Vyatta NOS documentation

Learn how to install, configure, and operate Vyatta Network Operating System (Vyatta NOS), which helps to drive our virtual networking and physical platforms portfolio.

Show Page Sections

CLI commands

This release contains new and updated CLI commands.

New configuration commands

This release contains updated configuration commands.

Jericho2
interfaces dataplane <tagnode> breakout-reserved-for <value>
BGP support for TCP-AO
  security key-chains key-chain <name> key <key-id> crypto-algorithm aes-128-cmac-96
  protocols bgp <tagnode> log authentication
  protocols bgp <tagnode> neighbor <tagnode> authentication
  protocols bgp <tagnode> neighbor <tagnode> authentication exclude-tcp-options
  protocols bgp <tagnode> neighbor <tagnode> authentication tcp-auth <value>
  protocols bgp <tagnode> peer-group <tagnode> authentication
  protocols bgp <tagnode> peer-group <tagnode> authentication exclude-tcp-options
  protocols bgp <tagnode> peer-group <tagnode> authentication tcp-auth <value>
  routing routing-instance <instance-name> protocols bgp <tagnode> log authentication
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> authentication
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> authentication exclude-tcp-options
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> authentication tcp-auth <value>
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> authentication
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> authentication exclude-tcp-options
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> authentication tcp-auth <value>
  security tcp-auth key-chain <name>
  security tcp-auth key-chain <name> description <value>
  security tcp-auth key-chain <name> key <key-id>
  security tcp-auth key-chain <name> key <key-id> receive-id <value>
  security tcp-auth key-chain <name> key <key-id> send-id <value>
Descriptions on static routes and tables
  protocols static interface-route <tagnode> description <value>
  protocols static interface-route6 <tagnode> description <value>
  protocols static route <tagnode> description <value>
  protocols static route6 <tagnode> description <value>
  protocols static table <tagnode> description <value>
  protocols static table <tagnode> interface-route <tagnode> description <value>
  protocols static table <tagnode> interface-route6 <tagnode> description <value>
  protocols static table <tagnode> route <tagnode> description <value>
  protocols static table <tagnode> route6 <tagnode> description <value>
  routing routing-instance <instance-name> protocols static interface-route <tagnode> description <value>
  routing routing-instance <instance-name> protocols static interface-route6 <tagnode> description <value>
  routing routing-instance <instance-name> protocols static route <tagnode> description <value>
  routing routing-instance <instance-name> protocols static route6 <tagnode> description <value>
  routing routing-instance <instance-name> protocols static table <tagnode> description <value>
  routing routing-instance <instance-name> protocols static table <tagnode> interface-route <tagnode> description <value>
  routing routing-instance <instance-name> protocols static table <tagnode> interface-route6 <tagnode> description <value>
  routing routing-instance <instance-name> protocols static table <tagnode> route <tagnode> description <value>
  routing routing-instance <instance-name> protocols static table <tagnode> route6 <tagnode> description <value>
IPsec RA VPN server – VFP support
  security vpn ipsec remote-access-server profile <profile-name> tunnel <tunnel-id> uses <value>
CGNAT
  service nat cgnat cpu-affinity event session <value>
  service nat cgnat export event port-block-allocation using kafka
  service nat cgnat export event port-block-allocation using kafka cluster <clustername>
  service nat cgnat export event port-block-allocation using kafka with field-delimiter <value>
  service nat cgnat export event port-block-allocation using kafka with key-field <name>
  service nat cgnat export event port-block-allocation using kafka with priority critical
  service nat cgnat export event port-block-allocation using kafka with storage-limit <value>
  service nat cgnat export event port-block-allocation using kafka with topic <value>
  service nat cgnat export event resource-constraint using kafka
  service nat cgnat export event resource-constraint using kafka cluster <clustername>
  service nat cgnat export event resource-constraint using kafka with field-delimiter <value>
  service nat cgnat export event resource-constraint using kafka with key-field <name>
  service nat cgnat export event resource-constraint using kafka with priority critical
  service nat cgnat export event resource-constraint using kafka with storage-limit <value>
  service nat cgnat export event resource-constraint using kafka with topic <value>
  service nat cgnat export event session using kafka
  service nat cgnat export event session using kafka cluster <clustername>
  service nat cgnat export event session using kafka with field-delimiter <value>
