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

version keyword
Synopsis MLD protocol version
Context configure service vprn string mld group-interface reference version keyword
Treeversion
Options1, 2
Default 2
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

interface [ip-interface-name] string
Synopsis Enter the interface list instance
Contextconfigure service vprn string mld interface string
Treeinterface
Introduced16.0.R1

Platforms

All

[ip-interface-name] string
Synopsis IP interface name
Context configure service vprn string mld interface string
Treeinterface
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R2

Platforms

All

admin-state keyword
Synopsis Administrative state of the MLD interface
Contextconfigure service vprn string mld interface string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

maximum-number-group-sources number
Synopsis Maximum number of group sources for this interface
Contextconfigure service vprn string mld interface string maximum-number-group-sources number
Treemaximum-number-group-sources

Description

This command configures the maximum number of group sources for which IGMP or MLD can have local receiver information based on received IGMP or MLD reports on this interface. When this configuration is changed dynamically to a lower value than the currently accepted number of group sources, the group sources that are already accepted are not deleted. Only new group sources are not allowed.

Range1 to 32000
Introduced16.0.R1

Platforms

All

mcac
Synopsis Enter the mcac context
Context configure service vprn string mld interface string mcac
Treemcac
Introduced16.0.R1

Platforms

All

bandwidth
Synopsis Enter the bandwidth context
Context configure service vprn string mld interface string mcac bandwidth
Treebandwidth
Introduced16.0.R1

Platforms

All

mandatory (number | keyword)
Synopsis Pre-reserved bandwidth for all mandatory channels
Contextconfigure service vprn string mld interface string mcac bandwidth mandatory (number | keyword)
Treemandatory
Range0 to 2147483647
Optionsunlimited
Defaultunlimited
Introduced16.0.R1

Platforms

All

total (number | keyword)
Synopsis Maximum allowed bandwidth
Context configure service vprn string mld interface string mcac bandwidth total (number | keyword)
Treetotal
Range0 to 2147483647
Optionsunlimited
Defaultunlimited
Introduced16.0.R1

Platforms

All

mc-constraints
Synopsis Enter the mc-constraints context
Contextconfigure service vprn string mld interface string mcac mc-constraints
Treemc-constraints
Introduced16.0.R1

Platforms

All

level [level-id] number
Synopsis Enter the level list instance
Context configure service vprn string mld interface string mcac mc-constraints level number
Treelevel
Introduced16.0.R1

Platforms

All

number-down [number-lag-port-down] number
Synopsis Enter the number-down list instance
Contextconfigure service vprn string mld interface string mcac mc-constraints number-down number
Treenumber-down
Introduced16.0.R1

Platforms

All

level number
Synopsis Level ID to associate with number of down LAG ports
Contextconfigure service vprn string mld interface string mcac mc-constraints number-down number level number
Treelevel

Description

This command specifies the bandwidth for a given level. Level 1 has the highest priority and level 8 has the lowest priority.

Range1 to 8

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

use-lag-port-weight boolean
Synopsis Use LAG port weight in calculating MCAC constraints
Contextconfigure service vprn string mld interface string mcac mc-constraints use-lag-port-weight boolean
Treeuse-lag-port-weight

Description

When configured to true, port weight is used when determining available bandwidth per level when LAG ports go down or come up. This command is required for proper operation on mixed port-speed LAGs and can also be used for unmixed port-speed LAGs.

Defaultfalse
Introduced16.0.R1

Platforms

All

policy reference
Synopsis Multicast CAC policy name
Context configure service vprn string mld interface string mcac policy reference
Treepolicy

Description

This command configures the name of the global channel bandwidth definition policy that is used for (H)MCAC and HQoS adjustment.

Within the scope of HQoS adjustment, the channel definition policy under the group interface is used if redirection is unconfigured. In this case, the HQoS adjustment can be applied to IPoE subscribers in per-SAP replication mode.

If redirection is configured, the channel bandwidth definition policy applied under the Layer 3 redirected interface is in effect.

Hierarchical MCAC (HMCAC) is supported on two levels simultaneously:

  • subscriber level and redirected interface when redirection is configured

  • subscriber level and group-interface level when redirection is unconfigured

In HMCAC, the subscriber is checked against its bandwidth limits first, then against the bandwidth limits of the redirected or group interface. If redirection is configured but the policy is referenced only under the group interface, no admission control is executed (HMCAC or MCAC).

Reference

configure mcac policy string

Introduced16.0.R1

Platforms

All

ssm-translate
Synopsis Enter the ssm-translate context
Contextconfigure service vprn string mld interface string ssm-translate
Treessm-translate
Introduced16.0.R1

Platforms

All

group-range start string end string
Synopsis Enter the group-range list instance
Contextconfigure service vprn string mld interface string ssm-translate group-range start string end string
Treegroup-range
Introduced16.0.R1

Platforms

All

source [source-address] string
Synopsis Add a list entry for source
Context configure service vprn string mld interface string ssm-translate group-range start string end string source string
Treesource
Min. Instances1
Introduced16.0.R1

Platforms

All

static
Synopsis Enter the static context
Context configure service vprn string mld interface string static
Treestatic
Introduced16.0.R1

Platforms

All

group [group-address] string
Synopsis Enter the group list instance
Context configure service vprn string mld interface string static group string
Treegroup
Introduced16.0.R1

Platforms

All

[group-address] string
Synopsis Group address of multicast channel
Context configure service vprn string mld interface string static group string
Treegroup

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

source [source-address] string
Synopsis Add a list entry for source
Context configure service vprn string mld interface string static group string source string
Treesource

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced16.0.R1

Platforms

All

starg
Synopsis any source address (*,G)
Context configure service vprn string mld interface string static group string starg
Treestarg

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced16.0.R2

Platforms

All

group-range start string end string step string
Synopsis Enter the group-range list instance
Contextconfigure service vprn string mld interface string static group-range start string end string step string
Treegroup-range
Introduced16.0.R1

Platforms

All

source [source-address] string
Synopsis Add a list entry for source
Context configure service vprn string mld interface string static group-range start string end string step string source string
Treesource

Notes

The following elements are part of a mandatory choice: source or starg.

Introduced16.0.R1

Platforms

All

query-interval number
Synopsis Time between two consecutive host-query messages
Contextconfigure service vprn string mld query-interval number
Treequery-interval
Range2 to 1024
Unitsseconds
Default 125
Introduced16.0.R1

Platforms

All

robust-count number
Synopsis Number of retries after expected message loss
Contextconfigure service vprn string mld robust-count number
Treerobust-count
Range2 to 10
Default2
Introduced 16.0.R1

Platforms

All

ssm-translate
Synopsis Enter the ssm-translate context
Contextconfigure service vprn string mld ssm-translate
Treessm-translate
Introduced16.0.R1

Platforms

All

group-range start string end string
Synopsis Enter the group-range list instance
Contextconfigure service vprn string mld ssm-translate group-range start string end string
Treegroup-range
Introduced16.0.R1

Platforms

All

msdp
Synopsis Enable the msdp context
Context configure service vprn string msdp
Treemsdp
Introduced19.10.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of MSDP
Context configure service vprn string msdp admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced19.10.R1

Platforms

All

group [name] string
Synopsis Enter the group list instance
Context configure service vprn string msdp group string
Treegroup
Introduced19.10.R1

Platforms

All

[name] string
Synopsis MSDP group name
Context configure service vprn string msdp group string
Treegroup
String Length1 to 32

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of MSDP
Context configure service vprn string msdp group string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced19.10.R1

Platforms

All

mode keyword
Synopsis Topology of groups of peers
Context configure service vprn string msdp group string mode keyword
Treemode
Optionsstandard, mesh-group
Default standard
Introduced19.10.R1

Platforms

All

peer [ip-address] string
Synopsis Enter the peer list instance
Context configure service vprn string msdp group string peer string
Treepeer
Introduced19.10.R1

Platforms

All

[ip-address] string
Synopsis IP address of the remote MSDP router for peering
Contextconfigure service vprn string msdp group string peer string
Treepeer

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

receive-message-rate
Synopsis Enter the receive-message-rate context
Contextconfigure service vprn string msdp group string peer string receive-message-rate
Treereceive-message-rate
Introduced19.10.R1

Platforms

All

receive-message-rate
Synopsis Enter the receive-message-rate context
Contextconfigure service vprn string msdp group string receive-message-rate
Treereceive-message-rate
Introduced19.10.R1

Platforms

All

peer [ip-address] string
Synopsis Enter the peer list instance
Context configure service vprn string msdp peer string
Treepeer
Introduced19.10.R1

Platforms

All

[ip-address] string
Synopsis IP address of the remote MSDP router for peering
Contextconfigure service vprn string msdp peer string
Treepeer

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of MSDP
Context configure service vprn string msdp peer string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced19.10.R1

Platforms

All

receive-message-rate
Synopsis Enter the receive-message-rate context
Contextconfigure service vprn string msdp peer string receive-message-rate
Treereceive-message-rate
Introduced19.10.R1

Platforms

All

receive-message-rate
Synopsis Enter the receive-message-rate context
Contextconfigure service vprn string msdp receive-message-rate
Treereceive-message-rate
Introduced19.10.R1

Platforms

All

rpf-table keyword
Synopsis Route tables for RPF lookup
Context configure service vprn string msdp rpf-table keyword
Treerpf-table
Optionsrtable-m, rtable-u, both
Defaultrtable-u
Introduced19.10.R1

Platforms

All

source [ip-prefix] string
Synopsis Enter the source list instance
Contextconfigure service vprn string msdp source string
Treesource
Introduced19.10.R1

Platforms

All

[ip-prefix] string
Synopsis Source IP address for accepted active source messages
Contextconfigure service vprn string msdp source string
Treesource

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

mss-adjust
Synopsis Enable the mss-adjust context
Context configure service vprn string mss-adjust
Treemss-adjust
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

nat-group number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNAT group used for TCP-MSS adjustment
Contextconfigure service vprn string mss-adjust nat-group number
Treenat-group
Max. Range0 to 4294967295

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

segment-size number
Synopsis TCP-MSS option value in transmitted TCP SYN requests
Contextconfigure service vprn string mss-adjust segment-size number
Treesegment-size
Range160 to 10240

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mtrace2
Synopsis Enter the mtrace2 context
Context configure service vprn string mtrace2
Treemtrace2
Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of multicast path tracing
Contextconfigure service vprn string mtrace2 admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

udp-port number
Synopsis Destination and listening port for the mtrace2 command
Contextconfigure service vprn string mtrace2 udp-port number
Treeudp-port
Range1024 to 49151
Default5000
Introduced 16.0.R1

Platforms

All

mvpn
Synopsis Enable the mvpn context
Context configure service vprn string mvpn
Treemvpn
Introduced19.5.R1

Platforms

All

auto-discovery
Synopsis Enter the auto-discovery context
Contextconfigure service vprn string mvpn auto-discovery
Treeauto-discovery
Introduced19.5.R1

Platforms

All

type keyword
Synopsis Status of multicast VPN membership auto-discovery
Contextconfigure service vprn string mvpn auto-discovery type keyword
Treetype
Optionsbgp, mdt-safi
Introduced 19.5.R1

Platforms

All

intersite-shared
Synopsis Enter the intersite-shared context
Contextconfigure service vprn string mvpn intersite-shared
Treeintersite-shared

Description

Commands in this context configure whether to use inter-site shared C-trees. Optional parameters allow enabling additional intersite shared functionality. Not specifying an optional parameter when executing the command disables that parameter.

Introduced19.5.R1

Platforms

All

persistent-type5-advertisement boolean
Synopsis Ensure Type-5 S-A routes are generated for MCAST source
Contextconfigure service vprn string mvpn intersite-shared persistent-type5-advertisement boolean
Treepersistent-type5-advertisement

Description

When configured to true, this command removes the MVPN Type-5 “Source Active AD routes” even if receivers are present but the keepalive timer (KAT) has timed out because of no traffic.

Defaultfalse
Introduced19.5.R1

Platforms

All

mdt-type keyword
Synopsis MVPN instance type per PE node
Context configure service vprn string mvpn mdt-type keyword
Treemdt-type
Optionssender-only, receiver-only, sender-receiver
Defaultsender-receiver
Introduced19.5.R1

Platforms

All

provider-tunnel
Synopsis Enter the provider-tunnel context
Contextconfigure service vprn string mvpn provider-tunnel
Treeprovider-tunnel
Introduced19.5.R1

Platforms

All

inclusive
Synopsis Enter the inclusive context
Context configure service vprn string mvpn provider-tunnel inclusive
Treeinclusive
Introduced19.5.R1

Platforms

All

bier
Synopsis Enable the bier context
Context configure service vprn string mvpn provider-tunnel inclusive bier
Treebier

Notes

The following elements are part of a choice: bier, mldp, p2mp-sr, pim, or rsvp.

Introduced19.5.R1

Platforms

All

p2mp-sr
Synopsis Enable the p2mp-sr context
Context configure service vprn string mvpn provider-tunnel inclusive p2mp-sr
Treep2mp-sr

Notes

The following elements are part of a choice: bier, mldp, p2mp-sr, pim, or rsvp.

Introduced21.5.R1

Platforms

All

bfd-leaf boolean
Synopsis Enable unidirectional multipoint BFD on the leaf PE
Contextconfigure service vprn string mvpn provider-tunnel inclusive p2mp-sr bfd-leaf boolean
Treebfd-leaf

Description

When configured to true, this command enables unidirectional multipoint BFD sessions on a receiver (leaf) PE node for upstream fast failure detection over P2MP SR tree LSP.

Defaultfalse
Introduced21.10.R1

Platforms

All

bfd-root
Synopsis Enable the bfd-root context
Context configure service vprn string mvpn provider-tunnel inclusive p2mp-sr bfd-root
Treebfd-root
Introduced21.10.R1

Platforms

All

multiplier number
Synopsis Multiplier for the transmit interval of the BFD session
Contextconfigure service vprn string mvpn provider-tunnel inclusive p2mp-sr bfd-root multiplier number
Treemultiplier

Description

This command configures the multiplier for the transmit interval. The interval and the multiplier are used to calculate the detection time, which is the period of time without receiving BFD packets after which the session failure is determined.

Range1 to 20
Default3
Introduced 21.10.R1

Platforms

All

transmit-interval number
Synopsis Transmit interval of the BFD session
Context configure service vprn string mvpn provider-tunnel inclusive p2mp-sr bfd-root transmit-interval number
Treetransmit-interval

Description

This command configures the transmit interval. The interval and the multiplier are used to calculate the detection time, which is the period of time without receiving BFD packets after which the session failure is determined.

Range10 to 100000

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

All

pim
Synopsis Enable the pim context
Context configure service vprn string mvpn provider-tunnel inclusive pim
Treepim

Notes

The following elements are part of a choice: bier, mldp, p2mp-sr, pim, or rsvp.

Introduced19.5.R1

Platforms

All

rsvp
Synopsis Enable the rsvp context
Context configure service vprn string mvpn provider-tunnel inclusive rsvp
Treersvp

Notes

The following elements are part of a choice: bier, mldp, p2mp-sr, pim, or rsvp.

Introduced19.5.R1

Platforms

All

bfd-root
Synopsis Enable the bfd-root context
Context configure service vprn string mvpn provider-tunnel inclusive rsvp bfd-root
Treebfd-root
Introduced19.5.R1

Platforms

All

umh-rate-monitoring
Synopsis Enter the umh-rate-monitoring context
Contextconfigure service vprn string mvpn provider-tunnel inclusive umh-rate-monitoring
Treeumh-rate-monitoring
Introduced21.5.R1

Platforms

All

selective
Synopsis Enter the selective context
Context configure service vprn string mvpn provider-tunnel selective
Treeselective
Introduced19.5.R1

Platforms

All

bier
Synopsis Enable the bier context
Context configure service vprn string mvpn provider-tunnel selective bier
Treebier

Notes

The following elements are part of a choice: bier, mldp, p2mp-sr, pim, or rsvp.

Introduced19.5.R1

Platforms

All

data-threshold
Synopsis Enter the data-threshold context
Contextconfigure service vprn string mvpn provider-tunnel selective data-threshold
Treedata-threshold
Introduced19.5.R1

Platforms

All

group-prefix [ip-group-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis Enter the group-prefix list instance
Contextconfigure service vprn string mvpn provider-tunnel selective data-threshold group-prefix (ipv4-prefix | ipv6-prefix)
Treegroup-prefix
Introduced19.5.R1

Platforms

All

mldp
Synopsis Enable the mldp context
Context configure service vprn string mvpn provider-tunnel selective mldp
Treemldp

Notes

The following elements are part of a choice: bier, mldp, p2mp-sr, pim, or rsvp.

Introduced19.5.R1

Platforms

All

multistream-spmsi [multistream-id] number
Synopsis Enter the multistream-spmsi list instance
Contextconfigure service vprn string mvpn provider-tunnel selective multistream-spmsi number
Treemultistream-spmsi
Introduced19.5.R1

Platforms

All

group-prefix [ip-group-prefix] (ipv4-prefix | ipv6-prefix) source-prefix (ipv4-prefix | ipv6-prefix)
Synopsis Add a list entry for group-prefix
Contextconfigure service vprn string mvpn provider-tunnel selective multistream-spmsi number group-prefix (ipv4-prefix | ipv6-prefix) source-prefix (ipv4-prefix | ipv6-prefix)
Treegroup-prefix
Introduced19.5.R1

Platforms

All

p2mp-sr
Synopsis Enter the p2mp-sr context
Context configure service vprn string mvpn provider-tunnel selective multistream-spmsi number p2mp-sr
Treep2mp-sr

Notes

The following elements are part of a choice: lsp-template, p2mp-sr, or pim.

Introduced21.5.R1

Platforms

All

pim
Synopsis Enable the pim context
Context configure service vprn string mvpn provider-tunnel selective multistream-spmsi number pim
Treepim

Notes

The following elements are part of a choice: lsp-template, p2mp-sr, or pim.

Introduced19.5.R1

Platforms

All

p2mp-sr
Synopsis Enable the p2mp-sr context
Context configure service vprn string mvpn provider-tunnel selective p2mp-sr
Treep2mp-sr

Notes

The following elements are part of a choice: bier, mldp, p2mp-sr, pim, or rsvp.

Introduced21.5.R1

Platforms

All

pim
Synopsis Enable the pim context
Context configure service vprn string mvpn provider-tunnel selective pim
Treepim

Notes

The following elements are part of a choice: bier, mldp, p2mp-sr, pim, or rsvp.

Introduced19.5.R1

Platforms

All

rsvp
Synopsis Enable the rsvp context
Context configure service vprn string mvpn provider-tunnel selective rsvp
Treersvp

Notes

The following elements are part of a choice: bier, mldp, p2mp-sr, pim, or rsvp.

Introduced19.5.R1

Platforms

All

umh-rate-monitoring
Synopsis Enter the umh-rate-monitoring context
Contextconfigure service vprn string mvpn provider-tunnel selective umh-rate-monitoring
Treeumh-rate-monitoring
Introduced21.5.R1

Platforms

All

group [group-ip-address] (ipv4-prefix | ipv6-prefix) source (ipv4-prefix | ipv6-prefix)
Synopsis Enter the group list instance
Context configure service vprn string mvpn provider-tunnel selective umh-rate-monitoring group (ipv4-prefix | ipv6-prefix) source (ipv4-prefix | ipv6-prefix)
Treegroup
Introduced21.5.R1

Platforms

All

redundant-source-list
Synopsis Enter the redundant-source-list context
Contextconfigure service vprn string mvpn redundant-source-list
Treeredundant-source-list
Introduced19.5.R1

Platforms

All

source-prefix [ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis Add a list entry for source-prefix
Contextconfigure service vprn string mvpn redundant-source-list source-prefix (ipv4-prefix | ipv6-prefix)
Treesource-prefix
Max. Instances16
Introduced19.5.R1

Platforms

All

rpf-select
Synopsis Enter the rpf-select context
Context configure service vprn string mvpn rpf-select
Treerpf-select
Introduced19.5.R1

Platforms

All

core-mvpn [core-mvpn-service-name] reference
Synopsis Enter the core-mvpn list instance
Contextconfigure service vprn string mvpn rpf-select core-mvpn reference
Treecore-mvpn
Introduced19.5.R1

Platforms

All

group-prefix [ip-group-prefix] string
Synopsis Enter the group-prefix list instance
Contextconfigure service vprn string mvpn rpf-select core-mvpn reference group-prefix string
Treegroup-prefix
Min. Instances1
Introduced19.5.R1

Platforms

All

starg boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisStarg flag.
Contextconfigure service vprn string mvpn rpf-select core-mvpn reference group-prefix string starg boolean
Treestarg
Defaultfalse
Introduced19.5.R1

Platforms

All

umh-pe-backup
Synopsis Enter the umh-pe-backup context
Contextconfigure service vprn string mvpn umh-pe-backup
Treeumh-pe-backup
Introduced19.5.R1

Platforms

All

umh-pe [ip-address] string
Synopsis Enter the umh-pe list instance
Contextconfigure service vprn string mvpn umh-pe-backup umh-pe string
Treeumh-pe
Introduced19.5.R1

Platforms

All

[ip-address] string
Synopsis IP address for the standby PE
Context configure service vprn string mvpn umh-pe-backup umh-pe string
Treeumh-pe

Notes

This element is part of a list key.

Introduced19.5.R1

Platforms

All

umh-selection keyword
Synopsis UMH selection mechanism
Context configure service vprn string mvpn umh-selection keyword
Treeumh-selection
Optionshighest-ip, hash-based, tunnel-status, unicast-rt-pref
Defaulthighest-ip
Introduced 19.5.R1

Platforms

All

vrf-export
Synopsis Enter the vrf-export context
Context configure service vprn string mvpn vrf-export
Treevrf-export
Introduced19.5.R1

Platforms

All

policy (policy-expr-string | string)
Synopsis Route policy name
Context configure service vprn string mvpn vrf-export policy (policy-expr-string | string)
Treepolicy

Description

This command specifies the route policy name. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed between double quotes.

String Length1 to 255
Max. Instances15
Min. Instances1

Notes

The following elements are part of a choice: policy or unicast.

This element is ordered by the user.

Introduced 19.5.R1

Platforms

All

unicast boolean
Synopsis Enable the unicast VRF export policy for the MVPN
Contextconfigure service vprn string mvpn vrf-export unicast boolean
Treeunicast
Defaultfalse

Notes

The following elements are part of a choice: policy or unicast.

Introduced19.5.R1

Platforms

All

vrf-import
Synopsis Enter the vrf-import context
Context configure service vprn string mvpn vrf-import
Treevrf-import
Introduced19.5.R1

Platforms

All

policy (policy-expr-string | string)
Synopsis Route policy name
Context configure service vprn string mvpn vrf-import policy (policy-expr-string | string)
Treepolicy

Description

This command specifies the route policy name. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed between double quotes.

String Length1 to 255
Max. Instances15
Min. Instances1

Notes

The following elements are part of a choice: policy or unicast.

This element is ordered by the user.

Introduced 19.5.R1

Platforms

All

unicast boolean
Synopsis Enable the unicast VRF import policy for the MVPN
Contextconfigure service vprn string mvpn vrf-import unicast boolean
Treeunicast
Defaultfalse

Notes

The following elements are part of a choice: policy or unicast.

Introduced19.5.R1

Platforms

All

vrf-target
Synopsis Enter the vrf-target context
Context configure service vprn string mvpn vrf-target
Treevrf-target
Introduced19.5.R1

Platforms

All

export
Synopsis Enter the export context
Context configure service vprn string mvpn vrf-target export
Treeexport
Introduced19.5.R1

Platforms

All

import
Synopsis Enter the import context
Context configure service vprn string mvpn vrf-target import
Treeimport
Introduced19.5.R1

Platforms

All

nat
Synopsis Enable the nat context
Context configure service vprn string nat
Treenat
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

inside
Synopsis Enter the inside context
Context configure service vprn string nat inside
Treeinside
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

l2-aware
Synopsis Enter the l2-aware context
Context configure service vprn string nat inside l2-aware
Treel2-aware
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

force-unique-ip-addresses boolean
Synopsis Enforce unique IPv4 addresses for L2-aware subscribers
Contextconfigure service vprn string nat inside l2-aware force-unique-ip-addresses boolean
Treeforce-unique-ip-addresses

Description

When configured to true, the system enforces the uniqueness of IPv4 addresses of L2-aware subscribers in an inside routing context.

This functionality is required if multicast sourced from the inside routing context is enabled for L2-aware subscribers.

Defaultfalse
Introduced23.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

large-scale
Synopsis Enter the large-scale context
Context configure service vprn string nat inside large-scale
Treelarge-scale
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dnat-only
Synopsis Enter the dnat-only context
Context configure service vprn string nat inside large-scale dnat-only
Treednat-only
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dual-stack-lite
Synopsis Enter the dual-stack-lite context
Contextconfigure service vprn string nat inside large-scale dual-stack-lite
Treedual-stack-lite
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

deterministic
Synopsis Enter the deterministic context
Contextconfigure service vprn string nat inside large-scale dual-stack-lite deterministic
Treedeterministic
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

prefix-map [source-prefix] string nat-policy reference
Synopsis Enter the prefix-map list instance
Contextconfigure service vprn string nat inside large-scale dual-stack-lite deterministic prefix-map string nat-policy reference
Treeprefix-map
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

map [from] string to string
Synopsis Enter the map list instance
Context configure service vprn string nat inside large-scale dual-stack-lite deterministic prefix-map string nat-policy reference map string to string
Treemap
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

first-outside-address string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisOutside IP address mapped to inside IP address range
Contextconfigure service vprn string nat inside large-scale dual-stack-lite deterministic prefix-map string nat-policy reference map string to string first-outside-address string
Treefirst-outside-address

Notes

This element is mandatory.

Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

endpoint [address] string
Synopsis Enter the endpoint list instance
Contextconfigure service vprn string nat inside large-scale dual-stack-lite endpoint string
Treeendpoint
Max. Instances128
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

min-first-fragment-size-rx number
Synopsis Minimum MTU size for upstream packets
Contextconfigure service vprn string nat inside large-scale dual-stack-lite endpoint string min-first-fragment-size-rx number
Treemin-first-fragment-size-rx

Description

This command configures the minimum MTU size for the first fragment in the upstream direction. This command can be used to enable processing of first IPv6 fragments smaller than 1280 bytes. RFC 8200 recommends the minimum MTU in IPv6 be 1280 bytes which allows fragmentation only for packets that are larger than 1280 bytes. If a first fragment is smaller than 1280 bytes, DS-lite implementation in the SR OS, by default, drops the first fragment.

Range512 to 1280
Default1280
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

tunnel-mtu number
Synopsis DS-Lite tunnel MTU for this address
Context configure service vprn string nat inside large-scale dual-stack-lite endpoint string tunnel-mtu number
Treetunnel-mtu

Description

This command configures the Dual Stack Lite (DS-Lite) tunnel MTU for this address.

Range464 to 9212
Default1500
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

max-subscriber-limit number
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisLargest value for all subscriber limits in each deterministic pool
Contextconfigure service vprn string nat inside large-scale dual-stack-lite max-subscriber-limit number
Treemax-subscriber-limit
Range1 | 2 | 4 | 8 | 16 | 32 | 64 | 128 | 256 | 512 | 1024 | 2048 | 4096 | 8192 | 16384 | 32768
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

subscriber-prefix-length number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisIPv6 prefix length of the Dual Stack Lite subscribers
Contextconfigure service vprn string nat inside large-scale dual-stack-lite subscriber-prefix-length number
Treesubscriber-prefix-length
Range32 to 64 | 128
Default128
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

filters
Synopsis Enter the filters context
Context configure service vprn string nat inside large-scale filters
Treefilters
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

nat-policy reference
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisNAT policy for LSN
Contextconfigure service vprn string nat inside large-scale nat-policy reference
Treenat-policy

Reference

configure service nat nat-policy string

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

nat44
Synopsis Enter the nat44 context
Context configure service vprn string nat inside large-scale nat44
Treenat44
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

destination-prefix [ip-prefix-length] string
Synopsis Enter the destination-prefix list instance
Contextconfigure service vprn string nat inside large-scale nat44 destination-prefix string
Treedestination-prefix
Max. Instances6144
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

deterministic
Synopsis Enter the deterministic context
Contextconfigure service vprn string nat inside large-scale nat44 deterministic
Treedeterministic
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

prefix-map [source-prefix] string nat-policy reference
Synopsis Enter the prefix-map list instance
Contextconfigure service vprn string nat inside large-scale nat44 deterministic prefix-map string nat-policy reference
Treeprefix-map
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

map [from] string to string
Synopsis Enter the map list instance
Context configure service vprn string nat inside large-scale nat44 deterministic prefix-map string nat-policy reference map string to string
Treemap
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

max-subscriber-limit number
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisLargest value for all subscriber limits in each deterministic pool
Contextconfigure service vprn string nat inside large-scale nat44 max-subscriber-limit number
Treemax-subscriber-limit
Range1 | 2 | 4 | 8 | 16 | 32 | 64 | 128 | 256 | 512 | 1024 | 2048 | 4096 | 8192 | 16384 | 32768
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

nat-import reference
Synopsis Import BGP-VPN routes in NAT inside routing context
Contextconfigure service vprn string nat inside large-scale nat44 nat-import reference
Treenat-import

Description

This command references an import policy to determine the routes that should be installed in the routing table as NAT routes, which are used to steer traffic to NAT.

A dynamic route obtained by BGP-VPN can be imported into an inside (private side) routing context in NAT environment. This route is associated with a NAT policy that maps traffic destined into a NAT pool and outside routing context. If the NAT policy is not explicitly configured in the import route-policy, the imported NAT route is, by default, associated with the default NAT policy defined in the NAT inside routing context.

All BGP-VPN routes that are destined to be imported into NAT inside routing context must be configured with action-type accept in the route policy.

Reference

configure policy-options policy-statement string

Max. Instances5

Notes

This element is ordered by the user.

Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

source-prefix [ip-prefix-length] string
Synopsis Enter the source-prefix list instance
Contextconfigure service vprn string nat inside large-scale nat44 source-prefix string
Treesource-prefix
Introduced23.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

nat-policy reference
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisAT policy associated with the source prefix
Contextconfigure service vprn string nat inside large-scale nat44 source-prefix string nat-policy reference
Treenat-policy

Reference

configure service nat nat-policy string

Notes

This element is mandatory.

Introduced23.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

nat64
Synopsis Enable the nat64 context
Context configure service vprn string nat inside large-scale nat64
Treenat64
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

drop-zero-ipv4-checksum boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDrop UDP datagrams with zero IPv4 checksum
Contextconfigure service vprn string nat inside large-scale nat64 drop-zero-ipv4-checksum boolean
Treedrop-zero-ipv4-checksum
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

insert-ipv6-fragment-header boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisInclude IPv6 fragment header to indicate that the sender allows fragmentation
Contextconfigure service vprn string nat inside large-scale nat64 insert-ipv6-fragment-header boolean
Treeinsert-ipv6-fragment-header
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-fragmentation keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisControl fragmentation of originated downstream IPv6 traffic
Contextconfigure service vprn string nat inside large-scale nat64 ip-fragmentation keyword
Treeip-fragmentation
Optionsfragment-ipv6, fragment-ipv6-unless-ipv4-df-set
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ipv6-mtu number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSize of the IPv6 downstream packet in NAT64
Contextconfigure service vprn string nat inside large-scale nat64 ipv6-mtu number
Treeipv6-mtu
Range1280 to 9212
Default1520
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

prefix string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisIPv6 prefix to derive the IPv6 address from the IPv4 address
Contextconfigure service vprn string nat inside large-scale nat64 prefix string
Treeprefix
Default64:ff9b::/96
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

subscriber-prefix-length number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisIPv6 prefix length for the NAT64 subscribers
Contextconfigure service vprn string nat inside large-scale nat64 subscriber-prefix-length number
Treesubscriber-prefix-length
Range32 to 64 | 128
Default128
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

tos
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the tos context
Contextconfigure service vprn string nat inside large-scale nat64 tos
Treetos
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

downstream
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the downstream context
Contextconfigure service vprn string nat inside large-scale nat64 tos downstream
Treedownstream
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

use-ipv4 boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisCopy TOS/DSCP bits from the incoming IPv4 frame to the outgoing IPv6 frame
Contextconfigure service vprn string nat inside large-scale nat64 tos downstream use-ipv4 boolean
Treeuse-ipv4
Defaultfalse
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

upstream
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the upstream context
Contextconfigure service vprn string nat inside large-scale nat64 tos upstream
Treeupstream
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

set-tos (keyword | number)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisTOS/DSCP bits in IPv4 frame in the upstream direction
Contextconfigure service vprn string nat inside large-scale nat64 tos upstream set-tos (keyword | number)
Treeset-tos
Range0 to 255
Optionsuse-ipv6
Defaultuse-ipv6
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

redundancy
Synopsis Enter the redundancy context
Context configure service vprn string nat inside large-scale redundancy
Treeredundancy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

peer string
Synopsis IP address of the NAT redundancy peer for this virtual router instance
Contextconfigure service vprn string nat inside large-scale redundancy peer string
Treepeer
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

peer6 string
Synopsis IPv6 address of the NAT redundancy peer for this virtual router instance
Contextconfigure service vprn string nat inside large-scale redundancy peer6 string
Treepeer6
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

static-port-forwards
Synopsis Enter the static-port-forwards context
Contextconfigure service vprn string nat inside large-scale static-port-forwards
Treestatic-port-forwards
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

spf-nat-policy [nat-policy] reference
Synopsis Add a list entry for spf-nat-policy
Contextconfigure service vprn string nat inside large-scale static-port-forwards spf-nat-policy reference
Treespf-nat-policy
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

subscriber-identification
Synopsis Enter the subscriber-identification context
Contextconfigure service vprn string nat inside large-scale subscriber-identification
Treesubscriber-identification
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

attribute
Synopsis Enter the attribute context
Context configure service vprn string nat inside large-scale subscriber-identification attribute
Treeattribute
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

type keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRADIUS attribute used as subscriber identifier
Contextconfigure service vprn string nat inside large-scale subscriber-identification attribute type keyword
Treetype
Optionsalc-sub-string, user-name, class, station-id, imsi, imei
Default alc-sub-string
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

vendor keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisThe RADIUS Vendor
Contextconfigure service vprn string nat inside large-scale subscriber-identification attribute vendor keyword
Treevendor
Optionsstandard, nokia, 3gpp
Defaultnokia
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

radius-proxy-server
Synopsis Enable the radius-proxy-server context
Contextconfigure service vprn string nat inside large-scale subscriber-identification radius-proxy-server
Treeradius-proxy-server
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

traffic-identification
Synopsis Enter the traffic-identification context
Contextconfigure service vprn string nat inside large-scale traffic-identification
Treetraffic-identification

Description

Commands in this context configure traffic idenification for NAT processing

Introduced23.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

map
Synopsis Enter the map context
Context configure service vprn string nat map
Treemap
Introduced16.0.R1

Platforms

VSR

outside
Synopsis Enter the outside context
Context configure service vprn string nat outside
Treeoutside
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dnat-only
Synopsis Enter the dnat-only context
Context configure service vprn string nat outside dnat-only
Treednat-only
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

route-limit number
Synopsis Limit for internal routes for downstream traffic
Contextconfigure service vprn string nat outside dnat-only route-limit number
Treeroute-limit
Range1 to 131072
Default32768
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

filters
Synopsis Enter the filters context
Context configure service vprn string nat outside filters
Treefilters
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

downstream
Synopsis Enter the downstream context
Context configure service vprn string nat outside filters downstream
Treedownstream
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

upstream
Synopsis Enter the upstream context
Context configure service vprn string nat outside filters upstream
Treeupstream
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mtu number
Synopsis MTU for downstream traffic
Context configure service vprn string nat outside mtu number
Treemtu
Range512 to 9000
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

pool [name] string
Synopsis Enter the pool list instance
Context configure service vprn string nat outside pool string
Treepool
Max. Instances4096
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis NAT pool name
Contextconfigure service vprn string nat outside pool string
Treepool
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

address-pooling keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisOutside IP address allocation mode for a NAT subscriber
Contextconfigure service vprn string nat outside pool string address-pooling keyword
Treeaddress-pooling

Description

This command configures address pooling which defines a relationship between the NAT subscriber and its outside IP address(es).

