li commands

li 
li-filter 
associations 
li-ip-filter reference 
ip-filter filter-name 
li-ipv6-filter reference 
ipv6-filter filter-name 
li-mac-filter reference 
mac-filter filter-name 
li-ip-filter named-item 
description description
entry number 
description description
match 
dst-ip 
address (ipv4-prefix-with-host-bits | ipv4-address)
mask ipv4-address
dst-port 
eq number
gt number
lt number
range 
end number
start number
fragment keyword
protocol (number | keyword)
src-ip 
address (ipv4-prefix-with-host-bits | ipv4-address)
mask ipv4-address
src-port 
eq number
gt number
lt number
range 
end number
start number
li-ipv6-filter named-item 
description description
entry number 
description description
match 
dst-ip 
address (ipv6-prefix-with-host-bits | ipv6-address)
mask ipv6-address
dst-port 
eq number
gt number
lt number
range 
end number
start number
next-header (number | keyword)
src-ip 
address (ipv6-prefix-with-host-bits | ipv6-address)
mask ipv6-address
src-port 
eq number
gt number
lt number
range 
end number
start number
li-mac-filter named-item 
description description
entry number 
description description
match 
dst-mac 
address mac-address
mask mac-address
frame-type keyword
outer-tag number
sap sap
src-mac 
address mac-address
mask mac-address
lock-filter keyword
reserved-block named-item 
description description
entry-range 
end number
start number
ip-filter filter-name 
ipv6-filter filter-name 
mac-filter filter-name 
li-source service-name 
admin-state keyword
li-ip-filter reference 
entry reference 
intercept-id number
session-id number
li-ipv6-filter reference 
entry reference 
intercept-id number
session-id number
li-mac-filter reference 
entry reference 
intercept-id number
session-id number
nat 
dslite service-name b4 ipv6-prefix 
intercept-id number
session-id number
ethernet-header 
destination-address mac-address
source-address mac-address
type number
l2-aware subscriber-id 
intercept-id number
session-id number
nat44 service-name ip ipv4-address 
intercept-id number
session-id number
nat64 service-name ip ipv6-prefix 
intercept-id number
session-id number
port mirror-source-port-lag-key 
egress boolean
ingress boolean
sap sap 
egress boolean
ingress boolean
intercept-id number
session-id number
subscriber subscriber-id 
egress boolean
fc keyword
host-type keyword
ingress boolean
intercept-id number
ip-address ipv4-address
ip-family keyword
mac-address mac-address
sap-id sap
session-id number
sla-profile external-named-item
wlan-gw-dsm-ue mac-address 
intercept-id number
session-id number
log 
log-id li-log-name 
admin-state keyword
description description
destination 
memory 
max-entries number
netconf 
max-entries number
snmp 
max-entries number
send-using-vprn service-name
filter log-filter-name
netconf-stream named-item
source 
li boolean
time-format keyword
mirror-dest-reservation 
end number
start number
mirror-dest-template named-item 
layer-3-encap 
direction-bit boolean
encap-type keyword
ip-source ipv4-unicast-address
router-instance router-instance
udp 
destination number
source number
type keyword
nat 
use-outside-ip-address boolean
radius 
mirror-dest-template reference
sci 
pfcp-li-shared-key encrypted-leaf
x-interfaces 
admin-state keyword
correlation-id 
ipoe keyword
pppoe keyword
ine-identifier named-item
lic named-item 
authentication 
password li-static-encrypted-leaf-hex
private-ki li-static-encrypted-leaf
sequence-group li-static-encrypted-leaf
description description
identifier named-item
ipv4 
ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
port number
router-instance named-item-64-or-empty
user-db named-item
x1 
ipv4 
local-address (ipv4-address-no-zone | ipv6-address-no-zone)
lic-peer reference
local-tcp-port number
timeouts 
message-timeout number
x2 
ipv4 
local-address (ipv4-address-no-zone | ipv6-address-no-zone)
lic-peer reference
timeouts 
keep-alive number
request number
x3 
alarms 
cpu-alarm 
high-threshold number
low-threshold number
memory-alarm 
high-threshold number
low-threshold number
throughput-alarm 
high-threshold number
low-threshold number
ipv4 
local-address-range 
end ipv4-unicast-address
start ipv4-unicast-address
li-group number
lic-peers reference 
session-limit number
timeouts 
keep-alive number
request number
target-retry-wait number

li command descriptions

li

Synopsis Configure lawful intercept
Context li
Tree li
Introduced19.10.R1

Platforms

All

li-filter

Synopsis Enter the li-filter context
Context li li-filter
Treeli-filter
Introduced19.10.R1

Platforms

All

associations
Synopsis Enter the associations context
Contextli li-filter associations
Treeassociations
Introduced19.10.R1

Platforms

All

li-ip-filter [li-filter-name] reference
Synopsis Enter the li-ip-filter list instance
Contextli li-filter associations li-ip-filter reference
Treeli-ip-filter
Introduced19.10.R1

Platforms

All

ip-filter [filter-name] filter-name
Synopsis Add a list entry for ip-filter
Contextli li-filter associations li-ip-filter reference ip-filter filter-name
Treeip-filter
Max. instances1
Min. instances1
Introduced 19.10.R1

Platforms

All

[filter-name] filter-name
Synopsis IP filter to be associated with specified LI IP filter
Contextli li-filter associations li-ip-filter reference ip-filter filter-name
Treeip-filter
String length1 to 64

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

li-ipv6-filter [li-filter-name] reference
Synopsis Enter the li-ipv6-filter list instance
Contextli li-filter associations li-ipv6-filter reference
Treeli-ipv6-filter
Introduced19.10.R1

Platforms

All

ipv6-filter [filter-name] filter-name
Synopsis Add a list entry for ipv6-filter
Contextli li-filter associations li-ipv6-filter reference ipv6-filter filter-name
Treeipv6-filter
Max. instances1
Min. instances1
Introduced 19.10.R1

Platforms

All

li-mac-filter [li-filter-name] reference
Synopsis Enter the li-mac-filter list instance
Contextli li-filter associations li-mac-filter reference
Treeli-mac-filter
Introduced19.10.R1

Platforms

All

mac-filter [filter-name] filter-name
Synopsis Add a list entry for mac-filter
Contextli li-filter associations li-mac-filter reference mac-filter filter-name
Treemac-filter
Max. instances1
Min. instances1
Introduced 19.10.R1

Platforms

All

li-ip-filter [li-filter-name] named-item
Synopsis Enter the li-ip-filter list instance
Contextli li-filter li-ip-filter named-item
Treeli-ip-filter

Description

Commands in this context create LI IPv4 filter lists, which can be used to create confidential IPv4 filter based LI source entries.

