application-assurance commands

configure 
application-assurance 
aarp number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
master-selection-mode keyword
peer (ipv4-address-no-zone | ipv6-address-no-zone)
peer-endpoint 
sap 
encap-type keyword
sap-id sap
spoke-sdp sdp-bind-id
priority number
apply-groups reference
apply-groups-exclude reference
cflowd 
field named-item 
apply-groups reference
apply-groups-exclude reference
comment named-item
flow-attribute 
attribute named-item 
apply-groups reference
apply-groups-exclude reference
comment named-item
group number 
apply-groups reference
apply-groups-exclude reference
certificate-profile named-item 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
file certificate-file
cflowd 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
collector (ipv4-address-no-zone | ipv6-address-no-zone) port number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
comprehensive 
apply-groups reference
apply-groups-exclude reference
flow-rate number
flow-rate-2 number
template 
apply-groups reference
apply-groups-exclude reference
dynamic-fields 
admin-state keyword
field named-item 
field-selection keyword
direct-export 
collector number 
address (ipv4-address-no-zone | ipv6-address-no-zone) port number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
apply-groups reference
apply-groups-exclude reference
description description
vlan-id number
export-override 
mode keyword
prefix named-item
obfuscation 
aes-128-encryption-key encrypted-leaf
aes-256-encryption-key encrypted-leaf
system-name named-item
tcp-performance 
apply-groups reference
apply-groups-exclude reference
flow-rate number
flow-rate-2 number
template 
apply-groups reference
apply-groups-exclude reference
dynamic-fields 
admin-state keyword
field named-item 
field-selection keyword
template-retransmit number
volume 
rate number
template 
apply-groups reference
apply-groups-exclude reference
dynamic-fields 
admin-state keyword
field named-item 
field-selection keyword
dns-ip-cache named-item 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
dns-match 
domain named-item 
apply-groups reference
apply-groups-exclude reference
expression display-string
trusted-server-address (ipv4-address-no-zone | ipv6-address-no-zone) 
apply-groups reference
apply-groups-exclude reference
server-name named-item
ip-cache 
high-watermark number
low-watermark number
size number
static-address (ipv4-address-no-zone | ipv6-address-no-zone) 
http-enrich named-item 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
field named-item 
aes-initialization-vector hex-string
anti-spoof boolean
apply-groups reference
apply-groups-exclude reference
calling-line-id boolean
encode 
cert-base64 reference
cert-profile reference
key 
type keyword
value encrypted-leaf
md5-salt string-not-all-spaces
name named-item
static-string string-not-all-spaces
rat-type-enrichment 
rat-type keyword 
apply-groups reference
apply-groups-exclude reference
rat-string string-not-all-spaces
http-error-redirect named-item 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
error-code number 
apply-groups reference
apply-groups-exclude reference
custom-message-size number
http-host display-string
participant-id named-item
template number
http-notification named-item 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
interval (number | keyword)
script-url http-redirect-url
template number
http-redirect named-item 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
captive-redirect 
vlan-id number
description description
redirect-https boolean
redirect-url http-redirect-url
tcp-client-reset boolean
template number
ip-identification-assist 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
passive-dns 
monitor boolean
trusted-server (ipv4-address-no-zone | ipv6-address-no-zone) 
apply-groups reference
apply-groups-exclude reference
comment named-item-or-empty
positive-app-id 
enabled boolean
partition number 
aa-sub-congestion-detection 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
rat-type keyword 
apply-groups reference
apply-groups-exclude reference
rtt-threshold (number | keyword)
rtt-threshold (number | keyword)
rtt-threshold-tolerance number
aa-sub-remote boolean
access-network-location 
source keyword 
apply-groups reference
apply-groups-exclude reference
rat-type keyword 
apply-groups reference
apply-groups-exclude reference
rtt-threshold (number | keyword)
rtt-threshold (number | keyword)
rtt-threshold-tolerance number
source-level keyword
apply-groups reference
apply-groups-exclude reference
aqp-initial-lookup boolean
cflowd 
export-type keyword 
admin-state keyword
app-group reference 
apply-groups reference
apply-groups-exclude reference
rate-choice keyword
application reference 
apply-groups reference
apply-groups-exclude reference
rate-choice keyword
apply-groups reference
apply-groups-exclude reference
description description
event-log named-item 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
buffer-type keyword
max-entries number
syslog 
address (ipv4-address-no-zone | ipv6-address-no-zone)
description description
facility keyword
port number
severity keyword
vlan-id number
gtp 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
gtp-filter named-item 
apply-groups reference
apply-groups-exclude reference
description description
gtp-in-gtp keyword
gtp-tunnel-database 
default-tunnel-endpoint-limit number
validate-gtp-tunnels boolean
validate-sequence-number boolean
validate-source-ip-addr boolean
imsi-apn-filter 
default-action keyword
entry number 
action keyword
apn display-string
apply-groups reference
apply-groups-exclude reference
imsi-mcc-mnc-prefix display-string
src-gsn 
ip-prefix (ipv4-prefix | ipv6-prefix)
ip-prefix-list reference
log 
action keyword
event-log reference
max-payload-length number
message-type 
default-action keyword
entry number 
action keyword
apply-groups reference
apply-groups-exclude reference
value (number | keyword)
message-type-gtp-v2 
default-action keyword
entry number 
action keyword
apply-groups reference
apply-groups-exclude reference
value (number | keyword)
gtpc-inspection boolean
log 
action keyword
event-log reference
mode keyword
http-match-all-requests boolean
http-x-online-host boolean
ip-identification-contribute boolean
ip-prefix-list named-item 
apply-groups reference
apply-groups-exclude reference
description description
prefix (ipv4-prefix | ipv6-prefix) 
apply-groups reference
apply-groups-exclude reference
name named-item
policy 
app-filter 
entry number 
admin-state keyword
application reference
apply-groups reference
apply-groups-exclude reference
description description
expression number 
apply-groups reference
apply-groups-exclude reference
eq display-string
neq display-string
type keyword
flow-setup-direction keyword
http-match-all-requests boolean
http-port 
eq 
port-list reference
port-number number
neq 
port-list reference
port-number number
ip-identification-assist boolean
ip-protocol 
eq (number | keyword)
neq (number | keyword)
network-address 
eq 
ip-prefix (ipv4-prefix | ipv6-prefix)
ip-prefix-list reference
neq 
ip-prefix (ipv4-prefix | ipv6-prefix)
ip-prefix-list reference
protocol 
eq (string | named-item)
neq (string | named-item)
server-address 
eq 
dns-ip-cache reference
ip-prefix (ipv4-prefix | ipv6-prefix)
ip-prefix-list reference
masked-ip 
address (ipv4-address-no-zone | ipv6-address-no-zone)
netmask (ipv4-address-no-zone | ipv6-address-no-zone)
neq 
dns-ip-cache reference
ip-prefix (ipv4-prefix | ipv6-prefix)
ip-prefix-list reference
masked-ip 
address (ipv4-address-no-zone | ipv6-address-no-zone)
netmask (ipv4-address-no-zone | ipv6-address-no-zone)
server-port 
eq 
first-packet-policy keyword
port-list reference
port-number number
range 
end number
start number
gt 
port-number number
lt 
port-number number
neq 
port-list reference
port-number number
range 
end number
start number
app-group named-item 
apply-groups reference
apply-groups-exclude reference
charging-group reference
description description
export-id number
app-profile named-item 
aa-sub-distribute-traffic-by-ip boolean
aa-sub-suppressible boolean
apply-groups reference
apply-groups-exclude reference
capacity-cost number
characteristic reference 
apply-groups reference
apply-groups-exclude reference
value reference
description description
divert boolean
app-qos-policy 
entry number 
action 
abandon-tcp-optimization boolean
apply-groups reference
apply-groups-exclude reference
bandwidth-policer 
anl reference
dual-bucket reference
flow reference
single-bucket reference
dns-ip-cache reference
drop boolean
error-drop 
event-log reference
flow-count-limit-policer 
event-log reference
policer-name reference
flow-setup-rate-policer 
event-log reference
policer-name reference
fragment-drop 
drop-scope keyword
event-log reference
gtp-filter reference
http-enrich reference
http-error-redirect reference
http-notification reference
http-redirect 
flow-type keyword
name reference
mirror-source 
all-inclusive boolean
mirror-service reference
overload-drop 
event-log reference
remark 
dscp 
in-profile keyword
out-profile keyword
fc keyword
priority keyword
sctp-filter reference
session-filter reference
tcp-mss-adjust number
tcp-validate reference
tls-enrich reference
url-filter 
characteristic reference
name reference
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
match 
aa-sub 
esm 
eq named-item
neq named-item
esm-mac 
eq named-item
neq named-item
sap 
eq sap
neq sap
spoke-sdp 
eq sdp-bind-id
neq sdp-bind-id
transit 
eq named-item
neq named-item
aa-sub-tethering keyword
app-group 
eq reference
neq reference
application 
eq reference
neq reference
apply-groups reference
apply-groups-exclude reference
characteristic reference 
apply-groups reference
apply-groups-exclude reference
eq reference
neq reference
charging-group 
eq reference
neq reference
dscp 
eq keyword
neq keyword
dst-ip 
eq 
ip-prefix (ipv4-prefix | ipv6-prefix)
ip-prefix-list reference
neq 
ip-prefix (ipv4-prefix | ipv6-prefix)
ip-prefix-list reference
dst-port 
eq 
port-list reference
port-number number
range 
end number
start number
neq 
port-list reference
port-number number
range 
end number
start number
flow-attribute named-item 
apply-groups reference
apply-groups-exclude reference
confidence 
eq number
gte number
lt number
ip-protocol 
eq (number | keyword)
neq (number | keyword)
src-ip 
eq 
ip-prefix (ipv4-prefix | ipv6-prefix)
ip-prefix-list reference
neq 
ip-prefix (ipv4-prefix | ipv6-prefix)
ip-prefix-list reference
src-port 
eq 
port-list reference
port-number number
range 
end number
start number
neq 
port-list reference
port-number number
range 
end number
start number
traffic-direction keyword
app-service-options 
characteristic named-item 
apply-groups reference
apply-groups-exclude reference
default-value named-item
value named-item 
application named-item 
app-group reference
apply-groups reference
apply-groups-exclude reference
charging-group reference
description description
export-id number
apply-groups reference
apply-groups-exclude reference
charging-filter 
entry number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
charging-group reference
description description
match 
app-group 
eq reference
neq reference
application 
eq reference
neq reference
flow-attribute named-item 
apply-groups reference
apply-groups-exclude reference
confidence 
eq number
gte number
lt number
tethered-flow 
charging-group named-item 
apply-groups reference
apply-groups-exclude reference
description description
export-id number
notify-start-stop keyword
custom-protocol custom-protocol-name 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
expression number 
apply-groups reference
apply-groups-exclude reference
direction keyword
eq display-string
offset number
ip-protocol keyword
default-charging-group reference
default-tethered-charging-group reference
policy-override 
aa-sub 
sap sap 
apply-groups reference
apply-groups-exclude reference
characteristic reference 
apply-groups reference
apply-groups-exclude reference
value reference
spoke-sdp sdp-bind-id 
apply-groups reference
apply-groups-exclude reference
characteristic reference 
apply-groups reference
apply-groups-exclude reference
value reference
transit named-item 
apply-groups reference
apply-groups-exclude reference
characteristic reference 
apply-groups reference
apply-groups-exclude reference
value reference
port-list named-item 
apply-groups reference
apply-groups-exclude reference
description description
port number 
range start number end number 
sctp-filter named-item 
apply-groups reference
apply-groups-exclude reference
description description
event-log reference
ppid 
default-action keyword
entry number 
action keyword
apply-groups reference
apply-groups-exclude reference
value (number | keyword)
ppid-range 
max number
min number
session-filter named-item 
apply-groups reference
apply-groups-exclude reference
default-action 
action keyword
event-log reference
description description
entry number 
action 
deny 
event-log reference
http-redirect reference
l3-l4-redirect 
dst-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
dst-port number
permit 
tcp-optimizer reference
apply-groups reference
apply-groups-exclude reference
description description
match 
dst-ip 
dns-ip-cache reference
ip-prefix (ipv4-prefix | ipv6-prefix)
ip-prefix-list reference
dst-port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
ip-protocol (number | keyword)
src-ip 
ip-prefix (ipv4-prefix | ipv6-prefix)
ip-prefix-list reference
src-port 
eq number
gt number
lt number
port-list reference
range 
end number
start number
shallow-inspection boolean
statistics 
aa-admit-deny 
accounting-policy reference
apply-groups reference
apply-groups-exclude reference
collect-stats boolean
gtp-filter-stats boolean
policer-stats boolean
policer-stats-resources boolean
sctp-filter-stats boolean
session-filter-stats boolean
tcp-validate-stats boolean
aa-app-group 
accounting-policy reference
apply-groups reference
apply-groups-exclude reference
collect-stats boolean
aa-application 
accounting-policy reference
apply-groups reference
apply-groups-exclude reference
collect-stats boolean
aa-partition 
accounting-policy reference
apply-groups reference
apply-groups-exclude reference
collect-stats boolean
tethering-stats boolean
traffic-type-stats boolean
aa-protocol 
accounting-policy reference
admin-state keyword
apply-groups reference
apply-groups-exclude reference
collect-stats boolean
aa-sub 
accounting-policy reference
aggregate-stats-export-using keyword
app-group reference 
apply-groups reference
apply-groups-exclude reference
export-using keyword
application reference 
apply-groups reference
apply-groups-exclude reference
export-using keyword
apply-groups reference
apply-groups-exclude reference
charging-group reference 
apply-groups reference
apply-groups-exclude reference
export-using keyword
collect-stats boolean
exclude-tcp-retrans boolean
max-throughput-stats boolean
protocol named-item 
apply-groups reference
apply-groups-exclude reference
export-using keyword
radius-accounting-policy reference
usage-monitoring boolean
aa-sub-study keyword 
aa-sub 
esm named-item 
esm-mac named-item 
sap sap 
spoke-sdp sdp-bind-id 
transit named-item 
accounting-policy reference
apply-groups reference
apply-groups-exclude reference
collect-stats boolean
tcp-validate named-item 
apply-groups reference
apply-groups-exclude reference
description description
log 
all boolean
event-log reference
strict boolean
tethering-detection 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
single-device 
expected-ttl number 
invert-match boolean
ttl-monitor 
tcp-protocols keyword
udp-protocols keyword
threshold-crossing-alert 
criteria keyword direction keyword 
apply-groups reference
apply-groups-exclude reference
high-watermark number
low-watermark number
gtp-filter reference criteria keyword direction keyword 
apply-groups reference
apply-groups-exclude reference
high-watermark number
low-watermark number
gtp-filter-entry reference entry-id number direction keyword 
apply-groups reference
apply-groups-exclude reference
high-watermark number
low-watermark number
policer named-item direction keyword 
apply-groups reference
apply-groups-exclude reference
high-watermark number
low-watermark number
sctp-filter reference criteria keyword direction keyword 
apply-groups reference
apply-groups-exclude reference
high-watermark number
low-watermark number
sctp-filter-entry reference entry-id reference direction keyword 
apply-groups reference
apply-groups-exclude reference
high-watermark number
low-watermark number
session-filter reference criteria keyword direction keyword 
apply-groups reference
apply-groups-exclude reference
high-watermark number
low-watermark number
session-filter-entry reference entry-id reference direction keyword 
apply-groups reference
apply-groups-exclude reference
high-watermark number
low-watermark number
tcp-validate reference direction keyword 
apply-groups reference
apply-groups-exclude reference
high-watermark number
low-watermark number
transit-ip-policy number 
apply-groups reference
apply-groups-exclude reference
default-app-profile reference
description description
detect-seen-ip boolean
dhcp 
admin-state keyword
diameter 
admin-state keyword
application-policy reference
ipv6-address-prefix-length number
radius 
admin-state keyword
authentication-policy reference
seen-ip-radius-acct-policy reference
static-aa-sub named-item 
app-profile reference
apply-groups reference
apply-groups-exclude reference
ip (ipv4-unicast-address | ipv6-prefix) 
sub-ident-policy reference
transit-auto-create 
admin-state keyword
inactivity-monitor boolean
transit-prefix-policy number 
apply-groups reference
apply-groups-exclude reference
description description
entry number 
aa-sub reference
apply-groups reference
apply-groups-exclude reference
match 
aa-sub-ip (ipv4-prefix | ipv6-prefix)
network-ip (ipv4-prefix | ipv6-prefix)
static-aa-sub named-item 
app-profile reference
apply-groups reference
apply-groups-exclude reference
is-remote boolean
wap1x 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
policer 
anl-bandwidth-policer named-item 
action keyword
adaptation-rule 
pir keyword
apply-groups reference
apply-groups-exclude reference
description description
mbs number
rate-percentage number
rate-percentage-stage-2 number
dual-bucket-bandwidth-policer named-item 
adaptation-rule 
cir keyword
pir keyword
apply-groups reference
apply-groups-exclude reference
cbs number
cir (number | keyword)
congestion-override 
cbs number
cir (number | keyword)
mbs number
pir (number | keyword)
congestion-override-stage-2 
cbs number
cir (number | keyword)
mbs number
pir (number | keyword)
description description
mbs number
pir (number | keyword)
time-of-day-override number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
cbs number
cir (number | keyword)
description description
mbs number
pir (number | keyword)
time-range 
daily 
all-days 
end policer-end-time
on keyword
start policer-start-time
weekly 
end 
day keyword
time policer-end-time
start 
day keyword
time policer-start-time
flow-bandwidth-policer named-item 
action keyword
adaptation-rule 
pir keyword
apply-groups reference
apply-groups-exclude reference
congestion-override 
mbs number
pir (number | keyword)
congestion-override-stage-2 
mbs number
pir (number | keyword)
description description
mbs number
pir (number | keyword)
time-of-day-override number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
mbs number
pir (number | keyword)
time-range 
daily 
all-days 
end policer-end-time
on keyword
start policer-start-time
weekly 
end 
day keyword
time policer-end-time
start 
day keyword
time policer-start-time
flow-count-limit-policer named-item 
action keyword
apply-groups reference
apply-groups-exclude reference
description description
granularity keyword
limit-gtp-flows boolean
peak-flow-count (number | keyword)
time-of-day-override number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
peak-flow-count (number | keyword)
time-range 
daily 
all-days 
end policer-end-time
on keyword
start policer-start-time
weekly 
end 
day keyword
time policer-end-time
start 
day keyword
time policer-start-time
flow-setup-rate-policer named-item 
action keyword
adaptation-rule 
peak-flow-setup-rate keyword
apply-groups reference
apply-groups-exclude reference
description description
flow-setup-rate-burst-size number
granularity keyword
peak-flow-setup-rate (number | keyword)
time-of-day-override number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
flow-setup-rate-burst-size number
peak-flow-setup-rate (number | keyword)
time-range 
daily 
all-days 
end policer-end-time
on keyword
start policer-start-time
weekly 
end 
day keyword
time policer-end-time
start 
day keyword
time policer-start-time
single-bucket-bandwidth-policer named-item 
action keyword
adaptation-rule 
pir keyword
apply-groups reference
apply-groups-exclude reference
congestion-override 
mbs number
pir (number | keyword)
congestion-override-stage-2 
mbs number
pir (number | keyword)
description description
granularity keyword
mbs number
pir (number | keyword)
time-of-day-override number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
mbs number
pir (number | keyword)
time-range 
daily 
all-days 
end policer-end-time
on keyword
start policer-start-time
weekly 
end 
day keyword
time policer-end-time
start 
day keyword
time policer-start-time
tcp-optimizer named-item 
apply-groups reference
apply-groups-exclude reference
dack-timeout number
description description
high-cpu-backoff boolean
initial-cwnd number
initial-ss-threshold (number | keyword)
network-rtt-threshold number
tcp-stack keyword
url-filter named-item 
admin-state keyword
apply-function-specific-behaviour boolean
apply-groups reference
apply-groups-exclude reference
default-action 
allow 
block-all 
block-http-redirect reference
description description
http-redirect reference
http-request-filtering keyword
icap 
custom-x-header named-item
default-action 
allow 
block-all 
block-http-redirect reference
http-redirect reference
server (ipv4-address-no-zone | ipv6-address-no-zone) port number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
vlan-id number
local-filtering 
allow-list reference
deny-list reference 
apply-groups reference
apply-groups-exclude reference
default-action 
allow 
block-all 
block-http-redirect reference
http-redirect reference
web-service 
category-set number
classification-overrides 
entry number 
apply-groups reference
apply-groups-exclude reference
category-name named-item
expression display-string
classifier keyword
default-action 
allow 
block-all 
block-http-redirect reference
default-profile reference
dns-server (ipv4-address-no-zone | ipv6-address-no-zone)
fqdn display-string
http-redirect reference
profile named-item 
apply-groups reference
apply-groups-exclude reference
block 
category web-serv-category-name 
description description
server (ipv4-address-no-zone | ipv6-address-no-zone) port number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
vlan-id number
url-list named-item 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description description
file display-string
host-expressions boolean
key encrypted-leaf
size keyword
http-enrich 
field named-item 
apply-groups reference
apply-groups-exclude reference
comment named-item
http-error-redirect 
error-code number 
apply-groups reference
apply-groups-exclude reference
comment named-item
template number 
apply-groups reference
apply-groups-exclude reference
comment named-item
http-notification 
template number 
apply-groups reference
apply-groups-exclude reference
comment named-item
http-redirect 
template number 
apply-groups reference
apply-groups-exclude reference
comment named-item
protocol named-item 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
radius-accounting-policy named-item 
apply-groups reference
apply-groups-exclude reference
description description
interim-update-interval number
radius-accounting-server 
access-algorithm keyword
retry number
router-instance string
server number 
address ipv4-unicast-address
apply-groups reference
apply-groups-exclude reference
port number
secret encrypted-leaf
source-address ipv4-unicast-address
timeout number
significant-change number
usage-alert-thresholds 
bit-rate-high-wmark (number | keyword)
bit-rate-low-wmark number
datapath-cpu-high-wmark (number | keyword)
datapath-cpu-low-wmark number
flow-setup-rate-high-wmark (number | keyword)
flow-setup-rate-low-wmark number
flow-table-high-wmark number
flow-table-low-wmark number
packet-rate-high-wmark (number | keyword)
packet-rate-low-wmark number

application-assurance command descriptions

application-assurance

Synopsis Enter the application-assurance context
Contextconfigure application-assurance
Treeapplication-assurance

Description

Commands in this context configure the attributes of Application Assurance (AA) operations.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

aarp [aarp-id] number

Synopsis Enter the aarp list instance
Context configure application-assurance aarp number
Treeaarp

Description

Commands in this context define an Application Assurance Redundancy Protocol (AARP) instance. This instance is paired with the same AARP ID in a peer node, as part of the configuration to provide flow and packet asymmetry removal for traffic of a multi-homed SAP or spoke SDP.

Max. instances100
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[aarp-id] number
Synopsis AARP ID
Contextconfigure application-assurance aarp number
Treeaarp
Range1 to 65535

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the AARP instance
Contextconfigure application-assurance aarp number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

description description
Synopsis Text description
Context configure application-assurance aarp number description description
Treedescription
String length1 to 80
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

master-selection-mode keyword
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAARP master selection mode
Contextconfigure application-assurance aarp number master-selection-mode keyword
Treemaster-selection-mode

Description

This command configures the AARP mode of operation with the peer instance. The modes affect the AARP state machine behavior according to the specified behavior. 

Optionsminimize-switchovers, inter-chassis-efficiency, priority-based-balance
Defaultminimize-switchovers
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

peer (ipv4-address-no-zone | ipv6-address-no-zone)
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAARP peer IP address
Contextconfigure application-assurance aarp number peer (ipv4-address-no-zone | ipv6-address-no-zone)
Treepeer

Description

This command defines the IP address of the AARP peer router, which must be a routable system IP address. If no peer is configured when the AARP is administratively enabled, it is configured as a single node AARP instance.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

peer-endpoint
Synopsis Enter the peer-endpoint context
Contextconfigure application-assurance aarp number peer-endpoint
Treepeer-endpoint

Description

Commands in this context specify the attributes of the peer endpoint parent AA subscriber of the AARP peer.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

sap
Synopsis Enable the sap context
Context configure application-assurance aarp number peer-endpoint sap
Treesap

Notes

The following elements are part of a choice: sap or spoke-sdp.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

spoke-sdp sdp-bind-id
Synopsis AARP peer endpoint spoke SDP
Context configure application-assurance aarp number peer-endpoint spoke-sdp sdp-bind-id
Treespoke-sdp
String length3 to 16

Notes

The following elements are part of a choice: sap or spoke-sdp.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

priority number
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAARP priority
Contextconfigure application-assurance aarp number priority number
Treepriority

Description

This command defines the priority for the AARP instance. The priority value is used to determine the master and backup upon initialization or rebalance.

Range0 to 255
Default100
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

cflowd

Synopsis Enter the cflowd context
Context configure application-assurance cflowd
Treecflowd
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

field [field-name] named-item
Synopsis Enter the field list instance
Context configure application-assurance cflowd field named-item
Treefield
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[field-name] named-item
Synopsis Cflowd record field name
Context configure application-assurance cflowd field named-item
Treefield
String length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

comment named-item
Synopsis User information comment
Context configure application-assurance cflowd field named-item comment named-item
Treecomment
String length1 to 32
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

flow-attribute

Synopsis Enter the flow-attribute context
Contextconfigure application-assurance flow-attribute
Treeflow-attribute
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

attribute [attribute-name] named-item
Synopsis Enter the attribute list instance
Contextconfigure application-assurance flow-attribute attribute named-item
Treeattribute
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[attribute-name] named-item
Synopsis Attribute name
Contextconfigure application-assurance flow-attribute attribute named-item
Treeattribute
String length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

group [aa-group-id] number

Synopsis Enter the group list instance
Context configure application-assurance group number
Treegroup

Description

Commands in this context configure an Application Assurance group and partition parameters.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[aa-group-id] number
Synopsis AA group ID
Contextconfigure application-assurance group number
Treegroup
Range1 to 255

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

certificate-profile [cert-prof-name] named-item
Synopsis Enter the certificate-profile list instance
Contextconfigure application-assurance group number certificate-profile named-item
Treecertificate-profile

Description

Commands in this context create a certificate profile to be used for certificate-based encryption in HTTP header enrichment.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

file certificate-file
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisCertificate file name
Contextconfigure application-assurance group number certificate-profile named-item file certificate-file
Treefile
String length1 to 95
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

cflowd
Synopsis Enter the cflowd context
Context configure application-assurance group number cflowd
Treecflowd
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of cflowd export
Contextconfigure application-assurance group number cflowd admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

collector [ip-address] (ipv4-address-no-zone | ipv6-address-no-zone) port number
Synopsis Enter the collector list instance
Contextconfigure application-assurance group number cflowd collector (ipv4-address-no-zone | ipv6-address-no-zone) port number
Treecollector

Description

Commands in this context configure flow data collectors for cflowd data.

In the current release, the system supports IPv4 addresses only for the cflowd collector host.

Max. instances2
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the remote cflowd collector host
Contextconfigure application-assurance group number cflowd collector (ipv4-address-no-zone | ipv6-address-no-zone) port number
Treecollector

Description

This command configures the IP address of the remote cflowd collector host.

In the current release, the system supports IPv4 addresses only for the cflowd collector host.

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

port number
Synopsis Cflowd collector host port number
Context configure application-assurance group number cflowd collector (ipv4-address-no-zone | ipv6-address-no-zone) port number
Treecollector

Description

This command configures the UDP port number used by the remote cflowd collector host.

Range1 to 65535
MD-CLI default4739

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the cflowd export
Contextconfigure application-assurance group number cflowd collector (ipv4-address-no-zone | ipv6-address-no-zone) port number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

comprehensive
Synopsis Enter the comprehensive context
Contextconfigure application-assurance group number cflowd comprehensive
Treecomprehensive

Description

Commands in this context configure cflowd comprehensive records output parameters.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

template
Synopsis Enter the template context
Context configure application-assurance group number cflowd comprehensive template
Treetemplate

Description

Commands in this context configure the template for comprehensive fields.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dynamic-fields
Synopsis Enter the dynamic-fields context
Contextconfigure application-assurance group number cflowd comprehensive template dynamic-fields
Treedynamic-fields

Description

Commands in this context configure the fields that are included in the exported cflowd template.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

field [field-name] named-item
Synopsis Add a list entry for field
Context configure application-assurance group number cflowd comprehensive template dynamic-fields field named-item
Treefield

Description

This command adds a dynamic field to be included in the exported cflowd template.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[field-name] named-item
Synopsis Cflowd template dynamic field name
Context configure application-assurance group number cflowd comprehensive template dynamic-fields field named-item
Treefield

Description

This command specifies the name of the field to be included in the exported cflowd template.

