s Commands – Part V
static-aa-sub
static-aa-sub
Syntax
static-aa-sub transit-aasub-name
static-aa-sub transit-aasub-name app-profile app-profile-name [create]
no static-aa-sub transit-aasub-name
Context
[Tree] (config>app-assure>group>transit-ip-policy static-aa-sub)
Full Context
configure application-assurance group transit-ip-policy static-aa-sub
Description
This command configures static transit aa-subs with a name and an app-profile. A new transit sub with both a name and an app-profile is configured with the create command. Static transit aa-sub must have an explicitly assigned app-profile. An existing transit sub can optionally be assigned a different app-profile, or this command can be used to enter the static-aa-sub context.
The no form of this command deletes the named static transit aa-sub from the configuration.
Parameters
- transit-aasub-name
-
Specifies the name of a transit subscriber up to 32 characters in length.
- app-profile-name
-
Specifies the name of an existing application profile up to 32 characters in length.
- create
-
Keyword used to create a new app-profile entry.
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
static-aa-sub
Syntax
static-aa-sub transit-aasub-name
static-aa-sub transit-aasub-name app-profile app-profile-name [create]
no static-aa-sub transit-aasub-name
Context
[Tree] (config>app-assure>group>transit-prefix-policy static-aa-sub)
Full Context
configure application-assurance group transit-prefix-policy static-aa-sub
Description
This command configures a static transit aa-sub with a name and an app-profile. A new transit sub with both a name and an app-profile is configured with the create command. Static transit aa-sub must have an explicitly assigned app-profile. An existing transit sub can optionally be assigned a different app-profile, or this command can be used to enter the static-aa-sub context.
The no form of this command deletes the named static transit aa-sub from the configuration.
Parameters
- transit-aasub-name
-
Specifies a transit aasub-name up to 32 characters.
- app-profile-name
-
Specifies the name of an existing application profile up to 32 characters.
- create
-
Keyword used to create a new app-profile entry
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
static-address
static-address
Syntax
[no] static-address {ip-address | ipv6-address}
Context
[Tree] (config>app-assure>group>dns-ip-cache>ip-cache static-address)
Full Context
configure application-assurance group dns-ip-cache ip-cache static-address
Description
This command configures a static address in the cache.
Parameters
- ip-address | ipv6-address
-
Specifies a character string up to 64 characters.
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
static-arp
static-arp
Syntax
static-arp ieee-mac-address unnumbered
static-arp ip-address ieee-mac-address
no static-arp [ieee-mac-address] unnumbered
no static-arp ip-address [ieee-mac-address]
Context
[Tree] (config>service>ies>if static-arp)
[Tree] (config>service>vprn>if static-arp)
Full Context
configure service ies interface static-arp
configure service vprn interface static-arp
Description
This command configures a static address resolution protocol (ARP) entry associating a subscriber IP address with a MAC address for the core router instance. This static ARP appears in the core routing ARP table. A static ARP can only be configured if it exists on the network attached to the IP interface.
If an entry for a particular IP address already exists and a new MAC address is configured for the IP address, the existing MAC address will be replaced with the new MAC address.
The no form of this command removes a static ARP entry.
Parameters
- ip-address
-
Specifies the IP address for the static ARP in IP address dotted decimal notation.
- ieee-mac-address
-
Specifies the 48-bit MAC address for the static ARP in the form aa:bb:cc:dd:ee:ff or aa-bb-cc-dd-ee-ff, where aa, bb, cc, dd, ee and ff are hexadecimal numbers. Allowed values are any non-broadcast, non-multicast MAC and non-IEEE reserved MAC addresses.
- unnumbered
-
Specifies the static ARP MAC for an unnumbered interface. Unnumbered interfaces support dynamic ARP. Once this command is configured, it overrides any dynamic ARP.
Platforms
All
static-arp
Syntax
static-arp ieee-mac-addr unnumbered
static-arp ip-address ieee-mac-address
no static-arp [ieee-mac-addr] unnumbered
no static-arp ip-address [ieee-mac-address]
Context
[Tree] (config>service>vpls>interface static-arp)
Full Context
configure service vpls interface static-arp
Description
This command configures a static address resolution protocol (ARP) entry associating a subscriber IP address with a MAC address for the core router instance. A static ARP can only be configured if it exists on the network attached to the IP interface.
If an entry for a particular IP address already exists and a new MAC address is configured for the IP address, the existing MAC address will be replaced with the new MAC address.
The no form of this command removes a static ARP entry.
Parameters
- ip-address
-
Specifies the IP address for the static ARP in dotted decimal notation
- ieee-mac-address
-
Specifies the 48-bit MAC address for the static ARP in the form aa:bb:cc:dd:ee:ff or aa-bb-cc-dd-ee-ff where aa, bb, cc, dd, ee and ff are hexadecimal numbers. Allowed values are any non-broadcast, non-multicast MAC and non-IEEE reserved MAC addresses.
- unnumbered
-
Specifies the static ARP MAC for an unnumbered interface. Unnumbered interfaces support dynamic ARP. Once this command is configured, it overrides any dynamic ARP.
Platforms
All
static-arp
Syntax
static-arp ip-address ieee-mac-address
no static-arp ip-address
Context
[Tree] (config>service>vprn>nw-if static-arp)
Full Context
configure service vprn network-interface static-arp
Description
This command configures a static address resolution protocol (ARP) entry associating a subscriber IP address with a MAC address for the core router instance. This static ARP will appear in the core routing ARP table. A static ARP can only be configured if it exists on the network attached to the IP interface. If an entry for a particular IP address already exists and a new MAC address is configured for the IP address, the existing MAC address will be replaced with the new MAC address.
The no form of this command removes a static ARP entry.
Parameters
- ip-address
-
Specifies the IP address for the static ARP in IP address dotted decimal notation.
- ieee-mac-address
-
Specifies the 48-bit MAC address for the static ARP in the form aa:bb:cc:dd :ee:ff or aa-bb-cc-dd -ee-ff where aa, bb, cc, dd, ee and ff are hexadecimal numbers. Allowed values are any non-broadcast, non-multicast MAC and non-IEEE reserved MAC addresses.
Platforms
All
static-arp
Syntax
static-arp ip-address ieee-address
no static-arp ip-address
static-arp ieee-address unnumbered
no static-arp unnumbered
Context
[Tree] (config>router>if static-arp)
Full Context
configure router interface static-arp
Description
This command configures a static Address Resolution Protocol (ARP) entry associating an IP address with a MAC address for the core router instance. This static ARP appears in the core routing ARP table. A static ARP can only be configured if it exists on the network attached to the IP interface.
If an entry for a specific IP address already exists and a new MAC address is configured for the IP address, the existing MAC address is replaced by the new MAC address.
The number of static-arp entries that can be configured on a single node is limited to 1000.
Static ARP is used when a router needs to know about a device on an interface that cannot or does not respond to ARP requests. Therefore, the router configuration can state that if it has a packet that has a certain IP address to send it to the corresponding ARP address. Use proxy ARP so the router responds to ARP requests on behalf of another device.
The no form of this command removes a static ARP entry.
Parameters
- ieee-address
-
Specifies the 48-bit MAC address for the static ARP in the form aa:bb:cc:dd :ee:ff or aa-bb-cc-dd -ee-ff, where aa, bb, cc, dd, ee and ff are hexadecimal numbers. Allowed values are any non-broadcast, non-multicast MAC and non-IEEE reserved MAC addresses.
- unnumbered
-
Specifies the static ARP MAC for an unnumbered interface. Unnumbered interfaces support dynamic ARP. Once this command is configured, it overrides any dynamic ARP.
Platforms
All
static-blackhole-first
static-blackhole-first
Syntax
[no] static-blackhole-first
Context
[Tree] (config>service>vprn>bgp-ipvpn>mpls>auto-bind-tunnel static-blackhole-first)
Full Context
configure service vprn bgp-ipvpn mpls auto-bind-tunnel static-blackhole-first
Description
This command configures the router to use a modified next-hop resolution sequence for each imported VPN-IP route. The router first checks for a static route in the Base routing table that matches the BGP next-hop address. If at least one such static route exists, and the route that is the longest match of the BGP next-hop address is a blackhole static route, the router resolves the VPN-IP route and programs it into the VPRN IP FIB table with a next-hop action that discards all matching packets. If there is no matching static route, or the longest matching static route is not a blackhole, the router resolves the VPN-IP route in the Base routing table as normal, that is, according to the configured VPRN auto-bind filter options.
The no form of this command configures the router to resolve VPN-IP routes in the Base routing table according to the configured VPRN auto-bind filter options.
Default
no static-blackhole-first
Platforms
All
static-cak
static-cak
Syntax
[no] static-cak
Context
[Tree] (config>macsec>connectivity-association static-cak)
Full Context
configure macsec connectivity-association static-cak
Description
This command allows the configuration of a Connectivity Association Key (CAK). The CAK is responsible for managing the MKA.
Platforms
All
static-entry
static-entry
Syntax
static-entry ip-prefix/ip-prefix-length upto prefix-length2 origin-as as-number [{valid | invalid}]
no static-entry ip-prefix/ip-prefix-length upto prefix-length2 origin-as as-number
Context
[Tree] (config>router>origin-validation static-entry)
Full Context
configure router origin-validation static-entry
Description
This command configures a static VRP entry indicating that a specific origin AS is either valid or invalid for a specific IP prefix range. Static VRP entries are stored along with dynamic VRP entries (learned from local cache servers using the RPKI-Router protocol) in the origin validation database of the router. This database is used for determining the origin-validation state of IPv4 and/or IPv6 BGP routes received over sessions with the enable-origin-validation command configured.
Static entries can only be configured under the config>router>origin-validation context of the base router.
Parameters
- ip-prefix/ip-prefix-length
-
Specifies an IPv4 or IPv6 address with a minimum prefix length value.
- prefix-length2
-
Specifies the maximum prefix length.
- as-number
-
Specifies as-number.
- valid
-
Specifies a keyword meaning the static entry expresses a valid combination of origin AS and prefix range.
- invalid
-
Specifies a keyword meaning the static entry expresses an invalid combination of origin AS and prefix range.
Platforms
All
static-function
static-function
Syntax
static-function
Context
[Tree] (config>router>segment-routing>srv6>locator static-function)
Full Context
configure router segment-routing segment-routing-v6 locator static-function
Description
Commands in this context configure the function field parameters of a static End, End.X, or service SID assignment.
Platforms
7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR
static-function
Syntax
static-function
Context
[Tree] (conf>router>sr>srv6>ms>block static-function)
Full Context
configure router segment-routing segment-routing-v6 micro-segment block static-function
Description
Commands in this context configure the function field parameters of a static uA or service micro-segment assignment.
Platforms
7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR
static-host
static-host
Syntax
static-host ip ip-prefix[/prefix-length] [mac ieee-address] [create]
no static-host ip ip-prefix[/prefix-length] [mac ieee-address]
no static-host all [force]
no static-host ip ip-prefix[/prefix-length]
Context
[Tree] (config>service>ies>sub-if>grp-if>sap static-host)
[Tree] (config>service>vprn>sub-if>grp-if>sap static-host)
Full Context
configure service ies subscriber-interface group-interface sap static-host
configure service vprn subscriber-interface group-interface sap static-host
Description
This command creates a static subscriber host for the SAP. Static subscriber hosts may be used by the system for various purposes. Applications within the system that make use of static host entries include anti-spoof, ARP reply agent and source MAC population into the VPLS forwarding database.
Multiple static hosts may be defined on the SAP. Each host is identified by either a source IP address, a source MAC address or both a source IP and source MAC address. Every static host definition must have at least one address defined, IP or MAC.
Static hosts can exist on the SAP even with anti-spoof and ARP reply agent features disabled. When enabled, each feature has different requirements for static hosts.
The no form of this command removes a static entry from the system. The specified ip-address and mac-address must match the host’s exact IP and MAC addresses as defined when it was created. When a static host is removed from the SAP, the corresponding anti-spoof filter entry and/or FDB entry is also removed.
Parameters
- ip-prefix[/prefix-length
-
Specifies information for the specified IP address and mask.
- mac-address
-
Specifies a MAC address. The MAC address must be specified for anti-spoof mac, and anti-spoof ip-mac and arp-reply-agent (arp-reply-agent is supported by the 7450 ESS only). Multiple static hosts may be configured with the same MAC address given that each definition is distinguished by a unique IP address.
Every static host definition must have at least one address defined, IP or MAC.
- force
-
Specifies the forced removal of the static host addresses.
- create
-
Keyword used to create the static host instance. The create keyword requirement can be enabled or disabled in the environment>create context.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
static-host
Syntax
static-host ip ip-address [mac ieee-address] [create]
static-host mac ieee-address [create]
no static-host ip ip-address mac ieee-address
no static-host all [force]
no static-host ip ip-address
Context
[Tree] (config>service>ies>if>sap static-host)
[Tree] (config>service>vpls>sap static-host)
[Tree] (config>service>vprn>if>sap static-host)
Full Context
configure service ies interface sap static-host
configure service vpls sap static-host
configure service vprn interface sap static-host
Description
This command creates a static subscriber host for the SAP. Static subscriber hosts may be used by the system for various purposes. Applications within the system that make use of static host entries include anti-spoof, ARP reply agent and source MAC population into the VPLS forwarding database.
Multiple static hosts may be defined on the SAP. Each host is identified by either a source IP address, a source MAC address or both a source IP and source MAC address. Every static host definition must have at least one address defined, IP or MAC.
Static hosts can exist on the SAP even with anti-spoof and ARP reply agent features disabled. When enabled, each feature has different requirements for static hosts.
The no form of this command removes a static entry from the system. The specified ip-address and mac-address must match the host’s exact IP and MAC addresses as defined when it was created. When a static host is removed from the SAP, the corresponding anti-spoof filter entry and/or FDB entry is also removed.
Parameters
- ip-address
-
Specify this optional parameter when defining a static host. The IP address must be specified for anti-spoof ip, anti-spoof ip-mac and arp-reply-agent (arp-reply-agent is supported by the 7450 ESS only). Only one static host may be configured on the SAP with a given IP address.
- mac-address
-
Specify this optional parameter when defining a static host. The MAC address must be specified for anti-spoof mac, and anti-spoof ip-mac and arp-reply-agent (arp-reply-agent is supported by the 7450 ESS only). Multiple static hosts may be configured with the same MAC address given that each definition is distinguished by a unique IP address.
Every static host definition must have at least one address defined, IP or MAC.
- force
-
Specifies the forced removal of the static host addresses.
- create
-
Keyword used to create the static host instance. The create keyword requirement can be enabled or disabled in the environment>create context.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
static-host-mgmt
static-host-mgmt
Syntax
static-host-mgmt
Context
[Tree] (config>service>vprn>sub-if>grp-if>sap static-host-mgmt)
[Tree] (config>service>ies>sub-if>grp-if>sap static-host-mgmt)
Full Context
configure service vprn subscriber-interface group-interface sap static-host-mgmt
configure service ies subscriber-interface group-interface sap static-host-mgmt
Description
Commands in this context configure common parameters for static hosts.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
static-isid
static-isid
static-label-range
static-label-range
Syntax
static-label-range static-range
no static-label-range
Context
[Tree] (config>router>mpls-labels static-label-range)
Full Context
configure router mpls-labels static-label-range
Description
This command configures the range of MPLS static label values shared among static LSP, MPLS-TP LSP, and static service VC label. Once this range is configured, it is reserved and cannot be used by other protocols such as RSVP, LDP, BGP, or Segment Routing to assign a label dynamically.
Default
static-label-range 18400
Parameters
- static-range
-
Specifies the size of the static label range in number of labels. The minimum label value in the range is 32. The maximum label value is therefore computed as {32+ static-range-1}.
Platforms
All
static-lsp
static-lsp
Syntax
[no] static-lsp lsp-name
Context
[Tree] (config>router>mpls static-lsp)
Full Context
configure router mpls static-lsp
Description
This command is used to configure a static LSP on the ingress router. The static LSP is a manually set up LSP where the nexthop IP address and the outgoing label (push) must be specified.
The no form of this command deletes this static LSP and associated information.
The LSP must be shutdown first in order to delete it. If the LSP is not shut down, the no static-lsp lsp-name command does nothing except generate a warning message on the console indicating that the LSP is administratively up.
Parameters
- lsp-name
-
Specifies the name that identifies the LSP.
Platforms
All
static-lsp-fast-retry
static-lsp-fast-retry
Syntax
static-lsp-fast-retry seconds
no static-lsp-fast-retry
Context
[Tree] (config>router>mpls static-lsp-fast-retry)
Full Context
configure router mpls static-lsp-fast-retry
Description
This command specifies the value used as the fast retry timer for a static LSP.
When a static LSP is trying to come up, the MPLS request for the ARP entry of the LSP next-hop may fail when it is made while the next-hop is still down or unavailable. In that case, MPLS starts a retry timer before making the next request. This enhancement allows the user to configure the retry timer, so that the LSP comes up as soon as the next-hop is up.
The no form of this command reverts to the default.
Default
no static-lsp-fast-retry
Parameters
- seconds
-
Specifies the value (in s), used as the fast retry timer for a static LSP.
Platforms
All
static-mac
static-mac
Syntax
static-mac ieee-mac-address [create]
no static-mac ieee-mac-address
Context
[Tree] (config>service>vpls>mesh-sdp static-mac)
[Tree] (config>service>vpls>spoke-sdp static-mac)
[Tree] (config>service>vpls>sap static-mac)
Full Context
configure service vpls mesh-sdp static-mac
configure service vpls spoke-sdp static-mac
configure service vpls sap static-mac
Description
This command creates a remote static MAC entry in the Virtual Private LAN Service (VPLS) forwarding database (FDB) associated with the service destination point (SDP).
In a VPLS service, MAC addresses are associated with a SAP or with an SDP. MACs associated with a SAP are classified as local MACs, and MACs associated with an SDP are remote MACs.
Local and remote static MAC entries create a permanent MAC address to SDP association in the forwarding database for the VPLS instance so that MAC address is not learned on the edge device.
Static MAC definitions on one edge device are not propagated to other edge devices participating in the VPLS instance, that is, each edge device has an independent forwarding database for the VPLS.
Only one static MAC entry (local or remote) can be defined per MAC address per VPLS instance.
By default, no static MAC address entries are defined for the SDP.
The no form of this command deletes the static MAC entry with the specified MAC address associated with the SDP from the VPLS forwarding database.
Parameters
- ieee-mac-address
-
Specifies the 48-bit MAC address for the static ARP in the form aa:bb:cc:dd :ee:ff or aa-bb-cc-dd -ee-ff where aa, bb, cc, dd, ee and ff are hexadecimal numbers. Allowed values are any non-broadcast, non-multicast MAC and non-IEEE reserved MAC addresses.
- create
-
Keyword used to create the static MAC instance. The create keyword requirement can be enabled or disabled in the environment>create context.
Platforms
All
static-mac
Syntax
static-mac
Context
[Tree] (config>service>vpls static-mac)
Full Context
configure service vpls static-mac
Description
A set of conditional static MAC addresses can be created within a VPLS supporting BGP-EVPN. Conditional Static Macs are also supported in B-VPLS with SPBs. Unless they are configured as black-hole, conditional Static Macs are dependent on the SAP/SDP state.
This command allows the assignment of a set of conditional Static MAC addresses to a SAP/ spoke-SDP or black-hole. In the FDB, the static MAC is then associated with the active SAP or spoke-SDP.
When configured in conjunction with SPBM services, Static MACs are used for PBB Epipe and I-VPLS services that may terminate external to SPBM. If this is configured under a Control B-VPLS the interface referenced will not use IS-IS for this neighbor. This may also be configured under a User B-VPLS where the corresponding interface is not supported under the Control B-VPLS.
Static MACs configured in a BGP-EVPN service are advertised as protected (EVPN will signal the MAC as protected).
Platforms
All
static-mac
Syntax
static-mac
Context
[Tree] (config>service>vpls>interface static-mac)
Full Context
configure service vpls interface static-mac
Description
A set of conditional static MAC addresses can be created within a VPLS supporting bgp-evpn. Conditional static macs are also supported in B-VPLS with SPBM. Conditional Static MACs are dependent on the SAP/SDP state.
This command allows assignment of a set of conditional static MAC addresses to a SAP/ spoke-SDP. In the FDB, the static MAC is then associated with the active SAP or spoke-SDP.
Static MACs are used for PBB Epipe and I-VPLS services that may terminate external to SPBM. If this is configured under a Control B-VPLS the interface referenced will not use IS-IS for this neighbor. This may also be configured under a User B-VPLS where the corresponding interface is not supported under the Control B-VPLS.
Static MACs configured in a bgp-evpn service are advertised as protected (EVPN will signal the mac as protected).
Platforms
All
static-mac
Syntax
static-mac ieee-address [create]
no static-mac ieee-address
Context
[Tree] (config>service>vpls>endpoint static-mac)
Full Context
configure service vpls endpoint static-mac
Description
This command assigns a static MAC address to the endpoint. In the FDB, the static MAC is then associated with the active spoke-SDP.
Parameters
- ieee-address
-
Specifies the static MAC address to the endpoint
- create
-
This keyword is mandatory while creating a static MAC
Platforms
All
static-policer
static-policer
Syntax
[no] static-policer policer-name [create]
Context
[Tree] (config>sys>security>dist-cpu-protection>policy static-policer)
Full Context
configure system security dist-cpu-protection policy static-policer
Description
Configures a static enforcement policer that can be referenced by one or more protocols in the policy. Once this policer-name is referenced by a protocol, then this policer will be instantiated for each object (for example, a SAP or network interface) that is created and references this policy. If there is no policer resource available on the associated card or fp then the object is be blocked from being created. Multiple protocols can use the same static-policer.
Parameters
- policy-name
-
Specifies the name of the policy, up to 32 characters.
Platforms
All
static-policy
static-policy
Syntax
static-policy name [ create]
no static-policy name
Context
[Tree] (conf>router>segment-routing>sr-policies static-policy)
Full Context
configure router segment-routing sr-policies static-policy
Description
This command creates a context to configure a segment routing policy. The resulting segment routing policy is targeted for local installation or propagation by BGP to another router.
The no form of this command deletes the statically defined segment routing policy.
Default
no static-policy
Parameters
- name
-
Specifies the name assigned to the statically defined segment routing policy, up to 64 characters.
- create
-
Keyword used to create the policy.
Platforms
All
static-policy-mpls
static-policy-mpls
Syntax
static-policy-mpls policy-name
no static-policy-mpls
Context
[Tree] (config>service>vprn>mvpn>pt>selective>p2mp-sr static-policy-mpls)
[Tree] (config>service>vprn>mvpn>pt>inclusive>p2mp-sr static-policy-mpls)
[Tree] (config>service>vprn>mvpn>pt>selective>multistream-spmsi static-policy-mpls)
Full Context
configure service vprn mvpn provider-tunnel selective p2mp-sr static-policy-mpls
configure service vprn mvpn provider-tunnel inclusive p2mp-sr static-policy-mpls
configure service vprn mvpn provider-tunnel selective multistream-spmsi static-policy-mpls
Description
This command assigns the specified static policy to the MVPN tunnel.