The behavior in NAT, as defined in RFC 7857, strongly recommends that the NAT subscribers be mapped to a single outside IP address. If this outside IP address runs out of ports, no new ports for the subscriber are allocated. This behavior is called paired address pooling.

The alternative behavior is arbitrary address pooling, where a NAT subscriber is mapped to multiple IP addresses when the current outside IP address runs out of ports. This way, the subscriber becomes associated with multiple outside IP addresses. While this results in better resource utilization in NAT, it may negatively affect the behavior of some applications.

Optionspaired, arbitrary
Default paired
Introduced23.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

address-range [start] string end string
Synopsis Enter the address-range list instance
Contextconfigure service vprn string nat outside pool string address-range string end string
Treeaddress-range
Max. Instances4096
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[start] string
Synopsis Lower bound of the NAT address range
Context configure service vprn string nat outside pool string address-range string end string
Treeaddress-range

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

end string
Synopsis Upper bound of the NAT address range
Context configure service vprn string nat outside pool string address-range string end string
Treeaddress-range

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

drain boolean
Synopsis Start or stop draining this NAT address range
Contextconfigure service vprn string nat outside pool string address-range string end string drain boolean
Treedrain
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the outside routing NAT pool
Contextconfigure service vprn string nat outside pool string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

applications
Synopsis Enter the applications context
Contextconfigure service vprn string nat outside pool string applications
Treeapplications
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

agnostic boolean
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNAT pool to create in the outside routing context
Contextconfigure service vprn string nat outside pool string applications agnostic boolean
Treeagnostic
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

flexible-port-allocation boolean
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisAllocates individual ports per subscriber in a pool
Contextconfigure service vprn string nat outside pool string applications flexible-port-allocation boolean
Treeflexible-port-allocation

Description

When configured to true, the router enables LSN44 pool behavior, where a subscriber allocates ports individually and not through port blocks. The port block is removed and port logging is disabled for this application. Static port forwards can be interleaved with dynamically allocated ports when this application is enabled. A subscriber limit that is the maximum number of subscribers per outside IP address is not supported for this application.

Defaultfalse
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

icmp-echo-reply boolean
Synopsis Allow NAT pool IP addresses to respond to ICMP PINGs
Contextconfigure service vprn string nat outside pool string icmp-echo-reply boolean
Treeicmp-echo-reply

Description

This command allows IP addresses in the NAT pool to respond to ICMP Echo requests (PINGs). The configuration can be toggled while the pool is in use.

In L2-aware NAT when port-block-extensions is disabled, the reply from an outside IP address is generated only when this IP address has at least one host (binding) behind it.

In L2-aware NAT when port-block-extensions is enabled, the reply from an outside IP address is generated regardless if a binding is present.

In LSN, the reply from an outside IP address is generated regardless if a binding is present.

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

l2-aware
Synopsis Enter the l2-aware context
Context configure service vprn string nat outside pool string l2-aware
Treel2-aware
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

default-host
Synopsis Enable the default-host context
Contextconfigure service vprn string nat outside pool string l2-aware default-host
Treedefault-host

Description

Commands in this context configure the default DMZ host options. A default DMZ host is a node on the inside to which all unknown traffic is redirected by changing the destination IPv4 address in the traffic header. During this operation, the checksums in the Layer 3 and Layer 4 header (UDP and TCP) are recalculated. 

Unknown traffic in NAT represent all unmatched traffic arriving from the outside (where there is no pinhole or a matching flow record created by traffic initiated from the inside). The purpose of the default DMZ host is to capture and analyze the unknown traffic as part of threat analysis.

The rate of redirected unknown traffic can be restricted by configuration.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-address string
Synopsis IP address of the default DMZ host
Context configure service vprn string nat outside pool string l2-aware default-host ip-address string
Treeip-address

Description

This command configures the IP address of the default DMZ host. Redirection to the default DMZ host is achieved by replacing the destination IP address in the traffic header in the unknown traffic initiated from the outside with the one of the default DMZ host.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

rate-limit number
Synopsis Rate limit for unknown traffic sent to default DMZ host
Contextconfigure service vprn string nat outside pool string l2-aware default-host rate-limit number
Treerate-limit

Description

This command configures the rate limit of the unknown traffic sent to the default DMZ host.

Unknown traffic sent to the default DMZ host is rate limited by a configurable value expressed in mbps. The rate limit is configurable per NAT pool per ISA, vISA, or ESA-VM.

Range1 to 10000
Unitsmegabps
Default 10
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

external-assignment boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisExternal IP address for Layer-2-aware
Contextconfigure service vprn string nat outside pool string l2-aware external-assignment boolean
Treeexternal-assignment
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

port-block-extension
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the port-block-extension context
Contextconfigure service vprn string nat outside pool string l2-aware port-block-extension
Treeport-block-extension
Introduced21.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ports number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisNumber of ports per dynamic port-block
Contextconfigure service vprn string nat outside pool string l2-aware port-block-extension ports number
Treeports

Description

For Carrier Grade NAT (CGN), this command represents the size of all port blocks for NAT subscribes in the NAT pool.

For L2-Aware NAT, this command represents only the size of the initial port block of a subscriber in the L2-aware NAT pool. Additional port-blocks (extended port blocks) for the L2-Aware subscriber must be explicitly enabled under the l2-aware port-block-extension hierarchy in the NAT pool.

This command does not affect the size of extended port-blocks.

Range10 to 5000

Notes

This element is mandatory.

Introduced21.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

subscriber
Synopsis Enter the subscriber context
Context configure service vprn string nat outside pool string l2-aware port-block-extension subscriber
Treesubscriber
Introduced22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

watermarks
Synopsis Enable the watermarks context
Context configure service vprn string nat outside pool string l2-aware port-block-extension subscriber watermarks
Treewatermarks

Description

This command configures watermarks for NAT resources.

Introduced22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

high number
Synopsis High watermark percentage
Context configure service vprn string nat outside pool string l2-aware port-block-extension subscriber watermarks high number
Treehigh

Description

This command configures the high threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

low number
Synopsis Low watermark percentage
Context configure service vprn string nat outside pool string l2-aware port-block-extension subscriber watermarks low number
Treelow

Description

This command configures the low threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

subscriber-limit number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisNumber of L2-Aware NAT subscribers per outside address
Contextconfigure service vprn string nat outside pool string l2-aware port-block-extension subscriber-limit number
Treesubscriber-limit

Description

When port-block extensions for the L2-Aware subscribers are enabled, the port space for an outside IP address is divided into the following:

  • well-known port (this is a fixed and permanently allocated block of ports for all NAT types)

  • static port-forwarding range (if enabled by configuration)

  • port range allocated for initial port blocks of each L2-Aware subscriber

  • port range allocated for extended port blocks for the remainder after the three previous port ranges

The number of L2-Aware NAT subscribers per an outside IP address multiplied by the size of the initial port-block size determines the size of the port range reserved for initial port-blocks of each subscriber.

The lower boundary of the extended port range is determined by adding the upper boundary of the configured port forwarding range and the size of the port range allocated for initial port blocks.

Range2 to 2000

Notes

This element is mandatory.

Introduced21.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

watermarks
Synopsis Enable the watermarks context
Context configure service vprn string nat outside pool string l2-aware port-block-extension watermarks
Treewatermarks
Introduced22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

high number
Synopsis High watermark percentage
Context configure service vprn string nat outside pool string l2-aware port-block-extension watermarks high number
Treehigh

Description

This command configures the high threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

low number
Synopsis Low watermark percentage
Context configure service vprn string nat outside pool string l2-aware port-block-extension watermarks low number
Treelow

Description

This command configures the low threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

large-scale
Synopsis Enter the large-scale context
Context configure service vprn string nat outside pool string large-scale
Treelarge-scale
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

default-host
Synopsis Enable the default-host context
Contextconfigure service vprn string nat outside pool string large-scale default-host
Treedefault-host

Description

Commands in this context configure the default DMZ host options. A default DMZ host is a node on the inside to which all unknown traffic is redirected by changing the destination IPv4 address in the traffic header. During this operation, the checksums in the Layer 3 and Layer 4 header (UDP and TCP) are recalculated. 

Unknown traffic in NAT represent all unmatched traffic arriving from the outside (where there is no pinhole or a matching flow record created by traffic initiated from the inside). The purpose of the default DMZ host is to capture and analyze the unknown traffic as part of threat analysis.

The rate of redirected unknown traffic can be restricted by configuration.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-address string
Synopsis IP address of the default DMZ host
Context configure service vprn string nat outside pool string large-scale default-host ip-address string
Treeip-address

Description

This command configures the IP address of the default DMZ host. Redirection to the default DMZ host is achieved by replacing the destination IP address in the traffic header in the unknown traffic initiated from the outside with the one of the default DMZ host.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

rate-limit number
Synopsis Rate limit for unknown traffic sent to default DMZ host
Contextconfigure service vprn string nat outside pool string large-scale default-host rate-limit number
Treerate-limit

Description

This command configures the rate limit of the unknown traffic sent to the default DMZ host.

Unknown traffic sent to the default DMZ host is rate limited by a configurable value expressed in mbps. The rate limit is configurable per NAT pool per ISA, vISA, or ESA-VM.

Range1 to 10000
Unitsmegabps
Default 10
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

deterministic
Synopsis Enter the deterministic context
Contextconfigure service vprn string nat outside pool string large-scale deterministic
Treedeterministic
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

port-reservation number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisNumber of ports per deterministic port-block
Contextconfigure service vprn string nat outside pool string large-scale deterministic port-reservation number
Treeport-reservation
Range1 to 65536
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

watermarks
Synopsis Enable the watermarks context
Context configure service vprn string nat outside pool string large-scale deterministic watermarks
Treewatermarks

Description

Commands in this context monitor extended (dynamic) port-block utilization per outside IP in a NAT pool in deterministic LSN.

High and low thresholds are configured in percentages of total available extended port-blocks per outside IP in a pool. Both values represent extended port-block utilization or occupancy per outside IP in a pool.

For the system to generate those events, the NAT event-id 2045 must be enabled through configuration in the log event-control.

Introduced22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

high number
Synopsis High watermark percentage
Context configure service vprn string nat outside pool string large-scale deterministic watermarks high number
Treehigh

Description

This command configures the high threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

low number
Synopsis Low watermark percentage
Context configure service vprn string nat outside pool string large-scale deterministic watermarks low number
Treelow

Description

This command configures the low threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

flexible-port-allocation
Synopsis Enter the flexible-port-allocation context
Contextconfigure service vprn string nat outside pool string large-scale flexible-port-allocation
Treeflexible-port-allocation

Description

Commands in this context enable LSN44 pool behavior where a subscriber allocates ports individually instead of through port blocks. The port block concept is removed for this application. Static port forwards can be interleaved with dynamically-allocated ports. Port logging in disabled when this application is enabled. A subscriber limit that is the maximum number of subscribers per outside IP address is not supported for this application.

Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

free-port-limit
Synopsis Enter the free-port-limit context
Contextconfigure service vprn string nat outside pool string large-scale flexible-port-allocation free-port-limit
Treefree-port-limit

Description

Commands in this context configure the minimal number of ports per protocol and per outside IP address in an LSN44 pool with flexible port allocations that must be free to map new subscribers to the outside IP address. This limit avoids rapid port depletion for new subscribers in paired pooling mode, or unnecessary toggling between external IP addresses for existing subscribers in arbitrary pooling mode.

Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

icmp number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLimit of free ports for ICMP per outside IP address
Contextconfigure service vprn string nat outside pool string large-scale flexible-port-allocation free-port-limit icmp number
Treeicmp

Description

This command configures the minimum number of ports for the ICMP protocol per outside IP address in an LSN44 pool with flexible port allocations that are free so that a new subscriber is mapped to the outside IP address. This limit is set to avoid rapid port depletion for new subscribers in paired pooling mode, or unnecessary toggling between external IP addresses for existing subscribers in arbitrary pooling mode.

Range1 to 10000
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

tcp number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLimit of free ports for TCP per outside IP address
Contextconfigure service vprn string nat outside pool string large-scale flexible-port-allocation free-port-limit tcp number
Treetcp

Description

This command configures the minimum number of ports for TCP protocol per outside IP address in an LSN44 pool with flexible port allocations that are free so that a new subscriber is mapped to the outside IP address. This limit is set to avoid rapid port depletion for new subscribers in paired pooling mode, or unnecessary toggling between external IP addresses for existing subscribers in arbitrary pooling mode.

Range1 to 10000
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

udp number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisLimit of free ports for UDP per outside IP address
Contextconfigure service vprn string nat outside pool string large-scale flexible-port-allocation free-port-limit udp number
Treeudp

Description

This command configures the minimum number of ports for UDP protocol per outside IP address in an LSN44 pool with flexible port allocations that are free so that a new subscriber is mapped to the outside IP address. This limit is set to avoid rapid port depletion for new subscribers in paired pooling mode, or unnecessary toggling between external IP addresses for existing subscribers in arbitrary pooling mode.

Range1 to 10000
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

redundancy
Synopsis Enter the redundancy context
Context configure service vprn string nat outside pool string large-scale redundancy
Treeredundancy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of NAT pool redundancy
Contextconfigure service vprn string nat outside pool string large-scale redundancy admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable

Notes

The following elements are part of a choice: (admin-state, export-route, and monitor-route) or follow.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

export-route string
Synopsis Route to export to the peer
Context configure service vprn string nat outside pool string large-scale redundancy export-route string
Treeexport-route

Notes

The following elements are part of a choice: (admin-state, export-route, and monitor-route) or follow.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

follow
Synopsis Enter the follow context
Context configure service vprn string nat outside pool string large-scale redundancy follow
Treefollow

Notes

The following elements are part of a choice: (admin-state, export-route, and monitor-route) or follow.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

subscriber-limit number
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisMaximum number of subscribers per IP address
Contextconfigure service vprn string nat outside pool string large-scale subscriber-limit number
Treesubscriber-limit
Range1 to 65535 | 4294967295
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mode keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisMode of operation of this NAT address pool
Contextconfigure service vprn string nat outside pool string mode keyword
Treemode
Optionsauto, napt, one-to-one
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

nat-group reference
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisCreate a NAT group
Contextconfigure service vprn string nat outside pool string nat-group reference
Treenat-group

Reference

configure isa nat-group number

Notes

The following elements are part of a mandatory choice: nat-group or wlan-gw-group.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

port-forwarding
Synopsis Enter the port-forwarding context
Contextconfigure service vprn string nat outside pool string port-forwarding
Treeport-forwarding
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dynamic-block-reservation boolean
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisReserve dynamic block for subscriber
Contextconfigure service vprn string nat outside pool string port-forwarding dynamic-block-reservation boolean
Treedynamic-block-reservation

Description

When configured to true, the system reserves dynamic port block when the first port forward for the subscriber is created. The dynamic port block allocation is logged only if the block is being used and mappings are created. Dynamic port block reservation due to the port forward creation but without any dynamic mapping, is not logged.

The reserved port block is released only when the last mapping in the block expires and there are no port forwards associated with the subscriber. The de-allocation log (syslog or RADIUS) is generated when the dynamic port block is completely released.

Dynamic port block reservations can be enabled only if the configured maximum number of subscribers per outside IP addresses are less than or equal to the maximum number of configured port blocks per outside IP address.

When configured to false, dynamic port blocks are not reserved when the first port forward for the subscriber is created.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

range-end number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisEnd of the wildcard range for port forwards
Contextconfigure service vprn string nat outside pool string port-forwarding range-end number
Treerange-end

Description

This command configures the upper boundary of the wildcard port range dedicated to port forwarding in a NAT pool, whereas the range-start command configures the lower boundary (the starting port) of the wildcard port range dedicated to port forwarding in a NAT pool.

If unconfigured, the range-end implicit value is set to 1023, that represents the end of the well-known port range that is always enabled.

Port forwards are supported only in pools in NAPT mode. Pools in 1:1 mode do not support port-forwards.

Range0 | 1023 to 65535
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

range-start number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisStart of the wildcard range for port forwards
Contextconfigure service vprn string nat outside pool string port-forwarding range-start number
Treerange-start

Description

This command configures the lower boundary (the starting port) of the wildcard port range dedicated to port forwarding in a NAT pool, whereas the range-end command configures the upper boundary of the wildcard port range dedicated to port forwarding in a NAT pool.

Port 0 is always excluded from the port forwarding range.

Port forwards are supported only in pools in Network Address and Port Translation (NAPT) mode. Pools in 1:1 mode do not support configured port forwards.

Range0 | 1 | 1025 to 65535
Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

port-reservation
Synopsis Enter the port-reservation context
Contextconfigure service vprn string nat outside pool string port-reservation
Treeport-reservation
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

port-blocks number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisPort block size for NAT subscribers
Contextconfigure service vprn string nat outside pool string port-reservation port-blocks number
Treeport-blocks

Description

In CGN, this command specifies the number of port-blocks per outside IP address in the NAT pool. The available ports per outside IP address (the end port minus the upper bound value of the static port-forwarding range) are divided into the number of port blocks specified in this command. This implicitly determines the size of each port block.

For L2-aware NAT, this command can be configured only if the port block extensions (extended port blocks) are disabled. You must disable the l2-aware port-block-extension hierarchy in the NAT pool.

Range0 to 64512

Notes

The following elements are part of a choice: port-blocks or ports.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ports number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisSize of the port block for NAT subscribers
Contextconfigure service vprn string nat outside pool string port-reservation ports number
Treeports

Description

For carrier-grade NAT (CGN), this command specifies the size of port blocks for NAT subscribes in the NAT pool.

For L2-aware NAT, this command specifies the size of the initial port-block of a subscriber in the pool. Additional port blocks (extended port blocks) for the L2-aware subscriber must be explicitly enabled under the l2-aware port-block-extension hierarchy in the NAT pool.

This command does not affect the size of extended port blocks.

Range0 to 64512

Notes

The following elements are part of a choice: port-blocks or ports.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

type keyword
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNAT pool type
Contextconfigure service vprn string nat outside pool string type keyword
Treetype
Optionslarge-scale, l2-aware, wlan-gw-anchor

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

watermarks
Synopsis Enable the watermarks context
Context configure service vprn string nat outside pool string watermarks
Treewatermarks

Description

This command configures watermarks for NAT resources.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

high number
Synopsis High watermark percentage
Context configure service vprn string nat outside pool string watermarks high number
Treehigh

Description

This command configures the high threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

low number
Synopsis Low watermark percentage
Context configure service vprn string nat outside pool string watermarks low number
Treelow

Description

This command configures the low threshold value as a percentage of the total port-block space in a NAT pool.

Range0 to 100
Unitspercent

Notes

This element is mandatory.

Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

wlan-gw-group reference
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisCreate a WLAN GW group for NAT
Contextconfigure service vprn string nat outside pool string wlan-gw-group reference
Treewlan-gw-group

Reference

configure isa wlan-gw-group number

Notes

The following elements are part of a mandatory choice: nat-group or wlan-gw-group.

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

network
Synopsis Enter the network context
Context configure service vprn string network
Treenetwork
Introduced16.0.R4

Platforms

All

ingress
Synopsis Enter the ingress context
Context configure service vprn string network ingress
Treeingress
Introduced16.0.R4

Platforms

All

filter
Synopsis Enter the filter context
Context configure service vprn string network ingress filter
Treefilter
Introduced16.0.R4

Platforms

All

qos
Synopsis Enter the qos context
Context configure service vprn string network ingress qos
Treeqos
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

instance number
Synopsis Forwarding plane ingress queue group instance
Contextconfigure service vprn string network ingress qos instance number
Treeinstance
Range1 to 65535
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS, VSR

network-interface [interface-name] string
Synopsis Enter the network-interface list instance
Contextconfigure service vprn string network-interface string
Treenetwork-interface
Introduced16.0.R1

Platforms

All

[interface-name] string
Synopsis Network interface name
Context configure service vprn string network-interface string
Treenetwork-interface
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

cflowd-parameters
Synopsis Enter the cflowd-parameters context
Contextconfigure service vprn string network-interface string cflowd-parameters
Treecflowd-parameters
Introduced16.0.R1

Platforms

All

sampling [sampling-type] keyword
Synopsis Enter the sampling list instance
Contextconfigure service vprn string network-interface string cflowd-parameters sampling keyword
Treesampling
Introduced16.0.R1

Platforms

All

[sampling-type] keyword
Synopsis Traffic sampling type
Context configure service vprn string network-interface string cflowd-parameters sampling keyword
Treesampling

Description

This command configures the type of traffic to be sampled on the associated IP interface.

Optionsunicast, multicast, both

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

direction keyword
Synopsis Direction of traffic for cflowd sampling
Contextconfigure service vprn string network-interface string cflowd-parameters sampling keyword direction keyword
Treedirection

Description

This command configures the direction in which sampling occurs on the associated IP interfaces.

Optionsingress-only, egress-only, both
Defaultingress-only
Introduced16.0.R1

Platforms

All

type keyword
Synopsis Type of cflowd analysis
Context configure service vprn string network-interface string cflowd-parameters sampling keyword type keyword
Treetype

Description

This command configures the cflowd sampling type on the associated IP interface.

Optionsacl, interface

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

egress
Synopsis Enter the egress context
Context configure service vprn string network-interface string egress
Treeegress
Introduced16.0.R1

Platforms

All

hold-time
Synopsis Enter the hold-time context
Context configure service vprn string network-interface string hold-time
Treehold-time
Introduced16.0.R1

Platforms

All

ipv4
Synopsis Enter the ipv4 context
Context configure service vprn string network-interface string hold-time ipv4
Treeipv4
Introduced16.0.R1

Platforms

All

down
Synopsis Enter the down context
Context configure service vprn string network-interface string hold-time ipv4 down
Treedown

Description

Commands in this context configure the down hold timer, which specifies the delay before activating the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface up, unless an operator configures the init-only command. 

Introduced16.0.R1

Platforms

All

init-only boolean
Synopsis Apply delay only at interface configuration or reboot
Contextconfigure service vprn string network-interface string hold-time ipv4 down init-only boolean
Treeinit-only

Description

This command applies a delay only when the IP interface is first configured or after a system reboot.

Defaultfalse
Introduced16.0.R1

Platforms

All

up
Synopsis Enter the up context
Context configure service vprn string network-interface string hold-time ipv4 up
Treeup

Description

Commands in this context configure the up hold timer, which specifies the delay before deactivation of the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface down.

Introduced16.0.R1

Platforms

All

ingress
Synopsis Enter the ingress context
Context configure service vprn string network-interface string ingress
Treeingress
Introduced16.0.R1

Platforms

All

ip-mtu number
Synopsis IP MTU applied to outgoing packets
Context configure service vprn string network-interface string ip-mtu number
Treeip-mtu

Description

This command configures the IP maximum transmission unit (MTU) for the associated router IP interface.

Range512 to 9786
Unitsbytes
Introduced 16.0.R1

Platforms

All

ipv4
Synopsis Enter the ipv4 context
Context configure service vprn string network-interface string ipv4
Treeipv4
Introduced16.0.R1

Platforms

All

bfd
Synopsis Enter the bfd context
Context configure service vprn string network-interface string ipv4 bfd
Treebfd
Introduced16.0.R1

Platforms

All

multiplier number
Synopsis Number of consecutive BFD messages missed from the peer
Contextconfigure service vprn string network-interface string ipv4 bfd multiplier number
Treemultiplier

Description

This command configures the number of missed messages before the BFD session state is changed to down and the upper-level protocol is notified of the fault. A multiplier of less than 3 should not be used in production environments. 

Range1 to 20
Default3
Introduced 16.0.R1

Platforms

All

receive number
Synopsis BFD receive interval over this interface
Contextconfigure service vprn string network-interface string ipv4 bfd receive number
Treereceive

Description

This command specifies the receive interval for the BFD session.

On the 7750 SR, this command can only be configured to a value less than 100 when the type command is configured to cpm-np.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 16.0.R1

Platforms

All

transmit-interval number
Synopsis BFD transmit interval over this interface
Contextconfigure service vprn string network-interface string ipv4 bfd transmit-interval number
Treetransmit-interval

Description

This command configures the transmit intervals.

On the 7750 SR, this command can only be configured to a value less than 100 when the type command is configured to cpm-np.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 16.0.R1

Platforms

All

type keyword
Synopsis Local termination point for the BFD session
Contextconfigure service vprn string network-interface string ipv4 bfd type keyword
Treetype

Description

This command sets the local termination point for the BFD session to allow for fast timers down to 10 ms granularity.

The options to specify where the BFD session runs are:

  • auto (default) – the system chooses and uses the line card CPU only for single-hop BFD sessions with timer intervals equal to or greater than 100ms. All others are placed on the cpm-np.

  • cpm-np – BFD session runs on the FP complex associated with the CPM. This is either the FP on the CPM or the one elected on smaller systems. 

  • fp – BFD session runs on the line card CPU. This option can only be used for single-hop BFD sessions with timers equal to or greater than 100ms.  

Optionscpm-np, auto, fp
Defaultauto
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

icmp
Synopsis Enter the icmp context
Context configure service vprn string network-interface string ipv4 icmp
Treeicmp
Introduced16.0.R1

Platforms

All

param-problem
Synopsis Enter the param-problem context
Contextconfigure service vprn string network-interface string ipv4 icmp param-problem
Treeparam-problem

Description

Commands in this context specify the settings for ICMP Parameter Problem messages generated by the interface.

Introduced16.0.R1

Platforms

All

redirects
Synopsis Enter the redirects context
Context configure service vprn string network-interface string ipv4 icmp redirects
Treeredirects

Description

Commands in this context configure the settings for ICMP redirect messages generated by the interface.

The system sends ICMP redirect messages to alert the sending node that a more optimal route is available on another router on the same subnetwork.

Introduced16.0.R1

Platforms

All

ttl-expired
Synopsis Enter the ttl-expired context
Context configure service vprn string network-interface string ipv4 icmp ttl-expired
Treettl-expired

Description

Commands in this context configure the settings for ICMP TTL expired messages generated by the interface.

Introduced16.0.R1

Platforms

All

unreachables
Synopsis Enter the unreachables context
Contextconfigure service vprn string network-interface string ipv4 icmp unreachables
Treeunreachables

Description

Commands in this context specify the settings for ICMP host and network destination unreachable messages generated by the interface.

Introduced16.0.R1

Platforms

All

neighbor-discovery
Synopsis Enter the neighbor-discovery context
Contextconfigure service vprn string network-interface string ipv4 neighbor-discovery
Treeneighbor-discovery
Introduced16.0.R1

Platforms

All

static-neighbor [ipv4-address] string
Synopsis Enter the static-neighbor list instance
Contextconfigure service vprn string network-interface string ipv4 neighbor-discovery static-neighbor string
Treestatic-neighbor
Introduced16.0.R1

Platforms

All

timeout number
Synopsis Timeout for an ARP entry learned on the interface
Contextconfigure service vprn string network-interface string ipv4 neighbor-discovery timeout number
Treetimeout

Description

This command configures the minimum time an ARP entry learned on the IP interface is stored in the ARP table. ARP entries are automatically refreshed when an ARP request or gratuitous ARP is seen by an IP host. Otherwise, the ARP entry is aged from the ARP table.

Range0 to 65535
Unitsseconds
Default 14400
Introduced16.0.R1

Platforms

All

primary
Synopsis Enable the primary context
Context configure service vprn string network-interface string ipv4 primary
Treeprimary
Introduced16.0.R1

Platforms

All

secondary [address] string
Synopsis Enter the secondary list instance
Contextconfigure service vprn string network-interface string ipv4 secondary string
Treesecondary
Introduced16.0.R1

Platforms

All

igp-inhibit boolean
Synopsis Disable the running IGP from recognizing secondary IP
Contextconfigure service vprn string network-interface string ipv4 secondary string igp-inhibit boolean
Treeigp-inhibit

Description

When configured to true, the running IGP does not recognize the secondary IP address as a local interface.

Defaultfalse
Introduced16.0.R1

Platforms

All

urpf-check
Synopsis Enable the urpf-check context
Context configure service vprn string network-interface string ipv4 urpf-check
Treeurpf-check
Introduced16.0.R1

Platforms

All

lag
Synopsis Enter the lag context
Context configure service vprn string network-interface string lag
Treelag
Introduced16.0.R1

Platforms

All

link-map-profile number
Synopsis LAG link map profile for a SAP or network interface
Contextconfigure service vprn string network-interface string lag link-map-profile number
Treelink-map-profile

Description

This command assigns a preconfigured LAG link map profile to a SAP or network interface configured on a LAG or a PW port that exists on a LAG. After an operator assigns a LAG link map profile, the system rehashes the SAP or network interface egress traffic over the LAG as required by the new configuration.

If the LAG link map profile for a SAP or network interface is deleted, the system reverts back to per-flow hashing.

Range1 to 64
Introduced16.0.R1

Platforms

All

per-link-hash
Synopsis Enter the per-link-hash context
Contextconfigure service vprn string network-interface string lag per-link-hash
Treeper-link-hash
Introduced16.0.R1

Platforms

All

load-balancing
Synopsis Enter the load-balancing context
Contextconfigure service vprn string network-interface string load-balancing
Treeload-balancing
Introduced16.0.R1

Platforms

All

flow-label-load-balancing boolean
Synopsis Enable flow label load balancing
Context configure service vprn string network-interface string load-balancing flow-label-load-balancing boolean
Treeflow-label-load-balancing

Description

When configured to true, the router enables load balancing in ECMP and LAG based on the output of a hash performed on the triplet (SA, DA, flow label) in the header of an IPv6 packet received on an IES, VPRN, R-VPLS, CSC, or network interface.

When configured to false, the router disables load balancing in ECMP and LAG.

Defaultfalse
Introduced21.5.R1

Platforms

All

ip-load-balancing keyword
Synopsis IP load-balancing algorithm
Context configure service vprn string network-interface string load-balancing ip-load-balancing keyword
Treeip-load-balancing

Description

This command specifies whether to include the source address, destination address, or both in LAG or ECMP hash on IP interfaces. Additionally, when the l4-load-balancing command is enabled, this command also includes the source or destination port in the hash inputs.

Optionsboth, destination, source, inner-ip
Default both
Introduced16.0.R3

Platforms

All

lsr-load-balancing keyword
Synopsis LSR load-balancing algorithm
Context configure service vprn string network-interface string load-balancing lsr-load-balancing keyword
Treelsr-load-balancing

Description

This command specifies whether the IP header is used in the LAG and ECMP LSR hashing algorithm. This is the per-interface setting.

Optionslbl-only, lbl-ip, ip-only, eth-encap-ip, lbl-ip-l4-teid
Introduced16.0.R1

Platforms

All

spi-load-balancing boolean
Synopsis Enable SPI use in hashing
Context configure service vprn string network-interface string load-balancing spi-load-balancing boolean
Treespi-load-balancing

Description

When configured to true, the router uses the Security Parameter Index (SPI) in hashing for ESP and AH encrypted IPv4 and IPv6 traffic. This is a per-interface setting.

Defaultfalse
Introduced16.0.R1

Platforms

All

loopback
Synopsis Use interface as a loopback interface
Contextconfigure service vprn string network-interface string loopback
Treeloopback

Notes

The following elements are part of a choice: loopback or port.

Introduced16.0.R1

Platforms

All

port string
Synopsis Port to bind the interface
Context configure service vprn string network-interface string port string
Treeport
String Length1 to 45

Notes

The following elements are part of a choice: loopback or port.

Introduced16.0.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service vprn string network-interface string qos
Treeqos
Introduced16.0.R1

Platforms

All

egress-instance number
Synopsis Port egress queue group instance for this interface
Contextconfigure service vprn string network-interface string qos egress-instance number
Treeegress-instance

Description

This command specifies which instance to associate with this specific network IP interface since multiple instances of the same egress queue-group can be applied to the same port.

Range1 to 65535
Introduced16.0.R1

Platforms

All

egress-port-redirect-group reference
Synopsis QoS queue group name
Context configure service vprn string network-interface string qos egress-port-redirect-group reference
Treeegress-port-redirect-group

Description

This command configures the egress queue group used for all egress forwarding-class redirections specified within the network QoS policy ID. The specified queue group name must exist as an egress queue group applied to the egress context of the port associated with the IP interface.

Reference

configure qos queue-group-templates egress queue-group string

Introduced16.0.R1

Platforms

All

ingress-fp-redirect-group reference
Synopsis Forwarding plane queue group policy for the interface
Contextconfigure service vprn string network-interface string qos ingress-fp-redirect-group reference
Treeingress-fp-redirect-group

Description

This command configures the ingress queue-group used for all ingress forwarding-class redirections specified within the network QoS policy ID. The specified queue group name must exist as an ingress queue group applied to the ingress context of the forwarding plane associated with the IP interface.

Reference

configure qos queue-group-templates ingress queue-group string

Introduced16.0.R1

Platforms

All

ingress-instance number
Synopsis Forwarding plane ingress queue group for this interface
Contextconfigure service vprn string network-interface string qos ingress-instance number
Treeingress-instance

Description

This command configures which instance to associate with this specific network IP interface. An operator can apply multiple instances of the same ingress queue group to the same forwarding plane.

Range1 to 65535
Introduced16.0.R1

Platforms

All

network-policy reference
Synopsis Network policy name associated with a network interface
Contextconfigure service vprn string network-interface string qos network-policy reference
Treenetwork-policy

Description

This command associates an existing network policy name with the IP interface.