  • Common to all templates are the following values: session/flowStartSeconds, session/flowDurationMilliseconds, postIpPrecedence, ipTTL, aaProt, aaApp, aaAppGrp, hostName, deviceId, deviceMfgId, deviceOsId, ipFamily, deviceOsVer1, deviceOsVer2, deviceOsVer3, anlType, anlTopology, anlCongestionState, timeZone, aaChargingGrp, flowAttr_video, flowAttr_abr_service, flowAttr_audio, flowAttr_encrypted, flowAttr_download, flowAttr_upload, flowAttr_realtime_communication, aaSubTetheringState

  • When AA is deployed in FWA SR, the following value applies: ApnExtended

  • For the TCP and comprehensive templates only, the following values apply: tcpSessionEstDelay, tcpRetransmittedBytes, tcpRetransmittedPackets

  • For the comprehensive templates only when deployed on VSR or ESA in FWA SR configured in the residential mode, the following values apply: dnsAnswerName, dnsType, dnsState, dnsTid, tlsCname, sliceId, mmeAmfAddr, flowActiveBytes, flowActiveTime, qci, policyRuleName chargeVolumeIPBytes, http-url-len http-uri http-referer http-ua http-ua-len http-request-method http-content-type httpReplyCode http-contentlen

  • For the Comprehensive template only (in Residential AA scale mode): sessionStartMilliseconds, sessionEndMilliseconds, flow-end-reason, aaSystemName

String length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

direct-export
Synopsis Enter the direct-export context
Contextconfigure application-assurance group number cflowd direct-export
Treedirect-export
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

collector [collector-id] number
Synopsis Enter the collector list instance
Contextconfigure application-assurance group number cflowd direct-export collector number
Treecollector
Max. instances16
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

address [ip-address] (ipv4-address-no-zone | ipv6-address-no-zone) port number
Synopsis Enter the address list instance
Contextconfigure application-assurance group number cflowd direct-export collector number address (ipv4-address-no-zone | ipv6-address-no-zone) port number
Treeaddress

Description

Commands in this context configure the cflowd direct export collector IP address.

In the current release, the system supports IPv4 addresses only for the cflowd direct export collector.

Max. instances2
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the remote cflowd collector host
Contextconfigure application-assurance group number cflowd direct-export collector number address (ipv4-address-no-zone | ipv6-address-no-zone) port number
Treeaddress

Description

This command configures the IP address of the remote cflowd collector host.

In the current release, the system supports IPv4 addresses only for the cflowd collector host.

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

port number
Synopsis Cflowd collector host port number
Context configure application-assurance group number cflowd direct-export collector number address (ipv4-address-no-zone | ipv6-address-no-zone) port number
Treeaddress

Description

This command configures the UDP port number used by the remote cflowd collector host.

Range1 to 65535
MD-CLI default4739

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the direct export collector
Contextconfigure application-assurance group number cflowd direct-export collector number address (ipv4-address-no-zone | ipv6-address-no-zone) port number admin-state keyword
Treeadmin-state

Description

This command sets the administrative state of the cflowd direct export collector.

In the current release, the system supports IPv4 addresses only for the cflowd direct export collector.

Optionsenable, disable
Default disable
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

export-override
Synopsis Enter the export-override context
Contextconfigure application-assurance group number cflowd export-override
Treeexport-override

Description

Commands in this context configure the AA subtype used in the cflowd record export. The cflowd statistics exported to the cflowd collector look identical to AA for the type of system defined by the mode. The following cflowd export fields are affected:

  • The cflowd export observation point (field 138) mode is derived from the export-override category that is selected.

  • The cflowd export AA_Subscriber_Type (field 12) mode is modified as configured, using existing field types.

  • The cflowd interface name is used as the sub-ID field, optionally modified to use the configured mode and prefix commands for global identifiers.

All AA cflowd record types are affected by export override. To change the export override or prefix, cflowd must first be disabled. When this command is set back to the default, the prefix is also set back to its default.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mode keyword
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAA cflowd export override mode
Contextconfigure application-assurance group number cflowd export-override mode keyword
Treemode

Description

This command specifies the type of system emulated for the cflowd export.

Optionsmobile, ifname-obfuscate
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

prefix named-item
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAA group cflowd export override prefix
Contextconfigure application-assurance group number cflowd export-override prefix named-item
Treeprefix

Description

This command specifies the prefix-string associated with the export override. The prefix string specifies up to an 8 character string. If the 8 character prefix is "ABCDEFG_" for a particular node, the cflowd export override would generate IPv4 interface names such as ABCDEFG_255.255.255.255 or IPv6 as ABCDEFG_2001:DB8:EF01:2345::/64. By default, the prefix is left blank.

String length1 to 8
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

obfuscation
Synopsis Enter the obfuscation context
Context configure application-assurance group number cflowd obfuscation
Treeobfuscation
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

system-name named-item
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisNode name to report in cflowd template
Contextconfigure application-assurance group number cflowd system-name named-item
Treesystem-name

Description

This command configures the system name of the cflowd AA group. This is exported to the comprehensive cflowd template as aaSystemName.

String length1 to 32
Introduced24.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

tcp-performance
Synopsis Enter the tcp-performance context
Contextconfigure application-assurance group number cflowd tcp-performance
Treetcp-performance

Description

Commands in this context configure TCP performance parameters for the group cflowd export.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

template
Synopsis Enter the template context
Context configure application-assurance group number cflowd tcp-performance template
Treetemplate

Description

Commands in this context configure the template for cflowd TCP performance fields.  

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dynamic-fields
Synopsis Enter the dynamic-fields context
Contextconfigure application-assurance group number cflowd tcp-performance template dynamic-fields
Treedynamic-fields

Description

Commands in this context configure the fields to be included in the exported cflowd template.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

field [field-name] named-item
Synopsis Add a list entry for field
Context configure application-assurance group number cflowd tcp-performance template dynamic-fields field named-item
Treefield

Description

This command adds a list entry for fields to include in the exported cflowd template.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[field-name] named-item
Synopsis Cflowd template dynamic field name
Context configure application-assurance group number cflowd tcp-performance template dynamic-fields field named-item
Treefield

Description

This command specifies the name of the field to be included in the exported cflowd template.

  • Common to all templates are the following values: session/flowStartSeconds, session/flowDurationMilliseconds, postIpPrecedence, ipTTL, aaProt, aaApp, aaAppGrp, hostName, deviceId, deviceMfgId, deviceOsId, ipFamily, deviceOsVer1, deviceOsVer2, deviceOsVer3, anlType, anlTopology, anlCongestionState, timeZone, aaChargingGrp, flowAttr_video, flowAttr_abr_service, flowAttr_audio, flowAttr_encrypted, flowAttr_download, flowAttr_upload, flowAttr_realtime_communication, aaSubTetheringState

  • When AA is deployed in FWA SR, the following value applies: ApnExtended

  • For the TCP and comprehensive templates only, the following values apply: tcpSessionEstDelay, tcpRetransmittedBytes, tcpRetransmittedPackets

  • For the comprehensive templates only when deployed on VSR or ESA in FWA SR configured in the residential mode, the following values apply: dnsAnswerName, dnsType, dnsState, dnsTid, tlsCname, sliceId, mmeAmfAddr, flowActiveBytes, flowActiveTime, qci, policyRuleName chargeVolumeIPBytes, http-url-len http-uri http-referer http-ua http-ua-len http-request-method http-content-type httpReplyCode http-contentlen

  • For the Comprehensive template only (in Residential AA scale mode): sessionStartMilliseconds, sessionEndMilliseconds, flow-end-reason, aaSystemName

String length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

volume
Synopsis Enter the volume context
Context configure application-assurance group number cflowd volume
Treevolume

Description

Commands in this context configure the cflowd volume export.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

template
Synopsis Enter the template context
Context configure application-assurance group number cflowd volume template
Treetemplate

Description

Commands in this context configure the template for cflowd volume fields.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dynamic-fields
Synopsis Enter the dynamic-fields context
Contextconfigure application-assurance group number cflowd volume template dynamic-fields
Treedynamic-fields

Description

Commands in this context configure the fields to be included in the exported cflowd template.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

field [field-name] named-item
Synopsis Add a list entry for field
Context configure application-assurance group number cflowd volume template dynamic-fields field named-item
Treefield

Description

This command adds a list entry for the fields to be included in the exported cflowd template.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[field-name] named-item
Synopsis Cflowd template dynamic field name
Context configure application-assurance group number cflowd volume template dynamic-fields field named-item
Treefield

Description

This command specifies the name of the field to be included in the exported cflowd template.

  • Common to all templates are the following values: session/flowStartSeconds, session/flowDurationMilliseconds, postIpPrecedence, ipTTL, aaProt, aaApp, aaAppGrp, hostName, deviceId, deviceMfgId, deviceOsId, ipFamily, deviceOsVer1, deviceOsVer2, deviceOsVer3, anlType, anlTopology, anlCongestionState, timeZone, aaChargingGrp, flowAttr_video, flowAttr_abr_service, flowAttr_audio, flowAttr_encrypted, flowAttr_download, flowAttr_upload, flowAttr_realtime_communication, aaSubTetheringState

  • When AA is deployed in FWA SR, the following value applies: ApnExtended

  • For the TCP and comprehensive templates only, the following values apply: tcpSessionEstDelay, tcpRetransmittedBytes, tcpRetransmittedPackets

  • For the comprehensive templates only when deployed on VSR or ESA in FWA SR configured in the residential mode, the following values apply: dnsAnswerName, dnsType, dnsState, dnsTid, tlsCname, sliceId, mmeAmfAddr, flowActiveBytes, flowActiveTime, qci, policyRuleName chargeVolumeIPBytes, http-url-len http-uri http-referer http-ua http-ua-len http-request-method http-content-type httpReplyCode http-contentlen

  • For the Comprehensive template only (in Residential AA scale mode): sessionStartMilliseconds, sessionEndMilliseconds, flow-end-reason, aaSystemName

String length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

field-selection keyword
Synopsis Field selection method
Context configure application-assurance group number cflowd volume template field-selection keyword
Treefield-selection

Description

This command configures the method for selecting the fields to be included in the exported cflowd template.

Optionslegacy, dynamic
Default legacy
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dns-ip-cache [dns-ip-cache-name] named-item
Synopsis Enter the dns-ip-cache list instance
Contextconfigure application-assurance group number dns-ip-cache named-item
Treedns-ip-cache

Description

Commands in this context configure a DNS IP cache that is used to snoop DNS requests generated by subscribers, to populate a cache of IP addresses that match a specified list of domain names. In the context of strengthening URL-content charging, Operators may also specify a list of trusted DNS servers to populate the DNS IP cache.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[dns-ip-cache-name] named-item
Synopsis DNS IP cache name within the AA group
Contextconfigure application-assurance group number dns-ip-cache named-item
Treedns-ip-cache
String length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the AA DNS IP cache object
Contextconfigure application-assurance group number dns-ip-cache named-item admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dns-match
Synopsis Enter the dns-match context
Context configure application-assurance group number dns-ip-cache named-item dns-match
Treedns-match
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

domain [domain-name] named-item
Synopsis Enter the domain list instance
Contextconfigure application-assurance group number dns-ip-cache named-item dns-match domain named-item
Treedomain

Description

Commands in this context configure a domain expression to populate the DNS IP cache.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[domain-name] named-item
Synopsis DNS IP cache domain name
Context configure application-assurance group number dns-ip-cache named-item dns-match domain named-item
Treedomain
String length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

expression display-string
Synopsis AA DNS domain expression to match
Context configure application-assurance group number dns-ip-cache named-item dns-match domain named-item expression display-string
Treeexpression

Description

This command specifies a domain name expression string used to define a pattern match. The domain expression uses the same syntax as the expressions used in configure application-assurance group partition policy app-filter entry app-filters configuration.

String length1 to 255
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

trusted-server-address [dns-server-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Enter the trusted-server-address list instance
Contextconfigure application-assurance group number dns-ip-cache named-item dns-match trusted-server-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treetrusted-server-address

Description

Commands in this context configure a trusted DNS server address. DNS responses from this DNS server are used to populate the DNS IP cache.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-cache
Synopsis Enter the ip-cache context
Context configure application-assurance group number dns-ip-cache named-item ip-cache
Treeip-cache
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

high-watermark number
Synopsis High watermark value for the DNS IP cache
Contextconfigure application-assurance group number dns-ip-cache named-item ip-cache high-watermark number
Treehigh-watermark

Description

This command configures the high watermark value for the DNS IP cache. When the number of cached IP addresses exceeds the threshold, the system generates a trap.

Range0 to 100
Default90
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

low-watermark number
Synopsis Low watermark value for the DNS IP cache
Contextconfigure application-assurance group number dns-ip-cache named-item ip-cache low-watermark number
Treelow-watermark

Description

This command configures the low watermark value for the DNS IP cache. When the number of cached IP addresses exceeds the high watermark threshold, the system generates a trap based on the high watermark. The trap clears after the number of cached IP addresses drops below the configured low watermark value.

Range0 to 100
Default80
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

size number
Synopsis Maximum number of IP addresses stored in the cache
Contextconfigure application-assurance group number dns-ip-cache named-item ip-cache size number
Treesize
Range10 to 64000
Default10
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

static-address [static-ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Add a list entry for static-address
Contextconfigure application-assurance group number dns-ip-cache named-item ip-cache static-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treestatic-address
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[static-ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Trusted IP address for the DNS IP cache
Contextconfigure application-assurance group number dns-ip-cache named-item ip-cache static-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treestatic-address

Description

This command configures an IP address to be used as a trusted IP address. For packets whose destination IP address matches that of the trusted IP address, a cache hit is assumed.

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

http-enrich [http-enrich-name] named-item
Synopsis Enter the http-enrich list instance
Contextconfigure application-assurance group number http-enrich named-item
Treehttp-enrich

Description

Commands in this context configure the attributes of the HTTP enrichment policy.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[http-enrich-name] named-item
Synopsis HTTP header enrichment policy name
Context configure application-assurance group number http-enrich named-item
Treehttp-enrich
String length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the HTTP enrichment policy
Contextconfigure application-assurance group number http-enrich named-item admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

field [field-name] named-item
Synopsis Enter the field list instance
Context configure application-assurance group number http-enrich named-item field named-item
Treefield
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[field-name] named-item
Synopsis Field name to insert into the HTTP header
Contextconfigure application-assurance group number http-enrich named-item field named-item
Treefield

Description

This command specifies the field type to insert into the HTTTP header. The command must be repeated for each field to be inserted. The same field cannot be inserted twice into the header under different header names.

Note: AA can insert two copies of the following fields in the same HTTP header (with a different header name):

imei-hyphenated, imei-hyphenated-2, imsi, imsi-2, static-string, static-string-2, user-location-raw, and user-location-raw2.

The following field types are supported in any deployment:

static-string - header name for the inserted string

static-string-2 - header name for the inserted string

subscriber-id - header name for the subscriber ID

subscriber-ip - header name for the subscriber IP address

The following field types are supported in Fixed Wireless Access (FWA) deployments only:

apn - complete APN string

apn-ni - APN Network Identifier (APN-NI) used by the UE

billing-type - UE charging type (charging characteristics)

dynamic-acr - dynamic Anonymous Customer Record (ACR)

static-acr - static ACR

imei-hyphenated - subscriber IMEI with format AABBBBBB-CCCCCC-EE

imei-hyphenated-2 - subscriber IMEI with format AABBBBBB-CCCCCC-EE

imei-sv - subscriber IMEI with format AABBBBBBCCCCCCEE

imsi - subscriber IMSI

imsi-2 - subscriber IMSI

msisdn - subscriber MSISDN

msisdn-ts - subscriber MSISDN appended with the UNIX timestamp

msisdn-without-cc - subscriber MSISDN without a country code

pgw-ggsn-address - PGW/GGSN address serving the UE

plmn-id - Public Land Mobile Network (PLMN) ID of the SGSN/MME

rat-type - Radio Access Technology (RAT) type

timestamp - timestamp inserted in UNIX time format; for example, 1531204313

user-location - UE LOCATION (ULI)

user-location-3gpp - ULI encoded as defined in 3GPP 29.061

user-location-raw - ULI in raw format:<ULI-TYPE1>[+<ULI-TYPE2>]=<ULI HEX>

Example: x-locinfo: TAI+ECGI=1300622c46130062014adf16

user-location-raw-2 - ULI in raw format:<ULI-TYPE1>[+<ULI-TYPE2>]=<ULI HEX>

Example: x-locinfo: TAI+ECGI=1300622c46130062014adf16

String length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

aes-initialization-vector hex-string
Synopsis Initialization vector for the AES CBC encryption
Contextconfigure application-assurance group number http-enrich named-item field named-item aes-initialization-vector hex-string
Treeaes-initialization-vector

Description

This command configures the initialization vector used for the AES CBC encryption. The vector consists of 34 characters, that is, 0x followed by exactly 32 hexadecimal characters.

String length34
Introduced22.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

anti-spoof boolean
Synopsis Enable anti-spoofing
Context configure application-assurance group number http-enrich named-item field named-item anti-spoof boolean
Treeanti-spoof

Description

When configured to true, this command enables the HTTP header enrichment anti-spoofing functionality.

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

calling-line-id boolean
Synopsis Enable calling line identification
Context configure application-assurance group number http-enrich named-item field named-item calling-line-id boolean
Treecalling-line-id

Description

When configured to true, this command configures the HTTP header for “x-up-calling-line-id” anti-spoofing.

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

encode
Synopsis Enter the encode context
Context configure application-assurance group number http-enrich named-item field named-item encode
Treeencode

Description

Commands in this context configure the encoding applied to the HTTP header enrichment field.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

key
Synopsis Enter the key context
Context configure application-assurance group number http-enrich named-item field named-item encode key
Treekey

Description

Commands in this context configure the encryption fields.

Notes

The following elements are part of a choice: cert-base64, cert-profile, or key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

type keyword
Synopsis Encoding type
Contextconfigure application-assurance group number http-enrich named-item field named-item encode key type keyword
Treetype

Description

This command configures the encoding/ encryption method.

Optionsmd5, rc4, rc4-md5-base64, aes128, aes256, aes128cbc, aes256cbc
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

md5-salt string-not-all-spaces
Synopsis MD5 salt string
Context configure application-assurance group number http-enrich named-item field named-item md5-salt string-not-all-spaces
Treemd5-salt

Description

This command configures an MD5 salt string. The configured string is appended to the parameter before performing MD5 hashing of the field.

String length1 to 16
Introduced22.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

name named-item
Warning:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisHTTP header field name
Contextconfigure application-assurance group number http-enrich named-item field named-item name named-item
Treename
String length1 to 32
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

rat-type-enrichment
Synopsis Enter the rat-type-enrichment context
Contextconfigure application-assurance group number http-enrich named-item rat-type-enrichment
Treerat-type-enrichment

Description

Commands in this context configure Radio Access Type (RAT) enrichment.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

rat-type [rat-type-name] keyword
Synopsis Enter the rat-type list instance
Contextconfigure application-assurance group number http-enrich named-item rat-type-enrichment rat-type keyword
Treerat-type
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[rat-type-name] keyword
Synopsis RAT type name
Contextconfigure application-assurance group number http-enrich named-item rat-type-enrichment rat-type keyword
Treerat-type

Description

This command configures a customised RAT value for the specified RAT-Type.

Optionsutran, geran, wlan, gan, hspa-evol, eutran, virtual, eutran-nb, ehrpd, hrpd, cdma-1x, umb, wifi, nr, lte-m

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

http-error-redirect [http-error-redirect-name] named-item
Synopsis Enter the http-error-redirect list instance
Contextconfigure application-assurance group number http-error-redirect named-item
Treehttp-error-redirect

Description

Commands in this context configure an HTTP error redirect policy that contains important information relevant to the redirect server.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[http-error-redirect-name] named-item
Synopsis HTTP error redirect policy name
Context configure application-assurance group number http-error-redirect named-item
Treehttp-error-redirect
String length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

error-code [error-code-value] number
Synopsis Enter the error-code list instance
Contextconfigure application-assurance group number http-error-redirect named-item error-code number
Treeerror-code

Description

Commands in this context configure the HTTP error status codes to which a redirect action is applied. Only messages with sizes less than that configured for the custom-message-size command are eligible for redirect action.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[error-code-value] number
Synopsis HTTP error code value for an HTTP error redirect
Contextconfigure application-assurance group number http-error-redirect named-item error-code number
Treeerror-code
Range400 to 999

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

custom-message-size number
Synopsis HTTP error redirect error code custom message size
Contextconfigure application-assurance group number http-error-redirect named-item error-code number custom-message-size number
Treecustom-message-size

Description

This command specifies the maximum message size above which an HTTP error redirect is not performed.

Max. range0 to 4294967295
Unitsoctets
Default1024
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

http-host display-string
Synopsis HTTP host for the HTTP error redirect object
Contextconfigure application-assurance group number http-error-redirect named-item http-host display-string
Treehttp-host

Description

This command specifies the HTTP hostname of the landing server (Barefruit or Xerocole). It is used in the HTTP GET operation from the client (which is being redirected) to the redirect search landing server. The hostname must contain a valid IP address or HTTP hostname or URI for the HTTP GET from the client to the landing server.

String length1 to 255
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

participant-id named-item
Synopsis Participant ID for the HTTP error redirect object
Contextconfigure application-assurance group number http-error-redirect named-item participant-id named-item
Treeparticipant-id

Description

This command specifies a string assigned to the operator by Barefruit. It is used by Barefruit landing servers (applies to template # 1 only).

String length1 to 32
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

template number
Synopsis Template ID for the HTTP error redirect object
Contextconfigure application-assurance group number http-error-redirect named-item template number
Treetemplate

Description

This command configures the template of parameters passed from the AA-ISA to the redirect server using JavaScript in the redirect packet. The template is specific to the redirect server used in the network. Currently, two partners are supported with AA-ISA redirect solution, Barefruit, and Xerocole.

Max. range0 to 4294967295
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

http-notification [http-notification-name] named-item
Synopsis Enter the http-notification list instance
Contextconfigure application-assurance group number http-notification named-item
Treehttp-notification

Description

Commands in this context configure an HTTP notification object for the subscriber in-browser notification.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[http-notification-name] named-item
Synopsis HTTP notification policy name
Context configure application-assurance group number http-notification named-item
Treehttp-notification
String length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

interval (number | keyword)
Synopsis Minimum HTTP response notification interval
Contextconfigure application-assurance group number http-notification named-item interval (number | keyword)
Treeinterval
Range1 to 1440
Unitsminutes
Options one-time
Defaultone-time
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

script-url http-redirect-url
Synopsis Script URL inserted into the HTTP response
Contextconfigure application-assurance group number http-notification named-item script-url http-redirect-url
Treescript-url

Description

This command configures the URL of the script used by the HTTP notification policy.

String length1 to 255
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

template number
Synopsis Template ID for the AA HTTP notification object
Contextconfigure application-assurance group number http-notification named-item template number
Treetemplate

Description

This command configures the template that defines the format and attributes included in the HTTP notification message.

Max. range0 to 4294967295
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

http-redirect [http-redirect-name] named-item
Synopsis Enter the http-redirect list instance
Contextconfigure application-assurance group number http-redirect named-item
Treehttp-redirect

Description

Commands in this context configure the parameters of the HTTP redirect policy.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[http-redirect-name] named-item
Synopsis HTTP redirect policy name
Context configure application-assurance group number http-redirect named-item
Treehttp-redirect

Description

This command specifies the applied HTTP redirect name. If no redirect name is specified, HTTP redirect is not enabled.

String length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

captive-redirect
Synopsis Enter the captive-redirect context
Contextconfigure application-assurance group number http-redirect named-item captive-redirect
Treecaptive-redirect

Description

Commands in this context configure the captive redirect capability for an HTTP redirect policy. HTTP redirect policies using captive redirect can be used in conjunction with a session-filter policy to terminate TCP flows in the ISA-AA card before reaching the Internet to redirect subscribers to the predefined redirect URL. 

Non-HTTP TCP flows are TCP reset. Captive redirect uses the provisioned VLAN ID to send the HTTP response to subscribers; therefore, this VLAN ID must be properly assigned in the same VPN as the subscriber. 

The operator can select the URL arguments to include in the redirect URL using either a specific template ID or by configuring the redirect URL using a supported macro substitution keyword.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

vlan-id number
Synopsis Captive redirect VLAN ID
Context configure application-assurance group number http-redirect named-item captive-redirect vlan-id number
Treevlan-id

Description

This command configures the VLAN ID for a captive redirect. Captive redirect uses the provisioned VLAN ID to send the HTTP response to subscribers; therefore, this VLAN ID must be properly assigned in the same VPN as the subscriber.

Range1 to 4094
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

redirect-https boolean
Synopsis Enable HTTPS redirect
Context configure application-assurance group number http-redirect named-item redirect-https boolean
Treeredirect-https

Description

When set to true, the HTTP redirect policy redirects HTTPS sessions to the configured redirect URL.

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

redirect-url http-redirect-url
Synopsis HTTP redirect URL
Context configure application-assurance group number http-redirect named-item redirect-url http-redirect-url
Treeredirect-url

Description

This command configures the HTTP redirect URL which is the URL (page) that the user is redirected to when an HTTP redirect takes effect.

The operator can select the URL arguments to include in the redirect URL, using either a specific template ID or by configuring any of the following macro substitution keywords:

  • $URL - The Request-URI in the HTTP GET Request received

  • $SUB - The subscriber ID

  • $IP - The IP address of the subscriber host

  • $RTRID - The router ID

  • $URLPRM - The HTTP URL parameter associated with the subscriber

  • $MAC - The UE MAC address

  • $SAP - The UE SAP

  • $CID - The circuit ID or interface ID of the subscriber

  • $RID - The remote ID of the subscriber

  • $CATID - The URL filter web-service rating category identifier

  • $CATNAME - The URL filter web-service rating category name

Only ESM and ESM-MAC sub types support $MAC, $SAP, $CID, and $RID macro substitution.

String length1 to 255
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

tcp-client-reset boolean
Synopsis Enable TCP client reset
Context configure application-assurance group number http-redirect named-item tcp-client-reset boolean
Treetcp-client-reset

Description

When configured to true, this command enables an HTTP-redirect policy to initiate a TCP reset towards the client if the AA policy results in a redirect with packet drop but the HTTP redirect cannot be delivered.  Scenarios for this include HTTP (TLS) sessions, blocking of non-HTTP TCP traffic, and blocking of existing flows after a policy re-evaluation of an existing subscriber.

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

template number
Synopsis Template ID for the HTTP redirect object
Contextconfigure application-assurance group number http-redirect named-item template number
Treetemplate

Description

This command configures the template that defines which parameters are appended to the HTTP host redirect field in the redirect message. The HTTP redirect template provides HTTP 302 redirect containing only the URL specified in the redirect policy, with no other parameters.

Max. range0 to 4294967295
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-identification-assist
Synopsis Enter the ip-identification-assist context
Contextconfigure application-assurance group number ip-identification-assist
Treeip-identification-assist

Description

Commands in this context configure the IP identification assist feature, which uses IP addresses to assist in traffic identification.

This optional mechanism is enabled by default and consults an internally generated and stored database when app-filters fail to classify the traffic as one of the configured applications from the AppDB.

Use the configure application-assurance group ip-identification-assist admin-state command to disable the administrative state of the IP identification assist feature.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

passive-dns
Synopsis Enter the passive-dns context
Context configure application-assurance group number ip-identification-assist passive-dns
Treepassive-dns

Description

Commands in this context configure passive DNS monitoring for the IP identification assist feature.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

monitor boolean
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisUse passive DNS monitoring to collect IP addresses
Contextconfigure application-assurance group number ip-identification-assist passive-dns monitor boolean
Treemonitor

Description

When configured to true, the router collects IP addresses by passively monitoring DNS traffic. The router uses the collected IP addresses to build its internal database.

