system

system
+  aaa
   +  accounting
      +  accounting-method reference
      +  event event-type identityref 
         +  record identityref
   +  authentication
      +  admin-user
         -  credentialz
            -  authorized-keys
               -  created-on string
               -  version string
            -  authorized-principals
               -  created-on string
               -  version string
            -  password
               -  created-on string
               -  version string
         -  failed-login-attempts number
         -  last-failed-login string
         -  last-successful-login string
         -  lockout
            -  active boolean
            -  end string
            -  start string
         +  password string
         -  password-change-required boolean
         +  role reference
         +  spiffe-ids string
         +  ssh-key string
         +  ssh-principals string
         +  superuser boolean
         -  username string
      +  authentication-method reference
      +  dynamic-spiffe
         +  allow boolean
         +  role reference
      +  exit-on-reject boolean
      +  idle-timeout number
      +  linuxadmin-user
         -  credentialz
            -  authorized-keys
               -  created-on string
               -  version string
            -  authorized-principals
               -  created-on string
               -  version string
            -  password
               -  created-on string
               -  version string
         +  password string
         +  ssh-key string
         +  ssh-principals string
         -  username string
      +  password
         +  aging number
         +  change-on-first-login boolean
         +  complexity-rules
            +  allow-username boolean
            +  maximum-length number
            +  minimum-length number
            +  minimum-lowercase number
            +  minimum-numeric number
            +  minimum-special-character number
            +  minimum-uppercase number
         +  hash-method keyword
         +  history number
         +  lockout-policy
            +  attempts number
            +  lockout number
            +  time number
         +  require-ntp-sync boolean
      -  session id number 
         -  authentication-method string
         -  login-time string
         -  priv-lvl number
         -  remote-host string
         -  role string
         -  service-name string
         -  spiffe-id string
         -  tty-name string
         -  username string
      +  user username string 
         -  credentialz
            -  authorized-keys
               -  created-on string
               -  version string
            -  authorized-principals
               -  created-on string
               -  version string
            -  password
               -  created-on string
               -  version string
         -  failed-login-attempts number
         -  last-failed-login string
         -  last-successful-login string
         -  lockout
            -  active boolean
            -  end string
            -  start string
         +  password string
         -  password-change-required boolean
         +  role reference
         +  spiffe-ids string
         +  ssh-key string
         +  ssh-principals string
         +  superuser boolean
   +  authorization
      -  authz-policy
         -  counters
            -  rpc name string 
               -  access-accepts number
               -  access-rejects number
               -  last-access-accept string
               -  last-access-reject string
         -  created-on string
         -  policy string
         -  version string
      +  role rolename string 
         +  cli
            +  allow-command-list string
            +  deny-command-list string
            +  load-global-plugins boolean
            +  load-user-plugins boolean
         +  services keyword
         +  superuser boolean
         +  tacacs
            +  priv-lvl number
   +  server-group name string 
      +  priv-lvl-authorization boolean
      +  server address (ipv4-address | ipv6-address) 
         +  name string
         +  network-instance reference
         -  oper-state keyword
         +  radius
            +  acct-port number
            +  auth-port number
            +  retransmit-attempts number
            +  secret-key string
         -  statistics
            -  accounting-connection-failures number
            -  accounting-rejects number
            -  accounting-success number
            -  authorization-connection-failures number
            -  authorization-rejects number
            -  authorization-success number
            -  login-connection-failures number
            -  login-rejects number
            -  login-success number
         +  tacacs
            +  port number
            +  secret-key string
      +  timeout number
      +  type identityref
-  app-management
   -  application name string 
      -  author string
      -  cgroup string
      -  failure-action string
      -  failure-threshold number
      -  failure-window number
      -  last-change string
      -  last-start-type keyword
      -  launch-command string
      -  oom-score-adj number
      -  path string
      -  pid number
      -  restricted-operations keyword
      -  search-command string
      -  state keyword
      -  statistics
         -  restart-count number
      -  supported-restart-types keyword
      -  version string
      -  yang
         -  modules string
         -  source-directories string
+  authentication
   +  keychain name string 
      -  active-key-for-send (keyword | reference)
      +  admin-state keyword
      +  description string
      -  expired boolean
      +  key index number 
         +  algorithm keyword
         +  authentication-key string
      +  type keyword
      -  usable boolean
+  banner
   +  login-banner string
   +  motd-banner string
+  boot
   +  autoboot
      +  admin-state keyword
      +  attempts number
      +  client-id keyword
      +  interface reference
      +  mode string
      -  oper-state string
      +  timeout number
   -  golden-image string
   -  image string
+  bridge-table
   +  mac-learning
      -  mac-relearn-only boolean
   +  mac-limit
      -  maximum-entries number
      -  warning-threshold-pct number
   -  proxy-arp
      -  statistics
         -  active-entries number
         -  in-active-entries number
         -  neighbor-origin origin keyword 
            -  active-entries number
            -  in-active-entries number
            -  pending-entries number
            -  total-entries number
         -  pending-entries number
         -  total-entries number
   -  proxy-nd
      -  statistics
         -  active-entries number
         -  in-active-entries number
         -  neighbor-origin origin keyword 
            -  active-entries number
            -  in-active-entries number
            -  pending-entries number
            -  total-entries number
         -  pending-entries number
         -  total-entries number
   -  statistics
      -  active-entries number
      -  failed-entries number
      -  mac-type type keyword 
         -  active-entries number
         -  failed-entries number
         -  total-entries number
      -  total-entries number
+  clock
   +  timezone keyword
+  configuration
   +  auto-checkpoint boolean
   -  candidate name string 
      -  started string
      -  type keyword
      -  username string
   -  checkpoint id number 
      -  comment string
      -  created string
      -  name string
      -  size number
      -  tag string
      -  username string
      -  version string
   -  commit id number 
      -  comment string
      -  ended string
      -  name string
      -  started string
      -  status keyword
      -  type keyword
      -  username string
   +  idle-timeout number
   -  last-change string
   +  max-candidates number
   +  max-checkpoints number
   +  role name reference 
      +  rule path-reference string 
         +  action keyword
   -  session id number 
      -  exclusive boolean
      -  name string
      -  started string
      -  type keyword
      -  username string
+  control-plane-traffic
   +  input
      +  acl
         +  acl-filter name reference type reference 
   +  output
      +  qos
         +  management-protocols-dscp (number | keyword)
+  dhcp-server
   +  admin-state keyword
   +  network-instance name reference 
      +  dhcpv4
         +  admin-state keyword
         -  oper-state keyword
         +  options
            +  bootfile-name string
            +  dns-server string
            +  domain-name string
            +  hostname string
            +  ntp-server string
            +  router string
            +  server-id string
            +  tftp-server-address string
            +  tftp-server-name string
         +  static-allocation
            +  host mac string 
               +  ip-address string
               +  options
                  +  bootfile-name string
                  +  dns-server string
                  +  domain-name string
                  +  hostname string
                  +  ntp-server string
                  +  router string
                  +  server-id string
                  +  tftp-server-address string
                  +  tftp-server-name string
         -  statistics
            -  client-packets-discarded number
            -  client-packets-received number
            -  server-packets-sent number
         +  trace-options
            +  trace keyword
      +  dhcpv6
         +  admin-state keyword
         -  oper-state keyword
         +  options
            +  dns-server string
         +  static-allocation
            +  host mac string 
               +  ip-address string
               +  options
                  +  dns-server string
         -  statistics
            -  client-packets-discarded number
            -  client-packets-received number
            -  server-packets-sent number
         +  trace-options
            +  trace keyword
+  dns
   +  host-entry name string 
      +  ipv4-address string
      +  ipv6-address string
   +  network-instance reference
   -  oper-state keyword
   +  search-list string
   +  server-list (ipv4-address | ipv6-address)
   +  source-address (ipv4-address | ipv6-address)
+  event-handler
   +  instance name string 
      +  admin-state keyword
      -  last-errored-execution
         -  end-time string
         -  input string
         -  oper-down-reason keyword
         -  oper-down-reason-detail string
         -  output string
         -  start-time string
         -  stdout-stderr string
         -  upython-duration number
      -  last-execution
         -  end-time string
         -  input string
         -  oper-down-reason keyword
         -  oper-down-reason-detail string
         -  output string
         -  start-time string
         -  stdout-stderr string
         -  upython-duration number
      -  oper-state keyword
      +  options
         +  object name string 
            +  value string
            +  values string
      +  paths string
      -  statistics
         -  execution-count number
         -  execution-errors number
         -  execution-successes number
         -  execution-timeouts number
         -  upython-duration number
      +  upython-script string
   +  run-as-user reference
-  features string
+  ftp-server
   +  network-instance name reference 
      +  admin-state keyword
      -  oper-state keyword
      +  session-limit number
      +  source-address (ipv4-address | ipv6-address)
      +  timeout number
+  grpc-server name string 
   +  admin-state keyword
   -  certz
      -  certificate
         -  created-on string
         -  version string
      -  crl
         -  created-on string
         -  version string
      -  ssl-profile-id string
      -  trust-anchor
         -  created-on string
         -  version string
   -  client id number 
      -  election-id string
      -  gnmi
         -  paths id number 
            -  mode keyword
            -  path string
            -  sample-interval number
      -  gribi
         -  persistence-mode keyword
      -  p4rt
         -  forwarding-complex
            -  device number
            -  id string
            -  slot number
         -  primary boolean
      -  remote-host (ipv4-address | ipv6-address)
      -  remote-port number
      -  rpc string
      -  start-time string
      -  type keyword
      -  user string
      -  user-agent string
   +  default-tls-profile boolean
   +  gnmi
      +  commit-confirmed-timeout number
      +  commit-save boolean
      +  include-defaults-in-config-only-responses boolean
   +  metadata-authentication boolean
   +  network-instance reference
   -  oper-state keyword
   +  port number
   +  rate-limit number
   +  services identityref
   +  session-limit number
   +  source-address (ipv4-address | ipv6-address)
   -  statistics
      -  access-accepts number
      -  access-rejects number
      -  last-access-accept string
      -  last-access-reject string
      -  rpc name string 
         -  access-accepts number
         -  access-rejects number
         -  last-access-accept string
         -  last-access-reject string
   +  timeout number
   +  tls-profile reference
   +  trace-options keyword
   +  unix-socket
      +  admin-state keyword
      -  socket-path string
   +  yang-models keyword
+  information
   +  contact string
   -  current-datetime string
   -  description string
   -  last-booted string
   +  location string
   -  version string
+  json-rpc-server
   +  admin-state keyword
   +  commit-confirmed-timeout number
   +  network-instance name reference 
      +  http
         +  admin-state keyword
         -  oper-state keyword
         +  port number
         +  session-limit number
         +  source-address (ipv4-address | ipv6-address)
         +  use-authentication boolean
      +  https
         +  admin-state keyword
         -  oper-state keyword
         +  port number
         +  session-limit number
         +  source-address (ipv4-address | ipv6-address)
         +  tls-profile reference
         +  use-authentication boolean
   +  trace-options keyword
   +  unix-socket
      +  admin-state keyword
      -  oper-state keyword
      -  socket-path string
      +  tls-profile reference
      +  use-authentication boolean
-  l2cp-transparency
   -  l2cp-statistics
      -  dot1x
         -  in-trap-to-cpu-packets number
         -  in-tunneled-packets number
         -  last-clear string
      -  lacp
         -  in-trap-to-cpu-packets number
         -  in-tunneled-packets number
         -  last-clear string
      -  last-clear string
      -  lldp
         -  in-trap-to-cpu-packets number
         -  in-tunneled-packets number
         -  last-clear string
      -  ptp
         -  in-trap-to-cpu-packets number
         -  in-tunneled-packets number
         -  last-clear string
      -  total-in-discarded-packets number
      -  total-in-packets number
      -  total-in-trap-to-cpu-packets number
      -  total-in-tunneled-packets number
      -  xstp
         -  in-trap-to-cpu-packets number
         -  in-tunneled-packets number
         -  last-clear string
+  lacp
   +  system-id string
   +  system-priority number
+  license id string 
   +  admin-state keyword
   +  data string
   +  description string
   -  expiration-date string
   -  expired boolean
   -  in-use boolean
   -  issued-date string
   +  preferred boolean
   -  valid boolean
+  lldp
   +  admin-state keyword
   -  chassis-id string
   -  chassis-id-type keyword
   +  hello-timer number
   +  hold-multiplier number
   +  interface name reference 
      +  admin-state keyword
      -  neighbor id string 
         -  capability name identityref 
            -  enabled boolean
         -  chassis-id string
         -  chassis-id-type keyword
         -  custom-tlv type number oui string oui-subtype string 
            -  value binary
         -  first-message string
         -  last-update string
         -  management-address address string 
            -  type keyword
         -  port-description string
         -  port-id (string | binary)
         -  port-id-type keyword
         -  system-description string
         -  system-name string
      -  oper-state keyword
      -  statistics
         -  frame-discard number
         -  frame-error-in number
         -  frame-error-out number
         -  frame-in number
         -  frame-out number
         -  last-clear string
         -  tlv-discard number
         -  tlv-unknown number
   +  management-address subinterface string 
      +  type keyword
   -  statistics
      -  entries-aged-out number
      -  frame-discard number
      -  frame-error-in number
      -  frame-in number
      -  frame-out number
      -  last-clear string
      -  tlv-accepted number
      -  tlv-discard number
      -  tlv-unknown number
   -  system-description string
   -  system-name string
   +  trace-options keyword
+  load-balancing
   +  hash-options
      +  destination-address boolean
      +  destination-port boolean
      +  hash-seed number
      +  ipv6-flow-label boolean
      +  mpls-label-stack boolean
      +  protocol boolean
      +  source-address boolean
      +  source-port boolean
      +  vlan boolean
+  logging
   +  buffer buffer-name string 
      +  facility facility-name keyword 
         +  priority
            +  match-above keyword
            +  match-exact keyword
      +  filter reference
      +  format (string | keyword)
      +  persist number
      +  rotate number
      -  rotations number
      +  size string
      +  subsystem subsystem-name keyword 
         +  priority
            +  match-above keyword
            +  match-exact keyword
   +  console
      +  facility facility-name keyword 
         +  priority
            +  match-above keyword
            +  match-exact keyword
      +  filter reference
      +  format (string | keyword)
      +  subsystem subsystem-name keyword 
         +  priority
            +  match-above keyword
            +  match-exact keyword
   +  file file-name string 
      +  directory string
      +  facility facility-name keyword 
         +  priority
            +  match-above keyword
            +  match-exact keyword
      +  filter reference
      +  format (string | keyword)
      +  rotate number
      -  rotations number
      +  size string
      +  subsystem subsystem-name keyword 
         +  priority
            +  match-above keyword
            +  match-exact keyword
   +  filter filter-name string 
      +  contains string
      +  facility facility-name keyword 
         +  priority
            +  match-above keyword
            +  match-exact keyword
      +  prefix string
      +  regex string
      +  tag string
   +  network-instance reference
   +  remote-server host (ipv4-address | ipv6-address | domain-name) 
      +  facility facility-name keyword 
         +  priority
            +  match-above keyword
            +  match-exact keyword
      +  filter reference
      +  format (string | keyword)
      +  remote-port number
      +  source-address (ipv4-address | ipv6-address)
      +  subsystem subsystem-name keyword 
         +  priority
            +  match-above keyword
            +  match-exact keyword
      +  transport keyword
   +  subsystem-facility keyword
   +  use-fqdn boolean
+  maintenance
   +  group name string 
      +  maintenance-mode
         +  admin-state keyword
      +  maintenance-profile reference
      +  members
         +  bgp
            +  network-instance name reference 
               +  neighbor reference
               +  peer-group reference
   +  profile name string 
      +  bgp
         +  export-policy reference
         +  import-policy reference
+  management
   +  openconfig
      +  admin-state keyword
      -  oper-state keyword
+  mirroring
   +  mirroring-instance name string 
      +  admin-state keyword
      +  description string
      +  mirror-destination
         +  local string
         +  remote
            +  encap keyword
            +  network-instance reference
            +  tunnel-end-points
               +  admin-state keyword
               +  destination-address (ipv4-address | ipv6-address)
               -  oper-state keyword
               +  source-address (ipv4-address | ipv6-address)
         -  statistics
            -  egress-mirrored-octets number
            -  egress-mirrored-packets number
            -  ingress-mirrored-octets number
            -  ingress-mirrored-packets number
      +  mirror-source
         +  acl
            +  acl-filter name reference type reference 
               +  entry sequence-id reference 
         +  interface name string 
            +  direction keyword
         +  subinterface name string 
            +  direction keyword
            -  oper-down-reason keyword
            -  oper-state keyword
      -  oper-down-reason keyword
      -  oper-state keyword
+  mpls
   +  label-ranges
      +  dynamic name string 
         -  allocated-labels number
         +  end-label number
         -  free-labels number
         +  start-label number
         -  status keyword
         -  user index number 
            -  owner identityref
      +  static name string 
         -  allocated-labels number
         +  end-label number
         -  free-labels number
         +  shared boolean
         +  start-label number
         -  status keyword
         -  user index number 
            -  owner identityref
   +  services
+  mtu
   +  default-ip-mtu number
   +  default-l2-mtu number
   +  default-mpls-mtu number
   +  default-port-mtu number
   +  min-path-mtu number
+  multicast
   +  multicast-ids
      -  statistics
         -  current-usage number
         -  maximum-ids number
         -  multicast-id-user-type user keyword 
            -  current-usage number
            -  total-pending number
         -  total-pending number
-  multicast-forwarding-information-base
   -  multicast-route network-instance reference source (ipv4-address | ipv6-address) group (ipv4-address | ipv6-address) 
      -  last-update string
      -  line-card-replication-index number
+  name
   +  domain-name string
   +  host-name string
+  network-instance
   +  protocols
      +  bgp-vpn
         +  bgp-instance id number 
            -  oper-down-reason keyword
            +  route-distinguisher
               -  rd (route-distinguisher-type-0 | route-distinguisher-type-1 | route-distinguisher-type-2 | route-distinguisher-type-2b)
               -  route-distinguisher-origin keyword
            +  route-target
               -  export-route-target-origin keyword
               -  export-rt (string | string | string | string | string | string | string | string)
               -  import-route-target-origin keyword
               -  import-rt (string | string | string | string | string | string | string | string)
      +  evpn
         +  ethernet-segments
            +  bgp-instance id reference 
               +  ethernet-segment name string 
                  +  admin-state keyword
                  -  association
                     -  network-instance name string 
                        -  bgp-instance instance number 
                           -  computed-designated-forwarder-candidates
                              -  designated-forwarder-candidate address (ipv4-address | ipv6-address) 
                                 -  add-time string
                                 -  designated-forwarder boolean
                           -  designated-forwarder-activation-start-time string
                           -  designated-forwarder-activation-time number
                           -  designated-forwarder-role-last-change string
                  -  autodiscovery-per-ethernet-segment-routes
                     -  attr-id reference
                     -  esi string
                     -  ethernet-tag-id number
                     -  label
                        -  value number
                        -  value-type keyword
                     -  neighbor (ipv4-address-with-zone | ipv6-address-with-zone)
                     -  route-distinguisher (route-distinguisher-type-0 | route-distinguisher-type-1 | route-distinguisher-type-2 | route-distinguisher-type-2b)
                  +  df-election
                     +  algorithm
                        +  manual-alg
                           +  primary-evi-range start-evi number 
                              +  end-evi number
                        -  oper-type keyword
                        +  preference-alg
                           +  capabilities
                              +  ac-df keyword
                              +  non-revertive boolean
                           -  oper-do-not-prempt boolean
                           -  oper-preference-value number
                           +  preference-value number
                        +  type keyword
                     +  interface-standby-signaling-on-non-df
                     +  timers
                        +  activation-timer number
                  +  esi string
                  -  esi-label number
                  -  ethernet-segment-routes
                     -  attr-id reference
                     -  esi string
                     -  neighbor (ipv4-address-with-zone | ipv6-address-with-zone)
                     -  originating-router (ipv4-address | ipv6-address)
                     -  route-distinguisher (route-distinguisher-type-0 | route-distinguisher-type-1 | route-distinguisher-type-2 | route-distinguisher-type-2b)
                  +  interface ethernet-interface reference 
                  +  multi-homing-mode keyword
                  +  next-hop l3-next-hop (ipv4-address | ipv6-address) 
                     +  evi start number 
                  -  oper-down-reason keyword
                  -  oper-esi string
                  -  oper-multi-homing-mode keyword
                  -  oper-state keyword
                  +  routes
                     +  ethernet-segment
                        +  originating-ip keyword
                     +  next-hop keyword
                  +  type keyword
            +  timers
               +  activation-timer number
               -  boot-remaining-time number
               -  boot-start-time string
               +  boot-timer number
+  ntp
   +  admin-state keyword
   +  network-instance reference
   -  oper-state keyword
   +  server address (ipv4 | ipv6 | domain-name) 
      +  iburst boolean
      -  jitter number
      -  offset number
      -  poll-interval number
      +  prefer boolean
      -  root-delay number
      -  root-dispersion number
      -  stratum number
   +  source-address (ipv4-address | ipv6-address)
   -  synchronized (ipv4-address | ipv6-address | domain-name | string)
+  packet-link-qualification
   +  profile name string 
      +  asic-loopback
      +  ntp
         +  end-time string
         +  start-time string
         +  teardown-time string
      +  packet-generator
         +  packet-rate number
         +  packet-size number
      +  rpc
         +  duration number
         +  post-sync-duration number
         +  pre-sync-duration number
         +  setup-duration number
         +  teardown-duration number
+  protocols
   +  bgp
      +  restart-max-wait number
+  ra-guard-policy name string 
   +  action keyword
   +  advertise-prefix-set reference
   +  hop-limit number
   +  managed-config-flag boolean
   +  other-config-flag boolean
   +  router-preference keyword
   +  source-prefix-set reference
+  sflow
   +  admin-state keyword
   +  collector collector-id number 
      +  collector-address (ipv4-address | ipv6-address)
      +  network-instance reference
      -  next-hop (ipv4-address | ipv6-address)
      +  port number
      +  source-address (ipv4-address | ipv6-address)
   +  dscp number
   +  sample-rate number
   +  sample-size number
   +  source-address (ipv4-address | ipv6-address)
   -  statistics
      -  total-offered-packets number
      -  total-samples-taken number
      -  total-sent-packets number
+  snmp
   +  access-group name string 
      +  admin-state keyword
      +  community-entry name string 
         +  community string
         +  description string
         +  prefix-list (ipv4-prefix | ipv6-prefix)
      +  description string
      +  security-entry name string 
         +  authentication
            +  password string
            +  protocol keyword
         +  description string
         +  privacy
            +  password string
            +  protocol keyword
         +  user string
      +  security-level keyword
   +  network-instance name reference 
      +  admin-state keyword
      +  engine-id string
      -  error-msg string
      +  listen-address (ipv4-address | ipv6-address)
      -  oper-state keyword
   +  trap-group name string 
      +  admin-state keyword
      +  description string
      +  destination name string 
         +  address (ipv4-address | ipv6-address)
         +  admin-state keyword
         +  community-entry name string 
            +  community string
            +  description string
         +  description string
         +  port number
         +  security-entry name string 
            +  authentication
               +  password string
               +  protocol keyword
            +  description string
            +  engine-id string
            +  privacy
               +  password string
               +  protocol keyword
            +  user string
         +  security-level keyword
      +  network-instance reference
      +  source-address (ipv4-address | ipv6-address)
+  ssh-server name string 
   +  admin-state keyword
   +  allowed-authentication-types keyword
   +  authorized-principal-check-tool keyword
   -  counters
      -  access-accepts number
      -  access-rejects number
      -  last-access-accept string
      -  last-access-reject string
   -  credentialz
      -  host-certificate
         -  created-on string
         -  version string
      -  host-key
         -  created-on string
         -  version string
      -  trusted-user-ca-keys
         -  created-on string
         -  version string
   +  disable-shell boolean
   +  host-key
      +  preserve boolean
      +  type type keyword 
         +  certificate string
         +  private-key string
         -  public-key string
   +  network-instance reference
   -  oper-state keyword
   +  port number
   -  protocol-version number
   +  rate-limit number
   +  revoked-keys string
   +  source-address (ipv4-address | ipv6-address)
   +  timeout number
   +  trust-anchors string
   +  use-credentialz boolean
+  sync
   +  freq-clock
      -  active-reference keyword
      -  freq-clock-state keyword
      -  freq-offset decimal-number
      +  network-type keyword
      +  ql-input-threshold keyword
      +  ql-selection boolean
      +  revert boolean
      -  system-ql-value keyword
      +  wait-to-restore number
   +  freq-references
      +  instance instance-number number 
         +  admin-state keyword
         -  not-qualified-reason keyword
         -  oper-state keyword
         +  priority number
         +  ql-override keyword
         -  ql-value keyword
         -  reference-status keyword
         +  source
            +  gnss
            +  interface reference
            +  ptp
            +  sync0
   +  one-pps
      +  admin-state keyword
   +  ptp
      +  instance instance-index number 
         -  current-ds
            -  mean-delay number
            -  offset-from-master number
            -  steps-removed number
         +  default-ds
            +  announce-receipt-timeout number
            -  clock-identity binary
            -  clock-quality
               -  clock-accuracy number
               -  clock-class number
               -  offset-scaled-log-variance number
            -  current-time
               -  date-time string
               -  time-nano-seconds number
               -  time-seconds number
            +  domain-number number
            +  instance-enable boolean
            +  instance-type keyword
            +  local-priority number
            +  log-announce-interval number
            -  number-ports number
            +  priority1 number
            +  priority2 number
            -  statistics
               -  anno-msg-rx number
               -  anno-msg-tx number
               -  del-req-msg-rx number
               -  del-req-msg-tx number
               -  del-resp-msg-rx number
               -  del-resp-msg-tx number
               -  delay-high-packet-loss number
               -  delay-packet-loss number
               -  discards
                  -  alternate-master number
                  -  bad-domain number
                  -  other number
                  -  out-of-sequence number
               -  follow-up-msg-rx number
               -  follow-up-msg-tx number
               -  multicast-msg-rate
                  -  anno-msg-rate-rx decimal-number
                  -  anno-msg-rate-tx decimal-number
                  -  del-req-msg-rate-rx decimal-number
                  -  del-req-msg-rate-tx decimal-number
                  -  del-resp-msg-rate-rx decimal-number
                  -  del-resp-msg-rate-tx decimal-number
                  -  follow-up-msg-rate-rx decimal-number
                  -  follow-up-msg-rate-tx decimal-number
                  -  other-rate-rx decimal-number
                  -  sync-msg-rate-rx decimal-number
                  -  sync-msg-rate-tx decimal-number
               -  other-rx number
               -  sync-high-packet-loss number
               -  sync-msg-rx number
               -  sync-msg-tx number
               -  sync-packet-loss number
            -  time-recovery-engine
               -  last-adjustment number
               -  last-adjustment-timestamp string
               -  recovery-state keyword
               -  state-last-changed string
               -  statistics
                  -  delay-too-much-pdv number
                  -  sync-too-much-pdv number
                  -  time-in-acquiring number
                  -  time-in-holdover number
                  -  time-in-initial number
                  -  time-in-locked number
            -  two-step-flag boolean
         -  parent-ds
            -  grandmaster-clock-quality
               -  clock-accuracy number
               -  clock-class number
               -  offset-scaled-log-variance number
            -  grandmaster-identity binary
            -  grandmaster-priority1 number
            -  grandmaster-priority2 number
            -  parent-port-identity
               -  clock-identity binary
               -  port-number number
            -  protocol-address
               -  mac-address string
               -  network-protocol identityref
         -  port-ds-gnss
            -  best-master boolean
            -  major-version-number number
            -  minor-version-number number
            -  parent-clock boolean
            -  port-state keyword
            -  ptp-port-number number
         +  port-ds-interface-list port-index number 
            +  admin-state keyword
            -  announce-receipt-timeout number
            -  best-master boolean
            +  dest-mac keyword
            +  local-priority number
            -  log-announce-interval number
            +  log-min-delay-req-interval number
            +  log-sync-interval number
            -  major-version-number number
            +  master-only boolean
            -  minor-version-number number
            -  neighbor-count number
            -  neighbor-list clock-identity binary port-number number 
               -  mac-address string
               -  rx-message-rate decimal-number
            -  parent-clock boolean
            -  port-state keyword
            -  ptp-port-number number
            +  source
               +  interface reference
               +  sync0
            -  statistics
               -  anno-msg-rx number
               -  anno-msg-tx number
               -  del-req-msg-rx number
               -  del-req-msg-tx number
               -  del-resp-msg-rx number
               -  del-resp-msg-tx number
               -  discards
                  -  alternate-master number
                  -  bad-domain number
                  -  other number
                  -  out-of-sequence number
               -  follow-up-msg-rx number
               -  follow-up-msg-tx number
               -  other-rx number
               -  sync-msg-rx number
               -  sync-msg-tx number
         -  time-properties-ds
            -  current-utc-offset number
            -  current-utc-offset-valid boolean
            -  frequency-traceable boolean
            -  leap59 boolean
            -  leap61 boolean
            -  ptp-timescale boolean
            -  time-source keyword
            -  time-traceable boolean
      +  ptp-profile keyword
+  tls
   +  server-profile name string 
      +  authenticate-client boolean
      +  certificate string
      +  certificate-revocation-list string
      -  certz
         -  certificate
            -  created-on string
            -  version string
         -  crl
            -  created-on string
            -  version string
         -  ssl-profile-id string
         -  trust-anchor
            -  created-on string
            -  version string
      +  cipher-list identityref
      -  dynamic boolean
      +  key string
      +  trust-anchor string
+  trace-options keyword

system Descriptions

system

Description Enclosing container for system management
Contextsystem
Treesystem
ConfigurableTrue
PlatformsSupported on all platforms

aaa

Description Top-level container for AAA services
Context system aaa
Treeaaa
ConfigurableTrue
PlatformsSupported on all platforms

accounting

Description Top-level container for accounting
Context system aaa accounting
Treeaccounting
ConfigurableTrue
PlatformsSupported on all platforms
accounting-method reference
Description

Ordered list of server-groups to use for accounting in the system

If accounting fails with one method, the next defined method is tried -- failure of all methods results in the accounting request failing.

Contextsystem aaa accounting accounting-method reference
Treeaccounting-method
Referencesystem aaa server-group name string
ConfigurableTrue
PlatformsSupported on all platforms
event event-type identityref
Description List of events subject to accounting
Context system aaa accounting event event-type identityref
Treeevent
ConfigurableTrue
PlatformsSupported on all platforms
event-type identityref
Description The type of activity to record at the accounting server
Contextsystem aaa accounting event event-type identityref
Options
  • command

    Specifies interactive command events for AAA accounting

ConfigurableTrue
PlatformsSupported on all platforms
record identityref
Description Type of record to send to the accounting server for this activity type
Contextsystem aaa accounting event event-type identityref record identityref
Treerecord
Options
  • start-stop

    Send start and stop records for user activities

    A start record is sent to the accounting server at the beginning of the activity, and a stop record at the end of the activity

  • stop

    Send only stop records for user activities

    A stop record is sent to the accounting server when the user activity completes

ConfigurableTrue
PlatformsSupported on all platforms

authentication

Description Top-level container for global authentication data
Contextsystem aaa authentication
Treeauthentication
ConfigurableTrue
PlatformsSupported on all platforms
admin-user
Description Enclosing container for admin user
Context system aaa authentication admin-user
Treeadmin-user
ConfigurableTrue
PlatformsSupported on all platforms
credentialz
Description

Information relating to the active user credentials as provided via Credentialz

State is provided by the gNSI Credentialz service, and can be changed using the gNSI.Credentialz.RotateAccountCredentials RPC

Contextsystem aaa authentication admin-user credentialz
Treecredentialz
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
authorized-keys
Description State relating to the Authorized Keys provided via Credentialz
Contextsystem aaa authentication admin-user credentialz authorized-keys
Treeauthorized-keys
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
created-on string
Description

The created on timestamp as provided by the gNSI client at the time of uploading the artifact

The maps to the created_on field within a Entity message in the Credentialz protobuf.

Contextsystem aaa authentication admin-user credentialz authorized-keys created-on string
Treecreated-on
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
version string
Description

The version string as provided by the gNSI client at the time of uploading the artifact

The maps to the version field within a Entity message in the Credentialz protobuf.

Contextsystem aaa authentication admin-user credentialz authorized-keys version string
Treeversion
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
authorized-principals
Description State relating to the Authorized Principals provided via Credentialz
Contextsystem aaa authentication admin-user credentialz authorized-principals
Treeauthorized-principals
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
created-on string
Description

The created on timestamp as provided by the gNSI client at the time of uploading the artifact

The maps to the created_on field within a Entity message in the Credentialz protobuf.

Contextsystem aaa authentication admin-user credentialz authorized-principals created-on string
Treecreated-on
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
version string
Description

The version string as provided by the gNSI client at the time of uploading the artifact

The maps to the version field within a Entity message in the Credentialz protobuf.

Contextsystem aaa authentication admin-user credentialz authorized-principals version string
Treeversion
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
password
Description State relating to the Password provided via Credentialz.
Contextsystem aaa authentication admin-user credentialz password
Treepassword
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
created-on string
Description

The created on timestamp as provided by the gNSI client at the time of uploading the artifact

The maps to the created_on field within a Entity message in the Credentialz protobuf.

Contextsystem aaa authentication admin-user credentialz password created-on string
Treecreated-on
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
version string
Description

The version string as provided by the gNSI client at the time of uploading the artifact

The maps to the version field within a Entity message in the Credentialz protobuf.

Contextsystem aaa authentication admin-user credentialz password version string
Treeversion
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
lockout
Description Information relating to the lockout state of this user
Contextsystem aaa authentication admin-user lockout
Treelockout
ConfigurableFalse
PlatformsSupported on all platforms
active boolean
Description

Indicates if a lockout is active for the user

Lockouts can occur after successive failed logins, and can be cleared by 'tools system aaa authentication user <username> unlock'

Contextsystem aaa authentication admin-user lockout active boolean
Treeactive
ConfigurableFalse
PlatformsSupported on all platforms
end string
Description Indicates the time at which the most recent lockout for this user ended or will end
Contextsystem aaa authentication admin-user lockout end string
Treeend
String Length20 to 32
ConfigurableFalse
PlatformsSupported on all platforms
start string
Description Indicates the time at which the most recent lockout for this user started
Contextsystem aaa authentication admin-user lockout start string
Treestart
String Length20 to 32
ConfigurableFalse
PlatformsSupported on all platforms
password string
Description

The admin password, supplied either as cleartext or as a hashed value

If provided as cleartext, the system will hash the value on input, storing only the hashed value. If provided as a hashed value, the value should include any '$' characters, for example '$ar2$aOvsuj0ALlU=$r750fMa3ZEA/Di8dIfU2fQ=='.

Contextsystem aaa authentication admin-user password string
Treepassword
Default$y$j9T$pNVjOgcNNGIWjBcdDfK/7.$Ir4uYxszxtqzVj5AGiZvdWJGs.bpLWBJvHON3YgqnC2
ConfigurableTrue
PlatformsSupported on all platforms
role reference
Description

List of roles to assign to this user

The most specific rule for a particular role takes precedence. Rules from all user roles are evaluated together, most permissive privilege taking precedence.

Contextsystem aaa authentication admin-user role reference
Treerole
Referencesystem aaa authorization role rolename string
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
Max. Elements32
spiffe-ids string
Description

The SPIFFE ID list for the user, including the spiffe:// URI

This list of IDs is evaluated by TLS-consuming servers (e.g. gNMI, JSON-RPC) that use a TLS server-profile with authenticate-client set to true.