The no form of this command removes the static policy from the MVPN tunnel.
Default
no static-policy-mpls
Parameters
- policy-name
-
Specifies the policy name, up to 32 characters.
Platforms
All
static-remote-aa-sub
static-remote-aa-sub
Syntax
static-remote-aa-sub transit-aasub-name
static-remote-aa-sub transit-aasub-name app-profile app-profile-name [create]
no static-remote-aa-sub transit-aasub-name
Context
[Tree] (config>app-assure>group>transit-prefix-policy static-remote-aa-sub)
Full Context
configure application-assurance group transit-prefix-policy static-remote-aa-sub
Description
This command configures static remote transit aa-subs with a name and an app-profile. Remote transit subscribers are configured for sites on the opposite side of the system as the parent SAP/spoke- SDP. A new remote transit sub with both a name and an app-profile is configured with the create command. Static remote transit aa-subs must have an explicitly assigned app-profile. An existing remote transit sub can optionally be assigned a different app-profile.
The no form of this command removes the name from the transit prefix policy.
Parameters
- transit-aasub-name
-
Specifies a transit aasub-name up to 32 characters.
- app-profile-name
-
Specifies the name of an existing application profile up to 32 characters.
- create
-
Keyword used to create a new app-profile entry.
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
static-route
static-route
Syntax
[no] static-route route-name
Context
[Tree] (config>service>pw-routing static-route)
Full Context
configure service pw-routing static-route
Description
This command configures a static route to a next hop S-PE or T-PE. Static routes may be configured on either S-PEs or T-PEs.
A default static route is entered as follows:
static-route 0:0:next_hop_ip_addresss
or
static-route 0:0.0.0.0:next_hop_ip_address
The no form of this command removes a previously configured static route.
Parameters
- route-name
-
Specifies the static pseudowire route.
Platforms
All
static-route
Syntax
[no] static-route ip-prefix/ip-prefix-length next-hop ip-address
Context
[Tree] (bof static-route)
Full Context
bof static-route
Description
This command creates a static route entry for the CPM management Ethernet port in the running configuration and the Boot Option File (BOF).
This command allows manual configuration of static routing table entries. These static routes are only used by traffic generated by the CPM Ethernet port. To reduce configuration, manual address aggregation should be applied where possible.
A maximum of 10 static routes can be configured on the CPM port.
The no form of this command deletes the static route.
Default
no static-route
Parameters
- ip-prefix/ip-prefix-length
-
Specifies the destination address of the static route in dotted decimal notation.
- mask
-
Specifies the subnet mask, expressed as an integer or in dotted decimal notation.
- ip-address
-
Specifies the next hop IP address used to reach the destination.
Platforms
All
static-route-entry
static-route-entry
Syntax
static-route-entry ip-prefix/prefix-length [mcast]
no static-route-entry ip-prefix/prefix-length [mcast]
Context
[Tree] (config>service>vprn static-route-entry)
Full Context
configure service vprn static-route-entry
Description
This command creates a static route entry for both the network and access routes. A prefix and netmask must be specified.
Once the static route context for the specified prefix and netmask has been created, additional parameters associated with the static route(s) may be specified through the inclusion of additional static-route parameter commands.
The no form of this command deletes the static route entry. If a static route needs to be removed when multiple static routes exist to the same destination, then as many parameters to uniquely identify the static route must be entered.
IPv6 static routes are not supported on the 7450 ESS except in mixed mode.
Default
No static routes are defined.
Parameters
- ip-prefix/prefix-length
-
The destination address of the static route.
- mcast
-
Specifies that the associated static route should be populated in the associated VPRN multicast route table.
Platforms
All
static-route-entry
Syntax
[no] static-route-entry ip-prefix/prefix-length [mcast]
Context
[Tree] (config>router static-route-entry)
Full Context
configure router static-route-entry
Description
This command creates a static route entry for both the network and access routes. A prefix and netmask must be specified.
After the static route context for the specified prefix and netmask has been created, additional parameters associated with the static routes may be specified through the inclusion of additional static route parameter commands.
The no form of this command deletes the static route entry. If a static route needs to be removed when multiple static routes exist to the same destination, then as many parameters to uniquely identify the static route must be entered.
Default
No static routes are defined.
Parameters
- ip-prefix/prefix-length
-
Specifies the destination address of the static route.
- ip-address
-
Specifies the IP address of the IP interface. The ip-addr portion of the address command specifies the IP host address that will be used by the IP interface within the subnet. This address must be unique within the subnet and specified in dotted decimal notation.
- mcast
-
Indicates that static route being configured is used for multicast table only.
Platforms
All
static-route-hold-down
static-route-hold-down
Syntax
static-route-hold-down initial initial multiplier multiplier max-value max-value
no static-route-hold-down
Context
[Tree] (config>router static-route-hold-down)
Full Context
configure router static-route-hold-down
Description
This command enables the hold down time feature globally for static routes in the system.
The static route hold-down time is a mechanism to protect from rapid, fluctuating state changes of static routes resulting from issues with reachability because of link flap.
This command applies to all static routes in the VPRN and the base router instance in which this hold-down time is configured.
The no form of this command disables the hold down time feature globally for static routes in the system.
Default
no static-route-hold-down
Parameters
- initial
-
Specifies the initial value of the hold down time, in seconds, globally for static routes in the system.
- multiplier
-
Specifies the multiplier value of the hold down time feature globally for static routes in the system.
- max-value
-
Specifies the maximum value of the hold down time, in seconds, globally for static routes in the system.
Platforms
All
static-sa
static-sa
Syntax
static-sa sa-name [create]
no static-sa sa-name
Context
[Tree] (config>ipsec static-sa)
Full Context
configure ipsec static-sa
Description
This command configures an IPsec static SA.
Platforms
All
static-string
static-string
Syntax
static-string static-string
no static-string
Context
[Tree] (config>app-assure>group>http-enrich>field static-string)
Full Context
configure application-assurance group http-enrich field static-string
Description
This command configures an HTTP header enrichment template field static string.
The no form of this command removes the template field static string.
Default
no static-string
Parameters
- static-string
-
Specifies a static string.
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
static-tunnel-redundant-next-hop
static-tunnel-redundant-next-hop
Syntax
static-tunnel-redundant-next-hop ip-address
no static-tunnel-redundant-next-hop
Context
[Tree] (config>service>ies>if static-tunnel-redundant-next-hop)
[Tree] (config>service>vprn>if static-tunnel-redundant-next-hop)
Full Context
configure service ies interface static-tunnel-redundant-next-hop
configure service vprn interface static-tunnel-redundant-next-hop
Description
This command specifies redundant next-hop address on public or private IPsec interface (with public or private tunnel-sap) for static IPsec tunnel. The specified next-hop address will be used by standby node to shunt traffic to master in case of it receives them. Refer to the 7450 ESS, 7750 SR, and VSR Multiservice Integrated Service Adapter and Extended Services Appliance Guide for information about IPsec commands and descriptions.
The next-hop address will be resolved in routing table of corresponding service.
The no form of this command removes the address from the interface configuration.
Parameters
- ip-address
-
Specifies the static ISA tunnel redundant next-hop address.
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
station
station
Syntax
station station-name [create]
no station station-name
Context
[Tree] (config>bmp station)
Full Context
configure bmp station
Description
The command configures the BMP monitoring station name.
The no form of this command removes the station name from the configuration.
Parameters
- station-name
-
Specifies the station name of the BMP monitoring station up to 32 characters.
- create
-
Keyword used to create the station name. The create keyword requirement can be enabled or disabled in the environment>create context.
Platforms
All
station
Syntax
station all
station name [name]
no station
Context
[Tree] (config>service>vprn>bgp>group>neighbor>monitor station)
[Tree] (config>service>vprn>bgp>group>monitor station)
[Tree] (config>router>bgp>group>monitor station)
[Tree] (config>router>bgp>monitor station)
[Tree] (config>router>bgp>group>neighbor>monitor station)
Full Context
configure service vprn bgp group neighbor monitor station
configure service vprn bgp group monitor station
configure router bgp group monitor station
configure router bgp monitor station
configure router bgp group neighbor monitor station
Description
This command configures the set of BMP monitoring stations for which BMP messages are to be sent, at the global BGP instance level, per group or for a particular neighbor.
Whatever value is configured for the station parameter at the most specific BGP hierarchy level is used.
-
If a station list or the no station command is configured at a neighbor context, then that value is used.
-
If no station command is configured at the neighbor context, the group value is used.
-
If a station list or the no station command is configured at a group context, then that value is used.
-
If no station command is configured at the group context, the global value is used.
-
If a station list or the no station command is configured at the global context, then that value is used.
-
If no station command is configured at the global context, then a no station is assumed.
The no form of this command disables sending BMP messages to BMP monitoring stations.
Parameters
- name
-
Specifies up to eight station names up to 32 characters. Allowed values are any string up to 32 characters long composed of printable,7-bit ASCII characters. If the string contains special characters (#, ?, space), the entire string must be enclosed within double quotes.
- all
-
Specifies all configured stations.
Platforms
All
station-address
station-address
Syntax
station-address ip-address | ipv6-address port port
no station-address
Context
[Tree] (config>bmp>station>connection station-address)
Full Context
configure bmp station connection station-address
Description
This command configures the IP address and TCP port number of the remote BMP monitoring station. This is a mandatory parameter and must be configured before the associated station can transitioned out of the shut down state.
The no form of this command removes the configured station IP address and port number for the BMP session. The no station-address command cannot be accepted unless the BMP or station instance is shut down.
Parameters
- ip-address
-
Specifies the station address expressed in dotted decimal notation. Allowed value is a valid routable IP address on the router, either an interface or system IP address.
- ipv6-address
-
Specifies the station address expressed in dotted decimal notation. Allowed value is a valid routable IPv6 address on the router, either an interface or system IPv6 address.
- port
-
Specifies the TCP (destination) port number to be used when establishing the connection to the associated BMP station.
Platforms
All
statistic
statistic
Syntax
statistic type type name name
no statistic
Context
[Tree] (debug>wlan-gw>group statistic)
Full Context
debug wlan-gw group statistic
Description
This command enables debugging of the specified statistic. The first packet that causes an increase of the specified statistic is shown in debug output. After the first packet, debugging of the counter is stopped.
Parameters
- type
-
Displays the type of statistic to be debugged; for example, DHCP or RADIUS.
- name
-
Specifies the name, up to 256 characters, of the statistic within that group. For a complete list, see the command show isa wlan-gw-group wlan-gw-group-id member member-id statistics.
Platforms
7750 SR, 7750 SR-e, 7750 SR-s, VSR
statistics
statistics
Syntax
statistics
Context
[Tree] (config>app-assure>group statistics)
Full Context
configure application-assurance group statistics
Description
Commands in this context configure accounting and billing statistics for this AA ISA group.
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
statistics
Syntax
statistics
Context
[Tree] (config>isa>aa-grp statistics)
Full Context
configure isa application-assurance-group statistics
Description
Commands in this context configure statistics generation.
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
stats-collection
stats-collection
Syntax
stats-collection
Context
[Tree] (config>isa>tunnel-grp stats-collection)
Full Context
configure isa tunnel-group stats-collection
Description
Commands in this context configure ISA statistics collection parameters.
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
stats-report-interval
stats-report-interval
Syntax
stats-report-interval [seconds]
no stats-report-interval
Context
[Tree] (config>bmp>station stats-report-interval)
Full Context
configure bmp station stats-report-interval
Description
This command configures the frequency of sending statistics reporting messages to the BMP monitoring station.
The no form of this command removes the interval from the configuration.
Parameters
- seconds
-
Specifies the frequency of sending statistics reporting messages, in seconds, to the BMP monitoring station.
Platforms
All
stats-type
stats-type
Syntax
stats-type {time | volume-time}
no stats-type
Context
[Tree] (config>service>dynsvc>acct-1 stats-type)
[Tree] (config>service>dynsvc>acct-2 stats-type)
Full Context
configure service dynsvc acct-1 stats-type
configure service dynamic-services dynamic-services-policy accounting-2 stats-type
Description
This command configures the type of statistics to be reported in dynamic data services RADIUS accounting. A RADIUS specified Stats Type overrides the CLI configured value.
The no form of this command resets the default value.
Default
stats-type volume-time
Parameters
- time
-
Only report Session-Time in the RADIUS Accounting Interim-Update and Stop message.
- volume-time
-
Report both Session-Time and Volume counter attributes in the RADIUS. Accounting Interim-Update and Stop messages.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
stats-type
Syntax
stats-type {volume-time | time}
no stats-type
Context
[Tree] (config>service>dynsvc>ladb>user>idx>acct stats-type)
Full Context
configure service dynamic-services local-auth-db user-name index accounting stats-type
Description
This command specifies whether dynamic service accounting should be enabled or disabled for this destination. RADIUS accounting is enabled by specifying the stats type: volume and time or time only. This command overrides the local configured value in the dynamic services policy.
The no form of this command disables RADIUS accounting (stats-type off).
Parameters
- volume-time | time
-
Enables RADIUS accounting for this dynamic service and specifies if volume counters should be included (volume-time) or time only (time) in the RADIUS accounting messages.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
status-verify
status-verify
Syntax
status-verify
Context
[Tree] (config>service>ies>if>sap>ipsec-gw>cert status-verify)
[Tree] (config>service>ies>if>ipsec>ipsec-tunnel>dyn>cert status-verify)
[Tree] (config>service>vprn>if>sap>ipsec-gw>cert status-verify)
[Tree] (config>ipsec>trans-mode-prof>dyn>cert status-verify)
[Tree] (config>service>vprn>if>sap>ipsec-tun>dyn>cert status-verify)
[Tree] (config>router>if>ipsec>ipsec-tun>dyn>cert status-verify)
[Tree] (config>service>vprn>if>ipsec>ipsec-tunnel>dyn>cert status-verify)
Full Context
configure service ies interface sap ipsec-gw cert status-verify
configure service ies interface ipsec ipsec-tunnel dynamic-keying cert status-verify
configure service vprn interface sap ipsec-gw cert status-verify
configure ipsec ipsec-transport-mode-profile dynamic-keying cert status-verify
configure service vprn interface sap ipsec-tunnel dynamic-keying cert status-verify
configure router interface ipsec ipsec-tunnel dynamic-keying cert status-verify
configure service vprn interface ipsec ipsec-tunnel dynamic-keying cert status-verify
Description
Commands in this context configure Certificate Status Verification (CSV) parameters.
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
- configure ipsec ipsec-transport-mode-profile dynamic-keying cert status-verify
- configure service ies interface sap ipsec-gw cert status-verify
- configure service vprn interface sap ipsec-tunnel dynamic-keying cert status-verify
- configure service vprn interface sap ipsec-gw cert status-verify
VSR
- configure router interface ipsec ipsec-tunnel dynamic-keying cert status-verify
- configure service vprn interface ipsec ipsec-tunnel dynamic-keying cert status-verify
- configure service ies interface ipsec ipsec-tunnel dynamic-keying cert status-verify
status-verify
Syntax
status-verify default-result {revoked | good}
no status-verify
Context
[Tree] (config>system>security>tls>server-tls-profile status-verify)
[Tree] (config>system>security>tls>client-tls-profile status-verify)
Full Context
configure system security tls server-tls-profile status-verify
configure system security tls client-tls-profile status-verify
Description
This command configures the certificate revocation status verification parameters for end-entity (EE) certificates in the TLS client or server. This configuration overrides the existing revocation check policy.
By default the router checks the certification revocation status, but if this command is set to good, the end-entity certificate revocation status is overwritten and a good revocation status is returned for the EE certificate.
If this command is set to revoked, the router returns the actual revocation status of the end-entity certificate.
The no form of this command returns the actual revocation status to that of the end entity certificate.
Default
status-verify default-result revoked
Parameters
- good
-
Specifies that the certificate is considered acceptable.
- revoked
-
Specifies that the certificate is considered revoked.
Platforms
All
std-acct-attributes
std-acct-attributes
Syntax
[no] std-acct-attributes
Context
[Tree] (config>subscr-mgmt>acct-plcy>include-radius-attribute std-acct-attributes)
Full Context
configure subscriber-mgmt radius-accounting-policy include-radius-attribute std-acct-attributes
Description
This command enables reporting of aggregated forwarded IPv4 and IPv6 octet, packet and gigaword counters using standard RADIUS attributes. This attribute is by default. It can be enabled simultaneously with detailed per queue or policer counters (detailed-acct-attributes).
The no form of this command reverts to the default.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
std-port-class-pools
std-port-class-pools
Syntax
std-port-class-pools
Context
[Tree] (config>qos>hs-port-pool-policy std-port-class-pools)
Full Context
configure qos hs-port-pool-policy std-port-class-pools
Description
Commands in this context configure standard port-class pools parameters. Within this context, the corresponding port-class pools can be associated with a mid-pool, explicitly sized as a percentage of the mid-pool size, dynamically-sized based on relative port bandwidth, or have a slope policy applied.
Platforms
7750 SR-7/12/12e
steering-profile
steering-profile
Syntax
steering-profile steering-profile-name
no steering-profile
Context
[Tree] (config>subscr-mgmt>loc-user-db>ppp>host steering-profile)
Full Context
configure subscriber-mgmt local-user-db ppp host steering-profile
Description
This command configures the steering profile for the specific host.
The no form of this command removes the steering profile for the host.
Parameters
- steering-profile-name
-
Specifies the name of the steering profile, up to 32 characters.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
steering-profile
Syntax
steering-profile steering-profile-name [create]
no steering-profile steering-profile-name
Context
[Tree] (config>subscr-mgmt steering-profile)
Full Context
configure subscriber-mgmt steering-profile
Description
This command configures a steering profile mapping. A steering profile can be applied to each L2TP LAC subscriber host that requires traffic steering.
The no form of this command removes the specified steering profile.
Parameters
- steering-profile-name
-
Specifies the name of the steering profile, up to 32 characters.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
steering-profile
Syntax
[no] steering-profile
Context
[Tree] (config>subscr-mgmt>acct-plcy>include-radius-attribute steering-profile)
Full Context
configure subscriber-mgmt radius-accounting-policy include-radius-attribute steering-profile
Description
This command enables including the Alc-Steering-Profile RADIUS attribute.
The no form of the command disables including the Alc-Steering-Profile RADIUS attribute.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
steering-route
steering-route
Syntax
steering-route ip-prefix/length
no steering-route
Context
[Tree] (config>service>vprn>nat>inside>redundancy steering-route)
Full Context
configure service vprn nat inside redundancy steering-route
Description
This command configures specifies the IP address and prefix length of the steering route. The steering route is used in the realm of this virtual router instance as an indirect next-hop for all the traffic that must be routed to the large scale NAT function.
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
steering-route
Syntax
steering-route ip-prefix/length
no steering-route
Context
[Tree] (config>router>nat>inside>redundancy steering-route)
Full Context
configure router nat inside redundancy steering-route
Description
This command is optionally used in LSN44 multi-chassis redundancy when filters are used on the inside to send traffic destined for the LSN44 function to MS-ISA, where NAT is performed.
If configured, the steering-route is advertised only from the active LSN44 node: the purpose is to bring the LSN44 node activity awareness to downstream routers. In this fashion, downstream routers can make a more intelligent decision when forwarding traffic in the upstream direction. Based on the steering-route, traffic can be sent directly towards the active LSN44 node. This route avoids an extra forwarding hop which would ensue in the case without LSN44 activity awareness, where the upstream traffic can be forwarded to the standby LSN44 node and then to the active LSN44 node.
LSN44 node activity (active/standby) is evaluated per isa-group based on monitoring routes advertised on the outside.
The no form of the command removes the ip-prefix/length from the configuration.
Parameters
- ip-prefix/length
-
Specifies the IP address and length of the steering route.
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
sticky-dest
sticky-dest
Syntax
sticky-dest hold-time-up
sticky-dest no-hold-time-up
no sticky-dest
Context
[Tree] (config>filter>ip-filter>entry sticky-dest)
[Tree] (config>filter>ipv6-filter>entry sticky-dest)
[Tree] (config>filter>redirect-policy sticky-dest)
[Tree] (config>filter>mac-filter>entry sticky-dest)
Full Context
configure filter ip-filter entry sticky-dest
configure filter ipv6-filter entry sticky-dest
configure filter redirect-policy sticky-dest
configure filter mac-filter entry sticky-dest
Description
This command configures sticky destination behavior for redundant PBR/PBF actions. Configuring sticky destination has an effect on PBR/PBF actions whether a secondary action is configured.
The hold-time-up parameter allows the operator to delay programming of a PBR/PBF action for a specified amount of time. The timer is only started when transitioning from all configured targets being down (that is, the primary target if no secondary target is configured, or both the primary and secondary targets when both are configured) to at least one target being up.
When the timer expires, the primary PBR/PBF action is programmed if its target is up. If the primary PBR/PBF target is down and a secondary PBR/PBF action has been configured and its target is up, then this secondary PBR/PBF action is programmed. In all other cases, no specific programming occurs when the timer expires.
When sticky destination is configured and the secondary PBR/PBF target is up and its associated action is programmed, it is not automatically replaced by the primary PBR/PBF action when its target transitions from down to up. In this situation, programming the primary PBR/PBF action can be forced using the activate-primary-action tools command.
Changing the value of the timer while the timer is running takes effect immediately (that is, the timer is restarted immediately using the new value).
The no form of the command disables sticky destination behavior.
Default
no sticky-dest
Parameters
- hold-time-up
-
Specifies the initial delay in seconds. Zero is equivalent to no-hold-time-up (no delay).
Platforms
All
sticky-dr
sticky-dr
Syntax
sticky-dr [priority dr-priority]
no sticky-dr
Context
[Tree] (config>service>vprn>pim>if sticky-dr)
Full Context
configure service vprn pim interface sticky-dr
Description
This command enables sticky-dr operation on this interface. When enabled, the priority in PIM hellos sent on this interface when elected as the designated router (DR) is modified to the value configured in dr-priority. This is done to avoid the delays in forwarding caused by DR recovery, when switching back to the old DR on a LAN when it comes back up.
By enabling sticky-dr on this interface, it will continue to act as the DR for the LAN even after the old DR comes back up.
The no form of this command disables sticky-dr operation on this interface.
Default
no sticky-dr
Parameters
- priority dr-priority
-
Sets the DR priority to be sent in PIM Hello messages following the election of that interface as the DR, when sticky-dr operation is enabled.
Platforms
All
sticky-dr
Syntax
sticky-dr [priority dr-priority]
no sticky-dr
Context
[Tree] (config>router>pim>interface sticky-dr)
Full Context
configure router pim interface sticky-dr
Description
This command enables sticky-dr operation on this interface. When enabled, the priority in PIM hellos sent on this interface when elected as the designated router (DR) will be modified to the value configured in dr-priority. This is done to avoid the delays in forwarding caused by DR recovery, when switching back to the old DR on a LAN when it comes back up.