Reference

configure qos network string

Introduced16.0.R1

Platforms

All

ntp
Synopsis Enable the ntp context
Context configure service vprn string ntp
Treentp
Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of NTP execution
Contextconfigure service vprn string ntp admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

authenticate boolean
Synopsis Authentication of NTP PDUs when acting as a server
Contextconfigure service vprn string ntp authenticate boolean
Treeauthenticate
Defaultfalse
Introduced16.0.R1

Platforms

All

authentication-key [key-id] number
Synopsis Enter the authentication-key list instance
Contextconfigure service vprn string ntp authentication-key number
Treeauthentication-key
Introduced16.0.R1

Platforms

All

key string
Synopsis Key to authenticate NTP packets
Context configure service vprn string ntp authentication-key number key string
Treekey
String Length1 to 71

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

type keyword
Synopsis Authentication method to authenticate NTP packet
Contextconfigure service vprn string ntp authentication-key number type keyword
Treetype
Optionsdes, message-digest

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

authentication-keychain reference
Synopsis Authentication keychain for unsolicited traffic
Contextconfigure service vprn string ntp authentication-keychain reference
Treeauthentication-keychain

Description

This command configures the authentication keychain used to handle unsolicited NTP requests.

If a request is received with a key ID that matches both a configured key and the keychain, the MAC is checked first using the key information. If the authentication fails, the MAC is checked using the information from the keychain.

Reference

configure system security keychains keychain string

Introduced23.10.R1

Platforms

All

broadcast [interface-name] reference
Synopsis Enter the broadcast list instance
Contextconfigure service vprn string ntp broadcast reference
Treebroadcast
Introduced16.0.R1

Platforms

All

[interface-name] reference
Synopsis Local interface used to transmit NTP broadcast packets
Contextconfigure service vprn string ntp broadcast reference
Treebroadcast

Reference

configure service vprn string interface string

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

authentication-keychain reference
Synopsis Keychain used to authenticate broadcast messages
Contextconfigure service vprn string ntp broadcast reference authentication-keychain reference
Treeauthentication-keychain

Description

This command configures the keychain used to authenticate messages sent by this node.

The keychain infrastructure is queried using this keychain name to get the youngest key used for generating the authentication value for the message. When an NTP packet is received by this node, the keychain infrastructure is queried using the keychain name and the key ID extracted from the received message to get the key used to perform the authentication check. If authentication does not pass, the packet is rejected. Keychain entries also have a direction. The key ID and authentication keychain are mutually exclusive. When neither one is set, for example, the key ID has a value of '0' and the value of this command is empty, no authentication is performed.

Reference

configure system security keychains keychain string

Notes

The following elements are part of a choice: authentication-keychain or key-id.

Introduced23.10.R1

Platforms

All

key-id reference
Synopsis Authentication key and type used by the node
Contextconfigure service vprn string ntp broadcast reference key-id reference
Treekey-id

Reference

configure service vprn string ntp authentication-key number

Notes

The following elements are part of a choice: authentication-keychain or key-id.

Introduced16.0.R1

Platforms

All

ttl number
Synopsis TTL of messages transmitted by the broadcast address
Contextconfigure service vprn string ntp broadcast reference ttl number
Treettl
Range1 to 255
Default127
Introduced 16.0.R1

Platforms

All

version number
Synopsis NTP version number generated by the node
Contextconfigure service vprn string ntp broadcast reference version number
Treeversion
Range2 to 4
Default4
Introduced 16.0.R1

Platforms

All

ospf [ospf-instance] number
Synopsis Enter the ospf list instance
Context configure service vprn string ospf number
Treeospf
Max. Instances32
Introduced16.0.R1

Platforms

All

[ospf-instance] number
Synopsis Specifies the value of the integrated OSPF instance.
Contextconfigure service vprn string ospf number
Treeospf
Range0
MD-CLI Default 0

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the OSPF instance
Contextconfigure service vprn string ospf number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

area [area-id] string
Synopsis Enter the area list instance
Context configure service vprn string ospf number area string
Treearea
Introduced16.0.R1

Platforms

All

[area-id] string
Synopsis Area-ID attribute
Context configure service vprn string ospf number area string
Treearea

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

area-range [ip-prefix-mask] string
Synopsis Enter the area-range list instance
Contextconfigure service vprn string ospf number area string area-range string
Treearea-range
Introduced16.0.R1

Platforms

All

[ip-prefix-mask] string
Synopsis IPv4 unicast address prefix and mask
Context configure service vprn string ospf number area string area-range string
Treearea-range

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

advertise boolean
Synopsis Advertise summarized range of addresses to other areas
Contextconfigure service vprn string ospf number area string area-range string advertise boolean
Treeadvertise
Defaulttrue
Introduced16.0.R1

Platforms

All

interface [interface-name] string
Synopsis Enter the interface list instance
Contextconfigure service vprn string ospf number area string interface string
Treeinterface
Introduced16.0.R1

Platforms

All

[interface-name] string
Synopsis IP interface name
Context configure service vprn string ospf number area string interface string
Treeinterface
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the OSPF interface
Contextconfigure service vprn string ospf number area string interface string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

bfd-liveness
Synopsis Enable the bfd-liveness context
Contextconfigure service vprn string ospf number area string interface string bfd-liveness
Treebfd-liveness
Introduced16.0.R1

Platforms

All

strict boolean
Synopsis Enable BFD strict mode
Context configure service vprn string ospf number area string interface string bfd-liveness strict boolean
Treestrict

Description

When configured to true, the system uses BFD strict-mode. BFD strict-mode mandates that an active BFD session must exist between the OSPF neighbors before establishing a full adjacency. When configured to true, the router uses Link-Local Signaling (LLS) with the B-flag set to instruct the OSPF neighbors that BFD must be enabled on the link. BFD strict-mode requires both sides to have the B-flag set.

During OSPFv3 BFD strict-mode operations, the router advertises the local interface IPv4 address TLV using LLS, but the SR OS router continues to use IPv6-based BFD sessions for both the IPv4 and IPv6 address families.

Defaultfalse
Introduced23.3.R1

Platforms

All

strict-mode-holddown number
Synopsis Adjacency up time delay after BFD session establishment
Contextconfigure service vprn string ospf number area string interface string bfd-liveness strict-mode-holddown number
Treestrict-mode-holddown

Description

This command configures a delay timer before bringing up the OSPF adjacency after the BFD session establishment. Holddown helps mitigate potential routing churn when BFD sessions are unstable. The holddown timer is reset when a BFD session operationally toggles.

Range1 to 600
Unitsseconds
Introduced 23.3.R1

Platforms

All

interface-type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisInterface type
Contextconfigure service vprn string ospf number area string interface string interface-type keyword
Treeinterface-type

Description

This command specifies the interface type.

broadcast - Broadcast network

To significantly improve adjacency forming and network convergence, configure a network as point-to-point if only two routers are connected, even if the network is a broadcast media such as Ethernet.

non-broadcast - Non-broadcast network

point-to-point - Point-to-point link

Set the interface type of an Ethernet link to point-to-point to avoid having to carry the broadcast adjacency maintenance overhead if the Ethernet link provided is used as a point-to-point.

p2mp-nbma - Point-to-multipoint on a link without broadcast or multicast support

No designated router or backup designated router is elected on this type of interface and all OSPF neighbors connect through individual point-to-point links. Only VPRN and IES services interfaces support this interface type.

secondary - Multiple secondary adjacencies allowed

A secondary interface allows multiple secondary adjacencies, in addition to the primary adjacency, to be established over a single IP interface. This interface type can also be applied to the system interface and to loopback interfaces to allow them to participate in multiple areas, although no adjacencies are formed over these types of interfaces.

Optionsbroadcast, non-broadcast, point-to-point, secondary, p2mp-nbma
Introduced16.0.R1

Platforms

All

loopfree-alternate
Synopsis Enter the loopfree-alternate context
Contextconfigure service vprn string ospf number area string interface string loopfree-alternate
Treeloopfree-alternate
Introduced16.0.R3

Platforms

All

policy-map
Synopsis Enable the policy-map context
Context configure service vprn string ospf number area string interface string loopfree-alternate policy-map
Treepolicy-map
Introduced16.0.R3

Platforms

All

lsa-filter-out keyword
Synopsis LSA flooding reduction
Context configure service vprn string ospf number area string interface string lsa-filter-out keyword
Treelsa-filter-out
Optionsnone, all, except-own-rtrlsa, except-own-rtrlsa-and-defaults
Defaultnone
Introduced16.0.R1

Platforms

All

message-digest-key [key-id] number
Synopsis Enter the message-digest-key list instance
Contextconfigure service vprn string ospf number area string interface string message-digest-key number
Treemessage-digest-key
Introduced16.0.R1

Platforms

All

metric number
Synopsis Route cost metric for the interface
Context configure service vprn string ospf number area string interface string metric number
Treemetric
Range1 to 65535
Introduced16.0.R1

Platforms

All

mtu number
Synopsis MTU for the OSPF to use on the interface
Contextconfigure service vprn string ospf number area string interface string mtu number
Treemtu
Range512 to 9786
Introduced16.0.R1

Platforms

All

passive boolean
Synopsis Advertise passive interfaces as OSPF interfaces
Contextconfigure service vprn string ospf number area string interface string passive boolean
Treepassive
Introduced16.0.R1

Platforms

All

poll-interval number
Synopsis Interval for Hellos to non-adjacent OSPF NBMA neighbor
Contextconfigure service vprn string ospf number area string interface string poll-interval number
Treepoll-interval
Max. Range0 to 4294967295
Unitsseconds
Default120
Introduced 16.0.R1

Platforms

All

priority number
Synopsis Interface priority in the DR election on the subnet
Contextconfigure service vprn string ospf number area string interface string priority number
Treepriority
Range0 to 255
Default1
Introduced 16.0.R1

Platforms

All

nssa
Synopsis Enable the nssa context
Context configure service vprn string ospf number area string nssa
Treenssa
Introduced16.0.R1

Platforms

All

area-range [ip-prefix-mask] string
Synopsis Enter the area-range list instance
Contextconfigure service vprn string ospf number area string nssa area-range string
Treearea-range
Introduced16.0.R1

Platforms

All

[ip-prefix-mask] string
Synopsis IPv4 unicast address prefix and mask
Context configure service vprn string ospf number area string nssa area-range string
Treearea-range

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

originate-default-route
Synopsis Enable the originate-default-route context
Contextconfigure service vprn string ospf number area string nssa originate-default-route
Treeoriginate-default-route
Introduced16.0.R1

Platforms

All

summaries boolean
Synopsis Send summary (Type 3) LSAs into the NSSA on an ABR
Contextconfigure service vprn string ospf number area string nssa summaries boolean
Treesummaries
Defaulttrue
Introduced16.0.R1

Platforms

All

sham-link [interface] string ip-address string
Synopsis Enter the sham-link list instance
Contextconfigure service vprn string ospf number area string sham-link string ip-address string
Treesham-link
Introduced16.0.R1

Platforms

All

[interface] string
Synopsis Local interface name used for the sham-link
Contextconfigure service vprn string ospf number area string sham-link string ip-address string
Treesham-link
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

ip-address string
Synopsis IP address of the sham-link neighbor
Context configure service vprn string ospf number area string sham-link string ip-address string
Treesham-link

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

message-digest-key [key-id] number
Synopsis Enter the message-digest-key list instance
Contextconfigure service vprn string ospf number area string sham-link string ip-address string message-digest-key number
Treemessage-digest-key
Introduced16.0.R1

Platforms

All

metric number
Synopsis Explicit route cost metric that is applied to the sham link
Contextconfigure service vprn string ospf number area string sham-link string ip-address string metric number
Treemetric
Range1 to 65535
Default1
Introduced 16.0.R1

Platforms

All

stub
Synopsis Enable the stub context
Context configure service vprn string ospf number area string stub
Treestub
Introduced16.0.R1

Platforms

All

summaries boolean
Synopsis Send summary (Type 3) LSAs into the stub area on an ABR
Contextconfigure service vprn string ospf number area string stub summaries boolean
Treesummaries
Defaulttrue
Introduced16.0.R1

Platforms

All

virtual-link [router-id] string transit-area reference
Synopsis Enter the virtual-link list instance
Contextconfigure service vprn string ospf number area string virtual-link string transit-area reference
Treevirtual-link
Introduced16.0.R1

Platforms

All

transit-area reference
Synopsis Transit area that links backbone area to area without physical connection with the backbone
Contextconfigure service vprn string ospf number area string virtual-link string transit-area reference
Treevirtual-link

Reference

configure service vprn string ospf number area string

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

message-digest-key [key-id] number
Synopsis Enter the message-digest-key list instance
Contextconfigure service vprn string ospf number area string virtual-link string transit-area reference message-digest-key number
Treemessage-digest-key
Introduced16.0.R1

Platforms

All

export-limit
Synopsis Enable the export-limit context
Contextconfigure service vprn string ospf number export-limit
Treeexport-limit
Introduced16.0.R1

Platforms

All

number number
Synopsis Maximum routes or prefixes exported from route table
Contextconfigure service vprn string ospf number export-limit number number
Treenumber
Range1 to 4294967295

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

export-policy reference
Synopsis Export policies that determine exported routes
Contextconfigure service vprn string ospf number export-policy reference
Treeexport-policy

Description

This command configures export routing policies for the routes exported from the routing table to IS-IS.

If the export policy is undefined, the system does not export non IS-IS routes from the routing table manager to IS-IS.

If multiple policy names are specified, the policies are evaluated in the order they are specified. The first policy that matches is applied.

If the aggregate command is also configured in the configure router context, the aggregation is applied before the export policy is applied.

Routing policies are created in the configure router policy-options context.

Reference

configure policy-options policy-statement string

Max. Instances5

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

All

external-db-overflow
Synopsis Enable the external-db-overflow context
Contextconfigure service vprn string ospf number external-db-overflow
Treeexternal-db-overflow
Introduced16.0.R1

Platforms

All

limit number
Synopsis Number of external LSA at which overload is triggered
Contextconfigure service vprn string ospf number external-db-overflow limit number
Treelimit
Range0 to 2147483647
Default0
Introduced 16.0.R1

Platforms

All

graceful-restart
Synopsis Enable the graceful-restart context
Contextconfigure service vprn string ospf number graceful-restart
Treegraceful-restart
Introduced16.0.R1

Platforms

All

ignore-dn-bit boolean
Synopsis Ignore the DN bit for OSPF LSA packets for the instance
Contextconfigure service vprn string ospf number ignore-dn-bit boolean
Treeignore-dn-bit
Defaultfalse
Introduced16.0.R1

Platforms

All

loopfree-alternate
Synopsis Enable the loopfree-alternate context
Contextconfigure service vprn string ospf number loopfree-alternate
Treeloopfree-alternate
Introduced16.0.R1

Platforms

All

exclude
Synopsis Enter the exclude context
Context configure service vprn string ospf number loopfree-alternate exclude
Treeexclude
Introduced16.0.R3

Platforms

All

prefix-policy reference
Synopsis Policy to exclude prefixes from LFA SPF calculation
Contextconfigure service vprn string ospf number loopfree-alternate exclude prefix-policy reference
Treeprefix-policy

Description

This command specifies the name of the policy for the prefixes to exclude from the LFA SPF calculation.

An excluded prefix is not included in LFA calculation regardless of its priority. The prefix tag is, however, used in the main SPF.

Reference

configure policy-options policy-statement string

Max. Instances5

Notes

This element is ordered by the user.

Introduced16.0.R3

Platforms

All

overload boolean
Synopsis Change local router state to appear overloaded
Contextconfigure service vprn string ospf number overload boolean
Treeoverload
Defaultfalse
Introduced16.0.R1

Platforms

All

preference number
Synopsis Preference for OSPF internal routes
Context configure service vprn string ospf number preference number
Treepreference
Range1 to 255
Default10
Introduced 16.0.R1

Platforms

All

reference-bandwidth number
Synopsis Bandwidth to reference default costing of interfaces
Contextconfigure service vprn string ospf number reference-bandwidth number
Treereference-bandwidth
Range1 to 18446744073709551615
Unitskilobps
Default100000000
Introduced 16.0.R1

Platforms

All

rib-priority
Synopsis Enter the rib-priority context
Contextconfigure service vprn string ospf number rib-priority
Treerib-priority
Introduced16.0.R1

Platforms

All

router-id string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisUnique router ID for the OSPF instance
Contextconfigure service vprn string ospf number router-id string
Treerouter-id
Introduced16.0.R1

Platforms

All

rtr-adv-lsa-limit
Synopsis Enable the rtr-adv-lsa-limit context
Contextconfigure service vprn string ospf number rtr-adv-lsa-limit
Treertr-adv-lsa-limit
Introduced16.0.R1

Platforms

All

timers
Synopsis Enter the timers context
Context configure service vprn string ospf number timers
Treetimers
Introduced16.0.R1

Platforms

All

lsa-accumulate number
Synopsis Delay to gather LSAs before advertising to neighbors
Contextconfigure service vprn string ospf number timers lsa-accumulate number
Treelsa-accumulate
Range0 to 1000
Unitsmilliseconds
Default 1000
Introduced16.0.R1

Platforms

All

lsa-arrival number
Synopsis Min delay between receipt of same LSAs from neighbors
Contextconfigure service vprn string ospf number timers lsa-arrival number
Treelsa-arrival
Range0 to 600000
Unitsmilliseconds
Default 1000
Introduced16.0.R1

Platforms

All

lsa-generate
Synopsis Enter the lsa-generate context
Contextconfigure service vprn string ospf number timers lsa-generate
Treelsa-generate
Introduced16.0.R1

Platforms

All

spf-wait
Synopsis Enter the spf-wait context
Context configure service vprn string ospf number timers spf-wait
Treespf-wait
Introduced16.0.R1

Platforms

All

spf-max-wait number
Synopsis Max interval between two consecutive SPF calculations
Contextconfigure service vprn string ospf number timers spf-wait spf-max-wait number
Treespf-max-wait
Range10 to 120000
Unitsmilliseconds
Default10000
Introduced 16.0.R1

Platforms

All

unicast-import boolean
Synopsis Submit routes into the unicast Route Table Manager
Contextconfigure service vprn string ospf number unicast-import boolean
Treeunicast-import
Defaulttrue
Introduced16.0.R1

Platforms

All

vpn-domain
Synopsis Enable the vpn-domain context
Context configure service vprn string ospf number vpn-domain
Treevpn-domain
Introduced16.0.R1

Platforms

All

id string
Synopsis OSPF VPN domain ID
Context configure service vprn string ospf number vpn-domain id string
Treeid

Description

This command specifies the OSPF VPN domain. This is exchanged using BGP in the Extended Community attribute associated with a prefix.

String Length14
Default0000.0000.0000
Introduced 16.0.R1

Platforms

All

type keyword
Synopsis VPN domain type
Context configure service vprn string ospf number vpn-domain type keyword
Treetype
Options0005, 0105, 0205, 8005

Notes

This element is mandatory.

Introduced 16.0.R1

Platforms

All

vpn-tag number
Synopsis OSPF VPN tag
Contextconfigure service vprn string ospf number vpn-tag number
Treevpn-tag
Max. Range0 to 4294967295
Default0
Introduced 16.0.R1

Platforms

All

ospf3 [ospf-instance] number
Synopsis Enter the ospf3 list instance
Context configure service vprn string ospf3 number
Treeospf3
Max. Instances32
Introduced16.0.R1

Platforms

All

[ospf-instance] number
Synopsis Specifies the value of the integrated OSPF instance.
Contextconfigure service vprn string ospf3 number
Treeospf3
Range0 to 31 | 64 to 95
MD-CLI Default0

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the OSPF instance
Contextconfigure service vprn string ospf3 number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

area [area-id] string
Synopsis Enter the area list instance
Context configure service vprn string ospf3 number area string
Treearea
Introduced16.0.R1

Platforms

All

[area-id] string
Synopsis Area-ID attribute
Context configure service vprn string ospf3 number area string
Treearea

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

area-range [ip-prefix-mask] (ipv4-prefix | ipv6-prefix)
Synopsis Enter the area-range list instance
Contextconfigure service vprn string ospf3 number area string area-range (ipv4-prefix | ipv6-prefix)
Treearea-range
Introduced16.0.R1

Platforms

All

[ip-prefix-mask] (ipv4-prefix | ipv6-prefix)
Synopsis Address ranges to create on an ABR for route summarization or suppression
Contextconfigure service vprn string ospf3 number area string area-range (ipv4-prefix | ipv6-prefix)
Treearea-range

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

advertise boolean
Synopsis Advertise summarized range of addresses to other areas
Contextconfigure service vprn string ospf3 number area string area-range (ipv4-prefix | ipv6-prefix) advertise boolean
Treeadvertise
Defaulttrue
Introduced16.0.R1

Platforms

All

interface [interface-name] string
Synopsis Enter the interface list instance
Contextconfigure service vprn string ospf3 number area string interface string
Treeinterface
Introduced16.0.R1

Platforms

All

[interface-name] string
Synopsis IP interface name
Context configure service vprn string ospf3 number area string interface string
Treeinterface
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

authentication
Synopsis Enable the authentication context
Contextconfigure service vprn string ospf3 number area string interface string authentication
Treeauthentication
Introduced16.0.R6

Platforms

All

bfd-liveness
Synopsis Enable the bfd-liveness context
Contextconfigure service vprn string ospf3 number area string interface string bfd-liveness
Treebfd-liveness
Introduced16.0.R1

Platforms

All

strict boolean
Synopsis Enable BFD strict mode
Context configure service vprn string ospf3 number area string interface string bfd-liveness strict boolean
Treestrict

Description

When configured to true, the system uses BFD strict-mode. BFD strict-mode mandates that an active BFD session must exist between the OSPF neighbors before establishing a full adjacency. When configured to true, the router uses Link-Local Signaling (LLS) with the B-flag set to instruct the OSPF neighbors that BFD must be enabled on the link. BFD strict-mode requires both sides to have the B-flag set.

During OSPFv3 BFD strict-mode operations, the router advertises the local interface IPv4 address TLV using LLS, but the SR OS router continues to use IPv6-based BFD sessions for both the IPv4 and IPv6 address families.

Defaultfalse
Introduced23.3.R1

Platforms

All

strict-mode-holddown number
Synopsis Adjacency up time delay after BFD session establishment
Contextconfigure service vprn string ospf3 number area string interface string bfd-liveness strict-mode-holddown number
Treestrict-mode-holddown

Description

This command configures a delay timer before bringing up the OSPF adjacency after the BFD session establishment. Holddown helps mitigate potential routing churn when BFD sessions are unstable. The holddown timer is reset when a BFD session operationally toggles.

Range1 to 600
Unitsseconds
Introduced 23.3.R1

Platforms

All

interface-type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisInterface type
Contextconfigure service vprn string ospf3 number area string interface string interface-type keyword
Treeinterface-type

Description

This command specifies the interface type.

broadcast - Broadcast network

To significantly improve adjacency forming and network convergence, configure a network as point-to-point if only two routers are connected, even if the network is a broadcast media such as Ethernet.

non-broadcast - Non-broadcast network

point-to-point - Point-to-point link

Set the interface type of an Ethernet link to point-to-point to avoid having to carry the broadcast adjacency maintenance overhead if the Ethernet link provided is used as a point-to-point.

p2mp-nbma - Point-to-multipoint on a link without broadcast or multicast support

No designated router or backup designated router is elected on this type of interface and all OSPF neighbors connect through individual point-to-point links. Only VPRN and IES services interfaces support this interface type.

secondary - Multiple secondary adjacencies allowed

A secondary interface allows multiple secondary adjacencies, in addition to the primary adjacency, to be established over a single IP interface. This interface type can also be applied to the system interface and to loopback interfaces to allow them to participate in multiple areas, although no adjacencies are formed over these types of interfaces.

Optionsbroadcast, non-broadcast, point-to-point, secondary, p2mp-nbma
Introduced16.0.R1

Platforms

All

loopfree-alternate
Synopsis Enter the loopfree-alternate context
Contextconfigure service vprn string ospf3 number area string interface string loopfree-alternate
Treeloopfree-alternate
Introduced16.0.R3

Platforms

All

policy-map
Synopsis Enable the policy-map context
Context configure service vprn string ospf3 number area string interface string loopfree-alternate policy-map
Treepolicy-map
Introduced16.0.R3

Platforms

All

lsa-filter-out keyword
Synopsis LSA flooding reduction
Context configure service vprn string ospf3 number area string interface string lsa-filter-out keyword
Treelsa-filter-out
Optionsnone, all, except-own-rtrlsa, except-own-rtrlsa-and-defaults
Defaultnone
Introduced16.0.R1

Platforms

All

metric number
Synopsis Route cost metric for the interface
Context configure service vprn string ospf3 number area string interface string metric number
Treemetric
Range1 to 65535
Introduced16.0.R1

Platforms

All

mtu number
Synopsis MTU for the OSPF to use on the interface
Contextconfigure service vprn string ospf3 number area string interface string mtu number
Treemtu
Range512 to 9786
Introduced16.0.R1

Platforms

All

neighbor [address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Add a list entry for neighbor
Context configure service vprn string ospf3 number area string interface string neighbor (ipv4-address-no-zone | ipv6-address-no-zone)
Treeneighbor
Introduced16.0.R1

Platforms

All

[address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IPv6 link local address of the OSPFv3 neighbor
Contextconfigure service vprn string ospf3 number area string interface string neighbor (ipv4-address-no-zone | ipv6-address-no-zone)
Treeneighbor

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

poll-interval number
Synopsis Interval for Hellos to non-adjacent OSPF NBMA neighbor
Contextconfigure service vprn string ospf3 number area string interface string poll-interval number
Treepoll-interval
Max. Range0 to 4294967295
Unitsseconds
Default120
Introduced 16.0.R1

Platforms

All

priority number
Synopsis Interface priority in the DR election on the subnet
Contextconfigure service vprn string ospf3 number area string interface string priority number
Treepriority
Range0 to 255
Default1
Introduced 16.0.R1

Platforms

All

nssa
Synopsis Enable the nssa context
Context configure service vprn string ospf3 number area string nssa
Treenssa
Introduced16.0.R1

Platforms

All

area-range [ip-prefix-mask] (ipv4-prefix | ipv6-prefix)
Synopsis Enter the area-range list instance
Contextconfigure service vprn string ospf3 number area string nssa area-range (ipv4-prefix | ipv6-prefix)
Treearea-range
Introduced16.0.R1

Platforms

All

[ip-prefix-mask] (ipv4-prefix | ipv6-prefix)
Synopsis Address ranges to create on an ABR for route summarization or suppression
Contextconfigure service vprn string ospf3 number area string nssa area-range (ipv4-prefix | ipv6-prefix)
Treearea-range

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

advertise boolean
Synopsis Advertise summarized range of addresses to other areas
Contextconfigure service vprn string ospf3 number area string nssa area-range (ipv4-prefix | ipv6-prefix) advertise boolean
Treeadvertise
Defaulttrue
Introduced16.0.R1

Platforms

All

originate-default-route
Synopsis Enable the originate-default-route context
Contextconfigure service vprn string ospf3 number area string nssa originate-default-route
Treeoriginate-default-route
Introduced16.0.R1

Platforms

All

summaries boolean
Synopsis Send summary (Type 3) LSAs into the NSSA on an ABR
Contextconfigure service vprn string ospf3 number area string nssa summaries boolean
Treesummaries
Defaulttrue
Introduced16.0.R1

Platforms

All

stub
Synopsis Enable the stub context
Context configure service vprn string ospf3 number area string stub
Treestub
Introduced16.0.R1

Platforms

All

summaries boolean
Synopsis Send summary (Type 3) LSAs into the stub area on an ABR
Contextconfigure service vprn string ospf3 number area string stub summaries boolean
Treesummaries
Defaulttrue
Introduced16.0.R1

Platforms

All

virtual-link [router-id] string transit-area reference
Synopsis Enter the virtual-link list instance
Contextconfigure service vprn string ospf3 number area string virtual-link string transit-area reference
Treevirtual-link
Introduced16.0.R1

Platforms

All

transit-area reference
Synopsis Transit area that links backbone area to area without physical connection with the backbone
Contextconfigure service vprn string ospf3 number area string virtual-link string transit-area reference
Treevirtual-link

Reference

configure service vprn string ospf3 number area string

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

authentication
Synopsis Enable the authentication context
Contextconfigure service vprn string ospf3 number area string virtual-link string transit-area reference authentication
Treeauthentication
Introduced16.0.R6

Platforms

All

export-limit
Synopsis Enable the export-limit context
Contextconfigure service vprn string ospf3 number export-limit
Treeexport-limit
Introduced16.0.R1

Platforms

All

number number
Synopsis Maximum routes or prefixes exported from route table
Contextconfigure service vprn string ospf3 number export-limit number number
Treenumber
Range1 to 4294967295

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

export-policy reference
Synopsis Export policies that determine exported routes
Contextconfigure service vprn string ospf3 number export-policy reference
Treeexport-policy

Description

This command configures export routing policies for the routes exported from the routing table to IS-IS.

If the export policy is undefined, the system does not export non IS-IS routes from the routing table manager to IS-IS.

If multiple policy names are specified, the policies are evaluated in the order they are specified. The first policy that matches is applied.

If the aggregate command is also configured in the configure router context, the aggregation is applied before the export policy is applied.

Routing policies are created in the configure router policy-options context.

Reference

configure policy-options policy-statement string

Max. Instances5

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

All

external-db-overflow
Synopsis Enable the external-db-overflow context
Contextconfigure service vprn string ospf3 number external-db-overflow
Treeexternal-db-overflow
Introduced16.0.R1

Platforms

All

limit number
Synopsis Number of external LSA at which overload is triggered
Contextconfigure service vprn string ospf3 number external-db-overflow limit number
Treelimit
Range0 to 2147483647
Default0
Introduced 16.0.R1

Platforms

All

graceful-restart
Synopsis Enable the graceful-restart context
Contextconfigure service vprn string ospf3 number graceful-restart
Treegraceful-restart
Introduced16.0.R1

Platforms

All

ignore-dn-bit boolean
Synopsis Ignore the DN bit for OSPF LSA packets for the instance
Contextconfigure service vprn string ospf3 number ignore-dn-bit boolean
Treeignore-dn-bit
Defaultfalse
Introduced16.0.R1

Platforms

All

loopfree-alternate
Synopsis Enable the loopfree-alternate context
Contextconfigure service vprn string ospf3 number loopfree-alternate
Treeloopfree-alternate
Introduced16.0.R1

Platforms

All

exclude
Synopsis Enter the exclude context
Context configure service vprn string ospf3 number loopfree-alternate exclude
Treeexclude
Introduced16.0.R3

Platforms

All

prefix-policy reference
Synopsis Policy to exclude prefixes from LFA SPF calculation
Contextconfigure service vprn string ospf3 number loopfree-alternate exclude prefix-policy reference
Treeprefix-policy

Description

This command specifies the name of the policy for the prefixes to exclude from the LFA SPF calculation.

An excluded prefix is not included in LFA calculation regardless of its priority. The prefix tag is, however, used in the main SPF.

Reference

configure policy-options policy-statement string

Max. Instances5

Notes

This element is ordered by the user.

Introduced16.0.R3

Platforms

All

overload boolean
Synopsis Change local router state to appear overloaded
Contextconfigure service vprn string ospf3 number overload boolean
Treeoverload
Defaultfalse
Introduced16.0.R1

Platforms

All

preference number
Synopsis Preference for OSPF internal routes
Context configure service vprn string ospf3 number preference number
Treepreference
Range1 to 255
Default10
Introduced 16.0.R1

Platforms

All

reference-bandwidth number
Synopsis Bandwidth to reference default costing of interfaces
Contextconfigure service vprn string ospf3 number reference-bandwidth number
Treereference-bandwidth
Range1 to 18446744073709551615
Unitskilobps
Default100000000
Introduced 16.0.R1

Platforms

All

rib-priority
Synopsis Enter the rib-priority context
Contextconfigure service vprn string ospf3 number rib-priority
Treerib-priority
Introduced16.0.R1

Platforms

All

router-id string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisUnique router ID for the OSPF instance
Contextconfigure service vprn string ospf3 number router-id string
Treerouter-id
Introduced16.0.R1

Platforms

All

rtr-adv-lsa-limit
Synopsis Enable the rtr-adv-lsa-limit context
Contextconfigure service vprn string ospf3 number rtr-adv-lsa-limit
Treertr-adv-lsa-limit
Introduced16.0.R1

Platforms

All

timers
Synopsis Enter the timers context
Context configure service vprn string ospf3 number timers
Treetimers
Introduced16.0.R1

Platforms

All

lsa-accumulate number
Synopsis Delay to gather LSAs before advertising to neighbors
Contextconfigure service vprn string ospf3 number timers lsa-accumulate number
Treelsa-accumulate
Range0 to 1000
Unitsmilliseconds
Default 1000
Introduced16.0.R1

Platforms

All

lsa-arrival number
Synopsis Min delay between receipt of same LSAs from neighbors
Contextconfigure service vprn string ospf3 number timers lsa-arrival number
Treelsa-arrival
Range0 to 600000
Unitsmilliseconds
Default 1000
Introduced16.0.R1

Platforms

All

lsa-generate
Synopsis Enter the lsa-generate context
Contextconfigure service vprn string ospf3 number timers lsa-generate
Treelsa-generate
Introduced16.0.R1

Platforms

All

spf-wait
Synopsis Enter the spf-wait context
Context configure service vprn string ospf3 number timers spf-wait
Treespf-wait
Introduced16.0.R1

Platforms

All

pcp
Synopsis Enter the pcp context
Context configure service vprn string pcp
Treepcp
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

server [name] string
Synopsis Enter the server list instance
Contextconfigure service vprn string pcp server string
Treeserver
Max. Instances8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis PCP server name
Context configure service vprn string pcp server string
Treeserver
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the PCP server
Contextconfigure service vprn string pcp server string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

description string
Synopsis Text description
Context configure service vprn string pcp server string description string
Treedescription
String Length1 to 80
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

interface [name] reference
Synopsis Add a list entry for interface
Contextconfigure service vprn string pcp server string interface reference
Treeinterface
Max. Instances32
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[name] reference
Synopsis Interface name
Contextconfigure service vprn string pcp server string interface reference
Treeinterface

Reference

configure service vprn string interface string

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

pim
Synopsis Enable the pim context
Context configure service vprn string pim
Treepim
Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of PIM
Context configure service vprn string pim admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

apply-to keyword
Synopsis IES and non-IES interfaces to create in PIM
Contextconfigure service vprn string pim apply-to keyword
Treeapply-to
Optionsall, none
Default none
Introduced16.0.R1

Platforms

All

bgp-nh-override boolean
Synopsis Disable VRF import EC support for next-hop resolution
Contextconfigure service vprn string pim bgp-nh-override boolean
Treebgp-nh-override

Description

When configured to true, the RPF check is performed using IPv4 VPN AF next-hop instead of IPv4 AF VRF import extended community (EC).

