filter commands

configure 
filter 
apply-groups reference
apply-groups-exclude reference
dhcp-filter number 
apply-groups reference
apply-groups-exclude reference
default-action 
bypass-host-creation 
drop 
description string
entry number 
action 
bypass-host-creation 
drop 
apply-groups reference
apply-groups-exclude reference
option 
absent 
match 
exact boolean
hex string
invert boolean
string string
number number
present 
dhcp6-filter number 
apply-groups reference
apply-groups-exclude reference
default-action 
bypass-host-creation 
na boolean
pd boolean
drop 
description string
entry number 
action 
bypass-host-creation 
na boolean
pd boolean
drop 
apply-groups reference
apply-groups-exclude reference
option 
absent 
match 
exact boolean
hex string
invert boolean
string string
number number
present 
gre-tunnel-template string 
apply-groups reference
apply-groups-exclude reference
description string
ipv4 
destination-address string 
gre-key (keyword | number)
skip-ttl-decrement boolean
source-address string
ipv6 
destination-address string 
gre-key keyword
skip-hop-decrement boolean
source-address string
ip-exception string 
apply-groups reference
apply-groups-exclude reference
description string
entry number 
apply-groups reference
apply-groups-exclude reference
description string
match 
dst-ip 
address (ipv4-prefix-with-host-bits | ipv4-address)
mask string
dst-port 
eq number
gt number
lt number
range 
end number
start number
icmp 
code number
type number
protocol (number | keyword)
src-ip 
address (ipv4-prefix-with-host-bits | ipv4-address)
mask string
src-port 
eq number
gt number
lt number
range 
end number
start number
filter-id number
ip-filter string 
apply-groups reference
apply-groups-exclude reference
chain-to-system-filter boolean
default-action keyword
description string
embed 
filter reference offset number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
flowspec offset number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
group number
router-instance string
openflow reference offset number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
grt 
sap reference
system 
vpls reference
vprn reference
entry number 
action 
accept 
accept-when 
pattern 
expression string
mask string
offset-type keyword
offset-value number
apply-groups reference
apply-groups-exclude reference
drop 
drop-when 
extracted-traffic 
packet-length 
eq number
gt number
lt number
range 
end number
start number
pattern 
expression string
mask string
offset-type keyword
offset-value number
ttl 
eq number
gt number
lt number
range 
end number
start number
fc keyword
forward 
bonding-connection number
esi-l2 
esi-value string
vpls reference
esi-l3 
esi-value string
sf-ip string
vas-interface reference
vprn reference
gre-tunnel reference
lsp string
mpls-policy 
endpoint string
next-hop 
interface-name string
nh-ip 
address string
indirect boolean
nh-ip-vrf 
address string
indirect boolean
router-instance string
redirect-policy reference
router-instance string
sap 
sap-id reference
vpls reference
sdp 
sdp-bind-id string
vpls reference
srte-policy 
color number
endpoint string
vprn-target 
adv-prefix string
bgp-nh string
lsp string
vprn reference
gtp-local-breakout 
http-redirect 
allow-override boolean
url (keyword | http-redirect-url)
ignore-match 
l2-aware-nat-bypass boolean
nat 
nat-policy reference
rate-limit 
extracted-traffic 
packet-length 
eq number
gt number
lt number
range 
end number
start number
pattern 
expression string
mask string
offset-type keyword
offset-value number
pir (number | keyword)
pps-pir (number | keyword)
ttl 
eq number
gt number
lt number
range 
end number
start number
reassemble 
remark 
dscp keyword
secondary 
apply-groups reference
apply-groups-exclude reference
forward 
next-hop 
nh-ip-vrf 
address string
indirect boolean
router-instance string
sap 
sap-id reference
vpls reference
sdp 
sdp-bind-id string
vpls reference
vprn-target 
adv-prefix string
bgp-nh string
lsp string
vprn reference
remark 
dscp keyword
tcp-mss-adjust 
apply-groups reference
apply-groups-exclude reference
description string
egress-pbr keyword
filter-sample boolean
interface-sample boolean
log reference
match 
destination-class number
dscp keyword
dst-ip 
address (ipv4-prefix-with-host-bits | ipv4-address)
ip-prefix-list reference
mask string
dst-port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
fragment keyword
icmp 
code number
type number
ip 
address (ipv4-prefix-with-host-bits | ipv4-address)
ip-prefix-list reference
mask string
ip-option 
mask number
type number
multiple-option boolean
option-present boolean
packet-length 
eq number
gt number
lt number
range 
end number
start number
port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
protocol (number | keyword)
protocol-list reference
src-ip 
address (ipv4-prefix-with-host-bits | ipv4-address)
ip-prefix-list reference
mask string
src-mac 
address string
mask string
src-port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
src-route-option boolean
tcp-established 
tcp-flags 
ack boolean
cwr boolean
ece boolean
fin boolean
ns boolean
psh boolean
rst boolean
syn boolean
urg boolean
ttl 
eq number
gt number
lt number
range 
end number
start number
pbr-down-action-override keyword
sample-profile reference
sticky-dest (number | keyword)
filter-id number
scope keyword
shared-policer boolean
subscriber-mgmt 
host-specific-entry 
credit-control 
range 
end number
start number
filter-rule 
range 
end number
start number
watermark 
high number
low number
shared-entry 
filter-rule 
range 
end number
start number
pcc-rule 
range 
end number
start number
watermark 
high number
low number
type keyword
ipv6-exception string 
apply-groups reference
apply-groups-exclude reference
description string
entry number 
apply-groups reference
apply-groups-exclude reference
description string
match 
dst-ip 
address (ipv6-prefix-with-host-bits | ipv6-address)
ipv6-prefix-list reference
mask string
dst-port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
icmp 
code number
type number
next-header (number | keyword)
port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
src-ip 
address (ipv6-prefix-with-host-bits | ipv6-address)
ipv6-prefix-list reference
mask string
src-port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
filter-id number
ipv6-filter string 
apply-groups reference
apply-groups-exclude reference
chain-to-system-filter boolean
default-action keyword
description string
embed 
filter reference offset number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
flowspec offset number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
group number
router-instance string
