Download Print this page

Nokia 7210 SAS D Configuration Manual

Service access switch os router.
Hide thumbs

Advertisement

TitlePage Guide Name
7210 SERVICE ACCESS SWITCH
7210 SAS D, E, K OS Router Configuration
Guide
Release 9.0.R1
3HE11494AAAATQZZA
Issue: 01
November 2016
Nokia — Proprietary and confidential.
Use pursuant to applicable agreements.

Advertisement

Chapters

   Related Manuals for Nokia 7210 SAS D

   Summary of Contents for Nokia 7210 SAS D

  • Page 1

    TitlePage Guide Name 7210 SERVICE ACCESS SWITCH 7210 SAS D, E, K OS Router Configuration Guide Release 9.0.R1 3HE11494AAAATQZZA Issue: 01 November 2016 Nokia — Proprietary and confidential. Use pursuant to applicable agreements.

  • Page 2

    © 2013, 2016 Nokia. Contains proprietary/trade secret information which is the property of Nokia and must not be made available to, or copied or used by anyone outside Nokia without its written authorization. Not to be used or disclosed except in accordance with applicable agreements.

  • Page 3: Table Of Contents

    Packet Matching Criteria ............89 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 4

    ........... . .181 Page 4 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 5

    Show Filter Counters............167 Common CLI Command Descriptions 7210 SAS D, E, K OS Router Configuration Guide Page 5...

  • Page 6

    List of Tables Page 6 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 7

    Applying an IP Filter to an Ingress Interface ........107 Common CLI Command Descriptions 7210 SAS D, E, K OS Router Configuration Guide Page 7...

  • Page 8

    7210 SAS D, E, K OS Router Configuration Guide Page 8...

  • Page 9: Preface

    This guide describes logical IP routing interfaces, IP and MAC-based filtering support provided by the 7210 SAS D, E, K OS and presents configuration and implementation examples. On 7210 SAS devices, not all the CLI commands are supported on all the platforms and in all the modes.

  • Page 10: List Of Technical Publications

    This guide describes how to configure features such as service mirroring and Operations, Administration and Management (OAM) tools. • 7210-SAS D, E, K OS Quality of Service Guide This guide describes how to configure Quality of Service (QoS) policy management. Page 10 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 11: Technical Support

    If you purchased an Alcatel-Lucent service agreement, contact your welcome center Web: http://www.alcatel-lucent.com/wps/portal/support 7210 SAS D, E, K OS Router Configuration Guide Page 11...

  • Page 12

    Preface Page 12 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 13: Getting Started

    IDs. IP and MAC filters Filter Policies on page 81 Reference List of IEEE, IETF, and other Standards and Protocol Support on page 339 proprietary entities. 7210 SAS D, E, K OS Router Configuration Guide Page 13...

  • Page 14: Getting Started

    Getting Started Page 14 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 15: Ip Router Configuration

    This chapter provides information about commands required to configure basic router parameters. Topics in this chapter include: • Configuring IP Router Parameters on page 16 → Interfaces on page 16 • Configuration Notes on page 21 Page 15 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 16: Configuring Ip Router Parameters

    The system interface is used to preserve connectivity (when routing reconvergence is possible) when an interface fails or is removed. The system interface is also referred to as the loopback address and is used as the router identifier. Page 16 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 17: Internet Protocol Versions

    “real-time” service was added in IPv6. • Authentication and privacy capabilities — Extensions to support authentication, data integrity, and (optional) data confidentiality are specified for IPv6. 7210 SAS D, E, K OS Router Configuration Guide Page 17...

  • Page 18: Table 2: Ipv6 Header Field Descriptions

    128-bit address of the originator of the packet. Destination Address 128-bit address of the intended recipient of the packet (possibly not the ulti- mate recipient if a routing header is present). Page 18 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 19: Ipv6 Applications For 7210 Sas-d

    AAAA resource record from an IPv4 or IPv6 DNS server. An assigned name can be used instead of an IPv6 address as IPv6 addresses are more difficult to remember than IPv4 addresses. 7210 SAS D, E, K OS Router Configuration Guide Page 19...

  • Page 20: Process Overview

    The following items are components to configure basic router parameters. • System interface — This creates an association between the logical IP interface and the system (loopback) address. The system interface address is the circuitless address (loopback) Page 20 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 21: Configuration Notes

    IPv6 /128-bit route lookup). • IPv6 interfaces are allowed to be created without allocating IPv6 route entries. With this only IPv6 hosts on the same subnet will be reachable. 7210 SAS D, E, K OS Router Configuration Guide Page 21...

  • Page 22

    Configuration Notes Page 22 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 23: Configuring An Ip Router With Cli

    Service Management Tasks on page 31 → Changing the System Name on page 31 → Modifying Interface Parameters on page 54 → Deleting a Logical IP Interface on page 32 7210 SAS D, E, K OS Router Configuration Guide Page 23...

  • Page 24: Router Configuration Overview

    The system interface is used as the router identifier. A system interface must have an IP address with a 32-bit subnet mask. Page 24 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 25: Basic Configuration

    The following example displays a router configuration: A:ALA-A> config# info . . . #------------------------------------------ # Router Configuration #------------------------------------------ router interface "system" address 10.10.10.103/32 exit exit exit #------------------------------------------ A:ALA-A> config# 7210 SAS D, E, K OS Router Configuration Guide Page 25...

  • Page 26: Common Configuration Tasks

    A:ALA-A>config>system# info #------------------------------------------ # System Configuration #------------------------------------------ name "ALA-A" location "Mt.View, CA, NE corner of FERG 1 Building" coordinates "37.390, -122.05500 degrees lat." snmp exit . . . exit ---------------------------------------------- Page 26 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 27: Configuring Interfaces

    IP address to the interface in the IES context and create logical IP interfaces for inband management. Note that the system interface cannot be deleted. Configuring a System Interface To configure a system interface: CLI Syntax: config>router interface interface-name address {[ip-address/mask]|[ip-address] [netmask]} 7210 SAS D, E, K OS Router Configuration Guide Page 27...