When configured to false, the RPF check is performed using IPv4 AF VRF import EC.

Defaultfalse
Introduced19.7.R1

Platforms

All

import
Synopsis Enter the import context
Context configure service vprn string pim import
Treeimport
Introduced16.0.R1

Platforms

All

interface [interface-name] string
Synopsis Enter the interface list instance
Contextconfigure service vprn string pim interface string
Treeinterface
Introduced16.0.R1

Platforms

All

[interface-name] string
Synopsis Interface name
Contextconfigure service vprn string pim interface string
Treeinterface
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of the PIM interface
Contextconfigure service vprn string pim interface string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

assert-period number
Synopsis Time for periodic refreshes of PIM Assert messages on an interface
Contextconfigure service vprn string pim interface string assert-period number
Treeassert-period
Range1 to 300
Default60
Introduced 16.0.R1

Platforms

All

bfd-liveness
Synopsis Enter the bfd-liveness context
Contextconfigure service vprn string pim interface string bfd-liveness
Treebfd-liveness
Introduced16.0.R1

Platforms

All

ipv4 boolean
Synopsis Use Bidirectional Forwarding Detection for IPv4 on PIM interface
Contextconfigure service vprn string pim interface string bfd-liveness ipv4 boolean
Treeipv4
Defaultfalse
Introduced16.0.R1

Platforms

All

ipv6 boolean
Synopsis Use Bidirectional Forwarding Detection for IPv6 on PIM interface
Contextconfigure service vprn string pim interface string bfd-liveness ipv6 boolean
Treeipv6
Defaultfalse
Introduced16.0.R1

Platforms

All

ipv4
Synopsis Enter the ipv4 context
Context configure service vprn string pim interface string ipv4
Treeipv4
Introduced16.0.R1

Platforms

All

monitor-oper-group
Synopsis Enter the monitor-oper-group context
Contextconfigure service vprn string pim interface string ipv4 monitor-oper-group
Treemonitor-oper-group
Introduced16.0.R1

Platforms

All

ipv6
Synopsis Enter the ipv6 context
Context configure service vprn string pim interface string ipv6
Treeipv6
Introduced16.0.R1

Platforms

All

monitor-oper-group
Synopsis Enter the monitor-oper-group context
Contextconfigure service vprn string pim interface string ipv6 monitor-oper-group
Treemonitor-oper-group
Introduced16.0.R1

Platforms

All

max-groups number
Synopsis Maximum number of groups for the interface
Contextconfigure service vprn string pim interface string max-groups number
Treemax-groups
Range0 | 1 to 16000
Default0
Introduced 16.0.R1

Platforms

All

mcac
Synopsis Enter the mcac context
Context configure service vprn string pim interface string mcac
Treemcac
Introduced16.0.R1

Platforms

All

bandwidth
Synopsis Enter the bandwidth context
Context configure service vprn string pim interface string mcac bandwidth
Treebandwidth
Introduced16.0.R1

Platforms

All

mandatory (number | keyword)
Synopsis Pre-reserved bandwidth for all mandatory channels
Contextconfigure service vprn string pim interface string mcac bandwidth mandatory (number | keyword)
Treemandatory
Range0 to 2147483647
Optionsunlimited
Defaultunlimited
Introduced16.0.R1

Platforms

All

total (number | keyword)
Synopsis Maximum allowed bandwidth
Context configure service vprn string pim interface string mcac bandwidth total (number | keyword)
Treetotal
Range0 to 2147483647
Optionsunlimited
Defaultunlimited
Introduced16.0.R1

Platforms

All

mc-constraints
Synopsis Enter the mc-constraints context
Contextconfigure service vprn string pim interface string mcac mc-constraints
Treemc-constraints
Introduced16.0.R1

Platforms

All

level [level-id] number
Synopsis Enter the level list instance
Context configure service vprn string pim interface string mcac mc-constraints level number
Treelevel
Introduced16.0.R1

Platforms

All

number-down [number-lag-port-down] number
Synopsis Enter the number-down list instance
Contextconfigure service vprn string pim interface string mcac mc-constraints number-down number
Treenumber-down
Introduced16.0.R1

Platforms

All

level number
Synopsis Level ID to associate with number of down LAG ports
Contextconfigure service vprn string pim interface string mcac mc-constraints number-down number level number
Treelevel

Description

This command specifies the bandwidth for a given level. Level 1 has the highest priority and level 8 has the lowest priority.

Range1 to 8

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

use-lag-port-weight boolean
Synopsis Use LAG port weight in calculating MCAC constraints
Contextconfigure service vprn string pim interface string mcac mc-constraints use-lag-port-weight boolean
Treeuse-lag-port-weight

Description

When configured to true, port weight is used when determining available bandwidth per level when LAG ports go down or come up. This command is required for proper operation on mixed port-speed LAGs and can also be used for unmixed port-speed LAGs.

Defaultfalse
Introduced16.0.R1

Platforms

All

policy reference
Synopsis Multicast CAC policy name
Context configure service vprn string pim interface string mcac policy reference
Treepolicy

Description

This command configures the name of the global channel bandwidth definition policy that is used for (H)MCAC and HQoS adjustment.

Within the scope of HQoS adjustment, the channel definition policy under the group interface is used if redirection is unconfigured. In this case, the HQoS adjustment can be applied to IPoE subscribers in per-SAP replication mode.

If redirection is configured, the channel bandwidth definition policy applied under the Layer 3 redirected interface is in effect.

Hierarchical MCAC (HMCAC) is supported on two levels simultaneously:

  • subscriber level and redirected interface when redirection is configured

  • subscriber level and group-interface level when redirection is unconfigured

In HMCAC, the subscriber is checked against its bandwidth limits first, then against the bandwidth limits of the redirected or group interface. If redirection is configured but the policy is referenced only under the group interface, no admission control is executed (HMCAC or MCAC).

Reference

configure mcac policy string

Introduced16.0.R1

Platforms

All

p2mp-ldp-tree-join
Synopsis Enter the p2mp-ldp-tree-join context
Contextconfigure service vprn string pim interface string p2mp-ldp-tree-join
Treep2mp-ldp-tree-join
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ipv4 boolean
Synopsis Allow dynamic mLDP in-band signaling for IPv4 PIM joins
Contextconfigure service vprn string pim interface string p2mp-ldp-tree-join ipv4 boolean
Treeipv4
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ipv6 boolean
Synopsis Allow dynamic mLDP in-band signaling for IPv6 PIM joins
Contextconfigure service vprn string pim interface string p2mp-ldp-tree-join ipv6 boolean
Treeipv6
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

priority number
Synopsis DR election priority for this interface
Contextconfigure service vprn string pim interface string priority number
Treepriority
Range1 to 4294967295
Default1
Introduced 16.0.R1

Platforms

All

ipv4
Synopsis Enter the ipv4 context
Context configure service vprn string pim ipv4
Treeipv4
Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of PIM operation for IPv4
Contextconfigure service vprn string pim ipv4 admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

All

grt-extranet
Synopsis Enter the grt-extranet context
Contextconfigure service vprn string pim ipv4 grt-extranet
Treegrt-extranet
Introduced16.0.R1

Platforms

All

any
Synopsis GRT or VRF extranet for the instance
Context configure service vprn string pim ipv4 grt-extranet any
Treeany

Notes

The following elements are part of a choice: any or group-prefix.

Introduced16.0.R1

Platforms

All

group-prefix [ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis Enter the group-prefix list instance
Contextconfigure service vprn string pim ipv4 grt-extranet group-prefix (ipv4-prefix | ipv6-prefix)
Treegroup-prefix

Notes

The following elements are part of a choice: any or group-prefix.

Introduced16.0.R1

Platforms

All

rpf-table keyword
Synopsis Route table for RPF lookup
Context configure service vprn string pim ipv4 rpf-table keyword
Treerpf-table
Optionsrtable-m, rtable-u, both
Defaultrtable-u
Introduced16.0.R1

Platforms

All

source-address
Synopsis Enter the source-address context
Contextconfigure service vprn string pim ipv4 source-address
Treesource-address

Description

Commands in this context configure the source IP address for PIM messages.

Introduced23.3.R1

Platforms

All

register-message string
Synopsis Source IPv4 address for PIM register messages
Contextconfigure service vprn string pim ipv4 source-address register-message string
Treeregister-message

Description

This command configures the source IPv4 address for register messages in this PIM instance. The IP address can be set to any unicast address, regardless of whether it resides on the node. Ensure that the specified IP address is configured on the router as a loopback or interface IP address.

When unconfigured, the source IP address for register messages is selected by choosing the smallest IP address from available interfaces on the node.

Introduced23.3.R1

Platforms

All

ipv6
Synopsis Enter the ipv6 context
Context configure service vprn string pim ipv6
Treeipv6
Introduced16.0.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of PIM operation for IPv6
Contextconfigure service vprn string pim ipv6 admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

All

rpf-table keyword
Synopsis Route table for RPF lookup
Context configure service vprn string pim ipv6 rpf-table keyword
Treerpf-table
Optionsrtable-m, rtable-u, both
Defaultrtable-u
Introduced16.0.R1

Platforms

All

source-address
Synopsis Enter the source-address context
Contextconfigure service vprn string pim ipv6 source-address
Treesource-address

Description

Commands in this context configure the source IP address for PIM messages.

Introduced23.3.R1

Platforms

All

register-message string
Synopsis Source IPv6 address for PIM register messages
Contextconfigure service vprn string pim ipv6 source-address register-message string
Treeregister-message

Description

This command configures the source IPv6 address for register messages in this PIM instance. The IP address can be set to any unicast address, regardless of whether it resides on the node. Ensure that the specified IP address is configured on the router as a loopback or interface IP address.

When unconfigured, the source IP address for register messages is selected by choosing the smallest IP address from available interfaces on the node.

Introduced23.3.R1

Platforms

All

mtu-over-head number
Synopsis MVPN tunnel MTU size reduction to allow for BIER header
Contextconfigure service vprn string pim mtu-over-head number
Treemtu-over-head

Description

This command subtracts the specified value from the MVPN tunnel MTU to allow a BIER header to be added without exceeding the network MTU.

Range0 | 44 | 76 | 140 | 268 | 536
Default0
Introduced 20.5.R1

Platforms

All

rp
Synopsis Enter the rp context
Context configure service vprn string pim rp
Treerp
Introduced16.0.R1

Platforms

All

bootstrap
Synopsis Enter the bootstrap context
Context configure service vprn string pim rp bootstrap
Treebootstrap
Introduced16.0.R1

Platforms

All

ipv4
Synopsis Enter the ipv4 context
Context configure service vprn string pim rp ipv4
Treeipv4
Introduced16.0.R1

Platforms

All

anycast [ipv4-address] string rp-set-peer string
Synopsis Add a list entry for anycast
Context configure service vprn string pim rp ipv4 anycast string rp-set-peer string
Treeanycast
Introduced16.0.R1

Platforms

All

[ipv4-address] string
Synopsis Loopback IP address shared by routes in RP set
Contextconfigure service vprn string pim rp ipv4 anycast string rp-set-peer string
Treeanycast

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

rp-set-peer string
Synopsis Configure a peer in the anycast rp-set.
Contextconfigure service vprn string pim rp ipv4 anycast string rp-set-peer string
Treeanycast

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

auto-rp-discovery boolean
Synopsis Enable auto-RP discovery mode and auto-RP listener
Contextconfigure service vprn string pim rp ipv4 auto-rp-discovery boolean
Treeauto-rp-discovery

Description

When configured to true, the system enables the auto-RP protocol in discovery mode and the auto-RP listener functionality.

See "Automatic discovery of group-to-RP mappings (auto-RP)" in the 7450 ESS, 7750 SR, 7950 XRS, and VSR Multicast Routing Protocols Guide for more information about the auto-RP protocol and configuration guidelines.

Defaultfalse
Introduced16.0.R1

Platforms

All

bsr-candidate
Synopsis Enter the bsr-candidate context
Contextconfigure service vprn string pim rp ipv4 bsr-candidate
Treebsr-candidate
Introduced16.0.R1

Platforms

All

candidate boolean
Synopsis Enable auto-RP to advertise candidate RP information
Contextconfigure service vprn string pim rp ipv4 candidate boolean
Treecandidate

Description

When configured to true, the auto-RP is enabled to advertise the candidate RP information. The auto-RP candidate RP announces the candidate RP messages on the 224.0.1.39 multicast address. This functionality is in addition to the listener functionality enabled by the auto RP discovery.

When configured to false, the candidate RP information is not specified.

Defaultfalse
Introduced20.10.R1

Platforms

All

mapping-agent boolean
Synopsis Enable the mapping agent on the node
Context configure service vprn string pim rp ipv4 mapping-agent boolean
Treemapping-agent

Description

When configured to true, the mapping agent is enabled on the node. The auto-RP MA observes the auto-rp-announcement messages, selects the RP and generates the RP discovery 224.0.1.40 messages. This functionality is in addition to the auto-RP discovery functionality.

Defaultfalse
Introduced20.10.R1

Platforms

All

rp-candidate
Synopsis Enter the rp-candidate context
Contextconfigure service vprn string pim rp ipv4 rp-candidate
Treerp-candidate
Introduced16.0.R1

Platforms

All

address string
Synopsis Local RP address
Context configure service vprn string pim rp ipv4 rp-candidate address string
Treeaddress

Description

This command specifies the local RP address that is sent in the RP candidate advertisements to the Bootstrap Router.

Introduced16.0.R1

Platforms

All

holdtime number
Synopsis Time during which the neighboring router considers this router to be up
Contextconfigure service vprn string pim rp ipv4 rp-candidate holdtime number
Treeholdtime
Range5 to 255
Unitsseconds
Default 150
Introduced16.0.R1

Platforms

All

static
Synopsis Enter the static context
Context configure service vprn string pim rp ipv4 static
Treestatic
Introduced16.0.R1

Platforms

All

address [ipv4-address] string
Synopsis Enter the address list instance
Contextconfigure service vprn string pim rp ipv4 static address string
Treeaddress
Introduced16.0.R1

Platforms

All

[ipv4-address] string
Synopsis IPv4 address for the static RP
Context configure service vprn string pim rp ipv4 static address string
Treeaddress

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

ipv6
Synopsis Enter the ipv6 context
Context configure service vprn string pim rp ipv6
Treeipv6
Introduced16.0.R1

Platforms

All

anycast [ipv6-address] string rp-set-peer string
Synopsis Add a list entry for anycast
Context configure service vprn string pim rp ipv6 anycast string rp-set-peer string
Treeanycast
Introduced16.0.R1

Platforms

All

[ipv6-address] string
Synopsis Loopback IP address shared by routes in RP set
Contextconfigure service vprn string pim rp ipv6 anycast string rp-set-peer string
Treeanycast

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

bsr-candidate
Synopsis Enter the bsr-candidate context
Contextconfigure service vprn string pim rp ipv6 bsr-candidate
Treebsr-candidate
Introduced16.0.R1

Platforms

All

embedded-rp
Synopsis Enable the embedded-rp context
Contextconfigure service vprn string pim rp ipv6 embedded-rp
Treeembedded-rp
Introduced16.0.R1

Platforms

All

rp-candidate
Synopsis Enter the rp-candidate context
Contextconfigure service vprn string pim rp ipv6 rp-candidate
Treerp-candidate
Introduced16.0.R1

Platforms

All

holdtime number
Synopsis Time during which the neighboring router considers this router to be up
Contextconfigure service vprn string pim rp ipv6 rp-candidate holdtime number
Treeholdtime
Range5 to 255
Unitsseconds
Default 150
Introduced16.0.R1

Platforms

All

static
Synopsis Enter the static context
Context configure service vprn string pim rp ipv6 static
Treestatic
Introduced16.0.R1

Platforms

All

address [ipv6-address] string
Synopsis Enter the address list instance
Contextconfigure service vprn string pim rp ipv6 static address string
Treeaddress
Introduced16.0.R1

Platforms

All

[ipv6-address] string
Synopsis Static IP address of the RP
Context configure service vprn string pim rp ipv6 static address string
Treeaddress

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

spt-switchover [ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis Enter the spt-switchover list instance
Contextconfigure service vprn string pim spt-switchover (ipv4-prefix | ipv6-prefix)
Treespt-switchover
Introduced16.0.R1

Platforms

All

[ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis IP address and mask length
Context configure service vprn string pim spt-switchover (ipv4-prefix | ipv6-prefix)
Treespt-switchover

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

threshold (number | keyword)
Synopsis SPT switchover threshold
Context configure service vprn string pim spt-switchover (ipv4-prefix | ipv6-prefix) threshold (number | keyword)
Treethreshold
Range1 to 4294967294
Unitskilobps
Options infinity

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

ssm-groups
Synopsis Enter the ssm-groups context
Context configure service vprn string pim ssm-groups
Treessm-groups
Introduced16.0.R1

Platforms

All

radius
Synopsis Enter the radius context
Context configure service vprn string radius
Treeradius
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

proxy [name] string
Synopsis Enter the proxy list instance
Context configure service vprn string radius proxy string
Treeproxy
Max. Instances8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis RADIUS proxy name
Context configure service vprn string radius proxy string
Treeproxy
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of RADIUS proxy
Context configure service vprn string radius proxy string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

attribute-matching
Synopsis Enter the attribute-matching context
Contextconfigure service vprn string radius proxy string attribute-matching
Treeattribute-matching
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

entry [index] number
Synopsis Enter the entry list instance
Context configure service vprn string radius proxy string attribute-matching entry number
Treeentry
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[index] number
Synopsis Index of this entry
Context configure service vprn string radius proxy string attribute-matching entry number
Treeentry
Range1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

type number
Synopsis Matching attribute type to RADIUS server policy
Contextconfigure service vprn string radius proxy string attribute-matching type number
Treetype
Range1 to 255
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

vendor (number | keyword)
Synopsis Matching Vendor ID to RADIUS server policy
Contextconfigure service vprn string radius proxy string attribute-matching vendor (number | keyword)
Treevendor
Range1 to 16777215
Optionsnokia
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

cache
Synopsis Enter the cache context
Context configure service vprn string radius proxy string cache
Treecache
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the RADIUS proxy cache
Contextconfigure service vprn string radius proxy string cache admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

key
Synopsis Enable the key context
Context configure service vprn string radius proxy string cache key
Treekey
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

attribute-type number
Synopsis RADIUS attribute type to cache for this RADIUS proxy server
Contextconfigure service vprn string radius proxy string cache key attribute-type number
Treeattribute-type
Range1 to 255

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

packet-type keyword
Synopsis Packet type of the RADIUS messages
Context configure service vprn string radius proxy string cache key packet-type keyword
Treepacket-type
Optionsaccess-request, access-accept

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

vendor (number | keyword)
Synopsis RADIUS Vendor ID
Context configure service vprn string radius proxy string cache key vendor (number | keyword)
Treevendor
Range1 to 16777215
Optionsnokia
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

timeout number
Synopsis Idle timeout value
Context configure service vprn string radius proxy string cache timeout number
Treetimeout
Range60 to 3600
Unitsseconds
Default 300
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

track-accounting
Synopsis Enter the track-accounting context
Contextconfigure service vprn string radius proxy string cache track-accounting
Treetrack-accounting
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

start boolean
Synopsis Update host with client that generated accounting-start
Contextconfigure service vprn string radius proxy string cache track-accounting start boolean
Treestart
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

stop boolean
Synopsis Remove ESM host and forward accounting-stop packet
Contextconfigure service vprn string radius proxy string cache track-accounting stop boolean
Treestop
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

track-authentication
Synopsis Enter the track-authentication context
Contextconfigure service vprn string radius proxy string cache track-authentication
Treetrack-authentication
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

defaults
Synopsis Enter the defaults context
Context configure service vprn string radius proxy string defaults
Treedefaults
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

description string
Synopsis Text description
Context configure service vprn string radius proxy string description string
Treedescription
String Length1 to 80
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

interface [interface-name] reference
Synopsis Add a list entry for interface
Contextconfigure service vprn string radius proxy string interface reference
Treeinterface
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[interface-name] reference
Synopsis IP interface name
Context configure service vprn string radius proxy string interface reference
Treeinterface

Reference

configure service vprn string interface string

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

load-balance-key
Synopsis Enter the load-balance-key context
Contextconfigure service vprn string radius proxy string load-balance-key
Treeload-balance-key
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

attribute-1
Synopsis Enter the attribute-1 context
Context configure service vprn string radius proxy string load-balance-key attribute-1
Treeattribute-1

Notes

The following elements are part of a choice: (attribute-1, attribute-2, attribute-3, attribute-4, and attribute-5) or source-ip-udp.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

attribute-2
Synopsis Enter the attribute-2 context
Context configure service vprn string radius proxy string load-balance-key attribute-2
Treeattribute-2

Notes

The following elements are part of a choice: (attribute-1, attribute-2, attribute-3, attribute-4, and attribute-5) or source-ip-udp.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

attribute-3
Synopsis Enter the attribute-3 context
Context configure service vprn string radius proxy string load-balance-key attribute-3
Treeattribute-3

Notes

The following elements are part of a choice: (attribute-1, attribute-2, attribute-3, attribute-4, and attribute-5) or source-ip-udp.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

attribute-4
Synopsis Enter the attribute-4 context
Context configure service vprn string radius proxy string load-balance-key attribute-4
Treeattribute-4

Notes

The following elements are part of a choice: (attribute-1, attribute-2, attribute-3, attribute-4, and attribute-5) or source-ip-udp.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

attribute-5
Synopsis Enter the attribute-5 context
Context configure service vprn string radius proxy string load-balance-key attribute-5
Treeattribute-5

Notes

The following elements are part of a choice: (attribute-1, attribute-2, attribute-3, attribute-4, and attribute-5) or source-ip-udp.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

source-ip-udp
Synopsis Key to consist of the source IP address and source UDP port of the RADIUS message
Contextconfigure service vprn string radius proxy string load-balance-key source-ip-udp
Treesource-ip-udp

Notes

The following elements are part of a choice: (attribute-1, attribute-2, attribute-3, attribute-4, and attribute-5) or source-ip-udp.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

purpose keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPurpose of the RADIUS proxy
Contextconfigure service vprn string radius proxy string purpose keyword
Treepurpose
Optionsaccounting, authentication, accounting-authentication

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

secret string
Synopsis Format of the secret key to access the RADIUS proxy server
Contextconfigure service vprn string radius proxy string secret string
Treesecret
String Length1 to 115
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

wlan-gw
Synopsis Enter the wlan-gw context
Context configure service vprn string radius proxy string wlan-gw
Treewlan-gw
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

address string
Synopsis IPv4 address of the distributed RADIUS proxy server
Contextconfigure service vprn string radius proxy string wlan-gw address string
Treeaddress

Description

This command configures the IPv4 address of the distributed RADIUS proxy server for use by the access points.

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

ipv6-address string
Synopsis IPv6 address of the distributed RADIUS proxy server
Contextconfigure service vprn string radius proxy string wlan-gw ipv6-address string
Treeipv6-address

Description

This command configures the IPv6 address of the distributed RADIUS proxy server for use by the access points.

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

wlan-gw-group reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisISA WLAN gateway group
Contextconfigure service vprn string radius proxy string wlan-gw-group reference
Treewlan-gw-group

Reference

configure isa wlan-gw-group number

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

server [name] string
Synopsis Enter the server list instance
Contextconfigure service vprn string radius server string
Treeserver
Max. Instances64
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis External RADIUS server name
Context configure service vprn string radius server string
Treeserver
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

accept-coa boolean
Synopsis Process Change of Authorization (CoA) messages
Contextconfigure service vprn string radius server string accept-coa boolean
Treeaccept-coa
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

acct-port number
Synopsis UDP port number of the RADIUS for accounting events
Contextconfigure service vprn string radius server string acct-port number
Treeacct-port
Range1 to 65535
Default1813
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the RADIUS server
Context configure service vprn string radius server string address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeaddress

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

auth-port number
Synopsis UDP port number of the RADIUS to be used as match criteria
Contextconfigure service vprn string radius server string auth-port number
Treeauth-port
Range1 to 65535
Default1812
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

description string
Synopsis Text description
Context configure service vprn string radius server string description string
Treedescription
String Length1 to 80
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

secret string
Synopsis Secret key associated with this RADIUS server
Contextconfigure service vprn string radius server string secret string
Treesecret
String Length1 to 115

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

reassembly
Synopsis Enable the reassembly context
Context configure service vprn string reassembly
Treereassembly
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

nat-group number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNAT group (including WLAN Gateway group) that executes the reassembly
Contextconfigure service vprn string reassembly nat-group number
Treenat-group
Max. Range0 to 4294967295
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

to-base-network boolean
Synopsis Allow reassembled traffic sent to network interface
Contextconfigure service vprn string reassembly to-base-network boolean
Treeto-base-network
Defaultfalse
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

redundant-interface [interface-name] string
Synopsis Enter the redundant-interface list instance
Contextconfigure service vprn string redundant-interface string
Treeredundant-interface
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[interface-name] string
Synopsis Interface name
Contextconfigure service vprn string redundant-interface string
Treeredundant-interface
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the interface
Contextconfigure service vprn string redundant-interface string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

hold-time
Synopsis Enter the hold-time context
Context configure service vprn string redundant-interface string hold-time
Treehold-time
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv4
Synopsis Enter the ipv4 context
Context configure service vprn string redundant-interface string hold-time ipv4
Treeipv4
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

down
Synopsis Enter the down context
Context configure service vprn string redundant-interface string hold-time ipv4 down
Treedown

Description

Commands in this context configure the down hold timer, which specifies the delay before activating the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface up, unless an operator configures the init-only command. 

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

init-only boolean
Synopsis Apply delay only at interface configuration or reboot
Contextconfigure service vprn string redundant-interface string hold-time ipv4 down init-only boolean
Treeinit-only

Description

This command applies a delay only when the IP interface is first configured or after a system reboot.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

up
Synopsis Enter the up context
Context configure service vprn string redundant-interface string hold-time ipv4 up
Treeup

Description

Commands in this context configure the up hold timer, which specifies the delay before deactivation of the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface down.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ip-mtu number
Synopsis IP MTU applied to outgoing packets
Context configure service vprn string redundant-interface string ip-mtu number
Treeip-mtu

Description

This command configures the IP maximum transmission unit (MTU) for the associated router IP interface.

Range512 to 9786
Unitsbytes
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv4
Synopsis Enter the ipv4 context
Context configure service vprn string redundant-interface string ipv4
Treeipv4
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

primary
Synopsis Enable the primary context
Context configure service vprn string redundant-interface string ipv4 primary
Treeprimary
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

address string
Synopsis IPv4 address to be assigned to the interface
Contextconfigure service vprn string redundant-interface string ipv4 primary address string
Treeaddress

Notes

This element is mandatory.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

spoke-sdp [sdp-bind-id] string
Synopsis Enter the spoke-sdp list instance
Contextconfigure service vprn string redundant-interface string spoke-sdp string
Treespoke-sdp
Max. Instances1
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[sdp-bind-id] string
Synopsis SDP binding ID
Contextconfigure service vprn string redundant-interface string spoke-sdp string
Treespoke-sdp
String Length3 to 16

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the SDP binding to the service
Contextconfigure service vprn string redundant-interface string spoke-sdp string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

egress
Synopsis Enter the egress context
Context configure service vprn string redundant-interface string spoke-sdp string egress
Treeegress
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

filter
Synopsis Enter the filter context
Context configure service vprn string redundant-interface string spoke-sdp string egress filter
Treefilter
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEgress MPLS VC label to send packets to the far end
Contextconfigure service vprn string redundant-interface string spoke-sdp string egress vc-label number
Treevc-label
Range16 to 1048575
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ingress
Synopsis Enter the ingress context
Context configure service vprn string redundant-interface string spoke-sdp string ingress
Treeingress
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

filter
Synopsis Enter the filter context
Context configure service vprn string redundant-interface string spoke-sdp string ingress filter
Treefilter
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

vc-label number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIngress MPLS VC label to send packets to the far end
Contextconfigure service vprn string redundant-interface string spoke-sdp string ingress vc-label number
Treevc-label
Range1 to 1048575
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

rip
Synopsis Enable the rip context
Context configure service vprn string rip
Treerip
Introduced16.0.R4

Platforms

All

admin-state keyword
Synopsis Administrative state of the RIP instance
Contextconfigure service vprn string rip admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R4

Platforms

All

authentication-key string
Synopsis Authentication password passed between RIP neighbors
Contextconfigure service vprn string rip authentication-key string
Treeauthentication-key

Description

This command sets the authentication password to be passed between RIP neighbors. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes.

The authentication type and authentication key must match exactly for the RIP message to be considered authentic and processed.

When unconfigured, this command removes the authentication password from the configuration and disables authentication.

String Length1 to 51
Introduced16.0.R4

Platforms

All

authentication-type keyword
Synopsis Authentication type used between RIP neighbors
Contextconfigure service vprn string rip authentication-type keyword
Treeauthentication-type

Description

This command sets the type of authentication to be used between RIP neighbors.

The authentication type and authentication key must match exactly for the RIP message to be considered authentic and processed.

When unconfigured, this command removes the authentication type from the configuration and effectively disables authentication.

Optionsnone, password, md5, md20
Default none
Introduced16.0.R4

Platforms

All

bfd-liveness boolean
Synopsis Enable BFD to control the state of protocol adjacency
Contextconfigure service vprn string rip bfd-liveness boolean
Treebfd-liveness

Description

When configured to true, this command enables BFD to control the state of the associated protocol adjacency.

When configured to false, this command removes BFD from the associated protocol adjacency.

Defaultfalse
Introduced16.0.R4

Platforms

All

check-zero boolean
Synopsis Enable checking of mandatory zero fields
Contextconfigure service vprn string rip check-zero boolean
Treecheck-zero

Description

When configured to true, this command enables checking of the mandatory zero fields in the RIPv1 and RIPv2 specifications and rejecting non-compliant RIP messages.

When configured to false, this command disables the check and allows the receipt of RIP messages even if the mandatory zero fields are non-zero.

Defaultfalse
Introduced16.0.R4

Platforms

All

export-limit
Synopsis Enable the export-limit context
Contextconfigure service vprn string rip export-limit
Treeexport-limit
Introduced16.0.R4

Platforms

All

number number
Synopsis Maximum routes or prefixes exported from route table
Contextconfigure service vprn string rip export-limit number number
Treenumber
Range1 to 4294967295

Notes

This element is mandatory.

Introduced16.0.R4

Platforms

All

group [group-name] string
Synopsis Enter the group list instance
Context configure service vprn string rip group string
Treegroup
Introduced16.0.R4

Platforms

All

[group-name] string
Synopsis RIP group name
Contextconfigure service vprn string rip group string
Treegroup
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

All

admin-state keyword
Synopsis Administrative state of RIP neighbor interface group
Contextconfigure service vprn string rip group string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R4

Platforms

All

authentication-key string
Synopsis Authentication password passed between RIP neighbors
Contextconfigure service vprn string rip group string authentication-key string
Treeauthentication-key

Description

This command sets the authentication password to be passed between RIP neighbors. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes.

The authentication type and authentication key must match exactly for the RIP message to be considered authentic and processed.

When unconfigured, the authentication password is removed from the configuration and authentication is disabled.

String Length1 to 51
Introduced16.0.R4

Platforms

All

authentication-type keyword
Synopsis Authentication type
Context configure service vprn string rip group string authentication-type keyword
Treeauthentication-type

Description

This command configures the type of authentication to be used.

The authentication type and authentication key must match exactly for the RIP message to be considered authentic and processed.

When unconfigured, this command removes the authentication type from the configuration and effectively disables authentication.

Optionsnone, password, md5, md20
Introduced 16.0.R4

Platforms

All

bfd-liveness boolean
Synopsis Enable BFD to control the state of protocol adjacency
Contextconfigure service vprn string rip group string bfd-liveness boolean
Treebfd-liveness

Description

When configured to true, this command enables BFD to control the state of the associated protocol adjacency.

When configured to false, this command removes BFD from the associated protocol adjacency.

Introduced16.0.R4

Platforms

All

check-zero boolean
Synopsis Enable checking of mandatory zero fields
Contextconfigure service vprn string rip group string check-zero boolean
Treecheck-zero

Description

When configured to true, this command enables checking of the mandatory zero fields in the RIPv1 and RIPv2 specifications and rejecting non-compliant RIP messages.

When configured to false, this command disables the check and allows the receipt of RIP messages even if the mandatory zero fields are non-zero.

Introduced16.0.R4

Platforms

All

export-policy reference
Synopsis Policies used to rule which routes are exported to RIP
Contextconfigure service vprn string rip group string export-policy reference
Treeexport-policy

Description

This command specifies the export route policies used to determine which routes are exported to RIP.

If multiple policy names are specified, the policies are evaluated in the order they are specified. The first policy that matches is applied.

Reference

configure policy-options policy-statement string

Max. Instances5

Notes

This element is ordered by the user.

Introduced16.0.R4

Platforms

All

import-policy reference
Synopsis Policies to decide routes accepted from RIP neighbors
Contextconfigure service vprn string rip group string import-policy reference
Treeimport-policy

Description

This command configures import route policies to determine which routes are accepted from RIP neighbors.

If multiple policy names are specified, the policies are evaluated in the order they are specified. The first policy that matches is applied.

Reference

configure policy-options policy-statement string

Max. Instances5

Notes

This element is ordered by the user.

Introduced16.0.R4

Platforms

All

metric-in number
Synopsis Metric added to routes received from a RIP neighbor
Contextconfigure service vprn string rip group string metric-in number
Treemetric-in
Range1 to 16
Introduced16.0.R4

Platforms

All

metric-out number
Synopsis Metric added to routes exported into RIP
Contextconfigure service vprn string rip group string metric-out number
Treemetric-out
Range1 to 16
Introduced16.0.R4

Platforms

All

neighbor [interface-name] string
Synopsis Enter the neighbor list instance
Contextconfigure service vprn string rip group string neighbor string
Treeneighbor
Introduced16.0.R4

Platforms

All

[interface-name] string
Synopsis IP interface name
Context configure service vprn string rip group string neighbor string
Treeneighbor
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

All

admin-state keyword
Synopsis Administrative state of the RIP neighbor interface
Contextconfigure service vprn string rip group string neighbor string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R4

Platforms

All

authentication-key string
Synopsis Authentication password passed between RIP neighbors
Contextconfigure service vprn string rip group string neighbor string authentication-key string
Treeauthentication-key

Description

This command sets the authentication password to be passed between RIP neighbors. If the string contains special characters (#, $, spaces, and so on), the entire string must be enclosed within double quotes.

