Vyatta Network OS Documentation

Learn how to install, configure and operate the Vyatta NOS, which helps drive our virtual networking & physical platforms portfolio.

Show Page Sections

Configuration commands

This section contains modified configuration commands.

TCP SYN packet MSS clamping commands

TCP SYN packet MSS clamping commands have been added to this release.

 interfaces bonding <tagnode> ip tcp-mss
 interfaces bonding <tagnode> ip tcp-mss limit <value>
 interfaces bonding <tagnode> ip tcp-mss mtu
 interfaces bonding <tagnode> ip tcp-mss mtu-minus <value>
 interfaces bonding <tagnode> ipv6 tcp-mss
 interfaces bonding <tagnode> ipv6 tcp-mss limit <value>
 interfaces bonding <tagnode> ipv6 tcp-mss mtu
 interfaces bonding <tagnode> ipv6 tcp-mss mtu-minus <value>
 interfaces bonding <tagnode> vif <tagnode> ip tcp-mss
 interfaces bonding <tagnode> vif <tagnode> ip tcp-mss limit <value>
 interfaces bonding <tagnode> vif <tagnode> ip tcp-mss mtu
 interfaces bonding <tagnode> vif <tagnode> ip tcp-mss mtu-minus <value>
 interfaces bonding <tagnode> vif <tagnode> ipv6 tcp-mss
 interfaces bonding <tagnode> vif <tagnode> ipv6 tcp-mss limit <value>
 interfaces bonding <tagnode> vif <tagnode> ipv6 tcp-mss mtu
 interfaces bonding <tagnode> vif <tagnode> ipv6 tcp-mss mtu-minus <value>
 interfaces bridge <tagnode> ip tcp-mss
 interfaces bridge <tagnode> ip tcp-mss limit <value>
 interfaces bridge <tagnode> ip tcp-mss mtu
 interfaces bridge <tagnode> ip tcp-mss mtu-minus <value>
 interfaces bridge <tagnode> ipv6 tcp-mss
 interfaces bridge <tagnode> ipv6 tcp-mss limit <value>
 interfaces bridge <tagnode> ipv6 tcp-mss mtu
 interfaces bridge <tagnode> ipv6 tcp-mss mtu-minus <value>
 interfaces dataplane <tagnode> ip tcp-mss
 interfaces dataplane <tagnode> ip tcp-mss limit <value>
 interfaces dataplane <tagnode> ip tcp-mss mtu
 interfaces dataplane <tagnode> ip tcp-mss mtu-minus <value>
 interfaces dataplane <tagnode> ipv6 tcp-mss
 interfaces dataplane <tagnode> ipv6 tcp-mss limit <value>
 interfaces dataplane <tagnode> ipv6 tcp-mss mtu
 interfaces dataplane <tagnode> ipv6 tcp-mss mtu-minus <value>
 interfaces dataplane <tagnode> vif <tagnode> ip tcp-mss
 interfaces dataplane <tagnode> vif <tagnode> ip tcp-mss limit <value>
 interfaces dataplane <tagnode> vif <tagnode> ip tcp-mss mtu
 interfaces dataplane <tagnode> vif <tagnode> ip tcp-mss mtu-minus <value>