If a match is found in any incoming offered client certificates, the provider of the certificate is associated with this local user, and given resulting permissions.

Contextsystem aaa authentication admin-user spiffe-ids string
Treespiffe-ids
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
ssh-key string
Description

SSH public key(s) for the user

If defined, the user may login to the system over SSH with this key. This should use the SSH public authorized key format.

Contextsystem aaa authentication admin-user ssh-key string
Treessh-key
ConfigurableTrue
PlatformsSupported on all platforms
Max. Elements32
ssh-principals string
Description

List of principals to associate with this user

If any of the principals in the list are matched in a SSH client's certificate, and that clients username matches this user, and the certificate is verified, the client will authenticate.

Contextsystem aaa authentication admin-user ssh-principals string
Treessh-principals
ConfigurableTrue
PlatformsSupported on all platforms
Max. Elements32
superuser boolean
Description

Indicates if the admin user is a superuser

A superuser is granted implicit authorization to all YANG paths, has the ability to execute all CLI plugins, and by default is permitted to access the device through any interface.

Additionally, users with the superuser attribute are able to execute 'sudo' in bash. A user may also be assigned a role or list of roles, but these are only evaluated for service authorization.

Contextsystem aaa authentication admin-user superuser boolean
Treesuperuser
Defaulttrue
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
dynamic-spiffe
Description Dynamic SPIFFE settings
Context system aaa authentication dynamic-spiffe
Treedynamic-spiffe
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
allow boolean
Description

Accept clients with SPIFFE ID values that are not configured under any local user

With this behaviour enabled, when a client using a client certificate containing SPIFFE ID connects the system will accept the client. Otherwise the SPIFFE ID must be configured under some local user. Even if enabled, any client using local user's configured SPIFFE ID will use that user's identity in all operations

Contextsystem aaa authentication dynamic-spiffe allow boolean
Treeallow
Defaultfalse
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
role reference
Description

List of roles to assign to all dynamic SPIFFE clients

Dynamic SPIFFE clients are clients authenticated using a client certificate containing SPIFFE ID value that is not configured under any local user. The most specific rule for a particular role takes precedence. Rules from all user roles are evaluated together, most permissive privilege taking precedence.

Contextsystem aaa authentication dynamic-spiffe role reference
Treerole
Referencesystem aaa authorization role rolename string
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
Max. Elements32
exit-on-reject boolean
Description

Enable/disable exit-on-reject behaviour for authentication attempts

With this behaviour enabled, when a reject is received from any server the system will not try further methods, and will reject the user authentication attempt. Default behaviour is to continue trying methods until one accepts the user, or the system runs out of methods to try.

Contextsystem aaa authentication exit-on-reject boolean
Treeexit-on-reject
Defaultfalse
ConfigurableTrue
PlatformsSupported on all platforms
idle-timeout number
Description

Set the idle timeout of all CLI sessions

After the timeout is reached, the session is disconnected from the system.

Contextsystem aaa authentication idle-timeout number
Treeidle-timeout
Default600
Unitsseconds
ConfigurableTrue
PlatformsSupported on all platforms
linuxadmin-user
Description Enclosing container for linuxadmin user
Contextsystem aaa authentication linuxadmin-user
Treelinuxadmin-user
ConfigurableTrue
PlatformsSupported on all platforms
credentialz
Description

Information relating to the active user credentials as provided via Credentialz

State is provided by the gNSI Credentialz service, and can be changed using the gNSI.Credentialz.RotateAccountCredentials RPC

Contextsystem aaa authentication linuxadmin-user credentialz
Treecredentialz
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
authorized-keys
Description State relating to the Authorized Keys provided via Credentialz
Contextsystem aaa authentication linuxadmin-user credentialz authorized-keys
Treeauthorized-keys
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
created-on string
Description

The created on timestamp as provided by the gNSI client at the time of uploading the artifact

The maps to the created_on field within a Entity message in the Credentialz protobuf.

Contextsystem aaa authentication linuxadmin-user credentialz authorized-keys created-on string
Treecreated-on
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
version string
Description

The version string as provided by the gNSI client at the time of uploading the artifact

The maps to the version field within a Entity message in the Credentialz protobuf.

Contextsystem aaa authentication linuxadmin-user credentialz authorized-keys version string
Treeversion
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
authorized-principals
Description State relating to the Authorized Principals provided via Credentialz
Contextsystem aaa authentication linuxadmin-user credentialz authorized-principals
Treeauthorized-principals
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
created-on string
Description

The created on timestamp as provided by the gNSI client at the time of uploading the artifact

The maps to the created_on field within a Entity message in the Credentialz protobuf.

Contextsystem aaa authentication linuxadmin-user credentialz authorized-principals created-on string
Treecreated-on
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
version string
Description

The version string as provided by the gNSI client at the time of uploading the artifact

The maps to the version field within a Entity message in the Credentialz protobuf.

Contextsystem aaa authentication linuxadmin-user credentialz authorized-principals version string
Treeversion
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
password
Description State relating to the Password provided via Credentialz.
Contextsystem aaa authentication linuxadmin-user credentialz password
Treepassword
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
created-on string
Description

The created on timestamp as provided by the gNSI client at the time of uploading the artifact

The maps to the created_on field within a Entity message in the Credentialz protobuf.

Contextsystem aaa authentication linuxadmin-user credentialz password created-on string
Treecreated-on
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
version string
Description

The version string as provided by the gNSI client at the time of uploading the artifact

The maps to the version field within a Entity message in the Credentialz protobuf.

Contextsystem aaa authentication linuxadmin-user credentialz password version string
Treeversion
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
password string
Description

The linuxadmin password, supplied either as cleartext or as a hashed value

If provided as cleartext, the system will hash the value on input, storing only the hashed value. If provided as a hashed value, the value should include any '$' characters, for example '$6$c66a15569d3f5952$kA2WPt9iqR5uMbaCUBNxsjKyXROQFdJtV1HX0CFY9wk7F326/yB3h.dERX9cH7YpeJ1N872hjzTb2tlaZFwwg0'.

Contextsystem aaa authentication linuxadmin-user password string
Treepassword
Default$y$j9T$l/vKPXdvWQKKPH8qPzbLs0$Hz98mmTg.j87QMZlTqY2ieGWa3Ed7kzHkp5z6kROEy4
ConfigurableTrue
PlatformsSupported on all platforms
ssh-key string
Description

SSH public key(s) for the user

If defined, the user may login to the system over SSH with this key. This should use the SSH public authorized key format.

Contextsystem aaa authentication linuxadmin-user ssh-key string
Treessh-key
ConfigurableTrue
PlatformsSupported on all platforms
Max. Elements32
ssh-principals string
Description

List of principals to associate with this user

If any of the principals in the list are matched in a SSH client's certificate, and that clients username matches this user, and the certificate is verified, the client will authenticate.

Contextsystem aaa authentication linuxadmin-user ssh-principals string
Treessh-principals
ConfigurableTrue
PlatformsSupported on all platforms
Max. Elements32
password
Description Top-level container for policies around user passwords
Contextsystem aaa authentication password
Treepassword
ConfigurableTrue
PlatformsSupported on all platforms
aging number
Description

Expire user passwords after this period

A value of 0 means that the user passwords do not expire

Contextsystem aaa authentication password aging number
Treeaging
Range0 to 500
Default0
Unitsdays
Configurable True
PlatformsSupported on all platforms
complexity-rules
Description Top-level container for password complexity rules
Contextsystem aaa authentication password complexity-rules
Treecomplexity-rules
ConfigurableTrue
PlatformsSupported on all platforms
hash-method keyword
Description

The hash algorithm for the passwords entered as plain text

If no value is configured, then Yescrypt will be used as the hash algorithm unless overriden for specific leafs using the srl_nokia-extensions:hash-algorithm yang extension. The Argon2 (ar2) hash algorithm is not supported for the linuxadmin user and if selected then the linuxadmin password will be hashed using Yescrypt.

Contextsystem aaa authentication password hash-method keyword
Treehash-method
Options
  • ar2

    The Argon2 password hashing algorithm

  • sha2

    The SHA512 password hashing algorithm

  • yescrypt

    The Yescrypt password hashing algorithm

ConfigurableTrue
PlatformsSupported on all platforms
history number
Description Defines how many previous passwords a new password is matched against, such that a new password can't be one of the previous n passwords
Contextsystem aaa authentication password history number
Treehistory
Range0 to 20
Default0
ConfigurableTrue
PlatformsSupported on all platforms
lockout-policy
Description Top-level container for lockout policy
Contextsystem aaa authentication password lockout-policy
Treelockout-policy
ConfigurableTrue
PlatformsSupported on all platforms
attempts number
Description

The number of failed login attempts that will lock the account

A value of 0 means unlimited number of failed login attempts is allowed

Contextsystem aaa authentication password lockout-policy attempts number
Treeattempts
Range0 to 64
Default0
ConfigurableTrue
PlatformsSupported on all platforms
lockout number
Description

The time duration in minutes the user account will be locked out

A value of 0 means that the user account will be locked out/disabled indefinitely

Contextsystem aaa authentication password lockout-policy lockout number
Treelockout
Range0 to 1440
Default15
Unitsminutes
Configurable True
PlatformsSupported on all platforms
session id number
Description List of active sessions in the system
Contextsystem aaa authentication session id number
Treesession
ConfigurableFalse
PlatformsSupported on all platforms
spiffe-id string
Description SPIFFE ID linked to the session
Context system aaa authentication session id number spiffe-id string
Treespiffe-id
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
user username string
Description List of local users configured on the system
Contextsystem aaa authentication user username string
Treeuser
ConfigurableTrue
PlatformsSupported on all platforms
Max. Elements128
username string
Description Assigned username for this user
Context system aaa authentication user username string
String Length1 to 32
ConfigurableTrue
PlatformsSupported on all platforms
credentialz
Description

Information relating to the active user credentials as provided via Credentialz

State is provided by the gNSI Credentialz service, and can be changed using the gNSI.Credentialz.RotateAccountCredentials RPC

Contextsystem aaa authentication user username string credentialz
Treecredentialz
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
authorized-keys
Description State relating to the Authorized Keys provided via Credentialz
Contextsystem aaa authentication user username string credentialz authorized-keys
Treeauthorized-keys
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
created-on string
Description

The created on timestamp as provided by the gNSI client at the time of uploading the artifact

The maps to the created_on field within a Entity message in the Credentialz protobuf.

Contextsystem aaa authentication user username string credentialz authorized-keys created-on string
Treecreated-on
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
version string
Description

The version string as provided by the gNSI client at the time of uploading the artifact

The maps to the version field within a Entity message in the Credentialz protobuf.

Contextsystem aaa authentication user username string credentialz authorized-keys version string
Treeversion
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
authorized-principals
Description State relating to the Authorized Principals provided via Credentialz
Contextsystem aaa authentication user username string credentialz authorized-principals
Treeauthorized-principals
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
created-on string
Description

The created on timestamp as provided by the gNSI client at the time of uploading the artifact

The maps to the created_on field within a Entity message in the Credentialz protobuf.

Contextsystem aaa authentication user username string credentialz authorized-principals created-on string
Treecreated-on
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
version string
Description

The version string as provided by the gNSI client at the time of uploading the artifact

The maps to the version field within a Entity message in the Credentialz protobuf.

Contextsystem aaa authentication user username string credentialz authorized-principals version string
Treeversion
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
password
Description State relating to the Password provided via Credentialz.
Contextsystem aaa authentication user username string credentialz password
Treepassword
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
created-on string
Description

The created on timestamp as provided by the gNSI client at the time of uploading the artifact

The maps to the created_on field within a Entity message in the Credentialz protobuf.

Contextsystem aaa authentication user username string credentialz password created-on string
Treecreated-on
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
version string
Description

The version string as provided by the gNSI client at the time of uploading the artifact

The maps to the version field within a Entity message in the Credentialz protobuf.

Contextsystem aaa authentication user username string credentialz password version string
Treeversion
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
lockout
Description Information relating to the lockout state of this user
Contextsystem aaa authentication user username string lockout
Treelockout
ConfigurableFalse
PlatformsSupported on all platforms
active boolean
Description

Indicates if a lockout is active for the user

Lockouts can occur after successive failed logins, and can be cleared by 'tools system aaa authentication user <username> unlock'

Contextsystem aaa authentication user username string lockout active boolean
Treeactive
ConfigurableFalse
PlatformsSupported on all platforms
end string
Description Indicates the time at which the most recent lockout for this user ended or will end
Contextsystem aaa authentication user username string lockout end string
Treeend
String Length20 to 32
ConfigurableFalse
PlatformsSupported on all platforms
start string
Description Indicates the time at which the most recent lockout for this user started
Contextsystem aaa authentication user username string lockout start string
Treestart
String Length20 to 32
ConfigurableFalse
PlatformsSupported on all platforms
password string
Description

The user password, supplied either as cleartext or as a hashed value

If provided as cleartext, the system will hash the value on input, storing only the hashed value. If provided as a hashed value, the value should include any '$' characters, for example '$ar2$aOvsuj0ALlU=$r750fMa3ZEA/Di8dIfU2fQ=='.

Contextsystem aaa authentication user username string password string
Treepassword
ConfigurableTrue
PlatformsSupported on all platforms
role reference
Description

List of roles to assign to this user

The most specific rule for a particular role takes precedence. Rules from all user roles are evaluated together, most permissive privilege taking precedence.

Contextsystem aaa authentication user username string role reference
Treerole
Referencesystem aaa authorization role rolename string
ConfigurableTrue
PlatformsSupported on all platforms
Max. Elements32
spiffe-ids string
Description

The SPIFFE ID list for the user, including the spiffe:// URI

This list of IDs is evaluated by TLS-consuming servers (e.g. gNMI, JSON-RPC) that use a TLS server-profile with authenticate-client set to true.

If a match is found in any incoming offered client certificates, the provider of the certificate is associated with this local user, and given resulting permissions.

Contextsystem aaa authentication user username string spiffe-ids string
Treespiffe-ids
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
ssh-key string
Description

SSH public key(s) for the user

If defined, the user may login to the system over SSH with this key. This should use the SSH public authorized key format.

Contextsystem aaa authentication user username string ssh-key string
Treessh-key
ConfigurableTrue
PlatformsSupported on all platforms
Max. Elements32
ssh-principals string
Description

List of principals to associate with this user

If any of the principals in the list are matched in a SSH client's certificate, and that clients username matches this user, and the certificate is verified, the client will authenticate.

Contextsystem aaa authentication user username string ssh-principals string
Treessh-principals
ConfigurableTrue
PlatformsSupported on all platforms
Max. Elements32
superuser boolean
Description

Indicates that this user is a superuser

A superuser is granted implicit authorization to all YANG paths, has the ability to execute all CLI plugins, and by default is permitted to access the device through any interface.

Additionally, users with the superuser attribute are able to execute 'sudo' in bash. A user may also be assigned a role or list of roles, but these are only evaluated for service authorization.

Contextsystem aaa authentication user username string superuser boolean
Treesuperuser
Defaultfalse
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

authorization

Description Top-level container for authorization configuration and operational state data
Contextsystem aaa authorization
Treeauthorization
ConfigurableTrue
PlatformsSupported on all platforms
authz-policy
Description

Information relating to the active gRPC authorization policy

This policy is provided by the gNSI gRPC service, and can be changed using the gNSI.Authz.Rotate RPC

Contextsystem aaa authorization authz-policy
Treeauthz-policy
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
counters
Description A collection of counters collected by the gNSI.authz module.
Contextsystem aaa authorization authz-policy counters
Treecounters
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
rpc name string
Description A collection of counters collected by the gNSI.authz module for a RPC identified by the `name`.
Contextsystem aaa authorization authz-policy counters rpc name string
Treerpc
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
name string
Description The name of the RPC the counters were collected for.
Contextsystem aaa authorization authz-policy counters rpc name string
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
access-accepts number
Description The total number of times the gNSI.authz module allowed access to a RPC.
Contextsystem aaa authorization authz-policy counters rpc name string access-accepts number
Treeaccess-accepts
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
access-rejects number
Description The total number of times the gNSI.authz module denied access to a RPC.
Contextsystem aaa authorization authz-policy counters rpc name string access-rejects number
Treeaccess-rejects
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
last-access-accept string
Description A timestamp of the last time the gNSI.authz allowed access to a RPC.
Contextsystem aaa authorization authz-policy counters rpc name string last-access-accept string
Treelast-access-accept
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
last-access-reject string
Description A timestamp of the last time the gNSI.authz denied access to a RPC.
Contextsystem aaa authorization authz-policy counters rpc name string last-access-reject string
Treelast-access-reject
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
created-on string
Description

The created on timestamp as provided by the gNSI client at the time of uploading the policy

This maps to the created_on field within a UploadRequest message in the Authz protobuf.

Contextsystem aaa authorization authz-policy created-on string
Treecreated-on
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
policy string
Description

The policy definition

This JSON string contains the full gRPC authorization rules conforming to the gRPC authorization policy schema:

This maps to the policy field within a UploadRequest message in the Authz protobuf.

Contextsystem aaa authorization authz-policy policy string
Treepolicy
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
version string
Description

The version string as provided by the gNSI client at the time of uploading the policy

The maps to the version field within a UploadRequest message in the Authz protobuf.

Contextsystem aaa authorization authz-policy version string
Treeversion
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
role rolename string
Description List of local roles configured on the system
Contextsystem aaa authorization role rolename string
Treerole
ConfigurableTrue
PlatformsSupported on all platforms
rolename string
Description Assigned rolename for this role
Context system aaa authorization role rolename string
String Length1 to 255
ConfigurableTrue
PlatformsSupported on all platforms
cli
Description Top-level container for cli plugin configuration
Contextsystem aaa authorization role rolename string cli
Treecli
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
allow-command-list string
Description

List of cli commands that are allowed for this role

Python style regular expressions are supported. Every item is left anchored (it matches from the beginning of line). Empty allow-command-list means anything that is not in deny-command-list is allowed. If both lists are empty then everything is allowed.

Contextsystem aaa authorization role rolename string cli allow-command-list string
Treeallow-command-list
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
Max. Elements100
deny-command-list string
Description

List of cli commands that are denied for this role

Python style regular expressions are supported. Every item is left anchored (it matches from the beginning of line). Empty deny-command-list means anything that is not in allow-command-list is denied. If both lists are empty then everything is allowed.

Contextsystem aaa authorization role rolename string cli deny-command-list string
Treedeny-command-list
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
Max. Elements100
load-global-plugins boolean
Description Specifies whether cli should load plugins from global plugin directory (from /etc/opt/srlinux/cli/plugins/).
Contextsystem aaa authorization role rolename string cli load-global-plugins boolean
Treeload-global-plugins
Defaulttrue
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
load-user-plugins boolean
Description Specifies whether cli should load plugins from user home directory (from ~/cli/plugins/).
Contextsystem aaa authorization role rolename string cli load-user-plugins boolean
Treeload-user-plugins
Defaulttrue
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
services keyword
Description

Services that members of this role are authorized for

Services are additive, if a user is a member of multiple roles, the available services are merged.

Contextsystem aaa authorization role rolename string services keyword
Treeservices
Options
  • cli

  • gnmi

  • gnoi

  • gnsi

  • gribi

  • netconf

  • p4rt

  • json-rpc

  • ftp

  • grpc-reflection

ConfigurableTrue
PlatformsSupported on all platforms
superuser boolean
Description

Indicates if users with this role are given superuser

A superuser is granted implicit authorization to all YANG paths, has the ability to execute all CLI plugins, and by default is permitted to access the device through any interface.

Additionally, users with the superuser attribute are able to execute 'sudo' in bash. A user may also be assigned a role or list of roles, but these are only evaluated for service authorization.

Contextsystem aaa authorization role rolename string superuser boolean
Treesuperuser
Defaultfalse
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
tacacs
Description Top-level container for configuration relating to TACACS+ interworking with roles
Contextsystem aaa authorization role rolename string tacacs
Treetacacs
ConfigurableTrue
PlatformsSupported on all platforms
priv-lvl number
Description

The TACACS+ priv-lvl to map to this role

All roles matching each specific priv-lvl, and their lessers are merged together to create the final ruleset applied to the user.

Contextsystem aaa authorization role rolename string tacacs priv-lvl number
Treepriv-lvl
Range0 to 15
ConfigurableTrue
PlatformsSupported on all platforms

server-group name string

Description

List of AAA server-groups in the system

Each server group specifies a type, of which all servers must use. If using the 'local' type, then no servers may be specified.

Contextsystem aaa server-group name string
Treeserver-group
ConfigurableTrue
PlatformsSupported on all platforms
Max. Elements3
name string
Description User defined name for the server group
Contextsystem aaa server-group name string
String Length1 to 255
ConfigurableTrue
PlatformsSupported on all platforms
priv-lvl-authorization boolean
Description

Use TACACS+ priv-lvl based authorization

If false, then authorization is skipped for TACACS+ users granting full admin access for those users.

Contextsystem aaa server-group name string priv-lvl-authorization boolean
Treepriv-lvl-authorization
Defaultfalse
ConfigurableTrue
PlatformsSupported on all platforms
server address (ipv4-address | ipv6-address)
Description

List of AAA servers to use within this server-group

Servers are tried in a round-robin fashion, with the first server always being tried if it is operationally available

Contextsystem aaa server-group name string server address (ipv4-address | ipv6-address)
Treeserver
ConfigurableTrue
PlatformsSupported on all platforms
Max. Elements5
address (ipv4-address | ipv6-address)
Description Address used to reach the server
Context system aaa server-group name string server address (ipv4-address | ipv6-address)
ConfigurableTrue
PlatformsSupported on all platforms
name string
Description User defined name assigned to the server
Contextsystem aaa server-group name string server address (ipv4-address | ipv6-address) name string
Treename
String Length1 to 255
ConfigurableTrue
PlatformsSupported on all platforms
network-instance reference
Description

Reference to a configured network-instance used for reachability to the server

This network-instance must already exist in the system, and different servers within the same server-group may use difference network-instances for connectivity.

Contextsystem aaa server-group name string server address (ipv4-address | ipv6-address) network-instance reference
Treenetwork-instance
Referencenetwork-instance name string
ConfigurableTrue
PlatformsSupported on all platforms
oper-state keyword
Description

Details the operational state of the server

A server is defined as being down if it fails to respond before the timeout period, or if a path towards the server is not available.

Contextsystem aaa server-group name string server address (ipv4-address | ipv6-address) oper-state keyword
Treeoper-state
Options
  • up

    Component or process is operational

  • down

    Component or process is not operational

  • empty

    Component slot is empty

  • downloading

    Component is downloading image into memory

  • booting

    Component is booting downloaded image

  • starting

    Component image operational, application processes starting

  • failed

    Component or process has failed

  • synchronizing

    Component is currently being synchronized

  • upgrading

    Component is currently being upgraded

  • low-power

    Component is offline due to insufficient system power

  • degraded

    Component or process is in a degraded state

  • warm-reboot

    Component or process is currently warm rebooting

    This state is set during a warm reboot immediately following initiation of the reboot, continuing after startup until the system has completed audit. In this state the system will not accept configuration changes.

  • waiting

    Component or process is currently waiting

    This state can be set by event handler when the reinvoke-with-delay action is used, and indicates that the event handler is waiting for the provided delay before reinvoking the instance.

ConfigurableFalse
PlatformsSupported on all platforms
radius
Description Top-level container for RADIUS server data
Contextsystem aaa server-group name string server address (ipv4-address | ipv6-address) radius
Treeradius
ConfigurableTrue
PlatformsSupported on all platforms
statistics
Description Enclosing container for server statistics
Contextsystem aaa server-group name string server address (ipv4-address | ipv6-address) statistics
Treestatistics
ConfigurableFalse
PlatformsSupported on all platforms
tacacs
Description Top-level container for TACACS+ server data
Contextsystem aaa server-group name string server address (ipv4-address | ipv6-address) tacacs
Treetacacs
ConfigurableTrue
PlatformsSupported on all platforms
port number
Description The port number on which to contact the TACACS+ server
Contextsystem aaa server-group name string server address (ipv4-address | ipv6-address) tacacs port number
Treeport
Range0 to 65535
Default49
ConfigurableTrue
PlatformsSupported on all platforms
timeout number
Description Set the timeout in seconds on responses from servers in this group
Contextsystem aaa server-group name string timeout number
Treetimeout
Range1 to 3600
Default10
Unitsseconds
Configurable True
PlatformsSupported on all platforms
type identityref
Description AAA server type -- all servers in the group must be of this type
Contextsystem aaa server-group name string type identityref
Treetype
Options
  • tacacs

    Specifies servers using the TACACS+ protocol

    Terminal Access Controller Access Control System (TACACS+)

  • radius

    Specifies servers using RADIUS protocol

    Remote Authentication Dial In User Service (RADIUS) AAA server

  • local

    Specifies using Linux local methods

    This type cannot be combined with a server address

ConfigurableTrue
PlatformsSupported on all platforms

app-management

Description Top-level container for application configuration and state
Contextsystem app-management
Treeapp-management
ConfigurableFalse
PlatformsSupported on all platforms

application name string

Description List of all applications managed by the application manager
Contextsystem app-management application name string
Treeapplication
ConfigurableFalse
PlatformsSupported on all platforms
failure-action string
Description

The action taken after 'failure-threshold' failures within 'failure-window'

This action can be to reboot the system, wait forever, or wait for a predefined number of seconds

Contextsystem app-management application name string failure-action string
Treefailure-action
ConfigurableFalse
PlatformsSupported on all platforms
failure-threshold number
Description

How many restarts within 'failure-window' are required to trigger the failure action

Setting this value to 0 will result in no action taking place on application restarts

Contextsystem app-management application name string failure-threshold number
Treefailure-threshold
Range0 to 255
ConfigurableFalse
PlatformsSupported on all platforms
last-start-type keyword
Description Indicates the type of the most recent start or restart of this application instance
Contextsystem app-management application name string last-start-type keyword
Treelast-start-type
Options
  • warm

    A warm start indicates that the application will leave state in IDB during a restart, and recover it post restart

    This type results in less disruption to surrounding applications and functionality.

  • cold

    A cold start indicates that the application will not leave state in IDB during a restart

    This type is equivalent to a normal application restart, i.e. one where the application's state is purged from the system during the restart, and recreated after.

ConfigurableFalse
PlatformsSupported on all platforms
restricted-operations keyword
Description The operations that may not be manually performed on this application
Contextsystem app-management application name string restricted-operations keyword
Treerestricted-operations
Options
  • restart

    This application may not be restarted manually

  • stop

    This application may not be stopped manually

  • start

    This application may not be started manually

  • reload

    This application may not be reloaded manually

  • quit

    This application may not be terminated manually

  • kill

    This application may not be terminated ungracefully manually

ConfigurableFalse
PlatformsSupported on all platforms
state keyword
Description Current state of this application instance
Contextsystem app-management application name string state keyword
Treestate
Options
  • running

    Application instance is running

    This is the normal, active state of an application

  • waiting-for-config

    Application instance is loaded, but has no configuration

    This state requires wait-for-config true within the applications YAML configuration. This results in the application being loaded into app-mgr, but not starting until the system receives configuration for it

  • error

    The application has not started successfully, or has failed

    This state can be caused by an application hitting the restart backoff, or an application failing to start following triggering a system reboot

  • starting

    The application has been asked to start

    All applications enter this state after initial execution, after which application manager will wait five seconds before checking their status. IDB connected applications may announce their state before this five second window has passed, resulting in them transitioning from this state faster than PID-monitored applications.

  • stopped

    The application is not running

    This state is most likely caused by an operator action

ConfigurableFalse
PlatformsSupported on all platforms
supported-restart-types keyword
Description Indicates the supported restart types for this application
Contextsystem app-management application name string supported-restart-types keyword
Treesupported-restart-types
Options
  • warm

    A warm start indicates that the application will leave state in IDB during a restart, and recover it post restart

    This type results in less disruption to surrounding applications and functionality.

  • cold

    A cold start indicates that the application will not leave state in IDB during a restart

    This type is equivalent to a normal application restart, i.e. one where the application's state is purged from the system during the restart, and recreated after.

ConfigurableFalse
PlatformsSupported on all platforms
yang
Description Top-level container for application state related to YANG
Contextsystem app-management application name string yang
Treeyang
ConfigurableFalse
PlatformsSupported on all platforms

authentication

Description Container for protocol authentication options available system wide
Contextsystem authentication
Treeauthentication
ConfigurableTrue
PlatformsSupported on all platforms

keychain name string

Description List of system keychains
Context system authentication keychain name string
Treekeychain
ConfigurableTrue
PlatformsSupported on all platforms
Max. Elements1024
name string
Description The user configured name for the keychain
Contextsystem authentication keychain name string
String Length1 to 255
ConfigurableTrue
PlatformsSupported on all platforms
admin-state keyword
Description

When set to disable, the keychain is inactive

When a protocol refers to a keychain that is inactive, no authentication data is added to the outbound messages and/or all inbound messages with authentication data are dropped, depending on the context.

A keychain is operationally disabled in a particular direction (send/receive) if:

Contextsystem authentication keychain name string admin-state keyword
Treeadmin-state
Defaultdisable
Options
  • enable

  • disable

Configurable True
PlatformsSupported on all platforms
expired boolean
Description

The value of this object indicates whether the keychain is expired

Expired can mean past end-time or prior to start-time.

Contextsystem authentication keychain name string expired boolean
Treeexpired
ConfigurableFalse
PlatformsSupported on all platforms
key index number
Description List of keys in the keychain
Context system authentication keychain name string key index number
Treekey
ConfigurableTrue
PlatformsSupported on all platforms
index number
Description Each key in a keychain requires a unique identifier, the index value specifies this identifier
Contextsystem authentication keychain name string key index number
ConfigurableTrue
PlatformsSupported on all platforms
algorithm keyword
Description The cryptographic algorithm used with the keying material to secure the messages
Contextsystem authentication keychain name string key index number algorithm keyword
Treealgorithm
Options
  • cleartext

    The authentication-key is encoded in plaintext

  • md5

    The authentication-key is used to generate an MD5 digest (RFC 1321)

  • hmac-md5

    The authentication-key is used to generate a 16-byte (128 bit) MD5 digest using the HMAC algorithm (RFC 2104)

  • hmac-sha-1

    The authentication-key is used to generate a SHA1 digest using the HMAC algorithm (RFC 2104)

  • hmac-sha-256

    The authentication-key is used to generate a SHA2 digest using the HMAC algorithm (RFC 2104)

    The SHA-256 variant of SHA2 produces an output of 32 bytes (256 bits)

  • aes-128-cmac

    The authentication-key is used with the AES-128 encryption algorithm to generate a cipher MAC (RFC 4493)

  • aes-256-cmac

    The authentication-key is used with the AES-256 encryption algorithm to generate a cipher MAC (RFC 4493).

ConfigurableTrue
PlatformsSupported on all platforms
type keyword
Description

Specifies the intended use of the keychain

The type constrains the set of crypto algorithms that are available to use with each key in the keychain. It is also used to ensure that this keychain is only used by protocols for which it is intended.

Contextsystem authentication keychain name string type keyword
Treetype
Options
  • tcp-md5

    Keychain intended to be used for TCP-MD5 authentication

  • isis

    Keychain intended to be used for authentication of IS-IS PDUs

  • ospf

    Keychain intended to be used for authentication of OSPFv2 messages

  • tcp-ao

    Keychain intended to be used for TCP-AO authentication

  • vrrp

    Keychain intended to be used for authentication of VRRPv2 messages

  • macsec

    Keychain intended to be used for key wrapping of SAK in a mka messages.