  service nat cgnat export event session using kafka with key-field <name>
  service nat cgnat export event session using kafka with priority critical
  service nat cgnat export event session using kafka with storage-limit <value>
  service nat cgnat export event session using kafka with topic <value>
  service nat cgnat export event subscriber using kafka
  service nat cgnat export event subscriber using kafka cluster <clustername>
  service nat cgnat export event subscriber using kafka with field-delimiter <value>
  service nat cgnat export event subscriber using kafka with key-field <name>
  service nat cgnat export event subscriber using kafka with priority critical
  service nat cgnat export event subscriber using kafka with storage-limit <value>
  service nat cgnat export event subscriber using kafka with topic <value>
  service nat cgnat log event port-block-allocation
  service nat cgnat log event resource-constraint
  service nat cgnat log event session
  service nat cgnat log event subscriber
  service nat cgnat policy <policyname> match source address-group <value>
  service nat cgnat policy <policyname> select event session address-group <value>
  service nat cgnat policy <policyname> select event session all-subscribers
  service nat cgnat policy <policyname> select event session creation
  service nat cgnat policy <policyname> select event session deletion
  service nat cgnat policy <policyname> select event session periodic <value>
  service nat cgnat policy <policyname> select event subscriber
  service nat cgnat select warning event resource-constraint mapping-table
  service nat cgnat select warning event resource-constraint mapping-table interval <value>
  service nat cgnat select warning event resource-constraint mapping-table threshold <value>
  service nat cgnat select warning event resource-constraint public-addresses
  service nat cgnat select warning event resource-constraint public-addresses interval <value>
  service nat cgnat select warning event resource-constraint public-addresses threshold <value>
  service nat cgnat select warning event resource-constraint session-table
  service nat cgnat select warning event resource-constraint session-table interval <value>
  service nat cgnat select warning event resource-constraint session-table threshold <value>
  service nat cgnat select warning event resource-constraint subscriber-table
  service nat cgnat select warning event resource-constraint subscriber-table interval <value>
  service nat cgnat select warning event resource-constraint subscriber-table threshold <value>
  service nat cgnat snat-alg-bypass
  system export kafka cluster <clustername>
  system export kafka cluster <clustername> bootstrap ipv4-address <address>
  system export kafka cluster <clustername> bootstrap ipv6-address <address>
  system export kafka cluster <clustername> bootstrap routing-instance <value>
  system export kafka cluster <clustername> bootstrap routing-instance default
  service nat pool <poolname> select event port-block-allocation
PCP
  service pcp feature-interface <name>
  service pcp feature-interface <name> template <name>
  service pcp feature-interface <name> template <name> internal-prefix <prefix>
  service pcp server <name>
  service pcp server <name> announce multicast
  service pcp server <name> announce unicast <address>
  service pcp server <name> announce unicast <address> port <value>
  service pcp server <name> listener <address>
  service pcp server <name> listener <address> port <value>
  service pcp server <name> log debug
  service pcp server <name> nonce-check <value>
  service pcp server <name> template <name>
  service pcp server <name> template <name> opcodes announce
  service pcp server <name> template <name> opcodes map
  service pcp server <name> template <name> type cgnat
  service pcp server <name> third-party
  service pcp server <name> third-party interface <name>
  routing routing-instance <instance-name> service pcp feature-interface <name>
  routing routing-instance <instance-name> service pcp feature-interface <name> template <name>
  routing routing-instance <instance-name> service pcp feature-interface <name> template <name> internal-prefix <prefix>
  routing routing-instance <instance-name> service pcp server <name>
  routing routing-instance <instance-name> service pcp server <name> announce multicast
  routing routing-instance <instance-name> service pcp server <name> announce unicast <address>
  routing routing-instance <instance-name> service pcp server <name> announce unicast <address> port <value>
  routing routing-instance <instance-name> service pcp server <name> listener <address>
  routing routing-instance <instance-name> service pcp server <name> listener <address> port <value>
  routing routing-instance <instance-name> service pcp server <name> log debug
  routing routing-instance <instance-name> service pcp server <name> nonce-check <value>
  routing routing-instance <instance-name> service pcp server <name> template <name>