 interfaces dataplane <tagnode> vif <tagnode> ipv6 tcp-mss
 interfaces dataplane <tagnode> vif <tagnode> ipv6 tcp-mss limit <value>
 interfaces dataplane <tagnode> vif <tagnode> ipv6 tcp-mss mtu
 interfaces dataplane <tagnode> vif <tagnode> ipv6 tcp-mss mtu-minus <value>
 interfaces l2tpeth <tagnode> ip tcp-mss
 interfaces l2tpeth <tagnode> ip tcp-mss limit <value>
 interfaces l2tpeth <tagnode> ip tcp-mss mtu
 interfaces l2tpeth <tagnode> ip tcp-mss mtu-minus <value>
 interfaces l2tpeth <tagnode> ipv6 tcp-mss
 interfaces l2tpeth <tagnode> ipv6 tcp-mss limit <value>
 interfaces l2tpeth <tagnode> ipv6 tcp-mss mtu
 interfaces l2tpeth <tagnode> ipv6 tcp-mss mtu-minus <value>
 interfaces l2tpeth <tagnode> vif <tagnode> ip tcp-mss
 interfaces l2tpeth <tagnode> vif <tagnode> ip tcp-mss limit <value>
 interfaces l2tpeth <tagnode> vif <tagnode> ip tcp-mss mtu
 interfaces l2tpeth <tagnode> vif <tagnode> ip tcp-mss mtu-minus <value>
 interfaces l2tpeth <tagnode> vif <tagnode> ipv6 tcp-mss
 interfaces l2tpeth <tagnode> vif <tagnode> ipv6 tcp-mss limit <value>
 interfaces l2tpeth <tagnode> vif <tagnode> ipv6 tcp-mss mtu
 interfaces l2tpeth <tagnode> vif <tagnode> ipv6 tcp-mss mtu-minus <value>
 interfaces openvpn <tagnode> ip tcp-mss
 interfaces openvpn <tagnode> ip tcp-mss limit <value>
 interfaces openvpn <tagnode> ip tcp-mss mtu
 interfaces openvpn <tagnode> ip tcp-mss mtu-minus <value>
 interfaces openvpn <tagnode> ipv6 tcp-mss
 interfaces openvpn <tagnode> ipv6 tcp-mss limit <value>
 interfaces openvpn <tagnode> ipv6 tcp-mss mtu
 interfaces openvpn <tagnode> ipv6 tcp-mss mtu-minus <value>
 interfaces tunnel <tagnode> ip tcp-mss
 interfaces tunnel <tagnode> ip tcp-mss limit <value>
 interfaces tunnel <tagnode> ip tcp-mss mtu
 interfaces tunnel <tagnode> ip tcp-mss mtu-minus <value>
 interfaces tunnel <tagnode> ipv6 tcp-mss
 interfaces tunnel <tagnode> ipv6 tcp-mss limit <value>
 interfaces tunnel <tagnode> ipv6 tcp-mss mtu
 interfaces tunnel <tagnode> ipv6 tcp-mss mtu-minus <value>
 interfaces vti <tagnode> ip tcp-mss
 interfaces vti <tagnode> ip tcp-mss limit <value>
 interfaces vti <tagnode> ip tcp-mss mtu
 interfaces vti <tagnode> ip tcp-mss mtu-minus <value>
 interfaces vti <tagnode> ipv6 tcp-mss
 interfaces vti <tagnode> ipv6 tcp-mss limit <value>
 interfaces vti <tagnode> ipv6 tcp-mss mtu
 interfaces vti <tagnode> ipv6 tcp-mss mtu-minus <value>