The LI IPv4 filter entries are merged into normal IPv4 filters configured with the li li-filter associations and li li-filter reserved-block commands. The LI IPv4 filter entries are visible only to users with LI permissions.

Introduced19.10.R1

Platforms

All

[li-filter-name] named-item
Synopsis LI filter name
Contextli li-filter li-ip-filter named-item
Treeli-ip-filter

Description

This command specifies the LI filter name. Filter names cannot start with an underscore character (for example, “_my-filter”) and cannot use the name “default”.

String length1 to 32

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

entry [li-entry-id] number
Synopsis Enter the entry list instance
Context li li-filter li-ip-filter named-item entry number
Treeentry

Description

Commands in this context configure an entry for the LI filter. 

Multiple entries can be created using unique entry ID numbers within the filter.  An entry in an LI filter always has an implicit action of “forward”. LI filter entries can be used as LI source entries.

The entry numbers for LI filters serve only as keys for managing the entries (deleting entries, and so on). The order of the LI filter entries is not guaranteed to match the entry numbers and the software may reorder entries. Operators must therefore use LI entries in such a way that their relative order is not important.

Entries removed from the filter are immediately removed from all services or network ports where the associated filter is applied.

Introduced19.10.R1

Platforms

All

[li-entry-id] number
Synopsis LI filter entry ID
Context li li-filter li-ip-filter named-item entry number
Treeentry
Range1 to 65535

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

match
Synopsis Enter the match context
Context li li-filter li-ip-filter named-item entry number match
Treematch

Description

Commands in this context configure match criteria for the filter entry. If more than one match criteria (within one match statement) are configured, all criteria must be satisfied (and function) for a match to occur.

A match context may consist of multiple match criteria, but multiple match statements cannot be configured per entry.

Introduced19.10.R1

Platforms

All

dst-ip
Synopsis Enter the dst-ip context
Context li li-filter li-ip-filter named-item entry number match dst-ip
Treedst-ip
Introduced19.10.R1

Platforms

All

dst-port
Synopsis Enter the dst-port context
Context li li-filter li-ip-filter named-item entry number match dst-port
Treedst-port
Introduced19.10.R1

Platforms

All

eq number
Synopsis Condition on equality to specified value
Contextli li-filter li-ip-filter named-item entry number match dst-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

gt number
Synopsis Condition on being greater than the specified value
Contextli li-filter li-ip-filter named-item entry number match dst-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

lt number
Synopsis Condition on being less than the specified value
Contextli li-filter li-ip-filter named-item entry number match dst-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

range
Synopsis Enable the range context
Context li li-filter li-ip-filter named-item entry number match dst-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

protocol (number | keyword)
Synopsis IP protocol to match
Context li li-filter li-ip-filter named-item entry number match protocol (number | keyword)
Treeprotocol
Range0 to 255
Optionstcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp
Introduced 19.10.R1

Platforms

All

src-ip
Synopsis Enter the src-ip context
Context li li-filter li-ip-filter named-item entry number match src-ip
Treesrc-ip
Introduced19.10.R1

Platforms

All

src-port
Synopsis Enter the src-port context
Context li li-filter li-ip-filter named-item entry number match src-port
Treesrc-port
Introduced19.10.R1

Platforms

All

eq number
Synopsis Condition on equality to specified value
Contextli li-filter li-ip-filter named-item entry number match src-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

gt number
Synopsis Condition on being greater than the specified value
Contextli li-filter li-ip-filter named-item entry number match src-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

lt number
Synopsis Condition on being less than the specified value
Contextli li-filter li-ip-filter named-item entry number match src-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

range
Synopsis Enable the range context
Context li li-filter li-ip-filter named-item entry number match src-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

li-ipv6-filter [li-filter-name] named-item
Synopsis Enter the li-ipv6-filter list instance
Contextli li-filter li-ipv6-filter named-item
Treeli-ipv6-filter

Description

Commands in this context create LI IPv6 filter lists, which can be used to create confidential IPv6 filter based LI source entries.

The LI IPv6 filter entries are merged into normal IPv6 filters configured with the li li-filter associations and li li-filter reserved-block commands. However, the LI IPv6 filter entries are visible only to users with LI permissions.

Introduced19.10.R1

Platforms

All

[li-filter-name] named-item
Synopsis LI filter name
Contextli li-filter li-ipv6-filter named-item
Treeli-ipv6-filter

Description

This command specifies the LI filter name. Filter names cannot start with an underscore character (for example, “_my-filter”) and cannot use the name “default”.

String length1 to 32

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

entry [li-entry-id] number
Synopsis Enter the entry list instance
Context li li-filter li-ipv6-filter named-item entry number
Treeentry

Description

Commands in this context configure an entry for the LI filter. 

Multiple entries can be created using unique entry ID numbers within the filter.  An entry in an LI filter always has an implicit action of “forward”. LI filter entries can be used as LI source entries.

The entry numbers for LI filters serve only as keys for managing the entries (deleting entries, and so on). The order of the LI filter entries is not guaranteed to match the entry numbers and the software may reorder entries. Operators must therefore use LI entries in such a way that their relative order is not important.

Entries removed from the filter are immediately removed from all services or network ports where the associated filter is applied.

Introduced19.10.R1

Platforms

All

[li-entry-id] number
Synopsis LI filter entry ID
Context li li-filter li-ipv6-filter named-item entry number
Treeentry
Range1 to 65535

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

match
Synopsis Enter the match context
Context li li-filter li-ipv6-filter named-item entry number match
Treematch

Description

Commands in this context configure match criteria for the filter entry. If more than one match criteria (within one match statement) are configured, all criteria must be satisfied (and function) for a match to occur.

A match context may consist of multiple match criteria, but multiple match statements cannot be configured per entry.

Introduced19.10.R1

Platforms

All

dst-ip
Synopsis Enter the dst-ip context
Context li li-filter li-ipv6-filter named-item entry number match dst-ip
Treedst-ip
Introduced19.10.R1

Platforms

All

dst-port
Synopsis Enter the dst-port context
Context li li-filter li-ipv6-filter named-item entry number match dst-port
Treedst-port
Introduced19.10.R1

Platforms

All

eq number
Synopsis Condition on equality to specified value
Contextli li-filter li-ipv6-filter named-item entry number match dst-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

gt number
Synopsis Condition on being greater than the specified value
Contextli li-filter li-ipv6-filter named-item entry number match dst-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

lt number
Synopsis Condition on being less than the specified value
Contextli li-filter li-ipv6-filter named-item entry number match dst-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

range
Synopsis Enable the range context
Context li li-filter li-ipv6-filter named-item entry number match dst-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

next-header (number | keyword)
Synopsis IP protocol to match
Context li li-filter li-ipv6-filter named-item entry number match next-header (number | keyword)
Treenext-header
Range0 to 255
Optionstcp-udp, icmp, igmp, ip, tcp, egp, igp, udp, rdp, ipv6, ipv6-route, ipv6-frag, idrp, rsvp, gre, ipv6-icmp, ipv6-no-nxt, ipv6-opts, iso-ip, eigrp, ospf-igp, ether-ip, encap, pnni, pim, vrrp, l2tp, stp, ptp, isis, crtp, crudp, sctp
Introduced 19.10.R1

Platforms

All

src-ip
Synopsis Enter the src-ip context
Context li li-filter li-ipv6-filter named-item entry number match src-ip
Treesrc-ip
Introduced19.10.R1

Platforms

All

src-port
Synopsis Enter the src-port context
Context li li-filter li-ipv6-filter named-item entry number match src-port
Treesrc-port
Introduced19.10.R1

Platforms

All

eq number
Synopsis Condition on equality to specified value
Contextli li-filter li-ipv6-filter named-item entry number match src-port eq number
Treeeq
Range0 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

gt number
Synopsis Condition on being greater than the specified value
Contextli li-filter li-ipv6-filter named-item entry number match src-port gt number
Treegt
Range0 to 65534

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

lt number
Synopsis Condition on being less than the specified value
Contextli li-filter li-ipv6-filter named-item entry number match src-port lt number
Treelt
Range1 to 65535

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

range
Synopsis Enable the range context
Context li li-filter li-ipv6-filter named-item entry number match src-port range
Treerange

Notes

The following elements are part of a choice: eq, gt, lt, or range.

Introduced19.10.R1

Platforms

All

li-mac-filter [li-filter-name] named-item
Synopsis Enter the li-mac-filter list instance
Contextli li-filter li-mac-filter named-item
Treeli-mac-filter

Description

Commands in this context configure LI MAC filter lists, which can be used to create confidential MAC filter based LI source entries. 

The LI MAC filter entries are merged into normal MAC filters as configured using the li-filter associations and li-filter reserved-block commands. The LI MAC filter entries are visible only to users with LI permissions.

Introduced19.10.R1

Platforms

All

[li-filter-name] named-item
Synopsis LI filter name
Contextli li-filter li-mac-filter named-item
Treeli-mac-filter

Description

This command specifies the LI filter name. Filter names cannot start with an underscore character (for example, “_my-filter”) and cannot use the name “default”.

String length1 to 32

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

entry [li-entry-id] number
Synopsis Enter the entry list instance
Context li li-filter li-mac-filter named-item entry number
Treeentry

Description

Commands in this context configure an entry for the LI filter. 

Multiple entries can be created using unique entry ID numbers within the filter.  An entry in an LI filter always has an implicit action of “forward”. LI filter entries can be used as LI source entries.

The entry numbers for LI filters serve only as keys for managing the entries (deleting entries, and so on). The order of the LI filter entries is not guaranteed to match the entry numbers and the software may reorder entries. Operators must therefore use LI entries in such a way that their relative order is not important.

Entries removed from the filter are immediately removed from all services or network ports where the associated filter is applied.

Introduced19.10.R1

Platforms

All

[li-entry-id] number
Synopsis LI filter entry ID
Context li li-filter li-mac-filter named-item entry number
Treeentry
Range1 to 65535

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

match
Synopsis Enter the match context
Context li li-filter li-mac-filter named-item entry number match
Treematch

Description

Commands in this context configure match criteria for the filter entry. If more than one match criteria (within one match statement) is configured, all criteria must be satisfied (and function) for a match to occur.

A match context may consist of multiple match criteria, but multiple match statements cannot be configured per entry.

Introduced19.10.R1

Platforms

All

dst-mac
Synopsis Enable the dst-mac context
Context li li-filter li-mac-filter named-item entry number match dst-mac
Treedst-mac
Introduced19.10.R1

Platforms

All

frame-type keyword
Synopsis Frame type for MAC filter match
Context li li-filter li-mac-filter named-item entry number match frame-type keyword
Treeframe-type

Description

This command specifies the frame type for MAC filter entry matching. A filter can be edited even if an LI source references an entry in the filter.

Options802dot3, 802dot2-llc, 802dot2-snap, ethernet-ii
Default 802dot3
Introduced19.10.R1

Platforms

All

outer-tag number
Synopsis Outer tag for the QinQ SAP for filter match
Contextli li-filter li-mac-filter named-item entry number match outer-tag number
Treeouter-tag

Description

This command configures the outer-tag to match on and must be used in conjunction with match criteria SAP in order for the entry match to activate.

The match criteria SAP must be an exact match with the QinQ configured on the Epipe or VPLS service (for example 1/1/1:1.*, where the outer tag (C-tag) must be "*"). This feature mandates the provisioning of an associated outer-tag (example, 1), to be able to match on the QinQ packet. This example would perform LI on 1/1/1:1.1 on a 1/1/1:1.* SAP.

Range1 to 4094
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

sap sap
Synopsis QinQ SAP for filter match
Context li li-filter li-mac-filter named-item entry number match sap sap
Treesap

Description

This command specifies the QinQ SAP to match from the Epipe or VPLS service, where the S-tag must be a value and the outer tag (C-tag) must be of type *. This filter match is used in conjunction with match criteria outer-tag, where the outer-tag must also be provisioned for the entry match on the QinQ packet to activate.

The match criteria SAP must be an exact match with the QinQ configured on the Epipe or VPLS service (for example 1/1/1:1.*, where the outer tag (C-tag) must be "*"). An associated outer-tag (example, 1) must be provisioned to match on the QinQ packet. This example would perform LI on 1/1/1:1.1 on a 1/1/1:1.* SAP.

String length1 to 45
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

src-mac
Synopsis Enable the src-mac context
Context li li-filter li-mac-filter named-item entry number match src-mac
Treesrc-mac
Introduced19.10.R1

Platforms

All

lock-filter keyword
Synopsis Lock state of LI filters
Context li li-filter lock-filter keyword
Treelock-filter
Optionslock, unlock
Default lock
Introduced19.10.R1

Platforms

All

reserved-block [block-name] named-item
Synopsis Enter the reserved-block list instance
Contextli li-filter reserved-block named-item
Treereserved-block
Max. instances8
Introduced19.10.R1

Platforms

All

[block-name] named-item
Synopsis Object uniquely identifying an LI reserved block
Contextli li-filter reserved-block named-item
Treereserved-block
String length1 to 32

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

entry-range
Synopsis Enable the entry-range context
Contextli li-filter reserved-block named-item entry-range
Treeentry-range
Introduced19.10.R1

Platforms

All

li-source [service-name] service-name

Synopsis Enter the li-source list instance
Contextli li-source service-name
Treeli-source
Introduced19.10.R1

Platforms

All

[service-name] service-name
Synopsis Administrative service name
Context li li-source service-name
Treeli-source
String length1 to 64

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

admin-state keyword
Synopsis Administrative state of mirror service
Contextli li-source service-name admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced19.10.R1

Platforms

All

li-ip-filter [li-filter-name] reference
Synopsis Enter the li-ip-filter list instance
Contextli li-source service-name li-ip-filter reference
Treeli-ip-filter
Introduced19.10.R1

Platforms

All

entry [li-entry-id] reference
Synopsis Enter the entry list instance
Context li li-source service-name li-ip-filter reference entry reference
Treeentry
Min. instances1
Introduced19.10.R1

Platforms

All

intercept-id number
Synopsis Intercept ID of the traffic flow
Context li li-source service-name li-ip-filter reference entry reference intercept-id number
Treeintercept-id

Description

This command configures the intercept ID that is inserted into the packet header for all mirrrored packets of the associated LI source entry. This intercept ID can be used (for example by a downstream LI gateway) to identify the particular LI session to which the packet belongs.

For LI source entries, when the configure mirror mirror-dest encap layer-3-encap header-type command is configured with ip-udp-shim routable encap, an intercept-id field (as part of the routable encap) is always present in the mirrored packets. If there is no intercept ID configured for an LI source entry, the default value is inserted.

When the mirror service is configured with ip-gre routable encap under the header-type command, no intercept ID is inserted and none should be specified against the LI source entries.

Range1 to 1073741823
Introduced19.10.R1

Platforms

All

session-id number
Synopsis Session ID of the traffic flow
Context li li-source service-name li-ip-filter reference entry reference session-id number
Treesession-id

Description

This command configures the session ID that is inserted into the packet header for all mirrored packets of the associated LI source entry. This session ID can be used (for example by a downstream LI gateway) to identify the particular LI session to which the packet belongs.

The session ID is only valid and used for mirror services that are configured with ip-udp-shim routable encap under the configure mirror mirror-dest encap layer-3-encap header-type command. For all types of LI source entries, when the mirror service is configured with ip-udp-shim routable encap, a session ID field (as part of the routable encap) is always present in the mirrored packets. If no session ID is configured for an LI source entry, the default value is inserted.

When a mirror service is configured with ip-gre routable encap under the header-type command, no session ID is inserted and none is specified against the LI source entries.

Range1 to 4294967295
Introduced19.10.R1

Platforms

All

li-ipv6-filter [li-filter-name] reference
Synopsis Enter the li-ipv6-filter list instance
Contextli li-source service-name li-ipv6-filter reference
Treeli-ipv6-filter
Introduced19.10.R1

Platforms

All

entry [li-entry-id] reference
Synopsis Enter the entry list instance
Context li li-source service-name li-ipv6-filter reference entry reference
Treeentry
Min. instances1
Introduced19.10.R1

Platforms

All

intercept-id number
Synopsis Intercept ID of the traffic flow
Context li li-source service-name li-ipv6-filter reference entry reference intercept-id number
Treeintercept-id

Description

This command configures the intercept ID that is inserted into the packet header for all mirrrored packets of the associated LI source entry. This intercept ID can be used (for example by a downstream LI gateway) to identify the particular LI session to which the packet belongs.

For LI source entries, when the configure mirror mirror-dest encap layer-3-encap header-type command is configured with ip-udp-shim routable encap, an intercept-id field (as part of the routable encap) is always present in the mirrored packets. If there is no intercept ID configured for an LI source entry, the default value is inserted.

When the mirror service is configured with ip-gre routable encap under the header-type command, no intercept ID is inserted and none should be specified against the LI source entries.

Range1 to 1073741823
Introduced19.10.R1

Platforms

All

session-id number
Synopsis Session ID of the traffic flow
Context li li-source service-name li-ipv6-filter reference entry reference session-id number
Treesession-id

Description

This command configures the session ID that is inserted into the packet header for all mirrored packets of the associated LI source entry. This session ID can be used (for example by a downstream LI gateway) to identify the particular LI session to which the packet belongs.

The session ID is only valid and used for mirror services that are configured with ip-udp-shim routable encap under the configure mirror mirror-dest encap layer-3-encap header-type command. For all types of LI source entries, when the mirror service is configured with ip-udp-shim routable encap, a session ID field (as part of the routable encap) is always present in the mirrored packets. If no session ID is configured for an LI source entry, the default value is inserted.

When a mirror service is configured with ip-gre routable encap under the header-type command, no session ID is inserted and none is specified against the LI source entries.

Range1 to 4294967295
Introduced19.10.R1

Platforms

All

li-mac-filter [li-filter-name] reference
Synopsis Enter the li-mac-filter list instance
Contextli li-source service-name li-mac-filter reference
Treeli-mac-filter
Introduced19.10.R1

Platforms

All

entry [li-entry-id] reference
Synopsis Enter the entry list instance
Context li li-source service-name li-mac-filter reference entry reference
Treeentry
Min. instances1
Introduced19.10.R1

Platforms

All

intercept-id number
Synopsis Intercept ID of the traffic flow
Context li li-source service-name li-mac-filter reference entry reference intercept-id number
Treeintercept-id

Description

This command configures the intercept ID that is inserted into the packet header for all mirrrored packets of the associated LI source entry. This intercept ID can be used (for example by a downstream LI gateway) to identify the particular LI session to which the packet belongs.

For LI source entries, when the configure mirror mirror-dest encap layer-3-encap header-type command is configured with ip-udp-shim routable encap, an intercept-id field (as part of the routable encap) is always present in the mirrored packets. If there is no intercept ID configured for an LI source entry, the default value is inserted.

When the mirror service is configured with ip-gre routable encap under the header-type command, no intercept ID is inserted and none should be specified against the LI source entries.

Range1 to 1073741823
Introduced19.10.R1

Platforms

All

session-id number
Synopsis Session ID of the traffic flow
Context li li-source service-name li-mac-filter reference entry reference session-id number
Treesession-id

Description

This command configures the session ID that is inserted into the packet header for all mirrored packets of the associated LI source entry. This session ID can be used (for example by a downstream LI gateway) to identify the particular LI session to which the packet belongs.

The session ID is only valid and used for mirror services that are configured with ip-udp-shim routable encap under the configure mirror mirror-dest encap layer-3-encap header-type command. For all types of LI source entries, when the mirror service is configured with ip-udp-shim routable encap, a session ID field (as part of the routable encap) is always present in the mirrored packets. If no session ID is configured for an LI source entry, the default value is inserted.

When a mirror service is configured with ip-gre routable encap under the header-type command, no session ID is inserted and none is specified against the LI source entries.

Range1 to 4294967295
Introduced19.10.R1

Platforms

All

nat
Synopsis Enter the nat context
Context li li-source service-name nat
Treenat
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

dslite [router-instance] service-name b4 ipv6-prefix
Synopsis Enter the dslite list instance
Contextli li-source service-name nat dslite service-name b4 ipv6-prefix
Treedslite
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[router-instance] service-name
Synopsis Name of the service
Context li li-source service-name nat dslite service-name b4 ipv6-prefix
Treedslite
String length1 to 64

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

b4 ipv6-prefix
Synopsis B4 prefix of the subscriber
Context li li-source service-name nat dslite service-name b4 ipv6-prefix
Treedslite

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

intercept-id number
Synopsis The intercept id of the traffic flow
Context li li-source service-name nat dslite service-name b4 ipv6-prefix intercept-id number
Treeintercept-id
Range1 to 4294967295
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

session-id number
Synopsis The session id of the traffic flow
Context li li-source service-name nat dslite service-name b4 ipv6-prefix session-id number
Treesession-id
Range1 to 4294967295
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ethernet-header
Synopsis Enter the ethernet-header context
Contextli li-source service-name nat ethernet-header
Treeethernet-header
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

type number
Synopsis Ethertype of the ethernet encapsulation
Contextli li-source service-name nat ethernet-header type number
Treetype
Range1536 to 65535
Default1792
Introduced 19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

l2-aware [subscriber-id] subscriber-id
Synopsis Enter the l2-aware list instance
Contextli li-source service-name nat l2-aware subscriber-id
Treel2-aware
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[subscriber-id] subscriber-id
Synopsis The string identifying the subscribe
Context li li-source service-name nat l2-aware subscriber-id
Treel2-aware
String length1 to 64

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

intercept-id number
Synopsis The intercept id of the traffic flow
Context li li-source service-name nat l2-aware subscriber-id intercept-id number
Treeintercept-id
Range1 to 4294967295
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

session-id number
Synopsis The session id of the traffic flow
Context li li-source service-name nat l2-aware subscriber-id session-id number
Treesession-id
Range1 to 4294967295
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

nat44 [router-instance] service-name ip ipv4-address
Synopsis Enter the nat44 list instance
Context li li-source service-name nat nat44 service-name ip ipv4-address
Treenat44
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[router-instance] service-name
Synopsis Name of the service
Context li li-source service-name nat nat44 service-name ip ipv4-address
Treenat44
String length1 to 64

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip ipv4-address
Synopsis IP address of the subscriber
Context li li-source service-name nat nat44 service-name ip ipv4-address
Treenat44

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

intercept-id number
Synopsis The intercept id of the traffic flow
Context li li-source service-name nat nat44 service-name ip ipv4-address intercept-id number
Treeintercept-id
Range1 to 4294967295
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

session-id number
Synopsis The session id of the traffic flow
Context li li-source service-name nat nat44 service-name ip ipv4-address session-id number
Treesession-id
Range1 to 4294967295
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

nat64 [router-instance] service-name ip ipv6-prefix
Synopsis Enter the nat64 list instance
Context li li-source service-name nat nat64 service-name ip ipv6-prefix
Treenat64
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[router-instance] service-name
Synopsis Name of the service
Context li li-source service-name nat nat64 service-name ip ipv6-prefix
Treenat64
String length1 to 64

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip ipv6-prefix
Synopsis IP prefix of the subscriber
Context li li-source service-name nat nat64 service-name ip ipv6-prefix
Treenat64

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

intercept-id number
Synopsis The intercept id of the traffic flow
Context li li-source service-name nat nat64 service-name ip ipv6-prefix intercept-id number
Treeintercept-id
Range1 to 4294967295
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

session-id number
Synopsis The session id of the traffic flow
Context li li-source service-name nat nat64 service-name ip ipv6-prefix session-id number
Treesession-id
Range1 to 4294967295
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

port [port-id] mirror-source-port-lag-key
Synopsis Enter the port list instance
Context li li-source service-name port mirror-source-port-lag-key
Treeport
Introduced20.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

[port-id] mirror-source-port-lag-key
Synopsis Port ID
Contextli li-source service-name port mirror-source-port-lag-key
Treeport

Notes

This element is part of a list key.

Introduced20.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

egress boolean
Synopsis Perform lawful intercept on egress traffic
Contextli li-source service-name port mirror-source-port-lag-key egress boolean
Treeegress

Description

When configured to true, the router allows lawful intercept on egress traffic. This command configures packets that egress the SAP to be mirrored. Egress packets are mirrored to the mirror destination after egress packet modification.

Defaultfalse
Introduced20.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

ingress boolean
Synopsis Perform lawful intercept on ingress traffic
Contextli li-source service-name port mirror-source-port-lag-key ingress boolean
Treeingress

Description

When configured to true, the router allows lawful intercept on ingress traffic. This command configures packets that ingress the SAP to be mirrored. Ingress packets are mirrored to the mirror destination before ingress packet modification.

Defaultfalse
Introduced20.5.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, 7950 XRS

sap [sap-id] sap
Synopsis Enter the sap list instance
Context li li-source service-name sap sap
Treesap

Description

Commands in this context create a service access point (SAP) within an LI configuration. The specified SAP must define a FastE, GigE, or XGigE, or XGigE access port with a dot1q, null, or q-in-q encapsulation type.

Introduced19.10.R1

Platforms

All

[sap-id] sap
Synopsis SAP ID
Contextli li-source service-name sap sap
Treesap

Description

This command specifies the physical port identifier portion of the SAP definition.

String length1 to 45

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

egress boolean
Synopsis Perform lawful intercept on egress traffic
Contextli li-source service-name sap sap egress boolean
Treeegress

Description

When configured to true, the router allows lawful intercept on egress traffic. This command configures packets that egress the SAP to be mirrored. Egress packets are mirrored to the mirror destination after egress packet modification.

Defaultfalse
Introduced19.10.R1

Platforms

All

ingress boolean
Synopsis Perform lawful intercept on ingress traffic
Contextli li-source service-name sap sap ingress boolean
Treeingress

Description

When configured to true, the router allows lawful intercept on ingress traffic. This command configures packets that ingress the SAP to be mirrored. Ingress packets are mirrored to the mirror destination before ingress packet modification.

Defaultfalse
Introduced19.10.R1

Platforms

All

intercept-id number
Synopsis Intercept ID of the traffic flow
Context li li-source service-name sap sap intercept-id number
Treeintercept-id

Description

This command configures the intercept ID that is inserted into the packet header for all mirrrored packets of the associated LI source entry. This intercept ID can be used (for example by a downstream LI gateway) to identify the particular LI session to which the packet belongs.

For LI source entries, when the configure mirror mirror-dest encap layer-3-encap header-type command is configured with ip-udp-shim routable encap, an intercept-id field (as part of the routable encap) is always present in the mirrored packets. If there is no intercept ID configured for an LI source entry, the default value is inserted.

When the mirror service is configured with ip-gre routable encap under the header-type command, no intercept ID is inserted and none should be specified against the LI source entries.

Range1 to 1073741823
Introduced19.10.R1

Platforms

All

session-id number
Synopsis Session ID of the traffic flow
Context li li-source service-name sap sap session-id number
Treesession-id

Description

This command configures the session ID that is inserted into the packet header for all mirrored packets of the associated LI source entry. This session ID can be used (for example by a downstream LI gateway) to identify the particular LI session to which the packet belongs.

The session ID is only valid and used for mirror services that are configured with ip-udp-shim routable encap under the configure mirror mirror-dest encap layer-3-encap header-type command. For all types of LI source entries, when the mirror service is configured with ip-udp-shim routable encap, a session ID field (as part of the routable encap) is always present in the mirrored packets. If no session ID is configured for an LI source entry, the default value is inserted.

When a mirror service is configured with ip-gre routable encap under the header-type command, no session ID is inserted and none is specified against the LI source entries.

Range1 to 4294967295
Introduced19.10.R1

Platforms

All

subscriber [subscriber-id] subscriber-id
Synopsis Enter the subscriber list instance
Contextli li-source service-name subscriber subscriber-id
Treesubscriber

Description

Commands in this context add hosts of a subscriber to a mirroring service.

Introduced19.10.R1

Platforms

All

[subscriber-id] subscriber-id
Synopsis Subscriber ID
Contextli li-source service-name subscriber subscriber-id
Treesubscriber
String length1 to 64

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

egress boolean
Synopsis Perform lawful intercept on egress traffic
Contextli li-source service-name subscriber subscriber-id egress boolean
Treeegress

Description

When configured to true, the router allows lawful intercept on egress traffic. This command configures packets that egress the SAP to be mirrored. Egress packets are mirrored to the mirror destination after egress packet modification.

Defaultfalse
Introduced19.10.R1

Platforms

All

fc keyword
Synopsis Forwarding classes to be mirrored
Context li li-source service-name subscriber subscriber-id fc keyword
Treefc

Description

This command specifies the name of the forwarding class with which to associate LI traffic. The forwarding class name must already be defined within the system.

If the FC name is not already defined, an error is returned and this command has no effect. If the FC name is defined, the forwarding class associated with the FC name overrides the default forwarding class.

Optionsbe, l2, af, l1, h2, ef, h1, nc
Max. instances 8
Introduced19.10.R1

Platforms

All

host-type keyword
Synopsis Subscriber host type to be monitored
Context li li-source service-name subscriber subscriber-id host-type keyword
Treehost-type

Description

This command specifies the host type for LI.

Optionsipoe, ppp
Introduced 19.10.R1

Platforms

All

ingress boolean
Synopsis Perform lawful intercept on ingress traffic
Contextli li-source service-name subscriber subscriber-id ingress boolean
Treeingress

Description

When configured to true, the router allows lawful intercept on ingress traffic. This command configures packets that ingress the SAP to be mirrored. Ingress packets are mirrored to the mirror destination before ingress packet modification.

Defaultfalse
Introduced19.10.R1

Platforms

All

intercept-id number
Synopsis Intercept ID of the traffic flow
Context li li-source service-name subscriber subscriber-id intercept-id number
Treeintercept-id

Description

This command configures the intercept ID that is inserted into the packet header for all mirrrored packets of the associated LI source entry. This intercept ID can be used (for example by a downstream LI gateway) to identify the particular LI session to which the packet belongs.

For LI source entries, when the configure mirror mirror-dest encap layer-3-encap header-type command is configured with ip-udp-shim routable encap, an intercept-id field (as part of the routable encap) is always present in the mirrored packets. If there is no intercept ID configured for an LI source entry, the default value is inserted.

When the mirror service is configured with ip-gre routable encap under the header-type command, no intercept ID is inserted and none should be specified against the LI source entries.

Range1 to 1073741823
Introduced19.10.R1

Platforms

All

ip-address ipv4-address
Synopsis IP address of the subscriber
Context li li-source service-name subscriber subscriber-id ip-address ipv4-address
Treeip-address

Description

This command specifies the service IP address (system IP address) of the remote device sending LI traffic. If 0.0.0.0 is specified, any remote router is allowed to send to this service.

Notes

The following elements are part of a choice: (ip-address, mac-address, and sap-id) or sla-profile.

Introduced19.10.R1

Platforms

All

ip-family keyword
Synopsis IP family for LI
Context li li-source service-name subscriber subscriber-id ip-family keyword
Treeip-family

Description

This command specifies the IP family for LI.

Optionsipv4, ipv6
Introduced 19.10.R1

Platforms

All

mac-address mac-address
Synopsis The source MAC address
Context li li-source service-name subscriber subscriber-id mac-address mac-address
Treemac-address

Description

This command specifies a MAC address when defining a static host.

Multiple static hosts may be configured with the same MAC address because each definition is distinguished by a unique IP address.

Notes

The following elements are part of a choice: (ip-address, mac-address, and sap-id) or sla-profile.

Introduced19.10.R1

Platforms

All

sap-id sap
Synopsis SAP ID
Contextli li-source service-name subscriber subscriber-id sap-id sap
Treesap-id
String length1 to 45

Notes

The following elements are part of a choice: (ip-address, mac-address, and sap-id) or sla-profile.

Introduced19.10.R1

Platforms

All

session-id number
Synopsis Session ID of the traffic flow
Context li li-source service-name subscriber subscriber-id session-id number
Treesession-id

Description

This command configures the session ID that is inserted into the packet header for all mirrored packets of the associated LI source entry. This session ID can be used (for example by a downstream LI gateway) to identify the particular LI session to which the packet belongs.

The session ID is only valid and used for mirror services that are configured with ip-udp-shim routable encap under the configure mirror mirror-dest encap layer-3-encap header-type command. For all types of LI source entries, when the mirror service is configured with ip-udp-shim routable encap, a session ID field (as part of the routable encap) is always present in the mirrored packets. If no session ID is configured for an LI source entry, the default value is inserted.

When a mirror service is configured with ip-gre routable encap under the header-type command, no session ID is inserted and none is specified against the LI source entries.

Range1 to 4294967295
Introduced19.10.R1

Platforms

All

sla-profile external-named-item
Synopsis SLA profile
Contextli li-source service-name subscriber subscriber-id sla-profile external-named-item
Treesla-profile

Description

This command specifies an SLA profile name.

Each host of a subscriber can use a different SLA profile. This option allows interception of only the hosts using the specified SLA profile. In some deployments, SLA profiles are assigned per type of traffic. There can be, for example, a specific SLA profile for voice traffic (which could be used for all SIP hosts).

String length1 to 32

Notes

The following elements are part of a choice: (ip-address, mac-address, and sap-id) or sla-profile.

Introduced19.10.R1

Platforms

All

wlan-gw-dsm-ue [mac] mac-address
Synopsis Enter the wlan-gw-dsm-ue list instance
Contextli li-source service-name wlan-gw-dsm-ue mac-address
Treewlan-gw-dsm-ue
Introduced19.10.R1

Platforms

All

[mac] mac-address
Synopsis MAC address of the DSM UE
Context li li-source service-name wlan-gw-dsm-ue mac-address
Treewlan-gw-dsm-ue

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

All

log

Synopsis Enter the log context
Context li log
Treelog
Introduced19.10.R1

Platforms

All

log-id [name] li-log-name
Synopsis Enter the log-id list instance
Contextli log log-id li-log-name
Treelog-id
Max. instances30
Introduced19.10.R1

Platforms

All

[name] li-log-name
Synopsis Log ID
Contextli log log-id li-log-name
Treelog-id
String length1 to 64

Notes

This element is part of a list key.

Introduced21.2.R1

Platforms

All

admin-state keyword
Synopsis The administrative state of the log
Context li log log-id li-log-name admin-state keyword
Treeadmin-state
Optionsenable, disable
Default enable
Introduced19.10.R1

Platforms

All

description description
Synopsis Text description
Context li log log-id li-log-name description description
Treedescription
String length1 to 80
Introduced19.10.R1

Platforms

All

destination
Synopsis Enter the destination context
Context li log log-id li-log-name destination
Treedestination

Description

Commands in this context specify where log event data is to be sent.

Introduced19.10.R1

Platforms

All

memory
Synopsis Enable the memory context
Context li log log-id li-log-name destination memory
Treememory

Description

Commands in this context configure log events directed to a memory file. A memory file is a circular buffer. When the file is full, each new entry replaces the oldest entry in the log.

Notes

The following elements are part of a choice: memory, netconf, or snmp.

Introduced19.10.R1

Platforms

All

max-entries number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNumber of events stored in this memory log
Contextli log log-id li-log-name destination memory max-entries number
Treemax-entries
Range50 to 1024
Default100
Introduced 19.10.R1

Platforms

All

netconf
Synopsis Enable the netconf context
Context li log log-id li-log-name destination netconf
Treenetconf

Description

Commands in this context configure log events directed to a NETCONF session as notifications. A NETCONF client can subscribe to a NETCONF log using the configured netconf-stream for the log in a subscription request. One or more NETCONF sessions can subscribe to a NETCONF log or stream.

Notes

The following elements are part of a choice: memory, netconf, or snmp.

Introduced20.2.R1

Platforms

All

max-entries number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisMaximum number of events stored in the NETCONF log
Contextli log log-id li-log-name destination netconf max-entries number
Treemax-entries

Description

This command configures the maximum number of events stored in the NETCONF log.

If this setting needs to be modified, the log ID must be removed and re-created.

Range50 to 1024
Default100
Introduced 20.2.R1

Platforms

All

snmp
Synopsis Enable the snmp context
Context li log log-id li-log-name destination snmp
Treesnmp

Description

Commands in this context configure log events directed to the snmp-trap-group associated with the log ID. A local circular memory log is maintained for SNMP logs.

Notes

The following elements are part of a choice: memory, netconf, or snmp.

Introduced19.10.R1

Platforms

All

max-entries number
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisNumber of events stored in this snmp log
Contextli log log-id li-log-name destination snmp max-entries number
Treemax-entries
Range50 to 1024
Default100
Introduced 19.10.R1

Platforms

All

send-using-vprn service-name
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisVPRN to use to send SNMP notifications
Contextli log log-id li-log-name destination snmp send-using-vprn service-name
Treesend-using-vprn

Description

This command configures lawful intercept (LI) SNMP notifications to transmit in a VPRN. This configuration is useful when doing management of LI via a VPRN.

The specified VPRN service must exist. After an LI log is configured using this command, the VPRN service cannot be deleted without removing the LI log ID.

When this command is configured, an LI log ID uses the snmp-trap-group configured for the VPRN.

When unconfigured, the outgoing routing instance of LI SNMP notifications is determined by the configure log route-preference command, and the LI log ID uses the snmp-trap-group configured in the main system log configuration.

String length1 to 64
Introduced23.10.R1

Platforms

All

filter log-filter-name
Synopsis Event filter ID to associate with log ID configuration
Contextli log log-id li-log-name filter log-filter-name
Treefilter
String length1 to 64
Introduced19.10.R1

Platforms

All

netconf-stream named-item
Synopsis Destination NETCONF stream name
Context li log log-id li-log-name netconf-stream named-item
Treenetconf-stream
String length1 to 32
Introduced20.2.R1

Platforms

All

source
Synopsis Enter the source context
Context li log log-id li-log-name source
Treesource
Introduced19.10.R1

Platforms

All

li boolean
Synopsis Event stream for events configured for LI activities
Contextli log log-id li-log-name source li boolean
Treeli
Defaultfalse
Introduced19.10.R1

Platforms

All

time-format keyword
Synopsis Time zone to display date and time
Context li log log-id li-log-name time-format keyword
Treetime-format
Optionsutc, local
Default utc
Introduced19.10.R1

Platforms

All

mirror-dest-reservation

Synopsis Enter the mirror-dest-reservation context
Contextli mirror-dest-reservation
Treemirror-dest-reservation

Description

Commands in this context configure the attributes to reserve mirror destination resources.

Introduced19.10.R1

Platforms

All

end number
Synopsis Upper bound of the mirror destination ID
Contextli mirror-dest-reservation end number
Treeend
Range1 to 2147483647
Introduced19.10.R1

Platforms

All

mirror-dest-template [name] named-item

Synopsis Enter the mirror-dest-template list instance
Contextli mirror-dest-template named-item
Treemirror-dest-template
Max. instances8
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[name] named-item
Synopsis Mirror destination template name
Context li mirror-dest-template named-item
Treemirror-dest-template
String length1 to 32

Notes

This element is part of a list key.

Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

layer-3-encap
Synopsis Enter the layer-3-encap context
Contextli mirror-dest-template named-item layer-3-encap
Treelayer-3-encap
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

encap-type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisThe header type of the layer 3 encapsulation.
Contextli mirror-dest-template named-item layer-3-encap encap-type keyword
Treeencap-type
Optionsip-udp-shim, ip-gre
Default ip-udp-shim
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

udp
Synopsis Enter the udp context
Context li mirror-dest-template named-item layer-3-encap udp
Treeudp
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

type keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisEncapsulation type supported by the mirror service
Contextli mirror-dest-template named-item type keyword
Treetype
Optionsether, ip-only
Default ether
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

nat

Synopsis Enter the nat context
Context li nat
Treenat
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

use-outside-ip-address boolean
Synopsis Report outside IP address for L2-Aware NAT subscribers
Contextli nat use-outside-ip-address boolean
Treeuse-outside-ip-address
Defaultfalse
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

sci

Synopsis Enter the sci context
Context li sci
Treesci
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

pfcp-li-shared-key encrypted-leaf
Synopsis Key used to encrypt and decrypt exchanged LI PFCP IEs
Contextli sci pfcp-li-shared-key encrypted-leaf
Treepfcp-li-shared-key

Description

This command configures the shared secret key that the SR OS uses in its role as a user plane (UP) to the MAG-c. The UP uses the shared secret key to encrypt and decrypt the LI PFCP IEs it exchanges with the MAG-c. The SR OS UP and the MAG-c must use matching secret keys. The system only accepts a secret key configured as a printable string.

String length1 to 199
Introduced23.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

x-interfaces

Synopsis Enter the x-interfaces context
Contextli x-interfaces
Treex-interfaces
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

admin-state keyword
Synopsis Administrative state of the x-interfaces
Contextli x-interfaces admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

correlation-id
Synopsis Enter the correlation-id context
Contextli x-interfaces correlation-id
Treecorrelation-id
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

ipoe keyword
Synopsis RADIUS accounting ID type for subscriber correlation
Contextli x-interfaces correlation-id ipoe keyword
Treeipoe
Optionsradius-host-acct-id, radius-queue-acct-id, radius-session-acct-id
Defaultradius-host-acct-id
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

pppoe keyword
Synopsis RADIUS accounting ID type for subscriber correlation
Contextli x-interfaces correlation-id pppoe keyword
Treepppoe
Optionsradius-host-acct-id, radius-queue-acct-id, radius-session-acct-id
Defaultradius-host-acct-id
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

ine-identifier named-item
Synopsis Intercepting Network Element (INE) ID
Contextli x-interfaces ine-identifier named-item
Treeine-identifier
String length1 to 32
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

lic [name] named-item
Synopsis Enter the lic list instance
Context li x-interfaces lic named-item
Treelic
Max. instances18
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

[name] named-item
Synopsis LIC name
Contextli x-interfaces lic named-item
Treelic
String length1 to 32

Notes

This element is part of a list key.

Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

authentication
Synopsis Enter the authentication context
Contextli x-interfaces lic named-item authentication
Treeauthentication
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

password li-static-encrypted-leaf-hex
Synopsis Password for the X1 and X2 interfaces
Contextli x-interfaces lic named-item authentication password li-static-encrypted-leaf-hex
Treepassword
String length1 to 50
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

private-ki li-static-encrypted-leaf
Synopsis Private Ki string for the X1 and X2 interfaces
Contextli x-interfaces lic named-item authentication private-ki li-static-encrypted-leaf
Treeprivate-ki
String length1 to 50
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

description description
Synopsis Text description
Context li x-interfaces lic named-item description description
Treedescription
String length1 to 80
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

identifier named-item
Synopsis LIC ID
Contextli x-interfaces lic named-item identifier named-item
Treeidentifier
String length1 to 32
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

ipv4
Synopsis Enter the ipv4 context
Context li x-interfaces lic named-item ipv4
Treeipv4
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the LIC
Context li x-interfaces lic named-item ipv4 ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeip-address
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

port number
Synopsis TCP port associated with the LIC
Context li x-interfaces lic named-item port number
Treeport
Range0 to 65535
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

router-instance named-item-64-or-empty
Synopsis Virtual router instance used by the X-interfaces
Contextli x-interfaces lic named-item router-instance named-item-64-or-empty
Treerouter-instance
String length0 to 64
Default
Introduced 21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

user-db named-item
Synopsis Location of the data-trigger host for the LIC
Contextli x-interfaces user-db named-item
Treeuser-db
String length1 to 32
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

x1
Synopsis Enter the x1 context
Context li x-interfaces x1
Treex1
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

ipv4
Synopsis Enter the ipv4 context
Context li x-interfaces x1 ipv4
Treeipv4
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

local-address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis X1 interface IP address
Context li x-interfaces x1 ipv4 local-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treelocal-address
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

x2
Synopsis Enter the x2 context
Context li x-interfaces x2
Treex2
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

ipv4
Synopsis Enter the ipv4 context
Context li x-interfaces x2 ipv4
Treeipv4
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

local-address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis X2 interface IP address
Context li x-interfaces x2 ipv4 local-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treelocal-address
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

timeouts
Synopsis Enter the timeouts context
Context li x-interfaces x2 timeouts
Treetimeouts
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

request number
Synopsis Tx2-normal timeout
Context li x-interfaces x2 timeouts request number
Treerequest
Range5 to 30
Unitsseconds
Default 5
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

x3
Synopsis Enter the x3 context
Context li x-interfaces x3
Treex3
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

alarms
Synopsis Enter the alarms context
Context li x-interfaces x3 alarms
Treealarms
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

cpu-alarm
Synopsis Enter the cpu-alarm context
Context li x-interfaces x3 alarms cpu-alarm
Treecpu-alarm
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

memory-alarm
Synopsis Enter the memory-alarm context
Contextli x-interfaces x3 alarms memory-alarm
Treememory-alarm
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

throughput-alarm
Synopsis Enter the throughput-alarm context
Contextli x-interfaces x3 alarms throughput-alarm
Treethroughput-alarm
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

ipv4
Synopsis Enter the ipv4 context
Context li x-interfaces x3 ipv4
Treeipv4
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

local-address-range
Synopsis Enter the local-address-range context
Contextli x-interfaces x3 ipv4 local-address-range
Treelocal-address-range
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

li-group number
Synopsis ISA group of the X3 interface
Context li x-interfaces x3 li-group number
Treeli-group
Range1 to 4
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

lic-peers [name] reference
Synopsis Add a list entry for lic-peers
Contextli x-interfaces x3 lic-peers reference
Treelic-peers
Max. instances16
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

session-limit number
Synopsis Maximum number of X3 sessions initiated to the LIC
Contextli x-interfaces x3 session-limit number
Treesession-limit
Range1 to 32
Default32
Introduced 21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

timeouts
Synopsis Enter the timeouts context
Context li x-interfaces x3 timeouts
Treetimeouts
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e

request number
Synopsis Tx3-normal timeout
Context li x-interfaces x3 timeouts request number
Treerequest
Range5 to 30
Unitsseconds
Default 5
Introduced21.5.R1

Platforms

7750 SR-1, 7750 SR-7/12/12e