ConfigurableTrue
PlatformsSupported on all platforms
usable boolean
Description The value of this object indicates if the keychain is usable for authentication
Contextsystem authentication keychain name string usable boolean
Treeusable
ConfigurableFalse
PlatformsSupported on all platforms

banner

Description Contains configuration and state related to system banners
Contextsystem banner
Treebanner
ConfigurableTrue
PlatformsSupported on all platforms

login-banner string

Description Banner to display before a user has authenticated
Contextsystem banner login-banner string
Treelogin-banner
ConfigurableTrue
PlatformsSupported on all platforms

motd-banner string

Description Banner to display after a user has authenticated
Contextsystem banner motd-banner string
Treemotd-banner
ConfigurableTrue
PlatformsSupported on all platforms

boot

Description Top-level container for configuration and state data related to booting the system
Contextsystem boot
Treeboot
ConfigurableTrue
PlatformsSupported on all platforms

autoboot

Description Top-level container for configuration and state data related to autobooting the system
Contextsystem boot autoboot
Treeautoboot
ConfigurableTrue
PlatformsSupported on all platforms
admin-state keyword
Description Administratively enable or disable autoboot functionality
Contextsystem boot autoboot admin-state keyword
Treeadmin-state
Options
  • enable

  • disable

Configurable True
PlatformsSupported on all platforms
attempts number
Description Sets the amount of executions to try autoboot, before rebooting the system
Contextsystem boot autoboot attempts number
Treeattempts
Range1 to 10
ConfigurableTrue
PlatformsSupported on all platforms
client-id keyword
Description The client ID to use on outgoing DHCP requests
Contextsystem boot autoboot client-id keyword
Treeclient-id
Options
  • serial

    Use the chassis serial number as the client ID

ConfigurableTrue
PlatformsSupported on all platforms
mode string
Description Ztp operation modes. One or more modes can passed
Contextsystem boot autoboot mode string
Treemode
ConfigurableTrue
PlatformsSupported on all platforms
oper-state string
Description The current operational status of the autoboot process
Contextsystem boot autoboot oper-state string
Treeoper-state
ConfigurableFalse
PlatformsSupported on all platforms
timeout number
Description Sets the timeout for each attempt to autoboot
Contextsystem boot autoboot timeout number
Treetimeout
Range200 to 3600
Unitsseconds
ConfigurableTrue
PlatformsSupported on all platforms

golden-image string

Description

The local image the system reverts to when a factory reset operation is requested

The value is the folder that contains the initramfs, kernel, and squashfs image. The search path for these directories is /mnt/nokiaos/<folder>

Contextsystem boot golden-image string
Treegolden-image
String Length1 to 255
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

image string

Description

Ordered list of local images used to boot the system

This directly translates into boot configuration in grub, where the images are tried in the order specified by the user. Images are sourced via the internal SD card, and the value passed is the folder that contains the initramfs, kernel, and squashfs image. The search path for these directories is /mnt/nokiaos/<folder>

Contextsystem boot image string
Treeimage
String Length1 to 255
ConfigurableFalse
PlatformsSupported on all platforms
Max. Elements3

bridge-table

Description system bridge-table information
Context system bridge-table
Treebridge-table
ConfigurableTrue
PlatformsSupported on all platforms

mac-limit

Description Bridge Table size and thresholds.
Context system bridge-table mac-limit
Treemac-limit
ConfigurableTrue
PlatformsSupported on all platforms
warning-threshold-pct number
Description Percentage of the configured max-number-macs over which a warning is triggered. The warning message is cleared when the percentage drops below the configured percentage minus 5%
Contextsystem bridge-table mac-limit warning-threshold-pct number
Treewarning-threshold-pct
ConfigurableFalse
PlatformsSupported on all platforms

proxy-arp

Description system bridge-table proxy ARP entry information
Contextsystem bridge-table proxy-arp
Treeproxy-arp
ConfigurableFalse
PlatformsSupported on all platforms
statistics
Description Enter the statistics context
Context system bridge-table proxy-arp statistics
Treestatistics
ConfigurableFalse
PlatformsSupported on all platforms
neighbor-origin origin keyword
Description the origin of the proxy entry installed in the table.
Contextsystem bridge-table proxy-arp statistics neighbor-origin origin keyword
Treeneighbor-origin
ConfigurableFalse
PlatformsSupported on all platforms

proxy-nd

Description system bridge-table proxy ND entry information
Contextsystem bridge-table proxy-nd
Treeproxy-nd
ConfigurableFalse
PlatformsSupported on all platforms
statistics
Description Enter the statistics context
Context system bridge-table proxy-nd statistics
Treestatistics
ConfigurableFalse
PlatformsSupported on all platforms
neighbor-origin origin keyword
Description the origin of the proxy entry installed in the table.
Contextsystem bridge-table proxy-nd statistics neighbor-origin origin keyword
Treeneighbor-origin
ConfigurableFalse
PlatformsSupported on all platforms

statistics

Description Enter the statistics context
Context system bridge-table statistics
Treestatistics
ConfigurableFalse
PlatformsSupported on all platforms
mac-type type keyword
Description the type of the mac in the system.
Context system bridge-table statistics mac-type type keyword
Treemac-type
ConfigurableFalse
PlatformsSupported on all platforms
type keyword
Description Enter the type context
Context system bridge-table statistics mac-type type keyword
Options
  • static

  • duplicate

  • learnt

  • irb-interface

  • evpn

  • evpn-static

  • irb-interface-anycast

  • proxy-anti-spoof

  • reserved

  • eth-cfm

ConfigurableFalse
PlatformsSupported on all platforms

clock

Description Top-level container for system clock configuration and state
Contextsystem clock
Treeclock
ConfigurableTrue
PlatformsSupported on all platforms

timezone keyword

Description The timezone to use for the system Based on IANAs Time Zone database
Contextsystem clock timezone keyword
Treetimezone
Options
  • Africa/Abidjan

  • Africa/Accra

  • Africa/Addis_Ababa

  • Africa/Algiers

  • Africa/Asmara

  • Africa/Bamako

  • Africa/Bangui

  • Africa/Banjul

  • Africa/Bissau

  • Africa/Blantyre

  • Africa/Brazzaville

  • Africa/Bujumbura

  • Africa/Cairo

  • Africa/Casablanca

  • Africa/Ceuta

    Ceuta, Melilla

  • Africa/Conakry

  • Africa/Dakar

  • Africa/Dar_es_Salaam

  • Africa/Djibouti

  • Africa/Douala

  • Africa/El_Aaiun

  • Africa/Freetown

  • Africa/Gaborone

  • Africa/Harare

  • Africa/Johannesburg

  • Africa/Juba

  • Africa/Kampala

  • Africa/Khartoum

  • Africa/Kigali

  • Africa/Kinshasa

    Dem. Rep. of Congo (west)

  • Africa/Lagos

  • Africa/Libreville

  • Africa/Lome

  • Africa/Luanda

  • Africa/Lubumbashi

    Dem. Rep. of Congo (east)

  • Africa/Lusaka

  • Africa/Malabo

  • Africa/Maputo

  • Africa/Maseru

  • Africa/Mbabane

  • Africa/Mogadishu

  • Africa/Monrovia

  • Africa/Nairobi

  • Africa/Ndjamena

  • Africa/Niamey

  • Africa/Nouakchott

  • Africa/Ouagadougou

  • Africa/Porto-Novo

  • Africa/Sao_Tome

  • Africa/Tripoli

  • Africa/Tunis

  • Africa/Windhoek

  • America/Adak

    Aleutian Islands

  • America/Anchorage

    Alaska (most areas)

  • America/Anguilla

  • America/Antigua

  • America/Araguaina

    Tocantins

  • America/Argentina/Buenos_Aires

    Buenos Aires (BA, CF)

  • America/Argentina/Catamarca

    Catamarca (CT); Chubut (CH)

  • America/Argentina/Cordoba

    Argentina (most areas: CB, CC, CN, ER, FM, MN, SE, SF)

  • America/Argentina/Jujuy

    Jujuy (JY)

  • America/Argentina/La_Rioja

    La Rioja (LR)

  • America/Argentina/Mendoza

    Mendoza (MZ)

  • America/Argentina/Rio_Gallegos

    Santa Cruz (SC)

  • America/Argentina/Salta

    Salta (SA, LP, NQ, RN)

  • America/Argentina/San_Juan

    San Juan (SJ)

  • America/Argentina/San_Luis

    San Luis (SL)

  • America/Argentina/Tucuman

    Tucuman (TM)

  • America/Argentina/Ushuaia

    Tierra del Fuego (TF)

  • America/Aruba

  • America/Asuncion

  • America/Atikokan

    EST - ON (Atikokan); NU (Coral H)

  • America/Bahia

    Bahia

  • America/Bahia_Banderas

    Central Time - Bahia de Banderas

  • America/Barbados

  • America/Belem

    Para (east); Amapa

  • America/Belize

  • America/Blanc-Sablon

    AST - QC (Lower North Shore)

  • America/Boa_Vista

    Roraima

  • America/Bogota

  • America/Boise

    Mountain - ID (south); OR (east)

  • America/Cambridge_Bay

    Mountain - NU (west)

  • America/Campo_Grande

    Mato Grosso do Sul

  • America/Cancun

    Eastern Standard Time - Quintana Roo

  • America/Caracas

  • America/Cayenne

  • America/Cayman

  • America/Chicago

    Central (most areas)

  • America/Chihuahua

    Mountain Time - Chihuahua (most areas)

  • America/Costa_Rica

  • America/Creston

    MST - BC (Creston)

  • America/Cuiaba

    Mato Grosso

  • America/Curacao

  • America/Danmarkshavn

    National Park (east coast)

  • America/Dawson

    Pacific - Yukon (north)

  • America/Dawson_Creek

    MST - BC (Dawson Cr, Ft St John)

  • America/Denver

    Mountain (most areas)

  • America/Detroit

    Eastern - MI (most areas)

  • America/Dominica

  • America/Edmonton

    Mountain - AB; BC (E); SK (W)

  • America/Eirunepe

    Amazonas (west)

  • America/El_Salvador

  • America/Fort_Nelson

    MST - BC (Ft Nelson)

  • America/Fortaleza

    Brazil (northeast: MA, PI, CE, RN, PB)

  • America/Glace_Bay

    Atlantic - NS (Cape Breton)

  • America/Godthab

    Greenland (most areas)

  • America/Goose_Bay

    Atlantic - Labrador (most areas)

  • America/Grand_Turk

  • America/Grenada

  • America/Guadeloupe

  • America/Guatemala

  • America/Guayaquil

    Ecuador (mainland)

  • America/Guyana

  • America/Halifax

    Atlantic - NS (most areas); PE

  • America/Havana

  • America/Hermosillo

    Mountain Standard Time - Sonora

  • America/Indiana/Indianapolis

    Eastern - IN (most areas)

  • America/Indiana/Knox

    Central - IN (Starke)

  • America/Indiana/Marengo

    Eastern - IN (Crawford)

  • America/Indiana/Petersburg

    Eastern - IN (Pike)

  • America/Indiana/Tell_City

    Central - IN (Perry)

  • America/Indiana/Vevay

    Eastern - IN (Switzerland)

  • America/Indiana/Vincennes

    Eastern - IN (Da, Du, K, Mn)

  • America/Indiana/Winamac

    Eastern - IN (Pulaski)

  • America/Inuvik

    Mountain - NT (west)

  • America/Iqaluit

    Eastern - NU (most east areas)

  • America/Jamaica

  • America/Juneau

    Alaska - Juneau area

  • America/Kentucky/Louisville

    Eastern - KY (Louisville area)

  • America/Kentucky/Monticello

    Eastern - KY (Wayne)

  • America/Kralendijk

  • America/La_Paz

  • America/Lima

  • America/Los_Angeles

    Pacific

  • America/Lower_Princes

  • America/Maceio

    Alagoas, Sergipe

  • America/Managua

  • America/Manaus

    Amazonas (east)

  • America/Marigot

  • America/Martinique

  • America/Matamoros

    Central Time US - Coahuila, Nuevo Leon, Tamaulipas (US border)

  • America/Mazatlan

    Mountain Time - Baja California Sur, Nayarit, Sinaloa

  • America/Menominee

    Central - MI (Wisconsin border)

  • America/Merida

    Central Time - Campeche, Yucatan

  • America/Metlakatla

    Alaska - Annette Island

  • America/Mexico_City

    Central Time

  • America/Miquelon

  • America/Moncton

    Atlantic - New Brunswick

  • America/Monterrey

    Central Time - Durango; Coahuila, Nuevo Leon, Tamaulipas (most areas)

  • America/Montevideo

  • America/Montserrat

  • America/Nassau

  • America/New_York

    Eastern (most areas)

  • America/Nipigon

    Eastern - ON, QC (no DST 1967-73)

  • America/Nome

    Alaska (west)

  • America/Noronha

    Atlantic islands

  • America/North_Dakota/Beulah

    Central - ND (Mercer)

  • America/North_Dakota/Center

    Central - ND (Oliver)

  • America/North_Dakota/New_Salem

    Central - ND (Morton rural)

  • America/Ojinaga

    Mountain Time US - Chihuahua (US border)

  • America/Panama

  • America/Pangnirtung

    Eastern - NU (Pangnirtung)

  • America/Paramaribo

  • America/Phoenix

    MST - Arizona (except Navajo)

  • America/Port-au-Prince

  • America/Port_of_Spain

  • America/Porto_Velho

    Rondonia

  • America/Puerto_Rico

  • America/Punta_Arenas

    Region of Magallanes

  • America/Rainy_River

    Central - ON (Rainy R, Ft Frances)

  • America/Rankin_Inlet

    Central - NU (central)

  • America/Recife

    Pernambuco

  • America/Regina

    CST - SK (most areas)

  • America/Resolute

    Central - NU (Resolute)

  • America/Rio_Branco

    Acre

  • America/Santarem

    Para (west)

  • America/Santiago

    Chile (most areas)

  • America/Santo_Domingo

  • America/Sao_Paulo

    Brazil (southeast: GO, DF, MG, ES, RJ, SP, PR, SC, RS)

  • America/Scoresbysund

    Scoresbysund/Ittoqqortoormiit

  • America/Sitka

    Alaska - Sitka area

  • America/St_Barthelemy

  • America/St_Johns

    Newfoundland; Labrador (southeast)

  • America/St_Kitts

  • America/St_Lucia

  • America/St_Thomas

  • America/St_Vincent

  • America/Swift_Current

    CST - SK (midwest)

  • America/Tegucigalpa

  • America/Thule

    Thule/Pituffik

  • America/Thunder_Bay

    Eastern - ON (Thunder Bay)

  • America/Tijuana

    Pacific Time US - Baja California

  • America/Toronto

    Eastern - ON, QC (most areas)

  • America/Tortola

  • America/Vancouver

    Pacific - BC (most areas)

  • America/Whitehorse

    Pacific - Yukon (south)

  • America/Winnipeg

    Central - ON (west); Manitoba

  • America/Yakutat

    Alaska - Yakutat

  • America/Yellowknife

    Mountain - NT (central)

  • Antarctica/Casey

    Casey

  • Antarctica/Davis

    Davis

  • Antarctica/DumontDUrville

    Dumont-d'Urville

  • Antarctica/Macquarie

    Macquarie Island

  • Antarctica/Mawson

    Mawson

  • Antarctica/McMurdo

    New Zealand time - McMurdo, South Pole

  • Antarctica/Palmer

    Palmer

  • Antarctica/Rothera

    Rothera

  • Antarctica/Syowa

    Syowa

  • Antarctica/Troll

    Troll

  • Antarctica/Vostok

    Vostok

  • Arctic/Longyearbyen

  • Asia/Aden

  • Asia/Almaty

    Kazakhstan (most areas)

  • Asia/Amman

  • Asia/Anadyr

    MSK+09 - Bering Sea

  • Asia/Aqtau

    Mangghystau/Mankistau

  • Asia/Aqtobe

    Aqtobe/Aktobe

  • Asia/Ashgabat

  • Asia/Atyrau

    Atyrau/Atirau/Gur'yev

  • Asia/Baghdad

  • Asia/Bahrain

  • Asia/Baku

  • Asia/Bangkok

  • Asia/Barnaul

    MSK+04 - Altai

  • Asia/Beirut

  • Asia/Bishkek

  • Asia/Brunei

  • Asia/Chita

    MSK+06 - Zabaykalsky

  • Asia/Choibalsan

    Dornod, Sukhbaatar

  • Asia/Colombo

  • Asia/Damascus

  • Asia/Dhaka

  • Asia/Dili

  • Asia/Dubai

  • Asia/Dushanbe

  • Asia/Famagusta

    Northern Cyprus

  • Asia/Gaza

    Gaza Strip

  • Asia/Hebron

    West Bank

  • Asia/Ho_Chi_Minh

  • Asia/Hong_Kong

  • Asia/Hovd

    Bayan-Olgiy, Govi-Altai, Hovd, Uvs, Zavkhan

  • Asia/Irkutsk

    MSK+05 - Irkutsk, Buryatia

  • Asia/Jakarta

    Java, Sumatra

  • Asia/Jayapura

    New Guinea (West Papua / Irian Jaya); Malukus/Moluccas

  • Asia/Jerusalem

  • Asia/Kabul

  • Asia/Kamchatka

    MSK+09 - Kamchatka

  • Asia/Karachi

  • Asia/Kathmandu

  • Asia/Khandyga

    MSK+06 - Tomponsky, Ust-Maysky

  • Asia/Kolkata

  • Asia/Krasnoyarsk

    MSK+04 - Krasnoyarsk area

  • Asia/Kuala_Lumpur

    Malaysia (peninsula)

  • Asia/Kuching

    Sabah, Sarawak

  • Asia/Kuwait

  • Asia/Macau

  • Asia/Magadan

    MSK+08 - Magadan

  • Asia/Makassar

    Borneo (east, south); Sulawesi/Celebes, Bali, Nusa Tengarra; Timor (west)

  • Asia/Manila

  • Asia/Muscat

  • Asia/Nicosia

    Cyprus (most areas)

  • Asia/Novokuznetsk

    MSK+04 - Kemerovo

  • Asia/Novosibirsk

    MSK+04 - Novosibirsk

  • Asia/Omsk

    MSK+03 - Omsk

  • Asia/Oral

    West Kazakhstan

  • Asia/Phnom_Penh

  • Asia/Pontianak

    Borneo (west, central)

  • Asia/Pyongyang

  • Asia/Qatar

  • Asia/Qostanay

    Qostanay/Kostanay/Kustanay

  • Asia/Qyzylorda

    Qyzylorda/Kyzylorda/Kzyl-Orda

  • Asia/Riyadh

  • Asia/Sakhalin

    MSK+08 - Sakhalin Island

  • Asia/Samarkand

    Uzbekistan (west)

  • Asia/Seoul

  • Asia/Shanghai

    Beijing Time

  • Asia/Singapore

  • Asia/Srednekolymsk

    MSK+08 - Sakha (E); North Kuril Is

  • Asia/Taipei

  • Asia/Tashkent

    Uzbekistan (east)

  • Asia/Tbilisi

  • Asia/Tehran

  • Asia/Thimphu

  • Asia/Tokyo

  • Asia/Tomsk

    MSK+04 - Tomsk

  • Asia/Ulaanbaatar

    Mongolia (most areas)

  • Asia/Urumqi

    Xinjiang Time

  • Asia/Ust-Nera

    MSK+07 - Oymyakonsky

  • Asia/Vientiane

  • Asia/Vladivostok

    MSK+07 - Amur River

  • Asia/Yakutsk

    MSK+06 - Lena River

  • Asia/Yangon

  • Asia/Yekaterinburg

    MSK+02 - Urals

  • Asia/Yerevan

  • Atlantic/Azores

    Azores

  • Atlantic/Bermuda

  • Atlantic/Canary

    Canary Islands

  • Atlantic/Cape_Verde

  • Atlantic/Faroe

  • Atlantic/Madeira

    Madeira Islands

  • Atlantic/Reykjavik

  • Atlantic/South_Georgia

  • Atlantic/St_Helena

  • Atlantic/Stanley

  • Australia/Adelaide

    South Australia

  • Australia/Brisbane

    Queensland (most areas)

  • Australia/Broken_Hill

    New South Wales (Yancowinna)

  • Australia/Currie

    Tasmania (King Island)

  • Australia/Darwin

    Northern Territory

  • Australia/Eucla

    Western Australia (Eucla)

  • Australia/Hobart

    Tasmania (most areas)

  • Australia/Lindeman

    Queensland (Whitsunday Islands)

  • Australia/Lord_Howe

    Lord Howe Island

  • Australia/Melbourne

    Victoria

  • Australia/Perth

    Western Australia (most areas)

  • Australia/Sydney

    New South Wales (most areas)

  • Europe/Amsterdam

  • Europe/Andorra

  • Europe/Astrakhan

    MSK+01 - Astrakhan

  • Europe/Athens

  • Europe/Belgrade

  • Europe/Berlin

    Germany (most areas)

  • Europe/Bratislava

  • Europe/Brussels

  • Europe/Bucharest

  • Europe/Budapest

  • Europe/Busingen

    Busingen

  • Europe/Chisinau

  • Europe/Copenhagen

  • Europe/Dublin

  • Europe/Gibraltar

  • Europe/Guernsey

  • Europe/Helsinki

  • Europe/Isle_of_Man

  • Europe/Istanbul

  • Europe/Jersey

  • Europe/Kaliningrad

    MSK-01 - Kaliningrad

  • Europe/Kiev

    Ukraine (most areas)

  • Europe/Kirov

    MSK+00 - Kirov

  • Europe/Lisbon

    Portugal (mainland)

  • Europe/Ljubljana

  • Europe/London

  • Europe/Luxembourg

  • Europe/Madrid

    Spain (mainland)

  • Europe/Malta

  • Europe/Mariehamn

  • Europe/Minsk

  • Europe/Monaco

  • Europe/Moscow

    MSK+00 - Moscow area

  • Europe/Oslo

  • Europe/Paris

  • Europe/Podgorica

  • Europe/Prague

  • Europe/Riga

  • Europe/Rome

  • Europe/Samara

    MSK+01 - Samara, Udmurtia

  • Europe/San_Marino

  • Europe/Sarajevo

  • Europe/Saratov

    MSK+01 - Saratov

  • Europe/Simferopol

    MSK+00 - Crimea

  • Europe/Skopje

  • Europe/Sofia

  • Europe/Stockholm

  • Europe/Tallinn

  • Europe/Tirane

  • Europe/Ulyanovsk

    MSK+01 - Ulyanovsk

  • Europe/Uzhgorod

    Ruthenia

  • Europe/Vaduz

  • Europe/Vatican

  • Europe/Vienna

  • Europe/Vilnius

  • Europe/Volgograd

    MSK+01 - Volgograd

  • Europe/Warsaw

  • Europe/Zagreb

  • Europe/Zaporozhye

    Zaporozh'ye/Zaporizhia; Lugansk/Luhansk (east)

  • Europe/Zurich

  • Indian/Antananarivo

  • Indian/Chagos

  • Indian/Christmas

  • Indian/Cocos

  • Indian/Comoro

  • Indian/Kerguelen

  • Indian/Mahe

  • Indian/Maldives

  • Indian/Mauritius

  • Indian/Mayotte

  • Indian/Reunion

  • Pacific/Apia

  • Pacific/Auckland

    New Zealand (most areas)

  • Pacific/Bougainville

    Bougainville

  • Pacific/Chatham

    Chatham Islands

  • Pacific/Chuuk

    Chuuk/Truk, Yap

  • Pacific/Easter

    Easter Island

  • Pacific/Efate

  • Pacific/Enderbury

    Phoenix Islands

  • Pacific/Fakaofo

  • Pacific/Fiji

  • Pacific/Funafuti

  • Pacific/Galapagos

    Galapagos Islands

  • Pacific/Gambier

    Gambier Islands

  • Pacific/Guadalcanal

  • Pacific/Guam

  • Pacific/Honolulu

    Hawaii

  • Pacific/Kiritimati

    Line Islands

  • Pacific/Kosrae

    Kosrae

  • Pacific/Kwajalein

    Kwajalein

  • Pacific/Majuro

    Marshall Islands (most areas)

  • Pacific/Marquesas

    Marquesas Islands

  • Pacific/Midway

    Midway Islands

  • Pacific/Nauru

  • Pacific/Niue

  • Pacific/Norfolk

  • Pacific/Noumea

  • Pacific/Pago_Pago

  • Pacific/Palau

  • Pacific/Pitcairn

  • Pacific/Pohnpei

    Pohnpei/Ponape

  • Pacific/Port_Moresby

    Papua New Guinea (most areas)

  • Pacific/Rarotonga

  • Pacific/Saipan

  • Pacific/Tahiti

    Society Islands

  • Pacific/Tarawa

    Gilbert Islands

  • Pacific/Tongatapu

  • Pacific/Wake

    Wake Island

  • Pacific/Wallis

  • UTC

ConfigurableTrue
PlatformsSupported on all platforms

configuration

Description Top-level container for configuration and state data related to the system configuration
Contextsystem configuration
Treeconfiguration
ConfigurableTrue
PlatformsSupported on all platforms

auto-checkpoint boolean

Description Configuration checkpoint will be automatically created after every successful commit (if set to true).
Contextsystem configuration auto-checkpoint boolean
Treeauto-checkpoint
Defaultfalse
ConfigurableTrue
PlatformsSupported on all platforms

candidate name string

Description List of configuration candidates currently active
Contextsystem configuration candidate name string
Treecandidate
ConfigurableFalse
PlatformsSupported on all platforms
name string
Description Name of the configuration candidate
Context system configuration candidate name string
String Length1 to 255
ConfigurableFalse
PlatformsSupported on all platforms
type keyword
Description Type of configuration candidate
Context system configuration candidate name string type keyword
Treetype
Options
  • shared

  • private

Configurable False
PlatformsSupported on all platforms

checkpoint id number

Description List of current checkpoints present in the system
Contextsystem configuration checkpoint id number
Treecheckpoint
ConfigurableFalse
PlatformsSupported on all platforms
id number
Description System generated ID for the checkpoint
Contextsystem configuration checkpoint id number
ConfigurableFalse
PlatformsSupported on all platforms
size number
Description Size of the checkpoint configuration file
Contextsystem configuration checkpoint id number size number
Treesize
Unitsbytes
ConfigurableFalse
PlatformsSupported on all platforms
tag string
Description Full system version that the checkpoint was generated on
Contextsystem configuration checkpoint id number tag string
Treetag
ConfigurableFalse
PlatformsSupported on all platforms

commit id number

Description List of configuration transactions
Context system configuration commit id number
Treecommit
ConfigurableFalse
PlatformsSupported on all platforms
id number
Description System identifier for the commit
Context system configuration commit id number
ConfigurableFalse
PlatformsSupported on all platforms
comment string
Description Operator provided comment associated with this commit
Contextsystem configuration commit id number comment string
Treecomment
ConfigurableFalse
PlatformsSupported on all platforms
ended string
Description

End date and time of the commit

This field is not populated if the commit is in progress

Contextsystem configuration commit id number ended string
Treeended
String Length20 to 32
ConfigurableFalse
PlatformsSupported on all platforms
name string
Description Name of the configuration candidate the commit was triggered from
Contextsystem configuration commit id number name string
Treename
String Length1 to 255
ConfigurableFalse
PlatformsSupported on all platforms
started string
Description Start date and time of the commit
Context system configuration commit id number started string
Treestarted
String Length20 to 32
ConfigurableFalse
PlatformsSupported on all platforms
status keyword
Description Current status of the commit
Context system configuration commit id number status keyword
Treestatus
Options
  • validating

  • publishing

  • unconfirmed

  • checkpoint

  • save

  • complete

  • reverting

  • failed

Configurable False
PlatformsSupported on all platforms
type keyword
Description Type of configuration candidate the commit was triggered from
Contextsystem configuration commit id number type keyword
Treetype
Options
  • shared

  • private

Configurable False
PlatformsSupported on all platforms

idle-timeout number

Description

The idle timeout of configuration candidates

After this period of no activity, the candidate is emptied and removed from the system.

Contextsystem configuration idle-timeout number
Treeidle-timeout
Default10080
Unitsminutes
ConfigurableTrue
PlatformsSupported on all platforms

last-change string

Description

Date and time of the last successful commit

Set to the time the configuration was loaded by management server, so is refreshed at boot time.

Contextsystem configuration last-change string
Treelast-change
String Length20 to 32
ConfigurableFalse
PlatformsSupported on all platforms

max-candidates number

Description The maximum number of combined private and shared candidates
Contextsystem configuration max-candidates number
Treemax-candidates
Range1 to 255
Default10
ConfigurableTrue
PlatformsSupported on all platforms

role name reference

Description List of roles configured in the system
Contextsystem configuration role name reference
Treerole
ConfigurableTrue
PlatformsSupported on all platforms
Max. Elements32
rule path-reference string
Description List of paths to perform access control against
Contextsystem configuration role name reference rule path-reference string
Treerule
ConfigurableTrue
PlatformsSupported on all platforms
Max. Elements256
path-reference string
Description

Reference to a valid YANG path, in CLI notation

This path may include keys, wildcards, ranges, and other management server supported constructs. Ranges will be expanded. The root path can be specified with '/'.

E.g. / "/interface" "/acl ipv4-filter foo* description"

Contextsystem configuration role name reference rule path-reference string
ConfigurableTrue
PlatformsSupported on all platforms
action keyword
Description Action to allow for this path
Context system configuration role name reference rule path-reference string action keyword
Treeaction
Options
  • read

    This path may be read by the role

  • write

    This path may be written and read by the role

  • deny

    This path may not be read or written to by the role

ConfigurableTrue
PlatformsSupported on all platforms

session id number

Description List of configuration sessions currently active
Contextsystem configuration session id number
Treesession
ConfigurableFalse
PlatformsSupported on all platforms
id number
Description System generated ID for the configuration session
Contextsystem configuration session id number
ConfigurableFalse
PlatformsSupported on all platforms
name string
Description

Name of the candidate the session is active on

Set to 'default' if a non-named candidate is active

Contextsystem configuration session id number name string
Treename
String Length1 to 255
ConfigurableFalse
PlatformsSupported on all platforms
started string
Description Start date and time of the configuration session
Contextsystem configuration session id number started string
Treestarted
String Length20 to 32
ConfigurableFalse
PlatformsSupported on all platforms
type keyword
Description Type of configuration session
Context system configuration session id number type keyword
Treetype
Options
  • shared

  • private

Configurable False
PlatformsSupported on all platforms
username string
Description User that started the configuration session
Contextsystem configuration session id number username string
Treeusername
String Length1 to 255
ConfigurableFalse
PlatformsSupported on all platforms

control-plane-traffic

Description Container for the control plane traffic.
Contextsystem control-plane-traffic
Treecontrol-plane-traffic
ConfigurableTrue
PlatformsSupported on all platforms

input

Description Defines parameters determining the handling of system generated traffic.
Contextsystem control-plane-traffic input
Treeinput
ConfigurableTrue
PlatformsSupported on all platforms
acl
Description Container for ACL.
Context system control-plane-traffic input acl
Treeacl
ConfigurableTrue
PlatformsSupported on all platforms
acl-filter name reference type reference
Description List MAC, IPv4, IPv6 ACL filter(s) to be applied on this subinterface direction
Contextsystem control-plane-traffic input acl acl-filter name reference type reference
Treeacl-filter
ConfigurableTrue
PlatformsSupported on all platforms

output

Description Defines parameters determining the handling of system generated traffic.
Contextsystem control-plane-traffic output
Treeoutput
ConfigurableTrue
PlatformsSupported on all platforms
qos
Description Parameters describing QoS handling of system generated traffic
Contextsystem control-plane-traffic output qos
Treeqos
ConfigurableTrue
PlatformsSupported on all platforms
management-protocols-dscp (number | keyword)
Description Defines dscp value the system generated traffic by management-protocols should be marked with
Contextsystem control-plane-traffic output qos management-protocols-dscp (number | keyword)
Treemanagement-protocols-dscp
Range0 to 63
Default32
Options
  • CS0

  • LE

  • CS1

  • AF11

  • AF12

  • AF13

  • CS2

  • AF21

  • AF22

  • AF23

  • CS3

  • AF31

  • AF32

  • AF33

  • CS4

  • AF41

  • AF42

  • AF43

  • CS5

  • EF

  • CS6

  • CS7

ConfigurableTrue
PlatformsSupported on all platforms

dhcp-server

Description Configures the dhcp server
Context system dhcp-server
Treedhcp-server
ConfigurableTrue
PlatformsSupported on all platforms

admin-state keyword

Description Globally enable or disable the dhcp server Disabling this will disable all dhcp servers.
Contextsystem dhcp-server admin-state keyword
Treeadmin-state
Defaultdisable
Options
  • enable

  • disable

Configurable True
PlatformsSupported on all platforms

network-instance name reference

Description List of network instances to run a dhcp server in
Contextsystem dhcp-server network-instance name reference
Treenetwork-instance
ConfigurableTrue
PlatformsSupported on all platforms
dhcpv4
Description Enter the dhcpv4 context
Context system dhcp-server network-instance name reference dhcpv4
Treedhcpv4
ConfigurableTrue
PlatformsSupported on all platforms
oper-state keyword
Description Details if the dhcp server is operationally available
Contextsystem dhcp-server network-instance name reference dhcpv4 oper-state keyword
Treeoper-state
Options
  • up

    Component or process is operational

  • down

    Component or process is not operational

  • empty

    Component slot is empty

  • downloading

    Component is downloading image into memory

  • booting

    Component is booting downloaded image

  • starting

    Component image operational, application processes starting

  • failed

    Component or process has failed

  • synchronizing

    Component is currently being synchronized

  • upgrading

    Component is currently being upgraded

  • low-power

    Component is offline due to insufficient system power

  • degraded

    Component or process is in a degraded state

  • warm-reboot

    Component or process is currently warm rebooting

    This state is set during a warm reboot immediately following initiation of the reboot, continuing after startup until the system has completed audit. In this state the system will not accept configuration changes.

  • waiting

    Component or process is currently waiting

    This state can be set by event handler when the reinvoke-with-delay action is used, and indicates that the event handler is waiting for the provided delay before reinvoking the instance.

ConfigurableFalse
PlatformsSupported on all platforms
options
Description Enter the options context
Context system dhcp-server network-instance name reference dhcpv4 options
Treeoptions
ConfigurableTrue
PlatformsSupported on all platforms
server-id string
Description IP address the dhcp server must match any address within the network_instance e.g. sub-interface primary address, loopback address, anycast gateway address in case of multihoming - option 54
Contextsystem dhcp-server network-instance name reference dhcpv4 options server-id string
Treeserver-id
ConfigurableTrue
PlatformsSupported on all platforms
static-allocation
Description Enter the static-allocation context
Context system dhcp-server network-instance name reference dhcpv4 static-allocation
Treestatic-allocation
ConfigurableTrue
PlatformsSupported on all platforms
host mac string
Description host name for static ip allocations
Context system dhcp-server network-instance name reference dhcpv4 static-allocation host mac string
Treehost
ConfigurableTrue
PlatformsSupported on all platforms
options
Description Enter the options context
Context system dhcp-server network-instance name reference dhcpv4 static-allocation host mac string options
Treeoptions
ConfigurableTrue
PlatformsSupported on all platforms
statistics
Description Enter the statistics context
Context system dhcp-server network-instance name reference dhcpv4 statistics
Treestatistics
ConfigurableFalse
PlatformsSupported on all platforms
trace-options
Description Container for tracing DHCP server operations instance
Contextsystem dhcp-server network-instance name reference dhcpv4 trace-options
Treetrace-options
ConfigurableTrue
PlatformsSupported on all platforms
dhcpv6
Description Enter the dhcpv6 context
Context system dhcp-server network-instance name reference dhcpv6
Treedhcpv6
ConfigurableTrue
PlatformsSupported on all platforms
oper-state keyword
Description Details if the dhcp server is operationally available
Contextsystem dhcp-server network-instance name reference dhcpv6 oper-state keyword
Treeoper-state
Options
  • up

    Component or process is operational

  • down

    Component or process is not operational

  • empty

    Component slot is empty

  • downloading

    Component is downloading image into memory

  • booting

    Component is booting downloaded image

  • starting

    Component image operational, application processes starting

  • failed

    Component or process has failed

  • synchronizing

    Component is currently being synchronized

  • upgrading

    Component is currently being upgraded

  • low-power

    Component is offline due to insufficient system power

  • degraded

    Component or process is in a degraded state

  • warm-reboot

    Component or process is currently warm rebooting

    This state is set during a warm reboot immediately following initiation of the reboot, continuing after startup until the system has completed audit. In this state the system will not accept configuration changes.

  • waiting

    Component or process is currently waiting

    This state can be set by event handler when the reinvoke-with-delay action is used, and indicates that the event handler is waiting for the provided delay before reinvoking the instance.

ConfigurableFalse
PlatformsSupported on all platforms
static-allocation
Description Enter the static-allocation context
Context system dhcp-server network-instance name reference dhcpv6 static-allocation
Treestatic-allocation
ConfigurableTrue
PlatformsSupported on all platforms
host mac string
Description host name for static ip allocations
Context system dhcp-server network-instance name reference dhcpv6 static-allocation host mac string
Treehost
ConfigurableTrue
PlatformsSupported on all platforms
options
Description Enter the options context
Context system dhcp-server network-instance name reference dhcpv6 static-allocation host mac string options
Treeoptions
ConfigurableTrue
PlatformsSupported on all platforms
statistics
Description Enter the statistics context
Context system dhcp-server network-instance name reference dhcpv6 statistics
Treestatistics
ConfigurableFalse
PlatformsSupported on all platforms
trace-options
Description Container for tracing DHCP server operations instance
Contextsystem dhcp-server network-instance name reference dhcpv6 trace-options
Treetrace-options
ConfigurableTrue
PlatformsSupported on all platforms

dns

Description Top-level container for DNS configuration and state
Contextsystem dns
Treedns
ConfigurableTrue
PlatformsSupported on all platforms

host-entry name string

Description List of static host entries
Context system dns host-entry name string
Treehost-entry
ConfigurableTrue
PlatformsSupported on all platforms
name string
Description Name of host entry
Context system dns host-entry name string
String Length1 to 253
ConfigurableTrue
PlatformsSupported on all platforms

oper-state keyword

Description Details the operational state of the DNS client
Contextsystem dns oper-state keyword
Treeoper-state
Options
  • up

    Component or process is operational

  • down

    Component or process is not operational

  • empty

    Component slot is empty

  • downloading

    Component is downloading image into memory

  • booting

    Component is booting downloaded image

  • starting

    Component image operational, application processes starting

  • failed

    Component or process has failed

  • synchronizing

    Component is currently being synchronized

  • upgrading

    Component is currently being upgraded

  • low-power

    Component is offline due to insufficient system power

  • degraded

    Component or process is in a degraded state

  • warm-reboot

    Component or process is currently warm rebooting

    This state is set during a warm reboot immediately following initiation of the reboot, continuing after startup until the system has completed audit. In this state the system will not accept configuration changes.

  • waiting

    Component or process is currently waiting

    This state can be set by event handler when the reinvoke-with-delay action is used, and indicates that the event handler is waiting for the provided delay before reinvoking the instance.

ConfigurableFalse
PlatformsSupported on all platforms

search-list string

Description An ordered list of domains to search when resolving a host name
Contextsystem dns search-list string
Treesearch-list
String Length1 to 253
ConfigurableTrue
PlatformsSupported on all platforms

server-list (ipv4-address | ipv6-address)

Description List of the DNS servers that the resolver should query
Contextsystem dns server-list (ipv4-address | ipv6-address)
Treeserver-list
ConfigurableTrue
PlatformsSupported on all platforms
Max. Elements3

source-address (ipv4-address | ipv6-address)

Description Source address for DNS to use for messages sent to a remote server
Contextsystem dns source-address (ipv4-address | ipv6-address)
Treesource-address
ConfigurableTrue
PlatformsSupported on all platforms

event-handler

Description Top-level container for configuration and state of event handler and event handling instances
Contextsystem event-handler
Treeevent-handler
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

instance name string

Description

List of all event handler instances

An event handler instance consists of a set of paths to be monitored for changes, and a Python script to execute if changes occur.