Policy based IPSEC with firewalls and DNAT/SNAT commands

Policy based IPSEC with firewalls and DNAT/SNAT commands have been added to this release.

 interfaces virtual-feature-point <ifname>
 interfaces virtual-feature-point <ifname> address <value>
 interfaces virtual-feature-point <ifname> description <value>
 interfaces virtual-feature-point <ifname> disable
 interfaces virtual-feature-point <ifname> ip tcp-mss
 interfaces virtual-feature-point <ifname> ip tcp-mss limit <value>
 interfaces virtual-feature-point <ifname> ipv6 tcp-mss
 interfaces virtual-feature-point <ifname> ipv6 tcp-mss limit <value>
 interfaces virtual-feature-point <ifname> mtu <value>

 interfaces virtual-feature-point <ifname> ip unnumbered donor-interface <tagnode>
 interfaces virtual-feature-point <ifname> ip unnumbered donor-interface <tagnode>
preferred-address <value>
 interfaces virtual-feature-point <ifname> ipv6 unnumbered donor-interface <tagnode>
 interfaces virtual-feature-point <ifname> ipv6 unnumbered donor-interface <tagnode>
preferred-address <value>
 interfaces virtual-feature-point <ifname> firewall in <value>
 interfaces virtual-feature-point <ifname> firewall local <value>
 interfaces virtual-feature-point <ifname> firewall out <value>

 interfaces virtual-feature-point <ifname> policy route pbr <value>

 security firewall name <ruleset-name> rule <tagnode> dscp-group <value>
 security firewall name <ruleset-name> rule <tagnode> protocol-group <value>

 security vpn ipsec site-to-site peer <tagnode> tunnel <tagnode> uses <value>

VXLAN tunnel support commands

VXLAN tunnel support commands have been added to this release.

 interfaces tunnel <tagnode> encapsulation vxlan
 interfaces tunnel <tagnode> encapsulation vxlan-gpe
 interfaces tunnel <tagnode> transport multicast-group <value>
 interfaces tunnel <tagnode> vxlan-id <value>
 interfaces tunnel <tagnode> transport routing-instance <value>

Firewall/QoS: make the policer overhead configurable commands

Make the policer overhead configurable commands have been added to this release.

 policy action
 policy action name <id>
 policy action name <id> mark dscp af11
 policy action name <id> mark dscp af12
 policy action name <id> mark dscp af13
 policy action name <id> mark dscp af21
 policy action name <id> mark dscp af22
 policy action name <id> mark dscp af23
 policy action name <id> mark dscp af31
 policy action name <id> mark dscp af32
 policy action name <id> mark dscp af33
 policy action name <id> mark dscp af41
 policy action name <id> mark dscp af42
 policy action name <id> mark dscp af43
 policy action name <id> mark dscp cs1
 policy action name <id> mark dscp cs2
 policy action name <id> mark dscp cs3
 policy action name <id> mark dscp cs4
 policy action name <id> mark dscp cs5
 policy action name <id> mark dscp cs6
 policy action name <id> mark dscp cs7
 policy action name <id> mark dscp default
 policy action name <id> mark dscp ef
 policy action name <id> mark dscp va
 policy action name <id> mark pcp <value>
 policy action name <id> police
 policy action name <id> police bandwidth <value>
 policy action name <id> police burst <value>
 policy action name <id> police frame-overhead <value>
 policy action name <id> police ratelimit <value>
 policy action name <id> police then action drop
 policy action name <id> police then mark dscp af11
 policy action name <id> police then mark dscp af12
 policy action name <id> police then mark dscp af13
 policy action name <id> police then mark dscp af21
 policy action name <id> police then mark dscp af22
 policy action name <id> police then mark dscp af23
 policy action name <id> police then mark dscp af31
 policy action name <id> police then mark dscp af32
 policy action name <id> police then mark dscp af33
 policy action name <id> police then mark dscp af41
 policy action name <id> police then mark dscp af42
 policy action name <id> police then mark dscp af43
 policy action name <id> police then mark dscp cs1
 policy action name <id> police then mark dscp cs2
 policy action name <id> police then mark dscp cs3
 policy action name <id> police then mark dscp cs4
 policy action name <id> police then mark dscp cs5
 policy action name <id> police then mark dscp cs6
 policy action name <id> police then mark dscp cs7
 policy action name <id> police then mark dscp default
 policy action name <id> police then mark dscp ef
 policy action name <id> police then mark dscp va
 policy action name <id> police then mark pcp <value>

 policy qos name <id> shaper class <id> match <id> action-group <value>
 policy qos name <id> shaper class <id> match <id> dscp-group <value>
 policy qos name <id> shaper class <id> match <id> police frame-overhead <value>
 policy qos name <id> shaper class <id> match <id> protocol-group <value>
 policy qos profile <id>
 policy qos profile <id> bandwidth <value>
 policy qos profile <id> burst <value>
 policy qos profile <id> description <value>
 policy qos profile <id> map dscp <id>
 policy qos profile <id> map dscp <id> to <value>
 policy qos profile <id> map pcp <id>
 policy qos profile <id> map pcp <id> to <value>
 policy qos profile <id> period <value>
 policy qos profile <id> queue <id>
 policy qos profile <id> queue <id> description <value>
 policy qos profile <id> queue <id> traffic-class <value>
 policy qos profile <id> queue <id> weight <value>
 policy qos profile <id> traffic-class <id>
 policy qos profile <id> traffic-class <id> bandwidth <value>
 policy qos profile <id> traffic-class <id> description <value>

 resources group address-group <tagnode> address-range <start>
 resources group address-group <tagnode> address-range <start> to <value>
 resources group dscp-group <group-name>
 resources group dscp-group <group-name> description <value>
 resources group dscp-group <group-name> dscp af11
 resources group dscp-group <group-name> dscp af12
 resources group dscp-group <group-name> dscp af13
 resources group dscp-group <group-name> dscp af21
 resources group dscp-group <group-name> dscp af22
 resources group dscp-group <group-name> dscp af23
 resources group dscp-group <group-name> dscp af31
 resources group dscp-group <group-name> dscp af32
 resources group dscp-group <group-name> dscp af33
 resources group dscp-group <group-name> dscp af41
 resources group dscp-group <group-name> dscp af42
 resources group dscp-group <group-name> dscp af43
 resources group dscp-group <group-name> dscp cs1
 resources group dscp-group <group-name> dscp cs2
 resources group dscp-group <group-name> dscp cs3
 resources group dscp-group <group-name> dscp cs4
 resources group dscp-group <group-name> dscp cs5
 resources group dscp-group <group-name> dscp cs6
 resources group dscp-group <group-name> dscp cs7
 resources group dscp-group <group-name> dscp default
 resources group dscp-group <group-name> dscp ef
 resources group dscp-group <group-name> dscp va
 resources group protocol-group <group-name>
 resources group protocol-group <group-name> description <value>
 resources group protocol-group <group-name> protocol <value>

Assign cost to summary route in OSPFv2 and OSPFv3 commands

Assign cost to summary route in OSPFv2 and OSPFv3 commands have been added to this release.

 protocols ospf area <tagnode> range <tagnode> metric <value>
 protocols ospf process <instance> area <tagnode> range <tagnode> metric <value>

 routing routing-instance <instance-name> protocols ospf process <instance> area <tagnode>
 	range <tagnode> metric <value>

 protocols ospfv3 address-family ipv4 unicast area <tagnode> range <tagnode> metric <value>
 protocols ospfv3 area <tagnode> range <tagnode> metric <value>
 protocols ospfv3 process <tagnode> address-family ipv4 unicast area <tagnode> range
<tagnode> metric <value>
 protocols ospfv3 process <tagnode> area <tagnode> range <tagnode> metric <value>

 routing routing-instance <instance-name> protocols ospfv3 process <process-name> address-family
ipv4 unicast area <tagnode> range <tagnode> metric <value>
 routing routing-instance <instance-name> protocols ospfv3 process <process-name> area <tagnode>
range <tagnode> metric <value>

 protocols rip log bfd

Assign tag to static route commands

Assign tag to static route commands have been added to this release.

