Vyatta Network OS Documentation

Learn how to install, configure and operate the Vyatta NOS, which helps drive our virtual networking & physical platforms portfolio.

Show Page Sections

CLI commands

This release contains new and updated CLI commands.

New configuration commands

This release contains updated configuration commands.

Jericho2
interfaces dataplane <tagnode> breakout-reserved-for <value>
BGP support for TCP-AO
  security key-chains key-chain <name> key <key-id> crypto-algorithm aes-128-cmac-96
  protocols bgp <tagnode> log authentication
  protocols bgp <tagnode> neighbor <tagnode> authentication
  protocols bgp <tagnode> neighbor <tagnode> authentication exclude-tcp-options
  protocols bgp <tagnode> neighbor <tagnode> authentication tcp-auth <value>
  protocols bgp <tagnode> peer-group <tagnode> authentication
  protocols bgp <tagnode> peer-group <tagnode> authentication exclude-tcp-options
  protocols bgp <tagnode> peer-group <tagnode> authentication tcp-auth <value>
  routing routing-instance <instance-name> protocols bgp <tagnode> log authentication
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> authentication
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> authentication exclude-tcp-options
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> authentication tcp-auth <value>
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> authentication
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> authentication exclude-tcp-options
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> authentication tcp-auth <value>
  security tcp-auth key-chain <name>
  security tcp-auth key-chain <name> description <value>
  security tcp-auth key-chain <name> key <key-id>
  security tcp-auth key-chain <name> key <key-id> receive-id <value>
  security tcp-auth key-chain <name> key <key-id> send-id <value>
Descriptions on static routes and tables
  protocols static interface-route <tagnode> description <value>
  protocols static interface-route6 <tagnode> description <value>
  protocols static route <tagnode> description <value>
  protocols static route6 <tagnode> description <value>
  protocols static table <tagnode> description <value>
  protocols static table <tagnode> interface-route <tagnode> description <value>
  protocols static table <tagnode> interface-route6 <tagnode> description <value>
  protocols static table <tagnode> route <tagnode> description <value>
  protocols static table <tagnode> route6 <tagnode> description <value>
  routing routing-instance <instance-name> protocols static interface-route <tagnode> description <value>
  routing routing-instance <instance-name> protocols static interface-route6 <tagnode> description <value>
  routing routing-instance <instance-name> protocols static route <tagnode> description <value>
  routing routing-instance <instance-name> protocols static route6 <tagnode> description <value>
  routing routing-instance <instance-name> protocols static table <tagnode> description <value>
  routing routing-instance <instance-name> protocols static table <tagnode> interface-route <tagnode> description <value>
  routing routing-instance <instance-name> protocols static table <tagnode> interface-route6 <tagnode> description <value>
  routing routing-instance <instance-name> protocols static table <tagnode> route <tagnode> description <value>
  routing routing-instance <instance-name> protocols static table <tagnode> route6 <tagnode> description <value>
IPsec RA VPN server – VFP support
  security vpn ipsec remote-access-server profile <profile-name> tunnel <tunnel-id> uses <value>
CGNAT
  service nat cgnat cpu-affinity event session <value>
  service nat cgnat export event port-block-allocation using kafka
  service nat cgnat export event port-block-allocation using kafka cluster <clustername>
  service nat cgnat export event port-block-allocation using kafka with field-delimiter <value>
  service nat cgnat export event port-block-allocation using kafka with key-field <name>
  service nat cgnat export event port-block-allocation using kafka with priority critical
  service nat cgnat export event port-block-allocation using kafka with storage-limit <value>
  service nat cgnat export event port-block-allocation using kafka with topic <value>
  service nat cgnat export event resource-constraint using kafka
  service nat cgnat export event resource-constraint using kafka cluster <clustername>
  service nat cgnat export event resource-constraint using kafka with field-delimiter <value>
  service nat cgnat export event resource-constraint using kafka with key-field <name>
  service nat cgnat export event resource-constraint using kafka with priority critical
  service nat cgnat export event resource-constraint using kafka with storage-limit <value>
  service nat cgnat export event resource-constraint using kafka with topic <value>
  service nat cgnat export event session using kafka
  service nat cgnat export event session using kafka cluster <clustername>
  service nat cgnat export event session using kafka with field-delimiter <value>
  service nat cgnat export event session using kafka with key-field <name>
  service nat cgnat export event session using kafka with priority critical
  service nat cgnat export event session using kafka with storage-limit <value>
  service nat cgnat export event session using kafka with topic <value>
  service nat cgnat export event subscriber using kafka
  service nat cgnat export event subscriber using kafka cluster <clustername>
  service nat cgnat export event subscriber using kafka with field-delimiter <value>
  service nat cgnat export event subscriber using kafka with key-field <name>
  service nat cgnat export event subscriber using kafka with priority critical
  service nat cgnat export event subscriber using kafka with storage-limit <value>
  service nat cgnat export event subscriber using kafka with topic <value>
  service nat cgnat log event port-block-allocation
  service nat cgnat log event resource-constraint
  service nat cgnat log event session
  service nat cgnat log event subscriber
  service nat cgnat policy <policyname> match source address-group <value>
  service nat cgnat policy <policyname> select event session address-group <value>
  service nat cgnat policy <policyname> select event session all-subscribers
  service nat cgnat policy <policyname> select event session creation
  service nat cgnat policy <policyname> select event session deletion
  service nat cgnat policy <policyname> select event session periodic <value>
  service nat cgnat policy <policyname> select event subscriber
  service nat cgnat select warning event resource-constraint mapping-table
  service nat cgnat select warning event resource-constraint mapping-table interval <value>
  service nat cgnat select warning event resource-constraint mapping-table threshold <value>
  service nat cgnat select warning event resource-constraint public-addresses
  service nat cgnat select warning event resource-constraint public-addresses interval <value>
  service nat cgnat select warning event resource-constraint public-addresses threshold <value>
  service nat cgnat select warning event resource-constraint session-table
  service nat cgnat select warning event resource-constraint session-table interval <value>
  service nat cgnat select warning event resource-constraint session-table threshold <value>
  service nat cgnat select warning event resource-constraint subscriber-table
  service nat cgnat select warning event resource-constraint subscriber-table interval <value>
  service nat cgnat select warning event resource-constraint subscriber-table threshold <value>
  service nat cgnat snat-alg-bypass
  system export kafka cluster <clustername>
  system export kafka cluster <clustername> bootstrap ipv4-address <address>
  system export kafka cluster <clustername> bootstrap ipv6-address <address>
  system export kafka cluster <clustername> bootstrap routing-instance <value>
  system export kafka cluster <clustername> bootstrap routing-instance default
  service nat pool <poolname> select event port-block-allocation
PCP
  service pcp feature-interface <name>
  service pcp feature-interface <name> template <name>
  service pcp feature-interface <name> template <name> internal-prefix <prefix>
  service pcp server <name>
  service pcp server <name> announce multicast
  service pcp server <name> announce unicast <address>
  service pcp server <name> announce unicast <address> port <value>
  service pcp server <name> listener <address>
  service pcp server <name> listener <address> port <value>
  service pcp server <name> log debug
  service pcp server <name> nonce-check <value>
  service pcp server <name> template <name>
  service pcp server <name> template <name> opcodes announce
  service pcp server <name> template <name> opcodes map
  service pcp server <name> template <name> type cgnat
  service pcp server <name> third-party
  service pcp server <name> third-party interface <name>
  routing routing-instance <instance-name> service pcp feature-interface <name>
  routing routing-instance <instance-name> service pcp feature-interface <name> template <name>
  routing routing-instance <instance-name> service pcp feature-interface <name> template <name> internal-prefix <prefix>
  routing routing-instance <instance-name> service pcp server <name>
  routing routing-instance <instance-name> service pcp server <name> announce multicast
  routing routing-instance <instance-name> service pcp server <name> announce unicast <address>
  routing routing-instance <instance-name> service pcp server <name> announce unicast <address> port <value>
  routing routing-instance <instance-name> service pcp server <name> listener <address>
  routing routing-instance <instance-name> service pcp server <name> listener <address> port <value>
  routing routing-instance <instance-name> service pcp server <name> log debug
  routing routing-instance <instance-name> service pcp server <name> nonce-check <value>
  routing routing-instance <instance-name> service pcp server <name> template <name>
  routing routing-instance <instance-name> service pcp server <name> template <name> opcodes announce
  routing routing-instance <instance-name> service pcp server <name> template <name> opcodes map
  routing routing-instance <instance-name> service pcp server <name> template <name> type cgnat
  routing routing-instance <instance-name> service pcp server <name> third-party
  routing routing-instance <instance-name> service pcp server <name> third-party interface <name>
Routing instance support for journal export to logstash
  routing routing-instance <instance-name> system journal export logstash
  routing routing-instance <instance-name> system journal export logstash endpoints <endpoint>
  routing routing-instance <instance-name> system journal export logstash endpoints <endpoint> hostname <value>
  routing routing-instance <instance-name> system journal export logstash endpoints <endpoint> port <value>
  routing routing-instance <instance-name> system journal export logstash index <value>
Configuration of neighbor discovery cache size
  system ipv6 neighbor resolution-throttling <value>
  system ipv6 neighbor table-size 65536
Rsyslog TLS
  system syslog host <tagnode> protocol tcp
  system syslog host <tagnode> protocol udp
  system syslog host <tagnode> tls
  system syslog host <tagnode> tls authentication mode x509/fingerprint
  system syslog host <tagnode> tls authentication mode x509/name
  system syslog host <tagnode> tls authentication peers <peer>
  system syslog host <tagnode> tls authentication peers <peer> fingerprint <value>
  system syslog host <tagnode> tls certificate-authority <CA>
  system syslog host <tagnode> tls certificate-authority <CA> file <value>
  system syslog host <tagnode> tls cipher-suite <cipher>
  system syslog host <tagnode> tls local-certificate certificate <value>
  system syslog host <tagnode> tls local-certificate key <value>
  routing routing-instance <instance-name> system syslog host <tagnode> protocol tcp
  routing routing-instance <instance-name> system syslog host <tagnode> protocol udp
  routing routing-instance <instance-name> system syslog host <tagnode> tls
  routing routing-instance <instance-name> system syslog host <tagnode> tls authentication mode x509/fingerprint
  routing routing-instance <instance-name> system syslog host <tagnode> tls authentication mode x509/name
  routing routing-instance <instance-name> system syslog host <tagnode> tls authentication peers <peer>
  routing routing-instance <instance-name> system syslog host <tagnode> tls authentication peers <peer> fingerprint <value>
  routing routing-instance <instance-name> system syslog host <tagnode> tls certificate-authority <CA>
  routing routing-instance <instance-name> system syslog host <tagnode> tls certificate-authority <CA> file <value>
  routing routing-instance <instance-name> system syslog host <tagnode> tls cipher-suite <cipher>
  routing routing-instance <instance-name> system syslog host <tagnode> tls local-certificate certificate <value>
  routing routing-instance <instance-name> system syslog host <tagnode> tls local-certificate key <value>
VRRP route tracking
  interfaces bonding <tagnode> vif <tagnode> vrrp vrrp-group <tagnode> track route-to <route>
  interfaces bonding <tagnode> vif <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight
  interfaces bonding <tagnode> vif <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight type decrement
  interfaces bonding <tagnode> vif <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight type increment
  interfaces bonding <tagnode> vif <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight value <value>
  interfaces bonding <tagnode> vrrp vrrp-group <tagnode> track route-to <route>
  interfaces bonding <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight
  interfaces bonding <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight type decrement
  interfaces bonding <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight type increment
  interfaces bonding <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight value <value>
  interfaces dataplane <tagnode> vif <tagnode> vrrp vrrp-group <tagnode> track route-to <route>
  interfaces dataplane <tagnode> vif <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight
  interfaces dataplane <tagnode> vif <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight type decrement
  interfaces dataplane <tagnode> vif <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight type increment
  interfaces dataplane <tagnode> vif <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight value <value>
  interfaces dataplane <tagnode> vrrp vrrp-group <tagnode> track route-to <route>
  interfaces dataplane <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight
  interfaces dataplane <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight type decrement
  interfaces dataplane <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight type increment
  interfaces dataplane <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight value <value>

Modified commands

A command has been modified in this release.

service nat cgnat policy <policyname> match source ip-address prefix <value>
has been replaced with
service nat cgnat policy <policyname> match source address-group <value>

Modified defaults

No default values have changed in this release.

Deprecated commands

This section lists the commands that have been deprecated in this release.

OpenVPN
  interfaces openvpn <tunnel-interface-name>
  interfaces openvpn <tunnel-interface-name> auth
  interfaces openvpn <tunnel-interface-name> auth ldap <value>
  interfaces openvpn <tunnel-interface-name> auth local
  interfaces openvpn <tunnel-interface-name> auth local group <value>
  interfaces openvpn <tunnel-interface-name> auth local user <value>
  interfaces openvpn <tunnel-interface-name> client-cert-not-required
  interfaces openvpn <tunnel-interface-name> description <value>
  interfaces openvpn <tunnel-interface-name> device-type <value>
  interfaces openvpn <tunnel-interface-name> disable
  interfaces openvpn <tunnel-interface-name> encryption <value>
  interfaces openvpn <tunnel-interface-name> hash <value>
  interfaces openvpn <tunnel-interface-name> ipv6
  interfaces openvpn <tunnel-interface-name> local-address <value>
  interfaces openvpn <tunnel-interface-name> local-host <value>
  interfaces openvpn <tunnel-interface-name> local-port <value>
  interfaces openvpn <tunnel-interface-name> mode <value>
  interfaces openvpn <tunnel-interface-name> openvpn-option <value>
  interfaces openvpn <tunnel-interface-name> protocol <value>
  interfaces openvpn <tunnel-interface-name> remote-address <value>
  interfaces openvpn <tunnel-interface-name> remote-host <value>
  interfaces openvpn <tunnel-interface-name> remote-port <value>
  interfaces openvpn <tunnel-interface-name> replace-default-route
  interfaces openvpn <tunnel-interface-name> replace-default-route local
  interfaces openvpn <tunnel-interface-name> server
  interfaces openvpn <tunnel-interface-name> server client <client>
  interfaces openvpn <tunnel-interface-name> server client <client> disable
  interfaces openvpn <tunnel-interface-name> server client <client> ip <value>
  interfaces openvpn <tunnel-interface-name> server client <client> push-route <value>
  interfaces openvpn <tunnel-interface-name> server client <client> subnet <value>
  interfaces openvpn <tunnel-interface-name> server domain-name <value>
  interfaces openvpn <tunnel-interface-name> server max-connections <value>
  interfaces openvpn <tunnel-interface-name> server name-server <value>
  interfaces openvpn <tunnel-interface-name> server push-route <value>
  interfaces openvpn <tunnel-interface-name> server subnet <value>
  interfaces openvpn <tunnel-interface-name> server topology <value>
  interfaces openvpn <tunnel-interface-name> shared-secret-key-file <value>
  interfaces openvpn <tunnel-interface-name> tls
  interfaces openvpn <tunnel-interface-name> tls ca-cert-file <value>
  interfaces openvpn <tunnel-interface-name> tls cert-file <value>
  interfaces openvpn <tunnel-interface-name> tls crl-file <value>
  interfaces openvpn <tunnel-interface-name> tls dh-file <value>
  interfaces openvpn <tunnel-interface-name> tls key-file <value>
  interfaces openvpn <tunnel-interface-name> tls role <value>

  interfaces switch-state switches <bridge-name> interfaces <port-name> forwarding-database <index>
  interfaces switch-state switches <bridge-name> interfaces <port-name> forwarding-database <index> mac <value>
  interfaces switch-state switches <bridge-name> interfaces <port-name> forwarding-database <index> state <value>
  interfaces switch-state switches <bridge-name> interfaces <port-name> forwarding-database <index> updated <value>
  interfaces switch-state switches <bridge-name> interfaces <port-name> forwarding-database <index> used <value>
  interfaces switch-state switches <bridge-name> interfaces <port-name> forwarding-database <index> vlan-id <value>

  interfaces openvpn <tunnel-interface-name> ip tcp-mss
  interfaces openvpn <tunnel-interface-name> ip tcp-mss limit <value>
  interfaces openvpn <tunnel-interface-name> ip tcp-mss mtu
  interfaces openvpn <tunnel-interface-name> ip tcp-mss mtu-minus <value>
  interfaces openvpn <tunnel-interface-name> ipv6 tcp-mss
  interfaces openvpn <tunnel-interface-name> ipv6 tcp-mss limit <value>
  interfaces openvpn <tunnel-interface-name> ipv6 tcp-mss mtu
  interfaces openvpn <tunnel-interface-name> ipv6 tcp-mss mtu-minus <value>

  interfaces openvpn <tunnel-interface-name> ipv6 address
  interfaces openvpn <tunnel-interface-name> ipv6 address autoconf
  interfaces openvpn <tunnel-interface-name> ipv6 address eui64 <value>
  interfaces openvpn <tunnel-interface-name> ipv6 address link-local <value>
  interfaces openvpn <tunnel-interface-name> ipv6 disable
  interfaces openvpn <tunnel-interface-name> ipv6 disable-forwarding
  interfaces openvpn <tunnel-interface-name> ipv6 dup-addr-detect-transmits <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert cur-hop-limit <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert default-lifetime <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert default-preference <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert link-mtu <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert managed-flag <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert max-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert min-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert other-config-flag <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert prefix <address>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert prefix <address> autonomous-flag <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert prefix <address> on-link-flag <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert prefix <address> preferred-lifetime <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert prefix <address> valid-lifetime <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert reachable-time <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert retrans-timer <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert send-advert <value>

  interfaces openvpn <tunnel-interface-name> ip multicast
  interfaces openvpn <tunnel-interface-name> ip multicast ttl-threshold <value>

  interfaces openvpn <tunnel-interface-name> remote-configuration
  interfaces openvpn <tunnel-interface-name> remote-configuration password <value>
  interfaces openvpn <tunnel-interface-name> remote-configuration server <value>
  interfaces openvpn <tunnel-interface-name> remote-configuration tunnel-password <value>
  interfaces openvpn <tunnel-interface-name> remote-configuration tunnel-username <value>
  interfaces openvpn <tunnel-interface-name> remote-configuration username <value>

  interfaces openvpn <tunnel-interface-name> policy route pbr <value>
  interfaces openvpn <tunnel-interface-name> policy route pbr-state name <group-name>
  interfaces openvpn <tunnel-interface-name> policy route pbr-state name <group-name> rule <rule-number>
  interfaces openvpn <tunnel-interface-name> policy route pbr-state name <group-name> rule <rule-number> bytes <value>
  interfaces openvpn <tunnel-interface-name> policy route pbr-state name <group-name> rule <rule-number> packets <value>

  interfaces openvpn <tunnel-interface-name> ip igmp
  interfaces openvpn <tunnel-interface-name> ip igmp access-group <value>
  interfaces openvpn <tunnel-interface-name> ip igmp enforce-router-alert
  interfaces openvpn <tunnel-interface-name> ip igmp immediate-leave group-list <value>
  interfaces openvpn <tunnel-interface-name> ip igmp join-group <multicast-group>
  interfaces openvpn <tunnel-interface-name> ip igmp join-group <multicast-group> source <value>
  interfaces openvpn <tunnel-interface-name> ip igmp last-member-query-count <value>
  interfaces openvpn <tunnel-interface-name> ip igmp last-member-query-interval <value>
  interfaces openvpn <tunnel-interface-name> ip igmp limit <value>
  interfaces openvpn <tunnel-interface-name> ip igmp limit-exception <value>
  interfaces openvpn <tunnel-interface-name> ip igmp offlink
  interfaces openvpn <tunnel-interface-name> ip igmp querier
  interfaces openvpn <tunnel-interface-name> ip igmp querier forced
  interfaces openvpn <tunnel-interface-name> ip igmp querier querier-timeout <value>
  interfaces openvpn <tunnel-interface-name> ip igmp query-interval <value>
  interfaces openvpn <tunnel-interface-name> ip igmp query-max-response-time <value>
  interfaces openvpn <tunnel-interface-name> ip igmp robustness-variable <value>
  interfaces openvpn <tunnel-interface-name> ip igmp startup-query-count <value>
  interfaces openvpn <tunnel-interface-name> ip igmp startup-query-interval <value>
  interfaces openvpn <tunnel-interface-name> ip igmp static-group <multicast-group>
  interfaces openvpn <tunnel-interface-name> ip igmp static-group <multicast-group> source <value>
  interfaces openvpn <tunnel-interface-name> ip igmp version <value>

  interfaces openvpn <tunnel-interface-name> ipv6 mld
  interfaces openvpn <tunnel-interface-name> ipv6 mld access-group <value>
  interfaces openvpn <tunnel-interface-name> ipv6 mld immediate-leave
  interfaces openvpn <tunnel-interface-name> ipv6 mld immediate-leave group-list <value>
  interfaces openvpn <tunnel-interface-name> ipv6 mld last-member-query-count <value>
  interfaces openvpn <tunnel-interface-name> ipv6 mld last-member-query-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 mld limit <value>
  interfaces openvpn <tunnel-interface-name> ipv6 mld limit-exception <value>
  interfaces openvpn <tunnel-interface-name> ipv6 mld querier-timeout <value>
  interfaces openvpn <tunnel-interface-name> ipv6 mld query-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 mld query-max-response-time <value>
  interfaces openvpn <tunnel-interface-name> ipv6 mld robustness-variable <value>
  interfaces openvpn <tunnel-interface-name> ipv6 mld static-group <multicast-group>
  interfaces openvpn <tunnel-interface-name> ipv6 mld static-group <multicast-group> source <value>
  interfaces openvpn <tunnel-interface-name> ipv6 mld version <value>

  interfaces openvpn <tunnel-interface-name> ip ospf
  interfaces openvpn <tunnel-interface-name> ip ospf authentication
  interfaces openvpn <tunnel-interface-name> ip ospf authentication key-chain <value>
  interfaces openvpn <tunnel-interface-name> ip ospf authentication md5
  interfaces openvpn <tunnel-interface-name> ip ospf authentication md5-key-id <key-id>
  interfaces openvpn <tunnel-interface-name> ip ospf authentication md5-key-id <key-id> md5-key <value>
  interfaces openvpn <tunnel-interface-name> ip ospf authentication plaintext
  interfaces openvpn <tunnel-interface-name> ip ospf authentication plaintext-password <value>
  interfaces openvpn <tunnel-interface-name> ip ospf cost <value>
  interfaces openvpn <tunnel-interface-name> ip ospf dead-interval <value>
  interfaces openvpn <tunnel-interface-name> ip ospf hello-interval <value>
  interfaces openvpn <tunnel-interface-name> ip ospf mtu-ignore
  interfaces openvpn <tunnel-interface-name> ip ospf network <value>
  interfaces openvpn <tunnel-interface-name> ip ospf priority <value>
  interfaces openvpn <tunnel-interface-name> ip ospf retransmit-interval <value>
  interfaces openvpn <tunnel-interface-name> ip ospf transmit-delay <value>

  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 area <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 authentication key-chain <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 cost <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 dead-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 hello-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 instance-id <instance-id>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 instance-id <instance-id> area <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 instance-id <instance-id> cost <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 instance-id <instance-id> dead-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 instance-id <instance-id> hello-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 instance-id <instance-id> link-lsa-suppression <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 instance-id <instance-id> mtu-ignore
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 instance-id <instance-id> neighbor <address>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 instance-id <instance-id> network <network-type>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 instance-id <instance-id> priority <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 instance-id <instance-id> retransmit-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 instance-id <instance-id> transmit-delay <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 link-lsa-suppression <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 mtu-ignore
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 neighbor <address>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 network <network-type>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 priority <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id> area <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id> authentication key-chain <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id> cost <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id> dead-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id> hello-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id> link-lsa-suppression <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id> mtu-ignore
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id> neighbor <address>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id> network <network-type>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id> priority <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id> retransmit-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id> transmit-delay <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 retransmit-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 transmit-delay <value>

  interfaces openvpn <tunnel-interface-name> ip pim
  interfaces openvpn <tunnel-interface-name> ip pim bsr-border
  interfaces openvpn <tunnel-interface-name> ip pim dr-priority <value>
  interfaces openvpn <tunnel-interface-name> ip pim exclude-genid
  interfaces openvpn <tunnel-interface-name> ip pim hello-holdtime <value>
  interfaces openvpn <tunnel-interface-name> ip pim hello-interval <value>
  interfaces openvpn <tunnel-interface-name> ip pim mode <value>
  interfaces openvpn <tunnel-interface-name> ip pim neighbor-filter <value>
  interfaces openvpn <tunnel-interface-name> ip pim propagation-delay <value>
  interfaces openvpn <tunnel-interface-name> ip pim state-refresh
  interfaces openvpn <tunnel-interface-name> ip pim state-refresh origination-interval <value>
  interfaces openvpn <tunnel-interface-name> ip pim unicast-bsm

  interfaces openvpn <tunnel-interface-name> ipv6 pim
  interfaces openvpn <tunnel-interface-name> ipv6 pim bsr-border
  interfaces openvpn <tunnel-interface-name> ipv6 pim dr-priority <value>
  interfaces openvpn <tunnel-interface-name> ipv6 pim exclude-genid
  interfaces openvpn <tunnel-interface-name> ipv6 pim hello-holdtime <value>
  interfaces openvpn <tunnel-interface-name> ipv6 pim hello-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 pim mode <value>
  interfaces openvpn <tunnel-interface-name> ipv6 pim neighbor-filter <value>
  interfaces openvpn <tunnel-interface-name> ipv6 pim propagation-delay <value>
  interfaces openvpn <tunnel-interface-name> ipv6 pim state-refresh
  interfaces openvpn <tunnel-interface-name> ipv6 pim state-refresh origination-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 pim unicast-bsm

  interfaces openvpn <tunnel-interface-name> ip rip authentication
  interfaces openvpn <tunnel-interface-name> ip rip authentication md5 <id>
  interfaces openvpn <tunnel-interface-name> ip rip authentication md5 <id> password <value>
  interfaces openvpn <tunnel-interface-name> ip rip authentication plaintext-password <value>
  interfaces openvpn <tunnel-interface-name> ip rip receive
  interfaces openvpn <tunnel-interface-name> ip rip receive version <value>
  interfaces openvpn <tunnel-interface-name> ip rip send
  interfaces openvpn <tunnel-interface-name> ip rip send version <value>
  interfaces openvpn <tunnel-interface-name> ip rip split-horizon
  interfaces openvpn <tunnel-interface-name> ip rip split-horizon disable
  interfaces openvpn <tunnel-interface-name> ip rip split-horizon poison-reverse

  interfaces openvpn <tunnel-interface-name> ipv6 ripng enable
  interfaces openvpn <tunnel-interface-name> ipv6 ripng metric-offset <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ripng neighbor <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ripng split-horizon
  interfaces openvpn <tunnel-interface-name> ipv6 ripng split-horizon disable
  interfaces openvpn <tunnel-interface-name> ipv6 ripng split-horizon poison-reverse

  interfaces openvpn <tunnel-interface-name> firewall in <value>
  interfaces openvpn <tunnel-interface-name> firewall local <value>
  interfaces openvpn <tunnel-interface-name> firewall out <value>
  interfaces openvpn <tunnel-interface-name> firewall state in name <group-name>
  interfaces openvpn <tunnel-interface-name> firewall state in name <group-name> rule <rule-number>
  interfaces openvpn <tunnel-interface-name> firewall state in name <group-name> rule <rule-number> bytes <value>
  interfaces openvpn <tunnel-interface-name> firewall state in name <group-name> rule <rule-number> packets <value>
  interfaces openvpn <tunnel-interface-name> firewall state local name <group-name>
  interfaces openvpn <tunnel-interface-name> firewall state local name <group-name> rule <rule-number>
  interfaces openvpn <tunnel-interface-name> firewall state local name <group-name> rule <rule-number> bytes <value>
  interfaces openvpn <tunnel-interface-name> firewall state local name <group-name> rule <rule-number> packets <value>
  interfaces openvpn <tunnel-interface-name> firewall state out name <group-name>
  interfaces openvpn <tunnel-interface-name> firewall state out name <group-name> rule <rule-number>
  interfaces openvpn <tunnel-interface-name> firewall state out name <group-name> rule <rule-number> bytes <value>
  interfaces openvpn <tunnel-interface-name> firewall state out name <group-name> rule <rule-number> packets <value>

  interfaces openvpn <tunnel-interface-name> client-bundle
  interfaces openvpn <tunnel-interface-name> client-bundle generic
  interfaces openvpn <tunnel-interface-name> client-bundle linux
  interfaces openvpn <tunnel-interface-name> client-bundle osx
  interfaces openvpn <tunnel-interface-name> client-bundle windows
L2TP/IPsec remote-access VPN server
  security vpn l2tp
  security vpn l2tp remote-access
  security vpn l2tp remote-access authentication
  security vpn l2tp remote-access authentication local-users
  security vpn l2tp remote-access authentication local-users username <name>
  security vpn l2tp remote-access authentication local-users username <name> disable
  security vpn l2tp remote-access authentication local-users username <name> password <value>
  security vpn l2tp remote-access authentication local-users username <name> static-ip <value>
  security vpn l2tp remote-access authentication mode <value>
  security vpn l2tp remote-access authentication radius-server <server-address>
  security vpn l2tp remote-access authentication radius-server <server-address> key <value>
  security vpn l2tp remote-access client-ip-pool
  security vpn l2tp remote-access client-ip-pool start <value>
  security vpn l2tp remote-access client-ip-pool stop <value>
  security vpn l2tp remote-access description <value>
  security vpn l2tp remote-access dhcp-interface <value>
  security vpn l2tp remote-access dns-servers
  security vpn l2tp remote-access dns-servers server-1 <value>
  security vpn l2tp remote-access dns-servers server-2 <value>
  security vpn l2tp remote-access ipsec-settings
  security vpn l2tp remote-access ipsec-settings authentication
  security vpn l2tp remote-access ipsec-settings authentication mode <value>
  security vpn l2tp remote-access ipsec-settings authentication pre-shared-secret <value>
  security vpn l2tp remote-access ipsec-settings authentication x509
  security vpn l2tp remote-access ipsec-settings authentication x509 ca-cert-file <value>
  security vpn l2tp remote-access ipsec-settings authentication x509 crl-file <value>
  security vpn l2tp remote-access ipsec-settings authentication x509 server-cert-file <value>
  security vpn l2tp remote-access ipsec-settings authentication x509 server-key-file <value>
  security vpn l2tp remote-access ipsec-settings authentication x509 server-key-password <value>
  security vpn l2tp remote-access ipsec-settings ike-lifetime <value>
  security vpn l2tp remote-access mtu <value>
  security vpn l2tp remote-access outside-address <value>
  security vpn l2tp remote-access outside-nexthop <value>
  security vpn l2tp remote-access server-ip-pool
  security vpn l2tp remote-access server-ip-pool start <value>
  security vpn l2tp remote-access server-ip-pool stop <value>
  security vpn l2tp remote-access wins-servers
  security vpn l2tp remote-access wins-servers server-1 <value>
  security vpn l2tp remote-access wins-servers server-2 <value>
NAT
  service nat ipv6-to-ipv4
  service nat ipv6-to-ipv4 rule <rule-number>
  service nat ipv6-to-ipv4 rule <rule-number> destination prefix <value>
  service nat ipv6-to-ipv4 rule <rule-number> inbound-interface <value>
  service nat ipv6-to-ipv4 rule <rule-number> source prefix <value>
System management
  system config-management commit-archive location <value>
  routing routing-instance <instance-name> system config-management commit-archive location <value>

Obsolete commands

A range of configuration commands have been obsoleted in this release.

  system alg rsh disable
  routing routing-instance <instance-name> system alg rsh disable