Contextsystem event-handler instance name string
Treeinstance
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
Max. Elements20
name string
Description A user-defined name for this event handler instance
Contextsystem event-handler instance name string
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
admin-state keyword
Description Administratively enable or disable this event handler instance
Contextsystem event-handler instance name string admin-state keyword
Treeadmin-state
Defaultdisable
Options
  • enable

  • disable

Configurable True
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
last-errored-execution
Description Operational state of the last errored execution of this instance
Contextsystem event-handler instance name string last-errored-execution
Treelast-errored-execution
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
end-time string
Description

The time this instance last finished execution

This timestamp includes any actions provided as output from the execution

Contextsystem event-handler instance name string last-errored-execution end-time string
Treeend-time
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
input string
Description The input provided to the script
Context system event-handler instance name string last-errored-execution input string
Treeinput
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
oper-down-reason keyword
Description The reason this instance is or was in its last operational state
Contextsystem event-handler instance name string last-errored-execution oper-down-reason keyword
Treeoper-down-reason
Options
  • admin-disabled

    Event handler instance is admin-disabled

  • failed-to-compile

    Event handler failed to compile the script, indicating that the script likely has a syntax error

  • exception

    Event handler caught an exception in the last execution of the script

  • timeout

    The last execution of the script did not complete before a timeout occurred

  • subscription-failed

    Event handler was unable to subscribe to the provided paths

  • script-unavailable

    Event handler was unable to find the script on the filesystem

  • script-error

    The script returned something invalid

  • missing-function

    Event handler was unable to find a function named event_handler_main() in the provided script

  • system-error

    There was a failure in setting up the python environment

  • ephemeral-action-failed

    Event handler was unable to perform a ephemeral-path action in the previous execution

  • cfg-action-failed

    Event handler was unable to perform a cfg-path action in the previous execution

  • tools-action-failed

    Event handler was unable to perform a tools-path action in the previous execution

  • state-action-failed

    Event handler was unable to perform a state-path action in the previous execution

  • script-action-failed

    Event handler was unable to perform a script action in the previous execution

ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
output string
Description

The output received from the script

If empty, no response was received.

Contextsystem event-handler instance name string last-errored-execution output string
Treeoutput
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
start-time string
Description The time this instance last started execution
Contextsystem event-handler instance name string last-errored-execution start-time string
Treestart-time
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
stdout-stderr string
Description The output printed on STDOUT or STDERR during this execution
Contextsystem event-handler instance name string last-errored-execution stdout-stderr string
Treestdout-stderr
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
upython-duration number
Description Time taken for the instance to return output
Contextsystem event-handler instance name string last-errored-execution upython-duration number
Treeupython-duration
Unitsmicroseconds
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
last-execution
Description Operational state of the last execution of this instance
Contextsystem event-handler instance name string last-execution
Treelast-execution
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
end-time string
Description

The time this instance last finished execution

This timestamp includes any actions provided as output from the execution

Contextsystem event-handler instance name string last-execution end-time string
Treeend-time
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
input string
Description The input provided to the script
Context system event-handler instance name string last-execution input string
Treeinput
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
oper-down-reason keyword
Description The reason this instance is or was in its last operational state
Contextsystem event-handler instance name string last-execution oper-down-reason keyword
Treeoper-down-reason
Options
  • admin-disabled

    Event handler instance is admin-disabled

  • failed-to-compile

    Event handler failed to compile the script, indicating that the script likely has a syntax error

  • exception

    Event handler caught an exception in the last execution of the script

  • timeout

    The last execution of the script did not complete before a timeout occurred

  • subscription-failed

    Event handler was unable to subscribe to the provided paths

  • script-unavailable

    Event handler was unable to find the script on the filesystem

  • script-error

    The script returned something invalid

  • missing-function

    Event handler was unable to find a function named event_handler_main() in the provided script

  • system-error

    There was a failure in setting up the python environment

  • ephemeral-action-failed

    Event handler was unable to perform a ephemeral-path action in the previous execution

  • cfg-action-failed

    Event handler was unable to perform a cfg-path action in the previous execution

  • tools-action-failed

    Event handler was unable to perform a tools-path action in the previous execution

  • state-action-failed

    Event handler was unable to perform a state-path action in the previous execution

  • script-action-failed

    Event handler was unable to perform a script action in the previous execution

ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
oper-down-reason-detail string
Description Any additional detail event handler can provide around the last operational state of this instance
Contextsystem event-handler instance name string last-execution oper-down-reason-detail string
Treeoper-down-reason-detail
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
output string
Description

The output received from the script

If empty, no response was received.

Contextsystem event-handler instance name string last-execution output string
Treeoutput
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
start-time string
Description The time this instance last started execution
Contextsystem event-handler instance name string last-execution start-time string
Treestart-time
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
stdout-stderr string
Description The output printed on STDOUT or STDERR during this execution
Contextsystem event-handler instance name string last-execution stdout-stderr string
Treestdout-stderr
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
upython-duration number
Description Time taken for the instance to return output
Contextsystem event-handler instance name string last-execution upython-duration number
Treeupython-duration
Unitsmicroseconds
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
oper-state keyword
Description Details if this event handler instance is operationally available
Contextsystem event-handler instance name string oper-state keyword
Treeoper-state
Options
  • up

    Component or process is operational

  • down

    Component or process is not operational

  • empty

    Component slot is empty

  • downloading

    Component is downloading image into memory

  • booting

    Component is booting downloaded image

  • starting

    Component image operational, application processes starting

  • failed

    Component or process has failed

  • synchronizing

    Component is currently being synchronized

  • upgrading

    Component is currently being upgraded

  • low-power

    Component is offline due to insufficient system power

  • degraded

    Component or process is in a degraded state

  • warm-reboot

    Component or process is currently warm rebooting

    This state is set during a warm reboot immediately following initiation of the reboot, continuing after startup until the system has completed audit. In this state the system will not accept configuration changes.

  • waiting

    Component or process is currently waiting

    This state can be set by event handler when the reinvoke-with-delay action is used, and indicates that the event handler is waiting for the provided delay before reinvoking the instance.

ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
options
Description Options to be passed on each execution of the script
Contextsystem event-handler instance name string options
Treeoptions
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
object name string
Description Enter the object list instance
Context system event-handler instance name string options object name string
Treeobject
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
name string
Description The name of this object
Context system event-handler instance name string options object name string
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
value string
Description A single value to associate with this object
Contextsystem event-handler instance name string options object name string value string
Treevalue
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
values string
Description List of values to associate with this object, these are serialized as a JSON array when provided as input to the script
Contextsystem event-handler instance name string options object name string values string
Treevalues
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
paths string
Description

List of valid YANG paths in CLI notation to monitor for changes

If any events are received on any of the provided paths, the configured script will be executed.

This path may include keys, wildcards, ranges, and other management server supported constructs.

E.g. "interface * oper-state" "acl ipv4-filter foo* description"

Contextsystem event-handler instance name string paths string
Treepaths
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
Max. Elements36
statistics
Description Top-level container for event handler statistics
Contextsystem event-handler instance name string statistics
Treestatistics
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
execution-count number
Description Indicates the total number of executions of this script
Contextsystem event-handler instance name string statistics execution-count number
Treeexecution-count
Default0
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
execution-errors number
Description Indicates the total number of errors in executions of this script
Contextsystem event-handler instance name string statistics execution-errors number
Treeexecution-errors
Default0
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
execution-successes number
Description Indicates the total number of successful executions of this script
Contextsystem event-handler instance name string statistics execution-successes number
Treeexecution-successes
Default0
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
execution-timeouts number
Description Indicates the total number of timeouts in executions of this script
Contextsystem event-handler instance name string statistics execution-timeouts number
Treeexecution-timeouts
Default0
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
upython-duration number
Description Total time taken for all executions of this script to return output
Contextsystem event-handler instance name string statistics upython-duration number
Treeupython-duration
Unitsmilliseconds
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
upython-script string
Description

File name of a MicroPython script, including .py suffix

This script should exist in /etc/opt/srlinux/eventmgr or /opt/srlinux/eventmgr already. Explicit paths outside of these two directories are not permitted.

Contextsystem event-handler instance name string upython-script string
Treeupython-script
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

run-as-user reference

Description

The user to run event handler instances as

If no user is configured, scripts are executed as the 'admin' user.

Contextsystem event-handler run-as-user reference
Treerun-as-user
Referencesystem aaa authentication user username string
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

features string

Description Features enabled on this platform
Context system features string
Treefeatures
String Length1 to 255
ConfigurableFalse
PlatformsSupported on all platforms

ftp-server

Description Top-level container for FTP server configuration and state
Contextsystem ftp-server
Treeftp-server
ConfigurableTrue
PlatformsSupported on all platforms

network-instance name reference

Description List of network-instances to run an FTP server in
Contextsystem ftp-server network-instance name reference
Treenetwork-instance
ConfigurableTrue
PlatformsSupported on all platforms
oper-state keyword
Description Details the operational state of the FTP server
Contextsystem ftp-server network-instance name reference oper-state keyword
Treeoper-state
Options
  • up

    Component or process is operational

  • down

    Component or process is not operational

  • empty

    Component slot is empty

  • downloading

    Component is downloading image into memory

  • booting

    Component is booting downloaded image

  • starting

    Component image operational, application processes starting

  • failed

    Component or process has failed

  • synchronizing

    Component is currently being synchronized

  • upgrading

    Component is currently being upgraded

  • low-power

    Component is offline due to insufficient system power

  • degraded

    Component or process is in a degraded state

  • warm-reboot

    Component or process is currently warm rebooting

    This state is set during a warm reboot immediately following initiation of the reboot, continuing after startup until the system has completed audit. In this state the system will not accept configuration changes.

  • waiting

    Component or process is currently waiting

    This state can be set by event handler when the reinvoke-with-delay action is used, and indicates that the event handler is waiting for the provided delay before reinvoking the instance.

ConfigurableFalse
PlatformsSupported on all platforms
source-address (ipv4-address | ipv6-address)
Description

IPv4 or IPv6 address for the FTP server to listen on within the network-instance

Default behavior is to listen on '::', which will listen on all addresses for both IPv4 and IPv6. In order to listen on IPv4 only, this field should be set to '0.0.0.0'.

Contextsystem ftp-server network-instance name reference source-address (ipv4-address | ipv6-address)
Treesource-address
Default::
ConfigurableTrue
PlatformsSupported on all platforms

grpc-server name string

Description List of configured gRPC server instances
Contextsystem grpc-server name string
Treegrpc-server
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

name string

Description User-provided name of this server instance
Contextsystem grpc-server name string
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

admin-state keyword

Description

Globally enable or disable the gRPC server instance

Disabling this will disable all gRPC server sockets in all network instances, and any configured unix domain sockets.

Contextsystem grpc-server name string admin-state keyword
Treeadmin-state
Defaultdisable
Options
  • enable

  • disable

Configurable True
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

certz

Description

Information relating to the active certificate and bundle/s as provided via Certz

State is provided by the gNSI Certz service, and can be changed using the gNSI.Certz.Rotate RPC

Contextsystem grpc-server name string certz
Treecertz
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
certificate
Description State relating to the active certificate provided via Certz
Contextsystem grpc-server name string certz certificate
Treecertificate
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
created-on string
Description

The created on timestamp as provided by the gNSI client at the time of uploading the policy

The maps to the created_on field within a Entity message in the Certz protobuf.

Contextsystem grpc-server name string certz certificate created-on string
Treecreated-on
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
version string
Description

The version string as provided by the gNSI client at the time of uploading the certificate or bundle/s

The maps to the version field within a Entity message in the Certz protobuf.

Contextsystem grpc-server name string certz certificate version string
Treeversion
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
crl
Description

State relating to the active certificate revocation list provided via Certz

The list of certificates provided will not be used to validate mTLS or servers, even if those certificates exist within the trust anchor.

Contextsystem grpc-server name string certz crl
Treecrl
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
created-on string
Description

The created on timestamp as provided by the gNSI client at the time of uploading the policy

The maps to the created_on field within a Entity message in the Certz protobuf.

Contextsystem grpc-server name string certz crl created-on string
Treecreated-on
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
version string
Description

The version string as provided by the gNSI client at the time of uploading the certificate or bundle/s

The maps to the version field within a Entity message in the Certz protobuf.

Contextsystem grpc-server name string certz crl version string
Treeversion
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
ssl-profile-id string
Description The ID of this gRPC server's SSL profile as used by the gNSI Certz service
Contextsystem grpc-server name string certz ssl-profile-id string
Treessl-profile-id
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
trust-anchor
Description

State relating to the active trust anchor provided via Certz

This is equivalent to the certificate authority bundle, and is the list of certificates used to validate clients in mTLS, and to validate servers in outbound TLS.

Contextsystem grpc-server name string certz trust-anchor
Treetrust-anchor
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
created-on string
Description

The created on timestamp as provided by the gNSI client at the time of uploading the policy

The maps to the created_on field within a Entity message in the Certz protobuf.

Contextsystem grpc-server name string certz trust-anchor created-on string
Treecreated-on
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
version string
Description

The version string as provided by the gNSI client at the time of uploading the certificate or bundle/s

The maps to the version field within a Entity message in the Certz protobuf.

Contextsystem grpc-server name string certz trust-anchor version string
Treeversion
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

client id number

Description List of active gRPC client sessions
Context system grpc-server name string client id number
Treeclient
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
id number
Description System generated ID for for the client
Contextsystem grpc-server name string client id number
Range0 to 4294967295
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
election-id string
Description

Election ID of this client

Provided only for services supporting an election ID

Contextsystem grpc-server name string client id number election-id string
Treeelection-id
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
gnmi
Description Container for gNMI related session info
Contextsystem grpc-server name string client id number gnmi
Treegnmi
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
paths id number
Description List of paths being subscribed to
Context system grpc-server name string client id number gnmi paths id number
Treepaths
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
id number
Description System generated ID for the subscribed path (within subscription)
Contextsystem grpc-server name string client id number gnmi paths id number
Range0 to 65535
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
mode keyword
Description Subscription mode (on-change, sample, target-defined, poll, once)
Contextsystem grpc-server name string client id number gnmi paths id number mode keyword
Treemode
Options
  • ON_CHANGE

  • SAMPLE

  • TARGET_DEFINED

  • POLL

  • ONCE

Configurable False
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
path string
Description Path being subscribed to
Context system grpc-server name string client id number gnmi paths id number path string
Treepath
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
sample-interval number
Description Time in seconds to provide updates to the remote host, set to 0 for all subscription modes except SAMPLE
Contextsystem grpc-server name string client id number gnmi paths id number sample-interval number
Treesample-interval
Unitsseconds
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
gribi
Description Container for gRIBI related session info
Contextsystem grpc-server name string client id number gribi
Treegribi
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
persistence-mode keyword
Description The defined persistence mode as signaled by the client
Contextsystem grpc-server name string client id number gribi persistence-mode keyword
Treepersistence-mode
Options
  • preserve

    Entries populated by the client will be persisted during a client disconnect, or control module switchover

  • delete

    Entries populated by the client will be purged on the client disconnecting, or a control module switchover

    If no persistence mode is signaled, the default is to delete entries.

ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
p4rt
Description Container for P4RT related session info
Contextsystem grpc-server name string client id number p4rt
Treep4rt
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
forwarding-complex
Description Enter the forwarding-complex context
Context system grpc-server name string client id number p4rt forwarding-complex
Treeforwarding-complex
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
device number
Description

The P4Runtime ID of the forwarding complex for which this client has established itself

This is the value configured at /platform/linecard/forwarding-complex/p4rt/id, or a system derived default.

Contextsystem grpc-server name string client id number p4rt forwarding-complex device number
Treedevice
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
id string
Description

The normalized ID for this forwarding-complex

This is the slot number and complex number seperated by a '/', 0 indexed. For example '1/0', or '1/1' representing two forwarding complexes on slot 1.

Contextsystem grpc-server name string client id number p4rt forwarding-complex id string
Treeid
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
slot number
Description The linecard slot for which this forwarding complex resides on
Contextsystem grpc-server name string client id number p4rt forwarding-complex slot number
Treeslot
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
primary boolean
Description

Indicates if this client is the primary for the specified forwarding complex

Only a single primary per forwarding complex is supported

Contextsystem grpc-server name string client id number p4rt primary boolean
Treeprimary
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
remote-host (ipv4-address | ipv6-address)
Description Remote host of the client
Context system grpc-server name string client id number remote-host (ipv4-address | ipv6-address)
Treeremote-host
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
remote-port number
Description Remote port of the client
Context system grpc-server name string client id number remote-port number
Treeremote-port
Range0 to 65535
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
rpc string
Description

The called package, service, and RPC

For example gnmi.gNMI.Subscribe

Contextsystem grpc-server name string client id number rpc string
Treerpc
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
start-time string
Description Time of the subscription creation
Context system grpc-server name string client id number start-time string
Treestart-time
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
type keyword
Description Enter the type context
Context system grpc-server name string client id number type keyword
Treetype
Options
  • gnmi

  • acctz

Configurable False
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
user string
Description Authenticated username for the client
Contextsystem grpc-server name string client id number user string
Treeuser
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
user-agent string
Description User agent used for the client
Context system grpc-server name string client id number user-agent string
Treeuser-agent
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

default-tls-profile boolean

Description Whether to use default TLS profile (generated by the system) if none is configured via tls-profile field
Contextsystem grpc-server name string default-tls-profile boolean
Treedefault-tls-profile
Defaultfalse
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

gnmi

Description Container for gnmi configuration and state
Contextsystem grpc-server name string gnmi
Treegnmi
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
commit-confirmed-timeout number
Description

Number of seconds to wait for confirmation

A value of 0 means commit confirmed is not used

Contextsystem grpc-server name string gnmi commit-confirmed-timeout number
Treecommit-confirmed-timeout
Range0 to 86400
Default0
Unitsseconds
Configurable True
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
commit-save boolean
Description Specifies whether to save startup configuration after every successful commit
Contextsystem grpc-server name string gnmi commit-save boolean
Treecommit-save
Defaultfalse
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
include-defaults-in-config-only-responses boolean
Description Specifies whether to include field default values in get/subscribe responses when using configuration only datastore (for example running/intended datastore)
Contextsystem grpc-server name string gnmi include-defaults-in-config-only-responses boolean
Treeinclude-defaults-in-config-only-responses
Defaultfalse
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

metadata-authentication boolean

Description Enable or disable the use of username/password metadata authentication for every gRPC request
Contextsystem grpc-server name string metadata-authentication boolean
Treemetadata-authentication
Defaulttrue
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

network-instance reference

Description Reference to a configured network instance where the gRPC will listen on for incoming connections
Contextsystem grpc-server name string network-instance reference
Treenetwork-instance
Referencenetwork-instance name string
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

oper-state keyword

Description Details if the gRPC server is operationally available
Contextsystem grpc-server name string oper-state keyword
Treeoper-state
Options
  • up

    Component or process is operational

  • down

    Component or process is not operational

  • empty

    Component slot is empty

  • downloading

    Component is downloading image into memory

  • booting

    Component is booting downloaded image

  • starting

    Component image operational, application processes starting

  • failed

    Component or process has failed

  • synchronizing

    Component is currently being synchronized

  • upgrading

    Component is currently being upgraded

  • low-power

    Component is offline due to insufficient system power

  • degraded

    Component or process is in a degraded state

  • warm-reboot

    Component or process is currently warm rebooting

    This state is set during a warm reboot immediately following initiation of the reboot, continuing after startup until the system has completed audit. In this state the system will not accept configuration changes.

  • waiting

    Component or process is currently waiting

    This state can be set by event handler when the reinvoke-with-delay action is used, and indicates that the event handler is waiting for the provided delay before reinvoking the instance.

ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

port number

Description Port the gRPC server will listen on for incoming connections
Contextsystem grpc-server name string port number
Treeport
Range0 to 65535
Default57400
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

rate-limit number

Description Set a limit on the number of RPC calls per minute
Contextsystem grpc-server name string rate-limit number
Treerate-limit
Range0 to 65535
Default60
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

services identityref

Description The gRPC service definitions that should be enabled for this gRPC server instance
Contextsystem grpc-server name string services identityref
Treeservices
Options
  • gnmi

    gNMI: gRPC Network Management Interface

  • gnoi

    gNOI: gRPC Network Operations Interface

  • gnoi.factory_reset

    gNOI: FactoryReset Service

  • gnoi.file

    gNOI: File Service

  • gnoi.healthz

    gNOI: Healthz Service

  • gnoi.os

    gNOI: OS Service

  • gnoi.packet_link_qualification

    gNOI: PacketLinkQualification Service

  • gnoi.system

    gNOI: System Service

  • gnsi

    gNSI: gRPC Network Security Interface

  • gnsi.acctz

    gNSI: Accounting Service

  • gnsi.attestz

    gNSI: Attestz Service

  • gnsi.authz

    gNSI: Authorization Policy Management Service

  • gnsi.certz

    gNSI: Certificate Management Service

  • gnsi.credentialz

    gNSI: Credentials Management Service

  • gnsi.enrollz

    gNSI: Enrollz Service

  • gnsi.pathz

    gNSI: Path-based Authorization Policy Management Service

  • gribi

    gRIBI: gRPC Routing Information Base Interface

  • p4rt

    P4RT: P4 Runtime

ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

session-limit number

Description

Set a limit on the number of simultaneous active gRPC sessions

A session is defined as an individual RPC invocation, which could result in a single client generating multiple sessions. In the context of a Subscribe RPC this is the number of simultaneously active SubscribeRequests across all Subscribe RPCs.

Contextsystem grpc-server name string session-limit number
Treesession-limit
Range0 to 65535
Default20
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

source-address (ipv4-address | ipv6-address)

Description List of IP addresses the gRPC server will listen on within the network instance
Contextsystem grpc-server name string source-address (ipv4-address | ipv6-address)
Treesource-address
Default::
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

statistics

Description Statistics related to the gRPC server
Contextsystem grpc-server name string statistics
Treestatistics
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
access-accepts number
Description The total number of times the gPRC allowed access to the server
Contextsystem grpc-server name string statistics access-accepts number
Treeaccess-accepts
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
access-rejects number
Description The total number of times the gRPC server denied access to the server
Contextsystem grpc-server name string statistics access-rejects number
Treeaccess-rejects
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
last-access-accept string
Description A timestamp of the last time the gRPC allowed access to the server
Contextsystem grpc-server name string statistics last-access-accept string
Treelast-access-accept
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
last-access-reject string
Description A timestamp of the last time the gRPC server denied access to the server
Contextsystem grpc-server name string statistics last-access-reject string
Treelast-access-reject
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
rpc name string
Description A collection of counters collected by the gNSI.authz module for a RPC identified by the `name`.
Contextsystem grpc-server name string statistics rpc name string
Treerpc
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
name string
Description The name of the RPC the counters were collected for.
Contextsystem grpc-server name string statistics rpc name string
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
access-accepts number
Description The total number of times the gNSI.authz module allowed access to a RPC.
Contextsystem grpc-server name string statistics rpc name string access-accepts number
Treeaccess-accepts
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
access-rejects number
Description The total number of times the gNSI.authz module denied access to a RPC.
Contextsystem grpc-server name string statistics rpc name string access-rejects number
Treeaccess-rejects
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
last-access-accept string
Description A timestamp of the last time the gNSI.authz allowed access to a RPC.
Contextsystem grpc-server name string statistics rpc name string last-access-accept string
Treelast-access-accept
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
last-access-reject string
Description A timestamp of the last time the gNSI.authz denied access to a RPC.
Contextsystem grpc-server name string statistics rpc name string last-access-reject string
Treelast-access-reject
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

timeout number

Description Set the idle timeout in seconds on gRPC connections
Contextsystem grpc-server name string timeout number
Treetimeout
Range0 to 65535
Default7200
Unitsseconds
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

tls-profile reference

Description

Reference to the TLS profile to use on the gRPC server

If none is specified, then TLS is not used.

Contextsystem grpc-server name string tls-profile reference
Treetls-profile
Referencesystem tls server-profile name string
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

trace-options keyword

Description gRPC trace options
Context system grpc-server name string trace-options keyword
Treetrace-options
Options
  • request

  • response

  • common

  • grpc

ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

unix-socket

Description Top-level container for configuration and state related to unix sockets
Contextsystem grpc-server name string unix-socket
Treeunix-socket
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
admin-state keyword
Description Administratively enable or disable the gRPC server
Contextsystem grpc-server name string unix-socket admin-state keyword
Treeadmin-state
Defaultdisable
Options
  • enable

  • disable

Configurable True
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
socket-path string
Description Path to the unix socket used by gRPC
Context system grpc-server name string unix-socket socket-path string
Treesocket-path
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

yang-models keyword

Description Specify yang-models to be used when origin field is not present in requests
Contextsystem grpc-server name string yang-models keyword
Treeyang-models
Defaultnative
Options
  • native

  • openconfig

Configurable True
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

information

Description Top-level container for system information configuration and state
Contextsystem information
Treeinformation
ConfigurableTrue
PlatformsSupported on all platforms

contact string

Description

The system contact

This field represents contact information for the person or group that maintains the system. This field is exposed via SNMP at the sysContact OID.

Contextsystem information contact string
Treecontact
ConfigurableTrue
PlatformsSupported on all platforms

description string

Description

The system description

This field is system generated, and is a combination of the system host name, software version, kernel version, and build date. The template for this field is: SRLinux-<version> <hostname> <kernel> <build date>. This field is exposed via SNMP at the sysDescr OID.

Contextsystem information description string
Treedescription
ConfigurableFalse
PlatformsSupported on all platforms

last-booted string

Description The date and time the system was last booted
Contextsystem information last-booted string
Treelast-booted
String Length20 to 32
ConfigurableFalse
PlatformsSupported on all platforms

location string

Description

The system location

This field represents the location of the system, and is commonly used by inventory management systems to group elements together. This field is exposed via SNMP at the sysLocation OID.

Contextsystem information location string
Treelocation
ConfigurableTrue
PlatformsSupported on all platforms

version string

Description

The system version

This field represents the version of the management server

Contextsystem information version string
Treeversion
ConfigurableFalse
PlatformsSupported on all platforms

json-rpc-server

Description Configures the JSON RPC access API
Context system json-rpc-server
Treejson-rpc-server
ConfigurableTrue
PlatformsSupported on all platforms

admin-state keyword

Description Globally enable or disable the JSON RPC server Disabling this will disable all JSON RPC servers.
Contextsystem json-rpc-server admin-state keyword
Treeadmin-state
Defaultdisable
Options
  • enable

  • disable

Configurable True
PlatformsSupported on all platforms

network-instance name reference

Description List of network instances to run the JSON RPC server in
Contextsystem json-rpc-server network-instance name reference
Treenetwork-instance
ConfigurableTrue
PlatformsSupported on all platforms
http
Description Top-level container for the JSON RPC HTTP server
Contextsystem json-rpc-server network-instance name reference http
Treehttp
ConfigurableTrue
PlatformsSupported on all platforms
admin-state keyword
Description Administratively enable or disable the HTTP JSON RPC server This requires the JSON RPC server to be globally enabled
Contextsystem json-rpc-server network-instance name reference http admin-state keyword
Treeadmin-state
Defaultdisable
Options
  • enable

  • disable

Configurable True
PlatformsSupported on all platforms
oper-state keyword
Description Details if the JSON RPC server is operationally available
Contextsystem json-rpc-server network-instance name reference http oper-state keyword
Treeoper-state
Options
  • up

    Component or process is operational

  • down

    Component or process is not operational

  • empty

    Component slot is empty

  • downloading

    Component is downloading image into memory

  • booting

    Component is booting downloaded image

  • starting

    Component image operational, application processes starting

  • failed

    Component or process has failed

  • synchronizing

    Component is currently being synchronized

  • upgrading

    Component is currently being upgraded

  • low-power

    Component is offline due to insufficient system power

  • degraded

    Component or process is in a degraded state

  • warm-reboot

    Component or process is currently warm rebooting

    This state is set during a warm reboot immediately following initiation of the reboot, continuing after startup until the system has completed audit. In this state the system will not accept configuration changes.

  • waiting

    Component or process is currently waiting

    This state can be set by event handler when the reinvoke-with-delay action is used, and indicates that the event handler is waiting for the provided delay before reinvoking the instance.

ConfigurableFalse
PlatformsSupported on all platforms
port number
Description The port the HTTP JSON RPC server will listen on for incoming connections
Contextsystem json-rpc-server network-instance name reference http port number
Treeport
Range0 to 65535
Default80
ConfigurableTrue
PlatformsSupported on all platforms
session-limit number
Description The number of concurrent requests the server will allow If a request comes in while this limit is reached, the request will block until another request is finished.
Contextsystem json-rpc-server network-instance name reference http session-limit number
Treesession-limit
Range1 to 100
Default10
ConfigurableTrue
PlatformsSupported on all platforms
https
Description Top-level container for the JSON-RPC HTTPS server
Contextsystem json-rpc-server network-instance name reference https
Treehttps
ConfigurableTrue
PlatformsSupported on all platforms
admin-state keyword
Description Administratively enable or disable the HTTPS JSON RPC server This requires the JSON RPC server to be globally enabled
Contextsystem json-rpc-server network-instance name reference https admin-state keyword
Treeadmin-state
Defaultdisable
Options
  • enable

  • disable

Configurable True
PlatformsSupported on all platforms
oper-state keyword
Description Details if the JSON RPC server is operationally available
Contextsystem json-rpc-server network-instance name reference https oper-state keyword
Treeoper-state
Options
  • up

    Component or process is operational

  • down

    Component or process is not operational

  • empty

    Component slot is empty

  • downloading

    Component is downloading image into memory

  • booting

    Component is booting downloaded image

  • starting

    Component image operational, application processes starting

  • failed

    Component or process has failed

  • synchronizing

    Component is currently being synchronized

  • upgrading

    Component is currently being upgraded

  • low-power

    Component is offline due to insufficient system power

  • degraded

    Component or process is in a degraded state

  • warm-reboot

    Component or process is currently warm rebooting

    This state is set during a warm reboot immediately following initiation of the reboot, continuing after startup until the system has completed audit. In this state the system will not accept configuration changes.

  • waiting

    Component or process is currently waiting

    This state can be set by event handler when the reinvoke-with-delay action is used, and indicates that the event handler is waiting for the provided delay before reinvoking the instance.

ConfigurableFalse
PlatformsSupported on all platforms
session-limit number
Description The number of concurrent requests the server will allow If a request comes in while this limit is reached, the request will block until another request is finished.
Contextsystem json-rpc-server network-instance name reference https session-limit number
Treesession-limit
Range1 to 100
Default10
ConfigurableTrue
PlatformsSupported on all platforms

unix-socket

Description Top-level container for configuration and state related to unix sockets
Contextsystem json-rpc-server unix-socket
Treeunix-socket
ConfigurableTrue
PlatformsSupported on all platforms
admin-state keyword
Description Administratively enable or disable the JSON RPC server via unix socket This requires the JSON RPC server to be globally enabled
Contextsystem json-rpc-server unix-socket admin-state keyword
Treeadmin-state
Defaultdisable
Options
  • enable

  • disable

Configurable True
PlatformsSupported on all platforms
oper-state keyword
Description Details if the JSON RPC server is operationally available
Contextsystem json-rpc-server unix-socket oper-state keyword
Treeoper-state
Options
  • up

    Component or process is operational

  • down

    Component or process is not operational

  • empty

    Component slot is empty

  • downloading

    Component is downloading image into memory

  • booting

    Component is booting downloaded image

  • starting

    Component image operational, application processes starting

  • failed

    Component or process has failed

  • synchronizing

    Component is currently being synchronized

  • upgrading

    Component is currently being upgraded

  • low-power

    Component is offline due to insufficient system power

  • degraded

    Component or process is in a degraded state

  • warm-reboot

    Component or process is currently warm rebooting

    This state is set during a warm reboot immediately following initiation of the reboot, continuing after startup until the system has completed audit. In this state the system will not accept configuration changes.

  • waiting

    Component or process is currently waiting

    This state can be set by event handler when the reinvoke-with-delay action is used, and indicates that the event handler is waiting for the provided delay before reinvoking the instance.

ConfigurableFalse
PlatformsSupported on all platforms

l2cp-transparency

Description Enclosing container for system level Layer-2 Control Protocol transparency.
Contextsystem l2cp-transparency
Treel2cp-transparency
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5

l2cp-statistics

Description Container for Layer-2 Control Plane protocol statistics.
Contextsystem l2cp-transparency l2cp-statistics
Treel2cp-statistics
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
dot1x
Description Container for 802.1x protocols.
Context system l2cp-transparency l2cp-statistics dot1x
Treedot1x
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
in-trap-to-cpu-packets number
Description

System level incoming 802.1x frames copied to CPU.

Cumulative of all Ethernet interfaces including all the copy-to-cpu 802.1x frames. 802.1x frames are identified by a destination MAC value of 01:80:c2:00:00:03 and EtherType value of 0x888e.

Contextsystem l2cp-transparency l2cp-statistics dot1x in-trap-to-cpu-packets number
Treein-trap-to-cpu-packets
Default0
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
in-tunneled-packets number
Description

System level incoming 802.1x tunneled frames.

Cumulative of all Ethernet interfaces including all the tunneled 802.1x frames. 802.1x frames are identified by a destination MAC value of 01:80:c2:00:00:03 and EtherType value of 0x888e.

Contextsystem l2cp-transparency l2cp-statistics dot1x in-tunneled-packets number
Treein-tunneled-packets
Default0
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
last-clear string
Description Timestamp of the last time the LACP counters were cleared.
Contextsystem l2cp-transparency l2cp-statistics dot1x last-clear string
Treelast-clear
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
lacp
Description Container for LACP.
Context system l2cp-transparency l2cp-statistics lacp
Treelacp
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
in-trap-to-cpu-packets number
Description

System level incoming Link Aggregation Control Protocol frames copied to CPU.

Cumulative of all Ethernet interfaces including all the copy-to-cpu LACP frames. LACP frames are identified by a destination MAC value of 01:80:c2:00:00:02, EtherType value of 0x8809 and slow protocol subtype 0x1.

Contextsystem l2cp-transparency l2cp-statistics lacp in-trap-to-cpu-packets number
Treein-trap-to-cpu-packets
Default0
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
in-tunneled-packets number
Description

System level incoming Link Aggregation Control Protocol tunneled frames.

Cumulative of all Ethernet interfaces including all the tunneled LACP frames. LACP frames are identified by a destination MAC value of 01:80:c2:00:00:02, EtherType value of 0x8809 and slow protocol subtype 0x1.

Contextsystem l2cp-transparency l2cp-statistics lacp in-tunneled-packets number
Treein-tunneled-packets
Default0
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
last-clear string
Description Timestamp of the last time the LACP counters were cleared.
Contextsystem l2cp-transparency l2cp-statistics lacp last-clear string
Treelast-clear
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
last-clear string
Description Timestamp of the last time the L2CP counters were cleared.
Contextsystem l2cp-transparency l2cp-statistics last-clear string
Treelast-clear
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
lldp
Description Container for LLDP.
Context system l2cp-transparency l2cp-statistics lldp
Treelldp
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
in-trap-to-cpu-packets number
Description

System level incoming Link Layer Discovery Protocol frames copied to CPU.