  routing routing-instance <instance-name> service pcp server <name> template <name> opcodes announce
  routing routing-instance <instance-name> service pcp server <name> template <name> opcodes map
  routing routing-instance <instance-name> service pcp server <name> template <name> type cgnat
  routing routing-instance <instance-name> service pcp server <name> third-party
  routing routing-instance <instance-name> service pcp server <name> third-party interface <name>
Routing instance support for journal export to logstash
  routing routing-instance <instance-name> system journal export logstash
  routing routing-instance <instance-name> system journal export logstash endpoints <endpoint>
  routing routing-instance <instance-name> system journal export logstash endpoints <endpoint> hostname <value>
  routing routing-instance <instance-name> system journal export logstash endpoints <endpoint> port <value>
  routing routing-instance <instance-name> system journal export logstash index <value>
Configuration of neighbor discovery cache size
  system ipv6 neighbor resolution-throttling <value>
  system ipv6 neighbor table-size 65536
Rsyslog TLS
  system syslog host <tagnode> protocol tcp
  system syslog host <tagnode> protocol udp
  system syslog host <tagnode> tls
  system syslog host <tagnode> tls authentication mode x509/fingerprint
  system syslog host <tagnode> tls authentication mode x509/name
  system syslog host <tagnode> tls authentication peers <peer>
  system syslog host <tagnode> tls authentication peers <peer> fingerprint <value>
  system syslog host <tagnode> tls certificate-authority <CA>
  system syslog host <tagnode> tls certificate-authority <CA> file <value>
  system syslog host <tagnode> tls cipher-suite <cipher>
  system syslog host <tagnode> tls local-certificate certificate <value>
  system syslog host <tagnode> tls local-certificate key <value>
  routing routing-instance <instance-name> system syslog host <tagnode> protocol tcp
  routing routing-instance <instance-name> system syslog host <tagnode> protocol udp
  routing routing-instance <instance-name> system syslog host <tagnode> tls
  routing routing-instance <instance-name> system syslog host <tagnode> tls authentication mode x509/fingerprint
  routing routing-instance <instance-name> system syslog host <tagnode> tls authentication mode x509/name
  routing routing-instance <instance-name> system syslog host <tagnode> tls authentication peers <peer>
  routing routing-instance <instance-name> system syslog host <tagnode> tls authentication peers <peer> fingerprint <value>
  routing routing-instance <instance-name> system syslog host <tagnode> tls certificate-authority <CA>
  routing routing-instance <instance-name> system syslog host <tagnode> tls certificate-authority <CA> file <value>
  routing routing-instance <instance-name> system syslog host <tagnode> tls cipher-suite <cipher>
  routing routing-instance <instance-name> system syslog host <tagnode> tls local-certificate certificate <value>
  routing routing-instance <instance-name> system syslog host <tagnode> tls local-certificate key <value>
VRRP route tracking
  interfaces bonding <tagnode> vif <tagnode> vrrp vrrp-group <tagnode> track route-to <route>
  interfaces bonding <tagnode> vif <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight
  interfaces bonding <tagnode> vif <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight type decrement
  interfaces bonding <tagnode> vif <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight type increment
  interfaces bonding <tagnode> vif <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight value <value>
  interfaces bonding <tagnode> vrrp vrrp-group <tagnode> track route-to <route>
  interfaces bonding <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight
  interfaces bonding <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight type decrement
  interfaces bonding <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight type increment
  interfaces bonding <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight value <value>
  interfaces dataplane <tagnode> vif <tagnode> vrrp vrrp-group <tagnode> track route-to <route>
  interfaces dataplane <tagnode> vif <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight
  interfaces dataplane <tagnode> vif <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight type decrement
  interfaces dataplane <tagnode> vif <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight type increment
  interfaces dataplane <tagnode> vif <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight value <value>
  interfaces dataplane <tagnode> vrrp vrrp-group <tagnode> track route-to <route>
  interfaces dataplane <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight
  interfaces dataplane <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight type decrement
  interfaces dataplane <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight type increment
  interfaces dataplane <tagnode> vrrp vrrp-group <tagnode> track route-to <route> weight value <value>