Defaulttrue
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

trusted-server [ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Enter the trusted-server list instance
Contextconfigure application-assurance group number ip-identification-assist passive-dns trusted-server (ipv4-address-no-zone | ipv6-address-no-zone)
Treetrusted-server

Description

Commands in this context configure a DNS server that the IP identification assist feature is allowed to passively monitor.

Max. instances64
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

positive-app-id
Synopsis Enter the positive-app-id context
Contextconfigure application-assurance group number ip-identification-assist positive-app-id
Treepositive-app-id

Description

Commands in this context implement the positive application identification mechanism, which monitors the correlations between IP addresses and applications identified with a high degree of confidence independently of any IP identification assist mechanism.

Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

enabled boolean
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisUse the positive application identification mechanism
Contextconfigure application-assurance group number ip-identification-assist positive-app-id enabled boolean
Treeenabled

Description

When configured to true, the router uses the positive application identification mechanism. This mechanism causes the router to add the IP addresses of the global applications learned through AA analysis into the IP identification assist cache. The router uses the harvested IP addresses to build its internal application-IP database.

When configured to false, only DNS is used to harvest IP addresses.

Defaulttrue
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

partition [aa-partition-id] number
Synopsis Enter the partition list instance
Contextconfigure application-assurance group number partition number
Treepartition

Description

Commands in this context configure the AA partition-related policies.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[aa-partition-id] number
Synopsis Partition ID within the AA group
Context configure application-assurance group number partition number
Treepartition
Range0 to 65535

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

aa-sub-congestion-detection
Synopsis Enter the aa-sub-congestion-detection context
Contextconfigure application-assurance group number partition number aa-sub-congestion-detection
Treeaa-sub-congestion-detection

Description

Commands in this context configure congestion detection parameters related to Non-location Based Dynamic Experience Management (NLB-DEM).

Note: NLB-DEM cannot be enabled if Access-Network Location (ANL) DEM mode is enabled; the two are mutually exclusive.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

rat-type [rat-type-name] keyword
Synopsis Enter the rat-type list instance
Contextconfigure application-assurance group number partition number aa-sub-congestion-detection rat-type keyword
Treerat-type

Description

Commands in this context configure the RAT types for which unique RTT thresholds are configured.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[rat-type-name] keyword
Synopsis Mobile radio access technology (RAT) type
Contextconfigure application-assurance group number partition number aa-sub-congestion-detection rat-type keyword
Treerat-type
Optionsutran, geran, wlan, gan, hspa-evol, eutran, virtual, eutran-nb, ehrpd, hrpd, cdma-1x, umb, wifi, nr, lte-m

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

rtt-threshold (number | keyword)
Synopsis Round trip time congestion threshold for a RAT type
Contextconfigure application-assurance group number partition number aa-sub-congestion-detection rat-type keyword rtt-threshold (number | keyword)
Treertt-threshold

Description

This command configures the maximum acceptable round trip time (RTT) under no congestion. Any measured RTT above the threshold is considered an indication of possible congestion.

Range1 to 500
Unitsmilliseconds
Options not-applicable

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

rtt-threshold (number | keyword)
Synopsis Round trip time congestion threshold
Context configure application-assurance group number partition number aa-sub-congestion-detection rtt-threshold (number | keyword)
Treertt-threshold

Description

This command configures the default round trip delay threshold used by the DEM gateway algorithm to determine subscriber congestion for NLB-DEM. This default value is used when the current RAT-Type is not known, or has no associated configured RTT threshold.

Range1 to 500
Unitsmilliseconds
Options not-applicable
Default173
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

rtt-threshold-tolerance number
Synopsis RTT threshold tolerance for congestion detection
Contextconfigure application-assurance group number partition number aa-sub-congestion-detection rtt-threshold-tolerance number
Treertt-threshold-tolerance

Description

This command configures the round trip delay threshold tolerance used by the DEM gateway algorithm to determine subscriber-level congestion.

Range0 to 100
Unitspercent
Default 50
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

aa-sub-remote boolean
Synopsis Reverse subscriber traffic direction
Context configure application-assurance group number partition number aa-sub-remote boolean
Treeaa-sub-remote

Description

When configured to true, the direction of the from-subscriber and to-subscriber traffic is reversed for this group partition.

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

access-network-location
Synopsis Enter the access-network-location context
Contextconfigure application-assurance group number partition number access-network-location
Treeaccess-network-location

Description

Commands in this context configure parameters related to dynamic experience management, also known as Access Network Location (ANL).

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

source [source-type] keyword
Synopsis Enter the source list instance
Contextconfigure application-assurance group number partition number access-network-location source keyword
Treesource

Description

Commands in this context configure location sources for dynamic experience management.

Max. instances1
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[source-type] keyword
Synopsis Access network location source
Context configure application-assurance group number partition number access-network-location source keyword
Treesource

Description

This command specifies the location or access technology. AA supports access points for WLGW access points or ULI-2gpp for mobile (for example, FWA).

Optionsmobile-3g, access-point, uli-3gpp

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

rat-type [rat-type-name] keyword
Synopsis Enter the rat-type list instance
Contextconfigure application-assurance group number partition number access-network-location source keyword rat-type keyword
Treerat-type

Description

Commands in this context configure the RAT types for which unique RTT thresholds are configured.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[rat-type-name] keyword
Synopsis Access network location RAT type
Context configure application-assurance group number partition number access-network-location source keyword rat-type keyword
Treerat-type
Optionsutran, geran, wlan, gan, hspa-evol, eutran, virtual, eutran-nb, ehrpd, hrpd, cdma-1x, umb, wifi, nr, lte-m

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

rtt-threshold (number | keyword)
Synopsis RTT congestion threshold for a RAT type
Contextconfigure application-assurance group number partition number access-network-location source keyword rat-type keyword rtt-threshold (number | keyword)
Treertt-threshold

Description

This command specifies the maximum acceptable round trip time (RTT) under no congestion. Any measured RTT above the threshold is considered an indication of possible congestion.

Range1 to 500
Unitsmilliseconds
Options not-applicable

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

rtt-threshold (number | keyword)
Synopsis Source round trip time congestion threshold
Contextconfigure application-assurance group number partition number access-network-location source keyword rtt-threshold (number | keyword)
Treertt-threshold

Description

This command configures the default round trip delay threshold used by the DEM gateway algorithm to determine ANL congestion. This default value is used when either the ANL RAT-Type is not known or has no associated configured RTT threshold. 

Range1 to 500
Unitsmilliseconds
Options not-applicable
Default173
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

rtt-threshold-tolerance number
Synopsis Source round trip time congestion threshold tolerance
Contextconfigure application-assurance group number partition number access-network-location source keyword rtt-threshold-tolerance number
Treertt-threshold-tolerance

Description

This command configures the ANL round trip delay threshold tolerance used by the DEM gateway algorithm to determine ANL-level congestion.

Range0 to 100
Unitspercent
Default 50
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

source-level keyword
Warning:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisAccess network location source level
Contextconfigure application-assurance group number partition number access-network-location source keyword source-level keyword
Treesource-level
Optionscell, transport-network-link, mac-vlan
Defaultcell
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

aqp-initial-lookup boolean
Synopsis Enable AQP initial lookup
Context configure application-assurance group number partition number aqp-initial-lookup boolean
Treeaqp-initial-lookup

Description

When configured to true, this command allows AA to perform application QoS policy (AQP) lookups on flows prior to complete application identification. As usual, AQP will be looked up again when identification is complete. Without this, AA executes AQPs that are part of the sub-default policy. The sub-default policy is formed by regular AQPs that contain ASOs, subID, or flow direction as matching conditions.

This behavior is required, for example, to apply GTP and SCTP filtering on the first packet of a new GTP/SCTP flow (AQP matching conditions).

When configured to false, AA only performs AQP lookups when identification is complete.

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

cflowd
Synopsis Enter the cflowd context
Context configure application-assurance group number partition number cflowd
Treecflowd

Description

Commands in this context configure the AA partition-based cflowd fields.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

export-type [flow-export-type] keyword
Synopsis Enter the export-type list instance
Contextconfigure application-assurance group number partition number cflowd export-type keyword
Treeexport-type

Description

Commands in this context configure the scope of traffic subjected to AA cflowd export.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[flow-export-type] keyword
Synopsis Cflowd flow export type for the partition
Contextconfigure application-assurance group number partition number cflowd export-type keyword
Treeexport-type

Description

This command allows the operator to configure the scope of traffic that can be sampled for cflowd export for the configured cflowd template.

Optionsvolume, tcp-performance, comprehensive

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

app-group [app-group-name] reference
Synopsis Enter the app-group list instance
Contextconfigure application-assurance group number partition number cflowd export-type keyword app-group reference
Treeapp-group

Description

Commands in this context configure application groups for flow sampling and cflowd export.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

application [application-name] reference
Synopsis Enter the application list instance
Contextconfigure application-assurance group number partition number cflowd export-type keyword application reference
Treeapplication

Description

Commands in this context configure applications for flow sampling and cflowd export.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

event-log [event-log-name] named-item
Synopsis Enter the event-log list instance
Contextconfigure application-assurance group number partition number event-log named-item
Treeevent-log

Description

Commands in this context configure an event log.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[event-log-name] named-item
Synopsis Partition event log name
Context configure application-assurance group number partition number event-log named-item
Treeevent-log
String length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

buffer-type keyword
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEvent log buffer type
Contextconfigure application-assurance group number partition number event-log named-item buffer-type keyword
Treebuffer-type
Optionslinear, circular, syslog
Defaultlinear
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

max-entries number
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMaximum number of entries for the event log
Contextconfigure application-assurance group number partition number event-log named-item max-entries number
Treemax-entries
Range1 to 100000
Default500
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

syslog
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the syslog context
Contextconfigure application-assurance group number partition number event-log named-item syslog
Treesyslog

Description

Commands in this context configure the syslog options for the partition.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

address (ipv4-address-no-zone | ipv6-address-no-zone)
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSyslog host IP address
Contextconfigure application-assurance group number partition number event-log named-item syslog address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeaddress
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

facility keyword
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAA syslog facility
Contextconfigure application-assurance group number partition number event-log named-item syslog facility keyword
Treefacility

Description

This command configures the syslog facility. The syslog facility is an information field associated with a syslog message. It is defined by the syslog protocol and provides an indication of which part of the system originated the message.

Optionskernel, user, mail, systemd, auth, syslogd, printer, netnews, uucp, cron, authpriv, ftp, ntp, logaudit, logalert, cron2, local0, local1, local2, local3, local4, local5, local6, local7
Default local7
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

port number
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisUDP port for syslog events
Contextconfigure application-assurance group number partition number event-log named-item syslog port number
Treeport
Max. range0 to 65535
Default514
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

severity keyword
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSyslog message severity level threshold
Contextconfigure application-assurance group number partition number event-log named-item syslog severity keyword
Treeseverity
Optionsemergency, alert, critical, error, warning, notice, info, debug
Default info
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

vlan-id number
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisISA service port VLAN ID for sending syslog traffic
Contextconfigure application-assurance group number partition number event-log named-item syslog vlan-id number
Treevlan-id

Description

This command configures the service port VLAN ID to be used by application assurance to provide syslog events. This VLAN ID also needs to be configured for the application assurance interface.

Range1 to 4094
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

gtp
Synopsis Enter the gtp context
Context configure application-assurance group number partition number gtp
Treegtp

Description

Commands in this context configure GTP parameters.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

gtp-filter [gtp-filter-name] named-item
Synopsis Enter the gtp-filter list instance
Contextconfigure application-assurance group number partition number gtp gtp-filter named-item
Treegtp-filter

Description

Commands in this context allow AA to treat traffic on UDP port number 2152 as GTP-U. Without further specifying any other parameters within this GTP context, AA performs basic GTP-U header sanity checks and discards packets that are malformed. This GTP context also allows the operator to configure various GTP filters.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[gtp-filter-name] named-item
Synopsis GTP filter name
Context configure application-assurance group number partition number gtp gtp-filter named-item
Treegtp-filter
String length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

gtp-tunnel-database
Synopsis Enter the gtp-tunnel-database context
Contextconfigure application-assurance group number partition number gtp gtp-filter named-item gtp-tunnel-database
Treegtp-tunnel-database

Description

Commands in this context configure GTP advanced firewall functions, such as validating GTP tunnels, sequence numbers, and source IP addresses).

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

default-tunnel-endpoint-limit number
Synopsis Default GTP tunnel endpoint limit
Context configure application-assurance group number partition number gtp gtp-filter named-item gtp-tunnel-database default-tunnel-endpoint-limit number
Treedefault-tunnel-endpoint-limit

Description

This command configures the maximum number of GTP endpoints requested in GTP-C messages by using, for example, the PDP Context Create message type. 

The validate-gtp-tunnels command must be enabled before using this command.

Range1 to 4294967295
Default4294967295
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

validate-gtp-tunnels boolean
Synopsis Enable GTP tunnel validation
Context configure application-assurance group number partition number gtp gtp-filter named-item gtp-tunnel-database validate-gtp-tunnels boolean
Treevalidate-gtp-tunnels

Description

When configured to true, this command configures GTP tunnel validation. This allows for the validation of TEIDs and is a prerequisite for sequence checking and UE IP address validation. This command is only applicable when AA GTP FW is deployed on S8/S5/Gp/Gn interfaces. The gtpc-inspection command in the configure application-assurance group partition gtp context must be configured to true before using this command.

When configured to false, the GTP tunnels cannot be validated.

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

validate-sequence-number boolean
Synopsis Enable GTP sequence number checking
Context configure application-assurance group number partition number gtp gtp-filter named-item gtp-tunnel-database validate-sequence-number boolean
Treevalidate-sequence-number

Description

When configured to true, this command enables GTP sequence number checking. GTP packets that fail the sequence number check are discarded.

The validate-gtp-tunnels command in the configure application-assurance group partition gtp gtp-filter gtp-tunnel-database context must be configured to true before using this command.

When configured to false, the GTP packet sequence number cannot be checked.

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

validate-source-ip-addr boolean
Synopsis Validate source IP address in GTP frames
Contextconfigure application-assurance group number partition number gtp gtp-filter named-item gtp-tunnel-database validate-source-ip-addr boolean
Treevalidate-source-ip-addr

Description

When configured to true, this command enables checking for spoofed or invalid UE IP addresses. Upstream GTP packets that contain invalid UE IP addresses are discarded. When a packet is dropped due to source-ip-address “invalid source IP add”, the statistics counter is updated.

The validate-gtp-tunnels command in the configure application-assurance group partition gtp gtp-filter gtp-tunnel-database context must be configured to true before using this command.

When configured to false, the spoofed or invalid UE IP addresses cannot be checked.

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

imsi-apn-filter
Synopsis Enter the imsi-apn-filter context
Contextconfigure application-assurance group number partition number gtp gtp-filter named-item imsi-apn-filter
Treeimsi-apn-filter

Description

Commands in this context configure IMSI and APN filtering.

The gtpc-inspection command in the configure application-assurance group partition gtp context must be configured to true before using this command. 

This command is only applicable to the GTP packets that contain IMSI or APN information elements (IEs).

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure application-assurance group number partition number gtp gtp-filter named-item imsi-apn-filter entry number
Treeentry

Description

Commands in this context configure an entry within the IMSI-APN filter to allow for IMSI-APN match and action configuration.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[entry-id] number
Synopsis AA IMSI-APN filter entry ID
Context configure application-assurance group number partition number gtp gtp-filter named-item imsi-apn-filter entry number
Treeentry

Description

This command specifies the index in the IMSI-APN list that defines a custom filtering action.

Range1031 to 2030

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

apn display-string
Synopsis APN as GTP filter match criterion
Context configure application-assurance group number partition number gtp gtp-filter named-item imsi-apn-filter entry number apn display-string
Treeapn

Description

This command configures a matching condition for an APN configured as a GTP filter. If no APN is specified, the entry is not checked for the APN IE in GTP-C packets. The values for this command are:

  •  string:The extracted APN must match string exactly.

  • ^string: The extracted APN must start with string.

  • string$: The extracted APN must end with string.

  • WILDCARD_APN: Special string that indicates that the extracted APN must be “*” (that is, a length octet with value one, followed by the ASCII code for the asterisk)

  • EMPTY_APN: Special string that indicates that the extracted APN must be empty (that is, “”)

  • ANY_APN: Special string that indicates that the extracted APN IE must be present and can have any value in order for the filter entry to match

String length1 to 100
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

imsi-mcc-mnc-prefix display-string
Synopsis IMSI (MCC-MNC) prefix as GTP filter match criterion
Contextconfigure application-assurance group number partition number gtp gtp-filter named-item imsi-apn-filter entry number imsi-mcc-mnc-prefix display-string
Treeimsi-mcc-mnc-prefix

Description

This command configures a matching condition for the IMSI (MCC-MNC) prefix. This string represents the IMSI prefix to be matched against the IMSI IE of the packet, or the special value ANY_IMSI to indicate that an IMSI IE must be present as a matching condition regardless of the IMSI IE value. If no MCC-MNC prefix is specified, the entry will match GTP packets that have an IMSI IE containing any value.

String length1 to 8
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

src-gsn
Synopsis Enter the src-gsn context
Context configure application-assurance group number partition number gtp gtp-filter named-item imsi-apn-filter entry number src-gsn
Treesrc-gsn

Description

Commands in this context configure a matching condition for the GSN IP address. The IP address value is checked only against the source IP address of the GTP packets that contain an APN IE or an IMSI IE.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-prefix (ipv4-prefix | ipv6-prefix)
Synopsis Source GSN IP address prefix as filter match criterion
Contextconfigure application-assurance group number partition number gtp gtp-filter named-item imsi-apn-filter entry number src-gsn ip-prefix (ipv4-prefix | ipv6-prefix)
Treeip-prefix

Description

This command specifies a valid unicast address associated with the IMSI-APN filter entry.

Notes

The following elements are part of a choice: ip-prefix or ip-prefix-list.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-prefix-list reference
Synopsis Source GSN IP address prefix list as match criterion
Contextconfigure application-assurance group number partition number gtp gtp-filter named-item imsi-apn-filter entry number src-gsn ip-prefix-list reference
Treeip-prefix-list

Reference

configure application-assurance group number partition number ip-prefix-list named-item

Notes

The following elements are part of a choice: ip-prefix or ip-prefix-list.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

log
Synopsis Enter the log context
Context configure application-assurance group number partition number gtp gtp-filter named-item log
Treelog

Description

Commands in this context configure the AA group partition GTP filter log.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

message-type
Synopsis Enter the message-type context
Contextconfigure application-assurance group number partition number gtp gtp-filter named-item message-type
Treemessage-type

Description

Commands in this context configure the GTP message-type filtering. If no message type is specified within a filter, all GTP message types are allowed.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure application-assurance group number partition number gtp gtp-filter named-item message-type entry number
Treeentry

Description

Commands in this context configure an entry for a specific GTPv1 message type value.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[entry-id] number
Synopsis GTP filter entry ID
Context configure application-assurance group number partition number gtp gtp-filter named-item message-type entry number
Treeentry

Description

This command specifies the index in the GTPv1 message value list that defines a custom message-type action.

Range1 to 255

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

value (number | keyword)
Warning:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisGTPv1 filter message type value
Contextconfigure application-assurance group number partition number gtp gtp-filter named-item message-type entry number value (number | keyword)
Treevalue
Range1 to 255
Optionsecho-request, echo-response, version-not-supported, node-alive-request, node-alive-response, redirection-request, redirection-response, create-pdp-context-request, create-pdp-context-response, update-pdp-context-request, update-pdp-context-response, delete-pdp-context-request, delete-pdp-context-response, initiate-pdp-context-activation-request, initiate-pdp-context-activation-response, error-indication, pdu-notification-request, pdu-notification-response, pdu-notification-reject-request, pdu-notification-reject-response, supported-extension-headers-notification, send-routing-information-for-gprs-request, send-routing-information-for-gprs-response, failure-report-request, failure-report-response, note-ms-gprs-present-request, note-ms-gprs-present-response, identification-request, identification-response, sgsn-context-request, sgsn-context-response, sgsn-context-acknowledge, forward-relocation-request, forward-relocation-response, forward-relocation-complete, relocation-cancel-request, relocation-cancel-response, forward-srns-context, forward-relocation-complete-acknowledge, forward-srns-context-acknowledge, ran-information-relay, mbms-notification-request, mbms-notification-response, mbms-notification-reject-request, mbms-notification-reject-response, create-mbms-context-request, create-mbms-context-response, update-mbms-context-request, update-mbms-context-response, delete-mbms-context-request, delete-mbms-context-response, mbms-registration-request, mbms-registration-response, mbms-de-registration-request, mbms-de-registration-response, mbms-session-start-request, mbms-session-start-response, mbms-session-stop-request, mbms-session-stop-response, mbms-session-update-request, mbms-session-update-response, ms-info-change-notification-request, ms-info-change-notification-response, data-record-transfer-request, data-record-transfer-response, tunnel-status, end-marker, g-pdu

Notes

This element is mandatory.

Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

message-type-gtp-v2
Synopsis Enter the message-type-gtp-v2 context
Contextconfigure application-assurance group number partition number gtp gtp-filter named-item message-type-gtp-v2
Treemessage-type-gtp-v2

Description

Commands in this context configure the GTPv2 message-type filtering.

If message-type GTPv2 is not specified within a filter, all GTP message types are allowed, except for the messages that are dropped by GTP-C inspection because they violate the expected GTP protocol for the deployment interface (for example, roaming deployment).

The gtpc-inspection command in the configure application-assurance group partition gtp context must be configured to true before configuring GTPv2 message-type filtering.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure application-assurance group number partition number gtp gtp-filter named-item message-type-gtp-v2 entry number
Treeentry

Description

Commands in this context configure an entry for a specific GTPv2 message type value.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[entry-id] number
Synopsis GTPv2 filter entry ID
Context configure application-assurance group number partition number gtp gtp-filter named-item message-type-gtp-v2 entry number
Treeentry

Description

This command configures the index in the GTP message value list that defines a custom message-type action.

Range516 to 770

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

action keyword
Synopsis GTPv2 filter message entry action
Context configure application-assurance group number partition number gtp gtp-filter named-item message-type-gtp-v2 entry number action keyword
Treeaction

Description

This command specifies the action to take for packets that match this GTPv2 filter message entry.

Optionsdeny, permit

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

value (number | keyword)
Warning:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisGTPv2 filter message type value
Contextconfigure application-assurance group number partition number gtp gtp-filter named-item message-type-gtp-v2 entry number value (number | keyword)
Treevalue
Range1 to 255
Optionsecho-request, echo-response, version-not-supported-indication, create-session-request, create-session-response, modify-bearer-request, modify-bearer-response, delete-session-request, delete-session-response, change-notification-request, change-notification-response, remote-ue-report-notification, remote-ue-report-acknowledge, modify-bearer-command, modify-bearer-failure-indication, delete-bearer-command, delete-bearer-failure-indication, bearer-resource-command, bearer-resource-failure-indication, downlink-data-notification-failure-indication, trace-session-activation, trace-session-deactivation, stop-paging-indication, create-bearer-request, create-bearer-response, update-bearer-request, update-bearer-response, delete-bearer-request, delete-bearer-response, delete-pdn-connection-set-request, delete-pdn-connection-set-response, pgw-downlink-triggering-notification, pgw-downlink-triggering-acknowledge, identification-request, identification-response, context-request, context-response, context-acknowledge, forward-relocation-request, forward-relocation-response, forward-relocation-complete-notification, forward-relocation-complete-acknowledge, forward-access-context-notification, forward-access-context-acknowledge, relocation-cancel-request, relocation-cancel-response, configuration-transfer-tunnel, detach-notification, detach-acknowledge, cs-paging-indication, ran-information-relay, alert-mme-notification, alert-mme-acknowledge, ue-activity-notification, ue-activity-acknowledge, isr-status-indication, create-forwarding-tunnel-request, create-forwarding-tunnel-response, suspend-notification, suspend-acknowledge, resume-notification, resume-acknowledge, create-indirect-data-forwarding-tunnel-request, create-indirect-data-forwarding-tunnel-response, delete-indirect-data-forwarding-tunnel-request, delete-indirect-data-forwarding-tunnel-response, release-access-bearers-request, release-access-bearers-response, downlink-data-notification, downlink-data-notification-acknowledge, pgw-restart-notification, pgw-restart-notification-acknowledge, update-pdn-connection-set-request, update-pdn-connection-set-response, modify-access-bearers-request, modify-access-bearers-response, mbms-session-start-request, mbms-session-start-response, mbms-session-update-request, mbms-session-update-response, mbms-session-stop-request, mbms-session-stop-response

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

gtpc-inspection boolean
Synopsis Enable inspection of GTP-C packets
Context configure application-assurance group number partition number gtp gtpc-inspection boolean
Treegtpc-inspection

Description

When configured to true, this command enables the inspection of GTP-C packets. This is relevant only when AA GTP FW is deployed on S8/S5/Gp/Gn interfaces. This command must be enabled before configuring related features, such as APN filtering, GTP tunnel validation, message-type-v2 filtering, sequence number validation, and SRC IP validation.

When configured to false, GTP-C packet inspection cannot be performed.

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

log
Synopsis Enter the log context
Context configure application-assurance group number partition number gtp log
Treelog

Description

Commands in this context configure the AA group partition GTP log.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

action keyword
Synopsis GTP log action
Contextconfigure application-assurance group number partition number gtp log action keyword
Treeaction

Description

This command specifies the action on which the GTP log is raised.

Optionsdeny, permit, all
Defaultdeny
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mode keyword
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisGTP mode
Contextconfigure application-assurance group number partition number gtp mode keyword
Treemode
Optionsfiltering, untunneling
Default filtering
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

http-match-all-requests boolean
Synopsis Enable HTTP matching for all requests for an expression
Contextconfigure application-assurance group number partition number http-match-all-requests boolean
Treehttp-match-all-requests

Description

When configured to true, this command enables HTTP matching for all requests for an HTTP expression.

When configured to false, this command restores the default and removes the matching request for this particular expression.

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

http-x-online-host boolean
Synopsis Enable X-Online-Host header field
Context configure application-assurance group number partition number http-x-online-host boolean
Treehttp-x-online-host

Description

When configured to true, this command enables the X-Online-Host header field as a replacement for the HTTP Host header field.

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-identification-contribute boolean
Synopsis Contribute traffic info from this partition to group
Contextconfigure application-assurance group number partition number ip-identification-contribute boolean
Treeip-identification-contribute

Description

When configured to true, the router collects information from traffic in this partition and contributes it to the database that is built by the IP identification assist feature at the group level.

Defaulttrue
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-prefix-list [ip-prefix-list-name] named-item
Synopsis Enter the ip-prefix-list list instance
Contextconfigure application-assurance group number partition number ip-prefix-list named-item
Treeip-prefix-list

Description

Commands in this context configure an IP prefix list.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

prefix [ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis Enter the prefix list instance
Contextconfigure application-assurance group number partition number ip-prefix-list named-item prefix (ipv4-prefix | ipv6-prefix)
Treeprefix

Description

Commands in this context configure an IP prefix within the list.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[ip-prefix] (ipv4-prefix | ipv6-prefix)
Synopsis AA IP prefix
Contextconfigure application-assurance group number partition number ip-prefix-list named-item prefix (ipv4-prefix | ipv6-prefix)
Treeprefix

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

policy
Synopsis Enter the policy context
Context configure application-assurance group number partition number policy
Treepolicy

Description

Commands in this context configure the fields for the Application Assurance policy. 

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

app-filter
Synopsis Enter the app-filter context
Context configure application-assurance group number partition number policy app-filter
Treeapp-filter

Description

Commands in this context configure an application filter for Application Assurance.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure application-assurance group number partition number policy app-filter entry number
Treeentry

Description

Commands in this context create an application filter entry. 

Application filter entries are an ordered list. The lowest numerical entry that matches the flow defines the application for that flow. 

An application filter entry or entries configure match attributes of an application.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

expression [expr-index] number
Synopsis Enter the expression list instance
Contextconfigure application-assurance group number partition number policy app-filter entry number expression number
Treeexpression

Description

Commands in this context configure string values to use in the application definition.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

eq display-string
Synopsis Exact match for application filter matching expression
Contextconfigure application-assurance group number partition number policy app-filter entry number expression number eq display-string
Treeeq
String length1 to 255

Notes

The following elements are part of a mandatory choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

neq display-string
Synopsis Non-match for application filter matching expression
Contextconfigure application-assurance group number partition number policy app-filter entry number expression number neq display-string
Treeneq
String length1 to 255

Notes

The following elements are part of a mandatory choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

type keyword
Synopsis Application filter matching expression type
Contextconfigure application-assurance group number partition number policy app-filter entry number expression number type keyword
Treetype
Optionshttp-host, http-uri, http-referer, sip-ua, sip-uri, sip-mt, citrix-app, http-user-agent, h323-product-id, tls-cert-subj-org-name, tls-cert-subj-common-name, rtsp-host, rtsp-uri, rtsp-ua, rtmp-page-host, rtmp-page-uri, rtmp-swf-host, rtmp-swf-uri, rtmp-tc-host, rtmp-tc-uri, dns-domain-name

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

http-match-all-requests boolean
Synopsis Enable HTTP matching for all requests
Contextconfigure application-assurance group number partition number policy app-filter entry number http-match-all-requests boolean
Treehttp-match-all-requests

Description

When configured to true, this command enables HTTP matching for all requests for an HTTP expression.

When configured to false, this command restores the default for this app-filter entry which matches the first request.

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

http-port
Synopsis Enter the http-port context
Context configure application-assurance group number partition number policy app-filter entry number http-port
Treehttp-port
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

eq
Synopsis Enter the eq context
Context configure application-assurance group number partition number policy app-filter entry number http-port eq
Treeeq

Description

Commands in this context configure the exact value as the match criterion.

Notes

The following elements are part of a choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

neq
Synopsis Enter the neq context
Context configure application-assurance group number partition number policy app-filter entry number http-port neq
Treeneq

Description

Commands in this context configure the non-match criterion used. 

Notes

The following elements are part of a choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-identification-assist boolean
Synopsis Enable IP identification assist for this entry
Contextconfigure application-assurance group number partition number policy app-filter entry number ip-identification-assist boolean
Treeip-identification-assist

Description

When configured to true, the router performs a network IP address lookup that overrides the assigned application if it finds the network IP address in its internal application-IP database.

If an IP match is found, the application assigned from the app-filter is overridden with the application from the IP lookup. This also affects the app-group and charging group.

If an IP match is not found, the application assigned from the app-filter is not overridden and remains (including the app-group and charging group).

When configured to false, this command disables the router from performing a network IP address lookup and overriding the assigned application.

Defaultfalse
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-protocol
Synopsis Enter the ip-protocol context
Context configure application-assurance group number partition number policy app-filter entry number ip-protocol
Treeip-protocol

Description

Commands in this context configure the IP protocol to use in the application definition.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

eq (number | keyword)
Synopsis Exact match criterion used for the IP protocol number
Contextconfigure application-assurance group number partition number policy app-filter entry number ip-protocol eq (number | keyword)
Treeeq
Range0 to 255
Optionstcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp

Notes

The following elements are part of a choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

neq (number | keyword)
Synopsis Non-match criterion used for the IP protocol number
Contextconfigure application-assurance group number partition number policy app-filter entry number ip-protocol neq (number | keyword)
Treeneq
Range0 to 255
Optionstcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp

Notes

The following elements are part of a choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

network-address
Synopsis Enter the network-address context
Contextconfigure application-assurance group number partition number policy app-filter entry number network-address
Treenetwork-address

Description

Commands in this context configure the network address to use for the application filter entry. The network address is the address on the network side of AA, independent of whether the subscriber is acting as a client or server and is not normally used in AA app-filters. The network address will match the destination IP address in a from-sub flow or the source IP address in a to-sub flow.

Notes

The following elements are part of a choice: network-address or server-address.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

eq
Synopsis Enter the eq context
Context configure application-assurance group number partition number policy app-filter entry number network-address eq
Treeeq

Description

Commands in this context specify an exact value as the match criterion for the network address.

Notes

The following elements are part of a choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

neq
Synopsis Enter the neq context
Context configure application-assurance group number partition number policy app-filter entry number network-address neq
Treeneq

Description

Commands in this context specify the non-match criterion used for the network address. 

Notes

The following elements are part of a choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

protocol
Synopsis Enter the protocol context
Context configure application-assurance group number partition number policy app-filter entry number protocol
Treeprotocol

Description

Commands in this context configure the protocol signature in the application definition.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

eq (string | named-item)
Synopsis Exact match criterion used for the AA protocol name
Contextconfigure application-assurance group number partition number policy app-filter entry number protocol eq (string | named-item)
Treeeq
String length1 to 32

Notes

The following elements are part of a choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

neq (string | named-item)
Synopsis Non-match criterion used for the AA protocol name
Contextconfigure application-assurance group number partition number policy app-filter entry number protocol neq (string | named-item)
Treeneq
String length1 to 32

Notes

The following elements are part of a choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

server-address
Synopsis Enter the server-address context
Contextconfigure application-assurance group number partition number policy app-filter entry number server-address
Treeserver-address

Description

Commands in this context configure the server address to use for the application filter entry. The server address is the address on the server end of a client-server session.

Notes

The following elements are part of a choice: network-address or server-address.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

eq
Synopsis Enter the eq context
Context configure application-assurance group number partition number policy app-filter entry number server-address eq
Treeeq

Description

Commands in this context configure the attributes of the IP address used for the exact match criterion for the application flow.

Notes

The following elements are part of a choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

masked-ip
Synopsis Enter the masked-ip context
Context configure application-assurance group number partition number policy app-filter entry number server-address eq masked-ip
Treemasked-ip

Description

Commands in this context configure the attributes of a masked IP address.

Notes

The following elements are part of a choice: dns-ip-cache, ip-prefix, ip-prefix-list, or masked-ip.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

neq
Synopsis Enter the neq context
Context configure application-assurance group number partition number policy app-filter entry number server-address neq
Treeneq

Description

Commands in this context configure the attributes of the IP address used for non-matching criteria in the application flow. 

Notes

The following elements are part of a choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

masked-ip
Synopsis Enter the masked-ip context
Context configure application-assurance group number partition number policy app-filter entry number server-address neq masked-ip
Treemasked-ip

Description

Commands in this context configure the attributes of a masked IP address.

Notes

The following elements are part of a choice: dns-ip-cache, ip-prefix, ip-prefix-list, or masked-ip.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

server-port
Synopsis Enter the server-port context
Context configure application-assurance group number partition number policy app-filter entry number server-port
Treeserver-port

Description

Commands in this context specify the server TCP or UDP port number to use in the application definition.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

eq
Synopsis Enter the eq context
Context configure application-assurance group number partition number policy app-filter entry number server-port eq
Treeeq

Description

Commands in this context configure the exact value as the match criterion for the server TCP or UDP number in the app-filter. 

Notes

The following elements are part of a choice: eq, gt, lt, or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

range
Synopsis Enter the range context
Context configure application-assurance group number partition number policy app-filter entry number server-port eq range
Treerange

Description

Commands in this context specify the match value as the match criterion based on the starting or ending port number.

Notes

The following elements are part of a choice: port-list, port-number, or range.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

gt
Synopsis Enter the gt context
Context configure application-assurance group number partition number policy app-filter entry number server-port gt
Treegt

Description

Commands in this context specify the greater than value as the match criterion for the server port number for the app-filter.

Notes

The following elements are part of a choice: eq, gt, lt, or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

lt
Synopsis Enter the lt context
Context configure application-assurance group number partition number policy app-filter entry number server-port lt
Treelt

Description

Commands in this context specify the less than value as the match criterion for the server port number for the app-filter.

Notes

The following elements are part of a choice: eq, gt, lt, or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

neq
Synopsis Enter the neq context
Context configure application-assurance group number partition number policy app-filter entry number server-port neq
Treeneq

Description

Commands in this context configure non-match criterion used for the server TCP or UDP number in the app-filter. 

Notes

The following elements are part of a choice: eq, gt, lt, or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

range
Synopsis Enter the range context
Context configure application-assurance group number partition number policy app-filter entry number server-port neq range
Treerange

Description

Commands in this context specify the match value as the match criterion based on the starting or ending port number.

Notes

The following elements are part of a choice: port-list, port-number, or range.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

app-group [application-group-name] named-item
Synopsis Enter the app-group list instance
Contextconfigure application-assurance group number partition number policy app-group named-item
Treeapp-group

Description

Commands in this context create an application group for an application assurance policy.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[application-group-name] named-item
Synopsis Application group name
Context configure application-assurance group number partition number policy app-group named-item
Treeapp-group
String length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

export-id number
Synopsis App group export ID used in RADIUS accounting export
Contextconfigure application-assurance group number partition number policy app-group named-item export-id number
Treeexport-id

Description

This command assigns an export ID value to a charging group, an application group, or an application that RADIUS accounting uses for accounting export identification. This export ID is encoded in the top two bytes of the RADIUS accounting VSA to identify which charging group the counter value represents.

If no export ID is assigned, the counter cannot be added to the AA subscriber stats RADIUS export-type. After a charging group index is referenced, it cannot be deleted without removing the reference.

Range1 to 255
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

app-profile [app-profile-name] named-item
Synopsis Enter the app-profile list instance
Contextconfigure application-assurance group number partition number policy app-profile named-item
Treeapp-profile

Description

Commands in this context configure an application profile.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

aa-sub-distribute-traffic-by-ip boolean
Synopsis Allow application assurance to divert traffic
Contextconfigure application-assurance group number partition number policy app-profile named-item aa-sub-distribute-traffic-by-ip boolean
Treeaa-sub-distribute-traffic-by-ip

Description

When configured to true, the system diverts traffic on the parent SAPor spoke-SDP to multiple ISAs or ESAs based on the source IP address. This is useful when the bandwidth of a single SAP is larger than the capacity of a single ISA or ESA. This is only supported for the auto-created transit IP subscribers.

The traffic is diverted when the hashing is enabled at the AA group level and in the parent SAP application profile.

Defaultfalse
Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s

aa-sub-suppressible boolean
Synopsis Enable AA suppression for subs with this app profile
Contextconfigure application-assurance group number partition number policy app-profile named-item aa-sub-suppressible boolean
Treeaa-sub-suppressible

Description

When configured to true, this command configures the ability to suppress Application Assurance for subscribers with this application profile. 

This function is used in the context of an SRRP group interface. If an SRRP group interface is configured as configure service ies subscriber-interface group-interface suppress-aa-sub or configure service vprn subscriber-interface group-interface suppress-aa-sub, subscribers with an application profile configured as suppressible are not diverted to Application Assurance.

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

capacity-cost number
Synopsis Application profile capacity cost
Context configure application-assurance group number partition number policy app-profile named-item capacity-cost number
Treecapacity-cost

Description

This command configures an application profile capacity cost. 

Capacity cost based load balancing allows a cost to be assigned to diverted SAPs (with the application profile). This allows for load balancing SAPs between ISAs and acts as a threshold to notify the operator if capacity planning is exceeded.

Range1 to 65535
Default1
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

characteristic [characteristic-name] reference
Synopsis Enter the characteristic list instance
Contextconfigure application-assurance group number partition number policy app-profile named-item characteristic reference
Treecharacteristic

Description

Commands in this context assign one of the existing values of an existing application service option characteristic to the application profile.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

divert boolean
Synopsis Enable traffic redirection to AA ISAs or ESA VMs
Contextconfigure application-assurance group number partition number policy app-profile named-item divert boolean
Treedivert

Description

When configured to true, this command enables the redirection of traffic to AA ISAs or ESA VMs for the system-wide forwarding classes diverted to Application Assurance (configure isa application-assurance-group divert-fc) for AA subscribers using this application profile.

When configured to false, this command stops the redirection of traffic to AA ISAs or ESA VMs for the AA subscribers using this application profile.

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

app-qos-policy
Synopsis Enter the app-qos-policy context
Contextconfigure application-assurance group number partition number policy app-qos-policy
Treeapp-qos-policy

Description

Commands in this context configure an application QoS policy.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure application-assurance group number partition number policy app-qos-policy entry number
Treeentry

Description

Commands in this context create an application QoS policy (AQP) entry. 

A flow that matches multiple AQP entries will have multiple AQP entries actions applied. If a conflict occurs for two or more actions, the action from the AQP entry with the lowest numerical value takes precedence.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

action
Synopsis Enter the action context
Context configure application-assurance group number partition number policy app-qos-policy entry number action
Treeaction

Description

Commands in this context configure AQP actions to be performed on flows that match the match criteria of the AQP entry.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

bandwidth-policer
Synopsis Enter the bandwidth-policer context
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number action bandwidth-policer
Treebandwidth-policer

Description

Commands in this context assign an existing bandwidth policer as an action on flows matching this AQP entry. 

The match criteria for the AQP entry must specify a unidirectional traffic direction before a policer action can be configured. If a policer is used in one direction in an AQP match entry, the same policer name cannot be used by another AQP entry that uses different traffic direction match criteria. 

When multiple policers apply to a single flow, the final action on a packet is the worst case of all policer outcomes (for example, if one of the policers marks packet out of profile, the final marking will reflect that).

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

anl reference
Synopsis Access network locator bandwidth policer
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number action bandwidth-policer anl reference
Treeanl

Description

This command creates an Application Assurance policy profile for a policer instance for each ANL that limits traffic bandwidth in the scope of that ANL. For ANL, only single-bucket bandwidth policers can be configured.

Reference

configure application-assurance group number policer anl-bandwidth-policer named-item

Notes

The following elements are part of a choice: anl, dual-bucket, flow, or single-bucket.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dual-bucket reference
Synopsis Dual bucket bandwidth limiting policer
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number action bandwidth-policer dual-bucket reference
Treedual-bucket

Description

This command creates an Application Assurance policy profile for a dual bucket (PIR) bandwidth limiting policer.

Reference

configure application-assurance group number policer dual-bucket-bandwidth-policer named-item

Notes

The following elements are part of a choice: anl, dual-bucket, flow, or single-bucket.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

single-bucket reference
Synopsis Single bucket bandwidth limiting policer
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number action bandwidth-policer single-bucket reference
Treesingle-bucket

Description

This command creates an Application Assurance policy profile for a single bucket (PIR) bandwidth limiting policer.

Reference

configure application-assurance group number policer single-bucket-bandwidth-policer named-item

Notes

The following elements are part of a choice: anl, dual-bucket, flow, or single-bucket.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

drop boolean
Synopsis Enable drop action for the AQP entry
Context configure application-assurance group number partition number policy app-qos-policy entry number action drop boolean
Treedrop

Description

When configured to true, all flow traffic matching this AQP entry is dropped. 

The drop action is performed first and no other action is invoked on that flow even if multiple other actions exist for the flow because of one or more AQP entry matches.

When configured to false, this command disables the drop action on flows matching this AQP entry.

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

error-drop
Synopsis Enable the error-drop context
Context configure application-assurance group number partition number policy app-qos-policy entry number action error-drop
Treeerror-drop

Description

Commands in this context configure a drop action for error flows (for instance, bad IP checksums or TCP/UDP port 0).

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

flow-count-limit-policer
Synopsis Enter the flow-count-limit-policer context
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number action flow-count-limit-policer
Treeflow-count-limit-policer

Description

Commands in this context assign an existing flow count limit policer as an action on flows matching this AQP entry. 

The match criteria for the AQP entry must specify a unidirectional traffic direction before a policer action can be configured. If a policer is used in one direction in an AQP match entry, the same policer name cannot be used by another AQP entry that uses different traffic direction match criteria. 

When multiple policers are applied to a single flow, the final action on a packet is the worst case of all policer outcomes (for example, if one of the policers marks packet out of profile, the final marking will reflect that).

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

policer-name reference
Synopsis Policer name
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number action flow-count-limit-policer policer-name reference
Treepolicer-name

Description

This command specifies the name of the flow count limit policer for flows matching the AQP entry. The policer name is configured in the configure application-assurance group policer context.

Reference

configure application-assurance group number policer flow-count-limit-policer named-item

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

flow-setup-rate-policer
Synopsis Enter the flow-setup-rate-policer context
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number action flow-setup-rate-policer
Treeflow-setup-rate-policer

Description

Commands in this context assign an existing flow setup rate policer as an action on flows matching this AQP entry.

The match criteria for the AQP entry must specify a unidirectional traffic direction before a policer action can be configured. If a policer is used in one direction in an AQP match entry, the same policer name cannot be used for another AQP entry that uses different traffic direction match criteria.

When multiple policers are applied to a single flow, the final action on a packet is the worst case of all policer outcomes (for example, if one of the policers marks a packet out of profile, the final marking reflects that).

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

fragment-drop
Synopsis Enter the fragment-drop context
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number action fragment-drop
Treefragment-drop

Description

Commands in this context specify the drop action options to apply to fragments.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

http-enrich reference
Synopsis HTTP header enrichment action for the AQP entry
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number action http-enrich reference
Treehttp-enrich

Description

This command configures the HTTP header enrichment template name that is applied as defined in the tmnxBsxHttpEnrichTable. An empty value specifies no HTTP header enrichment template.

Reference

configure application-assurance group number http-enrich named-item

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

http-error-redirect reference
Synopsis HTTP error redirect for the AQP entry
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number action http-error-redirect reference
Treehttp-error-redirect

Description

This command specifies the HTTP error redirect that is applied as defined in the redirect table. An empty value specifies no HTTP error redirect.

Reference

configure application-assurance group number http-error-redirect named-item

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

http-redirect
Synopsis Enter the http-redirect context
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number action http-redirect
Treehttp-redirect

Description

Commands in this context assign an existing HTTP redirect policy as an action on flows matching this AQP entry. 

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

flow-type keyword
Synopsis Flow type for HTTP redirect of flows matching the entry
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number action http-redirect flow-type keyword
Treeflow-type

Description

This command assigns an existing HTTP redirect policy as an action on flows matching this AQP entry. The redirect only takes effect if the matching flows are HTTP and the condition specified is met. 

The condition specified by dropped flows means the flow is dropped due to an AQP action, such as flow rate, count policers, or drop actions. The admitted flows condition allows the operator to redirect HTTP traffic to a web portal while allowing non-HTTP traffic matching the same AQP rule to be forwarded.

No HTTP redirect takes place if the HTTP redirect action and a drop/flow-police action are part of the default AQP policy. In this case, any flow drop actions take place before identification of the application/application-group.

Optionsdropped-flows, admitted-flows
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mirror-source
Synopsis Enter the mirror-source context
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number action mirror-source
Treemirror-source

Description

Commands in this context configure an application-based policy mirroring service that uses the AQP entry of this AA ISA as a mirror source. 

When configured, the AQP entry becomes a mirror source for IP packets seen by AA. The mirrored packet is an IP packet analyzed by AA and does not include encapsulations present on the incoming interfaces.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

all-inclusive boolean
Synopsis Mirror flows matching the AQP subscriber default policy
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number action mirror-source all-inclusive boolean
Treeall-inclusive

Description

This command specifies that all packets during the identification phase that could match a given AQP rule are mirrored in addition to packets after an application identification completes that match the AQP rule. This ensures that all packets of a flow are mirrored at a cost of sending some unidentified packets, which after the application is identified no longer match this AQP entry.

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

overload-drop
Synopsis Enable the overload-drop context
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number action overload-drop
Treeoverload-drop

Description

Commands in this context configure a drop action for cases where flow records are not created (overload). This command is only applicable to ISA2 hardware.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

remark
Synopsis Enter the remark context
Context configure application-assurance group number partition number policy app-qos-policy entry number action remark
Treeremark

Description

Commands in this context configure the remark action on flows matching this AQP entry.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dscp
Synopsis Enter the dscp context
Context configure application-assurance group number partition number policy app-qos-policy entry number action remark dscp
Treedscp

Description

Commands in this context configure the DSCP remark action or actions on flows matching this AQP entry. 

All packets for all flows matching this AQP entry are remarked to the configured DSCP name. 

DSCP remark can only be applied when the entry remarks forwarding class or forwarding class and priority. In-profile and out-of-profile of a packet for DSCP remark is assessed after all AQP policing and priority remarking actions have taken place.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

in-profile keyword
Synopsis DSCP name to remark matching in-profile flows
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number action remark dscp in-profile keyword
Treein-profile
Optionsbe, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

out-profile keyword
Synopsis DSCP name to remark matching out-of-profile flows
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number action remark dscp out-profile keyword
Treeout-profile
Optionsbe, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

fc keyword
Synopsis FC remark action for flows matching this entry
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number action remark fc keyword
Treefc
Options

be – Best effort

l2 – Low 2 (best effort)

af – Assured forwarding (assured)

l1 – Low 1 (assured)

h2 – High 2 (high priority)

ef – Expedited forwarding (high priority)

h1 – High 1 (high priority)

nc – Network control (high priority)

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

tcp-validate reference
Synopsis TCP validation policy action for entry matching flows
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number action tcp-validate reference
Treetcp-validate

Description

This command assigns an existing TCP validation policy as an action on flows matching this AQP entry.

TCP validation can only be called from AQP entries that:

  • have no matching conditions that relate to information extracted from the incoming IP packets; for example, no application or IP address.

  • allow the following match conditions: none, aa-sub, characteristic, traffic-direction (both only), traffic-direction cannot be unidirectional (from or to sub). It can either be set to both or left unspecified.

Reference

configure application-assurance group number partition number tcp-validate named-item

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

url-filter
Synopsis Enter the url-filter context
Context configure application-assurance group number partition number policy app-qos-policy entry number action url-filter
Treeurl-filter

Description

Commands in this context configure a URL filter action for flows matching this entry.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

match
Synopsis Enter the match context
Context configure application-assurance group number partition number policy app-qos-policy entry number match
Treematch

Description

Commands in this context configure flow match rules for this AQP entry. A flow matches this AQP entry only if it matches all match rules defined (logical AND of all rules). If no match rule is specified, the entry will match all flows. 

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

aa-sub
Synopsis Enter the aa-sub context
Context configure application-assurance group number partition number policy app-qos-policy entry number match aa-sub
Treeaa-sub

Description

Commands in this context specify a Service Access Point (SAP) or an Enhanced Subscriber Management (ESM) subscriber as matching criteria.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

esm
Synopsis Enter the esm context
Context configure application-assurance group number partition number policy app-qos-policy entry number match aa-sub esm
Treeesm

Description

Commands in this context configure the ESM fields for the AA subscriber match entry.

Notes

The following elements are part of a choice: esm, esm-mac, sap, spoke-sdp, or transit.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

esm-mac
Synopsis Enter the esm-mac context
Context configure application-assurance group number partition number policy app-qos-policy entry number match aa-sub esm-mac
Treeesm-mac

Description

Commands in this context configure the ESM MAC fields for the AA subscriber match entry.

Notes

The following elements are part of a choice: esm, esm-mac, sap, spoke-sdp, or transit.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

sap
Synopsis Enter the sap context
Context configure application-assurance group number partition number policy app-qos-policy entry number match aa-sub sap
Treesap

Description

Commands in this context configure the SAP fields for the AA subscriber match entry.

Notes

The following elements are part of a choice: esm, esm-mac, sap, spoke-sdp, or transit.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

spoke-sdp
Synopsis Enter the spoke-sdp context
Context configure application-assurance group number partition number policy app-qos-policy entry number match aa-sub spoke-sdp
Treespoke-sdp

Description

Commands in this context configure the spoke SDP fields for the AA subscriber match entry.

Notes

The following elements are part of a choice: esm, esm-mac, sap, spoke-sdp, or transit.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

transit
Synopsis Enter the transit context
Context configure application-assurance group number partition number policy app-qos-policy entry number match aa-sub transit
Treetransit

Description

Commands in this context configure the transit fields for the AA subscriber match entry.

Notes

The following elements are part of a choice: esm, esm-mac, sap, spoke-sdp, or transit.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

app-group
Synopsis Enter the app-group context
Context configure application-assurance group number partition number policy app-qos-policy entry number match app-group
Treeapp-group

Description

Commands in this context add an application group to the match criteria used by this AQP entry.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

application
Synopsis Enter the application context
Context configure application-assurance group number partition number policy app-qos-policy entry number match application
Treeapplication

Description

Commands in this context add an application to match criteria used by this AQP entry.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

characteristic [characteristic-name] reference
Synopsis Enter the characteristic list instance
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number match characteristic reference
Treecharacteristic

Description

Commands in this context configure an existing characteristic and its value to the match criteria used by this AQP entry.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

eq reference
Synopsis Match criterion used for AQP match characteristic
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number match characteristic reference eq reference
Treeeq

Reference

configure application-assurance group number partition number policy app-service-options characteristic named-item value named-item

Notes

The following elements are part of a mandatory choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

neq reference
Synopsis Non-match criterion used for AQP match characteristic
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number match characteristic reference neq reference
Treeneq

Reference

configure application-assurance group number partition number policy app-service-options characteristic named-item value named-item

Notes

The following elements are part of a mandatory choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

charging-group
Synopsis Enter the charging-group context
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number match charging-group
Treecharging-group

Description

Commands in this context add a charging group to match criteria used by this AQP entry.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dscp
Synopsis Enter the dscp context
Context configure application-assurance group number partition number policy app-qos-policy entry number match dscp
Treedscp

Description

Commands in this context add a DSCP name to the match criteria used by this entry.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

eq keyword
Synopsis Exact match criterion used for the DSCP
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number match dscp eq keyword
Treeeq
Optionsbe, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63

Notes

The following elements are part of a choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

neq keyword
Synopsis Non-match criterion used for the DSCP
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number match dscp neq keyword
Treeneq
Optionsbe, cp1, cp2, cp3, cp4, cp5, cp6, cp7, cs1, cp9, af11, cp11, af12, cp13, af13, cp15, cs2, cp17, af21, cp19, af22, cp21, af23, cp23, cs3, cp25, af31, cp27, af32, cp29, af33, cp31, cs4, cp33, af41, cp35, af42, cp37, af43, cp39, cs5, cp41, cp42, cp43, cp44, cp45, ef, cp47, nc1, cp49, cp50, cp51, cp52, cp53, cp54, cp55, nc2, cp57, cp58, cp59, cp60, cp61, cp62, cp63

Notes

The following elements are part of a choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dst-ip
Synopsis Enter the dst-ip context
Context configure application-assurance group number partition number policy app-qos-policy entry number match dst-ip
Treedst-ip

Description

Commands in this context configure a destination IP address to use as match criteria.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

eq
Synopsis Enter the eq context
Context configure application-assurance group number partition number policy app-qos-policy entry number match dst-ip eq
Treeeq

Description

Commands in this context specify the exact match value as the match criterion. A successful match occurs when the flow matches the specified address or prefix.

Notes

The following elements are part of a choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

neq
Synopsis Enter the neq context
Context configure application-assurance group number partition number policy app-qos-policy entry number match dst-ip neq
Treeneq

Description

Commands in this context specify the non-match value as the match criterion. A successful match occurs when the flow does not match the specified address or prefix.

Notes

The following elements are part of a choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dst-port
Synopsis Enter the dst-port context
Context configure application-assurance group number partition number policy app-qos-policy entry number match dst-port
Treedst-port

Description

Commands in this context configure a destination TCP/UDP port, a destination port list, or a destination range to use as match criteria.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

eq
Synopsis Enter the eq context
Context configure application-assurance group number partition number policy app-qos-policy entry number match dst-port eq
Treeeq

Description

Commands in this context specify the exact match criterion. A successful match occurs when the flow matches the specified port.

Notes

The following elements are part of a choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

range
Synopsis Enter the range context
Context configure application-assurance group number partition number policy app-qos-policy entry number match dst-port eq range
Treerange

Description

Commands in this context specify the match value as the match criterion based on the starting or ending port number.

Notes

The following elements are part of a choice: port-list, port-number, or range.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

neq
Synopsis Enter the neq context
Context configure application-assurance group number partition number policy app-qos-policy entry number match dst-port neq
Treeneq

Description

Commands in this context specify the non-match value as the match criterion. A successful match occurs when the flow does not match the specified port.

Notes

The following elements are part of a choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

range
Synopsis Enter the range context
Context configure application-assurance group number partition number policy app-qos-policy entry number match dst-port neq range
Treerange

Description

Commands in this context specify the match value as the match criterion based on the starting or ending port number.

Notes

The following elements are part of a choice: port-list, port-number, or range.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

flow-attribute [flow-attribute-name] named-item
Synopsis Enter the flow-attribute list instance
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number match flow-attribute named-item
Treeflow-attribute

Description

Commands in this context configure a flow attribute to use as match criteria. The supported options are: 

  • abr_service

  • audio

  • download

  • encrypted

  • esni

  • real_time_communication

  • upload

  • video

Max. instances10
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

confidence
Synopsis Enter the confidence context
Context configure application-assurance group number partition number policy app-qos-policy entry number match flow-attribute named-item confidence
Treeconfidence

Description

Commands in this context configure the confidence level of the flow attribute for use as match criteria.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-protocol
Synopsis Enter the ip-protocol context
Context configure application-assurance group number partition number policy app-qos-policy entry number match ip-protocol
Treeip-protocol

Description

Commands in this context configure the IP protocol to use in the application definition.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

eq (number | keyword)
Synopsis Exact match criterion used for the IP protocol
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number match ip-protocol eq (number | keyword)
Treeeq
Range0 to 255
Optionstcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp

Notes

The following elements are part of a choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

neq (number | keyword)
Synopsis Non-match criterion used for the IP protocol
Contextconfigure application-assurance group number partition number policy app-qos-policy entry number match ip-protocol neq (number | keyword)
Treeneq
Range0 to 255
Optionstcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp

Notes

The following elements are part of a choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

src-ip
Synopsis Enter the src-ip context
Context configure application-assurance group number partition number policy app-qos-policy entry number match src-ip
Treesrc-ip

Description

Commands in this context configure a source IP address to use as match criteria.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

eq
Synopsis Enter the eq context
Context configure application-assurance group number partition number policy app-qos-policy entry number match src-ip eq
Treeeq

Description

Commands in this context specify the exact match value as the match criterion. A successful match occurs when the flow matches the specified address or prefix.

Notes

The following elements are part of a choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

neq
Synopsis Enter the neq context
Context configure application-assurance group number partition number policy app-qos-policy entry number match src-ip neq
Treeneq

Description

Commands in this context specify the non-match value as the match criterion. A successful match occurs when the flow does not match the specified address or prefix.

Notes

The following elements are part of a choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

src-port
Synopsis Enter the src-port context
Context configure application-assurance group number partition number policy app-qos-policy entry number match src-port
Treesrc-port

Description

Commands in this context specify a source IP port, a source port list, or a source range to use as match criteria.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

eq
Synopsis Enter the eq context
Context configure application-assurance group number partition number policy app-qos-policy entry number match src-port eq
Treeeq

Description

Commands in this context specify the exact match criterion. A successful match occurs when the flow matches the specified port.

Notes

The following elements are part of a choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

range
Synopsis Enter the range context
Context configure application-assurance group number partition number policy app-qos-policy entry number match src-port eq range
Treerange

Description

Commands in this context specify the match value as the match criterion based on the starting or ending port number.

Notes

The following elements are part of a choice: port-list, port-number, or range.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

neq
Synopsis Enter the neq context
Context configure application-assurance group number partition number policy app-qos-policy entry number match src-port neq
Treeneq

Description

Commands in this context specify the non-match value as the match criterion. A successful match occurs when the flow does not match the specified port.

Notes

The following elements are part of a choice: eq or neq.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

range
Synopsis Enter the range context
Context configure application-assurance group number partition number policy app-qos-policy entry number match src-port neq range
Treerange

Description

Commands in this context specify the match value as the match criterion based on the starting or ending port number.

Notes

The following elements are part of a choice: port-list, port-number, or range.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

app-service-options
Synopsis Enter the app-service-options context
Contextconfigure application-assurance group number partition number policy app-service-options
Treeapp-service-options

Description

Commands in this context configure application service option characteristics.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

characteristic [characteristic-name] named-item
Synopsis Enter the characteristic list instance
Contextconfigure application-assurance group number partition number policy app-service-options characteristic named-item
Treecharacteristic

Description

Commands in this context create the characteristic of the application service options.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

value [value-name] named-item
Synopsis Add a list entry for value
Context configure application-assurance group number partition number policy app-service-options characteristic named-item value named-item
Treevalue

Description

Commands in this context configure a characteristic value.

Max. instances64
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

application [application-name] named-item
Synopsis Enter the application list instance
Contextconfigure application-assurance group number partition number policy application named-item
Treeapplication

Description

Commands in this context configure the policy application of the Application Assurance group partition.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

charging-filter
Synopsis Enter the charging-filter context
Contextconfigure application-assurance group number partition number policy charging-filter
Treecharging-filter
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure application-assurance group number partition number policy charging-filter entry number
Treeentry
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[entry-id] number
Synopsis Charging filter entry ID in the AA partition policy
Contextconfigure application-assurance group number partition number policy charging-filter entry number
Treeentry

Description

This command defines a charging filter entry ID. Charging filter entries are an ordered list; the lowest numerical entry that matches the flow, defines the charging filter for this flow.

Range1 to 65535

Notes

This element is part of a list key.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

charging-group reference
Synopsis Charging group to associate to flows matching the entry
Contextconfigure application-assurance group number partition number policy charging-filter entry number charging-group reference
Treecharging-group

Description

This command associates a charging group to the flows that match the charging filter entry.

Reference

configure application-assurance group number partition number policy charging-group named-item

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

match
Synopsis Enter the match context
Context configure application-assurance group number partition number policy charging-filter entry number match
Treematch
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

app-group
Synopsis Enter the app-group context
Context configure application-assurance group number partition number policy charging-filter entry number match app-group
Treeapp-group
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

eq reference
Synopsis Exact value as the match criterion
Context configure application-assurance group number partition number policy charging-filter entry number match app-group eq reference
Treeeq

Description

This command specifies that the value configured and the value in the flow must be equal for a match to occur.

Reference

configure application-assurance group number partition number policy app-group named-item

Notes

The following elements are part of a choice: eq or neq.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

neq reference
Synopsis Non-matching application to resolve to a charging group
Contextconfigure application-assurance group number partition number policy charging-filter entry number match app-group neq reference
Treeneq

Description

This command specifies that the value configured and the value in the flow must differ for a match to occur.

Reference

configure application-assurance group number partition number policy app-group named-item

Notes

The following elements are part of a choice: eq or neq.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

application
Synopsis Enter the application context
Context configure application-assurance group number partition number policy charging-filter entry number match application
Treeapplication
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

eq reference
Synopsis Exact value as the match criterion
Context configure application-assurance group number partition number policy charging-filter entry number match application eq reference
Treeeq

Description

This command specifies that the value configured and the value in the flow must be equal for a match to occur.

Reference

configure application-assurance group number partition number policy application named-item

Notes

The following elements are part of a choice: eq or neq.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

neq reference
Synopsis Non-matching application to resolve to a charging group
Contextconfigure application-assurance group number partition number policy charging-filter entry number match application neq reference
Treeneq

Description

This command specifies that the value configured and the value in the flow must differ for a match to occur.

Reference

configure application-assurance group number partition number policy application named-item

Notes

The following elements are part of a choice: eq or neq.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

flow-attribute [flow-attribute-name] named-item
Synopsis Enter the flow-attribute list instance
Contextconfigure application-assurance group number partition number policy charging-filter entry number match flow-attribute named-item
Treeflow-attribute
Max. instances10
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[flow-attribute-name] named-item
Synopsis Flow attribute name match criteria
Context configure application-assurance group number partition number policy charging-filter entry number match flow-attribute named-item
Treeflow-attribute

Description

This command adds a flow attribute to the match criteria used by this charging filter entry.

String length1 to 32

Notes

This element is part of a list key.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

confidence
Synopsis Enter the confidence context
Context configure application-assurance group number partition number policy charging-filter entry number match flow-attribute named-item confidence
Treeconfidence
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

eq number
Synopsis Exact value as the match criterion
Context configure application-assurance group number partition number policy charging-filter entry number match flow-attribute named-item confidence eq number
Treeeq

Description

This command specifies that a successful match occurs when the flow attribute confidence level is equal to the specified value.

Range0 to 100

Notes

The following elements are part of a choice: eq, gte, or lt.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

gte number
Synopsis Confidence value to resolve to a charging group
Contextconfigure application-assurance group number partition number policy charging-filter entry number match flow-attribute named-item confidence gte number
Treegte

Description

This command specifies that a successful match occurs when the flow attribute confidence level is greater than or equal to the specified value.

Range0 to 100

Notes

The following elements are part of a choice: eq, gte, or lt.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

lt number
Synopsis Less than value as the match criterion
Contextconfigure application-assurance group number partition number policy charging-filter entry number match flow-attribute named-item confidence lt number
Treelt

Description

This command specifies that a successful match occurs when the flow attribute confidence level is less than the specified value.

Range1 to 100

Notes

The following elements are part of a choice: eq, gte, or lt.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

charging-group [charging-group-name] named-item
Synopsis Enter the charging-group list instance
Contextconfigure application-assurance group number partition number policy charging-group named-item
Treecharging-group

Description

Commands in this context create a charging group for an Application Assurance policy.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

export-id number
Synopsis Charging group export ID used for RADIUS accounting
Contextconfigure application-assurance group number partition number policy charging-group named-item export-id number
Treeexport-id

Description

This command assigns an export ID value to a charging group, an app application group, or an application to be used for accounting export identification in RADIUS accounting. This ID is encoded in the top 2 bytes of the RADIUS accounting VSA to identify which charging group the counter value represents.

Range1 to 255
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

custom-protocol [custom-protocol-id] custom-protocol-name
Synopsis Enter the custom-protocol list instance
Contextconfigure application-assurance group number partition number policy custom-protocol custom-protocol-name
Treecustom-protocol

Description

Commands in this context configure custom protocols. 

Custom protocols allow the creation of TCP and UDP-based custom protocols that employ pattern-match at offset in the protocol signature definition.

Operator-configurable custom protocols are evaluated ahead of any Nokia-provided protocol signature in order of custom protocol ID within the context the protocol is defined. The lower ID is matched first in case of flow matching multiple custom protocols.

Custom protocols must be created before they can be used in an application definition but do not have to be enabled. To reference a custom protocol in an application definition, or any other CLI configuration one must use the protocol name that is a concatenation of “custom_” and, (for example, custom_01, custom_02 ... custom_10, and so on). This concatenation is also used when reporting custom protocol statistics.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[custom-protocol-id] custom-protocol-name
Synopsis Custom protocol ID for the AA policy custom protocol
Contextconfigure application-assurance group number partition number policy custom-protocol custom-protocol-name
Treecustom-protocol

Description

This command configures the index into the protocol list that defines a custom protocol for Application Assurance.

String length9

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

expression [expr-index] number
Synopsis Enter the expression list instance
Contextconfigure application-assurance group number partition number policy custom-protocol custom-protocol-name expression number
Treeexpression

Description

Commands in this context configure an expression string value for pattern-based custom protocols match. 

A flow matches a custom protocol if the specified string is found at an offset of a TCP/UDP of the first payload packet.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

direction keyword
Synopsis Flow direction for custom-protocol expression matching
Contextconfigure application-assurance group number partition number policy custom-protocol custom-protocol-name expression number direction keyword
Treedirection

Description

This command configures the protocol direction to match against for a custom protocol.

Optionsclient-to-server, server-to-client, any

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

eq display-string
Synopsis Exact match criterion for custom protocol expression
Contextconfigure application-assurance group number partition number policy custom-protocol custom-protocol-name expression number eq display-string
Treeeq
String length1 to 255

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

offset number
Synopsis Offset in protocol flow to start custom-protocol match
Contextconfigure application-assurance group number partition number policy custom-protocol custom-protocol-name expression number offset number
Treeoffset

Description

This command configures the offset into the protocol payload where the expr-string match criteria starts.

Range0 to 127
Default0
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-protocol keyword
Warning:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisIP protocol number for custom-protocol match criterion
Contextconfigure application-assurance group number partition number policy custom-protocol custom-protocol-name ip-protocol keyword
Treeip-protocol

Description

This command configures the IP protocol number of the TCP and UDP-based custom protocols.

Optionstcp, udp

Notes

This element is mandatory.

Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

default-charging-group reference
Synopsis Default charging group
Context configure application-assurance group number partition number policy default-charging-group reference
Treedefault-charging-group

Description

This command associates a charging group with any applications or application groups that do not have an explicitly assigned charging group for the Application Assurance policy.  

Reference

configure application-assurance group number partition number policy charging-group named-item

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

default-tethered-charging-group reference
Synopsis Default charging group for tethered traffic
Contextconfigure application-assurance group number partition number policy default-tethered-charging-group reference
Treedefault-tethered-charging-group

Description

This command configures the default charging group to be assigned to all flows which are classified as tethered.

For flows that have been identified as tethered, the AA will replace the charging group configured at the application level with the charging group configured for tethered traffic (that is, configured with default-tethered-charging-group).

Reference

configure application-assurance group number partition number policy charging-group named-item

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

policy-override
Synopsis Enter the policy-override context
Contextconfigure application-assurance group number partition number policy-override
Treepolicy-override

Description

Commands in this context configure policy override parameters.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

aa-sub
Synopsis Enter the aa-sub context
Context configure application-assurance group number partition number policy-override aa-sub
Treeaa-sub

Description

Commands in this context configure the AA policy override subscriber fields.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

sap [sap-id] sap
Synopsis Enter the sap list instance
Context configure application-assurance group number partition number policy-override aa-sub sap sap
Treesap

Description

Commands in this context configure the Service Access Point (SAP) within the partition.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

characteristic [characteristic-name] reference
Synopsis Enter the characteristic list instance
Contextconfigure application-assurance group number partition number policy-override aa-sub sap sap characteristic reference
Treecharacteristic

Description

Commands in this context configure an override characteristic and value.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

spoke-sdp [sdp-bind-id] sdp-bind-id
Synopsis Enter the spoke-sdp list instance
Contextconfigure application-assurance group number partition number policy-override aa-sub spoke-sdp sdp-bind-id
Treespoke-sdp

Description

Commands in this context configure the Service Destination Point (SDP) for the policy override.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

characteristic [characteristic-name] reference
Synopsis Enter the characteristic list instance
Contextconfigure application-assurance group number partition number policy-override aa-sub spoke-sdp sdp-bind-id characteristic reference
Treecharacteristic

Description

Commands in this context configure an override characteristic and value.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

transit [transit-sub-name] named-item
Synopsis Enter the transit list instance
Contextconfigure application-assurance group number partition number policy-override aa-sub transit named-item
Treetransit

Description

Commands in this context configure the AA transit subscriber fields.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

characteristic [characteristic-name] reference
Synopsis Enter the characteristic list instance
Contextconfigure application-assurance group number partition number policy-override aa-sub transit named-item characteristic reference
Treecharacteristic

Description

Commands in this context configure an override characteristic and value.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

port-list [port-list-name] named-item
Synopsis Enter the port-list list instance
Contextconfigure application-assurance group number partition number port-list named-item
Treeport-list

Description

Commands in this context define an AA group or partition named port list, which contains a list of port numbers or port ranges. 

The port list is then referenced in AA policy application filters, allowing increased flexibility in the use of server ports or HTTP proxy ports for application definition.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[port-list-name] named-item
Synopsis Port list name
Contextconfigure application-assurance group number partition number port-list named-item
Treeport-list
String length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

port [port-number] number
Synopsis Add a list entry for port
Context configure application-assurance group number partition number port-list named-item port number
Treeport

Description

Commands in this context specify the server TCP or UDP port number to use in the port list definition.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[port-number] number
Synopsis Port number
Contextconfigure application-assurance group number partition number port-list named-item port number
Treeport
Range0 to 65535

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

range start number end number
Synopsis Add a list entry for range
Context configure application-assurance group number partition number port-list named-item range start number end number
Treerange

Description

Commands in this context configure the AA group or partition named port-list range.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

start number
Synopsis Start value for the port range in the AA port list
Contextconfigure application-assurance group number partition number port-list named-item range start number end number
Treerange
Range0 to 65534

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

end number
Synopsis End value for the port range in the AA port list
Contextconfigure application-assurance group number partition number port-list named-item range start number end number
Treerange
Range1 to 65535

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

sctp-filter [sctp-filter-name] named-item
Synopsis Enter the sctp-filter list instance
Contextconfigure application-assurance group number partition number sctp-filter named-item
Treesctp-filter

Description

Commands in this context configure the Stream Control Transmission Protocol (SCTP) fields.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[sctp-filter-name] named-item
Synopsis SCTP filter name
Context configure application-assurance group number partition number sctp-filter named-item
Treesctp-filter
String length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ppid
Synopsis Enter the ppid context
Context configure application-assurance group number partition number sctp-filter named-item ppid
Treeppid

Description

Commands in this context configure actions for specific or default Payload Protocol Identifiers (PPIDs).

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure application-assurance group number partition number sctp-filter named-item ppid entry number
Treeentry

Description

Commands in this context specify SCTP PPID values and the corresponding action to apply.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[entry-id] number
Synopsis SCTP filter PPID entry ID
Context configure application-assurance group number partition number sctp-filter named-item ppid entry number
Treeentry
Range1 to 255

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

value (number | keyword)
Warning:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPPID entry value
Contextconfigure application-assurance group number partition number sctp-filter named-item ppid entry number value (number | keyword)
Treevalue
Range0 to 4294967295
Optionsiua, m2ua, m3ua, sua, m2pa, v5ua, h.248, bicc/q.2150.3, tali, dua, asap, enrp, h.323, q.ipc/q.2150.3, simco, ddp-segment-chunk, ddp-stream-session-control, s1-application-protocol, rua, hnbap, forces-hp, forces-mp, forces-lp, sbc-ap, nbap, x2ap, ircp, lcs-ap, mpich2, service-area-broadcast-protocol, fractal-generator-protocol, ping-pong-protocol, calcapp-protocol, scripting-service-protocol, netperfmeter-protocol-control-channel, netperfmeter-protocol-data-channel, echo, discard, daytime, character-generator, 3gpp-rna, 3gpp-m2ap, 3gpp-m3ap, ssh-over-sctp, diameter-in-a-sctp-data-chunk, diameter-in-a-dtls/sctp-data-chunk, r14p.-ber-encoded-asn.1-over-sctp, webrtc-control, domstring-last, binary-data-partial, binary-data-last, domstring-partial, 3gpp-pua, webrtc-string-empty, webrtc-binary-empty, 3gpp-xwap, 3gpp-xw-control-plane, 3gpp-ng-application-protocol, 3gpp-xn-application-protocol, 3gpp-f1-application-protocol, http-sctp, 3gpp-e1-application-protocol, ele2-lawful-interception, 3gpp-ngap-over-dtls-over-sctp, 3gpp-xnap-over-dtls-over-sctp, 3gpp-f1ap-over-dtls-over-sctp, 3gpp-e1ap-over-dtls-over-sctp, e2-cp, e2-up, e2-du, 3gpp-w1ap

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ppid-range
Synopsis Enter the ppid-range context
Context configure application-assurance group number partition number sctp-filter named-item ppid-range
Treeppid-range

Description

Commands in this context specify the range of PPID values that are allowed by the AA SCTP filter firewall.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

max number
Synopsis Maximum PPID value
Context configure application-assurance group number partition number sctp-filter named-item ppid-range max number
Treemax

Description

This command configures the maximum SCTP Payload Protocol Identifier (PPID) to be permitted by the SCTP filter. The value must be greater or equal to the minimum PPID value.

Range0 to 4294967295
Default4294967295
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

min number
Synopsis Minimum PPID value
Context configure application-assurance group number partition number sctp-filter named-item ppid-range min number
Treemin

Description

This command configures the minimum SCTP Payload Protocol Identifier (PPID) to be permitted by the SCTP filter. The value must be less than or equal to the maximum PPID value.

Range0 to 4294967295
Default0
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

session-filter [session-filter-name] named-item
Synopsis Enter the session-filter list instance
Contextconfigure application-assurance group number partition number session-filter named-item
Treesession-filter

Description

Commands in this context create a session filter.

Max. instances1000
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

default-action
Synopsis Enter the default-action context
Contextconfigure application-assurance group number partition number session-filter named-item default-action
Treedefault-action

Description

Commands in this context specify the default action to take for packets that do not match any filter entries.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure application-assurance group number partition number session-filter named-item entry number
Treeentry

Description

Commands in this context configure an AA session filter match entry.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[entry-id] number
Synopsis Entry ID for the session filter entry
Contextconfigure application-assurance group number partition number session-filter named-item entry number
Treeentry
Range1 to 65535

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

action
Synopsis Enter the action context
Context configure application-assurance group number partition number session-filter named-item entry number action
Treeaction

Description

Commands in this context configure the action for this entry.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

deny
Synopsis Deny sessions matching the criteria
Context configure application-assurance group number partition number session-filter named-item entry number action deny
Treedeny

Notes

The following elements are part of a choice: deny, http-redirect, l3-l4-redirect, permit, or tcp-optimizer.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

l3-l4-redirect
Synopsis Enter the l3-l4-redirect context
Contextconfigure application-assurance group number partition number session-filter named-item entry number action l3-l4-redirect
Treel3-l4-redirect

Description

Commands in this context specify sessions matching the criteria are redirected to a different destination using Layer 3 and Layer 4 redirect.

If the redirect action is removed from a session filter, the existing redirected flows are not affected, redirect still occurs. However, no redirect will be applied to newly-established flows.

Notes

The following elements are part of a choice: deny, http-redirect, l3-l4-redirect, permit, or tcp-optimizer.

Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dst-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Destination IP address for traffic redirection
Contextconfigure application-assurance group number partition number session-filter named-item entry number action l3-l4-redirect dst-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treedst-ip-address

Description

This command specifies a valid unicast server IPv4 or IPv6 address to forward the traffic to. The destination IP address (Layer 3) is modified as indicated. In the reverse direction (toward the subscriber), AA restores the original IP address as the source IP field.

Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dst-port number
Synopsis Destination port for traffic redirection
Contextconfigure application-assurance group number partition number session-filter named-item entry number action l3-l4-redirect dst-port number
Treedst-port

Description

This command specifies a valid TCP/UDP server destination port number. The destination port is modified as indicated. In the reverse direction (toward the subscriber), AA restores the original port number as the port field.

Range0 | 1 to 65535
Default0
Introduced 24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

permit
Synopsis Permit sessions that match the criteria
Contextconfigure application-assurance group number partition number session-filter named-item entry number action permit
Treepermit

Notes

The following elements are part of a choice: deny, http-redirect, l3-l4-redirect, permit, or tcp-optimizer.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

tcp-optimizer reference
Synopsis TCP optimizer to handle sessions matching the criteria
Contextconfigure application-assurance group number partition number session-filter named-item entry number action tcp-optimizer reference
Treetcp-optimizer

Reference

configure application-assurance group number tcp-optimizer named-item

Notes

The following elements are part of a choice: deny, http-redirect, l3-l4-redirect, permit, or tcp-optimizer.

Introduced22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

match
Synopsis Enter the match context
Context configure application-assurance group number partition number session-filter named-item entry number match
Treematch

Description

Commands in this context configure session conditions for this entry.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dst-ip
Synopsis Enter the dst-ip context
Context configure application-assurance group number partition number session-filter named-item entry number match dst-ip
Treedst-ip

Description

Commands in this context configure the destination IP address to match.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-prefix (ipv4-prefix | ipv6-prefix)
Synopsis Destination IP address prefix as match criterion
Contextconfigure application-assurance group number partition number session-filter named-item entry number match dst-ip ip-prefix (ipv4-prefix | ipv6-prefix)
Treeip-prefix

Notes

The following elements are part of a choice: dns-ip-cache, ip-prefix, or ip-prefix-list.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-prefix-list reference
Synopsis IP address prefix list as match criterion
Contextconfigure application-assurance group number partition number session-filter named-item entry number match dst-ip ip-prefix-list reference
Treeip-prefix-list

Reference

configure application-assurance group number partition number ip-prefix-list named-item

Notes

The following elements are part of a choice: dns-ip-cache, ip-prefix, or ip-prefix-list.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dst-port
Synopsis Enter the dst-port context
Context configure application-assurance group number partition number session-filter named-item entry number match dst-port
Treedst-port

Description

Commands in this context specify a destination TCP/UDP port, a destination port list, or a destination range to use as match criteria.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

eq number
Synopsis Match criterion used for destination or source port
Contextconfigure application-assurance group number partition number session-filter named-item entry number match dst-port eq number
Treeeq
Range0 | 1 to 65535
Default0

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

gt number
Synopsis Greater than match criterion for the port number
Contextconfigure application-assurance group number partition number session-filter named-item entry number match dst-port gt number
Treegt
Range0 | 1 to 65535
Default0

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

lt number
Synopsis Less than match criterion for the port
Contextconfigure application-assurance group number partition number session-filter named-item entry number match dst-port lt number
Treelt
Range0 | 1 to 65535
Default0

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

range
Synopsis Enable the range context
Context configure application-assurance group number partition number session-filter named-item entry number match dst-port range
Treerange

Description

Commands in this context specify a destination IP port, a destination port list, or a destination range to use as match criteria.

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-protocol (number | keyword)
Synopsis IP protocol as a match criterion
Context configure application-assurance group number partition number session-filter named-item entry number match ip-protocol (number | keyword)
Treeip-protocol
Range0 to 255
Optionstcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

src-ip
Synopsis Enter the src-ip context
Context configure application-assurance group number partition number session-filter named-item entry number match src-ip
Treesrc-ip

Description

Commands in this context specify a source IP address to use as match criteria.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-prefix (ipv4-prefix | ipv6-prefix)
Synopsis Source IP address prefix as match criterion
Contextconfigure application-assurance group number partition number session-filter named-item entry number match src-ip ip-prefix (ipv4-prefix | ipv6-prefix)
Treeip-prefix

Notes

The following elements are part of a choice: ip-prefix or ip-prefix-list.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

src-port
Synopsis Enter the src-port context
Context configure application-assurance group number partition number session-filter named-item entry number match src-port
Treesrc-port

Description

Commands in this context specify a source IP port, a source port list, or a source range to use as match criteria.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

eq number
Synopsis Match criterion used for destination or source port
Contextconfigure application-assurance group number partition number session-filter named-item entry number match src-port eq number
Treeeq
Range0 | 1 to 65535
Default0

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

gt number
Synopsis Greater than match criterion for the port number
Contextconfigure application-assurance group number partition number session-filter named-item entry number match src-port gt number
Treegt
Range0 | 1 to 65535
Default0

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

lt number
Synopsis Less than match criterion for the port
Contextconfigure application-assurance group number partition number session-filter named-item entry number match src-port lt number
Treelt
Range0 | 1 to 65535
Default0

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

range
Synopsis Enable the range context
Context configure application-assurance group number partition number session-filter named-item entry number match src-port range
Treerange

Description

Commands in this context specify a destination IP port, a destination port list, or a destination range to use as match criteria.

Notes

The following elements are part of a choice: eq, gt, lt, port-list, or range.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

statistics
Synopsis Enter the statistics context
Context configure application-assurance group number partition number statistics
Treestatistics

Description

Commands in this context configure accounting and billing statistics for this AA group.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

aa-admit-deny
Synopsis Enter the aa-admit-deny context
Contextconfigure application-assurance group number partition number statistics aa-admit-deny
Treeaa-admit-deny

Description

Commands in this context configure admit-deny statistics generation.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

aa-app-group
Synopsis Enter the aa-app-group context
Contextconfigure application-assurance group number partition number statistics aa-app-group
Treeaa-app-group

Description

Commands in this context configure the AA application group statistics fields.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

aa-application
Synopsis Enter the aa-application context
Contextconfigure application-assurance group number partition number statistics aa-application
Treeaa-application

Description

Commands in this context configure the application statistics fields.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

aa-partition
Synopsis Enter the aa-partition context
Contextconfigure application-assurance group number partition number statistics aa-partition
Treeaa-partition

Description

Commands in this context configure the AA partition statistics fields.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

aa-protocol
Synopsis Enter the aa-protocol context
Context configure application-assurance group number partition number statistics aa-protocol
Treeaa-protocol

Description

Commands in this context configure the AA protocol statistics fields.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

aa-sub
Synopsis Enter the aa-sub context
Context configure application-assurance group number partition number statistics aa-sub
Treeaa-sub

Description

Commands in this context configure accounting and statistics collection parameters for Application Assurance subscribers.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

app-group [app-group-name] reference
Synopsis Enter the app-group list instance
Contextconfigure application-assurance group number partition number statistics aa-sub app-group reference
Treeapp-group

Description

Commands in this context configure accounting and statistics collection parameters for AA application groups for a specific AA group/partition.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

application [application-name] reference
Synopsis Enter the application list instance
Contextconfigure application-assurance group number partition number statistics aa-sub application reference
Treeapplication

Description

Commands in this context configure the AA subscriber accounting statistics for the export of AA applications for an AA group/partition.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

charging-group [charging-group-name] reference
Synopsis Enter the charging-group list instance
Contextconfigure application-assurance group number partition number statistics aa-sub charging-group reference
Treecharging-group

Description

Commands in this context configure AA subscriber accounting statistics for the export of AA charging groups of an AA group/partition.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[charging-group-name] reference
Synopsis Charging group name
Context configure application-assurance group number partition number statistics aa-sub charging-group reference
Treecharging-group

Description

This command specifies the AA charging group to be included in the exported accounting records. 

Reference

configure application-assurance group number partition number policy charging-group named-item

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

exclude-tcp-retrans boolean
Synopsis Exclude TCP retransmission and error statistics
Contextconfigure application-assurance group number partition number statistics aa-sub exclude-tcp-retrans boolean
Treeexclude-tcp-retrans

Description

When configured to true, TCP errors and retransmission packets are not counted for the purpose of content-based billing. Note: This command is only applicable to EPC.This setting has no impact on app/app-group aggregate AA stats. 

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

protocol [protocol-name] named-item
Synopsis Enter the protocol list instance
Contextconfigure application-assurance group number partition number statistics aa-sub protocol named-item
Treeprotocol

Description

Commands in this context configure AA subscriber accounting statistics for the export of aa-sub protocols of an AA group/partition.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

usage-monitoring boolean
Synopsis Collect usage monitoring statistics
Context configure application-assurance group number partition number statistics aa-sub usage-monitoring boolean
Treeusage-monitoring

Description

When configured to true, this command allows the system to activate Gx usage monitoring at AA group/partition level, if enough usage monitoring resources exist for all existing subs. 

When configured to false, this command silently removes all monitoring instances (no PCRF notifications) for AA subscribers and all subsequent AA Gx usage monitoring messages are ignored.

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

aa-sub-study [study-type] keyword
Synopsis Enter the aa-sub-study list instance
Contextconfigure application-assurance group number partition number statistics aa-sub-study keyword
Treeaa-sub-study

Description

Commands in this context configure accounting and statistics collection parameters per AA special study subscribers.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

aa-sub
Synopsis Enter the aa-sub context
Context configure application-assurance group number partition number statistics aa-sub-study keyword aa-sub
Treeaa-sub

Description

Commands in this context add an existing subscriber identification to a group of special study subscribers.

Identifying a group of special study subscribers allows statistics and accounting records for those subscribers to be collected for protocols and applications through Application Assurance. When adding a subscriber to the special study group, accounting records and statistics generation commence immediately. When removing a subscriber from the group, special study statistics and accounting records for that subscriber in the current interval are lost.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

esm [esm-sub-name] named-item
Synopsis Add a list entry for esm
Context configure application-assurance group number partition number statistics aa-sub-study keyword aa-sub esm named-item
Treeesm

Description

Commands in this context configure the ESM fields.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

esm-mac [esm-mac-sub-name] named-item
Synopsis Add a list entry for esm-mac
Context configure application-assurance group number partition number statistics aa-sub-study keyword aa-sub esm-mac named-item
Treeesm-mac

Description

Commands in this context configure the ESM MAC fields.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

sap [sap-id] sap
Synopsis Add a list entry for sap
Context configure application-assurance group number partition number statistics aa-sub-study keyword aa-sub sap sap
Treesap

Description

Commands in this context configure the Service Access Point (SAP) for the purpose of enabling special study statistics.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

spoke-sdp [sdp-bind-id] sdp-bind-id
Synopsis Add a list entry for spoke-sdp
Contextconfigure application-assurance group number partition number statistics aa-sub-study keyword aa-sub spoke-sdp sdp-bind-id
Treespoke-sdp

Description

Commands in this context specify the spoke SDP ID and VC ID for the purpose of including the subscriber into AA special study statistics. 

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

transit [transit-sub-name] named-item
Synopsis Add a list entry for transit
Context configure application-assurance group number partition number statistics aa-sub-study keyword aa-sub transit named-item
Treetransit

Description

Commands in the context specify an existing transit subscriber to be included in AA sub special study statistics.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

tcp-validate [tcp-validate-name] named-item
Synopsis Enter the tcp-validate list instance
Contextconfigure application-assurance group number partition number tcp-validate named-item
Treetcp-validate

Description

Commands in this context configure a TCP validation policy.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[tcp-validate-name] named-item
Synopsis TCP validation policy name
Context configure application-assurance group number partition number tcp-validate named-item
Treetcp-validate
String length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

log
Synopsis Enter the log context
Context configure application-assurance group number partition number tcp-validate named-item log
Treelog

Description

Commands in this context enable event logging of traffic dropped by TCP validation.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

all boolean
Synopsis Enable logging of all dropped TCP packets
Contextconfigure application-assurance group number partition number tcp-validate named-item log all boolean
Treeall

Description

When configured to true, all dropped TCP packets are logged, including the following:

  • packets received after an RST and discarded

  • packets received before TCP session establishment (before SYN) and discarded

An event log must also be configured to enable logging of all dropped packets.

When configured to false, discards related to the described cases are not captured in any event log.

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

strict boolean
Synopsis Enable strict checking of TCP traffic
Contextconfigure application-assurance group number partition number tcp-validate named-item strict boolean
Treestrict

Description

When configured to true, the command specifies whether enforcement of TCP sequence and acknowledgment numbers are applied. If a packet does not meet the expected sequence or acknowledgment number, it is dropped. This command should only be enabled if the expected bit error rate or packet loss is low. 

For example, if acknowledgments are lost before being detected by AA, the server timeouts are triggered and retransmissions occur. If strict is enabled, these retransmissions resemble a reply attack and are dropped by AA.

When configured to false, the command removes the TCP sequence and acknowledgment number enforcement.

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

tethering-detection
Synopsis Enter the tethering-detection context
Contextconfigure application-assurance group number partition number tethering-detection
Treetethering-detection

Description

Commands in this context configure tethering detection for the group.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

single-device
Synopsis Enter the single-device context
Contextconfigure application-assurance group number partition number tethering-detection single-device
Treesingle-device

Description

Commands in this context configure the single-device fields and expected TTL values for flow-level tethering detection.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

expected-ttl [ttl] number
Synopsis Add a list entry for expected-ttl
Contextconfigure application-assurance group number partition number tethering-detection single-device expected-ttl number
Treeexpected-ttl

Description

Commands in this context configure the TTL values for single-device tethering detection.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

invert-match boolean
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisMark flows with expected TTL values as tethered
Contextconfigure application-assurance group number partition number tethering-detection single-device invert-match boolean
Treeinvert-match

Description

When configured to true, AA classifies flows with expected TTL values as coming from a connected device (tethered).

When configured to false, AA classifies flows with expected TTL values as coming from the host device (untethered).

Defaultfalse
Introduced23.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ttl-monitor
Synopsis Enter the ttl-monitor context
Context configure application-assurance group number partition number tethering-detection ttl-monitor
Treettl-monitor

Description

Commands in this context configure the scope of analysis for TCP and UDP traffic for tethering detection.

Introduced23.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

tcp-protocols keyword
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisScope of analysis for TCP traffic
Contextconfigure application-assurance group number partition number tethering-detection ttl-monitor tcp-protocols keyword
Treetcp-protocols

Description

This command configures whether AA analyzes all TCP traffic or only traffic from standard applications that generate consistent TTL values. Configuring AA to analyze all TCP traffic is typically recommended.

Options

standard – Protocols with reliable TTL-tethering state association

all – All protocols

Default standard
Introduced23.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

udp-protocols keyword
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisScope of analysis for UDP traffic
Contextconfigure application-assurance group number partition number tethering-detection ttl-monitor udp-protocols keyword
Treeudp-protocols

Description

This command configures whether AA analyzes all UDP traffic or only traffic from standard applications that generate consistent TTL values. Configuring AA to analyze only standard UDP traffic is recommended.

Options

standard – Protocols with reliable TTL-tethering state association

all – All protocols

Default standard
Introduced23.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

threshold-crossing-alert
Synopsis Enter the threshold-crossing-alert context
Contextconfigure application-assurance group number partition number threshold-crossing-alert
Treethreshold-crossing-alert

Description

Commands in this context configure the generation of threshold crossing alerts (TCAs).

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

criteria [criteria-id] keyword direction keyword
Synopsis Enter the criteria list instance
Contextconfigure application-assurance group number partition number threshold-crossing-alert criteria keyword direction keyword
Treecriteria

Description

Commands in this context configure the TCA criteria for the partition.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

gtp-filter [gtp-filter-name] reference criteria keyword direction keyword
Synopsis Enter the gtp-filter list instance
Contextconfigure application-assurance group number partition number threshold-crossing-alert gtp-filter reference criteria keyword direction keyword
Treegtp-filter

Description

Commands in this context configure TCA generation for a GTP filter.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

criteria keyword
Synopsis Criteria ID for GTP filter TCA
Context configure application-assurance group number partition number threshold-crossing-alert gtp-filter reference criteria keyword direction keyword
Treegtp-filter
Optionsmax-payload-length, message-type-default-action, header-sanity, message-type-gtpv2-default-action, imsi-apn-filter-default-action, validate-gtp-tunnels, validate-sequence-number, validate-src-ip-addr, missing-mandatory-ie, gtp-in-gtp, gtp-tunnel-database-full, gtp-tunnel-endpoint-limit

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

gtp-filter-entry [gtp-filter-name] reference entry-id number direction keyword
Synopsis Enter the gtp-filter-entry list instance
Contextconfigure application-assurance group number partition number threshold-crossing-alert gtp-filter-entry reference entry-id number direction keyword
Treegtp-filter-entry

Description

Commands in this context configure the AA GTP filter entry TCA fields.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

entry-id number
Synopsis Entry ID
Contextconfigure application-assurance group number partition number threshold-crossing-alert gtp-filter-entry reference entry-id number direction keyword
Treegtp-filter-entry

Description

This command configures the identifier for the statistics TCA GTP filter V1 message type entry, V2 message type entry, or imsi-apn filter entry.

Max. range0 to 4294967295

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

policer [policer-name] named-item direction keyword
Synopsis Enter the policer list instance
Contextconfigure application-assurance group number partition number threshold-crossing-alert policer named-item direction keyword
Treepolicer

Description

Commands in this context configure a TCA for the counter capturing drops or admit events.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

sctp-filter [sctp-filter-name] reference criteria keyword direction keyword
Synopsis Enter the sctp-filter list instance
Contextconfigure application-assurance group number partition number threshold-crossing-alert sctp-filter reference criteria keyword direction keyword
Treesctp-filter

Description

Commands in this context configure TCA generation for an SCTP filter.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

sctp-filter-entry [sctp-filter-name] reference entry-id reference direction keyword
Synopsis Enter the sctp-filter-entry list instance
Contextconfigure application-assurance group number partition number threshold-crossing-alert sctp-filter-entry reference entry-id reference direction keyword
Treesctp-filter-entry

Description

Commands in this context configure the AA SCTP filter PPID entry TCA fields.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

session-filter [session-filter-name] reference criteria keyword direction keyword
Synopsis Enter the session-filter list instance
Contextconfigure application-assurance group number partition number threshold-crossing-alert session-filter reference criteria keyword direction keyword
Treesession-filter

Description

Commands in this context configure TCA generation for a session filter.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

session-filter-entry [session-filter-name] reference entry-id reference direction keyword
Synopsis Enter the session-filter-entry list instance
Contextconfigure application-assurance group number partition number threshold-crossing-alert session-filter-entry reference entry-id reference direction keyword
Treesession-filter-entry

Description

Commands in this context configure the AA session filter entry TCA fields for the partition.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

tcp-validate [tcp-validate-name] reference direction keyword
Synopsis Enter the tcp-validate list instance
Contextconfigure application-assurance group number partition number threshold-crossing-alert tcp-validate reference direction keyword
Treetcp-validate

Description

Commands in this context configure TCP validation policy TCA fields for the partition.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

transit-ip-policy [ip-policy-id] number
Synopsis Enter the transit-ip-policy list instance
Contextconfigure application-assurance group number partition number transit-ip-policy number
Treetransit-ip-policy

Description

Commands in this context define a transit AA subscriber IP policy. Transit AA subscribers are managed by the system through the use of this policy assigned to services, which determines how transit subs are created and removed for that service.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dhcp
Synopsis Enter the dhcp context
Context configure application-assurance group number partition number transit-ip-policy number dhcp
Treedhcp

Description

Commands in this context enable dynamic DHCP-based management of transit aa-subs for the transit IP policy. Dynamic DHCP-based management and other types of management of transit subs for a transit IP policy are mutually exclusive.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

diameter
Synopsis Enter the diameter context
Context configure application-assurance group number partition number transit-ip-policy number diameter
Treediameter

Description

Commands in this context configure dynamic Diameter-based management of transit AA subs for the transit IP policy. This is mutually exclusive to other types of management of transit subs for a given transit IP policy.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

radius
Synopsis Enter the radius context
Context configure application-assurance group number partition number transit-ip-policy number radius
Treeradius

Description

Commands in this context enable dynamic RADIUS-based management of transit aa-subs for the transit IP policy. This is mutually exclusive to other types of management of transit subs for a given transit IP policy.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

static-aa-sub [transit-aa-sub-name] named-item
Synopsis Enter the static-aa-sub list instance
Contextconfigure application-assurance group number partition number transit-ip-policy number static-aa-sub named-item
Treestatic-aa-sub
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip [address] (ipv4-unicast-address | ipv6-prefix)
Synopsis Add a list entry for ip
Context configure application-assurance group number partition number transit-ip-policy number static-aa-sub named-item ip (ipv4-unicast-address | ipv6-prefix)
Treeip

Description

Commands in this context configure the IP address for a static transit aa-sub.

Max. instances32
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[address] (ipv4-unicast-address | ipv6-prefix)
Synopsis IP address for an AA static transit subscriber
Contextconfigure application-assurance group number partition number transit-ip-policy number static-aa-sub named-item ip (ipv4-unicast-address | ipv6-prefix)
Treeip

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

sub-ident-policy reference
Synopsis Subscriber identification policy
Context configure application-assurance group number partition number transit-ip-policy number sub-ident-policy reference
Treesub-ident-policy

Description

This command defines the subscriber identification policy for the transit IP policy that will be associated with a SAP. The subscriber identification policy must be defined prior to associating the profile with a SAP in the configure subscriber-mgmt sub-ident-policy context. Subscribers are managed by the system through the use of subscriber identification strings. A subscriber identification string uniquely identifies a subscriber. For static hosts, the subscriber identification string is explicitly defined with each static subscriber host.

For dynamic hosts, the subscriber identification string must be derived from the DHCP ACK message sent to the subscriber host. The default value for the string is the content of Option 82 CIRCUIT-ID and REMOTE-ID fields interpreted as an octet string. As an option, the DHCP ACK message may be processed by a subscriber identification policy which has the capability to parse the message into an alternative ASCII or octet string value.

When multiple hosts on the same port are associated with the same subscriber identification string, they are considered to be host members of the same subscriber. A subscriber identification policy can also be used for identifying dynamic transit subscriber names.

Reference

configure subscriber-mgmt sub-ident-policy external-named-item

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

transit-auto-create
Synopsis Enter the transit-auto-create context
Contextconfigure application-assurance group number partition number transit-ip-policy number transit-auto-create
Treetransit-auto-create

Description

Commands in this context enable the seen-IP auto creation of transit subscribers using the transit IP policy name and subscriber IP address as the aa-sub name. The default app-profile configured against the transit IP policy is applied to these subscribers.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

inactivity-monitor boolean
Synopsis Monitor inactivity on auto-created transit subscribers
Contextconfigure application-assurance group number partition number transit-ip-policy number transit-auto-create inactivity-monitor boolean
Treeinactivity-monitor

Description

When configured to true, this command enables the auto-removal of inactive transit subscribers. Periodically, AA removes any inactive auto-created subscribers. An inactive subscriber is defined as having no active flows in the last period. 

When configured to false, this command disables the auto-removal of inactive transit subscribers. 

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

transit-prefix-policy [prefix-policy-id] number
Synopsis Enter the transit-prefix-policy list instance
Contextconfigure application-assurance group number partition number transit-prefix-policy number
Treetransit-prefix-policy

Description

Commands in this context define a transit AA subscriber prefix policy. Transit AA subscribers are managed by the system through the use of this policy assigned to services, which determines how transit subscribers are created and removed for that service.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure application-assurance group number partition number transit-prefix-policy number entry number
Treeentry

Description

Commands in this context configure the index to a specific entry of a transit prefix policy.

Max. instances4095
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

match
Synopsis Enter the match context
Context configure application-assurance group number partition number transit-prefix-policy number entry number match
Treematch

Description

Commands in this context configure transit prefix policy entry match criteria.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

aa-sub-ip (ipv4-prefix | ipv6-prefix)
Synopsis AA subscriber IP address prefix
Context configure application-assurance group number partition number transit-prefix-policy number entry number match aa-sub-ip (ipv4-prefix | ipv6-prefix)
Treeaa-sub-ip

Description

This command configures a transit prefix subscriber IP address prefix. It is used when the site is on the local side, the same side of the system as the parent SAP. The local aa-sub-ip addresses represent the source IP in the from-SAP direction and destination IP in the to-SAP direction.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

static-aa-sub [transit-aa-sub-name] named-item
Synopsis Enter the static-aa-sub list instance
Contextconfigure application-assurance group number partition number transit-prefix-policy number static-aa-sub named-item
Treestatic-aa-sub
Max. instances4095
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

wap1x
Synopsis Enter the wap1x context
Context configure application-assurance group number partition number wap1x
Treewap1x

Description

Commands in this context configure the Wireless Application Protocol (WAP) 1.X.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

policer
Synopsis Enter the policer context
Context configure application-assurance group number policer
Treepolicer

Description

Commands in this context create application assurance policer profiles of a specified type. Policers can be bandwidth or flow-limiting and can have a granularity of system scope (limits traffic entering AA ISA for all or a subset of AA subscribers) or a subscriber scope (limits apply to each AA subscriber traffic).

The policer type and granularity can only be configured during creation. They cannot be modified. The policer profile must be removed from all AQPs to be removed. Changes to policer profile parameters take effect immediately for policers instantiated as a result of AQP actions using this profile.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

anl-bandwidth-policer [policer-name] named-item
Synopsis Enter the anl-bandwidth-policer list instance
Contextconfigure application-assurance group number policer anl-bandwidth-policer named-item
Treeanl-bandwidth-policer

Description

Commands in this context configure the AA ANL policer.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

action keyword
Synopsis Action for packets violating configured policer rate
Contextconfigure application-assurance group number policer anl-bandwidth-policer named-item action keyword
Treeaction

Description

This command configures the action to be performed by single-bucket bandwidth policers for non-conformant traffic.

Dual bucket bandwidth policers cannot have their action configured and always mark traffic below CIR as in-profile, between CIR and PIR as out-of-profile, and drop traffic above PIR. Flow policers always discard non-conformant traffic.

When multiple application assurance policers are configured against a single flow (including policers at both subscriber and system), the flow/packet is dropped if one of the policers requires the packet to be discarded. This occurs regardless of the action of the other policers.

Optionspermit-deny, priority-mark, monitor
Defaultpermit-deny
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure application-assurance group number policer anl-bandwidth-policer named-item adaptation-rule
Treeadaptation-rule

Description

Commands in this context configure the AA policer adaptation rule fields and define the method used by the system to derive the operational CIR and PIR values when the queue is provisioned. For the CIR and PIR values individually, the system attempts to find the best operational rate depending on the defined option. To change the CIR adaptation rule only, the current PIR rule must be part of the command executed.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

pir keyword
Synopsis Peak information rate value for the adaptation rule
Contextconfigure application-assurance group number policer anl-bandwidth-policer named-item adaptation-rule pir keyword
Treepir

Description

This command configures the adaptation rule to be used while computing the operational PIR value. The adaptation rule specifies the rules to compute the operational values while maintaining minimum offset.

Optionsmax, min, closest
Defaultclosest
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mbs number
Synopsis ANL bandwidth policer maximum burst size
Contextconfigure application-assurance group number policer anl-bandwidth-policer named-item mbs number
Treembs

Description

This command configures the maximum burst size (MBS) for the policer. Nokia recommends configuring MBS larger than twice the MTU for the traffic handled by the policer to allow for some burstiness of the traffic. MBS is configurable for single-bucket, dual-bucket bandwidth, and flow setup rate policers only.

Range0 to 131071
Unitskilobytes
Default 0
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

rate-percentage number
Synopsis Rate used by Access-Network-Location policers
Contextconfigure application-assurance group number policer anl-bandwidth-policer named-item rate-percentage number
Treerate-percentage

Description

This command configures the stage 1 congestion percentage used by Access-Network-Location (ANL) policers. Because ANL total bandwidth is dynamically measured and estimated by AA, this command allows the operator to configure the ratio of that measured bandwidth to be used by the ANL policer as the policer rate.

No limiting is performed if not specified.

Range0 to 200
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

rate-percentage-stage-2 number
Synopsis Rate used by Access-Network-Location policers
Contextconfigure application-assurance group number policer anl-bandwidth-policer named-item rate-percentage-stage-2 number
Treerate-percentage-stage-2

Description

This command configures the stage 2 congestion percentage rate used by Access-Network-Location (ANL) policers. Because ANL stage2 total bandwidth is dynamically measured and estimated by AA, this command allows the operator to configure the ratio of that measured bandwidth to be used by the ANL stage2 policer as the policer rate.

When unconfigured, limiting is not performed.

Range0 to 200
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dual-bucket-bandwidth-policer [policer-name] named-item
Synopsis Enter the dual-bucket-bandwidth-policer list instance
Contextconfigure application-assurance group number policer dual-bucket-bandwidth-policer named-item
Treedual-bucket-bandwidth-policer

Description

Commands in this context configure the dual-bucket bandwidth policer.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure application-assurance group number policer dual-bucket-bandwidth-policer named-item adaptation-rule
Treeadaptation-rule

Description

Commands in this context configure the AA policer adaptation rule fields and define the method used by the system to derive the operational CIR and PIR values when the queue is provisioned. For the CIR and PIR values individually, the system attempts to find the best operational rate depending on the defined option. To change the CIR adaptation rule only, the current PIR rule must be part of the command executed.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

cir keyword
Synopsis Committed information rate value for adaptation rule
Contextconfigure application-assurance group number policer dual-bucket-bandwidth-policer named-item adaptation-rule cir keyword
Treecir

Description

This command configures the CIR for the dual-bucket-bandwidth-policer adaptation rule policer. Nokia recommends configuring CIR larger than twice the maximum MTU for the traffic handled by the policer to allow for some burstiness of the traffic. The CIR is configurable for dual-bucket bandwidth policers only.

Optionsmax, min, closest
Defaultclosest
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

pir keyword
Synopsis Peak information rate value for the adaptation rule
Contextconfigure application-assurance group number policer dual-bucket-bandwidth-policer named-item adaptation-rule pir keyword
Treepir

Description

This command configures the adaptation rule to be used while computing the operational PIR value. The adaptation rule specifies the rules to compute the operational values while maintaining minimum offset.

Optionsmax, min, closest
Defaultclosest
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

cbs number
Synopsis Committed burst size when in congested state
Contextconfigure application-assurance group number policer dual-bucket-bandwidth-policer named-item cbs number
Treecbs

Description

This command configures the committed burst size (CBS) for a policer. Nokia recommends that CBS is configured larger than twice the maximum MTU for the traffic handled by the policer to allow for some burstiness of the traffic. CBS is configurable for dual-bucket bandwidth policers only.

Range0 to 131071
Unitskilobytes
Default 0
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

cir (number | keyword)
Synopsis Committed information rate value for the policer
Contextconfigure application-assurance group number policer dual-bucket-bandwidth-policer named-item cir (number | keyword)
Treecir

Description

This command configures the CIR for the dual-bucket-bandwidth-policer policer. Nokia recommends that the CIR is configured larger than twice the maximum MTU for the traffic handled by the policer to allow for some burstiness of the traffic. The CIR is configurable for dual-bucket bandwidth policers only.

Range0 to 100000000
Unitskilobps
Options max
Default 0
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

congestion-override
Synopsis Enter the congestion-override context
Contextconfigure application-assurance group number policer dual-bucket-bandwidth-policer named-item congestion-override
Treecongestion-override

Description

Commands in this context configure the congestion bandwidth policer override rates.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

cbs number
Synopsis Committed burst size in a congested stage 2 state
Contextconfigure application-assurance group number policer dual-bucket-bandwidth-policer named-item congestion-override cbs number
Treecbs

Description

This command configures the committed burst size for a policer. The configured CBS should be larger than twice the maximum MTU for the traffic handled by the policer to allow for some burstiness of the traffic. CBS is configurable for dual-bucket bandwidth policers only.

Range0 to 131071
Unitskilobytes
Default 0
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

cir (number | keyword)
Synopsis Committed information rate value for policer override
Contextconfigure application-assurance group number policer dual-bucket-bandwidth-policer named-item congestion-override cir (number | keyword)
Treecir

Description

This command configures the CIR for the dual-bucket bandwidth policer congestion override. Nokia recommends that the CIR is configured larger than twice the maximum MTU for the traffic handled by the policer to allow for some burstiness of the traffic. The CIR is configurable for dual-bucket bandwidth policers only.

Range0 to 100000000
Unitskilobps
Options max
Default 0
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mbs number
Synopsis Maximum burst size when in a congested state
Contextconfigure application-assurance group number policer dual-bucket-bandwidth-policer named-item congestion-override mbs number
Treembs

Description

This command configures the maximum burst size (MBS) for the policer. Nokia recommends configuring MBS larger than twice the MTU for the traffic handled by the policer to allow for some burstiness of the traffic. MBS is configurable for single-bucket, dual-bucket bandwidth, and flow setup rate policers only.

Range0 to 131071
Unitskilobytes
Default 0
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

congestion-override-stage-2
Synopsis Enter the congestion-override-stage-2 context
Contextconfigure application-assurance group number policer dual-bucket-bandwidth-policer named-item congestion-override-stage-2
Treecongestion-override-stage-2

Description

This command enables the context to configure per-subscriber stage 2 congestion bandwidth policer override rates.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

cbs number
Synopsis Committed burst size in a congested stage 2 state
Contextconfigure application-assurance group number policer dual-bucket-bandwidth-policer named-item congestion-override-stage-2 cbs number
Treecbs

Description

This command configures the committed burst size for a policer. The configured CBS should be larger than twice the maximum MTU for the traffic handled by the policer to allow for some burstiness of the traffic. CBS is configurable for dual-bucket bandwidth policers only.

Range0 to 131071
Unitskilobytes
Default 0
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

cir (number | keyword)
Synopsis Committed information rate value for policer override
Contextconfigure application-assurance group number policer dual-bucket-bandwidth-policer named-item congestion-override-stage-2 cir (number | keyword)
Treecir

Description

This command configures the CIR for the dual-bucket bandwidth policer congestion override. Nokia recommends that the CIR is configured larger than twice the maximum MTU for the traffic handled by the policer to allow for some burstiness of the traffic. The CIR is configurable for dual-bucket bandwidth policers only.

Range0 to 100000000
Unitskilobps
Options max
Default 0
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mbs number
Synopsis Maximum burst size when in a congested state
Contextconfigure application-assurance group number policer dual-bucket-bandwidth-policer named-item congestion-override-stage-2 mbs number
Treembs

Description

This command configures the maximum burst size (MBS) for the policer. Nokia recommends configuring MBS larger than twice the MTU for the traffic handled by the policer to allow for some burstiness of the traffic. MBS is configurable for single-bucket, dual-bucket bandwidth, and flow setup rate policers only.

