Force 10 Adit 3000 Series Reference Manual

Multi-service router (msr) card
Table of Contents

Advertisement

Quick Links

Adit 3000 Series and
Multi-Service Router (MSR) Card
CLI R
M
EFERENCE
ANUAL
Part Number: 770-0165-BC
Product Release: Adit 3000 Series - 1.6
MSR Card - 2.1
April 2009

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the Adit 3000 Series and is the answer not in the manual?

Questions and answers

Subscribe to Our Youtube Channel

Summary of Contents for Force 10 Adit 3000 Series

  • Page 1 Adit 3000 Series and Multi-Service Router (MSR) Card CLI R EFERENCE ANUAL Part Number: 770-0165-BC Product Release: Adit 3000 Series - 1.6 MSR Card - 2.1 April 2009...
  • Page 2 Copyright © 2009 Force10 Networks Inc. All rights reserved. ® Force10 Networks reserves the right to change, modify, revise this publication without notice. The hardware and software described herein are furnished under a license or non-disclosure agreement. The hardware, software, and manual may be used or copied only in accordance with the terms of this agreement. It is against the law to reproduce, transmit, transcribe, store in a retrieval system, or translate into any medium - electronic, mechanical, magnetic, optical, chemical, manual, or otherwise - any part of this manual or software supplied with the product for any purpose other than the purchaser’s personal use without the express written permission of Force10 Networks Inc.
  • Page 3: Preface

    REFACE Preface Safety Information CAUTION! HEN USING YOUR TELEPHONE EQUIPMENT BASIC SAFETY PRECAUTIONS SHOULD ALWAYS BE FOLLOWED TO REDUCE THE RISK OF FIRE ELECTRIC SHOCK AND INJURY TO PERSONS INCLUDING THE FOLLOWING Do not use this product near water for example, near a bathtub, washbowl, kitchen sink or laundry tub, in a wet basement or near a swimming pool.
  • Page 4: Notices

    Preface Notices This manual contains important information and warnings that must be followed to ensure safe operation of the equipment. DANGER! ANGER NOTICE INDICATES THE PRESENCE OF A HAZARD THAT CAN OR WILL CAUSE DEATH OR SEVERE PERSONAL INJURY IF THE HAZARD IS NOT AVOIDED CAUTION! AUTION NOTICE INDICATES THE POSSIBILITY OF INTERRUPTING NETWORK SERVICE IF THE HAZARD IS NOT AVOIDED...
  • Page 5: Table Of Contents

    ABLE OF ONTENTS Table of Contents Preface Safety Information ............. iii Notices .
  • Page 6 Table of Contents reload ..............3-18 show .
  • Page 7 Table of Contents remote-admin ............4-56 router ospf .
  • Page 8 Table of Contents Configuration - DHCP Pool Ethernet Mode do ..............7-2 end .
  • Page 9 Table of Contents Configuration - Dial Peer VoIP Mode destination-pattern ............10-2 do .
  • Page 10 Table of Contents release ..............11-23 remote-admin .
  • Page 11 Table of Contents ppp time-btwn-reconnect ..........12-24 ppp username .
  • Page 12 Table of Contents schedule-availability ........... . . 13-24 shutdown .
  • Page 13 Table of Contents Configuration - L2TPC Mode do ..............15-2 end .
  • Page 14 Table of Contents Configuration - OSPF Mode area commands ............16-2 compatible rfc1583 .
  • Page 15 Table of Contents ppp restart-timer ............17-23 ppp time-btwn-reconnect .
  • Page 16 Table of Contents Configuration - VLAN Port Mode do ..............21-2 end .
  • Page 17 Table of Contents history ..............24-7 input-gain .
  • Page 18 Table of Contents xviii Adit 3000 (Rel. 1.6) and MSR Card (Rel 2.1) CLI...
  • Page 19: Introduction

    The chapters are broken down into Modes and Configuration Groups. All commands that are listed in each group are described in the chapter. NOTE: Throughout this manual, examples primarily reflect the Adit 3000 series. Where differences exist for the MSR card, these differences are noted. In this Chapter...
  • Page 20: Overview

    Introduction Overview Overview The Adit 3000/MSR CLI has three command modes, each with access to different command sets. The following displays the basic flow of the CLI. Adit 3000 (Rel. 1.6) and MSR Card (Rel 2.1) CLI...
  • Page 21: Prompt Identifier

    Introduction Overview Prompt Identifier When you initiate a CLI session it will open in User mode, which is indicated by the ">" prompt. At any time you can quickly determine which mode you are in by the prompt. Command Access Method Prompt Displayed Exit Method Mode...
  • Page 22: Configuration Mode

    Introduction Overview Configuration Mode Allows users to configure specific features/functions. Use the configure terminal command to enter from Privileged mode. Identified by the (config)# prompt. Note: As the submodes change, the words inside the parentheses are modified. To exit Configuration mode, type exit or press Ctrl-Z. Configuration mode has various submodes: Configuration Mode Link to Command...
  • Page 23: Command Syntax Conventions

    Introduction Command Syntax Conventions Command Syntax Conventions The conventions used to present command syntax are as follows: Convention Description Vertical bars separate alternative, mutually exclusive elements. Example: (config)# clock source {1|2} {none|ds1 1|ds1 2|ds1 3|ds1 4} Square brackets indicate an optional element. Example: (config)# event-history priority [error|fatal|info|notice|warning] Braces indicate a required choice.
  • Page 24: Shortcuts

    Introduction Shortcuts Shortcuts Keystroke Description Up Arrow Use the up arrow key to re-display a previously entered command. Select the up arrow repeatedly, to scroll through all the commands entered starting with the most recent.  Will move curser one character to the left or right. Left and Right Arrow The question mark will display help for the current command.
  • Page 25: User Mode

    HAPTER User Mode User mode is the first level of commands after logging in. User mode is represented by the > prompt. User Mode Commands • date • enable • end • exit • help • history • ping • show •...
  • Page 26: End

    User Mode date Use the date command to display the current date. Syntax: > date Example: adit 3500> date Wed Jan 12 10:37:51 2007 Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: enable Use the enable command (at the User mode prompt) to enter the Privileged mode. Note: Once a correct password has been entered, the prompt changes from ">"...
  • Page 27: Help

    User Mode exit Use the exit command to close your current connection if you are in User mode or Privileged mode. If the command is entered in a subconfiguration mode (Interface or Routing), this command takes you to the previous level (example: back to Privileged mode from Interface configuration mode). Syntax: >...
  • Page 28: Ping

    User Mode history Use the history command to display commands that have been entered in this session. This command can be entered in any Configuration mode. Syntax: > history Example: Adit 3500> history date ping 192.168.1.1 -n 4 show version show users show voice-port fxs ping 192.168.1.1...
  • Page 29 User Mode ping Use the ping command to send a sequence of ICMP echo request packets to the specified host. If the host variable is omitted, and you are in User mode, the router prompts you for additional information. Note: The ping command verifies a connection, and is a very important troubleshooting tool. Syntax: >...
  • Page 30 User Mode show show alarms show ip ospf show arp show ip ospf database show caclkcd show ip ospf interface show config dynamic-dns show ip ospf neighbor show controller lcc show licenses show controller t1 show log show dhcp-leases show mac-address-table show digit-map show nat-fw show interface description...
  • Page 31: Show Alarms

    User Mode show alarms Use the show alarms command to display the active alarms. Syntax: > show alarms [t1 port|lcc number] {alert|all|critical|info|major|minor} Field Definition t1 port Display alarms for a specific port. Adit 3104: Value must be 1. Adit 3500: Range = 1-4. lcc number Display alarms for a specific Link Cross-Connect (LCC).
  • Page 32: Show Arp

    User Mode show arp Use the show arp command to display the ARP (Address Resolution Protocol) table. Syntax: > show arp {all|address|ethernet port} Field Definition Display entire ARP table. address Display ARP items of the entered IP address. ethernet port Display Ethernet ARP items only.
  • Page 33 User Mode show caclkcd Use the show caclkcd command to display the linux kernel crash dump Syntax: > show caclkcd Example: Adit 3500> show caclkcd ---------------- Begin cacLKCD ----------- 1 2003 00:00:44 <3> openrg: unhandled page fault at pc=0x400528c0, lr=0x400 digit-map Show digit-map settings 52890 (bad address=0x30303038, code 245)Show various interfaces...
  • Page 34 User Mode show config dynamic-dns Use the show config dynamic-dns command to display the dynamic DNS configuration. Syntax: > show config dynamic-dns Example: Adit 3500> show config dynamic-dns dynamic-dns username admin hostname Host1 dynamic-dns interface eth-2 no dynamic-dns offline enable no dynamic-dns wildcard enable no dynamic-dns backup-mx enable no dynamic-dns mail-exchanger...
  • Page 35: Supported Platforms

    User Mode show controller t1 Use the show controller t1 command to display the performance statistics of the DS1. Syntax: > show controller t1 port Field Definition port DS1 (T1) interface. Adit 3104 range = 1 Adit 3500 range 1-4 Example: Adit 3500>...
  • Page 36 User Mode show dhcp-leases Use the show dhcp-leases command to display the DHCP lease table. Syntax: > show dhcp-leases Example: Adit 3500> show dhcp-leases Ethernet 1 Hostname : new-host IP:192.168.1.10 MAC:00:00:ff:ff:00:00 Type:static Expires-In:0 Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: show digit-map Use the show digit-map command to display the Digit Map settings.
  • Page 37 User Mode show interface description Use the show interface description command to display interface information. Syntax: > show interface description Example: Adit 3500> show interface description Device State IP/Mask Dependencies T1 1 running None T1 2 running None T1 3 None T1 4 None...
  • Page 38: Show Interface Ethernet

    User Mode show interface ethernet Use the show interface ethernet command to display the Ethernet interface information. Syntax: > show interface ethernet port Field Definition port Ethernet port number. Range = 1-2. Example: Adit 3500> show interface ethernet 1 Device=Ethernet 1 State=running IP/Mask=192.168.1.1/255.255.255.0 Dependency=None...
  • Page 39 User Mode show interface serial Use the show interface serial command to display the configuration of the serial interface. Syntax: > show interface serial port Field Definition port Serial interface. Adit 3104: Value must be 1. Adit 3500: Range = 1-4. MSR: Range = 1-8.
  • Page 40 User Mode show interface stats Use the show interface stats command to display the interface statistics. Syntax: > show interface stats Example: Adit 3500> show interface stats Device=T1 1 State=up Dependency=None Status: Connecting (Alarm Condition) Device=T1 2 State=up Dependency=None Status: Connecting (Alarm Condition) Device=T1 3 State=running Dependency=None...
  • Page 41 User Mode Status: Unassigned Device=LinkCC 8 State=down Dependency=None Status: Unassigned Device=Ethernet 2 State=up IP/Mask=DHCP Unassigned Dependency=None Status: DHCP IP Address Released; Link: Down Tx (Packets/Bytes/Dropped/Errors)=(0/0/0/0) Rx (Packets/Bytes/Dropped/Errors)=(0/0/0/0) Broadcasts (Tx/Rx)=(0/0) Multicasts=0 Collisions=0 Device=Ethernet 1 State=running IP/Mask=10.0.0.3/255.255.255.0 Dependency=None Status: Connected; Link: 10T-HD Tx (Packets/Bytes/Dropped/Errors)=(1509/1577037/0/0) Rx (Packets/Bytes/Dropped/Errors)=(1540/119409/0/0) Broadcasts (Tx/Rx)=(0/0)
  • Page 42 User Mode show interface vpn_l2tpc Use the show interface vpn_l2tpc command to display configuration information and statistics for a VPN L2TPC interface. Syntax: > show interface vpn_l2tpc port Field Definition port Range = 0-99. Example: Adit 3500> show interface vpn_l2tpc 0 Device=L2TP#0 State=running IP/Mask=31.0.0.10/255.0.0.0...
  • Page 43: Show Ip Ospf

    User Mode show ip ospf Use the show ip ospf command to display the general OSPF routing process information. Syntax: > show ip ospf Example: adit 3500> show ip ospf Routing Process "ospf 0" with ID 192.168.1.1 Process uptime is 28 minutes Process bound to VRF default Conforms to RFC2328, and RFC1583Compatibility flag is disabled Supports only single TOS(TOS0) routes...
  • Page 44: Show Ip Ospf Database

    User Mode show ip ospf database Use the show ip ospf database command to display information related to the OSPF database for a specific router. The various forms of this command deliver information on defined OSPF link state advertisements. Syntax: >...
  • Page 45 User Mode Example: adit 3500> show ip ospf database Router Link States (Area 0.0.0.1) Link ID ADV Router Seq# CkSum Link count 192.168.3.1 192.168.3.1 313 0x800000c1 0x4978 1 192.168.3.255 192.168.3.255 568 0x8000003a 0xa6c0 1 Net Link States (Area 0.0.0.1) Link ID ADV Router Seq# CkSum...
  • Page 46: Show Ip Ospf Interface

    User Mode show ip ospf interface Use the show ip ospf interface command to display OSPF related interface information. Syntax: > show ip ospf interface {ethernet port|serial port|multilink port} Field Definition ethernet port Display information on the Ethernet interface. port = 1 or 2 serial port Display information on the serial interface.
  • Page 47: Show Ip Ospf Neighbor

    User Mode show ip ospf neighbor Use the show ip ospf neighbor command to display OSPF neighbor information. Syntax: > show ip ospf neighbor [interface address|neighbor-id|detail] Field Definition interface address Optional parameter. Enter interface IP address to define display. neighbor-id Optional parameter.
  • Page 48: Show Log

    User Mode show licenses Use the show licenses command to display all enabled feature keys. Syntax: > show licenses Example: Adit 3500> show licenses license = No license = Yes MGCP license = No G729A license = Yes Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: show log Use the show log command to display the current events on the system.
  • Page 49 User Mode Example: Adit 3500> show log t1 1 minor System Log Message Jan 1 00:00:08 2003 kern.err T1 ALARM: Alarm LOS T1#1 Major received System Log Message Jan 1 00:00:04 2003 kern.err T1 ALARM: Alarm LOS T1#1 Major received System Log Message Jan 1 01:19:13 2003 kern.err T1 ALARM: Alarm LOS T1#1 Major received...
  • Page 50 User Mode show nat-fw Use the show nat-fw command to display the current NAT and firewall connection table. Syntax: > show nat-fw Example: Adit 3500> show nat-fw Number Content TCP 11.0.0.4 36104<--> 172.15.16.1 36104[31.0.0.6 5516 ] TIME_WAIT/TIME_WAIT ttl 0 sec bytes 1320 pkts 7 ppp100 Outgoing BY FTP TCP 11.0.0.4 36103<-->...
  • Page 51: Show Route

    User Mode show port-trigger Use the show port-trigger command to display all port triggering information. Syntax: > show port-trigger Example: Adit 3500> show port-trigger Service ID:134217730 Enable Service Name:L2TP Trigger protocol: UDP port: src_start=0 src_end=0 dst_start=1701 dst_end=1701 Service ID:16777223 Enable Service Name:TFTP Trigger protocol: UDP port: src_start=1024 src_end=65535 dst_start=69 dst_end=69 Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 52 User Mode show service Use the show service command to displays all services. Syntax: > show service Example: Adit 3500> show service Group: Basic Web Utilities Service ID:16777216 Service Name:All Traffic Trigger protocol: NO PROTOCOL port: src_start=0 src_end=0 dst_start=0 dst_end=0 Service ID:16777217 Service Name:DNS Trigger protocol: TCP port: src_start=53...
  • Page 53: Show Users

    User Mode show users Use the show users command to displays all users on this system. Syntax: > show users Example: Adit 3500> show users Provisioned User List User-1 : admin Access: ADMIN <- User-2 : pauljones Access: ADMIN Active CLI Users User-1 : admin Access:ADMIN Authen:Config...
  • Page 54 User Mode Example: Adit MSR> show version Application Version: 2.1.0.4 Compilation Time: Wed Oct 8 2008 16:09:24 FPGA Version: 0.04 Boot Version: 1.19 Board Version: 0 003-1756-0001 Flash Size: 32M bytes Memory Size: 64M bytes IXP400 Software Release: 1_4 SQA4_1 MSP: 82610 - 100 channels Image File Name: TGW_v5_05.axf...
  • Page 55 User Mode show voice-port fxs Use the show voice-port fxs command to display the FXS interface information. Syntax: > show voice-port fxs Example: Adit 3500> show voice-port fxs Registration Address: 172.32.1.15 SIP Proxy: Yes Proxy Address: 172.32.1.18 * Line UID PhoneStatus RegisStatus RX/TX/Lost(Pkts) Jitter Overflow ---------------------------------------------------------------------------- 3035550001...
  • Page 56 User Mode show voice-port trunk Use the show voice-port trunk command to display the voice trunk statistics. Syntax: > show voice-port trunk port Field Definition port Adit 3500: DS1 (T1) interface. Value must be 1. MSR: Link Cross Connect (LCC). Range = 1-8. Example: Adit 3500>...
  • Page 57 User Mode Example: Adit MSR> show voice-port trunk 1 ******************************* PRI 1 *************************************** Channel no Internal Call Id Q931 Connection Id Tdm TimeSlot Call State ------------------------------------------------------------------------------- INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE...
  • Page 58: Traceroute

    User Mode traceroute Use the traceroute command to trace a route to a remote host. Syntax: > traceroute Syntax: > traceroute {address|hostname|stop} Field Definition address IP address of the remote host. hostname Host name of the remote host. stop Stop the traceroute process. Example: Adit 3500>...
  • Page 59: Privileged Mode

    HAPTER Privileged Mode The Privileged Mode allows the operator access to the configuration modes. This Mode is entered with the > enable command from the Basic mode. The Privileged Mode is represented by the # prompt. Privileged Mode Commands • clear •...
  • Page 60 Privileged Mode clear clear arp Use the clear arp command to clear the ARP (Address Resolution Protocol) table. Syntax: # clear arp {all|ethernet port|address} Field Definition Display entire ARP table. ethernet port Display Ethernet ARP items only. port - Define an Ethernet port number. Range 1 - 2. address Enter IP address for specific ARP information on this address.
  • Page 61 Privileged Mode configure terminal Use the configure terminal command to enter the configuration mode. Syntax: # configure terminal Example: adit 3500# configure terminal adit 3500 (config)# Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: copy copy defaults Use the copy defaults command to restore default setting. Syntax: # copy defaults running-config Example:...
  • Page 62: Date

    Privileged Mode Example: Adit MSR#copy path tftp://192.168.1.100/MSR_config running- config Adit MSR#Configuration restore: Success. WARNING: A reload is needed for changes to take effect. Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: copy running-config Use the copy running-config command to save the current configuration on the Adit. Note: The TFTP server must be running on the destination device.
  • Page 63: Debug

    Privileged Mode debug debug portmon all Use the debug portmon all command allows the user to monitor all traffic of a specific type. All traffic can be displayed, or a specific traffic type can be defined. Note: Immediately after this command is issued, any traffic that falls into the filter parameter will be displayed.
  • Page 64 Privileged Mode debug portmon {rx|tx|both} Use the debug portmon {rx|tx|both} command allows the user to monitor specific direction of traffic. Note: Immediately after this command is issued, any traffic that falls into the filter parameter will be displayed. To turn the monitoring off, you must issue a no debug portmon command. See no debug portmon command on page 3-16.
  • Page 65 Privileged Mode debug portmon ethernet Use the debug portmon ethernet command allows the user to monitor specific Ethernet traffic. Note: Immediately after this command is issued, any traffic that falls into the filter parameter will be displayed. To turn the monitoring off, you must issue a no debug portmon command. See no debug portmon command on page 3-16.
  • Page 66 Privileged Mode debug portmon management Use the debug portmon management command allows the user to configure management trace suppression. See no debug portmon command on page 3-16. Syntax: # debug portmon management {hush|off} Field Definition hush hush - Enable suppression of management traffic trace off - Disable suppression of management traffic trace Example: adit 3500# debug portmon management hush...
  • Page 67 Privileged Mode debug portmon multilink Use the debug portmon multilink command allows the user to monitor the multilink traffic. All traffic can be displayed, or a specific traffic type can be defined. Note: Immediately after this command is issued, any traffic that falls into the filter parameter will be displayed.
  • Page 68 Privileged Mode debug portmon raw Use the debug portmon raw command allows the user to display raw data related traffic. See no debug portmon command on page 3-16. Syntax: # debug portmon raw {off|on} Field Definition Disable display of packet hex data Enables display of packet hex data Example: adit 3500# debug portmon raw off...
  • Page 69 Privileged Mode debug portmon serial Use the debug portmon serial command allows the user to monitor traffic on a serial interface. Note: Immediately after this command is issued, any traffic that falls into the filter parameter will be displayed. To turn the monitoring off, you must issue a no debug portmon command. See no debug portmon command on page 3-16.
  • Page 70: End

    Privileged Mode debug trace Use the debug trace command allows the user to configure trace settings. Note: Immediately after this command is issued, any trace that falls into the filter parameter will be displayed. To turn the monitoring off, you must issue a no debug trace command. See no debug trace command on page 3-16.
  • Page 71: Help

    Privileged Mode help Use the help command to display the help information for this command. Note: This can also be accomplished with a ?. This command can be entered in any configuration mode. Syntax: # help Syntax: Example: adit 3500# help Display all commands clear Clear command...
  • Page 72: History

    Privileged Mode history Use the history command to display commands that have been entered in this session. This command can be entered in any configuration mode. Syntax: # history Example: adit 3500# history debug trace sip rx no debug trace no debug trace rx no debug trace sip no debug trace...
  • Page 73: Log Clear

    Privileged Mode log clear Use the log clear command to clear the history of the log. Syntax: # log clear {all|firewall|pri|sip|system|t1|lcc} Field Definition Clear the entire event log. firewall Clear firewall event log. Clear PRI event log. Note: Not supported on the Adit 3104. Clear SIP event log.
  • Page 74: No Debug

    Privileged Mode no debug no debug portmon Use the no debug portmon command to stop the Packet Monitor (portmon) process. To configure a debug command, see the debug command on page 3-5. Syntax: # no debug portmon Example: adit 3500# no debug portmon Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: no debug trace...
  • Page 75: Ping

    Privileged Mode ping Use the ping command to send a sequence of ICMP echo request packets to the specified host. If the host variable is omitted, and you are in Privileged mode, the router prompts you for additional information. Note: The ping command verifies a connection and is a very important troubleshooting tool.
  • Page 76: Reload

    Privileged Mode reload Use the reload command to reset the system. CAUTION! HIS IS A SERVICE AFFECTING COMMAND Syntax: # reload Example: adit 3500# reload Going to reboot! Restarting system. Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: 3-18 Adit 3000 (Rel.
  • Page 77: Show

    Privileged Mode show For maneuverability through these commands, all command names in blue or italics are hyperlinked. show alarms show interface description show arp show interface ethernet show caclkcd show interface multilink show config access-control show interface serial show config access-list show interface stats show config controller t1 show interface vpn_ipsec...
  • Page 78 Privileged Mode show alarms Use the show alarms command to display the active alarms. Syntax: # show alarms [t1 port|lcc number] {alert|all|critical|info|major|minor} Field Definition t1 port Display alarms for a specific port. Adit 3104: Value must be 1. Adit 3500: Range = 1-4. lcc number Display alarms for a specific Link Cross-Connect (LCC).
  • Page 79 Privileged Mode show arp Use the show arp command to display the ARP (Address Resolution Protocol) table. Syntax: # show arp {all|address|ethernet port} Field Definition Display entire ARP table. address Display ARP items of the entered IP address. ethernet port Display Ethernet ARP items only.
  • Page 80 Privileged Mode show caclkcd Use the show caclkcd command to display the linux kernel crash dump Syntax: # show caclkcd Example: adit 3500# show caclkcd ---------------- Begin cacLKCD ----------- 1 2003 00:00:44 <3> openrg: unhandled page fault at pc=0x400528c0, lr=0x400 digit-map Show digit-map settings 52890 (bad address=0x30303038, code 245)Show various interfaces...
  • Page 81 Privileged Mode show config access-control Use the show config access-control command to display all access control filters. Syntax: # show config access-control Example: adit 3500# show config access-control access-control id 1 apply-to lan time-range always service 1 enable Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: show config access-list Use the show config access-list command to display all access lists.
  • Page 82: Shutdown

    Privileged Mode show config controller t1 Use the show config controller t1 command to display the T1 information. Syntax: # show config controller t1 port Field Definition port T1 port to display. Adit 3104: Value must be 1. Adit 3500: Range 1 - 4. Example: adit 3500# show config controller t1 1 controller t1 1...
  • Page 83 Privileged Mode show config dmz-host Use the show config dmz-host command to display the DMZ information. Syntax: # show config dmz-host Example: adit 3500# show config dmz-host dmz-host 192.168.1.200 enable Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: show config host-filter Use the show config host-filter command to display the IP and host name filters.
  • Page 84 Privileged Mode show config interface ethernet Use the show config interface ethernet command to display the Ethernet port information. Syntax: # show config interface ethernet port Field Definition port Ethernet port to display. Range 1 - 2 Example: adit 3500# show config interface ethernet 1 Interface Ethernet 1 ip address 192.168.1.1 mask 255.255.255.0 description Ethernet 1...
  • Page 85 Privileged Mode show config interface multilink Use the show config interface multilink command to display the Multilink port information. Syntax: # show config interface multilink port Field Definition port Multilink port to display. Adit 3104, Adit 3200, Adit 3500: Value must be 1. MSR: Range = 1-8.
  • Page 86: Ppp Restart-Timer

    Privileged Mode show config interface serial Use the show config interface serial command to display serial interface information. Syntax: # show config interface serial port Field Definition port Serial interface to display. Adit 3104: Value must be 1. Adit 3500: Range = 1-4. MSR: Range = 1-8.
  • Page 87 Privileged Mode show config ip dhcp ethernet Use the show config ip dhcp ethernet command to display the DHCP Pool. Syntax: # show config ip dhcp ethernet port Field Definition port Ethernet port to display. Range 1 - 2 Example: adit 3500# show config ip dhcp ethernet 1 ip dhcp pool ethernet 1 no relay...
  • Page 88 Privileged Mode show config nat-bypass Use the show config nat-bypass command to display the NAT Bypass entries. Syntax: # show config nat-bypass Example: adit 3500# show config nat-bypass nat-bypass ip-address 192.168.1.120 mask 255.255.255.0 nat-bypass ip-address 192.168.1.120 mask 255.255.255.0 enable Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: show config network-object Use the show config network-object command to display the network object configuration.
  • Page 89 Privileged Mode show config remote-admin Use the show config remote-admin command to display the remote admin configuration. Syntax: # show config remote-admin Example: adit 3500# show config remote-admin remote-admin telnet primary-port port 23 remote-admin telnet secondary-port port 8023 remote-admin telnet primary-secure-port port 992 remote-admin web primary-port port 80 remote-admin web secondary-port port 8080 remote-admin web primary-secure-port port 443...
  • Page 90 Privileged Mode show config service Use the show config service command display the current defined services. Syntax: # show config service Example: adit 3500# show config service service id 4 name service1 description test protocol tcp server-src-port 1-1 server-dst-port 4-4 Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: show config static-dns...
  • Page 91 Privileged Mode show config voice-port fxs Use the show config voice-port fxs command to display the FXS port information. Syntax: # show config voice-port fxs [port] Field Definition port FXS port to display. Adit 3104: Range = 1 - 24. Adit 3500: Range = 1 - 4.
  • Page 92 Privileged Mode show config voice-port trunk Use the show config voice-port trunk command display the Trunk port information. Syntax: # show config voice-port trunk port Field Definition port Trunk port to display. Value must be 1. Example: adit 3500# show config voice-port trunk 1 Voice-port Trunk 1 description Trunk 1...
  • Page 93 Privileged Mode show controller lcc Use the show controller lcc command to display the settings for a Link Cross Connect on the MSR card. Syntax: # show controller lcc number Field Definition number Link Cross Connect number, 1-8. Example: Adit MSR> show controller lcc 1 Settings for interface LCC 1 --------------------------- Name...
  • Page 94 Privileged Mode show controller t1 Use the show controller t1 command displays the T1 configuration and performance information. Syntax: # show controller t1 port Field Definition port DS1 (T1) interface. Adit 3104 Range = 1 Adit 3500 Range 1 - 4 Example: adit 3500# show controller t1 1 Settings for interface T1 1...
  • Page 95 Privileged Mode show dhcp-leases Use the show dhcp-leases command to display the DHCP lease table. Syntax: # show dhcp-leases Example: Adit 3500# show dhcp-leases Ethernet 1 Hostname : new-host IP:192.168.1.10 MAC:00:00:ff:ff:00:00 Type:static Expires-In:0 Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: show digit-map Use the show digit-map command to display the Digit Map patterns.
  • Page 96 Privileged Mode show interface description Use the show interface description command to display the interface information. Syntax: # show interface description Example: adit 3500# show interface description Device State IP/Mask Dependencies T1 1 running None T1 2 running None T1 3 None T1 4 None...
  • Page 97 Privileged Mode show interface ethernet Use the show interface ethernet command to display the Ethernet interface information. Syntax: # show interface ethernet port Field Definition port Port number range 1-2. Example: adit 3500# show interface ethernet 1 Device=Ethernet 1 State=running IP/Mask=192.168.1.1/255.255.255.0 Dependency=None Status: Connected;...
  • Page 98 Privileged Mode show interface serial Use the show interface serial command to display the configuration of the serial interface. Syntax: # show interface serial port Field Definition port Serial interface. Adit 3104: Value must be 1. Adit 3500: Range = 1-4. MSR: Range = 1-8.
  • Page 99 Privileged Mode show interface stats Use the show interface stats command to display the interface statistics. Syntax: # show interface stats Example: Adit 3500# show interface stats Device=T1 1 State=up Dependency=None Status: Connecting (Alarm Condition) Device=T1 2 State=up Dependency=None Status: Connecting (Alarm Condition) Device=T1 3 State=running Dependency=None...
  • Page 100 Privileged Mode Status: Unassigned Device=LinkCC 8 State=down Dependency=None Status: Unassigned Device=Ethernet 2 State=up IP/Mask=DHCP Unassigned Dependency=None Status: DHCP IP Address Released; Link: Down Tx (Packets/Bytes/Dropped/Errors)=(0/0/0/0) Rx (Packets/Bytes/Dropped/Errors)=(0/0/0/0) Broadcasts (Tx/Rx)=(0/0) Multicasts=0 Collisions=0 Device=Ethernet 1 State=running IP/Mask=10.0.0.3/255.255.255.0 Dependency=None Status: Connected; Link: 10T-HD Tx (Packets/Bytes/Dropped/Errors)=(1509/1577037/0/0) Rx (Packets/Bytes/Dropped/Errors)=(1540/119409/0/0) Broadcasts (Tx/Rx)=(0/0)
  • Page 101 Privileged Mode show interface vpn_l2tpc Use the show interface vpn_l2tpc command to display configuration information and statistics for a VPN L2TPC interface. Syntax: # show interface vpn_l2tpc port Field Definition port Range = 0-99. Example: Adit 3500# show interface vpn_l2tpc 0 Device=L2TP#0 State=running IP/Mask=31.0.0.10/255.0.0.0...
  • Page 102 Privileged Mode show ip ospf Use the show ip ospf command to display the general OSPF routing process information. Syntax: # show ip ospf Example: adit 3500# show ip ospf Routing Process "ospf 0" with ID 192.168.1.1 Process uptime is 28 minutes Process bound to VRF default Conforms to RFC2328, and RFC1583Compatibility flag is disabled Supports only single TOS(TOS0) routes...
  • Page 103 Privileged Mode show ip ospf database Use the show ip ospf database command to display information related to the OSPF database for a specific router. The various forms of this command deliver information on defined OSPF link state advertisements. Syntax: # show ip ospf database {setting} Syntax: # show ip ospf database {adv-router address|self-originate}...
  • Page 104 Privileged Mode Example: adit 3500# show ip ospf database Router Link States (Area 0.0.0.1) Link ID ADV Router Seq# CkSum Link count 192.168.3.1 192.168.3.1 313 0x800000c1 0x4978 1 192.168.3.255 192.168.3.255 568 0x8000003a 0xa6c0 1 Net Link States (Area 0.0.0.1) Link ID ADV Router Seq# CkSum...
  • Page 105 Privileged Mode show ip ospf interface Use the show ip ospf interface command to display OSPF related interface information. Syntax: # show ip ospf interface {ethernet port|serial port|multilink port} Field Definition ethernet port Display information on the Ethernet interface. port = 1 or 2 serial port Display information on the serial interface.
  • Page 106 Privileged Mode show ip ospf neighbor Use the show ip ospf neighbor command to display OSPF neighbor information. Syntax: # show ip ospf neighbor [interface address|neighbor-id|detail] Field Definition interface address Optional parameter. Enter interface IP address to define display. neighbor-id Optional parameter.
  • Page 107: Show Ipsec

    Privileged Mode show ipsec Use the show ipsec command to display the IPSec Connections or the connection configuration information. Syntax: # show ipsec [vpn_ipsecconnection-id] Field Definition connection-id Enter the name of a connection. Example: adit 3500# show ipsec vpn_ipsec 0 vpn_ipsec 1 vpn_ipsec 2 vpn_ipsec 3...
  • Page 108 Privileged Mode show l2tpc Use the show l2tpc command to display the Layer 2 Tunneling Protocol Connections or the connection configuration information. Syntax: # show l2tpc [l2tpc connection-id] Field Definition connection-id Enter the name of a connection. Example: adit 3500# show l2tpc l2tp#0 l2tp#1 l2tp#2...
  • Page 109 Privileged Mode show licenses Use the show licenses command to display all enabled feature keys. Syntax: # show licenses Example: adit 3500# show licenses license = No license = Yes MGCP license = No G729A license = Yes Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: Adit 3000 (Rel.
  • Page 110 Privileged Mode show log Use the show log command to display the current events on the system. Syntax: # show log {firewall|pri|sip|system|t1 port|lcc number} [severity] Field Definition firewall Filter firewall alarms Display PRI logs. Note: This is not supported on the Adit 3104. Display SIP logs.
  • Page 111 Privileged Mode show mac-address-table Use the show mac-address-table command to display the current MAC addresses (LAN\WAN). Syntax: # show mac-address-table Example: adit 3500# show mac-address-table Ethernet 1 mac= 00:00:00:ff:ff:ff Ethernet 2 mac= 00:00:00:ff:ff:fd Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: show nat-fw Use the show nat-fw command to display the current NAT and firewall connection table.
  • Page 112 Privileged Mode show port-trigger Use the show port-trigger command to display the port trigger information. Syntax: # show port-trigger Example: adit 3500# show port-trigger Service ID:134217730 Enable Service Name:L2TP Trigger protocol: UDP port: src_start=0 src_end=0 dst_start=1701 dst_end=1701 Service ID:16777223 Enable Service Name:TFTP Trigger protocol: UDP port: src_start=1024...
  • Page 113 Privileged Mode show pptpc Use the show pptps command to display the PPTP connections or the PPTP connection details. Syntax: # show pptpc [pptpc connection-id] Field Definition connection-id Enter the name of a connection. Example: adit 3500# show pptpc PPTP#0 PPTP#1 Example: adit 3500# show pptpc pptpc 1...
  • Page 114: Authentication

    Privileged Mode show pptps Use the show pptps command to display the PPTP Server settings. Syntax: # show pptps Example: adit 3500# show pptps state = Enable status = Invalid vpn license Idle_Time = 1200 Authentication = MS-CHAP MS-CHAPv2 Encryption = MPPE-40 MPPE-128 (Stateless) Remote IP Address Range = 192.168.1.245 - 192.168.1.254...
  • Page 115 Privileged Mode show running-config Use the show running-config command to display the current configuration of the system. Syntax: # show running-config Example: adit 3500# show running-config ip host adit3500 log system notify none log security notify none log t1 notify none clock source 1 t1 1 clock source 2 none controller t1 1...
  • Page 116: Comfort-Noise

    Privileged Mode no radius-server voice-port trunk 1 description Trunk 1 no comfort-noise connection t1 2 no echo-cancel input-gain 0 output-gain 0 isdn switch-type primary-ni2 voice-port fxs 1 description Line 1 no comfort-noise echo-cancel enable input-gain 0 output-gain 0 dial-timeout 5 signal loop-start voice-codec g711ulaw ptime 20 voice-codec g711alaw ptime 20...
  • Page 117: Shutdown

    Privileged Mode session-timer refresher uac no session-timer mode redundancy type none redundancy ttl 3600 redundancy rollback-timer 300 redundancy advanced-timeout 2 redundancy advanced-retries 3 no filter-incoming Example: adit MSR# show running-config ! Start of commands to eliminate default configuration no voice-port trunk 1 interface serial 1 shutdown exit...
  • Page 118: Echo-Cancel

    Privileged Mode no schedule-availability ip ospf authentication null exit interface ethernet 2 ip address auto description Ethernet 2 ip mtu auto ip dhcp auto-provision no ip primary-dns no ip secondary-dns ip route-mode napt ip default-route enable no ip proxy-arp no ip rip ip rip receive-version 1or2 ip rip send-version 2-bcast sip-alg enable...
  • Page 119: Input-Gain

    Privileged Mode exit voice-port fxs no digit-map dial-timeout 5 exit voice-port fxs 1 description Line 1 no comfort-noise echo-cancel enable input-gain 0 output-gain 0 signal loop-start no per-line-logging no shutdown exit voice-port fxs 48 description Line 48 no comfort-noise echo-cancel enable input-gain 0 output-gain 0 signal loop-start...
  • Page 120 Privileged Mode registration rate 60 registration expire 3600 registration retry-timeout 500 registration tries 2 registration failed-time 60 registration window-size 10 no registration ignore-negotiated enable redundancy type none fax-protocol-t38 signaling sdp-preferred fax-protocol-t38 ecs redundant fax-protocol-t38 ls-redundancy 3 fax-protocol-t38 hs-redundancy 0 exit port-trigger service 134217730 enable port-trigger service 16777223 enable remote-admin telnet primary-port port 23...
  • Page 121 Privileged Mode no ipsec log ike ike-msg no ipsec log ike msg-byte no ipsec log ike msg-enc-dec no ipsec log ike msg-inp no ipsec log ike msg-outp no ipsec log ike pri-key no ipsec log ike rej-packet no ipsec log ipsec atc no ipsec log ipsec emvc no ipsec log ipsec etc no ipsec log ipsec ip-ctc...
  • Page 122 Privileged Mode show service Use the show service command to display all service information. Note: The following example, is only a portion of the list. Syntax: # show service Example: adit 3500# show service Group: Basic Web Utilities Service ID:16777216 Service Name:All Traffic Trigger protocol: NO PROTOCOL port: src_start=0 src_end=0...
  • Page 123 Privileged Mode show users Use the show users command to display all users on this system. Syntax: # show users Example: adit 3500# show users Provisioned User List User-1 : admin Access: ADMIN <- User-2 : pauljones Access: ADMIN Active CLI Users User-1 : admin Access:ADMIN Authen:Config...
  • Page 124 Privileged Mode Example: Adit MSR# show version Application Version: 2.1.0.4 Compilation Time: Wed Oct 8 2008 16:09:24 FPGA Version: 0.04 Boot Version: 1.19 Board Version: 0 003-1756-0001 Flash Size: 32M bytes Memory Size: 64M bytes IXP400 Software Release: 1_4 SQA4_1 MSP: 82610 - 100 channels Image File Name: TGW_v5_05.axf...
  • Page 125 Privileged Mode show voice-port fxs Use the show voice-port fxs command to display the FXS voice port information. Syntax: # show voice-port fxs Example: adit 3500# show voice-port fxs Registration Address: 172.32.1.15 SIP Proxy: Yes Proxy Address: 172.32.1.18 * Line UID PhoneStatus RegisStatus RX/TX/Lost(Pkts) Jitter Overflow ---------------------------------------------------------------------------- 3035550001...
  • Page 126 Privileged Mode show voice-port trunk Use the show voice-port trunk command to display the trunk voice port information. Syntax: # show voice-port trunk port Field Definition port Adit 3500: DS1 (T1) interface. Value must be 1. MSR: Link Cross Connect (LCC). Range = 1-8. Example: adit 3500# show voice-port trunk 1 trunk-1 t1-1 does not exist...
  • Page 127 Privileged Mode Example: adit MSR# show voice-port trunk 1 ******************************* PRI 1 *************************************** Channel no Internal Call Id Q931 Connection Id Tdm TimeSlot Call State ------------------------------------------------------------------------------- INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE INACTIVE...
  • Page 128: Traceroute

    Privileged Mode traceroute Use the traceroute command to trace a route to a remote host. Syntax: # traceroute Syntax: # traceroute {address|hostname|stop} Field Definition address IP address of the remote host. hostname Host name of the remote host. stop Stop the traceroute process. Example: Adit 3500# traceroute to 192.168.1.200 (192.168.1.200), 10 hops max...
  • Page 129: Exit

    HAPTER Global Configuration Mode The Global Configuration Mode allows commands to be entered directly to the router configuration. From this level, additional configuration modes can be entered. Once configuration is complete, use the exit/end command to return to the Privileged Mode prompt. This Mode is entered with the # configure terminal command from the Privileged mode.
  • Page 130: Configuration - Pptps Mode

    Global Configuration Mode Commands for Entering Configuration Submodes Configuration Mode Link to Command Prompt Displayed Controller LCC controller lcc (config-cont-lcc-{n})# Controller T1 controller t1 (config-cont-t1-{n})# DHCP server pool ip dhcp pool ethernet (config-dhcp-eth-{n})# Dial Peer FXS dial-peer voice pots fxs (config-dpeer-fxs)# Dial Peer Trunk dial-peer voice pots trunk...
  • Page 131: End

    Global Configuration Mode Global Configuration Commands Global Configuration Commands • access • l2tpc • access-control • local-server • access-list • log • authentication login • mail-server • clock source • nat-bypass • controller lcc • network-object • controller t1 • no commands •...
  • Page 132: Access

    Global Configuration Mode Global Configuration Commands access Use the access command to enable remote access via LAN or WAN. To disable remote access, see no access command on page 4-37. Syntax: (config)# access {lan|wan} enable Field Definition Enable remote access via the LAN. Enable remote access via the WAN.
  • Page 133: Access-List

    Global Configuration Mode Global Configuration Commands access-list Use the access-list command to configure the advanced filtering entries. To delete an access list, see no access-list command on page 4-38. Syntax: (config)# access-list rule {new|rule-name} apply {eth-lan| eth-wan|final|initial|ppp-wan} direction {in|out} operation {accept|accept-packet|drop|reject} time-range {always| schedule-name} src-host {address|address-range|any} dst-host {address|address-range|any} service service-id frag...
  • Page 134: Authentication Login

    Global Configuration Mode Global Configuration Commands Field Definition (Continued) frag enable - Enable fragmentation. none - Do not allow fragmentation. Enable or disables logging of packets matched by this rule. Example: (config)# access-list rule new apply eth-lan direction in operation accept time-range always src-host any dst-host any service 16777220 frag none log none Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms:...
  • Page 135: Controller Lcc

    Global Configuration Mode Global Configuration Commands controller lcc Use the controller lcc command to allow access to the Controller LCC configuration commands. See Chapter 5, Configuration - LCC Controller Mode for commands in this mode. Syntax: (config)# controller lcc number Field Definition number...
  • Page 136: Date

    Global Configuration Mode Global Configuration Commands date date auto-time-update Use the date auto-time-update command to automatically update the clock from the defined server. To stop the auto update, see no date auto-time-update command on page 4-38. Syntax: (config)# date auto-time-update protocol {ntp|tod} server address1 [address2] [address3] [address4] update-every hours Field Definition...
  • Page 137: Global Configuration Mode

    Global Configuration Mode Global Configuration Commands date summer-time Use the date summer-time command to update the clock for daylight savings time. To stop the update for daylight saving, see no date summer-time command on page 4-39. Note: Default settings are start: 3/28 time 00:00, end: 10/28 time 01:00. Syntax: (config)# date summer-time smonth sday shh:mm emonth eday ehh:mm offset...
  • Page 138: Delete Local-Server

    Global Configuration Mode Global Configuration Commands date timezone Use the date timezone command to set the time zone and the number of hours from the GMT. Syntax: (config)# date timezone hh:mm Field Definition Hour offset from GMT. Range is from -12 to +12, with a default of 0. Minute offset from GMT in minutes.
  • Page 139: Dial-Peer Voice

    Global Configuration Mode Global Configuration Commands dial-peer voice dial-peer voice pots fxs Use the dial-peer voice pots fxs command to allow access to the Dial Peer Voice FXS configuration commands. See Chapter 8, Configuration - Dial Peer FXS Mode for commands in this mode.
  • Page 140: Dmz-Host

    Global Configuration Mode Global Configuration Commands dial-peer voice voip Use the dial-peer voice voip command to allow access to the Dial Peer Voice VoIP configuration commands. See Chapter 10, Configuration - Dial Peer VoIP Mode for commands in this mode. For the no counterpart of this command see no dial-peer voice voip command on page 4-40.
  • Page 141: User Mode Commands

    Global Configuration Mode Global Configuration Commands Use the do commands to run User and Privileged mode commands. The following are links to the User and Privileged do commands. User Mode Commands date command, on page 2-2 enable command, on page 2-2 end command, on page 2-2 exit command, on page 2-3 help command, on page 2-3...
  • Page 142: Dynamic-Dns

    Global Configuration Mode Global Configuration Commands dynamic-dns Use the dynamic-dns commands to configure the DNS Dynamic entries. To disable Dynamic DNS, see no dynamic-dns command on page 4-40. dynamic-dns backup-mx Use the dynamic-dns backup-mx command to enable the Dynamic DNS backup MX. Syntax: (config)# dynamic-dns backup-mx enable Example:...
  • Page 143 Global Configuration Mode Global Configuration Commands dynamic-dns mail-exchanger Use the dynamic-dns mail-exchanger command to define the Dynamic DNS mail exchanger. Syntax: (config)# dynamic-dns mail-exchanger mail-exchanger Field Definition mail-exchanger Enter your mail exchange server address, to redirect all E-mails arriving at your Dyndns address to your mail server. Example: (config)# dynamic-dns mail-exchanger 10.10.1.0 Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 144: End

    Global Configuration Mode Global Configuration Commands dynamic-dns wildcard Use the dynamic-dns wildcard command to enable the Dynamic DNS wildcard. Syntax: (config)# dynamic-dns wildcard enable Example: (config)# dynamic-dns wildcard enable Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: Use the end command to exit the current configuration mode. Note: This command can be entered in any configuration mode with the same result.
  • Page 145: Host

    Global Configuration Mode Global Configuration Commands help Use the help command to display the help information for this command. Note: This can also be accomplished with a ?. This command can be entered in any configuration mode. Syntax: (config)# help or (config)# ? Example: (config)# help...
  • Page 146: History

    Global Configuration Mode Global Configuration Commands history Use the history command to display commands that have been entered in this session. This command can be entered in any configuration mode. Syntax: (config)# history Example: (config)# history clock source 1 none date date set 12:12:06 15 12 2006 date set 3:4:3...
  • Page 147: Host-Filter

    Global Configuration Mode Global Configuration Commands host-filter Use the host-filter command to configure the IP/host name filtering entries. To delete a host filter, see no host-filter command on page 4-41. Syntax: (config)# host-filter id filter-id {ip-address address|hostname hostname} apply-to {lan|network-object object-id} time-range {always|schedule-id} Field Definition...
  • Page 148: Interface Multilink

    Global Configuration Mode Global Configuration Commands interface multilink Use the interface multilink command to allow access to the MLPPP configuration commands. See Chapter 12, Configuration - Multilink Interface Mode for commands in this mode. To delete a Multilink interface, see no interface multilink command on page 4-41. Syntax: (config)# interface multilink group-number Field...
  • Page 149: Ipsec

    Global Configuration Mode Global Configuration Commands ipsec Use the ipsec commands to create an IPSec connection and to configure IPSec global settings. See Chapter 14, Configuration - IPSec Mode for additional commands in this mode. ipsec authentication-retries Use the ipsec authentication-retries command to enable the block-ip feature. To disable block-ip, see no ipsec authentication-retries command on page 4-42.
  • Page 150 Global Configuration Mode Global Configuration Commands ipsec log ike Use the ipsec log ike command to enable Internet Key Exchange (IKE) related logs. To disable IKE logging, see no ipsec log ike command on page 4-43 Syntax: (config)# ipsec log ike {auto-key|ike-int|ike-msg|msg-byte| msg-enc-dec|msg_inp|msg-outp|pri-key|rej-packet} Field Definition...
  • Page 151 Global Configuration Mode Global Configuration Commands ipsec log ipsec Use the ipsec log ipsec command to enable IPSec related logs. To disable IPSec logging, see no ipsec log ipsec command on page 4-44. Syntax: (config)# ipsec log ipsec {atc|emvc|etc|ip-ctc|irtmc|mirl |rc|rtmc|satmc|tc|tsmc|ttc|usc|vrp} Field Definition Authentication Transforms Code.
  • Page 152 Global Configuration Mode Global Configuration Commands ipsec net-to-net Use the ipsec net-to-net command to create a network-to-network connection. Syntax: (config)# ipsec net-to-net remote-ip {address|any} remote-subnet {ip address mask mask|any} pre-share secret Field Definition remote-ip address - Enter the remote tunnel endpoint address. any - Allow any IP address.
  • Page 153 Global Configuration Mode Global Configuration Commands ipsec vpn_ipsec Use the ipsec vpn_ipsec command to allow access to configuration commands for a specific IPSec connection. See Chapter 14, Configuration - IPSec Mode for commands in this mode. To delete this interface, see no ipsec vpn_ipsec command on page 4-45. Note: This connection must be created first.
  • Page 154: Ip Dhcp Pool Ethernet

    Global Configuration Mode Global Configuration Commands ip dhcp pool ethernet Use the ip dhcp pool ethernet command to allow access to the DHCP configuration commands. See Chapter 7, Configuration - DHCP Pool Ethernet Mode for commands in this mode. For the no counterpart, see no ip dhcp pool ethernet command on page 4-42.
  • Page 155: L2Tpc

    Global Configuration Mode Global Configuration Commands Use the key command to enable a specific keyed feature. To acquire a feature key code, contact Force10 Networks Customer Support. To disable a keyed feature, see the no key command on page 4-45. Syntax: (config)# key key-code Field...
  • Page 156: Local-Server

    Global Configuration Mode Global Configuration Commands local-server Use the local-server command to configure the local server entries. To delete a local server, see the no local-server command on page 4-46. Syntax: (config)# local-server id {name|new} {ip-address address |hostname hostname} time-range {always|schedule-name} fwd-port port service service-id Field Definition...
  • Page 157 Global Configuration Mode Global Configuration Commands log lcc buffer Use the log lcc buffer command to set the buffer size allowed for the Link Cross-Connect (LCC) log buffer. Syntax: (config)# log lcc buffer kilobytes Field Definition kilobytes Set the size of the LCC log buffer. Range is 1 - 256 KB. Default is 16KB.
  • Page 158 Global Configuration Mode Global Configuration Commands log pri Use the log pri command to configure PRI logging. Syntax: (config)# log pri {buffer-fill {0|1}|buffer-size kilobytes |display number|enable} Field Definition buffer-fill {0|1} Define the method of loading the buffer. 0 = Circular Buffer - the buffer will store a continuous stream of data by starting again at the beginning of the buffer after reaching the end.
  • Page 159 Global Configuration Mode Global Configuration Commands log security notify Use the log security notify command to set the remote security notify level. Syntax: (config)# log security notify {error|info|ip-address address |none|warn} Field Definition error Notify for error level. info Notify for information level. ip-address address Enter IP address of remote system to notify.
  • Page 160 Global Configuration Mode Global Configuration Commands log system buffer Use the log system buffer command to set the buffer size allowed for the system log buffer. Syntax: (config)# log system buffer kilobytes Field Definition kilobytes Set the size of the system log buffer. Range is 1 - 256 KB. Default is 16KB.
  • Page 161 Global Configuration Mode Global Configuration Commands log t1 buffer Use the log t1 buffer command to set the buffer size allowed for the T1 log buffer. Syntax: (config)# log t1 buffer kilobytes Field Definition kilobytes Set the size of the T1 log buffer. Range is 1 - 256 KB. Default is 16KB.
  • Page 162: Mail-Server

    Global Configuration Mode Global Configuration Commands mail-server mail-server authentication enable Use the mail-server authentication enable command to enable the outgoing mail server authentication. To disable the mail-server authentication, see no mail-server authentication command on page 4-46. Syntax: (config)# mail-server authentication enable Example: (config)# mail-server authentication enable Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 163 Global Configuration Mode Global Configuration Commands mail-server port Use the mail-server port command to set the outgoing mail server port. Syntax: (config)# mail-server port port Field Definition port Enter the port number. Range is 0 - 65535. Default is 25. Example: (config)# mail-server port 25 Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 164: Nat-Bypass

    Global Configuration Mode Global Configuration Commands nat-bypass Use the nat-bypass command to create and enable a NAT bypass rule. To disable NAT Bypass, see no nat-bypass command on page 4-46. Syntax: (config)# nat-bypass ip-address address mask mask [enable] Field Definition address Enter a NAT bypass IP address.
  • Page 165: No Commands

    Global Configuration Mode Global Configuration Commands no commands no access Use the access command to disable remote access via LAN or WAN. To enable remote access, see access command on page 4-4. Syntax: (config)# no access {lan|wan} Field Definition Disable access to the unit via the LAN. Disable access to the unit via the WAN.
  • Page 166 Global Configuration Mode Global Configuration Commands no access-list Use the no access-list command to remove an advanced filtering entry. To add a filter, see access- list command on page 4-5. Syntax: (config)# no access-list rule rule-name apply {eth-lan|eth-wan |ppp-wan|initial|final} Field Definition rule-name Enter an existing rule name to apply this command to.
  • Page 167 Global Configuration Mode Global Configuration Commands no date summer-time Use the no date summer-time command to remove daylight savings time setting. To enable daylight savings, see date summer-time command on page 4-9. Syntax: (config)# no date summer-time Example: (config)# no date summer-time Adit 3104, Adit 3200, Adit 3500 Supported Platforms: Not supported by the MSR...
  • Page 168 Global Configuration Mode Global Configuration Commands no dial-peer voice voip Use the no dial-peer voice voip command denies access to the Dial Peer Voice VoIP configuration commands. To allow access, see dial-peer voice command on page 4-11. Syntax: (config)# no dial-peer voice voip tag Field Definition Enter the tag number to denies access.
  • Page 169 Global Configuration Mode Global Configuration Commands no host-filter Use the no host-filter command to remove a IP host name filter entry. To add a IP host name, see host-filter command on page 4-19. Syntax: (config)# no host-filter name Field Definition name Name of an existing IP host name to remove.
  • Page 170 Global Configuration Mode Global Configuration Commands no ip dhcp pool ethernet Use the DHCP Pool no ip dhcp pool ethernet command to disable the DHCP server for the interface defined. To enter the DHCP configuration mode, see ip dhcp pool ethernet command on page 4-26.
  • Page 171 Global Configuration Mode Global Configuration Commands no ipsec log ike Use the no ipsec log ike command to disable Internet Key Exchange (IKE) related logs. To enable IKE logging, see ipsec log ike command on page 4-22 Syntax: (config)# no ipsec log ike {auto-key|ike-int|ike-msg|msg-byte| msg-enc-dec|msg_inp|msg-outp|pri-key|rej-packet} Field Definition...
  • Page 172 Global Configuration Mode Global Configuration Commands no ipsec log ipsec Use the no ipsec log ipsec command to disable IPSec related logs. To enable IPSec logging, see ipsec log ipsec command on page 4-23 Syntax: (config)# no ipsec log ipsec {atc|emvc|etc|ip-ctc|irtmc|mirl |rc|rtmc|satmc|tc|tsmc|ttc|usc|vrp} Field Definition...
  • Page 173 Global Configuration Mode Global Configuration Commands no ipsec vpn_ipsec Use the no ipsec vpn_ipsec command to delete an IPSec connection. To create an IPSec connection, see ipsec net-to-host command on page 4-23 or ipsec net-to-net command on page 4-24 To enter an IPSec connection, for configuration see ipsec vpn_ipsec command on page 4-25. Syntax: (config)# no ipsec ipsec connection-id Field...
  • Page 174 Global Configuration Mode Global Configuration Commands no local-server Use the no local-server command to disable a local server. To enable a local server, see local- server command on page 4-28. Syntax: (config)# no local-server name Field Definition name Enter a name of the server to remove. Example: (config)# no local-server BoulderServer Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 175 Global Configuration Mode Global Configuration Commands no network-object Use the no network-object command to remove network objects. To enable a network object, see network-object command on page 4-36. Syntax: (config)# no network-object id object-id type {hostname hostname|ip-address address|mac-address mac-address} Field Definition object-id Enter the numerical ID of the Network Object.
  • Page 176 Global Configuration Mode Global Configuration Commands no pptps Use the no pptps command to disable the VPN PPTP server. To enter the VPN PPTPS configuration mode, see the pptps command on page 4-55. Syntax: (config)# no pptps Example: (config)# no pptps Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: no radius-client...
  • Page 177 Global Configuration Mode Global Configuration Commands no remote-admin telnet Use the no remote-admin telnet command to remove remote administration via Telnet. To enable remote access via telnet, see remote-admin telnet command on page 4-57. Syntax: (config)# no remote-admin telnet {primary-port| primary-secure-port|secondary-port Field Definition...
  • Page 178 Global Configuration Mode Global Configuration Commands no remote-admin web Use the no remote-admin web command to remove remote administration via Web-management. To enable remote access via the web, see remote-admin web command on page 4-58. Syntax: (config)# no remote-admin web {primary-port| primary-secure-port|secondary-port|secondary-secure-port} Field Definition...
  • Page 179 Global Configuration Mode Global Configuration Commands no security-log Use the no security-log command to remove a security policy. To add a security policy, see security-log command on page 4-60. Syntax: (config)# no security-log setting Field Definition setting Accepted Events accepted-in-connects Disable incoming connections logging.
  • Page 180 Global Configuration Mode Global Configuration Commands no service Use the no service command to disable named services. To enable services, see service command on page 4-61. Syntax: (config)# no service service-id Field Definition service-id Enter the service number to apply the rule to. Note: The Service ID number is displayed with the show service command, on page 3-64 Example: (config)# no service-id 16777220...
  • Page 181 Global Configuration Mode Global Configuration Commands no static-dns Use the no static-dns command to remove DNS Static entries. To add a DNS static entry, see static- dns command on page 4-64. Syntax: (config)# no static-dns hostname hostname ip-address address Field Definition hostname Enter a DNS static host name of the server.
  • Page 182 Global Configuration Mode Global Configuration Commands no vlan Use the no vlan command to clear all VLANs. To enter the VLAN configuration mode, see vlan (global) command on page 4-65. Syntax: (config)# no vlan Example: (config)# no vlan Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: no voice-codec Use the no voice-codec command to remove a voice codec.
  • Page 183: Port-Trigger Service

    Global Configuration Mode Global Configuration Commands port-trigger service Use the port-trigger service command to configure the port-triggering entries. To delete a port trigger service, see no port-trigger-service command on page 4-47. Syntax: (config)# port-trigger service name enable Field Definition name Enter service name.
  • Page 184: Radius-Client

    Global Configuration Mode Global Configuration Commands radius-client Use the radius-client command to allow access to the RADIUS configuration commands. See Chapter 19, Configuration - RADIUS Mode for commands in this mode. For the no counterpart of this command, see no radius-client command on page 4-48. Syntax: (config)# radius-client Example:...
  • Page 185 Global Configuration Mode Global Configuration Commands remote-admin telnet Use the remote-admin telnet command to allow remote administration via Telnet. To deny telnet remote access, see no remote-admin telnet command on page 4-49. CAUTION! LLOWING REMOTE ADMINISTRATION IS A SECURITY RISK Syntax: (config)# remote-admin telnet {primary-port| primary-secure-port|secondary-port} {port port|enable}...
  • Page 186 Global Configuration Mode Global Configuration Commands remote-admin web Use the remote-admin web command to allow remote administration via Web-management. To deny Web remote access, see no remote-admin web command on page 4-50. CAUTION! LLOWING REMOTE ADMINISTRATION IS A SECURITY RISK Syntax: (config)# remote-admin web {primary-port| secondary-port|primary-secure-port|secondary-secure-port}...
  • Page 187 Global Configuration Mode Global Configuration Commands security-default Use the security-default command to configure the security policy. Syntax: (config)# security-default {maximum|minimum|typical} [block-ip-frag] Field Definition The following security levels are described in detail. Requests Originating in the Requests Originating in the LAN maximum Blocked: No access to network Limited: Only commonly-used...
  • Page 188 Global Configuration Mode Global Configuration Commands security-log Use the security-log command to configure the security policy. To delete a security policy, see no security-log command on page 4-51. Syntax: (config)# security-log setting enable Field Definition Accepted Events accepted-in-connections Sessions originated from the Internet that have been allowed by the firewall.
  • Page 189 Global Configuration Mode Global Configuration Commands service Use the service command to create/modify User-Defined Services. To delete a service policy, see no service command on page 4-52. Syntax: (config)# service id {service-id|new} name service-name description text protocol {protocol-number|ah|esp|gre|icmp|tcp |udp} [server-src-port|open-src-port] Field Definition service-id...
  • Page 190 Global Configuration Mode Global Configuration Commands server-src-port Defines the server source/destination port. Syntax: server-src-port {port|port-port|any} server-dst-port {port|port- port|any} server-src-port port - Enter the server source port to apply the service to. port-port - Enter a range of ports to apply the service to. any - Apply to any port.
  • Page 191 Global Configuration Mode Global Configuration Commands snmp-server host Use the snmp-server host command to set a SNMP host. Syntax: (config)# snmp-server host address {community community-name|version {1|2c} Field Definition address Enter an destination IP address. community-name Enter the SNMP community name. version 1 - SNMPv1 2c - SNMPv2c...
  • Page 192 Global Configuration Mode Global Configuration Commands static-dns Use the static-dns command to configure the DNS Static entries. To delete static DNS entries, see no static-dns command on page 4-53. Syntax: (config)# static-dns hostname hostname ip-address address Field Definition hostname Enter a DNS static host name of the server. address Enter the DNS static IP address.
  • Page 193 Global Configuration Mode Global Configuration Commands username Use the username command to create/modify a user profile for CLI. To delete a username, see no username command on page 4-53. Syntax: (config)# username name password password {admin|monitor |operator} Field Definition name Enter a User name, with a maximum of 15 characters.
  • Page 194 Global Configuration Mode Global Configuration Commands vlan (vlan-id) Use the vlan command to allow access to the VLAN port configuration commands. See Chapter 21, Configuration - VLAN Port Mode for commands in this mode. Syntax: (config)# vlan v-id Field Definition v-id VLAN identifier.
  • Page 195 Global Configuration Mode Global Configuration Commands voice-port (global) Use the voice-port fxs command to allow access to the Voice Port (global) configuration commands. See Chapter 22, Configuration - Voice Port Mode for commands in this mode. Syntax: (config)# voice-port Example: (config)# voice-port (config-vport)# Adit 3104, Adit 3500, MSR...
  • Page 196 Global Configuration Mode Global Configuration Commands voice-port trunk Use the voice-port trunk command to allow access to the Voice Port Trunk configuration commands. See Chapter 24, Configuration - Voice Port Trunk Mode for commands in this mode. To remove access to a Voice Port Trunk, see no voice-port trunk command on page 4-54.
  • Page 197 Note: The LCC Controller Configuration mode is supported by the MSR card only. For Controller Configuration commands for the Adit 3000 series, see Chapter 6, Configuration - T1 Controller Mode. This sub-group is entered with the (config)# controller lcc command from the Configuration mode.
  • Page 198 Configuration - LCC Controller Mode description Use the Controller LCC description command to enter a description for the LCC. Syntax: (config-cont-lcc-{n})# description text Field Definition text Enter a description for the LCC. Example: (config-cont-lcc-1)# description LCC#1 Supported Platforms: Adit 3000 (Rel. 1.6) and MSR Card (Rel 2.1) CLI...
  • Page 199 Configuration - LCC Controller Mode Use the do commands to run User and Privileged mode commands. The following are links to the User and Privileged do commands. User Mode Commands date command, on page 2-2 enable command, on page 2-2 end command, on page 2-2 exit command, on page 2-3 help command, on page 2-3...
  • Page 200 Configuration - LCC Controller Mode Use the end command to exit the current configuration mode, and must be used to mark the end of any configuration file. This command can be entered in any configuration mode with the same result. Syntax: (config-cont-lcc-{n})# end Example:...
  • Page 201 Configuration - LCC Controller Mode history Use the history command to display commands that have been entered in this session. This command can be entered in any configuration mode. Syntax: (config-cont-lcc-{n})# history Example: (config-cont-lcc-1)# history history description Test-LCC no shutdown history Supported Platforms: no command...
  • Page 202 Configuration - LCC Controller Mode shutdown Use the Controller LCC shutdown command to set the LCC interface down (out-of-service). To set the LCC up (in-service), see the no shutdown command on page 5-5. Syntax: (config-cont-lcc-{n})# shutdown Example: (config-cont-lcc-1)# shutdown Supported Platforms: Adit 3000 (Rel.
  • Page 203 The T1 Controller Configuration commands allow the user to configure the T1 parameters on the Adit 3000 series. Note: The T1 Controller Configuration mode is supported by the Adit 3000 series only. For Controller Configuration commands for the MSR card, see Chapter 5, Configuration - LCC Controller Mode.
  • Page 204: Description

    Configuration - T1 Controller Mode description Use the Controller T1 description command to set the circuit ID of the T1. Syntax: (config-cont-t1-{n})# description text Field Definition text Enter a description for the Controller T1. Example: (config-cont-t1-1)# description T1#1 Adit 3104, Adit 3200, Adit 3500 Supported Platforms: Adit 3000 (Rel.
  • Page 205 Configuration - T1 Controller Mode Use the do commands to run User and Privileged mode commands. The following are links to the User and Privileged do commands. User Mode Commands date command, on page 2-2 enable command, on page 2-2 end command, on page 2-2 exit command, on page 2-3 help command, on page 2-3...
  • Page 206 Configuration - T1 Controller Mode ds0-group Use the Controller T1 ds0-group command to create a group of T1s. To delete a DS0 group, see no ds0-group command on page 6-9. Syntax: (config-cont-t1-{n})# ds0-group timeslots range Field Definition range DS0 timeslot range, in the format n-n (1-4). Range is 1 - 24. Example: (config-cont-t1-1)# ds0-group timeslots 1-4 Adit 3104, Adit 3200, Adit 3500...
  • Page 207: Framing

    Configuration - T1 Controller Mode Use the Controller T1 fdl command to set line Facilities Data Link (FDL) capabilities the T1 interface. Syntax: (config-cont-t1-{n})# fdl {none|t1.403} Field Definition none Disable FDL output messages. Default. t1.403 Enable T1.403 FDL performance messages. Example: (config-cont-t1-1)# fdl none Adit 3104, Adit 3200, Adit 3500...
  • Page 208: History

    Configuration - T1 Controller Mode history Use the history command to display commands that have been entered in this session. This command can be entered in any configuration mode. Syntax: (config-cont-t1-{n})# history Example: (config-cont-t1-1)# history history framing d4 threshold daily lcv threshold d threshold daily pcv threshold daily bes...
  • Page 209 Configuration - T1 Controller Mode lbo long Use the Controller T1 lbo long command to set Line Build Out on the T1. Syntax: (config-cont-t1-{n})# lbo long {-7.5db|-15db|-22.5db} Field Definition -7.5db CSU attenuation for LBO of 7.5dB -15db CSU attenuation for LBO of 15dB -22.5db CSU attenuation for LBO of 22.5dB Example:...
  • Page 210: Linecode

    Configuration - T1 Controller Mode linecode Use the Controller T1 linecode command to set the line coding for the designated T1. Syntax: (config-cont-t1-{n})# linecode {ami|b8zs} Field Definition Alternate Mark Inversion line coding (AMI). b8zs Binary 8 Zero Substitution line coding (B8ZS). Default. Example: (config-cont-t1-1)# linecode ami Adit 3104, Adit 3200, Adit 3500...
  • Page 211: Loopdetect

    Configuration - T1 Controller Mode loopdetect Use the Controller T1 loopdetect command to enable the detection of CSU or NIU loop code. Syntax: (config-cont-t1-{n})# loopdetect {csu|niu|none} Field Definition Enable detection of CSU loop codes (10000 for loop up, 100 for loop down) Enable detection of NIU loop codes none...
  • Page 212: Pri-Group

    Configuration - T1 Controller Mode no shutdown Use the Controller T1 no shutdown command to set the T1 up (In-Service). To set the T1 down (Out-of-Service), see shutdown command on page 6-11. Syntax: (config-cont-t1-{n})# no shutdown Example: (config-cont-t1-1)# no shutdown Adit 3104, Adit 3200, Adit 3500 Supported Platforms: no tdm-group...
  • Page 213: Shutdown

    Configuration - T1 Controller Mode shutdown Use the Controller T1 shutdown command to set the T1 interface down (out-of-service). To set the T1 up (in-service) see no shutdown command on page 6-10. Syntax: (config-cont-t1-{n})# shutdown Example: (config-cont-t1-1)# shutdown Adit 3104, Adit 3200, Adit 3500 Supported Platforms: tdm-group Use the Controller T1 tdm-group command to create a group and define its direction.
  • Page 214: Threshold

    Configuration - T1 Controller Mode threshold Use the Controller T1 threshold command to define the interval and threshold levels for this T1. Syntax: (config-cont-t1-{n})# threshold {daily|min15} {bes|css|dm|es|lcv|les|pcv|sefs|ses|uas} {value} Threshold Settings Minute 15 Daily BES - Bursty Errored Seconds Default is 0. Default is 0.
  • Page 215 HAPTER Configuration - DHCP Pool Ethernet Mode The DHCP Pool Configuration commands allow the user to configure the DHCP parameters for each interface. This sub-group is entered with the (config)# ip dhcp pool ethernet command from the Configuration mode. The DHCP Pool commands are represented by the (config-dhcp-eth-{n})# prompt. DHCP Pool Commands •...
  • Page 216 Configuration - DHCP Pool Ethernet Mode Use the do commands to run User and Privileged mode commands. The following are links to the User and Privileged do commands. User Mode Commands date command, on page 2-2 enable command, on page 2-2 end command, on page 2-2 exit command, on page 2-3 help command, on page 2-3...
  • Page 217: End-Address

    Configuration - DHCP Pool Ethernet Mode Use the end command to exit the current configuration mode, and must be used to mark the end of any configuration file. This command can be entered in any configuration mode with the same result. Syntax: (config-dhcp-eth-{n})# end Example:...
  • Page 218: History

    Configuration - DHCP Pool Ethernet Mode history Use the history command to display commands that have been entered in this session. NOTE: This command can be entered in any configuration mode. Syntax: (config-dhcp-eth-{n})# history Example: (config-dhcp-eth-1)# history end-address 192.168.1.250 lease 900 relay 192.168.1.120 start-address 192.168.1.1 subnet-mask 255.255.255.0...
  • Page 219: No Commands

    Configuration - DHCP Pool Ethernet Mode no commands no option Use the DHCP Pool no option command to delete a DHCP option. To add a DHCP pool, see option command on page 7-6. Syntax: (config-dhcp-eth-{n})# no option {66|67} Field Definition Remove/Disable option 66 (TFTP server name).
  • Page 220: Option

    Configuration - DHCP Pool Ethernet Mode option Use the option command to configure DHCP options per RFC 2132. To delete an option, see no option command on page 7-5. Syntax: (config-dhcp-eth-{n})# option {66 {enable|value {address|hostname}|67 {enable|value filename} Field Definition 66 - Send the TFTP server name. address - Enter the IP address of the TFTP server.
  • Page 221: Start-Address

    Configuration - DHCP Pool Ethernet Mode start-address Use the DHCP Pool start-address command to define the DHCP start IP address. This command works with the end-address (end IP address) to define the number of IP addresses in the DHCP pool. This also limits the number of hosts that may be connected to the network in this subnet.
  • Page 222: Subnet-Mask

    Configuration - DHCP Pool Ethernet Mode subnet-mask Use the DHCP Pool subnet-mask command to define the subnet mask for the DHCP pool. Syntax: (config-dhcp-eth-{n})# subnet-mask mask Field Definition mask Enter the DHCP pool subnet mask, using the form xxx.xxx.xxx.xxx, where xxx is a number from 0 to 255. This is an optional setting. Example: (config-dhcp-eth-1)# subnet-mask 255.255.255.0 Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 223: Block-Out-Caller-Id

    HAPTER Configuration - Dial Peer FXS Mode The Dial Peer FXS Configuration commands allow the user to configure the Dial Peer FXS parameters. Enter this sub-group with the (config)# dial-peer voice pots fxs port command from the Configuration mode. The Dial Peer FXS commands are represented by the (config-dpeer-fxs)# prompt. Dial Peer FXS Commands •...
  • Page 224 Configuration - Dial Peer FXS Mode block-out-caller-id Use the Dial Peer block-out-caller-id command to enable the blocking of outgoing Caller ID. To disable blocking, see no block-out-caller-id command on page 8-8. Syntax: (config-dpeer-fxs)# block-out-caller-id enable Example: (config-dpeer-fxs)# block-out-caller-id enable Adit 3104, Adit 3500, MSR Supported Platforms: call-wait-caller-id Use the Dial Peer call-wait-caller-id command to enable Call Waiting and Caller ID.
  • Page 225: Codec Preference

    Configuration - Dial Peer FXS Mode codec preference Use the Dial Peer codec preference command to set the codec preferences used to establish the codec list offered during media negotiation. To delete a codec, see no codec preference command on page 8-9. Syntax: (config-dpeer-fxs)# codec preference {1|2|3} {g711alaw| g711ulaw|g729}...
  • Page 226: Exit

    Configuration - Dial Peer FXS Mode Use the do commands to run User and Privileged mode commands. The following are links to the User and Privileged do commands. User Mode Commands date command, on page 2-2 enable command, on page 2-2 end command, on page 2-2 exit command, on page 2-3 help command, on page 2-3...
  • Page 227: Exit

    Configuration - Dial Peer FXS Mode Use the end command to exit the current configuration mode, and must be used to mark the end of any configuration file. Syntax: (config-dpeer-fxs}# end Example: (config-dpeer-fxs)# end Adit 3104, Adit 3500, MSR Supported Platforms: exit Use the exit command to close your current connection if you are in the User mode, or Privileged mode.
  • Page 228: Fax-Protocol

    Configuration - Dial Peer FXS Mode fax-protocol Use the Dial Peer fax-protocol command to configure the fax protocol. Syntax: (config-dpeer-fxs)# fax-protocol {none|pass-through|t38} Field Definition none A Fax call would be treated as a normal voice call. Default. pass-through Will cause the line to transmit in G.711 mode, with echo cancellation and silence suppression disabled, on detection of Fax tone.
  • Page 229: Modem-Protocol

    Configuration - Dial Peer FXS Mode modem-protocol Use the Dial Peer modem-protocol command to configure the modem protocol. Syntax: (config-dpeer-fxs)# modem-protocol {none|pass-through} Field Definition none A Modem call would be treated as a normal voice call. Default. pass-through Will cause the line to transmit in G.711 mode, with echo cancellation and silence suppression disabled, on detection of Modem tone.
  • Page 230: No Commands

    Configuration - Dial Peer FXS Mode no commands no block-out-caller-id Use the Dial Peer no block-out-caller-id command to disable the Caller ID blocking. To enable blocking, see block-out-caller-id command on page 8-2. Syntax: (config-dpeer-fxs)# no block-out-caller-id Example: (config-dpeer-fxs)# no block-out-caller-id Adit 3104, Adit 3500, MSR Supported Platforms: no call-wait-caller-id...
  • Page 231: Sip-Authentication

    Configuration - Dial Peer FXS Mode no codec preference Use the Dial Peer no codec preference command to remove a codec preference. To set the codec preferences, see codec preference command on page 8-3. Syntax: (config-dpeer-fxs)# no codec preference {1|2|3} Field Definition 1|2|3...
  • Page 232 Configuration - Dial Peer FXS Mode sip-authentication Note: To disable this SIP authentication, see the no sip-authentication command on page 8-9. sip-authentication enable Use the Dial Peer sip-authentication enable command to enable SIP. Syntax: (config-dpeer-fxs)# sip-authentication enable Example: (config-dpeer-fxs)# sip-authentication enable Adit 3104, Adit 3500, MSR Supported Platforms: sip-authentication password...
  • Page 233: Destination-Pattern

    HAPTER Configuration - Dial Peer Trunk Mode The Dial Peer Trunk Configuration commands allow the user to configure the Dial Peer Trunk parameters. Enter this sub-group with the (config)# dial-peer voice pots trunk trunk dest-port command from the Configuration mode. The Dial Peer Trunk commands are represented by the (config-dpeer-trk)# prompt.
  • Page 234 Configuration - Dial Peer Trunk Mode codec preference Use the Dial Peer codec preference command to set the codec preferences used to establish the codec list offered during media negotiation. To delete a preference, see no codec preference command on page 9-6.
  • Page 235: Exit

    Configuration - Dial Peer Trunk Mode Use the do commands to run User and Privileged mode commands. The following are links to the User and Privileged do commands. User Mode Commands date command, on page 2-2 enable command, on page 2-2 end command, on page 2-2 exit command, on page 2-3 help command, on page 2-3...
  • Page 236 Configuration - Dial Peer Trunk Mode Use the end command to exit the current configuration mode, and must be used to mark the end of any configuration file. Syntax: (config-dpeer-trk)# end Example: (config-dpeer-trk)# end Adit 3500, MSR Supported Platforms: exit Use the exit command to close your current connection if you are in the User mode, or Privileged mode.
  • Page 237 Configuration - Dial Peer Trunk Mode history Use the history command to display commands that have been entered in this session. Syntax: (config-dpeer-trk)# history Example: (config-dpeer-trk)# history destination-pattern fax-protocol none modem-protocol pass-through sip-authentication enable strip-digits history Adit 3500, MSR Supported Platforms: modem-protocol Use the Dial Peer modem-protocol command to configure the modem protocol.
  • Page 238: No Commands

    Configuration - Dial Peer Trunk Mode no commands no codec preference Use the Dial Peer no codec preference command to remove a codec preference. To set the preferences, see codec preference command on page 9-2. Syntax: (config-dpeer-trk)# no codec preference {1|2|3} Field Definition 1|2|3...
  • Page 239: Prefix

    Configuration - Dial Peer Trunk Mode prefix Use the Dial Peer prefix command to define the prefix for the phone number. Syntax: (config-dpeer-trk)# prefix prefix Field Definition prefix Prefix is the digits or a name to be added to the phone number after the stripping process has been applied.
  • Page 240 Configuration - Dial Peer Trunk Mode sip-authentication username Use the Dial Peer sip-authentication username command to set the SIP ID. Syntax: (config-dpeer-trk)# sip-authentication username username Field Definition username The User ID to be used when responding to authentication requests. Default is the User ID of the line. Example: (config-dpeer-trk)# sip-authentication username test-user-1...
  • Page 241: Session-Target

    HAPTER Configuration - Dial Peer VoIP Mode The Dial Peer VoIP Configuration commands allow the user to configure the Dial Peer VoIP parameters. Enter this sub-group with the (config)# dial-peer voice voip port command from the Configuration mode. The Dial Peer VoIP commands are represented by the (config-dpeer-voip)# prompt. Dial Peer VoIP Commands •...
  • Page 242 Configuration - Dial Peer VoIP Mode destination-pattern Use the Dial Peer destination-pattern command to define the full telephone number to be used for a dial peer. To delete a preference, see no destination-pattern command on page 10-5. Syntax: (config-dpeer-voip)# destination-pattern number Field Definition number...
  • Page 243 Configuration - Dial Peer VoIP Mode Use the do commands to run User and Privileged mode commands. The following are links to the User and Privileged do commands. User Mode Commands date command, on page 2-2 enable command, on page 2-2 end command, on page 2-2 exit command, on page 2-3 help command, on page 2-3...
  • Page 244 Configuration - Dial Peer VoIP Mode Use the end command to exit the current configuration mode, and must be used to mark the end of any configuration file. Syntax: (config-dpeer-voip) end Example: (config-dpeer-voip)# end Adit 3104, Adit 3500, MSR Supported Platforms: exit Use the exit command to close your current connection if you are in the User mode, or Privileged mode.
  • Page 245 Configuration - Dial Peer VoIP Mode no commands no destination-pattern Use the Dial Peer no destination-pattern command to remove a destination pattern. To set the destination pattern, see destination-pattern command on page 10-2. Syntax: (config-dpeer-voip)# no destination-pattern Example: (config-dpeer-voip)# no destination-pattern Adit 3104, Adit 3500, MSR Supported Platforms: no prefix...
  • Page 246 Configuration - Dial Peer VoIP Mode prefix Use the Dial Peer prefix command to define the prefix for the phone number. To delete a prefix, see no prefix command on page 10-5. Syntax: (config-dpeer-voip)# prefix prefix Field Definition prefix Prefix is the digits or a name to be added to the phone number after the stripping process has been applied.
  • Page 247 Configuration - Dial Peer VoIP Mode strip-digits Use the Dial Peer strip-digits command to configure the number of digits (or characters) to be stripped off from the left most digits in the phone number. Possible usages include stripping off the area code, or the 3-digit office prefix.
  • Page 248 Configuration - Dial Peer VoIP Mode 10-8 Adit 3000 (Rel. 1.6) and MSR Card (Rel 2.1) CLI...
  • Page 249: Priority

    HAPTER Configuration - Ethernet Interface Mode The Ethernet Interface Configuration commands allow the user to configure the Ethernet interface parameters. Enter this sub-group with the (config)# interface ethernet command from the Configuration mode. The Ethernet Interface commands are represented by the (config-int-eth-{n})# prompt. Ethernet Interface Commands •...
  • Page 250: Description

    Configuration - Ethernet Interface Mode description Use the Ethernet Interface description command to set the description for this Ethernet interface. Syntax: (config-int-eth-{n})# description text Field Definition text Enter a description for the Ethernet interface with a maximum of 64 characters. Example: (config-int-eth-1)# description Eth#1 Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 251 Configuration - Ethernet Interface Mode Use the do commands to run User and Privileged mode commands. The following are links to the User and Privileged do commands. User Mode Commands date command, on page 2-2 enable command, on page 2-2 end command, on page 2-2 exit command, on page 2-3 help command, on page 2-3...
  • Page 252: Exit

    Configuration - Ethernet Interface Mode Use the end command to exit the current configuration mode, and must be used to mark the end of any configuration file. This command can be entered in any configuration mode with the same result. Syntax: (config-int-eth-{n})# end Example:...
  • Page 253: Full-Duplex

    Configuration - Ethernet Interface Mode full-duplex Use the Ethernet Interface full-duplex command to specify the Ethernet PHY (physical specifications) mode to full duplex. Syntax: (config-int-eth-{n})# full-duplex Example: (config-int-eth-1)# full-duplex Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: half-duplex Use the Ethernet Interface half-duplex command to specify the Ethernet PHY (physical specifications) mode to half duplex.
  • Page 254: History

    Configuration - Ethernet Interface Mode history Use the history command to display commands that have been entered in this session. This command can be entered in any configuration mode. Syntax: (config-int-eth-{n})# history Example: (config-int-eth-1)# history schedule-availability rule1 history full-duplex ip rip ip rip enable ip address speed auto...
  • Page 255: Ip Default-Gateway

    Configuration - Ethernet Interface Mode ip default-gateway Use the Ethernet Interface ip default-gateway command to set the default gateway for the Ethernet port. Syntax: (config-int-eth-{n})# ip default-gateway address Field Definition address Enter a default gateway address to the Ethernet port. Example: (config-int-eth-1)# ip default-gateway 192.168.100.150 Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 256 Configuration - Ethernet Interface Mode ip mtu Use the Ethernet Interface ip mtu command to set the Maximum Transmission Unit. Sets the largest packet size (bytes) the network will allow to transmit. Syntax: (config-int-eth-{n})# ip mtu {size|auto} Field Definition size Allows the user to set the Maximum Transmission Unit (MTU).
  • Page 257: Ip Ospf Authentication

    Configuration - Ethernet Interface Mode ip ospf authentication Use the Ethernet Interface ip ospf authentication command to enable the authentication method (either message-digest or simple authentication) for this Ethernet interface. To remove the authentication type for this interface set the parameter to null or see no ip ospf authentication command on page 11-18. Note: If an optional parameter is not entered, the authentication method of simple authentication is applied to the interface.
  • Page 258: Ip Ospf Authentication-Key

    Configuration - Ethernet Interface Mode ip ospf authentication-key Use the Ethernet Interface ip ospf authentication-key command to assign a password to be used by neighboring routers, that are using OSPF’s simple password authentication.To remove a previously assigned password, see no ip ospf authentication-key command on page 11-18. Syntax: (config-int-eth-{n})# ip ospf authentication-key password Field...
  • Page 259: Ip Ospf Disable

    Configuration - Ethernet Interface Mode ip ospf disable Use the Ethernet Interface ip ospf disable command to disable OSPF processing on this interface. To enable OSPF on this interface, see no ip ospf disable command on page 11-19. Syntax: (config-int-eth-{n})# ip ospf disable all Example: (config-int-eth-1)# ip ospf disable all Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 260: Ip Ospf Priority

    Configuration - Ethernet Interface Mode ip ospf priority Use the Ethernet Interface ip ospf priority command to set the router priority, which determines the designated router for this network. To restore the default setting of priority 1, see no ip ospf priority command on page 11-20.
  • Page 261: Ip Primary-Dns

    Configuration - Ethernet Interface Mode ip primary-dns Use the Ethernet Interface ip primary-dns command to configure the primary DNS. To delete a primary DNS, see no ip primary-dns command on page 11-20. Syntax: (config-int-eth-{n})# ip primary-dns address Field Definition address Enter the IP address of the primary server.
  • Page 262 Configuration - Ethernet Interface Mode ip rip ip rip enable Use the Ethernet Interface ip rip enable command to enable RIP on this interface. To disable RIP, see no ip rip command on page 11-21. Syntax: (config-int-eth-{n})# ip rip enable Example: (config-int-eth-1)# ip rip enable Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 263: Ip Route

    Configuration - Ethernet Interface Mode ip route Use the Ethernet Interface ip route command to configure the static routes on this interface. To delete a route, see no ip route command on page 11-21. Syntax: (config-int-eth-{n})# ip route dest-ip-addr mask mask gateway gateway metric metric Field Definition...
  • Page 264: Ip Secondary-Dns

    Configuration - Ethernet Interface Mode ip secondary-dns Use the Ethernet Interface ip secondary-dns command to configure the secondary DNS. To delete a secondary DNS address, see no ip secondary-dns command on page 11-21. Syntax: (config-int-eth-{n})# ip secondary-dns address Field Definition address Enter the IP address of the secondary Domain Name Server (DNS).
  • Page 265: No Commands

    Configuration - Ethernet Interface Mode no commands no firewall Use the no firewall command to disable the configured firewall. To enable the firewall, see firewall command on page 11-4. Syntax: (config-int-eth-{n})# no firewall Example: (config-int-eth-1)# no firewall Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: no ip address Use the Ethernet Interface no ip address command to remove the IP address from the alias.
  • Page 266 Configuration - Ethernet Interface Mode no ip ospf authentication Use the Ethernet Interface no ip ospf authentication command to disable the authentication method for this Ethernet interface. To enable the authentication type for this interface see ip ospf authentication command on page 11-9. Syntax: (config-int-eth-{n})# no ip ospf authentication Example:...
  • Page 267 Configuration - Ethernet Interface Mode no ip ospf disable Use the Ethernet Interface no ip ospf disable command to enable OSPF processing on this interface. To disable OSPF on this interface, see ip ospf disable command on page 11-11. Syntax: (config-int-eth-{n})# ip ospf disable all Example: (config-int-eth-1)# ip ospf disable all...
  • Page 268 Configuration - Ethernet Interface Mode no ip ospf priority Use the Ethernet Interface no ip ospf priority command to set the router priority to the default setting of priority 1. To set the router priority, which determines the designated router for this network, see ip ospf priority command on page 11-12.
  • Page 269 Configuration - Ethernet Interface Mode no ip proxy-arp Use the Ethernet Interface no ip proxy-arp command to disable the proxy ARP on this interface. To enable proxy ARP, see ip proxy-arp command on page 11-13. Syntax: (config-int-eth-{n})# no ip proxy-arp Example: (config-int-eth-1)# no ip proxy-arp Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 270 Configuration - Ethernet Interface Mode no remote-admin Use the Ethernet Interface no remote-admin command to disable remote access on this interface. To enable remote access, see remote-admin command on page 11-23. Syntax: (config-int-eth-{n})# no remote-admin Example: (config-int-eth-1)# no remote-admin Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: no schedule-availability Use the Ethernet Interface no schedule-availability command to disable a schedule...
  • Page 271: Release

    Configuration - Ethernet Interface Mode no tos ip Use the Ethernet Interface no tos ip command to disable IP TOS marking. To enable TOS marking, see tos command on page 11-25. Syntax: (config-int-eth-{n})# no tos ip Example: (config-int-eth-1)# no tos ip Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: release...
  • Page 272: Schedule-Availability

    Configuration - Ethernet Interface Mode schedule-availability Use the Ethernet Interface schedule-availability command to apply a schedule rule to this interface. To delete a schedule, see no schedule-availability command on page 11-22. Syntax: (config-int-eth-{n})# schedule-availability time-range schedule-id Field Definition schedule-id Enter an existing schedule rule name. See time-range command on page 4-64 to set the schedule-id Example: (config-int-eth-1)# schedule-availability time-range 1...
  • Page 273: Speed

    Configuration - Ethernet Interface Mode speed Use the Ethernet Interface speed command to specify the Ethernet PHY (physical specifications) speed. Syntax: (config-int-eth-{n})# speed {10|100|auto} Field Definition 10 Mbps speed . 100 Mbps speed. auto Auto-negotiate the speed for the interface. Default. Note: Setting speed to auto will set the duplex to auto.
  • Page 274 Configuration - Ethernet Interface Mode 11-26 Adit 3000 (Rel. 1.6) and MSR Card (Rel 2.1) CLI...
  • Page 275: Ppp Authentication

    HAPTER Configuration - Multilink Interface Mode The Multilink Interface Configuration commands allow the user to configure the MLPPP parameters. Enter this sub-group with the (config)# interface multilink number command from the Configuration mode. The Multilink Interface commands are represented by the (config-int-mlink-{n})# prompt. Note: Before configuring MLPPP parameters, you must create a multilink group from the corresponding Serial interface.
  • Page 276: Description

    Configuration - Multilink Interface Mode description Use the Multilink Interface description command to set the description for this Multilink interface. Syntax: (config-int-mlink-{n})# description text Field Definition text Enter a description for the Multilink interface with a maximum of 64 characters. Example: (config-int-mlink-1)# description MLPPP1 Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 277 Configuration - Multilink Interface Mode Use the do commands to run User and Privileged mode commands. The following are links to the User and Privileged do commands. User Mode Commands date command, on page 2-2 enable command, on page 2-2 end command, on page 2-2 exit command, on page 2-3 help command, on page 2-3...
  • Page 278: Exit

    Configuration - Multilink Interface Mode Use the end command to exit the current configuration mode, and must be used to mark the end of any configuration file. This command can be entered in any configuration mode with the same result. Syntax: (config-int-mlink-{n})# end Example:...
  • Page 279: History

    Configuration - Multilink Interface Mode history Use the history command to display commands that have been entered in this session. This command can be entered in any configuration mode. Syntax: (config-int-mlink-{n})# history Example: (config-int-mlink-1)# history description testdesc firewall enable ip rip enable ppp authentication pap ppp encryption 128-bit history...
  • Page 280: Ip Default-Route

    Configuration - Multilink Interface Mode ip default-route Use the Multilink Interface ip default-route command to enable the default route. To disable the default route, see no ip default-route command on page 12-14. Syntax: (config-int-mlink-{n})# ip default-route enable Example: (config-int-mlink-1)# ip default-route enable Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: ip mtu...
  • Page 281: Ip Ospf Authentication

    Configuration - Multilink Interface Mode ip ospf authentication Use the Multilink Interface ip ospf authentication command to enable the authentication method (either message-digest or simple authentication) for this Multilink interface. To remove the authentication type for this interface set the parameter to null or see no ip ospf authentication command on page 12-14.
  • Page 282: Ip Ospf Authentication-Key

    Configuration - Multilink Interface Mode ip ospf authentication-key Use the Multilink Interface ip ospf authentication-key command to assign a password to be used by neighboring routers, that are using OSPF’s simple password authentication.To remove a previously assigned password, see no ip ospf authentication-key command on page 12-15. Syntax: (config-int-mlink-{n})# ip ospf authentication-key password Field...
  • Page 283: Ip Ospf Disable

    Configuration - Multilink Interface Mode ip ospf disable Use the Multilink Interface ip ospf disable command to disable OSPF processing on this interface. To enable OSPF on this interface, see no ip ospf disable command on page 12-15. Syntax: (config-int-mlink-{n})# ip ospf disable all Example: (config-int-mlink-1)# ip ospf disable all Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 284: Ip Ospf Priority

    Configuration - Multilink Interface Mode ip ospf priority Use the Multilink Interface ip ospf priority command to set the router priority, which determines the designated router for this network. To restore the default setting of priority 1, see no ip ospf priority command on page 12-16.
  • Page 285: Ip Primary-Dns

    Configuration - Multilink Interface Mode ip primary-dns Use the Multilink Interface ip primary-dns command to configure the primary DNS. To delete a primary DNS, see no ip primary-dns command on page 12-17. Syntax: (config-int-mlink-{n})# ip primary-dns address Field Definition address Enter the IP address of the primary server.
  • Page 286: Ip Route

    Configuration - Multilink Interface Mode ip rip send-version Use the Multilink Interface ip rip send-version command to configure the send RIP messages on this interface. Syntax: (config-int-mlink-{n})# ip rip send-version {1|2-bcast|2-mcast |none} Field Definition Send RIP version 1. 2-bcast Send RIP version 2 - Broadcast. 2-mcast Send RIP version 2 - Multicast.
  • Page 287: Ip Route-Mode

    Configuration - Multilink Interface Mode ip route-mode Use the Multilink Interface ip route-mode command to configure the routing mode. Syntax: (config-int-mlink-{n})# ip route-mode {napt|route} Field Definition napt Set to NAPT mode. Default. NAPT is used if doing private IPs on the Ethernet side or if you want to hide specific publics on the internal side.
  • Page 288: No Commands

    Configuration - Multilink Interface Mode no commands no firewall Use the Multilink Interface no firewall command to disable the configured firewall. To enable the firewall on this interface, see firewall command on page 12-4. Syntax: (config-int-mlink-{n})# no firewall Example: (config-int-mlink-1)# no firewall Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: no ip address...
  • Page 289 Configuration - Multilink Interface Mode no ip ospf authentication-key Use the Multilink Interface no ip ospf authentication-key command to remove a password to be used by neighboring routers, that are using OSPF’s simple password authentication. To assign a password, see ip ospf authentication-key command on page 12-8. Syntax: (config-int-mlink-{n})# no ip ospf authentication Example:...
  • Page 290 Configuration - Multilink Interface Mode no ip ospf hello-interval Use the Multilink Interface no ip ospf hello-interval command to reset the interval of time to the default setting of 10 seconds. To define the interval of time between hello packets sent on the interface, see ip ospf hello-interval command on page 12-9.
  • Page 291 Configuration - Multilink Interface Mode no ip ospf retransmit-interval Use the Multilink Interface ip ospf retransmit-interval command to restore the default value of 5 seconds. To define the interval of time between link state advertisement retransmissions for adjacencies belonging to the interface, see ip ospf retransmit-interval command on page 12-10. Syntax: (config-int-mlink-{n})# no ip ospf retransmit-interval Example:...
  • Page 292: Ppp Authentication

    Configuration - Multilink Interface Mode no ip route Use the Multilink Interface no ip route command remove an IP route. To add a route, see ip route command on page 12-12. Syntax: (config-int-mlink-{n})# no ip route dest-ip-addr gateway Field Definition dest-ip-addr Enter destination IP address to remove.
  • Page 293: Ppp Encryption

    Configuration - Multilink Interface Mode no ppp encryption Use the Multilink Interface no ppp encryption command to disable PPP encryption. To enable PPP encryption, see the ppp encryption command on page 12-21. Syntax: (config-int-mlink-{n})# no ppp encryption [128-bit|40- bit|required|stateful] Field Definition Specifying the command without parameters d <CR>...
  • Page 294 Configuration - Multilink Interface Mode no ppp qos interleaving Use the Multilink Interface no ppp qos interleaving command to disable PPP QoS interleaving. To enable PPP QoS interleaving, see ppp qos-interleaving command on page 12-23. Syntax: (config-int-mlink-{n})# no ppp qos interleaving Example: (config-int-mlink-1)# no ppp qos interleaving Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 295: Ppp Authentication

    Configuration - Multilink Interface Mode no sip-alg Use the Multilink Interface no sip-alg command to disable SIP ALG on this interface. To enable SIP ALG, see sip-alg command on page 12-25. Syntax: (config-int-mlink-{n})# no sip-alg Example: (config-int-mlink-1)# no sip-alg Adit 3104, Adit 3500, MSR Supported Platforms: ppp authentication Use the Multilink Interface ppp authentication command to configure the support of authentication...
  • Page 296: Ppp Exec-Timeout

    Configuration - Multilink Interface Mode ppp exec-timeout Use the Multilink Interface ppp exec-timeout command to configure the PPP maximum idle time before hangup. Syntax: (config-int-mlink-{n})# ppp exec-timeout minutes Field Definition minutes Range is 0 - 99999 minutes. Example: (config-int-mlink-1)# ppp exec-timeout 150 Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: ppp link-fragmentation...
  • Page 297: Ppp Password

    Configuration - Multilink Interface Mode ppp password Use the Multilink Interface ppp password command set the PPP password. To delete a PPP password, see no ppp password command on page 12-19. Syntax: (config-int-mlink-{n})# ppp password password Field Definition password Enter the PPP password, with a maximum of 19 characters. Example: (config-int-mlink-1)# ppp username test-user-pswrd Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 298: Ppp Time-Btwn-Reconnect

    Configuration - Multilink Interface Mode ppp time-btwn-reconnect Use the Multilink Interface ppp time-btwn-reconnect command configure the time between reconnect attempts. Syntax: (config-int-mlink-{n})# ppp time-btwn-reconnect seconds Field Definition seconds Set the interval of time between reconnect attempts. Range is 0 - 99999 seconds. Default is 30 seconds. Example: (config-int-mlink-1)# ppp time-btwn-reconnect 15 Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 299: Shutdown

    Configuration - Multilink Interface Mode shutdown Use the Multilink Interface shutdown command to disable the multilink port. To set the Multilink port up (In-Service), see no shutdown command on page 12-20. Syntax: (config-int-mlink-{n})# shutdown Example: (config-int-mlink-1)# shutdown Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: sip-alg Use the Multilink Interface sip-alg command to enable SIP ALG.
  • Page 300 Configuration - Multilink Interface Mode 12-26 Adit 3000 (Rel. 1.6) and MSR Card (Rel 2.1) CLI...
  • Page 301: Encapsulation Ppp

    HAPTER Configuration - Serial Interface Mode The Serial Interface Configuration commands allow the user to configure the serial interface parameters. Enter this sub-group with the (config)# interface serial number command from the Configuration mode. The Serial Interface commands are represented by the (config-int-ser-{n})# prompt. Note: Before configuring serial interface parameters, you must enable PPP encapsulation on the interface using the encapsulation ppp command.
  • Page 302 Configuration - Serial Interface Mode description Use the Serial Interface description command to set the description for this serial interface. Syntax: (config-int-ser-{n})# description text Field Definition text Enter a description for the serial interface with a maximum of 64 characters. Example: (config-int-ser-1)# description Serial1 Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 303 Configuration - Serial Interface Mode Use the do commands to run User and Privileged mode commands. The following are links to the User and Privileged do commands. User Mode Commands date command, on page 2-2 enable command, on page 2-2 end command, on page 2-2 exit command, on page 2-3 help command, on page 2-3...
  • Page 304: Encapsulation Ppp

    Configuration - Serial Interface Mode encapsulation ppp Use the Serial Interface encapsulation ppp command to enable PPP encapsulation. To disable encapsulation (by deleting the serial interface), see no encapsulation ppp command on page 13-14. Syntax: (config-int-ser-{n})# encapsulation ppp Example: (config-int-ser-1)# encapsulation ppp Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: Use the end command to exit the current configuration mode, and must be used to mark the end of any...
  • Page 305 Configuration - Serial Interface Mode firewall Use the Serial Interface firewall command to enable the configured firewall. To delete a preference, see no firewall command on page 13-14. Syntax: (config-int-ser-{n})# firewall enable Example: (config-int-ser-1)# firewall enable Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: history Use the history command to display commands that have been entered in this session.
  • Page 306 Configuration - Serial Interface Mode ip address Use the Serial Interface ip address command to configure the IP address for the serial interface. To remove an IP address, see no ip address command on page 13-15. Syntax: (config-int-ser-{n})# ip address {address mask mask|auto |unnumbered} [secondary] Field Definition...
  • Page 307 Configuration - Serial Interface Mode ip ospf authentication Use the Serial Interface ip ospf authentication command to enable the authentication method (either message-digest or simple authentication) for this serial interface. To remove the authentication type for this interface set the parameter to null or see no ip ospf authentication command on page 13-15. Note: If an optional parameter is not entered, the authentication method of simple authentication is applied to the interface.
  • Page 308: Ip Ospf Cost

    Configuration - Serial Interface Mode ip ospf authentication-key Use the Serial Interface ip ospf authentication-key command to assign a password to be used by neighboring routers, that are using OSPF’s simple password authentication.To remove a previously assigned password, see no ip ospf authentication-key command on page 13-15. Syntax: (config-int-ser-{n})# ip ospf authentication-key password Field...
  • Page 309 Configuration - Serial Interface Mode ip ospf disable Use the Serial Interface ip ospf disable command to disable OSPF processing on this interface. To enable OSPF on this interface, see no ip ospf disable command on page 13-16. Syntax: (config-int-ser-{n})# ip ospf disable all Example: (config-int-ser-1)# ip ospf disable all Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 310 Configuration - Serial Interface Mode ip ospf priority Use the Serial Interface ip ospf priority command to set the router priority, which determines the designated router for this network. To restore the default setting of priority 1, see no ip ospf priority command on page 13-17.
  • Page 311 Configuration - Serial Interface Mode ip primary-dns Use the Serial Interface ip primary-dns command to configure the primary DNS. To delete a primary DNS, see no ip primary-dns command on page 13-18. Syntax: (config-int-ser-{n})# ip primary-dns address Field Definition address Enter the IP address of the primary server.
  • Page 312 Configuration - Serial Interface Mode ip rip send-version Use the Serial Interface ip rip send-version command to configure the send RIP messages on this interface. Syntax: (config-int-ser-{n})# ip rip send-version {1|2-bcast|2-mcast |none} Field Definition Send RIP version 1. 2-bcast Send RIP version 2 - Broadcast. 2-mcast Send RIP version 2 - Multicast.
  • Page 313 Configuration - Serial Interface Mode ip route-mode Use the Serial Interface ip route-mode command to configure the routing mode. Syntax: (config-int-ser-{n})# ip route-mode {napt|route} Field Definition napt Set to NAPT mode. Default. NAPT is used if doing private IPs on the Ethernet side or if you want to hide specific publics on the internal side.
  • Page 314 Configuration - Serial Interface Mode multilink-group Use the Serial Interface multilink-group command to configure a MLPPP group. Syntax: (config-int-ser-{n})# multilink-group group-number Field Definition group-number Enter multilink group. Adit 3104, Adit 3200, Adit 3500: Value must be 1. MSR: Range = 1-8. Example: (config-int-ser-1)# multilink-group 1 Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 315 Configuration - Serial Interface Mode no ip address Use the Serial Interface no ip address command to remove the IP address assigned to the serial interface. To set the Serial IP address, see ip address command on page 13-6. Syntax: (config-int-ser-{n})# no ip address address Field Definition...
  • Page 316 Configuration - Serial Interface Mode no ip ospf cost Use the Serial Interface no ip ospf cost command to reset the cost to null. To define the cost of sending a packet on this serial interface, see ip ospf cost command on page 13-8. Syntax: (config-int-ser-{n})# no ip ospf cost Example:...
  • Page 317 Configuration - Serial Interface Mode no ip ospf message-digest-key Use the Serial Interface no ip ospf message-digest-key command to remove an old MD5 key. To enable OSPF MD5 (Message-Digest) authentication, see ip ospf message-digest-key command on page 13-9. Syntax: (config-int-ser-{n})# no ip ospf message-digest-key key-id Field Definition key-id...
  • Page 318 Configuration - Serial Interface Mode no ip primary-dns Use the Serial Interface no primary-dns command to disable the primary DNS. To set the DNS primary IP address, see ip primary-dns command on page 13-11. Syntax: (config-int-ser-{n})# no ip primary-dns Example: (config-int-ser-1)# no ip primary-dns Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms:...
  • Page 319 Configuration - Serial Interface Mode no ppp authentication Use the Serial Interface no ppp authentication command disable PPP authentication. To enable PPP authentication, see ppp authentication command on page 13-21. Syntax: (config-int-ser-{n})# no ppp authentication Example: (config-int-ser-1)# no ppp authentication Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: no ppp encryption...
  • Page 320 Configuration - Serial Interface Mode no ppp password Use the Serial Interface no ppp password command to remove the PPP password. To set the PPP password, see ppp password command on page 13-23. Syntax: (config-int-ser-{n})# no ppp password Example: (config-int-ser-1)# no ppp password Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: no ppp username...
  • Page 321 Configuration - Serial Interface Mode no sip-alg Use the Serial Interface no sip-alg command to disable SIP ALG on this interface. To enable SIP ALG, see sip-alg command on page 13-25. Syntax: (config-int-ser-{n})# no sip-alg Example: (config-int-ser-1)# no sip-alg Adit 3104, Adit 3500, MSR Supported Platforms: ppp authentication Use the Serial Interface ppp authentication command to configure the support of authentication types...
  • Page 322 Configuration - Serial Interface Mode ppp exec-timeout Use the Serial Interface ppp exec-timeout command to set the PPP maximum idle time before hangup. Syntax: (config-int-ser-{n})# ppp exec-timeout minutes Field Definition minutes Range is 0 - 99999 minutes. Example: (config-int-ser-1)# ppp exec-timeout 150 Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: ppp link-fragmentation...
  • Page 323 Configuration - Serial Interface Mode ppp password Use the Serial Interface ppp password command set the PPP password. To delete a PPP password, see no ppp password command on page 13-20. Syntax: (config-int-ser-{n})# ppp password password Field Definition password Enter the PPP password, with a maximum of 19 characters. Example: (config-int-ser-1)# ppp username test-user-pswrd Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 324: Ppp Username

    Configuration - Serial Interface Mode ppp username Use the Serial Interface ppp username command set the PPP Login User Name. To delete a PPP user, see no ppp username command on page 13-20. Syntax: (config-int-ser-{n})# ppp username username Field Definition username Enter the Username, with a maximum of 19 characters.
  • Page 325 Configuration - Serial Interface Mode sip-alg Use the Serial Interface sip-alg command to enable SIP ALG. To disable SIP ALG, see no sip-alg command on page 13-21. Syntax: (config-int-ser-{n})# sip-alg enable Example: (config-int-ser-1)# sip-alg enable Adit 3104, Adit 3500, MSR Supported Platforms: Adit 3000 (Rel.
  • Page 326 Configuration - Serial Interface Mode 13-26 Adit 3000 (Rel. 1.6) and MSR Card (Rel 2.1) CLI...
  • Page 327: Ipsec Commands

    HAPTER Configuration - IPSec Mode The IPSecConfiguration commands allow the user to configure the VPN IPSec parameters. Enter this sub-group with the (config)# ipsec vpn_ipsec command from the Configuration mode. The IPSec commands are represented by the (config-ipsec-n)# prompt. Note: First a connection must be created. See ipsec net-to-host command on page 4-23, or ipsec net-to- net command on page 4-24.
  • Page 328: Aggressive-Mode

    Configuration - IPSec Mode aggressive-mode Use the IPSec aggressive-mode command to set to aggressive mode, instead of main mode. To set to main mode, see no aggressive-mode command on page 14-12. Syntax: (config-ipsec {n})# aggressive-mode Example: (config-ipsec-1)# aggressive-mode Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: authentication Use the IPSec authentication command to specify a peer authentication method.
  • Page 329 Configuration - IPSec Mode Use the do commands to run User and Privileged mode commands. The following are links to the User and Privileged do commands. User Mode Commands date command, on page 2-2 enable command, on page 2-2 end command, on page 2-2 exit command, on page 2-3 help command, on page 2-3 history command, on page 2-4...
  • Page 330: Dpd-Delay

    Configuration - IPSec Mode dpd-delay Use the IPSec dpd-delay command to set the Dead Period Detection delay. To set the DPD delay back to the default settings, see no dpd-delay command on page 14-12. Syntax: (config-ipsec {n})# dpd-delay seconds Field Definition seconds Set the delay time in seconds.
  • Page 331: Encryption

    Configuration - IPSec Mode encryption Use the IPSec encryption command to specify an encryption algorithm. To disable encryption, see no group command on page 14-13. Syntax: (config-ipsec {n})# encryption {des|3des|aes|aes192|aes256} Field Definition Set to 56-bit Data Encryption Standard (DES). 3des Set to 168-bit DES.
  • Page 332: Group

    Configuration - IPSec Mode group Use the IPSec group command to define the Diffie-Hellman (DH) group identifier for phase-1. Note: More than one group can be enabled. To disable a DH identifier, see no group command on page 14-13. Syntax: (config-ipsec {n})# group {1|2|5} Field Definition...
  • Page 333: History

    Configuration - IPSec Mode history Use the history command to display commands that have been entered in this session. This command can be entered in any configuration mode. Syntax: (config-ipsec {n})# history Example: (config-ipsec-1)# history dpd-timeout 900 history ip rip r ip rip receive-version 1or2 ip rip enable reconnect...
  • Page 334: Ipsec-Conn

    Configuration - IPSec Mode ipsec-conn Use the IPSec mode ipsec-conn command to enable or disable an IPSec connection without removing Syntax: (config-ipsec {n})# ipsec-conn {disable|enable} Field Definition disable Disable the IPSec connection. enable Enable the IPSec connection. Example: (config-ipsec-1)# ipsec-conn enable Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: ipsec-manual...
  • Page 335: Lifetime

    Configuration - IPSec Mode lifetime Use the IPSec mode lifetime command to set the connection lifetime. Syntax: (config-ipsec {n})# lifetime time seconds Field Definition seconds Set the connection lifetime. Range 1-86400 seconds, with a default of 86400. Example: (config-ipsec-1)# lifetime time 70000 Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: local-subnet...
  • Page 336: Max-Retries

    Configuration - IPSec Mode max-retries Use the IPSec mode max-retries command to set a maximum number of negotiation attempts. Syntax: (config-ipsec {n})# max-retries number Field Definition number Valid values: 0, 1, 2, 3, 4, 8, 16, 24, 32, 48, 64. Default is 3. 0 = infinite negotiation attempts.
  • Page 337: Net-Type

    Configuration - IPSec Mode net-type Use the IPSec mode net-type command to define the network type. Syntax: (config-ipsec {n})# network-type {dmz|lan|wan} Field Definition Demilitarized Zone. Local Area Network. Wide Area Network. Example: (config-ipsec-1)# net-type lan Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: netbios remote-brc-addr Use the IPSec netbios remote-brc-addr command to set the remote broadcast address for NetBIOS.
  • Page 338: No Commands

    Configuration - IPSec Mode no commands no aggressive-mode Use the IPSec mode no aggressive-mode command to set to main mode, instead of aggressive mode. To set to aggressive mode, see aggressive-mode command on page 14-2. Syntax: (config-ipsec {n})# no aggressive-mode Example: (config-ipsec-1)# no aggressive-mode Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 339 Configuration - IPSec Mode no encryption Use the IPSec no encryption command to disable encryption. To configure encryption, see encryption command on page 14-5. Syntax: (config-ipsec-{n})# no encryption {des|3des|aes|aes192| aes256} Field Definition Disable 56-bit Data Encryption Standard (DES). 3des Disable 168-bit DES. Default. Disable 128-bit Advanced Encryption Standard (AES) as the encryption algorithm.
  • Page 340 Configuration - IPSec Mode no hash Use the IPSec no hash command to disable a hash algorithm. To set a hash algorithm, see hash command on page 14-6. Syntax: (config-ipsec-{n})# no hash {md5|sha} Field Definition Disable the MD5 algorithm. Disable SHA1. SHA = Secure Hash Algorithm. Example: (config-ipsec-1)# no hash md5 Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 341 Configuration - IPSec Mode no reconnect Use the IPSec no reconnect command to disable automatic reconnection. To enable reconnection, see reconnect command on page 14-17. Syntax: (config-ipsec-{n})# no reconnect Example: (config-ipsec-1)# no reconnect Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: no schedule-availability Use the IPSec no schedule-availability command to set schedule availability to the default value.
  • Page 342 Configuration - IPSec Mode no transform-set Use the IPSec no transform-set command to disable Perfect Forward Secrecy. To enable PFS, see transform-set command on page 14-20. Syntax: (config-ipsec-{n})# no transform-set {ah-md5|ah-sha|esp-3des| esp-aes|esp-aes192|esp-aes256|esp-des|esp-md5|esp-null|esp-sha |ipcomp} Field Definition ah-md5 Authentication Header transform using MD5 authentication. Default. ah-sha Authentication Header transform using Secure Hash Algorithm (SHA1) authentication.
  • Page 343: Reconnect

    Configuration - IPSec Mode reconnect Use the IPSec reconnect command to enable the automatic reconnection option. To disable reconnection, see no reconnect command on page 14-15. Syntax: (config-ipsec-{n})# reconnect Example: (config-ipsec-1)# reconnect Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: rekey Use the IPSec rekey command to set the rekey lifetime, rekey margin and rekey fuzz percent.
  • Page 344: Remote-Subnet

    Configuration - IPSec Mode remote-subnet Use the IPSec remote-subnet command to set the remote subnet IP address. Syntax: (config-ipsec-{n})# remote-subnet {none|range {start-address address end-address address}|single ip address|subnet ip address} Field Definition none No IP address. range Enter an IP address range. start-address - Enter the start IP address of the range.
  • Page 345: Session-Key

    Configuration - IPSec Mode session-key Use the IPSec session-key command to specify the parameters needed during manual key exchange (ipsec-manual). Syntax: (config-ipsec-{n})# session-key {inbound|outbound} ah spi authentication [md5|sha] hex-key-data Field Definition inbound Set the inbound (local) IPSec key. outbound Set the outbound (remote) IPSec key. ah spi Set the Authentication Header Security Parameter Index.
  • Page 346: Transform-Set

    Configuration - IPSec Mode transform-set Use the IPSec transform-set command to set the allowable encryption methods, authentication protocols and to enable compression during automatic key exchange. To disable encryption/ authentication/compression, see no transform-set command on page 14-16. Syntax: (config-ipsec-{n})# transform-set {ah-md5|ah-sha|esp-3des| esp- aes|esp-aes192|esp-aes256|esp-des|esp-md5|esp-null|esp-sha |ipcomp} Field...
  • Page 347: Example Of Ipsec Connection Configuration

    Configuration - IPSec Mode Example of IPSec Connection Configuration Example of IPSec Connection Configuration Adit 3104(config)#ipsec VPN_IPSEC 0 Adit 3104(config-ipsec-0)#dev-name VPNIPSec0 Adit 3104(config-ipsec-0)#net-type WAN Adit 3104(config-ipsec-0)#aggressive-mode Adit 3104(config-ipsec-0)#authentication pre-share ocho Adit 3104(config-ipsec-0)#no encryption des Adit 3104(config-ipsec-0)#no encryption 3des Adit 3104(config-ipsec-0)#no encryption aes Adit 3104(config-ipsec-0)#encryption aes192 Adit 3104(config-ipsec-0)#no encryption aes256 Adit 3104(config-ipsec-0)#group 1...
  • Page 348 Configuration - IPSec Mode Example of IPSec Connection Configuration Adit 3104(config-ipsec-0)#transform-set esp-null Adit 3104(config-ipsec-0)#transform-set esp-des Adit 3104(config-ipsec-0)#transform-set esp-3des Adit 3104(config-ipsec-0)#transform-set esp-aes Adit 3104(config-ipsec-0)#transform-set esp-aes192 Adit 3104(config-ipsec-0)#transform-set esp-aes256 Adit 3104(config-ipsec-0)#transform-set esp-md5 Adit 3104(config-ipsec-0)#transform-set esp-sha Adit 3104(config-ipsec-0)#transform-set ah-md5 Adit 3104(config-ipsec-0)#transform-set ah-sha Adit 3104(config-ipsec-0)#no transform-set ipcomp Adit 3104(config-ipsec-0)# 14-22 Adit 3000 (Rel.
  • Page 349: Host-Ip

    HAPTER Configuration - L2TPC Mode The L2TPC Configuration commands allow the user to configure the VPN Layer 2 Tunneling Protocol Connection (L2TPC) parameters. Enter this sub-group with the (config)# l2tpc command from the Configuration mode. The VPN L2TPC commands are represented by the (config-l2tpc-1)# prompt. L2TPC Commands •...
  • Page 350 Configuration - L2TPC Mode Use the do commands to run User and Privileged mode commands. The following are links to the User and Privileged do commands. User Mode Commands date command, on page 2-2 enable command, on page 2-2 end command, on page 2-2 exit command, on page 2-3 help command, on page 2-3 history command, on page 2-4...
  • Page 351 Configuration - L2TPC Mode Use the end command to exit the current configuration mode, and must be used to mark the end of any configuration file. This command can be entered in any configuration mode with the same result. Syntax: (config-l2tpc-{n})# end Example: (config-l2tpc-1)# end...
  • Page 352 Configuration - L2TPC Mode history Use the history command to display commands that have been entered in this session. This command can be entered in any configuration mode. Syntax: (config-l2tpc-{n})# history Example: (config-l2tpc-1)# history firewall enable exit host-ip 192.168.1.10 ip default-route enable ip rip enable ip rip send-version none ip primary-dns 192.168.2.10...
  • Page 353 Configuration - L2TPC Mode ip address Use the L2TPC ip address command to configure the IP address for the port. To remove an IP address, see no ip address command on page 15-13. Syntax: (config-l2tpc-{n})# ip address {address mask mask|auto |unnumbered} [secondary] Field Definition...
  • Page 354 Configuration - L2TPC Mode ip ospf authentication Use the L2TPC ip ospf authentication command to enable the authentication method (either message- digest or simple authentication) for this interface. To remove the authentication type for this interface set the parameter to null or see no ip ospf authentication command on page 15-14. Note: If an optional parameter is not entered, the authentication method of simple authentication is applied to the interface.
  • Page 355 Configuration - L2TPC Mode ip ospf authentication-key Use the L2TPC ip ospf authentication-key command to assign a password to be used by neighboring routers, that are using OSPF’s simple password authentication.To remove a previously assigned password, see no ip ospf authentication-key command on page 15-14. Syntax: (config-l2tpc-{n})# ip ospf authentication-key password Field...
  • Page 356 Configuration - L2TPC Mode ip ospf disable Use the L2TPC ip ospf disable command to disable OSPF processing on this interface. To enable OSPF on this interface, see no ip ospf disable command on page 15-15. Syntax: (config-l2tpc-{n})# ip ospf disable all Example: (config-l2tpc-1)# ip ospf disable all Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 357 Configuration - L2TPC Mode ip ospf priority Use the L2TPC ip ospf priority command to set the router priority, which determines the designated router for this network. To restore the default setting of priority 1, see no ip ospf priority command on page 15-16.
  • Page 358 Configuration - L2TPC Mode ip primary-dns Use the L2TPC ip primary-dns command to configure the primary DNS. To delete a primary DNS, see no ip primary-dns command on page 15-17. Syntax: (config-l2tpc-{n})# ip primary-dns address Field Definition address Enter the IP address of the primary server. Example: (config-l2tpc-1)# ip primary-dns 192.168.2.100 Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 359 Configuration - L2TPC Mode ip rip send-version Use the L2TPC ip rip send-version command to configure the send RIP messages on this interface. Syntax: (config-l2tpc-{n})# ip rip send-version {1|2-bcast|2-mcast |none} Field Definition Send RIP version 1. 2-bcast Send RIP version 2 - Broadcast. 2-mcast Send RIP version 2 - Multicast.
  • Page 360 Configuration - L2TPC Mode ip route-mode Use the L2TPC ip route-mode command to configure the routing mode. Syntax: (config-l2tpc-{n})# ip route-mode {napt|route} Field Definition napt Set to NAPT mode. Default. NAPT is used if doing private IPs on the Ethernet side or if you want to hide specific publics on the internal side.
  • Page 361 Configuration - L2TPC Mode metric Use the L2TPC metric command to configure the Metric of the IP network on this interface Syntax: (config-l2tpc-{n})# metric metric Field Definition metric Range is 0-255, with a default is 10. Example: (config-l2tpc-1)# metric 150 Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: no commands...
  • Page 362 Configuration - L2TPC Mode no ip default-route Use the L2TPC no ip default-route command to disable the default route. To set the default IP address, see ip default-route command on page 15-5. Syntax: (config-l2tpc-{n})# no ip default-route Example: (config-l2tpc-1)# no ip default-route Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: no ip ospf authentication...
  • Page 363 Configuration - L2TPC Mode no ip ospf dead-interval Use the L2TPC no ip ospf dead-interval command to reset the interval of time to the default setting of 40 seconds. To define the interval of time that no hello packets have been seen before neighbors declare the router down, see ip ospf dead-interval command on page 15-7.
  • Page 364 Configuration - L2TPC Mode no ip ospf message-digest-key Use the L2TPC no ip ospf message-digest-key command to remove an old MD5 key. To enable OSPF MD5 (Message-Digest) authentication, see ip ospf message-digest-key command on page 15-8. Syntax: (config-l2tpc-{n})# no ip ospf message-digest-key key-id Field Definition key-id...
  • Page 365 Configuration - L2TPC Mode no ip ospf transmit-delay Use the L2TPC no ip ospf transmit-delay command to restore the default value of 1 second. To define the estimated time to transmit a link state update packet on the interface, see ip ospf transmit- delay command on page 15-9.
  • Page 366 Configuration - L2TPC Mode no ip secondary-dns Use the L2TPC no secondary-dns command to disable the secondary DNS. To enable the secondary DNS, see ip secondary-dns command on page 15-12. Syntax: (config-l2tpc-{n})# no ip secondary-dns Example: (config-l2tpc-1)# no ip secondary-dns Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: no ppp authentication...
  • Page 367 Configuration - L2TPC Mode no ppp exec-timeout Use the L2TPC no ppp exec-timeout command to disable PPP idle time. To set the PPP maximum idle time before hangup, see ppp exec-timeout command on page 15-22. Syntax: (config-l2tpc-{n})# no ppp exec-timeout Example: (config-l2tpc-1)# no ppp exec-timeout Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 368 Configuration - L2TPC Mode no ppp time-btwn-reconnect Use the L2TPC no ppp time-btwn-reconnect command to reset this time to the default settings. To set the interval between reconnect attempts, see ppp time-btwn-reconnect command on page 15-23. Syntax: (config-l2tpc-{n})# no ppp time-btwn-reconnect Example: (config-l2tpc-1)# no ppp time-btwn-reconnect Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 369 Configuration - L2TPC Mode no sip-alg Use the L2TPC no sip-alg command to disable SIP ALG on this interface. To enable SIP ALG, see sip-alg command on page 15-24. Syntax: (config-l2tpc-{n})# no sip-alg Example: (config-l2tpc-1)# no sip-alg Adit 3104, Adit 3500, MSR Supported Platforms: ppp authentication Use the L2TPC ppp authentication command to configure the support of authentication types for the...
  • Page 370 Configuration - L2TPC Mode ppp exec-timeout Use the L2TPC ppp exec-timeout command to set the PPP maximum idle time before hangup.To disable PPP idle time, see no ppp exec-timeout command on page 15-19. Syntax: (config-l2tpc-{n})# ppp exec-timeout minutes Field Definition minutes Range is 0 - 99999 minutes.
  • Page 371 Configuration - L2TPC Mode ppp restart-timer Use the L2TPC ppp restart-timer command to configure the PPP restart timer. To set the restart timer to the default setting, see no ppp restart-timer command on page 15-19. Syntax: (config-l2tpc-{n})# ppp restart-timer seconds Field Definition seconds...
  • Page 372 Configuration - L2TPC Mode schedule-availability Use the L2TPC schedule-availability command to apply a schedule rule to this interface. To delete a schedule, see no schedule-availability command on page 15-20. Syntax: (config-l2tpc-{n})# schedule-availability time-range schedule- Field Definition schedule-id Enter an existing schedule rule name. See time-range command on page 4-64 to set the schedule-id Example: (config-l2tpc-1)# schedule-availability time-range 1...
  • Page 373 HAPTER Configuration - OSPF Mode The Router OSPF Configuration commands allow the user to configure the OSPF parameters. OSPF (Open Shortest Path First) is a protocol based on the link-states of routers within a network. OSPF supports hierarchical routing by segmenting a larger network into smaller more manageable networks called areas.
  • Page 374: Area Commands

    Configuration - OSPF Mode area commands Note: For the following area commands, the first command that enters the area ID will set this parameter. The no area command will remove a specific area from the configuration. See the no area command on page 16-7.
  • Page 375: Compatible Rfc1583

    Configuration - OSPF Mode compatible rfc1583 Use the Router OSPF compatible rfc1583 command to restore the method used to calculate summary route costs per RFC 1583. To disable RFC 1583 compatibility, see the no compatible rfc1583 command on page 16-8. Syntax: (config-ospf)# compatible rfc1583 Example:...
  • Page 376 Configuration - OSPF Mode Use the do commands to run User and Privileged mode commands. The following are links to the User and Privileged do commands. User Mode Commands date command, on page 2-2 enable command, on page 2-2 end command, on page 2-2 exit command, on page 2-3 help command, on page 2-3 history command, on page 2-4...
  • Page 377: Exit

    Configuration - OSPF Mode Use the end command to exit the current configuration mode, and must be used to mark the end of any configuration file. This command can be entered in any configuration mode with the same result. Syntax: (config-ospf)# end Example: (config-ospf)# end...
  • Page 378: Network Area

    Configuration - OSPF Mode network area Use the Router OSPF network area command to define the interfaces on which OSPF will run and set the ID for those interfaces. To disable OSPF routing for the interface defined, see no network area command on page 16-8.
  • Page 379: No Commands

    Configuration - OSPF Mode no commands no area Use the Router OSPF no area command to remove a specific area from the OSPF configuration. To set an area, see the area commands command on page 16-2, or area stub command on page 16-2, the first use of either command will set the area.
  • Page 380 Configuration - OSPF Mode no area stub Use the Router OSPF no area stub command to remove the definition of an area as a Stub area. See the area stub command on page 16-2 for the counterpart of this command. Syntax: (config-ospf)# no area area-id stub Field...
  • Page 381: Router-Id

    Configuration - OSPF Mode no router-id Use the Router OSPF no router-id command to force OSPF to use the previous OSPF router ID behavior. To use a fixed router ID, see router-id command on page 16-9. Syntax: (config-ospf)# no router-id Example: (router-ospf)# no router-id Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 382: Sample Configuration

    Configuration - OSPF Mode Sample Configuration Sample Configuration ospf router ospf no compatible rfc1583 router-id 192.168.3.251 network 192.168.3.0 0.0.0.255 area 0.0.0.1 interface ethernet 1 ip address 192.168.2.251 mask 255.255.255.0 description Ethernet 1 ip mtu auto no tos ip tos ip value 0x0 ip default-gateway 0.0.0.0 no ip dhcp auto-provision no ip primary-dns...
  • Page 383 Configuration - OSPF Mode Sample Configuration ip ospf priority 2 exit interface ethernet 2 ip address 192.168.3.251 mask 255.255.255.0 description Ethernet 2 ip mtu auto ip default-gateway 192.168.3.1 ip dhcp auto-provision no ip primary-dns no ip secondary-dns ip route-mode route ip default-route enable no ip proxy-arp no ip rip...
  • Page 384 Configuration - OSPF Mode Sample Configuration 16-12 Adit 3000 (Rel. 1.6) and MSR Card (Rel 2.1) CLI...
  • Page 385 HAPTER Configuration - PPTPC Mode The PPTPC Configuration commands allow the user to configure the VPN (Virtual Private Network) Point-to-Point Tunneling Protocol Client parameters. Enter this sub-group with the (config)# pptpc command from the Configuration mode. The VPN PPTPC commands are represented by the (config-pptpc-n)# prompt. PPTP Client Commands •...
  • Page 386 Configuration - PPTPC Mode Use the do commands to run User and Privileged mode commands. The following are links to the User and Privileged do commands. User Mode Commands date command, on page 2-2 enable command, on page 2-2 end command, on page 2-2 exit command, on page 2-3 help command, on page 2-3 history command, on page 2-4...
  • Page 387 Configuration - PPTPC Mode Use the end command to exit the current configuration mode, and must be used to mark the end of any configuration file. This command can be entered in any configuration mode with the same result. Syntax: (config-pptpc-{n})# end Example: (config-pptpc-1)# end...
  • Page 388 Configuration - PPTPC Mode history Use the history command to display commands that have been entered in this session. This command can be entered in any configuration mode. Syntax: (config-pptpc-{n})# history Example: (config-pptpc-1)# history history ip mtu aut ip rip enable ip rip receive-version 1or2 ip route-mode route metric 3...
  • Page 389 Configuration - PPTPC Mode ip address Use the PPTP Client ip address command to configure the IP address for the port. To remove an IP address, see no ip address command on page 17-13. Syntax: (config-pptpc-{n})# ip address {address mask mask|auto |unnumbered} [secondary] Field Definition...
  • Page 390 Configuration - PPTPC Mode ip ospf authentication Use the PPTP Client ip ospf authentication command to enable the authentication method (either message-digest or simple authentication) for this interface. To remove the authentication type for this interface set the parameter to null or see no ip ospf authentication command on page 17-13. Note: If an optional parameter is not entered, the authentication method of simple authentication is applied to the interface.
  • Page 391 Configuration - PPTPC Mode ip ospf authentication-key Use the PPTP Client ip ospf authentication-key command to assign a password to be used by neighboring routers, that are using OSPF’s simple password authentication.To remove a previously assigned password, see no ip ospf authentication-key command on page 17-14. Syntax: (config-pptpc-{n})# ip ospf authentication-key password Field...
  • Page 392 Configuration - PPTPC Mode ip ospf disable Use the PPTP Client ip ospf disable command to disable OSPF processing on this interface. To enable OSPF on this interface, see no ip ospf disable command on page 17-14. Syntax: (config-pptpc-{n})# ip ospf disable all Example: (config-pptpc-1)# ip ospf disable all Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 393 Configuration - PPTPC Mode ip ospf priority Use the PPTP Client ip ospf priority command to set the router priority, which determines the designated router for this network. To restore the default setting of priority 1, see no ip ospf priority command on page 17-15.
  • Page 394 Configuration - PPTPC Mode ip primary-dns Use the PPTP Client ip primary-dns command to configure the primary DNS. To delete a primary DNS, see no ip primary-dns command on page 17-16. Syntax: (config-pptpc-{n})# ip primary-dns address Field Definition address Enter the IP address of the primary server. Example: (config-pptpc-1)# ip primary-dns 192.168.2.100 Adit 3104, Adit 3200, Adit 3500, MSR...
  • Page 395 Configuration - PPTPC Mode ip rip send-version Use the PPTP Client ip rip send-version command to configure the send RIP messages on this interface. Syntax: (config-pptpc-{n})# ip rip send-version {1|2-bcast|2-mcast |none} Field Definition Send RIP version 1. 2-bcast Send RIP version 2 - Broadcast. 2-mcast Send RIP version 2 - Multicast.
  • Page 396 Configuration - PPTPC Mode ip route-mode Use the PPTP Client ip route-mode command to configure the routing mode. Syntax: (config-pptpc-{n})# ip route-mode {napt|route} Field Definition napt Set to NAPT mode. Default. NAPT is used if doing private IPs on the Ethernet side or if you want to hide specific publics on the internal side.
  • Page 397 Configuration - PPTPC Mode no commands no firewall Use the PPTP Client no firewall command to disable the configured firewall. To enable the firewall, see firewall command on page 17-3. Syntax: (config-pptpc-{n})# no firewall Example: (config-pptpc-1)# no firewall Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: no ip address Use the PPTP Client no ip address command to remove the IP address assigned to the port.
  • Page 398 Configuration - PPTPC Mode no ip ospf authentication-key Use the PPTP Client no ip ospf authentication-key command to remove a password to be used by neighboring routers, that are using OSPF’s simple password authentication.To assign a password, see ip ospf authentication-key command on page 17-7. Syntax: (config-pptpc-{n})# no ip ospf authentication-key Example:...
  • Page 399 Configuration - PPTPC Mode no ip ospf hello-interval Use the PPTP Client no ip ospf hello-interval command to reset the interval of time to the default setting of 10 seconds. To define the interval of time between hello packets sent on the interface, see ip ospf hello-interval command on page 17-8.
  • Page 400 Configuration - PPTPC Mode no ip ospf retransmit-interval Use the PPTP Client ip ospf retransmit-interval command to restore the default value of 5 seconds. To define the interval of time between link state advertisement retransmissions for adjacencies belonging to the interface, see ip ospf retransmit-interval command on page 17-9. Syntax: (config-pptpc-{n})# no ip ospf retransmit-interval Example:...
  • Page 401 Configuration - PPTPC Mode no ip route Use the PPTP Client no ip route command remove an IP route. To add a route, see ip route command on page 17-11. Syntax: (config-pptpc-{n})# no ip route dest-ip-addr gateway Field Definition dest-ip-addr Enter destination IP address to remove.
  • Page 402 Configuration - PPTPC Mode no ppp encryption Use the PPTP Client no ppp encryption command to disable PPP encryption. To enable PPP encryption, see ppp encryption command on page 17-21. Syntax: (config-pptpc-{n})# no ppp encryption [128-bit|40- bit|required|stateful] Field Definition Specifying the command without parameters d <CR>...
  • Page 403 Configuration - PPTPC Mode no ppp password Use the PPTP Client no ppp password command to remove the PPP password. To set the PPP password, see ppp password command on page 17-22. Syntax: (config-pptpc-{n})# no ppp password Example: (config-pptpc-1)# no ppp password Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: no ppp restart-timer...
  • Page 404 Configuration - PPTPC Mode no schedule-availability Use the PPTP Client no schedule-availability command to disable a schedule rule. To add a rule, see schedule-availability command on page 17-24. Syntax: (config-pptpc-{n})# no schedule-availability Example: (config-pptpc-1)# no schedule-availability Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: no shutdown Use the PPTP Client no shutdown command to set the interface up...
  • Page 405 Configuration - PPTPC Mode ppp authentication Use the PPTP Client ppp authentication command to configure the support of authentication types for the password. To disable PPP authentication, see no ppp authentication command on page 17-17. Syntax: (config-pptpc-{n})# ppp authentication {chap|ms-chap| ms-chapv2|pap} Field Definition...
  • Page 406 Configuration - PPTPC Mode ppp exec-timeout Use the PPTP Client ppp exec-timeout command to set the PPP maximum idle time before hangup.To disable PPP idle time, see no ppp exec-timeout command on page 17-18. Syntax: (config-pptpc-{n})# ppp exec-timeout minutes Field Definition minutes Range is 0 - 99999 minutes.
  • Page 407 Configuration - PPTPC Mode ppp restart-timer Use the PPTP Client ppp restart-timer command to configure the PPP restart timer. To reset to the default setting, see no ppp restart-timer command on page 17-19. Syntax: (config-pptpc-{n})# ppp restart-timer seconds Field Definition seconds Range is 1 - 65535 seconds.
  • Page 408 Configuration - PPTPC Mode schedule-availability Use the PPTP Client schedule-availability command to apply a schedule rule to this interface. To delete a schedule, see no schedule-availability command on page 17-20. Syntax: (config-pptpc-{n})# schedule-availability time-range schedule- Field Definition schedule-id Enter an existing schedule rule name. See time-range command on page 4-64 to set the schedule-id Example: (config-pptpc-1)# schedule-availability time-range 1...
  • Page 409 HAPTER Configuration - PPTPS Mode The PPTP Server Configuration commands allow the user to configure the VPN (Virtual Private Network) Point-to Point Tunneling Protocol Server parameters. Enter this sub-group with the (config)# pptps command from the Configuration mode. The VPN PPTP Server commands are represented by the (config-pptps)# prompt. PPTP Server Commands •...
  • Page 410 Configuration - PPTPS Mode Use the do commands to run User and Privileged mode commands. The following are links to the User and Privileged do commands. User Mode Commands date command, on page 2-2 enable command, on page 2-2 end command, on page 2-2 exit command, on page 2-3 help command, on page 2-3 history command, on page 2-4...
  • Page 411 Configuration - PPTPS Mode Use the end command to exit the current configuration mode, and must be used to mark the end of any configuration file. This command can be entered in any configuration mode with the same result. Syntax: (config-pptps)# end Example: (config-pptps)# end...
  • Page 412 Configuration - PPTPS Mode history Use the history command to display commands that have been entered in this session. This command can be entered in any configuration mode. Syntax: (config-pptps)# history Example: (config-pptps)# history end-address 192.168.1.175 ppp encryption ppp authentication pap idle-time 99999 start-address 192.168.1.1 history...
  • Page 413 Configuration - PPTPS Mode no commands no idle-time Use the PPTP Server no idle-time command to reset the idle time to the default setting. To set the maximum idle time for a PPTP connection, see idle-time command on page 18-4. Syntax: (config-pptps)# no idle-time Example:...
  • Page 414 Configuration - PPTPS Mode no ppp encryption Use the PPTP Server no ppp encryption command to disable PPP encryption. To enable PPP encryption, see ppp encryption command on page 18-7. Syntax: (config-pptps)# no ppp encryption [128-bit|40- bit|required|stateful] Field Definition Specifying the command without parameters d <CR>...
  • Page 415 Configuration - PPTPS Mode ppp authentication Use the PPTP Server ppp authentication command to configure the support of authentication types for the password. To disable PPP authentication, see no ppp authentication command on page 18-5. Syntax: (config-pptps)# ppp authentication [chap|ms-chap|ms-chapv2|pap] Field Definition chap...
  • Page 416 Configuration - PPTPS Mode shutdown Use the PPTP Server shutdown command to set the admin state of the server down (out-of-service). To set the admin state up (in-service), see no shutdown command on page 18-6. Syntax: (config-pptps)# shutdown Example: (config-pptps)# shutdown Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: start-address...
  • Page 417: Radius Commands

    HAPTER Configuration - RADIUS Mode The RADIUS Configuration commands allow the user to configure the RADIUS parameters for each interface. This sub-group is entered with the (config)# radius-client command from the Configuration mode. The RADIUS commands are represented by the (config-radius)# prompt. RADIUS Commands •...
  • Page 418 Configuration - RADIUS Mode authentication Use the RADIUS authentication command to set the RADIUS client authentication method. Syntax: (config-radius)# authentication {chap|ms-chap|ms-chapv2|pap} Field Definition chap CHAP - Challenge Handshake Authentication ms-chap MS-CHAP - Microsoft CHAP ms-chapv2 MS-CHAPv2 - Microsoft CHAP Version 2 PAP - Unencrypted Password.
  • Page 419 Configuration - RADIUS Mode Use the do commands to run User and Privileged mode commands. The following are links to the User and Privileged do commands. User Mode Commands date command, on page 2-2 enable command, on page 2-2 end command, on page 2-2 exit command, on page 2-3 help command, on page 2-3 history command, on page 2-4...
  • Page 420: Exit

    Configuration - RADIUS Mode Use the end command to exit the current configuration mode, and must be used to mark the end of any configuration file. This command can be entered in any configuration mode with the same result. Syntax: (config-radius)# end Example: (config-radius)# end...
  • Page 421 Configuration - RADIUS Mode host Use the RADIUS host command to set the RADIUS server IP address on the system. Syntax: (config-radius)# host address auth-port port Field Definition address Enter the IP address of the RADIUS server. port Enter the port number to use for RADIUS authentication. Range is 0 - 65535 with a default of 1812.
  • Page 422 Configuration - RADIUS Mode 19-6 Adit 3000 (Rel. 1.6) and MSR Card (Rel 2.1) CLI...
  • Page 423: No Commands

    HAPTER Configuration - VLAN Mode The VLAN Configuration commands allow the user to configure the global VLAN parameters. This sub-group is entered with the (config)# vlan command from the Configuration mode. The global VLAN commands are represented by the (config-vlan)# prompt. VLAN (Global) Commands •...
  • Page 424 Configuration - VLAN Mode Use the do commands to run User and Privileged mode commands. The following are links to the User and Privileged do commands. User Mode Commands date command, on page 2-2 enable command, on page 2-2 end command, on page 2-2 exit command, on page 2-3 help command, on page 2-3 history command, on page 2-4...
  • Page 425 Configuration - VLAN Mode Use the end command to exit the current configuration mode, and must be used to mark the end of any configuration file. This command can be entered in any configuration mode with the same result. Syntax: (config-vlan)# end Example: (config-vlan)# end...
  • Page 426 Configuration - VLAN Mode no commands no port-dot1q Use the VLAN no port-dot1q command to disable dot1q tagging for the port. By default, VLAN tagging is disabled on a LAN port. In this default state, if the port receives a VLAN tagged frame, it will ignore the VLAN header and will process the ingress frames as a regular Ethernet frame.
  • Page 427 Configuration - VLAN Mode port-dot1q Use the VLAN port-dot1q command to enable dot1q tagging for the port. If VLAN tagging is enabled on a port, the port will forward any untagged or priority tagged frames with a VID equal to the ingress port’s PVID and the priority of the tagged frame will remain unchanged.
  • Page 428 Configuration - VLAN Mode port-protocol-filter Use the VLAN port-protocol-filter command to enable VLAN filtering for the port. Note: The vlan-feature command, on page 20-7, must be executed before this command. Syntax: (config-vlan)# port-protocol-filter {disable|enable} ethernet port Field Definition disable Disable VLAN filtering on defined Ethernet port. enable Enable VLAN filtering on defined Ethernet port.
  • Page 429 Configuration - VLAN Mode tag-all Use the VLAN tag-all command to enable dot1q tagging for all ports. If VLAN tagging is enabled on all ports, an ingress port should forward any untagged or priority tagged frames with a VID equal to the ingress port’s PVID and set the priority of the untagged frame to that of the ingress port.
  • Page 430 Configuration - VLAN Mode 20-8 Adit 3000 (Rel. 1.6) and MSR Card (Rel 2.1) CLI...
  • Page 431: Voip-Interface

    HAPTER Configuration - VLAN Port Mode The VLAN Port Configuration commands allow the user to configure the VLAN port parameters. This sub-group is entered with the (config)# vlan {vlan-id} command from the Configuration mode. The VLAN Port commands are represented by the (config-vlan-{n})# prompt. VLAN (Port) Commands •...
  • Page 432 Configuration - VLAN Port Mode Use the do commands to run User and Privileged mode commands. The following are links to the User and Privileged do commands. User Mode Commands date command, on page 2-2 enable command, on page 2-2 end command, on page 2-2 exit command, on page 2-3 help command, on page 2-3...
  • Page 433 Configuration - VLAN Port Mode Use the end command to exit the current configuration mode, and must be used to mark the end of any configuration file. This command can be entered in any configuration mode with the same result. Syntax: (config-vlan-{n})# end Example:...
  • Page 434 Configuration - VLAN Port Mode no commands no port Use the VLAN no port command to remove this port’s membership from the VLAN. To set the preferences, see port command on page 21-4. Syntax: (config-vlan-{n})# no port ethernet port Field Definition port Ethernet port in the form {port}.{sub-interface}.
  • Page 435 Configuration - VLAN Port Mode priority Use the VLAN priority command to set the VLAN priority level. Syntax: (config-vlan-{n})# priority priority Field Definition priority Set priority level. Range = 0 - 7. Example: (config-vlan-100)# priority 0 Adit 3104, Adit 3200, Adit 3500, MSR Supported Platforms: voip-interface Use the VLAN voip-interface command to set the VLAN tagging for the originating VoIP traffic.
  • Page 436 Configuration - VLAN Port Mode 21-6 Adit 3000 (Rel. 1.6) and MSR Card (Rel 2.1) CLI...
  • Page 437: Digit-Map (Global)

    HAPTER Configuration - Voice Port Mode The Voice Port Configuration commands allow the user to configure the Voice Port parameters. Enter this sub-group with the (config)# voice-port command from the Configuration mode. The Voice Port commands are represented by the (config-vport)# prompt. Note: There are two additional Voice Port groups (FXS-Chapter 23 and Trunk-Chapter 24), please see their respective chapters for information.
  • Page 438 Configuration - Voice Port Mode digit-map (global) Use the Voice Port digit-map global command to configure the Digit Map on a global level. To disable digit map, see no digit-map (global) command on page 22-5. Syntax: (config-vport)# digit-map mode {long-timeout seconds |pattern number pattern |short-timeout seconds} Field Definition...
  • Page 439: Exit

    Configuration - Voice Port Mode Use the do commands to run User and Privileged mode commands. The following are links to the User and Privileged do commands. User Mode Commands date command, on page 2-2 enable command, on page 2-2 end command, on page 2-2 exit command, on page 2-3 help command, on page 2-3...
  • Page 440 Configuration - Voice Port Mode Use the end command to exit the current configuration mode, and must be used to mark the end of any configuration file. This command can be entered in any configuration mode with the same result. Syntax: (config-vport)# end Example:...
  • Page 441: No Digit-Map (Global)

    Configuration - Voice Port Mode no digit-map (global) Use the Voice Port no digit-map command to remove a digit map pattern. To configure digit map, see digit-map (global) command on page 22-2. Syntax: (config-vport)# no digit-map pattern number Field Definition pattern number Enter pattern number to remove.
  • Page 442 Configuration - Voice Port Mode 22-6 Adit 3000 (Rel. 1.6) and MSR Card (Rel 2.1) CLI...
  • Page 443: Output-Gain

    HAPTER Configuration - Voice Port FXS Mode The Voice Port FXS Configuration commands allow the user to configure the Voice Port FXS parameters. Enter this sub-group with the (config)# voice-port fxs number command from the Configuration mode. The Voice Port FXS commands are represented by the (config-vport-fxs-{n})# prompt. Voice Port FXS Commands •...
  • Page 444 Configuration - Voice Port FXS Mode comfort-noise Use the Voice Port FXS comfort-noise command to enable the comfort noise feature. To disable comfort noise, see no comfort-noise command on page 23-6. Syntax: (config-vport-fxs-{n})# comfort-noise enable Example: (config-vport-fxs-1)# comfort-noise enable Adit 3104, Adit 3500, MSR Supported Platforms: description Use the Voice Port FXS description command to change the description of the voice port.
  • Page 445 Configuration - Voice Port FXS Mode Use the do commands to run User and Privileged mode commands. The following are links to the User and Privileged do commands. User Mode Commands date command, on page 2-2 enable command, on page 2-2 end command, on page 2-2 exit command, on page 2-3 help command, on page 2-3...
  • Page 446 Configuration - Voice Port FXS Mode echo-cancel Use the Voice Port FXS echo-cancel command to enable echo cancellation on this port. To disable echo cancellation, see the no echo-cancel command on page 23-6. NOTE: Normal Fax calls may fail if echo cancellation is disabled for an FXS line. Typically, echo cancellation should be enabled unless the line is used exclusively for modem calls or high-speed super-G3 Fax calls.
  • Page 447 Configuration - Voice Port FXS Mode history Use the history command to display commands that have been entered in this session. Syntax: (config-vport-fxs-{n})# history Example: (config-vport-fxs-1)# history description tests echo-cancel enable input-gain 4 output-gain 4 signal ground-start history Adit 3104, Adit 3500, MSR Supported Platforms: input-gain Use the Voice Port FXS input-gain command to set the gain on the receive side voice path for the...
  • Page 448 Configuration - Voice Port FXS Mode no commands no comfort-noise Use the Voice Port FXS no comfort-noise command to disable comfort noise. To enable remote access, see comfort-noise command on page 23-2. Syntax: (config-vport-fxs-{n})# no comfort-noise Example: (config-vport-fxs-1)# no comfort-noise Adit 3104, Adit 3500, MSR Supported Platforms: no echo-cancel...
  • Page 449 Configuration - Voice Port FXS Mode no shutdown Use the Voice Port FXS no shutdown command to set this voice port up (In-Service). To set this port down (Out-of-Service), see shutdown command on page 23-8. Syntax: (config-vport-fxs-{n})# no shutdown Example: (config-vport-fxs-1)# no shutdown Adit 3104, Adit 3500, MSR Supported Platforms:...
  • Page 450 Configuration - Voice Port FXS Mode shutdown Use the Voice Port FXS shutdown command to set this port down (Out-of-Service). To set this voice port up (In-Service), see no shutdown command on page 23-7. Syntax: (config-vport-fxs-{n})# shutdown Example: (config-vport-fxs-1)# shutdown Adit 3104, Adit 3500, MSR Supported Platforms: signal...
  • Page 451 HAPTER Configuration - Voice Port Trunk Mode The Voice Port Trunk Configuration commands allow the user to configure the Voice Port Trunk parameters. Enter this sub-group with the (config)# voice-port trunk number command from the Configuration mode. Note: The Trunk option is not supported on the Adit 3104 or the Adit 3200. The Voice Port Trunk commands are represented by the (config-vport-trk-{n})# prompt.
  • Page 452: Channel-Hunt

    Configuration - Voice Port Trunk Mode channel-hunt Use the Voice Port Trunk channel-hunt command to set the channel hunt scheme for finding an available (non-busy) trunk-group channel on incoming SIP-to-PRI/CAS calls. Note: The hunt sequence for the Adit 3500 is Ascending and is not configurable. Syntax: (config-vport-trk-{n})# channel-hunt {ascending|descending| round-robin}...
  • Page 453: Connection Lcc

    Configuration - Voice Port Trunk Mode connection lcc Use the Voice Port Trunk connection lcc command to connect an MSR Link Cross Connect (LCC). To disconnect this connection, see the no connection lcc command on page 24-9. Syntax: (config-vport-trk-{n})# connection lcc number Field Definition number...
  • Page 454: Digit-Map

    Configuration - Voice Port Trunk Mode digit-map Use the Voice Port Trunk digit-map command to configure the Digit Map on the trunk level. To disable digit map, see no digit-map command on page 24-10. Syntax: (config-vport-trk-{n})# digit-map mode {default|custom} Field Definition default Pass dialed number as a complete number for routing to the phone...
  • Page 455 Configuration - Voice Port Trunk Mode Use the do commands to run User and Privileged mode commands. The following are links to the User and Privileged do commands. User Mode Commands date command, on page 2-2 enable command, on page 2-2 end command, on page 2-2 exit command, on page 2-3 help command, on page 2-3...
  • Page 456: Echo-Cancel

    Configuration - Voice Port Trunk Mode echo-cancel Use the Voice Port Trunk echo-cancel command to enable echo cancellation on this trunk. To disable echo cancellation, see no echo-cancel command on page 24-10. NOTE: Normal Fax calls may fail if echo cancellation is disabled. Typically, echo cancellation should be enabled unless the line is used exclusively for modem calls or high-speed super-G3 Fax calls.
  • Page 457: History

    Configuration - Voice Port Trunk Mode history Use the history command to display commands that have been entered in this session. Syntax: (config-vport-trk-1)# history Example: (config-vport-trk-1)# history exit description VoiceP-#1 digit-map mode custom history Adit 3500, MSR Supported Platforms: input-gain Use the Voice Port Trunk input-gain command to set the gain on the receive side voice path for the specified voice channel(s).
  • Page 458: Isdn Switch-Type (Pri)

    Configuration - Voice Port Trunk Mode isdn switch-type (PRI) Use the Voice Port Trunk isdn switch-type command to configure the switching type (protocol) on this trunk. Syntax: (config-vport-trk-{n})# isdn switch-type {pri-dms100|pri-4ess |pri-5ess|pri-ni2} Field Definition pri-4ess PRI-4ess - The class 4 US AT&T proprietary version of ISDN. pri-5ess PRI-5ess - The class 5 ISDN central office circuit switching system developed by AT&T...
  • Page 459: No Commands

    Configuration - Voice Port Trunk Mode no commands no comfort-noise Use the Voice Port Trunk no comfort-noise command to disable comfort noise. To enable remote access, see comfort-noise command on page 24-2. Syntax: (config-vport-trk-{n})# no comfort-noise Example: (config-vport-trk-1)# no comfort-noise Adit 3500, MSR Supported Platforms: no connection lcc...
  • Page 460 Configuration - Voice Port Trunk Mode no digit-map Use the Voice Port Trunk no digit-map command to disable digit map on the trunk. To configure digit map, see digit-map command on page 24-4. Syntax: (config-vport-trk-{n})# no digit-map Example: (config-vport-trk-1)# no digit-map Adit 3500, MSR Supported Platforms: no echo-cancel...
  • Page 461 Configuration - Voice Port Trunk Mode no registration line Use the Voice Port Trunk no registration line command remove a registration line. To add a registration line, see registration line enable command on page 24-13. Syntax: (config-vport-trk-{n})# no registration line number Field Definition number...
  • Page 462: Output-Gain

    Configuration - Voice Port Trunk Mode output-gain Use the Voice Port Trunk output-gain command to gain on the transmit side voice path for the set the specified voice channel(s). Syntax: (config-vport-trk-{n})# output-gain value Field Definition value Range -12 to +6dB. Default is 0. Example: (config-vport-trk-1)# output-gain 6 Adit 3500, MSR...
  • Page 463 Configuration - Voice Port Trunk Mode registration line authentication Use the Voice Port Trunk registration line authentication command to configure the username to authenticate. Syntax: (config-vport-trk-{n})# registration line value line-numbers value authentication {phone-number|username username} password password Field Definition line value Enter the PBX line number to configure.
  • Page 464 Configuration - Voice Port Trunk Mode registration line first-phone-number Use the Voice Port Trunk registration line first-phone-number command to define the first number in a block that will be registered. Syntax: (config-vport-trk-{n})# registration line value line-numbers value first-phone-number phone-number description description Field Definition line value...
  • Page 465: Signal

    Configuration - Voice Port Trunk Mode signal Use the Voice Port Trunk signal command to configure the trunk signal type for a CAS trunk. Syntax: (config-vport-trk-{n})# signal {delay-dial|immediate| wink-start} Field Definition delay-dial Set the trunk to CAS Delay Dial signaling. immediate Set the trunk to CAS Immediate Start signaling.
  • Page 466 Configuration - Voice Port Trunk Mode 24-16 Adit 3000 (Rel. 1.6) and MSR Card (Rel 2.1) CLI...
  • Page 467 HAPTER Configuration - Voice Service SIP Mode The Voice Service SIP Configuration commands allow the user to configure the Voice Trunk SIP parameters. Enter this sub-group with the (config)# voice-service sip command from the Configuration mode. The Voice Port commands are represented by the (config-voice-serv-sip)# prompt. Voice Service SIP Commands •...
  • Page 468: Calling-Party-Disc

    Configuration - Voice Service SIP Mode calling-party-disc Use the Voice Service SIP calling-party-disc command to configure the call party disconnect feature. Syntax: (config-voice-serv-sip)# calling-party-disc duration Field Definition duration Range 500 - 3000 ms. Example: (config-voice-serv-sip)# calling-party-disc 600 Adit 3104, Adit 3500, MSR Supported Platforms: conference Use the Voice Service SIP conference command to enable the conference calling feature.
  • Page 469 Configuration - Voice Service SIP Mode Use the do commands to run User and Privileged mode commands. The following are links to the User and Privileged do commands. User Mode Commands date command, on page 2-2 enable command, on page 2-2 end command, on page 2-2 exit command, on page 2-3 help command, on page 2-3...
  • Page 470: Dtmf

    Configuration - Voice Service SIP Mode dtmf Use the Voice Service SIP dtmf command to configure the DTMF events. Syntax: (config-voice-serv-sip)# dtmf {inband|rfc2833} Field Definition inband Configure the DTMF in-band, as part of the RTP packets. rfc2833 Configure the DTMF events out-of-band, as RTP event packets. Example: (config-voice-serv-sip)# dtmf inband Adit 3104, Adit 3500, MSR...
  • Page 471: Exit

    Configuration - Voice Service SIP Mode Use the end command to exit the current configuration mode, and must be used to mark the end of any configuration file. This command can be entered in any configuration mode with the same result. Syntax: (config-voice-serv-sip)# end Example:...
  • Page 472: Fax-Protocol-T38 Ecs

    Configuration - Voice Service SIP Mode fax-protocol-t38 ecs Use the Voice Service SIP fax-protocol-t38 ecs command to configure the fax Error Correction Scheme parameter. Syntax: (config-voice-serv-sip)# fax-protocol-t38 ecs {none|redundant} Example: (config-voice-serv-sip)# fax-protocol-t38 ecs redundant Syntax Descriptions: Variable Definition none Set error correction to none. redundant Set error correction to redundant.
  • Page 473: Fax-Protocol-T38 Signaling

    Configuration - Voice Service SIP Mode fax-protocol-t38 signaling Use the Voice Service SIP fax-protocol-t38 signaling command to configure fax signaling. Syntax: (config-voice-serv-sip)# fax-protocol-t38 signaling {nse-only|nse-preferred|sdp-only|sdp-preferred} Example: (config-voice-serv-sip)# fax-protocol-t38 signaling sdp-preferred Syntax Descriptions: Variable Definition nse-only Named Service Element (NSE) will be the only method tried without any attempt to try alternate signaling method to establish connection if it fails.
  • Page 474: Gateway-Ip

    Configuration - Voice Service SIP Mode gateway-ip Use the Voice Service SIP gateway-ip command to set the IP address to be used as the source IP for VoIP. Syntax: (config-voice-serv-sip)# gateway-ip address Field Definition address The IP address to be used as the source IP for VoIP services when it matches one of our up or running interfaces’...
  • Page 475: No Commands

    Configuration - Voice Service SIP Mode no commands no conference Use the Voice Service SIP no conference command to disable the conference feature. To enable conference, see conference command on page 25-2. Syntax: (config-voice-serv-sip)# no conference Example: (config-voice-serv-sip)# no conference Adit 3104, Adit 3500, MSR Supported Platforms: no outbound-proxy...
  • Page 476 Configuration - Voice Service SIP Mode no redundancy filter-incoming Use the Voice Service SIP no redundancy-filter-incoming command to disable the incoming redundancy filter. To enable filter, see redundancy filter-incoming command on page 25-14. Syntax: (config-voice-serv-sip)# no redundancy filter-incoming Example: (config-voice-serv-sip)# no redundancy filter-incoming Adit 3104, Adit 3500, MSR Supported Platforms: no redundancy rollback-timer...
  • Page 477: Outbound-Proxy

    Configuration - Voice Service SIP Mode outbound-proxy Use the Voice Service SIP outbound-proxy command to configure the SIP outbound proxy. To disable outbound proxy, see no outbound-proxy command on page 25-9. Syntax: (config-voice-serv-sip)# outbound-proxy {hostname hostname| ip-address address} Field Definition hostname Enter the host name of the outbound proxy.
  • Page 478: Privacy-Mode

    Configuration - Voice Service SIP Mode privacy-mode Use the Voice Service SIP privacy-mode command to configure the SIP privacy mode. Syntax: (config-voice-serv-sip)# privacy-mode {none|rfc3325} Field Definition none Disables the Privacy Mode. Default is None. rfc3325 Enables support for RFC 3325, as supported on the Sylantro Application Server.
  • Page 479: Proxy-Type

    Configuration - Voice Service SIP Mode proxy-type Use the Voice Service SIP proxy-type command to configure the SIP proxy type. Syntax: (config-voice-serv-sip)# proxy-type {broadsoft-info|generic| sylantro} Field Definition broadsoft-info Sets the SIP proxy type to BroadSoft. generic Sets the SIP proxy type to generic. sylantro Sets the SIP proxy type to Sylantro.
  • Page 480: Redundancy Advance-Timeout

    Configuration - Voice Service SIP Mode redundancy advance-timeout Use the Voice Service SIP redundancy advance-timeout command to set the interval of time before moving onto the next proxy, when the first is not reachable. Syntax: (config-voice-serv-sip)# redundancy advance-timeout number Field Definition number Range 0 - 10 seconds, with a default of 2.
  • Page 481: Redundancy Rollback-Timer

    Configuration - Voice Service SIP Mode redundancy rollback-timer Use the Voice Service SIP redundancy rollback-timer command to set the interval of time between the time the primary proxy fails, and when a rollback is performed back to the primary proxy. To disable rollback timer, see no redundancy rollback-timer command on page 25-10.
  • Page 482: Redundancy Ttl

    Configuration - Voice Service SIP Mode redundancy ttl Use the Voice Service SIP redundancy ttl command to set the set the SRV Time To Live (TTL) option. The TTL is a set interval of time between flushing the SRV cache. Syntax: (config-voice-serv-sip)# redundancy ttl seconds Field...
  • Page 483: Registration

    Configuration - Voice Service SIP Mode registration Use the Voice Service SIP registration command to configure the SIP registration, which allows trunk registration for each user of a PBX. To disable ignore negotiated registration timeout, see no registration ignore-negotiated command on page 25-10. Syntax: (config-voice-serv-sip)# registration {expire seconds| failed-time seconds|ignore-negotiated enable|rate value|...
  • Page 484: Session-Timer

    Configuration - Voice Service SIP Mode session-timer session-timer mode Use the Voice Service SIP session-timer mode command to configure the timer mode. To disable the timer mode, see no session-timer mode command on page 25-10. Syntax: (config-voice-serv-sip)# session-timer mode {requested|supported} Field Definition requested...
  • Page 485: Sip-Port

    Configuration - Voice Service SIP Mode session-timer timeout Use the Voice Service SIP session-timer timeout command to configure the interval of idle time to pass before timeout. Syntax: (config-voice-serv-sip)# session-timer timeout seconds Field Definition seconds Range 90 - 7200 seconds, with a default of 1800. Example: (config-voice-serv-sip)# session-timer timeout 2500 Adit 3104, Adit 3500, MSR...
  • Page 486 Configuration - Voice Service SIP Mode 25-20 Adit 3000 (Rel. 1.6) and MSR Card (Rel 2.1) CLI...
  • Page 487 NDEX Index radius ........4-56 vlan ........4-65 access lan .
  • Page 488 Index dmz-host .......4-40 dhcp pool ethernet ..... . 4-26 dynamic-dns .
  • Page 489 Index security-default ......4-59 call-wait-caller-id ......8-8 security-log .
  • Page 490 Index ip default-route ......11-7 renew ........11-23 ip dhcp .
  • Page 491 Index set-pfs ........14-19 transform-set ......14-20 authentication .
  • Page 492 Index retransmit-interval ..... 12-10 sip-alg ........12-25 transmit-delay .
  • Page 493 Index ip ospf authentication ..... . . 17-13 authentication ......18-7 authentication-key .
  • Page 494 Index authentication-key ....13-15 shutdown ......6-10 cost .
  • Page 495 Index redundancy ......25-6 comfort-noise ......23-6 signaling .
  • Page 496 Index timezone ....... . 4-10 feature-mode ....... .25-7 date (clock) .
  • Page 497 Index send-version ....11-14 15-11 17-11 loopdetect ........6-9 ip rip enable .
  • Page 498 Index digit-map ....... 24-10 nat-bypass ....... .4-46 digit-map (global) .
  • Page 499 Index shutdown ..5-5 6-10 11-22 12-20 13-20 15-20 username ....12-24 13-24 15-23 17-23 17-20 18-6 23-7 pptpc ........4-55 sip-alg .
  • Page 500 Index interface proxy-server .......25-12 ethernet ......3-26 proxy-type .
  • Page 501 Index timeout ....... . . 25-19 port-trigger ......2-27 3-54 set-pfs .
  • Page 502 Index sip ........4-68 trunk .

Table of Contents