Cumulative of all Ethernet interfaces including all the copy-to-cpu LLDP frames. LLDP frames are identified by a destination MAC value of 01:80:c2:00:00:0e and EtherType value of 0x88cc.

Contextsystem l2cp-transparency l2cp-statistics lldp in-trap-to-cpu-packets number
Treein-trap-to-cpu-packets
Default0
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
in-tunneled-packets number
Description

System level incoming Link Layer Discovery Protocol tunneled frames.

Cumulative of all Ethernet interfaces including all the tunneled LLDP frames. LLDP frames are identified by a destination MAC value of 01:80:c2:00:00:0e and EtherType value of 0x88cc.

Contextsystem l2cp-transparency l2cp-statistics lldp in-tunneled-packets number
Treein-tunneled-packets
Default0
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
last-clear string
Description Timestamp of the last time the LACP counters were cleared.
Contextsystem l2cp-transparency l2cp-statistics lldp last-clear string
Treelast-clear
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
ptp
Description Container for Precision Time Protocol Peer-Delay protocol.
Contextsystem l2cp-transparency l2cp-statistics ptp
Treeptp
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
in-trap-to-cpu-packets number
Description

System level incoming Precision Time Protocol Peer-Delay frames copied to CPU.

Cumulative of all Ethernet interfaces including all the copy-to-cpu PTP frames. PTP frames are identified by a destination MAC value of 01:80:c2:00:00:0e and Ethertype value of 0x88F7.

Contextsystem l2cp-transparency l2cp-statistics ptp in-trap-to-cpu-packets number
Treein-trap-to-cpu-packets
Default0
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
in-tunneled-packets number
Description

System level incoming Precision Time Protocol Peer-Delay tunneled frames.

Cumulative of all Ethernet interfaces including all the tunneled PTP frames. PTP frames are identified by a destination MAC value of 01:80:c2:00:00:0e and Ethertype value of 0x88F7.

Contextsystem l2cp-transparency l2cp-statistics ptp in-tunneled-packets number
Treein-tunneled-packets
Default0
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
last-clear string
Description Timestamp of the last time the PTP counters were cleared.
Contextsystem l2cp-transparency l2cp-statistics ptp last-clear string
Treelast-clear
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
total-in-discarded-packets number
Description

System level incoming L2CP discarded frames.

Cumulative of all Ethernet interfaces including all the discarded L2CP frames. L2CP frames are identified by a destination MAC value of 01:80:c2:00:00:0X or 01:80:c2:00:00:2X, being X any value in the 0..F range.

Contextsystem l2cp-transparency l2cp-statistics total-in-discarded-packets number
Treetotal-in-discarded-packets
Default0
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
total-in-packets number
Description

System level total incoming L2CP frames.

Cumulative of all Ethernet interfaces including the tunneled, discarded and copy-to-cpu L2CP frames. L2CP frames are identified by a destination MAC value of 01:80:c2:00:00:0X or 01:80:c2:00:00:2X, being X any value in the 0..F range.

Contextsystem l2cp-transparency l2cp-statistics total-in-packets number
Treetotal-in-packets
Default0
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
total-in-trap-to-cpu-packets number
Description

System level incoming L2CP copy-to-cpu frames.

Cumulative of all Ethernet interfaces including all the L2CP frames that are copied to CPU. L2CP frames are identified by a destination MAC value of 01:80:c2:00:00:0X or 01:80:c2:00:00:2X, being X any value in the 0..F range.

Contextsystem l2cp-transparency l2cp-statistics total-in-trap-to-cpu-packets number
Treetotal-in-trap-to-cpu-packets
Default0
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
total-in-tunneled-packets number
Description

System level incoming L2CP tunneled frames.

Cumulative of all Ethernet interfaces including all the tunneled L2CP frames. L2CP frames are identified by a destination MAC value of 01:80:c2:00:00:0X or 01:80:c2:00:00:2X, being X any value in the 0..F range.

Contextsystem l2cp-transparency l2cp-statistics total-in-tunneled-packets number
Treetotal-in-tunneled-packets
Default0
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
xstp
Description Container for Spanning Tree Protocols.
Contextsystem l2cp-transparency l2cp-statistics xstp
Treexstp
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
in-trap-to-cpu-packets number
Description

System level incoming Spanning Tree Protocol frames copied to CPU.

Cumulative of all Ethernet interfaces including all the copy-to-cpu Spanning Tree frames. Spanning Tree frames are identified by a destination MAC value of 01:80:c2:00:00:00 and LLC value 0x42.

Contextsystem l2cp-transparency l2cp-statistics xstp in-trap-to-cpu-packets number
Treein-trap-to-cpu-packets
Default0
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
in-tunneled-packets number
Description

System level incoming Spanning Tree tunneled frames.

Cumulative of all Ethernet interfaces including all the tunneled Spanning Tree frames. xSTP frames are identified by a destination MAC value of 01:80:c2:00:00:00 and LLC value 0x42.

Contextsystem l2cp-transparency l2cp-statistics xstp in-tunneled-packets number
Treein-tunneled-packets
Default0
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
last-clear string
Description Timestamp of the last time the xSTP counters were cleared.
Contextsystem l2cp-transparency l2cp-statistics xstp last-clear string
Treelast-clear
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5

lacp

Description Enter the lacp context
Context system lacp
Treelacp
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

system-id string

Description The MAC address portion of the node's System ID. This is combined with the system priority to construct the 8-octet system-id
Contextsystem lacp system-id string
Treesystem-id
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

system-priority number

Description System priority used by the node on this LAG interface. Lower value is higher priority for determining which node is the controlling system.
Contextsystem lacp system-priority number
Treesystem-priority
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

license id string

Description List of licenses configured on the system
Contextsystem license id string
Treelicense
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
Max. Elements5

id string

Description Unique identifier for this license
Context system license id string
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

admin-state keyword

Description Enable or disable the use of this license
Contextsystem license id string admin-state keyword
Treeadmin-state
Defaultdisable
Options
  • enable

  • disable

Configurable True
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

data string

Description

Content of the license

This content includes a preceding UUID, followed by a space and the license data.

For example: 00000000-0000-0000-0000-000000000000 aACUAx...rYzNRPT0AAAAA

Contextsystem license id string data string
Treedata
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

description string

Description A user provided description for the license
Contextsystem license id string description string
Treedescription
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

expiration-date string

Description Date and time the license will expire
Contextsystem license id string expiration-date string
Treeexpiration-date
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

expired boolean

Description Indicates if the license has expired
Context system license id string expired boolean
Treeexpired
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

in-use boolean

Description Indicates if the license is actively in use
Contextsystem license id string in-use boolean
Treein-use
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

issued-date string

Description Date and time the license was issued
Context system license id string issued-date string
Treeissued-date
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

preferred boolean

Description

Set a license as being preferred

Amongst all valid licenses, the preferred license will be chosen to become active. If no license is set as preferred or the preferred license is not valid, the valid license with the most distant expiry is chosen to become active.

Only a single license can be set as preferred.

Contextsystem license id string preferred boolean
Treepreferred
Defaultfalse
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

valid boolean

Description Indicates if the license is valid for use
Contextsystem license id string valid boolean
Treevalid
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

lldp

Description Top-level container for LLDP configuration and state data
Contextsystem lldp
Treelldp
ConfigurableTrue
PlatformsSupported on all platforms

admin-state keyword

Description Enable or disable LLDP at the system level
Contextsystem lldp admin-state keyword
Treeadmin-state
Defaultenable
Options
  • enable

  • disable

Configurable True
PlatformsSupported on all platforms

chassis-id string

Description The Chassis ID is a mandatory TLV which identifies the chassis component of the endpoint identifier associated with the transmitting LLDP agent
Contextsystem lldp chassis-id string
Treechassis-id
ConfigurableFalse
PlatformsSupported on all platforms

chassis-id-type keyword

Description

The source for the chassis identifier string

It is an enumerator defined by the LldpChassisIdSubtype object from IEEE 802.1AB MIB.

Contextsystem lldp chassis-id-type keyword
Treechassis-id-type
DefaultMAC_ADDRESS
Options
  • CHASSIS_COMPONENT

    Chassis identifier based on the value of entPhysicalAlias object defined in IETF RFC 2737

  • INTERFACE_ALIAS

    Chassis identifier based on the value of ifAlias object defined in IETF RFC 2863

  • PORT_COMPONENT

    Chassis identifier based on the value of entPhysicalAlias object defined in IETF RFC 2737 for a port or backplane component

  • MAC_ADDRESS

    Chassis identifier based on the value of a unicast source address (encoded in network byte order and IEEE 802.3 canonical bit order), of a port on the containing chassis as defined in IEEE Std 802-2001

  • NETWORK_ADDRESS

    Chassis identifier based on a network address, associated with a particular chassis. The encoded address is composed of two fields. The first field is a single octet, representing the IANA AddressFamilyNumbers value for the specific address type, and the second field is the network address value

  • INTERFACE_NAME

    Chassis identifier based on the name of the interface, e.g., the value of ifName object defined in IETF RFC 2863

  • LOCAL

    Chassis identifier based on a locally defined value

ConfigurableFalse
PlatformsSupported on all platforms

hello-timer number

Description System level hello timer for the LLDP protocol
Contextsystem lldp hello-timer number
Treehello-timer
Default30
Unitsseconds
Configurable True
PlatformsSupported on all platforms

hold-multiplier number

Description

System level hold multiplier, used to define neighbor aging

This field defines how many hellos need to be missed before a neighbor is aged out.

This field also is used along with the 'hello-timer' field to define the TTL TLV in outgoing LLDPDUs.

Contextsystem lldp hold-multiplier number
Treehold-multiplier
Default4
ConfigurableTrue
PlatformsSupported on all platforms

interface name reference

Description List of interfaces on which LLDP can be enabled
Contextsystem lldp interface name reference
Treeinterface
ConfigurableTrue
PlatformsSupported on all platforms
name reference
Description Reference to the LLDP Ethernet interface
Contextsystem lldp interface name reference
Referenceinterface name string
ConfigurableTrue
PlatformsSupported on all platforms
admin-state keyword
Description Enable or disable LLDP on the interface
Contextsystem lldp interface name reference admin-state keyword
Treeadmin-state
Defaultenable
Options
  • enable

  • disable

Configurable True
PlatformsSupported on all platforms
neighbor id string
Description List of LLDP neighbors on this interface
Contextsystem lldp interface name reference neighbor id string
Treeneighbor
ConfigurableFalse
PlatformsSupported on all platforms
id string
Description System generated identifier for the remote neighbor
Contextsystem lldp interface name reference neighbor id string
ConfigurableFalse
PlatformsSupported on all platforms
capability name identityref
Description List of LLDP system capabilities advertised by the neighbor
Contextsystem lldp interface name reference neighbor id string capability name identityref
Treecapability
ConfigurableFalse
PlatformsSupported on all platforms
name identityref
Description

Name of the system capability advertised by the neighbor

Capabilities are represented in a bitmap that defines the primary functions of the system. The capabilities are defined in IEEE 802.1AB.

Contextsystem lldp interface name reference neighbor id string capability name identityref
Options
  • OTHER

    Other capability not specified; bit position 1

  • REPEATER

    Repeater capability; bit position 2

  • MAC_BRIDGE

    MAC bridge capability; bit position 3

  • WLAN_ACCESS_POINT

    WLAN access point capability; bit position 4

  • ROUTER

    Router; bit position 5

  • TELEPHONE

    Telephone capability; bit position 6

  • DOCSIS_CABLE_DEVICE

    DOCSIS cable device; bit position 7

  • STATION_ONLY

    Station only capability, for devices that implement only an end station capability, and for which none of the other capabilities apply; bit position 8

  • C_VLAN

    C-VLAN component of a VLAN Bridge; bit position 9

  • S_VLAN

    S-VLAN component of a VLAN Bridge; bit position 10

  • TWO_PORT_MAC_RELAY

    Two-port MAC Relay (TPMR) capability; bit position 11

ConfigurableFalse
PlatformsSupported on all platforms
chassis-id string
Description

The chassis ID of the remote neighbor

The Chassis ID is a mandatory TLV which identifies the chassis component of the endpoint identifier associated with the transmitting LLDP agent

Contextsystem lldp interface name reference neighbor id string chassis-id string
Treechassis-id
ConfigurableFalse
PlatformsSupported on all platforms
chassis-id-type keyword
Description

The type of identifier used in the chassis-id field

This field identifies the format and source of the chassis identifier string. It is an enumerator defined by the LldpChassisIdSubtype object from IEEE 802.1AB MIB.

Contextsystem lldp interface name reference neighbor id string chassis-id-type keyword
Treechassis-id-type
DefaultMAC_ADDRESS
Options
  • CHASSIS_COMPONENT

    Chassis identifier based on the value of entPhysicalAlias object defined in IETF RFC 2737

  • INTERFACE_ALIAS

    Chassis identifier based on the value of ifAlias object defined in IETF RFC 2863

  • PORT_COMPONENT

    Chassis identifier based on the value of entPhysicalAlias object defined in IETF RFC 2737 for a port or backplane component

  • MAC_ADDRESS

    Chassis identifier based on the value of a unicast source address (encoded in network byte order and IEEE 802.3 canonical bit order), of a port on the containing chassis as defined in IEEE Std 802-2001

  • NETWORK_ADDRESS

    Chassis identifier based on a network address, associated with a particular chassis. The encoded address is composed of two fields. The first field is a single octet, representing the IANA AddressFamilyNumbers value for the specific address type, and the second field is the network address value

  • INTERFACE_NAME

    Chassis identifier based on the name of the interface, e.g., the value of ifName object defined in IETF RFC 2863

  • LOCAL

    Chassis identifier based on a locally defined value

ConfigurableFalse
PlatformsSupported on all platforms
custom-tlv type number oui string oui-subtype string
Description List of custom LLDP TLVs from a neighbor
Contextsystem lldp interface name reference neighbor id string custom-tlv type number oui string oui-subtype string
Treecustom-tlv
ConfigurableFalse
PlatformsSupported on all platforms
oui string
Description

The organizationally unique identifier field from the custom TLV

This field shall contain the organization's OUI as defined in Clause 9 of IEEE Std 802. The high-order octet is 0 and the low-order 3 octets are the SMI Network Management Private Enterprise Code of the Vendor in network byte order, as defined in the 'Assigned Numbers' RFC [RFC3232].

Contextsystem lldp interface name reference neighbor id string custom-tlv type number oui string oui-subtype string
ConfigurableFalse
PlatformsSupported on all platforms
oui-subtype string
Description

The subtype value defined by the OUI for this custom TLV

The organizationally defined subtype field shall contain a unique subtype value assigned by the defining organization.

Contextsystem lldp interface name reference neighbor id string custom-tlv type number oui string oui-subtype string
ConfigurableFalse
PlatformsSupported on all platforms
management-address address string
Description List of management addresses received from the remote LLDP neighbor
Contextsystem lldp interface name reference neighbor id string management-address address string
Treemanagement-address
ConfigurableFalse
PlatformsSupported on all platforms
address string
Description

The management address received from the remote LLDP neighbor

The Management Address is a mandatory TLV which identifies a network address associated with the LLDP agent, which can be used to reach the agent on the port identified in the Port ID TLV.

Contextsystem lldp interface name reference neighbor id string management-address address string
ConfigurableFalse
PlatformsSupported on all platforms
type keyword
Description

The type of management address referenced in the address field

The enumerated value for the network address type identified in this TLV. This enumeration is defined in the 'Assigned Numbers' RFC [RFC3232] and the ianaAddressFamilyNumbers object.

Contextsystem lldp interface name reference neighbor id string management-address address string type keyword
Treetype
Options
  • IPv4

    Use IPv4 address for management address type

  • IPv6

    Use IPv6 address for management address type

ConfigurableFalse
PlatformsSupported on all platforms
port-description string
Description

The description of the port referenced in the port-id field

The binary string containing the actual port identifier for the port which this LLDP PDU was transmitted. The source and format of this field is defined by PtopoPortId from RFC2922.

Contextsystem lldp interface name reference neighbor id string port-description string
Treeport-description
ConfigurableFalse
PlatformsSupported on all platforms
port-id (string | binary)
Description

The Port ID of the remote neighbor

The Port ID is a mandatory TLV which identifies the port component of the endpoint identifier associated with the transmitting LLDP agent. If the specified port is an IEEE 802.3 Repeater port, then this TLV is optional.

Contextsystem lldp interface name reference neighbor id string port-id (string | binary)
Treeport-id
ConfigurableFalse
PlatformsSupported on all platforms
port-id-type keyword
Description

The type of identifier used in the port-id field

This field identifies the format and source of the port identifier string. It is an enumerator defined by the PtopoPortIdType object from RFC2922.

Contextsystem lldp interface name reference neighbor id string port-id-type keyword
Treeport-id-type
Options
  • INTERFACE_ALIAS

    Chassis identifier based on the value of ifAlias object defined in IETF RFC 2863

  • PORT_COMPONENT

    Port identifier based on the value of entPhysicalAlias object defined in IETF RFC 2737 for a port component

  • MAC_ADDRESS

    Port identifier based on the value of a unicast source address (encoded in network byte order and IEEE 802.3 canonical bit order) associated with a port

  • NETWORK_ADDRESS

    Port identifier based on a network address, associated with a particular port

  • INTERFACE_NAME

    Port identifier based on the name of the interface, e.g., the value of ifName object defined in IETF RFC 2863

  • AGENT_CIRCUIT_ID

    Port identifer based on the circuit id in the DHCP relay agent information option as defined in IETF RFC 3046

  • LOCAL

    Port identifier based on a locally defined alphanumeric string

ConfigurableFalse
PlatformsSupported on all platforms
system-description string
Description

The system description of the remote neighbor

The system description field shall contain an alpha-numeric string that is the textual description of the network entity. The system description should include the full name and version identification of the system's hardware type, software operating system, and networking software. If implementations support IETF RFC 3418, the sysDescr object should be used for this field.

Contextsystem lldp interface name reference neighbor id string system-description string
Treesystem-description
String Length0 to 255
ConfigurableFalse
PlatformsSupported on all platforms
system-name string
Description

The administratively assigned name of the remote neighbor

The system name field shall contain an alpha-numeric string that indicates the system's administratively assigned name. The system name should be the system's fully qualified domain name. If implementations support IETF RFC 3418, the sysName object should be used for this field.

Contextsystem lldp interface name reference neighbor id string system-name string
Treesystem-name
String Length0 to 255
ConfigurableFalse
PlatformsSupported on all platforms
oper-state keyword
Description Details the operational state of LLDP on the interface
Contextsystem lldp interface name reference oper-state keyword
Treeoper-state
Options
  • up

    Component or process is operational

  • down

    Component or process is not operational

  • empty

    Component slot is empty

  • downloading

    Component is downloading image into memory

  • booting

    Component is booting downloaded image

  • starting

    Component image operational, application processes starting

  • failed

    Component or process has failed

  • synchronizing

    Component is currently being synchronized

  • upgrading

    Component is currently being upgraded

  • low-power

    Component is offline due to insufficient system power

  • degraded

    Component or process is in a degraded state

  • warm-reboot

    Component or process is currently warm rebooting

    This state is set during a warm reboot immediately following initiation of the reboot, continuing after startup until the system has completed audit. In this state the system will not accept configuration changes.

  • waiting

    Component or process is currently waiting

    This state can be set by event handler when the reinvoke-with-delay action is used, and indicates that the event handler is waiting for the provided delay before reinvoking the instance.

ConfigurableFalse
PlatformsSupported on all platforms
statistics
Description LLDP counters on each interface
Context system lldp interface name reference statistics
Treestatistics
ConfigurableFalse
PlatformsSupported on all platforms

management-address subinterface string

Description

List of subinterfaces to source management addresses from

This list is sent in the management address TLV by LLDP.

Contextsystem lldp management-address subinterface string
Treemanagement-address
ConfigurableTrue
PlatformsSupported on all platforms
subinterface string
Description Reference to the subinterface to source management addresses
Contextsystem lldp management-address subinterface string
String Length5 to 25
ConfigurableTrue
PlatformsSupported on all platforms
type keyword
Description

Types of addresses sent in the management address TLV

The enumerated value for the network address type identified in this TLV. This enumeration is defined in the 'Assigned Numbers' RFC [RFC3232] and the ianaAddressFamilyNumbers object.

Contextsystem lldp management-address subinterface string type keyword
Treetype
Options
  • IPv4

    Use IPv4 address for management address type

  • IPv6

    Use IPv6 address for management address type

ConfigurableTrue
PlatformsSupported on all platforms

statistics

Description Global LLDP counters
Context system lldp statistics
Treestatistics
ConfigurableFalse
PlatformsSupported on all platforms
frame-in number
Description The number of LLDP frames received
Context system lldp statistics frame-in number
Treeframe-in
Default0
ConfigurableFalse
PlatformsSupported on all platforms
frame-out number
Description The number of LLDP frames transmitted
Contextsystem lldp statistics frame-out number
Treeframe-out
Default0
ConfigurableFalse
PlatformsSupported on all platforms
last-clear string
Description Indicates the last time the counters were cleared
Contextsystem lldp statistics last-clear string
Treelast-clear
String Length20 to 32
ConfigurableFalse
PlatformsSupported on all platforms

system-description string

Description

Field detailing system description, including name and versions

The system description field shall contain an alpha-numeric string that is the textual description of the network entity. The system description should include the full name and version identification of the system's hardware type, software operating system, and networking software.

Contextsystem lldp system-description string
Treesystem-description
String Length0 to 255
ConfigurableFalse
PlatformsSupported on all platforms

system-name string

Description

The systems administratively assigned name

The system name field shall contain an alpha-numeric string that indicates the system's administratively assigned name. The system name should be the system's fully qualified domain name.

Contextsystem lldp system-name string
Treesystem-name
String Length0 to 255
ConfigurableFalse
PlatformsSupported on all platforms

trace-options keyword

Description LLDP trace options
Context system lldp trace-options keyword
Treetrace-options
Options
  • received

  • transmitted

  • common

ConfigurableTrue
PlatformsSupported on all platforms

load-balancing

Description Adjust system-wide ECMP load balancing options.
Contextsystem load-balancing
Treeload-balancing
ConfigurableTrue
PlatformsSupported on all platforms

hash-options

Description Container for packet header fields and other inputs used in hashing calculations
Contextsystem load-balancing hash-options
Treehash-options
ConfigurableTrue
PlatformsSupported on all platforms
destination-port boolean
Description Include the destination TCP/UDP port number in the hash calculation if the packet is an unfragmented IP packet carrying a TCP/UDP payload
Contextsystem load-balancing hash-options destination-port boolean
Treedestination-port
Defaulttrue
ConfigurableTrue
PlatformsSupported on all platforms
hash-seed number
Description

A configured hash seed to override the default value of 0

Different routers can be configured with different hash-seed values to minimize traffic polarization effects. This hash-seed is used by all hash-related CRC calculations including those take IP header fields, those that take Ethernet header fields and those that take MPLS labels.

Contextsystem load-balancing hash-options hash-seed number
Treehash-seed
Default0
ConfigurableTrue
PlatformsSupported on all platforms
ipv6-flow-label boolean
Description

Include the IPv6 flow label in the hash calculation if the packet is an IPv6 packet

It is expected that the IPv6 flow label value is written by the server or other host originating the flow and not changed by any intermediate switch or router.

Contextsystem load-balancing hash-options ipv6-flow-label boolean
Treeipv6-flow-label
Defaultfalse
ConfigurableTrue
PlatformsSupported on all platforms
protocol boolean
Description Include the IP protocol number in the hash calculation. For an IPv6 packet this is protocol value in the next-header field of the last extension header.
Contextsystem load-balancing hash-options protocol boolean
Treeprotocol
Defaulttrue
ConfigurableTrue
PlatformsSupported on all platforms
source-port boolean
Description Include the source TCP/UDP port number in the hash calculation if the packet is an unfragmented IP packet carrying a TCP/UDP payload
Contextsystem load-balancing hash-options source-port boolean
Treesource-port
Defaulttrue
ConfigurableTrue
PlatformsSupported on all platforms
vlan boolean
Description Include the received VLAN ID in the hash calculation
Contextsystem load-balancing hash-options vlan boolean
Treevlan
Defaulttrue
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4

logging

Description System logging provides the interface to syslog services to setup output entities on a selection of log sources.
Contextsystem logging
Treelogging
ConfigurableTrue
PlatformsSupported on all platforms

buffer buffer-name string

Description

Log files maintained in memory, non-persistent across system reboots

These files are stored at directory /var/log/srlinux/buffer. Rotation into multiple files is available.

Contextsystem logging buffer buffer-name string
Treebuffer
ConfigurableTrue
PlatformsSupported on all platforms
buffer-name string
Description Base name of the file(s) to be stored in memory
Contextsystem logging buffer buffer-name string
ConfigurableTrue
PlatformsSupported on all platforms
facility facility-name keyword
Description List of facilities to source messages from
Contextsystem logging buffer buffer-name string facility facility-name keyword
Treefacility
ConfigurableTrue
PlatformsSupported on all platforms
facility-name keyword
Description Name of a Linux syslog facility
Context system logging buffer buffer-name string facility facility-name keyword
Options
  • all

  • audit

  • auth

  • authpriv

  • console

  • cron

  • daemon

  • ftp

  • kern

  • lpr

  • mail

  • news

  • ntp

  • syslog

  • user

  • uucp

  • local0

  • local1

  • local2

  • local3

  • local4

  • local5

  • local6

  • local7

ConfigurableTrue
PlatformsSupported on all platforms
priority
Description Narrows the capture to a given severity, a range or a specific set of severities
Contextsystem logging buffer buffer-name string facility facility-name keyword priority
Treepriority
ConfigurableTrue
PlatformsSupported on all platforms
format (string | keyword)
Description

Text format of syslog messages to a local output (buffer, file or console), in legacy rsyslog $template style or one of the predefined templates

The default presents a date timestamp according to rfc3339. The predefined templates are the ones supported by rsyslogd.

Contextsystem logging buffer buffer-name string format (string | keyword)
Treeformat
DefaultRSYSLOG_FileFormat
Options
  • RSYSLOG_FileFormat

  • RSYSLOG_TraditionalFileFormat

  • RSYSLOG_DebugFormat

ConfigurableTrue
PlatformsSupported on all platforms
persist number
Description

Time in seconds to shadow the buffer to persistent storage

Setting this field to 0 results in the buffer not being persisted. A value other than 0 will result in the log being persisted to disk based on the configured value. Logs with a non-zero persist value are persisted automatically on rollover, or at the configured value.

Contextsystem logging buffer buffer-name string persist number
Treepersist
Range0 | 60 to 604800
Default0
Unitsseconds
Configurable True
PlatformsSupported on all platforms
rotate number
Description Number of files to keep in rotation when a maximum file size is reached
Contextsystem logging buffer buffer-name string rotate number
Treerotate
Default4
ConfigurableTrue
PlatformsSupported on all platforms
size string
Description

Number of bytes an individual output file cannot exceed

The field allows the 'K, M, or G' suffixes as shorthand. When reaching that size, a rotation happens and subsequent data is stored in a new file with the same base name.

Contextsystem logging buffer buffer-name string size string
Treesize
Default10M
ConfigurableTrue
PlatformsSupported on all platforms
subsystem subsystem-name keyword
Description Entity or entities that may produce messages to be captured
Contextsystem logging buffer buffer-name string subsystem subsystem-name keyword
Treesubsystem
ConfigurableTrue
PlatformsSupported on all platforms
subsystem-name keyword
Description Reference to an available subsystem to source messages from
Contextsystem logging buffer buffer-name string subsystem subsystem-name keyword
Options
  • aaa

  • accounting

  • acl

  • app

  • arpnd

  • bfd

  • bgp

  • bridgetable

  • chassis

  • debug

  • dhcp

  • ethcfm

  • evpn

  • fib

  • gnmi

  • gnsi

  • gribi

  • grpc

  • igmp

  • isis

  • json

  • lag

  • ldp

  • license

  • linux

  • lldp

  • log

  • mgmt

  • mirror

  • mld

  • mpls

  • netinst

  • ospf

  • p4rt

  • pcc

  • pim

  • platform

  • policy

  • pw

  • qos

  • sdk

  • sflow

  • staticroute

  • sync

  • twamp

  • vxlan

  • xdp

ConfigurableTrue
PlatformsSupported on all platforms
priority
Description Narrows the capture to a given severity, a range or a specific set of severities
Contextsystem logging buffer buffer-name string subsystem subsystem-name keyword priority
Treepriority
ConfigurableTrue
PlatformsSupported on all platforms

console

Description Hardware serial device normally used for bring-up and diagnostics
Contextsystem logging console
Treeconsole
ConfigurableTrue
PlatformsSupported on all platforms
facility facility-name keyword
Description List of facilities to source messages from
Contextsystem logging console facility facility-name keyword
Treefacility
ConfigurableTrue
PlatformsSupported on all platforms
facility-name keyword
Description Name of a Linux syslog facility
Context system logging console facility facility-name keyword
Options
  • all

  • audit

  • auth

  • authpriv

  • console

  • cron

  • daemon

  • ftp

  • kern

  • lpr

  • mail

  • news

  • ntp

  • syslog

  • user

  • uucp

  • local0

  • local1

  • local2

  • local3

  • local4

  • local5

  • local6

  • local7

ConfigurableTrue
PlatformsSupported on all platforms
priority
Description Narrows the capture to a given severity, a range or a specific set of severities
Contextsystem logging console facility facility-name keyword priority
Treepriority
ConfigurableTrue
PlatformsSupported on all platforms
format (string | keyword)
Description

Text format of syslog messages to a local output (buffer, file or console), in legacy rsyslog $template style or one of the predefined templates

The default presents a date timestamp according to rfc3339. The predefined templates are the ones supported by rsyslogd.

Contextsystem logging console format (string | keyword)
Treeformat
DefaultRSYSLOG_FileFormat
Options
  • RSYSLOG_FileFormat

  • RSYSLOG_TraditionalFileFormat

  • RSYSLOG_DebugFormat

ConfigurableTrue
PlatformsSupported on all platforms
subsystem subsystem-name keyword
Description Entity or entities that may produce messages to be captured
Contextsystem logging console subsystem subsystem-name keyword
Treesubsystem
ConfigurableTrue
PlatformsSupported on all platforms
subsystem-name keyword
Description Reference to an available subsystem to source messages from
Contextsystem logging console subsystem subsystem-name keyword
Options
  • aaa

  • accounting

  • acl

  • app

  • arpnd

  • bfd

  • bgp

  • bridgetable

  • chassis

  • debug

  • dhcp

  • ethcfm

  • evpn

  • fib

  • gnmi

  • gnsi

  • gribi

  • grpc

  • igmp

  • isis

  • json

  • lag

  • ldp

  • license

  • linux

  • lldp

  • log

  • mgmt

  • mirror

  • mld

  • mpls

  • netinst

  • ospf

  • p4rt

  • pcc

  • pim

  • platform

  • policy

  • pw

  • qos

  • sdk

  • sflow

  • staticroute

  • sync

  • twamp

  • vxlan

  • xdp

ConfigurableTrue
PlatformsSupported on all platforms
priority
Description Narrows the capture to a given severity, a range or a specific set of severities
Contextsystem logging console subsystem subsystem-name keyword priority
Treepriority
ConfigurableTrue
PlatformsSupported on all platforms

file file-name string

Description

Log files maintained on disk, persistent across system reboots

When a maximum file size is reached, the file is renamed and a maximum rotate number of them are kept.

Contextsystem logging file file-name string
Treefile
ConfigurableTrue
PlatformsSupported on all platforms
file-name string
Description Base name of the file(s) to be stored on disk
Contextsystem logging file file-name string
ConfigurableTrue
PlatformsSupported on all platforms
directory string
Description Fully qualified path of a directory where the log file(s) shall be maintained
Contextsystem logging file file-name string directory string
Treedirectory
Default/var/log/srlinux/file
ConfigurableTrue
PlatformsSupported on all platforms
facility facility-name keyword
Description List of facilities to source messages from
Contextsystem logging file file-name string facility facility-name keyword
Treefacility
ConfigurableTrue
PlatformsSupported on all platforms
facility-name keyword
Description Name of a Linux syslog facility
Context system logging file file-name string facility facility-name keyword
Options
  • all

  • audit

  • auth

  • authpriv

  • console

  • cron

  • daemon

  • ftp

  • kern

  • lpr

  • mail

  • news

  • ntp

  • syslog

  • user

  • uucp

  • local0

  • local1

  • local2

  • local3

  • local4

  • local5

  • local6

  • local7

ConfigurableTrue
PlatformsSupported on all platforms
priority
Description Narrows the capture to a given severity, a range or a specific set of severities
Contextsystem logging file file-name string facility facility-name keyword priority
Treepriority
ConfigurableTrue
PlatformsSupported on all platforms
format (string | keyword)
Description

Text format of syslog messages to a local output (buffer, file or console), in legacy rsyslog $template style or one of the predefined templates

The default presents a date timestamp according to rfc3339. The predefined templates are the ones supported by rsyslogd.

Contextsystem logging file file-name string format (string | keyword)
Treeformat
DefaultRSYSLOG_FileFormat
Options
  • RSYSLOG_FileFormat

  • RSYSLOG_TraditionalFileFormat

  • RSYSLOG_DebugFormat

ConfigurableTrue
PlatformsSupported on all platforms
rotate number
Description Number of files to keep in rotation when a maximum file size is reached
Contextsystem logging file file-name string rotate number
Treerotate
Default4
ConfigurableTrue
PlatformsSupported on all platforms
size string
Description

Number of bytes an individual output file cannot exceed

The field allows the 'K, M, or G' suffixes as shorthand. When reaching that size, a rotation happens and subsequent data is stored in a new file with the same base name.

Contextsystem logging file file-name string size string
Treesize
Default10M
ConfigurableTrue
PlatformsSupported on all platforms
subsystem subsystem-name keyword
Description Entity or entities that may produce messages to be captured
Contextsystem logging file file-name string subsystem subsystem-name keyword
Treesubsystem
ConfigurableTrue
PlatformsSupported on all platforms
subsystem-name keyword
Description Reference to an available subsystem to source messages from
Contextsystem logging file file-name string subsystem subsystem-name keyword
Options
  • aaa

  • accounting

  • acl

  • app

  • arpnd

  • bfd

  • bgp

  • bridgetable

  • chassis

  • debug

  • dhcp

  • ethcfm

  • evpn

  • fib

  • gnmi

  • gnsi

  • gribi

  • grpc

  • igmp

  • isis

  • json

  • lag

  • ldp

  • license

  • linux

  • lldp

  • log

  • mgmt

  • mirror

  • mld

  • mpls

  • netinst

  • ospf

  • p4rt

  • pcc

  • pim

  • platform

  • policy

  • pw

  • qos

  • sdk

  • sflow

  • staticroute

  • sync

  • twamp

  • vxlan

  • xdp

ConfigurableTrue
PlatformsSupported on all platforms
priority
Description Narrows the capture to a given severity, a range or a specific set of severities
Contextsystem logging file file-name string subsystem subsystem-name keyword priority
Treepriority
ConfigurableTrue
PlatformsSupported on all platforms

filter filter-name string

Description Describes a set of critieria that captured messages are required to fulfill
Contextsystem logging filter filter-name string
Treefilter
ConfigurableTrue
PlatformsSupported on all platforms
filter-name string
Description Name of the filter
Context system logging filter filter-name string
ConfigurableTrue
PlatformsSupported on all platforms
contains string
Description Text to find in the MSG property of messages to capture from the stream This is slower than prefix.
Contextsystem logging filter filter-name string contains string
Treecontains
ConfigurableTrue
PlatformsSupported on all platforms
facility facility-name keyword
Description List of facilities to source messages from
Contextsystem logging filter filter-name string facility facility-name keyword
Treefacility
ConfigurableTrue
PlatformsSupported on all platforms
facility-name keyword
Description Name of a Linux syslog facility
Context system logging filter filter-name string facility facility-name keyword
Options
  • all

  • audit

  • auth

  • authpriv

  • console

  • cron

  • daemon

  • ftp

  • kern

  • lpr

  • mail

  • news

  • ntp

  • syslog

  • user

  • uucp

  • local0

  • local1

  • local2

  • local3

  • local4

  • local5

  • local6

  • local7

ConfigurableTrue
PlatformsSupported on all platforms
priority
Description Narrows the capture to a given severity, a range or a specific set of severities
Contextsystem logging filter filter-name string facility facility-name keyword priority
Treepriority
ConfigurableTrue
PlatformsSupported on all platforms
prefix string
Description Text to be present at the beginning of the MSG property of a message This is a fast lookup.
Contextsystem logging filter filter-name string prefix string
Treeprefix
ConfigurableTrue
PlatformsSupported on all platforms
regex string
Description Extended regular expression to search in the MSG property of messages
Contextsystem logging filter filter-name string regex string
Treeregex
ConfigurableTrue
PlatformsSupported on all platforms
tag string
Description Text to be searched in the SYSLOGTAG property of messages Usually a program name or part of it.
Contextsystem logging filter filter-name string tag string
Treetag
ConfigurableTrue
PlatformsSupported on all platforms

network-instance reference

Description

Reference to a configured network-instance to run rsyslogd in

This network-instance will be used as a source for requests to remote syslog servers.

Contextsystem logging network-instance reference
Treenetwork-instance
Referencenetwork-instance name string
ConfigurableTrue
PlatformsSupported on all platforms

remote-server host (ipv4-address | ipv6-address | domain-name)

Description List of output remote syslog servers
Context system logging remote-server host (ipv4-address | ipv6-address | domain-name)
Treeremote-server
ConfigurableTrue
PlatformsSupported on all platforms
host (ipv4-address | ipv6-address | domain-name)
Description Domain or IP address of a remote syslog server destination
Contextsystem logging remote-server host (ipv4-address | ipv6-address | domain-name)
String Length1 to 253
ConfigurableTrue
PlatformsSupported on all platforms
facility facility-name keyword
Description List of facilities to source messages from
Contextsystem logging remote-server host (ipv4-address | ipv6-address | domain-name) facility facility-name keyword
Treefacility
ConfigurableTrue
PlatformsSupported on all platforms
facility-name keyword
Description Name of a Linux syslog facility
Context system logging remote-server host (ipv4-address | ipv6-address | domain-name) facility facility-name keyword
Options
  • all

  • audit

  • auth

  • authpriv

  • console

  • cron

  • daemon

  • ftp

  • kern

  • lpr

  • mail

  • news

  • ntp

  • syslog

  • user

  • uucp

  • local0

  • local1

  • local2

  • local3

  • local4

  • local5

  • local6

  • local7

ConfigurableTrue
PlatformsSupported on all platforms
priority
Description Narrows the capture to a given severity, a range or a specific set of severities
Contextsystem logging remote-server host (ipv4-address | ipv6-address | domain-name) facility facility-name keyword priority
Treepriority
ConfigurableTrue
PlatformsSupported on all platforms
format (string | keyword)
Description

Text format of syslog messages to a remote server, in legacy rsyslog $template style or one of the predefined templates

The default presents a date timestamp according to rfc3339. The predefined templates are the ones supported by rsyslogd.

Contextsystem logging remote-server host (ipv4-address | ipv6-address | domain-name) format (string | keyword)
Treeformat
DefaultRSYSLOG_SyslogProtocol23Format
Options
  • RSYSLOG_ForwardFormat

  • RSYSLOG_SyslogProtocol23Format

  • RSYSLOG_TraditionalForwardFormat

ConfigurableTrue
PlatformsSupported on all platforms
remote-port number
Description Transport port for syslog to use for messages sent to a remote server
Contextsystem logging remote-server host (ipv4-address | ipv6-address | domain-name) remote-port number
Treeremote-port
Default514
ConfigurableTrue
PlatformsSupported on all platforms
source-address (ipv4-address | ipv6-address)
Description

Source address for syslog to use for messages sent to a remote server

If no source address is provided, then packets will be sent to the remote server using the source address indicated by the routing table.

Contextsystem logging remote-server host (ipv4-address | ipv6-address | domain-name) source-address (ipv4-address | ipv6-address)
Treesource-address
ConfigurableTrue
PlatformsSupported on all platforms
subsystem subsystem-name keyword
Description Entity or entities that may produce messages to be captured
Contextsystem logging remote-server host (ipv4-address | ipv6-address | domain-name) subsystem subsystem-name keyword
Treesubsystem
ConfigurableTrue
PlatformsSupported on all platforms
subsystem-name keyword
Description Reference to an available subsystem to source messages from
Contextsystem logging remote-server host (ipv4-address | ipv6-address | domain-name) subsystem subsystem-name keyword
Options
  • aaa

  • accounting

  • acl

  • app

  • arpnd

  • bfd

  • bgp

  • bridgetable

  • chassis

  • debug

  • dhcp

  • ethcfm

  • evpn

  • fib

  • gnmi

  • gnsi

  • gribi

  • grpc

  • igmp

  • isis

  • json

  • lag

  • ldp

  • license

  • linux

  • lldp

  • log

  • mgmt

  • mirror

  • mld

  • mpls

  • netinst

  • ospf

  • p4rt

  • pcc

  • pim

  • platform

  • policy

  • pw

  • qos

  • sdk

  • sflow

  • staticroute

  • sync

  • twamp

  • vxlan

  • xdp

ConfigurableTrue
PlatformsSupported on all platforms
priority
Description Narrows the capture to a given severity, a range or a specific set of severities
Contextsystem logging remote-server host (ipv4-address | ipv6-address | domain-name) subsystem subsystem-name keyword priority
Treepriority
ConfigurableTrue
PlatformsSupported on all platforms
transport keyword
Description Transport protocol for syslog to use for messages sent to a remote server
Contextsystem logging remote-server host (ipv4-address | ipv6-address | domain-name) transport keyword
Treetransport
Defaultudp
Options
  • udp

  • tcp

Configurable True
PlatformsSupported on all platforms

subsystem-facility keyword

Description Linux facility that internal application subsystems will use
Contextsystem logging subsystem-facility keyword
Treesubsystem-facility
Defaultlocal6
Options
  • all

  • audit

  • auth

  • authpriv

  • console

  • cron

  • daemon

  • ftp

  • kern

  • lpr

  • mail

  • news

  • ntp

  • syslog

  • user

  • uucp

  • local0

  • local1

  • local2

  • local3

  • local4

  • local5

  • local6

  • local7

  • auth

  • authpriv

  • cron

  • daemon

  • ftp

  • kern

  • lpr

  • mail

  • news

  • ntp

  • syslog

  • user

  • uucp

  • local0

  • local1

  • local2

  • local3

  • local4

  • local5

  • local6

  • local7

ConfigurableTrue
PlatformsSupported on all platforms

use-fqdn boolean

Description Use the FQDN instead of only the hostname for logging messages
Contextsystem logging use-fqdn boolean
Treeuse-fqdn
Defaultfalse
ConfigurableTrue
PlatformsSupported on all platforms

maintenance

Description Top-level container for Maintenance Mode configuration
Contextsystem maintenance
Treemaintenance
ConfigurableTrue
PlatformsSupported on all platforms

group name string

Description List of user-configured maintenance groups
Contextsystem maintenance group name string
Treegroup
ConfigurableTrue
PlatformsSupported on all platforms
name string
Description Name of the maintenance group.
Context system maintenance group name string
String Length1 to 255
ConfigurableTrue
PlatformsSupported on all platforms
maintenance-mode
Description Container with options for activating and deactivating maintenance mode for this group
Contextsystem maintenance group name string maintenance-mode
Treemaintenance-mode
ConfigurableTrue
PlatformsSupported on all platforms
admin-state keyword
Description

Enable or disable maintenance mode for this group

The enable setting is blocked if there is another maintenance group with at least one BGP session in its scope that overlaps with this maintenance group and that other maintenance group is currently in maintenance mode.

While a maintenance group is in maintenance mode it is not possible to modify the BGP configuration of its members.

Contextsystem maintenance group name string maintenance-mode admin-state keyword
Treeadmin-state
Defaultdisable
Options
  • enable

  • disable

Configurable True
PlatformsSupported on all platforms
members
Description Container for specifying the members of the maintenance group - i.e. the components that will eventually be taken out of service for repair or replacement.
Contextsystem maintenance group name string members
Treemembers
ConfigurableTrue
PlatformsSupported on all platforms
bgp
Description Container for specifying the BGP members of the maintenance group
Contextsystem maintenance group name string members bgp
Treebgp
ConfigurableTrue
PlatformsSupported on all platforms
network-instance name reference
Description List of network instances with one or more peers to be placed in maintenance mode
Contextsystem maintenance group name string members bgp network-instance name reference
Treenetwork-instance
ConfigurableTrue
PlatformsSupported on all platforms
neighbor reference
Description

List of BGP neighbors that belong to the network instance and that should be part of the maintenance group

It is not necessary to list neighbors that are members of peer-groups that are already listed.

If this list is empty and so is the group list, then the system interprets the meaning as ALL static and dynamic sessions belonging to the specified network-instance.

Contextsystem maintenance group name string members bgp network-instance name reference neighbor reference
Treeneighbor
Referencenetwork-instance name string protocols bgp neighbor peer-address (ipv4-address-with-zone | ipv6-address-with-zone)
ConfigurableTrue
PlatformsSupported on all platforms
peer-group reference
Description

List of BGP peer groups that belong to the network instance and that should be part of the maintenance group

If this list is empty and so is the neighbor list, then the system interprets the meaning as ALL static and dynamic sessions belonging to the specified network-instance.

Contextsystem maintenance group name string members bgp network-instance name reference peer-group reference
Treepeer-group
Referencenetwork-instance name string protocols bgp group group-name string
ConfigurableTrue
PlatformsSupported on all platforms

profile name string

Description Enter the profile list instance
Context system maintenance profile name string
Treeprofile
ConfigurableTrue
PlatformsSupported on all platforms
name string
Description Name of the maintenance profile
Context system maintenance profile name string
String Length1 to 255
ConfigurableTrue
PlatformsSupported on all platforms
bgp
Description Container for BGP policies used to achieve traffic draining
Contextsystem maintenance profile name string bgp
Treebgp
ConfigurableTrue
PlatformsSupported on all platforms

management

Description Enclosing container for options relating to management server
Contextsystem management
Treemanagement
ConfigurableTrue
PlatformsSupported on all platforms

openconfig

Description Top-level container for options relating to OpenConfig
Contextsystem management openconfig
Treeopenconfig
ConfigurableTrue
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
admin-state keyword
Description

Enable or disable the OpenConfig management server

This will disable OpenConfig throughout the system, and bring any gRPC servers that use it operationally down.

Contextsystem management openconfig admin-state keyword
Treeadmin-state
Options
  • enable

  • disable

Configurable True
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
oper-state keyword
Description Indicates the operational state of the OpenConfig management server
Contextsystem management openconfig oper-state keyword
Treeoper-state
Options
  • up

    Component or process is operational

  • down

    Component or process is not operational

  • empty

    Component slot is empty

  • downloading

    Component is downloading image into memory

  • booting

    Component is booting downloaded image

  • starting

    Component image operational, application processes starting

  • failed

    Component or process has failed

  • synchronizing

    Component is currently being synchronized

  • upgrading

    Component is currently being upgraded

  • low-power

    Component is offline due to insufficient system power

  • degraded

    Component or process is in a degraded state

  • warm-reboot

    Component or process is currently warm rebooting

    This state is set during a warm reboot immediately following initiation of the reboot, continuing after startup until the system has completed audit. In this state the system will not accept configuration changes.

  • waiting

    Component or process is currently waiting

    This state can be set by event handler when the reinvoke-with-delay action is used, and indicates that the event handler is waiting for the provided delay before reinvoking the instance.

ConfigurableFalse
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

mirroring

Description Top level container for configuration and operational state for mirroring
Contextsystem mirroring
Treemirroring
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7250 IXR-10e, 7250 IXR-6e

mirroring-instance name string

Description Mirroring instances configured on the local system
Contextsystem mirroring mirroring-instance name string
Treemirroring-instance
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7250 IXR-10e, 7250 IXR-6e
Max. Elements8
name string
Description A unique name identifying the mirroring instance
Contextsystem mirroring mirroring-instance name string
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7250 IXR-10e, 7250 IXR-6e
admin-state keyword
Description This leaf contains the configured, desired state of the mirroring instance.
Contextsystem mirroring mirroring-instance name string admin-state keyword
Treeadmin-state
Defaultenable
Options
  • enable

  • disable

Configurable True
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7250 IXR-10e, 7250 IXR-6e
description string
Description A user-entered description of this mirroring instance.
Contextsystem mirroring mirroring-instance name string description string
Treedescription
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7250 IXR-10e, 7250 IXR-6e
mirror-destination
Description Configure mirror destination
Context system mirroring mirroring-instance name string mirror-destination
Treemirror-destination
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7250 IXR-10e, 7250 IXR-6e
local string
Description subinterface of type local-mirror-dest used as local mirror destination
Contextsystem mirroring mirroring-instance name string mirror-destination local string
Treelocal
String Length5 to 25
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7250 IXR-10e, 7250 IXR-6e
remote
Description Enable the remote context
Context system mirroring mirroring-instance name string mirror-destination remote
Treeremote
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7250 IXR-10e, 7250 IXR-6e
tunnel-end-points
Description Enter the tunnel-end-points context
Context system mirroring mirroring-instance name string mirror-destination remote tunnel-end-points
Treetunnel-end-points
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7250 IXR-10e, 7250 IXR-6e
oper-state keyword
Description This leaf contains the operational state of the remote mirror tunnel
Contextsystem mirroring mirroring-instance name string mirror-destination remote tunnel-end-points oper-state keyword
Treeoper-state
Options
  • up

    Component or process is operational

  • down

    Component or process is not operational

  • empty

    Component slot is empty

  • downloading

    Component is downloading image into memory

  • booting

    Component is booting downloaded image

  • starting

    Component image operational, application processes starting

  • failed

    Component or process has failed

  • synchronizing

    Component is currently being synchronized

  • upgrading

    Component is currently being upgraded

  • low-power

    Component is offline due to insufficient system power

  • degraded

    Component or process is in a degraded state

  • warm-reboot

    Component or process is currently warm rebooting

    This state is set during a warm reboot immediately following initiation of the reboot, continuing after startup until the system has completed audit. In this state the system will not accept configuration changes.

  • waiting

    Component or process is currently waiting

    This state can be set by event handler when the reinvoke-with-delay action is used, and indicates that the event handler is waiting for the provided delay before reinvoking the instance.

ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7250 IXR-10e, 7250 IXR-6e
statistics
Description Enter the statistics context
Context system mirroring mirroring-instance name string mirror-destination statistics
Treestatistics
ConfigurableFalse
Platforms7220 IXR-D4, 7220 IXR-D5, 7250 IXR-10e, 7250 IXR-6e
mirror-source
Description Configure mirror source(s)
Context system mirroring mirroring-instance name string mirror-source
Treemirror-source
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7250 IXR-10e, 7250 IXR-6e
acl
Description Enter the acl context
Context system mirroring mirroring-instance name string mirror-source acl
Treeacl
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7250 IXR-10e, 7250 IXR-6e
acl-filter name reference type reference
Description List IPv4, IPv6 ACL filters
Context system mirroring mirroring-instance name string mirror-source acl acl-filter name reference type reference
Treeacl-filter
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7250 IXR-10e, 7250 IXR-6e
entry sequence-id reference
Description Add a list entry for entry
Context system mirroring mirroring-instance name string mirror-source acl acl-filter name reference type reference entry sequence-id reference
Treeentry
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7250 IXR-10e, 7250 IXR-6e
interface name string
Description List of interfaces used as mirror source
Contextsystem mirroring mirroring-instance name string mirror-source interface name string
Treeinterface
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7250 IXR-10e, 7250 IXR-6e
subinterface name string
Description List of subinterfaces used as mirror source
Contextsystem mirroring mirroring-instance name string mirror-source subinterface name string
Treesubinterface
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7250 IXR-10e, 7250 IXR-6e
oper-down-reason keyword
Description The reason for the mirror source being operational down. When the reason is not applicable, it is due to the mirror instance being shutdown or the mirror source is operational up.
Contextsystem mirroring mirroring-instance name string mirror-source subinterface name string oper-down-reason keyword
Treeoper-down-reason
Options
  • mirror-source-ingress-table-full

  • mirror-source-egress-table-full

  • not-applicable

ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7250 IXR-10e, 7250 IXR-6e
oper-state keyword
Description This leaf contains the operational state of the mirror-source.
Contextsystem mirroring mirroring-instance name string mirror-source subinterface name string oper-state keyword
Treeoper-state
Options
  • up

    Component or process is operational

  • down

    Component or process is not operational

  • empty

    Component slot is empty

  • downloading

    Component is downloading image into memory

  • booting

    Component is booting downloaded image

  • starting

    Component image operational, application processes starting

  • failed

    Component or process has failed

  • synchronizing

    Component is currently being synchronized

  • upgrading

    Component is currently being upgraded

  • low-power

    Component is offline due to insufficient system power

  • degraded

    Component or process is in a degraded state

  • warm-reboot

    Component or process is currently warm rebooting

    This state is set during a warm reboot immediately following initiation of the reboot, continuing after startup until the system has completed audit. In this state the system will not accept configuration changes.

  • waiting

    Component or process is currently waiting

    This state can be set by event handler when the reinvoke-with-delay action is used, and indicates that the event handler is waiting for the provided delay before reinvoking the instance.

ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7250 IXR-10e, 7250 IXR-6e
oper-down-reason keyword
Description The reason for the mirroring instance being operational down
Contextsystem mirroring mirroring-instance name string oper-down-reason keyword
Treeoper-down-reason
Options
  • mirror-inst-admin-down

  • no-mirror-source

  • local-mirror-subif-down

  • remote-mirror-dst-unreachable

ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7250 IXR-10e, 7250 IXR-6e
oper-state keyword
Description This leaf contains the operational state of the mirroring instance.
Contextsystem mirroring mirroring-instance name string oper-state keyword
Treeoper-state
Options
  • up

    Component or process is operational

  • down

    Component or process is not operational

  • empty

    Component slot is empty

  • downloading

    Component is downloading image into memory

  • booting

    Component is booting downloaded image

  • starting

    Component image operational, application processes starting

  • failed

    Component or process has failed

  • synchronizing

    Component is currently being synchronized

  • upgrading

    Component is currently being upgraded

  • low-power

    Component is offline due to insufficient system power

  • degraded

    Component or process is in a degraded state

  • warm-reboot

    Component or process is currently warm rebooting

    This state is set during a warm reboot immediately following initiation of the reboot, continuing after startup until the system has completed audit. In this state the system will not accept configuration changes.

  • waiting

    Component or process is currently waiting

    This state can be set by event handler when the reinvoke-with-delay action is used, and indicates that the event handler is waiting for the provided delay before reinvoking the instance.

ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7250 IXR-10e, 7250 IXR-6e

mpls

Description Container for system wide MPLS label management
Contextsystem mpls
Treempls
ConfigurableTrue
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

label-ranges

Description Container for managing MPLS label blocks
Contextsystem mpls label-ranges
Treelabel-ranges
ConfigurableTrue
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
dynamic name string
Description

List of dynamic label blocks

When a client application binds its operation to a dynamic label block that client application is expected to just ask for the next available label within the dynamic label block.

At this time a dynamic label block cannot be shared by multiple different clients/protocols. Each protocol needing dynamic labels must have its own label block.

Contextsystem mpls label-ranges dynamic name string
Treedynamic
ConfigurableTrue
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
name string
Description The name of the dynamic label block
Context system mpls label-ranges dynamic name string
String Length1 to 255
ConfigurableTrue
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
end-label number
Description

The ending label value of the label block.

When the status is not-ready or updating, the state value may be different from the configured value

Contextsystem mpls label-ranges dynamic name string end-label number
Treeend-label
Range16 to 1048575
ConfigurableTrue
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
free-labels number
Description

The number of labels that are currently available and free in this block.

When the status is not-ready or updating, the state value may be different from the configured value

Contextsystem mpls label-ranges dynamic name string free-labels number
Treefree-labels
ConfigurableFalse
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
start-label number
Description

The starting label value of the label block.

When the status is not-ready or updating, the state value may be different from the configured value

Contextsystem mpls label-ranges dynamic name string start-label number
Treestart-label
Range16 to 1048575
ConfigurableTrue
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
status keyword
Description The status of the MPLS label block
Context system mpls label-ranges dynamic name string status keyword
Treestatus
Options
  • ready

    The label block is ready to use.

  • not-ready

    The label block is not ready to use.

  • delete-pending

    The label block is in the process of being deleted.

  • updating

    The label block is available to use but the new limits do not apply yet.

ConfigurableFalse
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
user index number
Description The list of protocols that are using this label block. If the block is not shared there will only be 1 user
Contextsystem mpls label-ranges dynamic name string user index number
Treeuser
ConfigurableFalse
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
index number
Description Index number used to enumerate the clients
Contextsystem mpls label-ranges dynamic name string user index number
ConfigurableFalse
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
owner identityref
Description The protocol or service associated with the client
Contextsystem mpls label-ranges dynamic name string user index number owner identityref
Treeowner
Options
  • bgp

    The BGP/MP-BGP protocol carrying labels.

  • ldp

    The label distribution protocol (LDP).

  • sr-isis

    The IS-IS protocol with segment routing extensions

  • sr-ospf

    The OSPFv2 protocol with segment routing extensions

  • sr-ospfv3

    The OSPFv3 protocol with segment routing extensions

  • sr-policy

    A pseudo protocol representing SR policies

  • static-mpls

    A pseudo protocol representing static MPLS routes

  • evpn

    The BGP/EVPN protocol carrying labels.

  • network-instance

    The module allocating labels for bgp based vpn/evpn services

ConfigurableFalse
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
static name string
Description

List of static label blocks

When a client application binds its operation to a static label block that client application is expected to specify the exact label value it wants to use every time it requests a label within the static label block.

Contextsystem mpls label-ranges static name string
Treestatic
ConfigurableTrue
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
name string
Description The name of the static label block
Context system mpls label-ranges static name string
String Length1 to 255
ConfigurableTrue
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
end-label number
Description

The ending label value of the label block.

When the status is not-ready or updating, the state value may be different from the configured value

Contextsystem mpls label-ranges static name string end-label number
Treeend-label
Range16 to 1048575
ConfigurableTrue
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
free-labels number
Description

The number of labels that are currently available and free in this block.

When the status is not-ready or updating, the state value may be different from the configured value

Contextsystem mpls label-ranges static name string free-labels number
Treefree-labels
ConfigurableFalse
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
shared boolean
Description When set to true, the label block can be shared by multiple protoccols. When set to false, the label block is dedicated to one protocol.
Contextsystem mpls label-ranges static name string shared boolean
Treeshared
Defaulttrue
ConfigurableTrue
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
start-label number
Description

The starting label value of the label block.

When the status is not-ready or updating, the state value may be different from the configured value

Contextsystem mpls label-ranges static name string start-label number
Treestart-label
Range16 to 1048575
ConfigurableTrue
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
status keyword
Description The status of the MPLS label block
Context system mpls label-ranges static name string status keyword
Treestatus
Options
  • ready

    The label block is ready to use.

  • not-ready

    The label block is not ready to use.

  • delete-pending

    The label block is in the process of being deleted.

  • updating

    The label block is available to use but the new limits do not apply yet.

ConfigurableFalse
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
user index number
Description The list of protocols that are using this label block. If the block is not shared there will only be 1 user
Contextsystem mpls label-ranges static name string user index number
Treeuser
ConfigurableFalse
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
index number
Description Index number used to enumerate the clients
Contextsystem mpls label-ranges static name string user index number
ConfigurableFalse
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
owner identityref
Description The protocol or service associated with the client
Contextsystem mpls label-ranges static name string user index number owner identityref
Treeowner
Options
  • bgp

    The BGP/MP-BGP protocol carrying labels.

  • ldp

    The label distribution protocol (LDP).

  • sr-isis

    The IS-IS protocol with segment routing extensions

  • sr-ospf

    The OSPFv2 protocol with segment routing extensions

  • sr-ospfv3

    The OSPFv3 protocol with segment routing extensions

  • sr-policy

    A pseudo protocol representing SR policies

  • static-mpls

    A pseudo protocol representing static MPLS routes

  • evpn

    The BGP/EVPN protocol carrying labels.

  • network-instance

    The module allocating labels for bgp based vpn/evpn services

ConfigurableFalse
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

services

Description Container for system wide Services MPLS label management
Contextsystem mpls services
Treeservices
ConfigurableTrue
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

mtu

Description Top-level container for configuration and state data related to the system MTU
Contextsystem mtu
Treemtu
ConfigurableTrue
PlatformsSupported on all platforms

default-ip-mtu number

Description

System default IP MTU in bytes including the IP header but excluding Ethernet overhead

The 7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D3, 7220 IXR-H2, and 7220 IXR-H3 systems support a maximum IP MTU of 9398 bytes.

Contextsystem mtu default-ip-mtu number
Treedefault-ip-mtu
Range1280 to 9486
Default1500
ConfigurableTrue
PlatformsSupported on all platforms

default-l2-mtu number

Description

System default Layer-2 MTU in bytes for bridged subinterfaces

It includes the ethernet overhead and VLAN tags but excludes 4-bytes FCS. The default-l2-mtu is also used as the oper-mac-vrf-mtu and oper-vpws-mtu value if the network-instance does not have subinterfaces.

The 7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D3, 7220 IXR-H2, and 7220 IXR-H3 systems support a maximum L2 MTU of 9412 bytes.

Contextsystem mtu default-l2-mtu number
Treedefault-l2-mtu
Range1500 to 9500
Default9232
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5

default-mpls-mtu number

Description System default MPLS MTU in bytes including the size of the transmitted label stack.
Contextsystem mtu default-mpls-mtu number
Treedefault-mpls-mtu
Range1284 to 9496
Default1508
ConfigurableTrue
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

default-port-mtu number

Description

System default port MTU in bytes including ethernet overhead but excluding 4-bytes FCS

The 7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D3, 7220 IXR-H2, and 7220 IXR-H3 systems support a maximum port MTU of 9412 bytes.

Contextsystem mtu default-port-mtu number
Treedefault-port-mtu
Range1500 to 9500
Default9232
ConfigurableTrue
PlatformsSupported on all platforms

min-path-mtu number

Description

Sets the minimum path MTU to use when receiving an ICMP fragmentation needed message

This is controlled via the kernel min_pmtu option. In the event an ICMP fragmentation needed message is received by the kernel, the system will drop the session to this MTU to allow packets to traverse the entire path.

Contextsystem mtu min-path-mtu number
Treemin-path-mtu
Range552 to 9232
Default552
ConfigurableTrue
PlatformsSupported on all platforms

multicast

Description system multicast information
Context system multicast
Treemulticast
ConfigurableTrue
PlatformsSupported on all platforms

multicast-ids

Description system multicast id information
Context system multicast multicast-ids
Treemulticast-ids
ConfigurableTrue
PlatformsSupported on all platforms
statistics
Description Enter the statistics context
Context system multicast multicast-ids statistics
Treestatistics
ConfigurableFalse
PlatformsSupported on all platforms
multicast-id-user-type user keyword
Description the type of the user of multicast id in the system.
Contextsystem multicast multicast-ids statistics multicast-id-user-type user keyword
Treemulticast-id-user-type
ConfigurableFalse
PlatformsSupported on all platforms

multicast-forwarding-information-base

Description System Multicast Forwarding Information Base table
Contextsystem multicast-forwarding-information-base
Treemulticast-forwarding-information-base
ConfigurableFalse
PlatformsSupported on all platforms

multicast-route network-instance reference source (ipv4-address | ipv6-address) group (ipv4-address | ipv6-address)

Description List of all the MFIB entries in the system
Contextsystem multicast-forwarding-information-base multicast-route network-instance reference source (ipv4-address | ipv6-address) group (ipv4-address | ipv6-address)
Treemulticast-route
ConfigurableFalse
PlatformsSupported on all platforms
line-card-replication-index number
Description

Line card Replication Index (LRID) allocated by mfib_mgr

Upon programming an MFIB entry, mfib_mgr requests a Multicast Identifier (MCID) to mcid_mgr and based on the response with an allocated MCID, mfib_mgr allocates a LRID for the entry. A value 0 indicates that no MCID was received for the entry, and therefore the MFIB entry cannot forward multicast traffic.

Contextsystem multicast-forwarding-information-base multicast-route network-instance reference source (ipv4-address | ipv6-address) group (ipv4-address | ipv6-address) line-card-replication-index number
Treeline-card-replication-index
Default0
ConfigurableFalse
PlatformsSupported on all platforms

name

Description Contains configuration and state related to system naming
Contextsystem name
Treename
ConfigurableTrue
PlatformsSupported on all platforms

domain-name string

Description The system domain name
Context system name domain-name string
Treedomain-name
String Length1 to 253
ConfigurableTrue
PlatformsSupported on all platforms

host-name string

Description The system host name
Context system name host-name string
Treehost-name
String Length1 to 63
ConfigurableTrue
PlatformsSupported on all platforms

network-instance

Description Enable the network-instance context
Context system network-instance
Treenetwork-instance
ConfigurableTrue
PlatformsSupported on all platforms

protocols

Description The routing protocols that are enabled for this network-instance.
Contextsystem network-instance protocols
Treeprotocols
ConfigurableTrue
PlatformsSupported on all platforms
bgp-vpn
Description Enable the bgp-vpn context
Context system network-instance protocols bgp-vpn
Treebgp-vpn
ConfigurableTrue
PlatformsSupported on all platforms
bgp-instance id number
Description List of bgp-vpn instances configured in the system network-instance. Only one instance allowed in the current release.
Contextsystem network-instance protocols bgp-vpn bgp-instance id number
Treebgp-instance
ConfigurableTrue
PlatformsSupported on all platforms
Max. Elements1
route-distinguisher
Description Route Distinguisher (RD) of the bgp-vpn instance.
Contextsystem network-instance protocols bgp-vpn bgp-instance id number route-distinguisher
Treeroute-distinguisher
ConfigurableTrue
PlatformsSupported on all platforms
rd (route-distinguisher-type-0 | route-distinguisher-type-1 | route-distinguisher-type-2 | route-distinguisher-type-2b)
Description Route Distinguisher (RD) of the system bgp-vpn instance. The RD is auto-derived as <ip-address>:0 where 'ip-address' is the ipv4 address associated to the subinterface lo0.1.
Contextsystem network-instance protocols bgp-vpn bgp-instance id number route-distinguisher rd (route-distinguisher-type-0 | route-distinguisher-type-1 | route-distinguisher-type-2 | route-distinguisher-type-2b)
Treerd
ConfigurableFalse
PlatformsSupported on all platforms
route-distinguisher-origin keyword
Description

Origin of the operational Route Distinguisher (RD) of the bgp-vpn instance.

'Auto-derived-from-system-ip:0' refers to the RD for the EVPN Ethernet Segment routes that is automatically allocated with the format <ip-address>:0 where 'ip-address' is the ipv4 address associated to the subinterface lo0.1.

Contextsystem network-instance protocols bgp-vpn bgp-instance id number route-distinguisher route-distinguisher-origin keyword
Treeroute-distinguisher-origin
Options
  • auto-derived-from-system-ip:0

  • none

Configurable False
PlatformsSupported on all platforms
route-target
Description Route Target (RT) of the system bgp-vpn instance.
Contextsystem network-instance protocols bgp-vpn bgp-instance id number route-target
Treeroute-target
ConfigurableTrue
PlatformsSupported on all platforms
export-route-target-origin keyword
Description

Origin of the operational export Route Target (RT) of the bgp-vpn instance.

'Auto-derived-from-esi-bytes-1-6' refers to the ES-import RT for the EVPN Ethernet Segment routes that is derived from bytes 1 to 6 of the Ethernet Segment Identifier of the route.

Contextsystem network-instance protocols bgp-vpn bgp-instance id number route-target export-route-target-origin keyword
Treeexport-route-target-origin
Options
  • auto-derived-from-esi-bytes-1-6

  • none

Configurable False
PlatformsSupported on all platforms
export-rt (string | string | string | string | string | string | string | string)
Description

Export Route Target (RT) in the system bgp-vpn instance.

When used for evpn ES routes as ES-import Route Target, the RT is auto-derived from the high-order 6-octet portion of the 9-octet ESI value. Note that the ESI value excludes the left-most byte, which is reserved for the ESI type. The RT is encoded into the ES-import extended community advertised along with the ES route.

Contextsystem network-instance protocols bgp-vpn bgp-instance id number route-target export-rt (string | string | string | string | string | string | string | string)
Treeexport-rt
ConfigurableFalse
PlatformsSupported on all platforms
import-route-target-origin keyword
Description

Origin of the operational import Route Target (RT) of the bgp-vpn instance.

'Auto-derived-from-esi-bytes-1-6' refers to the ES-import RT for the EVPN Ethernet Segment routes that is derived from bytes 1 to 6 of the Ethernet Segment Identifier of the route.

Contextsystem network-instance protocols bgp-vpn bgp-instance id number route-target import-route-target-origin keyword
Treeimport-route-target-origin
Options
  • auto-derived-from-esi-bytes-1-6

  • none

Configurable False
PlatformsSupported on all platforms
import-rt (string | string | string | string | string | string | string | string)
Description

Import Route Target (RT) in the system bgp-vpn instance.

When used for evpn ES routes as ES-import Route Target, the RT is auto-derived from the high-order 6-octet portion of the 9-octet ESI value. Note that the ESI value excludes the left-most byte, which is reserved for the ESI type. The RT is encoded into the ES-import extended community received along with the ES route.