  • Page 28: Configuring Ipv6 Parameters

    [number seconds] redirects [number seconds] time-exceeded [number seconds] unreachables [number seconds] neighbor ipv6-address mac-address The following displays a configuration example showing interface information. A:ALA-49>config>router>if# info ---------------------------------------------- address 10.11.10.1/64 Page 28 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 29

    IP Router Configuration port 1/1/10 ipv6 address 10::1/64 exit ---------------------------------------------- A:ALA-49>config>router>if# 7210 SAS D, E, K OS Router Configuration Guide Page 29...

  • Page 30: Router Advertisement

    ---------------------------------------------- interface "n1" prefix 3::/64 exit use-virtual-mac no shutdown exit ---------------------------------------------- *A:sim131>config>router>router-advert# interface n1 *A:sim131>config>router>router-advert>if# prefix 3::/64 *A:sim131>config>router>router-advert>if>prefix# info detail ---------------------------------------------- autonomous on-link preferred-lifetime 604800 valid-lifetime 2592000 ---------------------------------------------- *A:tahi>config>router>router-advert>if>prefix# Page 30 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 31: Service Management Tasks

    "Mt.View, CA, NE corner of FERG 1 Building" coordinates "37.390, -122.05500 degrees lat." synchronize snmp exit security snmp community "private" rwa version both exit exit . . . ---------------------------------------------- A:TGIF>config>system# 7210 SAS D, E, K OS Router Configuration Guide Page 31...

  • Page 32: Deleting A Logical Ip Interface

    2. After the interface has been shut down, it can then be deleted with the no interface command. CLI Syntax: config>router no interface ip-int-name Example config>router# interface test-interface config>router>if# shutdown config>router>if# exit config>router# no interface test-interface config>router# Page 32 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 33: Ip Router Command Reference

    • Router Interface Commands on page 35 • Router Interface IPv6 Commands (supported only on 7210 SAS-D) on page 36 • Show Commands on page 37 • Clear Commands on page 38 7210 SAS D, E, K OS Router Configuration Guide Page 33...

  • Page 34: Router Commands

    [enable | disable] next-hop ip-address — [no] static-route {ip-prefix/prefix-length | ip-prefix netmask} [preference preference] [met- ric metric] [enable | disable] black-hole — interface interface-name — no interface interface-name Page 34 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 35: Router Interface Commands

    — icmp — redirects [number seconds] — no redirects — ttl-expired [number seconds] — no ttl-expired — unreachables [number seconds] — no unreachables — [no] loopback — [no] shutdown 7210 SAS D, E, K OS Router Configuration Guide Page 35...

  • Page 36: Router Interface Ipv6 Commands (supported Only On 7210 Sas-d)

    — no unreachables — link-local-address ipv6-address [preferred] — [no] local-proxy-nd — neighbor ipv6-address [mac-address] — no neighbor ipv6-address — proxy-nd-policy policy-name [ policy-name...(up to 5 max)] — no proxy-nd-policy Page 36 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 37: Show Commands

    [interface interface-name] [prefix ipv6-prefix[/prefix-length] [conflicts] — static-arp [ip-address | ip-int-name | mac ieee-mac-addr] — static-route [family] [[ip-prefix /mask] [ip-prefix /prefix-length] | [preference preference] | [next-hop ip-address| tag tag] | [detail] — status 7210 SAS D, E, K OS Router Configuration Guide Page 37...

  • Page 38: Clear Commands

    — [no] interface [ip-int-name | ip-address] — neighbor [ip-int-name] — packet [ip-int-name | ip-address] [headers] [protocol-id] — no packet [ip-int-name | ip-address] — route-table [ip-prefix/prefix-length] [longer] — no route-table Page 38 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 39

    — The description character string. Allowed values are any string up to 80 characters long composed of printable, 7-bit ASCII characters. If the string contains special characters (#, $, spaces, etc.), the entire string must be enclosed within double quotes. 7210 SAS D, E, K OS Router Configuration Guide Page 39...

  • Page 40

    — The preference of this static route versus the routes from different sources such as OSPF, expressed as a decimal integer. When modifing the preference of an existing static route, the metric will not be changed unless specified. Page 40 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 41

    IP address, mask, and any other parameter that is required to identify the exact static route. The administrative state is maintained in the configuration file. Default enable 7210 SAS D, E, K OS Router Configuration Guide Page 41...

  • Page 42

    Configuration Commands Page 42 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 43

    IP interface. If ip-int-name does not exist, the interface is created and the context is changed to that interface for further command processing. accounting-policy Syntax accounting-policy acct-policy-id no accounting-policy Context config>router 7210 SAS D, E, K OS Router Configuration Guide Page 43...

  • Page 44

    IP address. Allowed values are integers in the range 1— 32. Note that a mask length of 32 is reserved for system IP addresses. Values 1 — 32 Page 44 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 45

    This command creates a delay to make the interface operational by the specified number of seconds The value is used whenever the system attempts to bring the interface operationally up. 7210 SAS D, E, K OS Router Configuration Guide Page 45...

  • Page 46

    Allowed values are any non-broadcast, non-multicast MAC and non-IEEE reserved MAC addresses. proxy-arp-policy Syntax [no] proxy-arp-policy policy-name [policy-name...(up to 5 max)] Page 46 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 47

    The specified policy name(s) must already be defined. remote-proxy-arp Syntax [no] remote-proxy-arp Context config>router>interface Description This command enables remote proxy ARP on the interface. Default no remote-proxy-arp 7210 SAS D, E, K OS Router Configuration Guide Page 47...

  • Page 48

    10 — 1000 seconds — The time frame, in seconds, used to limit the number of ICMP redirect messages that can be issued,expressed as a decimal integer. Values 1 — 60 Page 48 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 49

    100 10 — Maximum of 100 unreachable messages in 10 seconds. Parameters number — The maximum number of ICMP unreachable messages to send, expressed as a decimal integer. The seconds parameter must also be specified. Values 10 — 1000 7210 SAS D, E, K OS Router Configuration Guide Page 49...

  • Page 50

    10 — 1000 seconds — Determines the time frame, in seconds, that is used to limit the number of param-problem messages issued per time frame. Values 1 — 60 Page 50 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 51

    [number seconds] no unreachables Context config>router>if>ipv6>icmp6 Description This command configures the rate for ICMPv6 unreachable messages. When enabled, ICMPv6 host and network unreachable messages are generated by this interface. 7210 SAS D, E, K OS Router Configuration Guide Page 51...

  • Page 52

    7-bit ASCII characters. If the string contains special characters (#, $, spaces, etc.), the entire string must be enclosed within double quotes. The specified policy name(s) must already be defined. Page 52 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 53

    (eight 16-bit pieces) x:x:x:x:x:x:d.d.d.d [0 — FFFF]H [0 — 255]D mac-address — Specifies the MAC address for the neighbor in the form of xx:xx:xx:xx:xx:xx or xx- xx-xx-xx-xx-xx. 7210 SAS D, E, K OS Router Configuration Guide Page 53...

  • Page 54

    Configuration Commands Page 54 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 55

    The IP interface name associated with the ARP entry. Interface The number of ARP entries displayed in the list. No. of ARP Entries Sample Output *B:7710-Red-RR# show router arp =============================================================================== 7210 SAS D, E, K OS Router Configuration Guide Page 55...

  • Page 56

    Interface Specifies the link-layer address. MAC Address Displays the current administrative state. State Displays the number of seconds until the entry expires. Displays the type of IPv6 interface. Type Page 56 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 57

    *A:Dut-A>config>router# show router neighbor static =============================================================================== Neighbor Table (Router: Base) =============================================================================== IPv6 Address Interface MAC Address State Expiry Type ------------------------------------------------------------------------------- 2193:12:17:1::5 A_to_B2_17 00:00:1b:00:00:01 REACHABLE Static ------------------------------------------------------------------------------- No. of Neighbor Entries: 1 7210 SAS D, E, K OS Router Configuration Guide Page 57...

  • Page 58

    Show Commands =============================================================================== *A:Dut-A>config>router# show router neighbor ma managed *A:Dut-A>config>router# show router neighbor managed =============================================================================== Neighbor Table (Router: Base) =============================================================================== IPv6 Address Interface MAC Address State Expiry Type Page 58 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 59

    The number of packets received from the DHCP clients that were Client Packets snooped. Snooped The number of packets received from the DHCP server that were dis- Server Packets carded. Discarded 7210 SAS D, E, K OS Router Configuration Guide Page 59...

  • Page 60

    ARP populate. 7210 SAS does not maintain lease state. Used/Provided Indicates whether Option 82 processing is enabled on the interface. Info Option Indicates the administrative state. Admin State Page 60 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 61

    — Displays FIB entries only matching the specified ip-prefix and length. ipv4-prefix: a.b.c.d (host bits must be 0) ipv4-prefix-length: 0 — 32longer — Displays FIB entries matching the ip-prefix/mask and routes with longer masks. 7210 SAS D, E, K OS Router Configuration Guide Page 61...

  • Page 62

    Neighbor Adver- tisements Sample Output A:SR-3>show>router>auth# show router icmp6 =============================================================================== Global ICMPv6 Stats =============================================================================== Received Total : 14 Errors Destination Unreachable : 5 Redirects Time Exceeded Pkt Too Big Page 62 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 63

    The number of echo replies. Echo Reply The number of times the router advertised its location. Router Advertise- ments The number of times the neighbor router advertised its location. Neighbor Adver- tisements 7210 SAS D, E, K OS Router Configuration Guide Page 63...

  • Page 64

    Up — The IP interface is operationally disabled. Network — The IP interface is a network/core IP interface. Mode The physical network port associated with the IP interface. Port Page 64 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 65

    The interface index of the IP router interface. If Index The virtual interface index of the IP router interface. Virt If Index The last change in operational status. Last Oper Change 7210 SAS D, E, K OS Router Configuration Guide Page 65...

  • Page 66

    : Bgp auto-discovery : Enabled UMH Selection : Highest-Ip intersite-shared : Enabled vrf-import : N/A vrf-export : N/A vrf-target : target:1:1 C-Mcast Import RT : target:10.20.1.3:2 ipmsi : pim-asm 224.1.1.1 Page 66 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 67

    The protocol through which the route was learned. Protocol The route age in seconds for the route. The route metric value for the route. Metric A:ALA# show router route-table =============================================================================== Route Table (Router: Base) =============================================================================== 7210 SAS D, E, K OS Router Configuration Guide Page 67...

  • Page 68

    Total active and available routes are also displayed. Sample Output A:ALA-A# show router route-table summary =============================================================================== Route Table Summary =============================================================================== Active Available ------------------------------------------------------------------------------- Static Direct ------------------------------------------------------------------------------- Total =============================================================================== A:ALA-A# Page 68 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 69

    12.200.1.1 00:00:5a:01:00:33 00:00:00 Inv to-ser1a ------------------------------------------------------------------------------- No. of ARP Entries: 1 =============================================================================== A:ALA-A# A:ALA-A# show router static-arp 12.200.1.1 =============================================================================== ARP Table =============================================================================== IP Address MAC Address Type Interface ------------------------------------------------------------------------------- 7210 SAS D, E, K OS Router Configuration Guide Page 69...

  • Page 70

    — Displays the tag used to add a 32-bit integer tag to the static route. The tag is used in route policies to control distribution of the route into other protocols. Values 1 — 4294967295 Page 70 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 71

    192.168.253.0/24 to-ser1 192.168.253.0/24 10.10.0.254 192.168.254.0/24 black-hole =============================================================================== A:ALA-A# A:ALA-A# show router static-route 192.168.250.0/24 =============================================================================== Route Table =============================================================================== IP Addr/mask Pref Metric Type Nexthop Interface Active ------------------------------------------------------------------------------- 192.168.250.0/24 10.200.10.1 to-ser1 7210 SAS D, E, K OS Router Configuration Guide Page 71...

  • Page 72

    The total number of routes in the route table. Total Routes Sample Output A:DUT-B>show>router# show router status ================================================================ Router Status (Router: Base) ================================================================ Admin State Oper State ---------------------------------------------------------------- Router Page 72 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 73

    IP Router Configuration Max Routes 10000 Total IPv4 Routes ECMP Max Routes ================================================================ A:DUT-B>show>router# 7210 SAS D, E, K OS Router Configuration Guide Page 73...

  • Page 74

    Syntax icmp6 all icmp6 global icmp6 interface interface-name Context clear>router Description This command clears ICMP statistics. Parameters all — Clears all statistics. global — Clears global statistics. Page 74 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 75

    [interface ip-int-name | ipv6-address] Context clear>router Description This command clears IPv6 neighbor information. Parameters all — Clears IPv6 neighbors. ip-int-name — Clears the specified neighbor interface information. Values 32 characters maximum 7210 SAS D, E, K OS Router Configuration Guide Page 75...

  • Page 76

    This command clears all router advertisement counters. Parameters all — Clears all router advertisement counters for all interfaces. interface interface-name — Clear router advertisement counters for the specified interface. Page 76 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 77

    Description This command configures debugging for IP. Syntax Context debug>router>ip Description This command configures route table debugging. icmp Syntax [no] icmp Context debug>router>ip Description This command enables ICMP debugging. 7210 SAS D, E, K OS Router Configuration Guide Page 77...

  • Page 78

    (host bits must be 0) ipv6-address x:x:x:x:x:x:x:x (eight 16-bit pieces) x:x:x:x:x:x:d.d.d.d x: [0 — FFFF]H d: [0 — 255]D headers — Only displays information associated with the packet header. Page 78 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 79

    0 — 32 longer — Specifies the prefix list entry matches any route that matches the specified ip-prefix and pre- fix mask length values greater than the specified mask. 7210 SAS D, E, K OS Router Configuration Guide Page 79...

  • Page 80

    Debug Commands Page 80 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 81: Filter Policies

    Filter Policy Configuration Overview on page 82 → Service -Based Filtering on page 82 → Filter Policy Entities on page 84 • Creating and Applying Policies on page 88 • Configuration Notes on page 97 7210 SAS D, E, K OS Router Configuration Guide Page 81...

  • Page 82: Filter Policy Configuration Overview

    Filter entry matching criteria can be as general or specific as you require, but all conditions in the entry must be met in order for the packet to be considered a match and the specified entry action Page 82 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 83

    The process stops when the first complete match is found and executes the action defined in the entry, either to drop or forward packets that match the criteria. 7210 SAS D, E, K OS Router Configuration Guide Page 83...

  • Page 84: Filter Policy Entities

    IES — Only IP filters are supported on IES SAP • VPLS — Both MAC and IP filters are supported on a VPLS SAP. The tables below provides more details on use of filter policies. Page 84 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 85: Table 4: Applying Filter Policies For 7210 Sas-d And 7210 Sas-k

    Routed VPLS is not Routed VPLS is not Routed VPLS is not SAPs) supported supported supported Ingress and egress of Not Available Not Available IES access SAP and IES access-uplink 7210 SAS D, E, K OS Router Configuration Guide Page 85...

  • Page 86: Acl On Range Saps

    Table 6: Applying ACLs support on Epipe and VPLS services on 7210 SAS-D and 7210 SAS- K variants when using range SAPs Types of filters Epipe VPLS Ingress IP or IPv6 Ingress MAC Egress IP Egress MAC Page 86 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 87

    NOTE: For details on filter support for various services and SAPs on different platforms, see “Table 4, “Applying Filter Policies for 7210 SAS-D and 7210 SAS-K,”Table 5, “Applying Filter Policies for 7210 SAS-E,”Table 7, “Applying Filter Policies for 7210 SAS-K,”. 7210 SAS D, E, K OS Router Configuration Guide Page 87...

  • Page 88: Creating And Applying Policies

    SPECIFY SCOPE, DEFAULT ACTION, DESCRIPTION CREATE AN IP OR MAC FILTER (FILTER ID) CREATE FILTER ENTRIES (ENTRY ID) SPECIFY ACTION, PACKET MATCHING CRITERIA CREATE SERVICE ASSOCIATE FILTER ID SAVE CONFIGURATION Page 88 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 89: Packet Matching Criteria

    ICMP code — Entering an ICMP code allows the filter to search for matching ICMP code in the ICMP header. • ICMP type — Entering an ICMP type allows the filter to search for matching ICMP types in the ICMP header. 7210 SAS D, E, K OS Router Configuration Guide Page 89...

  • Page 90

    Entering the Inner Dot1p value or range (using the mask) allows the filter to search for frames whose inner Dot1p (thats is, the Dot1p in the VLAN tag immediately following the Page 90 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 91

    Filter Policies outermost VLAN tag of the packet) matches the Dot1p value configured. The Dot1p value and mask accepts decimal values in the range 0 to 7. 7210 SAS D, E, K OS Router Configuration Guide Page 91...

  • Page 92: Table 7: Dscp Name To Dscp Value Table

    DSCP Name Decimal Hexadecimal Binary DSCP Value DSCP Value DSCP Value default af11 af12 cp13 cp15 cp17 af21 cp19 af22 cp21 af23 cp23 cp25 af31 cp27 af32 cp29 af33 cp21 Page 92 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 93: Filter Policies

    DSCP Value cp33 af41 cp35 af42 cp37 af43 cp39 cp41 cp42 cp43 cp44 cp45 cp47 (cs6) cp49 cp50 cp51 cp52 cp53 cp54 cp55 cp56 cp57 (cs7) cp60 cp61 cp62 7210 SAS D, E, K OS Router Configuration Guide Page 93...

  • Page 94: Ordering Filter Entries

    If a packet does not completely match, the packet continues to the next entry, and then subsequent entries. • If a packet does not completely match any subsequent entries, then the default action is performed. Page 94 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 95: Filter Policies

    REMAINING PACKETS ARE DROPPED PER THE DEFAULT ACTION (DROP) SA: 10.10.10.103, DA: 10.10.10.107 SA: 10.10.10.103, DA: 10.10.10.108 SA: 10.10.10.192, DA: 10.10.10.16 SA: 10.10.10.155, DA: 10.10.10.21 Figure 2: Filtering Process Example 7210 SAS D, E, K OS Router Configuration Guide Page 95...

  • Page 96: Applying Filters

    If the packet completely matches all criteria in an entry, the checking stops. If permitted, the traffic is forwarded. If the packets do not match, they are discarded or forwarded based on the default action specified in the policy. Page 96 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 97: Configuration Notes

    By default, the system allocates resources to maintain backward compatibility with release 4.0. Users can modify 7210 SAS D, E, K OS Router Configuration Guide Page 97...