openflow reference offset number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
grt 
sap reference
system 
vpls reference
vprn reference
entry number 
action 
accept 
accept-when 
pattern 
expression string
mask string
offset-type keyword
offset-value number
apply-groups reference
apply-groups-exclude reference
drop 
drop-when 
extracted-traffic 
hop-limit 
eq number
gt number
lt number
range 
end number
start number
pattern 
expression string
mask string
offset-type keyword
offset-value number
payload-length 
eq number
gt number
lt number
range 
end number
start number
fc keyword
forward 
bonding-connection number
esi-l2 
esi-value string
vpls reference
esi-l3 
esi-value string
sf-ip string
vas-interface reference
vprn reference
gre-tunnel reference
lsp string
mpls-policy 
endpoint string
next-hop 
nh-ip 
address string
indirect boolean
nh-ip-vrf 
address string
indirect boolean
router-instance string
redirect-policy reference
router-instance string
sap 
sap-id reference
vpls reference
sdp 
sdp-bind-id string
vpls reference
srte-policy 
color number
endpoint string
vprn-target 
adv-prefix string
bgp-nh string
lsp string
vprn reference
http-redirect 
allow-override boolean
url (keyword | http-redirect-url)
ignore-match 
nat 
nat-policy reference
nat-type keyword
rate-limit 
extracted-traffic 
hop-limit 
eq number
gt number
lt number
range 
end number
start number
pattern 
expression string
mask string
offset-type keyword
offset-value number
payload-length 
eq number
gt number
lt number
range 
end number
start number
pir (number | keyword)
pps-pir (number | keyword)
remark 
dscp keyword
secondary 
apply-groups reference
apply-groups-exclude reference
forward 
next-hop 
nh-ip-vrf 
address string
indirect boolean
router-instance string
sap 
sap-id reference
vpls reference
sdp 
sdp-bind-id string
vpls reference
vprn-target 
adv-prefix string
bgp-nh string
lsp string
vprn reference
remark 
dscp keyword
tcp-mss-adjust 
apply-groups reference
apply-groups-exclude reference
description string
egress-pbr keyword
filter-sample boolean
interface-sample boolean
log reference
match 
destination-class number
dscp keyword
dst-ip 
address (ipv6-prefix-with-host-bits | ipv6-address)
ipv6-prefix-list reference
mask string
dst-port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
extension-header 
ah boolean
esp boolean
hop-by-hop boolean
routing-type0 boolean
flow-label 
mask number
value number
fragment keyword
hop-limit 
eq number
gt number
lt number
range 
end number
start number
icmp 
code number
type number
ip 
address (ipv6-prefix-with-host-bits | ipv6-address)
ipv6-prefix-list reference
mask string
next-header (number | keyword)
next-header-list reference
packet-length 
eq number
gt number
lt number
range 
end number
start number
port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
src-ip 
address (ipv6-prefix-with-host-bits | ipv6-address)
ipv6-prefix-list reference
mask string
src-mac 
address string
mask string
src-port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
tcp-established 
tcp-flags 
ack boolean
cwr boolean
ece boolean
fin boolean
ns boolean
psh boolean
rst boolean
syn boolean
urg boolean
pbr-down-action-override keyword
sample-profile reference
sticky-dest (number | keyword)
filter-id number
scope keyword
shared-policer boolean
subscriber-mgmt 
host-specific-entry 
credit-control 
range 
end number
start number
filter-rule 
range 
end number
start number
watermark 
high number
low number
shared-entry 
filter-rule 
range 
end number
start number
pcc-rule 
range 
end number
start number
watermark 
high number
low number
type keyword
log number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
destination 
memory 
max-entries number
stop-on-full boolean
syslog 
name reference
summary 
admin-state keyword
summary-crit keyword
mac-filter string 
apply-groups reference
apply-groups-exclude reference
default-action keyword
description string
embed 
entry number 
action 
accept 
apply-groups reference
apply-groups-exclude reference
drop 
forward 
esi-l2 
esi-value string
vpls reference
sap 
sap-id reference
vpls reference
sdp 
sdp-bind-id string
vpls reference
http-redirect 
url string
ignore-match 
rate-limit 
pir (number | keyword)
secondary 
apply-groups reference
apply-groups-exclude reference
forward 
sap 
sap-id reference
vpls reference
sdp 
sdp-bind-id string
vpls reference
apply-groups reference
apply-groups-exclude reference
description string
log reference
match 
dot1p 
mask number
priority number
dst-mac 
address string
mask string
etype string
frame-type keyword
inner-tag 
mask number
tag number
isid 
range 
end number
start number
value number
llc-dsap 
dsap number
mask number
llc-ssap 
mask number
ssap number
outer-tag 
mask number
tag number
snap-oui keyword
snap-pid number
src-mac 
address string
mask string
pbr-down-action-override keyword
sticky-dest (number | keyword)
filter-id number
scope keyword
type keyword
match-list 
apply-groups reference
apply-groups-exclude reference
ip-prefix-list string 
apply-groups reference
apply-groups-exclude reference
apply-path 
bgp-peers number 
apply-groups reference
apply-groups-exclude reference
group string
neighbor string
router-instance string
description string
prefix string 
prefix-exclude string 
ipv6-prefix-list string 
apply-groups reference
apply-groups-exclude reference
apply-path 
bgp-peers number 
apply-groups reference
apply-groups-exclude reference
group string
neighbor string
router-instance string
description string
prefix string 
prefix-exclude string 
port-list string 
apply-groups reference
apply-groups-exclude reference
description string
port number 
range start number end number 
protocol-list string 
apply-groups reference
apply-groups-exclude reference
description string
protocol (number | keyword) 
md-auto-id 
filter-id-range 
apply-groups reference
apply-groups-exclude reference
end number
start number
redirect-policy string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
destination (ipv4-address-no-zone | ipv6-address-no-zone) 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
ping-test 
apply-groups reference
apply-groups-exclude reference
drop-count number
hold-down number
interval number
source-address (ipv4-address-no-zone | ipv6-address-no-zone)
timeout number
priority number
unicast-rt-test 
notify-dest-change boolean
router-instance string
sticky-dest (number | keyword)
redirect-policy-binding string 
apply-groups reference
apply-groups-exclude reference
binding-operator keyword
redirect-policy reference 
apply-groups reference
apply-groups-exclude reference
destination reference 
system-filter 
apply-groups reference
apply-groups-exclude reference
ip reference 
ipv6 reference 