 protocols static interface-route <tagnode> next-hop-interface <tagnode> tag <value>
 protocols static interface-route6 <tagnode> next-hop-interface <tagnode> tag <value>
 protocols static route <tagnode> blackhole tag <value>
 protocols static route <tagnode> next-hop <tagnode> tag <value>
 protocols static route <tagnode> unreachable tag <value>
 protocols static route6 <tagnode> blackhole tag <value>
 protocols static route6 <tagnode> next-hop <tagnode> tag <value>
 protocols static route6 <tagnode> unreachable tag <value>

 routing routing-instance <instance-name> protocols static interface-route <tagnode>
next-hop-interface <tagnode> tag <value>
 routing routing-instance <instance-name> protocols static interface-route6 <tagnode>
next-hop-interface <tagnode> tag <value>
 routing routing-instance <instance-name> protocols static route <tagnode> blackhole tag <value>
 routing routing-instance <instance-name> protocols static route <tagnode> next-hop <tagnode>
tag <value>
 routing routing-instance <instance-name> protocols static route <tagnode> unreachable
tag <value>
 routing routing-instance <instance-name> protocols static route6 <tagnode> blackhole tag <value>
 routing routing-instance <instance-name> protocols static route6 <tagnode> next-hop <tagnode>
tag <value>
 routing routing-instance <instance-name> protocols static route6 <tagnode> unreachable
tag <value>

 protocols static interface-route <tagnode> next-hop-routing-instance <routing-instance>
next-hop-interface <interface-name> tag <value>
 protocols static interface-route6 <tagnode> next-hop-routing-instance <routing-instance>
next-hop-interface <interface-name> tag <value>
 protocols static route <tagnode> next-hop-routing-instance <routing-instance> next-hop <tagnode>
tag <value>
 protocols static route6 <tagnode> next-hop-routing-instance <routing-instance>
next-hop <tagnode> tag <value>
 routing routing-instance <instance-name> protocols static interface-route <tagnode>
next-hop-routing-instance <routing-instance> next-hop-interface <interface-name>
tag <value>
 routing routing-instance <instance-name> protocols static interface-route6 <tagnode>
next-hop-routing-instance <routing-instance> next-hop-interface <interface-name>
tag <value>
 routing routing-instance <instance-name> protocols static route <tagnode>
next-hop-routing-instance <routing-instance> next-hop <tagnode> tag <value>
 routing routing-instance <instance-name> protocols static route6 <tagnode>
next-hop-routing-instance-v6 <routing-instance> next-hop <tagnode> tag <value>

IP-SLA support commands

IP-SLA support commands have been added to this release.

 service path-monitor monitor <name> history policy-state-change <value>
 service path-monitor monitor <name> history results <value>

 service path-monitor monitor <name> compliance-status-override disabled
 service path-monitor monitor <name> compliance-status-override enabled

 service path-monitor host <name> type ping data-size <value>
 service path-monitor policy <name> requires type ping jitter
 service path-monitor policy <name> requires type ping jitter robustness <value>
 service path-monitor policy <name> requires type ping jitter threshold <value>
 service path-monitor policy <name> requires type ping jitter tolerance <value>
 service path-monitor policy <name> requires type ping loss robustness <value>
 service path-monitor policy <name> requires type ping loss threshold <value>
 service path-monitor policy <name> requires type ping loss tolerance <value>

 service path-monitor monitor <name> type ping routing-instance <value>
 service path-monitor monitor <name> type ping routing-instance default

 service path-monitor host <name> type twping
 service path-monitor host <name> type twping control-port <value>
 service path-monitor host <name> type twping dscp af11
 service path-monitor host <name> type twping dscp af12
 service path-monitor host <name> type twping dscp af13
 service path-monitor host <name> type twping dscp af21
 service path-monitor host <name> type twping dscp af22
 service path-monitor host <name> type twping dscp af23
 service path-monitor host <name> type twping dscp af31
 service path-monitor host <name> type twping dscp af32
 service path-monitor host <name> type twping dscp af33
 service path-monitor host <name> type twping dscp af41
 service path-monitor host <name> type twping dscp af42
 service path-monitor host <name> type twping dscp af43
 service path-monitor host <name> type twping dscp cs1
 service path-monitor host <name> type twping dscp cs2
 service path-monitor host <name> type twping dscp cs3
 service path-monitor host <name> type twping dscp cs4
 service path-monitor host <name> type twping dscp cs5
 service path-monitor host <name> type twping dscp cs6
 service path-monitor host <name> type twping dscp cs7
 service path-monitor host <name> type twping dscp default
 service path-monitor host <name> type twping dscp ef
 service path-monitor host <name> type twping dscp va
 service path-monitor host <name> type twping padding <value>
 service path-monitor host <name> type twping port-range end <value>
 service path-monitor host <name> type twping port-range start <value>
 service path-monitor host <name> type twping source-address <value>
 service path-monitor monitor <name> type twping
 service path-monitor monitor <name> type twping host <value>
 service path-monitor monitor <name> type twping interface <value>
 service path-monitor monitor <name> type twping interval <value>
 service path-monitor policy <name> requires type twping
 service path-monitor policy <name> requires type twping reflect jitter
 service path-monitor policy <name> requires type twping reflect jitter robustness <value>
 service path-monitor policy <name> requires type twping reflect jitter threshold <value>
 service path-monitor policy <name> requires type twping reflect jitter tolerance <value>
 service path-monitor policy <name> requires type twping reflect time
 service path-monitor policy <name> requires type twping reflect time robustness <value>
 service path-monitor policy <name> requires type twping reflect time threshold <value>
 service path-monitor policy <name> requires type twping reflect time tolerance <value>
 service path-monitor policy <name> requires type twping round-trip jitter
 service path-monitor policy <name> requires type twping round-trip jitter robustness <value>
 service path-monitor policy <name> requires type twping round-trip jitter threshold <value>
 service path-monitor policy <name> requires type twping round-trip jitter tolerance <value>
 service path-monitor policy <name> requires type twping round-trip loss robustness <value>
 service path-monitor policy <name> requires type twping round-trip loss threshold <value>
 service path-monitor policy <name> requires type twping round-trip loss tolerance <value>
 service path-monitor policy <name> requires type twping round-trip time
 service path-monitor policy <name> requires type twping round-trip time robustness <value>
 service path-monitor policy <name> requires type twping round-trip time threshold <value>
 service path-monitor policy <name> requires type twping round-trip time tolerance <value>
 service path-monitor policy <name> requires type twping send jitter
 service path-monitor policy <name> requires type twping send jitter robustness <value>
 service path-monitor policy <name> requires type twping send jitter threshold <value>
 service path-monitor policy <name> requires type twping send jitter tolerance <value>
 service path-monitor policy <name> requires type twping send time
 service path-monitor policy <name> requires type twping send time robustness <value>
 service path-monitor policy <name> requires type twping send time threshold <value>
 service path-monitor policy <name> requires type twping send time tolerance <value>

 service path-monitor monitor <name> type twping routing-instance <value>
 service path-monitor monitor <name> type twping routing-instance default

 policy route pbr <tagnode> rule <tagnode> dscp-group <value>
 policy route pbr <tagnode> rule <tagnode> protocol-group <value>

 service twamp server use-legacy-authentication

 routing routing-instance <instance-name> service twamp server use-legacy-authentication

Other commands

Other commands have been added to this release.

 service diamond session-name <name> collector netconf get path-map <path>
 service diamond session-name <name> collector netconf get path-map <path> to <value>

 interfaces bonding <tagnode> cpu-affinity <value>
 interfaces bonding <tagnode> receive-cpu-affinity <value>
 interfaces bonding <tagnode> transmit-cpu-affinity <value>

 interfaces dataplane <tagnode> receive-cpu-affinity <value>
 interfaces dataplane <tagnode> transmit-cpu-affinity <value>

 system modems
 system modems connection-settings <connection-name>
 system modems connection-settings <connection-name> apn <value>
 system modems connection-settings <connection-name> interface <name>
 system modems connection-settings <connection-name> number <value>
 system modems connection-settings <connection-name> password <value>
 system modems connection-settings <connection-name> pin <value>
 system modems connection-settings <connection-name> user <value>