  • Page 98: Mac Filters

    Ethernet frame. Use the following table to determine the exclusivity of fields.In the 7210 SAS, the default frame-format is “EthernetII” Table 8: MAC Match Criteria Exclusivity Rules Frame Format Etype Ethernet – II 802.3 802.3 – snap 802.3-llc Page 98 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 99: Ip Filters

    "configure> system> resource-profile> ingress-internal-tcam> acl-sap-ingress> ipv4-match-enable" before using ingress ACLs with ipv4-criteria. The resource usage per IPv4 match entry is same as the mac-criteria. Please check the above 7210 SAS D, E, K OS Router Configuration Guide Page 99...

  • Page 100: Resource Usage For Egress Filter Policies (supported Only For 7210 Sas-d)

    When the user allocates resources for use by filter policies using the configure> system> resource- profile> egress-internal-tcam> CLI commands, the system allocates resources in chunks of 128 Page 100 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 101

    SAP uses ipv6-64bit-criteria or any combination thereof. • ipv4-criteria - The user need to allocate resources using the command "configure> system> resource-profile> egress-internal-tcam> acl-sap-egress> mac-ipv4-match- enable". The resource usage is as explained above. 7210 SAS D, E, K OS Router Configuration Guide Page 101...

  • Page 102: Resource Usage For Ingress Filter Policies For 7210 Sas-k

    128-bit addresses or allocation only a portion of it. The entries allocated are used by filter policies that use ipv6 criteria with 128-bit addresses. Each filter entry configured in the policy takes away Page 102 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 103

    64-bit address. Irrespective of the criteria, two (2) resources are taken for each entry configured on the filter policy. Use “tools>dump> system-resources” command to know the current usage and availability 7210 SAS D, E, K OS Router Configuration Guide Page 103...

  • Page 104

    Configuration Notes Page 104 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 105: Configuring Filter Policies With Cli

    Modifying an IP Filter Policy on page 119 → Deleting a Filter Policy on page 122 → Deleting a Filter Policy on page 122 → Copying Filter Policies on page 124 7210 SAS D, E, K OS Router Configuration Guide Page 105...

  • Page 106: Basic Configuration

    The following example displays a sample configuration of allocation of egress internal CAM resources for egress policy for 7210 SAS-D: A:SASD>config>system>res-prof>egr-internal-tcam# info detail ---------------------------------------------- acl-sap-egress 2 mac-ipv4-match-enable 2 ipv6-128bit-match-enable 0 mac-ipv6-64bit-match-enable 0 mac-match-enable 0 exit ---------------------------------------------- *A:SASD>config>system>res-prof>egr-internal-tcam# acl-sap-egress Page 106 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 107: Figure 3: Applying An Ip Filter To An Ingress Interface

    A:ALA-1>config>filter# The following figure shows the IP filter applied to an ingress interface. Ingress Filter ALA-1 TCP Connection OSRG007 Figure 3: Applying an IP Filter to an Ingress Interface 7210 SAS D, E, K OS Router Configuration Guide Page 107...

  • Page 108: Common Configuration Tasks

    Configure CAM hardware resource for use by the filter policy match-criteria IP Filter Policy The following displays an exclusive filter policy configuration example: A:ALA-7>config>filter# info ---------------------------------------------- ip-filter 12 create description "IP-filter" scope exclusive exit ---------------------------------------------- A:ALA-7>config>filter# Page 108 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 109

    Filter Policies 7210 SAS D, E, K OS Router Configuration Guide Page 109...

  • Page 110: Ip Filter Entry

    The following displays an IP filter entry configuration example. A:ALA-7>config>filter>ip-filter# info ---------------------------------------------- description "filter-main" scope exclusive entry 10 create description "no-91" match exit no action exit exit ---------------------------------------------- A:ALA-7>config>filter>ip-filter# Page 110 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 111: Ip Entry Matching Criteria

    • Enter an IPv6 filter entry ID. The system does not dynamically assign a value. • Assign an action, either drop or forward. 7210 SAS D, E, K OS Router Configuration Guide Page 111...

  • Page 112

    1 create no description match next-header none no dscp no dst-ip no dst-port src-ip 1::1/128 no src-port no tcp-syn no tcp-ack no icmp-type no icmp-code exit action forward exit *A:7210SAS>config>filter>ipv6-filter# Page 112 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 113: Creating A Mac Filter Policy

    • Matching criteria specified. MAC Filter Policy The following displays an MAC filter policy configuration example: A:ALA-7>config>filter# info ---------------------------------------------- mac-filter 90 create description "filter-west" scope exclusive exit ---------------------------------------------- A:ALA-7>config>filter# 7210 SAS D, E, K OS Router Configuration Guide Page 113...

  • Page 114: Mac Filter Entry

    Specify matching criteria. The following displays a MAC filter entry configuration example: A:sim1>config>filter# info ---------------------------------------------- mac-filter 90 create entry 1 create description "allow-104" match exit action drop exit exit ---------------------------------------------- A:sim1>config>filter# Page 114 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 115: Mac Entry Matching Criteria

    The following output displays IP and MAC filters assigned to an ingress and egress SAP: A:ALA-48>config>service>epipe# info ---------------------------------------------- sap 1/1/1.1.1 create ingress filter ip 10 exit egress filter mac 92 exit exit no shutdown ---------------------------------------------- A:ALA-48>config>service>epipe# 7210 SAS D, E, K OS Router Configuration Guide Page 115...

  • Page 116: Apply Filter Policies To An Ies Interface

    The following displays an IP filter applied to an IES sap at ingress. A:ALA-48>config>service>ies# info ---------------------------------------------- interface "to-104" create address 10.1.2.1/24 sap lag-2:0.* create ingress filter ip 10 exit exit ---------------------------------------------- A:ALA-48>config>service>ies# Page 116 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 117: Filter Management Tasks

    Use the following CLI syntax to renumber existing MAC or IP filter entries to re-sequence filter entries: CLI Syntax: config>filter ip-filter filter-id renum old-entry-number new-entry-number mac-filter filter-id renum old-entry-number new-entry-number Example config>filter>ip-filter# renum 10 15 config>filter>ip-filter# renum 20 10 config>filter>ip-filter# renum 40 1 7210 SAS D, E, K OS Router Configuration Guide Page 117...