Contextsystem network-instance protocols bgp-vpn bgp-instance id number route-target import-rt (string | string | string | string | string | string | string | string)
Treeimport-rt
ConfigurableFalse
PlatformsSupported on all platforms
evpn
Description Enable the evpn context
Context system network-instance protocols evpn
Treeevpn
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
ethernet-segments
Description Enable the ethernet-segments context
Context system network-instance protocols evpn ethernet-segments
Treeethernet-segments
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
bgp-instance id reference
Description bgp global instances configured in net-instance
Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference
Treebgp-instance
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
Max. Elements1
ethernet-segment name string
Description Ethernet Segment configuration and state.
Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string
Treeethernet-segment
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
Max. Elements1024
association
Description Enter the association context
Context system network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string association
Treeassociation
ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
network-instance name string
Description network instance associated to this ethernet-segment
Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string association network-instance name string
Treenetwork-instance
ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
bgp-instance instance number
Description bgp-instance associated to this ethernet-segment
Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string association network-instance name string bgp-instance instance number
Treebgp-instance
ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
computed-designated-forwarder-candidates
Description Enter the computed-designated-forwarder-candidates context
Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string association network-instance name string bgp-instance instance number computed-designated-forwarder-candidates
Treecomputed-designated-forwarder-candidates
ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
designated-forwarder-candidate address (ipv4-address | ipv6-address)
Description designated forwarder candidates for this evi
Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string association network-instance name string bgp-instance instance number computed-designated-forwarder-candidates designated-forwarder-candidate address (ipv4-address | ipv6-address)
Treedesignated-forwarder-candidate
ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
add-time string
Description The date and time when the designated-forwarder-candidate was added to the designated forwarder candidate list for this evi
Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string association network-instance name string bgp-instance instance number computed-designated-forwarder-candidates designated-forwarder-candidate address (ipv4-address | ipv6-address) add-time string
Treeadd-time
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
designated-forwarder boolean
Description Indicates if this designated-forwarder-candidate is the designated-forwarder.
Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string association network-instance name string bgp-instance instance number computed-designated-forwarder-candidates designated-forwarder-candidate address (ipv4-address | ipv6-address) designated-forwarder boolean
Treedesignated-forwarder
Defaultfalse
ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
designated-forwarder-activation-start-time string
Description Indicates the time at which the designated-forwarder activation timer started.
Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string association network-instance name string bgp-instance instance number designated-forwarder-activation-start-time string
Treedesignated-forwarder-activation-start-time
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
designated-forwarder-activation-time number
Description Indicates the number of seconds for the activation timer to run, for this node to become the designated forwarder for this bgp instance.
Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string association network-instance name string bgp-instance instance number designated-forwarder-activation-time number
Treedesignated-forwarder-activation-time
Unitsseconds
ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
designated-forwarder-role-last-change string
Description Indicates the time at which the designated-forwarder role was changed.
Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string association network-instance name string bgp-instance instance number designated-forwarder-role-last-change string
Treedesignated-forwarder-role-last-change
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
autodiscovery-per-ethernet-segment-routes
Description Enter the autodiscovery-per-ethernet-segment-routes context
Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string autodiscovery-per-ethernet-segment-routes
Treeautodiscovery-per-ethernet-segment-routes
ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
label
Description The encoded label value and type in the EVPN NLRI
Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string autodiscovery-per-ethernet-segment-routes label
Treelabel
ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
value number
Description

The value of the label field

If the route is an EVPN MPLS route, the mpls-label is read out of the 20-bit high order value. If the route is an EVPN VXLAN route, the vni is read out of the 24-bit value. If the route is an EVPN SRv6 route, this field is set to zero if no transposition is used and set to a non-zero value if transposition is used. For all the cases, if this is an Auto-Discovery per ES route, this leaf is set to zero.

Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string autodiscovery-per-ethernet-segment-routes label value number
Treevalue
Range0 to 16777215
ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
neighbor (ipv4-address-with-zone | ipv6-address-with-zone)
Description If the route was learned from a BGP neighbor, this is the IPv4 or IPv6 address of that neighbor.
Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string autodiscovery-per-ethernet-segment-routes neighbor (ipv4-address-with-zone | ipv6-address-with-zone)
Treeneighbor
ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
route-distinguisher (route-distinguisher-type-0 | route-distinguisher-type-1 | route-distinguisher-type-2 | route-distinguisher-type-2b)
Description The route distinguisher encoded in the NLRI.
Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string autodiscovery-per-ethernet-segment-routes route-distinguisher (route-distinguisher-type-0 | route-distinguisher-type-1 | route-distinguisher-type-2 | route-distinguisher-type-2b)
Treeroute-distinguisher
ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
df-election
Description Enter the df-election context
Context system network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string df-election
Treedf-election
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
algorithm
Description Enter the algorithm context
Context system network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string df-election algorithm
Treealgorithm
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
manual-alg
Description Enable the manual-alg context
Context system network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string df-election algorithm manual-alg
Treemanual-alg
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
primary-evi-range start-evi number
Description evi range for this ethernet-segment
Context system network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string df-election algorithm manual-alg primary-evi-range start-evi number
Treeprimary-evi-range
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
preference-alg
Description Enable the preference-alg context
Context system network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string df-election algorithm preference-alg
Treepreference-alg
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
capabilities
Description Enter the capabilities context
Context system network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string df-election algorithm preference-alg capabilities
Treecapabilities
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
timers
Description Enter the timers context
Context system network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string df-election timers
Treetimers
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
esi string
Description

The 10-byte Ethernet Segment Identifier of the ethernet segment.

ESI-0 or MAX-ESI values are not allowed. ESI values with bytes 1-6 all zeros are not allowed since they would produce a null ESI-import route-target.

Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string esi string
Treeesi
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
esi-label number
Description

The esi label allocated for this ethernet-segment.

The esi-label is advertised by the EVPN Auto-Discovery-Ethernet-Segment Advertisement routes and it is expected on received EVPN packets that were generated as multicast packets from this ethernet-segments peers.

Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string esi-label number
Treeesi-label
Range16 to 1048575
ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
ethernet-segment-routes
Description Enter the ethernet-segment-routes context
Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string ethernet-segment-routes
Treeethernet-segment-routes
ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
route-distinguisher (route-distinguisher-type-0 | route-distinguisher-type-1 | route-distinguisher-type-2 | route-distinguisher-type-2b)
Description The route distinguisher encoded in the NLRI.
Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string ethernet-segment-routes route-distinguisher (route-distinguisher-type-0 | route-distinguisher-type-1 | route-distinguisher-type-2 | route-distinguisher-type-2b)
Treeroute-distinguisher
ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
interface ethernet-interface reference
Description Add a list entry for interface
Context system network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string interface ethernet-interface reference
Treeinterface
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
Max. Elements1
multi-homing-mode keyword
Description

Multi-homing mode of the ethernet segment.

The state of this leaf can be different than the configured value in cases where the configured value is 'all-active' and the multi-homing mode advertised by the ES peers in the AD per-ES routes is 'single-active'. In this case, the state of this leaf will show 'single-active'.

Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string multi-homing-mode keyword
Treemulti-homing-mode
Defaultall-active
Options
  • all-active

  • single-active

Configurable True
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
next-hop l3-next-hop (ipv4-address | ipv6-address)
Description Enter the next-hop list instance
Context system network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string next-hop l3-next-hop (ipv4-address | ipv6-address)
Treenext-hop
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
Max. Elements1
evi start number
Description evi range for this ethernet-segment association
Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string next-hop l3-next-hop (ipv4-address | ipv6-address) evi start number
Treeevi
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
Max. Elements1
oper-down-reason keyword
Description The reason for the ethernet-segment being down in the bgp-instance
Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string oper-down-reason keyword
Treeoper-down-reason
Options
  • admin-disabled

  • no-nexthop-address

  • no-originating-address

  • no-associated-interface

  • associated-interface-oper-down

  • no-esi

  • no-esi-label

ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
oper-multi-homing-mode keyword
Description

Operational Multi-homing mode of the ethernet segment.

The state of this leaf can be different than the configured value in cases where the configured value is 'all-active' and the multi-homing mode advertised by the ES peers in the AD per-ES routes is 'single-active'. In this case, the state of this leaf will show 'single-active'.

Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string oper-multi-homing-mode keyword
Treeoper-multi-homing-mode
Options
  • all-active

  • single-active

Configurable False
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
oper-state keyword
Description This leaf contains the operational state of ethernet segment.
Contextsystem network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string oper-state keyword
Treeoper-state
Options
  • up

    Component or process is operational

  • down

    Component or process is not operational

  • empty

    Component slot is empty

  • downloading

    Component is downloading image into memory

  • booting

    Component is booting downloaded image

  • starting

    Component image operational, application processes starting

  • failed

    Component or process has failed

  • synchronizing

    Component is currently being synchronized

  • upgrading

    Component is currently being upgraded

  • low-power

    Component is offline due to insufficient system power

  • degraded

    Component or process is in a degraded state

  • warm-reboot

    Component or process is currently warm rebooting

    This state is set during a warm reboot immediately following initiation of the reboot, continuing after startup until the system has completed audit. In this state the system will not accept configuration changes.

  • waiting

    Component or process is currently waiting

    This state can be set by event handler when the reinvoke-with-delay action is used, and indicates that the event handler is waiting for the provided delay before reinvoking the instance.

ConfigurableFalse
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
routes
Description Enter the routes context
Context system network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string routes
Treeroutes
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
ethernet-segment
Description Enter the ethernet-segment context
Context system network-instance protocols evpn ethernet-segments bgp-instance id reference ethernet-segment name string routes ethernet-segment
Treeethernet-segment
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
timers
Description Enter the timers context
Context system network-instance protocols evpn ethernet-segments timers
Treetimers
ConfigurableTrue
Platforms7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5

ntp

Description Top-level container for NTP configuration and state
Contextsystem ntp
Treentp
ConfigurableTrue
PlatformsSupported on all platforms

admin-state keyword

Description Enables the system NTP client and indicates that the system should attempt to synchronize the clock
Contextsystem ntp admin-state keyword
Treeadmin-state
Options
  • enable

  • disable

Configurable True
PlatformsSupported on all platforms

oper-state keyword

Description Details the operational state of the NTP client
Contextsystem ntp oper-state keyword
Treeoper-state
Options
  • up

    Component or process is operational

  • down

    Component or process is not operational

  • empty

    Component slot is empty

  • downloading

    Component is downloading image into memory

  • booting

    Component is booting downloaded image

  • starting

    Component image operational, application processes starting

  • failed

    Component or process has failed

  • synchronizing

    Component is currently being synchronized

  • upgrading

    Component is currently being upgraded

  • low-power

    Component is offline due to insufficient system power

  • degraded

    Component or process is in a degraded state

  • warm-reboot

    Component or process is currently warm rebooting

    This state is set during a warm reboot immediately following initiation of the reboot, continuing after startup until the system has completed audit. In this state the system will not accept configuration changes.

  • waiting

    Component or process is currently waiting

    This state can be set by event handler when the reinvoke-with-delay action is used, and indicates that the event handler is waiting for the provided delay before reinvoking the instance.

ConfigurableFalse
PlatformsSupported on all platforms

server address (ipv4 | ipv6 | domain-name)

Description List of NTP servers to use for system clock synchronization
Contextsystem ntp server address (ipv4 | ipv6 | domain-name)
Treeserver
ConfigurableTrue
PlatformsSupported on all platforms
address (ipv4 | ipv6 | domain-name)
Description

Domain or IP address of the NTP server

IP address may be either IPv4 or IPv6.

Domain resolution requires working DNS configuration in the same network-instance.

Contextsystem ntp server address (ipv4 | ipv6 | domain-name)
String Length1 to 253
ConfigurableTrue
PlatformsSupported on all platforms
iburst boolean
Description Indicates whether this server should enable burst synchronization or not iburst, or initial burst, improves the time taken for initial synchronization by sending a burst of eight packets instead of the usual one, these packets are spaced by a two second delay
Contextsystem ntp server address (ipv4 | ipv6 | domain-name) iburst boolean
Treeiburst
Defaultfalse
ConfigurableTrue
PlatformsSupported on all platforms
jitter number
Description Measurement of the variance in latency on the network
Contextsystem ntp server address (ipv4 | ipv6 | domain-name) jitter number
Treejitter
Unitsmilliseconds
ConfigurableFalse
PlatformsSupported on all platforms
offset number
Description Estimate of the current time offset from the peer This is the time difference between the local and reference clock.
Contextsystem ntp server address (ipv4 | ipv6 | domain-name) offset number
Treeoffset
Unitsmicroseconds
ConfigurableFalse
PlatformsSupported on all platforms
prefer boolean
Description Indicates whether this server should be preferred or not All other things being equal, this host will be chosen for synchronization among a set of correctly operating NTP servers
Contextsystem ntp server address (ipv4 | ipv6 | domain-name) prefer boolean
Treeprefer
Defaultfalse
ConfigurableTrue
PlatformsSupported on all platforms
root-delay number
Description The round-trip delay to the server
Context system ntp server address (ipv4 | ipv6 | domain-name) root-delay number
Treeroot-delay
Unitsmilliseconds
ConfigurableFalse
PlatformsSupported on all platforms
root-dispersion number
Description Dispersion (epsilon) represents the maximum error inherent in the measurement
Contextsystem ntp server address (ipv4 | ipv6 | domain-name) root-dispersion number
Treeroot-dispersion
Unitsmilliseconds
ConfigurableFalse
PlatformsSupported on all platforms
stratum number
Description Indicates the level of the server in the NTP hierarchy as number increases, the accuracy is degraded. Primary servers are stratum 1 while a maximum value of 16 indicates unsynchronized. The values have the following meanings: 0 unspecified or invalid 1 primary server (e.g., equipped with a GPS receiver) 2-15 secondary server (via NTP) 16 unsynchronized 17-255 reserved
Contextsystem ntp server address (ipv4 | ipv6 | domain-name) stratum number
Treestratum
ConfigurableFalse
PlatformsSupported on all platforms

source-address (ipv4-address | ipv6-address)

Description Source address for NTP to use for messages sent to a remote server
Contextsystem ntp source-address (ipv4-address | ipv6-address)
Treesource-address
ConfigurableTrue
PlatformsSupported on all platforms

synchronized (ipv4-address | ipv6-address | domain-name | string)

Description Address of the NTP server that the local client is synchronized to This field is set to 'unsynchronized', if the local client is not synchronized
Contextsystem ntp synchronized (ipv4-address | ipv6-address | domain-name | string)
Treesynchronized
String Length1 to 253
ConfigurableFalse
PlatformsSupported on all platforms

packet-link-qualification

Description Top-level container for gNOI Packet Link Qualification profiles
Contextsystem packet-link-qualification
Treepacket-link-qualification
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

profile name string

Description List of configured Packet Link Qualification profiles
Contextsystem packet-link-qualification profile name string
Treeprofile
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
name string
Description Name of the Packet Link Qualification profile
Contextsystem packet-link-qualification profile name string
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
asic-loopback
Description

ASIC loopback

Use the ASIC loopback mode

Contextsystem packet-link-qualification profile name string asic-loopback
Treeasic-loopback
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
ntp
Description Enter the ntp context
Context system packet-link-qualification profile name string ntp
Treentp
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
end-time string
Description End time of the test
Context system packet-link-qualification profile name string ntp end-time string
Treeend-time
String Length20 to 32
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
start-time string
Description Start time of the test
Context system packet-link-qualification profile name string ntp start-time string
Treestart-time
String Length20 to 32
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
teardown-time string
Description Time at which the test should be torn down
Contextsystem packet-link-qualification profile name string ntp teardown-time string
Treeteardown-time
String Length20 to 32
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
packet-generator
Description Packet generator endpoint
Context system packet-link-qualification profile name string packet-generator
Treepacket-generator
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
packet-rate number
Description Packet rate of the packet generator
Context system packet-link-qualification profile name string packet-generator packet-rate number
Treepacket-rate
Range1 to 4294967295
Unitspackets per second
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
packet-size number
Description Packet size (in bytes) of the packet generator
Contextsystem packet-link-qualification profile name string packet-generator packet-size number
Treepacket-size
Range64 to 8184
Unitsbytes
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
rpc
Description Enter the rpc context
Context system packet-link-qualification profile name string rpc
Treerpc
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
duration number
Description Duration of the test
Context system packet-link-qualification profile name string rpc duration number
Treeduration
Range1 to 4294967295
Unitsseconds
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
post-sync-duration number
Description Duration of the post-sync phase
Context system packet-link-qualification profile name string rpc post-sync-duration number
Treepost-sync-duration
Unitsseconds
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
pre-sync-duration number
Description Duration of the pre-sync phase
Context system packet-link-qualification profile name string rpc pre-sync-duration number
Treepre-sync-duration
Unitsseconds
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
setup-duration number
Description Duration of the setup phase
Context system packet-link-qualification profile name string rpc setup-duration number
Treesetup-duration
Range20 to 4294967295
Unitsseconds
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
teardown-duration number
Description Duration of the teardown phase
Context system packet-link-qualification profile name string rpc teardown-duration number
Treeteardown-duration
Range15 to 4294967295
Unitsseconds
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

protocols

Description The routing protocols that are supported by the system
Contextsystem protocols
Treeprotocols
ConfigurableTrue
PlatformsSupported on all platforms

bgp

Description Enable the bgp context
Context system protocols bgp
Treebgp
ConfigurableTrue
PlatformsSupported on all platforms
restart-max-wait number
Description

The maximum amount of time that BGP will wait to receive End of RIB markers from all peers and for all address families that were up prior to restart.

After this time elapses BGP declares that convergence has occurred and sends its own EOR markers to its peers.

Contextsystem protocols bgp restart-max-wait number
Treerestart-max-wait
Range0 to 3600
Default600
Unitsseconds
Configurable True
PlatformsSupported on all platforms

ra-guard-policy name string

Description List containing RA Guard Policy and parameters
Contextsystem ra-guard-policy name string
Treera-guard-policy
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5
Max. Elements64

name string

Description RA Guard Policy name
Context system ra-guard-policy name string
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5

action keyword

Description Describes the RA Guard Policy action for RA Messages matching the specified attributes. RA Messages not matching the specified attributes will be handled in the opposite manner.
Contextsystem ra-guard-policy name string action keyword
Treeaction
Defaultdiscard
Options
  • accept

  • discard

Configurable True
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5

hop-limit number

Description Verifies the minimum advertised hop count limit, RA message value must e equal to or greater than hop-limit. If not specified the verification is skipped.
Contextsystem ra-guard-policy name string hop-limit number
Treehop-limit
Range1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5

managed-config-flag boolean

Description Causes the RA Guard policy to match IPv6 RA messages with the M (Managed address) flag set. If not specified the verification is skipped.
Contextsystem ra-guard-policy name string managed-config-flag boolean
Treemanaged-config-flag
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5

other-config-flag boolean

Description Causes the RA Guard policy to match IPv6 RA messages with the O (Other config) flag set. If not specified the verification is skipped.
Contextsystem ra-guard-policy name string other-config-flag boolean
Treeother-config-flag
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5

router-preference keyword

Description Verifies that the advertised default router preference parameter value is equal to or less than the specified limit. If not specified the verification is skipped.
Contextsystem ra-guard-policy name string router-preference keyword
Treerouter-preference
Options
  • high

  • medium

  • low

ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5

sflow

Description Context to configure sFlow Agent parameters and report sFlow state
Contextsystem sflow
Treesflow
ConfigurableTrue
PlatformsSupported on all platforms

admin-state keyword

Description Administratively enable or disable sFlow for the system
Contextsystem sflow admin-state keyword
Treeadmin-state
Defaultdisable
Options
  • enable

  • disable

Configurable True
PlatformsSupported on all platforms

collector collector-id number

Description List of sFlow collectors to which sFlow sample data is sent
Contextsystem sflow collector collector-id number
Treecollector
ConfigurableTrue
PlatformsSupported on all platforms
Max. Elements8
collector-id number
Description Specify the collector ID
Context system sflow collector collector-id number
Range1 to 8
ConfigurableTrue
PlatformsSupported on all platforms
next-hop (ipv4-address | ipv6-address)
Description Specifies the active IP next hop used to reach the associated collector
Contextsystem sflow collector collector-id number next-hop (ipv4-address | ipv6-address)
Treenext-hop
ConfigurableFalse
PlatformsSupported on all platforms
port number
Description Specifies the destination UDP port number to be used in sFlow packets
Contextsystem sflow collector collector-id number port number
Treeport
Default6343
ConfigurableTrue
PlatformsSupported on all platforms

dscp number

Description

Specify sFlow DSCP value

This value specifies the DSCP value used in IP header of samples sent to the associated collectors.

Contextsystem sflow dscp number
Treedscp
Range0 to 63
Default0
ConfigurableTrue
Platforms7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

sample-rate number

Description

Specify sFlow sample rate

This value is the rate at which traffic will be sampled at a rate of 1:N received packets.

Contextsystem sflow sample-rate number
Treesample-rate
Range1 to 2000000
Default10000
ConfigurableTrue
PlatformsSupported on all platforms

sample-size number

Description

Specify sFlow sample size

This value specifies the number of bytes the sFlow agent samples from each frame.

Contextsystem sflow sample-size number
Treesample-size
Range256 | 512
Default256
ConfigurableTrue
PlatformsSupported on all platforms

source-address (ipv4-address | ipv6-address)

Description Specifies the IP address to be used as the source address in sFlow packets
Contextsystem sflow source-address (ipv4-address | ipv6-address)
Treesource-address
ConfigurableTrue
PlatformsSupported on all platforms

statistics

Description Enter the statistics context
Context system sflow statistics
Treestatistics
ConfigurableFalse
PlatformsSupported on all platforms

snmp

Description Top-level container for SNMP configuration and state
Contextsystem snmp
Treesnmp
ConfigurableTrue
PlatformsSupported on all platforms

access-group name string

Description List of configured SNMP access-groups
Contextsystem snmp access-group name string
Treeaccess-group
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
name string
Description Name of the SNMP access-group
Context system snmp access-group name string
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
admin-state keyword
Description Enables the SNMP access-group
Context system snmp access-group name string admin-state keyword
Treeadmin-state
Defaultenable
Options
  • enable

  • disable

Configurable True
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
community-entry name string
Description List of configured SNMPv2 communities
Contextsystem snmp access-group name string community-entry name string
Treecommunity-entry
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
name string
Description Unique name for the SNMPv2 community.
Contextsystem snmp access-group name string community-entry name string
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
community string
Description SNMPv2 community
Context system snmp access-group name string community-entry name string community string
Treecommunity
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
description string
Description Description for the SNMPv2 community
Context system snmp access-group name string community-entry name string description string
Treedescription
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
prefix-list (ipv4-prefix | ipv6-prefix)
Description

Prefixes where this community can be used, both IPv4 and IPv6 addresses.

A /32 or /128 mask can be used to limit it to a single ip-address

Contextsystem snmp access-group name string community-entry name string prefix-list (ipv4-prefix | ipv6-prefix)
Treeprefix-list
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
Max. Elements16
description string
Description Description for this access-group
Context system snmp access-group name string description string
Treedescription
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
security-entry name string
Description List of configured SNMPv3 users
Context system snmp access-group name string security-entry name string
Treesecurity-entry
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
name string
Description Unique name of the SNMPv3 security
Context system snmp access-group name string security-entry name string
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
authentication
Description Authentication parameters for this user.
Contextsystem snmp access-group name string security-entry name string authentication
Treeauthentication
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
password string
Description

The user authentication password, supplied either as cleartext or as a hashed value.

If provided as cleartext, the system will hash the value on input, storing only the hashed value. If provided as a hashed value, the value should include any '$' characters, for example '$ar2$aOvsuj0ALlU=$r750fMa3ZEA/Di8dIfU2fQ=='.

Contextsystem snmp access-group name string security-entry name string authentication password string
Treepassword
String Length8 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
protocol keyword
Description Authentication protocol used by this user.
Contextsystem snmp access-group name string security-entry name string authentication protocol keyword
Treeprotocol
Defaulthmac-md5-96
Options
  • hmac-md5-96

    MD5

  • hmac-sha1-96

    SHA

  • hmac-sha2-224

    SHA-224

  • hmac-sha2-256

    SHA-256

  • hmac-sha2-384

    SHA-384

  • hmac-sha2-512

    SHA-512

ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
description string
Description Description for this user
Context system snmp access-group name string security-entry name string description string
Treedescription
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
privacy
Description Privacy parameters for this user.
Context system snmp access-group name string security-entry name string privacy
Treeprivacy
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
password string
Description

The user privacy password, supplied either as cleartext or as a hashed value. If not provided, authentication/password will be used.

If provided as cleartext, the system will hash the value on input, storing only the hashed value. If provided as a hashed value, the value should include any '$' characters, for example '$ar2$aOvsuj0ALlU=$r750fMa3ZEA/Di8dIfU2fQ=='.

Contextsystem snmp access-group name string security-entry name string privacy password string
Treepassword
String Length8 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
protocol keyword
Description Privacy protocol used by this user.
Context system snmp access-group name string security-entry name string privacy protocol keyword
Treeprotocol
Defaultcbc-des
Options
  • cbc-des

    DES

  • cfb128-aes-128

    AES

  • cfb128-aes-192

    AES-192

  • cfb128-aes-256

    AES-256

ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
user string
Description User name used in SNMPv3 authentication and privacy
Contextsystem snmp access-group name string security-entry name string user string
Treeuser
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
security-level keyword
Description Minimum security level required for this access-group.
Contextsystem snmp access-group name string security-level keyword
Treesecurity-level
Options
  • no-auth-no-priv

  • auth-no-priv

  • auth-priv

ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

network-instance name reference

Description List of network-instances to run an SNMP server in
Contextsystem snmp network-instance name reference
Treenetwork-instance
ConfigurableTrue
PlatformsSupported on all platforms
Max. Elements5
engine-id string
Description

The local SNMP engine's administratively assigned unique identifier.

If this leaf is not set, the device automatically calculates an engine ID, as described in RFC 3411.

Contextsystem snmp network-instance name reference engine-id string
Treeengine-id
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
error-msg string
Description Indicates a possible error message if the snmp-server was stopped at runtime
Contextsystem snmp network-instance name reference error-msg string
Treeerror-msg
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
listen-address (ipv4-address | ipv6-address)
Description List of IP addresses for the SNMP server to listen on within the network-instance
Contextsystem snmp network-instance name reference listen-address (ipv4-address | ipv6-address)
Treelisten-address
Default::
ConfigurableTrue
PlatformsSupported on all platforms
Max. Elements16
oper-state keyword
Description Details the operational state of the SNMP server
Contextsystem snmp network-instance name reference oper-state keyword
Treeoper-state
Options
  • up

    Component or process is operational

  • down

    Component or process is not operational

  • empty

    Component slot is empty

  • downloading

    Component is downloading image into memory

  • booting

    Component is booting downloaded image

  • starting

    Component image operational, application processes starting

  • failed

    Component or process has failed

  • synchronizing

    Component is currently being synchronized

  • upgrading

    Component is currently being upgraded

  • low-power

    Component is offline due to insufficient system power

  • degraded

    Component or process is in a degraded state

  • warm-reboot

    Component or process is currently warm rebooting

    This state is set during a warm reboot immediately following initiation of the reboot, continuing after startup until the system has completed audit. In this state the system will not accept configuration changes.

  • waiting

    Component or process is currently waiting

    This state can be set by event handler when the reinvoke-with-delay action is used, and indicates that the event handler is waiting for the provided delay before reinvoking the instance.

ConfigurableFalse
PlatformsSupported on all platforms

trap-group name string

Description List of configured SNMP trap-groups
Context system snmp trap-group name string
Treetrap-group
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
name string
Description Name of the SNMP trap-group
Context system snmp trap-group name string
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
admin-state keyword
Description Enables the SNMP traps in the network-instance
Contextsystem snmp trap-group name string admin-state keyword
Treeadmin-state
Defaultenable
Options
  • enable

  • disable

Configurable True
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
description string
Description Description for this trap-group
Context system snmp trap-group name string description string
Treedescription
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
destination name string
Description List of configured SNMPv3 trap-destinations
Contextsystem snmp trap-group name string destination name string
Treedestination
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
Max. Elements16
name string
Description Name of the SNMPv3 destination
Context system snmp trap-group name string destination name string
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
address (ipv4-address | ipv6-address)
Description Destination IP addresses for the SNMP trap
Contextsystem snmp trap-group name string destination name string address (ipv4-address | ipv6-address)
Treeaddress
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
admin-state keyword
Description Enables the SNMP traps to this destination
Contextsystem snmp trap-group name string destination name string admin-state keyword
Treeadmin-state
Defaultenable
Options
  • enable

  • disable

Configurable True
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
community-entry name string
Description SNMPv2 community configured on this destination
Contextsystem snmp trap-group name string destination name string community-entry name string
Treecommunity-entry
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
Max. Elements1
name string
Description Unique name for the SNMP community on this destination.
Contextsystem snmp trap-group name string destination name string community-entry name string
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
community string
Description SNMPv2 community
Context system snmp trap-group name string destination name string community-entry name string community string
Treecommunity
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
description string
Description Description for the SNMPv2 community
Context system snmp trap-group name string destination name string community-entry name string description string
Treedescription
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
description string
Description Description for this destination
Context system snmp trap-group name string destination name string description string
Treedescription
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
port number
Description Destination port for the SNMP trap
Context system snmp trap-group name string destination name string port number
Treeport
Range0 to 65535
Default162
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
security-entry name string
Description SNMPv3 security configured on this destination
Contextsystem snmp trap-group name string destination name string security-entry name string
Treesecurity-entry
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
Max. Elements1
name string
Description Unique name of the SNMPv3 security.
Context system snmp trap-group name string destination name string security-entry name string
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
authentication
Description Authentication parameters for this user.
Contextsystem snmp trap-group name string destination name string security-entry name string authentication
Treeauthentication
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
password string
Description

The user authentication password, supplied either as cleartext or as a hashed value.

If provided as cleartext, the system will hash the value on input, storing only the hashed value. If provided as a hashed value, the value should include any '$' characters, for example '$ar2$aOvsuj0ALlU=$r750fMa3ZEA/Di8dIfU2fQ=='.

Contextsystem snmp trap-group name string destination name string security-entry name string authentication password string
Treepassword
String Length8 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
protocol keyword
Description Authentication protocol used by this user.
Contextsystem snmp trap-group name string destination name string security-entry name string authentication protocol keyword
Treeprotocol
Defaulthmac-md5-96
Options
  • hmac-md5-96

    MD5

  • hmac-sha1-96

    SHA

  • hmac-sha2-224

    SHA-224

  • hmac-sha2-256

    SHA-256

  • hmac-sha2-384

    SHA-384

  • hmac-sha2-512

    SHA-512

ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
description string
Description Description for this user
Context system snmp trap-group name string destination name string security-entry name string description string
Treedescription
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
engine-id string
Description

The unique identifier for the SNMP engine of a trap sender.

If this leaf is not set, the local SNMP engine will be used, this needs to be configured on the destination side too

Contextsystem snmp trap-group name string destination name string security-entry name string engine-id string
Treeengine-id
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
privacy
Description Privacy parameters for this user.
Context system snmp trap-group name string destination name string security-entry name string privacy
Treeprivacy
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
password string
Description

The user privacy password, supplied either as cleartext or as a hashed value. If not provided, authentication/password will be used.

If provided as cleartext, the system will hash the value on input, storing only the hashed value. If provided as a hashed value, the value should include any '$' characters, for example '$ar2$aOvsuj0ALlU=$r750fMa3ZEA/Di8dIfU2fQ=='.

Contextsystem snmp trap-group name string destination name string security-entry name string privacy password string
Treepassword
String Length8 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
protocol keyword
Description Privacy protocol used by this user.
Context system snmp trap-group name string destination name string security-entry name string privacy protocol keyword
Treeprotocol
Defaultcbc-des
Options
  • cbc-des

    DES

  • cfb128-aes-128

    AES

  • cfb128-aes-192

    AES-192

  • cfb128-aes-256

    AES-256

ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
user string
Description User name used in SNMPv3 authentication and privacy
Contextsystem snmp trap-group name string destination name string security-entry name string user string
Treeuser
String Length1 to 255
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
security-level keyword
Description Security level required for this destination
Contextsystem snmp trap-group name string destination name string security-level keyword
Treesecurity-level
Options
  • no-auth-no-priv

  • auth-no-priv

  • auth-priv

ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
network-instance reference
Description Reference to a network-instance configured for SNMP
Contextsystem snmp trap-group name string network-instance reference
Treenetwork-instance
Referencesystem snmp network-instance name reference
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
source-address (ipv4-address | ipv6-address)
Description IP address for the SNMP server to use as source-address within the network-instance
Contextsystem snmp trap-group name string source-address (ipv4-address | ipv6-address)
Treesource-address
Default::
ConfigurableTrue
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

ssh-server name string

Description Enter the ssh-server list instance
Context system ssh-server name string
Treessh-server
ConfigurableTrue
PlatformsSupported on all platforms

name string

Description User-provided name of this server instance
Contextsystem ssh-server name string
String Length1 to 255
ConfigurableTrue
PlatformsSupported on all platforms

admin-state keyword

Description Enable or disable the SSH server instance
Contextsystem ssh-server name string admin-state keyword
Treeadmin-state
Defaultdisable
Options
  • enable

  • disable

Configurable True
PlatformsSupported on all platforms

allowed-authentication-types keyword

Description

List of allowed authentication types

This sets the AuthenticationMethods option within each SSH servers configuration file. Also sets PasswordAuthentication PubkeyAuthentication KbdInteractiveAuthentication options within each SSH servers configuration file.

Contextsystem ssh-server name string allowed-authentication-types keyword
Treeallowed-authentication-types
Defaultpublickey
Options
  • password

  • publickey

  • keyboard-interactive

ConfigurableTrue
PlatformsSupported on all platforms

authorized-principal-check-tool keyword

Description

Configure the tool used to check the authorized principals

Setting the value to hiba-chk sets the AuthorizedPrincipalsCommand to hiba-chk tool. If unset, the aaamgr will do the principal checking.

Contextsystem ssh-server name string authorized-principal-check-tool keyword
Treeauthorized-principal-check-tool
Options
  • hiba-chk

ConfigurableTrue
PlatformsSupported on all platforms

counters

Description A collection of counters that were collected by the SSH server during the SSH authentication process.
Contextsystem ssh-server name string counters
Treecounters
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
access-accepts number
Description The total number of times the SSH allowed access to the server.
Contextsystem ssh-server name string counters access-accepts number
Treeaccess-accepts
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
access-rejects number
Description The total number of times the SSH server denied access to the server.
Contextsystem ssh-server name string counters access-rejects number
Treeaccess-rejects
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
last-access-accept string
Description A timestamp of the last time the SSH allowed access to the server.
Contextsystem ssh-server name string counters last-access-accept string
Treelast-access-accept
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
last-access-reject string
Description A timestamp of the last time the SSH server denied access to the server.
Contextsystem ssh-server name string counters last-access-reject string
Treelast-access-reject
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

credentialz

Description

Information relating to the active host keys and certificates as provided via Credentialz

State is provided by the gNSI Credentialz service, and can be changed using the gNSI.Credentialz.RotateHostParameters RPC

Contextsystem ssh-server name string credentialz
Treecredentialz
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
host-certificate
Description State relating to the Host Certificates provided via Credentialz
Contextsystem ssh-server name string credentialz host-certificate
Treehost-certificate
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
created-on string
Description

The created on timestamp as provided by the gNSI client at the time of uploading the artifact

The maps to the created_on field within a Entity message in the Credentialz protobuf.

Contextsystem ssh-server name string credentialz host-certificate created-on string
Treecreated-on
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
version string
Description

The version string as provided by the gNSI client at the time of uploading the artifact

The maps to the version field within a Entity message in the Credentialz protobuf.

Contextsystem ssh-server name string credentialz host-certificate version string
Treeversion
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
host-key
Description State relating to the Host Keys provided via Credentialz
Contextsystem ssh-server name string credentialz host-key
Treehost-key
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
created-on string
Description

The created on timestamp as provided by the gNSI client at the time of uploading the artifact

The maps to the created_on field within a Entity message in the Credentialz protobuf.

Contextsystem ssh-server name string credentialz host-key created-on string
Treecreated-on
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
version string
Description

The version string as provided by the gNSI client at the time of uploading the artifact

The maps to the version field within a Entity message in the Credentialz protobuf.

Contextsystem ssh-server name string credentialz host-key version string
Treeversion
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
trusted-user-ca-keys
Description State relating to the Certificate Authorities provided via Credentialz.
Contextsystem ssh-server name string credentialz trusted-user-ca-keys
Treetrusted-user-ca-keys
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
created-on string
Description

The created on timestamp as provided by the gNSI client at the time of uploading the artifact

The maps to the created_on field within a Entity message in the Credentialz protobuf.

Contextsystem ssh-server name string credentialz trusted-user-ca-keys created-on string
Treecreated-on
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
version string
Description

The version string as provided by the gNSI client at the time of uploading the artifact

The maps to the version field within a Entity message in the Credentialz protobuf.

Contextsystem ssh-server name string credentialz trusted-user-ca-keys version string
Treeversion
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e

disable-shell boolean

Description Disable the ability to spawn a shell for incoming connections
Contextsystem ssh-server name string disable-shell boolean
Treedisable-shell
Defaultfalse
ConfigurableTrue
PlatformsSupported on all platforms

host-key

Description Enter the host-key context
Context system ssh-server name string host-key
Treehost-key
ConfigurableTrue
PlatformsSupported on all platforms
preserve boolean
Description

Indicates whether the autogenerated SSH server host keys should be preserved on reboots

Setting this to true will result in host keys in /etc/sshd not being cleared on a reboot. Alternatively setting this to false will result in host keys being removed and regenerated on each reboot of the system.

This is useful only when the host keys are not statically configured and not dynamically configured using gNSI Credentialz service (and therefore are suitable to be potentially regenerated on every reboot).

Takes effect only if the value is set to false for every configured ssh server instance.

Contextsystem ssh-server name string host-key preserve boolean
Treepreserve
Defaulttrue
ConfigurableTrue
PlatformsSupported on all platforms
type type keyword
Description List of the SSH servers host private-keys and certificates
Contextsystem ssh-server name string host-key type type keyword
Treetype
ConfigurableTrue
PlatformsSupported on all platforms
type keyword
Description Type of generated host key
Context system ssh-server name string host-key type type keyword
Options
  • ssh-rsa-3076

  • ecdsa-sha2-nistp256

  • ecdsa-sha2-nistp521

  • ssh-ed25519

  • ssh-rsa-2048

  • ssh-rsa-4096

ConfigurableTrue
PlatformsSupported on all platforms
certificate string
Description

Each item value should be the host key certificate as read from the *-cert.pub file generated by the CA including the certificate type, e.g. 'ssh-rsa-cert-v01@openssh.com AAAA<...> comment'.

This certificate is returned to clients during SSH init for the client to verify the host it is communicating with.

This sets the HostCertificate option within each SSH servers configuration file. The certificate should be generated by first extracting the systems current public key and having this signed by a CA.

Contextsystem ssh-server name string host-key type type keyword certificate string
Treecertificate
ConfigurableTrue
PlatformsSupported on all platforms
private-key string
Description

The value should be the host private key as read from the private key file.

This sets the HostKey option within each SSH servers configuration file.

Contextsystem ssh-server name string host-key type type keyword private-key string
Treeprivate-key
ConfigurableTrue
PlatformsSupported on all platforms

oper-state keyword

Description Operational state of the SSH server instance
Contextsystem ssh-server name string oper-state keyword
Treeoper-state
Options
  • up

    Component or process is operational

  • down

    Component or process is not operational

  • empty

    Component slot is empty

  • downloading

    Component is downloading image into memory

  • booting

    Component is booting downloaded image

  • starting

    Component image operational, application processes starting

  • failed

    Component or process has failed

  • synchronizing

    Component is currently being synchronized

  • upgrading

    Component is currently being upgraded

  • low-power

    Component is offline due to insufficient system power

  • degraded

    Component or process is in a degraded state

  • warm-reboot

    Component or process is currently warm rebooting

    This state is set during a warm reboot immediately following initiation of the reboot, continuing after startup until the system has completed audit. In this state the system will not accept configuration changes.

  • waiting

    Component or process is currently waiting

    This state can be set by event handler when the reinvoke-with-delay action is used, and indicates that the event handler is waiting for the provided delay before reinvoking the instance.

ConfigurableFalse
PlatformsSupported on all platforms

port number

Description Port the SSH server instance will listen on for incoming connections
Contextsystem ssh-server name string port number
Treeport
Range0 to 65535
Default22
ConfigurableTrue
PlatformsSupported on all platforms

rate-limit number

Description Set a limit on the number of unauthenticated sessions to the SSH server after this number is met, the server will start dropping connection attempts
Contextsystem ssh-server name string rate-limit number
Treerate-limit
Default20
ConfigurableTrue
PlatformsSupported on all platforms

revoked-keys string

Description

List of revoked public keys

Each items value should be the public key of a revoked keypair, e.g. 'ssh-rsa AAAA<...>= comment'. Any keys provided here cannot be used for public key authentication.

This sets the RevokedKeys option within each SSH servers configuration file.

Contextsystem ssh-server name string revoked-keys string
Treerevoked-keys
ConfigurableTrue
PlatformsSupported on all platforms

source-address (ipv4-address | ipv6-address)

Description List of IP addresses for the SSH server to listen on within the network-instance
Contextsystem ssh-server name string source-address (ipv4-address | ipv6-address)
Treesource-address
ConfigurableTrue
PlatformsSupported on all platforms

timeout number

Description Set the idle timeout in seconds on SSH connections
Contextsystem ssh-server name string timeout number
Treetimeout
Default0
Unitsseconds
Configurable True
PlatformsSupported on all platforms

trust-anchors string

Description

List of public keys used to verify user certificates during authentication

Each items value should be the public key of a CA, e.g. 'ssh-rsa AAAA<...>= comment'. If no trust anchors are configured, authentication using SSH certificates will not function.

This sets the TrustedUserCAKeys option within each SSH servers configuration file.

Contextsystem ssh-server name string trust-anchors string
Treetrust-anchors
ConfigurableTrue
PlatformsSupported on all platforms

use-credentialz boolean

Description

Use the gNSI Credentialz service global SSH configuration for this SSH server instance

Setting this to true will apply any gNSI Credentialz configuration for this SSH server instance. Static configuration will override any gNSI Credentialz configuration.

Contextsystem ssh-server name string use-credentialz boolean
Treeuse-credentialz
ConfigurableTrue
PlatformsSupported on all platforms

sync

Description Context to configure sync parameters and report sessions state
Contextsystem sync
Treesync
ConfigurableTrue
Platforms7220 IXR-D5

freq-clock

Description Enter the freq-clock context
Context system sync freq-clock
Treefreq-clock
ConfigurableTrue
Platforms7220 IXR-D5
active-reference keyword
Description

Indicates the current selected reference

This will be an instance-number; or internal for the case of holdover or freerun.

Contextsystem sync freq-clock active-reference keyword
Treeactive-reference
Options
  • 1

  • 2

  • 3

  • 4

  • 5

  • internal

ConfigurableFalse
Platforms7220 IXR-D5
freq-clock-state keyword
Description Shows the frequency clock mode state
Context system sync freq-clock freq-clock-state keyword
Treefreq-clock-state
Options
  • not-present

    Frequency clock is locked to a line timing reference signal

  • master-free-run

    Frequency clock is master free run mode

  • master-holdover

    Frequency clock is master holdover mode

  • master-locked

    Frequency clock is master locked mode

  • slave

    Frequency clock is slave mode

  • acquiring

    Frequency clock is acquiring mode

ConfigurableFalse
Platforms7220 IXR-D5
freq-offset decimal-number
Description The frequency offset between the central frequency clock and the selected reference in ppb
Contextsystem sync freq-clock freq-offset decimal-number
Treefreq-offset
Unitsparts-per-billion
ConfigurableFalse
Platforms7220 IXR-D5
network-type keyword
Description Configures SyncE for SSM code-type as SONET or SDH mode sdh specifies the values corresponding to ITU-T G.781 Option 1 compliant networks. sonet specifies the values corresponding to ITU-T G.781 Option 2 compliant networks.
Contextsystem sync freq-clock network-type keyword
Treenetwork-type
Defaultsonet
Options
  • sdh

    sdh specifies the values corresponding to G.781 Option 1 compliant networks

  • sonet

    sonet specifies the values corresponding to G.781 Option 2 compliant networks

ConfigurableTrue
Platforms7220 IXR-D5
ql-input-threshold keyword
Description This command configures the minimum acceptable QL value Frequency references with lower QL will not be considered for selection by the system timing module. Options: unused, prs, stu, st2, tnc, st3e, st3, prc, ssua, ssub, sec, eec1, eec2
Contextsystem sync freq-clock ql-input-threshold keyword
Treeql-input-threshold
Defaultunused
Options
  • unused

    No override or minimum QL level selected

  • prs

    QL of PRS

  • stu

    QL of STU

  • st2

    QL of Stratum 2

  • tnc

    QL of TNC

  • st3e

    QL of Stratum 3E

  • st3

    QL of Stratum 3

  • prc

    QL of PRC

  • ssua

    QL of SSU-A

  • ssub

    QL of SSU-B

  • sec

    QL of SEC

  • eec1

    QL of EEC-1

  • eec2

    QL of EEC-2

ConfigurableTrue
Platforms7220 IXR-D5
ql-selection boolean
Description Configures if frequency reference selection takes the QL (Quality Level) into account When enabled, the selection of system timing reference and BITS output timing reference takes into account quality level. Quality level is conveyed via the SSM or forced using the ql-override command..
Contextsystem sync freq-clock ql-selection boolean
Treeql-selection
Defaultfalse
ConfigurableTrue
Platforms7220 IXR-D5
revert boolean
Description This command configures if the frequency clock is in revertive mode In revertive mode, when a failed reference becomes operational, the system will automatically switch to the recovered reference if it is of higher priority and/or QL. When the mode is non-revertive, a failed clock source is not automatically selected.
Contextsystem sync freq-clock revert boolean
Treerevert
Defaultfalse
ConfigurableTrue
Platforms7220 IXR-D5
system-ql-value keyword
Description System QL value based on the reference selected
Contextsystem sync freq-clock system-ql-value keyword
Treesystem-ql-value
Options
  • unknown

    Unknown

  • prs

    QL of PRS

  • stu

    QL of STU

  • st2

    QL of Stratum 2

  • tnc

    QL of TNC

  • st3e

    QL of Stratum 3E

  • st3

    QL of Stratum 3

  • smc

    QL of SMC

  • st4

    QL of Stratum 4

  • dus

    QL of DNU

  • prc

    QL of PRC

  • ssua

    QL of SSU-A

  • ssub

    QL of SSU-B

  • sec

    QL of SEC

  • dnu

    QL of DNU

  • inv

    QL of INV

  • pno

    QL of PNO

  • eec1

    QL of EEC-1

  • eec2

    QL of EEC-2

  • failed

    Failed

Configurable False
Platforms7220 IXR-D5
wait-to-restore number
Description This command configures the time for the Wait to Restore timer A previously failed input reference must be valid for the time specified before it is used for the clock input reference.
Contextsystem sync freq-clock wait-to-restore number
Treewait-to-restore
Range0 to 12
Default5
Unitsminutes
Configurable True
Platforms7220 IXR-D5

freq-references

Description Enter the freq-references context
Context system sync freq-references
Treefreq-references
ConfigurableTrue
Platforms7220 IXR-D5
instance instance-number number
Description List of line references configured for frequency
Contextsystem sync freq-references instance instance-number number
Treeinstance
ConfigurableTrue
Platforms7220 IXR-D5
not-qualified-reason keyword
Description If the reference is not qualified, this identifies the reason
Contextsystem sync freq-references instance instance-number number not-qualified-reason keyword
Treenot-qualified-reason
Options
  • not-applicable

    Reason is not applicable

  • los

    Reference is not-qualified because of Loss of Signal (LOS)

  • ssm-quality

    Reference is not-qualified because of received SSM/QL level

  • out-of-range

    Reference is not-qualified because the reference is out of range in frequency

  • wtr

    Reference is not-qualified because the wait-to-restore timer has not expired

  • admin-disabled

    Reference is not-qualified because the reference has not been admin enabled

ConfigurableFalse
Platforms7220 IXR-D5
oper-state keyword
Description Indicates the operational state of this line reference
Contextsystem sync freq-references instance instance-number number oper-state keyword
Treeoper-state
Options
  • up

    Component or process is operational

  • down

    Component or process is not operational

  • empty

    Component slot is empty

  • downloading

    Component is downloading image into memory

  • booting

    Component is booting downloaded image

  • starting

    Component image operational, application processes starting

  • failed

    Component or process has failed

  • synchronizing

    Component is currently being synchronized

  • upgrading

    Component is currently being upgraded

  • low-power

    Component is offline due to insufficient system power

  • degraded

    Component or process is in a degraded state

  • warm-reboot

    Component or process is currently warm rebooting

    This state is set during a warm reboot immediately following initiation of the reboot, continuing after startup until the system has completed audit. In this state the system will not accept configuration changes.

  • waiting

    Component or process is currently waiting

    This state can be set by event handler when the reinvoke-with-delay action is used, and indicates that the event handler is waiting for the provided delay before reinvoking the instance.

ConfigurableFalse
Platforms7220 IXR-D5
priority number
Description Sets the priority of this line timing reference for the system timing selection process 1 = highest priority 5 = lowest priority Duplicate numbers are not allowed
Contextsystem sync freq-references instance instance-number number priority number
Treepriority
Range1 to 5
Default3
ConfigurableTrue
Platforms7220 IXR-D5
ql-override keyword
Description Override the incoming QL/SSM value for this line reference Quality level override of a timing reference Options are unused, prs, stu, st2, tnc, st3e, st3, prc, ssua, ssub, sec, eec1, eec2
Contextsystem sync freq-references instance instance-number number ql-override keyword
Treeql-override
Defaultunused
Options
  • unused

    No override or minimum QL level selected

  • prs

    QL of PRS

  • stu

    QL of STU

  • st2

    QL of Stratum 2

  • tnc

    QL of TNC

  • st3e

    QL of Stratum 3E

  • st3

    QL of Stratum 3

  • prc

    QL of PRC

  • ssua

    QL of SSU-A

  • ssub

    QL of SSU-B

  • sec

    QL of SEC

  • eec1

    QL of EEC-1

  • eec2

    QL of EEC-2

ConfigurableTrue
Platforms7220 IXR-D5
ql-value keyword
Description The incoming QL/SSM value from this line reference
Contextsystem sync freq-references instance instance-number number ql-value keyword
Treeql-value
Options
  • unknown

    Unknown

  • prs

    QL of PRS

  • stu

    QL of STU

  • st2

    QL of Stratum 2

  • tnc

    QL of TNC

  • st3e

    QL of Stratum 3E

  • st3

    QL of Stratum 3

  • smc

    QL of SMC

  • st4

    QL of Stratum 4

  • dus

    QL of DNU

  • prc

    QL of PRC

  • ssua

    QL of SSU-A

  • ssub

    QL of SSU-B

  • sec

    QL of SEC

  • dnu

    QL of DNU

  • inv

    QL of INV

  • pno

    QL of PNO

  • eec1

    QL of EEC-1

  • eec2

    QL of EEC-2

  • failed

    Failed

Configurable False
Platforms7220 IXR-D5
source
Description

Source for this input frequency reference

This shall be either a leafref to an interface or an application. The leafref must point to an existing physical ethernet interface.

Contextsystem sync freq-references instance instance-number number source
Treesource
ConfigurableTrue
Platforms7220 IXR-D5

one-pps

Description Enter the one-pps context
Context system sync one-pps
Treeone-pps
ConfigurableTrue
Platforms7220 IXR-D5
admin-state keyword
Description

Configure the administrative state of the 1PPS (50 ohm) output port

When enabled, output is enabled. Otherwise, the output is disabled.

Contextsystem sync one-pps admin-state keyword
Treeadmin-state
Defaultdisable
Options
  • enable

  • disable

Configurable True
Platforms7220 IXR-D5

ptp

Description Enter the ptp context
Context system sync ptp
Treeptp
ConfigurableTrue
Platforms7220 IXR-D5
instance instance-index number
Description

List of one or more PTP instances in the product (PTP Node)

Each PTP instance represents a distinct instance of PTP implementation (i.e. distinct Ordinary Clock, Boundary Clock, or Transparent Clock), maintaining a distinct time.

Contextsystem sync ptp instance instance-index number
Treeinstance
ConfigurableTrue
Platforms7220 IXR-D5
instance-index number
Description

The instance index of the current PTP instance

This instance index is used for management purposes only. This instance index does not represent the PTP domain number and is not used in PTP messages.

Contextsystem sync ptp instance instance-index number
Range1 to 2
ConfigurableTrue
Platforms7220 IXR-D5
current-ds
Description Provides current data from operation of the protocol
Contextsystem sync ptp instance instance-index number current-ds
Treecurrent-ds
ConfigurableFalse
Platforms7220 IXR-D5
default-ds
Description

The default data set of the PTP instance

In the context of the protocol, this data set is required for an Ordinary Clock or Boundary Clock

Contextsystem sync ptp instance instance-index number default-ds
Treedefault-ds
ConfigurableTrue
Platforms7220 IXR-D5
announce-receipt-timeout number
Description

Sets the time limit for missed Announce packets before the master clock is deemed down

This command configures the announceReceiptTimeout value for all peer associations. This defines the number of Announce message intervals that must expire with no received Announce messages before declaring an ANNOUNCE_RECEIPT_TIMEOUT event.

Contextsystem sync ptp instance instance-index number default-ds announce-receipt-timeout number
Treeannounce-receipt-timeout
Range2 to 10
Default3
ConfigurableTrue
Platforms7220 IXR-D5
clock-quality
Description The clockQuality of the local clock
Context system sync ptp instance instance-index number default-ds clock-quality
Treeclock-quality
ConfigurableFalse
Platforms7220 IXR-D5
current-time
Description The current time in the current data set
Contextsystem sync ptp instance instance-index number default-ds current-time
Treecurrent-time
ConfigurableFalse
Platforms7220 IXR-D5
domain-number number
Description

The IEEE Std 1588 domainNumber of the PTP instance

A domain consists of one or more PTP instances communicating with each other as defined by the protocol. A domain shall define the scope of PTP message communication, state, operations, data sets, and timescale. Therefore, each domain represents a distinct time. The default domain number is defined by the profile. itug8275dot1: 24 itug8275dot2: 44

Contextsystem sync ptp instance instance-index number default-ds domain-number number
Treedomain-number
Range0 to 255
ConfigurableTrue
Platforms7220 IXR-D5
instance-type keyword
Description

The type of PTP instance as per IEEE1588 standard

For G.8275.1: oc is for T-GM, bc is for T-BC; T-TSC not supported since T-BC can be used for this role For G.8275.2: oc is for T-GM, bc is for T-BC-A and T-BC-P; T-TSC-A and T-TSC-P are not supported since T-BC-A or T-BC-P can be used for this role

Contextsystem sync ptp instance instance-index number default-ds instance-type keyword
Treeinstance-type
Defaultbc
Options
  • bc

    boundary clock

ConfigurableTrue
Platforms7220 IXR-D5
local-priority number
Description

The IEEE Std 1588 priority2 of the PTP instance

The priority2 member is compared by the Best Master Clock Algorithm (BMCA) after priority1 and clockQuality. Lower values take precedence.

Contextsystem sync ptp instance instance-index number default-ds local-priority number
Treelocal-priority
Range1 to 255
Default128
ConfigurableTrue
Platforms7220 IXR-D5
log-announce-interval number
Description

The base-2 logarithm of the mean announceInterval

This is the mean time interval between successive Announce messages. The default log announce interval is defined by the profile. itug8275dot1: -3 (8 messages per second) itug8275dot2: 1 (1 message every two seconds)

Contextsystem sync ptp instance instance-index number default-ds log-announce-interval number
Treelog-announce-interval
Range-3 to 4
ConfigurableTrue
Platforms7220 IXR-D5
priority1 number
Description

The IEEE Std 1588 priority1 of the PTP instance

Since priority1 is one of the first comparisons performed by the Best Master Clock Algorithm (BMCA). Range is 0-255.

Contextsystem sync ptp instance instance-index number default-ds priority1 number
Treepriority1
Range0 to 255
Default128
ConfigurableTrue
Platforms7220 IXR-D5
priority2 number
Description

The IEEE Std 1588 priority2 of the PTP instance

The priority2 member is compared by the Best Master Clock Algorithm (BMCA) after priority1 and clockQuality. Lower values take precedence.

Contextsystem sync ptp instance instance-index number default-ds priority2 number
Treepriority2
Range0 to 255
Default128
ConfigurableTrue
Platforms7220 IXR-D5
statistics
Description Aggregate statistics for the PTP clock
Contextsystem sync ptp instance instance-index number default-ds statistics
Treestatistics
ConfigurableFalse
Platforms7220 IXR-D5
discards
Description Aggregate discard statistics for the PTP clock
Contextsystem sync ptp instance instance-index number default-ds statistics discards
Treediscards
ConfigurableFalse
Platforms7220 IXR-D5
multicast-msg-rate
Description Aggregate multicast message rates for the PTP clock
Contextsystem sync ptp instance instance-index number default-ds statistics multicast-msg-rate
Treemulticast-msg-rate
ConfigurableFalse
Platforms7220 IXR-D5
time-recovery-engine
Description Enter the time-recovery-engine context
Contextsystem sync ptp instance instance-index number default-ds time-recovery-engine
Treetime-recovery-engine
ConfigurableFalse
Platforms7220 IXR-D5
statistics
Description Time recovery engine state statistics for the PTP clock
Contextsystem sync ptp instance instance-index number default-ds time-recovery-engine statistics
Treestatistics
ConfigurableFalse
Platforms7220 IXR-D5
parent-ds
Description The parent data set of the clock
Context system sync ptp instance instance-index number parent-ds
Treeparent-ds
ConfigurableFalse
Platforms7220 IXR-D5
grandmaster-clock-quality
Description The clockQuality of the grandmaster clock
Contextsystem sync ptp instance instance-index number parent-ds grandmaster-clock-quality
Treegrandmaster-clock-quality
ConfigurableFalse
Platforms7220 IXR-D5
parent-port-identity
Description The portIdentity of the port on the master
Contextsystem sync ptp instance instance-index number parent-ds parent-port-identity
Treeparent-port-identity
ConfigurableFalse
Platforms7220 IXR-D5
protocol-address
Description The protocol address of the PTP Port that issues the Sync messages
Contextsystem sync ptp instance instance-index number parent-ds protocol-address
Treeprotocol-address
ConfigurableFalse
Platforms7220 IXR-D5
network-protocol identityref
Description Protocol used by a PTP instance to transport PTP messages
Contextsystem sync ptp instance instance-index number parent-ds protocol-address network-protocol identityref
Treenetwork-protocol
Options
  • udp-ipv4

    UDP on IPv4. Numeric value is 0001 hex

  • udp-ipv6

    UDP on IPv6. Numeric value is 0002 hex

  • ieee802-3

    IEEE Std 802.3 (Ethernet). Numeric value is 0003 hex

  • devicenet

    DeviceNet. Numeric value is 0004 hex

  • controlnet

    ControlNet. Numeric value is 0005 hex

  • profinet

    PROFINET. Numeric value is 0006 hex

  • otn

    Optical Transport Network (OTN). Numeric value is 0007 hex

  • unknown

    Unknown. Numeric value is FFFE hex

ConfigurableFalse
Platforms7220 IXR-D5
port-ds-gnss
Description List of port data sets for the GNSS special PTP port
Contextsystem sync ptp instance instance-index number port-ds-gnss
Treeport-ds-gnss
ConfigurableFalse
Platforms7220 IXR-D5
port-state keyword
Description Current state associated with the port
Contextsystem sync ptp instance instance-index number port-ds-gnss port-state keyword
Treeport-state
Options
  • initializing

    The port is initializing its data sets, hardware, and communication facilities

  • faulty

    The port is in the fault state

  • disabled

    The port is disabled and is not communicating PTP messages

  • listening

    The port is listening for an Announce message

  • pre-master

    The port is in the pre-master state

  • master

    The port is behaving as a master port

  • passive

    The port is in the passive state

  • uncalibrated

    A master port has been selected, but the port is still in the uncalibrated state

  • slave

    The port is synchronizing to the selected master port

ConfigurableFalse
Platforms7220 IXR-D5
port-ds-interface-list port-index number
Description List of port data sets for interfaces
Contextsystem sync ptp instance instance-index number port-ds-interface-list port-index number
Treeport-ds-interface-list
ConfigurableTrue
Platforms7220 IXR-D5
port-index number
Description

Index into the port-ds list

This is not the PTP port number. Configurable ports use port indices 1 through 999 but there is a limit on the overall number of these configured ports based on the platform and software release.

The data sets (i.e., information model) of IEEE Std 1588-2008 specify a member portDS.portIdentity, which uses a typed struct with members clockIdentity and portNumber.

In this YANG data model, portIdentity is not modeled in the port-ds. However, its members are provided as follows: portIdentity.portNumber is provided as this ptp-port-number leaf in port-ds, and portIdentity.clockIdentity is provided as the clock-identity leaf in default-ds of the instance (i.e., ../../default-ds/clock-identity).

Contextsystem sync ptp instance instance-index number port-ds-interface-list port-index number
Range1 to 999
ConfigurableTrue
Platforms7220 IXR-D5
announce-receipt-timeout number
Description

Sets the time limit for missed Announce packets before the master clock is deemed down

This defines the number of Announce message intervals that must expire with no received Announce messages before declaring an ANNOUNCE_RECEIPT_TIMEOUT event. To change this setting, refer to announce-receipt-timeout in the Default data set.

Contextsystem sync ptp instance instance-index number port-ds-interface-list port-index number announce-receipt-timeout number
Treeannounce-receipt-timeout
Range2 to 10
ConfigurableFalse
Platforms7220 IXR-D5
dest-mac keyword
Description Configure the MAC address associated with forwardable or non-forwardable
Contextsystem sync ptp instance instance-index number port-ds-interface-list port-index number dest-mac keyword
Treedest-mac
Defaultforwardable
Options
  • forwardable

    The clock uses the forwardable MAC address: 01-1B-19-00-00-00

  • non-forwardable

    The clock uses the non-forwardable MAC address: 01-80-C2-00-00-0E

ConfigurableTrue
Platforms7220 IXR-D5
log-min-delay-req-interval number
Description

The base-2 logarithm of the minDelayReqInterval

The minimum permitted mean time interval between successive Delay_Req messages. The default log-min-delay-req-interval is defined by the profile. itug8275dot1: -4 (16 messages per second) itug8275dot2: -6 (64 messages per second)

Contextsystem sync ptp instance instance-index number port-ds-interface-list port-index number log-min-delay-req-interval number
Treelog-min-delay-req-interval
Range-6 to 0
ConfigurableTrue
Platforms7220 IXR-D5
neighbor-list clock-identity binary port-number number
Description List of MAC address of all the neighbors of this port
Contextsystem sync ptp instance instance-index number port-ds-interface-list port-index number neighbor-list clock-identity binary port-number number
Treeneighbor-list
ConfigurableFalse
Platforms7220 IXR-D5
port-state keyword
Description Current state associated with the port
Contextsystem sync ptp instance instance-index number port-ds-interface-list port-index number port-state keyword
Treeport-state
Options
  • initializing

    The port is initializing its data sets, hardware, and communication facilities

  • faulty

    The port is in the fault state

  • disabled

    The port is disabled and is not communicating PTP messages

  • listening

    The port is listening for an Announce message

  • pre-master

    The port is in the pre-master state

  • master

    The port is behaving as a master port

  • passive

    The port is in the passive state

  • uncalibrated

    A master port has been selected, but the port is still in the uncalibrated state

  • slave

    The port is synchronizing to the selected master port

ConfigurableFalse
Platforms7220 IXR-D5
source
Description Source interface used by this PTP port
Contextsystem sync ptp instance instance-index number port-ds-interface-list port-index number source
Treesource
ConfigurableTrue
Platforms7220 IXR-D5
statistics
Description Total messages for a specific PTP port
Contextsystem sync ptp instance instance-index number port-ds-interface-list port-index number statistics
Treestatistics
ConfigurableFalse
Platforms7220 IXR-D5
discards
Description Aggregate discard statistics for the PTP clock
Contextsystem sync ptp instance instance-index number port-ds-interface-list port-index number statistics discards
Treediscards
ConfigurableFalse
Platforms7220 IXR-D5
time-properties-ds
Description The timeProperties data set of the clock
Contextsystem sync ptp instance instance-index number time-properties-ds
Treetime-properties-ds
ConfigurableFalse
Platforms7220 IXR-D5
time-source keyword
Description

The source of time used by the grandmaster clock

If a value is received that does not map to one of the enumerations, then the reserved value is used

Contextsystem sync ptp instance instance-index number time-properties-ds time-source keyword
Treetime-source
Options
  • atomic-clock

  • gps

  • terrestrial-radio

  • ptp

  • ntp

  • hand-set

  • other

  • internal-oscillator

  • reserved

Configurable False
Platforms7220 IXR-D5
ptp-profile keyword
Description Specifies the PTP profile mode for the PTP clock
Contextsystem sync ptp ptp-profile keyword
Treeptp-profile
Defaultitug8275dot1
Options
  • itug8275dot1

    ITU-T G.8275.1 (2014) Profile

ConfigurableTrue
Platforms7220 IXR-D5

tls

Description Top-level container for TLS configuration and state
Contextsystem tls
Treetls
ConfigurableTrue
PlatformsSupported on all platforms

server-profile name string

Description List of configured TLS server profiles
Contextsystem tls server-profile name string
Treeserver-profile
ConfigurableTrue
PlatformsSupported on all platforms
name string
Description Name of the TLS server-profile
Context system tls server-profile name string
String Length1 to 247
ConfigurableTrue
PlatformsSupported on all platforms
certificate string
Description

Base64 encoded certificate to use with the private key

This includes the '-----BEGIN CERTIFICATE-----' and '-----END CERTIFICATE-----' header and footer

Contextsystem tls server-profile name string certificate string
Treecertificate
ConfigurableTrue
PlatformsSupported on all platforms
certz
Description

Information relating to the active certificate and bundle/s as provided via Certz

State is provided by the gNSI Certz service, and can be changed using the gNSI.Certz.Rotate RPC

Contextsystem tls server-profile name string certz
Treecertz
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
certificate
Description State relating to the active certificate provided via Certz
Contextsystem tls server-profile name string certz certificate
Treecertificate
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
created-on string
Description

The created on timestamp as provided by the gNSI client at the time of uploading the policy

The maps to the created_on field within a Entity message in the Certz protobuf.

Contextsystem tls server-profile name string certz certificate created-on string
Treecreated-on
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
version string
Description

The version string as provided by the gNSI client at the time of uploading the certificate or bundle/s

The maps to the version field within a Entity message in the Certz protobuf.

Contextsystem tls server-profile name string certz certificate version string
Treeversion
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
crl
Description

State relating to the active certificate revocation list provided via Certz

The list of certificates provided will not be used to validate mTLS or servers, even if those certificates exist within the trust anchor.

Contextsystem tls server-profile name string certz crl
Treecrl
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
created-on string
Description

The created on timestamp as provided by the gNSI client at the time of uploading the policy

The maps to the created_on field within a Entity message in the Certz protobuf.

Contextsystem tls server-profile name string certz crl created-on string
Treecreated-on
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
version string
Description

The version string as provided by the gNSI client at the time of uploading the certificate or bundle/s

The maps to the version field within a Entity message in the Certz protobuf.

Contextsystem tls server-profile name string certz crl version string
Treeversion
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
ssl-profile-id string
Description The ID of this gRPC server's SSL profile as used by the gNSI Certz service
Contextsystem tls server-profile name string certz ssl-profile-id string
Treessl-profile-id
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
trust-anchor
Description

State relating to the active trust anchor provided via Certz

This is equivalent to the certificate authority bundle, and is the list of certificates used to validate clients in mTLS, and to validate servers in outbound TLS.

Contextsystem tls server-profile name string certz trust-anchor
Treetrust-anchor
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
created-on string
Description

The created on timestamp as provided by the gNSI client at the time of uploading the policy

The maps to the created_on field within a Entity message in the Certz protobuf.

Contextsystem tls server-profile name string certz trust-anchor created-on string
Treecreated-on
String Length20 to 32
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
version string
Description

The version string as provided by the gNSI client at the time of uploading the certificate or bundle/s

The maps to the version field within a Entity message in the Certz protobuf.

Contextsystem tls server-profile name string certz trust-anchor version string
Treeversion
ConfigurableFalse
Platforms7220 IXR-D1, 7220 IXR-D2, 7220 IXR-D2L, 7220 IXR-D3, 7220 IXR-D3L, 7220 IXR-D4, 7220 IXR-D5, 7220 IXR-H2, 7220 IXR-H3, 7220 IXR-H4, 7250 IXR-10, 7250 IXR-10e, 7250 IXR-6, 7250 IXR-6e
cipher-list identityref
Description

List of ciphers to use when negotiating TLS 1.2 with clients

TLS 1.3 cipher suites are always enabled: tls_aes_256_gcm_sha384, tls_aes_128_gcm_sha256, tls_chacha20_poly1305_sha256

Contextsystem tls server-profile name string cipher-list identityref
Treecipher-list
Defaultecdhe-ecdsa-aes256-gcm-sha384
Options
  • ecdhe-rsa-aes256-gcm-sha384

  • ecdhe-ecdsa-aes256-gcm-sha384

  • ecdhe-rsa-aes256-sha384

  • ecdhe-ecdsa-aes256-sha384

  • ecdhe-rsa-aes256-sha

  • ecdhe-ecdsa-aes256-sha

  • dhe-dss-aes256-gcm-sha384

  • dhe-rsa-aes256-gcm-sha384

  • dhe-rsa-aes256-sha256

  • dhe-dss-aes256-sha256

  • dhe-rsa-aes256-sha

  • dhe-dss-aes256-sha

  • dhe-rsa-camellia256-sha

  • dhe-dss-camellia256-sha

  • aes256-gcm-sha384

  • aes256-sha256

  • aes256-sha

  • camellia256-sha

  • psk-aes256-cbc-sha

  • ecdhe-rsa-aes128-gcm-sha256

  • ecdhe-ecdsa-aes128-gcm-sha256

  • ecdhe-rsa-aes128-sha256

  • ecdhe-ecdsa-aes128-sha256

  • ecdhe-rsa-aes128-sha

  • ecdhe-ecdsa-aes128-sha

  • dhe-dss-aes128-gcm-sha256

  • dhe-rsa-aes128-gcm-sha256

  • dhe-rsa-aes128-sha256

  • dhe-dss-aes128-sha256

  • dhe-rsa-aes128-sha

  • dhe-dss-aes128-sha

  • dhe-rsa-seed-sha

  • dhe-dss-seed-sha

  • dhe-rsa-camellia128-sha

  • dhe-dss-camellia128-sha

  • aes128-gcm-sha256

  • aes128-sha256

  • aes128-sha

  • seed-sha

  • camellia128-sha

  • psk-aes128-cbc-sha

  • ecdhe-rsa-des-cbc3-sha

  • ecdhe-ecdsa-des-cbc3-sha

  • edh-rsa-des-cbc3-sha

  • edh-dss-des-cbc3-sha

  • des-cbc3-sha

  • idea-cbc-sha

  • psk-3des-ede-cbc-sha

  • ecdhe-rsa-rc4-sha

  • ecdhe-ecdsa-rc4-sha

  • rc4-sha

  • psk-rc4-sha

ConfigurableTrue
PlatformsSupported on all platforms
dynamic boolean
Description Defines if the profile was dynamically created by service (for example gNSI Authz/Certz)
Contextsystem tls server-profile name string dynamic boolean
Treedynamic
ConfigurableFalse
PlatformsSupported on all platforms
key string
Description

Base64 encoded key to use with the server certificate

This includes the '-----BEGIN PRIVATE KEY-----', and '-----END PRIVATE KEY-----' header and footer The value is hashed, and only the hashed value is kept

Contextsystem tls server-profile name string key string
Treekey
ConfigurableTrue
PlatformsSupported on all platforms
trust-anchor string
Description

Base64 encoded certificate to use as a trust anchor

This includes the '-----BEGIN CERTIFICATE-----' and '-----END CERTIFICATE-----' header and footer

Contextsystem tls server-profile name string trust-anchor string
Treetrust-anchor
ConfigurableTrue
PlatformsSupported on all platforms

trace-options keyword

Description Management server trace options
Context system trace-options keyword
Treetrace-options
Options
  • request

  • response

  • common

ConfigurableTrue
PlatformsSupported on all platforms