Modified commands

A command has been modified in this release.

service nat cgnat policy <policyname> match source ip-address prefix <value>
has been replaced with
service nat cgnat policy <policyname> match source address-group <value>

Modified defaults

No default values have changed in this release.

Deprecated commands

This section lists the commands that have been deprecated in this release.

OpenVPN
  interfaces openvpn <tunnel-interface-name>
  interfaces openvpn <tunnel-interface-name> auth
  interfaces openvpn <tunnel-interface-name> auth ldap <value>
  interfaces openvpn <tunnel-interface-name> auth local
  interfaces openvpn <tunnel-interface-name> auth local group <value>
  interfaces openvpn <tunnel-interface-name> auth local user <value>
  interfaces openvpn <tunnel-interface-name> client-cert-not-required
  interfaces openvpn <tunnel-interface-name> description <value>
  interfaces openvpn <tunnel-interface-name> device-type <value>
  interfaces openvpn <tunnel-interface-name> disable
  interfaces openvpn <tunnel-interface-name> encryption <value>
  interfaces openvpn <tunnel-interface-name> hash <value>
  interfaces openvpn <tunnel-interface-name> ipv6
  interfaces openvpn <tunnel-interface-name> local-address <value>
  interfaces openvpn <tunnel-interface-name> local-host <value>
  interfaces openvpn <tunnel-interface-name> local-port <value>
  interfaces openvpn <tunnel-interface-name> mode <value>
  interfaces openvpn <tunnel-interface-name> openvpn-option <value>
  interfaces openvpn <tunnel-interface-name> protocol <value>
  interfaces openvpn <tunnel-interface-name> remote-address <value>
  interfaces openvpn <tunnel-interface-name> remote-host <value>
  interfaces openvpn <tunnel-interface-name> remote-port <value>
  interfaces openvpn <tunnel-interface-name> replace-default-route
  interfaces openvpn <tunnel-interface-name> replace-default-route local
  interfaces openvpn <tunnel-interface-name> server
  interfaces openvpn <tunnel-interface-name> server client <client>
  interfaces openvpn <tunnel-interface-name> server client <client> disable
  interfaces openvpn <tunnel-interface-name> server client <client> ip <value>
  interfaces openvpn <tunnel-interface-name> server client <client> push-route <value>
  interfaces openvpn <tunnel-interface-name> server client <client> subnet <value>
  interfaces openvpn <tunnel-interface-name> server domain-name <value>
  interfaces openvpn <tunnel-interface-name> server max-connections <value>
  interfaces openvpn <tunnel-interface-name> server name-server <value>
  interfaces openvpn <tunnel-interface-name> server push-route <value>
  interfaces openvpn <tunnel-interface-name> server subnet <value>
  interfaces openvpn <tunnel-interface-name> server topology <value>
  interfaces openvpn <tunnel-interface-name> shared-secret-key-file <value>
  interfaces openvpn <tunnel-interface-name> tls
  interfaces openvpn <tunnel-interface-name> tls ca-cert-file <value>
  interfaces openvpn <tunnel-interface-name> tls cert-file <value>
  interfaces openvpn <tunnel-interface-name> tls crl-file <value>
  interfaces openvpn <tunnel-interface-name> tls dh-file <value>
  interfaces openvpn <tunnel-interface-name> tls key-file <value>
  interfaces openvpn <tunnel-interface-name> tls role <value>

  interfaces switch-state switches <bridge-name> interfaces <port-name> forwarding-database <index>
  interfaces switch-state switches <bridge-name> interfaces <port-name> forwarding-database <index> mac <value>
  interfaces switch-state switches <bridge-name> interfaces <port-name> forwarding-database <index> state <value>
  interfaces switch-state switches <bridge-name> interfaces <port-name> forwarding-database <index> updated <value>
  interfaces switch-state switches <bridge-name> interfaces <port-name> forwarding-database <index> used <value>
  interfaces switch-state switches <bridge-name> interfaces <port-name> forwarding-database <index> vlan-id <value>

  interfaces openvpn <tunnel-interface-name> ip tcp-mss
  interfaces openvpn <tunnel-interface-name> ip tcp-mss limit <value>
  interfaces openvpn <tunnel-interface-name> ip tcp-mss mtu
  interfaces openvpn <tunnel-interface-name> ip tcp-mss mtu-minus <value>
  interfaces openvpn <tunnel-interface-name> ipv6 tcp-mss
  interfaces openvpn <tunnel-interface-name> ipv6 tcp-mss limit <value>
  interfaces openvpn <tunnel-interface-name> ipv6 tcp-mss mtu
  interfaces openvpn <tunnel-interface-name> ipv6 tcp-mss mtu-minus <value>

  interfaces openvpn <tunnel-interface-name> ipv6 address
  interfaces openvpn <tunnel-interface-name> ipv6 address autoconf
  interfaces openvpn <tunnel-interface-name> ipv6 address eui64 <value>
  interfaces openvpn <tunnel-interface-name> ipv6 address link-local <value>
  interfaces openvpn <tunnel-interface-name> ipv6 disable
  interfaces openvpn <tunnel-interface-name> ipv6 disable-forwarding
  interfaces openvpn <tunnel-interface-name> ipv6 dup-addr-detect-transmits <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert cur-hop-limit <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert default-lifetime <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert default-preference <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert link-mtu <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert managed-flag <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert max-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert min-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert other-config-flag <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert prefix <address>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert prefix <address> autonomous-flag <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert prefix <address> on-link-flag <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert prefix <address> preferred-lifetime <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert prefix <address> valid-lifetime <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert reachable-time <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert retrans-timer <value>
  interfaces openvpn <tunnel-interface-name> ipv6 router-advert send-advert <value>

  interfaces openvpn <tunnel-interface-name> ip multicast
  interfaces openvpn <tunnel-interface-name> ip multicast ttl-threshold <value>

  interfaces openvpn <tunnel-interface-name> remote-configuration
  interfaces openvpn <tunnel-interface-name> remote-configuration password <value>
  interfaces openvpn <tunnel-interface-name> remote-configuration server <value>
  interfaces openvpn <tunnel-interface-name> remote-configuration tunnel-password <value>
  interfaces openvpn <tunnel-interface-name> remote-configuration tunnel-username <value>
  interfaces openvpn <tunnel-interface-name> remote-configuration username <value>

  interfaces openvpn <tunnel-interface-name> policy route pbr <value>
  interfaces openvpn <tunnel-interface-name> policy route pbr-state name <group-name>
  interfaces openvpn <tunnel-interface-name> policy route pbr-state name <group-name> rule <rule-number>
  interfaces openvpn <tunnel-interface-name> policy route pbr-state name <group-name> rule <rule-number> bytes <value>
  interfaces openvpn <tunnel-interface-name> policy route pbr-state name <group-name> rule <rule-number> packets <value>

  interfaces openvpn <tunnel-interface-name> ip igmp
  interfaces openvpn <tunnel-interface-name> ip igmp access-group <value>
  interfaces openvpn <tunnel-interface-name> ip igmp enforce-router-alert
  interfaces openvpn <tunnel-interface-name> ip igmp immediate-leave group-list <value>
  interfaces openvpn <tunnel-interface-name> ip igmp join-group <multicast-group>
  interfaces openvpn <tunnel-interface-name> ip igmp join-group <multicast-group> source <value>
  interfaces openvpn <tunnel-interface-name> ip igmp last-member-query-count <value>
  interfaces openvpn <tunnel-interface-name> ip igmp last-member-query-interval <value>
  interfaces openvpn <tunnel-interface-name> ip igmp limit <value>
  interfaces openvpn <tunnel-interface-name> ip igmp limit-exception <value>
  interfaces openvpn <tunnel-interface-name> ip igmp offlink
  interfaces openvpn <tunnel-interface-name> ip igmp querier
  interfaces openvpn <tunnel-interface-name> ip igmp querier forced
  interfaces openvpn <tunnel-interface-name> ip igmp querier querier-timeout <value>
  interfaces openvpn <tunnel-interface-name> ip igmp query-interval <value>
  interfaces openvpn <tunnel-interface-name> ip igmp query-max-response-time <value>
  interfaces openvpn <tunnel-interface-name> ip igmp robustness-variable <value>
  interfaces openvpn <tunnel-interface-name> ip igmp startup-query-count <value>
  interfaces openvpn <tunnel-interface-name> ip igmp startup-query-interval <value>
  interfaces openvpn <tunnel-interface-name> ip igmp static-group <multicast-group>
  interfaces openvpn <tunnel-interface-name> ip igmp static-group <multicast-group> source <value>
  interfaces openvpn <tunnel-interface-name> ip igmp version <value>

  interfaces openvpn <tunnel-interface-name> ipv6 mld
  interfaces openvpn <tunnel-interface-name> ipv6 mld access-group <value>
  interfaces openvpn <tunnel-interface-name> ipv6 mld immediate-leave
  interfaces openvpn <tunnel-interface-name> ipv6 mld immediate-leave group-list <value>
  interfaces openvpn <tunnel-interface-name> ipv6 mld last-member-query-count <value>
  interfaces openvpn <tunnel-interface-name> ipv6 mld last-member-query-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 mld limit <value>
  interfaces openvpn <tunnel-interface-name> ipv6 mld limit-exception <value>
  interfaces openvpn <tunnel-interface-name> ipv6 mld querier-timeout <value>
  interfaces openvpn <tunnel-interface-name> ipv6 mld query-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 mld query-max-response-time <value>
  interfaces openvpn <tunnel-interface-name> ipv6 mld robustness-variable <value>
  interfaces openvpn <tunnel-interface-name> ipv6 mld static-group <multicast-group>
  interfaces openvpn <tunnel-interface-name> ipv6 mld static-group <multicast-group> source <value>
  interfaces openvpn <tunnel-interface-name> ipv6 mld version <value>

  interfaces openvpn <tunnel-interface-name> ip ospf
  interfaces openvpn <tunnel-interface-name> ip ospf authentication
  interfaces openvpn <tunnel-interface-name> ip ospf authentication key-chain <value>
  interfaces openvpn <tunnel-interface-name> ip ospf authentication md5
  interfaces openvpn <tunnel-interface-name> ip ospf authentication md5-key-id <key-id>
  interfaces openvpn <tunnel-interface-name> ip ospf authentication md5-key-id <key-id> md5-key <value>
  interfaces openvpn <tunnel-interface-name> ip ospf authentication plaintext
  interfaces openvpn <tunnel-interface-name> ip ospf authentication plaintext-password <value>
  interfaces openvpn <tunnel-interface-name> ip ospf cost <value>
  interfaces openvpn <tunnel-interface-name> ip ospf dead-interval <value>
  interfaces openvpn <tunnel-interface-name> ip ospf hello-interval <value>
  interfaces openvpn <tunnel-interface-name> ip ospf mtu-ignore
  interfaces openvpn <tunnel-interface-name> ip ospf network <value>
  interfaces openvpn <tunnel-interface-name> ip ospf priority <value>
  interfaces openvpn <tunnel-interface-name> ip ospf retransmit-interval <value>
  interfaces openvpn <tunnel-interface-name> ip ospf transmit-delay <value>

  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 area <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 authentication key-chain <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 cost <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 dead-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 hello-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 instance-id <instance-id>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 instance-id <instance-id> area <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 instance-id <instance-id> cost <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 instance-id <instance-id> dead-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 instance-id <instance-id> hello-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 instance-id <instance-id> link-lsa-suppression <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 instance-id <instance-id> mtu-ignore
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 instance-id <instance-id> neighbor <address>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 instance-id <instance-id> network <network-type>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 instance-id <instance-id> priority <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 instance-id <instance-id> retransmit-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 instance-id <instance-id> transmit-delay <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 link-lsa-suppression <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 mtu-ignore
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 neighbor <address>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 network <network-type>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 priority <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id> area <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id> authentication key-chain <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id> cost <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id> dead-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id> hello-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id> link-lsa-suppression <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id> mtu-ignore
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id> neighbor <address>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id> network <network-type>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id> priority <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id> retransmit-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 process <name> instance-id <instance-id> transmit-delay <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 retransmit-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ospfv3 transmit-delay <value>

  interfaces openvpn <tunnel-interface-name> ip pim
  interfaces openvpn <tunnel-interface-name> ip pim bsr-border
  interfaces openvpn <tunnel-interface-name> ip pim dr-priority <value>
  interfaces openvpn <tunnel-interface-name> ip pim exclude-genid
  interfaces openvpn <tunnel-interface-name> ip pim hello-holdtime <value>
  interfaces openvpn <tunnel-interface-name> ip pim hello-interval <value>
  interfaces openvpn <tunnel-interface-name> ip pim mode <value>
  interfaces openvpn <tunnel-interface-name> ip pim neighbor-filter <value>
  interfaces openvpn <tunnel-interface-name> ip pim propagation-delay <value>
  interfaces openvpn <tunnel-interface-name> ip pim state-refresh
  interfaces openvpn <tunnel-interface-name> ip pim state-refresh origination-interval <value>
  interfaces openvpn <tunnel-interface-name> ip pim unicast-bsm

  interfaces openvpn <tunnel-interface-name> ipv6 pim
  interfaces openvpn <tunnel-interface-name> ipv6 pim bsr-border
  interfaces openvpn <tunnel-interface-name> ipv6 pim dr-priority <value>
  interfaces openvpn <tunnel-interface-name> ipv6 pim exclude-genid
  interfaces openvpn <tunnel-interface-name> ipv6 pim hello-holdtime <value>
  interfaces openvpn <tunnel-interface-name> ipv6 pim hello-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 pim mode <value>
  interfaces openvpn <tunnel-interface-name> ipv6 pim neighbor-filter <value>
  interfaces openvpn <tunnel-interface-name> ipv6 pim propagation-delay <value>
  interfaces openvpn <tunnel-interface-name> ipv6 pim state-refresh
  interfaces openvpn <tunnel-interface-name> ipv6 pim state-refresh origination-interval <value>
  interfaces openvpn <tunnel-interface-name> ipv6 pim unicast-bsm

  interfaces openvpn <tunnel-interface-name> ip rip authentication
  interfaces openvpn <tunnel-interface-name> ip rip authentication md5 <id>
  interfaces openvpn <tunnel-interface-name> ip rip authentication md5 <id> password <value>
  interfaces openvpn <tunnel-interface-name> ip rip authentication plaintext-password <value>
  interfaces openvpn <tunnel-interface-name> ip rip receive
  interfaces openvpn <tunnel-interface-name> ip rip receive version <value>
  interfaces openvpn <tunnel-interface-name> ip rip send
  interfaces openvpn <tunnel-interface-name> ip rip send version <value>
  interfaces openvpn <tunnel-interface-name> ip rip split-horizon
  interfaces openvpn <tunnel-interface-name> ip rip split-horizon disable
  interfaces openvpn <tunnel-interface-name> ip rip split-horizon poison-reverse

  interfaces openvpn <tunnel-interface-name> ipv6 ripng enable
  interfaces openvpn <tunnel-interface-name> ipv6 ripng metric-offset <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ripng neighbor <value>
  interfaces openvpn <tunnel-interface-name> ipv6 ripng split-horizon
  interfaces openvpn <tunnel-interface-name> ipv6 ripng split-horizon disable
  interfaces openvpn <tunnel-interface-name> ipv6 ripng split-horizon poison-reverse

  interfaces openvpn <tunnel-interface-name> firewall in <value>
  interfaces openvpn <tunnel-interface-name> firewall local <value>
  interfaces openvpn <tunnel-interface-name> firewall out <value>
  interfaces openvpn <tunnel-interface-name> firewall state in name <group-name>
  interfaces openvpn <tunnel-interface-name> firewall state in name <group-name> rule <rule-number>
  interfaces openvpn <tunnel-interface-name> firewall state in name <group-name> rule <rule-number> bytes <value>
  interfaces openvpn <tunnel-interface-name> firewall state in name <group-name> rule <rule-number> packets <value>
  interfaces openvpn <tunnel-interface-name> firewall state local name <group-name>
  interfaces openvpn <tunnel-interface-name> firewall state local name <group-name> rule <rule-number>
  interfaces openvpn <tunnel-interface-name> firewall state local name <group-name> rule <rule-number> bytes <value>
  interfaces openvpn <tunnel-interface-name> firewall state local name <group-name> rule <rule-number> packets <value>
  interfaces openvpn <tunnel-interface-name> firewall state out name <group-name>
  interfaces openvpn <tunnel-interface-name> firewall state out name <group-name> rule <rule-number>
  interfaces openvpn <tunnel-interface-name> firewall state out name <group-name> rule <rule-number> bytes <value>
  interfaces openvpn <tunnel-interface-name> firewall state out name <group-name> rule <rule-number> packets <value>

  interfaces openvpn <tunnel-interface-name> client-bundle
  interfaces openvpn <tunnel-interface-name> client-bundle generic
  interfaces openvpn <tunnel-interface-name> client-bundle linux
  interfaces openvpn <tunnel-interface-name> client-bundle osx
  interfaces openvpn <tunnel-interface-name> client-bundle windows
L2TP/IPsec remote-access VPN server
  security vpn l2tp
  security vpn l2tp remote-access
  security vpn l2tp remote-access authentication
  security vpn l2tp remote-access authentication local-users
  security vpn l2tp remote-access authentication local-users username <name>
  security vpn l2tp remote-access authentication local-users username <name> disable
  security vpn l2tp remote-access authentication local-users username <name> password <value>
  security vpn l2tp remote-access authentication local-users username <name> static-ip <value>
  security vpn l2tp remote-access authentication mode <value>
  security vpn l2tp remote-access authentication radius-server <server-address>
  security vpn l2tp remote-access authentication radius-server <server-address> key <value>
  security vpn l2tp remote-access client-ip-pool
  security vpn l2tp remote-access client-ip-pool start <value>
  security vpn l2tp remote-access client-ip-pool stop <value>
  security vpn l2tp remote-access description <value>
  security vpn l2tp remote-access dhcp-interface <value>
  security vpn l2tp remote-access dns-servers
  security vpn l2tp remote-access dns-servers server-1 <value>
  security vpn l2tp remote-access dns-servers server-2 <value>
  security vpn l2tp remote-access ipsec-settings
  security vpn l2tp remote-access ipsec-settings authentication
  security vpn l2tp remote-access ipsec-settings authentication mode <value>
  security vpn l2tp remote-access ipsec-settings authentication pre-shared-secret <value>
  security vpn l2tp remote-access ipsec-settings authentication x509
  security vpn l2tp remote-access ipsec-settings authentication x509 ca-cert-file <value>
  security vpn l2tp remote-access ipsec-settings authentication x509 crl-file <value>
  security vpn l2tp remote-access ipsec-settings authentication x509 server-cert-file <value>
  security vpn l2tp remote-access ipsec-settings authentication x509 server-key-file <value>
  security vpn l2tp remote-access ipsec-settings authentication x509 server-key-password <value>
  security vpn l2tp remote-access ipsec-settings ike-lifetime <value>
  security vpn l2tp remote-access mtu <value>
  security vpn l2tp remote-access outside-address <value>
  security vpn l2tp remote-access outside-nexthop <value>
  security vpn l2tp remote-access server-ip-pool
  security vpn l2tp remote-access server-ip-pool start <value>
  security vpn l2tp remote-access server-ip-pool stop <value>
  security vpn l2tp remote-access wins-servers
  security vpn l2tp remote-access wins-servers server-1 <value>
  security vpn l2tp remote-access wins-servers server-2 <value>
NAT
  service nat ipv6-to-ipv4
  service nat ipv6-to-ipv4 rule <rule-number>
  service nat ipv6-to-ipv4 rule <rule-number> destination prefix <value>
  service nat ipv6-to-ipv4 rule <rule-number> inbound-interface <value>
  service nat ipv6-to-ipv4 rule <rule-number> source prefix <value>
System management
  system config-management commit-archive location <value>
  routing routing-instance <instance-name> system config-management commit-archive location <value>

Obsolete commands

A range of configuration commands have been obsoleted in this release.

  system alg rsh disable
  routing routing-instance <instance-name> system alg rsh disable