  • Page 118

    40 create entry 30 create match match dst-ip 10.10.10.91/24 dst-ip 10.10.10.91/24 src-ip 10.10.10.106/24 src-ip 10.10.0.200/24 exit exit action drop action forward exit exit exit exit ---------------------------------------------- ---------------------------------------------- A:ALA-7>config>filter# A:ALA-7>config>filter# Page 118 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 119: Modifying An Ip Filter Policy

    10.10.10.104/32 exit action drop exit entry 10 create match dst-ip 10.10.10.91/24 src-ip 10.10.0.100/24 exit action drop exit entry 15 create description "no-91" match dst-ip 10.10.10.91/24 src-ip 10.10.10.103/24 exit action 7210 SAS D, E, K OS Router Configuration Guide Page 119...

  • Page 120

    Common Configuration Tasks forward exit entry 30 create match dst-ip 10.10.10.91/24 src-ip 10.10.0.200/24 exit action forward exit exit ---------------------------------------------- A:ALA-7>config>filter# Page 120 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 121: Modifying A Mac Filter Policy

    "New entry info" match src-mac 00:dc:98:1d:00:00 ff:ff:ff:ff:ff:ff dst-mac 02:dc:98:1d:00:01 ff:ff:ff:ff:ff:ff exit action forward exit entry 2 create match dot1p 7 7 exit action drop exit exit ---------------------------------------------- A:ALA-7>config>filter# 7210 SAS D, E, K OS Router Configuration Guide Page 121...

  • Page 122: Deleting A Filter Policy

    To remove a filter from an egress SAP, enter the following CLI commands: CLI Syntax: config>service# [epipe | ies | vpls] service-id sap port-id[:encap-val] egress no filter Example config>service# epipe 5 config>service>epipe# sap 1/1/2:3 config>service>epipe>sap# egress config>service>epipe>sap>egress# no filter Page 122 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 123: From The Filter Configuration

    After you have removed the filter from the SAP, use the following CLI syntax to delete the filter. CLI Syntax: config>filter# no ip-filter filter-id CLI Syntax: config>filter# no mac-filter filter-id Example config>filter# no ip-filter 11 config>filter# no mac-filter 7210 SAS D, E, K OS Router Configuration Guide Page 123...

  • Page 124: Copying Filter Policies

    2 create ip-filter 12 create description "This is new" scope exclusive entry 1 create match dst-ip 10.10.10.91/24 src-ip 10.10.10.106/24 exit action drop exit entry 2 create ---------------------------------------------- A:ALA-7>config>filter# Page 124 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 125: Filter Command Reference

    {ip-address/mask | ip-address netmask} — no dst-ip — dst-port {eq} dst-port-number — no dst-port — fragment {true | false} — no fragment — icmp-code icmp-code — no icmp-code 7210 SAS D, E, K OS Router Configuration Guide Page 125...

  • Page 126

    — src-ip{ip-address/mask | ip-address netmask} — no src-ip — src-port {{eq} src-port-number — no src-port — tcp-ack {true | false} — no tcp-ack — tcp-syn {true | false} — no tcp-syn Page 126 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 127

    [ipv6-address/prefix-length] — tcp-ack {true | false} — no tcp-ack — tcp-syn {true | false} — no tcp-syn — renum old-entry-id new-entry-id — scope {exclusive | template} — no scope 7210 SAS D, E, K OS Router Configuration Guide Page 127...

  • Page 128

    — src-mac ieee-address [ieee-address-mask] — no src-mac — filter-name filter-name — no filter-name — renum old-entry-id new-entry-id — scope {exclusive | template} — no scope — type filter-type Page 128 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 129

    [vid-mask] — src-mac ieee-address [ieee-address-mask] — no src-mac — filter-name filter-name — no filter-name — renum old-entry-id new-entry-id — scope {exclusive | template} — no scope — type filter-type 7210 SAS D, E, K OS Router Configuration Guide Page 129...

  • Page 130

    [interval seconds] [repeat repeat] [absolute | rate] — ipv6 ipv6-filter-id entry entry-id [interval seconds] [repeat repeat] [absolute|rate] — mac-filter-id entry entry-id [interval seconds] [repeat repeat] [absolute | rate] Page 130 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 131

    — The description character string. Allowed values are any string up to 80 characters long composed of printable, 7-bit ASCII characters. If the string contains special characters (#, $, spaces, etc.), the entire string must be enclosed within double quotes. 7210 SAS D, E, K OS Router Configuration Guide Page 131...

  • Page 132

    — Indicates to the system that the hardware resources for the entries in this filter policy must be allocated from the IPv6 filter resource pool, if available. For more information see the CLI description above. Page 132 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 133

    That work-in-progress policy can be modified until complete and then written over the original filter 7210 SAS D, E, K OS Router Configuration Guide Page 133...

  • Page 134

    Values 1 — 65535 create — Keyword required when first creating the configuration context. Once the context is created, one can navigate into the context without the create keyword. Page 134 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 135

    If the policy is removed from the entity, it will become available for assignment to another entity. template — When the scope of a policy is defined as template, the policy can be applied to multiple SAPs or . 7210 SAS D, E, K OS Router Configuration Guide Page 135...

  • Page 136

    32 characters in length. The time-range name must already exist in the config>cron context. create — Keyword required when first creating the configuration context. Once the context is created, one can navigate into the context without the create keyword. Page 136 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 137

    — The protocol keyword configures an IP protocol to be used as an IP filter match criterion. The protocol type such as TCP or UDP is identified by its respective protocol number. 7210 SAS D, E, K OS Router Configuration Guide Page 137...

  • Page 138

    Virtual Router Redundancy Protocol l2tp Layer Two Tunneling Protocol Spanning Tree Protocol Performance Transparency Protocol isis ISIS over IPv4 crtp Combat Radio Transport Protocol crudp Combat Radio User Datagram Page 138 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 139

    A match context may consist of multiple match criteria, but multiple match statements cannot be entered per entry. The no form of the command removes the match criteria for the entry-id. 7210 SAS D, E, K OS Router Configuration Guide Page 139...

  • Page 140

    — The frame-type keyword configures an Ethernet frame type to be used for the MAC filter match criteria. ethernet_II — Specifies the frame type is Ethernet Type II. Page 140 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 141

    — The IP prefix for the IP match criterion in dotted decimal notation. Values 0.0.0.0 — 255.255.255.255 ipv6-address — The IPv6 prefix for the IP match criterion in dotted decimal notation. Values ipv6-address x:x:x:x:x:x:x:x (eight 16-bit pieces) x:x:x:x:x:x::d.d.d.d 7210 SAS D, E, K OS Router Configuration Guide Page 141...

  • Page 142

    — Configures a match on all fragmented IP packets. A match will occur for all packets that have either the MF (more fragment) bit set OR have the Fragment Offset field of the IP header set to a non-zero value. Page 142 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 143

    The no form of the command removes the criterion from the match entry. Default no icmp-type Parameters icmp-type — The ICMP type values that must be present to match. Values 0 — 255 7210 SAS D, E, K OS Router Configuration Guide Page 143...

  • Page 144

    0.0.0.0 — 255.255.255.255 mask — The subnet mask length expressed as a decimal integer. Values 0 — 32 netmask — Any mask epressed in dotted quad notation. Values 0.0.0.0 — 255.255.255.255 Page 144 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 145

    — Specifies matching on IP packets that do not have the ACK bit set in the control bits of the TCP header of the IP packet. tcp-syn Syntax tcp-syn {true | false} no tcp-syn Context config>filter>ip-filter>entry>match config>filter>ipv6-filter>entry>match 7210 SAS D, E, K OS Router Configuration Guide Page 145...

  • Page 146

    — Specifies matching on IP packets that have the SYN bit set in the control bits of the TCP header. false — Specifies matching on IP packets that do not have the SYN bit set in the control bits of the TCP header. Page 146 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 147

    To select a range from 4 up to 7 specify p-value of 4 and a mask of 0b100 for value and mask. Default 7 (decimal) Values 1 — 7 (decimal) 7210 SAS D, E, K OS Router Configuration Guide Page 147...

  • Page 148

    The Ethernet type field is used by the Ethernet version-II frames. IEEE 802.3 Ethernet frames do not use the type field. The no form of the command removes the previously entered etype field as the match criteria. Page 148 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 149

    7 would match all VIDs with the lower 3 bits set to 6. The no form of this command removes the previously entered VLAN tag value as the match criteria. Default no inner-tag 7210 SAS D, E, K OS Router Configuration Guide Page 149...

  • Page 150

    7 would match all VIDs with the lower 3 bits set to 6. The no form of this command removes the previously entered VLAN tag value as the match criteria. Page 150 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 151

    To configure so that all packets with a source MAC OUI value of 00-03-FA are subject to a match condition then the entry should be specified as: 003FA000000 0xFFFFFF000000 Default 0xFFFFFFFFFFFF (exact match) Values 0x00000000000000 — 0xFFFFFFFFFFFF 7210 SAS D, E, K OS Router Configuration Guide Page 151...

  • Page 152

    ID to reference the given policy in the CLI. Default no filter-name Parameters filter-name — A string of up to 64 characters uniquely identifying this filter policy. Page 152 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 153

    — Regular match criteria are allowed; ISID or VID filter match criteria not allowed. isid — Only ISID match criteria are allowed. vid — On.y VID match criteria are allowed on ethernet_II frame types. 7210 SAS D, E, K OS Router Configuration Guide Page 153...

  • Page 154

    Configuration Commands Page 154 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 155

    — Displays detailed information for the specified filter ID and its filter entries. Values 1 — 65535 entry entry-id — Displays information on the specified filter entry ID for the specified filter ID only. Values 1 — 65535 7210 SAS D, E, K OS Router Configuration Guide Page 155...

  • Page 156

    =============================================================================== IP Filters Total: =============================================================================== Filter-Id Scope Applied Description ------------------------------------------------------------------------------- 10001 Template Yes fSpec-1 Template Yes BGP FlowSpec filter for the Base router ------------------------------------------------------------------------------- Num IP filters: 2 =============================================================================== Page 156 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 157

    If the filter entry ID indicates the entry is , the filter entry is incomplete, no action was specified. Inactive Drop packets matching the filter entry. Drop — 7210 SAS D, E, K OS Router Configuration Guide Page 157...

  • Page 158

    ICMP Code : Undefined TCP-syn : Off TCP-ack : Off Match action : Drop Ing. Matches : 0 Egr. Matches =============================================================================== A:ALA-49>config>filter# *A:Dut-C>config>filter# show filter ip fSpec-1 associations =============================================================================== Page 158 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 159

    Fragment : Off Option-present : Off Sampling : Off Int. Sampling : On IP-Option : 0/0 Multiple Option: Off TCP-syn : Off TCP-ack : Off Match action : Drop 7210 SAS D, E, K OS Router Configuration Guide Page 159...

  • Page 160

    : Undefined ICMP Code : Undefined Fragment : Off Option-present : Off TCP-syn : Off TCP-ack : Off Match action : Forward Ing. Matches : 0 Egr. Matches =============================================================================== A:ALA-49# Page 160 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 161

    Entries ------------------------------------------------------------------------------- Filter Association : IP ------------------------------------------------------------------------------- Service Id : 1001 Type : VPLS - SAP 1/1/1:1001 (Ingress) Service Id : 2000 Type - SAP 1/1/1:2000 (Ingress) =============================================================================== A:ALA-49# 7210 SAS D, E, K OS Router Configuration Guide Page 161...

  • Page 162

    The number of egress filter matches/hits for the filter entry. Egr. Matches Note that egress counters count the packets without Layer 2 encapsula- tion. Ingress counters count the packets with Layer 2 encapsulation. Page 162 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 163: Table 9: Show Filter (no Filter-id Specified)

    The IP filter policy description. Description Sample Output *A:7210SAS>show>filter# ipv6 =============================================================================== IPv6 Filters Total: =============================================================================== Filter-Id Scope Applied Description ------------------------------------------------------------------------------- Template Yes ------------------------------------------------------------------------------- Num IPv6 filters: 1 =============================================================================== *A:7210SAS>show>filter# 7210 SAS D, E, K OS Router Configuration Guide Page 163...

  • Page 164: Table 10: Show Filter (with Filter-id Specified)

    True — Configured a match on packets with the SYN flag set to true. Off — The state of the TCP SYN flag is not considered as part of the match criteria. Page 164 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 165

    Filter Match Criteria : IPv6 ------------------------------------------------------------------------------- Entry Description : Test Src. IP : 1::1/128 Src. Port : None Dest. IP : ::/0 Dest. Port : None Next Header : Undefined Dscp : Undefined 7210 SAS D, E, K OS Router Configuration Guide Page 165...

  • Page 166: Table 11: Show Filter Associations

    (Ingress) The filter policy ID is applied as an ingress filter policy on the interface. (Egress) The filter policy ID is applied as an egress filter policy on the interface. The type of service of the service ID. Type Page 166 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 167: Table 12: Show Filter Counters

    The filter ID filter entry ID. If the filter entry ID indicates the Entry entry is (Inactive), then the filter entry is incomplete as no action has been specified. 7210 SAS D, E, K OS Router Configuration Guide Page 167...

  • Page 168

    — Displays counter information for the specified filter ID. entry entry-id — Displays information on the specified filter entry ID for the specified filter ID only. Values 1 — 65535 Page 168 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 169

    VLAN tag. Undefined indicates no value is specified. The IEEE 802.1p value for the match criteria used to match the Dot1p in inner Dot1p the inner VLAN tag. Undefined indicates no value is specified. 7210 SAS D, E, K OS Router Configuration Guide Page 169...

  • Page 170

    Description : Not Available Src Mac : 00:00:00:00:00:00 00:00:00:00:00:00 Dest Mac : 00:00:00:00:00:00 00:00:00:00:00:00 Dot1p : Undefined Ethertype : Ethernet Match action : Default Ing. Matches Egr. Matches =============================================================================== Page 170 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 171

    Mac Filter Filter Id The filter policy is of type Template. Scope Template — The filter policy is of type Exclusive. Exclusive — The MAC filter policy description. Description 7210 SAS D, E, K OS Router Configuration Guide Page 171...

  • Page 172

    Mac Filter =============================================================================== Filter Id Applied : No Scope : Template Def. Action : Drop Entries Type : unknown Description : (Not Specified) ------------------------------------------------------------------------------- Filter Match Criteria : Mac Page 172 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 173

    Outer TagVal: none Outer TagMask : none Inner TagVal: none Inner TagMask : none Ethertype : Undefined Match action: Drop Ing. Matches: 0 pkts Egr. Matches: 0 pkts =============================================================================== 7210 SAS D, E, K OS Router Configuration Guide Page 173...

  • Page 174

    — Specifies that only the counters associated with the specified filter policy entry will be cleared. Values 1 — 65535 ingress — Specifies to only clear the ingress counters. egress — Specifies to only clear the egress counters. Page 174 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 175

    — Specifies that only the counters associated with the specified filter policy entry will be cleared. Values 1 — 65535 ingress — Specifies to only clear the ingress counters. egress — Specifies to only clear the egress counters. 7210 SAS D, E, K OS Router Configuration Guide Page 175...

  • Page 176

    — The IP filter policy ID. Values 1 — 65535 entry-id — Specifies that only the counters associated with the specified filter policy entry will be monitored. Values 1 — 65535 Page 176 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 177

    No calculations are performed on the delta or rate statistics. rate — When the rate keyword is specified, the rate-per-second for each statistic is displayed instead of the delta. 7210 SAS D, E, K OS Router Configuration Guide Page 177...

  • Page 178

    Show Commands Page 178 7210 SAS D, E, K OS Router Configuration Guide...

  • Page 179: Common Cli Command Descriptions

    Common CLI Command Descriptions In This Chapter This section provides information about common Command Line Interface (CLI) syntax and command usage. Topics in this chapter include: • SAP syntax on page 180 7210 SAS D, E OS Router Configuration Guide Page 179...

  • Page 180: Common Service Commands

    0 — 4094 The SAP is identified by two 802.1Q tags on the port. qtag2: 0 — 4094 Note that a 0 qtag1 value also accepts untagged packets on the Dot1q port. Page 180 7210 SAS D, E OS Router Configuration Guide...

  • Page 181: Standards And Protocol Support

    Standards and Protocol Support Standards Compliance Efficient Handling of in-Profile RFC 1215 A Convention for Defining IEEE 802.1ab-REV/D3 Station and Traffic [Only for 7210 SAS-D] Traps for use with the SNMP Media Access Control Connectivity RFC 1907 SNMPv2-MIB Discovery IPv6 (only 7210 SAS-D,E) RFC 2011 IP-MIB IEEE 802.1d Bridging RFC 2460 Internet Protocol, Version 6...

  • Page 182

    Standards and Protocols ITU-T G.8262 Telecommunication TIMETRA-SERV-MIB.mib Standardization Section of ITU, TIMETRA-SYSTEM-MIB.mib draft-ietf-secsh-architecture.txt SSH Timing characteristics of TIMETRA-TC-MIB.mib Protocol Architecture synchronous Ethernet equipment TIMETRA-VRTR-MIB.mib draft-ietf-secsh-userauth.txt SSH slave clock (EEC), issued 08/2007. Authentication Protocol ITU-T G.8264 Telecommunication draft-ietf-secsh-transport.txt SSH Standardization Section of ITU, Transport Layer Protocol Distribution of timing information draft-ietf-secsh-connection.txt SSH...

  • Page 183

    IP filter policy MAC filter policy management tasks IP Router overview interfaces system configuring basic command reference interfaces overview service management tasks system interface system name 7210 SAS D, E, K OS Router Configuration Guide Page 183...

  • Page 184

    7210 SAS D, E, K OS Router Configuration Guide Page 184...

  • Page 185: Documentation Feedback

    Customer Document and Product Support Customer documentation Customer Documentation Welcome Page Technical Support Product Support Portal Documentation feedback Customer Documentation Feedback...

  • Page 186

    © 2013, 2016 Nokia. 3HE11494AAAATQZZA...

This manual also for:

7210 sas k, 7210 sas e

Comments to this Manuals

Symbols: 0
Latest comments: