Vyatta Network OS Documentation

Learn how to install, configure and operate the Vyatta NOS, which helps drive our virtual networking & physical platforms portfolio.

Show Page Sections

Configuration commands

This release contains updated configuration commands.

Extra Small (XS) uCPE hardware switch integration

Extra Small (XS) uCPE hardware switch integration configuration commands have been added to this release.

system platform type router
  system platform type switch

  protocols static bridge-mac <mac> vlan <value>

  interfaces dataplane <interface-name> hardware-switching disable
  interfaces dataplane <interface-name> hardware-switching enable

  interfaces dataplane <interface-name> switch-group
  interfaces dataplane <interface-name> switch-group admin-edge
  interfaces dataplane <interface-name> switch-group auto-edge
  interfaces dataplane <interface-name> switch-group bpdu-guard
  interfaces dataplane <interface-name> switch-group cost auto
  interfaces dataplane <interface-name> switch-group cost <value>
  interfaces dataplane <interface-name> switch-group mstp instance <id>
  interfaces dataplane <interface-name> switch-group mstp instance <id> cost auto
  interfaces dataplane <interface-name> switch-group mstp instance <id> cost <value>
  interfaces dataplane <interface-name> switch-group mstp instance <id> priority <value>
  interfaces dataplane <interface-name> switch-group network-port
  interfaces dataplane <interface-name> switch-group point-to-point auto
  interfaces dataplane <interface-name> switch-group point-to-point off
  interfaces dataplane <interface-name> switch-group point-to-point on
  interfaces dataplane <interface-name> switch-group port-parameters
  interfaces dataplane <interface-name> switch-group port-parameters mode access
  interfaces dataplane <interface-name> switch-group port-parameters mode trunk
  interfaces dataplane <interface-name> switch-group port-parameters vlan-parameters primary-vlan-id <value>
  interfaces dataplane <interface-name> switch-group port-parameters vlan-parameters untagged-egress-vlans <value>
  interfaces dataplane <interface-name> switch-group port-parameters vlan-parameters vlans <value>
  interfaces dataplane <interface-name> switch-group priority <value>
  interfaces dataplane <interface-name> switch-group restrict-tcn
  interfaces dataplane <interface-name> switch-group root-block
  interfaces dataplane <interface-name> switch-group switch <value>
	
  interfaces switch <name>
  interfaces switch <name> default-port-parameters mode access
  interfaces switch <name> default-port-parameters mode trunk
  interfaces switch <name> default-port-parameters vlan-parameters primary-vlan-id <value>
  interfaces switch <name> default-port-parameters vlan-parameters untagged-egress-vlans <value>
  interfaces switch <name> default-port-parameters vlan-parameters vlans <value>
  interfaces switch <name> description <value>
  interfaces switch <name> disable
  interfaces switch <name> disable-link-detect
  interfaces switch <name> mac <value>
  interfaces switch <name> physical-switch <value>
  interfaces switch <name> spanning-tree
  interfaces switch <name> spanning-tree forwarding-delay <value>
  interfaces switch <name> spanning-tree hello-time <value>
  interfaces switch <name> spanning-tree max-age <value>
  interfaces switch <name> spanning-tree mstp instance <id>
  interfaces switch <name> spanning-tree mstp instance <id> priority <value>
  interfaces switch <name> spanning-tree mstp instance <id> vlan <value>
  interfaces switch <name> spanning-tree mstp region name <value>
  interfaces switch <name> spanning-tree mstp region revision <value>
  interfaces switch <name> spanning-tree priority <value>
  interfaces switch <name> spanning-tree tx-hold-count <value>
  interfaces switch <name> spanning-tree version mstp
  interfaces switch <name> spanning-tree version rstp
  interfaces switch <name> spanning-tree version stp
  interfaces switch <name> vif <number>
  interfaces switch <name> vif <number> address dhcp
  interfaces switch <name> vif <number> address dhcpv6
  interfaces switch <name> vif <number> bfd template <value>
  interfaces switch <name> vif <number> description <value>
  interfaces switch <name> vif <number> disable
  interfaces switch <name> vif <number> disable-link-detect
  interfaces switch <name> vif <number> firewall in <value>
  interfaces switch <name> vif <number> firewall local <value>
  interfaces switch <name> vif <number> firewall out <value>
  interfaces switch <name> vif <number> inner-vlan <value>
  interfaces switch <name> vif <number> ip disable-forwarding
  interfaces switch <name> vif <number> ip enable-proxy-arp
  interfaces switch <name> vif <number> ip igmp
  interfaces switch <name> vif <number> ip igmp access-group <value>
  interfaces switch <name> vif <number> ip igmp enforce-router-alert
  interfaces switch <name> vif <number> ip igmp immediate-leave group-list <value>
  interfaces switch <name> vif <number> ip igmp join-group <multicast-group>
  interfaces switch <name> vif <number> ip igmp join-group <multicast-group> source <value>
  interfaces switch <name> vif <number> ip igmp last-member-query-count <value>
  interfaces switch <name> vif <number> ip igmp last-member-query-interval <value>
  interfaces switch <name> vif <number> ip igmp limit-exception <value>
  interfaces switch <name> vif <number> ip igmp limit <value>
  interfaces switch <name> vif <number> ip igmp offlink
  interfaces switch <name> vif <number> ip igmp querier
  interfaces switch <name> vif <number> ip igmp querier forced
  interfaces switch <name> vif <number> ip igmp querier querier-timeout <value>
  interfaces switch <name> vif <number> ip igmp query-interval <value>
  interfaces switch <name> vif <number> ip igmp query-max-response-time <value>
  interfaces switch <name> vif <number> ip igmp robustness-variable <value>
  interfaces switch <name> vif <number> ip igmp startup-query-count <value>
  interfaces switch <name> vif <number> ip igmp startup-query-interval <value>
  interfaces switch <name> vif <number> ip igmp static-group <multicast-group>
  interfaces switch <name> vif <number> ip igmp static-group <multicast-group> source <value>
  interfaces switch <name> vif <number> ip igmp version <value>
  interfaces switch <name> vif <number> ip multicast
  interfaces switch <name> vif <number> ip multicast ttl-threshold <value>
  interfaces switch <name> vif <number> ip ospf
  interfaces switch <name> vif <number> ip ospf authentication
  interfaces switch <name> vif <number> ip ospf authentication md5
  interfaces switch <name> vif <number> ip ospf authentication md5-key-id <key-id>
  interfaces switch <name> vif <number> ip ospf authentication md5-key-id <key-id> md5-key <value>
  interfaces switch <name> vif <number> ip ospf authentication plaintext
  interfaces switch <name> vif <number> ip ospf authentication plaintext-password <value>
  interfaces switch <name> vif <number> ip ospf cost <value>
  interfaces switch <name> vif <number> ip ospf dead-interval <value>
  interfaces switch <name> vif <number> ip ospf fall-over bfd
  interfaces switch <name> vif <number> ip ospf hello-interval <value>
  interfaces switch <name> vif <number> ip ospf mtu-ignore
  interfaces switch <name> vif <number> ip ospf network broadcast
  interfaces switch <name> vif <number> ip ospf network non-broadcast
  interfaces switch <name> vif <number> ip ospf network point-to-multipoint
  interfaces switch <name> vif <number> ip ospf network point-to-point
  interfaces switch <name> vif <number> ip ospf priority <value>
  interfaces switch <name> vif <number> ip ospf retransmit-interval <value>
  interfaces switch <name> vif <number> ip ospf transmit-delay <value>
  interfaces switch <name> vif <number> ip pim
  interfaces switch <name> vif <number> ip pim bsr-border
  interfaces switch <name> vif <number> ip pim dr-priority <value>
  interfaces switch <name> vif <number> ip pim exclude-genid
  interfaces switch <name> vif <number> ip pim hello-holdtime <value>
  interfaces switch <name> vif <number> ip pim hello-interval <value>
  interfaces switch <name> vif <number> ip pim mode dense
  interfaces switch <name> vif <number> ip pim mode dense-passive
  interfaces switch <name> vif <number> ip pim mode sparse
  interfaces switch <name> vif <number> ip pim mode sparse-dense
  interfaces switch <name> vif <number> ip pim mode sparse-dense-passive
  interfaces switch <name> vif <number> ip pim mode sparse-passive
  interfaces switch <name> vif <number> ip pim neighbor-filter <value>
  interfaces switch <name> vif <number> ip pim propagation-delay 1000
  interfaces switch <name> vif <number> ip pim propagation-delay 2000
  interfaces switch <name> vif <number> ip pim propagation-delay 3000
  interfaces switch <name> vif <number> ip pim propagation-delay 4000
  interfaces switch <name> vif <number> ip pim propagation-delay 5000
  interfaces switch <name> vif <number> ip pim state-refresh
  interfaces switch <name> vif <number> ip pim state-refresh origination-interval <value>
  interfaces switch <name> vif <number> ip pim unicast-bsm
  interfaces switch <name> vif <number> ip rip authentication
  interfaces switch <name> vif <number> ip rip authentication md5 <id>
  interfaces switch <name> vif <number> ip rip authentication md5 <id> password <value>
  interfaces switch <name> vif <number> ip rip authentication plaintext-password <value>
  interfaces switch <name> vif <number> ip rip receive
  interfaces switch <name> vif <number> ip rip receive version 1
  interfaces switch <name> vif <number> ip rip receive version 2
  interfaces switch <name> vif <number> ip rip receive version both
  interfaces switch <name> vif <number> ip rip send
  interfaces switch <name> vif <number> ip rip send version 1
  interfaces switch <name> vif <number> ip rip send version 2
  interfaces switch <name> vif <number> ip rip send version both
  interfaces switch <name> vif <number> ip rip split-horizon
  interfaces switch <name> vif <number> ip rip split-horizon disable
  interfaces switch <name> vif <number> ip rip split-horizon poison-reverse
  interfaces switch <name> vif <number> ip rpf-check disable
  interfaces switch <name> vif <number> ip rpf-check loose
  interfaces switch <name> vif <number> ip rpf-check strict
  interfaces switch <name> vif <number> ipv6 mld
  interfaces switch <name> vif <number> ipv6 mld access-group <value>
  interfaces switch <name> vif <number> ipv6 mld immediate-leave
  interfaces switch <name> vif <number> ipv6 mld immediate-leave group-list <value>
  interfaces switch <name> vif <number> ipv6 mld last-member-query-count <value>
  interfaces switch <name> vif <number> ipv6 mld last-member-query-interval <value>
  interfaces switch <name> vif <number> ipv6 mld limit-exception <value>
  interfaces switch <name> vif <number> ipv6 mld limit <value>
  interfaces switch <name> vif <number> ipv6 mld querier-timeout <value>
  interfaces switch <name> vif <number> ipv6 mld query-interval <value>
  interfaces switch <name> vif <number> ipv6 mld query-max-response-time <value>
  interfaces switch <name> vif <number> ipv6 mld robustness-variable <value>
  interfaces switch <name> vif <number> ipv6 mld static-group <multicast-group>
  interfaces switch <name> vif <number> ipv6 mld static-group <multicast-group> source <value>
  interfaces switch <name> vif <number> ipv6 mld version <value>
  interfaces switch <name> vif <number> ipv6 ospfv3 area <value>
  interfaces switch <name> vif <number> ipv6 ospfv3 cost <value>
  interfaces switch <name> vif <number> ipv6 ospfv3 dead-interval <value>
  interfaces switch <name> vif <number> ipv6 ospfv3 fall-over bfd
  interfaces switch <name> vif <number> ipv6 ospfv3 hello-interval <value>
  interfaces switch <name> vif <number> ipv6 ospfv3 instance-id <instance-id>
  interfaces switch <name> vif <number> ipv6 ospfv3 instance-id <instance-id> area <value>
  interfaces switch <name> vif <number> ipv6 ospfv3 instance-id <instance-id> cost <value>
  interfaces switch <name> vif <number> ipv6 ospfv3 instance-id <instance-id> dead-interval <value>
  interfaces switch <name> vif <number> ipv6 ospfv3 instance-id <instance-id> hello-interval <value>
  interfaces switch <name> vif <number> ipv6 ospfv3 instance-id <instance-id> link-lsa-suppression <value>
  interfaces switch <name> vif <number> ipv6 ospfv3 instance-id <instance-id> mtu-ignore
  interfaces switch <name> vif <number> ipv6 ospfv3 instance-id <instance-id> neighbor <address>
  interfaces switch <name> vif <number> ipv6 ospfv3 instance-id <instance-id> network <network-type>
  interfaces switch <name> vif <number> ipv6 ospfv3 instance-id <instance-id> priority <value>
  interfaces switch <name> vif <number> ipv6 ospfv3 instance-id <instance-id> retransmit-interval <value>
  interfaces switch <name> vif <number> ipv6 ospfv3 instance-id <instance-id> transmit-delay <value>
  interfaces switch <name> vif <number> ipv6 ospfv3 link-lsa-suppression <value>
  interfaces switch <name> vif <number> ipv6 ospfv3 mtu-ignore
  interfaces switch <name> vif <number> ipv6 ospfv3 neighbor <address>
  interfaces switch <name> vif <number> ipv6 ospfv3 network <network-type>
  interfaces switch <name> vif <number> ipv6 ospfv3 priority <value>
  interfaces switch <name> vif <number> ipv6 ospfv3 process <name>
  interfaces switch <name> vif <number> ipv6 ospfv3 process <name> instance-id <instance-id>
  interfaces switch <name> vif <number> ipv6 ospfv3 process <name> instance-id <instance-id> area <value>
  interfaces switch <name> vif <number> ipv6 ospfv3 process <name> instance-id <instance-id> cost <value>
  interfaces switch <name> vif <number> ipv6 ospfv3 process <name> instance-id <instance-id> dead-interval <value>
  interfaces switch <name> vif <number> ipv6 ospfv3 process <name> instance-id <instance-id> hello-interval <value>
  interfaces switch <name> vif <number> ipv6 ospfv3 process <name> instance-id <instance-id> link-lsa-suppression <value>
  interfaces switch <name> vif <number> ipv6 ospfv3 process <name> instance-id <instance-id> mtu-ignore
  interfaces switch <name> vif <number> ipv6 ospfv3 process <name> instance-id <instance-id> neighbor <address>
  interfaces switch <name> vif <number> ipv6 ospfv3 process <name> instance-id <instance-id> network <network-type>
  interfaces switch <name> vif <number> ipv6 ospfv3 process <name> instance-id <instance-id> priority <value>
  interfaces switch <name> vif <number> ipv6 ospfv3 process <name> instance-id <instance-id> retransmit-interval <value>
  interfaces switch <name> vif <number> ipv6 ospfv3 process <name> instance-id <instance-id> transmit-delay <value>
  interfaces switch <name> vif <number> ipv6 ospfv3 retransmit-interval <value>
  interfaces switch <name> vif <number> ipv6 ospfv3 transmit-delay <value>
  interfaces switch <name> vif <number> ipv6 pim
  interfaces switch <name> vif <number> ipv6 pim bsr-border
  interfaces switch <name> vif <number> ipv6 pim dr-priority <value>
  interfaces switch <name> vif <number> ipv6 pim exclude-genid
  interfaces switch <name> vif <number> ipv6 pim hello-holdtime <value>
  interfaces switch <name> vif <number> ipv6 pim hello-interval <value>
  interfaces switch <name> vif <number> ipv6 pim mode dense
  interfaces switch <name> vif <number> ipv6 pim mode dense-passive
  interfaces switch <name> vif <number> ipv6 pim mode sparse
  interfaces switch <name> vif <number> ipv6 pim mode sparse-dense
  interfaces switch <name> vif <number> ipv6 pim mode sparse-dense-passive
  interfaces switch <name> vif <number> ipv6 pim mode sparse-passive
  interfaces switch <name> vif <number> ipv6 pim neighbor-filter <value>
  interfaces switch <name> vif <number> ipv6 pim propagation-delay 1000
  interfaces switch <name> vif <number> ipv6 pim propagation-delay 2000
  interfaces switch <name> vif <number> ipv6 pim propagation-delay 3000
  interfaces switch <name> vif <number> ipv6 pim propagation-delay 4000
  interfaces switch <name> vif <number> ipv6 pim propagation-delay 5000
  interfaces switch <name> vif <number> ipv6 pim state-refresh
  interfaces switch <name> vif <number> ipv6 pim state-refresh origination-interval <value>
  interfaces switch <name> vif <number> ipv6 pim unicast-bsm
  interfaces switch <name> vif <number> ipv6 ripng enable
  interfaces switch <name> vif <number> ipv6 ripng metric-offset <value>
  interfaces switch <name> vif <number> ipv6 ripng neighbor <value>
  interfaces switch <name> vif <number> ipv6 ripng split-horizon
  interfaces switch <name> vif <number> ipv6 ripng split-horizon disable
  interfaces switch <name> vif <number> ipv6 ripng split-horizon poison-reverse
  interfaces switch <name> vif <number> log_martians
  interfaces switch <name> vif <number> mtu <value>
  interfaces switch <name> vif <number> vlan <value>