Range0 to 131071
Unitskilobytes
Default 0
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mbs number
Synopsis Bandwidth policer maximum burst size
Context configure application-assurance group number policer dual-bucket-bandwidth-policer named-item mbs number
Treembs

Description

This command configures the maximum burst size (MBS) for the policer. Nokia recommends configuring MBS larger than twice the MTU for the traffic handled by the policer to allow for some burstiness of the traffic. MBS is configurable for single-bucket, dual-bucket bandwidth, and flow setup rate policers only.

Range0 to 131071
Unitskilobytes
Default 0
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

pir (number | keyword)
Synopsis Peak information rate value for the bandwidth policer
Contextconfigure application-assurance group number policer dual-bucket-bandwidth-policer named-item pir (number | keyword)
Treepir
Range1 to 100000000
Unitskilobps
Options max
Default max
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

time-of-day-override [tod-override-id] number
Synopsis Enter the time-of-day-override list instance
Contextconfigure application-assurance group number policer dual-bucket-bandwidth-policer named-item time-of-day-override number
Treetime-of-day-override

Description

Commands in this context configure the time of day override policy for a given policer. Rate/mbs/cbs/flow-rate/flow-count configured in each override-id will override the default policer values at the specified time of day configured in the override.

Max. instances8
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

cbs number
Synopsis Committed burst size for time of day override policer
Contextconfigure application-assurance group number policer dual-bucket-bandwidth-policer named-item time-of-day-override number cbs number
Treecbs

Description

This command configures the committed burst size (CBS) for a policer. Nokia recommends configuring CBS larger than twice the maximum MTU for the traffic handled by the policer to allow for some burstiness of the traffic. CBS is configurable for dual-bucket bandwidth policers only.

Range0 to 131071
Unitskilobytes
Default 0
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

cir (number | keyword)
Synopsis Committed information rate for time of day override
Contextconfigure application-assurance group number policer dual-bucket-bandwidth-policer named-item time-of-day-override number cir (number | keyword)
Treecir

Description

This command configures the committed information rate (CIR) for the dual-bucket-bandwidth-policer policer time of day override. Nokia recommends that the CIR is configured larger than twice the maximum MTU for the traffic handled by the policer to allow for some burstiness of the traffic. The CIR is configurable for dual-bucket bandwidth policers only.

Range0 to 100000000
Unitskilobps
Options max
Default 0
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mbs number
Synopsis Maximum burst size for the policer time of day override
Contextconfigure application-assurance group number policer dual-bucket-bandwidth-policer named-item time-of-day-override number mbs number
Treembs

Description

This command configures the maximum burst size (MBS) for the policer. Nokia recommends that MBS is configured larger than twice the MTU for the traffic handled by the policer to allow for some burstiness of the traffic. MBS is configurable for single-bucket, dual-bucket bandwidth, and flow setup rate policers only.

Range0 to 131071
Unitskilobytes
Default 0
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

time-range
Synopsis Enter the time-range context
Context configure application-assurance group number policer dual-bucket-bandwidth-policer named-item time-of-day-override number time-range
Treetime-range

Description

Commands in this context configure the days of the week policer override is enabled as well as the time policer override starts and ends. When using a daily override the operator can select which days during the week from Sunday to Saturday it is applicable along with the start/end hour/min time range repeated over these days.When using a weekly override the operator can select between which days in the week the policy start up to the hours/min for both start day and end day.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

daily
Synopsis Enable the daily context
Context configure application-assurance group number policer dual-bucket-bandwidth-policer named-item time-of-day-override number time-range daily
Treedaily

Description

Commands in this context configure the daily start and end times for policer override.

Notes

The following elements are part of a choice: daily or weekly.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

end policer-end-time
Synopsis Daily end time
Contextconfigure application-assurance group number policer dual-bucket-bandwidth-policer named-item time-of-day-override number time-range daily end policer-end-time
Treeend

Description

This command configures the daily end time of the policer override.

The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.

String length3 to 5

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

start policer-start-time
Synopsis Daily start time
Context configure application-assurance group number policer dual-bucket-bandwidth-policer named-item time-of-day-override number time-range daily start policer-start-time
Treestart

Description

This command configures the daily start time of the policer override.

The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.

String length3 to 5

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

weekly
Synopsis Enable the weekly context
Context configure application-assurance group number policer dual-bucket-bandwidth-policer named-item time-of-day-override number time-range weekly
Treeweekly

Description

Commands in this context configure the weekly start and end times for policer override.

Notes

The following elements are part of a choice: daily or weekly.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

end
Synopsis Enable the end context
Context configure application-assurance group number policer dual-bucket-bandwidth-policer named-item time-of-day-override number time-range weekly end
Treeend

Description

Commands in this context configure the weekly end time for policer override.When using a weekly override, the operator can select between which days in the week the policy ends up to the hours or minutes for both start of the day and end of the day.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

time policer-end-time
Synopsis Weekly end time
Context configure application-assurance group number policer dual-bucket-bandwidth-policer named-item time-of-day-override number time-range weekly end time policer-end-time
Treetime

Description

This command configures the weekly end time of the policer override.

The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.

String length3 to 5

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

start
Synopsis Enable the start context
Context configure application-assurance group number policer dual-bucket-bandwidth-policer named-item time-of-day-override number time-range weekly start
Treestart

Description

Commands in this context configure the weekly start time for policer override.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

time policer-start-time
Synopsis Weekly start time
Context configure application-assurance group number policer dual-bucket-bandwidth-policer named-item time-of-day-override number time-range weekly start time policer-start-time
Treetime

Description

This command configures the weekly start time of the policer override.

The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.

String length3 to 5

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

flow-bandwidth-policer [policer-name] named-item
Synopsis Enter the flow-bandwidth-policer list instance
Contextconfigure application-assurance group number policer flow-bandwidth-policer named-item
Treeflow-bandwidth-policer
Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

action keyword
Synopsis Action for packets violating configured policer rate
Contextconfigure application-assurance group number policer flow-bandwidth-policer named-item action keyword
Treeaction

Description

This command configures the action to be performed by single-bucket bandwidth policers for non-conformant traffic.

Dual bucket bandwidth policers cannot have their action configured and always mark traffic below CIR as in-profile, between CIR and PIR as out-of-profile, and drop traffic above PIR. Flow policers always discard non-conformant traffic.

When multiple application assurance policers are configured against a single flow (including policers at both subscriber and system), the flow/packet is dropped if one of the policers requires the packet to be discarded. This occurs regardless of the action of the other policers.

Optionspermit-deny, priority-mark, monitor
Defaultpermit-deny
Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure application-assurance group number policer flow-bandwidth-policer named-item adaptation-rule
Treeadaptation-rule
Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

pir keyword
Synopsis Peak information rate value for the adaptation rule
Contextconfigure application-assurance group number policer flow-bandwidth-policer named-item adaptation-rule pir keyword
Treepir

Description

This command configures the adaptation rule to be used while computing the operational PIR value. The adaptation rule specifies the rules to compute the operational values while maintaining minimum offset.

Optionsmax, min, closest
Defaultclosest
Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

congestion-override
Synopsis Enter the congestion-override context
Contextconfigure application-assurance group number policer flow-bandwidth-policer named-item congestion-override
Treecongestion-override
Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mbs number
Synopsis Maximum burst size when in a congested state
Contextconfigure application-assurance group number policer flow-bandwidth-policer named-item congestion-override mbs number
Treembs

Description

This command configures the maximum burst size (MBS) for the policer. Nokia recommends configuring MBS larger than twice the MTU for the traffic handled by the policer to allow for some burstiness of the traffic. MBS is configurable for single-bucket, dual-bucket bandwidth, and flow setup rate policers only.

Range0 to 131071
Unitskilobytes
Default 0
Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

congestion-override-stage-2
Synopsis Enter the congestion-override-stage-2 context
Contextconfigure application-assurance group number policer flow-bandwidth-policer named-item congestion-override-stage-2
Treecongestion-override-stage-2
Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mbs number
Synopsis Maximum burst size when in a congested state
Contextconfigure application-assurance group number policer flow-bandwidth-policer named-item congestion-override-stage-2 mbs number
Treembs

Description

This command configures the maximum burst size (MBS) for the policer. Nokia recommends configuring MBS larger than twice the MTU for the traffic handled by the policer to allow for some burstiness of the traffic. MBS is configurable for single-bucket, dual-bucket bandwidth, and flow setup rate policers only.

Range0 to 131071
Unitskilobytes
Default 0
Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mbs number
Synopsis Bandwidth policer maximum burst size
Context configure application-assurance group number policer flow-bandwidth-policer named-item mbs number
Treembs

Description

This command configures the maximum burst size (MBS) for the policer. Nokia recommends configuring MBS larger than twice the MTU for the traffic handled by the policer to allow for some burstiness of the traffic. MBS is configurable for single-bucket, dual-bucket bandwidth, and flow setup rate policers only.

Range0 to 131071
Unitskilobytes
Default 0
Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

pir (number | keyword)
Synopsis Peak information rate value for the bandwidth policer
Contextconfigure application-assurance group number policer flow-bandwidth-policer named-item pir (number | keyword)
Treepir
Range1 to 100000000
Unitskilobps
Options max
Default max
Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

time-of-day-override [tod-override-id] number
Synopsis Enter the time-of-day-override list instance
Contextconfigure application-assurance group number policer flow-bandwidth-policer named-item time-of-day-override number
Treetime-of-day-override
Max. instances8
Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mbs number
Synopsis Bandwidth policer MBS for time of day override
Contextconfigure application-assurance group number policer flow-bandwidth-policer named-item time-of-day-override number mbs number
Treembs

Description

This command configures the maximum burst size (MBS) for the policer. Nokia recommends configuring MBS larger than twice the MTU for the traffic handled by the policer to allow for some burstiness of the traffic. MBS is configurable for single-bucket, dual-bucket bandwidth, and flow setup rate policers only.

Range0 to 131071
Unitskilobytes
Default 0
Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

time-range
Synopsis Enter the time-range context
Context configure application-assurance group number policer flow-bandwidth-policer named-item time-of-day-override number time-range
Treetime-range

Description

Commands in this context configure the days of the week policer override is enabled as well as the time policer override starts and ends. When using a daily override the operator can select which days during the week from Sunday to Saturday it is applicable along with the start/end hour/min time range repeated over these days.When using a weekly override the operator can select between which days in the week the policy start up to the hours/min for both start day and end day.

Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

daily
Synopsis Enable the daily context
Context configure application-assurance group number policer flow-bandwidth-policer named-item time-of-day-override number time-range daily
Treedaily

Description

Commands in this context configure the daily start and end times for policer override.

Notes

The following elements are part of a choice: daily or weekly.

Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

end policer-end-time
Synopsis Daily end time
Contextconfigure application-assurance group number policer flow-bandwidth-policer named-item time-of-day-override number time-range daily end policer-end-time
Treeend

Description

This command configures the daily end time of the policer override.

The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.

String length3 to 5

Notes

This element is mandatory.

Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

start policer-start-time
Synopsis Daily start time
Context configure application-assurance group number policer flow-bandwidth-policer named-item time-of-day-override number time-range daily start policer-start-time
Treestart

Description

This command configures the daily start time of the policer override.

The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.

String length3 to 5

Notes

This element is mandatory.

Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

weekly
Synopsis Enable the weekly context
Context configure application-assurance group number policer flow-bandwidth-policer named-item time-of-day-override number time-range weekly
Treeweekly

Description

Commands in this context configure the weekly start and end times for policer override.

Notes

The following elements are part of a choice: daily or weekly.

Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

end
Synopsis Enable the end context
Context configure application-assurance group number policer flow-bandwidth-policer named-item time-of-day-override number time-range weekly end
Treeend

Description

Commands in this context configure the weekly end time for policer override.When using a weekly override, the operator can select between which days in the week the policy ends up to the hours or minutes for both start of the day and end of the day.

Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

time policer-end-time
Synopsis Weekly end time
Context configure application-assurance group number policer flow-bandwidth-policer named-item time-of-day-override number time-range weekly end time policer-end-time
Treetime

Description

This command configures the weekly end time of the policer override.

The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.

String length3 to 5

Notes

This element is mandatory.

Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

start
Synopsis Enable the start context
Context configure application-assurance group number policer flow-bandwidth-policer named-item time-of-day-override number time-range weekly start
Treestart

Description

Commands in this context configure the weekly start time for policer override.

Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

time policer-start-time
Synopsis Weekly start time
Context configure application-assurance group number policer flow-bandwidth-policer named-item time-of-day-override number time-range weekly start time policer-start-time
Treetime

Description

This command configures the weekly start time of the policer override.

The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.

String length3 to 5

Notes

This element is mandatory.

Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

flow-count-limit-policer [policer-name] named-item
Synopsis Enter the flow-count-limit-policer list instance
Contextconfigure application-assurance group number policer flow-count-limit-policer named-item
Treeflow-count-limit-policer

Description

Commands in this context configure the AA flow count limit policer.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

action keyword
Synopsis Action for packets violating configured policer rate
Contextconfigure application-assurance group number policer flow-count-limit-policer named-item action keyword
Treeaction

Description

This command configures the action to be performed by single-bucket bandwidth policers for non-conformant traffic.

Dual bucket bandwidth policers cannot have their action configured and always mark traffic below CIR as in-profile, between CIR and PIR as out-of-profile, and drop traffic above PIR. Flow policers always discard non-conformant traffic.

When multiple application assurance policers are configured against a single flow (including policers at both subscriber and system), the flow/packet is dropped if one of the policers requires the packet to be discarded. This occurs regardless of the action of the other policers.

Optionspermit-deny, priority-mark, monitor
Defaultpermit-deny
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

granularity keyword
Warning:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPolicer granularity
Contextconfigure application-assurance group number policer flow-count-limit-policer named-item granularity keyword
Treegranularity
Optionssystem, subscriber

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

time-of-day-override [tod-override-id] number
Synopsis Enter the time-of-day-override list instance
Contextconfigure application-assurance group number policer flow-count-limit-policer named-item time-of-day-override number
Treetime-of-day-override

Description

Commands in this context configure the time of day override policy for a specific policer. Rate/mbs/cbs/flow-rate/flow-count configured in each override ID overrides the default policer values at the specified time of day configured in the override.

Max. instances8
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

time-range
Synopsis Enter the time-range context
Context configure application-assurance group number policer flow-count-limit-policer named-item time-of-day-override number time-range
Treetime-range

Description

Commands in this context configure the days of the week policer override is enabled as well as the time policer override starts and ends. When using a daily override the operator can select which days during the week from Sunday to Saturday it is applicable along with the start/end hour/min time range repeated over these days.When using a weekly override the operator can select between which days in the week the policy start up to the hours/min for both start day and end day.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

daily
Synopsis Enable the daily context
Context configure application-assurance group number policer flow-count-limit-policer named-item time-of-day-override number time-range daily
Treedaily

Description

Commands in this context configure the daily start and end times for policer override.

Notes

The following elements are part of a choice: daily or weekly.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

end policer-end-time
Synopsis Daily end time
Contextconfigure application-assurance group number policer flow-count-limit-policer named-item time-of-day-override number time-range daily end policer-end-time
Treeend

Description

This command configures the daily end time of the policer override.

The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.

String length3 to 5

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

start policer-start-time
Synopsis Daily start time
Context configure application-assurance group number policer flow-count-limit-policer named-item time-of-day-override number time-range daily start policer-start-time
Treestart

Description

This command configures the daily start time of the policer override.

The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.

String length3 to 5

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

weekly
Synopsis Enable the weekly context
Context configure application-assurance group number policer flow-count-limit-policer named-item time-of-day-override number time-range weekly
Treeweekly

Description

Commands in this context configure the weekly start and end times for policer override.

Notes

The following elements are part of a choice: daily or weekly.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

end
Synopsis Enable the end context
Context configure application-assurance group number policer flow-count-limit-policer named-item time-of-day-override number time-range weekly end
Treeend

Description

Commands in this context configure the weekly end time for policer override.When using a weekly override, the operator can select between which days in the week the policy ends up to the hours or minutes for both start of the day and end of the day.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

time policer-end-time
Synopsis Weekly end time
Context configure application-assurance group number policer flow-count-limit-policer named-item time-of-day-override number time-range weekly end time policer-end-time
Treetime

Description

This command configures the weekly end time of the policer override.

The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.

String length3 to 5

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

start
Synopsis Enable the start context
Context configure application-assurance group number policer flow-count-limit-policer named-item time-of-day-override number time-range weekly start
Treestart

Description

Commands in this context configure the weekly start time for policer override.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

time policer-start-time
Synopsis Weekly start time
Context configure application-assurance group number policer flow-count-limit-policer named-item time-of-day-override number time-range weekly start time policer-start-time
Treetime

Description

This command configures the weekly start time of the policer override.

The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.

String length3 to 5

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

flow-setup-rate-policer [policer-name] named-item
Synopsis Enter the flow-setup-rate-policer list instance
Contextconfigure application-assurance group number policer flow-setup-rate-policer named-item
Treeflow-setup-rate-policer

Description

Commands in this context configure the flow setup rate policer.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

action keyword
Synopsis Action for packets violating configured policer rate
Contextconfigure application-assurance group number policer flow-setup-rate-policer named-item action keyword
Treeaction

Description

This command configures the action to be performed by single-bucket bandwidth policers for non-conformant traffic.

Dual bucket bandwidth policers cannot have their action configured and always mark traffic below CIR as in-profile, between CIR and PIR as out-of-profile, and drop traffic above PIR. Flow policers always discard non-conformant traffic.

When multiple application assurance policers are configured against a single flow (including policers at both subscriber and system), the flow/packet is dropped if one of the policers requires the packet to be discarded. This occurs regardless of the action of the other policers.

Optionspermit-deny, priority-mark, monitor
Defaultpermit-deny
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure application-assurance group number policer flow-setup-rate-policer named-item adaptation-rule
Treeadaptation-rule

Description

Commands in this context configure the AA policer adaptation rule fields and define the method used by the system to derive the operational CIR and PIR values when the queue is provisioned. For the CIR and PIR values individually, the system attempts to find the best operational rate depending on the defined option. To change the CIR adaptation rule only, the current PIR rule must be part of the command executed.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

granularity keyword
Warning:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisPolicer granularity
Contextconfigure application-assurance group number policer flow-setup-rate-policer named-item granularity keyword
Treegranularity
Optionssystem, subscriber

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

time-of-day-override [tod-override-id] number
Synopsis Enter the time-of-day-override list instance
Contextconfigure application-assurance group number policer flow-setup-rate-policer named-item time-of-day-override number
Treetime-of-day-override

Description

Commands in this context configure the time of day override policy for a given policer. Rate/mbs/cbs/flow-rate/flow-count configured in each override-id will override the default policer values at the specified time of day configured in the override.

Max. instances8
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

time-range
Synopsis Enter the time-range context
Context configure application-assurance group number policer flow-setup-rate-policer named-item time-of-day-override number time-range
Treetime-range

Description

Commands in this context configure the days of the week policer override is enabled as well as the time policer override starts and ends. When using a daily override the operator can select which days during the week from Sunday to Saturday it is applicable along with the start/end hour/min time range repeated over these days.When using a weekly override the operator can select between which days in the week the policy start up to the hours/min for both start day and end day.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

daily
Synopsis Enable the daily context
Context configure application-assurance group number policer flow-setup-rate-policer named-item time-of-day-override number time-range daily
Treedaily

Description

Commands in this context configure the daily start and end times for policer override.

Notes

The following elements are part of a choice: daily or weekly.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

end policer-end-time
Synopsis Daily end time
Contextconfigure application-assurance group number policer flow-setup-rate-policer named-item time-of-day-override number time-range daily end policer-end-time
Treeend

Description

This command configures the daily end time of the policer override.

The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.

String length3 to 5

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

start policer-start-time
Synopsis Daily start time
Context configure application-assurance group number policer flow-setup-rate-policer named-item time-of-day-override number time-range daily start policer-start-time
Treestart

Description

This command configures the daily start time of the policer override.

The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.

String length3 to 5

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

weekly
Synopsis Enable the weekly context
Context configure application-assurance group number policer flow-setup-rate-policer named-item time-of-day-override number time-range weekly
Treeweekly

Description

Commands in this context configure the weekly start and end times for policer override.

Notes

The following elements are part of a choice: daily or weekly.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

end
Synopsis Enable the end context
Context configure application-assurance group number policer flow-setup-rate-policer named-item time-of-day-override number time-range weekly end
Treeend

Description

Commands in this context configure the weekly end time for policer override.When using a weekly override, the operator can select between which days in the week the policy ends up to the hours or minutes for both start of the day and end of the day.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

time policer-end-time
Synopsis Weekly end time
Context configure application-assurance group number policer flow-setup-rate-policer named-item time-of-day-override number time-range weekly end time policer-end-time
Treetime

Description

This command configures the weekly end time of the policer override.

The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.

String length3 to 5

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

start
Synopsis Enable the start context
Context configure application-assurance group number policer flow-setup-rate-policer named-item time-of-day-override number time-range weekly start
Treestart

Description

Commands in this context configure the weekly start time for policer override.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

time policer-start-time
Synopsis Weekly start time
Context configure application-assurance group number policer flow-setup-rate-policer named-item time-of-day-override number time-range weekly start time policer-start-time
Treetime

Description

This command configures the weekly start time of the policer override.

The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.

String length3 to 5

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

single-bucket-bandwidth-policer [policer-name] named-item
Synopsis Enter the single-bucket-bandwidth-policer list instance
Contextconfigure application-assurance group number policer single-bucket-bandwidth-policer named-item
Treesingle-bucket-bandwidth-policer

Description

Commands in this context configure the single-bucket bandwidth policer.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

action keyword
Synopsis Action for packets violating configured policer rate
Contextconfigure application-assurance group number policer single-bucket-bandwidth-policer named-item action keyword
Treeaction

Description

This command configures the action to be performed by single-bucket bandwidth policers for non-conformant traffic.

Dual bucket bandwidth policers cannot have their action configured and always mark traffic below CIR as in-profile, between CIR and PIR as out-of-profile, and drop traffic above PIR. Flow policers always discard non-conformant traffic.

When multiple application assurance policers are configured against a single flow (including policers at both subscriber and system), the flow/packet is dropped if one of the policers requires the packet to be discarded. This occurs regardless of the action of the other policers.

Optionspermit-deny, priority-mark, monitor
Defaultpermit-deny
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

adaptation-rule
Synopsis Enter the adaptation-rule context
Contextconfigure application-assurance group number policer single-bucket-bandwidth-policer named-item adaptation-rule
Treeadaptation-rule
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

pir keyword
Synopsis Peak information rate value for the adaptation rule
Contextconfigure application-assurance group number policer single-bucket-bandwidth-policer named-item adaptation-rule pir keyword
Treepir

Description

This command configures the adaptation rule to be used while computing the operational PIR value. The adaptation rule specifies the rules to compute the operational values while maintaining minimum offset.

Optionsmax, min, closest
Defaultclosest
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

congestion-override
Synopsis Enter the congestion-override context
Contextconfigure application-assurance group number policer single-bucket-bandwidth-policer named-item congestion-override
Treecongestion-override

Description

Commands in this context configure the congestion bandwidth policer override rates.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mbs number
Synopsis Maximum burst size when in a congested state
Contextconfigure application-assurance group number policer single-bucket-bandwidth-policer named-item congestion-override mbs number
Treembs

Description

This command configures the maximum burst size (MBS) for the policer. Nokia recommends configuring MBS larger than twice the MTU for the traffic handled by the policer to allow for some burstiness of the traffic. MBS is configurable for single-bucket, dual-bucket bandwidth, and flow setup rate policers only.

Range0 to 131071
Unitskilobytes
Default 0
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

congestion-override-stage-2
Synopsis Enter the congestion-override-stage-2 context
Contextconfigure application-assurance group number policer single-bucket-bandwidth-policer named-item congestion-override-stage-2
Treecongestion-override-stage-2

Description

Commands in this context configure per-subscriber stage 2 congestion bandwidth policer override rates.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mbs number
Synopsis Maximum burst size when in a congested state
Contextconfigure application-assurance group number policer single-bucket-bandwidth-policer named-item congestion-override-stage-2 mbs number
Treembs

Description

This command configures the maximum burst size (MBS) for the policer. Nokia recommends configuring MBS larger than twice the MTU for the traffic handled by the policer to allow for some burstiness of the traffic. MBS is configurable for single-bucket, dual-bucket bandwidth, and flow setup rate policers only.

Range0 to 131071
Unitskilobytes
Default 0
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mbs number
Synopsis Bandwidth policer maximum burst size
Context configure application-assurance group number policer single-bucket-bandwidth-policer named-item mbs number
Treembs

Description

This command configures the maximum burst size (MBS) for the policer. Nokia recommends configuring MBS larger than twice the MTU for the traffic handled by the policer to allow for some burstiness of the traffic. MBS is configurable for single-bucket, dual-bucket bandwidth, and flow setup rate policers only.

Range0 to 131071
Unitskilobytes
Default 0
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

time-of-day-override [tod-override-id] number
Synopsis Enter the time-of-day-override list instance
Contextconfigure application-assurance group number policer single-bucket-bandwidth-policer named-item time-of-day-override number
Treetime-of-day-override

Description

Commands in this context configure the time of day override policy for a given policer. Rate/mbs/cbs/flow-rate/flow-count configured in each override-id will override the default policer values at the specified time of day configured in the override.

Max. instances8
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mbs number
Synopsis Bandwidth policer MBS for time of day override
Contextconfigure application-assurance group number policer single-bucket-bandwidth-policer named-item time-of-day-override number mbs number
Treembs

Description

This command configures the maximum burst size (MBS) for the policer. Nokia recommends configuring MBS larger than twice the MTU for the traffic handled by the policer to allow for some burstiness of the traffic. MBS is configurable for single-bucket, dual-bucket bandwidth, and flow setup rate policers only.

Range0 to 131071
Unitskilobytes
Default 0
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

time-range
Synopsis Enter the time-range context
Context configure application-assurance group number policer single-bucket-bandwidth-policer named-item time-of-day-override number time-range
Treetime-range

Description

Commands in this context configure the days of the week policer override is enabled as well as the time policer override starts and ends. When using a daily override the operator can select which days during the week from Sunday to Saturday it is applicable along with the start/end hour/min time range repeated over these days.When using a weekly override the operator can select between which days in the week the policy start up to the hours/min for both start day and end day.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

daily
Synopsis Enable the daily context
Context configure application-assurance group number policer single-bucket-bandwidth-policer named-item time-of-day-override number time-range daily
Treedaily

Description

Commands in this context configure the daily start and end times for policer override.

Notes

The following elements are part of a choice: daily or weekly.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

end policer-end-time
Synopsis Daily end time
Contextconfigure application-assurance group number policer single-bucket-bandwidth-policer named-item time-of-day-override number time-range daily end policer-end-time
Treeend

Description

This command configures the daily end time of the policer override.

The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.

String length3 to 5

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

start policer-start-time
Synopsis Daily start time
Context configure application-assurance group number policer single-bucket-bandwidth-policer named-item time-of-day-override number time-range daily start policer-start-time
Treestart

Description

This command configures the daily start time of the policer override.

The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.

String length3 to 5

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

weekly
Synopsis Enable the weekly context
Context configure application-assurance group number policer single-bucket-bandwidth-policer named-item time-of-day-override number time-range weekly
Treeweekly

Description

Commands in this context configure the weekly start and end times for policer override.

Notes

The following elements are part of a choice: daily or weekly.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

end
Synopsis Enable the end context
Context configure application-assurance group number policer single-bucket-bandwidth-policer named-item time-of-day-override number time-range weekly end
Treeend

Description

Commands in this context configure the weekly end time for policer override.When using a weekly override, the operator can select between which days in the week the policy ends up to the hours or minutes for both start of the day and end of the day.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

time policer-end-time
Synopsis Weekly end time
Context configure application-assurance group number policer single-bucket-bandwidth-policer named-item time-of-day-override number time-range weekly end time policer-end-time
Treetime

Description

This command configures the weekly end time of the policer override.

The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.

String length3 to 5

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

start
Synopsis Enable the start context
Context configure application-assurance group number policer single-bucket-bandwidth-policer named-item time-of-day-override number time-range weekly start
Treestart

Description

Commands in this context configure the weekly start time for policer override.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

time policer-start-time
Synopsis Weekly start time
Context configure application-assurance group number policer single-bucket-bandwidth-policer named-item time-of-day-override number time-range weekly start time policer-start-time
Treetime

Description

This command configures the weekly start time of the policer override.