filter command descriptions

filter

Synopsis Enter the filter context
Context configure filter
Treefilter
Introduced16.0.R1

Platforms

All

dhcp-filter [filter-id] number

Synopsis Enter the dhcp-filter list instance
Contextconfigure filter dhcp-filter number
Treedhcp-filter
Introduced16.0.R1

Platforms

All

[filter-id] number
Synopsis Unique DHCP filter policy ID
Context configure filter dhcp-filter number
Treedhcp-filter
Range1 to 65535

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

default-action
Synopsis Enable the default-action context
Contextconfigure filter dhcp-filter number default-action
Treedefault-action
Introduced16.0.R1

Platforms

All

drop
Synopsis DHCP host creation when the filter entry is matched
Contextconfigure filter dhcp-filter number default-action drop
Treedrop

Notes

The following elements are part of a mandatory choice: bypass-host-creation or drop.

Introduced16.0.R1

Platforms

All

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure filter dhcp-filter number entry number
Treeentry
Max. Instances10
Introduced16.0.R1

Platforms

All

[entry-id] number
Synopsis DHCP filter entry index
Context configure filter dhcp-filter number entry number
Treeentry
Range1 to 65535

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

action
Synopsis Enable the action context
Context configure filter dhcp-filter number entry number action
Treeaction
Introduced16.0.R1

Platforms

All

bypass-host-creation
Synopsis Host creation options to bypass
Context configure filter dhcp-filter number entry number action bypass-host-creation
Treebypass-host-creation

Notes

The following elements are part of a mandatory choice: bypass-host-creation or drop.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

drop
Synopsis DHCP host creation when the filter entry is matched
Contextconfigure filter dhcp-filter number entry number action drop
Treedrop

Notes

The following elements are part of a mandatory choice: bypass-host-creation or drop.

Introduced16.0.R1

Platforms

All

option
Synopsis Enable the option context
Context configure filter dhcp-filter number entry number option
Treeoption
Introduced16.0.R1

Platforms

All

absent
Synopsis Require the absence of related option
Contextconfigure filter dhcp-filter number entry number option absent
Treeabsent

Notes

The following elements are part of a mandatory choice: absent, match, or present.

Introduced16.0.R1

Platforms

All

match
Synopsis Enable the match context
Context configure filter dhcp-filter number entry number option match
Treematch

Notes

The following elements are part of a mandatory choice: absent, match, or present.

Introduced16.0.R1

Platforms

All

hex string
Synopsis Matching pattern for the filtered option
Contextconfigure filter dhcp-filter number entry number option match hex string
Treehex
String Length1 to 256

Notes

The following elements are part of a mandatory choice: hex or string.

Introduced16.0.R1

Platforms

All

string string
Synopsis Matching pattern for the filtered option
Contextconfigure filter dhcp-filter number entry number option match string string
Treestring
String Length1 to 127

Notes

The following elements are part of a mandatory choice: hex or string.

Introduced16.0.R1

Platforms

All

number number
Synopsis Number for DHCP or DHCPv6 option to filter on
Contextconfigure filter dhcp-filter number entry number option number number
Treenumber
Range0 to 255

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

present
Synopsis Require the presence of related option
Contextconfigure filter dhcp-filter number entry number option present
Treepresent

Notes

The following elements are part of a mandatory choice: absent, match, or present.

Introduced16.0.R1

Platforms

All

dhcp6-filter [filter-id] number

Synopsis Enter the dhcp6-filter list instance
Contextconfigure filter dhcp6-filter number
Treedhcp6-filter
Introduced16.0.R1

Platforms

All

[filter-id] number
Synopsis Unique DHCP filter policy ID
Context configure filter dhcp6-filter number
Treedhcp6-filter
Range1 to 65535

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

default-action
Synopsis Enable the default-action context
Contextconfigure filter dhcp6-filter number default-action
Treedefault-action
Introduced16.0.R1

Platforms

All

bypass-host-creation
Synopsis Enable the bypass-host-creation context
Contextconfigure filter dhcp6-filter number default-action bypass-host-creation
Treebypass-host-creation

Notes

The following elements are part of a mandatory choice: bypass-host-creation or drop.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

drop
Synopsis Drop DHCPv6 message (do not process)
Context configure filter dhcp6-filter number default-action drop
Treedrop

Notes

The following elements are part of a mandatory choice: bypass-host-creation or drop.

Introduced16.0.R1

Platforms

All

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure filter dhcp6-filter number entry number
Treeentry
Max. Instances10
Introduced16.0.R1

Platforms

All

[entry-id] number
Synopsis DHCP filter entry index
Context configure filter dhcp6-filter number entry number
Treeentry
Range1 to 65535

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

action
Synopsis Enable the action context
Context configure filter dhcp6-filter number entry number action
Treeaction
Introduced16.0.R1

Platforms

All

bypass-host-creation
Synopsis Enable the bypass-host-creation context
Contextconfigure filter dhcp6-filter number entry number action bypass-host-creation
Treebypass-host-creation

Notes

The following elements are part of a mandatory choice: bypass-host-creation or drop.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

drop
Synopsis Drop DHCPv6 message (do not process)
Context configure filter dhcp6-filter number entry number action drop
Treedrop

Notes

The following elements are part of a mandatory choice: bypass-host-creation or drop.

Introduced16.0.R1

Platforms

All

option
Synopsis Enable the option context
Context configure filter dhcp6-filter number entry number option
Treeoption
Introduced16.0.R1

Platforms

All

absent
Synopsis Require the absence of related option
Contextconfigure filter dhcp6-filter number entry number option absent
Treeabsent

Notes

The following elements are part of a mandatory choice: absent, match, or present.

Introduced16.0.R1

Platforms

All

match
Synopsis Enable the match context
Context configure filter dhcp6-filter number entry number option match
Treematch

Notes

The following elements are part of a mandatory choice: absent, match, or present.

Introduced16.0.R1

Platforms

All

hex string
Synopsis Matching pattern for the filtered option
Contextconfigure filter dhcp6-filter number entry number option match hex string
Treehex
String Length1 to 256

Notes

The following elements are part of a mandatory choice: hex or string.

Introduced16.0.R1

Platforms

All

string string
Synopsis Matching pattern for the filtered option
Contextconfigure filter dhcp6-filter number entry number option match string string
Treestring
String Length1 to 127

Notes

The following elements are part of a mandatory choice: hex or string.

Introduced16.0.R1

Platforms

All

number number
Synopsis Number for DHCP or DHCPv6 option to filter on
Contextconfigure filter dhcp6-filter number entry number option number number
Treenumber
Range0 to 255

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

present
Synopsis Require the presence of related option
Contextconfigure filter dhcp6-filter number entry number option present
Treepresent

Notes

The following elements are part of a mandatory choice: absent, match, or present.

Introduced16.0.R1

Platforms

All

gre-tunnel-template [gre-tunnel-template-name] string

Synopsis Enter the gre-tunnel-template list instance
Contextconfigure filter gre-tunnel-template string
Treegre-tunnel-template
Max. Instances8191
Introduced16.0.R1

Platforms

All

[gre-tunnel-template-name] string
Synopsis GRE tunnel template ID
Context configure filter gre-tunnel-template string
Treegre-tunnel-template
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

ipv4
Synopsis Enter the ipv4 context
Context configure filter gre-tunnel-template string ipv4
Treeipv4

Notes

The following elements are part of a choice: ipv4 or ipv6.

Introduced16.0.R1

Platforms

All

destination-address [address] string
Synopsis Add a list entry for destination-address
Contextconfigure filter gre-tunnel-template string ipv4 destination-address string
Treedestination-address

Description

This command defines a destination for the GRE IP header used to encapsulate the matching IPv4/IPv6 packet.

A single destination address can be specified for an IPv6 gre-tunnel-template.

Traffic matching the associated IPv4 or IPv6 filter is hashed across any available ECMP or UCMP route next hop available to the destination address. If no destination address is available, then matching traffic follows the configured pbr-down-action-override action, if configured. If no pbr-down-action-override is configured traffic is discarded.

Max. Instances32
Introduced16.0.R1

Platforms

All

ipv6
Synopsis Enter the ipv6 context
Context configure filter gre-tunnel-template string ipv6
Treeipv6

Notes

The following elements are part of a choice: ipv4 or ipv6.

Introduced22.7.R1

Platforms

All

gre-key keyword
Synopsis Include a key value in GRE header
Context configure filter gre-tunnel-template string ipv6 gre-key keyword
Treegre-key

Description

This command includes a key value in the GRE header of ifIndex of the ingress interface.

Optionsif-index
Introduced22.7.R1

Platforms

All

skip-hop-decrement boolean
Synopsis Decrement TTL of the received packet
Context configure filter gre-tunnel-template string ipv6 skip-hop-decrement boolean
Treeskip-hop-decrement

Description

When configured to true, the system decrements the TTL of the IP packet matching the IPv4 or IPv6 filter when it is encapsulated into the GRE tunnel header.

When configured to false, the system increases the TTL of the received packet.

Defaultfalse
Introduced22.7.R1

Platforms

All

ip-exception [filter-name] string

Synopsis Enter the ip-exception list instance
Contextconfigure filter ip-exception string
Treeip-exception
Introduced20.10.R1

Platforms

VSR

[filter-name] string
Synopsis Filter name
Contextconfigure filter ip-exception string
Treeip-exception
String Length1 to 64

Notes

This element is part of a list key.

Introduced20.10.R1

Platforms

VSR

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure filter ip-exception string entry number
Treeentry
Introduced20.10.R1

Platforms

VSR

[entry-id] number
Synopsis ID for a match criteria and the corresponding action
Contextconfigure filter ip-exception string entry number
Treeentry
Range1 to 2097151

Notes

This element is part of a list key.

Introduced20.10.R1

Platforms

VSR

match
Synopsis Enter the match context
Context configure filter ip-exception string entry number match
Treematch
Introduced20.10.R1

Platforms

VSR

dst-ip
Synopsis Enter the dst-ip context
Context configure filter ip-exception string entry number match dst-ip
Treedst-ip
Introduced20.10.R1

Platforms

VSR

address (ipv4-prefix-with-host-bits | ipv4-address)
Synopsis IP address to match
Context configure filter ip-exception string entry number match dst-ip address (ipv4-prefix-with-host-bits | ipv4-address)
Treeaddress
Introduced20.10.R1

Platforms

VSR

dst-port
Synopsis Enter the dst-port context
Context configure filter ip-exception string entry number match dst-port
Treedst-port
Introduced20.10.R1

Platforms

VSR

eq number
Synopsis Exact match criterion
Context configure filter ip-exception string entry number match dst-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced20.10.R1

Platforms

VSR

gt number
Synopsis Condition on being greater than the specified value.
Contextconfigure filter ip-exception string entry number match dst-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced20.10.R1

Platforms

VSR

lt number
Synopsis Condition on being less than the specified value.
Contextconfigure filter ip-exception string entry number match dst-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced20.10.R1

Platforms

VSR

range
Synopsis Enable the range context
Context configure filter ip-exception string entry number match dst-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced20.10.R1

Platforms

VSR

end number
Synopsis Upper bound of the port range to match
Contextconfigure filter ip-exception string entry number match dst-port range end number
Treeend
Range1 to 65535

Notes

This element is mandatory.

Introduced20.10.R1

Platforms

VSR

icmp
Synopsis Enter the icmp context
Context configure filter ip-exception string entry number match icmp
Treeicmp
Introduced20.10.R1

Platforms

VSR

protocol (number | keyword)
Synopsis IP protocol to match.
Context configure filter ip-exception string entry number match protocol (number | keyword)
Treeprotocol
Range0 to 255
Optionstcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp
Introduced 20.10.R1

Platforms

VSR

src-ip
Synopsis Enter the src-ip context
Context configure filter ip-exception string entry number match src-ip
Treesrc-ip
Introduced20.10.R1

Platforms

VSR

address (ipv4-prefix-with-host-bits | ipv4-address)
Synopsis IP address to match
Context configure filter ip-exception string entry number match src-ip address (ipv4-prefix-with-host-bits | ipv4-address)
Treeaddress
Introduced20.10.R1

Platforms

VSR

src-port
Synopsis Enter the src-port context
Context configure filter ip-exception string entry number match src-port
Treesrc-port
Introduced20.10.R1

Platforms

VSR

eq number
Synopsis Exact match criterion
Context configure filter ip-exception string entry number match src-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced20.10.R1

Platforms

VSR

gt number
Synopsis Condition on being greater than the specified value.
Contextconfigure filter ip-exception string entry number match src-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced20.10.R1

Platforms

VSR

lt number
Synopsis Condition on being less than the specified value.
Contextconfigure filter ip-exception string entry number match src-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced20.10.R1

Platforms

VSR

range
Synopsis Enable the range context
Context configure filter ip-exception string entry number match src-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced20.10.R1

Platforms

VSR

end number
Synopsis Upper bound of the port range to match
Contextconfigure filter ip-exception string entry number match src-port range end number
Treeend
Range1 to 65535

Notes

This element is mandatory.

Introduced20.10.R1

Platforms

VSR

filter-id number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisFilter ID
Contextconfigure filter ip-exception string filter-id number
Treefilter-id
Range1 to 65535
Introduced20.10.R1

Platforms

VSR

ip-filter [filter-name] string

Synopsis Enter the ip-filter list instance
Contextconfigure filter ip-filter string
Treeip-filter
Introduced16.0.R1

Platforms

All

[filter-name] string
Synopsis Filter name
Contextconfigure filter ip-filter string
Treeip-filter
String Length1 to 64

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

default-action keyword
Synopsis Action for packets that do not match any entry
Contextconfigure filter ip-filter string default-action keyword
Treedefault-action
Defaultdrop
Optionsdrop, accept
Introduced16.0.R1

Platforms

All

embed
Synopsis Enter the embed context
Context configure filter ip-filter string embed
Treeembed

Description

Commands in this context embed a previously defined IPv4 embedded filter policy or Hybrid OpenFlow switch instance into an exclusive, template, or system filter policy at the specified offset value. Rules derived from the BGP FlowSpec can also be embedded into template filter policies only.

Introduced16.0.R1

Platforms

All

filter [name] reference offset number
Synopsis Enter the filter list instance
Contextconfigure filter ip-filter string embed filter reference offset number
Treefilter
Introduced16.0.R1

Platforms

All

[name] reference
Synopsis IPv4 policy to be embedded in the filter
Contextconfigure filter ip-filter string embed filter reference offset number
Treefilter

Reference

configure filter ip-filter string

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

offset number
Synopsis Offset of the inserted entries
Context configure filter ip-filter string embed filter reference offset number
Treefilter
Range0 to 2097150

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

flowspec offset number
Synopsis Enter the flowspec list instance
Contextconfigure filter ip-filter string embed flowspec offset number
Treeflowspec
Introduced16.0.R1

Platforms

All

offset number
Synopsis Offset of the inserted entries
Context configure filter ip-filter string embed flowspec offset number
Treeflowspec
Range0 to 2097151

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

group number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisInterface group ID for an external configured set of flowspec rules
Contextconfigure filter ip-filter string embed flowspec offset number group number
Treegroup
Range0 to 16383
Introduced16.0.R1

Platforms

All

router-instance string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVirtual router for an external configured set of flowspec rules
Contextconfigure filter ip-filter string embed flowspec offset number router-instance string
Treerouter-instance

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

openflow [of-switch] reference offset number
Synopsis Enter the openflow list instance
Contextconfigure filter ip-filter string embed openflow reference offset number
Treeopenflow
Introduced16.0.R4

Platforms

All

offset number
Synopsis Offset of the inserted entries
Context configure filter ip-filter string embed openflow reference offset number
Treeopenflow
Range0 to 2097150

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

All

grt
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisGlobal routing context
Contextconfigure filter ip-filter string embed openflow reference offset number grt
Treegrt

Notes

The following elements are part of a choice: grt, system, (sap and vpls), or vprn.

Introduced16.0.R4

Platforms

All

sap reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSAP context
Contextconfigure filter ip-filter string embed openflow reference offset number sap reference
Treesap

Reference

configure service vpls string sap string

Notes

The following elements are part of a choice: grt, system, (sap and vpls), or vprn.

Introduced16.0.R4

Platforms

All

system
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSystem context
Contextconfigure filter ip-filter string embed openflow reference offset number system
Treesystem

Notes

The following elements are part of a choice: grt, system, (sap and vpls), or vprn.

Introduced16.0.R4

Platforms

All

vpls reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVPLS context
Contextconfigure filter ip-filter string embed openflow reference offset number vpls reference
Treevpls

Reference

configure service vpls string

Notes

The following elements are part of a choice: grt, system, (sap and vpls), or vprn.

Introduced16.0.R4

Platforms

All

vprn reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVPRN context
Contextconfigure filter ip-filter string embed openflow reference offset number vprn reference
Treevprn

Reference

configure service vprn string

Notes

The following elements are part of a choice: grt, system, (sap and vpls), or vprn.

Introduced16.0.R4

Platforms

All

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure filter ip-filter string entry number
Treeentry
Introduced16.0.R1

Platforms

All

[entry-id] number
Synopsis ID for a match criteria and the corresponding action
Contextconfigure filter ip-filter string entry number
Treeentry
Range1 to 2097151

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

All

action
Synopsis Enable the action context
Context configure filter ip-filter string entry number action
Treeaction
Introduced16.0.R1

Platforms

All

accept
Synopsis Accept regular routing to forward a matching packet
Contextconfigure filter ip-filter string entry number action accept
Treeaccept

Notes

The following elements are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.

Introduced16.0.R1

Platforms

All

accept-when
Synopsis Enable the accept-when context
Contextconfigure filter ip-filter string entry number action accept-when
Treeaccept-when
Introduced19.5.R1

Platforms

All

pattern
Synopsis Enable the pattern context
Context configure filter ip-filter string entry number action accept-when pattern
Treepattern
Introduced19.5.R1

Platforms

All

drop
Synopsis Drop a packet matching this entry
Context configure filter ip-filter string entry number action drop
Treedrop

Notes

The following elements are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.

Introduced16.0.R1

Platforms

All

drop-when
Synopsis Enable the drop-when context
Context configure filter ip-filter string entry number action drop-when
Treedrop-when
Introduced16.0.R1

Platforms

All

packet-length
Synopsis Enable the packet-length context
Contextconfigure filter ip-filter string entry number action drop-when packet-length
Treepacket-length

Notes

The following elements are part of a choice: packet-length or ttl.

Introduced16.0.R1

Platforms

All

eq number
Synopsis Exact match criterion for the length
Context configure filter ip-filter string entry number action drop-when packet-length eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced16.0.R1

Platforms

All

gt number
Synopsis Greater than match criterion for the length
Contextconfigure filter ip-filter string entry number action drop-when packet-length gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced16.0.R1

Platforms

All

lt number
Synopsis Less than match criterion for the length
Contextconfigure filter ip-filter string entry number action drop-when packet-length lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced16.0.R1

Platforms

All

range
Synopsis Enable the range context
Context configure filter ip-filter string entry number action drop-when packet-length range
Treerange

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced16.0.R1

Platforms

All

pattern
Synopsis Enable the pattern context
Context configure filter ip-filter string entry number action drop-when pattern
Treepattern
Introduced16.0.R4

Platforms

All

ttl
Synopsis Enable the ttl context
Context configure filter ip-filter string entry number action drop-when ttl
Treettl

Notes

The following elements are part of a choice: packet-length or ttl.

Introduced16.0.R1

Platforms

All

eq number
Synopsis Equal to condition match value
Context configure filter ip-filter string entry number action drop-when ttl eq number
Treeeq
Range0 to 255

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced16.0.R1

Platforms

All

gt number
Synopsis Greater than condition match value
Context configure filter ip-filter string entry number action drop-when ttl gt number
Treegt
Range0 to 254

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced16.0.R1

Platforms

All

lt number
Synopsis Less than condition match value
Context configure filter ip-filter string entry number action drop-when ttl lt number
Treelt
Range1 to 255

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced16.0.R1

Platforms

All

range
Synopsis Enable the range context
Context configure filter ip-filter string entry number action drop-when ttl range
Treerange

Description

This command in this context specify an inclusive range. When range is used, the start of the range (the first value entered) must be smaller than the end of the range (the second value entered).

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced16.0.R1

Platforms

All

fc keyword
Synopsis Class name to be forwarded for matching packets
Contextconfigure filter ip-filter string entry number action fc keyword
Treefc
Optionsbe, l2, af, l1, h2, ef, h1, nc
Introduced 16.0.R1

Platforms

All

forward
Synopsis Enter the forward context
Context configure filter ip-filter string entry number action forward
Treeforward

Notes

The following elements are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.

Introduced16.0.R1

Platforms

All

bonding-connection number
Synopsis Connection ID over which packet is forwarded
Contextconfigure filter ip-filter string entry number action forward bonding-connection number
Treebonding-connection
Range1 to 2

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

esi-l2
Synopsis Enable the esi-l2 context
Context configure filter ip-filter string entry number action forward esi-l2
Treeesi-l2

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.

Introduced16.0.R1

Platforms

All

esi-l3
Synopsis Enable the esi-l3 context
Context configure filter ip-filter string entry number action forward esi-l3
Treeesi-l3

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.

Introduced16.0.R1

Platforms

All

esi-value string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisESI of the first ESI-identified appliance
Contextconfigure filter ip-filter string entry number action forward esi-l3 esi-value string
Treeesi-value

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

sf-ip string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP address of the service function to forward traffic
Contextconfigure filter ip-filter string entry number action forward esi-l3 sf-ip string
Treesf-ip

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

vprn reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVPRN service name
Contextconfigure filter ip-filter string entry number action forward esi-l3 vprn reference
Treevprn

Reference

configure service vprn string

Notes

This element is mandatory.

Introduced16.0.R4

Platforms

All

gre-tunnel reference
Synopsis GRE tunnel template ID that sets the location where an encapsulated matching packet is transported
Contextconfigure filter ip-filter string entry number action forward gre-tunnel reference
Treegre-tunnel

Reference

configure filter gre-tunnel-template string

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.

Introduced16.0.R1

Platforms

All

lsp string
Synopsis LSP that is specified to forward a packet matching this entry
Contextconfigure filter ip-filter string entry number action forward lsp string
Treelsp
String Length1 to 64

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.

Introduced16.0.R1

Platforms

All

mpls-policy
Synopsis Enable the mpls-policy context
Contextconfigure filter ip-filter string entry number action forward mpls-policy
Treempls-policy

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.

Introduced19.10.R1

Platforms

All

next-hop
Synopsis Enable the next-hop context
Context configure filter ip-filter string entry number action forward next-hop
Treenext-hop

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.

Introduced16.0.R1

Platforms

All

interface-name string
Synopsis IP interface name that forwards matching packets
Contextconfigure filter ip-filter string entry number action forward next-hop interface-name string
Treeinterface-name
String Length1 to 32

Notes

The following elements are part of a mandatory choice: interface-name, nh-ip, or nh-ip-vrf.

Introduced16.0.R1

Platforms

All

nh-ip
Synopsis Enable the nh-ip context
Context configure filter ip-filter string entry number action forward next-hop nh-ip
Treenh-ip

Notes

The following elements are part of a mandatory choice: interface-name, nh-ip, or nh-ip-vrf.

Introduced16.0.R1

Platforms

All

address string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIPv4 address of next hop to forward matching packets
Contextconfigure filter ip-filter string entry number action forward next-hop nh-ip address string
Treeaddress

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

nh-ip-vrf
Synopsis Enable the nh-ip-vrf context
Context configure filter ip-filter string entry number action forward next-hop nh-ip-vrf
Treenh-ip-vrf

Notes

The following elements are part of a mandatory choice: interface-name, nh-ip, or nh-ip-vrf.

Introduced16.0.R1

Platforms

All

address string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIPv4 address of next hop to forward matching packets
Contextconfigure filter ip-filter string entry number action forward next-hop nh-ip-vrf address string
Treeaddress

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

redirect-policy reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNext hop or forward next hop router that forwards a packet that matches this entry
Contextconfigure filter ip-filter string entry number action forward redirect-policy reference
Treeredirect-policy

Reference

configure filter redirect-policy string

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.

Introduced16.0.R1

Platforms

All

router-instance string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisRouter name or VPRN service name
Contextconfigure filter ip-filter string entry number action forward router-instance string
Treerouter-instance

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.

Introduced16.0.R1

Platforms

All

sap
Synopsis Enable the sap context
Context configure filter ip-filter string entry number action forward sap
Treesap

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.

Introduced16.0.R1

Platforms

All

sdp
Synopsis Enable the sdp context
Context configure filter ip-filter string entry number action forward sdp
Treesdp

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.

Introduced16.0.R1

Platforms

All

srte-policy
Synopsis Enable the srte-policy context
Contextconfigure filter ip-filter string entry number action forward srte-policy
Treesrte-policy

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.

Introduced19.10.R1

Platforms

All

vprn-target
Synopsis Enable the vprn-target context
Contextconfigure filter ip-filter string entry number action forward vprn-target
Treevprn-target

Notes

The following elements are part of a choice: bonding-connection, esi-l2, esi-l3, gre-tunnel, lsp, mpls-policy, next-hop, redirect-policy, router-instance, sap, sdp, srte-policy, or vprn-target.

Introduced16.0.R1

Platforms

All

gtp-local-breakout
Synopsis Break out matching traffic locally from a GTP tunnel for GTP-subscriber-hosts, or forward for other entities
Contextconfigure filter ip-filter string entry number action gtp-local-breakout
Treegtp-local-breakout

Notes

The following elements are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.

Introduced16.0.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

http-redirect
Synopsis Enable the http-redirect context
Contextconfigure filter ip-filter string entry number action http-redirect
Treehttp-redirect

Description

Commands in this context configure the filter entry action for HTTP redirection.

Notes

The following elements are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.

Introduced16.0.R1

Platforms

All

allow-override boolean
Synopsis Override the HTTP redirect URL by a RADIUS VSA
Contextconfigure filter ip-filter string entry number action http-redirect allow-override boolean
Treeallow-override

Description

This command specifies whether the RADIUS VSA can override the configured HTTP redirect URL for this filter entry.  

When configured to true, the RADIUS VSA can override the HTTP redirect URL. 

When configured to false, the HTTP redirect URL is not overriden.

This does not apply if the CPF option is specified for the URL.

Defaultfalse
Introduced16.0.R1

Platforms

All

url (keyword | http-redirect-url)
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisURL used for HTTP redirect action
Contextconfigure filter ip-filter string entry number action http-redirect url (keyword | http-redirect-url)
Treeurl

Description

This command specifies the URL to use for HTTP redirection for this filter entry.  

A URL can be specified or the CPF option can be used for BNG CUPS ESM sessions only.

The following macro substitutions may be used:

$URL — request-URI in the HTTP GET request received

$MAC — a string that represents the MAC address of the subscriber

host

$IP — a string that represents the IP address of the subscriber host

$SUB — a string that represents the subscriber ID

$SAP — a string that represents a SAP ID

$SAPDESC — description string configured on the SAP

$CID — a string that represents the circuit ID or interface ID of the

subscriber host (hexadecimal format)

$RID — a string that represents the remote ID of the subscriber host

(hexadecimal format)

String Length 1 to 255
Options from-cpf

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

ignore-match
Synopsis Ignore match criteria for the entry
Context configure filter ip-filter string entry number action ignore-match
Treeignore-match

Notes

The following elements are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.

Introduced16.0.R1

Platforms

All

l2-aware-nat-bypass boolean
Synopsis Divert traffic from an L2-Aware NAT subscriber
Contextconfigure filter ip-filter string entry number action l2-aware-nat-bypass boolean
Treel2-aware-nat-bypass

Description

When configured to true, the filter action selectively diverts traffic from a L2-Aware NAT subscriber away from NAT. This action is only applicable to L2-Aware NAT subscribers and must be configured together with action accept. Traffic identified in the match condition bypasses L2-Aware NAT. An example is to bypass NAT for on-net destinations (within the customer network).

For selective NAT bypass to take effect, in addition to IP filter configuration, the L2-Aware NAT subscriber must be specifically enabled for selective bypass via the allow-bypass configuration option in the configure subscriber-mgmt sub-profile nat allow-bypass context.

When configured to false, traffic that is not classified for bypass automatically diverts to L2-Aware NAT, unless it is explicitly configured in the IP filter action to be dropped.

Defaultfalse
Introduced20.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

nat
Synopsis Enable the nat context
Context configure filter ip-filter string entry number action nat
Treenat

Notes

The following elements are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

nat-policy reference
WARNING:

Modifying this element clears ISA state, such as flow state, for the new value to take effect.

SynopsisNAT policy name when action is NAT
Contextconfigure filter ip-filter string entry number action nat nat-policy reference
Treenat-policy

Reference

configure service nat nat-policy string

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

rate-limit
Synopsis Enable the rate-limit context
Context configure filter ip-filter string entry number action rate-limit
Treerate-limit
Introduced16.0.R1

Platforms

All

packet-length
Synopsis Enable the packet-length context
Contextconfigure filter ip-filter string entry number action rate-limit packet-length
Treepacket-length

Notes

The following elements are part of a choice: packet-length or ttl.

Introduced16.0.R1

Platforms

All

eq number
Synopsis Exact match criterion for the length
Context configure filter ip-filter string entry number action rate-limit packet-length eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced16.0.R1

Platforms

All

gt number
Synopsis Greater than match criterion for the length
Contextconfigure filter ip-filter string entry number action rate-limit packet-length gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced16.0.R1

Platforms

All

lt number
Synopsis Less than match criterion for the length
Contextconfigure filter ip-filter string entry number action rate-limit packet-length lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced16.0.R1

Platforms

All

range
Synopsis Enable the range context
Context configure filter ip-filter string entry number action rate-limit packet-length range
Treerange

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced16.0.R1

Platforms

All

pattern
Synopsis Enable the pattern context
Context configure filter ip-filter string entry number action rate-limit pattern
Treepattern
Introduced16.0.R4

Platforms

All

pir (number | keyword)
Synopsis Peak information rate
Context configure filter ip-filter string entry number action rate-limit pir (number | keyword)
Treepir
Range0 to 2000000000
Unitskilobps
Options max

Notes

The following elements are part of a mandatory choice: pir or pps-pir.

Introduced16.0.R1

Platforms

All

pps-pir (number | keyword)
Synopsis Peak information rate
Context configure filter ip-filter string entry number action rate-limit pps-pir (number | keyword)
Treepps-pir
Range0 to 100000000
Unitspackets per second
Optionsmax

Notes

The following elements are part of a mandatory choice: pir or pps-pir.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, 7950 XRS

ttl
Synopsis Enable the ttl context
Context configure filter ip-filter string entry number action rate-limit ttl
Treettl

Notes

The following elements are part of a choice: packet-length or ttl.

Introduced16.0.R1

Platforms

All

eq number
Synopsis Equal to condition match value
Context configure filter ip-filter string entry number action rate-limit ttl eq number
Treeeq
Range0 to 255

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced16.0.R1

Platforms

All

gt number
Synopsis Greater than condition match value
Context configure filter ip-filter string entry number action rate-limit ttl gt number
Treegt
Range0 to 254

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced16.0.R1

Platforms

All

lt number
Synopsis Less than condition match value
Context configure filter ip-filter string entry number action rate-limit ttl lt number
Treelt
Range1 to 255

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced16.0.R1

Platforms

All

range
Synopsis Enable the range context
Context configure filter ip-filter string entry number action rate-limit ttl range
Treerange

Description

This command in this context specify an inclusive range. When range is used, the start of the range (the first value entered) must be smaller than the end of the range (the second value entered).

Notes

The following elements are part of a mandatory choice: eq, gt, lt, or range.

Introduced16.0.R1

Platforms

All

reassemble
Synopsis Forward matching packets to reassembly function
Contextconfigure filter ip-filter string entry number action reassemble
Treereassemble

Notes

The following elements are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

remark
Synopsis Enable the remark context
Context configure filter ip-filter string entry number action remark
Treeremark
Introduced16.0.R1

Platforms

All

dscp keyword
Synopsis Destination SAP
Context configure filter ip-filter string entry number action remark dscp keyword
Treedscp
Optionsbe, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63

Notes

This element is mandatory.

Introduced 16.0.R1

Platforms

All

secondary
Synopsis Enable the secondary context
Context configure filter ip-filter string entry number action secondary
Treesecondary
Introduced16.0.R1

Platforms

All

forward
Synopsis Enter the forward context
Context configure filter ip-filter string entry number action secondary forward
Treeforward

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

next-hop
Synopsis Enable the next-hop context
Context configure filter ip-filter string entry number action secondary forward next-hop
Treenext-hop

Notes

The following elements are part of a choice: next-hop, sap, sdp, or vprn-target.

Introduced16.0.R1

Platforms

All

nh-ip-vrf
Synopsis Enable the nh-ip-vrf context
Context configure filter ip-filter string entry number action secondary forward next-hop nh-ip-vrf
Treenh-ip-vrf

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

address string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIPv4 address of next hop to forward matching packets
Contextconfigure filter ip-filter string entry number action secondary forward next-hop nh-ip-vrf address string
Treeaddress

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

sap
Synopsis Enable the sap context
Context configure filter ip-filter string entry number action secondary forward sap
Treesap

Notes

The following elements are part of a choice: next-hop, sap, sdp, or vprn-target.

Introduced16.0.R1

Platforms

All

sap-id reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisSAP ID used to forward packets matching the entry
Contextconfigure filter ip-filter string entry number action secondary forward sap sap-id reference
Treesap-id

Reference

configure service vpls string sap string

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

sdp
Synopsis Enable the sdp context
Context configure filter ip-filter string entry number action secondary forward sdp
Treesdp

Notes

The following elements are part of a choice: next-hop, sap, sdp, or vprn-target.

Introduced16.0.R1

Platforms

All

sdp-bind-id string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVPLS SDP bind ID used to forward matching packets
Contextconfigure filter ip-filter string entry number action secondary forward sdp sdp-bind-id string
Treesdp-bind-id
String Length3 to 16

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All

vprn-target
Synopsis Enable the vprn-target context
Contextconfigure filter ip-filter string entry number action secondary forward vprn-target
Treevprn-target

Notes

The following elements are part of a choice: next-hop, sap, sdp, or vprn-target.

Introduced21.7.R1

Platforms

All

remark
Synopsis Enable the remark context
Context configure filter ip-filter string entry number action secondary remark
Treeremark
Introduced16.0.R1

Platforms

All

dscp keyword
Synopsis Destination SAP
Context configure filter ip-filter string entry number action secondary remark dscp keyword
Treedscp
Optionsbe, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63

Notes

This element is mandatory.

Introduced 16.0.R1

Platforms

All

tcp-mss-adjust
Synopsis Adjust MSS option of TCP matching packets to configured value of tcp-mss in router interface context
Contextconfigure filter ip-filter string entry number action tcp-mss-adjust
Treetcp-mss-adjust

Notes

The following elements are part of a mandatory choice: accept, drop, forward, gtp-local-breakout, http-redirect, ignore-match, nat, reassemble, or tcp-mss-adjust.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

egress-pbr keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPBR that has an effect when this filter is applied on egress
Contextconfigure filter ip-filter string entry number egress-pbr keyword
Treeegress-pbr
Optionstrue, true-with-l4lb
Introduced16.0.R1

Platforms

All

filter-sample boolean
Synopsis Sample matching traffic if IP interface is set to cflowd ACL mode
Contextconfigure filter ip-filter string entry number filter-sample boolean
Treefilter-sample
Defaultfalse
Introduced16.0.R1

Platforms

All

log reference
Synopsis Log that is used for packets matching this entry
Contextconfigure filter ip-filter string entry number log reference
Treelog

Reference

configure filter log number

Introduced16.0.R1

Platforms

All

match
Synopsis Enter the match context
Context configure filter ip-filter string entry number match
Treematch

Description

Commands in this context configure match criteria for the filter entry. When the match criteria are satisfied, the action associated with the match criteria is executed.

Introduced16.0.R1

Platforms

All

destination-class number
Synopsis Destination class as a match criterion
Contextconfigure filter ip-filter string entry number match destination-class number
Treedestination-class

Description

This command configures the BGP destination class value as a match criterion. Filtering egress traffic on the destination class requires the destination-class-lookup command (under the ingress context for the service interface) to be enabled (set to true).

Range1 to 255
Introduced20.7.R1

Platforms

All

dscp keyword
Synopsis DSCP used as an IP filter match criterion
Contextconfigure filter ip-filter string entry number match dscp keyword
Treedscp
Optionsbe, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63
Introduced 16.0.R1

Platforms

All

dst-ip
Synopsis Enter the dst-ip context
Context configure filter ip-filter string entry number match dst-ip
Treedst-ip

Notes

The following elements are part of a choice: ip or (dst-ip and src-ip).

Introduced16.0.R1

Platforms

All

address (ipv4-prefix-with-host-bits | ipv4-address)
Synopsis IPv4 address used as the match criterion
Contextconfigure filter ip-filter string entry number match dst-ip address (ipv4-prefix-with-host-bits | ipv4-address)
Treeaddress

Notes

The following elements are part of a choice: (address and mask) or ip-prefix-list.

Introduced16.0.R1

Platforms

All

mask string
Synopsis IPv4 address mask used as the match criterion
Contextconfigure filter ip-filter string entry number match dst-ip mask string
Treemask

Notes

The following elements are part of a choice: (address and mask) or ip-prefix-list.

Introduced16.0.R1

Platforms

All

dst-port
Synopsis Enter the dst-port context
Context configure filter ip-filter string entry number match dst-port
Treedst-port

Notes

The following elements are part of a choice: port or (dst-port and src-port).

Introduced16.0.R1

Platforms

All

eq number
Synopsis Exact match criterion for the port number
Contextconfigure filter ip-filter string entry number match dst-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced16.0.R1

Platforms

All

gt number
Synopsis Greater than match criterion for the port number
Contextconfigure filter ip-filter string entry number match dst-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced16.0.R1

Platforms

All

lt number
Synopsis Less than match criterion for the port number
Contextconfigure filter ip-filter string entry number match dst-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced16.0.R1

Platforms

All

range
Synopsis Enable the range context
Context configure filter ip-filter string entry number match dst-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced16.0.R1

Platforms

All

end number
Synopsis Upper bound of the port range as port match criterion
Contextconfigure filter ip-filter string entry number match dst-port range end number
Treeend
Range1 to 65535

Notes

This element is mandatory.

Introduced16.0.R1

Platforms

All