Static/duplex configuration of interfaces

Static/duplex configuration of interfaces commands have been added to this release.

interfaces dataplane <interface-name> duplex auto
  interfaces dataplane <interface-name> duplex full
  interfaces dataplane <interface-name> duplex half
  interfaces dataplane <interface-name> speed 100g
  interfaces dataplane <interface-name> speed 100m
  interfaces dataplane <interface-name> speed 10g
  interfaces dataplane <interface-name> speed 10m
  interfaces dataplane <interface-name> speed 1g
  interfaces dataplane <interface-name> speed 25g
  interfaces dataplane <interface-name> speed 2.5g
  interfaces dataplane <interface-name> speed 40g
  interfaces dataplane <interface-name> speed auto

IPsec remove access client support for AT&T vVIG

IPsec remove access client support for AT&T vVIG commands have been added to this release.

  security vpn ike retransmit base <value>
  security vpn ike retransmit timeout <value>
  security vpn ike retransmit tries <value>

  security vpn ipsec logging connection-manager all level alert
  security vpn ipsec logging connection-manager all level crit
  security vpn ipsec logging connection-manager all level debug
  security vpn ipsec logging connection-manager all level emerg
  security vpn ipsec logging connection-manager all level err
  security vpn ipsec logging connection-manager all level info
  security vpn ipsec logging connection-manager all level notice
  security vpn ipsec logging connection-manager all level warning
  security vpn ipsec logging connection-manager connection level alert
  security vpn ipsec logging connection-manager connection level crit
  security vpn ipsec logging connection-manager connection level debug
  security vpn ipsec logging connection-manager connection level emerg
  security vpn ipsec logging connection-manager connection level err
  security vpn ipsec logging connection-manager connection level info
  security vpn ipsec logging connection-manager connection level notice
  security vpn ipsec logging connection-manager connection level warning
  security vpn ipsec logging connection-manager event level alert
  security vpn ipsec logging connection-manager event level crit
  security vpn ipsec logging connection-manager event level debug
  security vpn ipsec logging connection-manager event level emerg
  security vpn ipsec logging connection-manager event level err
  security vpn ipsec logging connection-manager event level info
  security vpn ipsec logging connection-manager event level notice
  security vpn ipsec logging connection-manager event level warning
  security vpn ipsec logging connection-manager job level alert
  security vpn ipsec logging connection-manager job level crit
  security vpn ipsec logging connection-manager job level debug
  security vpn ipsec logging connection-manager job level emerg
  security vpn ipsec logging connection-manager job level err
  security vpn ipsec logging connection-manager job level info
  security vpn ipsec logging connection-manager job level notice
  security vpn ipsec logging connection-manager job level warning
  security vpn ipsec logging connection-manager path-monitor level alert
  security vpn ipsec logging connection-manager path-monitor level crit
  security vpn ipsec logging connection-manager path-monitor level debug
  security vpn ipsec logging connection-manager path-monitor level emerg
  security vpn ipsec logging connection-manager path-monitor level err
  security vpn ipsec logging connection-manager path-monitor level info
  security vpn ipsec logging connection-manager path-monitor level notice
  security vpn ipsec logging connection-manager path-monitor level warning

  security vpn ipsec remote-access-client
  security vpn ipsec remote-access-client profile <profile-name>
  security vpn ipsec remote-access-client profile <profile-name> authentication id type keyid
  security vpn ipsec remote-access-client profile <profile-name> authentication id type rfc822
  security vpn ipsec remote-access-client profile <profile-name> authentication id value <value>
  security vpn ipsec remote-access-client profile <profile-name> authentication mode psk+eap-gtc
  security vpn ipsec remote-access-client profile <profile-name> authentication password <value>
  security vpn ipsec remote-access-client profile <profile-name> authentication pre-shared-secret <value>
  security vpn ipsec remote-access-client profile <profile-name> authentication username <value>
  security vpn ipsec remote-access-client profile <profile-name> backoff auth-failure base <value>
  security vpn ipsec remote-access-client profile <profile-name> backoff auth-failure delay <value>
  security vpn ipsec remote-access-client profile <profile-name> backoff auth-failure jitter <value>
  security vpn ipsec remote-access-client profile <profile-name> backoff auth-failure upper-limit <value>
  security vpn ipsec remote-access-client profile <profile-name> backoff reconnect base <value>
  security vpn ipsec remote-access-client profile <profile-name> backoff reconnect delay <value>
  security vpn ipsec remote-access-client profile <profile-name> backoff reconnect jitter <value>
  security vpn ipsec remote-access-client profile <profile-name> backoff reconnect upper-limit <value>
  security vpn ipsec remote-access-client profile <profile-name> backoff servers base <value>
  security vpn ipsec remote-access-client profile <profile-name> backoff servers delay <value>
  security vpn ipsec remote-access-client profile <profile-name> backoff servers jitter <value>
  security vpn ipsec remote-access-client profile <profile-name> backoff servers upper-limit <value>
  security vpn ipsec remote-access-client profile <profile-name> backoff source-interfaces base <value>
  security vpn ipsec remote-access-client profile <profile-name> backoff source-interfaces delay <value>
  security vpn ipsec remote-access-client profile <profile-name> backoff source-interfaces jitter <value>
  security vpn ipsec remote-access-client profile <profile-name> backoff source-interfaces upper-limit <value>
  security vpn ipsec remote-access-client profile <profile-name> description <value>
  security vpn ipsec remote-access-client profile <profile-name> esp-group <value>
  security vpn ipsec remote-access-client profile <profile-name> failover mode disable
  security vpn ipsec remote-access-client profile <profile-name> failover mode random-start
  security vpn ipsec remote-access-client profile <profile-name> failover mode sequential
  security vpn ipsec remote-access-client profile <profile-name> ike-group <value>
  security vpn ipsec remote-access-client profile <profile-name> install-vip-on <value>
  security vpn ipsec remote-access-client profile <profile-name> local-address any
  security vpn ipsec remote-access-client profile <profile-name> local-address <value>
  security vpn ipsec remote-access-client profile <profile-name> server <serveraddr>
  security vpn ipsec remote-access-client profile <profile-name> server <serveraddr> source-interface <ifname>
  security vpn ipsec remote-access-client profile <profile-name> server <serveraddr> source-interface <ifname> path-monitor monitor <name>
  security vpn ipsec remote-access-client profile <profile-name> server <serveraddr> source-interface <ifname> path-monitor monitor <name> policy <name>
  security vpn ipsec remote-access-client profile <profile-name> server <serveraddr> source-interface <ifname> path-monitor policy operator AND
  security vpn ipsec remote-access-client profile <profile-name> server <serveraddr> source-interface <ifname> path-monitor policy operator OR
  security vpn ipsec remote-access-client profile <profile-name> source-interface <source-interface-ref>
  security vpn ipsec remote-access-client profile <profile-name> source-interface <source-interface-ref> priority <value>
  security vpn ipsec remote-access-client profile <profile-name> tunnel <tunnel-id>
  security vpn ipsec remote-access-client profile <profile-name> tunnel <tunnel-id> local network <value>
  security vpn ipsec remote-access-client profile <profile-name> tunnel <tunnel-id> remote network <value>
  security vpn ipsec remote-access-client profile <profile-name> tunnel <tunnel-id> uses <value>

  security vpn x509 status crl cache
  security vpn x509 status crl disable
  security vpn x509 status interface <value>
  security vpn x509 status ocsp disable

QoS Enhancements

Qos enhancement commands have been added to this release.

policy action name <id> mark pcp-inner
  policy action name <id> police tc <value>
  policy action name <id> police then mark pcp-inner

  policy qos name <id> shaper class <id> match <id> mark pcp-inner
  policy qos name <id> shaper class <id> match <id> police tc <value>
  policy qos name <id> shaper class <id> match <id> police then mark pcp-inner
  policy qos name <id> shaper profile <id> queue <id> priority-local
  policy qos name <id> shaper profile <id> queue <id> wred-map
  policy qos name <id> shaper profile <id> queue <id> wred-map dscp-group <group-name>
  policy qos name <id> shaper profile <id> queue <id> wred-map dscp-group <group-name> mark-probability <value>
  policy qos name <id> shaper profile <id> queue <id> wred-map dscp-group <group-name> max-threshold <value>
  policy qos name <id> shaper profile <id> queue <id> wred-map dscp-group <group-name> min-threshold <value>
  policy qos name <id> shaper profile <id> queue <id> wred-map filter-weight <value>

  policy qos profile <id> queue <id> priority-local
  policy qos profile <id> queue <id> wred-map
  policy qos profile <id> queue <id> wred-map dscp-group <group-name>
  policy qos profile <id> queue <id> wred-map dscp-group <group-name> mark-probability <value>
  policy qos profile <id> queue <id> wred-map dscp-group <group-name> max-threshold <value>
  policy qos profile <id> queue <id> wred-map dscp-group <group-name> min-threshold <value>
  policy qos profile <id> queue <id> wred-map filter-weight <value>

PPPoE support

PPPoE support commands have been added to this release.

interfaces pppoe <ifname>
  interfaces pppoe <ifname> chap-user <value>
  interfaces pppoe <ifname> connect-on-demand
  interfaces pppoe <ifname> default-route
  interfaces pppoe <ifname> idle-timeout <value>
  interfaces pppoe <ifname> interface <value>
  interfaces pppoe <ifname> mtu <value>
  interfaces pppoe <ifname> name-server
  interfaces pppoe <ifname> service-name <value>

  resources chap-secrets
  resources chap-secrets user <name>
  resources chap-secrets user <name> local-addresses <value>
  resources chap-secrets user <name> secret <value>
  resources chap-secrets user <name> server <value>

MPLS OAM support

MPLS OAM support commands have been added to this release.

protocols mpls-oam log dataplane
  protocols mpls-oam log error
  protocols mpls-oam log event
  protocols mpls-oam log nsm
  protocols mpls-oam log packet
  protocols mpls-oam log rib

VRRP path monitor tracking

VRRP path monitor tracking commands have been added to this release.

interfaces bonding <interface-name> vif <number> vrrp vrrp-group <group-number> track interface <name>
  interfaces bonding <interface-name> vif <number> vrrp vrrp-group <group-number> track interface <name> weight
  interfaces bonding <interface-name> vif <number> vrrp vrrp-group <group-number> track interface <name> weight type decrement
  interfaces bonding <interface-name> vif <number> vrrp vrrp-group <group-number> track interface <name> weight type increment
  interfaces bonding <interface-name> vif <number> vrrp vrrp-group <group-number> track interface <name> weight value <value>
  interfaces bonding <interface-name> vif <number> vrrp vrrp-group <group-number> track path-monitor monitor <name>
  interfaces bonding <interface-name> vif <number> vrrp vrrp-group <group-number> track path-monitor monitor <name> policy <name>
  interfaces bonding <interface-name> vif <number> vrrp vrrp-group <group-number> track path-monitor monitor <name> policy <name> weight
  interfaces bonding <interface-name> vif <number> vrrp vrrp-group <group-number> track path-monitor monitor <name> policy <name> weight type decrement
  interfaces bonding <interface-name> vif <number> vrrp vrrp-group <group-number> track path-monitor monitor <name> policy <name> weight type increment
  interfaces bonding <interface-name> vif <number> vrrp vrrp-group <group-number> track path-monitor monitor <name> policy <name> weight value <value>
  interfaces bonding <interface-name> vrrp vrrp-group <group-number> track interface <name>
  interfaces bonding <interface-name> vrrp vrrp-group <group-number> track interface <name> weight
  interfaces bonding <interface-name> vrrp vrrp-group <group-number> track interface <name> weight type decrement
  interfaces bonding <interface-name> vrrp vrrp-group <group-number> track interface <name> weight type increment
  interfaces bonding <interface-name> vrrp vrrp-group <group-number> track interface <name> weight value <value>
  interfaces bonding <interface-name> vrrp vrrp-group <group-number> track path-monitor monitor <name>
  interfaces bonding <interface-name> vrrp vrrp-group <group-number> track path-monitor monitor <name> policy <name>
  interfaces bonding <interface-name> vrrp vrrp-group <group-number> track path-monitor monitor <name> policy <name> weight
  interfaces bonding <interface-name> vrrp vrrp-group <group-number> track path-monitor monitor <name> policy <name> weight type decrement
  interfaces bonding <interface-name> vrrp vrrp-group <group-number> track path-monitor monitor <name> policy <name> weight type increment
  interfaces bonding <interface-name> vrrp vrrp-group <group-number> track path-monitor monitor <name> policy <name> weight value <value>
  interfaces dataplane <interface-name> vif <number> vrrp vrrp-group <group-number> track interface <name>
  interfaces dataplane <interface-name> vif <number> vrrp vrrp-group <group-number> track interface <name> weight
  interfaces dataplane <interface-name> vif <number> vrrp vrrp-group <group-number> track interface <name> weight type decrement
  interfaces dataplane <interface-name> vif <number> vrrp vrrp-group <group-number> track interface <name> weight type increment
  interfaces dataplane <interface-name> vif <number> vrrp vrrp-group <group-number> track interface <name> weight value <value>
  interfaces dataplane <interface-name> vif <number> vrrp vrrp-group <group-number> track path-monitor monitor <name>
  interfaces dataplane <interface-name> vif <number> vrrp vrrp-group <group-number> track path-monitor monitor <name> policy <name>
  interfaces dataplane <interface-name> vif <number> vrrp vrrp-group <group-number> track path-monitor monitor <name> policy <name> weight
  interfaces dataplane <interface-name> vif <number> vrrp vrrp-group <group-number> track path-monitor monitor <name> policy <name> weight type decrement
  interfaces dataplane <interface-name> vif <number> vrrp vrrp-group <group-number> track path-monitor monitor <name> policy <name> weight type increment
  interfaces dataplane <interface-name> vif <number> vrrp vrrp-group <group-number> track path-monitor monitor <name> policy <name> weight value <value>
  interfaces dataplane <interface-name> vrrp vrrp-group <group-number> track interface <name>
  interfaces dataplane <interface-name> vrrp vrrp-group <group-number> track interface <name> weight
  interfaces dataplane <interface-name> vrrp vrrp-group <group-number> track interface <name> weight type decrement
  interfaces dataplane <interface-name> vrrp vrrp-group <group-number> track interface <name> weight type increment
  interfaces dataplane <interface-name> vrrp vrrp-group <group-number> track interface <name> weight value <value>
  interfaces dataplane <interface-name> vrrp vrrp-group <group-number> track path-monitor monitor <name>
  interfaces dataplane <interface-name> vrrp vrrp-group <group-number> track path-monitor monitor <name> policy <name>
  interfaces dataplane <interface-name> vrrp vrrp-group <group-number> track path-monitor monitor <name> policy <name> weight
  interfaces dataplane <interface-name> vrrp vrrp-group <group-number> track path-monitor monitor <name> policy <name> weight type decrement
  interfaces dataplane <interface-name> vrrp vrrp-group <group-number> track path-monitor monitor <name> policy <name> weight type increment
  interfaces dataplane <interface-name> vrrp vrrp-group <group-number> track path-monitor monitor <name> policy <name> weight value <value>

Static route path monitor tracking

Static route path monitor tracking commands have been added to this release.

protocols static interface-route6 <prefix> next-hop-interface <interface-name> path-monitor monitor <name>
  protocols static interface-route6 <prefix> next-hop-interface <interface-name> path-monitor monitor <name> policy <name>
  protocols static interface-route6 <prefix> next-hop-interface <interface-name> path-monitor monitor <name> policy <name> state compliant
  protocols static interface-route6 <prefix> next-hop-interface <interface-name> path-monitor monitor <name> policy <name> state non-compliant
  protocols static interface-route6 <prefix> next-hop-routing-instance <routing-instance> next-hop-interface <interface-name> path-monitor monitor <name>
  protocols static interface-route6 <prefix> next-hop-routing-instance <routing-instance> next-hop-interface <interface-name> path-monitor monitor <name> policy <name>
  protocols static interface-route6 <prefix> next-hop-routing-instance <routing-instance> next-hop-interface <interface-name> path-monitor monitor <name> policy <name> state compliant
  protocols static interface-route6 <prefix> next-hop-routing-instance <routing-instance> next-hop-interface <interface-name> path-monitor monitor <name> policy <name> state non-compliant
  protocols static interface-route <prefix> next-hop-interface <interface-name> path-monitor monitor <name>
  protocols static interface-route <prefix> next-hop-interface <interface-name> path-monitor monitor <name> policy <name>
  protocols static interface-route <prefix> next-hop-interface <interface-name> path-monitor monitor <name> policy <name> state compliant
  protocols static interface-route <prefix> next-hop-interface <interface-name> path-monitor monitor <name> policy <name> state non-compliant
  protocols static interface-route <prefix> next-hop-routing-instance <routing-instance> next-hop-interface <interface-name> path-monitor monitor <name>
  protocols static interface-route <prefix> next-hop-routing-instance <routing-instance> next-hop-interface <interface-name> path-monitor monitor <name> policy <name>
  protocols static interface-route <prefix> next-hop-routing-instance <routing-instance> next-hop-interface <interface-name> path-monitor monitor <name> policy <name> state compliant
  protocols static interface-route <prefix> next-hop-routing-instance <routing-instance> next-hop-interface <interface-name> path-monitor monitor <name> policy <name> state non-compliant
  protocols static route6 <prefix> next-hop <address> path-monitor monitor <name>
  protocols static route6 <prefix> next-hop <address> path-monitor monitor <name> policy <name>
  protocols static route6 <prefix> next-hop <address> path-monitor monitor <name> policy <name> state compliant
  protocols static route6 <prefix> next-hop <address> path-monitor monitor <name> policy <name> state non-compliant
  protocols static route6 <prefix> next-hop-routing-instance <routing-instance> next-hop <address> path-monitor monitor <name>
  protocols static route6 <prefix> next-hop-routing-instance <routing-instance> next-hop <address> path-monitor monitor <name> policy <name>
  protocols static route6 <prefix> next-hop-routing-instance <routing-instance> next-hop <address> path-monitor monitor <name> policy <name> state compliant
  protocols static route6 <prefix> next-hop-routing-instance <routing-instance> next-hop <address> path-monitor monitor <name> policy <name> state non-compliant
  protocols static route <prefix> next-hop <address> path-monitor monitor <name>
  protocols static route <prefix> next-hop <address> path-monitor monitor <name> policy <name>
  protocols static route <prefix> next-hop <address> path-monitor monitor <name> policy <name> state compliant
  protocols static route <prefix> next-hop <address> path-monitor monitor <name> policy <name> state non-compliant
  protocols static route <prefix> next-hop-routing-instance <routing-instance> next-hop <address> path-monitor monitor <name>
  protocols static route <prefix> next-hop-routing-instance <routing-instance> next-hop <address> path-monitor monitor <name> policy <name>
  protocols static route <prefix> next-hop-routing-instance <routing-instance> next-hop <address> path-monitor monitor <name> policy <name> state compliant
  protocols static route <prefix> next-hop-routing-instance <routing-instance> next-hop <address> path-monitor monitor <name> policy <name> state non-compliant
  protocols static table <table-number> interface-route6 <prefix> next-hop-interface <interface-name> path-monitor monitor <name>
  protocols static table <table-number> interface-route6 <prefix> next-hop-interface <interface-name> path-monitor monitor <name> policy <name>
  protocols static table <table-number> interface-route6 <prefix> next-hop-interface <interface-name> path-monitor monitor <name> policy <name> state compliant
  protocols static table <table-number> interface-route6 <prefix> next-hop-interface <interface-name> path-monitor monitor <name> policy <name> state non-compliant
  protocols static table <table-number> interface-route <prefix> next-hop-interface <interface-name> path-monitor monitor <name>
  protocols static table <table-number> interface-route <prefix> next-hop-interface <interface-name> path-monitor monitor <name> policy <name>
  protocols static table <table-number> interface-route <prefix> next-hop-interface <interface-name> path-monitor monitor <name> policy <name> state compliant
  protocols static table <table-number> interface-route <prefix> next-hop-interface <interface-name> path-monitor monitor <name> policy <name> state non-compliant
  protocols static table <table-number> route6 <prefix> next-hop <address> path-monitor monitor <name>
  protocols static table <table-number> route6 <prefix> next-hop <address> path-monitor monitor <name> policy <name>
  protocols static table <table-number> route6 <prefix> next-hop <address> path-monitor monitor <name> policy <name> state compliant
  protocols static table <table-number> route6 <prefix> next-hop <address> path-monitor monitor <name> policy <name> state non-compliant
  protocols static table <table-number> route <prefix> next-hop <address> path-monitor monitor <name>
  protocols static table <table-number> route <prefix> next-hop <address> path-monitor monitor <name> policy <name>
  protocols static table <table-number> route <prefix> next-hop <address> path-monitor monitor <name> policy <name> state compliant
  protocols static table <table-number> route <prefix> next-hop <address> path-monitor monitor <name> policy <name> state non-compliant
  routing routing-instance <instance-name> protocols static interface-route6 <prefix> next-hop-interface <interface-name> path-monitor monitor <name>
  routing routing-instance <instance-name> protocols static interface-route6 <prefix> next-hop-interface <interface-name> path-monitor monitor <name> policy <name>
  routing routing-instance <instance-name> protocols static interface-route6 <prefix> next-hop-interface <interface-name> path-monitor monitor <name> policy <name> state compliant
  routing routing-instance <instance-name> protocols static interface-route6 <prefix> next-hop-interface <interface-name> path-monitor monitor <name> policy <name> state non-compliant
  routing routing-instance <instance-name> protocols static interface-route6 <prefix> next-hop-routing-instance <routing-instance> next-hop-interface <interface-name> path-monitor monitor <name>
  routing routing-instance <instance-name> protocols static interface-route6 <prefix> next-hop-routing-instance <routing-instance> next-hop-interface <interface-name> path-monitor monitor <name> policy <name>
  routing routing-instance <instance-name> protocols static interface-route6 <prefix> next-hop-routing-instance <routing-instance> next-hop-interface <interface-name> path-monitor monitor <name> policy <name> state compliant
  routing routing-instance <instance-name> protocols static interface-route6 <prefix> next-hop-routing-instance <routing-instance> next-hop-interface <interface-name> path-monitor monitor <name> policy <name> state non-compliant
  routing routing-instance <instance-name> protocols static interface-route <prefix> next-hop-interface <interface-name> path-monitor monitor <name>
  routing routing-instance <instance-name> protocols static interface-route <prefix> next-hop-interface <interface-name> path-monitor monitor <name> policy <name>
  routing routing-instance <instance-name> protocols static interface-route <prefix> next-hop-interface <interface-name> path-monitor monitor <name> policy <name> state compliant
  routing routing-instance <instance-name> protocols static interface-route <prefix> next-hop-interface <interface-name> path-monitor monitor <name> policy <name> state non-compliant
  routing routing-instance <instance-name> protocols static interface-route <prefix> next-hop-routing-instance <routing-instance> next-hop-interface <interface-name> path-monitor monitor <name>
  routing routing-instance <instance-name> protocols static interface-route <prefix> next-hop-routing-instance <routing-instance> next-hop-interface <interface-name> path-monitor monitor <name> policy <name>
  routing routing-instance <instance-name> protocols static interface-route <prefix> next-hop-routing-instance <routing-instance> next-hop-interface <interface-name> path-monitor monitor <name> policy <name> state compliant
  routing routing-instance <instance-name> protocols static interface-route <prefix> next-hop-routing-instance <routing-instance> next-hop-interface <interface-name> path-monitor monitor <name> policy <name> state non-compliant
  routing routing-instance <instance-name> protocols static route6 <prefix> next-hop <address> path-monitor monitor <name>
  routing routing-instance <instance-name> protocols static route6 <prefix> next-hop <address> path-monitor monitor <name> policy <name>
  routing routing-instance <instance-name> protocols static route6 <prefix> next-hop <address> path-monitor monitor <name> policy <name> state compliant
  routing routing-instance <instance-name> protocols static route6 <prefix> next-hop <address> path-monitor monitor <name> policy <name> state non-compliant
  routing routing-instance <instance-name> protocols static route6 <prefix> next-hop-routing-instance-v6 <routing-instance> next-hop <address> path-monitor monitor <name>
  routing routing-instance <instance-name> protocols static route6 <prefix> next-hop-routing-instance-v6 <routing-instance> next-hop <address> path-monitor monitor <name> policy <name>
  routing routing-instance <instance-name> protocols static route6 <prefix> next-hop-routing-instance-v6 <routing-instance> next-hop <address> path-monitor monitor <name> policy <name> state compliant
  routing routing-instance <instance-name> protocols static route6 <prefix> next-hop-routing-instance-v6 <routing-instance> next-hop <address> path-monitor monitor <name> policy <name> state non-compliant
  routing routing-instance <instance-name> protocols static route <prefix> next-hop <address> path-monitor monitor <name>
  routing routing-instance <instance-name> protocols static route <prefix> next-hop <address> path-monitor monitor <name> policy <name>
  routing routing-instance <instance-name> protocols static route <prefix> next-hop <address> path-monitor monitor <name> policy <name> state compliant
  routing routing-instance <instance-name> protocols static route <prefix> next-hop <address> path-monitor monitor <name> policy <name> state non-compliant
  routing routing-instance <instance-name> protocols static route <prefix> next-hop-routing-instance <routing-instance> next-hop <address> path-monitor monitor <name>
  routing routing-instance <instance-name> protocols static route <prefix> next-hop-routing-instance <routing-instance> next-hop <address> path-monitor monitor <name> policy <name>
  routing routing-instance <instance-name> protocols static route <prefix> next-hop-routing-instance <routing-instance> next-hop <address> path-monitor monitor <name> policy <name> state compliant
  routing routing-instance <instance-name> protocols static route <prefix> next-hop-routing-instance <routing-instance> next-hop <address> path-monitor monitor <name> policy <name> state non-compliant
  routing routing-instance <instance-name> protocols static table <table-number> interface-route6 <prefix> next-hop-interface <interface-name> path-monitor monitor <name>
  routing routing-instance <instance-name> protocols static table <table-number> interface-route6 <prefix> next-hop-interface <interface-name> path-monitor monitor <name> policy <name>
  routing routing-instance <instance-name> protocols static table <table-number> interface-route6 <prefix> next-hop-interface <interface-name> path-monitor monitor <name> policy <name> state compliant
  routing routing-instance <instance-name> protocols static table <table-number> interface-route6 <prefix> next-hop-interface <interface-name> path-monitor monitor <name> policy <name> state non-compliant
  routing routing-instance <instance-name> protocols static table <table-number> interface-route <prefix> next-hop-interface <interface-name> path-monitor monitor <name>
  routing routing-instance <instance-name> protocols static table <table-number> interface-route <prefix> next-hop-interface <interface-name> path-monitor monitor <name> policy <name>
  routing routing-instance <instance-name> protocols static table <table-number> interface-route <prefix> next-hop-interface <interface-name> path-monitor monitor <name> policy <name> state compliant
  routing routing-instance <instance-name> protocols static table <table-number> interface-route <prefix> next-hop-interface <interface-name> path-monitor monitor <name> policy <name> state non-compliant
  routing routing-instance <instance-name> protocols static table <table-number> route6 <prefix> next-hop <address> path-monitor monitor <name>
  routing routing-instance <instance-name> protocols static table <table-number> route6 <prefix> next-hop <address> path-monitor monitor <name> policy <name>
  routing routing-instance <instance-name> protocols static table <table-number> route6 <prefix> next-hop <address> path-monitor monitor <name> policy <name> state compliant
  routing routing-instance <instance-name> protocols static table <table-number> route6 <prefix> next-hop <address> path-monitor monitor <name> policy <name> state non-compliant
  routing routing-instance <instance-name> protocols static table <table-number> route <prefix> next-hop <address> path-monitor monitor <name>
  routing routing-instance <instance-name> protocols static table <table-number> route <prefix> next-hop <address> path-monitor monitor <name> policy <name>
  routing routing-instance <instance-name> protocols static table <table-number> route <prefix> next-hop <address> path-monitor monitor <name> policy <name> state compliant
  routing routing-instance <instance-name> protocols static table <table-number> route <prefix> next-hop <address> path-monitor monitor <name> policy <name> state non-compliant
  service path-monitor monitor <name> type ping interval-delay random
  service path-monitor monitor <name> type ping interval-delay random max <value>
  service path-monitor monitor <name> type ping packets <value>

OSPF throttle enhancements

OSPF throttle enhancement commands have been added to this release.

protocols ospf process <instance> area <area-identifier> virtual-link <address> fall-over bfd
  protocols ospf process <instance> timers lsa arrival <value>
  protocols ospf process <instance> timers throttle lsa delay <value>
  protocols ospf process <instance> timers throttle lsa max-wait <value>
  protocols ospf process <instance> timers throttle lsa min-wait <value>
  protocols ospf process <instance> timers throttle spf delay <value>
  protocols ospf process <instance> timers throttle spf max-wait <value>
  protocols ospf process <instance> timers throttle spf min-wait <value>
  protocols ospf process <instance> traffic-engineering
  protocols ospf timers lsa arrival <value>
  protocols ospf timers throttle lsa delay <value>
  protocols ospf timers throttle lsa max-wait <value>
  protocols ospf timers throttle lsa min-wait <value>
  protocols ospf timers throttle spf delay <value>
  protocols ospf timers throttle spf max-wait <value>
  protocols ospf timers throttle spf min-wait <value>
  protocols ospf traffic-engineering

  routing routing-instance <instance-name> protocols ospf process <instance> timers lsa arrival <value>
  routing routing-instance <instance-name> protocols ospf process <instance> timers throttle lsa delay <value>
  routing routing-instance <instance-name> protocols ospf process <instance> timers throttle lsa max-wait <value>
  routing routing-instance <instance-name> protocols ospf process <instance> timers throttle lsa min-wait <value>
  routing routing-instance <instance-name> protocols ospf process <instance> timers throttle spf delay <value>
  routing routing-instance <instance-name> protocols ospf process <instance> timers throttle spf max-wait <value>
  routing routing-instance <instance-name> protocols ospf process <instance> timers throttle spf min-wait <value>

BGP enhancements

BGP enhancement commands have been added to this release.

protocols bgp <as-number> neighbor <address> capability disable-route-refresh
  protocols bgp <as-number> peer-group <group-name> capability disable-route-refresh
  routing routing-instance <instance-name> protocols bgp <as-number> neighbor <address> capability disable-route-refresh
  routing routing-instance <instance-name> protocols bgp <as-number> peer-group <group-name> capability disable-route-refresh

RIB enhancements

RIB enhancement commands have been added to this release.

protocols rib log bfd
  protocols rib log path-monitor
  routing routing-instance <instance-name> protocols rib log bfd

NETCONF VRF support

NETCONF VRF support commands have been added to this release.

routing routing-instance <instance-name> service netconf
  routing routing-instance <instance-name> service netconf disable

Firewall enhancements

Firewall enhancement commands have been added to this release.

security firewall icmp-strict
  security firewall name <ruleset-name> rule <rule-number> police tc <value>
  security firewall session-log tcp closed

  security zone-policy zone <input-zone-name> local-zone

Extra Small (XS) uCPE hardware switch integration system service enhancements

Extra Small (XS) uCPE hardware switch integration system service enhancement commands have been added ot this release.

system login max-sessions <value>
  system login tacplus-server <server-address> source-interface <value>
  routing routing-instance <instance-name> system login tacplus-server <server-address> source-interface <value>

  system ntp source-interface <value>
  routing routing-instance <instance-name> system ntp source-interface <value>

  security ssh-client source-interface <value>
  service ssh permit cipher 3des-cbc
  service ssh permit cipher aes128-cbc
  service ssh permit cipher aes192-cbc
  service ssh permit cipher aes256-cbc
  service ssh permit cipher blowfish-cbc
  service ssh permit cipher cast128-cbc
  routing routing-instance <instance-name> service ssh permit cipher 3des-cbc
  routing routing-instance <instance-name> service ssh permit cipher aes128-cbc
  routing routing-instance <instance-name> service ssh permit cipher aes192-cbc
  routing routing-instance <instance-name> service ssh permit cipher aes256-cbc
  routing routing-instance <instance-name> service ssh permit cipher blowfish-cbc
  routing routing-instance <instance-name> service ssh permit cipher cast128-cbc

Boot-loader enhancements

Boot-loader enhancement commands have been added to this release.

system boot-loader user <user-id>
  system boot-loader user <user-id> encrypted-password <value>
  system boot-loader user <user-id> plaintext-password <value>

  system boot-loader reduced <value>

Create custom flow classification applications

Create custom flow classification application commands have been added to this release.

service application rule <rule-number>
  service application rule <rule-number> description <value>
  service application rule <rule-number> destination address <value>
  service application rule <rule-number> destination mac-address <value>
  service application rule <rule-number> destination port <value>
  service application rule <rule-number> disable
  service application rule <rule-number> dscp af11
  service application rule <rule-number> dscp af12
  service application rule <rule-number> dscp af13
  service application rule <rule-number> dscp af21
  service application rule <rule-number> dscp af22
  service application rule <rule-number> dscp af23
  service application rule <rule-number> dscp af31
  service application rule <rule-number> dscp af32
  service application rule <rule-number> dscp af33
  service application rule <rule-number> dscp af41
  service application rule <rule-number> dscp af42
  service application rule <rule-number> dscp af43
  service application rule <rule-number> dscp cs1
  service application rule <rule-number> dscp cs2
  service application rule <rule-number> dscp cs3
  service application rule <rule-number> dscp cs4
  service application rule <rule-number> dscp cs5
  service application rule <rule-number> dscp cs6
  service application rule <rule-number> dscp cs7
  service application rule <rule-number> dscp default
  service application rule <rule-number> dscp ef
  service application rule <rule-number> dscp va
  service application rule <rule-number> dscp-group <value>
  service application rule <rule-number> ethertype <value>
  service application rule <rule-number> icmp
  service application rule <rule-number> icmp group <value>
  service application rule <rule-number> icmp name TOS-host-redirect
  service application rule <rule-number> icmp name TOS-host-unreachable
  service application rule <rule-number> icmp name TOS-network-redirect
  service application rule <rule-number> icmp name TOS-network-unreachable
  service application rule <rule-number> icmp name address-mask-reply
  service application rule <rule-number> icmp name address-mask-request
  service application rule <rule-number> icmp name communication-prohibited
  service application rule <rule-number> icmp name destination-unreachable
  service application rule <rule-number> icmp name echo-reply
  service application rule <rule-number> icmp name echo-request
  service application rule <rule-number> icmp name fragmentation-needed
  service application rule <rule-number> icmp name host-precedence-violation
  service application rule <rule-number> icmp name host-prohibited
  service application rule <rule-number> icmp name host-redirect
  service application rule <rule-number> icmp name host-unknown
  service application rule <rule-number> icmp name host-unreachable
  service application rule <rule-number> icmp name ip-header-bad
  service application rule <rule-number> icmp name network-prohibited
  service application rule <rule-number> icmp name network-redirect
  service application rule <rule-number> icmp name network-unknown
  service application rule <rule-number> icmp name network-unreachable
  service application rule <rule-number> icmp name parameter-problem
  service application rule <rule-number> icmp name port-unreachable
  service application rule <rule-number> icmp name precedence-cutoff
  service application rule <rule-number> icmp name protocol-unreachable
  service application rule <rule-number> icmp name redirect
  service application rule <rule-number> icmp name required-option-missing
  service application rule <rule-number> icmp name router-advertisement
  service application rule <rule-number> icmp name router-solicitation
  service application rule <rule-number> icmp name source-quench
  service application rule <rule-number> icmp name source-route-failed
  service application rule <rule-number> icmp name time-exceeded
  service application rule <rule-number> icmp name timestamp-reply
  service application rule <rule-number> icmp name timestamp-request
  service application rule <rule-number> icmp name ttl-zero-during-reassembly
  service application rule <rule-number> icmp name ttl-zero-during-transit
  service application rule <rule-number> icmp type <type-number>
  service application rule <rule-number> icmp type <type-number> code <value>
  service application rule <rule-number> icmpv6
  service application rule <rule-number> icmpv6 group <value>
  service application rule <rule-number> icmpv6 name address-unreachable
  service application rule <rule-number> icmpv6 name bad-header
  service application rule <rule-number> icmpv6 name communication-prohibited
  service application rule <rule-number> icmpv6 name destination-unreachable
  service application rule <rule-number> icmpv6 name echo-reply
  service application rule <rule-number> icmpv6 name echo-request
  service application rule <rule-number> icmpv6 name mobile-prefix-advertisement
  service application rule <rule-number> icmpv6 name mobile-prefix-solicitation
  service application rule <rule-number> icmpv6 name multicast-listener-done
  service application rule <rule-number> icmpv6 name multicast-listener-query
  service application rule <rule-number> icmpv6 name multicast-listener-report
  service application rule <rule-number> icmpv6 name neighbor-advertisement
  service application rule <rule-number> icmpv6 name neighbor-solicitation
  service application rule <rule-number> icmpv6 name no-route
  service application rule <rule-number> icmpv6 name packet-too-big
  service application rule <rule-number> icmpv6 name parameter-problem
  service application rule <rule-number> icmpv6 name port-unreachable
  service application rule <rule-number> icmpv6 name redirect
  service application rule <rule-number> icmpv6 name router-advertisement
  service application rule <rule-number> icmpv6 name router-solicitation
  service application rule <rule-number> icmpv6 name time-exceeded
  service application rule <rule-number> icmpv6 name ttl-zero-during-reassembly
  service application rule <rule-number> icmpv6 name ttl-zero-during-transit
  service application rule <rule-number> icmpv6 name unknown-header-type
  service application rule <rule-number> icmpv6 name unknown-option
  service application rule <rule-number> icmpv6 type <type-number>
  service application rule <rule-number> icmpv6 type <type-number> code <value>
  service application rule <rule-number> ipv6-route
  service application rule <rule-number> ipv6-route type <value>
  service application rule <rule-number> log
  service application rule <rule-number> pcp <value>
  service application rule <rule-number> protocol <value>
  service application rule <rule-number> protocol-group <value>
  service application rule <rule-number> source address <value>
  service application rule <rule-number> source mac-address <value>
  service application rule <rule-number> source port <value>
  service application rule <rule-number> tcp
  service application rule <rule-number> tcp flags <value>
  service application rule <rule-number> then name <protocol>
  service application rule <rule-number> then protocol <protocol>
  service application rule <rule-number> then type <type-value>

Access control over YANG RPCs, notifications and operational data

Access control over YANG RPCs, notifications and operational data commands have been added to this release.

system acm notification-default allow
  system acm notification-default deny
  system acm notification-ruleset
  system acm notification-ruleset rule <rule-number>
  system acm notification-ruleset rule <rule-number> action allow
  system acm notification-ruleset rule <rule-number> action deny
  system acm notification-ruleset rule <rule-number> group <value>
  system acm notification-ruleset rule <rule-number> module-name <value>
  system acm notification-ruleset rule <rule-number> notification-name <value>
  system acm rpc-default allow
  system acm rpc-default deny
  system acm rpc-ruleset
  system acm rpc-ruleset rule <rule-number>
  system acm rpc-ruleset rule <rule-number> action allow
  system acm rpc-ruleset rule <rule-number> action deny
  system acm rpc-ruleset rule <rule-number> group <value>
  system acm rpc-ruleset rule <rule-number> module-name <value>
  system acm rpc-ruleset rule <rule-number> rpc-name <value>

Power-over-ethernet (POE) support

Power-over-ethernet (POE) support commands have been added to this release.

interfaces dataplane <interface-name> poe enable

Support MSTP as spanning tree protocol

Support MSTP as spanning tree protocol commands have been added to this release.

interfaces bridge <interface-name> spanning-tree version mstp

Control logstash export of journal logs

Control logstash export of journal logs commands have been added to this release.

system journal export logstash
  system journal export logstash endpoints <endpoint>
  system journal export logstash endpoints <endpoint> hostname <value>
  system journal export logstash endpoints <endpoint> port <value>

Diamond service enhancements

Diamond service enhancement commands have been added to this release.

service diamond session-name <name> handler amqp-topic host <value>
  service diamond session-name <name> handler amqp-topic vhost <value>

Specify interface IP address for syslog messages

Specify interface IP address for syslog messages commands have been added to this release.

system syslog source-interface <value>
  routing routing-instance <instance-name> system syslog source-interface <value>