The time format must be [hh:mm]. The hh value is 00 to 24. The mm value is 00, 15, 30, or 45. If hh is 24, mm must be 00.

String length3 to 5

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

tcp-optimizer [tcp-optimizer-name] named-item
Synopsis Enter the tcp-optimizer list instance
Contextconfigure application-assurance group number tcp-optimizer named-item
Treetcp-optimizer

Description

Commands in this context configure the TCP optimizer policy. When a TCP optimizer policy is removed or deleted, the existing flows using this policy are abandoned, and optimization is stopped.

Introduced22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[tcp-optimizer-name] named-item
Synopsis TCP optimizer name
Context configure application-assurance group number tcp-optimizer named-item
Treetcp-optimizer

Description

This command configures the name of the TCP optimizer policy.

String length1 to 32

Notes

This element is part of a list key.

Introduced22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dack-timeout number
Synopsis Delayed acknowledgment timeout for client and server
Contextconfigure application-assurance group number tcp-optimizer named-item dack-timeout number
Treedack-timeout

Description

This command configures a delay ACK (DACK) timeout for the TCP optimizer. By entering this command a default of 200 ms timeout is enabled for delayed acknowledgment. This value is not configurable.

Range200
Units milliseconds
Introduced 22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

high-cpu-backoff boolean
Synopsis Stop optimizing sessions when CPU capacity is limited
Contextconfigure application-assurance group number tcp-optimizer named-item high-cpu-backoff boolean
Treehigh-cpu-backoff

Description

When configured to true, AA stops optimizing TCP sessions when the CPU capacity is limited.

AA implements the following CPU utilization thresholds:

level 1 - 75%

level 2 - 85%

level 3 - 90%

The following describes the functionality of the preceding thresholds:

early random bypass stage (level 1)

When the CPU utilization is between level 1 and level 2, AA randomly optimizes or bypasses new TCP sessions proportional to the position of the CPU utilization within the range between level 1 and level 2.

stop optimization of new flows stage (level 2)

When the CPU utilization is at or above level 2, AA stops optimizing new TCP sessions.

abandon stage (level 3)

When the CPU utilization is at or above level 3, AA abandons existing optimized TCP sessions.

Note: The CPU utilization is measured once per second in each core or worker. The CPU utilization may differ between cores.

When configured to false, AA optimizes TCP sessions, regardless of the CPU capacity.

Defaultfalse
Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

initial-cwnd number
Synopsis MSS of the TCP optimizer initial congestion window
Contextconfigure application-assurance group number tcp-optimizer named-item initial-cwnd number
Treeinitial-cwnd

Description

This command configures the maximum segment size (MSS) of the initial congestion window used by the TCP optimizer (TCPO) during the Slow Start (SS) period.

Range1 to 256
Default8
Introduced 22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

initial-ss-threshold (number | keyword)
Synopsis Initial TCP Slow Start threshold for client and server
Contextconfigure application-assurance group number tcp-optimizer named-item initial-ss-threshold (number | keyword)
Treeinitial-ss-threshold

Description

This command configures the initial Slow Start (SS) threshold for a specific TCP optimizer policy. Nokia recommends setting the threshold close to the access network Bandwidth Delay Product (BDP).

Range0 to 1000000
Unitskilobytes
Optionsauto
Default1000000
Introduced22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

network-rtt-threshold number
Synopsis Network round trip time threshold
Context configure application-assurance group number tcp-optimizer named-item network-rtt-threshold number
Treenetwork-rtt-threshold

Description

This command configures the threshold of the Round Trip Time (RTT) delay of the network side (between AA and the content provider) above which TCP Optimization (TCPO) is performed. This enables the operator to disable optimization for content that is served from a location close to the TCP optimizer.

Range1 to 100
Unitsmilliseconds
Introduced 22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

tcp-stack keyword
Synopsis TCP stack congestion control algorithm
Contextconfigure application-assurance group number tcp-optimizer named-item tcp-stack keyword
Treetcp-stack

Description

This command configures the TCP stack used toward the subscriber.

Note: The TCP stack used toward the core network is new-reno, and it is not configurable. TCP BBR, BBRv2, TCP Illinois, and TCP Westwood implement a sender-side modification of the TCP congestion window algorithm that improves the performance of TCP Reno in wireless networks with lossy links.

Optionswestwood, illinois, new-reno, bbr, bbrv2
Defaultwestwood
Introduced22.2.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

url-filter [url-filter-name] named-item
Synopsis Enter the url-filter list instance
Contextconfigure application-assurance group number url-filter named-item
Treeurl-filter

Description

Commands in this context configure a URL filter action for flows of a specific type matching this entry. If no URL filters are specified, then no URL filters are evaluated.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[url-filter-name] named-item
Synopsis URL filter name
Context configure application-assurance group number url-filter named-item
Treeurl-filter
String length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the AA URL filter
Contextconfigure application-assurance group number url-filter named-item admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

apply-function-specific-behaviour boolean
Synopsis Use function-specific behavior for action or redirect
Contextconfigure application-assurance group number url-filter named-item apply-function-specific-behaviour boolean
Treeapply-function-specific-behaviour

Description

When configured to true, the function-specific configurations for URL list, ICAP, and web service (url-list, icap, and web-service) are used for default action (default-action) and HTTP redirect (http-redirect).

When configured to false, the configuration at the URL filter level (url-filter) is used for default action and HTTP redirect.

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

default-action
Synopsis Enter the default-action context
Contextconfigure application-assurance group number url-filter named-item default-action
Treedefault-action

Description

Commands in this context configure the default action to take effect when the URL filter cannot be used. This may occur in the following cases:

  • for the local URL list when the URL list is shut down or the file is not loaded due to an error.

  • in the case of ICAP or web filtering when all TCP connections are busy or down.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

allow
Synopsis Allow all requests as the default URL filter action
Contextconfigure application-assurance group number url-filter named-item default-action allow
Treeallow

Description

When configured, the router allows all requests as the default URL filter action when the URL filter cannot be used.

Notes

The following elements are part of a choice: allow, block-all, or block-http-redirect.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

block-all
Synopsis Block all requests as the default URL filter action
Contextconfigure application-assurance group number url-filter named-item default-action block-all
Treeblock-all

Description

When configured, the router blocks all requests as the default URL filter action when the URL filter cannot be used.

Notes

The following elements are part of a choice: allow, block-all, or block-http-redirect.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

block-http-redirect reference
Synopsis HTTP URL name for block and redirect request action
Contextconfigure application-assurance group number url-filter named-item default-action block-http-redirect reference
Treeblock-http-redirect

Description

This command specifies the URL that the user is directed to when the router blocks traffic. The information page can be different from the page the user is redirected to when the site that the user tried to access is found in the URL filter. This page is configured using the configure application-assurance group url-filter http-redirect command.

Reference

configure application-assurance group number http-redirect named-item

Notes

The following elements are part of a choice: allow, block-all, or block-http-redirect.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

icap
Synopsis Enter the icap context
Context configure application-assurance group number url-filter named-item icap
Treeicap

Description

Commands in this context configure the URL filter ICAP policy fields.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

custom-x-header named-item
Synopsis Custom x-header field name to include in ICAP requests
Contextconfigure application-assurance group number url-filter named-item icap custom-x-header named-item
Treecustom-x-header

Description

This command configures the URL filter ICAP policy to include a new x-header field; the content of the x-header is populated based on the AQP URL filter action which can optionally specify the ASO characteristic value to include in the x-header.

String length1 to 32
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

default-action
Synopsis Enter the default-action context
Contextconfigure application-assurance group number url-filter named-item icap default-action
Treedefault-action

Description

Commands in this context configure a default action for the URL filter. The default action takes effect when the URL filter cannot be used. This may happen when all TCP connections are busy or down.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

allow
Synopsis Allow all requests as the default action
Contextconfigure application-assurance group number url-filter named-item icap default-action allow
Treeallow

Description

When configured, this command allows all traffic when the URL filter cannot be used.

Notes

The following elements are part of a choice: allow, block-all, or block-http-redirect.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

block-all
Synopsis Block all requests as the default action
Contextconfigure application-assurance group number url-filter named-item icap default-action block-all
Treeblock-all

Description

When configured, this command blocks all traffic when the URL filter cannot be used.

Notes

The following elements are part of a choice: allow, block-all, or block-http-redirect.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

block-http-redirect reference
Synopsis HTTP URL for redirection when URL filter cannot be used
Contextconfigure application-assurance group number url-filter named-item icap default-action block-http-redirect reference
Treeblock-http-redirect

Description

This command blocks traffic and redirects the user to an information page, which can be different than the page the user is redirected to when the site they attempted to access was found in the URL filter; this page is configured using the configure application-assurance group url-filter http-redirect command.

Reference

configure application-assurance group number http-redirect named-item

Notes

The following elements are part of a choice: allow, block-all, or block-http-redirect.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

server [ip-address] (ipv4-address-no-zone | ipv6-address-no-zone) port number
Synopsis Enter the server list instance
Contextconfigure application-assurance group number url-filter named-item icap server (ipv4-address-no-zone | ipv6-address-no-zone) port number
Treeserver

Description

Commands in this context configure the IP address and server port of the ICAP server.

In the current release, the system supports IPv4 addresses only for the ICAP server.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis ICAP server IP address
Context configure application-assurance group number url-filter named-item icap server (ipv4-address-no-zone | ipv6-address-no-zone) port number
Treeserver

Description

This command configures the ICAP server address.

In the current release, the system supports IPv4 addresses only for the ICAP server.

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

port number
Synopsis ICAP server port
Context configure application-assurance group number url-filter named-item icap server (ipv4-address-no-zone | ipv6-address-no-zone) port number
Treeserver
Range1 to 65535
MD-CLI default1344

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of this URL filter ICAP server
Contextconfigure application-assurance group number url-filter named-item icap server (ipv4-address-no-zone | ipv6-address-no-zone) port number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

vlan-id number
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisVLAN ID of the ICAP server service port
Contextconfigure application-assurance group number url-filter named-item icap vlan-id number
Treevlan-id
Range1 to 4094
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

local-filtering
Synopsis Enter the local-filtering context
Contextconfigure application-assurance group number url-filter named-item local-filtering
Treelocal-filtering

Description

Commands in this context configure a URL filter policy for local filtering to filter traffic based on a list of URLs located on a file stored in the router compact flash.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

deny-list [url-list-name] reference
Synopsis Enter the deny-list list instance
Contextconfigure application-assurance group number url-filter named-item local-filtering deny-list reference
Treedeny-list

Description

Commands in this context configure a list of denied URLs to be added to the local URL filter policy.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

default-action
Synopsis Enter the default-action context
Contextconfigure application-assurance group number url-filter named-item local-filtering deny-list reference default-action
Treedefault-action

Description

Commands in this context configure a default action for the URL filter. The default action takes effect when the URL filter cannot be used. This may happen in the case of a local URL list when the URL list is disabled or the file is not loaded due to an error.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

allow
Synopsis Allow all requests as the default action
Contextconfigure application-assurance group number url-filter named-item local-filtering deny-list reference default-action allow
Treeallow

Description

This command allows all traffic when the URL filter cannot be used.

Notes

The following elements are part of a choice: allow, block-all, or block-http-redirect.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

block-http-redirect reference
Synopsis HTTP URL for redirection when URL filter cannot be used
Contextconfigure application-assurance group number url-filter named-item local-filtering deny-list reference default-action block-http-redirect reference
Treeblock-http-redirect

Description

This command blocks traffic and redirects the user to an information page, which can be different than the page the user is redirected to when the site they attempted to access was found in the URL filter; this page is configured using the configure application-assurance group url-filter http-redirect command.

Reference

configure application-assurance group number http-redirect named-item

Notes

The following elements are part of a choice: allow, block-all, or block-http-redirect.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

web-service
Synopsis Enter the web-service context
Context configure application-assurance group number url-filter named-item web-service
Treeweb-service

Description

Commands in this context configure the URL filter policy using web-service filtering. The operator must configure the web service, hostname, DNS server to use, the AA interface VLAN ID, and provision the category profiles.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

category-set number
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisWeb service category ID
Contextconfigure application-assurance group number url-filter named-item web-service category-set number
Treecategory-set
Range1 to 65535
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

classification-overrides
Synopsis Enter the classification-overrides context
Contextconfigure application-assurance group number url-filter named-item web-service classification-overrides
Treeclassification-overrides

Description

Commands in this context create a classification override and allow the operator to manually set the category of a hostname.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

entry [entry-id] number
Synopsis Enter the entry list instance
Context configure application-assurance group number url-filter named-item web-service classification-overrides entry number
Treeentry

Description

Commands in this context configure a classification override, manually setting the category of a hostname.

Max. instances200
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

classifier keyword
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisWeb service classifier
Contextconfigure application-assurance group number url-filter named-item web-service classifier keyword
Treeclassifier
Optionsweb-service-1
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

default-action
Synopsis Enter the default-action context
Contextconfigure application-assurance group number url-filter named-item web-service default-action
Treedefault-action

Description

Commands in this context configure a default action for the URL filter. The default action takes effect when the URL filter cannot be used. This may happen when all TCP connections are busy or down.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

allow
Synopsis Allow all requests as the default action
Contextconfigure application-assurance group number url-filter named-item web-service default-action allow
Treeallow

Description

This command allows all traffic when the web service is unavailable.

Notes

The following elements are part of a choice: allow, block-all, or block-http-redirect.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

block-all
Synopsis Block all requests as the default action
Contextconfigure application-assurance group number url-filter named-item web-service default-action block-all
Treeblock-all

Description

This command blocks all traffic when the web service is unavailable.

Notes

The following elements are part of a choice: allow, block-all, or block-http-redirect.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

block-http-redirect reference
Synopsis HTTP URL for redirection when traffic is blocked
Contextconfigure application-assurance group number url-filter named-item web-service default-action block-http-redirect reference
Treeblock-http-redirect

Description

This command specifies the HTTP URL to be redirected to when traffic is blocked. This URL can be different than the URL the user is redirected to when the site they attempted to access was found in the URL filter (which is configured in the configure application-assurance group url-filter http-redirect command).

Reference

configure application-assurance group number http-redirect named-item

Notes

The following elements are part of a choice: allow, block-all, or block-http-redirect.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dns-server (ipv4-address-no-zone | ipv6-address-no-zone)
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisWeb service DNS server
Contextconfigure application-assurance group number url-filter named-item web-service dns-server (ipv4-address-no-zone | ipv6-address-no-zone)
Treedns-server
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

fqdn display-string
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisWeb service fully qualified domain name
Contextconfigure application-assurance group number url-filter named-item web-service fqdn display-string
Treefqdn
String length1 to 255
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

profile [profile-name] named-item
Synopsis Enter the profile list instance
Contextconfigure application-assurance group number url-filter named-item web-service profile named-item
Treeprofile

Description

Commands in this context configure the category profiles of the web service.

Max. instances8
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[profile-name] named-item
Synopsis Web service profile name
Context configure application-assurance group number url-filter named-item web-service profile named-item
Treeprofile
String length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

block
Synopsis Enter the block context
Context configure application-assurance group number url-filter named-item web-service profile named-item block
Treeblock
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

category [category-name] web-serv-category-name
Synopsis Add a list entry for category
Context configure application-assurance group number url-filter named-item web-service profile named-item block category web-serv-category-name
Treecategory

Description

Commands in this context configure the category that is blocked in the category profile.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[category-name] web-serv-category-name
Synopsis Web service profile category name to be blocked
Contextconfigure application-assurance group number url-filter named-item web-service profile named-item block category web-serv-category-name
Treecategory
String length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

server [ip-address] (ipv4-address-no-zone | ipv6-address-no-zone) port number
Synopsis Enter the server list instance
Contextconfigure application-assurance group number url-filter named-item web-service server (ipv4-address-no-zone | ipv6-address-no-zone) port number
Treeserver
Max. instances4
Introduced23.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[ip-address] (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis AA web service server IP address
Context configure application-assurance group number url-filter named-item web-service server (ipv4-address-no-zone | ipv6-address-no-zone) port number
Treeserver

Notes

This element is part of a list key.

Introduced23.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

port number
Synopsis AA web service server port
Context configure application-assurance group number url-filter named-item web-service server (ipv4-address-no-zone | ipv6-address-no-zone) port number
Treeserver
Range1 to 65535
MD-CLI default8080

Notes

This element is part of a list key.

Introduced23.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

vlan-id number
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisWeb-service VLAN ID
Contextconfigure application-assurance group number url-filter named-item web-service vlan-id number
Treevlan-id

Description

This command configures the VLAN ID on which the AA ISA emits the traffic mapping to a preconfigured AA interface.

Range1 to 4094
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

url-list [url-list-name] named-item
Synopsis Enter the url-list list instance
Contextconfigure application-assurance group number url-list named-item
Treeurl-list

Description

Commands in this context configure a URL list object. The URL list points to a file containing a list of URLs located on the system Compact Flash and is then referenced in a URL filter object to filter and redirect subscribers when a URL from this file is accessed.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[url-list-name] named-item
Synopsis URL list name
Contextconfigure application-assurance group number url-list named-item
Treeurl-list
String length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the URL list
Context configure application-assurance group number url-list named-item admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

file display-string
Synopsis File name of the URL list on compact flash
Contextconfigure application-assurance group number url-list named-item file display-string
Treefile
String length1 to 180
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

host-expressions boolean
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisAllow URL list to contain hostnames with wildcards
Contextconfigure application-assurance group number url-list named-item host-expressions boolean
Treehost-expressions

Description

When configured to true, this command adds hostnames with wildcards to the URL list.

When configured to false, the URL list containing hostnames with wildcards is removed from the configuration.

Defaultfalse
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

key encrypted-leaf
Synopsis URL list decryption key
Context configure application-assurance group number url-list named-item key encrypted-leaf
Treekey

Description

This command configures the secret key for decrypting the URL list.

String length1 to 115
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

size keyword
Warning:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSize limit of the URL list
Contextconfigure application-assurance group number url-list named-item size keyword
Treesize
Optionsstandard, extended
Default standard
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

http-enrich

Synopsis Enter the http-enrich context
Context configure application-assurance http-enrich
Treehttp-enrich

Description

Commands in this context should not be used by the operators. Configuring them has no effect. Operators should use the commands in the application-assurance group context.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

field [field-name] named-item
Synopsis Enter the field list instance
Context configure application-assurance http-enrich field named-item
Treefield

Description

Commands in this context should not be used by the operators. Configuring them has no effect. Operators should use the commands in the application-assurance group context.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[field-name] named-item
Synopsis HTTP enrich field name (void, do not use)
Contextconfigure application-assurance http-enrich field named-item
Treefield

Description

This command should not be used by the operators. Configuring it has no effect. Operators should use the commands in the application-assurance group context.

String length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

http-error-redirect

Synopsis Enter the http-error-redirect context
Contextconfigure application-assurance http-error-redirect
Treehttp-error-redirect

Description

Commands in this context should not be used by the operators. Configuring them has no effect. Operators should use the commands in the application-assurance group context.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

error-code [error-code-number] number
Synopsis Enter the error-code list instance
Contextconfigure application-assurance http-error-redirect error-code number
Treeerror-code

Description

Commands in this context should not be used by the operators. Configuring them has no effect. Operators should use the commands in the application-assurance group context.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

template [template-id] number
Synopsis Enter the template list instance
Contextconfigure application-assurance http-error-redirect template number
Treetemplate

Description

Commands in this context should not be used by the operators. Configuring them has no effect. Operators should use the commands in the application-assurance group context.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[template-id] number
Synopsis HTTP error redirect template ID
Context configure application-assurance http-error-redirect template number
Treetemplate
Max. range0 to 4294967295

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

http-notification

Synopsis Enter the http-notification context
Contextconfigure application-assurance http-notification
Treehttp-notification

Description

Commands in this context should not be used by the operators. Configuring them has no effect. Operators should use the commands in the application-assurance group context.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

template [template-id] number
Synopsis Enter the template list instance
Contextconfigure application-assurance http-notification template number
Treetemplate

Description

Commands in this context should not be used by the operators. Configuring them has no effect. Operators should use the commands in the application-assurance group context.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[template-id] number
Synopsis HTTP notification template ID
Context configure application-assurance http-notification template number
Treetemplate
Max. range0 to 4294967295

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

http-redirect

Synopsis Enter the http-redirect context
Contextconfigure application-assurance http-redirect
Treehttp-redirect

Description

Commands in this context should not be used by the operators. Configuring them has no effect. Operators should use the commands in the application-assurance group context.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

template [template-id] number
Synopsis Enter the template list instance
Contextconfigure application-assurance http-redirect template number
Treetemplate

Description

Commands in this context should not be used by the operators. Configuring them has no effect. Operators should use the commands in the application-assurance group context.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[template-id] number
Synopsis HTTP redirect template ID
Context configure application-assurance http-redirect template number
Treetemplate

Description

This command specifies the HTTP policy redirect template ID.

The available options are:

1 - JavaScript based redirect embedded in HTTP 200 OK response with a predefined number of arguments automatically appended to the redirect URL

2 - HTTP 302 redirect with a predefined number of arguments automatically appended to the redirect URL

3 - HTTP 302 redirect with no parameters appended to the URL (empty)

4 - Empty redirect format using JavaScript

5 - Redirect supporting macro substitution using HTTP 302

6 - Redirect supporting macro substitution using JavaScript

Max. range0 to 4294967295

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

protocol [protocol-name] named-item

Synopsis Enter the protocol list instance
Contextconfigure application-assurance protocol named-item
Treeprotocol

Description

Commands in this context configure the administrative state of system-wide protocols.Some protocols are always enabled and cannot be disabled. These are "base protocols" that were present in R1 of the release.Some protocols are disabled by default and can be enabled. There are protocols that were introduced post R1, which are all enabled by default but may be disabled if not desired.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[protocol-name] named-item
Synopsis AA protocol name
Context configure application-assurance protocol named-item
Treeprotocol
String length1 to 32

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the protocol
Context configure application-assurance protocol named-item admin-state keyword
Treeadmin-state
Optionsenable, disable
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

radius-accounting-policy [rad-acct-plcy-name] named-item

Synopsis Enter the radius-accounting-policy list instance
Contextconfigure application-assurance radius-accounting-policy named-item
Treeradius-accounting-policy

Description

Commands in this context configure an existing subscriber RADIUS-based accounting policy to use for AA. RADIUS accounting policies are configured in the configure application-assurance radius-accounting-policy context.

Max. instances8
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

radius-accounting-server
Synopsis Enter the radius-accounting-server context
Contextconfigure application-assurance radius-accounting-policy named-item radius-accounting-server
Treeradius-accounting-server

Description

Commands in this context configure an existing subscriber RADIUS-based accounting policy to use for AA. RADIUS accounting policies are configured in the configure application-assurance radius-accounting-policy context.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

server [server-index] number
Synopsis Enter the server list instance
Contextconfigure application-assurance radius-accounting-policy named-item radius-accounting-server server number
Treeserver

Description

Commands in this context configure the RADIUS server and the RADIUS server IP address, index, and key values.

RADIUS servers are accessed in order from lowest to highest index for authentication requests until a response from a server is received. A higher indexed server is only queried if no response is received from a lower indexed server (which implies that the server is not available). If a response from a server is received, no other RADIUS servers are queried.

Max. instances5
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[server-index] number
Synopsis RADIUS accounting server index
Context configure application-assurance radius-accounting-policy named-item radius-accounting-server server number
Treeserver

Description

This command configures the index for the RADIUS server. The index determines the sequence in which the servers are queried for authentication requests. Servers are queried in order from lowest to highest index.

Range1 to 5

Notes

This element is part of a list key.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

address ipv4-unicast-address
Synopsis RADIUS server IP address
Context configure application-assurance radius-accounting-policy named-item radius-accounting-server server number address ipv4-unicast-address
Treeaddress

Description

This command configures the IP address of the RADIUS server. Two RADIUS servers cannot have the same IP address. An error message is generated if the server address is a duplicate.

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

secret encrypted-leaf
Synopsis RADIUS server secret key
Context configure application-assurance radius-accounting-policy named-item radius-accounting-server server number secret encrypted-leaf
Treesecret

Description

This command configures the secret key to access the RADIUS server. This secret key must match the password on the RADIUS server.

String length1 to 54

Notes

This element is mandatory.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

source-address ipv4-unicast-address
Synopsis Source IP address of RADIUS packets
Context configure application-assurance radius-accounting-policy named-item radius-accounting-server source-address ipv4-unicast-address
Treesource-address

Description

This command configures the source IP address of the RADIUS packet. 

The system IP address must be configured for the RADIUS client to work. The system IP address must only be configured if the source address is not specified. When this command reverts to its default, the source address is determined at the moment the request is sent. 

This address is also used in the nas-ip-address command in the configure aaa radius isa-policy accounting include-attributes and configure aaa radius isa-policy authentication include-attributes contexts as it is set to the system IP address if no source address was given. 

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

usage-alert-thresholds

Synopsis Enter the usage-alert-thresholds context
Contextconfigure application-assurance usage-alert-thresholds
Treeusage-alert-thresholds

Description

Commands in this context configure the AA performance monitoring alerts.

Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

bit-rate-high-wmark (number | keyword)
Synopsis High watermark for bit rate alarms
Context configure application-assurance usage-alert-thresholds bit-rate-high-wmark (number | keyword)
Treebit-rate-high-wmark

Description

This command configures the high watermark for bit rate alarms. The value must be larger than or equal to the low watermark value.

Range1 to 100000
Unitsmegabps
Options max
Default max
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

bit-rate-low-wmark number
Synopsis Low watermark for bit rate alarms
Context configure application-assurance usage-alert-thresholds bit-rate-low-wmark number
Treebit-rate-low-wmark

Description

This command configures the utilization of the flow records on the ISA-AA group when the full alarm is cleared by the agent.

Range0 to 99999
Default0
Introduced 21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

datapath-cpu-high-wmark (number | keyword)
Synopsis High watermark for datapath CPU alarms
Contextconfigure application-assurance usage-alert-thresholds datapath-cpu-high-wmark (number | keyword)
Treedatapath-cpu-high-wmark

Description

This command configures the system-wide high watermark threshold as a percentage of the per-ISA datapath core CPU utilization, where an alarm is raised by the agent. CPU usage is the average usage across all datapath cores.

Range0 to 100
Unitspercent
Options max
Default 95
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

datapath-cpu-low-wmark number
Synopsis Low watermark for datapath CPU alarms
Contextconfigure application-assurance usage-alert-thresholds datapath-cpu-low-wmark number
Treedatapath-cpu-low-wmark

Description

This command configures the system-wide low watermark threshold as a percentage of the per-ISA datapath core CPU utilization, where an alarm is raised by the agent. CPU usage is the average usage across all datapath cores.

Range0 to 100
Unitspercent
Default 90
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

flow-setup-rate-high-wmark (number | keyword)
Synopsis High watermark for flow setup rate
Context configure application-assurance usage-alert-thresholds flow-setup-rate-high-wmark (number | keyword)
Treeflow-setup-rate-high-wmark

Description

This command configures the system-wide high watermark threshold for per-ISA throughput in packets/second when an alarm is raised by the agent. The value must be larger than or equal to the packet-rate-low-wmark value.

Range1 to 2000000
Optionsmax
Defaultmax
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

flow-table-high-wmark number
Synopsis Flow table high watermark
Context configure application-assurance usage-alert-thresholds flow-table-high-wmark number
Treeflow-table-high-wmark

Description

This command configures the system-wide high watermark threshold as a percentage of the flow table size for the per-ISA utilization of the flow records when a full alarm is raised by the agent.

Range0 to 100
Unitspercent
Default 95
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

flow-table-low-wmark number
Synopsis Flow table low watermark
Context configure application-assurance usage-alert-thresholds flow-table-low-wmark number
Treeflow-table-low-wmark

Description

This command configures the system-wide low watermark threshold as a percentage of the flow table size for per-ISA. 

Range0 to 100
Unitspercent
Default 90
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

packet-rate-high-wmark (number | keyword)
Synopsis Packet rate high watermark
Context configure application-assurance usage-alert-thresholds packet-rate-high-wmark (number | keyword)
Treepacket-rate-high-wmark

Description

This command configures the packet rate on the ISA-AA when a packet rate alarm is raised by the agent.

Range1 to 148809524
Optionsmax
Defaultmax
Introduced21.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR