Skip to content

Support

Techpubs Home
Report an Error

Short Contents

Entire manual as PDF [4977 KB]

Chapter: About This Guide
[PDF 55 KB]
Objectives
Audience
Document Organization
Part Organization
Using the Indexes
Documentation Conventions
General Conventions
Conventions for Software Commands and Statements
List of Technical Publications
Documentation Feedback
How to Request Support
Chapter: Services Interfaces Overview
[PDF 18 KB]
Service PIC Types
Chapter: Services Interfaces Configuration Statements
[PDF 149 KB]
[edit applications] Hierarchy Level
[edit forwarding-options] Hierarchy Level
[edit interfaces] Hierarchy Level
[edit logical-routers] Hierarchy Level
[edit services] Hierarchy Level
Chapter: Adaptive Services Overview
[PDF 121 KB]
Services Configuration Flow
Stateful Firewall Overview
Firewall Application Protocols Support
Stateful Firewall Anomaly Checking
Network Address Translation Overview
IPSec Overview
IPSec
Security Associations
IKE
Comparison of IPSec Services and ES Interface Configuration
Layer 2 Tunneling Protocol Overview
Voice Services Overview
Examples: Services Interfaces Configuration
Chapter: Configure Applications
[PDF 95 KB]
Configure Application Protocol Properties
Configure an Application Protocol
Configure the Network Protocol
Configure the ICMP Code and Type
Configure Source and Destination Ports
Configure the Inactivity Timeout Period
Configure an SNMP Command
Configure an RPC Program Number
Configure the TTL Threshold
Configure a Universal Unique Identifier
Configure Application Sets
Examples: Configure Applications
Chapter: Summary of Applications Configuration Statements
[PDF 59 KB]
application
application-protocol
application-set
applications
destination-port
icmp-code
icmp-type
inactivity-timeout
protocol
rpc-program-number
snmp-command
source-port
ttl-threshold
uuid
Chapter: Configure Stateful Firewall Services
[PDF 60 KB]
Configure Stateful Firewall Properties
Configure the Stateful Firewall Rule Set
Configure Stateful Firewall Rule Content
Configure Stateful Firewall Match Conditions
Configure Stateful Firewall Actions
Configure IP Option Handling
Examples: Configure Stateful Firewall Properties
Chapter: Summary of Stateful Firewall Configuration Statements
[PDF 61 KB]
allow-ip-option
application-sets
applications
destination-address
from
match-direction
rule
rule-set
services
source-address
syslog
term
then
Chapter: Configure Network Address Translation Services
[PDF 69 KB]
Configure Network Address Translation Properties
Configure Address and Port Information
Configure the NAT Rule Set
Configure NAT Rule Content
Configure NAT Match Conditions
Configure NAT Actions
Examples: Configure Network Address Translation Properties
Chapter: Summary of Network Address Translation Configuration Statements
[PDF 81 KB]
address
application-sets
applications
destination-address
destination-pool
from
match-direction
pool
port
rule
rule-set
services
source-address
source-pool
syslog
term
then
translated
translation-type
Chapter: Configure Intrusion Detection Services
[PDF 72 KB]
Configure Intrusion Detection Properties
Configure the IDS Rule Set
Configure IDS Rule Content
Configure IDS Match Conditions
Configure IDS Actions
Examples: Configure Intrusion Detection Properties
Chapter: Summary of Intrusion Detection Services Configuration Statements
[PDF 90 KB]
aggregation
application-sets
applications
destination-address
destination-prefix
force-entry
from
ignore-entry
logging
match-direction
mss
rule
rule-set
services
source-address
source-prefix
syn-cookie
syslog
term
then
threshold
Chapter: Configure IPSec Services
[PDF 224 KB]
Minimum Security Association Configurations
Manual SA Configuration
Dynamic SA Configuration
Configure Security Associations
Configure Manual Security Associations
Configure Direction
Configure the Protocol
Configure the Security Parameter Index (SPI)
Configure the Auxiliary Security Parameter Index
Configure Authentication
Configure Encryption
Configure Dynamic Security Associations
Configure an IKE Proposal
Configure an IKE Authentication Algorithm
Configure an IKE Authentication Method
Configure an IKE Diffie-Hellman Group
Configure an IKE Encryption Algorithm
Configure an IKE Lifetime
Example: Configure an IKE Proposal
Configure an IKE Policy for Preshared Keys
Configure IKE Policy Mode
Configure IKE Policy Proposals
Configure IKE Policy Preshared Key
Configure IKE Policy Description
Configure Local and Remote IDs
Example: Configure an IKE Policy
Configure an IPSec Proposal
Configure an Authentication Algorithm
Configure an IPSec Proposal Description
Configure an Encryption Algorithm
Configure the IPSec Lifetime
Configure the Protocol for the Dynamic SA
Configure an IPSec Policy
Configure an IPSec Policy Description
Configure Perfect Forward Secrecy
Configure IPSec Policy Proposals
Example: IPSec Policy Configuration
Configure IPSec Service Rules
Configure the IPSec Rule Set
Configure IPSec Rule Content
Configure IPSec Match Conditions
Configure IPSec Actions
Example: Configure IPSec Services
Chapter: Summary of IPSec Services Configuration Statements
[PDF 184 KB]
authentication
authentication-algorithm
authentication-algorithm (IKE)
authentication-algorithm (IPSec)
authentication-method
auxiliary-spi
clear-dont-fragment-bit
description
destination-address
dh-group
direction
dynamic
encryption
encryption-algorithm
from
ike
ipsec
lifetime-seconds
local-id
manual
match-direction
mode
no-anti-replay
perfect-forward-secrecy
policy
policy (IKE)
policy (IPSec)
pre-shared-key
proposal
proposal (IKE)
proposal (IPSec)
proposals
protocol
remote-gateway
remote-id
rule
rule-set
services
source-address
spi
syslog
term
then
Chapter: Configure Layer 2 Tunneling Protocol Services
[PDF 106 KB]
L2TP Services Components
L2TP Minimum Configuration
Configure L2TP Group Properties
Configure a Tunnel Group
Configure Access Profiles
Configure Addressing
Configure Window Size
Configure Timers
Hide Attribute-Value Pairs
Configure System Log Properties
Configure the Logical Interface Identifier
Trace Layer 2 Tunneling Protocol Operations
Example: Configure L2TP Services
Chapter: Summary of Layer 2 Tunneling Protocol Configuration Statements
[PDF 80 KB]
dial-options
facility-override
hello-interval
hide-avps
host
l2tp-access-profile
local-gateway address
log-prefix
maximum-send-window
ppp-access-profile
receive-window
retransmit-interval
service-interface
services
services (hierarchy)
services (syslog)
syslog
traceoptions
tunnel-group
tunnel-timeout
Chapter: Configure Voice Services
[PDF 52 KB]
Configure Voice Services Properties
Configure Logical Interface Encapsulation
Configure the Interface Address
Configure Compression
Configure the Bundle Interface
Example: Configure Voice Services
Chapter: Summary of Voice Services Configuration Statements
[PDF 51 KB]
address
bundle
compression
encapsulation
f-max-period
family
interfaces
port
queues
rtp
unit
Chapter: Configure Service Sets
[PDF 61 KB]
Configure Service Set Properties
Configure Service Interfaces
Configure Service Rules
Configure System Log Properties
Apply a Service Set to an Interface
Trace Adaptive Services PIC Operations
Example: Configure Service Sets
Chapter: Summary of Service Set Configuration Statements
[PDF 78 KB]
adaptive-services-pics
facility-override
host
ids-rules
interface-service
ipsec-vpn-options
ipsec-vpn-rules
local-gateway
log-prefix
nat-rules
next-hop-service
service-interface
service-set
services
services (hierarchy)
services (syslog)
stateful-firewall-rules
syslog
traceoptions
Chapter: Configure Interfaces
[PDF 77 KB]
Services Interface Naming
Configure Interface Properties
Configure the Interface Address and Domain
Configure Default Timeout Settings
Configure Default System Log Properties
Enable Fragmentation on GRE Tunnels
Apply Filters and Services to an Interface
Configure Service Filters
Example: Configure a Services Interface
Chapter: Summary of Interface Configuration Statements
[PDF 94 KB]
address
clear-dont-fragment-bit
facility-override
family
host
inactivity-timeout
input
interfaces
log-prefix
open-timeout
output
post-service-filter
service
service-domain
service-filter
service-set
services
services-options
syslog
unit
Chapter: Configure Encryption Interfaces
[PDF 94 KB]
Configure an Encryption Interface
Specify the Security Association Name
Configure MTU for an Encryption Interface
Example: Configure an Encryption Interface
Configure Traffic
Traffic Overview
Configure the Security Association
Configure an Outbound Traffic Filter
Example: Configure an Outbound Traffic Filter
Apply the Outbound Traffic Filter
Example: Apply the Outbound Traffic Filter
Configure an Inbound Traffic Filter
Example: Configure an Inbound Traffic Filter
Apply the Inbound Traffic Filter to the Encryption Interface
Example: Apply the Inbound Traffic Filter to the Encryption Interface
Configure an ES Tunnel Interface for a Layer 3 VPN
Configure ES PIC Redundancy
Example: Configure ES PIC Redundancy
Configure IPSec Tunnel Redundancy
Chapter: Summary of Encryption Configuration Statements
[PDF 56 KB]
address
backup-destination
backup-interface
destination
es-options
family
filter
interfaces
ipsec-sa
tunnel
unit
Chapter: Flow Monitoring and Discard Accounting Overview
[PDF 70 KB]
Passive Flow Monitoring
Active Flow Monitoring
Complete Monitoring Services Interface Configuration Hierarchy
Chapter: Configure Flow Monitoring and Discard Accounting
[PDF 222 KB]
Minimum Traffic Sampling or Forwarding Configuration
Configure Traffic Sampling
Configure Traffic Sampling Properties
Disable Traffic Sampling
Configure Traffic Sampling Output
Traffic Sampling Output Files
Trace Traffic Sampling Operations
Examples: Configure Traffic Sampling
Sample a Single SONET Interface
Sample All Traffic from a Single IP Address
Sample All FTP Traffic
Configure Flow Monitoring
Configure the Flow Monitoring Interface
Configure Flow Monitoring Properties
Example: Configure Flow Monitoring
Configure cflowd
Debug cflowd Flow Aggregation
Configure Port Mirroring
Examples: Configure Port Mirroring
Load Balancing among Multiple Monitoring Interfaces
Configure Discard Accounting
Enable Passive Flow Monitoring
Passive Flow Monitoring for MPLS Encapsulated Packets
Remove MPLS Labels from Incoming Packets
Chapter: Summary of Flow Monitoring Configuration Statements
[PDF 312 KB]
accounting
address
aggregate-export-interval
aggregation
autonomous-system-type
boot-command
cflowd
cflowd (Discard Accounting and Sampling)
cflowd (Flow Monitoring)
core-dump
destination
disable
engine-id
engine-type
export-format
family
family (Interfaces)
family (Monitoring)
family (Port Mirroring)
family (Sampling)
file
file (Sampling)
file (Trace Options)
filename
files
filter
flow-active-timeout
flow-export-destination
flow-inactive-timeout
forwarding-options
input
input (Port Mirroring)
input (Sampling)
input-interface-index
interface
interface (Accounting or Sampling)
interface (Monitoring)
interface (Port Mirroring)
interfaces
local-dump
max-packets-per-second
monitoring
multiservice-options
next-hop
next-hop-group
no-core-dump
no-filter-check
no-local-dump
no-stamp
no-syslog
no-world-readable
output
output (Accounting)
output (Monitoring)
output (Port Mirroring)
output (Sampling)
output-interface-index
passive-monitor-mode
pop-all-labels
port
port-mirroring
rate
receive-options-packets
receive-ttl-exceeded
required-depth
run-length
sampling
sampling (Forwarding Options)
sampling (Interfaces)
size
source-address
stamp
syslog
traceoptions
unit
version
world-readable
Chapter: Configure Flow Collection
[PDF 105 KB]
Configure Flow Collection Properties
Configure Flow Collector Destinations
Configure a Packet Analyzer
Configure File Formats
Configure Interface Mappings
Configure Transfer Logs
Configure Retry Attempts
Send cflowd Records to the Flow Collector Interface
Enable Flow Collection Mode and Interface
Example: Flow Collector Interface Configuration
Chapter: Summary of Flow Collection Configuration Statements
[PDF 86 KB]
analyzer-address
analyzer-id
collector
data-format
destinations
destinations (Server Address)
destinations (Transfer Log)
filename
file-specification
file-specification (File Format)
file-specification (Interface Mapping)
flow-collector
ftp
ftp (Flow Collector Files)
ftp (Transfer Log Files)
interface-map
interval
maximum-size
name-format
password
password (Flow Collector File Servers)
password (Transfer Log File Servers)
retry
retry-delay
transfer
transfer-log
username
variant
Chapter: Configure Link and Multilink Services Interfaces
[PDF 258 KB]
Configure Multilink and Link Services Logical Interface Properties
Default Settings for Multilink and Link Services Logical Interfaces
Configure a Link Services Point-to-Point DLCI
Configure a Link Services Multicast-Capable DLCI
Configure a Drop Timeout Period
Configure Logical Interface Encapsulation
Configure a Fragmentation Threshold
Configure Link Services Delay-Sensitive Packet Interleaving
Configure Minimum Links
Configure MRRU
Configure Sequence Format
Configure Link Services Physical Interface Properties
Default Settings for Link Services Interfaces
Configure Link Services Physical Interface Encapsulation
Configure Link Services Acknowledgment Timers
Configure Link Services Differential Delay
Configure Link Services Keepalive Settings on Frame Relay LMI
Multilink and Link Services Interface Structure
Multilink Services and Link Services PIC Capacities
Link Services PIC Capabilities
Configure Bundles
Configure Link Services CoS Components
Example: Configure Link Services CoS Components
Examples: Configure Multilink Interfaces
Examples: Configure Link Services Interfaces
Chapter: Summary of Link Services Configuration Statements
[PDF 125 KB]
acknowledge-retries
acknowledge-timer
action-red-differential-delay
address
bundle
destination
dlci
drop-timeout
encapsulation
encapsulation (Logical Interface)
encapsulation (Physical Interface)
family
fragment-threshold
hello-timer
interfaces
interleave-fragments
lmi-type
mlfr-uni-nni-bundle-options
minimum-links
mrru
multicast-dlci
n391
n392
n393
red-differential-delay
short-sequence
t391
t392
unit
yellow-differential-delay
Chapter: Configure Tunnel Interfaces
[PDF 82 KB]
Configure a Unicast Tunnel
Configure a Multicast Tunnel
Configure a Logical Tunnel
Configure a Tunnel Interface for Routing Table Lookup
Configure a Tunnel Interface for VRF Table Lookup
Configure PIM Tunnels
Configure an IPv6-over-IPv4 Tunnel
Example: Configure Unicast Tunnels
Example: Configure a Virtual Loopback Tunnel Interface for VRF Table Lookup
Example: Configure an IPv6-over-IPv4 Tunnel
Example: Configure a Logical Tunnel
Chapter: Summary of Tunnel Services Configuration Statements
[PDF 50 KB]
destination
destination (Address)
destination (Routing Instance)
interfaces
multicasts-only
peer-unit
routing-instance
source
ttl
tunnel
unit
Chapter: Adaptive Services PIC System Log Messages
[PDF 127 KB]
System Log Message Fields
System Log Message Severity Levels
Startup System Log Messages
EID_SYS_ONLINE
Authentication and Login System Log Messages
EID_SSH_LOGIN_ACCEPT
EID_LOGIN_ACCEPT
EID_SSH_LOGIN_FAILED
EID_LOGIN_FAILED
EID_START_AUTHEN
EID_AUTHEN_ERROR
EID_AUTHEN_FAILURE
Policy Change System Log Messages
EID_FW_TIMER_CHANGE
EID_SYS_CONFIG_DELETE
EID_SYS_CONFIG_DELETE_ERROR
EID_SYS_CONFIG_ERROR
EID_SYS_CONFIG_INSTALL
Policy Lookup System Log Messages
EID_FW_NO_POLICY_ERROR
EID_FW_NO_RULE_DROP
EID_FW_RULE_ACCEPT
EID_FW_RULE_DROP
EID_FW_RULE_PROMO_ERROR
EID_FW_RULE_REJECT
NAT-related System Log Messages
EID_NAT_NO_PORTS
EID_NAT_PORT_RELEASE
Hacker Defense System Log Messages
EID_ICMP_HEADER_LEN_ERROR
EID_ICMP_PACKET_ERROR_LENGTH
EID_IP_FRAGMENT_ASSEMBLY_TIMEOUT
EID_IP_FRAGMENT_OVERLAP
EID_IP_PACKET_CHECKSUM_ERROR
EID_IP_PACKET_DST_BROADCAST
EID_IP_PACKET_FRAGMENT_LENGTH_ERROR
EID_IP_PACKET_INCORRECT_LENGTH
EID_IP_PACKET_LAND_ATTACK
EID_IP_PACKET_NOT_VERSION_4
EID_IP_PACKET_PROTOCOL_ERROR
EID_IP_PACKET_SRC_BAD
EID_IP_PACKET_TOO_LONG
EID_IP_PACKET_TOO_SHORT
EID_IP_PACKET_TTL_ERROR
EID_SMURF_ATTACK
EID_SYN_DEFENSE
EID_TCP_FLAGS_ERROR
EID_TCP_HEADER_LEN_ERROR
EID_TCP_NON_SYN_FIRST_PACKET
EID_TCP_PORT_ZERO
EID_TCP_SEQNUM_AND_FLAGS_ZERO
EID_TCP_SEQNUM_ZERO_FLAGS_SET
EID_UDP_HEADER_LEN_ERROR
EID_UDP_PORT_ZERO
Intrusion Detection System Log Messages
EID_FW_UDP_SCAN
EID_IDS_SYN_PROTECTION_MEMORY_ERROR
EID_IDS_SYN_PROTECTION_OFF
EID_IDS_SYN_PROTECTION_ON
EID_TCP_BAD_SYN_COOKIE_RESPONSE
EID_TCP_SCAN
EID_TCP_SYN_ATTACK
ALG-related System Log Messages
EID_FTP_ACTIVE_ACCEPT
EID_FTP_PASSIVE_ACCEPT
EID_FW_APP_MSG_TOO_LONG
EID_PING_DUPLICATED_SEQNO
EID_PING_MISMATCHED_SEQNO
EID_PING_OUTOF_SEQNO_CACHE
EID_TCP_RECONSTRUCT_DROP
Chapter: Index
[]
Chapter: Index of Statements and Commands
[]