By enabling sticky-dr on this interface, it will continue to act as the DR for the LAN even after the old DR comes back up.
The no form of this command disables sticky-dr operation on this interface.
Default
no sticky-dr
Parameters
- priority dr-priority
-
Sets the DR priority to be sent in PIM Hello messages following the election of that interface as the DR, when sticky-dr operation is enabled.
Platforms
All
sticky-ecmp
sticky-ecmp
Syntax
sticky-ecmp
no sticky-ecmp
Context
[Tree] (config>router>policy-options>policy-statement>default-action sticky-ecmp)
[Tree] (config>router>policy-options>policy-statement>entry>action sticky-ecmp)
Full Context
configure router policy-options policy-statement default-action sticky-ecmp
configure router policy-options policy-statement entry action sticky-ecmp
Description
This command specifies that BGP routes matching an entry or default-action of a route policy should be tagged internally as requiring sticky ECMP behavior. When a BGP route with multiple equal-cost BGP next-hops is programmed for sticky ECMP the failure of one or more of its BGP next-hops causes only the affected traffic flows to be re-distributed to the remaining next-hops; by default (without sticky-ECMP) all flows are potentially affected, even those using a next-hop that did not fail.
Default
no sticky-ecmp
Platforms
All
sticky-msaps
sticky-msaps
Syntax
sticky-msaps [idle-timeout seconds]
no sticky-msaps
Context
[Tree] (config>subscr-mgmt>msap-policy sticky-msaps)
Full Context
configure subscriber-mgmt msap-policy sticky-msaps
Description
This command prevents MSAPs associated with the specified MSAP policy from being deleted unless a manual clear command is issued. If this command is not enabled, an MSAP is deleted when a host creation fails or when a subscriber is no longer associated with the MSAP, for example, when a subscriber ends the session. This feature is useful for an operator who wants to keep historical statistics on MSAPs. It can also speed up host creation on an MSAP since the MSAP is already created. The idle-timeout parameter allows the removal of MSAPs that are idle for longer than the specified time.
The no form of this command allows an MSAP to be deleted when a host creation fails or when a subscriber is no longer associated with the MSAP.
Default
no sticky-msaps
Parameters
- seconds
-
Specifies the idle timeout, in seconds.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
stp
stp
Syntax
[no] stp
Context
[Tree] (config>service>vpls>pbb>backbone-vpls stp)
Full Context
configure service vpls pbb backbone-vpls stp
Description
This command enables or disable STP through B-VPLS service.
Platforms
All
stp
Syntax
[no] stp
Context
[Tree] (config>service>vpls>pbb>bvpls stp)
Full Context
configure service vpls pbb backbone-vpls stp
Description
This command enables STP on the backbone VPLS service.
The no form of this command disables STP on the backbone VPLS service.
Platforms
All
stp
Syntax
stp
Context
[Tree] (config>service>template>vpls-sap-template stp)
[Tree] (config>service>vpls>spoke-sdp stp)
[Tree] (config>service>template>vpls-template stp)
[Tree] (config>service>vpls stp)
[Tree] (config>service>vpls>sap stp)
Full Context
configure service template vpls-sap-template stp
configure service vpls spoke-sdp stp
configure service template vpls-template stp
configure service vpls stp
configure service vpls sap stp
Description
Commands in this context configure the Spanning Tree Protocol (STP) parameters. Nokia’s STP is simply the Spanning Tree Protocol (STP) with a few modifications to better suit the operational characteristics of VPLS services. The most evident change is to the root bridge election. Since the core network operating between Nokia’s service routers should not be blocked, the root path is calculated from the core perspective.
Platforms
All
stp
Syntax
[no] stp
Context
[Tree] (debug>service>id stp)
Full Context
debug service id stp
Description
Commands in this context debug STP.
The no form of the command disables debugging.
Platforms
All
stp
Syntax
stp
Context
[Tree] (config>service>pw-template stp)
Full Context
configure service pw-template stp
Description
Commands in this context configure the Spanning Tree Protocol (STP) parameters. The STP is simply the Spanning Tree Protocol (STP) with a few modifications to better suit the operational characteristics of VPLS services. The most evident change is to the root bridge election. Since the core network operating between service routers should not be blocked, the root path is calculated from the core perspective.
Platforms
All
stream-run-type
stream-run-type
Syntax
stream-run-type {sequential | parallel}
no stream-run-type
Context
[Tree] (config>test-oam>sath>svc-test stream-run-type)
Full Context
configure test-oam service-activation-testhead service-test stream-run-type
Description
This command configures the execution sequence for service streams that are run during the specified service test.
The no form of this command removes the configured run type.
Default
stream-run-type parallel
Parameters
- sequential
-
Keyword to run the streams consecutively.
- parallel
-
Keyword to run the streams in parallel.
Platforms
7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS
stream-selection
stream-selection
Syntax
[no] stream-selection
Context
[Tree] (config>isa>video-group stream-selection)
Full Context
configure isa video-group stream-selection
Description
This command specifies whether or not stream selection is enabled on this video group.
The no form of the command disables stream-selection for the group.
Default
no stream-selection
Platforms
7450 ESS, 7750 SR, 7750 SR-s
streaming
streaming
Syntax
streaming
Context
[Tree] (config>oam-pm streaming)
Full Context
configure oam-pm streaming
Description
This command specifies the context to configure the OAM-PM streaming template and its associated parameters.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
streaming
Syntax
streaming
Context
[Tree] (config>system>snmp streaming)
Full Context
configure system snmp streaming
Description
This command enables the proprietary SNMP request/response bundling and TCP-based transport mechanism for optimizing network management of the router nodes. In higher latency networks, synchronizing router MIBs from network management via streaming takes less time than synchronizing via classic SNMP UDP requests. Streaming operates on TCP port 1491 and runs over IPv4 or IPv6.
Platforms
All
strict
strict
Syntax
[no] strict
Context
[Tree] (config>app-assure>group>tcp-validate strict)
Full Context
configure application-assurance group tcp-validate strict
Description
This command specifies whether enforcement of TCP sequence and acknowledgment numbers is applied. If a packet does not meet the expected sequence or acknowledgment number, it is dropped.
This command should only be enabled if the expected bit error rate or packet loss is low. For example, if acknowledgments are lost before being detected by AA, the server timeouts are triggered and retransmissions occur. If strict is enabled, these retransmissions would resemble a reply attack and would be dropped by AA.
The no form of this command removes TCP sequence and acknowledgment number enforcement.
Default
no strict
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
strict-adjacency-check
strict-adjacency-check
Syntax
[no] strict-adjacency-check
Context
[Tree] (config>service>vprn>isis strict-adjacency-check)
Full Context
configure service vprn isis strict-adjacency-check
Description
This command enables strict checking of address families (IPv4 and IPv6) for IS-IS adjacencies. When enabled, adjacencies do not come up unless both routers have exactly the same address families configured. If there is an existing adjacency with unmatched address families, it is torn down.
This command is used to prevent black-holing traffic when IPv4 and IPv6 topologies are different. When disabled (no strict-adjacency-check) a BFD session failure for either IPv4 or IPv6 will cause the routes for the other address family to be removed as well.
When disabled (no strict-adjacency-check), both routers only need to have one common address family to establish the adjacency.
Default
no strict-adjacency-check
Platforms
All
strict-adjacency-check
Syntax
[no] strict-adjacency-check
Context
[Tree] (config>router>isis strict-adjacency-check)
Full Context
configure router isis strict-adjacency-check
Description
This command enables strict checking of address families (IPv4 and IPv6) for IS-IS adjacencies. When enabled, adjacencies will not come up unless both routers have exactly the same address families configured. If there is an existing adjacency with unmatched address families, it will be torn down. This command is used to prevent black-holing traffic when IPv4 and IPv6 topologies are different. When disabled (no strict-adjacency-check) a BFD session failure for either IPv4 or Ipv6 will cause the routes for the other address family to be removed as well.
When disabled (no strict-adjacency-check), both routers only need to have one common address family to establish the adjacency.
Platforms
All
strict-ero-nhop-direct-resolution
strict-ero-nhop-direct-resolution
Syntax
[no] strict-ero-nhop-direct-resolution
Context
[Tree] (config>router>mpls strict-ero-nhop-direct-resolution)
Full Context
configure router mpls strict-ero-nhop-direct-resolution
Description
This command enables the strict Explicit Route Object (ERO) next-hop direct resolution. The feature restricts the routes used to resolve the next hop of an ERO address to local and host routes. This command avoids using a next hop over a parallel link when a half link is up in the routing table.
When enabled, this command applies to an ERO when all of the following conditions are met:
-
the ERO next hop is an IPv4 address
-
the ERO object is a strict hop
-
the IPv4 address matches the primary subnet of a local numbered interface
An ERO that meets the preceding conditions restricts resolution of the next hop to a LOCAL or a HOST route. If no such route exists, RSVP rejects the PATH message with ErrCode = Routing Error (24) and SubErrCode = Bad Strict Node (2).
The no form of this command disables the strict ERO next-hop direct resolution.
Default
no strict-ero-nhop-direct-resolution
Platforms
All
strict-esp-seq-number-ordering
strict-esp-seq-number-ordering
Syntax
[no] strict-esp-seq-number-ordering
Context
[Tree] (config>isa>tunnel-grp strict-esp-seq-number-ordering)
Full Context
configure isa tunnel-group strict-esp-seq-number-ordering
Description
This command configures the router to use strict ESP sequence number ordering.
When ESP sequence number ordering is enabled, the outbound ESP sequence number of a CHILD_SA must be in the same order as when clear packets are received by the same CHILD_SA.
The no form of this command disables strict ESP sequence number ordering.
Default
no strict-esp-seq-number-ordering
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s
strict-lsa-checking
strict-lsa-checking
Syntax
[no] strict-lsa-checking
Context
[Tree] (config>service>vprn>ospf>graceful-restart strict-lsa-checking)
[Tree] (config>service>vprn>ospf3>graceful-restart strict-lsa-checking)
Full Context
configure service vprn ospf graceful-restart strict-lsa-checking
configure service vprn ospf3 graceful-restart strict-lsa-checking
Description
This command indicates whether an OSPF restart helper should terminate graceful restart when there is a change to an LSA that would be flooded to the restarting router during the restart process.
The default OSPF behavior is to terminate a graceful restart if an LSA changes, which causes the OSPF neighbor to go down.
The no strict-lsa-checking command disables strict LSA checking.
Default
strict-lsa-checking
Platforms
All
strict-lsa-checking
Syntax
[no] strict-lsa-checking
Context
[Tree] (config>router>ospf3>graceful-restart strict-lsa-checking)
[Tree] (config>router>ospf>graceful-restart strict-lsa-checking)
Full Context
configure router ospf3 graceful-restart strict-lsa-checking
configure router ospf graceful-restart strict-lsa-checking
Description
This command indicates whether an OSPF restart helper should terminate graceful restart when there is a change to an LSA that would be flooded to the restarting router during the restart process.
The default OSPF behavior is to terminate a graceful restart if an LSA changes, which causes the OSPF neighbor to go down.
The no form of this command disables strict LSA checking.
Default
strict-lsa-checking
Platforms
All
strict-mode
strict-mode
Syntax
[no] strict-mode
Context
[Tree] (config>service>upnp>upnp-policy strict-mode)
Full Context
configure service upnp upnp-policy strict-mode
Description
This command enable UPnP strict mode. With strict-mode, system only allows changes to existing UPnP mapping if the request comes from same UPnP client.
Default
no strict-mode
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
string
string
Syntax
string string
no string
Context
[Tree] (config>subscr-mgmt>loc-user-db>ipoe>host>host-ident string)
Full Context
configure subscriber-mgmt local-user-db ipoe host host-identification string
Description
This command specifies the string from the Nokia vendor-specific sub-option (VSO) in Option 82 to match when the LUDB is accessed using a DHCPv4 server.
This command is only used when string is configured as one of the match-list parameters.
The no form of this command removes the host identification string from the configuration.
Parameters
- string
-
Specifies the VSO string of this host, up to 255 characters.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
string
Syntax
[no] string text
Context
[Tree] (config>service>vpls>sap>dhcp>option>vendor string)
[Tree] (config>service>vprn>if>dhcp>option>vendor string)
[Tree] (config>service>ies>sub-if>grp-if>dhcp>option>vendor string)
[Tree] (config>subscr-mgmt>msap-policy>vpls-only>dhcp>option>vendor string)
[Tree] (config>service>vprn>sub-if>grp-if>dhcp>option>vendor string)
Full Context
configure service vpls sap dhcp option vendor-specific-option string
configure service vprn interface dhcp option vendor-specific-option string
configure service ies subscriber-interface group-interface dhcp option vendor-specific-option string
configure subscriber-mgmt msap-policy vpls-only-sap-parameters dhcp option vendor-specific-option string
configure service vprn subscriber-interface group-interface dhcp option vendor-specific-option string
Description
This command specifies the string in the Nokia vendor-specific sub-option of the DHCP relay packet.
The no form of this command reverts to the default.
Parameters
- text
-
Specifies a string that can be any combination of ASCII characters, up to 32 characters. If spaces are used in the string, enclose the entire string in quotation marks (" ").
Platforms
All
- configure service vprn interface dhcp option vendor-specific-option string
- configure service vpls sap dhcp option vendor-specific-option string
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
- configure service vprn subscriber-interface group-interface dhcp option vendor-specific-option string
- configure service ies subscriber-interface group-interface dhcp option vendor-specific-option string
- configure subscriber-mgmt msap-policy vpls-only-sap-parameters dhcp option vendor-specific-option string
string
Syntax
[no] string text
Context
[Tree] (config>router>if>dhcp>option>vendor-specific-option string)
Full Context
configure router interface dhcp option vendor-specific-option string
Description
This command specifies the vendor-specific sub-option string of the DHCP relay packet.
The no form of this command returns the default value.
Default
no string
Parameters
- text
-
Specifies a string that can be any combination of ASCII characters, up to 32 characters in length. If spaces are used in the string, enclose the entire string in quotation marks (" ”).
Platforms
All
strings-from-option
strings-from-option
Syntax
strings-from-option dhcp-option-number
no strings-from-option
Context
[Tree] (config>subscr-mgmt>sub-ident-pol strings-from-option)
Full Context
configure subscriber-mgmt sub-ident-policy strings-from-option
Description
This command enables DHCPv4 option processing on DHCP ACK for subscriber host identification.
The parameter dhcp-option-number specifies the DHCPv4 option number containing subscriber host identification strings such as subscriber ID, sub-profile, sla-profile strings, and so on. The identification strings can be inserted by an SR OS based DHCPv4 server via a local user database lookup.
Applicable to DHCPv4 hosts and PPP hosts that use the internal DHCP client to get an IPv4 address from an SR OS based DHCPv4 server.
The no form of this command reverts to the default.
Default
no strings-from-option
Parameters
- dhcp-option-number
-
Specifies the DHCPv4 option number containing subscriber host identification strings.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
strip-label
strip-label
Syntax
[no] strip-label
Context
[Tree] (config>router>if strip-label)
Full Context
configure router interface strip-label
Description
This command forces packets to be stripped of all (max 5) MPLS labels before the packets are handed over for possible filter (PBR) processing.
If the packets do not have an IP header immediately following the MPLS label stack after the strip, they are discarded. Only MPLS encapsulated IP, IGP shortcuts and VPRN over MPLS packets will be processed. However, IPv4 and IPv6 packets that arrive without any labels are supported on an interface with strip-label enabled.
This command operates in promiscuous mode. This means that the router does not filter on the destination MAC address of the Ethernet frames. In some network designs, multiple ports may be tapped and combined into interface toward the router. Promiscuous mode allows all of these flows to be processed without requiring the destination MAC address to be updated to match the router address.
This command is supported on:
-
Optical ports for the 7750 SR and 7450 ESS
-
Null/Dot1q encaps
-
Network ports
-
IPv4
-
IPv6
In order to associate an interface that is configured with the strip-label parameter with a port, the port must be configured as single-fiber for the command to be valid.
Packets that are subject to the strip-label action and are mirrored (using mirrors or lawful interception) will contain the original MPLS labels (and other L2 encapsulation) in the mirrored copy of the packet, as they appeared on the wire, when the mirror-dest type is the default type "ether”. If the mirror-dest type is "ip-only”, then the mirrored copy of the packet will not contain the original L2 encapsulation or the stripped MPLS labels.
The no form of this command removes the strip-label command.
Default
no strip-label
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
strip-srv6-tlvs
strip-srv6-tlvs
Syntax
[no] strip-srv6-tlvs
Context
[Tree] (config>router>bgp>group>srv6>route>fam strip-srv6-tlvs)
[Tree] (config>router>bgp>group>neighbor>srv6>route>family strip-srv6-tlvs)
Full Context
configure router bgp group segment-routing-v6 route-advertisement family strip-srv6-tlvs
configure router bgp group neighbor segment-routing-v6 route-advertisement family strip-srv6-tlvs
Description
This command specifies that BGP routes that belong to the address family configured in the family command are advertised to peers with SRv6 TLVs removed. Locally or remotely added SRv6 TLVs can be removed.
The no form of this command configures the router not to strip SRv6 TLVs from the BGP routes advertised to peers.
Default
no strip-srv6-tlvs
Platforms
7450 ESS, 7750 SR, 7750 SR-s, 7950 XRS, VSR
stub
stub
Syntax
[no] stub
Context
[Tree] (config>service>vprn>ospf>area stub)
[Tree] (config>service>vprn>ospf3>area stub)
Full Context
configure service vprn ospf area stub
configure service vprn ospf3 area stub
Description
This command enables access to the context to configure an OSPF stub area and adds/removes the stub designation from the area. External routing information is not flooded into stub areas. All routers in the stub area must be configured with the stub command. An OSPF area cannot be both an NSSA and a stub area. Existing virtual links of a non STUB or NSSA area will be removed when its designation is changed to NSSA or STUB.
By default, an area is not a stub area.
The no form of this command removes the stub designation and configuration context from the area.
Default
no stub — The area is not configured as a stub area.
Platforms
All
stub
Syntax
[no] stub
Context
[Tree] (config>router>ospf>area stub)
[Tree] (config>router>ospf3>area stub)
Full Context
configure router ospf area stub
configure router ospf3 area stub
Description
This command enables access to the context to configure an OSPF or OSPF3 stub area and adds/removes the stub designation from the area.
External routing information is not flooded into stub areas. All routers in the stub area must be configured with the stub command. An OSPF or OSPF3 area cannot be both an NSSA and a stub area.
Existing virtual links of a non STUB or NSSA area will be removed when its designation is changed to NSSA or STUB.
By default, an area is not a stub area.
The no form of this command removes the stub designation and configuration context from the area.
Default
no stub
Platforms
All
sub-domain
sub-domain
Syntax
sub-domain sub-domain
no sub-domain
Context
[Tree] (config>service>vprn>mvpn>provider-tunnel>selective>bier sub-domain)
[Tree] (config>service>vprn>mvpn>provider-tunnel>inclusive>bier sub-domain)
Full Context
configure service vprn mvpn provider-tunnel selective bier sub-domain
configure service vprn mvpn provider-tunnel inclusive bier sub-domain
Description
This command sets the sub-domain used to attach the BIER provider tunnel. Both PMSI within the MVPN need to have the same sub-domain.
The no form of this command removes the sub-domain.
Parameters
- sub-domain
-
The identifier of the sub-domain.
Platforms
All
sub-domain
Syntax
[no] sub-domain sub-domain
[no] sub-domain start sub-domain end sub-domain
Context
[Tree] (config>router>bier>template sub-domain)
Full Context
configure router bier template sub-domain
Description
This command creates a BIER sub-domain or range of sub-domains. For example, for IS-IS each sub-domain is associated with a single IS-IS topology, which may be any of the topologies supported by IS-IS.
The no form of this command removes a sub-domain.
Default
sub-domain 0
Parameters
- sub-domain
-
The ID of the sub-domain to be created or removed.
Platforms
All
sub-host-trk
sub-host-trk
Syntax
[no] sub-host-trk
Context
[Tree] (config>redundancy>multi-chassis>peer>sync sub-host-trk)
Full Context
configure redundancy multi-chassis peer sync sub-host-trk
Description
This command specifies whether subscriber host tracking information should be synchronized with the multi-chassis peer.
Default
no sub-host-trk
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
sub-hosts-only
sub-hosts-only
Syntax
[no] sub-hosts-only
Context
[Tree] (config>service>vprn>igmp>grp-if sub-hosts-only)
Full Context
configure service vprn igmp group-interface sub-hosts-only
Description
This command enables the IGMP traffic from known hosts only.
The no form of this command disable the IGMP traffic from known hosts only
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
sub-hosts-only
Syntax
[no] sub-hosts-only
Context
[Tree] (config>router>igmp>group-interface sub-hosts-only)
Full Context
configure router igmp group-interface sub-hosts-only
Description
This command disables the processing of IGMP messages outside of the subscriber-host context. No other hosts outside of the subscriber-hosts can create IGMP states.
Disabling this command allows the creation of the IGMP states that correspond to the AN that operate in IGMP proxy mode. In this mode, the AN will hide source IP addresses of IGMP messages and will source IGMP messages with its own IP address. In this case, an IGMP state can be created under the sap context. This IGMP state creation under the SAP is controlled via the import policy under the group-interface.
The IGMP state processing for regular subscriber-hosts is unaffected by this command.
The no form of the command disables the command.
Default
sub-hosts-only
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
sub-hosts-only
Syntax
[no] sub-hosts-only
Context
[Tree] (config>router>mld>group-interface sub-hosts-only)
Full Context
configure router mld group-interface sub-hosts-only
Description
This command processes the handling of MLD joins received from hosts that are not known in subscriber management or on which no MLD policy is applied.
Disabling this command allows the creation of the MLD states that correspond to the AN that operate in MLD proxy mode. In this mode, the AN will hide source IP addresses of MLD messages and will source MLD messages with its own IP address. In this case, an MLD state can be created under the sap context. This MLD state creation under the SAP is controlled via the import policy under the group-interface.
The MLD state processing for regular subscriber-hosts is unaffected by this command.
The no form of the command enables the command.
Default
sub-hosts-only
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
sub-id
sub-id
Syntax
[no] sub-id
Context
[Tree] (config>service>nat>syslog>syslog-export-policy>include sub-id)
Full Context
configure service nat syslog syslog-export-policy include sub-id
Description
This command includes the sub-id string in the flow log. The sub-id is applicable only in subscriber-aware NAT. If subscriber-aware NAT is not enabled, the sub-id string is set to '-'.
The no form of the command disables the feature.
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
sub-ident-policy
sub-ident-policy
Syntax
[no] sub-ident-policy sub-ident-policy-name
Context
[Tree] (config>subscr-mgmt sub-ident-policy)
Full Context
configure subscriber-mgmt sub-ident-policy
Description
This command configures a subscriber identification policy. Each subscriber identification policy can have a default subscriber profile defined. The subscriber identification policy default subscriber profile overrides the system default and the subscriber SAP default subscriber profiles. Defining a subscriber identification policy default subscriber profile is optional.
The subscriber identification policy default subscriber profile cannot be defined with the subscriber profile name default.
Defining a subscriber profile as a subscriber identification policy default subscriber profile will cause all active subscribers currently associated with a subscriber SAP using the policy and associated with a subscriber policy through the system default or subscriber SAP default subscriber profiles to be reassigned to the subscriber policy defined as default on the subscriber identification policy.
Attempting to delete a subscriber profile that is currently defined as a default for a subscriber identification policy will fail.
When attempting to remove a subscriber identification policy default subscriber profile definition, the system will evaluate each active subscriber on all subscriber SAPs the subscriber identification policy is currently associated with that are using the default definition to determine whether the active subscriber can be either reassigned to a subscriber SAP default or the system default subscriber profile. If all active subscribers cannot be reassigned, the removal attempt will fail.
The no form of this command reverts to the default.
Parameters
- sub-ident-policy-name
-
Specifies the name of the subscriber identification policy, up to 32 characters.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
sub-ident-policy
Syntax
sub-ident-policy sub-ident-policy-name
Context
[Tree] (config>service>vprn>sub-if>grp-if>sap>sub-sla-mgmt sub-ident-policy)
[Tree] (config>service>ies>sub-if>grp-if>sap>sub-sla-mgmt sub-ident-policy)
[Tree] (config>service>vpls>sap>sub-sla-mgmt sub-ident-policy)
[Tree] (config>subscr-mgmt>msap-policy>sub-sla-mgmt sub-ident-policy)
[Tree] (config>service>ies>sub-if>grp-if>sap-parameters>sub-sla-mgmt sub-ident-policy)
[Tree] (config>service>vprn>sub-if>grp-if>sap-parameters>sub-sla-mgmt sub-ident-policy)
Full Context
configure service vprn subscriber-interface group-interface sap sub-sla-mgmt sub-ident-policy
configure service ies subscriber-interface group-interface sap sub-sla-mgmt sub-ident-policy
configure service vpls sap sub-sla-mgmt sub-ident-policy
configure subscriber-mgmt msap-policy sub-sla-mgmt sub-ident-policy
configure service ies subscriber-interface group-interface sap-parameters sub-sla-mgmt sub-ident-policy
configure service vprn subscriber-interface group-interface sap-parameters sub-sla-mgmt sub-ident-policy
Description
This command associates a subscriber identification policy to this SAP. The subscriber identification policy must be defined prior to associating the profile with a SAP in the config>subscr-mgmt>sub-ident-policy context.
Subscribers are managed by the system through the use of subscriber identification strings such as a subscriber identifier, an sla-profile string, a sub-profile string and an app-profile string.
The subscriber identification policy performs following functions for subscriber hosts and sessions associated with the SAP or MSAP:
-
mapping of sla-profile, sub-profile and app-profile strings obtained from authentication (for example, LUDB, RADIUS, Diameter, or Python) into profile names that are configured on the router
-
for IPoE DHCPv4 hosts, the subscriber identification strings can be derived from the DHCP ACK message sent to the subscriber host using a Python script referenced in the sub-ident-policy
-
for PPPoE hosts that get an IPv4 address via the PPPoE DHCPv4 client and for IPoE DHCPv4 hosts, an SR OS DHCPv4 server in combination with an LUDB returns the identification strings in a DHCPv4 option. The strings-from-option command in the sub-ident-policy tells the system from which option to extract the identification strings.
The no form of this command removes the default subscriber identification policy from the SAP configuration.
Parameters
- sub-ident-policy-name
-
Specifies a subscriber identification policy for this SAP.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
- configure service ies subscriber-interface group-interface sap sub-sla-mgmt sub-ident-policy
- configure service vprn subscriber-interface group-interface sap sub-sla-mgmt sub-ident-policy
- configure subscriber-mgmt msap-policy sub-sla-mgmt sub-ident-policy
- configure service vpls sap sub-sla-mgmt sub-ident-policy
7750 SR, 7750 SR-e, 7750 SR-s, VSR
- configure service vprn subscriber-interface group-interface sap-parameters sub-sla-mgmt sub-ident-policy
- configure service ies subscriber-interface group-interface sap-parameters sub-sla-mgmt sub-ident-policy
sub-ident-policy
Syntax
[no] sub-ident-policy policy-name
Context
[Tree] (debug>subscr-mgmt sub-ident-policy)
Full Context
debug subscriber-mgmt sub-ident-policy
Description
This command debugs subscriber identification policies.
The no form of this command disables debugging.
Parameters
- policy-name
-
Specifies the subscriber identification policy to debug.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
sub-ident-policy
Syntax
sub-ident-policy sub-ident-policy-name
no sub-ident-policy
Context
[Tree] (config>app-assure>group>transit-ip-policy sub-ident-policy)
Full Context
configure application-assurance group transit-ip-policy sub-ident-policy
Description
This command associates a subscriber identification policy to this SAP. The subscriber identification policy must be defined prior to associating the profile with a SAP in the config>subscribermgmt>sub-ident-policy context.
Subscribers are managed by the system through the use of subscriber identification strings. A subscriber identification string uniquely identifies a subscriber. For static hosts, the subscriber identification string is explicitly defined with each static subscriber host.
For dynamic hosts, the subscriber identification string must be derived from the DHCP ACK message sent to the subscriber host. The default value for the string is the content of Option 82 CIRCUIT-ID and REMOTE-ID fields interpreted as an octet string. As an option, the DHCP ACK message may be processed by a subscriber identification policy which has the capability to parse the message into an alternative ASCII or octet string value.
When multiple hosts on the same port are associated with the same subscriber identification string they are considered to be host members of the same subscriber.
A sub-ident-policy can also be used for identifying dynamic transit subscriber names.
The no form of this command removes the default subscriber identification policy from the SAP configuration.
Default
no sub-ident-policy
Parameters
- sub-ident-policy-name
-
Specifies the subscriber identification policy name, up to 32 characters.
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
sub-insert-credit-control
sub-insert-credit-control
Syntax
sub-insert-credit-control start-entry entry-id count count
no sub-insert-credit-control
Context
[Tree] (config>filter>ipv6-filter sub-insert-credit-control)
[Tree] (config>filter>ip-filter sub-insert-credit-control)
Full Context
configure filter ipv6-filter sub-insert-credit-control
configure filter ip-filter sub-insert-credit-control
Description
This command inserts point information for credit control for the filter.
The no form of the command reverts to the default.
Default
no sub-insert-credit-control
Parameters
- entry-id
-
Identifies a filter on this system.
- count
-
Specifies the count
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
sub-insert-radius
sub-insert-radius
Syntax
sub-insert-radius start-entry entry-id count count
no sub-insert-radius
Context
[Tree] (config>filter>ipv6-filter sub-insert-radius)
[Tree] (config>filter>ip-filter sub-insert-radius)
Full Context
configure filter ipv6-filter sub-insert-radius
configure filter ip-filter sub-insert-radius
Description
This command inserts point information for RADIUS for the filter.
The no form of the command reverts to the default.
Default
no sub-insert-radius
Parameters
- entry-id
-
Specifies at what place the filter entries received from RADIUS will be inserted in the filter.
- count
-
Specifies the count.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
sub-insert-shared-pccrule
sub-insert-shared-pccrule
Syntax
sub-insert-shared-pccrule start-entry entry-id count count
no sub-insert-shared-pccrule
Context
[Tree] (config>qos>sap-ingress sub-insert-shared-pccrule)
[Tree] (config>qos>sap-egress sub-insert-shared-pccrule)
Full Context
configure qos sap-ingress sub-insert-shared-pccrule
configure qos sap-egress sub-insert-shared-pccrule
Description
This command defines the range of filter and QoS policy entries that are reserved for shared entries received in Flow-Information AVP via Gx interface (PCC rules – Policy and Charging Control).
The no form of this command disables the insertion, which will result in a failure of PCC rule installation.
Default
no sub-insert-shared-pccrule
Parameters
- entry-id
-
Specifies the lowest entry in the range.
- count
-
Specifies the number of entries in the range.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
sub-insert-shared-pccrule
Syntax
sub-insert-shared-pccrule start-entry entry-id count count
no sub-insert-shared-pccrule
Context
[Tree] (config>filter>ipv6-filter sub-insert-shared-pccrule)
[Tree] (config>filter>ip-filter sub-insert-shared-pccrule)
Full Context
configure filter ipv6-filter sub-insert-shared-pccrule
configure filter ip-filter sub-insert-shared-pccrule
Description
This command defines the range of filter and QoS policy entries that are reserved for shared entries received in Flow-Information AVP via Gx interface (PCC rules – Policy and Charging Control). The no form of this command disables the insertion, which will result in a failure of PCC rule installation.
Default
no sub-insert-shared-pccrule
Parameters
- entry-id
-
Specifies the lowest entry in the range.
- count
-
Specifies the number of entries in the range.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
sub-insert-shared-radius
sub-insert-shared-radius
Syntax
sub-insert-shared-radius start-entry entry-id count count
no sub-insert-shared-radius
Context
[Tree] (config>filter>ip-filter sub-insert-shared-radius)
[Tree] (config>filter>ipv6-filter sub-insert-shared-radius)
Full Context
configure filter ip-filter sub-insert-shared-radius
configure filter ipv6-filter sub-insert-shared-radius
Description
This command configures the insert point for shared host rules from RADIUS.
Default
no sub-insert-shared-radius
Parameters
- entry-id
-
Identifies a filter on this system.
- count
-
Specifies the count.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
sub-insert-wmark
sub-insert-wmark
Syntax
sub-insert-wmark low low-watermark high high-watermark
no sub-insert-wmark
Context
[Tree] (config>filter>ipv6-filter sub-insert-wmark)
[Tree] (config>filter>ip-filter sub-insert-wmark)
Full Context
configure filter ipv6-filter sub-insert-wmark
configure filter ip-filter sub-insert-wmark
Description
This command configures the low and high watermark percentage for inserted filter entry usage reporting.
The no form of the command reverts to the default.
Default
sub-insert-wmark low 90 high 95
Parameters
- low-watermark
-
Specifies the utilization of the filter ranges for filter entry insertion, at which a table full alarm will be cleared by the agent.
- high-watermark
-
Specifies the utilization of the filter ranges for filter entry insertion, at which a table full alarm will be raised by the agent.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
sub-mcac-policy
sub-mcac-policy
Syntax
sub-mcac-policy sub-mcac-policy-name [create]
no sub-mcac-policy b
Context
[Tree] (config>subscr-mgmt sub-mcac-policy)
Full Context
configure subscriber-mgmt sub-mcac-policy
Description
This command creates a policy template with MCAC bandwidth limits that are applied to the subscriber.
Per interface mcac bandwidth limits are set directly under the interface (regular interface or group-interface) and no such policy templates are needed.
The need for a separate policy template for subscribers is due to the fact that groups of subscribers under the same group-interface can share certain settings that can be configured via this template.
To summarize, the MCAC bandwidth constraints for subscribers are defined in the sub-mcac-policy while the mcac bandwidth constraints for the interface are configured directly under the igmp>interface>mcac or igmp>grp-if>mcac context without the need for policy templates.
The sub-mcac-policy only deals with the mcac bandwidth limits and not the channel bandwidth definitions. Channels bandwidth is defined in a different policy (in the config>router>mcac context) and that policy is applied on the interface level as follows:
-
For group-interface: under the config>service>vprn>igmp>grp-if>mcac context
-
For regular interface: under the config>service/router>igmp>interface>mcac context.
In case of HQoS Adjustment, it is mandatory that the sub-mcac-policy be created and applied to the subscriber. The sub-mac-policy does not have to contain any bandwidth constrains, but it has to be in a no shutdown state in order for HQoS Adjustment to work.
The no form of this command reverts to the default.
Parameters
- policy-name
-
Specifies the name of the policy up to 32 characters.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s
sub-mcac-policy
Syntax
sub-mcac-policy policy-name
no sub-mcac-policy
Context
[Tree] (config>subscr-mgmt>sub-prof sub-mcac-policy)
Full Context
configure subscriber-mgmt sub-profile sub-mcac-policy
Description
This command references the policy template in which the mcac bandwidth limits are defined. Mcac for the subscriber is effectively enabled with this command when the sub-profile is applied to the subscriber. The bandwidth of the channels is defined in a different policy (under the config>router>mcac context) and this policy is applied on the interface level as follows:
-
For group-interfaces under the config>service>vprn>igmp>grp-if>mcac context
-
For regular interfaces under the config>service/router>igmp>interface>mcac context
In case of HQoS Adjustment, it is mandatory that the sub-mcac-policy be created and applied to the subscriber. The sub-mac-policy does not have to contain any bandwidth constrains, but it has to be in a no shutdown state in order for HQoS Adjustment to work.
The no form of this command removes the policy from the configuration.
Parameters
- policy-name
-
Specifies the policy name configured in the config>subscr-mgmt>sub-mcac-policy context.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s
sub-mgmt
sub-mgmt
Syntax
[no] sub-mgmt
Context
[Tree] (config>redundancy>multi-chassis>options sub-mgmt)
Full Context
configure redundancy multi-chassis options sub-mgmt
Description
This command enables the CLI context to configure subscriber management multi-chassis options parameters.
Default
sub-mgmt
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
sub-mgmt-extensions
sub-mgmt-extensions
Syntax
[no] sub-mgmt-extensions
Context
[Tree] (config>fwd-path-ext>fpe sub-mgmt-extensions)
Full Context
configure fwd-path-ext fpe sub-mgmt-extensions
Description
This command configures FPE for subscriber management extensions. The FPE cannot be used for other applications but can be used for multiple subscriber management applications.
The no version of this command disables FPE for subscriber management extensions.
Default
no sub-mgmt-extensions
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
sub-port
sub-port
Syntax
sub-port port-id [create]
no sub-port port-id
Context
[Tree] (config>port>ethernet>dot1x>macsec sub-port)
Full Context
configure port ethernet dot1x macsec sub-port
Description
This command creates a MACsec instance on a physical port, targeting the specific subset of traffic defined by the encap-match command.
The no form of this command removes the MACsec instance.
Parameters
- port-id
-
Specifies the sub-port id index.
- create
-
Creates a new sub-port.
Platforms
All
sub-profile
sub-profile
Syntax
[no] sub-profile
Context
[Tree] (config>subscr-mgmt>acct-plcy>include-radius-attribute sub-profile)
Full Context
configure subscriber-mgmt radius-accounting-policy include-radius-attribute sub-profile
Description
This command specifies that subscriber profile attributes should be included into RADIUS accounting messages.
The no form of this command excludes subscriber profile attributes into RADIUS accounting messages.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
sub-profile
Syntax
sub-profile sub-profile-name
no sub-profile
Context
[Tree] (config>service>vprn>sub-if>grp-if>sap>static-host sub-profile)
[Tree] (config>service>vprn>if>sap>static-host sub-profile)
[Tree] (config>service>ies>if>sap>static-host sub-profile)
[Tree] (config>service>vpls>sap>static-host sub-profile)
[Tree] (config>service>ies>sub-if>grp-if>sap>static-host sub-profile)
Full Context
configure service vprn subscriber-interface group-interface sap static-host sub-profile
configure service vprn interface sap static-host sub-profile
configure service ies interface sap static-host sub-profile
configure service vpls sap static-host sub-profile
configure service ies subscriber-interface group-interface sap static-host sub-profile
Description
This command specifies an existing subscriber profile name to be associated with the static subscriber host.
The no form of this command reverts to the default.
Parameters
- sub-profile-name
-
Specifies the sub-profile name.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
sub-profile
Syntax
[no] sub-profile subscriber-profile-name
Context
[Tree] (config>subscr-mgmt sub-profile)
Full Context
configure subscriber-mgmt sub-profile
Description
Commands in this context configure a subscriber profile. A subscriber profile is a template used to define the aggregate QoS for all hosts within a subscriber context. This is done through the definition of the egress and ingress scheduler policies that govern the aggregate SLA for subscribers using the subscriber profile. Subscriber profiles also allow for specific SLA profile definitions when the default definitions from the subscriber identification policy must be overridden.
Subscribers are either explicitly mapped to a subscriber profile template or are dynamically associated by one of various non-provisioned subscriber profile definitions.
A subscriber host can be associated with a subscriber profile in the following ways, listed from lowest to highest precedence:
-
The subscriber profile named default.
-
The subscriber profile defined as the subscriber SAP default.
-
The subscriber profile found by the subscriber identification policy sub-profile-map.
-
The subscriber profile found by the subscriber identification policy explicit map.
In the event that no defaults are defined and the subscriber identification string is not explicitly provisioned to map to a subscriber profile, either the static subscriber host creation will fail or the dynamic subscriber host DHCP ACK is discarded.
Default Subscriber profile:
When a subscriber profile is created with the subscriber-profile-name default, it is used when no other subscriber profile is associated with the subscriber host by the system. Creating a subscriber profile with the subscriber-profile-name default is optional. If a default subscriber profile is not created, all subscriber hosts subscriber identification strings must match either a non-provisioned default or be provisioned as an explicit match to a subscriber profile.
The default profile has no effect on existing active subscriber on the system as they exist due to higher precedence mappings.
Attempting to delete any subscriber profile (including the profile named default) while in use by existing active subscribers will fail.
The no form of this command reverts to the default.
Parameters
- subscriber-profile-name
-
Specifies the name of the subscriber profile, up to 32 characters.
- create
-
Keyword used to create the subscriber profile.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
sub-profile-map
sub-profile-map
Syntax
sub-profile-map
Context
[Tree] (config>subscr-mgmt>sub-ident-pol sub-profile-map)
Full Context
configure subscriber-mgmt sub-ident-policy sub-profile-map
Description
Commands in this context configure subscriber profile mapping parameters.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
sub-profile-string
sub-profile-string
Syntax
sub-profile-string sub-profile-string
no sub-profile-string
Context
[Tree] (config>subscr-mgmt>loc-user-db>ppp>host>ident-strings sub-profile-string)
[Tree] (config>subscr-mgmt>loc-user-db>ipoe>host>ident-strings sub-profile-string)
Full Context
configure subscriber-mgmt local-user-db ppp host identification-strings sub-profile-string
configure subscriber-mgmt local-user-db ipoe host identification-strings sub-profile-string
Description
This command specifies the subscriber profile string which is encoded in the identification strings.
The no form of this command returns to the default.
Parameters
- sub-profile-string
-
Specifies the subscriber profile string, up to 32 characters.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
sub-profile-string
Syntax
sub-profile-string string
no sub-profile-string
Context
[Tree] (config>subscr-mgmt>vrgw>brg>brg-profile sub-profile-string)
Full Context
configure subscriber-mgmt vrgw brg brg-profile sub-profile-string
Description
This string will be used as a default for subscriber-profile lookup. This string can be overridden during BRG or host authentication. The no form of the command removes the string from the configuration.
Default
no sub-profile-string
Parameters
- string
-
Specifies the string used to look up the subscriber profile.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
sub-ring
sub-ring
Syntax
[no] sub-ring {virtual-link | non-virtual-link}
Context
[Tree] (config>eth-ring sub-ring)
Full Context
configure eth-ring sub-ring
Description
This command specifies this ring-id to be sub-ring as defined in G.80312. By declaring this ring as a sub-ring object, this ring will only have one valid path and the sub-ring will be connected to a major ring or a VPLS instance.
The virtual-link keyword declares that a sub-ring is connected to another ring and control messages can be sent over the attached ring to the other side of the sub-ring.
The non-virtual-link channel parameter declares that a sub-ring may be connected to another ring or to a VPLS instance but no control messages from the sub-ring use the attached ring or VPLS instance. The non-virtual channel behavior is standard G.8032 capability.
The no form of this command deletes the sub-ring and its virtual channel associations.
Default
no sub-ring
Parameters
- virtual-link
-
Specifies that the interconnection is to a ring and a virtual link will be used.
- non-virtual-link
-
Specifies that the interconnection is to a ring or a VPLS instance and a virtual link will not be used.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
sub-sla-mgmt
sub-sla-mgmt
Syntax
[no] sub-sla-mgmt
Context
[Tree] (config>service>ies>sub-if>grp-if>sap sub-sla-mgmt)
[Tree] (config>service>vprn>sub-if>grp-if>sap sub-sla-mgmt)
[Tree] (config>subscr-mgmt>msap-policy sub-sla-mgmt)
[Tree] (config>service>vpls>sap sub-sla-mgmt)
[Tree] (config>service>ies>if>sap sub-sla-mgmt)
[Tree] (config>service>vprn>if>sap sub-sla-mgmt)
Full Context
configure service ies subscriber-interface group-interface sap sub-sla-mgmt
configure service vprn subscriber-interface group-interface sap sub-sla-mgmt
configure subscriber-mgmt msap-policy sub-sla-mgmt
configure service vpls sap sub-sla-mgmt
configure service ies interface sap sub-sla-mgmt
configure service vprn interface sap sub-sla-mgmt
Description
Commands in this context configure subscriber management parameters for this SAP.
The no form of this command reverts to the default.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
- configure service vpls sap sub-sla-mgmt
- configure service ies subscriber-interface group-interface sap sub-sla-mgmt
- configure subscriber-mgmt msap-policy sub-sla-mgmt
- configure service vprn subscriber-interface group-interface sap sub-sla-mgmt
All
- configure service vprn interface sap sub-sla-mgmt
- configure service ies interface sap sub-sla-mgmt
sub-sla-mgmt
Syntax
[no] sub-sla-mgmt
Context
[Tree] (config>service>ies>sub-if>grp-if>sap-parameters sub-sla-mgmt)
[Tree] (config>service>vprn>sub-if>grp-if>sap-parameters sub-sla-mgmt)
Full Context
configure service ies subscriber-interface group-interface sap-parameters sub-sla-mgmt
configure service vprn subscriber-interface group-interface sap-parameters sub-sla-mgmt
Description
Commands in this context configure subscriber management parameters.
The no form of this command removes the parameters from the configuration.
Default
sub-sla-mgmt
Platforms
7750 SR, 7750 SR-e, 7750 SR-s, VSR
subinterface
subinterface
Syntax
subinterface subinterface
no subinterface
Context
[Tree] (config>router>if>extref>oc subinterface)
[Tree] (config>svc>vprn>if>extref>oc subinterface)
Full Context
configure router interface external-reference openconfig subinterface
configure service vprn interface external-reference openconfig subinterface
Description
This command configures the subinterface ID used to map a Nokia vendor-specific configuration and the OpenConfig state.
This command configures the ability to query the OpenConfig state through NETCONF, gRPC, and the MD-CLI from any configuration mode without having to add any OpenConfig model configuration. As part of the configuration, a user must also add a port to the Layer 3 interface.
The no form of this command reverts to the default.
Default
no subinterface
Parameters
- subinterface
- Specifies the subinterface ID.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
subject
subject
Syntax
subject {eq | neq} subject [regexp]
no subject
Context
[Tree] (config>service>vprn>log>filter>entry>match subject)
Full Context
configure service vprn log filter entry match subject
Description
This command adds an event subject as a match criterion.
The subject is the entity for which the event is reported, such as a port. In this case the port-id string would be the subject. Only one subject command can be entered per event filter entry. The latest subject command overwrites the previous command.
The no form of this command removes the subject match criterion.
Default
no subject
Parameters
- eq | neq
-
This operator specifies the type of match. Valid operators are listed below.
- subject
-
A string used as the subject match criterion.
- regexp
-
Specifies the type of string comparison to use to determine if the log event matches the value of subject command parameters. When the regexp keyword is specified, the string in the subject command is a regular expression string that will be matched against the subject string in the log event being filtered.
When regexp keyword is not specified, the subject command string is matched exactly by the event filter.
Platforms
All
subject
Syntax
subject {eq | neq} subject [regexp]
no subject
Context
[Tree] (config>log>filter>entry>match subject)
Full Context
configure log filter entry match subject
Description
This command adds an event subject as a match criterion.
The subject is the entity for which the event is reported, such as a port. In this case the port-id string would be the subject. Only one subject command can be entered per event filter entry. The latest subject command overwrites the previous command.
The no form of this command removes the subject match criterion.
Parameters
- eq | neq
-
Specifies the match type. Valid operators are listed in Valid Operators.
Table 2. Valid Operators Operator
Notes
eq
equal to
neg
not equal to
- subject
-
Specifies a string up to 32 characters, used as the subject match criterion.
- regexp
-
Specifies the type of string comparison to use to determine if the log event matches the value of subject command parameters. When the regexp keyword is specified, the string in the subject command is a regular expression string that will be matched against the subject string in the log event being filtered. When the regexp keyword is not specified, the subject command string is matched exactly by the event filter.
Platforms
All
subnet
subnet
Syntax
subnet {ip-address/mask | ip-address netmask} [create]
no subnet {ip-address/mask | ip-address netmask}
Context
[Tree] (config>service>vprn>dhcp>server>pool subnet)
[Tree] (config>router>dhcp>server>pool subnet)
Full Context
configure service vprn dhcp local-dhcp-server pool subnet
configure router dhcp local-dhcp-server pool subnet
Description
This command creates a subnet of IP addresses to be served from the pool. The subnet cannot include any addresses that were assigned to subscribers without those addresses specifically excluded. When the subnet is created, no IP addresses are made available until a range is defined.
The no form of the removes the subnet parameters from the configuration.
Parameters
- ip-prefix/mask
-
Specifies the address prefix and mask. A mask of 255.255.255.255 is reserved for system IP addresses.
- netmask
-
Specifies a string of 0s and 1s that mask or screen out the network part of an IP address so that only the host computer part of the address remains.
- create
-
Keyword used to create the subnet. The create keyword requirement can be enabled or disabled in the environment>create context.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
subnet-check
subnet-check
Syntax
[no] subnet-check
Context
[Tree] (config>service>vprn>igmp>grp-if subnet-check)
[Tree] (config>service>vprn>igmp>if subnet-check)
Full Context
configure service vprn igmp group-interface subnet-check
configure service vprn igmp interface subnet-check
Description
This command enables subnet checking for IGMP messages received on this interface. All IGMP packets with a source address that is not in the local subnet are dropped.
The no form of this command disables local subnet checking for IGMP.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
- configure service vprn igmp group-interface subnet-check
All
- configure service vprn igmp interface subnet-check
subnet-check
Syntax
[no] subnet-check
Context
[Tree] (config>router>igmp>if subnet-check)
[Tree] (config>router>igmp>group-interface subnet-check)
Full Context
configure router igmp interface subnet-check
configure router igmp group-interface subnet-check
Description
This command enables subnet checking for IGMP messages received on this interface. All IGMP packets with a source address that is not in the local subnet are dropped.
Default
subnet-check
Platforms
All
- configure router igmp interface subnet-check
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
- configure router igmp group-interface subnet-check
subnet-check
Syntax
[no] subnet-check
Context
[Tree] (config>router>mld>group-interface subnet-check)
Full Context
configure router mld group-interface subnet-check
Description
This command enables subnet checking for MLD messages received on this interface. All MLD packets with a source address that is not in the local subnet are dropped.
Default
subnet-check
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
subnet-mask
subnet-mask
Syntax
subnet-mask ip-address
no subnet-mask
Context
[Tree] (config>router>dhcp>server>pool>subnet>options subnet-mask)
[Tree] (config>subscr-mgmt>loc-user-db>ipoe>host>options subnet-mask)
Full Context
configure router dhcp local-dhcp-server pool subnet options subnet-mask
configure subscriber-mgmt local-user-db ipoe host options subnet-mask
Description
This command specifies the subnet-mask option to the client. The mask can either be defined (for supernetting) or taken from the pool address.
The no form of this command removes the address from the configuration.
Parameters
- ip-address
-
Specifies the IP address of the subnet mask. This address must be unique within the subnet and specified in dotted decimal notation. Allowed values are IP addresses in the range 1.0.0.0 – 223.255.255.255 (with support of /31 subnets).
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
subrate
subrate
Syntax
subrate {digital-link | larscom} rate-step
no subrate
Context
[Tree] (config>port>tdm>ds3 subrate)
Full Context
configure port tdm ds3 subrate
Description
This command configures the channel service unit (CSU) compatibility mode to interoperate with existing DS-3 subrate standards.
This configuration applies only for non-channelized DS-3s on ASAP TDM MDAs.
The no form of this command remove the subrate functionality.
Default
no subrate
Parameters
- digital-link
-
Enables the Digital-Link (Quick Eagle) CSU compatibility mode.
- larscom
-
Enables the Larscom CSU compatibility mode.
- rate-step
-
Specifies the subrate value for the associated DS-3.
Platforms
7450 ESS, 7750 SR-7/12/12e, 7750 SR-a, 7750 SR-e
subscriber
subscriber
Syntax
subscriber sub-ident
no subscriber
Context
[Tree] (config>service>vprn>sub-if>grp-if>sap>static-host subscriber)
[Tree] (config>service>vpls>sap>static-host subscriber)
[Tree] (config>service>vprn>if>sap>static-host subscriber)
[Tree] (config>service>ies>sub-if>grp-if>sap>static-host subscriber)
[Tree] (config>service>ies>if>sap>static-host subscriber)
Full Context
configure service vprn subscriber-interface group-interface sap static-host subscriber
configure service vpls sap static-host subscriber
configure service vprn interface sap static-host subscriber
configure service ies subscriber-interface group-interface sap static-host subscriber
configure service ies interface sap static-host subscriber
Description
This command specifies an existing subscriber identification profile to be associated with the static subscriber host.
Parameters
- sub-ident
-
Specifies the subscriber identification.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
subscriber
Syntax
subscriber sub-ident-string [sap sap-id] [ip ip-address] [{[mac ieee-address] | sla-profile sla-profile-name}] [fc {[be] [l2] [af] [l1] [ h2] [ef] [h1] [nc]}] {[ingress] [ egress]} [host-type host-type] [family family]
no subscriber sub-ident-string
Context
[Tree] (config>mirror>mirror-source subscriber)
Full Context
configure mirror mirror-source subscriber
Description
This command adds hosts of a subscriber to mirroring service.
Parameters
- sub-ident-string
-
Specifies the name of the subscriber identification policy.
- sap-id
-
Specifies the physical port identifier portion of the SAP definition.
- ip-address
-
Specifies the service IP address (system IP address) of the remote device sending LI traffic. If 0.0.0.0 is specified, any remote router is allowed to send to this service.
- ieee-address
-
Specify this optional parameter when defining a static host. The MAC address must be specified for anti-spoof ip-mac and arp-populate. Multiple static hosts may be configured with the same MAC address given that each definition is distinguished by a unique IP address.
- sla-profile-name
-
Each host of a subscriber can use a different sla-profile. This option allows interception of only the hosts using the specified sla-profile. In some deployments sla-profiles are assigned per type of traffic. There can be, for example, a specific sla-profile for voice traffic (which could be used for all SIP-hosts). The name can have up to 32 characters.
- fc
-
Specifies the name of the forwarding class with which to associate traffic. The forwarding class name must already be defined within the system. If the fc-name does not exist, an error will be returned and the fc command will have no effect. If the fc-name does exist, the forwarding class associated with fc-name will override the default forwarding class.
- egress
-
Specifies that packets egressing the SAP should be mirrored. Egress packets are mirrored to the mirror destination after egress packet modification.
- ingress
-
Specifies that packets ingressing the SAP should be mirrored. Ingress packets are mirrored to the mirror destination prior to ingress packet modification.
- host-type
-
Specifies the host type for mirroring. The anti-spoof filter on the SAP must be configured as ip-mac.
- family
-
Specifies the IP family for mirroring. The anti-spoof filter on the SAP must be configured as ip-mac.
Platforms
All
subscriber
Syntax
subscriber sub-ident-string [sap sap-id [ip ip-address] [mac ieee-address] | sla-profile sla-profile-name] [fc {[be] [l2] [af] [l1] [ h2] [ef] [h1] [nc]}] [intercept-id intercept-id] [session-id session-id] {[ingress] [egress]} [ host-type host-type] [family ip-family]
no subscriber sub-ident-string
Context
[Tree] (config>li>li-source subscriber)
Full Context
configure li li-source subscriber
Description
This command adds hosts of a subscriber to mirroring service.
Parameters
- sub-ident-string
-
Specifies the name of the subscriber identification policy.
- sap-id
-
Specifies the physical port identifier portion of the SAP definition.
- ip-address
-
Specifies the service IP address (system IP address) of the remote device sending LI traffic. If 0.0.0.0 is specified, any remote router is allowed to send to this service.
- ieee-address
-
Specifies a MAC address when defining a static host. The MAC address must be specified for anti-spoof ip-mac and arp-populate. Multiple static hosts may be configured with the same MAC address given that each definition is distinguished by a unique IP address.
- sla-profile-name
-
Specifies an SLA profile name, up to 32 characters. Each host of a subscriber can use a different sla-profile. This option allows interception of only the hosts using the specified sla-profile. In some deployments sla-profiles are assigned per type of traffic. There can be, for example, a specific sla-profile for voice traffic (which could be used for all SIP-hosts).
- fc
-
The name of the forwarding class with which to associate LI traffic. The forwarding class name must already be defined within the system. If the fc-name does not exist, an error will be returned and the fc command will have no effect. If the fc-name does exist, the forwarding class associated with fc-name will override the default forwarding class.
- intercept-id
-
Specifies the intercept-id that is inserted into the packet header for all mirrored packets of the associated li-source entry. This intercept-id can be used (for example by a downstream LI Gateway) to identify the particular LI session to which the packet belongs.
For all types of li-source entries (filter, nat, sap, or subscriber), when the mirror service is configured with ip-udp-shim routable encap, an intercept-id field (as part of the routable encap) is always present in the mirrored packets. If there is no intercept-id configured for an li-source entry, then the default value will be inserted. When the mirror service is configured with ip-gre or ip-udp-shim-sampled routable encap, no intercept-id is inserted and none can be specified against the li-source entries.
- session-id
-
Specifies the session-id that is inserted into the packet header for all mirrored packets of the associated li-source entry. This session-id can be used (for example by a downstream LI gateway) to identify the particular LI session to which the packet belongs. The session-id is only valid and used for mirror services that are configured with ip-udp-shim routable encapsulation (config>mirror>mirror-dest>encap>ip-udp-shim).
For all types of li-source entries (filter, nat, sap, or subscriber), when the mirror service is configured with ip-udp-shim routable encap, a session-id field (as part of the routable encapsulation) is always present in the mirrored packets. If there is no session-id configured for an li-source entry, then the default value will be inserted. When a mirror service is configured with ip-gre or ip-udp-shim-sampled routable encap, no session-id is inserted and none can be specified against the li-source entries.
- ingress
-
Specifies the ingress policy for lawful intercept.
- egress
-
Specifies the egress policy for lawful intercept.
- host-type
-
Specifies the host type for lawful intercept. The anti-spoof filter on the SAP must be configured as ip-mac.
- ip-family
-
Specifies the IP family for lawful intercept. The anti-spoof filter on the SAP must be configured as ip-mac.
Platforms
All
subscriber
Syntax
subscriber sub-ident-string [sap sap-id] [ip ip-address] [{mac ieee-address] | sla-profile sla-profile-name}] [fc {[be] [l2] [af] [l1] [ h2] [ef] [h1] [nc]}] {[ingress] [ egress]}
no subscriber sub-ident-string
Context
[Tree] (debug>mirror-source subscriber)
Full Context
debug mirror-source subscriber
Description
This command adds hosts of a subscriber to mirroring service.
Parameters
- sub-ident-string
-
Specifies the name of the subscriber identification policy.
- sap-id
-
Specifies the physical port identifier portion of the SAP definition.
- ip-address
-
The service IP address (system IP address) of the remote 7750 SR or 7450 ESS device sending LI traffic.
- ieee-address
-
Specify this optional parameter when defining a static host. The MAC address must be specified for anti-spoof ip-mac and arp-populate. Multiple static hosts may be configured with the same MAC address given that each definition is distinguished by a unique IP address.
- sla-profile-name
-
Specifies the SLA profile name, up to 32 characters.
- fc
-
Specifies name of the forwarding class with which to associate LI traffic.
- ingress
-
Specifies information for the ingress policy.
- egress
-
Specifies information for the egress policy.
Platforms
All
subscriber-bw-limit
subscriber-bw-limit
Syntax
subscriber-bw-limit bandwidth
no subscriber-bw-limit
Context
[Tree] (config>mcast-mgmt>mcast-info-plcy>video-policy>video-if subscriber-bw-limit)
Full Context
configure mcast-management multicast-info-policy video-policy video-interface subscriber-bw-limit
Description
This command configures of an egress per-subscriber bandwidth limit for the combined retransmission and Fast Channel Change (FCC) replies for requests received directed to the IP address. If the bandwidth for a request will exceed the bandwidth limit, the request is logged and dropped.
The no form of the command disables enforcement of an egress bandwidth limit.
Default
no subscriber-bw-limit
Parameters
- bandwidth
-
The per-subscriber egress bandwidth limit for retransmission and FCC packets in kilobits per second expressed as an integer indicates infinity or no limit.
Platforms
7450 ESS, 7750 SR, 7750 SR-s
subscriber-data
subscriber-data
Syntax
[no] subscriber-data
Context
[Tree] (config>aaa>isa-radius-plcy>acct-include-attributes subscriber-data)
Full Context
configure aaa isa-radius-policy acct-include-attributes subscriber-data
Description
This command enables the inclusion of subscriber data attributes.
The no form of the command excludes subscriber data attributes.
Default
no subscriber-data
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
subscriber-id
subscriber-id
Syntax
subscriber-id sub-ident-string
no subscriber-id
Context
[Tree] (config>subscr-mgmt>loc-user-db>ipoe>host>ident-strings subscriber-id)
[Tree] (config>subscr-mgmt>loc-user-db>ppp>host>ident-strings subscriber-id)
Full Context
configure subscriber-mgmt local-user-db ipoe host identification-strings subscriber-id
configure subscriber-mgmt local-user-db ppp host identification-strings subscriber-id
Description
This command specifies the subscriber ID which is encoded in the identification strings.
The no form of this command returns to the default.
Parameters
- sub-ident-string
-
Specifies the subscriber ID string, up to 32 characters.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
subscriber-id
Syntax
[no] subscriber-id
Context
[Tree] (config>subscr-mgmt>acct-plcy>include-radius-attribute subscriber-id)
Full Context
configure subscriber-mgmt radius-accounting-policy include-radius-attribute subscriber-id
Description
This command specifies that subscriber ID attributes should be included into RADIUS accounting messages.
The no form of this command excludes subscriber ID attributes into RADIUS accounting messages.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
subscriber-id
Syntax
[no] subscriber-id
Context
[Tree] (config>aaa>isa-radius-plcy>acct-include-attributes subscriber-id)
Full Context
configure aaa isa-radius-policy acct-include-attributes subscriber-id
Description
This command specifies that subscriber ID attributes should be included into RADIUS accounting messages.
Default
no subscriber-id
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
subscriber-identification
subscriber-identification
Syntax
subscriber-identification
Context
[Tree] (config>router>nat>inside subscriber-identification)
Full Context
configure router nat inside subscriber-identification
Description
Commands in this context configure subscriber identification for Large Scale NAT.
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
subscriber-interface
subscriber-interface
Syntax
subscriber-interface ip-int-name [create] [wan-mode mode]
subscriber-interface ip-int-name [create] fwd-service service-id fwd-subscriber-interface fwd-int-name [wan-mode mode]
no subscriber-interface ip-int-name
Context
[Tree] (config>service>vprn subscriber-interface)
[Tree] (config>service>ies subscriber-interface)
Full Context
configure service vprn subscriber-interface
configure service ies subscriber-interface
Description
This command allows the operator to create special subscriber-based interfaces. It is used to contain multiple group interfaces. Multiple subnets associated with the subscriber interface can be applied to any of the contained group interfaces in any combination. The subscriber interface allows subnet sharing between group interfaces.
The no form of this command reverts to the default.
Parameters
- ip-int-name
-
Specifies the interface name of a subscriber interface, up to 32 characters. If the string contains special characters (#, ?, space), the entire string must be enclosed within double quotes.
- create
-
Keyword used to create the subscriber interface.
- fwd-service service-id
-
Specifies the wholesale service ID or service name.
- ip-int-name
-
Specifies the wholesale subscriber interface.
- wan-mode mode
-
Specifies the WAN mode as 64-bit or 128-bit. To change the WAN mode after creation, the interface must first be removed then recreated.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
subscriber-interface-statistics
subscriber-interface-statistics
Syntax
subscriber-interface-statistics
Context
[Tree] (config>subscr-mgmt subscriber-interface-statistics)
Full Context
configure subscriber-mgmt subscriber-interface-statistics
Description
Commands in this context enable or disable the collection of subscriber interface statistics.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
subscriber-limit
subscriber-limit
Syntax
subscriber-limit limit
no subscriber-limit
Context
[Tree] (config>service>vprn>nat>outside>pool subscriber-limit)
Full Context
configure service vprn nat outside pool subscriber-limit
Description
This command configures the maximum number of subscribers per outside IP address.
If multiple port blocks per subscriber are used, the block size is typically small; all blocks assigned to a given subscriber belong to the same IP address; the subscriber limit guarantees that any subscriber can get a minimum number of ports.
The subscribers are counted per protocol (UDP, TCP and ICMP). For example, in LSN44 a source IPv4 address that uses ports on each of the three protocols (UDP, TCP and ICMP) on an outside IP address count as 3 subscribers on that outside IP address. The ‘no subscriber-limit’ removes the limit for the number of subscribers per outside IP address.
This command is not applicable to pools with:
- arbitrary address pooling enabled
- flexible port allocations (application configured under a pool)
Parameters
- limit
-
Specifies the maximum number of subscribers per outside IP address.
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
subscriber-mgmt
subscriber-mgmt
Syntax
subscriber-mgmt
Context
[Tree] (config>service>ies subscriber-mgmt)
[Tree] (config>service>vprn subscriber-mgmt)
Full Context
configure service ies subscriber-mgmt
configure service vprn subscriber-mgmt
Description
Commands in this context configure per service subscriber management parameters.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
subscriber-mgmt
Syntax
subscriber-mgmt
Context
[Tree] (config subscriber-mgmt)
Full Context
configure subscriber-mgmt
Description
Commands in this context configure subscriber management entities. A subscriber is uniquely identified by a subscriber identification string. Each subscriber can have several DHCP sessions active at any time. Each session is referred to as a subscriber host and is identified by its IP address and MAC address.
All subscriber hosts belonging to the same subscriber are subject to the same hierarchical QoS (HQoS) processing. The HQoS processing is defined in the sub-profile (the subscriber profile). A sub-profile refers to an existing scheduler policy (configured in the config>qos>scheduler-policy context) and offers the possibility to overrule the rate of individual schedulers within this policy.
Because all subscriber hosts use the same scheduler policy instance, they must all reside on the same complex.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
subscriber-mgmt
Syntax
subscriber-mgmt
Context
[Tree] (config>system>persistence subscriber-mgmt)
Full Context
configure system persistence subscriber-mgmt
Description
This command configures subscriber management persistence parameters.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
subscriber-mgmt
Syntax
[no] subscriber-mgmt
Context
[Tree] (config>redundancy>multi-chassis>peer>sync subscriber-mgmt)
Full Context
configure redundancy multi-chassis peer sync subscriber-mgmt
Description
Commands in this context configure the synchronization of subscriber management information with the multi-chassis peer.
The no form of this command disables the router from synchronizing subscriber management information with the multi-chassis peer.
Default
no subscriber-mgmt
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
subscriber-prefix-length
subscriber-prefix-length
Syntax
subscriber-prefix-length prefix-length
no subscriber-prefix-length
Context
[Tree] (config>service>vprn>nat>inside>dslite subscriber-prefix-length)
Full Context
configure service vprn nat inside dual-stack-lite subscriber-prefix-length
Description
This command configures the IPv6 prefix length of the DS-Lite subscribers.
The no form of this command reverts the default.
Default
subscriber-prefix-length 128
Parameters
- prefix-length prefix-length
-
Specifies the IPv6 prefix length of the DS-Lite subscriber.
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
subscriber-prefix-length
Syntax
subscriber-prefix-length prefix-length
no subscriber-prefix-length
Context
[Tree] (config>router>nat>inside>dual-stack-lite subscriber-prefix-length)
Full Context
configure router nat inside dual-stack-lite subscriber-prefix-length
Description
This command sets the value for the number of high order bits of the source IPv6 address that will be considered as DS-Lite subscriber. The remaining bits of the source IPv6 address will be masked off, effectively aggregation all IPv6 source addresses under the configured prefix length into a single DS-Lite subscriber. Source IPv4 addresses/ports of the traffic carried within the DS-Lite subscriber will be translated into a single outside IPv4 address and the corresponding deterministic port-block (port-blocks can be extended).
The range of values for subscriber-prefix-length in non-deterministic DS-Lite is limited from 32 to 64 (a prefix will be considered as a DS-Lite subscriber) or it can be set to a value of 128 (the source IPv6 address is considered as a DS-Lite subscriber).
In cases where deterministic DS-Lite is enabled in a giver inside routing context, the range of values of the subscriber-prefix-length depends on the value of dslite-max-subscriber-limit parameter as follows:
subscriber-prefix-length – n = [32..64,128]
where n = log2(dslite-max-subscriber-limit)
[or in an alternate form: dslite-max-subscriber-limit = 2^n.]
In other words the largest prefix length for the deterministic DS-Lite subscriber will be 32+n, where n = log2(dslite-max-subscriber-limit). The subscriber prefix length can extend up to 64 bits. Beyond 64 bits for the subscriber prefix length, there only one value is allowed: 128. In the case n must be 0, which means that the mapping between B4 elements (or IPv6 address) and the IPv4 outside addresses is in 1:1 ratio (no sharing of outside IPv4 addresses).
This parameter can be changed only when there are no deterministic prefixes configured in the same routing context.
The no form of the command reverts to the default.
Default
128
Parameters
- prefix-length
-
In non-deterministic DS-Lite this value can be [32..64,128], assuming that the deterministic DS-Lite is not concurrently enabled in the same inside routing context. In case that deterministic DS-Lite is enabled, this value can be within the range [(32+n)..64,128] where n = log2(dslite-max-subscriber-limit). The value of 128 is allowed only when n=0 (each subscriber is mapped to a single outside IPv4 IP address).
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
subscriber-prefix-length
Syntax
subscriber-prefix-length prefix-length
no subscriber-prefix-length
Context
[Tree] (config>service>vprn>nat>inside>nat64 subscriber-prefix-length)
[Tree] (config>router>nat>inside>nat64 subscriber-prefix-length)
Full Context
configure service vprn nat inside nat64 subscriber-prefix-length
configure router nat inside nat64 subscriber-prefix-length
Description
This command specifies the IPv6 address prefix length to be used for the NAT64 subscribers in this virtual router instance.
Default
subscriber-prefix-length128
Parameters
- prefix-length
-
Specifies the subscriber identification for Large Scale NAT.
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
subscriber-prefixes
subscriber-prefixes
Syntax
subscriber-prefixes
Context
[Tree] (config>service>ies>sub-if>ipv6 subscriber-prefixes)
[Tree] (config>service>vprn>sub-if>ipv6 subscriber-prefixes)
Full Context
configure service ies subscriber-interface ipv6 subscriber-prefixes
configure service vprn subscriber-interface ipv6 subscriber-prefixes
Description
Commands in this context configure aggregate off-link subscriber prefixes associated with this subscriber interface. Individual prefixes are specified under the prefix context list aggregate routes in which the next hop is indirect via the subscriber interface.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
subscriber-retention
subscriber-retention
Syntax
subscriber-retention [hrs hours] [min minutes]
no subscriber-retention
Context
[Tree] (config>service>nat>nat-policy>timeouts subscriber-retention)
[Tree] (config>service>nat>up-nat-policy>timeouts subscriber-retention)
Full Context
configure service nat nat-policy timeouts subscriber-retention
configure service nat up-nat-policy timeouts subscriber-retention
Description
This command specifies the subscriber retention timeout, which is the time a NAT subscriber and its associated IP address are kept after all hosts and associated port blocks have expired. If a NAT subscriber host appears before the retention timeout has elapsed, it is given the same outside IP address.
Default
no subscriber-retention
Parameters
- hrs hours
-
Specifies the hours a subscriber’s IP address is kept after all hosts and port blocks have expired.
- min minutes
-
Specifies the minutes a subscriber’s IP address is kept after all hosts and port blocks have expired.
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
subscriber-sap-id
subscriber-sap-id
Syntax
[no] subscriber-sap-id
Context
[Tree] (config>service>ies>if>sap>static-host subscriber-sap-id)
[Tree] (config>service>ies>sub-if>grp-if>sap>static-host subscriber-sap-id)
[Tree] (config>service>vpls>sap>static-host subscriber-sap-id)
[Tree] (config>service>vprn>if>sap>static-host subscriber-sap-id)
[Tree] (config>service>vprn>sub-if>grp-if>sap>static-host subscriber-sap-id)
Full Context
configure service ies interface sap static-host subscriber-sap-id
configure service ies subscriber-interface group-interface sap static-host subscriber-sap-id
configure service vpls sap static-host subscriber-sap-id
configure service vprn interface sap static-host subscriber-sap-id
configure service vprn subscriber-interface group-interface sap static-host subscriber-sap-id
Description
This command enables using the SAP ID as the subscriber ID.
Parameters
- subscriber-sap-id
-
Specifies to use the sap-id as the subscriber-id.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
subscribers
subscribers
Syntax
subscribers {qset-size size | non-shaper-queues}
Context
[Tree] (config>qos>fp-resource-policy>aggregate-shapers>queue-sets>default-size subscribers)
Full Context
configure qos fp-resource-policy aggregate-shapers queue-sets default-size subscribers
Description
This command configures the default queue-set size for subscribers.
Parameters
- size
-
Specifies the size of the queue sets.
- non-shaper-queues
-
Specifies that subscribers will not use hardware aggregate shapers on FPs where the FP resource policy is applied.
Platforms
7750 SR-1, 7750 SR-s
subscription
subscription
Syntax
subscription percentage
no subscription
Context
[Tree] (config>router>rsvp>interface subscription)
Full Context
configure router rsvp interface subscription
Description
This command configures the percentage of the link bandwidth that RSVP can use for reservation and sets a limit for the amount of over-subscription or under-subscription allowed on the interface.
When the subscription is set to zero, no new sessions are permitted on this interface. If the percentage is exceeded, the reservation is rejected and a log message is generated.
The no form of this command reverts the percentage to the default value.
Default
subscription 100
Parameters
- percentage
-
Specifies the percentage of the interface's bandwidth that RSVP allows to be used for reservations.
Platforms
All
subscription
Syntax
subscription subscription-id cancel
subscription cancel-all
Context
[Tree] (admin>system>telemetry>grpc subscription)
Full Context
admin system telemetry grpc subscription
Description
This command cancels an active telemetry subscription.
Parameters
- subscription-id
-
Specifies the ID of the telemetry subscription to cancel.
Platforms
All
subscription
Syntax
subscription name [create]
no subscription name
Context
[Tree] (config>system>telemetry>persistent-subscriptions subscription)
Full Context
configure system telemetry persistent-subscriptions subscription
Description
Commands in this context configure persistent subscription commands.
The no form of this command removes the configuration.
Parameters
- name
-
Specifies the subscription name, up to 32 characters.
- create
-
Keyword used to create the subscription.
Platforms
All
suggest-internal-objects
suggest-internal-objects
Syntax
[no] suggest-internal-objects
Context
[Tree] (environment suggest-internal-objects)
Full Context
environment suggest-internal-objects
Description
This command enables suggesting of internally created objects while auto completing.
The no form of the command disables the command.
Platforms
All
summaries
summaries
Syntax
[no] summaries
Context
[Tree] (config>service>vprn>ospf3>area>nssa summaries)
[Tree] (config>service>vprn>ospf>area>stub summaries)
[Tree] (config>service>vprn>ospf>area>nssa summaries)
Full Context
configure service vprn ospf3 area nssa summaries
configure service vprn ospf area stub summaries
configure service vprn ospf area nssa summaries
Description
This command enables sending summary (type 3) advertisements into a stub area or Not So Stubby Area (NSSA) on an Area Border Router (ABR). This parameter is particularly useful to reduce the size of the routing and Link State Database (LSDB) tables within the stub or nssa area. By default, summary route advertisements are sent into the stub area or NSSA.
The no form of this command disables sending summary route advertisements and, for stub areas, only the default route is advertised by the ABR.
Default
summaries — Summary routes are advertised by the ABR into the stub area or NSSA.
Platforms
All
summaries
Syntax
[no] summaries
Context
[Tree] (config>router>ospf3>area>stub summaries)
[Tree] (config>router>ospf>area>nssa summaries)
[Tree] (config>router>ospf>area>stub summaries)
[Tree] (config>router>ospf3>area>nssa summaries)
Full Context
configure router ospf3 area stub summaries
configure router ospf area nssa summaries
configure router ospf area stub summaries
configure router ospf3 area nssa summaries
Description
This command enables sending summary (type 3) advertisements into a stub area or Not So Stubby Area (NSSA) on an Area Border Router (ABR).
This parameter is particularly useful to reduce the size of the routing and Link State Database (LSDB) tables within the stub or NSSA area (default: summary).
By default, summary route advertisements are sent into the stub area or NSSA.
The no form of this command disables sending summary route advertisements and, for stub areas; only the default route is advertised by the ABR.
Default
summaries
Platforms
All
summary
summary
Syntax
summary
Context
[Tree] (config>filter>log summary)
Full Context
configure filter log summary
Description
Commands in this context configure log summarization. These settings will only be taken into account when syslog is the log destination.
Platforms
All
summary
Syntax
summary [ip-address]
no summary
Context
[Tree] (debug>router>isis summary)
Full Context
debug router isis summary
Description
This command enables debugging for ISIS summary addresses.
The no form of the command disables the debugging.
Parameters
- ip-address
-
When specified, only packets with the specified address are debugged.
Platforms
All
summary-address
summary-address
Syntax
summary-address {ip-prefix/mask | ip-prefix [netmask]} [level] [ tag tag]
no summary-address {ip-prefix/mask | ip-prefix [netmask]}
Context
[Tree] (config>service>vprn>isis summary-address)
Full Context
configure service vprn isis summary-address
Description
This command creates summary-addresses for the specified router or VPRN instance.
Parameters
- ip-prefix/mask
-
Specifies information for the specified IP prefix and mask length.
- netmask
-
The subnet mask in dotted decimal notation.
- level
-
Specifies IS-IS level area attributes. If no level parameter is specified, the default is level-1/2.
- tag tag
-
Assigns a route tag to the summary address.
Platforms
All
summary-address
Syntax
summary-address {ip-prefix/ip-prefix-length | ip-prefix netmask} [level] [tag tag] [algorithm algo-id]
summary-address {ip-prefix/ip-prefix-length | ip-prefix netmask} [level] [tag tag] [algorithm algo-id] advertise-unreachable [match-route-tag tag] [advertise-route-tag tag]
no summary-address {ip-prefix/ip-prefix-length | ip-prefix netmask}
Context
[Tree] (config>router>isis summary-address)
Full Context
configure router isis summary-address
Description
This command creates a summary IPv4, IPv6, or SRv6 locator address.
When an IS-IS domain exists out of multiple areas, the user must redistribute IP addresses and SRv6 locators between areas for inter-area SRv6-based transport services.
Scaling may be impacted if all existing IPv4, IPv6, and SRv6 locators are redistributed between all existing areas. SRv6 locators and IP addresses can be summarized when they are redistributed from one area into another area. Summarization reduces the number of entries redistributed, which reduces the size of the Link State Database (LSDB) and increases network stability.
The no form of this command reverts to the default.
Default
no summary-address
Parameters
- ip-prefix/ip-prefix-length
-
Specifies the IP prefix and prefix length of the summary address.
- netmask
-
Specifies the subnet mask in dotted decimal notation.
- level
-
Specifies IS-IS level area attributes.
- tag
-
Specifies the route tag to assign for the summary address.
- algo-id
-
Specifies the algorithm topology applied for the summary address.
- match-route-tag tag
-
Specifies the route tag to match the Unreachable Prefix Announcements (UPAs). This selects a subset of summary member prefixes to monitor for reachability.
- advertise-route-tag tag
-
Specifies the route tag to advertise in the UPA. The UPA tag can be used when there are multiple ASBR redistributing prefixes between two IGP areas.
Platforms
All
summary-crit
summary-crit
Syntax
summary-crit dst-addr
summary-crit src-addr
no summary-crit
Context
[Tree] (config>filter>log>summary summary-crit)
Full Context
configure filter log summary summary-crit
Description
This command defines the key of the index of the mini-table. If key information is changed while summary is administratively enabled (no shutdown), the filter summary mini-table is flushed and recreated with different key information. Log packets received during the reconfiguration time will be handled as if summary was not active.
The no form of the command reverts to the default parameter.
Default
summary-crit src-addr
Parameters
- dst-addr
-
Specifies that received log packets are summarized based on the destination IPv4, IPv6, or MAC address.
- src-addr
-
Specifies that received log packets are summarized based on the source IPv4, IPv6 or MAC address.
Platforms
All
super-backbone
super-backbone
Syntax
[no] super-backbone
Context
[Tree] (config>service>vprn>ospf super-backbone)
Full Context
configure service vprn ospf super-backbone
Description
This command specifies whether CE-PE functionality is required or not. The OSPF super backbone indicates the type of the LSA generated as a result of routes redistributed into OSPF. When enabled, the redistributed routes are injected as summary, external or NSSA LSAs. When disabled, the redistributed routes are injected as either external or NSSA LSAs only.
Default
no super-backbone
Platforms
All
supplicant-timeout
supplicant-timeout
Syntax
supplicant-timeout seconds
no supplicant-timeout
Context
[Tree] (config>port>ethernet>dot1x supplicant-timeout)
Full Context
configure port ethernet dot1x supplicant-timeout
Description
This command configures the period during which the router waits for a client to respond to its EAPOL messages. When the supplicant-timeout expires, the 802.1x authentication session is considered to have failed.
The no form of this command returns the value to the default.
Default
supplicant-timeout 30
Parameters
- seconds
-
Specifies the server timeout period in seconds.
Platforms
All
supported-features
supported-features
Syntax
[no] supported-features
Context
[Tree] (config>subscr-mgmt>diam-appl-plcy>gx>include-avp supported-features)
Full Context
configure subscriber-mgmt diameter-application-policy gx include-avp supported-features
Description
This command includes the supported-features in CCR messages.
The no form of this command resets the command to the default setting.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
suppress
suppress
Syntax
suppress integer
no suppress
Context
[Tree] (config>router>policy-options>damping suppress)
Full Context
configure router policy-options damping suppress
Description
This command configures the suppression parameter for the route policy damping profile.
A route is suppressed when it has flapped frequently enough to increase the Figure of Merit (FoM) value to exceed the suppress threshold limit. When the FoM value exceeds the suppress threshold limit, the route is removed from the route table or inclusion in advertisements.
The no form of this command removes the suppress parameter from the damping profile.
Default
no suppress
Parameters
- integer
-
Specifies the suppress value expressed as a decimal integer.
Platforms
All
suppress-attached-bit
suppress-attached-bit
Syntax
[no] suppress-attached-bit
Context
[Tree] (config>service>vprn>isis suppress-attached-bit)
Full Context
configure service vprn isis suppress-attached-bit
Description
This command configures IS-IS to suppress setting the attached bit on originated Level 1 LSPs to prevent all L1 routers in the area from installing a default route to it.
Platforms
All
suppress-attached-bit
Syntax
[no] suppress-attached-bit
Context
[Tree] (config>router>isis suppress-attached-bit)
Full Context
configure router isis suppress-attached-bit
Description
This command configures IS-IS to suppress setting the attached bit on originated Level 1 LSPs to prevent all L1 routers in the area from installing a default route to it.
Default
no suppress-attached-bit
Platforms
All
suppress-dn-bit
suppress-dn-bit
Syntax
[no] suppress-dn-bit
Context
[Tree] (config>service>vprn>ospf suppress-dn-bit)
[Tree] (config>service>vprn>ospf3 suppress-dn-bit)
Full Context
configure service vprn ospf suppress-dn-bit
configure service vprn ospf3 suppress-dn-bit
Description
This command specifies whether to suppress the setting of the DN bit for OSPF LSA packets generated by this instance of OSPF on the router. When enabled, the DN bit for OSPF LSA packets generated by this instance of the OSPF router will not be set. When disabled, this instance of the OSPF router will follow the normal procedure to determine whether to set the DN bit.
Default
no suppress-dn-bit
Platforms
All
suppress-lo-alarm
suppress-lo-alarm
Syntax
[no] suppress-lo-alarm
Context
[Tree] (config>port>sonet-sdh suppress-lo-alarm)
Full Context
configure port sonet-sdh suppress-lo-alarm
Description
This command enables the suppression of lower order alarms on SONET/SDH port such as MLPPP bundle alarms, DS1/E1 links alarms and 336 APS channel groups alarms.
The no form of this command disables the suppression of lower order alarms on SONET/SDH port.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
suppress-lsn-events
suppress-lsn-events
Syntax
[no] suppress-lsn-events
Context
[Tree] (configure>isa>wlan-gw-group>nat suppress-lsn-events)
Full Context
configure isa wlan-gw-group nat suppress-lsn-events
Description
This command suppresses the generation of Large Scale NAT (LSN) events when RADIUS accounting is enabled.
By default, only one logging facility for tracking subscribers in LSN44, DS-Lite, and NAT64 can be enabled at the time, either the SR OS event logging facility or the RADIUS logging facility. Note that SR OS event logs can be sent to multiple destinations, such as the console session, a telnet or SSH session, memory logs, file destinations, SNMP trap groups, and syslog destinations.
If RADIUS logging is enabled, the NAT logs are sent to the RADIUS destination and the NAT logs are suppressed in the SR OS event logging facility, for example, NAT logs are not sent to the syslog server.
If RADIUS logging is disabled, the NAT logs are sent to the SR OS event logging facility, for example, syslog, assuming that the events are enabled via the SR OS event-control (configure log event-control nat event generate).
The no form of this command, the NAT logs can be sent to both logging facilities simultaneously, the SR OS event logging facility and RADIUS logging facility.
Default
suppress-lsn-events
Platforms
7750 SR, 7750 SR-e, 7750 SR-s, VSR
suppress-lsn-events
Syntax
[no] suppress-lsn-events
Context
[Tree] (config>isa>nat-group suppress-lsn-events)
Full Context
configure isa nat-group suppress-lsn-events
Description
This command suppresses the generation of Large Scale NAT (LSN) events when RADIUS accounting is enabled.
By default, only one logging facility for tracking subscribers in LSN44, DS-Lite, and NAT64 can be enabled at the time: either the SR OS event logging facility or the RADIUS logging facility. SR OS event logs can be sent to multiple destinations, such as the console session, a telnet or SSH session, memory logs, file destinations, SNMP trap groups, and syslog destinations.
If RADIUS logging is enabled, the NAT logs are sent to the RADIUS destination and the NAT logs are suppressed in the SR OS event logging facility, for example, NAT logs are not sent to the syslog server.
If RADIUS logging is disabled, the NAT logs are sent to the SR OS event logging facility; for example, syslog, assuming that the events are enabled via the event-control command (configure log event-control nat event generate).
By explicitly disabling this command (no suppress-lsn-events), the NAT logs can be sent to both logging facilities simultaneously, the SR OS event logging facility, and the RADIUS logging facility.
Default
suppress-lsn-events
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
suppress-lsn-sub-blks-free
suppress-lsn-sub-blks-free
Syntax
[no] suppress-lsn-sub-blks-free
Context
[Tree] (configure>isa>wlan-gw-group>nat suppress-lsn-sub-blks-free)
Full Context
configure isa wlan-gw-group nat suppress-lsn-sub-blks-free
Description
This command suppresses the tmnxNatLsnSubBlksFree summary notification and use the tmnxNatPlBlockAllocationLsn notifications. When the SR OS node is in a state of excessive logging, the queue associated with the transmission of logs on the MS-ISA can become congested. This event further delays the generation of logs, and with this, further allocations and deallocations of NAT resources (port-blocks) is stalled until the queue is relieved of congestion. For example, an excessive logging state in the system can be caused by issuing a command to clear a large number of NAT subscribers where a large number of resources (port-blocks) are released at once.
The suppress-lsn-sub-blks-free command enables the generation of individual logs carried in event-id 2012 for every released port block regardless of the state of the transmission queue (whether congested or not). If NAT subscribers have a large number of allocated port blocks (this could be hundreds of port blocks per subscriber), generating individual logs per port-block release contributes to the congestion.
To alleviate transmission queue congestion, this behavior can be changed by disabling this command (no suppress-lsn-sub-blks-free). This causes the suppression of logs related to the release of individual port blocks of a NAT subscriber when the transmission queue is congested. As a result, only a summarized release log via event-id 2021 for the subscriber is generated. The purpose of this new log is to inform the operator in a single message that all ports blocks for the subscriber are released. For example, the log message for LSN is "LSN subscriber all blocks freed”. The benefit of such summarization (or log aggregation) is to alleviate the congestion of the transmission queue and consequently accelerate resource releases. An effect is the decreased granularity of information.
If summarization is enabled (no suppress-lsn-sub-blks-free) while there is no logging congestion in the system, the port block releases continue to be logged individually via the event-id 2012 (assuming that this is enabled in the event control), except for the last port block of the subscriber. When the last port block is released, the log with event-id 2021 is generated indicating that all port blocks for the subscriber are now released without carrying the specific information about this last port block that is released.
Platforms
7750 SR, 7750 SR-e, 7750 SR-s, VSR
suppress-lsn-sub-blks-free
Syntax
[no] suppress-lsn-sub-blks-free
Context
[Tree] (config>isa>nat-group suppress-lsn-sub-blks-free)
Full Context
configure isa nat-group suppress-lsn-sub-blks-free
Description
This command suppresses the tmnxNatLsnSubBlksFree summary notification and use the tmnxNatPlBlockAllocationLsn notifications. When the SR OS node is in a state of excessive logging, the queue associated with the transmission of logs on the MS-ISA can become congested. This event further delays the generation of logs, and with this, further allocations and deallocations of NAT resources (port-blocks) will be stalled until the queue is relieved of congestion. For example, an excessive logging state in the system can be caused by issuing a command to clear a large number of NAT subscribers where a large number of resources (port-blocks) are released at once.
The suppress-lsn-sub-blks-free command enables the generation of individual logs carried in event-id 2012 for every released port block regardless of the state of the transmission queue (whether congested or not). If NAT subscribers have a large number of allocated port blocks (this could be hundreds of port blocks per subscriber), generating individual logs per port-block release contributes to the congestion.
To alleviate transmission queue congestion, this behavior can be changed by disabling this command (no suppress-lsn-sub-blks-free). This causes the suppression of logs related to the release of individual port blocks of a NAT subscriber when the transmission queue is congested. As a result, only a summarized release log via event-id 2021 for the subscriber is generated. The purpose of this new log is to inform the operator in a single message that all ports blocks for the subscriber are released. For example, the log message for LSN will be "LSN subscriber all blocks freed”. The benefit of such summarization (or log aggregation) is to alleviate the congestion of the transmission queue and consequently accelerate resource releases. An effect is the decreased granularity of information.
If summarization is enabled (no suppress-lsn-sub-blks-free) while there is no logging congestion in the system, the port block releases continue to be logged individually via the event-id 2012 (assuming that this is enabled in the event control), except for the last port block of the subscriber. When the last port block is released, the log with event-id 2021 is generated indicating that all port blocks for the subscriber are now released without carrying the specific information about this last port block that is released.
Default
no suppress-lsn-sub-blks-free
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
suppress-standby-signaling
suppress-standby-signaling
Syntax
[no] suppress-standby-signaling
Context
[Tree] (config>service>vpls>endpoint suppress-standby-signaling)
Full Context
configure service vpls endpoint suppress-standby-signaling
Description
When this command is enabled, the pseudowire standby bit (value 0x00000020) will not be sent to T-LDP peer when the specified spoke is selected as a standby. This allows faster switchover as the traffic will be sent over this SDP and discarded at the blocking side of the connection. This is particularly applicable to multicast traffic.
Default
suppress-standby-signaling
Platforms
All
suppress-threshold
suppress-threshold
Syntax
suppress-threshold suppress-penalties reuse-threshold reuse-penalties
Context
[Tree] (config>port>ethernet>dampening suppress-threshold)
Full Context
configure port ethernet dampening suppress-threshold
Description
This command configures the penalties thresholds at which the port state events to the upper layer are dampened (suppress threshold) and then permitted (reuse threshold).
Parameters
- suppress-penalties
-
Specifies the threshold at which the port up state is suppressed until the accumulated penalties drop below the reuse threshold again.
- reuse-penalties
-
Specifies the threshold at which the port up state is no longer suppressed, after the port has been in a suppressed state and the accumulated penalties decay drops below this threshold. The reuse threshold value must be less than the suppress threshold value.
Platforms
All
svc-id
svc-id
Syntax
svc-id service-id
no svc-id
Context
[Tree] (config>system>security>mgmt-access-filter>mac-filter>entry>match svc-id)
Full Context
configure system security management-access-filter mac-filter entry match svc-id
Description
This command specifies an existing svc-id to use as a match condition.
Parameters
- service-id
-
Specifies a service-id to match.
Platforms
All
svc-path
svc-path
Syntax
svc-path path-id svc-index service-index
no svc-path
Context
[Tree] (config>subscr-mgmt>isa-svc-chain>vas-filter>entry>action>insert-nsh svc-path)
Full Context
configure subscriber-mgmt isa-service-chaining vas-filter entry action insert-nsh svc-path
Description
This command configures the service path identifier and service index to be inserted in NSH in the steered traffic if the forward action indicates NSH insertion.
The no form of this command removes the parameters from the configuration.
Parameters
- path-id
-
Specifies the 24-bit path ID in the base part of NSH.
- service-index
-
Specifies the 8-bit service index inserted in the base part of NSH.
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
svc-ping
svc-ping
Syntax
svc-ping ip-address [ service service-id] [local-sdp] [ remote-sdp]
Context
[Tree] (oam svc-ping)
Full Context
oam svc-ping
Description
This command tests a service ID for correct and consistent provisioning between two service end points.
The svc-ping command accepts a far-end IP address and a service ID for local and remote service testing. The following information can be determined from svc-ping:
Local and remote service existence
-
Local and remote service state
-
Local and remote service type correlation
-
Local and remote customer association
-
Local and remote service-to-SDP bindings and state
-
Local and remote ingress and egress service label association
Unlike sdp-ping, only a single message is sent per command; no count nor interval parameter is supported and round trip time is not calculated. A time out value of 10 seconds is used before failing the request. The forwarding class is assumed to be Best-Effort Out-of-Profile.
If no request is sent or a reply is not received, all remote information is shown as N/A.
To terminate a svc-ping in progress, use the CLI break sequence <Ctrl-C>.
Upon request time out, message response, request termination, or request error the following local and remote information is displayed. See Svc-ping. Local and remote information is dependent upon service existence and reception of reply.
Field |
Description |
Values |
---|---|---|
Request Result |
The result of the svc-ping request message. |
Sent - Request Timeout |
Sent - Request Terminated |
||
Sent - Reply Received |
||
Not Sent - Non-Existent Service-ID |
||
Not Sent - Non-Existent SDP for Service |
||
Not Sent - SDP For Service Down |
||
Not Sent - Non-existent Service Egress Label |
||
Service-ID |
The ID of the service being tested. |
service-id |
Local Service Type |
The type of service being tested. If service-id does not exist locally, N/A is displayed. |
Epipe, Ipipe, Fpipe, Apipe |
TLS |
||
IES |
||
Mirror-Dest |
||
— |
||
Local Service Admin State |
The local administrative state of service-id. If the service does not exist locally, the administrative state is Non-Existent. |
Admin-Up |
Admin-Down |
||
Non-Existent |
||
Local Service Oper State |
The local operational state of service-id. If the service does not exist locally, the state is N/A. |
Oper-Up |
Oper-Down |
||
— |
||
Remote Service Type |
The remote type of service being tested. If service-id does not exist remotely, N/A is displayed. |
Epipe, Ipipe, Fpipe, Apipe |
TLS |
||
IES |
||
Mirror-Dest |
||
— |
||
Remote Service Admin State |
The remote administrative state of service-id. If the service does not exist remotely, the administrative state is Non-Existent. |
Up |
Down |
||
Non-Existent |
||
Local Service MTU |
The local service-mtu for service-id. If the service does not exist, N/A is displayed. |
service-mtu |
— |
||
Remote Service MTU |
The remote service-mtu for service-id. If the service does not exist remotely, N/A is displayed. |
remote-service-mtu |
— |
||
Local Customer ID |
The local customer-id associated with service-id. If the service does not exist locally, N/A is displayed. |
customer-id |
— |
||
Remote Customer ID |
The remote customer-id associated with service-id. If the service does not exist remotely, N/A is displayed. |
customer-id |
— |
||
Local Service IP Address |
The local system IP address used to terminate remotely configured SDP-ID (as the far-end address). If an IP interface has not been configured to be the system IP address, N/A is displayed. |
system-ip-address |
— |
||
Local Service IP Interface Name |
The name of the local system IP interface. If the local system IP interface has not been created, N/A is displayed. |
system-interface-name |
— |
||
Local Service IP Interface State |
The state of the local system IP interface. If the local system IP interface has not been created, Non-Existent is displayed. |
Up |
Down |
||
Non-Existent |
||
Expected Far-end Address |
The expected IP address for the remote system IP interface. This must be the far-end address entered for the svc-ping command. |
orig-sdp-far-end-addr |
dest-ip-addr |
||
— |
||
Actual Far-end Address |
The returned remote IP address. If a response is not received, the displayed value is N/A. If the far-end service IP interface is down or non-existent, a message reply is not expected. sdp-ping should also fail. |
resp-ip-addr |
— |
||
Responders Expected Far-end Address |
The expected source of the originator’s sdp-id from the perspective of the remote router terminating the sdp-id. If the far-end cannot detect the expected source of the ingress sdp-id or the request is transmitted outside the sdp-id, N/A is displayed. |
resp-rec-tunnel-far-end-address |
— |
||
Originating SDP-ID |
The sdp-id used to reach the far-end IP address if sdp-path is defined. The originating sdp-id must be bound to the service-id and terminate on the far-end IP address. If an appropriate originating sdp-id is not found, Non-Existent is displayed. |
orig-sdp-id |
Non-Existent |
||
Originating SDP-ID Path Used |
Whether the Originating router used the originating sdp-id to send the svc-ping request. If a valid originating sdp-id is found, operational and has a valid egress service label, the originating router should use the sdp-id as the requesting path if sdp-path has been defined. If the originating router uses the originating sdp-id as the request path, Yes is displayed. If the originating router does not use the originating sdp-id as the request path, No is displayed. If the originating sdp-id is non-existent, N/A is displayed. |
Yes |
No |
||
— |
||
Originating SDP-ID Administrative State |
The local administrative state of the originating sdp-id. If the sdp-id has been shutdown, Admin-Down is displayed. If the originating sdp-id is in the no shutdown state, Admin-Up is displayed. If an originating sdp-id is not found, N/A is displayed. |
Admin-Up |
Admin-Up |
||
— |
||
Originating SDP-ID Operating State |
The local operational state of the originating sdp-id. If an originating sdp-id is not found, N/A is displayed. |
Oper-Up |
Oper-Down |
||
— |
||
Originating SDP-ID Binding Admin State |
The local administrative state of the originating sdp-ids binding to service-id. If an sdp-id is not bound to the service, N/A is displayed. |
Admin-Up |
Admin-Up |
||
— |
||
Originating SDP-ID Binding Oper State |
The local operational state of the originating sdp-ids binding to service-id. If an sdp-id is not bound to the service, N/A is displayed. |
Oper-Up |
Oper-Down |
||
— |
||
Responding SDP-ID |
The sdp-id used by the far end to respond to the svc-ping request. If the request was received without the sdp-path parameter, the responding router does not use an sdp-id as the return path, but the appropriate responding sdp-id is displayed. If a valid sdp-id return path is not found to the originating router that is bound to the service-id, Non-Existent is displayed. |
resp-sdp-id |
Non-Existent |
||
Responding SDP-ID Path Used |
Whether the responding router used the responding sdp-id to respond to the svc-ping request. If the request was received via the originating sdp-id and a valid return sdp-id is found, operational and has a valid egress service label, the far-end router should use the sdp-id as the return sdp-id. If the far end uses the responding sdp-id as the return path, Yes is displayed. If the far end does not use the responding sdp-id as the return path, No is displayed. If the responding sdp-id is non-existent, N/A is displayed. |
Yes |
No |
||
— |
||
Responding SDP-ID Administrative State |
The administrative state of the far-end sdp-id associated with the return path for service-id. When a return path is administratively down, Admin-Down is displayed. If the return sdp-id is administratively up, Admin-Up is displayed. If the responding sdp-id is non-existent, N/A is displayed. |
Admin-Up |
Admin-Up |
||
N/A |
||
Responding SDP-ID Operational State |
The operational state of the far-end sdp-id associated with the return path for service-id. When a return path is operationally down, Oper-Down is displayed. If the return sdp-id is operationally up, Oper-Up is displayed. If the responding sdp-id is non-existent, N/A is displayed. |
Oper-Up |
Oper-Down |
||
— |
||
Responding SDP-ID Binding Admin State |
The local administrative state of the responder’s sdp-id binding to service-id. If an sdp-id is not bound to the service, N/A is displayed. |
Admin-Up |
Admin-Down |
||
— |
||
Responding SDP-ID Binding Oper State |
The local operational state of the responder’s sdp-id binding to service-id. If an sdp-id is not bound to the service, N/A is displayed. |
Oper-Up |
Oper-Down |
||
— |
||
Originating VC-ID |
The originator’s VC-ID associated with the sdp-id to the far-end address that is bound to service-id. If the sdp-id signaling is off, originator-vc-id is 0. If the originator-vc-id does not exist, N/A is displayed. |
originator-vc-id |
— |
||
Responding VC-ID |
The responder’s VC-ID associated with the sdp-id to originator-id that is bound to service-id. If the sdp-id signaling is off or the service binding to sdp-id does not exist, responder-vc-id is 0. If a response is not received, N/A is displayed. |
responder-vc-id |
— |
||
Originating Egress Service Label |
The originating service label (VC-Label) associated with the service-id for the originating sdp-id. If service-id does not exist locally, N/A is displayed. If service-id exists, but the egress service label has not been assigned, Non-Existent is displayed. |
egress-vc-label |
— |
||
Non-Existent |
||
Originating Egress Service Label Source |
The originating egress service label source. If the displayed egress service label is manually defined, Manual is displayed. If the egress service label is dynamically signaled, Signaled is displayed. If the service-id does not exist or the egress service label is non-existent, N/A is displayed. |
Manual |
Signaled |
||
— |
||
Originating Egress Service Label State |
The originating egress service label state. If the originating router considers the displayed egress service label operational, Up is displayed. If the originating router considers the egress service label inoperative, Down is displayed. If the service-id does not exist or the egress service label is non-existent, N/A is displayed. |
Up |
Down |
||
— |
||
Responding Service Label |
The actual responding service label in use by the far-end router for this service-id to the originating router. If service-id does not exist in the remote router, N/A is displayed. If service-id does exist remotely but the remote egress service label has not been assigned, Non-Existent is displayed. |
rec-vc-label |
— |
||
Non-Existent |
||
Responding Egress Service Label Source |
The responder’s egress service label source. If the responder’s egress service label is manually defined, Manual is displayed. If the responder’s egress service label is dynamically signaled, Signaled is displayed. If the service-id does not exist on the responder or the responder’s egress service label is non-existent, N/A is displayed. |
Manual |
Signaled |
||
— |
||
Responding Service Label State |
The responding egress service label state. If the responding router considers its egress service label operational, Up is displayed. If the responding router considers its egress service label inoperative, Down is displayed. If the service-id does not exist or the responder’s egress service label is non-existent, N/A is displayed. |
Up |
Down |
||
— |
||
Expected Ingress Service Label |
The locally assigned ingress service label. This is the service label that the far-end is expected to use for service-id when sending to the originating router. If service-id does not exist locally, N/A is displayed. If service-id exists but an ingress service label has not been assigned, Non-Existent is displayed. |
ingress-vc-label |
— |
||
Non-Existent |
||
Expected Ingress Label Source |
The originator’s ingress service label source. If the originator’s ingress service label is manually defined, Manual is displayed. If the originator’s ingress service label is dynamically signaled, Signaled is displayed. If the service-id does not exist on the originator or the originators ingress service label has not been assigned, N/A is displayed. |
Manual |
Signaled |
||
— |
||
Expected Ingress Service Label State |
The originator’s ingress service label state. If the originating router considers its ingress service label operational, Up is displayed. If the originating router considers its ingress service label inoperative, Down is displayed. If the service-id does not exist locally, N/A is displayed. |
Up |
Down |
||
— |
||
Responders Ingress Service Label |
The assigned ingress service label on the remote router. This is the service label that the far end is expecting to receive for service-id when sending to the originating router. If service-id does not exist in the remote router, N/A is displayed. If service-id exists, but an ingress service label has not been assigned in the remote router, Non-Existent is displayed. |
resp-ingress-vc-label |
— |
||
Non-Existent |
||
Responders Ingress Label Source |
The assigned ingress service label source on the remote router. If the ingress service label is manually defined on the remote router, Manual is displayed. If the ingress service label is dynamically signaled on the remote router, Signaled is displayed. If the service-id does not exist on the remote router, N/A is displayed. |
Manual |
Signaled |
||
— |
||
Responders Ingress Service Label State |
The assigned ingress service label state on the remote router. If the remote router considers its ingress service label operational, Up is displayed. If the remote router considers its ingress service label inoperative, Down is displayed. If the service-id does not exist on the remote router or the ingress service label has not been assigned on the remote router, N/A is displayed. |
Up |
Down |
||
— |
Parameters
- ip-address
-
Specifies the far-end IP address to which to send the svc-ping request message in dotted decimal notation.
- service-id
-
Specifies the service ID of the service being tested must be indicated with this parameter. The service ID need not exist on the local router to receive a reply message.
- local-sdp
-
Specifies the svc-ping request message should be sent using the same service tunnel encapsulation labeling as service traffic. If local-sdp is specified, the command attempts to use an egress sdp-id bound to the service with the specified far-end IP address with the VC-Label for the service. The far-end address of the specified sdp-id is the expected responder-id within the reply received. The sdp-id defines the encapsulation of the SDP tunnel encapsulation used to reach the far end; this can be IP/GRE or MPLS. On originator egress, the service-ID must have an associated VC-Label to reach the far-end address of the sdp-id and the sdp-id must be operational for the message to be sent.
If local-sdp is not specified, the svc-ping request message is sent with GRE encapsulation with the OAM label.
Message Encapsulation indicates whether a message is sent and how the message is encapsulated based on the state of the service ID.
Table 4. Message Encapsulation Local Service State
local-sdp Not Specified
local-sdp Specified
Message Sent
Message Encapsulation
Message Sent
Message Encapsulation
Invalid Local Service
Yes
Generic IP/GRE OAM (PLP)
No
None
No Valid SDP-ID Bound
Yes
Generic IP/GRE OAM (PLP)
No
None
SDP-ID Valid But Down
Yes
Generic IP/GRE OAM (PLP)
No
None
SDP-ID Valid and Up, But No Service Label
Yes
Generic IP/GRE OAM (PLP)
No
None
SDP-ID Valid, Up and Egress Service Label
Yes
Generic IP/GRE OAM (PLP)
Yes
SDP Encapsulation with Egress Service Label (SLP)
- remote-sdp
-
Specifies svc-ping reply message from the far-end should be sent using the same service tunnel encapsulation labeling as service traffic.
If remote-sdp is specified, the far-end responder attempts to use an egress sdp-id bound to the service with the message originator as the destination IP address with the VC-Label for the service. The sdp-id defines the encapsulation of the SDP tunnel encapsulation used to reply to the originator; this can be IP/GRE or MPLS. On responder egress, the service-ID must have an associated VC-Label to reach the originator address of the sdp-id and the sdp-id must be operational for the message to be sent.
If remote-sdp is not specified, the svc-ping request message is sent with GRE encapsulation with the OAM label.
Message Response Encapsulation indicates how the message response is encapsulated based on the state of the remote service ID.
Table 5. Message Response Encapsulation Remote Service State
Message Encapsulation
remote-sdp
Not Specified
remote-sdp
Specified
Invalid Ingress Service Label
Generic IP/GRE OAM (PLP)
Generic IP/GRE OAM (PLP)
Invalid Service-ID
Generic IP/GRE OAM (PLP)
Generic IP/GRE OAM (PLP)
No Valid SDP-ID Bound on Service-ID
Generic IP/GRE OAM (PLP)
Generic IP/GRE OAM (PLP)
SDP-ID Valid But Down
Generic IP/GRE OAM (PLP)
Generic IP/GRE OAM (PLP)
SDP-ID Valid and Up, but No Service Label
Generic IP/GRE OAM (PLP)
Generic IP/GRE OAM (PLP)
SDP-ID Valid and Up, Egress Service Label, but VC-ID Mismatch
Generic IP/GRE OAM (PLP)
Generic IP/GRE OAM (PLP)
SDP-ID Valid and Up, Egress Service Label, but VC-ID Match
Generic IP/GRE OAM (PLP)
SDP Encapsulation with Egress Service Label (SLP)
Platforms
All
Output
Output Example*A:router1> svc-ping far-end 10.10.10.10 service 101 local-sdp remote-sdp
Request Result: Sent – Reply Received
Service-ID: 101
Err Basic Info Local Remote
--- ----------------- ------ ------
__ Type: TLS TLS
__ Admin State: Up Up
__ Oper State: Up Up
__ Service-MTU: 1514 1514
__ Customer ID: 1001 1001
Err System IP Interface Info
--- -------------------------------------------------------------
Local Interface Name: "7750 SR-System-IP-Interface (Up to 32 chars)…”
__ Local IP Interface State: Up
__ Local IP Address: 10.10.10.11
__ IP Address Expected By Remote: 10.10.10.11
__ Expected Remote IP Address: 10.10.10.10
__ Actual Remote IP Address: 10.10.10.10
Err SDP-ID Info Local Remote
--- ----------------- ------ ------
__ Path Used: Yes Yes
__ SDP-ID: 123 325
__ Administrative State: Up Up
__ Operative State: Up Up
__ Binding Admin State: Up Up
__ Binding Oper State: Up Up
__ Binding VC-ID: 101 101
Err Service Label Information Label Source State
--- ------------------------- ----- ----------- -----
__ Local Egress Label: 45 Signaled Up
__ Remote Expected Ingress: 45 Signaled Up
__ Remote Egress: 34 Signaled Up
__ Local Expected Ingress: 34 Signaled Up
svlan-statistics
svlan-statistics
Syntax
svlan-statistics
Context
[Tree] (config>subscr-mgmt svlan-statistics)
Full Context
configure subscriber-mgmt svlan-statistics
Description
Commands in this context enable subscriber VLAN statistics collection.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
swap
swap
Syntax
swap {out-label | implicit-null-label} nexthop ip-address
no swap
Context
[Tree] (config>router>mpls>if>label-map swap)
Full Context
configure router mpls interface label-map swap
Description
This command swaps the incoming label and specifies the outgoing label and next hop IP address on an LSR for a static LSP.
The no form of this command removes the swap action associated with the in-label.
Parameters
- implicit-null-label
-
Specifies the use of the implicit label value for the outgoing label of the swap operation.
- out-label
-
Specifies the label value to be swapped with the in-label. Label values 16 through 1,048,575 are defined as follows:
-
label values 16 through 31 are reserved
-
label values 32 through 1,023 are available for static assignment
-
label values 1,024 through 2,047 are reserved for future use
-
label values 2,048 through 18,431 are statically assigned for services
-
label values 28,672 through 131,071 are dynamically assigned for both MPLS and services
-
label values 131,072 through 1,048,575 are reserved for future use
-
- nexthop ip-address
-
Specifies the IP address to forward to. If an ARP entry for the next hop exists, then the static LSP will be marked operational. If ARP entry does not exist, software will set the operational status of the static LSP to down and continue to ARP for the configured nexthop. Software will continuously try to ARP for the configured nexthop at a fixed interval.
Platforms
All
sweep
sweep
Syntax
sweep start dispersion-start end dispersion-end
Context
[Tree] (config>port>dwdm>coherent sweep)
Full Context
configure port dwdm coherent sweep
Description
This command allows users to configure the dispersion sweep 'start’ and 'end’ values for the automatic mode of coherent control. If the user knows the approximate or theoretical residual dispersion of the link, this command can be used to limit the range of sweeping for the automatic control mode and thus achieve faster link up.
Parameters
- dispersion-start
-
Specifies the lower range limit for the dispersion compensation.
- dispersion-end
-
Specifies the upper range limit for the dispersion compensation.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
switch-defined-cookie
switch-defined-cookie
Syntax
[no] switch-defined-cookie
Context
[Tree] (config>open-flow>of-switch>flowtable switch-defined-cookie)
Full Context
configure open-flow of-switch flowtable switch-defined-cookie
Description
This command enables OpenFlow switch-defined Flow Table cookie encoding for flowtable 0 that allows multi-service operation.
The no form of the command disables the above function.
Default
no switch-defined-cookie
Platforms
VSR
switch-fabric
switch-fabric
Syntax
switch-fabric
Context
[Tree] (config>system switch-fabric)
Full Context
configure system switch-fabric
Description
Commands in this context configure switch fabric parameters.
Platforms
7450 ESS, 7750 SR-7, 7750 SR-12e, 7750 SR-7s, 7750 SR-14s, 7950 XRS
switching-mode
switching-mode
Syntax
switching-mode {bi-directional | uni-directional}
Context
[Tree] (config>port>aps switching-mode)
Full Context
configure port aps switching-mode
Description
This command configures the switching mode for the APS group.
Parameters
- bi-directional
-
Configures the group to operate in Bidirectional 1+1 Signaling APS mode.
- uni-directional
-
Configures the group to operate in Unidirectional 1+1 Signaling APS mode.
Platforms
7450 ESS, 7750 SR-7/12/12e, 7750 SR-a, 7750 SR-e
switchover-exec
switchover-exec
Syntax
switchover-exec file-url
no switchover-exec
Context
[Tree] (config>system switchover-exec)
Full Context
configure system switchover-exec
Description
This command specifies the location and name of the CLI script file executed following a redundancy switchover from the previously active CPM card. A switchover can happen because of a fatal failure or by manual action.
The CLI script file can contain commands for environment settings, classic CLI debug configuration (excluding mirroring settings), and other commands not maintained by the configuration redundancy.
The following commands are not supported in the switchover-exec file: clear, configure, candidate, oam, tools, oam, ping, traceroute, mstat, mtrace and mrinfo.
Default
no switch-over-exec
Parameters
- file-url
-
Specifies the location and name of the CLI script file.
Platforms
All
symbol-monitor
symbol-monitor
Syntax
symbol-monitor
Context
[Tree] (config>port>ethernet symbol-monitor)
Full Context
configure port ethernet symbol-monitor
Description
This command configures Ethernet Symbol Monitoring parameters. Support for symbol monitoring is hardware dependent. An error message indicating that the port setting cannot be modified will be presented when attempting to enable the feature or configure the individual parameters on unsupported hardware.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
sync
sync
Syntax
[no] sync
Context
[Tree] (config>redundancy>multi-chassis>peer sync)
Full Context
configure redundancy multi-chassis peer sync
Description
Commands in this context configure synchronization parameters.
Default
no sync
Platforms
All
sync
Syntax
[no] sync
Context
[Tree] (config>isa>nat-group>inter-chassis-redundancy sync)
Full Context
configure isa nat-group inter-chassis-redundancy sync
Description
This command configures synchronization of NAT flows between the nodes.
The no form of this command disables synchronization of NAT flows that were enabled between the ISAs or ESAs across the nodes. This allows NAT reconfiguration on both nodes. The synchronization of flows must be disabled on both nodes, active and standby, while NAT configuration changes are performed. The active NAT node continues to forward traffic while flow synchronization is disabled.
Default
no sync
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
sync-boot-env
sync-boot-env
Syntax
sync-boot-env
Context
[Tree] (admin>satellite>eth-sat sync-boot-env)
Full Context
admin satellite eth-sat sync-boot-env
Description
The command forces the specified Ethernet-satellite chassis to synchronize the boot image.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
sync-e
sync-e
Syntax
[no] sync-e
Context
[Tree] (config>card>mda sync-e)
[Tree] (config>card>xiom>mda sync-e)
Full Context
configure card mda sync-e
configure card xiom mda sync-e
Description
This command enables synchronous Ethernet on the MDA. Then any port on the MDA can be used as a source port in the sync-if-timing configuration.
The no form of this command disables synchronous Ethernet on the MDA.
Platforms
All
- configure card mda sync-e
7750 SR-1s, 7750 SR-2s, 7750 SR-2se, 7750 SR-7s, 7750 SR-14s
- configure card xiom mda sync-e
sync-e
Syntax
[no] sync-e
Context
[Tree] (config>system>satellite>eth-sat sync-e)
Full Context
configure system satellite eth-sat sync-e
Description
This command enables the Ethernet satellite for synchronous Ethernet operation so that the transmit timing of the satellite access ports use the frequency of the host router’s central clock.
To enable this functionality, both host ports on the router that connect to the U1 and U2 ports of the satellite must be synchronous Ethernet-capable ports.
When the Ethernet satellite is configured for synchronous Ethernet, ESMC frames are enabled on the host ports. The SSM code-type used between the host and the satellite should be manually configured on the host ports to match the code-type desired on the satellite client ports. The code-type setting on the host ports does not restrict the code-type used on the satellite client ports, as those may be configured on an individual port basis.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
sync-if-timing
sync-if-timing
Syntax
sync-if-timing
Context
[Tree] (config>system sync-if-timing)
Full Context
configure system sync-if-timing
Description
This command creates or edits the context to create or modify timing reference parameters.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
sync-if-timing
Syntax
sync-if-timing
Context
[Tree] (config>system>sat>eth-sat sync-if-timing)
Full Context
configure system satellite eth-sat sync-if-timing
Description
Commands in this context configure references used in the Ethernet satellite.
The configure system satellite eth-sat sync-e command must first be configured before commands in this context are accepted.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
sync-if-timing
Syntax
sync-if-timing
Context
[Tree] (debug sync-if-timing)
Full Context
debug sync-if-timing
Description
The context to debug synchronous interface timing references.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
synce
synce
Syntax
synce
Context
[Tree] (config>system>sync-if-timing synce)
Full Context
configure system sync-if-timing synce
Description
Commands in this context configure attributes related to the CPM/CCM SyncE/1588 ports.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
synchronize
synchronize
Syntax
synchronize {boot-env | config}
Context
[Tree] (config>redundancy synchronize)
Full Context
configure redundancy synchronize
Description
This command enables the automatic synchronization of the standby CPM's images and/or config files from the active CPM. Either the boot-env or config parameter must be specified. When the standby CPM takes over operation following a failure or reset of the active CPM, it is important to ensure that the active and standby CPMs have identical software images and configuration files. This includes the saved configuration, saved incremental configuration files in model-driven configuration mode, CPM, XCM, and IOM images.
The active CPM ensures that the active configuration is maintained on the standby CPM. However, to ensure smooth operation under all circumstances, runtime images and system initialization configurations must also be automatically synchronized between the active and standby CPM.
If synchronization fails, alarms and log messages that indicate the type of error that caused the failure of the synchronization operation are generated. When the error condition ceases to exist, the alarm is cleared.
Only files stored on the router are synchronized. If a configuration file or image is stored in a location other than on a local compact flash, the file is not synchronized (for example, storing a configuration file on an FTP server).
Default
synchronize config
Parameters
- boot-env
-
Synchronizes all files required for the boot process (boot loader, BOF configuration, SR OS images, and all configuration files).
- config
-
Synchronizes the primary, secondary, and tertiary configuration files, SSH keys, the password history and the model-driven commit history.
Platforms
All
synchronize
Syntax
synchronize cert
synchronize {boot-env | config}
Context
[Tree] (admin>redundancy synchronize)
Full Context
admin redundancy synchronize
Description
This command performs a synchronization of the standby CPM’s images and/or configuration files to the active CPM. Either the boot-env or config parameter must be specified.
In the admin>redundancy context, this command performs a manually triggered standby CPM synchronization. When the standby CPM takes over operation following a failure or reset of the active CPM, it is important to ensure that the active and standby CPM have identical operational parameters. This includes the saved configuration, CPM, XCM, and IOM images.
The active CPM ensures that the active configuration is maintained on the standby CPM. However, to ensure smooth operation under all circumstances, runtime images and system initialization configurations must also be automatically synchronized between the active and standby CPM. If synchronization fails, alarms and log messages that indicate the type of error that caused the failure of the synchronization operation are generated. When the error condition ceases to exist, the alarm is cleared.
Only files stored on the router are synchronized. If a configuration file or image is stored in a location other than on a local compact flash, the file is not synchronized (for example, storing a configuration file on an FTP server).
The no form of the command removes the parameter from the configuration.
Default
no synchronize
Parameters
- cert
-
Synchronizes the imported certificate, key, and CRL files.
- boot-env
-
Synchronizes all files required for the boot process (boot loader, BOF, images, and configuration).
- config
-
Synchronizes the primary, secondary, and tertiary configuration files.
Platforms
All
synchronous-execution
synchronous-execution
Syntax
synchronous-execution seconds
synchronous-execution never
Context
[Tree] (config>system>management-interface>ops>global-timeouts synchronous-execution)
Full Context
configure system management-interface operations global-timeouts synchronous-execution
Description
This command configures the period of time that operations launched as "'synchronous” (the default method for all operations) are allowed to execute before they are automatically stopped, and their associated data is deleted.
If a specific execution timeout is not included in the request for a particular synchronous operation, this system-level timeout applies.
This execution timeout is part of the general global operations infrastructure and is separate and independent from any operation-specific timeouts (for example, the ping operation also has its own timeout parameter).
This timeout also applies to operations requested in the MD-CLI interface (for example, ping, file dir, and so on). If synchronous-execution is enabled with a specific time value, MD-CLI operations are subject to this timeout and are interrupted if they execute longer than the configured synchronous-execution time.
Default
synchronous-execution never
Parameters
- seconds
-
Specifies the period of time, in seconds, that synchronous operations are allowed to execute.
- never
-
Keyword to specify that an execution timeout is not applied to synchronous operations.
Platforms
All
syslog
syslog
Syntax
syslog script name
no syslog
Context
[Tree] (config>python>py-policy syslog)
Full Context
configure python python-policy syslog
Description
This command enables Python script to process syslog related messages and events.
The no form of this command disables the Python script to process syslog related messages and events.
Parameters
- name
-
Specifies the name of the Python script, up to 32 characters, that is used to handle the specified message.
Platforms
All
syslog
Syntax
syslog syslog-id [name syslog-name]
no syslog syslog-id
Context
[Tree] (config>service>vprn>log syslog)
Full Context
configure service vprn log syslog
Description
This command creates the context to configure a Syslog target host that is capable of receiving selected Syslog messages from this network element.
A valid syslog-id must have the target Syslog host address configured.
A maximum of 30 Syslog IDs can be configured.
No log events are sent to a Syslog target address until the syslog-id has been configured as the log destination (to) in the log-id node.
The Syslog ID configured in the configure>service>vprn context has a local VPRN scope and only needs to be unique within the specific VPRN instance. The same ID can be reused under a different VPRN service or in the global log context under config>log.
Default
No syslog IDs are defined.
Parameters
- syslog-id
-
Specifies the Syslog ID for the Syslog destination.
- name syslog-name
-
Specifies an optional Syslog name, up to 64 characters, that can be used to refer to the Syslog destination after it is created.
Platforms
All
syslog
Syntax
syslog
Context
[Tree] (config>app-assure>group>evt-log syslog)
Full Context
configure application-assurance group event-log syslog
Description
Commands in this context configure the target syslog server.
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
syslog
Syntax
syslog
Context
[Tree] (config>service>nat syslog)
Full Context
configure service nat syslog
Description
Commands in this context configure syslog reporting of NAT flow parameters.
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
syslog
Syntax
syslog syslog-id [name syslog-name]
no syslog syslog-id
Context
[Tree] (config>log syslog)
Full Context
configure log syslog
Description
Commands in this context configure a Syslog target host capable of receiving selected syslog messages from this network element.
A valid syslog-id must have the target Syslog host address configured.
A maximum of 10 Syslog IDs can be configured.
Log events are not sent to a Syslog target address until the syslog-id is configured as the log destination (to) in the node specified by the Log ID.
The Syslog ID configured in the config>service>vprn context has a local VPRN scope and only needs to be unique within the specific VPRN instance. The same ID can be reused under a different VPRN service or in the global log context under config>log.
The no form of this command removes the Syslog configuration.
Parameters
- syslog-id
-
Specifies the Syslog ID for the Syslog destination.
- name syslog-name
-
Configures an optional Syslog name, up to 64 characters, that can be used to refer to the Syslog destination after it is created.
Platforms
All
syslog-export-policy
syslog-export-policy
Syntax
syslog-export-policy policy-name
no syslog-export-policy
Context
[Tree] (config>service>nat>nat-policy syslog-export-policy)
Full Context
configure service nat nat-policy syslog-export-policy
Description
This command creates a syslog export policy with a set of transport parameters that will be used to transmit NAT flow records in syslog format to an external collector node. This policy name is then referenced from the nat-policy applied to an inside routing context.
Default
no syslog-export-policy
Parameters
- policy-name
-
Specifies the name of the syslog export policy.
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
syslog-export-policy
Syntax
syslog-export-policy name [create]
no syslog-export-policy name
Context
[Tree] (config>service>nat>syslog syslog-export-policy)
Full Context
configure service nat syslog syslog-export-policy
Description
This command creates a syslog export policy with a set of transport parameters that are used to transmit NAT flow records in syslog format to an external collector node. This policy name is then referenced from the NAT policy applied to an inside routing context.
The no form of the command removes the policy name from the configuration.
Parameters
- name
-
Specifies the syslog export policy name, up to 32 characters.
- create
-
Keyword used to create the syslog export policy.
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
system
system
Syntax
system
Context
[Tree] (config>eth-cfm system)
Full Context
configure eth-cfm system
Description
Commands in this context configure Connectivity Fault Management (CFM) general system parameters.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS
system
Syntax
[no] system
Context
[Tree] (debug system)
Full Context
debug system
Description
This command displays system debug information.
Platforms
All
system-base-mac
system-base-mac
Syntax
system-base-mac mac-address
no system-base-mac
Context
[Tree] (bof system-base-mac)
Full Context
bof system-base-mac
Description
This command is used to specify the base MAC address for a VSR-based system. The specified MAC address is used as the first MAC address by the system to assign MAC addresses to individual interfaces.
It is strongly recommended that a unique base MAC address is assigned to each VSR instance with a minimum gap of 1024 between base addresses to avoid a MAC address overlap.
The no form of this command removes the configured system base MAC address.
Default
no system-base-mac
Parameters
- mac-address
-
Specifies the MAC address.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS-20, 7950 XRS-20e, VSR
system-behavior
system-behavior
Syntax
system-behavior
Context
[Tree] (config>subscr-mgmt system-behavior)
Full Context
configure subscriber-mgmt system-behavior
Description
Commands in this context configure system-wide subscriber management behavior parameters.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
system-filter
system-filter
Syntax
system-filter
Context
[Tree] (config>filter system-filter)
Full Context
configure filter system-filter
Description
Commands in this context activate system filter policies.
Platforms
All
system-id
system-id
Syntax
system-id system-id
no system-id
Context
[Tree] (config>subscr-mgmt>loc-user-db>ipoe>host>host-ident system-id)
Full Context
configure subscriber-mgmt local-user-db ipoe host host-identification system-id
Description
This command specifies the system ID to match for a host lookup. When the LUDB is accessed through a DHCPv4 server, the system ID is matched against the Nokia vendor specific sub-option in DHCP Option 82.
This command is only used when system-id is configured as one of the match-list parameters.
The no form of this command removes the system ID from the configuration.
Parameters
- system-id
-
Specifies the system ID, up to 255 characters
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
system-id
Syntax
[no] system-id
Context
[Tree] (config>service>ies>sub-if>grp-if>dhcp>option>vendor system-id)
[Tree] (config>subscr-mgmt>msap-policy>vpls-only>dhcp>option>vendor system-id)
[Tree] (config>service>vpls>sap>dhcp>option>vendor system-id)
[Tree] (config>service>vprn>if>dhcp>option>vendor system-id)
[Tree] (config>service>vprn>sub-if>grp-if>dhcp>option>vendor system-id)
Full Context
configure service ies subscriber-interface group-interface dhcp option vendor-specific-option system-id
configure subscriber-mgmt msap-policy vpls-only-sap-parameters dhcp option vendor-specific-option system-id
configure service vpls sap dhcp option vendor-specific-option system-id
configure service vprn interface dhcp option vendor-specific-option system-id
configure service vprn subscriber-interface group-interface dhcp option vendor-specific-option system-id
Description
This command specifies whether the system-id is encoded in the Nokia vendor-specific sub-option of Option 82.
The no form of this command reverts to the default.
Platforms
7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR
- configure service ies subscriber-interface group-interface dhcp option vendor-specific-option system-id
- configure subscriber-mgmt msap-policy vpls-only-sap-parameters dhcp option vendor-specific-option system-id
- configure service vprn subscriber-interface group-interface dhcp option vendor-specific-option system-id
All
- configure service vprn interface dhcp option vendor-specific-option system-id
- configure service vpls sap dhcp option vendor-specific-option system-id
system-id
Syntax
system-id isis-system-id
no system-id
Context
[Tree] (config>service>vprn>isis system-id)
Full Context
configure service vprn isis system-id
Description
This command configures the IS-IS system ID. The system ID has a fixed length of 6 octets; it is determined using the following preference order:
-
config>service>vprn>isis>system-id
-
config>service>vprn>isis>router-id
-
config>service>vprn>router-id
-
config>service>vprn>if>address
-
The default system ID 2550.0000.0000, based on the default router ID 255.0.0.0
The system ID is integral to IS-IS; therefore, for the system-id command to take effect, a shutdown and then no shutdown must be performed on the IS-IS instance. This will ensure that the configured and operational system ID are always the same.
The no form of this command removes the system ID from the configuration. The router ID is used when no system ID is specified.
Default
no system-id
Parameters
- isis-system-id
-
12 hexadecimal characters in dotted-quad notation.
Platforms
All
system-id
Syntax
[no] system-id
Context
[Tree] (config>router>if>dhcp>option>vendor-specific-option system-id)
Full Context
configure router interface dhcp option vendor-specific-option system-id
Description
This command specifies whether the system-id is encoded in the Nokia vendor-specific sub-option of Option 82.
Default
no system-id
Platforms
All
system-id
Syntax
system-id isis-system-id
no system-id
Context
[Tree] (config>router>isis system-id)
Full Context
configure router isis system-id
Description
This command configures the IS-IS system ID. The system ID has a fixed length of 6 octets; it is determined using the following preference:
-
config>router>isis>system-id
-
config>router>isis>router-id
-
config>router>router-id
-
config>router>interface>system> address
-
The default system ID 2550.0000.0000, based on the default router ID 255.0.0.0
The system ID is integral to IS-IS; therefore, for the system-id command to take effect, the IS-IS instance must be shutdown and then no shutdown. This will ensure that the configured and operational system ID are always the same.
The no form of this command removes the system ID from the configuration. The router ID is used when no system ID is specified.
Parameters
- isis-system-id
-
Specifies 12 hexadecimal characters in dotted-quad notation.
Platforms
All
system-ip-load-balancing
system-ip-load-balancing
Syntax
[no] system-ip-load-balancing
Context
[Tree] (config>system>load-balancing system-ip-load-balancing)
Full Context
configure system load-balancing system-ip-load-balancing
Description
This command enables the use of the system IP address in the ECMP hash algorithm to add a per system variable. This can help guard against cases where multiple routers, in series, will end up hashing traffic to the same ECMP/LAG path.
This command is set at a system wide basis, however if certain IOMs do not support the new load-balancing algorithm, they will continue to use the default algorithm. By default, the IPv4 system IP address is used in the hash algorithm. When no IPv4 system IP address is configured, the IPv6 system IP address, when configured, is used in the hash algorithm.
The no form of the command resets the system wide algorithm to default.
Default
no system-ip-load-balancing
Platforms
All
system-mac
system-mac
Syntax
system-mac mac-address
no system-mac
Context
[Tree] (config>system>ned>profile system-mac)
Full Context
configure system network-element-discovery profile system-mac
Description
This command configures the MAC address to be advertised.
The no form of this command removes any explicitly defined MAC address and chassis MAC address will be advertised.
Default
no system-mac
Parameters
- mac-address
-
Specifies the MAC address to be associated with the profile in xx:xx:xx:xx:xx:xx or xx-xx-xx-xx-xx-xx format.
Platforms
All
system-name
system-name
Syntax
system-name name
[no] system-name
Context
[Tree] (config>app-assure>group>cflowd system-name)
Full Context
configure application-assurance group cflowd system-name
Description
This command configures the system name of the cflowd AA group. This is exported to the comprehensive cflowd template as aaSystemName.
The no form of this command removes the cflowd system name.
Default
no system-name
Parameters
- name
-
Specifies the name of the system, up to 32 characters.
Platforms
7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR
system-password
system-password
Syntax
system-password admin-password
system-password dynsvc-password
Context
[Tree] (admin>system>security system-password)
Full Context
admin system security system-password
Description
This operational command changes a local system password.
Parameters
- admin-password
-
Specifies to change the administrative password.
- dynsvc-password
-
Specifies to change the dynamic services password.
Platforms
All
system-priority
system-priority
Syntax
system-priority value
no system-priority
Context
[Tree] (config>redundancy>multi-chassis>peer>mc-ep system-priority)
Full Context
configure redundancy multi-chassis peer mc-endpoint system-priority
Description
This command allows the operator to set the system priority. The peer configured with the lowest value is chosen to be the master. If system-priority are equal then the one with the highest system-id (chassis MAC address) is chosen as the master.
The no form of this command sets the system priority to default.
Default
no system-priority
Parameters
- value
-
Specifies the priority assigned to the local MC-EP peer.
Platforms
All
system-profile
system-profile
Syntax
system-profile {profile-a | profile-b}
no system-profile
Context
[Tree] (bof system-profile)
Full Context
bof system-profile
Description
This command configures the system profile in the BOF.
System profile none represents the existing system capabilities and allows hardware based on FP3 and later generations (for example, FP4, FP5) to co-exist within a system. This profile is indicated by the omission of the system-profile parameter in the BOF.
System profile profile-a is primarily targeted at subscriber services and layer 2 and 3 VPN business services.
System profile profile-b is primarily targeted at infrastructure routing, core, peering, and DC-GW applications.
System profiles profile-a and profile-b support only line cards based on FP4 and later generations (for example, FP5).
On 7750 SR-1 and 7750 SR-s systems, the following conditions apply about the profile parameter:
-
The parameter should be configured to either profile-a or profile-b.
-
If the parameter is omitted, profile profile-a is used by the system.
-
If the parameter is configured to an invalid value, it is ignored and profile profile-a is used by the system.
On 7750 SR-7-B/12-B/12e and 7950 XRS-20/20e systems, the following conditions apply about the profile parameter:
-
The default system profile is none when the parameter is omitted.
-
The parameter can be configured to either profile-a or profile-b, in which case only FP4-based line cards are supported.
-
If the parameter is configured to an invalid value, it is ignored and profile none is used by the system.
On all other systems, the following conditions apply about the profile parameter:
-
These systems must use profile none (the existing system capabilities). As a result, the parameter must not be configured.
-
If the parameter is configured to profile-a or profile-b, the system boots, allowing access using the console and CPM management interface, but FP2-based and FP3-based line cards cannot be provisioned; if these card types are present in the boot configuration, the boot sequence aborts loading the configuration file when it encounters their configuration. This issue can be corrected by removing the parameter and rebooting the system.
-
If the parameter is configured to an invalid value, it is ignored and profile none is used by the system.
See "System profiles" in the 7450 ESS, 7750 SR, 7950 XRS, and VSR Basic System Configuration Guide for more information.
The no form of this command removes the system-profile parameter from the BOF.
Parameters
- profile-a
-
Specifies that the system profile is for subscriber services and Layer 2 and 3 VPN business services.
- profile-b
-
Specifies that the system profile is primarily targeted at infrastructure routing, core, peering, and DC-GW applications.
Platforms
All
system-reserve
system-reserve
Syntax
system-reserve percent-of-buffers
no system-reserve
Context
[Tree] (config>qos>hs-pool-policy system-reserve)
Full Context
configure qos hs-pool-policy system-reserve
Description
This command defines the amount of HSQ IOM buffers that is set aside for internal system use. By default, 5% of the total buffer space is reserved for system internal queues. The command is provided for the case where the reserved buffer space is either insufficient or excessive. Exercise care when modifying this value.
When the system reserve value is changed, all the provisioned port-class, mid-tier, and root pool sizes are reevaluated and possibly changed.
Use the show hs-pools card-slot-number fp forwarding-plane egress command to display the current buffer allocation and buffer usage conditions on an HSQ IOM.
The no form of the command reverts to the default system reserve value.
Default
system-reserve 5.0
Parameters
- percent-of-buffers
-
Specifies the percentage of HS buffers that are reserved for internal system use. This parameter is required when executing the system-reserve command. The parameter accepts a percent value with two decimal places (100th of a percent).
Platforms
7750 SR-7/12/12e