The authentication type and authentication key must match exactly for the RIP message to be considered authentic and processed.

When unconfigured, this command removes the authentication password from the configuration and disables authentication.

String Length1 to 51
Introduced16.0.R4

Platforms

All

authentication-type keyword
Synopsis Authentication type
Context configure service vprn string rip group string neighbor string authentication-type keyword
Treeauthentication-type

Description

This command configures the type of authentication to be used.

The authentication type and authentication key must match exactly for the RIP message to be considered authentic and processed.

When unconfigured, this command removes the authentication type from the configuration and effectively disables authentication.

Optionsnone, password, md5, md20
Introduced 16.0.R4

Platforms

All

bfd-liveness boolean
Synopsis Enable BFD to control the state of protocol adjacency
Contextconfigure service vprn string rip group string neighbor string bfd-liveness boolean
Treebfd-liveness

Description

When configured to true, this command enables BFD to control the state of the associated protocol adjacency.

When configured to false, this command removes BFD from the associated protocol adjacency.

Introduced16.0.R4

Platforms

All

check-zero boolean
Synopsis Enable checking of mandatory zero fields
Contextconfigure service vprn string rip group string neighbor string check-zero boolean
Treecheck-zero

Description

When configured to true, this command enables checking of the mandatory zero fields in the RIPv1 and RIPv2 specifications and rejecting non-compliant RIP messages.

When configured to false, this command disables the check and allows the receipt of RIP messages even if the mandatory zero fields are non-zero.

Introduced16.0.R4

Platforms

All

export-policy reference
Synopsis Policies used to rule which routes are exported to RIP
Contextconfigure service vprn string rip group string neighbor string export-policy reference
Treeexport-policy

Description

This command specifies the export route policies used to determine which routes are exported to RIP.

If multiple policy names are specified, the policies are evaluated in the order they are specified. The first policy that matches is applied.

Reference

configure policy-options policy-statement string

Max. Instances5

Notes

This element is ordered by the user.

Introduced16.0.R4

Platforms

All

import-policy reference
Synopsis Policies to decide routes accepted from RIP neighbors
Contextconfigure service vprn string rip group string neighbor string import-policy reference
Treeimport-policy

Description

This command configures import route policies to determine which routes are accepted from RIP neighbors.

If multiple policy names are specified, the policies are evaluated in the order they are specified. The first policy that matches is applied.

Reference

configure policy-options policy-statement string

Max. Instances5

Notes

This element is ordered by the user.

Introduced16.0.R4

Platforms

All

receive keyword
Synopsis Accepted version on received packets
Context configure service vprn string rip group string neighbor string receive keyword
Treereceive
Optionsversion-1, version-2, both, none
Introduced 16.0.R4

Platforms

All

send keyword
Synopsis RIP version and method used to send RIP updates
Contextconfigure service vprn string rip group string neighbor string send keyword
Treesend
Optionsnone, version-1, broadcast, multicast, unicast
Introduced16.0.R4

Platforms

All

split-horizon boolean
Synopsis Enable split horizon and poison reverse
Contextconfigure service vprn string rip group string neighbor string split-horizon boolean
Treesplit-horizon

Description

When configured to true, this command enables the use of split horizon with poison reverse. Split-horizon with poison reverse means that routes learned from a neighbor through a given interface are advertised in updates out of the same interface but with a metric of 16 (infinity).

When configured to false. this command enables split horizon without poison reverse. This allows the routes to be re-advertised on interfaces other than the interface that learned the route, with the advertised metric equaling an increment of the metric-in value.

Introduced16.0.R4

Platforms

All

timers
Synopsis Enable the timers context
Context configure service vprn string rip group string neighbor string timers
Treetimers
Introduced16.0.R4

Platforms

All

flush number
Synopsis RIP flush timer
Context configure service vprn string rip group string neighbor string timers flush number
Treeflush

Description

This command specifies the time a route is maintained in the RIP database after it has been declared invalid. When the timer expires, the route is flushed from the RIP database completely.

Range1 to 1200
Unitsseconds

Notes

This element is mandatory.

Introduced 16.0.R4

Platforms

All

timeout number
Synopsis RIP timeout timer
Context configure service vprn string rip group string neighbor string timers timeout number
Treetimeout

Description

This command specifies the RIP timeout timer. If a route is not updated by the time the timer expires, the route is declared invalid, but the route is maintained in the RIP database.

Range1 to 1200
Unitsseconds

Notes

This element is mandatory.

Introduced 16.0.R4

Platforms

All

update number
Synopsis Timer that controls the frequency of updates
Contextconfigure service vprn string rip group string neighbor string timers update number
Treeupdate
Range1 to 600
Unitsseconds

Notes

This element is mandatory.

Introduced 16.0.R4

Platforms

All

receive keyword
Synopsis Accepted version on received packets
Context configure service vprn string rip group string receive keyword
Treereceive
Optionsversion-1, version-2, both, none
Introduced 16.0.R4

Platforms

All

send keyword
Synopsis RIP version and method used to send RIP updates
Contextconfigure service vprn string rip group string send keyword
Treesend
Optionsnone, version-1, broadcast, multicast
Introduced 16.0.R4

Platforms

All

split-horizon boolean
Synopsis Enable split horizon and poison reverse
Contextconfigure service vprn string rip group string split-horizon boolean
Treesplit-horizon

Description

When configured to true, this command enables the use of split horizon with poison reverse. Split-horizon with poison reverse means that routes learned from a neighbor through a given interface are advertised in updates out of the same interface but with a metric of 16 (infinity).

When configured to false. this command enables split horizon without poison reverse. This allows the routes to be re-advertised on interfaces other than the interface that learned the route, with the advertised metric equaling an increment of the metric-in value.

Introduced16.0.R4

Platforms

All

timers
Synopsis Enable the timers context
Context configure service vprn string rip group string timers
Treetimers
Introduced16.0.R4

Platforms

All

flush number
Synopsis RIP flush timer
Context configure service vprn string rip group string timers flush number
Treeflush

Description

This command specifies the time a route is maintained in the RIP database after it has been declared invalid. When the timer expires, the route is flushed from the RIP database completely.

Range1 to 1200
Unitsseconds

Notes

This element is mandatory.

Introduced 16.0.R4

Platforms

All

timeout number
Synopsis RIP timeout timer
Context configure service vprn string rip group string timers timeout number
Treetimeout

Description

This command specifies the RIP timeout timer. If a route is not updated by the time the timer expires, the route is declared invalid, but the route is maintained in the RIP database.

Range1 to 1200
Unitsseconds

Notes

This element is mandatory.

Introduced 16.0.R4

Platforms

All

update number
Synopsis Timer that controls the frequency of updates
Contextconfigure service vprn string rip group string timers update number
Treeupdate
Range1 to 600
Unitsseconds

Notes

This element is mandatory.

Introduced 16.0.R4

Platforms

All

message-size number
Synopsis Maximum number of routes in the RIP message
Contextconfigure service vprn string rip message-size number
Treemessage-size
Range25 to 255
Default25
Introduced 16.0.R4

Platforms

All

metric-in number
Synopsis Metric added to routes received from a RIP neighbor
Contextconfigure service vprn string rip metric-in number
Treemetric-in
Range1 to 16
Default1
Introduced 16.0.R4

Platforms

All

metric-out number
Synopsis Metric added to routes exported into RIP
Contextconfigure service vprn string rip metric-out number
Treemetric-out
Range1 to 16
Default1
Introduced 16.0.R4

Platforms

All

preference number
Synopsis Route preference
Context configure service vprn string rip preference number
Treepreference
Range1 to 255
Default100
Introduced 16.0.R4

Platforms

All

propagate-metric boolean
Synopsis Enable the BGP MED used to configure the RIP metric
Contextconfigure service vprn string rip propagate-metric boolean
Treepropagate-metric

Description

When configured to true, this command enables the BGP MED to be used to configure the RIP metric at the BGP to RIP transition on egress routers.

When configured to false, this command sets the RIP metric to the optional value configured with the metric-out command plus one.

Defaultfalse
Introduced16.0.R4

Platforms

All

receive keyword
Synopsis Accepted version on received packets
Context configure service vprn string rip receive keyword
Treereceive
Optionsversion-1, version-2, both, none
Default both
Introduced16.0.R4

Platforms

All

send keyword
Synopsis RIP version and method used to send RIP updates
Contextconfigure service vprn string rip send keyword
Treesend
Optionsnone, version-1, broadcast, multicast
Default broadcast
Introduced16.0.R4

Platforms

All

split-horizon boolean
Synopsis Enable split horizon and poison reverse
Contextconfigure service vprn string rip split-horizon boolean
Treesplit-horizon

Description

When configured to true, this command enables the use of split horizon with poison reverse. Split-horizon with poison reverse means that routes learned from a neighbor through a given interface are advertised in updates out of the same interface but with a metric of 16 (infinity).

When configured to false. this command enables split horizon without poison reverse. This allows the routes to be re-advertised on interfaces other than the interface that learned the route, with the advertised metric equaling an increment of the metric-in value.

Defaulttrue
Introduced16.0.R4

Platforms

All

timers
Synopsis Enable the timers context
Context configure service vprn string rip timers
Treetimers
Introduced16.0.R4

Platforms

All

flush number
Synopsis RIP flush timer
Context configure service vprn string rip timers flush number
Treeflush

Description

This command specifies the time a route is maintained in the RIP database after it has been declared invalid. When the timer expires, the route is flushed from the RIP database completely.

Range1 to 1200
Unitsseconds

Notes

This element is mandatory.

Introduced 16.0.R4

Platforms

All

timeout number
Synopsis RIP timeout timer
Context configure service vprn string rip timers timeout number
Treetimeout

Description

This command specifies the RIP timeout timer. If a route is not updated by the time the timer expires, the route is declared invalid, but the route is maintained in the RIP database.

Range1 to 1200
Unitsseconds

Notes

This element is mandatory.

Introduced 16.0.R4

Platforms

All

update number
Synopsis Timer that controls the frequency of updates
Contextconfigure service vprn string rip timers update number
Treeupdate
Range1 to 600
Unitsseconds

Notes

This element is mandatory.

Introduced 16.0.R4

Platforms

All

ripng
Synopsis Enable the ripng context
Context configure service vprn string ripng
Treeripng
Introduced16.0.R4

Platforms

All

admin-state keyword
Synopsis Administrative state of the RIPng instance
Contextconfigure service vprn string ripng admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R4

Platforms

All

bfd-liveness boolean
Synopsis Enable BFD to control the state of protocol adjacency
Contextconfigure service vprn string ripng bfd-liveness boolean
Treebfd-liveness

Description

When configured to true, this command enables BFD to control the state of the associated protocol adjacency.

When configured to false, this command removes BFD from the associated protocol adjacency.

Defaultfalse
Introduced16.0.R4

Platforms

All

check-zero boolean
Synopsis Enable checking of mandatory zero fields
Contextconfigure service vprn string ripng check-zero boolean
Treecheck-zero

Description

When configured to true, this command enables checking of the mandatory zero fields in the RIPv1 and RIPv2 specifications and rejecting non-compliant RIP messages.

When configured to false, this command disables the check and allows the receipt of RIP messages even if the mandatory zero fields are non-zero.

Defaultfalse
Introduced16.0.R4

Platforms

All

export-limit
Synopsis Enable the export-limit context
Contextconfigure service vprn string ripng export-limit
Treeexport-limit
Introduced16.0.R4

Platforms

All

number number
Synopsis Maximum routes or prefixes exported from route table
Contextconfigure service vprn string ripng export-limit number number
Treenumber
Range1 to 4294967295

Notes

This element is mandatory.

Introduced16.0.R4

Platforms

All

group [group-name] string
Synopsis Enter the group list instance
Context configure service vprn string ripng group string
Treegroup
Introduced16.0.R4

Platforms

All

[group-name] string
Synopsis RIP group name
Contextconfigure service vprn string ripng group string
Treegroup
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

All

admin-state keyword
Synopsis Administrative state of RIPng neighbor interface group
Contextconfigure service vprn string ripng group string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R4

Platforms

All

bfd-liveness boolean
Synopsis Enable BFD to control the state of protocol adjacency
Contextconfigure service vprn string ripng group string bfd-liveness boolean
Treebfd-liveness

Description

When configured to true, this command enables BFD to control the state of the associated protocol adjacency.

When configured to false, this command removes BFD from the associated protocol adjacency.

Introduced16.0.R4

Platforms

All

check-zero boolean
Synopsis Enable checking of mandatory zero fields
Contextconfigure service vprn string ripng group string check-zero boolean
Treecheck-zero

Description

When configured to true, this command enables checking of the mandatory zero fields in the RIPv1 and RIPv2 specifications and rejecting non-compliant RIP messages.

When configured to false, this command disables the check and allows the receipt of RIP messages even if the mandatory zero fields are non-zero.

Introduced16.0.R4

Platforms

All

export-policy reference
Synopsis Policies used to rule which routes are exported to RIP
Contextconfigure service vprn string ripng group string export-policy reference
Treeexport-policy

Description

This command specifies the export route policies used to determine which routes are exported to RIP.

If multiple policy names are specified, the policies are evaluated in the order they are specified. The first policy that matches is applied.

Reference

configure policy-options policy-statement string

Max. Instances5

Notes

This element is ordered by the user.

Introduced16.0.R4

Platforms

All

import-policy reference
Synopsis Policies to decide routes accepted from RIP neighbors
Contextconfigure service vprn string ripng group string import-policy reference
Treeimport-policy

Description

This command configures import route policies to determine which routes are accepted from RIP neighbors.

If multiple policy names are specified, the policies are evaluated in the order they are specified. The first policy that matches is applied.

Reference

configure policy-options policy-statement string

Max. Instances5

Notes

This element is ordered by the user.

Introduced16.0.R4

Platforms

All

metric-in number
Synopsis Metric added to routes received from the neighbor
Contextconfigure service vprn string ripng group string metric-in number
Treemetric-in
Range1 to 16
Introduced16.0.R4

Platforms

All

neighbor [interface-name] reference
Synopsis Enter the neighbor list instance
Contextconfigure service vprn string ripng group string neighbor reference
Treeneighbor
Introduced16.0.R4

Platforms

All

bfd-liveness boolean
Synopsis Enable BFD to control the state of protocol adjacency
Contextconfigure service vprn string ripng group string neighbor reference bfd-liveness boolean
Treebfd-liveness

Description

When configured to true, this command enables BFD to control the state of the associated protocol adjacency.

When configured to false, this command removes BFD from the associated protocol adjacency.

Introduced16.0.R4

Platforms

All

check-zero boolean
Synopsis Enable checking of mandatory zero fields
Contextconfigure service vprn string ripng group string neighbor reference check-zero boolean
Treecheck-zero

Description

When configured to true, this command enables checking of the mandatory zero fields in the RIPv1 and RIPv2 specifications and rejecting non-compliant RIP messages.

When configured to false, this command disables the check and allows the receipt of RIP messages even if the mandatory zero fields are non-zero.

Introduced16.0.R4

Platforms

All

export-policy reference
Synopsis Policies used to rule which routes are exported to RIP
Contextconfigure service vprn string ripng group string neighbor reference export-policy reference
Treeexport-policy

Description

This command specifies the export route policies used to determine which routes are exported to RIP.

If multiple policy names are specified, the policies are evaluated in the order they are specified. The first policy that matches is applied.

Reference

configure policy-options policy-statement string

Max. Instances5

Notes

This element is ordered by the user.

Introduced16.0.R4

Platforms

All

import-policy reference
Synopsis Policies to decide routes accepted from RIP neighbors
Contextconfigure service vprn string ripng group string neighbor reference import-policy reference
Treeimport-policy

Description

This command configures import route policies to determine which routes are accepted from RIP neighbors.

If multiple policy names are specified, the policies are evaluated in the order they are specified. The first policy that matches is applied.

Reference

configure policy-options policy-statement string

Max. Instances5

Notes

This element is ordered by the user.

Introduced16.0.R4

Platforms

All

receive keyword
Synopsis Accepted version on received packets
Context configure service vprn string ripng group string neighbor reference receive keyword
Treereceive
Optionsnone, ripng
Introduced 16.0.R4

Platforms

All

send keyword
Synopsis RIPng version and method used to send RIPng updates
Contextconfigure service vprn string ripng group string neighbor reference send keyword
Treesend
Optionsnone, ripng, unicast
Introduced16.0.R4

Platforms

All

split-horizon boolean
Synopsis Enable split horizon and poison reverse
Contextconfigure service vprn string ripng group string neighbor reference split-horizon boolean
Treesplit-horizon

Description

When configured to true, this command enables the use of split horizon with poison reverse. Split-horizon with poison reverse means that routes learned from a neighbor through a given interface are advertised in updates out of the same interface but with a metric of 16 (infinity).

When configured to false. this command enables split horizon without poison reverse. This allows the routes to be re-advertised on interfaces other than the interface that learned the route, with the advertised metric equaling an increment of the metric-in value.

Introduced16.0.R4

Platforms

All

timers
Synopsis Enable the timers context
Context configure service vprn string ripng group string neighbor reference timers
Treetimers
Introduced16.0.R4

Platforms

All

flush number
Synopsis RIP flush timer
Context configure service vprn string ripng group string neighbor reference timers flush number
Treeflush

Description

This command specifies the time a route is maintained in the RIP database after it has been declared invalid. When the timer expires, the route is flushed from the RIP database completely.

Range1 to 1200
Unitsseconds

Notes

This element is mandatory.

Introduced 16.0.R4

Platforms

All

timeout number
Synopsis RIP timeout timer
Context configure service vprn string ripng group string neighbor reference timers timeout number
Treetimeout

Description

This command specifies the RIP timeout timer. If a route is not updated by the time the timer expires, the route is declared invalid, but the route is maintained in the RIP database.

Range1 to 1200
Unitsseconds

Notes

This element is mandatory.

Introduced 16.0.R4

Platforms

All

update number
Synopsis Timer that controls the frequency of updates
Contextconfigure service vprn string ripng group string neighbor reference timers update number
Treeupdate
Range1 to 600
Unitsseconds

Notes

This element is mandatory.

Introduced 16.0.R4

Platforms

All

receive keyword
Synopsis Accepted version on received packets
Context configure service vprn string ripng group string receive keyword
Treereceive
Optionsnone, ripng
Introduced 16.0.R4

Platforms

All

send keyword
Synopsis RIPng version and method used to send RIPng updates
Contextconfigure service vprn string ripng group string send keyword
Treesend
Optionsnone, ripng
Introduced 16.0.R4

Platforms

All

split-horizon boolean
Synopsis Enable split horizon and poison reverse
Contextconfigure service vprn string ripng group string split-horizon boolean
Treesplit-horizon

Description

When configured to true, this command enables the use of split horizon with poison reverse. Split-horizon with poison reverse means that routes learned from a neighbor through a given interface are advertised in updates out of the same interface but with a metric of 16 (infinity).

When configured to false. this command enables split horizon without poison reverse. This allows the routes to be re-advertised on interfaces other than the interface that learned the route, with the advertised metric equaling an increment of the metric-in value.

Introduced16.0.R4

Platforms

All

timers
Synopsis Enable the timers context
Context configure service vprn string ripng group string timers
Treetimers
Introduced16.0.R4

Platforms

All

flush number
Synopsis RIP flush timer
Context configure service vprn string ripng group string timers flush number
Treeflush

Description

This command specifies the time a route is maintained in the RIP database after it has been declared invalid. When the timer expires, the route is flushed from the RIP database completely.

Range1 to 1200
Unitsseconds

Notes

This element is mandatory.

Introduced 16.0.R4

Platforms

All

timeout number
Synopsis RIP timeout timer
Context configure service vprn string ripng group string timers timeout number
Treetimeout

Description

This command specifies the RIP timeout timer. If a route is not updated by the time the timer expires, the route is declared invalid, but the route is maintained in the RIP database.

Range1 to 1200
Unitsseconds

Notes

This element is mandatory.

Introduced 16.0.R4

Platforms

All

update number
Synopsis Timer that controls the frequency of updates
Contextconfigure service vprn string ripng group string timers update number
Treeupdate
Range1 to 600
Unitsseconds

Notes

This element is mandatory.

Introduced 16.0.R4

Platforms

All

message-size number
Synopsis Maximum number of routes in the message
Contextconfigure service vprn string ripng message-size number
Treemessage-size
Range25 to 255
Default25
Introduced 16.0.R4

Platforms

All

metric-in number
Synopsis Metric added to routes received from the neighbor
Contextconfigure service vprn string ripng metric-in number
Treemetric-in
Range1 to 16
Default1
Introduced 16.0.R4

Platforms

All

metric-out number
Synopsis Metric added to routes exported into RIPng
Contextconfigure service vprn string ripng metric-out number
Treemetric-out
Range1 to 16
Default1
Introduced 16.0.R4

Platforms

All

receive keyword
Synopsis Accepted version on received packets
Context configure service vprn string ripng receive keyword
Treereceive
Optionsnone, ripng
Default ripng
Introduced16.0.R4

Platforms

All

send keyword
Synopsis RIPng version and method used to send RIPng updates
Contextconfigure service vprn string ripng send keyword
Treesend
Optionsnone, ripng
Default ripng
Introduced16.0.R4

Platforms

All

split-horizon boolean
Synopsis Enable split horizon and poison reverse
Contextconfigure service vprn string ripng split-horizon boolean
Treesplit-horizon

Description

When configured to true, this command enables the use of split horizon with poison reverse. Split-horizon with poison reverse means that routes learned from a neighbor through a given interface are advertised in updates out of the same interface but with a metric of 16 (infinity).

When configured to false, this command enables split horizon without poison reverse. This allows the routes to be re-advertised on interfaces other than the interface that learned the route, with the advertised metric equaling an increment of the metric-in value.

Defaulttrue
Introduced16.0.R4

Platforms

All

timers
Synopsis Enable the timers context
Context configure service vprn string ripng timers
Treetimers
Introduced16.0.R4

Platforms

All

flush number
Synopsis RIP flush timer
Context configure service vprn string ripng timers flush number
Treeflush

Description

This command specifies the time a route is maintained in the RIP database after it has been declared invalid. When the timer expires, the route is flushed from the RIP database completely.

Range1 to 1200
Unitsseconds

Notes

This element is mandatory.

Introduced 16.0.R4

Platforms

All

timeout number
Synopsis RIP timeout timer
Context configure service vprn string ripng timers timeout number
Treetimeout

Description

This command specifies the RIP timeout timer. If a route is not updated by the time the timer expires, the route is declared invalid, but the route is maintained in the RIP database.

Range1 to 1200
Unitsseconds

Notes

This element is mandatory.

Introduced 16.0.R4

Platforms

All

update number
Synopsis Timer that controls the frequency of updates
Contextconfigure service vprn string ripng timers update number
Treeupdate
Range1 to 600
Unitsseconds

Notes

This element is mandatory.

Introduced 16.0.R4

Platforms

All

router-id string
Synopsis Unique router ID for the router in the AS
Contextconfigure service vprn string router-id string
Treerouter-id
Introduced16.0.R1

Platforms

All

segment-routing-v6 [instance] number
Synopsis Enter the segment-routing-v6 list instance
Contextconfigure service vprn string segment-routing-v6 number
Treesegment-routing-v6
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

[instance] number
Synopsis Segment routing IPv6 instance
Context configure service vprn string segment-routing-v6 number
Treesegment-routing-v6
Range1 to 2

Notes

This element is part of a list key.

Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

locator [locator-name] reference
Synopsis Enter the locator list instance
Contextconfigure service vprn string segment-routing-v6 number locator reference
Treelocator
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

function
Synopsis Enter the function context
Context configure service vprn string segment-routing-v6 number locator reference function
Treefunction

Description

Commands in this context configure the End SID functions for each SRH mode. 

The end-dt4 configuration and the end-dt46 configuration are mutually exclusive.

The end-dt6 configuration and the end-dt46 configuration are mutually exclusive.

Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

end-dt4
Synopsis Enable the end-dt4 context
Context configure service vprn string segment-routing-v6 number locator reference function end-dt4
Treeend-dt4
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

value number
Synopsis SRv6 function value
Context configure service vprn string segment-routing-v6 number locator reference function end-dt4 value number
Treevalue

Description

This command assigns the optional static function value for the routes in the VPRN, VPLS, or Epipe instance.

When unconfigured, the system allocates a value dynamically.

Range1 to 1048575
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

end-dt46
Synopsis Enable the end-dt46 context
Context configure service vprn string segment-routing-v6 number locator reference function end-dt46
Treeend-dt46
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

value number
Synopsis SRv6 function value
Context configure service vprn string segment-routing-v6 number locator reference function end-dt46 value number
Treevalue

Description

This command assigns the optional static function value for the routes in the VPRN, VPLS, or Epipe instance.

When unconfigured, the system allocates a value dynamically.

Range1 to 1048575
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

end-dt6
Synopsis Enable the end-dt6 context
Context configure service vprn string segment-routing-v6 number locator reference function end-dt6
Treeend-dt6
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

value number
Synopsis SRv6 function value
Context configure service vprn string segment-routing-v6 number locator reference function end-dt6 value number
Treevalue

Description

This command assigns the optional static function value for the routes in the VPRN, VPLS, or Epipe instance.

When unconfigured, the system allocates a value dynamically.

Range1 to 1048575
Introduced21.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

micro-segment-locator [locator-name] reference
Synopsis Enter the micro-segment-locator list instance
Contextconfigure service vprn string segment-routing-v6 number micro-segment-locator reference
Treemicro-segment-locator
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

[locator-name] reference
Synopsis Micro-segment SRv6 locator name
Context configure service vprn string segment-routing-v6 number micro-segment-locator reference
Treemicro-segment-locator

Description

This command associates a pre-defined micro-segment SRv6 locator (defined in the configure router segment-routing segment-routing-v6 context) with the SRv6 instance in the service. The same micro-segment locator can be referenced in multiple BGP instances used by IPVPN or EVPN.

Reference

configure router string segment-routing segment-routing-v6 micro-segment-locator string

Notes

This element is part of a list key.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

function
Synopsis Enter the function context
Context configure service vprn string segment-routing-v6 number micro-segment-locator reference function
Treefunction
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

udt4
Synopsis Enable the udt4 context
Context configure service vprn string segment-routing-v6 number micro-segment-locator reference function udt4
Treeudt4

Description

Commands in this context configure the SRv6 uDT4 behavior and the function value that is associated with the SRv6 instance in the service. When configured, decapsulation and table lookup for IPv4 prefixes occur in the VPRN service.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

value number
Synopsis SRv6 function value
Context configure service vprn string segment-routing-v6 number micro-segment-locator reference function udt4 value number
Treevalue

Description

This command assigns the optional static function value for the routes in the VPRN, VPLS, or Epipe instance.

When unconfigured, the system allocates a value dynamically.

Range1 to 1048575
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

udt46
Synopsis Enable the udt46 context
Context configure service vprn string segment-routing-v6 number micro-segment-locator reference function udt46
Treeudt46

Description

The commands in this context configure the SRv6 uDT46 behavior and the function value that is associated with the SRv6 instance in the service. When configured, decapsulation and table lookup for IPv4 and IPv6 prefixes occur in the VPRN service.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

value number
Synopsis SRv6 function value
Context configure service vprn string segment-routing-v6 number micro-segment-locator reference function udt46 value number
Treevalue

Description

This command assigns the optional static function value for the routes in the VPRN, VPLS, or Epipe instance.

When unconfigured, the system allocates a value dynamically.

Range1 to 1048575
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

udt6
Synopsis Enable the udt6 context
Context configure service vprn string segment-routing-v6 number micro-segment-locator reference function udt6
Treeudt6

Description

Commands in this context configure the SRv6 uDT6 behavior and the function value that is associated with the SRv6 instance in the service. When configured, decapsulation and table lookup for IPv6 prefixes occur in the VPRN service.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

value number
Synopsis SRv6 function value
Context configure service vprn string segment-routing-v6 number micro-segment-locator reference function udt6 value number
Treevalue

Description

This command assigns the optional static function value for the routes in the VPRN, VPLS, or Epipe instance.

When unconfigured, the system allocates a value dynamically.

Range1 to 1048575
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR

selective-fib boolean
Synopsis Enable selective FIB
Context configure service vprn string selective-fib boolean
Treeselective-fib
Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

service-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisService ID
Contextconfigure service vprn string service-id number
Treeservice-id
Range1 to 2147483647
Introduced16.0.R1

Platforms

All

sfm-overload
Synopsis Enable the sfm-overload context
Contextconfigure service vprn string sfm-overload
Treesfm-overload
Introduced16.0.R2

Platforms

7450 ESS, 7750 SR-1, 7750 SR-7/12/12e, 7750 SR-a, 7750 SR-e, 7750 SR-2s, 7750 SR-2se, 7750 SR-7s, 7750 SR-14s, 7950 XRS, VSR

holdoff-time number
Synopsis Delay in detecting SFM failures and setting overload
Contextconfigure service vprn string sfm-overload holdoff-time number
Treeholdoff-time
Range1 to 600
Unitsseconds
Introduced 16.0.R2

Platforms

7450 ESS, 7750 SR-1, 7750 SR-7/12/12e, 7750 SR-a, 7750 SR-e, 7750 SR-2s, 7750 SR-2se, 7750 SR-7s, 7750 SR-14s, 7950 XRS, VSR

sgt-qos
Synopsis Enter the sgt-qos context
Context configure service vprn string sgt-qos
Treesgt-qos
Introduced16.0.R1

Platforms

All

dot1p
Synopsis Enter the dot1p context
Context configure service vprn string sgt-qos dot1p
Treedot1p
Introduced16.0.R1

Platforms

All

application [dot1p-app-name] keyword
Synopsis Enter the application list instance
Contextconfigure service vprn string sgt-qos dot1p application keyword
Treeapplication
Introduced16.0.R1

Platforms

All

[dot1p-app-name] keyword
Synopsis Dot1p application ID that generates control traffic
Contextconfigure service vprn string sgt-qos dot1p application keyword
Treeapplication
Optionsarp, isis, pppoe

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

dot1p (keyword | number)
Synopsis Dot1p value to the traffic generated by this application
Contextconfigure service vprn string sgt-qos dot1p application keyword dot1p (keyword | number)
Treedot1p
Range0 to 7
Optionsbe, l2, af, l1, h2, ef, h1, nc
Introduced16.0.R1

Platforms

All

dscp
Synopsis Enter the dscp context
Context configure service vprn string sgt-qos dscp
Treedscp
Introduced16.0.R1

Platforms

All

application [dscp-app-name] keyword
Synopsis Enter the application list instance
Contextconfigure service vprn string sgt-qos dscp application keyword
Treeapplication

Description

Commands in this context configure DSCP remarking for self-generated application traffic.

All packets generated by the configured application instance use the value configured for the DSCP name or value. The instance can be Base, router, VPRN, or management.

The system uses the DSCP value configured in this instance to:

  • set the DSCP bits in the IP packet

  • signal from the CPM to the egress FC QoS policy to set the Ethernet 802.1p and MPLS EXP bits including, PPPoE, and IS-IS packets that do not carry DSCP bits

  • configure the DSCP value in the egress IP header (which the egress QoS policy does not overwrite)

Introduced16.0.R1

Platforms

All

[dscp-app-name] keyword
Synopsis DSCP application ID that generates control traffic
Contextconfigure service vprn string sgt-qos dscp application keyword
Treeapplication

Description

This command configures the DSCP application ID that generates control traffic.

Optionsbgp, dhcp, dns, ftp, icmp, igmp, l2tp, ldp, mld, msdp, ndis, ntp, ospf, pim, radius, rip, rsvp, snmp, snmp-notification, srrp, ssh, syslog, tacplus, telnet, tftp, traceroute, vrrp, ptp, gtp, diameter, pcep, call-trace, bmp, grpc, mtrace2, http, pfcp, ibcp

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

dscp (keyword | number)
Synopsis DSCP value to the traffic generated by this application
Contextconfigure service vprn string sgt-qos dscp application keyword dscp (keyword | number)
Treedscp
Range0 to 63
Optionsbe, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63
Introduced16.0.R1

Platforms

All

dscp-map [dscp-name] keyword
Synopsis Enter the dscp-map list instance
Contextconfigure service vprn string sgt-qos dscp dscp-map keyword
Treedscp-map
Introduced16.0.R2

Platforms

All

[dscp-name] keyword
Synopsis DSCP name mapped to forwarding class
Context configure service vprn string sgt-qos dscp dscp-map keyword
Treedscp-map
Optionsbe, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63

Notes

This element is part of a list key.

Introduced16.0.R2

Platforms

All

fc keyword
Synopsis Value for the forwarding class for this mapping
Contextconfigure service vprn string sgt-qos dscp dscp-map keyword fc keyword
Treefc
Optionsbe, l2, af, l1, h2, ef, h1, nc
Introduced 16.0.R2

Platforms

All

snmp
Synopsis Enter the snmp context
Context configure service vprn string snmp
Treesnmp
Introduced16.0.R5

Platforms

All

access boolean
Synopsis Enable SNMP access for the VPRN service
Contextconfigure service vprn string snmp access boolean
Treeaccess
Defaultfalse
Introduced16.0.R5

Platforms

All

community [community-string] string
Synopsis Enter the community list instance
Contextconfigure service vprn string snmp community string
Treecommunity

Description

Commands in this context set the SNMP community names to be used with the associated VPRN instance. These VPRN community names are used to associate SNMP v1/v2c requests with a particular VPRN context and to return a reply that contains VPRN-specific data or limit SNMP access to data in a specific VPRN instance.

VPRN SNMP communities configured with an access permission of 'r' are automatically associated with the default access group "snmp-vprn-ro” and the “vprn-view” view (read only). VPRN SNMP communities configured with an access permission of 'rw' are automatically associated with the default access group "snmp-vprn” and the “vprn-view” view (read/write).

The community in an SNMP v1/v2 request determines the SNMP context (that is, the VPRN number for accessing SNMP tables) and not the VPRN of the incoming interface on which the request was received. For example, when an SNMP request arrives on VPRN 5 interface “ringo” with a destination IP address equal to the “ringo” interface, but the community in the SNMP request is the community configured against VPRN 101, the SNMP request is processed using the VPRN 101 context. (the response contains information about VPRN 101). Nokia recommends avoiding the use of a simple series of VPRN SNMP community values that are similar to each other (for example, avoid my-vprncomm-1, my-vprn-comm-2, and so on).

Introduced16.0.R5

Platforms

All

[community-string] string
Synopsis SNMP v1/v2c community name associated with the VPRN
Contextconfigure service vprn string snmp community string
Treecommunity
String Length1 to 114

Notes

This element is part of a list key.

Introduced16.0.R5

Platforms

All

source-access-list reference
Synopsis List name used to validate the source IP address
Contextconfigure service vprn string snmp community string source-access-list reference
Treesource-access-list

Description

This command specifies the SNMP source access list to use with the SNMP community. The source access list is used to validate the source IP address of all received SNMP requests that use the community.

Reference

configure system security snmp source-access-list string

Introduced16.0.R5

Platforms

All

source-address
Synopsis Enter the source-address context
Contextconfigure service vprn string source-address
Treesource-address

Description

Commands in this context configure the source address and application to use in all unsolicited packets.

Introduced16.0.R1

Platforms

All

ipv4 [application] keyword
Synopsis Enter the ipv4 list instance
Context configure service vprn string source-address ipv4 keyword
Treeipv4
Introduced16.0.R1

Platforms

All

[application] keyword
Synopsis Application that uses the source IP address
Contextconfigure service vprn string source-address ipv4 keyword
Treeipv4
Optionstelnet, ssh, snmptrap, ping, traceroute, ntp, cflowd, ptp, icmp-error

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

address string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSource IPv4 address
Contextconfigure service vprn string source-address ipv4 keyword address string
Treeaddress

Notes

The following elements are part of a mandatory choice: address or interface-name.

Introduced16.0.R1

Platforms

All

interface-name string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP interface name
Contextconfigure service vprn string source-address ipv4 keyword interface-name string
Treeinterface-name
String Length1 to 32

Notes

The following elements are part of a mandatory choice: address or interface-name.

Introduced16.0.R1

Platforms

All

ipv6 [application] keyword
Synopsis Enter the ipv6 list instance
Context configure service vprn string source-address ipv6 keyword
Treeipv6
Introduced16.0.R1

Platforms

All

[application] keyword
Synopsis Application that uses the source IP address
Contextconfigure service vprn string source-address ipv6 keyword
Treeipv6
Optionstelnet, snmptrap, ping, traceroute, cflowd, ntp, icmp6-error, ssh, ptp

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

address string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSource IPv6 address
Contextconfigure service vprn string source-address ipv6 keyword address string
Treeaddress

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

spoke-sdp [sdp-bind-id] string
Synopsis Enter the spoke-sdp list instance
Contextconfigure service vprn string spoke-sdp string
Treespoke-sdp
Introduced16.0.R1

Platforms

All

[sdp-bind-id] string
Synopsis SDP binding ID
Contextconfigure service vprn string spoke-sdp string
Treespoke-sdp
String Length3 to 16

Notes

This element is part of a list key.

Introduced16.0.R3

Platforms

All

static-routes
Synopsis Enter the static-routes context
Contextconfigure service vprn string static-routes
Treestatic-routes
Introduced16.0.R1

Platforms

All

hold-down
Synopsis Enable the hold-down context
Context configure service vprn string static-routes hold-down
Treehold-down

Description

Commands in this context enable the hold-down time feature globally for static routes in the system.

The static route hold-down time is a mechanism to protect from rapid, fluctuating state changes of static routes resulting from issues with reachability because of link flap.

The commands in this context apply to all static routes in the VPRN and the base router instance in which this hold-down time is configured in.

Introduced16.0.R1

Platforms

All

initial number
Synopsis Value for the initial hold-down time
Context configure service vprn string static-routes hold-down initial number
Treeinitial

Description

This command specifies the initial value of the hold-down time globally for static routes in the system.

When a static route is ready to become active, it remains inactive for the hold-down time before activating the static-route. If, during this hold-down period, the static route becomes inactive again because of factors such as interface failure, the hold-down timer is reset, effectively postponing the activation of the route until the next opportunity.

Range1 to 65535

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

max-value number
Synopsis Maximum value of the hold-down time
Context configure service vprn string static-routes hold-down max-value number
Treemax-value

Description

This command specifies the maximum value of the hold-down time globally for static routes in the system.

Range1 to 65535

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

multiplier number
Synopsis Multiplier of the previous hold-down time
Contextconfigure service vprn string static-routes hold-down multiplier number
Treemultiplier

Description

This command specifies the multiplier value by which the previous hold-down time is multiplied to calculate the new one. This value applies globally for static routes in the system.

Range1 to 10

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

route [ip-prefix] (ipv4-prefix | ipv6-prefix) route-type keyword
Synopsis Enter the route list instance
Context configure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword
Treeroute
Introduced16.0.R1

Platforms

All

[ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis IP prefix and prefix length for the static routes
Contextconfigure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword
Treeroute

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

route-type keyword
Synopsis Static route type
Context configure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword
Treeroute
Optionsunicast, multicast

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

backup-tag number
Synopsis Static route backup tag
Context configure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword backup-tag number
Treebackup-tag

Description

This command associates a 4-byte backup route tag with the static route when the backup next-hop functionality is activated. The tag value is used in route policies to control distribution of the static route into other protocols when the backup next-hop function is activated for the associated static route.

The tag specified at this level of the static route causes the tag values that are configured under the next-hop, black-hole, and indirect contexts of the static route to be ignored.

Range1 to 4294967295
Introduced21.2.R1

Platforms

All

blackhole
Synopsis Enable the blackhole context
Context configure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword blackhole
Treeblackhole
Introduced16.0.R1

Platforms

All

prefix-list
Synopsis Enter the prefix-list context
Context configure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword blackhole prefix-list
Treeprefix-list
Introduced16.0.R1

Platforms

All

community string
Synopsis Community ID associated with the static route
Contextconfigure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword community string
Treecommunity
String Length1 to 72
Max. Instances12

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

All

grt
Synopsis Enable the grt context
Context configure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword grt
Treegrt
Introduced16.0.R1

Platforms

All

indirect [ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Enter the indirect list instance
Contextconfigure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone)
Treeindirect
Introduced16.0.R1

Platforms

All

[ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Next-hop IP address used to reach the destination
Contextconfigure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone)
Treeindirect

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

cpe-check [address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Enter the cpe-check list instance
Contextconfigure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) cpe-check (ipv4-address-no-zone | ipv6-address-no-zone)
Treecpe-check

Description

When configured, this command enables the Customer Premises Equipment (CPE) check feature and specifies the IP address of the target CPE device.

This option initiates a background ICMP ping test to the configured target IP address. The IP address can either be an IPv4 address for IPv4 static routes or an IPv6 address for IPv6 static routes. To avoid possible circular references, the target IP address cannot exist in the same subnet as the static route subnet. This command is mutually exclusive with BFD support on a specific static route.

Note: A node that is sourcing CPE-check packets waits an additional full interval before taking action, which gives the CPE time to respond. For example, with a drop-count of 3 and an interval of 1s, three CPE-check packets are sent out and the node waits for the duration of another interval before acting on the loss. Failure declaration may take extra time depending on the load, interval, and other factors. In line with multitasking, multi-priority operating principles of the node, and the relative priority of cpe-ping, the node paces these minor events.

Max. Instances1
Introduced16.0.R1

Platforms

All

[address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the target CPE device
Context configure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) cpe-check (ipv4-address-no-zone | ipv6-address-no-zone)
Treecpe-check

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

drop-count number
Synopsis Consecutive ping replies missed before CPE deemed down
Contextconfigure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) cpe-check (ipv4-address-no-zone | ipv6-address-no-zone) drop-count number
Treedrop-count
Range1 to 255
Default3
Introduced 16.0.R1

Platforms

All

interval number
Synopsis Interval between ICMP pings to target CPE IP address
Contextconfigure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) cpe-check (ipv4-address-no-zone | ipv6-address-no-zone) interval number
Treeinterval
Range1 to 255
Unitsseconds
Default 1
Introduced16.0.R1

Platforms

All

log boolean
Synopsis Log CPE connectivity checks transitions
Contextconfigure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) cpe-check (ipv4-address-no-zone | ipv6-address-no-zone) log boolean
Treelog
Defaultfalse
Introduced16.0.R1

Platforms

All

preference number
Synopsis Priority of this static route over the routes from different sources
Contextconfigure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) preference number
Treepreference
Range1 to 255
Default5
Introduced 16.0.R1

Platforms

All

prefix-list
Synopsis Enter the prefix-list context
Context configure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) prefix-list
Treeprefix-list
Introduced16.0.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) qos
Treeqos
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

forwarding-class keyword
Synopsis Forwarding class associated with the static route
Contextconfigure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) qos forwarding-class keyword
Treeforwarding-class
Optionsbe, l2, af, l1, h2, ef, h1, nc
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

priority keyword
Synopsis Static route priority
Context configure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) qos priority keyword
Treepriority
Optionslow, high
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

tag number
Synopsis Static route tag
Context configure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword indirect (ipv4-address-no-zone | ipv6-address-no-zone) tag number
Treetag
Range1 to 4294967295
Introduced16.0.R1

Platforms

All

interface [interface-name] string
Synopsis Enter the interface list instance
Contextconfigure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword interface string
Treeinterface
Introduced16.0.R1

Platforms

All

cpe-check [address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Enter the cpe-check list instance
Contextconfigure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword interface string cpe-check (ipv4-address-no-zone | ipv6-address-no-zone)
Treecpe-check

Description

When configured, this command enables the Customer Premises Equipment (CPE) check feature and specifies the IP address of the target CPE device.

This option initiates a background ICMP ping test to the configured target IP address. The IP address can either be an IPv4 address for IPv4 static routes or an IPv6 address for IPv6 static routes. To avoid possible circular references, the target IP address cannot exist in the same subnet as the static route subnet. This command is mutually exclusive with BFD support on a specific static route.

Note: A node that is sourcing CPE-check packets waits an additional full interval before taking action, which gives the CPE time to respond. For example, with a drop-count of 3 and an interval of 1s, three CPE-check packets are sent out and the node waits for the duration of another interval before acting on the loss. Failure declaration may take extra time depending on the load, interval, and other factors. In line with multitasking, multi-priority operating principles of the node, and the relative priority of cpe-ping, the node paces these minor events.

Max. Instances1
Introduced16.0.R1

Platforms

All

[address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the target CPE device
Context configure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword interface string cpe-check (ipv4-address-no-zone | ipv6-address-no-zone)
Treecpe-check

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

prefix-list
Synopsis Enter the prefix-list context
Context configure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword interface string prefix-list
Treeprefix-list
Introduced16.0.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword interface string qos
Treeqos
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ipsec-tunnel [ipsec-tunnel-name] string
Synopsis Enter the ipsec-tunnel list instance
Contextconfigure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword ipsec-tunnel string
Treeipsec-tunnel
Introduced16.0.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword ipsec-tunnel string qos
Treeqos
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

next-hop [ip-address] (ipv4-address-with-zone | ipv6-address-with-zone)
Synopsis Enter the next-hop list instance
Contextconfigure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone)
Treenext-hop
Introduced16.0.R1

Platforms

All

[ip-address] (ipv4-address-with-zone | ipv6-address-with-zone)
Synopsis Next-hop IP address used to reach the destination
Contextconfigure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone)
Treenext-hop

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

backup-next-hop
Synopsis Enter the backup-next-hop context
Contextconfigure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) backup-next-hop
Treebackup-next-hop

Description

Commands in this context configure static route entry fast failover.

Introduced21.2.R1

Platforms

All

address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Backup next-hop IP address
Context configure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) backup-next-hop address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeaddress

Description

This command specifies the backup IP forwarding address that is used for static route Fast ReRoute (FRR). The configured address, if reachable, acts as pre-installed backup forwarding information that can be used when the primary IP next-hop suddenly fails.

The configured backup next-hop IP address can be directly or indirectly connected (using an IGP or tunnel) to the node. The backup next-hop forwarding information or the Next-hop Label Forwarding Entry (NHLFE) tunnel forwarding information from the IP Routing Table Manager (RTM) is used to preconfigure an IP fast-reroute backup path.

One backup next-hop address can protect a single primary static route entry next-hop address without ECMP and it is only activated when the primary next-hop has no active ECMP.

The configured IP address can be either on the network or the access side.

Introduced21.2.R1

Platforms

All

cpe-check [address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Enter the cpe-check list instance
Contextconfigure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) cpe-check (ipv4-address-no-zone | ipv6-address-no-zone)
Treecpe-check
Max. Instances1
Introduced16.0.R1

Platforms

All

[address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the target CPE device
Context configure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) cpe-check (ipv4-address-no-zone | ipv6-address-no-zone)
Treecpe-check

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

drop-count number
Synopsis Consecutive ping replies missed before CPE deemed down
Contextconfigure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) cpe-check (ipv4-address-no-zone | ipv6-address-no-zone) drop-count number
Treedrop-count
Range1 to 255
Default3
Introduced 16.0.R1

Platforms

All

interval number
Synopsis Interval between ICMP pings to target CPE IP address
Contextconfigure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) cpe-check (ipv4-address-no-zone | ipv6-address-no-zone) interval number
Treeinterval
Range1 to 255
Unitsseconds
Default 1
Introduced16.0.R1

Platforms

All

log boolean
Synopsis Log CPE connectivity checks transitions
Contextconfigure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) cpe-check (ipv4-address-no-zone | ipv6-address-no-zone) log boolean
Treelog
Defaultfalse
Introduced16.0.R1

Platforms

All

preference number
Synopsis Priority of this static route over the routes from different sources
Contextconfigure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) preference number
Treepreference
Range1 to 255
Default5
Introduced 16.0.R1

Platforms

All

prefix-list
Synopsis Enter the prefix-list context
Context configure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) prefix-list
Treeprefix-list
Introduced16.0.R1

Platforms

All

qos
Synopsis Enter the qos context
Context configure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) qos
Treeqos
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

forwarding-class keyword
Synopsis Forwarding class associated with the static route
Contextconfigure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) qos forwarding-class keyword
Treeforwarding-class
Optionsbe, l2, af, l1, h2, ef, h1, nc
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

priority keyword
Synopsis Static route priority
Context configure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) qos priority keyword
Treepriority
Optionslow, high
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

tag number
Synopsis Static route tag
Context configure service vprn string static-routes route (ipv4-prefix | ipv6-prefix) route-type keyword next-hop (ipv4-address-with-zone | ipv6-address-with-zone) tag number
Treetag
Range1 to 4294967295
Introduced16.0.R1

Platforms

All

subscriber-interface [interface-name] string
Synopsis Enter the subscriber-interface list instance
Contextconfigure service vprn string subscriber-interface string
Treesubscriber-interface
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[interface-name] string
Synopsis Subscriber interface name
Context configure service vprn string subscriber-interface string
Treesubscriber-interface
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the subscriber interface
Contextconfigure service vprn string subscriber-interface string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

fwd-service reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisConfigure the forwarding service.
Contextconfigure service vprn string subscriber-interface string fwd-service reference
Treefwd-service

Reference

configure service vprn string

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

group-interface [group-interface-name] string
Synopsis Enter the group-interface list instance
Contextconfigure service vprn string subscriber-interface string group-interface string
Treegroup-interface
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[group-interface-name] string
Synopsis Group interface name
Context configure service vprn string subscriber-interface string group-interface string
Treegroup-interface
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

bonding-parameters
Synopsis Enter the bonding-parameters context
Contextconfigure service vprn string subscriber-interface string group-interface string bonding-parameters
Treebonding-parameters
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

connection [connection-index] number
Synopsis Enter the connection list instance
Contextconfigure service vprn string subscriber-interface string group-interface string bonding-parameters connection number
Treeconnection
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

fpe reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisFPE that provisions bonding functionality
Contextconfigure service vprn string subscriber-interface string group-interface string bonding-parameters fpe reference
Treefpe

Reference

configure fwd-path-ext fpe number

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

multicast
Synopsis Enter the multicast context
Context configure service vprn string subscriber-interface string group-interface string bonding-parameters multicast
Treemulticast
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

connection (number | keyword)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMulticast connection
Contextconfigure service vprn string subscriber-interface string group-interface string bonding-parameters multicast connection (number | keyword)
Treeconnection
Range1 to 2
Optionsuse-incoming
Defaultuse-incoming
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

brg
Synopsis Enter the brg context
Context configure service vprn string subscriber-interface string group-interface string brg
Treebrg
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

cflowd-parameters
Synopsis Enter the cflowd-parameters context
Contextconfigure service vprn string subscriber-interface string group-interface string cflowd-parameters
Treecflowd-parameters
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

sampling [sampling-type] keyword
Synopsis Enter the sampling list instance
Contextconfigure service vprn string subscriber-interface string group-interface string cflowd-parameters sampling keyword
Treesampling
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[sampling-type] keyword
Synopsis Traffic sampling type
Context configure service vprn string subscriber-interface string group-interface string cflowd-parameters sampling keyword
Treesampling

Description

This command configures the type of traffic to be sampled on the associated IP interface.

Optionsunicast, multicast, both

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

direction keyword
Synopsis Direction of traffic for cflowd sampling
Contextconfigure service vprn string subscriber-interface string group-interface string cflowd-parameters sampling keyword direction keyword
Treedirection

Description

This command configures the direction in which sampling occurs on the associated IP interfaces.

Optionsingress-only, egress-only, both
Defaultingress-only
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

type keyword
Synopsis Type of cflowd analysis
Context configure service vprn string subscriber-interface string group-interface string cflowd-parameters sampling keyword type keyword
Treetype

Description

This command configures the cflowd sampling type on the associated IP interface.

Optionsacl, interface

Notes

This element is mandatory.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

data-trigger
Synopsis Enter the data-trigger context
Contextconfigure service vprn string subscriber-interface string group-interface string data-trigger
Treedata-trigger
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

accept-ipv6-link-local-address boolean
Synopsis Enable IPv6 Link Local Address to start authentication
Contextconfigure service vprn string subscriber-interface string group-interface string data-trigger accept-ipv6-link-local-address boolean
Treeaccept-ipv6-link-local-address

Description

When configured to true, the system triggers authentication of the subscriber based on an IPv6 packet with a source IP Link Local Address (LLA). The authentication trigger only occurs if the anti-spoof is type nh-mac. If the anti-spoof is not nh-mac, the packet with an IPv6 LLA is ignored.

When configured to false, the system ignores all IPv6 packets with a LLA as a source IP address.

Defaultfalse
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

dynamic-routes-track-srrp
Synopsis Enable the dynamic-routes-track-srrp context
Contextconfigure service vprn string subscriber-interface string group-interface string dynamic-routes-track-srrp
Treedynamic-routes-track-srrp
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

gtp-parameters
Synopsis Enter the gtp-parameters context
Contextconfigure service vprn string subscriber-interface string group-interface string gtp-parameters
Treegtp-parameters
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

fpe reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPE that provisions the GTP user interface
Contextconfigure service vprn string subscriber-interface string group-interface string gtp-parameters fpe reference
Treefpe

Reference

configure fwd-path-ext fpe number

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

ingress
Synopsis Enter the ingress context
Context configure service vprn string subscriber-interface string group-interface string ingress
Treeingress
Introduced19.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipoe-linking
Synopsis Enter the ipoe-linking context
Contextconfigure service vprn string subscriber-interface string group-interface string ipoe-linking
Treeipoe-linking
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

gratuitous-router-advertisement boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSend unsolicited router advertisement after DHCP setup
Contextconfigure service vprn string subscriber-interface string group-interface string ipoe-linking gratuitous-router-advertisement boolean
Treegratuitous-router-advertisement
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

shared-circuit-id boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable circuit ID in DHCPv4 Option82 to validate DHCPv6
Contextconfigure service vprn string subscriber-interface string group-interface string ipoe-linking shared-circuit-id boolean
Treeshared-circuit-id
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipoe-session
Synopsis Enter the ipoe-session context
Contextconfigure service vprn string subscriber-interface string group-interface string ipoe-session
Treeipoe-session
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

force-auth
Synopsis Enter the force-auth context
Context configure service vprn string subscriber-interface string group-interface string ipoe-session force-auth
Treeforce-auth
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipoe-session-policy reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPoE Session policy to be used for new sessions
Contextconfigure service vprn string subscriber-interface string group-interface string ipoe-session ipoe-session-policy reference
Treeipoe-session-policy

Reference

configure subscriber-mgmt ipoe-session-policy string

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

stateless-redundancy boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRemove IPoE sessions when the system becomes stand-by in a stateless multi-chassis redundancy setup
Contextconfigure service vprn string subscriber-interface string group-interface string ipoe-session stateless-redundancy boolean
Treestateless-redundancy
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv4
Synopsis Enter the ipv4 context
Context configure service vprn string subscriber-interface string group-interface string ipv4
Treeipv4
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

arp-host
Synopsis Enter the arp-host context
Context configure service vprn string subscriber-interface string group-interface string ipv4 arp-host
Treearp-host
Introduced16.0.R6

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

bfd
Synopsis Enter the bfd context
Context configure service vprn string subscriber-interface string group-interface string ipv4 bfd
Treebfd

Description

Commands in this context configure the attributes of bidirectional forwarding detection (BFD) sessions that control the state of ESM dynamic BGP peers.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

multiplier number
Synopsis Number of consecutive BFD messages missed from the peer
Contextconfigure service vprn string subscriber-interface string group-interface string ipv4 bfd multiplier number
Treemultiplier

Description

This command configures the number of missed messages before the BFD session state is changed to down and the upper-level protocol is notified of the fault. A multiplier of less than 3 should not be used in production environments. 

Range1 to 20
Default3
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

receive number
Synopsis BFD receive interval over this interface
Contextconfigure service vprn string subscriber-interface string group-interface string ipv4 bfd receive number
Treereceive

Description

This command specifies the receive interval for the BFD session.

On the 7750 SR, this command can only be configured to a value less than 100 when the type command is configured to cpm-np.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

transmit-interval number
Synopsis BFD transmit interval over this interface
Contextconfigure service vprn string subscriber-interface string group-interface string ipv4 bfd transmit-interval number
Treetransmit-interval

Description

This command configures the transmit intervals.

On the 7750 SR, this command can only be configured to a value less than 100 when the type command is configured to cpm-np.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

type keyword
Synopsis Local termination point for the BFD session
Contextconfigure service vprn string subscriber-interface string group-interface string ipv4 bfd type keyword
Treetype

Description

This command sets the local termination point for the BFD session to allow for fast timers down to 10 ms granularity.

The options to specify where the BFD session runs are:

  • auto (default) – the system chooses and uses the line card CPU only for single-hop BFD sessions with timer intervals equal to or greater than 100ms. All others are placed on the cpm-np.

  • cpm-np – BFD session runs on the FP complex associated with the CPM. This is either the FP on the CPM or the one elected on smaller systems. 

  • fp – BFD session runs on the line card CPU. This option can only be used for single-hop BFD sessions with timers equal to or greater than 100ms.  

Optionscpm-np, auto, fp
Defaultauto
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

dhcp
Synopsis Enter the dhcp context
Context configure service vprn string subscriber-interface string group-interface string ipv4 dhcp
Treedhcp
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-applications
Synopsis Enter the client-applications context
Contextconfigure service vprn string subscriber-interface string group-interface string ipv4 dhcp client-applications
Treeclient-applications
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

gi-address string
Synopsis GI address for the DHCP relay
Context configure service vprn string subscriber-interface string group-interface string ipv4 dhcp gi-address string
Treegi-address

Description

This command configures the GI address to distinguish between the different subscriber interfaces (and potentially group interfaces) defined when the router functions as a DHCP relay.

By default, the GI address used in the relayed DHCP packet is the primary IP address of a normal IES interface. Specifying the GI address allows the user to choose a secondary address. For group interfaces, a GI address must be specified under the group interface DHCP context or subscriber interface DHCP context for DHCP to function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lease-populate
Synopsis Enter the lease-populate context
Contextconfigure service vprn string subscriber-interface string group-interface string ipv4 dhcp lease-populate
Treelease-populate
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

l2-header
Synopsis Enable the l2-header context
Context configure service vprn string subscriber-interface string group-interface string ipv4 dhcp lease-populate l2-header
Treel2-header
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

offer-selection
Synopsis Enter the offer-selection context
Contextconfigure service vprn string subscriber-interface string group-interface string ipv4 dhcp offer-selection
Treeoffer-selection
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-mac
Synopsis Enter the client-mac context
Context configure service vprn string subscriber-interface string group-interface string ipv4 dhcp offer-selection client-mac
Treeclient-mac

Notes

The following elements are part of a choice: client-mac or server.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

discover-delay number
Synopsis Delay before sending DHCP Discover messages
Contextconfigure service vprn string subscriber-interface string group-interface string ipv4 dhcp offer-selection discover-delay number
Treediscover-delay

Description

This command configures the time to delay sending DHCP Discover messages. The delay is applied to all DHCP Discover messages for which no per DHCP server or per client MAC delay is configured.

Range1 to 100
Unitsdeciseconds
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

server [ipv4-address] string
Synopsis Enter the server list instance
Contextconfigure service vprn string subscriber-interface string group-interface string ipv4 dhcp offer-selection server string
Treeserver
Max. Instances8

Notes

The following elements are part of a choice: client-mac or server.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

option-82
Synopsis Enter the option-82 context
Context configure service vprn string subscriber-interface string group-interface string ipv4 dhcp option-82
Treeoption-82

Description

Commands in this context configure the processing required when the router receives a DHCP request that already has an Option 82 field in the packet.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

circuit-id
Synopsis Enter the circuit-id context
Context configure service vprn string subscriber-interface string group-interface string ipv4 dhcp option-82 circuit-id
Treecircuit-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

vlan-ascii-tuple
Synopsis Include the VLAN ID and dot1p bits in the ASCII tuple
Contextconfigure service vprn string subscriber-interface string group-interface string ipv4 dhcp option-82 circuit-id vlan-ascii-tuple
Treevlan-ascii-tuple

Description

When configured, the router includes the VLAN ID and dot1p bits with the ASCII-tuple information. This only occurs on dot1q and QinQ-encapsulated ports. When the Option 82 bits are stripped, dot1p bits are copied to the Ethernet header of the outgoing packet.

When unconfigured, the router leaves the circuit ID sub-option of the DHCP packet empty.

Notes

The following elements are part of a choice: ascii-tuple, ifindex, none, sap-id, or vlan-ascii-tuple.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

remote-id
Synopsis Enter the remote-id context
Context configure service vprn string subscriber-interface string group-interface string ipv4 dhcp option-82 remote-id
Treeremote-id

Description

Commands in this context configure the remote IP sub-option of the DHCP packet with the identity of the remote host end (typically the DHCP client).

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

vendor-specific-option
Synopsis Enter the vendor-specific-option context
Contextconfigure service vprn string subscriber-interface string group-interface string ipv4 dhcp option-82 vendor-specific-option
Treevendor-specific-option

Description

Commands in this context configure the Nokia Vendor-Specific Option (VSO) of the DHCP packet.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

proxy-server
Synopsis Enter the proxy-server context
Contextconfigure service vprn string subscriber-interface string group-interface string ipv4 dhcp proxy-server
Treeproxy-server
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lease-time
Synopsis Enter the lease-time context
Context configure service vprn string subscriber-interface string group-interface string ipv4 dhcp proxy-server lease-time
Treelease-time
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

relay-proxy
Synopsis Enable the relay-proxy context
Contextconfigure service vprn string subscriber-interface string group-interface string ipv4 dhcp relay-proxy
Treerelay-proxy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

server string
Synopsis IP addresses for DHCP server requests
Contextconfigure service vprn string subscriber-interface string group-interface string ipv4 dhcp server string
Treeserver

Description

This command configures a list of servers that this interface forwards requests to.

The operator can enter the list of servers as either IP addresses or fully qualified domain names. The operator must specify at least one server specified for DHCP relay to work. If there are multiple servers, the system forwards the request to all the servers in the list.

Max. Instances8

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

trusted boolean
Synopsis Relay untrusted packets
Context configure service vprn string subscriber-interface string group-interface string ipv4 dhcp trusted boolean
Treetrusted

Description

When configured to true, the router enables the trusted mode on the interface. When enabled, the relay agent changes the existing GI address (of the request) to the ingress interface, and forwards the request.

A DHCP request that contains a GI address of 0.0.0.0 and an Option 82 field in the packet is discarded unless it arrives on a trusted circuit.

This behavior only applies if the Relay Agent Information Option action is to keep the existing information. When the Option 82 field is replaced by the relay agent, the original Option 82 information is lost, and there is no reason to enable the trusted option.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

icmp
Synopsis Enter the icmp context
Context configure service vprn string subscriber-interface string group-interface string ipv4 icmp
Treeicmp
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

param-problem
Synopsis Enter the param-problem context
Contextconfigure service vprn string subscriber-interface string group-interface string ipv4 icmp param-problem
Treeparam-problem

Description

Commands in this context specify the settings for ICMP Parameter Problem messages generated by the interface.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

redirects
Synopsis Enter the redirects context
Context configure service vprn string subscriber-interface string group-interface string ipv4 icmp redirects
Treeredirects

Description

Commands in this context configure the settings for ICMP redirect messages generated by the interface.

The system sends ICMP redirect messages to alert the sending node that a more optimal route is available on another router on the same subnetwork.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ttl-expired
Synopsis Enter the ttl-expired context
Context configure service vprn string subscriber-interface string group-interface string ipv4 icmp ttl-expired
Treettl-expired

Description

Commands in this context configure the settings for ICMP TTL expired messages generated by the interface.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

use-matching-address boolean
Synopsis Use the subscriber interface address as source address
Contextconfigure service vprn string subscriber-interface string group-interface string ipv4 icmp ttl-expired use-matching-address boolean
Treeuse-matching-address

Description

When configured to true, the system uses a matching subscriber interface address as the source address of the ICMP TTL expired message.

For matching to occur, the source address of the offending packet must be in the same subnet of the subscriber interface address.

When configured to false, the system uses the first configured address.

Defaultfalse
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

unreachables
Synopsis Enter the unreachables context
Contextconfigure service vprn string subscriber-interface string group-interface string ipv4 icmp unreachables
Treeunreachables

Description

Commands in this context specify the settings for ICMP host and network destination unreachable messages generated by the interface.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ignore-df-bit boolean
Synopsis Ignore DF bit in the IPv4 header when fragmenting
Contextconfigure service vprn string subscriber-interface string group-interface string ipv4 ignore-df-bit boolean
Treeignore-df-bit

Description

When configured to true, fragmentation is applied according to the applicable egress MTU instead of the DF bit for frames egressing the WLAN-GW group. The DF bit is reset for frames that are fragmented.

When configured to false, the router fragments a packet larger than the MTU if the DF bit is set to 0 and drops the packet if the DF bit is set to 1.

Defaultfalse
Introduced20.5.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

neighbor-discovery
Synopsis Enter the neighbor-discovery context
Contextconfigure service vprn string subscriber-interface string group-interface string ipv4 neighbor-discovery
Treeneighbor-discovery
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

local-proxy-arp boolean
Synopsis Enable local proxy ARP on interface
Context configure service vprn string subscriber-interface string group-interface string ipv4 neighbor-discovery local-proxy-arp boolean
Treelocal-proxy-arp

Description

When configured to true, the router enables local proxy ARP on the interface.

When configured to false, the router does not respond to ARP requests for addresses on the same subnet.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

urpf-check
Synopsis Enable the urpf-check context
Context configure service vprn string subscriber-interface string group-interface string ipv4 urpf-check
Treeurpf-check
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv6
Synopsis Enable the ipv6 context
Context configure service vprn string subscriber-interface string group-interface string ipv6
Treeipv6
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

auto-reply
Synopsis Enter the auto-reply context
Context configure service vprn string subscriber-interface string group-interface string ipv6 auto-reply
Treeauto-reply
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

bfd
Synopsis Enter the bfd context
Context configure service vprn string subscriber-interface string group-interface string ipv6 bfd
Treebfd

Description

Commands in this context configure the attributes of bidirectional forwarding detection (BFD) sessions that control the state of ESM dynamic BGP peers.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

multiplier number
Synopsis Number of consecutive BFD messages missed from the peer
Contextconfigure service vprn string subscriber-interface string group-interface string ipv6 bfd multiplier number
Treemultiplier

Description

This command configures the number of missed messages before the BFD session state is changed to down and the upper-level protocol is notified of the fault. A multiplier of less than 3 should not be used in production environments. 

Range1 to 20
Default3
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

receive number
Synopsis BFD receive interval over this interface
Contextconfigure service vprn string subscriber-interface string group-interface string ipv6 bfd receive number
Treereceive

Description

This command specifies the receive interval for the BFD session.

On the 7750 SR, this command can only be configured to a value less than 100 when the type command is configured to cpm-np.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

transmit-interval number
Synopsis BFD transmit interval over this interface
Contextconfigure service vprn string subscriber-interface string group-interface string ipv6 bfd transmit-interval number
Treetransmit-interval

Description

This command configures the transmit intervals.

On the 7750 SR, this command can only be configured to a value less than 100 when the type command is configured to cpm-np.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

type keyword
Synopsis Local termination point for the BFD session
Contextconfigure service vprn string subscriber-interface string group-interface string ipv6 bfd type keyword
Treetype

Description

This command sets the local termination point for the BFD session to allow for fast timers down to 10 ms granularity.

The options to specify where the BFD session runs are:

  • auto (default) – the system chooses and uses the line card CPU only for single-hop BFD sessions with timer intervals equal to or greater than 100ms. All others are placed on the cpm-np.

  • cpm-np – BFD session runs on the FP complex associated with the CPM. This is either the FP on the CPM or the one elected on smaller systems. 

  • fp – BFD session runs on the line card CPU. This option can only be used for single-hop BFD sessions with timers equal to or greater than 100ms.  

Optionscpm-np, auto, fp
Defaultauto
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

dhcp6
Synopsis Enter the dhcp6 context
Context configure service vprn string subscriber-interface string group-interface string ipv6 dhcp6
Treedhcp6
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

option
Synopsis Enter the option context
Context configure service vprn string subscriber-interface string group-interface string ipv6 dhcp6 option
Treeoption
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

interface-id
Synopsis Enter the interface-id context
Contextconfigure service vprn string subscriber-interface string group-interface string ipv6 dhcp6 option interface-id
Treeinterface-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

pd-managed-route
Synopsis Enable the pd-managed-route context
Contextconfigure service vprn string subscriber-interface string group-interface string ipv6 dhcp6 pd-managed-route
Treepd-managed-route
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

proxy-server
Synopsis Enter the proxy-server context
Contextconfigure service vprn string subscriber-interface string group-interface string ipv6 dhcp6 proxy-server
Treeproxy-server
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-applications
Synopsis Enter the client-applications context
Contextconfigure service vprn string subscriber-interface string group-interface string ipv6 dhcp6 proxy-server client-applications
Treeclient-applications
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

server-id
Synopsis Enter the server-id context
Context configure service vprn string subscriber-interface string group-interface string ipv6 dhcp6 proxy-server server-id
Treeserver-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

relay
Synopsis Enter the relay context
Context configure service vprn string subscriber-interface string group-interface string ipv6 dhcp6 relay
Treerelay
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

advertise-selection
Synopsis Enter the advertise-selection context
Contextconfigure service vprn string subscriber-interface string group-interface string ipv6 dhcp6 relay advertise-selection
Treeadvertise-selection
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-mac
Synopsis Enter the client-mac context
Context configure service vprn string subscriber-interface string group-interface string ipv6 dhcp6 relay advertise-selection client-mac
Treeclient-mac

Notes

The following elements are part of a choice: client-mac or server.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

preference-option
Synopsis Enter the preference-option context
Contextconfigure service vprn string subscriber-interface string group-interface string ipv6 dhcp6 relay advertise-selection client-mac preference-option
Treepreference-option

Description

Commands in this context configure the DHCPv6 preference option that is inserted in the DHCPv6 Advertise message.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

preference-option
Synopsis Enter the preference-option context
Contextconfigure service vprn string subscriber-interface string group-interface string ipv6 dhcp6 relay advertise-selection preference-option
Treepreference-option

Description

Commands in this context configure the DHCPv6 preference option that is inserted in the DHCPv6 Advertise message.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

server [ipv6-address] string
Synopsis Enter the server list instance
Contextconfigure service vprn string subscriber-interface string group-interface string ipv6 dhcp6 relay advertise-selection server string
Treeserver
Max. Instances8

Notes

The following elements are part of a choice: client-mac or server.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

preference-option
Synopsis Enter the preference-option context
Contextconfigure service vprn string subscriber-interface string group-interface string ipv6 dhcp6 relay advertise-selection server string preference-option
Treepreference-option

Description

Commands in this context configure the DHCPv6 preference option that is inserted in the DHCPv6 Advertise message.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

solicit-delay number
Synopsis Delay before sending DHCPv6 Solicit messages
Contextconfigure service vprn string subscriber-interface string group-interface string ipv6 dhcp6 relay advertise-selection solicit-delay number
Treesolicit-delay

Description

This command configures the time to delay DHCPv6 Solicit messages. The delay is applied to DHCPv6 Solicit messages for which no overriding value is configured in the server instance or the client-mac context.

Range1 to 100
Unitsdeciseconds
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-applications
Synopsis Enter the client-applications context
Contextconfigure service vprn string subscriber-interface string group-interface string ipv6 dhcp6 relay client-applications
Treeclient-applications
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lease-split
Synopsis Enter the lease-split context
Context configure service vprn string subscriber-interface string group-interface string ipv6 dhcp6 relay lease-split
Treelease-split

Description

Commands in this context configure DHCPv6 lease split.

DHCPv6 lease split is active when administratively enabled and for all IA_NA and IA_PD options in the transaction, the configured lease split valid lifetime (short lease time) is less than or equal to one of the following:

  • the renew time T1 committed by the server (long renew time)

  • half of the preferred lifetime committed by the server when T1 committed by the server equals zero

Introduced21.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

snooping
Synopsis Enter the snooping context
Context configure service vprn string subscriber-interface string group-interface string ipv6 dhcp6 snooping
Treesnooping
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

neighbor-discovery
Synopsis Enter the neighbor-discovery context
Contextconfigure service vprn string subscriber-interface string group-interface string ipv6 neighbor-discovery
Treeneighbor-discovery
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

router-advertisements
Synopsis Enter the router-advertisements context
Contextconfigure service vprn string subscriber-interface string group-interface string ipv6 router-advertisements
Treerouter-advertisements
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

options
Synopsis Enter the options context
Context configure service vprn string subscriber-interface string group-interface string ipv6 router-advertisements options
Treeoptions
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

dns
Synopsis Enter the dns context
Context configure service vprn string subscriber-interface string group-interface string ipv6 router-advertisements options dns
Treedns
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

prefix-options
Synopsis Enter the prefix-options context
Contextconfigure service vprn string subscriber-interface string group-interface string ipv6 router-advertisements prefix-options
Treeprefix-options
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

router-solicit
Synopsis Enter the router-solicit context
Contextconfigure service vprn string subscriber-interface string group-interface string ipv6 router-solicit
Treerouter-solicit
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

urpf-check
Synopsis Enable the urpf-check context
Context configure service vprn string subscriber-interface string group-interface string ipv6 urpf-check
Treeurpf-check
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

local-address-assignment
Synopsis Enter the local-address-assignment context
Contextconfigure service vprn string subscriber-interface string group-interface string local-address-assignment
Treelocal-address-assignment
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv4
Synopsis Enter the ipv4 context
Context configure service vprn string subscriber-interface string group-interface string local-address-assignment ipv4
Treeipv4
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-applications
Synopsis Enter the client-applications context
Contextconfigure service vprn string subscriber-interface string group-interface string local-address-assignment ipv4 client-applications
Treeclient-applications
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv6
Synopsis Enter the ipv6 context
Context configure service vprn string subscriber-interface string group-interface string local-address-assignment ipv6
Treeipv6
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-applications
Synopsis Enter the client-applications context
Contextconfigure service vprn string subscriber-interface string group-interface string local-address-assignment ipv6 client-applications
Treeclient-applications
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

pppoe
Synopsis Enter the pppoe context
Context configure service vprn string subscriber-interface string group-interface string pppoe
Treepppoe
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

dhcp-client
Synopsis Enter the dhcp-client context
Context configure service vprn string subscriber-interface string group-interface string pppoe dhcp-client
Treedhcp-client
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

sap [sap-id] string
Synopsis Enter the sap list instance
Context configure service vprn string subscriber-interface string group-interface string sap string
Treesap
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[sap-id] string
Synopsis SAP ID
Contextconfigure service vprn string subscriber-interface string group-interface string sap string
Treesap
String Length1 to 45

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

anti-spoof keyword
Synopsis Type of anti-spoof filtering
Context configure service vprn string subscriber-interface string group-interface string sap string anti-spoof keyword
Treeanti-spoof
Optionssource-ip-addr, source-ip-and-mac-addr, next-hop-ip-and-mac-addr
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

cpu-protection
Synopsis Enter the cpu-protection context
Contextconfigure service vprn string subscriber-interface string group-interface string sap string cpu-protection
Treecpu-protection
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s

eth-cfm-monitoring
Synopsis Enable the eth-cfm-monitoring context
Contextconfigure service vprn string subscriber-interface string group-interface string sap string cpu-protection eth-cfm-monitoring
Treeeth-cfm-monitoring

Notes

The following elements are part of a choice: eth-cfm-monitoring, ip-src-monitoring, or mac-monitoring.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR-7/12/12e, 7750 SR-7s, 7750 SR-14s

default-host
Synopsis Enter the default-host context
Contextconfigure service vprn string subscriber-interface string group-interface string sap string default-host
Treedefault-host
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

ipv4 [address] reference prefix-length number
Synopsis Enter the ipv4 list instance
Context configure service vprn string subscriber-interface string group-interface string sap string default-host ipv4 reference prefix-length number
Treeipv4
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

next-hop string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNext-hop IP address used to forward traffic on the SAP
Contextconfigure service vprn string subscriber-interface string group-interface string sap string default-host ipv4 reference prefix-length number next-hop string
Treenext-hop

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

ipv6 [address] string prefix-length number
Synopsis Enter the ipv6 list instance
Context configure service vprn string subscriber-interface string group-interface string sap string default-host ipv6 string prefix-length number
Treeipv6
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

next-hop string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNext-hop IP address used to forward traffic on the SAP
Contextconfigure service vprn string subscriber-interface string group-interface string sap string default-host ipv6 string prefix-length number next-hop string
Treenext-hop

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

egress
Synopsis Enter the egress context
Context configure service vprn string subscriber-interface string group-interface string sap string egress
Treeegress
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

agg-rate
Synopsis Enter the agg-rate context
Context configure service vprn string subscriber-interface string group-interface string sap string egress agg-rate
Treeagg-rate
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

filter
Synopsis Enter the filter context
Context configure service vprn string subscriber-interface string group-interface string sap string egress filter
Treefilter
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

qos
Synopsis Enter the qos context
Context configure service vprn string subscriber-interface string group-interface string sap string egress qos
Treeqos
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

policer-control-policy
Synopsis Enter the policer-control-policy context
Contextconfigure service vprn string subscriber-interface string group-interface string sap string egress qos policer-control-policy
Treepolicer-control-policy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

sap-egress
Synopsis Enter the sap-egress context
Context configure service vprn string subscriber-interface string group-interface string sap string egress qos sap-egress
Treesap-egress
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service vprn string subscriber-interface string group-interface string sap string egress qos scheduler-policy
Treescheduler-policy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

virtual-port
Synopsis Enter the virtual-port context
Contextconfigure service vprn string subscriber-interface string group-interface string sap string egress virtual-port
Treevirtual-port
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

eth-cfm
Synopsis Enter the eth-cfm context
Context configure service vprn string subscriber-interface string group-interface string sap string eth-cfm
Treeeth-cfm
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

collect-lmm-fc-stats
Synopsis Enter the collect-lmm-fc-stats context
Contextconfigure service vprn string subscriber-interface string group-interface string sap string eth-cfm collect-lmm-fc-stats
Treecollect-lmm-fc-stats

Description

Commands in this context configure per forwarding class (FC) LMM information collection.

The commands fc-in-profile and fc in this context are mutually exclusive. The commands apply to either profile-aware or profile-unaware FCs respectively. 

This command and the collect-lmm-stats command are mutually exclusive when there is entity resource contention.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

fc keyword
Synopsis Forwarding class name for profile-unaware counter
Contextconfigure service vprn string subscriber-interface string group-interface string sap string eth-cfm collect-lmm-fc-stats fc keyword
Treefc

Description

This command configures individual counters for the specified FCs without regard for profile. The system includes all countable packets that match a configured FC, regardless of profile, in this counter.

An FC specified as part of this command and for this specific context cannot be specified as a profile-aware FC using the fc-in-profile command under the collect-lmm-fc-stats context. 

When this command is reentered, a differential is performed. Omitted FCs stop counting, newly added FCs start counting, and unchanged FCs continue to count.

Optionsbe, l2, af, l1, h2, ef, h1, nc
Max. Instances 8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

fc-in-profile keyword
Synopsis Forwarding class name for profile-aware counter
Contextconfigure service vprn string subscriber-interface string group-interface string sap string eth-cfm collect-lmm-fc-stats fc-in-profile keyword
Treefc-in-profile

Description

This command configures individual counters for the specified FCs with regard to profile. The system includes all countable packets that match a configured FC and that are deemed to be in-profile in this counter.

An FC specified as part of this command and for this specific context cannot be specified as a profile-unaware FC using the fc command under the collect-lmm-fc-stats context.

When this command is reentered, a differential is performed. Omitted FCs stop counting, newly added FCs start counting, and unchanged FCs continue to count.

Optionsbe, l2, af, l1, h2, ef, h1, nc
Max. Instances 8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

collect-lmm-stats boolean
Synopsis Collect statistics for loss measurement message tests
Contextconfigure service vprn string subscriber-interface string group-interface string sap string eth-cfm collect-lmm-stats boolean
Treecollect-lmm-stats

Description

When configured to true, the router instantiates the statistical counter to transmit and receive packets for the LAG facility MEP bindings.

The show eth-cfm collect-lmm-stats command displays entities that have been enabled to collect transit and receive counters.

When configured to false, the router does not instantiate the counter and the LMM PDU associated with the MEP does not populate the counters in the packet.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

mep md-admin-name reference ma-admin-name reference mep-id number
Synopsis Enter the mep list instance
Context configure service vprn string subscriber-interface string group-interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number
Treemep
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

alarm-notification
Synopsis Enter the alarm-notification context
Contextconfigure service vprn string subscriber-interface string group-interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number alarm-notification
Treealarm-notification

Description

Commands in this context configure the Fault Notification Generator (FNG) time values to raise an alarm or reset the CCM defect alarm. 

Use these timers for network management processes. The timers are not tied into delaying the notification to the fault management system on the network element and do not affect fault propagation mechanisms.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

ccm-padding-size number
Synopsis Number of octets of padding to insert in CCM packets
Contextconfigure service vprn string subscriber-interface string group-interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number ccm-padding-size number
Treeccm-padding-size

Description

This command sets the byte size of the optional Data TLV to be included in the ETH-CC PDU.

This command increases the size of the ETH-CC PDU by the configured value. The base size of the ETH-CC PDU, including the Interface Status TLV and Port Status TLV, is 83 bytes not including the Layer 2 encapsulation. CCM padding is not supported when the CCM interval (configured through configure eth-cfm domain association ccm-interval) is less than 1 second.

Range3 to 1500
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

csf
Synopsis Enable the csf context
Context configure service vprn string subscriber-interface string group-interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number csf
Treecsf
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

eth-test
Synopsis Enable the eth-test context
Context configure service vprn string subscriber-interface string group-interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test
Treeeth-test

Description

Commands in this context configure information used by the Ethernet Test (ETH-TST) packet. The commands must be configured on both the sender and the receiver nodes. The test packets are used with the oam eth-cfm eth-test command.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

test-pattern
Synopsis Enter the test-pattern context
Contextconfigure service vprn string subscriber-interface string group-interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test test-pattern
Treetest-pattern

Description

Commands in this context specify the test pattern for the ETH-TST frames. The pattern does not have to be the same on the sender and the receiver.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

pattern keyword
Synopsis Test pattern for Ethernet Test frames
Contextconfigure service vprn string subscriber-interface string group-interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number eth-test test-pattern pattern keyword
Treepattern

Description

This command specifies the test pattern of the Ethernet Test (ETH-TST) frames. This does not have to be configured the same on the sender and the receiver.

Optionsall-zeros, all-ones
Default all-zeros
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

grace
Synopsis Enter the grace context
Context configure service vprn string subscriber-interface string group-interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace
Treegrace

Description

Commands in this context configure the Nokia ETH-CFM Grace function and the ITU-T Y.1731 Ethernet Expected Default (ETH-ED) function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

eth-ed
Synopsis Enter the eth-ed context
Context configure service vprn string subscriber-interface string group-interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-ed
Treeeth-ed

Description

Commands in this context configure the ITU-T Y.1731 ETH-ED function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

eth-vsm-grace
Synopsis Enter the eth-vsm-grace context
Contextconfigure service vprn string subscriber-interface string group-interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace
Treeeth-vsm-grace

Description

Commands in this context configure the Nokia ETH-CFM Grace function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

rx-eth-vsm-grace boolean
Synopsis Receive and process Nokia ETH-CFM Grace PDU on the MEP
Contextconfigure service vprn string subscriber-interface string group-interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace rx-eth-vsm-grace boolean
Treerx-eth-vsm-grace

Description

When configured to true, the router enables the Nokia Grace function, which is a vendor-specific PDU that informs MEP peers that the local node may be entering a period of expected defect.

When configured to false, the router disables the Nokia Grace function.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

tx-eth-vsm-grace boolean
Synopsis Transmit ETH-ED PDUs from the MEP
Context configure service vprn string subscriber-interface string group-interface string sap string eth-cfm mep md-admin-name reference ma-admin-name reference mep-id number grace eth-vsm-grace tx-eth-vsm-grace boolean
Treetx-eth-vsm-grace

Description

When configured to true, the router can transmit the Nokia ETH-CFM Grace PDU from the MEP when a system soft reset notification is received for one or more cards.

The Nokia Grace function is a vendor-specific PDU that informs MEP peers that the local node may be entering a period of expected defect.

The operator must configure the configure system eth-cfm grace command to instruct the system that the node is capable of transmitting expected-defect windows to peers. The system can only transmit one form of ETH-CFM grace (Nokia ETH-CFM Grace or ITU-T Y.1731 ETH-ED).

When configured to false, the router disables the transmission of the Nokia ETH-CFM Grace PDU from the MEP.

Defaulttrue
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

squelch-ingress-levels number
Synopsis Levels for which ETH-CFM packets are silently discarded
Contextconfigure service vprn string subscriber-interface string group-interface string sap string eth-cfm squelch-ingress-levels number
Treesquelch-ingress-levels

Description

This command defines the levels of the ETH-CFM packets that are silently discarded on ingress into the SAP or SDP binding from the wire that matches the service delineation of the SAP or SDP binding. All ETH-CFM packets inbound to the SAP or SDP binding that match the configured levels are dropped without regard for any other ETH-CFM criteria. No statistical information or drop count is available for any ETH-CFM packet that is silently discarded by this option.

The list of levels must be a complete contiguous list from 0 up to the highest level that will be dropped.

Range0 to 7
Max. Instances8
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

fwd-wholesale
Synopsis Enter the fwd-wholesale context
Contextconfigure service vprn string subscriber-interface string group-interface string sap string fwd-wholesale
Treefwd-wholesale
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

igmp-host-tracking
Synopsis Enter the igmp-host-tracking context
Contextconfigure service vprn string subscriber-interface string group-interface string sap string igmp-host-tracking
Treeigmp-host-tracking
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ingress
Synopsis Enter the ingress context
Context configure service vprn string subscriber-interface string group-interface string sap string ingress
Treeingress
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

filter
Synopsis Enter the filter context
Context configure service vprn string subscriber-interface string group-interface string sap string ingress filter
Treefilter
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

qos
Synopsis Enter the qos context
Context configure service vprn string subscriber-interface string group-interface string sap string ingress qos
Treeqos
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

policer-control-policy
Synopsis Enter the policer-control-policy context
Contextconfigure service vprn string subscriber-interface string group-interface string sap string ingress qos policer-control-policy
Treepolicer-control-policy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

sap-ingress
Synopsis Enter the sap-ingress context
Context configure service vprn string subscriber-interface string group-interface string sap string ingress qos sap-ingress
Treesap-ingress
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

scheduler-policy
Synopsis Enter the scheduler-policy context
Contextconfigure service vprn string subscriber-interface string group-interface string sap string ingress qos scheduler-policy
Treescheduler-policy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lag
Synopsis Enter the lag context
Context configure service vprn string subscriber-interface string group-interface string sap string lag
Treelag
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

link-map-profile number
Synopsis LAG link map profile for a SAP or network interface
Contextconfigure service vprn string subscriber-interface string group-interface string sap string lag link-map-profile number
Treelink-map-profile

Description

This command assigns a preconfigured LAG link map profile to a SAP or network interface configured on a LAG or a PW port that exists on a LAG. After an operator assigns a LAG link map profile, the system rehashes the SAP or network interface egress traffic over the LAG as required by the new configuration.

If the LAG link map profile for a SAP or network interface is deleted, the system reverts back to per-flow hashing.

Range1 to 64
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

per-link-hash
Synopsis Enter the per-link-hash context
Contextconfigure service vprn string subscriber-interface string group-interface string sap string lag per-link-hash
Treeper-link-hash
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

static-host
Synopsis Enter the static-host context
Context configure service vprn string subscriber-interface string group-interface string sap string static-host
Treestatic-host
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv4 [ip] string mac string
Synopsis Enter the ipv4 list instance
Context configure service vprn string subscriber-interface string group-interface string sap string static-host ipv4 string mac string
Treeipv4
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

mac string
Synopsis MAC address used by the static host
Context configure service vprn string subscriber-interface string group-interface string sap string static-host ipv4 string mac string
Treeipv4
MD-CLI Default00:00:00:00:00:00

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

app-profile
Synopsis Enter the app-profile context
Context configure service vprn string subscriber-interface string group-interface string sap string static-host ipv4 string mac string app-profile
Treeapp-profile
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

managed-route [prefix] string
Synopsis Enter the managed-route list instance
Contextconfigure service vprn string subscriber-interface string group-interface string sap string static-host ipv4 string mac string managed-route string
Treemanaged-route

Description

Commands in this context configure managed route parameters.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[prefix] string
Synopsis Managed route prefix associated with IPv4 static host
Contextconfigure service vprn string subscriber-interface string group-interface string sap string static-host ipv4 string mac string managed-route string
Treemanaged-route

Description

This command configures the managed route prefix. The prefix length must be in the range of 1 to 32.

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

cpe-check
Synopsis Enable the cpe-check context
Context configure service vprn string subscriber-interface string group-interface string sap string static-host ipv4 string mac string managed-route string cpe-check
Treecpe-check
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

destination-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP address of the target CPE device
Contextconfigure service vprn string subscriber-interface string group-interface string sap string static-host ipv4 string mac string managed-route string cpe-check destination-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treedestination-ip-address
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

failed-action
Synopsis Enter the failed-action context
Contextconfigure service vprn string subscriber-interface string group-interface string sap string static-host ipv4 string mac string managed-route string cpe-check failed-action
Treefailed-action
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

subscriber-id
Synopsis Enter the subscriber-id context
Contextconfigure service vprn string subscriber-interface string group-interface string sap string static-host ipv4 string mac string subscriber-id
Treesubscriber-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv6 [prefix] string mac string
Synopsis Enter the ipv6 list instance
Context configure service vprn string subscriber-interface string group-interface string sap string static-host ipv6 string mac string
Treeipv6
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

app-profile
Synopsis Enter the app-profile context
Context configure service vprn string subscriber-interface string group-interface string sap string static-host ipv6 string mac string app-profile
Treeapp-profile
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

managed-route [ipv6-prefix] string
Synopsis Enter the managed-route list instance
Contextconfigure service vprn string subscriber-interface string group-interface string sap string static-host ipv6 string mac string managed-route string
Treemanaged-route

Description

Commands in this context configure managed route parameters.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[ipv6-prefix] string
Synopsis Managed route prefix associated with IPv6 static host
Contextconfigure service vprn string subscriber-interface string group-interface string sap string static-host ipv6 string mac string managed-route string
Treemanaged-route

Description

This command configures the managed route prefix. The prefix length must be in the range of 1 to 128.

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

cpe-check
Synopsis Enable the cpe-check context
Context configure service vprn string subscriber-interface string group-interface string sap string static-host ipv6 string mac string managed-route string cpe-check
Treecpe-check
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

destination-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP address of the target CPE device
Contextconfigure service vprn string subscriber-interface string group-interface string sap string static-host ipv6 string mac string managed-route string cpe-check destination-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treedestination-ip-address
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

failed-action
Synopsis Enter the failed-action context
Contextconfigure service vprn string subscriber-interface string group-interface string sap string static-host ipv6 string mac string managed-route string cpe-check failed-action
Treefailed-action
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

subscriber-id
Synopsis Enter the subscriber-id context
Contextconfigure service vprn string subscriber-interface string group-interface string sap string static-host ipv6 string mac string subscriber-id
Treesubscriber-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

mac-learning
Synopsis Enter the mac-learning context
Contextconfigure service vprn string subscriber-interface string group-interface string sap string static-host mac-learning
Treemac-learning
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

sub-sla-mgmt
Synopsis Enter the sub-sla-mgmt context
Contextconfigure service vprn string subscriber-interface string group-interface string sap string sub-sla-mgmt
Treesub-sla-mgmt
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

defaults
Synopsis Enter the defaults context
Context configure service vprn string subscriber-interface string group-interface string sap string sub-sla-mgmt defaults
Treedefaults
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

int-dest-id
Synopsis Enter the int-dest-id context
Context configure service vprn string subscriber-interface string group-interface string sap string sub-sla-mgmt defaults int-dest-id
Treeint-dest-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

subscriber-id
Synopsis Enter the subscriber-id context
Contextconfigure service vprn string subscriber-interface string group-interface string sap string sub-sla-mgmt defaults subscriber-id
Treesubscriber-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

single-sub-parameters
Synopsis Enter the single-sub-parameters context
Contextconfigure service vprn string subscriber-interface string group-interface string sap string sub-sla-mgmt single-sub-parameters
Treesingle-sub-parameters
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

non-sub-traffic
Synopsis Enable the non-sub-traffic context
Contextconfigure service vprn string subscriber-interface string group-interface string sap string sub-sla-mgmt single-sub-parameters non-sub-traffic
Treenon-sub-traffic
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

sap-parameters
Synopsis Enter the sap-parameters context
Contextconfigure service vprn string subscriber-interface string group-interface string sap-parameters
Treesap-parameters
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

sub-sla-mgmt
Synopsis Enter the sub-sla-mgmt context
Contextconfigure service vprn string subscriber-interface string group-interface string sap-parameters sub-sla-mgmt
Treesub-sla-mgmt
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

defaults
Synopsis Enter the defaults context
Context configure service vprn string subscriber-interface string group-interface string sap-parameters sub-sla-mgmt defaults
Treedefaults
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

subscriber-id
Synopsis Enter the subscriber-id context
Contextconfigure service vprn string subscriber-interface string group-interface string sap-parameters sub-sla-mgmt defaults subscriber-id
Treesubscriber-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

srrp [srrp-id] number
Synopsis Enter the srrp list instance
Context configure service vprn string subscriber-interface string group-interface string srrp number
Treesrrp
Max. Instances1
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[srrp-id] number
Synopsis SRRP instance ID
Context configure service vprn string subscriber-interface string group-interface string srrp number
Treesrrp
Range1 to 4294967295

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

bfd-liveness
Synopsis Enable the bfd-liveness context
Contextconfigure service vprn string subscriber-interface string group-interface string srrp number bfd-liveness
Treebfd-liveness
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

dest-ip string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDestination IPv4 prefix
Contextconfigure service vprn string subscriber-interface string group-interface string srrp number bfd-liveness dest-ip string
Treedest-ip

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

interface-name string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisName of the interface running BFD
Contextconfigure service vprn string subscriber-interface string group-interface string srrp number bfd-liveness interface-name string
Treeinterface-name
String Length1 to 32

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

message-path reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSAP to use as the SRRP message path
Contextconfigure service vprn string subscriber-interface string group-interface string srrp number message-path reference
Treemessage-path

Reference

configure service vprn string subscriber-interface string group-interface string sap string

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

monitor-oper-group
Synopsis Enter the monitor-oper-group context
Contextconfigure service vprn string subscriber-interface string group-interface string srrp number monitor-oper-group
Treemonitor-oper-group
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

policy reference
Synopsis VRRP priority control policy associated with the SRRP
Contextconfigure service vprn string subscriber-interface string group-interface string srrp number policy reference
Treepolicy

Reference

configure vrrp policy number

Max. Instances2

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisGroup interface type
Contextconfigure service vprn string subscriber-interface string group-interface string type keyword
Treetype
Optionsplain, lns, wlan-gw, gtp, bonding
Defaultplain
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

wlan-gw
Synopsis Enter the wlan-gw context
Context configure service vprn string subscriber-interface string group-interface string wlan-gw
Treewlan-gw
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

gateway-address [address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Enter the gateway-address list instance
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw gateway-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treegateway-address
Max. Instances10
Introduced16.0.R4

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

purpose
Synopsis Enter the purpose context
Context configure service vprn string subscriber-interface string group-interface string wlan-gw gateway-address (ipv4-address-no-zone | ipv6-address-no-zone) purpose
Treepurpose
Introduced16.0.R4

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

group-encryption
Synopsis Enter the group-encryption context
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw group-encryption
Treegroup-encryption
Introduced21.10.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

l2-ap
Synopsis Enter the l2-ap context
Context configure service vprn string subscriber-interface string group-interface string wlan-gw l2-ap
Treel2-ap
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

access-point [sap-id] string
Synopsis Enter the access-point list instance
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw l2-ap access-point string
Treeaccess-point
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

epipe-sap-template reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisParameters template for the L2 access point SAP
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw l2-ap access-point string epipe-sap-template reference
Treeepipe-sap-template

Reference

configure service template epipe-sap-template string

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

lanext
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the lanext context
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw lanext
Treelanext
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

max-bd number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of bridge domains
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw lanext max-bd number
Treemax-bd
Range1 to 131071
Default131071
Introduced 16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

learn-ap-mac
Synopsis Enable the learn-ap-mac context
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw learn-ap-mac
Treelearn-ap-mac
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

mcs-peer
Synopsis Enable the mcs-peer context
Context configure service vprn string subscriber-interface string group-interface string wlan-gw mcs-peer
Treemcs-peer

Description

Commands in this context configure a multi-chassis synchronization peer.

Introduced23.10.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

address reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP address of the MCS peer
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw mcs-peer address reference
Treeaddress

Description

This command configures the IPv4 address or the global IPv6 unicast address for a multi-chassis synchronization peer.

Reference

configure redundancy multi-chassis peer (ipv4-address-no-zone | ipv6-address-no-zone)

Notes

This element is mandatory.

Introduced23.10.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

sync-tag string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSynchronization tag shared by MCS peers
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw mcs-peer sync-tag string
Treesync-tag

Description

This command configures the synchronization tag for synchronization of ESM and the tunnel state for ESM over soft-GRE with an MCS peer.

String Length1 to 32

Notes

This element is mandatory.

Introduced23.10.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

mobility
Synopsis Enter the mobility context
Context configure service vprn string subscriber-interface string group-interface string wlan-gw mobility
Treemobility
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

trigger
Synopsis Enter the trigger context
Context configure service vprn string subscriber-interface string group-interface string wlan-gw mobility trigger
Treetrigger
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

promiscuous-mode boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable promiscuous mode for this group interface
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw promiscuous-mode boolean
Treepromiscuous-mode

Description

When configured to true, the router accepts all traffic, including traffic that is not destined for a WLAN gateway group interface MAC or virtual MAC address for ESM processing.

When configured to false, the router only accepts traffic that is destined for a WLAN gateway group interface MAC or virtual MAC address for ESM processing.

Defaultfalse
Introduced23.10.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

tunnel-egress-qos
Synopsis Enter the tunnel-egress-qos context
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw tunnel-egress-qos
Treetunnel-egress-qos
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

granularity keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisGranularity of the egress shaping for WLAN Gateway
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw tunnel-egress-qos granularity keyword
Treegranularity
Options

per-tunnel – Applied to each tunnel

per-retailer – Applied to each retailer Mobile Network Operator's fraction of the tunnel payload

Defaultper-tunnel
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

tunnel-encaps
Synopsis Enter the tunnel-encaps context
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw tunnel-encaps
Treetunnel-encaps
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

learn-l2tp-cookie (keyword | hex-string)
Synopsis System that learns the cookie from L2TP tunnels terminating on this interface
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw tunnel-encaps learn-l2tp-cookie (keyword | hex-string)
Treelearn-l2tp-cookie
String Length6
Options

never – Never interpret the cookie

always – Interpret cookie regardless of first two octets value

Defaultnever
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

vlan-range [range] string
Synopsis Enter the vlan-range list instance
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string
Treevlan-range
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

authentication
Synopsis Enter the authentication context
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string authentication
Treeauthentication
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

local
Synopsis Enable the local context
Context configure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string authentication local
Treelocal
Introduced22.2.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

data-triggered-ue-creation
Synopsis Enter the data-triggered-ue-creation context
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string data-triggered-ue-creation
Treedata-triggered-ue-creation

Description

Commands in this context configure data-triggered subscriber creation for Wi-Fi subscribers. Data-triggered UE creation only works upon receipt of TCP and UDP packets.

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

create-proxy-cache-entry
Synopsis Enter the create-proxy-cache-entry context
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string data-triggered-ue-creation create-proxy-cache-entry
Treecreate-proxy-cache-entry
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

proxy-server
Synopsis Enable the proxy-server context
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string data-triggered-ue-creation create-proxy-cache-entry proxy-server
Treeproxy-server
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

dhcp4
Synopsis Enter the dhcp4 context
Context configure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string dhcp4
Treedhcp4
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

lease-time
Synopsis Enter the lease-time context
Context configure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string dhcp4 lease-time
Treelease-time
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

dhcp6
Synopsis Enter the dhcp6 context
Context configure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string dhcp6
Treedhcp6
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

preferred-lifetime
Synopsis Enter the preferred-lifetime context
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string dhcp6 preferred-lifetime
Treepreferred-lifetime
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

valid-lifetime
Synopsis Enter the valid-lifetime context
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string dhcp6 valid-lifetime
Treevalid-lifetime
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

dsm
Synopsis Enter the dsm context
Context configure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string dsm
Treedsm
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

accounting-update
Synopsis Enable the accounting-update context
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string dsm accounting-update
Treeaccounting-update
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

application-assurance
Synopsis Enter the application-assurance context
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string dsm application-assurance
Treeapplication-assurance
Introduced21.10.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

egress
Synopsis Enter the egress context
Context configure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string dsm egress
Treeegress
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

ingress
Synopsis Enter the ingress context
Context configure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string dsm ingress
Treeingress
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

soft-quota-exhausted-filter reference
Synopsis Filter applied when soft volume quota is reached
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string dsm ingress soft-quota-exhausted-filter reference
Treesoft-quota-exhausted-filter

Description

This command applies a filter when a soft volume quota is reached. The filter replaces the currently applied filter (which can be preconfigured using the ip-filter command in the configure service vprn subscriber-interface group-interface wlan-gw vlan-range dsm ingress ip-filter context or be set using a RADIUS CoA message) for the UE upon quota exhaustion. If the quota is extended using a RADIUS CoA message, the filter is automatically reverted. Configuration changes apply only to new DSM UEs and not to existing UEs. 

Reference

configure subscriber-mgmt isa-filter string

Introduced21.7.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

one-time-redirect
Synopsis Enter the one-time-redirect context
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string dsm one-time-redirect
Treeone-time-redirect
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

volume-quota-direction keyword
Synopsis Volume quota direction for WLAN GW
Context configure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string dsm volume-quota-direction keyword
Treevolume-quota-direction

Description

This command specifies the direction that volume quotas are applied. Configuration changes apply only to new DSM UEs and not to existing UEs.

Options

both – Both directions

ingress – Ingress direction (upstream)

egress – Egress direction (downstream)

Defaultboth
Introduced21.7.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

dynamic-service boolean
Synopsis Dynamically assign WLAN-GW subscriber to a VPLS service
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string dynamic-service boolean
Treedynamic-service

Description

When configured to true, the WLAN-GW subscriber is dynamically assigned to a VPLS service, based on RADIUS authentication reply attributes. This feature is used in conjunction with the configure service vpls wlan-gw wlan-gw-group command.

See "Dynamic VPLS service" in the 7450 ESS, 7750 SR, and VSR Triple Play Service Delivery Architecture Guide for more information about the dynamic VPLS service feature.

Defaultfalse
Introduced23.3.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

extension [extension-range] string
Synopsis Add a list entry for extension
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string extension string
Treeextension
Introduced21.7.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

[extension-range] string
Synopsis VLAN tag range used for matching
Context configure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string extension string
Treeextension

Description

This command configures the additional VLAN range that is used for matching. Any traffic within the extension range is considered part of the same VLAN range for purposes of intra-SSID mobility. 

Notes

This element is part of a list key.

Introduced21.7.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

l2-service
Synopsis Enable the l2-service context
Context configure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string l2-service
Treel2-service
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

slaac
Synopsis Enter the slaac context
Context configure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string slaac
Treeslaac
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

preferred-lifetime
Synopsis Enter the preferred-lifetime context
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string slaac preferred-lifetime
Treepreferred-lifetime
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

valid-lifetime
Synopsis Enter the valid-lifetime context
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string slaac valid-lifetime
Treevalid-lifetime
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

vrgw
Synopsis Enter the vrgw context
Context configure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string vrgw
Treevrgw
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

brg
Synopsis Enter the brg context
Context configure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string vrgw brg
Treebrg
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

default-brg-profile reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisDefault BRG profile to use if the AAA server does not specify one
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string vrgw brg default-brg-profile reference
Treedefault-brg-profile

Reference

configure subscriber-mgmt vrgw brg-profile string

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

lanext
Synopsis Enter the lanext context
Context configure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string vrgw lanext
Treelanext
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

access
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the access context
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string vrgw lanext access
Treeaccess
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

network
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the network context
Contextconfigure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string vrgw lanext network
Treenetwork
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

xconnect
Synopsis Enter the xconnect context
Context configure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string xconnect
Treexconnect
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

accounting
Synopsis Enter the accounting context
Context configure service vprn string subscriber-interface string group-interface string wlan-gw vlan-range string xconnect accounting
Treeaccounting
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

wpp
Synopsis Enable the wpp context
Context configure service vprn string subscriber-interface string group-interface string wpp
Treewpp
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

initial
Synopsis Enter the initial context
Context configure service vprn string subscriber-interface string group-interface string wpp initial
Treeinitial
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

portal
Synopsis Enter the portal context
Context configure service vprn string subscriber-interface string group-interface string wpp portal
Treeportal
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

name string
Synopsis Web portal server name
Context configure service vprn string subscriber-interface string group-interface string wpp portal name string
Treename
String Length1 to 32

Notes

The following elements are part of a choice: portal-group or (name and router-instance).

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

hold-time
Synopsis Enter the hold-time context
Context configure service vprn string subscriber-interface string hold-time
Treehold-time
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv4
Synopsis Enter the ipv4 context
Context configure service vprn string subscriber-interface string hold-time ipv4
Treeipv4
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

down
Synopsis Enter the down context
Context configure service vprn string subscriber-interface string hold-time ipv4 down
Treedown

Description

Commands in this context configure the down hold timer, which specifies the delay before activating the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface up, unless an operator configures the init-only command. 

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

init-only boolean
Synopsis Apply delay only at interface configuration or reboot
Contextconfigure service vprn string subscriber-interface string hold-time ipv4 down init-only boolean
Treeinit-only

Description

This command applies a delay only when the IP interface is first configured or after a system reboot.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

up
Synopsis Enter the up context
Context configure service vprn string subscriber-interface string hold-time ipv4 up
Treeup

Description

Commands in this context configure the up hold timer, which specifies the delay before deactivation of the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface down.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv6
Synopsis Enter the ipv6 context
Context configure service vprn string subscriber-interface string hold-time ipv6
Treeipv6
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

down
Synopsis Enter the down context
Context configure service vprn string subscriber-interface string hold-time ipv6 down
Treedown

Description

Commands in this context configure the down hold timer, which specifies the delay before activation of the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface up, unless an operator configures the init-only command. 

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

init-only boolean
Synopsis Apply delay only at interface configuration or reboot
Contextconfigure service vprn string subscriber-interface string hold-time ipv6 down init-only boolean
Treeinit-only

Description

When configured to true, the system applies a delay only when the IP interface is first configured or after a system reboot.

Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

up
Synopsis Enter the up context
Context configure service vprn string subscriber-interface string hold-time ipv6 up
Treeup

Description

Commands in this context configure the up hold timer, which specifies the delay before deactivation of the associated interface. The delay is invoked whenever the system attempts to bring the associated IP interface down.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipoe-linking
Synopsis Enter the ipoe-linking context
Contextconfigure service vprn string subscriber-interface string ipoe-linking
Treeipoe-linking
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipoe-session
Synopsis Enter the ipoe-session context
Contextconfigure service vprn string subscriber-interface string ipoe-session
Treeipoe-session
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv4
Synopsis Enter the ipv4 context
Context configure service vprn string subscriber-interface string ipv4
Treeipv4
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

address [ipv4-address] string
Synopsis Enter the address list instance
Contextconfigure service vprn string subscriber-interface string ipv4 address string
Treeaddress
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[ipv4-address] string
Synopsis IP address associated with the subscriber subnet
Contextconfigure service vprn string subscriber-interface string ipv4 address string
Treeaddress

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

arp-host
Synopsis Enter the arp-host context
Context configure service vprn string subscriber-interface string ipv4 arp-host
Treearp-host
Introduced16.0.R6

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

bfd
Synopsis Enter the bfd context
Context configure service vprn string subscriber-interface string ipv4 bfd
Treebfd

Description

Commands in this context configure the attributes of bidirectional forwarding detection (BFD) sessions that control the state of ESM dynamic BGP peers.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

multiplier number
Synopsis Number of consecutive BFD messages missed from the peer
Contextconfigure service vprn string subscriber-interface string ipv4 bfd multiplier number
Treemultiplier

Description

This command configures the number of missed messages before the BFD session state is changed to down and the upper-level protocol is notified of the fault. A multiplier of less than 3 should not be used in production environments. 

Range1 to 20
Default3
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

receive number
Synopsis BFD receive interval over this interface
Contextconfigure service vprn string subscriber-interface string ipv4 bfd receive number
Treereceive

Description

This command specifies the receive interval for the BFD session.

On the 7750 SR, this command can only be configured to a value less than 100 when the type command is configured to cpm-np.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

transmit-interval number
Synopsis BFD transmit interval over this interface
Contextconfigure service vprn string subscriber-interface string ipv4 bfd transmit-interval number
Treetransmit-interval

Description

This command configures the transmit intervals.

On the 7750 SR, this command can only be configured to a value less than 100 when the type command is configured to cpm-np.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

type keyword
Synopsis Local termination point for the BFD session
Contextconfigure service vprn string subscriber-interface string ipv4 bfd type keyword
Treetype

Description

This command sets the local termination point for the BFD session to allow for fast timers down to 10 ms granularity.

The options to specify where the BFD session runs are:

  • auto (default) – the system chooses and uses the line card CPU only for single-hop BFD sessions with timer intervals equal to or greater than 100ms. All others are placed on the cpm-np.

  • cpm-np – BFD session runs on the FP complex associated with the CPM. This is either the FP on the CPM or the one elected on smaller systems. 

  • fp – BFD session runs on the line card CPU. This option can only be used for single-hop BFD sessions with timers equal to or greater than 100ms.  

Optionscpm-np, auto, fp
Defaultauto
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

default-dns string
Synopsis Default DNS server addresses
Context configure service vprn string subscriber-interface string ipv4 default-dns string
Treedefault-dns
Max. Instances2

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

dhcp
Synopsis Enter the dhcp context
Context configure service vprn string subscriber-interface string ipv4 dhcp
Treedhcp
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-applications
Synopsis Enter the client-applications context
Contextconfigure service vprn string subscriber-interface string ipv4 dhcp client-applications
Treeclient-applications
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

gi-address string
Synopsis GI address for the DHCP relay
Context configure service vprn string subscriber-interface string ipv4 dhcp gi-address string
Treegi-address

Description

This command configures the GI address to distinguish between the different subscriber interfaces (and potentially group interfaces) defined when the router functions as a DHCP relay.

By default, the GI address used in the relayed DHCP packet is the primary IP address of a normal IES interface. Specifying the GI address allows the user to choose a secondary address. For group interfaces, a GI address must be specified under the group interface DHCP context or subscriber interface DHCP context for DHCP to function.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lease-populate
Synopsis Enter the lease-populate context
Contextconfigure service vprn string subscriber-interface string ipv4 dhcp lease-populate
Treelease-populate
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

offer-selection
Synopsis Enter the offer-selection context
Contextconfigure service vprn string subscriber-interface string ipv4 dhcp offer-selection
Treeoffer-selection
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-mac
Synopsis Enter the client-mac context
Context configure service vprn string subscriber-interface string ipv4 dhcp offer-selection client-mac
Treeclient-mac

Notes

The following elements are part of a choice: client-mac or server.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

discover-delay number
Synopsis Delay before sending DHCP Discover messages
Contextconfigure service vprn string subscriber-interface string ipv4 dhcp offer-selection discover-delay number
Treediscover-delay

Description

This command configures the time to delay sending DHCP Discover messages. The delay is applied to all DHCP Discover messages for which no per DHCP server or per client MAC delay is configured.

Range1 to 100
Unitsdeciseconds
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

server [ipv4-address] string
Synopsis Enter the server list instance
Contextconfigure service vprn string subscriber-interface string ipv4 dhcp offer-selection server string
Treeserver
Max. Instances8

Notes

The following elements are part of a choice: client-mac or server.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

option-82
Synopsis Enter the option-82 context
Context configure service vprn string subscriber-interface string ipv4 dhcp option-82
Treeoption-82

Description

Commands in this context configure the processing required when the router receives a DHCP request that already has an Option 82 field in the packet.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

vendor-specific-option
Synopsis Enter the vendor-specific-option context
Contextconfigure service vprn string subscriber-interface string ipv4 dhcp option-82 vendor-specific-option
Treevendor-specific-option

Description

Commands in this context configure the Nokia Vendor-Specific Option (VSO) of the DHCP packet.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

proxy-server
Synopsis Enter the proxy-server context
Contextconfigure service vprn string subscriber-interface string ipv4 dhcp proxy-server
Treeproxy-server
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lease-time
Synopsis Enter the lease-time context
Context configure service vprn string subscriber-interface string ipv4 dhcp proxy-server lease-time
Treelease-time
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

relay-proxy
Synopsis Enable the relay-proxy context
Contextconfigure service vprn string subscriber-interface string ipv4 dhcp relay-proxy
Treerelay-proxy
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

server string
Synopsis DHCP server IP addresses
Context configure service vprn string subscriber-interface string ipv4 dhcp server string
Treeserver
Max. Instances8

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

unnumbered
Synopsis Enter the unnumbered context
Context configure service vprn string subscriber-interface string ipv4 unnumbered
Treeunnumbered
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ip-address string
Synopsis IP address for the subscriber interface
Contextconfigure service vprn string subscriber-interface string ipv4 unnumbered ip-address string
Treeip-address

Notes

The following elements are part of a choice: ip-address or ip-int-name.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ip-int-name string
Synopsis Interface name from which an IPv4 addressed is borrowed
Contextconfigure service vprn string subscriber-interface string ipv4 unnumbered ip-int-name string
Treeip-int-name
String Length1 to 32

Notes

The following elements are part of a choice: ip-address or ip-int-name.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv6
Synopsis Enable the ipv6 context
Context configure service vprn string subscriber-interface string ipv6
Treeipv6
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

address [ipv6-address] string
Synopsis Enter the address list instance
Contextconfigure service vprn string subscriber-interface string ipv6 address string
Treeaddress
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[ipv6-address] string
Synopsis IPv6 address for the subscriber interface
Contextconfigure service vprn string subscriber-interface string ipv6 address string
Treeaddress

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

host-type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisHost type for subscriber interface prefixes
Contextconfigure service vprn string subscriber-interface string ipv6 address string host-type keyword
Treehost-type
Options

pd – IPv6 ESM hosts for DHCPv6 prefix-delegation

wan – ESM hosts for DHCPv6 addresses or by WAN interface

pd-wan – Both prefix-delegation and ESM hosts

Defaultpd
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

bfd
Synopsis Enter the bfd context
Context configure service vprn string subscriber-interface string ipv6 bfd
Treebfd

Description

Commands in this context configure the attributes of bidirectional forwarding detection (BFD) sessions that control the state of ESM dynamic BGP peers.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

multiplier number
Synopsis Number of consecutive BFD messages missed from the peer
Contextconfigure service vprn string subscriber-interface string ipv6 bfd multiplier number
Treemultiplier

Description

This command configures the number of missed messages before the BFD session state is changed to down and the upper-level protocol is notified of the fault. A multiplier of less than 3 should not be used in production environments. 

Range1 to 20
Default3
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

receive number
Synopsis BFD receive interval over this interface
Contextconfigure service vprn string subscriber-interface string ipv6 bfd receive number
Treereceive

Description

This command specifies the receive interval for the BFD session.

On the 7750 SR, this command can only be configured to a value less than 100 when the type command is configured to cpm-np.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

transmit-interval number
Synopsis BFD transmit interval over this interface
Contextconfigure service vprn string subscriber-interface string ipv6 bfd transmit-interval number
Treetransmit-interval

Description

This command configures the transmit intervals.

On the 7750 SR, this command can only be configured to a value less than 100 when the type command is configured to cpm-np.

Range10 to 100000
Unitsmilliseconds
Default100
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

type keyword
Synopsis Local termination point for the BFD session
Contextconfigure service vprn string subscriber-interface string ipv6 bfd type keyword
Treetype

Description

This command sets the local termination point for the BFD session to allow for fast timers down to 10 ms granularity.

The options to specify where the BFD session runs are:

  • auto (default) – the system chooses and uses the line card CPU only for single-hop BFD sessions with timer intervals equal to or greater than 100ms. All others are placed on the cpm-np.

  • cpm-np – BFD session runs on the FP complex associated with the CPM. This is either the FP on the CPM or the one elected on smaller systems. 

  • fp – BFD session runs on the line card CPU. This option can only be used for single-hop BFD sessions with timers equal to or greater than 100ms.  

Optionscpm-np, auto, fp
Defaultauto
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s

default-dns string
Synopsis Default DNS server addresses
Context configure service vprn string subscriber-interface string ipv6 default-dns string
Treedefault-dns
Max. Instances2

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

dhcp6
Synopsis Enter the dhcp6 context
Context configure service vprn string subscriber-interface string ipv6 dhcp6
Treedhcp6
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

pd-managed-route
Synopsis Enable the pd-managed-route context
Contextconfigure service vprn string subscriber-interface string ipv6 dhcp6 pd-managed-route
Treepd-managed-route
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

proxy-server
Synopsis Enter the proxy-server context
Contextconfigure service vprn string subscriber-interface string ipv6 dhcp6 proxy-server
Treeproxy-server
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-applications
Synopsis Enter the client-applications context
Contextconfigure service vprn string subscriber-interface string ipv6 dhcp6 proxy-server client-applications
Treeclient-applications
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

server-id
Synopsis Enter the server-id context
Context configure service vprn string subscriber-interface string ipv6 dhcp6 proxy-server server-id
Treeserver-id
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

relay
Synopsis Enter the relay context
Context configure service vprn string subscriber-interface string ipv6 dhcp6 relay
Treerelay
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

advertise-selection
Synopsis Enter the advertise-selection context
Contextconfigure service vprn string subscriber-interface string ipv6 dhcp6 relay advertise-selection
Treeadvertise-selection
Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-mac
Synopsis Enter the client-mac context
Context configure service vprn string subscriber-interface string ipv6 dhcp6 relay advertise-selection client-mac
Treeclient-mac

Notes

The following elements are part of a choice: client-mac or server.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

preference-option
Synopsis Enter the preference-option context
Contextconfigure service vprn string subscriber-interface string ipv6 dhcp6 relay advertise-selection client-mac preference-option
Treepreference-option

Description

Commands in this context configure the DHCPv6 preference option that is inserted in the DHCPv6 Advertise message.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

preference-option
Synopsis Enter the preference-option context
Contextconfigure service vprn string subscriber-interface string ipv6 dhcp6 relay advertise-selection preference-option
Treepreference-option

Description

Commands in this context configure the DHCPv6 preference option that is inserted in the DHCPv6 Advertise message.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

server [ipv6-address] string
Synopsis Enter the server list instance
Contextconfigure service vprn string subscriber-interface string ipv6 dhcp6 relay advertise-selection server string
Treeserver
Max. Instances8

Notes

The following elements are part of a choice: client-mac or server.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

preference-option
Synopsis Enter the preference-option context
Contextconfigure service vprn string subscriber-interface string ipv6 dhcp6 relay advertise-selection server string preference-option
Treepreference-option

Description

Commands in this context configure the DHCPv6 preference option that is inserted in the DHCPv6 Advertise message.

Introduced20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

solicit-delay number
Synopsis Delay before sending DHCPv6 Solicit messages
Contextconfigure service vprn string subscriber-interface string ipv6 dhcp6 relay advertise-selection solicit-delay number
Treesolicit-delay

Description

This command configures the time to delay DHCPv6 Solicit messages. The delay is applied to DHCPv6 Solicit messages for which no overriding value is configured in the server instance or the client-mac context.

Range1 to 100
Unitsdeciseconds
Introduced 20.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-applications
Synopsis Enter the client-applications context
Contextconfigure service vprn string subscriber-interface string ipv6 dhcp6 relay client-applications
Treeclient-applications
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lease-split
Synopsis Enter the lease-split context
Context configure service vprn string subscriber-interface string ipv6 dhcp6 relay lease-split
Treelease-split

Description

Commands in this context configure DHCPv6 lease split.

DHCPv6 lease split is active when administratively enabled and for all IA_NA and IA_PD options in the transaction, the configured lease split valid lifetime (short lease time) is less than or equal to one of the following:

  • the renew time T1 committed by the server (long renew time)

  • half of the preferred lifetime committed by the server when T1 committed by the server equals zero

Introduced21.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

server string
Synopsis DHCP6 server(s) to which the DHCP6 requests are forwarded
Contextconfigure service vprn string subscriber-interface string ipv6 dhcp6 relay server string
Treeserver
Max. Instances8

Notes

This element is ordered by the user.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

link-local-address
Synopsis Enter the link-local-address context
Contextconfigure service vprn string subscriber-interface string ipv6 link-local-address
Treelink-local-address
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

prefix [ipv6-prefix] string
Synopsis Enter the prefix list instance
Contextconfigure service vprn string subscriber-interface string ipv6 prefix string
Treeprefix
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[ipv6-prefix] string
Synopsis IPv6 address for a router interface
Context configure service vprn string subscriber-interface string ipv6 prefix string
Treeprefix

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

holdup-time number
Synopsis Time to wait before route accepts new state attribute
Contextconfigure service vprn string subscriber-interface string ipv6 prefix string holdup-time number
Treeholdup-time
Range100 to 5000
Unitsmilliseconds
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

host-type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisHost type for subscriber interface prefixes
Contextconfigure service vprn string subscriber-interface string ipv6 prefix string host-type keyword
Treehost-type
Options

pd – IPv6 ESM hosts for DHCPv6 prefix-delegation

wan – ESM hosts for DHCPv6 addresses or by WAN interface

pd-wan – Both prefix-delegation and ESM hosts

Defaultpd
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

router-advertisements
Synopsis Enter the router-advertisements context
Contextconfigure service vprn string subscriber-interface string ipv6 router-advertisements
Treerouter-advertisements
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

options
Synopsis Enter the options context
Context configure service vprn string subscriber-interface string ipv6 router-advertisements options
Treeoptions
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

dns
Synopsis Enter the dns context
Context configure service vprn string subscriber-interface string ipv6 router-advertisements options dns
Treedns
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

prefix-options
Synopsis Enter the prefix-options context
Contextconfigure service vprn string subscriber-interface string ipv6 router-advertisements prefix-options
Treeprefix-options
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

router-solicit
Synopsis Enter the router-solicit context
Contextconfigure service vprn string subscriber-interface string ipv6 router-solicit
Treerouter-solicit
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

local-address-assignment
Synopsis Enter the local-address-assignment context
Contextconfigure service vprn string subscriber-interface string local-address-assignment
Treelocal-address-assignment
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv4
Synopsis Enter the ipv4 context
Context configure service vprn string subscriber-interface string local-address-assignment ipv4
Treeipv4
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-applications
Synopsis Enter the client-applications context
Contextconfigure service vprn string subscriber-interface string local-address-assignment ipv4 client-applications
Treeclient-applications
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv6
Synopsis Enter the ipv6 context
Context configure service vprn string subscriber-interface string local-address-assignment ipv6
Treeipv6
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

client-applications
Synopsis Enter the client-applications context
Contextconfigure service vprn string subscriber-interface string local-address-assignment ipv6 client-applications
Treeclient-applications
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

pppoe
Synopsis Enter the pppoe context
Context configure service vprn string subscriber-interface string pppoe
Treepppoe
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

private-retail-subnets boolean
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisExport subnets to the forwarding service
Contextconfigure service vprn string subscriber-interface string private-retail-subnets boolean
Treeprivate-retail-subnets
Defaultfalse
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

wan-mode keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisMode of operation for hosts with /128 WAN IPv6 address
Contextconfigure service vprn string subscriber-interface string wan-mode keyword
Treewan-mode
Optionsmode64, mode128
Default mode64
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

wlan-gw
Synopsis Enable the wlan-gw context
Context configure service vprn string subscriber-interface string wlan-gw
Treewlan-gw
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

pool-manager
Synopsis Enter the pool-manager context
Contextconfigure service vprn string subscriber-interface string wlan-gw pool-manager
Treepool-manager
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

dhcp6-client
Synopsis Enter the dhcp6-client context
Contextconfigure service vprn string subscriber-interface string wlan-gw pool-manager dhcp6-client
Treedhcp6-client
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

dhcpv4-nat
Synopsis Enter the dhcpv4-nat context
Context configure service vprn string subscriber-interface string wlan-gw pool-manager dhcp6-client dhcpv4-nat
Treedhcpv4-nat
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

ia-na
Synopsis Enter the ia-na context
Context configure service vprn string subscriber-interface string wlan-gw pool-manager dhcp6-client ia-na
Treeia-na
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

lease-query
Synopsis Enable the lease-query context
Contextconfigure service vprn string subscriber-interface string wlan-gw pool-manager dhcp6-client lease-query
Treelease-query
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

slaac
Synopsis Enter the slaac context
Context configure service vprn string subscriber-interface string wlan-gw pool-manager dhcp6-client slaac
Treeslaac
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

watermarks
Synopsis Enter the watermarks context
Context configure service vprn string subscriber-interface string wlan-gw pool-manager watermarks
Treewatermarks
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

redundancy
Synopsis Enter the redundancy context
Context configure service vprn string subscriber-interface string wlan-gw redundancy
Treeredundancy
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

export string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRoute to export to peer
Contextconfigure service vprn string subscriber-interface string wlan-gw redundancy export string
Treeexport
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

monitor string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisPeer route to monitor
Contextconfigure service vprn string subscriber-interface string wlan-gw redundancy monitor string
Treemonitor
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

subscriber-mgmt
Synopsis Enter the subscriber-mgmt context
Contextconfigure service vprn string subscriber-mgmt
Treesubscriber-mgmt
Introduced22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

dhcpv4
Synopsis Enter the dhcpv4 context
Context configure service vprn string subscriber-mgmt dhcpv4
Treedhcpv4
Introduced23.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

routed-subnet-transparent-forward boolean
Synopsis Transparently forward DHCPv4 from CPE LAN over IPoE
Contextconfigure service vprn string subscriber-mgmt dhcpv4 routed-subnet-transparent-forward boolean
Treerouted-subnet-transparent-forward

Description

When configured to true, the router transparently forwards DHCPv4 packets received on a subscriber interface with a source IP in a routed subnet that is associated with a routed IPoE session or host.

Supported routed subnets are:

  • RADIUS and NASREQ framed routes

  • routes learned via an ESM dynamic BGP peer

  • managed routes that are associated with a static IPv4 host

When configured to false, the system disables transparent forwarding of DHCPv4 packets.

Defaultfalse
Introduced23.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

multi-chassis-shunt-id number
Synopsis Shunt ID for a pair of resilient nodes
Contextconfigure service vprn string subscriber-mgmt multi-chassis-shunt-id number
Treemulti-chassis-shunt-id

Description

This command configures the shunt ID that is used to shunt downstream traffic from a standby node to an active node. Because this ID identifies the traffic service on the standby node, the same ID must be configured per service on each node.

This configuration is required for inter-BNG-UP resiliency shunting, but not for non-BNG-UP shunting. However, when configured, it is also used for shunting non-BNG-UP sessions in the same service.

Range1 to 8191
Introduced22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

up-resiliency
Synopsis Enter the up-resiliency context
Contextconfigure service vprn string subscriber-mgmt up-resiliency
Treeup-resiliency
Introduced22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

monitor-oper-group [oper-group] reference
Synopsis Enter the monitor-oper-group list instance
Contextconfigure service vprn string subscriber-mgmt up-resiliency monitor-oper-group reference
Treemonitor-oper-group

Description

Commands in this context define parameters to derive the service health based on monitored operational groups. The BNG-UP sends the health value to the MAG-c. The MAG-c uses the value to determine the need for a BNG-UP status change (active or standby).

Note: The following is only applicable for the configure service vpls capture-sap context. If the configured groups are not the same for all capture SAPs sharing the same underlying port or LAG, the configuration of a Layer 2 access ID alias is required, or else the system chooses arbitrarily one set of configured groups.

Max. Instances2
Introduced22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

health-drop number
Synopsis Number subtracted from the health value per failure
Contextconfigure service vprn string subscriber-mgmt up-resiliency monitor-oper-group reference health-drop number
Treehealth-drop

Description

This command configures the drop in the health value for every operational group member failure. Every failure of an operational group member decreases the base health value to a possible minimum of 0.

Range1 to 100
Default1
Introduced 22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ttl-propagate
Synopsis Enter the ttl-propagate context
Contextconfigure service vprn string ttl-propagate
Treettl-propagate
Introduced16.0.R1

Platforms

All

local keyword
Synopsis Local TTL propagation control for the VPRN
Contextconfigure service vprn string ttl-propagate local keyword
Treelocal

Description

This command specifies the local TTL propagation control for the VPRN and overrides the global configuration of the TTL propagation for locally generated packets that are forwarded over MPLS LSPs in a given VPRN service context.

Optionsnone, all, vc-only, use-base
Default use-base
Introduced16.0.R1

Platforms

All

transit keyword
Synopsis Transit TTL propagation control for the VPRN
Contextconfigure service vprn string ttl-propagate transit keyword
Treetransit

Description

This command overrides the global configuration of the TTL propagation for in transit packets that are forwarded over MPLS LSPs in a given VPRN service context.

Optionsnone, all, vc-only, use-base
Default use-base
Introduced16.0.R1

Platforms

All

twamp-light
Synopsis Enter the twamp-light context
Context configure service vprn string twamp-light
Treetwamp-light
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

reflector
Synopsis Enable the reflector context
Context configure service vprn string twamp-light reflector
Treereflector
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

admin-state keyword
Synopsis Administrative state of TWAMP Light functionality
Contextconfigure service vprn string twamp-light reflector admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

allow-ipv6-udp-checksum-zero boolean
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisProcess IPv6 packets with a zero UDP checksum
Contextconfigure service vprn string twamp-light reflector allow-ipv6-udp-checksum-zero boolean
Treeallow-ipv6-udp-checksum-zero

Description

When configured to true, this command allows the processing of IPv6 packets that arrive with a UDP checksum of zero. The destination UDP ports that are registered as TWAMP Test packets as part of this template allow this behavior. 

When configured to false, IPv6 packets that arrive with a UDP checksum of zero are discarded.

Defaultfalse
Introduced21.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

prefix [ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis Enter the prefix list instance
Contextconfigure service vprn string twamp-light reflector prefix (ipv4-prefix | ipv6-prefix)
Treeprefix
Max. Instances50
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

[ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis Source prefix for the TWAMP-Light reflector
Contextconfigure service vprn string twamp-light reflector prefix (ipv4-prefix | ipv6-prefix)
Treeprefix

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

type keyword
Synopsis Processing behavior type for the reflector
Contextconfigure service vprn string twamp-light reflector type keyword
Treetype

Description

This command configures the processing behavior of the TWAMP Light reflector. When the value is twamp-light the reflector does not check the received PDU as a traditional base TWAMP Light packet without TLV processing. When the value is stamp, the reflector attempts to find and process supported STAMP TLVs that follow the base STAMP packet. 

In mixed environments where different types of Session-Senders may be targeting a common TWAMP Light reflector, set the value to stamp. When the reflector is operating in stamp mode, the primary parsing is based on STAMP, checking and processing known TLVs, or determining if the arriving PDU is a TWAMP Light PDU. A Session-Sender launching a TWAMP Light-based packet must use all zeros padding pattern when the pad size is non zero.

Optionsstamp, twamp-light
Default twamp-light
Introduced22.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

udp-port number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisUDP port on which the specified TWAMP-Light reflector listens for TWAMP PDUs
Contextconfigure service vprn string twamp-light reflector udp-port number
Treeudp-port
Range862 | 64364 to 64373

Notes

This element is mandatory.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

video-interface [interface-name] string
Synopsis Enter the video-interface list instance
Contextconfigure service vprn string video-interface string
Treevideo-interface
Max. Instances9
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

[interface-name] string
Synopsis Video interface name
Context configure service vprn string video-interface string
Treevideo-interface
String Length1 to 29

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

address [ip-address] string
Synopsis Add a list entry for address
Context configure service vprn string video-interface string address string
Treeaddress
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

[ip-address] string
Synopsis IPv4 address for the video interface within the service
Contextconfigure service vprn string video-interface string address string
Treeaddress

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

admin-state keyword
Synopsis Administrative state of the video interface
Contextconfigure service vprn string video-interface string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

channel [mcast-address] string source string
Synopsis Enter the channel list instance
Contextconfigure service vprn string video-interface string channel string source string
Treechannel
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

[mcast-address] string
Synopsis Multicast channel address
Context configure service vprn string video-interface string channel string source string
Treechannel

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

source string
Synopsis Unicast source address
Context configure service vprn string video-interface string channel string source string
Treechannel

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

scte35-action keyword
Synopsis Enable downstream forwarding of SCTE 35 cue avails
Contextconfigure service vprn string video-interface string channel string source string scte35-action keyword
Treescte35-action
Optionsforward, drop
Default forward
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

zone-channel [zone-mcast-address] string zone-source string
Synopsis Enter the zone-channel list instance
Contextconfigure service vprn string video-interface string channel string source string zone-channel string zone-source string
Treezone-channel
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

description string
Synopsis Text description
Context configure service vprn string video-interface string description string
Treedescription
String Length1 to 80
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

output-format keyword
Synopsis Output format
Contextconfigure service vprn string video-interface string output-format keyword
Treeoutput-format
Optionsudp, rtp-udp
Default rtp-udp
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

video-sap
Synopsis Enable the video-sap context
Context configure service vprn string video-interface string video-sap
Treevideo-sap
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

egress
Synopsis Enter the egress context
Context configure service vprn string video-interface string video-sap egress
Treeegress
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

filter
Synopsis Enter the filter context
Context configure service vprn string video-interface string video-sap egress filter
Treefilter
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

qos
Synopsis Enter the qos context
Context configure service vprn string video-interface string video-sap egress qos
Treeqos
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

ingress
Synopsis Enter the ingress context
Context configure service vprn string video-interface string video-sap ingress
Treeingress
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

filter
Synopsis Enter the filter context
Context configure service vprn string video-interface string video-sap ingress filter
Treefilter
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

qos
Synopsis Enter the qos context
Context configure service vprn string video-interface string video-sap ingress qos
Treeqos
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

video-group-id reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVideo group ID
Contextconfigure service vprn string video-interface string video-sap video-group-id reference
Treevideo-group-id

Reference

configure isa video-group number

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-1s, 7750 SR-2s, 7750 SR-7s, 7750 SR-14s

vprn-type keyword
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisVPRN type
Contextconfigure service vprn string vprn-type keyword
Treevprn-type
Optionsregular, hub, spoke, subscriber-split-horizon
Defaultregular
Introduced16.0.R1

Platforms

All

vxlan
Synopsis Enter the vxlan context
Context configure service vprn string vxlan
Treevxlan
Introduced16.0.R1

Platforms

All

tunnel-termination [ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Enter the tunnel-termination list instance
Contextconfigure service vprn string vxlan tunnel-termination (ipv4-address-no-zone | ipv6-address-no-zone)
Treetunnel-termination
Introduced16.0.R1

Platforms

All

[ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Non-system IP address that terminates the VXLAN
Contextconfigure service vprn string vxlan tunnel-termination (ipv4-address-no-zone | ipv6-address-no-zone)
Treetunnel-termination

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

fpe-id reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisFPE id for this entry
Contextconfigure service vprn string vxlan tunnel-termination (ipv4-address-no-zone | ipv6-address-no-zone) fpe-id reference
Treefpe-id

Reference

configure fwd-path-ext fpe number

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

weighted-ecmp keyword
Synopsis Weighted load-balancing capability for ECMP routes
Contextconfigure service vprn string weighted-ecmp keyword
Treeweighted-ecmp
Optionsfalse, true, strict
Defaultfalse
Introduced16.0.R1

Platforms

All

wlan-gw
Synopsis Enable the wlan-gw context
Context configure service vprn string wlan-gw
Treewlan-gw
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

distributed-subscriber-mgmt
Synopsis Enter the distributed-subscriber-mgmt context
Contextconfigure service vprn string wlan-gw distributed-subscriber-mgmt
Treedistributed-subscriber-mgmt
Introduced16.0.R4

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

mobility-triggered-accounting
Synopsis Enter the mobility-triggered-accounting context
Contextconfigure service vprn string wlan-gw mobility-triggered-accounting
Treemobility-triggered-accounting
Introduced16.0.R4

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

xconnect
Synopsis Enter the xconnect context
Context configure service vprn string wlan-gw xconnect
Treexconnect
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the WLAN-GW cross-connect
Contextconfigure service vprn string wlan-gw xconnect admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

tunnel-source-ip string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIPv6 address and prefix for the tunnel source
Contextconfigure service vprn string wlan-gw xconnect tunnel-source-ip string
Treetunnel-source-ip
Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

wlan-gw-group reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisISA WLAN-GW Group
Contextconfigure service vprn string wlan-gw xconnect wlan-gw-group reference
Treewlan-gw-group

Reference

configure isa wlan-gw-group number

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

wpp
Synopsis Enable the wpp context
Context configure service vprn string wpp
Treewpp
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of WPP
Context configure service vprn string wpp admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

portal [name] string
Synopsis Enter the portal list instance
Contextconfigure service vprn string wpp portal string
Treeportal
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis Web portal name
Context configure service vprn string wpp portal string
Treeportal
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisWPP portal address
Contextconfigure service vprn string wpp portal string address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeaddress

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the WPP portal server
Contextconfigure service vprn string wpp portal string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

port-format keyword
Synopsis Format of the port in the ACK_INO message
Contextconfigure service vprn string wpp portal string port-format keyword
Treeport-format
Optionsstandard, vendor-specific
Defaultstandard
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

retry-interval number
Synopsis Time between two consecutive retransmissions
Contextconfigure service vprn string wpp portal string retry-interval number
Treeretry-interval
Range10 to 2000
Unitsmilliseconds
Default 2000
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

secret string
Synopsis Message authentication between portal and BRAS by applying the secret used by WPPv2
Contextconfigure service vprn string wpp portal string secret string
Treesecret
String Length1 to 115
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

version number
Synopsis Protocol version to be expected by the WPP portal
Contextconfigure service vprn string wpp portal string version number
Treeversion
Range1 | 2
Default1
Introduced 16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR